Wakazvifumura Nguva pfupi Yapfuura?

by Sep 14, 2023BI/Analytics0 mashoko

 

Tiri kutaura nezvekuchengetedzwa mugore

Over Exposure

Ngatizviise seizvi, chii chaunonetseka nekufumura? Ndezvipi zvinhu zvako zvakakosha? Yako Social Security Number? Mashoko ako eakaundi yebhangi? Zvinyorwa zvepachivande, kana mapikicha? Izwi rako remhodzi ye crypto? Kana iwe uchitonga kambani, kana uine basa rekuchengetedza data, unogona kunetseka nezve iwo mamwe marudzi eruzivo ari kukanganisa, asi paab.roader scale. Iwe wakaronzeswa nevatengi vako kuchengetedza data ravo.

Sevatengi, isu tinotora kuchengetedzeka kwedata redu sezvisina basa. Zvakawanda uye kazhinji mazuva ano iyo data inochengetwa mugore. Vanoverengeka vevatengesi vanopa masevhisi anobvumira vatengi kuchengetedza data kubva kumakomputa emunharaunda kuenda kune gore. Funga nezvayo seyakaoma hard drive mudenga. Iyi inoshambadzirwa senzira yakachengeteka uye iri nyore yekudzivirira data rako. Yakanaka, hongu. Unogona kudzoreredza faira rawakadzima netsaona. Iwe unogona kudzoreredza hard drive yese ine data yakashatiswa.

Asi hazvina ngozi here? Unopihwa kiyi nekiyi. Chinokosha ndechekuti, kazhinji, zita rekushandisa uye password. Iyo yakavharidzirwa uye inozivikanwa kwauri chete. Ndosaka nyanzvi dzekuchengetedza dzichikurudzira kuchengetedza password yako. Kana mumwe munhu akawana password yako, ivo vane kiyi chaiyo kune yako chaiyo imba.

Munoziva zvose izvi. Pasiwedhi yako kune backup Cloud service ine mavara gumi nematanhatu kureba, ine mavara makuru uye madiki, manhamba uye akati wandei mavara. Iwe unochishandura mwedzi mitanhatu yega yega nekuti unoziva izvo zvinoita kuti zviomerwe kune hacker. Yakasiyana nemamwe mapassword ako - haushandise password imwe chete kumasaiti akawanda. Chii chinogona kukanganisa?

Mamwe makambani anopa chavakadaidza se "Personal Cloud." Western Digital ndeimwe yeaya makambani anopa nzira iri nyore yekuchengetedza data rako kunzvimbo yako wega mugore. Iyo inetiweki yekuchengetedza inowanikwa painternet. Inobata muWi-Fi router yako kuti ugone kuiwana kubva kupi zvako mukati metiweki yako. Zviri nyore, nekuti zvakare yakabatana neinternet, unogona kuwana yako yega data kubva chero kupi paInternet. Nekureruka kunouya njodzi.

Chimiro Chekukanganisa

Kutanga kwegore rino, matsotsi akapinda muWestern Digital's masisitimu uye takakwanisa kudhawunirodha ingangoita gumi Tb yedata. Iwo matsamba evatema akabva abata data rerudzikinuro ndokuedza kutaurirana kuchamhembe kweUS $ 10 yekudzoserwa kwakachengeteka kwedata. Data yakafanana nemafuta. Kana kuti zvichida goridhe iri nani kuenzanisa. Mumwe wema hackers akataura nenyaya yekusada kudomwa nezita. Ha! TechCrunch akamubvunzurudza paaive ari mushishi rebhizimusi iri. Chinofadza ndechekuti data rakakanganiswa raisanganisira Western Digital's code-signing certificate. Iyi ndiyo tekinoroji yakaenzana neyeretina scan. Chitupa chinoitirwa kuratidza muridzi kana mutakuri. Neiyi chaiyo retina scan, hapana password inodiwa kuti uwane "yakachengetedzwa" data. Mune mamwe mazwi, nechitupa ichi uyu muzvinabhizimusi weheti nhema anogona kufamba pamusuwo wepamberi we digital muzinda.

madokero Digital vakaramba kutaura vachipindura zvaitaurwa nemutsotsi kuti vanga vachiri muWD's network. The hacker asina kudomwa akaratidza kuodzwa mwoyo kuti vamiririri kuWestern Digital aisadaira macalls ake. Zviri pamutemo, mu a mupepanhau, Western Digital yakazivisa kuti, "Kubva pakuferefeta kusvika pari zvino, Kambani inotenda kuti bato risina mvumo rakawana imwe data kubva kumasisitimu ayo uye riri kushanda kuti rinzwisise mamiriro nekukura kwedata." Saka, Western Digital ari mhamha, asi hacker ari kutaura. Kana zviri zvemaitirwo avakazviita, mubiki anotsanangura mashandisiro avakaita kusadzivirirwa kwaakaita uye vakakwanisa kuwana ruzivo mugore semutungamiriri wepasi rose.

Mutongi wepasi rose, nechimiro chebasa, anokwanisa kuwana zvese. Haadi password yako. Ane kiyi huru.

madokero Digital Haasi Ega

A tsvakurudzo gore rapfuura zvakaona kuti chikamu che83% chemakambani akaongororwa aive nacho kupfuura imwe kutyora data, 45% yavo yaive-yakavakirwa gore. The pakati nepakati mutengo wekutyorwa kwedata muUnited States yaive US $9.44 miriyoni. Mitengo yakakamurwa kuita zvikamu zvina zvemitengo - bhizinesi rakarasika, kuona uye kukwira, ziviso uye mhinduro yekutyora mushure. (Ini handina chokwadi chekuti rudzikinuro rwedata rwuri muchikamu chipi. Hazvina kujeka kana mumwe wevakapindura akabhadhara rudzikinuro zvinodiwa.) Ivhareji nguva inotora sangano kuti rizive uye ripindure pakutyora kwedata rinenge 9 mwedzi. Hazvishamisi, saka, kuti mwedzi yakati wandei mushure meWestern Digital kutanga vakabvuma kutyora data, vachiri kuongorora.

Zvakaoma kutaura chaizvo kuti makambani mangani akatyorwa nedata. Ndinoziva imwe kambani hombe yakavanzika yakarwiswa neransomware. Varidzi vacho vakaramba kutaurirana uye havana kubhadhara. Izvi zvaireva, panzvimbo pezvo, akarasika maemail uye data mafaira. Vakasarudza kuvakazve zvese kubva kune vasina hutachiona backups uye reinstall software. Paive neakakosha-nguva-nguva uye yakarasika chibereko. Chiitiko ichi hachina kumbobuda munhau. Iyo kambani yaive nerombo rakanaka nekuti 66% emakambani madiki kusvika pakati nepakati anorwiswa neransomware anopedzisira abuda mubhizinesi mukati memwedzi mitanhatu.

  • 30,000 mawebhusaiti ari hacked mazuva ose
  • 4 miriyoni mafaira ari kuba mazuva ese
  • 22 bhiriyoni zvinyorwa zvaive kutyorwa muna 2021

Kana wakamboita bhizinesi ne, kana kushandisa masevhisi eCapital One, Marriott, Equifax, Target kana Uber, zvinogoneka kuti password yako yakakanganiswa. Imwe neimwe yemakambani makuru aya akatambura nekutyorwa kwakanyanya kwedata.

 

  • Capital One: A hacker akawana mukana kune 100 miriyoni vatengi uye vanyoreri nekushandisa kusagadzikana mune yekambani cloud infrastructure.
  • Marriott: Kutyora kwedata kwakafumura ruzivo kune 500 miriyoni vatengi (kutyorwa uku hakuna kuonekwa kwemakore mana).
  • Equifax: Ruzivo rwemunhu mugore pane 147 miriyoni vatengi rwakafumurwa.
  • Chinangwa: MaCybercriminals akawana 40 miriyoni manhamba emakadhi echikwereti.
  • Uber: Matsotsi akakanganisa laptop yemugadziri uye akawana mukana wevashandisi 57 miriyoni uye 600,000 vatyairi.
  • LastPass[1]: MaHackers akaba 33 miriyoni vatengi 'vault data mukuputsika kwegore rekuchengetedza kambani iyi password maneja. Iye anorwisa akawana mukana wekuchengetera gore reLastpass achishandisa "kiyi yekuchengetera gore rekupinda uye maviri ekuchengetedza mudziyo decryption makiyi" akabiwa kubva munzvimbo yekuvandudza.

Iwe unogona kutarisa kuti uone kana iwe wakafumurwa mukutyora data pane ino webhusaiti: ndakabatwa here? Nyora email kero yako uye ichakuratidza kuti vangani data rakatyora iyo email kero yakawanikwa mukati. Semuenzaniso, ndakataipa imwe yeangu email kero ndikaona kuti yanga iri chikamu chemakumi maviri neshanu ekutyora data kwakasiyana, kusanganisira Evite. , Dropbox, Adobe, LinkedIn uye Twitter.

Kurasa Vasingadiwe Suitors

Panogona kusambove nekubvumwa neruzhinji neWestern Digital chaizvo zvakaitika. Chiitiko chacho chinoenzanisira zvinhu zviviri: data riri mugore rinongochengeteka sevanorichengeta uye vachengeti vemakiyi vanofanira kungwarira zvikuru. Kudimikira iyo Peter Parker Principle, nemidzi yekuwana inouya basa rakakura.

Kuti zvive zvakanyatsojeka, mushandisi wemidzi uye mutongi wepasi rose haana kunyatsofanana. Ose ane simba rakawanda asi anofanirwa kuve akaparadzana maakaundi. Iyo mudzi mushandisi ndeyake uye inokwanisa kuwana iyo corporate cloud account padanho rakaderera. Saka nekudaro, iyi account inogona kudzima data rese, maVM, ruzivo rwevatengi - zvese zvakachengetwa nebhizinesi mugore. MuAWS, kune chete 10 mabasa, kusanganisira kumisikidza uye kuvhara yako AWS account, iyo inoda zvechokwadi kuwana midzi.

Administrator maakaundi anofanirwa kugadzirwa kuita mabasa ekutonga (duh). Kunowanzo kune akawanda Administrator maakaundi ayo anowanzo akavakirwa pamunhu, kusiyana neiyo imwechete midzi account. Nekuti Administrator maakaundi akasungirirwa kumunhu, unogona kutarisa zviri nyore kuti ndiani akaita shanduko nharaunda.

Kadikidiki Ropafadzo yeMaximum Security

Ongororo yekutyora dhata yakaongorora maitiro e28 zvinhu pakuomarara kwekutyora kwedata. Kushandiswa kwekuchengetedzwa kweAI, nzira yeDevSecOps, kudzidziswa kwevashandi, chitupa chekuzivikanwa uye kuwana manejimendi, MFA, kuchengetedza analytics zvese zvakave nemhedzisiro yakanaka mukuderedza avhareji yemadhora yakarasika muchiitiko. Nepo, kutadza kutevedzera, kuomarara kwehurongwa hwekuchengetedza, kushomeka kwehunyanzvi hwekuchengetedza, uye kutama kwegore zvaive zvinhu zvakakonzera kuwedzera kwepamusoro mumutengo weavhareji wekutyora data.

Sezvo iwe uchitamira kune gore, iwe unofanirwa kuve wakangwarira kupfuura kare mukuchengetedza data rako. Hedzino dzimwe nzira dzekuwedzera dzekudzikisa njodzi yako uye kumhanya nharaunda yakachengeteka kubva ku chibatiso chimiro:

1. Muli-factor Authentication: simbisa MFA yemidzi uye ese Administrator maakaundi. Kunyangwe zvirinani, shandisa yemuviri MFA mudziyo. Anogona hacker angangoda kwete chete zita reakaundi uye password, asiwo iyo yemuviri MFA iyo inogadzira iyo yakawiriraniswa kodhi.

2. Simba munhamba diki: Gadzirisa kuti ndiyani anowana mudzi. Dzimwe nyanzvi dzezvekuchengetedza dzinokurudzira vashandisi vanopfuura vatatu. Tonga midzi yevashandisi kuwana zvine hunyanzvi. Kana iwe ukaita yekuzivikanwa manejimendi uye off-boarding hakuna kumwe kumwe, ita pano. Kana mumwe ari mudenderedzwa rekuvimba akasiya sangano, shandura iyo password password. Dzorera iyo MFA mudziyo.

3. Default Account Maropafadzo: Paunenge uchipa maakaundi evashandisi matsva kana mabasa, ita shuwa kuti vanopihwa rombo rakanaka nekutadza. Tanga neiyo shoma yekuwana mutemo uye wozopa mamwe mvumo sezvinodiwa. Iyo musimboti wekupa iyo shoma chengetedzo kuti uite basa muenzaniso unozopfuura SOC2 chengetedzo yekutevedzera zviyero. Pfungwa iyi ndeyekuti chero mushandisi kana application inofanirwa kuve nechengetedzo shoma inodiwa kuita basa rinodiwa. Iyo yakakwirira ropafadzo iyo inokanganiswa, iyo inowedzera ngozi. Ukuwo, kuderera kweropafadzo kunoratidzwa, ngozi yacho inoderera.

4. Auditing Rondedzero: Gara uchiongorora uye ongorora ropafadzo dzakapihwa vashandisi, mabasa, uye maakaundi mukati memakore ako nharaunda. Izvi zvinoita kuti vanhu vangove nemvumo inodiwa chete yekuita mabasa avo avakasarudzirwa.

5. Identity Management uye Just-in-nguva Ropafadzo: Ziva uye ukanzure chero kodzero dzakawandisa kana kusashandiswa kuderedza njodzi yekuwanikwa usina mvumo. Ipa chete kodzero dzekuwana kuvashandisi pavanenge vachidzida kune rimwe basa kana nguva shoma. Izvi zvinoderedza nzvimbo yekurwisa uye inoderedza hwindo remukana wezvinogona kutyisidzira kuchengetedza. https://www.cnbc.com/2022/10/20/former-hacker-kevin-mitnick-tips-to-protect-your-personal-info-online.html

6. Embedded credentials: Rambidza kuomeswa kwekodhi yechokwadi chisina kuvharwa (zita rekushandisa, password, makiyi ekuwana) mune zvinyorwa, mabasa, kana imwe kodhi. Pane kudaro tarisa mukati a secret manager iyo iwe yaunogona kushandisa kudzoreredza zvitupa.

7. Infrastructure-as-Code (IaC) Configuration: Temerera kukuchengetedza akanakisa maitiro paunenge uchigadzira yako cloud zvivakwa uchishandisa IaC zvishandiso seAWS CloudFormation kana Terraform. Regedza kupa veruzhinji mukana nekusarudzika uye ganhurira kuwana zviwanikwa kune chete akavimbika network, vashandisi, kana IP kero. Shandisa zvibvumirano zvakanaka-zvakaremerwa uye nzira dzekudzora nzira dzekusimbisa musimboti werudaviro rudiki.

8. Kutema Zviito: Gonesa kudhirowa kwakazara uye kutarisa kwezviito uye zviitiko mukati megore rako nharaunda. Bata uye ongorora matanda kune chero zvisingaite kana zvingangoita zvakaipa zviitiko. Shandisa robust log management uye ruzivo rwekuchengetedza uye chiitiko manejimendi (SIEM) mhinduro yekuona uye kupindura kune zvekuchengetedza zviitiko nekukasira.

9. Kuongororwa Kwekusagadzikana Kwenguva Dzose: Ita ongororo yekusagadzikana uye kuyedza kupinda kuti uone kusasimba kwekuchengetedza munzvimbo yako yegore. Rongedza uye gadzirisa chero kusadzivirirwa kwakaonekwa nekukasira. Chengetedza zvigadziriso zvekuchengetedza uye zvigamba zvakaburitswa nemupi wako wegore uye simbisa kuti zvinoiswa nekukasira kudzivirira kutyisidzira kunozivikanwa.

10. Education uye Training: Kurudzira tsika yekuziva nezvekuchengetedza uye kupa dzidziso yenguva dzose kuvashandi maererano nekukosha kweiyo musimboti weiyo rombo rombo. Vadzidzisei nezvenjodzi dzinogona kuitika dzine chekuita neropafadzo dzakawandisa uye maitiro akanakisa ekutevera kana uchiwana uye kutonga zviwanikwa mukati memakore nharaunda.

11. Patches uye Updates: Deredza kusasimba nekugara uchigadziridza ese server software. Chengetedza zvivakwa zvako zvegore uye maapplication anoenderana kusvika parizvino kuti udzivirire kubva panjodzi inozivikanwa. Vanopa Cloud vanowanzo buritsa zvigamba zvekuchengetedza uye zvigadziriso, saka kugara uripo nemazano avo kwakakosha.

chivimbo

Zvinouya pasi kuvimba - kupa chete avo vari musangano rako chivimbo chekuzadzisa mabasa avanoda kuita kuti basa ravo riitwe. Nyanzvi dzekuchengetedza dzinokurudzira Zero Vimbai. Iyo Zero Trust yekuchengetedza modhi yakavakirwa pamisimboti mitatu yakakosha:

  • Simbisa zvakajeka - shandisa ese aripo data mapoinzi kusimbisa kuzivikanwa kwemushandisi uye kuwana.
  • Shandisa mukana-mudiki kuwana - nenguva uye chengetedzo yakakwana.
  • Fungidzira kutyora - encrypt zvese, shandisa proactive analytics uye uve nemhinduro yekukurumidzira munzvimbo.

Semutengi wegore uye makore masevhisi, zvinouya zvakare pasi kuvimba. Iwe unofanirwa kuzvibvunza, "ndinovimba nemutengesi wangu kuti achengete data rangu rinokosha mugore?" Vimba, mune iyi kesi, zvinoreva kuti unovimba nekambani iyoyo, kana imwe yakafanana nayo, kutonga chengetedzo sezvatatsanangura pamusoro. Neimwe nzira, kana ukapindura zvisina kunaka, wakagadzirira here kuita iwo marudzi mamwe chete ekuchengetedza manejimendi chiitiko munzvimbo yako yepamba. Unozvivimba here?

Sekambani inopa masevhisi mugore, vatengi vakaisa chivimbo chavo mauri kuchengetedza data ravo mune yako cloud infrastructure. Inzira inoenderera. Gara uchiziva nezve kutyisidzira kuri kubuda, gadzirisa matanho ako ekuchengetedza zvinoenderana, uye ubatane nenyanzvi dzine ruzivo kana varairidzi vezvekuchengetedza kuti uve nechokwadi chekuchengetedzwa kwakanyanya kwebhizinesi rako munzvimbo inogara ichishanduka yegore.

 

  1. https://www.bleepingcomputer.com/news/security/lastpass-hackers-stole-customer-vault-data-in-cloud-storage-breach/