Survey: Removable Media Devices Overtake Web Viruses As Top Security Threat

Removable media devices now present the biggest threat to corporate security, according to research conducted at this year’s InfoSecurity Europe conference in London. However, the research conducted by Centennial Software found that four out of five companies do not have effective measures in place to protect against the threat the devices can pose.

More than 43 percent of those questioned have no controls whatsoever in place to manage removable media devices, 27.4 percent leave it to the manager’s discretion, and 8.6 percent have taken the drastic step of introducing a company-wide ban. Only 16.4 percent use endpoint security software to manage the potential risks effectively. This is despite a raft of recent media stories surrounding insider data theft using removable media.

But companies are not ignorant of the risk. In a significant development for Centennial’s annual “Security Attitudes Survey”, 2007 saw removable media devices rated by 38.4 percent of respondents as the top security issue facing their organization. The risk has taken over from Web viruses (23.7 percent) and malware/spyware (22.3 percent) for the first time.

While more company officals in 2007 said they do include removable devices in the acceptable use policies (63.4 percent versus 54.5 percent last year), with more USB sticks than ever in use on the network (65.6 percent regularly use USB sticks, up from 36.3 percent last year), it’s not enough to rely on a policy, according to Centennial.

“It’s long been recognized that human error leads to the majority of information security problems,” said Matt Fisher, vice president at Centennial. “Leaving the use of removable devices at the discretion of staff exacerbates the risks posed by these devices -- especially when a minority of employees may have reasons for wanting to steal or compromise data.

“A larger proportion of companies than last year said they had no controls for managing removable devices in place -- 43.3 percent versus 38.5 percent last year. This is an alarming trend; if organizations recognize the risks of data loss, theft and damage from USB sticks, smartphones and MP3 players, they need to take action to manage the threat and protect their data.”

The third annual “Security Attitudes Survey” was conducted over the three days of Infosecurity Europe and was completed by more than 370 mid and senior level IT managers.

Featured

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure.

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings.

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file.