Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Arrogance Undermines Best Antivirus Defense

Overconfidence and a series of missteps allow a virus through the corporate defenses.

July 21, 2003 12:00 PM ET

Computerworld - I've always been proud of my security team's antivirus defense and scathing in my criticism of other companies that have had virus problems, believing as I did that any organization can eliminate virus problems by using a simple, layered defense like ours.
We deploy antivirus software on our desktops, on our file, Web and e-mail servers, and at the e-mail and Web gateways. We even use an outsourced e-mail scanning service. We use a range of vendors' products and update signatures daily. I'm proud of that system.
But then, pride goes before the fall.
It started when the PC support team reported that a user said he was receiving a weird e-mail message. An antivirus software pop-up had been reporting a virus on the user's machine since Thursday. Now it was Monday, and he was just calling it in.
This wasn't good. We have centralized desktop virus reporting, so we should have known about the problem right away and informed the user, not the other way around. What went wrong?
The central antivirus server had been decommissioned for an upgrade from Windows NT 4 to Windows 2000, but the new build had problems and now no central server was online. Instead of getting the new server working and then turning off the old one, someone decided it would be quicker to just rebuild the old one. With decent server and gateway protection, this person presumed we'd be OK without the server for a few days. Then those few days stretched into weeks.
Stupidly, I'd taken the complete lack of alerts from this server to mean that there were no problems to report, when in fact it indicated a failure in our reporting infrastructure.
We managed to track the infection to a new user whose machine didn't have antivirus software. This flies in the face of our antivirus policy. How could it have happened?
The support group's process for new builds is to install Windows and the applications and then push the antivirus configuration from the central antivirus server -- which was down for rebuilding.
Not only did we not have central reporting, but also we had no protection on new machines rolled out during the two weeks the machine was down. What caused me to miss this? In a word, complacency. We hadn't had a virus outbreak for two years, and we had lowered our guard.
Fortunately, the previously deployed client software was configured to download updates from the Internet as well as the central server, so at least the



Jump to comments

Security

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs