HomeinetSymantec: New hacking tactics Security tips for businesses and users

Symantec: New hacking tactics Security tips for businesses and users

According to the conclusions of the Symantec Internet Security Threat Report, cybercriminals are changing tactics and acting quickly and methodically!Symantec Security Threat Map

Symantec Security Tips for Businesses and End Users

In today’s hyper-connected world, it’s no longer a question of if someone will attack your data, but when. According to the recent Symantec (Nasdaq: SYMC) Internet Security Threat Report (ISTR), Vol. 20, cybercriminals have changed their tactics, penetrating networks and then valuable data, skillfully avoiding detection by breaching the infrastructure and using that infrastructure to their advantage.

The most advanced cybercriminals continue to breach networks with spear-phishing attacks, which increased by 8% in 2014. The accuracy of these attacks is remarkable, using 20% ​​fewer emails to successfully penetrate target organizations and incorporating more drive-by malware downloads and other web-based exploits.

Last year, 60% of all targeted attacks targeted small and medium-sized businesses. These businesses typically invest fewer resources in security and many continue to fail to adopt basic security practices, such as blocking executable files and screen saver attachments in emails, increasing the risk to both themselves and their partners.

Malicious attacks are multiple and complex. The most common are those that compromise users' e-mail. With simple text messages for Password recovery, an intrusion is achieved through social engineering.

Some of the most effective scams are often very simple and believable in their execution. Someone "impersonates" a police officer, or an authority, for example, and asks the average user to confirm passwords, which the user of course most of the time confirms.

This type of fraud is based on two things: Its simplicity and the fact that the vast majority of people trust their data to the Authority that requests it from them, especially if it is credible.

Security and cybercrime researchers have also begun to pay more attention to the cloud, as much more data is now moving from traditional computing systems to this new environment.

The amount of data and other resources stored in the cloud is set to grow further, as IT decision makers plan to significantly increase their spending on cloud computing in 2015. As with any system, every time a new layer is introduced to a service stack, the potential for attacks increases. While cloud environments can suffer from common vulnerabilities, such as SQL injection flaws, they can also be affected by additional security issues, such as insecure interface APIs, shared resources, data breaches, malicious users, and misconfiguration issues.

A third point that deserves attention in security matters is the fact that companies today, at regular intervals, lose valuable intellectual property.

While many security initiatives have focused on the threats posed by cybercriminals and hackers, there is also a less obvious factor in the theft of corporate assets, and that is none other than employees.

In most cases, companies trust employees to move, exchange, and expose sensitive data in order to do their daily work.

However, there are also cases of employees who deliberately obtain confidential information in order, for example, to use it on their next employer, without realizing that they are exposing themselves and the companies they work for or will work for to risk, since valuable data may end up in dangerous "hands".

Therefore, the proper management of corporate and personal data, through security systems that are protected multiple times, prevents potential risks of attack.

Symantec Business Advice:

• Using advanced security solutions helps businesses find threats and respond faster to malicious incidents.
• Implementing a multi-layered endpoint protection solution, network security, encryption, strong authentication, and reputation-based technologies secures valuable data.
• Prevention is always better, so they should be prepared for the worst. The proactive management of a malicious incident ensures the security framework and must enable optimization as well as measurable and verifiable results for all events that were collected.
• Providing ongoing education and training, as well as defining directions and policies for the company and procedures for protecting sensitive data on personal and corporate devices.
Tips for end users:
• Using strong passwords: The stronger and more unique a password is on accounts and devices, the more difficult it is to breach. It is also important to change it at regular intervals, ideally every three months. Finally, we never use the same password on different accounts.
• Be careful on social media: We do not click on links and e-mails that we do not know and on messages from unknown sources. Fraudsters know well that most users are more likely to click on links from friends and thus create corresponding accounts in order to put users at risk and send malicious links to the account holder's contacts.
• What is published in common "view": When installing a device that is connected to the network, e.g. a router, or downloading a new app, the terms must always be reviewed so that we know where which data is stored. We disable remote access when not needed.

https://www.youtube.com/watch?v=x5R34SXnRpk

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS