Remember when CheckPoint were just firewalls, Symantec were just AV, and security companies could just provide consultancy?

Neither do I, it’s been too long.

Security has now become too complex, and too important to play the mix-and-match game with individual vendors, it’s only integrated, multi-function, solutions that will now make the cut.  But there are so few of them out there.  Well, so few that actualy do what they say they do anyway.

As security became a multi-billion £/$/€ a year industry, hundreds of companies started up to bring us the silver bullet appliances that will end our problems forever.  Not only do silver bullets not exist in security – and you should be shot for using the phrase in any way that’s non-derogatory – but where are those companies now?

They either failed, or have been bought up by larger companies who have tried to duct-tape the disparate products into silver-bullet SOLUTIONS.

Which have also failed.

It’s not that the products don’t work, some of them actually do, it’s that;

  1. Businesses threw technology at problems without knowing WHY they were doing it
  2. The big companies that collected the smaller ones tried to integrate the individual products together under one GUI, instead of unifying the functionality under a single code base
  3. There has never been, and there never will be, a one-size-fits-all solution to security

But the market is still ripe for innovation, and there will continue to be companies starting up with the goal of bringing a single product to market that will catch the latest security hype/wave/buzz and make them their fortunes (MDM for example).  They may even succeed, but only if they make their impact in the first year or two, otherwise the market will have moved on.

If they’re VERY lucky, the larger companies that collect little ones will be naive / ignorant enough to buy them and save them the trouble.

I am not against combining single products into a larger solutions, in fact it’s the only way to go, but only if it’s done correctly.  Single product companies have 100% focus, which gives them drive, goals, and a dedication to making their one product the best. The second you absorb that company, every one of those attributed that put them on (or near) the top, is lost in the larger mix.  The functionality is diluted, innovation ceases, and the the whole thing quickly becomes obsolete.

True integration of functionality can only be accomplished with a single code base, and a single platform, which means that any organisation that absorbed the smaller companies better have a plan in mind to migrate not only the applications over to their growing solution, but they will need to consider all of the clients who bought the product prior to the M&A.  These guys often suffer from a total lack of customer service and support, and there’s no way they’ll buy into the larger programme.

From what I have heard, the due diligence necessary to combine product companies is not overly abundant, and until it is, we should all be VERY careful when we look to resolve our security issues with multi-function solutions.

That’s why I call these ‘collage companies’, as the picture might be pretty, but it’s in no way whole.

Here are a few questions you might want to ask your potential providers;

  1. Can your solution replace some / most of my current functionality?
  2. Do you provide a consultancy ‘wrapper’ around these solutions to help us manage them against our business goals?
  3. Will the output from your solution feed into my current collection mechanism, or can my current output feed into yours?
  4. Are the various aspects / functions of your solution ‘home grown’, or obtained through acquisition?  If acquisition, how have you unified the back end code and platforms?
  5. How do you ensure that the different functions of the solution receive a similar attention to what the single product vendors provide?
  6. Do you have a single customer support process to handle all functionality questions?

Regardless of the shenanigans going on in the security product market, your choice of vendor should only be driven by what your risk assessment and gap analysis said you need, and your due diligence should cover any requirements you may have regarding integration and ongoing maintenance.

If is doesn’t, don’t expect the collage companies to help, they have enough problems keeping their own houses in order.

Choose wisely.

Yes …mostly.

Not that the question is even relevant, like it or not, cyber insurance is already here and will only continue to grow.  The number of regulations that reserve the right to levy  fines – some potentially astronomical – is growing to the point that they will feature large on any list of business risks. Or at least they should.

The challenges bringing this to market are numerous, but mostly on the insurance company side.  Security is almost the definition of risk, it’s incredibly diverse, and forever changing and expanding.  And not important enough yet.

With car insurance for example, the more cars you have in the road, the slower everyone has to go, so you actually REDUCE the risk.  What once was a few very costly collisions, is becoming more fender-benders.  So, just up your no-claims bonus and even those claims will reduce.

The more computers and smart phones on the Internet, the more data you have everywhere, and the risks grow almost exponentially.

How do you insure that?  If you don’t know security well, how do you write the policies?  How do you perform appropriate due diligence on a concept that’s new to everyone?  How do you perform PROPER due diligence in the face of stiff competition?

There are policies out there already, but these have been driven by specific regulations (PCI, or HIPAA for example), are aimed mostly at the smaller organisations, and are very much off-the-shelf affairs with limited – in some cases VERY limited – due diligence.  In fact, the pressure is on to make it as simple as possible or you’ll lose the deal; if your insurance company has a 12 page questionnaire, and your competition has only 1 (assuming price and T&Cs are the same), where will the buyers go?

Of course, the competition may end up regretting their stupidity later, but new insurance types are a very rare occurrence, and no-one wants to lose out on a revenue stream.

But what happens when VERY large organisations wish to insure themselves against the potential fines of the General Data Protection Regulation (GDPR), where 2% of global revenue is at stake?  When multi-millions are on the line, a one page questionnaire that asks nothing about security will not suffice.  What does that due diligence look like?

I believe it will run the gamut from some limited external vulnerability scanning in the case of smaller e-commerce, to an onsite audit in the case of a Fortune/FTSE 500.  The better your security, the cheaper your policy.  This may save pennies for smaller organisations, but would be of real significance to the larger ones.

However, I have always compared selling security to selling insurance; no-one wants to spend the money where there’s no positive ROI i.e. MAKING money.  But the ‘negative’ ROI can be just as important, where not LOSING money on fines, forensics, reputational damage, client loss etc can be every bit as meaningful.

Now combine selling insurance FOR security, and you’ve lost almost before you start.  That is of course until the costs of loss far outweigh the costs to insure.

Poor security drives the need for regulation, the regulatory fines will drive the cyber insurance market, which in turn will drive the security market.  Eventually I would hope that organisation understand that they have brought this on themselves by not taking security and privacy seriously. Until they do, the burden of regulatory audit and the associated cost of mitigation will continue to rise in the face of public demand.

Regulation and cyber insurance are just symptoms of poor security, and as I have stressed many times, this is a cultural issue stemming from the senior managements lack of involvement and/or caring;

“Let’s be very clear; The CEO sets the tone for the entire company: its vision, its values, its direction, and its priorities.  If the organisation fails to achieve [goal], its the CEOs fault, and no-one else’s.”

Replace “goal” with “low security overhead”  and the rest is the same.

Sensing a theme here?

The CEO can single-handedly reduce the costs of security, I wonder why so few are paying attention…

Some time ago I gave a presentation on BrightTalk titled ‘Insecurity Through Technology: Back to Basics‘ with the premise that the uncontrolled purchase of security technology to satisfy a perceived need may actually INCREASE your risk (go to Downloads if you just want the presentation).

Despite the crayon-esque diagrams, and the majority focus on PCI, I wanted to expand upon this concept in light of my current focus on simplifying security into “core concepts”, “appropriate / proportional security”, and “business-first”.

PCI lends itself as the perfect example of how a perceived need for technology can result in some very poor purchasing decisions.  Just look through the 12 sections of the PCI DSS and you may, in some form – and if you’re very unlucky – need ALL of the following; firewalls / routers, encryption, anti-virus, web application firewall, access control mechanisms, physical security measures, logging mechanism, vulnerability scanning, penetration testing, wireless scanning, file integrity monitoring, and a ton of ‘paperwork’.

All too often budgets are spent on items such as these at the beginning of a compliance project instead of when, and IF it’s really necessary. A lot goes into a compliance before you should be buying anything other than expert guidance or an education series.

The problem is on both sides of the sales process. The salesperson only knows how to sell either what they are being asked for, or more usually, as much as they possibly can. The purchaser has probably not done their proper due diligence and is asking the wrong questions. The best way to resolve this is if at least one side of the equation is aware of the The 6 Security Core Concepts, and follows the established good practice for the institution of a security program.

Analogy; If your doctor tells you you’re going to require an operation, you will of course learn all you can about the procedure. You may even become something of an authority in your condition (to laymen anyway). What you will NOT do is try to perform the operation yourself. Why would you treat cybersecurity any differently if you’re not an expert?

Know enough to ask the right questions, then let the experts take over. How do I…

  • choose the right technology?
  • ensure it can be integrated with current processes?
  • manage and monitor it?
  • measure it?
  • show the benefit to senior leadership?
  • …and so on…

If new technology is not properly configured, baselined, monitored, and maintained, you have added another potential vulnerability to your infrastructure. Any appliance is just another hardened server running an application of some sort, and should be treated the same way as the ones you build yourself.

Also, the more data you receive the more important baselining and tuning becomes, as you don’t want the important stuff to be obscured under layers of false positives. I do not believe there is room for Big Data analysis in security (per Don’t Get Me Started on ‘Big Data’), so integration of new technology with less-is-more security processes is paramount.

This has been, and will continue to be a theme throughout my blogs; 1) don’t buy anything until you know why you need it, 2) install nothing in production until you have figured out how to use and manage it, and 3) integrate all processes around it with a single overarching operations centre.

The threat landscape is intimidating enough without making things easier for the bad guys.

[If you liked this article, please share! Want more like it, subscribe!]

There is a lot of confusion about how to treat Cloud providers from a vendor due diligence, or compliance assessment perspective.  I’m not sure why, they are just another service provider. The Cloud, in and of itself, adds nothing.

My thoughts on The Cloud are not a secret; Don’t Get Me Started On ‘The Cloud’, but it needn’t be all negative.

So you have – or you want to – outsource/d some aspect of your business function, usually an ancillary part, unless your business is almost entirely white labeled (like in e-commerce for example), and must therefore ensure that the service provider treats your data and/or systems the same way (or better) than you do.

In theory, the only reason you would not be able to measure your service/cloud provider against a defined standard, is if you don’t have one.  You have one, right?  That, by itself, precludes your compliance with ANY standard or accepted good practice.

All too often the real issue is that organisations are trying to outsource their problems (PCI compliance for example), and not focusing on their business needs in general.  While you can outsource almost every business function you can never outsource responsibility.  You can even outsource some of the liability (cyber-insurance for example), but it’s your name that will be dragged through the mud if things go wrong.

It bears repeating; You can NEVER outsource, or in any way deflect, the responsibility for the protection of the data you control.

The way to look at this is to see all 3rd parties / vendors as just a different department of your organisation.  You should have THAT kind of control, and it’s up to you to ensure that they are meeting their commitments.  Service Levels Agreements (SLAs) are a difficult concept, especially for Cloud providers, but that should not your problem, it’s should be theirs.

Here’s a lengthy but good article from IBM on SLAs; Best Practices to Develop SLAs for Cloud Computing

They may have just chosen to jump on the cloud bandwagon, and see this as a way to multiply their client base using the same, or retro-fitted, infrastructure (you need built for purpose).  Calling it a cloud service is, in this case, another phrase for smoke and mirrors.  However, there are some excellent cloud/service providers out there, and you will know them by the way in which they answer, or in some cases entirely pre-empt, your concerns.  They will:

  1. come to you with detail about how they will manage your systems / apps etc, and this will almost certainly support your policies or compliance. Ideally the services will be independently certified as compliant (against PCI for example, and if relevant).
  2. have no problem incorporating your policies or regulatory reporting needs into their service.  They may already exceed yours in this respect if they follow the concept of go-with-what’s-hardest-and-everything-else-is-covered.
  3. have various levels of SLA already defined from which to choose.  Be VERY wary of any cloud / service provider who has no pre-defined SLAs.
  4. have a seamless way for you to measure them against the SLAs.  The old misquoted cliche; You can’t manage what you can’t measure, while irritating, is completely appropriate here.
  5. be able to assist, or train you, to find everything you need during a compliance assessment.  YOU must be able to answer your auditors/assessors questions, you can’t just point at your vendor.

If you don’t have a vendor due diligence program, you need to get one.  If you don’t have a set of defined policies and business need SLAs, get them.  And if you don’t know how to go about any of this, ask someone who does!

Just like in Top 10 Roadblocks to PCI Compliance, not knowing how to do something is not an excuse, there are quite literally hundred of experts who can help you.

Find one.

[If you liked this article, please share! Want more like it, subscribe!]