IT Security

APT survey

by Mark Rowe

Most, 83 percent of IT professionals do not believe advanced persistent threats (APTs) are over-hyped; however they are still very naïve about the length of time it would take to identify an advanced persistent threat on their own corporate network, according to a survey from Lieberman Software Corporation.

The study at Black Hat Conference 2015 looked at the attitudes of nearly 150 IT security people. It found that 10 percent of IT professionals believe it would take them only one hour to identify an APT on their network, while 55 percent said it would take them one week to one month. However this is in contrast with data from a recent Mandiant report which revealed that hackers are present on the network for an average of 205 days before being discovered.

Among other findings, 84 percent of respondents believe that unmanaged privileged credentials are the biggest cyber security vulnerability within their organisation.

Comment

Philip Lieberman, pictured, CEO of Lieberman Software Corporation, said: “Today’s sophisticated cyber attacks are designed to stay under the radar. Organizations must have security inside the firewall for when these difficult to detect attacks slip by perimeter defenses. That’s why it’s encouraging to see that IT professionals understand the dangers of unmanaged privileged credentials. Despite the prevalence of cyber attacks, and the difficult task of stopping them, malware and APTs do have a weakness. To be able to do their worst, they need privileged credentials to gain elevated access to a system. Ultimately, if they can’t install something, they can’t attack.”

Among other findings, many IT people are still very dubious about the cloud, with 97 percent of respondents stating that they are worried about some of their organization’s cloud hosted data being either lost, corrupted or accessed by unauthorized individuals.

Lieberman added: “Generally speaking, the security provided by cloud services is often superior to that which is implemented by most small and medium sized businesses. However what concerns most organisations is the security of their critical data. Cloud service providers need to demonstrate how seriously they take cyber security and the lengths they are going to in order to protect sensitive information against access by unauthorized individuals. Organisations should always keep a close eye on all their cloud hosted data and keep a log of who is accessing the data and when. This will help ensure it is not accessed by anyone it shouldn’t be.”

For more on the survey, see http://go.liebsoft.com/blackhat-security-survey.

Newsletter

Subscribe to our weekly newsletter to stay on top of security news and events.

© 2024 Professional Security Magazine. All rights reserved.

Website by MSEC Marketing