Sunday, December 11, 2005

When is your IT department an obstacle to security?

It may seem like a funny question, but the IT department is an obstacle to security when they operate under the myth that a high thick wall keeps the bad guys out. This is a myth because 60 to 80% of all corporate crimes have an insider element: This element can be unwitting or witting.

So how do you know if your IT department believes in this myth? Simply listen when an executive asks them: Are we secure? If they answer by saying something along the lines of "Yes, we have a firewall, intrusion detection and virus protection" then indeed they do believe the myth.

An electronic crime does not occur as a simple event. It evolves. It begins with the bad guy collecting information form unsuspecting sources. He (or she) then uses that information to create traffic that looks to your firewall, intrusion systems or perhaps your virus scanners, every bit like valid traffic. Electronic crime sneaks past the barrier of the "high, thick wall."