Markets
SecurityInfoWatch




IT Asset & Technology Centers

Updated: April 30th, 2008 10:24 AM PDT

Hacker school: Beating the hackers starts with knowing what you're up against

Ethical hacker shares ideas on proactive data security

The Latest from SIW

Transformed by terrorism at the ’72 Munich Olympics Former U.S. Olympian and Congressman Thomas McMillen discusses his Olympic security experiences NAPCO acquires Marks USA Deal expected to bolster product line, revenues Federal judge: No guns at Atlanta airport The security week that was: 08/15/08 Chertoff stresses IEDs as DHS unveils grants McAfee completes purchase of Reconnex
VarBusiness
via NewsEdge Corporation

Larry Detar has a job that tech-loving kids only dream of having when they grow up. As the vice president of global services for a company called EC-Council, Albuquerque, N.M., he hacks into networks for a living.

As a Certified Ethical Hacker, Detar conducts vulnerability assessments and penetration tests for financial institutions, government agencies and corporations. He executes code to infiltrate systems. He enters data centers pretending to be a member of the IT staff. He even digs through dumpsters to get to find whatever Achilles' heel exists in a seemingly impenetrable business.

And never once in the last five years since Detar's association with EC-Council did he fail to get at a company's sensitive data.

"That's the state of security," Detar said. "The majority of those access points are open to the 9-to-5ers. Not only the passwords to get into the computer, but the core application that controls the financials for that institution. They have access to everything that's not locked up."

Over the years, Detar has seen some security breaches that would make a TJX executive cringe. The simple fact, however, is that many security holes are avoidable.

While there is to date no security solution that is completely hackproof, Detar and fellow security experts agree that there are definitely some tried-and-true strategies that, when applied, will significantly reduce the odds that hackers will pick your business for their next attack.

1. Training, Training, Training

You can't get enough. Most experts agree that the security of an organization is as good as its weakest link-which is why they emphasize that training and awareness should be implemented at every level.

1 2 3 4 5 6 next


More From IT Asset & Technology Centers




SIW eNews

FrontLine

Markets & Sys

PracticeReport

AppReport

ProductWatch

EventWatch

Weekly Recap

EndUser Blasts

Dealer Blasts