South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
I think you missed the sarcasm.A network firewall is just a fraction of all cyber security controls so only having a firewall (even if it is administered by a competent team) is like wearing 5% of a condom and then wondering why a swimmer got past.
If you use cloud/SaaS services, Exchange Online, Onedrive, Wetransfer, Dropbox, etc. then all of those are not protected by a network firewall. It's like locking the front door but your employees are doing dumb stuff with your client data in an unprotected building down the street.
I did. My bad.I think you missed the sarcasm.
If that is the case then JD Group can save huge bucks by replacing their Fortigates with Mikrotiks. No need to blow all your money on a 5% firewall condom like Fortinet.A network firewall is just a fraction of all cyber security controls so only having a firewall (even if it is administered by a competent team) is like wearing 5% of a condom and then wondering why a swimmer got past.
If you use cloud/SaaS services, Exchange Online, Onedrive, Wetransfer, Dropbox, etc. then all of those are not protected by a network firewall. It's like locking the front door but your employees are doing dumb stuff with your client data in an unprotected building down the street.
Nooit. Me???I think you missed the sarcasm.
What's the bet it wasnt on a server...What's the bet it was a Windows server .....
Never trust the State with your personal information..... nor who they collect it from or distribute it to.
Is your bank connected to home affairs' db with your permission?
We sometimes need to learn the hard way.Never trust the State with your personal information..... nor who they collect it from or distribute it to.
Is your bank connected to home affairs' db with your permission?
Private companies too. Like this one, all the banks, cellphone providers and more.
we still dont know how it has accessed, so the wall of text @r00igev@@r wrote might be all for nothing,
it might be something super simple like a flash drive shared between people.
now we see if all those POPIA laws are actually worth the paper they are written on.I know it was not hacking a server. This was more than likely a staff member giving the information away or selling it. As usual.
Fun tip, even script kiddies know how to use double quotes.Fun tip. Pepper commas into your passwords. If it gets leaked at least you can break the CSV a little.
now we see if all those POPIA laws are actually worth the paper they are written on.
Here's a thought... Train your humans. All the tech in the world can't prevent ignorance.If that is the case then JD Group can save huge bucks by replacing their Fortigates with Mikrotiks. No need to blow all your money on a 5% firewall condom like Fortinet.Why spent 100% of your budget on 5% of the mitigation? I must use that in my next conversation with firewall admins...
My opinion is that this reasoning is flawed. In most cases admin configure DNS to the local ISP instead of Quad9. The local ISP when lead you to command and control faster than what you can say a Russian and slaptjips. They also probably have hundreds of stale rules and no documentation. Because not documenting what things do is a way to make you more safe so not only do the bad players not know what you doing but also yourself. Irrational, IMO. Then of course they are also using advanced traffic analytics because hacks usually occur with persistence. Weeks before the hack you'll see the Chinese receive the data.
Then of course they are most likely have the 5% condom configured using network attributes instead of identity. Even though they bought the identity license and everything else including the kitchen sink and SD-WAN.
And then the firewall is so good that you don't need micro segmentation and you can get to all your internal IoT devices including cameras and access control directly on the internal network which is just one zone. Because your only need three zones: internal, external and DMZ. The latter is best left empty according to best practice.
Cloud services are indeed not protected by a network firewall from a commercial vendor because they don't want to be hacked. They use Linux's netfilter. Most commercial firewalls are 10 year old forks of Linux or BSD and somehow we are meant to believe they can program the kernel better than the experts. Ja nee well fine.
Most companies with Fortigates push their websites through Cloudflare because inherently they know the their expensive tin sucks. Cloudflare is just Linux netfilter with a web UI that aggregates and orchestrates some sophisticated techniques. Here is a thought, maybe just use the cloud technology at the edge as well???
You can open the markets up to competition, though.Here's a thought... Train your humans. All the tech in the world can't prevent ignorance.
I'm convinced you're making a point somewhere in there.You can open the markets up to competition, though.
The only training needed is how the West turned the tables on their overlords, and then promptly fell asleep at the wheel ala Jefferson's eternal vigilance.
Human beings respond to incentives, given they first commit themselves to the moral principle of strictly voluntary interaction.