• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

Informing mgt their security is leakier than Luisa Zissman's fanny rag

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    Informing mgt their security is leakier than Luisa Zissman's fanny rag

    Conundrum....


    A) Righteously email management, which creates a electronic chain of evidence that by definition MUST be pursued, whipping up some discontent, risking antagonising HE WHO SIGNS MY TIMESHEETS, or;


    B) Drop a quiet word in the meeting room, knowing full well if I tell them verbally, nothing will be done, then walk offsite in a few months with much fatter pockets, but knowing a big brand name who are in the business of safeguarding lives can't even completely safeguard their data?


    WWYD ???

    #2
    Besides telling them about it, can you do anything to sort things that will make you money?

    Comment


      #3
      It's a no brainer. If lives are at stake you have a moral obligation, at least, to step forward and make your case in the email.
      Obviously this will lead to a lot of angst, problems and antagonism and ultimately your sacking, but that is a price worth paying.
      Then nothing will be done and your valuable insight will be missing, ergo the chances to save lives will be immensly reduced. So dont send that email. Its a no brainer
      (\__/)
      (>'.'<)
      ("")("") Born to Drink. Forced to Work

      Comment


        #4
        Are you a security expert? Is it your profession?

        Comment


          #5
          Originally posted by Ticktock View Post
          Besides telling them about it, can you do anything to sort things that will make you money?


          Like what dude? Blackmail them into a rate rise ???!??!!!?!!?

          They'd possibly extend but I'd rather go for a higher rate elsewhere with my newly enhanced skillset.

          Comment


            #6
            The key to getting management on board with security issues is to point how how it will either *save* them money if they fix it, or *cost* them money if they don't.

            You have to couch it in business terms they will understand and see as relevant to them. Just telling them that they have a technical vulnerability in an application relating to a buffer over flow leveraging a cross site scripting exploit (or whatever the problem is) will not get them to take notice, even if they are the IT manager or Director. It will just irritate them.

            You can also throw in the upcoming changes to legislation coming from Europe that will mean increased accountability for data security, introduce legal requirements to report data loss incidents with 24 hours and introduce new sanctions against those that fail to protect information appropriately.

            Full review from a Specialist legal firm here: https://www.slaughterandmay.com/medi...ion-reform.pdf there are lots more if you look for them, all saying the same thing.
            "Being nice costs nothing and sometimes gets you extra bacon" - Pondlife.

            Comment


              #7
              Originally posted by Gym beast View Post
              Like what dude? Blackmail them into a rate rise ???!??!!!?!!?

              They'd possibly extend but I'd rather go for a higher rate elsewhere with my newly enhanced skillset.
              No dude. Like is it something that you have the skills to be able to fix?!?!?!?!?!?!?!?!?!?!
              So you can not only tell them about the problem, but also sell in a solution. Hardly blackmail - they can take you up on the offer or they can source a fix elsewhere.

              In any case, I fail to understand why telling your client "I've spotted a potential issue, here are the details" would get you fired. Perhaps it's because I generally have a fairly decent relationship with my clients.

              Comment


                #8
                Originally posted by Gym beast View Post
                Like what dude? Blackmail them into a rate rise ???!??!!!?!!?

                They'd possibly extend but I'd rather go for a higher rate elsewhere with my newly enhanced skillset.
                With your frankly bizzare thread title and use of the word 'dude', i can only assume you're a pillock or a 15 year old boy.
                I'm sorry, but I'll make no apologies for this

                Pogle is awarded +5 Xeno Geek Points.
                CUK University Challenge Champions 2010
                CUK University Challenge Champions 2012

                Comment


                  #9
                  Is submitting it anonymously an option, as a letter or something like that?
                  Originally posted by MaryPoppins
                  I'd still not breastfeed a nazi
                  Originally posted by vetran
                  Urine is quite nourishing

                  Comment


                    #10
                    Originally posted by Pogle View Post
                    With your frankly bizzare thread title and use of the word 'dude', i can only assume you're a pillock or a 15 year old boy.
                    Snorted my coffee reading this one!

                    'CUK forum personality of 2011 - Winner - Yes really!!!!

                    Comment

                    Working...
                    X