Building A Kevlar Company

Accepting the reality that mistakes will be made,hackers but to be honest does it really matter?
intrusions will occur and that inoculation and list updatesUniversally they are persona non grata no matter
will lag behind any new attack, will guide corporations inwhat intent they have or attack vector they use. What
the establishment of realistic countermeasures whichall companies want is for the problem to go away.
will allow them to survive systemic attacks, avertingCertainly as long as computers are in use, hackers will
the risk of corporate-wide compromise.exist - another undeniable truth. Companies want to
Safe & Secure - For The Moment:keep them out of their revenues, or more specifically
After months of reverse engineering, endless nightsfrom impacting their revenues. Security breaches are
and bad Chinese food, the as-of-yet unknown hackerproduction impacting events (PIEs) that can crush
group, the Internet Free Radicals, has found their newrevenue generation in numerous ways:
attack point. Using steganography, they have devised• Literal loss of revenue based on production
a method of injecting malicious code into any image filedowntime.
which will regenerate and re-inject itself into any• Loss of customer confidence due to bad
network. Using this algorithm, a time-delayed virus ispress.
attached to several "humorous" videos that have been• Erosion of competitive advantage due to
posted for download on the immensely popular socialcompliance failures.
website - By 5am that same morning more thanThe real solution lies in the 95%. Security executives
1,000,000 systems are now infected and the virus islive in fear of the infamous "Sunday afternoon phone
just getting started. The virus, not due to show itselfcall", where the weekend IT staff informs the CSO
for several days, quietly spreads undetected.that over half of the corporation's resources are down
Later that same morning...due to some previously unknown hack.
International Global Finance Corporation (IGFC)A far better scenario that every CSO can live with is
completes updating virus inoculation files on all of theirarriving to work on Monday morning only to find a few
servers and have completely scanned over 20systems that "need attention". This is 95%.
terabytes of financial data on their ATM servers. TheThe best position companies can hope to achieve in
scan has taken four IO intensive hours but finally allfuture security events is one that minimizes the impact
systems are clean and secure. One minute later a thirdof an attack by making it impossible for the mistakes
shift operator at IGFC views a video posted atof a few to cripple the revenue generating capacity of
The Computer Age:the many.
Twenty years after the release of the personalCompanies need to embrace the new tact of
computer, the world is a different place. No one needsinformation survivability by minimizing PIE, production
to point out the prevalence of computers in daily life orimpacting events.
the inherent risk that comes with using them. TheThe global business community has to change
problem is simply this: these very computing systemsexpectations to match the changes brought about by
that we rely upon were not designed with security inthe proliferation and accessibility of computing
mind. With the growth of computing use across everyresources.
segment of business operations, only now arePublic and private sector organizations can create an
corporate information security teams scrambling to findenvironment in which pressure is put back on those
effective systemic security solutions.who would seek to do damage by implementing true
Unfortunately there are five words that are neverbusiness continuity efforts. Nothing is more daunting to
spoken but words whose truth is know by everyonean attacker than to see their "prey" bounce right back
involved in information assurance circles;after a blow.
There is no 100% solution.Attackers will soon turn to other ventures once they
Every Chief Security Officer knows this to be true andrealize their efforts leave their targets unfazed and
every CEO should hear and completely understandnonplussed. From the view of the attackers, this is the
this reality. Ninety-five (95%) percent is the new oneultimate deterrent. From the view of the corporation
hundred percent in the world of information security.this drives customer satisfaction and creates a
This includes all security efforts: trusted computing,strengthened work environment.
data integrity, identity theft, and anti-malware software.The next security event is not an If but a When. What
To view corporate security in any other way is toCEO's and CSO's need to implement are aggressive
deny reality - the proverbial e-ostrich stance.policy, practice and procedural measures coupled with
Three irrefutable facts dictate this reality:solutions that turn a 5000 system event into a five (5)
• Hackers are consumers and purchasesystem non-event.
every version of software usedin business today.The real question that needs to be asked is how a
• There is no way to remove human chaoscompany can become event agnostic not how it can
from the information securityequation.be 100% secure.
• Software development companies cannotWe must acknowledge that the enemy will find a
eliminate the flaws in theircode nor create qualityweakness to exploit but also realize that you can
assurance environments that emulate all ofthemake certain that any intrusion is contained, controlled,
complexities of the global business environment.and ultimately crushed. At every level of a company
So what can be done? Go on the offensive? Notthere must be a new understanding that their will be
likely. Today's attackers are well trained, agile andpot-holes but not sink holes. There is much to be said
virtually invisible making capture almost impossible.for the company that weathers a storm.
These facts coupled with the obvious one thatThe good news is that there are many new
corporations are in the business of conducting businesstechniques being made available that will help a
not tracking downwould-be malcontents serves tocorporation reach the reality of 95%.
heighten the problem. Should UPS concentrate onGreat strides are being made in malware spread
getting packages to their destination on time or turn allmitigation, trusted computing, data portability, and
of their resources towards tracking down hackers?network attached security solutions as well as the
Don't bother to ask UPS, they know their missionconsolidation of effective solution sets. These efforts
statement. It includes boxes not bits.coupled with proper metrics and procedures will allow
That leaves a defensive posture.businesses to obtain an enterprise wide view of their
Ask any General how he or she feels about defensivesecurity efforts thereby allowing them to easily deploy
stances in the theatre of war (and yes, informationnew security techniques and measure their
security is a war). The answer will not be positive oreffectiveness.
reassuring. Somehow, someway the attacker will findIn the end, corporations seeking to create the Kevlar
a means of "getting inside the walls". Unfortunately forCompany need to focus on eliminating production
the global business community this is currently the onlyimpacting events through survivability. Resilience is the
stance possible.ultimate preemptive stance when it comes to
Or is it?information assurance. Only from this 95% posture can
Much has been written about the motivation behindthe goal of 100% assurance ever be achieved.