Heres one answer: In a 10-minute Web search, I gained access to thousands of viruses and software tools with which I could create and launch polymorphic attacks.Meanwhile, in a 10-week span, I have yet to find a CIO who will talk about a security breach.In a sense, hackers are more open and honest. This explains, in part, why theyre kicking tail. So why not adopt some hacker wisdom?Communicate. Organize yourselves. Talk honestly about security failures, what youve learned and how youre adapting. Its not that easy, right? To tell the world (read: shareholders) about a security breach is to create a litigious morass and possibly a public relations disaster. Fortunately, there are ways to talk about the problem and avoid this, such as Senior Writer Sarah Scalets piece about a virus outbreak at an anonymous company.Besides, clamming up doesnt make you safer. The public will find out about security compromises one way or another. Sometimes they have the right to know. Getting in front of the problem, talking openly about weaknesses everyone is susceptible to may just make a CIO a leader, not a failure. I think some CIOs want to broaden the security dialogue. They want to have frank conversations about whats happening and develop an organized strategy to combat hackers.Case-in-point: Girl Scouts of America CIO Marcia Balestrino was ready to talk to CIO about her experience with a defacement of the GSUSA website. Balestrino saw in her hacking experience a simple but crucial lesson she could share with her peers. And, she would be encouraging others to come forward. But first she had to check with PR, and PR gagged her.The PR contact asked me, Is there any way I could steer this interview away from the specific incident and just have her talk about security in general?I said no. So the Girl Scouts said no interview. Balestrino said she was disappointed but had to respect the PR departments decision.I suspect this is typical. And I wonder when or if CIOs will start pushing back on the PR and legal departments that somehow think the problem will go away or that security lapses will be kept secret if they block discourse.A caution: Though I think there is great unmined value in the virus story or the ill-fated Girl Scouts tale, this is not a plea to get good stories. Its my job to get those stories despite PR. Im simply saying its time for CIOs to shift strategy in the security battle. Because the hacker community is just thata community. Growing. Tighter and more organized than the good guys. Hell, they even have a trade show in Las Vegas next month. They keep in constant communication. They use the media. They build products and improve them rapidly. They continuously talk about what does and doesnt work, and they constantly improve their craft.Its a shame Im talking about the bad guys there. Related content news New Trojan ZenRAT masquerades as Bitwarden password manager A report by Proofpoint identifies the new Trojan as undocumented and possessing information-stealing capabilities. By Lucian Constantin Sep 28, 2023 4 mins Cyberattacks Cyberattacks Cyberattacks news UK Cyber Security Council CEO reflects on a year of progress Professor Simon Hepburn sits down with broadcaster ITN to discuss Council’s work around cybersecurity professional standards, careers and learning, and outreach and diversity. By Michael Hill Sep 27, 2023 3 mins Government Data and Information Security Security Practices news FIDO Alliance certifies security of edge nodes, IoT devices Certification demonstrates that products are at low risk of cyberthreats and will interoperate securely. By Michael Hill Sep 27, 2023 3 mins Certifications Internet Security Security Hardware news analysis Web app, API attacks surge as cybercriminals target financial services The financial services sector has also experienced an increase in Layer 3 and Layer 4 DDoS attacks. By Michael Hill Sep 27, 2023 6 mins Financial Services Industry Cyberattacks Application Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe