Information Security Blog

What Horse Meat & Cloud Security Have in Common

What Horse Meat & Cloud Security Have in Common

15 Flares

15 Flares


×

Occasionally in the middle of a conversation a strange “association” pops into my head. This is one of those cases.

During a business breakfast with a lawyer (litigator) client of Pivot Point Security, we were discussing a very interesting lawsuit that he is working on.  His client provides a Software-as-a-Service (SaaS) solution that was leveraging a third-party cloud service provider for storage.  As you are likely already guessing, during a SAN upgrade something went terribly wrong and all of their client data was lost – and the offsite backups they believed were part of their contracted service… weren’t.  It’s not yet clear (as they are still in discovery) whether the backups were contracted to happen and didn’t happen, or were contracted and just didn’t work.  It is clear that the data is gone, along with the bulk of their customers and likely the business.

So right away I’m thinking “horse meat.”  Why? 

Because last night I watched Ikea dragged though the “horse meat scandal” mud over their meatballs containing horse meat.  Burger King recalled over 10 million hamburgers, and meat producers have reported that sales have fallen 43% since the scandal broke.  While Ikea and Burger King were in one sense the “victim” in that their provider misrepresented what was in the meat they bought, ultimately they will each pay a steep price for their suppliers’ transgressions. 

Is this fair?  Unfortunately, whether it is fair or not doesn’t matter.   What could/should they have done? Implement better vendor risk management practices. Just as with information security, they need to understand risks relating to their providers (e.g., contamination with bacteria, drugs, foreign materials), communicate the controls they require to prevent these risks from being realized, and put some form of monitoring in place to ensure that their requirements are being met and service level agreements kept.  Trust – but verify.

Going back to our client the lawyer: arguably the SaaS provider is also a victim. They did “nothing wrong,” yet it looks like overnight they have likely lost what was once a thriving business.  Sure they are suing the cloud service provider for millions. But winning that is a long shot (as is collecting) as the cloud service provider may well end up out of business also.  So unless there is a deep-pocketed cyber insurance provider (who wasn’t smart enough to include negligence provisions) in the mix, all is likely lost anyway.  Further, several of the SaaS provider’s clients have also filed suit, so the only ones likely to benefit from this are all the lawyers.

So much like Ikea and horse meat, the heart of the problem is a lack of vendor risk management. What did the contract say? What due diligence was performed? What ongoing monitoring was done? What residual risk was covered by a cyber insurance policy?  Not enough. None. None. None.

Horse meat and cloud security are not just supply chain risks — they are very real business risks.  If you’re not sure where to turn to manage information security related vendor risks, the Shared Assessments program has some very good guidance, including a new Vendor Risk Management Program Maturity Modeling tool. Highly information security literate attorneys are also a real asset. Finally, an insurance broker that can help you select the right cyber liability insurance policy. 

Need help looking at it all holistically? Turn to Pivot Point to simplify the process.

0


Best Practices for Firing A Network Security Administrator

Firing A Network Security AdministratorWant to know how to fire a Network Admin? Need to know what precautions to take? Firing any employee can be a stressful event. Firing one who has significant knowledge of and privileged access to your Information Technology/Security infrastructure is even more stressful, as the risks are so notable.

Free Whitepaper: Five Best Practices for SIEM

siem-whitepaper

The promise of SIEM is the consolidation of all relevant Security Event Logs from disparate sources into a single unified and normalized data store.

Free Whitepaper: Stop Wasting Money on Penetration Testing

penetration-testing-whitepaper

Penetration Testing is most frequently performed to:

  • Substantiate the net effectiveness of a mature control environment
  • Prove to a third party that an environment is secure/trustworthy
  • Quickly assess the security of a less mature control environment (in a sense a technical risk assessment)
  • To validate that significant changes did not have unanticipated results

Free Download: A Best Practices Guide to Database Security

database security roadmap

Because data is only as secure as the systems & processes it relies on – a holistic approach to data security is essential. This roadmap is not meant to be exhaustive but rather to stimulate the necessary thought process to put you on the path to good data security.

Free Download: ISO 27001 Implementation Roadmap

ISO 27001 RoadmapHave no fear – our “roadmap” will guide you, step by step, through the entire ISO 27001 process.

Getting to ISO 27001 certification is a process made up of things you already know – and things you may already be doing!

Is ISO 27001 Right for (Y)our Organization?

iso-27001-webinar

Thinking about ISO 27001 Certification? View our free On-Demand ISO 27001 Webinar

  • How to deal with increasing threats
  • How to manage multiple regulatory requirements
  • How to handle client requests for attestation
  • To validate that significant changes did not have unanticipated results

Download: Information Security Attestation Guide

Information Security GuideA Best-Practices Guide to Information Security Attestation

Download our proven Information Security Guide to simplify the process of protecting your data, proving you’re secure and growing your business.

About the Author:

John Verry (CISA, 27001 Certified Lead Auditor, CCSE, CRISC) is Pivot Point's resident "Security Sherpa". He is lucky enough to spend most of his day helping clients develop a road map to address security, compliance, and attestation requirements.

Add a Comment

15 Flares Twitter 5 Facebook 2 Google+ 2 Pin It Share 0 LinkedIn 4 Reddit 0 StumbleUpon 0 Email -- Email to a friend 15 Flares ×