Posts

GE-CIRT Joins FIRST

Image
I am pleased to announce that on Friday 19 March the Forum of Incident Response and Security Teams, or FIRST , accepted the General Electric Computer Incident Response Team, GE-CIRT , as a full member . This represents about a year of work for us. I am really proud of our team, especially since we reached initial operational capability on 1 January 2009. I would like to thank James Barlow and Rob Renew for sponsoring our application; Sarah Gori for leading our application process; David Bianco for helping Sarah with technical aspects of the process; and our security team members for assisting with meeting FIRST's criteria. If you are a member of an incident detection and response team but your team is not part of FIRST, please check out the membership process . I advocated joining FIRST for three reasons: Joining FIRST is a sign to the world that your team has reached a certain level of maturity, stability, and capability. The membership process itself will help focus your team...

Bejtlich in April Wired Magazine

Image
The April issue of Wired Magazine features an article by Noah Shachtman titled Security Watch: Beware the NSA’s Geek-Spy Complex . Noah writes: Early this year, the big brains at Google admitted that they had been outsmarted. Along with 33 other companies, the search giant had been the victim of a major hack — an infiltration of international computer networks that even Google couldn’t do a thing about. So the company has reportedly turned to the only place on Earth with a deeper team of geeks than the Googleplex: the National Security Agency... Technically, rendering this aid isn’t the NSA’s job, says Richard Bejtlich, a former Air Force cybersecurity officer now with General Electric. “But when you’re in trouble, you go to the guys who actually have a clue.” I appreciate the mention Noah! The focus of his article is as follows: [Within NSA, o]ne team wants to exploit software holes; the other wants to repair them. This has created a conflict — especially when it comes to working w...

Bejtlich Returns to PaulDotCom Podcast

Image
The guys at PaulDotCom posted the podcast .mp3 (39 MB) they conducted last week . It was another debate between myself and Ron Gula. We contrast control-centric and threat-centric defensive strategies, as well as discuss advanced persistent threat. Thanks for having us. I had forgotten that I was on their second show in January 2006!

Ways to Justify Security Programs: 13 Cs

Image
My last post Forget ROI and Risk. Consider Competitive Advantage seems to be attracting some good comments. I thought it might be useful to mention a variety of ways to justify a security program. I don't intend for readers to use all of these, or to even agree. However, you may find a handful that might have traction in your environment. Crisis. Something bad happens. Although this is the worst way to justify a program, it is often very effective. Compliance. An external force compels a security program. This is also not a great way to justify a program, because resources are often misallocated. Competitiveness. Please see my previous blog post. Comparison. If your company security team is 10% the size of the average peer organization size, it's not going to look good when you have a breach and have to justify your decisions. Cost. It's likely that breaches are more expensive than defensive measures, but this can be difficult to capture. Customers. It seems rar...

Forget ROI and Risk. Consider Competitive Advantage

Image
In my last post, Time and Cost to Defend the Town , I mentioned pondering different ways to discuss digital security with a new executive. This business leader reportedly said "every day, our businesses are competing in a global marketplace. How can we help them?" I thought about that statement and one idea came to mind: Digital security helps businesses build competitive advantage. I've decided that competitiveness is the new theme which I will use to justify my team's activities when discussing our mission with management. It seems simple and accurate to me. Capable digital security teams help businesses build competitive advantage by keeping data out of the hands of adversaries. Contrast competitiveness with two other popular paradigms for discussing digital security: ROI and risk. Imagine the following conversations. Which do you prefer? 1. "ROI-centric discussion" Security person: Hello boss. We need to implement our security program because it ...

Time and Cost to Defend the Town

Image
Recently I guest-blogged on the importance of learning how another person thinks . This week I had a chance to apply this lesson with a new decision maker. I learned that I need to develop a way for this executive to think about our security program. I discussed the situation with my wife and she suggested focusing on cost. I thought about this a little more and realized that was the right way to approach the problem. Consider the following scenario. You're the mayor of a town. You need to decide how much of your budget to allocate to the fire department. To apply the most simplistic analysis to the problem, consider this scene. As mayor you give the fire chief a simple goal: "protect us from fires!" The fire chief asks you: "Mayor, on average, how fast do you want the fire department to respond to a fire?" I am not an expert on fighting real fires, but let's think about a range of some possible answers. Option 1. Instantly . Literally as soon as a...

Guest Post on SecureThinking about Cyber Shockwave

Image
BT asked me to write a guest post on their blog, so I provided a new Reaction to Cyber Shockwave . I hadn't really addressed one of the main reasons why I liked Cyber Shockwave, despite the LOL-worthy "technical" aspects of the "simulation," when I wrote my first Reaction to Cyber Shockwave . Please check out the post if you'd like to read more about this. Thank you.