We all know how helpful it can be to discuss a problem with someone. Be it through support networks, industry associations, group therapy, whatever, burdens often become lighter when we share them with others who can offer advice, information, or even just an ear.
Yet when it comes to cybercrime, a problem that’s bound to get worse before it gets better, companies clam up. As detailed in the first story (“The story behind the stats“) in our “Profiling Cybercrime” special section, few companies report cybercrime to law-enforcement officials. It’s understandable why companies don’t issue press releases that scream “Network infiltrated, thousands of consumers’ credit card information revealed!” We all know that can lead to fleeing customers, crashing stock prices, maybe even dismissals.
Yet according to law-enforcement officials, including the FBI’s Computer Intrusion Section chief, (see “Serious business“), there’s little hope of cracking down on these criminals without more information about them. Unfortunately it’s up to the victims to stick their necks out and come forward, much like Authorize.net did with its recent distributed denial-of-service attack as told in the story “Victim’s rights“.
But there’s another way to help stem cybercrime: Talk among yourselves. If companies begin sharing information with others in their industry about cybercrime attacks, they might be able to help prevent future attacks. By sharing information, patterns can be detected so that networks can be reinforced accordingly and criminals lose the element of surprise. Companies could share ideas about security technology, procedures and policies that work, and more importantly ones that don’t.
The formation of tightly knit, trusted groups that share cybercrime and security information in a variety of industries also could help law-enforcement officials in their quest to profile perpetrators, assuming a communications mechanism could be established to feed authorities information about attacks without revealing the victims.
Maybe this is something you do already; you bump into a competitor at an industry event and commiserate about the stresses of your job. Or maybe the idea of sharing sensitive information about your network’s vulnerability with a rival sounds like heresy.
But history shows industries that share information about common threats often benefit from it. It has worked for the banking industry, for ISPs, and it can work for you, too.




