Category Archives: Articles

Computer Weekly – Think Tank

I provided a response to the Computer Weekly Think Tank question ‘What should corporate IT managers do to ensure data protection?’:

Hacks of Google and at least 20 other companies in December prove that sophisticated cyber espionage attacks are a real and present danger. But in the light of the fact that most commercial security tools are ineffective against these attacks, according to the SANS Institute, what can and should corporate IT managers do to ensure data protection?

“Few organisations have the resources available to Google, who were still unable to prevent or readily detect the recent wide-scale electronic espionage, and most are unlikely to work with the National Security Agency after a compromise. Yet, organisations that form part of the UK critical national infrastructure (CNI) have for years received government advice and guidance on threats, including those emanating from China, from the Centre for the Protection of National Infrastructure (CPNI). Although its private advice is not readily available, the CPNI website provides non-classified information that non-CNI businesses should be aware of.

Many organisations tend to focus on preventative measures – policy, procedure, and technology – and fail to fully address the detective and responsive controls required for good information security management. Log analysis, required for firewalls, intrusion detection and data loss prevention, is resource intensive, requires expert interpretation of results and is not particularly appealing, but is necessary to detect anomalous behaviours. A robust incident reporting and management procedure is also required, along with an associated forensic readiness plan.

Every organisation should understand the need for regular upgrades and patches, after adequate testing and planning, for all vulnerable systems. Sometimes this is set aside for operational expediency, for critical systems where downtime or the risk of failure is unacceptable, or due to backward compatibility requirements, for legacy applications or platforms  – but the risk posed by the failure to upgrade or patch must be mitigated by additional controls that compensate for the vulnerabilities. Defence is depth, or layered security, would mean that a single weakness or vulnerability does not expose everything.

Common factors in this and similar attacks is the level of research and targeting that goes into them, not just utilising multiple zero-day vulnerabilities in IE6 and Adobe Acrobat, but directing the attack at specific people with sufficiently contextually correct information to trick them into effecting the compromise. The attackers appear patient and with long-term goals, rather than seeking money or glory, which makes them all the more insidious. A long-term strategy of user awareness training and education is required to combat this threat, in conjunction with technical and procedural security measures.”

The full articles is available online at:

http://www.computerweekly.com/Articles/2010/02/15/240300/Think-Tank-What-should-corporate-IT-managers-do-to-ensure-data.htm


ISNow – Coming Threats

The following introduction was originally published in the BCS Information Security Now Magazine, Winter 2009/10 issue (Volume 4, Issue 2), which was on the topic of Coming Threats:

“The start of each new year brings the promise of a bevy of unwelcome threats. Many will be variations on an existing theme, some may rely on the growth of a particular medium, and there could be an occasional new but predictable attack that leads us to smack our foreheads and wonder why we didn’t see it coming.

I’m no soothsayer, but I have a few ideas of threat-related trends we may well see in the coming year:

Business Change

The global downturn, recession, comeuppance for greed and risk ignorance, or whatever you wish to call it, threatens business. This could be through redundancies, liquidation, jettisoning failing companies and mergers, all of which will bring significant business changes that have to be managed securely, ensuring that critical business assets are properly protected.

Cloud Computing

Bringing together all the benefits and pitfalls of outsourcing, off-shoring, virtualisation, co-location and rapid application development. Great when it works, but when it doesn’t there may well be issues of legal jurisdiction, enforcing contract and audit rights, forensic investigation, data migration and so on. Make sure the cloud doesn’t become a basket to hold all your eggs.

Social Networking

Website, email and instant messaging wrapped up into one. Already allowing ready personal and business information leakage through to providing a new platform for malware distribution and botnet command and control, the social networking phenomenon offers unrivalled growth for interaction, both good and bad, which is likely to continue unabated.

I’m sure this only touches the tip of the iceberg, and we may well see more large-scale politically motivated attacks, new vulnerabilities in core internet services, smartphones get hit hard, growth in internet governance (read interference, control and surveillance) along with new ways to avoid it.

Happy New Year.”

A PDF version of the magazine is available online at:

http://www.bcs.org//upload/pdf/isnow-winter09_1.pdf

ISNow – Insider Threat

The following introduction was originally published in the BCS Information Security Now Magazine, Autumn 2009 issue (Volume 4, Issue 1), which was on the topic of Insider Threats:

“The insider threat is not new. But when companies seek to make cost savings by divesting themselves of their biggest assets, especially during a recession when uncertainty amongst the workforce is likely to be heightened and financial pressures felt more acutely, the likelihood and impact of the threat may increase. Normal controls, such as separation of duty, audit and training, may well get left behind as the remaining employees each try to do more, due to necessity and self-preservation. Whereas a company making significant changes should review their risk assessments, which may show increased controls are required.

Taking away data
Research appears to bear out the view that staff will take information when they leave a business, and may also exploit that information in any future role. Indeed, senior management and IT staff seem more likely to take information in their possession, which may be more valuable and accessible due to their roles.

Logic bombs
Recent scandals in Formula 1 have demonstrated the value of competitor intelligence, however obtained, and secret arrangements being exposed. Also, in the last few years there have been a number of cases of logic bombs, left just in case the person lost their job, and passwords being changed on departure.

Robust contracts
When dealing with an insider threat, the whole gamut of people, process and technology controls should be considered, preferably in that order, to help mitigate the risk; including robust contracts, staff screening, training, awareness, information marking, handling, access based on business need, role and least privilege, separation of duties, logging/audit, data loss prevention and so on.”

A PDF version of the magazine is available online at:

http://www.bcs.org//upload/pdf/isnow-autumn09.pdf

ISNow – Data Loss & Data Leakage

The following introduction was originally published in the BCS Information Security Now Magazine, Summer 2009 issue (Volume 3, Issue 4), which was on the topic of Data Loss and Data Leakage:

Data Loss
Data loss prevention should be less about deploying the latest technology that claims unrivalled capabilities in securing all the data you value, rather it should be about having the right data policies, procedures in place along with suitably educated and motivated people, who can act as your data guardians.

The lack of universal technical control will always leave gaps for data to be deliberately exfiltrated or accidently exposed, but without comprehensive and effective data policies and procedures, and the people to support and enforce it, technology cannot provide a solution to your data management ills.
It is key that data procedures cover at least:

  1. how the organisation assigns a value to its data and information, i.e. values its assets;
  2. how its categorises and marks data, in relation to its value or sensitivity;
  3. how it assigns rules for handling data throughout its whole lifecycle, especially for personal information.

In a recession, the impact of the loss of corporate or customer data can be amplified and leave your organisation more vulnerable to disaster than before. The actual or suspected loss of information should be covered by your organisation’s incident response or business continuity plan.

Data Leakage
People can be shocked and concerned when media-friendly volumes of data are lost or exposed, even though only a tiny proportion may directly relate to or affect them, yet they volunteer personal information to near strangers when using the Internet and think very little about the implications of doing so.

With their photos, blogs, CVs, social networks, and contributions to online discussions individuals can provide the greatest insight and intrusion into their online and real world lives, and also the lives of their friends and family who may not have consented to their information being shared so openly.

Maybe each Internet connection should come with a health/wealth warning…”

A PDF version of the magazine is available online at:

http://www.bcs.org/upload/pdf/isnow-summer09.pdf