Deals from Amazon

Showing posts with label IT Security. Show all posts
Showing posts with label IT Security. Show all posts

Wednesday, 13 July 2011

Do Web Developers Avoid Scrutiny?

Due to the nature of our business we speak to many people in various industries and something is becoming more and more clear as time goes by – website and web application developers are reluctant to have the security of their work scrutinised.

I understand their dilemma – if they have their solutions security tested it will add to their costs and increase the price of their product.  Or it may affect client beliefs that the products they deliver are already secure.  

Then there is the hosting company who provide the hardware and infrastructure which allows websites to be accessed – some of the security issues may lie there, so why would the site developer worry about security?

Indeed, I had a conversation recently with a website development company who didn’t want their product security tested because to do so may imply that they aren’t building things properly in the first place.  They went on to point out that if the client discovers a security issue in the application later, they can charge them again for fixing it!

The other problem is one of accountability.  In the recent attacks against Sony, Sega and others it is the company or organisation attacked that gets the bad press and the flak, not the company they got in to develop the website or application.

This means the website developers get off scot-free with the probably loss of just that piece of work or client.
So how do we change this?  What should companies and organisations do to ensure the work done for them is of a high enough standard?

Well here are a number of suggestions:

1.       Ask them about the security measures they build in to your solution.  If they’re vague or evasive find another supplier.  Have whatever response you get evaluated by an expert.

2.       Ask them up-front if they have the site independently security tested or whether they are happy for you to do so once the solution is complete but before you pay for it.

3.       Ask them to guarantee the site’s security, or at least provide fixes for free should security vulnerabilities be identified later.  Make sure this is in the contract.

4.       If they do security test the solution find out if it is truly independent and whether the site will receive any accreditation in the form a security seal or other certificate.

At the end of the day, if you employ a website developer to create your website it’s still your data, reputation and profit that’s at risk if your security isn’t up to scratch.  Is that a risk you’re willing to take?

For more information on website security in general and website security auditing contact Secure Thinking on 0845 071 4690 or visit www.securethinking.co.uk

Friday, 24 June 2011

Online Backup Service - Selection Criteria

There are many online backup and “cloud” data storage/sync solutions available via the internet.  Some offer free backups and the paid ones start from as little as £5/month.
But before you run off and pick a backup service for your critical business data based on price alone here are a few things you should consider during the selection process:

1.     Offsite Data Storage

Obviously with an online solution it has to be offsite but if you share data centre space in managed facilities make sure your data isn’t being stored in the same facility as your servers.  If it is then find another provider or make sure your provider has point 14 covered.

2.     Easy to setup

There’s no point picking a backup solution which requires you to be an IT technical guru – even if you are one!
Therefore your chosen solution should be easy to setup and configure whether that’s by your or the technical team from the vendor.

3.     Automatic

It goes without saying but your backup solution has to look after itself.  If it doesn’t then stay away as you’ll simply be buying yourself more work and the time you forget to run a backup is the time you’ll need your data to be recovered.
Also, it’s a good idea to select a service you can use to backup your data based on a schedule.  If you save your files at the end of one day you don’t want to have to wait a day, or over the weekend for them to be backed up.

4.     24 x 365

Just like it being automatic, there’s no point in having a backup solution that’s only available Monday to Friday 9am-5pm!  You need maximum availability to ensure your data is backed up when you need it to be and that you can recover the data as quickly as possible in the event of a disaster.

5.     Simple Restore

If a disaster does strike your business and you need to restore data from your backups it needs to be as simple and easy as possible.  In a real disaster, you and your business are probably already in a world of pain and worrying about getting your data back shouldn’t add to your problems.

6.     Monitored on your behalf

Why worry about things you don’t have to?  Your backup should just happen and only notify you if there’s a problem.  But you need to know that it’s working correctly and be comfortable with the solution to have real faith in your backups as a disaster recovery tool.

7.     Wide Compatibility

Compatibility of your backup solution is vital.  Just because you use Windows 7 Desktop and MS Office now doesn’t mean that’s what you’ll always use and you need to make sure you can recover files, folders and other types of data when you need them on whatever platform you’re using.
Also, a wider range of supported platforms and applications will likely mean a more rounded and thoroughly tested product.
 But there are other benefits to a wide range of compatibility – namely that your backup service will integrate better with software applications and database products meaning you can recover finer grained layers of data.
One example of this is single mailbox recovery in MS Exchange.  Without a good level of compatibility and integration, all you can recover should you have a problem with MS Exchange email, is the entire email data set.  This in turn means you have a considerable amount of work to do to get a single mailbox back from a multi-user backup, even assuming you have the space and ability to bring back a full copy of your email system without overwriting the active one.
However, with a fully integrated product it is possible to recover individual mailboxes without a major amount of work.
So when choosing your backup service provider, have a close look at the level of compatibility and integration and make sure that it is covering all of your critical data, files and folders and bear in mind any future requirements you might have.

8.     Transmission Encrypted

The security of your data is paramount.  After all it’s why you’re backing it up in the first place.  It’s also why the transmission of your data across the internet or other networks should be encrypted.
Encrypted data transmission ensures that your data can’t be intercepted and read/accessed by anyone or anything else between your computers and the storage facility used by your chosen provider.

9.     Data Compression

This is a really handy feature and should be available in the backup solution you choose.  Essentially data compression means that the amount of data actually transferred between your computer and the storage facility is less than the amount of data on your computers.
Compression takes the data you have and squashes it down into smaller, tighter packages for transmission over the internet.
This means you don’t use or need huge amounts of bandwidth and large data transfer allowances to make use of an online backup solution.

10.Storage Encrypted

This is potentially where we start to see the largest difference between online backup providers – how and where your data is stored and who has access to it.
Your data must be stored encrypted once it lands at the remote storage facility.  Otherwise your data could be accessed by anybody who has or gains access to their network or facilities.
Ideally, only you should have the encryption key used to protect your data – see point 11.

11. No Access to Data by Provider/DC Staff

Whilst many backup and online “cloud” storage providers claim your data is encrypted on their system that doesn’t always mean what you think.
A truly encrypted solution would mean that no-one other than the individual or group who know the encryption key can actually access the data.
Many online backup and cloud storage solutions do indeed encrypt the data but it is done by them, and they have the encryption keys.  This also means that they potentially have access to your data and you’re not likely to know if anyone else accesses it.
So choose your backup solution carefully, particularly if you manage sensitive data.

12. Data Centre Locations

Where is your data physically stored once it leaves your network?  Are the data centres used by your backup provider located in your home country?  Or are they elsewhere such as within the EU or US?  Do you even know?
One thing to bear in mind when selecting an online backup provider is where your data ends up.  Different nations and regions have different laws on data protection, due process and lawful searches.
If your data is no longer in your own country then it is no longer under the protection of your nation’s legal system and could be subject to access based on processes which would hold little or no sway in your own country.
And remember, ultimately if your data security is breached and you fall under the legal or regulatory jurisdiction you may be liable for the breach – even if it occurs elsewhere in the world.  You can outsource your data storage but you can’t outsource the responsibilities and liabilities attached to that data.

13. ISO27001 Certified Data Centres

Ideally, the data centres used to store your backups should be certified as secure to an internationally recognised standard such as ISO-27001 Information Security Management standard.
This should give you confidence that your data is safe and the service providers are taking their information security responsibilities seriously.

14. Geographical Secure Data Centre Replication

You’re taking precautions and backing up your data.  That’s very commendable and responsible of you – too many don’t even bother to do that!
But does your solution provider take the same precautions?  If you need to recover a file or two, or your entire data collection will the service provider’s systems be up and available?  Are they replicating the data you’re entrusting to them to a geographically separate location to ensure its availability should they encounter and issue at their primary data centre?
If you’re backing up your data, you’re doing so for a reason – to protect it.  Now you might feel that your copy and the copy they have in the “cloud” is enough security for your data.  But if you’re paying for a service you might as well pick one that maximises your protection and ensures you can access your data when you need it most.
After all, if it can go wrong it will and reducing the “single points of failure” in any technical solution increases the resilience and availability of the whole solution.

15. Free technical support

Finally, if you’re paying for a backup solution are they offering you free technical support or is it all premium rate numbers you can’t get hold of or a helpdesk you can only call during set (and usually inconvenient) hours?
Hopefully you won’t need technical support, but if you do it’s nice to know they’re there when you need them!

So there you have it – the criteria we use and therefore recommend you use for choosing an online backup or cloud data storage/sync solution for your business.

Wednesday, 25 May 2011

Data Backup Considerations

Data is vital to modern businesses.  Some say it's the life blood of a business.  After all we live in the information age.

But do we all protect data and information to the best of our abilities?  Do we ensure we can recover from its loss, corruption or theft?

In information security parlance are we properly protecting its CIA - Confidentiality, Integrity and Availability?

Most businesses take some steps to backup their data. This can be using traditional methods such as tape drives to newer techniques involving optical media, removable USB storage or even online backup solutions.

If you're not backing up your data then you should be. It's inexpensive and might just save your business one day.

But backing up your data is only half the story.  Having a backup is meaningless if you can't recover your data in the event of an incident.

You need to test that you can restore your data on a regular and random basis.  This exercises your solution and ensures it is actually doing what you expect of it.

Another consideration is the age and technology used.  If your infrastructure, devices and backup software are more than a few years old you may have other problems should you experience a significant incident or disaster with your systems.

If your incident takes out your current infrastructure can you replace it to actually recover your backups?

Without compatible technology and software your data may be inaccessible without expensive and time consuming 3rd party services.

Then there are online solutions.  There are many of them out there and they are fairly inexpensive but which one should you choose?

Depending on the data and the legal or regulatory requirements you may need to think very carefully. Your data may fall under one jurisdiction while it's residing on your servers and PCs in your office but whose jurisdiction is it under the control of on the backup storage?  What are their data protection, privacy and security laws like?

Is the data stored encrypted where only you can access it or can the staff at the service provider actually access your data, with or without your permission?

These are all things you need to consider when selecting a backup solution.  It isn't a simple choice based on price so think carefully and ask the questions above. They might just stop you going out of business.

In the meantime if you are looking for an online backup solution why not contact us on 0845 071 4690 or visit www.SecureThinking.co.uk and ask us these questions?

Monday, 2 May 2011

Information Security Posture - What's Yours Like?

Pretty much all modern businesses deal with information of some description. Whether it's basic day-to-day accounting data on your own business, financial records of other businesses and individuals, or detailed personal and medical files on thousands of people, information exists within your business.
Unfortunately, whatever information you have in your business there's a pretty good chance that someone else wants it. These people could be simple criminals out to make a fast buck, organised crime gangs running a profitable if somewhat corrupt operation, competitors willing to try a little industrial espionage, or even nation states using your business to gain international advantage.
And your size and stature doesn't always have to be substantial - indeed the Information Commissioner's Office here in the UK considers smaller businesses a weak link precisely because they are small and often unwilling to invest in effective information security controls, and because they frequently supply to or work on behalf of major corporations.
So we've established that your business handles information, and that a threat exists to that information. The next question is what are you currently doing about it?
If you have existing security controls in-place, are they effective, both in terms of costs and protection? Do your staff understand their role in protecting information? And can and should you be doing more?
Now unless you have an effective system for testing and assessing your information security controls it's doubtful you can answer these questions with any degree of certainty.
So how do you go about measuring the level of information security within your business?
The 1st option is to trust in fate and hope that you never experience a breach. The problem with this approach is that it relies on your organisation never being targeted. Now of course it may indeed never be targeted directly. But I'm sure you would agree that's not the most sensible approach. Especially when all evidence suggests such attacks are on the increase.
Another option is to implement a process of measuring your own security controls. If you have the skills and resources this might appear the best solution and that way you're not exposing your soft underbelly to 3rd parties. The downside of this is that like any internal process, you may be the victim of politics where the judgements and test results end up being skewed by internal issues and rivalries, making the results unreliable.
In addition, if reduced risk and improved security is your goal, with a long term objective of possibly gaining some kind of certification (such as ISO27001), then you really need an objective, unbiased opinion from a trusted business partner.
Which brings us to the 3rd option - find a suitable security assessment provider and have them do an assessment of your business.
Now obviously there are a number of solutions in this area. Fixed price offerings such as Secure Thinking's Quick Information Security Assessment (QISA) are primarily designed for small and medium sized organisations. If you are a lege business or need something more thorough you might opt for an assessment performed on a consultative basis by an experienced individual or business.
If you wish to go down the route of certification you might need help in choosing an appropriate certifying body and then assistance implementing the controls, policies and systems needed to obtain certification.
All of these services can be performed by a number of reputable companies, including Secure Thinking.
Whichever option you go for in the end you are far better off ensuring you properly assess your information security controls than simply crossing your fingers and hoping for the best. Your business and your customers are deepending on you!

Friday, 22 April 2011

Simplifying the Web Site Security Issue

Web site security vulnerabilities are a common problem but few web site owners, business operators or even web designers truly understand the nature of the problem. 

I wrote some time ago about why web site security is important for everyone but it is a hard concept to communicate to people who have little or no understanding of the technology involved in hosting a web site, Internet service or e-commerce business. 

So this article is an attempt to make a non-technical comparison which can be understood by anyone. 

Imagine you own a Conference Centre (your website). This facility has lots of rooms (pages) and attracts hundreds of attendees (visitors or customers computers) every day. Some attendees will come regularly for different courses or will cover the same course over and over again. 

Other attendees may have a quick look around and decide they aren't ready to do a course just yet. But may come back later. 

Unbeknown to you, one of the training rooms has a broken lock on the fire exit (vulnerability) through which every day a hypnotist enters. 

This hypnotist is a nasty person (malware) and he quickly hypnotises (infects) everyone in the room. He tells them to gather as much information on the financial transactions of those around them as they can. Then, when they hear the keyword "download", they will divulge all the information they have gathered and forget what they have done. 

So the attendees go off about their day-to-day activities and, without realising what they're doing, quietly gather the information. 

They collect the bank statements and account details of their family and loved ones, they watch as people enter PIN numbers at the checkout and they copy down and skim credit card details. 

They also collect security codes, PIN numbers and password used for non-financial purposes because they know people reuse them frequently and they may be useful. 

Then, a few days later a phone call arrives and the keyword is mentioned. The attendee passes everything they have gathered to the hypnotist. 

Days, weeks or months pass before anyone starts noticing. First it's a card transaction declined. Then it's bailiffs calling round and before long the reason is understood - the family and friends of the attendee have been the victims of identity theft and fraud, and have lost thousands. 

Tens, hundreds or even thousands of people have been robbed of thousands or even millions of pounds. 

Eventually, the auhorities trace the cause of the problem back to the Conference Centre but there's no sign of the hypnotist. 

All that happens now is the attendees lose confidence in the Conference Centre and stop coming. Very quickly the centre goes out of business. 

And all because the owner of the conference centre didn't make sure the facility was secure. 


Friday, 18 February 2011

Protecting Your Information - Laptop Encryption

At Secure Thinking, we are being asked more and more about how busy professionals can protect the business critical and often sensitive information they carry around on laptop and netbook computers.

The simple solution to this problem is to encrypt the laptop disk drive so that only the owner of the computer can access the data.

Most computers have a password which is used to prevent access to the software, applications and data in a casual fashion.  Passwords, and particularly strong passwords* are a vital component in preventing unauthorised access to information and applications.  However, they only protect systems that remain in the physical possession of the owner.

Once physical possession is compromised, as in the case of a lost or stolen computer, then there are ways of bypassing the logical access controls imposed by usernames and passwords.  Such bypass techniques can be as simple as using a brute-force password cracking tool or just simply removing the hard disk drive from the machine and plugging it in to another computer.

This can be a particular problem in the case of mobile computers, where the opportunity for loss or theft is far greater than machines protected by a secure physical environment.

Encryption of the hard drive can protect against the dangers highlighted above.  It means that, in effect, if the computer is lost or stolen, the data cannot be accessed by the new owner without the password or pass phrase used to perform the encryption.  In addition, where whole disk encryption is utilised, the system cannot even be started unless it is completely reinstalled - overwriting any data on the disk drive.

So if you want to protect your mobile computers, or even your office based ones should you feel the need, then contact Secure Thinking and we will be more than happy to go through your requirements and help you decide on the best solution for your business.


* Strong Passwords should be at least 12 characters long and consist of upper- and lower-case letters, numbers and special characters such as !'#@"£$ etc.  They should not be made up of dates, names or dictionary words - even obscure ones!

Wednesday, 2 February 2011

Secure Thinking When Online

If you run a small business or you manage the HR department of a large organisations you may well be aware of some of the issues surrounding staff use of social networking sites.

Social networking sites such as Facebook, professional networking sites like LinkedIn, and the various personal and professional blogging facilities, not to mention the micro-blogging sites like Twitter provide everyone with an opportunity to communicate with others with whom they have an affinity, voice their grievances and raise awareness of issues.

The problem for businesses and employers is when employees over-step the professional/social boundary.

If employees use social networking to make comments about the company, fellow employees, management or customers it can have a dire effect on business, perceptions and relationships both inside and external to the organisation.

Whilst many companies are aware of this and take some steps to mitigate the risk, it is often only done using a stick.  The general approach appears to be to discipline anyone who oversteps the mark - even when those marks aren't clearly defined.  This leads to further frustration and ultimately a breakdown in relations between employer and employee.

At Secure Thinking, we believe that this approach is wrong and have now decided to do something about it.  We are therefore offering a new awareness service - Secure Thinking When Online - where we will come on site at your company, or other location, and present to your staff about the risks of online behaviour, why the rules exist and how to protect themselves in their everyday internet based activities.



Thursday, 30 December 2010

New Year's Resolution

It's that time of year again when we all make new year's resolutions.  It's pretty much par for the course.  We will be all enthusiastic for the 1st few days or maybe even weeks (if you're really keen).  Then it will all tail off into nothing.

The same story happens every year - why should this be any different?

Well how about setting a New Year's Resolution you can stick to?  One that will enhance your professional and business reputation?  One that will bring huge benefits to your organisation?

The New Year's Resolution I'm talking about is to call Secure Thinking and let us see if we can help you improve the Information Security within your business.  We can look at your current  information security policies, procedures and controls and investigate whether they are effective and are protecting your business interests.

We can also help you out with ongoing information security management which can plague businesses and is frequently ignored by busy owner managers.

So whatever information and IT security needs you may have, whether you require help with business processes such as security policies, procedures and standards, with employee education  in the form of awareness, guidelines and training, or with technical solutions such as anti-virus, encryption and secure backups, contact Secure Thinking now and make this year's resolution one that truly benefits you and your business!




Friday, 24 December 2010

Merry Christmas

Secure Thinking would like to wish all our staff, customers and contacts a very Merry Christmas.

Let's hope Santa brings you everything you need, and protects your information, identities and finances!

Have a good one!

Lee


Wednesday, 24 November 2010

10 Information Security Tips for Businesses

Businesses are recognising the importance of the information they manage, and more companies than ever deal with sensitive information on a regular basis.  So whether you are a one-man-band or a multi-national corporate entity here are Secure Thinking's 10 Information Security Tips for Businesses:

1. Implement policies and guidelines
Implement policies, processes and guidelines - the rules of the game - that are appropriate for your organisation.  This means a top-down approach to information security showing that your organisation is committed and willing to invest in protecting it's data.  Remember that often, the simplest solution is the best so keep your rules simple because doing so makes them easier to follow.

2. Lead by example
Senior level buy-in is vital but business owners and senior management must also follow the same policies and guidelines, otherwise it becomes a pointless exercise as staff will bypass them in the same way.  That means it's vital to lead by example, showing your team that you take information security seriously.

3. Staff education and training
It may seem obvious, but if you don't educate your staff on their information security roles and responsibilities then you can't expect them to provide effective protection for your data.  You should not only teach your staff what they have to do and the rules they must follow but also why it is important to you, how they do it and who they should speak to if they have any questions or issues.  It is important here to make the process as entertaining and fun as possible as it is seen often as a very dry, if not dull topic.

4. Business processes
It is important to implement appropriate business processes in your organisation and to align them with your information security policies as much as possible.  Otherwise it may become easier to bypass the controls you have implemented in order to achieve your business goals.

5. Technical solutions
In the same way as it is important to have appropriate business processes, it is also vital to implement appropriate technical solutions.  Many organisations see IT as the driving force in protecting their data.  However, this is not the case.  IT is simply one of the tools available and you therefore have to ensure your technical solutions and IT systems provide your organisation with the protection it desires in line with your information security policies.

6. Spot checks
A good way to ensure your staff follow your information security rules is to employ a regime of spot-checks.  It is important that this should be done to raise awareness of issues and not as a method of punishing those that fail to follow the rules, after all you need your employees to buy-in to the spirit of the program not merely follow instructions like sheep.  A great way of achieving this is to encourage staff to come up with ideas for improving security and reward the best ideas.

7. Test and measure
In addition to performing your own spot-checks, it's a good idea to employ an external agency or consultancy to test your security controls on a regular basis.  Many corporate bodies have regular penetration tests of IT infrastructure and less frequent tests of physical security.  Smaller businesses might see this as overkill but unless you actually test your controls you have no idea as to their effectiveness!

8. Check your suppliers
Most companies make use of 3rd party service providers.  Whether it's for your IT, web hosting, accountancy or legal operations it's important to ensure your suppliers take the same care and consideration over their information security (and yours) as you do.  It's no use having fantastic information security controls only for every Tom, Dick and Harriet at XYZ IT Support Company to have access to your sensitive data because they provide your IT support services.  Take the time and ask questions - ask to see their policies, how they vet their staff, and what controls they employ to protect your data.  At the end of the day, protecting your data is your responsibility.

9. Plan for the worst, hope for the best
In the same way that it's a good idea to have business insurance, all companies should invest in a Business Continuity Plan.  This means looking at the threats to your business, the risks posed by them and how you respond in order to continue operating should the worst happen.  Your Business Continuity Plan needs to cover all the high risks to your business and should be tested and reviewed on a regular basis to ensure it meets your changing operational requirements.  Obviously, testing a Business Continuity or Disaster Recovery Plan completely may be prohibitively expensive but there are ways of assessing the plan without necessarily having to buy hardware or pay for office space.

10. Incident response
Although having all the policies, processes and guidelines, the correct technical solutions, and excellent staff awareness will give you the best chance of not having an information security breach, it doesn't guarantee it.  Therefore, it is essential that you have a clearly defined process for responding to an incident.  This should include reporting points, escalation, evidence gathering and media management.  It should also clearly define the roles and responsibilities for relevant personnel and how your organisation reports the breach to the relevant authorities - be they law enforcement, the Information Commissioner or regulatory bodies - and of course how you inform the individuals or companies concerned.




Wednesday, 3 November 2010

10 Client Site InfoSec Rules

If you're working on a client site, in addition to obeying their rules and policies on information security here are Secure Thinking's 10 Client Site InfoSec rules you should employ  to keep yourself and your information safe and protect the client.

1. Never leave equipment unattended
Laptops, phones, disks, memory sticks etc., should be taken with you, locked away securely or, in the case of laptops, locked to something solid with a Kensington style lock if they have to be left unattended.

2. Use encryption
Encrypt laptops, external disk drives, USB sticks to protect the data on them whilst on the move.  This will help to protect your data should you lose an item of equipment or it is deliberately targeted.

3. Operate a clear desk policy
Even if the client doesn't operate a clear desk policy, you should.  Never leave papers or other media on unattended desks.  Lock it away or carry it with you.

4. Leave sensitive information where it belongs
Don't carry sensitive information in bags, briefcases or laptop cases unless it's directly relevant to the work you're engaged in. If you do carry sensitive information, keep it in a secure bag and don't leave the bag unattended.

5. Never send unencrypted data or emails over public or client wi-fi networks
Just because your client trusts their wi-fi network doesn't mean you should.  Only send non-sensitive information over non-secure networks.

6. Never directly connect to client networks
Unless it is essential for your role never directly connect your systems to their network.  This is to protect them and you!  You don't know their network is secure and virus free and they don't know your system is.

7. Always lock your screen
When not working on your computer or laptop make sure it is locked and set a low timeout value for the automated screen lock.  This helps to prevent your system being accessed should you become distracted.

8.  Only work on that client's data
Never work on another client's data while on-site at a different client.  There are a whole host of potential legal and regulatory issues you could be opening yourself up to and you've no idea who might be interested in snooping over your shoulder.

9. Keep your equipment up-to-date and secure
I know it's a common one but you should ensure your Anti-Virus, Anti-Spyware, Operating System and other software packages that you use are patched up-to-date, you should also disable all unnecessary applications and services, and have your firewall enabled.

10. Don't use removable media
Unless it's essential to your work, don't use removable media to transfer data between your system and client systems.  If you do have to use a USB stick or other device, ensure you have auto-run functionality disabled (preferably on both systems) and ensure the device is virus scanned at both ends.  Use a brand-new device where possible and encrypt it if it's practical.





Friday, 1 October 2010

Mobile & Social Networking Apps

The subject of 3rd party "Apps" has raised its head again - this time on Google Android smart phones.

Apps on smart phones and on social networking sites are becoming ever more popular, but are the intentions of the App developers always in the best interests of the users?

A recent study of the apps on Android mobile phones has shown that the data they access and how they use it does not always tally with what the user authorises when they install the app.

This becomes even more of an issue where apps are downloaded or installed from other, shall we say less reputable sources.

There has also been occurrences of apps being developed reusing code segments created by other developers. This could lead to all kinds of unauthorised or malicious use of personal data which even the app creator doesn't know about.

So here are some simple rules to follow to enhance your security and protect your data:
  • Don't use apps unless you really need to
  • Only install apps from reputable sources
  • Only install apps that are essential for you
  • Remove apps you no-longer use
  • Always read what data will be collected by an app
  • If in doubt don't install it
  • Don't provide an app with access to sensitive information or don't place sensitive information in a location an app has access to

Tuesday, 28 September 2010

Location Based Services & Security

It seems that more and more location based services are surfacing, jumping on the Social Media bandwagon.

Now, I'm not an old fuddy-duddy, and I can see how some of these services might be of use to businesses and potentially to individuals. I do however, have massive concerns over the privacy and security of these services.

Firstly, there is the physical security aspects. The information about where you are could be used to target you personally for malicious intent. This could range from mugging you as you leave a venue to burgling your home while you're out.

Then there are the issues of who has access to this information. There are various rules and laws which apply to data protection but under what jurisdiction are you accounts being managed? Who both from a staffing point of view and a company point of view has access to the information? Are your locations, movements and habits being observed, monitored and assessed for other reasons - some of these may be purely for targeted marketing but others could be for more insidious purposes?

I have been critical in the past of individuals who post on Twitter, Facebook and other social networking sites with too much detail about where they are and what they are doing. Now we have services specifically designed to post and collect this information.

The simple fact of the matter is that people will leave themselves open because there are multiple, complicated options on the security settings page - will every user truly understand them all? And how do you know all of your "friends" are the only ones viewing your information? It could be that their accounts have been compromised or that you have mistakenly added a "friend" who isn't who you think it is.

My philosophy is this - whatever you share on the internet, even just to "friends" you should consider it public domain. Don't tell anyone anything, say you are or have been anywhere, or opine about something you wouldn't want your mother, your boss or the rest of the world to know! That way, you can protect yourself, your identity and your information.




Thursday, 12 August 2010

Why Website Security is Important for Everyone

Most websites, whether owned by an individual, an organisation or a business, are never security tested. Many see it as an irrelevant or unjustified expense, citing the fact that it’s mainly static content, there’s no sensitive information held on the site, it doesn’t accept financial transactions, etc., so there’s no point in potentially expensive web security testing, as the business or organisation can’t be affected by insecurities.

Well, to put it simply, this is not true!

Whilst your website might not contain sensitive information, might not accept any financial or personal transactions, and may be purely static content, you are still putting your clients and website visitors at risk.

Cyber criminals, of which there are many, are not necessarily interested in gaining access to your business and its information – although you are always a likely target – but they ARE after your customers. They want access to their computers and their details and they can use the vulnerabilities in your website to get that access.

More and more often, we are seeing ordinary websites used to load malicious software onto the computers of unsuspecting victims. Cyber criminals are scanning the internet, looking for any websites which are insecure and are loading them with malicious software (called ‘malware’). This in turn is then passed on to the computers of every visitor to your site in what is known as a “drive by attack”, exposing them to all kinds of issues such as identity theft, bank account skimming and credit card fraud.

So whilst your organisation may not be affected directly by your website security problems, there is a huge amount of damage that can be inflicted on your customers and passing visitors, for which you are at least partly to blame.

This has now reached a point in the US where victims of such incidents are taking the website owners to court for compensation. And whilst this may not be likely to happen in the UK or elsewhere, there is certainly the potential for it, particularly where an incident can be traced back to a specific website.

If every person who merely looked at your premises was in danger of some injury, you would rightly take steps to prevent it. So why wouldn’t you take such a course of action in the virtual world of the internet, where such damage can be just as serious?

Information Security for SMEs

If you run a small or medium sized enterprise, then you’re probably up to your eyes in government red-tape, and legal and regulatory obligations, and that’s before you start to actually run and operate your business in order to make a living.

A key component in the smooth running of your business is information. That information may take on many forms – customer or supplier details, financial data or secret recipes for the perfect carrot cake – whatever it is, it is vital to your organisation. As such you need to make sure it is protected, kept from your competitors, guarded against public disclosure and available as and when you need it.

This is why good information security management and practices are as important to you as they are to the ‘big boys’. The major banks and corporations employ dedicated staff to manage their information security risks. You probably don’t have that luxury, but you still need someone to take responsibility for information security.

At this point, many SME managers and business owners claim they don’t have the time for information security, they don’t have the resources, it isn’t important to them, or they can’t afford it. After all, you’re only a small business, your IT people take care of that side of things, and you’re not at risk.

The information and data you use on a daily basis is the lifeblood of your business. Can you imagine if you had none of it? If one day you turned up at the office and all of your paperwork was blank? All of your computers had been wiped? Where would that leave you?

But it isn’t just the total loss of information that is of concern in the modern world. Criminals, including the so-caller ‘cyber’ criminals, want your information and my information. They want personal and financial details from as many people as they can for a variety of reasons, including identity theft. Even corporate data is now a target for the unscrupulous members of society.

So how would your company survive, particularly in the current economic climate, if it was discovered that your customers’ bank accounts were being drained, that identity thieves had access to personal data that could only have come from your business?

Apart from the obvious, potentially fatal, legal and regulatory fines, a well publicised incident of this nature would have a disastrous effect on your brand and business reputation. Even accidental disclosure of sensitive personal information is jumped on by the press, and that is without any direct criminal involvement.

If you hold personal information relating to living individuals, you fall under the jurisdiction of the Data Protection Act (DPA), if you handle financial information for individuals or other businesses you are very likely regulated by the Financial Services Authority (FSA), and if you handle credit and debit card payments you will almost certainly have to comply with the Payment Card Industry Data Security Standards (PCI-DSS). All of these mean you must adhere to minimum standards for information security for regulatory and/or legal reasons.

At the end of the day, information security is as important to SMEs as it is to anyone, so the question isn’t really “why do you need to worry about information security?” but “can you afford NOT to worry about information security?”

Why information security is NOT just an IT issue

Time and again, when I talk to business owners and managers about information security, I get the line “that’s an IT issue” or “our IT guys look after that”.

Whilst I’m well aware that IT and IT security plays a significant role in information security, it is not the Holy Grail many people seem to think it is.

IT is not some kind of magic wand, to wave over your information assets to suddenly make them secure. The careful and appropriate use of IT solutions is an enabler of information security. It is a method of securing your information and data whilst being used or accessed electronically.

Information is available throughout your organisation in a whole host of formats. Hardcopy printouts, hand-written documents and notes, and doubtless shelves of folders and binders, all make up a substantial element of your business information.

This information needs to be kept secure also.

But, by making information security and IT issue, many senior managers feel they have done their duty, and allocated it some someone who can deal with it. The problem here is that without senior management buy-in, and a top-down culture of security and security awareness among non-IT staff, the ‘IT Crowd’ can only achieve so much.

Often, IT security controls and processes, implemented without the understanding and buy-in of non-IT staff, will be circumvented. If staff feel that IT is getting in their way, they will do everything they can to work around it or subvert the controls. This is how we end up with users sharing logins or passwords, or documents being emailed to large groups of people because “Joe can’t access them”.

To successfully implement an information security programme, managers and business owners need to take ownership themselves. They need to be involved in writing the policies and procedures. They need to educate their staff and system users as to WHY they need to adhere to the policies, HOW to do it and WHAT the consequences will be if they are not followed. They can then use the available IT solutions to assist with the businesses information security policies, approach and objectives.

Information security is NOT an IT issue, but done properly IT can help you achieve your information security aims. You just need to make sure you’ve defined your business objectives beforehand, and educated your staff along the way.