There are some things in life that you assume everyone must know by now; give a firm handshake, never accept credit for someone else’s efforts, never be rude to waiters and so on. Yet so many vendors in the information security industry fall foul of an offence far worse than these.

They use phrases like:

  • 100% secure
  • Unbreakable
  • Completely safe
  • Fraud-proof
  • Hack-proof
  • and so on…

The fact remains that NOTHING in information technology is 100% secure. Nothing. If someone wants it badly enough, and they have the necessary skill-set/support, they are going to get it, and anyone who espouses differently should find another line of work before they cause any[more] damage.

And it’s all so unnecessary. You don’t need 100% security even if it was possible, what you need is security ENOUGH. The bad guys are lazy, and if you’re too difficult to breach they will move on, so just ‘build your fence higher than your neighbour’s’ From what I’ve seen in the 15 years I’ve been consulting across the globe, this should not be too difficult.

The calculation you have to make is this;

If the Cost of Security > Value of Data = do what you can afford and no more, OR, if the Cost of Security < Value of Data = do it, but do only what makes sense.

So what process magically gives you the answers to this equation? Easy, the Risk Assessment. One of the most basic tenets of a security program done well, and one of the most under-utilised business tools in every organisation I’ve helped. A risk assessment process performed appropriately will tell you what you’re not doing well, how to fix it, AND how much to spend on doing so.

But I digress.

I can actually empathise with organisations and individuals trying to sell security. It’s tough, but that’s no excuse for lying about your products, and that’s exactly what you’re doing if you claim 100% security. Lying. You have a responsibility to your customers, and whether you like it or not, and whether you ARE or not, you are the usually the expert in the room (if you know 1% more than the other person you are the expert). Your client came to you for help, it’s up to you to provide what they NEED, not necessarily what they asked for.

Your credibility as a provider of information security services or products goes hand-in-hand with your integrity as an organisation and/or individual. Think of your integrity as a form of currency; you can either invest it in your credibility, or spend it on quick wins. Only one of these has a long-term future.

I will note however that if you’re a buyer of security services, you have as much responsibility as the seller to buy only what you need. YOU must ask the right questions, and the only way you can do that is to either do your homework, or hire someone to do it for you. Never expect a salesperson to think twice about giving you what you ask for, then charging you again for providing what you should have asked for in the first place. This scope creep is your fault as much as theirs.

This white paper is not how to sell, I can’t do that, this is how I think you sell with integrity; How to Sell Security

There seems to be quite a bit of confusion about the ‘new’ requirements for service provider contracts. I say ‘new’ sarcastically because this should have been part of your vendor due diligence processes from the beginning.

From a merchant’s perspective, unless they have hired a QSA (or other PCI expert) to help define the service requirements and contractual obligation, it’s very difficult for them to ask the right questions. From a  service providers perspective, I’ve seen the gamut from complete ignorance of their obligations, to out-and-out lies in terms of what they are and are not providing.

The DSS v3.0 requirements of 12.8.X go a long way to resolve this, but not far enough in my opinion. The bottom line is that someone has to be responsible for each requirement, and there are only the following choices;

  1. SP agrees to be fully responsible for the requirement;
  2. SP agrees to be partially responsible, and;
  3. SP pushes the entire requirement back on you.

That’s it.

The above list is fairly obvious, but for the service provider’s clients the challenges are now twofold:

  1. If the service provider accepts full responsibility, are they PCI compliant for the service(s)?
  2. If they are only partially responsible, EXACTLY what part of the requirement is left?

Does the service provider need to be fully PCI compliant for you to achieve compliance? The answer is no, but if they are not, you have just doubled your assessment scope. Again, someone has to answer the questions, so if your service provider has not validated compliance for the services they are offering, you need to add them to your validation efforts.

As for the partial responsibility, that’s easy, get your service provider to tell you what they’re doing. For example;

DSS Req. #

Description

Service Provider Responsibility Client Responsibility
1.1.3

Examine data-flow diagram and interview personnel to verify the diagram:

*  Shows all cardholder data flows across systems and networks.

*  Is kept current and updated as needed upon changes to the environment.

SP will provide initial diagrams in Visio format for the pre-production environment but will not own, manage, or keep up-to-date the data-flow diagrams post-production.

 This requirement is not part of SP PCI Report on Compliance dated [Mmm dd, yyyy]

Client must own, manage, and keep up-to-date all data-flow diagrams for inclusion into their own PCI compliance efforts once services have reached a production state.

You must repeat the above for EVERY requirement in the PCI DSS v3.0, then add this as an addendum or annex to your signed service contract. This applies not only for the services they are providing DIRECTLY, but the SP has a responsibility for any SUB-contractor they may bring in, and so on down the line.

Again, SOMEONE has to answer the questions!

However, let’s back up a bit and handle each DSS Requirement in turn:

12.8.1 Maintain a list of service providers

Easy, just maintain a list of Service Providers, with – at a minimum – the following detail;

  • Company Name
  • Service Description
  • Is [CONFIDENTIAL] Data Shared?
  • Regulatory Compliance Date
  • Status Verified By

12.8.2 Maintain a written agreement that includes an acknowledgement that the service providers are responsible for the security of cardholder data the service providers possess or otherwise store, process or transmit on behalf of the customer, or to the extent that they could impact the security of the customer’s cardholder data environment.

Even easier, they wrote it down for you!! Include – again, at a minimum – the language in red in your contracts. You will likely want significantly more than this as there is no declaration of LIABILITY, or even SLAs.

12.8.3 Ensure there is an established process for engaging service providers including proper due diligence prior to engagement.

If you don’t have robust vendor due diligence and vendor on-boarding/off-boarding processes you are really asking for trouble. For PCI services, if you have not ensured they are PCI compliant for the services they are providing AND you have the full details written into contact, then you have created a world of pain for yourself.

12.8.4 Maintain a program to monitor service providers’ PCI DSS compliance status at least annually.

Does this say anything about the service providers actually working towards PCI compliance? No, it doesn’t, so the status could be; “They will never achieve PCI compliance.” and this is good enough for PCI. This should NEVER be good enough for you.

12.8.5 Maintain information about which PCI DSS requirements are managed by each service provider, and which are managed by the entity.

This we’ve already covered, all you need is a table, like the above, of every PCI requirement handled by each of your service providers and their sub-contractors. Your QSA can then tell you precisely what is left for you to cover for full compliance.

Whether you’re assessing for the first time, or re-assessing under v3.0, you need to start these conversation with your service providers NOW, as while this may be simple, it is not easy.

Advice for Merchants:

  • Only choose PCI compliant service providers (start here; Visa Europe Merchant Agent List)
  • Only choose service providers who have already addressed 12.8.2 and 12.8.5 up-front. You should not have to ask for this from SP worth their salt
  • If you have existing SPs and don’t know where to start, hire a decent consultant who is familiar with the PCI DSS to help

Advice for Service Providers:

  • Get your responsibility mappings and your contract language sorted out now, BEFORE you are asked
  • If you need help, ask for it, ignorance is not an excuse your clients can accept, nor can the card schemes

Easy huh?

Q: What do you do?

A: I’m a consultant.

9 times out of ten the asker of the question enquires no deeper, because they were either just making polite conversation, or they just don’t care. Or both.

The title of ‘consultant’ can hide all manner of sins, as it can be used to enhance the reputation of the unworthy, leading others to believe that their level of expertise goes as deep as the up-front appearances. It is, however, far preferable to ‘expert’, which is bandied around far too often and usually by the very people least equipped to do so.

The old cliche; “An expert is someone who knows 1% more than those around him.” is as true now as it’s always been. And if I’m honest with myself, so is “An expert is just somebody from out of town with slides.”, but that’s a little too close to the mark.

Luckily, you don’t need to be an expert in anything to be a great consultant, you just need to know people who are experts, and when to apply them. For example, there are thousands of people who do every individual thing that I do, and do it many time better, but few can apply their overall knowledge, experience, and skill-set to a client’s maximum long-term benefit.

What are the 4 consultant types?

  1. The ‘Auditor’: Auditors are extremely detail oriented, and can (and do) write massively detailed reports on exactly what you’re doing wrong. While this can be very useful in some scenarios, if you were looking for someone to tell you anything other than what is broken you have the wrong person. There will be little to no out-of-the-box thinking with an auditor, if you aren’t doing exactly what is written, you will fail the test. You will also receive very little in the way of of help actually fixing the problems, so will probably end up paying someone else to finish the piece of work;
    o
  2. The ‘Assessor‘: Assessors are still very tied to the written instructions, but are better able to read the intent of the situation, and are subsequently better able to tell you why a things is not right, as well provide some limited guidance on how to fix it. As with the Auditor, you will likely require additional help to reach your goals, but if you are looking for a sanity check or [cringe] tick-in-the-box compliance with a standard like PCI, then Assessors are a reasonable choice. Mostly because they are cheaper;
    o
  3. The ‘Consultant’: I reserve this title for people who are able to not only explain simply what you are doing wrong, but 1) why it’s wrong, 2) what you should be doing, and 3) provide several options on how to fix what’s wrong. The Consultant’s experience will be such that they have seen close to your specific scenario many times, and can provide all the guidance you need to choose the right solution(s) as well as implement them appropriately. You might be thinking this is the ultimate, but it isn’t, there is a critical aspect missing from the Consultants’ portfolio, which is filled by;
    o
  4. The ‘Teacher’: Teachers approach every gig with a single goal in mind; to never have to repeat anything they do. These rare folks are able to enormously simplify the challenge at hand, and TEACH the client to fix it themselves. And not just once, whatever the solution was, the Teacher will show the client how to maintain the fix, and how to implement a cycle of continual improvement in line with business goals. Above all, the Teacher will help you to always ask the right questions, which is half the battle.

In the PCI space for example, I can count the number of Teachers I have seen on one hand, and even Consultants are thin on the ground. I don’t blame the consulting companies for this, it’s the clients who are continually bitching about price and settling for the lowest bidders.

In consulting, more than in almost any other profession, you get what you pay for, and Consultants/Teachers are always cheaper in the long run.

Also, you will eventually get the type of consultant equivalent to the level of effort you put in finding one. If you end up with an idiot, it’s because you’re lazy.

Don’t know where to start? Ask.

[If you liked this article, please share! Want more like it, subscribe!]

Even now it’s fairly easy for most technology support people to perform their function. They have either extremely deep knowledge in one sector (PC, Mac, iOS, etc.), or are something of a jack-of-all-trades/techs. Much like a handyman is great for most day-to-day repairs, but should never be used to replace your boiler, your electrical system, or your windows.

But what happens when everything is online? Well, almost everything.

When I raise the subject of Internet of Things, I usually get one of three reactions;

  1. The what of who?
  2. That’s awesome, can’t wait!
  3. No thank you.

The first answer is invariably from people who are not technology oriented (majority), the second one from people who ARE technology oriented and usually young, and the third answer from people who are either terrified of technology itself, or who realise that privacy would be a thing of the past.

It’s hard to argue with the latter when you’ve voluntarily put your entire life’s infrastructure online. Like I will.

But who’s going to support all of this? Governments will do their best to regulate this, and they’ll fail; technology providers will attempt to make it simple and safe for the average user, and they will fail; and your PC repair dude will have little idea where to start, but probably charge you for trying.

Luckily the technology behind the Internet of Things is already known to most techies, but they can no longer stay as deep into one technology as they may have done in the past, and probably prefer.  Customers will begin demanding jacks-of-all-techs over specific and individual knowledge-sets, and expect them to be able to fix their smartphone, re-program their dogs’ locator chip, and propose a tasty dinner based on the computer generated contents of their fridge.

The new generation of technology support professionals will need to keep up with innovation as never before, or lose out to those that do; your local PC repair shop will lose to home service; and  we, the consumer, will expect this to be seamless, painless, and cheap.

I even foresee both regulation and certification around providing these services. It’s one thing to support a customer who can’t flush his toilet using his iPhone, it’s quite another supporting a customer who is having issues with her pacemaker, or insulin dispenser.

In the race to profit from this technology explosion, standardisation, interoperability, and ease of maintenance will be ignored, meaning that every new technology you deploy will be stand-alone.  Maintenance complexity does not go up linearly with the number of individual technologies, it goes up exponentially.  Support contracts will be how most of these businesses make their money.

However, to the rescue comes the jack-of-all-techs who will not only help you fix what’s broken, but will be able to help you choose what technology you can go for next given their knowledge of what you have now, and what goal(s) you are trying to active.  Every good support person, consultant, or friend, gives you what you need, and not necessarily what you ask for. Even if they use sentences which end in prepositions.

The only thing holding back total technology adoption are people born before 1990. Most people born after that take the Internet, smartphones, and loss of privacy for granted. Every year that goes by our numbers fall, so the checks and balances between the Internet of Things and an individual’s rights for independence from technology are weakened.

Once again, here comes the jack-of-all-techs! The right tech support professional inherently understands that customer service is the only thing that matters, and you can never provide world class customer service if you don’t have your client’s best interests at heart.

Let the learning begin.

Screen Shot 2013-10-03 at 15.02.42

While this is most likely true in every industry, it is VERY true in cybersecurity.

Most organisations above the ‘corner store’ size have some form of ‘in-house’ IT support, even if it’s just the CEO’s brother-in-law, but only the larger organisation will have dedicated in-house security expertise. It’s simply too expensive.

However, most organisations need security expertise – usually when it’s too late unfortunately – so it’s crucial that they are able to define their specific needs in such a way as to attract the right suppliers of those services. Unfortunately, and all too often, the wrong questions lead to the wrong suppliers who provide the wrong services. If they gave you what you asked for, whose fault is it?

Instead, it makes sense to outsource the choice of your security services to someone best placed to judge; a security expert unhindered by organisational or employment commitments. i.e. they are not employed by a security company and are 100% ‘vendor neutral’ in terms of service or product ‘recommendations’.

Of course, you still have the problem of where to find this person, and ensure that they are the right person to make these choices on your behalf, and the responsibility for this due diligence must begin with the person most accountable. Whether this is the CEO, COO, or IT Manager or whatever, the individual who understands the business goals of the organisation needs to be the one asking the questions.

Many large organisations make the curious choice of allowing their purchasing departments to run the vendor selection process, often without specialist security input beyond the most basic of initial requirement definitions. This leads to an RFP that not only asks all the wrong questions, but also to reviews of the responses by people who don’t understand the answers. The choice is then often based on price and not capability turning the whole thing in a debacle.

You don’t allow your dentist to choose which law firm you use to represent you, why would you have anyone other than a security expert define your security solutions?

Even your in-house security team is under certain limitations, and cannot be truly objective with regard their choices. Whether it be pressure from above, fear of making a mistake, or vendor preference / bias, the choices are rarely the optimal result for the organisation. Nothing nefarious, just human nature.

The development of an overarching security program has many moving parts, and every step must be with a view to the end goals, the current needs (risk priorities), and the bit that’s often neglected; how each piece integrates with the next. The purchase of security services, and especial products/technology must be based on not only cost, but of how it will be installed, maintained, managed, monitored, and measured.

This can only be performed by a Governance function that has access to, and guidance from, a true security expert.

I can’t say that I’ve come across a service like this, perhaps I’ll start my own…

[If you liked this article, please share! Want more like it, subscribe!]