Is your organization protecting yesterday's infrastructure from yesterday's threats? Vulnerability evolves not only in response to external drivers like viruses, but also network change. The challenge is that few IT executives have the dollars to scan and update their entire environment. This forces them to manage vulnerability in the rearview mirror.
For security professionals, saying yes, or offering workable alternative solutions, is especially hard. When asked to consider new technologies, we instinctively want to just say no. Isn't saying no our job?
Despite the recent TJX security breach, it is natural to conclude that companies will continue to ignore the seething vulnerabilities that lead to massive thefts of sensitive information. Most companies have been slow to react to other highly publicized exposures of personal information from the past two years.
VeriSign announced this week that it will raise registry domain name fees for .com and .net addresses by seven percent this October, per a December 2006 deal inked with the Internet Corporation for Assigned Names and Numbers (ICANN) that some security experts have criticized for a lack of foresight.