Obama’s Cyber Security Coordinator Is The Perfect Metaphor For CIO Impotence

Written by Evan Schuman
January 27th, 2010

Late last month, President Barrack Obama finally named his cyber coordinator, some 10 months after he declared filling the position a priority. The person who was tapped for the position comes to the job with a resume boasting jobs that include chief information security officer at eBay and chief security officer at Microsoft. But the interesting part is how this new job so closely parallels the worst parts of today’s typical retail CIO gig.

The role itself is a spreadsheet of contradictions. White House jobs, especially those senior enough where the President is personally involved in the selection, are highly coveted. And yet, quite a few of the people who were approached for this particular gig rejected it. This position is supposed to get a lot of POTUS face-time. And yet, in a town known for its inflated titles (another czar anyone?), this job title is the underwhelming Cyber Coordinator. Coordinator? That’s the best they could do?

But there’s a serious issue with this gig. Here’s a short excerpt from a wonderful piece in The Washington Post, which spoke with associates of the people who had turned the gig down: “First, you’re not really a czar, reporting as you would to national security adviser Jim Jones and White House economic adviser Larry Summers. ‘What real authority do you have?’ said one of those who demurred. ‘Who’s going to go to Jim Jones and say, ‘This is what you need to do’? ‘Do you have the President behind you?’ Second, ‘It’s a huge, huge turf war. You have Defense fighting the Treasury fighting the [intelligence] groups fighting Homeland Security’ for control, he said.”

Another person in the piece described the job as “bag-holder in chief: if something bad happens, you’re responsible for cyber security, even if you don’t have the authority to pull it off.”

Sound familiar? Let’s see. Would any corporation put an executive in charge of information security but give that exec no direct-report-authority over the various business unit managers whose attitudes and actions will truly dictate how secure the company is?

In many ways, this lack of authority problem nicely encapsulates all of the problems with IT security management today: all responsibility; no authority; not enough money; plenty of blame.

Clearly, some chains handle this much better than others. But the way authority is handed out says so much about corporate priorities. For example, how many chains have heads of human resources who need to sign off before anyone is hired? That HR exec is in charge of enforcing the company’s hiring policies and is given the veto power to guarantee some level of success. There are finance execs who are empowered to refuse to process any check until the purchasing procedures and contract are satisfactory to that individual’s ideals. Or what about a corporate legal counsel who can kill any contract?

But have you ever seen any IT security chief whose signature was required before a customer data project was launched or a new form of payment accepted? The chief may have input. But if a line-of-business exec wants to disregard that advice and proceed, will that indeed not happen? Typically, that security chief may have to go two or more executive levels before getting to a COO or CEO who can overrule that security-reckless exec’s decision, if they want to.

CEOs have started to grasp the idea of the importance of security, but they haven’t internalized it. Once the security chief’s signature is required for passwords to be issued, projects to be approved and programs to be launched (watch out mobile plans!), things get interesting. The real test will happen a couple of weeks later, when the security chief chooses to reject something. The LOB exec who is impacted will appeal that decision, and it will quickly hit the COO’s or the CEO’s desk. That’s when corporate policy will be made. If the security exec is backed up, suddenly, all company managers will change their attitude.

Talking up security is nice. But unless you can live with doing without various programs, it will never be more than talk. Boards and CEOs learned years ago that it pays to back up their chief legal counsel, CFO and the HR boss. They never needed to learn to listen to the head of sales or the head of engineering. How many more disasters will it take before the security lesson is learned? Maybe they need to take Heartland’s heartaches to heart?


Comments are closed.


StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!

Most Recent Comments

Why Did Gonzales Hackers Like European Cards So Much Better?

I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
@David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.