<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: Tag employee</title>
    <link>http://blog.clearnetsec.com/articles/tag/employee</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>tough to find where to begin</title>
      <description>&lt;p&gt;I shouldn't be shocked, but I am. A piece of the conversation  today we had with a client went something like this:&lt;/p&gt;
&lt;blockquote&gt;&lt;p&gt;client: yeah, we also just found out we have an ex-employee  logging in from the internet to our servers and helping other nurses with some  computer tasks&lt;/p&gt;
&lt;p&gt;us: um, you have an ex-employee logging into your servers  remotely?&lt;/p&gt;
&lt;p&gt;client: yes&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Talk about scary. I wish I could say more.  Let's just say this is relatively minor compared to other illegitimate activities  this particular client is suffering from (e.g. knowledgeable attackers with  clear targets).&amp;nbsp; It is quickly turning  into one of those scenarios whereby you can&amp;rsquo;t trust the integrity of anything  electronic.&lt;/p&gt;
&lt;p&gt;On top of that, it&amp;rsquo;s another flare on why it is so important  to just know what is and should be happening on your network.&amp;nbsp; Forget about all the fancy security  solutions; what is important first is to understand why and how devices talk.&amp;nbsp; Do these systems over here need to talk to  these systems here?&amp;nbsp; No.&amp;nbsp; Why are they talking then?&amp;nbsp; &lt;/p&gt;
&lt;p&gt;This client has security point solutions in place, but they  haven&amp;rsquo;t a clue what is happening or why.&amp;nbsp;  If you spend the time to define the relationships, catching potentially  illegitimate activity is a LOT easier. &lt;/p&gt;

</description>
      <pubDate>Tue, 25 Apr 2006 02:13:00 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:e25d2bcf-db20-4ec3-976e-aef90edf5e1c</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2006/04/25/tough-to-find-where-to-begin</link>
      <category>security</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>ex</category>
      <category>employee</category>
      <category>compromise</category>
    </item>
  </channel>
</rss>
