Home Press Releases Nearly 40 Percent of Large Or ...

Press Releases by CGIDir

Nearly 40 Percent of Large Organizations Don't Monitor Databases for Suspicious Activity – Or Don’t Know If They Do

June 4, 2007; 05:06 AM
Application Security, Inc., today announced from the Gartner IT Security Summit the results of a Ponemon Institute survey underscoring the serious challenges organizations face in securing sensitive data. With more than 150 million data records exposed in the past two years, the survey also highlights an organizational disconnect between the realization of the threat and the urgency in addressing it.

Conducted by one of the foremost authorities on data security and privacy, the Ponemon Institute surveyed 649 respondents in corporate information technology (IT) departments worldwide. Respondents averaged more than seven years of experience in the information security field; more than 60 percent work within corporate CIO or CTO departments.

In an increasingly precarious balancing act, organizations are wrestling with how to protect data from misuse by external and internal forces while expanding access to the same data to drive business initiatives. Highlighting these challenges, the survey reveals that:

  • Forty percent said their organizations dont monitor their databases for suspicious activity, or dont know if such monitoring occurs. Notably, more than half of these organizations have 500 or more databases and the number of databases is growing.
  • Trusted insiders ability to compromise critical data was cited as the most serious concern with 57 percent perceiving inadequate protection against malicious insiders and 55 percent for data loss by internal entities.
  • Seventy-eight percent believe that databases are either critical or important to their business. Customer data represents the most common data type contained within these databases.
  • Customer/consumer and employee data rank 3rd and 4th respectively in regard to organizations prioritization of what must be protected.

Data can be monetized quickly and the bad guys know it, said Larry Ponemon, chairman and founder of the Ponemon Institute. Organizations that fail to protect their data effectively are proving easy targets often left to contend with considerable damage to their reputations and financial results.

Unless organizations directly protect their databases, everything else theyre doing for data security is on shaky ground, said Toby Weiss, president and CEO of Application Security, Inc. As States and the Federal government grapple with how to compel organizations to protect consumer privacy, leading organizations are looking inward to protect data where it lives. Responsible organizations are increasingly seeking to enhance security, mitigate risk and address key compliance concerns as part of a comprehensive approach to addressing data governance within their existing IT infrastructure.

The full report is available at: -Database-Security-Study-Sponsored-by-Application-Security-Inc.pdf.

About the Ponemon Institute

The Ponemon Institute© is dedicated to advancing responsible information and privacy management practices in business and government. To achieve this objective, the Institute conducts independent research, educates leaders from the private and public sectors and verifies the privacy and data protection practices of organizations in a variety of industries.

About the Gartner IT Security Summit

The Gartner IT Security Summit hits the critical spot between strategic planning and tactical advice. Gartner analysts, industry experts and IT security practitioners deliver unbiased, realistic analysis on the current state of IT security, as well as an independent overview of the market over the next 12-18 months. Covering the depth and breadth of topics comprising IT security today, the Gartner IT Security Summit has a single objective: to bring to light the repeatable, manageable security processes needed to address today's and tomorrow's threats. Additional information is available at

About Application Security, Inc.

Application Security, Inc. ( is the leading global provider of database security solutions for the enterprise. Application Security, Inc.s products the industrys only complete database security solution proactively secure database applications across databases around the world. Application Security, Inc. delivers up-to-date database protection that minimizes risk and allows organizations to confidently connect with customers, partners, and suppliers.



Related Resources

Other Resources

image arrow