My top security myths, or security excuses, call them what you want.
I hear these all of the time from clients and everyone believes them.
- We have a firewall, therefore, we are secure.
- It is only a test server, it does not need to be secured.
- It’s on the internal network, it doesn’t need to be secured.
- No one would break in like that.
- Wireless signals do not leave the building.
- If we apply updates, all of our servers and desktops will crash.
- Virtual servers do not need anti virus.
- Everyone else does security this way, why can’t we ? (if all of your friends jumped off a bridge, would you jump off a bridge?)
- You only need to audit our firewalls, you do not need to check the external web servers, those are secure.
- If someone broke into our network, we would know about it.
- Macs and Linux don’t have security problems, never get hacked and dont need anti virus.
- Firefox is more secure than Internet explorer.
- Microsoft CANT be secured.
- A friend forwarded me an email, therefore it is true.
- Our former employees would not attack our systems. We trust them, even though we just fired them, we don’t need to change passwords.
- No one would attack us, we are to small to have anything of value.