Business is the tortoise and hackers the hare

newsguy 0 Tallied Votes 373 Views Share

IT Week that business is just too slow to respond to cyber-criminals, and as a result the hackers are simply worried about their ability to prevent them breaking in.

The article quotes Dan Hubbard, the Vice President of Security Research at Websense as saying that from a purely technological perspective "it is almost possible to admire the ways attackers are creating tools and using modern enterprise IT infrastructure to propagate their attacks" and that these are evolving at a faster pace than the security industry. "They haven't got business processes holding them back; they're free to innovate" he added.

The two technologies causing most concern would appear to be virtualisation and cloud computing. The former is compared to the early days of firewalling at an enterprise level when users complained about being restricted so security was weakened and the bad guys sneaked through, and the same is happening with server virtualisation. Cloud computing is equally scary stuff, it is suggested, with services capable of running an entire OS and streaming enterprise data right out the front door while the IT department only sees web traffic moving around.

To be fair, the article isn't all doom and gloom, but don't read it if you are involved in IT security from your business and want to put a smile on your face today…

Dani AI

Generated

’s point about attackers outpacing business processes is still the clearest way to frame this thread. ’s note about unpatched legacy hosts names the most common root cause. ’s curiosity about cloud is well placed—cloud and virtualization change where risks live and how you see them. is right about the tortoise: steady, disciplined work usually wins.

Practical, high-impact starting steps (do these in order):

  • Inventory and prioritize: find every VM, container, cloud account and map business criticality. If you can’t see it, you can’t protect it.
  • Baseline and patch: build hardened images, apply automated patching for OS and runtimes, and replace mutable servers with immutable images where possible.
  • Identity and access: enforce least privilege, require MFA for all admin and remote access, isolate service accounts and rotate keys.
  • Network controls: segment management planes, use internal firewalls/microsegmentation for east-west traffic, and limit egress.
  • Visibility and detection: centralize logs, enable provider audit trails, run EDR/endpoint telemetry, and tune alerts for high-fidelity detections.
  • Backups and playbooks: verify backups, test restores, and keep a practiced incident response plan.

Cloud-specific cautions: treat cloud as a shared-responsibility model—confirm which controls your provider manages and which you must own. Encrypt sensitive data at rest and in transit. Apply the same hardening and monitoring to cloud workloads as to on-prem systems. Automate security checks into CI/CD and IaC pipelines so misconfigurations are caught before deployment.

Operational advice: measure mean time to detect and respond, run regular tabletop exercises, and aim for automation that reduces manual lag. Start with fast wins (MFA, inventory, critical patches) and build repeatable controls. The “hare” innovates fast; the “tortoise” wins by turning discipline into speed.

Maulth 4 Junior Poster in Training

Cloud computing? Sounds interesting, may have to google that one.

jbennet 1,618 Most Valuable Poster Team Colleague Featured Poster

the fact is that most businesses run unsecure, unpatched systems anyway

loads of places run nt4/os2/other ancient systems e.g redhat 5

Tr0y 0 Newbie Poster

Yes but the tortoise won in the story. :\

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.