from Andrew Hollands
Every business and online service faces different threats when it comes to cyber-crime. It’s important to understand what hackers want from you; if you understand what they are after, you can better protect those assets.
The first and most obvious asset hackers are after is user data. If your service collects and stores information about its users, it is your responsibility to ensure that data is stored safely. A person’s individual privacy is a right that should not be infringed upon. If hackers circumvent your security measures and obtain private user data, they will sell it on the black market to the highest bidder.
So, how do you protect user data? For starters, only store what is absolutely necessary, if you don’t store it, it can’t be stolen. If payment is required, have it through a vendor like PayPal. Some very reputable web services (e.g. Quora and DigitalOcean) have you login through your Google account. This is because they know Google can afford to safely store data.
Maybe you don’t store user data, what do hackers want with you? Well, if a hacker gains control of your server, they can hold it hostage. They know every day your site is down, you lose clients and reputability. They could charge a ransom of, say, $20 000 in bitcoin and you’d have to pick between paying it or losing everything. Bitcoin can be entirely anonymous and so there may be no way to take legal action. It is truly terrifying to imagine, but a very real possibility.
How do you prevent this? Despite investing in cyber security, there is no way to guarantee this will never happen to you. So, you should always keep regular backups of your site, if your server is jeopardized you can move your application to a new server.
The final asset a hacker may want from you is your infrastructure. The server your site is on is just a computer. If a hacker gains access to it, they can use it to hack other computers. If anyone tries to track them, it will lead back to your server making you liable and them potentially untraceable.
There are a lot of things hackers want from you. Investing in security is always the best approach, but you must always prepare for the worst-case scenario. It’s about finding the balance between being proactive and reactive.