Linked on /. this morning is an editorial entitled Security Absurdity: The Complete, Unquestionable, And Total Failure of Information Security. It is an interesting read and is meant to serve as a wakeup call to the industry. I’d love to see people’s comments on this article. Below are some of mine.

Too many of our security layers of defense are broken. Security professionals are enjoying a surge in business and growing salaries and that is why we tolerate the dismal situation we are facing. Yet it is our mandate, first and foremost, to protect.

Not every information security business is based around protection or defense. Many of us focus on long-term strategy and planning, best practices, and policies in addition to technological solutions.

One only has to open a newspaper and view current headlines documenting the almost constant loss of personal and financial data due to carelessness and hacking. It isn’t just careless individuals that are leaking confidential information – it is large, multinational corporations with smart, capable I.T. departments with dedicated security professionals and huge security budgets.

If all the advice given by those dedicated information security professionals was heeded, would we really be where we are today? For every information leak and hack attack you show me, I can probably show you a situation where the recommendations were not followed because of:

  • cost
  • interference with long-standing practices
  • ease of use

It is easy to put the blame on the information security professionals, but not when they are offering solutions that are not implemented.

Through increased awareness can there be new dialogs and discussions on solutions. Because what is clearly missing is more dialog to come up with solutions to today’s security challenges.

Is more dialog really needed? Is all we need to do to solve this problem is get together and talk about it? Not on your life! It is time for action; time to stop talking about solutions and start implementing them. When solutions such as web content filters, intelligent managed PKI, encryption of disks and databases, virtual private networks with strong authentication, and patch management systems are installed everywhere, I suspect we will find the situation to be less dire than the author of this article supposes.

3 thoughts on “Failure of Information Security”

  1. Laura says:

    Unfortunately, security professionals aren’t the decision makers – and because of our aversion to management in general – we probably never will be. We can recommend things until we’re blue in the face, and we can even recommend things with different costs, and different tradeoffs based on why clients don’t want to implement security. Upper management still doens’t listen to us.

    Until a security failure or breach hurts a company’s bank account – security isn’t worth it. Sure, government regulations like SOX and HIPAA help, but until security (or the lack thereof) hits the company in the bottom line, they’re not going to pay attention to us.

    We have the unique job of trying to scare people into using security without blowing the threats out of proportion – and sometimes, exageration is the only way to get people to listen to us.

  2. Matt Appler says:

    Although the premise of the article is interesting, I don’t believe it stands up to some very simple analysis. If we are at such a crisis of Information Security, then how is business faring so well? The Dow and the NASDAQ continue to rise. E-Commerce sites continue to increase revenue. Credit card companies continue to make increased revenue and earnings.

    The author of the article does not only say that we are vulnerable (like a house with no smoke detectors), but that we are suffering the results of constant attack. I disagree. The economic results of corporate America do not agree. Could we do better? Of course we could. We will continue to do better. Our security products and knowledge are improving every month. However, we are not at a crisis in Information Security.

    The opinions expressed are those of the author, not the company he works for.

  3. Anil says:

    Isn’t this the cycle of security for all things?

    There is the company, empire, country, etc. that wants to “secure” itself in response to a threat (or perceived threat). If nothing happens for a while, then security is less of an issue…

    Then, whether is be because security is lax or otherwise, something happens and security suddenly becomes a priority again. The, “oh I should of done this…and that…”

    It seems as though security is always the after thought and one of the fast ways to cut costs – until something happens.

    It is evolutionary by nature…your body doesn’t create antibodies before you get sick, only after. If I were a white blood cell, I’d be mad about it too – though I, and the economy are still alive, but I do cough from time to time…

Comments are closed.