Attacks on critical infrastructure IT systems are widespread and growing in frequency, and could cost over US$6m (A$6.7m) a day on average, according to a detailed new report from security giant McAfee launched today.
In the Crossfire: Critical Infrastructure in the Age of Cyberwar is one of the most in-depth reports of its kind in the security area. McAfee surveyed over 600 professionals responsible for critical infrastructure protection across seven sectors in 14 countries, and commissioned think-tank the Centre for Strategic and International Studies to conduct additional qualitative research to compile the report.
Nearly 60 percent of respondents believe that foreign governments have been involved in cyber attacks against critical infrastructure in their country, while a third had actually suffered large-scale distributed denial-of-service attacks several times a month, most of which had an impact on operations.
In addition, a third believe that the threat to critical infrastructures is growing, and two-fifths expect a major security incident within the next year. Infections with viruses or malware was the most commonly reported form of attack, while "theft-of-service" was perceived as the most common motivation for attack. The most common target is financial information.
Yet many countries appear woefully unprepared for such attacks, according to the report. Over a third described their resources as 'inadequate' or 'somewhat adequate'.
McAfee's chief technology officer, George Kurtz, said that much of the problem lies with the fact that most critical infrastructures are run by the private sector, so the motivation for securing them is not as high as it should be.
"The private sector is financially motivated, and governments are motivated by security and the national interest, and these two sides can't always be reconciled," he argued in an interview with V3.co.uk.
"One way of going forward is if the government could provide tax incentives to critical infrastructure companies to secure and upgrade their systems. Governments also need to hold these firms accountable and be prescriptive in the security measures they need to adopt. They need to find a way of clearly measuring security and risk equally across departments."
The report comes just a fortnight after it was revealed that Google and at least 20 other firms had been hit by a sophisticated and possibly state-sponsored attack originating from China.
Critical infrastructures under attack, warns McAfee
By
Phil Muncaster
on Jan 29, 2010 9:25AM

Got a news tip for our journalists? Share it with us anonymously here.
Partner Content

Channel can help lead customers to boosting workplace wellbeing with professional headsets

Build cybersecurity capability with award winning Fortinet training from Ingram Micro

Tech For Good program gives purpose and strong business outcomes

How NinjaOne Is Supporting The Channel As It Builds An Innovative Global Partner Program

Kaseya Dattocon APAC 2024 is Back
Sponsored Whitepapers
-1.jpg&w=100&c=1&s=0)
Stop Fraud Before It Starts: A Must-Read Guide for Safer Customer Communications

The Cybersecurity Playbook for Partners in Asia Pacific and Japan

Pulseway Essential Eight Framework

7 Best Practices For Implementing Human Risk Management

2025 State of Machine Identity Security Report