Top IT Security Bloggers

Protect against cyber crime, but don’t forget about human error



Cyber_threats


According to a BBC report released this month, GCHQ, a UK government intelligence agency is to advise organisations to ‘create a more security conscious culture’.


This follows an earlier disclosure in June 2012 that MI5 is battling an ‘astonishing’ level of cyber attacks on UK industry. In fact, the British government estimates that UK businesses lose a staggering £21bn a year to Internet crime. Cyber criminals aren’t partisan – their targets span all sectors, and this year alone victims have included government bodies, charities, banks, engineering firms, broadcasters and academic institutions.


Interestingly, the BBC report also highlights a recent survey which suggested that ‘nearly 9 out of 10 UK businesses were very or fairly confident about their defences.’


This points to a worrying disparity between enterprises’ perceptions of the capabilities of their IT security strategies, and the reality. It also raises the question: do organisations really understand what the threats are? And if you don’t know what’s out there, how can you protect against it?


The reality is that too many organisations are woefully unprotected against cyber crime and data loss, but remain unaware of this fact until it’s too late 


In an attempt to address this issue, the GCHQ will suggest at a forthcoming foreign office press conference that in many cases, confidence in IT security systems is misplaced. To better protect their IT infrastructure, the government will recommend that enterprises make security a more visible part of everyday corporate life.


This is something Clearswift has been saying for a very long time. It's not always possible to know all the potential threats that could damage your organisation, but there are simple steps you can take to step up your security measures regardless.


An educated workforce is the backbone of any robust security strategy. We have long recommended that organisations: 1) establish a policy 2) educate employees 3) enforce with robust web and email security solutions that enable, rather than prohibit, free-flowing digital communications.


It’s also worth remembering that although cyber crime is a real and significant threat, accidental data loss caused by human error can be just as damaging.


It’s not enough to simply block inbound threats; protecting your data from the inside is crucial. Businesses need to find a way to manage the two-way flow of digital communication inside and out of the organisation. Reinforcing intelligent web and email gateways with clear policies, education and openness, is a great way to start.


Susannah Woolmer



 





Permalink

| Leave a comment  »

Read the full article
CSO Corporate Partners
  • Webroot
  • Trend Micro
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Sophos SafeGuard Enterprise

Your central key for data protection

Security Awareness Tip

Incident handling is a vast topic, but here are a few tips for you to consider in your incident response. I hope you never have to use them, but the odds are at some point you will and I hope being ready saves you pain (or your job!).


  1. Have an incident response plan.

  2. Pre-define your incident response team 

  3. Define your approach: watch and learn or contain and recover.

  4. Pre-distribute call cards.

  5. Forensic and incident response data capture.

  6. Get your users on-side.

  7. Know how to report crimes and engage law enforcement. 

  8. Practice makes perfect.

For the full breakdown on this article

Security ABC Guides

Warning: Tips for secure mobile holiday shopping

I’m dating myself, but I remember when holiday shopping involved pouring through ads in the Sunday paper, placing actual phone calls from tethered land lines to research product stock and availability, and actually driving places to pick things up. Now, holiday shoppers can do all of that from a smartphone or tablet in a few seconds, but there are some security pitfalls to be aware of.