Home ME Facebook ME LinkedIn ME Twitter map of ME logo

MET

CONTACT US | SUBSCRIBE | NEWSLETTER | RSS

 
Welcome, Guest |   Sign In   |   Register  
 
Print Email Page RSS Feeds

Posted Date: 1/19/2009

You Have Been Hacked!

By Ben Halpert
No, really -- you have been hacked. You have lost organizational sensitive information and customer and employee personal information. If you don't think you have had such a loss, you are not looking in the right places.

Current security measures do not work efficiently. You may not realize this, but your adversaries do. Who is your adversary? It depends on your industry, but generally speaking your adversarial threats can be classified under corporate espionage, state-sponsored espionage, organized crime, hackers, and current or former employees with malicious intent.

These adversaries have one goal in mind: to extract all the information they can from your computing environment.

Your adversaries use automated tools to scan for vulnerabilities in your unpatched systems. They use spear phishing to trick your employees into visiting compromised websites that in turn compromise computing assets and data. They use social engineering techniques that bring your employee's guard down to the point where they will reveal sensitive information.

A determined adversary only needs to be right once to achieve their objective. Your organization's security measures need to be perfect all the time. Who has the upper hand? Not your organization.

The 2008 Data Breach Investigations Supplemental Report (http://www.verizonbusiness.com/resources/security/databreachsuppwp.pdf) compiled by the Verizon Business Risk Team, noted that nine out of 10 data breaches involved one of the following:

  • A system unknown to the organization (or business group affected)

  • A system storing data that the organization did not know existed on that system

  • A system that had unknown network connections or accessibility

  • A system that had unknown accounts or privileges

What does this mean for your organization? The latest and greatest security tool you just purchased will not fix your problems. Get your house in order; develop a process, with supporting tools and staff, to locate and maintain an inventory of all computing assets and related network connectivity; determine and track the information stored on those assets; create a program to deal with identity and access management to organizational resources; and create and test a plan for when the inevitable happens.

If you don't know what you have, you won't know what has gone missing.



Ben Halpert, CISSP, is an information security researcher and practitioner and writes monthly about security. Comments, questions & requests can be sent to him at editor@mobileenterprisemag.com; please include SECURITY in the subject line.

Rate this Content (5 Being the Best)
12345
Current rating: 0 (0 ratings)

 


Show Off the Rugged: Next Gen Devices Modernize the Field
5/15/2013 2:00:00 PM (EST)
Moderator:
Dorene Rettas, Publisher, Mobile Enterprise
Panelists:
Michael Ho, Regional Service Manager, Canon Canada Inc.
David Krebs, VP, Enterprise Mobility and Connected Devices Practice, VDC Research
Mika Majapuro, Product Marketing Manager, Honeywell
Wes Rupel, Co-Founder, President and Chief Technology Officer, Allegro Mobile Solutions
Savino Griesi, Co-Founder and Chief Executive Officer, Allegro Mobile Solutions
View On Demand

Mobilizing Your Ecosystem through BYOD and MAM
3/28/2013 2:00:00 PM (EST)

Moderator: 
Lori Castle, Editor In Chief, Mobile Enterprise

Panelists:
Chris Marsh, Principal Analyst, Yankee Group
Gabriel Weiss, Head of Interactive Marketing Technologies, Mitsubishi Electric

View On Demand

Mobile Engagement: Leveraging Cross-Channel Communications to Improve Business Operations Mobile Engagement: Leveraging Cross-Channel Communications to Improve Business Operations
5/15/2013
As enterprises recognize the need for a mobile strategy, there are many challenges to capitalizing on the opportunities. This paper explains why enterprises can and should embrace mobile engagement to help solve customer, partner and employee communication challenges.
Download Now

Mobile Application Management - Meeting the BYOD challenge with next-generation application and device management Mobile Application Management - Meeting the BYOD challenge with next-generation application and device management
5/1/2013
Discover how a well-designed Mobile Application Management (MAM) solution enables IT teams to achieve fine-grained control over mobile applications across a range of devices, over every type of network and deployment mode, without impinging on users' privacy rights or damaging end users' personal property.
Download Now


MEDIA KIT | CALENDAR OF EVENTS | EDITORIAL CALENDAR | PRIVACY STATEMENT | TERMS & CONDITIONS | ABOUT US | CONTACT US | PARTNER PAGE
All materials on this site Copyright Edgell Communications. All rights reserved.