Menu

  • Home
  • Latest

Categories

  • AI
  • Automation
  • Cloud Computing
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Uncategorized

Subscriptions

  • Bill Mew
  • Dez Blanchfield
  • Swatantra Kumar
  • TechTV Live
Vidnion
  • Home
  • Categories
    • AI
    • Automation
    • Cloud Computing
    • Cyber Security
    • Data
    • Digital Enterprise
    • Infrastructure
    • Mainframe
    • Supply Chain
    • Telco & Mobile
No Result
View All Result
  • Login
UPLOAD
Vidnion
No Result
View All Result

Cybersecurity Update

53 Views
7 months ago
0 0
0
Share
Twitter Linked In Facebook
    TechTV Live TechTV Live
    0 Subscriber

    00:00:02
    [Music] Imagine waking up one morning to find your city’s power cut, the water supply contaminated, your bank account inaccessible, and the supermarket shelves empty. Not due to war plananes or tanks, but because of an invisible silent strike launched through the internet. Back in 2012, US Defense Secretary Leon Petta predicted an attack that would paralyze and shock the nation, not through military means, but via a cyber attack, which perpetrated by nation straits or violent extremist groups, could be as destructive as the

    00:00:52
    terrorist attacks of 9/11. They could, he said, contaminate the water supply in major cities or shut down the power grid across large parts of the country. His words marked a turning point, a new era of cyber warfare where the battlefield is now digital. Countries and corporations have since begun to confront a sobering reality. The next major conflict may be fought with code, not bullets. Hackers, no longer isolated or amateurish, are highly coordinated and often backed by powerful nation states. They shift from

    00:01:31
    sector to sector using artificial intelligence to identify and exploit vulnerabilities. Hospitals, universities, supermarkets, nothing is off limits. Just last year, UK education institutions were targeted and now high street retailers like Co-op and M&S have joined the growing list. Is this just another wave of disruption or a prelude to something much more catastrophic? While defenders deploy the same AI tools to detect and patch vulnerabilities, they’re locked in an arms race with adversaries who have the advantage of

    00:02:10
    anonymity, state protection, and global reach. How can we protect ourselves when many of these cyber criminals operate from jurisdictions beyond the reach of Western law enforcement? And there are signs that something’s happening behind the scenes. Within the last few days, it was announced that the UK mod is to spend an extra billion on defense, a significant proportion of that on cyber. All worrying signs. There is hope, however, in a rare example of international cooperation. Police forces from Britain,

    00:02:46
    the US, Germany, France, and others recently dismantled a major Russian-led malware network. Arrest warrants have been issued. Indictments have been unsealed, but is this enough? Today, we ask the crucial questions. Are we prepared for the big one? Can our lawyers and systems and keep up with the criminals and the cyber threats? And how do we protect ourselves in a world where the next devastating attack might arrive not by land, air, or sea, but simply through a click? To discuss all of this, I am joined

    00:03:23
    today by my TechTV colleague Pete Warren and by Gary Cox, senior technical manager for UK and Ireland at InfoBlocks. Over to you, Pete. Gary, you’ve done a lot of work with the government. What what’s going on at the moment? Our high streets being attacked. The government’s been attacked. There’s been attacks on the NHS within the last week. There’s been attacks on the court system. What’s going on? Well, I mean, Pete, I I don’t know if I can comment exactly on on what’s going

    00:03:56
    on other than that the government is no different to any other enterprise. I think we should all assume that we are going to be under attack all of the time. Um, we all need to shift to a state of readiness and preparation. Um, I said governments are are no different. Government departments are no different. HS is is no different. um the importance of those organizations, you know, they all need to we all need to focus on our cyber hygiene generally. Um there’s a lot of great defenders inside all of those

    00:04:29
    organ organizations uh who are doing, you know, good jobs. Um but we can all do more. But it’s an interesting point, isn’t it? A year ago, I was in Panama. I bumped into some people completely coincidentally from the US State Department. Um and um I said to them, “We appear to be in a cyber war. This cyber war has been going on for far longer than the Ukrainian conflict. Why are people remorselessly attacking computer systems? It’s in many ways it’s a it’s a faceless crime. I mean, if we think think back,

    00:05:08
    you know, bank robbers used to go in with sorn off shotguns in a van waiting out outside to do their getaway, right? But then you were caught, everyone knew who you were, and you’d go to prison. With computers, with the internet, now cyber crime and indeed cyber warfare can be conducted at great distance. I mean, arms length and then some, right? Um, so yeah, it’s it’s it’s a it’s it’s a difficult one to get to attribution of the criminal. And I think that an anonymity is why um it’s

    00:05:41
    so prevalent at least from a criminal perspective. Why do we have this anomimity? We’re seeing Europole beginning to strip this back in with certain gangs. We’re seeing Interipole as well becoming involved. We’re seeing cooperation between um police forces in the US and Europe in bringing these gangs down. So attribution is possible. Why is it so difficult? Is it because some people won’t let us into their networks to find out where the attacks are coming from? I I don’t know if it’s

    00:06:15
    so much that people won’t let people into networks, but and I think you’ve actually hit the nail on the head. It’s that cooperation uh crossjurisdictional is what really will will lead to, you know, people being identified and prosecuted. probably none of us have the full picture which is why you know an individual agency it’s really difficult for them to go and and find you know the the criminal um and and get them but the second you start to join the dots together to cooperate to track it at a

    00:06:47
    global scale you know I I think this is where we start to see benefits I mean if I just look at things that happen for example here inside uh the United Kingdom people cyber cyber defense alliance So, the Cyber Defense Alliance are joining together law enforcement and all of uh or many of our our banks, our you know, re retail banks and they’re doing it for the greater good. It’s to make sure that again you’ve got that triangulation between different entities working together for a common

    00:07:18
    cause. So, in that case then, can we identify where these lines of of cooperation break down? If we’re seeing cooperation between European police forces and American police forces, we may not be seeing cooperation between those forces of law and order and Russian police forces. We may not be seeing that cooperation between those forces, Chinese and Chinese forces, North Korean forces. Is that a fair thing to actually say? I I don’t know if I’m qualified to answer that quite honestly, Pete. I’m

    00:07:55
    not in those in inner circles to know who does talk to who and when and where. Um I’m sure there are communications where where appropriate, but again, I’m I wouldn’t I wouldn’t even like to step on that one. I mean, I’m just pushing for this question of attribution. I one of the things that seems to be happening at the moment is many many times I wrote a book in 2005 warning of this situation. Obviously it was such a wellbought book that nobody heeded it but um the the the point is at that time

    00:08:30
    people were talking about this being a wild west. This is more than a wild west. We’ve got gangs just, you know, riding up the metaphorical internet high street on their horses just shooting. Um, and we don’t appear to be doing very much about it apart from saying, “Oh, we better put some stuff across the windows and and make sure that walls are bulletproof.” Surely we do need some other other solutions to this. Yeah. You know, I mean, I think one of the best things that we can all do is come back

    00:09:02
    to some some foundational basics. things like making sure that our attack surface is known is you know when I say attack surface it’s internal and external if I’ve got let’s say a bunch of Microsoft servers let’s make sure those are patched if those Microsoft servers are running critical services can I decouple them so maybe move my DNS onto something else so again I’m spreading that make sure that we know what does our internet presence look like online and that could be what are what are my employees

    00:09:34
    sharing on the likes of LinkedIn or indeed any other social social media. Um, and what does my company footprint look like? If from the outside in, if someone’s scanning, which they are, they shouldn’t do, but they they can do. It’s an it’s an external internet presence, right? What does that attack surface look like? Is it easy to map out where are my easy points of entries? And certainly, I mean, the area that that uh, you know, the company that I work for specializes in, we’re able to look

    00:10:04
    at some of those things. And it could be something as simple as um being able to see does a company use docyign. If a company uses docyign, well, if I’m the bad actor, that is just one thing I could look at to say, well, if I wanted to do a fishing campaign against these folks, that’s one one piece of the puzzle where maybe I’m going to use docysine or indeed anything else. So I think if we are aware of our attack surface, we can start to you know batten the hatches down where appropriate and

    00:10:36
    that includes training training our users to say hey if you know this is what corporate you know standards look like. If you see something that deviates from it then you know be be wary. Um and yeah I say that’s good cyber hygiene. It goes far beyond that of of course um there are what you see what you seem to be saying is that modern businesses aren’t modern. What you what you’re saying is that modern businesses are still very 20th century. They’re not even 21st century. They’re not able to

    00:11:10
    visualize themselves on the internet or in an IT world and they’re not actually able to visualize what those threats are to that. You seem to be talking to me about a world where people can’t actually see what they look like. So, I think they can if they choose to go looking. I think it’s a it’s a question of going and doing that due diligence, understanding what your presence of your company or yourself as an individual looks like on the internet. How much of of a risk am I? What processes do I have in place? Are

    00:11:45
    people using, you know, two-factor authentication, for example? what if you’re not that’s absolutely a foundational thing that should be put in put in place you know so it’s it’s all of these sort of checks and balances that I think give us good cyber hygiene I mean you know you you mentioned UK government earlier so if we look at things like cyber essentials cyber essentials plus that is uh the you know the UK government or the NCSC starting to put in in place frameworks for companies inside the UK

    00:12:17
    to get to a baseline standard. Now, of course, it’s not mandated and it’s very difficult to to do that, but that is an again, it’s a good way of of starting to make sure that I’ve got those checks and balances in place. I’m getting to at least a baseline, and the baseline still might not be good enough. It really might might not, okay? You know, our adversaries, we should be respectful of them and and you know, they collaborate far more than than perhaps we as defenders do, which is really scary. Um,

    00:12:47
    but yeah, that baseline at least is a starting point. But that I mean that that baseline with all due respect, it reminds me very much of the green cross code man that we used to see. Um it is almost that basic where and I mean that that does actually go to a little bit of a an irony that even then that you were trying to tell people how to cross a road and we’re in a similar situation now in with the cyber high street that green cross code man attitude. we have to radically up because small and

    00:13:24
    medium-sized businesses are now coming under attack and they’re the ones who are least able to defend themselves currently. Mhm. Yeah, I um I would agree with that as as a premise and I think we you know we all need to start somewhere. So as you as you rightly said the green cross code man a great analogy for it. You know it’s trying to teach people those foundations. Um, some will listen, some won’t. Some will be careful and look both ways before they’re crossing, others others won’t. Um, and I think

    00:13:55
    you’re right as well, you know, the the the SMBs, the smaller companies who don’t have, you know, any budget for cyber, you know, or a CISO, someone to guide them through the choppy choppy waters, who’s qualified, has experience in doing this. Um, I mean, there are some great organizations out there that that that try their their hardest to support people like those those um those smaller organizations. Um, whether they be local sort of cyber cyber clusters or people like IC Squared, Bides, they all

    00:14:28
    try and do the sort of community education piece. Um, could there be more? There can always be more. And I and I think you know one of the I’m I’m a huge advocate for you know making sure that anyone whether it’s a relative, friend, family member, small company has somewhere to go to get quality advice. But that also argues that we should have people who are on the boards of companies who actually do know what they’re talking about in terms of technology. This is something that we’re beginning to see

    00:14:59
    mandated in the US for large companies. the um the the the the the Fed in the US is is is is is making sure this is mandatory with the resilience measures that are being proposed by the EU and will be probably replicated in the UK. Those are things that we need to see too, aren’t they? Yeah, absolutely. And and I mean certainly there are some excellent excellent CISOs out there that I know who look after very large or organizations and they do a fantastic job. Not every company in the UK has a

    00:15:34
    has a CISO for some it won’t be appropriate. But I think if I’m sort of cutting to the to the chase there certainly whether you’re labeled as a CISO or or you’re not. If you’re responsible for the technology inside an organization, whether that’s just a a a website and and an email address, you know, for really small small companies, I think we need to be techsavvy. we need to be tech-savvy to know well what should I be doing as a best practice um and and it comes down to to education

    00:16:06
    but and and yet we’re also now moving into this AI world where people are seeking to deploy AI as quickly as possible even though they don’t understand the cyber security AI is data hungry so if your data is poisoned you’re in a very very bad situation we’re also going to have a supply chain nightmare bill in his introduction was talking about the poss possibility of the one big attack. Well, the one big attack could quite likely just be a catastrophic accident unless we get on top of all of this.

    00:16:38
    Yeah, AI is uh it’s interesting. It it’s a it’s a blessing and a curse in equal measure. And the reason I I I phrase it that way is certainly all of us can use it for for the greater good. those small uh you know small companies they can absolutely use chat GPT or indeed any other to say hey look this is the profile of my company how could I best defend myself what are the basics I should do and you know check trust but verify right but it’ll give you the starting point of what does what

    00:17:11
    does the start of good look like then on the inverse we have our bad actors using AI to accelerate their timelines to do things faster quicker easier you better. Uh, I remember one of the very first things that I personally tried with with with AI and perhaps being a techy security geek, this was naturally the first thing I did. I wrote a a fishing email, which I fortunately was never going to send, and said, “Translate this into Russian. Now translate it into French. Now trans I don’t speak any of those languages, and

    00:17:42
    it did a fantastic job.” you know uh so that’s just an example of how easy AI tooling can make it you know whether we go down the line of you know deep fakes and all that stuff but just the rudimentary stuff it makes it really easy for the bad actors to create campaigns to weaponize to deliver those campaigns and do it on mass at scale I think that’s a very important lesson isn’t it the very important lesson to think about with all of this is people talk about AI attacks, what they’re

    00:18:17
    actually not realizing is that an AI attack could be just using the technology to actually take advantage of existing weaknesses. So, for example, you mentioned the fact that on social media people give out a incredible amount of information about themselves. The intelligence agencies call open-source intelligence. You can find lots and lots and lots of detail about people’s lives on that. You could actually tell a uh AI engine to go through a social media profile, find out all about them, and base an attack on that. And you

    00:18:52
    could just tell them to do that, couldn’t you? We’re not talking about sophisticated coding. No, absolutely not. I mean, I I think, you know, the the those of us that will succeed in in an AI world will be those that get the prompts down to a fine art, like know what you’re looking for, know how to iterate through that in order to get the best out of it using the right AI tooling, the right AI engines to go and really get the right data that you want and then validate it, verify it, of of

    00:19:23
    course, but yeah, it’s it’s it’s all about it’s all about the expediency. And as you rightly say, absolutely tell it, hey, you know, go to go go go to go to LinkedIn and look up Peter Warren for please tell me all the books he’s written and and articles he’s you know, it’ll come back in a flash. I’m I’m not sure it could do that. That’s a huge volume of data. Um uh AI is there for big data problems, Pete. Well, that’s point, isn’t it? And that’s

    00:19:54
    the point that we’ve got to come to terms with. We’re moving into the I mean a lot of people we used to use the term 21st century to talk about the future. We’re now in the 21st century and we’re talking about a 22nd century. We don’t we’re not actually properly uh prepared for this 21st century world. We need to significantly educate people in all of this. A lot of people will say a lot of the the chief executives of small businesses will say I don’t have time to for this. I actually make tables. I just

    00:20:30
    want to concentrate on making tables. How do I protectselves? So how do they protect themselves? Do they buy in a service from somebody else? Do they go to Microsoft and say, “We want you to run this and make sure that we’re all safe so I can just carry on and concentrate on making tables.” Or do they have to have some awareness of this world? So um yeah there’s there’s something that we always talk about called the cyber maturity curve and I think it’s really good to know where you are on

    00:20:58
    that cyber maturity curve and you know you talk about buying in buying in services I think that is a fantastic starting point like if if you know if people are honest with themselves and say hey you know I I I know how to operate my email and and and do all my word documents or my Google docs or whatever but I don’t know anything about about cyber I don’t know where to start with that and they probably don’t have a team of of people to you know run a security operation center. So yes,

    00:21:24
    absolutely, you know, outsource that. It’s going to be the quickest way to start on that side maturity uh journey. As companies scale up and they start to have in-house teams, then of course then you can start to look at either hybridizing or going fully in inhouse. But I mean it’s um it again it’s it’s a really really hard thing and companies need to choose what’s the right model for them. Um I’m always you know in in favor of of sort of hybridizing that world because you

    00:22:01
    can absolutely buy in the skills you need if you don’t have them in house rather than languish without them and put yourself at risk. However, your own staff inside your organization, they know your organization better than anyone else ever could, one would hope. So, I I think the blending of those two worlds can be so powerful. You seem to be suggesting that there’s possibly a role for government here in actually saying not just that there is cyber essentials but also in terms of giving advice on the attacks that are

    00:22:36
    coming saying to businesses this is the information that you need to be available that needs to be available to you. This is where you can go to get additional information. Do you think that we need that information resource so that we can say to businesses, yeah, be cyber ready? I I think we already have that. I mean, if I look at publications from NCSC, if I look at publications in the US from from NIST and and and CISA and various others, I think it’s out there. I mean, I think um but in that case, if it’s out there,

    00:23:08
    then how how how do we disseminate that? Do we actually say go round to the parish councils and say, “Hey, make sure all of the businesses in your area know this, the county councils, the district councils.” Uh, yeah. I mean, that that’s the challenge, isn’t it? It’s how do you how do you make sure the information is in in in the the hearts and minds of the right of the right people. Um, I other than being an advocate in your own community, I honestly don’t don’t know.

    00:23:35
    I mean, I mentioned earlier things like, you know, IC2, you know, chapters or uh various different cyber clusters that we’ve got up and down the UK. They’re a fantastic starting point because they tend to be in their communities for their communities. Um, that’s a good starting point, but as I think we’ve said a couple of times, not everyone is a member of those. That information doesn’t doesn’t reach every single one in the population. I mean maybe quite honestly perhaps the best thing that uh you know

    00:24:05
    the the the government or anyone else could do for us is a media campaign is to get it out there. You know I mean you mentioned the green cross code uh one earlier that was on TV. I don’t think I’ve seen a TV campaign uh you know talking about cyber essentials or anything else. So I mean we need to find a way of getting it to the you know to the masses. And maybe it’s not a TV campaign campaign nowadays. Maybe it’s a I don’t know an online social media campaign. Wherever it’s going to reach

    00:24:34
    the the the right people, that’s where it should go. Gary Cox, next week it’s Infosk, the annual bean feast of the cyber security world. It’s also a European cyber crime conference as well on what we’ve got to do to confront cyber crime. Gary, thank you very much. Gary Cox of Infoblocks. Thank you very much. and and Gary, thank you very much there. Thank you for joining us. I I think Pete, a lot of this comes down to two major focus areas, both the technical side and the political side.

    00:25:09
    And we talked a lot there about training and the need for education. Uh it is the reality, however, that specialist education, specialist skills are in very short supply, and that’s why we’re seeing the rise of things like managed security service providers. But on the political side uh we also have to face reality here. Every country is a signary to the UN agreement around law enforcement and collaboration. So in theory we should be able to ask Russia or China or North Korea to help us to

    00:25:44
    track down these misgrants. But the reality is that all too often it’s they are statebacked organizations and it’s these states that are backing them. And therefore it will take a change in politics and uh a completely different role for the UN its mandate and and everything else for us to make that difference. So in the meantime I think relying on the skills is going to be essential. I hope you agree. Well, Bill, I actually think that I mean the statistics according to the companies who will be talking at infosc next week,

    00:26:20
    they claim that and probably with much more authority than me that 80% of the attacks come from nation state actors in some shape or form. Uh if that’s the case, then really all that you can do is make sure that you’re protected until you can actually get an agreement from all of these nation states that what they’re doing is going to eventually become very very dangerous because one of the things that people talk about agnosium in the technology world is about an ecosystem. We are all now relying on this

    00:26:57
    information sphere for one of a better phrase and that’s what we’re potentially jeopardizing with some of these attacks. Sometimes the attacks are not particularly well coordinated. If you look at the not the not Petia one for example that attacked a lot a lot of things that it wasn’t intended to go for. It nearly took out the shipping line. Um I forget the name of it mk. Um, yeah, exactly. And that wasn’t it it its intended victim. However, it was that wasn’t nearly its biggest casualty. So,

    00:27:30
    you’ve got to be very very careful about what’s going on in this. Well, hopefully we’ll see a lot more technology, a lot more advice, um, some great new tools at inc. Um, I want to thank Gary for joining us today and I hope that uh in the near future we’ll see great progress not just on the technical side but um I’m ever the optimist. I hope that the political side and the collaboration through the UN or otherwise will help at some point uh crack down on some of these international actors and the fact

    00:28:05
    that they’re effectively operating from a safe agent at this moment in time. Anyway, thank you everyone and uh do tune in again soon and hopefully we’ll be bringing you more updates on this and many other similar topics. [Music]

    Category: Uncategorized
    Next Post
    Heads Up: Highlights from Infosecurity Europe 2025

    Heads Up: Highlights from Infosecurity Europe 2025

    Recommended videos

    Intelligent Infrastructure

    26 Views
    April 14, 2024

      ATTBizSummit – Day 1 – Talking to Chris Gardener from Happyness

      36 Views
      April 14, 2024

        Conversation with Janet Giesen & Rob Kaloustian of Commvault Metallic

        31 Views
        April 14, 2024

          Chris Powell, Chief Marketing Officer – Qlik ( #QlikWorld2023 )

          27 Views
          April 14, 2024
            Show More
            vidnion.com

            © Sociaall Inc.

            Navigate Site

            • Home
            • Privacy Policy
            • Contact Us

            Follow Us

            Welcome Back!

            Login to your account below

            Forgotten Password?

            Retrieve your password

            Please enter your username or email address to reset your password.

            Log In

            Add New Playlist

            No Result
            View All Result
            • Home
            • AI
            • Automation
            • Cloud Computing
            • Cyber Security
            • Data
            • Digital Enterprise
            • Infrastructure
            • Mainframe
            • Supply Chain
            • Telco & Mobile
            • Privacy Policy
            • Contact Us

            © Sociaall Inc.