No shying away from cyber protection, say security experts

India is one of the leading countries in the information technology space. The irony is that India till date has no in-built operating system and majority of the population are either using Windows or Ubunto, both developed in foreign countries. VIKANT SAHAY spoke to various stakeholders in the world of cyber security to understand how important it is for us to protect our data, value and assets when we are online

As dependence on IT to conduct business has increased, companies and even individuals need to review their risk posture with cyber security. Ease of faster communication and reduced costs has made IT the backbone of any activity. Nearly every activity has an interface with Internet with the entry of Internet of Things (IOT). 
“We must take cyber security very very seriously be it a school student, individual, corporate or government agency. India must have its own cyber security strategy now and at the moment we do not have it. Many other countries have got it. It should not happen that our banks, stock market, energy grids collapse by an enemy cyber attack. Now we have hostile neighbours and if they start attacking us in the cyber domain what will happen? I also feel that people should be online only when required,” said Dr Muktesh Chander, Director General of Police, Goa. Dr Chander is also a Cyber security expert and has studied the subject very deeply.
The increased IT and Internet usage and the comfort it gives, comes with risks that business houses need to understand and plan to mitigate. Threats are increasingly becoming more sophisticated. It is no longer only the large companies that are the target of the bad guys. We are seeing an alarming increase of IT security incidents in small and medium businesses. There may hardly be a company that has not been the target of an unauthorised intrusion or ransomware (a term used when the company’s website is hacked and controls are taken over by the ransom seeker to release it) attack. 
These attacks can originate from anywhere and are not restricted to geographical boundaries. A company in US is as exposed to an attack as any company in Goa. We can no longer feel safe about our location, size or sector. In the connected world every company is equally accessible to the bad elements.
Many of the larger companies after facing such incidents have invested and ramped up their cyber security risk posture and it may get increasingly difficult for the bad guys to spend resources in trying to get into the network of these large companies. In fact, they need to invest at least two per cent of their earnings in keeping their data safe. There are many SME companies that have not focused on the security of their IT infrastructure and hence are easy pickings for intrusions and attacks.
There are many standards bodies and government agencies too that have been highlighting the importance of IT security and have released standards that can be used by companies as a reference to prepare a cyber security framework. Some of these are ISO 27001, NIST 800, RBI’s guidelines for scheduled commercial banks and urban co-operative banks etc. While developing a cyber security policy, companies need to understand that threats can be both external and internal.
“Threats to IT assets are a reality that companies need to plan for. It is seen that companies that have a cyber security policy in place are better prepared to respond to a cyber security incident as compared to those that don’t.  We cannot isolate ourselves and stay disconnected, rather what is needed is to take a risk-based approach towards cyber security so that we do not hamper conducting business but are aware of the risks and either mitigate them or have a plan in place in case we have a cyber security incident,” said Bidesh Chitnis and IT Security Consultant with Infosec Armour.
Generic malwares slow down your computers and bring down your productivity. Sophisticated ones targeted at businesses, individuals may gather confidential data, financial, personal data and send it to the author who may in turn misuse it. Chitnis gave several examples on such targeted attempts at businesses like Target (a large supermarket chain in US), EQUIFAX etc.
Phishing is a very common bait on the Internet for simple and ignorant people. It is especially painful when one gets duped of cash from their bank accounts. Fake websites which are lookalikes of real ones for e.g. bank websites, people click on links and enter secure data which is collected and used to commit financial fraud and identity thefts. More targeted form of phishing is called spear phishing and has a much smaller audience, target – for example customers of a particular business.
When the target is even more specific, and involves a lot of planning and groundwork. Here specific individuals of high net worth are specifically targeted on the internet to gain personal, confidential, financial data to commit identity or financial frauds.
Also, servers, websites need not be important to be hacked. It is a common misconception that websites, servers that get a lot of traffic and are famous are the only ones that are targets for hacking attempts. There has been a recent study that shows websites that get less than ten human visitors a day are most prone to hack attempts and that 93 per cent of the traffic on these websites are bots (like search engine bots, content scraping bots etc.) and 47 per cent of these are bad bots which attempt hacking.
When we think of hacking, we think it is always done intentionally by nerds sitting in their basement who are pros at hacking computer systems. Most of the times, hack attempts are by a network of bots (Botnets) which are constantly trying to propagate and add more infected servers to their network. Most of these hacking incidents are oversights of solved problems – not having security updates etc.
With the future in IOT and other connected devices, security threats are only going to increase. A simple example- RFID access control cards can be easily cloned in under a minute thereby giving access to unauthorized people to secure areas. IOT devices are usually connected to the internet and hence are as prone to cyber attacks as any other. IOT Devices usually running on very minimal hardware (to reduce cost) which makes it difficult to have full-fledged firewalls and other security measures running on the device itself.
“There is a misconception that storing data in the cloud is not safe. What we fail to understand is any computer that is connected to the world wide web has the same risk irrespective of where it is. We at Teknorix Systems, specialise in building SaaS Applications and migrating large enterprise applications to the cloud. Cloud providers invest in the best infrastructure and moreover security professionals, which smaller companies are not always able to afford. I believe paying cloud providers to securely store your data or run your applications is worth every penny,” said Yashvit Naik, Co-Founder & CTO, Teknorix Systems.

Share This Article