Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Monday, November 26, 2012

Network Security - I Have a Firewall, So I Am Safe From Hackers, Right?

Wrong. How many high profile organisations have been hacked in recent months? We are talking about Government, DoD, Security Companies, Sony! You can bet your cotton socks that these guys have more than one Firewall protecting their network(s) plus a whole load more protective controls.

So, if they have so much Security, how on Earth were they hacked - what was the weak link? Human Beings, a wireless Printer, Surveillance Bugs?

Well frankly it could be any number of things. A Human can be tricked into providing restricted information such as their user credentials. A printer might be running an old version of firmware susceptible to man in the middle attacks or a bug could be planted in the IT Room to eavesdrop on useful information.

The point here is that placing a Firewall on your Network or installing a Laser Beam Alarm Systems in the building is not enough. You need to put yourself in the shoes of a Hacker and think the way they do. Why break into a building at night when they can walk into to the building during the day and impersonate an employee? Why hack the firewall when they can plant a USB stick on the floor for an employee to pick up and connect to their PC punching a hole straight through the firewall?

What do we have to do in order to protect ourselves from these attacks? Well, I would start by having a carefully thought out Security Policy. Sounds a bit tame doesn't it? Well its the equivalent of a having a plan. Do you think the USA ever went into a War without a plan - actually don't answer that! Having a well thought out plan makes your life so much easier by providing you the path that you need to follow rather than trying to feel your way through. An Employee education programme would be a good place to start. It may include guidelines like:

'NEVER provide your User Credentials to ANYONE'. All seems quite obvious but you'd be amazed at how easy it is to pose as an IT Support member and blag a password out of someone. Another one might be to forbid the use of unauthorised external media such as USB Sticks. A quarterly staff or departmental presentation to educate staff on Security and explain why these controls are being put in place - Believe it or not it helps for the staff to know why they have been asked to act in a certain way.

Read more in Part 2 of this document so keep a look out!

Protect Your Privacy With Reputation Management   Top 5 Reasons to Check Website Security   Why Ignoring IDS Could Lead to Substantial Damage for Businesses   

An Explanation of CISPA for Small Businesses

Recently, the House of Representatives passed CISPA, the Cyber Intelligence Sharing and Protection Act. With the SOPA debate that occurred earlier this year, not to mention its sister PIPA and several other lesser-known initiatives, 2012 seems rife with technology legislation for small business owners to wade through.

Although some are comparing SOPA and CISPA, there is little similarity. While SOPA was an attempt to prevent copyright infringements on the internet, CISPA is trying to reduce cyberattacks through data sharing. The bill allows private companies to share data about potential cyberattacks; this data can be shared with other companies or with the federal government.

SOPA was almost universally rejected in the tech world (in some cases quite vehemently). CISPA, on the other hand, has garnered more support. Microsoft and Facebook (at least as of this writing) have both expressed open support of the bill. Companies in support of CISPA maintain that the legal right to share data will help them better defend their networks against cyberterrorism. Even tech giant Google has declined to take a formal position on the bill, thus giving it tacit support, according to some. The only major player in the technology space that openly opposes CISPA is Mozilla, the creator of the popular Firefox web browser.

Why does Mozilla stand as one of the lone opponents to CISPA? One word: privacy. Mozilla sent a statement to Forbes summarizing its official viewpoint: "The bill infringes on our privacy, includes vague definitions of cybersecurity, and grants immunities to companies and government that are too broad around information misuse."

CISPA's effect (if it passes the Senate in its current form) will probably be felt mostly by individuals. Of course, anything that affects individuals will affect the small businesses run by those individuals. Do you use Salesforce for customer relationship management? Your data could be shared with other companies if it's deemed useful to investigations of cyberattacks. Even your email could be subject to this, unless it is hosted on a server you own and not in the cloud.

Both opponents and supporters of CISPA agree that we need to continue the fight against cyberattacks. Many entities-especially non-profit privacy advocate groups-see CISPA as a step too far, infringing the basic rights of American citizens. Others, like tech companies that stand to lose the most from hacking and other cyberattacks, see CISPA as a step in the right direction. Interestingly, the White House has threatened to veto the bill, should it reach the President's desk in its current form. Where do you stand on this issue?

Protect Your Privacy With Reputation Management   Top 5 Reasons to Check Website Security   Why Ignoring IDS Could Lead to Substantial Damage for Businesses   

Twitter Facebook Flickr RSS



Français Deutsch Italiano Português
Español 日本語 한국의 中国简体。