News: 1614751094

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Eugene Kaspersky says cyber-crooks coined it during COVID and will take a break to spend their loot

(2021/03/03)


Kaspersky Lab CEO Eugene Kaspersky has suggested that the end of the COVID-19 pandemic will bring a slowdown in cyber-crime.

Speaking yesterday at the Kaspersky-sponsored Asia Pacific Online Policy Forum, the CEO said: "If the pandemic goes away, criminals will go away and on vacation.” He added that one reason for the slowdown would be taking time to spend all the money they stole during the pandemic, and that a return to robbery-as-usual can be expected a few months later.

[1]

This theory was swiftly shot down by Australian infosec boffin, Dr. Greg Austin, a professor of Cyber Security, Strategy and Diplomacy at the University of New South Wales.

Austin's counter-argument asserted that as workers return to offices, risky behaviour like falling for phishing emails will follow. He described cyber-criminals as opportunists who will take advantage of changes in group behavior and called for a renewed emphasis on security training and education.

[2]

Reading El Reg while working from home? Here's a pleasant thought: Kaspersky says 1 in 10 of you are naked right now [3]READ MORE

At the onset of the forum, Kaspersky said COVID-19 has seen new entrants to the online crime industry.

“More junior criminals are joining cyberspace,” said Kaspersky, adding “I'm afraid this is the next step in a cyber war, to hack not just the traditional computer systems and smartphones, but also to get into the industrial systems, into infrastructure, including critical infrastructure.”

The Forum also featured government officials from Vietnam, Malaysia and Indonesia, all outlining their national approach to information security.

Vietnam's Vice Minister of Information and Communication, Nguyen Huy Dung, detailed the country’s adoption of a four layer protection strategy that includes in-house security, 24-hour security services provided by an external professional, additional independent security, and a monitoring system. He also stated Vietnam had a public infosec awareness campaign, but said he sees a need for further such education.

Azleyna Ariffin, principal assistant director of Malaysia's National Cyber Security Agency, described the security of Malaysia's cyberspace as a collective effort requiring both regional and international collaborations. She also discussed a national cybersecurity awareness campaign that extends from primary school education to adulthood.

Director of National Critical Information Infrastructure at the National Cyber and Crypto Agency in Indonesia, Achmadi Salmawan, outlined the importance of engaging all players big and small, particularly in geographically and culturally diverse Indonesia where motivations and approaches greatly vary.

While the government officials largely discussed education as awareness campaigns, Dr. Austen presented an argument for a pipeline of capable, educated professionals. He said that university degrees were not enough and organisations therefore need to invest in up-to-date on-the-job training. He specifically suggested simulations and red teaming activities.

[4]

Let the (cyber) games begin. ®

Get our [5]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YD9sSNcMYEAuXv9jLFkBSQAAAFI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YD9sSNcMYEAuXv9jLFkBSQAAAFI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[3] https://www.theregister.com/2020/12/09/kaspersky_guilty_lockdown_pleasures/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YD9sSNcMYEAuXv9jLFkBSQAAAFI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://whitepapers.theregister.com/

Potemkine!

I'm afraid this is the next step in a cyber war, to hack not just the traditional computer systems and smartphones, but also to get into the industrial systems, into infrastructure, including critical infrastructure

I wonder why cybercrooks didn't target industrial systems massively yet. Maybe because the "traditional market" is still lucrative enough?

Cybersecurity in industrial systems is most of the time a joke. I know an example of an industrial device provider asking for an open connection 24h a day to its system without even being able to provide a fixed public IP to filter (a little bit) the input. The same provider did not realize why it was wrong, and moreover didn't care.

There's a bright future for cybercrooks, they have plenty of devices to play with.

Excessively technocentric once again (as always)

Mike 137

" ... organisations therefore need to invest in up-to-date on-the-job training. He specifically suggested simulations and red teaming activities. " [Dr. Greg Austin, professor of Cyber Security, Strategy and Diplomacy, University of New South Wales]

In over 20 years of infosec consulting, I've never found in practice (or in any breach report) an organisation that was breached despite robust security management. A reactive technocentric stance is almost universal, coupled with perfunctory risk and awareness management. The result is unwitting soft targets everywhere. Simulations and red teaming typify such strategies of reactive response. They are necessary but far from sufficient.

The most important contributions to real cyber security are [1] executive commitment so the problem is taken seriously and the necessary resources are available to manage it; [2] genuine risk management expertise so the results of assessments are not total nonsense; [3] adequate communication upwards and sideways as well as downwards in a no blame culture so those in charge find out fast what's really happening. In my experience these attributes are practically never present in any organisation, regardless of size.

As a result we skirmish with bandits in their own territory so we lose. The reality of cyber defence is that it's not primarily a technology issue - it's a management issue with technological aspects.

If the designers of X-window built cars, there would be no fewer than five
steering wheels hidden about the cockpit, none of which followed the same
principles -- but you'd be able to shift gears with your car stereo. Useful
feature, that.
-- From the programming notebooks of a heretic, 1990.