Showing posts with label #blackberry. Show all posts
Showing posts with label #blackberry. Show all posts

Thursday, 13 September 2018

Cyber Trends 2018

James McDowell and Camble Murray gave an interesting talk, at the Blackberry Security Conference, on recent trends in cyber security and what we can learn from the last 12 months.

Probably the most quotable aspect was how easy it is to social engineer an attack if the attacker targets people in Sales roles. Apparently, sales people are so eager to make a sale that "they will open anything" on an email attachment. They also claimed, that if the attacker uses "appropriate HR language", then it is quite easy to persuade an HR user to do so too. So there are some communities to focus on with communications and cyber awareness training. It also appears that some security professionals are starting to adopt psychological techniques such as NLP to re-inforce their approaches to building security cultures.

It seems that Ransom Ware and Email targeting for spear fish attacks remain the 2 most prevalent threats, mainly because of the economics of cost and return from such types of attack; generally perpetrators reckon to pick up quite significant returns for relatively modest outlays, given the general availability of many cheap attack kits and the ability to sustain high volumes of attacks, almost guaranteeing that some will succeed.

It also appears that attackers are increasingly using Facebook and other social media platforms to identify individuals who are susceptible to "clicking on things" and profile them for future attacks. So perhaps this is the time to educate people about separating their social media personnae from their work ones, making it much less easy to cross link them.

Th other notable point was the significant number of crypto currency exchanges and wallets which had been targeted for attack. There is something about saying that something is secure that invites the wrong type of attention.

The other big trend is the emergence of the term Cyber Resilience, which is really about how capable a business is in dealing with major security incidents and continuing to operate when under cyber attack. So whilst there is a strong need to deal with security basics systematically, there is also the need to design in security at both an environmental and a project level, when implementing new stuff, there is also the need to have a well oiled and rehearsed approach to managing the response to an attack. 

The Return of the Crackberry

This week, Blackberry held its annual security conference in London. so it was a good time to catch up with what Blackberry is doing now, after the melt down of its original secure corporate phone and email business model. 

Well, it is still in the phone business. Partnering with TCL, who undertakes hardware manufacture and smart phone distribution, blackberry is still designing new smart phones. The new models look very smart and offer a key pad equipped, touch sensitive android phone at a competitive price point, i.e. several hundred notes cheaper than the equivalent Samsung or Apple model. It would be easy to dismiss them as being a choice for someone who is into retro chic or an old school aficionado of key pads. However, there are some subtleties in the product design which are increasingly relevant in the current environment of aggressive cyber crime. The devices are designed and built bottom up to be resilient to infiltration and takeover, combining both hardware and software features for this. Additionally, the thumbprint security control is implemented in a way which allows the user to differentiate between what is private and what is shared. Which coupled with features in Android enabling separation between personal and corporate personas, makes it very much a smart phone of the age.

However, mobile phones are really only a side show and not the main story. Blackberry has built on its global secure telecommunications capabilities to emerge as a leading "Enterprise of Things" (EoT) enabler. Someone described its primary mission as being to "Secure your Communications and your Data". However the vision is one of comprehensively enabling secure IoT exploitation by enterprises, leveraging industry standard to deliver on government quality security in the deployment of Smart Things, or as one of the speakers stated "Moving from Mobile First to Things First".

There's a comprehensive set of products with SDKs which enable OEMs to develop secure smart products and Enterprises to deploy Thing based business models securely, whilst users enjoy a relatively seamless secure access experience across a comprehensive range of products.

Although what was probably the most impressive aspect of the conference was to see representatives from Google, Microsoft, Samsung and Blackberry discuss how they are collaborating to deliver a new generation of products which integrate securely and build the IoT world of the future.