{"id":66815,"date":"2017-11-09T20:32:03","date_gmt":"2017-11-09T12:32:03","guid":{"rendered":"https:\/\/wp-productionenv-bjg9h2g2bgg5b8aa.southeastasia-01.azurewebsites.net\/news\/how-better-social-practices-can-improve-your-cyber-resiliency-2\/"},"modified":"2017-11-09T20:32:03","modified_gmt":"2017-11-09T12:32:03","slug":"how-better-social-practices-can-improve-your-cyber-resiliency-2","status":"publish","type":"post","link":"https:\/\/starpath.global\/news\/how-better-social-practices-can-improve-your-cyber-resiliency-2\/","title":{"rendered":"How Better Social Practices Can Improve Your Cyber Resiliency"},"content":{"rendered":"<\/p>\n<p>Speakers at the 2017 CyberSat Summit emphasized that improving technology capabilities is only a piece of the larger cybersecurity puzzle. During a panel assessing the evolving threat landscape in aerospace, a group of experts agreed that it is equally important to monitor the \u201cpeople and processes\u201d that form the foundation of companies\u2019 every day operations.<\/p>\n<p>Specifically, the panelists said that cybersecurity precautions must originate from the very top with senior executives and board directors. \u201cOne of the big problems we have to face is that the folks in the boardroom don\u2019t understand how things work and why,\u201d said <strong>Cyxtera Federal Group <\/strong>President Greg Touhill. \u201cWe need to have folks continually keeping their skills up to date. And we need to make sure the folks who are making those decisions on risk are adequately prepared. It takes homework.\u201d<\/p>\n<p>The speakers noted that there has been a recent shift in corporate culture, hefting responsibility for scenarios such as cyber breaches toward company leaders. Randy Sabett, head of the cyber practice group at <strong>Cooley<\/strong>, pointed to the 2013 <strong>Target<\/strong> breach for which the retail company had to pay an $18.5 million settlement as a salient example. After the incident, Target shareholders pointed the finger at the company\u2019s board of directors and C-suite executives for not fulfilling their fiduciary responsibilities, and recommended that seven out of the 10 board members not be voted back into their positions. The company\u2019s Chief Executive Officer (CEO) at the time, Gregg Steinhafel, also resigned amid the blowback.<\/p>\n<p>That vigilance, however, must also trickle down to mid- and low-level employees, the panelists said. James Turgal, executive assistant director of the <strong>FBI\u2019s <\/strong>information and technology branch, noted the FBI recently arrested a technologist who was identified as an \u201cinternal threat\u201d at an undisclosed company. Turgal highlighted third-party vetting as a more secure way of ensuring companies are hiring the \u201cright talent,\u201d and said too that such responsibility ultimately comes back to \u201caccountability and leadership.\u201d<\/p>\n<p>Touhill added that during his tenure at the <strong>Department of Homeland Security<\/strong> (DHS), \u201ccareless negligence and indifferent people\u201d caused a majority of the cybersecurity incidents he witnessed. \u201cToo many folks go right to the technology,\u201d Touhill said. \u201cWe\u2019ve got a lot of antiquated technology but we also have a lot of antiquated procedures and folks who don\u2019t have the mindset of thinking like a hacker.\u201d<\/p>\n<p>Sabett also emphasized the importance of training employees to be prepared for the different forms an attack may take \u2014 saying that being proactive means \u201cbeing ready for the punch.\u201d<\/p>\n<p>\u201cWe\u2019re seeing some incredible attacks these days with business email compromise. It\u2019s getting somebody to click on an email that\u2019s not [from] the Nigerian prince, but your friend,\u201d Sabett said.<\/p>\n<p>According to Turgal, part of being prepared is establishing a resiliency and recovery plan for the day an attack inevitably occurs, which includes having the right communications channels in place to work alongside the FBI. \u201cWhen the FBI comes and knocks on your door \u2026 you need to have that plan in place,\u201d Turgal said. \u201cThe sooner we get there, the sooner we can stop the bleeding.\u201d<\/p>\n<p>\u201cThe time to exchange business cards is not during a crisis. You need to plan ahead before that day,\u201d Touhill added.<\/p>\n<p>Still, despite companies\u2019 best efforts to manage the behavioral and social side of cybersecurity, the panelists acknowledged that cyber attackers will come up with more creative ways to infiltrate satellite technology \u2014 such as \u201cmonkeying with the rocket\u201d so it doesn\u2019t make it to orbit, Touhill said. Hackers may also attempt a Denial of Service (DOS) attack to interrupt the transmission of data from the ground station to the satellite or, worse yet, in the case of a compromised employee, include a vulnerability in the satellite\u2019s design that doesn\u2019t manifest until later \u2014 not unlike the Death Star from <em>Star Wars.<\/em><\/p>\n<p>Modernizing the infrastructure satellite communications relies on can help mitigate some of these attack vectors, said Lisa Donnan, managing director of <strong>Option3Ventures<\/strong>. Donnan brought up Artificial Intelligence (AI)\/machine learning as an example of an emerging technology that can be leveraged to improve cyber resiliency. According to Donnan, Option3Ventures recently invested in a company that uses machine learning for automated threat intelligence. The technology has allowed the company to turn near-time awareness of cyber threats into real-time detection. Comparatively, she said, \u201cyou\u2019re done\u201d if you\u2019re forced to wait for an analyst or Chief Information Security Officer&nbsp;(CISO)&nbsp;to manually assess the threat.<\/p>\n<p>Near the end of the discussion, Touhill stressed that while government regulation can help standardize responses to cyber threats, it shouldn\u2019t be the first line of defense. \u201cWe need to work together as part of the cyber neighborhood watch,\u201d he said. \u201cWe don\u2019t expect the police to check our doors every night to make sure they\u2019re locked. We don\u2019t expect the <strong>National Transportation Safety Board<\/strong> (NTSB) to make sure the air in our tires is at the right level. We\u2019ve got to accept some responsibility.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Speakers at the 2017 CyberSat Summit emphasized that improving technology capabilities is only a piece of the larger cybersecurity puzzle. During a panel assessing the evolving threat landscape in aerospace, a group of experts agreed that it is equally important to monitor the \u201cpeople and processes\u201d that form the foundation of companies\u2019 every day operations. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":66816,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":"","_links_to":"","_links_to_target":""},"categories":[2],"tags":[],"class_list":["post-66815","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"acf":[],"_links":{"self":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/66815"}],"collection":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/comments?post=66815"}],"version-history":[{"count":0,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/posts\/66815\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media\/66816"}],"wp:attachment":[{"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/media?parent=66815"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/categories?post=66815"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/starpath.global\/blog\/wp-json\/wp\/v2\/tags?post=66815"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}