Story: A Failed Site Inspection

Catherine Aird, as quoted in the Quote of the Day mailing list (qotd-request@ensu.ucalgary.edu), wrote: "If...you can't be a good example, then you'll just have to be a horrible warning."

Recently, a consumer-products firm with world-wide operations invited one of the authors to a casual tour of one of the company's main sites. The site, located in an office park with several large buildings, included computers for product design and testing, nationwide management of inventory, sales, and customer support. It included a sophisticated, automated voice-response system costing thousands of dollars a month to operate; hundreds of users; and dozens of T1 (1.44 Mbits/sec) communications lines for the corporate network, carrying both voice and data communications.

The company thought that it had reasonable security - given the fact that it didn't have anything to lose. After all, the firm was in the consumer-products business. No government secrets or high-stakes stock and bond trading here.

What We Found ...

After our inspection, the company had some second thoughts about its security. Even without a formal site audit, the following items were discovered during our short visit.

Fire hazards

Potential for eavesdropping and data theft

Easy pickings

Physical access to critical computers

Possibilities for sabotage

"Nothing to Lose?"

Simply by walking through this company's base of operations, we discovered that this company would be an easy target for many attacks - both complicated and primitive. The attacker might be a corporate spy for a competing firm, or might simply be a disgruntled employee. Given the ease of stealing computer equipment, the company also had reason to fear less-than-honest employees. Without adequate inventory or other controls, the company might not be able to discover and prove any wide-scale fraud, nor would they be able to recover insurance in the event of any loss.

Furthermore, despite the fact that the company thought that it had "nothing to lose," an internal estimate had put the cost of computer downtime at several million dollars per hour because of its use in customer-service management, order processing, and parts management. An employee, out for revenge or personal gain, could easily put a serious dent into this company's bottom line with a small expenditure of effort, and little chance of being caught.

Indeed, the company had a lot to lose.

What about your site?