BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Just One Open Server Is Enough For Misuse Of Privilege

Posted January 30, 2012    Peter McCalister

Gambling on the odds may be fine for a weekend in Las Vegas, but do you really want to take that same risk with your precious corporate information assets? Zappos learned the hard way what happens when even one server is at risk from a security perspective.

A recent Dark Reading articled entitled “Zappos Dealing With Data Breach” reported on the recent need for the online shoe and clothing retailer (owned by Amazon) to email its 24 million customers with a notification of an internal breach. The article goes on to quote Zappos CEO, Tony Hsieh: “We were recently the victim of a cyberattack by a criminal who gained access to parts of our internal network and systems through one of our servers in Kentucky. We are cooperating with law enforcement to undergo an exhaustive investigation.”

I recently read Mr. Hsieh’s excellent book Delivering Happines and was thoroughly impressed with his attention to corporate culture and customer service. His 10 core values can be an inspiration for every company looking to differentiate itself in this hyper-competitive global economy. The challenge that needs to be highlighted in this story is that all it ever takes in a single server with full admin rights available for someone to abuse that privilege and gain unauthorized access to sensitive information.

Implementing a least privilege solution across every server (physical, virtual and cloud-based) is a great first step in preventing this type of embarrassment from happening to you.

Leave a Reply

Additional articles

webinar_ondemand

On Demand Webinar – Why You Still Suck at Patching

Posted March 27, 2015    Lindsay Marsh

On Demand Webinar: Dave Shackleford recounts some of his personal experiences in patch management failure, and breaks down the most critical issues holding many teams back from patching more effectively.

Tags:
,
dave-shackleford-headshot

Why You Still Suck at Patching…and How to Turn Your Life Around

Posted March 25, 2015    Dave Shackleford

Live webinar | March 26, 2015 | 10am PT/1pm ET | Dave Shackleford, SANS Instructor | Why You Still Suck at Patching…and How to Turn Your Life Around

Tags:
, ,
infographic

Privilege Gone Wild 2: Over 25% of Organizations Have No Privileged Access Controls

Posted March 24, 2015    Scott Lang

BeyondTrust recently conducted a survey, with over 700 respondents, to explore how organizations view the risk of misuse from privileged account misuse, as well as trends in addressing and mitigating those risks.

Tags:
,