The integration of systems that have traditionally run machinery as standalone, closed-in operations with the Internet has created both an opportunity and a challenge. In this second instalment of a two-part article on the impact of the increasing convergence of IT and operating technology on network security, industry experts offer their insights as to how organisations can mitigate the risks. The integration of systems that have traditionally run machinery as standalone, closed-in operations with the Internet has created both an opportunity and a challenge. In this second instalment of a two-part article on the impact of the increasing convergence of IT and operating technology on network security, Tracey Caldwell talks to industry experts about how organisations can mitigate the risks and how we need to establish new levels of collaboration and openness to drive true change.
The separation between IT and operational technology (OT) networks, such as those linking manufacturing control systems, is breaking down. Not long ago, systems that monitor and control physical equipment were engineered and implemented independently from the computers, systems and applications that process, store and exchange operational data. But the line between IT and OT is blurring. In this, the first instalment of a two-part article on the impact of increasing IT and operating technology convergence on network security, industry experts contribute their assessment of the emerging threats. The separation between IT and operational technology (OT) networks, such as those linking manufacturing control systems, is breaking down. Not long ago, systems that monitored and controlled physical equipment were engineered and implemented independently from the computers, systems and applications that process, store and exchange operational data. But the line between IT and OT is blurring. In this first instalment of a two-part article, Tracey Caldwell asks industry experts for their assessment of the emerging threats.
Hacktivism is no longer driven by well-meaning amateurs or bored teenagers, if it ever was. The nature of hacktivism is changing and cause-based activism typified by the Anonymous collective is being replaced by heavy-duty, politicised attacks by the likes of the Syrian Electronic Army and ISIS - or even attacks carried out by nation states. Hacktivism intended for social and political protest can have unintended (or intended!) impacts on organisations of all sizes caught in the cyber crossfire.
As countries around the world seek to tighten up security at borders in the face of threats of terrorism and immigration pressures, biometric technology is playing an increasingly important part.
The risks associated with developing software following agile methods have been a subject for discussion for some time and continue to evolve. And agile development methods are no longer just confined to software development.Tracey Caldwell highlights the risks arising from the agile approach - characterised by incremental, iterative work cadences - and addresses concerns that the customer or product owner focus of agile methods may compromise network security, as these major stakeholders are not generally prioritising security.The security risks associated with developing software following agile methods have been a subject for discussion for some time and continue to evolve. In addition, agile development methods are no longer just confined to software development and may be used to develop any number of web or IT-dependent products and services too that are interdependent with the network security of an enterprise.
The healthcare biometrics sector is poised for rapid development. Major suppliers are working on new biometric applications for launch in 2015, while a convergence between health and fitness biometric applications and those for healthcare-related identification and authentication looks imminent.
Tracey Caldwell, editor, interviews Isabelle Moeller, chief executive at The Biometrics Institute, on topics ranging from the role of The Biometrics Institute on the global stage to the need for more debate within the biometrics industry on privacy and standards.
In your book ‘Identity is the new money’, you say the future of money is linked to the future of identity and that biometric technology might underpin that? How?
2014 was the year that mobile biometrics became mainstream and that the financial sector took biometric technology to its heart.
Tracey Caldwell, editor, interviews Christoph Busch, a leading mover and shaker in the biometrics sector, on topics ranging from fingerprint quality research, to mobile biometrics, from continuous authentication to ear biometrics.
The delayed launch of the UK's national Computer Emergency Response Team (CERT) - popularly known as a digital fire brigade - looks set to happen in 2014. CERT-UK looks likely to take on the role of co-ordinating responses to online attacks on a national level. But even as it is barely in the starting blocks there are already calls for national efforts to cross borders and for CERTs in Europe to co-ordinate responses to cyber-attacks on a larger scale. The delayed launch of the national Computer Emergency Response Team (CERT) - popularly known as a digital fire brigade - in the UK looks set to happen in 2014. But even as CERT-UK has barely got going, there are already calls for CERTs in Europe to co-ordinate responses to cyber-attacks. Tracey Caldwell reports on the issues look likely to affect the effective operation of UK-CERT and its ability to share information with similar bodies around the globe.
It is not a matter of whether organisations will be hacked and their defences breached, but when. Responsible Chief Information Security Officers (CISOs) should assume the perimeter is permeable and security efforts need to trickle right down to protecting individual data on the network. It is not a matter of whether organisations will be hacked and their defences breached, but when. These days, you should assume the perimeter is permeable. This means that security efforts need to trickle right down to protecting individual data on the network. Tracey Caldwell looks at methods for securing data in transit and at rest. And she explores how you can achieve a good balance between network and data security and between the conflicting demands for data security and data sharing.
Identity has become key in a de-perimeterised world. Effective Identity and Access Management (IAM) enables open interaction between a business and employees, consumers or customer and partner organisations. Identity has become key in a de-perimeterised world. Effective identity and access management enables open interaction between a business and employees, consumers or customer and partner organisations. However, many organisations are struggling to get identity management right, reports Tracey Caldwell. Organisations may have recognised the need for identity management, but many are making basic mistakes implementing it. She explores the issues and ways in which they can be addressed.
In the modern, developed world people accept that they need to be able to prove their identity when interacting with the state or with private entities such as banks. Authentication is at the heart of accessing rights and services, including education, employment, financial services, voting and benefit transfers.
Tracey Caldwell interviews Kevin Mangold at the US National Institute of Science and Technology (NIST) about its work on the command and control of biometric capture devices via web services and the benefits of open and interoperable standards based on web services.
Tracey Caldwell, editor, interviews SA Mathieson, author of ‘Card declined – How Britain said no to ID cards, three times over’, about the role biometric technology has played in national identification in the UK.
Virtual Private Networks (VPNs) are essential to most organisations that need to offer flexible and remote working. Increasingly, smaller and medium-sized companies are offering remote access to corporate systems through VPNs as well as the large corporates. But are VPNs up to the job? There is evidence that small and medium enterprises are not up to speed with the risks created by giving workers with laptops VPN access to the company's network across public telecommunications systems.
For years there has been talk of ‘de-perimeterisation’. Now people talk of having multiple perimeters, or of bringing the perimeter further inside the organisation. The use of cloud services and mobile devices for enterprise use is also increasing in all sizes of organisation. Is there any place left in this changing world for the security appliance? For years there's been talk of ‘de-perimeterisation’. Now people talk of having multiple perimeters, or of bringing the perimeter further inside the organisation. Is there any place in this changing world for the security appliance? How does it fit with the new security landscape and new modes of working? Tracey Caldwell looks at where the security appliance fits into today's network security architecture.
Organisations are going to great lengths to protect the data on their networks but many are falling at the final hurdle by failing to delete data properly from end-of-life equipment. Part of the problem appears to be that, on the face of it, it seems easy to delete data securely. But all too often the data proves to be recoverable. Tracey Caldwell explains how a lifecycle approach to managing data can identify data and plan for its proper and efficient destruction. Organisations are going to great lengths to protect data on their networks. But many are falling at the final hurdle by failing to delete data properly from end-of-life equipment. This leaves them vulnerable – not just to the leak of sensitive information, but also potential fines and other legal ramifications.
The rapid consumer adoption of smart devices is driving smartphones and tablets into the enterprise. Yet enterprises are often ill-prepared to secure smart device access to their networks and are having to act fast to enable this. The rapid consumer adoption of smart devices is driving smartphones and tablets into the enterprise. Yet enterprises are often ill-prepared to secure smart device access to their networks and are having to act fast to support the demand from employees to be able to use such devices. Tracey Caldwell looks at the benefits and issues surrounding smart device access to the enterprise network. This article looks at a number of implementations of secure smart-device access to enterprise networks and reports on expert and analyst views on the issues facing network managers.