Friday, April 30, 2010

What Does a Security Breach Cost?

Someone finally assigned a dollar value for security breach that we can relate to. Not in millions or billions or gazillions, but in three figures - $204 per lost record. This is according to a recent report by the Poneman Institute. At 66%, loss of business is the biggest cost. Customers lose trust. Then there's the cost of spin to control bad publicity.

What can companies do to minimize costs? It helps to put a chief information security officer at the helm. It also helps to keep up to date on the most advanced firewalls and penetration software. There will always be someone who thinks he's a better hacker. Oh, and for those who like figures in the millions, the average cost to an organization is $3.43 million. The figure of $204 per record is for the U.S. because of notification laws, but the sum varies among nations. Read the Ponemon Institute's "2009 Annual Study: Cost of a Data Breach"
http://www.encryptionreports.com/.

Monday, April 26, 2010

Visa's M-Bet

Visa, meet CyberSource. More than 40% of online payments are done through Visa, and e-commerce is getting old. Cell phone companies are pushing smart phones because they can increase their revenues as we become increasingly tethered not only to our cells phones, but to our computers.

CyberSource, Visa needs you. At $2 billion, this is the largest amount of money Visa ever paid for anything. But, hey, Visa needs to compete with PayPal. As much as people complain about the fees, they know they're stuck with it if they want to buy something on eBay. M-commerce is not going away and CyberSource may even be able to serve those who refuse to embrace BlackBerry devices and iPhones.

Now it comes down to data protection. There will be be a new level of penetration tests those of us in IT security need to learn. I hope Visa doesn't skimp on this. Otherwise, they will be in the same embarrassing -- and costlier -- position as other financial institutions that decided to gamble on security. They ended up paying for "free" credit monitoring. It wasn't free for them.

Read more at:
http://www.nytimes.com/2010/04/22/business/22visa.html

Tuesday, April 13, 2010

Toast

Yesterday's article in The New York Times about concern over nuclear arms in Asia is long overdue. This is something that I have been concerned about for years. Any American company that has a data center in India could be toast. This risk is bigger than the ones many financial institutions have taken by not allocating money for better security domestically. How many times have you heard that a particular company will offer its customers free credit monitoring for a year because their data has been compromised. That's nothing compared to the potential physical meltdown of a company's data center. As an investor, I worry about that.

There are backups, but that may be too little too late in this scenario. It wasn't just jobs that have been outsourced to India; it's security. It's a company's lifeline. Whatever money the company has saved by not upgrading firewalls and penetration software and by hiring cheaper labor overseas and temporary workers domestically can be gone in one explosion. Not a pretty picture and that's without even thinking about the consequences to the land and to people's health.

Thursday, April 8, 2010

iAm Not Surprised

The initial excitement over the iPad is beginning to settle down. Apple is, without a doubt, the most innovative company when it comes to visual design, applications and marketing. A few people will admit to buying Macs because of their seductive designs, but the majority justify buying the overpriced hardware because they think that Macs are flawless, never crash and never get viruses. Those are myths, something my wife, who has worked on one for years at a newspaper, can attest to that. My main complaints against Apples are the pricing, which I think is exorbitant in comparison to PCs which are equally good for graphics and the fact that PC desktops are expandable.

But I digress. The point of this blog is to address the first issue that has come up with the much-hyped iPad. There's a problem with the WiFi connection. You would think that the company did better testing, but at least it can be fixed. That said, I'd be livid if I spent all that money and it didn't work. One of my pet peeves is when sales people don't know enough about a product, you buy it and then have to return it because no one mentioned that the product doesn't work with your standard software.

I am a very cautious consumer. I've always embraced new technology, but at arms length at least until the second generation came out to remove the bugs from the first one.

Friday, March 12, 2010

Can Software Avoid Fraud?

With the recent 2200 page report about the accounting gimmicks at Lehman Brothers, it's worth looking at the merger of EMC and Archer Technologies. I'm not suggesting accounting fraud. On the contrary, the merger should take Archer's SmartSuite financial data security and EMC's own services from RSA Security Practice and boost standards and compliance to the next level. The Virtualization and Private Cloud Security services are supposed to assess secure virtual desktops and private clouds. A Fraud Assessment and Strategy offers recommendations to mitigate risk. A Risk Operations Service helps companies build security centers.

It isn't easy to create a corporate entity that's in the league of companies such as Lehman Brothers, Enron, MCI WorldCom or others that fell after accounting scandals, but it is possible to nip problems in the bud. You need ethical management and auditors. But it also helps tremendously to plug security breaches. All you need is vulnerability and one sticky fingered employee or financial whiz who thinks he can razzle-dazzle upper management by falsifying data, and you've got a potential disaster.

A new survey by the Ponemon Institute and Guardian Analytics found that 55% of businesses admitted that they have experienced fraud in the past year, with 58% enabled by online banking. A full 80% of banks failed to catch the fraudulent transactions before the funds were transferred out. Slightly more than one quarter of these companies were not compensated for their losses. The bottom line is that cybercrooks are targeting online bank accounts of small and medium-sized businesses and financial institutions are not protecting their customers' assets.
While new technologies such as virtualized data centers and cloud computing are exciting and are supposed to be cost-effective, they carry additional security and risk management issues. Companies cannot wait for auditors to identify weaknesses. There must be constant automated analysis and encryption of information from multiple sources. Who can benefit from such a product? A credit card processing company such as First Data, which is testing TransArmor. It will be able to take card numbers out of merchants' point-of-sale systems just as a transaction occurs. The software encrypts the data credit card companies and card-issuing banks for approval. Stores won't have to worry about protecting their customers' credit card information.

As an investor, I look forward to the potential of other software development that makes me feel confident that when the auditors sign their standard statement in a company's annual report, the figures are indeed accurate and that my investment won't go the way of Enron.

Wednesday, March 10, 2010

Cloudy or Sunny?

There's a lot of buzz lately about cloud computing. While it sounds like a new and improved way of forecasting the weather, the people at The Weather Channel have nothing to worry about.

Cloud computing is basically anything which involves delivering hosted services over the Internet, such as IaaS (Infrastructure-as-a-Service), PaaS (not Easter eggs, but Platform-as-a-Service) and SaaS) Software-as-a-Service (SaaS). Computer people like cute and catchy names, and this one comes from the cloud symbol that represents the Internet in various flow charts and diagrams.

So what does this really mean? The whole point of the Internet is to deliver services efficiently. If it's a public cloud, it sells to anyone and everyone. Amazon.com is a public cloud. There are private clouds which are proprietary, such as a hospital portal that allows access only to doctors who are affiliated with that hospital. What's really key about cloud computing are the forces that are driving it.

Microsoft is seriously looking at a new way for large corporations to buy MS Office under a new license called "Union." It would charge companies the same amount for software whether it is hosted on-site or in the cloud. SD Times reported that this new license would address various degrees of software usage. Regular and heavy users may require an on-premise server version. Light users may be able to use a version that is hosted by Microsoft. The "Union" bundle might combine Office 2010 (which is currently in the beta stage) with office web applications and store it from Sharepoint Online. It sounds, well, nebulous, but it's all about the money. Microsoft is hoping to maximize revenue without driving customers to seek inexpensive or free solutions.

More small and mid-size banks are paying considerable attention to cloud computing because it may be cost-efficient for regulation, compliance and security. Accessibility is also a driving force. Yet a survey by the think-tank, The Financial Services Club, reported that 37.9% of retail banking firms are not even considering cloud computing, in part because they are unsure of what it is. A survey by Wall Street & Technology found that that 12 percent of executives in the capital markets are dismissing cloud computing as a marketing gimmick.

The bottom line is that until there is more evidence for effective cost-cutting and until more large companies use it, cloud computing is remain a niche for people in IT. A word to the wise: Learn!

Monday, March 8, 2010

Two, Four, Six ... Eight?

Most consumers are happy with duo-core processors. Bump up a computer to dual-quad and they're even more thrilled with the performance. But the news that Intel will soon launch six-core processors has people like me higher than a kite. The "Westmere," which sounds like a luxury real estate development, is expected to be out by the end of the month. Advanced Micro Devices is trailing slightly behind with its Phenom II X6. The Westmere is not the first six-core chip from Intel, but the Core i7-980X is targeted for dual-socket platforms and more advanced than the six-core Extreme Edition chips, which is based on 32-nanometer process technology. Hyper-threading will, for all practical purposes, double the number of threads executed per core. Pricing? Just over a thou and you need 12MB of memory on your computer. Some industry experts think it's overkill for most people. But then, didn't Bill Gates once say that no one will ever need more than 640MB of hard drive? Westmere, Eastmere. Phenom. Extreme. Whatever the name, they'll set new standards.