View profile

Security | Life | Cynicism - Issue #4

March 8 · Issue #4 · View online
Security | Life | Cynicism
Extreme ownership

Before we kick things off, click on this link and see this short clip and then we can talk. It’s ok, I can wait.
Rep. Katie Porter on Twitter: "For over a year, a major cyber attack against @solarwinds enabled foreign hackers to quietly spy on @DeptofDefense, @USTreasury, and @DHSgov. Today, I demanded answers from the company’s CEO—like why their servers were accessible with the password “Solarwinds123.” Yes, really.…"
If my kid was outside and kicked a football that went an broke a neighbours window, I’d fully expect the neighbour to come and talk to me about it. I’d be apologetic, and offer to replace the window. What I wouldn’t do is throw my kid to the wolves, tell him it’s his fault and try to wash my hands of it.
But that’s exactly what Solarwinds CEO tried to do by blaming an intern for setting a weak password of solarwinds123 which allowed the organisation to be breached.
Even if it is true that an intern in 2017 set that password, why did you allow an intern to set a password? Why didn’t you have password policies or audits? Why was there no multi factor authentication? Why did it go undetected for about 4 years? Why why why?
I get it, security is hard and mistakes happen. We’ve all been there and seen things go wrong. But if you’re the type of person to try and pin the whole issue on an intern, then you can expect far more criticism than had you just taken it on the chin.
Extreme Ownership is the book by ex navy seals Jokko Wilink and Leif Babin. In the book, they talk about what they key to being a great leader is. As the title suggests, leaders require extreme ownership - to own their team’s mistakes and failures without blame of excuses - and objectively assess what works and what doesn’t in order to constantly improve.
The CEO of Solarwinds could do with reading the book.
If reading is too much effort, then spare 14 minutes listening to Jocko’s TED talk.
Extreme Ownership | Jocko Willink | TEDxUniversityofNevada
I used to be under the impression this was a meme.
Did you enjoy this issue?
If you don't want these updates anymore, please unsubscribe here.
If you were forwarded this newsletter and you like it, you can subscribe here.
Powered by Revue