Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Re-assessing risk (The crown jewels are almost worthless)

Security: Risk and Reward By Andreas M. Antonopoulos , Network World , 11/19/2007
Andreas Antonopoulos
  • Share/Email
  • Comment
  • Print

A popular expression in security circles is to equate critical company intellectual property with the crown jewels. That comparison is apt in more ways than one. I’ve visited the Tower of London and the crown jewels. The crown jewels are protected by many layers of security, but the truth is that they make very poor targets for theft because they are far too distinctive to fence. To sell such items, a thief would have to take great risks and heavy discounts. If someone was holding the queen hostage, they’d more likely ask for “nonsequential unmarked bills” that the crown jewels. Any item, whether tangible like the crown jewels or intangible like your company’s latest flying car design is only worth what a buyer will offer. If the market for such an item is too small or the risk of laundering too high, the item will have to be heavily discounted. Yet, in most information security risk-assessment methodologies we measure the loss impact for the company and ignore the gain potential for the thief.

The impact of a loss is a very important component of the risk assessment because it allows us to compare cost and benefit of securing an asset. But equally important is the other cost-benefit that occurs in the mind of a cybercriminal. In selecting which targets to attack, the criminal must consider the fully discounted value of the asset based on how easy it is to monetize it. So the flying car design has only a handful of potential buyers and leaves a trail because its source is easy to identify. So if I’m the attacker I will go for the asset that is most like small unmarked bills. In most companies that is either cash and financial instruments or the identities stored in various databases. The identity theft market is large and growing very fast. Identities can be sold for $14 to $18 in black markets, with anonymity and plenty of buyers.

When companies are trying to decide how much to invest in security and which assets to protect, they rely on a risk assessment that multiplies the impact of a loss with the probability of a loss. In turn, the probability of a loss depends on the rate of attacks and the vulnerability of the asset. So while we can calculate the relative vulnerability of our assets, how do we rate the probability of an attack? Most models use statistics based on reported attacks. But a better way to rank assets by probability of attack is to consider their resale discount rate – the cost of monetizing those assets in a black market. While we’re focused on protecting the flying car design, our HR database is like a pile of cash, enticing and easy to trade. Perhaps we need to re-assess risk by incorporating the motives of the attacker.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (2)
Login
Forgot your account info?

Crown jewels versus nickels and dimesBy Rob on November 23, 2007, 11:08 amSome crown jewels are not sellable, obviously, such as the formula for coca-cola. Yet the Attorney-General of the US estimated that the loss to the US economy...

Reply | Read entire comment

RE: Re-assessing risk (The crown jewels are almost worthless)By Robert on November 19, 2007, 4:00 pmA very good point. Most companies that pay attention to security worry about the theft of their proprietary data that is otften their primary source of income....

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.