More companies reporting cybersecurity incidents

At least 19 financial institutions have disclosed to investors in recent weeks that their computers were targets of malicious cyber­assaults last year, a sign of growing openness among corporations about the breadth of cybersecurity incidents plaguing the private sector.

In their annual financial reports to the Securities and Exchange Commission, major banks such as Bank of America, Citi, Wells Fargo and JPMorgan Chase, along with smaller institutions, have reported that their systems were hit with computer disruptions or intrusions.

Special Report: Zero Day - The Threat in Cyberspace

Latest from National Security

U.S. acknowledges four Americans killed in counterterrorism missions

U.S. acknowledges four Americans killed in counterterrorism missions

Attorney General Eric Holder informs Congress of deaths one day before major speech by President Obama.

Man tied to Boston bombing suspect killed in encounter with FBI, others

Man tied to Boston bombing suspect killed in encounter with FBI, others

Ibragim Todashev implicated himself and Tamerlan Tsarnaev in a triple homicide two years ago, officials say.

Fine Print: For Senate panel, there’s power and limitations on Syria

Fine Print: For Senate panel, there’s power and limitations on Syria

Despite passage of bill calling for aid, Foreign Relations Committee should watch its step on pushing Obama.

Iran paving over suspected nuclear-related testing site, U.N. agency says

Iran paving over suspected nuclear-related testing site, U.N. agency says

Officials believe the facility may have been used to test a special kind of detonator used in atomic weapons.

Judge apologizes for lack of transparency in leak probe

Judge apologizes for lack of transparency in leak probe

Leak-investigation documents related to Fox reporter James Rosen were erroneously kept under seal.

Almost all reported that they were targeted in last year’s highly publicized “distributed denial of service attacks” (DDOS) — efforts to disrupt access to Web sites by barraging servers with computer traffic. The assaults, which are ongoing, made headlines in the fall when U.S. officials said they believed they were launched by the Iranian government in retaliation for sanctions imposed because of Tehran’s nuclear program.

The disclosures are significant in that for years, companies, including banks, have been loath even to acknowledge that they have been victims of such incidents.

But it appears that SEC guidance issued in October 2011 making clear that companies need to report significant computerized theft or disruption, combined with greater public attention to the issue, is forcing more disclosure. Also, the fact that the banks hit by the DDOS attacks have been named in media accounts has made ignoring them more difficult.

Fifth Third Bank in Cincinnati, for instance, disclosed it had endured a DDOS attack early last year. “We did it as a way to be transparent,” said Debra DeCourcy, a bank spokeswoman. “If there is something else positive that can be gained from that, it’s all the better.”

DDOS incidents do not involve penetrating networks, but the assaults that washed over the banking industry in the fall were of such force and duration that banks have spent millions of dollars shoring up their security, industry officials said. Some analysts estimate that the collective cost comes to hundreds of millions of dollars.

The disruptions also got the attention of the White House and the national security community, which have been trying to help the private sector better handle such incidents. President Obama recently signed an executive order aimed at helping companies in critical sectors shore up their network security. Improved sharing of threat data between the government and companies is considered crucial to that effort.

Such corporations as eBay, LinkedIn, Level 3 Communications, Chesapeake Energy and AT&T have admitted they suffered intrusions or disruptions last year. “It’s almost naive for most large companies in the critical infrastructure sector to say that they aren’t subject to attack,’’ said Paul Smocer, president of BITS, a financial services trade organization.

The stepped-up disclosure, he said, “brings greater awareness, greater diagnosis and a desire to find a stronger cure” for system vulnerabilities.

Even with the new openness, security experts say the real scale of companies affected by cybersecurity incidents is much larger.

Loading...

Comments

Add your comment
 
Read what others are saying About Badges