Information Security for SMEs

>that has been altered in subtle ways (imagine your
This article explores computer security, aiming to giveaccounts with 10% taken off each figure), a website
businesses an insight into why they must be proactivethat is 'owned' by a teenager in another country or an
in protecting their systems. There are many aspects tooffice full of computers that no longer do the job for
security on the Internet and a lot has been madewhich they were intended.
recently of the security of e-commerce transactions.Almost worse than losing all your data (because we
Whilst many of the security issues that a websiteknow you keep a regular backup), is having your
administrator faces are similar to those that yoursystem infected with a worm program. In some cases
businesses computers are threatened with, this columnthis can leave your computer unknowingly sending an
will concentrate on how and why you should secureattack the way of all your contacts. Alternatively, your
your internal IT investment.computer could be under the complete control of a
The Internet in its current state is similar to a city withthird-party, who is using your processor, memory and
no locks on the doors of its houses, where computershard-disk for their own purposes.
can be thought of as houses and the networksWhat can I do to stop it?
making up the Internet, the city streets. Computers asJust as it is not the councils responsibility to stop
they are sold today are inherently insecure, allowingburglars coming down your street, in the UK there is
access to anyone with a bit of curiosity or maliciousvery little responsibility on ISPs to prevent attacks. If
intent. As businesses come to rely more and more onyour systems are not locked (with firewall software),
electronic information (not least e-mail), the potentialalarmed (with an intrusion detection system) and
disruption caused by a data burglary, informationalinsured (by taking a daily backup) you have no-one to
arson attack or digital graffiti has reached a level thatblame but yourself.
businesses should not ignoreThere are three pieces of software that every
The threatbusiness needs to at least consider. I cannot
Any computer on the Internet exposes a series ofover-emphasise the need for an up-to-date virus
ports through which information flows. By default thesescanning program. Most reputable products will scan
are all open and unlocked. Whilst many of them mayfor and remove some Internet worms and some
lead to empty rooms or brick walls, an attacker willTrojan horses; however they will not detect other
only need to find one port vulnerable to attack for thetypes of attack. For those attacks a good firewall
whole system to be compromised.package is essential. Installing one of these programs is
Even if your ports are secure; intruders can get intoakin to fitting locks to your doors and windows. Finally
your computer in a Trojan horse. A piece of softwarean intrusion detection system (IDS) is similar to an
disguised as something useful can contain a maliciousalarm system, warning you of a potential attack.
sub-program to install a backdoor into your system.In my opinion all businesses should have a solid
Often these programs claim to give something foranti-virus policy as well as a good firewall. Whichever
free or display small games whilst an attacker has asolution you choose at the end of the day, you must
good nose aroundfully understand its capabilities or it will be as effective
One of the most worrying developments has been theas not having anything at all.
proliferation of automated attacks. These can be runKeep an eye on patches
from an attacker's computer, scanning hundreds orMost electronic attacks exploit a mistake in the
thousands of computers in a day; or can be theprogram code of the software you use. Responsible
self-replicating Internet worm. These are a hybrid ofsoftware vendors will issue a 'patch' that resolves
virus programs and computer security attacks. Ineach issue as soon as it is brought to their attention.
worst-case scenarios, they can bring whole segmentsYou will find that many software companies have
of the Internet to a standstill.e-mail lists that you can subscribe to in order to be
Attacks on your information can be carried out for asnotified of new problems and patches.
varied reasons as an arsonist burns things, a robberThis patching mechanism makes up the software
steals things or kids spray-paint walls. An electronicindustry's response to the hacker community. If you
attack could leave you with no data (imagine losingare applying your patches diligently, the security of
your accounts the day before your filing date), datayour computer systems depend on how far ahead
that has been altered in subtle ways (imagine youreither side is. It is therefore good practice to have a
accounts with 10% taken off each figure), a websitecomplete security audit of your systems by an
that is 'owned' by a teenager in another country or anexternal consultant twice a year or more often if you
office full of computers that no longer do the job forrely heavily on your data.
which they were intended.It won't happen to me
When we drive a car we are accepting and using aYour business network is constantly being probed by
set of standards that have evolved since the turn ofhackers on the Internet looking for ways into your
the century to ensure safety, convenience and fairdata. Most attacks occur without the user even
access for all users of the road system. Some ofknowing that a system is compromised. Our systems
these standards are globally accepted (for instance aat FWOSS get probed three or four times a week, so
road is made from tarmac and wheels are made fromour firewall is invaluable in ensuring they get no further.
rubber) whilst others vary from country to country (forWhat can I do in the case of an attack?
example if we drive on the left or the right). TheOf course your regular backup provides your ultimate
practical upshot of these standards is that a carsafety-net, but as the effects of different electronic
designed and built for use in one country can be safelyattacks are so varied there are no hard and fast rules
used in another (possibly with a little bit ofto recovery.
inconvenience).It is very much a case of prevention being better than
The aftermathcure; therefore you should think about installing an
Attacks on your information can be carried out for asanti-virus program, firewall and intrusion detection
varied reasons as an arsonist burns things, a robbersystem. You should keep a daily backup; check if your
steals things or kids spray-paint walls. An electronicsystems need patching weekly; and have a security
attack could leave you with no data (imagine losingaudit bi-annually or more frequently.
your accounts the day before your filing date), data