Think Your IT Is Secure? Think Again.
NEW YORK (TheStreet) -- The data breach last week at email service provider Epsilon affecting large firms including Verizon (VZ), Capital One (COF), Best Buy (BBY), Citigroup (C), and Target (TGT) should have small-business owners reassessing their own strategies to keep customer information, employee records and other confidential information safe.
TheStreet interviewed Sarah Fender, vice president of marketing and product management at PhoneFactor, the Overland Park, Kan., company providing phone-based authentication solutions to small and large companies. Additional comments came via email from PhoneFactor co-founder and Chief Technology Officer Steve Dispensa.
|Workers checking email and logging onto networks remotely can spread viruses. PhoneFactor is among companies providing security such as phone-based identification systems to limit data breaches.|
What are some common misconceptions small firms have when it comes to IT security?PhoneFactor: The first one relates to antivirus and anti-malware software. Antivirus software generally only catches 60% of the current viruses that are out there, so that's 40% of the brand-new viruses [that the software] isn't even looking for. No one is going to recommend that you don't use antivirus software; we just want people to be aware it's not enough as kind of a standalone. If that's the only thing you're doing to protect your business, then you're probably not doing enough. Another common misconception, particularly among small businesses, is that passwords keep the bad guys out. This may be true for workers logging into their PC at the office, where physical security helps ensure that the legitimate user is logging in. A co-worker would likely notice a stranger sitting in the cubicle next to them. Increasingly, we're all working remotely. We're checking email from our smartphone. We've got Apple (AAPL) iPads. We've got all kinds of ways to log into email or networks when we're not in the office. In those scenarios, passwords are not enough. How can small firms implement a strong data loss prevention security strategy? What is most important in doing that? PhoneFactor: The basics are important -- keeping servers and user computers patched, with current anti-malware software and an active firewall. [Small businesses should] do some basic security training even with a small team helping them to understand social engineering and how to handle confidential information and have more awareness to identify those types of threats. Safeguarding means more than data leakage prevention; it also means having good backups of email and other data, including regular restore testing. Outsourcing email services to a third party can be a good move for small firms, but be careful to take into consideration the kind of security that your email provider is able to provide for you, and go with a reputable firm.
Select the service that is right for you!COMPARE ALL SERVICES
- $2.5+ million portfolio
- Large-cap and dividend focus
- Intraday trade alerts from Cramer
- Weekly roundups
Access the tool that DOMINATES the Russell 2000 and the S&P 500.
- Buy, hold, or sell recommendations for over 4,300 stocks
- Unlimited research reports on your favorite stocks
- A custom stock screener
- Upgrade/downgrade alerts
- Diversified model portfolio of dividend stocks
- Alerts when market news affect the portfolio
- Bi-weekly updates with exact steps to take - BUY, HOLD, SELL
- Real Money + Doug Kass Plus 15 more Wall Street Pros
- Intraday commentary & news
- Ultra-actionable trading ideas
- 100+ monthly options trading ideas
- Actionable options commentary & news
- Real-time trading community
- Options TV