About
Subscribe

Profile the enemy

Cyber security is shifting from reactive to proactive, and it all starts with knowing your threats and threat actors.

Johannesburg, 13 Nov 2017
Caesar Tonkin, Divisional Head, Cyber Security, StorTech.
Caesar Tonkin, Divisional Head, Cyber Security, StorTech.

As more businesses move into the digital space, never before has security been more important. It's a cyberwar, where organisations need to be prepared for an attack from anywhere in the world, especially as South African businesses move to the cloud.

Businesses have little choice but to turn to technology to minimise the threat posed to their critical business systems and to their users, says Caesar Tonkin, head of StorTech's Cyber Security.

Tonkin says: "Businesses need to have several layers of security, starting with outer perimeter security and have further layers as you get closer to the data, the person or the system that you want to protect."

That's standard practice when it comes to security. This is known as defence in depth, where you have a firewall, anti-virus and various security controls and security policies in place. However, says Tonkin, these fit for purpose measures aren't enough to assure businesses that nobody can steal their data or hack into their e-mail to see which deals are being struck with whom, for example. They're no longer sufficient to defend against threats such as phishing, ransomware or other cyber attacks.

"Today's cyber attacks, which even include attacks on businesses by their competitors, have reached a level where businesses are seeing cyber attacks as board level agenda items," says Tonkin. "We're seeing panic amongst security peers and customers, who are saying it's a matter of not if, but when they'll be attacked.

"Businesses are seeing their closest competitors being attacked and are concerned about being able to put together sufficient mitigating security controls in time to avoid suffering the same fate. Adding to their worry is the pending General Data Protection Regulation, which comes into effect next March, and the Cybercrime Bill, which is probably going to be passed within the year. Organisations in the financial and telecommunications space are already asking for our advice on how to be compliant."

Tonkin says that businesses need to change how they respond to cyber attacks, which could require an investment in people and security technology. He adds: "Cyber security is no longer exclusively the domain of IT staff. These types of decisions need to be made at board level. The C-suite must commit to a robust cyber security strategy including how they'll respond to a cyber attack. The business needs to know how quickly it can resume normal operations should it be subject to a cyber attack. Cyber resilience must be guaranteed. This means that we're engaging more of our customers, on an executive level - and not merely on security technology and incident response handling processes. Although we're having technology and investment discussions with CISOs and CIOs - the underlying theme in our discussions is on cyber resilience and business continuity."

Tonkin explains there's a difference between disaster recovery and business continuity. "This is a whole new approach. If your business is hit by a massive cyber attack, how quickly can you get back in business? How do you do that? This is a whole new strategy."

However, first prize is to prevent an attack from happening before it strikes, and that is where technology really comes into its own, says Tonkin. Big data and analytics come together to generate cyber security intelligence that proactively looks for cyber threats. "This proactive approach alerts the business to who is tracking it on social media, who might be trying to attack their system and networks, or who is carrying out social engineering on senior employees and system administrators. This type of proactive threat hunting is done in addition to all of the usual security measures, and combines all previous well known cyber security research.

"We identify trends on social media, see events happening on the network or applications that are suspicious, and combine that with additional cyber research that we undertake. This includes setting traps (e.g. honeypots) and seeing who responds. We recognise that typically as attackers become more ingenious, organisations are forced to constantly improve their security initiatives. Even organisations with strong cybersecurity programs find it hard to determine and defend against a cyberattack. Our team assists organisations to proactively hunt for adversaries, determine if the organisation is being attacked and provide insight into the attack methodologies used by the adversary. We will identify the advanced threats and shut it down, and advise on the security controls to further strengthen their cyber defences.

"If you consider the increase in distributed denial of service attacks that are in excess of 350 gigabytes over the past year alone, the market is certainly going to be focused on this kind of proactive cyber threat intelligence capability going forward," concludes Tonkin.

Share