From the filing: We experienced security breaches in the corporate network in 2010 which were not sufficiently reported to Management.
In 2010, the Company faced several successful attacks against its corporate network in which access was gained to information on a small portion of our computers and servers. We have investigated and do not believe these attacks breached the servers that support our Domain Name System (“DNS”) network. Information stored on the compromised corporate systems was exfiltrated. The Company’s information security group was aware of the attacks shortly after the time of their occurrence and the group implemented remedial measures designed to mitigate the attacks and to detect and thwart similar additional attacks. However, given the nature of such attacks, we cannot assure that our remedial actions will be sufficient to thwart future attacks or prevent the future loss of information. In addition, although the Company is unaware of any situation in which possibly exfiltrated information has been used, we are unable to assure that such information was not or could not be used in the future.
The occurrences of the attacks were not sufficiently reported to the Company’s management at the time they occurred for the purpose of assessing any disclosure requirements. Management was informed of the incident in September 2011 and, following the review, the Company’s management concluded that our disclosure controls and procedures are effective. However, the Company has implemented reporting line and escalation organization changes, procedures and processes to strengthen the Company’s disclosure controls and procedures in this area. See Item 4 “Controls and Procedures” in Part I of this report.
It's interesting to note that the SEC issued guidelines on the reporting of security breaches on October 13th, 2011 ( http://www.sec.gov/divisions/corpfin/guidance/cfguidance-top... ) and VeriSign's SEC filing was released about two weeks later on October 28th, 2011. It could be the case that the security breach wasn't actually a major one, but because the SEC guidelines were so new they thought it prudent to mention even a minor security breach.
From this filing, there's no way to know the severity of the breach, which is why I think it's unfair for reuters to make this seem like a bigger deal than it might actually be. (They mention the RSA security breach which was a huge deal, and they suggest the attack was done by a "nation-state".) It reads like an article written by Nancy Grace.
Of course it could be the case that this was a major attack carried out by China, but it could also be a mundane attack on a public web server that wouldn't have made the news if not for the timing of the recent SEC guidelines. There's just no way to know from the information available.
"I think it's unfair for reuters to make this seem like a bigger deal than it might actually be"
The filing says:
"the Company faced several successful attacks against its corporate network in which access was gained to information on a small portion of our computers and servers"
The headline was:
"Key Internet operator VeriSign hit by hackers"
This wasn't the lead story on the nightly news. It was a Reuters article with a fair headline for what happened. The mere fact that they reported it in their filings but didn't disclose it to company management is a problem right there.
This delightful fear-mongering quote from a former DHSer is in the article:
"Oh my God," said Stewart Baker, former assistant secretary of the Department of Homeland Security and before that the top lawyer at the National Security Agency. "That could allow people to imitate almost any company on the Net."
The point is that this was a small attack that affected a very small part of the company that they don't believe has any lasting implications to their business. You get an article with quotes like that from such a small attack, and it makes you raise an eyebrow.
This doesn't make sense. It is company management who writes the filings, not the network admins. How can it be in the filings but not go through management?
>He said he hoped new legislation on cybersecurity, expected to reach the Senate floor this month, would call for more disclosures and bring more aid to companies under attack.
Uh huh.
Interesting that a large argument against SOPA was that it would break the security of the internet. Now we are getting stories claiming that the internet is already broken and we'll need new laws to fix it.
Expect the laws needed to fix the security of the internet to also include fixing the "evils" of copyright "theft".
Comments
The reuters article provides no details about the security breach, so I did some digging. The most I could find was VeriSign's original SEC filing at http://www.sec.gov/Archives/edgar/data/1014473/0001193125112...
From the filing: We experienced security breaches in the corporate network in 2010 which were not sufficiently reported to Management.
In 2010, the Company faced several successful attacks against its corporate network in which access was gained to information on a small portion of our computers and servers. We have investigated and do not believe these attacks breached the servers that support our Domain Name System (“DNS”) network. Information stored on the compromised corporate systems was exfiltrated. The Company’s information security group was aware of the attacks shortly after the time of their occurrence and the group implemented remedial measures designed to mitigate the attacks and to detect and thwart similar additional attacks. However, given the nature of such attacks, we cannot assure that our remedial actions will be sufficient to thwart future attacks or prevent the future loss of information. In addition, although the Company is unaware of any situation in which possibly exfiltrated information has been used, we are unable to assure that such information was not or could not be used in the future.
The occurrences of the attacks were not sufficiently reported to the Company’s management at the time they occurred for the purpose of assessing any disclosure requirements. Management was informed of the incident in September 2011 and, following the review, the Company’s management concluded that our disclosure controls and procedures are effective. However, the Company has implemented reporting line and escalation organization changes, procedures and processes to strengthen the Company’s disclosure controls and procedures in this area. See Item 4 “Controls and Procedures” in Part I of this report.
It's interesting to note that the SEC issued guidelines on the reporting of security breaches on October 13th, 2011 ( http://www.sec.gov/divisions/corpfin/guidance/cfguidance-top... ) and VeriSign's SEC filing was released about two weeks later on October 28th, 2011. It could be the case that the security breach wasn't actually a major one, but because the SEC guidelines were so new they thought it prudent to mention even a minor security breach.
From this filing, there's no way to know the severity of the breach, which is why I think it's unfair for reuters to make this seem like a bigger deal than it might actually be. (They mention the RSA security breach which was a huge deal, and they suggest the attack was done by a "nation-state".) It reads like an article written by Nancy Grace.
Of course it could be the case that this was a major attack carried out by China, but it could also be a mundane attack on a public web server that wouldn't have made the news if not for the timing of the recent SEC guidelines. There's just no way to know from the information available.
You said:
"I think it's unfair for reuters to make this seem like a bigger deal than it might actually be"
The filing says:
"the Company faced several successful attacks against its corporate network in which access was gained to information on a small portion of our computers and servers"
The headline was:
"Key Internet operator VeriSign hit by hackers"
This wasn't the lead story on the nightly news. It was a Reuters article with a fair headline for what happened. The mere fact that they reported it in their filings but didn't disclose it to company management is a problem right there.
This delightful fear-mongering quote from a former DHSer is in the article:
"Oh my God," said Stewart Baker, former assistant secretary of the Department of Homeland Security and before that the top lawyer at the National Security Agency. "That could allow people to imitate almost any company on the Net."
The point is that this was a small attack that affected a very small part of the company that they don't believe has any lasting implications to their business. You get an article with quotes like that from such a small attack, and it makes you raise an eyebrow.
Heh, isn't that what the RSA breach was at first, too?
This doesn't make sense. It is company management who writes the filings, not the network admins. How can it be in the filings but not go through management?
>He said he hoped new legislation on cybersecurity, expected to reach the Senate floor this month, would call for more disclosures and bring more aid to companies under attack.
Uh huh.
Interesting that a large argument against SOPA was that it would break the security of the internet. Now we are getting stories claiming that the internet is already broken and we'll need new laws to fix it.
Expect the laws needed to fix the security of the internet to also include fixing the "evils" of copyright "theft".