« The Arrival of the CEO Blog | Main | Thanks for Nothing »

Daily Posts

May 2008
Sun Mon Tue Wed Thu Fri Sat
1 2 3
4 5 6 7 8 9 10
11 12 13 14 15 16 17
18 19 20 21 22 23 24
25 26 27 28 29 30 31

About SLW

Events

Subscribe

Email Alerts

Subscribe and receive email alerts when new articles are published!

Enter Your Email Address

U.S. Code

Code of Federal Regulations

Thursday, April 27, 2006

GAO Flags SEC Security Holes

As discussed in this Reuters article, the GAO announced last month that its audit of the SEC showed that the SEC had "failed to limit remote access to its servers, establish controls over passwords, securely configure all network devices, and adopt security monitoring procedures."  The article posits that "a successful hacker could use nonpublic information to make trouble for a targeted company or rival" and offers this "nightmare scenario:"

A hacker accesses e-mails in U.S. Securities and Exchange Commission computers and splashes them across the Internet, revealing an inquiry into a company that shakes investor confidence before the probe is complete.

Such an attack has never happened at the SEC, but computer experts say it could if the agency fails to tighten security.

"Splashing information" actually would be a fortunate and much less embarrassing outcome for the SEC compared to what greedier hackers might choose to do with such information.  For instance, what do you think the Estonian Spider Hackers would do with that information?  What would Plotkin and Pajcin do with it?  You guessed it.

In fact, "hacking into the SEC" was probably already on the Plotkin/Pajcin business plan, somewhere between stealing Business Week and hiring "exotic dancers" to extract information from investment bankers.

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

TrackBack

TrackBack URL for this entry:
http://blog.riskmetrics.com/cgi-bin/mt-tb.cgi/709

   
 
About RiskMetrics Group | Disclaimer

Copyright © 2007 RiskMetrics Group
The World Leader in Proxy Voting and Corporate Governance Services

Powered by Movable Type 3.36