In a recent article in SC Magazine; “An Inconvenient Truth: New Customer Data Regulations Coming” Jeremy King of the SSC suggests that Payment Card Industry (PCI) “provides the most complete set of data security standards available globally.” I can only assume he means that the PCI Data Security Standard (DSS) contains a list of basic security controls every organisation should have in place, and not that the PCI DSS in any way resembles real-world security.

Because it doesn’t, and you only have to look at the number of breaches involving ‘PCI compliant’ merchants and service providers to see that PCI, by itself, does little to prepare organisations against the challenges they face.

PCI compliance is a commercial obligation, nothing more, and any fines levied are only paid because the merchant or service provider who was breached wants to keep taking plastic. The Payments Services Directive 2 (PSD2) and the General Data Protection Regulation (GDPR) will be LAW in the 28 countries of the EU, and attract both legal and financial repercussions that could potentially cripple even the largest of businesses. No standard based on a bare minimum set of controls will ever protect personal data in a meaningful way.

Nor will any ISO standard, or COBIT, or any other information security framework for that matter. At least the PCI DSS puts its money where its mouth is and tells you what controls to implement, all security frameworks do is tell you something is a good idea, never how to do it a manner appropriate to your business.

Because they can’t, only the individual organisation can ever provide definition, and business justification, around the horribly inexact – but regulation standard – phrases; ‘appropriate’ and/or ‘reasonable security’.

The implementation of a security program that can meet the intent of ANY regulation includes very specific processes that the PCI DSS does not cover, and if they do, it’s in a very limited fashion with no-where near the emphasis required to express the importance. For example;

  1. The Risk Assessment (RA) is way down in section 12, when it should have been the very first thing performed before PCI compliance was even contemplated. An RA performed in-line with the PCI DSS would not be sufficient.
  2. The only nod to Disaster Recovery and Business Continuity Planning is a single bullet in 12.10.1, when these processes are absolutely central to any organisation staying in business responsibly.
  3. The requirements related to 3rd party due diligence are entirely inadequate relative to the risk involved.

…and so on. I have addressed the inadequacy of the actual PCI controls many times, so I won’t bother repeating them here. Suffice to say, the majority of the controls would be no-where near enough.

There are only 3 main ways to appropriately address the current and new tranche of regulations / directives:

  1. Make the CEO legally responsible for security breaches, and apply criminal penalties in-line with the egregiousness of the negligence – Clearly fines don’t worry CEOs enough, perhaps some jail time would.
  2. Ensure the policies, procedures, and standards are world-class – There is no security program without the application of accurate corporate knowledge
  3. Training & Education – This should be self-explanatory

Compliance with any of the upcoming regulations is no different from any regulation already in place. There is nothing outside of an appropriate security program that will ever be required, so just do the things you should have been doing from the very beginning.

Security is not easy, but it IS simple.

For security professionals, the role of Chief Information Security Officer (CISO) is often seen as the ultimate career objective. The pinnacle job after years of paying your dues in what is still a fairly rarefied industry sector.

And it should be, if that’s what you actually want. I can think of no other position outside of the CEO who should have a better grasp on how a business functions than a CISO doing their job well. In fact, while the CEO has the overarching strategy and direction in their remit, it’s the CISO who knows where the information needed to make the right decisions is.

If you accept that data in context is information, information in context is knowledge, and knowledge correctly applied is what makes organisations successful, then; a) Confidentiality of the base data is critical, b) if the data is safe, Integrity can be more reasonably assured and the resulting information is above all things, accurate, and c) the application of the information must be unhindered, suggesting that Availability of the data is the final piece of the puzzle.

You’ve all heard of C.I.A. in security, right? As far as I’m concerned it’s the CISO who is the guardian of it.

In a perfect world.

Unfortunately, far more prevalent is that the Board decides that a CISO is needed from an appearances perspectives – perhaps due to some regulatory pressures – and the person hired has no real authority, no understanding of the overarching corporate strategy, and probably reports into the CTO or someone equally unsuitable.

It’s a shame really, because a good CISO will have unparalleled input into the following:

  1.  The Security Program – From Risk Assessment all the way to Business Continuity Planning the CISO must be aware of every process related to the security life-cycle of the data under their care. Even the CTO won’t have their fingers in this many pies.
    o
  2. Asset Management – There is nothing in security that can be performed outside of robust and comprehensive asset management. This will be the CISO’s primary focus until it’s where it needs to be.
    o
  3. Mapping of Business Processes – If you don’t know how something works you can neither protect it nor fix it if it breaks. Business processes are the ultimate application of corporate knowledge and the CISO cannot do their job properly until they are all mapped, and preferably optimised.
    o
  4. Success Measurement – As Peter Drucker is so often mis-quoted as saying; “You can’t manage what you can’t measure.” In security, unless the CISO can determine which security controls are working and which are not, appropriate security will be impossible. As will staying within budget.
    o
  5. Regulatory Compliance – I cannot think of one regulatory compliance regime that does not have data at its core, so who better to report compliance status than the person who knows where it all is, and the controls around it?
    o
  6.  Change Control – In theory, if nothing can change on the inside without robust oversight, the only increase in risk to data assets will be from the changes to the external threat landscape. Which segues perfectly to;
    o
  7. Vulnerability Management – With asset management and business processes as their primary focus, who is better placed to feed into the vulnerability management process to help prioritise ongoing remediation efforts?
    o
  8. Business Transformation – In the 2000’s, competitive advantages last weeks, not years. No-one is better placed to help a business transform itself than the person who knows where everything is, and everyONE who manages it.

Prospective CISOs may go into their new job thinking they will get to do all of the above, and the CEO who hires them may think that’s what they’re getting.

Too often neither side asks the right questions, and the CISO role ends up an empty suit.

[If you liked this article, please share! Want more like it, subscribe!]

Easy enough to answer; if there was suddenly a security silver bullet we’d be attacked by hackers who are vampires, zombies, aliens, flesh eating bacteria, and everything else unaffected by silver, just not werewolves. Or maybe werewolves with bullet-proof vests, but I’ve about beaten this analogy to death.

The fact is, and I am probably the 100 millionth person to say it; THERE IS NO SILVER BULLET IN SECURITY! Never has been, and there NEVER will be. So don’t look for it, don’t believe anyone who says they have one (especially vendors) …in fact, don’t even use the phrase unless you’re telling someone else not to use it!

Technology is not the answer …alone. Process is not the answer …alone. Even people are not the answer, although they get the closest. It is a combination of all of these things that provide what every organisation should be looking for in their security program; something appropriate. Appropriate in cost, effectiveness, sustainability, manageability, measurability and every other relevant -ness and -ility out there.

Every organisation only needs security enough to cover the risk to their business. Period / full-stop.

So define appropriate? This is not like asking how long is a piece of string, this is actually very simple. It all falls roughly into 3 categories:

People

This starts with the CEO/BoD as the only foundation that matters. If they don’t care, no-one below them will care, and the organisation will never have the kind of security culture necessary to ever effect appropriate security. They will be breached, and they will deserve it.

But why should the CEO care about security, don’t they have better things to do? Let me answer that with a question; How many businesses are dependant on the correctly applied use of their data assets? Maybe the former CEOs of Target or Equifax have some insight?

Any CEO who has not been through a major breach is not equipped to lead an organisation in the 2000’s, but a CEO who cares about security will surround themselves with people who think securely.

Process

Everything a business does is a process of some sort. Either a good one, a bad one, or likely somewhere in between. Unfortunately, if you don’t write these processes down, you have no way of repeating them consistently enough to actually measure their effectiveness. In other words, your business processes are your corporate knowledge, your competitive advantage, and your ability to change all rolled into one.

Without documentation of your business processes, you have no baseline from which to measure your strengths and weaknesses, no way to develop a competitive advantage BASED on your strengths, or to transform your business in the face of competitive loss.

Technology

Purchase of new technology is the last resort of a security program run well, with adjustments to existing processes and reconfiguration of existing technology taking up the 1. and 2. positions respectively. No purchases should be made outside of a risk assessment, and MUST include all of these things or your kit will likely become yet another paperweight on the IT Director’s desk:

  1. Is the technology appropriate for the current needs, and the needs of the immediate future only? Anything more than that is excessive, and you were likely sold what you asked for, not what you needed:
    o
  2. Who is going to implement it / integrate it? Do you have the skill-set in-house?
    o
  3. Who is going to manage / maintain it? Patches? Upgrades? Base-lining / tuning?
    o
  4. Who is going to monitor it / perform initial incident response? In-house? Managed service?
    o
  5. How are you going to measure it? You’ve made the investment, how do you know if it’s provided a business benefit?

You implement technology to optimise the efficient output of a known business need, you don’t document processes to cover your new technology purchases.

In the end, security is difficult to do well, especially without senior management support, but it is nevertheless EASY to do if, and ONLY if you don’t try and cut corners.

Looking for a silver bullet is the very definition of cutting corners.

[If you liked this article, please share! Want more like it, subscribe!]

Whatever side you are on in the whole privacy debate, you have probably heard variants of the following two arguments:

  1. I don’t care if the Government reads my emails while looking for bad guys, I have nothing to hide, and I feel safer knowing they are doing something; or
    o
  2. There is no evidence that mass digital surveillance has any positive impact on the reduction of crime or terrorism, so my individual right to privacy (UDHR, Article 12) is more important.

Privacy-is-everything advocates will say things like; “Saying you don’t care about the right to privacy because you have nothing to hide, is no different than saying you don’t care about free speech because you have nothing to say.”, or “You can’t give away the rights of a minority, even if you vote as a majority.”

Privacy-as-a-currency advocates will counter with things like; “Saying mass surveillance has no proven benefit is like saying laws are ineffective, you have no idea how many crimes were prevented for fear of being caught.“, or “The minority has no right to impose their will on the majority when personal safety is at stake.

It makes no difference what side you are on, I will not change your mind, and you will not change mine, but we each must pay the same cost for the conveniences and functionality we have come to expect. And accept the responsibility for our choices.

The Internet and now mobile devices have completely changed the way we do business, interact with family and friends, buy stuff, and according to Ian Morris in “The Decline and Fall of Empires”, they will even ‘help’ change our biology;

“As social development rises ever higher, revolutions in genetics, computing, robotics and nanotechnology are beginning to feed back into our biology, transforming what it means to be human.”

Yet we somehow have this expectation that both the Internet and mobile devices are human rights in and of themselves, that we can do whatever we want on them and through them yet still have an expectation for privacy. Governments aside, how can we be so naive?

From my overly simplistic perspective, the world is made up of three kinds of people:

  1. The Good – We don’t have to worry about the good, their lives are spent taking care of whatever it is they care about, which is always in-line with established societal norms / laws, and regardless of the area of influence (i.e. immediate family, community, country, or global);
    o
  2. The Bad – They care nothing for societal norms, they want, so they take. They care nothing for your right to privacy, and outside of instances of gross incompetence, their actions fall almost entirely within your ability to point fingers if you are a victim. IF you can catch them;
    o
  3. The Ordinary – Basically decent, perhaps with a little ‘moral flexibility’ thrown in, who may not like the Bad guys, but understand them enough not to be shocked when they do bad things. These are the majority, and the smarter ones prepare for the worse case scenario.

Laws and rights are written to protect everyone, but not everyone can be protected in the same way. I have contended many times that the more ‘out there’ that’s known about me, the less someone else can pretend to BE me. My life’s story is the equivalent of a public ledger, and any anomalies immediately obvious. This is true for my blogs, my social media, my payment history, and hopefully, even my identity itself.

Of course, there are many people who, quite literally, think I’m 100% wrong, an idiot, or both.

Whatever course YOU choose cannot be seen entirely within the context of your rights, especially ones you are spending every moment you are online.

[If you liked this article, please share! Want more like it, subscribe!]

[Ed. Found this, thought it was well done; Amazing Mind Reader Reveals His ‘Gift’]

The following things have been clear for a while:

  1. The three and four party models represented by the card schemes are in real danger of being disintermediated as mobile technology advances;
  2. The use of plastic will only begin to fade when consumers have a compelling reason to move, mobile payments alone is insufficient;
  3. Retailers are desperate to engage consumers much earlier in the buying process, as well as for a long time after it;
  4. Identity Management and Authentication will take their rightful place in payments and beyond; and
  5. The average consumer has no idea what they want

What has NOT been clear [to me anyway] is what will be the impetus for thing to actually change, and I never thought it would be a regulation.

But that is exactly what is happening here in the EU. Even a cursory examination of the Payment Services Directive 2 (PSD2) makes it clear that the established order is changing. It has already been adopted by the European Parliament, and adoption by the EU Council of Ministers is only a pending formality. Once published, each of the EU countries has just 2 years to write the Directive into their laws.

If you had to distill the PSD2 into its major players, they would be;

  1. Account Servicing Payment Service Provider (ASPSP) – Usually the banks, these guys will need to open up account data once they have received permission to do so from the consumer.
  2. Account Information Service Providers (AISPs) – Aggregators of data received from ASPSPs
  3. Payment Initiation Service Providers (PISPs) – Can initiate a payment, but can only provide a ‘Yes’ or ‘No’ in terms of funds availability.

It’s the AISPs that are truly the new guys on the block. Imagine it; a non-bank Third Party Provider (TPP) can, once properly vetted / ‘licensed’ request all the information from all of your banks / financial institutions and display it to you in a single location! The possibilities to money management alone are enormous, but it’s retail that will be the big winners. Well, some retailers.

The reason that retail and TPPs alike should be dribbling at the thought of this is that these centralised ‘Money Managers’ (MMs) are the perfect location to begin the buying process.

You want to buy a TV, so you open your MM app which has already gone through the effort to combine feeds from all of the following:

  1. Retailers – If retailers do not provide feeds of stock, deals, locations, terms and so on, these will not be presented to the consumer as an option
  2. Ratings & Reviews – Few people realise what goers into those 5 stars you see on Amazon and the like, but you’d be surprised how much influence they have
  3. Your Finances – No point looking if you can’t afford it

Then, once you have gone through a nice friendly wizard to narrow down what you are looking for, your MM goes out and looks for the best deal, AND offers you the best payment terms from all of your lenders. And the WAY you pay? What do you care, the MM has already determined the best way and took care of the detail?!

Those steps may not sound all that radical, but there are two incredibly important facts here:

1) the holder of your money has become far less relevant, so even the banks themselves are losing the Race to the Consumer, and

2) consumers will stop caring HOW they pay in terms of channel, making every other intermediary in the current payment ecosystem irrelevant.

This is what your money is, a stored value, why SHOULD you care if it’s direct debit, standing order, or branded card as long as it’s the best deal for you. It all comes back to you anyway.

[If you liked this article, please share! Want more like it, subscribe!]