Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

How long do you protect the vulnerable?

by The Gurus
March 17, 2014
in Opinions & Analysis
Share on FacebookShare on Twitter

Attending a breakout session at last week’s CSIT conference, the subject of liability cyber education came up.
 
Hosting the session were Dr Ulf Lindqvist from SRI International and Raj Samani from McAfee. The subject of liability was an interesting one among the dozen-strong roundtable, especially as it touched the case of whether banks should reimburse those users who show a blatant disregard for security.
 
Samani asked that if people don’t care about security, why should banks repay lost savings if this is the third time a user has been phished in a month. “There is no way to prove a user did their due diligence to do a claim, as if they didn’t have the latest version of software, banks can refuse to pay outright,” he said.
 
The conversation between the group asked if we as a society should have to pay for others’ lack of due diligence, particularly if banks will not bail out users forever. If a user is not security savvy, clicks on links indiscriminately and as a result suffers financial loss, the first question to ask the bank is: will they cover the user forever if they show no effort or intent to improve their ways?
 
It is the equivalent of walking down a dark alley and someone steals your wallet, would you take that route again knowing that there is a chance that you will lose money once again and suffer the same personal attack? Online it seems, it is a different game.
 
In a keynote at the conference, Douglas Maughan from the US Department of Homeland Security asked why home users or small businesses feel the need to buy security technologies when they don’t understand the benefit of it.
 
The discussion moved on to one of recording online behaviours, and whether a user would allow their bank to put a form of black box recorder in to cover their losses and ensure that the due diligence was being done elsewhere.
 
Samani said that a black box recorder can show liability to a bank, as it will put a wrapper around user activity and act accordingly from it, as this can prove negligence. “The ability to automatically sense and to detect clicks is too difficult, but it can record the trust element and risk. But if the machine learns, when does this become creepy? Are you happy with analytics if improves your life?”
 
Some eyebrows may be raised at this concept considering the headlines of the last ten months, but if this is a case of a bank trying to prove a level of negligence and to cover itself so it is not forced to use funds to repay negligent users, then this may be a way forward for them. As for the users, well if they keep making the mistakes then perhaps this can be a form of online electronic tag.
 
Samani later asked how much personal data is worth to you, stating that the personal data economy will be worth 1 trillion euro by 2020. He said: “Who cares about cyber security? Why don’t people seem to care? If you lose money the bank pays it back so why take it seriously? Is it fair to pay for others negligence when costs from credit card and overdraft interest goes to pay where people are negligent.” He argued that there needs to be an adoption of technologies in order to be fair on those who take it seriously and not paying for the failure of others.
 
This is an interesting discussion and one that I have not come across in some time in the public awareness debate, and one I am sure that the financial services community will welcome.

ShareTweet
Previous Post

CSIT Conference – Belfast

Next Post

Student Will Shackleton named as fourth UK Cyber Security Challenge winner

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol