Hacker and Fed Headaches

Opinion
Jul 28, 20072 mins

Some readers still maintain “hacker” means curious investigator of computers and networks. Sorry, hacker to me always meant criminal, and the definition continues to slide down the scumbag scale. The news about attacks against Instant Message clients being up almost 80 percent just adds to the criminal intent. As e-mail security improves, criminals search for easier marks, and Instant Message security lags way behind e-mail security. Worse, phishing criminals now skulk around various IM networks. If you use those in your business, which I recommend for those selling or offering services to the under-25 age group, warn your users. Phishing training must be on your agenda for all IM users. This is another reason I recommend using a privately hosted IM service for internal communications rather than trusting one of the public services. Let’s sing Happy Birthday to the Sarbanes-Oxley Act which just turned five years old. Like most five year olds, SOX creates more headaches than happiness. But hugging your own five year old feels much better than hugging SOX regulations.

Fun aside, small public companies suffer through SOX and spend too much trying to comply. Although I joke SOX just says “when you’re doing something illegal, keep better notes,” some companies find focusing on financial and business processes helps by pointing out what does and doesn’t work for that company. But if you’re not a public company but a large private one, be prepared for more and more federal regulation. I wonder if any of the security firms have compared the cost of protection against hackers to the cost of interfering federal regulations? My bet says the feds cost most companies more money than the hackers. Any research firm have a study to share?