Showing posts with label Ponemon Institute. Show all posts
Showing posts with label Ponemon Institute. Show all posts

Sunday, May 17, 2020

Program Maturity - Cyber-security and Operational Risk Maturity

The Balancing Act

In reviewing my LinkedIn notifications I was wonderfully surprised to find  an article written by Gideon T. Rasmussen, VCISO topic: Cyber-Security and Operational Risk Maturity.  As soon as I saw it I was thinking this is center to our consulting business I better pay attention. So here we go.


As Gideon T. Rasmussen comments on leveraging risk I immediately get hooked.  How can you even begin to understand your operational and situational awareness with out at first understanding your risk.  At Integris Security we advise our clients if not done within the past twelve months get a solid risk assessment done ASAP!  This risk assessment can then help you set priorities, establish tactical and strategic budgeting, technology goals and priorities and help you weigh your operational risk.  We at Integris believe this will improve the overall maturity of your cyber and operational approach.  But let's go on and see what else Rasmussen's nicely laid out article reveals.

Rasmussen's talks about U.S. Department of Commerce's,  N.I.S.T. (National Institute for Science and Technology).  For a great many of us in the IT security practice N.I.S.T. for years has been the go to "tool shed" for in-depth building blocks.  Their publications can take you from the very beginning of ....   What should I do? Where do I start? To a polished well informed presentation.   N.I.S.T. has a great many publications and they are 100% free.

The F.F.I.E.C., also provides great free guidance.  The men and women of the Northeast Chapter of the F.F.I.E.C., are your local financial services regulators.  You should get to know them, work with them and understand how they are approaching many of the same issues we all are trying to tackle every day.  Integris Security highly recommends you  review the regulators guidance and find answers to your company's compliance problems. These tools are also 100% free and incredibly useful information.

I do take issue with Rasmussen regarding this statement:
"There are no requirements for disaster recovery or business continuity. The card brands do not care if your business goes under, as long as their payment card data is secure." 
This is a nit, and can also be style but the point has to be made.  Their are literally hundreds of best practices for disaster recovery and business continuity and they should be put to use, despite the lack of attention by card brands to advise this.  Promotion of best practices is something we owe to the industry as a whole in our writings and presentations.  Taking on the Card Brands for lack of attention to Rasmussen's legitimate concerns would do better as a separate article, another a day and time in my eyes. We're talking Cyber-Security and Operational Risk Maturity.  At Integris Security we push all to stay focused.  Good practice is too important to relegate to tomorrow's news.  Let's keep it up front and worthy of continual presence and persuasion in our discussions in how to improve cyber-security and operational risk maturity.

In maturity level II, I love this discussion of controls and it reminds me of C.O.B.I.T., as well as the many information security joint forums held with ISACA in years past and their auditor/members.  You gotta love the structure that these individual professionals have developed and the principles that they follow.  This is a serious group of security professionals and we could all learn allot from them.  Rasmussen then lays out the common controls read: GAP analysis, and Risk based deployment of controls, while not much new here he provides a great review.  All solid material for a CEO and others within the organization to read and understand when weighing decisions on investment in the security program or cutting the fat off an already lean program.  These decisions will not be easy ones for sure.

My own note here:

The Cyber-Security and Operational Risk Maturity discussions can not be left alone to the operational business units, departments or divisions of your company.  These discussions need to expand and involve audit committee's at the board level and become a fluid ongoing discussions lead by the chair of the audit, technology and other important committees as the board and operational personnel try to achieve a balance of risk Vs reward and continue to build market value for the company's shareholders and investors.
 Joseph R. Concannon             

In maturity level III, Risk Management, Rasmussen covers it nicely and I smiled as he stated:
"It is necessary to tailor controls to the organization and to adapt to changes in the threat landscape."
Nicely done Gideon T. Rasmussen, these words couldn't be truer.  It also reminds me to tell our readers to remember that each organization has its own culture.  Some are very risk sensitive and others not so much so.  I often use Johnson and Johnson and Martha Steward Living as examples.  Two great companies but their approach to security was night and day.  Johnson and Johnson a security controls organization (almost war like) and Martha Steward Living a creative design firm.  The cultures were completely different at the time of my interview with security personnel.  Management of your and the company expectations are very important.  Don't get ahead of your skates or you  may get caught off balance.  Knowing the culture of your organization is key and very important.  Now that you have new security and risk management information in hand how do you operationalize it?  The best advice is work with your team and leader and try to introduce incremental improvements to improve your organizations overall security/risk posture.  This will work to your benefit for the short term tactical business operations as well as long term strategic planning for important improvements.

Your threat and vulnerability map will be constantly evolving, as targets and priorities come and go.  The risk assessment report provides you with items for your to-do list.  The report will show best practices and offer a target rich list for you to prioritize.  Rasmussen I believe understands this and covers it nicely and provides some bonus points by laying out some bullets for a prospective slide deck to communicate your findings and setting some future objectives.

The Risk Register is a platform to inform and Rasmussen points this out clearly.  Want to know more about your risk?  The Risk Register is a place you want to go to identify, define, understand impact, respond, prioritize, and take notes.  Its an invaluable tool given to us by the folks from project management.

Maturity level IV, Strong Risk Management, Rasmussen lays out a ten step program.


Rasmussen says:


1. There is appropriate separation of duties in the CISO’s reporting structure, such as reporting to the CEO, Chief Risk Officer or Board of Directors. When the CISO reports to the CIO, it is a conflict of interest  2. Cyber-security metrics, KPIs and KRIs feed into an Enterprise Risk Management program.  3.The CISO provides updates to the Board of Directors or similar executive group.  4.The cyber-security program maintains controls specific to line of business products, services and assets. 5. A process management program is in place, to include policy, an inventory and process risk analysis.  6. A fraud prevention program is in place, to include fraud risk assessments conducted by an independent third party. 7. An operational risk management function maintains a risk scenarios inventory and conducts quantitative risk analysis. 8.The organization leverages the Three Lines of Defense Model, with active support from operational management, risk management and compliance functions and internal audit. 9.  Operational functions and lines of business are required to declare self-identified audit issues, with metrics in place to demonstrate the control environment is improving continuously 10. Incident response and business continuity exercises are conducted annually to include senior executives, lines of business leaders, information technology, legal, public relations and critical suppliers
This information is a like having a great cyber-security road map.  However, just like any road map their are going to be detours, accidents, potholes and your going to need the awareness, patience and skills to work around it all.  If you follow the program laid out by Rasmussen you'll be in a better position to mitigate those great unknowns and navigate your way freely from obstructions.

At Integris Security we say: you make it, we make it secure!  We look forward to having these and many other important discussions with you and really enjoyed our read of Gideon T. Rasmussen's LinkedIn article concerning Program Maturity - Cyber-Security and Operational Risk Maturity and hope that you will too!  Their is much to learn and many experiences to endure before we can truly say we're secure.


#Cyber-Security  #HomelandSecurity  #InfraGard #ISSA #ISACA #FFIEC #NIST










Monday, April 27, 2020

Pandemic: Human Resource Help

A Resource no one should ignore


As some of you will no doubt know I do a lot of networking on LinkedIn.  I'm always interested in what's growing, what's moving and how to advance the story of our lives here in America.  Many of my professional connections are on LinkedIn and I am thrilled that I can reach into the resource from time to time seek the advice and opinions that they willingly provide.


This post is about exposing a resource whose time has come.  The need is here and people should pay attention to the depth and breathe of posts.  Its about helping others who may really be in a bind due to the downturn (self imposed) of our economy during this pandemic.  As we press forward and reopen our economy the endless opportunities will slowly give rise to America's unlimited potential which should be great news for everyone involved.

In the meantime, Andrew Seaman does a segment on LinkedIn called #Gethired and provides some tremendous resources that I have found to be just terrific and incredibly helpful.  Andrew is a great writer and inserts into his posts another resource of LinkedIn called LinkedIn Learning.  I have viewed many of the videos and taken a number of these courses and found the quality to be top notch.  He quotes experts from the field and links them in his posts for additional value.  I call that bonus points.

A take away from the resume course is in the table I'm inserting below.  Within a few minutes you can brighten your day and freshen up that resume with color and relevance.


Keywords
Tell a story
Contrast/Compare
Never give up

I was also interested in what LinkedIn was saying on its blog.  Yes, if you didn't know it LinkedIn has a blog and this is another terrific resource for all involved.  LinkedIn has managed to pull together a great team of individuals on its platform who do one terrific job of communicating.  That can not be understated.

That's what this post is all about.  Take a look at your LinkedIn account and drive some attention to the posts and resources that LinkedIn personnel and contactors have so handsomely put together in one place for your use.

@andrewseaman #Gethired

Thursday, April 23, 2020

APWG 4th Quarter Report 2019

Fraud and confidence schemes of the modern day: Phishing

History:

Prior to sophisticated electronics and computers, fraudsters or con men found ways with far less technical means to swindle people out of anything of value.  Then came the Internet. 
Phishing has its roots in the 1790's, and more recently 1990's with Vic Commodore computers, AOL, credit cards number thefts and the Warez community.  "The Warez Scene" as it is known was a group of people specializing in distribution of pirated content dating back to 1975.  Phishing attempts were crude in the early days.  As phishing became more prominent criminal elements started to get focused: first on selecting specific companies as targets, then focusing on extorting top tier executives and eventually the complete hostage taking of companies technical assets (software, hardware, networks) with the introduction of ransomware.   

The internet just made all of this a lot easier. In 1995 random credit generators existed with the use of algorithms.  For a more complete reading see Ed Skoudis' Malware timeline that tracks the growth of technology, industry and subterfuge.  January 2, 1996 the term phishing was for the first time posted on a Usenet group on AOL.  By September of 2003 hackers and con men began registering domains of popular companies, by October of 2003 Pay Pal users found malware contained on clickable emails and the Minmail Virus was introduced to the public.  

2004 produced another first as email solicitations for the U.S. Presidential campaign of John Kerry came in from bogus sites in India and Texas.  Phishing was now making its debut in US Presidential campaigns.  Fraudsters continued to use phishing in the years following and in its pursuits found novel ways to leverage the internet like link manipulation, web site cloning, filter evasion, website forgery, covert redirect and much more.

Today APWG provides an annual report for phishing and much of the same rings true about fraud and con men.  They find a soft spot and prey on their victim.  They are patient, technically smart and hungry for a win while the rest of us are just trying as best as we know how to avoid them at all cost.  

Who is APWG?

The APWG is registered as a U.S. based 501(c)6 corporation (a business oriented not for profit) as defined by the the IRS internal revenue code.  On its web site APWG states, it is a international coalition unifying the global response to cybercrime across industry, government, law enforcement and NGO communities.

APWG.EU the institution's European chapter established in Barcelona in 2013 as a non-profit research foundation incorporated in Spain and managed by an independent board, including APWG founding directors; and the STOP. THINK. CONNECT. Messaging Convention, Inc., a US-based non-profit 501(c)3 corporation jointly managed by APWG and Washington, D.C.-based N.C.S.A..

What is Phishing?

Phishing as defined by the APWG (anti phishing working group) is a crime employing both social engineering and technical subterfuge to steal consumers’ personal identity data and financial account credentials. Social engineering schemes prey on unwary victims by fooling them into believing they are dealing with a trusted, legitimate party, such as by using deceptive email addresses and email messages. These are designed to lead consumers to counterfeit Web sites that trick recipients into divulging financial data such as usernames and passwords. Technical subterfuge schemes plant malware onto computers to steal credentials directly, often using systems that intercept consumers’ account user names and passwords or misdirect consumers to counterfeit Web sites.

What are the numbers?

Thousands of URL's emanating from hundreds of thousands of web sites


APWG tracks phishing sites which can consist of hundreds if not thousands of URL's all leading to the same attack destination.  Web sites reported for Q2 and Q3 2019 represented a larger number of web sites than those reported Q4 for 2019 on a quarter by quarter basis for that year.  However a year to date look at Q4 2019 Vs Q4 2018: 162,155 Vs 138,328 respectively represents a 14.694% increase.  The summer months of July, August and September 2019 showed the months greatest increase roughly between 80-90 thousand phishing web sites reported per month.

 Greg Aaron, APWG Senior Research Fellow and President of Illumintel Inc., stated “July though October was the worst period for phishing that the APWG had seen in three years, and then phishing levels settled back down to more normal levels.”

In the news: COVID-19

"Cyber-criminals are already targeting healthcare organizations—specifically hospitals—with phishing campaigns, ransomware, and other malicious acts that can adversely impact health information technology, medical response, and patient safety. As cases of the virus began to increase in the US, so too did the amount of email-based phishing campaigns referencing COVID-19." https://cyber.nj.gov/alerts-advisories/cyber-threats-cybersecurity-for-healthcare-during-covid-19

"Threat actors are targeting Small and Midsize Businesses (SMBs) with phishing emails in an attempt to deliver the Remcos remote access trojan (RAT). Aimed at SMBs that may be experiencing financial problems from COVID-19 shutdowns, the threat actor impersonates the US Small Business Administration (US SBA)." https://cyber.nj.gov/alerts-advisories/threat-actors-target-smbs-using-government-grant-phishing-emails

"After three years, the Zeus Sphinx banking trojan has resurfaced in coronavirus-themed phishing campaigns containing information on government relief payments." https://cyber.nj.gov/alerts-advisories/zeus-sphinx-banking-trojan-and-other-covid-19-financial-relief-phishing-campaigns

"Google found there were 149,195 active phishing websites in January. That number rose by 50 percent in February to 293,235 websites. Now, in March, there are 522,495—a 350 percent increase since the beginning of the year." https://www.pcmag.com/news/phishing-attacks-increase-350-percent-amid-covid-19-quarantine

"The COVID-19 pandemic has created an environment ripe for fraudulent activity, with threat actors leveraging fears of the virus to perpetrate a variety of malicious and criminal exploitation. Observed scams and fraud have included selling fraudulent personal protective equipment (PPE), hawking fake cures and tests, spreading disinformation, phishing campaigns, and other related scams. The Intelligence Bureau (IB) assesses that this activity will continue, and it will potentially pivot to leverage changing government responses to the pandemic and shifting needs for supplies. Additionally, the IB assesses that cyber-enabled crime will also evolve to prey upon the public’s need to remain updated on the stream of ever-changing COVID-19-related information and may shift from COVID-19 themed outbreak to recovery lures."  NYPD SHIELD, 04/23/20
Attribution: 4/23/20 conference call

Sectors:

The most targeted sectors for 2019 was shown as a pie chart as follows:

  • Saas / web mail 30.80%
  • Payment card industry 19.80%
  • Financial institutions 19.40%
  • Social media 6.80%
  • E commerce / retail 5.4%
  • Cloud storage / file hosting 3.4%
  • Telecom 3.3%

Business email compromise campaigns:

As noted by APWG: In a BEC (Business email compromise) attack, a scammer targets employees who have access to company finances, usually by sending them email from fake or compromised email accounts (a “spear phishing” attack). The scammer impersonates a company employee or other trusted party, and tries to trick the employee into sending money.  APWG states attackers could prepare for weeks for such an attack inside financial systems, personnel systems and other area likely to produce a positive harvest of legitimate looking emails.  The BEC attack is said to cost the industry billions of dollars. Wire transfers can be 5 to 20 times larger in the amount of money gained by attackers over gift cards whose amounts are generally much smaller.  The use of gift cards is stated to be used as a way of laundering other funds to buy physical goods which can later be sold rather than put them into cryptocurrency exchanges, which is said to be another popular way of laundering money.

Schemes:

The following is a list of schemes in priority:

  • Gift card (click here: Google play cards scheme {most request} decreased but eBay, Target, Best Buy, and Sephora all saw increases)  62%
  • Direct transfer 22%
  • Payroll diversion 16%
Taken from a conference call 4/23/20:

Analysis:

Deception of others and stealing (confidence schemes, con games) is not uncommon, however use of the internet since the 1990's has created miles of new paths to travel for those with criminal intent.  Our nation has and is enduring heart-ships heretofore not contemplated (9/11, COVID-19).  Duping of unsuspecting victims will continue to happen using these incidents and a great many others to pry money out of the hands of unsuspecting victims. It is said 93% of data breaches are still caused by phishing incidents with the cost estimated at 1.6 million dollars for mid sized companies. These incidents will continue for some time to come.  Awareness training should continue as a mitigation strategy to reduce the incidents.

Update 4/23/20: Corporate email 


Per conference call today 4/23/20 thanks to everyone on the call.  We are also reviewing a NYPD Shield report 4/20/20 and when we have a green light will post highlights on this page.

Selected Terms:

  • APWG: Anti Phishing Working Group
  • BEC: business email compromise
  • SSL: Secure sockets layer, standard security technology for establishing a encrypted link between a server and client (web site)
  • Saas: Software as a service
  • gTLD: Generic top level domains legacy, such as: .com, .org, .Asia, .biz
  • nTLD: New generic top level domains examples: .work, .icu
  • ccTLD: Country code domains examples: .UK, .MX
  • NCSA: National cyber security alliance
  • Spear phishing: email spoofing attack that targets a specific organization or individual, seeking unauthorized access to sensitive information
  • Whale phishing: is a specific type of phishing attack that targets high-profile employees in order to steal sensitive information from a company
  • Smishing phishing: criminals sending text messages via telephones
  • Viinishing phishing: is an actual telephone conversation
  • Angler phishing: Fake URL's, cloned web sites, social media etc.


Friday, June 24, 2016

Drones: Are they on your radar?

Drones - friend or foe?
Early in the computer industry programmers used to write computer code to automate many functions and features.  As the years progressed the same code was used for more nefarious purposes. Computer code used for these nefarious purposes is commonly called malware: Viruses, Worms and Trojans. 

Now early in the drone industry we are being teased with visions of Amazon dropping boxes in our rear yard, fast food deliveries arriving with piping hot pizza via a drone and many other examples of how the use of this technology can enhance our lives.  The examples are endless.

However, while drones can in fact do much to enhance our lives the use of drones can also be pointed to more nefarious purposes.  Common perimeter defenses can be easily undermined with relatively little effort for the determined attacker.  With a few thousand dollars your intellectual property can vanish in seconds.  Installation of an onboard camera with pan tilt and zoom could steal your ideas right out of your board room.  The drone can do this and more while still being blocks away.  As drones mature and their payload capability increases security directors and facility personnel concerns will only increase.

Integris Security LLC has for years identified both leading and bleeding edge technologies.  Today, we have identified a strategy, a technology and method to address not all but some of the issues concerning drones.  We would like to set an appointment to speak with you and see if this is on your radar screen.  Drones can be managed and can be one less thing that keeps you up at night.

Press Release:
http://tinyurl.com/hjwpt54

FAA News:

http://thecipherbrief.com/article/exclusive/tech/implications-new-faa-commercial-drone-rules-1092

Integris Security Web Site 6/25/16:





Drones: Are they on your radar?

Drones - friend or foe?
Early in the computer industry programmers used to write computer code to automate many functions and features.  As the years progressed the same code was used for more nefarious purposes. Computer code used for these nefarious purposes is commonly called malware: Viruses, Worms and Trojans. 

Now early in the drone industry we are being teased with visions of Amazon dropping boxes in our rear yard, fast food deliveries arriving with piping hot pizza via a drone and many other examples of how the use of this technology can enhance our lives.  The examples are endless.

However, while drones can in fact do much to enhance our lives the use of drones can also be pointed to more nefarious purposes.  Common perimeter defenses can be easily undermined with relatively little effort for the determined attacker.  With a few thousand dollars your intellectual property can vanish in seconds.  Installation of an onboard camera with pan tilt and zoom could steal your ideas right out of your board room.  The drone can do this and more while still being blocks away.  As drones mature and their payload capability increases security directors and facility personnel concerns will only increase.

Integris Security LLC has for years identified both leading and bleeding edge technologies.  Today, we have identified a strategy, a technology and method to address not all but some of the issues concerning drones.  We would like to set an appointment to speak with you and see if this is on your radar screen.  Drones can be managed and can be one less thing that keeps you up at night.

Press Release:


Drones: Are they on your radar?

Drones - friend or foe?
Early in the computer industry programmers used to write computer code to automate many functions and features.  As the years progressed the same code was used for more nefarious purposes. Computer code used for these nefarious purposes is commonly called malware: Viruses, Worms and Trojans.  See our updated posts below.

Now early in the drone industry we are being teased with visions of Amazon dropping boxes in our rear yard, fast food deliveries arriving with piping hot pizza via a drone and many other examples of how the use of this technology can enhance our lives.  The examples are endless.

However, while drones can in fact do much to enhance our lives the use of drones can also be pointed to more nefarious purposes.  Common perimeter defenses can be easily undermined with relatively little effort for the determined attacker.  With a few thousand dollars your intellectual property can vanish in seconds.  Installation of an onboard camera with pan tilt and zoom could steal your ideas right out of your board room.  The drone can do this and more while still being blocks away.  As drones mature and their payload capability increases security directors and facility personnel concerns will only increase.

Integris Security LLC has for years identified both leading and bleeding edge technologies.  Today, we have identified a strategy, a technology and method to address not all but some of the issues concerning drones.  We would like to set an appointment to speak with you and see if this is on your radar screen.  Drones can be managed and can be one less thing that keeps you up at night.

Press Release:

http://tinyurl.com/hjwpt54

FAA News:
http://thecipherbrief.com/article/exclusive/tech/implications-new-faa-commercial-drone-rules-1092

Integris Security Web Site 6/25/16:
https://www.integrissecurity.com/index.php?solutions=DroneDefense




Monday, June 9, 2014

What's Your Risk Tolerance?


                 Where's your army?

At  Integris Security we're asking the question who do you have protecting  your data and your information?  What's your risk tolerance?

Do you have an army of security professionals that are well trained and well informed?  If you are new to your environment have you conducted a full audit and/or do you have a full audit program in place?  Are you truly ready for a Red Team to come in and test your defenses?

If you're not scanning, testing and performing a critical analysis of your systems, people and workplace, then you just aren't testing and might as well leave the front doors open, leave the userid's and  passwords on the desk all day long and don't purchase another defensive tool. 

At Integris Security we perform system scanning as a good low level way to reveal vulnerabilities and to create of punch list to work on.  We conduct penetration testing because it takes testing several steps deeper and provides a full analysis on what's going on inside your environment.  But while all of these things are good they are really not good enough.  A network topology and architecture review would also be a great start but still not good enough.  You need to understand your risk tolerance.  In order to do this you need to understand your total environment.

An ISO 27001 certification is a top/down inside look at your environment. 


ISO/IEC 27001:2005, part of the growing ISO/IEC 27000 family of standards, is an information security management system (ISMS) standard published in October 2005 by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).

If you're sitting on a board of a company it should be something you have in your binder and it needs to be maintained annually with weekly, monthly, quarterly, semi annual and annual updates.  This is a fact driven file that all discussions emanate from.  This certification is something every new CEO should be given once the keys to the kingdom are in his/her hands.  Every single discussion concerning future enhanced functions coming into a company need to flow from this certification.

Consider if you would driving a car without knowlege of how much gas you have left, whether or not you know if your signals or headlights are working.  You would effectively be driving blind.  Don't drive blind, know what's going on around you and respect the incredible complexity which is driving your companies profit center.  Become informed, challenge operators on both the security team as well as those on the business team to bring all the facts to the table.  Make an informed Risk Tolerance decision.  

How can you even begin to know your risk tolerance if you don't know what's in your wheel house?  Call Integris Security and let's get informed together. 


Trust is at the core of Integris Security. We can be counted upon to provide you with the services and intelligence to keep your information, systems and institution secure. Call us and let's get to work on improving your security/risk posture.



Tuesday, June 3, 2014

Uncertainty, risky first half of 2014...the year of the hack?

Pushing the buttons of millions of individual Americans is the fact that their accounts have been hacked according to Larry Ponemon at the Ponemon Institute in a study conducted for CNN Money.  Ponemon's study gaged that 47% of adults had their accounts hacked during 2014, which may soon become known as "the year of the hack".  That's just about half of all adults in the United States.

The facinating numbers come at the heals of the Target breach which we have been discussing on this blog and doesn't include the millions in the latest eBay Breach.  Its raining on the American Public as millions of  (PII) records are exposed.  Here are the facts and figures Ponemon and Jose Pagliery of CNN have dug up for CNN Money:

"Cyber attacks are growing so numerous that we're becoming numb to them. Researchers at IT company Unisys (UIS) say we're now experiencing "data-breach fatigue." Even the most recent numbers make for a dizzying list:

More numbing then the facts and figures presented by Ponemon Institute for CNN MONEY is the fact that the industry has not adopted better and well known security practices as a whole.  Need I go on?  For ten years industry has been digging a hole deep in the sand and sticking their preverbal heads in the hole.  See my blog post on accountability.

Let's not blame it on companies looking at profits after all isn't that why companies are in business to begin with.  However we too pause, when companies select tactical gains to satisfy quarterly earnings statements and maybe making themselves look good as opposed to the overall strategic growth and health of a company or corporation.  Read responsibility to share holders, and company employees. To some extent the risk Vs reward discussion will come up and when presented executives will nervously select profits.  Until boards reflect the knowledge, skills and abilities necessary to make both tactical and strategic management decisions we will continue to see the deep decline and clearly the never ending "year of the breach".  Operational executives will respond in kind when Boards of Directors begin to ask the thorny questions which should focus on the strategic growth of the company.  Employees will then be motivated and hear the clarion call from mount high when the CEO comes back from the board meeting and says they want more security and assurance before we can bring that function on board, who certified that code, who tested it and who is taken ownership of the relationship with the software team?

Here's hoping that the second half of 2014 is the year of Board of Directors active and attuned to what is going on not only in the front office but every office.  That function continues to thrive and work closely if not right next to the security team.  That multi-factor authentication is used not just for outsiders, but insiders as well.  That outside relationships are clearly defined and SLA's (service level agreements) are scoped out to protect both the vendor and the company.  That data which can be held in a planet sized computer terminal or a tiny smart phone is protected and preserved because we should all enjoy a level of privacy.   That when we buy the state of the art upstream gadget that detects attacks and when alarms go off and people start screaming at the top of their lungs someone will listen and will have been properly trained on the use of the gadget and that it is properly configured. All very hopeful that the year end will be better than the start.  The future is now before us.  Let's see how we do!

Good luck everyone!