<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The TJX breach and meaningless analysis</title>
	<atom:link href="http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/</link>
	<description>An Information Security Magazine in a Blog Format</description>
	<lastBuildDate>Mon, 30 Jan 2012 11:01:25 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Alex</title>
		<link>http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/comment-page-1/#comment-73</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Tue, 03 Apr 2007 11:43:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/#comment-73</guid>
		<description>Great question Adam.

Isn&#039;t TJX already an outlier?  How many $50 million dollar breaches are there?

But to answer your question - You know I can&#039;t say &quot;become PCI compliant&quot; :)


It&#039;s my (small sample size warning) experience that retailers, in general, don&#039;t prioritize information risk management.

The argument the CISO would like to make is that spending a few million (more) on IRM budget would reduce the likelihood of incident.  Therefore it makes sense to spend $5million to prevent the probable (or what&#039;s more likely communicated, worst case) loss of $50 million.

The business owners tend to think more in terms of cash flow.  I&#039;m not saying that they like to make  $50 million one time charge-offs, but outfits the size of TJX will accept them.  On the other hand, taking $5 million in cash that could open several new stores or a new market and allocating it to a _potential_ loss situation - that&#039;s just not compelling.

So therefore, I&#039;d have to say that maybe - MAYBE - Ms. Meyrowitz’s peers are making the right business decision if they&#039;re don&#039;t doing anything and roll the dice.

It&#039;s all in the utility of that $5 million they could spend to upgrade their IRM program, isn&#039;t it?</description>
		<content:encoded><![CDATA[<p>Great question Adam.</p>
<p>Isn&#8217;t TJX already an outlier?  How many $50 million dollar breaches are there?</p>
<p>But to answer your question &#8211; You know I can&#8217;t say &#8220;become PCI compliant&#8221; <img src='http://www.bloginfosec.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>It&#8217;s my (small sample size warning) experience that retailers, in general, don&#8217;t prioritize information risk management.</p>
<p>The argument the CISO would like to make is that spending a few million (more) on IRM budget would reduce the likelihood of incident.  Therefore it makes sense to spend $5million to prevent the probable (or what&#8217;s more likely communicated, worst case) loss of $50 million.</p>
<p>The business owners tend to think more in terms of cash flow.  I&#8217;m not saying that they like to make  $50 million one time charge-offs, but outfits the size of TJX will accept them.  On the other hand, taking $5 million in cash that could open several new stores or a new market and allocating it to a _potential_ loss situation &#8211; that&#8217;s just not compelling.</p>
<p>So therefore, I&#8217;d have to say that maybe &#8211; MAYBE &#8211; Ms. Meyrowitz’s peers are making the right business decision if they&#8217;re don&#8217;t doing anything and roll the dice.</p>
<p>It&#8217;s all in the utility of that $5 million they could spend to upgrade their IRM program, isn&#8217;t it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kenneth F. Belva</title>
		<link>http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/comment-page-1/#comment-74</link>
		<dc:creator>Kenneth F. Belva</dc:creator>
		<pubDate>Tue, 03 Apr 2007 10:02:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/#comment-74</guid>
		<description>A program that can satisfactorily determine and reduce technological risk.

What are your suggestions, Adam?</description>
		<content:encoded><![CDATA[<p>A program that can satisfactorily determine and reduce technological risk.</p>
<p>What are your suggestions, Adam?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/comment-page-1/#comment-75</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Tue, 03 Apr 2007 03:24:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/#comment-75</guid>
		<description>To clarify my question--what do her peers do to not be breached, and thus leave TJX as an outlier?</description>
		<content:encoded><![CDATA[<p>To clarify my question&#8211;what do her peers do to not be breached, and thus leave TJX as an outlier?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/comment-page-1/#comment-76</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Mon, 02 Apr 2007 19:28:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/#comment-76</guid>
		<description>What are the factors that cause TJX to become an outlier, and what can Meyrowitz’s peers do to effectively leave her in that outlying state?</description>
		<content:encoded><![CDATA[<p>What are the factors that cause TJX to become an outlier, and what can Meyrowitz’s peers do to effectively leave her in that outlying state?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Walsh</title>
		<link>http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/comment-page-1/#comment-77</link>
		<dc:creator>Chris Walsh</dc:creator>
		<pubDate>Mon, 02 Apr 2007 16:53:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/#comment-77</guid>
		<description>Event studies lose power if they cannot isolate events of interest (eg., breaches) from others that may have occurred during the event window.

Unfortunately, &quot;stuff happens&quot;, and precisely because information about breaches does not magically appear everywhere at once, it is sometimes methodologically necessary to use a somewhat wider event window.  Mandatory centralized disclosure would lessen this.</description>
		<content:encoded><![CDATA[<p>Event studies lose power if they cannot isolate events of interest (eg., breaches) from others that may have occurred during the event window.</p>
<p>Unfortunately, &#8220;stuff happens&#8221;, and precisely because information about breaches does not magically appear everywhere at once, it is sometimes methodologically necessary to use a somewhat wider event window.  Mandatory centralized disclosure would lessen this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/comment-page-1/#comment-79</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Mon, 02 Apr 2007 12:32:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/#comment-79</guid>
		<description>FYI:  The color of an orange depends on how old it is :)</description>
		<content:encoded><![CDATA[<p>FYI:  The color of an orange depends on how old it is <img src='http://www.bloginfosec.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/comment-page-1/#comment-78</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Mon, 02 Apr 2007 12:31:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.bloginfosec.com/2007/04/02/the-tjx-breach-and-meaningless-analysis/#comment-78</guid>
		<description>Perfect article.

Here&#039;s an interesting question - how many of Carol Meyrowitz&#039;s peers do you think are now thinking &quot;Man, I can&#039;t let that happen to me, I better spend some money on InfoSec&quot;?</description>
		<content:encoded><![CDATA[<p>Perfect article.</p>
<p>Here&#8217;s an interesting question &#8211; how many of Carol Meyrowitz&#8217;s peers do you think are now thinking &#8220;Man, I can&#8217;t let that happen to me, I better spend some money on InfoSec&#8221;?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

