No system is risk-free. But…
In yesterday's security-related email, I made an analogy with some holes in it:
If my house gets robbed, I can't really prevent it happening again just by moving to a different house.
Well, maybe. Sure, merely moving to a new house doesn't necessarily change things.
But in truth, moving to a different house absolutely can reduce the risk -- especially if the first house had crappy locks, no alarm, and was in a high-burglary area.
Likewise:
Changing CRM vendors or architectures can materially change security risk.
"No system is risk-free" does not imply "choice of system doesn’t much affect risk."
The stronger lesson is that security is risk management, not a simple "yes-or-no" attribute of a given product:
architecture,
maintenance,
access controls,
hosting,
backups,
organizational practices,
incident response,
the amount and type of data you're storing,
whether a single breach could expose many organizations at once (as in the Beacon CRM case) …
Improving any of them can reduce your actual level of risk.
All the best,
A.

