It's kind of ironic that after seeing and posting the Ziggy cartoon about the Nigerian email scams that The Register has an article about a HUGE loss due to email scams.
This reminds us of the importance of being very diligent in how we deal with what seems like legitimate emails. We all get them. More often than not they are SPAM or scams. They are getting more and more realistic now. I received one the other day pleading for money to buy Bibles for Christians in Russia or somewhere. I receive similar emails that are legitimate so that makes these hard to detect. The look of an email will go a long way in determining who will or will not act on it. This is true in business and in scams. The bad guys know this and they are starting to pay more attention to it. They are spending more time polishing their emails so that they will get looked at. That's half the battle. If they can get someone to open the email then there is a much better chance that they will take action on it. Hopefully that action will be to delete it, but often enough it is to click on the link, reply to the plea and then get infected or have their ID stolen or bank account emptied.
We must be careful with all email even those that we receive from people we know or think we know. The incident with SuperValu is a great example of how "blind trust" can really hurt. The emails looked legitimate. The seemed to be from a known and trusted source. Yet it cost the company more than $10 million dollars. All because internal controls broke down. All because everything "looked" right.
You could argue several positions on this. Lack of a good User Awareness program was at fault. Not having good internal policy and controls played a part in this. Having both of these in place could have gone a long way in preventing this but nothing works as well as common sense and due diligence to ensure that things are as they seem.
So, what do we learn from this? Have the proper framework in place. UA program, policy, controls and encourage your people to think. Thinking is the thing that really can make a difference and prevent something really bad from happening.
Security's Everyman
Tuesday, October 30, 2007
It's not always what it seems to be
Posted by
Andy, ITGuy
at
8:11 AM
Labels: Andy ITGuy, information security, UA Training
Friday, August 24, 2007
Users don't care about security threats
It seems that most mobile workers think that security should be completely left up to the IT department and that they should be able to do what ever they want. This article from Information Week gives the details.
I saw this earlier in the week but was too busy to really look at it or think about it. It was brought to my attention today as I was looking at this weeks SANS News Bites newsletter. For those of you who aren't familiar with this newsletter typically it has stories about this weeks news and the editors will comment on it. It was one of those comments that got my attention today. After reading the story about how mobile workers think that security is IT's job and that they do things that they know they shouldn't without a care the editors started in. They talked about things like how sad this attitude is and how UA training has failed and how people are just stupid enough (my words not theirs) to believe that they really won the UK lottery or some other something. Then Johannes Ullrich, who is Chief Technology Officer of the Internet Storm
Center, made a stupid comment. He said
Why shouldn't users expect IT to take care of securityy? I think we (IT / Security professionals) expect too much if we expect office workers to worry about security. Perhaps we can ask them not to leave their laptop unattended. But beyond that, it's our job!Before I start ranting..... He is correct that security is OUR job. That's what we get paid for. But unless companies are going to hire a Security Professional for every worker, to stand behind them and look over their shoulder and physically stop them from opening emails, clicking on links, going to porn sites, installing unauthorized software, etc... then we have to put some measure of responsibility in their hands. Information Security technology can only go so far and do so much. Users have to be responsible for their actions. They have to use common sense and follow company policy. They have to learn to be careful with their actions. It's not their laptop. It's not their data. It's not their company to take such risk with. They need to realize that their compromised machines don't only affect them. The data they lose affects the company, the customers, the investors, the partners. The malware that they install on their machine causes the rest of us to be at risk because of their actions. They should be charged with SWS (Surfing While Stupid) and be taken off the information superhighway. They should, in some cases, be fired or put on probation. Mr Ullrich, and those who promote reckless computer use should be charged as an accessory prior to the fact and given similar sanctions.
When technology gets to the point where everyone surfs in their own little virtual world and they can't hurt others by their stupidity then I will quit promoting quality UA training and will happily let users do what they want. Until then I will continue to promote and practice good security. I will work to make sure the technological controls are in place and the users are trained properly. I will also rant when people make ridiculous comments like this.
Posted by
Andy, ITGuy
at
4:16 PM
2
comments
Labels: Andy ITGuy, information security, SANS, UA Training


