Cyber Security Summit Blog

Following reports of the well-documented Target data breach in 2013, the need to improve the existing security framework to ensure that customer credit card numbers and other personal data are no longer at risk has been brought up by corporations and media alike. Target Corp. responded to their data breach with a change in CIO and CEO, the latter being appointed earlier today. The widespread publicity surrounding the Target breach has brought added attention to the problem, but unfortunately it hasn't prevented other similar breaches from occurring in its wake. The entry point for the afflicted 70 million customers in the Target breach was the point-of-sale ...
Unisys Corporation recently sponsored a survey by the Ponemon Institute of 599 security executives of critical infrastructure providers. The top three functions of the respondents were chief information officer, business operations leader and IT security leader. According to the report, the research was conducted "to learn how utility, oil and gas, alternate energy and manufacturing organizations are addressing cyber security threats. These industries have become a high profile target for security exploits.” The survey found that almost 70 percent of the businesses surveyed had experienced a major security breach within the last year. 64 percent said they were expecting at ...
McAfee Labs recently released its June 2014 Threats Report. The report outlines key topics and threat statistics and is published every quarter. The report dives into four key cyber security topics of the quarter, which include: Almost 80 percent of the 300 Flappy Bird mobile game clones contained malware. Malware botnets that have virtual currency-mining capabilities. Despite previous decline, it is expected that rootkit-based attacks will begin to increase in the near future. Mobile platform protection is not enough to keep mobile apps safe. The report also includes statistics about mobile malware, malware, web threats, messaging threats and network threats. According to the report, “In just ...
At the 2014 Clinton Global Initiative America meeting yesterday, Symantec announced the launch of Symantec Cyber Career Connection, a program focused on closing the cyber security workforce gap by providing students with virtual mentorships, training, and cyber security internships. Symantec says it will assist program graduates in obtaining jobs through the use of its networks. According to a press release from Symantec: “An estimated 300,000 cybersecurity jobs are vacant in the United States; among those, 60,000 could be filled by individuals without a four-year college degree.” Those numbers are expected to increase with time along with the number of cyber security ...
A recent survey shows that many businesses are confident in their ability to detect a data breach, though some experts question whether that confidence is justified. Successful attacks on organizations including Target, eBay and Evernote have demonstrated that even large businesses are not immune to cyber threats. However, the survey, conducted by Atomic Research and sponsored by security solutions provider Tripwire, Inc., showed that many companies have not increased the level of attention given to their security. The survey included 253 organizations in the U.K., all of which process card payments. Of the 253 organizations, 102 were financial and 151 were retail ...
More than 400 teams are already registered for the 2014-2015 season of CyberPatriot, a competition that began in 2009 to motivate students to consider careers in cyber security and other science, technology, engineering, and mathematics disciplines. The current season, known as CyberPatriot VII, boasts participation from 40 states as well as Puerto Rico, Canada, and U.S. Department of Defense Dependent Schools in Germany. Each team consists of a coach and two to six students from the same middle school, high school, or other approved educational organization. The competition is structured as a tournament where the highest scoring teams advance until the top 28 teams are identified. The ...
In remarks delivered earlier today at the American Enterprise Institute in Washington, D.C., FCC Chairman Tom Wheeler outlined his organization's philosophy on cyber security. Stressing the importance of network security, Wheeler noted that today information networks don't just support the economy, they essentially are the economy. "As such, information networks aren’t ancillary; they are integral," he said. "And their security is vital." Wheeler said that given the dynamic nature of the threats we face today, the new security paradigm must be based on private sector innovation and the alignment both public and private interests. “Companies must have the capacity to assure themselves, their ...
Following a year of continued Congressional division, sequestration, a government shutdown and the troubled rollout of Healthcare.gov, IT industry association TechAmerica last week released its annual survey of federal government CIOs. TechAmerica surveys federal government CIOs each year to gauge their ongoing priorities and concerns. In this year's 24th annual report, that group was expanded slightly to include CISOs. The No. 1 priority identified this year was again cyber security/IT security, which sixty-three percent of respondents identified as one of their top three priorities (more than twice as much as any other priority mentioned). In addition, two-thirds of respondents said threats to ...
White House Cybersecurity Coordinator Michael Daniel shared his thoughts on existing cyber security regulations earlier today on the White House blog. In his post, he highlights Executive Order 13636, “Improving Critical Infrastructure Cybersecurity,” which among other things directs Executive Branch departments and agencies that regulate the security of private-sector critical infrastructure to assess whether, based on the Cybersecurity Framework, existing regulatory authority is sufficient to address cyber risks. Reports were produced by the Environmental Protection Agency, Department of Health and Human Services and the Department of Homeland Security. The degree to which they regulate for cyber security ranges from high-level requirements to voluntary guidance; however, ...
Earlier today, we learned details of the latest cyber attack to affect a major online retailer when eBay reported that a database containing encrypted passwords and other non-financial data had been compromised. The company is asking its users — all 128 million of them — to change their passwords as a precautionary measure, joining others who have recently been required to issue large-scale password resets including Yahoo, AOL and Evernote. EBay says extensive network tests have so far found no evidence of any unauthorized activity for users or unauthorized access to financial or credit card information (which is stored separately). As ...