Monday, March 10, 2014

Cyber Security - Important things startups should keep in mind



On Dec 15th, 2013, Target found out that cyber criminals breached the Target security system and stole credit card and debit card information of 70 million individuals. The question that pops in our head is, Is it that easy to get into a corporate company's database to steal information? Yes and No. Yes because every cyber breach till date is because of the sloppiness of the company's security team. And No because it does take knowledge to breach a database. Target definitely could have added extra protection. Target's security team did warn them beforehand to add security to their point of sale transactions, which was not heeded by Target. 



So what can we do about this? McAfee says that the Target attack was indeed defendable. They say that companies think that if their point of sale systems are not standard, then they are safe, which is not the case and is proved by Target Breach. In fact, the breach was done using software that we could get from any cyber crime community. There are ways to prevent these attacks and every company, focuses on these set of points to protect themselves from cyber threats. 
  • Spam - Spam emails are the easiest way of infecting a system if it bypasses the internal network. Spam emails are infected with viruses and malware hosts. If one infected email gets into the network and is able to find one vulnerable system, then the whole internal network can be vulnerable to security threats. Companies always employ multilevel security. Multi level security is similar to giving access rights to each user depending on the type of job. An employee simply receives information that is strictly 'needed to know' and the information will not be useful if it is held by someone else. Email spam filtering, electronic mail monitoring is absolutely necessary at this point.

  • Gateway Protection - Protect the point where the company connects to the internet. This is the point where firewalls are hard at work and it is significant to secure this layer with utmost caution. Web content filtering, a high end security system with excellent antivirus and firewall is necessary at this point.

  • Endpoint protection - Each computer has an up to date anti virus and spyware software which is updated and runs scans frequently. If a system is infected, the security team immediately disconnects the system from the internal network and dis-infects the system. At this level, it is in the hands of employees to keep the system clean and follow company guidelines. Severe action is taken on the employee if the security team finds out that the employee's system is infected because of the employee's negligence.

  • Testing and Training - Even though, the security team does its job better, hacktivists still expose flaws in the system. Companies make sure that the cyber security team is on top of it, and tests the system for vulnerability and solve all the bugs before hand. Every employee is educated on how to utilize the system and how to be aware of security threats.

Even though, there are various ways to protect oneself and companies are aware of it, the hackers need only one flaw to breach the system. Evidently every software does have flaws. So, it is a battle that will never end. Target did not require a new silver bullet to defend their systems. The security systems they needed was readily available. It is important to note that hackers never rest, So should companies. Companies should work hard to achieve an upper hand and secure their systems with comprehensive security technologies.


References: 



2 comments:

  1. This blog provides useful information about cyber security. The one thing I liked the most is the way you have organized your blog. I also liked the way you have provided some techniques on how the data can be protected from cyber-attacks. Your description about Spam, Gateway Protection, Endpoint protection and Testing and Training is clear and informative.

    ReplyDelete
    Replies
    1. Hi Swathi,

      Thanks for your review. I am happy that you like my post.

      Delete