In today's climate, companies face the increasing threat of business information theft and fraud. The biggest threat comes from within the business, ranging from negligent system end-users, and internal fraud activity to attacks by disgruntled employees, costing organisations millions per annum in both losses and the investigation, recovery and containment efforts associated with securing business data and access. Blue Turtle, through Quest One Identity Manager, is delivering effective identity and access management (IAM) to customers in SA.
“As threats increase, Blue Turtle provides a key solution in Quest One Identity that ensures business and IT are able to manage and control access to their applications, systems and data, with comprehensive auditing, reporting and control over access permissions - all through a central and intuitive Web-based front-end. Additionally, Quest's IAM solutions assist businesses with governance and legislative compliance,” comments Michael Hutchinson, Infrastructure Product Manager at Blue Turtle Technologies.
“Today's security challenges are drastically different than they were just a few years ago. The advent of cloud computing, mobile access, and new compliance concerns has essentially taken everything organisations thought they knew about security best practices and flipped it on its head. As the nature of doing business changes, companies need to get smart - fast - about building strong and sustainable identity and access management strategies. As a trusted advisor and steadfast technology provider for nearly 90% of the Fortune 500, Quest Software has amassed the knowledge, experience, and technology necessary to successfully guide organisations through the new security landscape,” adds John Milburn, vice-president and general manager, Identity and Access Management, Quest Software.
If you're feeling a little paranoid about data security threats, you can relax. You're not paranoid! The threats are real. While financial institutions have gotten smarter (the recent breach at Global Payments notwithstanding), companies in other industries, such as retail and hospitality, are now in the crosshairs, and hackers and scammers are finding easier prey in small to medium businesses.
According to the Verizon Business report: “2012 Data Breach Investigations”, last year saw the second-highest data loss total since the company started keeping track in 2004. Some 855 incidents resulted in 174 million compromised records.
A couple of other stats are startling:
* Ninety-six percent of the attacks were not highly difficult.
* Ninety-seven percent of breaches were avoidable through simple or intermediate controls.
This suggests that the problem within targeted organisations has more to do with education, process, and vigilance than with evil geniuses outsmarting expensive technological defences. In fact, a major contributor to the problem is simply the way the world has changed over the last few years. It used to be easier to think about data security (if not to put it into practice): companies just had to physically secure hard drives and archives. But today, bits are residing and flying all around the globe, and with cloud computing and mobile devices, you may not even know where your data is!
Given this reality, the most important step to preventing breaches is to recognise your company's vulnerabilities and fully understand the processes you need to develop to meet the challenges. Only then can you decide on the right technology for implementing these processes. With this in mind, here are my top five security threats and what it takes to deal with them.
Top five IT security threats and how to combat them
Faced with external security threats from hackers and others, along with a growing array of even more dangerous internal security threats, companies worldwide are feeling the heat.
Industry experts agree that strong identity and access management technology and practices should be the cornerstone of every security strategy; but legacy IAM offerings often are considered overly complex and difficult to maintain - a problem compounded by the advent of cloud and mobile trends affecting enterprise access.
Quest Software provides a modular approach to IAM ideally suited to address a full range of security concerns. This advisory provides the top threats companies should prepare for, and specific IAM best practices they should follow to combat threats early on.
Organisations traditionally have had only two options to address identity and access management:
1. Solving specific pains in an ad-hoc manner with system- and task-specific tools and practices from a variety of vendors.
2. Implementing a monolithic framework that seeks to address issues enterprise-wide through an almost entirely customised approach.
These options either are too customised and cumbersome to be sustainable, or too controlling and rigid to address today's new market realities. Neither adequately addresses the business-driven needs that are forcing organisations into action.
There is a better way. Quest Software, with its Quest One Identity Solutions, makes security and compliance simple and effective. Unlike identity and access management solutions from legacy vendors, which require extensive and costly customisation, Quest's modular, yet integrated, approach addresses immediate concerns, but is nimble enough to tackle future business needs - with an eye firmly on simplifying some of the most complex challenges organisations face today.
News facts:
A leading provider of identity and access management solutions, Quest Software identifies the following five top security threats and offers a set of solutions, proven in the real-world, that make achieving security and compliance not only simpler, but less expensive and more effective.
1. Internal Excessive Privilege - System administrators with complete access to servers and data can pose a tremendous internal threat if they turn against the company. Similarly, everyone from administrators up to executives pose a threat to security and data if they maintain excessive access rights after changing positions or taking on different roles.
2. Third Party Access - Giving partners and other third parties appropriate access to data is no longer cut and dried. Data stored in the cloud may be located across the country or overseas - or sit on physical servers owned by one vendor, but housed in facilities owned by any number of data centres. Employees of these third parties often have direct access to unencrypted data, or they may retain copies of both encrypted or unencrypted data.
3. Hactivism - Politically motivated hacking is on the rise, by operations such as Anonymous Operation and Lulz-Sec. Members of these groups assert that much of their success comes not from their technical expertise, but from having found easy targets. While an organisation may not have control over whether or not it is attacked, effective identity and access management strategies and technologies, and basic employee security training, will reduce the chances that attacks will succeed.
4. Social Engineering - Social engineering is the age-old technique of using lies, deception and manipulation to gain sufficient knowledge to dupe an unwary employee or company. Using public social channels to detail every aspect of your upcoming “unplugged” vacation trip may be just what a scammer needs to put an attack in motion.
5. Internal Negligence - Negligence typically is an offense committed by management when “they should have known better”. Most successful data security breaches have some element of managerial negligence associated with them, such as simply forgetting to check log reports for clearly suspicious patterns.
The lessons - how to combat security threats
* Adopt a “least privilege” security posture that gives each employee the least privilege necessary to accomplish required tasks, and ensures that unnecessary access rights are revoked whenever an employee changes roles. Some of the most common implementation options to help get to a least privilege state include: assigning appropriate access directly to users based on well-defined roles, limiting access to administrator and/or root accounts - making sure that the passwords to these accounts are not shared, are changed frequently, and that there are controls in place to limit and track their use.
* Embrace an access review policy and regular, automated access alerts that notify two or more administrators of access changes, employee changes or other critical issues. To prevent access creep, access privileges must be dynamically linked to human resources and staffing databases. Notifying more than one administrator helps overcome negligence.
* Lock the front door by fostering education, encouraging diligence, and developing processes such as regularly changed passwords, or by adopting “harder” security access technologies with tools such as Microsoft Active Directory or multifactor authentication. Employee education can cover the logistics and basics of security, but also can address topics such as the psychology and known techniques of social engineering hacks.
* Achieve compliance by implementing access control and separation of duties practices and technologies, and developing, implementing, and enforcing secure policy on all system access. Provide a complete audit trail of policy and activities, and eliminate non-compliant login practices.
“Efficiently authenticate, monitor, audit, manage and protect your business-critical information and integrate access governance, privileged account management, identity administration and user activity monitoring into a comprehensive solution that enables organisations to better control access and secure their data whether internally on premises or externally,” concludes Hutchinson.
Supporting information:
Gartner, 29 November 2011: “Predicts 2012: Sophisticated Attacks, Complex IT Environments and Increased Risks Demand New Approaches to Infrastructure Protection”
“Sophisticated new threats - especially targeted attacks - the financial and reputational damage from attacks and the growing 'consumerisation' of IT are among the factors increasing the complexity, difficulty and criticality of protecting enterprise IT infrastructure. Enterprises should recognise that every new trend in technology brings new vulnerabilities, and should use some of the cost savings they realise from these trends to improve their security controls.”
Supporting resources:
Want to know how your identity and access management performance compares to the best-in-class?
Take a free interactive assessment.
John Milburn is responsible for product direction for all solutions supporting identity and access management at Quest Software. Prior to his current position, Milburn served in various roles at Quest, including Vice-President of System Consultants in North America. He has more than 15 years of experience in Microsoft-focused corporate IT environments. Before joining Quest in 1999, Milburn worked on WINtel architecture for Bank of America. He has a bachelor's degree in finance from Southern Methodist University, and a master's degree in information sciences from the University of Texas.
Blue Turtle Technologies
Blue Turtle Technologies provides solutions for optimising, enhancing and leveraging existing IT investment, and supporting the cost-effective delivery of new technology initiatives. With experience from mainframe to desktop, Blue Turtle delivers solutions for the effective management of IT infrastructures, employing innovative software products, backed by 'best-practice' implementation services. Blue Turtle's strategy leverages 'best-in-class' software products brought together from leading international and South African software providers to deliver compelling and cost-effective technology management solutions to customers. For more information: www.blueturtle.co.za
Dana Jedrisko
Marketing
Blue Turtle Technologies
(+27) 011 206 5600
danaj@blueturtle.co.za
Quest Software
Established in 1987, Quest Software (Nasdaq: QSFT) provides simple and innovative IT management solutions that enable more than 100,000 global customers to save time and money across physical and virtual environments. Quest products solve complex IT challenges ranging from database management, data protection, identity and access management, monitoring, user workspace management to Windows management
Quest, Quest Software, and the Quest logo are trademarks or registered trademarks of Quest Software in the United States and certain other countries. All other trademarks and registered trademarks are property of their respective owners.
More about Quest Software at: www.quest.com
Nisha Morris
Quest Software, Inc.
(949).754.8714
nisha.morris@quest.com
Editorial contacts

