Showing posts with label #Cyber. Show all posts
Showing posts with label #Cyber. Show all posts

Thursday, 13 September 2018

Cyber Trends 2018

James McDowell and Camble Murray gave an interesting talk, at the Blackberry Security Conference, on recent trends in cyber security and what we can learn from the last 12 months.

Probably the most quotable aspect was how easy it is to social engineer an attack if the attacker targets people in Sales roles. Apparently, sales people are so eager to make a sale that "they will open anything" on an email attachment. They also claimed, that if the attacker uses "appropriate HR language", then it is quite easy to persuade an HR user to do so too. So there are some communities to focus on with communications and cyber awareness training. It also appears that some security professionals are starting to adopt psychological techniques such as NLP to re-inforce their approaches to building security cultures.

It seems that Ransom Ware and Email targeting for spear fish attacks remain the 2 most prevalent threats, mainly because of the economics of cost and return from such types of attack; generally perpetrators reckon to pick up quite significant returns for relatively modest outlays, given the general availability of many cheap attack kits and the ability to sustain high volumes of attacks, almost guaranteeing that some will succeed.

It also appears that attackers are increasingly using Facebook and other social media platforms to identify individuals who are susceptible to "clicking on things" and profile them for future attacks. So perhaps this is the time to educate people about separating their social media personnae from their work ones, making it much less easy to cross link them.

Th other notable point was the significant number of crypto currency exchanges and wallets which had been targeted for attack. There is something about saying that something is secure that invites the wrong type of attention.

The other big trend is the emergence of the term Cyber Resilience, which is really about how capable a business is in dealing with major security incidents and continuing to operate when under cyber attack. So whilst there is a strong need to deal with security basics systematically, there is also the need to design in security at both an environmental and a project level, when implementing new stuff, there is also the need to have a well oiled and rehearsed approach to managing the response to an attack. 

Friday, 17 August 2018

Cyber Aggression versus Authenticity

In a week when EU officials expressed the fear that "British Agents may have bugged Brexit Planning Sessions", it is interesting to note that President Trump has decided to reverse a previous Obama administration framework for controlling the launch of cyber attacks by the US.

Sabine Weyand expressed the EU officials' fears following an incident in which Britain requested that slides from an briefing meeting should not be released to press. this has led to all mobile devices and ipads being banned from meetings, in case they are used to spy on them or leak secrets. Trump's move undoes measures designed to ensure co-ordinated and considered response by the US's intelligence community to perceived threat. The exact reasons for this have not been disclosed, but given the president's penchant for action, the political pressure that he has suffered following allegations that Russian organisations may have interfered with the presidential election and the fact that a considerable number of potential foes may be looking for ways to hit back at the US following sanctions placed on Turkey, Russia and Iran, it is not surprising that he might want to be able to react quickly without engaging multiple layers of decision making and delay.

At the same time in an almost polar opposite direction, key operators in the digital world are emphasising the need for "brand authenticity" in the way in which they market and sell their products to today's modern consumer. This is discussed in some detail in this quarters magazine from Nimbus Ninety, an organisation focused the London Digital Ecosystem. They also discuss some interesting thoughts from academia about how Socrates railed against the idea of writing things down and how this would damage young people's minds, in a strikingly similar way to which modern social media is being accused of damaging generation Z's cognitive attention spans. Plus ca change, plus ca meme chose.

Friday, 10 June 2016

Cyber Fear and Digital Defence

How do we deal with the proposition that we are already penetrated?

Ever since the rise of the Advanced Persistent Threat and Socially Engineered Attacks the term Cyber has taken on new meanings and the IT Security industry has become one of the most vibrant sectors of the IT Industry.

At the European Infosec Event this week over 400 vendors were promoting their wares with the expectation that more than £1Bn of orders will result.

I have been to 3 such events recently and the range of issues arising has been phenomenal.

Planning and rehearsing for major events has become de rigeur with CIOs and other senior stakeholders needing to take media training. The industry has responded to Digital Challenges with a range of products providing cloud based security monitoring and encryption. Products similar to Military Battlefield Management Systems provide overarching monitoring, control and simulation systems. There is a high degree of inter-operation between many products and innovative products conduct network discovery and behavioural anomaly detection to track down new attacks using advanced machine learning and statistical analysis. There are even niche products for things such as system administrator control and user recognition via typing pattern recognition at keyboards.

However, one family of products disturbed me. There are now systems for monitoring user behaviour and predicting who is likely to cause a major leakage incident. This sort of big brother system is going to take significant effort to tune so that unfortunate false positives are avoided. Once people are used to them, they will be readily gamed. Whatever happened to actually managing and knowing the people who use your systems?