Fortunately, there are steps you can take to protect your company in the meantime.
BEST PRACTICES:
1. Publish your mail server addresses. Some vendors have already begun incorporating Sender ID into their products, so companies should make sure they record the IP addresses of their outbound mail servers with their ISP or domain name registrar. Companies already register their domain names and corresponding IP addresses so they can receive mail. Rounding up the IP addresses of all servers authorized to send mail on behalf of the company is a relatively simple step. Taking it will ensure that anyone using sender authentication can reject e-mails that attempt to spoof your company.
2. Educate customers. People who know about phishing stand a better chance of resisting a phisher's hook. "While you're waiting for the technology, the best defence is that a consumer has heard of phishing," says Patricia Poss, an attorney with the Bureau of Consumer Protection at the US Federal Trade Commission. "They're going to think twice" about replying to any e-mail or pop-up that requests personal information.
Warn your customers about the dangers of phishing; let them know you'll never ask for their account number, password, Tax ID number or any other personal information via e-mail. Encourage them to avoid clicking on e-mail links to reach you; they should instead type your company's URL directly into a new browser window.
PayPal interrupts its own log-in screens periodically with a phishing warning. "Users have to click through [the warning] to get to the main screen," Miller says. A Security Centre on PayPal's site includes an e-commerce safety guide, fraud protection tips for buyers and sellers, a link to let users report spoof e-mails, and a prominent reminder to log into PayPal by opening a new browser window and typing in the URL.
A target of phishers since early 2003, EarthLink also focuses its efforts on increasing customer awareness, says Linda Beck, executive vice president of operations for the ISP. In addition to creating customer education pieces, EarthLink developed its own ScamBlocker toolbar, which it offers free to anyone on its Web site. ScamBlocker relies on a blacklist of known phisher sites to warn users when they attempt to access a site on that list. (In fact, EarthLink shares blacklist data with eBay, which has its own antifraud toolbar.) EarthLink's education efforts and its investment in developing ScamBlocker appear to be paying off. Although it once got 40,000 calls per attack, EarthLink's call centre now fields from 10,000 to 12,000 phisher-related calls per month. As a result, the cost per attack has fallen from a peak of $US115,000 to a little more than $US40,000.
Companies can also point customers to a free browser extension known as SpoofStick, which can be downloaded at www.corestreet.com/spoofstick. SpoofStick helps users detect a spoof; visiting a spoofed eBay site, for example, brings up a toolbar message along the lines of "You're on 10.19.32.4" instead of "You're on eBay.com".
3. Establish online communication protocols. Now that phishing has become a fact of life, companies need to be careful about how they use e-mail to communicate with customers. In May, Wachovia's phones started ringing off the hook after the bank sent customers an e-mail instructing them to update their online banking user names and passwords by clicking on a link. Although the e-mail was legitimate (the bank had to migrate customers to a new system following a merger), a quarter of the recipients questioned it. Frankly, Wachovia should have known better.
As Wachovia discovered, companies need to think through clearly their customer communication protocols. For example: All e-mails and Web pages should have a consistent look and feel, all e-mails should greet customers by first and last name, and a company shouldn't ask for personal or account data viae-mail. If any time-sensitive personal information is sent through e-mail, it has to be encrypted. Although e-mail marketers may wring their hands at the prospect of not sending customers links that would take them directly to targeted offers, instructing customers to bookmark key pages or linking to special offers from the home page would be a lot more secure.
It also makes sense to revisit what customers are allowed to do on your Web site. They should not be able to open a new account, sign up for a credit card or change their address online with just a password. Although stronger authentication is ideal (see number 6), at minimum companies should acknowledge every online transaction through e-mail and one other method of the customer's choosing (such as calling the phone number on record) so that customers are aware of all online activity on their accounts. And to prevent phishers from copying your online data capture forms, don't put them on your Web site for all to see. Instead, require secured log-in to access e-commerce forms.
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Email Archiving 101—Customer Case Study
Business Intelligence and Enterprise Performance Management: Trends for Emerging Businesses
Radicati Market Quadrant 2008 on Corporate Web Security
Gaining Competitive Advantage Through Enterprise Planning
Achieving the impossible: Unlimited application scalability
Enterprise Wireless WLAN Security
Security Inside Out
Taking On Demand CRM Integration to the Next Level
- White PaperJoin Lee Benjamin, a Microsoft Exchange MVP and Ryan Shipkowski, network administrator for Matthews, to discuss the process and ROI of implementing an email archiving solution, with emphasis on a case study from Matthews International.
- White PaperYour organisation may well have devised and implemented an Acceptable Use Policy (AUP) some time ago in order to guard against the risks of inappropriate use of computer systems by your workers, but are you confident that your AUP remains 'fit for purpose'? Read on to discover how you can enhance the effectiveness of your AUP.
- White PaperView this webcast and discover the drivers for changing network design practices, why many organisations are changing their approach to network architecture and how enterprises should be moving forward with open architecture multi-vendor network solutions. Register now and learn how your business can maximize the business value of the enterprise network.
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25
For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders. - +
CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00
Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00
Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance. - +
CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05
Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
- +
Chris Hoff on Virtualization and Cloud Computing 20 November, 2008 10:55:00
Chris Hoff, chief security architect for the systems and technology division at Unisys and an advisor on the Skybox Security customer advisory board, is one of the biggest critics of virtualization security out there. Not because it isn't important - but rather because it is vital and needs to mature rapidly. - +
Cybersecurity is focus of new start-up incubator 20 November, 2008 07:19:00
Texas uni announces the Institute for Cyber Security.The University of Texas at San Antonio Tuesday announced a technology incubator aimed at fostering IT security-based start-ups within the state. - +
Dilip Sarangan on Physical Security M&A 20 November, 2008 11:18:00
Dilip Sarangan tracks physical security companies for Frost & Sullivan. He expects the industry's "need to have" products to weather the economic storm well, with the big players (now including IBM and Cisco) looking for value-priced acquisitions. - +
International Challenges in PCI Security 20 November, 2008 09:15:00
In a country that's seen many regulatory compliance challenges this decade, the headaches of PCI security tend to be analyzed from a largely American perspective. - +
PCI council sharpens oversight of security auditors 19 November, 2008 10:53:00
Quality assurance plan targets security assessors and scanning vendorsThe PCI Security Standards Council Monday unveiled a plan to sharpen oversight of the hundreds of security-service providers now authorized to evaluate merchant networks under the organization's Payment Card Industry data standards.
Vignette Announces 2008 Excellence Awards 21 November, 2008 10:50:00
PGP and Ponemon Institute Unveil Inaugural Australian Data Breach Study 2008 20 November, 2008 17:34:00
Symantec Cloud Services Transform Data Centre Operations Through Proactive Management 20 November, 2008 12:06:00
Verizon Business Offers Tips to Building a Successful Unified Communications and Collaboration Plan 20 November, 2008 12:04:00
AARNet Brings 4K Digital Cinema to Australia: First 4K HD Video Signal delivered into Australia by AARNet 20 November, 2008 12:02:00
|
||
|
||
|
|
||
|
Choices in Storage Architecture for Oracle Environments
Database systems have always been at the core of the IT landscape. Not only is storage an increasingly large cost component of database investments, but storage architecture can significantly and directly impact the performance, availability, and recovery of data. Read on to explore the interaction between Oracle databases and EMC and Network Appliance storage architectures.














