禍起蕭墻:來自合作伙伴的安全風險
????我借剛才那個比喻擴展開來講吧:這家購物中心已落成并且開始運營,但購物中心的老板根本就不知道有哪些人來往這個購物中心,去哪些商店購物,甚至就連這些人是怎么進出的都不知道。正如我們所看到的那樣,企業內部這種缺乏深謀遠慮的行為使得所謂的“高級持續性威脅(APT)”攻擊能夠持續存在,甚至加劇。 ????作為一名投資者,我和創業者和初創公司共事——比如 BitSight Technologies公司。這家公司認識到,市場對可解讀企業產生的數據的工具有著迫切的需求,同時還認識到,現代企業依靠的商業合作伙伴、承包商和供應商這個復雜的網絡存在固有風險。 ????今后的歲月里,這些工具將會幫助企業將業務從高風險供應商轉向低風險供應商;一旦某個商業伙伴淪陷,企業能借助這些工具關閉其IT環境與這個商業伙伴IT環境之間的鏈接;同時它還能要求行為不端的承包商走人。用《圣經》上的比喻來說:比起預測暴風雨,還是建造諾亞方舟來得更重要。 ????本文作者文奇?加納森是門羅風險投資公司合伙人。(財富中文網) ????譯者:iDo98???? |
????To extend my earlier analogy: The mall is up and running, but the mall owner has no idea who is coming and going, what stores they visit or even how they enter and leave. As we've seen, that myopia within organizations allows so-called "APT" attacks to linger, and fester. ????As an investor, I am working with entrepreneurs and start-up firms, like BitSight Technologies, that recognize the urgent need for tools that can make sense of the data generated by enterprises and the risk inherent in the complex web of business partners, contractors and suppliers that modern organizations rely on. ????In the months and years ahead, these tools will allow enterprises to shift business from high-risk to lower-risk suppliers, shut down links between their IT environment and those of a compromised business partner and show the door to misbehaving contractors. To use a biblical analogy: Predicting rain doesn't count for much. Building arks does. ????Venky Ganesan is a partner with venture capital firm Menlo Ventures. |