Headline grabbers
With the maturing attitude to security, is an increasing focus on the headline security issues. Major industry headlines, said AVG’s Chin, such as Shellshock and Gameover Zeus have shown Ireland’s businesses that, despite technology becoming easier to use, there are still substantial security risks with IT and that it is still best to leave things in the hands of experts. “Many businesses are now asking our MSP partners to resolve issues around protection of devices, data and employees,” she said.
However, while the threats from advanced persistent threats (APT) and criminal malware cannot be ignored, Rob Paddon, solutions director, Trilogy Technologies, warns that the internal threat, be it malicious or not, must also be mitigated.
“Organisations are recognising that looking at employee threats is as important as external attack,” said Paddon. “This does not suggest that information theft or malicious activity is widespread, more an understanding that setting and monitoring user standards and policies to reflect new mobile and cloud infrastructures is essential and then having systems to detect and mitigate breaches in policy is key.”
Paddon said that mitigating this internal risk is likely to be a key focus for many Irish organisations over the next 12 months.
“You can’t have the M&M approach, where you have a hard exterior, where you assume nothing is ever going to get in, and a soft interior, which once someone is inside, they can navigate easily, find valuable data and then exfiltrate it,” Dermot Williams, Threatscape
For Symantec’s Fegan, data loss prevention is emerging as a central concern.
“The main influence for Data Loss Prevention being increasingly on the agenda,” said Fegan, “is a need for organisations to be able to monitor the huge amounts of data held today and way in which intellectual property is being accessed and used. It enables them to put protective policies in place that prevent the loss of important data, whether that be malicious or non-malicious.”
Fegan said that server hardening in the data centre too is rising in demand.
New directives
“Understandably so,” he said, “with new EU directives soon coming into place. This technology ultimately prevents your infrastructure from being tampered with either by internal or external forces. It turns the tables on cybercriminals. For example, if a breach has occurred, the attacker cannot make any changes that have not already been approved by the organisation’s Data centre administrator.”
“Limiting the cost of business disruption and data loss for large organisations is critical,” said Fegan. “By outsourcing their security monitoring and management to Symantec’s Managed Security Services, it reduces exposure to threats while delivering significant business advantages.”
In the longer timeframe, Fegan said that cybercrime is becoming ever more complex and difficult to detect, with traditional antivirus only one single element of a company’s defences.
“If you take for example the recent Regin threat uncovered by Symantec,” he said, “this is a multi-staged threat with each stage hidden and encrypted, with the exception of the first stage. Each individual stage provides little information on the complete package. Only by acquiring all five stages is it possible to analyse and understand this highly complex threat. While Regin is most likely a state sponsored attack and most threats do not have the same level of sophistication, it is imperative companies have in place a robust security strategy to counteract any such threats.”
The new EU data protection regulation is also going be a key influencer on a corporation’s security policies,” argues Fegan. “Rather than just being a headache for the IT team, due to the size of the fines the EU can impose, it will soon be incumbent upon the company’s directors to seek clear answers about security risks and ensure appropriate steps are taken to ensure compliance with the directive.”









Ltd