Perimeter
6/7/2012
10:57 AM
50%
50%

The Truth Is Not Believable

Too many businesses don’t want to know about their compliance problems

If you are an IT professional, then you’ve likely faced battles to get necessary technical projects approved and funded. Compliance-related projects are frequently even harder to get approved because they may often be seen by management as delayable expenses with little to no return. Times are tough, money is tight, and compliance projects can wait until another day.

If you are a nontechnical business leader, then I think you might admit that all of these tech projects seem like never-ending, expensive magic -- maybe genuinely necessary magic for the business, but magic nonetheless that involves a good deal of uncertainty: Which projects are the most urgent? Are their cost estimates reliable? Oh, and that eternal question: Surely, you can find an adequate answer for less money, right?

At first glance, compliance with rules, regulations, and laws seems cumbersome, especially to newer organizations accustomed to growing quickly in today’s Web-driven economy. Anything that adds time, cost, and distraction is undesirable.

I was in a meeting recently with Carolyn Campbell, an officer for Human Resource Management, and she made a very interesting observation. She said her firm rarely loses compliance projects to another firm, but instead to inaction. Clients simply don’t do anything to address their problems, which begin with refusing to acknowledge the possibility of problems.

In other words, these companies simply keep not doing right whatever they were already not doing right and continue doing wrong whatever they were doing wrong before. In small and midsize businesses, this typically means having the HR duties (and related compliance issues) managed by an unprepared CFO or staff member.

By not hiring Carolyn or someone else who can really help them, these companies intentionally choose to be ignorant of their HR compliance risks, sometimes finding a false confidence in not knowing where the liabilities are and what action they will require. Ignorance apparently remains blissful for some. For these business leaders, as my friend Bill Thomas often says, “The truth is not believable.”

We find exactly the same issue with companies that have technical-related compliance programs. “How we’ve always done it” often trumps proper assessments and resolution action.

There can also be the challenge of, “We know we have issues, but we’ll deal with them when we have more time and money.” Occasionally, organizations follow through on this plan. More often, even when there is more money, there is rarely ever more time. And as a staff develops operational habits, they inherently develop procedural and security issues, then sometimes become a huge obstacle in overcoming these compliance problems.

Too many professionals, both technical and nontechnical, ignore compliance issues. They choose not to believe the truth, sometimes taking care to keep the truth as far away as possible. To seek and engage any truth, including the truth of compliance and security issues, can require painful steps. It takes a kind of courage not every businessperson has.

Glenn S. Phillips, the president of Forte' Incorporated, works with business leaders who want to leverage technology and address often hidden risks within. He is the author of the book Nerd-to-English and you can find him on twitter at @NerdToEnglish.

Glenn works with business leaders who want to leverage technology and understand the often hidden risks awaiting them. The Founder and Sr. Consultant of Forte' Incorporated, Glenn and his team work with business leaders to support growth, increase profits, and address ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-9710
Published: 2015-05-27
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time windo...

CVE-2014-9715
Published: 2015-05-27
include/net/netfilter/nf_conntrack_extend.h in the netfilter subsystem in the Linux kernel before 3.14.5 uses an insufficiently large data type for certain extension data, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via outbound network traffic that trig...

CVE-2015-2666
Published: 2015-05-27
Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing a crafted microcode header and leveraging root privileges for write access to t...

CVE-2015-2830
Published: 2015-05-27
arch/x86/kernel/entry_64.S in the Linux kernel before 3.19.2 does not prevent the TS_COMPAT flag from reaching a user-mode task, which might allow local users to bypass the seccomp or audit protection mechanism via a crafted application that uses the (1) fork or (2) close system call, as demonstrate...

CVE-2015-2922
Published: 2015-05-27
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.

Dark Reading Radio
Listen Now Incident Response War Gaming: Practicing the Post-Breach Panicking
After a serious cybersecurity incident, everyone will be looking to you for answers -- but you’ll never have complete information and you’ll never have enough time. So in those heated moments, when a business is on the brink of collapse, how will you and the rest of the board room executives respond?