When hundreds of thousands of documents rained down on Wall Street on September 11 – a sight observers described as reminiscent of a ticker tape parade – it was a wake up call to businesses around the world to consider data security and storage options to protect their clients and themselves.
And, as Wall Street got back to business the following week, people began to apply the experience to their own lives, not just in terms of extraordinary disasters like the one in New York, but in preparation for more common events such as fires and floods.
Beyond Cash Donations: How New Forms of Giving Are Transforming Not-for-Profit Accounting
Evolving Funding Landscape for Not-for-Profits Not-for-profit organizations are being asked to do more with less,…
Learn More
Joe Forlingieri, director of the TotalStorage Solution Center (TSSC), a company opened in Lincoln last summer by IBM partner Lighthouse Computer Services, Inc, said that he has noticed an increased interest in data security since the September 11 attacks.
“It is unfortunate that it takes an event like that to make people aware of the importance of data,” he said.
The function of the TSSC is to put in place customized storage plans for clients, as well as offer them training services.
The most common storage solutions involve the use of a storage server in a company’s computer room, which stores information from each of a company’s computers. Clients may also opt for off-site back-up storage.
Tim Hebert, chief technology officer at Atrion Networking Corporation in Warwick, said that in light of the terrorist attacks “people are really looking at their disaster recovery mechanisms. If your information isn’t backed up at another location, you could be out of business.”
Hebert said while almost all companies need data security to some extent, there are certain types of companies he would identify as high risk: banking, finance, medical, many in the high tech sector and “anything involving a client transaction,” like credit card companies, e-commerce, etc.
“Storage has been a big issue in the high tech industry in the last two or three years,” he said. “I think part of it is a lot of companies that have been growing in the past couple of years are technology-based companies.”
Hebert’s business partner, Atrion Chief Executive Officer Charles Nault, pointed out that even at more traditional businesses, the trend toward customer relationship management (CRM) has increased the interest in information security.
Through a CRM system, a company can store information about a customer regarding search preferences and past purchases. For example, using “cookies” (small text files placed on a computer’s hard drive to collect information about user activity on the site), Web pages can be customized according to user preferences, based on stored information on what a user did on the last visit to a site.
“It shows an interest in the customer, but the storage requirement for that is huge,” said Nault.
Nault said that information security is a “strategy, not a Band-Aid.” With so many different aspects to security – necessitated by so many different modes of attack – virus protection and content filtering are only two of the security options open to companies interested in securing vital information.
“That’s why a security policy is really important,” said Nault.
An Aug. 29 poll, conducted on Providence Business News’s Web site, showed that 44 percent of the site’s visitors who responded to the poll had been significantly affected by a computer virus within the previous 30 days. Fifty-six percent said they had not.
In a separate PBN poll, conducted on Sept. 28, many respondents said they currently store vital data off-site (38 percent), but most do not (62 percent).
In a third poll, conducted on Oct. 1, 62 percent of respondents said their companies budgeted for data storage; 23 percent said their companies did not, while 15 percent were unsure.
A report from the International Data Corporation (IDC) predicts that worldwide, Internet security revenue will exceed $14 billion by 2005.
According to IDC, all four security software markets – firewalls, encryption software, antivirus software, and security authentication, authorization and administration (3A) — grew 25 percent or more in 2000, with the firewalls segment growing the most at 42 percent.
Overall, worldwide Internet security software revenue jumped 33 percent to $5.1 billion in 2000. By 2005, IDC predicts that this market will amass more than $14 billion in revenue – a 2000-2005 compound annual growth rate (CAGR) of 23 percent.
And a separate IDC report suggests that security is regarded more and more as a necessity, not a luxury.
“For companies conducting eBusiness, security and privacy options aren’t value-added features. They’re core requirements for conducting business,” said Lucie Draper, an analyst with IDC’s Technology Integration Panel Study research program.
IDC has found that in all industries, antiviral tools are the most common security technology; more than 90 percent of respondents to the survey indicated their organizations had been impacted by a virus. While viruses strike a significant number of companies regardless of industry, what distinguished industries is their ability to repel virus attacks at their inception. The resources, government, and utilities sectors are the most likely to stop a virus attack before it causes any damage.
On the other hand, retail, education, engineering and management, health care services and transportation companies have the most trouble recognizing and stopping virus attacks.
Last summer, computer systems in the U.S. and abroad were hit hard by two versions of the Code Red virus. Originally deployed in mid-July, the CERT Coordination Center (CERT/CC) began receiving notifications of Code Red II infections on Aug. 4, according to the organization’s Web site.
The organization has since reported that it continues to receive notifications of Code Red II infections.
The total number of systems affected by Code Red is not known.
The newest virus on the loose is Nimda, which was deployed on Sept. 18.
The Nimda virus can be spread to end-users through an e-mail attachment called README.EXE or by surfing an infected Web site. Once a computer is infected, the worm continues to spread in two different ways: via e-mails directed to addresses found from a user’s e-mail inbox and through randomly scanning Internet addresses, trying to locate servers to infect.
“The scary thing about Nimda is that the points of contagion are so widespread,” said Erik Petersen, chief operations officer at Providence-based Orbidex, Inc.
Petersen said many Web site “traffic reports” may reflect high numbers of hits because of Nimda, which scans random Internet addresses trying to locate vulnerable IIS Web servers and in doing so, generates massive amounts of Internet traffic.
“Somebody has really put effort into this one,” said Mikko Hypponen, manager of Anti-Virus Research at Espoo, Finland-based Internet security firm F-Secure Corporation (with a North American headquarters in San Jose, California). “This worm is spreading fast mainly because it’s combining many of the earlier attacks into one.”
According to the F-Secure Web site, Nimda is the first worm to modify existing Web sites to start offering infected files for download. It is also the first worm to use normal end user machines to scan for vulnerable Web sites, enabling Nimda to easily reach intranet Web sites located behind firewalls – something worms such as Code Red couldn’t do.
Online news service CNET reported 120,000 new Nimda infections detected during a single 24-hour period.
The latest security patches from Microsoft for Outlook and IIS Web server will close the vulnerabilities the worm is using. With the outbreaks of Code Red (and a number of variants) and Nimda in the last few months, Petersen thinks it may be time to reevaluate the ways in which computer-users conduct business.












