Ok, the real title of this post should be thinking like a cracker, but I reserve the right to use the term that people *think* that one means as opposed to the differences between the two words. Confused yet? Ok, ignore this paragraph – this is for the hacker/cracker purists… I digress….
Computer security is not something many people think about, but it really is an exercise in risk mitigation. It comes down to this; What can be done, what is the risk, what is the potential outcome? Let’s not delve too deeply into theories of risk management, but let’s talk very surface-level of dangers to your database.
Your charity might have the nicest, most genuine people in the world. However, that does not mean they are incapable of employee theft or fraud. Nor does it preclude future employees from such actions. Computer security should not be based on “would this happen?” or “has this happened?”, but “could this happen?” This does not mean you must have a security fix for every possibility, but you should at least be aware of what is possible and what it means to your organization.
Recent Comments