Verizon’s annual data breach report shows there hasn’t been much change in the threat landscape over the last year, other than the fact that attacks continue to rise. In a report chock full of interesting data points (and some truly creative prose), federal IT professionals will be most interested in how the government compares with the other major sectors.
Glancing at a graphical breakdown by sector, two trends become immediately apparent: The public sector is taking the brunt of crimeware attacks and government and the health care sectors are fighting many of the same battles.
Download: Verizon 2016 Data Breach Investigations Report
“When you look at the public sector, the first thing that jumps out is the sheer number of incidents,” Mark Spitler, the report’s lead author, told Federal Times, noting the 47,237 incidents reported. “This is not an indictment on the public sector,” he added, as public entities tend to have much stricter reporting requirements, which leads to more publicly available data.
Spitler noted the size and breadth of government operations also lead to more incidents. For instance, many agencies deal with highly sensitive information about citizens, like Social Security numbers, which makes them a prime target for hackers but also ups the ante in situations like accidental leakage, such as an employee forgetting a laptop on a bus.
And while non-malicious incidents topped the list for the public sector — accounting for 24 percent of incidents — misuse of privileged access (22 percent), stolen assets (20 percent) and crimeware (16 percent) were close behind.
When it comes to crimeware — a category that only significantly affected the public and transportation sectors — Spitler said that category was used as a “catch-all” for malware that didn’t fit elsewhere. These incidents would include hacks that weren’t motivated by espionage — either governmental or corporate — but also aren’t accidental.
Reported incidents from the public and health care sectors map almost perfectly, especially when compared to the other sectors. Like government, health care organizations’ biggest concerns are stolen assets (32 percent), privilege misuse (23 percent) and miscellaneous errors (18 percent).

These similarities weren’t a surprise to Spitler and his team.
“It has a lot to do with the reporting requirements,” he explained. “We get so much more information, especially around lost or stolen devices,” which private companies aren’t required to self-report.
For all other sectors, denial-of-service attacks were the predominant threat, accounting for as much as 99 percent of incidents in the entertainment sector.
In government, denial-of-service incidents only added up to 1 percent of the total. However, with more than 47,000 incidents reported, “1 percent is a significant value,” Spitler noted.
Spitler said he wasn’t sure exactly why the percentage was so low for the public sector, saying they “just haven’t seen it in our data.” And it’s not that DOS attacks aren’t taking place, he added, the other attack vectors are just “flooding out denial-of-service” by their sheer numbers.
Overall, there was little variance for public sector results in this year’s report as compared to year’s past.
Once again, Spitler credited this to the structured reporting mandates government bodies have to follow.
“With public, we’ve maintained a very consistent contributor set,” he said. “The incidents and the breaches that we’ve seen within that have maintained the same level — nothing really show-stopping.”




