11:34 AM
Connect Directly
Repost This

Broadband Improves Performance Of Both Apps And Malware

Allied Cash's database administrator Christian Alvarez has been working to secure the company's new Web-based user interface in recent months.

Securing the data that can be accessed via Allied Cash's new Web-based user interface has been the most pressing security concern for company database administrator Christian Alvarez during the past several months.

"We've gone from dial-up connections to a broadband solution for employees accessing Allied Cash applications," Alvarez told InformationWeek. Now the company's nearly 500 employees in about 250 locations across the country have speedy access to the hosted applications that let the company offer customers cash advances against their paychecks. "This gives employees more ability to roam on the Internet," he said. And of course, more roaming means a greater exposure of Allied Cash's IT systems to the Web's more malicious elements.

These sorts of concerns are consistent with those expressed in InformationWeek Research's latest annual Global Information Security survey, conducted with consulting firm Accenture. Of the companies feeling more vulnerable to attack today, 70% cite the increased sophistication of threats, including SQL injections, while 58% worry about the growth in the number of ways to attack corporate networks, including wireless networks. About half of the U.S. respondents are concerned with the increased volume of attacks, while little more than one-third worry about the malicious intent of their peers using the Web.

To counteract these threats, Allied Cash uses SurfControl's WebDefense Web-filtering application, "which has different sites broken down by categories, like gaming sites or dating sites, that we have locked down," Alvarez said. "These are sites that could have malicious software on them and that employees shouldn't be using from work. We found that our users were going to non-work-related sites, and we were getting a lot of requests because their PCs were going down," Alvarez said. That's when the company decided to implement WebDefense.

With broadband access to the Internet, employees are more open to malicious Web content while they're using the Web to access software used to record customer transactions, including payment, marketing materials, and collection calls. "We deal with financial information about our customers, so you have to go beyond simple antivirus software for security," Alvarez said. "If employees are doing anything not work-related, they run the risk of downloading malware such as a keylogger that can be used to steal login information."

To control this, Allied Cash's point-of-sale system is IP-address-controlled at the network firewall, Alvarez said. Allied Cash only allows users to access its applications if they're coming from an approved IP address. "If someone tries to log into our site from an unauthorized IP address, they wouldn't be able to get in, even if they have a valid user name and password," he said.

Alvarez acknowledged that securing a business has gotten more complex as new offerings have hit the market. "People say security is complicated because of the different avenues they can take to protect themselves," he said. "But the best way for people to protect themselves is to start by limiting everything -- what you're going to allow out, and what you're going to allow in."

Comment  | 
Print  | 
More Insights
The Agile Archive
The Agile Archive
When it comes to managing data, donít look at backup and archiving systems as burdens and cost centers. A well-designed archive can enhance data protection and restores, ease search and e-discovery efforts, and save money by intelligently moving data from expensive primary storage systems.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Elite 100 - 2014
Our InformationWeek Elite 100 issue -- our 26th ranking of technology innovators -- shines a spotlight on businesses that are succeeding because of their digital strategies. We take a close at look at the top five companies in this year's ranking and the eight winners of our Business Innovation awards, and offer 20 great ideas that you can use in your company. We also provide a ranked list of our Elite 100 innovators.
Twitter Feed
Audio Interviews
Archived Audio Interviews
GE is a leader in combining connected devices and advanced analytics in pursuit of practical goals like less downtime, lower operating costs, and higher throughput. At GIO Power & Water, CIO Jim Fowler is part of the team exploring how to apply these techniques to some of the world's essential infrastructure, from power plants to water treatment systems. Join us, and bring your questions, as we talk about what's ahead.