Embarrassing security secrets

Opinion
Apr 18, 20053 mins

The stupid things big companies do

On the road now with Network World’s Remote Office Networking Technology Tour , I’m meeting representatives from large companies who need help connecting multiple offices. But many of their questions focus on security, and the pain caused by security mistakes doesn’t diminish when your company grows. Before you feel superior to the big guys, however, make sure you and your company don’t make these same mistakes.

One attendee asked how she could educate her boss about security without getting fired. He believes he knows everything, yet demands his password be “password” and changes it back to “password” if the IT department changes it comply with company security policy.

I expected the audience to say, “He’s an idiot,” but most attendees just nodded their heads in agreement.

Can you train a boss like that? Yes, in one of two ways. Try laying out security articles from trade and general-purpose magazines and newspapers in which firms lost money or were embarrassed by security breaches. Factoid: 60% of security breaches come from insiders, not outside hackers (according to one of our Technology Tour sponsors). Banks that lose customer financial records face steep fines and perhaps federal scrutiny. If your boss loses employee health records because of a worthless password, multiple federal privacy protection laws are broken and employees can sue. (Most bosses hate lawyers, so play that up.)

Second, since some executives don’t believe computer information is “real” or tangible, they ignore security. Ask them this: Do you lock your car in the parking lot? Do you have a car alarm? Lock the petty cash drawer? The closet with all the office supplies? The front and back doors of the company? Absolutely.

A worthless password makes it easy for a thief to steal your bank account numbers and your money. Although the money isn’t “real” since it’s just numbers on a bank statement, your boss might believe the money is real and belongs to him. Using a worthless password is no better than laying your cash on the sidewalk and hoping no one takes it.

Another attendee told a story of a billion-dollar company in which the executives set up strict security rules for everyone except themselves.

A big company can get away with that much more easily than a small one. When you know everyone’s name, you tend to know most of their business. An owner or manager who believes security is “something everyone else has to do” won’t be able to hide that attitude.

Worse, a company with an owner who doesn’t care about security will be full of employees who don’t care either. That company will suffer a variety of security problems because barriers against spam, viruses, spyware and phishing schemes will be non-existent or weakly implemented.

It seems the best way to learn the value of security is to ignore it. Let’s hope you and your company don’t need any security lessons.