Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Ransomware considered top overall threat to data

by The Gurus
September 11, 2017
in Editor's News
ransomware
Share on FacebookShare on Twitter

According to the results of a new survey to be released by SANS Institute on the 6th September, ransomware is considered the top overall threat to businesses’ data, with user credentials and privileged accounts the most common data types involved in significant breaches.
 
The ‘Sensitive Data at Risk: The SANS 2017 Data Protection Survey’ questioned IT and security administrators, engineers, managers, developers and privacy experts globally, across a wide variety of industries. These front-line professionals considered ransomware as the top overall threat to data availability, based on occurrences in the past 12 months.
 
Insider threats and denial of service are also considered top threats to sensitive data. While the majority of respondents indicated that they escaped actual compromise of sensitive data, enough respondents did lose sensitive data to provide valuable lessons from these events. Of the respondents, 78% reported two or more threats occurring in the past 12 months; 68% reported the same threat occurring multiple times over that same period.
 
User credentials and privileged accounts represented the most common data types involved in these breaches, highlighting the fact that access data is prized by attackers. Access information is most sought after because it grants the attackers the same privilege as their victims. They often use this privilege to escalate and spread their attacks, allowing them to gather more types of sensitive information. Other key data being targeted in significant breaches includes customer personally identifiable data, selected by 31% of respondents, and employee data and intellectual property, each chosen by 28%.
 
“I used to consider data sources such as network and personnel directories as items that need to be protected—although not at the level of ‘sensitive’ data, such as financial and healthcare records,” says Barbara Filkins, SANS Analyst Program Research Director and author of the survey report. “Maybe access information needs even greater protection, given that this survey showed that user credentials and privileged accounts represented the most common data types involved in breaches.”
 
Knowing what the attackers are looking for is half the battle. Understanding how data flows through systems, which is done by less than 4% of the survey sample, is an example of a step defenders can use to aid in both detection and remediation of breaches. Yet 62% indicate that identifying all pathways to their sensitive data is a key challenge.
 
“When defenders know what attackers want most, they know how to prioritise their efforts,” says Benjamin Wright, an expert on the legal aspects of data protection and advisor on this project. “This survey shows how much attackers covet user credentials and privileged accounts.”
 
“Drawing data maps and flows may not be perfect, but the process illustrates a key starting point,” continues Filkins. “A picture—or in this case a map—is worth a thousand words in understanding where to start protecting data.”
 
Full results will be shared during a Wednesday, September 6, 2017 webcast at 1 PM EDT, sponsored by Infoblox and McAfee, and hosted by SANS. Register to attend the webcast at www.sans.org/u/vpK
 
Those who register for the webcast will also receive access to the published results paper developed by SANS Analyst Program Research Director and data protection expert, Barbara Filkins.

Tags: CybersecurityTechnology
ShareTweet
Previous Post

Putting app security centre stage against threat actors

Next Post

What boards must do to mitigate the cyber attack risk

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol