Dear Reader, 

June is almost gone but we are still digging out from what we gleaned at RSAC… just in time for the next deluge of press releases and meeting requests for BlackHat in Las Vegas.  So let's take care of that at the start.  We are not going to BlackHat and we don’t cover press releases... for free.

However, we are going to the biggest cybersecurity conference and exhibition in Europe, with more than 15.000 visitors: it-sa365. And we're printing a magazine for the occasion, so if you want to be part of this, either with an article or an ad, contact us.

Until then - enjoy reading our newsletter.

Lou Covey, Joe Basques and Patrick Boch

Dealing with Dinosaurs

"Your scientists were so preoccupied with whether they could, they didn’t stop to think if they should.”

 That quote from Jurassic Park was the focal point of the entire movie franchise spanning multiple decades. It is largely forgotten not only by fans of the movies but by the entire technology industry cranking out products that are arguably more dangerous than they are beneficial.

 The issue of controlling the presumed monsters of deep fakes and disinformation encouraged by the technology is common conversation among pundits and politicians.  Even the people who are creating and marketing it’s supposedly benign uses are sounding alarms. But as governments debate the how, a new tech niche is arising designed to self-regulate the industry through transparency.

 We are calling it, with apologies to Harry Potter, The Defense Against AI Arts. We’ve started interviewing companies offering these defenses but this will be an ongoing, multimedia effort.  We are partnering with the Infosec.live community, the market research company IT-Harvest and the IT-SA show runners to cover this subject through November to produce podcasts, YouTube videos and a November special issue.

 We are in talks with several companies interested in sponsoring this effort but there is still room for more. Contact us for more information.

A Trip to the Dark Side of ChatGPT
Artificial Intelligence might become a weapon in the hands of cyber criminals. We spoke with Sergey Shykevich from CheckPoint to see how concerned the cybersecurity worlds needs to be.
Read more...
Security issues, regulation, reality dull AI hype
In the last year the tech world has seen some spectacular expectation resets on “revolutionary” technology. Social media has gone from a boon to democracy to a hellscape of mediocre…
Read more...
The Double-Edged Sword of AI & Cybersecurity
The benefits of AI in cybersecurity are significant, as it has the power to improve automated security efforts and reduce human error. However, AI can also open the door for…
Read more...

SME Security Options

Most of the industry players focus only on large enterprises but 80 percent of the market are the small-to-medium enterprise. That’s problematic because the smaller companies make up the backbone of the supply chain for multiple industries.  If they aren’t protected, no one is safe, no matter how much they invest it the latest and greatest tools and services.  So when you call us about your latest product announcement (that we won’t cover) be ready to answer that question.

Cloud Security Cheat Sheet: There’s an Acronym for That
The DHS/NCCIC Acronyms List currently includes 609 industry acronyms making it difficult for even experts to read analyst reports without a glossary. But that doesn’t even cover cloud data security,…
Read more...

Is this trip really necessary?

 Quantum computing security is, apparently, still a thing, despite the lack of a credible threat.  We are noticing that many vendors in the quantum computing defense industry (like Quantinnium and Sectigo) are pivoting to offering tools to install quantum encryption that offer defenses.  that trend may have a story in it if we can get some people to admit to it.

Quantum Computing: the next big thing or science fiction?
It seems like quantum computing is the core fusion of the tech industry: it's always only a few years away - but is it? We interviewed Matt Campagna, Chairman of…
Read more...

Persistence will pay off

There are several stories we are still working on, mostly because we haven’t found anyone who wants to talk about it seriously.  We’ve had several interviews that went nowhere, but the reason they go nowhere makes it worth pursuing. The subject include

Zero Trust Noise and Fury— It seems to be more a philosophy than a technology.  And the gate keepers of the term aren’t helping.  The concept of Zero Trust was first stated in 1994 in a doctoral thesis by Stephen Marsh but he doesn’t get much love.  So where does it really start what does it mean?

Board accountability Now that corporate officers and board members will be held responsible it seems we are adding an entirely new level of ignorance to a crucial business practice.  How do we fix that?

The Dark Web —There are darker places than what can be searched in a Tor browser (which was developed by the CIA to track criminal online behavior). We’ll be looking into these areas for the next year.

Ethics and integrity in engineering — This is becoming a big deal. Every popular consumer electronic product and software platform, including social media, has violated the codes of ethics for IEEE and ACM.  It seems to have been left to the cybersecurity industry to correct those lapses. How we bring the disparate tech industries into compliance will be a Herculean task.

Zero Trust in Practice – Adopting and Sustaining it in Your Real-World Environment
Zero trust is a heavily used buzzword. It inspires confidence when it’s used by cyber security and technology experts to imply a completely secure technology environment that protects people, devices…
Read more...
Getting ahead of NIS2: Prepare your organization and avoid the consequences.
The NIS2 directive is designed to establish a ‘common level’ of cyber security across Europe, responding to the growing threats and the increasing number of cyberattacks. Here's how to get…
Read more...
Is your freelancer a nation-state hacker?
The Biden administration warned in May that the freelancer you hired to code may be a North Korean spy. These cyber spies are posing as remote, contract IT workers and…
Read more...

Tomorrow!

Our chief editor is moderating a panel for Traitware, “Proactive vs. Reactive Security - How Can We Do Better?” on Linkedin Live on June 21 at 8 am Pacific time.  Sign up and learn some stuff

Thank You, Big Time

We’ve often said how we prefer not to take revenue from advertising.  We prefer the sponsorship model of public broadcasting and donations.  That, apparently, is resonating in the industry as we start receiving both, including for this issue of the newsletter.  Please click on their banners and give them a look.  They are making the way for independent journalism to thrive.

And that’s it for this issue of the Cyber Protection Magazine newsletter. If you have a comment, question or pitch on any of the above subjects, drop us a line on the website, or a one-minute audio comment on the Crucial Tech podcast. We will get back to you.

facebook  twitter  linkedin  youtube 
Cyber Protection Magazine
https://cyberprotection-magazine.com
Modify your subscription    |    View online