Wednesday, February 11, 2015

Complexity is the Enemy of Security

I'm sure we've all heard the sound bite "complexity is the enemy of security" from time to time.  It's a popular, attention-grabbing phrase, but what can we learn from it?  My thoughts on the topic in my latest SecurityWeek piece: http://www.securityweek.com/complexity-enemy-security.  After all, the point of any sound bite should be to stimulate thought, discussion, and ideas, right?

Why is timely detection and response so difficult?

Why is timely detection and response so difficult?  People often ask me that question, so I put down my thoughts in this piece in IT Security Guru: http://www.itsecurityguru.org/gurus/breaking-barriers-improved-detection-response/#.VNtR1Fqf_Vt.  Timely detection and response is indeed a big challenge confronting organizations.  The good news is that there are practical, applicable steps that can be taken to improve the status quo.  I hope you agree and find tidbits you can leverage operationally.

Friday, February 6, 2015

Caveat Emptor

Although I'm not a Latin speaker, I am quite aware of the phrase "caveat emptor".  This phrase is most often translated as "let the buyer beware".  There are many contexts in which this phrase is appropriate, most notably when discussing contracts or legally binding agreements.  Unfortunately, I would argue that the phrase is becoming increasingly important in the field of information security.  What do I mean by this?  Allow me to explain.

I was fortunate enough to be invited to speak at a conference earlier this week.  Before my talk, I introduced myself briefly, as I typically do.  This particular time, it was a new crowd for me, and I did not know many people.  I was a stranger to them.  As I listened to some of the other talks, something dawned on me, and the idea of caveat emptor crossed my mind repeatedly.

When I introduce myself or talk about my background and experiences, I do so honestly.  People who know me and have worked with me in the past will vouch for that.  However, as we all know, not all people approach themselves in the same manner.  In fact, one speaker's introduction sounded nearly identical to mine.  What was the issue?  I have come across this individual in the past, and although I do indeed have the experience and skills I say I do, this particular individuals does not possess those same experience and skills.  Surely, we have all worked with or crossed paths with individuals like this in the past.  Where there's smoke, there's fire - except when there's not.

What's interesting to me is not necessarily that some people choose to embellish or blatantly falsify their backgrounds.  What's more interesting to me are two points: a) the rate at which these individuals seem to be appearing in the information security space and b) how hard they make life for the rest of us.

Regarding point a, this is perhaps not surprising.  Information security is now a hot field.  Whereas ten years ago, we were the obscure, quiet geeks in the corner, today, we are en vogue.  With the amount of money being thrown around in our domain of expertise, it's not surprising that there are suddenly countless new "experts" coming out of the woodwork.

Of course, with all these new "experts", it makes life that much more difficult for the rest of us.  I realized something very important when this particular speaker introduced himself.  To the crowd of strangers we both addressed, we are the same.  I'm not sure they can differentiate between who is real and who is not real.  At first, you may have an adverse reaction to this statement, but it is an important point.  Perception is reality.  This is unfortunate, and this is where the caveat emptor point comes in.

If you have ever been in or spoken with someone in a leadership position within an enterprise, you know that all day, every day, "experts" hound them.  After a while, all the buzzwords and marketing lingo begin to sound the same.  It makes it tough for both the enterprises, who very much need effective help (rather than ineffective or incompetent help), as well as the true information security professionals who are too busy working and solving problems to self-promote and shout above everyone else.

So what can we as a community do?  We can provide honest, truthful references and feedback.  We can vet people and companies we speak to.  We can seek out other opinions.  I fear that the days of taking what someone says at face value are slipping away from what was once a very tight and close-knit community.  It makes sense to vet.  Take care of the good information security professionals you  know - they need it.  We have entered the days of caveat emptor.

Friday, January 30, 2015

How to hire a top security employee

It likely comes as no surprise that people are an extremely important part of the people, process, and technology triad.  In the information security realm, finding the right people is certainly not easy for a number of different reasons.  How can organizations properly vet and assess candidates for security positions to ensure they do not make critical and costly hiring mistakes?  My thoughts on the topic in my latest piece in The Business Journals: http://www.bizjournals.com/bizjournals/how-to/human-resources/2015/01/how-to-hire-a-top-security-employee.html.

Tuesday, January 27, 2015

It's Okay to Fail

This may sound radical, but I would argue that we as a security community don't fail enough.  Or rather, that we aren't failing in the right way often enough.  Interested in understanding what I mean? Have a look at my latest SecurityWeek piece entitled "It's Okay to Fail": http://www.securityweek.com/its-okay-fail-security-problem-cant-be-solved.  Hope you enjoy.

Tuesday, January 13, 2015

Collection and Analysis: Two Sides to the Coin

While many individuals and organizations focus on collection of relevant data for security operations, fewer focus on the analytical component of the equation.  Curious what I mean?  Have a look at my latest piece in SecurityWeek: http://www.securityweek.com/collection-and-analysis-two-sides-coin

Monday, January 12, 2015

If I had a hammer: Security technology is a tool, not a solution in itself

We would never expect a hammer, some nails, and a pile of wood to magically build itself into a bird house.  So why do we sometimes expect our security technologies to magically build themselves into solutions to our security problems?  Technology is, first and foremost, a tool to be used in conjunction with intelligence and expertise.  Only then can we approach a solution.  My thoughts on this topic in my latest in The Business Journals: http://www.bizjournals.com/bizjournals/how-to/technology/2015/01/security-technology-as-tool-not-solution.html