Bugwatch: Common sense security

The tightest IT security measures aren't always the best ...

Chris Barling

This week Chris Barling, chief executive officer of Actinic, calls for more trust in IT security and less dependence on overzealous safety measures.

A few years back, I was working on getting investment into our business. We had big problems with the lawyer from the other side, who kept raising objections. The issue wasn't that her points were invalid; they just weren't material. In other words, they were unlikely to cause problems for their investor.

Advertisement

This might seem a million miles away from security issues, but I think it can illuminate similar dilemmas in computer security.

IT security professionals aim to protect their companies and clients from harm, but the tightest security is not necessarily the best.

Let's use the airline industry as an example. There's been a lot in the press recently about the US demand to put armed marshals on transatlantic flights. They can tackle hijackers, so they must improve security, right?

But there are downsides too. What happens if the bullets cause some critical damage to the plane? Attempts to improve security can sometimes backfire. And the same principle applies to IT.

Forcing passwords to be at least eight characters long, changing them every month and never allowing them to be reused are good security policies, aren't they? Well, maybe not, if a significant number of confused users stick their passwords to their screens using post-it notes.

Others may end up phoning the help desk with their password problems, which can create an environment where a confident hacker is able to blag a new password by asking the help desk.

Sometimes well-intentioned actions can have unexpected side effects. Taking an example from my own company, we have a number of employees working from home. One left some time ago, but we were still being charged for their ADSL line. When we tried to cancel it we couldn't, because we weren't quoting their security code, which we did not have and could not get.

Of course, the line was cancelled eventually and the charge credited, but not before BT had totally destroyed its relationship with us, losing our future business.

Despite what some security-conscious people might think, the truth is that business relies on trust. Whenever I give my credit card details out over the phone or the net, I am exercising trust.

I'm doing the same when I hand over my credit card in a restaurant. I do the same when I ask a plumber to visit my house. If at every stage I had to totally validate every aspect of my business dealings, it would be unworkable.

That's why we are so outraged when people exploit this trust and fail to deliver.

It's why Watchdog is a popular TV programme. Most of us feel that the perpetrators of the scams should be sent to jail, the key melted down and sold to recover some of the losses they caused. We hate trust-breakers because if everyone was like them, our society couldn't operate.

My investment deal was almost broken by the overzealous lawyer. Of the many investments made by that investor, ours was the only one that made them money. Yet it was threatened by a specialist doing their best, who put being 'right' as their top priority, when being pragmatic was the better option.

In these days of out-of-control viruses, worms and other exploits, we still need to apply a common sense approach to security. Wooden zealotry too often ends up achieving the opposite.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

How to sell - A movable feast

The explosion in wireless technology and employee mobility has had a major knock-on effect in the security market. CRN looks at the new dangers ahead

How to sell - Protection money

With security now a factor in every area of IT the reseller is ideally placed to take a leading role in defending the end-user. Paul Bray writes the first of five CRN reports on this crucial market

Humans to blame for security breaches

84 per cent of breaches caused by human error, survey finds

Security vital to successful remote working

Threats to the safety of wireless networks call for serious measures, writes Lindsay Nicolle.

Related whitepapers

Related jobs

Most watched

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Summit: Salesforce.com on SaaS and information overload

How web services contribute to data headaches

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Fingers on keyboard

New Flash vulnerability discovered

Web sites could be vulnerable to Flash attacks

Chris Adams

Summit: Microsoft Office to the rescue

Chris Adams, Office Client product manager for Microsoft UK, explains...

Illegal downloader

Industry and human rights campaigners united in opposition to "three strikes" plan

Critics says government proposals to curb illegal downloading are unworkable...

Primary Navigation