Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Sunday, 6 September 2009

HACKERS SAY TAKE SUMMER OFF BEFORE THE WINTER SPIKE

Posted on 10:47 by Unknown

HACKERS SAY TAKE A BREAK THIS SUMMER BEFORE WINTER HACKING SPIKE

Hacker Survey at DEFCON Reveals Hackers Work the Night Shift; Believe Compliance Initiatives Don’t Improve A Company’s Security Posture

(Eskenzi PR) – Enjoy the rest of your summer vacation say the hacking community, as you’re far less likely to be targeted now than during your Christmas and New Year vacation. That’s according to the results released today by Tufin Technologies, the leading provider of Security Lifecycle Management solutions, who have released the findings of its “Hacker Habits” survey conducted amongst 79 hackers at the annual gathering of hackers at Defcon 17 in Las Vegas this month. Eighty nine percent of hackers admitted that IT professionals taking a summer vacation would have little impact on their hacking activities, as a whopping 81% revealed they are far more active during the winter holidays with 56% citing Christmas as the best time to engage in corporate hacking and 25% naming New Years Eve.

“It’s received knowledge in the security world that the Christmas and New Year season are popular with hackers targeting western countries,” said Michael Hamelin, chief security architect, Tufin Technologies. “Hackers know this is when people relax and let their hair down, and many organizations run on a skeleton staff over the holiday period.”

If you want to know when you should be most on your guard it’s during weekday evenings with 52% stating that this is when they spend most of their time hacking, 32% during work hours (weekdays), and just 15% hacking on weekends.

Ninety six percent of hackers in the survey said it doesn’t matter how many millions a company spends on its IT security systems, it’s all a waste of time and money if the IT security administrators fail to configure and watch over their firewalls. Eighty six percent of respondents’ felt they could successfully hack into a network via the firewall; a quarter believed they could do so within minutes, 14% within a few hours. Sixteen percent wouldn’t hack into a firewall even if they could.

“This may be stating the obvious,” said Hamelin, “but poorly configured firewalls remain a significant risk for many organizations. It’s not the technology that’s at fault, but rather the configuration and change control processes that are neglected or missing altogether. Best practice suggests you should test and review your firewall configuration regularly, but many organizations fail to do so.”

Validating the frustrating gap between compliance and security, seventy percent of the hackers interviewed don’t feel that regulations introduced by governments worldwide to implement privacy, security and process controls has made any difference to their chances of hacking into a corporate network. Of the remaining 30%, 15% said compliance initiatives have made hacking more difficult and 15% believe they’ve made it easier.

“These results further validate the reality that there is little common ground between compliance and security, but as an industry we have the collective knowledge and the resources to change that,” said Hamelin. “As the media constantly reminds us, while standards such as PCI-DSS provide a good baseline, organizations that assume achieving PCI compliance will solve their security woes are in for a rude awakening. With security and compliance budgets so deeply intertwined, it serves us as security professionals to make the two more synonymous. At the end of the day, the more accountable we are willing to be, the less we’ll have to be.”

With the Network Solutions breach being the latest in a series of widely reported breaches of PCI compliant companies, how big is the threat of a high-profile malicious hack? One important factor in determining that is to understand the scope of criminal activity.

Seventy percent of those sampled believe the number of malicious hackers – criminals motivated by economic gain – is less then 25% of the of hacker community.

“This survey highlights the fact cyber security investments are only as effective as the people, processes and technology tasked with managing them,” said Hamelin. “Just as a small subset of criminal hackers can taint the reputation of an entire community, a few good guys willing to be accountable for their internal processes and technology can preserve a company’s reputation. With winter right around the corner, we have time to shift the dynamic from 86% who can hack into a network through its firewalls to 86% that can’t.”

Tufin Technologies is the leading provider of Security Lifecycle Management solutions that enable large organizations to enhance security, ensure business continuity and increase operational efficiency. Tufin’s products SecureTrack, SecureChange™ Workflow, and the Tufin Security Suite™, help security operations teams to manage change, minimize risks and dramatically reduce manual, repetitive tasks through automation. Tufin’s open, extensible architecture enables any company with best of breed applications, devices and systems to take advantage of Tufin’s unmatched policy optimization, change management, and auditing capabilities. With a combination of accuracy and simplicity, Tufin empowers security officers to perform reliable audits and demonstrate compliance with corporate and government standards. Founded in 2005 by leading firewall and business systems experts, Tufin now serves more than 325 customers around the world, including leading financial institutions, telecom service providers, transportation, and energy and pharmaceutical companies. For more information visit www.tufin.com, or follow Tufin on:
Twitter at http://twitter.com/TufinTech,
LinkedIn at http://www.linkedin.com/groupRegistration?gid=1968264,
FaceBook at http://www.facebook.com/group.php?gid=84473097725,
The Tufin Blog at http://tufintech.wordpress.com/
The Tufin Channel on YouTube at http://www.youtube.com/user/Tufintech

<>

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • DDoS-Attacks disable many shopping websites, including Amazon
    Just in time for last minute Christmas shopping major shopping sites disabled by Michael Smith (Veshengro) London, December 26, 2009: An...
  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • Cyber-Ark Expands RSA Secured Partner Program Certification Status
    Cyber-Ark Privileged Identity Management Suite, Inter-Business Vault and Sensitive Document Vault Now Formally Interoperable with RSA enVisi...
  • Infosecurity Adviser applauds forensics lab training facilities at key UK university
    London, UK. May 2009: Infosecurity Adviser, Infosecurity Europe’s online community for the information security industry, has published a r...
  • Scientific company discusses simultaneously protecting applications and data
    Simultaneously protecting applications and data: The next evolution in security? September 2009 (Eskenzi PR) – In a recent Imperva podcast...
  • TUFIN TECHNOLOGIES WINS the PRESTIGIOUS 2010 Computing Security Award for ‘Best bench tested solution of the Year’
    Network Computing and Computing Security Magazine Editors Select Tufin’s SecureChange Workflow as the Top Product Reviewed in 2010 Londo...
  • Brocade Service Could Help Reduce Billions in Data Centre Operations Costs
    New Energy Efficiency Review provides holistic assessment and remedial strategies to help companies optimise efficiency and reduce costs Ene...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • Tufin survey reveals the truth about fudging audits, IT cost cutting and buying equipment online
    Ramat Gan, Israel – May 27, 2009 – Tufin Technologies today announced the results of its “Reality Bytes” security survey. The survey parti...
  • ISACA’s EuroCACS Conference Demystifies the Cloud
    Event for IT Professionals Will Take Place 20-23 March, Manchester London, England, (8 th March 2011)— Global business and information ...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ►  2012 (1)
    • ►  January (1)
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ►  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ►  February (27)
    • ►  January (27)
  • ▼  2009 (240)
    • ►  December (25)
    • ►  November (9)
    • ►  October (21)
    • ▼  September (19)
      • Five Best Practices for Mitigating Insider Breaches
      • Encryption is the equivalent of a seat belt for data
      • Scientific company discusses simultaneously protec...
      • UK firms need to tighten up on Web app security
      • Storage Expo - free advice on cloud issues from Go...
      • DeviceLock host Webinar on securing businesses aga...
      • Bye Bye Baby
      • Toll-Free PBX hack highlights need for code auditing
      • Could your mobile device land your CEO in court?
      • Cyber-Ark Launches latest Privileged Identity Mana...
      • Hard disks will be boosted by Intel's Braidwood
      • Imperva says new SQL injection attacks from China ...
      • Increase in Cyber Criminals Targeting SMBs Online ...
      • HACKERS SAY TAKE SUMMER OFF BEFORE THE WINTER SPIKE
      • Hammer to Distribute Data Locker Encrypted Disk Drive
      • Finjan Welcomes Initiatives for Public Disclosure ...
      • Social Networking Poll Shows Users More Vulnerable...
      • Blogger asks CPS to 'take one for the team' in Gar...
      • RSA® Conference Europe 2009 Launches Registration ...
    • ►  August (30)
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile