Too many UK businesses exposed to hackers

Survey finds high-risk vulnerabilities down but low-risk ones on the rise

Andy McCue

A third of UK businesses are leaving themselves exposed to hackers by failing to crack down on medium and low-level security flaws, according to the results of a network monitoring survey.

The fifth annual Security Audit survey by consultant NTA Monitor found that, despite tackling major security vulnerabilities, UK companies are failing to address smaller flaws.

The audit examined data from more than 600 regular network perimeter security tests carried out by the company at client sites during 2002. One-third of corporate networks tested were found to have at least 10 flaws.

"A third of companies we examined were guilty of bad security housekeeping,with unacceptably high levels of basic flaws found," said Roy Hills, technical director at NTA Monitor, in the report.

"Although corporates are clearly prioritising security vulnerabilities and addressing high-profile issues this is at the expense of a much larger number of lower-profile vulnerabilities, which are being ignored.

"The net result is that corporate networks remain exposed to external attack."

Just six per cent of businesses had a high-risk vulnerability which could allow hackers to access and take control of computer systems - down from 19 per cent the previous year.

But medium-profile vulnerabilities were found in 73 per cent of tests, and low-profile vulnerabilities were found in every test instance.

Vulnerabilities in router and firewall systems remain at an "unreasonably" high level, often because they are installed with a standardised configuration geared towards functionality and up-time, said the survey.

Medium-risk issues allow external users to disrupt services or internal users to gain unauthorised access to systems, and a low-risk issue provides information that could be useful to a hacker in attempting an external attack, according to NTA Monitor.

The survey found that the main low-level flaws causing problems are DNS vulnerabilities, which have risen from 70 per cent in 2000 to 83 per cent last year.

The DNS Zone Transfer vulnerability enables hackers to gain a company's DNS data, such as network names and addresses, which can be utilised in malicious attacks.

Server-related vulnerabilities were the only area to show a fall during the five years of the survey, down to 73 per cent this year from 86 per cent last year. NTA Monitor put this down to the increased level of management attention devoted to websites.

Users should focus on good security design and policy and then configure all systems according to that plan, advised NTA Monitor.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

EU law lets in hackers

An upcoming European law designed to combat hackers could actually work to their advantage

XML security standard targets hackers

Oasis puts forward Application Vulnerability Description Language for web services-based apps

City firms ignore network security threat

Third of wireless networks vulnerable to hackers

Comment: Buffers cause heaps of problems

Hackers have exploited buffer overflow weaknesses in stacks since the 1980s. Now a new variation involving memory heaps could catch many firms unawares, says Neil Barrett

Related white papers

Related jobs

Most watched

Black Hat: Speaking with Cisco CSO John Stewart

Security chief reflects on changes to the industry

Nuance Dragon 11

Nuance Dragon 11 video demo

We get a look at the speech recognition software in action

Analysis and Reports

MessageLabs intelligence report June 2010
In June, MessageLabs identified an average of 1,598 websites each day harbouring malware and other potentially harmful programs.

Six steps to data protection for SMEs
Today's data protection challenges pose substantial risks to companies of all sizes, but they pose the greatest risk to small and midsize businesses.

Poll

Gary McKinnon poll

Gary McKinnon poll

Should Gary McKinnon serve a prison sentence in the UK?

View poll results

White paper library

Attachmate

Smartstream

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Steve Ballmer

Ballmer confirms Microsoft working on iPad rival

Windows 7-based slate device is top priority, says chief exec

Black Hat: Speaking with Cisco CSO John Stewart

Security chief reflects on changes to the industry

Facebook

Top 10 articles: Facebook pros and cons, and IPv4 warnings

V3.co.uk readers' most popular stories this week

Motorola Flipout hands on

The Motorola Flipout looks like a strange device with its...

Primary Navigation