Live data from Hacker News

2024 Verizon Data Breach Investigation Report [pdf]

verizon.com

31–40 of 51 posts

Re: 2024 Verizon Data Breach Investigation Report [pdf]

#32
What is up with the glib tone featured throughout this document? To cite a few examples (there are many more):

Page 11: "Hello, friends, and welcome to the “Results and analysis” section."

Page 15: "Hey, you, don’t skip this section this year! We know we keep repeating, “It’s always external criminals wanting your money” alongside dated pop culture references, but we have some interesting data points to discuss this year. Does this mean External actors are not the most prevalent? No, of course they are, silly. But since we got your attention, please read on."

Page 37: "In the cybersecurity world, or “the cyber biz,” as we call it, we certainly love our catchy terminology. Terms such as whaling, smishing, quishing, tishing, vishing, wishing, pharming, snowshoeing and plain old phishing are ever-present in the Social Engineering pattern. This makes sense because there are a lot of vectors on which we need to educate our employees and end users, and we’re positive that in another five years, there will be new ones that we will have to add to our list."

Re: 2024 Verizon Data Breach Investigation Report [pdf]

#33

Submitted title is very misleading. The linked paper is called “ 2024 DBIR Data Breach Investigations Report” and is not about a Verizon breach.

Verizon publishes the DBIR every year. The full name is the Verizon Data Breach Investigation Report.

Re: 2024 Verizon Data Breach Investigation Report [pdf]

#34

This is actually a really solid high-level report. Very well-written. Frankly, it blows my mind that it was made by a company with such infuriatingly asinine, incompetent, and ineffective support processes. I'll bet a non-zero quantity of hiring managers that have been burned by Verizon's support have subconsciously passed over talented candidates coming from there.

Every large organization has good parts and bad parts. What most people forget is a company is just a collection of people. When you have 1,000, 10,000, 100,000, etc. employees, they can't all be good, bad, etc.

Re: 2024 Verizon Data Breach Investigation Report [pdf]

#35

Earlier quoted context omitted.

> since it's hard to prove to the bean counters that an attack will happen with reasonable certainty on a given system in the next quarter, good luck getting resources and priority for mitigations beyond the usual. False. Companies are now liable to report breaches to the SEC and steps taken to remediate. As I've mentioned several times on HN before, heads do roll and C-Suite does care about security posture now that…

> Companies are now liable to report breaches to the SEC and steps taken to remediate. I'm looking at UnitedHealth's stock price over the last year. The theft happened in February. There was a dip; it's already recovering from that. The market doesn't particularly care about those disclosures, it would seem.

Investors do care. After all, if a company does not improve its security, its customers will leave.

Re: 2024 Verizon Data Breach Investigation Report [pdf]

#36

Earlier quoted context omitted.

Stocks are not the "holy grail decide all" when much of UHG and Optum's leadership is in front of Congress as we speak during an election year and with significant liabilities due to potential breaches of contract by failing to produve billing to their customers. Go on LinkedIn and take a look at who's on the CISO org and below at UHG and Optum today - in 6 months 60% of them will no longer list either as their emplo…

Being dragged in front of Congress on anything related to a computer is not a big deal; if it were, Mark Zuckerberg would not be CEO of Meta. The liabilities will be played out in court over the next decade, and you'll possibly see some legislation passed over that time period limiting liability in these situations, because how can we possibly expect these companies to deliver value to shareholders while shouldering…

You stated "Being dragged in front of Congress on anything related to a computer is not a big deal". I do not think you understand how the United States works. The United States government can destroy a company if it wants to. A good example is TikTok. Angering senators, or representatives is a very dangerous thing to do. If you want to see the results, look at the legal problems Google is having, or the problems Microsoft had in the late 1990s and early 2000s.

Re: 2024 Verizon Data Breach Investigation Report [pdf]

#37

Breaches by attackers will continue until it becomes prohibitively expensive or dangerous for the attackers to do what they do. This isn't something companies can do; it takes a government to do that. Until then, it's a great way to squeeze crypto out of some company to make up for the fact that your country is under sanctions tied to the US Dollar, and since it's hard to prove to the bean counters that an attack wil…

> until it becomes prohibitively expensive or dangerous for the attackers to do what they do.

We used to hang thieves. We still had theft.

Re: 2024 Verizon Data Breach Investigation Report [pdf]

#38
post #9

Kelly Shortridge's post about the DBIR is great https://kellyshortridge.com/blog/posts/shortridge-makes-sens...

I was thoroughly entertained by this read, thanks for the rec

The DBIR is an interesting dataset in that it only covers breaches that have been covered by the media.

It does not include the vast majority of breaches that happen every year and are reported to federal and state regulatory bodies or as posted to cybercrime / ransomware sites.

One of the coolest things is that this process though flawed is transparent and semi-open to the public.

The dataset and the underlying process for which events are selected takes place in the open on GitHub.

Kudos to their commitment to open source.

https://github.com/vz-risk/VCDB

Re: 2024 Verizon Data Breach Investigation Report [pdf]

#39

This is actually a really solid high-level report. Very well-written. Frankly, it blows my mind that it was made by a company with such infuriatingly asinine, incompetent, and ineffective support processes. I'll bet a non-zero quantity of hiring managers that have been burned by Verizon's support have subconsciously passed over talented candidates coming from there.

Every large organization has good parts and bad parts. What most people forget is a company is just a collection of people. When you have 1,000, 10,000, 100,000, etc. employees, they can't all be good, bad, etc.

Sure, but few orgs have as much surface area with such a ridiculously bad service. And I said subconsciously. I really doubt anyone would deliberately refuse to hire a good candidate because they worked for a company with shit customer service. But our thought processes are influenced a whole lot more by subconscious factors than we like to think they are. People that think their thought process is entirely logical and deliberate usually just lack the introspection to see how wrong they are. It's basically the core tenet of modern advertising.

Re: 2024 Verizon Data Breach Investigation Report [pdf]

#40
post #13

Direct link - https://www.verizon.com/business/resources/T5d2/reports/2024... From the title, it seemed that Verizon had published a postmortem of a recent data breach incident they had

the "direct link" expires and becomes the page attempting to harvest your personal info, unfortunately.
Post reply on HN