Examining evidence
by Sathya Mithra Ashok on Tuesday, 26 May 2009
“People ask us to analyse some incident or other and we perform a full examination of the material provided. We pass on our findings which are then used in court or by other agencies. Our descriptions are also used by organisations to formulate preliminary expert appraisals,” explains Stefan Tanase, researcher, global research and analysis team over at Kaspersky Lab EEMEA.
Similar services are offered by eHDF, which has a team based within the region, as well as McAfee which calls in experts from Europe. While a significant number of large enterprises in the Middle East, especially those who are sensitive to data loss, call in the resources offered by these firms, especially for pre-emptive penetration testing, many of them still do not believe in having an in-house person to constantly test their network and applications for vulnerabilities.
“Ethical hackers are traditionally security experts or analysts who perform penetration testing activities on the applications, systems and networks upon formal approval by the business. They are important elements of security as they provide the technology and the guidance required to proactively strengthen related elements before an external hacker exploits the same,” points out Baig.
The role of ethical hackers within an organisation is to constantly test the integrity of the systems to ensure that they are not prone to attacks. Much of this testing is done by simulating attacks and trying to get through the company’s defences, just like any true-blue hacker.
“Ethical hackers in a customer’s internal environment are a definite value add as they will enable the company to answer the question of where the organisation stands today with respect to information security. We need to bear in mind at all times that we cannot protect ourselves from an external threat environment that is dynamic with an internal security architecture and protection process that is static,” says Premchand Kurup, CEO of Paramount Computer Systems.
While the relative availability of ethical hackers remains limited in the region, enterprises that do need such in-house resources can tap into talent pools in either India or Europe. Despite these advantages, hackers remain in the minority within regional organisations.
Counting advantages
Forensics, whether performed remotely or by an in-house team, comes with various advantages.
READERS' COMMENTS
MORE FROM ARABIANBUSINESS.COM
TOP IN MIDDLE EAST TECHNOLOGY
TOP MIDDLE EAST BUSINESS STORIES
ALSO IN MIDDLE EAST TECHNOLOGY
SHARE PRICE CHECK
RELATED STORIES
e-Hosting Datafort
- Lease versus build: The data centre debate
14 Oct '09 | Interviews - Head of the class
16 Mar '09 | Features
Kaspersky
- Courting corporates
16 Aug '09 | Features - Kaspersky fights the grey tide
12 Aug '09 | News - Kaspersky planning for growth in the Middle East
26 Jun '09 | News
McAfee
- Downhill drag
11 Nov '09 | Features - Secure strategy
1 Nov '09 | Interviews - 10 most dangerous celebrities
26 Aug '09 | In Pictures
Paramount Computer Systems
- Securing the future today
23 Mar '09 | Features - Paramount gears up for security shift
12 May '08 | Interviews




