Just sat down with StateScoop’s Jake Williams and the State of California’s Chief Information Security Officer Peter Liebert to discuss all things ransomware. Take a listen to a preview of this edition of StateScoop’s Virtual Roundtable series as I discuss emerging threats and what it means for state and local governments across the country.
You can listen to the full virtual roundtable via SoundCloud here.
Recently I sat down with DubaiEye Radio 103.8FM to talk all things IoT and Smart Cities cyber security. One area of particular interest were “rogue drones” and the recent havoc at airports causing massive flight and safety disruptions. The adoption of smart city/connected living technology across the United Arab Emirates (UAE) is the answer to ‘rogue drones’ causing havoc at local airports, that being the ability to monitor and detect the billions of IoT connected devices to include internet enabled drones.
Click below to listen to the interview and hear my thoughts on IoT, connected living and drones.
Your refrigerator might have helped bring down the internet last Friday.
As many users noticed, shortly before last weekend a massive cyber-attack disrupted service to major websites ranging from the New York Times to PayPal and many more. The attack took place in three stages, all targeted at the Domain Name Services (DNS) company Dyn, Inc.
Dyn’s business, domain name services, is often referred to as the roadmap of the internet. It’s what translates URLs like TheStreet.com into the 12-digit IP address at which websites reside. This isn’t because IP addresses are secret (at time of writing, for example, this website’s address was 107.23.89.155). They’re simply tough for human beings to remember…..read the full article here with my comments as I weigh in with TheStreet author Eric Reed .
Imagine that you are driving through downtown New York City (NYC) and only relying on your GPS for directions. All of a sudden, the GPS stops working and you are stuck in mid-town Manhattan traffic during rush hour. If you have ever tried to drive in NYC, you know it’s easier to navigate a corn maze blindfolded than to attempt to navigate the complicated NYC streets.
A Domain Name System (DNS) is much like a GPS, in that DNS gets you from point A to point B online. While a GPS allows you to look up any destination in the world and find a path to that destination, DNS is your map, navigator, and transportation all rolled up in one, specifically for the internet. Behind every domain name is an intimidating looking series of numbers called an internet protocol (IP) address (Example: 172.217.0.XX) and it gets much worse with next generation addresses which may look something like (2606:2800:220:6d:26bf:1447:1097:XXX). The bottom line is it’s much easier to remember a name (i.e. – Google dot com) rather than commit to memory a series of random numbers for every destination on the internet. DNS is the foundation that translates the domain name you type into your browser to the correct IP address and routes your request to the right place in real time. It just works, but when it doesn’t, it becomes one of the most disruptive roadblocks for the web.
On October 21st, 2016, various media outlets reported multiple waves of Distributed Denial of Service (DDoS) attacks that targeted New Hampshire based-DNS provider Dyn, which led to the disruption of the company’s ability to provide its subscribers with DNS services – resulting in massive issues for 17 of the top 100 most visited sites such as Twitter, Github, Reddit, AirBnB, Spotify, Soundcloud, Netflix and PayPal…..read more here.
Recently RSA Security’s Chief Marketing Officer (CMO) Holly Rollo and I sat down and put our brains together to flush out the absolute necessities of what needs to be in place when the unthinkable happens to a company and/or government organization….that being….you don’t have a data breach communication and response plan when a cyber breach happens.
Below is a highlight of what Holly and I had to say in a recent Harvard Business Reviewfeature titled “Your Company Needs a Communication Plan for Data Breaches”…..
In an instant, any business can find itself in the frightening position of watching the brand you’ve worked so hard to build being taken to its knees by a cyber breach. Few things are more damaging to a brand’s reputation than a hack in the headlines, and in the event of a public security incident, it’s highly likely that the Chief Marketing Officer (CMO) and the Chief Security Officer (CSO) will be the first people the CEO looks to and says “What do we do now?”
When a data breach happens, there is nothing worse than trying to figure out how to manage the crisis on the fly as it is still happening. That’s why every strategic marketing plan, and every company’s overall security strategy, should incorporate a data breach communication plan.
Even a rumor of a breach can trigger a communications crisis. Here’s a generalized scenario similar to cases we’ve experienced: A hot new mobile technology company lands one of the most successful IPOs of the year. A hacker going by the name of ‘Tumbleweed’ enters a forum and brags that the device can be hacked. Other hackers begin to post on different forums, and a newspaper picks it up. A news cycle begins. Senior engineers in the company respond to the forums by denying the hacking claims. Hacker forums go crazy and issue a “bug bounty” to try to compromise the device, with some claiming success………
Read the complete Harvard Business Review feature here….
Given the increased complexities and sophistication of cyber adversaries today, the demand for skilled IT security practitioners has outweighed the supply — particularly those skilled in security operations, intelligence, data analytics and forensic analysis. Drawing parallels to healthcare, increases in medical device, imaging, research/development and clinical care has involved much the same way. These advances in technologies have given us the ability to detect faster, “diagnose” and prevent. The outgrowth has created a broad shortage of practitioners with both the clinical/tactical skills and the operational experience necessary within today’s evolving threat landscape. So what does a Cyber Doctor look like and what are we doing to educate and train the next generation of “security care givers”?
In my last post, I discussed a common syndrome experienced by many organizations called “SOC Enterprise Amnesia” whereby the most valuable data (intelligence) gleaned from events/incidents is flushed and forgotten as operational fatigue sets in while the volume of security control and instrumentation data continues to overwhelms the operators field of view. The outgrowth of this state is called “Operational or Organizational Thrashing”.
In recent blog posts I discussed the concept of Switch Targeting and the fundamentals of how adversaries use seemingly trusted hop points as vectors in and out of primary targets. I also introduced the concept of R3 or (Readiness – Response – Resiliency) based on my experience in the field helping organizations position themselves to detect where these switch targets may be based on attack infrastructure intelligence.
In Part I of my post on Switch Targeting, I discussed the fundamentals of how adversaries use seemingly trusted hop points as vectors in and out of primary targets similar to how bank robbers target, stage and execute their robberies. Now I want to introduce the concept of the three “R’s” or R3 based on my experience in the field helping organizations position themselves to detect where these switch targets may be relative to their own attack infrastructure as part of designing a Next Generation Security Operations Center (SOC). R3 is comprised of three focal areas for the Chief Information Security Officer (CISO) to consider —- Readiness, Response and Resiliency.
Conventional computer network defense (CND) concepts in the past 10 + years introduced practices such as adversary “beach head, pivot point, lateral traversal, command/control” analysis for passive cyber defense. If I don’t see it on my network, then I must not be a target and/or my business is of no interest to advanced threats actors, right? The correct answer is in asking yourself as a business, “why me?”