Comments
Black Hat Survey: Security Pros Expect Major Breaches in Next Two Years
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
7/13/2017 | 7:36:06 AM
Defining "cyberattack"
> Sixty percent of respondents to the Black Hat survey believe that a successful cyberattack on U.S. critical infrastructure will occur in the next two years.

How loosely or strictly are we defining "cyberattack" here?

Because, depending upon the definition, there have already been such successful cyberattacks.

Case in point from six years ago here: pastebin.com/Wx90LLum
Dario.Forte
50%
50%
Dario.Forte,
User Rank: Author
7/10/2017 | 9:08:48 AM
Disparity in priorities
I think the concern over the disparity between the practitioner priorities and those of top management in their organizations is probably one of the most relevant of the survey and it denotes a misalignment between business and technical requirements. While it is clear that compliance is a driver (and probably it always will be), the importance of creating a common playground for technical and business management is mandatory. I think GDPR will provide a huge opportunity to create (and maintain) this common layer, as it is a clear example of how compliance cannot be reached without technical execution.
tcritchley07
50%
50%
tcritchley07,
User Rank: Strategist
7/7/2017 | 9:57:54 AM
Re:Breaches over Next 2 Years
The 'breach' (in its broadest sense) figures are climbmg inexorable despite all the talk and flannel os vendors and consultants. It is like fixng rust spots on a rust bucket car whre as soon as you fix one, another appears. This will never work and the whole issue needs a new, solid cybersecurity architecture. This will take much of the onus off the end user or organisation and quite rightly. When I fly, I am not expected to take my own oxygen, life vest etc. It is supplied by the body that sold me the ticket. We expect the equivalent of users/organisations over cybersecurity.

The architecture wil inevitabky involve:

1. Changes to existing internet SW (DNS, Windows etc.) or even scrapping and repleacing. This will allow intimate knowledge of 'user', whether good guy or bad guy, including location, SW level, his PC ID/serial no. etc.

2, Hardware innovation such as built in memory and storage encryption.

3. Judicious data placement ( I am working on this) and other tricks of the trade to prevent malicious encryption and possibly make it theft-proof. These things will not happen by fiddling, patching and twiddling with the current setup. The internet is open, was conceived that way and the SW around it reflects that ethos. It MUST change if we are to have true security.

4. The redoubt (miltary fallback for a last stand); this means a proper disaster recovery (DR) plan where the organisation or user is not wiped out when data is lost (deleted) or encrypted. The recent UK NHS Wannacry debacle showed the need for, and in this case the absence of, a good, rapid recovery DR plan.

If you think about this you will see the sense in it. The architecture must be agreed by all (conforming nations at least) which will get over the disaster I see promised by the dozen or more cybersecurity initiatives being developed by government bodies and other bodies. If they all come to pass, I dread to think what will happen when a system with cybersecurity 1 tries to talk to one with cybersecurity 6; it will be 'request rejected. I don't recognise you'. Take a look at the US and UK cybersecurity initiatives as a starter, then look at all the cybersecurity vendors (about 50 or more) and what their initaitives are and you will see what I see as a final result; a complete dog's breakfast'.

Terry Critchley
Joe Stanganelli
0%
100%
Joe Stanganelli,
User Rank: Ninja
7/6/2017 | 12:30:41 PM
2 years, and compliance
Coincidentally, as per an old stat that's been floating around a few years now (from Gartner, I think? I don't quite remember) indicating that within two years of a major breach, a small business goes out of business.

On a separate note, I'm not sure how I feel about compliance gaining a bigger percentage of the "top priority" pie here. On the one hand, it's good to see more security pros taking it seriously. On the other hand, it's kind of sad when you think about it that compliance has to take so much away from actual security and privacy issues. While compliance can help make you way more secure, compliance and security are not the same thing -- and, sometimes, even contradict each other!


Cybersecurity's 'Broken' Hiring Process
Kelly Jackson Higgins, Executive Editor at Dark Reading,  10/11/2017
How Systematic Lying Can Improve Your Security
Lance Cottrell, Chief Scientist, Ntrepid,  10/11/2017
Ransomware Grabs Headlines but BEC May Be a Bigger Threat
Marc Wilczek, Digital Strategist & CIO Advisor,  10/12/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.