This week the social networking site Twitter was hacked resulting in the compromise of up to 250,000 account holders. Insiders say it was a sophisticated and coordinated attack that could leave other high profile websites vulnerable too.
The accounts affected were some of the oldest users of the site including original investors and even some employees. The hack appears to have been initiated through a flaw in the most recent version of java that allows potential hackers to execute arbitrary code into such systems.
Java is a free plug- in provided by Oracle that allows certain functionality within websites. Apple and Mozilla have released version updates which disables java in each of their respective web browsers. The US Department of Homeland Security issued a warning early in January after it was brought to their attention by an independent source.
This comes after The New York Times and the Wall Street journal reported similar attacks and Amazon had it’s “Gateway page” shut down for almost an hour last Thursday. Last year Sony PlayStation users were hacked and individual Gmail accounts were impersonated to extort money from friends and relatives.
The most recent reports from government meetings in Davos also suggest that other sectors are being targeted including hospitals and energy networks. Although governments seem to be aware of the threat, some business leaders have not yet risen to the challenge either through ignorance or the belief that they are somehow immune from such an event.
With the popularity of cloud computing, more and more individuals and businesses are putting their data on-line therefore increasing the likelihood of cyber attacks from unauthorized 3rd parties. Yet many small to medium businesses either don’t have the knowledge or the resources to adequately protect their information.
8 simple things that can help to be better prepared:
- Make sure your systems have the latest updates and security patches installed (including ALL servers.)
- Check what browser add-ons or plug-ins are installed on web browsers and remove any you do not recognize or have not approved for installation.
- Make sure you have a ‘leavers procedure’ for staff no-longer in your employment. Ensure that it includes:
- disabling all their user accounts across all systems they had access to
- redirecting their mail to a colleague or supervisor with a view to disabling it after a set period of time
- disabling remote access rights such as VPN, Remote Desktop or Terminal Services
- disabling or uninstalling 3rd party remote access software such as log me in, TeamViewer and go to my PC
- Make sure you are fully protected from external and internal threats. Ensure your security software protects your PCs and servers from:
- Viruses – programs that causes a system not to function properly
- Trojans – a program that appears harmless but hides malicious functions
- Worms – programs that exploit security vulnerabilities on a system
- Spyware – programs that record what a user does on a system
- Adware / Potentially Unwanted Applications (PUAs) – programs that render unwanted advertisements on a system either by way of pop-ups or redirecting your browser to specific websites
- If you allow mobile devices to access your network ensure you have adequate endpoint security installed. Endpoint security ensures that mobile devices have the latest system and security updates installed before granting them access to your network.
- If you do not have the resources to employ your own IT personnel then outsource these services to a local IT firm.
- Develop a disaster recovery plan that includes being able to continue working even if you go off-line or have to operate from a temporary office. Include off-site and on-site servers which mirror your data at particular intervals in order to minimise the amount of data you cannot recover.
- Keep abreast of any threats or trends that may be developing so you are protected when they strike.
The threat is from a variety of sources, including criminal gangs, international governments and gifted amateurs. Talking to a small business owner this week who had to manually reproduce her data lost after just such an event, these security breaches can be a costly and time consuming affair.
To find out more about how to protect your online business from attackers get in touch and our IT Specialists will be able to help you.
