Contributor

It’s over. No more hacking of retailers.

Opinion
Aug 7, 20082 mins

has indicted the 11 individuals responsible for all of this century’s hacks of retailers such as TJX companies, BJ’s Wholesale Club, OfficeMax, Boston Market, Barnes & Noble, Sports Authority, forever 21 and DFW Inc. (well, maybe not all but that is a partial list).

We can all breathe a sigh of relief, especially any retailer that was holding off on investments in IT security. Their gamble has paid off. The US Secret Service

Seriously though, you have to admit that is surprising that so many of these attacks were carried out by one group of linked individuals. The original thinking of many, including myself, was that the retailers were lax, there was an open market for credit cards, and hackers were having a heyday. Now it turns out that a small band of cyber thieves allegedly following the lead of a Secret Service informant (I know it is bizarre, I can’t make this stuff up) just repeated their early success with one retailer to attack any other vulnerable retailer.

Lessons learned?

  1. Talk to and listen to your peers within your own industry. If one of them says “hey we were attacked through an open WiFi hotspot” think about securing your own infrastructure.
  2. Listen to advisors. I am not the only one who has been warning you to get secure.
  3. Law enforcement works.

This last point is important. Ultimately, the only way to impact the rise of cybercrime is to catch the criminals and punish them. Just don’t let this astounding coup on the part of the Secret Service be an excuse for more delays in securing your network.

Richard Stiennon is chief research analyst at IT-Harvest, the firm he founded in 2005 to cover the 1,600 vendors that make up the IT security industry. He is the author of Surviving Cyberwar (Government Institutes, 2010) and There Will Be Cyberwar: How the Move to Network-Centric Warfighting Set the Stage for Cyberwar. He is a member of the advisory board at the Information Governance Initiative and principal of TrueBit Cyber Partners. He also serves on the R2-TAC, the technical advisory committee for the Responsible Recycling standard for e-waste.

Stiennon was chief marketing officer for Fortinet Inc. and vice president of threat research at Webroot Software. Prior to that, he was vice president of research at Gartner Inc. He has a B.S. in aerospace engineering and an M.A. in war in the modern world from King’s College, London.

The opinions expressed in this blog are those of Richard Stiennon and do not necessarily represent those of IDG Communications Inc. or its parent, subsidiary or affiliated companies.

More from this author