Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

3/6/2012
12:25 PM
50%
50%

5 Steps To Stronger SMB Application Security

How one never-breached, midmarket retailer avoids the too-small-to-be-secure mindset in favor of Fortune 500-grade threat prevention.

9 Startups To Watch In 2012
9 Startups To Watch In 2012
(click image for larger view and for slideshow)
Small and midsize businesses (SMBs) have a litany of excuses at their disposal for spotty security practices, with slim budgets and IT departments leading the list. Those two, in particular, are valid reasons. You can either cave to them, or secure your company's assets anyway.

Bob's Stores chose the latter for its approach to application security. The midsize, regional retail chain employs roughly 650 people; suffice it to say the lion's share of the staff works on something other than application security.

"IT is very light," said Yaron Baitch, director of IT and information security at Bob's Stores. In an interview, Baitch outlined how Bob's Stores ensures top-notch security for both its internal employee and external customer applications, in spite of limited resources.

[ The new Internet protocol is coming--are you ready? See 3 Ways For SMBs To Plug IPv6 Security Holes. ]

He shared a panel on the topic last week at the RSA Security Conference. It's a fairly straightforward recipe grounded in an organizational understanding that the company's bottom-line health is at stake. And it works: Bob's Stores has never had a breach. Baitch half-jokes that acknowledging this fact makes his company a juicier target for hackers. Dark humor aside, that speaks to a basic security mistake many SMBs still make: Thinking no one would bother with their "small" business.

Here's how Bob's Stores sidesteps that myth in favor of secure applications.

1. Security Is A State Of Mind
That basic level of awareness is a must--not just for IT, but for each and every person in the organization, regardless of their job description. This is the step that sounds easy, yet gets bypassed on a regular basis. "Security is everybody's responsibility," Baitch said. That mindset should extend to vendor-built applications, too; Baitch points out that if there's a security breach, your customers will associate it with your brand, not with a backend developer. "Making sure everyone's playing on the same page is critical," Baitch said.

2. Let Your Pain Points Make Your Business Case
Baitch considers it good fortune that his company must adhere to Payment Card Industry (PCI) standards. I'll repeat that: Baitch is glad he has to deal with PCI, even though he doesn't have the compliance budget of much larger retailers that operate under the exact same rules. He's not insane; he's pragmatic. PCI essentially makes Baitch's business case for him when he explains the importance of security to executives and other stakeholders. If your company contends with heavy compliance burdens, use those to prove your security case to the rest of the business. Still, Baitch acknowledges it's not always easy. Negotiation with the business is key--if you aren't so "fortunate" to deal with a regulatory quagmire, come up with a different set of reasons and priorities that non-technical people can understand and buy into.

3. Know Your Strengths And Weaknesses
Don't shy away from your natural limits. You don't have Google's gazillions; you can't spend your way past every business challenge. Boo-hoo: Double-down on your strengths and shine an equal spotlight on the skills that are lacking. Doing so will help you identify where it makes sense to allocate your finite budget. An example: Baitch is "thoroughly impressed" by his small internal development team and credits them with excellent custom-built applications. But ensuring that each line of the code behind those applications is secure isn't necessarily a strong suit. "They don't have the holistic view of security in mind," Baitch said. So Bob's Stores enlists a third party, Veracode, to test its applications for potential security holes.

4. Outsource Your Weaknesses
If Baitch had to start over, one thing he'd do differently would be to embrace outside help earlier. It can run counter to the do-it-yourself ethos common among many SMBs. It can also require letting go of some ego. But outsourcing your skill shortages can turn them into strengths. "Leveraging third-party tools from the beginning would probably be the number one thing I would have changed, as opposed to having a learn-on-the-job type thing for developers," Baitch said.

5. Know Your Endgame
Baitch is quick to point out that no two companies are quite alike. Therefore, there's no set of security goals that can be applied uniformly to every SMB. Define what you need to secure and why--then pursue those goals with gusto. PCI compliance was the headliner for Bob's Stores. Your SMB's list might look entirely different. Having clear goals helps reinforce step one--that organizational mindset that understands there are a real reasons for doing X, Y, and Z, rather than considering those variable practices a waste of time. "The endgame has to have everyone on the same page," Baitch said. "It's your job to implement. How you implement is completely up to you, as long as you meet that end result."

Security concerns give many companies pause as they consider migrating portions of their IT operations to cloud-based services. But you can stay safe in the cloud. In our Cloud Security report, we explain the risks and guide you in setting appropriate cloud security policies, processes, and controls. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Bprince
50%
50%
Bprince,
User Rank: Ninja
3/15/2012 | 1:57:17 AM
re: 5 Steps To Stronger SMB Application Security
Number 4 is good one. Sometimes it can be cost-effective and smart to get some help.
Brian Prince, InformationWeek/Dark Reading Comment Moderator
Commentary
Ransomware Is Not the Problem
Adam Shostack, Consultant, Entrepreneur, Technologist, Game Designer,  6/9/2021
Edge-DRsplash-11-edge-ask-the-experts
How Can I Test the Security of My Home-Office Employees' Routers?
John Bock, Senior Research Scientist,  6/7/2021
News
New Ransomware Group Claiming Connection to REvil Gang Surfaces
Jai Vijayan, Contributing Writer,  6/10/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: This gives a new meaning to blind leading the blind.
Current Issue
The State of Cybersecurity Incident Response
In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-28815
PUBLISHED: 2021-06-16
Insecure storage of sensitive information has been reported to affect QNAP NAS running myQNAPcloud Link. If exploited, this vulnerability allows remote attackers to read sensitive information by accessing the unrestricted storage mechanism. This issue affects: QNAP Systems Inc. myQNAPcloud Link vers...
CVE-2021-3535
PUBLISHED: 2021-06-16
Rapid7 Nexpose is vulnerable to a non-persistent cross-site scripting vulnerability affecting the Security Console's Filtered Asset Search feature. A specific search criterion and operator combination in Filtered Asset Search could have allowed a user to pass code through the provided search field. ...
CVE-2021-32685
PUBLISHED: 2021-06-16
tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the browser (hashing, random, encryption, decryption, signatures, conversions), used by TogaTech.org. In versions prior to 7.0.3, the `verifyWithMessage` method of `tEnvoyNaClSigningKey` always returns `true` for any signature that has a SHA-5...
CVE-2021-32623
PUBLISHED: 2021-06-16
Opencast is a free and open source solution for automated video capture and distribution. Versions of Opencast prior to 9.6 are vulnerable to the billion laughs attack, which allows an attacker to easily execute a (seemingly permanent) denial of service attack, essentially taking down Opencast using...
CVE-2021-32676
PUBLISHED: 2021-06-16
Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate the session cookie after a successful authentication event. It is recommended that the Nextcloud Talk App is upgraded to 9...