Home Podcasts Videos Guest Posts Q&A My Take Bio Contact
 

Top Stories

 

MY TAKE: Michigan’s cybersecurity readiness initiatives provide roadmap others should follow

By Byron V. Acohido

Michigan is known as the Wolverine State in deference to the ornery quadruped that roams its wild country.

However, after a recent visit to Detroit, Ann Arbor and Grand Rapids as a guest of the Michigan Economic Development Corp., or MEDC, I’m prepared to rechristen Michigan the Cybersecurity Best Practices State.

Related: Michigan moves to close the cybersecurity skills gap. 

This new nickname may not roll off the tongue. But it does fit like a glove. (Michigan’s other nickname, by the way, is the Mitten State, referring to the shape of the larger of its two main peninsulas.)

Cobo Center

I was recently privileged to be part of a group of journalists covering the 2018 North American International Cyber Summit at Detroit’s Cobo Convention Center. My reporting trip included meetings with Michigan-based cybersecurity vendors pursuing leading-edge innovations, as well as a tour of a number of thriving public-private cybersecurity incubator and training programs.

It was the latter that jumped out at me. In an age when cybersecurity intelligence sharing and collaboration is in dire need — but all too short supply —  Michigan has quietly and methodically, stood up some well-thought-out programs that could – if not should – be a model for other states to follow.

I had the chance to meet briefly with two-term Gov. Rick Snyder, who is about to leave office and can point to significant strides Michigan has made ‘reinventing’ its economy under his watch. What’s noteworthy, from my perspective, is that Snyder had the foresight to make cybersecurity readiness a key component of his reinvent Michigan strategy, from day one.

Getting proactive

Snyder says his experience as head of Gateway Computers and as an investor in tech security startups, prior to entering politics, gave him an awareness of why putting Michigan ahead of the curve, dealing with cyber threats, would be vital. …more

GUEST ESSAY: California pioneers privacy law at state level; VA, VT, CO, NJ take steps to follow

By Matt Dumiak

Privacy regulations and legislation are topics that continue to be of concern for consumers and businesses alike.  News of data breaches, data vulnerabilities and compromised private information is released almost daily from businesses both small and large.

Related: Europe’s GDPR ushers in new privacy era

Legislation has recently been proposed for individual states, addressing data privacy regulations head-on.  Several states including Virginia, Vermont, Colorado, and New Jersey have all introduced related privacy regulations recently. California recently set themselves apart in the privacy space with the adoption of the California Consumer Privacy Act (CCPA), which gave citizens the rights to not only protect their own data, but to obligate businesses to disclose exactly which information has been collected about them.…more

GUEST ESSAY: The privacy implications of facial recognition systems rising to the fore

By Lance Cottrell

Tech advances are accelerating the use of facial recognition as a reliable and ubiquitous mass surveillance tool, privacy advocates warn.

A  string of advances in biometric authentication systems has brought facial recognition systems, in particular, to the brink of wide commercial use.

Related: Drivers behind facial recognition boom

Adoption of facial recognition technology is fast gaining momentum, with law enforcement and security use cases leading the way. Assuming privacy concerns get addressed, much wider consumer uses are envisioned in areas such as marketing, retailing and health services.

According to Allied Market Research, the facial recognition systems market is in the midst of rising at a compounded annual growth rate of 21% between 2016 to 2022. The research firm projects that the facial recognition market will climb to $9.6 billion by 2022.

Pieces in place

Ntrepid is focused on the privacy ramifications associated with these developments. As privacy concerns get addressed, facial recognition technologies are expect to emerge as a consumer favorite, when compared to other biometric authentication systems, such as voice, skin texture, iris and fingerprint systems.

This trend is rapidly unfolding because all of the required pieces are finally in place. Cameras have become cheap and ubiquitous. …more

New DigiCert poll shows companies taking monetary hits due to IoT-related security missteps

By Byron V. Acohido

Even as enterprises across the globe hustle to get their Internet of Things business models up and running, there is a sense of  foreboding about a rising wave of IoT-related security exposures. And, in fact, IoT-related security incidents have already begun taking a toll at ill-prepared companies.

Related: How to hire an IoT botnet — for $20

That’s the upshot of an extensive survey commissioned by global TLS, PKI and IoT security solutions leader DigiCert. The 2018 State of IoT Security study took a poll of 700 organizations in the US, UK, Germany, France and Japan and found IoT is well on its way to be to be woven into all facets of daily business operations. Meanwhile, IoT-related security incidents have already started to wreak havoc, according to study findings released today.

Among companies surveyed that are struggling the most with IoT security, 25 percent reported IoT security-related losses of at least $34 million in the last two years. Losses include lost productivity, compliance penalties, lost reputation and stock price declines.

Carried out by ReRez Research, DigiCert’s poll queried senior officials at organizations in the fields of healthcare, industrial manufacturing, consumer products and transportation ranging in size from 999 to 10,000 employees. Some 83% of respondents indicated IoT is extremely important to their organization, while some 92% indicated IoT will be vital within two years.

Respondents cited operational efficiency, customer experience, revenue and business agility as their top IoT objectives; currently two-thirds are engaged with IoT, although only a third have completed implementing their IoT strategy.

“Enterprises today fully grasp the reality that the Internet of Things is upon us and will continue to revolutionize the way we live, work and recreate,” said Mike Nelson, vice president of IoT Security at DigiCert. “The companies with a good handle on things have discovered how to leverage robust authentication and encryption regimes to help maintain the integrity of their IoT systems.”

Tiered performances

What I found to be particularly instructive about this survey is that it sheds light on how IoT-related security incidents are playing out in the real world. A series of detailed questions were designed to parse differences between companies handling IoT well versus those struggling with IoT implementation.

Survey results were then divided into tiers; the top tier companies reported the least problems with IoT security issues, while the bottom tier organizations were much more likely to report difficulties mastering specific aspects of IoT security. …more

NEW TECH: Cequence Security launches platform to shield apps, APIs from malicious botnets

By Byron V. Acohido

Cyber criminals are deploying the very latest in automated weaponry, namely botnets, to financially plunder corporate networks.

The attackers have a vast, pliable attack surface to bombard: essentially all of the externally-facing web apps, mobile apps and API services that organizations are increasingly embracing, in order to stay in step with digital transformation.

Related: The ‘Golden Age’ of cyber espionage is upon us

The nonstop intensity of these attacks is vividly illustrated by the fact that malicious bot communications now account for one-third of total Internet traffic. Cybersecurity vendors, of course, have been responding. Established web application firewall  (WAF) suppliers like Imperva, F5 and Akamai are hustling to strengthen their respective platforms. And innovation is percolating among newer entrants, like PerimeterX, Shape Security and Signal Sciences.

This week a new entrant in this field, Cequence Security, formally launched what it describes as a “game-changing” application security platform. I had the chance to sit down with CEO Larry Link to discuss what Cequence is up to, and why it believes it can help enterprises detect and mitigate bot attacks, without unduly disrupting the speed and flexibility they’d like to extract from digital-centric operations. Here are takeaways from our discussion:

The botnet problem

According to Gemalto’s Breach Level Index, 3.3 billion data records were compromised worldwide in the first half of 2018 – a 72 percent rise in the number of lost, stolen or compromised records reported in the first six months of 2017. Vulnerable online apps and services factored in as a primary target of automated botnet attacks. This activity can be seen at any moment of any day by examining the volume of malicious botnet traffic moving across the Internet.

A bot is a computing nodule with a small bit of coding that causes it to obey instructions from a command and control server. …more

Q&A: How certifying in-house IT staffers as cyber analysts, pen testers can boost SMB security

By Byron V. Acohido

A security-first mindset is beginning to seep into the ground floor of the IT departments of small and mid-sized companies across the land.

Senior executives at these SMBs are finally acknowledging that a check-box approach to security isn’t enough, and that instilling a security mindset pervasively throughout their IT departments has become the ground stakes.

Related: The ‘gamification’ of cybersecurity  training

Ransomware, business email compromises and direct ACH system hacks continue to morph and intensify. The exposure faced by SMBs is profound. Cyber intruders skilled at taking the quickest route to digitally exfiltrating the largest amount of cash prey on the weak. No small organization can afford to be lackadaisical.

More and more SMBs have begun dispatching their line IT staff to undergo training and get tested in order to earn basic cybersecurity certifications issued by the Computing Technology Industry Association, aka CompTIA, the non-profit trade association that empowers people to build successful tech careers.

Many companies are taking it a step further, selecting certain techies to also receive advanced training and pursue specialty CompTIA certifications in disciplines such as ethical hacking and penetration testing. Last Watchdog recently sat down with James Stanger, CompTIA’s Chief Technology Evangelist, to discuss how and why SMBs have finally come to see the light. Below are excerpts of our discussion edited for clarity and length:

LW: What are the drivers behind SMBs finally ‘getting’ security?

Stanger: It’s two things. First, companies are more reliant on digital systems than ever before. Frankly, a lot of companies got away with using analogue processes for years, and now they’re finally having to adopt the cloud and the Internet of Things. Secondly, businesses with 10 to 250 people generally have felt for a long time that they weren’t big enough to attack. That’s just not the case anymore. …more

GUEST ESSAY: Did you know these 5 types of digital services are getting rich off your private data?

By Greg Sparrow

Now more than ever before, “big data” is a term that is widely used by businesses and consumers alike.  Consumers have begun to better understand how their data is being used, but many fail to realize the hidden privacy pitfalls in every day technology.

Related: Europe tightens privacy rules

From smart phones, to smart TVs, location services, and speech capabilities, often times user data is stored without your knowledge. Here are some of the most common yet hidden privacy dangers facing consumers today.

•Geo-Location- Geo-Location can be convenient, especially when you’re lost or need GPS services. However, many fail to realize that any information surrounding your location is stored and archived, and then often times sold to a third party who wants to use that information for a wide variety of reasons.

For example, are you aware that data is routine collected while you shop? A variety of stores will purchase location information to determine how long a customer browsed in a particular aisle, so that they can further market to those customers in the future- promoting similar products.  The information may seem harmless, but would you feel that same way if you saw a physical person following you around collecting the same information?

•Social Media- Facebook, Google, Twitter,and Instagram are all social media services that are provided to individuals for “free,” but have you ever wondered what the real cost might be? The hidden cost for utilizing these social media sites is the forfeit of personal information for the social media sites to sell and thus profit from. In fact, Google and Yahoo can actually read their customers personal email.

Some individuals might say they don’t mind because they have “nothing to hide,” but wouldn’t you be wary of publicly posting your login credentials not knowing who might have access? Giving these large organizations rights to your private messages, can be interpreted as pretty much the same thing. …more