Colt 45 and Two ZigZags, Baby

Colt 45 and Two ZigZags, Baby

OK. This whole world of Cybersecurity can now be declared officially insane.

Sonatype research claims that 57% of the Global Fortune 100 has yet to address the flaw in Apache Struts that led to the most expensive and damaging breach in history. The list included seven technology companies, eight auto manufacturers and fifteen financial services and insurance companies.

That would be 30% of the Fortune 100 just in those three sectors. And seven technology companies? Come’on man.

Equifax not only failed to fix the vulnerability once but did so again later, earning it the Stooge of the Year award (up until now). As a reminder, these were the folks who brought us 148 million compromised PII records and a quarter of a Billion dollars in expense to date (tally still going). This of course, prompted the FBI to issue a flash “alert” warning to everyone paying attention that we need to patch the software.

Apparently only half of the Fortune 100 was paying attention. Because an astounding 8,780 Apache Struts downloads have occurred in the wake of the Equifax breach, and yes, everyone of them is vulnerable to the same attack.

Why we haven’t applied the patches and why we keep downloading older vulnerable versions is a mystery to many. Last year, known vulnerabilities remained the leading cause of data breaches accounting for almost 50% of all incidents. We have been harping here for what seems like forever about the need to apply critical security patches immediately upon notification. Instead, it appears that most businesses (judging by the statistics) would rather keep changing their door locks to the coolest ones they can find at RSA each year, while insisting on leaving all of their windows open.

This is a clear indication that business would rather intentionally favor continuity of application and network connectivity and availability over security. I guess that’s a choice one could make, but so is unemployment.

How about instead, if one is so determined to continue introducing known vulnerabilities, we at least couple those acts with proactive security best practices so that access can be managed and minimized and even eliminated where it is unnecessary.

I can’t believe I just wrote that.

It’s like saying to a Fentanyl addict, let’s go ahead with those daily injections, but at least let me clean the syringe in between pops.

要查看或添加评论,请登录

Steve King, CISM, CISSP的更多文章

  • Connected Device Security: A Growing Threat

    Connected Device Security: A Growing Threat

    Many cybersecurity analysts have warned of the rapidly emerging threat from an expanded IoT space. And as you have…

    3 条评论
  • China’s Ticking Time-Bomb.

    China’s Ticking Time-Bomb.

    It should now be clear to even the casual observer that China has been spying on us for years and stealing reams of…

    7 条评论
  • Comparing Major Crises To COVID-19: A Teachable Moment

    Comparing Major Crises To COVID-19: A Teachable Moment

    Lessons from past financial crises might prepare us for the long and short-term effects of COVID-19 on the economy and…

  • The Escalating Cyber-Threat From China

    The Escalating Cyber-Threat From China

    A Modern-day Munich Agreement In an article penned back in May of 2015 in a policy brief published by the Harvard…

    1 条评论
  • Cybersecurity: Past, present, future.

    Cybersecurity: Past, present, future.

    We have made a flawed assumption about cybersecurity and based on that assumption we have been investing heavily on…

    15 条评论
  • Three Marketing Tips for Improved Conversion Rates

    Three Marketing Tips for Improved Conversion Rates

    While we are all devastated to one degree or another by this outbreak and with the knowledge that it will likely change…

  • Coronavirus in the Dark.

    Coronavirus in the Dark.

    So, yes. It is now very clear that the outbreak of the COVID-19 virus and the concomitant investor panic leading to a…

    13 条评论
  • Panicky Investors Issue Dire Warning On Coronavirus

    Panicky Investors Issue Dire Warning On Coronavirus

    Sequoia Capital just issued a dire warning to its portfolio companies. “Coronavirus is the black swan of 2020.

    5 条评论
  • AI in Cybersecurity? Closing In.

    AI in Cybersecurity? Closing In.

    "AI Needs to Understand How the World Actually Works" On Wednesday, February 26th, Clearview AI, a startup that…

    8 条评论
  • Do CapitalOne Shareholders Have a Case Against AWS?

    Do CapitalOne Shareholders Have a Case Against AWS?

    An adhesion contract (also called a "standard form contract" or a "boilerplate contract") is a contract drafted by one…

    1 条评论

社区洞察

其他会员也浏览了