| Mike Sconzo, principal security consultant, NetWitness, believes that industries in the critical infrastructures, such as utilities and manufacturing, are starting to take the steps necessary to become more resilient. "Critical infrastructures are going through the same kind of growing pains as the IT industry did over the years," Sconzo says. "For instance, the first version of NERC's CIP (North American Electric Reliability Corporation's Critical Infrastructure Protection) standard consisted of primarily of security box checking. Meaning if you do X, Y, and Y you are supposedly secure. I'm hearing more interest now, however, in moving toward more risk-based assessments. A lot of people are realizing that risk-based security management is not such a horrific idea," he says |



