Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

1/25/2012
01:56 PM
Mike Rothman
Mike Rothman
Commentary
50%
50%

Looking Over The RIM And Into The Chasm

What security folks need to learn from RIM's stunning downfall

If you've been too focused on fighting fires all week, you may have missed the big news in the mobile space. No, not that Apple sold 37 million iPhones and 15 million iPads. Founders and co-CEOs of RIM (Research in Motion) stepped down. Even better, they went all the way down the hall to find their successor. COO Thorsten Heins was named to the CEO post, and his first public statement was: "I Don’t Think There Is a Drastic Change Needed."

Really? RIM has been executing so well that vultures have been circling around its carcass for almost two years. We don't track market share or anything, but you know it's hard to restrain that chuckle when you see some poor sap pull out a BlackBerry nowadays. You probably ask whether his new iPhone or Android is on order. If not, he grumbles something about still being on Windows XP and how his IT group isn't quite on the cutting edge.

To be clear, this isn't about RIM --in my Ivan Drago voice, "If they die, they die" -- it's just sad to see a company that was a true innovator with huge momentum refuse to acknowledge market realities, refuse to change, and then move so slowly once it decided it had problems. HP basically gave up, as it couldn't rescue WebOS. This game is over, and RIM lost. Oh, well. But there are a couple of very instructive lessons that we security folks need to pay attention to, or face a similar fate.

The first is the need to evolve with the times. For a long time, the fairly rudimentary defenses we had were good enough. You know: keeping your devices patched, your AV up to date, and your network ops team from screwing with the firewall and IDS too often. But then things started to change, and far too many security folks have been too resistant to change with them.

The attackers aren't going through the front door anymore. They use your people against you through novel social-engineering attacks. They use your developers against you by taking advantage of holes in your code. They attack your security vendors to be able to bypass the products you buy from them. Yet far too many security folks get excited by that firewall upgrade, or getting their hands on the newest version of the endpoint suite, which sucks less than the last one. What worked in the past won't work in the future.

Not that we can turn away from these traditional security controls. Due to both compliance mandates and script kiddies, we're still forced to keep these products in use and will for the foreseeable future. But those controls aren't enough. You have to roll with the tides and understand your controls are insufficient. You need to look at new technologies (like network-based malware detection), address the soft spots (database and application security), and focus on detection and response. You already are compromised -- the question is whether you know it yet.

Second, sometimes you need new blood. RIM seemed to take the easy path and just promote someone who was involved in the fiasco that company has become. Sometimes that has worked out, but there are very few examples of that. Be brutally honest about your situation. Do your IT and security leaders continue to be tone deaf to what's going on around them? Are they more concerned with their fiefdoms than in asking the tough questions that need to be asked? If so, then maybe it's time to figure out whether you can be successful in your job. We've all seen that movie before, and it is usually someone other than the senior folks to take the fall, at least the first couple of times.

There will be another job, just like there was another smartphone to step in when RIM couldn't evolve fast enough. The best thing you can do as a practitioner is to stay focused on what you need to do and make an assessment regarding whether you can be successful. When it's clear you are destined for failure, pack up and move on. The last thing you want is to still be on the ship as it runs aground. Falling into the lifeboat doesn't sound very good during your next interview.

Mike Rothman is President of Securosis and author of the Pragmatic CSO. Mike's bold perspectives and irreverent style are invaluable as companies determine effective strategies to grapple with the dynamic security threatscape. Mike specializes in the sexy aspects of security, like protecting networks and endpoints, security management, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RichieB
50%
50%
RichieB,
User Rank: Apprentice
1/25/2012 | 9:34:03 PM
re: Looking Over The RIM And Into The Chasm
I second the point about innovation, and RIM promoting the COO to CEO is probably a bad move. But this is Dark Reading and BlackBerries are still the only phones today that I will let near our corporate E-mail. All the other alternatives simply can't touch the secure-by-design appoach of RIM. When you loose a locked BlackBerry, there is no known method for an attacker to read it's content. Loose a locked iPhone or Android, an attacker can get to the data on it quite easily.

I hope RIM will stay afloat at least until the other vendors get it right.
Why Cyber-Risk Is a C-Suite Issue
Marc Wilczek, Digital Strategist & CIO Advisor,  11/12/2019
Unreasonable Security Best Practices vs. Good Risk Management
Jack Freund, Director, Risk Science at RiskLens,  11/13/2019
6 Small-Business Password Managers
Curtis Franklin Jr., Senior Editor at Dark Reading,  11/8/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-18986
PUBLISHED: 2019-11-15
Pimcore before 6.2.2 allow attackers to brute-force (guess) valid usernames by using the 'forgot password' functionality as it returns distinct messages for invalid password and non-existing users.
CVE-2019-18981
PUBLISHED: 2019-11-15
Pimcore before 6.2.2 lacks an Access Denied outcome for a certain scenario of an incorrect recipient ID of a notification.
CVE-2019-18982
PUBLISHED: 2019-11-15
bundles/AdminBundle/Controller/Admin/EmailController.php in Pimcore before 6.3.0 allows script execution in the Email Log preview window because of the lack of a Content-Security-Policy header.
CVE-2019-18985
PUBLISHED: 2019-11-15
Pimcore before 6.2.2 lacks brute force protection for the 2FA token.
CVE-2019-18928
PUBLISHED: 2019-11-15
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.