THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Friday, January 27, 2023
In 2012, over 3,600 patients' personal information was stolen from a physician's laptop. A $1.5 million fine was imposed on Massachusetts Eye and Ear Infirmary for violating HIPAA privacy rules.
Fremont, CA: The term endpoint refers to any device that connects to a computer network. Knowing the endpoints is one thing, but plugging the attacks emanating from these endpoints is quite another. Endpoint security risks include:
Phishing
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Phishing is the most popular and least sophisticated method of gaining access using fake messages. In order to trick users into providing personal information or downloading malware, the message appears to come from a trustworthy source (such as a bank or known company). From there, the information or malware is used to gain access to the user's system and gain a foothold in the larger network.
Device Loss
Over 40 percent of data breaches between 2005 and 2015 were caused by lost or stolen endpoint devices, including laptops, tablets, and smartphones.
In 2012, over 3,600 patients' personal information was stolen from a physician's laptop. A $1.5 million fine was imposed on Massachusetts Eye and Ear Infirmary for violating HIPAA privacy rules.
Outdated Patches
One of the pains of modern life, constant patches causes slight inconvenience but a necessary evil to keep up with evolving threats online. And yet many companies (even those on the Forbes 500) still neglect to hit the update button.
Malware Ads
Also known as malvertising, this scam uses legitimate-looking advertisements and can propagate across reputable websites and social media before being taken down.
In recent years, sophisticated malware has appeared that doesn't require any user interaction at all. Such "pre-click" malware can be embedded in the main scripts of webpages, enabling them to run automatically even without being clicked by the user.
Drive-by Download
Similar to phishing, this method uses deception to trick users into clicking a link or downloading malware. Examples include fake system alerts, anti-virus notifications, or deceptive installation agreements different from the program the user intended to download.
Data Loss and Theft
Rather than methods of entry, these are the effects of an endpoint security breach.
The term "data loss" refers to the irreversible loss of data. An individual's personal photos, portfolio, and correspondence can be lost due to this endpoint security risk. A University of Texas study found that 94 percent of organizations that experience extensive data loss close up – 43 percent immediately and 51 percent within two years.
Data theft is even more insidious. This means that priceless corporate data, from customer databases to years of R&D, can end up on the dark web or in the hands of competitors.
Ransomware
There is no other endpoint cyber security risk as straightforward as ransomware. Ransomware encrypts all of the users' files, making them inaccessible unless a ransom is paid.
Many times, the app is disguised as a legitimate program to trick users into running it - however, newer versions can travel between computers automatically without requiring user interaction.
More in News