Palo Alto Networks achieves rigorous common criter... » London: Palo Alto Networks firewalls have achieved Common Criteria certification at Evaluation Assur... Copy cat, copy cat sitting on the doormat - Barrac... » Last week Google announced that it is unifying storage across its products and influenced by this ne... Do young employees present a phishing risk? » In a new blog post from Aaron Higbee, CTO of PhishMe, a new security risk is discussed, which specif... Three bodies, two guns, one river » Toxicologist uses expertise to write realistic crime novel ATLANTA, Ga.: Any investigator will tell... IGEL extends UK distribution with Arrow appointme... » Reading, UK: IGEL Technology has appointed Arrow Electronics Inc. as a distributor in the UK. The ap... Parliament receives troop rotation details for fi... » The troop rotation arrangements outlining the tour lengths for deployed UK personnel between now and... Lancope joins Cloud Security Alliance to help prot... » LONDON (UK): Lancope, Inc., a leader in network visibility and security intelligence, has joined the... Why Hosters Should Care About Web Security » Last week, the “Moroccan Ghosts” published a list of 52 defaced Israeli sites, replacing site conten... AhnLab sets aggressive business growth targets in... » LONDON, UK: AhnLab, a leader in advanced internet security protection for businesses, today announce... Unified Security Management provider included i... » San Mateo, Calif.: AlienVault, the leading Unified Security Management provider committed to making ...

Advertise with Vigilance

Got News?

Got news for Vigilance?

Have you got news/articles for us? We welcome news stories and articles from security experts, intelligence analysts, industry players, security correspondents in the main stream media and our numerous readers across the globe.

READ MORE

Subscribe to Vigilance Weekly

Information Security Header

“It’s important to understand that, if you reduce the privilege on high-end accounts, you do not impair operational efficiency. You do, however, reduce the level of risk in an organisation – and that’s a great situation to be in,”

-- Paul Kenyon, Avecto COO

Manchester UK and Boston, USA: Commenting on recent reports - which assert that cybercriminal social engineering attacks are now targeting IT admins and even call centre staff - Avecto says that a least privilege approach to security is the key to solving this issue.

 

Paul Kenyon, chief operating officer with the Windows privilege management specialist, says the real reason why cybercriminals are targeting the IT support function is the immense power that staff in these areas have - thanks to the admin accounts they have access to.

“Many of these staff are using what security professionals call privileged accounts - that is, admin accounts that can carry out a number of high-end tasks, which the more mundane user accounts do not normally have access to. If unnecessary privileges are removed from these accounts, this lowers the security risk involved,” he said.

“It’s important to understand that, where IT admins and least privilege are concerned, it’s not about taking rights and privileges away – it is about protecting their privileged identity, empowering them to make conscious decisions on when those privileges are used, and monitoring all privileged activity for signs of misuse or exploitation,” he added.

The Avecto COO went on to say that the advantage of adopting a least privilege/least risk security posture with admin account privileges is that the security advantages also transfer over to the servers these IT admins control.

The process of removing unnecessary privileges from the admin account arena, he explained, comes down to adopting an effective audit and governance strategy, which in turn reduces risk and increases efficiency.

“It’s important to understand that, if you reduce the privilege on high-end accounts, you do not impair operational efficiency. You do, however, reduce the level of risk in an organisation – and that’s a great situation to be in,” he said

Add comment


Security code
Refresh