Security Market Segment LS
Tuesday, 20 December 2016 11:03

Data is the new gold, trust is the new driver

By

More data breaches — some very high profile ones with Yahoo!, Sony, Ashley Madison, Target, LinkedIn, IRS/FBI/US Department of Homeland Security and a host of health-related record keepers — hit the headlines in 2016. People trusted these organisations, rightly so, to keep their data safe.

In fact, the US-based Identity Theft Resource Centre lists 980 significant, known breaches to date and over 35 million personally identifiable data records that were exposed. There are thousands of unreported breaches as well.

Palo Alto Sean DucaSean Duca, vice-president and regional chief security officer, Asia Pacific, Palo Alto Networks,  has written on his company’s security predictions for 2017 and warns, “People will continue to be too trusting or fooled into thinking something is safe – for example, confidential data - when it really isn’t.”

Duca says 2016 was a challenging year for organisations particularly as cyber adversaries achieved high-profile success, mainly with ransomware and data breaches. Being aware of security concerns doesn’t mean avoiding new technology altogether. It’s about being sensible and trying to stay ahead of cyber criminals by understanding current and potential threats and what can be done to mitigate the risk.

Palo Alto Networks security predictions for Asia-Pacific in 2017

Industrial control systems may turn against you

Industrial control systems (ICS) are an integral part of any business, especially in Asia-Pacific. They can control lifts, security cameras, access doors and much more.

Many businesses outsource building management so they don’t necessarily know whether the third-party provider has adequate security in place. It is not impossible for a malicious actor to execute an attack that could cause significant damage.

For example, an attacker could turn the heating up to a dangerous level in a company’s server room or data centre and then disable all the building access points so no one can get in to physically remove hardware to a safer location. The hardware overheats, causing significant disruption to a business, its customers and its partners.

Business needs to consider:

  • Organisations need to gain an overarching view of their potential weak spots through third parties as well as their own network. Additionally, they need to put a plan in place that would help counter any potential attacks.
  • Have you checked what non-IT equipment your business depends on and what security it has? Are these devices connected to the internet or are they managed by a third-party?
  • When outsourcing to a third-party, what level of security assurance do they have in place? Are they able to provide information on how they secure themselves and, ultimately, how they secure and manage their customer's network and systems?

The Internet of Things (IoT) devices will be a target for cybercrime

Gartner predicts that the number of connected ‘things’ will rise from 6.5 billion in 2015 to almost 21 billion by 2020.

Connected devices will also be a target for cybercrime, even more so because people place enormous trust in third-party vendors being safe. These endpoint devices provide thousands of potential entry points to an organisation’s network - they need to be secured.

In 2016, we saw the first real challenges appear where compromised devices were connected in a botnet to launch DDoS attacks against banks and key parts of the internet infrastructure.

Business needs to consider:

  • Understand that the IoT is a current reality - not a possibility or a project of the future. Ask suppliers involved in security assurance how they can assure the security of the devices they provide.
  • Any devices using factory settings for security are simply asking to be compromised. IT managers must change those standard administrator passwords to avoid being targeted.
  • These devices should also be regularly checked to see if they adhere to the company’s security policy.

We may see a ransomware vortex with a nasty surprise

Ransomware involves attackers locking up a business’s data and demanding a ransom for its release.

If you thought 2016 was bad for ransomware – where attackers access data and ransom it back to the victim – then 2017 will be worse. Expect to see a higher attack volume, using more sophisticated technologies. If the discovery of Locky ransomware was anything to go by, financial malware will continue an upward trajectory in 2017.

What business needs to consider:

  • If you have fewer than 72 hours to respond, do you have a comprehensive backup strategy and response ready to counter these attacks?
  • When was the last time you tested and verified the backup?
  • Have you applied basic file blocking to prevent threats from entering your organisation?

We will have serious data trust issues

People will continue to be too trusting or fooled into thinking something is safe when it really isn’t. For example, confidential data can be exposed, or made available, that looks like it comes from an organisation when it was actually planted by a malicious party. Either way, there’s a business reputational risk and a monetary price to pay.

What Can Be Done?

  • Businesses need to look at two key things: where sensitive data resides and what data is critical to it to operate
  • Who amongst employees has access to sensitive data? Simply knowing who has access to documents or big data stores stops short of understanding to what they have access.
  • A key way to reduce risk to sensitive information is to also understand how the data is protected. Is there protection in place, and does it meet the right level to mitigate risk for something that could be mission-critical to a business?

PAP 1

PAP 2
 


Subscribe to ITWIRE UPDATE Newsletter here

Active Vs. Passive DWDM Solutions

An active approach to your growing optical transport network & connectivity needs.

Building dark fibre network infrastructure using WDM technology used to be considered a complex challenge that only carriers have the means to implement.

This has led many enterprises to build passive networks, which are inferior in quality and ultimately limit their future growth.

Why are passive solutions considered inferior? And what makes active solutions great?

Read more about these two solutions, and how PacketLight fits into all this.

CLICK HERE!

WEBINAR INVITE 8th & 10th September: 5G Performing At The Edge

Don't miss the only 5G and edge performance-focused event in the industry!

Edge computing will play a critical part within digital transformation initiatives across every industry sector. It promises operational speed and efficiency, improved customer service, and reduced operational costs.

This coupled with the new capabilities 5G brings opens up huge opportunities for both network operators and enterprise organisations.

But these technologies will only reach their full potential with assured delivery and performance – with a trust model in place.

With this in mind, we are pleased to announce a two-part digital event, sponsored by Accedian, on the 8th & 10th of September titled 5G: Performing at the Edge.

REGISTER HERE!

BACK TO HOME PAGE
Ray Shaw

joomla stats

Ray Shaw ray@im.com.au  has a passion for IT ever since building his first computer in 1980. He is a qualified journalist, hosted a consumer IT based radio program on ABC radio for 10 years, has developed world leading software for the events industry and is smart enough to no longer own a retail computer store!

Share News tips for the iTWire Journalists? Your tip will be anonymous

WEBINARS ONLINE & DEMAND

GUEST ARTICLES

VENDOR NEWS

Guest Opinion

Guest Interviews

Guest Reviews

Guest Research

Guest Research & Case Studies

Channel News

Comments