Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Opportunistic attacks outweigh targeted efforts

by The Gurus
December 9, 2013
in Editor's News
Share on FacebookShare on Twitter

The majority of attacks are opportunistic rather than targeted, which businesses struggle to detect and contain.
 
According to a report by Trusteer and Ponemon Institute, 53 per cent of 755 IT security professionals have experienced “opportunistic” attacks, compared to 16 per cent who believe that an attack was targeted at them. Of those surveyed, 55 per cent said that they had “some involvement” in preventing or detecting those targeted attacks.
 
Trusteer senior security strategist George Tubin told IT Security Guru that the majority being opportunistic did not surprise him, nor did the time taken to detect and mitigate as it “takes time to find it and detect it immediately”.
 
He said: “With RSA, they didn’t catch it until the criminals stole the core of their data for their two factor tokens. It is a case of how long the criminals are in and what do they do before they download. The average time to be caught is 225 days and organisations do not usually find APT attacks until the attacker has got what they needed.
 
“44 per cent said that they can contain an attack, while 49 per cent can detect, but what if they have detected before anything was stolen and shut them down, as far as they know!”
 
The majority of respondents (67 per cent) claimed that there had been no change in the frequency of opportunistic attacks over the last 12 months, which Tobin claimed was typical as it is fairly easy to launch such an attack through an email blast, while launching a targeted attack involves research.
 
“It is like fishing with a big net, and maybe you will catch a big fish, but what we see with targeted attacks is advanced techniques is cyber criminals are paying for zero-day vulnerabilities and they can target an organisation and we see vulnerabilities that no-one knows and it reduces the chances of getting caught.
 
“With a targeted attack, it is more work and you reduce the reach and who to send to, and what you get out of it; while with opportunistic attacks you use malware and vulnerabilities rather than investing time into it, so there will be more use of sophisticated methods as it is easier to prevent than targeted attacks.”
 
In terms of the frequency not changing, Tobin said that the cyber criminal landscape changes and we will see targeted attacks mainly against financial companies. “Some will do advanced attacks to see what they can catch, but we see many cyber criminals moving to fund attacks and do finer targeting. We see significant operations in targeted attacks and sophisticated techniques.
 
“Organisations are aware of APT and how it has changed over time. There is a huge need for new technologies that work and security leaders need budget and to fix problems as there is a goal to make it happen. Things are changing and we are not there yet.”

Tags: APTattack
ShareTweet
Previous Post

Apple, Microsoft and Facebook form group to push reform of Government surveillance

Next Post

The past and present of DDoS attacks with Neustar

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol