Technology Sectors

Market Sectors

The Heartland debacle, take two

Recently, the folks at Heartland Payment Systems announced a data breach. With their tagline being 'The Highest Standards. The Most Trusted Transactions,' I just had to laugh. Not that many people had their identity stolen, but that we've seen this movie before (starring the likes of TJX Corp. and Hannaford Bros.) and we will see it again. Guaranteed.

Why? Because many organizations (dare I say most) continue to believe that compliance equals security. They figure if they are 'compliant' with a standard, their data is secure. Whether that standard is PCI or FISMA or any other, it's of no matter. These myopic organizations believe that once they get that little sticker, certificate or audit finding, they are done.

Well, they aren't. We live in a dynamic world, where the attackers are always coming up with new and innovative ways to separate you from your private data. Due to the general process of how a regulation comes to be, it is, by definition, addressing problems that were top-of-mind two years ago.

For example, the PCI-DSS requirements were updated to version 1.2 back in October, and one of the big new requirements was to eliminate the use of WEP (wired equivalent privacy) in wireless networks. The problem is WEP has been widely known as insecure for years. In fact, it was determined that WEP was one of the contributing factors to the TJX breach, and thus the PCI Security Standards Council moved to eliminate it. Unfortunately, it was a few years too late.

So, if compliance does not equal security, what is a security professional to do? Focus on securing critical information, and focus on reacting faster, basically planning for a compromise by gathering data (via network and system monitoring) to pinpoint the attack and respond to it. Heartland could have used that advice, eh?

To get a bit more specific, a broad and aggressive monitoring program allows organizations to react faster to attacks. Heartland was probably only monitoring its security logs (as prescribed by PCI-DSS) and that allowed configuration changes (to install a network sniffer) and strange network flows (sending data from the compromised servers outside of the organization) to go unnoticed.

Heartland thought it was safe because they were PCI compliant, but the attackers knew that wasn't the case. And now, up to 100 million consumers will also learn that reality, the hard way.

Mike Rothman is senior VP, strategy, and chief marketing officer at eIQnetworks, a security and compliance management specialist. He can be reached at: mike.rothman@eIQnetworks.com

 

Recent Webinars

Thu, 04/26/2012 - 2:00pm - 3:00pm

Extracting real-time intelligence from Big Data with deep analytics is valuable but dif

Upcoming Events

Event Details Dates of Event
SANS Security West 2012 May 10 - 18
SANS Toronto 2012 May 14 - 19
SANS Secure Indonesia 2012 May 14 - 19
Emergency Management Seminar May 15 - 15
Counter Terror Expo US May 16 - 17
Emergency Management Seminars May 17 - 17
SANS at iTWeb Security Summit 2012 May 17 - 18
New Fire & Emergency Communications Codes Educational Seminar May 18 - 18
Managing Your Physical Security Program: Collaborate and Manage Smarter May 21 - 24
SANS Brisbane 2012 May 21 - 26
CEIC 2012 (Computer and Enterprise Investigations Conference) May 21 - 24
NERC CIP Compliance Training May 24 - 24
NESCO Town Hall: Security Risk Management Practices for Electric Utilities May 30 - 31
Advanced Hands-On CAMEO Training Jun 4 - 6
Security Program Design: A Critical Infrastructure Protection Model Jun 4 - 5
Facility Security Design Jun 4 - 6
SANS Rocky Mountain 2012 Jun 4 - 9
F5 Government Technology Symposium Jun 6 - 6
SEL Modern Solutions Power Systems Conference Jun 6 - 8
Second Annual Citizen Engagement Seminar Jun 12 - 12
ASIS Assets Protection Course: Functional Management (APC III) Jun 18 - 21
SANS Malaysia 2012 Jun 18 - 23
Data Center Brainstorm 2012 Jun 19 - 19
SANS Forensics and Incident Response Summit 2012 Jun 21 - 27
Vanguard Security & Compliance 2012 Jun 25 - 28
SANS Canberra 2012 Jul 2 - 10
SANSFIRE 2012 Jul 7 - 15
Executive Protection Jul 9 - 10
Military Vehicles Exhibition & Conference Jul 10 - 13
NERC CIP Compliance Training Jul 12 - 12
Security Force Management Jul 16 - 17
Physical and Logical Security: Advanced Applications and Economics Jul 16 - 19
Investigative Interviewing Methods Jul 18 - 19
SANS Thailand 2012 Jul 23 - Aug 4
SANS San Francisco 2012 Jul 30 - Aug 6
College & University Police & Investigators Conference Jul 31 - Aug 3