Showing posts with label data breach. Show all posts
Showing posts with label data breach. Show all posts

Tuesday, November 26, 2013

Small/Medium Business and Security/Privacy exploration










In this blog entry I want to explore the effects and the threats surrounding the small business realm and how it is effected by concerns of security and of course indirectly privacy.

But first some numbers.

1) Targeted attacks destined for Small  Business (1 to 250 (employees) accounted for 31 percent of all attacks, compared with 18 percent in 2011, an increase of 13 percent [1]

2) According to the National Federation of Independent Businesses, as many as 30% of an average company's employees do steal, and another 60% will steal if given a motive and opportunity.[2]

3) Almost three-quarters (72%) of data breaches investigated by Verizon Communications’ forensic analysis unit were focused on companies with less than 100 employees.[3]

And the list goes on. But I hope you get the idea.

In fact, depending on the source of data, there is no difference between the security issues of large organizations and small & medium business (SMB) (under 1000 employees).

Both types of businesses rely on computerize ‘everything’, to support their ongoing commercial and not for profit endeavors, never mind using social media for commercial marketing etc.. Both (large and SMB), for the most part, have web sites, use email, store information within databases containing commercial/proprietary information, financial positions (bookkeeping) etc. The employees also have access to various types of data (including those mentioned above), and can carry around that information on smartphones (bring your own device (BYOD)), etc.  Yet, except for some superficial attempt to secure the endeavor’s information, most SMB are vulnerable to threats like those that are mentioned above. The reason is because not enough is done to protect that sensitive information.


Let’s just investigate some best practices for organizations today.

All organizations, whether big or small, should have a Disaster Recovery (DR)/Business Continuity Plan (BCP) to enable them to still function and continue to be in business if an issue presents itself. How many small businesses do have a fully tested, functional BCP? Yet a disaster does not care if the company in question has 100 employees or 5,000.

All organizations should have and enforce internet/email usage policies. This should reduce any blatant misuse and potentially harmful activities of employees (or at least enable employers to take action if need be).

And the list of items that need addressing goes on and on. Many large organizations have specialist(s) whose entire responsibilities are just to ensure the day-to-day operation of the business.

While all organizations have to address critical issues, SMB have a number of strong disadvantages. The obvious one that comes to mind is their lack of resources. Namely most small business cannot afford a full time security/privacy professional. If money is not the issue (ever heard of a company where it wasn’t?) then a lack of expertise would be another major factor (and handicap). It takes time and experience to protect and recover from security concerns. And the basic human thought, ‘it will never happen to us, is something all personnel have to deal with.

So let’s take look at an realistic example of what can  happen to a $5,000,000 dollar a year SMB business.

11)    They have a major system failure and their systems were completely down for 4 days, and only partially in order for another six days. Total loss approx. $175,000
22) Cost to hire professionals to bring their system back on line $12,000
33)  Lost of a number important documents (payroll information, orders, A/R etc) that would be difficult to recreate. Cost unknown.

Total cost $187,000 +

Now lets take a look on the cost of setting up a relatively simple BCP/DR Etc

11)   Set up a working and tested DR/backup plan as part of a BCP $10,000
22)   Set up a commercial firewall, configured to help enforce the companies policies $10,000
33) Set up endpoint security (Anti-malware, Data Loss Prevention etc.) $5,000
44) Administration, training $5,000

Total cost $30,000

For a savings of  about $157,000 and with a big reduction of risk to the organization it then becomes obvious which of the two is the better option.

You can see by the numbers, the company in question would agree, it was a costly oversight not to do the due diligence, to say the least.

So we have all these organizations that are liable to have security/compliance/privacy etc issues, yet money is a huge concern. So what can be done?


There are a number of independent consultants whose specialty is to work with SMB. These consultants can plan and implement the best practices that are needed for an organization. They bring expertise, certifications, etc. that a small organization could ill afford to develop in-house due to the costs involved. For most SMB, once a comprehensive plan is developed and deployed, only a small additional cost would be needed moving forward to make sure everything is tested/working (maintenance/review changes etc) on an ongoing bases .

However, I would be remiss if I did not highlight the importance of finding a competent resource. There are a lot of consultants that have hung their shingle out to find business. So due diligence is in order. Ask for references, preferably with companies of a similar nature. Ask for any professional certifications that are concerned with this domain/realm. Ask for an estimate for the work needed. Get a Statement of Work (SOW) which should also include an established procedure for cost escalation and/or additional work requests. In other words try to make sure you are getting value for your money.


At then end it comes down to that, in our electronic world we work/live in, cutting corners will end up biting you on your bottom line. Ignoring the issues does not make it go away. But there is a reasonable way of mitigating those very real risks.

As the saying goes, ‘an ounce of prevention is worth a pound of cure’, and the sooner the better.




[1] http://www.symantec.com/about/news/release/article.jsp?prid=20130415_01
[2] www.nfib.com/business-resources/business-resources-item?cmsid=29624
[3] http://www.verizonenterprise.com/DBIR/2013/

Monday, October 14, 2013

Robert's Law of security and technology progress


Robert's law of privacy & security.

"The number of advances in capabilities within the online world is proportional to the number of issues with privacy and security."

 A strong statement, some would gather, and something that would seem counterintuative. Would not technology improve security, or as some would say build a better mouse trap?

Let’s delve into this a little further.

We now have a number of cloud computing capabilities that improve the ability to share resources, DropBox, Google Drive, Dump Truck to name but three. These types of software/hardware allows us to share files among our peers within the 'Cloud', thus allowing a more seamless experience when trying to share presentations, school projects etc. Yet this year alone Drop Box (and I only use this as an example as some other cloud suppliers have had security concerns expressed about them as well) had a security issue. In a four(4) hour period, accounts were unlocked and accessible to the general public.

Let’s take another example.

Social media. It is in the forefront of most peoples minds right now. And, as we see, a lot of companies are embracing this new market place with vigor. It is seen, by some, to better connect or re-connect, with friends and family. I for one, keep in touch with relatives from Australia, Hungary and Michigan using a combination of Twitter, Facebook and LinkedIn. Companies are jumping on board as well,  seeing the opportunity to have another marketing vehicle in their arsenal,  providing enhanced customer service and differentiating themselves from the competition. Yet there have been a multitude of security and privacy issues with the social media suppliers. For example, there was the time a that a certain number of users  potentially exposed their personal identifiable information within Facebook. Twitter, another social media darling  had a number of issues concerning security as well.

And another

RFID = Radio Frequency IDentification.. We all use it. But what is it? It actually encompasses a lot of different devices and uses. They include the NEXIS card, issued by the US and Canadian governments to allow pre-screened passengers, speedier border crossings. It allows Jane Smith to tap her credit card on the gas pump reader to pay. it can be used to track merchandise in warehouses etc. Yet within a very short period of time after general deployment in the public arena security issues started to be asked/exploited in both the public as well as informed experts hands.

And finally within the last month (as of this is being written) the fingerprint recognition capability within the new iOS 7 had it’s security questioned. The new capability allows anyone with a new Iphone 5Sc  to buy songs etc., using their fingerprint, in the ITUNE store (more to follow I am sure). Yet within a very short period of time, concerns about the security of this capability surfaced.

So what does this all mean? Should we ban all new technology? While I am sure there maybe some people who would say yes (as there are still some people who believe the world is flat and Elvis is alive) that is not going to happen. If we would have banned technology then, no computers? Or if we waited and implemented the ban when transistors came about. or when the Arpnet/Internet was created, or when the WWW (world wide web) etc. where would we be now?

In reality as the human race continues to explore and innovate, technology will move forward.

So Am I advocating we just plow ahead full steam? Well.....

I think we need to recognize that with each innovation, invention etc the security privacy landscape changes. That when we embrace the new mouse trap, we should also realize that it brings with it potential security privacy issues that need to be addressed.

Let’s take the last example I used.  Apple introduced the new capability stating that Iphone 5S is an innovative way to simply and securely unlock your iPhone with just the touch of a finger. However, noticeably absent was any further discussion about the security component.  While I don't expect a detailed discussion, I do expect a phrase or two addressing the obvious concerns.

Why is it that security (and indirectly privacy) is such  an afterthought.  We introduce new ways to build a better mouse trap1 yet we do not look at what the implications for this new technology are and what changes need to be so it is implemented safely and securely. Companies jump on bandwagons all the time without fully engaging in a analysis of the various issues of concern. Apple introduces a finger scanner, yet a hack was published within the month. Banks introduced 'chip and pin' credit cards and then tried to deny any reimbursement for fraudulently used cards.

So what does this all mean? In all our dealings, whether it is building a new web site (Privacy by Design) or a new technology, we should be advocating Security by Design in what ever we do. It should not be an afterthought. We should expect that there will be issues and not wait for some smart hacker to point out the problems. We should take the bull by the tail and face the situation. Be proactive rather then reactive as we seem to be most of the time. If we do this, then we will hear less and less press releases on how some new technology was hacked and broken. And as a result, a fix had to be  developed and deployed. Never mind the PR issues that raise their head during this event.

FOOTNOTE

1 The actual saying goes like this 'If a man has good corn or wood, or boards, or pigs, to sell, or can make better chairs or knives, crucibles or church organs, than anybody else, you will find a broad hard-beaten road to his house, though it be in the woods' Ralph Waldo Emerson. I prefer the modern version for brevity, if for no other reason.