The global nuclear watchdog agency, the IAEA, said last week that the Japanese government was remiss in their risk assessment duties by not failing to fully anticipate what dangers a giant tsunami might pose to a nuclear reactor in that country. In fact the head of the IAEA, Michael Weightman, actually said that he could not understand how a country that has excelled in the prediction of earthquakes could have failed so spectacularly in predicting a giant tsunami. He went on to say that "Perhaps, their methodologies or data didn't allow them to predict that this size of tsunami could occur."
Huh?
I am under the impression, and operate as such, that in the aftermath of 9/11's lesson, no risk scenario is too remote or unlikely to reasonably plan for and reasonably anticipate. How is possible that Tokyo could not or did not fail to see the corollary between a large earthquake - which Japan undergoes with regular frequency - and the quite likely consequence of a tsunami. Japan is, after all, an island nation that is surrounded by water, so tsunamis would be one of the most likely threats to consider planning for. The city of Topeka, Kansas can be excused for not having a tsunami response plan, but not any city in Japan.
If you plan a beer garden event, you better have a corollary plan to address the risks of full bladders; if you plan a vacation to London, you better plan for rain; and if you plan to buy a Bugatti Veyron Super Sport ($2.7 million), a car that has 16 cylinders, has 1001 horsepower and gets only 8 miles to the gallon in the city, you had better be prepared for the consequences of higher fuel bills, higher car insurance and significantly less disposable income for other luxuries (Four new wheels and tires $50,000; Annual routine maintenance $20,000).
With the Bugatti's top speed at about 253 miles per hour, need we even broach the subject of the increased risk of dying in a crash?
Privacy and security are typically good things. But the way they are implemented or presented to real people to follow in the real world are not always realistic. Sometimes they are just down right ridiculous.
Sunday, June 5, 2011
Wednesday, May 4, 2011
For Privacy & Security, when Technology and Intelligence compete...it's no contest
With the recent news of the capture and death of Osama Bin laden, one thing was evident and overwhelmingly clear: our brilliant and sophisticated technological superiority notwithstanding, at the end of the day it was pure, simple human intelligence that produced the dramatic results.
Take away: though technophiles like me love to layer on security tools and controls to maintain data and privacy security throughout the organization, it is the simple sentence and/or concept that hits home to the end user employee who sits on the frontline of the trench warfare between customer confidence and blaring headlines that it is he and she who really determine our long-term success.
Being able to translate the importance and criticality of security being 'everyone's job' (and not just InfoSec's) within the company, is the single most valuable ROI of security & privacy awareness a company can realize. Forget DLP, NAC, anti-virus, encryption, etc. translating 'intelligence' into accessible and actionable steps your employees can take to protect the company's 'crown jewels' will ultimately be the reward your business folks will be looking for, appreciate, and best of all, value.
Take away: though technophiles like me love to layer on security tools and controls to maintain data and privacy security throughout the organization, it is the simple sentence and/or concept that hits home to the end user employee who sits on the frontline of the trench warfare between customer confidence and blaring headlines that it is he and she who really determine our long-term success.
Being able to translate the importance and criticality of security being 'everyone's job' (and not just InfoSec's) within the company, is the single most valuable ROI of security & privacy awareness a company can realize. Forget DLP, NAC, anti-virus, encryption, etc. translating 'intelligence' into accessible and actionable steps your employees can take to protect the company's 'crown jewels' will ultimately be the reward your business folks will be looking for, appreciate, and best of all, value.
Sunday, May 1, 2011
Bring Your Own Device to Work and Help Put the IT Department Out of Work?!?
I was a having a conversation with another fellow security professional at the CSO Perspectives seminar a few weeks ago and he used the word “disintermediation” to make a point about his website. We had a bit of a chuckle about how that word that was used (rather, overused) during the dot-com days. The context back then was that the new, online world was going to obsolesce the traditional world of bricks-n-mortars through the ‘disintermediation’ process of cutting out the no-value-adding, costly infrastructure of middle-men.
This got me to thinking about the topic I was speaking about at the conference: the way to bring about a culturally acceptable balance between security and the use of consumerized IT. That is, how could IT departments allow users to bring and use their own equipment in the work environment and still maintain a modicum of security and privacy?
Why is this issue even a concern? In this cost-conscious environment where businesses are constantly being pressured to reduce expenses as much as possible, doesn’t consumerized IT actually make sense?
In some ways, yes. The primary downside of this veritable technological tsunami is the impact it has had on the dynamic between the typical user and the IT department. The user demand (especially among C-level types) of bringing in a new iPad, iPhone, Droid, Xoom, etc. that they got for Christmas and expecting it to be hooked up to the company network, inevitably highlights the tension and traditional IT resistance of allowing unknown/untrusted devices into the inner sanctum. The risks are obvious and myriad. These risks have led many organizations to firmly resist consumerization by restricting personal devices/consumer electronics into the workplace.
I argue that regardless of the formal or informal position of the IT department, or even the company policy in general, this faction of users is growing and is in fact disintermediating the IT department by working around them to get their devices to work at work. The ‘Just Say No’ position of many IT departments is in fact making the company less secure overall as it is causing employees to circumvent the rules blockades put up and kept in place from years past.
The driver of this form of insubordination is clear: these days, the boundaries of a company’s information network are not as clearly defined as they were in the recent past - the mobile phone is now the mobile office, for example. The ultimate objective of consumerization is simply work and personal life converged onto a single device. There is no longer credibility in walking around with five devices clipped to your belt, looking like something out of Batman Beyond. Today, if you walk into a meeting and plop down more than one device on the table, you are immediately branded a dinosaur.
The primary theme of my speech was that that the trend of consumerized IT is irreversible and futile to resist, so CIO/CISO/CTOs need to seek a culturally acceptable middle-way of accommodating the movement, while still setting reasonable guidelines. The benefits of cooperation with a workforce who is more tech-savvy than ever are numerous, not the least being the reputation of IT as supporter of the business will be greatly enhanced. No longer IT will be identified as the “Dept. of No.”
Here are few more reasons why it makes sense to listen to the sound of inevitability that’s coming at us at 100 mph. It’s all about productivity via familiarity of the toolset. Think about how life was like 15 years ago: you had use of all the great technology and software at work. When you came home, all you had was some stripped down versions of that machinery and applications – toys, really. Today, the scenario is reversed. Employees who have state-of-the art technology at home can’t reconcile the fact that when they come to work they have a Windows XP, or worse, Windows 98, machine that takes 2 days to boot up. Pent-up user demand (I want my MTV!), especially of the Gen X & Y and Millennials should not be underestimated, and consumerized IT can be the Holy Grail of employee satisfaction.
The toothpaste is now out of the tube, folks. Employees are a lot more productive when they have a say on the tools they use every day. What we as IT professionals need to do is to show leadership & get it right so that the company is protected & users are happy. At least for now.
Tuesday, April 5, 2011
Fare thee well, Epsilon…A future case study for brand & reputation risk
Like me, maybe you have received a notice in the last few days from one of many institutions that were affected by a major data breach of Epsilon, an online marketing firm. So far, we are told, mostly e-mail addresses were compromised, but in some cases so were customer names. You might not think this sounds terribly alarming, unlike, say, the T.J. Maxx episode in 2007 that included the loss of 45 million debit and credit card numbers. But you would be wrong
In the T.J. Maxx scenario, only the reputation and brand of T.J. Maxx was impacted. In this case, Epsilon is the service provider to a significant list of top-tier financial institutions including Barclays Bank, U.S. Bancorp, Walt Disney, Marriott, Ritz-Carlton, Best Buy, L. L. Bean, Home Shopping Network, TiVo and Target. The ongoing concern is that customers of these institutions can now be specifically targeted for fraudulent e-mail threats know as ‘spear phishing.’ (Though notice of the breach was sent to me by e-mail, oddly enough
In the T.J. Maxx case, the credit cards and debit cards were quickly canceled and replaced by the issuers (Visa, Mastercard, etc.). And in most cases these days, unlike in the recent past, the customer is not even responsible for the first $50 of fraudulent charges (Bank of America tells me that I will not be responsible for any fraudulent charges!). This lack of material and financial impact on a customer of T.J. Maxx helps explain why after their breach, not only did the sales of the company continue as before, but their stock price suffered no long-term ill effect. Average customers liked what the stores offered in terms of fashions and prices and disassociated the breach itself from the stores and the merchandise.
In the Epsilon case, however, I fear the result will be much more disastrous for them. The publicity around this episode alone is more significant than most other ones like it. Rush Limbaugh actually used the Epsilon example today to sell one of the identity theft products he touts on his show. The actual service offered by Epsilon can easily be replaced, but the untarnished reputation of the brand whose customer falls prey to a fraudulent e-mail cannot so easily be restored. If my identity is stolen after I click on a fake e-mail from my bank, I am going to remember and negatively associate the experience with the bank, not the e-mail marketing vendor who didn’t encrypt my e-mail address and name in their database.
We are not sure yet just how lax Epsilon was in their security controls that led to this incident. Whether or not they were as lax as T.J. Maxx was, will be uncovered in brutal detail in the process over the next few weeks, especially in the security world. Security folks will be using this very case as a way to reiterate the internal message of due care and the need for this or that software or hardware to help protect their own shop from suffering a similar fate.
This unfortunate series of events highlights the kind of brand and reputation risk a firm can suffer when outsourcing even the most seemingly innocuous service. Proper vendor management and due diligence of service providers will be the talk of the town over the next couple of months. Your clients will be asking what and how you do it in your shop, without a doubt. So be ready with a solid response.
In the T.J. Maxx scenario, only the reputation and brand of T.J. Maxx was impacted. In this case, Epsilon is the service provider to a significant list of top-tier financial institutions including Barclays Bank, U.S. Bancorp, Walt Disney, Marriott, Ritz-Carlton, Best Buy, L. L. Bean, Home Shopping Network, TiVo and Target. The ongoing concern is that customers of these institutions can now be specifically targeted for fraudulent e-mail threats know as ‘spear phishing.’ (Though notice of the breach was sent to me by e-mail, oddly enough
In the T.J. Maxx case, the credit cards and debit cards were quickly canceled and replaced by the issuers (Visa, Mastercard, etc.). And in most cases these days, unlike in the recent past, the customer is not even responsible for the first $50 of fraudulent charges (Bank of America tells me that I will not be responsible for any fraudulent charges!). This lack of material and financial impact on a customer of T.J. Maxx helps explain why after their breach, not only did the sales of the company continue as before, but their stock price suffered no long-term ill effect. Average customers liked what the stores offered in terms of fashions and prices and disassociated the breach itself from the stores and the merchandise.
In the Epsilon case, however, I fear the result will be much more disastrous for them. The publicity around this episode alone is more significant than most other ones like it. Rush Limbaugh actually used the Epsilon example today to sell one of the identity theft products he touts on his show. The actual service offered by Epsilon can easily be replaced, but the untarnished reputation of the brand whose customer falls prey to a fraudulent e-mail cannot so easily be restored. If my identity is stolen after I click on a fake e-mail from my bank, I am going to remember and negatively associate the experience with the bank, not the e-mail marketing vendor who didn’t encrypt my e-mail address and name in their database.
We are not sure yet just how lax Epsilon was in their security controls that led to this incident. Whether or not they were as lax as T.J. Maxx was, will be uncovered in brutal detail in the process over the next few weeks, especially in the security world. Security folks will be using this very case as a way to reiterate the internal message of due care and the need for this or that software or hardware to help protect their own shop from suffering a similar fate.
This unfortunate series of events highlights the kind of brand and reputation risk a firm can suffer when outsourcing even the most seemingly innocuous service. Proper vendor management and due diligence of service providers will be the talk of the town over the next couple of months. Your clients will be asking what and how you do it in your shop, without a doubt. So be ready with a solid response.
Monday, March 28, 2011
Things Worth Fighting For
I came across a little publicized story this week that presents an interesting parallel to my constant message of privacy & security diligence. Here is the story: The Yamaha Motor Manufacturing Corporation has been making an all-terrain vehicle (ATV) in the U.S. called the ‘Rhino’ since 2003. The Rhino is different than its single-passenger predecessor since it allows for two passengers to sit side-by-side.
Four years later, the company added a few safety updates like more passenger hand-holds. Lawyers for some injured drivers (plaintiffs) jumped on the company’s move insisting that the reason the safety features were added was because the vehicles were not safe in the first place. Naturally, lawsuits piled in. Overwhelming a company with so many lawsuits that it figures it’s easier to settle then fight was the approach the plaintiff’s attorneys took. The attorneys attacking the company even petitioned the Consumer Product Safety Commission (CPSC) to aid their suits by trying to force Yamaha to recall their vehicles.
Yamaha did not feel a recall was warranted and even worked with the Consumer Product Safety Commission to make other modest safety changes that would satisfy the agency.
Most importantly, the company responded to the litany of lawsuits in an uncommon way: It decided to fight back.
The company was ultimately vindicated as it proved that in a significant number of instances, the drivers of the vehicles were grossly at fault due to their own behavior. Though riders are cautioned to operate the vehicle properly, the CPSC investigations indicated that product defects, insufficient warnings, negligence, etc., was not the cause of the injuries.
What’s the takeaway then? The company believed in its product, it believed it had provided sufficient safety and precautionary advice to its customers to operate safely, and it had decided to stand its ground and fight back on a principle of having done the right thing. (How unorthodox!)
And what is the connection to privacy & security? Companies create and publish rules and guidelines all the time for their employees on why and how it expects the employees to follow those policies. Some times the rules aren’t followed. Often, the rules are only words in a document on the company Intranet to make Legal or HR happy. Sometimes the Information Security team is only a paper tiger with little enforcement power or ability to bring about change and assure compliance.
But in some cases, the company itself, usually with the tone set at the top, decides to practice what it preaches and enforce the rule; make examples of those who purposely attempt the flout the rules, and inform those who do it unwittingly.
These days, consumers are savvier than ever about information. They know the value of their information and they want it protected. A customer will walk away from a company who only pays lip service to the principles of privacy & security, and they will excoriate the company online in blogs and forums for doing so.
The twin pillars of privacy & security in a company can easily be an asset and competitive advantage to a company who knows how to leverage that expertise, and maintain its diligence. I know it’s not always easy to keep up the pressure. Employees get comfortable; employees get lazy. IT can sometimes be a hindrance and not a help to getting the business of the company done, so creative employees will go around the roadblocks to meet deadlines. Privacy & security sometimes suffers. When a company becomes lax, or inertia sets in, the guard gets let down and rules are no longer followed or enforced. That’s when incidents happen; that’s when headlines happen.
If a company believes in its principles, believes it has provided reasonably sufficient safety and precautionary advice to its employees to treat and handle information securely, and it decides to stand its ground and fight back against the perpetual inertia of letting violations slide by because its easier than making a fuss, then it has done the right thing. It will fight back and should fight back. Why? Because privacy & security is worth fighting for.
Thursday, February 3, 2011
What Does Stuxnet and Rollerball Have in Common? Only The Future of Warfare...
We have seen the future of war, and its name is Stuxnet.
When I was a kid, one of my favorite movies was a science fiction picture that proposed the idea that in the future, nations would no longer exist and war would no longer exist. The world would be controlled by a handful of international corporations. The controlling industrialists realized the folly of war with its destruction, its carnage, its irrelevance, and resorted instead to a particularly gruesome sport as a proxy for war itself: Rollerball. Primary cities each had their own teams and the teams would battle it out on the hardwood coliseum for supremacy. The movies tagline is: "In the not too distant future, wars will no longer exist. But there will be Rollerball." (Rollerball is like a cross between roller derby, hockey and motocross.)
The original version of the movie (1975) is a bit dated and contrived , but Rollerball does contemplate a future that, in retrospect now seems pretty plausible and a good security allegory.
The worst-case scenario of all-out nuclear war looks unlikely to occur due to a variety of reasons; not the least of which is the overwhelming destruction and the obvious repercussions on the instigator. What is much more likely based upon recent evidence is that States and private industry will increasingly engage in proxy fights through esoteric non-State actors. Numerous examples of these proxy fights exist which include cyber-warfare between entities where the target was obvious, but the attacker was not. In 2007, a three-week wave of massive cyber-attacks were aimed at the small Baltic country of Estonia, where Parliament, banks, and the media were targeted, allegedly by Russian hackers after the Estonians' removal of a Soviet war memorial in the center of the capital, Tallin. In late 2010, companies like Visa, MasterCard, PayPal and Amazon.com were also targets of coordinated distributed denial-of-service attacks, designed to force the websites offline or make them generally unavailable for business by hacker sympathizers of Julian Assange due to the websites' refusal to process payments to support the Wikileaks effort.
To best illustrate the premise that future conventional warfare for most of the advanced world will pose a lesser risk than it has historically, and will instead be replaced by pure cyber-warfare, consider the case of Stuxnet.
'Stuxnet' is a computer worm that was launched in July of last year with a destructive payload that had a defined target: Windows-based industrial systems. The worm was designed very specifically to attack only certain types of industrial systems; like the ones that run nuclear plants.. Unlike most viruses and malware, Stuxnet does little harm to computers and networks that don't meet the explicit configuration requirements of its code. Like a laser sight on a snipers rifle, fingerprinting technology allows Stuxnet to precisely identify the systems it infects The creator of this worm took great care to ensure that only the designated target(s) were hit. A tremendous and sophisticated effort was required to avoid collateral damage.
What was the intended target? It is difficult to say for sure, but this much is known: 60% of the infected computers worldwide were in Iran. It is surely not a coincidence that Stuxnet infected the systems at two nuclear power plants that were hurriedly trying to enrich uranium.
The complexity of the code and the use of multiple programming languages contemplates the idea that only a -State or collection of States accessing deep enough pockets and vast dedicated resources could have the collective skill to create and deploy such a focused cyber-weapon. Most of the blame falls on the U.S. or Israel, in particular, who would ostensibly have the most to gain by stopping or slowing the ability of the Iranians to get nuclear capability.
The supposition then is obvious: this cyber-weapon was created o do what conventional warfare and diplomacy could not by surreptitiously taking out enemy nuclear capabilities like a sniper in the night. Unlike the very public 2007 Israeli air force raid on a Syrian site that the Israelis claimed was a nuclear facility with a military purpose, the Stuxnet attack is a much lower profile attack. The message is no less ambiguous than a full frontal assault and the effect just as valuable. Coupled by the additional benefits of no human causalities, and no political fallout, cyber warfare appears to also be very, very cost effective.
From the limited test case of Stuxnet, we can easily extrapolate to an 1984-like world of cyber-warfare where instead of Oceania declaring war on Eurasia one week or Eastasia the following week, battles will instead be played out over DS3s, T1s and fiber optic networks. Rather than sending one million expensively armed soldiers to invade an enemy, one simple mouse click could deploy a worm or virus that will shut down power grids, water systems or wreck havoc on international financial systems.
It may not be roller derby, but either way, Stuxnet presages the future of warfare.
Saturday, January 29, 2011
The TSA Color Coded Alerts: Fade To Black
Is it any surprise that the TSA announced this week that the color-coded threat system it has had in place since post-September 11th is being replaced?
I will refrain from comment on the new system it the details have been fleshed out and give it a chance to better inform us of what real and imminent dangers we may be in store for.
However, last post I made a point about the threat system having 5 different levels, and never having ever been at the two lowest colors - blue and green. Security Expert Bruce Schneier makes this pithy insight:
"The DHS could have lowered the level to something more reasonable, but that would have been politically impossible. If there were a terrorist attack and the threat level had been blue or green, the DHS would have been blamed for not warning us. Keeping the level high might increase the general dread among some people and cause sniggering among others, but it helps protect the jobs of those charged with keeping us safe from terrorism."
Schneier also goes on to make the great point about our ability to be on alert, which in the intention of the colored system. But always having the alert color be at one of the three highest of the colors puts a tremendous burden of responsibility on average travelers. Schneier says "According to scientists, California could experience a huge earthquake sometime in the next 200 years. Even though the magnitude of the disaster will be enormous, people can't stay alert for two centuries."
He's right. We have to be on our guard for sure, and I always like to say that every and any decision we make day-to-day is a risk-based decision, but we cannot be infinitely diligent. Human beings just don't have the mental ability to be that alert at all times. We can't even text and drive at the same time.
I will refrain from comment on the new system it the details have been fleshed out and give it a chance to better inform us of what real and imminent dangers we may be in store for.
However, last post I made a point about the threat system having 5 different levels, and never having ever been at the two lowest colors - blue and green. Security Expert Bruce Schneier makes this pithy insight:
"The DHS could have lowered the level to something more reasonable, but that would have been politically impossible. If there were a terrorist attack and the threat level had been blue or green, the DHS would have been blamed for not warning us. Keeping the level high might increase the general dread among some people and cause sniggering among others, but it helps protect the jobs of those charged with keeping us safe from terrorism."
Schneier also goes on to make the great point about our ability to be on alert, which in the intention of the colored system. But always having the alert color be at one of the three highest of the colors puts a tremendous burden of responsibility on average travelers. Schneier says "According to scientists, California could experience a huge earthquake sometime in the next 200 years. Even though the magnitude of the disaster will be enormous, people can't stay alert for two centuries."
He's right. We have to be on our guard for sure, and I always like to say that every and any decision we make day-to-day is a risk-based decision, but we cannot be infinitely diligent. Human beings just don't have the mental ability to be that alert at all times. We can't even text and drive at the same time.
Subscribe to:
Posts (Atom)