Risk
8/24/2007
12:19 PM
Keith Ferrell
Keith Ferrell
Commentary
50%
50%

Weathering The Weather

Watch the news coverage of the Midwest floods and the toll they've taken on families, homes and holdings, and you can't avoid hearing -- and often -- from flood victims who discovered that their insurance didn't cover flood or landslide/mudslide damage. It's no great leap to extend those personal stories to small and mid-size business stories. How covered are you when a natural disaster strikes your business?

Watch the news coverage of the Midwest floods and the toll they've taken on families, homes and holdings, and you can't avoid hearing -- and often -- from flood victims who discovered that their insurance didn't cover flood or landslide/mudslide damage. It's no great leap to extend those personal stories to small and mid-size business stories. How covered are you when a natural disaster strikes your business?Not all the threats your business faces are digital, and not all of them are criminal.

If you don't have a disaster preparation and recovery plan in place for your business -- and, just as crucially, for your remote and mobile employees -- you're running a risk that could catch up with you without warning.

Are all of your business-critical and confidential files backed up and stored on a remote site? What's the date of your most frequent backup?

Do you have a contingency plan in place for running your business -- even minimally -- if your office equipment is destroyed, or if you face an extended period of time without electricity?

Do you carry sufficient insurance to replace that equipment -- and does the insurance cover the likeliest (and, to be safe, the most likely of the unlikely) natural disasters for your region?

Are all of your employees up-to-speed on your disaster and recovery plans?

For that matter, are all of your employees up-to-speed on assistance and support they could offer other employees (first) and your business (once you're sure everyone is all right) in the event of a natural disaster?

Some of you may be experiencing some of this first-hand: in addition to the floods over the past few days, a power outage has knocked out a chunk of Chicago's electric grid as I write.

When natural disaster strikes you'll have plenty to deal with without being distracted -- or heartbroken -- by matters you could have dealt with earlier.

Make sure your overall security planning includes planning for weather and other natural catastrophes as well as digital disasters.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8148
Published: 2015-01-26
The default D-Bus access control rule in Midgard2 10.05.7.1 allows local users to send arbitrary method calls or signals to any process on the system bus and possibly execute arbitrary code with root privileges.

CVE-2014-8157
Published: 2015-01-26
Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.

CVE-2014-8158
Published: 2015-01-26
Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

CVE-2014-9571
Published: 2015-01-26
Cross-site scripting (XSS) vulnerability in admin/install.php in MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 allows remote attackers to inject arbitrary web script or HTML via the (1) admin_username or (2) admin_password parameter.

CVE-2014-9572
Published: 2015-01-26
MantisBT before 1.2.19 and 1.3.x before 1.3.0-beta.2 does not properly restrict access to /*/install.php, which allows remote attackers to obtain database credentials via the install parameter with the value 4.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.