BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Mozilla Breach and Privileged Users

Posted January 11, 2011    Peter McCalister

If you have one of 44,000 inactive Mozilla accounts, you may have received a belated Christmas present on December 27th when the company sent out notifications of a potential leak of their account information. In this case the company was able to reassure those users there was virtually no possibility of any harm to them.

accidental misuse of privilegeHowever what’s interesting about the incident is I can only presume it ties back to a very specific administrator who on a very specific day and time made a mistake and put the database on the wrong server. Something we see with surprising frequency.

Now put yourself in Mozilla’s shoes. If this happened to you, would you know which IT staff was responsible? What would you tell the CEO? Would a witch hunt ensue and how would that impact the department?

The incident highlights once more that the IT staff can and do make terrible mistakes that can cost millions in breaches, notifications and more. Because IT staff have such deep access to the IT systems themselves, a single logistical mistake can have deep security implications.

The incident highlights why organizations need processes and systems in place that account for the very real possibility of errors by IT staff. In other words, you need to monitor and record the actions of individual administrators and remove blanket root access.

This not only creates accountability for individual staff to not make a mistake in the first place, but avoids the witch hunt when it happens. Employees need to know that if they make mistakes, the company will know it was them.

]]>

Leave a Reply

Additional articles

CyberResiliency

6 things I like about Gartner’s Cyber Resiliency Strategy

Posted August 27, 2015    Nigel Hedges

There were 6 key principles, or recommendations, that Gartner suggested were important drivers towards a great cyber resiliency posture. I commented more than once during the conference that many of these things were not new. They are all important recommendations that are best when placed together and given to senior management and the board – a critical element of organisations that desperately need to “get it”.

Tags:
,
powerbroker-difference-1

Why Customers Choose PowerBroker: Flexible Deployment Options

Posted August 26, 2015    Scott Lang

BeyondTrust commissioned a study of our customer base in early 2015 to determine how we are different from other alternatives in the market. What we learned was that there were six key differentiators that separate BeyondTrust from other solution providers in the market. We call it the PowerBroker difference,

Tags:
, ,
Mac-Security-Enterprise

On Demand Webinar: Security Risk of Mac OS X in the Enterprise

Posted August 20, 2015    BeyondTrust Software

In the last several years, Mac administrators have come to realize that they may be just as vulnerable to exploits and malware as most other operating systems. New malware and adware is released all the time, and there have been serious vulnerabilities patched by Apple in the past several years, some of which may afford attackers full control of your systems.

Tags:
, ,