Conference Presentation, Panel, Fireside Chat
Cybersecurity: The Internet of Threats
Milken InstituteEdward Lucas, Nadav Zafrir, Paul Gillan, Sinisa Patkovic, Dan, John Derrick, Stephen
- Structural Vulnerabilities of the Internet:
- The internet was designed for academic cooperation based on trust, not as the central nervous system for modern critical infrastructure, e-banking, and commerce.
- Founders of the internet would reportedly be horrified by current reliance on unsecure protocols for essential services.
- The Offensive-Defensive Asymmetry:
- Attackers operate on a significantly faster innovation pace ("clock") than defenders, causing the gap between offensive capability and defensive readiness to broaden.
- Nadav Zafrir (Team8) describes a "perfect storm" where rising attacker sophistication, talent scarcity, and increasing system interconnectedness make current solutions ineffective and unsustainable.
- Sinisa Patkovic (BlackBerry) identifies complexity as the "enemy of security," noting that distributed systems make "security by design" difficult to achieve.
- Organizational and Economic Barriers:
- Customer convenience frequently trumps security; unless forced by regulation or defense needs, businesses prioritize speed to market over security features.
- Security by design is often avoided because it increases time-to-market for new hardware and software.
- A "literacy gap" exists where board members and decision-makers lack understanding of cyber risks, often demanding simple "green dashboard" metrics despite complex underlying threats.
- CIOs and CISOs face difficulty justifying security spend as boards view security as a cost center rather than a business enabler.
- Attribution and Justice Challenges:
- Cybercriminals operate with little consequence due to jurisdictional issues and the anonymity of the internet.
- Society and media treat digital theft differently than physical theft; while a physical bank robbery makes a bank a "victim," a cyber breach implies negligence.
- Cooperation between financial institutions is strong, but global law enforcement coordination and "digital hot pursuit" remain inadequate compared to physical policing.
- Adopting New Defensive Paradigms:
- Nadav Zafrir advocates for a "learning competition" where defenders must "think like offense" to identify and exploit attacker vulnerabilities, such as their need for network order and predictable topologies.
- Defenders are moving from passive perimeter defense to active strategies that lure attackers into making mistakes to improve the signal-to-noise ratio of alerts.
- Paul Gillan (Barclays) notes that while the threat landscape varies by region, increased investment and intelligence sharing are heading the right direction.
- Human Factors and Insider Threats:
- Insider threats, including malicious actors, leavers, and compromised low-level staff (e.g., cleaners using USB drives), are considered as dangerous as external APTs (Advanced Persistent Threats).
- Sophisticated attacks often involve a hybrid model where insiders collaborate with external attackers.
- The "weakest link" theory is challenged by the need to view the organization as a holistic "organism" where agility and behavior monitoring are critical.
- A 2014 KVM (Keyboard Video Mouse) attack on a Barclays branch demonstrated how low-tech social engineering can bypass high-tech physical security.
- The Cost of Security for SMEs:
- Small enterprises and charities lacking resources for major infrastructure investments are at high risk; the industry is shifting toward Managed Security Service Providers (MSSPs) and "cyber as a service."
- Threat Actor Taxonomy:
- State Actors: Viewed as the "fifth domain" of warfare (US) or "fourth domain" (Israel), used for destruction and intelligence gathering (e.g., 2007 attacks on Estonia).
- Organized Cybercriminals: Operate via "crime-as-a-service" models involving malware coders, drop handlers, and money mules, often with low attribution risk.
- Cyber-Terrorists: Currently using cyber tools for recruitment and propaganda with increasing sophistication.
- Future Outlook and Optimism:
- Zafrir estimates there are approximately 500 cybersecurity startups globally, driving innovation and a shift toward proactive, offensive-thinking defense.
- Sinisa Patkovic cites the ability to make security "seamless" (e.g., BlackBerry's single-phone solution for government and personal use) as a key optimism driver, reducing user resistance.
- Paul Gillan believes society will eventually shift its mindset to view cybercrime with the same severity as physical crime, driving regulatory and operational change.
- Patkovic emphasizes layered security architectures where multiple "doors" must be breached to compromise a system, minimizing the impact of any single vulnerability.
- Misconceptions and Reality:
- The panel clarified that while any unencrypted phone can theoretically be tapped, the practical ability for non-state actors to monitor all UK mobile calls is false; the "Bourne Identity" scenario is Hollywood drama, not reality.
- However, the panel warned that the gap will likely widen before it narrows, as state-sponsored tools become more accessible via the dark web (e.g., Target 2013 exploit tools purchased for ~$10,000).
- The panel noted that while total prevention is impossible, breaches need not be catastrophic if organizations possess the discipline, board commitment, and layered defenses to detect and respond rapidly.