10 common security ailments and 10 practical remedies
Unwired and Unsafe Workers
The Hole | The CISO of the Midwestern financial services company shares this nightmare: An executive decides she wants to put a wireless access point in her house so she can work at home from anywhere in her house. Her son gets her up and running. She wirelessly logs into the network, and she uses the default password for the connection that came straight out of the box.
The Problem | "Go to every single hacker site, and you can find every default password and user ID [for wireless routers]," says the CISO. "Home PCs are one of the greatest vulnerabilities." And once this executive authenticates, others can see how she did it, "then people are in," the CISO says.
The Solution | Back to the basics with this one. CIOs need to make sure all employees who work from home know that they have to change all the default settings, and they can’t forget about firewall, VPN, antivirus patching and authentication tools. That all takes an omnipresent security education program, but to this CISO, it’s the cost of doing business today. "The struggle with security education is getting it so it becomes like breathing," the CISO says. "Users have to become smarter about how they do things."
40 Million "Served"
The Hole | In June, MasterCard announced that CardSystems Solutions, a third-party processor of credit card transactions for MasterCard, Visa, American Express and Discover, allowed an unauthorized individual to infiltrate its network and access cardholder data.
The Problem | Up to 40 million cardholders’ information could have been exposed. It turns out CardSystems had violated its agreement with the credit card companies: It was not allowed to store cardholders’ account information on its systems, and yet it did just that.
The Solution | If a company has an agreement not to store another company’s data on its systems, it shouldn’t. And if for some strange reason it becomes necessary, the company had better ensure that it has the necessary controls. "All of those cases of breaches speak to the need for a good, old-fashioned defense, in-depth, with multiple layers of control," says PwC’s Lobel. For example, he says, instead of just having a firewall, companies should have multiple layers of controls on their network. Or rather than just using SSL, companies need to use authentication too. "You get into the security versus ease-of-use trade-off and cost," he says. "That’s the decision that businesses have to make with their eyes wide open."
$firstKeyword



