Time for a moratorium on FUD?

Analysis
Apr 30, 20126 mins

Where does all the fear, uncertainty and doubt in information security come from?

Fear. Uncertainty. Doubt. Otherwise known as FUD, it’s arguably a bigger threat to security assets and data than Stuxnet, hacktivism and WikiLeaks-style insider threats combined.

If you work in the information security industry, you can’t escape FUD. Each and every day, we’re pelted with the latest corporation or government to experience a data breach or other attack. Couple that with our friends in the blogosphere who interpolate potential and realized threats together into a tapestry of a “see what will happen to you!” mentality, and we wind up in a vicious circle. Fear creates uncertainty, uncertainty amplifies doubt, doubt transitions to fear, and then we’re back to square one. One security practitioner or commentator dismisses talk of large-scale cyber attacks doing significant damage, while another says this type of attack is a very real and present danger – it’s not a matter of “if,” but a matter of “when.” Someone else says that the threat of WikiLeaks-style insider attacks is overblown, while journalists and pundits might say they are a top security priority. Still others say that the prospect of cyberwar – large-scale attacks sponsored by nation-states – are overhyped.

Maybe, or maybe not. But, why does FUD like this exist in the security industry in the first place? From my perspective, the problem is threefold. First, we have to admit that there is no such thing as 100% security. If you have a tangible asset – a server, some data, a set of credentials – the fact is, given the right circumstances, that asset could be stolen, breached or destroyed (either intentionally or accidentally). Many organizations – and more than a few C-level executives – assume that if they have a competent CISO, and they throw enough money at PCI DSS, FISMA or other applicable laws, these things can’t happen. And that belief, of course, is what spawns a lot of FUD in the first place, especially when these organizations get breached.

Second, different security practitioners have different levels of understanding of threats. Want a concrete example? One of my good friends, former White House CIO Theresa Payton, recently gave a great presentation to a large number of CISOs and hands-on security practitioners from the commercial world. One of the topics included in her discussion was the idea of supply chain security for IT: the concept that there are risks to both the source and chain of custody of IT assets like servers, firewalls, and software. If you buy 500 Cisco firewalls from a reseller, for example, how do you know they’re genuine Cisco products? What if they’re knockoffs that also happen to contain code that keeps a port open to a single static IP address in another country, and is programmed to hide this fact? Even if the device is a legitimate product of a trusted vendor, how do you know that vendor ensures the integrity of its systems from all its suppliers (remember the Sony BMG rootkit)? You might be surprised at how many people in the room simply hadn’t thought of that type threat before – but in the case of the federal government, who is a high-value target that buys a lot of technology, it makes complete sense; and so like many federal CIOs and CISOs, Theresa had a good understanding of that particular threat. This inconsistent understanding of threats causes many security people to either under-value or over-value their potential impact, depending on their relative familiarity to the issue.

The third problem that propagates FUD is simply one of mis-calculating not only the impact of a threat, but its likelihood. We have to remember that just because a threat exists, that doesn’t mean it’s a foregone conclusion that it will be realized. The fact is, we simply don’t know. Even with a risk-driven security program in place, there’s still a back-and-forth see-saw over estimating the likelihood of threats that makes FUD such a difficult and potentially dangerous aspect of practicing information security.

It’s the combination of these three variables that makes FUD so lethal. It causes one organization to over-spend itself into a competitive disadvantage – or even oblivion – on security controls, while another underestimates its risk and unknowingly exposes itself to massive threats. It’s the driving force behind the hundreds of different and overlapping regulations, best practices and standards in our industry, all because we can’t come to an agreement on basic security concepts and controls. And most of all, it creates discord among ourselves and the general public, amplifying conspiracy theories that the entire security industry is some sort of continuance of a Y2K conspiracy.

Fear. Uncertainty. Doubt.

Now, there will be those who accuse me of actually spreading FUD by writing this. I want to make it clear that that is not my intention. The point is that FUD is real at its most basic level. We fear – as we should – a malicious attack on critical infrastructure, data and assets. We are uncertain whether we’ve implemented the necessary security controls to mitigate an attack (and hope that they work). And while we both doubt that an attack of the magnitude that some have predicted will occur, and whether we will be able to provide the business the answers it needs if an attack is successful – again, we’re not sure.

Why do we have this fear, leading to uncertainty and doubt? Because nobody knows what the attack will look like. The days of relying entirely on signature-based attack detection are long gone – that’s at least one thing the industry can agree on. Perhaps it is time that we all agreed to dispense with the FUD and focus on the facts. Perhaps we should look to define, or redefine terms like APT, cyber terrorism and cyberwar so that we are all clear on what they encompass. Perhaps we should agree on the most effective way to tackle the current and emerging cyber and insider threats so that our networks are stronger, our data is more secure and we, as an industry, are better equipped to tackle what is undeniably a growing problem. So, how about we start an open and honest debate about the state of our industry?

I’ll leave you with some statistics, taken from the 2012 Verizon Data Breach Report.

  • 85% of breaches in 2011 took more than two weeks to detect
  • 92% of breaches in 2011 were detected by a third party
  • 96% of breaches in 2011 had compromised servers
  • 69% of breaches in 2011 incorporated malware 

Oh, and 97% of data breaches in 2011 were avoidable through “simple or intermediate” security controls. No FUD … just cold, hard, facts. What does this mean for security practitioners? I’ll cover that in my next post.