Protect you computer and your data


Building A Kevlar Company

Accepting the reality that mistakes will be
made, intrusions will occur and thatOr  is  it?
inoculation and list updates will lag behind
any new attack, will guide corporations inMuch has been written about the motivation
the establishment of realisticbehind hackers but to be honest does it
countermeasures which will allow them toreally matter? Universally they are persona
survive systemic attacks, averting the risknon grata no matter what intent they have or
of  corporate-wide  compromise.attack vector they use. What all companies
want  is  for  the  problem  to  go  away.
Safe  &  Secure  -  For  The  Moment:
Certainly as long as computers are in use,
After months of reverse engineering, endlesshackers will exist - another undeniable
nights and bad Chinese food, the as-of-yettruth. Companies want to keep them out of
unknown hacker group, the Internet Freetheir revenues, or more specifically from
Radicals, has found their new attack point.impacting their revenues. Security breaches
Using steganography, they have devised aare production impacting events (PIEs) that
method of injecting malicious code into anycan crush revenue generation in numerous
image file which will regenerate andways:
re-inject itself into any network. Using
this algorithm, a time-delayed virus is• Literal loss of revenue based on
attached to several "humorous" videos thatproduction  downtime.
have been posted for download on the
immensely popular social website - By 5am• Loss of customer confidence due to
that same morning more than 1,000,000 systemsbad  press.
are now infected and the virus is just
getting started. The virus, not due to show• Erosion of competitive advantage due
itself for several days, quietly spreadsto  compliance  failures.
undetected.
The real solution lies in the 95%. Security
Later  that  same  morning...executives live in fear of the infamous
"Sunday afternoon phone call", where the
International Global Finance Corporationweekend IT staff informs the CSO that over
(IGFC) completes updating virus inoculationhalf of the corporation's resources are down
files on all of their servers and havedue  to  some  previously  unknown  hack.
completely scanned over 20 terabytes of
financial data on their ATM servers. The scanA far better scenario that every CSO can live
has taken four IO intensive hours but finallywith is arriving to work on Monday morning
all systems are clean and secure. One minuteonly to find a few systems that "need
later a third shift operator at IGFC views aattention". This  is  95%.
video  posted  at
The best position companies can hope to
The  Computer  Age:achieve in future security events is one that
minimizes the impact of an attack by making
Twenty years after the release of theit impossible for the mistakes of a few to
personal computer, the world is a differentcripple the revenue generating capacity of
place. No one needs to point out thethe  many.
prevalence of computers in daily life or the
inherent risk that comes with using them.Companies need to embrace the new tact of
The problem is simply this: these veryinformation survivability by minimizing PIE,
computing systems that we rely upon were notproduction  impacting  events.
designed with security in mind. With the
growth of computing use across every segmentThe global business community has to change
of business operations, only now areexpectations to match the changes brought
corporate information security teamsabout by the proliferation and accessibility
scrambling to find effective systemicof  computing  resources.
security  solutions.
Public and private sector organizations can
Unfortunately there are five words that arecreate an environment in which pressure is
never spoken but words whose truth is know byput back on those who would seek to do damage
everyone involved in information assuranceby implementing true business continuity
circles;efforts. Nothing is more daunting to an
attacker than to see their "prey" bounce
There  is  no  100%  solution.right  back  after  a  blow.
Every Chief Security Officer knows this to beAttackers will soon turn to other ventures
true and every CEO should hear and completelyonce they realize their efforts leave their
understand this reality. Ninety-five (95%)targets unfazed and nonplussed. From the
percent is the new one hundred percent in theview of the attackers, this is the ultimate
world of information security. This includesdeterrent. From the view of the corporation
all security efforts: trusted computing, datathis drives customer satisfaction and creates
integrity, identity theft, and anti-malwarea  strengthened  work  environment.
software. To view corporate security in any
other way is to deny reality - the proverbialThe next security event is not an If but a
e-ostrich  stance.When. What CEO's and CSO's need to implement
are aggressive policy, practice and
Three irrefutable facts dictate this reality:procedural measures coupled with solutions
that turn a 5000 system event into a five (5)
• Hackers are consumers and purchasesystem  non-event.
every version of software usedin business
today.The real question that needs to be asked is
how a company can become event agnostic not
• There is no way to remove human chaoshow  it  can  be  100%  secure.
from  the  information  securityequation.
We must acknowledge that the enemy will find
• Software development companies cannota weakness to exploit but also realize that
eliminate the flaws in theircode nor createyou can make certain that any intrusion is
quality assurance environments that emulatecontained, controlled, and ultimately
all ofthe complexities of the global businesscrushed. At every level of a company there
environment.must be a new understanding that their will
be pot-holes but not sink holes. There is
So what can be done? Go on the offensive?much to be said for the company that weathers
Not likely. Today's attackers are wella  storm.
trained, agile and virtually invisible making
capture  almost  impossible.The good news is that there are many new
techniques being made available that will
These facts coupled with the obvious one thathelp  a corporation reach the reality of 95%.
corporations are in the business of
conducting business not tracking downwould-beGreat strides are being made in malware
malcontents serves to heighten the problem.spread mitigation, trusted computing, data
Should UPS concentrate on getting packages toportability, and network attached security
their destination on time or turn all ofsolutions as well as the consolidation of
their resources towards tracking downeffective solution sets. These efforts
hackers? Don't bother to ask UPS, they knowcoupled with proper metrics and procedures
their mission statement. It includes boxeswill allow businesses to obtain an enterprise
not  bits.wide view of their security efforts thereby
allowing them to easily deploy new security
That  leaves  a  defensive  posture.techniques  and  measure their effectiveness.
Ask any General how he or she feels aboutIn the end, corporations seeking to create
defensive stances in the theatre of war (andthe Kevlar Company need to focus on
yes, information security is a war). Theeliminating production impacting events
answer will not be positive or reassuring.through survivability. Resilience is the
Somehow, someway the attacker will find aultimate preemptive stance when it comes to
means of "getting inside the walls".information assurance. Only from this 95%
Unfortunately for the global businessposture can the goal of 100% assurance ever
community this is currently the only stancebe achieved.
possible.



1 A B C 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 96 97 98 99 100 101 102 103 104 105