Find White Papers
Home
About Us
List Your Papers
    
> McAfee Inc > The Security Paradox

The Security Paradox

White Paper Published By: McAfee Inc

Medium organizations around the globe are increasingly concerned about cyberthreats, and the rising number of incidents shared publicly certainly justifies their worries. In the first half of 2009, for example, McAfee Labs saw almost as much new malware as it did in all of 2008. At the same time, most organizations have frozen or cut their IT security budgets. Threats up, budgets down. This is what we call the "security paradox."



Tags : 
mcafee, security, cyberattacks, midsize, cyberthreats, compliance, security tools, sans

McAfee Inc
Published:  Oct 26, 2009
Type:  White Paper
Length:  15 pages

The Security ParadoxThe First Global Study that Quantifies the Cost of Reactive  Versus Proactive Security in a Midsize Organization
The Security Paradox 1The Security Paradox CONTENTS
Foreword 3
Methodology 4
Key Findings Worldwide 5
Threats Rise, Budgets Fall 6
Worry Tempered By Size 8
Threats and Responses Analysis 9
Threats Versus Budgets 11
The Changing Face of the Threats 12
Moving from Reactive to Proactive 13
The Best Defense in a Downturn 14
Contact 14Foreword
Medium organizations around the globe are increasingly concerned
about cyberthreats, and the rising number of incidents shared
publicly certainly justifies their worries. In the first half of 2009, for ®example, McAfee Labs saw almost as much new malware as it
did in all of 2008. At the same time, most organizations have frozen
or cut their IT security budgets. Threats up, budgets down. This is
what we call the "security paradox."
Those realities are exploited by cybercriminals, who use the downturn to step up the pace. Disgruntled employees are also walking away with valued information assets, while businesses scale back on defense in an effort to get lean. And it's happening at a time when businesses can ill afford downtime, decreased productivity, stolen data, lost sales and a damaged corporate reputation.
This report quantifies security spending within midsize organizations (those with 51 to 1,000 employ-ees). As these companies grow into larger enterprises, we wanted to examine how they allocate their security resources and dollars, particularly as they react to a growing threat landscape. In the last year, one in five midsize organizations had a security incident that directly caused their organization to lose revenue-$41,000 on average. In China, 38 percent of businesses had an incident with an average loss of $85,000. Some 70 percent of businesses believe there is some chance a serious data breach could put their company out of business. About the same number froze or cut their IT security budgets to focus their resources on building or retaining their businesses. When revenues are down, so are budgets.
The good news is that being proactive costs far less than what companies spend during remediation resulting from a cyberattack. With the right solutions in place, midsize organizations can reduce the complexity and cost of deploying and managing security-during a time when doing more with less is the number one priority.
Darrell Rodenbaugh Senior Vice PresidentGlobal Mid-Market Business Unit McAfee, Inc.
The Security Paradox 3Methodology
For this report, McAfee surveyed companies in Australia, Canada, China, France, Germany, India, Spain, the United Kingdom and the United States. The results were then compared to previous studies conducted in Europe and North America.
The study was conducted by MSI International. Approximately 100 surveys were collected in each Medium-sized business members of an online country. The data was weighted by employee size Internet panel were recruited to participate in an to reflect the proportion of companies within the Internet survey. To qualify, the person completing employee range of 51 to 1,000.the survey had to meet the following criteria: MSI International is a full-service marketing intel-. Be employed in a company with 51 to 1,000 ligence firm headquartered in Philadelphia, and employees worldwide has been in business for more than 15 years. In . Be involved in the management of IT products 2004, the company launched a joint venture, and services or have decision-making respon- MSI-ITM B.V., based in Amsterdam, to specialize in sibilities for their company concerning IT and Web-based marketing intelligence solutions. MSI's security issues current clients include leading global, national and regional firms. To learn more, visit www.msimsi.. Be employed in a company that was not com and www.msi-itm.com.considered a government-sector or non-profit organization
4 The Security ParadoxKey Findings Worldwide
56% 78%of midsize organizations are seeing more security of midsize organizations around the world are incidents this year than last concerned about being a target of cybercrime
29% 19%of midsize organizations suffered from a data of midsize organizations had an IT security inci-br... [download for more]

Browse Technology Topics

Data Center

Virtualization, Cloud Computing, Infrastructure, Design and Facilities, Power and Cooling, Green Computing  
    

Data Management

Application Integration, Analytical Applications, Business Intelligence, Configuration Management, Database Development, Data Integration, Data Mining, Data Protection, Data Quality, Data Replication, Database Security, EDI, SOAP, Service Oriented Architecture, Web Service Management, Data Warehousing  
    

Enterprise Applications

Application Integration, Application Performance Management, Best Practices, Business Activity Monitoring, Business Analytics, Business Integration, Business Intelligence, Business Management, Business Metrics, Business Process Automation, Business Process Management, Call Center Management, Call Center Software, Change Management, Corporate Governance, Customer Interaction Service, Customer Relationship Management, Customer Satisfaction, Customer Service, EBusiness, Enterprise Resource Planning, Enterprise Software, EProcurement, Extranets, Groupware Workflow, HIPAA Compliance, IP Faxing, IT Spending, Marketing Automation, Performance Testing, Product Lifecycle Management, Project Management, Return On Investment, Risk Management, Sales & Marketing Software, Sales Automation, Server Virtualization, Simulation Software, Supply Chain Management, System Management Software, Total Cost of Ownership, Video Conferencing, Voice Recognition, Voice Over IP, Workforce Management, Incentive Compensation, Spend Management, Manufacturing Execution Systems, International Computing  

Human Resource Technology

Human Resources Services, Payroll Software, Time and Attendance Software, Workforce Management Software, Financial Management, Employee Monitoring Software, Employee Training Software, Recruiting Software/Services, Employee Performance Management, ELearning, Benefits Management, Expense Management  
    

IT Career Advancement

Cisco Certification, Microsoft Certification, Linux Certification, Network Security Certification, Software Development Certification  

IT Management

Employee Performance, ITIL, Productivity, Project Management, Software Compliance, Sarbanes Oxley Compliance, Service Management, Desktop Management  
    

Knowledge Management

Collaboration, Collaborative Commerce, Contact Management, Content Delivery, Content Integration, Content Management System, Corporate Portals, Customer Experience Management, Document Management, Information Management, Intranets, Messaging, Records Management, Search And Retrieval, Search Engines, Secure Content Management, SLA  

Networking

Active Directory, Bandwidth Management, Convergence, Distributed Computing, Ethernet Networking, Fibre Channel, Gigabit Networking, Governance, Grid Computing, Infrastructure, Internetworking Hardware, Interoperability, IP Networks, IP Telephony, Local Area Networking, Load Balancing, Migration, Monitoring, Network Architecture, Network Management, Network Performance, Network Performance Management, Network Provisioning, Network Security, OLAP, Optical Networking, Quality Of Service, Remote Access, Remote Network Management, Server Hardware, Servers, Small Business Networks, TCP/IP Protocol, Test And Measurement, Traffic Management, Tunneling, Utility Computing, VPN, Wide Area Networks, Green Computing, Cloud Computing, Power and Cooling, Data Center Design and Management, Colocation and Web Hosting  
    

Platforms

AS/400, Domino, Linux, Microsoft Exchange, Oracle, PeopleSoft, SAP, Siebel, Solaris, Tivoli, Unix, Web Sphere, Windows, Windows Server  

Security

Access Control, Anti Spam, Anti Spyware, Anti Virus, Application Security, Auditing, Authentication, Biometrics, Business Continuity, Compliance, DDoS, Disaster Recovery, Email Security, Encryption, Firewalls, Hacker Detection, High Availability, Identity Management, Internet Security, Intrusion Detection, Intrusion Prevention, IPSec, Network Security Appliance, Password Management, Patch Management, Phishing, PKI, Policy Based Management, Security Management, Security Policies, Single Sign On, SSL, Secure Instant Messaging, Web Service Security, PCI Compliance, Vulnerability Management  
    

Software Development

.NET, C++, Database Development, Java, Middleware, Open Source, Software Outsourcing, Quality Assurance, Scripting, SOAP, Software Testing, Visual Basic, Web Development, Web Services, Web Service Security, XML  

Storage

Backup And Recovery, Blade Servers, Clustering, IP Storage, ISCSI, Network Attached Storage, RAID, Storage Area Networks, Storage Management, Storage Virtualization, Email Archiving, Data Deduplication  
    

Wireless

802.11, Bluetooth, CDMA, GPS, Mobile Computing, Mobile Data Systems, Mobile Workers, PDA, RFID, Smart Phones, WiFi, Wireless Application Software, Wireless Communications, Wireless Hardware, Wireless Infrastructure, Wireless Messaging, Wireless Phones, Wireless Security, Wireless Service Providers, WLAN  
Search