I'm just informed enough about IT security to know that I really know very very little about it. That said, I probably know ten times as much as do 99% of people. I'm an expert in my field, and while I've been a jack of all trades on many fronts, today's threats to privacy and IT security require expert knowledge to combat.
I do not have time.
The long winded point I have is that it is now just too damn much work to do it all right. I'm tired after a 10 hour workday. I've obviously taken more steps than most, but it is still leaky as hell...
I need a company/organization that I can reasonably trust to manage my information security/property, to manage my computers, manage my vpns, e.g., to isolate my web browser windows over multiple vpns, ... all of it, and it can't be GOOGLE. My data is my property, as long as I can hold it, so it needs to be a company/organization that built in privacy obligations (like lawyers and doctors supposedly do).
-Signed: A Frustrated Tired Old Nerd (with children)
[Ed's Comment: Does such a company exist? Is it even possible to provide such a service? Or have we just identified a niche in the market for some enterprising person to fill?]
(Score: 1, Interesting) by Anonymous Coward on Monday October 05 2015, @05:58PM
There are many armchair experts at everything™ here on soylent, but I have an ever growing laundry list of credentials. Threats are getting to dynamic and too numerous for a non-specialist to even conceive of.
Don't trust the "usual names" here on soylent. None of them have any more knowledge on security than an average CS or admin does. Think about how many times you have had to patch something; every time that happens, a team of architects, designers, developers, QA, and admins failed simultaneously at keeping your assets secure. Think of them as medical assistants and IA specialists as doctors. They have some knowledge but it is more likely to be wrong via incompleteness as it is to be right.
However, the post I am responding to handles the general philosophy of what you ought to do in a manner which makes me feel it unnecessary to add to. Out of nearly fifty posts, that humble currently +1 insightful AC is the one you should be listening to.
If you want more technical, specific advice, you are going to tell me what the deliverables are; i.e. what your risk tolerance is in technical terms, what your assets are, categorize them, give me information on importance weighting, and what the constraints are; critical use assets, budget in dollars and initial time investment along with an ongoing maintenance budget. That is step zero. A risk assessment that includes use-case analysis, impact analysis, and budgeting. Then we can start working on a development plan. A plan to fail is a failure to plan. Yeah its hard and takes more effort than anyone is comfortable with. That is why nobody gets it right.
(Score: 1, Insightful) by Anonymous Coward on Tuesday October 06 2015, @01:34AM
Thank you very much.
I'm actually not an amateur. I spent ($years) in infosec until I figured out that it's a codeword for scapegoat, then I moved on.
I also figured out that bosses don't care about security, they care about not being sued - which is a kind of security itself. But that meant that all my employers were always primed for catastrophe.
The rest of my advice simply follows directly from that.
It's really all about reducing exposure in the teeth of cruel reality, and being prepared for when it all goes bad.