U.S.Secret Service agent says focus needs to shift from prevention to incident identification
Prevention is better than cure, right? That’s what we were told as kids when it came to trying to avoid catching a cold. That’s what you learn as you grow up and have to start taking responsibility for your actions (assuming you want to, that is). And in reality, that is probably a pretty sensible way to go through life where possible.

The same obviously applies in business, always better to buy the umbrella before it starts raining, they say. And when it comes to security, be it data, network, endpoint and so on, the industry, and anyone with a computer, in fact, has always focused on stopping people from getting in. We spend billions every year on this very important security piece.

But the times they are a changin’ and more and more we are hearing experts say forget the heavy focus on prevention, people are getting into your systems; it’s time to focus on the clean-up; it’s time to spend your money on what you’re going to do after the person has got in, because like it or not, they are getting in.

Even the U.S. Secret Service is pedaling this message. Special agent Tate Jarrow told Cyber Risk in New York Wednesday that the focus is no longer heavily weighted toward prevention. “I think the balance is shifting because I think people are recognizing it’s a kind of war,” he told delegates at theChannelnomics’ sister-publication conference.

After the Target breach at the end of 2013, people started to recognize that if a “giant like that” can be breached, anyone can, which, according to Jarrow, helped to shift focus onto dealing with the breach, rather than trying to stop it from happening.

“Because of the publicity and these incidents that keep happening and being highlighted in the media, I think, from what I hear, that companies are far more willing to spend money and allocate resources to addressing the problem. Before it was a much more difficult ask.”

So what does this mean for the channel? Where does it leave resellers who focus on selling security aimed at preventing cyber breaches?

The answer is, of course, in pretty much the same place as they were before this ‘revelation’ as customers are always going to need to make every effort to prevent their systems from being breached. The difference now is the added opportunity this brings for the channel.

Now, solution providers, after having sold prevention hardware and software, need to ensure their customers understand that while attempts at prevention are necessary, breaches are inevitable in today’s world and a stronger focus on dealing with the aftermath must be adopted.

The good news is that this provides myriad opportunities for resellers to integrate further systems into the customer’s network. The solution provider that explains to the customer this need to shift focus and why, will give him or herself the opportunity to become the trusted advisor the customer turns to to try and understand where they should be spending money to deal with any breach aftermath.

Further, Jarrow advises that the shift in focus should be to incident identification rather than prevention, which presents another opportunity for the channel.

“A better way to look at all this is incident identification: How do we know if we do, in fact, have an incident? That’s where you need to know your baseline. Several companies that I’ve talked to in the past, they hire a third party to work with their own internal forensics where they do a snapshot of their network every so often and they know that this is my ‘baseline’, so if I have something that’s changing sufficiently, this is going to give me an alert that I need to check out.”

Resellers can be advising their customers to identify this baseline so that they can identify where and when it’s shifting. And, of course, customers will likely need someone to help them do this.

“If you don’t have that baseline, you’ll never know if something in your network has changed or something unusual is happening,” Jarrow pointed out. “And I think more and more companies are doing this and there are more and more third-party companies that offer this capability.”

Solution providers should recognize this need and should make sure they are in a position to be that third party, otherwise they may find that the shift in focus from prevention to aftermath may also mean a shift in focus from them to another reseller that has just the solution to mop up the mess.

source: http://www.channelnomics.com/