
Sign up to save your podcasts
Or


With the rise of cybercrime comes the need for cyber forensics, and this episode’s guest, Dr. LeGrande Gardner has been in the field of digital evidence for more than 30 years. Currently, he is an instructor in the Criminology Department at the University of South Florida, where he also serves as the Director of the MS in Cybercrime degree program and administrates the Graduate Certificate Program in Digital Forensics.
Co-hosts Bill McQueen and Ernie Ferraresso joined Dr. Gardner for a discussion about digital evidence, its role in the justice community, and opportunities for the future. The field of cyber forensics started rather simply, as a way to detect and connect the pieces of a crime. As evidence was being submitted into the justice system, a need for increased scientific methodologies and protocols grew to preserve legal integrity and the rights of the accused.
Cyber forensic professionals are able to examine a range of devices, networks--even the cloud--to uncover criminal activity and gather evidence that can lead to legal prosecution. Dr. Gardner discusses how advances in computer science have made an impact in the ability to locate criminals. In his first example, he shares how hash algorithms are used to catch pedophiles and provide a digital footprint to catch larger pedophile rings. Next, he details the Target breach, where criminals were able to hack the nationwide retailer via their air conditioning’s computerized system. Then, he talks about how search warrants involving cybercrime uncovered how criminals were using their neighbor’s open IP addresses, putting routers unknowingly in their attics, and other deviousness that thwarted detection and capture. Unfortunately, Dr. Gardner reveals, international criminals are even more elusive, but that having solid cyber forensics can help law enforcement agencies from multiple countries coordinate efforts.
Cyber forensics now has several sub-specialties, such as cloud forensics, network forensics, malware forensics, IoT forensics, and vehicle forensics. Many colleges and universities are developing programs and training around these expanding and evolving sub-specialties. Dr. Gardner points out that this is a great time to be a cybercriminal and there will be an increased need for cyber forensic technicians and digital evidence specialists to combat the widespread crime.
There is a push for law enforcement officers to receive training in cyber forensics to facilitate crime scene collections, recognize patterns, and maintain protocols. Dr. Gardner’s history in law enforcement and as a Task Force Agent with the FBI’s Cyber Crime Unit gave him a special insight to device and data collection at crime scenes and he shares his thoughts on training opportunities in police academies.
Hackers and cyber criminals aren’t the only reasons the field of cyber forensics is growing. Corporations are also employing their own forensic teams. Companies use digital evidence to substantiate their security and to protect themselves if a situation with an employee requires documentation. Civil matters are increasingly including digital evidence, and professionals are being called upon to provide expert testimony.
The need for cyber forensics professionals is growing exponentially, according to Dr. Gardner. There is no end in sight for the potential of this field and the importance it will play in protecting our security and stopping crime.
TIME STAMPS
00:43 Meet Our New Co-host: Ernie Ferraresso, Associate Program Director of Cyber Florida
02:43 Who is Dr. LeGrande Gardner, Director of the MS in Cybercrime Degree Program, University of South Florida
03:15 What is Cyber Forensics and Digital Evidence?
04:47 Recognizing the field of Cyber Forensics
05:59 Following the Rules of Evidence and Procedure
06:33 The Growing Impact of Digital Evidence and Digital Exploitation
07:35 Evolving Field of Cyber Forensic Careers
08:58 Collecting Cyber Forensic Data
09:51 Digital Evidence as a Science
12:52 Components of Digital Evidence
13:45 Hash Algorithms, Digital DNA
14:25 Child Pornography Hash Algorithms
14:55 Hash Algorithms are like Fingerprints
16:37 Verifying and Preserving Digital Evidence Using Scientific Protocols
18:29 Training to be a Cyber Forensic Technician or Specialists
21:34 Specialized Cyber Forensic Fields
24:01 Criminals, Digital Evidence & Law Enforcement
26:30 Training Law Enforcement for Digital Evidence Collection
28:24 Finding Breaches and Identifying Vulnerabilities
31:00 How to Start a Cyber Forensic Investigation
31:29 Cyber Forensic Incident Response
34:38 Cyber Police of the Future
35:35 Trends in Cyber Forensic Prosecutions
37:05 International Cyber Criminals and Cyber Forensics
38:19 Every Cop as a Cyber Cop
38:39 How is Cybercrime Changing
41:26 The Future of the Cyber Forensic Field
42:24 Corporate Digital Forensic Units and Civil Courts
44:43 Cyber Forensic Academics, Digital Certifications and Careers
Kerry Long’s role at IARPA is to make the Intelligence Community more secure in the tech world. His vision of the future of cloud computing is to fundamentally change the way we use computers to be more secure. His hope is to redesign how all of us interact with computers to get ahead of hackers and breaches. His program, VirtUE, will soon be released to the world as open source code to promote cloud security and ingenuity. He also philosophizes about what cyber space really means as the only truly human-created domain.
When asked what is the most critical aspect of cloud security, Mr. Long answered, “Depending on users to secure their environment.” The current shared service model has cloud hosts providing a hypervisor (or virtual machine monitor [VMM]) and physical security of the data center while the user is responsible for their own data security. Most users are not security experts and they shouldn’t be, as Long argues that the cloud providers need to take on more security responsibilities. He points out that small-to-medium-sized businesses rarely have adequate IT resources to properly secure their own servers and, therefore, the cloud is a much more secure option because of hypervisors and other systems being updated nearly every day.
Long goes on to detail how we build things without knowing the ramifications because engineers can’t fathom every possible way a user would or could use it. The problem with pre-cloud computing is that we were stuck with those decisions for decades. “What I love about the cloud is it constantly gives you a chance to do-over.The cloud is anything that we want it to be. The cloud providers change out their infrastructure every 18 months to two years with brand new hardware. They are innovating and adding new things every week, every two weeks, and taking things out that don’t work. It’s an amazing opportunity as an engineer to say ‘hey, actually I thought I was smart, but I’m smarter now.’
VirtUE (Virtuous User Environment) is an IARPA program managed by Mr. Kerry Long that is an example of using the cloud and re-engineering it to be more secure for tomorrow. Traditional memory computers are running too many roles at once while in comparison cloud computing can separate roles. VirtUE is trying to engineer ways to make the separate environments function seamlessly for users while maintaining the security. This program is coming to an end soon, and will be released as open source code for the world to examine and work on.
VirtUE is related to SCITE (Scientific advances to Continuous Insider Threat Evaluation)
Link to IARPA: www.iarpa.gov IARPA facilitates the transition of research results to their Intelligence Community customers for operational application.
Link to IARPA profile for Kerry Long: https://www.iarpa.gov/index.php/20-program-managers
TIME STAMPS
00:07 Cloud Computing
01:11 Who is Kerry Long, IARPA, Cybersecurity
02:00 Mission of IARPA
02:45 Cloud Security and Potential of Cloud Computing
03:59 Getting Ahead of Security Breaches
05:35 What is the most critical aspect of cloud security?
07:11 Cloud security options for businesses and individuals
09:58 What data is at risk of being stolen?
12:38 Cyber Engineering
13:50 Cloud Engineering & Infrastructure
15:18 What is a VirtUE – Virtuous User Environment?
18:59 How Safe is our Cyber Community?
21:00 Redesigning Computing with the Cloud
23:22 The Future of Computing
24:18 VirtUE as Open Source
This is part two of a two-part special edition that was recorded at the 2019 Cyber Florida Conference. In the first part, a panel of cybersecurity experts discussed “Cybersecurity and the C-Suite,” while the second part discusses partnerships and opportunities that bridge the gap for qualified cybersecurity personnel and our interconnected cyber ecosystem. The panel was moderated by Sprint’s Chief Information Security Officer Mark Clancy. On the panel sat three cybersecurity professionals who have years of expertise: Diane Janosek, Commandant of NSA's National Cryptologic School; Andy Zolper, SVP, CISO, and Head of Technology at Raymond James Financial; and Terry Roberts, CEO and Founder of WhiteHawk, Inc. (To learn more about Janosek, Zolper, and Roberts, listen to the The No Password Required Podcast episode titled “Cybersecurity in the C-Suite.”)
This No Password Required episode began with the question, “What can the big guy do to help the small guy?” and panelists discussed the role of large corporations and technology service providers. Often small-to-mid-sized organizations are understaffed when it comes to their IT department and/or they are solely reliant on external providers for their security. Many larger organizations and service providers are making the investment to provide advanced security protocols because it impacts their products and, for some, it gives them a competitive edge in the marketplace. Larger corporations and service providers are carrying the responsibility of protecting smaller organizations, but it is a symbiotic relationship. Smaller organizations must do their part to have good cyber hygiene and understand their risks and their roles in preventing those risks.
Motivating smaller organizations to have a proactive cyber culture is often dependent on two things: communication and risk. A panelist emphasizes that the success of motivation revolves around language. The key to communicating with C-level executives and business stakeholders is to provide information as it relates to them, using their industry-specific lingo, demonstrating their profit and loss potentials, and illustrating how it impacts their community. By answering “how can we partner in a way that shows that we want to mitigate risks to a point that we’re a stronger business partner” can solve some of the gaps in cybersecurity. “Don’t wait for someone to offer, ask,” is the advice of Andy Zolper when it comes to mitigating risks.
Mark Clancy asked the panel, “How do you cyberize the CEO?” Cyberizing the CEO often begins with a review of their cybersecurity risk profile. By mapping risks to reputation and quantifying revenue to business impact can be the necessary wake-up call. “Cyberizing” was a phrase coined in part 1 of this series that is interpreted as educating/training C-level professionals to understand their company’s tech, their role in cybersecurity and operations, and their leadership in corporate cyber culture. “Cyberizing” encourages insight that helps build an adequate IT team or relationship with technology service providers. Cyberizing naturally encourages investing in employees as the greatest assets. It holds the belief that employees are responsible for maintaining good cyber hygiene, managing customer and partner relationships, and evolving with technology.
Another solution offered is “cyberizing the principal.” This involves instilling the value of cybersecurity as soon as a child is handed technology. One panelist advocates for developing educational programs that incorporate cybersecurity in programs from elementary to college, with her belief that it will carryover good cyber hygiene from the home to the public and business sectors.
Another component of closing the cybersecurity personnel gap is by encouraging information sharing in new ways, as well as, encouraging IT professionals to transition through various sectors and educational opportunities to keep their experience fresh and relevant. The panel discussed some of the current issues and possible solutions that involve sharing information, the importance of nonprofit interlocutors, the problem with classified versus unclassified information sharing, zero trust, and more. The cybersecurity experts also discussed educational opportunities, crossover through sectors and the role of leveraging academia and cyber labs to find solutions.
In the final segment of the podcast, the guests discuss some of the highlights of the 2019 Cyber Florida Conference and list topics that they would like explored at the future conferences.
You can find part 1 and 2, as well as other episodes of No Password Required Podcast, on our website at https://cyberflorida.org/podcast/. This special edition was recorded at the 2019 Cyber Florida Conference in Tampa, Florida. Learn about upcoming Cyber Florida events, including the Annual Conference, at cyberflorida.org or follow us on social media.
TIME STAMPS
01:30 Partnering Competitively & Cyber Ecosystem
07:17 Cyberizing the CEO
10:43 Cyberizing the Principal
13:48 Public-Private Partnerships
15:51 Nonprofit Interlocutor & Scaling Partnerships
17:32 Collaborating for Information Sharing
19:00 Zero Trust
24:42 Classified vs Unclassified Sharing
25:30 Surprises from the Cyber Florida Conference
During Cyber Florida Conference 2019, a panel of respected cybersecurity experts gathered to share their insights on how cybersecurity impacts the C-level professional, changes in accountability and business models, and what it means to build a cyber-strong workforce. The panel was moderated by Mark Clancy, Chief Information Security Officer (CISO) for Sprint. The esteemed guests on the panel were Diane Janosek, NSA Commandant of the National Cryptologic School; Andy Zolper, SVP, CISO, and Head of Technology Infrastructure for Raymond James Financial; and Terry Roberts, Founder and President of WhiteHawk, Inc.
C-level professionals have been a driving force in developing business and securing infrastructures. Recent breaches resulting in CEO firings and similar repercussions are impacting the way many C-level leaders are engaging with technology and their workforce’s cyber culture. Cyber Florida took the opportunity at the conference to help both the C-level professionals and stakeholders who are part of their decision-making process with a discussion titled “Cybersecurity and the C-Suite.” The panelists discussed why it is vital for C-level executives to embrace cybersecurity education and innovation. The experts spoke to what factors C-level leadership face in their organization and workforce in relation to security, networking, and data fundamentals. A large portion of the conversation focused on identifying what it takes to onboard a workforce in this computer-centric modern life (with the phrase “cyberize” being coined to discuss the process), and understanding the crossover that is occurring because of the inter-connectivity of roles and risks.
Panelists discussed case studies and resources, such as cyber executive programs, where C-level professionals can:
This is a two-part edition with the second part discussing the personnel gap in cybersecurity and what can be done about it. You can find parts 1 and 2, as well as other episodes of No Password Required podcast, on our website at https://cyberflorida.org/podcast/. This special edition was recorded at Cyber Florida Conference 2019 in Tampa, Florida. Learn about upcoming Cyber Florida events, including the annual conference, at cyberflorida.org or follow us on social media.
TIME STAMPS
00:42 Who is Diane Janosek, Cybersecurity Expert, Cyber Security Woman of the Year
02:03 Who is Andy Zolper, CISO at Raymond James Financial
02:45 Who is Terry Roberts, Cybersecurity Exchange
03:58 How to Communicate Cybersecurity to Leadership
07:25 C-Level Accountability, Cyber Risk Ratings are a Commodity, Cyber Executive Program
09:53 Hiring a Cybersecurity Workforce and Training a Cybersecurity Culture
15:55 Innovation in Education for Cybersecurity and Cyber Risk Training
18:50 Identifying, Leading and Managing Critical Skills
21:54 Cyberize Your Team, Workforce Crossovers, and Cyber Defense Ecosystem
26:07 Business Interruption and Constructive Actions to Address Cyber Crimes
27:35 Cyber Executive Programs and Case Management
Cyber threat intelligence is a conceptual term with an international impact. Agencies around the world are racing to identify and stop cybercriminals from infecting and infiltrating networks to use our data against us. In this episode of No Password Required, Dr. Sagar Samtani, assistant professor of information systems and decision sciences at the University of South Florida, explains the cyber threat intelligence (CTI) life cycle and what you and/or your organization should do to help protect data assets and prevent cyberattacks.
Data is the prime target of many cybercriminals, yet what data they are searching depends on their goals. Are they scraping for social security numbers? Obtaining passwords? Collecting credit card numbers? Or worse? And why? It’s hard to imagine all the ways that data can be exploited.
Your data is widely available depending on where and how you store your data and whom you give permission to access that information. Personal choices, like having a smartphone, can be a gateway to someone collecting your data. Being on the grid with a social security number, health insurance, financial accounts, all these bits of information are housed somewhere, and cybercriminals know this. With the help of artificial intelligence (AI), cybercriminals are able to scrape data faster than ever before and with the launch of quantum machines, our security choices will be paramount to protecting our identity and data assets.
Cyber threat intelligence is helping individuals and industries protect themselves by understanding what is important, what are the exploits, and how to effectively respond. It is also helping to refine artificial intelligence algorithms to better assist in threat analytics. Dr. Samtani describes how industries are responding to industry-specific cybercrimes and developing response standards, protocols, and frameworks. He gives the example of the healthcare industry and HIPAA compliance as well as financial institutions and their evolving PCI compliance protocols. Understanding why a data asset is a target is a key facet to the cyber threat intelligence life cycle.
What are the Four Phases of Cyber Threat Intelligence?
Dr. Samtani explains there are two basic types of cyber threat intelligence analytics. First are the traditional threats, such as malware analysis. The second category is quickly changing as artificial intelligence evolves: data mining, text mining, and natural language processing based on pattern and techniques. Building systems that are designed to log and report data is crucial to discovering breaches and reporting them to prevent further penetration.
Once Data is Stolen, Where Does it Go?
Dr. Samtani discusses how hackers, cybercriminals, even geopolitical threat actors are using the data. He explains how the Dark Web is playing a role as a marketplace and toolbox for hackers. He details the four basic platforms--forums, Dark Web marketplaces, darknet carding shops, and internet relay chat--that cybercriminals use to complete their tasks and possibly grow their notoriety. Hacker behavior on the Dark Web is unlike traditional crime circuits where anonymity is preferred. There are tiers of hacker and they can use their screen names to build their reputation for monetization, credibility, and recognition. Artificial intelligence is being fine-tuned to help detect cybercriminals through intelligent predictions.
Security Protocols and the Danger of Oversharing
Individuals, organizations, developers, and even marketers play a role in security. Developers who were once tasked in racing product to market are now evolving to build-in and protect against exploits. Cultures are changing to bring awareness of the dangers of oversharing and learning from other’s breaches and incidents. Dr. Samtani and No Password Required host Bill McQueen discuss how oversharing can be as simple as a phone call asking what version a software is on and divulging that information, likening that to handing over the keys to a car.
The Study of Cybersecurity Science
As computing evolves, so do the crimes; the cybersecurity field is in the infancy of where it will be potentially. Developing talented professionals to stop cybercriminals, building frameworks and protocols, and advocating for strong cyber cultures at home and in the workplace will be essential to the future. There is ample opportunity for employment and research in the field of cybersecurity, cyber threat research, and cyber threat intelligence.
TIME STAMPS
1:12 Who is Dr. Sagar Samtani
1:30 How Does AI Automate Cybercrime and Cyber Threat Intelligence
3:08 The Four Phases of the Cyber Threat Intelligence Life Cycle
7:43 How Do You Rate and Respond to a Cyber Threat
10:03 Industry Specific Frameworks for Threat Identification and Mitigation
10:24 Data Characteristics in Cybersecurity
11:20 Defcon and AI Village
11:48 Tuning Algorithms for Cybersecurity
12:54 How are Hackers Fighting Against AI Detection
13:53 Developing Organizational Strategies to Counter Cybercrime
15:19 Cybersecurity/AI Ethics and Rules
18:40 Dark Web & Data
19:38 Dark Web Platforms
22:53 Access to Dark Web Platforms
23:50 Hacker Notoriety – Reputation, Monetization and Detection
27:40 Developers & Cyber Security Protocols
29:35 Double-Edged Sword of Sharing Cybersecurity Capabilities
30:40 Operational Intelligence and Risk Management
31:58 Hacker Behavior on the Dark Web/Darknet
33:40 What Can We Do to Protect Ourselves? Following the CTI Lifecycle
35:44 Cybersecurity Science as a Legitimate Field
Each year, businesses are losing $12-$13 billion dollars because of cybercrime. One criminal tool is called the Business E-mail Compromise (BEC), aka “The Man in the Middle Attack.” It begins when criminals use information, like that readily found on social media platforms, to target an employee. The criminal may phone or email the employee, gain their trust, steal their identity, compromise and access their emails and the business network (including human resources, banking and client accounts) and so on, all for the ultimate goal of stealing large sums of money.
In this podcast, Stacy Arruda, a cybersecurity threat specialist, provides insight on how individuals and businesses can better protect themselves against cybercriminals and take steps to prevent criminals from stealing their money or exploitation them in other ways. BECs have seen a 1300% increase since 2015, and, as Arruda says, “it’s no longer a question of 'if,' it’s 'when,' and not just 'when' but when you discover that the bad guys are inside your network.” Businesses have options and they begin with training employees and reporting problems quickly. Having a strong corporate culture that trains employees about proper handling of emails, account security, personal information, and reporting can make a tremendous difference.
Stacy Arruda is a former FBI supervisory special agent with more than 20 years of experience in cybersecurity and counterintelligence.She is the CEO of the ARRUDA Group, a cyber threat consultancy firm, and the Executive Director of the not-for-profit Florida Information Sharing and Analysis Organization (FL-ISAO).
Stacy details how cyber criminals use social media to profile potential victims, building trust to gain access to networks. Anyone can be a target, and cybercriminals do their homework by connecting the dots to gain access to large payouts.
Arruda notes that women, in particular, seem to overshare information on social media, nearly every aspect of their lives, and it’s a problem. As an educator and speaker, Arruda speaks on how women can better safeguard their information, warning that online activity can escalate to physical threats and exploitation.
Children can also be targeted. Predators can use simple techniques to lure information from children and they can cross-reference social media to gain information about the family. Gaining a real name online can have a criminal scrolling a family’s social media profile and readily finding things like an email, place of work, child’s school, and after-school activities. Monitoring a child’s online activity and restricting shared information is important to the entire family’s safety.
The business email compromise,(BEC), also known as “The Man in the Middle Attack,” is a cybersecurity scam that is typically short-lived and aimed at stealing information and money. “Once they send that email, and you click on that email, the bad guy has a lot of avenues that they can go down. Once they're sitting on the network, they can steal data, they can introduce ransomware and shut down the network. They can sit on the computers and they can wait for invoices to come in and wait for payments and steal money,” states Arruda.
Well-organized criminals, terrorists and spies use the information that is innocuously shared by us to gain our trust so that they can:
Arruda recommends that companies should have security drills, much like fire drills, to implement a response plan and reinforce the company’s culture on security.
The FBI has a unit called the Recovery Asset Team, where companies can report a compromise for the possibility of freezing accounts to stop the wire transfer. Time is of the essence relative to how quickly a bank will process a wire transfer; two weeks is far too long, and the money will likely be unrecoverable.
SOME KEY POINTS:
Security is often a failure because of two factors:
For the individual, Arruda shares that human error and oversharing can be the gateway to being compromised. Having system patches up-to-date, strong passwords, and reducing one’s cyber footprint, such as oversharing personal details or falling for scams because they know our likes and dislikes, can be key to preventing cybersecurity threats at home.
Defense-in-Depth is a tactic that individuals can use to protect themselves. Having our systems patched, running a firewall, running antivirus software scans, using strong passwords are examples of how an individual or business can add layers of defense against cyber criminals.
An untrained employee is a liability and changing company culture to encourage calls to higher-ups to confirm requested transactions is a must.
BEC - 1300% increase since 2015, and it’s getting worse because “it’s an easy way for criminals to make a lot of money quickly” and defense-in-depth is one way to hinder BEC criminals.
Posting on the internet so openly, especially on social media, is creating opportunities for criminals to target and manipulate individuals. Controlling your footprint on the internet is vital, and being elusive may discourage a criminal from targeting someone.
Businesses can also add a layer of protection by not sharing/oversharing personal information about their employees, such as the CEO is married to so-and-so and their children’s names are Tom, Becky, and Mike and their ages. Criminals profile and store this information, and this creates unnecessary risk.
The FL-ISAO, which helps to build cyber resilience for the state of Florida, has an agreement with the Department of Homeland Security to encourage removing the corporate stigma of sharing information to prevent data breaches, hacking, cyber incidents, cyberattacks, and other cybercrimes. Trends show that reporting to the Internet Crime Complaint Center has increased and more and more victims are willingly coming forward. While this is critical, more can be done so the FL-ISAO is expanding to provide training, tips and business support to prevent cybercrimes. Organizations can contact Arruda via www.flisao.org or via email at [email protected]
TIME STAMPS
1:00 About Stacy Arruda, Cybersecurity Expert
1: 38 Oversharing on Social Media Can Compromise Your Security
2: 51 Using Email to Breach Your Network
6:41 Reporting Cyber Incidents & Breaches – Time Matters
7:14 Using Defense-In-Depth to Stop Cyber Crimes
9: 11 How Convenience Can Cost Billions
9:50 Human Error: A Major Factor in Cybercrime
12:41 BEC Crimes
19:00 Cybercrime Rings Stole $11 Million
21:28 Victims, Including Businesses, Should Break the Silence
22:26 Building a Corporate Cyber Culture to Stop Data Breaches & Cyber Crimes
27:08 Women: Targets of Cyber Crime
30:22 Cybercriminals Targeting Children
35:52 Florida Information Sharing and Analysis Organization (FL-ISAO)
From wearables, cellphones, and thermostats to point-of-sale systems, clouds, and critical infrastructure, our world is connected. We’re part of the Internet of Things (IoT) at work, at home, even in our cars and, of course, in our pockets. There are more than 27 billion devices in the world that connect in some way to the internet, and each of those items pose an access threat. Cybersecurity experts like Ed Cabrera, the Chief Cybersecurity Officer for Trend Micro and former Secret Service officer and National Cybersecurity and Communications Integration/Homeland Security advisor, are identifying how data breaches happen and what can be done to prevent them. Ed investigates technology from every aspect, from hotspots to artificial intelligence and machine learning.
More Than Your Computer Is At Risk
Vulnerabilities are all around:
Traditionally, risk management for connectivity wasn’t first and foremost in a designer’s mind but increasingly companies’ reputations and responsibilities are being questioned and impacted by product breaches. This is affecting the way leadership and designers approach their products.
Cabrera suggests that we use the same diligence that we protect our businesses should be applied to our personal lives. Consumers need to investigate if devices that they bring into their home, like Amazon's Alexa, smart TV’s and IP cameras, even printers and smart home services, are subject to threats and what manufacturers are doing to prevent breaches.
Corporate Culture & Cyber Education
The evolution of cybersecurity is also changing the executive level of companies. Chief Security Officers and IT managers are keystones in understanding what their developers and researchers are finding and relaying that information to other executives and board members. Cabrera says that CSO’s need to be Chief Translating Officers to ensure decision makers understand the threats and how to prevent them.
Businesses also play a role in growing the cyber community and closing the personnel gap. There is large gap between currently taught IT and engineering skills and those needed for machine learning and AI. This gap is causing a shortage, and Cabrera estimates that there are 300,000 openings nationally right now in the cybersecurity industry. He advocates for apprenticeship models to foster a partnership between education and employment. The apprenticeship model also addresses the soft skills needed to be an integral part of a company.
These workers are needed as cybercriminals and nation-state actors are relying on automated crypto ransomware, cyberattacks, cyber manipulation, and identity theft. In 2016, automation helped cybercriminals attempt more than one billion attacks, but now criminals are being pickier to reap a larger reward. Organizations and governments of all sizes continue to be at risk.
Chapters
What is an IoT? 02:52
Connectivity is the Door to Data Breaches 03:57
Digital Extortion 07:15
Corporate Culture 07:55
Examples of IoT Breaches 09:11
Machine Learning and AI Skill Gaps 11:34
Chief Translating Officer 14:25
Apprenticeship Models 17:22
Hacking Medical Records 22:37
Culture of Cybercriminals 24:34
Crypto Ransomware and Automation 26:25
Can a piece of dust on your touchscreen compromise your data? The answer is yes. We learn how from No Password Required Podcast guest Roger A. Grimes, KnowBe4’s data-driven defense evangelist, whose mission is to educate others about cybersecurity issues that can compromise computers. He shares two of the largest threats of cyberattacks impacting companies: social engineering and unpatched software. His simple advice for avoiding 99% of cyber risks: “Patch your stuff and don’t get tricked into doing something you shouldn’t; you do those two things and you will not get hacked.”
Roger is a prolific author, blogger and speaker. He shares his 30+ years of penetration testing/ethical hacking expertise with companies and tech professionals to improve their security and defend their network. In this interview, he talks about man-in-the-middle attacks and other social engineering scams that open doors for data breaches. He examines the lack of improvement in technical controls and the proliferation of adversaries and continuous daily malware attempts. Roger also discusses the future of computing with quantum supremacy on the horizon and the threat it poses to public key cryptography.
Topics in Order:
Who is Roger A. Grimes?
Hacking Isn’t That Hard
Is Misinformation Part of the Cybersecurity Problem
Anti-Virus and Firewalls Don’t Work - Close Your Computer Exploits by Patching Software
10 Ways I Can Hack You
Recognizing Red Flags of Social Engineering
Why is Hacking Still Such a Problem
How to Hack Passwords & Multi-factor Authentication
The Truth Behind Password Lengths and Password Policies
How to Never Be Hacked
Is that Dust or Hair on Your Touchscreen? Nope, it’s an Embedded Scam
What are the Two Biggest Cybersecurity Risks?
Have You Heard of this Scam? Security Awareness Training and Social Engineering
Creating a Cyber Culture for Your Employees through Security Awareness Training
The End of Classic Computing
Will Quantum Computers Launch in 2019? The Sprint for Quantum Supremacy
A Better Future with Quantum Models
The Downside of Quantum Computers: Breaking the Public Key Cryptography
The Coming Quantum Break
Post-Quantum Encryption and Susceptibility
Has the Quantum Crypto Break Already Happened?
Is Quantum Supremacy a Big Deal or the Next Y2K?
What is Crypto-Agility and Will it Matter with Quantum Computing?
Is Society Becoming Tolerant of Hacking and Cybercrime? Why and What Do We Do About It?
From the publisher's feed