Don’t be a Blobmonger

Opinion
Oct 7, 20085 mins

* Security lessons from The Blob

Mudd: Regular people do not want to hear about some vague entity waiting in the shadows to insinuate itself into their computers. That holds true for at-home users as well as business executives. So, borrowing a quote from The Blob’s protagonist, Steve Andrews (played by Steve McQueen): “How do you get people to protect themselves from something they don’t believe in?”

Sharon Mudd graduated from the Master of Science in Information Assurance (MSIA) program at Norwich University in June. She contributes today’s column – what follows is entirely her own work with minor edits.

* * *

Do you remember the quintessential horror movie “The Blob”? OK, technically, I don’t either. I am not old enough (it was released in 1958). But I do remember hearing about it and seeing clips from it used in other movies or TV shows. Recently, on a morning radio show, I heard the host describe the villain as an amorphous thing that attached itself to one person, ate him, and then proceeded to eat half the town. That summary struck me as almost exactly the same kind of description given for many of the complex security problems seen over the last several years.

Here’s the problem, though: Regular people do not want to hear about some vague entity waiting in the shadows to insinuate itself into their computers. That holds true for at-home users as well as business executives. But they also have no patience for wading through ever-so-enthralling details of IP addresses, code fragments and vulnerable ports.

So, borrowing a quote from the film’s protagonist, Steve Andrews (played by Steve McQueen), “How do you get people to protect themselves from something they don’t believe in?”

Too many times what the general public (or even our management) hears from us geeks sounds like the same warnings of impending doom Steve was giving the people in the movie. “You’re in danger: a thing has come to town and is eating everything in its path. We may not be able to stop it.”

In familiar security terms, some of us attempt to instill fear, uncertainty, and doubt (FUD) so that the folks with the cash will give it to us to protect their assets. The trouble is that if we try to solve all problems with FUD, pretty soon the panic will be replaced by complacency. People only have so much roil-ability before our emergencies start becoming old news. This is bad.

I can think of several reasons why we, as information security professionals, still resort to Blobmongering. Here are my top candidates:

* In the world of 24-hour TV and Internet news coupled with increased home computer use, flashy exploits have gotten too much exposure. The enormous volume of information available overwhelms people. Even security professionals can be overwhelmed.

* Unfortunately, some security professionals seem to think that non-security people are too stupid to understand the complexity of the situation(s).

* Some business leaders are not patient enough or simply not willing to discuss technical issues, forcing security leaders to explain issues in overly simple terms.

The first step in correcting the problem is for security folks to recognize that we need to get better at extracting ourselves from the bits and bytes of detail. We need to present the bigger picture without resorting to gross overgeneralization. Our colleagues must understand why they need to pay attention, and we have to present the information they need in as non-Blobish a manner as possible. That means we need to learn to speak human rather than geek if we want to be heard.

Here’s a practical example. Some friends were in the habit of forwarding chain-e-mails and I sent them the following message: “Hey gang – can you please stop copying us on these kinds of group chain e-mails? I don’t like them coming in and bringing their potential viruses with them. They clog up my inbox and could potentially let someone steal my identity. I have no patience for them and I would rather [my child] not get all of them either.”

That message was not in techie-talk and was not Blobmongering, either. I identified a problem and gave some consequences, in simple language (viruses and identity theft). Granted, this message would not have passed muster in a business context, but the basic principle is there.

Turning the corner in this headline society is not going to be easy and it will take us out of the tech-speak comfort zone. But if you can master that art of relaying security problems in practical terms it will help you relay the appropriate sense of urgency to those who need to listen. As a bonus, it will also increase your credibility so that in those extreme cases when you really need to scramble the troops to deal with a real monster, they will be willing to trust you that The Blob really is eating half the town and MUST BE STOPPED.

* * *

Sharon Mudd, MSIA, CISSP, CISA, is an Information Risk Consultant with more than 18 years of information technology and security experience in the financial services, healthcare, telecommunications, and government sectors. She welcomes comments by e-mail