newsfilter.io
Conference Presentation, Panel, Fireside Chat

Cyber-Security: Protecting Companies and Citizens From Assault

  • The cybersecurity threat landscape is projected to intensify, necessitating improved security postures where CEOs assume direct ownership, particularly as the U.S. leads globally while other regions catch up.
  • Organizations are expected to increase investments in security equipment, specialized skills, and crisis response drills, with 90% of such simulations now focusing on cyber issues rather than natural disasters.
  • The industry anticipates a "no normal" environment characterized by jurisdictional conflicts between data privacy and local cultural expectations, creating challenges for technology that must operate securely across borders.
  • Potential U.S. government mandates for encryption backdoors are predicted to erode the competitive advantage and moral standing of American companies, as adversaries may cease using technologies with known vulnerabilities.
  • A cybersecurity framework is expected to establish a prevailing standard of care in courts over time, increasing liability for breaches and driving better cyber hygiene among small and medium-sized businesses.
  • Cyber insurance markets are expected to mature as companies establish neutral reporting mechanisms to build actuarial tables, though effective underwriting requires better metrics to account for daily network changes.
  • In the next five years, mobile operating systems are predicted to offer safer environments than desktops, with significant user improvements driven by the implementation of FIDO standards to replace passwords with biometrics.
  • Yahoo plans to continue rolling out on-demand passwords and biometric authentication via the FIDO standard, while the broader industry seeks to develop open-source end-to-end encryption projects that exclude service provider access.
  • A shift from prevention to detection and incident response is identified as a major trend, with startups leveraging offensive software knowledge for defensive tools likely to succeed.
  • Companies are expected to share cyber threat indicators previously held as competitive advantages, achieving near real-time situational awareness where adversaries succeed only once.
  • Leadership structures are evolving with the emergence of cybersecurity committees as board subdivisions, and experts predict a future where cyber specialists assume CEO roles.
  • Future corporate strategy requires balancing negative threat narratives with positive data monetization stories to satisfy institutional investors, with a third potentially basing investment decisions on these data strategies.
  • Executive leadership is expected to prioritize reputational issues and values over strict legal obligations during breaches, alongside a call for cybersecurity hygiene education to become standard curriculum.
  • Risks include a potential "cyber Pearl Harbor" event, financial "taxes" on small companies causing revenue loss, and the danger that prescriptive frameworks could create fragile systems focused solely on compliance rather than comprehensive threat mitigation.
  • The legal landscape regarding metadata collection has not changed significantly post-Snowden, while government efforts will continue to involve international partners, including the EU and The Usual Five, in sharing best practices and operational information.
  • The Department of Homeland Security is expected to continue assisting companies in rebuilding systems to be more secure upon request, though the dynamic nature of networks requires constant measurement and automation rather than static standards.