Money can buy you insurance against network break-ins but investing in infosec hygiene wouldn't go amiss, says new NCSC chief
- Reference: 1617103087
- News link: https://www.theregister.co.uk/2021/03/30/ncsc_ceo_infosec_better_than_insurance/
- Source link:
Lindy Cameron took over from founding CEO Ciaran Martin last summer and on Friday made her first public appearance since taking office. She used the speech to emphasise that infosec "is a team sport" that the UK plays "really well, both at home and beyond."
[1]
Addressing recent fears over those types of attacks on online systems and networks that are never out of the news for long the days, Cameron said: "Insurance can really help to cover costs, but it cannot be a substitute for better basic cybersecurity, making ransomware attacks as hard as possible."
Marking the importance that the government security establishment places on the event, former MI6 chief John Scarlett and ex-GCHQ boss [2]Iain Lobban were both watching the online stream of the speech.
[3]
Cameron's line here made an interesting contrast to the NCSC's position in August last year, when it said that paying off ransomware crooks through the medium of insurance [4]could be considered OK in some cases .
Cyberlaw wonks squint at NotPetya insurance smackdown: Should 'war exclusion' clauses apply to network hacks? [5]READ MORE
"Cybersecurity is still not taken as seriously as it should be, and is simply not embedded into the UK's boardroom thinking," she continued, lamenting how many British companies see proper infosec hygiene as an optional bolt-on or something for the insurance company to sort out after the disaster, believing everything will be all right on the night.
As the [6]experience of various schools and colleges has shown over the past few weeks, that belief can be actively harmful.
The new NCSC chief was also quite blunt about continuing the GCHQ offshoot's "interventionist approach" to security standards and also the wider market.
She said in response to The Register 's questions: "I think it is an area where we need to help the market think about how to factor security in; whether, for example, there is a market for more secure products or volume – would you pay more to get a safer product of a certain kind – and actually, therefore, is that something that private sector organisations will be interested in supplying?"
That kind of interventionism is [7]now central to how government intends to approach the UK infosec industry over the next few years , taking a much firmer stance on growing the industry itself as well as talking to makers of Internet-of-Things tat and making them pull their socks up.
[8]
It's also a stance being echoed by US attitudes towards the wider tech industry. Last week it was [9]reported that US president Joe Biden's administration plans to force software vendors supplying the government into a mandatory vulnerability disclosure policy. ®
Get our [10]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YGNLHnA5beb7JToMgw57FgAAANU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2014/04/15/brit_spymasters_gchq_get_shiny_new_spook_boss/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YGNLHnA5beb7JToMgw57FgAAANU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2020/08/06/ncsc_cyber_insurance_guidance/
[5] https://www.theregister.com/2019/07/26/do_insurance_war_exclusion_clauses_apply_to_cyberattacks/
[6] https://www.theregister.com/2021/03/23/ransomware_targeting_education_ncsc_warning/
[7] https://www.theregister.com/2021/03/25/defence_industrial_strategy_infosec_industry_lures/
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YGNLHnA5beb7JToMgw57FgAAANU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.reuters.com/article/idUSL1N2LN3E
[10] https://whitepapers.theregister.com/
Re: Simply not embedded into the UK's boardroom thinking
It needs standards and regulations. The things we have governments for, allegedly.
And enforcement - often governments think the first two is enough.
It was illegal to build towerblocks that burn down. It seems more difficult to force builders to care.
Wow! Ground breaking expert guidance!
" ... cyber-attack insurance "cannot be a substitute for better basic cybersecurity," the National Cyber Security Centre's chief exec has said "
Anyone who thinks insurance can substitute for security should take the locks off their external doors - and then see what the insurer says about it. And it's no different in the "cybersphere". Any policy worth its premium will come with conditions of cover that include maintaining an adequate security stance. Otherwise it won't pay out. Any policy that doesn't include such conditions ain't worth a dime as it probably won't pay out.
Only once the "experts" get beyond spouting truisms will the appalling vulnerability of most organisations be capable of improvement.
Hearing about insurance companies paying ransomware attacks, or worse, universities paying ransomware not because they dont have a backup plan, but because they believed by paying, the bad actors would destroy the data they had already copied, is nothing short of unbelievable naivety.
Apart from ‘care free’ lusers who will click anything no matter how obvious the ruse, software houses need to stop with the constant ‘brainfart’ patching and take a break from the constant ‘new features’ and take a hard look at the crap that’s already been created, and ask themselves, does it work, is it secure
I swear, none of them do that last bit, hence why we get so many damn patches
Won't work
> "Insurance can really help to cover costs, but [...]"
What else is there to cover?... Wake up and smell the shareholder meeting! The goal of management is to minimize cost and maximize profit, so insurance is "good", while spending money on something as vague (and potentially unneeded!) as "security" is definitely wasting money, and you don't do that if you value your career and bonus.
The whole thing is a bet, reinforced by the knowledge that if you win, the gains are yours to pocket, and if you lose, the loss is somebody else's...
Re: Won't work
"What else is there to cover?"
Loss of reputation.
After you've had your customers' personal data cast abroad over the interwebs you'll have seen the last of a good number of them. You may think you're sorting things out for them by letting Experian slurp more of their data for 6 months but it's unlikely they'll think that solves the problem and it's what they think that matters in the long run.
I don't think the C-Suite are ignoring it but many companies and organisations have been around for a long time and their networks have grown like slime moulds over decades. If these were brand new networks then securing them would be far easier. It's like trying to find a way to make a horse and cart carry a shipping container.
The board probably do see the problem but it seems nearly impossible to fix in a financially viable way, plus they've spent many of the last 5yr decimating their IT departments so they have no resources or skills to do the work even if they wanted to. This is something I've always found hard to understand, C-Suite falling over themselves to proclaim a new digital future yet forgetting who actually has to do the work on anything that is digital.
"yet forgetting who actually has to do the work on anything that is digital."
It's the cloud that does it innit?
Even working at a relatively new company is no better, we have good people here and are trying hard but shiny features trump security every time. So the tech debt pile is growing.
Simply not embedded into the UK's boardroom thinking
It's simply not embedded into products. Especially embedded products.
If you can't interest builders in using less flammable building materials than those that literally cost lives, you're not going to convince a few suits to spend money protecting binary digits.
It needs standards and regulations. The things we have governments for, allegedly.