| OUR EXPERTS: Sol Cates, CSO, Vormetric Chris Coleman, CEO, Lookingglass Gene Fredriksen, CISO, PSCU Ron Gula, CEO and CTO, Tenable Network Security James Knight, CEO, Beta Unlimited Larry Ponemon, chairman, Ponemon Institute Raj Samani, CTO, EMEA, McAfee/Intel Security Tom Smith, VP, Gemalto
|
A byproduct of the recent deluge of breaches is that some organizations are “unfortunately doubling down on maybe ineffective practices – just buying security defensive products,” Gula (left) says. They're stuck in a “vulnerability treadmill,” doing some sort of periodic security audit, getting a big report of vulnerabilities. They work hard to get rid of them, never improving, constantly see-sawing up and down. Such companies typically do not patch effectively on a continual basis.“They're grabbing the wrong metrics,” he notes, adding organizations should be counting the number of computers that are not being managed or missing a certain vendor's patches. The whole business – from top to bottom – must be aligned and scrutinized. How it makes money, engages and supports new and existing customers must be examined by analyzing the collection, storage and management of CRM and ERP data, Gula adds. Sol Cates, CSO of Vormetric, a San Jose, Calif.-based provider of data security solu- tions, agrees and urges all organizations to ask: “Do I have appropriate monitoring controls and procedures across every step throughout the organization to help minimize the impact of an event?”Knowing the whereabouts and number of copies of all data is critical, points out Cates. He advocates encryption, which received “a bad rap because it was a nightmare to manage.” Key management and access control issues are now easily overcome by technical solutions, Cates says.
Cloud providers aren't necessarily a weak link. “If you're going to put your data in somebody else's house, then protect their house [with encryption],” Cates (right) advises. “Quite often the service provider is better at security than you. But you want to keep the key just in case they're comprised.”Another preventive measure is removing potential risk from administrators. Hackers can't steal what a compromized administrator doesn't have privilege to, Cates notes.And, when assessing vulnerabilities, just don't rely on technology, Coleman points out. “Organizations have to get their staff really dedicated to actively hunt for anomalies for things that aren't right,” he says. “Humans need to question information flows, asking such questions as: Who is the organization talking to in the public internet? Should this transaction happen? Does this really make sense?” For his part, Fredriksen advocates a balanced, proactive approach. “Security professionals can't do it all themselves,” he says. It takes a holistic mix of people, process, and technology to“effectively protect that information.Aside from technical actions, Cates advises that – before a breach – organizations proactively align themselves with experienced outside counsel that has previously waded through the legal aspects of a breach. “They already have the expertise from other clients. Counsel can be an enabler in getting your response team together.”It is very hard for organizations following a breach to recover reputation-wise. The brand almost always suffers damage from not only a customer perspective, but also business partners. “Reputational cost is difficult to measure, and because it isn't measurable insurance won't cover it,” notes Ponemon, admitting that what's missing from his firm's company's cost of analysis model is “long-term reputational effect.” He believes a landmark judicial award involving a class-action suit resulting from a data breach is likely to occur soon that will determine an organization's exposure. | Health care: Unexpected breaches Just because an organization is regulatory compliant doesn't necessarily mean your enterprise is secure. Just ask Anthem and Premara Blue Cross. Larry Ponemon, chairman and founder of the Ponemon Institute, believes that even though Anthem had a strong security posture, it still couldn't stop a recent breach. “No one would have expected that the records could have been exposed,” he says. Chris Coleman, CEO of Lookingglass, an Arlington, Va.-based cyber threat intelligence management firm, points out that while health care historically has invested in IT security, it didn't believe it could be a major target. “Obviously that's changed over the past year.” He thinks that a sector like health care might have thought as long as they were compliant with HIPAA, it was a safe. “The problem with that is that it narrowly focuses an organization to become checkbox compliant.” |
