Most tech solutions providers on the exhibit floor at NRF this week appeared, shall we say, stubbornly upbeat about 2009 business. One company principal said he saw no reason at this point in the year for dire pessimism and half-joked that "if everyone acts like it's going to be a bad year, they'll most certainly have one." No one was denying, however, the increased pressure to provide proof of ROI for tech products in such a tough economic climate. That may be a rather simple math equation for vendors that focus on labor efficiencies or optimizing business processes, but in the area of network security - specifically, the safeguarding of customer credit card information and other critical data - potential buyers are dealing with a murkier cost/risk analysis. So with purse strings tightened, CIOs and department heads may be looking at their security situation and trying to figure out how to plug the biggest holes at the lowest cost.
Verizon Business, in their 2008 Data Breach Investigations Report, looked at incidents spanning four years and more than 500 forensic investigations. The breaches they examined included three of the five largest ever reported, and compromised, in total, approximately 230 million records. Retail represented 35 percent of the cases, the largest portion by industry. Eric Brohm, Senior Consultant, Investigative Response, said attention should be drawn to two security targets: involvement in secure systems by third parties, such as suppliers and maintenance companies, and the use of eCommerce applications, which are notoriously vulnerable to hackers. In the first case, Mr. Brohm said vendors are prone to sloppiness in following simple security procedures, often "forgetting to close the door on their way out" once their work with a retailer is done. IT managers could reduce risks tremendously, he said, by simply tightening control of these partners.
Manav Khurana, head of industry marketing for Aruba Networks, described how "unauthorized or accidental devices" (i.e. workers bringing in their own equipment) can bring risks to a wireless network environment, opening a back door to data. In high profile cases, roving hackers with laptops have been known to sit in the parking lots of malls searching for WiFi networks within that aren't properly safeguarded.
PCI standards call for auditing the physical environment of the store or office at least once a quarter to find any wireless devices in use, explained Mr. Khurana. Of course, companies can dispatch a tech with a handheld device to monitor offices, stores and distributions centers, but that can be prohibitively expensive. Aruba offers its AirWave Wireless Management Suite 6.2 (newly released) that works with sensing devices that can automatically check enterprise locations and provide detailed reporting to data center admins. Users can view all enterprise locations on a world map and then, by drilling down, display a floor plan of each location, pinpointing all the wireless devices that exist and revealing which are posing security risks. Further, a PCI Compliance Report feature gives an executive-level summary of all issues across the enterprise in a one-screen report.
Configuresoft products similarly look at workstations and servers in a physical or virtual environment and assess them for various configuration aspects, including security. Again, the cost-savings, according to Dave Shackleford, Director, Center for Policy & Compliance, comes from "giving one administrator the ability, from a single console, to do a lot of different things with all of their systems." Configuresoft designs templates that are updated monthly to make it much easier for admins to keep systems in PCI compliance and do routine chores, such as patch management.
When asked where the biggest holes are in systems, Mr. Shackleford said, "It would amaze you, actually." Rather than sophisticated, complex attacks, "it's really simple things that people lost track of," for example, forgotten old test systems that stayed online, multiple users sharing a common password, or workers storing passwords in plain text files. (Sound familiar?)
Discussion Questions: Do you expect that large retail companies will fall behind in their security procedures and safeguards during the economic downturn? For your IT dollar, where do you think efforts should be concentrated to plug security holes?
- Verizon Business Data-Breach Report
Examines Industry-Specific Challenges - Verizon news release
- 2008 Data Breach Investigations Report - Verizon Business
- 2008 Data Breach Investigations Supplemental Report - Verizon Business
- Aruba Networks Introduces PCI Compliance
Reporting In New Airwave Wireless Management Suite 6.2 - Aruba Networks
news release
- Configuresoft Announces Industry's
First Free Utility to Help Ensure Payment Card Industry Data Security
Standard v1.2 Compliance - Configuresoft news release