Polymer

Download free DLP for AI whitepaper

Summary

  • The Verizon data breach investigations report (DBIR) found that the human element accounted for 82% of intrusions in 2021.
  • Stolen credentials accounted for almost 50% of cyber-attacks in 2021.
  • Supply chain attacks are on the rise.
  • Nearly 25% of all data breaches in 2021 involved ransomware.

It’s that time of year again! The telecoms and mobile security conglomerate Verizon has released its annual Data Breach Investigation Report (DBIR) – an in-depth report with some of the best insights into security and malware that you’ll find. 

This year’s findings are collated from over 5,000 data breaches around the world that occured in 2021. As always, the DBIR is a meaty, mighty read. So if you want the ‘TL; DR’ version, you’ve come to the right blog! 

Let’s dive in. 

  1. The ‘human’ element is a huge factor in data breaches

The research found that the human element accounted for 82% of intrusions in 2021. Verizon defines the human element as anything involving the following:

  • Errors: Mistakes made by employees that allow cyber-criminals to access sensitive data. A prime example of this would be a misconfigured cloud instance that is set to public. This accounted for 13% of all data breaches. 
  • Privilege misuse: The use of stolen credentials to log-in to employee accounts.
  • Social engineering: Incidents where employees fall for scams like phishing or SMS-ishing. 

This is a pretty sobering finding. Any security guy knows that the ‘human factor’ has been a major player in data breaches for decades. And yet, things aren’t changing. 

From our perspective, there’s one huge reason for this. Companies still rely on tick-box training that doesn’t have a true impact. 

Screenshot from Verizon DBIR

Organizations need to move away from boring e-Learning programs and annual away days. Instead, we advocate incorporating employee security training directly into the daily workflow via what’s known as security and privacy nudges. 

Successful nudging techniques are based on a positive manipulation of people’s actions. They either make people stop and think, so they can choose a better outcome or rely on people’s tendency to take the easy option.

For example, let’s say an employee is about to close a Google doc that’s full of sensitive information, but they haven’t set it to private. The nudge will pop-up to remind them that they should change the settings. 

Sounds cool, right? Well, that’s what our engine does. We provide employee-based risk scoring based on patterns of sharing sensitive data. Our user nudges and warnings are designed to help users avoid phishing scams, data loss and cloud misconfigurations. 

  1. Stolen credentials are a huge way cyber-criminals get into companies

Stolen credentials accounted for almost 50% of cyber-attacks in 2021. The report found that there’s actually been a 30% increase in credentials theft since 2017. 

We find this particularly interesting. We would’ve expected credentials theft to go down, given the rise of multi-factor authentication. However, it seems that companies either aren’t implementing MFA or hackers are finding workarounds (as was the case in the EA data breach). 

For organizations, the rise in credentials theft really underlines the importance of implementing a zero-trust approach to security. It’s no longer secure to rely on passwords as a means of authentication. 

Of course, implementing zero-trust is a bit like tackling a behemoth. It can’t be done overnight. Luckily, though, there are tools out there – like ours – that are built on the principles of zero trust, offering you a ready-to-go solution that kick-starts your zero-trust journey.

You see, our cloud data protection engine protects against credentials misuse by moving access controls closer to your sensitive data. The engine uses user behavior analytics to dynamically authenticate users as they interact with your corporate data, ensuring that only legitimate and trusted people are given access.  

  1. Supply chain breaches are as big an issue as feared

Supply chain attacks were a mainstay feature in the headlines last year. As a result, it’s not surprising that 62% of system intrusion incidents came from companies’ partners and suppliers. 

For cybercriminals, supply chain attacks are a holy grail. Rather than compromising just one company, they can infiltrate hundreds – if not thousands! 

Protecting against supply chain breaches is a complex undertaking – but a very important one. We advise reviewing NIST’s guide to supply chain security management as a way to set up a supplier assurance process. 

As well as having policies in place, you’ll also need the right tools. Again, taking a data-centric approach is vital – especially in instances where your data is stored in third-party cloud environments. 

This is where Next-gen DLP or Data Exposure Prevention (DEP) comes in. It works by monitoring, classifying and protecting sensitive data across cloud applications and collaboration tools. Through predefined policies, it prevents data loss in real-time through automatic actions like redaction, encryption and deletion.

  1. The ransomware reign continues

Nearly 25% of all data breaches in 2021 involved ransomware, a form of malware that encrypts access to your data and files until you pay a hefty ransom. 

Screenshot from Verizon DBIR, showing ransomware has increased.

Ransomware is often delivered to a company via a phishing email. So, again, employee training and thoughtful nudges can be a great way to reduce your risk of these attacks. As well as this, make sure you regularly backup critical data to the cloud. That way, if the worst-case scenario happens, you’ll be able to restore your files without having to pay criminals! 

Conclusion

That’s a wrap! The major takeaways from Verizon’s DBIR 2022. Our main learning? Companies need to rapidly move to a zero-trust security model and improve how they educate their employees on security. 

Doing this doesn’t need to be difficult. With Polymer DLP, you can enhance your cloud security posture in a matter of minutes, thanks to a no-code deployment model. 

Learn more about our solution here

Polymer is a human-centric data loss prevention (DLP) platform that holistically reduces the risk of data exposure in your SaaS apps and AI tools. In addition to automatically detecting and remediating violations, Polymer coaches your employees to become better data stewards. Try Polymer for free.

SHARE

Get Polymer blog posts delivered to your inbox.

HOKI311

KUPU178

RATU311

RATU311

RATU311

KUPU178

KUPU178

THOR311

KUPU178

RATU311

THOR311

THOR311

THOR311

THOR311

RATU311

RATU311

KUPU178

KUPU178

KUPU178

THOR311

THOR311

THOR311

THOR311

RATU311

RATU311

RATU311

RATU311

thor311 domino qq

thor311 akses

thor dingdong

THOR311

ceri188

ceri188

ceri188

HOKI311

KUPU178

RATU311

RATU311

kupu178

kupu178

HOKI311

togel

kupu178

ratu311

mix parlay

ceri188

slot online

kupu178

THOR311

THOR311

KUPU178

KUPU178

KUPU178

RATU311

kupu178

hoki311

THOR311

hoki311

togel online

kupu178

slot mahjong

ceri188

slot server thailand

ratu311

ceri188

ceri188

punjabi virasat

mimcord.com

Centrum Medyczne

www.vrcorporate.in

phbalance.vn

KUPU178

daftar slot gacor

hoki311

togel hongkong

kupu178

slot mahjong

ratu311

slot gacor

kupu178

kupu178

ceri188

kupu178

ceri188

KUPU178

KUPU178

kupu178

RATU311

RATU311

RATU311

KUPU178

KUPU178

RATU311

RATU311

slot online

kupu178

thor311

thor311

kupu178

kupu178

THOR311

THOR311

KUPU178

slot mahjong ways

hoki311

slot gacor

ceri188

ratu311

kupu178

Casino Baccarat Online

kupu178

kupu178

ceri188

ceri188

THOR311

RATU311

toto macau

KUPU178

slot gacor

HOKI311

sabung ayam online

RATU311

SLOT LUCKY NEKO

CERI188

Slot Gacor

KUPU178

RATU311

RATU311

Link Spaceman

CERI188

Slot Gacor Online

THOR311

Mahjong ways

KUPU178

THOR311

THOR311

Live Casino

HOKI311

CERI188

CERI188

THOR311

THOR311

RATU311

RATU311

RATU311

RATU311

RATU311

RATU311

RATU311

KUPU178

KUPU178

CERI188

HOKI311 SLOT

TOTO TOGEL TOKYO

CERI188

CERI188 SITE

CERI188

RATU311

RATU311

RATU311

Toto Togel

KUPU178

Slot Mahjong

CERI188

CERI188

CERI188

Slot Sweet Bonanza 2500

KUPU178

SLOT ONLINE

RATU311

RATU311

RATU311

RATU311

KUPU178 X SLOT777

judi bola online

THOR311

KUPU178 10 GAME SLOT TERBAIK

KUPU178

KUPU178 SLOT TERPERCAYA

KUPU178 TOGEL

TOTO 4D MACAU

KUPU178

SITUS BOLA

CERI188

KUPU178

RATU311

THOR311

HOKI311

KUPU178

RATU311

THOR311

CERI188

Slot Mahjong Ways

KUPU178

CERI188

Slot Online Resmi

KUPU178

RATU311 SLOT ONLINE

KUPU178

KUPU178: Link Akses Resmi

KUPU178: Strategi Menang Di Game Live Casino

KUPU178

KUPU178: Minimal 200 Rupiah

Slot Gacor Online

KUPU178

Mix Parlay

CERI188

CERI188

THOR311

THOR311

THOR311

THOR311

THOR311

KUPU178

Slot Thailand

CERI188

CERI188

THOR311 RTP

RATU311

RATU311

RATU311

CERI188

KUPU178 TOTO SLOT

CERI188 TOTO Singapore

THOR311

KUPU178

KUPU178

RATU311

CERI188

RATU311: Alternatif karnpuracollege

RATU311

RATU311

Thor311 Terbaru

THOR311 MAHJONG

RATU311: BONUS SABUNG AYAM

CERI188: Masuk Akun Slot Super Cepat

CERI188

CERI188

CERI188

THOR311

HOKI311

HOKI311

RATU311

HOKI311

KUPU178

RATU311

RATU311

RATU311

RATU311

THOR311

CERI188

CERI188

RATU311

RATU311

RATU311

RATU311

Game Thor311

HOKI311

HOKI311

RATU311

HOKI311

HOKI311

THOR311

RATU311 NONTON BOLA

HOKI311 Link QRIS EWALLET

RATU311

HOKI311 Link Apk Resmi

CERI188

RATU311 judi bola

KUPU178

situs judi bola

HOKI311

RATU311

THOR311

HOKI311

KUPU178

kupu178 link alternatif

kupu178 slot

kupu178 daftar

kupu178 login

link daftar kupu178

judi bola

RATU311

link alternatif RATU311

Link daftar RATU311

link login RATU311

RATU311

KUPU178

KUPU178

RATU311

RATU311

KUPU178

THOR311

slot thailand

judi bola

KUPU178

slot gacor

slot gacor

slot gacor

RATU311

THOR311