Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Wednesday, June 6, 2007

Back from the dead ... and more concerned than ever!

So this blogging is harder to keep up with than I expected. I can't believe it's June already. Let me catch you up quickly on the last month:
  • My company has gone through significant growth - our unique approach to security and risk assessments has really caught on and we're hiring people as quickly as we can find them. If you're a CISSP or have a similar background, please call me!
  • I have attended several regional trade shows and conferences over the past month. Some were security related, but most were not. As a result, I have spent a lot of time talking with people who are not "security experts".
  • I have also spent significant time speaking with IT directors and leaders in local and regional government bodies.

And after a month of talking and listening, listening and talking, here's what I see:

  • Everyone seems to accept that security issues are real and that they are at risk.
  • If you haven't been breached, the risk you're under is acceptable. I would be a rich man if only I had a dollar for every version of, "it won't happen to me" that I have heard.
  • The security threats - particularly in the area of social engineering - are becoming more prevelent and are attacking smaller and smaller organizations. I recently ran into the president of a company in rural Pennsylvania - Amish country - whose A/R person was deceived into giving away banking information. They are a 24 person company.

Folks - what's it going to take?!?! At some point, this is going to become irresponsible behavior to keep ignoring these issues. (In fact, California is currently considering forcing companies who have been breached to cover all costs for consumers and businesses who have to deal with their information being compromised)

This blog REALLY isn't intended to be a commercial for my company. But it drives me crazy that we have the resources and ability to help protect you, your company and your customers - but you won't let us. (obviously, I don't direct that to our customers - you guys I love!) :-)

I know this sounds like a rant - and it is - but it's also a plea. As a business owner, you have a responsibility to protect your customers. Do the right thing. Your I.T. people don't have the depth - trust me - they don't. It's not their fault - I'm sure they do a great job keeping the business running. But security is a full time job and they just don't have the time.

So bring in a professional organization. If you don't like me or Pervasive Solutions - no problem. I'll even recommend some others for you if you want. But find someone you can trust and have them help you. At a minimum, here are the things you should be doing every 9 - 12 months:

  • End-user security awareness training: help your employees understand the importance of security and the threats that they may face.
  • External network vulnerability assessment: find out what risks exist on your network
  • Network and server configuration assessment: help your I.T. team build security into your infrastructure instead of trying to bolt it on afterwards
  • Policy & procedure review: establish and review your security policies and procedures, both for your I.T. team and your company as a whole, to set expectations and protect the company from compliance and litigation risks

I know these may sound like a lot. But I assure you, they aren't. For only a few thousand dollars per year, you can cover 80% of your risk with just these four steps. Certainly, I would suggest that you eventually conduct complete, thorough security and compliance risk audits which will dig deep. But don't worry about that now. Just do the basics. If you do, you'll be ahead of your peers who are still burying their head in the sand.

It's like the old joke, "if we get chased by a bear, I don't have to outrun the bear - I just have to outrun you." Make your company a smaller target - sure, you'll still be a target - but there will be bigger targets all around you.

Friday, March 16, 2007

Why your data is more likely to be stolen than your car

If you decided to shed your morals and take up a life of crime, how would you do it? Would you rob banks? Would you steal cars? If you're a reasonably intelligent crook, you're going to carefully consider all of the risk vs. reward data that you can find. If you are a computer-literate crook, I'll give you one guess where you'll find the greatest reward and the lowest risk of being caught.

Cybercrime.

It's just a fact. Last night, I attended a lecture given by George Kurtz, co-author of the book, Hacking Exposed, and currently SVP at McAfee, Inc. According to George, McAfee and the hundreds of researches they employ, cybercrime is now a $105 BILLION industry. And it makes absolute sense. The criminals have become so technically innovative in the way they launch attacks that it becomes nearly impossible to track them down and arrest them.

Countries like Russia, China, India and many others with lax industrial espionage and intellectual property laws also have large numbers of impoverished people. With little law enforcement, access to the world's networks via the internet, and a glut of how-to information freely available, organized crime is training cyber-criminals by the hundreds and making millions and millions of dollars every month.

When you combine high reward, low risk and abundant opportunity, you get a form of crime that is far safer, and more profitable, than traditional crime.

Why does this matter to you? Are you thinking, "OK, but I'm just a nobody" or "My 200 person company isn't big enough to attack" or "With all the computers on the web, what is the likelihood they're going to find me?" If you are, consider this:

Gartner research indicates that between 2007 and 2010, mid-market American companies will become the primary targets of a large percentage of cybercrime.

Again, the reasons are simple:

  1. Most network attacks are not targetted attacks against a particular business. Rather, they operate like a fishing net, thrown into the ocean to see what it catches.
  2. Enterprise-level organizations, generally, have spent the last several years improving their security infrastructure so that they don't get caught in these nets.
  3. The SMB sector lacks the resources and expertise to defend themselves. You may have an IT team, but unless you have at least one resource dedicated to security, I will guarantee you that your IT team is not adequately protecting you. They're just too overloaded and don't have the depth of security knowledge.
  4. Here's the clincher: The crooks know all these things. So if you're a crook and you know it will take you a lifetime to penetrate a Fortune 500 network, but you can breach 100 SMBs every WEEK, where is the quickest return on your investment?

That's why you should be concerned. Security threats are real. And if you aren't a target today, you'll be one soon. You need to be prepared.

One quick story - among other things, my company performs security assessments. In one such assessment at a mid-size hospital, our ethical hacking team was able to penetrate the network and access actual patient care devices in the infant ICU. These devices were keeping babies alive. And yet, our team COULD have crashed those machines with one keystroke. Had that been a real hacker ... as a father of three, I don't want to think about it.

Security is about more than protecting data. No matter what business you're in, you have information and systems whose breach could materially impact the lives and livelihoods of you, your employees and your clients. I encourage you to make certain you're doing everything you can to protect them.

Josh