Cyber Security

Panel discusses technology defense mechanisms

How safe do you feel about your information?
How safe should you feel? Providence Business News has put together a panel
of experts to discuss that issue and much more.

Beyond Cash Donations: How New Forms of Giving Are Transforming Not-for-Profit Accounting

Evolving Funding Landscape for Not-for-Profits Not-for-profit organizations are being asked to do more with less,…

Learn More

Stephen Chow: During my day job I spend a lot of time looking at telecommunications
technology. I happened to be a patent lawyer, and we look at various business
schemes that have come up because of the enablement through the Internet and
other electronic devices. I also act as a volunteer, as a uniform law commissioner
drafting laws that are applicable to commerce. In doing so, we are always weighing
the rights of both the individual and of enterprises in the idea of privacy
as well as balancing that against security. What we’re seeing today is an enormous
amount of information that is moved around some of which is just left at enterprises,
at businesses that people don’t really keep track of. What happens sometimes
in lawsuits – and I’ve acted as a special master going through people’s computers
to make sure – to see what kinds of information is there, what is appropriately
discovered in the litigation and what is not. And this is a major problem. We’ve
seen it happening more on the West Coast but certainly is moving here on the
East Coast as well. How do you keep your records straight?


James Mignone: The services group that I work in provides all the technology
and operations support for the bank, and as a bank we commit substantial resources
toward security generally. You know, when you walk into a branch, you think
of the tellers and the plastic and the vaults and all that stuff. Well, in the
same way as we looked at the Internet and doing commerce on the Internet, we
provided a tremendous amount of resources toward providing a secure way of banking
on the Internet. What that means changes daily, a little bit different from
the vault in the back that’s sort of been static for many, many years. The thing
I want to stress today is that it’s a partnership though we can do our part,
but our customers and everybody else has to be very aware that the Internet
is inherently insecure, and as such you have to be smart about what you’re doing
and think about what you’re doing. One of the things I’m going to probably stress
too many times – but I want you all to hear – is that when you are solicited
via the Internet by a financial institution asking for private information,
delete it. No reputable financial institution is going to ask for information
that they should have in their records. So that’s a common theme that I’ll probably
keep repeating. But generally speaking, online banking is really quite safe
as long as you take the precautions that you need to take, and you can be sure
we’re highly regulated. Those loads of regulations around what we can and can’t
do in terms of customer information and the security surrounding it. And we’re
checked by that by a number of institutions. So you can be sure that it’s safe.
If there is a breach at Citizens and you ever had any loss, you have no liability.
One of the things you want to think about too with that is whether you have
– your bank is giving you 100 percent liability coverage or not.


Tom Turner: My day-to-day responsibility is the product strategy for
a single technology that tries to address a certain area within the information
security problem. My observation the last five or six years of being in the
security industry is that one thing is true. The cyber security paradigm is
one that is – it’s a game that you always have changing offense and improving
defense. And while I focus very solely on a single product, I see that security
isn’t just an issue of security technologies, but it’s something that should
be imbedded in every business decision that we make. And that has not been the
case for most of the customers that I spend my time with. Security is still
a very reactive practice for most enterprises or institutions. And the end result
of that is that we are always essentially playing catch-up to things that have
already occurred. Now technology can absolutely help to improve a company or
an institution’s security posture, but it can’t solve the whole problem. And
I think what’s very important to understand is that user education and user
participation is absolutely critical for any security framework to be successful.
And that for users to be truly engaged in this requires security to be at the
highest level of thinking within the company. This needs to be a boardroom decision,
and this is slowly beginning to happen because companies have experienced so
much damage in the last three to five years. And I think that’s really what
I hope to leave everybody here with is that while technology will continually
change in response to the threats that will evolve, the only way to truly sort
of become more resilient is to put people and technology together.



Steven Ursillo: I’m the director in principal of a CPA firm where I specialize in technology insurance services, and my role basically from assisting clients from a consulting standpoint would be to go out and guide them in the ways of designing their security policies, coming up with the proper risk management techniques in order to channel and reduce the exposure in a lot of these risks that happen on the Internet and internally within the organizations. My group gets involved from security implementations to security audits as well as penetration tests being that we are actually put on the offense to direct attacks with the authorization of a client to try to look for holes in their systems and vulnerabilities within their systems to provide firsthand assurance that there are problems. More times than not, a lot of the controls and responsibilities that go into providing secure systems is always a cost benefit analysis that has to be done. And the best way to enlighten a client as to whether or not something is significant vulnerability would be to present that. You can demonstrate that that vulnerability is exposed, and that will expedite a lot of the processes behind getting those controls in place. But as mentioned earlier, and I think it’s extremely important that information security is not just one person’s responsibility. It is an enterprise-wide issue from people who don’t use their computers to users to managers to executives all the way through the channels because one user walking away from a terminal with sensitive information on the monitor can expose some highly confidential information. So our responsibility also for financial institutions and consulting and audit and test work is also again training and providing these users with the risks that are out there.


 


Michael Pare, PBN Editor: Stephen Chow, I get the impression with
some issues, by the time they arrive at your desk, they must be at a pretty
serious point. What are some of the pressing electronic security issues facing
businesses today?



Chow: I think that some of what the other panelists have talked about which is direct attack and invasion of the computer systems tends not to be as major an issue for – on the lower point of view. People are shut down for various reasons. Smaller businesses have different types of problems with these situations. But what I see as a concern for all businesses is really how you handle your communications inside. People do use e-mail in a way that they think they’re talking on the telephone, and they make a lot of comments that are quite embarrassing if it turns out in litigation later on. Often almost any kind of litigation that involves employees or between businesses results in looking at e-mail, and a lot of that e-mail is not, was not intended to be brought to the public in terms of written materials.


 


Pare: Is that fair game in court?




Chow:
It is fair game, and sometimes it’s very intrusive because people do use their computers as their personal – they use it as their telephone. You do your shopping on it. You look at your stock quotations. People do surfing of inappropriate things, and often that comes up as an issue. Another thing that comes up for smaller enterprises are because of the interactivity of the Internet, there’s such things as Spyware, things that are brought into your computer to – so you communicate and so you can go to Web sites and not have to enter all your information. It’s pop-up ads when – that are appropriate to what you’re inquiring about. It’s been a balance between whether that’s just pure spam and something that people just want to get rid of, or is it a legitimate advertising means? In larger companies, those things are often prevented by firewalls and things that prevent you from interacting, but in small enterprises typically you have these things. And those (inaudible) create the computers that offer a vulnerability to viruses and worms and those kinds of things.


 


Pare: Are you seeing that, Steve Ursillo, in some of your clients this
kind of thing – hackers coming in?



Ursillo: Absolutely. Unfortunately it’s extremely realistic, and I think that one of the difficult issues that I come up against when you’re dealing with smaller organizations or mid-size organizations is they don’t really see themselves as a target. So one of the things I like to bring up is that … most attackers out there aren’t looking to target a particular information. They’re looking to target a vulnerability. They’ll stay back, and they’ll scan, and they’ll look around on the Internet for these types of vulnerabilities, and when they do pop up, they take it to the next level. They try to find out who owns the system, what could potentially be on that system, what system does that have a trustworthy relationship with because if they attack one particular system that’s exposed to the Internet, they can use that as a launch pad to get behind a network and then behind other networks where there’s more confidential information that’s supposed to be protected. So it is an extremely sensitive issue, and even the smallest companies – I’ve seen small companies deploy servers with the proper logging mechanisms and intrusion detection, and within a day of being up, there are attacks launched against their network just looking for these types of vulnerabilities.


 


Pare: Tom, how critical is security a factor when you talk about building
on networks and rolling out new business?



Turner: I think in the past security has been a hurdle for either application owners or people charged with building a new sector – segment of a network to try and blow through because they’ve seen security as really being something that gets in the way of productivity. And so we see that that’s always going to be a challenge for any company or any user who is trying to utilize either the network or the computer to gain a business advantage, anything that puts constraints around that time to market is – you always have that natural tension. In the past I think security was always an afterthought. Security was never really built in to networks. Security was delivered in appliances later on to deal with problems after the fact. And what we’re absolutely seeing is now the customers are demanding the security not just be an add-on that they pay for but is absolutely embedded in everything that they purchase. So a very good example of that would be voice-over Internet – voiceover IP – the ability to transmit telephone calls over the same wires that you have your Internet connectivity. Well, security absolutely has to be part of that solution, not something that you bolt on top because we think about the resilience that we demand from our voice infrastructure. So I think it’s changing is the answer to the question.


 



Pare: Stephen Chow, I’d like to address what I think is something that we can all relate to, and that’s unwanted e-mail and spam. What’s being done to address that as it continues to clutter up our inboxes?



 



Chow: We’ve had a number of state statutes that try to address the issue, but what Congress enacted very rapidly with a statute called “can spam,” or some people call it “can spam?” because the question is whether it really is effective or not. The thought is that really what the issue is to try to address – get to the spammers’ real address as opposed to the kinds of what you call spoofing things that are sent and put into people’s computers all over the place, and spam is sent from different places or just the addresses are really put in as fictitious addresses. There was a thought to try to get a do-not-call registry, but the FDC and FCC both decided that there was really two – if you had a registry you would actually invite people to spam all people on the registry. What is happening right now is there is perhaps an effort, an agreement to try between some of the large public network players, Microsoft, American Online, Earthlink and Yahoo to create a system where you can actually identify the actual physical address that these things come from and actually call for identification through digital signatures of perhaps the person who is sending these things. The problem with that is still that some of the Internet was set up so that you could do things anonymously, and this would beat that segment of society who wants to do things anonymously.


 


Pare: At what point, Stephen, does some of this stuff that we may think
is innocuous or just time-consuming, when does it become illegal?



Chow: Well I think that where you see these things happening as more on a commercial speech side. You see people who are setting up Web sites who criticize their employers. There are Web sites that criticize someone else, some other competitor, and you have calls about that. Generally the same rules go for that as in defamation. There’s a certain amount of free speech where we expect in our society. But in terms of doing things illegally when you do invade someone else’s site or you violate someone else’s trademark – those things may be actionable.


 


Pare: What about if a company’s computer that is shut down for an afternoon,
and it means hundreds or tens of hundreds of thousands of dollars in some cases?



Chow: Well, certainly that’s cause for federal prosecution as well, but often in those situations you can’t find these people. The way that many of these things are set up is to use – to distribute the different attacking programs in people’s computers that it’s totally innocent. So maybe you have 500,000 personal computers sitting around the country trying to flood one company with a lot of requests. That’s called a denial service attack.


 


Pare: Tom, is there a silver bullet to address that somewhere down
the line, maybe not today or tomorrow, but next month



Turner: I’d love to tell you there was.


 


Pare: Trademark it, right?



Turner: Yeah, back to my original point that technology is improving. And the more the technology includes security, whether it’s something that’s not really related to security, it’s the control servers that you have in a voice-over infrastructure or if it’s in databases that are shipped natively with the customer relationship management software that you purchase, technology will help improve the problem. But I think anyone who has been in the security space for any period of time, or anyone who is trying to establish and manage risk within a company understands that there’s no such thing as 100 percent security. Our best efforts are a layered approach. And that layered approach is easy if we have or easier if we have buying throughout the whole company. I can absolutely foresee the security situation improving from the standpoint of us being proactive, but there is no silver bullet. Individual layers will improve, but we have to understand and believe and work within the constraint that any single layer of an infrastructure can fail from a security standpoint if someone is really actively trying to defeat it.


 


Pare: Steven Ursillo, are you seeing your clients getting more confident
in the security that they have out there?



Ursillo: Well, I think that as Tom was saying, it’s clearly a case of self-defense. You have to protect yourself and wait for everything else to evolve, and a lot of that growth of spam and the problems that you’re having with these Trojan horses and back-ends into systems is because so many people have unprotected systems out there, and it’s just a way of replicating and making things worse. So if you take a real self-defense standpoint – and that’s what we do with our client base is basically get in and try to assess, but it’s again subject to the cost benefit of what’s going to be allowed to be spent to prevent this risk from actually occurring, or prevent something from occurring. So there are means where organizations will set up gateway level enterprise protection that will filter and go through the content of these types of mail messages or these types of packets that are coming through the Internet and just allow them to get access to the user, so they don’t make it to the user.


 


Pare: Let’s talk for a minute about wireless technology. It’s becoming
much more popular these days. Does this pose its own additional security risks?
Steve, do you want to start?



Ursillo: Absolutely, wireless technology especially because of the growth and the level which wireless technology has come in – a lot of the applications and network infrastructure didn’t really have to change. Wireless technology was just another way for users to be able to access the systems in which they had without physically being attached to them. So one of the major risks that wireless security really poses is that it eliminates the physical protection of your enterprise, so if you don’t need to be on a wired network, you don’t have to be within the doors or within the gates of that organization’s perimeter. You can potentially be out in the parking lot. You can be three blocks down the road. You can be potentially miles away depending on how it’s deployed. So the challenge becomes for these organizations in when they deploy this wireless technology to make sure that it’s prone to a particular area where they know that the users are going to be. And another risk that really poses is that companies spend hundreds of thousands of dollars in infrastructure to protect their local area networks, to protect their enterprise. By putting up a wireless access point that you can get for a $100 online or something like that, you’re completely bypassing all of that technology and allowing somebody potentially to get right on the network if it’s not protected. Some of the ways that we address that are clearly in the ways of scanning for what’s called ROQ access points or unauthorized access points. That allows us to see if there’s some type of access point out there that’s allowing these wireless connectivity to take place unauthorized against corporate security policy. That is an extreme risk as it relates to particular companies infrastructure.


 


Turner: Cisco is a big provider of wireless infrastructure. I think
to draw an analogy, you have to look at wireless as another doorway into an
enterprise and just assume that going forward there will be more and more egress
points. The point that was made by Steve was that you’re aware from the physical
security provided by your building. And we see with the wireless space as well
as with even wired connections now that we have a very transitory population
in our user base. Most people have laptops today instead of desktop computers
and have the ability to plug them in at any place that they happen to be it
a hotel room or in an airport where there is a wireless access point. And there
are technologies like BPM’s that certainly help to guarantee the integrity of
the data or ensure the integrity of the data a little more.


 


Pare: Jim, do you see wireless entering the banking industry?



Mignone: Well, actually some banks have tried to introduce wireless, and there actually hasn’t been at tremendous amount of consumer demand for it. And to build it securely takes a tremendous amount of effort. For our internal users, we have some wireless solutions. But we’ve really built the security into them, but we don’t allow wireless access on our LAN right now, and we work hard to make sure that it’s not there. Until there are solutions that really can make it fairly as safe as the rest of it, we just don’t allow it.



 


Pare: Stephen, are we seeing wireless – the results of some of that entering
the courtroom?




Chow: Not so much in a courtroom yet. The wireless situation is – I think has been mentioned that some of the security related to it is available through encryption, but others it’s a question of whether there’s a computer that’s coming onto your network that you don’t know about. The issues on wireless of legal point of view have tended to be more on the privacy side.


 


Pare: Tom, who needs to be responsible in a given enterprise for some of
these concerns? And should it be a particular person or group or department,
or what is the defense strategy?



Turner: Well, I think we see certainly when I talk to customers on the matter of the size whether it’s a very large service provider to a small- or medium-size business, the security hat can be worn by a variety of people. I think you find that in the wake of a security incident, then the hat is worn by the CEO. So if we look at some of the airlines that were unable to fly planes when some of these more recent Internet attacks came along because their reservation systems were down, this suddenly became a board level discussion. In the past, security has been the preserve either of the network administrators or a security director, and it’s often been difficult for security to be truly implemented across all the business applications because back to my point earlier on, the security had been an afterthought. What I’m seeing now, and I imagine that some of the enterprises in this room are saying this, is there is the establishment of someone who is now called the chief security officer or chief information security officer.


 


Pare: I want to get back for a minute and talk about the privacy issue
because that is so important. You know, Stephen, how does privacy fit into since
we see in health care we have HIPAA, and that has changed that whole health
care and insurance industries. How important – where does cyber security sort
of fall and most important element in each of these cases?




Chow:
Privacy comes about from a number of different sources. In Europe, which tends to be leading us in privacy, there’s really the memory of the World War II and some of the dictatorships that identified people and sent them to concentration camps. So they’re very careful about identifying people on a personal level. In the United States though we’ve looked it much more from a search-and-seizure approach coming from our Constitution so that the question is how intrusive is someone searching of your identity. The Supreme Court just ruled on a case where one, on a five-to-four basis, where one did not have the right to say to the police that ‘I will not show you any identification.’ Many people felt that you should – if you’re not suspected of a crime, why should you necessarily answer to police to show identification. In today’s closet of course this is for security purposes very much – it’s important. In American society about one-quarter of individuals really feel an inherent need to have space and not be tracked, not be tracked by discount cards or affinity cards and those kinds of things. That tends to be put aside where privacy really looks at effects such as identity theft, conversion of health information to HIPAA and these other things. They’re very focused on those kinds of information.


 



Turner: From the standpoint of product development, I think we are developing security products in the business unit that I work in, and the difference between security and privacy isn’t always very easy to understand. I can give a concrete example where the technology we develop helps to identify and hopefully stop malicious behavior on either desktops or servers. And in reporting that back to a central management console, you may identify which machine that was and who the user was, and for us to sell this in Europe in certain areas, we have to remove that information. What we’re trying to do is solve the security problem. But we are running into some privacy regulations where the way the privacy laws are written in Europe, the disclosure of that IP address or the user name on that computer violates the privacy law because the identity is being taken off that machine and sent to a central area.


 



Pare: Are some industries ahead of others when it comes to addressing cyber security, and are some industries behind the times?





Mignone: I would say generally financial institutions. I mean you’ve got to look at – the way we look at security is as an enabler to do business. So it’s not – Tom mentioned that it’s a necessary add-on afterthought, but we look at it as a way to allow people to do business with us because our only business requires security around it. So we look at things a little bit differently. And that would go for people at mutual fund companies, any financial institution, anything where you’re trying to allow commerce to happen.


 


Pare: Steven, have you seen any trends where some kinds of business are
more apt to be ahead of the others?



Ursillo: Well, I think that as mentioned before, I mean a lot of it depends on the expectation of consumers and really what exactly that particular business and industry is involved in. And naturally in financial industries because there’s so much at risk, and relying so much on third-part consumers to come in and utilize those systems of security is always – let’s put it this way – one of the reasons why we don’t see online banking taking off is because everybody is worried about the security although they’re not familiar with it. So with that being said, you know, a mid-size manufacturing company out there doesn’t necessarily see themselves as at the risk level that a major financial institution would be because they don’t think that they’re a target. If you have a presence on the Internet, if you’re running any type of server that you’re hosting an environment, and you have users that have this access, then you are a target whether you realize it or not. Now you might not be a target where somebody is specifically going for the company, but they may be looking for that particular vulnerability that allows them to use that server to attack the financial institution or to attack a home user to relay against those organizations.


 



Turner: Well, I’ve seen a change actually in the last six years that I’ve been in the industry. The federal government financial institutions were always absolutely invested in security more than any other vertical that we ran into. Now what’s changed and what has brought other verticals almost to a par with that is that while the financial services sector and the federal government very much worry about the theft of proprietary and sensitive information, what we’ve seen in the last two or three years are these nuisance attacks, you know, the worms and viruses. They’re not stealing anything, but we run so much of our business on a computing infrastructure now, that businesses are going down. Airplanes are not taking off. Manufacturing lines aren’t running. And so these are absolutely people who perhaps didn’t feel the need to have security from the standpoint of warning about the theft of their intellectual property or certainly not the measures of the federal government and the financial services sector have had to have. But the fact that their businesses weren’t running effectively, and that they were losing dollars is really what’s changed that paradigm, and this is a sort of new wave and back to the security is the game of changing offense and improving defense.


 


Pare: Tom, I think you said that security is always a very reactive process,
that technology will get a lot done but that at some point you have to connect
people and technology and get them to work together. Maybe you could expand
on that a little bit from the old standpoints. Do most businesses realize that
that technology alone is not going to get it done?



Turner: I think that business is beginning to realize that because we look at how security threats have continued to be very newsworthy, and it’s in spite of the fact that most companies have security technologies. Most companies have anti-virus and have firewalls. And it’s not that those technologies aren’t good. They are adapting as they need to, to the change and the threats that we experience. But so much now because we are this very transitory-user community where the laptop is essentially a server. I mean the laptop you carry around might as well be a database server because it has all this radical information. So now I’m an end user, and I’m involved in the security of my machine. And that wasn’t always the way. And so I think people are having to address this. And the more that executives in a company are building security decisions into any business decision they make, we’re starting to see that. But it’s not easy.


 


Pare: How often should businesses be re-examining their cyber security
practices?



Ursillo: I think that for something like a financial institution, it would obviously be more frequent than what’s determined to be inside the company. But periodic audits and security reviews should be done at least annually. I have clients that choose to do it quarterly. So again it depends really where management steps in and says, ‘Well, we see this as a substantial risk.’ Technology is constantly changing.


 


Pare: I want to give you all a minute to give a final statement. Maybe
you have some advice or some sort of summary for us. Stephen Chow?



Chow: I think one of the major issues for all businesses is just what your internal policies are with respect to employees and how they use the Internet resources that are available, and it’s often a very delicate balance. How much do you tell the employees that they have no expectation of privacy, but you have to balance that against morality. You have to balance that against how likely these policies will be adhered to. There’s so many different kinds of business models that are evolving as we talk today.


 



Mignone: Well, I guess I would reiterate my earlier comment that really security is a partnership. If you want to bank online, I would say that it’s a secure thing to do. If you want to drive on the highway, you insert precautions when you drive on the highway because you know there’s a risk when you do that. I think people need to be aware of the fact that when they’re doing anything on the Internet, it’s inherently insecure. You should be cautious about when you’re getting unsolicited either phone calls or e-mails.


 



Turner: So I’ll just say I was listening to Steve talk about privacy, and I’ve taken a couple of notes that when I get back to the office, I’m going to delete all my e-mails and take the fast lane transponder off my car so my wife doesn’t know where I’ve been. My only point is I think the security shouldn’t be an overlay. It’s absolutely got to be a part of the process of rolling out a new line of business or even blanket technology that enables some form of business. Security has to be embedded, not bolted on.


 



Ursillo: Just to spin off of that comment, it’s equally as important as we talked about bridging the gap between users and the technology – education and awareness. The reason why all of you are here today, and the reason why different managers and directors are getting out to try to expand their horizon because the more information, the more education that you have, the better decisions you can make to secure your enterprise. And that also includes home users. We talked about home users, online banking, having that protection – a lot of the problems with some of the accountability and the privacy is that people don’t want to be recognized when they’re going in certain places. This is continuing to pose a huge impact in the law enforcement community as well because now you can have attackers that are getting on home wireless networks without anybody knowing, perpetrating crimes and not being detected. So there’s a fine line, but the best defense is self-defense at this point and continued education.

No posts to display