Home » News » Currently Reading:

SQL injection is top SMB database security concern

May 18, 2012 News

A survey of more than six thousand IT administrators, DBAs, data security professionals and consultants about their most critical database security concerns has highlighted that the respondents’ primary concerns were: SQL injection attacks from internal and external users (51 percent); Internal threats, including unauthorised database access, database administrator errors, and data exposure to non-privileged internal users (31 percent); and regulatory compliance (18 percent).

“In today’s environment, it isn’t a matter of whether you will be hacked, but when. Cybercriminals recognise that not only enterprises but also SMBs are especially vulnerable,” said the research’s sponsor GreenSQL ‘s CEO, Amir Sadeh. “Databases contain the crown jewels of an organisation, which means a break-in by insiders or outsiders can cost millions in fines, lawsuits, and customer attrition.”

Cybercriminals use SQL injection to target both external websites and internal databases when seeking data for identity theft and other profitable black market activities. Public websites serving as the face of an organisation are known to be vulnerable to SQL injection attacks but so are internal collaborative sites as shown by the recent assault on the internal Nokia developer application.

Internal data security leaks let corporate data get into the wrong hands. While developers, administrators, and customer service representatives all need data access, they should have different access privileges. In addition, true data protection covers threats from both employee theft and error. Coordinating database access control and command permissions can significantly reduce data loss from errors while lowering the cost to repair any that remain.

Our Sponsors

AdvertisementAdvertisementAdvertisementAdvertisement

VitAL Tweets

Follow VitALMagazine on Twitter

VitAL Newsletter:

Email Newsletter icon, E-mail Newsletter icon, Email List icon, E-mail List icon Sign up for our Email Newsletter

Useful Downloads

Latest Issue of VitAL Magazine

Product News

New virtualisation solution

April 12, 2013

Ipanema Technologies has launched a new virtualisation solution, the virtual|engine. According to the company, with the virtual|engine, enterprises can deploy the Ipanema’s Autonomic Networking System (ANS) over their virtual infrastructure and guarantee the performance of their application portfolio like ERP, Unified Communications, cloud applications, video, social media, etc. over their entire corporate network including the [...]

Service Management makes a splash

March 15, 2013

ITSM solutions provider SysAid Technologies Ltd has announced that the largest operator of water parks and family entertainment centres in the US, Palace Entertainment, has selected its fully-integrated ITSM solution, SysAid 9.0. The software will allow Palace Entertainment to manage its internal IT operations, including the help desk and asset management, and to oversee employee [...]

The HEAT is on

February 1, 2013

FrontRange, has announced the latest release of its HEAT Help Desk solution that it says delivers flexible customer service and support for IT help desks, support centres and call centres. According to the company HEAT Help Desk 9.6 contains two major enhancements: Mobile Field Service and web-based Managers Monitor. “Field service reps need access to [...]

Fusion launches Remedy ITSM Value Assessment

February 1, 2013

Fusion Business Solutions has launched a Remedy ITSM Value Assessment service that it says enables customers to realise the full benefits of their existing Remedy ITSM implementation. It is free of charge to existing Fusion customers. The ITSM Value Assessment evaluates the effectiveness of an existing Remedy ITSM implementation in terms of process, functionality, technology, [...]

Data Centre World 2013 set to be bigger and better

January 17, 2013

Data Centre World 2013 set to be bigger and better than last year with pre-show registrations up year on year  The UK’s fastest growing free-to-attend dedicated data centre event takes place on 27-28 February 2013 at ExCeL, London   Data Centre World, the UK’s fastest growing free-to-attend data centre event, has already seen a huge [...]