Newsletter:

Skip Navigation LinksHome > News > Security > Patching no longer works, says Cisco CSO

Patching no longer works, says Cisco CSO

By Negar Salek in the Gold Coast
20 May 2008 12:55PM
Tags: auscert

Patching is dead and costly, according to John Stewart, chief security officer at Cisco Systems, who presented a keynote address at the AusCERT conference on the Gold Coast, today.

24/7 online access requirements; sheer volume of client seats requiring patches (especially at an enterprise level,) and surging malware numbers are fuelling the demise of the age-old practice.

“Patching is a deadline of first defense,” Stewart said. “I can’t use patching environments of anti-virus. It’s already the case that we have consumed or over consumed those two technologies in a way to defend.”

In fact, Stewart claimed that to mathematically keep up with the frequency of new malware is now impossible.

Using Cisco as an example, Stewart said applying patches has become problematic as it requires offline time.

“I rely on my infrastructure, I can’t have it offline,” Stewart said. “[And] I only want to patch it when I can take it offline. Those are very restrictive time frames.”

As well as an expensive one he added.

"When a company like Cisco is a 73,000 person company, it has 73,000 seats of anti-virus, it’s a phenomenal amount of capital expense.”

Stewart also called on security professionals to share information and collaborate further.

“One of the things I want to be sure of is that you learn from my mistakes so if you’re about to embark on something, you can learn what we learned and hopefully not repeat some of the mistakes we made,” he said.

“Think about what the hacking community is doing. They’re doing that already, we’re just not.”

   


Ads by Google





Product Reviews

Star Rating
The Aventail EX-1600 is a high-end SSL VPN designed for the needs of medium to large enterprises.
Star Rating
The Sophos NAC Advanced product is a well-designed offering which balances the need for ease of...
Star Rating
The Kerio WinRoute Firewall is an interesting product for this category.
Star Rating
The BiGuard S6000 extends the network to the remote user with features such as Network Extender, Transport...
Star Rating
Sendmail Sentrion DS 3.0 is a rack-mounted email authentication appliance used strictly for applying digital...
ITNews NetSeminars
TopTopics
(18960) -  iphone
(6352) -  telstra
(4250) -  accc
(4134) -  broadband
(4101) -  online
(4098) -  hack
(3752) -  australia
(3616) -  government
(3285) -  smartphone
(2924) -  microsoft
(2686) -  computer
(2091) -  apple
(1905) -  yahoo
(1815) -  spam
(1814) -  security