Information Security:
2016 in Review
SearchInform experts prepared an annual research on the information security level in the companies of the CIS countries. The data for the research was collected during the series of the Road Show SearchInform 2016 conferences ‘Insider: Detect and Neutralize’. The event gathered 3,057 information security experts and other experts from 23 CIS cities.
COMPANY PROFILE
Sphere:

technology



health care




financial sphere

transportation



Staff:
DATA LEAKAGES AND
THEFT ATTEMPTS
confidential data leakages in 2016.
This rate is 3% less
than it was last year
prevent data theft attempts
CIS COMPANIES MOSTLY USED TO LOSE:

clients and deals

secret

information

data

about partners

accounting
PORTRAIT OF INSIDER
In 2016, it was mostly common employees (52%) who were trying to steal confidential data. As a comparison: last year, around 30% of thefts were committed by managers.

employees


economists and
financial experts


assistants,
secretaries

administrators

of their position are in the risk group: while leaving
the job, some of them steal information to take revenge,
others steal it to gain a new employer’s favour.
caught their ex-employees
in data theft
WHO PROTECTS
At present, the rate of information security experts, who are in charge of information security, has been steadily increasing. And in 2015, this rate amounted only up to 22%.



security departments have
field-specific education
HOW THEY PROTECT
do not secure their sensitive data of the CIS companies do not secure their sensitive data
WHAT THEY PROTECT
In 2016, more CIS companies started monitoring documents sent to print: this rate increased by 3%. Otherwise, companies started paying less attention to popular data channels:






Some companies consider that the best way to prevent data leakages over particular channels is to block them. 53% of the companies do so. Among the channels, cloud services (blocked by 5% of the respondents), entertainment websites (5%) and anonymizers (1%) are of the least concern to employers. The top three channels to be blocked are



channels blocking won’t stop
an insider, and leave all channels open,
choosing rather to control them
EMPLOYEES
AND INFORMATION SECURITY
75% of the CIS companies instruct on information security rules. Last year, employees in 72% of the companies were instructed on information security.
of the CIS companies suggest that their employees sign
a non-disclosure agreement.
What penalties are applied to an employee who let a breach occur?
What penalties are applied to an employee who let a breach occur?
* Other variants: limiting access to information, dismissal after a second incident,
disciplinary penalties by the management decision, etc.
LIABILITY OF PARTIES
In 2016, the CIS companies started informing more often about incidents. A year back, it was 11% of the companies that used to do this.
HOW IMPORTANT IS PROTECTION??
of the companies assess importance
of confidential data protection with
a score of 10 out of 10 points
16% - 5 out of 10 points
14% - 8 out of 10 points
12% - 7 out of 10 points