Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

7/18/2012
02:26 PM
50%
50%

Risks Deferred Are Risks Accepted

Decisions to delay compliance and security efforts do not delay the risks

The client did something I’ve seen many times before. The staff considered addressing obvious compliance and security issues, and then decided to postpone that work. While they said they were simply going to push the work back a few months, as typically happens, the postponement became indefinite.

Or perhaps more accurately, the postponement will be indefinite until a costly problem exposes these ignored risks as real, costly and immediate.

Like most clients, they claimed a number of reasons to postpone this work: cash flow, timing, budget restrictions, pending new projects, disruption to other projects, and the time required by management and staff.

Sounding sincere about their need to address these compliance and security issues, clients say, “This is going to be a lot of work, and we need to take care of other matters first so we can better focus on this with less distraction.”

Yet despite claiming to believe compliance and security work is important, clients usually minimize their concerns about risk. After all, they say, as they’ve grown their business, the risks have never materialized, and they really need to put their cash into the growth of the business.

As a business owner, I realize there are times you must make risky decisions. I know there are times where you do have to postpone important work because of something as simple as cash flow or lack of manpower. However, these risky decisions should be made with a sincere evaluation and acceptance of the risks, not by turning a convenient blind-eye and manufacturing emotional justification.

Too many leaders become overwhelmed by the size of the risks they have created -- or allowed to be created -- over time. When these issues become obvious, for whatever the reason, the most common response unfortunately is not to attack these risks full-blast or even to start whittling them down. No, the most common response is to push all these risks into the back of a dark closet where they can be ignored, where they can be put out of sight and out of mind.

Business leaders who decide to defer addressing real security and compliance risks must understand they are essentially self-insuring this risk. They have accepted the risks, even if that acceptance is by default or denial.

If a problem develops from these ignored compliance and security risks, it will be the business that pays the cost, whether it be cash, distraction, reputation, and, perhaps even, sanctions. Perhaps some risks are worth taking, but in most cases I see few leaders acknowledge the true risks and actual consequences. Apparently ignorance is bliss even when the ignorance is by choice.

Glenn S. Phillips, the president of Forte' Incorporated, works with business leaders who want to leverage technology and understand the often hidden risks within. He is the author of the book Nerd-to-English and you can find him on twitter at @NerdToEnglish.

Glenn works with business leaders who want to leverage technology and understand the often hidden risks awaiting them. The Founder and Sr. Consultant of Forte' Incorporated, Glenn and his team work with business leaders to support growth, increase profits, and address ... View Full Bio

 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/3/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
Browsers to Enforce Shorter Certificate Life Spans: What Businesses Should Know
Kelly Sheridan, Staff Editor, Dark Reading,  7/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-17366
PUBLISHED: 2020-08-05
An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation ".roa" files or X509 Certificate...
CVE-2020-9036
PUBLISHED: 2020-08-05
Jeedom through 4.0.38 allows XSS.
CVE-2020-15127
PUBLISHED: 2020-08-05
In Contour ( Ingress controller for Kubernetes) before version 1.7.0, a bad actor can shut down all instances of Envoy, essentially killing the entire ingress data plane. GET requests to /shutdown on port 8090 of the Envoy pod initiate Envoy's shutdown procedure. The shutdown procedure includes flip...
CVE-2020-15132
PUBLISHED: 2020-08-05
In Sulu before versions 1.6.35, 2.0.10, and 2.1.1, when the "Forget password" feature on the login screen is used, Sulu asks the user for a username or email address. If the given string is not found, a response with a `400` error code is returned, along with a error message saying that th...
CVE-2020-7298
PUBLISHED: 2020-08-05
Unexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call.