Fraud Awareness - Types of threats

The advent of World Wide Web or the internet has made the data transmission very convenient lending ways for organizations to develop and deploy many critical applications using this medium.  Increased speed and lower bandwidth costs has made the medium even more popular.  Most of the enterprise applications like CRM, HRMS, some ERPs, portals etc. are deployed over the net for ease of access.

While using web-based architecture makes the deployment and access very convenient and cost effective, it exposes the risk of unauthorized access to undesirable audience.  If the password of an application is compromised, there is no way for an application to distinguish between an authorized and an unauthorized access.  There are several ways passwords can be leaked:

The Risk  
When the passwords are compromised the access to the system is automatically granted.  Unauthorized access can lead to any of the following:
  • Data Theft:  Unauthorized users can have access to confidential data that can be put to undesirable use.  Systems like CRM, HR, business applications contain critical business information like key customer details, HR applications contain confidential payroll/salary data and various other business applications can have sensitive, critical and confidential information that if misused, can be very costly to a business.
  • Data Corruption:  Once system access is in the hands of users who would like to harm an organization, deleting or changing critical information can render the data corrupt and if such data corruption is not caught immediately any attempt to restore can become very tedious, error prone and in some cases extremely costly. For example, if in CRM or business application data mapping is changed, all subsequent transactions get mapped incorrectly impacting the overall calculations.  While data mapping can be restore if and when caught, the resulting transactions can be either very tedious/error prone or irreversible due to various dependencies.
  • System instability:  If some master data or configuration settings are changed, application can become very instable or practically stalled till the time such instability is restored.  Such malicious changes are very difficult to track and at times lead to unpleasant and painful troubleshooting with vendors.  Sometimes such activities are never traceable and doubts are placed on the vendor application.
  • IP Theft:  Even though many applications purchased by various organizations are derived from industry standards, the customizations done by organizations are very specific to their processes. Organizations spend significant amount of time and money on defining these processes and the intellectual property can easily be passed on to the competitors through such unauthorized usage.
Solution from Bennett  
Bennett has launched an anti-fraud solution that can help minimize most of these threats and make these applications resistant to a majority of the these threats. In addition to our anti fraud product, we at Bennett offer customized security applications including anti-money laundering, multi factor authentication and fraud detection software
Partners
 
hit