Google Search

Showing posts with label fight. Show all posts
Showing posts with label fight. Show all posts

Wednesday, November 13, 2013

Hey board directors, help your companies fight cybercrime - and yes, it matters

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Boardroom. Image from ShutterstockBoardrooms need to "wake up" to the danger of cybercrime, according to a recent report.

The UK's ICSA, commissioned by the government's Department for Business, Innovation and Skills (BIS), issued the guidance document on how boards can better understand and cope with the threats posed to businesses by malware, hacking, cyber espionage and other digital dangers.

Now, in security circles, "ICSA" generally refers to a leading security testing and certification body, formerly known as NCSA. Or, in some specialist cases, the International Chinese Statistical Association (for some reason, founded in San Francisco and registered as a non-profit in Delaware).

But no, the ICSA we're talking about here is the Institute of Chartered Secretaries and Administrators.

Their report didn't get much attention when it first appeared a few weeks ago. In fact, I didn't spot it until the press release was picked up by, of all places, an Isle of Man-based news site.

So, I hear you ask, what's the rumpus? A bunch of people moan about their bosses' ignorance, and no-one really listens. Big deal.

Two things though. First, these are not the people who do the typing and answer the phones. Important and delightful as those secretaries are, these are corporate secretaries, a whole different thing.

Corporate secretary is a high-power position, basically sitting between the board of directors and the company at large, ensuring the board gets the information it needs from the company, and the company acts on the board's decisions.

The ICSA is the body representing the most experienced and highly-qualified corporate secretaries in the UK, and rightly refers to itself as "a recognised authority on corporate governance and compliance". So, if they say boards are paying too little attention to cyber issues, you can be pretty sure they're right.

Second, their report (PDF) provides some pretty good advice. It gives a clear, simple breakdown of the dangers businesses might face, stressing the need to weigh up the risks specific to a given organisation and the importance of focusing on resilience in the face of attack:

The cyber threats facing businesses and their supply chains cannot be prevented through investment in technology alone. It requires comprehensive risk assessment processes to identify and prioritise the protection of critical information assets.

It puts particular emphasis on the problem extending to all parts of a company:

Internal functions such as HR, finance, legal and marketing may not appreciate the extent to which critical information is at risk, nor realise the potential impact of a cyber attack on their organisation. ...Day-to-day control of cyber risks should not be left to the IT department.

Few companies can survive these days without some sort of internet presence, and even the smallest are likely to be making ever more use of information technology.

Blindfolded man on computer. Image courtesy of ShutterstockFor most, all this is still a relatively new side of doing business, and it changes and evolves at a bewildering pace. This exposes firms to a whole new world of risk, which many staff - especially in senior roles - have minimal understanding of.

Board positions tend to be very senior roles indeed, so members might not be in touch with the fast-moving world of cyber security.

They also tend to be filled from a limited set of backgrounds, mainly financial, sales, marketing and legal areas with limited uptake of people from more technical departments. But their input and backing is vital to ensure cyber security is given the proper emphasis at every level.

It seems that board members need all the help and advice they can get when it comes to shoring up their firms against digital dangers.

So, if you're a board member, read the guidance, and act on it. If you're working for a board which isn't helping with your cyber security needs, try subtly pointing them towards this kind of advice - it just might sink in.

Follow @VirusBTN
Follow @NakedSecurity

Images of hand shadow, boardroom and blindfolded man on computer courtesy of Shutterstock.


View the original article here

Saturday, July 2, 2011

Hackers 'should fight cyber spies'

Britain faces losing its position at the leading edge of technology unless news ideas are developed to fight cyber attacks, according to the Institute for Security and Resilience Studies.

The group, based at University College London, says the government needs to develop more innovative ideas to tackle the problem rather than simply adopting a “sticking plaster” approach.

It follows high profile attacks on the Serious and Organised Crime Agency and attacks allegedly from “bedroom hackers” in Britain on the CIA and US Senate.

In a report to be published by the think-tank, chaired by Lord Reid, the former Defence Secretary, will say that without urgent action Britain could lose its position as a “location of choice for global technology corporations” and leave it reliant on systems based abroad over which it would have “little or no influence.”

Lord Reid said terrorism now had to be regarded in a “far deeper and wider strategic context” and added: "Cyberspace not only enhances the capacity to learn but also creates a target rich environment for the terrorist.”

He is writing to the Chancellor of the Exchequer, the Foreign Secretary and the Defence Secretary calling on them to establish a “Cyber-Resilience Task Force” to bring together their best brains in government, industry and academia.

The task force would look at how to train and recruit computer experts from outside the mainstream, including former hackers who want to help fight off attacks from Chinese and Russian spies and from organised criminal gangs.

It would seek to increase the number of professionals fighting cyber attacks by selecting, training, educating, and testing “competent individuals” for the public, private and academic sectors.

Another idea involves encouraging innovation through “Cyber Enterprise Zones” for entrepreneurs.

Ideas should be shared with other countries and “open source” applications to fight cyber crime should be shared with others in the field, the report says.

The task force would also advise the top-level National Security Council on the financial risks of new hacking techniques.

It would echo the role of the US Cyber Security Co-ordinator who has direct links with the Office of Management and Budget in the White House.

The think-tank, set up by Lord Reid in 2008, includes Baroness Manningham-Buller, the former head of MI5, Admiral Lord Boyce, the former Chief of the Defence Staff, and Michael Chertoff, former US Secretary of Homelands Security.

Cyber attacks are currently fought by the Office of Cyber Security and the Cyber Security Operations Centre based at GCHQ.

Last year the government announced a “transformative programme for cyber security,” including a £500m injection, as part of the National Security Strategy.


View the original article here