{"id":2573,"date":"2020-07-28T09:28:41","date_gmt":"2020-07-28T13:28:41","guid":{"rendered":"https:\/\/zzzptm.com\/wordpress\/?p=2573"},"modified":"2020-07-28T09:28:41","modified_gmt":"2020-07-28T13:28:41","slug":"when-roi-becomes-dos","status":"publish","type":"post","link":"https:\/\/zzzptm.com\/wordpress\/?p=2573","title":{"rendered":"When RoI becomes DoS"},"content":{"rendered":"\n<p>Here&#8217;s the scenario: a firm purchases a security solution. The firm skimps on professional&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/services\">services<\/a>&nbsp;and\/or rushes the schedule on implementation and\/or neglects to maintain the product properly.<\/p>\n\n\n\n<p>Do not be surprised when, one day, that&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/security-solution\">security solution<\/a>&nbsp;does something that results in a system-wide outage:<\/p>\n\n\n\n<p><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/peerlyst\/image\/upload\/c_limit,dpr_2.0,f_auto,fl_lossy,q_auto\/v1\/post-attachments\/explosion1_bkmnrt\">Fig. 1: System-wide outage<\/p>\n\n\n\n<p>Why were those decisions made? Because professional services, longer timelines, and proper staffing\/coordination are all costs, and we demand better return on investment!<\/p>\n\n\n\n<p>The problem is that many&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/security-systems\">security systems<\/a>&nbsp;have the capability to shut down the entire&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/network\">network<\/a>, or kill&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/access\">access<\/a>&nbsp;to PCs, or other stuff that, well, keeps&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/devices\">devices<\/a>&nbsp;completely safe from&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/threats\">threats<\/a>&nbsp;by denying any access to them whatsoever. And while an enraged&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/executive\">executive<\/a>&nbsp;can satisfy his need to offer up a sacrifice to the shareholders in his firm by kicking out the&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/vendor\">vendor<\/a>&nbsp;closest to the outage, there&#8217;s still the problem of cleaning up the after-effects. The vendor typically survives to roll out product another day, but the firm is left with the same problem as before &#8211; and will have to now go to another vendor whose product can be just as destructive as the first, if implemented incorrectly.<\/p>\n\n\n\n<p><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/peerlyst\/image\/upload\/c_limit,dpr_2.0,f_auto,fl_lossy,q_auto\/v1\/post-attachments\/explosion2_ijrp5o\">Fig. 2: Vendor making an exit from firm after system-wide outage<\/p>\n\n\n\n<p>Worse, the firm may choose to reject all&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/vendors\">vendors<\/a>&nbsp;of a particular solution and instead seek to eliminate all technology that requires such a solution with a Bold Move. &#8220;We&#8217;re going to get rid of all our&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/windows\">Windows<\/a>&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/workstations\">workstations<\/a>&nbsp;and switch over to thin clients that run on&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/burner-phones\">burner phones<\/a>, so we don&#8217;t need&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/firewalls\">firewalls<\/a>&nbsp;anymore.&#8221; Yeah. Good luck with that. This much I know: whatever product is mentioned as part of a Bold Move&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/strategy\">Strategy<\/a>&nbsp;definitely has an amazing salesperson in that region. Chances are, that Bold Move is going to involve a purchase order that skimps on professional services, compresses timelines, and lacks proper&nbsp;<a href=\"https:\/\/www.peerlyst.com\/tags\/staffing\">staffing<\/a>&nbsp;and coordination, which may result not in a system-wide outage, but an undesired result after a lofty promise.<\/p>\n\n\n\n<p><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/peerlyst\/image\/upload\/c_limit,dpr_2.0,f_auto,fl_lossy,q_auto\/v1\/post-attachments\/fail2_o1vi4s\">Fig. 3: Undesired result after a lofty promise<\/p>\n\n\n\n<p>This, in turn, can result in the executive that oversaw a failed vendor implementation and a failed Big Move taking an opportunity at another company. This makes way for a new executive to step in and try his hand at choosing between doing things on the cheap or doing things correctly. Because RoI is much easier to measure than the chance that a botched implementation results in a DoS, my money&#8217;s on the cheap.<\/p>\n\n\n\n<p><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/peerlyst\/image\/upload\/c_limit,dpr_2.0,f_auto,fl_lossy,q_auto\/v1\/post-attachments\/curly_i2afd8\">Fig. 4: Another botched implementation of a security product&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here&#8217;s the scenario: a firm purchases a security solution. The firm skimps on professional&nbsp;services&nbsp;and\/or rushes the schedule on implementation and\/or neglects to maintain the product properly. Do not be surprised when, one day, that&nbsp;security solution&nbsp;does something that results in a system-wide outage: Fig. 1: System-wide outage Why were those decisions made? Because professional services, longer [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[12],"tags":[],"class_list":["post-2573","post","type-post","status-publish","format-standard","hentry","category-security"],"_links":{"self":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2573"}],"version-history":[{"count":1,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2573\/revisions"}],"predecessor-version":[{"id":2574,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/2573\/revisions\/2574"}],"wp:attachment":[{"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2573"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zzzptm.com\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}