DocuCrunch.com » Data hacking: It’s not just angry teens

Data hacking: It’s not just angry teens

February 2, 2010 by Sam Narisi
Posted in: Security, Special Report

security-breach

Attacks on corporate data are getting more professional. The image of the lone hacker in his bathrobe playing gotcha is being superseded by one of dedicated, professional industrial espionage.

That’s according to a recent survey by the Center for Strategic and International Studies (CSIS).

The study, commissioned by computer security firm McAfee, interviewed over 600 IT managers in 14 countries and revealed a rapid growth in serious corporate and government espionage.

Almost 60% of the respondents said their networks were “under repeated cyber-attack, often by high-level adversaries such as nation-states, organized crime gangs or terror groups.” The attacks include such things as shutting down sites (denial of service attacks), malware and finding unprotected data on the site.

Only 57% of these companies installed security patches and updated security software on a regular basis. Scariest of all, some of the most vulnerable companies are utilities (electricity, water, sewage) that depend on Internet-connected systems management software to keep in operation.

Your company is probably not the target of interest for international cyber warriors or crime syndicates. Nevertheless, the techniques and tricks keep developing as fast as, or faster than, the technology to defend against them. If the largest global companies with serious IT budgets are having problems keeping the data safe, then smaller operations where the IT departments are being pulled in every direction to support daily operations are even more open to attack.

It’s a good idea for top management, IT staff and other concerned folks (HR, finance and others) to review the current state of the company’s defense strategy and the plans to upgrade it.

The biggest challenge: making the case for an increased security budget. Experts recommend IT explain security as a kind of insurance, with a detailed analysis of how attacks can lead to lost revenue.

  • Share/Bookmark

DocuCrunch.com delivers the latest IT and Imaging news once a week to the inboxes of over 200,000 IT and Imaging professionals.

Click here to sign up and start your FREE subscription to DocuCrunch!

Tags: , ,


One Response to “Data hacking: It’s not just angry teens”

  1. Bob Says:

    The biggest mistake most companies make is that they don’t do a good job of risk analysis. Consequently, risk mitigation is often way out of proportion — either way too little, or way too much — of the risk of information being disclosed.

    Any time a company handles consumer data, and especially types of data that could be exploited for ID theft, that company has the responsibility to implement the strongest security controls and practices, or look at opportunities to outsource that part of the business that’s “high risk / high cost”.

    An example is payment processing. “Mom and Pop” websites that use off-the-shelf or open source e-Commerce packages and process their own credit card transactions potentially carry a huge liability. The Payment Card Industry (PCI) Data Security Standard is in place to try to ensure that sufficient controls exist around payment card data, and these controls might be quite expensive. A better alternative might be to outsource payment processing to Paypal, Google or Amazon. Although there are structured fees around outsourcing of payment processing, this might be much less expensive than a full-on implementation of a PCI compliance program, which could run in to the hundreds of thousands of dollars even for a relatively small deployment.

    The best approach is to look at the risk, look at the cost, and make a determination to move the risk, accept the cost and mitigate the risk, or accept the risk as part of doing business.

    Too often, businesses accept risks that they don’t understand, and there are no clear guidelines on how much risk should be able to be accepted vs. mitigated — a clear example of this was the housing bubble and credit meltdown caused by companies that aggregated too many high-risk investments.

    Pulling in a consultant is often a good way to make sure residual risk is properly sized for the business. If your company is accepting too much risk, a good consultant can identify that, qualify the risk, and help formulate a cost-effective remediation strategy.


advertisement


Whitepapers

  • How to Select a Web Host
    November 27, 2011 by marketing

    Creating a new website?  Not sure how to choose from among all the options?  Need shared hosting, small business hosting, or VPS hosting?  Lots of email accounts? 5-star reliability rating? Fortunately, there’s information available to help. The Best Web Hosts is great resource that will help you select the best web hosting company. It features reviews, rankings, and definitions that can help make your job of selecting a new web host more effective.

  • SMART Steps Towards Workload Automation
    January 19, 2010 by Luke Marchie

    Consolidating job scheduling into a single, comprehensive workload automation solution is a critical first step to effective Workload Automation (WLA).

    Download the free whitepaper here! More…

  • Identifying and Thwarting Malicious Intrusions
    January 12, 2010 by Luke Marchie

    Identifying and Thwarting Malicious Intrusions

    The phenomenal growth in social media has opened the door for all new malicious intrusions from gangs of cyber criminals. Utilizing the trusted relationships in social networking and benefiting from immature security and content controls, hackers are seeing increased performance in their attacks.

    Download the free whitepaper here More…

  • The Security Issues with Web 2.0
    January 12, 2010 by Luke Marchie

    The collaborative benefits of Web 2.0 technologies have fueled rapid growth in online consumer markets and now are being adopted by businesses worldwide. With these technologies come new types of attack vectors.

    Download the free whitepaper here

    More…

  • Network-Critical Physical Infrastructure: Optimizing Business Value
    December 29, 2009 by Luke Marchie

    To stay competitive in today’s rapidly changing business world, companies must update the way they view the value of their investment in Network-Critical Physical Infrastructure (NCPI). No longer are simple availability and upfront costs sufficient to make adequate business decisions. Agility, or business flexibility, and low total cost of ownership have become equally important to companies that will succeed in a global, ever-changing marketplace.

    Download the free whitepaper here! More…

  • The New World of eCrime: Targeted Brand Attacks and How to Combat Them
    December 26, 2009 by Luke Marchie

    Nothing is more valuable to a business than its reputation. That is why brand attacks, which leverage a company’s valuable brand for nefarious purposes, must be battled on every possible front. Brand attacks are the new form of eCrime, and they’re being launched with new and rapidly evolving exploits, including phishing and—most recently—malware.

    Download the free whitepaper here! More…

  • DDoS: The Mother of All Cyber Threats
    December 16, 2009 by Luke Marchie

    DDoS: The Mother of All Cyber Threats

    Don’t wait until your business is targeted. A Forrester Consulting study commissioned by VeriSign revealed that nearly 75 percent of the 400 study respondents have experienced one or more DDoS attacks in the past year. Yet, most e-commerce businesses are not prepared for a large-scale DDoS attack. Could your business afford three or more hours of downtime? Avoid that revenue loss by registering for this free white paper

    Click here to download the free white paper More…

  • View more offers


    Quick Vote

    • Does your office have a color printer or copier?

      • Yes (75%, 3 Votes)
      • We're looking into buying one (25%, 1 Votes)
      • No (0%, 0 Votes)

      Total Voters: 4

      Loading ... Loading ...

  • advertisement