Successfully reported this slideshow.
We use your LinkedIn profile and activity data to personalize ads and to show you more relevant ads. You can change your ad preferences anytime.

Startups Security


Published on

Why should startups take care about security or answer to the question who will hack my server.

Published in: Technology, News & Politics
  • Be the first to comment

Startups Security

  1. 1. [email_address] SS 14 th June 2008 Do Startups Need to Worry about Security ? Or Why Will Anyone Hack My Servers ?
  2. 2. [email_address] SS 14 th June 2008 Do Startups Need to Worry about Security ? YES, and here is why. Three recent headlines <ul><li>Web infection attacks more than 100,000 pages [ on 24 th April 2008 ] </li></ul><ul><li>Drive-by download attack compromises 500,000 websites [ on 13 th May 2008 ] </li></ul><ul><li>Hackers 'seeding' legitimate websites. A 220% increase in Web-based malware [ on 9th June 2008] </li></ul>
  3. 3. SS 14 th June 2008 But how is this relevant to my startup ? <ul><li>Do you have a web application as your interface to the end user? </li></ul><ul><li>Are you letting your users add content to the web app ? </li></ul><ul><li>Are you trusting your users to be always benign ? </li></ul><ul><li>Would you want to serve malware unknowingly ? </li></ul><ul><li>Do your developers understand XSS, CSRF & SQL injection ? </li></ul>Do Startups Need to Worry about Security ?
  4. 4. SS 14 th June 2008 <ul><li>For bandwidth to host and serve malware. </li></ul><ul><li>To add one line of extra code to download trojans. </li></ul><ul><li>To use your site as a conduit while performing other attacks. </li></ul><ul><li>Because on the web bad guys trade hosting space as currency. </li></ul><ul><li>Because some script kiddie is learning how to do all this </li></ul>Why Will Anyone Hack My Servers ?
  5. 5. SS 14 th June 2008 <ul><li>Educate developers to follow secure coding principals. </li></ul><ul><li>Add security testing as an integral part of app testing. </li></ul><ul><li>Making sure the testing covers OWASP Top 10 vulnerabilities. </li></ul>So what exactly can we do about this ?
  6. 6. SS 14 th June 2008 But why, what is the point ? <ul><li>Loosing trust on line can be a death knell for a startup. </li></ul><ul><li>Legally you are responsible for what is on your website. </li></ul><ul><li>Keeping yourself secure makes good business sense anyway </li></ul>
  7. 7. SS 14 th June 2008 <ul><li>Been working on Info Sec domain for the past 3 years. </li></ul><ul><li>Worked with CDAC Bangalore securing their web and email servers. </li></ul><ul><li>Bootstrapped End Point Security and IDS teams for StillSecure </li></ul><ul><li>Flying Solo from 1 st of July to help companies with Info Security </li></ul><ul><li>You have any questions about security come talk to me. </li></ul>So what is my angle ? Why am I telling you all this ? BLOG / WEBSITE [email_address]