UK businesses at mercy of hackers

UK businesses at mercy of hackers

A third of UK businesses are leaving themselves exposed to hackers by failing to crack down on medium and low-level security flaws, according to the results of a network monitoring survey.

Link: Businesses ignore new security standard

The fifth annual Security Audit survey by consultant NTA Monitor found that, despite tackling major security vulnerabilities, UK companies are failing to address smaller flaws.

The audit examined data from more than 600 regular network perimeter security tests carried out by the company at client sites during 2002. One-third of corporate networks tested were found to have at least 10 flaws.

‘A third of companies we examined were guilty of bad security housekeeping,with unacceptably high levels of basic flaws found,’ said Roy Hills, technical director at NTA Monitor, in the report.

‘Although corporates are clearly prioritising security vulnerabilities and addressing high-profile issues this is at the expense of a much larger number of lower-profile vulnerabilities, which are being ignored.

‘The net result is that corporate networks remain exposed to external attack.’

Just 6% of businesses had a high-risk vulnerability which could allow hackers to access and take control of computer systems – down from 19% the previous year.

But medium-profile vulnerabilities were found in 73% of tests, and low-profile vulnerabilities were found in every test instance.

Vulnerabilities in router and firewall systems remain at an ‘unreasonably’ high level, often because they are installed with a standardised configuration geared towards functionality and up-time, said the survey.

Medium-risk issues allow external users to disrupt services or internal users to gain unauthorised access to systems, and a low-risk issue provides information that could be useful to a hacker in attempting an external attack, according to NTA Monitor.

The survey found that the main low-level flaws causing problems are DNS vulnerabilities, which have risen from 70% in 2000 to 83% last year.

The DNS Zone Transfer vulnerability enables hackers to gain a company’s DNS data, such as network names and addresses, which can be utilised in malicious attacks.

Server-related vulnerabilities were the only area to show a fall during the five years of the survey, down to 73% this year from 86% last year. NTA Monitor put this down to the increased level of management attention devoted to websites.

Users should focus on good security design and policy and then configure all systems according to that plan, advised NTA Monitor.

Share

Subscribe to get your daily business insights

Resources & Whitepapers

The importance of UX in accounts payable: Often overlooked, always essential
AP

The importance of UX in accounts payable: Often overlooked, always essentia...

2m Kloo

The importance of UX in accounts payable: Often ov...

Embracing user-friendly AP systems can turn the tide, streamlining workflows, enhancing compliance, and opening doors to early payment discounts. Read...

View article
The power of customisation in accounting systems
Accounting Software

The power of customisation in accounting systems

2m Kloo

The power of customisation in accounting systems

Organisations can enhance their financial operations' efficiency, accuracy, and responsiveness by adopting platforms that offer them self-service cust...

View article
Turn Accounts Payable into a value-engine
Accounting Firms

Turn Accounts Payable into a value-engine

3y Accountancy Age

Turn Accounts Payable into a value-engine

In a world of instant results and automated workloads, the potential for AP to drive insights and transform results is enormous. But, if you’re still ...

View resource
8 Key metrics to measure to optimise accounts payable efficiency
AP

8 Key metrics to measure to optimise accounts payable efficiency

2m Kloo

8 Key metrics to measure to optimise accounts paya...

Discover how AP dashboards can transform your business by enhancing efficiency and accuracy in tracking key metrics, as revealed by the latest insight...

View article