Welcome | Sign In
ECommerceTimes.com
Security

Companies Not Keeping Up With Network Security Needs

Print Version
E-Mail Article
Reprints
Companies Not Keeping Up With Network Security Needs

Vernier President and CEO Simon Khalaf said that the survey revealed some "shocking" findings about companies' knowledge level about internal network security. "Companies did not realize how open their network and their systems are to attacks from within the company," he said.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

Most companies depend exclusively on perimeter defenses to protect their computer networks from intruders, a practice that appears to be more sieve than stone wall, according to a survey released yesterday by Vernier Networks, a network access management firm in Mountain View, Calif.

Surveyors found that 51 percent of those sampled said they relied on strong perimeter security, or the "doorman" approach to network protection. Once past the doorman, users have unlimited access to information on the company's network.

The doorman, though, appears to be leaving his portal unattended, as 62 percent of the security execs admitted that intruders had occasionally gained access to their networks.

Opening Doors

The survey sampled some 140 chief security officers (CSOs) and security executives who attended a recent nationwide seminar series on network security held by Vernier and Qualys, a vulnerability management firm in Redwood Shores, Calif.

"The perimeter isn't as deigned as it used to be," Qualys CEO and Chairman Philippe Courtot told TechNewsWorld. "If you let people connect to your network from the outside, you're opening doors."

Vernier President and CEO Simon Khalaf said that the survey revealed some "shocking" findings about the knowledge level of companies when it comes to internal network security.

"Companies did not realize how open their network and their systems are to attacks from within the company," he told TechNewsWorld. "This has been talked about for the last year and a half, but the response has been [to do] more of the same, which is strengthening the defenses around the network versus putting security inside the network."

Marc Borbas, product manager for e-mail security at Sophos in Vancouver, British Columbia, Canada, agreed that many organizations might be emphasizing perimeter security to the exclusion of other security layers.

Desktop No Answer

"We've noticed, especially in the e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse segment of our business, there's a huge amount of investment that's gone into the perimeter and an underinvestment in the constituent layers of the e-mail system," he told TechNewsWorld.

"Companies have a good hard shell in many cases, but they're very vulnerable in that middle spot, he added.

At most companies, internal security controls are placed at the desktop level, which is inadequate, Khalaf contends. "If a desktop or a laptop has been hacked into, the security on the desktop ain't going to do much," he said.

He explained that intruders attempting to break into a network from outside the system usually must go through a firewall, an antivirus gateway and an intrusion prevention system. If they're breaking into the system from a compromised desktop or laptop connected to the system, they don't go through anything.

"The reaction to securing the network from the inside has been, let us put more security software on the desktop," Khalaf said. "I believe that is a bit flawed. What needs to happen is that the connection between the laptop or desktop and the network needs to go through the same rigorous security as a connection between the Internet and the intranet.

Reluctant To Quarantine

Security officers participating in the survey appear to agree with Khalaf. An overwhelming number of them -- 88 percent -- said that tighter user access to internal networks would improve overall security.

Ironically, while companies are leaning on local measures to thwart internal security problems, they are reluctant to take steps to strengthen those measures. A large portion of the survey's respondents -- 64 percent -- refuse to quarantine most devices on their systems that do not have the latest security patches from their software vendors.

Nevertheless, Khalaf noted that there's a growing awareness of the need to bolster the security layer between the firewall and the desktop, an awareness driven by factors like outsourcing.

Everyone on Same Page

He explained that many U.S.-based organizations have outsourced a lot of their functions outside the network. Those outsourcers often need access to resources inside the network, which has prompted companies to beef-up internal control.

Don Bowman, co-founder and chief architect of Sandvine in Waterloo, Ontario, Canada, explained that problems can occur with outsourcing when external partners haven't implemented the same security standards as the company hiring them.

"If you're expanding your border security to outside contractors, you should take steps to make sure that a contractor has the same level of diligence that you do," Bowman told TechNewsWorld. "You don't want a corrupt employee or an incompetent one exposing your data."


Print Version E-Mail Article Reprints More by John P. Mello Jr.


More by John P. Mello Jr.

Music Sites That Fill In iTunes' Gaps
November 24, 2009
iTunes is by far the dominant online music store, but it can't be all things to all music lovers. Other sites have found loyal customers by doing what iTunes doesn't. Some work variations on the subscription angle, offering unlimited music so long as a set fee is paid. Others promote instant streaming rather than downloads, and some bank on their social features.
Learning the Way of the Snow Leopard
November 23, 2009
When confronted with a new piece of technology, some users will jump right in, but others may want to learn from an expert how to get the most out of it. Class On Demand puts 13 lessons onto a DVD that Mac greenhorns can use straight from their new computers. However, as many vendors operating in the Apple universe have found, one of their biggest rivals may turn out to be Apple itself.
VMware Fuses Performance With Convenience
November 16, 2009
Fusion 3.0, the latest virtualization app from VMware that lets Mac users run Windows alongside OS X, puts an emphasis on performance. VMware built it specifically to leverage the 64-bit capabilities of Snow Leopard with a new 64-bit native engine. Its Migration Assistant for Windows lets Mac switchers recreate their old Windows PC inside a Mac, file by file.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network