Skip to main content

schneier-questions-need-for-himself

I read with delight this quote from omnipresent security pundit Bruce Schneier questioning the reasons for the existance of the security industry:

"We shouldn't have to come and find a company to secure our e-mail. E-mail should already be secure. We shouldn't have to buy from somebody to secure our network or servers. Our networks and servers should already be secure."

Does he also question the existance of the automobile parts after-market? I wonder what the automobile market would look like if there were no safety regulations? I bet there would be an "automobile safety industry" that offered a much greater diversity of products at better prices increasing the utility of all market participants. Perhaps the U.S. automakers would be stronger players. I'm glad that there are multiple options for securing my network. I don't want to buy a firewall with my network. I want to choose my own.

I liked this from John Collins of Freeform Dynamics:

"I always used to think the security industry existed to make people scared and then sell them something to protect them from what they were afraid of. But now I think it exists because of what people are prepared to buy," he said, adding that investment in security products tends to be reactive to a problem a company has already suffered, making security a "fire extinguisher industry."

I think that the tipping point that Ian G is looking for will occur when companies invest in security products before they suffer because of what their peers have suffered, reaching a nirvana where they invest the appropriate amount in security to match their risks to their desired weighted-average cost of capital. However, without a flourishing, varied and robust security industry, many companies will not be able to reach that plateau.

Current rating: 1

Recent Posts

Archive

2024
2022
2021
2019
2018
2017
2016
2015
2014
2013
2012
2011
2010
2009
2008

Categories

Tags

Authors

Feeds

RSS / Atom