In this episode of Cyber Security Inside, Camille and Tom revisit the best pieces of cybersecurity advice from experts they have interviewed throughout the year 2021. This advice is for users, companies, and manufacturers.
They talk about:
Always being prepared for the worst-case security scenario, such as the SolarWinds attack.
Accountability in cybersecurity and putting the training focus on IT and security professionals, rather than just users.
How remote work has impacted cybersecurity in how we access our work digitally and what physical systems we are able to have set up in our home.
How security should be a part of every aspect of a device, not just a feature.
... and more. Don’t miss it!
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
Here are some key takeaways:
This is a special edition of the podcast where Tom and Camille look back at tips and advice guests have given about cybersecurity over the year 2021.
One piece of advice, from Eric Cole, was to always operate as if we are going to be hit by something like the SolarWinds attack at the beginning of this year. He talks about having firewalls and filtering devices to limit access to your private network, and to use software sniffers to make sure there is no extra activity or connections.
Accountability in the security industry is very important, according to Malcolm Harkins. When there is a large-scale attack, there needs to be a review to identify what controls failed, label what failed and the company that sold you, and put it out publicly.
Right now, the way we put blame on people for cyber attacks is by putting that blame on the users, says Malcolm Harkins. We tell them to be more careful, to be more informed, etc. Being cautious is good, but we also need to understand how to make systems in general more secure and more accountable. This is because we limit what computing can do by scaring people and putting blame on them. The way we engage with computing is the same way we become vulnerable to attacks. We have to train users, but we also have to have accountability on the company’s side.
Right now a lot of training that is occurring in cybersecurity is on the user side. But maybe it should be more on the IT/developers/technical population side. It would probably have a bigger payoff in the end.
Doing the basics is super important. Keep your machines updated, use vulnerability fixes, etc. But do it across your entire infrastructure.
The Work-from-Home necessity has also created different technology and security needs and risks. Devices are now hooked up to at-home devices (consumer routers, printers, etc.) that open up more opportunities for attacks. Also, because of the speed at which devices had to be available, things were missed and infrastructure was not correctly set up with cybersecurity in mind.
According to Carolina Milanese, there are essentially two options for companies with employees working remotely. The first is for the IT department to dictate everything about how you connect, what you use, etc. The second is for IT to just provide the equipment with cellular connections. When working remotely becomes an option more than a mandate, corporations will likely have really specific requirements not only for your tech, but also for your space and furniture for liability purposes.
Security is not just a built in feature, but should be a part of every aspect of a device. Having a learning mindset is important; it allows us to take what we learned from previous issues and build that into future products to make them better. This is seen in threat modeling.
Security impacts everything, whether you have thought about it or not!
Some interesting quotes from today’s episode:
“Make sure you’re very careful and deliberate about updates. A lot of vendor software updates are functionality that you don’t need and add complexity. So have a strict rule that you’re only going to update after verification and validation.” - Eric Cole
“The people that I know that are in the security industry have been saying for so long that it’s just a matter of time. This wasn’t actually a groundbreak attack at all, other than it was a large enough scale attack to where it was newsworthy and people that really hadn’t been paying attention that were kind of sleeping, finally got shaken by the shoulders.” - Tom Garrison on the SolarWinds attack
“Yeah, not really a wake-up call when it’s the fifth time you’ve hit the snooze button on your alarm.” - Camille Morhardt on the SolarWinds attack
“I think we are doing band-aids, bubble gum, and baling wire making up for dated security technologies and other technologies that won’t work; they’re insufficient and flawed controls.” - Malcolm Harkins
“But how do I use my computer? I click on things. I open things, right? If I’m afraid to go do that, I’ve just reduced what computing is about and how I use it and how I engage it.” - Malcolm Harkins on where we put the blame for cyber attacks
“Just think of your phone, you know, which is… a consumer device. But how much data exists on that device?” - Tom Garrison on the work-from-home situation and where vulnerabilities have opened up in the last year
“To be honest, teaching people how valuable that data, that information is so that there’s more of an understanding of how I use it, where I use it, what kind of device I use to access it and so forth.” - Carolina Milanese on what can help secure remote and cloud-based work.
“Every system is different and used for different purposes. Thus, every threat model is unique and deserves its own diligence and attention.” - Johnny Valamehr
“Security should be a part of everybody’s job and everything that you do you need to think, is there a security impact to what you’re doing, even if it doesn’t seem like that in the beginning?” - Dina Treves