Inside Intel's security organisation

"Here You Have" e-mail virus infects Intel employees' computers

The "Here You Have" e-mail virus that ripped across the Internet last week didn't leave Intel unscathed: The 80,000-plus employee company had 4,400 employees click on the malware and wound up with 400 infected machines.

Malcolm Harkins, Intel's chief information security officer, would naturally rather have had no one at the company take the bait but the way he sees it, it's better than having 44,000 people click on it.

He sees users wanting to click on things being one of five irrefutable laws of information security, which he outlined during a talk about the most significant vulnerability ("misperception of risk" by IT security, business execs and end users) facing organizations at Forrester's Security Forum in Boston on Thursday.

Forrester: Trust no one when it comes to IT security

Harkins also shared a story about Intel CEO Paul Otellini getting ensnared in a phishing trap that looked legit by exploiting Intel's involvement in an actual lawsuit. Otellini figured out the error of his ways soon after but not before his system's cache – presumably including "remember me" passwords -- was extracted. Harkins said the company was protected but that Otellini learned a lesson and wound up having to go through the hassle of changing banking accounts.

In addition to users wanting to click, another irrefutable security law is that information wants to be free and that people want to share it.

Also on the list: • Code wants to be wrong. Harkins cited mobile apps: "What kind of security do we think is in something that sells for 99 cents? Not much." • Services want to be on. Harkins asked if anyone in the audience had been negatively affected by a certain DAT (virus definition file) issue a while back, referring to the flawed McAfee update that froze PCs during April, and got more than a few nodding heads. • Security features can be used for harm. Harkins painted a grim scenario in which a rogue admin managing a certificate authority or an application vulnerability was to change encryption keys and turn all of an organization's encrypted laptops into bricks.

As long as an organization recognizes these truisms, it can strategize to deal with them by making predictions, being persistent about necessary safeguards, having patience and being prepared, Harkins said.

"Compromise is inevitable under any computing model," such as whether you've got thick or thin clients, Windows or Linux machines, Harkins said. Even if you can't invest in all the resources you'd like to secure your network, you can at least prepare yourself to handle all sorts of threats by at least having a concept of what might occur, he said.

Intel has gotten a handle on security in part by conducting thorough assessments via a multidisciplinary emerging threat analysis team that brainstorms and plays war games regarding threats that could bite Intel in the backside, Harkins said.

Harkins has also emphasized throughout Intel's security organization attention to what makes one person perceive a risk as high that another sees as low risk. For example, he said upon spotting a laptop infected with malware known to be part of a botnet, IT security would want to wipe the computer clean of the malware whereas the end user might not see the point since the computer is running fine. The big problem, he said, is that some exaggerate risk while others far underestimate it.

Join the PC World newsletter!

Error: Please check your email address.

Tags securityintel

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Bob Brown

Network World
Show Comments

Essentials

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Michael Hargreaves

Windows 10 for Business / Dell XPS

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Kathy Cassidy

STYLISTIC Q702

First impression on unpacking the Q702 test unit was the solid feel and clean, minimalist styling.

Anthony Grifoni

STYLISTIC Q572

For work use, Microsoft Word and Excel programs pre-installed on the device are adequate for preparing short documents.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?