SEPTEMBER 2019 | FUTUREOFBUSINESSANDTECH.COM
DIGITAL SECURITY
An Independent Supplement by Mediaplanet to USA Today
Robert Herjavec
The “Shark” and security expert offers tips on how to protect your company’s crown jewels
First Data can protect you and your customers from a data breach | Page 11 How AI could eventually give hackers an advantage | Page 12
Five Lessons Learned From Cybersecurity Breaches Brennan P. Baybeck CISA, CISM, CRISC, CISSP, Chairperson, ISACA Board of Directors; Vice President of Customer Support Services Security Risk Management, Oracle Corporation
ven as more boards and executive leaders become savvier about cybersecurity risk, critical gaps remain in organizations’ preparedness, allowing the vicious cycle of cybersecurity breaches to continue. Here are five ways organizations can guard against becoming next in line to be damaged by a breach:
1. Sharpen focus on data governance and protection. Most of the prominent breaches we hear about can be traced back to a failure to execute core security fundamentals — not patching properly, weak passwords, and uncertainty about where key data is being stored and how it is being protected. Security executives need to be proactive in establishing solid data protection and data governance programs before drawing the board’s reproach or, worse, having their security program’s shortcomings exposed in the form of a major breach. 2. Combine existing and new capabilities for greater impact. Providers are developing new security capabilities and services that are being incorporated in cloud platforms and “Software as a Service” (SaaS) applications that enable business transformation and should be heavily leveraged in a security strategy.
3. Collaborate across the organization to address security. Security teams often function in a siloed fashion — an approach that needs to change to best equip the entire organization to deal with the growing attack surface. Security and data protection is a team sport. As leveraging data becomes increasingly critical to all business functions, the security team needs to partner with business units to make sure sound policies and procedures are being applied to new-use cases for handling data and the deployment of various emerging technologies. 4. Prioritize skills-based training. As evidenced by the ongoing cybersecurity skills gap, organizations are challenged to bring in practitioners with the needed skills to defend against the expanding threat landscape, and the data breaches that result. In most cases,
waiting for candidates with the ideal background to walk through the door is unrealistic. That means organizations need to be open-minded about hiring technology-minded people who might not have an extensive cybersecurity background, and then provide the skillsbased training to help them become proficient in these critical roles. 5. Take a proactive approach. Security teams often are so busy with day-to-day concerns and issues that they fail to take advantage of opportunities to proactively address longer-term challenges. As with the businesses we serve, AI, cloud computing, and other drivers of digital transformation empower security teams to find new ways to address vulnerabilities and inefficiencies that can better position the organization to avoid breaches and thrive. n
Publisher Danica Feuz Business Developer Mac Harris Managing Director Luciana Olson Lead Designer Tiffany Pryor Designer Keziah Makoundou Lead Editor Mina Fanous Copy Editor Dustin Brennan Director of Sales Shannon Ruggiero Director of Business Development Jourdan Snyder Director of Product Faye Godfrey Content Strategist Vanessa Rodriguez Cover Photo Lesley Bryce All photos are credited to Getty Images unless otherwise specified. This section was created by Mediaplanet and did not involve USA Today. FOLLOW US: @MEDIAPLANETUSA
2 • FUTUREOFBUSINESSANDTECH.COM
INQUIRIES: US.EDITORIAL@MEDIAPLANET.COM AND US.ADVERTISE@MEDIAPLANET.COM
PLEASE RECYCLE
MEDIAPLANET
Call us today 1-877-505-7087
The most powerful, comprehensive identity theft protection. Because your digital and financial identity are at constant risk, you need constant protection.
Save up to
33% off with this special offer
Protect your future. Start your free 7-day trial today! Visit identityguard.com/usatoday for details and costs following end of trial period.
The Prevention Methods That Can Keep You Safe From Online Scams A cyberwar is making every single person at your organization a target — a target that must be equipped to protect itself and your operation. “The problem with cyber is that you don’t feel it,” said U.S. Air Force Col. (Ret.) Cedric Leighton. “It’s not like a bomb goes off and everybody’s eardrums are shot.” Instead, he says, the danger is what you don’t see. Church scammed What leaders at Saint Ambrose Catholic Parish in Ohio did not see was devastating. Cybercriminals targeted the church during a construction project, hacking into the email server and using confidential information to pose as the contractor. Father Bob Stec, who wrote
about the project going well, suddenly wrote the parish about a heartbreaking call from the construction company. Why, the company asked, had the church failed to pay $1.7 million? “Upon a deeper investigation by the FBI, we found that our email system was hacked and the perpetrators were able to deceive us into believing [the contractor] had changed its bank and wiring instructions,” Stec said. “The result is that our payments were sent to a fraudulent bank account and the money was then swept out by the perpetrators before anyone knew what had happened.” Known as a business email compromise (BEC) attack, this kind of activity is rampant. According to the U.S. Secret Service, BEC attacks increased
136 percent between December 2016 and May 2018, and losses now stand at $13.5 billion over the past six years. This is one of many ways that hackers use phishing emails to steal or encrypt your organization’s data until you pay a ransom. Lowering your risk Latest research shows more than 90 percent of all cyberattacks are perpetrated in some way through email. However, leading cybersecurity companies have documented that regular security awareness training works to combat this. The most effective programs include a systematic approach that allows for reporting of suspicious emails, provides education around current attack methods, and sends fake phish-
HOW MANY WILL TAKE THE BAIT? Get your true click rate and benchmark your phishing simulation results against other organizations Register For The October 2019 Gone Phishing Tournament Learn more: TERRANOVASECURITY.COM/GONEPHISHINGTOURNAMENT
4 • FUTUREOFBUSINESSANDTECH.COM
ing emails that track whether employees click when they should not. These tests provide a baseline on how the program is working. If your security awareness program is part of a consistent strategy around cybersecurity, attorney Shawn Tuma says it may benefit you in court. “When you can show you’ve done those things, and you can show you’ve made legitimate efforts to combat the risk that your company faces,” he says, “then even when you do have an incident, it makes you look so much better in the eyes of the regulators, the judges, and the attorneys.” And that, he says, can help limit liability and financial damages. n Bruce Sussman, SecureWorld News
Five Steps to Closing the Cybersecurity Skills Gap The threat landscape is changing daily and the threats themselves are becoming significantly more complicated. Unfortunately, the number of qualified cybersecurity professionals is not keeping up. In fact, a study by ISACA and RSA Conference found that 6 in 10 cybersecurity team leaders say their staff can’t handle anything beyond simple incidents. Further, the same study found that it often takes more than six months to fill a cybersecurity position — and half the selected candidates do not have the necessary skills that make them job-ready.
Addressing this problem is possible, though it will take some time. Here are five steps we must aggressively pursue to begin closing the cybersecurity skills gap to ensure that organizations have access to the competent, qualified skilled candidates they need: 1. Drive awareness of the cybersecurity career field Students are exposed to a number of careers from a young age, but being a cybersecurity practitioner isn’t usually one of them. A recent survey by Raytheon indicates that 67 percent of men and 77 percent of women said no high school or ssecondary school teacher, or
guidance or career counselor ever mentioned the idea of a cybersecurity career. And when students are aware of the job — perhaps a family member or friend works in the profession — the role models they see in those positions are overwhelmingly men. 2. Help college students develop strong foundational cybersecurity knowledge University programs need to be directly linked to the knowledge and skills that cybersecurity jobs require. Their courses should provide a strong foundation of cybersecurity knowledge in their courses, but they can’t stop there. Students must be given the opportunity to build hands-on skills, throughout their college careers. 3. Focus on skills-based training Companies are looking for cyber professionals who don’t just know what a threat is, but also how to detect threats, mitigate their effects, and use their skills to guard against future threats.
4. Invest in your cybersecurity workforce To accomplish the shift from knowledge-based learning to skills-based training, organizations need to invest in their workforces. This type of training can be more expensive, but the outcome is exactly what companies are seeking — experienced cybersecurity pros. 5. Open additional pathways to cybersecurity careers Four-year degrees in cybersecurity or related fields are excellent. However, we need to open additional pathways to the industry in order to widen the talent pipeline. This might include a shorter technical school program or investing in training to bring staff from unrelated business units into the cybersecurity function. Whatever the answer, it is implementable and, given the current skills gap, not a subject many should find debatable. n Matt Loeb, CEO, ISACA
The Physical Key to Your Digital Security YubiKey protects you from remote hackers and password phishing. Just tap the key to securely access your online accounts. It’s the easy, strong, two-factor, multi-factor and passwordless login.
yubico.com/stop-phishing
MEDIAPLANET • 5
evolving battle to defend against cyber actors who need very few resources and no geographic proximity to launch attacks. There are also no boundaries to the negative effect of cyber attacks, which impact both the public and private sector.
lot of steps you can take to help keep yourself and your country safe in cyber space. Implementing practices like those in the Department of Homeland Security’s S t o p .Th i n k .C o n n e c t . initiative will begin to reduce the risk to your online security from malicious cyber actors. This includes setting strong passwords and avoiding repeated passwords across multiple accounts. Safeguarding critical information is everyone’s responsibility. Be aware of the risks that are out there and defend yourself against them. There’s no going back. n
Playing your part This isn’t just a government issue. There are a
George C. Barnes, Deputy Director, National Security Agency
How Can You Help Increase Our Country’s Cybersecurity? As bad actors get more technologically savvy, we all need to do our part to keep ourselves and our country safe in cyber space. A decade ago, the average household was not aware of the risks that cyber threats posed to their personal data. The majority of us simply enjoyed the convenience of emerging services
like online banking and shopping that made our day-to-day lives easier. But that was 10 years ago. Today, due to an increase in both frequency and severity of cyber attacks, all Americans need to join the ranks of cybersecurity professionals to understand the threat to their data and what they must do to protect themselves online.
Assessing the threats Today’s cyber space is inhabited with both cyber criminals and nation-state actors (individuals sponsored by an official government) who are looking to conduct malicious activity that harms individual interests and national security. It’s here that the National Security Agency engages in a constantly
We’re transforming the way adult women learn - and succeed! • Cybersecurity Degree 100% Online • Financial Aid/Scholarships • Employer Partnerships • Industry-based Curriculum Visit us today at baypath.edu/cyber
“By preparing adult women to pursue jobs in cybersecurity and information technology, The American Women’s College of Bay Path University is helping address the national need for a digitally fluent workforce.” - Beverly Benson, Program Director, IT & Security
6 • FUTUREOFBUSINESSANDTECH.COM
eneration Alpha (made up of people born between 1995 and 2010) is also known as the Glass Generation since its population’s main medium of communication will be device screens. From an early age, even as young as toddlers, members of this generation are constantly connected with, learning from, and being entertained by tablets, smartphones, voice-controlled personal assistant services, virtual reality, intuitive search engines, and streaming services. Round-the-clock mobile connectivity and interaction with the cloud are daily routine activities that are second-nature to the next generation of digital citizens. 5G networks have opened up new possibilities in terms of interconnection and access to information, making the world seem like a much smaller place. This broad access to information comes with a flipside, however.
MEDIAPLANET
How We Can Keep the Next Generation of Digital Citizens Safe Kids today have the advantage of taking the internet and online technologies for granted, but that familiarity can lead to false trust.
Ramifications As they get a little older and build social media profiles, they willingly share data about themselves with a wide net of individuals, creating accounts for gaming systems, mobile apps, video chat platforms, and even online retailers. Their anonymity will quickly erode as a result. They inherently trust technology because they’ve always had access to it, unlike previous generations who tend to be more wary of technology infringing upon their privacy. In order to enjoy the convenience of online connections, we must also be mindful of the
profound cybersecurity risks involved and remain vigilant to protect our children. Staying vigilant Yes, it sounds scary, but it just means we need to reconcile the huge benefits of these technologies with the risk of privacy loss. Ideally, this means an increased focus on cybersecurity education and training that starts at an early age in primary schools, and continues through university programs. Many progressive schools have established such curriculums, but we need to keep pace with the changing nature of our digital world.
Basic cybersecurity principles like strong encryption, password management, and data backup are valuable lessons students should be taught so we can arm them with the skills to protect themselves and their data online. While we need to demand that service providers and technology creators account for the most vulnerable among us, we also need to become personally accountable for our own security and not let vendors of the products we buy decide for us. n Wesley Simpson, COO, (ISC)2
MEDIAPLANET • 7
How to Avoid Phishing in an Always Expanding Sea Phishing scams can devastate a company’s network if it isn’t prepared, and the increase of BYOD and cloud computing only exacerbate this. We asked an expert panel about how you can protect your network from these attacks.
which an attacker will send a fake link to reset the password.
Stina Ehrensvärd CEO and Founder, Yubico What are common mistakes you see when it comes to digital security in business? Stina Ehrensvärd: Roughly 80 percent of data breaches are a result of stolen or phished credentials. However, while this is one of the leading security problems for businesses, only about 10 percent of IT security’s time is dedicated to solving this issue by providing strong authentication options. Hed Kovetz: Many businesses still focus their security efforts on the network perimeter, without realizing that
Hed Kovetz Co-Founder and CEO, Silverfort
Lise Lapointe CEO, Terranova Security
Jason Asbury President of ThreatAdvice, NXTsoft
those perimeters are no longer effective. People are bringing their laptops and phones in and out of the office every day, and a single infected device can allow malicious actors to take over the whole network from within.
Jason Asbury: Most often, mistakes are tied to the administrative components of the security program, as the very best technology isn’t effective if it isn’t implemented correctly or properly managed. Lack of strong third-party vendor agreements holding vendors accountable for security matters is very common. Finally, the lack of having a remedial security training program in place occurs far too often.
of two-factor authentication (2FA), and break the stigma of it being difficult or hard to use. Many of the top services you use on a daily basis already have 2FA built into their applications.
Lise Lapointe: Overreliance on technology. People tend to forget that the human risk can leave an organization just as exposed as a technological gap. Up to 90 percent of breaches stem from employees tricked by phishing and other scams. Training, especially executive-backed training, is key.
What are best practices for employee education when it comes to phishing? SE: It is critical to educate users on the importance
If your company falls victim to phishing, what are the critical first actions to take? HK: Companies should immediately notify all employees about the ongoing threat to ensure no additional employees fall victim. Targeted employees should change their passwords, however, they should also be warned against “change password” scams, in
Beyond employee education, how can employers minimize risk? LL: Employee education goes hand-in-hand with technical controls to detect and respond to phishing attempts. We also recommend securing browsers, deploying multi-factor authentication, and subscribing to a service that monitors the use of your brand. How do you recommend business owners secure information on multi-cloud platforms? JA: Multi-cloud platforms have one common denominator and that is the devices that access them. It is essential to secure and protect computers, tablets, and mobile devices that have access to multiple platforms. n
Think Your Employees Are Too Smart To Click on a Phishing Email? Willing to Bet Your Company on It? Your business needs cybersecurity education. Let us prove it with a free phishing simulation. Visit threatadvice.com/phish 8 • FUTUREOFBUSINESSANDTECH.COM
Why a Career in Cybersecurity May Be for You While technology and automation are shrinking many industries, they’re expanding the need for cybersecurity professionals. We talked with Dr. Geanie Umberger, executive director of the Purdue Cybersecurity Apprenticeship Program (P-CAP), about why people need to consider this career path.
Moving Your Digital Security Strategy Into the 21st Century As the author of the autobiographical book-turned-film “Catch Me If You Can,” Frank W. Abagnale knows a thing or two about theft. Once a con man, he now works as a security consultant and has written multiple books on the subject. We asked him about the biggest trends in the world of digital security.
What are the biggest trends in digital identity right now? The trends I see are the realization that passwords are the core issue we face, and that we need to work to remove them. All the breaches you hear about are related to stealing static credentials. We have to make things harder for criminals to steal and easier for consumers to use. I see that, in the near future, more and more organizations will prioritize this task, as we now have industry solutions for it. The next trend I see is using government-issued ID to prove identity for online transactions. Just like when you drive, you are asked to show your driver’s license, we now have the technology to do that on mobile phones. Because it is so easy to fool the support call center and pretend to be someone
else, the need for better identity proofing to prevent SIM Swaps is urgent.
hash prevents the data from being reverted to its original values.
What are some rudimentary security steps you can implement for any data you’re collecting from clients?
What industries are currently most at risk for a data breach?
Encryption, and when possible one-way hashing. Say you want to authenticate a customer by asking them to scan their driver’s license (on a risky transaction). You do not need to store any PII (personally identifiable information) to do so. You do not need to store the data encrypted with a symmetric key either. If you one-way hash the data, into a value even, you cannot reverse, and you can still run the comparison without risking your customer’s data. To explain this, I use this line: “You can’t unscramble scrambled eggs.” One-way
It’s better to ask which one isn’t, and the answer is simple: everyone is at risk, period. There are only two kinds of organizations: those who have been breached and know it, and those how have been breached and don’t know it, yet. If you are in charge of security and you are still using passwords to protect your organization, your employees, and your customers data, you are putting them all at risk. We are all insecure because we are still using technology from the 1960s to protect us today. To change the security landscape and turn the tide, we need to move off of passwords. n
PHOTO: ABAGNALE AND ASSOCIATES
What are the benefits of pursuing a career in cybersecurity? It’s a fact that we all need some form of cybersecurity protection in all aspects of our lives. This need grows exponentially every day. Although technology is rapidly advancing, industry and academia are unable to keep up with the growing gap between the number of vacant jobs and the number of cybersecurity professionals needed to protect everything, from hospitals, financial institutions, manufacturers, the electric grid, and beyond. Does a career in cybersecurity allow you to scale into different verticals? Cybersecurity should be thought of as a generic term that encompasses many different types of jobs, with more created over time. A person can choose to explore many branches, all leading to a high-paying job with tremendous opportunities for advancement. What are the ideal qualities for this profession? Most people can be trained on the technical skills via on-the-job training and classroom-based coursework. However, there are certain essential “cyber aptitudes” that cannot be taught. Where do students from Purdue University typically work after graduating? Those enrolled in the Purdue Cybersecurity Apprenticeship Program (P-CAP) will be enrolled in school at the same time they are working. This means there isn’t the traditional post-graduation process of finding a job — the apprentice is earning while learning and already has a job when they complete the program. MEDIAPLANET • 9
PHOTO: LESLEY BRYCE
How to Keep Your Network Safe and Protect Your Company’s Crown Jewels Business and critical infrastructure are increasingly being moved to digital platforms, which means security has to keep pace. Robert Herjavec, founder of security solutions firm Herjavec Group and co-host of ABC’s “Shark Tank,” offered some tips on how your business can keep its “crown jewels” safe. For those who are unfamiliar, what are the major red flags to look out for that could indicate a phishing email?
What are the major benefits of using privileged access management (PAM) solutions for a business?
Given your expertise in this space, what is the greatest piece of advice you have for a CEO looking to secure their company assets?
Phishing emails are the most common way hackers can gain access to your company’s network. It’s unlikely that the Prince of Nigeria is messaging you to give you part of his fortune, or your CEO messages you out of the blue asking you to download a file. Every member of your organization must be trained on what to look out for because your people really are the weakest link. My team and I get phishing emails daily and it’s scary stuff. This is why we have certain protocols in place to mitigate the risks associated with phishing scams. We also use external email monitoring to indicate when a communication is EXTERNAL, even if it’s coming from a name you may recognize as a colleague.
Here’s the thing: Almost all security breaches by outside attackers (vs. insider threat) involve a form of escalating access management. Hackers get in through a back channel, find the vulnerability that allows them to escalate their privilege into your network, and then start moving their way laterally through the organization until they find something specific about you. That’s how it almost always works. We need to prevent this chain of events from happening. A hacker might be able to “upgrade” a normal user role to a system administrator, but without a PAM capability, they will not be able to gain access to the actual data — or the “crown jewels.” Having the ability to prevent this chain of events is why a PAM solution is critical.
Focus on the data and understand it’s not an infrastructure issue but a data protection issue. CEOs and their security leaders need to align on what their companies’ crown jewels are, and then determine the best way to protect them. It’s shocking to me that many organizations still don’t know what their crown jewels are. Often there is a disconnect between the security team and the organization’s overall business function. As a security practitioner, you have an obligation to the organization to connect the dots between each critical question and make sure it always leads back to protecting the crown jewels. n
10 • FUTUREOFBUSINESSANDTECH.COM
Read more at futureofbusinessandtech.com
How to Deal With Security in an Increasingly Cloud-Based World
Importing your old security protocols to your new cloud-based system can be cumbersome and inefficient. Your cloud service provider likely has a better option. So you’ve moved your IT to the cloud. How safe do you feel? If you haven’t already suffered a security incident, you’re lucky. If you’re worrying about
what happens when you do, you’re smart. If you’re not worried at all, you may have made one of the most common cloud mistakes: assuming the cloud service provider (CSP) will handle all your security for you. CSPs like Amazon and Microsoft are clear that the customer shares the responsibility for cloud security. Customers who don’t address
their cloud security responsibilities end up flying blind with no visibility into their data, applications, and security posture. They can’t review their logs to work out what led to a security incident. Companies that understand shared responsibility often make another mistake: They try to port security tools and solutions from their own premises into the cloud. That’s expensive, cumbersome, and ineffective. Vendors don’t always build tools with the cloud in mind. Native solutions There’s an easier way to solve your cloud security problems: Use your CSP’s existing security solutions. They are already in the cloud and therefore are easy to set up, reducing the need
for expensive IT professionals. They replace expensive, complex equipment and software with a single recurring payment, and because they’re using cloud infrastructure, they scale with your computing needs. Bringing security to market The large CSPs are stepping up with new options, too. Microsoft has Azure Sentinel and Google has Backstory. Amazon has its GuardDuty and Security Hub services. To perfect your cloud security, it’s time to map these cloud-native features against your security requirements and turn them on accordingly. You’ll sleep easier at night, and so will your customers. n Brian Bourne, Director and Co-Founder, Black Arts Illuminated Inc.
We make cyber criminals cry Help protect your business and your customers from the consequences of a data breach FirstData.com/#mer
© 2019 Fiserv, Inc. or its affiliates.
MEDIAPLANET
MEDIAPLANET • 11
How Artificially Intelligent Malware Could Intensify Attackers’ Capabilities It won’t be long before artificial intelligence is put to work to identify and eliminate digital threats. However, hackers tend to be only slightly behind their security worker counterparts. echnology has advanced at an astounding rate in the past decade and the pace is only set to accelerate. Capabilities that seemed impossible only a short time ago will develop quickly, aiding those who see them coming and hindering those who don’t. As artificial intelligence (AI) systems are adopted by organizations, they will become increasingly critical to day-today operations. Some organizations already have, or will have, business models entirely based on AI technology. Securing these systems and the information that feeds them will be of vital importance.
AI: friend or foe? According to some experts, AI will bring significant benefits to society, especially in areas like research and healthcare. AI, using advanced analytics, could offer a significant, if temporary, advance in thwarting potential attackers, however, technological advances tend to be a cat and mouse game. Hackers usually work in close pursuit of security workers, meaning security workers can be compromised. In the coming years, attackers will take advantage of breakthroughs in AI to develop malware that can learn from its surrounding environment and adapt to discover new vulnera-
THE OFFICIAL
CYBER SECURITY SUMMIT EXCLUSIVELY FOR SENIOR LEVEL EXECUTIVES
Rated “TTp 50” InffSec CCnferences Gllbally
bilities. This malware will surpass the performance of human hackers, exposing information, including mission-critical information assets, and causing financial, operational, and reputational damage. Conventional techniques used to identify and remove malware will quickly become ineffective. Instead, AI-based solutions will be needed to fight this new malware — leading to a race for supremacy between offensive and defensive AI. How should you prepare? Moving forward, business and information security leaders alike must understand AI before
embracing a technology that will become a critically important part of everyday business. In the near-term, organizations should invest in people with technical expertise in AI, particularly machine learning, malware analysis, and reverse engineering. These experts will be able to better understand how to work with defensive AI systems. However, recruitment is likely to be a challenge as people with relevant skills and expertise are likely to be targeted by major technology vendors. Therefore, be prepared to invest in internal training and development. In the longer term, organizations should review threat intelligence capabilities and knowledge with peers to better monitor developments in the malware ecosystem, and understand these new threats. This may involve engaging with external specialists and malware protection providers. Early preparation is essential. n Steve Durbin, Managing Director, Information Security Forum
We stop phishing emails immeditately
REMAINING 2019 SUMMITS
Charllle, NC
New YYrk, NY
September 17
Octtber 3
Scccsdale, AZ
BBsttn, MA
Octtber 17
NNvember 6
HHusttn, TX
LLs Angeles, CA
NNvember 21
December 5
LEARN FROM EXPERTS FROM THE FBI, CIA, US DOJ & MORE.
Register NNw at CyberSummitUSA.ccm
Speaking/Exhibiঞng Oppprtuniঞes: CCntact Bradffrd Rand at 212.655.4505 x223 / BRand@CyberSummitUSA.ccm
12 • FUTUREOFBUSINESSANDTECH.COM
Protect yourself from Display name spoofing Domain name spoofing Malicious attachments “Friendly from” spoofing
Real Time Advanced Threat Protection
Perfect for Office 365 users and compatible with all email services
Starts at $45 for 150 users Sets up in 10 minutes 24/7 technical support Start your FREE TRIAL at www.phishprotection.com
Coupon code: ppmp for the first month free
Big Fish Bite If You’ve Got Good Bait Corporations have long had security measures to protect their assets and personnel, however, none of these protections have addressed the vulnerability of senior executives in cyberspace. biquitous social and business networks, and the wide range of interconnected sensors and devices make it much more difficult to firewall an executive. The C-suite is a favorite target for cyber and identity thieves. They have the most valuable credentials in the enterprise when combining the value of the information and assets to which they have access, along with their own value to the company. While Jane Doe’s credentials go for some dollars in the identify theft marketplace, executive credentials for a Global 1000 enterprise can go for hundreds of thousands of dollars. Combine this with an executive’s aversion to security policies, and you have the kind
of triangulation that makes for successful exploitation. Modern executives have grown up with technology and it’s hard to separate them from it (more bait). There is also a growing expectation of hyper-connectivity; to go faster, go smarter, and outperform the competition. This just expands the waters and seasons to bag a trophy fish. Leave no trace Well, try at least. It is critical to develop a practice of personal information hygiene and set in place a privacy design style that benefits any individual and organization. Why not practice global privacy best practice and greatly reduce the executive — and organizational — risk profile?
Offer personal training Executives respond to challenges, and top performers accept being pushed by a coach, which is where fitness is obtained by regular workouts. Keeping your executives and protection systems operating at high levels of performance matters. Travel trouble Executives expect perks and typically belong to airline, hotel, car rental, and other travel clubs. Each of these brings its own set of network and connectivity challenges. Secure device, burner device, VPN by default, and whitelisted access are all things that need to be in place, particularly for executives on the go.
Everybody’s special To be clear, the biggest risk is the human one. No firewall, biometric multi-factor authentication, or AI super protector can overcome bad human decisions. Usable and invisible The best security and privacy are never felt or seen. Find the path that makes it easy for executives to work cooperatively with business, security, privacy, legal, and information technology staffs, and create as little user friction as possible while maximizing protection. Drive this to where security and privacy are operational by default. n Salvatore D’Agostino, CEO, IDmachines; IT Security Council Member, ASIS; Co-Founder, OpenConsent
Read more about how to stay secure online at futureofbusinessandtech.com
MEDIAPLANET
MEDIAPLANET • 13
Improving Cyber Safety Starts With You As hackers and cybercriminals are growing in numbers and creativity, many consumers have trouble staying ahead of the new threats that emerge daily, struggling to decide what to do or not do. With a few commonsense steps and a bit of vigilance, consumers can feel safer online. The usual suspects The FBI’s Internet Crime Complaint Center 2018 Internet Crime Report includes information from nearly 352,000 complaints of suspected internet crime, with reported losses in excess of $2.7 billion. The top three crime types reported were non-paym e n t /n o n - d e l i v e r y, extortion, and personal data breach. If you think your home network is too small of a target for a cyberattack, or that the many connected devices present in your home have built-in security that’s good enough, you are wrong on both counts. Most cyberattacks are not personal in nature. Rather, they are crimes of opportunity, made
possible by faulty security practices for devices and networks. If it’s connected to the internet, it’s susceptible to outside threats unless precautions are taken. Safety steps One such precaution is to stay current with software updates and patches for all devices that connect to the internet. Software updates add new features and functions, but in many instances they
14 • FUTUREOFBUSINESSANDTECH.COM
also include critical fixes to counter a real threat or vulnerability that’s been identified. Delaying software upgrades only serves to raise the odds of an attack. Smart phones, tablets, computers typically have auto-updating features, but many other connected devices do not. Be sure to check regularly for software updates on routers and any other devices around your home that connect to the internet, or
to computers and mobile devices, most often by Wi-Fi or Bluetooth. When adding new devices to your home network, be sure to change the factory-installed default configurations, usernames, and passwords. Leaving these unchanged creates opportunities for outsiders to gain unauthorized access to information, install malicious software (malware), and cause other problems.
Staying vigilant Always proceed with a “buyer beware” mindset before buying a new connected device. Do a little research first. There are a variety of ways to see if a vendor or product has known privacy or security issues. You can search for vendors and specific products to see if they have known vulnerabilities and whether they’ve been patched. Another option is to visit the Better Business Bureau site to see if other customers have reported issues, or if there are government actions against the company. You can also use your favorite search engine to look for the product or vendor name with the word “recall”to see if there are any recalls under way. Finally, make it a habit to regularly back up your data and valuable information, either to an external device or a cloud-based service. These backups are crucial to minimize the impact if data is lost, corrupted, infected, or stolen. n Todd Thibodeaux, President and CEO, The Computing Technology Industry Association MEDIAPLANET
DOMINATE WITH THE RIGHT BYTES.
EARN AN M.S. DEGREE IN
DEGREES/CONCENTRATIONS INCLUDE
COMPUTING WITH JUST
30 CREDITS. AVAILABLE ONLINE.
Application Development Artificial Intelligence Computer Science Cybersecurity Data Science/Analytics Information Systems Information Technology Software Engineering
NSA AND DHS RECOGNIZED Designated since 2005 as a National Center of Academic Excellence in Information Assurance—Cyber Defense Education by the National Security Agency (NSA) and the Department of Homeland Security (DHS).
GET STARTED TODAY. cec.nova.edu | (954) 262-2031 | cecinfo@nova.edu Nova Southeastern University admits students of any race, color, sexual orientation, gender, gender identity, military service, veteran status, and national or ethnic origin. n Nova Southeastern University is accredited by the Southern Association of Colleges and Schools Commission on Colleges to award associate’s, baccalaureate, master’s, educational specialist, doctorate, and professional degrees. Contact the Commission on Colleges at 1866 Southern Lane, Decatur, Georgia 30033-4097 or call 404-679-4500 for questions about the accreditation of Nova Southeastern University. 08-117-19SAT