Showing posts with label anti-virus. Show all posts
Showing posts with label anti-virus. Show all posts

Monday, 8 April 2013

Running with Scissors

There are things that we just shouldn't do - like running with scissors.  We can be told not to do them.  We can know intellectually not to do them.  But until we've stabbed ourselves or someone else it just doesn't sink in.

I've been seeing a lot of discussion recently on attack as pro-active defence - especially related to botnets.  The proponents make a good case that they are making everyone safer.  The opponents say that any unauthorised access - even to disable malware - is wrong and must not happen.  In both cases they have the implicit assumption that the people who own the computers that have been turned into bots are also victims.  I think it's time we addressed the elephant in the room.  We should adjust our thinking and stop thinking of them as victims and start thinking of them as part of the problem.

The only reason they have been turned into bots in the first place is that they haven't enabled even the most basic protections on their computer.  They are running with scissors.  They are stabbing people with the scissors.

We can no longer accept this.  Basic protections won't stop a determined attacker, but turning on automatic patching and running a free antivirus solution will stop most of them being owned most of the time.

It's time the software and operating system vendors made it impossible to turn off these sort of basic protections.  And it's time for society as the real victim of cybercrime demanded it.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com


 

Monday, 17 December 2012

Myth #4: We comply with PCI DSS

There are a lot of organisation who think they are compliant with the controls in the PCI DSS, but really aren’t.  There are even more that were compliant at a point of time in the past, but aren’t now.  But let’s for the moment assume that an organisation really is compliant with the 6 objectives, 12 requirements and 225 controls in the PCI DSS.  Does this mean that they are more secure?

The Verizon 2012 Data Breach Investigations Report provides statistics on organisations that suffered a data breach, but should have been compliant with the PCI DSS.  If they were compliant they were 24× less likely to suffer a loss.  This is a really clear statistic, companies really are far more secure if they are compliant with the PCI DSS.

Of course this shouldn’t be a surprise, since the standard is just good security practice, and if organisations take this good practice and apply it to everything, it naturally follows that they will be more secure.

But there were still breaches from PCI DSS compliant organisations.  This doesn’t imply that the standard isn’t good enough – there is no such thing as perfect security – but more perhaps reflects that the only part of an organisation covered by the standard is the cardholder data environment.  It’s possible to have a compliant cardholder data environment, but neglect security in other areas, and still get compromised.

Compliance drives security, but does not equal security.

If PCI DSS is used as a basis for the entire security culture, then this myth is confirmed.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com

Tuesday, 11 December 2012

Myth #3: We have the best hardware

We have the best hardware.  We have firewalls from more than one vendor.  We have anti-virus appliances at the gateway.  We have excellent logging capabilities.  We’ve just implemented a data loss prevention solution.  And we’ve had the smartest engineers hook it all up.  Of course we are secure, our vendors told us so!

If you go back to Myth #1, most of the businesses that suffered a data breach had the best hardware.  It didn’t stop the bad guys.

The Verizon 2012 Data Breach Investigations Report has some really enlightening statistics about the timing of data breaches.  Most compromises happened within minutes of initial attack, and data exfiltration happened within minutes of compromise.  But detection of the compromise didn’t happen for months, and containment took weeks after that.  And many of these breaches happened to companies with all the best hardware.

The thinking underpinning this myth is that as technology created the problem, it can also solve it.  As most of these technical systems are scoped, implemented and managed by capable technologists, they are unfortunately blind to the truth.  Information Security is a People Business.  It’s not about the technology.  It’s never been about the technology.

People are the easiest system to attack, and people can subvert any security control.  And much to the annoyance of the technologists, they can’t be patched, and they can’t be upgraded!

Hardware provides a solid platform, and without it security isn’t possible.  But policy, configuration and management trump functionality every time.  Many businesses focus too much on capex and so will overspend on the former, and underspend on the latter.

That makes this myth busted.

Phil Kernick Chief Technology Officer
@philkernick www.cqr.com