You need authentication
I am constantly amazed at the lassez faire attitude
that the majority of businesses, large and small, have about their online
security.
Those that require their users / members to log on
will provide a user name and password log in to verify their identity – and
that’s it.
I suppose that if the large players like Amazon and
iTunes can get away with it then the smaller guys think that’s all they need
to.
The reality is that if the big boys get a hit – they
have the firepower to deal with it.
But SME’s just need one bad hack and they are out of business.
2011 is going down as the year of the ‘Hack’ ( http://www.infosecurity-magazine.com/view/22481/year-of-the-hack-/?utm_source=twitterfeed&utm_medium=twitter) with
many high profile victims like SONY, RSA and Epsilon losing millions of their
users personal information. Despite this there seems to be the
attitude that ‘ it cant happen to me’
. I have just read
about the latest phishing scam targeting Amazon users ( http://bit.ly/tXBENH ) – warning you that your
account is about to expire and that you need to re-register. In the process handing over your precious
information and opening up your Amazon account to the hacker. There is also one going
around for PayPal and Apple at the moment. Yet they persist with user name and password. Incredible.
I
suspect there is a bit of the “ it wont
happen to me “ but also I
believe that most SME owners think that they just can’t afford a proper
solution because the image created by the industry is that you have to be a big
corporate to have ‘proper’ security. It clearly is not true. There are more and more solutions now targeting
the ‘low’ end of the market.
While some are ‘samey’ to
the big guys there are one or two which are really quite unique. What should you look for in such
a solution ?
It needs
to be easy to get. You shouldn’t have to call someone – have someone
visit you – do some kind of an IT project. It should be a SAAS service available on line and easy to
integrate.
It needs
to be easy to use. Your users should not have to get some ‘thing’ - be it a token ( physical or otherwise
), a dongle, a card reader, a USB key or even a cookie or some kind of
software download. Ideally
your users should rely on something they already have like their smart-phone or
their laptops as part of the solution.
It should
not cost a lot. Ideally
some kind of ‘Pay as you Go’ solution which means that you don’t incur any
unnecessary expenditure upfront in getting the product in place.
If you are going for something that is more
complicated than that then you are making your life difficult. Check out http://www.liveensure.com
Comments
Post a Comment