enterprisesecuritymag

| | May-June 2017ENTERPRISE SECURITY8 siliconindia | | April 20138 | | November 20158By Bob Fecteau, CIO, SAICHype vs. RealityCyber security is no doubt a significant global challenge, but I question whether we are expecting too much from our IT professionals and if we are giving them proper support. With the public moving toward a zero-fault position, cyber security has become an overwhelming focus for CIOsĀ­ and increasingly for CEOs, CFOs, boards of directors, and shareholders. A view is emerging that protecting a company's data from intrusions, breaches, and viruses falls squarely on the CIO and their team. Nothing could be further from the truth. It is a total team effort that must become part of an organization's DNA. During the recent cyber-attack against the U.S. government's Office of Personnel Management data systems, the public criticized OPM for compromising the data of millions of active and former government, military, and contractor personnel. Critics were quick to point fingers, but failed to recognize the challenges associated with securing this type of data in an increasingly complex digital world.As the House Oversight Committee grilled OPM Director Katherine Archuleta over exactly how many records were compromised (ranging from 14 million to 20 million), the complexity of the challenge was missed. The truth is, it does not matter how many records are compromised. A single record breached is too many and CIOs work diligently every day to ensure data is as secure as possible. The focus should not have been on numbers, but how the breach was dealt with. When security is compromised, CIOs and their teams have to act fast, smart, and decisively with prepared and tested remediation plans that safeguard those affected, ensure a resolution, and protect other areas that could also be vulnerable to the now known threat. Leaders at all levels must know these plans and procedures and be ready to execute them in these situations. Archuleta, who had held her post for 17 months, was not able to do that. Demands for her resignation came quickly, demonstrating how vulnerable leaders are to a cyber-event. Perfect StormUnfortunately, no matter what Katherine did or how much taxpayer money she dedicated to securing OPM data, she may not have been able to prevent the attacks. Anything short of disconnecting the systems from outside networks would not have prevented this attack by a sophisticated adversary. The OPM breach occurred over a period of more than a year before it was discovered. If this attack was state-sponsored, as has been alleged, the chances of initial detection a year ago may not have been possible given the state of sensor technology and signature recognition at the time. In this case, some of OPM's legacy systems are so old that just keeping them patched and operational requires constant and costly attention. The sophistication of today's attacks and the ability of an advanced threat to establish foothold operations in almost any network via web-injected agents, Trojans, advanced malware, tailored phishing events, or attacking insufficient IT practices on aged CIO ... Only Until the Next Data BreachIn my opinion
< Page 7 | Page 9 >