The Tech Herald

2012 Predictions: Businesses reveal security breaches for compliance

by Torsten George - Agiliance - Dec 9 2011, 17:30

2012 Predictions: Agiliance

Prediction: New government mandates around cyber security will require businesses to reveal security breaches for full compliance, in turn sending them into a tailspin as they must find new ways to manage data around and report these attacks.


2011 showed record numbers of cyber security attacks and associated breaches with very public disclosures from Citigroup, the International Monetary Fund, RSA (The Security Division of EMC), Lockheed Martin, Google, Sony, ADP, and NASDAQ amongst the many. Government networks, critical infrastructure operators, and the private sector are facing an increasing frequency and sophistication of cyber attacks and breaches of information security -- often with discovery after the fact.

As a result, the U.S. House of Representatives’ Intelligence Panel  recently approved a bill to let U.S. spy agencies share intelligence on cyber threats with defense contractors and Internet service providers and the SEC issued a memo suggesting that corporations disclose all cyber attacks, showing that continuous compliance and allocation of resources in accordance with risk posture will be even more important for many federal-regulated organizations.

But the true question is – will these guidelines be helpful or harmful in the long-term?

I believe that these actions represent much-needed progress in the fight against cyber criminals. It is a common understanding among security professionals that collaboration among the good guys to outmaneuver the bad guys is a preemptive measure that has great potential to reduce the frequency and scope of hackers’ attacks.

While it will be interesting to see how the cyber security bill will enhance the risk posture of government agencies, defense contractors, and Internet service providers, the overarching question is whether the bill is wide reaching enough. Sharing sensitive threat information becomes essential in preventing widespread attacks across different verticals and industries.

At the end of the day, we have to understand that cyber criminals are coordinating their efforts and are well-versed in sharing vulnerabilities and attack methodologies. To counter them, government and private industry have to work hand-in-hand to quickly dissipate information about threats.

What collaboration can produce has been showcased by the strengthening and unifying of all government agencies to overcome the breakdown of intelligence data exchange after the September 11 attacks. Improvements in network consolidation, intelligence integration, and cross-departmental training can be contributed to the detection and subsequent killing of al-Qaeda leader and founder Osama bin Laden.

Collaboration isn’t easy. Often, movement can only be achieved by way of mandatory obligation. Although this cyber security bill and SEC memo is a move in the right direction, a broadening of the group that information will be shared with and regulations that mandate prioritizing security in the overall picture will really move the needle. As companies evolve to shift their outlook to risk-based security, to achieve full compliance, it will result in a safer, more secure network infrastructure.


The Tech Herald welcomes 2012 related threat predictions from vendors, as long as they do not reference the end of the world and remain product neutral. All submissions are subject to editing and are due by December 20, 2011. Submissions can be delivered to [email protected] with the email subject of 2012 Predictions.


Around the Web

Comment on this Story

comments powered by Disqus


Shelby GT350 Mustang Pictures

We have added a bunch of pictures of the all-new Shelby GT350 Mustang from Ford. The ne...

All-new Shelby GT350 Mustang

Ford have revealed details of the new Shelby GT350 Mustang. First introduced in 1965 the new...

Best Cars To Buy In 2015

Leading vehicle research company Kelley Blue Book has released its list of the best cars to ...

A.C. Milan Take On Audi R8

Five A.C. Milan stars take on an Audi R8 in a game of street soccer in a new ad for Toyo Tir...

Jaguar 2016 F-TYPE R Coupe All-Wheel-Drive

Jaguar has unveiled the 2016 F-TYPE R Coupe, the first to feature all-wheel-drive. The 2016 ...