On last.fm: Taylor Swift photos and free music!
BNET Business Network:
BNET
TechRepublic
ZDNet

Talkback

Add your opinion
advertisement

From our video sponsors

advertisement
Security's hidden costs

The costs of security in terms of downtime and clean-up can be considerable. But as Determina's Charles Renert explains, there are also hidden costs, such as false positives and performance hits.

My name is Charles Renert and I'm the head of security research and development at Determina Corporation. I'm here to talk about the hidden cost of security.

We all know that worms and Trojans and a bunch of attacks that are spreading in the Internet and causing problems and so a lot of folks are looking to security solutions to fix them up. Now, we all agree you're going to need some level of security to protect yourself. The question is, does it cost more than it should in order to protect you?

So, when we're talking about attacks, let's talk about just the cost of the attacks themselves. I mean you're going to get downtime. If you're attacked, you're going to have to take your machine down. You're going to have to fix it up. There's a clean-up cost. Maybe you'll lose some confidentiality. You'll lose some key data on your system, and you'll never be able to effectively recover them. So, when we're talking about cost, maybe downtime is, you know, not substantial. Maybe you can get yourself up quickly. Typically clean up is very expensive. I mean, actually the clean-up of a number of machines can take a great deal of time and confidentiality is really unbounded, but I mean, it can be very sensitive information that you wouldn't want released and so this can actually be a very critical loss. So, when we talk about security, the idea is to protect you from these losses.

However, some security has some issues. False positives. A false positive is when a security product thinks you're being attacked, when you're not. So, you might actually incur a lot of costs here in terms of downtime or clean-up that you really didn't need to. Performance. Sometimes security solutions actually grind your computer down to a halt or so slow that you actually can't use it for what you intended. Again downtime.

Circumvention. Some security products actually don't really detect much in the way of a broad class of threat. So when a new attack comes, they're not actually going to be able to protect you. So when that happens, you're effectively reintroducing all of the costs.

And then finally, there's an operational cost. So, in order to manage security, frequently solutions will require training or updates or other things that require you to go and modify your system and do a number of updates.

So, what I want you to take away is that, with respect to security, you want to make sure that as you're trying to protect against the costs here, that you're also avoiding the costs here because if you're actually not careful, what can wind up happening is you'll just wind up paying lots.