Data Storage Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Information for Data Storage Professionals
Panasonic Toughbook® Mobile
Tablets & Laptops are rugged & reliable
with lower TCO & greater ROI

www.panasonic.com
Saturday, May 25th 
Stingray Traffic Manager on Amazon Web Services
Home
Data Centers
Storage Solutions
Storage Networks
Data Storage Issues
Data Security
Enterprise I.T.
DST Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement

Data Security

What Global Payments Did Right in the Security Breach

What Global Payments Did Right in the Security Breach
April 3, 2012 11:15AM

Bookmark and Share
Global Payments spotted the breach on its own, which security analyst Geoff Webb said would imply that the credit card processor has both monitoring tools in place and policies that enable it to use the information gathered and to respond appropriately to a breach. Webb said this self-detection actually speaks well of Global Payments' security.

Panasonic Toughbook® mobile computers are engineered to withstand drops, spills, dust and grime, and to perform in the harshest environments. Rugged reliability, low cost of ownership and accolades from reviewers are just a few of the reasons why Toughbook computers keep winning over the world's toughest users. Click here to learn more.

Visa has nixed Global Payments from its credit card processing provider list after the firm reported that 1.5 million credit card files were compromised in a security breach -- at least for now. Global Payments has yet to reveal the root of the breach.

We caught up with Neil Roiter, research director at Corero Network Security, to get his take on the ongoing saga even as Global Payments remains tight-lipped about the open door. So far, Global Payments has stated only that the attack was "contained" and confirmed that about 1.5 million records were compromised.

"Global Payments was clearly vulnerable, and other processing companies likely are as well," Roiter said. "They all need to review continuously the security policies, practices and technology controls they have in place, including but not limited to encryption, access controls and authentication."

A Self-Detected Breach

Geoff Webb, director at Credant Technologies, told us he considered it interesting that the security breach was self-detected. That's because in the majority of breaches, the actual breached party finds out from a third party.

In this case Global Payments spotted the breach on its own, which Webb said would imply that the credit card processor has both monitoring tools in place and policies that enable it to use the information gathered and to respond appropriately. While Global Payments is getting plenty of criticism, Webb said this self-detection actually speaks well of the firm's security preparedness.

"Only a small number of servers were breached -- and it would seem these were used to handle North American card transactions, hence the limit of the breach to North American cards. This is not unusual," Webb said.

"Attackers will identify servers with weaknesses -- such as being left with default vendor-supplied service accounts -- and use those to gain access to the network Relevant Products/Services. They will then watch for, and copy, unencrypted card information as it moves across the processors network. They'll often use some customer Relevant Products/Services-designed software Relevant Products/Services to do this, as we've seen before in other breaches."

What Global Payments Did Right

Global Payments went to the federal authorities early, within hours of the breach being detected. For this the credit card processor is being recognized in a positive light. Any organization breached in this way needs to move quickly to contact the federal government, Webb said, and then they should wait for guidance.

"The worst thing they could do is to shut down their systems and, as a result, warn the thieves that the breach has been spotted -- who then immediately begin to cover their tracks," Webb said. "Far better to allow the investigators an opportunity to look at the breached systems and gather as much information as possible -- huge amounts of forensic data Relevant Products/Services can be lost by shutting down a breached system in a panicked response to identifying a breach."

Tell Us What You Think
Comment:

Name:

Advertisement



 Data Security
1. Money Stirs Electronic Records Push
2. Twitter Hoping To Halt Hack Attacks
3. Blue Coat Beefs Up Big Data Security
4. China Hackers Resume U.S. Attacks
5. Financial Times Latest Hacking Target


advertisement


 Most Popular Articles
1. Half of Companies To Mandate BYOD by 2017, Gartner Says
2. Best of Interop Award Winners Announced
3. Novell Filr Offers IT-Friendly Dropbox Alternative
4. Add Guardian to Hacked List; Twitter Sends Security Memo
5. HP and SAP Team To Advance HANA Database Technology

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Money Stirs Electronic Records Push
  HP PCs Aim for Flexibility, Mobility
  Twitter Hoping To Halt Hack Attacks
  Nvidia GPU Boosts Citrix XenDesktop
  Security Alert: New Trojan Attacking

 Technology Marketplace

BYOD & MDM
Forrester Research Inc., Report: BYOD from AT&T. Make everyone more efficient.
 
Cloud & Virtualization
Brocade technologies help enable the full benefits of virtualization.
Riverbed Stingray Traffic Manager on Amazon Web Services
 
Contact Centers
Unlock the potential in your people with Microsoft Dynamics
Unlock the potential in your people with Microsoft Dynamics
 
Customer Service
Unlock the potential in your people with Microsoft Dynamics
Unlock the potential in your people with Microsoft Dynamics
 
Data Security
Simpana® 10 software: an exponential leap forward
 
Data Storage
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Software
Simpana® 10 software: an exponential leap forward
 
Hardware
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Laptops & Tablets
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Mobile Gadgets
Rugged and reliable Panasonic Toughbook® mobile computers.
 
Network Security
Brocade makes it easier to deploy, manage, and scale networks.
 
Navigation
Data Storage Today
Home/Top News | Data Centers | Storage Solutions | Storage Networks | Data Storage Issues | Data Security | Enterprise I.T.
DST Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 Data Storage Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.