In the wake of LulzSec, Anonymous, AntiSec, botnets, phishing and malware, etc., etc., etc. I’m really feeling that the system has let everyone down.
I don’t mean I need someone to make the playground a safe place to be in. I’m the first to acknowledge that I am responsible for my computer and browsing habits.
I mean that I expect companies, agencies, corporations and IT professionals to take things seriously. They need to protect what we trust them with.
Instead, we get a “disclaimer”, which absolves everyone from the software writer to the CEO, company, agency, etc. and leaves you without recourse.
Well, that’s not good enough when some criminal makes off with your life’s savings and identity.
You might be taking every step you can or can afford to take and be completely responsible, yet at some point you’re dependent on others to do their jobs.
I’m saying this is not an “Act of G-d” which no one could anticipate and prepare for. IT professionals can, do and are capable of making tremendous contributions to Information Security. They do more than fix computers and keep networks up and running.
More: They deserve respect. Their jobs require CEO’s and others (co-workers) to take them seriously. I don’t think they receive it, and I don’t see the attitude “I can’t be bothered to understand, know, do and be responsible for security” as being helpful or useful. Further: Everyone in a company, agency or corporation is responsible for keeping security policy.
So what’s the answer? How do we get out of this mess? I don’t say there is one, and I don’t claim we can. I do say we can try a lot harder.
I’ve just read in PCWorld that 90% of companies in a recent survey say they’ve been hacked. Worse, 50% said they’d been hacked twice or more.
That’s insane!
I believe someone has to establish, set and require the standard. I also believe that's part of the IT professional's job. Also, nothing less should be accepted nor required for those who decide to require sensitive numbers and data from others. You see, there’s an ethical and moral responsibility (as well as legal) which no “Disclaimer” should be allowed to invalidate except in the case where the company, corporation or agency has met or exceeded the required standard.
I believe in the IT people. They should be able to do their work and be heeded.
There also need to be really significant “deterrents” for criminals.
No claims of the victim causing it should be tolerated. If there is negligence, there’s liability. Yes, liability.
It’s laughable, but liability attorneys might be the very solution we need. That’s because said agencies, etc. have one thing in common: Enlightened self interest.
They don’t want to have to explain to the shareholders why they screwed up and lost them money. Sony and dropbox are finding out about that now. There are suits in progress.
Also, it can be made abundantly clear by serious CEO’s that either you learn and do correctly or you’re gone.
Sources:
http://www.juniper.net/us/en/local/pdf/additional-resources/ponemon-perceptions-network-security.pdf
http://www.pcworld.com/article/230937/survey_90_of_companies_say_theyve_been_hacked.html
http://arstechnica.com/tech-policy/news/2011/07/will-your-employer-get-sued-for-your-security-screw-ups.ars