The hidden data organizations don’t realize is vulnerable to hackers

3 min read

Long gone are the days of the small cyberattacks carried out by college kids in their garages. Today, organized criminals and professional hackers are developing frequent, debilitating attacks targeted at companies. Businesses now need to accept that a cyberattack is not an “if,” it’s a “when.”

With the right preparation, organizations can reduce the risk of cyberattacks to a tolerable level with lower exposure. But how? This first step is understanding what vulnerabilities your company faces, including the data and technology you might not even realize is vulnerable.

So where are vulnerabilities hiding?

In the world of organized crime and international business, destabilizing businesses and conducting espionage can often be a business in and of itself. These attacks are typically targeted at sensitive information, often with the goal of gaining unauthorized access to intellectual property for purposes of selling to competitors.

From financial statements to emails, the insider threat risks of leaked critical business data can be catastrophic. Take the risks associated with M&A deals, for example. If information is leaked on a potential asking price, or even information on competitors’ existing bids, that could be hugely detrimental to all parties involved. Not only is the confidential information now out in the public, but also it presents the opportunity for competitors to gain further knowledge on the market landscape.

Phishing emails are virtually undetectable now, arriving in inboxes with proper formatting and very carefully crafted and grammatically correct English. From email addresses to social security numbers, the data derived from these types of attacks can be debilitating to retail consumers if not recovered.

Most recently, popular video streaming service Netflix was hit with an almost undetectable phishing scam. Demands for account information often top the list of email requests from hackers, as many Netflix users unknowingly provide personal details to a third party.

What are some common traits of a phishing email or scam? Beware of unknown senders or those that look familiar but are relaying urgency. Verify by hovering over the sender’s name to reveal the true email address. Remember the golden rule of security – always think and verify before you act.

Internet of Things (IoT) devices, such as internet cameras and programmable thermostats, can serve as an easy gateway into an organization’s back-end systems, enabling attackers to ultimately harvest and even alter data in other systems at will.

One of the latest IoT botnets has been dubbed Reaper. This botnet similar to Mirai, but with one twist.

Continue Reading

Enjoyed this summary? Read the complete article at the source:

Continue at information-management.com →

Yves Mulkers

Yves Mulkers is the founder of 7wData and a widely followed voice in the data and AI community. He curates the 7wData and AI Beat newsletters, reaching hundreds of thousands of data and AI professionals, and writes on data strategy, analytics, AI, and the evolving data ecosystem.