Cyber3 Conference: Actionable Takeaways for Global Thought Leaders

Palo Alto Networks recently participated in the second Cyber3 (Cyber Connect, Cyber Security, and Cyber Crime) Conference , which was held in Tokyo in late November and included official support from the Japanese government. The conference brought over 300 thought leaders from all over the world to discuss cybersecurity challenges and share best practices. As William H. Saito, Cyber3 Chairman and Special Advisor to the Japanese Cabinet Office, made it clear during his opening remarks, the goal was to keep the forum interactive and contribute to better cyber resiliency.

The conference showcased the strong leadership of the Japanese government to provide a thought-provoking and multi-stakeholder platform that allows leaders in academia, business, and government to network with each other, build trust, and discuss innovations such as artificial intelligence and connected cars and cyberthreat intelligence in an open and frank manner. Japanese Chief Cabinet Secretary Yoshihide Suga was on hand for closing remarks, which underscored the government’s interest in the gathering.

This is a watershed moment for Japan. While Europe and the United States have regular cybersecurity conferences addressing both technical and strategic audiences, such as DefCon and NATO Conference on Cyber Conflict, Japan has not had such a high-level, cybersecurity-focused conference, due to the lack of interest in cybersecurity until the first Cyber3 Conference was held in Okinawa in early November 2015. The atmosphere changed drastically after September 2013, when Tokyo was chosen to host the Summer Olympic and Paralympic Games 2020. The clear deadline and mission to make the games successful sparked the Japanese to craft cybersecurity policies, invest more in cybersecurity human resources development, and move forward the public-private partnerships for information sharing and global collaboration. That is why some of the Cyber3 speakers were surprised to find out during the two-day conference how passionate the Japanese are about ensuring security for Tokyo 2020 and promoting cyberthreat information sharing.

The Japanese government hosted the G7 Ise-Shima Summit in May 2016 and included cybersecurity as a standalone topic for the first time in G7 discussions. The two consecutive Cyber3 Conferences and G7 Ise-Shima Summit’s cybersecurity documents prove the Japanese government’s firm determination to play a leading role in cybersecurity policymaking, thought leadership discussions and global cooperation.

Palo Alto Networks representatives participated in this important conference as a sponsor and as speakers and shared insights regarding automated cyberattack prevention, cyberthreat information sharing, and business risk management. Rick Howard, Chief Security Officer at Palo Alto Networks, was on the “Threat Intelligence, Information Sharing” panel and pointed out that cyberthreat information sharing has not previously worked well because security vendors monetize and compete on their information. However, cyberattacks are increasing and becoming more complicated. To improve cyber defense overall to protect users, security vendors have to pursue a collective defense. That’s why Palo Alto Networks, Fortinet, Symantec, and McAfee launched the Cyber Threat Alliance (CTA) two years ago – an example of vendors that compete directly in the market but, when it comes to shared threat intelligence, have agreed to work together for the greater good of protecting individuals, businesses and governments. U.S. President Barack Obama referred to CTA as a successful example of information sharing during the White House Cybersecurity Summit at Stanford University in February 2015.

Ryan Gillis, Vice President of Cybersecurity Strategy and Global Policy at Palo Alto Networks, moderated the “Human Resources Development” panel. First, Yasuhiko Taniwaki, Director-General of the Global ICT Strategy Bureau, Japanese Ministry of Internal Affairs and Communications, stated that the Japanese government included cybersecurity human resources development in its Cybersecurity Strategy in 2015, as Japan faces a shortage of cybersecurity talent. In July 2014, the Japanese Information-Technology Promotion Agency found that Japan has 230,000 cybersecurity professionals, and that 140,000 of them need further training; it also found that there is a shortfall of 22,000 professionals. Taniwaki encouraged academia, the government, and industries to work together to tackle the manpower challenge and pointed out that people who can bridge business leadership and IT engineers are in dire need. The Japanese government plans to create a human resources development plan by March 2017.

I appeared on a panel titled “Current and Future World, Government, and Organizations Changed by Cyber.” I reiterated the importance of a multi-stakeholder approach, which is the philosophy of Cyber3. Since the damage caused by cyberattacks is not necessarily constrained within a certain sector, a traditional stovepipe approach to combating them no longer works. We must overcome silos and work together beyond the border of organizations, sectors and nations. Several countries in the world are facing political dynamics and administration changes. Cybersecurity, however, is a bi-partisan issue and opportunity – a business and consumer enabler, not just a cost center. We should take advantage of the convenience brought by ICT and ensure security. Cybersecurity is everybody’s problem – individual, company, government, or university. At the same time, cybersecurity enriches our lives and I hope Tokyo 2020 changes our mindset under the tight deadline and creates a positive prototype of multi-stakeholder efforts to increase resiliency.

Noboru Nakatani, Executive Director of Interpol Global Complex for Innovation, pointed out a stark contrast between Japanese and non-Japanese perspectives on cybersecurity. The Japanese tend to frame breaches as information leaks and blame the insufficient cyber defense on the victim organizations. On the other hand, Americans and Europeans tend to frame breaches as hacks and often focus on how to prevent future successful cyberattacks by attackers. The trend is reflected in how the media reports cyber incidents.

Situational awareness supported by full visibility and cyberthreat information would help shift such a mindset. During the Day 2 luncheon, Rumi Horio, Security Consultant, Palo Alto Networks K.K., cited an anecdote of several blind men who touched different parts of an elephant and thought it was a fan, rope or something else. Japanese organizations are inclined to count the number of cyberattacks rather than seek methods to reduce the attack surface and prevent attackers from achieving their goals by cyberattacks. She argued that it is time to take a proactive approach rather than being reactive to damages.

Cyber3 was an insightful cybersecurity conference for mutual learning and finding new ways of partnering and collaborating to take actions based on lessons learned together. Palo Alto Networks appreciates the opportunity to have been able to sponsor and participate in the conference in 2016 and 2015.  We look forward to continuing to work with the Japanese government and global thought leaders.

[Palo Alto Networks Research Center]

2017 Cybersecurity Predictions: Ransomware and SaaS Challenges Persist in Healthcare

This post is part of an ongoing blog series examining “Sure Things” (predictions that are almost guaranteed to happen) and “Long Shots” (predictions that are less likely to happen) in cybersecurity in 2017.  

2016 was the year of ransomware in cybersecurity, and it was especially impactful in healthcare. In this blog post, I’ll lay out a few predictions about the type of threats that the healthcare industry will face in 2017.

Sure Things

1. Ransomware Will Continue to Target Healthcare

I suppose this is an obvious one. Many hospitals were impacted by ransomware this past year. Hospitals in California, Indiana and Kentucky were hit especially hard by ransomware variants that target servers, as opposed to user PCs. A hospital in Washington was impacted to the point where it had to redirect patients to other facilities in order to maintain adequate quality of care.

The bad guys have turned to ransomware as their go-to choice of attack because the Bitcoin payments are anonymous and, as a business model, it is an effective way to get paid without getting caught by the police. They target healthcare because the attack vector for the highly effective SAMSA ransomware variant is through unpatched JBOSS application servers in the DMZ (the internet-facing area of a network).  Hospitals that have many of these servers and are being successfully exploited in increasing numbers.

With any luck, the word has been spread well enough to healthcare organizations so that JBOSS vulnerabilities have been patched or at least mitigated. However, we haven’t seen the last of this trend.  Ransomware will continue to target healthcare throughout 2017 through the standard areas of attack: web-based drive-by downloads, malicious email attachments or links, and unpatched servers in the DMZ.

2. Accidental Oversharing in SaaS Apps Will Increase, Resulting in Losses of Patient Data

Medical staff love to use cloud file-sharing SaaS apps, like Box, Dropbox and Google Drive, because they fill a gap in many healthcare organizations: easy file sharing. The problem with the public versions of these services is that it’s up to the user to control who has access to the files, and it’s quite easy to accidentally configure a file containing protected health information (PHI) to be shared with the entire internet public. Enterprise versions of Box, for example, enable administrators the ability to restrict public access, but many healthcare organizations don’t block the free versions.

I wrote a blog post earlier this year on the topic of SaaS security, along with some recommendations for mitigating the risk. Until healthcare organizations provide a sanctioned method for file sharing, both within and external to their organizations, and proactively block unsanctioned file-sharing websites, we are likely to see losses of patient data due to accidental oversharing.

Long Shots

1. A Cyberattack on a Medical Device Will Cause the First Confirmed Injury to a Patient

Many medical devices used in medical facilities today lack basic security. Often, medical devices lack endpoint protection, and regular patching, functioning on outdated operating systems, like Windows XP. For these reasons, they are prime targets for malware and cyberattacks.

There has been only one confirmed FDA order to pull a specific medical device out of hospitals. I believe the reason we have only seen one is due to insufficient research on and awareness of the problem.  There hasn’t been much research because medical devices are expensive and there is no financial incentive to perform the sort of security research required to find and fix medical device vulnerabilities.

Attackers motivated by money have used ransomware due to the quick payout and anonymity, but there’s a type of attacker who is in the “I did it because I could” crowd. These adversaries hack for fun. To date there have been no confirmed cases of physical harm to patients due to a cyberattack on a medical device, but I believe that it’s only a matter of time before a bad actor takes advantage of the most vulnerable area of hospital networks – medical devices – and wants to make a statement.

What are your cybersecurity predictions for the healthcare industry? Share your thoughts in the comments and be sure to stay tuned for the next post in this series where we’ll share predictions for financial services.

 

This article originally appeared on HealthDataManagement.com 

[Palo Alto Networks Research Center]

Insurance Carrot Beats Government Stick in Quest for Stronger Cybersecurity

When it comes to cybersecurity, the U.S. federal government recognizes the carrot is more effective than the stick. Instead of using regulations to increase data security and protect personal information within private organizations, the White House is enlisting the insurance industry to offer incentives for adopting security best practices.

In March 2016, the U.S. House Homeland Security Cybersecurity Subcommittee held a hearing to explore possible market-driven cyber insurance incentives. The idea, said Rep. John Ratcliffe, chairman of the subcommittee, is to enable “all boats to rise, thereby advancing the security of the nation.”

The issue isn’t a lack of cyber insurance. Today, 80% of companies with more than 1,000 employees have a standalone cybersecurity policy, according to a Risk and Insurance Management Society survey. The real issue is getting companies to maintain more than a minimum set of security standards.

Borrowing from the fire insurance playbook
The insurance industry has been a catalyst for change in the past. Attendees of the Homeland Security Cybersecurity Subcommittee hearing pointed to the fire insurance market as a good example of using a carrot to drive positive behavior. Insurers offer lower rates to policyholders who adhere to certain fire safety standards, such as installing sprinklers and having extinguishers nearby.

Identifying best practices
So, what are the cybersecurity equivalents of sprinklers and fire alarms? Hearing attendees highlighted four components of an effective cyber risk culture:

  • Executive leadership: what boards of directors should do to build corporate cultures that manage cyber risk well.
  • Education and awareness: training and other mechanisms that are necessary to foster a culture of cybersecurity.
  • Technology: specific technologies that can improve cybersecurity protections.
  • Information sharing: ensuring the right people within the company have the information they need to enhance cybersecurity risk investments.

Spurring much-needed actuarial data
The hearing also touched on a major missing element in the current cyber insurance industry: reliable actuarial data regarding data breaches and other cyber incidents. Auto insurers know the likelihood of car accidents, so they know how to price the liability and measure the risk. But the likelihood and ramifications of various data breaches are a wildcard today, leading to problems in pricing cybersecurity policies.

Hearing attendees discussed creating an actuarial data repository with data from leading actuarial firms, forensic technology firms and individual insurer cyber claims. The proposed database would be housed at a nongovernmental location such as the Insurance Services Office Inc. (ISO), which has managed insurer actuarial databases for more than four decades. The hope is the database would encourage voluntary sharing of information about data breaches, business interruption events and cybersecurity controls to aid in risk mitigation.

While the cyber insurance carrot is a long way from becoming reality, at least the seed has been planted.

Laurie Kumerow, Consultant, Code42

[Cloud Security Alliance Blog]

The Cybersecurity Canon: How to Measure Anything in Cybersecurity Risk

We modeled the Cybersecurity Canon after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have more than 25 books on the initial candidate list, but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite. 

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

Book Review by Canon Committee Member, Steve Winterfeld: How to Measure Anything in Cybersecurity Risk (2016) by Douglas W. Hubbard and Richard Seiersen

Executive Summary

How to Measure Anything in Cybersecurity Risk is a book that reads like a college statistics textbook (but the good kind you highlight a lot). It is a book anyone who is responsible for measuring risk, developing metrics, or determining return on investment should read. It is grounded in classic quantitative analysis methodologies and provides a good balance of background and practical examples. This book belongs in the Cybersecurity Canon under Governance Risk and Compliance (GRC).

Review

As I said, this book reads like an education in quantitative modeling and how to apply the methodology to cybersecurity. It truly challenges the current common practices in use to develop expert opinion-based risk frameworks. Here is a snippet from the book:

“So let’s be clear about our position on current methods: They are a failure. They do not work. A thorough investigation of the research on these methods and decision-making methods in general indicates the following: There is no evidence that the types of scoring and risk matrix methods widely used in cybersecurity improve judgment. On the contrary, there is evidence these methods add noise and error to the judgment process. Any appearance of “working” is probably a type of “analysis placebo.” That is, a method may make you feel better even though the activity provides no measurable improvement in estimating risks (or even adds error). There is overwhelming evidence in published research that quantitative, probabilistic methods are effective. Fortunately, most cybersecurity experts seem willing and able to adopt better quantitative solutions. But common misconceptions held by some—including misconceptions about basic statistics—create some obstacles for adopting better methods. How cybersecurity assesses risk, and how it determines how much it reduces risk, are the basis for determining where cybersecurity needs to prioritize the use of resources. And if this method is broken—or even just leaves room for significant improvement—then that is the highest-priority problem for cybersecurity to tackle!”

The authors lay out the book in three sections:

  • Part I sets the stage for reasoning about uncertainty in security. It outlines terms on things like security, uncertainty, measurement and risk management. Plus, it argues against toxic misunderstandings of these terms and why we need a better approach to measuring cybersecurity risk and, for that matter, measuring the performance of cybersecurity risk analysis itself. Finally, it introduces a simple quantitative method that could serve as a starting point for anyone, no matter how averse the person may be to complexity.
  • Part II delves further into evolutionary steps we can take with a simple quantitative model. It explains how to add further complexity to a model and how to use even minimal amounts of data to improve those models.
  • Part III describes what is needed to implement these methods in the organization. It addresses the implications of this book for the entire cybersecurity “ecosystem,” including standards organizations and vendors.

The cybersecurity community suffers from not having standard evaluation metrics, like earnings before interest, taxes, depreciation and amortization (EBITDA). The authors try to bring some discipline to terms by offering standard definitions coming from the quantitative analytics field. From the book:

  • Definitions for Uncertainty and Risk, and Their Measurements Uncertainty: The lack of complete certainty, that is, the existence of more than one possibility. The “true” outcome/state/ result/value is not known. Measurement of Uncertainty: A set of probabilities assigned to a set of possibilities. For example: “There is a 20% chance we will have a data breach sometime in the next five years.” Risk: A state of uncertainty where some of the possibilities involve a loss, catastrophe, or other undesirable outcome. Measurement of Risk: A set of possibilities, each with quantified probabilities and quantified losses. For example: “We believe there is a 10% chance that a data breach will result in a legal liability exceeding $10 million.”

They also walk the reader through established methodologies like: Monte Carlo simulations, Bayesian interpretation, risk matrix, loss exceedance curve, heat maps, chain rule tree, beta distribution changes, regression model predations, analytics maturity mode, power law distribution, subjective probability, calibration, dimensional modeling, expected opportunity loss, bunch of guys sitting around talking, expected value of prefect information, NIST and ISO. They explain how, in Excel, so they are truly practical. They also lay out survey results from attitudes toward quantitative methods, global information security workforce study, and stats literacy and acceptance studies.

This work follows other work like Factor Analysis of Information Risk (FAIR) which is a well-recognized value at risk (VaR) framework. They outline another Monte Carlo–based methodology and tools like those developed by Jack Jones and Jack Freund. Another similar work is The Wisdom of Crowds by James Surowiecki.

Finally the book has some great online resources. You can find eight sample downloads of the methods explained, as well as webinar/blog info.

Conclusion

How to Measure Anything in Cybersecurity Risk is an extension of Hubbard’s successful first book, How to Measure Anything: Finding the Value of “Intangibles” in Business. It lays out why statistical models beat expertise every time. It is a book anyone who is responsible for measuring risk, developing metrics, or determining return on investment should read. It provides a strong foundation in qualitative analytics with practical application guidance.

Bottom line: The authors lay out a solid case for why other industries with the similar challenges of lack of quantifiable, standardized or historical actuarial table-like data are able to use classic statistical modeling and methodologies to measure risk in a qualified, repeatable way. Definitely worth considering.

[Palo Alto Networks Research Center]

Calling All Women in Technology: Japan’s Cybersecurity Field Needs You

This post originally appeared on Context: By New America

Where were all the Japanese women?

I was asking myself that question while participating in the Grace Hopper Celebration of Women in Computing conference last month, one of the largest global conferences for women in IT.

At the conference, I spoke with dozens of female college students majoring in computer science and cybersecurity in the United States. About half of the women I spoke with were American students, while the other half were students from India and China who were studying in the U.S. and ultimately hoped to stay and work in cybersecurity after graduation. But during my time at the conference I found myself asking, where were the women from my home country, Japan?

At the 2016 Grace Hopper Conference.

Seven years ago, I moved from Japan to the U.S. to pursue my graduate degree in international relations and economics at Johns Hopkins University and later conducted research on Japan–U.S. cybersecurity cooperation as a Fulbright scholar. I’ve also worked at the Japanese Ministry of Defense, a U.S. think tank that specializes in international security, and at Japanese and American tech companies. During this time, I’ve met few Japanese women working in the cybersecurity and tech industries overseas.

I began to investigate why and found a few factors that may explain why more Japanese women aren’t pursuing cyber jobs. It’s important now, more than ever, for women to enter this field.

First, some demographic context: The number of Japanese students matriculating in overseas universities and graduate programs has continued to decrease since 2004. This could be partly attributed to the decline in the number of children born in Japan since the 1980s. On the other hand, some observers, such as Aoyama Gakuin University Professor Kazuo Ogoura, have questioned whether the Japanese have become more introverted as Japan’s economic prosperity and affluence has grown, and thus are less inspired to seek new frontiers overseas.

This demographic reality is compounded by gendered one: a smaller percentage of Japanese girls report that they want to pursue professional careers in engineering and computing than the global average, according to an OECD survey report in 2012. While the global average is approximately five percent, the figure is about three percent in Japan and the U.S. On the other hand, the global average of boys who want to pursue careers in engineering and computing is 18 percent. Broken out, that figure is 15 percent in Japan and 17 percent in the U.S.

One survey report by the Japanese Ministry of Education in March 2015found that 9.1 percent of Japanese male college students work in the Information and Communications Technology (ICT) field, compared with just 6 percent of Japanese female students. The ratio of female students (44.9 percent) to male students (40.0 percent) who pursue a bachelor’s degree is noticeably higher in Japan. It indicates that fewer female students in Japan are choosing to pursue a career in tech.

Perhaps this is why I rarely see Japanese men or women (particularly the latter) at international cybersecurity conferences outside of Japan, particularly in the U.S., U.K. and France. There are also practical and cultural reasons for this: It is often challenging for non-native English speakers to draft proposals and deliver complex technical or international security conference presentations in their non-native tongue. Additionally, Japanese culture traditionally discourages people to speak up in a meeting to challenge a different opinion or idea because it disrupts group harmony, a priority in Japanese culture. Based on my own experience, the pressure of this tradition is even greater for women.

This lack of visibility is problematic because Japan is losing out on opportunities to provide and learn from different perspectives in global cybersecurity discussions. And it needs to be part of this global dialogue more than ever. That’s because Japan is hosting the Tokyo Summer Olympic Games in 2020, which prompted the government to publish the Japanese Cybersecurity Strategy in 2015, a vision about how to secure Japan and prepare for Tokyo 2020 for the next three years. One of its key arguments is that top-notch cybersecurity professionals need to be global and should play an active role beyond national borders since cybersecurity is a global challenge. As of 2014, Japan had approximately 265,000 information security professionals (160,000 of this group reportedly need more training) and a shortfall of roughly 80,000 professionals.

Like the rest of the world, Japan’s cybersecurity workforce shortfall is one that could hurt the country’s security in the long term. The Japanese government is well aware of the risk and finding ways to address the challenge.

That’s one reason why Japan’s efforts to cultivate a larger and global cybersecurity workforce will soon need to include diversity discussions like those happening in the U.S., determining how to recruit and retain groups that have been underrepresented in the cybersecurity workforce — like women. This is a place where Japan could be a global leader, if the private and public sectors make some of the necessary changes together, learning from the best practices of other nations and creating some of their own.

Still, it will be tough to remove some of the obstacles that are holding back women (and men) from the global cybersecurity workforce, and it won’t happen overnight. Japanese cybersecurity professionals will still face a language barrier and encounter cultural differences when joining international cybersecurity discussions and conferences. But joining in these discussions will ultimately help Japan, and the world, become more secure.

It can be scary to some women — particularly Japanese women — to be the minority in a conference room. It might require courage to speak up at a meeting. But as cybersecurity challenges grow increasingly complex and global, these perspectives representing different cultures and backgrounds will become even more important and valuable to the discussion. Think of yourself as an ambassador, paving the way and bridging the gap for other people from your community, country or culture. And you’re not alone; I will do my part and look forward to seeing you at future conferences, or hopefully, as a colleague.

[Palo Alto Networks Research Center]

English
Exit mobile version