Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Partner Perspectives  Connecting marketers to our tech communities.
SPONSORED BY
3/21/2018
09:00 AM
Paul Martini
Paul Martini
Partner Perspectives
Connect Directly
Twitter
RSS
50%
50%

Cybersecurity Spring Cleaning: 3 Must-Dos for 2018

Why 'Spectre' and 'Meltdown,' GDPR, and the Internet of Things are three areas security teams should declutter and prioritize in the coming months.

With each successive data breach, the stakes for companies seem to get higher and higher, with more individuals affected and the costs for remediation escalating. That’s why it’s no surprise that a report published last July by insurance giant Lloyd’s of London estimates that a theoretical global cyberattack could trigger roughly $53 billion in economic losses – a figure that is comparable to record-shattering natural disasters such as 2012’s devastating Superstorm Sandy.

This forecast has serious ramifications for information security teams. It demonstrates that organizations that are following the latest security best practices of 2017 may still need to overhaul their cybersecurity strategy to combat tomorrow's newest, most highly-evolved threats. With spring just around the corner, along with the deadline for the EU's May 24 General Data Protection Regulations (GDPR) deadline, now is a good time for businesses to focus on "spring cleaning" data and company data collection and protection policies.

Here are three areas where security teams can declutter and reprioritize for spring 2018.

Fallible Hardware, Beefed up Security
Just a few days into the new year, security experts discovered a 20-year-old flaw within the processors underpinning the majority of computing devices, unveiling vulnerabilities for almost every individual and business the world over. Called Spectre and Meltdown, the bugs leverage data exfiltration techniques to steal network data after penetrating the network perimeter.

While it’s impossible to stop every threat from entering the network perimeter, security teams should seek out tools that can stop attempts at this kind of data exfiltration in their tracks. Among these tools are a class of so-called data loss prevention (DLP) tools that offer a line of defense when advanced threat detection capabilities that guard the network gateway fails.

New Regs, Increased Measurement & Monitoring
It may seem counterintuitive to suggest that security teams "declutter" by doing more reporting on the activity taking place on their network. But the fact is, in the run-up to GDPR if your existing security tools aren’t keeping tabs on potentially anomalous traffic taking place over the network – especially those related to data collection – your company will be ill-prepared to meet the new GDPR compliance regulations, and a bevy of other rules going into effect in the coming months.

Short- and Long-Term Strategy for Internet of Things
Even if your organization hasn’t yet embarked on a wide-scale IoT deployment you probably will in the near future. IDC Forecasts worldwide spending on the Internet of Things to Reach $772 billion in 2018. As teams continue to beef up their traditional enterprise networks, now is the time to also begin thinking about how they can secure the oncoming enterprise IoT.

What will this entail? Organizations can start by deciding whether IoT devices will leverage the same gateways and network defenses used for standard connectivity on their existing network. Teams may find it more effective to deploy a dedicated network and administration team to manage the high-frequency, low-energy, beacon-sensor transmissions that characterize the IoT in parallel with larger network connectivity.

The Better Business Bureau and the National Cyber Security Alliance offer a valuable checklist for digital spring cleaning strategies. But security teams will need to go above and beyond to make sure their plans, policies, and tools are ready to defend against current and future advanced threats. What better time than now to get started?

 

Paul Martini is the CEO, co-founder and chief architect of iboss, where he pioneered the award-winning iboss Distributed Gateway Platform, a web gateway as a service. Paul has been recognized for his leadership and innovation, receiving the Ernst & Young Entrepreneur of The ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Ransomware Damage Hit $11.5B in 2019
Dark Reading Staff 2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5243
PUBLISHED: 2020-02-21
uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent hea...
CVE-2019-14688
PUBLISHED: 2020-02-20
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial produc...
CVE-2019-19694
PUBLISHED: 2020-02-20
The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malicious actor could manipulate a key file at a certain time during the system startup process to disable the product's malware protection functions or the ...
CVE-2020-5242
PUBLISHED: 2020-02-20
openHAB before 2.5.2 allow a remote attacker to use REST calls to install the EXEC binding or EXEC transformation service and execute arbitrary commands on the system with the privileges of the user running openHAB. Starting with version 2.5.2 all commands need to be whitelisted in a local file whic...
CVE-2020-8601
PUBLISHED: 2020-02-20
Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product installer to load other DLL files located in the same directory.