Don't Bankrupt Your Company in the Search for Absolute Security

By

Vendors will try to scare you to death to sell you their products. Don’t fall for it, says an IBM vendor who sells security systems to military groups.

At the Hot Topics in Tech track at ITEXPO in Fort Lauderdale yesterday, IBM security evangelist Westley McDuffie invoked Dwight Eisenhower when he told the assembled crowd that the desire to achieve absolute security might very well bankrupt your company.

“I preach the gospel of security,” McDuffie says. He works with nations and governments, rather than corporations and businesses. “The difference is, if you mess with my clients, they can kill you.”

McDuffie used statistics to reinforce his claim that vendors will sell you what you don’t need. He says 75% of security threats can be attributed to internal attacks. But he notes that most of those internal issues are the result of carelessness, rather than an attempted attack.

He says less than 1% of security issues arise from targeted attacks. Vendors still try to sell you on protection against zero-day, which accounts for less than 0.1% of security issues.

McDuffie offered a few military-type tips for improving your IT security without breaking the bank:

  • Align your security risks with your corporate goals, not the other way around. Don’t let the tail wag the dog, he says. When security concerns get in the way of making money, corporate goals aren’t being pursued.
  • Adjust your change of control procedures. Do you complete change-of-control functions over the weekend? McDuffie says push that to Thursday, so your chief technician – not the weekend guy - is on duty, just in case.
  • Spend the money when you need to. McDuffie says governments aren’t afraid to spend, while corporations limit their IT security outlays to around 7% of their budgets. Can you afford to spend a little more than normal?

McDuffie stressed that proper security involves applying the proper procedures, over and over. “Security is something you do, not something you have,” he says.

It doesn’t help to let fear rule your decision making. “Fear, uncertainty and doubt run rampant in the world,” he says.

Don’t let vendors sell you the “Swiss knife” solution, or the magic bullet that will solve all your security concerns. The complete security solution doesn’t exist, he says, and if it did, you probably couldn’t afford it.




Edited by Erik Linask
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

Communications Correspondent

SHARE THIS ARTICLE
Related Articles

Introducing the Newest Addition to ITEXPO #TECHSUPERSHOW: Enterprise Cybersecurity Expo

By: TMCnet News    6/11/2024

TMC today announced the launch of Enterprise Cybersecurity Expo, set to take place from February 11-13, 2025, in Fort Lauderdale, Florida, at the Brow…

Read More

The Shifting Landscape: Emergent Technological Paradigms in Online Sports Wagering

By: Contributing Writer    6/7/2024

In the ever-evolving sphere of online sports wagering, technological advancements have been instrumental in reshaping the landscape, altering how enth…

Read More

Unpacking The Differences: How CPaaS And Network APIs Drive Distinct Innovations

By: Special Guest    6/5/2024

While they share some technical synergies, CPaaS and Network APIs serve different markets and purposes, highlighting the need for complementary strate…

Read More

Protecting Your Digital Fortress Through Threat Exposure Management

By: Contributing Writer    5/23/2024

In today's digital landscape, cybersecurity threats loom large, posing significant risks to businesses, organizations, and individuals alike. With the…

Read More

Why Block Websites? Understanding the Reasons

By: Contributing Writer    5/6/2024

The internet is such an expansive network where every click can lead to information, entertainment, or opportunities for productivity. However, this a…

Read More