June 14, 2006 1:14 PM PDT

Money lost to cybercrime down--again

SCOTTSDALE, Ariz.--While many headlines spell doom and gloom when it comes to computer-related misdeeds, the average losses at businesses due to cybercrime continue to drop, according to a new survey.

For the fourth straight year, the financial losses incurred by businesses due to incidents such as computer break-ins have fallen, according to the 2006 annual survey by the Computer Security Institute and the FBI. Robert Richardson, editorial director at the CSI, discussed the survey's findings in a presentation at the CSI NetSec conference here Wednesday.

Respondents in the 2005 survey reported an average of $204,000 in cybercrime losses, Richardson said. This year, that's down to $168,000, about an 18 percent drop, he added. Compared with 2004, the average loss is down 68 percent.

"How do you go about reconciling the sense of things getting worse with the respondents who are saying they are losing less money?" Richardson asked. The 2006 survey, a final version of which is slated to be released next month, could provide some answers.

Most important, perhaps, the 615 U.S. CSI members who responded to this year's survey reported fewer security incidents. Viruses, laptop theft and insider abuse of Net access are still the most reported threats, but all have decreased compared with last year.

"The danger of insiders may be somewhat overstated, according to the survey group," Richardson said. About a third of respondents said they had no losses at all due to insider threats, another 29 percent said less than one-fifth of overall losses came from insider threats.

Consistent use of security technology may also contribute to the improvements, with essentially all of the respondents stating that they use firewall and antivirus software, not much of a change from last year. This year, eight out of 10 said they also use spyware protection, a category not listed a year ago.

"Overall, you have a picture that is pretty good in many ways," Richardson said. "We're seeing fewer of some of the attacks that have been such a plague for us in many years, and respondents are using less and less money."

That "less money" may be good for companies, but not for security vendors. It refers to the percentage of IT budgets spent on security. In the 2006 survey, nearly half of the respondents said less than 2 percent of the budget is spent on security. Last year that percentage was 35 percent.

When it comes to cybercrime losses, consumers might be bearing the brunt of them, and they are not covered by the survey, Richardson suggested. "Consumers are the low-hanging fruit," he said. Costs related to identity theft, for example, fall largely back onto the consumer, he added, even if it did start with a data breach at an enterprise.

See more CNET content tagged:
respondent, survey, cybercrime, security

5 comments

Join the conversation!
Add your comment
Ironic...
don't you think? As people get smarter and dump Wind0ze and IE
(wheeeee) for Linux, Firefox and OS X, viruses and cybercrime
drop!
Posted by robot999 (109 comments )
Reply Link Flag
Ironic? I'd say sensible
I dropped IE a long time ago, and a Mac is actually looking like quite the bargain right now. Still, the consumer isn't covered in the survey, so who knows where cybercrime really stands?
Posted by ~Canuck~ (71 comments )
Link Flag
wait til VA mishap numbers register
So, the survey cited "615 U.S. CSI members who responded to this year's survey reported fewer security incidents," how about a separate study showing the impact of the 26.5 million U.S. Veterans? What about when those numbers start to come through? <a class="jive-link-external" href="http://www.iwantmyess.com/?p=61" target="_newWindow">http://www.iwantmyess.com/?p=61</a>
Posted by marileev (292 comments )
Reply Link Flag
Statistics
Are these statistics accurate?

Neal Saferstein
Posted by nealsaferstein (26 comments )
Reply Link Flag
Agreed
That is the 1 thing about statistics people don't realize, You can use them to prove or disprove your point very easily.
Posted by stacksmasher (8 comments )
Reply Link Flag
 

Join the conversation

Add your comment

The posting of advertisements, profanity, or personal attacks is prohibited. Click here to review our Terms of Use.

What's Hot

Discussions

Shared

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.