Came across this article via digg. A sad story is told how the “Director of Data Security And Compliance” was fired from his job due to incompetence after a break-in and theft left the company with hundreds of thousands in replacement and labor costs. The fired person’s story is that he tried to convince his management to implement all kinds of security controls that would have prevented this, but they chose not to due to cost.

Whether or not the story is true, a few lessons can probably be learned from it.

  • If your job is to ensure your company is secure, and you’re recommending something that is absolutely required, don’t take “no” for an answer. Your job could end up on the line anyway, so you need to fight very hard against cost-cutting measures.
  • Potential costs due to data/equipment theft or losses must be calculated before the loss occurs. This way they can be used as part of a return on investment argument for whether or not security improvements are implemented.
  • Document all your requests and received responses having to do with requesting improvements in security. Send emails/memos instead of having verbal discussions. There’s a big difference between a guy telling a sad story about being wrongly fired, and a guy with documented proof who could sue his company for wrongful termination.