9/15/2006

Top Five Causes of Data Compromises

Filed under: — By Aviran Mordo @ 1:03 pm

In a key step to help businesses better understand and protect themselves against the risks of fraud, Visa USA and the U.S. Chamber of Commerce today announced the five leading causes of data breaches and offered immediate, specific prevention strategies for each.

“The single, most effective weapon in the battle against today’s data theft is education,” said Sean Heather, executive director, U.S. Chamber of Commerce.

The findings, which are described in a comprehensive security alert from Visa, came from a detailed review of the card security environment, including common fraud techniques, potential areas of weakness by card-accepting merchants, and emerging threats.

As outlined today, the five leading causes of card-related data breaches are:

  1. Storage of Magnetic Stripe Data - The most common cause of data breaches occurs when a merchant or service provider stores sensitive information encoded on the card’s magnetic stripe in violation of the PCI Data Security Standard. This can occur because a number of point-of-sale systems improperly store this data, and the merchant may not be aware of it.
  2. Missing or Outdated Security Patches - In this scenario, hackers are able penetrate a merchant or service provider’s systems because they have not installed up-to-date security patches, leaving their systems vulnerable to intrusion.
  3. Use of Vendor Supplied Default Settings and Passwords - In many cases, merchants receive POS hardware or software from outside vendors who install them using default settings and passwords that are often widely known to hackers and easy to guess.
  4. SQL Injection - Criminals use this technique to exploit Web-based applications for coding vulnerabilities and to attack a merchant’s Internet applications (e.g. shopping carts).
  5. Unnecessary and Vulnerable Services on Servers - Servers are often shipped by vendors with unnecessary services and applications that are enabled, although the user may not be aware of it. Because the services may not be required, security patches and upgrades may be ignored and the merchant system exposed to attack.

The Visa alert along with helpful answers to data security questions can be found at the Chamber’s web page.



Vote Reddit Story ?

 

4 Responses to “Top Five Causes of Data Compromises”

  1. Ulf Joronen Says:

    One of the most serious and simple data compromise techniques has been forgotten: Physical security. It matters not how secure your system is if it can be accessed at the console, or worse yet, removed from the premeses and hacked at the thief’s leisure.

  2. 辞書ボイヤ Says:

    Aren’t employees the main cause of data theft?

    The solution is simple, get rid of the employees!

  3. Dan Cornell Says:

    I posted some commentary on this post on my blog here: http://denimgroup.typepad.com/denim_group/2006/09/top_5_causes_of.html

    The gist of my feedback is that all of these causes are super-preventable and that until organizations put the base level of protections in place the Internet is going to be a truly scary place

    –Dan

  4. POS Equipment Says:

    i dont understand why there isnt better security on the internet it seems like it would be simple to protect computers from hackers

Leave a Reply

You must have Javascript enabled in order to submit comments.

All fields are optional (except comment).
Some comments may be held for moderation (depends on spam filter) and not show up immediately.
Links will automatically get rel="nofollow" attribute to deter spammers.

Powered by WordPress