Each year several vendors and organizations publish updates on the state of the art in security threats. Most of these updates could be entitled “Be nervous, be very very nervous.” While it is never fun to read these reports, they do provide helpful insight into vulnerabilities that we should be aware of. With that in mind, we will use this newsletter to highlight some of the findings of a recent IBM report on security threats.
Quiz: Do you know IT security?
The report is entitled X-Force 2010 Trend and Risk Report and IBM published it in March of this year. The report documents a 27% increase in security vulnerabilities in 2010 vs. 2009 and stated that “This data points to an expanding threat landscape in which sophisticated attacks are being launched against increasingly complex computing environments.” That comment highlights a simple, well-known fact of life in IT. That fact is that the more complex an environment, the more difficult it is to manage, optimize and secure that environment. Unfortunately, while the use of mobile workers and the adoption of cloud computing add great value, they also add significant complexity. In recognition of that fact, the IBM report dedicated a new section to the security trends and best practices that are associated with mobile devices and cloud computing.
We have written before about our concern that the nature of hacking was changing. It used to be that for the most part hackers were loners who were attracted to hacking by the desire to read about themselves in the trade press. In many cases, these hackers were not that technically sophisticated but were good at techniques such as dumpster diving.
While this class of hacker still exists, the last year or so has seen the emergence of much more sophisticated hackers including organized crime and rogue nations. The IBM report validated our concerns about the shifting nature of hacking and the risk to networks when it stated that, “2010 is most remembered as a year marked by some of the most high profile, targeted attacks that the industry has ever witnessed. For example, the Stuxnet worm demonstrated that the risk of attacks against highly specialized industrial control systems is not just theoretical. These types of attacks are indicative of the high level of organization and funding behind computer espionage and sabotage that continues to threaten a widening variety of public and private networks.”
Part of the irony here is that today one of the reasons that many IT organizations don’t make extensive use of public cloud computing solutions is the concerns that they have over security. That said, one of the great promises of cloud computing is that over time, solutions from public cloud providers will enable better overall security and will help companies fight off increasingly sophisticated attacks from both run of the mill hackers and sophisticated organizations.




