« I guess wireless IPS didn't cut it | Main | An old/new kind of cybercrime/cybercriminal »

April 23, 2008

I'm the security guy. I used to have a security guy, but he died. Now I'm the security guy

The_producers While attending the SANS event in Orlando this week I had a chance to meet a fellow who works at a company that is a StillSecure customer.  I had never met this particular guy before, so I asked him how long he had been working in security at the company.  The answer I got reminded me of an old quote from the move "The Producers" -

-Who d'ya want? -I beg your pardon? -Who d'ya want? Nobody gets in the building unless I know who they want. I'm the concierge. My husband used to be the concierge, but he's dead. Now I'm the concierge.

This guy had worked at the company for a number of years in the network department. They had a "guy who did the security".  He is the one that bought the StillSecure product.  Evidently a while back the security guy left the company.  It is not clear whether he quit or was asked to leave, but the bottom line is they had no security guy. Instead of hiring another security guy, they made this poor SOB the security guy.  He inherited a bunch of security products including our own and a bunch of "open source stuff".  This guy didn't even know where to begin.

After floundering around for a while, he made a smart move and signed up for some security training from SANS and is just beginning to realize how much he doesn't know.  But it will still be some time before he is in a position to handle the security at his company, that by the way has SOX issues to deal with.  I suggested that perhaps he look into some MSSP service to help him out.  I am going to try and help this fellow out as much as I can, but he has a tall order.

How many others are out there in the same boat?  How many people have had the security role thrust on them, without the training or expertise to make it happen.  The greatest tools in the world, won't make up for this lack of skills and experience.  Is it any wonder that we have a breach a day announced and our security seems to be in such disarray? We should let security be handled by security professionals or else we deserve what we get!

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/547509/28400424

Listed below are links to weblogs that reference I'm the security guy. I used to have a security guy, but he died. Now I'm the security guy:

Comments

Search

Lijit Search

disclaimer

  • The views and opinions expresed here are those of myself only and in no way represent the views or positions or opinions of my employer, Latis Networks, Inc. d/b/a StillSecure or anyone else.

Forbes.com

StillSecure, After all these years, the podcast

  • Podlogo

Currently Reading

  • Conn Iggulden: Genghis: Birth of an Empire

    Conn Iggulden: Genghis: Birth of an Empire
    I have always been drawn to stories of Genghis Khan. How was he able to take a primitive people and conquer most of the world? What did the Mongol culture have that enabled this. This is the first of a trilogy on the life of the great Khan. It is great, easy reading and gives a great picture into the life and times of GK. (****)

Read Recently

Blog powered by TypePad
Member since 10/2005