|
|
Like this article? PLEASE +1 it! |
|
Chinese Computer Hacking of Chamber of Commerce has Already Hurt Your Business
|
| Guest post by: Dovell Bonnett |
Article Overview: On December 21, 2011 the Wall Street Journal reported that U.S. Chamber of Commerce was hacked. Many of the major media outlets are all re-publishing the report. But, if you look at the fine print you will discover that the attack occurred back in November 2009 and was discovered in May 2010. That left the Chamber’s 3 million company members uninformed and their information vulnerable for two years as the FBI and cyber investigators analyzed the attack.
![]() |
Free Download - Zappos Data Breach - Customer Safety and Security By Dovell Bonnett |
Chinese Computer Hacking of Chamber of Commerce has Already Hurt Your Business
On December 21, 2011 the Wall Street Journal reported that U.S.
Chamber of Commerce was hacked. Many of the major media outlets are all
re-publishing the report. But, if you look at the fine print you will
discover that the attack occurred back in November 2009 and was discovered in May 2010.
That left the Chamber’s 3 million company members uninformed and their
information vulnerable for two years as the FBI and cyber investigators
analyzed the attack.
It seems the attack used the tried-and-true
strategy we see every day. An employee received a phishing or
spearphishing email with a spyware attachment. The employee opens the
attachment link not knowing that they have affected the network. The
spyware is able to capture employees and/or administrators passwords to
have unfettered access to all the accounts. Remember, IT is unable to
identify a breach when a legitimate User Name and Password is entered.
Businesses
are also subject to a Catch-22 thanks to the requests of cyber
investigators versus the government’s privacy laws. When a company first
discovers a breach the first instinct is to contact the authorities
like the FBI or FTC that a breach has occurred. Typically these
authorities want to do a full forensics on the attack to learn the
sources and people responsible so they will request that the company NOT
disclose the breach. This investigation can take months during which a
company’s customers are unaware that any of their personal information
is being compromised. When the authorities are finally finished and
allow the company to notify their customers of the breach per the law,
the company is then hit with lawsuits for delaying notification to their
customers.
The costs that the Chamber is going to occur will
probably be horrific. It has already been reported that they hired
independent “cyber sleuths” and have destroyed serves and computers that
are infected. What is still looming are the legal fees, lawsuits and
government fines for the breach. The Ponemon Institute has identified
the average 2010 company costs for a breach is $7.2M per incident.
What the Chinese hack should teach every company:
- Train employees about email security.
- Have strong passwords.
- Use a multi-factor password manager like Power LogOn.
- Implement secure email programs.
- Before a breach occurs or is discovered have a recovery plan already in place that includes legal protections so you as the business owner don’t get multiple attacks on all of your castle walls.
|
About the Author: Dovell Bonnett RSS for Dovell's articles - Visit Dovell's website Founded in 2005 and headquartered in Ladera Ranch, California, Access Smart delivers Access-as-a-Service (AaaS) solutions by way of a password manager for Windows authentication to reduce the risk of cyber-attacks. Access Smart implements AaaS using contact or contactless smartcards, magnetic stripe or 125kHz Prox technologies. The value that Access Smart brings is to offer more security functions and affordability onto a single employee ID badge. Security does not have to be cumbersome to be affective. That is why our products are designed using state-of-the-art security technologies while focusing on ease-of-use and low cost-of -ownership. Previously, smartcard technology was only available to governments and Fortune 500 companies. Access Smart has turned that model upside down by matching the technology to the needs, no annual subscription fees and fully transferable licenses to keep security affordable to even high employee/student turnover businesses. The Access Smart team has over 50 combined years in the smartcard and security industry. By addressing the very real problems from a systems mindset, Access Smart delivers everything for a company to implement AaaS within hours and not months/years. Please contact Dovell Bonnett at Access Smart as to discuss how best to implement Authentication, Authorization and Non-Repudiation into your business. Access Smart - The Alternative to PKI. Click here to visit Dovell's website The Law May Consider Your Business a Bank Network Security Doesnt Have To Be A Burden Safeguard Business Data Value Advantage of Integrating Logical Access on an Employee ID Badge 2012 The Year of Cyber Espionage Dont Wait for Windows 8 to Secure Your Passwords |
Related Forum Posts
Share this article with your friends. Fund someone's dream.
Leave a comment below or share on the left and you'll help support entrepreneurs in Africa through our partnership with Kiva. Over $50,000 raised and counting - Please keep sharing! Learn more.
Get advice & tips from famous business
owners, new articles by entrepreneur
experts, my latest website updates, &
special sneak peaks at what's to come!
Selling On Ebay The Good The Bad And The Ugly
Life, Conflict and Work
Why We MUST Reinvent The Wheel
Email us your ideas on how to make our
website more valuable! Thank you Sharon
from Toronto Salsa Lessons / Classes for
your suggestions to make the newsletter
look like the website and profile younger
entrepreneurs like Jennifer Lopez.



