Perimeter
12/5/2011
10:32 AM
Mike Rothman
Mike Rothman
Commentary
Connect Directly
RSS
E-Mail
50%
50%

Work And Play In Security

As we look toward 2012, it's time to have more fun at work

Security folks tend to be a pretty grumpy lot. The reasons behind that are pretty obvious, since many practitioners get marginalized because security doesn't really contribute to either the top or bottom lines of an organization. I mean, a breach can impact both, but there is no assurance of a breach or any assurance that investment will prevent a breach. So the entire security house of cards is based on the fact that investments are made to stop something that might or might not happen. And we wonder why the clear impact of a compliance fine drives so much investment is security controls nowadays?

It doesn't help that there is no real "win" for a security practitioner. Today the attackers might not achieve their objectives, but there is always tomorrow. What about doing some kind of security awareness? Yeah, most think that's futile as well. Most folks think of security as a burden and behave accordingly. Looking ahead toward 2012, I'm done with predicting. Yeah, things will be worse. Or not. We'll get more budget. Or not. We'll be breached. Or ... OK, that will happen. Given that my crystal ball is not retired, let's think a bit more tangibly. We need to have more fun in 2012.

You know the old saying, "All work and no play makes Jack a dull boy." Guess what? You're Jack. We all are. That's the nature of the job. But that doesn't mean we can't be more active about making our day-to-day existence a little less miserable. Then I read this post on the New School blog positing :The Future of Work is Play." It makes perfect sense. But how does that apply to security, where "play" isn't usually a word you'd associate with the discipline? I can think of a few ways off of the top of my head:

1. Awareness Games: Nobody like security-awareness training. Most folks tune out within the first five to ten minutes, but they check the box and then proceed to get owned at every turn. What if we turned the security awareness into a game? Try a scavenger hunt with prizes for folks who can detect which emails are phishing, or those who don't click on a bad link. OK, it's not Gears of War, but it's not like you can make awareness training less effective. So try to have some fun with it.

2. Friendly Competitions: Most of you have trouble getting developers to code securely. Why not try a contest? Any developer who has no code flagged for security issues each month gets a night out on the town, courtesy of the security team. Or provide a bounty for out-of-the-box thinking during a threat-modeling exercise. Given what it costs you to clean up the mess when crappy, insecure code gets shipped, this would be a good investment.

3. Capture The Flag: You need to be doing incident-response exercises anyway, and we have always been fans of pen tests to keep your folks on their toes. Why not organize a capture the flag exercise on your own networks? OK, there would need to be some rules of engagement (like not taking down the website), but offer up some prizes and create some competition. Folks love competition, and they also like being able to give their teammates a hard time. As long as the razzing is all in good fun, this can again be a cheap way to keep folks engaged.

I'm sure there are a ton of other ideas to add a little more play to our jobs in security. It probably can't get less fun, so what do you have to lose? And you get to watch the reaction of your significant other when you tell him or her you played games all day at work. Sounds like a great idea to me. Happy holidays, y'all, and I'm looking forward to Hacking Off some more in 2012.

Mike Rothman is President of Securosis and author of the Pragmatic CSO. Mike's bold perspectives and irreverent style are invaluable as companies determine effective strategies to grapple with the dynamic security threatscape. Mike specializes in the sexy aspects of security, like protecting networks and endpoints, security management, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4448
Published: 2014-10-22
House Arrest in Apple iOS before 8.1 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information from a Documents directory by obtaining this UID.

CVE-2014-4449
Published: 2014-10-22
iCloud Data Access in Apple iOS before 8.1 does not verify X.509 certificates from TLS servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVE-2014-4450
Published: 2014-10-22
The QuickType feature in the Keyboards subsystem in Apple iOS before 8.1 collects typing-prediction data from fields with an off autocomplete attribute, which makes it easier for attackers to discover credentials by reading credential values within unintended DOM input elements.

CVE-2012-5242
Published: 2014-10-21
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.

CVE-2012-5243
Published: 2014-10-21
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.