SecChat

Threat Predictions 2016
Threat Predictions: January 2016 from Intel Security Biz
SPCoulson
And that was #SecChat - awesome - thank you everyone. I'll blog my answers with some comment shortly. #HiddenText
Wesley Budd
thank you :) my first one and v interesting! Would like to know more on the skills gap and cisos focus
SPCoulson
If you fancy talking offline about this - I'll be writing up a blog on this tonight - get in contact at hiddentext.co.uk
SPCoulson
just noticed who you work for ... Google Qinetiq Masterclass and see what you guys did in November ;)
Wesley Budd
oh dear! I m embarrassed I didn't know this! 😳
SPCoulson
big company - a lot to know about !
Wesley Budd
What's people's thoughts on the new eu gdpr rules? Will businesses take it seriously?
SPCoulson
no- I'm already seeing people rolling their eyes "Yet more legislation!"
Wesley Budd
I would have agreed but am hearing it's one of a number of key reasons for taking classification
Wesley Budd
Maybe a soft reason?
Howard Fuhs
Well, they must as soon it became law in the EU. The question is what fines will they face if they fail to comply
Howard Fuhs
No serious fines no serious compliance
Wesley Budd
That's the fuzzy part about it I guess. Either of you seen any surveys or reports from biz on it at all?
SPCoulson
so true - if the fine isn't big enough then why do it
Howard Fuhs
PCI DSS is quite a nice example - initial compliance was due 2007/8 and even today some companies haven't managed to comply
Wesley Budd
Going to an event based on PCI DSS next week. Can get a show of hands on it maybe. Agree Stuart, if biz is happy to take a hit then they will...
Wesley Budd
Well we shall see. I'm pushing to get a survey from cisos on it. Hopefully mid year we might have something
SPCoulson
A3) Big data leaks caused by lack of security being implemented correctly in cloud infrastructures
Howard Fuhs
or by the lack of overview of the systems in use
SPCoulson
A10) all tech to have a step which considers security and a statement that explains how they met it
SPCoulson
A10) filling the skills gaps by recruiting into areas we need and allowing seniors do their proper jobs
Wesley Budd
how big is the gap? Finding good technical pre-sales is tough!
Howard Fuhs
because no company wants to invest into educating their own people
SPCoulson
Senior analysts shouldn't be doing the basics, they should be doing the hard stuff, juniors should be doing the simple stuff
SPCoulson
look at what I do with the cybersecuritychallenge(.org.uk) finding new talent. There are ways - even up-skilling own staff
SPCoulson
A10) Stop selling blinky cyber LEDs that are not effective.
Wesley Budd
What are the biggest threats to biz this year then?
Howard Fuhs
Human stupidity
SPCoulson
Totally - it'll be the meatware that will threaten business
Wesley Budd
Lol @ meatware! :) give the right tools to the end users to prevent them doing stupid!
Howard Fuhs
no, give them no tools to prevent doing stupid things
Wesley Budd
Remove computers?
Howard Fuhs
Nice idea but impractical. Provide them with a proper environment which prevents stupid things to be done
Wesley Budd
Agreed whole heartedly! So based on what we think are threats what do you think cisos will be investing in for 2016?
Howard Fuhs
This is going to be a long list - lets start with Business Continuity - when the sh**t hits the fan
Howard Fuhs
proper infrastruture planning and maintaining
SPCoulson
Cisos will be looking at:
Stopping the insider threat,
Monitoring their data to see who's using it and how
Ensuring they know what to do when IT happens
Supplier reputation
Upgrading old kit when budget allows
SPCoulson
Securing more infosec budget
Wesley Budd
So a focus on DLP and classification together with reporting?
SPCoulson
Even just the basics - an understanding as to what needs protecting and how
SPCoulson
A10) Get users to understand what secure looks like and how they can get there.
Wesley Budd
they need to be dealing with security every day. Only way to promote security and drive awareness.
Howard Fuhs
give them the right environment which prevents stupid things to be done
SPCoulson
A10) home security tech. Plug in devices to secure the home.
SPCoulson
A9) The legislation will only be good if it done by someone who knows what secure looks like