OMAHA, NE--(Marketwired - Apr 19, 2016) - Solutionary, an NTT Group security company (NYSE: NTT) and leading cybersecurity services provider, is pleased to announce the release of the annual Global Threat Intelligence Report (GTIR). NTT Group has expanded its view of the threat landscape to include findings from key partners -- Lockheed Martin, Wapack Labs, Recorded Future and the Center for Internet Security -- to analyze the attacks, threats and trends from the previous year. The 2016 GTIR is the most comprehensive report to date, pulling information from 24 security operations centers, seven R&D centers, 3.5 trillion logs, 6.2 billion attacks and nearly 8,000 security clients across six continents.
The 2016 GTIR gives security personnel and decision makers the information they need to enable their organizations to disrupt attacks. Practical application of a comprehensive, integrated solution and strategy will not only enable efficiency and effectiveness, but also support the security life cycle of the entire organization.
To achieve this goal, this year's GTIR identifies controls (based on the Center for Internet Security's Critical Security Controls) that can be effective at each stage of the Lockheed Martin Cyber Kill Chain®. Organizations that have implemented controls at each stage of the Kill Chain have an increased ability to disrupt attacks. The report also includes a breakdown of a case study in a "Practical Application of Security Controls to the Cyber Kill Chain."
Key findings from the report include:
Incident Response and Case Studies
- Trend data from incident response activities illustrates on average only 23 percent of organizations are capable of responding effectively to a cyber incident. 77 percent have no capability to respond to critical incidents and often purchase support services after an incident has occurred.
- Activity related to the Reconnaissance phase of the Lockheed Martin Cyber Kill Chain (CKC) accounted for nearly 89 percent of all log volume. These logs accounted for approximately 35 percent of escalated attack activity, making Reconnaissance the largest single element in the CKC.
- Spear phishing attacks accounted for approximately 17 percent of incident response activities supported in 2015. In many cases, the attacks targeted executives and finance personnel with the intent of tricking them into paying fraudulent invoices.
Geographic and Vertical Market Trends
- The retail sector experienced the most attacks per client. Retail was followed by the hospitality, leisure and entertainment sector, then insurance, government and manufacturing. While the finance sector showed the highest volume of attacks overall, on a per-client basis, retail clients experienced 2.7 times the number of attacks as finance.
- NTT Group observed an 18 percent rise in malware detected for every industry other than education. NTT clients from the education sector tended to focus less on the more volatile student and guest networks, but malware for almost every other sector increased.
Vulnerabilities, Attacks and Exploitation
- Nearly 21 percent of vulnerabilities detected in client networks were more than three years old. Results included vulnerabilities from as far back as 1999, making them more than 16 years old. This is for vulnerabilities with a Common Vulnerability Scoring System (CVSS) score of 4.0 or higher.
- DoS/DDoS attack volume fell 39 percent from levels observed in 2014. Implementation of better mitigation tools, along with fewer attacks, combined for a drop in detections of denial of service (DoS) and distributed denial of service (DDoS) activities. But, extortion based on the victim's paying to avoid or stop DDoS attacks became more prevalent.
- All of the top 10 vulnerabilities targeted by exploit kits during 2015 are related to Adobe Flash. In 2013, the top 10 vulnerabilities targeted by exploit kits included one Flash and eight Java vulnerabilities. That has changed as new Java vulnerabilities have dropped steadily since 2013. The number of publicized Flash vulnerabilities jumped by almost 312 percent over 2014 levels.
This year's GTIR provides actionable intelligence, guidance about what attackers are doing, and comprehensive security controls designed to disrupt attacks. Controls recommended in this report will contribute to an organization's survivability and resiliency in the face of an attack.
To download the full report, please visit: https://www.solutionary.com/2016-GTIR
Solutionary, an NTT Group Security Company (NYSE: NTT), is the next generation managed security services provider (MSSP), focused on delivering managed security services, professional security services and global threat intelligence. Comprehensive Solutionary security monitoring and security device management services protect traditional and virtual IT infrastructures, cloud environments and mobile data. Solutionary clients are able to optimize current security programs, make informed security decisions, achieve regulatory compliance and reduce costs. The patented, cloud-based ActiveGuard® service platform uses multiple detection technologies and advanced analytics to protect against advanced threats. The Solutionary Security Engineering Research Team (SERT) researches the global threat landscape, providing actionable threat intelligence, enhanced threat detection and mitigating controls. Experienced, certified Solutionary security experts act as an extension of clients' internal teams, providing industry-leading client service to global enterprise and mid-market clients in a wide range of industries, including financial services, health care, retail and government. Services are delivered 24/7 through multiple state-of-the-art Security Operations Centers (SOCs).