Pakistan lifts block on Twitter - ZDNet Asia: Pakistan lifts block on TwitterZDNet Asia59 Jakarta 10350, Indones... http://t.co/61n85ajh
9 minutes ago by semarang_photo on twitterZDNet is available in the following editions:
Affected vendors should be truthful and provide customers timely updates and advice to keep IT systems' safe as companies that handle such incidents well could enhance reputations, observers say.
Security vendors need to develop a response strategy that balances being truthful with customers and maintaining discretion to allow investigations to take place should these companies be victims of security breaches, industry observers stated.
Rob McMillan, research director of security, risk and privacy at Gartner, noted that these companies face a difficult balancing act should they get hacked. This is because they not only need to be perceived as open and honest with customers and provide timely, pragmatic advice, but yet keep certain information confidential so as not to compromise investigations, he explained.
In such scenarios, the analyst advised vendors to focus on keeping customers' IT systems safe above all other considerations and obligations.
Aliza Shima Mohammad Kasim, industry analyst of ICT practice at Frost & Sullivan, added that the security vendor should always apologize to its customers and keep them well-informed of the situation.
As for regaining customers' trust, she acknowledged that it would be difficult for vendors to do so but it is possible with a good strategy that helps build trust between both parties.
One example would be for companies to constantly renew their security offerings to let customers know these are not the compromised versions, and assure people that such incidents would never happen again, the analyst highlighted.
The affected company's marketing team should also devise a strategy that constantly reminds customers of the vendor's reputation and the "greatness" of its product lines, stated Kasim.
H.D. Moore, chief architect at Metasploit, a penetration testing software developer, added that no company is immune from attacks but a properly handled incident can improve the company's reputation.
He cited the recent breach of U.S. online retailer Zappos.com as an example, saying that while many customers did not like how the attack was handled initially, most of them were "delighted" with the notification and customer service process introduced as a result of the incident.
Give timely updates, advice
Companies that ZDNet Asia spoke to also noted that timely disclosure is paramount after security vendors suffer data breaches.
Kara Manon, marketing manager at Data Cave, a U.S.-based data center operator, said in such situations, she would need to know specific information on how the breach occurred to better understand if it was a fatal flaw in the system and should the company migrate to another vendor.
"Breaches happen but if the vendor is specific to the information security industry, I would be extremely worried," she added.
How companies deal with the breach is another important consideration, noted Kevin Creechan, an Internet technology developer at Canada-based digital marketing agency Aholattafun.
"Judging a security vendor is all about its response to an event and how well it can mitigate further impact on its clients by empowering them with enough information to proceed with business safely and securely," he said.
Asked to comment on Symantec's response following the theft of its Norton security source code last month, Moore said software vendors hardly ever turn off their products entirely. This, he said, indicated a lack of confidence in how the application had been designed and how the security compromise was not something that could easily be fixed.
The Metasploit executive had earlier told Reuters that Symantec was "crazy" to tell its customers to stop using its pcAnywhere software after hackers had stolen parts of the antivirus code.
McMillan disagreed, saying it is quite likely the advice by Symantec was not issued lightly. He said the vendor was in the best position to determine if the advice is prudent, and it was ultimately up to customers to act on the advice dependent on the resources available to them.
Kasim also defended the company's decision, saying that while it was "not the best move" by any huge corporation to ask customers to stop using its product, the steps taken were beneficial to the wider public.
This can be seen by the fact that there has been no major security breaches reported since the source code was stolen, she explained. "The move to ask customers to stop using its product can be considered a smart move from Symantec's end, because it forewarned customers and put their best interests first," the Frost & Sullivan analyst said.
Pakistan lifts block on Twitter - ZDNet Asia: Pakistan lifts block on TwitterZDNet Asia59 Jakarta 10350, Indones... http://t.co/61n85ajh
9 minutes ago by semarang_photo on twitterPakistan lifts block on Twitter http://t.co/WHqoJOqm http://t.co/erFX4aVv #arcavir
9 minutes ago by V_RaV on twitterhttp://t.co/VNaZtseV Pakistan lifts block on Twitter: Country restores access after briefly ... http://t.co/5gqegFWK http://t.co/wiqY9ktt
9 minutes ago by RavtachSolution on twitterMac users' indifference toward security 'worrying'. http://t.co/i7gZ8WVn
24 minutes ago by zdnetasia on twitterMac users' indifference toward security 'worrying' - ZDNet Asia: Mac users' indifference toward security 'worryi... http://t.co/CD9pvW08
24 minutes ago by win7antivirus on twitterRT @zdnetasia: Mac users' indifference toward security 'worrying'. http://t.co/i7gZ8WVn
24 minutes ago by t_phuck on twitterMac users' indifference toward security 'worrying' - ZDNet Asia: USA TODAYMac users' indifference toward securit... http://t.co/4EUVidiO
24 minutes ago by Namosofts on twitterMac consumers indifferent about security, security vendors warn such mindset is "worrying" http://t.co/ZGIxdg67 #In
24 minutes ago by EllyZDNetAsia on twitterMac users take note! RT @zdnetasia: Mac users' indifference toward security 'worrying'. http://t.co/YrLB9btb #mac #apple
24 minutes ago by jolintan on twitterRT @zdnetasia: Mac users' indifference toward security 'worrying'. http://t.co/i7gZ8WVn
24 minutes ago by KevinZDNetAsia on twitterMac users' indifference toward security 'worrying': However, Mac users ZDNet Asia spoke to expressed indifferenc... http://t.co/15DulmWS
24 minutes ago by ArkinOttman54 on twitterRT @jolintan: Mac users take note! RT @zdnetasia: Mac users' indifference toward security 'worrying'. http://t.co/2RQkfCKt #mac #apple
24 minutes ago by ewenboey on twitterAPAC tech merger and acquisition in Q1 down but value up: http://t.co/V7UkMABl
24 minutes ago by CopenhagenINK on twitterMac users' indifference toward security 'worrying' - ZDNet Asia: Mac users' indifference toward security 'worryi... http://t.co/PINqvJxT
39 minutes ago by antivirusdown on twitterI reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...
2 hours ago by wykoong on Gartner: Mobile CRM gives better ROI than socialThis video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...
19 hours ago by TradeBrother on A quick fill handle trick for Microsoft Excelwaiting...
2 days ago by eapete on What should count in a company's market value?Boy, you've opened a can of worms now.
Wait for the rants & raves.
I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...
3 days ago by wykoong on Drop the egos, copy ideas, then innovateEchelon 2012 - The Awesomer Tech Event in Asia
Echelon 2012 – SEA’s longest running tech startup event goes Awesomer. Catch 50 of Asia’s most promising startups & over 40 international speakers on June 11-12.
Startup Asia Jakarta showcases new product-ready tech startups. Plus: hackathon, exhibition, and speakers. Use promo code CBSi50 for 50% discount.
ZDNet Asia Intelligent Singapore video series
Featuring inteviews with CXOs who define "intelligence" in their markets and reveal how their companies drive business efficiencies through ICT.
Of course data breaches keep on happening because data vulnerabilities continue to be unmitigated.Most security breaches are attacks by insiders and most attackers are trusted people that exploit software system vulnerabilities (bugs, weak passwords, default configurations etc…). Neither security awareness nor UAC are effective security countermeasures for trusted insider attacks that exploit system vulnerabilities – premeditated or not.