- Mythbuster busts his own tale
- 10 open source companies to watch
- Sony recalls 73,000 Vaio laptops
- Tool to evade China's Web censorship
- Chrome and Firefox and add-ons
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:App Performance | On Demand Security | Networking Solution | SOA | Value of WDS
In the last column I talked about the challenge of trying to predict attacks, and how that approach leads to “anti-X” security strategies that are rapidly made obsolete by each new wave of threats.
The strategy of threat prediction suffers from two major flaws. First, it assumes predictability in a field that is full of surprises. Security is adversarial, and the adversaries already knows what we are doing – they can read this magazine, for example. New attacks are not designed in a vacuum; they are designed explicitly to sidestep our expectations. If we base our defenses on predicted threats, attackers sidestep our defenses when they sidestep our expectations.
Second, threat prediction causes tunnel vision. It pushes us to focus on attacks rather than assets, on the “bad” rather than the “valuable.” This plays right into the hands of attackers, as tunnel vision narrows our defenses thereby making them easier to bypass. Rather than trying to predict threats, we should focus on general security preparedness.
After all, there is no such thing as a “secure” company or system. Everything can be broken with enough effort and money. Secure companies are not those that do not get breached – every company will suffer a security failure (or several) sooner or later. Rather, secure companies are those that minimize both the incidence of successful attacks and then further minimize the impact of those few breaches. Accepting breaches as normal, business-as-usual and unavoidable puts the emphasis on preparedness rather than prediction.
Of course, this does not invalidate the need to establish defenses and controls that are specific. Just like a flu shot in the fall, you may take precautions against specific threats that are known and predictable. But most companies put a lot less emphasis on preparedness that they do on specific threats. We have seen this in our research year after year, where we find very few companies with specific, well designed and well drilled incident-response policies. It’s as if “incidents” represent the failure of security that no one wants to acknowledge. “Incidents” are of course the norm, not the exception. To repeat a biological example, we should be putting a lot more emphasis on frequent hand washing while keeping some chicken soup in stock, rather than trying to find more vaccines to take every fall.

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...
Vulnerability Management For DummiesDownload this concise book "Vulnerability Management for Dummies," to learn about the simple steps...
The ROI and TCO Benefits of Data Deduplication for Data Protection in the EnterpriseThis paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...
PoE Plus: Impact on the PoE MarketThe standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...
Harnessing the power of communications to increase workplace performanceDue to the convergence of IT and telecommunications technologies, the business workplace has been...

We have so many holes punched in our firewalls today that many industry insiders question the value...
The self-managed networkWe aren't there yet, but advances in network and systems management tools are making it possible to...
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment