News: 1710746954

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Infosec teams must be allowed to fail, argues Gartner

(2024/03/18)


Zero tolerance of failure by information security professionals is unrealistic, and makes it harder for cyber security folk to do the essential part of their job: recovering fast from inevitable attacks, according to Gartner analysts Chris Mixter and Dennis Xiu.

In their keynote at the firm's Security & Risk Management Summit in Sydney, Australia, today, VP analyst Mixter and director analyst Xiu argued that no amount of effort can prevent infosec incidents, and the quality of organizations' response is a more appropriate measure of an infosec team’s effectiveness than expecting they will never fail to fend off the never-ending torrent of attacks.

"Adrenalin does not scale," Xiu told the event – a reference to the practice of infosec teams responding to incidents by attacking them without a rehearsed plan.

[1]

Relying on adrenaline also means the business assumes infosec teams are capable of heroic effort, motivated by the fear that cyber attacks create personal consequences of being fired or even prosecuted.

[2]

[3]

"We cannot allow this persecution mindset to persist," Xiu argued. "If we do our mindset will not change."

Mindset change is needed, the pair contend, because most organizations are immature in terms of their incident response capabilities.

[4]

The two analysts therefore counselled infosec pros to work with the business, to develop recovery plans based on tolerable impacts, as doing so helps infosec teams to prioritize investments.

When incidents occur, those discussions also make it easier to explain the infosec team's response – which could include a recommendation to take down systems that have not been impacted. Such recommendations will likely generate pushback, but preparing the ground makes it easier to handle such objections.

The pair recommended extensive rehearsal for recoveries – especially for incidents caused by third parties, as they are the root cause of most cyber attacks.

[5]

Developing recovery playbooks and practising their execution will help to keep infosec teams effective – by making heroic action less necessary and by allowing cyber security practitioners to follow processes they have rehearsed.

[6]SolarWinds slams SEC lawsuit against it as 'unprecedented' victim blaming

[7]British Library begins contacting customers as Rhysida leaks data dump

[8]Clorox CISO flushes self after multimillion-dollar cyberattack

[9]Desktop GPU shipments jumped by a third – no thanks to AI PCs

Better mental health can result, they argued. And in a later session, Gartner's senior director of research – and content leader of its cyber security research team – Christine Lee did likewise.

Lee characterized burnout as a debilitating state that leaves workers unable to do their jobs – not mere tiredness. She said infosec workers can experience post-traumatic stress disorder after responding to incidents and become prone to health issues.

She therefore suggested that incident response plans must create at least two teams who work on strictly defined shifts, so that incident responders get proper rest. She also advocated for chief information security officers to be trained to detect signs of stress so they can manage incident response teams more effectively. Lee also advocated for mental health debriefs to become part of post-incident assessments.

In another conference session, senior principal analyst Alex Michaels suggested infosec teams could even consider hiring behavioral psychologists to help them understand the mental state of their staff and attackers. Doing so, he proposed, could even help orgs to overcome shortages of staff with infosec skills.

Perhaps counterintuitively, Mixter and Xiu called for infosec teams to acknowledge more incidents – a conscious inversion of the "days since last incident" metric used to indicate observance of safety procedures in many industries. The analysts said that reporting even small events can see teams take pride in being able to continuously, and calmly, cope with infosec issues.

It also creates more opportunities to hone their recovery routines, which in turn means more opportunities to innovate – demonstrating that the org is constantly working to improve cyber security and is not deserving of censure when incidents emerge. ®

Get our [10]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZfgeyKkj@KBlRikOhxL4tAAAAQo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfgeyKkj@KBlRikOhxL4tAAAAQo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfgeyKkj@KBlRikOhxL4tAAAAQo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZfgeyKkj@KBlRikOhxL4tAAAAQo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZfgeyKkj@KBlRikOhxL4tAAAAQo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2024/01/29/solarwinds_sec_lawsuit/

[7] https://www.theregister.com/2023/11/29/british_library_begins_contacting_customers/

[8] https://www.theregister.com/2023/11/16/clorox_ciso_washes_out/

[9] https://www.theregister.com/2024/03/06/desktop_gpu_shipments/

[10] https://whitepapers.theregister.com/



Infosec is one of the hardest IT domains there is

Pascal Monett

I really think Infosec the hardest area one can work in in IT. You need to juggle with the needs and demands of users and management, while stitching together the failures of the products you didn't choose to use to try and ensure that miscreants inside and out won't make a total dog's breakfast of the whole network.

And every time Borkzilla posts a new update, I'm guessing you just cringe and hope for the best . . .

If all incidents are inevitable..

James 139

..and infosec personnel are working under the "do your job or be fired", shouldn't the same threat apply upwards in the chain?

If something was requeated to mitigate, minimise or prevent an incident, yet was denied by managers, accountants or even the board, the oft applied "the expense doesn't justify it" excuse, aren't they responsible too?

You go slow, be gentle. It's no one-way street -- you know how you
feel and that's all. It's how the girl feels too. Don't press. If
the girl feels anything for you at all, you'll know.
-- Kirk, "Charlie X", stardate 1535.8