This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. > Find out more here

 

RSA conference: Security giant reveals lessons learnt from data breach

By Stuart Sumner

12 Oct 2011

View Comments
RSA security conference 2011

Senior staff at security firm RSA, part of infrastructure solutions giant EMC, gave delegates at the London based RSA conference yesterday details of the lessons the company had learnt from its devastating network breach in March this year.

Art Coviello, executive vice president for EMC and executive chairman of RSA, began by describing the difficulty of defending against modern cyber attacks.

Further reading

"People are the new perimeter, contending with zero-day malware delivered through spear-phishing attacks that are invisible to traditional perimeter-based security defenses such as anti-virus and intrusion detection systems," he said.

"Clearly, conventional security is either not effective or not enough. The threat landscape is evolving and our security systems must change to outpace our adversaries."

And company president Tom Heiser described the cat-and-mouse game that cyber criminals and security professionals play.

"Sophisticated attackers know traditional security controls and are adapting and changing tactics," he said. "[They are] determined to find exploits in complex, rapidly evolving IT environments and through people."

He made five recommendations for enterprises to tighten up their network security.

  • Reassess your risk: Conduct a risk assessment to identify your high-value and high-risk information assets, looking at things from a cyber criminal's perspective.
  • Re-think malware protection: Your anti-virus solutions will work up to a point, but additional security measures are required.
  • Install security and network forensics capabilities for continuous monitoring and improved analysis of network traffic.
  • Harden identity and access management procedures.
  • Increase user education and communication: Staff need to be aware of their responsibilities to help defend the corporate network.

Reader comments

blog comments powered by Disqus

Newsletters

Does Google know too much about you?

Google's linked data policy, which came into effect on March 1, allows the company to collect information about its users across all its products, services and websites and store it in one place. This has been criticised by organisations ranging from CNIL to Microsoft, all of whom have expressed concerns that it's difficult to tell which data Google collects and how it's used. Now the Information Commissioner's Office is investigating whether Google's privacy policy is compliant with UK law. Are you worried that Google knows too much about you?

41 %

5 %

15 %

39 %