![]() |
||||||
|
|
||||||
|
|
||||||
|
|
||||||
Beware: IP Theft Is Often an Inside JobA new report released by Verizon Information Technologies that examines incidents of intellectual property (IP) theft at companies in several industries, including the high tech, financial, and manufacturing sectors, offers sobering news to the electronics industry as it seeks to electronically protect its patents -- the very thing that brings value and competitive advantage to a company's business. DBIR Snapshot: Intellectual Property Theft is a report that examined 85 confirmed data breaches over the last two years resulting in the theft of intellectual property. The findings are based on breaches investigated by Verizon's Research Intelligence Solutions Knowledge (RISK) Team or one of its partner organizations, which include the Australian Federal Police, the Dutch National High Tech Crime Unit, the Irish Reporting and Information Security Service, the Police Central e-Crime Unit, and the United States Secret Service. The data shows that while most of the breaches originate from external entities that often use malware and hacking methods to steal IP data, even more troubling is that 46 percent of employees are participating in the theft of intellectual property information. The research also shows that efforts to combat system penetration will have to focus on several aspects of data security as adversaries rely on multiple methods of attack to successfully penetrate a company's knowledge assets. The study outlines several ways that an attack occurs, including:
Listing the top three methods an attacker uses to carry out IP theft, the research found that 45 percent of data penetration occurred via abuse of system access or privileges, another 34 percent occurred as a result of using stolen login credentials, and 32 percent were the result of pretexting, which is the act of using false information to trap individuals into divulging privileged information that can be used to penetrate data systems. When managing security in a modern high-tech supply chain, Wade Baker, managing principal for Verizon's RISK team, said the links between supply chain partners such as component suppliers, contract manufacturers, and distributors operating across the globe opens up the electronic manufacturing enterprise to many new security threats. "If I have three other partners who I depend on to send me information so that I can do what I need to do for my business, and if a supply chain partner sends me information [with a computer virus attached], or if my information is compromised, the impact spreads," said Baker, who is also the principal author of the report. While the report offers several recommendations to protect IP theft, the report concludes that:
The report also lists a number of recommendations to protect against IP theft, which include:
If there's anything that IT security executives at high-tech manufacturing companies can learn from the report's findings, it is that as their extended supply chains rely on networks that manage sensitive company information, they need to continue to develop policies and procedures that will prevent these attacks. Certainly, the time, effort, and resources committed to mitigating IP theft is a worthwhile endeavor. |
More Blogs from At the Source
On the hunt for a demand-driven maturity model for companies that are looking at ways to optimize their supply chains.
Removing harmful electronic products in a responsible way is not only the right thing to do, but a smart business move.
While some parts of the high-tech supply chain network can be improved by implementing policies and procedures, other parts of the network are beyond the control of even the most skilled supply chain executive.
As Intel improves its chip technology and deals with a declining PC market, the company is still making a concerted effort to improve its supply chain.
Civil engineers give US transportation infrastructure embarrassingly poor grades. We've got work ahead of us.
Datasheets.com Parts Search185 million searchable parts
|
|||||
|
|
||||||