The Changing Threat Landscape
CSO - In covering the security threat landscape over the years, two fundamental issues have stayed constant. First, the threat landscape continues to evolve and gain sophistication. Second, attackers will always be a step ahead of the defenders in exploiting vulnerabilities across the spectrum of people, process and technologies. But what's different today is the motivation, methods and tools of these attacks: we're no longer fighting an individual hacker, but a highly organized, well-funded crime syndicate, and in some cases, even a state sponsored agent.
Also see Kark's Building a business case for information security
As IT security professionals work toward building their high-performance security organization, it will be essential to consider the changing nature of the threat landscape. In particular:
Motivation: Gone are the days when hackers bragged about their latest exploits openly in underground newsgroups to gain fame and notoriety. Today, not only is organized crime involved in these endeavors, they are also looking for big financial gains. Attackers will go after systems that store millions of records. Consider this stat: cybercrime costs $8 billion to the US economy according to US Congress reports, equivalent to the Bahamas' GDP.
Method: Unlike the visible attacks of the past, low and slow attacks provide a systematic and precise attack, where the attackers can take months gathering intelligence on the target and then going after the weaknesses systematically, covering all traces of their presence as they penetrate the different parts of the environment. The ultimate goal is to modify the application in some way where they are able to get a consistent stream of revenue over a long time period--such as the infamous TJX breach.
Tools: The move from manual to automated attacks significantly increases the amount of information and context a machine can extract from unsuspecting users. For example, French researchers have developed an automated social engineering tool that uses a man-in-the middle attack to strike up online conversations with potential victims. They were able to entice users to click onto malicious links sent via chat messages 76% of the time. Add to this the ability of machines to crawl the Web and glean publically available information about you and the results can be astonishingly precise in penetrating through your defenses.
So what is the best way for CISOs to handle this changing landscape to compete with a new level of sophistication and rate of change in attack methods? Here are three key ways to manage the development process:
1. Invest in Your People Controls to Maximize Impact: There is no denying the fact that people are the most important control in any organization. And this year, 62% of IT decision makers are making "upgrading the security environment" a critical priority, according to Forrester's Q2 Global IT Budgets, Priorities, And Emerging Technology Tracking Survey. It's about time that the entire organization, especially management, take ownership of risk and become more involved with security decision making. Additionally, as companies expand the scope of security responsibilities, it is important to recognize that spending more on security does not mean better security. Some investments in information security will deliver much more value and mitigate much more risk than others. The application security area is one good example.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Expert Guide to Secure Your Active Directory
- Layered security is the way to go when it comes to protecting Active Directory. This expert e-guide explains the best method to use...
- ESG Lab Validation Report: HP Data Protector & Deduplication Solutions
- Many organizations have deployed disk-to-disk backup technologies to improve the speed and reliability of their backup and disaster recovery operations. A growing number...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts