The government has warned ministries and other state institutions about the need for increased vigilance when it comes to the security of computer systems. This is not a minor problem. Indeed as Aramco discovered in August last year, when its IT systems were attacked by hackers, the consequences can be extremely serious. More than 30,000 of its computers were compromised.
The challenges of computer security are by no means unique to the Kingdom. All over the world, it is clear that there is a low-level cyber war going on. Washington, Beijing and Moscow all appear to be seeking to penetrate both government and commercial computer networks. Little is being said by anyone except the Americans, whose protests are largely directed against the Chinese.
Washington has also established the Cyber Defense Agency, ostensibly to defend against attacks. Yet it is certain that the Americans are also working on their own offensive strategies for the full-blown conflict in cyberspace, which many predict will be the shape of future warfare. Victory will come to the state that can paralyze its rival’s power systems and communications. Preferable though such a fight may be to the horrors of thermonuclear war. Indeed it could be that US cyber warriors, probably working with Israeli government hackers, were responsible for the disruption to the Iranian nuclear program by causing centrifuges used in the uranium enrichment to go haywire.
Yet the warning from the National Center for Information Security of the Ministry of Communications and Information Technology here in the Kingdom, was less about this level of highly-sophisticated cyber assault, and more about a common sense attitude to the use of computers that are an everyday part of working life.
Every computer, including those we use at home, contains private information. Thieves can access computers and use details of bank accounts or credit cards to try and steal funds or make online purchases. Personal details can also be used for identity theft, which could mean for instance that provocative or offensive statements could be posted on social media, so landing an entirely blameless person in controversy.
The classic error is when people leave notes on their computer screens to remind them of their passwords, or choose simple passwords in the first place “1234” or their own names, are typical examples of this poor level of security, not simply among Saudis but all around the world.
Then there is the issue of caution and discipline when operating on the Internet. A very common danger arises when e-mails arrive, apparently from friends or acquaintances that contain a link to a website, but very often no other text except a subject heading saying something “Look at this” or “I think you will find this interesting.” The unsuspecting who click on the link will run the danger of going to a website that while it is loading, could also install a piece of software containing a virus that will infect the computer or a “Trojan” that will for instance log all key strokes and send them to a remote computer. Thus a hacker will be able to access that machine in future.
It is plain common sense to be suspicious of anything that arrives unexpectedly in your mailbox. It is a matter of a couple of minutes to send a mail to the person who apparently sent the message and link, to ask if it did in fact come from them. Equally, if the mail header includes a lot of other names, it is very probable that the hacker has hijacked the person’s address book. At the very least, opening the link will allow your own address book to be used in a similar manner.
Further dangers exist when computers are left unattended and have not been set up to default to requiring a password to reactivate the screen. In government offices this can expose confidential or even classified documents to unauthorized eyes.
A new risk is emerging with the trend toward people using their own personal devices for work. The Bring Your Own Device (BYOD) is now a fact of life in North America and Europe, where executives use their personal tablets or notebook computers to do work on the move. Corporate IT department heads first tried to insist that employees only used the mobile devices that were issued by the firm. However at the same time, they forbade the personal use of these computers. Now it seems many companies have given up and are accepting BYOD arrangements, despite the considerable dangers. Government departments however are much stricter in this area. Therefore it must be hoped that despite the love affair that so many people in the Kingdom seem to have with the tablets and smart phones, their use for official business will either be forbidden or strictly controlled.









