The Top Internet Security Screw Ups

The Top Internet Security Screw Ups

With over 22 years experience of defending against Internet Security threats, Brent MacLean, Managing Director of http://www.jbm.net J.B. MacLean Consulting Inc., has seen it all. The top ten Internet security screw ups. So here they are, in reverse order (saving the best to last):

10) Failing to archive firewall log files. Firewalls are often correctly configured with full logging enabled. This tends to generate massive amounts of data, but often they are referred to only when there is a problem. However, left unattended, they can become a problem by their own permissions. Before you know it, you have 10GB of data and a terrible shortage of disk space. Complete system failure soon follows and often the system has to be rebuilt from scratch; not a good thing.

9) Not knowing where your sensitive passwords are documented. Nothing makes supporting customers more of a challenge than if they cannot remember where their passwords are documented and/or stored. That is, of course, if they had correctly and securely documented them at all. Often, passwords remain in the heads of administrators, and are simply shared by word of mouth or by voice mail or email. You might as well write them on a poster and display them on an office wall. Let’s get security protocols in place people.

8) Not systematically scanning all incoming emails for potentially harmful viruses. Without question, email borne viruses are today the biggest internet security threat. Fortunately, most corporations and large networks have aggressive email virus scanning techniques and methodologies--either deployed in-house or using one of the growing numbers of managed services. Unfortunately, some businesses still don’t see the need, thinking that it is sufficient to deploy workstation virus products. Why let the viruses through the front door in the first place?

7) Not blocking Instant Messaging on your firewall. With Microsoft now in a big push to get people using their IM technology, we are beginning to see IM clients freely deployed in businesses, mainly by users. Without proper auditing and control procedures, IM simply opens up a porthole that can be used by the unscrupulous to disseminate viruses and worms. If you haven’t thought through the challenges of allowing IM onto your network, the simplest thing to do is to block it at the firewall.

6) Depending too much on users to patch their own workstations. Let’s face it people; users are terrible at following even the simplest of technical instructions. We all know how difficult Microsoft makes it for administrators to keep their products properly patched. There are tools to make life easier, although it has to be said that some seem to make the task of patching more difficult. Hopefully, one day MS will crack the problem, but until then, depending on users to patch reliably and regularly is a strategy targeted for disaster.

5) Not having an incident response plan (IRP). All networking and security professionals know that even with the best planning in the world, something will always go wrong with technology growing by leaps and bounds. It simply isn’t possible, with today’s complex environments, to be 100% secure. As luck would have it, the first major problem will come while you are on a glorious vacation up some remote hillside in Tuscany. Have an incident response plan, even a very simple one; at least it is a start. What are you going to do when a problem arises, who are you going to call for help and why didn’t you print if off rather than leave it stored on a file server which no-one can now log into? Let’s get some emergency policies in place, everyone. It is simply good protocol.

4) Failing to disable accounts for departed employees. You would not believe how frequently HR fails to tell IT managers that an employee has left the business. They might, if you are lucky, remember to ask them for their mobile phone, but hey, why not let’s leave all their remote access privileges in place! Can we say a disaster waiting to happen?

3) Failing to configure any security on a wireless access point. We all know wireless is here to stay. But, if you are going to broadcast all your company’s data to the world and potential hackers, perhaps it would a good idea to enable the basic security features that comes standard with the product. It may not be the greatest, and it may be inconvenient, but it sure beats having to explain to the boss why he was able to connect to the network from the car park on his new wireless PDA, just purchased at the nearest Best Buy.

2) Not keeping your firewall patched. This is pretty much tantamount to paying for an expensive lock on your front door at home and then leaving the keys in the lock--on the outside! And of course if you are going to patch the firewall software, don’t forget to patch the underlying operating system, if there is one. Let’s keep those software updates and hardware (firmware) current.

And the Oscar goes to...not securing home PCs with their own firewall, VPN and virus detection. It was difficult to decide what should be top of the list, but this won out. With broad band and laptops becoming widely deployed, users are accessing corporate resources from outside your logical boundary. If these machines are not properly secured, then neither is your network!

http://www.jbm.net Security is here to stay and is a growing field in all aspects. So let’s get it right the first time. Here are just a few friendly tips...more to come so stay tuned.
Company: jbm.net
Share |

Related press releases

  • Customize and secure the Internet Explorer.
    [2010-02-02 04:19:44]
    IE Internet Security is a password-protected Internet security utility that customizes different features of the Internet Explorer Web browser. It allows you to disable abilities to change your web br...
  • Comodo Provides Security Freeware in 17 Languages
    [2009-07-07 23:07:26]
    Jersey City, NJ, July 07, 2009 - Until now, Comodo Internet Security had a drawback: it was only available in English. Grateful Internet users around the world install the award-winning freeware on...
  • New Comodo Video: PC and Mac Butt Heads
    [2009-08-07 03:22:46]
    Jersey City, NJ, August 05, 2009 - "Geniuses don't just come to you, buddy," says the Mac in Comodo's rip-roaring new video, PC vs. Mac Parody. In a departure from its normal educational fare—vid...
  • New Security Portal Focuses on Information
    [2006-05-21 00:00:00]
    Security Port is an innovative web site that provides news, resources and information about critical security issues. The new site located at http://www.security-port.com makes it easy for individuals...
  • Comodo Internet Security Earns 5 Prestigious CNET Stars
    [2009-06-30 04:30:03]
    Jersey City, NJ, June 30, 2009 - Comodo's free pc security software, Comodo Internet Security, has earned five stars, the maximum number possible, at CNET/Download.com. Download.com, owned by CNET,...
  • Comodo Is Leader in Matousec's Proactive Security Challenge With a Perfect Score...
    [2010-07-12 03:34:50]
    Research Firm's Criteria Based on 148 Security Tests in the Testing Suite Jersey City, NJ, July 08, 2010 - Comodo, a leading Certificate Authority and Internet security organization, today announce...
  • The Internet security, computer security and access control software!
    [2006-06-14 00:00:00]
    Advanced Security Level is the best computer security application for Windows-based computers. It gives you an excellent administrative support to control the user access rights for your computer by s...
  • SSLGenie offers the highest level of security, provides confidentiality, message...
    [2007-10-28 19:22:49]
    SSLGenie provides privacy and reliability between two communicating applications on the Internet. SSLGenie is an application of cryptography, the discipline of changing information into a form that is...
  • Advanced Security Level
    [2005-06-10 00:00:00]
    Advanced Security Level is the best computer security application for Windows-based computers. It gives you an excellent administrative support to control the user access rights for your computer by s...
  • Blog Updates Ma, Pa and the Corporate Clueless on Security Awareness
    [2005-01-05 00:00:00]
    Seminole, FL -- Business and home computer users are quickly adopting a “security aware” culture in response to the rising amount of internet security problems. A new tool in this fight is a blog affe...