Showing posts with label Cyber Security Program. Show all posts
Showing posts with label Cyber Security Program. Show all posts

Sunday, March 1, 2009

Significant, targeted attacks even against ISPs?
-Absolutely! (just ask Time Warner)

One might think that larger financial institutions and other entities with directly exploitable financial or personal information remain the major nexus of criminal cyber problems. However, even consumer grade ISPs are increasing facing challenges. Time Warner's drawn out efforts now in the limelight represent just the latest example of an organization scrambling to address service and reputation impacts from a disrupting cyber security attack.

  • February 28, 2009

    During the past week, hackers have launched a series of attacks on Time Warner Cable's servers. Time Warner Cable is working with law enforcement agencies to resolve these crimes.

    As a result of these attacks, you may have experienced a temporary "outage" when attempting to surf the Web, including an intermittent "page cannot be displayed" error message. The outages did not result in services being 100% unavailable; and were limited to sporadic timeouts which appeared to be random events. Some users may have experienced a total disconnect, however. These types of attacks are not uncommon, especially for a network as large as ours. We suspect that the attackers are using "zombie computers," or hijacking unsuspecting subscribers' machines to perpetrate the attack without its owner's knowledge.

    All of us at TWC take these attacks extremely seriously. As previously mentioned, we are working with the appropriate law enforcement agencies that specialize in investigating these types of crimes. We will pursue prosecution of all perpetrators to the fullest extent of the law. We apologize for the inconvenience that these attacks may have caused and encourage you to report any suspicious activity. Instructions for reporting security abuse are located at
    http://help.rr.com.

    Sincerely,
    Time Warner Cable


    More: Google News Search: Time Warner Attack

The persistent assault centers on impacting Time Warner’s domain naming system (DNS) services. Given that DNS supports domain name to Internet address resolution functions, e.g., when Internet surfing, an easy mitigation for customers is to use an alternative provider, such as OpenDNS. I've been using both Time Warner and OpenDNS in my home networking environment for years with great results. OpenDNS also helps protect users from visiting known harmful and other inappropriate Internet sites.

Much attention is put on specific, in-scope compliance issues within critical infrastructure organizations. The obvious twist is that even basic, persistent attacks increasingly are a factor in considering overall business risk to service and reputation. Additionally, cyber security problems that affect non-operational, business network settings, also increase the risk of "pivot attacks" creating more serious operational issues that regulators and senior management are acutely concerned with.

From a broader perspective, this issue saliently points out how even narrow, basic attacks can impact an organization and their customers. Critical infrastructure organizations risk even larger potential impacts steming from such issues- driving the need for ongoing cyber security improvements.

Tuesday, February 10, 2009

Top 10 Reasons to NOT Have a Corporate Cyber Security Program

Updated 8/2/2009
I regularly walk past a humorous list of posted reasons why a corporate project management office is not needed based on Jim Chapman’s 1996 list of “Top 10 Reasons NOT to Use Project Management” Considering the focus on cost and change challenges many IT organizations are facing, this insightful list inspired me to come up with my own Top 10- enjoy:


Top 10 Reasons to NOT Have a Corporate Cyber Security Program

10. Our internal and external customers really love us, so they do not care if company information and systems are appropriately and consistently secured.

9. Corporately organizing to manage cyber security risk is not compatible with our culture, and the last thing we need around this place is change.

8. All cyber security work is easy, with little guidance, direction, or accountability needed, and does not have cost, schedule, or any other significant technical, managerial or operational risks anyway.

7. We are not smart enough to develop an enabling cyber security strategy, program, or architecture without stifling creativity and offending our silos of technical and managerial geniuses.

6. We might have to understand our customers’ requirements and document a lot of stuff for review, input and approval which then would need to be maintained and that is such a bother.

5. Understanding, applying, and maintaining specific, definitive cyber security measures and clearly communicating actual status requires integrity and courage, so they would have to pay me extra.

4. Our bosses will not provide support needed for results; they want us to ensure regulatory and legal requirements, congressional concerns, and other related risks are managed through magic.

3. We would have even lengthier debates and still end up applying arbitrary, overly burdensome cyber security measures to all projects regardless of size, complexity, or risk and that would be stupid.

2. I know there is well-developed cyber security body of knowledge that is applicable to the work I am doing, but it is too hard to understand, apply and help us improve with anyway.

1. We figure it is more beneficial to put increasing time and money into cyber security independently in various areas and accept a growing, uneven and obscure patchwork of results than to have an organized, more transparent company approach.

Disclaimer: While there may be times when one or more of the Top 10 resonate, an effective cyber security program should help clearly refute this list at every opportunity.

There continues to be sporadic debate about whether or not IT Security should be viewed as a profit center versus the cost center realty that the vast majority of practitioners work in, e.g., Mike Rothman’s recent commentary: Compliance is SO a Cost Center. Regardless of how security is organized and executed, the best justification approach around security improvements focuses on business benefit in the form of cost savings or value, centered on mutually well understood reality.

Many organizations are under increasing pressure to deliver more with internal resources, including addressing growing security expectations, and keeping costs contained. While the means and alignment to meaningfully execute and maintain security improvements remains vital, an even more important success factor in my opinion to manage such risk over the long term requires clearly articulating an overall company program. The program - however thick or thin in scope and resourcing - provides the means for ongoing leadership driven attention to risk management, policy, goals, results, preparations, with sufficient transparency and organizational support across various groups, compliance programs, and increasingly interested and engaged management.