Newsletters Welcome, Guest Log In | Register

SMB Tech

Expert tech insight and advice for small businesses with big goals

About this Blogger RSS

Subscribe

Sign up now and get the best business technology insights direct to your inbox.

  • Daily Edge
  • CTO Edge Update
  • Business Tools & Templates
  • Aligning IT & Business Goals
  • Maximizing IT Investments

0

Security Is for SMBs, Too

Posted by Paul Mah May 11, 2009 5:42:35 AM

I came across this interesting Q&A with an FBI agent who played a pivotal role in busting a transnational cybercrime outfit. Agent J. Keith Mularski spent two years infiltrating an underground Internet forum used to facilitate the buying and selling of stolen credit card data for identity fraud, which led to 60 arrests around the world.

 

While the article was interesting enough purely in terms of how the investigation took place, I feel that the interview really crystallizes the notion that SMBs need to be more proactive than ever in terms of how they approach IT security.

 

A couple of thoughts struck me upon reading the article.

 

Exploits and botnets are more sophisticated than ever

 

Mularski noted how security attacks are more sophisticated than ever. A case in point: The majority of botnets in the past were coordinated from IRC channels, which is considered to be fairly simple, if not downright primitive. I think any fairly savvy administrator would be able to find and eliminate any such infected machines on the network relatively quickly.

 

Unfortunately, the situation has changed dramatically. At the moment, botnets such as the Storm worm are much more sophisticated and operate via peer-to-peer networks. Throw in some protocol obfuscation or data encryption, and it is easy to see why it becomes extraordinarily hard to track down and locate infected terminals, much less identifying and eliminating the command and control servers.

 

All about the money

 

Remember the Web defacement attacks of yesteryear?  Well, rather than the stereotyped "18-year-old pimply faced kid" in his dorm committing cybercrimes these days, such attacks have passed into the domain of organized crime groups. And instead of petty demonstrations of hacking skills, the primary driving motivation for these crime groups is profit.

 

When it comes to stealing the credit card numbers of your customers or making off with a copy of your human resource database, your small and medium-sized business is as fair game as any. In fact, I think it would arguable be easier to infiltrate an SMB than an enterprise with its dedicated security personnel and independent security audits.

 

Conclusion

 

SMBs need to stop thinking that all security entails is the presence of an antivirus application and corporate firewall. In truth, these are simply tools to reduce the probability of security incidences, and not the solutions per se.

 

And rather than relegating the idea of implementing computer security as yet another unnecessary chore, it is time for small and medium businesses to wake up and think hard about this.

Add a comment Leave a comment on this blog post.

There are no comments on this post

Software Forum: Information On Demand Virtual Experience

This interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Performance Under Pressure: The State of Enterprise Web Application Quality and Availability

This research study finds that Web application issues are an all-too-common problem and examines these Web-based enterprise application issues from two perspectives: that of an online customer and that of a site manager.

Decision Management

Applications, management tools and industry advice on how to optimize your data for better business decisions.

Energy Efficiency

Best practices to optimize computing ability while minimizing power costs.

Business Intelligence

Best-practice tools, strategies and technologies for determining and managing the data you need to make better business decisions.

Information Management

Tools, tips and solutions to help you manage your data more efficiently to tackle today's challenging economic environment.

Budget & Finance Toolkit for IT - 2010 Edition

What kind of year are you planning in 2010?  Growth or continued "survival mode"?  Download a comprehensive collection of templates, forms, instruction and advice that will help you to plan and submit your 2010 IT Budget.

Learn more >

Disaster Recovery & Business Continuity Template Pack

Prepare your company for any type of disaster you can envision and those you cannot. Immediately download this comprehensive set of templates and tools for documenting your business contingency plans.

Learn more >