Government Technology

    Digital Communities
    Industry Members

  • Click sponsor logos for whitepapers, case studies, and best practices.
  • AT&T Logo
  • McAfee
  • Net App

Security Threat Update



May 18, 2009 By

2008 saw a dramatic spike in security breaches resulting in millions of compromised records. This could be spurred by economic troubles, or perhaps online crime is just an easy target.

For example, the average bank robbery will net about $3,000 -- with a fairly good chance of going to prison or even being shot.

Now compare the use of a botnet to commit an online crime. On average, such thefts make $5,000 a week, with very little chance of being caught and even less chance of being injured or killed. Not to mention, you can do this from the comfort of your own living room. Which option is more appealing?

With statistics like these, it's no wonder thieves are turning to online crimes. Internet crime has grown exponentially in recent years and trends show that it will continue in this direction until we change the way we think about security.

In a recent security threat update, Don Hewatt of Verizon Business explained that highly organized crime circles are responsible for the majority of security breaches. In Verizon's recently published 2009 Data Breach Investigation Report, it is estimated that 285 million records were breached in 2008, which is more than the past four years combined. Over 90 percent of those compromised records were attributed to organized crime networks. Attacks and breaches are becoming very complex in nature. A new trend shows that there is a rise in custom malware which targets specific assets. And what do criminals do once they obtain this data? Usually it is handed over to another "tier" in the criminal hierarchy, making it even more difficult to catch those involved in these types of crimes.

While hacking, phishing and SPAM still remain as external threats, data breaches can also be instigated by internal sources. In fact, even though most data breach cases were perpetrated by external sources, internal breaches account for more total compromised records. Disgruntled ex-employees and rogue IT technicians can prove to be a serious threat to data security and must be mitigated by close monitoring of event logs.

State and local government agencies are especially rich targets because they store an immense amount of data online. As more government services become available online, the more at risk that data becomes. Hackers are opportunistic; they will go where the money is. In this case, money can be in the form of personal information such as Social Security numbers, accounts numbers or addresses and phone numbers. But the threats don't stop there. Increasingly, security professionals are seeing the results of hacking at the national level, which becomes a treat to national security.

Hewatt said, "technology is not always the answer." The report shows that nearly nine out of 10 breaches were considered avoidable if security basics had been followed and that it's not the lack of technology that allowed these breaches, but the lack of policies and processes that actually created the opportunity for these criminals to act. There are things that agencies can do to make themselves less vulnerable. Some recommendations were:

  • Technology is not always the answer -- do not use products as a replacement for better processes.
  • Find, track and assess data. Know exactly what data you have in your possession and where exactly it is stored -- eliminate unknowns.
  • Prioritize security-- find out what needs what needs to be patched immediately and stay updated when new patches become available.
  • Have internal resource experts -- employees who multi-task have divided attention.

| More

Comments


Add Your Comment

You are solely responsible for the content of your comments. We reserve the right to remove comments that are considered profane, vulgar, obscene, factually inaccurate, off-topic, or considered a personal attack.

In Our Library

White Papers | Exclusives Reports | Webinar Archives | Best Practices and Case Studies
Identity and Access Management Considerations
Gain insight into enterprise identity and access management (IAM) trends and a unified approach that can simplify identity and access management before, during, and after your organization implements cloud-based services.
Document Driven Process Automation and Human Services
By the Center for Digital Government

Read this Center for Digital Government issue to find out how document-driven process automation can drastically accelerate workflow in state and local government human services agencies.
Using Wireless Technology to Manage and Optimize Government Fleets: Saving Money, Generating Revenues, and Increasing Safety
Using Wireless Technology to Manage and Optimize Government Fleets: Saving Money, Generating Revenues, and Increasing Safety. The paper discusses the challenges federal, state and local government agencies currently face with their government fleets; how mobile technology can help; considerations when selecting a mobile solutions partner; and the benefits of choosing Sprint. Specifically, Frost & Sullivan highlights Sprint’s fleet expertise, its powerful networks, and advanced partnerships that work in concert to provide government fleets with the ability to: Save money, Generate new revenues, Enhance safety, Help the environment, Increase the availability and transparency of information to the public
View All

RSS

Digital Communities members get access to our collaboration task forces

427 Members

77 Discussions

84 Files

Latest members Become a member

Digital Communities members get access to our collaboration task forces

669 Members

145 Discussions

150 Files

Latest members Become a member

 


Featured White Papers & Reports

CIOs Redefine Local Government and Industry Relations

Based off of discussions of the Digital Communities Large Jurisdiction Chief Information Officer (CIO) Working Group, this white paper aims to answer the question, "In today's economic, political and business environment, what constitutes a successful relationship between government and industry?" Cause for Optimism identifies and clarifies the issues that separate government and industry, and begins to find an answer to the question necessary for both to enjoy a successful and prosperous future.


View Full Library

Events

GTC East

Don't miss this opportunity to see the latest in digital government solutions, keep abreast of current policy issues and network with key government executives, technologists and industry specialists.

View All Events