Menu

  • Home
  • Latest

Categories

  • AI
  • Automation
  • Cloud Computing
  • Cyber Security
  • Data
  • Digital Enterprise
  • Infrastructure
  • Mainframe
  • Supply Chain
  • Telco & Mobile
  • Uncategorized

Subscriptions

  • Bill Mew
  • Dez Blanchfield
  • Swatantra Kumar
  • TechTV Live
Vidnion
  • Home
  • Categories
    • AI
    • Automation
    • Cloud Computing
    • Cyber Security
    • Data
    • Digital Enterprise
    • Infrastructure
    • Mainframe
    • Supply Chain
    • Telco & Mobile
No Result
View All Result
  • Login
UPLOAD
Vidnion
No Result
View All Result

Heads Up: Highlights from Infosecurity Europe 2025

64 Views
7 months ago
0 0
0
Share
Twitter Linked In Facebook
    TechTV Live TechTV Live
    0 Subscriber

    00:00:03
    [Music] [Music] Hello. This week we have been at Infosysk Europe. This is the jambbury that happens every year at um the docklands in the uh east end. and Pete and I were there as normal. It had a little bit of a different feel about it. Long gone are the scantily clad cheerleaders from the early days when it used to be an Olympia. They’re long gone. Ever since it found its new home at the Excel Center in the London Docklands, it’s been a far more serious affair. But in these new AI focused

    00:00:50
    days, how has it changed? Pete, what did you think? Well, I think you know obviously AI is very much in the agenda, but there’s a new reality for cyber at the moment and you you can definitely get a feel of that. It’s come from the defense review. It’s also come from Bill I I think it it’s it’s come from all of the hacking attacks that we’ve having we’ve been having. Uh you know, you were talking to the celebrated hacker infosc institution cyber security historian Miko Hitman.

    00:01:24
    What what was his take on? Well, all round great lad and Mo was a really a fascinating guy to meet. Um he struck what I thought was an unusually positive note given the spate of attacks that we’ve had recently. He reckons that those working on the side of defense side still have an edge over the cyber attackers. But we can’t afford to celebrate just yet. uh because as he explains during our interview, once the easy marks have gone and once they’ve done with the lowhanging fruit, the

    00:01:56
    attackers are going to be forced to start making better use of AI. And when that starts to happening, uh that’s the time when we really need to start worrying. So Mo, really nice to see you here at Infoscurity Europe. Um I’m very interested in your thoughts on where we are at the moment in the cyber war. uh whether we’re winning, whether we’re losing, and what the big trends are. The only thing I’ve learned over these decades that I’ve worked in cyber security is that nothing changes the

    00:02:28
    world more than technology revolutions. And this applies to cyber security as well. We’ve seen this with the connectivity revolution, with the computing revolution, with the social media revolution, and now we are seeing these huge shifts in cyber security because of the generative AI revolution, both on the defensive side, but also on the offensive side. So, we’ve got both teams using AI as much as they can um to to increase their productivity. um one side using the AI to find vulnerabilities to exploit, the other

    00:03:03
    one’s finding vulnerabilities uh in order to patch them. Is this an arms race? It is an arms race and and we’re really glad that for once we have a situation where the good guys seem to be ahead of the bad guys. What I mean by this is that security companies have been using machine learning for a very long time and now everybody’s jumping to the bandwagon of generative AI for defensive purposes and the attackers seem to be a little bit behind. What I mean is that we’ve only seen things like

    00:03:34
    deep fake videos trying to push scams and and and things like that. We haven’t really seen an explosion of um vulnerabilities and exploit being developed by generative AI from the bad guys. We have seen security researchers discover zero day vulnerabilities with generative AI, but that’s a good thing because that allows us to patch them before they’re used by the bad guys. But this will change. We will see offensive use of vulnerability discovery being done by the online criminals as well.

    00:04:07
    and the fact that we’re ahead of them. Is that because we have more skills and resources employed on the white hat side than on the black hat? Um, is it because there’s greater collaboration and cooperation? I mean, I hear that a lot of the gangs actually share information and are collaborating to a great extent and sometimes uh we may be collaborating as industry peers but possibly not as different uh uh uh law enforcement bodies because there are very much um uh safe harbors where a lot of uh uh people

    00:04:38
    operate from. We have the same thing on both sides. on on defensive side, cyber security companies do cooperation but also competition. Then when you look at cyber criminals, it’s the same thing. They do cooperate. They share information. They have these forums where they discuss these topics, but they also compete with each other. So for example, when you look at ransomware gangs, gangs like Akira and Play and Lockpit, they are actually poaching members from other gangs to each other. They’re attacking each other’s sites.

    00:05:11
    they are doxing like leaking information about the operation of their competitors to try to get ahead. So there’s both competition and cooperation happening on both sides. And I think the reason why from my point of view um attackers are a little bit behind defenders as it comes to generative AI is the simple fact that these criminal gangs have been making a killing with traditional mechanism. So ransomware gangs have been making millions and millions for for for a decade now without using generative AI.

    00:05:45
    So it sort of becomes the question that why should they spend their time and money into developing something that they don’t need right now. They will do that when they need it, but they haven’t needed it yet. So there’s enough lowhanging flu fruit fruit for them to exploit. It’s too easy for them to um force them to go down the the more uh difficult route of AI. But that will happen. That will happen. And and it will happen because we are getting better at defending our systems. And let

    00:06:14
    me just underline this. I think cyber security situation right now is better than ever before. And I know what this sounds like because we all know that there’s data leaks and data breaches and and malware outbreaks all the time. But still, I think it’s better than ever before. You simply look at what where we were 10 years ago and where we are today. 10 years ago, users around the world were still getting infected simply by browsing the web and clicking on links, getting burned by Drive by

    00:06:47
    exploits which were exploiting their browsers through Flash and Java plugins. We don’t have that problem anymore. We are getting better and that will push the attackers to make more advanced attacks. So they are they are learning and they are becoming more advanced as we build better defenses. But is there a gap here in terms of law enforcement? Because every country that is a signary of the UN charter has signed up to collaborate and cooperate in terms of law enforcement and yet we have safe

    00:07:20
    harbors where a lot of these people operate from and often they’re state sponsored which is going a step even further. Um, how much more do we need to do in collaboration? The law enforcement side of thing, the biggest failure we have in cyber security is that we seem to be unable to catch most of the criminals, prosecute them and sentence them. I mean, if we would be more successful in putting more of these leaders of cyber crime gangs into jail, we would concretely show to potential newcomers into cyber crime that crime

    00:07:56
    doesn’t pay. not not even online crime. And this is where we are failing and and the biggest failure is Russia. I live in Finland. I live two hours away from from the border of of Russia. Russia is a safe harbor for many of the largest gangs in the world. And that’s because there is a war in Europe. These Russian ransomware gangs are not targeting local victims and local companies in Russia, not because they would be patriotic, but because they know that the Russian law enforcement doesn’t care what they do

    00:08:30
    against European or American targets. So they pretty much have a free reign to do these attacks. when there are the occasional arrests of of cyber criminals in Russia like we had earlier this year one of the leaders of lockpit was arrested in Khalinik mysteriously he was let go like three days later we don’t know how we don’t know why we just noticed that he was again streaming drunk online on his Twitter channel from his home and and and this is where the biggest problem is we don’t have global

    00:09:02
    law enforcement we don’t have global laws and then we have these countries which are not paying attention in actually catching and prosecuting these criminals. But you’ve talked about the offensive side of Russia. What about Russia’s defenses? Obviously the Ukrainians are are not beginners in this particular game. Um do you see a re enormous amount of tit for tats or is it very much oneway traffic? When we look at international statistics of cyber attacks, roughly 15% of all cyber attacks in the world are targeting

    00:09:34
    Ukraine. That’s how bad the situation is right now. Now, Ukraine is defending successfully majority of those attacks. And there’s a lot of talk about how we the West or we Europeans should be um helping Ukraine and offering our support and you know helping them out. And of course, we should. However, I think it’s a little bit more complicated than that. You see, in my opinion, the best country in the world in defending against governmental cyber attacks from Russia is Ukraine. They’ve been doing it for

    00:10:07
    more than a decade. So, it’s not just that we should be helping Ukraine. There’s a ton of things we should be learning from Ukraine because Ukraine is successfully defending themselves both in the real world, but also in the online world. A last question, a little bit closer to home from your home nation. Um, Finland now that it’s joined NATO, has that made Finland more of a target? Well, first of all, thanks for having us in NATO. We promise to do our part. Well, I’m I’m a former serving

    00:10:35
    officer and I would love to welcome you and we’re very grateful for your your you joining the the whole gang. Thank you. Thank you. And yes, um, when you look at the the obvious attacks like the denial of service attacks targeting critical infrastructure or visible targets like the website of the House of Parliament or or website of the Ministry of Defense, yes, we’ve seen an increased amount of attacks from these uh patriotic hacker groups operating from from Russia. That’s that’s a given. We

    00:11:04
    also see um more serious attacks targeting different entities in Finland, but I don’t think it’s really changing the the overall picture m much. If they’re trying to make us scared, they’re failing. We’re not scared. Well, thank you very much, Miko, for your time. I hope you have a productive time at the the security conference here today, and we look forward to hearing more from you in the future on TechTV. and um we’re very grateful as are all our viewers um in sort of the insightful

    00:11:36
    uh update that you’ve given us. Thank you very much indeed. Thank you very much and thanks for having me. Anything that you notice, Pete? Well, it’s funny that you mentioned Mo. I can remember back in 2007, I was up in the upstairs bar of a pub at the back of Olympia. They’ve been taken over this for the duration of infra, which was the sort of the nice thing that happened then. And yeah, this ponytail guy next to me looked at my phone and suddenly piped up with Prada. Prada Prada don’t make

    00:12:08
    phones cuz I’d got this old Prada phone on the bar. It was one It was a one-off that LG and Prada had collaborated on. It’s fairly limited sort of smartphone side of things to come. Uh but in terms of uh what was going on, I think that yeah, Mo may say that things are a bit more positive. I if you recall, we did that um interview with Gary Cox just before um Infosc and yeah, I think things are changing. You know, this the the old days of infos long gone. You know, take one of the announcements in the defense

    00:12:52
    review that we were going to have lots and lots of hackers that were going to be recruited by the government. Well, I mean, that’s something that we put to uh Julian at Bug Crowd, didn’t we, Julian? Here we are in London infosc. Uh there’s a certain change here at the moment, isn’t there? The the the atmosphere is not quite the same. It might be in the hall, but there’s a a bit of a feeling about what’s going on at the moment just because we’ve seen these drone attacks and we’ve seen this

    00:13:25
    increased hacking activity. What are your thoughts on this? Yeah, absolutely. I mean, I think um obviously the spending review is the strategic spending review has talked about increasing the spend in in cyber uh uh cyber warfare capability. And certainly one of the one of the things that we see from our client base that they’re often wanting to when we do red team type of attacks on them, they’re wanting to simulate nation state attackers because that’s becoming much more prevalent uh

    00:13:54
    in the uh you know in in in the world today that uh nation state attackers who are attacking commercial customers for uh espionage for you know North Korea for example are often um going after cash to fund their warfare. Um, and we’re certainly seeing that our customers are looking to sort of up their game from, you know, the the level of standard penetration testing to much more advanced technique, red team attacks um and and getting more advanced um hackers to to simulate those sorts of um those sorts of attacks that they’re

    00:14:32
    seeing in the wild. So that’s the underlying beat then is it that we seeing nation states because some people have said and this figure has been bandied around for a long time 80% of attacks come from nation states. Is that right? Uh I would I would expect so either nation states or nation state sponsored actors. So you a lot of the larger ransomware gangs um uh and AP groups will often be not officially um affiliated with a nation state, but they’ll certainly be um facilitated by nation states. I mean, it’s interesting,

    00:15:08
    isn’t it? Because one of the things that we’ve been told is that the cooperation between hackers is far better than the cooperation between the police forces. For example, it would appear as you’ve said that there are hacking groups that may be coming from, dare I say it, places like Russia, North Korea, China. Uh they’re not exactly going to collaborate with our police forces, are they? No, I can’t say that. Can’t see that happening. And certainly, I mean, some of the um hacking groups are are

    00:15:39
    truly global with members across multiple countries in every continent operating together as a as a single entity. you know, that kind of that kind of force can only be um met with an equal kind of force of um of group of of hackers. And that’s kind of where Bug Crowd really started its uh life 12 years ago is with the basic premise that the the defenders were outnumbered. So the only way to really help our our customers was to bring that um that that group that that crowd of ethical hackers uh to bear in

    00:16:18
    in this kind of scale that no commercial organization or even government organization would be able to achieve. You know with over half a million hackers that that work for Bug Crowd across our customer base. um you know, that’s the only way we’re going to kind of um combat the scale in the in the bad actor community. Well, let’s talk about that because the UK government in its uh defense review has suggested that it’s going to be keen on recruiting people to do, I suppose you could call it hacking.

    00:16:50
    Um they they want to give them initial salaries of £40,000, bonuses of £25,000 on top of that. Is that going to work? Is that is that I mean it might be useful to recruit juniors into the industry and you know potentially in in years to come with with good training budgets that that delivers something but the reality is the commercial sector is is already paying far more than that for elite uh red team uh hacker skills. uh and the ethical hacker community, some of the top hackers on the bug crowd platform

    00:17:23
    can earn that kind of money in a month, right, from from finding very specialist bugs that uh uh that their elite skills have enabled them to find. So, how do we go about stopping this? Because this magic figure 80% comes up again because apparently there’s an 80% shortfall in the defenders that we need. How are we going to plug that gap? Do we go out to bug crowd and say, “Hey, bring your people in. We we we we we will open the doors of of government to you.” Yeah. Well, absolutely. I mean, we’re already

    00:17:54
    seeing uh governments running vulner vulnerability disclosure programs which are essentially uh you know, the see something, say something uh approach to to bug hunting. Um you know, we ourselves have worked with the US federal government on a number of initiatives. you know, back in 2018, we did hack the Pentagon where we brought in um ethical hackers. So, this is absolutely the way I think they should they should be going um because again, it’s bringing that diversity um of talent. It brings um uh elite skills. It

    00:18:28
    brings the sort of people that might not really want to work in a military establishment, but might be very much up for the mission of helping defend the the nation. So, there’s going to be a need for a bit of an image change then. The civil servants and the soldiers have got to hang out with the kids. They’ve got to stop being so uh barky and authoritative. Yeah, I think that that would certainly probably help with some of our community for sure. One of the issues with this is going to

    00:18:56
    be the armed forces are already struggling with recruitment. Yeah. So, how are they going to make themselves more attractive? What can they do to actually can they make a impassioned plea to patriotism? Can they say, “Hey, come and come and help us.” Yeah. Man the barricades. I think, you know, there’s lots of lots of different things they can do, but ultimately, um, recruiting full-time hackers into their team is going to they’re going to struggle to reach the numbers they need

    00:19:25
    to by engaging in the crowdsource model where you can go to thousands, tens of thousands, hundreds of thousands potentially of ethical hackers. Give them a mission. the the you know these people are incentivized by um by money, yes, but they’re also incentivized by testing their skills, by uh solving really hard problems, by proving themselves. So, um that’s certainly how many of the the government uh vulnerability disclosure programs work is people are there because they want to hack NASA. They want to prove that they

    00:19:59
    can get a letter from NASA to say they they’ve hacked them rather than just um you know, just for cash. feeling we could do something like engaging computer games. One of the very interesting exercises that happened was a load of hackers hacked a computer games company and it said that they were going to wipe out all of their scores to zero and the computer games company went to all of the computer games people and said look this is what the hackers are going to and that engaged them. I mean do you

    00:20:31
    think that we should be doing things like that? Do you think that we should also be encouraging people when they’re at school? I mean, you know, kids love trying to be clever and smartasses about all of this. Yeah. Well, I I mean, a lot of um a lot of the hackers in our community actually come from gaming and they started in just that, you know, trying to uplevel themselves or get fake currency in the game and that’s where they learned some of their hacking skills. I mean, we have a we have a

    00:20:58
    challenge. We’ve had a challenge for for years in in recruiting into STEM, you know, STEM in school and and diversity in in STEM recruitment as well. And again, all of the all of these things come back to education and and school in that sense as well. Um, our community of hackers is global though and a lot of the a lot of the people we have may not have had a formal education. you know, they will use it as an opportunity to climb out of a poor um environment by um by learn teaching their own skills and

    00:21:30
    and um and they can sometimes again again again that diversity means that they’ve learned in a different way. They haven’t had the formal komsky education, gone to you know gone to Chelenham to to learn the next stage. They’ve they’ve learned it on the on, you know, on the a 3G modem on the the streets of some some poor village in Southeast Asia, you know. Um, and they have climbed out of of of that environment by being able to exercise these skills um in a in an ethical and financially valuable way to them. So,

    00:22:08
    oh, hack is always young. The stereotype is always of the little kid with a hoodie clicking away on his keyboard. Are there out there who are doing this? I’ve not met not met many oxygenarians, I’ll be honest. But they certainly come come in all ages, sizes, um, and yeah, I mean, many of the most elite elite people are in their 40s and 50s for sure now because they’ve been doing it for so long. And of course, you know, tenure and experience is is one of the really important things to to help um you know,

    00:22:41
    develop those elite skills. Well, maybe they should be passing their skills onto a younger generation. Yeah, absolutely. And I mean you certainly see that in some of the organizations we we um partner with like Hat the Box and Secure Code Warrior that are are helping um through training platforms of um uh of of the young and well of the young and any age, you know. And there and there’s also a lot a lot of organizations that are uh trying to train um ex-servicemen that have come out of the you know come

    00:23:14
    out of um traditional military service. um uh in these kind of skills as well and you know perhaps that’s somewhere that the the government should be focusing on as well. diversity. I mean, you mentioned diversity. Should we extend that diversity everywhere? I mean, it’s been said that people are on on the autistic spectrum are particularly good at this because of their ability to focus, to concentrate on problems. Is that an area that we should be looking at, too? Yeah, absolutely. And I think a lot of it is

    00:23:43
    about enabling work environments that suit individuals that are that are on the autistic spectrum or individuals that have ADHD. Um and traditional work environments particularly traditional military work environments don’t suit those uh type of people and and again with with with an organization like Bug Crowd we enable fully remote working. We enable people to not have cameras on if they don’t want to. So that’s just for our staff but for the the hackers that that work on our behalf on our customer

    00:24:14
    engagements. They’re able to you know work at whatever time of day or night they want. they um you know they don’t they’re rarely in an office. Um they you know they can wear whatever clothes they want to wear when they’re working. And these kind of um these kind of um enablements are what um will certainly help people that are on the spectrum be able to gain um you know really useful um employment but also for for us the defenders to be able to to gain really really useful skills and capability.

    00:24:48
    So a formal organization needs to become very informal is where you’re I would suggest that would help. Yeah. Yeah. I mean that’s a fascinating perspective from Julian. Um but overall I think uh it it appears and it’s really came home to me during the show that cyber security now has gone mainstream. uh and about time. Uh rather than simply having rows and rows of antivirus company as it was a a bit like in the past this year we saw stands from a number of regions that were seeking to

    00:25:24
    attract talent and investment everywhere from Bavaria or Virginia to Canada. If only someone had told uh Co-op and M&S that cyber security is now mainstream. Maybe they’d have invested more in protecting against the failures of that they experienced recently. Uh and maybe they put more effort into incident response. I I hear that weeks after the hack, M&S are still unable to take orders online. Anyway, hopefully all of this will be restored by next year’s Infoitech Europe. Although I fear that

    00:25:57
    the news agenda will be dominated by a host of other incidents long before that. It’s only a matter of time. Yeah, I mean it’s funny, isn’t it? I mean, at the top you mentioned uh the you know the the the the early days back in Olympia which there there was a nice feeling about it then about that sort of ghettoization. I mean you remember there was Dr. Alan Solomon sadly passed away about a year ago and there were all of those other sort of individuals that that sort of individuality seems to have

    00:26:31
    gone a bit. Yeah. I mean, the show’s celebrating its 30th anniversary and and obviously in that period, you’re bound to have seen a certain amount of change. Um, and and if you think back 30 years, uh, very few people in the general public would have been particularly aware of, uh, cyber security hackers or anything like that. And yet, it’s in the headlines all the time at the moment. Uh, it’s a sign of the times. Yeah. And in a sense, what what was also interesting again Yeah. All of those

    00:27:03
    cyber security companies didn’t seem to be there. That element of personalization army code wasn’t really there, was it? There there there were companies that we saw that had actually built a lot of that old antivirus stuff already into their offering. So you know there was that company Broadcom for example that seems to have absorbed semantic and carbon black which were those early days alongside VMware and a host of other stuff. It seems to be on a a permanent acquisition spree. Um, but I

    00:27:39
    I I enjoy seeing some of the characters and and I hope we don’t lose out on seeing some of the characters and hopefully uh my my interview with Mo and and yours and and some of the other uh meetings that we had at the show show that there’s still enough characters about to keep the sector interesting. Yeah, I thought one of the really interesting things that Bill was that this move towards a concentration on data and on some AI tools that were going to be uh picking up the movement of that data and trying to nail down

    00:28:10
    some of that data. What do you think? Yeah, I I I think that’s going to be a theme going forward. I think we’re going to see that throughout the rest of the year and beyond. Um, I I would invite people to um hopefully have a look at um the the interviews we’ve done here and elsewhere on the site. Uh comment on them um uh follow our channel and uh retweet as much as possible. We look forward to seeing you uh at the next chapter with um a lot more to come. Uh and Pete hopefully will be celebrating

    00:28:42
    um a few more cyber successes and uh hopefully seeing a few less casualties in the in the immediate future. Well, I think though, Bill, just pick up one last thing before we go. It is that there is this Gary Cox again from Infoblocks, he he mentioned it in the interview that we did, and that was that it looks as though companies are going to start taking cyber security seriously. It looks as though they’re going to be buying in services from companies that take that cyber security load off their heads and let them

    00:29:17
    concentrate on what they’re doing. Particularly because as a lot of commentators have been saying, we’re going to have an attack that starts on smaller companies. I I’ve heard uh the many announcements before and many predictions that oh, we’re all going to take cyber security seriously now. And I’ve I’ve heard that too many times in the past. Um I although there is one thing on the immediate horizon which I will be covering on this channel um I should sure a number of times. Um the

    00:29:47
    government is about to introduce its cyber security and and business resilience bill and and I think that is going to make a change. It’s going to put people on the metal. It’s going to have a new regulator. They’re going to be uh new expectations and and I hope to see more detail on that when the government publishes it. So hopefully that could be a catalyst for the sort of change that people have been predicting for a long time. Yep. That and so insurance. Hopefully we we can live in hope.

    00:30:16
    Anyway, thank you everyone. I hope you’ve enjoyed our coverage of Info Security Europe. We look forward to seeing you again soon. There we go. What did you think? [Music] [Music]

    Category: Uncategorized
    Next Post
    AI and anthropomorphisation

    AI and anthropomorphisation

    Recommended videos

    TMFdigital – Talking with Rick Mallon, Head of Product Line BSS Catalog & Order Care at Ericsson

    39 Views
    April 5, 2024

      Penny Gralewski, Commvault Solutions Marketing Head, on Commvault Cloud Servey 2019

      22 Views
      April 14, 2024

        Susan Dean, Director of Business Technology – Takeuchi ( #QlikWorld2023 )

        31 Views
        April 14, 2024

          Discussion with Hemant Malik, Head of Product Line Transport, Ericsson Networks

          35 Views
          April 14, 2024
            Show More
            vidnion.com

            © Sociaall Inc.

            Navigate Site

            • Home
            • Privacy Policy
            • Contact Us

            Follow Us

            Welcome Back!

            Login to your account below

            Forgotten Password?

            Retrieve your password

            Please enter your username or email address to reset your password.

            Log In

            Add New Playlist

            No Result
            View All Result
            • Home
            • AI
            • Automation
            • Cloud Computing
            • Cyber Security
            • Data
            • Digital Enterprise
            • Infrastructure
            • Mainframe
            • Supply Chain
            • Telco & Mobile
            • Privacy Policy
            • Contact Us

            © Sociaall Inc.