blueAPACHE 2014 IT Security Summary
blueAPACHE 2014 IT security summary
A look back at the security landscape of 2014 — a year that changed how Australian organisations thought about cyber risk, and one whose lessons remain uncomfortably current.
Why 2014 was a turning point
Until roughly 2014, cyber security in the mid-market was widely treated as an IT hygiene problem: install antivirus, keep the firewall current, remind people not to click things.
That year made three things clear that have shaped every security conversation since.
Infrastructure itself could be vulnerable. 2014 produced serious flaws in the foundational software everyone depends on and nobody thinks about — the encryption libraries and shell utilities embedded in operating systems, appliances, routers and devices across every network. The lesson was structural: your exposure is not limited to the applications you chose. It includes every component underneath them, much of which you did not choose, cannot see, and may not be able to patch.
Retail and payment systems became primary targets. Large-scale point-of-sale compromises demonstrated that attackers had industrialised card data theft, and that breaches could be sustained for months before detection.
Breaches became public events. High-profile incidents established that a serious compromise is not an IT problem contained within IT. It becomes a board matter, a media matter, a customer trust matter, and — increasingly — a regulatory matter.
The lessons that still apply
Patching is a security control, not maintenance. The gap between a vulnerability becoming public and being exploited at scale is now measured in days. An organisation without a defined patching cadence, and a defined exception process for what cannot be patched, is relying on not being noticed.
You cannot protect what you have not inventoried. Most organisations, asked to list every internet-facing service they operate, produce an incomplete answer. The forgotten test server, the appliance installed by a departed contractor, the management interface that was supposed to be temporary — these are where intrusions start.
Detection matters as much as prevention. Prevention fails eventually. What separates a contained incident from a catastrophic one is how long the intruder operates undetected. Continuous monitoring is the control that shortens that window.
Backup is a security control. 2014 predates the ransomware era at its current scale, but the principle was already visible: recovery capability determines outcome when prevention fails. A backup reachable from a compromised administrative account is not a backup.
The human layer is the residual risk. No technical control stops a well-constructed request from a plausible sender asking a finance officer to change a supplier's bank details. The control is procedural: verification by voice call to a previously known number — never the number in the email.
How the approach has matured since
blueAPACHE's own security posture has been formalised in the years since. The company holds ISO/IEC 27001:2022 certification — certificate 202507-118, issued by Sensiba Australia, valid 1 August 2025 to 1 August 2028.
That matters for a services provider specifically. A provider advising clients on security controls while operating without an independently certified information security management system of its own is asking for trust it has not evidenced.
Security now runs across blueAPACHE's portfolio rather than sitting beside it:
- 24/7 monitoring of managed infrastructure, with emergency response on every day of the year
- Email security and resilience, including work in the Mimecast ecosystem
- Endpoint protection and management, including the NinjaOne and ControlUp partnerships
- Network security, including the Fortinet ecosystem
- Backup and disaster recovery, with Veeam Cloud Connect into blueAPACHE's Australian cloud
- Data sovereignty — three geographically diverse data centres on Australia's eastern seaboard
A practical baseline
For an organisation reviewing its position today, five questions establish where it actually stands:
- What is internet-facing? Produce the list. Verify it against a scan rather than against memory.
- How quickly do we patch, and what are the exceptions? Both answers should be written down.
- Who would notice an intrusion, and how long would it take? If the answer depends on someone happening to look, the answer is too long.
- Can we restore, and how long does it take? Tested, with the time recorded.
- What stops a fraudulent payment request? If the answer is "our people are careful", it is not a control.
About blueAPACHE
Founded in 1998, blueAPACHE is an Australian-owned IT services provider with more than 280 staff across Melbourne, Sydney, Brisbane, London and Miami, and more than 90 industry awards.
To discuss your security posture, call 1800 248 749.
Frequently asked questions
Why does this post treat 2014 as a turning point for cyber security? Because that year established three things that have shaped security thinking since: that foundational infrastructure software can itself be vulnerable, not just the applications an organisation chose; that retail and payment systems had become industrialised targets, with breaches sustained for months before detection; and that a serious compromise is a board, media, customer-trust and regulatory matter rather than an IT problem contained within IT.
What does "your exposure is not limited to the applications you chose" mean in practice? It means the encryption libraries, shell utilities and firmware embedded in operating systems, appliances, routers and devices across a network are part of the attack surface. Much of that stack was not selected by the organisation, is not visible to it, and in some cases cannot be patched by it at all.
Why is patching described as a security control rather than maintenance? Because the gap between a vulnerability becoming public and being exploited at scale is now measured in days. Without a defined patching cadence and a defined exception process for what cannot be patched, an organisation is relying on not being noticed rather than on a control.
Why does the post say backup is a security control? Because recovery capability determines the outcome once prevention has failed. The post makes the sharper point that a backup reachable from a compromised administrative account is not a backup — the isolation of the copy is what makes it a control rather than a convenience.
What is the residual risk that technical controls cannot remove? The human layer. No technical control stops a well-constructed request from a plausible sender asking a finance officer to change a supplier's bank details. The control is procedural: verification by voice call to a previously known number, never the number supplied in the email.
What security certification does blueAPACHE itself hold? ISO/IEC 27001:2022, certificate 202507-118, issued by Sensiba Australia and valid from 1 August 2025 to 1 August 2028. The post argues this matters specifically for a provider advising others on security controls.
What are the five questions for reviewing a security position? What is internet-facing, verified by a scan rather than memory; how quickly the organisation patches and what the documented exceptions are; who would notice an intrusion and how long that would take; whether restores work and how long they take, tested and recorded; and what actually stops a fraudulent payment request — noting that "our people are careful" is not a control.
Related
- Security services
- emPOWER Security
- Managed detection and response — the detection window this post describes
- Human risk management — the residual human layer
- Exposure management — knowing what is internet-facing
- Offsite backup as a service
- Disaster recovery as a service
- Governance, risk and compliance
- ISO 27001 certification
- Data sovereignty and privacy
- Managed services
- Vendor partners — Mimecast, NinjaOne, ControlUp, Fortinet, Veeam
Knowledge Base
What is the blueAPACHE 2014 IT Security Summary?
It is a downloadable infographic published by blueAPACHE that summarizes IT security statistics and trends from 2014.
When was the blueAPACHE 2014 IT Security Summary article published?
It was published on November 8, 2014.
What growth in IT security incidents did the blueAPACHE 2014 IT Security Summary report?
The summary reported a 48% growth in IT security incidents over the past year.
What percentage of organisations experienced an IT security attack according to the 2014 summary?
According to the blueAPACHE 2014 IT Security Summary, 94% of organisations had experienced at least one attack in the past 12 months.
Does the blueAPACHE 2014 IT Security Summary include information on the cost of attacks?
Yes, the summary includes the costs of a single successful attack, in addition to data on incident growth and attack prevalence.
Where can the blueAPACHE 2014 IT Security Summary infographic be downloaded?
It can be downloaded as a PDF (700kb) or a full size PNG (1.3Mb) via links provided on the blueAPACHE website page for this article.
Is there a related article for further reading on IT security threats mentioned on this page?
Yes, the page references a related article titled 'record number of IT security attacks' for more information on targeted threats and challenges facing organisations.
Who should be contacted for help managing IT security risk according to this blueAPACHE page?
The page advises contacting blueAPACHE for more information on how to better and more cost effectively manage security risk, via their contact page.
Who is credited as the author of the blueAPACHE 2014 IT Security Summary article?
The article is written by blueAPACHE, listed as an organization author.
How long does it take to read the blueAPACHE 2014 IT Security Summary article?
The article has a stated read time of 1 minute.
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c2207b7741bf53e6c79_blueAPACHE-2014-IT-Security-Summary.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701c2307b7741bf53e6cc7_blueAPACHE-Security-Report.png
blueAPACHE Security Report
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.
-
https://www.facebook.com/tr?id=541021476571056&ev=PageView&noscript=1
(no alt text)