newsfilter.io
Conference Presentation, Panel, Fireside Chat

Hacked and Back: Cybersecurity Lessons From the C-suite

  • Criminal groups are predicted to continue monetizing via scams, identity theft, credit card fraud, and banking information theft, while hacktivists will target organizations for personal or policy-related vendettas.
  • Nation-state actors identified as primary concerns include China, Russia, Iran, and North Korea, with China orchestrating nearly two decades of intellectual property theft and the cyber conflict landscape evolving from theft to disruptive and destructive attacks over the last seven to eight years.
  • The hospitality industry is expected to face the highest targeting levels due to the pursuit of credit card data and VIP guest lists, while the entertainment industry is predicted to become a major target for all threat actors as it transitions into data aggregation, ambient computing, and the Internet of Things.
  • Attackers are estimated to take an average of 1 hour and 58 minutes to achieve a breakout from a compromised system, necessitating detection under one minute, investigation within 10 minutes, and network ejection within one hour.
  • Future security discipline is expected to increase in the entertainment sector as companies tie vulnerabilities to retail and allied areas, potentially forcing executive personal liability and shifting leadership toward the security pace set by organizations like Hyatt and CrowdStrike.
  • Governments currently lack the authority to compel information sharing outside of a narrow chemical industry segment, with existing classified information sharing systems described as broken, outdated, and hindering rapid declassification.
  • A centralized repository for hack profiles is anticipated to significantly reduce cyber crime scale, while a single dollar investment in leverage points like Windows Update could yield a 100-to-1 amplification in security outcomes.
  • Legal frameworks governing the digital space are viewed as outdated, requiring updates to address modern threats, with the National Protection and Programs Directorate potentially changing its name contingent on congressional action within approximately 10 years.
  • The entertainment industry faces risks from distributed workforces, untrained temporary staff, and personal devices, while technology is expected to remain a double-edged sword enabling both life-enhancing applications and untraceable weapons or disinformation that could cause mayhem.
  • Industry leaders from the financial sector are expected to adopt "conditional access" concepts, though this may disrupt creative processes and value creation within the entertainment industry, requiring a holistic shift in workforce education and security values.
  • The transition to ambient computing is expected to require immediate response times for the entertainment industry to prevent panic or civil unrest, with trusted brands needing to integrate vulnerabilities into retail and allied areas.
  • Imperfect information currently leads to flawed decisions at national and institutional investment levels, and average publicly traded companies are expected to bridge the gap between commercially reasonable security investments and military-grade security outcomes.
  • A collective security model involving government and industry collaboration is seen as essential for stabilizing global order, with the government needing to improve communication, marketing, and the ability to drive better security outcomes through binding operational directives.