SourceSecurity.com
  • Products
    CCTV
    • CCTV cameras
    • CCTV software
    • IP cameras
    • Digital video recorders (DVRs)
    • Dome cameras
    • Network video recorders (NVRs)
    • IP Dome cameras
    • CCTV camera lenses
    Access Control
    • Access control readers
    • Access control software
    • Access control controllers
    • Access control systems & kits
    • Audio, video or keypad entry
    • Electronic locking devices
    • Access control cards/ tags/ fobs
    • Access control system accessories
    Intruder Alarms
    • Intruder alarm system control panels & accessories
    • Intruder detectors
    • Intruder warning devices
    • Intruder alarm communicators
    • Intruder alarm accessories
    • Intruder alarm lighting systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Dahua Smart Dual Illumination Active Deterrence Network PTZ Camera

    Dahua Smart Dual Illumination Active Deterrence Network PTZ Camera

    Hikvision DS-K6B630TX: Smart Pro Swing Barrier for Modern Access Control

    Hikvision DS-K6B630TX: Smart Pro Swing Barrier for Modern Access Control

    Climax Mobile Lite: Advanced Personal Emergency Response System (PERS)

    Climax Mobile Lite: Advanced Personal Emergency Response System (PERS)

    Hanwha Vision OnCAFE: Cloud-Based Access Control for Modern Enterprises

    Hanwha Vision OnCAFE: Cloud-Based Access Control for Modern Enterprises

  • Companies
    Companies
    • Manufacturers
    • Distributors
    • Resellers / Dealers / Reps
    • Installers
    • Consultants
    • Systems integrators
    • Events / Training / Services
    • Manned guarding
    Companies by Product area
    • CCTV
    • Access control
    • Intruder alarm
    • IP networking products
    • Biometrics
    • Software
    • Digital video recording
    • Intercom systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • News
    News
    • Product news
    • Corporate news
    • Case studies
    • Events news
    Latest
    • Hikvision attains ISO 37301 Certification for Compliance Management System
    • SentriGuard's role in sustainable security solutions
    • Axis joins CISA Secure by design for cybersecurity
    • Xtract One's SmartGateway enhances Nova Scotia security
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • Insights
    Insights
    • Expert commentary
    • Security beat
    • Round table discussions
    • Round Table Expert Panel
    • eMagazines
    • Year in Review 2023
    • Year in Review 2022
    Featured
    • What are emerging applications for physical security in transportation?
    • What is the most overlooked factor when installing security systems?
    • Amid rising certificate demands, stricter compliance and quantum threats, PKIaaS is a necessity
    • How should security adapt to the unique aspects of healthcare?
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
  • Markets
    Markets
    • Airports & Ports
    • Banking & Finance
    • Education
    • Hotels, Leisure & Entertainment
    • Government & Public Services
    • Healthcare
    • Remote Monitoring
    • Retail
    • Transportation
    • Industrial & Commercial
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Alamo enhances security with Alcatel-Lucent solutions

    Alamo enhances security with Alcatel-Lucent solutions

    The University of Dundee implements HID for modern access control

    The University of Dundee implements HID for modern access control

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    The Camp: Enhance security with ASSA ABLOY Aperio wireless locks

    SBB upgrades surveillance with Hanwha Vision cameras

    SBB upgrades surveillance with Hanwha Vision cameras

  • Events
    Events
    • International security
    • Regional security
    • Vertical market
    • Technology areas
    • Conferences / seminars
    • Company sponsored
    Virtual events
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Security Storage
    • Video Management Systems
    • Integrated Systems
    Understanding AI-powered video analytics
    Understanding AI-powered video analytics
    Gartner IT Infrastructure, Operations & Cloud Strategies Conference 2025

    Gartner IT Infrastructure, Operations & Cloud Strategies Conference 2025

    Technology Summit International 2025

    Technology Summit International 2025

    G2E Philippines 2025

    G2E Philippines 2025

    IFSEC India 2025

    IFSEC India 2025

  • White papers
    White papers
    • Video Surveillance
    • Access Control
    • Video Analytics
    • Video Compression
    • Security Storage
    White papers by company
    • HID
    • ASSA ABLOY Opening Solutions
    • Milestone Systems
    • Eagle Eye Networks
    • Hanwha Vision America
    Other Resources
    • eMagazines
    • Videos
    Aligning physical and cyber defence for total protection

    Aligning physical and cyber defence for total protection

    Understanding AI-powered video analytics

    Understanding AI-powered video analytics

    Modernizing access control

    Modernizing access control

    Enhancing physical access control using a self-service model

    Enhancing physical access control using a self-service model

About us Advertise
  • AI-powered video analytics
  • AI special report
  • Cyber security special report
  • 6
Cyber security
  • Home
  • About
  • News
  • Expert commentary
  • Security beat
  • Case studies
  • Round table
  • Products
  • White papers
  • Videos

Check out our special report on casino security

Get it now!

Assessing cyber security risks and vulnerabilities

Michael Fickes
Michael Fickes
icon Add as a preferred source Download PDF version
Quick Read
⌵
Summary is AI-generated, newsdesk-reviewed
  • Cybercrime's rise emphasises need for robust cyber security risk assessments and vulnerability management.
  • Companies must report data breaches, enabling consumer protection and identity safeguarding.
  • Establish risk-based data security programs comprising physical, logical, and administrative controls.
Related Links
  • How cybersecurity impacts the physical security world
  • SourceSecurity.com Technology Report - Meeting the Cybersecurity Challenge of IP Video Systems
A company must report a cyber-incident that resulted in the loss of personal data, whether for employees, customers or both
Suffering a breach is probably something that companies won’t admit to unless they must

As the world has grown more and more interconnected through the Internet and company networks, cybercrime has grown at an alarming rate. According to the Federal Trade Commission, 783 businesses reported IT breaches in 2014, up 27.5 percent from 2013. “There were probably many more, but most go unreported,” says Kim Phan, of council with the Washington, D.C., law offices of Ballard Spahr LLP

Protecting consumer data

Suffering a breach is probably something that companies won’t admit to unless they must. A company must report a cyber-incident that resulted in the loss of personal data, whether for employees, customers or both.

In the Target Stores incident in December 2013, hackers stole credit and debit card information for 40 million Target customers along with contact information for 70 million more individuals. Hackers compromised credit card data for 56 million JP Morgan Chase customers in September of last year. The list of major hacking incidents goes on and on.

In most major cases, the victimised companies must notify their employees and customers, enabling them to take steps to protect their identities and credit. “The states are far ahead of the federal government in legislation related to cyber-intrusions,” says Phan. “Forty-seven states now have regulations requiring companies to notify people whose personal data has been breached.”

The federal government may be behind the states in this, but the Federal Trade Commission has been quite active in evaluating company security measures after a breach. The Commission imposes penalties if it determines that a company has failed to provide reasonable security measures.

What is reasonable? There are no hard and fast regulations. The area is too new, continues Phan. Companies should monitor how state and federal regulators are shaping their responses to company breaches. They should also pay attention to the results of legal actions brought by a long list of parties that may be injured by a breach: consumers, financial institutions, shareholders, and others.

The Federal Trade Commission has been quite active in evaluating company security measures after a breach

Ballard Spahr attorneys advise developing a risk-based data security program that consists of three components. First, identify all information assets; record their physical locations — some assets may be in more than one location; and identify the person responsible for each of the assets.

Second, carry out a formal risk assessment. What are the network vulnerabilities? Where and how might a hacker break into your system? What weaknesses have past incidents attacked? How have you shored up the weak points on the network? Depending upon the amount of data involved, a company might retain an IT security professional to conduct the assessment and make recommendations. Third, develop a security program that addresses your network’s vulnerabilities.

Developing a security program

The first step in IT security is physical security. If someone steals your computer or uses your computer to steal files on your network, the game is over before it starts. So lock the doors and lock the buildings where the physical components of IT systems reside.

In his book, “The Basics of Information Security,” Jason Andress writes that three kinds of controls mitigate the risks associated with IT attacks. They are physical controls, logical controls and administrative controls.

Again, physical controls are doors, locks, access control systems, cameras and alarms that will let you know when someone is trying to break into — or has broken into — a computer room or computer equipment closet. Logical security covers passwords, biometrics, encryption, firewalls and other intrusion prevention and detection systems.

Administrative security deals with policies and procedures about using the system. For example, many companies set policies that control what components of the network employees at various levels may access. That’s administrative security.

Finally, the Federal Trade Commission notes that vulnerabilities change as technology advances. So it is important to assess risks and vulnerabilities and adjust your IT security program on a continuing basis.

From facial recognition to LiDAR, explore the innovations redefining gaming surveillance

Download PDF version Download PDF version
Google logo Add as a preferred source on Google
  • Physical security
  • Security management
  • Security devices
  • Security access systems
  • Security training
  • Door access control
  • Security service
  • Cyber security
  • Related categories
  • CCTV cameras
  • Access control systems & kits
  • Related links
  • Articles by Michael Fickes
Related white papers
Aligning physical and cyber defence for total protection

Aligning physical and cyber defence for total protection

Download
Combining security and networking technologies for a unified solution

Combining security and networking technologies for a unified solution

Download
System design considerations to optimize physical access control

System design considerations to optimize physical access control

Download
Related articles
How physical security consultants ensure cybersecurity for end users

How physical security consultants ensure cybersecurity for end users

How managed detection and response enhances cybersecurity management in organisations

How managed detection and response enhances cybersecurity management in organisations

Drawbacks of PenTests and ethical hacking for the security industry

Drawbacks of PenTests and ethical hacking for the security industry

Follow us

Sections Products CCTV Access Control Intruder Alarms Companies News Insights Case studies Markets Events White papers Videos AI special report Cyber security special report RSS
Topics Artificial intelligence (AI) Mobile access Healthcare security Counter terror Cyber security Robotics Thermal imaging Intrusion detection Body worn video cameras
About us Advertise About us 10 guiding principles of editorial content FAQs eNewsletters Sitemap Terms & conditions Privacy policy and cookie policy
  1. Home
  2. Topics
  3. Cyber security
  4. News
  5. Expert commentary
About this page

Explore top-notch biometric access control systems and video surveillance solutions for enhanced security measures at SourceSecurity.com.

See this on SecurityInformed.com

Subscribe to our Newsletter

Stay updated with the latest trends and technologies in the security industry
Sign Up

DMA

SourceSecurity.com - Making the world a safer place
Copyright © Notting Hill Media Limited 2000 - 2025, all rights reserved

Our other sites:
SecurityInformed.com | TheBigRedGuide.com | HVACinformed.com | MaritimeInformed.com | ElectricalsInformed.com

Subscribe to our Newsletter


You might also like
Understanding AI-powered video analytics
Understanding AI-powered video analytics
Security and surveillance technologies for the casino market
Security and surveillance technologies for the casino market
Modernizing access control
Modernizing access control
Addressing Cybersecurity Vulnerabilities in the Physical World
Addressing Cybersecurity Vulnerabilities in the Physical World
SourceSecurity.com
SecurityInformed.com

Browsing from the Americas? Looking for our US Edition?

View this content on SecurityInformed.com, our dedicated portal for our Americas audience.

US Edition International Edition
Sign up now for full access to SourceSecurity.com content
Download Datasheet
Download PDF Version
Download SourceSecurity.com product tech spec