ALKHOBAR, 24 May 2005 — A few years ago finding an IT security specialist outside the US or large European nations was nearly impossible. Fortunately that situation is changing. Smaller nations and even countries in the developing world are recognizing the importance of home grown network security specialists.

Murat Lostar, Information Security Consultant, Lostar Information Security, is becoming well-known in his native Turkey. When Microsoft was looking for a young professional in the field to talk about security at the Gulf Developer’s Conference 2005, they didn’t turn to a resource in the US. Instead they invited Lostar to come and have some frank discussions with Arab developers about the changing requirements of IT security.

Lostar was an excellent choice to talk about IT security with developers used to functioning in a market where security hasn’t been a priority for application development. And Lostar didn’t find it too disturbing or surprising that many people here in Saudi Arabia don’t have basic security on their computers such as firewalls or antivirus software.

“Technology has come into people’s lives more than most of them could ever imagine. People haven’t had time to absorb all the implications of technology into their ideas and culture,” said Lostar. “Think of the locks on our doors. We instinctively understand the importance of physical locks for security because enough generations have had such locks to know what they are. Each time we leave home it is natural now to lock the door. With technology, most people still can’t understand what is a lock and how it works.”

According to Lostar, part of the problem with getting people to lock up data is that they can’t see it, so they are always forgetting that it exists. Plus, even though they know their data is important, since it has never been given a specific value, no amount has been assigned to protect it.

“A businessman can see that he has desks and chairs and goods at his company. If these disappear, he knows they’re gone. If information disappears it’s usually a big surprise and some companies never know when their information has been stolen,” Lostar advised. “Another problem is that most companies don’t list their data among their assets. These companies put a real figure on their physical assets but they don’t have a clue about the worth of their data. The value of their information isn’t written into their balance sheets — yet. It’s hard to justify spending money on security to protect data that is worthless on a company’s bottom line.”

Providing a valuation for corporate data and digital information is essential because only then can a business decide the resources required to protect it. The fact is that protecting information costs money from time to time and it’s an ongoing expense. Unlike physical locks, it’s not a purchase-and-forget-it proposition. Hardware and software must be bought, licensed and upgraded. Staff must be trained to implement and use the IT security. Policies must be formulated to address data access or restriction.

“Again and again we tell companies that IT security is about technology, people and processes,” said Lostar. “Without having all three there is no real IT security. When we start talking to companies about making purchases, training staff and creating policies they are often unhappy with these expenses. But if a company already knows the dollar value of its information, then that company will consider security an investment, not an expense.”

How did we get into the current IT security mess? Part of the problem according to Lostar is that for a long time software vendors had the goal of being first on the market with their applications. The performance of the software for the required tasks was the most important thing — not security. The vendors could get away with such an approach because four or five years ago the market didn’t care much about security. Then hackers and malicious code writers came along and things became very unpleasant in the virtual world. Additionally, technology allowed us to put more and more valuable information into networks and applications. Suddenly we all found that we’d created huge virtual vaults of information and we didn’t have any idea how to effectively keep thieves away from our data.

“Now security is a subject that everyone, vendors, customers and developers have to care about,” said Lostar. “All vendors have started security initiatives although Microsoft’s is perhaps the most famous. That is not to say that all the security problems are gone, but things are getting better.”

But Lostar is emphatic that complacency is a big mistake when it comes to IT security.

“There will always be new ways of attacking,” he remarked. “Look at it from the concept of computer viruses. Until now we have never been able to free ourselves from their threat. Yes, there are antivirus firms and solutions but it’s like a horse race. There are constantly new viruses and the antivirus companies are eternally racing to beat that code. One virus is neutralized and then another one springs up.”

The future for IT security looks increasingly challenging, too. More and more devices are “smart” and it’s only a matter of time before hackers decide that a critical mass has been reached, which makes attacking such gadgets a certainty.

“The first mobile phones were only used for voice applications. Now we have smart phones and so we have the first real mobile viruses,” said Lostar “Most of the devices in our lives are integrating or merging. Soon what we will be able to do with a smart phone is what we could do in the past with a computer. Malicious code will be proliferating. These criminal code writers want their viruses to be spread as much as possible. Mainframes have practically no viruses. The average malicious code writer doesn’t have much access to a mainframe to play around with. But mobile devices are becoming more and more common. This makes them attractive to people who write viruses. Any mobile device that has the capability to communicate can be targeted in an attack. If a device is reachable, it’s accessible.”

What could that mean? Well, the fact is that a laptop crash will seem like a minor problem compared to what we may have to deal with.

“People can’t imagine anything worse than PC infected with a virus, but more and more vehicles now come with integrated digital technology — smart cars,” commented Lostar. “Some of the newest car models are able to communicate with the manufacturer in the case of a malfunction. This is supposed to be convenient for the car’s owners but I believe it will have the downside of allowing the cars to be reachable by hackers and susceptible to attack by malicious code. Just envision your car coming to a complete stop in the middle of nowhere because the smart device in the engine has been disabled by a virus or hacker. Wait a few years and I’m sure we’ll see that.”

* * *

(Comments to [email protected].)