Tuesday | 7 July, 2009
CSO
The 10 Most Common Internal Security Threats
Who’s gaining access to your internal network? New criminal tactics and new kinds of malware are probing networks for vulnerabilities — and increasingly, finding them. We identify the top candidates for security breaches inside your own company
Rick Cook (CIO) 05/07/2007 10:09:09

Of course, internal and external threats can work synergistically. For example, peer-to-peer networks are an internal problem, because they are deliberately installed on corporate systems, but they are a threat because they can be exploited externally to breach security.

And there are a lot of vulnerabilities.

"In 2006 we did a survey of 30 customers of different sizes, from a few hundred workstations to tens of thousands of workstations all around the world," says Amir Kolter, CEO of security software vendor Promisec. "That was almost 200,000 endpoints."

According to Kolter, the results were depressing. "All of [the customers] had internal threats," he says. "The total number of threats was higher than we ever expected." In addition, the number of companies with a given vulnerability was often much higher than the percentage of computers showing that vulnerability. Thus, says Kolter, while only 4 percent of the total endpoints surveyed had peer-to-peer software installed, 22 percent of the companies surveyed had one or more endpoints with this vulnerability.

While the percentages of computers with problems may seem low, keep in mind that it takes only one vulnerable computer in an organization to compromise the entire network.

Some of what Promisec found were the old vulnerability standbys: versions of Windows without the latest patches, antivirus software that needed signature files updated, and so on. However, some of the endpoint threats Promisec found were less traditional, and less obvious.

Promisec found 10 major areas of problems. Not all the companies had all the problems, but all of them had at least one. In some cases the endpoint threat could be completely eliminated, such as computers without the latest security updates. In others, such as unsecured USB devices, the solution is to control the vulnerability, typically with software-enforced policies.

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

Extensible Threat Management

Unified threat management (UTM) spawned a new era of IT security. The promise of these integrated security appliances proved to be an exceptional and efficient way of securing commercial networks. However, businesses today face an inflection point, dictated by changing market trends and new technologies that demand more of today’s UTM. Hence the need is for eXtensible threat management (XTM) solutions, the next generation of UTM appliances.

Sponsored Links