BeyondTrust

Security In Context

Bringing you news and commentary on solutions and strategies for protecting your critical IT infrastructure.

Security from Data Breaches Start from Within

Post by Peter McCalister March 22, 2012

Keeping the bad guys out is what comes to mind for a lot of us when we think of securing our companies’ IT environment. And to be honest, this mindsit might very well be the reason we hear about so many data breaches. Companies are getting hit with breach and breach of sensitive information despite the best firewall systems and anti-malware software available. And the reason? The security focus is not in the right place. While keeping intruders out is important, keeping the liabilities and risks (read: people) inside your company at bay is far more critical. It’s no wonder breaches and leaks are still occuring- unmonitored and unmanaged users are running around our organizations with access to sensitive information. If you haven’t already started examining how to keep your information safe from the inside out, it’s time to make it a priority.

According to Mark Diodatti of Gartner, “organizations continue to struggle with excessive user privilege as it remains the primary attack point for data breaches and unauthorized transactions.” It would make sense, then, to allocate appropriate budget and resources to projects surrounding the primary attack point. Technologies like Anti-virus, firewalls, intrustion detection and prevention, email security, and web security are obviously important. Billions of dollars are spent each year in security budget to secure the outside perimeter from hostile intent…and I’m not saying that’s a bad thing. It just seems to me that more focus should be allocated to the primary point of attack. With the majority of organizations still struggling with excessive user privileges, it’s clear priorities aren’t jiving with needs.

Now, more than ever, there is a strong need to evaluate the security inside our environments. Ensuring privilege identity management as well as data security and leak prevention are becoming corporate “need-to-haves” in order to prevent the insider threat from effecting your organization. Click here to learn how to get started.

Leave a Reply

Additional articles

smart rules manager for vulnerabilities

Staying on Top of the Latest Vulnerabilities with BeyondInsight v5.1

It’s no secret that dozens of new OS and application vulnerabilities are revealed every day. Staying on top of these new exposures normally requires paying for services or subscribing to multiple RSS feeds. BeyondInsight 5.1 provides customers with another option: a built-in, customizable vulnerability alerting system that delivers up-to-date information on the latest vulnerabilities in…

Post by Morey Haber April 21, 2014
Tags:
, , , , , ,
BI-Qualys-Connector-IMG1

Getting More Value from QualysGuard Vulnerability Data with BeyondInsight v5.1

If your vulnerability assessment scans can’t produce meaningful and actionable reports, performing a scan does no good for anyone. If you’ve read my other blog posts, you know I have no qualms about stating that BeyondTrust provides the best vulnerability reporting in the industry. Ask your favorite analyst and they’ll tend to agree. Of course,…

Post by Morey Haber April 18, 2014
Tags:
, , , , , , , ,
insider-threat-fed

Mitigating Inside Threats to U.S. Federal IT Environments

Recent high-profile cases have increased the perceived risks that go along with disclosure and usage of confidential information. One of the most difficult security threats to mitigate is an attack from the inside. When an over-privileged user, such as an unhappy current or former employee, contractor, or consultant, begins navigating your network, how will you…

Post by BeyondTrust Software April 17, 2014
Tags:
, , , , ,