{"id":66797,"date":"2017-11-13T22:34:50","date_gmt":"2017-11-13T14:34:50","guid":{"rendered":"https:\/\/wp-productionenv-bjg9h2g2bgg5b8aa.southeastasia-01.azurewebsites.net\/news\/3-takeaways-from-cybersecurity-experts-at-cybersat\/"},"modified":"2017-11-13T22:34:50","modified_gmt":"2017-11-13T14:34:50","slug":"3-takeaways-from-cybersecurity-experts-at-cybersat","status":"publish","type":"post","link":"https:\/\/starpath.global\/news\/3-takeaways-from-cybersecurity-experts-at-cybersat\/","title":{"rendered":"3 Takeaways from Cybersecurity Experts at CyberSat"},"content":{"rendered":"<\/p>\n<p>Cybersecurity threats and protocols aren\u2019t exactly the most comfortable topics for public discussion. Few are eager to reveal their practices and even fewer are willing to ask for guidance out of fear that they will be perceived as vulnerable. The cybersecurity discussion at the 2017 Via Satellite CyberSat Summit, however, felt long overdue \u2014 and even welcome. Attendees from a variety of industries shared their thoughts and concerns about protecting sensitive data in the age of the Internet of Things (IOT) and automation, when threats are continuously evolving and attacks are increasingly bold and aggressive. Here are some of the most important takeaways and most popular discussions from the productive two-day event:<\/p>\n<p><strong>Cybersecurity frameworks are simply foundations, which companies must then build upon with measures that match the nature of their operations.<\/strong><\/p>\n<p>The <strong>National Institute of Standards and Technology\u2019s<\/strong> (NIST) most recent cybersecurity frameworks not only provide suggestions for how businesses should protect their data networks \u2014 they also elevate collaboration and communication as key network defense tools.<\/p>\n<p>Ron Clifton, senior solutions architect for <strong>Tata Communications<\/strong>, led a panel discussion focused on the recommended cybersecurity measures for satellite, broadcast, cable, wireless and wireline service providers outlined by the U.S.<strong> Federal Communications Commission\u2019s<\/strong> (FCC) CSRIC IV Working Group 4 (WG4) between 2013 and 2015. The WG4 council was created to provide recommendations to the FCC to ensure, \u201coptimal security and reliability of communications systems, including telecommunications, media, and public safety\u201d for consumers and enterprises, as written in its FCC mission statement.<\/p>\n<p>Clifton and panelists stressed that the NIST framework is not a \u201cone-size-fits-all\u201d security roadmap. It is simply the foundation of a protocol that needs to be customized to the use. The framework isn\u2019t universal, either. It may not be appropriate for other types of critical infrastructure \u2014specifically infrastructure in motion, such as aircraft, Robert Hickey, of the U.S. <strong>Department of Homeland Security\u2019s<\/strong> (DHS) Aviation Cyber Security Division said during his keynote presentation. \u201cCritical infrastructure that is in motion [a vehicle] demands a paradigm shift from traditional methods of protecting and reconstituting stationary critical infrastructure.\u201d<\/p>\n<p><strong>Strategic network segmentation will be the cornerstone of cyber defenses in the age of automation.<\/strong><\/p>\n<p>The age of self-driving transportation is upon us, taking control of vehicle systems entirely out of human hands. Letting go of the wheel also means placing an incredible amount of trust in the cybersecurity defenses that are built into a vehicle\u2019s systems. Andy Davis, transport assurance practice director for the <strong>NCC Group<\/strong>, referred to a rather terrifying example of how cyberattacks could potentially put millions of lives at risk in the automated world \u2014 the \u201cJeep Hack.\u201d<\/p>\n<p>In 2015, Charlie Miller, a security researcher at <strong>Twitter<\/strong>, and Chris Valasek, director of vehicle security research at <strong>IOActive<\/strong>, remotely hacked into a Jeep\u2019s various \u201cconnected device\u201d systems, eventually gaining complete control of the cars\u2019 various functions. Situated miles away from a journalist riding shotgun in a Jeep, they drove the car from their laptops, changed radio stations, operated the air conditioning and eventually crashed the vehicle into a ditch. Davis was surprised that a vast majority of audience members never heard of the experiment, which was featured in <em>WIRED<\/em> magazine.<\/p>\n<p>\u201cCyber-defenses need to be even more layered than the networks operating these vehicles, or the big brand names that are hosting these systems will be held responsible,\u201d he said. \u201cThe Jeep hack happened because Miller and Valasek exploited a vulnerability in the cellular carrier\u2019s connection, which enabled them to then exploit a vulnerability in the Jeep\u2019s infotainment system. This process continued until all of the systems were under their control. Interestingly, the hack is referred to as the \u2018Jeep Hack,\u2019 but it was a weakness in all of these third party systems that enabled the hack.\u201d<\/p>\n<p>Hickey\u2019s keynote on aviation cyber defenses also touched on this point, underlining the lives that would be put at risk if even one of a pilot\u2019s vital navigation tools was compromised.<\/p>\n<p><strong>Cybersecurity is a job for everyone \u2014 not just IT.<\/strong><\/p>\n<p>Executive leadership at the world\u2019s largest companies are starting to realize the perils of placing the responsibility of securing enterprise networks entirely on the shoulders of IT departments.<\/p>\n<p><strong>PBS<\/strong> Senior Director of Engineering and Technical Maintenance Philip Schoene told CyberSat Summit attendees that the core of his company\u2019s approach to cybersecurity is having all workers in the building share the same responsibility of protecting its broadcasts. \u201cAt PBS, serious cybersecurity discussions happen at all levels \u2014 from the executive board to entry level team members,\u201d he said. \u201cOur leadership creates policies that are fully supportive of our IT department. It is the responsibility of everyone working in the building to follow their recommendations, exercise caution, and communicate their concerns when suspicious activity happens.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity threats and protocols aren\u2019t exactly the most comfortable topics for public discussion. Few are eager to reveal their practices and even fewer are willing to ask for guidance out of fear that they will be perceived as vulnerable. The cybersecurity discussion at the 2017 Via Satellite CyberSat Summit, however, felt long overdue \u2014 and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":66798,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[2],"tags":[],"class_list":["post-66797","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/66797"}],"collection":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/comments?post=66797"}],"version-history":[{"count":0,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/66797\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media\/66798"}],"wp:attachment":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media?parent=66797"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/categories?post=66797"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/tags?post=66797"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}