Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Digesting the Verizon Data Breach Investigations Report 2017 current page
Link copied

Digesting the Verizon Data Breach Investigations Report 2017

Oct 20, 2017
Author:
Andrew Avanessian
Blog banner default
Digesting the Verizon Data Breach Investigations Report 2017
Andrew Avanessian

The much anticipated 2017 Data Breach Investigations Report from Verizon was launched this week and once again it highlights some interesting and concerning security trends.

This is the tenth year the Verizon Data Breach Investigations Report (DBIR) has delved into the world of cyber security as it pulls together a comprehensive picture of cyber crime today.

So, what does this year’s DBIR tell us?

Unmasking the culprits

Of the 65 organizations Verizon surveyed, around 75% of breaches were perpetrated by outsiders or organized criminal groups (51%). However, the enemy within also can’t be ignored. Verizon found that 25% of breaches resulted from internal actors, malicious or otherwise. In 60% of these cases, insiders absconded with data in the hope of converting it into financial gain in the future.

Who is affected?

Financial organizations remained the main target for cyber crime. 24% of breaches affected the financial services sector. Elsewhere healthcare and retail both ranked towards the top of the hackers hit list, representing 15% of breaches each.

Means and methods

Verizon found the overwhelming majority of hacking-related cases related to stolen or weak passwords and over half of breaches (51%) included some form of malware. One of the standout statistics in this area was that 43% of breaches originated via social media, underlining how social engineering has become an effective weapon in the cyber criminal’s arsenal.

7.3% of users across multiple data contributors were successfully phished – whether via a link or email attachment. In a typical company with over 30 employees, around 15% of users who fell victim once also took the bait a second time.

What else do we know?

This year’s DBIR also uncovered how email attachments are proving a fruitful tactic. 66% of malware was installed via malicious attachments.

Key learnings

From my own experience, and when we analyze many of today’s data breaches we often find a common pattern, or we can point to a common set of mistakes. Though the approach cyber criminals are taking is diversifying and becoming more sophisticated, the overall strategies remain unchanged. In fact, Verizon found that 88% of breaches in this year’s report fall into nine patterns it first identified back in 2014.

Unfortunately, many organizations are still failing to take appropriate action to address the gaps in their defenses. There remains a certain level of apathy which seems to be harder to eradicate than we’d like, as Verizon themselves identify, “No one thinks it’s going to be them. Until it is”.

We need to change that mentality, we need to move away from reacting to data breaches to proactively defending against them with the right mix of technologies that are fit for purpose, not outdated AV or firewalls. No matter what size your business, if you don’t have solid security foundations in place it will collapse.

You can learn more about how Defendpoint can proactively secure your business and defend against data breaches by visiting https://www.avecto.com/defendpoint or get in touch with one of our tech consultants for a software demo.

Latest Posts
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
  • A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    May 26, 2026 A Security Researcher’s Guide to Understanding Copilot Studio AI Agents
    Blog
    3m
  • How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    May 21, 2026 How to Secure Cloud-Native Infrastructure at Scale and Speed: A Conversation with Madhu Adireddi
    Blog
    5m
  • Cybersecurity as a Boardroom Priority for Major African TelCos
    May 12, 2026 Cybersecurity as a Boardroom Priority for Major African TelCos
    Blog
    8m
  • Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    May 11, 2026 Geopolitics and Cybersecurity: Why Attackers Go After Identities and Privileged Access First
    Blog
    4m
Related
  • How to Detect Session Hijacking Before It’s Too Late: A Data Science & Behavioral Modeling Approach
    May 14, 2025 How to Detect Session Hijacking Before It’s Too Late: A Data Science & Behavioral Modeling Approach
    Blog
    11m
  • Make Privileged Password Management Painless for IT Admins
    Sep 18, 2018 Make Privileged Password Management Painless for IT Admins
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.