Monday, November 3, 2008

...but I already have a firewall

I talk to a lot of people about identity theft and fraud these days. Most individuals and companies don't really know, but somehow think they are protected.

"I'm pretty sure we have a good firewall - our IT guy is great!"

He/she might be great - but then why do I keep reading statistics about the millions of compromised computers? hmm - something to think about!

This morning I'm getting ready to go see a new prospect. On the phone she said that they had a good firewall so they should be ok. But then I asked her if she and her fellow employees had the ability to
  • to install their own software?
  • view attachments in email?
  • use their personal phones to text clients?
  • what are they doing with wi-fi?
These are all areas where even with a solid firewall you still may be exposed. The only way to determine if a business is 'secure enough' is to analyze all the potential threats for that specific company, and create a threat matrix.

In building a threat matrix I have to look at all the inbound and outbound data sources. This includes cell phones, networks, all the devices an employee uses, usage patterns, the employees themselves as well as normal internet usage. (eg. the things an up to date firewall could potentially stop)

Oh, here's one more thing to think about as a consumer of online services - the bad guys are now using text messaging to persuade people to call them and give up their NPI!
... text message phishing, occurs when customers receive a text message from what seems to be a reputable financial institution prompting them to call a telephone number due to a possible fraudulent transaction on their account.

SourceWire | Press Releases - Mobile phone identity theft on the increase

No comments: