Corporate Counsel
  • Home
  • News
  • Surveys
  • Resources
  • Lawjobs
  • Advertise
  • Subscribe
  • Bookstore
  • Contact

Topics » IP Insider | Labor & Employment | From the Experts | On the Job | Moves | DC Watch | International

Home > Employees May Be a Company's Greatest Cybersecurity Vulnerability

Font Size: increase font decrease font

Employees May Be a Company's Greatest Cybersecurity Vulnerability

By Catherine Dunn Contact All Articles 

Corporate Counsel

February 21, 2013

  •    
  •    
  •    
  •      
 
computer_security

© designsoliman - Fotolia.com

Apple Inc, disclosed a cyber attack Tuesday, which started when employees visited a website for software developers and inadvertently picked up malicious software that infected their computers. Similarly, Facebook announced last week that malware got onto employee laptops after some employees visited a “compromised” developer website. And in a recent report about hackers infiltrating systems at The New York Times, investigators came to suspect that employees opened malicious links or attachments contained in emails.

In these and other cyber attacks on corporations and government agencies, employees often serve as gateways for intruders—underscoring the need for better employee education about digital security, according to a new report by the data security solutions firm Trustwave.

“[A]ll the security controls in the world are useless if an attacker can manipulate an employee with system access,” according to the findings, which include an analysis of more than 450 data breach investigations in 2012.

Whether thieves are after customer data or a company’s intellectual property portfolio, employee email, mobile devices, network passwords, and social media can all open the door for an attack.

“Concern over targeted attacks is increasing,” the report finds. “In previous years, and in 2012, the initial attack is frequently carried out by email, and this situation showed no sign of abating during 2012.”

Contrary to the belief that targeted attacks distributing malware are “ultrasophisticated,” they actually tend toward the “mundane” yet plausible, according to Trustwave.

The covertly malicious emails received by employees may purport to be about conferences, meeting invitations, or security updates. Attackers, having done their homework, can manipulate the “From” field so it looks like the email originated from someone within the company. Given the sender, subject, and context, “the email makes sense to an employee of that organization,” say the report’s authors.

The proliferation of smartphones and mobile apps presents another set of security worries, “as these devices routinely connect to unknown networks every day,” says Trustwave. “Mobile devices not only connect back to corporate networks but also contain valuable personal information, making them attractive targets for cybercriminals.”

Meanwhile passwords that guard devices like routers and firewalls are consistently “configured with weak or easily guessable default passwords,” the report finds.

In a sample of nearly 3.1 million passwords, for example, Trustwave found that while about 1 million were unique, many were not. “Welcome1” topped the list of most common passwords, showing up 30,465 times, followed by “STORE123” (21,362 times), and “Password1” (15,383 times).

“Passwords once thought to be complex enough to make cracking improbable are now able to be reversed in hours or days,” the report states. “This requires users and administrators to rethink how they create passwords and how users are educated about password security.”

Seemingly innocuous postings on social media by employees can also help thieves execute an attack.

“Posting one’s place of work on Facebook might not seem dangerous,” the report warns, “but when combined with co-worker connections on LinkedIn, pictures of office parties from FlickR and check-ins on Foursquare, an attacker can create a very detailed picture of the internal workings of a company without ever setting foot inside.”

All in all, the authors identified employee education as integral to any other cyber defenses, arguing that “no policy enacted will have much impact if employees aren’t on board (especially if they don’t truly understand the consequences of their actions).”

One step companies can take is to conduct training on security awareness. “Regular staff training on both core security techniques and topical issues is important to build a successful security foundation,” the report recommends. “This awareness training must include case studies highlighting both obvious pitfalls (clicking on suspicious links) and not-so-obvious ones (posting company photos online in which staff members are wearing their security badges).”

Running security awareness campaigns also help to reinforce those ideas, and remind employees to stay vigilant. Incentives don’t hurt, either. “Reward staff for identifying incidents, which will encourage them to be observant,” the report advises.

See also:
“Cybersecurity Report Spotlights Risks to U.S. Business from Chinese Hackers,” CorpCounsel, February 2013.



Subscribe to Corporate Counsel

You must be signed in to comment on an article

Find similar content

Companies, agencies mentioned

    
  • New York Times Company
  • Apple Inc.

Key categories

    
  • Corporate & Business Law
  • Internet and Technology Law

Most viewed stories

    
  1. Best Legal Departments 2013
    •      
  2. 6 Things In-House Counsel Must Know About E-Discovery
    •      
  3. 3-D Printing: The Next Big Thing in IP Law?
    •      
  4. Bristol-Myers Squibb: The Caped Crusaders
    •      
  5. U.S. Legal System Ranked as Most Costly
    •      
lawjobs.com

TOP JOBS

MORE JOBS

POST A JOB

From the Law.com Network

Taking the Reins of Legal Department Operations

In-House Law: Now in 3-D!

Simpson Helps Yahoo, Tumblr Connect for $1 Billion Deal

Kasowitz Benson Launches in Los Angeles

Contrite Companies Can Win Forgiveness in Bribery Cases
  •      
    • Subscription Required

Plaintiffs Want to See Toyota's 'Crown Jewels'
  •      
    • Subscription Required

Collaboration Is Key to Defending Cyberattacks

Stanford Law Builds on Role as Legal Tech Incubator

Prolific ADA Plaintiff Faces Nemesis in Harassment Suit

Ullyot Exit Closes Chapter for Facebook

Rothstein Bankruptcy Trustee Files New Reorganization Plan
  •      
    • Subscription Required

Fla. Bar Wants Disbarment for Former Judge
  •      
    • Subscription Required

Appellate Division To Roll Out Electronic Case Filing System

Court Limits Liability for Injury Or Death of One Invited To Help
  •      
    • Subscription Required

The Affordable State-Specific Practice Solution
Available in NY, NJ, PA and CT editions - research, draft and prepare even the most complex cases with ease.

Court Officials Seek to Reform Process of Naming Acting Justices

NYC Defends Police Department's Use of Stop-and-Frisk

Immigrant Investor Program Gets Watchful Eye

Judge Orders Parties to Hire Neutral Expert to Probe Facebook

Law Schools Are Looking Beyond LSATs, Says Mich. Dean

Is Freezing Your Eggs the Solution?

Water Warriors: Local Governments Bring Pollution Suits
  •      
    • Subscription Required

Sanction Reversed; Filing of Sexually Explicit Chat OKd
  •      
    • Subscription Required

Lenders Win On Foreclosures
  •      
    • Subscription Required

Justices: Doc Interviews With Defense Are Attorney Work Product
  •      
    • Subscription Required

Corporate Bribery Case Part Of National Trend
  •      
    • Subscription Required

Court Continues To Grant Lawyers Fraud Immunity
  •      
    • Subscription Required

  • About |
  • ALM Properties |
  • ALM Reprints |
  • Customer Support |
  • Privacy Policy |
  • Terms & Conditions |
  • ALM User License Agreement
ALM Media