Days of individual security over, says IIA chief
- 29 March, 2011 16:08
- Comments
People solely relying on patching and upgrades are leading themselves into a false sense of security and individual protection is no longer sufficient in the age of multi-vector attacks, according to the president of the Internet Industry Association of Australia.
Most people rely on operating system and software updates – including security patches – to gain a perception of security, but with increasing sophistication of cyber attacks this single-minded approach is no longer sufficient, according to IIA chief executive Peter Coroneos.
“What is a concern is the capacity of individual users to manage their own security and that time has passed,” Coroneos said.
“Patching and updating software is still necessary but it is not enough.”
Coroneos said vendors need to intervene at the network level and need to provide security tools at a multiple levels to help secure people from the multiple levels of threats that are emerging.
The rise of cloud computing is also adding another dimension to the security problem.
“If you look back 15 years ago we were talking about thin clients and now we are seeing an increase in migrations to the Cloud,” he said.
“However, there are issues with the Cloud, including data protection and security.”
“It reminds me of a Monty Python skit where a building is being held up by trust. It’s only standing up because people are believing it will stand up and Cloud computing is clearly within that frame.”
According to Coroneos, people need to ask if Cloud applications are secure and private and a problem is few client products are applicable in Cloud environments.
“As an industry we need to ensure Cloud services are safe and trustworthy because if it isn’t we are in trouble as a society, not just the IT industry.”
The AIIA has its own iCode initiative for securing online access via ISPs.
“If you turn the clock back 15 years ago ISPs were relying on a tool provided by the ACMA to notify people of an insecure PC,” Coroneos said.
“We codified that and now 90 per cent of local ISPs are participating without any legislation, which is a unique thing around Internet governance. The ISPs see it as a win-win.”
He said it is not in the vendors’ interest to see infected users and good security also lowers the cost of support.
iCode was launched in June went live on December 1 last year.
“Since then we have had enquiries from government and organisations worldwide,” Coroneos said, adding most zombie botnets are not originating in Australia.
TrustDefender co-founder and CEO, Ted Egan, said end-point security and authentication is not enough today as there are more threats emerging around the type of session being initiated by a client.
“We can reach out to a device with an unknown security health,” Egan said.
“One credit union customer has been running end-point security for three years and has already experienced authentication token security.”
TrustDefender conducts it research and development in Sydney Australia. Although the company has yet to get any of the “big four” banks as customers, Egan said it has secured contracts with large financial institutions in Europe.
The AIIA’s Coroneos said consumers need to increasingly adopt a multi-layered approach to security and can’t rely on a single vendor.
“For example, a man-in-the-middle attack can result in a user not knowing if a trojan has used existing authentication to transfer funds from an account,” he said.
Coroneos said as criminals find it more difficult to target tier-1 financial insitutions they will look to smaller, tier-2 companies.
Follow Rodney Gedda on Twitter: @rodneygedda
Follow CIO Australia on Twitter: @CIO_Australia
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Top 5 Myths of Safe Web Browsing
- There is a HP Printer for everyone
- Businesses are ready for a new approach to IT - Simplify deployment and reduce complexity using systems integrated with expertise
- Best Practices for Secure Enterprise Content Mobility
- Stopping Fake Antivirus: How to Keep Scareware off Your Network
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Monday Grok: Will Siri crack the walls of GOOG?
-
Face Time - Interview with John Brennan and Robert DiStefano
-
ALM Buyers Guide: A Practical Guide to Choosing the Right Agile Tools for your Team
This buyer's guide describes the key criteria for application lifecycle management (ALM) solutions for today's high-performance teams. It includes key considerations for enhancing your single- or multi-vendor ALM environment. -
Business Process Management, Service-Oriented Architecture, and Web 2.0: Business Transformation or Train Wreck?
As a result of more and more organisations adopting new technologies and business practices surrounding BPM, SOA, and Web 2.0, fundamental changes have arisen in the way IT and business stakeholders work together. Make this into an opportunity - read on. -
Transforming Your Business by Transforming Your Processes
In this white paper, we build on the “Intelligent Guide to Enterprise BPM: V olume One” in which we described the three entry points where you can begin to build true Enterprise BPM. In this white paper we explain the value of Process T ransformation, the entry point to strategy and design. Successful implementation of Process T ransformation will mean you have successfully documented, standardized, harmonized, managed—as well as analyzed and improved—your business processes. T he next two white papers will detail the other two entry points: Process Automation and Process Intelligence.
-
Cics
-
Google Sketchup and Sketchup Pro 7 Bible
-
Microsoft Works 2000 for Dummies Quick Reference
-
Accredited Symbian Developer Primer - Fundamentals of Symbian OS
-
Storage Area Networks for Dummies
-
Cryptography for Dummies
-
Director 8 and Lingo Bible
-
Mastering Active Directory for Windows Server 2008
-
Excel 2007 Data Analysis for Dummies








Comments
Post new comment