API Security

Criminal using a device to make a deep fake voice call

Telemarketers are hated, but loved by criminals and entrepreneurs

Everyone hates telemarketers. If they can convince one or two suckers out of a thousand call to sign up, it…more...

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
man writing on paper

Insurance for Cybersecurity, IT and Technology Professionals

If you are an independent contractor and/or a small business having an insurance policy is a must and offers you protection and peace of mind. Here are some quick tips on how to get started and safely covered as a Cybersecurity, IT and/or Technology professional.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
Security expert collapsed from exhastion

Breach fatigue or too big to fail?

As we prepare for the annual October holiday season with Cybersecurity Awareness Month there is an important question to ask. Are we as a society at the point of fatigue over every new security breach, or are the companies getting breached just too big to fail?

Security giant Fortinet announced a data breach this week that was remarkable in two ways. One was how small the breach was (less than 500GB) Two was how calm Fortinet seemed to be about. Security gadfly Dr. Chase Cunningham posted a flippant comment about the breach on Linkedin, encouraging his followers to “buy on the breach.” He pointed out that with big public companies, in security or not, generally take a hit on their stock for a day or two after a breach, but the stock rises to new highs as the dust clears. And no one seems to care about the downstream customers whose data might have been stolen.

A 2010 study published in the Journal of Cost Management concluded that a company could be more profitable if it annoyed unhappy customers more than they already were. The success of that strategy increased with the size of the company, according to the study, and when there were fewer competitors for a customer to turn to.

The reasons for the success were simple. If a pissed off customer decided to go a smaller provider, there were always new customers who signed up, simply because they were the biggest. If there were no smaller competitors, the customer never went away. In the process, the offending company rarely has to pay out to make the customer whole. The study pointed our that companies like United Airlines have notoriously bad customer service, but they rarely lose market share because of it.

Kevin Szczepanski, co-chair of Barclay Damon's Data Security, is much more forgiving

Membership Required

You must be a member to access this content.

View Membership Levels

Already a member? Log in here
a man wearing a white and black boxing glove

How Breach and Attack Simulation (BAS) Enhances Robust Cybersecurity Practices

Traditional methods of safeguarding information assets have become insufficient in today’s world of advanced cybercrime strategies. A more proactive approach is needed. This article explains the concept of breach and attack simulation (BAS).

California legislature pases AI laws

Solons scrambling to save AI

State legislatures are scrambling hard to enact regulations of the cybersecurity and AI industries to protect them from themselves. And the leaders of those industries object to the efforts, like drug abusers forced into rehab.

For the past 10 years, the investor world shoveled money into any company that said they are focused on AI, but that support is starting to shake. Many AI startups that have received billions of investment are struggling financially, not the least of which is the elephant in the room, OpenAI. The most successful AI company in the world is on pace to lose $5 billion this year and, according to CEO Sam Altman, the company needs more than $8 billion more investment this year or will face bankruptcy inside 12 months.

Part of the loss of confidence in AI are the number of failures that seem to be increasing. The AI Incident Database, which chronicles incidents dating back to 1983, now contains 629 incidents. An even bigger reason is the self-governing rules the industry says it has adopted either don’t work or are ignored altogether.

The industry has generally acknowledged its weaknesses. More than a year ago, Altman sat before the US Senate essentially begging for the government to regulate the industry. Support for that legislation has waned, however, as 15 U.S. state legislatures are considering dozens of bills to regulate the development and use of artificial intelligence.

In a letter from OpenAI Chief Strategy Officer Jason Kwon to California Senator Scott Wiener (author of SB 1047), the company highlighted several reasons it opposed the bill, including the recommendation that regulation should be, "shaped and implemented at the federal level. A federally-driven set of AI policies, rather than a patchwork of state laws, will foster innovation and position the US to lead the development of global standards."

The “patchwork” argument has been used to oppose proposed laws in nine states. The problem with that is most federal laws come after a critical mass of laws at the state level. Historically, when two thirds of the sites pass similar laws, the US Congress considers standardizing them nationally. The US is less than halfway through that process.

The legislators authoring these bills seem to understand that they are not “experts” in technology and have been working with tech companies to make the bills more palatable. In California’s SB 1047, Weiner, removed provisions for criminal prosecution and an entirely new state bureaucracy to enforce the bill before it went to the governor’s desk last week. Instead, the bill merely directs the state attorney general to file civil charges when companies violate the mandates.

Premium Membership Required

You must be a Premium member to access this content.

Join Now

Already a member? Log in here

Deepfake DNA & the need for new AI detection tools for rescuing our legal system.

Deepfake can affect our society including misinformation, fake news, political destabilisation, cyber-espionage, copyright and more, disturbing scenarios.
There is a need to detect what is real to prevent/reduce the impact of these threats.

Membership Required

You must be a member to access this content.

View Membership Levels

Already a member? Log in here
grey concrete building

Addressing Financial Organizations’ Digital Demands while Avoiding Cyber Threats

Keeping up with requirements has caused financial organizations to rapidly overhaul their IT infrastructure. Because of this rapid digitalization, organizations are consuming many different security solutions creating a bespoke environment that inadvertently exposes them to cyber threats. 

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here

The Evolution of Ransomware: From Simple Scams to Advanced Cybercrime Strategies

Ransomware vulnerability is typically exacerbated by immature security programs, leaving organizations susceptible to a variety of infiltration tactics. Additionally, a lack of security culture within companies increases susceptibility to ransomware attacks.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
white printer paper on brown wooden table

The Crucial Role of Regulatory Frameworks in Ensuring Robust Cyber Security

In order to understand the ever-changing regulatory landscape, we spoke to eight cybersecurity experts about the latest developments and how businesses should navigate their way through.

Enhancing Security Operations Efficiency

Today businesses face increasingly sophisticated cyber threats that necessitate robust security measures. One such innovative approach gaining traction is the Security Operations Center as a Service (SOCaaS). This model offers organizations the opportunity to enhance their security operations efficiently and effectively by leveraging external expertise and advanced technologies.

Voters mareking ballots at voting station

Election security is not a technology problem. It is how naive we are

When it comes to election security, the technology we use to vote and count those votes is not the problem. The problem is how naive we are.

Election security has been at the forefront of daily news cycles for more a decade. The concerns about illicit use of technology to input and count the votes turned out to be largely overblown. Every U.S. state other than the Commonwealth of Louisiana, uses paper ballots, matching the practice of every other western democracy. Lawsuits have bankrupted people and organizations claiming the technology was changing votes. Those that have complained the loudest about election interference are now facing prosecution for the crimes.

Now the tech focus is on the use of artificial Intelligence to create deepfake video and audio. A recent pitch from Surfshark,

Membership Required

You must be a member to access this content.

View Membership Levels

Already a member? Log in here

Why every modern enterprise needs a CISO

Richard Starnes, CISO at Six Degrees, discusses the increasingly pivotal role of today’s CISOs and why, in the face of growing danger from an ever-expanding variety of cyber-attacks, every modern enterprise needs one in place.

Membership Required

You must be a member to access this content.

View Membership Levels

Already a member? Log in here
black Android smartphone

The future of online document signing

In an increasingly tech-savvy world, businesses are redefining the very core of transactions – the signature. With the rise of remote work and global digital transactions, the need for secure and efficient document processing has elevated electronic signatures into a near business-critical fundamental.

Free Membership Required

You must be a Free member to access this content.

Join Now

Already a member? Log in here
a screenshot of a phone

Reinforcing Multi Factor Authentication

As the password slowly abdicates to a new heir, which specific alternatives are shaping up to take its place? Multi-factor authentication (MFA) has been rapidly adopted by organizations to help reduce the opportunities for breaches. But MFA brings its own considerations that must be addressed.

Poster for US Army Recruitment

Talent Acquisition in the Age of Skills Shortage

The IT skills shortage has become one of the biggest challenges for companies in recent years. Despite difficult economic conditions,…more...

Membership Required

You must be a member to access this content.

View Membership Levels

Already a member? Log in here

Securing the building blocks of an interconnected world

APIs are often overlooked when it comes to securing a company's landscape. We sat down with Andy Grolnick, CEO at Graylog,to discuss the rapidly growing market of API security.

Membership Required

You must be a member to access this content.

View Membership Levels

Already a member? Log in here
RSA Conference 2024 banner

RSAC Reporter’s Notebook: Change is coming

The cybersecurity industry is just absolute chaos, and rightly so.  This is the industry charged with plugging dikes during the Class-5 hurricane that the internet seems to be today.  Nowhere is that chaos more evident than at RSAC just from a marketing perspective. Everyone has “ground-breaking”, “industry-leading”, and “first ever” product offerings and this year was no different.  But if you can look past the Macho-man impersonations, Formula One cars, and the mesmerizing miasma of the website and show floor, you can see an order forming in the chaos. Change is coming.

Back to step one

RSA CEO Rohit Ghai, said we have missed a step in AI development.  “We’ve seen it first as a co-pilot alongside of a human pilot and then see it taking over flying the plane.”  He said the first step is making it an advanced cockpit making it easier for less trained and experienced people to do the work.  He pointed out that cybersecurity is an industry with negative employment making it difficult to find experienced technicians to do the work.

Last year, any discussion of ethical development was met with confused stares. This year, the need for ethical AI development is taken seriously but few can see a profit in it. Cybersecurity VC Rob Ackerman (DataTribe) and Carmen Marsh, CEO of the United Cybersecurity Alliance, were open to suggestions,

“From the perspective of (companies like OpenAI), I understand the reasons to go as fast as they can to develop a true artificial intelligence, the question is, who are the people in the room guiding the process?” said Ackerman. “Once you get a diverse set of advisors working on the problem, then you do the best you can to create something ethical.  But right now, we aren’t even doing the best we can.”

Membership Required

You must be a member to access this content.

View Membership Levels

Already a member? Log in here

How Do You Insure an Unpredictable Risk?

From our Cyber Insurance Issue: In today’s interconnected digital world, there is no such thing as an “unconnected” business.   That means for most that the extent of their online exposure will include running a calculated risk of becoming the victim of a cyber-attack because that event risk can never be zero. Or does i

Membership Required

You must be a member to access this content.

View Membership Levels

Already a member? Log in here
50s style ladies chasing a robber down the street

A lesson on election security from tea ladies

Our current election season faces the same problems as in 2016 and 2020. Foreign adversaries are interfering with the election process. This time we know it’s happening we know where it’s coming from and we have ways of dealing with it. The question is, is it enough?

Membership Required

You must be a member to access this content.

View Membership Levels

Already a member? Log in here
Close-Up Shot of Keyboard Buttons

World Backup Day: 3-2-1, ready?

It’s World Backup Day. The technology landscape has changed, with (generative) AI all over the place and more cloud offerings on the market. What does that mean for Backups and how do companies ensure they have a solid backup strategy? We put together some commentaries on the subject…