It’s Time To Change

Servers? Connectivity? Partners? Credit Card Processing? That database full of patient
data?

2049713405

The Real Attack Surface: People

There are lots of surveys, studies and findings out in the world these days that hype CYBER/CYBER-SECURITY/Security/INFO-SEC/etc. and while Ransomware is set to hit 5 BILLION or so in damages this year, there is an even more interesting finding out there-at least in my book: The primary attack surface has now become YOU (aka us, her or him). http://www.csoonline.com/article/3149510/security/the-human-attack-surface-counting-it-all-up.html

Why Companies Still Don’t Fix Security

The fortune 500 (five hundred companies) employed 27 million people-think about that for a minute-27 MILLION PEOPLE. Now I don’t know those people but I am going to make a few educated guesses here:

  1. An awful lot of those passwords can be cracked using automated tools
  2. In addition, of the remainder, many would fall for a well crafted and targeted phishing attack

Lets say 1 and 2 above total a million accounts-this is not many compared to the population of a given country but lets put that in perspective-1 million plus accounts in the fortune 500 companies… If an attacker can compromise at least 1 person in each of those companies that has administrative access on corporate databases, it is relatively trivial to cause serious damage. Companies could and would recover, but even 5-10 minutes of downtime at 20% of the fortune 500 companies in a coordinated attack would reverberate through world financial markets like an air-horn in St. Peter’s Square on a Sunday morning.

The same problem(s) security practitioners faced in the early 90’s and earlier remain problems today. Attitudes are still lackadaisical in this regard and we must change the game up a bit. Real awareness of security threats and risk is still near the bottom of the rung in many companies-or floating near the middle if there is leadership that is risk-adverse and does not want to be featured post-breach on Fox-Business at 6pm (but that is the exception.)

Costs drive business and until the cost of breaches is calculated and acted on in a responsible manner, things will not not change with regard to security postures. Standards exist for many “bits of technology” in our everyday life and these are routinely ignored for cost reasons, by the LARGEST of companies-a situation that often manifests itself on a country by country basis due to drivers such as liability which vary quite a bit.

Time for Legal Consequences

If we raise penalties to modify the risk-appetite of businesses, we will more than likely see a corresponding modification in security postures as a result. At present, our system is skewed to ignore the individual citizen (their personal data, privacy, etc.) and favor companies and industry verticals-until this changes we will continue to see out medical records held ransom, etc. It is time to take a look at our legal frameworks and think seriously about bringing significant criminal penalties to those suffering large breaches who simply did not take adequate measures to protect data of citizens that they hold. If an automobile manufacturer uses crepe-paper for their seat belt straps they will be heavily fined in short order-it is time the large enterprises be likewise fined for continually leaving our personal data with inadequately protections.

Also on LinkedIn

Consulting: Need independent analysis or security support? See AI & Cybersecurity Consulting.

Scroll to Top