About
Subscribe
  • Home
  • /
  • Security
  • /
  • Managing your e-security - Internal or external attacks

Managing your e-security - Internal or external attacks

Maeson Maherry
By Maeson Maherry
Johannesburg, 04 Sept 2002

As with most crime, cyber crime is on the increase. The Computer Crime and Security Survey conducted by the Federal Bureau of Investigation and the Computer Security Institute revealed that external attacks slightly outnumbered internal threats again this year.

One of the reasons for this trend could just be that more and more companies are noticing and reporting external incidents which include viruses that circulate the Internet. Previously there was an element of secrecy around these attacks, as organisations were reluctant to jeopardise client confidence by admitting their systems were not as secure as they should be," explains Maeson Maherry, general manager of NamITrust, the Enterprise Security Solutions Provider (ESSP) within NamITech.

"Another factor is that as systems become more and more complicated, with new features being added all the time, extra avenues of entry into the organisation are opened up with the most frequent point of attack being the Internet connection," he continues.

While external attacks may become the number one threat of the future, attacks from within the organisation should not be underestimated. External breaches are often easier to defend against than internal breaches. With internal intrusions, the attacker knows where to go for the information and how best to cover his tracks.

Research has shown that 60% to 70% of corporate fraud originates internally. A criminal, dissatisfied employee - or an ex-employee with a grudge - can often determine where confidential company data is stored and then access it in order to use it against the company. These attacks are generally more deliberate than external hacks, and harder to trace. International venture capitalist company 3i recently ran an e-security survey, in which the two current primary risks to e-security cited by the respondents are white-collar crime and internal sabotage. The predicted primary risks in three years time will be corporate espionage and internal sabotage.

"Internal sabotage is clearly an area of concern that will not go away. While physical measures such as biometric identification, the use of smart cards and protection of the network infrastructure are fundamental to a defence against internal attacks, the threat is also a people problem," says Maherry.

"Corporates need to create a culture of security and secure habits among employees.

"However, whether attacks are internal or external, they need to be addressed and the increase of these threats creates opportunities for security providers.

"The current trend is towards outsourcing corporate e-security. Managed security services (MSS) involves the management and monitoring of an organisation`s e-security by an external company specialising in this field," says Maherry.

"The spend on MSS is predicted to increase by some 8% in 2002. Managing e-security is a process, a holistic approach to the issue bringing in all elements of security including managed PKI, biometrics and intrusion detection.

NamITrust incorporates SACA, experts in the field of PKI and encryption technology. The company was acquired last year by NamITech, enhancing its already comprehensive security offering. Now NamITech, through NamITrust, is primed to capitalise on these MSS opportunities.

"We are a strong local affiliate of VeriSign, the world`s largest provider of Internet trust services; we operate out of our own seven-tier secure trust centre (the only such facility in Africa) where we continue to securely issue digital certificates and we are already providing managed PKI solutions," Maherry points out.

"Over the last five years SACA secured 80% of local PKI projects and we aim to continue and improve on this track record. NamITech offers a comprehensive range of security solutions and becoming an ESSP is a natural progression for the company."

Share

NamITech

NamITech Ltd is the secure technology provider within the established Nampak group of companies, focusing on a number of key market areas to provide leading edge technology solutions.

NamITrust is the newly established Enterprise Security Service Provider within the NamITech Limited group, specialising in the monitoring and management of security in the digital domain. This focused division offers comprehensive managed security services including managed PKI, Intrusion Detection and non-repudiation of transactions. NamITrust operates out of the only seven-tier secure facility in Africa.

At the heart of the company is the provision of secure end-to-end business solutions and the development and implementation of value-added applications stemming from the intelligent use of smart cards and the latest technology. NamITech`s core areas of expertise are secure card technology, payment solutions and enterprise security solutions.

Trust is embedded in all its business solutions and NamITech brings accountability to the converging world of electronic transacting and commerce.

Editorial contacts

Debbie Dias
BE Agency
(012) 346 1018