Showing posts with label global security. Show all posts
Showing posts with label global security. Show all posts

Tuesday, 10 July 2018

How to Keep Up on the Latest in Cybersecurity News


Cybersecurity is always a hot topic, for a very good reason: the hits just keep on coming. Trying to keep up with the latest news and vulnerabilities is a daunting task, but you have to do it. Installing the latest security software and running the latest tests is not complete due diligence in the modern world of continuous cyber attacks. As the saying goes, “knowledge is power,” and it is especially so in the web-connected world.

So, how do you keep your knowledge at peak efficiency? Reading, of course. There are hundreds of technology sites and blogs that will help keep you informed about the latest issues but that’s a lot of reading. What follows is a list of the some of the best. You should recognize some of these if cyber security is not a new to you. Hopefully, the list includes some that you weren’t aware of and will add some bulk to your reading list.

The Hacker News 

The Hacker News is one of the largest and well-read information security sites. They feature news and thorough coverage of the information technology vulnerabilities and trends. The Hacker News is supported and endorsed by security experts, administrators, and members of various underground hacker groups and communities worldwide.

Krebs on Security

Brian Krebs is not your typical cyber export (but who is typical?).  His formal education includes a Bachelor of Arts degree in International Studies from George Mason University in 1994 (programming was a hobby). So, what prompted him to switch his focus to cyber security? In 2001 his home network was compromised by a Chinese hacking group. What followed was a self-taught crash course in computer and Internet security.

In his own words from his website, “Much of my knowledge about computers and Internet security comes from having cultivated regular and direct access to some of the smartest and most clueful geeks on the planet. The rest I think probably comes from a willingness to take risks, make mistakes, and learn from them.”

Open Web Application Security Project (OWASP)

Established in 2001, OWASP is a non-profit organization that has dedicated itself to the development of knowledge, tools, and best practices for secure application development. In their own words, they want to “be the thriving global community that drives visibility and evolution in the safety and security of the world’s software.”

One of their most important projects in my experience has been the “OWASP Top 10 Most Critical Web Application Security Risks”. Not only do they describe the risks in detail but the also provide examples for mitigation in multiple languages.

Schneier on Security

Bruce Schneier’s blog has been in existence since 2004. He writes about security in articles, books, and academic papers. He is currently the CTO of IBM Resilient, a fellow at Harvard's Berkman Center, and a board member of the EFF.

The blog includes articles pertinent to current security issues and has an engaging comment area with lively discussions. He also produces a monthly, well-read newsletter.

Dark Reading 

Dark Reading is a long-time source for information about new cyber threats and current cybersecurity technology trends.

From their website: “Dark Reading.com encompasses 13 communities, each of which drills deeper into the enterprise security challenge: Analytics, Attacks & Breaches, Application Security, Careers and People, Cloud Security, Endpoint,  IoT, Mobile, Operations, Perimeter, Risk, Threat Intelligence, and Vulnerabilities and Threats. Each community is led by editors and subject matter experts who collaborate with security researchers, technology specialists, industry analysts and other Dark Reading members to provide timely, accurate and informative articles that lead to spirited discussions.”

Naked Security by SOPHOS 

Naked Security is SOPHOS’ news aggregator, providing the news, opinion, and advice on our favorite topic: computer security issues and the latest Internet threats.

Naked Security also produces a daily newsletter that provides a list of important cybersecurity news articles published within the last 24 hours. This is a must read.

Summary

I hope this list added a few more sources for your cybersecurity knowledge needs. Feel free to comment below on these and other sites that you have found invaluable to our work.

Thursday, 29 March 2018

How Does the United States’ Approach to Security Compare to the Rest of the World?


- Alan Jamieson, BOHH VP of Business Development


Continual data breaches and the constant collection of personal information fuels debate on whether privacy is dead in the digital age. Regardless of who is winning this debate, privacy, security and trust—all increasingly at risk—are vital and must be interlinked in our data-driven society.

With the global focus to prevent cybersecurity threats or attacks, companies are investing in new strategies and even new roles, such as Chief Privacy Officer. CEO’s and their Boards say they are investing in cybersecurity to build trust with customers concerning the usage and storage of data, but is that enough?  As we have seen after many breaches, consumers will vote for responsible innovation and data use with their wallets.  In fact, we have seen a significant number of Fortune 500 companies who have lost significant earnings and customer retention because they have not adequately protected customer data as they embrace the digital times.

As security becomes more critical to the existence and growth of companies, some parts of the worlds are better prepared than others to combat these complex cyberattacks. Where does the US fit in?

The Global Cybersecurity Index (GCI) is a survey that measures the commitment of 193 Member States to cybersecurity in order to raise awareness.  In 2017, The United States was ranked 2nd globally in the Global Cybersecurity Index 2017, the first and third places were taken by Singapore and Malaysia respectively.  Europe’s best country was Estonia ranked 5th globally. 

  • Singapore ranks number one as its started its cybersecurity strategy in 2005, so it has greater knowledge and experience than most other mature countries.  Singapore’s Internet Content Providers (ICPs) and Internet Access Service Providers (IASPs) are licensable under the Broadcasting Act and they are required to comply with the Internet Code of Practice to protect children online. Since 2012, all service providers have been legally obligated to offer filtering services with Internet subscriptions and to make this known to consumers when they subscribe or renew. The Info-communications Media Development Authority also symbolically blocks 100 pornographic, extremist or hate websites.  Malaysia is second in Asia and third globally, its Government is a strong advocate of cybersecurity which focuses on businesses and Government alike. Malaysia created the Information Security Certification Body (ISCB), a department of Cybersecurity Malaysia, which manages information security certification.

Leaders in the United States and European Union have recognized that the interconnected nature of information and communications systems and the global nature of the threats demand international cooperation.  Legalizations that are driving change and commonality of strategy between the US and European Union (EU) are:

  • In the United States, the centerpiece is the National Institute of Standards and Technology Framework for Improving Critical Infrastructure Cybersecurity (NIST Framework) issued in 2014.  It’s now undergoing revision, coupled with state data breach notification laws and regulation of data security practices by various federal and state laws and agencies.
  • At the European Union level, legislation that takes effect in 2018: the Network Information Security Directive (NIS Directive) and the General Data Protection Regulation (GDPR) effective May 25, 2108.

While there are certain differences between the US and EU legal processes, their approaches to cybersecurity are aligned in essential ways.

Cybersecurity is an ecosystem where laws, organizations, skills, cooperation and technical implementation needs to be in harmony to be most effective.  Cybersecurity is not just a concern of the Federal or Central Governments, but also needs commitment from the private sector and consumers which we are starting to see happening in the tumultuous cybersecurity climate. As such, it is critical to develop a cybersecurity culture where citizens are aware of the trade-off between risks and monitoring of personal data when using electronic networks for research, data storage and/or acquisition.

While, the US was ranked 2nd in 2017 for commitment to cybersecurity, as the cyber threat grows, so must the government’s capabilities to put forth strategies to keep its citizens and their information.

Up until now, a large amount of cybersecurity protection efforts have largely fallen on private sector institutions, but many government officials and security experts believe not enough is being done and more standard regulations are needed. Already we are seeing more states bring forth their own data breach notification laws, privacy laws, and even cloud regulations, but only time will tell if and when these get passed and what impact they might have. As the number of security breaches and threats continue to rise, it is time we start to take a closer look at the standards we are using and re-evaluate what tools are needed to keep information protected from. Cyber hacks have become more complex and it is time we figure out how to flip the switch on them as well.