Risk
12/24/2009
12:59 PM
Fredric Paul
Fredric Paul
Commentary
50%
50%

5 Security Predictions For 2010

Varonis shares five security trends that will impact SMBs in the coming year.

Varonis shares five security trends that will impact SMBs in the coming year.Raphael Reich, senior director of marketing for data security vendor Varonis, says the issues listed below will have a big effect on companies of all sizes, but SMBs may be even more vulnerable to these trends because they have less time and money to spend on IT security.

Here are Reich's top 5 security trends:

1. Unstructured data continues to "dog" organizations that do not begin to get it under control. Unstructured data represents about 80% of business data, and grows at over 50% per year, with data being generated from many sources and devices. Also constantly changing are the needs users have to access this data. Without proper solutions in place, managing this data is labor intensive, and organizations that do not make it a priority to get better control of this data will forever be playing catch-up with it.

2) Protecting Personally Identifiable Information (PII) becomes a bigger priority for organizations. Information about customers is a tremendously valuable business resource, especially as businesses seek to build closer relationships with their customers. At the same time, individuals and governments want to protect the privacy and security of this information, as witnessed by the growing number of countries and US states that have PII legislation in place. With more and more PII being created, analyzed, and used, businesses will need to intensify their efforts to protect PII to ensure they are complying with laws and industry best practices.

3. US Healthcare changes drive increased security requirements for patient data. Electronic medical records and computerized physician order entry systems promise to help transform US health care. As healthcare organizations, hospitals, doctors, and others begin to use these systems, security of patient information will be critical to establish patient trust and rapid adoption.

4. Employees continue to abuse business data access. Unfortunately this is not a new story, but a continuing saga. Employees already have access to far more data that is needed to do their jobs. General curiosity coupled with anxiety about job stability in today's economy will tempt employees to abuse access privileges and take corporate data home or to their next employer, or potentially inflict damage before they leave the company.

5. Economic times continue to demand that IT purchases have positive impact on operational efficiency. Organizations continue to scrutinize new purchases to ensure that IT products demonstrate clear return on investment through reduction in capital expenditures and/or increased operational efficiency. Because ongoing operations represent a recurring cost, organizations will focus on how to reduce these costs to gain lower operating costs and greater efficiency now, and into the future.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-1793
Published: 2014-12-25
rendering/svg/RenderSVGResourceFilter.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted SVG document that leads to a "stale pointer."

CVE-2011-1794
Published: 2014-12-25
Integer overflow in the FilterEffect::copyImageBytes function in platform/graphics/filters/FilterEffect.cpp in the SVG filter implementation in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified ...

CVE-2011-1795
Published: 2014-12-25
Integer underflow in the HTMLFormElement::removeFormElement function in html/HTMLFormElement.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document con...

CVE-2011-1796
Published: 2014-12-25
Use-after-free vulnerability in the FrameView::calculateScrollbarModesForLayout function in page/FrameView.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaS...

CVE-2011-1798
Published: 2014-12-25
rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not properly perform a cast of an unspecified variable during an attempt to handle a block child, which allows remote attackers to cause a denial of service (application crash) or possibly have unknown othe...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.