Help locking down access to client data from "outside" hacking.

Reply

Join Date: Jun 2006
Posts: 4
Reputation: grindy is an unknown quantity at this point 
Solved Threads: 0
grindy grindy is offline Offline
Newbie Poster

Help locking down access to client data from "outside" hacking.

 
0
  #1
Oct 15th, 2006
My situation is this:
I have a small business with 5 users. Each user can access our clients data from our internal file server. All users are running XP Professional, as is the server machine.
All of us require daily internet access, which is broadband cable behind a router. Each system is running a Security Suite with personal firewall.
What I need to do is be as certain as is "practically" possible that our clients data is not "compromised" from the outside ( via our broadband connection ).
What - if anything - should I add to this setup to be more secure from "outside" hacking?
All comments are certainly appreciated.
Reply With Quote Quick reply to this message  
Join Date: Jan 2006
Posts: 1,605
Reputation: 'Stein is on a distinguished road 
Solved Threads: 104
Team Colleague
'Stein's Avatar
'Stein 'Stein is offline Offline
Lapsed Skeptic

Re: Help locking down access to client data from "outside" hacking.

 
0
  #2
Oct 16th, 2006
(moved.)
Now if ya like the help ya could always raise our reputation...
Reply With Quote Quick reply to this message  
Join Date: Apr 2006
Posts: 5,050
Reputation: John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold John A is a splendid one to behold 
Solved Threads: 331
Moderator
John A's Avatar
John A John A is offline Offline
Vampirical Lurker

Re: Help locking down access to client data from "outside" hacking.

 
0
  #3
Oct 16th, 2006
Originally Posted by grindy
Each system is running a Security Suite with personal firewall.
What I need to do is be as certain as is "practically" possible that our clients data is not "compromised" from the outside ( via our broadband connection ).
What - if anything - should I add to this setup to be more secure from "outside" hacking?
OK, there are a couple of main security models in terms of firewalls.
  • One Internet gateway firewall that's extremely secure, and all the other computers insecure. This is the most common model. Benefits of this model are that security updates only need to done on one system, disadvantages are that once the hacker is in, your whole system is compromised.
  • Firewall is in place on main gateway, but firewalls are also installed on every network client machine. Benefits of this is that it's very secure, disadvantages are that it will become increasingly difficult to maintain security updates on all machine and still keep the network running.
As most people opt for the first one, that's probably the best one to go with. It's still very secure, and like I just said, it's very easy to maintain.

Your router has a built-in firewall, so your router can double as an Internet gateway. However, you might want to consider getting a seperate Internet gateway machine (woud have 2 network cards, one connected to the Internet, and the other connected to the WAN port in the router) that all the data has to pass through before it gets to the router, if you find the router's built-in firewall to limited.

Hope this helps
"Technological progress is like an axe in the hands of a pathological criminal."
Reply With Quote Quick reply to this message  
Join Date: Aug 2003
Posts: 372
Reputation: TheOgre is a jewel in the rough TheOgre is a jewel in the rough TheOgre is a jewel in the rough 
Solved Threads: 6
TheOgre's Avatar
TheOgre TheOgre is offline Offline
Posting Whiz

Re: Help locking down access to client data from "outside" hacking.

 
0
  #4
Nov 7th, 2006
What kind of router are you using? Is it a cheapo LinkSys/D-Link/Netgear/etc or is it a more robust FIREWALL (Netopia/Cyberguard/etc.)? Do you have access controls in place? Do you allow VPN access into your network (so people can work from home)?

What KIND of data are you trying to protect? Do you fall under GLBA/SOX/HIPAA and are therefor required to meet government regulations for securing data access?


Do you have antivirus installed on all systems? What kind of spyware protection do you have? How are you preventing your inside users from downloading potentially harmful files from the Net that can initiate connections that bring in potentially unsafe content?

Some more details would help..
If you spend more on coffee than on IT security, you will be hacked.
What's more, you deserve to be hacked.
-- former White House cybersecurity czar Richard Clarke
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:


Thread Tools Search this Thread



About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC