Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Partner Perspectives  Connecting marketers to our tech communities.
SPONSORED BY
3/21/2018
09:00 AM
Paul Martini
Paul Martini
Partner Perspectives
Connect Directly
Twitter
RSS
50%
50%

Cybersecurity Spring Cleaning: 3 Must-Dos for 2018

Why 'Spectre' and 'Meltdown,' GDPR, and the Internet of Things are three areas security teams should declutter and prioritize in the coming months.

With each successive data breach, the stakes for companies seem to get higher and higher, with more individuals affected and the costs for remediation escalating. That’s why it’s no surprise that a report published last July by insurance giant Lloyd’s of London estimates that a theoretical global cyberattack could trigger roughly $53 billion in economic losses – a figure that is comparable to record-shattering natural disasters such as 2012’s devastating Superstorm Sandy.

This forecast has serious ramifications for information security teams. It demonstrates that organizations that are following the latest security best practices of 2017 may still need to overhaul their cybersecurity strategy to combat tomorrow's newest, most highly-evolved threats. With spring just around the corner, along with the deadline for the EU's May 24 General Data Protection Regulations (GDPR) deadline, now is a good time for businesses to focus on "spring cleaning" data and company data collection and protection policies.

Here are three areas where security teams can declutter and reprioritize for spring 2018.

Fallible Hardware, Beefed up Security
Just a few days into the new year, security experts discovered a 20-year-old flaw within the processors underpinning the majority of computing devices, unveiling vulnerabilities for almost every individual and business the world over. Called Spectre and Meltdown, the bugs leverage data exfiltration techniques to steal network data after penetrating the network perimeter.

While it’s impossible to stop every threat from entering the network perimeter, security teams should seek out tools that can stop attempts at this kind of data exfiltration in their tracks. Among these tools are a class of so-called data loss prevention (DLP) tools that offer a line of defense when advanced threat detection capabilities that guard the network gateway fails.

New Regs, Increased Measurement & Monitoring
It may seem counterintuitive to suggest that security teams "declutter" by doing more reporting on the activity taking place on their network. But the fact is, in the run-up to GDPR if your existing security tools aren’t keeping tabs on potentially anomalous traffic taking place over the network – especially those related to data collection – your company will be ill-prepared to meet the new GDPR compliance regulations, and a bevy of other rules going into effect in the coming months.

Short- and Long-Term Strategy for Internet of Things
Even if your organization hasn’t yet embarked on a wide-scale IoT deployment you probably will in the near future. IDC Forecasts worldwide spending on the Internet of Things to Reach $772 billion in 2018. As teams continue to beef up their traditional enterprise networks, now is the time to also begin thinking about how they can secure the oncoming enterprise IoT.

What will this entail? Organizations can start by deciding whether IoT devices will leverage the same gateways and network defenses used for standard connectivity on their existing network. Teams may find it more effective to deploy a dedicated network and administration team to manage the high-frequency, low-energy, beacon-sensor transmissions that characterize the IoT in parallel with larger network connectivity.

The Better Business Bureau and the National Cyber Security Alliance offer a valuable checklist for digital spring cleaning strategies. But security teams will need to go above and beyond to make sure their plans, policies, and tools are ready to defend against current and future advanced threats. What better time than now to get started?

 

Paul Martini is the CEO, co-founder and chief architect of iboss, where he pioneered the award-winning iboss Distributed Gateway Platform, a web gateway as a service. Paul has been recognized for his leadership and innovation, receiving the Ernst & Young Entrepreneur of The ... View Full Bio
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Aviation Faces Increasing Cybersecurity Scrutiny
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/22/2019
Microsoft Tops Phishers' Favorite Brands as Facebook Spikes
Kelly Sheridan, Staff Editor, Dark Reading,  8/22/2019
MoviePass Leaves Credit Card Numbers, Personal Data Exposed Online
Kelly Sheridan, Staff Editor, Dark Reading,  8/21/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2016-6154
PUBLISHED: 2019-08-23
The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).
CVE-2019-5594
PUBLISHED: 2019-08-23
An Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in Fortinet FortiNAC 8.3.0 to 8.3.6 and 8.5.0 admin webUI may allow an unauthenticated attacker to perform a reflected XSS attack via the search field in the webUI.
CVE-2019-6695
PUBLISHED: 2019-08-23
Lack of root file system integrity checking in Fortinet FortiManager VM application images of all versions below 6.2.1 may allow an attacker to implant third-party programs by recreating the image through specific methods.
CVE-2019-12400
PUBLISHED: 2019-08-23
In version 2.0.3 Apache Santuario XML Security for Java, a caching mechanism was introduced to speed up creating new XML documents using a static pool of DocumentBuilders. However, if some untrusted code can register a malicious implementation with the thread context class loader first, then this im...
CVE-2019-15092
PUBLISHED: 2019-08-23
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.