INTERNAL SECURITY |
|
Protect your networks and endpoints from the threats that emerge within your organization.
Internal Security solutions will help you defend against the worms, attacks, and other
malicious threats that often exploit laptops and other mobile devices in order to enter
your network to do harm. |
|
Despite perimeter firewalls and anti-virus measures, worms and viruses are getting into
internal networks with alarming success and doing tremendous damage. They spread fast, often
swamping LANs within hours. Users are unable to do their work, and they overwhelm help desks with
calls. The network and security administrators battling the outbreaks often spend weeks cleaning
up systems and fully restoring operations. Once inside the network, worms can persist indefinitely. |
|
Worms and viruses that spread inside corporate LANs cost more than any other type of attack.
No complex mathematics is required to understand the numbers. Just multiply the number of
compromised PCs by the time and dollars it takes your IT staff to clean and rebuild each one after
a successful attack. In the case of attacks like Nachi/Welchia, the cost is greater still because
they overwhelm network resources. Now the business can no longer operate effectively. This problem
becomes exponentially worse for large networks: the larger the network, the more PCs, the greater
the damage. Preventing this damage has become the number one issue for network security managers
across the world. |
|
The most obvious risk is the human factor. People having access to internal networks are
always a threat that is very difficult to manage. The responsibility of attack should not be
put on the shoulders of an individual employee.
Companies are investing in information security to protect networks against external
threats. But anti-virus solutions, firewalls and virtual private networks (VPNs) – collectively
referred to as perimeter security – can only provide security if the internal network can be
trusted. Strong evidence suggests that internal networks can not be trusted and that
business-critical information is sent unprotected through corporate intranets. Traditionally,
companies have put their information security efforts in perimeter security, protecting only
the outer walls of the corporate networks. Internal information security has been a matter
of trusting the employees. |
|
Most security breaches do not originate from external hackers, viruses or worms, but
from employees who, according to Gartner, commit more than 70% of unauthorized access to information
systems. They are responsible for more than 95% of intrusions. According to the Computer Security
Institute and the FBI, an insider attack causes an average of 2,1 million Euros in damages, whereas
the average outside attack costs 45 000 Euros. |
|
Protecting against the threats arising from internal networks require proactive actions
in multiple areas:
- Security policy must take internal security into consideration.
- All critical data in the computers must be protected.
- All users using critical data must be authenticated and authorized.
- All critical data communications must be encrypted end-to-end.
|
|
If all of the above is not taken into consideration, the overall protection will not work in
reality. |
|