Comments
Target's Weak Points, Examined
Newest First  |  Oldest First  |  Threaded View
asksqn
100%
0%
asksqn,
User Rank: Ninja
3/27/2014 | 3:53:27 PM
Consumers Lose Again
This is the kind of breach consumers can expect from companies that don't actually hire anyone for the CIO position who holds any kind of knowledge, skills, abilities in security.  Beth Jacob, who resigned as the top dog (who was in charge of security and for noticing red flags) was a Director of Guest Contact Cente and later, VP.  Sadly, such positions that are big on "soft" skills does not translate into security of consumer data.
dak3
50%
50%
dak3,
User Rank: Strategist
3/19/2014 | 9:44:01 AM
Re: Culture of awareness
Exactly.

 

But if you do decide to lainch "pop quiz" type activity to test people on their training make sure that the powers that be are aware - unlike the army commander in this story....
dak3
50%
50%
dak3,
User Rank: Strategist
3/19/2014 | 9:41:24 AM
Re: Repeating Myself
Perhaps you mis-read how the FireEye system works - by comparing the live site to a known good private site. It flags changes and rates them based on a judgment of how dangerous they can be. The risk of a false positive is extremely small, and well worth that cost in preventing an attack such as took place.
rradina
50%
50%
rradina,
User Rank: Ninja
3/18/2014 | 9:00:07 PM
Repeating Myself
As I said in another post on this site, they turned off the automatic action because it's too risky to have a false positive whack all of your POS systems.  It might be OK for devices that aren't customer facing but call center, POS, ATMs and similar devices cannot be brought down because the vendor updated their product or a definition database that suddenly thinks the POS print driver is a virus.  It's happened numerous times over the years with enteprise AV products and it will happen again.

If Target has a SOC, the alert should be raised there with an automatic ticket.  The SOC should be required to close the ticket with a reason code.  That provides accountability and after that it's a people problem if they ignore it or close it with a nonsense reason code.

If the product is showering the SOC with alerts, then the configuration needs to be reviewed, the product needs to be replaced with one that works better or the alerts need to be routed to someting htat can mine the noise for valuable intel (like Splunk).
pfretty
50%
50%
pfretty,
User Rank: Moderator
3/18/2014 | 2:00:58 PM
Culture of awareness
As you point out, it takes a mix of technology, education, awareness, etc. to build a true culture of understanding. A culture that pays close attention to risks and takes action when needed.  According to the Ponemon 2013 Cost of Cyber Crime report (http://www.hpenterprisesecurity.com/ponemon-study-2013), the number of attacks continues to climb -- up 20 percent over the previous year.  And, at the same time, hacker sophostication continues to intensify.  Failing to build and support the culture could ultimately be catestrophic.

Peter Fretty (j.mp/pfrettyhp)

  


The Business of Going Digital
The Business of Going Digital
Digital business isn't about changing code; it's about changing what legacy sales, distribution, customer service, and product groups do in the new digital age. It's about bringing big data analytics, mobile, social, marketing automation, cloud computing, and the app economy together to launch new products and services. We're seeing new titles in this digital revolution, new responsibilities, new business models, and major shifts in technology spending.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Tech Digest - September 17, 2014
It doesn't matter whether your e-commerce D-Day is Black Friday, tax day, or some random Thursday when a post goes viral. Your websites need to be ready.
Flash Poll
Video
Slideshows
Twitter Feed
InformationWeek Radio
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.