Caught between a rock and a hard place, Google did something few companies are brave enough to do — it went public about a data breach. This is especially noble as the company is really betting on cloud computing and SaaS for future growth.
While Google applications were not breached, Google (and all cloud providers) took a PR hit with this incident. That said, Google did a good job of reassuring the public about its security.
Clearly Google has its own business reasons for outing China with regard to its cybersecurity attacks. Nevertheless, there are a few bigger and more ominous warnings contained here:
- Sophisticated adversaries can trump strong security. Google is no TJX–it really knows what it is doing when it comes to securing its networks, servers, and applications. In spite of this expertise, however, its assets were still penetrated. The bad guys are really good at what they do, folks. If this doesn’t illustrate this fact, nothing will.
- Beware of industrial espionage. The breach at Google may have compromised dissident emails but I have no doubt that foreign and possibly state sponsored adversaries are poking at our networks as I write this. American and European tech companies whose business is based upon Intellectual Property (IP) should be especially worried. Sort of gives cybersecurity a whole new level of business value.
- The cyber supply chain may be next. The majority of our technology is now produced off-shore, primarily in Asia. How can we be sure that these components haven’t been compromised already? With the exception of the DOD, NSA, and a few other global government agencies, we are just coming to terms with this risk.
Google has a lot of chutzpah but it is really fighting a battle for the good of Google. It is up to the rest of us to recognize that we are under attack and protect ourselves accordingly.
Related posts:
- Howard Schmidt Appointed as New Cybersecurity Coordinator
- Will Google Tip the Scale Toward OpenID?
- Google + DoubleClick = Privacy Problems
- Cyber Stowaways
- Dell Warns of Malicious Code on Server Motherboards
Tags: cyber supply chain, Cybersecurity, DOD, Federal Government, Google, industrial espionage, NSA




Information security:
blogs


