Facebook hacked

It seems that bad news does come in threes. This week Facebook  revealed it had suffered a security breach, on top of 2500,000  compromised twitter accounts and the cyber attack on the New York Times earlier this month.  Again it has stemmed from the same issue of a weakness in (Java) script that duped Facebook employees to infect their laptops with malware as they visited the site of a mobile developer.  Oracle has since sent a “fix” to Facebook and other users but the stories just keep on coming.

Cyber crime is now part of our everyday on-line life.  Simply clicking on a link from an unknown source, or one that porports to come from a known source, can allow a computer to be hijacked or personal information such as passwords and bank account details to be sent to a remote computer.  On a more sophisticated level, when Russian activists bombarded Estonian banks the whole country had to go “off-line” until the threat had passed.  In 2010, the UK had two reported targeted attacks a day on government institutions and companies.

By the close of 2012 that figure had risen by almost 25,000% to 500 a day. Some hackers are now able to take over a computer, lock it down and not relinquish control until they have been paid – all from the comfort of their homes. The US government have also raised questions with regard to Huawei, (a Chinese company that provides some of the technology behind broadband, particular mobile dongles) as to whether the Chinese government will have access to information passing through these devices.

For small to medium enterprises these issues seem difficult to comprehend, let alone prevent, as ultimately nothing can be 100% secure.  Like protecting a physical premises, you can take measures to reduce the risk of a break-in by using surveillance systems, sophisticated access control or on-site security personnel, but you can only minimise the risk, not remove it entirely.  With on-line security, you can try to foresee the next threat but ultimately, as in the case of Java, it’s a game of catch up once the horse has bolted.

It is difficult for managers of SME companies to keep pace with this world of rapidly evolving software and technologies.  To protect their own data they will either need to bring the skills and competence in house or engage a local IT firm that deals with this sort of thing often enough to be abreast of the trends.
Planning for the eventuality of a cyber attack will not be made any easier, as it was reported this week that there is a skills shortage of IT security specialists within the UK.  When upgrading their technology, business owners need to balance the requirement for greater flexibility with the growing and more sophisticated threat of cyber attack. Whatever procedures, or personnel are put in place, they will need to keep up with this ever changing world.

To ensure your business has the basics covered, please see our ‘8 steps towards greater internet security‘ article.

Server security how to improve