infoTECH Feature

August 17, 2015

Hackers Report Easy Access to Privileged Accounts Despite Increased Security Spending

Hackers are regarded, and not without reason, as one of the greatest dangers information technology can face. While there will be some discussion over that point—especially in terms of the distinction between hackers and “crackers,” or white hat versus black hat hackers—the point remains that those who would enter systems without permission are still a major threat. As such, a host of new developments has emerged as a means to protect against this growing threat, but a new report from Thycotic brought out a distressing new point: that the new measures aren't helping much.

The Thycotic survey was conducted among 201 hackers—of both white and black hat persuasions—at the Black Hat USA 2015 event. According to that survey, 75 percent of hackers haven't seen any real change in difficulty when it comes to getting access to privileged accounts. This is a development that will likely hit many by surprise, given that IT security spending has been on the rise for the last two years.

What was worse was that privileged account credentials are reportedly cropping up in unexpected places, particularly in connection with spreadsheets and other unprotected files. A total of 94 percent had seen privileged credentials in unprotected files, while just 6 percent reported never having seen such an issue.

Those two points were just the start of the bad news for IT security. Many hackers regarded privileged account credentials as the best way to get access to data, with 45 percent of respondents calling such credentials a “favorite target.” Thirty-three percent, meanwhile, preferred end-user credentials as a target. Ninety percent of respondents called it either as easy or even easier to compromise such credentials now than it was even just two years ago. Primary targets for breach vulnerabilities were terrifying in scope; healthcare organizations were on the block in 29 percent of cases, while 25 percent targeted financial services and almost as many, 24 percent, went after government organizations instead.

Thycotic's senior technology evangelist, Nathan Wenzler, offered up some comment around this study, saying “Perhaps not surprising to those in the cybersecurity industry, it is apparent that for all the new defensive solutions that have been introduced, we still haven't cracked the code on how best to protect mission-critical data and company secrets, and in fact, in some cases we're only adding additional layers of complexity which provide attackers more attack vectors to use to break in.”

While admittedly, this study might not be the most valid, since its sample size is so small, the information revealed here should be a wake-up call sufficient for any slumbering giant. A recent study among new chief information security officers (CISOs) revealed that keeping systems protected was a much more difficult proposition than some might expect due to a whole host of issues. So with such problems on hand in companies—a lack of trust within organizations, a lack of clear strategy, even a lack of resources—it might be reason enough there are such problems in organizations.

Information security affects all of us in one way or another, whether it's the safety of online dealings we routinely have or the perceived safety of dealings we haven't had yet. Better security is vital to the best in online experiences, and the better job we do protecting that experience, the better off we all are. 




Edited by Dominick Sorrentino
FOLLOW US

Subscribe to InfoTECH Spotlight eNews

InfoTECH Spotlight eNews delivers the latest news impacting technology in the IT industry each week. Sign up to receive FREE breaking news today!
FREE eNewsletter

infoTECH Whitepapers