Featured post

Photographer Movie Review

Photographer Tamil Movie Review ஹாய் மக்களே இன்னிக்கு நம்ம photographer படத்தோட review வை தான் பாக்க போறோம். Ashraf Ali ,  Janani Samathanam...

Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Tuesday, 19 October 2021

Expanding and Diversifying the Cybersecurity Talent Pool

 Expanding and Diversifying the Cybersecurity Talent Pool Through Engagement

 

With the advancement of technology, Cybersecurity has become a complex security challenge in the present times. As the dependence on Information and Communications Technology is deepening, cyber threats are penetrating every nook and corner of various businesses targeting individuals, businesses, and governments. Two-thirds of Indian organizations believe they have a proactive capability when it comes to cyber security: the largest percentage of any country. Furthermore, 60% of employees agreed that their organization struggles to recruit people with cybersecurity skills whereas 27% employees believed that the number of external security partners their company use will increase significantly in the next 1 year.

2021 has already proven to be one of the worst ever recorded years for ransomware, with a number of high-profile attacks targeting enterprises and critical infrastructure alike. Many in the industry – and the media – believe that things are destined to continue to get worse until there are extradition laws enacted, cyber norms solidified, better products made available and a slew of other dues ex machine solutions. However, modern cybercrime and advanced persistent threats require a multi-generational approach – not a silver bullet.

In turn, this requires that more people recognize that this is a problem that they can help solve.

The most significant challenge today in cybersecurity workforce development is visibility. Young people choose careers that they see in their communities and that they can see themselves working in.

The Covid-19 pandemic has exacerbated a major talent shortage in the cybersecurity space, according to a report by professional recruitment services firm Michael Page India titled ‘The Humans of Cybersecurity.’ The report suggested that the cybersecurity field is currently experiencing a 43 percent talent shortage with skills such as Application Development Security, Cloud Security Risk Management, Threat Intelligence, Data Privacy and Security being high on priority in the Asia Pacific region. Considering the sudden rise in cybercrime amidst the pandemic, 95 percent of businesses in APAC do not have adequate cybersecurity mechanisms which makes them prone to frequent attacks.  To cater to this problem, here are several potential realistic options to make cybersecurity jobs visible to young people.

Engaging Potential Cyber Talent Directly

If enough cybersecurity practitioners engage directly with their communities, they can help ensure that the school will have a topical and engaging school assembly on careers in cybersecurity. For example, high school students considering their career options might be very interested to learn that there were nearly half a million entry-level cybersecurity jobs open at the end of August 2021 in the United States. On the other hand, taking about India, among the population of approximately 1.34 billion people, the country demanded 1 million cybersecurity professionals by 2020 to meet the demands of its rapidly growing economy as per a NASSCOM report.  

 

The pandemic and working from home has shown us that schools are critical infrastructure. Unfortunately, there is no generally agreed-upon standard of due care for cybersecurity at schools; this became abundantly clear during the substantial volume of ransomware attacks on schools as they prepared to start the 2020/2021 school year. With limited budgets, outdated technologies and ad-hoc incident response capabilities, schools remain a compelling target for criminal threat actors. Community members with a background in cybersecurity can help schools build resiliency by volunteering.

 

Similarly, volunteering at a local organization that serves the needs of middle or high-school students through afterschool programs is one of the best ways to connect with potential cybersecurity talent directly. The intent is the same – to increase visibility so that young people know that cybersecurity careers exist. By giving an interesting presentation on cybersecurity to small groups of students, individual practitioners can help young people learn about the team-oriented nature of cybersecurity jobs. Some afterschool organizations also provide the opportunity to mentor young people and provide career guidance.

 

Choosing to not engage young people about cybersecurity careers is choosing the status quo – a continued year-over-year increase in the number of data breaches annually and a related increase in year-over-year average financial damages caused by said breaches. This unsustainable harm can be stopped by the collective efforts of individual cybersecurity professionals working to make our jobs visible and appealing to potential future colleagues.

 

Friday, 9 July 2021

Indian Foreign Secretary Statement at UNSC on Cybersecurity

                         Indian Foreign Secretary Statement at UNSC on Cybersecurity

 *Some States using Cyberspace skills to execute cross-border terror: India @ UNSC Open Debate*

 *Open Societies particularly vulnerable to cyber-attack and disinformation campaigns*

India recently voiced concern over emerging threats from the realm of cyberspace and said that some countries are using cyberspace to conduct cross-border terrorism. Representing India at the United Nations Security Council’s high-level debate on ‘Maintenance of international peace and security: Cyber security’, Foreign Secretary Harshvardhan Shringla put for forward India’s concern at the growing risks to international peace and security caused by the malicious activity in cyberspace.

Speaking at the debate, which was also attended by several foreign ministers of member states, Foreign Secretary Harshvardhan Shringla without taking any names said, “Some States are leveraging their expertise in cyberspace to achieve their political and security-related objectives and indulge in contemporary forms of cross-border terrorism.”

He pointed out that "terrorists have also used social media for planning and executing their terror attacks and wreaking havoc", adding, "as a victim of terrorism, India has always underlined the need for Member States to address and tackle the implications of terrorist exploitation of the cyber domain more strategically."

Highlighting the fact that democracies and open societies are particularly vulnerable to threats emerging from cyberspace the Foreign Secretary also mentioned the need to maintain integrity and security of Information Communication Technology products, which form the building blocks of cyber space.

Speaking on the need for collective action he said, “we need to adopt a collaborative rules based approach in cyberspace and work towards ensuring its openness, stability and security.”

During his address, he also listed the use of "transformative technology initiatives" like Aadhar and UPI by India to implement the Sustainable Development Goals (SDGs).

Mentioning the use of Co-WIN app, he said, "As part of its COVID vaccination drive, one of the largest such drives in the world, India has developed Co-WIN – a scalable, inclusive and open technological platform" and this "can be customized and scaled up for health interventions across the globe."

 

Wednesday, 10 March 2021

What is 5G and What Does it Mean for

 What is 5G and What Does it Mean for Cybersecurity?

The buzz around 5G is reaching a fevered pitch – barely a day goes by where it isn’t in the news.  We have heard about the data capacity and speed increases, lower latency, and lower power consumption.

The Ericsson Mobility Report 2020 shows how the impact of Covid19 has led to network’s crucial role in society. The report expects the global number of 5G subscriptions to top 2.8 billion by the end of 2025. In India, 5G is expected to represent around 18 percent of mobile subscriptions at the end of 2025.

It also states that in India, the projected value of the 5G-enabled digitalization revenues will be approximately USD 17 billion by 2030. With 5G being a platform for innovation it will enable the development of new services for consumers, enterprises, and industry, including large-scale IoT use cases.

BUT WHAT EXACTLY IS 5G?

When we spoke with Dorothy Stanley, IEEE Member and Chair of the IEEE 802.11 Working Group, she pointed out that confusion stems from the term ‘5G’ being used to refer to several ideas interchangeably: “Is 5G a vision? A set of services and data rates that are a goal to be accomplished, requiring multiple technologies? Or something that’s tied only to cellular carriers and what they can deliver?”

Some experts are most focused on the mixed nature of the technology. Babak Beheshti, IEEE Member and Interim Dean, College of Engineering and Computing Sciences, New York Institute of Technology, for example: “The very design philosophy of 5G is based on network heterogeneity. This means that the network can be a combination of technologies such as Wi-Fi® and LTE.”

Therefore, what 5G means depends on the context of the discussion, but it’s likely to include a combination of technologies.

This heterogeneity makes security more complex. However, there are already some exciting developments in the pipeline for 5G and IoT device security.

“According to T-Mobile US, 4G information being carried across mobile networks was not always encrypted. In 5G, end-to-end encryption is intended to provide much stronger safeguards for data privacy,” Beheshti says.

That will be coupled with a globally unique subscriber permanent identifier (SUPI) for each user. Beheshti: “The SUPI is never broadcast over the air during connection establishment for a mobile device, which can help prevent the hijacking of a mobile’s identity. 3G and 4G networks are inferior in this respect.”

For Stanley, top of mind is “The latest security solution, Wi-Fi CERTIFIED Easy Connect™. You scan the QR code, and that bootstraps a protocol exchange that gets you on the network securely, so your traffic over the wireless link will not be snipped.”

Since IoT devices don’t often have robust user interfaces, using a QR code lets manufacturers create security protocols that can be operated without the use of a keyboard, Stanley says. “The QR code is just a way to encode data. Basically, you’re encoding a public key that then can be used to establish and bootstrap trust. Only the peer device that has the private key can decode that.”

So upcoming security technologies are promising.

WHAT CAN CONSUMERS DO TO MAKE SURE THEIR CURRENT IoT SETUPS ARE SECURE?

For Kayne McGladrey, IEEE Member and Director of Security and Information Technology at Pensar Development, “Consumers should use the ‘guest’ network of their home Wi-Fi routers as a dedicated network for IoT devices, so if one of those devices were compromised, the threat actor can’t easily pivot to more valuable data.”

That’s the case for newer devices, he says. “For older, cheap, IP-based security cameras and digital video recorders (DVRs), the easiest way to secure them is to recycle them responsibly as there often are no security updates available.”

The ability to update devices over their lifetime is essential to security, and should factor into buying decisions, he says.

Han Guangjie, IEEE Senior Member and professor at Hohai University, seconds this point: “Check and update the IoT device firmware. If IoT devices have exploitable vulnerabilities, manufacturers often identify and fix problems before the hacker can access the device’s environment.”