Writing in Gold
Image generated via DALL-E

Writing in Gold

There's a quote which is deservedly well-known in health and safety circles. I've heard it multiple times over the years, and it carries an impact which sticks. It's been attributed to various people over the years, and finding the true source is not the point of this article.

"Those regulations are written in blood."

Another thing I hear more and more is that information security now is where health and safety was decades ago.

I'm sorry to say, that's untrue. In terms of maturity, maybe.

In terms of the future path of security? Not so much.

There's a fundamental problem. Health and safety progressed because enough people were directly harmed, and in some cases died, that there was a demand for improvement.

No matter what we may feel about the importance of information and cyber security, it is not life and death in enough circumstances to drive that level of demand.

Our regulations are not written in blood. The harms caused are too abstract to drive the same sort of movement, and that leaves us with a problem.

The simple fact is our regulations are written in gold. When information security breaks down, money is lost, and money simply doesn't have the same grip on humans as blood.

Regulatory frameworks are improving, but there's a limit to what fines can do, and there's little appetite to move beyond financial threats to try and enforce good behaviour.

Companies often see security risks as something to simply insure against, little more than a tax on operating as a business. Meaningful reductions of them, building secure systems and ways of working from scratch, takes effort and understanding that isn't seen as worthwhile - instead buying 'solutions' to patch over the cracks and insurance to cover the inevitable damage are the standard.

This is a problem, and it's one that will continue to worsen either until we change the narrative and generate sufficient demand for security, or until the damage gets bad enough that it becomes life-threatening.

I hope for the former, and there are organisations that work towards changing their systems, but most signs point to the latter.

If writing in gold isn't enough, then sadly writing in blood is inevitable.

要查看或添加评论,请登录

James Bore的更多文章

  • Boring On is Going Multimedia

    Boring On is Going Multimedia

    For those who follow my word of the day (and there are enough of you that it convinced me to keep it going) you've…

    2 条评论
  • Customer Insecurity

    Customer Insecurity

    I'm a big fan of taking lessons from one area of security to another, and a recent article about Walgreens[1] was too…

    3 条评论
  • The Thinking Trap

    The Thinking Trap

    We've all seen the posts about how AI can streamline research, accelerate papers, short-circuit decision-making, and…

    16 条评论
  • Can't Think Outside the Box Without a Box

    Can't Think Outside the Box Without a Box

    I recently had a brief conversation which gave me a full-on epiphany about why so many VC-funded, massively successful…

    8 条评论
  • Dropping the Ball

    Dropping the Ball

    It happens to everyone from time to time, both in personal and professional life, but it's much more noticeable when…

    3 条评论
  • Making Policy

    Making Policy

    One of the most common challenges we come across working with clients who have mature management systems is that they…

    3 条评论
  • Defining Objectives

    Defining Objectives

    Last week we talked about building the foundation of our management system - defining who we are and what we are as a…

    2 条评论
  • Starting Over

    Starting Over

    This is a bit of an experiment. We've decided to rebuild our BMS (Business Management System) from scratch.

    3 条评论
  • Informational Flak

    Informational Flak

    I did have another topic planned, but given what I'm already seeing out there this one seemed more timely…

    14 条评论
  • Deepfakes: Solving the Wrong Problem

    Deepfakes: Solving the Wrong Problem

    I first wrote about deepfakes back in 2019 in a textbook for Springer, and made a few predictions. Sadly the publishing…

    27 条评论

社区洞察

其他会员也浏览了