newsfilter.io
Conference Presentation, Panel, Fireside Chat

Cybersecurity: The Internet of Threats

  • Structural Vulnerabilities of the Internet:
    • The internet was designed for academic cooperation based on trust, not as the central nervous system for modern critical infrastructure, e-banking, and commerce.
    • Founders of the internet would reportedly be horrified by current reliance on unsecure protocols for essential services.
  • The Offensive-Defensive Asymmetry:
    • Attackers operate on a significantly faster innovation pace ("clock") than defenders, causing the gap between offensive capability and defensive readiness to broaden.
    • Nadav Zafrir (Team8) describes a "perfect storm" where rising attacker sophistication, talent scarcity, and increasing system interconnectedness make current solutions ineffective and unsustainable.
    • Sinisa Patkovic (BlackBerry) identifies complexity as the "enemy of security," noting that distributed systems make "security by design" difficult to achieve.
  • Organizational and Economic Barriers:
    • Customer convenience frequently trumps security; unless forced by regulation or defense needs, businesses prioritize speed to market over security features.
    • Security by design is often avoided because it increases time-to-market for new hardware and software.
    • A "literacy gap" exists where board members and decision-makers lack understanding of cyber risks, often demanding simple "green dashboard" metrics despite complex underlying threats.
    • CIOs and CISOs face difficulty justifying security spend as boards view security as a cost center rather than a business enabler.
  • Attribution and Justice Challenges:
    • Cybercriminals operate with little consequence due to jurisdictional issues and the anonymity of the internet.
    • Society and media treat digital theft differently than physical theft; while a physical bank robbery makes a bank a "victim," a cyber breach implies negligence.
    • Cooperation between financial institutions is strong, but global law enforcement coordination and "digital hot pursuit" remain inadequate compared to physical policing.
  • Adopting New Defensive Paradigms:
    • Nadav Zafrir advocates for a "learning competition" where defenders must "think like offense" to identify and exploit attacker vulnerabilities, such as their need for network order and predictable topologies.
    • Defenders are moving from passive perimeter defense to active strategies that lure attackers into making mistakes to improve the signal-to-noise ratio of alerts.
    • Paul Gillan (Barclays) notes that while the threat landscape varies by region, increased investment and intelligence sharing are heading the right direction.
  • Human Factors and Insider Threats:
    • Insider threats, including malicious actors, leavers, and compromised low-level staff (e.g., cleaners using USB drives), are considered as dangerous as external APTs (Advanced Persistent Threats).
    • Sophisticated attacks often involve a hybrid model where insiders collaborate with external attackers.
    • The "weakest link" theory is challenged by the need to view the organization as a holistic "organism" where agility and behavior monitoring are critical.
    • A 2014 KVM (Keyboard Video Mouse) attack on a Barclays branch demonstrated how low-tech social engineering can bypass high-tech physical security.
  • The Cost of Security for SMEs:
    • Small enterprises and charities lacking resources for major infrastructure investments are at high risk; the industry is shifting toward Managed Security Service Providers (MSSPs) and "cyber as a service."
  • Threat Actor Taxonomy:
    • State Actors: Viewed as the "fifth domain" of warfare (US) or "fourth domain" (Israel), used for destruction and intelligence gathering (e.g., 2007 attacks on Estonia).
    • Organized Cybercriminals: Operate via "crime-as-a-service" models involving malware coders, drop handlers, and money mules, often with low attribution risk.
    • Cyber-Terrorists: Currently using cyber tools for recruitment and propaganda with increasing sophistication.
  • Future Outlook and Optimism:
    • Zafrir estimates there are approximately 500 cybersecurity startups globally, driving innovation and a shift toward proactive, offensive-thinking defense.
    • Sinisa Patkovic cites the ability to make security "seamless" (e.g., BlackBerry's single-phone solution for government and personal use) as a key optimism driver, reducing user resistance.
    • Paul Gillan believes society will eventually shift its mindset to view cybercrime with the same severity as physical crime, driving regulatory and operational change.
    • Patkovic emphasizes layered security architectures where multiple "doors" must be breached to compromise a system, minimizing the impact of any single vulnerability.
  • Misconceptions and Reality:
    • The panel clarified that while any unencrypted phone can theoretically be tapped, the practical ability for non-state actors to monitor all UK mobile calls is false; the "Bourne Identity" scenario is Hollywood drama, not reality.
    • However, the panel warned that the gap will likely widen before it narrows, as state-sponsored tools become more accessible via the dark web (e.g., Target 2013 exploit tools purchased for ~$10,000).
    • The panel noted that while total prevention is impossible, breaches need not be catastrophic if organizations possess the discipline, board commitment, and layered defenses to detect and respond rapidly.