Be secure: 'Plan, don't patch', says AV pioneer

By Will Sturgeon, Special to ZDNet Asia
Tuesday, October 04, 2005 02:05 PM

Companies are putting too much faith in patching software and investing too little time in proper risk assessment, according to a pioneer of antivirus software.

Dr Peter Tippett told silicon.com the current approach to security has become outdated, counterproductive and too costly. He also controversially suggested companies only patch their computers once per year.

Tippett's words echo the growing voice of support for a move towards a risk-based approach to security.

As such Tippett, CTO of security giant CyberTrust, now dedicates much of his time to monitoring "the underground" and working out the likelihood of malicious code being written to exploit emerging and existing technologies and "knowing exactly what the real problems are".

Tippett likened the necessary intelligence-gathering and risk assessment to the very British obsession with checking the weather forecast.

"Predicting the weather is not a perfect science but it can help a lot," said Tippett, who advises companies to spend more time assessing risk and the probability of attack rather than waiting for the window of vulnerability to open and then rushing to baton down the hatches.

"Companies who decide that patching is going to be their primary method of defence are always going to be worse off than average and are going to spend more and more money on security each year. If you can patch 100 percent you will be protected against a lot of threats but nobody does or can patch 100 percent," said Tippett. "The average is around 70 percent."

"Patching works well if you have one computer. It even works well if you have three computers but if you have 10,000 then forget about it.

"There are all kinds of computers which are not known about by the management. There are mobile workers and protected computers which are never touched except during a service window."

"It would therefore be a mistake to put any faith in patching," said Tippett. "I'd say patch your computers once per year. Plan it three or six months in advance and you'll at least be able to get hold of all laptops and computers."

"Get it done properly and get all your computers to a situation where software is within a year old."

Companies who have already distanced themselves from the reactive, fire-fighting approach to security are claiming significant savings - such as a halving of the IT budget at insurance giant Zurich, as covered recently by silicon.com.

According to Tippett: "These companies spend less money on scanning and less money on paying people to run around patching like crazy."

Tippett agreed with the recent assertion of Gartner analyst and advocate of a risk-based perspective, Jay Heiser, who said such an approach will come from the business and not from the techies.

"Technical people see things in a binary way. They adopt a 'world is flat' approach. The higher up the organization you go, the more this starts making sense."

Silicon.com's Will Sturgeon reported from London.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Cost and graphics concerns delay a VDI project

Tech Management

Virtual desktops are a serious paradigm shift and Scott Lowe is taking it in a slow and measured way. In this article, he provides an update on ongoing VDI efforts at Westminster College.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web