{"id":36702,"date":"2019-10-04T02:42:02","date_gmt":"2019-10-03T18:42:02","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=36702"},"modified":"2019-10-04T07:56:46","modified_gmt":"2019-10-03T23:56:46","slug":"change-culture-to-deal-with-cybersecurity-threats-say-it-experts","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2019\/10\/04\/change-culture-to-deal-with-cybersecurity-threats-say-it-experts\/","title":{"rendered":"Change the culture to deal with cybersecurity threats, say IT experts"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>SAN JOSE, CALIFORNIA \u2013 Security is harder than everyone thinks, according to Vikram Phatak, founder of NSS Labs, here at NetEvents 2019: Global IT Summit. <\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is not surprising because the global cost of cybercrime\nreached $600 billion in 2018, and is expected to reach $3 trillion by 2020. Current\ntop targets for cybercriminals include government agencies, healthcare\nindustry, and financial industry \u2013 where, according to Phatak, \u201cthere\u2019s money.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thomas Edwards from the US Department of Homeland Security\nnoted that \u201ccybercrimes are driven by profit.\u201d Cybercriminals, for instance,\nare after personal identification, and then turn this into profit; or are after\ncredential theft, but then again eye to monetize this (credential).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Surprisingly, cybersecurity spending is pegged at only $124\nbillion in 2019, and only growing to $188.4 billion by 2023.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Phatak noted that there continues to be various issues affecting how companies respond to cyberthreats. There is skills shortage, for instance, with \u201cnot enough trained cybersecurity experts\u201d, and labor-intensive solutions requiring these experts. Also, \u201cnew attack vectors (force) us to compromise ourselves (since) situational awareness is lacking.\u201d And then \u201cwe have to consider where we\u2019re headed \u2013 e.g. cloud, IoT, 5G, and what happens when attacks jump from the virtual world to the physical world?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But exactly because of the layers of issues that coalesce when tackling the cybersecurity landscape that IT experts say cultural change needs to happen to effectively deal with cyberthreats. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ZERO-TRUST CULTURE<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to Michael Levin, CEO and founder of Center for Information Security Awareness, \u201cWe\u2019re not training our people about cybersecurity until there\u2019s a problem.\u201d For him, therefore, \u201chow do we create a culture (that is aware of cyberthreats)?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is because for him, \u201cwhen you think of cybercrimes, you also need to think of social engineering.\u201d This means that the crime can be done in many ways \u2013 e.g. it could be over the phone, over social media, or over emails. \u201cThere are so many ways (for cybercrimes to be done), so that you have to come up with mechanisms for employees to be always on the lookout. We need to come up with simple mechanisms to deal with these crimes.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threats could come from various sources, but Levin said that it doesn&#8217;t matter where these come from. In the end, &#8220;you still have to train your people (how to deal with the threats).&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ted Ross, CEO and co-founder of SpyCloud, recommends the\nestablishment of a \u201czero-trust culture\u201d.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cPeople underestimate cybercriminals&#8217; ability to innovate,\u201d he said, noting that cybercrimes have long been associated with emails. But \u201cfairly sophisticated criminals can access data\u201d so there is a need to teach employees to \u201ctreat everyone as an adversary.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>OPEN-DOOR POLICIES<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some of the cyberthreats are actually easy to discern if\nemployees \u201ctake it slow.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Levin, for one, said that people need to heed the \u201csense of\nurgency\u201d of an act (e.g. an email). \u201cThis forces people to think quickly, and\nthis results in fraud. For instance, we click links and attachments (when we\nthink they\u2019re urgent).,\u201d he said. \u201cNow how do you get people to think, and to\nslow down.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For Levin, there is a need to create policies and procedures\nfor this.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Edwards added that \u201cemployees need to know that it\u2019s okay to commit mistakes (by having an) open culture.\u201d This way, employees are \u201ctransparent with their cyber hygiene.\u201d With the transparency, they are therefore empowered; which will prove beneficial to the company in the long run.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>REALISTIC ASSESSMENT\nOF CAPABILITIES<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Paul Kraus, VP for engineering of NetScout Systems Inc.,\nsaid that companies need to know what they have (their assets). \u201c(It starts\nwith) gathering of inventory of what you have. How valuable is the asset? Secondly,\ncan you monitor? Does the security team even understand what\u2019s out there?\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Edwards from the US Department of Homeland Security similarly\nnoted that without sharing of information between the private and public\nsectors about cyberthreats, \u201cwe\u2019d lose the battle eventually; so information\nsharing is important.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Nowadays, \u201csecurity is like a gym membership,\u201d Phatak said. \u201cYou\njoin, but do you really use it?\u201d And in the end, to really deal with cyberthreats,\n\u201cyou need to use this membership.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The global cost of cybercrime reached $600 billion in 2018, and is expected to reach $3 trillion by 2020. Because of the layers of issues that coalesce when tackling the cybersecurity landscape that IT experts say cultural change needs to happen to effectively deal with cyberthreats.<\/p>\n","protected":false},"author":2,"featured_media":36703,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22],"tags":[1481,6498,6151,272,54],"class_list":["post-36702","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-spotlight","tag-cybersecurity","tag-good-tech","tag-high-tech","tag-netevents","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/36702","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=36702"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/36702\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/36703"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=36702"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=36702"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=36702"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}