5 ms·
Naive question, but common our enterprise break-ins where a company would need a tool devoted entirely to it?
by notdarkyet 13y ago
Naive question, but common our enterprise break-ins where a company would need a tool devoted entirely to it?
- maaku 13y agoIt doesn't matter if they are common. What matters is that if/when it does happen, the results aren't catastrophic.
- thirsteh 13y agoAmong all enterprises? Very common. You don't hear about the vast majority of them. (Keep in mind a break-in doesn't have to have been targeted specifically at you to cause damage or to be classified as a break-in.)
- MacsHeadroom 13y agoThat depends on the industry and company size, and also on your definition of a breach. 45% of all retail companies DETECTED at least one serious information systems breach in 2013. (Many more would have experienced a breach without knowing.) According to Trustwave's 2013 Global Security Report, the top 5 most breached industries are 1. Retail 2. Food & Beverage 3. Hospitality 4. Financial Services and 5 Non-Profits, followed by High-Tech. The Trustwave report doesn't break things down by company size. But you can be sure that large retail companies (Macy's, GoDaddy, Microsoft, Goodyear, Betty Crocker, etc) have many many incident response teams who follow up on multiple incidents each day. Most aren't serious, of course. But they all need to be handled thoroughly because one mishandled serious breach is all it takes to cost a company as much as hundreds of millions of dollars in damages. A quick LinkedIn search shows 150,000 people working in incident response positions in the U.S. A good bit of those work for incident response service providers like Mandiant https://www.mandiant.com/services/incident-response/ https://www.mandiant.com/services/incident-response/ Most companies under ~300 employees aren't going to have in-house IR teams (many do though). They'll hire companies like Mandiant to respond to serious incidents while letting insurance handle the less serious incidents.