Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

7/8/2011
01:58 PM
Rob Enderle
Rob Enderle
Commentary
50%
50%

Murdoch Kills 'News of the World': The Coming Security Backlash

News Corp. scandal demonstrates massive shift in how privacy is perceived

It was interesting to watch News Corpo.’s response to the voicemail hacking allegations -- this practice had been going on for years. It appeared to be a current event with enough magnitude to kill one of the publishing firm's most successful businesses.

What happened wasn’t that the crime changed, but that people’s perception of the crime changed, and what was allowed suddenly wasn’t. The environment continues to be very hostile to companies that violate privacy, and companies like Google and Facebook that trade in personal information are at risk. They aren’t the only ones: We can see the problems Sony is having and the fact this could drift to anyone (like the carriers who controlled the voice mail systems) who gets breached.

Voicemail is normally provided by a carrier, but it could be provided by a company or a government. In either case, a breach that exposed a protected person (civil servant or soldier who died on duty, suicide victim, child, disabled person, elderly person, etc.) could result in a backlash not just against the attacker, but against the organization that didn’t adequately secure the service.

Given News Corp.’s reach and business, and the need for it to switch the focus off of it, the likely target would be the service providers who were breached, and News Corp. has the reach and resources to pull off this change.

But even if it doesn’t, anyone who provided a service that is seen as inadequately secure is at risk, and the real problem is that the bar for “inadequate” is dropping like a rock. What seemed acceptable last week no longer seems acceptable today, and one big public breach could result in a massive backlash. You could actually be more secure than a competitor, but if it is your company that gets hit, it is your company that could be in front of a Senate committee or on the wrong side of a class action suit like Sony.

Clearly, part of this is making sure security of personal information is at an acceptable level of risk by balancing the likely chance you’ll have an event like this with the level of effort you are making to secure the critical personal information.

This suggests having in place response plans for when the event occurs that immediately focuses on going after the attackers who penetrated the company. It would also message out the firm or entity as a victim and can articulate what has been done to secure the information as reasonable.

This is all about managing perceptions, and I think News Corp. got this wrong. The firm should have fired and filed criminal charges against the employees who committed the acts against protected people, but defended those that went after public figures under freedom of press rules.

The effort should have been to make this look like a few people didn’t understand that those who are aren’t public figures are off-limits. Shutting down the entire paper makes them look guilty. The response makes this actually appear more like a cover-up, where they are attempting to burn the evidence, and it isn’t playing out well -- likely because News Corp. didn’t have in place a contingency play for an investigation method blowing up on them.

What we often forget about security is that a good portion of the effort is about managing perceptions. If people feel secure, then they think you are doing a good job. If they don’t, then you aren’t, and often there is little relation to how secure they are to how secure they feel.

Given the rapid proliferation of breaches, plans to deal with the media aspect of the breach and to focus anger on the attacking -- rather than the defending -- organizations would be wise for those of us on the defense side.

Rob Enderle is is president and founder of The Enderle Group. Special to Dark Reading

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
News
US Formally Attributes SolarWinds Attack to Russian Intelligence Agency
Jai Vijayan, Contributing Writer,  4/15/2021
News
Dependency Problems Increase for Open Source Components
Robert Lemos, Contributing Writer,  4/14/2021
News
FBI Operation Remotely Removes Web Shells From Exchange Servers
Kelly Sheridan, Staff Editor, Dark Reading,  4/14/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: "Elon, I think our cover's been blown."
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-2296
PUBLISHED: 2021-04-22
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromi...
CVE-2021-2297
PUBLISHED: 2021-04-22
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromi...
CVE-2021-2298
PUBLISHED: 2021-04-22
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attac...
CVE-2021-2299
PUBLISHED: 2021-04-22
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful atta...
CVE-2021-2300
PUBLISHED: 2021-04-22
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of...