Cyber-attacks: 5 things companies should know

closeThis article could be out of date, as it was published 1 year 6 months 9 days ago.

The advanced persistent threat is waging an all-out attack on enterprises’ intellectual property.

Yet most companies continue to try to protect themselves using approaches that are years out of date.

That is one of the conclusions in Responding to Targeted Cyberattacks, a frank new how-to book published by global IT association ISACA and written by professionals at Ernst & Young LLP.

The threat landscape has progressed from unsophisticated “script kiddies” to hackers to insiders to today’s state-sponsored attacks, where enterprises are attacked because of who they are, what they do and the value of their intellectual property (IP).

“There are no universal solutions to prevent being infiltrated,” sayx James Holley, leader, Ernst & Young LLP’s Information Security Incident Response services.

“If sophisticated and well-funded attackers target a specific environment, they will get in.

“In this rapidly evolving threat landscape, information security professionals need to adopt the mindset that their network is already compromised or soon will be.”

Five things companies should know:

• Advanced threats now target people—people have become your first line of defense.

• Cyberattacks are a business problem and a people problem, not just a technology problem.

• User education and awareness are critical to your success.

• “Prevention” strategies of the past are not enough now – today’s strategy needs to be: “Complicate – Detect – Respond – Educate – Govern.”

• Four emerging capabilities are needed to implement the new strategy for dealing with cyberattacks:

• Centralised log aggregation and correlation; Ability to conduct forensic analysis across the enterprise, ability to sweep the enterprise for indicators of compromise and ability to inspect memory to detect malicious code

The survey of more than 1,500 security professionals found that an overwhelming majority (94%) of respondents believe the APT represents a credible threat to national security and economic stability.

Additionally, 63% think it is only a matter of time before they are attacked and one in five has already experienced an APT attack.

Is this an act of scaremongering or are companies facing serious cyber-security threats? Tell us your thoughts below

Follow Us
on Google+
Sponsored

Hilton Auckland

As more and more conferences and events arrive in New Zealand, the opportunity to gain knowledge and build networks becomes better every day. Conferences can be hard work, and there’s nothing like retiring to a nice hotel room at the end of the day to relax and rest. But how do you turn a night in a hotel room into a lesson in building brand loyalty?   Read More →

Android App Review: Vimeo

NetGuide I review a lot of apps that, for one reason or another, aren’t that good. But it’s rare to find one that’s actually irredeemably broken. Video sharing website Vimeo’s app, however, is closer than it should be for an app with such obvious potential.   Read More →

Review: Samsung Gear S

NetGuide It takes something pretty special to stand out from the crowd in the smart wearable space. With new smartwatches and bands launching on a weekly basis, there’s lots of noise and plenty of confusion.   Read More →