About Us | Contact Us
View Cart

Would I love to interview Lenovo’s Incident Response Team!

By Dan Hadaway | Friday, March 6, 2015 - Leave a Comment

How much can failure be worth?

Dan gets an idea while filling out a “customer satisfaction survey!”
Another one of those Dan’s New Leaf Posts, meant to inspire thought about IT Governance . . . .


So though I tried to comment on Lenovo’s site during the early days of their Superfish incident and they wouldn’t let me log in . . .  in the amazingly inept decision to go silent instead of transparent . . . they must have forgotten to shut off the customer satisfaction survey engine.

Okay, I should be nicer . . . . they probably decided to let that part of it continue so they could measure the damages, if possible.  And I don’t blame them.

Frankly, we really do need to be nicer to companies that are struggling with their IT Governance Processes . . . and help them along the path to risk management.  So I’m glad I was not able to put a comment on their site, because when I was trying in vain to register my comment on their bogus post about Superfish not being a problem, my state of irritation would have led to a regrettable comment.  So again the American Monkey Trap saves Dan from an American Monkey Trap (more on that in a future article called . . . . you guessed it . . .  The American Monkey Trap!)

Lenovo had such a great opportunity to turn a lemon into lemonade, and instead they clammed up, probably taking the advise of lawyers rather than incident response experts, and now they have a lot of work to do to rebuild their reputation.

You see, they did NOT have an incident response plan.  Had they proactively developed a plan, and then tested the plan (with their lawyers present), when the Superfish incident hit they surely would have been more transparent and truthful.

So this is what I said in my survey response:


So hey, we’ll see if anybody bites on the bait.  I did try calling them, but that was a waste of time . . . well at least given I have very little time these days . . . . I’m too busy updating the Vendor Management Program to address the risk we now face when engaging with hardware vendors . . . .

Original article by Dan Hadaway CRISC CISA CISM. Founder and Managing Partner, infotex

“Dan’s New Leaf” is a “fun blog to inspire thought in the area of IT Governance.”



Latest News
    Ransomware payments sent to countries under sanctions could result in fines… An article review. Whether or not to pay the organization behind a ransomware attack has been a hotly debated subject for many years, but a new advisory issued by the Treasury Department’s Office of Foreign Assets Control (OFAC) warns those who do pay up […]
    Welcome Webinar Attendees! You can download the deliverables by clicking on the link below. Boilerplates/Handouts Click here to download files.        
    Another awareness poster for YOUR customers (and users).  Now that we have our own employees aware, maybe it’s time to start posting content for our customers! Download the large versions here: Awareness Poster (Portrait) Awareness Poster (Landscape)   You are welcome to print out and distribute this around your office. Data by Rob Sobers, writing […]
    Thanks for being interested in our Technology Planning Webinars! This year‘s annual webinar on the subject will include a review of the previous years’ movies that are already available, and a discussion about alternative tactics that have arisen from recent virtual conferences and regulator panels. It’s not too late to register for the 2020 Technology […]
    Check out the Sponsor Video! We will be updating the video on YouTube in the coming days, but will include the credits so everyone is recognized for all their hard work. Like our Facebook, Twitter, and Subscribe on YouTube for further updates! Credits Producer: Bryan Bonnell “K0s$” Director: Sara Fultz Editor: Sofia Tafoya Wardrobe: Our […]