Blog|Login|Chinese German Japanese|Follow @imperva
September 01, 2009
 WSJ: Keeping Your Site Out of Hackers' Clutches - At Cost

Riva Richmond of the Wall Street Journal tells small companies how to to protect themselves against hackers. It's the same story again, but now the Nation's respectable paper adds some protection advises as the attacks are growing. 

Attackers are increasingly infiltrating small businesses' Web sites and using them to quietly drop malicious programs, typically designed to steal personal financial information, onto the computers of visitors, security experts say. Some are also digging around in databases for valuable information or trying to capture e-commerce customers' credit-card numbers.
Yup, the bad guys penetrate web applications and databases, looking for digital assets they can steal. No surprises here.

While I understand that a newspaper is not a substitute for research I am disappointed that the WSJ did not cover one of the more appropriate solutions for small companies: Web Application Firewalls
The WSJ offered different suggestions from religiously apply security updates, through bringing in a security expert, using strong passwords (and keep them close), using automated tools for finding flaws 
or even hire a hacker (just to to expose any vulnerabilities from faulty site construction) and then find fix any problems he finds.

Small companies will find that identifying the problems is one thing, but then fixing it has an expensive price tag, hence Web Application Firewalls are more efficient. 

At least the WSJ was pointing at some good industry references like WhiteHat Security and FireHost Inc. 

Internet newspaper


Comments

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been saved. Comments are moderated and will not appear until approved by the author. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

Comments are moderated, and will not appear until the author has approved them.

« The Risk Based Approach For Data Protection in Massachusetts | Main | Imperva Podcast Interview with DirecTV - Database & Web Application Correlation »