Email this article   Print article 


Organizations Take Lessons From A Certified Ethical Hacker

By Stefanie Hoffman
April 21, 2008    12:00 AM ET

Page 1 of 3

Larry Detar has a job that tech-loving kids only dream of having when they grow up. As the vice president of global services for a company called EC-Council, Albuquerque, N.M., he hacks into networks for a living.

As a Certified Ethical Hacker, Detar conducts vulnerability assessments and penetration tests for financial institutions, government agencies and corporations. He executes code to infiltrate systems. He enters data centers pretending to be a member of the IT staff. He even digs through dumpsters to get to find whatever Achilles' heel exists in a seemingly impenetrable business.

And never once in the last five years since Detar's association with EC-Council did he fail to get at a company's sensitive data.

"That's the state of security," Detar said. "The majority of those access points are open to the 9-to-5ers. Not only the passwords to get into the computer, but the core application that controls the financials for that institution. They have access to everything that's not locked up."

Over the years, Detar has seen some security breaches that would make a TJX executive cringe. The simple fact, however, is that many security holes are avoidable.

While there is to date no security solution that is completely hackproof, Detar and fellow security experts agree that there are definitely some tried-and-true strategies that, when applied, will significantly reduce the odds that hackers will pick your business for their next attack.

1. Training, Training, Training
You can't get enough. Most experts agree that the security of an organization is as good as its weakest link--which is why they emphasize that training and awareness should be implemented at every level.

"Although everybody gives lip service that security starts at the lowest rung, nobody bothers to train that rung of the organization," Detar said.

Basic security training reinforces common sense behaviors, such as Internet safety, regularly installing security updates, file sharing protocols or mobile technology best practices. Yet many breaches occur as the result of carelessness or lack of user education, experts say. One such example is phishing, and there are other socially engineered attacks that can bring down a network by active consent from an unsuspecting user.

"People will get phished if they've never heard about phishing," said Guillaume Lovet, manager for the EMEA Threat Response Team at Fortinet Inc., Sunnyvale, Calif. "That's why social engineering is so cherished by hackers--it's so effective."

2. Encrypt Sensitive Data
Porous networks and mobile devices like BlackBerries and laptops have enabled increased mobility for workers, but have increased exposure to critical data. As a result, companies need solutions for protecting the information, as opposed to protecting the device in which it is stored, experts say.

Paul Kocher, president and chief scientist of San Francisco-based Cryptography Research Inc., said that companies need to protect at-risk data, or get it off their network altogether.

"The main thing encryption does is make it so data itself is no longer the critical thing to protect, but the keys are," he said. "In a way, you can think of encryption as transferring the security properties of an object to something that's easier to manage."

Next: 3. Pass On The Passwords



1 | 2 | 3 | Next >>

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Tech 10: Hot Antivirus Alternatives For 2013

CRN identifies 10 vendors that have developed innovative ways to detect malware and analyze threats to better protect corporate networks. They take a giant step beyond traditional signature technologies.

10 Emerging Security Technologies Gaining Interest, Adoption

Despite some security defenses being only in their infancy, they are attracting interest for addressing BYOD issues, cloud security concerns and stolen account credentials. Here's a look at some of the top new security areas gaining industry interest.

5 Government Intelligence Facilities You've Never Heard Of

One facility has been around since the dawn of space exploration, while other buildings are still in construction. But, they all have serious data analysis and surveillance support activities associated with them.

  More Slide Shows




Related Videos
Loading...