IT security teams must cooperate to defeat threats

Symantec report highlights the convergence of attack methods

Written by Phil Muncaster

IT security experts must pool their resources and work together more efficiently if they are to combat the increasingly converged nature of enterprise security threats, according to the latest bi-annual threat report from Symantec.

The report notes that criminals are "refining their methods and consolidating their assets" to incorporate several different attack methods in so-called " multi-staged attacks".

There are also toolkits available on the black market such as MPack, which contain malicious code, spam and exploits for browser vulnerabilities, it added.

In the face of these threats, security teams which have been traditionally been divided in their responsibilities into anti-spam, desktop protection, servers and so on, must share information more readily than before, said Symantec's chief scientist Guy Bunker.

"We're seeing an increasing sophistication of attacks and the bundling of multiple threat vectors together," he added. "People must realise security is hugely important and if you have a serious attack it can harm the brand, which is everything."

Donal Casey of IT consultancy Morse agreed that a siloed approach to security would leave firms at risk. "Only by taking a combined approach to defence will companies be able to protect against increasingly challenging attacks," he added. "These are being launched to steal funds and information, bring down networks and ultimately play havoc with business operations."

Andrew Kellett of analyst Butler Group argued that many enterprises don't have joined up teams because they have bought point products over the years.

"Large enterprises may have properly defined roles and procedures but this is not the majority – most retain a firefighting approach," he said.

But he argued that products are getting more built-in security, as firms such as CA, Oracle and Microsoft acquire security vendors to give them in-house expertise. "They don't buy these firms because it's a nice-to-have but because they protect what they really want to sell," he said.

Jean Paul Ballerini, senior technology solutions expert for Internet Security Systems, IBM, said that the siloed approach of many security departments is preventing them from implementing a defence in depth approach.

“In very large enterprises there are situations where a branch office chooses a different security solution than that of the head office, leading to a more complex management of security which challenges the capacity of actually identifying the threats,” he added. “But we cannot expect businesses to change their organisation overnight, and often this is not wise, even from the security perspective.”

But John Colley, managing director of security certifications organisation the ISC2, said that info security teams in many large firms already work in well organised groups.

"It depends on the quality of the information security people in the organisation but … the people I talk to are co-ordinated and controlled," he added.

The report also highlighted a big spike in web browser plug-in vulnerabilities and an increase in phishing attacks of 53 percent since the last report. According to Symantec just three phishing toolkits were responsible for nearly half of the attacks.

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

security image

Integration the key to data leak prevention

Firms need to shore up defences, but many products are still immature, argue security experts 03 Sep 2007

 

Suite bolsters mobile defences

Symantec launches update to Mobile Security Suite 12 Jul 2007

IT teams urged to rethink web and network security

Industry could see more convergence soon, says security expert 09 Jul 2007

Consumers blow holes in corporate security

Analysts Gartner has warned firms to prepare for new security threats 15 Jun 2007

Symantec expands and upgrades AV protection

Endpoint Protection 11 includes NAC and behavioural threat protection 13 Jun 2007

Security is a ‘necessary evil’ for half of IT executives

New research finds complexity remains a challenge for CIOs 07 Jun 2007

Malware jumps over 200 per cent in 2008

Symantec reports huge rise in malicious attacks, and warns of the smartphone risk 14 Apr 2009

Malware attacks shoot up

Virus infections are on rise, with smartphones thought to be biggest security weakness for business in near future 16 Apr 2009

Malicious activity still growing, Symantec warns

Security firm's 14th Internet Security Report claims web-based attacks are rocketing, with the underground economy raking in the cash 14 Apr 2009

related whitepapers

today's top stories

Telepresence: coming to a screen near you?

Telepresence systems enable organisations to hold boardroom-style meetings with far-flung participants without the hassle and expense of arranging travel and accommodation. But while the technology is impressive, it does not come cheap, as Martin Courtney discovered when he sat in on a virtual meeting with executives from Philips 10 Mar 2010

Users give their verdict on Azure

Some of the first wave of UK adopters met in London recently to air their views on Microsoft’s cloud computing platform. Dave Bailey listened in 10 Mar 2010

Protests greet new Digital Economy Bill amendment

ISPs, digital rights groups and Liberal Democrat supporters cry foul 05 Mar 2010

Publishing special - Publishers innovate to survive

1) IT could hold the key to the future of publishing 2) Case Study: The Guardian harnesses social and mobile apps 3) How publishers are reacting to the iPad 02 Mar 2010

IT Leaders' Forum in association with IBM

A unique opportunity to hear from expert speakers and engage in a debate about the future of the CIO job function 29 Jan 2010

Advertisement

Keys to successful Service‐Oriented Architecture implementation

This white paper explores best practices and general design patterns for service oriented architecture (SOA).

The Roadmap to IT Maturity — Matching Strategy to Infrastructure for Business Success

This paper defines a roadmap for matching infrastructure strategy to business success.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

NHS centralised data

NHS centralised data

Do you think the NHS can be trusted to safely look after personal data electronically?

View poll results

Latest audio and video articles

Video

HP unveils S Series notebooks

'Prosumer' line overhauled 01 Mar 2010

Web Seminar Listings

Preparing for enterprise-scale Windows 7 migration

The web seminar on 18 Feb will discuss how Windows 7 migration can increase IT efficiency in large enterprises, freeing up budgetary and personnel resources to focus on business innovation. Our panel of experts will examine the strategies, tools and services IT leaders can use to migrate successfully and reap the rewards of increased efficiency. 19 Feb 2010

Latest in-depth articles

LaboratoryFeatures

Finding the right formula

Drug and food testing company Eclipse Scientific wanted to make its internal communications system easier to manage and more responsive to the needs of employees and customers. Nicola Brittain reports 16 Mar 2010

Videoconference on a laptopFeatures

Get ready to roll

Moving staff over to a unified communications platform can have a huge impact on their working practices. Rachel Fielding explains how IT leaders can ensure the transition goes smoothly 16 Mar 2010

Primary Navigation