You are here: silicon.com > Software > Security Strategy

Security Strategy

Firms still leave security to chance

"More than 50 per cent of our customers do not have even the most basic of firewalls in place..."

Tags: firewall, psinet

By Will Sturgeon

Published: 22 September 2003 15:06 GMT

Too many companies are still leaving the security of their websites to chance - adopting an 'it couldn't happen to us' attitude rather than implementing robust security on their site and servers.

PSINet Europe and Pan Security International (PanSec) conducted research which revealed the risks that companies are running by failing to protect themselves online.

Yet despite this the companies claim hundreds of thousands of firms are still leaving their websites open to attack.

The companies set up two 'dummy' websites resembling European banking sites. One site was left unprotected while the other was equipped with a standard firewall, and the number of hacker attacks each faced over an eight-week period was monitored and compared.

The research showed that the unprotected server was attacked 19,128 times, nearly ten times more frequently than the one protected by a firewall, which was attacked 1,672 times over the two months.

However, while this research shows that a firewall significantly reduces the risk of hacker attacks, more than one third of the attacks aimed at the secure site were classified as serious 'high risk' threats - theoretically carrying the potential to bring the system crashing down.

This means that even an effective firewall is still a ticking timebomb if poorly configured, vulnerable the second an as-yet undiscovered flaw is exposed. This should highlight to system administrators and IT managers the need to remain up to date with patching.

However, Neil Downing group product manager for PSINet Europe, said in a statement: "With the threat of cyber-terrorism being added to the increasing impact of email viruses and hacker intrusion, online security should be a primary concern for all firms. However, surprisingly more than 50 per cent of our customers do not have even the most basic of firewalls in place and that is a very conservative estimate. This is comparable to an individual not having a lock on their front door - in other words it's the most basic first line of defence."

The clear message would appear to be you will get attacked. Expect it, plan for it, prepare for it and survive it - because the downtime may prove a lot more costly than the security spend.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
Senior Software Engineer

CompanyMcAfee creates best-of-breed computer security solutions that span large enterprises, governments, small- & medium-sized businesses, & ...

Security Operations Centre Manager (SOC Manager), SC Security Cleared

Moderate IT security experience (UNIX, NT, firewalls, virus, intrusion detection). Basic awareness of computer based network attack ...

Information Security Analyst (Attack Monitoring/Data Leakage/CISSP/CEH

A highly risk-aware Attack Monitoring Analyst is required for a leading global bank to and tackle all potential incidents and threats to global ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: