Insecure In The Cyber World

author-image
DQChannels Bureau
New Update

As a security solutions provider, are you talking to your prospective
customers about hackers, crackers, spammers, viruses, remote tools, adware,
spyware, trojans, worms and of course, security audit? They probably have read
about these things before. But do they know enough about the threat it poses to
their business?

Advertisment

The cyber world is cause for a lot of insecurity for corporate users at this
point of time. For security solution providers, this can be an opportunity as it
means that there are many prospective customers who would like to deploy these
solutions in their enterprises. But a reality check shows that business in this
region is not all that booming.

Ignorance or the lack of customer education is a major reason for this. I
have seen security solutions providers who will sit with a calculator and keep
throwing numbers at a prospective customer! "I have these two solutions, A
and B... You have 150 users on your LAN... you have a central database server, a
mail server... you are still on Windows NT? ... tap — tap - tap...! Solution A
will cost you Rs X and solution B will cost you Rs Y. Now, when do I get the
purchase order?" That's an extreme case and a little exaggerated, but I
think you will get the point.

IGNORANCE IS NOT BLISS

Don't assume that the customer knows everything about security and in case
he doesn't, don't ever make him feel ignorant. If you have approached the
customer on your own, it's your job to educate him beyond what he already
knows and even if a customer has come to you for a solution on his own - chances
are that he is not fully aware of all the security issues.

Advertisment

An
average customer is not aware of the threats that exist all around him. He just
knows about parallel ports, serial ports and USB ports. If you talk to him about
port scanning, he won't know what you are talking about. You may find yourself
talking to an EDP head renamed as IT Manager. He may be a great EDP guy, but don't
expect him to be a security expert.

It's a very delicate job to handle such a customer. You have to make him
aware of the threats that exist, the vulnerabilities that are inherent to the
operating systems, applications and databases. You have to make him aware of the
ease with which a hacker can get into the system. And do all this, without just
scaring him about the consequences. He must feel confident that you have a
solution to these scary problems!

VIRUSES SPREAD

THROUGH MAILS

Hacker and cracker tools are proliferating like never before, and
unintentional attacks must be causing more damage than the really targeted
attacks. Take for example the code that gets into your computer and sits inside
your Outlook Express. The person who released that code doesn't even know
where it travels and embeds itself!

Advertisment

There are companies who get their PCs infected routinely like this and keep
cleaning the machines after they are infected. But within a span of one or two
days that they take the machines for cleaning, the damage could have already
been done. Thousands of infected mails with files from PCs randomly attached to
them must have already left from their mail server.

Imagine such mails going out to international customers of a pharmaceutical
company. The image of a company that claims very high standards of quality
control in drug manufacturing can be ruined in just one day. It's very
important to talk to the customers about such issues than just focusing on your
own technical superiority. May be a free sample security audit and an educative
session with the customer will be more effective than routine sales calls and
high pressure follow up.

I remember attending a seminar organized by a security solutions provider for
launching a new product. The seminar started late by an hour, the speakers just
rushed through their power point presentations, there was no printed material to
take home and all that the one hundred-odd people from prospective customers got
was cocktails and dinner! It took more than a month more to get detailed
information about the product that was launched during the seminar. Doing a
sample security audit for prospective customers can be costly but worth more
than blowing up money on inefficiently handled events like this seminar.

Advertisment

CONVINCING CUSTOMERS

TO BUY THE SOLUTION

Getting a customer to accept your offer for a sample security audit is not
as easy as it sounds. It involves access to their network and unless the
customer trusts you, he will not let you enter his server room. You need to
prove your credentials for carrying out penetration testing.

Security is an important issue for every business but more so for companies
in the financial sector. You will have guidelines to follow and you will be also
talking to chartered accountants more than IT people. The best way to earn their
trust is to carry out some tests remotely on their IP address, in their presence
and show them the results.

In one such instance, I have seen a sample audit come out with very
convincing results. A server that was assumed to be well protected by the
customer's IT department showed many vulnerabilities, a Spyware program
embedded in the system, an operating system that was never updated with patches
in last three years (Have you ever counted the number of patches Microsoft
releases every day?), the Administrator user name was 'Administrator' and
the password was very weak, it was the company name itself!

Advertisment

MTNL and BSNL have recently announced their 'high speed-low cost-always on'
broadband Internet services. Tata Indicom, Reliance and many others are also in
the race to make the broadband boom a reality in India. This will tremendously
increase the Internet usage and with it the security issues. It's high time
security solutions providers also got into the act to make the cyber world a
safer place to live in. The only problem may be, how to get the CEOs, CIOs and
CFOs together and talking!

Ashok Dongre is an independent
consultant