6 Predictions About Cybersecurity Challenges In 2024

Share

Forbes – My predictions with Senior Contributor Edward Segal 

Leveraging AI Tools

Emerging threats “where monitoring for and detecting cyber threats will increasingly become a ‘fool’s errand’ where it will be impossible to distinguish between what good and bad looks like,” Peter M. Tran, the head of global cyber infrastructure and product security solutions at InferSight, said via email.

“This is a direct result of the commercial use of AI tools across most all major business operating functions to gain efficiencies while at the same time, cyber attackers are leveraging the same AI tools to generate attack techniques and tactics that can ‘deep fake’ current cybersecurity defenses,” he pointed out.

Want more details? Read the full article >> here << 



Facebook and Twitter Are Charging for Added Security.

Share

TIME MAGAZINE [By Mariah Espada w/ Peter Tran] – Social media platforms have battled bots, spam, hacks and impersonation for many years. Now, Meta and Twitter have come up with a new approach to tackling the problem: passing the cost of better security on to users.

Meta announced on Feb. 19 it would be launching Meta Verified, a subscription service that offers additional verification, security and customer service features, for the price of $11.99 a month on the web and $14.99 on iOS. It is currently being tested in Australia and New Zealand. The process: users can sign up for the service, provide their government ID for screening and then if approved, they will get a blue badge and Meta will proactively monitor against fake accounts and provide direct customer support.

“This new feature is about increasing authenticity and security across our services,” wrote Meta CEO Mark Zuckerbeg in an announcement on his Facebook page. It’s quite similar to Elon Musk’s Twitter Blue service that recently relaunched, which offers perks like a blue verified check mark (a once free feature reserved for the notable and famous) and the ability to edit your tweets, for $11 a month. It’s not just a blue check mark that users are paying for, but also a security feature that has become standard for various online accounts: from late March, non-Blue users will no longer have access to Twitter’s two-factor authentication via text message system. (If you don’t disable the feature, you may be logged out of your account after March 20).

These services seem to be targeting content creators, with a growing following, who may want the extra security. But the average user is still vulnerable to hacking and impersonation. Nearly one-fifth of U.S. teens and adults experienced their social media accounts getting hacked within the first three months of 2022, according to a survey conducted by Deloitte. Half of the respondents said they were concerned about online security breaches.

For more details on how this may impact you and to read my exclusive comments click here

 



(BOOK REVIEW) The Hacker and the State: Cyber Attacks and the New Normal of Geopolitics

Share

BOOK REVIEW: The Hacker and the State: Cyber Attacks and the New Normal of Geopolitics
Author: Ben Buchanan

Reviewed by Peter Tran for The Cipher Brief

In the midst of the coronavirus global pandemic, I can’t help but draw parallels to the cyber
world in that the enemy is invisible, adaptable, pervasive and capable of shaping multiple
dimensions of domestic and international geopolitics. This is exactly what Ben Buchanan
accomplishes in somewhat of a Hitchcock-esque “Rear Window” style of putting the reader in a
front row seat to watch exactly how select nation states use their own home brew cyber hacking
techniques and tactics or what Buchanan calls “Statecraft” to disrupt, manipulate and arguably
change the course of our daily lives.

Although the book takes a scholarly approach in its research and fact finding, I did get a strong
sense this was more than just another cyber conspiracy story rooted in age-old cloak and dagger
politics. Buchanan takes the reader through an extremely relevant, well-articulated and qualified
view of the new realities of where the real battlefield exists in the next frontier of information
technology platforms and how those platforms extend geopolitically to everyday people from
Madison Avenue to Main Street.


What I found intriguing was Buchanan’s approach to espionage and disruption attacks within the
context of hacking with an original view of how the private sector big tech firms such as AT&T,
Google, Facebook, Apple and others hold a considerable burden on their shoulders within the
geopolitical foreign counter intelligence tug-of-war. This makes the reader really think about
whether the enemy of your enemy is really your friend. This made me question who is really
spying on what the book calls, “the backbone of the internet.”


The author then takes a sharp right-hand turn to provide a chilling view of what feels like state
sponsored cyber “street justice” reminiscent of hit men and snipers but with a twist, as the book
brings the reader through a vast and complex world called the Advanced Persistent Threat (APT)
with shadowy state-sponsored hacker subgroups with names such as BYZANTINE HADES,
BIZANTINE CANDOR and hacking the hackers through tailored access operations (TAO)
somewhere in and around Ft. Meade, Maryland. For me, this was an up close and personal replay
back to my days with the former U.S. Department of Defense Joint Task Force Global Network
Operations now the U.S. Cyber Command based out of the NSA. Buchanan does a brilliant job
making this transition to taking the reader as close to the front lines as possible short of being
right on the hacker’s lap and keyboard somewhere in mainland China or North Korea.
In an impacting moment in the book, Buchanan quotes former Director of the NSA, General
Keith Alexander, saying “Iran was an unpredictable adversary because it did not calculate in its
hacking operations but rather ‘will act emotionally’.” This took me even closer to feeling the
adversary’s moves as it brought in the human element rather than treating it like zeros and ones
floating out in cyber space.


The Hacker and The State is direct, no nonsense and strikes to the core of the state-sponsored
hacker’s industrial complex while balancing thought provoking sub themes and challenging
current and future geopolitical integrity, intent and global data privacy expectations. Buchanan
leaves the reader well anchored in qualified facts, true to life use cases and animated experiences
with thought provoking glimpses for the reader to formulate his/her own correlations and
conclusions.

This book earns a prestigious 3.5 out of four trench coats.

Go to the Cipher Brief online to subscribe to get more great reviews and content.

 



The Secret CSO – IDG Connect Interview

Share

IDG Connect Interview with Peter Tran

What was your first job? My first real job as a young adult was as a pathology technician performing autopsy procedures as part of a Harvard Medical School teaching hospital.

How did you get involved in cybersecurity? I became interested in cybersecurity when I was a graduate student in forensic sciences at the George Washington University. I was beginning to see that crime scene trace evidence was going digital and more and more crimes were occurring over computers and networks.

What was your education? Do you hold any certifications? What are they? I hold an undergraduate degree with an emphasis on criminalistics from the University of California Santa Barbara, a Master of Forensic Sciences from the George Washington University and post graduate executive education from MIT in blockchain security/cryptocurrency and the Harvard Kennedy School of Government cyber security technology and policy. I hold the ISC2 CISSP as well as the SANS Global Reverse Engineering Malware (GREM) certifications as well as advanced training from the Department of Defense (DoD), Federal Law Enforcement Training Center (FLETC) and the Federal Bureau of Investigations (FBI) Cyber Training Academy.

Explain your career path. Did you take any detours? If so, discuss. Career growth never happens if you don’t pivot and take detours along the way. I take detours almost every day. That’s how dynamic the cyber security field is no matter what level you are. You learn to wrap your arms around it and learn, adapt, assess, and execute…. everyday!

Was there anyone who has inspired or mentored you in your career? 100% my wife.

What do you feel is the most important aspect of your job? Coaching and Mentorship.

What metrics or KPIs do you use to measure security effectiveness? – Mean time to disrupt, detect, respond, contain and remediate. Command and control disruption KPIs are critical as I characterise them as “pre-weaponized” detection and disruption to determine cyberattack surface volatility index metrics (CASVI).

Is the security skills shortage affecting your organisation? What roles or skills are you finding the most difficult to fill? The security skills shortage is not only affecting my organisation, but it is affecting every industry globally. The highest skill demands are changing to more data science and advanced analytics knowledge and experience.

Cybersecurity is constantly changing – how do you keep learning? I keep learning by looking beyond the obvious security threats and question the quiet times when it may seem the cyber threat actors may be under control.   

What conferences are on your must-attend list? The consumer electronics show. This will give you a better sense of the current and new attack surfaces.

What is the best current trend in cybersecurity? The worst? The best is AI and Machine Learning and the worst trend is SIEM.

What’s the best career advice you ever received? Sometimes stopping to camp is ok when you are trying to climb the mountains of your career as growth occurs in all directions.

What advice would you give to aspiring security leaders? Empower your teams to use their imagination beyond what the tools are capable of.

What has been your greatest career achievement? Starting my own family.

Looking back with 20:20 hindsight, what would you have done differently? I would have become a professional cyclist in Europe.

What is your favourite quote? Dreams Don’t Have Deadlines (DDHD).

What are you reading now? my fortune from as many fortune cookies I can get my hands on….

In my spare time, I like to… build Lego exotic sport cars…..

Most people don’t know that I… used to be a break dancer in a fashion show when I was 13 years old….

Ask me to do anything but… pick up a snake…..



Exclusive Book Review – “Dawn of The Code War”

Share

THE CIPHER BRIEF BOOK REVIEW: Dawn of The Code War: Americas Battle Against Russia, China, and the Rising Global Cyber Threat

By: John P. Carlin with Garrett M. Graff, Public Affairs, New York, 2018

Reviewed by Peter M. Tran

In 1789, Benjamin Franklin wrote in a letter that “Our new Constitution is now established, and has an appearance that promises permanency; but in this world nothing can be said to be certain, except death and taxes.” Fast forward 229 years to 2018, and my contention would be in our current transformed cyber world, nothing is certain now except death, taxes and cyber-threats. This is exactly what John P. Carlin and Garrett M. Graff convey in an authentic, technical and true-to-life book. Dawn of the Code War takes us through what, at first glance, would appear to be yet another fictional cold war spy thriller, but don’t judge this book by its cover.

Carlin and Graff give Richard A. Clarke’s “Cyber War – The Next Threat to National Security and What to Do About It” a run for its money, with a superb view into how “freaks and geeks” became this next century’s invisible enemy through the weaponization of the Internet. The book squarely makes the case that “cybersecurity isn’t a wonky IT issue,” as Carlin puts it, and provides the details of some of the most impactful nation state cyber-attacks of the last

decade. The book describes how the resulting federal law enforcement and intelligence community investigations from the attacks on the Pentagon, Office of Personnel Management (OPM), Sony and Equifax have created the cyber industrial complex. We are taken through the hacker, “Do It Yourself” (DIY) culture where the proliferation of off-the-shelf dark market tools makes you wonder if there will soon be a hacking aisle at your local Home Depot.

What Carlin and Graff uniquely take us through, is how code has become king in new conventional war-fighting. Crime has taken a back seat to net-centric warfare, cyber terrorism, and geopolitical and economic trade craft through social media manipulation (#fakenews), where the adversary can hide in plain sight with each attack. From al-Qaeda to ISIL, China, Ukraine and the Syrian Electronic Army, the modern cyber adversarial lines start to blur as the book pivots and explains how not all hackers are created equal, and how Silicon Valley-born technological innovations may be used against us, as nation state hackers master data analytics, artificial intelligence and machine learning to counter our own detection methods.

The book marks what Carlin and Graff call the “end of innocence” for information technology as we know it and uses the circa 2000 “I Love You” virus as a perfect example to illustrate that term. Through this end of innocence, we are given the vantage point of seeing the code war evolve through the eyes of the FBI and CIA cyber operational and intelligence functions. The investigative tactics, and the various nation state cat and mouse games which ensued, continued to frustrate prosecutors and politicians alike, with one of the most notorious series of cyber incidents involving Google, and other heavy hitting names, under code name Operation Aurora.

Advanced and persistent, Carlin and Graff take us through how the playing field is never equal, in part because nation states such as China and Russia don’t play by the same rules of engagement. The rise of the term “Advanced Persistent Threat” (APT) begins to mean more than characterizing attack sets, and as we read on, each chapter sheds deeper insight into the techniques, tools and procedures (TTPs) used by our opponents. The style, flare and arrogance of hackers such as the “Comment Crew”, “Ugly Gorilla”, “Black Vine” tell us much about our adversaries.

The book progresses like a linear accelerator raising a reasonable doubt about whether an equal attack surface the United States can play on, even exists. It becomes more evident to the reader that every public and commercial enterprise is a data-driven business, and the interdependencies between governments and the private sector globally, feeds a code war. Carlin and Graff leave us with a better understanding of where we are now, the hard lessons learned, and what our nation and the world needs to firmly grasp in order to address the known unknowns needed to defend against, and win, the code war.

Dawn of the Code War earns The Cipher Brief three out of four trench coats. 

 

 



What’s The Future of Your Online Identity, Authorization, Authentication and Access Controls?

Share

WTOP Federal News RadioToday’s cyber security threat landscape has completely changed from the years where a Common Access Card (CAC) or Personal Identity Verification (PIV) card could provide reasonable security. For example, in 2015 the United States Central Command Twitter account was hacked. The Department of Defense has limited ways to secure this resource well beyond any kind of current identity controls.

Besides out-of-network networks, another concern is the multitude of devices that were never even conceived when CAC and PIV standards were written. Today we have smart phones, tablets, even a plethora of sensors from the Internet of Things. We must consider other options for identity that go beyond CAC and PIV.

In the midst of recent news surrounding Russian hacking, global ransomware attacks and data leaks, I  joined WTOP Federal News Radio in Washington, DC for a multi part special segment to talk “Federal Identity Governance”, insider threats and much more to address these issues.

Want to hear more? Tune-in to the first segment by clicking here.

 

 



MIT Technology Reivew – Smart Cities Could Be Crippled by Dumb Security

Share

On April 7, residents of Dallas, Texas struggled to get sleep as 156 of the city’s hurricane warning system sirens sounded all in one shot and it didn’t stop at that….triggering another 15 times. Prior to this incident, I wrote a Smart City security Q/A op-ed for IT Pro Portal on what would keep a city leader up at night and this was certainly one of them as the New York Times reported the hurricane emergency warning system was hacked!  Connected living and Smart Cities are here and security concerns are building up faster than we can find solutions. As the MIT Technology Review outlines, “Researchers have been finding vulnerabilities in connected city hardware, from traffic signals to smart meters, for several years now. The concern is that as such infrastructure proliferates, with devices increasingly connected by the Internet of things, hackers will identify more flaws and and use them to plunge whole cities into chaos.”

Do you think you live in a connected or Smart City? Worried about your connected living security? Read more of my comments as I weigh in with Jamie Condliffe and the MIT Technology Review.



Preparing for Australia’s data breach notification legislation

Share

Breach NotificationAustralia’s Privacy Amendment (Notifiable Data Breaches) Act 2017 marks a milestone for information security legislation, but industry is still questioning the need for legal intervention.

Australia is not the first country to introduce strict breach notification laws, nor is it likely to be the last. To date, approximately 90 countries have introduced legislation or have existing laws for breach notification with varying degrees of strictness, enforcement and penalties. And yet data breaches still go undetected and unreported. The United States has approximately 47 states with separate breach notification laws and has yet to introduce a consolidated and unified law at the national level.

It’s not a matter of strictness, breadth or depth that makes digital privacy and breach notification laws effective. In fact, the only way the effectiveness of breach notification and data privacy laws is measured is anchored on whether the legislation helped prevent breaches from happening in the first place. Measuring effectiveness of legislation is a “fuzzy science” at best…….[read my complete article featured in ComputerWorld].

 



Is the U.S. in a cyberwar now?

Share

Kim Komando ShowRecently I sat down with the Kim Komando Show to talk all things cyberwar and Russian hacking. As we engaged in our discussion we concluded its likely the United States is under cyber attack right now and no one knows exactly where some of the attacks are coming from. Take a listen to this Komando on Demand podcast as I weigh in with Kim Komando and Peter W. Singer for proof of these attacks and how they could lead to a much bigger war in the near future.

Listen to the podcast free via iTunes or on YouTube

 



Super Bowl “Digital Deflategate” Is Not Just Air

Share

When we think of large entertainment venues and events, it’s not just ticket fees and concessions anymore. Sporting is entertainment and this year’s Super Bowl LI (51) is one of the most complex, technologically orchestrated events in the world; ranging from tablet-based play books to RFID wearable sensors on players sending real time performance data and analytics to coaches and mobile apps. Supply chain attacks can affect virtually any industry that relies on complex IT and infrastructures, as well as data delivery networks. While we typically think of large retailers, this weekend’s NFL event stands to be one of the most high-value targets for cyber criminals and other sophisticated attackers intent on mass disruption, manipulation and/or destruction. The number of third-party vendors involved in supporting the “game of all games” is comprised of one of the most complex interlocked networks imaginable. It’s “mind bending” to think of the network of suppliers, each introducing unique vulnerabilities and cyber security issues into the overall infrastructure, resulting in “breach exposure windows” during a very compressed period of time when sponsors, vendors, broadcast networks and advertisers have hundreds of millions at stake.

Just days away from Super Bowl LI, I talked with Dan Stoller of Bloomberg BNA on the possibility that we may be seeing a “national digital deflategate debate” if a major Super Bowl cyberattack were to happen. Let’s face it, data has changed athletics and sporting to a point where game play is based on bioinformatics, data science and using technology to increase marginal gains for competitive advantage. It shouldn’t be the case that the amount of air in a ball is scrutinized and debated, but it has become a material breach in proprietary competitive data and intellectual property lending an unfair advantage to teams in one of the only sporting entertainment events that owns its own day of the week. Read more as I weigh in with Bloomberg BNA.



« Older Entries