Analyzing & Visualizing Data - Topic PPT

profilekushi2286
Week4Discussion.pptx

Computer Security Threats

By Mounika Mogilipalli

ABC Company

ABC Company

ABC Company is a firm that deals with web development.

The company has a competent team of web developers and programmers who specialize in the development, testing and deployment of World Wide Web applications.

ABC Company began five years ago but it has managed to secure a pool of talented developers. Using these employees, the company has completed projects for some of the big firms in the country.

Security Issue

The top management at ABC believes that employees deserve to be free to work from home or areas they feel comfortable provided that they get the work done.

Therefore, the company uses laptops and Notebook computer systems which are issued to each employee for convenience in executing their duties.

The employees have remote access to the company’s network of resources remotely.

Cont’d

The use of laptops and notebook computer systems by all employees of the company has promoted a culture where employees only show up for work two or three days in a week.

Other than the decentralized nature of the company, the projects seems to be running smoothly and on schedule. The managers reports that giving employees the freedom has increased their level of productivity.

Cont’d

I am concerned that the use of laptops and notebook computer systems by the employees of ABC put the company at risk of a cyber attack.

ABC has recently began taking projects from some of the big firms in the country. These clients have highly valuable data which they would protect at any cost. The fact that ABC is developing world wide web applications for such companies makes the company a target by cyber criminals.

Why BYOD is tricky?

Laptop and notebook computer systems are light and portable making it easy for the employees to travel with them in different places such as coffee shops.

The portability and convenience of laptops and notebooks makes them easy to steal. Cyber criminals can easily steal a laptop from one of the company employee and use the details to create a backdoor into the company’s network (Jajodia et al., 2011).

A laptop or notebook with an IP address recognized by the company servers would not raise a red flag on the company firewall.

Remote Access

Cyber criminals are known to have resourceful means of getting access into a companies network. For instance, the remote connection of the laptops to the company servers can be used as an access point to launch a Distributed Denial of Service attack (DDoS) (Graham, 2010).

If hackers gain access to one of the laptops, they can create a bot network that can be used to deny services to the company affecting the ongoing projects.

Phishing Attacks

Company employees using laptops and notebooks systems are prey for phishing attacks by cyber criminals. Employees of ABC do not report to work frequently as mot of them opt to work from home. This increases their possibility of falling for phishing attacks when hackers pretend to be an employee from the company (Brenner, 2009).

Difficult to Control employees activities

ABC employees conduct their business activities online. Most of the employees work from home meaning that they use laptops to access different websites for activities such as shopping and even communicating with family and loved ones.

Laptops are issued to the employees for work related activities. However, whatever activities that the employees decided to use the laptops for when they are away from work is up to them. The company has no way of ensuring that the laptops are used for work related activities only (Jang-Jaccard & Nepal, 2014).

Rogue Wi-Fi Connections

Employees of the company are free to visit different places such as hotels. In the event that they are out of network connections, they might be tempted to connect to available Wi-Fi connections provided in places such as coffee shops when they need to hand in their work.

Doing so posses a security threat to the company’s network as hackers might be using such connections for eavesdropping or as an access point for hacking the laptop and the network (Probst et al., 2010).

References

Jajodia, S., Ghosh, A. K., Swarup, V., Wang, C., & Wang, X. S. (Eds.). (2011). Moving target defense: creating asymmetric uncertainty for cyber threats (Vol. 54). Springer Science & Business Media.

Graham, D. E. (2010). Cyber threats and the law of war. J. Nat'l Sec. L. & Pol'y, 4, 87.

Brenner, S. W. (2009). Cyberthreats: The emerging fault lines of the nation state. Oxford University Press.

Jang-Jaccard, J., & Nepal, S. (2014). A survey of emerging threats in cybersecurity. Journal of Computer and System Sciences, 80(5), 973-993.

Probst, C. W., Hunker, J., Bishop, M., & Gollmann, D. (Eds.). (2010). Insider threats in cyber security (Vol. 49). Springer Science & Business Media.