Dirty secrets of IT security vendors

IBM ISS Security Strategist Joshua Corman speaks out on what he believes are eight blights affecting the security industry.


Joshua Corman would seem an unlikely critic of IT security vendors. After all, he works for one. Yet Corman, principal security strategist for IBM's Internet Security Systems division, is speaking out about what he sees as eight trends undermining the ability of IT security practitioners to mount an effective defence against online outlaws.

Having worked for the vendor side, Corman says he is uniquely positioned to grasp its weaknesses up close. And so, with a PowerPoint presentation on the "8 Dirty Secrets" of the market in hand, he has traveled to seminars and worked the phones, hoping to motivate a change for the better. Here is the breakdown of those 8 dirty secrets and what Corman sees as practical ways to keep the vendors honest.

Dirty Secret 1: Vendors don't need to be ahead of the threat, just the buyer
This is the problem that leads to the seven "dirty secrets" that follow. In essence, Corman said, the goal of the security market is to make money, not to ensure the customer's security.

Tom Vredenburg, regional IM manager for Houston-based Wartsila Corp., said Corman's take is consistent with what he has experienced in the trenches. "Not only has security become a phantom deliverable, but the vendors themselves have become equally tough to pin down and evaluate. Are they software sellers or risk managers? Are they service providers or network designers? Am I buying partnerships or licenses? Most of them don't know themselves what they are -- only that they need to sell something that most people don't really want to buy in the first place -- insurance."

Several security vendors defended themselves against that notion, including Cloakware product management director Terry Brown.

"Ultimately, there's still a quest for dollars across the security market, but now, because of the economic downturn, both vendors and customers are developing more reasonable expectations, right-sizing the market and IT spending."

Dirty Secret 2: AV certification omissions
While AV tools detect replicating malware like worms, they fail to identify such as non-replicating malware as Trojans. Though Trojans have been around since the beginning of malicious code, Corman said there's no accountability in AV certification tests. Companies are therefore lulled into a false sense of security, wrongly believing the AV they purchased is protecting them from all malware.

"Today Trojans and other forms on non-replicating malcode constitute 80 percent or more of the threats businesses are likely to face," Corman said. "AV accountability metrics are simply no longer reflective of the true state of threat."

"Recommended For You"

Proctor & Gamble picks IBM for outsourced security Enterprise is being overrun with consumer devices