Walt Conway has some interesting commentary [treasuryinstitute.org] on the recently released Verizon data breach report [verizonbusiness.com].
All the valuable PCI compliance insight aside, I found the statistics on the prevalence and value of targeted attacks to be especially interesting. We are frequently engaged to perform social engineering exercises for our clients, primarily to help them stress the importance of security policies, procedures, and communication to their employees.
While our generic email campaigns typically fool a few of the overly curious or too-quick-to-click crowd, the more informed (targeted) phishing campaigns are overwhelming effective to the point that we often need to reassure our clients that the world is not ending. Unfortunately, this report highlights the fact that targeted attacks are not just elements of security company sales talk.