Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • The Weakest Link: Desktop Security current page
Link copied

The Weakest Link: Desktop Security

Oct 20, 2017
Author:
Russell Smith Bio Pic 2021 Square
Russell Smith
IT Consultant & Security MVP
Blog banner default
The Weakest Link: Desktop Security
Russell Smith Bio Pic 2021 Square
Russell Smith
IT Consultant & Security MVP

At the beginning of this year, the South Carolina House of Representatives decided to increase funding for computer security after almost all the Department of Revenue’s tax records were leaked. While testifying in front of a House committee on 3rd January, the Revenue’s former chief of security, Scott Shealy, claimed that management at the agency hadn’t taken the security of taxpayer’s data seriously and had been more concerned with stopping employees from surfing the Internet and cutting end user security training.

Shealy went on to accuse the CIO of micromanagement and not listening to the advice he’d been given, and as a result was unable to do his job. In September 2012, while the hacking attempt was apparently underway, the CIO resigned; although it’s not clear for what reason. Shealy resigned from his post a year before the hacking incident took place. An independent investigation showed that the most likely cause of the hack was an employee clicking on a malicious link that enabled the attacker to set up other entry points to the Revenue’s systems.

Many organizations, despite the advances in security technologies and best practice advice, still rely on network edge firewalls and endpoint antivirus software as the mainstays of their security defenses. Recent research shows that antivirus and firewalls are no longer the top priorities for desktop security, and prove ineffective unless used as part of a defense-in-depth strategy. Most security professionals will also testify that desktop computers are often compromised when antivirus is employed as the only barrier to attack.

It’s common for resources to be ploughed into defending servers and databases, and while this is important, it shouldn’t be forgotten that once users are authorized to access data from a desktop computer, no matter how much time and effort has gone into protecting the back-end, the security of the access device becomes important too. Security dependencies such as this are often overlooked.

Antivirus solutions have evolved to provide more comprehensive protection than just the ability to match files against a signature database. Most endpoint security suites also include a desktop firewall, device control, spam filtering and protection against attacks that rely on social engineering. AV is a well-understood technology that has been the primary form of desktop security for two decades, but even with a comprehensive endpoint security suite, privilege management and application allow listing are also critical to ensure that when AV fails, there is another layer of defense to prevent malicious software from infecting a system.

With the example of the Southern California House of Representatives in mind, now is the time to re-evaluate your desktop security strategy, particularly if AV is the only protection you have in place.

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • Pokémon Go Exposes What’s Wrong with Using the Same Google Account for Business and Pleasure
    Jul 12, 2016 Pokémon Go Exposes What’s Wrong with Using the Same Google Account for Business and Pleasure
    Blog
    1m
  • Birmingham Women's & Children’s NHS Foundation Trust Maintains Secure Access at All Times with Bomgar
    Jul 26, 2018 Birmingham Women's & Children’s NHS Foundation Trust Maintains Secure Access at All Times with Bomgar
    Blog
    1m
Share this Article
  • Link
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.