A Blast of Fresh Holiday Security Cheer

The holiday season is a great time of year, one of my favorites. Cookies and mistletoe, decorations and caroling, the festive spirit always brings out the best in people.

I’m kidding about the caroling, but the holidays definitely put me in a good mood. Everything looks brighter, and my attitude is more positive. I generally feel better about life, even if circumstances haven’t changed.

So I suppose it’s no surprise that I’m here to provide each of you with a fresh perspective on your information security headaches. Yes, I’m sure you’ve all had serious problems this year – technical, financial or operational – and you’re expecting more in 2012. But now is a time for reflection. A time for renewal. A time to forget old acquaintance, and auld lang syne.

Consider it my gift to you.

So get yourself a warm cookie and a chilled goblet of your favorite Christmas cheer, and grab a cozy in front of the fireplace while I attempt to make eggnog out of rotten security eggs.

  • You’re only as bad as your last fail – We’re all human, and we all have the same defensive mechanisms. This means that, in general people will only remember your last disaster. So cheer up! The SQL injection flaws you left exposed in April don’t matter anymore, all that matters today is the massive databreach from November. Tomorrow is a new day.
  • The good guys will always be behind – By definition, we will always be in reactive, defensive mode, but that’s OK! If you do the math you realize that they can’t get all of us. Also, we may be losing the race but there are only two runners so we’re guaranteed second place. That’s a silver medal in some contests.
  • There are no guarantees – There is no such thing as 100% secure – so find comfort in that fact. The day I gave up thinking I would ever dunk a basketball was a happy day, I just didn’t know it yet. Mediocrity can be invigorating if given a chance and approached with the right perspective. You’re as likely to secure your enterprise as I am to dunk a basketball. Enjoy.
  • It’s always going to be this bad – Things in the information security Universe are frighteningly bad, but it’s always been this way and it always will be. So relax – there’s no sense killing yourself over something you have little control over. Read a book. Go to lunch. Or even better, get your Law degree and save your career.
  • Everyone else has problems, too – If all of the above attempts to freshen your perspective have failed, rest easy – the bank across the street really has it bad. So does the hospital you go to. And the fast food chain where you had lunch today. Oh and don’t forget about your car dealer, your kids’ college and your church. And every other business within visible range. In fact, you’re probably no worse off than anyone else. So take a deep breath and revel in the fact that everyone sucks at security.

By now you’re probably ready to build a snowman and donate your bonus to charity, so I’ll let you get back to your holiday preparations. Just remember that there’s a bright side to information security and there’s no better time than the holidays to celebrate that fact.

I feel better already.


