Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

6/7/2011
04:40 PM
Mike Rothman
Mike Rothman
Commentary
50%
50%

The Truth Will Set You Free

We seem to have a problem in the security space: telling the truth, which makes crisis communications a pretty valuable skill moving forward

We have a skill deficiency in the security industry. No, I'm not talking about application security specialists or cloud security jockeys. I'm not even thinking about sys admins or firewall ninjas. Sure, we could always use more of those folks, but I'm talking about crisis communications specialists. If there were one place that most organizations are falling down, it's what happens *after* the breach -- when the house is burning and the clock is ticking.

By the way, it's not just security where we have crisis communications issues. There are all sorts of examples from real life, the most recent being a certain congressman with a proclivity to take photos of soft targets and send them to co-eds via Twitter (talk about a DM fail). Or a home-run hitter who liked certain creams, and not just for their moisturizing benefits. Folks do jail time -- not necessarily for the action, but for the cover-up. Remember Martha Stewart's excellent stock-trading adventure? These folks feel compelled to obfuscate the facts and inevitably realize the act of lying to the authorities, customers, and/or public is far worse than whatever they did in the first place. By then it's too late.

We are seeing more of this in the security space, as well. Our first case is the folks at Sony. They company has been owned and traded more often than a set of Pokemon cards. There are attacker groups fighting over who can compromise more Sony data. I'd say it was kind of comical if it wasn't so sad. Yet Sony still has not come clean about what is happening and why. You see, to err is human. To lie about it is sin. And that's what we as an industry continue to do.

My first Hacked Off column ("RSA Breach Disclosure: It's Not About You") made the case that RSA had no responsibility to tell the general public what was taken and how. I hold to that position. But in the wake of the compromised SecurID intellectual property being used in an attempted breach, it's time to come clean. Fully clean. RSA has made some concessions, offering to replace tokens and/or provide risk-based authentication to address the security issue.

Yet it is missing what Oprah would call a "teaching moment." We have some details about the breach and how it was detected. Now the company has an opportunity to take it to the next step and discuss exactly how to layer defenses so that one control is not a single point of compromise in any environment. If anything, it's in RSA's best interest to do that, given a big part of any solution is full packet capture, which RSA just acquired with NetWitness.

The most critical thing right now for both organizations is to start rebuilding customer trust. Every day these companies dance around the issue of what happened is a day their customers (and potential customers) lose faith in their ability to protect their information. Do I think there will be a run on the bank in either case? Nope -- though I do believe Sony is more at risk since the switching costs are much less in the consumer space, given the number of good alternatives for online gaming.

So when this happens to you (notice I said when, not if), what do you do? Tell the truth. Not a half truth. Not a version of the truth that leaves out details. If there is clear negligence or malicious intent from an insider, own it. If you were had by an innovative attack, or you just suffered from simple human error, face the music. Again, to err is human. Customers can forgive that. To lie about it is a lot harder to get past. Trust customers to make their own risk management decisions, but understand they can't do that without the full story.

To be clear, your legal representation will not appreciate this position. They will push you to say nothing, admit nothing, and accept no liability for anything. That's their job, but they are wrong. The truth will come out at some point, and your organization will pay -- usually a lot less if you are controlling the story and making a reasonable offer to customers to compensate them for whatever was breached. If your proverbial weiner shows up on TMZ.com, it will cost you a lot more in the long run.

Now there is a caveat to this. It's when law enforcement is involved, which I suspect is the case with RSA. I don't know this to be a fact, but it wouldn't surprise me to learn a gag order is in place that forced its hands relative to both the public statements and requiring the NDA for customers. In this case, your hands are tied. Regardless of the risk of alienating customers and becoming a punching bag in the media, you don't want to get on the bad side of law enforcement.

Don't fret if you aren't very good at security. Maybe you have a future in crisis communications. It's not like we should be expecting fewer breaches during the next few years, eh?

Mike Rothman is president of Securosis and author of the Pragmatic CSO

Mike's bold perspectives and irreverent style are invaluable as companies determine effective strategies to grapple with the dynamic security threatscape. Mike specializes in the sexy aspects of security, like protecting networks and endpoints, security management, and ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/13/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-20907
PUBLISHED: 2020-07-13
In Lib/tarfile.py in Python through 3.8.3, an attacker is able to craft a TAR archive leading to an infinite loop when opened by tarfile.open, because _proc_pax lacks header validation.
CVE-2020-14174
PUBLISHED: 2020-07-13
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to view titles of a private project via an Insecure Direct Object References (IDOR) vulnerability in the Administration Permission Helper. The affected versions are before version 7.13.6, from version 8.0.0 before 8.5....
CVE-2019-20901
PUBLISHED: 2020-07-13
The login.jsp resource in Jira before version 8.5.2, and from version 8.6.0 before version 8.6.1 allows remote attackers to redirect users to a different website which they may use as part of performing a phishing attack via an open redirect in the os_destination parameter.
CVE-2019-20898
PUBLISHED: 2020-07-13
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to access sensitive information without being authenticated in the Global permissions screen. The affected versions are before version 8.8.0.
CVE-2019-20899
PUBLISHED: 2020-07-13
The Gadget API in Atlassian Jira Server and Data Center in affected versions allows remote attackers to make Jira unresponsive via repeated requests to a certain endpoint in the Gadget API. The affected versions are before version 8.5.4, and from version 8.6.0 before 8.6.1.