Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Monday, 3 August 2009

Loyal Employees or Snooping Staff? You Decide

Posted on 11:15 by Unknown
Cyber-Ark Software provides five steps to protect company data from desperate employees tempted to steal secrets

By Mark Fullbrook, UK Director – Cyber-Ark Software

According to figures released in June 2009 by the Office for National Statistics(1) redundancies level for the three months to April 2009 was 302,000, up 36,000 over the quarter and up 191,000 over the year. This is the highest figure since comparable records began in 1995. However anxious these times may be for employees, nervously looking round to see where the axe will fall next, employers should not be complacent and expect loyalty in return for a regular pay packet. In fact the opposite could well be true - as the saying goes “desperate times call for desperate measures”.

In a recent Cyber-Ark survey into “The recession and its effects on work ethics” carried out amongst 250 office workers in London’s busy Canary Wharf, a staggering sixty percent admitted they would take valuable data with them, if they could get away with it, were they faced with redundancy or the sack! Remarkably, 40% confessed to having already snooped around the networks and downloaded sensitive company secrets from under their bosses nose in anticipation that they could lose their job. Top of the list of desirable information to steal is customer and contact databases, with plans and proposals, product information, and access/password codes all popular choices and as having a perceived value – either monetary to an unscrupulous third party or as a negotiating tool in securing a new position.

In a separate Cyber-Ark global survey into “Trust, Security & Passwords” of more than 400 senior IT professionals both in the US and UK, mainly from enterprise class companies, 35 percent of IT workers admitted to accessing corporate information without authorisation. The types of information this audience would target was proprietary data and information that is critical to maintaining competitive advantage and corporate security. Ominously, 1 in 5 companies confessed having experienced cases of insider sabotage or IT security fraud.

When staff take data and cause a security incident, it tends to be filed away as an example of an “employee gone bad.” In reality it constitutes a failure of the organisation to uphold its responsibility on behalf of the business to manage, control and monitor the power it provides to its employees and systems or indeed have any controls actually in place to actually manage and control staff from causing breaches.

The failure stems from the ‘perception of control’ an organisation has over their most sensitive networks, systems and devices versus the stark reality that this control is most often not in place across the organisation. So, what can be done to protect sensitive data from an increasingly unsettled, and to some extent desperate, workforce?

Trust is not a security policy
To significantly cut the risk of these insider breaches, employers must have appropriate systems and processes in place to prevent prying personnel.

One approach to address this challenge is a privileged identity management holistic approach using solutions such as digital vaults, especially valuable for users with high levels of enterprise/network access as well as those handling sensitive information and/or business processes. Instead of trying to protect every facet of an enterprise network, digital vault technology creates safe havens – distinct areas for storing, protecting, and sharing the most critical business information – and provides a detailed audit trail for all activity associated within these safe havens. This encourages secure employee behaviour and significantly reduces the risk of human error.

For organisations serious about preventing internal breaches, be they accidental or malicious, here are five steps to protecting company data from desperate employees tempted to steal secrets :

Step 1: Establish a Safe Harbour

By establishing a safe harbour, or vault, for highly sensitive data (such as administrator account passwords, HR files, or intellectual property including corporate databases), security is built directly into the business process independent of the existing network infrastructure. This will protect the data from the security threats of not only nosy employees snooping around for information they should not be privy to, but also from hackers.

A digital vault is set up as a dedicated, hardened server that provides a single data access channel with only one way in and one way out. It is protected with multiple layers of integrated security including a firewall, VPN, authentication, access control, and full encryption. By separating the server interfaces from the storage engine, many of the security risks associated with widespread connectivity are removed.

Step 2: Automate Privileged Identities and Activities

Ensure that privileged administrative and application accounts, and their underlying passwords are actively managed, secured, changed regularly, highly guarded from unauthorised use, and closely monitored, including full activity capture and recording. Once these privileged identities are being managed, make sure to proactively monitor and report actual adherence to the defined policies, and adopt the well-accepted security axiom of ‘Trust, but verify’ . This is a critical component in safeguarding organisations and helps to simplify audit and compliance requirements, as companies are able to answer questions associated with “who” has access and “what” is being accessed.

Step 3: Identify All Your Privileged Accounts

The best way to start managing privileged accounts is to create a checklist of operating systems, databases, appliances, routers, servers, directories, and applications throughout the enterprise. Each target system typically has between one and five privileged accounts. Add them up and determine which area poses the greatest risk. With this data in hand, organisations can easily create a plan to secure, manage, automatically change, and log all privileged passwords.

Step 4: Secure Embedded Application Accounts

Up to 80 percent of system breaches are caused by internal users, including privileged administrators and power users, who accidentally or deliberately damage IT systems or release confidential data assets.

Many times, the accounts leveraged by these users are the application identities embedded within scripts, configuration files, or an application. The identities are used to log into a target database or system and the fact that these credentials, are traditionally hard-coded, in clear-text and usually never changed is often overlooked within a traditional security review. Even if located, the account identities are difficult to monitor and log because they appear to a monitoring system as if the application (not the person using the account) is logging in.

These privileged, application identities are being increasingly scrutinised by internal and external auditors, especially during PCI- and SOX-driven audits, and are becoming one of the key reasons that many organisations fail compliance audits. Therefore, organisations must have effective control of all privileged identities, including application identities, to ensure compliance with audit and regulatory requirements.

Step 5: Avoid Bad Habits

To better protect against snoopers, organisations must establish best practices for securely exchanging privileged information. For instance, employees must avoid bad habits (such as sending sensitive or highly confidential information via courier). IT managers must also ensure they educate employees about the need to create and set secure passwords for their computers instead of using sequential password combinations or their first names.

The risk of internal data misuse from snoopers can be significantly mitigated by implementing effective policies and technologies. In doing so, organisations can better manage, control, and monitor the power they provide to their employees and systems and avoid the negative economic and reputational impacts caused by an insider data breach. It would be unthinkable to leave money on a desk, an obvious temptation to anyone passing, instead it is always safely locked away. The time has come for companies to give sensitive information and key systems the same consideration, and as always – ‘Trust…But Verify’.

www.cyber-ark.com

Courtesy: Eskenzi PR
<>
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • DDoS-Attacks disable many shopping websites, including Amazon
    Just in time for last minute Christmas shopping major shopping sites disabled by Michael Smith (Veshengro) London, December 26, 2009: An...
  • Cyber-Ark Expands RSA Secured Partner Program Certification Status
    Cyber-Ark Privileged Identity Management Suite, Inter-Business Vault and Sensitive Document Vault Now Formally Interoperable with RSA enVisi...
  • Infosecurity Adviser applauds forensics lab training facilities at key UK university
    London, UK. May 2009: Infosecurity Adviser, Infosecurity Europe’s online community for the information security industry, has published a r...
  • Scientific company discusses simultaneously protecting applications and data
    Simultaneously protecting applications and data: The next evolution in security? September 2009 (Eskenzi PR) – In a recent Imperva podcast...
  • TUFIN TECHNOLOGIES WINS the PRESTIGIOUS 2010 Computing Security Award for ‘Best bench tested solution of the Year’
    Network Computing and Computing Security Magazine Editors Select Tufin’s SecureChange Workflow as the Top Product Reviewed in 2010 Londo...
  • Brocade Service Could Help Reduce Billions in Data Centre Operations Costs
    New Energy Efficiency Review provides holistic assessment and remedial strategies to help companies optimise efficiency and reduce costs Ene...
  • Tufin survey reveals the truth about fudging audits, IT cost cutting and buying equipment online
    Ramat Gan, Israel – May 27, 2009 – Tufin Technologies today announced the results of its “Reality Bytes” security survey. The survey parti...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • ISACA’s EuroCACS Conference Demystifies the Cloud
    Event for IT Professionals Will Take Place 20-23 March, Manchester London, England, (8 th March 2011)— Global business and information ...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ►  2012 (1)
    • ►  January (1)
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ►  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ►  February (27)
    • ►  January (27)
  • ▼  2009 (240)
    • ►  December (25)
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ▼  August (30)
      • Leona Lewis music hack may be publicity stunt
      • US Court Grants Finjan a Permanent Injunction for ...
      • Swisscom IT cuts time spent on firewall management...
      • Amazon cloud evangelist to give Storage Expo openi...
      • Crown Plaza Venice hotel booking fiasco could have...
      • Fowlers Revs Up With Numara Track-It!
      • Twitter security move positive but is it it enough?
      • Stolen Lincoln playgroup laptop highlights danger ...
      • Mobile laptop usage soaring - but what about compa...
      • Security players form alliance to tackle malware
      • 1.7 million reasons for local authorities to use p...
      • “VirtualiSation and the Other Green Computing Init...
      • Cross site scripting (XSS) flaws hit the Ministry ...
      • Britney Spears hack highlights reputational risk o...
      • CREDANT Technologies extends data protection to Ma...
      • Compliance does not guarantee security
      • Staff&Line Partners with ProServ
      • Microsoft announces Office 2010 web applications
      • Weak cloud password security highlights strength o...
      • Peru makes a big statement about reusing rather th...
      • FSA £3m fine on HSBC could easily have been avoided
      • Twitter down again - another attack?
      • Pro-Georgian blogger was the target of Internet at...
      • Finjan Prevents Zero-Day Exploit of Adobe Acrobat ...
      • Microsoft and Yahoo cooperate on Search
      • DESlock+ Achieves ‘Five Star’ Accolade
      • Instant message dangers are growing
      • Google promises end to viruses - Fortify says: don...
      • Criminals could capture data from wireless keyboards
      • Loyal Employees or Snooping Staff? You Decide
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile