Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Three Blind Mice… See How Apps Run.
Articles

Three Blind Mice… See How Apps Run.

ISBuzz TeamBy ISBuzz TeamMarch 14, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In today’s world, not being able to see potential threats to applications is fatal for business where data is king. As the digital economy grows, business intelligence relies on three crucial areas: visibility, context and control.

Did you ever see such a thing in your life?

Today, there is no rhyme or reason why companies should not focus on implementing robust application security solutions to protect customer data. With rapidly increasing encrypted traffic, being able to visualise potential threats is vital to avoid both exfiltration of data and infiltration of malware.

A Gartner report published in 2016 stated that only 27% of top 1 million websites use HTTPS (+11%), but more than 38% (+5%) of Google Chrome browsing is done in HTTPS (63% if we include fragment changes and history browsing). However, analysts predict it will soon be 100% across the board and become the new standard for web browsers. Encryption is a growing problem for many companies because the inadequate security solutions they have implemented are not able to decrypt traffic or their ineffective tools could degrade performance by up to 85% compared to normal service. Hackers know this and hide malware within their encrypted communications, which is why data theft continues to be a serious challenge for many firms. It is like breaking into the castle and abducting the king.

Cybercriminals are malicious pests that are sadly spawning across the globe, intent on stealing vital information. In fact, 28% of today’s attacks target user identities and 44% target applications, which are the gateway to your data. Weak or duplicate passwords for multiple applications used by people daily give hackers a rudimentary way to access sensitive information, which they can sell for high profits on the black market.

See how they run.

Now it is time to re-think the approach to security. To be a leader in data compliance and best practice, firms must secure applications wherever they are and ensure that users can access them securely from any device or location. The three essential elements that determine best security practice are as follows:

  • Visibility:

A fundamental principle of security is protecting what you do not see or know. Effective architecture provides complete visibility into all application traffic to help secure vital data. This should include identification of the user, the type and health of device in use, along with its location, user behaviour patterns, the type of network connection, availability of the application and the nature of data. Solutions like SSL Interception provides visibility and allows customers to offload all SSL traffic duties.

  • Context:

Visibility alone is insufficient. Context helps to understand all the characteristics of the applications that need to be protected and the external forces that threaten them. With context comes greater insight as multiple data points provide an additional level of intelligence that enables firms to assess risk and make informed decisions about the policies to create. Context also delivers accuracy to apply the correct controls (e.g. deciding whether to grant or deny a user access to an application based on their current situation).

  • Control:

With context, it is essential to have the ability to apply the right security controls. Without control, visibility or context become redundant. By having a single point of control to authenticate users, firms can easily improve application security and integrate existing infrastructure. Delivering consistent security policies is vital to apps applied across the data centre or in the public and private cloud. Once the blind spots are eliminated, companies have better control of identity and access management to protect all applications from DDoS attacks, web fraud and much more.

Cut off their tails with a carving knife.

In the nursery rhyme ‘Three Blind Mice’, the vermin eventually succumb to having their tails removed by a carving knife. Similarly, cutting out weaknesses in application security and curtailing hackers much faster will help to limit serious data breaches.

Visibility into network traffic makes security far more effective and simplifies overall management. Rigorous application access controls mitigate risk by authenticating and authorising the right people. Ultimately, securing the application – the king of the castle – protects against data theft and ensures that apps run faster whether in the data centre or in the cloud.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}