Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

Guest Blog // Selected Security Content Provided By Sophos
What's This?
4/18/2012
10:21 AM
Brian Royer
Brian Royer
Security Insights
50%
50%

The Benefits Of Top-Down Security

While enterprise-level breaches often get the attention of C-level suite executives and the members of their IT staff, industry research shows it actually falls to rank-and-file employees to apply best practices and exercise sound judgment in order to properly contain them

Since the release of Verizon's 2012 Data Breach Investigations Report, I can't help but think that in most cases it's not IT that will keep users safe -- it's a combination of management and best practices. The Verizon report revealed that 97% of data breaches evaluated by the telecom giant in 2011 were avoidable and did not require hackers to possess special skills, resources, or customization. And it found that the majority (30% of breaches, impacting 84% of records breached) was the result of stolen login credentials.

Case in point: this story in Aviation Week, which detailed how, since 2009 and continuing undetected for "around 18 months" the BAE systems' portion of the Lockheed Martin F-35 program in the U.K. had likely been subject to significant data theft, possibly by a nation state using Advanced Persistent Threat (APT).

As detailed in the article, the remedies to data thefts like the BAE breach have included the emergence of an experimental information-sharing program founded by ADS (Aerospace and Defense Trade association) known as the Virtual Task Force and, separately, a British-government backed "Cybersecurity" pilot hub involving participants from five business sectors -- defense, energy, pharmaceuticals, telecommunications, and finance.

In both cases the goal is information-sharing. As Julian Fraser, director of a classified-information disposal service and a committee member of ADS’ Cyber Protection and Assurance Group, said, "The point of the Virtual Task Force is to involve companies at boardroom level, as well as getting their technical people together to analyze attacks and discuss the solutions they find. "

Mutual cooperation. That's a start in the right direction, but the article also significantly mentions the possible weak link in the chain: getting employees to pay attention, take charge, and take responsibility.

As the author properly suggests, security will not improve if only the CEO and the information technology department know about the threat. For example, the BAE F-35 breach and a similar hack on Lockheed Martin and RSA, its digital security supplier, used "spearphishing" attacks where an individual employee was tricked into opening an email that went on to infect and compromise the network.

Spot-on commentary by Don Smith, technology director of Dell SecureWorks, drives home the point:

"The problem exists between the keyboard and the chair. The initial trigger is duping an end user, and that mechanism remains a highly successful method of penetrating organizations that have multi-layered security controls. "

"If you were to start with [educating] lower-down employees in large organizations, and you get them to appreciate the importance of information security like they appreciate the importance of green issues, then they are going to start to demand better practices of their employers," says Fraser.

A conclusion reinforced by evidence accrued in the aforementioned Verizon report and the following summation by Marc Spitler, a Verizon security analyst:

"Very often, the companies breached had no firewalls, had ports open to the Internet or used default or easily guessable passwords."

In other words, easy-to-find, easy-to-learn and easy-to-exploit weak passwords.

Additionally, according to the Verizon report, social engineering methodologies dominated the types of data breaches, including 46% taken advantage of by phone and 37% in-person. Surprisingly, breach by email came in a relatively distant third at "just" 17%. In other words, the "victim" of the breach and the hacker on the other end actually communicated with one another, either face to face or verbally by phone. In other words, employees who were quick to believe "the tale" they were being told.

Cumulatively, the findings highlight the need for companies to pay attention to security basics. "It is about going back to basic security principles. A lot of the same recommendations we have used in past years, we have recommended this year, " he added.

But what kind of reception will these security basics find among employees? A just-released Sophos-sponsored survey of global IT professionals found that 96 percent of respondents (IT professionals and IT decision makers) do not trust their own end users to make sound IT security decisions.

Additional highlights included:

• 48% of respondents fix security issues caused by end user negligence at least once a week

• 26% of respondents say senior management commits the worst IT security offenses

• 19% of respondents say that IT commits the worst IT security offenses

These results underscore the impact that a lack of understanding security policies and best practices -- in every department and at all levels of an organization -- can have on an IT infrastructure. In sum, disclosure of data breaches should not stop at the boardroom doors. Indeed, think of your organization as a microcosm, a subset of the aforementioned Virtual Task Force or British Cybersecurity hub. Apply top-down security by sharing information about breach events as they happen. Leave no one out of the loop. Consider every employee a stakeholder in the process of securing your network and its intellectual property. Conduct general security awareness training. Give employees specific instructions on how to recognize and stop breaches. And then make those same employees accountable by getting them to appreciate that it’s up to them to keep their eyes open and their suspicions about any offer, whether face-to-face, over email or by phone, hardwired to maximum setting.

That way, when Verizon releases its next report on data breaches, it won't be your company (or any of your employees) that’s counted among its casualties.

Brian Royer, a security subject matter expert, Sophos U.S., is partnering with SophosLabs to research and report on the latest trends in malware, web threats, endpoint and data protection, mobile security, cloud computing and data center virtualization.

Join Sophos for a Dark Reading sponsored webcast: 3 Steps to Securing Private Data in the Public Cloud, on Thursday, April 26, 2012 at 11:00 AM PT/ 2:00 PM EST. The webcast will include discussion on the security challenges of storing data in the cloud; limitations of a digital do-it-yourself approach; and three simple steps to protecting data in the cloud. Click here for registration and more information.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-22392
PUBLISHED: 2021-08-05
Cross Site Scripting (XSS) vulnerability exists in Subrion CMS 4.2.2 when adding a blog and then editing an image file.
CVE-2021-3591
PUBLISHED: 2021-08-05
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Notes: none.
CVE-2021-3642
PUBLISHED: 2021-08-05
A flaw was found in Wildfly Elytron where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality. This flaw affectes Wildfly Elytron versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final.
CVE-2021-3655
PUBLISHED: 2021-08-05
A vulnerability was found in the Linux kernel in versions before v5.14-rc1. Missing size validations on inbound SCTP packets may allow the kernel to read uninitialized memory.
CVE-2021-32003
PUBLISHED: 2021-08-05
Unprotected Transport of Credentials vulnerability in SiteManager provisioning service allows local attacker to capture credentials if the service is used after provisioning. This issue affects: Secomea SiteManager All versions prior to 9.5 on Hardware.