Cybersecurity Lessons from Star Wars: Blame Vader, Not the IT Department

Cybersecurity Lessons from Star Wars: Blame Vader, Not the IT Department

The SIG Resource Center is moving to The SIG Community. If you are a SIG Member, or enrolled in SIG University, and don’t have access yet, you can do so here. Already have access? Log in and visit the new SIG Resource Center.

Original Source: Council on Foreign Relations

In “The Galactic Empire Has Terrible Cybersecurity,”Alex Grigsby looks at a number of high-profile failures, covered in “A New Hope” and the rest of the Star Wars canon.

Unfortunately, the approach he takes to the Galactic Empire obscures the larger, more dangerous issue is its cybersecurity culture.   There are two errors in Grigsby’s analysis, and they are worth examining. As Yoda once said, “Much to learn you still have.”

Grigsby’s first assumption is that more controls leads to better security. But controls need to be deployed judiciously to allow operations to flow. For example, when you have Stormtroopers patrolling in the Death Star, adding layers of access controls may in fact hamper operations. The Shuttle with outdated keys in Return of the Jedi shows that security issues are rampant, and officers are used to escalations. Security processes that are full of routine escalations desensitize people. They get accustomed to saying OK, and are thus unlikely to give their full attention to each escalation…

Contributors:
Categories: ,
SRC Type: , ,

Please log in to download the document.

Please log in to view the video.