While it’s still true that hackers who are bent on gaining access to internal networks are a menace, IT managers have also discovered that another type of hacker – the ethical hacker – is an indispensable force in their fight against this darker side of hacking.
It’s a dangerous world out there – especially for IT organizations charged with protecting valuable data from would-be cyberthieves and vandals. During a less complicated time in IT’s history, internal networks were simply walled-off from the outside world – serving communications needs among employees, but rarely beyond. But today’s enterprises can no longer isolate their networks from the outside world; e-commerce, supply chains, mobile computing and many other requirements of business in the 21st century simply won’t allow it to happen. The only path that security managers can realistically follow now is to harden their networks, applications, and operating systems as best they can, accept that there will always be some level of risk, and go on conducting business.
What do you think?
Discuss ethical hacking in our forum
Back then, the term “hacker” first referred to knowledgeable and highly motivated geeks who were pushing computing forward. As personal computing spread, though, the term started to be applied to people who used their knowledge more mischievously. Within just a few years, “hacker” came represent a threatening entity determined to use his (or her – though not often) knowledge to do harm to your networks, systems, and data. The admirable hacker became the sinister hacker, and hacking became something to fear.
But not so fast. While it’s still true that hackers who are bent on gaining access to internal networks are a menace, IT managers have also discovered that another type of hacker – the ethical hacker – is an indispensable force in their fight against this darker side of hacking.
Ethical hacks, sometimes called penetration tests, are simulations of real attacks on networks, systems, and applications. These simulations are designed to identify vulnerabilities in IT infrastructures in order to truly understand the effectiveness of current security controls. In fact, trying to measure a network’s security without conducting an ethical hack is like trying to determine seaworthiness of a newly built boat without putting it in the water.
How important is an ethical hack in the IT manager’s repertoire? In a recent survey of 202 IT professionals conducted by INS, only 8% of respondents said that there is no chance of their network being successfully hacked in the coming year. Though many tools on the market can help repel (or, worst case, recover from) these likely attacks, none is as powerful and effective as an ethical hack, which identifies points of vulnerability before the attacker finds them, enabling remediation before the fact, not during or after. Surprisingly, more than one-third of survey respondents either never conduct ethical hacks on their networks, or do so less than once a year. Why? The usual obstacle is lack of management support, although other factors, such as potential embarrassment from the findings, also enter the equation.
Ethical hacks are best conducted by independent third parties, which can use their objectivity to more closely simulate the likely actions of a real attacker. Also, because their bread and butter is dependent on current threats, third parties are fully up to speed on all the tools and techniques that an attacker might employ. Part-time ethical hackers simply cannot match the thoroughness of a dedicated professional. Furthermore, a moderately skilled employee trying to break into the network could unintentionally cause as much damage as a real attacker. A full-time ethical hacker is much less likely to cause disruptions or damage systems.
A thorough ethical hack doesn’t just look at the portions of the network accessible from the Internet. Many other aspects of the IT infrastructure also need to be tested, including internal networks, virtual private networks, wireless networks, and Web applications. And searching for unauthorized modems is still important in order to pinpoint all potential weak spots in the network.
INS’s survey also discovered that internal networks are most likely to be insecure. Ethical hacks on respondents’ internal networks revealed that 25 percent have serious vulnerabilities, and another 42 percent having some vulnerabilities with moderate impact. Wireless networks, web applications, and Internet-accessible are in somewhat – but not much – better shape than internal networks..
The value of ethical hacks extends beyond just identifying vulnerabilities. Regular comprehensive ethical hacks can also help enterprises comply with regulatory mandates, such as the Sarbanes-Oxley Act, protect against lawsuits, and validate security investments. This latter benefit is particularly important as it can help justify the cost of an ethical hack to corporate management.
Ethical hacking is not a panacea that will solve all security problems, but it is a critical tool to employ in the never-ending effort to secure your company’s assets from a dangerous world. And who knows, it may even start to swing the prevailing view of a hacker back from malevolent to benevolent.
Rick Blum is Senior Manager, Strategic Marketing at INS, a provider of IT infrastructure consulting services, including ethical hacking, based in Santa Clara, CA.




