MichaelPeters.org

  • CRM
  • PMP
  • 0
  • 1
  • 2

MichaelPeters.org - Your Personal CXO, LLC

  • Your Personal CXO
  • The Policy Machine
  • Keynote
  • Company Store
  • Podcasting
  • HORSE Wiki
  • About Michael

Uninsured – Underinsured Information Highway Motorists

0

By Michael Peters on November 18th, 2011

On the information freeway, the vast majority of the population is driving ninety miles per hour (144 KPH) without insurance; this includes business entities as well. In the United States, as in many other countries as well, the law dictates that a person possess a minimum level of automobile insurance to protect the financial stability of other drivers, their property and themselves in the event of a crash. Most people would not be able to afford the expenses associated with a crash should it occur. We all tend to dislike insurance, but are infinitely pleased when we have it in a time of catastrophe right?

When it comes to cyberspace crime, it is all about identities and intellectual property. The largest business segment for cyber-criminals to target identities is in the retail marketplace. You might be pondering right now “Michael, no way! Banks are where the real money is!” Think about this for a moment; just one credit card is used at dozens, hundreds, maybe even thousands of retail establishments from every part of the world right? When is the last time you heard about a security breach at a credit card issuer like Visa or MasterCard?  Citibank comes to mind, but no one else. When is the last time you heard about a security breach at a retailer? I’d run out of fingers and toes counting them off to you.

According to the U.S. Census Bureau, three quarters of all U.S. business firms are classified as small businesses (Source: U.S. Census Bureau). The likelihood of consumers like you, doing business with any one of these firms is significant. Now for the next big question I want you to consider. How many of these small businesses are required to comply with Payment Card Industry PCI security mandates? Technically all merchants are supposed to comply with these guidelines however, anyone processing less than 1 million transactions a year must only claim compliance which is not verified. Do you think the honor system, wink-wink, is going to be effective at protecting your identity from criminals? I say “criminal” instead of “cyber-criminal” because without effective and fundamental information security controls in place, data theft of your credit card information and personally identifying information is ripe for the picking by dishonest employees, dishonest support vendors and cyber-criminals alike. According to Visa Inc., small merchants account for over 80 percent of compromise events (Source: VISA Inc.). Hackers love small businesses because they are usually not well protected. Regardless of size, any organization that is not protected will be targeted by cyber-criminals.

The PCI Security Standards Council is an open global forum. The Council’s five founding global payment brands, American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa Inc., all agreed to set security standards so on the positive side, we all have consistent standards. On the negative side, some of these requirements are antiquated by technological standards and must be updated in my opinion. For example, encryption; 3DES encryption is still authorized by the PCI consortium. 3DES was defeated in 2005.  For discussion purposes, AES is faster and has not been defeated. Why then has the requirements not been updated you ask? It is expensive to update the technology to support high encryption rather than low encryption. It really represents collusion between the PCI consortium and the financial institutions to “dumb down” security measures purely for business impact purposes.

Now that I’ve taken you on a brief tour of just one security component protecting consumers by mandating basic security standards are in place, I assure you that there are many other fundamental security measures that should be in place to protect consumers and corporations alike regardless of size that are not required, measured, tested or reported on currently. As a business entity, the lifeblood of that business is the customer and the customer can only support business if their financial identity is solvent. This symbiotic relationship will not thrive without vigilance on both sides. Merchants must protect their intellectual property, their customers, profits, etc. while consumers must play their part. Keeping their technology up to date and utilizing secure methods of conducting business or personal transactions is vital. The other facet is in demanding businesses handle your personal information with great care. Just like corporations come together for mutual benefit, like the members of the PCI consortium have, so to must consumers come together for mutual benefit.
Article first published as Uninsured – Underinsured Information Highway Motorists on Technorati.

Share this:

  • Email
  • Print
  • Digg
  • Google +1
  • LinkedIn
  • Twitter
  • Tumblr
  • Pinterest
  • Reddit
  • StumbleUpon
  • Facebook
  • CXO, Lazarus Alliance, Your Personal CISO
  • Search

  • Your Personal CXO

  • The Security Trifecta

    Hire the experts to implement The Security Trifecta in your organization. Click for more information!

  • Louisville Metro InfoSec

    The Louisville Metro InfoSec is the premier ISSA information security conference!

  • External Services

  • Thousands of other great people can't be wrong! Enter your email address to subscribe to this blog. -

  • Affiliates

  • RSS SBN RSS

    • SBN Sponsor Post
    • SBN Sponsor Post
    • Security News June 19
    • RANTing Rockstar
    • Microsoft Announces Bug Bounty Program
  • RSS The Register

    • That Microsoft-Nokia merger you've been predicting? It's no go
    • Microsoft caves on Xbox One DRM and used-game controls
    • Kim Dotcom victim of 'largest data MASSACRE in history'
    • Google preps wave of machine learning apps
    • Reg to Australia: Here's your chance to find NBN answers
  • Categories

    • Books
    • CXO
    • Featured
    • HORSE Project
    • HORSE Project V1
    • Kickback Cafe
    • Law
    • Lazarus Alliance
    • Life Learner
    • Obsolescence
    • Projects
    • Remember
    • Securing the C Level
    • Syndication
    • The Security Trifecta
    • Uncategorized
    • Your Personal CISO
  • Archives

    • March 2013
    • February 2013
    • January 2013
    • December 2012
    • November 2012
    • October 2012
    • September 2012
    • August 2012
    • July 2012
    • June 2012
    • May 2012
    • April 2012
    • March 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011
    • January 2011
    • December 2010
    • November 2010
    • September 2010
    • August 2010
    • July 2010
    • June 2010
    • May 2010
    • April 2010
    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • May 2008
    • April 2008
    • January 2008
    • December 2007
    • July 2007
    • June 2007
    • May 2007
  • Get the app!

    Your Personal CXO now on Android!

  • Get the app!

    The HORSE Project now on Android!

  • Your Personal CXO
  • The Policy Machine
  • Keynote
  • Company Store
  • Podcasting
  • HORSE Wiki
  • About Michael

More on Your Personal CXO, LLC

  • EXTERNAL

    • AppHappening
    • CheckSavvy
    • Dynamic Clinical Systems
    • eLance
    • HORSE Project
    • Maprehend
    • Quest for Tech
  • Meta

    • Register
    • Log in
    • Entries RSS
  • Recent Posts

    • The Policy Machine
    • Top 1% Most Viewed LinkedIn Profile
    • Reasonable Duty of Care: Data Security and Privacy
    • Security Overlooked: Weathering the DDoS Storm
    • Please Vote for this blog!
  • Top Links

    • clouds (70)
    • No Title Given (57)
    • mba-mdp (47)
    • site (30)
    • peters-wgu-sbit-infosec (25)
    • CISSP-MDP-2013 (23)
    • An Introduction (21)
    • http://michaelpeters.org/?page_id=336 (21)
    • LinkedIn.com (19)
    • CMBA-MichaelPeters-2007 (17)

Copyright © 2013 MichaelPeters.org - MICHAELPETERS.ORG - Your Personal CXO, LLC

 
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.