Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


December 12, 2008

Succeeding in IT: An Old-School Low-Tech Tip

It's not always the security solution that enables security
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!
back to blog index

These three IT-related events have one failure in common. Can you find it? 
1. An enterprise IT solution deployed by an IT department didn’t solve the problem it was supposed to.

2. A website and forum was a victim of two SQL Server injection attacks, causing the site to go down two separate times for over a week each time.

3. An investigative team discovered that in over half of the cases of data breaches it studied, the organization whose data was compromised had security policies and procedures in place.

Hard to narrow it down? The failure in all three was lack of follow through.

The Verizon Business Investigative Response team investigated over 500 cases between 2004 and 2007 where security was breached or data was compromised. These cases crossed all industries and organizations, from education to healthcare to technology, though the most breaches were in the payment card industry. One finding in the report was that lack of follow through was key in weakening security.

I tend to be a little skeptical about vendor studies. Yet they’re useful for telling us things that we need to be reminded about—such as following through.

In the examples above, if IT had followed through on using the software and training users on the software it deployed, one IT pro from that department told me, they might have actually gotten something out of the solution they spent good money on. If the owner of the website targeted for a SQL injection attack had employed preventive measures, the site wouldn’t have been down long enough for its subscribers to abandon it. And if the organizations that experienced data breaches had followed through on the policies and procedures they’d set up, maybe they wouldn’t have ended up as statistics in a data breach report.

I don’t want to be a statistic. I’m sure you don’t either. Let’s resolve, in the coming year, to follow through.

Making good on that resolution, I’d like to follow through. Here are some interesting excerpts from the Verizon report:

1. Data thieves appear perfectly willing to victimize “smaller mom and pop” operations as well as larger enterprises.

2. Data compromises are considerably more likely to result from external attacks than from any other source. Business partners were involved in 39 percent of the data breaches. Internal sources accounted for the fewest number of incidents (18 percent), trailing those of external origin by a ratio of four to one.

3. In over 40 percent of the breaches investigated during this study, an attacker gained unauthorized access to the victim via one of the many types of remote access and control software. Despite the large amount of media attention given to the supposed weakness of wireless networks, this vector was exploited considerably less than others. When wireless infrastructure was the means of entry, it was due to poor configuration and weak encryption rather than a successful attack against an adequately secured WLAN.

4. In 59 percent of data breaches, the organization had security policies and procedures established for the system but these were not enacted through actual processes. Stated differently, victims knew what they needed to do, fully intended to do it, but did not follow through. 

To read the Verizon team’s report, see the PDF at the Verizon site.

For resources about preventing SQL injection attacks, see
“Protecting Your Organization from SQL Injection Attacks”
“Better Defenses For Your Web Applications And Database Servers”

For our recent reviews of security-related products, see
“Types of Endpoint-Protection Products”
"Enterprise Random Password Manager"
"2 Ways to Prevent Rogue Devices From Stealing Your Data"

End of Article



Reader Comments

You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now





Search Industry Bytes
 
Industry Bytes
NOVEMBER 2009
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30      
or

 Recently in Industry Bytes
Interop News: Datacom Unveils New 10Gb Data Filtering Taps and Switches
Make a Comment
Tony Redmond's Top 10 Things About Exchange 2010

Last Comment
In defense of Tony's list, remember that it's "Top 10 Things You Need to Know About Exchange 2010," ...
(3 Comments)
Hire Better Employees with This 5-Step Process
Make a Comment
MOSS 2007 and SharePoint 2010: Walking the line between past and future
Make a Comment
Notes from the Hiring Table, Part 4: Become the Ultimate Employee
Make a Comment

More blogs about technology,
software, and Windows.

Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2009 Penton Media, Inc. Terms of Use | Privacy Statement