Tag: Cybersecurity

  • Financial Institutions Struggle to Keep Up with ‘Changing Business Needs’ Such as Social Mobile Apps, and Getting Risk Data Quickly, Deloitte Report Suggests

    Deloitte’s report is based on a survey of 94 financial institutions around the world that operate in a range of financial sectors and with aggregate assets of $29.1 trillion.

    Deloitte’s Edward Hida  — financial risk community of practice global leader and a partner in Deloitte Risk and Financial Advisory — posted his executive summary the latest Global Risk Management Survey which is the organization’s eleventh. The report is a detailed one and Deloitte draws quite a few conclusions around the continued focus on cyber security, engagement of boards of directors, increase attention to non-financial risks, the potential of digital risk management, enterprise risk management, the proliferation of Chief Risk Officers, an increased reliance on stress testing and more.

    A couple figures jumped out at me which show at least two challenges to financial institutions.

    Hear this Deloitte professional at ICRMC in Toronto April 15-16!

    Respondents are finding “extremely challenging” the need to keep up with changing business operational needs, such as deployment of social mobile applications, data analytics and cloud-based risks. Also in the “extremely challenging” category, not surprisingly, are threats from “sophisticated actors,” like foreign governments and crackerjack hacktivists.

    Other issues categorized as “extremely high priority “revolve around getting quality risk data quickly. Given the average length of time other studies show that a hacker can poke around in your network before you realize it — and how much damage they can do when they have all that time — it’s easy to see why this is a major concern for financial institutions.

    You can read the rest of his executive summary here. You can also download the full report as well as all of Deloitte’s past editions.


    Two of Edward Hida’s Deloitte colleagues — Beth Dewitt and Adel Melek — are speaking at the International Cyber Risk Management Conference April 15-16, 2019, in Toronto. They are addressing the global regulatory landscape.

    Here is the session description:

    “Large-scale data breaches are increasingly in the public eye; consumer trust in brands is faltering, creating a surge in data and privacy protection discussions from the Boardroom to the front lines. While the European Union’s General Data Protection Regulation (GDPR) has occupied much of the spotlight since coming into effect in May, globally there has been a barrage of privacy laws like the California Consumer Privacy Act that was passed in June and the breach-reporting amendments to PIPEDA came into force on November 1st. What do these and the plethora of other privacy regulations mean for your organization when it comes to protecting an individual’s personal data?”

     .   

  • Mitigating Operational Cyber Risk: As Business Technology Changes, So Does Your Risk Profile

    By Tom Hagy

    The various risks of doing business in our digitally connected world continue to evolve.  So must the approach organizations take in confronting those risks, for failing to do so in the current risk landscape can be far more dangerous than in prior years.

    I spoke with Nick Galletto, Global Cyber Risk Leader at Deloitte, who traced the evolution of the dangers of doing business in a digitally connected world. Early on, our focus in the cyber risk management space was on how to protect websites from being defaced, he explained. Organizations had to make sure websites were functioning properly, that data was secure, and the integrity was maintained.

    Galletto went on to say that we’ve moved from an era of compliance and risk management to an era of complexity.  From an organization’s perspective, their focus was on making sure the company was compliant with new and evolving regulations, and risk management meant having policies, procedures and effective controls in place.

    “While compliance is a necessity, it is not the silver bullet that’s going to protect us from any potential breaches,” Galletto said. “So organizations must look at conducting their business in this connected world not merely from a compliance perspective but from a risk perspective. A clear example of this is the number of PCI-compliant companies that were still getting breached.”

    “Now as organizations move into an era of complexity, they need to be proactive in detecting anomalies and suspicious behavior and be prepared so their teams have a playbook that allows for seamless response. Effective organizations will play back possible breach scenarios – whether they involved data breaches or denial of service — to  prevent and prepare for similar attacks. They also focus on understanding what their crown jewels are and where they reside and how to best protect them.  Much of this also has to do with data,” Galletto said.

    “Organizations are increasingly reliant on the cloud and they must understand the associated risks and the individuals responsible for managing those risks,” he said. “They need to be sure they have the right coverage as well.”

    “This era of complexity – automation, machine learning, artificial intelligence and the internet of things, along with the tremendous advantages, like the cloud – also bring new risks,” Galletto continued. “As consumers we see use of these technologies more and more in our daily lives. But organizations are increasingly integrating them into their operations. When something goes wrong here there can be actual safety implications, such as with autonomous vehicles or industrial controls in the mining and manufacturing sectors, as examples. In the financial sector these technologies bring great advantages to customers in terms of accessing their information more efficiently or providing better customer support. But as machine learning and AI become more prevalent in the world of FinTech, decisions are being made without human cognitive capabilities to know right from wrong. These new technologies bring more complexity.”

    “As organizations take advantage of these innovative new technologies, they also have to know that their risk profile is changing right along with them. Smart companies will be proactive in understanding the risks associated with cyber everywhere, understanding where their cyber posture is and make adjustments along the way to better manage complexity.”

    Galletto is one of the speakers at this week’s International Cyber Risk Management Conference in Bermuda, which just kicked off this afternoon with more than 200 professionals in this center of global cyber risk.  

  • Aon SVP Belfiore on Corporate Cyber Risk

    Cyber Risk of Paramount Concern to Corporate Boards

    Lack of History Remains a Challenge

    “Cyber security is the most polarizing issue on the corporate board agenda these days,” says Anthony Belfiore, SVP and Chief Information Security Officer at Aon. “It has the most potential impact and the most regulatory pressure among all risks companies face. Nothing is more top of mind right now.”

    “You just have to look at the amount of media coverage and the actual realized impacts companies are experiencing. Hundreds of thousands of businesses from big to small are being affected. The entire healthcare system in the UK went down. The impact is tangible. It’s affecting day-to-day operations,” he says. “And no one is immune. Board members come from a diverse set of industries, and all are impacted.”

    Why is cyber risk such a hot button for companies versus other types of risks?

    “The risk has become more urgent as it has shifted to actual business interruption,” Belfiore says. “Historically companies were concerned with data leakage and loss, or regulatory fines, but now the actual operation itself can come to a halt. When a company goes down for three days that hits the media. Analysts notice. You can trace a specific event to a drop in stock values.”

    Aren’t fines still a concern?  

    “Yes. We are operating in a regulatory environment which can have a significant downside,” Belfiore says. “This is especially true if you are a multi-national firm with considerable operating and capital expenses. You can sustain significant and unforeseen punitive fines which can be imposed anywhere around the globe, for example, if you’re found non-compliant with GDPR.”

    What about directors themselves?  

    “Potential for board liability for failing to protect shareholders is a hot-button issue right now.  D&O liability and coverage is evolving,” says Belfiore.  “There is uncertainty as to who is protected.”

    The digitization of so many aspects of conducting business has been around for a while now. So why does cyber risk continue to present challenges for the insurance industry?

    “Historical data is a challenge for insurers because there is very little relative to other risks like those posed by fire or storms for which we have decades of statistics. This makes it difficult to qualify and quantify the risk. Models are used to gauge the potential for losses but, still,” he says, “there isn’t a lot of history to go on.”

    Aren’t companies and boards okay as long as they have insurance?  

    “Organizations who think they are covered may come to a different conclusion when they read the fine print. That’s why it’s imperative to work with an experienced broker to navigate the various coverages and nuances in policy language,” Belfiore says.

    At a high-level, what should security leaders at companies do to reduce risk and anxiety around potential cyber losses? 

    Belfiore urges companies to “set up effective governance and establish an effective governance committee. Examine how you run your operation day-to-day, consider how to best manage the expectations of the C-suite and the board. Get the most out of governance committee discussions, ensure you have alignment up and down the stack, and make sure you have installed effective risk management and risk protocols.”


    Belfiore is on “The CISO Perspective” panel at the International Cyber Risk Management Conference (ICRMC) on Dec. 6-7, 2018 in Bermuda, along with Tim Dawson, Cybersecurity Chief Technology Officer at HSBC; Tom Pageler, Chief Security Officer at BitGo, Inc.; and Derek Vadala, Chief Information Security Officer at Moody’s Corporation.  

    You will be able to hear insights like these, and updates on anything that occurs between now and December in Bermuda.

    This posted was edited by HB Founder & Managing Director Tom Hagy. In the 1990s Tom launched one of the first nationwide legal reports in this area — Mealey’s Litigation Report: Cyber Tech & E-Commerce — when he was publisher at Mealey’s, now part of LexisNexis. If you are interested in posting on this site or discussing speaking opportunities, please contact us at Editor@LitigationConferences.com.

  • Cyber Risks Enter a New and Increasingly Vicious Phase

    For anyone plotting the evolution of cyber risks, the last phase of cyber-attacks was dominated by breaches that resulted in lost or stolen personal or financial data that could then be monetized.

    The current phase is different.

    “We have observed a significant increase in the number of disruptive breaches that our clients are dealing with,” says Charles Carmakal, Vice President at Mandiant/FireEye. “These involve destruction, extortion, or public shaming.”

    How are organizations dealing with this shift?

    “It’s catching many organizations off guard. Most don’t have a playbook for dealing with extortion,” Carmakal says. “While they may have thought about a ransomware situation, that’s different from the more common type of extortion we are seeing these days, where a threat actor threatens C-level executives or corporate board members with the release of sensitive information.”

    “Many organizations assume the default is they wouldn’t give into the demands, but when in the middle of a crisis too often the decision is made to pay the threat actors,” he says.

    “So it’s important to consider what your organization will do in this situation. For example, who will be involved in the decision-making process? Organizations should play out an extortion scenario so they have a plan when faced with real demands.”

    How can organizations better test the efficacy of their security capabilities?

    Many organizations conduct penetration testing or red-teaming exercises, but they often undermine their own efforts.

    “A problem arises when an organization contracts a third-party to test their capabilities, but puts a lot of restrictions on those who are doing the testing,” Carmakal says. “For example, they will tell the testing team or red team to identify vulnerabilities, but not to exploit them, or they can exploit a vulnerability but stop there and not dig any further.  The penetration testers might be allowed to test only during a certain day of the week or certain time of day. Or they might be allowed to sample only a fraction of the organization’s IP addresses and ignore everything else.”

    “What happens is the penetration testers are not permitted access to the crown jewels,” Carmakal warns. “They can’t demonstrate business impact to the organization. This creates a false sense of security because the organization can say they had a team of qualified people try and fail to break into the network, but in reality they were unable to break through because of all the unrealistic restrictions imposed on that team.”

    This false sense of security travels to the top. “Testing results are shared with the board and the board believes that because a really good third-party was not able to get to the crown jewels that they have a much safer environment than they really do. That’s a very common theme we see across the industry,” Carmakal says.

    How do penetration testers deal with unrealistic testing parameters?

    “It’s part of the education process,” he says. “When a company wants us to do a very limited test, and we believe our reports will be shared with the leadership team or the board, then we just won’t take the engagement. We try to make it clear that this is not an exercise to make anyone look bad, but a way to leverage the lessons from all the bad guys who are breaking into organizations so you can strengthen your security.”

    In the end, he says, “It’s better we identify the vulnerabilities than have the bad guys do it.”

    What the geopolitical trends you are seeing?

    Iran – “They used to be unorganized. They even clumsily posted social media profiles of themselves,” Carmakal says. “But they have become much more organized, more structured, more technologically adept, and have affiliated with government entities.”

    “In 2017 we saw more intrusions from Iran than we had ever seen before. There was a noticeable spike in offensive intrusions coming from them. For some reason, in 2018 we really haven’t seen Iran targeting organizations in the United States. They’ve scaled back significantly in the US, but are still active in other parts of the world.”

    “What makes security professionals nervous about Iran,” Carmakal says, “is that they are a wildcard. You don’t know what they are going to do. You don’t understand the rationale behind their activity. But what we do see is a capability and a willingness to be incredibly destructive – taking down businesses and publicly shaming organizations. The fact that they’ve slowed down their attacks on U.S. organizations is interesting, but we expect that to change.”

    Russia – “Russia is not hacking the U.S. midterm elections like they were with the presidential election in 2016, but they are conducting some significant offensive operations around the world. They are very capable. They are also very good at disinformation and throwing false flags, so when you investigate them it’s difficult to tell who they really are. Russia is one of the few countries that demonstrates the willingness and capabilities to cause kinetic consequences through cyber-attacks, such as when they turned off the lights in Ukraine.”

    In March 2018 The New York Times wrote, “The Trump administration accused Russia … of engineering a series of cyber-attacks that targeted American and European nuclear power plants and water and electric systems, and could have sabotaged or shut power plants off at will.”

    When asked about this and the reporting that surrounded it, Carmakal said the story was a bit “sensationalized” and not 100% accurate. “While the intrusion was serious, we didn’t see the Russian actors getting anywhere near being able to shut off the lights,” he said, adding that they “certainly have the capability” in other parts of the world.

    China – There has been a “notable decrease” in cyber intrusions from China since the 2015 bi-lateral cyber agreement was reached between President Obama and China’s President Xi, Carmakal says. While narrow in scope, addressing economic espionage — China’s state-sponsored theft of private U.S. intellectual property and then turning it over to state-owned and private companies in China — the agreement does appear have helped, reports suggest. “They are still hacking organizations and are following a defined playbook. We’re keeping a close eye on them to see how their offensive operations evolve,” Carmakal says.

    North Korea – Except for the highly publicized attack against a major U.S.-based entertainment company, “North Korea rarely goes after Western organizations.” Given the country’s need for cash, “their focus has been more on robbing digital currency exchanges and stealing from banks digitally,” Carmakal says, adding that they, like Iran, are a bit of a “wild card.” North Korea actors have stolen more than $100 million from victims, Carmakal says.


    You will be able to hear insights like these, and updates on anything that occurs between now and December in Bermuda when Carmakal and his fellow panelists discuss important trends in global cyber risks.

    This posted was edited by HB Founder & Managing Director Tom Hagy. In the 1990s Tom launched one of the first nationwide legal reports in this area — Mealey’s Litigation Report: Cyber Tech & E-Commerce — when he was publisher at Mealey’s, now part of LexisNexis. If you are interested in posting on this site or discussing speaking opportunities, please contact us at Editor@LitigationConferences.com.

  • Kenneth Jones of Tanenbaum Keale on Law Firm Tech Development Capabilities

    Should Law Firms Should be Able to Develop Custom Technologies?

    Here is #10 of Jones’ Top-10 List.

    #10. Security. The cloud is great, and generally speaking, companies in this space operate systems in a highly professional manner. However, occasionally one encounters special business needs which call for extensive “above and beyond” levels of security. This could be times a firm is storing financial information, medical records, or other data they wish to absolutely, positively protect. In these situations — under the theory that “no one does things better than I do” —it’s nice to have the option to build super-secure systems with features such as encrypted data within database tables, and to manage the systems with a very small number of highly trusted professionals specifically known by the law firm. Read more of the article posted by Thomson Reuters.


    Kenneth Jones oversees various aspects of technology at Tanenbaum Keale LLP in the role of Chief Technologist. He leads efforts to support TK’s computing environment and infrastructure, one that features a strategy of professionally protecting and processing client data in the cloud with highly skilled and respected leading-edge business partners in the technology space. Ken also helps lead and support various TK programs in the areas of security, compliance, business continuity and firm administration. Learn more. 

  • Protecting Intangible Assets: Risk Transfer Market Yet to Catch Up

    Intrinsically Intangible.                        

    by Giles Harlow, Senior Vice President, Aon (Bermuda) Ltd.

    In the early 1980’s, tangible assets made up around 80% of the value of the S&P 500. Fast forward to today and nearly 85% of the value of the S&P 500 is attributable to intangible assets.

    However, the risk transfer market has not caught up. According to the Aon/Ponemon report of last year, whilst around 60% of tangible assets (property, plant and equipment) are currently being insured, only 12% of informational assets are.

    So what gives?

    If the vast majority of companies’ values in 2018 are attributable to intangibles, why are they not transferring those risks? Is it a lack of education on the client side? A lack of innovation in the brokerage community? A lack of understanding or willingness to accept these new risks on the carrier end? Or is it that whilst the marine and property markets have had centuries to evolve, the newer intangible insurance markets are just gearing up to size as they collate the data they need to properly price and model these risks?

    Likely, it is some combination of all of these factors. We have seen great strides in the cyber market, with double-digit premium growth over the last four-to-five years. The market has evolved from being focused on large data holders, to providing products which contemplate the cyber perils affecting manufacturers, the transportation industry and other non-data holders.  “Business interruption” has quickly morphed into “system failure coverage.” “Contingent business interruption” now looks more akin to full supply chain risk, not just for IT service providers but now contemplating all vendors. “Bodily injury” and “property damage” stemming from non-physical threats complete the circle back into tangible loss being covered under cyber policies.

    Intellectual property — hands down — makes up the largest dollar percentage of the intangible asset value of the S&P 500.  This has long been a conundrum for the industry as a whole – both in terms of how to value the asset and, more so, how to value the loss. Again, we have seen great momentum here with much larger limits than were historically available now obtainable from the markets both as a theft product as well as being offered for IP infringement. Even now carriers are contemplating supporting the multi-trillion dollar asset class of intellectual property when used as collateral. This could dramatically impact both the equity financing model and asset backed lending world we know today.

    Clearly the will to innovate is alive and well within the industry. It is tough to price emerging risk when the models that our industry are built on rely on historical data, data that is often out of date or irrelevant in these rapidly evolving intangible classes of business. New ways to price and structure these insurance purchases have to be found in order to maintain the industry’s relevance in today’s world.


    Bermuda is at the forefront of many of these initiatives and its underwriters and brokers are constantly seeking to raise the bar to address evolving client need. The panel titled “Evolution of Product and Buyer” will be tackling these and more topics in detail at the Dec. 6-7, 2018, International Cyber Risk Management Conference, or ICRMC, in Bermuda from the perspective of brokers, underwriters and insurance purchasers.

    Get 10% off the registration fee with promotion code HB2018. 

    http://www.aon.com/risk-services/cyber.jsp

    http://www.aon.com/risk-services/amats/intellectual-property-solutions.jsp

  • Cyber Insurance Policy Language Review: A Deep Dive Into Key Policy Provisions and Important Differences Among Cyber Policies | Oct. 25, 2018 | Now On-Demand!

    [one-third-first]

    Now Available On Demand

    PLACE: Your computer or mobile device

    PRICE:  $197

    CLE: 1 credit
    Please send CLE questions to
    CLE@LitigationConferences.com

    SPEAKERS:

    Judy Selby
    Principal
    Judy Selby Consulting LLC 

    Scott Godes
    Partner
    Barnes & Thornburg

    Please contact us with any registration questions:

    Brownie.Bokelman@LitigationConferences.com

    Kathleen.McFadden@LitigationConferences.com

    Your registration includes:

    •  A site license to attend this webinar (invite as many people in one location as you can fit around your computer at no extra charge).

    • Downloadable PowerPoint presentations from our speakers.

    •  The opportunity to connect directly with speakers via email to
           HBWebinars@LitigationConferences.com

    •  At least one-hour of CLE credit.

    Produced in collaboration with

    Judy Selby Consulting LLC

    Also available as part of your subscription at
    the Thomson Reuters West LegalEdcenter.

    [/one-third-first] [two-thirds]

    What’s in your cyber policy?

    Cyber insurance can provide a lifeline to companies dealing with today’s high stakes and constantly evolving cyber risk and regulatory compliance landscape. But not all cyber policies are created equal, and a single policy word can mean the difference between a covered and an uncovered claim.  

    In this session, we analyze various cyber insurance coverage terms, conditions, and exclusions and describe how the words can impact coverage for real-life claims.

    What you will learn:

    • Important differences among generally available insurance coverages for cyber and privacy risks 

    • Understanding basic cyber insurance policy conditions and how they can affect coverage  

    • The importance of common insurance policy provisions concerning “other insurance” and “choice of law” in the cyber insurance context 

    • How certain cyber insurance policy exclusions can affect coverage for common cyber and privacy liabilities 

    • How to reconcile coverage under cyber insurance policies with other “traditional” insurance policies 


    Speakers

    Judy Selby | Principal | Judy Selby Consulting LLC 

    Judy brings 25 years of insurance coverage litigation experience on behalf of insurers and policyholders to her insurance consulting work and this webinar. She has a particular expertise in cyber insurance and coverage under various policy forms for today’s emerging risks. Judy provides coverage evaluation, policy negotiation, and gap analysis services to companies across multiple industries, helping them to make the most of their insurance premium dollars. She also provides insurance due diligence, expert witness and litigation consulting services to both policyholders and insurance companies in coverage disputes.

    In the course of her career, she has evaluated coverage under a wide variety of policy forms, including: CGL; D&O; / E&O; Employment Practices; Homeowners / Fine Arts & Collections / Auto; Tech E&O; Commercial Property; Manufacturers Output (MOP) / Commercial Output (COP); Bermuda Form; Crime; and Fidelity.

    She is a prolific author and sought-after speaker on insurance, cyber, technology, and compliance issues. She has been quoted in leading publications, including the Wall Street Journal, Fortune, Forbes, Reuters, Directors & Boards, InformationWeek, Business Insurance, Law360, Bloomberg BNA, CIO, CSO, Insurance Business America, National Law Journal, Dark Reading, Corporate Executive Board, and LegalTech News. Judy has authored the eBooks “Demystifying Cyber Insurance: 5 Steps to the Right Coverage” and “Big Data for Business Leaders.”

    In addition to her law degree, she have completed courses in Finance with Harvard Business School HBX, Big Data, Crisis Management/Business Continuity, Cyber Security and the Internet of Things (IoT) with the Massachusetts Institute of Technology (MIT) Professional Education, and Cloud Computing with IEEE.

    Judy is a former co-chair of the CLM Cyber Committee and member of the Law360 Insurance Editorial Board and a 2015 finalist for the CLM Outside Professional of the Year award.

    Scott Godes | Partner | Barnes & Thornburg

    Scott N. Godes (pronounced GOD-ess) is a veteran trial lawyer with experience litigating – in and out of trial – matters involving insurance coverage, technology and Section 337 of the Tariff Act before the International Trade Commission (ITC). He is a partner in Barnes & Thornburg LLP’s Washington, D.C., office and is a member of the firm’s Litigation Department, co-chair of the Data Security and Privacy Practice Group, and a member of the Insurance Recovery and Counseling Group, the Internet & Technology Law Group and the Federal Procurement Practice Group.

    Scott has assisted a variety of clients over the years to obtain more than $1 billion in insurance coverage. In one of his most significant matters, he was co-lead counsel in a landmark class action trial. It was the first case of its kind to determine that insurance coverage was available, without aggregate limits, for thousands of asbestos claims. In addition, he represents clients facing cybersecurity, data breach, cyberattack, privacy and other technology-related claims.

    Scott has litigated one of the few court cases regarding the scope of coverage available under a cyberinsurance policy, resulting in favorable settlements for his client.

    Scott serves as co-chair of the Cyber Risk & Data Privacy Subcommittee of the American Bar Association Section of Litigation Insurance Coverage Litigation Committee. He has also been a co-chair of the American Bar Association’s Computer Technology Subcommittee of the Insurance Coverage Litigation Committee. He edits the BT Policyholder Protection blog. Since 2017, Scott has been named on The Best Lawyers in America list for his work in insurance law.

    He has represented policyholders in declaratory judgment, breach of contract, and bad faith insurance coverage actions, insurance-related bankruptcies and adversary actions, federal court receiverships, insurer rehabilitation actions, and commercial arbitrations. He has litigated and advised clients regarding insurance coverage for cyberattacks, data breaches, and cyber security issues; business email compromises and CEO fraud; advertising injury claims; personal injury and libel claims; ransomware claims; Telephone Consumer Protection Act (TCPA) claims; directors and officers and securities claims; errors and omissions claims; crime and fidelity claims; general liability claims; consumer class action claims; business interruption, extra expense, and contingent business interruption claims; first-party property claims; computer data, hardware, and software claims; mass tort liabilities; product liability claims; class actions; asbestos claims; environmental property damage involving PCBs and underground storage tanks (UST); flood claims; and class actions.

    Scott received a J.D., with honors, in 1998 from The George Washington University Law School, where he was managing editor for the Public Contract Law Journal and was a member of the Moot Court Board. He received his B.A., cum laude, from Middlebury College in 1994.

    REGISTER NOW

    [/two-thirds]

  • Financial Services Cyber Risk Information Sharing

    Why We Need to be More Like Apes, Less Like Seagulls

    By Tom Hagy

    Featuring Craigg Ballance, Director of Canadian Member Services, FS-ISAC

    Even before we can walk we are encouraged to share. We’re told to share our things even when we barely have any. Even some wild animals share food and resources – even when those resources are scarce. Some creatures are better at it than others, of course. Apes and lions? Absolutely. Seagulls? All you have to do next time you’re on the beach is toss what’s left of your ham sandwich into the air and see how generous gulls are.

    People fall into sharing — and not-fond-of-sharing — groups, too. Sharing is particularly critical in the financial sector where, while privacy and security regulations command a tight lid on data, global financial institutions are successfully sharing data about cyber risk, says Craigg Ballance, Director of Canadian Member Services for FS-ISAC in Toronto. But, he says, sharing has to take place across a broad landscape.

    “Information analysis sharing has to cut across the various subsets of the financial sector,” says Ballance. “While banks share local data, they are trying more and more to share globally, but,” he says, “banks need to share with other institutions, like insurers, investment funds, pension funds, and other types of financial institutions, for this cooperation to have the greatest and most effective impact on security.”

    While some IT professionals may tend to want to play things close to the vest, when it comes to cybersecurity teams it is the IT professional who works openly with others who is an invaluable player.

    The Danger of Over-Confidence

    Some blamed over-confident IT professionals for the massive cyber attack that temporarily crippled shipping giant Maersk in June 2017. At the same time, as reported by Reuters on June 27, 2017, Ukrainian commercial banks also sustained a cyber attacks.

    “There are a lot of smart people out there actively trying to figure out ways to mess us up,” Ballance says, whether it’s through new denial of service attacks, or cyberware and ransomware, or the creatively diabolical phishing attacks. “When one entity is falls prey to one of these schemes we’re suddenly all at greater risk,” Ballance says. “There is a limited volume of resources and talent to combat cyber-attacks, so pooling resources, information and skill sets is critical.”

    Ballance emphasizes the importance of having a playbook so when a crisis occurs people know who is supposed to do what and when. “In the midst of an attack people tend to lose their minds and not necessarily act logically,” he says. “So having a prepared methodology to get your organization out of a pickle is a piece of work we strongly advocate, as well as sharing that methodology across industries. This way, as examples, banks and insurance companies and investors can enrich each other with new insights and skills.”

    He also advocates simulated attacks and table-top exercises so people can engage as if they are dealing with a real disaster, like those conducted by FS-ISAC. Conducting post-event analysis to improve response and sharing those findings is also important.

    Experience tells us that when it comes to global cybersecurity we need to be more like gorillas and big cats than selfish seagulls down by the sea shore.


    Craigg Ballance will share insights like these and more at the International Cyber Risk Management Conference Dec. 6-7, 2018 in Bermuda. He will be joined by Nick Galletto, Global Cyber Risk Services Leader at Deloitte in a session titled, “Strength Through Information Sharing Within the Global Financial Services Arena.”

    Over the past three-plus decades, Ballance has led and managed advanced technology-enabled business initiatives across a wide range of competitive sectors, countries and areas of innovation. These build on his experience in leading electronic commerce development in one of the world’s path-setting banks in the field and on his extensive work in finance, logistics, international business and government. He is the author/co-author of three books on leveraging technology for business innovation.

    Tom Hagy is a Philadelphia-based writer and entrepreneur, Founder and Managing Director of HB Litigation Conferences LLC and Custom Legal Content LLC, former Editor and Publisher of Mealey’s Litigation Reports, and a former Vice President at LexisNexis®.

  • Blockchain: Power to the People

    Dan Solove, co-founder of the Privacy+Security Forum and professor at GW Law School, just posted an interview with Steve Shillingford, Founder and CEO of Anonyome Labs, a consumer privacy software company. Below is part of just one exchange in the interview. 

    SOLOVE: The Internet has made so many things possible that we couldn’t do in an analog world. Yet, in some ways, the online world seems to lack the capabilities of the offline world. In the offline world, it is much easier to have anonymous transactions. This becomes much more challenging online. How can the online world be made more like the offline world in this regard?

    SHILLINGFORD: Blockchain technology shifts the balance of power back to people—to individuals—and away from tech giants, governments and data miners. It allows you to transact on your terms, just as you do offline. And it’s not just limited to financial transactions. Put anything on the blockchain you want. The blockchain gives a person the ability to publish only the information THEY decide to divulge. Nothing more, nothing less. And no more hidden agendas, no selling personal data without your consent, no worries about privacy. Just like the analogue world, you decide the context, the content, and duration of the information you provide…not the big guys. It can really be that easy.

    Read the complete interview. 

    See the latest faculty and agenda updates for the Privacy+Security Forum 2018 | Oct. 3-5, 2018 | Washington, D.C.

  • Courtney Klein on Social Media & Security

    A Restructured Paradigm for Corporate Teamwork

    By Courtney Klein of Soteria Risk Consultants

    Social media has become an integral part of everyday life. It’s how some of us get our news, research our opinions, learn about local events, and connect with friends. For the modern western business, it is also immensely important for staying in touch with customers, advertising, and overall visibility. For this reason, many companies employ veritable armies of “Social Media Specialists” that do everything from designing graphics to writing tweets to replying to customer questions and complaints. Some companies interact with each other (such as the hilarious and long-standing Twitter Battle between Wendy’s and McDonald’s), and some use it as their primary form of communication.

    Customers, too, know that social media is a way to get in touch with a company – for good reasons and for bad – and while many companies are aware that they will and do receive threats on social media, very few of them have any kind of protocol in place for how to deal with them – and even fewer still encourage their social media teams to pass this information on to or (better yet) work together with their security team. This sort of blasé attitude to threats – either because “it’s not my job” or “they can’t be serious” – leads to real-world ramifications. Incidents such as the April 4th Youtube Shootings (which, we acknowledge, was a failure of many different departments, companies, and law enforcement operations) are a reminder of just how social media “banter” can turn into a real-world nightmare.

    Now, in defense of essentially any company guilty of this, Social Media is a new beast that even the best are still trying to get their arms wrapped around. Not only is social media relatively new to the game, but it’s dynamic and ever-changing. What was relevant yesterday no longer will be tomorrow. Updates add new features and kill our favorites, terms of service changes impact business, trends are fleeting but ever so important for a business to understand, customer service issues must be dealt with in a timely fashion. Take all of this and add security concerns on top of the social media specialist’s plate and you’re only going to run into failure. That’s why we at Soteria are such strong believers in having social media and security teams work together every step of the way.

    Folding security into the fray … will make a world of difference

    With few exceptions, social media teams plan their calendar very carefully. Words must be scripted, graphics must be designed, legal must be consulted; it’s not often that there’s a “last minute tweet that just has to go out right here right now.” With everything else that goes into these seemingly benign releases, folding security into the fray is, ultimately, a minor change, but one that will make a world of difference. Giving the security team insight into what will be posted provides a number of benefits.

    The security team will be able to assess what posts may aggravate any known or active threats. In general, security teams like to keep information about who wants to do harm to a company under relative secrecy so as to not unnecessarily alarm staff. As a dedicated intelligence analyst (working for a company with an incredible need to integrate a security function into social media) I personally witnessed a number of occasions where I’d read a post – a perfectly fine, professional post that a normal person wouldn’t bat an eye at – and thought “Oh heck, John Doe isn’t going to be happy about this one,” and upon further investigation discovered that, as suspected, Doe was all sorts of worked up over 260 characters and was heading down to the local office to cause a ruckus. With a little bit of notice, my team could have prepared our local staff for the event and given them adequate time to get ready rather than going into overdrive mode.

    It can help reduce the stress that the social media team feels during the normal course of their duties. Most people know that it’s possible to directly message a company’s customer service group via social media, but often times it’s actually the social media team that is in charge of screening and fielding these messages. On the occasion when a hateful comment or threat comes through, the social media specialist on the receiving end – who likely and rightly doesn’t have a lot of experience with such things – may react in any number of ways, from panic to disbelief. Whatever the response is, the likelihood that they’ll consider sending it to security for analysis without some previous instruction to do so is slim to none. At the very least, giving these staff this simple instruction can mitigate some of the basic issues. At best, it can begin to smooth the path for future growth into a more robust Social Media-Security partnership.

    Even security teams with dedicated social media analysts are still constrained by the limits of being human. While your company may have a well staffed social media threat team there is only so much a person can handle at any given time. In reality, though, it’s more likely that whoever is watching social media for threats is also juggling a multitude of different security tasks as well. By working or liaising with your organization’s social media team, you’ll have extra eyes on all the time. Many times, when a person is threatening an organization online they are not directing this information to the company’s inbox or direct messaging their team. Sometimes it’s as simple (and clear) as someone saying “I’m going to go shoot up XYZ Company tomorrow” without any connection to official accounts. Most social media groups monitor for any mention of their company’s name as part of a marketing strategy and to ensure only legitimate accounts are using the company branding. Clearly, this threat is not something that they should be dealing with – but it is certainly the job of corporate security. Even a tenuous partnership between the teams could result in threats like this being effectively handled.

    Just as your average security specialist wouldn’t know how to effectively announce a major company event on Twitter, neither will your typical social media analyst have the tools and skills necessary to investigate threats and persons.

    Security teams, by the nature of our work, are often able to access information that is not available to social media teams. Tools like Nexis and TLO aren’t given to groups without a legitimate use case, but these tools are often necessary in order to identify a threat actor. Depending on the severity of a threat, this information is often incredibly useful when providing information to the police. They are generally so overworked, underfunded, and understaffed, that having so much information handed to them, especially with an honest, well-documented case file that explains the methodology of your investigation, is a relief, and will help jumpstart an investigation.

    Social media teams know who is a regular issue. They know that John Doe sends rude comments to the Instagram inbox every time something is posted. They also know that they have a lot more to their job description than just reading mean comments. The regulars are remembered because of their consistency, but there are other threats who may not come up often enough to remember, and these may be the most dangerous. Likewise, if John Doe suddenly stops sending his vitriol, a social media specialist is likely to feel relief, whereas an intelligence analyst or other security professional might feel apprehension. What’s changed? Where did he go? Was he arrested? Did he find a new target? Or is he planning something that’s taking all of his time? For five years Jarrod Ramos threatened the staff at the Capital Gazette through social media, phone calls, emails, and any means he could find. It was normal for them, though the staff never ignored his threats. But in 2016 he went quiet. The small newspaper had neither the staff nor the resources to figure out why, and it would have been impossible for them to guess that in June of 2018 Ramos would be responsible for the vicious murder of five of their colleagues, but that’s exactly what happened. Likewise, in the reverse, should a case of minor, random harassment become more regular it’s possible an overworked social media specialist might be so harried they just wouldn’t notice. Paying attention to and noticing such trends is well within the wheelhouse of Corporate Security, but our ability to do this work is dependent on good, effective, two-way communication with the people on the receiving end (including and beyond social media).

    Finally, and very importantly, it is imperative for any security team to work with the people in their organization if for no other reason than to build relationships. Security is, if we’re being frank, a pain for everyone. While, yes, our goal is to keep people alive and well, completing this task also means we have to be an impediment. The same perimeter security measures that keep out a bad actor also slow down the company’s employee during a torrential downpour. The same check-in procedures that ensure only authorized persons and wanted guests get past the lobby also make the new guy late right before a big meeting when he’s left his badge at home. The same systems that only grant entry to someone with a need-to-access also ruins the forgetful employee’s day when she hears the door click shut behind her just as she notices she left her access card on her desk. Security costs money but doesn’t make it. Security gets in the way of art and gardens and aesthetics. Security is necessary, but it’s also difficult for everyone. By working amicably with as many people as possible throughout an organization and making sure they understand that you’re there to help them get their job done, you are building bridges to better relationships. You’re recruiting ambassadors that can help explain to others why piggybacking is such an issue. You’re educating additional bodies who can come to your team when they notice that outside door isn’t locking when it shuts. You’re expanding the pool of people who will quickly let you know when something doesn’t seem right, rather than just telling you after the fact. And, unlike many teams within many organizations, the social media team is often overwhelmingly comprised of young employees who will be more vocal about their support for you and may even come up with interesting, innovative ways to spread the security word that we may not think of.

    The long and short of it is that the world is always changing and evolving and in a field as vast and dynamic as security, we will always be met with new challenges. The most effective way to deal with such hurdles, at least on the front end, may very well be referring to the expertise of other professionals. By working with them instead of against them, we’ll be more able to understand the threats posed to our organizations and communities, and better ensure the continued safety of those who depend on us.

    Editor’s note: This article was re-published with the generous permission of the author. She is not the poor soul depicted in the photo above, however, who, for my money, is being a bit dramatic. –Tom Hagy


    COURTNEY KLEIN, PSP
    Courtney got her start in security while pursuing her master’s degree in criminal justice. Since then, she has served in a consulting capacity for educational institutions, major law firms, local and federal law enforcement, religious organizations, internationally celebrated entertainers, a number of non-profit organizations, a preeminent entertainment company, and state task forces grappling with innovative standards designs.

    Much of Courtney’s experience also rests in serving on dedicated corporate security teams, focused on everything from basic CPTED design and access control to international travel security and internal fraud investigations. Currently, Courtney proudly serves as the Senior Intelligence Analyst for a major international non-profit, where she uses her experience to identify and monitor individuals who pose a physical or intellectual threat to the organization’s employees, clients, assets and mission.

    Read more about Soteria Risk Consultants.