AlertSec Xpress

User access control Fundamental but forgotten

May 7th, 2013

User access control is a cornerstone of information security management. Everybody needs it and does it. Yet in practice it’s poorly conceived, implemented and managed. It’s one of those elephants in the room: a problem that is highly significant, but difficult to tackle so business is reluctant to acknowledge it. If it wasn’t for compliance and internal audit the situation would be even worse.

English: A candidate icon for Portal:Computer ...

English: A candidate icon for Portal:Computer security (Photo credit: Wikipedia)

A number of theoretical models have been developed over the years but they don’t deliver in practice. We’ve got ACLs, Capabilities, MAC, DAC and RBAC, none of which work in a medium or large enterprise. There are several reasons for this.

Firstly, the models are too simple. Access control is too rich a subject to be determined by a single label or capability. Deciding whether a user can have access to an enterprise system is far from simple. It depends on who they are, what they are, how important they are, where they are, what they are doing, to whom they report, and what other access they might already possess. This requires unambiguous policy rules and reliable decision processes, supported by smart application front-ends, all of which are in short supply.

Secondly, we rarely have enough knowledge in one place to make this work. Neither systems owners nor administrators have perfect knowledge of who does what across the enterprise and what access they require, especially in an organization that is continuously acquiring, divesting and restructuring business units.

Thirdly, we don’t pay enough attention to administration. It’s too often poorly resourced and equipped. Cost savings can easily be made by streamlining processes and implementing better tools but this requires enterprise-wide cooperation and it’s rarely at the top of any business unit’s agenda.

Fourthly, we are constrained by legacy systems and infrastructure which complicate the problem space and restrict the solution space. Ambitious visions quickly fade into the distance.

An inescapable fact is that we can’t control a complex situation with simple controls. Today’s access requirements are a sophisticated blend of numerous factors. Access rights depend on multiple user characteristics that can be surprisingly hard to define measure and monitor.

The end result is that it doesn’t get done properly. Instead we fudge it. We do the minimum we can to keep it going and rarely get around to developing the rich policies, knowledge base and streamlined processes needed to build a sustainable, effective access control system.

In fact it’s much easier to close the back doors, through vulnerability management and penetration testing rather than to secure the front entrance. But compliance is catching up with the thousands of wrong profiles, toxic combinations and dead registrations. Sooner or later we will have to put aside the easy, quick wins and face up to the long-standing elephant in the room.

Prevention is better than cure. Prevent your systems from attacks with Alertsec Xpress.

Get your personal as well as office laptops encrypted by Alertsec

Unencrypted laptops present a major risk of data loss. 80% of information theft is due to lost or stolen laptops and other equipment. About 50% of network intrusions are performed with credentials gathered from lost or stolen devices. The penalties for a data breach are severe not only in terms of the monetary fines imposed on the organization, but also the potential loss of trust from customers and suppliers. Encryption software greatly enhances the security of your organization’s data as the information is not compromised if a laptop is lost or stolen.

Alertsec Xpress is the full disk encryption service that delivers a mobile data protection system for all information stored on laptops used throughout your organization.

Enhanced by Zemanta

Hardware giant narrowly averts PC security nightmare

April 6th, 2013

American Megatrends, a company that specializes in PC hardware and firmware, has attempted to calm the rising trend of the panic attacks over the cryptographic signing keys leak as well as the source code for its UEFI (Unified Extensible Firmware Interface) BIOS, the code that starts up millions of computers around the world. On account of the code leak that took place, a security researcher and penetration tester Adam Caudill from United States received a warning from his research partner Brandon Wilson regarding a Taiwanese vendor who had left a FTP (File Transfer Protocol) server open for public browsing and downloading. This called for again new challenge regarding the computer protection which was more baneful after this security leak as by keeping the encryption software they could have easily averted such mishaps.

PC security nightmare narrowly averted

The take-off also included few more things among internal emails and other data – those were the source code for American Megatrends Incorporated’s UEFI BIOS and cryptographic signing keys used for verification of it. Therefore it was in the keen interest of the American Megatrends company to enable the proper encryption software for their computer protection in order to stop the security leak threatening them, every now and then. The company was afraid to access the source code for the UEFI BIOS and the cryptographic signing keys to verify the absolute binary programs, this led researchers to the development of the fear that attackers might create and/ or disseminate malicious updates which in turn, could be used to compromise and control millions and millions of computers worldwide for a long time to come. According to the researcher Caudill, “this kind of leak is a dream come true for advanced corporate espionage or intelligence operations. The ability to create a nearly undetectable, permanent hole in a system’s security is an ideal scenario for covert information collection,” He continued.

BIOS or the basic input/output system is a code stored in read-only memory which is non-volatile on personal computers as well as on other similar devices. It is assumed to run only when devices start up and loads operating systems, initialising of the hardware such as their keyboard, storage and videos beforehand. The company started developing a Unified Extensible Firmware Interface since 2005 to overcome the limitations of the original Basic Input Output System (BIOS) specifications – which was designed to suit the basic 16-bit computers decades ago, also to provide further features such as the cryptographic security for booting up. The hardware company, American Megatrends claims to the largest BIOS vendor in the world. It said so in response to the researchers Caudill and Wilson’s findings when it was revealed that the security keys on the FTP server were in fact meant for the testing and not used for the production systems.

Chief Executive and Co-founder of the American Megatrends, Subramonian Shankar stated in an interview after the security that “while today’s news is certainly distressing, AMI would like to reassure its customers and partners in no uncertain terms that this should not be a security concern for them.” Security Researcher Caudill after whatever happened noted that while AMI instructed all its vendors regarding the usage of its UEFI BIOS to change the key initially, before building a production environment, and it is not known till now that if the customer with the open FTP server was following that practice or not. Caudill did not reveal that which Taiwanese vendor had leaked the information.

Get your personal as well as office laptops encrypted by Alertsec

With so much vulnerability on public networks Unencrypted laptops present a major risk of data loss. 80% of information theft is due to lost or stolen laptops and other equipment. About 50% of network intrusions are performed with credentials gathered from lost or stolen devices. The penalties for a data breach are severe not only in terms of the monetary fines imposed on the organization, but also the potential loss of trust from customers and suppliers. Encryption software greatly enhances the security of your organization’s data as the information is not compromised if a laptop is lost or stolen. Alertsec Xpress is the full disk encryption service that delivers a mobile data protection system for all information stored on laptops used throughout your organization.

Enhanced by Zemanta

Data theft: An internal and an external threat.

March 30th, 2013

In this digital era where data travels at the blink of an eye and hi-tech devices like mobiles and tabs take on different forms, global corporations are at a risk of losing highly sensitive data than ever. For this, there is an urgent need for data security. Apart from large data breach by professional computer hackers, there is a critical concern for industries who are at risk, when it is associated with their employees. With the increasing negligence or malice by company employees, there is a risk factor of information leakage which can become a key conversation piece in risk discussions. A recently published study made it clear that the risk of data breach is significant. The study indicated that more and more number of employees are transferring and storing corporate information off the premises. This calls for data encryption software so that data transfer could be secured.

A survey carried out among half of the employees showed that they transfer work documents using home computers through less secure accounts such as Gmail. One-third of the total responses indicated that they transfer data using file-sharing apps such as Dropbox without any prior permission. Out of five, two transfer the files using their personal tabs or smartphones, where the risk of data breach is at its highest. But, in all these scenarios data security are important. Also, the majority of these people do not delete the data once transferred. For the ignorance of such risks IDC Canada reported that e-mail is the main source of data breach, with laptops secondary, and removable media being the third. Both employees as well as employers are to be blamed and the reason being that the employees are performing official activities in lots of public places, and there’s no one to bother cleaning it up or enforcing policies for computer protection.

Our major issue of concern is data breach through company employees who are moving on to other jobs. A study conducted recently showed that 50% of working professionals kept confidential information while leaving or losing their jobs, while 40% of the employees planned to use it in their new jobs. Also, 60% workers join hands with competitors who offer to share the confidential data from their last job. This is why data security with the help of data encryption software should be ensured so that employees do not carry confidential information even after leaving the company.

Data Theft : An Internal and External Threat

What’s more surprising, is the fact that those 55% of the employees are not ready to accept that it’s a crime using competitor’s confidential information while other 68% said that their company does not take strict actions to ensure they don’t use competitive information. Also, company employees often believe that they are the rightful owners since they played a part in creating or contributing to the secured data. This leads them to think that their employers do not care about computer protection, and it would not cause any harm if they take it, which is absolutely wrong. Today’s growing corporate trend demands employers to pay more attention, since the risks could be substantial ranging from monetary to loss of business to competitors, to legal action and inquiries. But that again invites the risk for data breach where data security must be assured  for computer protection.

Perhaps, there’s one thing that employees always look for and i.e., personally identifiable information on customers. So, they need good contacts with the people involved in sales, corporate IT and company support as these people have an easy access to such records. In some cases, to avoid getting noticed employees often download large lists incrementally to text files or spreadsheets. While client or customer based information might be one of the more prolific targets, therefore, one has to be very careful regarding data security as to whom access is being given to monitor internet by making sure that the stuff is not leaked out of the company.

Encryption software prevents data breaches

Traditional antivirus approaches don’t work any more and a new approach to endpoint security is required to better protect your company from malicious threats.

The above threat could have simply been reduced to an insurance matter by a mere investment of $13/month. The information would have been secure with no loss what so ever. That is certainly a small price to pay compared to what can happen if you lose confidential or sensitive data. Alertsec Xpress offers a very good and easy-to-use laptop security service that includes more than the traditional software licensing model. Feel free to subscribe for your personal 30-day free trial

Alertsec further offers computer protection software from Check Point as a fully customizable and pre-packaged data encryption software solution. It can help you dramatically reduce your cost of ownership for encrypting your laptops.

Enhanced by Zemanta

Data Breach Revealed at Government Ministry

March 25th, 2013

In recently published news, there has been another privacy data breach revealed at a Government department, at the Ministry of Health this time. A news website named, ONE News discovered 19 people to have been affected by a printing error as a result of which high use cards were sent out on the wrong addresses. A woman from Dunedin who had received her son’s high use card in a mail said, there was another high use card in the mail attached with the same, containing another high use card referring to someone else. The lady also said, it was for “no one that I know, totally different city, totally different name, totally different address, everything”.

Data Breach at the Health Ministry

The lady, who is a mother of two, immediately rang the Ministry of Health as her responsibility who had told her about a mechanical error with a printer meant two letters, with two cards, which had been placed in one envelope. “I at first sort of didn’t really know what to do, it just concerned me. I thought if this has come to me, what else has gone to wherever else?” The Ministry of Health apologized to all 19 people affected by the glitch, following all the data breach related incidents. As a precautionary measure, the health ministry is issuing 366 replacement cards for all the people who have been affected in the batch of the cards, and cancelling those sent out mail and/ or letters. The privacy data breach involves the name and addresses of the card recipients, but does not include any medical details of the same. The knowledge about the aforesaid incident comes in the wake of recent high profile privacy breaches at ACC, Earthquake Commission and the Ministry of Environment. The Ministry of Health finally assures the public by saying that the data breach has been resolved and has asked the contractor who was involved to accommodate an automatic checking method so that the same mistake could not be repeated again.

Encryption software prevents data breaches

Traditional antivirus approaches don’t work anymore and a new approach to endpoint security is required to better protect your company from malicious threats.

The above threat could have simply been reduced to an insurance matter by a mere investment of $13/month. The information would have been secure with no loss whatsoever. That is certainly a small price to pay compared to what can happen if you lose confidential or sensitive data. Alertsec Xpress offers a very good and easy-to-use laptop security service that includes more than the traditional software licensing model. Feel free to subscribe for your personal 30-day free trial.

Alertsec further offers computer protection software from Check Point as a fully customizable and pre-packaged data encryption software solution. It can help you dramatically reduce your cost of ownership for encrypting your laptops.

Enhanced by Zemanta

EQC to shut IT systems after being hit by Data Breach

March 23rd, 2013

The Government ordered Earthquake Commission (EQC) to shut down all its outgoing IT systems for the purpose of data security after it was hit by an email, sent leaking the private information the second time. The recent data breach is another privacy revelation, happening twice in less than a week for the organisation, after admitting to unintentionally release of the details of 80,000 claimants in its Canterbury Home Repair Programme – described “embarrassing” to this incident. Later, in Parliament it was revealed that a second email was also sent, which included the personal details of the claimants, like their names and bank account details. The email which was sent, as a result of another data breach, contained a spreadsheet file with 2200 names of the claimants and information including money owed in stopped cheques, which totals around $23 million.

Therefore, the Earthquake Minister Mr. Gerry Brownlee in response to the data breach incident, ordered the Earthquake Commission to shut a number of its IT systems down, as well as its external email service and business-to-business (B2B) exchanges. Brownlee also told Colin MacDonald, the Government’s chief information officer to investigate the incident to know what had happened, which remains unaware of the data security.

Brownlee told that he was “deeply distressed and concerned” by the leak occurring twice in a very short span of time, he also said that this data breach may lead to attribute to an IT problem.

“The recipient took the appropriate actions and advised EQC they had received the information in error through EQC’s online complaints process about a month ago,” he said.

Call for action

Earthquake Minister, Brownlee passed an order for EQC to immediately shut down all the external email systems including the IT Department, in order to defend emails from sending or receiving by the organisation. For this, all the business-to-business systems and data exchange activities as well as the accessing into EQC systems by external parties, has also been immediately ceased.

MacDonald has been tasked to investigate the problem and keep an eye on the implementation of a solution. “Mr MacDonald will develop a priority work programme to resolve and manage the issues with EQC’s information systems and bring its processes and procedures up to standard,” said Brownlee.

“I think this is a timely opportunity to draw breath after what has been a very rapid growth for EQC and ensure the privacy New Zealanders have the right to expect from any agency holding private information is offered to them by EQC.”

Privacy data breach ’staggering’

Later, the Labour MP Lianne Dalziel announced about the data breach during Parliamentary Question Time. She also described the degree of the privacy breaches by EQC to be “staggering”. “This is an absolute scandal and proof that there is a systemic problem with the security of electronic data held by EQC and other agencies across the entire state sector,” she said after Question Time.

“New Zealanders take their privacy very seriously. But this Government has let them down time and time again. We’ve now had major breaches at EQC, ACC, MSD, IRD, Corrections and Novopay. “What will it take for this Government to act? It’s time to stop the flippant responses such as Gerry Brownlee dismissing it as ’similar to putting the wrong address on an envelope’ and give New Zealanders the confidence they deserve that their information is safe.”

However, the moment topic was being raised in the parliament, Brownlee was banged on her dictum for the late information of the allegations which she had received long ago. “If the member considers this the breach that it appears to be I’m disappointed she didn’t contact my office to let me know that she is now in receipt of people’s private information,” he said in response to her questions. He added that she had time to contact him before the afternoon session began. “I will certainly check it out, and take whatever action is necessary to ensure that EQC does get on top of its system, so this sort of thing doesn’t happen,” he said. This exchange created commotion and jeering in the Parliament House, with some people calling to resign on Brownlee over the leaks happened, and asking the Speaker to call for an order. When a news channel named, ONE News contacted Earthquake Commission, it disagreed to comment on the latest privacy data breach allegation.

How can Alertsec help prevent such data breaches?

Alertsec cloud based information security service provides an easy and convenient way to protect information on your organization’s computers. No server, training or IT knowledge is required as everything is a part of the subscription plan. Alertsec helps you comply with HIPAA, PCI and SOX requirements. The implemented encryption has the highest security certifications – FIPS, Common Criteria, and BITS.

With Alertsec Xpress there is no impact on the performance of the encrypted computer. The Full Disk Encryption software is very fast and works on-the-fly by encrypting and decryption your files as you access them. Everything on your disk is encrypted, including the operating system and free space.

Enhanced by Zemanta