Home Business IT Security Survey: 1 in 5 organisations has experienced an APT attack

Get all your tech news delivered to your mail box five days a week
iTWire UPDATE - it's FREE!

Probably, the others just don't know that they have.

ISACA, a global provider of information system assurance and security, surveyed over 1,500 security professionals during the fourth quarter of 2012 to find that around one in five reported that their enterprise had been the victim of an advanced persistent threat (APT). Further, according to the survey, 94% of those respondents said that "APTs represent a credible threat to national security and economic stability, yet most enterprises are employing ineffective technologies to protect themselves."

ISACA has released the results of the survey to show that there is a still-growing threat.

"APTs are sophisticated, stealthy and unrelenting," said Christos Dimitriadis, international vice president of ISACA and head of information security at INTRALOT GROUP. "Traditional cyberthreats often move right on if they cannot penetrate their initial target, but an APT will continually attempt to penetrate the desired target until it meets its objective - and once it does, it can disguise itself and morph when needed, making it difficult to identify or stop."

The survey also noted that over 60% of survey respondents thought that it was merely a matter of time before their enterprise was targeted. Contrasting with the 53% who considered that APTs were no different to 'ordinary' threats. These numbers are rather confusing when linked with the fact that around 60% of those surveyed believed their organisations were prepared for an APT incident.

However, more concerning (especially amongst so-called security professionals) was the opinion amongst a vast majority of respondents that antivirus and antimalware along with network perimeter technologies such as firewalls were sufficient protection.

They're not.

"APTs call for many defensive approaches, from awareness training and amending third-party agreements to ensure vendors are well-protected, to implementing technical controls," said Jo Stewart-Rattray, director of ISACA and director of information security and IT assurance at BRM Holdich.

The organisation also calls for the recognition that APTs are entirely different to 'normal' threats. As one security expert recently told iTWire (and we paraphrase), "you're either being hit by APTs, or you simply don't know that you're being hit by APTs."


Tomorrow, 26 August we’re delivering a FREE day of high-impact content to give you the know-how to lead in the App Economy. Please don’t be sorry you missed it.

• Keynotes on how software is rewriting businesses the world over, including our own backyard

• View code level details with context and repair problems quickly

• Fix problems in minutes before they wreak havoc

• Streams covering DevOps, Security and Management Cloud from pioneers at the coalface.

Register Now - it's FREE!



Where are your clients backing up to right now?

Is your DR strategy as advanced as the rest of your service portfolio?

What areas of your business could be improved if you outsourced your backups to a trusted source?

Read the industry whitepaper and discover where to turn to for managed backup


David Heath

joomla statistics

David Heath has over 25 years experience in the IT industry, specializing particularly in customer support, security and computer networking. Heath has worked previously as head of IT for The Television Shopping Network, as the network and desktop manager for Armstrong Jones (a major funds management organization) and has consulted into various Australian federal government agencies (including the Department of Immigration and the Australian Bureau of Criminal Intelligence). He has also served on various state, national and international committees for Novell Users International; he was also the organising chairman for the 1994 Novell Users' Conference in Brisbane. Heath is currently employed as an Instructional Designer, building technical training courses for industrial process control systems.