There’s something to be said for worrying about the cloud

Opinion
Dec 1, 20033 mins

When he asked what that cloud consisted of, they’d tell him. “Oh, that’s the network. We don’t need to worry about it. It’s always there.” Well, in the attacks of Sept. 11, New York lost 2,250 telecom circuits, knocking out service to companies all around New York. Pelgrin concluded: “We need to worry about the cloud.”

I was recently asked to moderate a panel discussion at the Executive Council of New York on the topic of Security and Business Continuity. One of the keynote speakers was William Pelgrin, director of the New York State Office of Cyber Security & Critical Infrastructure Coordination. Created in response to the Sept. 11 attacks, CSCIC coordinates private and public cybersecurity initiatives in New York, and is actively sharing best practices with the other 49 states.

It’s a great initiative (and I’m not just saying that because I’m a New Yorker). The goal of better securing network infrastructure and services is laudable by itself. But it’s how CSCIC is going about the process that’s unusual: actively recruiting participation by private companies, including key infrastructure and service providers and businesses that are vulnerable to cyberthreats – and then listening to them. (When was the last time government agencies listened to you?)

What motivated me to write this column was a comment that Pelgrin made about the dangers of assuming too much about network infrastructure. In a previous role as a non-technologist heading up the New York state Office for Technology, he often asked his team to explain infrastructure components. Too often, they would draw the network as a series of clouds, with no detail. When he asked what that cloud consisted of, they’d tell him. “Oh, that’s the network. We don’t need to worry about it. It’s always there.”

Well, in the attacks of Sept. 11, New York lost 2,250 telecom circuits, knocking out service to companies all around New York. Pelgrin concluded: “We need to worry about the cloud.”

He’s absolutely right.

But worrying is only helpful if it’s constructive. What can IT executives do to ensure that their critical network infrastructure is protected against attacks? Some recommendations:

•  Get engaged. Companies based in New York can contact CSCIC to find out more about best practices for network security and to learn what their infrastructure providers are up to. As noted, other states are beginning to work with New York to share best practices, so non-New Yorkers should contact the technology departments for their state governments and find out what they’re up to.

•  Invest. A recent Nemertes Research survey uncovered the nerve-wracking fact that virtually all companies are substantially underinvesting in security initiatives. The average investment was 3% of the overall IT budget, well below the best practices of 5% minimum or the 10% that a handful of leading-edge firms are investing.

•  Share your pain. Make sure all your suppliers, including telcos, understand that sharing their security strategies, tactics and practices is a requirement for doing business with you. As noted in previous columns, it’s best to bring this up when they’re likely to listen: during contract negotiations or renegotiations. When there’s money on the table, it’s surprising how well telcos listen.

•  Keep me posted. Please share the challenges and successes of your network security initiatives – a solid body of best practices is the best way to avoid making dangerous mistakes.