New survey raises serious concerns about the effectiveness of disaster recovery plans

Although almost all UK companies back up their critical IT systems and data, more than a quarter of them still do not have a disaster recovery plan in place. Half of those that do have plans, fail to test them. Also, 15% of companies do not take their backups off-site. This is despite the fact that 92% of businesses now consider disaster recovery planning an important driver of their IT expenditure.

These are among the early findings of the 2008 Information Security Breaches Survey (ISBS) carried out by a consortium, led by PricewaterhouseCoopers LLP, on behalf of the Department for Business, Enterprise & Regulatory Reform (BERR). The full results of the survey will be launched at Infosecurity Europe in London, 22-24 April www.infosec.co.uk.

The survey shows that 58% of UK businesses would suffer significant business disruption if their IT systems were not available for a day – the highest figure recorded since the surveys began. This rises to 70% of large companies.

Some 68% of companies polled believe that business continuity in a disaster situation is a very important driver of their information security expenditure, and a further 24% say it is important. Only 2% say it is not very important.

As a result, UK businesses appear better protected than ever:

  • 99% of UK companies back up their critical systems and data. 86% do this at least on a daily basis.

  • 85% of all UK companies take their backups off-site (up from 76% two years ago); 91% of large businesses take their backups off-site.

  • 72% of all UK businesses have a disaster recovery plan in place, up from 58% two years ago. 91% of large companies have a disaster recovery plan.

However, there are concerns about the effectiveness of these controls:

  • 28% of companies do not have a disaster recovery plan in place.

  • Almost half of the disaster recovery plans have not been tested in the last year.

  • 10% of companies with a disaster recovery plan do not store backups off-site.

  • When companies suffered a systems failure or data corruption incident, 31% had no contingency plan in place and a further 10% found their contingency plan to be ineffective.

The south-west has now overtaken London as the region with the most disaster recovery plans in place (possibly as a result of last year’s floods), but fewer of these plans are tested than in other regions.

Chris Potter, partner, PricewaterhouseCoopers LLP, who led the survey commented:

It is encouraging to see that almost every UK business makes backups and the vast majority now take these backups off-site. The risks are well understood; it does not take an incident to raise awareness.

“The number of companies with a disaster recovery plan has gone up. However, experience shows that plans are only effective if regularly tested. It is a concern that only half of plans have been tested in the last year.”

Martin Sadler, Director of HP’s Systems Security Lab at HP Labs Bristol, one of the consortium members responsible for the survey, added:

“There has been an explosion of information within businesses. Acquiring, analysing and delivering the right information to people so they can act on it is a major challenge for companies. The volume of data, and companies’ dependence on it, pose significant backup challenges for them.

“Increasingly, businesses need to back up their data more frequently. One in five large companies now automatically replicates transaction data to an off-site location as those transactions occur. Companies of all sizes are now using storage area networks to organise their data better.

Taking backups off-site poses its own security risks. Historically, backups have tended to be unencrypted to minimise the effort to restore data. More companies are now considering whether they ought to be encrypting their backups.


Bye Bye Baby

By Calum MacleodCyber-Ark

Our baby is leaving home. Now I know he’s only 23 and has only been in fulltime employment for the last several years but my wife doesn’t know how the baby is going to cope. After all he’s never had to cook, wash, and take out the garbage. His mother has even done his tax returns for him!! And now the debate starts about what he is legitimately allowed to take with him when he goes. First item on the agenda is the TV. After all when you’re setting up your own home it’s important to make sure you have your priorities straight.

The other topic of discussion is the front door key. After all if he’s leaving then he leaves his keys – front and back door! After all just because he lived here does not mean he’s entitled to just walk in when it suits him. Obviously a point that was lost on Mr. Harold James Boomer, from Kansas City who has just started a 10 month sentence in federal prison without parole, and who has to pay a fine of $24,000 in restitution to Midwest Technology Connections. It seems as if Mr. Boomer decided to make a copy of the back door key when he left MTC in June 2006 to set up on his own. During his last day he created an administrator user name that was set up to give him complete administrative access to the network, and to monitor the e-mail accounts of key employees. He also admitted that he placed hacking software on MTC’s systems, and that he had access to all of MTC’s customers’ data!!

And it’s not like our man was not aware of what he was doing. After all his new company offered services such as Ethical Hacking. On his website he stated that “companies cannot afford to have hackers infiltrating their systems and stealing their valuable information and assets.” Additionally he stated on his website that “We have found that security requirements are rarely addressed adequately in the design of new IT systems or projects. Our testing will highlight any security areas that may have been overlooked as well as allowing a more complete test of compliance with your security policy.”

Our man could truly speak from experience when he states on his web site that “a greater percentage of attacks come from the inside (from “trusted folks”) than from the outside… He then goes on to say that “systems administrators should evaluate their users and the assets they have access to”. What he conveniently forgot to mention is that studies show that systems administrators represent the biggest risk.

From a security perspective, Shared/Administrative Identities are the most powerful IDs on any system and these IDs are also required for various system and security functions. This is especially true of most distributed systems such as Windows, UNIX, firewalls and network appliances.

Distributed systems, especially in an enterprise environment, are supported by groups of systems administrators, - including very often folks that are working their notice period! - So there is always the risk associated with the sharing of the passwords related to these shared IDs.

The result is that every enterprise finds itself in a very vulnerable situation both from an overall security perspective and also from a regulatory and compliance situation because the most powerful IDs have shared passwords that are infrequently changed. Sharing the password of a privileged account leaves an organization vulnerable to unplanned/malicious changes, and also makes it difficult to hold individuals accountable for their actions.

For example if the password is shared, any of the administrators can change the password, thus locking out all other administrators for the affected system. Also, if the password is lost, the system typically will need to be taken offline in order to recover. And of course they can create new accounts with administrator privileges or use their privilege to install some nasty software on the system!

In general the accounts will fall into the following categories

  1. System Admin Accounts, those supplied and used by the operating system. (e.g. “administrator, root”) or by the device (router, firewall, etc)
  2. Operator Functional Accounts, those used to perform system functions
  3. Application Functional Accounts, those used for applications to install or run. (e.g. ‘db2inst’) –also known as Built-In Accounts
  4. Application Admin Accounts, those used to administer applications (e.g. Microsoft SQL’s ‘sa’, DB2’s ‘dba’, MQSeries ‘mqm’). These accounts are identities that are hard coded in applications, Operational Support Accounts, those created for and used by teams to perform support activities etc.
  5. Batch/Embedded/Service Accounts Account information in scripts is retrieved using a script specific password or other authentication mechanism

Many organizations rely on manual procedures which are completely inadequate. They rely on paper based procedures generally known as “emergency envelope procedures”; they have policies that are rarely if ever enforced; they take little or no account of physical disaster situations; they forget about the risk posed by IT staff.

In some case, this “emergency envelope procedures” may have been replaced by a secure password store, or an encrypted file but this does not address the issue of managing the account on the target system. Although it may move the passwords to a digital format it does not eliminate the majority of the manual processes involved in updating and managing the target account.

What is required is a Privileged Password Management solution that solves the problem of password management, protection, automatic changing, and access auditing in multi-user, multi-system environments for shared identities that need to be accessed by several individuals.
We know from surveys conducted in the UK that approximately a third of IT professionals leave an organization in possession of privileged accounts. Like my baby who thinks that because he’s watched TV at home for 23 years, he’s entitled to take it with him, some IT professionals seems to think that admin account credentials are some sort of compensation that they are entitled to when they leave.

Maybe it’s time to start a campaign “Help Keep Former Employees in Employment!” As in this case everyone is a loser and had MTC implemented a Privileged Password Management solution in the form of a digital vault for storing and managing passwords from Cyber-Ark, Mr. Boomer would still be free and MTC would not have been hacked! In any case my baby will be leaving the backdoor key behind and the TV is staying exactly where it is right now!

Calum Macleod -Cyber-Ark - www.cyber-ark.com

Cyber-Ark is exhibiting at Infosecurity Europe 2008, Europe’s number one dedicated Information security event. Now in its 13th year, the show continues to provide an unrivalled education programme, new products & services, over 300 exhibitors and 11,700 visitors from every segment of the industry. Held on the 22nd – 24th April 2008 in the Grand Hall, Olympia, this is a must attend event for all professionals involved in Information Security. www.infosec.co.uk
.

Fortify Software Releases Industry’s First Software Assurance Suite

Fortify 360® provides comprehensive software security from development through production

Fortify® Software, the market leader in enterprise application security, announced today its newest product, Fortify 360. Fortify 360 is a suite of integrated solutions for identifying, prioritizing and fixing security vulnerabilities in software while managing the business of ensuring application security. The cornerstone of Fortify’s recently announced Business Software Assurance framework (see separate release), Fortify 360 executes on the company’s holistic approach to protecting corporate assets and preventing catastrophic data loss by focusing on the most vulnerable area in the enterprise – the software applications that automate critical business processes.

The first solution set of its kind, Fortify 360 uses patented capabilities to precisely identify the location of deadly vulnerabilities at every phase of development through production. Once identified, Fortify 360 provides the means to manage the complex process of repairing the numerous problems that are usually uncovered, as well as a centralized dashboard for effective management and reporting.

Software vulnerabilities can translate directly to business risk,” said analyst Diana Kelley of SecurityCurve. “Organizations need solutions that help them identify and respond to software vulnerabilities throughout the lifecycle. C-level executives require insight and understanding regarding risks and impacts, developers need solutions that work inside their development environments to help them create more secure software, and testers and auditors need solutions that help them assess software risk postures before acceptance. Fortify 360 is an innovative approach because it brings together multiple software security functions into a single framework.”

Graham Titterington – Principal Analyst at Ovum said "Application security is an area that has traditionally received little attention, but has now become critical as mainstream corporate processes are performed by externally facing applications. Applications need to be secure to protect corporate assets and operations."

Fortify 360 allows companies to implement Business Software Assurance as an ongoing business process, seamlessly connecting security, software development and C-level business management teams.

It’s not just about the technology, but also about bridging the gap between those in the enterprise responsible for development and security. Security is a low priority in software development compared to functionality, quality and performance, and most business managers are often unaware of the inherent business and security risks of deploying dangerously exposed software,” said Roger Thornton, Fortify’s Chief Technology Officer and founder. “Fortify 360 connects all of these teams, integrating software assurance as a business process throughout the organization.”

Fortify 360 offers:

- Fortify 360 Analysis: applies three integrated levels of analysis including static analysis of the code, dynamic analysis of running applications during QA testing, and real-time monitoring of applications once they have been deployed, providing the most comprehensive security analysis in the market today

- Audit Workbench: correlates and prioritizes vulnerabilities so that IT and security teams can effectively manage and remediate the most pressing risks first

- Instant Remediation capability: allows rapid response to time-sensitive vulnerabilities affecting deployed applications by delivering patches immediately

- Collaboration Module: provides a shared working environment where security and development teams can work together to resolve vulnerabilities

- Software Security Governance: establishes a centralized security dashboard and control center for effective reporting and trend tracking over multiple applications

In addition to its analysis and remediation processes, Fortify 360 also provides users with regular threat intelligence updates generated by the Fortify Security Research Group, the industry’s only team of researches dedicated to software application security. These updates, known as rulepacks, are well-known throughout the industry for their insight on why real world systems fail and how Fortify customers can best address impending threats.

"DTCC implemented an industry leading software security program by focusing on the collection and aggregation of multiple vulnerability detection sources and turning them into prioritized remediation requirements aligned with projects and business areas integrated with the software development lifecycle,” said Jim Routh, Chief Information Security Officer of Depository Trust & Clearing Corporation. “Fortify 360 is one of the solutions that addresses many of the reporting and management requirements for software security programs for financial service firms."

Fortify 360 challenges the premise of other point solutions in the industry by addressing the root cause of software vulnerabilities from the get-go,” commented Barmak Meftah, Senior Vice President of Products and Services at Fortify. “Our product suite and approach really allows our customers to change how they view their software, and achieve their security goals much faster.”

About Fortify Software, Inc.

Fortify® Software products protect companies from the threats posed by security flaws in business-critical software applications. Its software security suite —Fortify 360—drives down costs and security risks by implementing threat intelligence, automating key processes of developing and deploying secure applications. Fortify Software's customers include government agencies and FORTUNE 500 companies in a wide variety of industries, such as financial services, healthcare, e-commerce, telecommunications, publishing, insurance, systems integration and information management. The company is backed by world-class teams of software security experts and partners. More information is available at www.fortify.com.

Gateshead Council deploys Solcara Communications Centre

Gateshead Council has deployed Solcara’s Communications Centre software within its media operations. The software package allows organisations of any size to co-ordinate, manage and benefit from easy control of news and information.

Gateshead joins the growing number of local government offices using Communications Centre to help manage media relations. The key benefits of the package are that it greatly helps Communications teams to measure the success of campaigns for public perception and positive media coverage.

Solcara Communications Centre provides the team with one area in which all their vital information is easily accessible for sharing, distribution and evaluation, producing a faster, more efficient press office. The Gateshead team also use PR Newswire’s Media Atlas service and Communications Centre allows this service to link directly into the contact management module, allowing them to import and manage contacts automatically, seamlessly combining these vital press office tools.

Sam Reed, Media Manager, Gateshead Council said:

“Solcara Communications Centre means we can work more effectively as a team and we can log and monitor all our work. It has a fantastic search facility and it’s really flexible too. We’ve been able to customise it to our needs. As part of the process we looked at a million other products and Solcara Communications Centre was the solution that covered most of our requirements. Now, we couldn’t work without it”.

Solcara Media Centre is used by hundreds of press officers nationwide for media relations, internal communications, campaign and event management, incident management and team and agency management.

For more information about Solcara’s products, go to www.solcara.com

Employee behaviour key to improving information security, new survey finds

UK companies have become increasingly aware of the need to have information security policies in place, with seven out of eight large businesses now claiming to have one. However, the high priority given to information security by companies does not necessarily translate into improved security awareness among employees. Increasingly, companies are realising that to tighten up further on information security, they have to change their people’s behaviour.

These are among the early findings of the 2008 Information Security Breaches Survey (ISBS) carried out by a consortium, led by PricewaterhouseCoopers LLP, on behalf of the Department for Business, Enterprise & Regulatory Reform (BERR). The full results of the survey will be launched at Infosecurity Europe in London, 22-24 April www.infosec.co.uk.

The survey shows that companies are placing greater trust in their staff and they want their staff to use technology to improve their effectiveness. For example, 54% of UK companies now allow staff to access their systems remotely (up from 36% in 2006); every very large business gives remote access to at least some staff. The proportion of businesses restricting Internet access to some staff only has nearly halved (from 42% to 24%), and only 9% give no staff access to the Internet.

At the same time, the survey shows that staff are increasingly targeted by social engineering attacks (where outsiders try to obtain confidential information from employees). In addition, businesses are becoming increasingly concerned about what is being said about them on social networking sites (such as MySpace, Facebook and Bebo), and some staff have posted confidential information on these sites.

Against this background, companies are hardening their technical controls:

  • Use of strong (i.e. multi-factor) authentication has nearly doubled since 2006. 14% of small businesses and 53% of large companies now use strong authentication for some of their systems.
  • Two-thirds of companies that allow staff to access their systems remotely require additional authentication over that access. Virtual Private Network (VPN) use is almost universal among very large businesses for remote access.
  • 81% of large companies block access to inappropriate websites and 86% log and monitor staff access to the Internet.

However, technology controls alone are not enough. Key to making sure that staff remain the organisation's greatest asset is to ensure they behave in a security-conscious way. Increasingly, companies are focused on setting clear policies, making staff aware of the policies and then monitoring behaviour to ensure that it is in line with those policies. The proportion of companies that have an information security policy has quadrupled over the last eight years. Large businesses remain more likely to have a security policy; seven out of eight do so, and some of the 12% that do not have a security policy per se have an integrated overall set of business policies that include information security.

Some 68% of companies surveyed that give a high or very high priority to security have a security policy (up from 55% in 2006 when the last ISBS was conducted) compared with 64% of those that treat security as low or no priority (up massively from 13% in 2006).

There is some correlation between how clearly senior management understands security issues and whether a security policy is in place. However, even where senior management has a very poor understanding, 56% of those businesses have a security policy. The biggest correlation is between security policy and risk assessment; companies that carry out risk assessment are nearly twice as likely to have a security policy in place as those that do not.

Security awareness is not just an issue for a company’s staff. Nearly two-thirds of very large companies would welcome more education for the general public about information security risks.


Chris Potter, partner, PricewaterhouseCoopers LLP, who led the survey commented:

”Of course, having a security policy alone does not magically improve security awareness among staff. The overwhelming majority of companies take steps to raise awareness. The priority given by senior management makes a difference in the extent to which security awareness is drilled into all areas of the organisation. Only one in five companies for whom security is not a priority at all takes any steps to raise the security awareness of their staff.

“What companies are realising is that increasing security awareness is only part of the answer. The critical issue is changing the behaviour of their people. A ‘click mentality’ has grown up - users do what expedites their activity rather than what they know they ought to. It is a bit like the road speed limit – everyone knows what they ought to do, but only a few actually do it. Only when behaviour changes do businesses realise the benefits of a security-aware culture.”


Martin Smith, Chairman and Founder of The Security Company (International) Limited, a company that focuses on promoting long term behavioural change across all levels of organisations, added:

“Traditionally, where organisations have attempted to improve employee awareness they have used a combination of computer-based training and face-to-face presentations to get security messages across. But these methods are somewhat transient - much more collaborative and longer-lasting programmes are needed. Genuine behaviour change is essential, and this takes time and effort.

“To be truly effective, awareness messages need to be personalised and tailored to the audience – staff need ownership, plus what works well for a bank won’t necessarily come across well on the shop floor. Messages also need to be kept up to date, so sharing experience with other organisations is important. But if you want to really change staff behaviour, you must put metrics in place to measure actual performance, to ensure compliance, and to reinforce and reward the right conduct.”

Solcara Communications Centre is De Beers’ best friend!


  • Solcara’s Communications Centre deployed across De Beers operations
  • Market-leading communications software deployed in South Africa, India, Russia and Canada
De Beers, the world’s leading diamond company, has installed Solcara Communications Centre to manage stakeholder engagement and communications across the globe. De Beers joins a number of large plcs, government organisations and international enterprises that have benefited from deployment of Solcara’s Communications Centre.

Implemented at the De Beers office in London, Solcara Communications Centre will aid the communications teams when managing stakeholder relationships, providing a comprehensive contact database, an enquiry management service and an events calendar. The Communications Centre works by creating one area where all vital information is easily accessible for sharing, distribution and evaluation. Team members, activities and information can work together for a faster, more efficient media operation.

Kirsty Lane, Media Relations Executive at De Beers commented,

”The De Beers Communications Team is always looking for ways to bring our disparate teams closer together by sharing current information and best practice across all markets. For the first time we have a secure, online stakeholder management database that we can all access, no matter where in the world we are located. Solcara enables any of our users to get the information they need about an issue, stakeholder or event in real-time“.

Rob Martin, Solcara’s Managing Director added,

“Solcara Communications Centre continues to prove an indispensable tool for marketing, press and media relations personnel across all business sectors. Solcara Communications Centre is now installed at some of the largest and most prestigious companies in the UK and the global leader in terms of diamond production.

“What we have found is that once deployed, Solcara’s Communications Centre becomes indispensable and we are particularly pleased to see how many former customers who move jobs, quickly order Communications Centre when in their new role”.

Initially piloted by De Beers’ UK office, Solcara’s Communications Centre has since been rolled out to De Beers’ international operations – within its External & Corporate Affairs offices in South Africa, India, Russia and Canada.

Free Your Computer with Ubuntu

There is lots of talk everywhere, I know, about the different Linux operating system distributions but I must say that, as far as I am concerned, I shall, for the time being for personal use, at least, stick with Ubuntu by Canonical.

I like Ubuntu for a number of reasons, and the word Ubuntu being one of then. I know that that may be silly but so be it. I also love the Ubuntu promise, which is to keep it totally free of licensing fees. The promise was given some while back and it is still as true as it was then. Let us hope that it will also remain thus, namely free of all license fees.

We have come a considerable way already since I started using Ubuntu, with Dapper Drake. Feisty Fawn came and went, the Gutsy Gibbon arrived and then the Heron. Now, yet another version/upgrade is due out soon. I am not worried about that, presently.

For, while now even Gutsy Gibbon and the Heron are both out and more or less, history, I personally still use the Dapper Drake version of Ubuntu and am very happy with it for the work PC, e.g. the one where all the writing is done, predominately. It sits there quietly in the corner, is ready when I want it and never freezes up or crashes – well, at least not so far. It is quacking great, the Drake, in my view, and very dapper.

If you have an older computer or just want to get the absolute best performance out of your computer you may want to try Xubuntu, which, apparently, uses the slim and trim Xfce Desktop. If you want the KDE Desktop there is Kubuntu. And, if you want to run a thin client and server setup for a classroom there is Edubuntu.

For all of the versions except Xubuntu you can request a free install CD.
However, if you have a broadband Internet connection, or have a friend who does, downloading the CD images will get it to you faster and conserve resources for those that have not choice but to order the CD.

I guess that, personally, I am biased as to the Linux distro that I use, e.g. Ubuntu, simply because it was Ubuntu that introduced me proper to Linux on the desktop and as far as I am concerned Ubuntu it will remain for a long time to come.

This is not to say that I shall not, in due course, as I have a number of “older” PCs sitting about here that I want to put to use again, experiment with Fedora, Puppy, Damn Small Linux, and a few others. I still doubt, however, that any of them will replace my Ubuntu one(s).

Let me reiterate that Ubuntu Linux is definitely worth a look

The Ubuntu developers have a philosophy and a product that seems to be Second to none. Here are some points that I find appealing as regards Ubuntu Linux:

Ubuntu Linux has a company behind it to make sure releases and updates are available in addition to support by an active user community. They have pledged never to charge a license fee. They make their money by offering paid support only.

The people behind Ubuntu Linux are committed to the free Open Source software concept and working hard to get the software out to people to use.

One impressive way they are helping to spread the word about (free) Open Source Software is by offering free CD-ROMs with free shipping. This is a great way to get the software to those without fast Internet connections and to get people to share it with their friends.

Ubuntu Linux is available as a Live Linux version you can run from the CD so you can see how you like it before installing.

Ubuntu Linux is definitely worth trying whether you have ever run Linux before or not. Check it out! I did exactly that. I checked it out by ordering the live CD and got sent about five of them. One for use, theoretically, and four, I guess, to pass on to others. I have meanwhile also cut CDs of those and given them of people who were interested.

I had heard a lot about Linux and decided to give it a go. I liked what I saw and stuck with it. I also stuck with the first initial version of Ubuntu that I ever stuck onto the PC. Why? Because of the old adage “if you Linux box works, leave it alone”. The real reason is, it does what I want it to do, is fast about doing it and, well, I am happy with it. As said, give it a try, you have nothing to lose bar your ties to Microsoft. You can set up – the CD does that automatically – a dual-boot on the PC so you have the option to return to Windows at any time, should you so wish; though I doubt that you would wish to.

© Michael Smith (Veshengro), March 2008

P.S. I am not getting paid by Canonical for this, before anyone asks. I just like the product.