Symtrex Inc.

Cyber Security Specialist

Call - 866-431-8972 | Send an Email | Request a Quote
Visit Us On FacebookVisit Us On TwitterVisit Us On Linkedin
  • Home
  • Profile
    • Contact Us
    • Security News
    • White Papers
  • Services
    • Compliance Regulations
      • PCI DSS Suite of Products
      • HIPAA/Hitech
      • SOX – Sarbanes Oxley
      • DCID 6/3/NISPOM Chapter 8/JAFAN DoD
      • NERC/FERC
    • Industry Consulting and Implementation
      • Banking and Financial
      • Energy/Utilities
      • Healthcare
      • Retail/Hospitality
    • Security Assessment
  • Security Solutions
    • Sophos
    • Endpoint Security Solutions
      • Bitdefender Business Solutions
      • Sophos Endpoint Protection
    • Forensic Solution – Threat Hunter
    • Network Access Control
      • NetShield
        • NetShield
    • NGFW – UTM – Perimeter Security
      • Sophos Network Protection
    • Security Awareness Training
      • KnowBe4 – Security Awareness Training
      • Sophos Phish Threat
  • White Papers
    • Sophos Webinar Series
  • Security News
    • Blog
    • Sophos Webinar Series
  • Free Security Tools

Cyber Attacks On US Companies in 2014

2014/10/28 by admin

By Riley Walters

The spate of recent data breaches at big-name companies such as JPMorgan Chase, Home Depot, and Target raises questions about the effectiveness of the private sector’s information security. According to FBI Director James Comey, “There are two kinds of big companies in the United States. There are those who’ve been hacked…and those who don’t know they’ve been hacked.”

A recent survey by the Ponemon Institute showed the average cost of cyber crime for U.S. retail stores more than doubled from 2013 to an annual average of $8.6 million per company in 2014. The annual average cost per company of successful cyber attacks increased to $20.8 million in financial services, $14.5 million in the technology sector, and $12.7 million in communications industries.

This paper lists known cyber attacks on private U.S. companies since the beginning of 2014. (A companion paper discussed cyber breaches in the federal government.) By its very nature, a list of this sort is incomplete. The scope of many attacks is not fully known. For example, in July, the U.S. Computer Emergency Readiness Team issued an advisory that more than 1,000 U.S. businesses have been affected by the Backoff malware, which targets point-of-sale (POS) systems used by most retail industries. These attacks targeted administrative and customer data and, in some cases, financial data.

Read Full Article - >

Cyber Attacks Article

Filed Under: Advanced Persistent Threat, antivirus, byod, Cloud, compliance, endpoint, industry, Kaspersky, Log Management, Malware, NetClarity, PCI, Products, profile, Security News, Snare, Snare Agents, Sophos, Uncategorized, Unified Threat Management

APT Attacks

2014/10/02 by admin

According to an article in info-security, most security professionals expect an APT attack in the next six months. Within the article, it is quoted:

“The three structures of IT Security used to be ‘prevention’, ‘detection’ and ‘remediation’. However, with prevention an almost impossible task due to the very nature of the way IT is used today, it now falls down to ‘detection’ as the best way to protect systems,”.

Prevention is extremely difficult, however, using a defense in depth will assist - implementing a Unified Threat Management system, endpoint protection, as well as utilizing a NAC solution to see who is on your network, as well as stop communication back to command and control, are great first steps.

Using an Event Log Management system or SIEM will help detect abnormal behaviour, improving detection of not only malware or APTS, but also unusual activity by employees, guests, and other cyber threats. Most ELMs, or SIEMs have the ability to do file integrity monitoring as well - providing you with detailed information on what files were altered and by whom.

Take a look at some of our whitepapers on APT’s, or contact us.

 

Filed Under: Advanced Persistent Threat, antivirus, byod, Cloud, compliance, endpoint, industry, Kaspersky, Log Management, Malware, NetClarity, PCI, Products, profile, Security News, Snare, Snare Agents, Sophos, Uncategorized, Unified Threat Management

Enterprise Snare Agent for Windows

2014/08/22 by admin

A new version of the Enterprise Snare Agent for Windows is available for our clients. This release is primarily a bug fix:

Regular expression (RegEx) matching memory fix
If regular expression matching option is selected for objective(s) then in Snare Enterprise Agents prior to v4.2.6, it can cause an internal application crash every 10 minutes. It may log an application crash error in the Windows application log and a restart of the Snare service every 10 minutes. The issue was related to mishandling of the memory associated with the regular expression

For complete release notes and to access your client area please click here,

Filed Under: Uncategorized

Employees are number-one cyber security threat

2013/07/17 by admin

Despite attention-grabbing headlines about cyber-threats from external attackers, company bosses in fact see their own employees as the greatest threat to corporate data and computer systems.

That is the view of 53% of respondents to ‘Boardroom Cyber Watch 2013’, an international survey of senior executive opinion conducted by IT Governance, the global leader in IT governance, risk management and compliance expertise.

The threat from employees was ranked ahead of risks from criminals (27%), state-sponsored cyber-attackers (12%) and competitors (8%) by an international sample of 260 board directors, IT directors and other technology professionals polled by IT Governance in April and May 2013.

The survey confirms the high level of cyber-threat facing today’s organisations, with 25% of bosses saying they have received a ‘concerted attack’ in the past 12 months. However, the true total may be higher, as over 20% are unsure if their organisation has been subject to such an attack.

However, many board directors still appear inadequately informed about cyber-risks. While a majority of respondents say their board receives ‘regular’ reports on the status of their organisation’s IT security, 52% say that such reports are received, at best, annually. Only 5% say reports are submitted daily, with 11% being submitted weekly and 33% monthly.

View full article

Filed Under: antivirus, byod, Cloud, compliance, endpoint, industry, Log Management, NetClarity, PCI, Products, profile, Security News, Snare, Snare Agents, Uncategorized, Unified Threat Management

Website vulnerabilities down, but progress still needed, survey finds

2013/05/03 by admin

SearchSecurity - George Leopold, Contributor Published: 02 May 2013

Fully one-third of all websites surveyed last year were found to be vulnerable on a daily basis to a “serious” flaw like cross-site scripting, information leakage or content spoofing, according to a report on site vulnerabilities released today by WhiteHat Security.

While industries like entertainment and media were relatively quick to fix website vulnerabilities (an average of 33 days), WhiteHat’s survey found that industry-wide the average was 193 days from first notification.

Retail, health care and insurance websites were among the laggards, each taking well over 200 days to fix their sites after notification. Frequently updated retail sites, for instance, generally pose greater security challenges for Web developers, experts said, because each code deployment introduces new vulnerabilities.

“It’s an unforgiving environment,” stressed Jeremiah Grossman, WhiteHat Security’s founder and chief technical officer. The proliferation of “broken code” results in a “race to see who can exploit vulnerabilities.” Hence, most security patches for websites don’t work.

Still, the remediation rate for all sites surveyed was 61% in 2012, the Web security firm found, compared to only 35% in 2007.

[Read Full Article]

Filed Under: Uncategorized

  • « Previous Page
  • 1
  • 2
  • 3
  • 4
  • Next Page »

Let us help answer any questions you may have

requestmoreinformation.fw

Security News and Updates

  • Was my information part of a breach?
  • Phishing and stolen credentials
  • Ransomware is the Biggest Threat for Small to Medium Businesses

RSS SecurityWeek

  • 'Critical Severity' Warning for Malware Embedded in Popular JavaScript Library
  • REvil Ransomware Gang Hit by Law Enforcement Hack-Back Operation
  • Microsoft Introduces Security Program for Non-Profits

Contact

  • Contact Us

Request More Info

  • Request Quote

Site Map

  • Site Map

© Copyright 2016 Symtrex Inc. ; All Rights Reserved · Privacy Statement