#4 I'm fine with, the CEO meeting on IT security quarterly sounds adequate to me. His involvement in IT security should not extend beyond ensuring policy is in place and being acted on. Quarterly is more than adequate to ensure this is being done.
#4 I'm fine with, the CEO meeting on IT security quarterly sounds adequate to me. His involvement in IT security should not extend beyond ensuring policy is in place and being acted on. Quarterly is more than adequate to ensure this is being done.
It's important to understand that because it's the reason why your bosses will never care unless/until they have an experience like this, or until they expect someone important to be looking for an opening (audits, due diligence, etc).
Second, there are indeed some clowns and cronies hired at these sort of places, but a lot of the people are decently skilled. I'm speaking generally about the workforce at these larger enterprisey companies, as I don't know anyone at Equifax afaik.
Technical competence is less of an issue than intra-managerial political games like "shift the blame" and "silo defense", at least some of the time. Part of "intra-managerial games" is having the least-skilled people in the most authoritative positions, leaving decision authority with those least equipped to evaluate a situation and determine a responsible response.
I am sure that there is someone at Equifax who saw the news on this vulnerability and registered it as being something they needed to patch. I wouldn't be surprised at all to learn that this person didn't say anything because they learned long ago that there's nothing to be gained by actually trying to get the patch done in any non-routine manner.
I also wouldn't be surprised to learn they did try to raise the alarm and were mocked and/or shut down, both by other technical groups trying to avoid the appearance of an issue with "their" section of the system, and/or by management, who are likely to interpret such attempts as alarmism, if not plain political malfeasance.
Hate to say it but we're on the brink of a formalized licensing program for security, servers, etc. I am honestly surprised that the mainstream outlets and politicians have not been touting this yet, with all the high-profile and extremely costly data security breaches that have been occurring over the last few years, but I really expect it to come soon. I wouldn't be surprised at all to see Equifax become the Enron-like scapegoat for such legislation.
Exactly. I'm reminded about the tale about the two hikers and the bear. Two hikers are out hiking one day, when off in the distance they see a bear running their way to attack them. One starts to run, but the other stops to change his hiking boots to running shoes. The other says: "What are you doing? You can't outrun a bear!". To which the running shoe changer replies: "I don't have to outrun the bear, I just have to outrun you".
Same goes here. Don't have to really spend on security, just enough to not actually be the one of the two (or three or four) who suffer a breach.
Open source vulnerability management is a technology process that has levels of maturity. That being said, a freeware tool could have spotted this right away.