"If we learned one thing following our breach 19 months ago, it's that all companies can be breached. What is important is the speed of detection and response, to minimise the window of opportunity for the attackers."
So said Art Coviello, RSA chairman, in an interview during the RSA Conference 2012 in London this morning.
"The breach definitely informed our strategy. We are engaging with customers at a strategic level as never before. They are interested in how the breach happened, how we responded, and how we did that so quickly; how we handled it and with what tools, what worked, and what didn't."
He said what the company has heard time and time again is "If it can happen to RSA, it could happen to anyone", and this has definitely driven a fresh awareness and a closer look at security strategies.
Coviello is of the opinion that it's not going to get any easier. "It's not a big surprise that this level of breach can take place. It's also a clear indication that perimeter defences are not good enough; we need a far more agile, intelligence-driven approach to security.
"Companies need to understand potential enemies, and what the potential targets are. What information needs protecting, and whether or not a breach on your organisation could in fact be an attack on a third party. We need to anticipate who will attack, what they're likely to go after, and be in a position where your response is closer to real time, instead of after the fact. This is the only way that you could minimise the damage should an attack take place."
He reiterated that there is an 'inertia' surrounding security budgets that is preventing effective controls from being implemented. "Security models are not moving from the perimeter-based to the intelligence-based quickly enough."
Coviello added that while there is plenty of awareness around security, what is lacking is understanding and context.
Giving advice to companies that have suffered a breach, Coviello says customers were impressed at RSA's speed of response. "Disclosure to those that could be affected is vital, and also a legal obligation. Bring in law enforcement. Gain a better and more thorough understanding of risk. Who might attack and why?
Ultimately, he says RSA was able to lessen the damage, and more importantly, advise its customers in time, so they could protect themselves to mitigate any risk.

