Barry Coatesworth, Director of Risk, Compliance and Security, Guidehouse
2021 was an unusual year. Cybercriminals took advantage of the global pandemic, the ongoing shift to hybrid working, and the vulnerability of organizations to ransomware saw one of the biggest increases in cybercrime activity. For 2022, we can expect more of the same as ransomware will continue to evolve, and the sophistication of these extortion techniques’ criminals are using will improve. Also threat actors have been trying to recruit insiders to help them gain access to an organisations system to install malware. This combined with growing attacks against Operational Technology (OT) systems and critical infrastructure services, could result in serious disruption, potentially even endangering human life.
So we will see increased use of Social engineering as well as consequences of improvements in deep fake technology which has allowed threat actors to bypass Multi Factor Authentication (MFA) and also illicit fraud by using faked audio.
Mun Valiji, CISO, Trainline
Looking at 2022 what will we see on the Infosec front? Mun outlines his thoughts on Nation State attacks, the surge in perimeter and access management, the expectation within organisations to validate basic security tooling, vulnerability management, antivirus, malware protection, for instance. We will see a recalibration of tooling and capability along with some centralisation, automation and orchestration of some of these functions. Some of the other points he mentions includes: a focus on resilience, simulation exercises, IDFA and due diligence along with engaging in agile ways of working and good governance.
Jenny Radcliffe, founder of Human Factor SecurityIn her session, Jenny will be speaking about human-centred vulnerabilities, looking at the social engineering side of cyber security: how that's changed, what’s stayed the same and how we can address those vulnerabilities to give us a business advantage as well a personal protection for all of us as nodes on the network in business. Jenny explains that we are all part of this now. The attacks are bigger, they are more wide ranging, and people still mistake that for being a technical problem, when in fact most attacks have a human element in them. She urges organisations to empower staff, make it easy for people to do the right thing, especially now, as we re-board people, we can show them things that we needed them to know before the pandemic started, empower people, give them knowledge, She makes a call for "Evangelists of home", make them the champion of their own home, remember as people come back they can bring either good or bad practice into the office, it’s your choice.
Rob Demain, CEO and Founder, e2eassure Rob discusses how many companies do not have an effective security operation, their cybersecurity defences are not being deployed efficiently. They might have them in place, but the signals aren’t been processed quick enough, so something that could have been dealt with in a day by a SOC, are being ignored and can endi up being major incidents. Also he suggest that there are many technical threats, insider threats, ransomware, but also supply chain incidents, including where third-party providers bring an inherent risk to you through the supply chain. One key takeaway is do not to focus on buying more tech, but treat security as a board level issue and like a long term problem.
John Smith, Manager, Solution Architects, EMEA and APAC, Veracode John puts a call out for the the world of software development and the world of security to come together, to work more closely. He argues that software development is moving incredibly quickly, and security is finding it hard to keep up with it. He describes the specific challenges in keeping up to date with the new vulnerabilities being identified in code and being published. He suggests we need to break down those silos between the people who create the code and those who operate the software, we need to work together and have collective responsibility to create a more secure environment.
Richard Robinson, CEO, Cynalytica Root of the challenge for companies is that adversaries always seem to be a couple of steps ahead of where the defence is, Richard says. One of the best things companies can do is to close the gap between offence and defence. Of course you have the traditional threats, ransomware, cloud security, phishing attacks but also threats to industrial control systems and critical infrastructure. He urges a holistic approach to understand your environments and prepare for the next phase. Monitor, take a step back and take a full assessment of your “crown jewels"
Nick Baglin, VP for EMEA, Guardicore Ransomware is one of the biggest threats right now, Nick suggests. There are so many threats that a CISO has to deal with, but one of the foundational strategies has to be how to mitigate against ransomware. Just in the last month we have seen a memo come from the Whitehouse urging companies to take 5 key steps to protect themselves against ransomware, which also filtered through into GCHQ who issued similar. Nick discusses the importance of segmenting the network, because if you assume that an attack is going to breach the perimeter (which is a widely held belief right now) you are going to want to limit lateral movement.
Shiri Ivetsan, Director of Product Management, Whitesource Shiri discusses the management of opensource which is arguably the biggest revolution we had in the last 10 years, but companies need to be aware of issues that can arise from it. Her tips include first of all create a bill of materials, so you know which opensource code you are using right through to understanding the legal requirements of using it. 85% of vulnerability of open source have often been fixed in later updates, so it’s worth making sure you keep up-to-date versions.
Rick Jones, CEO and Co-founder, Digital XRAID Rick suggests that companies should be looking to protect their information assets, their data, which can lead to publicised incidents where sensitive data is breached. Another threat which is more prevalent he says, is ransomware which is becoming one of major threats to 2021. To help limit the risk and help prevent these threats Rick shares some solutions. He says that big and small companies tend to miss basics: Vulnerability assessments, understanding threat landscape, regular patching, making sure there are no easy targets on their cloud environment. Look also at monitoring techniques such as SOC.
Tim Ward, CEO and Co-founder, Think Cyber Shift to working from home and hybrid working, have created new threats, such as sharing devices, use of shadow IT, and all the cues to act securely have gone,. The traditional awareness we normally had has gone, and we have been too slow to adapt to these changing threads and changing contexts. The fact that 90% of cyber attacks start with the human user, Tim argues that behavioural change is key to creating solutions.
Jonathan Slater, Co-founder and CEO, CAPSLOCK CAPLOCK won this year’s DCMS Award for the Most Innovative Cyber Security SME for their revolutionary new educational organisation, they have redesigned higher education to plug the skills gap, at speed and at scale. They are helping bust myths that cyber is not all about tech, their curriculum is built around what industry needs. They are even helping re-skill those in the armed forces. They are seeing there are so many roles available and that the industry really open to taking people on with transferrable skills from other sectors. “This is a massive achievement and lovely to be recognised as an educational organisation that is rethinking the way things are normally done. Education and that skills gap is a problem that needs solving, we are really trying to change the sector in the way it’s done.” They also say that Infosecurity Europe is hugely important to the industry, it brings the whole community together and was a key element in their research in developing their business.
Robin Smith, Head of Cyber and Information Security, Aston Martin
Learn from Aston Martin’s innovative approach to cyber threat intelligence management, essential now in the face of a massive surge in cyber criminality and learn how they have integrated that into futures design. With the surge of ransomware and new tactics such as info stealers, businesses have to continue to defend their organisation against current threats, while keeping an eye on what’s in the horizon. Aston Martin’s case study will discuss how their process informs and helps plan delivery and development over the next decade.
Ian Hill, Global Director of Cyber Security, Royal BAM Group nv
Are we seeing a Cyber Cold War? When you look around at he number of state sponsored cyber attacks and their increased severity against critical infrastructure and even health services, it is clear that there is an escalation. Ian draws some analogies in history on how wars have started in the past and how technology has been a key player. He argues that we can all see from around us that the situation is getting worse and we need to shore up our defences because the reason a lot of these attacks succeed is because we our defences weak in many areas. This is everyone’s problem.
Robert Hannigan, Former Director General, GCHQ
Robert gives us a glimpse of what he’ll be discussing on the Keynote stage. The rising tide of threats, both nation state and criminal, in particular ransomware and how it is changing. We have seen a tidal wave of ransomware in the last 2 years, a growing sophistication in its delivery and what it does once it’s delivered. The second thing is the supply chain, CISOs are realising that everything is connected to this big ecosystem of vendors and suppliers and each of these represents some threat. Considering the events of last weekend, the Kaseya attack in the US, really brings home these two areas, the combination of a sophisticated ransomware attack delivered through the supply chain.
Benjamin Corll, VP Cybersecurity, CoatsBenjamin advises putting processes in place to evaluate, assess and manage the vendors, rate them, make sure you have a right to audit. Also ask them what frameworks they have in place, are they subject to regulatory standards like PCI or SOCs. What reports can they share to show they are adhering to those standards? If they have cyber insurance it gives you an idea of the level of maturity that the third party is at and how well they will treat your data.
Milos Pesic, Global Head of Information & Cyber Security, Make LtdMilos suggests you look at your business initiatives and strategic goals and then base different types of security around these, including data protection assessments. Also abide by domestic laws especially if you are a global company, have legal agreements on both sides and have NDAs, CDAs in place, conduct security risk assessments and know the flow. Look at the different standards, for instance ISO 29 will give you insight into how good your processes are. Education and Communication are also key.
Quentyn Taylor, Director EMEA Infosecurity, Canon EMEA
Quentyn discusses how we can’t eliminate third-party risk unless you do it all yourself, you have to understand that their risk is for risk and if they have a data breach or security incident that you’ve understood the liability you’re carrying. As well as regular security reviews of your third-party provider services, he also suggests starting at the perimeter, what exposures are on the internet and what does that look like to an attacker?
Meha Shukla, Director, Skill-Formation Ltd, Researcher at University College London
Meha calls for holistic operational risk management. With organisations having to sift through a plethora of international guidelines and standards, ensuring operational resilience and understanding liability risks in the event of a disruption is key o helping business as usual in the case of a cyber attack or human error. She also proposes there is a benchmark and appropriate methodologies to understand what 3rd parties need to do for compliance.
Infosecurity Europe is thrilled to announce the Wendy Nather is the 2021 Hall of Fame Inductee. We asked Wendy what she thought of being inducted into the Infosecurity Hall of Fame “it’s a very big deal, Infosecurity Europe is such an important conference for everyone to attend, because it brings so many diverse perspectives. The conference is a highlight of my year, it’s a terrific honour.” Wendy also mentions the importance of the start up booths exhibiting at the show, to learn what they are working on, because they are the seeds of what we’ll be doing in the future. So, it’s an opportunity to learn from both the big companies and the smaller ones.
Maxine Holt, Senior Research Director, Omdia Ensuring companies have access to the applications, data and services with require in a secure manner, ensuring BYOD are secure enough to provide access. Supporting staff who are working remotely in terms of mental health is also key. Combining people, process and technology is key, the “sticking plaster” employed at the beginning of the pandemic, is slowly being peeled back to reveal a dish-mash of security controls that require serious review to make them fit-for-purpose in this reset normality.
Steve Wright, Partner, Privacy Culture Without peer review and with increased pressure people are more likely to make mistakes and try the easy route if they’re not sure. With the 400% increase in cyber crime, to mitigate risk organisations would be best to carry out a proper assessment on the whole impact of remote working, data, IT, general operations. Refresher training is essential, but so it supporting the mental health of those who are remote working so they don’t feel isolated..
David Edwards, CISO and Independent Researcher Packed with some excellent tips on how to get into and move up the career ladder in Infosec, David shares with us his background in IT, working as a solutions and enterprise architect, and how he moved into Infosec and hasn’t looked back. He describes the fascination he finds in the job, and gives some motivational advice on how how to get into Infosecurity, how we should get rid of the stereotype maybe and look to personality and individual quirks as these may open opportunity to find the best fit in your team. His prediction of automated pen testing being one of the possible new solutions to fight automated cyber crime, it’s an excellent time to enter the industry.
Steve Wright - CISO, Privacy Culture / Former Interim DPO Bank of England Work hard and enjoy the journey! Some valuable tips to get ahead from Steve in our interview with him here. Honing people skills like empathy especially in today’s pandemic is also essential. To encourage more people to get into the sector, he explains how Cyber is more professional now, there are also more courses offered by universities, but we can do more as an industry, open up apprenticeships and internships to allow the next generation to try and see if Infosec is for them plus there are tax incentives for organisations. We should also be looking at reaching out to schools maybe even making it part of the curriculum.
Sarb Sembhi - CTO/MD, former CISO, Virtually Informed Sarb has such extensive exposure to many aspects of Infosecurity, from infrastructure to cyber insurance. He describes how the human element got left behind in our recruitment within the industry, the tech can be learnt, we need more leaders who haven’t come from a tech background who can deal with issues the right way, recruiting from neardiverse backgrounds can also enrich a team. The next Big Things in our industry AI/BlockChain/Edge, Cyber intelligence so many aspects with many opportunities for people to get involved in. Sarb recommends, to get ahead and move up the career path, you should get involved in thing outside the paid area of your work, this is where opportunity and experience lie. You never know where that may take you.
Ryan Algar, Security Engineering Manager, William Hill Ryan describes his journey into Infosec, from general IT into senior technical lead and senior management, across digital forensics through to the security weapons defence sector. He has learn so much across the different threat landscapes in each sector. He advises people to learn as much as possible about a wide variety of technologies because in security you’re never dealing with just one thing. Read what you can, there are great news articles and podcasts to gain knowledge about the industry as a whole. He has been that those who have the enthusiasm do do well, so take every opporutniy, don’t hold yourself back. With AI and Machine learning coming to the fore, there’s a gap in the market for people with programming skills to help alleviate the pressure, also with the adoption of cloud this is a good aspect to look at if you’re thinking of getting into Infosec.
Paul McKay - Senior Analyst - Security and Risk, Forrester Research Paul shares with us his personal journey and describes his fascinating current role which he says is such a privileged position to have the exposure at such a high level in effect acting as independent arbitrator. He opens up about his journey into Infosec, as a result of his ability he entered consultancy at an early age and faced challenges as a result. However working hard to prove himself he has gained a respected position and works across countries. As well as celebrating the fact that remote working has opened up recruitment opportunities over and above purely metropolitan regions, one of his key messages is that we should be reaching out to universities, colleges, schools with clearer explanations of what experience and qualifications students need in order to achieve a successful career path. There are also too high and unrealistic entry requirements for even entry level positions. We need to be realistic in order to attract the new talent.
Maxine Holt, Senior Research Director, Omdia
With 3 decades of experience, Maxine started her career with a BTEC in Computer Studies, going on to work as a developer, analyst and consultant and switched. She celebrates just how wide and varied roles are within Infosecurity, her role is fast-paced, there’s always something new going on and something new to learn. Having experience in different roles within a company can give you a much broader perspective. Addressing skills gaps and recruitment challenges can be helped by reaching out to schools and colleges to help educate teachers and students on Infosecurity. At the moment this is a real problem which can be solved if we all pull together, the media and individuals to help inspire the next generation.
Mark Nicholls - CISO, Chime Group Have we ourselves created the problem in our recruitment struggle? There are so many roles within the industry that having an open mind and recruiting people from a wide range of backgrounds, including those from non academic backgrounds can enrich your team. There are people out there with a hug interest in the industry that they will go above and beyond to train and excel within the roles. If you are looking to get into Infosec, networking is a good way to connect with people in the industry and see which sectors appeal to you, Infosecurity Europe when he went years ago he found intimidating but was exciting too. A great idea Mark suggests is to have a mentorship programme where newbies into the industry can be taken round the show by a professional.
Heidi Shey, Principal Analyst - Security and Risk, Forrester Research With a background in Economics and Art, it might seem like an unlikely foundation into Infosec, but as Heidi has found, all the experiences we have add to something, her skill set enables her to look at things differently. She recommends giving yourself a chance, push yourself outside of your comfort zone and don’t embrace imposter syndrome, stay hungry and keep learning.
Amar Singh - CEO/CISO, Cyber Management Alliance
For Amar, every, day, every minute is different. To get ahead and progress, he says, you need to have passion. We are hung up as an industry on certificates, sometimes passion can be worth much more. Anyone can get into Infosec, “this industry is for you”. Yes we do need the technicians, but we also need a mix. The Pandemic saw many companies losing control of what they thought they had control of, but he says it’s been a period of Trust, Adapt and Innovate, and this is set to continue. We should be looking to the much younger generation, reaching out to inspire kids, encourage them to play around with robotics, hacking, building things, programming. Get them excited about it. It should be a national pipeline, ideally with lead inspiration from people in government who might do well to demonstrate programming knowledge to inspire the next generation.
Troy Hunt - Regional Director, Microsoft; Founder, HaveIBeenPwned
Troy is frequently cited as an inspiration to many in this industry and he shares with us some tips on how to get ahead. One of the things he mentions is to think about your online professional presence where prospective employers are looking not just for what topics you’re engaging in for instance on Twitter, but also ‘how” you are engaging, are you writing code on forums and so on. A benefit of the pandemic has been that for some in the industry working from home has suited as some of us can be quite introverted by nature and so have proven that remote working can be extremely effective. Friction of change is lower when integrating new staff, and for employees wanting to change being able to market yourself around while being in one place has also been an advance. There are some big things we are seeing in Infosec, from IoT, through to the Ultimate Authentication scheme we are also seeing the zero trust principle playing out and less scruples on the part of nefarious parties.
COVID-19 accelerated the cloud journeys of enterprises large and small. As part of this settling-in, security functions are peeling back the sticking plaster that did what it could for security in the early days of the pandemic, and are focusing on building more sustainable security for the expected continuation of remote working and changed business operations. Omdia research undertaken midway through 2020 found that during the pandemic, remote working accounted for 54% of the total employee base for organizations, up from a pre-pandemic level of 18%. Moreover, plans for post-pandemic showed that 34% of the employee base is expected to be working remotely. As 2020 has progressed and cloud journeys have accelerated, then the biggest challenge has been the security surrounding these newer ways of working and actually finding the staff with cloud security skills and expertise. With the recent high profile Manchester United cyberattack, ransomware isn’t new but its really grabbing attention right now and this isn’t going to go away, unfortunately.
2020 saw us all adapting and adjusting under duress, 2021 will see us getting better at it but with the increase in having to do things more digitally, and the increase in data, the entire attack surface has also increased. In terms of innovation, with millions of websites, billions of people using them, many using the same passwords, we will see the trend in improving authentication schemes continue.
Forrester published their research on trends recently which covers many trends and predictions, but I this podcast, Heidi shares with us three lesser known predictions.There will be an increase in companies collecting and analysing employee data, but care and governance are needed. Secondly a CISO from global 500 company is going to be fired for instilling a toxic culture. This has been bubbling up for quite a while, but will come to a head in 2021 which will be the year of reckoning for that type of failure. Finally, for technology and start ups, funding for non-US companies will increase by 20%, funding will come from Europe and elsewhere.
Becky Pinkard, CISO Aldemore BankCyber Resiliency came in focus in 2020 where we saw companies scale and speed up digital transformation. We will see testing and the proving of different pillars attached to operational resilience continue, with a focus on what are services customers need, what they depend upon. Will we see companies thinking about the box more, making sure they are ready for next big challenge, taking advantage of technologies from block chain, distributed ledger, extended reality, AI, quantum computing, being more proactive, exploring new technology to help with that resiliency lens. We will also see more deep fake technology, potentially influencing companies and politics for example vishing. With the threat landscape now so wide, will we see more backing behind educating the public about cyber security?
With Covid-19 having such a phenomenal impact on businesses, we ask Bridget Treacy how has this impacted SMEs’ ability to manage cyber resilience:
Who should be training and supporting small businesses? Government, large tech companies, the companies themselves? It has been really tough for small businesses, especially when it comes to finding support. Forums like Infosecurity Europe are particularly important to bring organisations together, where there’s a wealth of learning on offer for small organisations.
With Covid-19 having such a phenomenal impact on businesses, we ask Maxine Holt how has this impacted SMEs’ ability to manage cyber resilience:
The speed companies had to move to remote working was a huge challenge particularly for small businesses who typically do not have a security function, there was a “sticking plaster” placed over security during the rapid shift and this approach isn’t really sustainable.
With Covid-19 having such a phenomenal impact on businesses, we ask Heidi Shey how has this impacted SMEs’ ability to manage cyber resilience:
Very few large corporations let alone small businesses had a business continuity plan in pace for responding to a pandemic. Just trying to maintain operations meant that security wasn’t necessarily the key focus. Most spending was reactive. Cyber Resilience is a necessary part of business operations, not just a nice to have.
With Covid-19 having such a phenomenal impact on businesses, we ask David Edwards how has this impacted SMEs’ ability to manage cyber resilience:
The speed, lack of skills and resources, combined with the pace to market means more risk is taken. David suggests that there could be an easy access small business tax relief for staining Cyber Essentials. Does the amount of money spent on cyber resilience depend on the revenue companies have taken in over this period? Are we seeing a survival of the fittest?
In the future, the Covid-19 outbreak might be viewed as the moment when the way world used to work fundamentally changed. Working from home is currently the work mode of choice for most companies who are able to maintain operations. This new paradigm shift has also created a serious challenge for information security professionals. CISOs around the world all are scrambling to figure out how to keep enterprise information assets safe when the user computers are not secured by the standard enterprise level controls. Attending such global virtual events are the ONLY way now to share our problems and ideas with a larger group of fellow InfoSec professionals. ‘Cyber Resiliency’ is more important than ever. We will discuss these new threats, how can we better defend our organizations against those threats and be more resilient
Learning never stops, and as many of us are now working with new schedules, we should embrace the fact that this new virtual conference gives us flexibility and also the opportunity to come together to discuss solutions to the challenges we are now facing. In James’ session he will be stressing how with this change in behavioural and usage patterns we should be establishing a new normal baseline as quickly as possible, how we should be rebalancing risk and support business continuity.
In its 25th year InfoSec Europe is the leading European security event, it is even more important we come together as a community of Infosec professionals to respond to the changing landscape and the threats it brings. My session "New Ways of Working and Securing Businesses Remotely to Achieve Business Continuity" will bring together a panel of experts to discuss how we as security professionals adapt to the "new normal". This pandemic has certainly opened our eyes to how businesses can adapt and survive, but of course this brings new InfoSec challenges we must respond to.
One of the few great things to come out of the Covid-19 pandemic has been cyber security’s response – not only are we pulling together more than ever, but doing so in more innovative ways. I look forward to supporting the Infosecurity Europe event as it also rises to the challenge of continuing to unite the industry through these challenging times. We need current, topical security information now more than ever – and coming together across platforms with global reach capability is a true testament to the fortitude of those on the cyber security front.
Having the conference go virtual shows that we are an inclusive industry, we are sharing knowledge and working together for a more secure world and the virtual format is natural in the digital connected world. Not only does it reach a wider audience, but also has a better impact over our environment. Her session will cover how having more digital communications, working from home and seeing each other less adds to information overload and can make us more vulnerable to attacks. Supply chain attacks have been on the rise in the recent years and now we are more vulnerable than ever to them, especially to business email compromise (BEC)
Becky Pinkard, CISO, Aldermore Bank
With our recent poll on cyber resilience indicating that the main solution rests with the human in the loop, Becky discusses the frightening statistic that with stress levels reaching an all time high for CISOs we are seeing an average life-span in a role of just 18-24 months. She goes on to describe how the pressure is so high that anyone in cyber security will be able to tell you a time when they’ve made a mistake.
Paul McKay, Senior Analyst, FORRESTER
Are we seeing a crisis in the cyber security industry? Paul discusses how human skill and expertise are the most important element of a cyber resilience approach, but this combined with the fact there is a struggle to recruit the right staff, the stress levels in our industry are at an all time high. "I don’t think I’ve ever seen security professionals under this much pressure."
Becky Pinkard, Chief Information Security Officer, Aldermore
The way Norsk Hydro dealt with their data breach could be viewed as a gold standard in incident response, Becky discusses that as well has having a stress-tested and documented response plan, companies should focus on how transparent they can be with their customers should an incident occur. Enterprises should also be looking at support teams, security is a 24/7 job and professional burnout can easily fracture a strong performing team.
Maxine Holt, Research Director, Ovum
From examining shadow IT systems through your ‘e’-discovery process to ensuring you have a 6-P mantra (proper preparation and planning prevents poor performance) at the front of your mind, Maxine takes us through how you should be addressing data breach with a good cyber hygiene regime. Proactive threat hunting is more than just scanning.
Troy Hunt, Microsoft Regional Director, Founder of Have I Been Pwned With the US elections taking place in 2020 there will be a focus on that of course, but Troy also highlights credential stuffing, we have more data, more user names and passwords. We could also see greater government access to communications and continuing trends like IoT creating even more data (just consider the Aadhar biometric system). Could there be a major data breach (think Madison breach or Equifax) or a serious terrorist attack?
Killian Faughnan, Group CISO, William Hill
There will continue to be some long-standing trends in 2020 including skills shortage, but Killian suggests companies will begin to recruit from other professionals rather than purely security. He also predicts slow but steady improvements in security awareness at board level; cloud security; increase i discussions around automation vs augmentation and access control (including BYOD and mobile - which are difficult to solve without being either too restrictive or too lenient).
Becky Pinkard, Chief Information Security Officer, AldermoreIn the bid to keep pace with consumer demand and technology capabilities, industry is borrowing more technical debt than it’s repaying and that is catching up to us. As a result, Becky discusses how we’ll start to see more headlines focused on successful attacks due to this growing technical debt and the associated “shadow risk” it creates.
Paul Watts, Dominos, CIO of Dominos Pizza Group With a real worry of a possible cataclysmic digital 3rd world war, what sort of epiphany needs to occur before fundamental issues need addressing? Will we see a consumer revolution? Also we are in a ring of cat and mouse, with the speed of digital innovation racing security solutions.
Mark D. Nicholls CISM MCMI, Head of Information Security & Governance, Peabody Compliance and large scale breaches are driving investment, but rather than being the weakest link, we should also consider people as one of our strongest lines of defence alongside automated solutions.
Becky Pinkard, Chief Information Security Officer, Aldermore Bank. Becky reminds us of the Morris Worm and how we should learn from that in terms of how similar platforms are being used across the board today. She goes on to discuss how regulation should be a key issue and how CISOs roles could be better defined to help.
Troy Hunt, Microsoft Regional Director, Founder of Have I Been Pwned?
What will the next 25 years look like for cyber? Will we see an act of war on critical infrastructure? Will we see more regulatory penalties hitting corporates, what about the executives themselves? Troy Hunt shares his thoughts on how the next two and half decades will shape up for cyber.
Andrew Rose, Chief Security Officer, Vocalink Mastercard company suggests that AI and Machine Learning are two elements that offer tremendous hope in cybersecurity. The ability to recognise outlier events, edge cases and subtle behaviour change, and then automate responses, will help industry tackle issues before they become incidents.
David Edwards, Head of Information Security in the Financial Sector, gives his views on how AI is leading to new inventions, and how start-ups are taking advantage of several banking APIs to invent new ways of saving and payment. He describes how he will also be showing one of the first platforms in the world to have real time conversations designed with social constructs to implement deception in order to train staff.
Keynote speaker Maxine Holt, Research Director for Ovum shares how innovation is key to moving forward, with not only advances in accelerated learning freeing up time for other staff, but also how Machine Learning and Deep Learning is driving insight into threat intelligence.
We speak with Phil Beecher, President and CEO of the Wi-SUN Alliance on whether there is a convergence on cyber and physical and if there is scope for collaboration.
We ask Paul Edon, Senior Director of Technical Services for Tripwire his opinion on security of IT and OT environments and how we’ve matured in both of those areas, the position we are in at the moment and where we need to go.
Sarb Sembhi, CISO, CTO for Virtually Informed discusses an overlooked issue that Cyber Physical attacks can be targeted towards the very buildings that companies are operating from.
Will systems become harder to secure as they become more complex or will organisations see 2019 as the year to streamline technologies and processes to simplify their security architecture, a topic which will be hotly debated during Infosecurity Europe 2019.
We asked Paul Watts, Chief Information Security Officer for Dominos Pizza UK & Ireland what his thoughts are on this subject.