* EMA's disappointing response from its service provider after a hacking invasion
“I’m sorry sir, but Abuse does not work on weekends. You will need to call us back on Monday in order to follow up this hack of your Web site, and it will typically take up to 24 hours for us to complete our forensic analysis to try to determine how you got hacked.”
Except for the fact that it actually took nearly 48 hours for our Web hosting supplier to complete its analysis, not 24, this was essentially the automated response we received from the provider’s help desk earlier this month when we discovered that one of our Web sites had been hacked. Without naming names, this company is one of the largest service providers, with thousands of customers and a worldwide presence. This brought up a few issues that we would like to bring to the attention of Web hosting service providers and consumers.
The fact that we were hacked was not surprising, especially since we had been hacked a few months before and our service provider told us that it was due to a bug in a CGI script that’s part of our online discussion board software. We certainly do not blame our service provider for the fact that we were hacked.
The problems occurred when our service provider informed us that its “abuse” department (is that the customer abuse department?) does not work weekends, and when it did get on the job, it took two days to complete its investigation. Meanwhile, because altering any site content would have interfered with the provider’s forensic investigation, we couldn’t touch any of our files, which meant that we had to let the site remain defaced.
It seems to us that service providers need to be doing more in this area. First, the amount of time that passes between being hacked and getting the Web site back up should be measured in hours not days, particularly when it seems to us that the forensic analysis process was limited to taking a copy of the documents and files stored on the service provider’s Web server (at least from our perspective). Second, our service provider had no idea that we had been hacked – the only reason that we found out was because we use a third-party monitor from AlertSite (http://www.alertsite.com) that notifies us when there is a content change on the site. Third, although this service provider does provide a security service package, when asked for details, our service provider admitted that this package does not include vulnerability monitoring for its customers, regardless of the tier of service or willingness to pay for said services.
But there are other companies that do provide just that. ScanAlert, for example, offers a Web site security monitoring service that evaluates vulnerabilities based on scenarios from hack simulation to a more aggressive denial-of-service. Evaluation can be automated, and discovered vulnerabilities can be specifically retested to evaluate remediation. Sites that are consistent with ScanAlert’s security standards are permitted to display its “HACKER SAFE” logo. This is becoming a valuable branding that customers are increasingly associating with site security, as evidenced by ScanAlert’s growing customer list – and even recognition by insurers. The acknowledgment of the tangible reduction of risk offered by effective measures is a highly cherished goal of security management. ScanAlert has achieved this recognition in coverage being offered to ScanAlert customers in Japan through the AIU Japan division of the American International Group (AIG).
We think that just about every Web service provider should offer these types of services, either through partnerships with companies such as ScanAlert or by developing their own technology – and not just because of poor customer service. Web service providers should be doing a much better job of helping their customers to know when their Web site has a problem, followed by helping them get back online as quickly as possible. This is particularly true for Web service providers, since many customers that take advantage of Web hosting do so because they do not have the resources or technical ability to do it themselves.
Web hosting providers are still not aware of the very real liabilities they face in an increasingly regulated and litigious environment. As an example, major credit card companies are becoming increasingly aggressive with banks that fail to curb fraud risk. Banks, in turn, pass their risk management along to businesses by “pulling the plug” on their precious credit operations. It is only a matter of time before a major liability (and public relations) issue threatens a Web service provider.
Moreover, the regulatory climate is becoming increasingly aggressive as well. California Senate Bill 1386, for example, requires any business to make public any security breach in which the personal information of California residents may have been exploited. Though limited to California in scope, this statute effectively impacts virtually any business. Regardless of contractual relationships between Web hosting providers and their customers, consequences can be expected to come their way to service providers, should such an incident have a significant impact on a customer’s business. You can expect relationships and agreements such as security-based service-level agreements to begin appearing that address these issues.
For now, we’d welcome a more proactive, considerate response from Web hosting providers that treat a security breach as if it were someone else’s problem.
We welcome your ideas, suggestions and comments on the subjects of outsourcing and information security; our e-mail addresses are below. Thanks for reading.




