Hackers business to provoke an "arms race»

The story six months ago: from the bank account of a large company was listed a few large sums for the benefit of unknown companies from out of town. It turned out that the bank has received relevant electronic payment orders signed by digital signature. But neither the director nor the chief accountant did not know about it. Business owners through connections in law enforcement agencies were able to quickly, with no paperwork to track money transfers, to block the accounts of recipients and return back. That's all calmed down. Less than a month as accounting company received an email from an Italian supplier with a request to transfer a regular payment for goods supplied - just a few hundred thousand euros - on other details, which was done. It soon became clear that the provider does not know anything about the new details, but the letter was a forged sender address. The delivered goods had to pay for the second round. "Management and the owners did not have to settle for a refund for the first time - analyzes errors CEO Alexei SecurIT Rajewski. - Was required to spend at least a superficial investigation to determine if individuals are not criminals, but at least the ways in which they are used. But in the end crooks got a second chance. " The philosophy of hacking. Cyber ​​crime is changing from the rare events in the category of ordinary, which is confirmed by statistics. According SecurIT, the cost of information security (IS) in the Russian companies in 2010 increased by 25-30% and equaled the pre-crisis 2008. And at the same time an increasing number of thefts of cash from bank accounts. Head of Customer Financial sector companies "Aladdin RD" Denis Kalemberg believes that a return to pre-crisis indicators, including costs associated with the growth of banks to protect against the theft of money from the accounts of their customers. According to him, in 2010, the cost of banks to provide information security has increased by 20%. The Director-General Leo Matveyev does SearchInform shows explosive growth in demand - in 3-4 times in 2010 - and predicts a doubling in 2011. Director General of Group-IB Ilya Sachkov approached the problem philosophically. "In 2010, expenditures on information security business grew, but the number of incidents has grown even more. That is, the number of accidents does not depend on the budget - he explains. - Companies should not engage with hackers in an "arms race" by updating its own security system after each incident. A planned to pursue criminals in the legal field. A new system of information security, by contrast, attracts hackers become for them a kind of challenges. Only the fear of inevitable punishment will reduce the number of IT-crimes. " Participants in the information security market talk about the importance of preventive measures, competent approach to IT-security. This usually means high costs of attracting well-known third-party specialist or company. But there are basic rules that comply with fairly simple. First, the need to protect confidential information should be regulated. "If the company's by no mode is set to protect confidential information, there is no security policy, legally it is considered that the organization is not confidential information, - says Alexey Raevsky. - Why can not it leaks or unauthorized access to, and hence the grounds for appeal to the police or the prosecution is very slim. " Second, the incidents leading some common mistakes that lists Leo Matveyev: free access to ICQ, Skype, to send outgoing mail from the workplace, lack of system automatically stops the sending of suspicious messages. Although this protection is not absolute. "The employee will try to send valuable information once, twice, then take pictures of the phone or just tell you who should, over a beer", - said Leo Matveyev. Price information. Another story: scammers infected workstation a major construction company accountant "trojan" and with it stole the keys of digital signature, which then signed several fake money orders for 3 million. Leadership decided that it is a mistake, and attempted to resolve the issue of returning the money through a bank, but do not give statements to the police. Moreover, the computer continued to work accountant, and even reinstalled the operating system. "Conduct an investigation was not possible, the chance to return no money left", - says Denis Kalemberg. He explains that the company had immediately contact the police and / or the company to investigate the incident (which was also turned to the police) and lock up your PC to prevent bad "clean up the tracks." "If the perpetrators of the incident were found and brought to justice, then the company, even less the cost of services for the investigation and all court costs, failed to return at least 80% of the money" - he said. Another example of ignorance: the hackers infiltrated the network of regional branch of a major FMCG-company (supplier of goods in the consumer sector) and remove the important financial information. In parallel, regardless of what the hackers got into a network virus. ITbezopasnosti office decided that the information deleted by a virus and not understanding the nature and sources of infection, began to deal with it yourself. "Lack of experience and, consequently, incorrect response resulted in a cascade of computers infected branches and destroy traces of malicious, - says Ilya net. - As a result, the branch was disconnected from the Internet and the parent company, its operating activities stood at 10 days and the investigation and bringing criminals to justice became impossible. " However, the market is gradually accumulating a standard response to the incident. All situations are placed in two schemes: lost money from my account and everything else. In the first case of appeal to the police inevitably, in the second, you can use the services of a private company or try to solve the problem on its own. But the corporate office of professional information security - expensive. According to task manager to work with clients of the financial sector of "Aladdin RD" Dennis Kalemberga, wages of highly skilled professionals can reach up to 100 rubles a month. The average cost of services for the disclosure of a domestic incident, provided by third party - 50 - 150 thousand rubles.