Perimeter
6/7/2011
04:40 PM
Mike Rothman
Mike Rothman
Commentary
Connect Directly
RSS
E-Mail
50%
50%

The Truth Will Set You Free

We seem to have a problem in the security space: telling the truth, which makes crisis communications a pretty valuable skill moving forward

We have a skill deficiency in the security industry. No, I'm not talking about application security specialists or cloud security jockeys. I'm not even thinking about sys admins or firewall ninjas. Sure, we could always use more of those folks, but I'm talking about crisis communications specialists. If there were one place that most organizations are falling down, it's what happens *after* the breach -- when the house is burning and the clock is ticking.

By the way, it's not just security where we have crisis communications issues. There are all sorts of examples from real life, the most recent being a certain congressman with a proclivity to take photos of soft targets and send them to co-eds via Twitter (talk about a DM fail). Or a home-run hitter who liked certain creams, and not just for their moisturizing benefits. Folks do jail time -- not necessarily for the action, but for the cover-up. Remember Martha Stewart's excellent stock-trading adventure? These folks feel compelled to obfuscate the facts and inevitably realize the act of lying to the authorities, customers, and/or public is far worse than whatever they did in the first place. By then it's too late.

We are seeing more of this in the security space, as well. Our first case is the folks at Sony. They company has been owned and traded more often than a set of Pokemon cards. There are attacker groups fighting over who can compromise more Sony data. I'd say it was kind of comical if it wasn't so sad. Yet Sony still has not come clean about what is happening and why. You see, to err is human. To lie about it is sin. And that's what we as an industry continue to do.

My first Hacked Off column ("RSA Breach Disclosure: It's Not About You") made the case that RSA had no responsibility to tell the general public what was taken and how. I hold to that position. But in the wake of the compromised SecurID intellectual property being used in an attempted breach, it's time to come clean. Fully clean. RSA has made some concessions, offering to replace tokens and/or provide risk-based authentication to address the security issue.

Yet it is missing what Oprah would call a "teaching moment." We have some details about the breach and how it was detected. Now the company has an opportunity to take it to the next step and discuss exactly how to layer defenses so that one control is not a single point of compromise in any environment. If anything, it's in RSA's best interest to do that, given a big part of any solution is full packet capture, which RSA just acquired with NetWitness.

The most critical thing right now for both organizations is to start rebuilding customer trust. Every day these companies dance around the issue of what happened is a day their customers (and potential customers) lose faith in their ability to protect their information. Do I think there will be a run on the bank in either case? Nope -- though I do believe Sony is more at risk since the switching costs are much less in the consumer space, given the number of good alternatives for online gaming.

So when this happens to you (notice I said when, not if), what do you do? Tell the truth. Not a half truth. Not a version of the truth that leaves out details. If there is clear negligence or malicious intent from an insider, own it. If you were had by an innovative attack, or you just suffered from simple human error, face the music. Again, to err is human. Customers can forgive that. To lie about it is a lot harder to get past. Trust customers to make their own risk management decisions, but understand they can't do that without the full story.

To be clear, your legal representation will not appreciate this position. They will push you to say nothing, admit nothing, and accept no liability for anything. That's their job, but they are wrong. The truth will come out at some point, and your organization will pay -- usually a lot less if you are controlling the story and making a reasonable offer to customers to compensate them for whatever was breached. If your proverbial weiner shows up on TMZ.com, it will cost you a lot more in the long run.

Now there is a caveat to this. It's when law enforcement is involved, which I suspect is the case with RSA. I don't know this to be a fact, but it wouldn't surprise me to learn a gag order is in place that forced its hands relative to both the public statements and requiring the NDA for customers. In this case, your hands are tied. Regardless of the risk of alienating customers and becoming a punching bag in the media, you don't want to get on the bad side of law enforcement.

Don't fret if you aren't very good at security. Maybe you have a future in crisis communications. It's not like we should be expecting fewer breaches during the next few years, eh?

Mike Rothman is president of Securosis and author of the Pragmatic CSO

Mike's bold perspectives and irreverent style are invaluable as companies determine effective strategies to grapple with the dynamic security threatscape. Mike specializes in the sexy aspects of security, like protecting networks and endpoints, security management, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5242
Published: 2014-10-21
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.

CVE-2012-5243
Published: 2014-10-21
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

CVE-2012-5702
Published: 2014-10-21
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to i...

CVE-2013-7406
Published: 2014-10-21
SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-4514
Published: 2014-10-21
Cross-site scripting (XSS) vulnerability in includes/api_tenpay/inc.tenpay_notify.php in the Alipay plugin 3.6.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to the getDebugInfo function.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.