USING WHAT WORKS

Duda Owner IONOS • January 10, 2014

Even the bad guys and bad girls have some smarts.  They know enough to use what works.  This is definitely true when it comes to cybersecurity.  So my question is why don’t we?

Kaspersky released its 2013 annual report last month.  It contains various cybersecurity highlights from which we can learn.  Unless companies and individuals remain vigilant, some of these highlights will likely be highlights again in Kaspersky’s 2014 report.

The one that jumps out to me the most is software vulnerability.  When basic software used my most PCs is not updated in a timely manner, this leaves the door wide open for hackers to have their way.  Java is a prime example of this as explained in the bulletin:

Cybercriminals have continued to make widespread use of vulnerabilities in legitimate software to launch malware attacks.  They do this using exploits—fragments of code designed to use a vulnerability in a program to install malware on a victim’s computer without the need for any user interaction.  This exploit code may be embedded in a specially-crafted e-mail attachment, or it may target a vulnerability in the browser.  The exploit acts as a loader for the malware the cybercriminal wishes to install. . . . Cybercriminals focus their attention on applications that are widely-used and are likely to remain unpatched for the longest time—giving them a large window of opportunity through which to achieve their goals.  In 2013, Java vulnerabilities accounted for around 90.52% of attacks . . . .  This follows an established trend and isn’t surprising.  Java is not only installed on a huge number of computers (3 billion, according to Oracle), but its updates are not installed automatically. . . . To reduce their ‘attack surface’, businesses must ensure that they run the latest versions of all software used in the company, apply security updates as they become available and remove software that is no longer needed in the organization. ” (pp. 17–18)

These are startling statistics and excellent—albeit basic—advice.  Unfortunately, the relative success of the hackers reveals the inattentiveness of many businesses and individuals.

A basic principle of warfare is that we should know our enemy and know ourselves.  It seems we are falling down on both counts.





By James Meadows July 13, 2026
What every front desk professional should know about credit card surcharging
By James Meadows September 7, 2025
Is a college degree still worth the investment? It depends of the path you craft.
By James Meadows August 12, 2025
You need to give serious thought to taming the tiger before you are in its cage.
By James Meadows June 8, 2025
My transparent reflection about my five-year post-layoff experience, how I navigated it, learned through it, and identified some wisdom that might inspire others.
By James Meadows June 29, 2024
The earliest days of this series present fundamentally significant leadership content.
By James Meadows August 22, 2023
What we should expect from fidelity to science.
Honesty, honest,  honestly
By James Meadows August 9, 2023
We explore the overuse or inappropriate use of the words "honest," "honesty," and "honestly." Much of the overuse or inappropriate use of these words is in contexts that intrinsically message the audience that the speaker is not trustworthy. I call the overuse or inappropriate use of these words in this context HONESTY VALIDATORS because the speaker believes they validate the truth being spoken. We need a solution to this problem. My solution is to replace these honesty validators with CLARITY VALIDATORS. Instead of trying to be honest, try to be clear. Replacing "honest," "honesty," and "honestly," with "clear," "clarity," and "clearly," produces significantly more benefit to the speaker and to the audience.
By James Meadows August 7, 2023
It's the real thing alright!
By James Meadows May 30, 2023
Reflecting on 30 years as a PC user.
By James Meadows July 26, 2020
What the Boeing 737 Max crashes teach us about training, corporate culture, and communication.