> Security and privacy may become an essential product offering.
So I used to think that this was an issue of unknown unknowns, but I'm now of the opinion that it is an issue of OPSEC valuation. Experience is the best teacher when it comes to a thing's true value. Story time:
I'm sitting in a conference room with a bunch of DBAs, a few network guys, some programmers, a couple of managers and a logistics guy. When the bullet point on customer mailing address correctness comes up - the action item is quickly assigned: price out services that offer a REST API. The network guy that usually wears the infosec hat insists on SSL for incremental, SFTP for bulk batches. On to the next bullet point, casual Fridays. I ask if we really want to broadcast the mailing addresses of our customers, and how much work are we willing to do to accomplish the task in house. Pushing through the blank stares, I ask how much would we pay for such information on one of our competitors - not only for sales leads but also second order strategic information like acquisition rate, campaign activity related to targeted markets and demographics, etc. I see glimmers of recognition on only two faces: the infosec hat and the logistics guy. The logistics guy makes it clear that such an information leak is unacceptable.
Now the reason why the infosec hat got it is obvious, the news is full of third party breaches. The logistics guy got it because he was prior military, where OPSEC is highly valued and experiences related to costly lapses are pretty unpleasant (ranging from public shaming due to a lost crypto key loader, to a friend being shot in the face while smoking at night).
While I'm glad that corporate America doesn't ape the military in everything, I do wish they'd do something approaching what the military did for software acquisition prior to the massive shift to COTS:
So I used to think that this was an issue of unknown unknowns, but I'm now of the opinion that it is an issue of OPSEC valuation. Experience is the best teacher when it comes to a thing's true value. Story time:
I'm sitting in a conference room with a bunch of DBAs, a few network guys, some programmers, a couple of managers and a logistics guy. When the bullet point on customer mailing address correctness comes up - the action item is quickly assigned: price out services that offer a REST API. The network guy that usually wears the infosec hat insists on SSL for incremental, SFTP for bulk batches. On to the next bullet point, casual Fridays. I ask if we really want to broadcast the mailing addresses of our customers, and how much work are we willing to do to accomplish the task in house. Pushing through the blank stares, I ask how much would we pay for such information on one of our competitors - not only for sales leads but also second order strategic information like acquisition rate, campaign activity related to targeted markets and demographics, etc. I see glimmers of recognition on only two faces: the infosec hat and the logistics guy. The logistics guy makes it clear that such an information leak is unacceptable.
Now the reason why the infosec hat got it is obvious, the news is full of third party breaches. The logistics guy got it because he was prior military, where OPSEC is highly valued and experiences related to costly lapses are pretty unpleasant (ranging from public shaming due to a lost crypto key loader, to a friend being shot in the face while smoking at night).
While I'm glad that corporate America doesn't ape the military in everything, I do wish they'd do something approaching what the military did for software acquisition prior to the massive shift to COTS:
https://en.wikipedia.org/wiki/MIL-STD-498