BeyondTrust

Security In Context

Bringing you news and commentary on solutions and strategies for protecting your critical IT infrastructure.

How Sensitive Could Data Be?

Post by Peter McCalister March 25, 2011

Here at BeyondTrust, we work with some of the most sensitive information in the world. The kind of stuff that makes or breaks businesses, collapses empires, or creates headlines.  Ok – we’re being melodramatic, and we also deal with things as simple as system configuration settings that hike up help desk costs.

But it’s always interesting to hear extravagant cases of extremely sensitive, but small volumes of data. Like Goldman’s top secret algorithms, or a Wikileaks breach that could publically humiliate the company with as little as 1 or as many as 10,000 documents.

Today I read a story that made me think of an unexpected source – the feds completed a comprehensive “stress test” (see WSJ story) and the results of those tests are confidential. In other words, some banks could have been evaluated by the government and to have been evaluated by the government as unable to survive economic uncertainty.

That gets one to wondering, who has access to these reports, who would pay for them and what is the potential risk/damage to every major American bank?  Surely key corporate execs at the bank have the report results; lots of employees probably have some idea; government representatives have them; oh AND every IT staffer with access to the corporate email system.

If I was a departing employee in the IT department and I felt underpaid and under appreciated; if I was angry, resentful and truly motivated to cause harm to the company, that’s exactly how I would do it.

Leave a Reply

Additional articles

smart rules manager for vulnerabilities - v2

A New Way of Looking at Vulnerabilities in Your Environment

Assets, users, vulnerabilities and exploits; all are common themes in my posts on BeyondInsight. With BeyondInsight v5.1, we unveiled a new way to view exploitable assets. Sure, most vulnerability management solutions link vulnerability data to exploit information, allowing tools like NeXpose and QualysGuard to list an asset, its vulnerabilities, and any related exploits. BeyondInsight does…

Post by Morey Haber April 23, 2014
Tags:
, , , , ,
smart rules manager for vulnerabilities

Staying on Top of the Latest Vulnerabilities with BeyondInsight v5.1

It’s no secret that dozens of new OS and application vulnerabilities are revealed every day. Staying on top of these new exposures normally requires paying for services or subscribing to multiple RSS feeds. BeyondInsight 5.1 provides customers with another option: a built-in, customizable vulnerability alerting system that delivers up-to-date information on the latest vulnerabilities in…

Post by Morey Haber April 21, 2014
Tags:
, , , , , ,
BI-Qualys-Connector-IMG1

Getting More Value from QualysGuard Vulnerability Data with BeyondInsight v5.1

If your vulnerability assessment scans can’t produce meaningful and actionable reports, performing a scan does no good for anyone. If you’ve read my other blog posts, you know I have no qualms about stating that BeyondTrust provides the best vulnerability reporting in the industry. Ask your favorite analyst and they’ll tend to agree. Of course,…

Post by Morey Haber April 18, 2014
Tags:
, , , , , , , ,