|
Dear Reader,
Welcome to our second newsletter of 2025 and we are already getting won pushback on our new theme (Put up or shut up) and our new tagline, (Cybersecurity explained… with an attitude). Some of our interviews have been contentious but most have been resolved amicably if not agreeably. Expect more of the same.
Why antagonize? Well, for one, companies like the concept of “earned media.” Which generally means they expect us to parrot back whatever is sent to us. We’ve decided that if they are getting our services for free (not sponsoring) then they need to EARN the coverage with honesty, not BS and buzzwords. Most of the work we do is uncompensated. We have a wonderful primary sponsor in Safety National Insurance who leaves us alone to determine our editorial direction… even when we offer them some prime coverage. This year, however, they have agreed to be more involved and will do several podcasts, the first of which premiered in February. Their head of cyber and technology, Spenser Timmel, is a font of insight and wisdom regarding how the insurance industry is protecting us from ourselves so we are going to take advantage of that.
Our first special issue contained our second annual predictions collection from ourselves and some leading experts. We work very hard to vet all predictions and then, at the end of the year, show just how far off , or how spot on they were. We suggest you get a first-level subscription (it costs your name and email and check it out. And our next issue will target cyberinsurance. That’s scheduled to come our late March or early April.
There are several subjects we will be returning to often during the year. You'll find a list, along with a few sample articles, in this newsletter.
Of course, all this is flexible, so what else ya got? Let us know at [email protected]
Enjoy Reading
Lou, Joe and Patrick |
| |
|
Statistics and Truth: This will be an ongoing effort. We did a podcast with the curmudgeon James Bore — We hear how bad the situation is in security. Lots of jobs going unfilled. Cyber attacks on the increase. The cost of cybercrime approaching $25 trillion dollars. But is it that bad? |
| |
|
Security industry addicted to bland marketing |
|
There is no question that the cybersecurity industry performs a vital role in keeping the digital world safe. It’s too bad the industry is so dedicated to bland, repetitive and… |
|
|
| |
|
How you gonna power that? Digital technology is not the largest consumer of electrical power in the world… yet. But the world’s reliance on it for communication, supply chain maintenance, and security makes the availability of power on a constant basis a significant concern. Right now, the internet consumes 1-2 percent of all the power generated, most of it to power data centers. But by 2030 that is expected to double as Quantum computing systems and AI processing centers come online, competing with heavy manufacturing for available sources. Where will we get the power from? And how will we protect the crumbling infrastructure that transports it. |
| |
|
The quantum computing chimera |
|
Quantum computing could potentially break current encryption methods, leading to a surge in research into quantum-safe cryptography, but will they in our lifetimes? Or is the current concern about quantum… |
|
|
| |
|
In our last newsletter we listed several subject we hope we would get to. Made a pretty good dent in them but misused a few. But as the RSA Conference is coming up we are going to revisit them and see what the industry responds to. So here’s your cue, PR folks who want to talk with our Chief Editor Lou Covey before, at, or after the conference. Here are some of the stories we will be working on.
AI-Driven Cyber Attacks — As artificial intelligence advances, cybercriminals are expected to use it to craft highly sophisticated phishing scams, automate attacks, and develop malware that can rapidly evolve. Defenders will need AI-powered tools to detect and mitigate these threats in real time. Which way will the scales tip this year? |
| |
|
The Dark Side of GenAI – Why 96% of Executives are Concerned |
|
Generative artificial intelligence (GenAI) represents the latest technological shift, with significant implications for cybersecurity. However, 96% of executives believe that integrating GenAI increases the risk of a security breach within… |
|
|
| |
|
Zero Trust Expansion — Zero Trust security models are no longer a trend but an industry standard. But it has become so “buzzified” does it even have any meaning?
Supply Chain Vulnerabilities — Supply chain defense has been a major issue in industry with increasing complexity, targeting third-party vendors and cloud providers to compromise large organizations. Will governments finally deploy stricter regulations to secure critical infrastructures, or will cost-cutting open the floodgates of attack?. |
| |
|
Why Zero Trust Should Be at the Heart of Every Organization’s Security Strategy |
|
The Zero Trust approach treats every user and every access request in the system as a potential threat and approaches them with suspicion. This approach may seem difficult and complicated… |
|
|
| |
|
Ransomware-as-a-Service (RaaS) Evolution — Will ransomware-as-a-Service become even more sophisticated, enabling less-skilled cybercriminals to carry out complex attacks? Law enforcement made significant headway in shutting down the groups last year but will populist governments follow up with stricter laws around paying ransoms? Will organizations refocus on prevention rather than post-attack mitigation strategies? |
| |
|
How to build ransomware if you can’t code |
|
These days, having GenAI in your back pocket to speed up and sense-check your development process is a real benefit. In the wrong hands, however, it can also ramp up… |
|
|
| |
|
Cybersecurity for Smart Cities — As cities adopt smart infrastructure, cybersecurity will become critical to protecting transportation, utilities, and municipal systems. The interconnectivity of these systems makes them highly vulnerable to large-scale cyberattacks. Will municipalities invest enough in cybersecurity measures to protect citizens and services?
Insider Threats — Insider threats are still a significant problem, driven by remote work, employee dissatisfaction, and increasingly complex organizational structures. Businesses need advanced monitoring and behavioral analysis tools to detect unusual activity from within. Employee training and awareness programs will become even more critical. But with investment in cyber slowing this past year, will it be enough? |
| |
|
Privilege abuse threatens IoT networks lacking integrated and automated access management |
|
With the Internet of Things (IoT) expected to reach 55.7 billion devices next year, the scale and complexity of cyber threats have grown at an alarming rate. Many of these environments rely… |
|
|
| |
|
Biometric Security - As passwords become increasingly inadequate for securing systems, biometric authentication grows in popularity. However, will biometric data itself become a target for hackers, leading to the need for stronger protections around how this sensitive information is stored and used? What are the challenges in balancing security with privacy concerns.? |
| |
|
Biometrics and payment cards? |
|
Biometric multi-factor authentication is all the rage in security. And yet it is also the cause of terror for security-minded folk. For every breakthrough we get a news story about… |
|
|
| |
|
And that’s it for this issue of the Cyber Protection Magazine newsletter. If you have a comment, question or pitch on any of the above subjects, drop us a line on the website, or a one-minute audio comment on the Crucial Tech podcast. We will get back to you. |
| |
Cyber Protection Magazine
https://cyberprotection-magazine.com
| |
|