Lean Security Expert Lean Security Expert

How-to Improve Cyber Security For Non-Profit Organisations

The number of businesses and organisations that have been hacked by cyber-criminals and malicious hackers just keeps increasing.

Cyber-security experts are scrambling here and there to cover all vulnerable holes within a framework – considering no organisation is safe from hackers.

The number of businesses and organisations that have been hacked by cyber-criminals and malicious hackers just keeps increasing.

Cyber-security experts are scrambling here and there to cover all vulnerable holes within a framework – considering no organisation is safe from hackers.

From healthcare to banks, retail and government agencies… all are constantly at risk.

NGO’s – Why Do They Attract Cyber-Criminals

One point of attraction hackers and cyber-criminals have towards non-profit organisations is the large volume of sensitive data handled every day. This includes client records, donor information, confidential emails, and numerous other transactions passing through the organisation.

Cyber security should be at the top of every organisation’s priority list but how concerned should non-profits be in the face of increasing cyber attacks and security threats? How can non-profit organisations ensure their sensitive data remains secure from malicious threats?

More importantly, how can donor confidence in non-profit organisations and their security framework be re-established?

By Upgrading All Computers

Many non-profits don’t realize the importance of installing the latest computer systems. Are you still using an old version of Windows XP? Fun Fact: Microsoft no longer supports Windows XP.

This means computer systems operating on outdated software are even more vulnerable when it comes to cyber attacks and hacking.

Focus On Strong Passwords

Do you use the same password for every social network and website that you access? This will just make it easier for hackers to steal important information considering cracking one password will lead to a domino effect.

Change your passwords, even a slight difference will ensure that information cannot be accessed by another person. Can’t remember complicated passwords? Copy and keep it in a secure location like your work related diary.

What makes a great password? According to web application security experts Lean Security, there are 6 different ways you can build a strong password. What is the best way to make a strong password?

Mix up different types of characters used normally to make a password like numbers, letters, and symbols. Don’t use words that can be found in the dictionary.

Assess and Identify Security Risks

Improving cyber-security for your non-profit organisation is a team effort and needs to include representatives from IT, legal and compliance, HR, accounting, finance and operations departments. Order of the day should be risk management – assessing risks by making inventory of the organisation’s systems and data.

The web security assessment team’s first task is to rank systems and data according to importance and sensitivity. Risk and damage from the following events should be considered for good risk management:

  • Asset failure or loss
  • Asset theft
  • Exposure to unauthorised entry

You have a responsibility towards not just your donors but also the beneficiaries. Make sure cybercrimes don’t mar your credibility by focusing on improved security from internal and external forces. Get in touch with Lean Security for more information.

Read More
Network Security Lean Security Expert Network Security Lean Security Expert

Highlighting Open Source Software – How Detrimental It Is For Your Company

Like many businesses looking to increase productivity and efficiency without shelling out the extra bucks, you also must have thought about exploring the world of open source software.

Like many businesses looking to increase productivity and efficiency without shelling out the extra bucks, you also must have thought about exploring the world of open source software.

After all, it doesn’t make sense to spend a lot for Photoshop or Microsoft Office with better, more efficient and less costly (sometimes free) software available in the market!

Why should you even fork a ton of money on the newest Windows operating system for your business’s computer system when other cheap alternatives are easily available?

It does make sense to choose the cheaper alternative for some web applications. However, using open source software isn’t all milk and honey.

Try and learn more about this type of software before implementing in your operation.

Open Source Software – What It’s All About

It is a term that refers to something which can be modified and shared as its design is publically accessible. The term open source is normally used in the concept of software development, to design computer programs using a different or specific approach.

Open source software.png

 

Understanding Open Source Software

It is simple software with source code that allows barrier free access to content. Any software with such an open source code can be inspected, modified, and enhanced by people.

Source code is the part of software program that cannot be seen i.e. most computer users don’t ever see it. This is the code that individuals (programmers and hackers) manipulate and use to change entire aspects of a program or application. They can change how it works.

Still planning to give open source software a chance? Following are some advantages that can convince any company to try this type of software:

  • Cheaper than commercially marketed software
  • Helps an organisation become more flexible
  • Created by expert programmers
  • Highly reliable and efficient

As mentioned above, it’s not always milk and honey when it comes to using OSS. There are some disadvantages of this type of software, the first and most important one being security vulnerabilities.

While all software has some bugs and internal vulnerabilities – OSS has the added disadvantage of being used by malicious users for their own gain.

Older software usually has more security vulnerabilities that often go undetected or unreported. Make sure the OSS you are using isn’t out-of-date by many months or years.

You can have the web application security services of Lean Security at your beck and call during implementation of OSS or even closed sourced software. Check out our full service catalogue here.

Read More
Lean Security Expert Lean Security Expert

Infographic: Five Most Common Security Concerns Businesses Face Today

From untested system to exposed source, read five most common security concerns businesses face today

From untested system to exposed source, read five most common security concerns businesses face today

Read More
Lean Security Expert Lean Security Expert

Web Security Issues You’re Not Addressing

Back in 2013, a popular research study by the National Institute of Standards and Technology concluded that inadequate web security and tools cost the economy as much as $22.2 billion annually

Back in 2013, a popular research study by the National Institute of Standards and Technology concluded that inadequate web security and tools cost the economy as much as $22.2 billion annually.

Things don’t seem to be getting any better. As the modern business environment continues to grow so do the numbers of people looking to exploit key business information transmitted over the internet.

If you are looking forward to web security testing to identify if your website and applications deliver the data safety protection you promised, don’t forget to address the following issues.

Cross Site Scripting

Cross site scripting works by injecting code through a client-side script in the web application’s output. The primary concept behind cross site scripting to get hold of client side scripts and execute imminent steps just like the hacker would want.

It can be used to deface websites on your browser, redirect you to malicious websites and even hijack user sessions.

Broken Authentication

If you have issues like broken session management and authentication, address these issues before anything else. If your authentication credentials are not protected, broken sessions management could be the perfect chance to breach into your company data.

Insecure References

When a web application exposes any reference to an internal implementation page, it is called insecure direct object reference. Internal pages could show up in the form of database records, keys, directories and even other confidential information. It’s as simple as this—when a webpage leads to a reference where critical information is displayed, this page can be used to access other parts of your website including personal data.

Security Misconfigurations

Security misconfigurations often go unnoticed and they are among the most common issues behind security risks and vulnerabilities. A secure configuration must be deployed for database server, web server, frameworks, and the platform.

Double check all configurations as even the slightest error here could end up compromising your entire system.

SQL Injections

SQL injection issues involve a hacker who attempts to use application code to access, corrupt or modify database content. In case the hacker is successful, he/she will be able to edit, alter, read and delete data from backend database. While SQL injections are among the most common web security issues, they are also among the most ignored.

Looking for a penetration testing provider how offers web and application security testing? You’ve come to the right place. We offer a wide variety of services, all aimed at making your websites, applications and IT infrastructures safer and more efficient. Get in touch with us to discuss your needs.

Read More
Lean Security Expert Lean Security Expert

Conducting Web Application Testing On Your Own? This Checklist Will Help

All business owners want their websites to work smoothly and leave the right impression on their customers. Apart from the web design and how web applications seem on the surface, there’s a lot that can be done to prevent unpleasant surprises.

All business owners want their websites to work smoothly and leave the right impression on their customers. Apart from the web design and how web applications seem on the surface, there’s a lot that can be done to prevent unpleasant surprises.

One easy way to ensure that your web applications and consequently website is functioning like it should, is to conduct a web application test.

Even though it is better left to pros like us, here is a quick checklist that will allow you to conduct web application tests on your own: 

Functionality

This step includes checking all the links in web pages, forms used to submit information, cookie information and database connections.

Check Links

· Test all internal links

· Test jumping links on same pages

· Test all outgoing links

· Double check for broken links in all the links mentioned above

Check Forms

Forms play a key role in acquiring customer information that facilitates online business operations. Here are a few things you should check here:

· Check default values in fields

· Check validation in all fields

· Check all options to generate forms

· Check fields by inputting wrong values

Usability

All content used across web pages should be logical and easy to understand. Check content for spelling mistakes and avoid use of dark colours. Each and every anchor link should be working; images should be positioned and sized in coherence with the rest of the layout.

There should be a sitemap for all the links in the website with a precise tree view of navigation. Double check onsite search options.

Interface Testing

The primary interfaces are application server and web server. Double check; all the interactions between these servers should be streamlined.

If the database returns with an error message, the application server should be able to catch these errors and display them. Also consider checking what happens when a transaction is interrupted in between. Similarly, find out what happens if the web server connection is reset.

Security Testing

Web application security is essential to ensure that customer data is kept safe and protected at all times.

· If you are logged in with a username and password, try changing the link in the address bar to see what happens.

· What happens when you paste an internal URL on the browser address bar?

· Try inputting invalid username and password details to see how the web application responds.

· Test CAPTCHA.

· If you are using SSL, it should be able to display a logo when users switch between an unprotected and protected webpage.

But that’s not it. There’s a lot more to application security testing than these pointers. As the leading name in the web application security testing industry, we conduct thorough inspections of all your applications, leaving no stone unturned and no gaps left behind.

We also offer highly reliable mobile application security testing services. Get in touch with us to learn more about the services you need.

Read More