16.02.2013

Facebook - hacked - are you?

Facebook - hacked - are you?

twitter icon

Facebook recently announced that they had been subject to a highly sophisticated attack. Whilst facebook's internal security teams has been able to respond and contain the attack, many small business don't have the resources to do the same. Just recently I was contacted by another Manchester professionals member and when looking at the website listed in her companies profile, our security filters blocked access as the website had some sort of malware installed. Websites are a valuable part of any electronic marketing strategy and having them blocked, or hijacked by hackers represents a significant loss of investment for any business. However if you don't have the means to detect it you could be referring clients or prospects to your site and infecting them potentially damaging your own reputation in the process. As part of our forensic investigations we many numerous companies that have suffered security breaches, typically that lead to the theft of credit card data, personal data (such as mailing lists, contact details or CRM data). Many of these breaches could have been prevented through the application of sensible security practices being applied. Don't just leave the security to your IT provider and expect that they will do it "out of the box". Very recently we investigated a company whose IT provider had left very weak passwords on the remote access software which meant that almost anyone could log into their network. When queried the IT provider had never been audited by their customer, or subject to any level of review. Nothing was in the contract mandating any security levels and so everything was done to the lowest common denominator. Securing information appropriately is an expectation under the data protection act if you are looking for guidance then the international standards ISO 27001 & ISO27002 are a good starting point. If you would like to discuss how a security breach could affect you, or how to comply with security standards such as the PCI DSS or ISO27001 then please feel free to get in touch (07889 183207 - andrew.barratt@ptpconsultingllp.com).

Contact Details Mobile - 07889 183 207 Skype - andrewbarratt andrew.barratt@coalfire.com Andrew is an experienced IT and Information Security Consultant, PCI DSS advisor and QSA. As a…

Follow us for more articles and posts direct from professionals on      
Business Management

Coca Cola - CEO hacked

The BBC has recently published that the CEO of coca cola http://www.bbc.co.uk/news/technology-20204671 suffered an IT…
Business Management

It could be you... Euromillions website gets hacked.

The BBC is reporting that http://www.bbc.co.uk/news/world-europe-20118960 the Euromillions French website has been…
Business Management

Tricks of the infosec trade - by Pen Test Partner Ken Munro

Sending hackers on a wild goose chase, and ‘playing dead' in front of thieves, are brilliant ploys – but they're not…

More Articles

Business Management

Greater Manchester Police force pays £120,000 penalty for...

An ICO investigation into a data breach at Greater Manchester Police has concluded with the force being fined for…
Business Management

BYOD - Bring Your Own Disaster!

Bring Your Own Device - perhaps we should call it "Bring Your Own Disaster!" There have been lots of good reasons…
Business Management

Social media perils!

The media has been crawling all over Ashley Cole the England left back criticising him heavily for use of certain…

Would you like to promote an article ?

Post articles and opinions on Manchester Professionals to attract new clients and referrals. Feature in newsletters.
Join for free today and upload your articles for new contacts to read and enquire further.