Identity Theft Market to Eclipse Security Market

According to Nemertes Research, while various groups reported the exposure of 77 million identity records in the first half of 2007, the actual number of exposed identities may be 10 times the reported amount — or close to one billion records per year. The growing identity theft market has created a race between security organizations and thieves, with the value of the identity theft market set to exceed the value of organizations fighting to protect identity information.

Driving identity theft is the “street value” of someone’s personal record. Andreas M. Antonopoulos, Nemertes’ Senior VP and Founding Partner, and Ted Ritter, Nemertes Research Analyst, in a joint report stated that a basic identity record typically trades for $14; the more personally identifiable information in the record, the higher the record’s value. If only five percent of the exposed records are traded, the market for trading identities in 2007 will still exceed $679 million. Conservatively, Nemertes estimates that the net income for an identity trader is close to 80 percent — dwarfing that of established security companies. If the black market was a publicly traded company, it would rank in the Top 5 pure-play security firms in the world with greater annual revenue than Checkpoint and a higher net income than Symantec.

Nemertes found that the overall ID theft market, including goods stolen with false IDs, saw revenue growth of 64 percent last year. Assuming consistent growth, in less than five years, the black market revenues for trading identity records will exceed Symantec’s revenue and in seven years will exceed the combined revenues of today’s five largest publicly traded security companies.

Identity thieves are investing more in R&D than most security companies and are attacking with ever more sophistication. Since the best defense is a coordinated defense, Nemertes believes vendors must lower competitive barriers and focus on collaborative efforts to fight ID theft.

Enterprise organizations must also do more to fight attackers. Security must be put in place to protect the assets that offer the highest value to the attackers, not just what offers the highest value to the company. This requires the allocation of more resources to protect employee and customer personally identifiable information.

Employees Indulge in Risky Business

A national survey of US white-collar workers commissioned by the nonprofit organization ISACA, completed in September 2007, has found that more than one-third (35 percent) of employees have violated their company’s information technology (IT) policies and that nearly one-sixth (15 percent) of employees have used peer-to-peer file sharing at their place of business, opening the door to security breaches and placing sensitive business and personal information at risk.

“Considering that companies rely on their IT infrastructure to store and transmit sensitive company, employee and customer data, risky activities including the ones this survey reveals are of significant concern for all businesses,” said John Pironti, member of ISACA’s Education Board. “A single seemingly harmless activity, such as using peer-to-peer networks while at work, can breach the confidentiality and security of an entire corporate network, including all of the documents, data and internal communications that reside on that network. On average, at a company of 1,000 white-collar employees, up to 70 employees are likely using peer-to-peer file sharing while at work often or very often, based on the survey findings. Companies and employees should be very concerned about their personal and corporate data in light of this information.”

Unfortunately, the opposite seems to be true. For example, the telephone survey found that 65 percent of white-collar professionals are either not very concerned or not concerned at all about their privacy when using a workplace computer. A surprising 63 percent are not very concerned or are not concerned at all about the security of their information while at work.

Additionally, most employees have the misconception that these behaviors pose little to no risk to their companies. Of respondents who said they engaged in these practices, the behaviors they deem to have the least risk include:

• Downloading personal software onto a work computer — 74 percent of those who have done this believe it is not a risky behavior, even though they may unintentionally install spyware or malware on the work computer.

• Checking personal e-mail from a work computer — 73 percent of those who have done this at work believe it is not risky, despite the fact that they could unknowingly download a virus that infects the corporate network.