Welcome!

Agile Computing Authors: Yeshim Deniz, Pat Romanski, ManageEngine IT Matters, Stackify Blog, Liz McMillan

News Feed Item

Une enquête sur la cybersécurité réalisée par l'ISACA révèle qu'une entreprise sur cinq a subi une attaque APT

Plus d'une personne sur cinq participant à une enquête mondiale sur la cybersécurité , réalisée auprès de plus de 1500 professionnels de la sécurité, déclare que son entreprise a subi une attaque APT (« advanced persistant threat »). D'après l'étude réalisée par l'association TI mondiale ISACA, 94 % déclarent que les APT constituent une menace crédible à la sécurité et à la stabilité économique nationales, et pourtant la plupart des entreprises emploient des technologies inefficaces pour se protéger.

Les APT, une tactique d'espionnage visant à voler la propriété intellectuelle, ont fait les gros titres au cours des dernières années pour avoir porté atteinte à des réseaux commerciaux et gouvernementaux majeurs dans le monde entier. Plus de 60 % des personnes interrogées ont indiqué qu'il n'était qu'une question de temps avant que leur entreprise soit ciblée.

Sensibilisation de l'ISACA aux « advanced persistant threats » : Les résultats de l'étude indiquent que 96 % des personnes interrogées se déclarent un tant soit peu familières avec les APT. Bien que ceci soit positif, 53 % déclarent qu'elles ne pensent pas que les APT diffèrent des menaces traditionnelles—ce qui indique qu'elles sont nombreuses à mal les comprendre.

« Les APT sont sophistiquées, furtives et incessantes », a déclaré Christos Dimitriadis, Ph.D., CISA, CISM, CRISC, vice-président international de l'ISACA et chef de la sécurité des informations d'INTRALOT GROUP. « Les cybermenaces traditionnelles se dissipent souvent si elles ne peuvent pas pénétrer leur cible initiale, mais une APT tente continuellement de pénétrer la cible désirée jusqu'à ce qu'elle atteigne son objectif—et, ceci fait, elle peut se déguiser et se transformer si nécessaire, ce qui la rend difficile à identifier ou à stopper ».

Plus de 60 % des personnes interrogées ont indiqué qu'elles étaient prêtes à se défendre contre les attaques APT. Toutefois, les antivirus et les anti-logiciels espions (95 %) et les technologies de périmètre de réseau telles que les pare-feux (93 %) sont les principaux contrôles utilisés par leurs entreprises pour bloquer les APT—un résultat inquiétant, étant donné que les APT sont connus pour éviter d'être pris par ces types de contrôles. L'étude indique que les contrôles de sécurité mobiles, qui sont plus efficaces, sont utilisés nettement moins fréquemment.

« Les APT exigent de nombreuses approches défensives, d'une formation de sensibilisation et d'une modification des accords tiers assurant la protection des fournisseurs, à la mise en œuvre de contrôles techniques », a ajouté Jo Stewart-Rattray, CISA, CISM, CGEIT, CRISC, FACS CP, directeur de l'ISACA et directeur de la sécurité des informations et de l'assurance TI chez BRM Holdich.

L'enquête a également révélé que :

  • 90 % des personnes interrogées considèrent que l'utilisation de sites de réseautage sociaux augmente la probabilité d'une attaque APT concluante.
  • 87 % considèrent que BYOD (« apportez votre propre matériel ») , combiné à l'enracinement ou au déverrouillage de l'appareil, augmentent la probabilité d'une attaque APT concluante.
  • Plus de 80 % déclarent que leurs entreprises n'ont pas actualisé leurs accords de fournisseurs pour se protéger contre les APT.

« Nous ne sommes qu'en février et déjà nous pouvons proclamer 2013 l'année du piratage », a confié quant à lui Tom Kellermann, CISM, conseiller de confiance auprès du gouvernement des États-Unis et vice-président en charge de la cybersécurité chez Trend Micro. « La recherche de l'ISACA révèle que les entreprises sont attaquées et ne le réalisent même pas. Il est nécessaire d'intégrer cette sensibilisation au programme d'études des professionnels de la sécurité pour leur permettre d'élaborer la défense personnalisée dont ils ont besoin pour combattre ces attaques ciblées ».

L'étude ISACA, parrainée par Trend Micro, peut être téléchargée gratuitement sur www.isaca.org/cybersecurity.

À propos de l’ISACA

L'ISACA, qui compte 100 000 membres à l'échelle mondiale, (www.isaca.org) aide les entreprises à inspirer confiance en leurs informations et leurs systèmes, et à en tirer de la valeur. Fondée en 1969, l’ISACA atteste des compétences et des connaissances en technologies de l’information en octroyant les certifications CISA, CISM, CGEIT et CRISC. ISACA a développé le cadre COBIT, qui aide les entreprises à gérer et à gouverner leurs informations et leur technologie.

Twitter : https://twitter.com/ISACANews

Le texte du communiqué issu d’une traduction ne doit d’aucune manière être considéré comme officiel. La seule version du communiqué qui fasse foi est celle du communiqué dans sa langue d’origine. La traduction devra toujours être confrontée au texte source, qui fera jurisprudence.

More Stories By Business Wire

Copyright © 2009 Business Wire. All rights reserved. Republication or redistribution of Business Wire content is expressly prohibited without the prior written consent of Business Wire. Business Wire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

@ThingsExpo Stories
In order to meet the rapidly changing demands of today’s customers, companies are continually forced to redefine their business strategies in order to meet these needs, stay relevant and continue to see profitable growth. IoT deployment and development is integral in this transformation, and today businesses are increasingly seeing the value of investing their resources into IoT deployments. These technologies are able increase ROI through projects such as connecting supply chains or enabling sm...
SYS-CON Events announced today that Progress, a global leader in application development, has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Enterprises today are rapidly adopting the cloud, while continuing to retain business-critical/sensitive data inside the firewall. This is creating two separate data silos – one inside the firewall and the other outside the firewall. Cloud ISVs ofte...
DevOps is often described as a combination of technology and culture. Without both, DevOps isn't complete. However, applying the culture to outdated technology is a recipe for disaster; as response times grow and connections between teams are delayed by technology, the culture will die. A Nutanix Enterprise Cloud has many benefits that provide the needed base for a true DevOps paradigm.
SYS-CON Events announced today that DivvyCloud will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. DivvyCloud software enables organizations to achieve their cloud computing goals by simplifying and automating security, compliance and cost optimization of public and private cloud infrastructure. Using DivvyCloud, customers can leverage programmatic Bots to identify and remediate common cloud problems in rea...
SYS-CON Events announced today that Outscale, a global pure play Infrastructure as a Service provider and strategic partner of Dassault Systèmes, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Founded in 2010, Outscale simplifies infrastructure complexities and boosts the business agility of its customers. Outscale delivers a secure, reliable and industrial strength solution for its customers, which in...
New competitors, disruptive technologies, and growing expectations are pushing every business to both adopt and deliver new digital services. This ‘Digital Transformation’ demands rapid delivery and continuous iteration of new competitive services via multiple channels, which in turn demands new service delivery techniques – including DevOps. In this power panel at @DevOpsSummit 20th Cloud Expo, moderated by DevOps Conference Co-Chair Andi Mann, panelists will examine how DevOps helps to meet th...
SYS-CON Events announced today that Cloudistics, an on-premises cloud computing company, has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Cloudistics delivers a complete public cloud experience with composable on-premises infrastructures to medium and large enterprises. Its software-defined technology natively converges network, storage, compute, virtualization, and management into a ...
SYS-CON Events announced today that A&I Solutions has been named “Bronze Sponsor” of SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Founded in 1999, A&I Solutions is a leading information technology (IT) software and services provider focusing on best-in-class enterprise solutions. By partnering with industry leaders in technology, A&I assures customers high performance levels across all IT environments including: mai...
Every successful software product evolves from an idea to an enterprise system. Notably, the same way is passed by the product owner's company. In his session at 20th Cloud Expo, Oleg Lola, CEO of MobiDev, will provide a generalized overview of the evolution of a software product, the product owner, the needs that arise at various stages of this process, and the value brought by a software development partner to the product owner as a response to these needs.
Most technology leaders, contemporary and from the hardware era, are reshaping their businesses to do software in the hope of capturing value in IoT. Although IoT is relatively new in the market, it has already gone through many promotional terms such as IoE, IoX, SDX, Edge/Fog, Mist Compute, etc. Ultimately, irrespective of the name, it is about deriving value from independent software assets participating in an ecosystem as one comprehensive solution.
SYS-CON Events announced today that EARP will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. "We are a software house, so we perfectly understand challenges that other software houses face in their projects. We can augment a team, that will work with the same standards and processes as our partners' internal teams. Our teams will deliver the same quality within the required time and budget just as our partn...
SYS-CON Events announced today that delaPlex will exhibit at SYS-CON's @ThingsExpo, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. delaPlex pioneered Software Development as a Service (SDaaS), which provides scalable resources to build, test, and deploy software. It’s a fast and more reliable way to develop a new product or expand your in-house team.
SYS-CON Events announced today that Tappest will exhibit MooseFS at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. MooseFS is a breakthrough concept in the storage industry. It allows you to secure stored data with either duplication or erasure coding using any server. The newest – 4.0 version of the software enables users to maintain the redundancy level with even 50% less hard drive space required. The software func...
In his keynote at @ThingsExpo, Chris Matthieu, Director of IoT Engineering at Citrix and co-founder and CTO of Octoblu, focused on building an IoT platform and company. He provided a behind-the-scenes look at Octoblu’s platform, business, and pivots along the way (including the Citrix acquisition of Octoblu).
SYS-CON Events announced today that Systena America will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Systena Group has been in business for various software development and verification in Japan, US, ASEAN, and China by utilizing the knowledge we gained from all types of device development for various industries including smartphones (Android/iOS), wireless communication, security technology and IoT serv...
SYS-CON Events announced today that Outscale will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. Outscale's technology makes an automated and adaptable Cloud available to businesses, supporting them in the most complex IT projects while controlling their operational aspects. You boost your IT infrastructure's reactivity, with request responses that only take a few seconds.
DevOps at Cloud Expo – being held October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's largest enterprises – and delivering real r...
SYS-CON Events announced today that delaPlex will exhibit at SYS-CON's @CloudExpo, which will take place on June 6-8, 2017, at the Javits Center in New York City, NY. delaPlex pioneered Software Development as a Service (SDaaS), which provides scalable resources to build, test, and deploy software. It’s a fast and more reliable way to develop a new product or expand your in-house team.
Five years ago development was seen as a dead-end career, now it’s anything but – with an explosion in mobile and IoT initiatives increasing the demand for skilled engineers. But apart from having a ready supply of great coders, what constitutes true ‘DevOps Royalty’? It’ll be the ability to craft resilient architectures, supportability, security everywhere across the software lifecycle. In his keynote at @DevOpsSummit at 20th Cloud Expo, Jeffrey Scheaffer, GM and SVP, Continuous Delivery Busine...
SYS-CON Events announced today that CollabNet, a global leader in enterprise software development, release automation and DevOps solutions, will be a Bronze Sponsor of SYS-CON's 20th International Cloud Expo®, taking place from June 6-8, 2017, at the Javits Center in New York City, NY. CollabNet offers a broad range of solutions with the mission of helping modern organizations deliver quality software at speed. The company’s latest innovation, the DevOps Lifecycle Manager (DLM), supports Value S...