Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • The Year in Breaches: Can It Get Any Worse? current page
Link copied

The Year in Breaches: Can It Get Any Worse?

Sep 21, 2015
Author:
Dave shackleford
Dave Shackleford
Cybersecurity Expert and Founder of Voodoo Security
Blog banner default
The Year in Breaches: Can It Get Any Worse?
Dave shackleford
Dave Shackleford
Cybersecurity Expert and Founder of Voodoo Security

2015 has seen a staggering number of high profile data breaches and attacks, covering almost every major industry segment imaginable. There have been several major attacks on healthcare organizations, resulting in medical and patient data stolen. The Hacking Team breach exposed numerous 0-day vulnerabilities, and the LastPass and Kaspersky breaches demonstrated that security software companies aren't immune to attacks, either. The OPM breach has some of the most significant implications for long-term identity theft across government and military sectors, and the Ashley Madison breach and subsequent data exposure has led to a number of scandalous revelations about what people are really doing in their spare time.

The pace of these breaches is accelerating, and the impact on companies, government agencies, and society as a whole is getting worse. Marriages are wrecked, people are committing suicide, identities are being stolen, and the level of trust in the Internet and software overall has never been lower. We have to ask ourselves in the security industry what we’re doing wrong, and how these attackers are able to break into our environments and steal data so readily and easily.

For those in the information security industry for any length of time, cynicism is high. We’ve pushed for more strenuous application of controls, more monitoring and response tools and capabilities, and better integration of security into the very fabric of IT for many years, often with little to show for it. Today, it’s tempting to say “I told you so” to those who ignored or overlooked security controls for so long. However, cynicism alone won’t really get us anywhere, and it’s time to start looking for new options that can help convince stakeholders to take action, as well as prevent and detect these attacks much more effectively than in the past.

The attackers are innovating quickly, and the pace of security innovation isn’t keeping up. Our tools are getting better, and more people are listening, but we still have deep foundational problems that just won’t go away. People still insist on clicking things. I have actually had great success in pen tests convincing people that they were about to view the BEST CAT VIDEOS EVER upon clicking a link. We don’t do a good job of patching and locking down systems, and we have too many legacy systems and applications to count, many of which are incredibly vulnerable. People still don’t choose good passwords, and this extends all the way to the most privileged users in many organizations. What gives? How can we be expected to prevent or detect really sophisticated attacks when the simple issues are still plaguing us?

We’ve got a lot of work to do, unfortunately, and turning the ship will take some time. We’re really battling ingrained behaviors and cultural issues that will only change when enough damage has been done to really get the majority of people and organizations concerned. So will the problems keep getting worse? I think the answer is “yes”, and we’ll probably be facing this uphill battle for a while longer. Can we do anything about it? Most definitely, join me in this webinar and we’ll explore some ways to accomplish this.

Want to learn more? Watch Now

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Achieving Security at the Service Desk Without Impacting Productivity
    Jun 26, 2018 Achieving Security at the Service Desk Without Impacting Productivity
    Blog
    1m
  • How to Mitigate the Windows DogWalk Vulnerability
    Aug 15, 2022 How to Mitigate the Windows DogWalk Vulnerability
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.