Showing posts with label CISO. Show all posts
Showing posts with label CISO. Show all posts

Thursday, 16 August 2012

Potential Security Risks You Can't Ignore



Information security is not just about privacy, secrecy, and confidentiality. With cyber criminals taking over the malspace, law makers also need to be closely involved. Steve Durbin, the Global VP of Information Security Forum Ltd, describes the potential security risks that might cost a lot if overlooked -Hiren Mehta Thursday, August 16, 2012

Given the way security threats are evolving, there can exist only two kinds of organisations in cyberspace: Those who have already been attacked; and those who WILL be attacked. Hence, the question to ask is not whether you will be attacked but WHEN you will be attacked next. We attended Threat Horizon 2014, an event aimed to help CISOs understand the security threats landscape and what should be done about it. It was conducted by the Information Security Forum Ltd in Mumbai in July. Here are the major findings.

Most Malware is Coming from Malspace

Cybercrime is a typical external security threat. The Information Security Forum calls it Malspace, to denote the realm of cyber criminals, their network, malware, methods, tools and data. Phishing and spamming are only indicative examples of the methodologies that they use. The malspace is maturing very rapidly and the coordination, planning and determination seen between cyber criminal networks and gangs these days is unmatched even by the discipline of the most revered law enforcement agencies. Crowd-sourcing is a rising phenomenon used in malspace.

To combat malspace, organizations need to implement a baseline security model as their first line of defence. Further, organisations need to improve their cyber resilience. Since malspace has cyber criminals involved, they must also connect with law enforcement agencies to share information and work better rather than plan defences in an isolated manner.