Tuesday | 7 July, 2009
CSO
Ouch! Security pros' worst mistakes
We've all done regrettable things on the job, but does any valuable wisdom come of it? Four security pros candidly explain their biggest blunders and what they learned in the process
Bill Brenner (CSO (US)) 04/09/2008 08:05:00

4. OPEN MOUTH, INSERT BOTH FEET, WITH SHOES

  • Mistake maker: Dave Bixler

  • Position: CISO, Siemens IT Solutions and Services

  • Location: Ohio, US

  • The incident: Sarcasm with the CEO

"Many years ago, during one of the last great e-mail-based virus outbreaks -- it was six or seven years ago and may have been the Anna Kournikova virus -- I was wearing two hats as the information security person, and also responsible for infrastructure, including the e-mail servers. The virus outbreak had spread rapidly through all seven of our mail servers, and by the time we had a virus signature that could clean out the virus, the mail servers had ground to a screeching halt.

"We took the servers offline and were in the process of getting them cleaned up when I received a call from the CEO, asking for a status. I proceeded to explain where we were, what the impact was, and how long it would take before the servers would be back online. At the end of my explanation, he joked 'Better you than me.' Naturally, my mouth engaged well in advance of my brain and I responded with 'Well, that's what you underpay me for.'"

THE LESSON

Think before you speak.

"Fortunately, my CEO had an excellent sense of humor and I was still employed the following day."

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

The business justification for data security

In the information security world we face two major types of threats: "noisy" threats which directly interfere with our ability to do business and "quiet" threats which cause real damage, but don't necessarily prevent people from doing their jobs. Read on to discover how to combat both types of threats and to justify the use of data security within your business.

Sponsored Links