Skip to content
  • SOBRE NÓS
  • SOLUÇÕES
    • CONSULTORIA
    • LGPD
    • TESTE DE INVASÃO
    • SASE – CATO
    • EDR & MDR – ThreatDown
  • SERVIÇOS GERENCIADOS
    • SOC – Security Operations Center
    • BPO – CONTROLE DE ACESSO
  • PÓS E MBA
    • PÓS: CIBERSEGURANÇA
    • MBA: SEGURANÇA DA INFORMAÇÃO E SECURITY OFFICER
  • TREINAMENTOS
    • PARCEIROS
      • EC-Council
      • CompTIA
      • PECB
      • Offensive Security
      • ISC2
    • CARREIRAS
      • BLUE TEAM
      • RED TEAM
      • GESTÃO
      • IA – Inteligência Artificial
      • CLOUD
      • DevSec
      • REDES
    • NÍVEIS
      • INTRODUTÓRIO
      • FUNDAMENTOS
      • INTERMEDIÁRIO
      • AVANÇADO
      • EXPERT
    • CCISO – EC-COUNCIL

    Parceiros

    COMPTIA
    NEW - Treinamento IA
    EC-COUNCIL
    PECB
    New - Treinamentos IA
    ISC2
    OFFENCIVE SECURITY

    NÍVEIS

    INTRODUTÓRIO
    FUNDAMENTOS
    INTERMEDIÁRIO
    AVANÇADO
    EXPERT

    CARREIRAS

    BLUE TEAM
    RED TEAM
    GRC
    IA - INTELIGÊNCIA ARTIFICIAL
    NEW
    CLOUD SECURITY
    DESENVOLVIMENTO SEGURO
    NETWORK SECURITY

    CCISO - EC-Council

    Treinamento para quem necessita criar estratégia de segurança da informação

    AGENDA DE TREINAMENTOS

  • BLOG
  • PODCAST
  • FALE CONOSCO

Segurança não é somente produto mas sim processo

mar 21, 2016

The most popular hacking methods and why firewalls don’t help

Julia Dutton March 9, 2016

A recent survey conducted by Balabit to uncover the ten most popular hacking methods aims to help organisations clearly see which methods or vulnerabilities attackers are using the most when they want to get sensitive data in the shortest possible time.

The survey also shows that 40% of respondents were aware that first-line defense tools, such as firewalls, are not effective at preventing a cyber attack. Simply put, security is no longer a product but a process. “Technology itself is too weak”, said Amit Yoran, President of RSA at last month’s RSA conference.

# 1: Social engineering (e.g. phishing attacks)

Topping the list was, unsurprisingly, social engineering – e.g. phishing attacks – which we at IT Governance have been blogging about extensively over the last few years.  Although traditional access control tools and anti-malware solutions are important, once criminals manage to break into a system, they can easily escalate their rights and gain privileged access to the network.

#2: Compromised accounts (e.g. weak passwords)

Coming in at a close second was compromised accounts, which could be caused by weak password security practices.

#3: Web-based attacks

Websites and web applications offer an easy-access route to company assets and provide a huge attack surface, making these types of attacks – which include methods like SQL injection – highly popular.

The other attack methods are listed in order:

  1. Client-side attacks (e.g. against doc readers, web browsers)
  2. Exploits against popular server updates (e.g. OpenSSL, Heartbleed)
  3. Unmanaged personal devices (e.g. lack of BYOD policy)
  4. Physical intrusion
  5. Shadow IT (e.g. users’ personal Cloud-based services being used for business purposes)
  6. Managing third-party service providers (e.g. outsourced infrastructure)
  7. Taking advantage of getting data added to the Cloud (e.g. IAAS, PAAS).

Why ISO 27001 provides an effective defense against these attacks

ISO 27001, the international standard for information security, provides a best-practice approach to cyber risk management through the implementation of a cost-effective and efficient management system. Encompassing people, processes and technology, the management system is based on the logic that conducting regular risk assessments and implementing controls to negate these risks provide a robust, ongoing defense.

The Standard provides a list of recommended controls that cover a broad range of cyber risks, such as frequent website and network penetration testing, security staff awareness training, and the development of appropriate policies and procedures.  The Standard also emphasizes continual improvement, thereby ensuring that the management system continues to adapt to the changing cyber risk landscape.

 

Posts Relacionados:

  1. 5 ferramentas grátis de Gerenciamento de Riscos que podem agregar valor para o programa de segurança
  2. Conheça a ISO 27001 e sua influência na segurança da informação
  3. Segurança da informação: como saber se seus dados estão seguros
  4. Profissional de TI: conheça a certificação em Segurança da Informação que pode trazer mudanças à carreira

AULAS GRATUITAS:

Posts recentes

  • Ransomware no Brasil: os Dados de 2026 que Assustam
  • IA agêntica em segurança: proteção contra CVE em 45 minutos

Arquivos

Institucional
  • Home
  • Sobre Nós
  • Blog
  • Podcast
  • Fale Conosco
Soluções
  • Consultoria
  • LGPD
  • Teste de Invasão
  • SASE – CATO
  • EDR & MDR – ThreatDown
Serviços & Formação
  • SOC – Serviços Gerenciados
  • BPO – Controle de Acesso
  • Pós: Cibersegurança
  • MBA: Segurança da Informação
  • Treinamentos
Contato

Telefone(11) 3939-0988 / (11) 2897-1566

E-mail[email protected]

Endereço – BrasilAv. Francisco Prestes Maia, 275 – Conj. 122, Centro
São Bernardo do Campo – SP – CEP 09770-000

Endereço – Estados Unidos7345 W Sand Lake Rd, Ste 210, Office 6532
Orlando – FL – 32819 – United States

  • Politica de Privacidade
  • Faça sua solicitação relacionado a dados pessoais
  • Código de conduta e ética
  • Agende sua provas
  • Facebook
  • X
  • Instagram
Strong Security Brasil - Strong Technology Comércio e Serviços em Informática LTDA - Todos os direitos reservados – Copyright © 2019 - 2026