Imagine for a moment that a gang of bank robbers decided to target the big guys — Citi, JPMorgan Chase, Bank of America, Wells Fargo — you know, the ones where a billion dollars is petty cash.

The robberies always use the same basic techniques, and the amounts stolen are starting to add up.

Plus, it’s embarrassing. But so far nobody has managed to catch the culprits.

Do you think these companies would have the wherewithal to take care of the problem?

Listen to the apostles of capitalism and you might think so. And yet, in the contest between world corporatism and cybercriminals, the cybercriminals aren’t just winning. They’re winning with impunity, so much so that InfoWorld’s Roger Grimes — not the kind of person you’d call a hysteric ­– is using words like “crisis” and “catastrophe” to describe the situation.

Now I ain’t no expert. And as regular readers know I try to avoid the grand American inverse correlation between knowledge and strength of opinion, so I’m not claiming to have the solution, or even a solution.

Just some notions. Like these two for all corporations:

  • Spend more. No, you can’t solve problems by throwing money at them. You also can’t solve them by refusing to spend money on them.

Target, for example, expects its data breach will cost it something like a billion dollars in direct costs, and that doesn’t include damage to its brand and lost customer loyalty. And Target’s cybersecurity wasn’t all that much worse than average.

Its cybersecurity budget? Do some Googling and back-of-the-envelope scratching (I couldn’t track down the number) and you’ll probably arrive a number along the lines of $125 million. Do the math.

  • Practice identity management 101: I don’t have a statistically valid sample; I am invited into enough companies to think this conclusion is reliable: Way too many companies are way too sloppy about identity management.

We’re talking about the basics, not anything fancy. Lots of companies provision new employees by “making her like him” instead of by defining access rights and restrictions by role. Way too many add rights as employees take on new responsibilities without removing the ones they don’t need anymore.

This isn’t complicated. Just time consuming. Also, silo-busting, because HR should be the hub, not IT. After all, every hire, transfer, promotion and termination flows through HR, and these are the exact events that should trigger changes in rights and restrictions.

Corporations can certainly do better when it comes to protecting their cyber assets. The cyberprotection industry worries me more. In the aggregate they (truth in advertising: I’m a Dell employee. Elsewhere at Dell we have information security products and consultants, so in a sense “they” is “we”) … in the aggregate the cyberprotection industry has more money to spend on defense than the bad guys have to spend on offense.

Yes, offense is easier. And yet, if everyone involved pooled their knowledge and resources …

Phishing attacks are the biggest source of security breaches. Couldn’t, for example, IBM put Watson on the hunt? It’s a classic big-data-analytics problem. Even without creating a public repository for everyone in the world to send phishing emails they receive, IBM employs enough people to get this started.

If Watson-style technology can spot credit card fraud, surely its analytics can spot phishing attacks as well.

Here’s another: Stop with signatures already and deal with behavior. As in, the problem with computer viruses is that they make computers do things the computers’ owners don’t want them to do.

I know I’m going out on a limb here on the strongly-held-opinion-correlated-with-ignorance front. Still, bear with me.

What does malware do? It: wipes hard drives; sends out data without a triggering keyboard or mouse command; updates files and databases without a triggering keystroke or mouse command; sends out massive amounts of email without a triggering keystroke or mouse command …

How hard can it be to write features into the OS kernel that monitor for these sorts of malware tells? Pop a big message onto the screen warning users in plain English about what their computer has been instructed to do and ask if it’s something the user wants it to do.

These are probably naïve and simple-minded suggestions. I’m not, after all, an expert in the field and besides, I’m giving these ideas away for free.

Unlike yours truly, the cyberprotection industry has all the expertise it needs. It has, in the aggregate, big R&D budgets. How about coupling these resources with the same level of innovative thinking cybercriminals put into their attacks?

What’s clear: Our current strategy … identifying the next threat and responding to it … guarantees we’ll always be a step behind.

Dear Bob …

I’m the first line of defense when it comes to information technology here, here being a 30-person non-profit. I know you normally advise companies a hundred times our size or bigger, but I’m still hoping you can help me out.

What I’m looking for are … I know, not best practices, I’ve been paying attention … but some tested, reliable practices I can put into place here to keep the joint running, to coin a phrase.

Any suggestions?

– Stretched thin

Stretch …

Not a comprehensive list by any means. These should get you started:

  • Anti-virus/anti-malware: Choose one. Not a free one either. Install on every machine. Uninstalling to improve performance is a firing offense, because really, no business needs employees that stupid.
  • License management: In my admittedly limited experience, employees in small offices tend to be more cavalier about license legitimacy than those in large enterprises, those who work in non-profits even more so.

Impress on everyone that being smaller, or an organization that does good works won’t help a bit if there’s an audit. And besides, for many software categories non-profits qualify for very large discounts, so if someone needs a piece of software there’s rarely even a financial case for using an illegitimate copy of something.

  • Password reset: Set passwords to expire after no more than 60 days. Passwords should cover the basics — at least 8 characters long with at least two alphas and two numeric.

Yes, everyone will complain. Empathize, but hold your ground.

And while you’re talking to everyone about passwords, you might as well suggest they have a few different ones for different types of on-line life. The experts say they’re supposed to have a different password for every website they log into, but since that isn’t going to happen, having (for example) one for financial sites, a second for social media and a third for news will provide at least a layer of additional protection.

  • Phishing attacks: Educate everyone to recognize these, and in particular to avoid clicking on links within emails if they aren’t certain of the source.

Phishing attacks are the single most common way passwords are stolen, so this is critical.

And don’t be shy. Most people like to learn a few things so they feel more sophisticated about a topic, so long as you don’t overdo it.

So show them how to find out what’s in a link, and how to spot a URL that looks legitimate but isn’t (example: www.yourbankname.phonyphisher.com/lotsanonsensetohidethings).

They’ll feel good about knowing a bit more, and you’ll be a bit safer.

  • Installing free software: In a small office like yours I’m guessing you don’t lock down everyone’s system, and that’s okay. The best advice I have here is to caution everyone to be careful about what sites and software they download. Remind them to Google the name of any software they’re thinking of downloading — to do some research first to see if there are reports that a particular program isn’t safe.

In particular (and I’m carrying a grudge here), if a site offering free software tries to install a downloader first “to make installing software more convenient,” never (sorry, NEVER) trust that site. It’s easy to get fooled, by the way. I ended up with Mezaa a couple of months ago by missing that this was happening. It’s a nasty piece of malware I ended up with just by trying to upgrade a program I’d been using for some time.

Mezaa is what you might call flashmob software: When it comes in it immediately invites all of its friends to join it.

Don’t get me wrong. I’ve downloaded and used plenty of free software over the years that I’ve found immensely valuable and helpful. What you’re trying to do is to help everyone tell the difference between safe and unsafe free.

  • Protecting sensitive information: If it’s sensitive and someone is copying it to a jump drive, they should encrypt/protect it first.

MS Office has this as a built-in option; everyone should learn how to use it. Or, most jump drives now come with on-board encryption — all you have to do is enable it.

One complicating factor is that some countries have made it illegal to bring encrypted files through customs. Travelers should check the rules.

  • Last one: If a user becomes frustrated with their computer, it is not okay to throw it out the window. There might be an innocent pedestrian below — always check before hurling something heavy.

That’s what occurs to me. KJR subscribers … what did I miss?