Failures of the security industry: Accountability and action plan


The information security industry is losing the cyberwar. Make that cyberwars. Plural. Black hat “hacktivists,” organized crime syndicates, state-sponsored operatives, terrorists, and other threat actors attack computer systems and critical infrastructure on multiple fronts across the globe with seeming impunity. Motivations and objectives vary. The common thread is malicious intent. Backed by alarmingly sophisticated skills and deep resources, these 21st century intruders frequently succeed in attaining their objectives. But, it is not only the sophisticated that succeed. Often, perpetrators with more persistence than acumen are able to exploit weaknesses. Enterprises unwittingly provide broad attack surfaces with inadequately secured or completely vulnerable points of entry. Whether targets of adept cyber saboteurs and criminals or of their own lack of preparation and investment, victims of cyberattacks sustain damages that range from isolated annoyance to devastating, expansive…and expensive.

The adverse financial impact alone is staggering. Factor in how the relentless barrage of cybersecurity breaches weaken the security of sovereign nations, stifle innovation, lower consumer confidence and threaten public safety, and the magnitude of the problem is truly intimidating. Cybercrime hurts the global economy.

