繁体中文  
 
版主:黑木崖
 · 九阳全新免清洗型豆浆机 全美最低
 
Why $250M didn't protect JPMorgan from hackers
送交者:  2014年08月29日07:08:27 于 [世界军事论坛] 发送悄悄话

Why $250M didn't protect JPMorgan from hackers

When a series of cyberattacks targeted banks like JPMorgan Chase (JPM) this month, it was clear to the FBI that the break-ins, which obtained gigabytes of data, according to the New York Times, were all coordinated. Some of the missing information may have included checking and savings account data.

Trish Wexler, a spokeswoman for JPMorgan, told CBS News: "Companies of our size unfortunately experience cyber attacks nearly every day. We have multiple, layers of defense to counteract any threats and constantly monitor fraud levels." The company says that there has been no unusual fraud activity and that it is currently working with law enforcement to understand the scope of the attack.

JPMorgan reported to shareholders that it will have spent $250 million on cybersecurity (pdf) by the end of 2014. It employs more than 1,000 people for these efforts, according to the annual shareholder letter from Chairman and CEO Jamie Dimon.

That makes this defeat particularly bitter.

Sadly, the pattern is anything but unusual. Total spending on cybersecurity by private companies, non-profits, and government agencies easily runs into the tens of billions annually. Market analyst ABI research estimates that global cybersecurity spending on critical infrastructure will hit $46 billion this year. The Department of Homeland Security alone sought a $1.25 billion cybersecurity budget in the fiscal year starting in October.

And yet, there are always new stories of data losses and successful attacks. That's because there are a number of factors that make the problem continuously tough to solve.

One is that companies are often playing catch-up. Cybersecurity is not a CEO's or CFO's favorite budget item. It's pure cost, adding nothing to a brand, product design, sales, or shareholder value. But after years of high profile attacks that were PR nightmares, corporations had to respond.

After the credit card breach last year, Target is reportedly spending $100 million to adopt technology so it can accept credit and debit cards that use embedded chips for added security.

Even as companies try to get caught up, they can be foiled by basic problems in their IT departments. One of the most important forms of protection is to regularly update servers, desktops, and mobile devices with the latest software security patches for the operating system and all programs on the machines.

Large companies may have thousands of servers and tens of thousands of desktops and mobile devices, which makes the task daunting enough. But it becomes more complex as any change in software could potentially affect how installed applications and systems could run. Someone has to test the high number of updates that come in before installing them, which means more time and money spent on security.

Also adding to the cybersecurity difficulty is the sheer numbers of hackers that are out there looking for unpatched vulnerabilities. There are always new system updates that may have created new security holes that haven't been patched yet. As computer networks become increasingly complex -- involving mobile devices tapping into wireless and cellular networks -- any new change creates an opportunity for weakness that someone might find.

Ultimately, one of the biggest security issues is human -- and therefore impossible to control with tech solutions. Hackers will often obtain information necessary to break into networks directly from customer service employees who are trying to be helpful.

Even with all the money companies are spending on security, chances are that break-ins will continue to happen and companies, and their customers, will have to find new ways to manage the unpleasant results.

0%(0)
0%(0)
标 题 (必选项):
内 容 (选填项):
实用资讯
北美最大最全的折扣机票网站
美国名厂保健品一级代理,花旗参,维他命,鱼油,卵磷脂,30天退货保证.买百免邮.
一周点击热帖 更多>>
一周回复热帖
历史上的今天:回复热帖
2013: 俄称不肯单独卖中国117S发动机 必须先买
2013: 李某某案,根据《中华人民共和国刑法》
2012: 如果你是真正的王者,一切都将属于你
2012: 最近很火的3D打印技术,太逆天了,土鳖
2011: 警卫员回忆:胡耀邦任华北野三纵政委时
2011: 中共官媒:骆家辉轻车简从 是新殖民主义
2010: 中越青年联欢大会在广西南宁举行 胡锦涛
2010: “火星-500”试验隔离舱的终极宅男生活
2009: 怎么每次有点事,军坛就马甲乱飞。
2009: 这里有相当一部分人,一边在批帝国主义