CyberSecTalk

Cyber Security Open Microphone
Open microphone discussion about all things related to Cyber Security
Ratan Jyoti
Q. #bitcoin laundering techniques are widely used by #Cybercriminlas. What do you think how can we tackle this?
Dez Blanchfield
- the research tracking down the Bitcoin washing has been very interesting to watch..
Tony Flath 🎙 Podcast
it's a good point how to block #bitcoin when its all about #blockchain
Ratan Jyoti
@TmanSpeaks @dez_blanchfield There should be strategy to use #blockchain, which is the digital database that can record #bitcoin transactions. This will help monitor, manage and track worldwide shipping #bitcoin transactions.
Tony Flath 🎙 Podcast
yes so better visibility of #bitcoin and pursuing cyber criminals but a while before #blockchain @dtapscott love to hear from you
Ratan Jyoti
Since the transactions made using the #cryptocurrency like #Bitcoin are completely anonymous and so #cybercriminals love to do this and hence #Cybersecurity needs to be built in.
Tony Flath 🎙 Podcast
this is so true how do you identify the bad guy here
Tony Flath 🎙 Podcast
this is why moving beyond port and protocol is so important and get beyond just the perimeter
Ratan Jyoti
@TmanSpeaks Solution lies in how miners verify transactions and find a block can accept the transactions. If they are "bad" or "malicious" miners, it can broadcast the bad block. Feels solution should be within the #Blockchain. ALL THESE ARE MY ASSUMPTIONS
Tony Flath 🎙 Podcast
yes but blockchain will certainly play a part here @dtapscott would love your insight
Kevin L. Jackson - (ISC)2 CCSP, Swansea, UK
#Blockchain has tremendous value as an e-commerce tool. Marketplace forces will weed out the bad actors @reach2ratan
Dez Blanchfield
@Kevin_Jackson any key names you can share who are already down this path Kevin?
Dez Blanchfield
@TmanSpeaks keen to get more insight here Tony, fire away .. what are the top 3x value points do you think?
Tony Flath 🎙 Podcast
@dez_blanchfield 1. #blockchain may have potential to be record of source but long time to adopt
Tony Flath 🎙 Podcast
@dez_blanchfield 2. the current environment is ripe for the picking for #cybercrime
Tony Flath 🎙 Podcast
3. need to follow a secure by design approach
Tony Flath 🎙 Podcast
check Kevin's suggestions out thanks @kevin_Jackson
Ronald Gruia
Blockchain can reveal all the transactions but there could be exploits to keep some of those hidden (I guess). Bitcoin has become popular in places like Venezuela to help solve the pain point of transferring cash out of that country.
Veredictum
Full auditability & transparency of #blockchain #bitcoin #cryptocurrencies you can track bad guys' payments IF you know the source.e.g. DAO attacker last year - the auditor of our Token Sale smart contract monitors those stolen funds even now
Veredictum
but with other #cryptocurrecnies such as #monero & #zcash it is harder as they tumble payments through ring signatures.
Ratan Jyoti
State sponsered actors are one of the biggest cyber threats. Your views please
Tony Flath 🎙 Podcast
wow sure seems to be the case will be interesting to find out more @dez_blanchfield
Dez Blanchfield
- I don't have data to back that up currently, what are you basing this on Ratan?
Dez Blanchfield
- my data indicates that we're far more at risk from roge lone wolf script kiddies and breach data traders..
Dez Blanchfield
@TmanSpeaks - interesting view fro Ratan, but let's get some data and references to back this up..
Ratan Jyoti
@TmanSpeaks @dez_blanchfield I also do not have any authenticated data
Tony Flath 🎙 Podcast
interesting world and interesting topic to say the least!
Ronald Gruia
The biggest threat I see for this type of attack vector are obsolete systems used by verticals such as public utilities, national healthcare systems, even municipally owned traffic signaling systems.
Tony Flath 🎙 Podcast
@dez_blanchfield @rgruia yes so true have to get the frogs falling from the sky to get them to upgrade and it's in their best interest
Dez Blanchfield
@rgruia - love to hear your top 5x bullet pointed "first steps" here then?
Kevin L. Jackson - (ISC)2 CCSP, Swansea, UK
#Cyber is a very cost effective geopolitical tool @reach2ratan. That's why nation states love it.
Ratan Jyoti
@kevin_Jackson Both public and private entities are leaving sensitive and monetisable data unprotected or less protected . Given the very high rewards and very low risks for these #cyberattacks, nation-states appears to be more active than ever.
Tony Flath 🎙 Podcast
so true GDPR will ultimately evolve globally to better control
Suresh Prajapati,
Yes this is era of #Cyberwars #Drones and #Intelligence ..# CyberArmy will deiced he fate of any war in coming days..#China and Russia are top in State Sponsored #CyberAttacks
Dez Blanchfield
Q2: who do you think should be taking the lead in Communicating organisational Cyber Security needs, CEO, CIO, CRO !? Who?
Tony Flath 🎙 Podcast
it's probably at CIO even CFO in some mid sized organizations but CISO is best
Ratan Jyoti
@TmanSpeaks Yes #CISO is the best answer. but IF CISO, CIO and CRO speaks a common language, that should be the best case
Tony Flath 🎙 Podcast
More organizations need to appoint a #CISO
Ratan Jyoti
@TmanSpeaks Ture The board level interest requires a risk based #Cybersecurity approach, and #CISO must adapt and embrace this for the success of #Cybersecurity and #Infosec
Tony Flath 🎙 Podcast
@reach2ratan love to get your perspective to how to communicate most effectively on cyber security even top 3
Ratan Jyoti
@TmanSpeaks #CISO should communicate to board about #Cybersecurity 1. in pain English without using the technical jargon 2. Visual aids are better and effective 3.If you can convert #Cyberthreats to Dollars it would be the best
Ian Moyse
All of the above - anytime someone things Cyber is someone elses remit it dilutes the focus
Tony Flath 🎙 Podcast
@imoyse great point Ian thanks for joining in!
Kevin L. Jackson - (ISC)2 CCSP, Swansea, UK
CEO must be the Team Captain with the #CISO serving as the Head Coach @dez_blanchfield http://kevinljackson...
Kevin L. Jackson - (ISC)2 CCSP, Swansea, UK
A2. CEO must be the Team Captain with the #CISO serving as the Head Coach @dez_blanchfield http://kevinljackson...
Tony Flath 🎙 Podcast
Yes @kevin_Jackson so agree! and the #CISO needs to be at CEO/Board level exposure and hierarchy
Ronald Gruia
CIO, CSO, and even some CXOs
Suresh Prajapati,
I think CEO is the one who can lead and make Security as business critical and CISO is always to support it.