{"id":2349,"date":"2011-08-24T07:00:30","date_gmt":"2011-08-24T15:00:30","guid":{"rendered":"http:\/\/www.formtek.com\/blog\/?p=2349"},"modified":"2011-08-24T07:00:30","modified_gmt":"2011-08-24T15:00:30","slug":"security-people-continue-to-be-the-weakest-link","status":"publish","type":"post","link":"https:\/\/formtek.com\/blog\/security-people-continue-to-be-the-weakest-link\/","title":{"rendered":"Security:  People Continue to be the Weakest Link"},"content":{"rendered":"<p>A recent spate of hackings and breakins, including highly secure organizations like the <a title=\"Hacking the pentagon\" href=\"http:\/\/news.yahoo.com\/blogs\/technology-blog\/pentagon-loses-24-000-classified-files-massive-hacking-212127976.html\" target=\"_blank\">Pentagon<\/a>, <a title=\"EMC's RSA hacking\" href=\"http:\/\/bits.blogs.nytimes.com\/2011\/04\/02\/the-rsa-hack-how-they-did-it\/\" target=\"_blank\">EMC&#8217;s RSA<\/a> and <a title=\"Lockheed Martin cyber attack\" href=\"http:\/\/www.informationweek.com\/news\/government\/security\/229700151\" target=\"_blank\">Lockheed Martin<\/a>, has clearly shown that every organization is vulnerable. \u00a0Often it&#8217;s not the technology, the encryption and authentication methods or the firewalls which are the problem. \u00a0While having security technologies in place is essential for cyber-protection, but more often than not, security lapses are the result of human error.<\/p>\n<p>Much of the problem is that users are often not properly\u00a0trained on security. \u00a0 <a title=\"Venify Security Survey\" href=\"http:\/\/www.venafi.com\/News\/Press_Releases\/2011-07-28\/Majority-of-Enterprises-Failing-to-Apply-IT-Security-Best-Practices.aspx\" target=\"_blank\">A survey by certificate management company Venifi<\/a> found that few companies do regular training with their employees on security best practices. \u00a0In fact, the report found that few companies were following five of the best practices for ensuring secure operations:<\/p>\n<ol>\n<li>Perform quarterly security training with employees. \u00a0[77 percent of companies are not doing this.]<\/li>\n<li>Encrypt all cloud data and cloud transactions. \u00a0[64 percent of companies are not doing this.]<\/li>\n<li>Use encryption throughout the organization. \u00a0[10 percent of companies are not doing this.]<\/li>\n<li>Have a business continuity plan in place should security certificates be compromised. \u00a0[55 percent of companies are not doing this.]<\/li>\n<li>Rotate SSH keys every 12 months. \u00a0[82 percent of companies are not doing this.]<\/li>\n<\/ol>\n<p><a title=\"Rich Mogull\" href=\"http:\/\/www.linkedin.com\/profile\/view?id=227016&amp;authType=name&amp;authToken=icjj&amp;locale=en_US&amp;pvs=pp&amp;trk=ppro_viewmore\" target=\"_blank\">Rich Mogull<\/a>, security editor at TidBITS and former Gartner research vice president, <a title=\"Rich Mogull quote on security\" href=\"http:\/\/www.zdnet.co.uk\/news\/security-management\/2004\/11\/01\/greatest-security-risk-social-engineering-says-gartner-39172157\/\" target=\"_blank\">said<\/a> that \u00a0&#8220;People, by nature, are unpredictable and susceptible to manipulation and persuasion. Studies show that humans have certain behavioral tendencies that can be exploited with careful manipulation. \u00a0Many of the most-damaging security penetrations are, and will continue to be, due to social engineering, not electronic hacking or cracking.&#8221;.<\/p>\n<div id=\"_mcePaste\">Security Editor at TidBITS<\/div>\n<p>&#8220;People, by nature, are unpredictable and susceptible to manipulation and persuasion. Studies show that humans have certain behavioural tendencies that can be exploited with careful manipulation.<br \/>\n&#8220;Many of the most-damaging security penetrations are, and will continue to be, due to social engineering, not electronic hacking or cracking,&#8221; said Mogull.<br \/>\nSecurity Editor at TidBITS<\/p>\n<div class=\"lightsocial_container\"><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/digg.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/digg.png\" alt=\"Digg This\" title=\"Digg This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.reddit.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/reddit.png\" alt=\"Reddit This\" title=\"Reddit This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.stumbleupon.com\/submit?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F&amp;title=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/stumbleupon.png\" alt=\"Stumble Now!\" title=\"Stumble Now!\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/buzz.yahoo.com\/buzz?targetUrl=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F&amp;headline=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/yahoo_buzz.png\" alt=\"Buzz This\" title=\"Buzz This\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dzone.com\/links\/add.html?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dzone.png\" alt=\"Vote on DZone\" title=\"Vote on DZone\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.facebook.com\/sharer.php?t=&amp;u=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/facebook.png\" alt=\"Share on Facebook\" title=\"Share on Facebook\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/delicious.com\/save?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/delicious.png\" alt=\"Bookmark this on Delicious\" title=\"Bookmark this on Delicious\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.dotnetkicks.com\/kick\/?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetkicks.png\" alt=\"Kick It on DotNetKicks.com\" title=\"Kick It on DotNetKicks.com\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/dotnetshoutout.com\/Submit?title=&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/dotnetshoutout.png\" alt=\"Shout it\" title=\"Shout it\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.linkedin.com\/shareArticle?mini=true&amp;url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F&amp;title=&amp;summary=&amp;source=\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/linkedin.png\" alt=\"Share on LinkedIn\" title=\"Share on LinkedIn\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.technorati.com\/faves?add=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/technorati.png\" alt=\"Bookmark this on Technorati\" title=\"Bookmark this on Technorati\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/twitter.com\/home?status=Reading+https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/twitter.png\" alt=\"Post on Twitter\" title=\"Post on Twitter\" \/><\/a><\/div><div class=\"lightsocial_element\"><a class=\"lightsocial_a\" href=\"http:\/\/www.google.com\/buzz\/post?url=https%3A%2F%2Fformtek.com%2Fblog%2Fsecurity-people-continue-to-be-the-weakest-link%2F\" target=\"_blank\"><img decoding=\"async\" class=\"lightsocial_img\" src=\"https:\/\/formtek.com\/blog\/wp-content\/plugins\/light-social\/google_buzz.png\" alt=\"Google Buzz (aka. Google Reader)\" title=\"Google Buzz (aka. Google Reader)\" \/><\/a><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>A recent spate of hackings and breakins, including highly secure organizations like the Pentagon, EMC&#8217;s RSA and Lockheed Martin, has clearly shown that every organization is vulnerable. \u00a0Often it&#8217;s not the technology, the encryption and authentication methods or the firewalls<span class=\"ellipsis\">&hellip;<\/span><\/p>\n<div class=\"read-more\"><a href=\"https:\/\/formtek.com\/blog\/security-people-continue-to-be-the-weakest-link\/\">Read more &#8250;<\/a><\/div>\n<p><!-- end of .read-more --><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[31],"tags":[],"class_list":["post-2349","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/2349","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/comments?post=2349"}],"version-history":[{"count":0,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/posts\/2349\/revisions"}],"wp:attachment":[{"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/media?parent=2349"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/categories?post=2349"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/formtek.com\/blog\/wp-json\/wp\/v2\/tags?post=2349"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}