Security monitoring and measuring needs to be expanded to trusted third parties; here’s why.
When it comes to securing sensitive data from attack, there’s certainly no lack of evidence that current tactics are falling short. This is despite the considerable investment that enterprises have made to secure their systems and data. According to the research firm Gartner, worldwide security software spending reached $19.2 billion in 2012, an increase of 7.9 percent from the prior year. There’s no sign of that spending slowing any time soon.
Regardless of these efforts, the outcome has been less desirable. This is evidenced in the stubbornly consistent poor quality of software security, new forms of ever more successful malware, advanced attack exploits, and countless data breaches. And there’s also a quiet, yet massive, amount of intellectual property theft underway — to the sum of $300 billion annually according to the Commission on the Theft of American Intellectual Property.
The brilliant physicist Albert Einstein is often quoted as saying that the definition of insanity is doing the same thing over and over again and expecting different results. By that definition, many aspects of IT security are nothing short of insane.
So what should risk management and security professionals change?
For starters, we do know that many organizations simply aren’t looking for the right breach indicators on their systems. According to the Verizon 2013 Data Breach Investigations Report, for instance, most compromises are underway for weeks and months before they are detected. And in about 70 percent of the cases, the enterprise doesn’t become aware of its own compromise through its own efforts — rather a partner or a third party actually notifies it that there is a problem. Not good.
We know that organizations are struggling with all of these issues on the systems they run and manage. When taking into account the uncertainty that enterprises accept when connecting systems with third parties, it becomes apparent how much risk is actually being taken on through the extended business of partners, suppliers, and in some cases even customers.