There's a new guy working in your office. You haven't seen him around before and he keeps switching desks, using those of people who are out of the office, or work different shifts.
He has a nice smile and seems really friendly. You guess he works in IT because he always has a laptop and fiddles with peoples desktop PCs quite a bit, but you haven't spoken to him directly yet.
As time goes by you work out he's a bit of a charmer. He has a way with people, makes them feel comfortable with him around and some of the ladies in the office have taken quite a shine to him. He's witty, amusing and likes to bring in buscuits or doughnuts for everyone.
Eventually you find out his name is Tim and he is something to do with IT – you were right! You pluck up the courage to chat to him, and he tells you about his family, his wife and kids, his favourite sport and the team he supports. You get chatting about common interests, he's a really nice bloke and can talk well about almost any topic – not your typical IT geek then, phew!
The following Monday you see no sign of Tim, but you think nothing of it. He's probably off today or working at your other site.
By Wednesday, you have realised he must be off on holiday – you hope he's not ill or anything, especially that lovely wife of his.
The next Monday morning arrives and still no Tim. You don't worry too much because your PC is playing up and you can't log in to the network.
After logging a call with the Helpdesk, you notice that there seems to be a lot of senior managers and directors in various meetings, all looking very serious. Oh god, not more redundancies. So you knuckle down and look busy – as much as you can without your computer, putting the lack of Tim to the back of your mind.
When you turn up on Tuesday morning you see that everyone is being taken into a room with some gentlement in suits – you were right, it is more redundancies. Your turn to go in the room comes and you enter with some trepidation.
The rather stern looking gentleman in front of you says, “My name is Detective Seargent Jim Gallows. What can you tell me about someone working here recently called Tim....”
And that's when you find out that Tim didn't work in IT, he didn't actually work for your company, or a supplier. In fact it's very doubtful his name was even Tim.
You also find out that your company computer systems are offline beacause they have been infected with a virus which has deleted all your corporate data, but not the police suspect, before “Tim” took copies of all your essential information – personnel records, bank account & credit card details, sensitive customer records, financial data, etc. “Tim” and whoever he worked for now knows more about your company, it's employees, suppliers and customers than your company does!
That's all because you, your colleagues and managers didn't check who “Tim” was, didn't make sure he had the permission and the authority to be where he was, doing what he was doing.
Your company has just been the victim of a social engineering scam. “Tim” had essentially conned his way into your company, planted key-loggeers on peoples PCs to collect their user Ids and passwords. He had then connected his laptop to your corporate network and hacked into various systems, using the credentials he'd collected, to steal all you vital business data. At the end of this he had uploaded his virus to the network, ensuring you didn't have access to your systems for at least a few days.
Now imagine if there was no virus, no tell-tale to let your IT people know something was wrong. Would you even know this had happened?
Deals from Amazon
Thursday, 12 August 2010
Why Website Security is Important for Everyone
Most websites, whether owned by an individual, an organisation or a business, are never security tested. Many see it as an irrelevant or unjustified expense, citing the fact that it’s mainly static content, there’s no sensitive information held on the site, it doesn’t accept financial transactions, etc., so there’s no point in potentially expensive web security testing, as the business or organisation can’t be affected by insecurities.
Well, to put it simply, this is not true!
Whilst your website might not contain sensitive information, might not accept any financial or personal transactions, and may be purely static content, you are still putting your clients and website visitors at risk.
Cyber criminals, of which there are many, are not necessarily interested in gaining access to your business and its information – although you are always a likely target – but they ARE after your customers. They want access to their computers and their details and they can use the vulnerabilities in your website to get that access.
More and more often, we are seeing ordinary websites used to load malicious software onto the computers of unsuspecting victims. Cyber criminals are scanning the internet, looking for any websites which are insecure and are loading them with malicious software (called ‘malware’). This in turn is then passed on to the computers of every visitor to your site in what is known as a “drive by attack”, exposing them to all kinds of issues such as identity theft, bank account skimming and credit card fraud.
So whilst your organisation may not be affected directly by your website security problems, there is a huge amount of damage that can be inflicted on your customers and passing visitors, for which you are at least partly to blame.
This has now reached a point in the US where victims of such incidents are taking the website owners to court for compensation. And whilst this may not be likely to happen in the UK or elsewhere, there is certainly the potential for it, particularly where an incident can be traced back to a specific website.
If every person who merely looked at your premises was in danger of some injury, you would rightly take steps to prevent it. So why wouldn’t you take such a course of action in the virtual world of the internet, where such damage can be just as serious?
Well, to put it simply, this is not true!
Whilst your website might not contain sensitive information, might not accept any financial or personal transactions, and may be purely static content, you are still putting your clients and website visitors at risk.
Cyber criminals, of which there are many, are not necessarily interested in gaining access to your business and its information – although you are always a likely target – but they ARE after your customers. They want access to their computers and their details and they can use the vulnerabilities in your website to get that access.
More and more often, we are seeing ordinary websites used to load malicious software onto the computers of unsuspecting victims. Cyber criminals are scanning the internet, looking for any websites which are insecure and are loading them with malicious software (called ‘malware’). This in turn is then passed on to the computers of every visitor to your site in what is known as a “drive by attack”, exposing them to all kinds of issues such as identity theft, bank account skimming and credit card fraud.
So whilst your organisation may not be affected directly by your website security problems, there is a huge amount of damage that can be inflicted on your customers and passing visitors, for which you are at least partly to blame.
This has now reached a point in the US where victims of such incidents are taking the website owners to court for compensation. And whilst this may not be likely to happen in the UK or elsewhere, there is certainly the potential for it, particularly where an incident can be traced back to a specific website.
If every person who merely looked at your premises was in danger of some injury, you would rightly take steps to prevent it. So why wouldn’t you take such a course of action in the virtual world of the internet, where such damage can be just as serious?
Labels:
AVDS,
IT Security,
Secure Thinking,
Vulnerability,
Web Site Security,
WSSA
The importance of having an Information Security Awareness Programme
Most businesses are starting to recognise the importance of information security, both from the perspective of regulatory or legal responsibilities, and from a viewpoint of good business practice and brand protection.
But information security policies, procedures and practices are only as good as the people and systems that operate them. If the people who work in the system don’t understand their role, their responsibilities and why the controls are in place, then the results can be as bad for your organisation as not having them there in the first place.
Over the last few years there have been many stories in the press about information security failures within major organisations and government bodies. These organisations almost certainly had information security policies in place at the time of the failure. So why did it still occur and what can we learn from the mistakes of others?
As already stated, information security policies are only any use if they are understood, are adhered to and ultimately enforced as part of the culture within an organisation. Many of the well publicised information security failures have occurred because either the staff involved didn’t know their responsibilities, weren’t aware they were breaching the policies, or were operating without adequate supervision.
Another common failing is that information security policies do exist but are complex documents, unlikely to be thoroughly digested and understood by staff, even where they have apparently ‘signed them off’. This often means that staff ignore, or at best pay lip-service to the policies and the only time they are truly understood is following a security failure.
In most cases, a programme implemented to raise awareness of information security may well have prevented the failure, either partially - reducing the impact of the failure; or completely, by preventing the breach from occurring in the first place.
A carefully implemented information security awareness programme, encompassing properly documented, easy to understand security policies, standards, procedures and staff guidelines, along with ongoing training and evaluation, is a proven method for reducing information security failures.
It ensures your staff are aware, not only that the policies exist and that they are expected to adhere to them, but also why they exist, what their responsibilities are and how to operate on a day-to-day basis to maintain the required level of security. It also allows management to understand the levels of awareness within the organisation and provides them with the ability to target any specific issues which may arise.
Finally, even a good information security awareness programme needs to be backed up with a policy of open reporting. Having a ‘blame culture’ is not a good environment in which to raise information security issues. Staff need to feel they can report actual or potential problems without the threat of some kind of retaliation or witch hunt!
But information security policies, procedures and practices are only as good as the people and systems that operate them. If the people who work in the system don’t understand their role, their responsibilities and why the controls are in place, then the results can be as bad for your organisation as not having them there in the first place.
Over the last few years there have been many stories in the press about information security failures within major organisations and government bodies. These organisations almost certainly had information security policies in place at the time of the failure. So why did it still occur and what can we learn from the mistakes of others?
As already stated, information security policies are only any use if they are understood, are adhered to and ultimately enforced as part of the culture within an organisation. Many of the well publicised information security failures have occurred because either the staff involved didn’t know their responsibilities, weren’t aware they were breaching the policies, or were operating without adequate supervision.
Another common failing is that information security policies do exist but are complex documents, unlikely to be thoroughly digested and understood by staff, even where they have apparently ‘signed them off’. This often means that staff ignore, or at best pay lip-service to the policies and the only time they are truly understood is following a security failure.
In most cases, a programme implemented to raise awareness of information security may well have prevented the failure, either partially - reducing the impact of the failure; or completely, by preventing the breach from occurring in the first place.
A carefully implemented information security awareness programme, encompassing properly documented, easy to understand security policies, standards, procedures and staff guidelines, along with ongoing training and evaluation, is a proven method for reducing information security failures.
It ensures your staff are aware, not only that the policies exist and that they are expected to adhere to them, but also why they exist, what their responsibilities are and how to operate on a day-to-day basis to maintain the required level of security. It also allows management to understand the levels of awareness within the organisation and provides them with the ability to target any specific issues which may arise.
Finally, even a good information security awareness programme needs to be backed up with a policy of open reporting. Having a ‘blame culture’ is not a good environment in which to raise information security issues. Staff need to feel they can report actual or potential problems without the threat of some kind of retaliation or witch hunt!
Labels:
Awareness,
Information Security,
Secure Thinking,
Training
Information Security for SMEs
If you run a small or medium sized enterprise, then you’re probably up to your eyes in government red-tape, and legal and regulatory obligations, and that’s before you start to actually run and operate your business in order to make a living.
A key component in the smooth running of your business is information. That information may take on many forms – customer or supplier details, financial data or secret recipes for the perfect carrot cake – whatever it is, it is vital to your organisation. As such you need to make sure it is protected, kept from your competitors, guarded against public disclosure and available as and when you need it.
This is why good information security management and practices are as important to you as they are to the ‘big boys’. The major banks and corporations employ dedicated staff to manage their information security risks. You probably don’t have that luxury, but you still need someone to take responsibility for information security.
At this point, many SME managers and business owners claim they don’t have the time for information security, they don’t have the resources, it isn’t important to them, or they can’t afford it. After all, you’re only a small business, your IT people take care of that side of things, and you’re not at risk.
The information and data you use on a daily basis is the lifeblood of your business. Can you imagine if you had none of it? If one day you turned up at the office and all of your paperwork was blank? All of your computers had been wiped? Where would that leave you?
But it isn’t just the total loss of information that is of concern in the modern world. Criminals, including the so-caller ‘cyber’ criminals, want your information and my information. They want personal and financial details from as many people as they can for a variety of reasons, including identity theft. Even corporate data is now a target for the unscrupulous members of society.
So how would your company survive, particularly in the current economic climate, if it was discovered that your customers’ bank accounts were being drained, that identity thieves had access to personal data that could only have come from your business?
Apart from the obvious, potentially fatal, legal and regulatory fines, a well publicised incident of this nature would have a disastrous effect on your brand and business reputation. Even accidental disclosure of sensitive personal information is jumped on by the press, and that is without any direct criminal involvement.
If you hold personal information relating to living individuals, you fall under the jurisdiction of the Data Protection Act (DPA), if you handle financial information for individuals or other businesses you are very likely regulated by the Financial Services Authority (FSA), and if you handle credit and debit card payments you will almost certainly have to comply with the Payment Card Industry Data Security Standards (PCI-DSS). All of these mean you must adhere to minimum standards for information security for regulatory and/or legal reasons.
At the end of the day, information security is as important to SMEs as it is to anyone, so the question isn’t really “why do you need to worry about information security?” but “can you afford NOT to worry about information security?”
A key component in the smooth running of your business is information. That information may take on many forms – customer or supplier details, financial data or secret recipes for the perfect carrot cake – whatever it is, it is vital to your organisation. As such you need to make sure it is protected, kept from your competitors, guarded against public disclosure and available as and when you need it.
This is why good information security management and practices are as important to you as they are to the ‘big boys’. The major banks and corporations employ dedicated staff to manage their information security risks. You probably don’t have that luxury, but you still need someone to take responsibility for information security.
At this point, many SME managers and business owners claim they don’t have the time for information security, they don’t have the resources, it isn’t important to them, or they can’t afford it. After all, you’re only a small business, your IT people take care of that side of things, and you’re not at risk.
The information and data you use on a daily basis is the lifeblood of your business. Can you imagine if you had none of it? If one day you turned up at the office and all of your paperwork was blank? All of your computers had been wiped? Where would that leave you?
But it isn’t just the total loss of information that is of concern in the modern world. Criminals, including the so-caller ‘cyber’ criminals, want your information and my information. They want personal and financial details from as many people as they can for a variety of reasons, including identity theft. Even corporate data is now a target for the unscrupulous members of society.
So how would your company survive, particularly in the current economic climate, if it was discovered that your customers’ bank accounts were being drained, that identity thieves had access to personal data that could only have come from your business?
Apart from the obvious, potentially fatal, legal and regulatory fines, a well publicised incident of this nature would have a disastrous effect on your brand and business reputation. Even accidental disclosure of sensitive personal information is jumped on by the press, and that is without any direct criminal involvement.
If you hold personal information relating to living individuals, you fall under the jurisdiction of the Data Protection Act (DPA), if you handle financial information for individuals or other businesses you are very likely regulated by the Financial Services Authority (FSA), and if you handle credit and debit card payments you will almost certainly have to comply with the Payment Card Industry Data Security Standards (PCI-DSS). All of these mean you must adhere to minimum standards for information security for regulatory and/or legal reasons.
At the end of the day, information security is as important to SMEs as it is to anyone, so the question isn’t really “why do you need to worry about information security?” but “can you afford NOT to worry about information security?”
Labels:
Data Protection,
Information Security,
IT Security,
Secure Thinking,
SME
Why information security is NOT just an IT issue
Time and again, when I talk to business owners and managers about information security, I get the line “that’s an IT issue” or “our IT guys look after that”.
Whilst I’m well aware that IT and IT security plays a significant role in information security, it is not the Holy Grail many people seem to think it is.
IT is not some kind of magic wand, to wave over your information assets to suddenly make them secure. The careful and appropriate use of IT solutions is an enabler of information security. It is a method of securing your information and data whilst being used or accessed electronically.
Information is available throughout your organisation in a whole host of formats. Hardcopy printouts, hand-written documents and notes, and doubtless shelves of folders and binders, all make up a substantial element of your business information.
This information needs to be kept secure also.
But, by making information security and IT issue, many senior managers feel they have done their duty, and allocated it some someone who can deal with it. The problem here is that without senior management buy-in, and a top-down culture of security and security awareness among non-IT staff, the ‘IT Crowd’ can only achieve so much.
Often, IT security controls and processes, implemented without the understanding and buy-in of non-IT staff, will be circumvented. If staff feel that IT is getting in their way, they will do everything they can to work around it or subvert the controls. This is how we end up with users sharing logins or passwords, or documents being emailed to large groups of people because “Joe can’t access them”.
To successfully implement an information security programme, managers and business owners need to take ownership themselves. They need to be involved in writing the policies and procedures. They need to educate their staff and system users as to WHY they need to adhere to the policies, HOW to do it and WHAT the consequences will be if they are not followed. They can then use the available IT solutions to assist with the businesses information security policies, approach and objectives.
Information security is NOT an IT issue, but done properly IT can help you achieve your information security aims. You just need to make sure you’ve defined your business objectives beforehand, and educated your staff along the way.
Whilst I’m well aware that IT and IT security plays a significant role in information security, it is not the Holy Grail many people seem to think it is.
IT is not some kind of magic wand, to wave over your information assets to suddenly make them secure. The careful and appropriate use of IT solutions is an enabler of information security. It is a method of securing your information and data whilst being used or accessed electronically.
Information is available throughout your organisation in a whole host of formats. Hardcopy printouts, hand-written documents and notes, and doubtless shelves of folders and binders, all make up a substantial element of your business information.
This information needs to be kept secure also.
But, by making information security and IT issue, many senior managers feel they have done their duty, and allocated it some someone who can deal with it. The problem here is that without senior management buy-in, and a top-down culture of security and security awareness among non-IT staff, the ‘IT Crowd’ can only achieve so much.
Often, IT security controls and processes, implemented without the understanding and buy-in of non-IT staff, will be circumvented. If staff feel that IT is getting in their way, they will do everything they can to work around it or subvert the controls. This is how we end up with users sharing logins or passwords, or documents being emailed to large groups of people because “Joe can’t access them”.
To successfully implement an information security programme, managers and business owners need to take ownership themselves. They need to be involved in writing the policies and procedures. They need to educate their staff and system users as to WHY they need to adhere to the policies, HOW to do it and WHAT the consequences will be if they are not followed. They can then use the available IT solutions to assist with the businesses information security policies, approach and objectives.
Information security is NOT an IT issue, but done properly IT can help you achieve your information security aims. You just need to make sure you’ve defined your business objectives beforehand, and educated your staff along the way.
Labels:
Information Security,
IT Security,
Secure Thinking
Subscribe to:
Posts (Atom)