Recently, members of the security team at Google made an important announcement about “real-world exploitation of publicly unknown vulnerabilities.” While it was done on the Google Online Security blog, all indications are that this is an official Google policy statement.…
Economics and Risk, Highlights, Random, Vulnerability Management
Cognitive Dissonance or Spite?
by Pete Lindstrom •
I happened to see a tweet the other day that said: “If you want a bug fixed quickly, sell it on the Russian black market. It’ll be so heavily abused that the vendor will patch out of cycle.” Now, it…
Economics and Risk, Highlights, Incidents, Random
How Much did Amazon Lose in Yesterday’s Outage?
by Pete Lindstrom •
One of the crucial aspects of risk management for infosec pros to learn is how to estimate consequences. It can be helpful to review incidents and create a model for thinking about losses. Amazon’s outage for an hour yesterday, is…
Economics and Risk, Highlights, Metrics, Random
How the Cost of Interventions provides Insight into Security Decisionmaking
by Pete Lindstrom •
In 1994, Tengs, et.al. published the research paper “Five-Hundred Life-Saving Interventions and Their Cost-Effectiveness.” (pdf) The research reviewed 587 different interventions and calculated the “cost per life-year saved” as a normalized metric across over 200 different studies on economic costs. So,…
Economics and Risk, Metrics, Random
Ruminations on Info Asset Value, Impact, and Control Horizons
by Pete Lindstrom •
One of the most challenging characteristics in our space is that *direct* information asset value – what the business is interested in – has an ambiguous relationship to consequences/impact – what security professionals are trying to minimize. I am a…
Economics and Risk, Highlights, Metrics, Random
How Red Meat can make Cybersecurity Healthier
by Pete Lindstrom •
Recently, the L.A. Times and other places wrote about a study done by Dr. Walter Willett of Harvard, et.al. regarding the impact of red meat on one’s mortality. He found that eating as little as one extra serving of red…