Are we getting better? Why, we don't know. What can we do about it? These were the questions asked by Joshua Corman, director at Akamai Technologies, during his keynote at RSA Conference 2012, in London.
He believes we are not getting better, or perhaps we are, but the situation is getting worse, which negates any improvement. "Change is constant; we are faced with evolving compliance, threats, technology, business and economics.
"There are more breaches than ever. We are facing more adversaries. However, we seem to be ok with this, as we usually have someone to blame."
Unfortunately, Corman said we are increasingly dependent on technology. "We run Windows systems on cars; we have medical devices such as insulin pumps that can be hacked to deliver a fatal dose - these days, software equates to vulnerability."
He said security budgets have traditionally been allocated to investigating the attacker, and how he or she operates. These days, we are focusing on meeting regulations; covering ourselves, as it were.
"We are more interested in being compliant, and not getting into trouble than on actually defending ourselves. Our focus has shifted from real security."
Corman added that exploits such as SQL injection are still there, and are still responsible for many, many attacks, and posed the question: "Why has this not been resolved?" Too many issues we've had for a long time have not been fixed. SQL injection exploits have been around for 13 years.
"This calls for a shift from faith-based to evidence-based security," added Corman.
He said there is also too much focus on replaceable data. "We focus on the things that are visible, not those that are important. Much like a drunk leaning on a lamppost; it's a matter of support, not illumination. We use data to reinforce our views and the messages we want to communicate, rather than to show the real picture."
Real security calls for four really important elements: defensible infrastructure, operational excellence, situational awareness, and lastly, counter measures.

