Tuesday, 29 September 2009

Thanks and goodbye

As I will be leaving AppGate soon to join the Swedish Post and Telecom agency (from January 1) as the Director General it is time to end this blog. I would like to thank everyone for this time!

Tuesday, 15 September 2009

Thin clients...now on Mobile phones

I have worked with mobile users and applications for several years. I have seen the transition from "oh I am so happy to have emails on my phone" to something that are a part of the organisations IT access architecture. The problem has been (and still is) that it is almost impossible to create applications that works with all mobile operating systems...or phones. I spoke to some friends in the industry yesterday and the answer seems to be simple...use the web browser in the phone and connect to the Intranet through an VPN. Simple, secure and cost effective. Now when the mobile networks are so good it is not necessary to carry around the data. Why create solutions that are un-necessary. I even have customers who run terminal servers on their mobile phones.

Monday, 14 September 2009

Black list versus white list

As long as I have been active in the IT-industry the methodology for internal security has been blacklisting. You can reach almost everything but we will close down access to certain resources. That was probably OK "in the old days""when there where an limited amount of information accessible. I therefore think white-listing is much easier to use: block everything and give access only to information that is needed for the given task. Much easier, much more secure...and probably more cost-effective.

Maybe you already know...

I have been appointed by the Swedish Government to be the new Director-General of the Swedish Post-and Telecom Agency. I am sorry to leave my friends at AppGate but happy to get new ones at PTS. I will start my at my new job in January 2010, until then I will continue to blog. For more information about PTS, please visit www.pts.se

Tuesday, 8 September 2009

Time they are a changing

I read something interesting today, the sales of ADSL is losing momentum due to increased usage of mobile data access. It sounds fairly obvious when I think about it, mobile is easier, more flexible and therefore in a way, more user friendly. But the change is also interesting from other perspectives because it has other implications then just the obvious. The fact that people now can be connected everywhere will create new business models, the need need for new security architectures and more connected "devices". I remember when I (several years ago) tried to buy an "connected refrigerator" (not the best of ideas...) but now we will see a fast adoption of new things connected to Internet.( Please do not tell my wife but I will buy a TV with internet access soon.. ). My next car will probably be connected etc etc. We have talked about this for a long time but the difference is that now it is really happening. Maybe we are now "Back to the Future". What I do not know is who will produce those services, companies like Skype and Spotify has taught me to humble. Ten years ago the industry was filled with fun ideas (not all of them very good) based on new technologies. I think that we will see a lot of that new innovation "pulse" again.

Monday, 7 September 2009

Security and energy consumption

For good reasons there is a lot of talk about the IT industry´s need for energy and all the measures that can be taken to limit that need. I spoke to a customer this morning that we did some work with a while ago and replaced several security point products (a mobile VPN system, several internal firewalls, an SSL VPN and an old IP-sec based VPN) and he told me that one of effects he now has seen is lower usage of electricity due to less servers and point products. At the same time they started to virtulize the infrastructure so the effect was double (they run our server in a virtualized form "on top" of the applications)

I have not thought about this effect before but it makes me happy that increased security can sometimes lower energy consumption. So my tip of the day is to look into the usage of power when you design your next architecture.

Wednesday, 2 September 2009

Reality versus hype

I read an study today about customers willingness to adopt "the cloud". In the study only 8% where ready to make the move. The others had concerns about security, integrity and costs. I think this proves that the IT industry has matured, people now understand that they need to analyse the consequences of implementing new technologies. I think this is good..being tired of all hypes that vendors have sold to their customers over the years...with the result that a lot of money and energy has been lost on immature or useless products.

Tuesday, 25 August 2009

The first thing to check for any manager...

Yesterday I was invited to attend an internal discussion with one of our customers. The customer main business is in finance and they did something that I think more companies should do: they did a war game. They tried to find any potential breach they could have from any type of source, internal or external. I was invited to help them with questions to ask themselves. They did a good and thorough job so I ended up with only one question: Is anyone responsible for all access systems? I think that in any security environment there should be a 2-hand principle. As an example: one person handles the access system, another person should handle the LDAP. We ended up doing a map of whom was responsible for which system. A couple of minutes ago I go an email from my customer where they told me that they added the principle to their security plan and they already changed some access rules internally.

Thursday, 20 August 2009

A very intelligent article by someone else then me....

I get happy when other people express what I am trying to say (in a much better way then me..). AppGate has a new partner in South Africa: Condyn. They recently wrote an article about security that I think is great...so here are some quotes:

Most investigations concerning computer crimes show that 60% to 80% of all security breaches are performed by insiders. These statistics highlight the fact that the most common method of protecting a corporate network and computers – the “ring wall” – is ineffective as it is assumed that attacks will come from the outside.

“This type of firewall-centric solution was designed many years ago and is slowly becoming obsolete,” explains Jorina van Rensburg, CEO of Condyn.

“Protection has been moved closer to the assets, such as application servers as well as workstations and laptops. So, how do you transform this traditional view into a more modern and effective architecture?” she asks.

According to Van Rensburg, the first step forward is simply observing the fact that the larger a network becomes, the more insecure it will be. This means that security can be improved by partitioning the corporate network.

Traffic between domains should be strictly controlled and potential problems logged. This immediately puts a limit on the maximum amount of damage a security problem can cause, and increases the possibilities to both detect and deal with potential problems.

The next step is to fully move away from the “ring wall” architecture. “If the servers can be protected against all unauthorised traffic, then operating systems, network protocols and applications cannot be attacked.

Step three involves improving client security. Clients need to be correctly configured, configurations must be reviewed and all software patched to make sure they do not contain any publicly known vulnerabilities. The security system should also be able to do a “client-check” before access to sensitive resources are granted. This check could guarantee, for example, that the client has anti-virus software installed, a good personal device firewall is in use, that no file sharing software is present, or any other rules the application system owner would like to enforce before access to that application is granted.

I really looking forward to work this company, they know what they talk about.

Wednesday, 19 August 2009

Why are not all patches applied?

One of reasons for security breaches is that security patches have not been applied. The message from the vendor often seems to be: yes we screwed up but now there is a patch so it is not our problem anymore. They seem to expect everybody to jump on any new patch and install them in an instant...this seems not to be the case. Are people stupid or lazy (or both?)? I do not think so; I think it is a question of time and resources. Any given company or organisation runs several applications and hardware at the same time. Just to know that there is a new patch out there can sometime be a problem. Another problem is to find out if the patch will have any implications on the rest of infrastructure.
This is especially true when it comes the network and security infrastructure where many point products interact with each other (many times in strange ways...). As always there is no simple solution but I have over the years recommended a short list of things to do...
1. Make sure that you UTM products instead of point products...that is an easy one.
2. Limit people’s access to applications (when things goes wrong the problem is isolated)
3. Make a list of the most dangerous applications and systems you have and grade them.
4. Check how different point products interact with each other.
5. Make a due diligence plan..and do due diligence often..

With this you hopefully created time....use that to patch.

Friday, 14 August 2009

What will you do if the Swine flu hits your organisation?

The latest UK Government figures suggest a worst case of up to one in eight employees forced to take time off work due to swine flu. On 28 th July, the British Chambers of Commerce (BCC) advised businesses to consider offering staff the option of home working to maintain continuity during the swine flu epidemic. The organisation warned that companies could be hit by intense periods of staff absence if projected figures for infections are realised.
Remote access is simple in theory but hard to achieve on a mass scale...here are some things that needs to be considered:
1. Who should be able to access and what should they be able to access? It is never a good idea to open the whole network for access.
2. How should they be able to access? To let everybody use their private PC:s for access could be a security challenge. How do you know if the PC is infected or not? Maybe a USB client with terminal access would be the best and most cost-effective solution.
3. How do the users authenticate themselves? I have seen many times that intruders use crises in a organisation to exploit networks..simply because no-one cares about IT Security during (as an example) a bomb threat. I strongly recommend 2-factor authentication.
I guess what I am trying to say is to plan ahead. The cost of trying to solve the problem during the crises will always be more expensive then fixing the problem beforehand. A small investment now can save tons of money later.

Wednesday, 12 August 2009

How to survive vacation?

I do not know about you but being away from the office could be quite stressful for me..I need to be in the loop. Luckily enough I have an understanding wife and I work in a company that makes remote working possible. This year I added to the technical infrastructure in my boat by installing a wireless router that I connected to my 3G data card. That made it possible for both me and my wife to "work" and use Internet...even on a remote island (and mostly in the rain..). I now had the same access as if I was in the office.
I had one technical problem this summer...when I learned that mobile phones do not swim very well. Skype helped me to overcome that burden until I could buy a new phone.
Sitting in my boat I realised that all this has created a new level of freedom, just a couple of years ago this would have been impossible or very expensive. Now it is easy and actually quite cheap. My wife in the end had a slightly other view..she told me that I now gone from working full time to working all-the-time.

Monday, 10 August 2009

I am back from vacation....

I have not posted anything in a while...mostly because I have been away from my desk and in my boat...and partly because this summer has been different from most other summers in terms of business. We have never been more active then we are right now at AppGate. I think this is proof of that the customers are looking for security solutions that are built around another concept then the old "firewall inside-outside" model. Anyway I am happy....

Monday, 22 June 2009

An argument for keeping control of your data.

http://www.cio.com/article/494553/T_Mobile_Confirms_Stolen_Data_is_Genuine

As I have stated many times before, before you outsource any data or parts of your infrastructure...make a an security assessment . Think about the go-to-jail factor.

(Thanks Malcom for the link)

Wednesday, 17 June 2009

This is pure marketing...but I am proud of it

Following rigorous testing over the past year, AppGate’s solution has been chosen to ensure police officers on the beat can securely access essential information held on the central network at police head quarters via their mobile phones. AppGate’s technology will now make it possible for the Police force to change how they work to be more productive and efficient.

Stockholm 17 June 2009 - It has been a tough knot for the Police to solve, how to make confidential information available for officers working on the street while ensuring the information remains secured. Previously, officers had to return to the station each time they needed to retrieve information, despite the fact that it would be more effective and efficient if they were able to access it while at the scene of the crime.
A key requirement has been to find a solution that uses the highest possible level of security while at the same time providing the best possible availability, and the new solution from AppGate achieves that making it possible to retrieve highly classified information over a mobile phone. The solution will be available to police all over Sweden and 10 000 police officers will use the system at first with the possibility to scale it up to incorporate more users later.

The AppGate system makes it possible to integrate all types of access: Mobile, PC/Mac, PDA, in one single solution without having to accept reduced security or functionality. The users will get exactly the access they need when they need it – no more and no less. One set of users might be restricted to downloading e-mail and synchronizing their calendars on their mobile phones, while others who are running the required AV software on their mobile devices might have access to SAP and the CRM system as well.

As always AppGate security servers build on existing proven functionality such as:
Application Layer Firewall
Mobile & Fixed VPN
Granular & Role based Access
End-point Security Control

Monday, 15 June 2009

I am so tired of hidden agendas from vendors

I read an article with someone called Mark Hennessy from IBM today. In the article he claimed that in the future the IT-department of most companies would disappear due to that everybody would use "the cloud" for all types of applications. He is entitled to have his view of course and I also think that a lot of companies will jump on this new outsourcing trend. What makes me irritated is that again a salesperson hides behinds his title….to sell a product. This is not uncommon in the IT-industry..anti-virus companies sends out reports that shows that there are more viruses then ever...router vendors that "foresees" increased usage of Internet (so operators needs to buy new and faster routers). Do they actually think that most people do not see through their marketing effort and take their advice for what it is...pure selling.
On the subject about cloud computing I think that companies that has IT as an integrated part of their business strategy will never outsource all part of their application infrastructure.

Tuesday, 9 June 2009

Who is responsible if the shit hits the fan?

I am often invited by companies to act as a bridge between the IT department and the higher management. That is not always easy..the management seems to think that IT people likes new toys to play with...and IT people seems to think that management does not understand the importance of IT. A way of getting around the discussion is to play the responsibility game. I start by asking what the worst thing that could happen would be. Usually that is that the company does something that hurts a 3-party...and then gets sued for it. I did this when I talked to a CEO about cloud computing...and I really enjoyed when he realised that he could never delegate the responsibility just because he outsourced his applications. That CEO is now very much involved in all discussions regarding outsourcing and cloud computing. I call it the go-to-jail factor.

Monday, 8 June 2009

More about Mobility

I spend a lot of time with customers who want to increase the usage of mobile phones but have concerns about security and costs. There is no single answer that would fit anyone but over time I have formulated a list of questions to ask.
1. Will you use the mobile phone to access more then just email? Intranet, business applications and other applications are on the wish list of most users today. Will that increase your return on your investment?
2. What is the lowest level of authentication you will accept for access to information? Passwords? 2-factor authentication? Does your mobile solution support the authentication system that you already use?
3. What are the security effects on your infrastructure? How many ports do you need to open in your firewall etc etc?
4. Can you accept that your traffic goes trough a 3-party gateway (like the Blackberry solution).
5. How do you manage the mobile and support the mobile phone? Can a phone be updated remotely?
6. Can you control the identity of the actual phone before it is connected to the network?
7. Should information be stored on the phone or centrally?
8. Does the phone have encryption pre-installed or do you need to add that.
There is one more thing I usually tell everybody that wants to listen...make a difference between what you NEED to do...and what is fun to do. I have seen the costs of many mobile projects explode due to the FUN factor. Make a list of features that you need rather then options vendors try to sell to you. One of the features many talk about is the users use of the phone..expensive reports are created for something that you get from your operator for free.

Tuesday, 2 June 2009

How boring is IT-Security?

I had some friends over for dinner a couple of weeks ago and for some odd reason we started to talk about my blog. The verdict was that is had to be good...as they did not understand a word about anything I wrote. I have to admit I was a little but surprised because I want to think that I write about things that people should understand...as it concerns everybody. My wife gave me the simple (but fairly cruel) answer...IT Security as a dinner discussion is very very boring for 99.999% of the worlds population. It is such a boring subject that next time I bring it up..she will force me to bed without dessert. So why is IT-Security such a boring subject? I am not boring; my friends in the industry are not boring (at least we do not think so). I do not have the answer but maybe security is boring because we do not think it is that important. We actually believe that the threat is un-real and that the makers of software do a decent job to protect us. Therefore we who work in the industry are troublesome whistleblowers who try to make a dollar by scaring honest people to buy stuff they do not need. I wish it were true. I am open to any suggestion how to make IT Security more interesting for people outside the industry..at least that would make my dinner parties more interesting.

Monday, 18 May 2009

Are humans the biggest security problem?

I read a story today about a person that got his mobile phone infected with a virus when he received an MMS that happened to contain hidden software. The journalist that wrote the story talked to a representative from Microsoft who said that end-users are the biggest security problem. I do not debate that users has to take some responsibility to ensure their safety but I still think that we in the industry cause more problems then most users. It is strange that in an area where so many people (and companies) depend on communication so little is done to fix the underlying problem of security. Many applications are badly designed, badly written and full of holes. Access systems are seldom used or badly implemented. In any other industry consumer groups would be shouting (and suing) suppliers that lie as much as the IT-industry does. So humans are never the "problem", let us start to think about their needs instead.