Dave Bailey
Dave Bailey

New Year's security resolutions

IT departments require good systems to secure both the company LAN and mobile clients outside the firewall

Written by Dave Bailey

It is that time of year when people make New Year's resolutions, many of which will concern the avoidance of certain alcoholic beverages. My own resolutions are not in tatters yet, but this is really only because I didn't make any. Looking at security for 2005, however, it seems IT managers should have made a couple, and should also ensure they stick with them.

The first resolution should be: "I will install antivirus gateway tools immediately - not tomorrow or next week, but now." When I talked to Sophos security consultant Graham Cluley just before the festive drinking session got underway, he mentioned that if firms had installed such security products last January, they would have stopped nine out of the top 10 viruses that hit the headlines - and corporate networks - in 2004.

With statistics like that, I think it would be quite easy for IT teams to present a convincing case to the board of directors to purchase gateway antivirus tools.

The second resolution should be to implement a company-wide policy on the use of mobile devices, or, to be more exact, to put some controls on the use of these devices and what sort of data employees should and should not have stored on them. To go by the trends of 2004, mobiles will be high on the list of targets for attacks this year.

There is still some debate about how much mobile technology will really help to boost firms' productivity, but concerns about security are another barrier to the decision to deploy mobile devices. The mobile phone companies have a good record on security and until now the main problems for administrators have been caused by handsets being stolen or left on trains.

But last year saw the first virus specifically targeting smartphones. Although Cabir was only a proofof-concept virus, it was a step towards an attack that might conceivably bring down a mobile network, or allow hackers to access valuable information.

Security experts pointed out that to be infected with Cabir, users would have had to download and install it themselves. And the executable in question was not certified. But just look at the number of users who immediately open email attachments despite the warnings about viruses and Trojans. Firms clearly need some way to save users from their own stupidity.

Another reason why virus writers may target mobile devices this year is that for the first time some phones will have a miniature hard disk for data storage. Seagate, Hitachi and Toshiba provide inch-sized disks that can hold gigabytes of data, whether in the form of video clips or corporate documents.

However, one thing hindering virus writers is that they need a target to aim for, and there just is not the same all-pervasive platform in the mobile world as there is on corporate desktops and servers. Maybe Java-enabled phones will prove to be the weak spot.

One thing experts do agree on is that virus writers now realise that there is money in crime. Attacks were once designed for bragging rights in online forums, but cash is the new motivation.

Tags:

Further reading

Bots and adware top threats for 2005

Happy new year   More...

UK business running scared

Survey reveals a high percentage of firms feel vulnerable to IT security attacks   More...

Related articles

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

22 Jul 2008

3.22 MBSat-nav crashes, open source security and female gamers More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement