Thursday | 8 January, 2009
CIO
Sweat About the Threat
With the world falling apart all around you it is tempting to focus on those nagging technical questions that have been plaguing you and your team. Think again. Your nightmares are about to get 10 times worse.
Adam Cobb 04 February, 2003 10:19:30

What's the cost of bringing down the government? Priceless.

It is as if the world has gone mad. Serene Bali scarred forever, "credible threats" of terrorism at home, Australia's Prime Minister threatening pre-emptive military action in Asia, North Korea declaring its nuclear capability, old foes Iran and the US looking towards military cooperation in an Iraq invasion, the Syrian president in London meeting the Queen, and the US issuing a new nuclear policy threatening the use of "small" nuclear weapons against anyone who uses "weapons of mass destruction" against them (read terrorists or Saddam).

With the world falling apart all around you it is tempting to focus on those nagging technical questions that have been plaguing you and your team. Think again. Your nightmares are about to get 10 times worse.

Ever attended an estimates hearing in your portfolio? Imagine senators Robert Ray or John Faulkner dissecting your every action and decision in front of the nation's media as you try to stumble through an explanation of why your security processes should have stopped the terrorists from bringing down a key element of your system.

It is mid 2003. In the packed committee room on the Senate side of Parliament House, you look to your minister for support against the torrent of questions from the hard men of the ALP. Your minister stares straight ahead with a glassy stare. Then you remember the minister's press release issued back in November with its now common refrain: " . . . on the advice of my departmental advisers I can assure the public that the system in question is robust. Nevertheless the CIO has been requested to ensure reasonable measures have been put in place to deter, defend and defeat an attack."

On your measly budget the actions you took were reasonable, you quickly tell yourself. It is amazing how the word "reasonable" in normal usage becomes so damn unreasonable in front of judges and senators. Then you wonder whether you said that last thought out loud because senators Ray and Faulkner look like they are heading for the kill. Everyone in the room can smell blood - your blood.

With little forensic support you have as yet been unable to accurately identify how your system was penetrated. Holding this hearing now is so grossly unfair. Right now you honestly don't know how all that hugely sensitive personal data on all the families of the Defence personnel serving in the war on Iraq got into the hands of JI. As the troops negotiate a chemical and biological Dante's inferno in Baghdad, your slip-up has exposed the families to a series of threats and attacks that followed the bogus cancellation of a whole month's pay.

The sweat pours down your face: "Damn outsourcing" you scream inside your head in the air-conditioned plushness of the Senate estimates room. You quickly go over who could be responsible . . . Was it a mistake of that gateway mob under DPIE? Did they let the attack through? No, their audit logs prove that they had nothing to do with it. What about your AS06 security expert? No good either: he is obviously nothing more than the electronic equivalent of an airport bag checker - doing his job exactly as the rule book tells him - no imagination, no innovation and no awareness. You cannot let the pregnant silence go on for much longer; Ray is almost shouting now for an answer.

Little do you know that sitting in the public gallery of the committee room is Mark the contract cleaner. As he watches your career collapse beneath you he has a wry smile on his face. No one notices him, no one ever has; Mark and his employers like it that way.

No one noticed when he used his access card to legitimately swipe his way into your office. While busy dusting he plugged a USB memory stick into your PC. No one noticed the tiny device - only the size of a packet of gum but able to carry a gigabyte of data. Mark was dusting alright: he dusted all the critical passwords and access codes right off the system manager's PC.

But Mark was not just cleaning that night, and others gone by. In the seven different departments his company is commissioned to clean, he was delivering malicious code into all the key systems. He was also configuring his wireless PDA to your department's encryption key (which he got from your machine a month back) to enable him to access your LAN from a van outside the building using the tools of the trade - a laptop and Pringles chips tin. A chip tin? Yes. Mark's Web surfing showed him that a Pringles tin just happens to be perfectly shaped to act as a wireless network base station. Cost of a laptop: $2600. Cost of a Pringles tin: $3.50. Cost of bringing down the government: priceless.

Remember how you used to wonder about the quality of life of the ASO4 in corporate services - you know, the nice guy who wanted to chat a little too much at morning tea but was always upbeat and eager to help out? Remember how you used to wonder how he could put up with his nasty, self-important, brown nosing superiors/back stabbing subordinates/office manager? You are about to find out. Personally.

National security is critically important to every CIO in these tense times. There might be the greatest gateways in the world ringing your site off from the rest of the world, but it does not take a very smart spy to penetrate the core of the defence establishment, let alone non-national security government systems that nevertheless have information that could be used in new and threatening ways. Indeed, as the above example shows, your system can be penetrated even if it is totally isolated from the Net.

Security is a living thing; a smart attacker will assess your routines and work with them to their advantage.

Being vigilant is not enough if you do not know what you are looking for. If you are up to your neck in red tape keeping your system alive, perhaps you might save your neck if you spent a small part of your budget undertaking a RED TEAM risk assessment and security audit.

Adam Cobb (PhD Cambridge) is a former director of Strategic Policy in Air Force and now director of Stratwise, an international strategic and security advisory firm based in Sydney (www.stratwise.com)

Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from CIO and leading technology partners.
Newsletter Subscription
Sign up for our CIO newsletters!
RSS Feeds
Featured Whitepaper Sponsors
Market Place
 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Data breaches rose sharply in 2008, says study 08 January, 2009 08:27:00

    More than 35 million data records were breached in 2008, according to the Identity Theft Resource Center.
    More than 35 million data records were breached in 2008 in the U.S., a figure that underscores continuing difficulties in securing information, according to the Identity Theft Resource Center (ITRC).
  • +

    Rogue SSL certificate exploit puts VeriSign on the spot 07 January, 2009 11:04:00

    Wishes "white hat" researchers had notified VeriSign before public demo.
    Following the success of researchers last week in creating a false SSL certificate based on VeriSign's RapidSSL brand, the company is scrambling to explain how it happened, how it's preventing it from reoccurring, and whether its other SSL certificate-generation services are at risk.
  • +

    With Gaza conflict, cyberattacks come too 05 January, 2009 08:03:00

    Pro-Palestinian hackers have defaced thousands of sites following attacks in Gaza.
    The conflict raging in Gaza between Israel and Palestine has spilled over to the Internet.
  • +

    5 ways to secure your Blackberry 18 December, 2008 12:58:00

    What do Tom Cruise and the McCain campaign have in common? They have both been bitten by the loss of a Blackberry. Mobile expert Dan Hoffman gives advice on how to keep your cherished mobile device safe, even if it's out of your hands
    What do Tom Cruise and the McCain campaign have in common? They have both been bitten by the loss of a Blackberry. Mobile expert Dan Hoffman gives advice on how to keep your cherished mobile device safe, even if it's out of your hands.
  • +

    Wireless VPNs: Protecting the wireless wanderer 18 December, 2008 11:04:00

    Employees sipping café Java over their wireless laptops may think a VPN makes them safe and secure. With careful configuration, there's some chance they're right
    Employees sipping café Java over their wireless laptops may think a VPN makes them safe and secure. With careful configuration, there's some chance they're right.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Best Practice in Building an Integrated Information Management Strategy

Discover the business value that creating an integrated information platform can bring. Learn how to provide consistent, accurate information to all stakeholders within your business network. Integrate vital data from disparate sources and deliver a trusted information foundation. Read on to uncover the stepping-stones to your new information management strategy.