#3 Indian Cyber Security Gurus on Hacks to Fight an Attack90% companies worldwide have acknowledged that they are insufficiently prepared to protect themselves against cyber attacks

ByBaishali Mukherjee

Opinions expressed by Entrepreneur contributors are their own.

You're reading Entrepreneur India, an international franchise of Entrepreneur Media.

Pixabay

We are living in an era of hyper-connectivity in which smart phones, tablets, computers, Internet, social media, online banking, e-commerce, third-party payment gateways, games, online utility payments, internet of things are bound to touch every aspect of our lives.

越来越多的人becoming addicted to comfort and convenience with the inclusion of technology. With the emerging trend of staying connected in the past few years, the well-known rumour of "cyber-crime' or "cyber security' has turned into a frightening reality. Nowadays, we regularly read about data theft, loss of money, software and hardware malfunctions, data center outage etc.

Whether it is corporate or a government organization, all seems helpless to stop intrusion or incursion. Cyber attacks have become a continuous news in the media. Over 90 per cent of companies worldwide have acknowledged that they are insufficiently prepared to protect themselves against cyber attacks. Cyber-crime costs the global economy over US$400 billion per year.

What is Cyber Security?

Sushobhan Mukherjee,ChairmanofInfosec FoundationandCEOofPrime Infoserv LLP, defined it as achieving the basic security criteria, including assuring confidentiality of all data, maintaining integrity of all data and infrastructure, assuring availability of services in desired quality parameters, assuring protection of privacy, non-repudiation of person and/or transaction, maintaining incident response with defined service level parameters and availability of customer protection functionalities in end-to-end IT infrastructure.

What are the Basic Requirements

网上银行应用程序保持un测试for many customer-oriented risks and vulnerabilities, such as man-in-the-middle attack, malware, business intelligence, information leakage. "In some cases, it is observed that even very basic requirement is missing, for example SSL/TLS is not used; password storage in browser not blocked; auto-complete is enabled; cookie is not secured; security patches are not applied; to name a few from a long list," said Mukherjee.

Security vulnerabilities such as SQL-Injection, Cross Site Scripting, CSRF, unsafe transport layer, session hijacking, etc. are other major concerns. These vulnerabilities are a hacker's gateway to encroach on the user demographic and transaction data.

"Any compromise violates the basic cyber security criteria like confidentiality, integrity, privacy, etc. and exposes the citizen to the risk of various losses, including financial, regulatory, credibility, image, identity hijack, etc. Very limited web-portals are rigorously tested for cyber security vulnerabilities," he rued.

What are the Internal Factors

Ankit Dudhwewala,FounderofSoftware Suggest, a software discovery platform, suggested that people generally look at cyber risk from external factors. "Small and medium business often face greater risk from internal factors, when it comes to cyber risks. Mismanagement of passwords and other important company information is one of the most important critical reasons for financial and IP loss," he revealed.

How About a Password Management Tool

Dudhwewala works with a team of 50 members and to prevent such hacks he uses a password management tool calledLastPass. "This tool is a password repository, which allows our team members to login to online accounts of the company like bank account, payment gateway account, etc without the actual password being shared. Whenever a team member leaves the organization we remove his/her access to the repository that stops access to our online corporate accounts. This software also ensures that the password repository is not accessible from outside our office premises," he shared.

Data Hosted on the Cloud

Varun Biyani,Co-Founder ofTruckHall, an IIM-C incubated start-up operating in the road transport and logistics domain, has been working with SMEs and large corporate houses for long and is always asked how safe is their data? Most of their applications are hosted on the cloud. As a start-up, he makes sure that no matter what, the clients' data are protected by restricting the access rights. Proper encryption standards are also maintained while storing sensitive information.

"We make sure that proper access roles are defined for each user and user sessions on the application are managed properly. We also use features like re-captcha to make sure that users cannot auto log into our applications and have to authenticate themselves after periodic intervals. This also protects us from attacks as the site access is blocked unless the user authenticates oneself," he disclosed.

Wavy Line
Baishali Mukherjee

Former Freelancer

Related Topics

Business Ideas

The Top 10 Home Business Ideas for 2023

Can't figure out which enterprise you should launch in 2023? Check out 10 stellar home business ideas to get inspiration.

Thought Leaders

I Pitched 300 People a Day For 1 Year — and Learned This Impactful Entrepreneurial Lesson

After working myself to the bone pitching 300 people each day for one year, I came out of that experience as a new man — but surprisingly, an unhappier one. Here's what I learned.

Starting a Business

10 Common Obstacles to Avoid When Starting a Business

Starting a new business can be an exciting and rewarding venture, but it also comes with its fair share of challenges. Here are some common obstacles to avoid when starting a new business.

Money & Finance

How to Make Money Online: 10 Proven Ways to Make Money Online

Need to know how to make money online as a side gig or new career? Check out this breakdown of the 10 top online money-making methods.

Business News

Report: AI Will Take More Jobs Away from Women Than Men

Automation is many things, but apparently, it is not gender-neutral.

News and Trends

Google Invites Applications For Eighth Batch Of Startups Accelerator Programme

Applications are open until August 22, and eligible startups should have AI as a core solution or product, including generative AI