Showing posts with label IT Security. Show all posts
Showing posts with label IT Security. Show all posts

Saturday, October 3, 2015

See User Rights in Context

Many companies often underestimate the threat from organized cybercriminals and industrial espionage. Even risks that may arise from its own employees, have little presence.


Firewalls and perimeter security are now outdated in the distributed nature of many enterprise networks, in principle. New approaches, such as the Identity Relationship Management (IRM) can be a way out.

Hardly a day on which the press cannot report a blatant attack on the data security or cyber-attacks. One event after another: meetings may each. Recent cases like the pecking of Lufthansa Miles accounts of frequent flyers or bonus card users have brought clear once again into consciousness.

Many companies often underestimate the growing threat posed by organized crime and cyber economic espionage. Even the risks that may arise from its own employees, are not sufficiently present. Loss of data, the restoration costs, additional working hours and earnings and sales shortfalls pull cost billions of dollars by themselves. But the damage caused by industrial espionage calculates the VDI annually to approximately 100 billion euros. Is it any wonder that the data security is generally doubted, and consumers concerned remembers their past credit card purchases?

Including loss of confidence

Any breach of the data identity always attracts a loss of confidence in the trade mark concerned after themselves, not to mention the damaged customer confidence in the company and in the system in general. Both are extremely difficult to predict and may at worst jeopardize the economic survival of the company, or at least severely impair. Companies that react too late after an incident, have to reckon with substantial fines under certain circumstances. European companies are pressed for time when it comes to a proposal by the European Union for the end of 2015 the introduction of a General Data Protection Regulation (General Data Protection Regulation, GDPR) is, according to which uniform rules for the processing of personal data by private companies should be EU-wide.

Thursday, October 1, 2015

Cyber danger threatens to the Digital Economy

The Digital Economy is a decisive factor in global competition. A Forsa study on behalf of the specialty insurer Hiscox for handling digital cyber risks is now: Despite knowledge about the threat to the potential danger for the digital economy and thus the business location in the world is considerable.

Cyber risks constitute a tangible threat to the corporate balance sheets and the future economic development of the digital medium-sized companies are: two-thirds (66 %) of the digital company say they need in the event of a cyber incident interrupting the ongoing operation. A lengthy stoppage would mean for 66 % of company sales declines. Almost three-quarters (73 %) of the surveyed digital company would in the case of a hacker attack or data loss suffer from loss of reputation and more than half (55 %) expects for this case in order to lose customers.

And the danger is real:
Every fourth digital companies (25 %) already had to cope with at least one cyber damage in the past. 72 % of these losses were caused by hacking, 36 % were secondary technical failures and 14 % due to the loss of mobile devices or theft of hardware.

Rapid development calls for quick solutions


Robert Dietrich, General Representative of Hiscox, says: "The Digital Economy is developing at a breathtaking pace, revealing the foundations for the future of the global economy. The problem of an existential threat to the Digital Industry by cyber threats urgently demands a solution: Who can such help the digital economy? To answer this question, we jointly investigated by Forsa, such as digital entrants already protect themselves, where their IT security has gaps and by whom the economy hopes help. "

Monday, September 7, 2015

Concepts for the company's use of mobile devices


In more and more companies move mobile devices in the first place when it comes to further increase employee productivity. Finally, the processing power of smartphones is sufficient today to perform more complex enterprise applications. Most, however, it comes at the right app strategy.


Regardless of whether apps are provided for field service personnel or for academic staff, this development opens boosting productivity to place a lot of potential, even the most demanding applications and data to mobile devices of the user. Moreover, the idea of employees who are always online, extremely attractive for companies.
With all the positive aspects, however, need to be protected applications and content before an illegitimate use and dissemination. Two approaches have been established there to meet this challenge: the Mobile Device Management (MDM) with the control of the terminals used for corporate purposes and the Mobile Application Management (MAM) with policies for the use of applications. In both cases, these approaches focus ensuring the safety, the regulated access and distribution as well as the reliable closure of enterprise applications.

Monday, August 31, 2015

Cyber Insurance mitigate damage

Safety awareness is strengthened


Policies against cyber-attacks that already have several insurers offer, have several positive effects for companies.


"Insurance against cyber-attacks are becoming increasingly popular for German companies. Several reputable insurers have appropriate policies already on offer. This is due to the increasing number of serious security breaches around the world that make headlines again. With the so-called cyber-insurance companies can reduce the impact on their business - an already widespread overseas action to protect with security incidents.

Protection from what?


With the appropriate insurance, companies do not protect against the occurrence of security breaches, but their consequences. Absolute security does not exist, as determined threat author always looking for new ways to break into networks and stealing data.

Friday, August 28, 2015

Investing in IT security: Make it save

Is it worth investing in an integrated enterprise security platform? Forrester Consulting has been on the ground in the context of a detailed survey of companies on this issue.

For each investment in a commercial environment a question plays a central role: it pays the like? On the topic of IT security, there is the question of costs and benefits of acquisition, even with an integrated enterprise security platform. But what does that mean for a solution?

One Enterprise Security Platform provides networking, cloud and endpoint security in a common architecture. As an integrated security platform, it ensures transparency and control, allowing organizations to detect and prevent cyber-attacks, during the operation of productive applications is ensured.

Many companies shy away at first glance not inconsiderable investment and rely on their self-compiled over years grown security architecture. Forrester Consulting conducted a study on the economic impact (Total Economic Impact, TEI) recently.

The aim of this study was to clarify the financial implications of a platform-based approach and the potential return on investment (ROI) display. In order to gain a practical assessment, Forrester companies surveyed who use a current enterprise security platform for several years.

Monday, August 3, 2015

Samsung gives clear – TV, listens only to users with desire

Once the Terms of Use have aroused from Samsung TVs fears of spying in the living room, the electronics group is clear.

Users need only click a button on the remote control a search query via voice command enabled. Only then would sound recordings transmitted to third-party, a spokesman said on Monday. Expressly only for this case, the warning was meant in the Terms of Use, that this also any confidential conversations could be transmitted. The generally formulated set in the terms of use allowed the interpretation that the television constantly could transfer recordings from the room. That is not the case, assured the Samsung spokesman.

Another function, when about the volume or channel can be changed via voice control, working principle without an Internet connection. The TV reacts to certain code words like Hi, TV or smart TV. In order to hear from the speech flow, he must listen while permanently. But the speech information would thereby process exclusively in the device itself, said Samsung spokesman.

Image Credit: www.englandrugby.com



Sunday, August 2, 2015

BMW stoking slip fear of hacker attacks on cars

Viruses, Trojans, hackers, secret services - in the digital world lurk some dangers. And when it comes to data security, many consumers are just in this country wary. This is also true for cars. A now stuffed vulnerability at BMW makes itself heard.

Since cars are connected to the Internet, there is the fear of hackers. If a user can start his car via the smartphone App and there is possibly others butt in or it may even happen that someone takes over the control of braking or steering

The auto industry beckons from previously. The systems are safe. But now throws a Schnitzer BMW new question. Around 2.2 million cars equipped with Internet connections Series Connected Drive could be disrupted by radio because of an encryption error with technical skill.

This is no great drama, but the case shows that even things that should not happen occur when someone makes a mistake. And that a gap can make it through all the quality controls in the series. The ADAC discovered the vulnerability and warned the manufacturer - the upgraded then soon after.

The problem and the concerns there are ultimately being moved in the car computer. In 2011 it was university researchers from San Diego and Washington succeeded in using a manipulated music file in the computer systems Onstar and Sync, advance technology by General Motors and Ford. In addition, they were able to install via the service interface for workshops WLAN malicious software in the car.

Saturday, August 1, 2015

Anonymised data sets not as secure as thought

Individual people can be sometimes published with little effort from large, anonymous records.

The researchers found the US Massachusetts Institute of Technology (MIT) and the Danish University of Aarhus reveal research result. They examined a set of credit card data of 1.1 million people. The data contained neither names nor bank account numbers, but only the date, place and amount of payments that had been made by a particular account.

Nevertheless, the researchers were able to find an individual with a high probability in the record. For this purpose they had to know only four payment transactions with them and reconcile with the data set. Such private information can be derived for example, from a public tweet or a vote on the Internet.

The researchers did in this way that a person on Monday buy a coffee with a credit card paid, had bought on Tuesday at the grocery store, was in a sporting goods store and on Friday on Thursday at a clothing store, they could that person in 90 percent of cases in the find record.

Behind the Trojans Reign infected probably the NSA

Evidence of a link between the US monitoring service and the NSA spy software Reign there was for some time, now there is another tangible indication.

The IT security firm Kaspersky noted that Reign and a program used by Western intelligence services have the same software code for the Recording of keyboard strokes. About the spyware QWERTY, which is used by the Secret Service Alliance Five Eyes, recently had the news magazine reported. It has documents from the collection of the informant Edward Snowden. Among the Five Eyes include the secret services of the United States, Britain, Canada, Australia and New Zealand.

The complex Regin program businesses and governments, especially in Russia and Saudi Arabia have been spied on for years. But elements of Regin said to have been found on the EU institutions and the Belgian telecom Belgacom Group also in attacks the NSA and its British partner service GCHQ. The end of December was also discovered on a computer of an employee at the European department of the Chancellery Reign.

IBM researchers tackle new personal data protection in the cloud

Developed by IBM Research in Zurich, Identity Mixer is available from spring 2015 for beta testing in the Bluemix -Cloud.

The IBM announces on the occasion of today's International Privacy Tags. The Identity Mixer, for short “Idemix” to personal information such as date of birth or credit card information can be protected better at web and mobile transactions. Cryptographic algorithms enable a privacy-friendly authentication to online services, in which the user disclosing as little data as possible. Idemix is loud IBM already in two pilot projects with the German Red Cross and the National Science Authority of Australia (CSIRO) tested in practice.

Users can give loud Big Blue over service providers in the network often disclose personal data, although this would not be necessary for the provision of the requested power. With the Identity Mixer, the user can select exactly what data he wants to share with whom, explains Christina Peters, Chief Privacy Officer at IBM. The technology also provides for online service providers advantages they can improve their risk profile and strengthen the confidence of customers. With the cloud version of the technology is also integrated in the future easier for developers.

The market for identity management is booming

The topic of security is driving the global ICT market. It's a perspective not so much about the protection of individual devices as new management and analysis tools.

For their first published Security Vendor Benchmark took the Expert Group more than 450 active in Security providers under the microscope. After preliminary and detailed selection remained 138 who classified the team of analysts at research fellow Oliver Already Schek as relevant for the EURO market. In eleven categories - including Cloud Security, Mobile Security, Backup and Security Consulting - the vendors were then evaluated and ranked according to competitive strength and portfolio appeal. Overall, we have our review around 100 different criteria as a basis, says Even-shek.

So playing in the Identity and Access Management (IAM), surprisingly, in Leader quadrant cavort with the pink giant, IBM , Atos, Microsoft, Oracle, Dell, CA and other total even equal to 13 companies - a clear indication that the market for identity management solutions than ever booming.
We have not looked specifically at the history of the party, but we devoted its products and solutions, says Even-shek.

Thursday, July 30, 2015

Thousands of US service stations unsecured on the Internet

The dangers of the total networking may soon get to feel many American motorists. Thousands petrol stations, mainly in the United States are connected via TCP/IP to the Internet unprotected.

The reports of the chief research officer of security firm Rapid7, HD Moore, in a blog post and refers to insider information from the industry. Around 5800 the so-called Automatic Tank Gauges (ATG) is controllable via the Internet without any detours and password protection and thus manipulates - 5300 of them in the US alone, at least three percent of all gas stations in the country.

Using ATG manufactured by Veeder-Root will be controlled and monitored the fuel tank almost all American stations and many other stations around the world. About a monitoring console operator levels, refueling operations, threatening leaks or environmental influences from the outside can control. Connected this ATG are serial interfaces, fax, modem or even TCP/IP. To access via the Internet to the monitoring console, use many station operators TCP/IP, mostly on TCP port 10001 - because password protection is not set by default, the systems often are therefore open and freely accessible on the Internet.

What brings the IoT for pros and cons

The flood of devices on the Internet of Things has huge potential, but also comes with a whole range of problems and hurdles to take it yet. In many places are still missing concepts. Manufacturers recognize, however, that the solution might lie in standards.

The Internet of Things countless new intelligent and connected devices are coming, who accompany us in everyday life. Here most of the enormous potential stresses are undoubtedly attractive for developers and IT fallow . But the Internet of Things brings huge challenges whose solutions are yet to come.

One example is safety. With the number of networked devices every day the amount of data that is collected and stored on the devices themselves or in the cloud grows. The data are not only attractive to hackers; the potential for security breaches is growing exponentially with each device. And the damage that can be caused when a hacker attack is much greater. Just imagine what can be done with chopped locking systems, car or automatically operated industrial plants for damage ...