Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

7/15/2009
10:07 AM
Keith Ferrell
Keith Ferrell
Commentary
50%
50%

Will Unemployed IT Workers Turn To Cybercrime?

A weak IT market may create a boom in IT-trained criminals, a report from Cisco suggests.

A weak IT market may create a boom in IT-trained criminals, a report from Cisco suggests.Cisco's midyear security report, summarized here yesterday includes plenty of solid information and insight concerning the variety of threats we and our systems face.

And the report suggests as well that ranking high among those threats is the current sluggish nature of the economy in general and IT employment prospects in particular.

In short, IT staff, current, former and unemployed may have precisely the skills needed to make it in the one IT area that's booming: cybercrime.

I've railed here before about the challenges of keeping your guard up in terms of your IT staff without creating an atmosphere of distrust. This is one of those managerial balancing acts that far more easily railed about than implemented, but it's no less important for that.

Knowing who you trust, and who you can trust with the keys to your business's information -- which almost undoubtedly includes customer and vendor information as well -- is among the largest security challenges any business faces. And it is probably the largest of your security responsibilities.

Certainly when employees -- IT or otherwise -- are terminated for any reason, there are large and immediate security measures to be taken.

And Cisco is absolutely right on target in pointing out that [security]"contractors or other third parties... pose a very serious threat, as they know how to exploit an organization's weaknesses, security policies, and technologies to steal data, intellectual property, or money -- or simply, disrupt operations."

Therein, I think, lies one of the report's largest and most critical warnings. You're aware of the nature and trustworthiness of existing IT staff. You've taken precautions to prevent former employees from coming back to haunt (or worse) your systems.

But, particularly in lean times when considering outsourcing security or other IT functions that involve security access, you have to raise the bar for access, and keep it raised.

Outsider threats are magnified when you invite outsiders into your organization: Thorough, ongoing background and reference checks, performance -- and procedural -- monitoring for any unnecessary, unseemly or out-of-the ordinary access or use of company systems and information are mandatory when using IT contractors.

And that's as true in good times as in tough ones.

The complete Cisco 2009 Midyear Security is here.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Manchester United Suffers Cyberattack
Dark Reading Staff 11/23/2020
As 'Anywhere Work' Evolves, Security Will Be Key Challenge
Robert Lemos, Contributing Writer,  11/23/2020
Cloud Security Startup Lightspin Emerges From Stealth
Kelly Sheridan, Staff Editor, Dark Reading,  11/24/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-29367
PUBLISHED: 2020-11-27
blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data.
CVE-2020-26245
PUBLISHED: 2020-11-27
npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. The issue is fixed in version 4.30.5. If you cannot upgrade, be sure to check or sani...
CVE-2017-15682
PUBLISHED: 2020-11-27
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the admin panel.
CVE-2017-15683
PUBLISHED: 2020-11-27
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.
CVE-2017-15684
PUBLISHED: 2020-11-27
Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system.