
■ Security policies may not be written, but they may be understood
by all and communicated verbally.
■ Budgets will be tight, and until something happens that causes a
need to arise, security will not be a major concern.
The many companies that operate in this fashion, though they
suffer from no threats from internal personnel, are usually very
poorly protected from the Internet with as little as a single stateful
packet filter between themselves and the Internet. It is companies
like these that have been cracked and provide the beach-head for
hackers and spammers to launch assaults on the Internet at large.
The level of automation of hacking tools necessitates ...