Re: [fw-wiz] SCADA (or: How I learned to love receiving FWW in digest form)

Dotzero wrote:
would Marcus' artist friend agree to a 10% or 20% increase in his
utility bills to have "proper security" (however one defines this)?

Wait a minute!! It was properly secure BEFORE.
In fact, had to have SPENT MONEY to make it worse.

Someone, someplace, put it into a less secure state
"to save money" or "for business reasons." What we're
seeing is that their cost/benefit analysis was wrong;
it didn't save as much as they thought (because they
did it wrong!) or, if it recouped enough on the
investment, then any additional security expense
comes out of that profit/benefit's margin.

Let me belabor that point a bit: security is often
seen as a bill that gets presented; a cost of doing
business. What they don't understand is that the
bill is just interest coming due for when they cut
some corners years ago. A break-in or disaster is
that interest, compounded.

This is one reason I am (obviously) highly skeptical
of many business justifications. They omit to take
hidden costs into account and then try to shift/blame
someone else for them later. It's very easy to see
something as a profitable and desirable activity as
long as you only look at the upside.

Marcus J. Ranum CSO, Tenable Network Security, Inc.
firewall-wizards mailing list

Relevant Pages

  • nbc Kudos to the dems :-) nbc
    ... The 85-8 vote makes this bill veto proof. ... Congress sends 9/11 panel recommendations to Bush ... Security Committee Chairman Bennie Thompson, ... the past six years," said White House spokesman Scott Stanzel. ...
  • 7 Months Later, Pelosis Childishly Screwed Up Homeland Security Bill Almost Fixed in Senate
    ... WASHINGTON -- Lawmakers agreed Thursday to a goal of scanning all cargo-containing ships before they leave foreign ports as Congress neared a deal on a major security bill to carry out the 9/11 Commission's recommendations. ... In House-Senate negotiations on the bill, House and Senate Democrats pushed through a provision allowing a five-year window for radiation scanning technology to be put in place and giving the Homeland Security secretary authority to make exceptions. ... Opponents said a risk-based approach taken in a port security bill passed last year was more effective. ...
  • Re: Totally OT (politics) by request
    ... Bill C wrote: ... as security risks and un-American while doing nothing about the ... preferring instead to blow front gate locks off private homes ... That should, rather nicely, turn the undecided into supporters of the ...
  • Better hurry up..just a day left to fix things.
    ... Thai PM rushes security bill to parliament before poll ... Despite being in caretaker mode, the interim government, called the ... after having a coup and failing to eliminate Thai Rak ...
  • =?iso-8859-1?B?v0PzbW8gZXMgc3UgRXNwYfFvbD8=?=
    ... I walked into a blue collar business -- an auto repair shop ... The convoluted immigration bill working its way into law promises only ... working illegals, and yet we are never told of the staggering costs to ... The dirty little secret right now is that our Social Security system ...