Skip to main content

GISEC 2019 Day Three

Page 1

01-03 day three April 2019 BROUGHT BY

Nedaa Showcases Smart City capabilities at GISEC

P

rofessional Communication Corporation – Nedaa, the Dubai Government security networks provider, is participating in GISEC, the region’s largest information security conference and exhibition being held from the 1st to the 3rd of April at the Dubai World Trade Center. Nedaa is displaying a diverse range of Smart City solutions enabled through its 4G Network, designed to improve the quality of the services provided to Nedaa customers, and to raise and improve the communication and operational efficiency. Nedaa is highlighting in cooperation with its technology arm Esharah Etisalat Security Solutions and its partner the latest

smart cities technologies delivered over its private network; providing support for a variety of applications for different fields in a smart city environment. Nedaa is addressing how key security, safety and privacy challenges can be addressed while connecting drones to a smart city infrastructure; revealing a wide array of IoT and Machine to Machine(M2M) solutions enabling and supporting the Smart Dubai Plan 2021. Nedaa’s live video streaming services is deployed using smart phones over its mission critical network for increased security. Those devices allowing instant group communications, snapshots of critical moments and live-stream videos to exchange data safely. Additionally, Nedaa

is addressing smart city initiatives through its network offerings for an ultra-reliable remote control systems for high speed drones required for increasing the operational efficiency for the different fields in smart city such as harbor operational automation. Its services are also extended to demos on 5G secure devices for faster connectivity; operational efficiency with private LTE utilized in different smart cities fields such as Gas mining and airports; and enabling smart venue experiences with 5G small cells and optical LAN. “Smart cities based on shared operational and security intelligence run more efficiently, gather better insights and can deliver better services to improve the

lives of residents. As a leading security networks provider, we are excited to join GISEC, bringing forth technologies and solutions utilized by our partners for creating secure applications, and to make life better in the digital age. GISEC as a platform has given us an opportunity to demonstrate the role we play in delivering smarter and safer cities, and the challenges tackled in order to develop solutions to address them. We aim to offer best-inclass smart connectivity over our network in order to enable cities become ‘smarter’ and more connected.” commented H.E. Mansoor Bu Osaiba, Chief Executive Officer, Nedaa. The development of smart cities has a huge potential to bring benefits for businesses, city services and people. To deepen smart connectivity, Nedaa’s 4G private network integrates communications, enabling seamless interoperability for enhanced efficiency delivered over many platforms.


03

“Expertise on Demand” In conversation with Jens Monrad – Head of Intelligence, EMEA, FireEye

What have been the primary changes in the cyber security technology landscape in the last 12-24 months? The biggest change is the increased speed of innovation across the region. Unfortunately, security can’t always keep up with innovation, causing many new and weaker points to cover from a cyber security point of view. Our traditional security measures quickly become outdated. The increased digitalisation, as well as the innovation into the Internet of Things

(IoT), has expanded the cyber-attack surface area greatly. It becomes an attractive space for attackers who are motivated by stealing financial funds as well as those who are involved in online geopolitical conflicts, where nation states use cyberspace as a field for attacking other nations.

attacks, it rarely provides context to the threat. Without context, the CISO will not be able to understand the threat landscape and therefore how to protect the organisation. It therefore becomes a challenge to minimise risk when the organisation is operating in cyberspace.

How is this new technology landscape affecting a vendor’s future product portfolio across 2019 into 2020? The new technology landscape will focus on how we can combine solutions and save time for the security people. As the number of threats continues to increase, new solutions need to be able to combine existing products; provide contextualised information that enables organisations to make the right security decisions to manage their risk; and provide automation and prioritisation of the threats so the security staff can focus on threats based on the severity.

When a CISO approaches a cyber security vendor today, what are their primary expectations and standards that they expect from the cyber security industry? I believe, from a CISO perspective, it is all about minimising risk to their business. To reduce risk, a CISO cannot rely on technology alone. Understanding how threat actors operate, what their motivation is and how the threat landscape affects the organization (based on industry, region or country) will help the CISO make informed decisions on how to reduce risk.

How will the new technology landscape help CISOs in their job roles and responsibilities? While technology can help prevent certain

According to you what are the key challenges that CISOs face in their day to day operations and how do your solutions help overcome these pain points? We have what you could call a cyber secu-

rity talent crisis. The demand for skilled people has probably never been higher, and it puts the CISO in a challenging spot as he or she needs to explain to leadership what risk they are facing in cyberspace and how well prepared they are dealing with the threats. Throughout our years of providing leading technology, being an innovator in threat intelligence, as well as providing industry leading incident response, we have seen the demand for more talent within the organisations we have helped. Therefore, we recently launched a service we call “Expertise on Demand” where we try to help organisations address the gap they might have in their organisation at the current time. Expertise on Demand is designed as a prepaid annual subscription that provides flexible, pay-per-use access to our security expertise and threat intelligence. As cyber threats keep evolving, so does the requirements from an organization. I believe if you as a CISO can have cybersecurity expertise and actionable threat intelligence available on “speed dial,” it will help minimise the cyber risk as well as address the skills gap we are currently experiencing.

Offering Unrivalled Protection and Intelligence In conversation with Rawad Sarieddine, Sr. Director - META, CrowdStrike Middle East What have been the primary changes in the cyber security technology landscape in the last 12-24 months? Adversaries have changed their tactics heavily in the last two years, moving away from malware-centric attacks, to living “off-the-land”. Threat actors are increasingly leveraging exploits against existing system and application vulnerabilities, and weaponizing admin tools such as Powershell to perform stealthier attacks. As a result, traditional security tools can no longer keep up with these advanced attacks, and enterprises are turning to cloud native platforms that leverage artificial intelligence and behavioural analytics. CrowdStrike is at the forefront of next-generation vendors leading the path to stopping the modern

adversary. How is this new technology landscape affecting a vendor’s future product portfolio across 2019 into 2020? Adversaries have upped their game, and so the security industry has to do the same to combat the challenge. Traditional approaches to Cybersecurity are clearly not working, so it is time for defense technologies to move away completely from signature based or IOC based protection, towards a new model that embraces big data analytics and artificial intelligence. Cloud is the most innovative and important development in cybersecurity and will be for the foreseeable future. The speed of deployment and speed of implementation cloud hosted services

like CrowdStrike Falcon offer enterprises in the Middle East unrivalled visibility and cyber protection which far outstrips that offered by legacy security vendors. International technology analysts like Gartner and Forrester have recognised CrowdStrike is a disruptive player in the market offering unrivalled protection and intelligence. How will the new technology landscape help CISOs in their job roles and responsibilities? CISOs have a demanding job and in many ways, it has never been a harder time to be a CISO. There is almost a perfect storm of increasing levels of cybercrime, married with increased recognition of the importance of managing customer and corporate data for the good of the long-term business

and good of the brand. Alongside this, CISOs are finding it increasingly hard to recruit and hold onto trained cybersecurity staff. CISOs need support from their suppliers and vendors like never before. They demand reliable and effective solutions which enable them to target the most critical and important security incidents. Cyberattacks are a fact of life for CISOs and other business leaders today, visibility and speed of remission are the critical factors to the successful mission for enterprise leaders. We at CrowdStrike aim to lighten the burden off the CISOs shoulders, by offering the perfect blend of cuttingedge protection technology, along with world leading services and threat intelligence to help manage the technology and ultimately stop the breach.


04

Tripwire: 80% of Security Professionals Say Skilled Workers are More Difficult to Find Tripwire revealed the results of a survey conducted by Dimensional Research that examines how organizations are addressing the cybersecurity skills gap. The survey was administered to 336 IT security professionals in February. Eighty percent of survey respondents believe it’s becoming more difficult to find skilled cybersecurity professionals. As emerging technology and threat landscapes experience rapid transformation, the skillsets needed change as well. Nearly all respondents (93 percent) say the skills required to be a great security professional have changed over the past few years. “The skills gap issue continues to worsen,” said David Meltzer, chief technology officer at Tripwire, “which is troubling, since cybersecurity threats only continue to grow. Additionally, security teams are in search of new skillsets to deal with evolving attacks and more complex attack surfaces as they include a mix of physical, virtual, cloud, DevOps and operational technology environments. It’s becoming more difficult to maintain critical security controls, and there are fewer people available to do it.” The survey found that while 85 percent report their security teams are already understaffed, only 1 percent believe they can manage all of their organization’s cybersecurity needs when facing a shortage of skilled workers. Nearly all respondents (96 percent) say they are either currently facing difficulty in staffing security teams due to the skills gap or can see it coming. Of those, 68 percent are concerned with losing the ability to stay on top of vulnerabilities, 60 percent worry about being able to identify and respond to issues in a timely manner and stay on top of emerging threats, and 53 percent fear they will lose their ability to manage and secure configurations properly. Lamar Bailey, senior director of security research at Tripwire added: “Because security teams are stretched thin, it’s going to be more important than ever to build strong partnerships. Organizations can collaborate with trusted vendors to take pressure off their in-house resources. Approaches could include more automation of security tasks and support through managed service to ensure that no critical security controls are dropped. Maintaining a strong foundation of security is non-negotiable, so it’s imperative that organizations partner across the info security community to continue meeting security goals effectively.”

DFLabs and CyberGate Join Hands DFLabs revealed that CyberGate, based in Abu Dhabi, United Arab Emirates, as its first managed security services provider (MSSP) partner in the Middle East. Using the DFLabs IncMan SOAR platform, CyberGate will provide managed incident response and remediation services for enterprises and government entities within the Gulf Cooperation Council (GCC) region, including United Arab Emirates, Bahrain, Kuwait, Oman, and Saudi Arabia. The new version of IncMan SOAR enables MSSPs to centrally perform one-to-many operations across multiple customer environments regardless of the security products deployed at each location, while providing flexible deployment options for regulatory compliance and granular analytics for reporting. The companies are demonstrating DFLabs IncMan SOAR solution at GISEC from April 1-3 at the Dubai World Trade Center. “We are pleased to partner with CyberGate, a leading security expert in the Middle East, to provide security orchestration, automation and response-as-a-service in the region,” said Dario Forte, Founder and CEO of DFLabs. “We look forward to working with CyberGate to support organizations that require advanced cyber threat detection and response capabilities but lack the internal resources to manage this function themselves.” “Many of our customers lack the expertise to handle security incidents and perform threat hunting, yet rec-

ognize they need security orchestration, automation and response to protect themselves from data breaches,” said Mohammad Bin Bouta Al Harsousi, Founder and Managing Director, CyberGate. “The DFLabs IncMan SOAR

platform is a force multiplier that enables our security operations center to scale the number of customers they can support by an order of magnitude. It enables us to respond to more incidents, faster, and more efficiently”.


OFFICIAL GOVERNMENT CYBER SECURITY PARTNER

OFFICIALLY SUPPORTED BY

THE WORLD'S MOST FAMOUS HACKER AND EX-#1 ON THE FBI'S MOST WANTED LIST TO HACK LIVE IN DUBAI See the jaw-dropping live hack by KEVIN MITNICK for as little as AED 1,999. #GISEC www.gisec.ae I gisec@dwtc.com I +971 4 308 6805

OFFICIALLY SUPPORTED BY

STRATEGIC PARTNERS

GOLD SPONSORS

IOT PARTNER

POWERED BY

CO-LOCATED WITH

PLATINUM SPONSOR

ORGANISED BY

DIAMOND SPONSOR


06

Engineering Simplicity

SANDER GROOT, THE HEAD OF CHANNELS AT JUNIPER NETWORKS

At GISEC 2019, Juniper is further re-emphasizing on simplifying the complexities of networking in the digital era with a key focus on security relating to multi-cloud, automation adoption, as well as Juniper’s connected security portfolio. Sander Groot, the Head of Channels at Juniper Networks said, “The market is ever-changing and the threats keep rising. There is a dire need in the organizations to protect the inside perimeters as we have observed that 75% of breaches happen due to internal threat rather than external. What Juniper is doing from a connected security point of view is that, we treat the entire network as a firewall.”

Engineering simplicity forms the DNA of Juniper Networks and Groot adds that it is an overarching and consistent theme. “Complexity is one of the biggest hindrance to security and we at Juniper Networks aim to address this. We want to preach to the organizations to use the entire network as a security device and we make that possible with our products and solutions. We have certainly added a flavor of automation to it that makes it much more easier for the smaller security teams to monitor, detect and prevent all types of threat.” adds Groot. Juniper recently announced native integration of Juniper’s platforms with Software for Open Network-

ing in the Cloud (SONiC), which was developed and contributed to the Open Compute Project (OCP) Foundation by Microsoft. This integration will give cloud providers a simplified and automated switch management platform, enhanced by the rich routing and deep telemetry innovations valued by customers. Groot states that a significant amount of the revenue is put back in the company for R&D. “We constantly scan the market for what the next kind of needs are try to integrate our technology based on the needs. We protect the customers in three key domains—The service provider domain, the cloud domain and the enterprise domain.”

See what a Hacker sees!

FOUAD KHALIL, VP COMPLIANCE OF SECURITY SCORECARD

The evolving vulnerability landscape has been putting many organizations under the growth curve, everyday, every minute. Security Scorecard comes on board with a very niche solution and service that instantly identifies vulnerabilities, active exploits, and advanced threats to help you rigorously protect your business and strengthen your security posture – from an outside-in perspective, enabling you to see what a hacker sees. Fouad Khalil, VP Compliance of Security Scorecard says, “Our platform, a year ago, had two hundred thousand domains and as of December 2018 we have one million domains and we expect to have ten million domains by the end of 2019. From a scalability, assessment and data collection point of view, we have special information that enables risk assessments and mitigation aspects, data analytics and everything that we need to identify risk and what we need to do to mitigate it. We are non-intrusive and we see what a hacker sees as our model. We look at the publicly available information and report on that. Our compliance mapping module reveals issues that pertain to the specific checkpoints of security standards -- including PCI, NIST, ISO, SIG, HIPAA, and GDPR -- that apply to your business.” The company has recently launched a new solution called Atlas. Atlas is a revolutionary questionnaire and evidence exchange platform that has a “smart-mapping” engine which enables organizations to rapidly respond to any questionnaire, significantly reducing completion time. Atlas accelerates the questionnaire exchange process by enabling organizations to easily send, manage, and review questionnaires at scale. Talking about their partnership with Spire Solutions, Fouad says, “Its been over two years that we have been partners and Spire has been an excellent partner to work with. They are a perfect match in terms of the services we offer and they offer and the customers they have. Security Scorecard compliments Spire’s existing portfolio as well, thus making the partnership more special. From a marketing, PR, technology and sales point of view, the partnership ranks really high.”


07

72% of the Global 2000 Companies Located in the Middle East Exposed to Email Fraud Risk

EMILE ABOU SALEH, REGIONAL DIRECTOR MEA, PROOFPOINT

Proofpoint revealed its analysis of the 57 Global 2000 companies located in the middle east and their exposure to email fraud. For many organisations, the road to easing email fraud risk is paved with DMARC (Domain-based Message Authentication, Reporting and Conformance), an email protocol being adopted globally as the passport control of the email security world. It verifies that the purported domain of the sender has not been impersonated. DMARC verificaiton relies on the established DKIM (DomainKeys Identified Mail) and SPF (Sender Policy Framework) standards to ensure the email is not spoofing the domain. This authentication protects employees, customers, and partners from cybercriminals looking to impersonate a trusted domain. To gauge how quickly the DMARC standard is being adopted across the

Middle East, Proofpoint conducted an analysis of the primary corporate domains of all 57 Global 2000 organisations located in the region in March 2019. Key findings include: 72 percent of the Middle East largest organisations are exposed to email fraud via domain spoofing; In total, only 28 percent of the 57 Global 2000 companies located within the Middle East have published DMARC records to begin protecting their employees, customers and partners from some forms of email fraud. However, only 20 percent of those have published a strict “reject” policy (the most effective policy for defending against domain-spoofing). In the United Arab Emirates, 27% of the Global 2000 companies surveyed had a DMARC record in place; Globally, the adoption level is the highest in the United States with 54%, followed by the Nordic region (Denmark, Sweden, Finland and

Norway), the Benelux (Belgium, Netherlands, Luxembourg) and Australia, all at 49% and the UK at 47%. “Email fraud continues to provide great returns for cybercriminals and our latest research confirm that it is not going away,” said Emile Abou Saleh, regional director of Middle East and Africa for Proofpoint. “As these threats grow in scope and sophistication, it is critical that organisations shore up their defences against email fraud by adopting technology like DMARC to protect their brand against impersonation. Additionally, as cybercriminals take advantage of the human factor to execute their campaigns, companies need to ensure they deploy effective security awareness training to educate employees about best practices as well as establish a people-centric strategy to defend against threat actors’ unwavering focus on compromising end users.”

Defence in Depth Approach

CHAITANYA RAO, FOUNDER, PRODMARC

The growing number of businesses attract attackers who tend to use the brand value of a company for their benefit. On of the major channels they use to attack is Email. The majority of the cybr attacks begin with one simple phishing email. ProDMARC analytics platform has been setup by ProgIST, a new age cyber security firm. ProDMARC has been built with a mission to achieve secure and spoofing free email channel across the internet space.

At GISEC 2019, the company is showcasing their email security solution. “ProDMARC stops domain spoofed phishing attacks by automating the process of DMARC (Domain-based Message Authentication, Reporting and Conformance) email authentication. It helps protect customers from cyber-attacks, maintain trust in the brand and improve digital communications,” says Chaitanya Rao, Founder, ProDMARC.

The company plans to have a local office soon and is also in search of new partnerships at the event. “We have a few happy customers here like RAK Bank, Network International, etc. Our customers are happy with out products and services. GISEC is a great platform to meet news customers and make new partnerships. We are here to establish ourselves as a premier player in our solutions segment and we believe we will achieve that,” he concludes.

Defending Digital Transformation

JAY HUFF, MARKETING DIRECTOR, INTERNATIONAL, RISKIQ

Headquartered in San Francisco, RiskIQ provides the most comprehensive discovery, intelligence and mitigation of threats associated with an organization’s digital presence. With more than 75 percent of attacks originating outside the firewall, RiskIQ allows enterprises to gain unified insight and control over web, social and mobile exposures. The company’s platform combines advanced internet data reconnaissance and analytics to expedite investigations, understand digital attack surfaces, assess risk and take action to protect the business, brand and customers. “We help people understand what vulnerabilities they have on the internet. We help them find instances of impersonation. We help security analysts understand the nature of the threat,” said Jay

Huff, Marketing Director, International, RiskIQ. Jay believes that the organization has gone through a major digital transformation in the last decade. As they organizations embrace the change, their online presence and attack surface has grown. RiskIQ helps organizations automate attack surface visibility and targeted threat protection packaged in a Software-as-a-Service application suite that optimizes tasks across security teams. Jay sees GISEC as the right platform for them to showcase their solutions. He says that this show also helps them to get a lot of customers/prospects. “The ecosystem for security vendors is very large. Hence, I also use these shows to update myself on new developments.”


www.btxshow.com

APRIL 2019 SAUDI ARABIA 23rd APRIL

BAHRAIN TBA

KUWAIT TBA

OMAN TBA

TRANSFORMATION IN

SECURITY NETWORKING BUSINESS APPLICATIONS IT & COMPUTING BROUGHT BY

OFFICIAL MEDIA PARTNERS


Turn static files into dynamic content formats.

Create a flipbook
GISEC 2019 Day Three by GEC Media Group - Issuu