ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Most UK companies 'still vulnerable' to blended attacks

Munir Kotadia ZDNet.co.uk

Published: 29 Oct 2003 16:45 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Almost 75 percent of UK companies still do not have adequate protection against the type of attacks used by worms such as MSBlast or Nachi, according to a survey by security company Network Associates (NA).

The firm interviewed 200 IT directors from medium to large firms in Europe during August, a period which coincided with the outbreak of several malicious viruses and worms that exploited vulnerabilities in Microsoft's Windows operating system.

Christopher Thompson, vice president of marketing at Network Associates, told ZDNet UK he was concerned about the number of companies -- especially in the UK and the Netherlands -- that admitted to not having protection against blended threats. These exploit an existing vulnerability to gain access to a system, then deploy a malicious payload.

According to the survey, 42 percent of UK companies are unprotected against blended attacks while 38 percent have no plans to protect themselves. "This means somewhere close to 70 percent probably have inadequate protection strategies against blended threats," Thompson said. "That is a dangerous place for companies to be and it tells me the risk to companies is growing, not shrinking," he said.

Thompson also said he was surprised by the general lack of awareness about security issues during a period of so much viral activity: "You would think that after Slammer, Lovsan, MSBlast, Nachi and Sobig, there would be a heightened state of awareness. We were surprised by the relative level of preparedness and the variations between different countries in Europe," he said.

The survey also revealed that there is a significant difference in attitudes towards security between European countries. Companies in Germany, France and Sweden tended to adopt a proactive policy, whereas in the UK and Netherlands companies opted for a reactive policy. "The UK and Netherlands are spending most of their time reacting to things that happen -- such as applying patches and fixing security vulnerabilities," said Thompson.

More than half of companies in Germany and the Netherlands discuss security issues at board level, whereas in France, only 25 percent of respondents said the subject of security was discussed during board meetings. The UK ranked slightly higher at 35 percent. Although the situation is dangerous, Thompson said it is an improvement over 2001. "The good news is that this is now being discussed, which is an improvement to what we were seeing 18 months ago," he said.

In the past, security companies have been guilty of "over-promising and under delivering", Thompson admitted, but he blamed Microsoft for some of the problems. For example, he said, there is no reason that the "buffer overflow" vulnerabilities frequently discovered in Windows should even exist. "Buffer overflows are the result of sloppy programming -- it is shoddy workmanship," he said.

Earlier this month, Microsoft announced it has enhanced the memory protection in Windows XP in order to reduce the operating system's vulnerability to buffer overflow exploits, but the enhancement will only be available as part of Service Pack 2, which will not be available until next year.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
62 out of 125 people found this useful


Full Talkback thread

1 comment

  1. Unfortunately this report comes as no surprise to... Richard Starnes

Company/Topic Alerts

Create a new alert from the list below:












Related Jobs

SAP HCM Business Development Executive (Europe)

SAP HCM Business Development Executive (Europe) Job ID GBS-0107946 Job type Full-time Regular Work country United Kingdom Work city Any city in ...

Risk manager - Accountancy - credit risk - market risk- oil - gas

My clients are a UK based oil business which have operations in UK, Germany, and Netherlands and has sold fuels into North America, Africa and the ...

CRM Incentive Compensation Management Consultants-00047339

The ICM technology consultant will be accountable to the Project Board for overall delivery. With approximately 146,000 people in 49 countries, the ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment