Most businesses and organizations have a web presence to share information on the Internet with interested parties. Consider the amount of data that can be obtained through an organizations web site, almost any information that has been used in the daily course of operations has likely moved through the web server. There are financial records as well as personally identifiable information pertaining to the customers. This amount of information becomes a high value target for would be attackers.
Stories in the news media of breaches to corporate data are not rare, quite the contrary most people hear about these data breaches regularly. Not only is a data breach a stain on the company’s image it can have serious consequences to the victims whose information was stolen. Identity theft can cause tremendous hardship, not only are there inconveniences such as changing credit cards but there too can long lasting effects from a damaged credit report. Web servers have become a prime target for attackers seeking valuable information.
Not only are attackers looking for financial or personal information alterations on an organizations web site are also common targets. Attackers that have philosophical or political differences with a company can target webservers to place embarrassing or misleading information. When unauthorized individuals alter a corporation’s web presence it can cause mistrust among its customers and business partners. Web site defacement is a common tactic employed during a web attack against an organization.
With the amount of data available on web servers and the public’s reliance on accessing this information via the Internet organizations need to take steps to mitigate the risks of attack. Web servers are a vulnerable target that carries a high reward with little risk. Some companies would rather hide the fact their server was breached than take the proper steps to mitigate risks. Not having a mitigation plan in place can expose the organization to unnecessary risks and potential liability in the event of an online attack.
The economic damages to an attack coupled with the damage to reputation can be catastrophic to a business. Consider the impact that a data breach had on Yahoo, between 2013-2014 approximately 1.5 billon user accounts were compromised (Armerding, 2018). The news was released in 2016 during sales negations, this revelation caused the price to fall by 350 million dollars (Armerding, 2018). Most organizations would be crippled or possibly bankrupted by an attack of this magnitude. The Yahoo attack targeted the real names, addresses, dates of birth, and telephone numbers, in some cases even the security questions and answers were compromised (Armerding, 2018).
Attackers are not just looking for personal information but also financial information. In 2008 Heartland Payment Systems exposed 134 million credit cards through a SQL injection attack (Armerding, 2018). The attack was not discovered for almost a year, when credit card issuers notified the company of suspicious transactions (Armerding, 2018). Heartland was found to not be compliant with the Payment Card Industry Data Security Standard and paid 145 million dollars in compensation because of the breach (Armerding, 2018).

Security must be a top priority for businesses. Consider the two examples above and the financial impact that a security breach can have on an organization. Most companies run on tight margins that cannot afford the unforeseen burden of losses in the millions of dollars, let alone the lasting impact of public perception due to a data breach. Organizations need to mitigate their risks as the sophistication of the attackers continues to grow. Not only are organizations needed to safeguard against small groups of attackers that work for personal gain but must protect against state sponsored groups with vast resources expert knowledge (Armerding, 2018).
Keeping a secure webserver is one of the foundations of a good security policy. The web server is the main point of online contact for visitors coming to an organizations website (Techopedia, n.d.). The web servers deliver data to browsers that request data, it is not uncommon for companies to have several different web servers to run their online presence (Techopedia, n.d.). With the numbers of servers that are running on the internet it is not a surprise that they are so commonly targeted for exploitation.
Over 45 percent of webservers run Apache server to perform the functions of a web server (W3Techs, n.d.). This provides many potential targets that perform in a similar manner. Web servers running open source software that have known bugs that are not patched can become an inviting target for would be attackers. For comparison only about, 10 percent of web servers run Microsoft IIS operating systems (W3Techs, n.d.). It is important for IT personnel to keep software up to date to minimize security risks.
Despite the financial devastation that can occur from a data breach some organizations are more concerned with the damage to their reputation after a security event (Security Magazine, 2017). The biggest fear that many companies express is not the data breach but potential long-term damage to their brand (Security Magazine, 2017). It is interesting that numerous corporations would be more concerned with their reputation than with the safety of their customer’s data, considering that nineteen people fall victim to identity theft every minute (Trans Union, 2016).
It is reported that 76 percent of organizations do not have a strategy or fundamental knowledge with regard to critical assets and vulnerabilities (Security Magazine, 2017). Despite the risks that their customers face for identity theft most organizations do not have a comprehensive security policy in place. Individuals who face personal data theft can have accounts opened in their name and suffer long term credit rating damage (Trans Union, 2016). Not only will the customer have to prove that the accounts were opened fraudulently but there could be significant court costs to deal with creditor lawsuits (Trans Union, 2016). With the potential damage that can occur to customers organizations would be well served from making security a priority for their customers as well as their bottom line.
There are numerous methods that attackers can use in an attempt to gain access to unauthorized information. According to Rapid 7, a computer security company some of the most common are:
- SQL Injection Attack: This attack uses malicious code that is injected into a SQL statement that causes the server to display information that it normally would not show. This can be a serious concern if there is sensitive customer data stored on the server. This attack works by exploiting known SQL vulnerabilities.
- Cross Site Scripting: This attack is similar to SQL injection but rather targets the user visiting the website. Malicious code is placed on the compromised site and then runs on the visitor’s browser, this attack targets the visitor and not the organization itself.
- Denial of Service Attacks: This type of attack overloads the webserver of the organization with more traffic than it was designed to handle, thus rendering the website inoperable.
- Session Hijacking and Man-in-the-Middle Attacks: This type of attack involves hijacking the session id between a legitimate user and a webserver and using it for unauthorized access. If the attacker gets between the user and the webserver this is known as a man in the middle attack and the attacker can read information in both directions.
With these types of risks and the potential financial devastation that can occur with a data breach web server security needs to be on the top of any organizations list.
Implementation of an IT governance framework can help organizations mitigate risks as well as improve their bottom line, thereby satisfying the need for customer security and maintaining brand image. Agencies with effective IT governance generate more return on their IT investments than their competitors (Devos & Van de Ginste, 2015). Implementation of COBIT framework tackles the following needs:
- Meeting Stakeholder Needs
- Covering the Enterprise End to End
- Applying a single, Integrated Framework
- Enabling a Holistic Approach
- Separating Governance from Management (Devos & Van de Ginste, 2015).
Through the use of a framework security needs for the organization as well as the customer can be maintained, and risks mitigated.
References
Armerding, T. (2018, Jan. 26). The 17 biggest data breaches of the 21st century. Retrieved from CSO Online: https://www.csoonline.com/article/2130877/data-breach/the-biggest-data-breaches-of-the-21st-century.html
Devos, J., & Van de Ginste, K. (2015). Towards a Theoretical Foundation of IT Governance – The COBIT 5 Case. The Electronic Journal Information Systems Evaluation, 95-103.
Rapid 7. (n.d.). Common Types of Cybersecurity Attacks. Retrieved Aug 17, 2018, from Rapid 7: https://www.rapid7.com/fundamentals/types-of-attacks/
Security Magazine. (2017, Feb 3). Enterprises Fear Brand Damage More Than Breaches. Retrieved from Security Magazine: https://www.securitymagazine.com/articles/87779-enterprises-fear-brand-damage-more-than-breaches
Techopedia. (n.d.). Web Server. Retrieved Aug 17, 2018, from Techopedia: https://www.techopedia.com/definition/4928/web-server
Trans Union. (2016, Oct 12). What are the Effects of Identity Theft? Retrieved from Trans Union: https://www.transunion.com/blog/identity-protection/what-are-the-effects-of-identity-theft
W3Techs. (n.d.). Usage of Webservers for Websites. Retrieved Aug 18, 2018, from w3Techs: https://w3techs.com/technologies/overview/web_server/all

