Most Security is Useless

Looks like I missed this the first time around but there is an article about a speech recently given by Peter Tippet, a VP at Verizon and a scientist at ICSA labs, who talks about how useless most security actually is. Most of his points are ones that I have been making for years like the uselessness of long complex passwords, all your doing is inconveniencing the user. Or how ineffective the continuous search for, reacting to, and patching of new software holes really is when you consider that only a small percentage of those holes are ever exploited. Do you want the highest rate of return on your security dollar? Spend it on the weakest link, the people. Security awareness training, while hard to quantify, will provide the biggest return in terms of security. If you can train your users to think about security as part of their everyday work lives your overall level of security will increase dramatically.

 



About Space Rogue

With over two decades of experience, Space Rogue (Cris Thomas) has testified before the U.S. Senate Committee on Homeland Security and Governmental Affairs, and has been interviewed by Wired, CNBC and even MTV. He created the wildly popular websites the Whacked Mac Archives and Cyber Squirrel 1. He produced the weekly podcast SpiderLabs Radio, and the critically acclaimed weekly news video program the Hacker News Network. His writing has appeared in Network Computing, New Statesman, The Hill, and the Christian Science Monitor. He has spoken at security conferences such as Def Con, Blackhat, and Shmoocon. Space Rogue currently works as the Global Lead of Policy and Special Initiatives for the legendary IBM X-Force.
This entry was posted in Commentary, Current Events. Bookmark the permalink.

Comments are closed.