Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Trusteer reports on the State of Targeted Attacks
Study & Research

Trusteer reports on the State of Targeted Attacks

ISBuzz TeamBy ISBuzz TeamDecember 9, 2013Updated:July 15, 20243 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
targeted attacks
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Endpoint cybercrime prevention specialist Trusteer, an IBM company, has announced the results of a recent study on the State of Targeted Attacks.  It took into consideration the feedback from over 750 IT and IT security practitioners who have involvement in defensive efforts against APTs launched at their organisations.  Some key findings include:

 

·         Top consequences of advanced attacks are IT downtime, business interruption, exfiltration of sensitive data and theft of intellectual property

·         51% felt their organisations do not effectively detect advanced threats

·         87% said company execs were not aware of APT threats

·         93% said malware was the source of an APT attack

·         68% said zero day attacks are their organisations’ greatest threats

·         Java and Adobe Readers pose the most risk

·         Better technology controls are needed

“While this study shows that organisations are becoming much more aware of targeted attacks more so than a few years ago, it’s also become apparent that current technologies just aren’t working well enough and are being bypassed by targeted attacks,” said George Tubin, senior security strategist at Trusteer, an IBM company.  “It indicates a need for better technology, but at the same time IT and security staff aren’t given the budget they feel they need to support this and that needs to change.”

The top six approaches to detecting APTs are: intrusion detection systems (IDS), anti-virus (AV)/anti-malware software, intrusion prevention systems (IPS), managed or outsourced security provider, event correlation software and network or traffic intelligence software.  According to the study, intrusion detection systems came out on top, with 85% of respondents saying that this was the method that most helped them detect an APT.  Yet, it took an average of 225 days to detect an APT that had been launched against their organisations and a staggering 63% claimed to have discovered an APT completely by accident.

The study also found that, according to almost 80% of the respondents, Java is an organisation’s most serious vulnerability and the most difficult application when it comes to ensuring all security patches have been fully implemented in a timely manner.  Seventy three percent of respondents even claimed that “If I could, I would discontinue using Java;” but 55% said it was nearly impossible to replace it with a less risky alternative.  Adobe Reader was a close second and considered more difficult to patch than Windows, Flash, Chrome, Android, Mac OSX, Safari, Firefox, Internet Explorer and Microsoft Word.

The figures here are interesting because Android has seen a significant amount of press lately pointing to its vulnerabilities. When in practice, IT and security professionals actually find Java, Adobe Reader, Windows, Flash and Chrome all more difficult than Android to secure.  And despite the risks, 75% of those surveyed said their companies continued to operate one or more of these applications in the production environment knowing that vulnerabilities exist and a viable security patch is unavailable.

The survey also highlights how IT and IT security professional believe their organisations are unprepared to deal with advanced threats, with 68% citing they have inadequate budget resources and 65% saying that security personnel were inadequate.  On average, nine APT related incidents are seen in a year and over 70% of respondents admitted that exploits and malware evaded their IDS and AV solutions.

Exfiltration of confidential information is often given the most importance in terms of consequences of advanced targeted attacks, but for IT professionals, the most experienced consequence  is IT downtime and business interruption.  Interestingly, 17% had been issued data breach fines as a result of an APT attack.

To read the full report please visit:

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}