A Johannesburg-based IT security company has urged organisations to ensure that their networks are secured both internally and externally, as 70% of security threats originate from inside an organisation.
IS Digital Networks MD Barry Cribb says 40% of companies are likely to have had the integrity of their systems compromised in an information security incident in the last 12 months, while 15% of companies have experienced criminal or illegal use of their computer systems during that time.
Cribb adds that, in the past 12 months, 14% of companies suffered theft of information or data, or damage to data and 40% suffered physical theft of hardware. Some 11% suffered unauthorised access to their systems and 9% have experienced some type of financial fraud.
These statistics, he tells ITWeb, have been gleamed from several global reports on IT security. Most internal security threats result from actions of disgruntled employees.
"Vulnerability testing of an organisation`s network is an often misunderstood and complicated exercise. If not done properly it could have disastrous consequences." He adds that often organisations spend considerable sums of money on vulnerability testing and are told that they are safe when their systems are not.
"Understandably, this leaves many managers questioning the value of the test and the return on investment if their systems are then compromised. It is our concern that there is insufficient testing being carried out."
Businesses depend on the effectiveness of their network security, yet, he says, most companies fail to have their systems independently tested, which is crucial as these tests take a totally unbiased look at security.
"Several recently-published reports on information security recognise that regular independent testing is the only way of checking integrity to ensure that the security software delivers the level of protection for which it was designed," says Cribb.
Testing should highlight an incorrect firewall configuration or rule-set errors, and ensure that systems comply with the company`s security policy, if it has one. It will also detect missing patches and upgrades, Cribb adds.
Details of IS Digital`s "no-find-no-fee" testing can be found at http://www.isdigital.co.za/guaranteed_testing.html

