If you were told that a new venture for your business would reap nearly 1,500 percent returns, would you pull the trigger? Cybercriminals certainly do. According to a new report from Trustwave Holdings Inc., this is the ROI that an enterprising hacker can get on certain types of breaches involving ransomware, which essentially involves taking data hostage by encrypting it until the rightful owner pays up.
The potential profits from breaches are not the only unnerving statistics revealed in the “2015 Trustwave Global Security Report,” in which the security company analyzes data collected from 574 breach investigations across 15 countries last year.
For starters, it appears that some companies are failing to figure out that they’ve been breached. “Anytime you discover a breach yourself, you’re going to get a jump on things,” Charles Henderson, vice president of managed security testing at Trustwave, told CorpCounsel.com. Clearly, some companies are falling behind. In 81 percent of the investigations studied, the victim organization didn’t detect the incursion internally.
This has real consequences. According to the data, self-detected breaches only lasted a median of 14.5 days from intrusion to containment. Those that were externally detected lasted a median of 154 days. Henderson added that those companies with their own detection capabilities (or with their own managed security services to detect breaches for them) create their own hacker deterrence.
“I think the reason that most companies don’t self-detect is that the companies that are in the position to self-detect in the first place don’t tend to get breached, because they remain in a much better position from a security perspective,” Henderson said.
The report also looked at where breaches are occurring, and concluded that the U.S is still a big target with half the compromises happening within U.S. borders. However, this is a 9 percent decrease from last year. Other countries, such as Australia and the U.K., with 24 percent and 14 percent of attacks, respectively, are taking more of the heat.
Looking at the industries being breached, the most compromised, according to Trustwave, is retail, with 43 percent of investigations in 2014, up from 35 percent in 2013. Henderson said that retailers place a lot of time and energy into their core business and the bottom line. “So security becomes an afterthought,” he said. “But I think more and more you’re seeing retailers paying more attention to security.” Behind retail was the food and beverage industry, followed by hospitality, two other sectors that might not yet be accustomed to focusing on customer data protection.
The report also delved into a perennial problem for companies: trying to encourage the use of better passwords among employees to mitigate breach risk. By looking at thousands of passwords found in penetration testing over the past year, Trustwave found that “Password1” still reigns as the most used password, followed by “Welcome1,” likely because simple passwords are set by network administrators and then never get changed by employees.
If they weren’t using variations on words like “password,” employees often used variations on names and places. Some 8.4 percent of passwords used names from the top 2,000 baby names, and 4.9 percent used U.S. city names. These credentials may be easier for hackers to figure out.
Password length was a big issue as well. Most passwords did not exceed eight characters, the number often required by policy. The report pointed out that the estimated time it takes to crack an eight-character password is a single day, while a password that is slightly longer, at 10 characters, is much safer, taking an estimated 591 days.
Motivating a sales team boosts productivity substantially. Providing goals and encouraging salespeople to meet them by offering various types of incentive compensation for their efforts is an effective way to increase the volume of a business's total sales.
A business can pump up its team using three different methods to incentive employees and bolster the company:
1. Have a contest Sometimes a little healthy competition is exactly what a sales team needs to increase productivity. According to Business News Daily, organizing a contest is a fun way to involve all employees and inspire sales staff to reach a quota.
"We've tried running sales contests in the past, using various software and tools," said Rick Hanson, vice president of worldwide sales and field operations at Hewlett-Packard Enterprise Security, according to Business News Daily. "There was a single goal and the reps who achieved that goal were rewarded, usually with money."
While a financial incentive for the winner may be one way a business can motivate individuals to participate in the contest, there are other noncash alternatives that may work as well – potentially even better. Some potential prizes an operation may consider offering include:
Tickets to a sporting event, concert or local festival
Time off from work
Dinner on the boss
A prize basket
The chance to become boss for the day
Bragging rights
Performance and compensation management software may be a great way to keep track of progress throughout the duration of a contest. While this may be a good way to motivate salespeople, it may wind up awarding the same top-performing reps and discourage others from participating. Consider creating leagues to assign sales reps to based on past performance.
The Harvard Business Review noted offering prizes that aren't cash may be especially beneficial if a business holds multiple contests among different groups of salespeople.
2. Create a fun environment Making work something employees look forward to can serve as a fantastic motivator. A business can set group goals and offer a prize like a pizza party or ping-pong table for the office. Motivating all employees together is also a great way to unify staff and foster strong relationships among employees.
3. Recognize spouses, partners and kids Businesses should also consider reaching out to the family of sales reps. Including them in on the fun can encourage them to motivate the team at home as well. This is a fun way to deepen the relationships a business has with its employees, according to Business News Daily.
4 Ways IT Teams and CIOs Can Improve the Security Status Quo
By Perry Dickau
Few conversations are more stressful for IT pros and CIOs than the ones immediately following a data breach. The unauthorized exposure of customer or employee personally identifiable information (PII) or intellectual property/trade secrets is a worst-case scenario for most companies, so it’s only natural that proactive data protection is a priority. As the recent RSA Conference made clear, it’s no longer enough to enlist reactionary security strategies or focus solely on preventing hacks at the perimeter. Instead, your company must minimize threats by protecting data where it lives.
The only way to avoid that awkward post-breach conversation is to stop it from happening in the first place. Here are four important ways to start improving your data security landscape before a breach occurs.
Protect data at its core.
Data lives and moves within a layered ecosystem – from where it is stored, through networks, servers, applications, and firewalls – as it is managed and consumed throughout its lifecycle. Does your team prioritize the application or firewall layers at the top of the IT stack when you’re developing security protocols? This strategy has been proven largely ineffective, so it’s time to make changes to the security status quo.
Securing the perimeter is an integral part of data protection, but this method alone is one-dimensional and outdated, and it can leave your business powerless against new threats. Eliminating the possible effects of a breach at the center of the IT stack is more effective, and it’s a more prudent use of time and money. Securing PII and other sensitive data where it’s created means that even if an outsider gains entry to your network, he won’t readily be able to steal information.
Don’t follow hackers’ leads.
It’s important to update security protocols as new threats emerge, but this can’t be the only weapon in your arsenal. Status quo security methods can only stop known threats, and playing catch-up to the evolving security landscape is a losing proposition for IT teams and CIOs. Instead, stay ahead of cybercriminals by creating a holistic approach that uses actionable insights to protect infrastructure on both the inside and outside.
Consider the security of your ecosystem, not just your IT.
The Ponemon Institute reports that 78 percent of data breaches are caused by employees saving information in a vulnerable domain or deleting critical files, while hackers are increasingly adroit at getting into corporate IT systems through other paths. For example, back-door approaches like exploiting unused accounts practically invite hackers to gain entry undetected.
Data-aware technology secures data as it’s created, increasing protection and eliminating threats. If your efforts are devoted to keeping threats out, your core ecosystem won’t be prepared to withstand a breach when one manages to get in. The companies that have suffered high-profile hacks in recent months are a major reminder that change is needed in the security industry, and it’s time to do something different in order to get – and stay – ahead of inbound threats.
Accept that you can’t stop a breach in its tracks.
This isn’t an easy thing for a company to accept. CIOs want to know their teams can identify issues as they occur and bring them to a halt instantly. Unfortunately, this isn’t a reality for anyone. Even detecting a breach or hack while it’s happening has proven difficult. Frequently, the only way to discover these issues is through monitoring event logs or after the subsequent fallout. Adopting a security protocol that improves data visualization can help you prevent data breaches before they take hold, which becomes far more valuable than trying to stop them as they occur.
Data Lake has become one of the latest buzzwords for data management. It is probably the most misunderstood concept. The reason for that is it could be different for each organization. It depends on how much data exists, what the bottlenecks are and how is it going to be used. The good news is that technology exists today that can enable a wide variety of use cases, a good example is the Hadoop ecosystem.
In pharmaceutical and biotechnology research organizations, there has been a explosion of data long before it hit other industries. From sequencing of the human genomes over multiple years to now sequencing multiple genomes per week, that generated terabytes of raw data, which needed to be managed in a way so it could be analyzed at least as fast as it was getting produced. Now with Hadoop based solutions, this is somewhat a solved problem, but it was not the case when sequencing technologies started evolving more than 10 years ago. Then there are experiments that get conducted through various departments in the quest to characterize functions of genes for example. Scientists need a flexible environment to store their results, and record their insights and be able to quickly share those insights with other groups within the organization. The experimental data requires a structured data management treatment, but the insights are largely unstructured text that need to be then analyzed as such, which is where a data lake solution can provide value.There are new technologies being introduced in laboratories all the time, and there is a need to quickly integrate the data from these systems. Traditionally, the way to manage experimental protocols and data has bee to develop large enterprise LIMS systems that take several years to develop and are generally obsolete by the time they are deployed. A data lake in this context could be a re-imagined LIMS system that does not require thousands of hours of programming to integrate new sources of experimental data. One can argue you can still dump the output from experiments in a Hadoop environment, but managing samples through a laboratory workflow and seamlessly integrating instrumentation within that workflow all the while tracking the details of each process is needed for regulatory reasons. Data lake in a biotechnology research organization has the potential to accelerate productivity by removing bottlenecks in data movement through the organization, but it has to be designed for efficiency like any IT system. A high performance data storage and analysis environment is needed for both exploratory analytical experiments as well as production data analysis processes, both of which can potentially utilize variants of the data lake concept utilizing the Hadoop ecosystem.
In the magazine publishing industry or any consumer retail industry, the understanding the value of efficiently managing and utilizing large amounts of data is in its infancy by comparison to the the biological sciences mentioned above. In most cases, marketers are the key users of data for in any consumer retail industry. In the magazine publishing industry, traditionally, they would sales data and use segmentation to group their customers and maybe use some demographic data from other sources to further refine groups, and then either cross-sell or up-sell or flat out ignore bad payers for example. Very little statistical modeling was involved in this relatively simple model. In the last decade, there has been a explosion of data now available that can potentially characterize these customers even better beyond just the purchase history. The challenge here is to develop a analytical methodology that can extract the signal from the noise. A bigger challenge is even knowing what the signal is you are looking for, and how do you know it is significant. In such a environment, the role of the data lake is really less of data management, more of a playground that enables data scientists to use large data sets and run exploratory analyses to run data experiments, develop new methods and test them rapidly with new sources data as they become available. In this context, the data lake maybe more of a data repository that ingests data from all sources, internal and external, structured and unstructured and provides enough resources for data scientists. Most consumer retail organizations are not as mature as Google, Amazon etc, hence the data lake maybe more of a simplistic solution to get started. The key for such companies is to start small and carefully define specific use cases to be implemented first as they launch the data lake journey.
The current marketing materials from Hadoop vendors will try to convince you they have the data lake strategy for you, but in fact every IT organization in conjunction with the business needs to define what it is going to be. Managing and analyzing large amounts of data is a key requirement for business success now, but it each business needs to define what that means for them. Technology continues to evolve at a rapid pace, utilizing the power of opensource. As new use cases for data and analytics are explored, new components are being added to the Hadoop ecosystem as we speak. There is a lot of confusion and opinions regarding the Hadoop environment due to that. An experience that an organization may have had with Hadoop 2 years ago maybe no longer relevant as the solution set has evolved. Picking a vendor that stays somewhat current with the technology trends is an important consideration, as you launch your data lake strategy.
CIOs and C-level execs are enamored by the data lake term, but unfortunately, it is not something you can just buy off the shelf and check a box: "we now have a data lake"!
We’ve been working in an area of untapped potential for Big Data for the last couple of years, which can best be summed up by the phrase “Contact Big Data Quality”. It doesn’t exactly roll off the tongue, so we’ll probably have to create yet another acronym, CBDQ… What do we mean by this? Well, our thought process started when we wondered exactly what people mean when they use the phrase “Big Data” and what, if anything, companies are doing in that arena. The more we looked into it, the more we concluded that although there are many different interpretations of “Big Data”, the one thing that underpins all of them is the need for new techniques to enable enhanced knowledge and decision making. I think the challenges are best summed up by the Forrester definition:
“Big Data is the frontier of a firm’s ability to store, process, and access (SPA) all the data it needs to operate effectively, make decisions, reduce risks, and serve customers. To remember the pragmatic definition of Big Data, think SPA — the three questions of Big Data:
Store. Can you capture and store the data?
Process. Can you cleanse, enrich, and analyze the data?
Access. Can you retrieve, search, integrate, and visualize the data?”
As part of our research, we sponsored a study by The Information Difference (available here) which answered such questions as:
how many companies have actually implemented Big Data technologies, and in what areas
how much money and effort are organisations investing in it
what areas of the business are driving investment
what benefits are they seeing
what data volumes are being handled
We concluded that plenty of technology is available to Store and Access Big Data, and many of the tools that provide Access also Analyze the data – but there is a dearth of solutions to Cleanse and Enrich Big Data, at least in terms of contact data which is where we focus. There are two key hurdles to overcome:
Understanding the contact attributes in the data i.e. being able to parse, match and link contact information. If you can do this, you can cleanse contact data (remove duplication, correct and standardize information) and enrich it by adding attributes from reference data files (e.g. voter rolls, profiling sources, business information).
Being able to do this for very high volumes of data spread across multiple database platforms.
The first of these should be addressed by standard data cleansing tools, but most of these only work well on structured data, maybe even requiring data of a uniform standard – and Big Data, by definition, will contain plenty of unstructured data which is of widely varying standards and degrees of completeness. At helpIT systems, we’ve always developed software that doesn’t expect data to be well structured and doesn’t rely on data being complete before we can work with it, so we’re already in pretty good shape for clearing this hurdle – although semantic annotation of Big Data is more akin to a journey than a destination!
The second hurdle is the one that we have been focused on for the last couple of years and we believe that we’ve now got the answer – using in-memory processing for our proven parsing/matching engine, to achieve super-fast and scalable performance on data from any source. Our new product, matchIT Hub will be launching later this month, and we’re all very excited by the potential it has not just for Big Data exploitation, but also for:
increasing the number of matches that can safely be automated in enterprise Data Quality applications, and
providing matching results across the enterprise that are always available and up-to-date.
In the next post, I’ll write about the potential of in-memory matching coupled with readily available ETL tools.