Skip Links

Network World

  • Social Web 
  • Email 
  • Close

9/11 security lessons lost on businesses?

CEOs should act to protect key national assets, consultant says
By Tim Greene , Network World , 09/11/2007
  • Share/Email
  • Comment
  • Print

CHICAGO -- In the six years since 9/11 people in charge of key infrastructure have lost their sense of urgency to improve security, according to a panel at the Security Standard conference today.

“Treat every day as if it is 9/12 of 2001,” says Stephen Squires, a former NSA employee and now a security consultant. “Everybody in America has to decide what they’re going to do and do it. Don’t wait for somebody else to do it.”

He called for CEOs of major industries to determine what their companies can do to improve security of their networks and to take steps toward that even if it means extra spending.


Read about what University of Arizona scientists are doing to fight terrorists online

Catherine Allen, chairman and CEO of the Santa Fe Group, says that in the financial industry, businesses are security-focused. That’s because they have huge assets to protect and because they were they target of the 9/11 attacks. She said she sees continuing improvement of financial network infrastructure. “I sometimes feel like [this industry is] alone in that,” she said.

Her industry relies on carriers and power companies to support its networks, but she said their preparations for disaster may not be enough. “We work with energy and telecoms and tell them how dependent we are on them and that our regulations require us to be up within two hours of a crash,” Allen said.

The federal government doesn’t appreciate that these regulations don’t take into account that financial networks rely on these other providers, and that lack of understanding is damaging. “I think we’re doing an abysmal job on a federal government level,” she said.

Another panelist, Michael Assante, infrastructure-protection strategist for Idaho National Laboratory, said protecting power lines is a tough task, as evidenced by attacks against them in other countries that resulted in major business disruptions. “It’s a very difficult industry to protect,” he said.

Squires said that computer hardware could be made more secure based on industry research completed in the mid-1960s, but that no one has acted on it. “We’re living on a mid-20th-century computer architecture. There are better ways to do it. Why wait and ask for permission?” he said. “Leaders of great industries have to come together and decide they’re going to lead.”

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed