Social engineering, big data top security priorities for 2013: Gartner
- 09 November, 2012 12:01
Gartner Australia research director Rob McMillan.
The technique of using deception and manipulation to gain sufficient knowledge to dupe an unwary individual, employee or company into revealing personal information has the potential to be one of the biggest security threats in 2013 according to a security expert.
Gartner Australia research director, Rob McMillan, who is due to speak at the analyst firm’s annual Symposium on the Gold Coast next week, told Computerworld Australia that social engineering has emerged over the last four years as a growing threat, especially for non-IT professionals who do not understand the techniques used by scammers.
For example, the long running Windows Event Viewer scam involves telemarketers calling people, telling them they have a virus and requesting the recipient's authority to run a Windows program called Event Viewer in order to fix ‘so-called’ bugs in the operating system. Other callers claim they can remove the virus for a fee and ask for people's credit card details.
According to research from Sophos, scammers have called people posing as a member of their company’s IT department and named the person’s boss in order to gain their trust.
“If you want to break into an organisation you would research that organisation and identify a few individuals that you want to target, than research them,” McMillan said. “The reason why this is important is the need for stronger education and depth of understanding for non-security professionals who have access to important resources.”
Turning to the subject of how businesses protect customer data with the need to increase revenue, he said that big data should be factored into security measures.
“The thing about big data is that it is harder to get the value out of your information and to protect everything when this mass of information becomes large in volume and deep in complexity,” he said.
“It’s like your bedroom or garage — if you walk in the place and there is stuff strewn everywhere it does get more difficult to find things eventually.”
According to McMillian, IT executives need to understand where the data resides, what the data means and organising it correctly so they can extract value out of the data.
“More importantly from a security perspective you need to know how to protect it,” he said.
“If you think about payment card industry [PCI] compliance, you’ve got obligations to protect any of the data that falls under that regime,” he said.
He added that PCI compliance will be much easier if the organisation can confine all of the credit card information in a restricted area such as a couple of secure databases.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Backup and Recovery Changes Drive IT Infrastructure and Business Transformation
- Big Data Computerworld Strategy Guide
- Big Data is talking. Are you listening?
- Can Your Business Intelligence Environment Handle Data Growth?
- Best Practices for Implementing a Data Warehouse on the Oracle Exadata Database Machine
Why change management doesn’t work
Larry Page wants to see your medical records
Dual-Persona Smartphones Not a BYOD Panacea
After two-year hiatus, EFF accepts bitcoin donations again
CIOs struggle to deliver timely mobile business apps: survey
Tolly Report: Performance Survey of Virtual Environment Security
This report by Tolly tests the system resource requirements of competing vendor solutions when performing on-demand and on-access scanning functions, during distributed definition updates. Click to download how the four competing options ranked against each other.
A Holistic Approach to your BYOD Challenge
More and more enterprises are seeing significant benefits from allowing employees to choose the device they use to get their jobs done, and are adopting bring your own device (BYOD) initiatives. While the BYOD trend increases flexibility and productivity, it introduces a host of new challenges for your IT administrators. Click for more!
Getting Real About Security Management and Big Data – A Roadmap for Big Data in Security Analytics
It’s an exciting yet daunting time to be a security professional. Security threats are becoming more aggressive and voracious. This whitepaper examines the escalating complexity for the security management environment; how to get more meaning from data already collected and the combination of infrastructure, analytic tools and threat intelligence need to drive business value from Big Data. Download now.