Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Active Directory Mismanagement Exposes 90% of Businesses to Breaches
Newest First  |  Oldest First  |  Threaded View
Franois_ISDecisions
100%
0%
Franois_ISDecisions,
User Rank: Apprentice
2/15/2017 | 10:32:04 AM
Shouldn't stop at adminstrators' credentials...
For me, Skyport Systems' focus on the over exposure of Active Directory (AD) administrators' credentials shouldn't stop there. Organisations need to better protect and secure all AD user accounts as an effective measure against compromised credentials from insider threats and external accounts... not just the administrators. While IT administrators are important gatekeepers, any kind of compromised staff credentials leave organisations vulnerable and can be equally devastating.

Although I agree with the conclusion that organisations need to pay more close attention to their AD infrastructure because of the growing threat and range of attack tools, I believe it's important that any modern approaches called for in the article don't add unnecessary complexity to systems.

Take multi-factor authentication (MFA). The article implies it is a negative that fewer than 25 percent of organisations are using MFA. IS Decision's own research conducted with IT security professionals last year similarly found that 76 percent of UK organisations don't use MFA. We identified that the primary barriers to adoption were frustrations with complexity, implementation time and cost.

A far more practical alternative to MFA is the use of context-aware security which is fast gaining in popularity. Context-aware security comes with all the security benefits of MFA but without the cons of lost productivity or unmanageability. It works by restricting access to networks through only IT-approved workstations, laptops, tablets, times of day and geographies, so companies stand a much better chance of keeping out attackers who use real logins. Crucially, this kind of security would've prevented some of the recent high-profile cyber attacks that have impacted companies like Dropbox, Sony, eBay, Sage and Three.

Context-aware security is well worth looking into.


Look Beyond the 'Big 5' in Cyberattacks
Robert Lemos, Contributing Writer,  11/25/2020
Why Vulnerable Code Is Shipped Knowingly
Chris Eng, Chief Research Officer, Veracode,  11/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: I think the boss is bing watching '70s TV shows again!
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-26250
PUBLISHED: 2020-12-01
OAuthenticator is an OAuth login mechanism for JupyterHub. In oauthenticator from version 0.12.0 and before 0.12.2, the deprecated (in jupyterhub 1.2) configuration `Authenticator.whitelist`, which should be transparently mapped to `Authenticator.allowed_users` with a warning, is instead ignored by ...
CVE-2020-28576
PUBLISHED: 2020-12-01
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version and build information.
CVE-2020-28577
PUBLISHED: 2020-12-01
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names.
CVE-2020-28582
PUBLISHED: 2020-12-01
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents.
CVE-2020-28583
PUBLISHED: 2020-12-01
An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information.