All Access. All in one subscription. From $2 per week
Subscribe now

All Access Weekly

From $2 per week
Pay just
$15.75
$2
per week ongoing
Subscribe now
BEST VALUE

All Access Annual

Pay just
$449
$49
per year ongoing
Subscribe now
Learn more
30
NZ Herald
  • Home
  • Latest news
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather forecasts

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
    • The Great NZ Road Trip
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
    • Cooking the Books
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • What the Actual
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Technology

Don't gamble on systems security

By by Adam Gifford
19 Apr, 2005 05:48 AM4 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Security is a minefield, where anything you lay down to protect your network or your organisation can blow up in your face.

Yesterday's best practice becomes today's gaping system hole leaking your data to unauthorised eyes.

But as you tell yourself when something goes wrong, you can learn from your mistakes.

Mistake 1: Relying on the vendor

Tony Krzyzewski, of Auckland consultancy Kaon Security, says the biggest mistakes are assuming a piece of software or hardware is secure, and assuming the person they have paid for a security solution knows how to close all the holes.

"I come across so many systems, even those put in by professional organisations, which are misconfigured, because people don't understand the vulnerabilities associated with each type of system," Krzyzewski says.

"People focus on internet vulnerability, but in general business terms the greatest threat comes from within the organisation - people getting improper access, people abusing systems, and leading on from that we see commercial fraud, time-wasting, and generally having access to what they shouldn't see."

Ian Mitchell, from security alert specialist Co-logic, agrees people have excessive confidence in software suppliers and their alert services.

Mistake 2: No change

Even when systems do get locked down, and Krzyzewski doesn't see a lot that are, administrators fail to recognise the environment changes.

"People do open things for temporary reasons and fail to lock them down again, or the threat changes."

This is where patch systems come in. Organisations need systems in place to ensure they install patches and keep anti-virus systems up to date.

Patching can often require testing of systems to make sure the patch hasn't affected interconnected systems. Krzyzewski says that is the reason some system managers shirk the task.

"You have to make an investment. It requires constant management.

"Microsoft released eight patches last Monday morning, and I know sites which will be up to date because they have systems in place and testing in place. Other sites are two or three years out of date, so there are basic vulnerabilities.

"In some cases, management don't know they got into that situation - their IT staff or facilities management company claimed they were doing the patches, but it was too hard.

"A lot of IT organisations gamble on IT security."

Mistake 3: Buying on cost

Krzyzewski says when it comes to firewalls, many organisations buy perimeter defence equipment based on cost.

"We always say base your frontline defence on certifications, preferably by government bodies," he says.

A firewall isn't enough. "What is worse than no firewall is turning it on and running it without checking the settings meet your business requirements.

"For example, we have come across installations where all ports are open outbound. That means if a bit of malware does get in, you can find you are transmitting connections to anyone."

Mistake 4: Not having and enforcing a security policy

Organisations must have policies controlling their security. These policies need to be documented and available in an easily accessible form on the corporate internet.

Kaon offers a template for a policy system on www.kaonsecurity.com, based on the ISO 17799 standard. Krzyzewski says policies have to state how the company's information and its systems are to be managed. They need to control what people can do, how the information is stored, what access levels are required.

"Polices are in place to protect an organisation from information loss. My accounting records are as important to me as a defence record.

Mistake 5: Relying on intrusion detection systems

"Intrusion detection is a waste of time. People get so many alerts they ignore them," Krzyzewski says.

Mitchell agrees that administrators can get bogged down with information.

"There is a lot of white noise out there," Mitchell says.

Cologic's approach is to provide a service after extensive analysis of an organisation's systems, so only relevant alerts go out.

Mistake 6: Allowing uncontrolled net access

Assuming staff will comply by default with what management expects is a no-no. Krzyzewski recommends an internet access control system like Websense, which blocks sites which may be home to malware such as Active X controls.

Mistake 7 : Treating email as a personal asset

"Very few organisations archive email. Email is a business record. Our general opinion is it should be archived and maintained as a business record," Krzyzewski says.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.
Save

    Share this article

Latest from Technology

Premium
Technology

Spark confirms jobs will go as it outsources to AI, networking partner

16 May 04:00 AM
Premium
Technology

Kiwi startup lands TikTok as a client

16 May 02:00 AM
Premium
Business

Xero cracks $2 billion revenue for first time but subscriber growth slows

14 May 11:51 PM

Deposit scheme reduces risk, boosts trust – General Finance

sponsored
Advertisement
Advertise with NZME.
Recommended for you
Exclusive: Peter Burling on Team NZ exit, success and what's next
America's Cup

Exclusive: Peter Burling on Team NZ exit, success and what's next

16 May 05:03 PM
'Insanity': Auckland villa owners told double-glazed windows violate heritage rules
New Zealand

'Insanity': Auckland villa owners told double-glazed windows violate heritage rules

16 May 05:00 PM
Napier homicide: Sacred haka to honour slain teen, killer still on the loose
New Zealand

Napier homicide: Sacred haka to honour slain teen, killer still on the loose

16 May 05:00 PM
'Real conversations': Fieldays spotlight on forestry's future role
The Country

'Real conversations': Fieldays spotlight on forestry's future role

16 May 05:00 PM
'Radical change': Possible crayfish ban for Northland's east coast
Northern Advocate

'Radical change': Possible crayfish ban for Northland's east coast

16 May 05:00 PM

Latest from Technology

Premium
Spark confirms jobs will go as it outsources to AI, networking partner

Spark confirms jobs will go as it outsources to AI, networking partner

16 May 04:00 AM

Restructure comes on top of contract to outsource roles to Infosys.

Premium
Kiwi startup lands TikTok as a client

Kiwi startup lands TikTok as a client

16 May 02:00 AM
Premium
Xero cracks $2 billion revenue for first time but subscriber growth slows

Xero cracks $2 billion revenue for first time but subscriber growth slows

14 May 11:51 PM
Premium
The big lessons for NZ in Australia's under-16 social media ban

The big lessons for NZ in Australia's under-16 social media ban

14 May 05:32 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • What the Actual
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven CarGuide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
All Access. All in one subscription. From $2 per week
Subscribe now

All Access Weekly

From $2 per week
Pay just
$15.75
$2
per week ongoing
Subscribe now
BEST VALUE

All Access Annual

Pay just
$449
$49
per year ongoing
Subscribe now
Learn more
30
TOP
search by queryly Advanced Search