Posts

Showing posts with the label Risk Management

What the Anthropic Decision Reveals About the Future of AI Security

Image
The recent decision by the U.S. administration to lift restrictions on Anthropic’s frontier AI models has generated plenty of debate. Some have questioned whether the original restrictions were justified, while others argue they reflected legitimate concerns about the cybersecurity capabilities of increasingly powerful AI systems. Regardless of where you stand, I believe the real story lies elsewhere. This is one of the clearest examples yet of governments treating AI models as technologies with potential national security implications rather than simply another software product. That should make every cybersecurity leader take notice. AI Security Is Different For decades, cybersecurity has focused on protecting systems from attack. Today, we are entering an era where AI itself can influence the speed, scale and sophistication of those attacks. Modern frontier models can assist with code analysis, vulnerability discovery, malware understanding and offensive research. While t...

Third Party Security Risks to Consider and Manage

Image
Guest article by Josh Lefkowitz, CEO of Flashpoint   Acceptable business risks must be managed, and none more so than those associated with external vendors who often have intimate access to infrastructure or business data. As we’ve seen with numerous breaches where attackers were able to leverage a weaknesses a contractor or service provider, third-party risk must be assessed and mitigated during the early stages of such a partnership, as well as throughout the relationship.   The following tips can help security decision makers more effectively address the risks posed by relationships with technology vendors.   Do Your Homework Conducting thorough due diligence on a prospective vendor is essential. Organisations could evaluate technical and regulatory risk through due diligence questionnaires, for example, or even on-site visits if necessary. The point is to evaluate not only a third party’s information security risk, but compliance with regulations such as...

Cyber Security Predictions for 2019

Image
A guest article authored by Jim Ducharme, Vice President of Engineering and Product Management at RSA 1. Prepare for IOT, the “Identity of Things” From personal assistants, to wearables, smartphones, tablets and more, there is no shortage of connected devices. The explosion of IOT has finally reached a tipping point where the conversation of identity will start to take on a whole new meaning. The billions of new digital identities being created don’t come without risk – including new privacy and cybersecurity vulnerabilities. With businesses and consumers all in on IOT, how do we protect and securely manage the “identity” of the things?  2. Biometrics vs. the Four-Digit Pin Biometrics are under a lot of pressure these days to be the silver bullet of authentication. So how could a simple 4-digit pin, which has at most 10,000 possible combinations, give biometrics like FaceID with a 1 in 50 million entropy a run for its money? The industry will come to realize when 4-digit pin...

All I want for Christmas: A CISO's Wishlist!

Image
As Christmas fast approaches, CISOs and cyber security experts around the world are busy putting plans in place for 2019 and reflecting on what could have been done differently this year. The high-profile data breaches have been no secret - from British Airways to Dixons Carphone to Ticketmaster - and the introduction of GDPR in May 2018 sent many IT professionals into a frenzy to ensure practices and procedures were in place to become compliant with the new regulation. What the introduction of GDPR did demonstrate was that organisations should no longer focus on security strategies, which protect the organisation’s network, but instead focus on Information Assurance (IA) which protects an organisation’s data. After all - if an organisation’s data is breached, not only will it face huge fallouts of reputational damage, hits to the organisation’s bottom line and future prospecting difficulties, but it will also be held accountable to regulatory fines - up to as much as €20 million, or...

Science of CyberSecurity: Thoughts on the current state of Cyber Security

As part of a profile interview for  Science of Cybersecurity I was asked five questions on cyber security last week, here's question 1 of 5. Q. What are your thoughts on the current state of cybersecurity, both for organizations and for consumers? Thanks to regular sensational media hacking headlines most organisational leaders are worried about their organisation’s cyber security posture, but they often lack the appropriate expert support in helping them properly understand their organisation’s cyber risk. To address the cyber security concern, an ‘off the peg’ industry best practice check box approach is often resorted to. However, this one-size-fits-all strategy is far from cost effective and only provides limited assurance in protecting against modern cyber attacks, given every organisation is unique, and cyber threat adversaries continually evolve their tactics and methodologies. In these difficult financial times of limiting cyber security budgets, it is important...

Cyber Security Incident Management, Response and Recovery Guidance

Image
Yesterday I spoke at the R3 Summit (Resilience, Response and Recovery) in London, on the topic of Cyber Security Incident Management and response. Given the Q & A and the ensuing discussion after my talk, the attendees were particularly interested in my views on incident containment ahead of recovery. Below is a summary of what I said. Step 1: Incident Management Planning and Preparation The most crucial part of incident management is the preparation, it is important to always consider cyber security incidents as a ‘When’ not an ‘If’ as you plan ahead. So here’s my ‘brain dump’ of an incident management planning strategy: A company Cyber Security Incident Management Policy It must define what the company (aka the board) consider as a cyber security incident Cyber Security Incident notification communications channel or even better a reporting application/system Upon identifying an incident who do staff notify (the incident management team) Staff awareness of how to...

What is Tor and Should your website block Tor users?

Image
Great infographic by State of the Internet which raises an interesting question, should websites block Tor users?  Certainly one for debate, my view is it depends on your website 'marketplace', function and risk, in other words perform a risk assessment, a lazy answer I know. But i f like me you find yourself often explaining what Tor is to business folk, so they can perform those risk assessments properly, you'll find this infographic comes in quite handy. As it does a simple job of explaining Tor; who uses it, how it provides anonymity  online, and how cyber criminals are embracing the tool for various illicit purposes. I recommend checking out the  State of the Internet website  for further info, statistics and reports on Web and DDoS attacks, which continue to blight the Internet.

Top security best practices for IoT applications - Combating IoT cyber threats

I have written the following article for IBM which was published today on  IBM Development Works . https://www.ibm.com/developerworks/library/iot-security-best-practices-iot-apps/ The Internet of Things is changing the way that businesses operate, especially in the areas of warehousing, transportation, and logistics. These changes make the security of IoT devices even more crucial, given the time and money that is required if a hacker breaks through the defenses. This article outlines the best practices for securely developing robust IoT solutions.

Security Today - Cyber Information Security News Stream & Alerts Twitter Feed

Image
I was an early adopter to Twitter, opening my  @securityexpert  account back in October 2008, I found Twitter has been an excellent tool for picking up and sharing information security news, articles, major breaches and critical vulnerability alerts. As well as making my own contributions I often retweet tweets of InfoSec interest, education and intrigue, however I have always had a strict policy of never allowing my  @securityexpert  account to send any automated tweets, every tweet is manually sent or is retweeted by yours truly. Once you go down that road the personal nature of the account goes. I recognise that many of  followers of the account are interested are in the latest news, so with that in mind I have launched a new Twitter account to provide a more comprehensive and more regular stream of InfoSec news. @securitytoday  has been launched  to just tweet cyber information security related new...

Cloud is the New Security Perimeter

The rise of cloud computing is undeniable and unstoppable, information security professionals have to accept resistance to cloud is futile. The Cisco 2014 Annual Security Report , projects cloud network traffic will grow more than threefold by 2017, with businesses executives eyeing up cloud as the silver bullet in eliminating expensive IT hardware. This cost saving elixir means cloud solutions are often quickly steamrollered in by business, leaving information security playing second fiddle. InfoSec Resistance to Cloud is Futile More and more confidential information is moving towards the cloud, and if Cisco’s projection is correct, we can expect, if not already, vast volumes of information processed and stored by business to be typically cloud based. This data moving trend is the most radical change in information security since the dawn of the commercial Internet, and presents a major shift of the security perimeter. Blindly trusting cloud service providers to deliver a level o...

Terrorism Risk Assessment

After reading through news website comments, listening to radio talk shows and general conversations with peeps down the pub, the biggest debate post the failed UK terrorist attacks, isn't about the changing the "foreign policy", or "pulling our troops out of Iraq", it's the old chestnut personal Civil Rights Vs State Security. On scrutiny I found that most of those who sided with the extra security measures for the state over personal rights infringement, tended to because of fear of being a victim. For me as a security guy this isn't rational thinking, as they just aren't risk assessing the situation properly. So what leads people to think in this way? Well as terrible and deplorable terrorist acts are, I think the way the media over sensualises it, not only encourages these acts in the first place, but is helping instilling an irrational fear. I mean if I put on my "risk managers" hat, I know for a statistical fact that I am more likel...