By Jon Moynihan and Ed Savage of PA Consulting Group
Published: July 5 2010 16:25 | Last updated: July 5 2010 16:25
All organisations connected to the internet must consider themselves vulnerable to outside attack, and all organisations with computer systems are vulnerable to insider attacks, possibly involving sabotage or theft.
Using the internet, or working from the inside, individuals, organisations or nations can steal intellectual property and personal data or cause untold damage with relatively little investment in time or money, and with little chance of their identity being detected.
While the cloud (delivery of IT services via the internet) promises significant cost and operational savings for companies, it also offers malicious individuals and organisations access to cheap and unprecedented processing power that can be used in probes and attacks.
And cyberwarfare, by one state upon another, has been documented in at least half a dozen cases over the past few years.
Until recently, many organisations seemed to assume their firewalls and anti-virus software would protect them. But those that have suffered attacks are aware that this is not the case, and are part of a growing consensus that a new technical approach, and a much stronger focus on the people and organisational aspects of cyber defences, are badly needed.
Cyber defence traditionally focuses on keeping threats out, mostly talking about repelling attacks on the company’s IT infrastructure.
However, even the best anti-virus products are no obstacle to a “zero day” attack (one involving a previously unknown virus, hack or worm) since it will not have been known about prior to that attack.
Best practice therefore requires a resilient architecture plus mechanisms to permit rapid identification of such attacks; their immediate isolation from the live network; and tracking to enable potential identification of the attacker and their intentions.
There is, however, a consensus among specialists that most corporate networks already carry hidden malicious code, waiting to be triggered by a further entry through a prepared ”trapdoor”. Such targeted attacks will succeed, unless the very difficult task of searching for and removing such malware is successfully undertaken.
Best practice has not yet identified a way to spot all such pre-embedded malware “bombs”, although it has been suggested they might be identified by checking every line of the software against a duplicate copy of the original code, examining deviations.
This has not yet been shown to be practicable in most cases, but easier-to-implement immediate steps that could be taken include the following:
● Getting better information on all intrusive probes and attacks on software infrastructure. Most organisations are under daily attack from amateurs; those calling themselves “semi-professionals”, or “hacktivists”; and professional intelligence agencies of other countries.
Organisations need to get better at monitoring all attempts to penetrate their systems.
● Reviewing all software to discover what trap doors have been installed or may have been or exploited, and what malware may have been added to their software. This could be costly and difficult in practice. Some newer detection products are achieving good hit rates, although it is almost impossible to be certain all malware has been removed.
● Installing new software, protected from intrusion, from a reliable source, to replace old and potentially compromised software. This is expensive but could be confined to the most sensitive areas. Where IT services have been sourced to a third party, “protect and replace” agreements must be written into contracts at the outset.
● Locking down key parts of the software, and removing access from the public internet. For many organisations this will limit normal business, but some have found that doing this is possible for key control systems and more sensitive data networks.
● Preparing contingency plans against cyberattack. This would include, for example, resilient back-up systems that could be switched to, completely isolated from the net, in the event of cyberattack.
● Maintaining a highly skilled counter-cyberterrorism capability is essential. National authorities such as CESG and CPNI in the UK provide much needed assistance but are still under-resourced.
While much investment goes on fighting external attacks, malign insiders still pose a great risk because they know the organisation, its high value assets, its vulnerabilities and, often, its defences.
Malign insiders can pose multiple threats – sabotage; facilitating third party access; corruption data; theft and espionage.
To reduce their exposure to such loss, organisations need to ensure their protective monitoring capabilities against insider threats are sound.
This need not entail significant additional investment in technology. The biggest gains in effectiveness often come from ensuring the organisational and process elements in an organisation’s monitoring are soundly based.
Strategic protective monitoring can also save an organisation from human error – since even the best technical defences can be thwarted by an individual unwittingly introducing a Trojan from a corrupted memory stick or by visiting an infected web site.
It makes good sense for every organisation to review, in its own way, its defences and actions to protect itself against the growing threat of cybercrime and terrorism.
Jon Moynihan is executive chairman, and Ed Savage, is senior defence and security specialist, both at PA Consulting Group
Copyright The Financial Times Limited 2010. Print a single copy of this article for personal use. Contact us if you wish to print more to distribute to others.
Showing posts with label IT Security. Show all posts
Showing posts with label IT Security. Show all posts
Monday, July 05, 2010
Friday, May 22, 2009
How safe is your IT security?
How safe is your IT security?
By Graham Fern, director of axon-IT
Published: May 22 2009 09:49 | Last updated: May 22 2009 09:49
The largest challenge facing businesses today is IT security. As business become increasingly reliant on the data in its systems, it faces an ever-increasing threat to the network and data integrity.
Everyone is aware of issues regarding internet usage and the security of electronic data stored or transmitted to third parties. Recently, Microsoft issued a report indicating that 97 per cent of all e-mails sent over the net are unwanted – spam is dominant.
So is IT security really an issue or are we just scaremongering?
The simple answer is yes, security is a big problem if you don’t take reasonable protective measures. So how do you “shut the door” to your PC network?
Simple steps can reduce the risk – data must be protected but without spending very large amounts of money. The solutions differ slightly between home and business users but we’re looking here at business.
IT systems use a multi-layered approach to ensure security, similar to methods used in banks. When it comes to protecting the money, banks place their highest security closest to the money – the vault door with complex alarms, together with the front of house security.
This multi-layered approach allows and encourages normal people into the bank, but in turn discourages the thief, who is faced with a difficult path to the money.
This is similar for IT systems and the data they contain: IT security should be tiered with multiple levels of security from the front door to the bank vault.
So how does this translate into the real world?
First, e-mail, a recent Microsoft study determined that e-mail was the number one use of a PC. So if e-mail is important we need steps to ensure the e-mails received are relevant to the business:
We need a device or a service that “cleans” e-mails of spam, and that removes viruses at the same time, ensuring what arrives in an inbox is relevant and safe.
Such systems are not 100 per cent perfect, therefore any system must be able to learn and needs to be simple to use and administer. This protection then needs to be extended to the PC itself as another layer – in the form of a suite of software that blocks and inhibits spyware, viruses, malware, spam etc.
This software needs to be adaptive to the threats and learn quickly, it also needs to talk to a central system with status information.
Firewalls can also stop the internet from getting inside your computer network. They vary considerably in features and price and one size does not fit all.
Best practice is usually for a relatively simple and fast device to be placed closest to the internet to undertake simple security blocking tasks (like the front door to the bank). Closer to the users you would place a more complex device (like the bank vault) that can undertake a very fine inspection of information flowing in.
These complex devices can also inspect/block what is going out from your network, which can be a useful productivity and security tool if your staff are surfing potentially unsafe websites that could contain spyware and viruses.
The use of professionally written, intelligent and well executed viral code is becoming widespread. These code writers use the same processes and procedures a professional application developer would use to ensure the highest quality virus.
Infections today are less openly destructive than they used to be – yet more damaging – as virus writers now know they can extract useful and valuable data that has a financial worth, such as credit card details. Infected machines have allowed thieves to undertake money laundering, gain remote access to internal database systems, allowed terrorism to be funded, and other criminal activities.
These attacks are not just limited to small time ad-hoc efforts but they can be streamlined targeted affairs for a particular purpose. This type of criminal activity is rapidly becoming mainstream, the number of detected viruses over the past two years is almost equal to all the viruses detected since they started recording such information.
Axon IT is accredited as a Microsoft Gold Partner with a specialisation in security.
Copyright The Financial Times Limited 2009
By Graham Fern, director of axon-IT
Published: May 22 2009 09:49 | Last updated: May 22 2009 09:49
The largest challenge facing businesses today is IT security. As business become increasingly reliant on the data in its systems, it faces an ever-increasing threat to the network and data integrity.
Everyone is aware of issues regarding internet usage and the security of electronic data stored or transmitted to third parties. Recently, Microsoft issued a report indicating that 97 per cent of all e-mails sent over the net are unwanted – spam is dominant.
So is IT security really an issue or are we just scaremongering?
The simple answer is yes, security is a big problem if you don’t take reasonable protective measures. So how do you “shut the door” to your PC network?
Simple steps can reduce the risk – data must be protected but without spending very large amounts of money. The solutions differ slightly between home and business users but we’re looking here at business.
IT systems use a multi-layered approach to ensure security, similar to methods used in banks. When it comes to protecting the money, banks place their highest security closest to the money – the vault door with complex alarms, together with the front of house security.
This multi-layered approach allows and encourages normal people into the bank, but in turn discourages the thief, who is faced with a difficult path to the money.
This is similar for IT systems and the data they contain: IT security should be tiered with multiple levels of security from the front door to the bank vault.
So how does this translate into the real world?
First, e-mail, a recent Microsoft study determined that e-mail was the number one use of a PC. So if e-mail is important we need steps to ensure the e-mails received are relevant to the business:
We need a device or a service that “cleans” e-mails of spam, and that removes viruses at the same time, ensuring what arrives in an inbox is relevant and safe.
Such systems are not 100 per cent perfect, therefore any system must be able to learn and needs to be simple to use and administer. This protection then needs to be extended to the PC itself as another layer – in the form of a suite of software that blocks and inhibits spyware, viruses, malware, spam etc.
This software needs to be adaptive to the threats and learn quickly, it also needs to talk to a central system with status information.
Firewalls can also stop the internet from getting inside your computer network. They vary considerably in features and price and one size does not fit all.
Best practice is usually for a relatively simple and fast device to be placed closest to the internet to undertake simple security blocking tasks (like the front door to the bank). Closer to the users you would place a more complex device (like the bank vault) that can undertake a very fine inspection of information flowing in.
These complex devices can also inspect/block what is going out from your network, which can be a useful productivity and security tool if your staff are surfing potentially unsafe websites that could contain spyware and viruses.
The use of professionally written, intelligent and well executed viral code is becoming widespread. These code writers use the same processes and procedures a professional application developer would use to ensure the highest quality virus.
Infections today are less openly destructive than they used to be – yet more damaging – as virus writers now know they can extract useful and valuable data that has a financial worth, such as credit card details. Infected machines have allowed thieves to undertake money laundering, gain remote access to internal database systems, allowed terrorism to be funded, and other criminal activities.
These attacks are not just limited to small time ad-hoc efforts but they can be streamlined targeted affairs for a particular purpose. This type of criminal activity is rapidly becoming mainstream, the number of detected viruses over the past two years is almost equal to all the viruses detected since they started recording such information.
Axon IT is accredited as a Microsoft Gold Partner with a specialisation in security.
Copyright The Financial Times Limited 2009
Subscribe to:
Posts (Atom)