It's interesting that those cable cars in Switzerland get more frequent and in-depth inspections.
It's a management problem, but it's also a problem because the people responsible aren't doing a good job convincing management. Which is why I think enginners/sysadmins/devs who have the ambition should start getting mbas and going for the CTO/CIO position... which is the main executive position (if it even exists) failing.
It's also why I'm working on my data science degree now. Execs don't like you, they don't trust you, and they generally don't listen well... but they love numbers and pretty graphs!
But if I was an executive or shareholder? Why would I care? We've seen time and time again how data breaches are just a blip in the stock price, the government doesn't punish anyone for negligence, and if someone manages to take serious money from you the government will go after them on your behalf. Security is expensive, and the odds of you having a breach that actually hurts you for more than a short period seem astronomically low.
We have more businesses saying they are shutting down or leaving the EU market over the fact that they can't take user data without permission than we have shutting down because they leaked all their users data or let hackers in through complete negligence of any modern security practices
The thing to remember is one side cannot fully ever take out the other.
On SWIFT, yes, you can, thanks to their own reply to the Bangladesh incident: a reasonably thorough set of security guidelines called CSP/CSCF (Customer Security Program/Control Framework), compliance to which is now mandatory. Network isolation, 2-factor authentication, secure VDI for access, physical access controls, log retention, it's all in there. It's the perfect chance to get money and people from management and sanitize the situation.
Actually if in May 2018 you don't already have a running project and resources for compliance, you should be quite worried.
https://www2.swift.com/uhbonline/books/a2z/customer_security...
is there a openly published version of this - it would be interesting to see what best practise looked like
https://www.swift.com/myswift/customer-security-programme-cs...
I actually run my local firewall in addition to the network one (to which I have no access) and am toying with a WAF I'm adding to the picture, gradually tightening the ruleset.
Just one question: AGS = SAG? I've never seen it written like that.
Folks then have to log off the restricted network and onto the wifi to run simple processes that require data that is inaccessible through the cabled network.
The potential for abuse by an intruder is obvious.
[1]from my own experience as an IR+Red team guy.