Deals from Amazon

Wednesday, 13 July 2011

Do Web Developers Avoid Scrutiny?

Due to the nature of our business we speak to many people in various industries and something is becoming more and more clear as time goes by – website and web application developers are reluctant to have the security of their work scrutinised.

I understand their dilemma – if they have their solutions security tested it will add to their costs and increase the price of their product.  Or it may affect client beliefs that the products they deliver are already secure.  

Then there is the hosting company who provide the hardware and infrastructure which allows websites to be accessed – some of the security issues may lie there, so why would the site developer worry about security?

Indeed, I had a conversation recently with a website development company who didn’t want their product security tested because to do so may imply that they aren’t building things properly in the first place.  They went on to point out that if the client discovers a security issue in the application later, they can charge them again for fixing it!

The other problem is one of accountability.  In the recent attacks against Sony, Sega and others it is the company or organisation attacked that gets the bad press and the flak, not the company they got in to develop the website or application.

This means the website developers get off scot-free with the probably loss of just that piece of work or client.
So how do we change this?  What should companies and organisations do to ensure the work done for them is of a high enough standard?

Well here are a number of suggestions:

1.       Ask them about the security measures they build in to your solution.  If they’re vague or evasive find another supplier.  Have whatever response you get evaluated by an expert.

2.       Ask them up-front if they have the site independently security tested or whether they are happy for you to do so once the solution is complete but before you pay for it.

3.       Ask them to guarantee the site’s security, or at least provide fixes for free should security vulnerabilities be identified later.  Make sure this is in the contract.

4.       If they do security test the solution find out if it is truly independent and whether the site will receive any accreditation in the form a security seal or other certificate.

At the end of the day, if you employ a website developer to create your website it’s still your data, reputation and profit that’s at risk if your security isn’t up to scratch.  Is that a risk you’re willing to take?

For more information on website security in general and website security auditing contact Secure Thinking on 0845 071 4690 or visit www.securethinking.co.uk

Friday, 24 June 2011

Online Backup Service - Selection Criteria

There are many online backup and “cloud” data storage/sync solutions available via the internet.  Some offer free backups and the paid ones start from as little as £5/month.
But before you run off and pick a backup service for your critical business data based on price alone here are a few things you should consider during the selection process:

1.     Offsite Data Storage

Obviously with an online solution it has to be offsite but if you share data centre space in managed facilities make sure your data isn’t being stored in the same facility as your servers.  If it is then find another provider or make sure your provider has point 14 covered.

2.     Easy to setup

There’s no point picking a backup solution which requires you to be an IT technical guru – even if you are one!
Therefore your chosen solution should be easy to setup and configure whether that’s by your or the technical team from the vendor.

3.     Automatic

It goes without saying but your backup solution has to look after itself.  If it doesn’t then stay away as you’ll simply be buying yourself more work and the time you forget to run a backup is the time you’ll need your data to be recovered.
Also, it’s a good idea to select a service you can use to backup your data based on a schedule.  If you save your files at the end of one day you don’t want to have to wait a day, or over the weekend for them to be backed up.

4.     24 x 365

Just like it being automatic, there’s no point in having a backup solution that’s only available Monday to Friday 9am-5pm!  You need maximum availability to ensure your data is backed up when you need it to be and that you can recover the data as quickly as possible in the event of a disaster.

5.     Simple Restore

If a disaster does strike your business and you need to restore data from your backups it needs to be as simple and easy as possible.  In a real disaster, you and your business are probably already in a world of pain and worrying about getting your data back shouldn’t add to your problems.

6.     Monitored on your behalf

Why worry about things you don’t have to?  Your backup should just happen and only notify you if there’s a problem.  But you need to know that it’s working correctly and be comfortable with the solution to have real faith in your backups as a disaster recovery tool.

7.     Wide Compatibility

Compatibility of your backup solution is vital.  Just because you use Windows 7 Desktop and MS Office now doesn’t mean that’s what you’ll always use and you need to make sure you can recover files, folders and other types of data when you need them on whatever platform you’re using.
Also, a wider range of supported platforms and applications will likely mean a more rounded and thoroughly tested product.
 But there are other benefits to a wide range of compatibility – namely that your backup service will integrate better with software applications and database products meaning you can recover finer grained layers of data.
One example of this is single mailbox recovery in MS Exchange.  Without a good level of compatibility and integration, all you can recover should you have a problem with MS Exchange email, is the entire email data set.  This in turn means you have a considerable amount of work to do to get a single mailbox back from a multi-user backup, even assuming you have the space and ability to bring back a full copy of your email system without overwriting the active one.
However, with a fully integrated product it is possible to recover individual mailboxes without a major amount of work.
So when choosing your backup service provider, have a close look at the level of compatibility and integration and make sure that it is covering all of your critical data, files and folders and bear in mind any future requirements you might have.

8.     Transmission Encrypted

The security of your data is paramount.  After all it’s why you’re backing it up in the first place.  It’s also why the transmission of your data across the internet or other networks should be encrypted.
Encrypted data transmission ensures that your data can’t be intercepted and read/accessed by anyone or anything else between your computers and the storage facility used by your chosen provider.

9.     Data Compression

This is a really handy feature and should be available in the backup solution you choose.  Essentially data compression means that the amount of data actually transferred between your computer and the storage facility is less than the amount of data on your computers.
Compression takes the data you have and squashes it down into smaller, tighter packages for transmission over the internet.
This means you don’t use or need huge amounts of bandwidth and large data transfer allowances to make use of an online backup solution.

10.Storage Encrypted

This is potentially where we start to see the largest difference between online backup providers – how and where your data is stored and who has access to it.
Your data must be stored encrypted once it lands at the remote storage facility.  Otherwise your data could be accessed by anybody who has or gains access to their network or facilities.
Ideally, only you should have the encryption key used to protect your data – see point 11.

11. No Access to Data by Provider/DC Staff

Whilst many backup and online “cloud” storage providers claim your data is encrypted on their system that doesn’t always mean what you think.
A truly encrypted solution would mean that no-one other than the individual or group who know the encryption key can actually access the data.
Many online backup and cloud storage solutions do indeed encrypt the data but it is done by them, and they have the encryption keys.  This also means that they potentially have access to your data and you’re not likely to know if anyone else accesses it.
So choose your backup solution carefully, particularly if you manage sensitive data.

12. Data Centre Locations

Where is your data physically stored once it leaves your network?  Are the data centres used by your backup provider located in your home country?  Or are they elsewhere such as within the EU or US?  Do you even know?
One thing to bear in mind when selecting an online backup provider is where your data ends up.  Different nations and regions have different laws on data protection, due process and lawful searches.
If your data is no longer in your own country then it is no longer under the protection of your nation’s legal system and could be subject to access based on processes which would hold little or no sway in your own country.
And remember, ultimately if your data security is breached and you fall under the legal or regulatory jurisdiction you may be liable for the breach – even if it occurs elsewhere in the world.  You can outsource your data storage but you can’t outsource the responsibilities and liabilities attached to that data.

13. ISO27001 Certified Data Centres

Ideally, the data centres used to store your backups should be certified as secure to an internationally recognised standard such as ISO-27001 Information Security Management standard.
This should give you confidence that your data is safe and the service providers are taking their information security responsibilities seriously.

14. Geographical Secure Data Centre Replication

You’re taking precautions and backing up your data.  That’s very commendable and responsible of you – too many don’t even bother to do that!
But does your solution provider take the same precautions?  If you need to recover a file or two, or your entire data collection will the service provider’s systems be up and available?  Are they replicating the data you’re entrusting to them to a geographically separate location to ensure its availability should they encounter and issue at their primary data centre?
If you’re backing up your data, you’re doing so for a reason – to protect it.  Now you might feel that your copy and the copy they have in the “cloud” is enough security for your data.  But if you’re paying for a service you might as well pick one that maximises your protection and ensures you can access your data when you need it most.
After all, if it can go wrong it will and reducing the “single points of failure” in any technical solution increases the resilience and availability of the whole solution.

15. Free technical support

Finally, if you’re paying for a backup solution are they offering you free technical support or is it all premium rate numbers you can’t get hold of or a helpdesk you can only call during set (and usually inconvenient) hours?
Hopefully you won’t need technical support, but if you do it’s nice to know they’re there when you need them!

So there you have it – the criteria we use and therefore recommend you use for choosing an online backup or cloud data storage/sync solution for your business.

Saturday, 18 June 2011

A New Breed of Hacker

An interesting development seems to have taken place in the world of Internet security over the last few months.

Back in the early days of the web hackers were mainly script kiddies and other individuals or small groups out to prove a point.

The threats and the risks increased when organised crime realised there was big money in online hacking activities and brought their considerable financial and organisational skills to the arena.

We have also seen nation states allegedly taking part with coordinated attacks designed to access or infiltrate the systems of other countries, either for political or commercial reasons.

Then there was the "hacktivists" - people out to cause disruption or protest against certain companies, beliefs or activities.

But over the last few months we have seen a new form of "hacktivist". One that takes on a scary new role.

These new style groups which include Anonymous/4Chan and LulzSec have a number of similar attributes They are:

Almost anarchistic
Anti-establishment
Competitive with each other
Loosely organised
Democratic
Ego driven
Out to prove they can "do it"
Bordering on the mercenary

They are however having one positive effect - they are making the issue of web and Internet security front page news across the world.

Ultimately this could prove to be their primary motivation - only time will tell.

In the meantime, their indiscriminate attacks need to be thwarted so take a long hard look at your website and ask yourself "is my security up to scratch?"

If it isn't or you're not sure seek expert advice and get some protection before you become a target.

For more information on website security contact Secure Thinking on 0845 071 4690 or visit http://www.SecureThinking.co.uk

Wednesday, 25 May 2011

Data Backup Considerations

Data is vital to modern businesses.  Some say it's the life blood of a business.  After all we live in the information age.

But do we all protect data and information to the best of our abilities?  Do we ensure we can recover from its loss, corruption or theft?

In information security parlance are we properly protecting its CIA - Confidentiality, Integrity and Availability?

Most businesses take some steps to backup their data. This can be using traditional methods such as tape drives to newer techniques involving optical media, removable USB storage or even online backup solutions.

If you're not backing up your data then you should be. It's inexpensive and might just save your business one day.

But backing up your data is only half the story.  Having a backup is meaningless if you can't recover your data in the event of an incident.

You need to test that you can restore your data on a regular and random basis.  This exercises your solution and ensures it is actually doing what you expect of it.

Another consideration is the age and technology used.  If your infrastructure, devices and backup software are more than a few years old you may have other problems should you experience a significant incident or disaster with your systems.

If your incident takes out your current infrastructure can you replace it to actually recover your backups?

Without compatible technology and software your data may be inaccessible without expensive and time consuming 3rd party services.

Then there are online solutions.  There are many of them out there and they are fairly inexpensive but which one should you choose?

Depending on the data and the legal or regulatory requirements you may need to think very carefully. Your data may fall under one jurisdiction while it's residing on your servers and PCs in your office but whose jurisdiction is it under the control of on the backup storage?  What are their data protection, privacy and security laws like?

Is the data stored encrypted where only you can access it or can the staff at the service provider actually access your data, with or without your permission?

These are all things you need to consider when selecting a backup solution.  It isn't a simple choice based on price so think carefully and ask the questions above. They might just stop you going out of business.

In the meantime if you are looking for an online backup solution why not contact us on 0845 071 4690 or visit www.SecureThinking.co.uk and ask us these questions?

Wednesday, 11 May 2011

How's Your Business Continuity Plan?

Businesses are fragile things. They can be affected in their success by
a whole host of factors including market forces, consumer habits, and
changes in attitudes.
But many aspects of your business success are firmly held in your own
hands. You can develop an agile approach allowing you to change your
model based on market forces, you can adapt your products or services to
take into account consumer demands and you can keep track of people's
opinions to ensure you keep with current thinking and attitudes.
But how would you cope with a major incident that occurred to or in your
business?
Business continuity and disaster recovery are essential tools designed
to protect your business should the worst happen.
If you make use of technology in your business and particularly if it
forms the backbone of your operations you need to make sure you have a
Disaster Recovery Plan.
Disaster Recovery is the process of recovering your technical systems,
data and applications to a level which allows you to continue operating
your business.
Sometimes a DR solution will only recover key systems - just enough to
keep you going in the short term until a full recovery can be performed.
A technical disaster or incident can be caused by a number of internal
factors including technical faults, accidental damage caused by errors
or malicious activity.
Disasters can also be caused by external factors such as power cuts,
floods or property damage.
The key to an effective DR plan is to evaluate which systems,
applications and data are key to your operations and ensuring these are
recovered first. There is no point spending time and effort recovering
your marketing database when your customers aren't getting the products
they've ordered or the services they've bought.
Getting your DR plan right can mean the difference between having a
business in serious trouble and your customers not even knowing there
was a problem.
A Business Continuity Plan is similar in many ways to a Disaster
Recovery Plan. The main difference is that the BCP deals with more than
just technology.
Your BCP covers all aspects of your business, from offices and desk
space, communications, operations, to incident response, staff safety
and public relations.
Whether you decide your business needs a full BCP or merely a DRP you
should be aware that having one and making sure it is up to date and
tested can be the difference between your business surviving and growing
and it's complete failure.
There are many statistics out there but the general consensus is that
businesses experiencing a major incident and who don't have an effective
BCP will go out of business within 6-24 months of the incident.
You have insurance to cover you should the worst happen. A Business
Continuity Plan or at the least a Disaster Recovery Plan should help
protect you in the same way - by ensuring your business survives
whatever is thrown at it!
Our philosophy is simple - plan for the worst, hope for the best!
For more information or a free BCP/DRP consultation contact Secure
Thinking on 0845 071 4690 or visit http://www.securethinking.co.uk/

Monday, 2 May 2011

Information Security Posture - What's Yours Like?

Pretty much all modern businesses deal with information of some description. Whether it's basic day-to-day accounting data on your own business, financial records of other businesses and individuals, or detailed personal and medical files on thousands of people, information exists within your business.
Unfortunately, whatever information you have in your business there's a pretty good chance that someone else wants it. These people could be simple criminals out to make a fast buck, organised crime gangs running a profitable if somewhat corrupt operation, competitors willing to try a little industrial espionage, or even nation states using your business to gain international advantage.
And your size and stature doesn't always have to be substantial - indeed the Information Commissioner's Office here in the UK considers smaller businesses a weak link precisely because they are small and often unwilling to invest in effective information security controls, and because they frequently supply to or work on behalf of major corporations.
So we've established that your business handles information, and that a threat exists to that information. The next question is what are you currently doing about it?
If you have existing security controls in-place, are they effective, both in terms of costs and protection? Do your staff understand their role in protecting information? And can and should you be doing more?
Now unless you have an effective system for testing and assessing your information security controls it's doubtful you can answer these questions with any degree of certainty.
So how do you go about measuring the level of information security within your business?
The 1st option is to trust in fate and hope that you never experience a breach. The problem with this approach is that it relies on your organisation never being targeted. Now of course it may indeed never be targeted directly. But I'm sure you would agree that's not the most sensible approach. Especially when all evidence suggests such attacks are on the increase.
Another option is to implement a process of measuring your own security controls. If you have the skills and resources this might appear the best solution and that way you're not exposing your soft underbelly to 3rd parties. The downside of this is that like any internal process, you may be the victim of politics where the judgements and test results end up being skewed by internal issues and rivalries, making the results unreliable.
In addition, if reduced risk and improved security is your goal, with a long term objective of possibly gaining some kind of certification (such as ISO27001), then you really need an objective, unbiased opinion from a trusted business partner.
Which brings us to the 3rd option - find a suitable security assessment provider and have them do an assessment of your business.
Now obviously there are a number of solutions in this area. Fixed price offerings such as Secure Thinking's Quick Information Security Assessment (QISA) are primarily designed for small and medium sized organisations. If you are a lege business or need something more thorough you might opt for an assessment performed on a consultative basis by an experienced individual or business.
If you wish to go down the route of certification you might need help in choosing an appropriate certifying body and then assistance implementing the controls, policies and systems needed to obtain certification.
All of these services can be performed by a number of reputable companies, including Secure Thinking.
Whichever option you go for in the end you are far better off ensuring you properly assess your information security controls than simply crossing your fingers and hoping for the best. Your business and your customers are deepending on you!

Friday, 22 April 2011

Simplifying the Web Site Security Issue

Web site security vulnerabilities are a common problem but few web site owners, business operators or even web designers truly understand the nature of the problem. 

I wrote some time ago about why web site security is important for everyone but it is a hard concept to communicate to people who have little or no understanding of the technology involved in hosting a web site, Internet service or e-commerce business. 

So this article is an attempt to make a non-technical comparison which can be understood by anyone. 

Imagine you own a Conference Centre (your website). This facility has lots of rooms (pages) and attracts hundreds of attendees (visitors or customers computers) every day. Some attendees will come regularly for different courses or will cover the same course over and over again. 

Other attendees may have a quick look around and decide they aren't ready to do a course just yet. But may come back later. 

Unbeknown to you, one of the training rooms has a broken lock on the fire exit (vulnerability) through which every day a hypnotist enters. 

This hypnotist is a nasty person (malware) and he quickly hypnotises (infects) everyone in the room. He tells them to gather as much information on the financial transactions of those around them as they can. Then, when they hear the keyword "download", they will divulge all the information they have gathered and forget what they have done. 

So the attendees go off about their day-to-day activities and, without realising what they're doing, quietly gather the information. 

They collect the bank statements and account details of their family and loved ones, they watch as people enter PIN numbers at the checkout and they copy down and skim credit card details. 

They also collect security codes, PIN numbers and password used for non-financial purposes because they know people reuse them frequently and they may be useful. 

Then, a few days later a phone call arrives and the keyword is mentioned. The attendee passes everything they have gathered to the hypnotist. 

Days, weeks or months pass before anyone starts noticing. First it's a card transaction declined. Then it's bailiffs calling round and before long the reason is understood - the family and friends of the attendee have been the victims of identity theft and fraud, and have lost thousands. 

Tens, hundreds or even thousands of people have been robbed of thousands or even millions of pounds. 

Eventually, the auhorities trace the cause of the problem back to the Conference Centre but there's no sign of the hypnotist. 

All that happens now is the attendees lose confidence in the Conference Centre and stop coming. Very quickly the centre goes out of business. 

And all because the owner of the conference centre didn't make sure the facility was secure. 


Friday, 18 February 2011

Protecting Your Information - Laptop Encryption

At Secure Thinking, we are being asked more and more about how busy professionals can protect the business critical and often sensitive information they carry around on laptop and netbook computers.

The simple solution to this problem is to encrypt the laptop disk drive so that only the owner of the computer can access the data.

Most computers have a password which is used to prevent access to the software, applications and data in a casual fashion.  Passwords, and particularly strong passwords* are a vital component in preventing unauthorised access to information and applications.  However, they only protect systems that remain in the physical possession of the owner.

Once physical possession is compromised, as in the case of a lost or stolen computer, then there are ways of bypassing the logical access controls imposed by usernames and passwords.  Such bypass techniques can be as simple as using a brute-force password cracking tool or just simply removing the hard disk drive from the machine and plugging it in to another computer.

This can be a particular problem in the case of mobile computers, where the opportunity for loss or theft is far greater than machines protected by a secure physical environment.

Encryption of the hard drive can protect against the dangers highlighted above.  It means that, in effect, if the computer is lost or stolen, the data cannot be accessed by the new owner without the password or pass phrase used to perform the encryption.  In addition, where whole disk encryption is utilised, the system cannot even be started unless it is completely reinstalled - overwriting any data on the disk drive.

So if you want to protect your mobile computers, or even your office based ones should you feel the need, then contact Secure Thinking and we will be more than happy to go through your requirements and help you decide on the best solution for your business.


* Strong Passwords should be at least 12 characters long and consist of upper- and lower-case letters, numbers and special characters such as !'#@"£$ etc.  They should not be made up of dates, names or dictionary words - even obscure ones!

Wednesday, 2 February 2011

Secure Thinking When Online

If you run a small business or you manage the HR department of a large organisations you may well be aware of some of the issues surrounding staff use of social networking sites.

Social networking sites such as Facebook, professional networking sites like LinkedIn, and the various personal and professional blogging facilities, not to mention the micro-blogging sites like Twitter provide everyone with an opportunity to communicate with others with whom they have an affinity, voice their grievances and raise awareness of issues.

The problem for businesses and employers is when employees over-step the professional/social boundary.

If employees use social networking to make comments about the company, fellow employees, management or customers it can have a dire effect on business, perceptions and relationships both inside and external to the organisation.

Whilst many companies are aware of this and take some steps to mitigate the risk, it is often only done using a stick.  The general approach appears to be to discipline anyone who oversteps the mark - even when those marks aren't clearly defined.  This leads to further frustration and ultimately a breakdown in relations between employer and employee.

At Secure Thinking, we believe that this approach is wrong and have now decided to do something about it.  We are therefore offering a new awareness service - Secure Thinking When Online - where we will come on site at your company, or other location, and present to your staff about the risks of online behaviour, why the rules exist and how to protect themselves in their everyday internet based activities.