Showing posts with label IT security. Show all posts
Showing posts with label IT security. Show all posts

Wednesday, January 18, 2012

Data center security - a look at the other side of the firewall

In today’s cyber world nobody in his right mind, business or individual, operates without a firewall. But – did you know that around 80 percent of all security threats to organizations come from the inside? Astonishingly enough most companies focus their security resources on preventing external hackers from causing them harm, and no matter how successful firewalls and various intrusions detection/preventing systems are, they are not of much help when the attack/intrusion comes from within the organization, behind the firewall doors…

While people, or workers from within your organization can actually do far more damage to your business than any hacker, this threat is often over looked, not given enough attention or forgotten all together. A recent global study with more than 5.500 IT personnel reveals that increased threats to sensitive and confidential data are caused due to a lack of control and oversight of privileged users.

Think about it for a moment, do you (or anyone else inside your organization) really know how many of your employees, IT personnel, external contractors - or even former IT staff – have access to your critical systems and data? Or, for that sake, do you know how many of your company’s IP addresses, passwords and user names are currently floating around inside your IT department on various spreadsheets and post-it notes?

One security layer that could easily be implemented to protect against such threats is an application that manages remote access inside, as much as outside, of the organization’s data center. This would provide you with a simple way to administer IP addresses, user profiles and user rights while avoiding password sharing with external service providers. Think of it as a firewall behind the firewall - it will allow you to centrally manage and control who has access to what, and with what level of permissions, while it at the same time you can see which privileged users entered which target, from which IP address, through which access method. This will also ensure you that the right access, to the right equipment is given ONLY to the right people inside your organization. 

To learn more on how easily you can protect your internal passwords and increase the security to your own IT infrastructure, watch this video!

Monday, June 14, 2010

The IT Security Behind the World Cup

“Mahindra Satyam, the soccer tournament's official IT services provider, is responsible for safeguarding 160,000 users, the distribution of 3 million tickets, and 40 terabytes of data.” (full story here)

While you are keeping your eye on the ball, Satyam has to make sure no one hacks into the World Cup ticketing system, and to check out the security status of game attendees. Complying with the laws of each of the 208 participating countries was too complex, so Switzerland was chosen the gold standard.

Interesting angle – Satyam is also responsible for secure access and authentication of the 160,00 event management system users. Wonder if he has any time to watch the games…

Sunday, November 15, 2009

Prognosis Poor for Enterprise Infections

This article on CIO Today, Security Report Finds Enterprise Infections Up 100 Percent, paints a bleak picture of the current state of enterprise security. With an almost 100 percent rise in enterprise worm infections in the first six months of 2009 from the previous half year, companies need to be proactive in order to escape the clutches of worms like Conficker and Taterf.

According to the article:

“Microsoft outlined four key security best practices: Understand the Microsoft security-update process and terminology, make sure all third-party applications are being updated regularly by the vendor, make sure a customer's development team is using a software security assurance process, and, finally, put policies in place to help secure all file shares and regulate the use of removable media.”

Which of these four best practices have you found it most difficult to implement (assuming you have implemented them)?