By
Targeted attacks by hackers have skyrocketed, according to a report – and what’s more, small to medium-size businesses have become the corporate target of choice.
Hackers have changed their tactics, according to Liam O Murchu from security software firm Symantec.
“The picture that we had before of targeted attacks was they went after CEOs or other top people in a company, and they went after very large companies and government agencies. Targeted attacks are now being spread out and used in far more scenarios,” O Murchu says.
The latest data found:
Attackers may be targeting smaller companies because of the less sophisticated security processes and many targets are in HR, public relations and sales. “While these workers may not have access to the data the attacker is ultimately after, they are often a convenient vector for penetrating an organisation's defences because they are easy to identify online and are used to being contacted and sent attachments (like resumes) from unknown sources,” O Murchu says.
Because many organisations lack role-based access management process – whereby individuals only have access to resources dependent on their role within the company – hackers who gain access to one of these workers’ accounts, may gain access to a whole host of sensitive data.
“What companies need to realise right now is that once attackers get inside the perimeter of their network, they're going to spread out," says O Murchu. “Your defences should not be focused primarily on the perimeter of the network. You should access controls set up correctly on all of your valuable data. And you should have applications in place that can watch for the loss of valuable data.”
Takeaways to ensure security