BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

1 In 14 Could Cost You $129 Without Least Privilege

Posted May 24, 2011    Peter McCalister

Yep, this is a pretty esoteric title for today’s blog, but blame the late hour and the recent article in PC World about malicious code and downloaded software.
According to this article, “about one out of every 14 programs downloaded by Windows users turns out to be malicious.” This didn’t come from some random blogger or disgruntled day trader. It came from Microsoft’s own research and, according to the article, “even though Microsoft has a feature in its Internet Explorer browser designed to steer users away from unknown and potentially untrustworthy software, about 5 percent of users ignore the warnings and download malicious Trojan horse programs anyway.”

So the bottom line is that people can potentially take advantage of admin rights by downloading software and will have a 1 in 14 chance of infecting their computer with malicious code. This will then trigger a help desk call which can cost approximately $30 per incident and, according to Gartner Group $129 per PC annually.

If it can cost $129 per PC per year and it is known that people will ignore standard warnings when doing admin-related tasks such as downloading software from the internet, then why do IT directors continue to allow users to have full administrator privileges of their desktops? Especially when a least privilege solution can mitigate this risk and associated costs.

Leave a Reply

Additional articles

randy franklin smith

At the End of Day You Can’t Control What Privileged Users Do: It’s about Detective/Deterrent Controls and Accountability

Posted March 31, 2015    Randy Franklin Smith

Live Webinar: Thursday, April 2, 2015 | 10am PT/1pm ET | REGISTER NOW! In this webinar, Security Expert Randy Franklin Smith will look at how to audit what admins do inside Linux and UNIX with sudo’s logging capabilities.

Tags:
, ,
BA_Hacked

British Airways Executive Club Member Accounts Hacked

Posted March 30, 2015    Brian Chappell

British Airways has released information regarding the hacking of a number of their Executive Club (BA’s frequent flyer programme) member’s accounts.

Tags:
, , ,
webinar_ondemand

On Demand Webinar – Why You Still Suck at Patching

Posted March 27, 2015    Lindsay Marsh

On Demand Webinar: Dave Shackleford recounts some of his personal experiences in patch management failure, and breaks down the most critical issues holding many teams back from patching more effectively.

Tags:
,