Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Sage Software Firm Hit By Data Breach
News & Analysis

Sage Software Firm Hit By Data Breach

ISBuzz TeamBy ISBuzz TeamAugust 17, 2016Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

A data breach at large UK software company Sage may have compromised personal information for employees at 280 UK businesses, it is understood. Police are investigating the breach and Sage is probing the “unauthorised access” of data by someone using an “internal” company computer login.

IT security experts from ESET, Lieberman Software, AlienVault, MIRACL and Certes Networks commented below.

Mark James, Security Specialist at ESET:

mark-james“One of the weakest links in any organisation are the users, you can have as many security features as you like but most of the time someone somewhere needs access to it in one way or another. If that user gets compromised or joins the dark side then that data could be at risk. Of course there are lots of things you can do to make it difficult; making sure only some of the network is accessible through segregated access, masking certain stored information to ensure it’s not viewable in its entirety. Encrypting the data that’s stored in the databases and of course making sure that every single task or keystroke is audited. But typically your admins will need to access a large chunk of that data to keep it happy and accessible for all, insider threats are on the up, it’s no longer sufficient to assume your biggest threats are from external attacks.”

Jonathan Sander, VP of Product Strategy at Lieberman Software:

Jonathan Sander“The Sage breach is a reminder that despite all the headlines about bad guys trying to break in there is an ever present danger from within, too. Often firms spend tons of money protecting against outsiders getting in, but fall into the “we trust our people” tap when it comes to insider threat. The trouble with trusting staff is that they’re likely worthy of that trust until the moment they become disgruntled – and there’s no way to see that moment happen. Every organization must shift to a least trust model for inside security, and even make the goal zero trust. Every scrap of sensitive information should be under a least permission model in files, folders, email systems, and inside applications. Very rigorous process must be applied to IT administrators and the privileged access they have because it can bypass all your strong security if you’re not careful.”

Javvad Malik, Security Advocate at AlienVault:

Javvad Malik“Insider threats are a growing concern for many companies. Ever since Edward Snowden became the poster-child to showcase the immense damage a motivated malicious insider can cause, more efforts have been put into understanding, preventing and detecting this threat.

We can define an insider as an individual with legitimate access within the corporate perimeter – be it physical or virtual. This would include permanent and temporary employees, 3rd party contractors as well as 3rd party support companies and outsourced service providers.

Typically, a threat is defined as something or someone exploiting a vulnerability in a target. In the case of insiders, this can be reframed as someone abusing their trust.

Detecting insider threats are not as straightforward as blocking attacks at the perimeter. Like many security controls, the concept of defense in depth can be applied where a collection of procedural, user, and technical controls can be applied to detect suspicious activity.”

Brian Spector, CEO at MIRACL:

brian-spectoreic“Personal and financial data is one of the most valuable commodities on the Internet today. This kind of data fuels the multi-billion dollar business of identity fraud on the dark net, and is therefore a prime target for any hacker, or motivated insider, to exploit.

But whether this particular incident was motivated by financial gain, or some other motive, the breach suggests that inadequate security measures were being used. Using old technologies such as username and password, it’s pretty easy for a hacker or insider to steal the relevant credentials and gain access to sensitive data. In reality, any organisation that houses such a treasure trove of financial data should be using stronger security measures such as biometrics or multi-factor authentication, to prevent such ‘unauthorised access’ to data. The username and password system is old technology that is simply not up to the standard required to secure the deep information and private services that we all store and access online today. By contrast, new, secure methods of multi-factor authentication can make database hacks, stolen credentials, password reuse and social engineering a thing of the past.”

Paul German, VP EMEA at Certes Networks:

paul-german-of-Pbxwall“The fact that Sage does not know the full extent of the data breach shows that the company does not have adequate segmentation in place. Quite simply, if Sage had cryptographically segmented its security system into predefined and clearly understood fragments, the breach would have been more manageable, instead of system wide, and Sage would know the parts of the network infrastructure that have been hacked. Sage should have a crypto-segmentation strategy in place, which would ensure that all sensitive application flows inside and outside the perimeter are encrypted, creating a clean and unbreakable link between each user and the permitted data and applications. As a result, if a breach does occur, the hacker is limited with the information and data that it is able to exploit.

Additionally, it must be asked as to how this breach was able to happen in the first place. Why could an internal user’s login permit access to confidential customer data and why wasn’t it stored in an encrypted format? This attack shows the need for organisations to adopt a Zero trust strategy, which assumes that there is no such thing as a trusted network or IT environment. Instead, every user, device, network and application must be treated as untrusted, and all enterprise systems should be considered already compromised.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

The Real Cost of Inconsistent Third-Party Access

December 18, 20255 Mins Read

What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

August 7, 20256 Mins Read

The Evolving Importance of Identity Governance in FinTech

July 10, 20258 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}