Santa shares 5 security tips for 2020. Credit: Tweak Library

5 security tips from Santa – Here’s What He said!

Think back to all of the good security practices you’ve adopted over the past 11 or so months. And then think back to all of the bad security practices you’ve adopted when you should have been doing the right thing. Oh, dear. It’s not looking good for you, is it?

Here’s the good news, though: because Santa is a benevolent soul, there’s time to make amends (unless you’re reading this after Christmas2). Here’s a list of useful security tips and practices that Santa follows and therefore are bound to put you on his “good” side.

1. Use a password manager

Santa is very careful with his passwords. Here’s a little secret: from time to time, rather than have his elves handcraft every little present, he sources his gifts from other parties. I’m not suggesting that he pays market rates (he’s ordering in bulk, and he has a very, very good credit rating), but he uses lots of different suppliers, and he’s aware that not all of them take security as seriously as he does. He doesn’t want all his account logins to be leaked if one of his suppliers is hacked, so he uses separate passwords for each account. Now, Santa, being Santa, could remember all of these details if he wanted to—and even generate unique passwords that meet all the relevant complexity requirements for each site—but he uses an open source password manager for safety and for succession planning.3

2. Manage personal information properly

You may work for a large company, organisation, or government, and you may think you have lots of customers and associated data, but consider Santa. He manages (or has managed) names, birth dates, addresses, hobbies, shoe sizes, colour preferences, and other personal data for literally every person on Earth. That’s an awful lot of sensitive data, and it needs to be protected. When people grow too old for presents from Santa,4 he needs to delete their data securely. In fact, Santa may well be the archetypal GDPR data controller, and he needs to be very careful who and what can access the data that he holds. Of course, he encrypts all the data and is very careful about key management. He’s also very aware of the dangers associated with cold boot attacks (given the average temperature around his residence), so he ensures data is properly wiped before shutdown.

3. Measure and mitigate risk

Santa knows all about risk. He has complex systems for ordering, fulfillment, travel planning, logistics, and delivery that are the envy of most of the world. He understands what impact failure in any part of the supply chain can have on his customers: mainly children and IT professionals. He quantifies risk, recalculating it on a regular basis to ensure that he is up to date with possible vulnerabilities and ready with mitigations.

4. Patch frequently but carefully

Santa absolutely cannot afford for his systems to go down, particularly around his most busy period. He has established processes to ensure that the concerns of security are balanced with the needs of the business.5 He knows that sometimes business continuity must take priority, and on other occasions, the impact of a security breach would be so major that patches just have to be applied. He tells people what he wants and listens to their views, taking them into account where he can. In other words, he embraces open management, delegating decisions where possible to the people who are best positioned to make the call, and only intervenes when asked for an executive decision or when exceptions arise. Santa is a very enlightened manager.

5. Embrace diversity

One of the useful consequences of running a global operation is that Santa values diversity. Old or young (at heart); male, female, or gender-neutral; neurotypical or neurodiverse; of any culture, sexuality, race, ability, creed, or nose colour, Santa takes into account his stakeholders and their views on what might go wrong. What a fantastic set of viewpoints Santa has available to him! And he’s surprisingly hip to the opportunities for security practices that a wide and diverse set of opinions and experiences can bring6 not to mention the multiple positive impacts on his organisation.


Here’s my advice: Be like Santa, and adopt at least some of his security practices. You’ll have a much better opportunity of getting onto his good side, and that’s going to go down well—not just with him, but also with your employer, who is just certain to give you a nice bonus, right? And if not, well, it’s not too late to write that letter directly to Santa himself.

Spread the love

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

%d bloggers like this: