Showing posts with label CIO. Show all posts
Showing posts with label CIO. Show all posts

Thursday, January 12, 2017

(The Big Disrupt) CIO: Why 2017 is going to look a lot like 2016 for CIO's and CISO's






As terrible years go, 2016 was terrible for CIO's and CISO's everywhere as data breaches reached record levels. 2015 was no better and many were predicting 2016 to be worse but few could have predicted Yahoo's reporting a record data leak (on top of another mammoth data leak) or the effect hacking would have on the recent US election as the fallout of both events are sure to spill well into 2017. 

There isn't, or at least there shouldn't  be any CIO and CISO looking upon 2017 with a glass half full as all the problems that has made the last five years a living hell for CIO's and CISO  still exist and in some cases, are almost certainly going to get worse.  

A combination of low transaction costs in favor of hackers, cybersecurity talent shortages and the ever expanding amount of data collected by organizations in both the public and private sector were big reasons why 2016 was the year of the hack and why 2017 will almost certainly follow suit. All these problems are compounded by both companies and governments unwilling share information about breaches with each other which would help avoid the notable trend of enterprise level companies falling victim to the same exploits. 
Hackers on the other hand frequently collaborate and share new malware and exploits which has contributed to why the market for stolen data and malware is arguably the most vibrant and dynamic market on the net. As long as this persists, we'll continue to see a steady stream of news stories that have come to define the year past.  

2016 was trying for CIO's and CISO's but it was abysmal for cybersecurity as an industry as U.S officials openly talked about intervening. While it's not exactly clear whether governments can improve the level of cybersecurity, it's quite clear something has to be done as the industry is the picture of market failure. 2017 won't be any better as calls for the government to get involved will almost certainly get louder despite cybersecurity being a growth market in the face of record year on year spikes in data breaches. 

In sum, CIO's and CISO's know the year ahead will look like the year past and are painfully aware of how little they can do about it as while they do everything in their power to secure their organization's IT infrastructure, they're fighting an enemy that has all the advantages and they know it. This is an indictment of the sorry state of cybersecurity as an industry and its inability to find solutions to combat attackers effectively and should it continue, the most dangerous thing you do all day will be switching on your computer. 

Monday, October 10, 2016

(The Big Disrupt) Cybersecurity: The fine rewards for failure –Why the Cybersecurity industry is set to explode and why that's bad thing






All companies, much like the people who own and work for them, don't like failing and for good reason. Failure means bad earnings, job losses and lawsuits but failure in cybersecurity is currently driving a growth market. 

You might be wondering how this is possible but the answer is simple; bad timing. With the advent of IoT, the internet is expanding into the physical world at a rate CIO's and CISO's can't handle which is why a growing number of the devices we own from fitness trackers, smartphones and even household appliances are vulnerable and at the mercy of hackers looking to steal valuable data to sell on the black market. What makes this worse is that CIO's and CISO's can't hire this problem away as the cybersecurity labour market has been thin. 

The upshot of all this has made cybersecurity the safest career path in corporate history despite organizations across the board reporting large data breaches.  However,  careers are made and lost at a blink of the eye as CIO's and CISO's are often the fall guys when things fall apart. While CIO's and CISO's are naturally targets for blame when an organization experiences a breach, CIO's and CISO's are fighting a losing battle where they're asked to play an expensive game of whack-a-mole where the moles are getting smarter and the holes are expanding.  

Oorganisations, now realising that suffering a breach is question of if rather than when, are coming to grips with the fact that they need contingency plan beyond a hokey and unassuring press release and sharp spike in their legal firm's monthly retainer. In searching for that contingency, a number of organisations have taken out a cyber insurance policy which has turned cyber insurance from a relatively dormant sideshow insurers used to upsell customers  to one of the hottest markets in insurance. Some commentators see cyber insurance as a way to encourage organisations to improve their security posture but with the cover of an cyber insurance policy, organisations also have an incentive to lean on their insurance should the worst happen. 

What all this means is that the expansion of the internet into the real world via IoT couldn't have come at worst time when corporations and governments cannot guarantee the safety of their large computer networks and yet spent billions expanding them creating booming markets in securing devices that predicted to be at least three times number of humans on earth. Insanity is doing the same thing and expecting different results and by that measure just about every major corporation embracing the vast expansion of the internet into the real world are certifiable.   

In sum, cybersecurity is a fine industry if you like job security but if you like to avoid record breaking failure on a yearly basis, cybersecurity is not for you.  


Sunday, June 5, 2016

(The Big Disrupt) IoT security: why IoT could prove to be a terrible idea





The history of internet it has been one of growth and expansion as we're more connected than ever however the timing of the internet continued expansion into the physical world through the Internet of Things couldn't be worse. The internet of things (IoT) has to be one of the most talked about technology with a vast number of companies entering the IoT marketplace but their rush to market has seen them relegate security as an afterthought which, given the scale that IoT operates, is highly irresponsible. 

As mentioned above, IoT is at base an expansion of the internet into the real world which on the face of sounds like a great idea but after some consideration, it just might be one of the worst ideas to come out of Silicon Valley. Connecting a car for example to the internet may sound like a great idea until you remember your driving a car connected to the internet.  

The internet as we know it is a truly strange place at the best of times but introducing an Audi TT on to a network that's all too vulnerable to being hacked is not only careless  but really stupid. The rush to market by so many players in a market tipped to be worth over $1 trillion in next five years is understandable from a business sense but from a security perspective, the players in question are playing with fire. 

Why organizations would be this careless makes no sense as organizations left and right have had their fingers burned to the nub in costly lawsuits  and reputational damage over the last few years as they struggle to secure their networks from external threats and suffer humiliating data breachesWith the advent of IoT and the security concerns that come with it, the recent growth spurts in the cyber insurance and IoT security markets look set to explode in the next few years.    

Expanding the internet through IoT is a truly crazy idea when most CIO's and CISO's expect to get hacked and are at a serious disadvantage as hackers only have find one vulnerability while CIO's and CISO's have to find them all and stamp them out. Add to that that hackers collaborate with their peers and CIO's and CISO 's don't, connecting cars, watches, CCTV cameras, refrigerators, smartphones and the like to a network is a disaster waiting to happen as the people tasked to keep these networks secure are in no position to do so. 

In sum, IoT is likely to be one of the most important technologies in the 21st century but given it's glaring yet unaddressed flaws and the scale it operates at, IoT can also prove to be a truly terrible idea we all might regret. 

LinkWithin

Related Posts Plugin for WordPress, Blogger...