Criminologist George Kelling first came up with the “broken window” theory of crime back in 1982, before there was a computer on every work desk and an internet connection in everyone’s hands.
The concept — that if a window in a building is broken and is left unrepaired, all the rest of the windows will soon be broken — was used to turn around the fight against crime in New York, and is now widely embraced. As Kelling put it, “vandalism can occur anywhere once communal barriers ... are lowered by actions that seem to signal that ‘no-one cares’,” meaning that looking after the small issues helped prevent the bigger issues.
According to Stefan van de Giessen, GM of cybersecurity at Networks Unlimited Africa, the theory fits neatly into the area of IT and its role in business.
“There is not normally a way for an external party to see that there are any ‘broken windows’ in a company’s cyber security,” he says. “We are therefore applying a ‘broken window, broken business’ principle when looking at our internal cyber security posture.
This means making sure that you have no “broken windows” or gaps in your security through which uninvited elements could enter. To do this, you first need to create a firm baseline to develop your posture.”
A lot of companies overlook the basics, he says, and then, at a later stage, get caught in the expensive trap of needing to acquire solutions to plug security gaps. Small business in particular pays this price.
“Smaller organisations often make the mistake of using a ‘just enough’ mentality to get the network operating. We advise that, when looking to build any network and adding security on top of this, it is important to ensure that you are using human resources who are certified within their respective fields.
“As a first step to ensure you cover all bases, ascertain whether there are any cracks in your posture — in essence, a ‘broken window’. A lack of proper network segmentation, as well as inadequate password management and a vulnerable e-mail security, are all factors that can act as broken policies.”
However, even the largest organisations allow cyber criminals into this broken window, as was seen in the breach of Liberty Life’s e-mail systems two years ago. Now, such “endpoints” of a network are more vulnerable than ever before.
Says Van de Giessen: “The endpoint is one of the most crucial vectors for attack, especially considering the current, significantly increased number of employees working from home. This is a true ‘broken window’ potential.
“Traditional antivirus has become irrelevant due to the evolution of attacks such a file-less attacks. Additionally, the endpoint needs to be able to create a secure connection to the private network at head office.”
In effect, looking after the these fundamentals protects an IT environment from “falling into disrepair”, and becoming an appealing target to cyber criminals.
• Goldstuck is founder of World Wide Worx and editor-in-chief of Gadget.co.za




