Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

8/8/2019
06:30 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Equifax CISO: 'Trust Starts and Ends with You'

Organizational culture is key to good enterprise security posture, Jamil Farshchi told Black Hat attendees.

BLACK HAT USA — Las Vegas — One of the main takeaways from major data breaches like the one at Equifax in September 2017 is that organizational culture is fundamental to a good security posture, said Jamil Farshchi, the credit monitoring bureau's CISO, in a talk here today.

Farshchi was CISO at Home Depot when the breach at Equifax happened. He was hired at Equifax less than six months later and has been in charge of rebuilding the company's beleaguered security program. It's the same role he was called in to play at Home Depot following the 2014 data breach that exposed data on over 50 million payment cards.

"Equifax was meaningfully impacted right out of the gate," Farshchi said. The company experienced a 40% loss in market cap in the immediate aftermath of the breach. It also lost its CEO, CIO, and CSO and had over $1.25 billion in incremental transformation costs. Recently, Equifax also agreed to pay $700 million to compensate victims of the breach.

Incidents like these tend to focus a lot of attention on the immediate causes and less so on the underlying, systemic issues, he said. At a Senate hearing on the Equifax breach, for instance, many of the questions that Farshchi received were focused on technical issues, such as the company's patching processes, certificate management habits, and asset inventory-handling capabilities.

While all of the questions were meaningful and relevant, they did not touch on root-cause issues that often have to do with organizational culture and attitudes toward security, he said. "If you are looking at individual breaches, you are missing the bigger picture," he said.

Farshchi said his experience has shown that five things are key to having an effective security organization. First, the head of security or the CISO needs to have the ability to influence and drive change as required across the entire enterprise. Second, this person also needs to be able to regularly interact with the board of directors and senior leadership on security strategies and direction.

The third big driver is economic incentive. The organizations that are doing well at security tie economic incentives to the effectiveness of the security program.

Farshchi identified the fourth and fifth key factors to security success as risk management and crisis management. Security teams that conduct regular crisis management exercises with executive leadership and the board are often better prepared to deal with an actual one, he noted.

Security organizations need to have the ability to identify meaningful risks, and security leaders need to have the conviction to escalate concerns even if doing so means halting or delaying a business initiative, he said. It is absolutely critical for security groups not to just identify an issue but to do something about it, Farshchi said.

He noted a new "say/do" motto within his own organization that emphasizes the idea that if you say something, you absolutely need to deliver on it. "Trust starts and end with you," Farshchi said.

Related Content:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/2/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9498
PUBLISHED: 2020-07-02
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
CVE-2020-3282
PUBLISHED: 2020-07-02
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
CVE-2020-5909
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
CVE-2020-5910
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
CVE-2020-5911
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.