


|
This seems that most SMBs are simply arrogant and un-educated when it comes to varying attacks -- granted they probably would not be as targeted as a HUGE corporation or anything but the fact that SMBs make money (a lot or a little) still makes the business a target none-the-less.... It is like me saying since I live in a small town in MN, I don't need to drive my car carefully and will never get in an accident because the majority of accidents occur in NYC....its just not common sense! Especially now with the increasing variety of potental attacks -- namely the newcomers being cellphones/PDAs being easy targets......... |
|
Yeah you don't even need to social engineer some SMBs to get valuable info. You can merely call or email people and ask for it most of the time they'll freely give it to you no questions asked. I have a friend who does Penetration testing for a security firm. and he says the easiest thing to do is find the email address of an executive officer in the company and forge an email from their security team, helpdesk, ops group requesting their login info and someone will always bite and send it. |
|
It is this mixture of arogance and ignorance that always gets people into trouble. One of the most disturbing stats is that so many didn't think their data has any value for criminals. I hear this a lot from home users. Almost all businesses, even small ones, have competitors and I am sure they see value in their data. Not to mention the fact that cyber criminals may not even be interested in the data at all. A small company with say 20 computers would make a nice additon to a botnet. Or even as an anonymous way to comunicate terrorist plots or other illegal activity. Security is everyones concern. Period. Any part of the poulation, business or otherwise, that thinks differently is helping the criminals do their work. Until that changes Identity theft and cyber-crime in general will continue to rise. Education is the best tool we have and all the software in the world won't stop cyber crime until that is addressed. |
The problem is people have to be willing to be educated -- generally I would say that 95% of people (once they have a certain mindset) require a HUGE life-altering event to take place before they change their mind to reason with common sense (i.e. a large attack on their small-scale network or perhaps a DoS attempt...) Something to tie into this -- I regularly have people that "own their own businesses" come into work needing one of their main workstations to be fixed under warranty. I tell them that I have to ship it off and strongly recommend that they back up their data before doing so (most of the time I find out these people have NEVER backed up their data in the first place). Anyway for $100 they gasp and say "no way!! OMG that way too much!". I say fine, ship it off -- low and behold it comes back witha replaced HDD and there's now a 0% chance to get data back as the repair center destroys bad HDDs for customer privacy. Guess what? These people that scoffed at $100 now tell me that there was 5 yrs worth of data on there, never backed up, that is going to cost their company THOUSANDS of dollars.... I guess $1000 < $100 in their heads -- similiar to SMBs and implementing good security within their networks; why pay a relatively smaller amount to make sure attacks are prevented and a network is set up more robust, when you can spend TEN TIMES that amount on repairs after the attack has taken place.....dumb |
|
Excellent points Ice. I've dealt with the same crap as well. They scoff as well at spending a few hundred to a few thousand dollars for a good backup sollution with redundency because the $99 external hard drive they got on sale is fine for their needs. I guess no one ever told them hard drives sometimes fail and take your data with it. I even had a customer that swore he was fine with his external hard drive for back-ups and when I looked at his setup, he never set up the backup software at all. The Hard drive was sitting there not doing a thing. Nada. I guess I should love these people as they keep me in beer nuts..... |