The simple act of reporting hackers to authorities is one of the most effective weapons businesses can use to fight cyber criminals, but it is also one of the most rarely used.
"Companies are naturally resistant to tell the world they have been victims of fraud, they are afraid people will laugh at them," Pottengal Mukundan, director of the International Chamber of Commerce's commercial crime services said Wednesday.
Of course, it's not just that companies are worried that other companies will laugh, but also the negative effect such an admission can have on customer relations and stock prices, Mukundan said here at InfowarCon 2000. Reticence to report security breaches has an affect.
"In the absence of actual meaningful information coming from corporations, it is difficult to stop the crime," he said.
Various studies recently have found that 90 percent of respondents detected computer security breaches in 1999. Surveys have been done recently by the Computer Security Institute and the US Federal Bureau of Investigation's computer intrusion squad with large companies and US government agencies forming the bulk of respondents. Of those who were surveyed, 74 percent report financial losses because of security breaches, Mukundan said.
A similar survey conducted in the UK on behalf of the Department of Trade and Industry showed that 60 percent of respondents suffered a breach of computer security in the last two years, he added.
"It appears to be a rising problem, but how do we know if these figures mean anything," Mukundan said.
The way things are now, the "good guys" are keeping information to themselves, while the "bad guys" are freely sharing information with each other.
"It is important for these companies to portray a good image, so the good guys end up keeping the information to themselves," Mukundan said. "The baddies, on the other hand, are out there freely sharing information with each other on the Web."
Ready-made kits for creating Trojan horses or viruses are available to anybody on the Internet, opening companies to a whole new threat.
Take the recent "ILOVEYOU" worm that jammed e-mail servers. "The software was not sophisticated, but what the authors lacked in technical expertise, they made up for in guile. It brought the e-mail systems of some governments to a halt," he said.
But the most interesting thing about the worm was that it depended on unprepared humans to run it, he said. "There is no reason for people sitting in an office to open an e-mail which is clearly suspicious, and definitely not work related," he addedThe human angle in Internet security is perhaps most often ignored, Mukundan said.
"Take the physical office building, for example, there is very little use in spending millions on software security if you don't have decent security on the premises," he said.
Human error in security matters seems to be a larger problem as well, with government laptops containing classified information stolen in London, and former US Central Intelligence Agency Director John Deutch was stripped of security top clearance when it was revealed that he stored classified documents on his unsecured home computer, which he used to send and receive e-mail and to access the Internet.
"The Internet is fundamentally insecure," Mukundan said. "Internal networks should be physically removed from the Web, and it makes sense to run static Web sites from a CD-ROM instead of a server."
Software filters are useful as well, he added. "But there is no point in having this system if the IT manager is too busy to actually look at the logs."
Equally important is the adoption of international laws related to cyber crimes, so that criminals don't slip through the gaps in the legal system, Mukundan said.
"Also, there is still a feeling that people who commit online crimes are not as bad as their physical counterparts," he said. "This needs to be changed as well."
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Refresh your AUP: Top tips to ensure your acceptable use policy is fit for purpose
Data grids and service-oriented architecture
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Email Archiving Implementation: Five Costly Mistakes to Avoid
Making the Business Case for IT Consolidation
Taking On Demand CRM Integration to the Next Level
Email Archiving 101—Customer Case Study
Best Practice in Building an Integrated Information Management Strategy
Zones provide focussed content from Computerworld and leading technology partners.Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Virtual magic: HR specialist throws out 40 servers, adds 8TB SAN and saves $100,000 for disaster recovery 2008-12-01 15:28:00+11
Sybiz adds up for SMEs in downturn 2008-12-01 14:27:00+11
EXCOM scores back-to-back award trifecta 2008-12-01 10:46:00+11
Citect extends SCADA networks with mobility solutions 2008-12-01 09:48:00+11
Citect extends SCADA networks with mobility solutions 2008-12-01 09:48:00+11
Controlling storage costs with Oracle database 11g
Organisations must embrace new ways of storing data that don't involve adding more of the same hardware to accommodate data growth and dealing with duplication as well as uncompressed information. Simple steps such as tiering storage, moving data across these tiers and reducing the amount of data to be managed, can dramatically reduce capital and operating expenses. Read on to learn how to implement these steps in your business.











