So, when SANS comes out with a document - The Top Cyber Security Risks then it is time to sit up and take notice.
And especially when their findings pretty much agree with what the rest of the industry is saying.
The interesting thing is that there are really only two major risks highlighted and one observation.
The observation is that Companies are being good with patching Operating System level vulnerabilities. I guess this is well-done to Microsoft and the other OS creators. However, if you are not fully patched on an OS level then you are the low hanging fruit. And you will be in trouble.
"Hackers" are moving to hacking applications these days - both pre-packaged ones which you will be more likely to find on the desktop and custom built ones which will more likely be hosted on a website.
So, companies now need to look at patching applications quicker.
They must also have a good solid web application plan in place and stick to it before exposing themselves online.
Showing posts with label risk. Show all posts
Showing posts with label risk. Show all posts
Friday, September 18, 2009
Tuesday, April 29, 2008
Because Hackers Don't Care... (Why Metrics Don't Work)
Lets start with some statistics:
99% of all workstations with up-to-date antivirus
Antivirus blocks over 99% of all malware.
That is amazing! That is great stuff to show the IT Director, CIO, CSO, mom and to put on the wall. But, yet, a company I know (not the one I work for) still managed to get a virus which brought about some painful downtime.
The virus was one of the 1% that the antivirus doesn't block and it spread through the organisation like wildfire. Essentially the saving grace was that it infected a small part of the network, brought that down and didn't spread from there. Luck. It was also non-destructive other than network downtime. Luck.
The metrics lied.
You could say that there was residual risk but it really looks quite small. What is 1% between friends? But that 1% is precisely what any hacker (or virus writer etc) worth his salt is targeting.
So, where to from here?
I won't throw the baby out with the bathwater. 99% of PCs with antivirus is certainly safer than 50% or 0%. 99% of PCs fully patched is safer then 70% or even 100% of PCs almost fully patched. But 99% of PCs with antivirus is not a guarantee that no virus will find its way to destroying your network. It is important that your boss(es) know this and more important is that you know this.
And have plans in place when the 1% risk becomes reality.
99% of all workstations with up-to-date antivirus
Antivirus blocks over 99% of all malware.
That is amazing! That is great stuff to show the IT Director, CIO, CSO, mom and to put on the wall. But, yet, a company I know (not the one I work for) still managed to get a virus which brought about some painful downtime.
The virus was one of the 1% that the antivirus doesn't block and it spread through the organisation like wildfire. Essentially the saving grace was that it infected a small part of the network, brought that down and didn't spread from there. Luck. It was also non-destructive other than network downtime. Luck.
The metrics lied.
You could say that there was residual risk but it really looks quite small. What is 1% between friends? But that 1% is precisely what any hacker (or virus writer etc) worth his salt is targeting.
So, where to from here?
I won't throw the baby out with the bathwater. 99% of PCs with antivirus is certainly safer than 50% or 0%. 99% of PCs fully patched is safer then 70% or even 100% of PCs almost fully patched. But 99% of PCs with antivirus is not a guarantee that no virus will find its way to destroying your network. It is important that your boss(es) know this and more important is that you know this.
And have plans in place when the 1% risk becomes reality.
Thursday, August 16, 2007
Calif-online-crime Law
According to CSO merchants in California may end up liable for data breaches.
I think this is a good thing but I also think it is a bad thing.
Its good because a lot of large companies pay lip service to Information Security and don't take it seriously enough. This will make sure that they do. It is good because it is not the poor customer who takes the risk when he does his shopping.
Its bad because it attacks companies for essentially being victims of crime. Not does the company suffer from the crime itself but it suffers from the after effects of the crime.
On the other hand, (I think we are up to 3 by now) there is always a risk in doing business and especially a risk of crime, it has just moved online now. Companies make good profits or else they would not be doing what they are doing so they need to offset some profits into protecting themselves and their customers' information from the criminals rather than ignoring the issues and pushing the risk onto the very customers that give them money.
I guess its kinda like me locking my expensive car and keeping the keys in my pocket but borrowing a friend's cheap car and leaving it unlocked and motor running in the street because, hey, its not my car.
This law is receiving strong opposition but I think it will be passed. If it is you can bet that somehow the cost will be passed on to the customers who will pay for protecting their own information.
I think this is a good thing but I also think it is a bad thing.
Its good because a lot of large companies pay lip service to Information Security and don't take it seriously enough. This will make sure that they do. It is good because it is not the poor customer who takes the risk when he does his shopping.
Its bad because it attacks companies for essentially being victims of crime. Not does the company suffer from the crime itself but it suffers from the after effects of the crime.
On the other hand, (I think we are up to 3 by now) there is always a risk in doing business and especially a risk of crime, it has just moved online now. Companies make good profits or else they would not be doing what they are doing so they need to offset some profits into protecting themselves and their customers' information from the criminals rather than ignoring the issues and pushing the risk onto the very customers that give them money.
I guess its kinda like me locking my expensive car and keeping the keys in my pocket but borrowing a friend's cheap car and leaving it unlocked and motor running in the street because, hey, its not my car.
This law is receiving strong opposition but I think it will be passed. If it is you can bet that somehow the cost will be passed on to the customers who will pay for protecting their own information.
Monday, April 23, 2007
Allen Baranov is alive, well and living a State of Fear (Part One)
"Is something wrong, she said
Well of course there is
You're still alive, she said
Oh, and do I deserve to be?
Is that the question?" - Pearl Jam, "Alive"
Yes. I am still about.
The last few weeks have been mad. My folks are visiting from Australia, blogger has been doing funny things, work has been hectic and I'm trying to work out what to do with my life. Lots of excuses why I have not posted in a long while...however...
... I am reading "State of Fear" by Michael Crichton. It is a really good book and worth reading as are all his books. The basic story behind it (besides all the fast paced action you should expect from his novels) is that Global Warming is junk invented by Earth Rights groups to get money that should go to starving kids in Africa and not some theory that may or may not be true.
So, what does this mean for us security professionals? This IS (sorta) an info-sec blog.
Well, he takes it further near the end of the book. He says that there are always issues facing mankind. The press and interested parties (in each case) just blow them up for their own gain. Interested parties so that they can get funding and the press so they can sell their media.
I know I get excited every time some bit of security news makes the papers (sometimes front page) even if once I dissect it, it is really some arbitrary news. It puts what I do in the spotlight and I can get a warm fuzzy feeling. I can also (maybe one day) tell people exactly what I do instead of "I'm in IT". And maybe more companies will take Information Security more seriously and spend more and some of that will trickle down into my usually empty pockets.
Bruce Schneier seems to think about this issue a lot and I like the title of his book "Beyond Fear" because that sums up where I think we should be going. Manage your systems correctly and don't worry.
Still, there are the Fear-mongers - buy security (and then even more) because you may go to jail if you don't secure your company down to the last little screw.
There are also...hmmm... the naive ones... who believe everything can be put into black and white. I always thought I was missing something because even in all my (too many) years in security I have no idea what numbers to use in a risk assessment.
Recently I posted to a security list asking "is a firewall really necessary?" and one answer was "do a risk assessment". I wasn't talking about an external firewall but the answer came from someone who didn't know that.
I can't see how my time would be best spent trying to (research/invent) numbers to prove that a firewall is needed. Its just plain sense (at least on the border) - I think.
Maybe there is a fine line between State of Fear and State of Risk. I hope that I am there.
Well of course there is
You're still alive, she said
Oh, and do I deserve to be?
Is that the question?" - Pearl Jam, "Alive"
Yes. I am still about.
The last few weeks have been mad. My folks are visiting from Australia, blogger has been doing funny things, work has been hectic and I'm trying to work out what to do with my life. Lots of excuses why I have not posted in a long while...however...
... I am reading "State of Fear" by Michael Crichton. It is a really good book and worth reading as are all his books. The basic story behind it (besides all the fast paced action you should expect from his novels) is that Global Warming is junk invented by Earth Rights groups to get money that should go to starving kids in Africa and not some theory that may or may not be true.
So, what does this mean for us security professionals? This IS (sorta) an info-sec blog.
Well, he takes it further near the end of the book. He says that there are always issues facing mankind. The press and interested parties (in each case) just blow them up for their own gain. Interested parties so that they can get funding and the press so they can sell their media.
I know I get excited every time some bit of security news makes the papers (sometimes front page) even if once I dissect it, it is really some arbitrary news. It puts what I do in the spotlight and I can get a warm fuzzy feeling. I can also (maybe one day) tell people exactly what I do instead of "I'm in IT". And maybe more companies will take Information Security more seriously and spend more and some of that will trickle down into my usually empty pockets.
Bruce Schneier seems to think about this issue a lot and I like the title of his book "Beyond Fear" because that sums up where I think we should be going. Manage your systems correctly and don't worry.
Still, there are the Fear-mongers - buy security (and then even more) because you may go to jail if you don't secure your company down to the last little screw.
There are also...hmmm... the naive ones... who believe everything can be put into black and white. I always thought I was missing something because even in all my (too many) years in security I have no idea what numbers to use in a risk assessment.
Recently I posted to a security list asking "is a firewall really necessary?" and one answer was "do a risk assessment". I wasn't talking about an external firewall but the answer came from someone who didn't know that.
I can't see how my time would be best spent trying to (research/invent) numbers to prove that a firewall is needed. Its just plain sense (at least on the border) - I think.
Maybe there is a fine line between State of Fear and State of Risk. I hope that I am there.
Subscribe to:
Posts (Atom)