Just a day after I talked about how it takes sustained failures for consumers to leave a company and go to a competitor, we have an example where switching isn’t really an option.
Stepping between Hoff and Curphey.
Consumers always lie in surveys and claim that if a company loses their credit card or other personal info, they’ll go someplace else. In reality, they almost never do.
I haven’t met Richard Bejtlich yet, but I have a feeling we’d get along just fine. We’re both fans of the History Channel, have backgrounds in martial arts, love the show Human Weapon (martial arts AND the History Channel!), and have a background in the military (four years on a Navy ROTC scholarship, but I ended up becoming a paramedic instead of going active duty).
Over at the Network Security Blog, Martin’s been doing a great job of putting the CISSP certification (Certified Information Systems Security Professional for you non-security-geeks) in proper context.
If you’ve ever worked as a front-line security professional in any organization, at some point in time you’ve been asked what certification or standards compliance would guarantee security. Then, away from the office, you’ve probably directed countless friends and family members to protect themselves using some of the various anti-phishing toolbars like Netcraft, or those built into your antivirus suite.
As I mentioned just a couple days ago, there’s a bit of debate and confusion surrounding leak/loss prevention technologies and what the heck to call these things.
In a recent post at Security Ripcord, Cutaway says:
Let me elaborate on the second topic a little more. The days of hacking for fun are over. I think it is safe to say that nearly everybody has come to that realization (there may be a few holdouts in upper management but they will not last long). This means that the stakes are higher for the good guys and the bad guys.
No registration required anymore. If the trolls and spam get too bad I’ll have to turn it back on, but we’ll see how this goes… *[Email:]: Email *[Twitter:]: Twitter *[Phone:]: Phone
I’m still catching up on my blogroll, and caught this article over at Emergent Chaos, which also referenced this one by Thurston. Both articles discuss the infamous Ponemon study that claimed the average losses in a breach were $182 per record.
Read here, safe for work, but very disturbing.
Double entendre title fully intended. *[Email:]: Email *[Twitter:]: Twitter *[Phone:]: Phone