enterprisesecuritymag

| | October- 2019ENTERPRISE SECURITY8owza! Another massive data breach affecting more than 100 million people across the United States due to an improperly configured Web Application Firewall (WAF). The exposed data contained information submitted by the customers and small businesses in their applications for Capital One credit cards from 2005 to early 2019. The information included addresses, dates of birth, and self-reported income. This breach compromised approximately 140,000 Social Security numbers and 80,000 bank account numbers, as well as some customers' credit scores and transaction data. You may be thinking, `Who would do something like this?' What does a hacker look like? We have seen these characters played on the big screen for decades. Movies like War Games, Blackhat, the Matrix, Tron, and Untraceable have created this euphoria around a faceless human with super abilities to bypass electronic controls and steal our most personal details.In the example outlined above, a former AWS employee was arrested and indicted with fraud and identity theft charges after she documented her hacking journey on slack for the world to read. Shouldn't companies be able to prevent these types of risks? That is a great question and a perfect transition into why web security is so important. Have you ever tried to communicate a web security risk to someone? You mention web security, and they hear, `ejbebvo' Hung'. If you are a fan of `Star Wars' then you are aware that is the Klingon translation for web security. Ok for everyone else, what exactly is web security? Web security is a form of application security that is specific to the security of websites, web applications, and web services. Web applications are constantly at risk from various threats such as cross-site scripting, insecure direct object references, security misconfiguration, injection flaws, broken authentication and session management, insufficient transport layer protection, and more. I know that some of you who are reading this still are sensing a bit of Klingon. Applications are hosted on servers available via the Internet or other networks and may have internal, connection-based, or other risks associated with the server operating systems. (A really cool guide containing the most serious risks is maintained by the Open Web Application Security Project (OWASP) and can be found on their website). Web security needs tobecome a critical consideration for all businesses, big or small, because that website represents WCybersecurity Challenges to Enhance Web Security for EnterprisesBy Billy Spears, SVP, Chief Information Security Officer, loanDepotIn My Opinion
< Page 7 | Page 9 >