Search
00
GBAF Logo
trophy
Top StoriesInterviewsBusinessFinanceBankingTechnologyInvestingTradingVideosAwardsMagazinesHeadlinesTrends

Subscribe to our newsletter

Get the latest news and updates from our team.

Global Banking and Finance Review

Global Banking & Finance Review

Company

    GBAF Logo
    • About Us
    • Profile
    • Wealth
    • Privacy & Cookie Policy
    • Terms of Use
    • Contact Us
    • Advertising
    • Submit Post
    • Latest News
    • Research Reports
    • Press Release
    • Awards▾
      • About the Awards
      • Awards TimeTable
      • Submit Nominations
      • Testimonials
      • Media Room
      • Award Winners
      • FAQ

    Global Banking & Finance Review® is a leading financial portal and online magazine offering News, Analysis, Opinion, Reviews, Interviews & Videos from the world of Banking, Finance, Business, Trading, Technology, Investing, Brokerage, Foreign Exchange, Tax & Legal, Islamic Finance, Asset & Wealth Management.
    Copyright © 2010-2025 GBAF Publications Ltd - All Rights Reserved.

    ;
    Editorial & Advertiser disclosure

    Global Banking and Finance Review is an online platform offering news, analysis, and opinion on the latest trends, developments, and innovations in the banking and finance industry worldwide. The platform covers a diverse range of topics, including banking, insurance, investment, wealth management, fintech, and regulatory issues. The website publishes news, press releases, opinion and advertorials on various financial organizations, products and services which are commissioned from various Companies, Organizations, PR agencies, Bloggers etc. These commissioned articles are commercial in nature. This is not to be considered as financial advice and should be considered only for information purposes. It does not reflect the views or opinion of our website and is not to be considered an endorsement or a recommendation. We cannot guarantee the accuracy or applicability of any information provided with respect to your individual or personal circumstances. Please seek Professional advice from a qualified professional before making any financial decisions. We link to various third-party websites, affiliate sales networks, and to our advertising partners websites. When you view or click on certain links available on our articles, our partners may compensate us for displaying the content to you or make a purchase or fill a form. This will not incur any additional charges to you. To make things simpler for you to identity or distinguish advertised or sponsored articles or links, you may consider all articles or links hosted on our site as a commercial article placement. We will not be responsible for any loss you may suffer as a result of any omission or inaccuracy on the website.

    Top Stories

    Varonis Says Rise In Hacking Is Due To Lack Of Basic Controls

    Varonis Says Rise In Hacking Is Due To Lack Of Basic Controls

    Published by Gbaf News

    Posted on March 19, 2013

    Featured image for article about Top Stories

    London, 14th March 2013 – Commenting on a Wall Street Journal report that the top US spies have warned of the rising threat of state-sponsored hacking, social engineering, APTs and other security breaches, security expert Yaki Faitelson today noted that most organisations lack the basic controls that can help them to quickly remediate and learn from an attack, and in many cases prevent or limit breaches in the first place.

    “Most of these attacks are not that sophisticated, and even if they are they don’t need to be to do damage if basic controls aren’t in place. We can’t ignore fundamental data protection “blocking & tackling” and expect to protect ourselves from basic threats, much less sophisticated attacks.

    “Unfortunately what we’re seeing is that basic controls just aren’t there for most organisations— for example, in our survey on data protection, only 19% of organisations reported that they monitor all access activity across common data stores, and 27% reported that they audit no access activity[1]. Without basic auditing, it’s no wonder that organisations have a difficult time spotting intrusions and misuse. Recovering from security incidents is also much more difficult when you don’t have a record of what was accessed.”

    Faitelson noted a recent incident where Varonis identified hackers who had signed on as contractors at a large enterprise organisation. The individuals’ unusual download activity was tracked and perpetrators spotted, and further wrong-doing prevented.

    While the specific anatomy of each attack differs, most attacks can be prevented or minimised with fundamental controls. Spear-phishing attacks, for example, are far worse when the compromised accounts have access to large amounts of data that aren’t relevant for them, and there is no audit trail of what the compromised accounts access,” said Faitelson, who is CEO and co-founder of the New York-based data governance provider Varonis.

    Faitelson also cautioned against overuse of the term “cyber warfare” to describe ongoing attacks, and agreed with comments made this week by President Obama. “You always have to be careful with war analogies — there’s a big difference between them engaging in cyber espionage or cyber attacks and, obviously, a hot war,” Obama told ABC News in the interview, which was taped on Tuesday but aired on Wednesday. What is absolutely true is that we have seen a steady ramping up of cyber security threats.

    (source: http://www.chicagotribune.com/business/technology/chi-cyber-attacks-more-hacking-attacks-from-china-20130313,0,1295096.story)

    “Just as bankers must always be on the lookout for fraud, we must now always be vigilant about protecting our information– it’s just a part of our information economy. We have to shift the way we think—data is valuable. Don’t be surprised when people try to get it, not just a certain country or individual,” Faitelson said.

    Organisations and individuals need to treat their emails, files, and other data like currency. Look at their information like assets on a balance sheet, he advises.

    Faitelson recommends these steps:
    1. Know where your assets are
    2. Learn to assess the value of your information assets
    3. Put basic controls around them – The 4 A’s:
    • Authentication (verify the user is who they claim to be – multifactor is better)
    • Authorization (make sure they only have access to the data they need)
    • Auditing (all access must be monitored)
    • Alert (analyse activity for potential abuse)
    4. Make sure people use protected, authorized platforms
    5. Focus on the balance between productivity and security—people need a modern work experience that doesn’t put organisational data at risk
    For more information on state-sponsored hacking, see http://online.wsj.com/article/SB10001424127887323826704578356182878527280.html?mod=WSJ_hpp_LEFTTopStories

    For more information on Varonis visit www.varonis.com

     

     

    Why waste money on news and opinions when you can access them for free?

    Take advantage of our newsletter subscription and stay informed on the go!

    Subscribe