Cyber Security - How Confident (Complacent?) Are You?

Attention all cyber security professionals! We all know that today’s cyber security landscape is an ever-changing one. So how often should organizations review their cyber security strategy? If it’s a question that hasn’t been asked in a while, chances are that in this world of constant threat, you’re probably at risk. 

For despite the near constant stream of data breaches making headlines, far too many organizations insist their current cybersecurity model is good enough. However, the contrary holds true.

Quite simply, if any of the statements below apply to your business, then it’s arguable that cyber security confidence is actually misplaced complacency:-

  • We haven’t been hacked before, and I know where my organization’s critical or sensitive data is at all times. Why change something that’s working today?

No business can ever be 100% sure where its data is or that it hasn’t been compromised in transit. Failure to recognize this issue is a board-level responsibility.

  • We tick the boxes when it comes to GDPR, PCI DSS, HIPAA (and other regulations) so my organization is secure. No company that has met their compliance requirements has ever been hacked, right?

Taking a compliance-led approach to securing customer data will cause a fundamental vulnerability within the cyber security infrastructure, simply waiting for hackers to exploit. Compliance is important, clearly, but it should be a subset of the overall, continuously evolving security strategy, rather than an end-point goal in itself.

Organizations are understandably concerned about the financial penalties associated with failing to achieve regulatory compliance. But take a step back and consider the financial implications of a data breach, of high profile customer data compromise. That is a far more significant cost and an event that will have long-term repercussions on customer perception and loyalty.

  • We trust that our WAN (Wide Area Network)  provider has the necessary controls in place to keep our data secure as it moves between locations.

But WAN providers can’t guarantee the security of their environments and the security of your data is ultimately your responsibility. What’s needed is a data-first ‘Zero Trust’ mindset that protects data before sending it to the carrier network.

  • IT costs need to be reduced, so the easiest thing is to cut the security budget; it reduces cost without reducing functionality. But, just in case, we’ve increased our cyber insurance coverage. 

Cyber security insurance policies require customer diligence. You cannot buy a security policy, not deploy security and then expect a post-hack payout. More significantly, think about the cost and loss of earnings associated with the fallout of a data breach.

  • My network is secure so I don’t need to secure our data in motion. After all, we own the entire infrastructure end to end, wherever our data goes.

When 70% of all breaches are as a result of internal user compromise, this is a false sense of security. Not only are current security models broken, current trust models are too so they must be realigned and rebuilt.

The only way to do that is to change the emphasis. Shift the security focus from infrastructure to the user or application and it doesn’t matter how complex technology has become, or becomes in the future; the security model remains simple and hence both manageable and relevant. Moreover, whether the environment is owned by the business, third party, or in the cloud, when access is based on users and application, only a user with cryptographic keys and credentials gains access. It is that simple.

  • We need not worry: we can do encryption on our firewall, switches and routers for less money and achieve the same result.

Turning on encryption in a network device WILL degrade the performance, typically by 50%. The reason lies in the way encryption has been deployed to date. In order to address the continued friction between operational goals and security imperatives, organizations need to decouple encryption from the infrastructure completely and instead overlay the security measures, leaving the underlying infrastructure untouched. The answer is Layer 4 encryption.

Layer 4 encryption is dedicated to providing the level of trust of data in motion and applications moving across the infrastructure, yet avoids any impact on network performance and complexity. Furthermore, Layer 4 encryption operates in ‘stealth’ mode: it is only the data payload that is encrypted – not the entire network data packet. All of the complex management and maintenance problems created by traditional encryption deployment are removed. The data in motion is secure without adding complexity or compromising the operational performance of the infrastructure.

  • We don’t need encryption because our firewalls will keep the hackers out, or if not our intrusion detection will let us know immediately so we can stop a breach while it’s happening.

The current security mindset must move away from outdated thinking about securing the perimeter, assuming that breaches can be ‘protected’ against, ‘detected’, and ‘reacted’ to. With the average time to detection being 120 to 150 days, depending on the source, this clearly is a fallacy. When it comes to data breaches, it is a case of ‘when’ not ‘if’, so organizations must think about how they can best ‘contain’ a hacker from wreaking havoc on their data by adopting a software-defined approach to security and leaving the infrastructure-based security mindset behind. 

  • Data compromise is something that happens to other businesses, not ours!

That’s what all the brands that have been in the headlines over the past 18 months thought as well. The game has changed; it’s no longer about the high profile, kudos-winning breaches. Today’s hacking community is far more focused on the theft of sensitive, critical customer data that will leave those affected with long-term repercussions. Cybersecurity must be a process of continual evolution: just because you feel protected today doesn’t mean you will be tomorrow.
 
About the author: Paul German is CEO at Certes Networks

You Might Also Read:

Zero Trust Architecture - No Longer A ‘Nice to Have’:

 

« Top Nine Technology Trends Of 2021
Facebook Is 'making hate worse' »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

Blue Frost Security

Blue Frost Security

Blue Frost Security provides high-level IT security consulting, penetration testing services, ISO 27001 Solutions, PCI compliance solutions and training.

Cyber Conflict Studies Association (CCSA)

Cyber Conflict Studies Association (CCSA)

Cyber Conflict Studies Association (CCSA) is a non-profit organization dedicated to leading a diversified research agenda in the field of cyber conflict.

Telefonica Tech

Telefonica Tech

Telefónica Cyber Security Tech is focused on the prevention, detection and appropriate response to security incidents aimed at protecting your digital services.

RiskSense

RiskSense

RiskSense empowers enterprises and governments to reveal cyber risk, quickly orchestrate remediation, and monitor the results.

MSG Systems

MSG Systems

MSG are committed to intelligent IT and industry solutions and offer independent consulting on all aspects of information security.

Celare

Celare

Celare delivers DPI based network perimeter monitoring solutions with integrated Big Data security analytics and threat detection.

Think Cyber Security (ThinkCyber)

Think Cyber Security (ThinkCyber)

ThinkCyber is a Tel Aviv-based Israeli company with a team of cybersecurity professionals who are experts in both information and operations technology.

SQN Banking Systems

SQN Banking Systems

SQN Banking Systems fraud detection software products are a critical step towards overcoming the growing problem of fraud across the various payment channels.

AXELOS

AXELOS

AXELOS develops best practice frameworks and methodologies used globally by professionals working primarily in IT management and cyber resilience.

Area 1 Security

Area 1 Security

Area 1 is the only Pay-per-Phish solution in cyber security. And the only technology that blocks phishing attacks before they damage your business.

Orbus Software

Orbus Software

Orbus develops, markets and sells enterprise software which helps large, blue chip and government organisations across the globe to achieve digital transformation outcomes.

Route1

Route1

Route1 is an advanced provider of secure data intelligence solutions to drive your business forward.

Legit Security

Legit Security

Legit Security's mission is to secure every organization's software factory by protecting the pipelines, infrastructure, code and people for faster and more secure software releases.

Mayer Brown

Mayer Brown

Mayer Brown is a global law firm. We have deep experience in high-stakes litigation and complex transactions across industry sectors including the global financial services industry.

BitLyft

BitLyft

BitLyft is a managed detection and response provider that is dedicated to delivering unparalleled protection from cyber attacks for organizations of all sizes.

Tidal Cyber

Tidal Cyber

We formed Tidal for one simple reason—we believe that defenders need and deserve tools and services that make achieving the benefits of threat-informed defense practical and sustainable.