Story image

How to prevent data breaches

06 May 15

Multi-dimensional attacks using a variety of tools can put sensitive data at risk, and many businesses are failing to protect themselves adequately from the increasingly-sophisticated techniques used by cyber criminals to target physical and virtual data centres.

Palo Alto Networks vice president for Australia and New Zealand Armando Dacal
says it is important for organisations to see how the threat landscape and cyber criminals’ techniques are changing. 

“Businesses are at great risk of suffering significant financial and reputational damage as cyber criminals target data centres to steal financial data,” he says.

Palo Alto Networks says the risk of a network breach constantly increases as cyber crime techniques evolve. In 2014, 783 data breaches resulted in the loss of more than 85 million records from organisations around the world. 

“The number of data breaches this year is already tracking worse than 2014,” the company says in a statement. “Cyber criminals using automated attacks cost business millions of dollars in missed revenue by compromising customer data.”

Dacal adds, “An organisation is only as strong as its weakest entry point. A prevention mindset should drive effective strategy and organisations must consider multiple points working together to prevent all aspects of an attack.”

Palo Alto Networks has identified four key ways to prevent data breaches:
1. Block evasion techniques. Organisations can block the different techniques attackers can use to evade detection and establish command-and-control channels. This increases the effectiveness of monitoring tools that can detect malware and suspicious network activity.
2. Prevent malware. Preventing both unknown and polymorphic malware from being installed lessens the risk of data being stolen from the organisation. Applications that are unknown or behave in an unexpected manner should be blacklisted and made unavailable for installation.
3. Block vulnerability exploitation. Organisations can block the different techniques that attackers must follow to exploit vulnerabilities. This decreases the overall attack surface available to cyber criminals and makes it more difficult, and potentially expensive, for them to penetrate the organisation.
4. Proactively monitor. Organisations that closely monitor and control communications are better prepared to recognise when legitimate identities are hijacked. This helps to protect the organisation from malware moving laterally through the network. Detection technologies and incidence response should be coupled with a preventative mindset to stop criminals from penetrating systems.

“It is impossible to keep up with threats if the organisation’s only answer is to clean up after the attack,” Dacal says. “Businesses need to feel confident that the enterprise security platform prevents advanced threats at all steps in the attack kill chain.” 

ForeScout acquires OT security company SecurityMatters for US$113mil
Recent cyberattacks, such as WannaCry, NotPetya and Triton, demonstrated how vulnerable OT networks can result in significant business disruption and financial loss.
Exclusive: Fileless malware driving uptake of behavioural analytics
Fileless malware often finds its way into organisations via web browsers (or in combination with other vectors such as infected USB drives).
'DerpTrolling’ faces jail time for Sony DoS attacks
A United States federal court has charged a 23-year-old man for the hacks on Sony Online Entertainment and other major companies back in 2014.
Kiwis concerned about being scammed – survey
This unease is warranted given the growing sophistication of scammers and their activities, and numbers of attempted fraud.
It's time to rethink your back-up and recovery strategy
"It is becoming apparent that legacy approaches to backup and recovery may no longer be sufficient for most organisations."
Dropbox strengthens security with raft of new partnerships
Integrations will keep customer content protected and secure with tools for controlling identity access, governing data, and managing devices.
Interview: Aruba’s NZ country manager talks channel strategy
“What we're taking to market is that message around simplification and having everything in one place.”
Companies swamped by critical vulnerabilities – Tenable
Research has found enterprises identify 870 unique vulnerabilities on internal systems every day, on average, with over 100 of them being critical.