Mon, Jan 4th 2010 12:00 am
January Tip of the Month
Someone breaks into your home, what do they take? Jewelry? Electronics? Cash? That is a scary thought, isn't it? What about if they break into your computer – what do they steal? Your credit card numbers? Your personal information? They steal your identity. The very essence of who you are.
Is that a scary thought? Absolutely! And rightly so. A person with the right information can actually become you! If they know the right answers to the right questions – there is nothing someone else can do. For all they know, that person is you!
At home, you install burglar alarm systems, lock your doors, maybe you even have a weapon to protect yourself and your family when you're at home. But what about your computer systems? What about your corporate network? Your HR department has all that personal information. They've got the answers to most of the questions someone would ask to verify you are who you say you are.
What about your clients' information? Do you store name, address, phone, social security number, credit card, or other private information. How would you like to be held liable for the loss of that information and the subsequent loss of a client's identity? That's another scary thought!
Let me cap all the scary thoughts off with one more thought – when the thieves break into your home and steal your jewelry, you know it was stolen because it is no longer there – it is missing. When thieves break into your computer or network, however, how do you know the information was stolen? You don't! This is because the information was copied, replicated, etc. The original copy is still there and you have no idea it has gone missing or been stolen.
An Intrusion Prevention System (IPS) is an intelligent program that monitors your network for malicious or unwanted behavior and can react in real-time to block the attack.
What can you do in your home and in your business? Many things. Be sure your operating systems are patched continually. Scan your systems for malware regularly – at least weekly. Put a layered system of defense at the perimeter of your network – intrusion prevention, antispyware and antivirus scanning on the firewall, and content filtering.
If you are in a larger organization, get help from people who know what they are talking about. Use security consultants to keep you informed. Outsource some of the IT Security functions, allowing people who specialize in security knowledge to take care of the security. You wouldn’t ask your accountant to write code for a program, would you? Don’t ask folks with no security experience to run your vulnerability scans, penetration tests, patch management programs, or to manage your firewalls. Let professionals who know what they are doing do their jobs.
Should you be afraid of what’s out there and what could cause difficulties for you? Yes! Can you do something about it? Absolutely! But be sure to start acting now, before thieves gain access to your system.
Guidant Partners Security Services can provide a layered approach to securing your business. We use a centrally managed, multi-layered firewall, which includes Gateway Antivirus, Preemptive Antispyware, Intrusion Prevention, Application Firewall, and Content Filtering. We can further enhance your organizations security by providing secure
remote access to your network from the outside. If you have regulatory compliance issues (PCI, GLBA, SoX, HIPAA, etc.), let Guidant Partners help you position yourself to meet the stringent data security requirements. Call us for further assistance at (615) 277-3352 or email EKarkau@GuidantPartners.com