No system is risk-free. But…

In yesterday's security-related email, I made an analogy with some holes in it:

If my house gets robbed, I can't really prevent it happening again just by moving to a different house.

Well, maybe. Sure, merely moving to a new house doesn't necessarily change things.

But in truth, moving to a different house absolutely can reduce the risk -- especially if the first house had crappy locks, no alarm, and was in a high-burglary area.

Likewise:

Changing CRM vendors or architectures can materially change security risk.
"No system is risk-free" does not imply "choice of system doesn’t much affect risk."

The stronger lesson is that security is risk management, not a simple "yes-or-no" attribute of a given product:

architecture,
maintenance,
access controls,
hosting,
backups,
organizational practices,
incident response,
the amount and type of data you're storing,
whether a single breach could expose many organizations at once (as in the Beacon CRM case) …

Improving any of them can reduce your actual level of risk.

All the best,
A.

Next
Next

Planning for the worst