The Softletter/Prolexic Website Security Survey

[image]


Softletter's Marketing and Selling SaaS (Software as a Service) Seminar, 2008
Softletter's Marketing and Selling SaaS Seminar, 2008
January 30/31, Atlanta, GA

 

Dear Colleague:

As you may know, Softletter, now in its 23rd year of publication, publishes a series of surveys that examine every aspect of running a successful software business. This survey, conducted in cooperation with Prolexic (www.prolexic.com) covers website security and up time. As you are undoubtedly well aware, doing business online can be a dangerous exercise. Recent security breaches involving the states of Massachusetts, Vermont, Connecticut etc., the massive loss of data at TJ Max, and a recent phishing attack at Salesforce.com only highlight the current state of online security affairs.

This survey looks at the three principal sources of website security breakdowns and breaches. These are:

DDoS attacks. Distributed Denial of Service attacks are a class of online assault that use compromised PCs and servers to overwhelm a company’s websites and web applications. The object of a DDoS attack is to generate a torrent of incoming messages to a website that forces it offline, thereby denying legitimate visitors and customers access to the site/system.

Hacking attacks. Hacking attacks use password theft, backdoors, SQL injection, viruses, trojans, bots, et al to allow an external party to gain direct control over the functions and data of a site or damage or prevent it from operating properly.

Phishing/Social Engineering attacks. Phishing/Engineering attacks attempt to manipulate or trick an individual(s) to voluntarily provide information that will allow a third party to gain unauthorized access to a site's operations and data.

We're looking for some fairly standard information and will use this data to identify trends and current benchmarks that you can use to see how your own numbers and processes compare to those of comparable companies. In addition, we analyze information based on company development stages, an important factor that allows us to establish medians for companies in different market sectors. We also break software companies into four types: Enterprise/Client Server, SaaS, Desktop/Retail and OEM. The entire survey is 25 questions and should take approximately 15 to 20 minutes to complete. Please pass this invitation along to a colleague in the industry who you feel should participate.

Everyone who supplies data for this survey will receive a complimentary copy of the summary report. Of course, all responses will be strictly confidential. We won't disclose or identify data about any individuals or about participating companies. Also note that we will be sending the summary results via E-mail; if you provide us with a non-working address you won't receive them. We're sorry, we don't have the time to deal with whitelist verification and suggest you add softgram@softletter.com and rickchapman@softletter.com to your approved recipients lists to ensure you receive the survey results.

Don't forget to push the Submit Survey button at the bottom of this question page, and then wait for the acknowledgement page.

Final summary results will appear in our January 31st issue of Softletter.

For more information on subscribing to Softletter (www.softletter.com) and Softletter publications such as the Financial and Software as a Service Handbooks, please click here.

Many thanks for your help!

Merrill R. (Rick) Chapman, Managing Editor
Softletter
34 Sugar Hill Road
Killingworth, CT 06419
860/663-0552
rickchapman@softletter.com

The Softletter 2007 Website Security Survey

(Please enter all monetary numbers in US$, 100,000 format, no decimals, dollar signs, or percentage symbols.)

1. Development stage of the company:





2. Current revenues:






3. What type of software does your company primarily sell?





4. Please pick the choice which best reflects your assessment of
the importance your customers place in your website being online 24/7/365.






5. In terms of period of unavailability, which statement best
describes how long your website can be unavailable to
your customers, partners, and suppliers?








6.

In terms of its estimated overall negative impact on your business, please rank the security problems listed below. You do not need to have undergone one of these types of attacks to answer this question.

Amount of negative impact on your business.
Very high
negative impact
High
negative impact
Moderate
negative impact
Low
negative impact
Very low
negative impact
DDoS
Hacking

Phishing/
Social Engineering


7. Please estimate the hourly costs to your business if your
website/portals/applications were to go offline.








8. Has your website ever undergone a DDos, Hacking, or Phishing/Social Engineering attack?



DDoS Attacks

9. Has your company ever undergone a DDoS attack?




10. If your company experienced a DDoS attack, was it within the last 12
months?




11. What do you think is the likelihood that you will experience
a DDoS attack within the next 12 months?




12. Do you currently use a managed DDoS protection service or
have specific DDoS equipment in place internally?




13. Do you currently use a managed DDoS protection service or
have specific DDoS equipment in place internally?




14. Are you actively looking to implement more robust DDoS
protection within the next 12 months?



Hacking Attacks

15. Has your company ever undergone a hacking attack?




16. If your company has experienced a hacking attack, was it within the last 12
months?




17. What do you think is the likelihood that you will experience
a hacking attack within the next 12 months?




18. Do you currently use a managed hacking protection service or
have specific anti-hacking equipment in place internally?




19. Do you currently use a managed anti-hacking protection service or
have specific anti-hacking equipment in place internally?




20. Are you actively looking to implement more robust anti-hacking
protection within the next 12 months?



Phishing/Social Engineering

21. Has your company ever undergone a phishing/social engineering attack?




22. If your company has experienced a phishing/social engineering attack, was
it within the last 12 months?




23. What do you think is the likelihood that you will experience
a phishing/social engineering attack within the next 12 months?





24. Are you actively looking to implement more robust
anti-phishing/social engineering protection within the next 12 months?



25. Please send my free copy of the summary report to:

Thank you for your patience and help in taking this survey. The summary results will be published in the January 31st issue of Softletter. Interested in subscribing to Softletter and obtaining key business metrics and keeping up with vital trends in the software industry? Then please click here.

©2007 Softletter, 34 Sugar Hill Road, Killingworth, CT 06419. Voice: 860/663-0552; Fax:860/663-0553.
E-mail: rickchapman@softletter.com


Powered by SurveySolutions
survey software