Wednesday, January 7, 2009

Devolution and data-centric security

Forrester has been covering the data-centric security space for a while - Paul Stamp has had some good articles and now Andy Jaquith has an new report out as well - "Data-Centric Security Requires Devolution, Not A Revolution". The bottom line is to not think of this approach as revolutionary - While I agree with Andy to a certain degree, I would like to characterize this approach as being more the "logical" way to really protect data. You don't need to devolve to do this, but approach it logically :)

There are no complete solutions out there yet that fulfill the promise of data or information-centric security completely - and as in the case of all technology, there will always be work to be done! Therefore, one will be working with some sort of hybrid solutions for a while. There will still be areas where protecting the device or the network will make sense - these tools are widely available and have become mature. However this mistake that is made is to assume this is sufficient.

Andy has blogged about his report. He mentions that all data needs to be secure - no doubt. But we have to start thinking beyond those data elements at rest and think of data as a flowing medium - protect it everywhere. In this case, the only logical way appears to me to be the information-centric approach.

Tuesday, January 6, 2009

Two data breaches a day!

And to think that the numbers might be even higher! According to the Identity Theft Resource Center in San Diego, some 656 breaches were reported in 2008, up almost 50% from the previous year. This is almost two breaches a day - and according to the article in the Washington Post, many breaches do not even get reported. So this could be even higher!

I wonder if folks are getting blase about these breaches. To borrow a often-used Indian saying "Chalta hai!" - meaning "its okay, it happens" etc. :)

Hopefully the companies (and their customers) that have been affected don't have this sense of chalta-hai and pull up their collective socks to fix their data protection issues...

Wednesday, December 17, 2008

The security double whammy

A lot of the recent news is about how the recession will cause increases in cyber threats. Combining that with reduced investment in security, and you have a true double whammy. And some want to add icing to the cake by suggesting that employees will also become more tempted to steal data..

Nice - a triple whammy!

Organizations should be cognizant of the tradeoffs they are making from a risk management perspective. Even if one cannot get everything complete, use the old 80/20 rule to ensure the high priority and projects that will reduce the most risk get implemented. No use being penny wise and pound foolish...

Thursday, December 11, 2008

Crime and the economy

Seems like the prevailing wisdom is that when the economy is in tatters, crime rears up - a negative correlation, if you will. Apparently this is even more true for cybercrime - easier to make a few bucks when folks are scared about their savings, looking for bargains and the always popular, "too-good-to-be-true".

And criminal syndicates are taking advantage of this by providing "help" in ensuring their bank accounts are not in danger, new job opportunities targeting those who might have lost their jobs etc. Just read more of this from news.com.

Larger organizations are also not immune from this - what comes in as malware in only part of the threat and unfortunately seems to be the major focus. And folks are still pushing perimeter security and anti-malware as the main protection against this. I think we should be looking beyond - more defense in depth and more protection focused on the data itself.

Monday, December 8, 2008

New Cybersecurity post recommended

I think this is a long time coming - the idea of a more concerted effort and responsibility to fight all kinds of cybercrime. Be it commercial or against government classified data.

Global cyberspace is fragile and it will take a concerted effort to get the message out about the dangers and the grave responsibility that each organization trusted with information holds. The appointment of a national post in the new administration is welcome! I hope it happens and happens fast!

Wednesday, November 12, 2008

Scary criminal activity and data theft

Even though one knows that criminals are increasingly behind some of the larger data breaches, it not until we get hit on the head do we pay attention. I just read this recent article from USA Today about the latest attacks on corporate intellectual property - I tell you, this is serious stuff.
Any organization not taking this very seriously is doing a disservice to its stakeholders and shareholders.

The problem seems intractable - for every hole you think you have blocked two open up to allow these criminals to grab data. What does any organization do?

I think the answer lies in the data itself - one cannot go about protecting the periphery to protect the asset. One has to protect the asset itself - in this case the data. If the data itself is always encrypted, at rest as well as in motion (even when it is grabbed of the computer by malware), we might have a shot at preventing this.

Else we are putting our collective heads in the sand thinking that encrypting the laptop drive or USB device is enough...

Thursday, November 6, 2008

WPA encryption cracked..

Just read this about the "more secure" WPA encryption for Wi-Fi networks is now cracked. Read all about it here - apparently by the same guys who broke WEP (this is what hurt TJX). I guess the bar has been raised...