2010: The Future of Security

By Scott Berinato

PAGE 2

Since then, the phrase has become bromidic to the point that former cybersecurity czar Richard Clarke declared that "digital Pearl Harbors are happening every day."

Whether conceived of as rare or quotidian, the digital Pearl Harbor’s definition has remained constant: It’s a computer outage, a big one, a physically and financially damaging one. More recently, it has become a shorthand way to say, "Terrorists will take down the Internet."

In either case, this definition is wrong. Not only is it wrong, it’s not even useful.

"I hesitate to even use the term," says Jeff Schmidt, an elected member of the FBI’s InfraGard national executive board. "It’s come to mean any attack that’s massively inconvenient. But I don’t think they merit the term digital Pearl Harbor."

"We need to distinguish between the mischievous and the malicious," says Darwin John, who served recently (albeit briefly) as CIO of the FBI and is considered one of the godfathers of the CIO profession. "We’ve tolerated the attacks until now because they’re mischievous. The malicious attack will be the one that moves the public consciousness, and it’s so much harder to know what that attack will be."

It’s much easier to know what a digital Pearl Harbor won’t be. Taking down the Internet or ATM networks, compromising the Social Security database, even hacking into the electric grid?Schmidt and others argue that while each event may be part of a digital Pearl Harbor, none qualifies in and of itself. None would galvanize society, spurring it to action.

And it needn’t be a terrorist attack. Open networks coupled with vulnerable software make it more likely that a transformational event will arise from a more banal source, like a motivated group of computer experts, a common thief or, most fickle of all, an accident.

The coming digital Pearl Harbor doesn’t even have to be a single event. Thinking about the nature of disasters, Software Engineering Institute fellow Watts Humphrey consulted nuclear power people. "I talked to one guy who did nothing but review incidents," Humphrey says. "And typically, these kinds of disasters result from a combination of many smaller events that each seem highly unlikely. But they all happen at once to create unforeseeable consequences."

That’s the "Perfect Storm" theory, and what makes an event perfect (in a negative sense) is the apparent lack of relationship between systems in a complex environment. The blackout last August was a Perfect Storm. Random, seemingly unrelated factors?an aging power grid, certain corporate decisions, a heat wave, a history of deregulation and some human errors?all came together to darken a significant chunk of the northern hemisphere.

$firstKeyword

Loading...
Security MarketSpace
Practical Approaches for Securing Web Applications
Enterprises understand the importance of securing web applications to protect critical corporate and customer data. What many don't understand, is how to implement a robust process for integrating security and risk management throughout the web application software development lifecycle. Learn more »
An Executive's Guide to Web Application Security
Since so many Web sites contain vulnerabilities, hackers can leverage a relatively simple exploit to gain access to a wealth of sensitive information, such as credit card data, social security numbers and health records. It's more important than ever to examine your Web application security, assess your vulnerability and take action to protect your business. Learn more »
Web Application Vulnerabilities
Security managers may work for midsize or large organizations; they may operate from anywhere on the globe. But inevitably, they share a common goal: to better manage the risks associated with their business infrastructure. Increasingly, Web application security plays a significant role in achieving that goal. Learn more »
Retooling IT for a Mobile Workforce
Check out this research note from IDC for guidance. Learn more »
Today's Risky Data Environment
This paper explains how an IT and security service provider can provide a practical, manageable and reliable solution. Learn more »
Business Continuity - Are You Always Open for Business?
This Oracle business brief explains how mid-sized can improve performance by creating an IT infrastructure that makes working faster, easier and more effective. Learn more »
 
SPONSORED LINKS
 

Making Consumer Two-Factor Authentication Simple and Cost-Effective

Mining the Cloud to Ease the Enterprise Compliance Burden

Solve Five Key IT Security Challenges with Cloud-Based Authentication

White Paper: Managed Security for a Not-So-Secure World

Secure Email and Web-Based Communication from Evolving Attacks

WagerWorks Takes Fraudsters Out of the Game using iovation

White Paper: A Security Blueprint Delivered From within the Network

Return on Information: Google Enterprise Search pays you back

Cut Costs & Green Your IT Operations with PC Power Management

White Paper: 4 Customer Service Myths

White Paper: Improve Agility with Operational Responsiveness

White Paper: Legacy Tools: Not Built for the Helpdesk

Taking a Seat at the Executive Table: The Reality of Virtualization

White Paper: Next Generation Remote Infrastructure Management

Seven Design Requirements for Web 2.0 Threat Protection

Increase UPS efficiency without sacrificing protection.

Learn how advanced forecasting tools can deliver significant business results for global corporations.

Lower IT Costs with Oracle Database 11g Release 2

White Paper: Visibility and the New Normal of Mobile Work

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

Return on Information: Google Enterprise Search pays you back. Get the facts.

VMware. The source for Business Infrastructure Virtualization.

ShoreTel tells businesses to untangle from competitors' complexity and turn to its brilliantly simple UC solution

Top Five CIO Challenges

Authentication as a Service by Forrester Research

Cloud-Based Authentication for Next-Generation Extranets

Mobile Security: The Essential Ingredient for Today's Enterprise

IDC White Paper: CCM for IT Compliance and Risk Management

Keeping Your Members Safe from Online Scams and Predators

Learn about the growing threat of insider data theft.

Upgrading to VMware vSphere with vWire

Maximizing website Return on Information with high-quality search

See how AT&T can help protect your network.

Webcast: Unleashing the Power of Customer Data

White Paper: 5 Best Practices for Smartphone Support

Global Research: CIOs Weigh In On Virtualization

5 Key Virtualization Management Challenges

The Total Economic Impact of Network Security Intrusion Prevention

Generation Remote Infrastructure Management - Changing the Paradigm

Cloud-Based Email Management: Opinion Shifts In Favor

eBook: How Can You Make Your People Productive Anywhere?

Achieving Business Agility with Application Grid

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

AT&T Synaptic Storage as a Service. Expand on demand

Trend Micro ranked #1 against real-world malware. Read more.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Streamline IT Costs. Boost Performance with WAN Optimization.

 
 
RESOURCE CENTER