![]()
Crafting a Technology Security Plan
Keeping your networks secure and your data safe is critical to the success of your business. Most small-business owners understand that complete, end'to'end network security is something they should have - but it's something they probably don't. And how can they? With security threats coming from a multitude of sources and no end in sight to the new attacks that are frequently launched on both networks and PCs, keeping up with all these threats and figuring out just what to do about them is challenging enough for big companies with dedicated IT staffs. For small businesses, it can be completely overwhelming. The risks of not adequately securing your business network and PCs are huge, however. Remember: It's not just your data that's at risk from attacks from viruses, spyware, hackers and others. Any customer data stored on your computers - including Social Security numbers, bank account information and confidential data, such as key sales and marketing data - is at risk as well. Here are the facts, according to consumer product research organization Consumer Reports:
Since security threats continue to evolve, business owners must not only continue to protect themselves from existing threats such as viruses, spyware and scam e-mails, but must also keep abreast of new threats and understand how hackers will be targeting computers in the future. So what will the newest threats be in 2007? Here are some trends to watch: More narrowly defined threats, or "targeted threats," are becoming common. These attacks tend to focus on sensitive information from a single company or individual rather than indiscriminately letting a worm loose to find victims randomly wherever they can. The "malware" capable of these attacks is being delivered to users in increasingly sophisticated ways such as in e-mail attachments, embedded in video files or hyperlinks, and even through social engineering tactics that lure, fool or trick the user to make what seems like a benign action that automatically installs the malware without user help. Malicious bots - short for robots, or software applications that run automated tasks over the internet - are expected to increase. Bots are sometimes used to create automated attacks on networks, such as DoS attacks. Rootkits are increasingly becoming a concern. Rootkits are a set of software tools whose purpose is to conceal processes, files or system data from a computer's operating system. Rootkits can enable hackers to maintain access to a computer system. Because they can burrow deeply, are capable of modifying parts of an operating system, and can go undetected, rootkits can be particularly challenging to remove. Zero-day attacks are also on the rise. A zero-day (also called zero hour) attack takes advantage of computer security holes for which no solution is yet available. They're called "zero day" because they attack between the time a security hole becomes known and the time when a patch to plug the hole is available. As a result, zero-day attacks can spread at an alarming rate. Identity theft will continue to be a growing concern. The FTC estimates that 10 million Americans are victims of identity fraud each year. Hackers who gain unauthorized access to computers are often in search of personal identity data they can exploit or sell. THE SOLUTIONS Now that you've got some idea what you're up against, is there anything you can really do to protect your business? Absolutely. First, you need to develop a plan that addresses both education and technology. It's critical that you educate your users on what they can do to make sure they're not potentially compromising security (safe user habits for reading and acting upon e-mails can prevent many virus attacks). And make sure unauthorized users (for instance, family or friends) don't use your business's computers. Next, develop a comprehensive technology plan to address all aspects of security. Talk to your trusted IT adviser. Make a complete list of the security you already have in place, with an eye toward sniffing out vulnerabilities. Develop a plan for complete, end-to-end network protection, and make sure there are steps in place to regularly update your security. Then revisit your plan several times a year to ensure it continues to meet your needs and addresses new security threats that continue to evolve. Your plan should include the following security essentials:
The bottom line is, would you like to be in charge of your computers, your network and your data - or would you rather leave that up to a hacker? Source: Peter Alexander is Entrepreneur.com's "Tech Trends" columnist and vice president of worldwide commercial marketing at Cisco Systems Inc., the leading supplier of networking equipment and network management for the internet. |