Lost and Stolen Assets
Please provide the information below to view the online Verizon Data Breach Investigations Report.
Thank You.
Thank you.
You will soon receive an email with a link to confirm your access, or follow the link below.
Thank you.
You may now close this message and continue to your article.
- 2024
- Summary of Findings
- Introduction
- Helpful Guidance
- Results and Analysis - Introduction
- Incident Classification - Introduction
- Incident Classification - System Intrusion
- Incident Classification - Social Engineering
- Incident Classification - Basic Web Application Attacks
- Incident Classification - Miscellaneous Errors
- Incident Classification - Denial of Service
- Incident Classification - Lost and Stolen Assets
- Incident Classification - Privilege Misuse
- Industries - Introduction
- Introduction to Regions
- Wrap Up
- Appendix
- Corrections
- Download the full report (PDF)
Summary
This year we saw an increase in the percentage of cases resulting in confirmed data breaches in this pattern.
What is the same?
Devices are still much more likely to be lost than stolen. Laptops continue to be a risk for loss in particular.
Frequency |
199 incidents, 181 with confirmed data disclosure |
|
Threat actors |
Internal (88%), External (12%) (breaches) |
|
Actor motives |
Financial (92%–100%), Convenience/Espionage/Fear/Fun/Grudge/Ideology/Other/Secondary (0%–8% each) (breaches) |
|
Data compromised |
Personal (97%), Internal (42%), Bank (25%), Other (17%) (breaches) |
Now where did I put that?
If you’ve ever been through the line at airport security where you had to remove your electronic devices, take off your shoes and throw away that bottle of water you weren’t finished with, all while masking the amount of anxiety you were feeling to avoid triggering an “enhanced security screening,” you know that it’s a stressful experience. It is little wonder items go missing while people are away from their usual environment and potentially distracted. Despite having wonderful data storage capabilities and an ever-smaller size, User Devices are the most likely to go missing—whether by ill will or inattention. Chief among them is the ubiquitous laptop, and we’ve seen an increase of those events this year after a brief downturn in 2022, as shown in Figure 53.
As we have seen consistently in our dataset, assets are vastly more likely to be lost than stolen. Figure 54 shows that this was not always the case. Until 2021, we saw more items stolen, but perhaps given the pandemic’s lessening of people out mingling, the theft opportunities were reduced. That said, we still see this trend despite most companies returning to a more traditional in-person work environment, so there could be something else at play here.
This year we saw a higher percentage of incidents involving Assets in this pattern causing confirmed data breaches as well, with last year showing about 8% confirmed breaches and this year showing a surprising 91%.
The important thing is to have protections on assets, where possible, that can stop a lost or stolen device from becoming a reportable data breach. Given the prevalence of this pattern, it seems that someone lost that memo.
CIS Controls for consideration
Protect data at rest Data Protection [3] |
Secure Configuration of Enterprise Assets and Software [4] |