- +
Ticked Off at Tick the Box Mentality 04/02/2008 13:01:15
Does your executive search firm know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?Does your executive search firm know its MIS managers from its elbow? Does it even know the difference between an MIS manager and a CIO, and if it does, can it explain that difference to its corporate clients?
Read up on the latest ideas and technologies from companies that sell hardware, software and services. How to Beef Up Your Sales Pipeline
Optimized Back-up and Recovery for VMWare for VMWare Infrastructure with EMC Avamar
Email Archiving Technical Overview
Best Practice in Building an Integrated Information Management Strategy
Revolutionising Back-up and Recovery
CRM your salespeople will love
Improving Sales Productivity: An Opportunity for Sales and IT Leadership
Email Archiving 101—Customer Case Study
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
A CFO at a Fortune 1000 company holds his cursor over an e-mail that appears to be from a direct report. In reality, it's from someone he's never met, a criminal who's targeted and stalked the highly compensated executive, searching through company SEC filings and compiling personal details through corporate and social networking sites.
Now the cybercriminal is in position to launch an attack that will allow him to mine the CFO's hard drive for credit card numbers, passwords to corporate databases or other proprietary information.
In one click, the CFO is going to have himself a big problem. If you're his IT manager, you're going to have one too.
If Viagra-touting spammers and credit card phishers are the carpet-bombers of computer crime, so called C-level attackers are the snipers. They mine information from a relatively small number of wealthy or high-status individuals in positions of power.
The treasure sought is corporate and/or personal data, both of which can be extremely lucrative. The hackers can use the information they garner to wreak further havoc elsewhere or, more likely, they will sell it and resell it for profit through online underground servers.
These types of targeted C-level attacks are rare, but they're on the rise, and they're sophisticated enough to make the average IT manager's blood run cold.
Following the money trail
C-level attacks "started out about a year ago in very low numbers but have been ramping up since," reports Matt Sargeant, senior antispam technologist for MessageLabs, a New York-based security services provider.
Last summer 24-year-old Russian Igor Klopov and four others were indicted by a New York grand jury for stealing US$1.5 million and attempting to steal another US$10.7 million from more than a dozen wealthy victims. Klopov used the Forbes 400 list of the world's wealthiest people to pick his marks. They included Texas businessman Charles Wyly and Anthony Pritzker, president of TransUnion Credit (and member of the prominent Pritzker clan of Hyatt Hotel fame.)
The government charges that Klopov found information on some of his victims' real estate holdings and lines of credit -- much of which was publicly available -- and used it to build dossiers on them. He used Monster.com, CareerBuilder.com and similar employment sites to recruit accomplices.
The gang created and used fake IDs to contact the victims' financial institutions (JPMorgan Chase, Merrill Lynch and Fidelity Investments) to try to gain information on their accounts, get duplicate checkbooks and the like. The institutions flagged the attempts and contacted the authorities.
An IT manager at a Fortune 500 financial institution says his company, too, was recently affected by a C-level attack. In this instance, a bank executive's laptop was hacked while he was working from home. The hacker captured passwords and log-ins and tried to access some of the bank's accounts. The attempt, which was later traced to a Russian IP address, failed, says the source, who spoke on condition of anonymity.
George Brown, a database and security consultant, says he always tells client CEOs to guard their private information zealously.
"It's the Wild, Wild West out there. Publicly held companies are forced to reveal a lot of information about their executives, so that's already out there. I tell them not to compound that by putting more information up on social networking sites," says Brown, CEO of Database Solutions Inc. in Cherry Hill, N.J. "Don't put anything out there that you don't absolutely have to."
One executive, the CIO of a Boston-area health care organization, hears that message loud and clear. Though she says she hasn't experienced any targeted attacks directly, she is extremely cautious in how she handles e-mail of any kind. "I do not open anything unless I'm absolutely sure I know where it comes from," she notes. "If I miss something important, that person will call."
The CIO -- who says that the percentage of her organization's IT spend that goes to multilevel security increases every year -- doesn't participate in any business social networking sites either, and she recommends that other executives follow suit. And talking publicly about security issues? Definitely a no-no, she says (hence her anonymity), "unless you want to make yourself a target."
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Mid-Comp’s Odyssey supply chain solution allows Sydney University students to do their home work 2008-10-08 15:11:00+10
AIIA Challenges the ICT Industry to Reduce Australia's Carbon Footprint 2008-10-08 12:16:00+10
Australian SMBs Love of Mobile Phones and Increased Data Speeds Will Drive Mobile Spending Higher, Finds IDC 2008-10-08 10:21:00+10
VeCommerce Launches Top Ten List of Personal Security Breaches In Lead Up to National ID Fraud Awareness Week 2008-10-07 15:10:00+10
Multimedia Technology signs exclusive National distribution agreement with Freecom 2008-10-07 14:30:00+10
Wireless LANs: Is my enterprise at risk?
Achieve an overall understanding of the risks associated with wireless LANs. Discover their inherent properties, as well as what makes them different from wired networks. Read on to uncover a list of recently published articles on real-life breaches and incidents illustrating the need for proactive measures to mitigate wireless security risks.











