Friday, 15 July 2011

Lessons from Booz, RSA, Epsilon, etcetera: Partners may be your weakest security link…

Computer hackers by and large focus on the weakest link of an organization’s security system. Whether it’s an unprotected server, a newly discovered system vulnerability, or an unsuspecting employee’s computer that is connected to the corporate network, cyber criminals are experts at sniffing out the weakest link.
On the surface, this week’s breach of 90,000 military e-mails and password hashes may look the same. After all, the hackers claiming responsibility for the break-in did so through an unsecured server in a network that basically had no security measures in place. What’s different about this attack, however, is the exploited server was not the military’s. The server belonged to government contractor, Booz Allen Hamilton. In other words, this criminal strategy went beyond the walls of an organization’s own network defenses.
In the case of the Epsilon security breach, where millions of customer email addresses were compromised, hackers targeted a single entity to steal private data on many of the marketing giant’s big-name customers like Chase, Citi and Target. The Booz Allen hack reverses that scenario. Instead of going after one to get to many, cyber criminals targeted multiple entities to get to one.
Much like the supply chains of the 1990s that tied systems together, today’s business enterprises are built on the same idea. Unfortunately, with a number of different partners connecting in real-time to a central network, an organization’s security is only as good as its partners’ security practices. If even a single partner does not adhere to today’s best practice security standards, what will result is a weakest link of the chain. Cyber criminals know this, and this week’s military breach is a prime example of what happens when hackers exploit a business partner to get to another business.
In today’s world, the epicenter of a cyber attack isn’t necessarily at the core of your network anymore. With so many endpoints connecting to your enterprise, how can you protect yourself when you can’t control the assets people use to get to your network? The fact is, organizations and people are getting hit in and between companies. The fight against cyber crime is becoming more about the weakest link in the entire value chain, not the organization, itself.
Insisting on best practice security standards from all of your partners can be a first step to protecting your endpoints from attacks that start outside of your network. However, relying on your partners to maintain updates to ensure your corporate policies are enforced can potentially leave your network vulnerable to outside attacks. That’s why when pushing security standards, we recommend mandating a proactive security posture for your own endpoints and those of all of your partners. Naturally, we feel strongly that deploying an application whitelisting solution like CoreTrace Bouncer is a key component of that proactive strategy.

by JT Keating

Gartner Wireless IPS Marketscope rates AirTight “Strong Positive”!

The latest Gartner research on wireless IPS has just been published and AirTight has received the highest rating of “Strong Positive”.

by Mike Baglietto 

Learning from Morgan Stanley’s Data Breach

Morgan Stanley Admits to Loss of Unencrypted CDs” reads the latest data breach headline in SC Magazine. I can’t help but shake my head as this could have been easily avoided. The lost information contained 34,000 client account and social security numbers, among other confidential data. The CDs were delivered in tact to the New York State department of taxation and finance’s mail room and disappeared somewhere between there and the intended recipient’s hands.
IT departments worry about data security and do their best to put systems in place to prevent this kind of data breach. So how does it happen? Some of the biggest risks come from employees who work around an IT mandated solution. In this case, it looks like there was a file too large for either Morgan Stanley’s, the recipient’s, or both systems’ email restrictions. For the employee who opted to mail the unencrypted CD, the magnitude of the potential loss and risk involved may have never crossed their minds or took a backseat to Getting the Job Done.
You, as an IT professional, can easily save the day and provide a way for your users to share information and collaborate securely.
In addition to banning CDs, thumbdrives, free dropbox-type of applications, FTP or USB sticks, implementing secure file sharing technology such as Accellion’s helps enterprises securely share files in a way that can be seamless to employees and their intended recipients. With Accellion, you can track and manage who has sent and downloaded what file, where, and via what device.
Since Accellion supports any file format and size, I suspect Morgan Stanley’s CDs were used to transfer files an Accellion user would’ve been able to send easily. With Accellion, shared files are stored securely on a server, so issues with the recipients’ email storage limits are also bypassed. And the file is encrypted in transit and at rest.
Some of the world’s leading financial services organizations use Accellion to protect their sensitive data including: AEW Capital Management, American Capital, Australian Unity, Bank of Scotland, Bank of Spain-Miami (Banco Santander), Cigna WorldWide Insurance Company, Covenant Bank, Deloitte & Touche CA, Georgia Bank and Trust, Farmers Insurance Group, Federal Credit Union, HeathMarkets, IMA Financial Group, Inc., KPMG, MIB Solutions, PFS Global Ltd., Princeton Financial Systems, United Community Bank, ViewPoint Bank and Xpress Holding to name a few.
Financial services firms need to protect their sensitive data in a way that’s easy-to-use for employees and easy-to-manage for IT staff. Accellion solutions can help.

by Accellion

Beyond the Glitz and Glamour: Mobile Collaboration

Nothing is more interesting to me than watching people interact with their mobile devices, whether that’s an iPhone or iPad, Android, BlackBerry or even those rare Windows phones. People swoosh their fingers across the screen to access page after page of content…whether it’s the New York Times, Washington Post, Facebook, Twitter, and even business content. I know it’s hard to believe, but watching this behavior is actually quite fascinating. People interact with their mobile devices when they’re alone, out with friends or even on a date. Yes…I have seen it happen and probably am guilty of it too.
Clearly, mobile devices have become extensions of their owners and close attachments have been formed. Flashy people bejewel their mobile device cases with faux rhinestones. Many women change mobile device cases depending on what they’re wearing…just as they would change purses. And, of course, people who don’t care either way, or prefer a traditional looking phone, tend to have sturdy cases in “wonderful” black, grey and white hues.
But beyond the glitz and glamour involved with the look and feel of mobile devices, the material that people access is most important. No one would be obsessed with their mobile device if content was useless or boring.
Today, people want information on the go. In particular, busy professionals want full access to work files whether they’re at a coffee shop, security line at the airport, or on the road. With this in mind, Accellion delivers mobile apps for the iPhone/iPad, Android and BlackBerry mobile devices. Accellion Secure Collaboration customers can securely view their workspace files, make comments on files, and get notified when collaborators have made comments or added files to a workspace. Accellion Mobile Apps ensure that business can be conducted securely on the go, whether you use a leopard print cover is up to you.

by Nina Seth 

Friday, 8 July 2011

EOL for Space Shuttle – 30 Year Product Life Better Than Most Cars?


Atlantis on October 3, 1985 Photo Credit: NASA/KSC
This week, after 30 years of service, the Atlantis Space Shuttle is scheduled to make its final flight before retirement. 30 years ago we had no iPad or iPhone, we didn’t even have the Internet. MS-DOS was just released by Microsoft, the hottest computer was the Sinclair ZX80 retailing at $199.95 and the “Best Selling Car in the America” was the Ford Escort. With this technological perspective the Space Shuttle design is a mind blowing achievement.
It’s become easy over the years to take for granted the almost routine take off and landings of the Space Shuttle. Yet a 30 year product lifetime, for any product, is impressive. Compare the Space Shuttle’s 30 years of service to the ten years expected lifetime of a car and three years for a mobile phone. Admittedly, the Space Shuttle didn’t get daily use, but still most technologies don’t have a 30 year product life. Most people would consider themselves lucky to get two years of service out of laptop.
At Accellion, we’re proud that our file sharing solution has been in service for more than five years at customers such as P&G, Ogilvy & Mather, St. Jude’s Children’s Hospital, L’Oreal, and Hilton Hotels to name just a few. Along the way we have enhanced Accellion file sharing, to support new technologies such as virtualization, cloud, and mobile apps. And, yes, our customer base has grown significantly over the years, including the addition of NASA several years ago. While product life is definitely influenced by technological advancement, customer satisfaction is perhaps the bigger contributing factor. At Accellion, our extremely high customer renewal rate (>98%) represents not only a long product life but, more importantly, that our customers are our old friends.
Congratulations and best wishes to NASA for the final Space Shuttle launch.

by Paula Skokowski

Wednesday, 6 July 2011

Top Endpoint Security Stories for June 2011: Malware developers show just how efficient they’ve become

We’ve always known how tenacious hackers are, working around the clock to infiltrate corporate networks. In June, we found out just how efficient they are. Mutating malware that bypasses security updates within hours and unconventional cyber attacks on seemingly secure networks have prompted the need for stronger endpoint defenses. For many, whitelisting is the answer. Here are some of the top endpoint security stories for June 2011.

Hackers move quickly to evade the latest security updates

In June, we saw two examples of how quickly cyber criminals can adopt to change. Security updates to both Macs and Windows held hackers back only long enough for them to create new variants that allowed them to resume active attacks on the same fixed vulnerabilities a few hours later.
According to the article, “Apple’s malware detection update circumvented in 8 hours,” malware developers were able to rewrite code overnight to evade the latest Mac updates. In another incident, “Hackers move fast to exploit just-patched IE bug,” just three days after Microsoft patched 11 bugs in Internet Explorer, cyber criminals were exploiting one of the patched vulnerabilities.
With hackers working non-stop to develop new malware and malware variants that can bypass even the most recent updates and signatures, organizations need a solution that doesn’t place a band-aid on known vulnerabilities that criminals can peel off hours later. Security tools like application whitelisting do this by simply preventing the execution of all unauthorized applications.

Poor user updating practices creating unclosed security holes

While security patches have their own challenges keeping cyber criminals from returning to exploit known vulnerabilities (see above), a recent study by G Data SecurityLabs found that users certainly aren’t helping (which is not a surprise to any InfoSec pro).
In the article, “Malware Authors Relying on Poor User Updating Practices,” cyber criminals are taking advantage of users’ negligence around installing the latest security updates. As a result, hackers are targeting both current and older unclosed security holes, said Ralf Benzmüller, head of G Data SecurityLabs.
“Even though an enormous number of program updates are being provided, users should not be fooled into deactivating automatic update functions. Not only does this apply to Java, but it should also apply in general to all browser plug-ins used and all applications installed on the PC.”

Whitelisting a top strategy for combating modern malware attacks

As cyber criminals exploit any vulnerability they can to infect corporate networks, implementing security strategies that stop targeted attacks that quietly stealing sensitive data is critical for combating modern day cyber threats.
The article, “Top five strategies for combating modern computer security threats,” outlines some techniques for protecting computer systems from unauthorized and malicious software from exploiting a user’s laptop or computer. One of the recommended solutions is application whitelisting.
While there are valid concerns around preventing attacks like memory exploits and handling dynamic environments without impacting user and IT productivity, advancements in leading whitelisting solutions have resolved these issues to provide Total Application Control (TAC) that allows organizations to proactively defend their network endpoints from modern malware attacks.

A key goal of today’s cyber attacks: Establishing a “persistent point of presence”

Today’s cyber criminal is not your stereotypical crook who breaks in, steals the loot, and gets out as fast as he can. According to Gartner analyst John Pescatore, the goal behind many of today’s attacks is to surreptitiously establish a persistent point of presence inside a network and use that to snoop on and steal information.
“A common thread through many damaging incidents is targeted executables getting installed on critical servers or high value employee PCs.”
In the article, “Attacks on IMF, Lockheed and others highlight need for defenses against targeted attacks,” a recent rash of successful cyber attacks against supposedly secure organizations has prompted the need for enterprises to deploy stronger defenses to protect their networks against highly targeted and persistent threats. Using whitelisting products alongside other AV tools to automatically block any unapproved applications from running on a system is one way to defend endpoints against custom Trojans that have been seen in many recent attacks.
Thanks for reading this month’s recap on some of the security industry’s biggest stories. I encourage you to regularly stop by to read our blog. Your thoughts on these important stories are always welcome.

by JT Keating

Monday, 4 July 2011

In the Cloud, Outside the Cloud…Securing Your Information

In the technology world, we’ve had a few action packed weeks. First, Box announced their integration with Google Docs. Then, Microsoft made their highly anticipated announcement of Microsoft 365, their cloud solution of productivity apps that includes Microsoft Office, Microsoft SharePoint Online, Microsoft Exchange Online and Microsoft Lync. Next, Google rebutted the announcement in their enterprise blog entitled “365 reasons to consider Google Apps”. And lastly, Box jumped into the fray with a ding at Microsoft for being late to the cloud game and why Box’s open platform is better for consumers.
You might be wondering if there is any valuable information in all this noise. Well, despite the proliferation of cloud computing, Microsoft Office is still the de facto application for business – with 31 million copies of Office 2010 sold. And it’s likely that those organizations will continue to use Microsoft products. But many small to medium (SMBs) businesses and newer companies have embraced the cloud wholeheartedly. They often use more consumer-oriented solutions such as Google and Box due to lower costs, flexibility, and perceived ease of use. They are often looking for more platform-agnostic solutions and not necessarily for enterprise-class solutions, which offer the security that every business requires today.
At Accellion, we spend a lot of time thinking about how employees at large and small companies securely share and send files. In fact, we’ve built our entire business around the premise that information can be shared securely. We offer our solutions through a web interface, native mobile apps, and plug-ins for Microsoft Outlook, OCS and SharePoint, as well as other business applications such as iManage so that users can securely share files through the business applications they already use.
For those of our customers who migrate to Microsoft 365 or are new to Microsoft 365, Accellion offers an Outlook plug-in that enables your users to securely send files to recipients.
Remember that no matter whether your organization uses a desktop or cloud solution, it should allow you to securely send information. To learn more, download our whitepaper, “Secure File Transfer and Collaboration in the Cloud: Maximizing the Benefits While Minimizing the Risks.”

by Nina Seth