Cybersecurity And Media Companies

Cyber Security expert and former Chief of Staff at the Department of Homeland Security Paul Rosen said at the C-Tech Cyber Security event,

“Broadcast and media companies, like so many others, are seeing two things, an increased frequency of cyber-attacks, and an enhanced sophistication and complexity to such attacks,”

Companies must take responsibility: the reality is that creative media and broadcasting companies are high targets because of their valued content. Knowing your valued assets and being prepared is key, Rosen explained.

“Hackers have the “ability to do great damage to companies, financial, reputational and operational…You can’t eliminate cyber risk in an interconnected world, but you can do a lot to mitigate it.”

Rosen said: “Cyber incidents have legal, practical and policy consequences and addressing cyber security is becoming a mainstream focus of companies.”

The increasingly higher volume of cyber breaches is driving awareness, Rosen said: “Company employees from the board of directors down recognise the need to understand the risks associated with cyber security and protect their businesses from attacks.”

Ultimately it is culture driven; you have to instill cyber ethics across the company.

“Allocating appropriate resources is critical. It can be costly to put in place adequate preventative and response resources, but the cost of ignoring today’s cyber threats can be significantly higher.

“This is why so many business executives at the highest levels are embracing cyber security.”

Mitigating Risk

Rosen oversaw the United States Department of Homeland Security’s (DHS) response to some of the most sensitive and complex challenges including significant cybersecurity events.

Rosen said: “Companies should have a risk-mitigation strategy and a response plan in place to respond when an incident occurs.”

His experience within DHS made clear, “it is inevitable that security breaches will occur, which is why businesses can’t afford to ignore them,” he continued, “If businesses in this industry are going to operate in an interconnected world, media and broadcasting companies need to address what they’re going to do to lessen the cyber threat while continuing to advance their business.

“In homeland security, it is all about promoting security by identifying and minimising risk, while at the same time facilitating business and lawful trade and travel.”

This philosophy can be applied across all sectors, including the valuable content created by the broadcast industry. “When it comes to pre-release media content, big dollars are at stake if there is a hack of that content or a security breach before it is released.”

“Media and broadcasting companies need to address what they’re going to do to lessen the cyber threat while continuing to advance their business”

Rosen said there is good news. Companies and organisations can implement a number of concrete steps to be ready for attacks. “Working with a law firm and forensic firm before an incident occurs” is a useful strategy to have in place.

“Some examples of important prevention measures include regularly patching and backing up your network, and maintaining an updated incident response plan: know the first five steps you’re going to take in the first hours of a beach, including who your outside counsel is.”

He said: “Every threat actor has a motivation, which is important to understand. A nation state actor may have a different motivation than a criminal organisation, for example.

“One may want money while another may be looking to embarrass an executive or business, or may want to conduct an influence campaign by taking over or interfering with broadcasting or media.”

To Pay or Not to Pay

The issue of ransomware and whether a company decides to pay ransom is a complicated decision.

Rosen explained the host of tactics employed by hackers. He said: “One common attack method are phishing emails, where the goal is to get a person to click on a link which leads to malware being downloaded onto a computer or network.”

“Ransomware has presented some unique and interesting issues when it comes to cyber security”

Rosen explained: “Whether to pay a ransom is a business decision, but it may have practical and legal implications that companies together with their counsel should consider. Some of the practical implications include figuring out what bitcoin is and how to get it, if that’s what the attackers want. Who makes the decision within the company about whether you are going to pay, and are you going to coordinate with law enforcement?

“If you are inclined to pay the ransom, companies may also consider whether will be making yourself a target for future attacks? Will hackers see your company and industry as a viable target for future attacks?”

He explained, “Ultimately, when a company is faced with losing $10 million a day, or paying a $10 thousand ransom, executives may see a strong business reason to pay.”

It’s an IT security issue but needs to be understood company-wide. “But there are also potential legal implications of paying a ransom, including US sanctions laws and anti-money laundering controls that companies should explore with counsel,” Rosen said.

“Cyber security hygiene is a growing and an important component to any major business, and I think it’s only going to continue to grow.

“Hackers will find new ways to infiltrate networks, and whether it’s the broadcasting and media industries or some other sector, as long as there is a desire for what you have or to manipulate what you’re doing, the threat of cyber-attacks will continue,” Rosen stated.

Rosen said the key for broadcast companies is: “Plan and prepare in order to mitigate the risk of attacks. And practicing your response to an incident will make you better and more prepared for the real thing.”

IBC.org:

You Might Aso Read: 

French Media’s Emergency Meeting After Isis Hack:

Hackers Steal Game of Thrones Script:

Disney Says Film Hack Threat Was A Hoax:

« Machine Learning is Transforming Data
UK 'biggest audience' In EU For Jihadist Web Content »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC (formerly Reciprocity) is a leader in the GRC SaaS landscape, offering robust and intuitive products designed to make compliance straightforward and efficient.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Teneo

Teneo

Teneo is a Solutions Provider focused on reducing complexity. We combine leading technology with deep expertise to create new ideas on how to simplify IT operations.

CROW - University of Waikato

CROW - University of Waikato

CROW is the first cyber security lab established in a New Zealand educational institution at the University of Waikato.

4N6

4N6

4N6 is a privately-owned firm founded with the goal of providing expert knowledge of computer forensics.

DefenseStorm

DefenseStorm

DefenseStorm is a Security Data Platform that watches everything on your network and matches it to your policies, providing cybersecurity management that is safe, compliant and cost effective.

Havelsan

Havelsan

HAVELSAN is a leading technology company in Turkey developing indigenous systems for domestic and foreign military, public and private sector clients.

Nuspire

Nuspire

Nuspire provide services to protect your network with best-in-class managed detection and response, allowing you to stay focused on managing your business.

R3

R3

R3 is an enterprise blockchain software firm working with a broad ecosystem of more than 300 participants across multiple industries to develop blockchain applications.

Sum&Substance (Sumsub)

Sum&Substance (Sumsub)

Sum&Substance is a developer of remote verification solutions. Our technology allows online services around the world to meet regulatory requirements, prevent fraud and enhance customer confidence.

Cyber Talents

Cyber Talents

CyberTalents is on a mission to close the gap of cyber security professionals shortage across the globe.

Axxum Technologies

Axxum Technologies

Axxum Technologies is a premier provider of Network Communications and Information Technology Security Solutions.

StartupXseed Ventures

StartupXseed Ventures

StartupXseed Ventures is a smart capital provider for Deep Tech, B2B, Early Stage Startups. We support, NextGen Tech Entrepreneurs, who have potential to deliver the outsized growth.

CyGlass

CyGlass

CyGlass simply and effectively identifies, detects, and responds to threats to your network without requiring any additional hardware, software, or people.

Talion

Talion

Talion aim to reduce the complexity involved in securing your organisation and to give security teams unrivalled visibility into their security operations, so they can make optimal decisions, fast.

G-71

G-71

G-71 LeaksID is a cutting-edge ITM technology aimed at safeguarding sensitive documents from insider threats.

Memcyco

Memcyco

Memcyco is a provider of cutting-edge digital trust technologies to empower brands in combating online brand impersonation fraud, and preventing fraud damages to businesses and their clients.

Robosoft Technologies

Robosoft Technologies

Robosoft Technologies is a full-service digital transformation partner. We provide end-to-end digital transformation services in areas including cybersecurity.