CompUSA
Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Tuesday, October 27, 2009

Study Finds U.S. Small Businesses Lack Cybersecurity Awareness and Policies

/PRNewswire/ -- Small business owners' cybersecurity policies and actions are not adequate enough to ensure the safety of their employees, intellectual property and customer data, according to the 2009 National Small Business Cybersecurity Study. The study, co-sponsored by the National Cyber Security Alliance (NCSA) and Symantec [Nasdaq: SYMC], as part of this year's National Cyber Security Awareness Month, surveyed nearly 1,500 small business owners across the United States about their cybersecurity awareness policies and practices.

The survey confirmed that small businesses today are handling valuable information - 65 percent store customer data, 43 percent store financial records, 33 percent store credit card information, and 20 percent have intellectual property and other sensitive corporate content online. 65 percent of the business survey claimed that the Internet was critical to their businesses success yet they are doing very little to ensure that their employees and systems are not victims of a data breach.

The survey shows discrepancies between needs and actions regarding security policies and employee education on security best practices. Only 28 percent of U.S. small businesses have formal Internet security policies and just 35 percent provide ANY training to employees about Internet safety and security. At the same time, 86 percent of these firms do not have anyone solely focused on information technology (IT) security. For those small businesses that do provide cybersecurity training, 63 percent provide less than 5 hours per year.

The lack of focus on cybersecurity awareness and education on the part of U.S. small businesses can lead to the loss of vital customer and company data. The study found that while more than 9 in 10 small businesses said they believe they are safe from malware and viruses based on the security practices they have in place, only 53 percent of firms check their computers on a weekly basis to ensure that anti-virus, anti-spyware, firewalls and operating systems are up-to-date and 11 percent never check them.

"The 20 million small businesses in the U.S. are a critical part of the nation's economy. While small business owners may understandably be focused on growing their business and the bottom line, it is imperative to understand that a cybersecurity incident can be disruptive and expensive," said NCSA Executive Director Michael Kaiser. "To the millions of very savvy entrepreneurs across our nation, our message is simple - being smart about the online safety of your employees, business and customers is a critical part of doing business. Cybersecurity is not a nice thing to have for American businesses, it is critical to their survival."

Meanwhile, small businesses seem out of sync with some Internet security risks. 75 percent of small businesses said that they use the Internet to communicate with customers yet only 6 percent fear the loss of customer data and only 42 percent believe that their customers are concerned about the IT security of their business. What's more, 56 percent of small businesses believe cybersecurity is the cost of doing business while 21 percent believe it is just "a nice thing to have."

Laptops, PDAs and wireless networks are great conveniences to businesses, yet they carry with them an added responsibility to ensure the data is secure. Today, more than 66 percent of employees take computers or PDAs containing sensitive information off-site. Wireless networks are gateways for hackers and cyber criminals and must be secured by complex passwords. Unsecured wireless networks are akin to leaving the front door of a filing cabinet wide open on the sidewalk. 62 percent of the companies surveyed have a wireless network but 25 percent of them do not password protect their wireless networks. This is a significant security risk as hackers can steal information being passed through these open networks.

"Security threats are becoming more complex and employees of small businesses are increasingly the target of attacks that expose their organizations to data loss," said Sheri Atwood, vice president, global solutions and programs, Symantec. "Security awareness and education, combined with a comprehensive security solution, can empower small businesses and their employees to protect themselves and their information."

For more information on how you can keep you and your business safe online visit www.staysafeonline.org. For additional results from the Zogby study, visit: http://staysafeonline.mediaroom.com/index.php?s=67

The demographic makeup of the small business polled focused on number of employees and revenue. 56 percent of those polled were companies with one-to-nine employees, 10 percent had 10-25 employees, five percent had 26-50 employees and five percent had more than 51 employees. In terms of revenue, 56 percent had annual revenue of $249,000 or less, 11 percent have revenue of $250,000-$499,000, eight percent have revenue of $500,000 to $1 million. 11 percent have revenue between $1 million and $5 million and five percent have revenues exceeding $5 million. The Zogby International poll has a margin of error of +/- 2.6 percentage points.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow us on Twitter: @GAFrontPage

Saturday, September 5, 2009

UGA to convene cybersecurity panel Sept. 11

Nationally recognized experts will come to the University of Georgia on Sept. 11 to teach university and community members how to protect themselves from cyberterrorism during “The Growing Cybersecurity Threat: From National Security to UGA,” a free panel discussion running from 10 a.m.–noon at the UGA Chapel.

As information sharing and Internet use become cornerstones of the average person’s wired life, keeping up-to-date about growing threats is increasingly important, said John Newton, event organizer and emergency operation coordinator in UGA’s Office of Security and Emergency Preparedness, which is co-sponsoring the event with the Center for International Trade and Security and Enterprise Information Technology Services.

“There’s been an explosion of cybersecurity threats over the past few years that affect everyone from governments and the military down to people who shop or do business online,” Newton said. “It’s something that reaches most of us nearly every day, and because the threats change rapidly it’s important to keep re-learning how to combat them.”

The panel will consist of FBI Special Agent Lee Kirschbaum; Brian Rivers, director of information security at UGA, and Kevin Mandia, a cybersecurity expert and owner of the information security firm Mandiant Systems

“As far as information security risks and threats, they always change, but for the most part the university has changed and adapted along with the threats,” Rivers said. “But threats continue to evolve. People are getting better at attacking us. Over the last 10 years there’s been a shift from people hacking for fun to people hacking for profit. It’s now big business overseas.”

As Web surfers increase their online business transactions and store more personal information on the Internet, the availability of data to potentially harmful sources ramps up. Over-the-net business is overwhelmingly safe, but it’s important to be watchful for new trends in hacking, said Kirschbaum, who works at the Atlanta FBI headquarters.

“We want to make folks at UGA aware of some of the threats that are out there, so if they come up, they may sense them. When you’re in academia and doing research, the propensity is to share your information with anybody and everybody because we all want to see knowledge advance,” Kirschbaum said. “But at times the information you’re giving out can be too sensitive. People may begin to ask questions that are too probing, and at that point in time we want people to realize that this maybe something that they should let law enforcement know about.”

Modern hackers use a variety of computer intrusion techniques like unsolicited e-mails, malware and programs embedded on thumb drives that can invade entire computer networks and send back users’ private information, he said. A one-computer virus does not rate the same threat level as it did a few years ago.

Beyond personal and professional significance, the issue has national prominence as well. Cyberterrorism grabbed worldwide headlines in July, when the U.S. and South Korea fell victims to an orchestrated network attack. While no major harm was done, the incident revealed computer weaknesses in the governments that could have been disastrous and caused renewed interest in cyber health, said Igor Khripunov, interim director of the Center for International Trade and Security.

“The newly-announced U.S. Cyber Command will likely make great strides in protecting national-level critical infrastructure and systems from cyberterrorists,” he said. “However, other systems are at risk, including those here at the University of Georgia.”

“According to the Homeland Security Department, cyber attacks on federal computer systems alone have increased by more than 250 percent over the last two years,” he added. “But a few fundamental management changes—centralized management of information technology systems, better education and training, and tougher access control—could prevent man of the most common attacks.”

The event is part of OSEP’s Academic-Professional Security Series. For more information, see www.osep.uga.edu.

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page

Tuesday, May 19, 2009

Cybersecurity Groups Launch 'Chain of Trust' Initiative to Combat Malware

/PRNewswire / -- Three of the world's leading cybersecurity groups today launched a new initiative to combat malicious software (malware) by establishing a "Chain of Trust" among all organizations and individuals that play a role in securing the Internet.

Developed by the Anti-Spyware Coalition (ASC), National Cyber Security Alliance (NCSA) and StopBadware.org, the Chain of Trust Initiative will link together security vendors, researchers, government agencies, Internet companies, network providers, advocacy and education groups in a systemic effort to stem the rising tide of malware.

Applying many of the same approaches used to bring nuisance adware under control, the Chain of Trust Initiative aims to establish a united front against a threat that continues to grow exponentially. Kaspersky Labs recently reported that malware distributed through social networking sites is successful 10 times more often than scams distributed via email.

"Strong security in any one organization or sector is not enough to combat an agile, fast evolving threat like malware, which exploits security breakdowns between entities," said Ari Schwartz, ASC Coordinator and Vice President of the Center for Democracy & Technology (CDT). "We all need to work together to build a system that can withstand and repel the next generation of exploits."

The first order of business in the Chain of Trust Initiative is to map the complex, interdependent network of organizations and individuals that make up the chain. Only by identifying all the vulnerable links and understanding how they connect to one another can malware fighters get a handle on the problem and begin to develop consensus solutions.

"Online safety and security is a shared responsibility that requires the involvement of governments, corporations, non-profit institutions and citizens," said Michael Kaiser, Executive Director of the NCSA. "The Chain of Trust Initiative will focus furthering the development of tools that provide better protections. However, we must also continue to ensure that all of us implement universal behaviors online that protect us against a multitude of threats."

ASC, NCSA and StopBadware.org will lead the mapping effort and jointly develop ideas and initiatives to form stronger bonds between links on the chain. Leaders of the initiative have already begun reaching out to key players and identifying critical areas for collaboration. In the next six months, the Chain of Trust Initiative will produce a paper tracking the results of the mapping project and propose initial recommendations to strengthen the chain.

"Organization and collaboration are our best tools against an enemy that doesn't play by any rules," said StopBadware.org manager Maxim Weinstein. "Just by nature of how the Internet works, malware distributors have a technological advantage, but we can respond by strengthening our shared networks and by better understanding our shared responsibilities."

-----
www.fayettefrontpage.com
Fayette Front Page
www.georgiafrontpage.com
Georgia Front Page
Follow on Facebook