I am always receiving information about security, new vulnerabilities and other topics in my inbox. The one that stands out a webcast from Trend Micro. The CEO said that every 7 seconds there is a new virus on the net. I thought "WOW, isn't that incredible". But even more incredible is the fact that viruses and other cyber crime can be as lucrative as Oil and Drugs.
We all have read about lowering the costs of our IT infrastructure in terms of security in these times of economical crisis, but being careless with Security spending can make you lose your most valuable asset: your company’s information- including client databases, procedures, etc. I think that the fact that your information is the target of many cyber criminals and that there are many viruses and malwares on the Internet to make your platform vulnerable and extract any kind of valuable information is propitious to secure your internal infrastructure from the Internet.
This leads me to add that the risk is not only on the Internet. Recent statistics have said that the most common security incidents come from insiders –that is, your own employees and outsourced personnel. They can take advantage of the vulnerabilities in your systems to commit cyber crime using your IT infrastructure. Some of those statistics have said that 44% responded to insider abuse and 29% to unauthorized access to systems. So, the question now is more specific, Where should I start securing my infrastructure, by protecting myself against internal or external attacks?
Statistics say that the 3 most common technologies used to secure the infrastructure. Do you know which is the most important? If you guessed antivirus, you're right. But isn't that amazing that 3% of the companies surveyed have said that they don't use antivirus software? I hope you're not one of them. The second technology was firewalls. The last one was Antispyware.
This tells us that companies are securing their infrastructure and information from the first risk called "malware" (Malicious Software), which are the most common risks from the Internet. But, what about the cyber criminals? These people can be in the coffee shop with free Internet on the street corner, or in any other part of the world, or even worse, at the next desk in your office. Companies are not paying attention to these people. We think, “this can't happen to me, all my employees have signed my Confidential Policy, and so on”. But there are employees that signed that policy long time ago. Have you refreshed that information to them? Are your outsourced personnel aware of your security policies and the consequences of doing malicious attacks in your company?
I hope the information given in this article has helped you in taking action to improve the security of your data and even your own security.
I am looking forward to hearing from you regarding your thoughts and knowledge about this topic. So I ask you: Have you heard about this before? What do you think about this? What do companies should do to increment the security in their business? And even more important to me, how could we reduce the amount of threats on the net? What about paying attention to the security before implementing a system or systems in your organization?
Wednesday, February 18, 2009
Subscribe to:
Posts (Atom)