Conference Presentation, Panel, Fireside Chat
Cybersecurity: Can the Next Threat Be Stopped?
Milken InstituteJeevan Vasagar, Aditya Mathur, Jacqueline Poh, Alain Raes, Nadav Zafrir, Sean, Senator Dunn, Jocelyn, Doug Mellinger, Ajit
- The 2012 Sony cyber attack resulted in direct costs of approximately $41 million and lost sales/dividend impact of roughly $77 billion, though the event was deemed survivable for a media company; financial institutions or critical infrastructure facing similar disruption could face existential threats or total operational collapse.
- Singapore's government policy involves separating public internet access from internal intranet access via distinct devices for public servants, a measure intended to protect citizen and corporate data while maintaining full service productivity.
- Panelist Nadav projects that air-gapped or dual-network systems will likely converge into a single network within three to four years due to the impracticality of maintaining two separate systems for data transfer and the preference of workers for a single device.
- Panelist Aditya argues that "air-gapping" is merely a defensive friction tool (similar to locking a door) and not an impenetrable barrier, citing the Stuxnet attack on a supposedly isolated system as proof that determined attackers can bypass physical separation.
- Switching to low-tech or "Amish" solutions, such as reverting to paper records or typewriters, is deemed infeasible as the Internet is integral to modern productivity, economic survival, and the future of sectors like healthcare and transportation.
- Cyber threats are global rather than regionally specific; while high-profile attacks have occurred in Asia (e.g., Bangladesh, Vietnam), the threat landscape is expanding globally alongside the rapid increase in internet and telecommunications infrastructure.
- Adversaries have evolved from purely technical hackers to sophisticated operators who understand and exploit financial processes and organizational workflows to access funds, necessitating robust process improvements alongside technological defenses.
- Information sharing between organizations is critical for security but faces a "quandary" where early disclosure of a breach may temporarily depress share prices, whereas delayed disclosure risks severe reputational damage and loss of trust if data is later revealed to have been withheld.
- In 2015, over 250 attempted cyber attacks on critical infrastructure (power, water, transportation) were recorded in the US alone; a successful attack on a Ukrainian power grid in December 2015 affected 80,000 people for several hours.
- The Internet of Things (IoT) and Industrial Control Systems (ICS) present unique cybersecurity challenges due to the lack of prevailing security doctrines for field-deployed sensors and the difficulty of patching devices that are inexpensive to replace but costly to secure.
- Future cybersecurity risks involving autonomous vehicles and IoT are projected to be driven more by human error and system configuration anomalies than by malicious state-sponsored hacking, though these systems must be resilient to single-point failures like incorrect data pings.
- The banking industry is facing significant cost pressures from the dual mandates of digitizing services to reduce overhead and the simultaneous need to invest heavily in cybersecurity and regulatory compliance.
- Cybercriminals face a "glut" of scrutiny and advanced countermeasures, but the industry remains in a continuous cat-and-mouse game where attackers remain agile and capable of finding new exploitation methods.
- Total global productivity losses attributed to cyber activity are estimated between $500 billion and $1 trillion annually, a figure significantly exceeding the economic impact of physical terrorism.
- Panelists advocate for a shift in mindset from passive defense to "proactive defense," which involves understanding attacker vectors to anticipate threats, rather than relying solely on reactive measures.
- There is a growing consensus that the legal and social sentiment toward cybercriminals must align with that of physical bank robbers, treating digital theft from foreign jurisdictions as a serious crime warranting severe penalties rather than negligence on the part of the victim.
- Democratic and open societies possess a larger "attack surface" due to higher connectivity and openness, making them statistically more vulnerable to state-sponsored attacks and large-scale intrusions.
- The line between cybercrime, cyber warfare, and state intelligence operations is blurring, with nations developing dual-use capabilities for both offensive and defensive operations across land, sea, and cyber domains.
- Effective cyber defense requires a triangle of security, usability, and cost management, as these factors are interdependent; reducing security costs often inevitably impacts usability or operational security.
- The next generation of cybersecurity threats will likely involve autonomous AI systems (both defensive and offensive) competing against one another, a landscape already being tested in competitions like the DARPA Grand Challenge.
- Individual citizens share responsibility for cyber security, with poor personal hygiene (e.g., shared passwords, unpatched firewalls) remaining a significant vulnerability across both public and private sectors.