Surveying the network security landscape

October 2010 Infrastructure

Report outlines effective security practices for strengthening and protecting enterprises’ competitive edge.

Businesses must change their mindset on security to help ensure that their networks and vital corporate information are protected from evolving security threats, according to the Cisco 2010 Midyear Security Report.

Tectonic shifts – the increasing use of social networking, the proliferation of network-connected mobile devices, and virtualisation – continue to alter the security landscape. As a result, enterprise professionals must act immediately to put effective security practices into place in order to protect their companies’ reputations and maintain a competitive edge. The report outlines five recommendations for improving corporate security.

Key findings

* Tectonic pressures mounting – Major forces are changing the enterprise security landscape. Social networking, virtualisation, cloud computing and a heavy reliance on mobile devices continue to have a dramatic impact on the ability of information technology departments to maintain effective network security. To help manage these converging trends, enterprises should:

- Enforce granular per-user policies for access to applications and data on virtualised systems.

- Set strict limits for access to business data.

- Create a formal corporate policy for mobility.

- Invest in tools to manage and monitor cloud activities.

- Provide employees with guidance on the use of social media in the workplace.

* Virtual farms being tended – Cisco Security Intelligence Operations research found that 7% of a global sample of users accessing Facebook spend an average of 68 minutes per day playing the popular interactive game FarmVille, Mafia Wars was the second most popular game, with 5% of users each racking up 52 minutes of play daily, while Café World, played by 4% of users, accounted for 36 minutes of wasted time per day.

- Although loss of productivity is not a security threat, cyber criminals are believed to be developing ways to deliver malware via these games.

* Company policies ignored – 50% of end users admitted that they ignore company policies prohibiting the use of social media tools at least once a week, and 27% said they change the settings on corporate devices to access prohibited applications.

* Innovation gap being bridged – Cyber criminals are using technological innovation to their advantage. They exploit the gap between how quickly they can innovate to profit from vulnerabilities and the speed at which enterprises deploy advanced technologies to protect their networks.

- While legitimate businesses spend time weighing the decision to embrace social networking and peer-to-peer technologies, cyber criminals are among the early adopters, using them to not only commit crimes but also to enhance their communications and to speed transactions with each other.

* Spam continuing meteoric rise – Despite recent disruptions to criminal spam operations, in 2010 the worldwide volume of spam is expected to grow by as much as 30% over 2009 levels, according to new research compiled by Cisco Security Intelligence Operations.

- The United States is once again the country where the largest amount of spam originates, pushing Brazil to third place. India currently ranks second, and Russia and South Korea round out the top five.

- Brazil experienced a 4,3% decrease in the amount of spam originating in-country, most likely because more ISPs in that country are limiting Port 25 access.

* Multivector spam attacks rising – Cyber criminals remain intent on targeting legitimate Websites but are launching strategically timed, multivector spam attacks with a focus on establishing keyloggers, back doors and bots.

* Terrorists going social – Social networks remain a playground for cyber criminals, with an increasing number of attacks. New threats are now emerging from a more dangerous criminal element: terrorists. The US Government is concerned enough that it has awarded grants to examine how social networks and other technologies can be used to organise, coordinate, and incite potential attacks.

The report includes several other findings and concludes with recommendations to help enterprises strengthen their security.

For more information contact Cisco, +44 7770 751107.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Cyber resilience – protect, defend, recover
Infrastructure
The challenge with AI is that threats are getting harder to detect. As a result, plans in 2024 are not just about detection and prevention, but about recovery.

Read more...
Powering business resilience and field operations
Infrastructure Products & Solutions
[Sponsored] The Anker 757 Portable Power Station emerges as a strategic asset for businesses looking to overcome power instability and the demand for operational efficiency in remote and field-based environments.

Read more...
Top bets for backup and business continuity
Infrastructure
Become your organisation’s data pioneer and spearhead data governance and protection of critical data. Challenge why best practices are not adopted or in place, while highlighting the inherent risks this poses.

Read more...
Next-gen solar-powered switches
Infrastructure
Duxbury Networking has introduced its range of solar unmanaged switches, which are ideal for any environment requiring reliable Power-over-Ethernet (PoE) capabilities, such as IP phones, cameras, and access points.

Read more...
Navigating South Africa's cybersecurity regulations
Sophos Information Security Infrastructure
[Sponsored] Data privacy and compliance are not just buzzwords; they are essential components of a robust cybersecurity strategy that cannot be ignored. Understanding and adhering to local data protection laws and regulations becomes paramount.

Read more...
Creating a cybersecurity strategy in a world where threats never sleep
Information Security Infrastructure
[Sponsored Content] The boom of Internet of Things (IoT) technology and the chaos that surrounded the sudden shift to work-from-home models in 2020 kick-started the age of cybercrime. In that period, incidents rose by 600%, affecting every industry and showing no signs of slowing down.

Read more...
Gallagher Security’s achieves SOC2 Type 2 recertification
Gallagher News & Events Integrated Solutions Infrastructure
Gallagher has achieved System and Organization Controls (SOC2 Type 2) recertification after a fresh audit of the cloud-hosted services of its integrated security solution, Command Centre. The recertification was achieved on 21 December 2023.

Read more...
Cyberattacks the #1 cause of business outages
Editor's Choice Information Security Infrastructure
The latest survey by Veeam Software shows that 92% of organizations will increase their spending on data protection by 2024 to achieve cyber resilience due to continued threats of ransomware and cyberattacks.

Read more...
Nology races to end 2023
Editor's Choice News & Events Infrastructure
Nology ended 2023 with an event highlighting its various products and services to the local market, followed by a few laps around the Kyalami Indoor Karting track.

Read more...
Cybersecurity integrated with data protection
Technews Publishing News & Events Infrastructure
Last year's VeeamOn Tour conference in South Africa was a smaller version of the annual global Veeam conference, aimed at the company's regional partners and customers.

Read more...