I hate to say it, but in my humble opinion, for the last decade or so the infosec and cyber security industry seems to have lacked vision, that is, the ability to look around the corner to visualise what the next attack vector or risk might look like. I feel that the industry as a whole, not to mention many of the organisations with which I’ve worked, have leaned too greatly on technological solutions, which on many occasions, I have observed, are bolted on top of flawed systems and architectures–solutions that ultimately do little except paper over the cracks and nevertheless leave the enterprise vulnerable.
On a similar note, we have at the same time been very accommodating to jump into bed with compliance, governance, and standards, all of which we have treated as demi-gods at the expense of practical security solutions and robust activities. There are too many examples of this to even mention.
Things that seemed obvious to me in the past are finally being picked up by others in the industry. For example, while reading the current issue of Infosecurity Magazine, I came upon an article relating to the balance of privacy and security. It’s funny, for when I raised this issue some years ago, I was shot down. But then I guess I should be grateful that at least the magazine in question has caught up, albeit a little late in the day.
Additionally, I recently read in Computing Security that anti-virus software is past its sell-by date, which many, including myself, have been saying for a number of years now.
Agreed, no one knows everything. However, we as an industry need to raise our eyes from the barriers of what we can see and as a group look beyond towards identifying the “unknown unknowns.”
Above all, as painful as it might be [and I know], we must not be afraid to speak out against mass opinion. Trust your instincts and know that the industry will eventually follow–even if it takes a number of years to do so.