{"id":2525,"date":"2020-07-28T08:58:50","date_gmt":"2020-07-28T12:58:50","guid":{"rendered":"https:\/\/zzzptm.com\/wordpress\/?p=2525"},"modified":"2020-07-28T08:58:50","modified_gmt":"2020-07-28T12:58:50","slug":"just-in-time-needs-to-become-just-in-case","status":"publish","type":"post","link":"https:\/\/zzzptm.com\/wordpress\/?p=2525","title":{"rendered":"&#8220;Just in Time&#8221; Needs to Become &#8220;Just in Case&#8221;"},"content":{"rendered":"\n<p>On 12 December 2019, Chinese broadcaster&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/cctv\">CCTV<\/a>&nbsp;announced that a new viral outbreak had started in the city of Wuhan. While the first confirmed case was on 17 November, it was not until more cases came to the attention of authorities &#8211; in a way that they could not ignore &#8211; that the Chinese&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/government\">government<\/a>&nbsp;began to publicly acknowledge something new was underway. Following that 12 December announcement, the world began to transform. As output ground to a halt in much of&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/china\">China<\/a>, factories depending on Chinese raw and intermediate goods had to slow or stop production. The&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/lesson\">lesson<\/a>&nbsp;learned was both sharp and timely &#8211; &#8220;just in time&#8221; methods of production left firms&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/vulnerable\">vulnerable<\/a>&nbsp;to disruptions in the supply chain. If firms kept a reserve of parts, those could have lasted through at least some of the lapse, if not all of it, and would have allowed for less economic dislocation.<\/p>\n\n\n\n<p>Part of the &#8220;just in time&#8221; mentality of go, go, go all the time is the ideal of &#8220;five nines&#8221; or even &#8220;six nines&#8221; &#8211; 99.999% or more uptime for all systems. While, yes, this does mean the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/product\">product<\/a>&nbsp;always moves out the door, it also means that the things making those products go&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/unpatched\">unpatched<\/a>&nbsp;and unprotected for long stretches of time, making them prime&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/targets\">targets<\/a>&nbsp;for attackers. Those&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/vulnerabilities\">vulnerabilities<\/a>&nbsp;leave the firm just one click on an email attachment away from utter ruin.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/peerlyst\/image\/upload\/c_limit,dpr_2.0,f_auto,fl_lossy,h_316,q_auto,w_316\/v1\/post-attachments\/just_in_time_qbvuin\" alt=\"\"\/><\/figure>\n\n\n\n<p>Just as there&#8217;s an argument to be made for adding some&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/storage\">storage<\/a>&nbsp;capacity to help weather&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/supply-chain\">supply chain<\/a>&nbsp;shocks, we need to talk about &#8220;two nines&#8221; uptime as a way to avoid eventual &#8220;infinite zeroes&#8221; uptime conditions. If you give me 100 minutes each week, I can get a breathing space to apply needed&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/patches\">patches<\/a>&nbsp;on production servers and equipment. If I don&#8217;t need a week&#8217;s 100 minutes, let it roll up into next week &#8211; maybe I&#8217;ll need more time to apply the next&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/patch\">patch<\/a>, who knows? But let me have a reserve of time during the working year so I can do my&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/job\">job<\/a>&nbsp;to patch and protect. Let me reboot gear that needs its queues cleared, let me stop and restart&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/services\">services<\/a>&nbsp;on servers, let me keep things up to date so we can spend the other 99% of the time feeling more confident about the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/resiliency\">resiliency<\/a>&nbsp;of the environment&#8230; just in case, ok?<\/p>\n\n\n\n<p>I&#8217;m aware that executives in most nations have a fiduciary duty to maximize shareholder value. That&#8217;s a short term goal that is itself replete with abuses when it considers&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/employees\">employees<\/a>&nbsp;as expenses as opposed to capital or when it looks at wages as a race to the bottom. I&#8217;ll leave those criticisms of neoliberalism for another paper at another time. But here is where I criticize those fiduciary duties as regards security. Maximizing shareholder value means minimizing expenses in the short run, and security is seen as an expense, not as an investment. Current accounting structures blind the books to an ability to properly assess the value of a security system in its ability to provide long-term&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/stability\">stability<\/a>&nbsp;and constancy. I would love it if share prices for a firm jumped every time it announced it was undertaking a security project. Sadly, they&#8217;re more likely to drop as those expenditures for security are seen as short-term profits lost, not long-term profits gained.<\/p>\n\n\n\n<p>In the meantime, I&#8217;m reading headlines about increases in&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/ransomware\">ransomware<\/a>&nbsp;and other&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/attacks\">attacks<\/a>&nbsp;using email attachments with references to&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/coronavirus\">coronavirus<\/a>,&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/covid-19\">COVID-19<\/a>, and even SARS-CoV-2 to successfully&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/penetrate\">penetrate<\/a>&nbsp;those PCs bridging&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/traffic\">traffic<\/a>&nbsp;between the raw&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/internet\">Internet<\/a>&nbsp;and the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/corporate\">corporate<\/a>&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/vpn\">VPN<\/a>, because it was cheaper to use a split-tunnel solution than to backhaul all the Internet traffic through the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/corporate-networks\">corporate networks<\/a>&nbsp;&#8211; and also because it was seen as &#8220;nicer&#8221; than banning non-business related Internet usage for&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/devices\">devices<\/a>&nbsp;on the VPN. I know I&#8217;m getting into just one of the technical weedpatches of issues, there are others&#8230; and if firms could see their way towards working more for the long haul than the short-term gain, we&#8217;d likely have the right&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/solutions\">solutions<\/a>&nbsp;instead of the cheapest and easiest, which are never the strongest.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>On 12 December 2019, Chinese broadcaster&nbsp;CCTV&nbsp;announced that a new viral outbreak had started in the city of Wuhan. While the first confirmed case was on 17 November, it was not until more cases came to the attention of authorities &#8211; in a way that they could not ignore &#8211; that the Chinese&nbsp;government&nbsp;began to publicly acknowledge [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[],"class_list":["post-2525","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2525","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2525"}],"version-history":[{"count":1,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2525\/revisions"}],"predecessor-version":[{"id":2526,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2525\/revisions\/2526"}],"wp:attachment":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}