Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Friday, 31 March, 2023
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

The new age of cybersecurity

by The Gurus
November 15, 2016
in This Week's Gurus
Share on FacebookShare on Twitter

The very successful digitisation trend over the past 20 years has produced huge efficiencies in every type of corporation and government. But the dark side is that the security industry has largely failed to evolve the standard security architecture to keep pace with these broader changes in IT.
 
The firewalled perimeter remains the primary defence in IT security. Yet every major data breach in the pandemic of breaches taking place around the world shows how simply firewalls can be bypassed. If a government worker clicks on the wrong email and falls prey to a phishing attack, a hacker can leapfrog the firewall and browse at will through the government agency’s digitised records and applications.
 
The explosion of IT systems, networks, users, Clouds and devices has caused the size of the typical enterprise’s attack surface to expand exponentially. Any user or device can be the weakest link and become the steppingstone to a major data breach.
 
Billions of dollars in venture capital over the past five years has been poured into start-ups trying to improve IT security. Yet industry statistics show that today the typical data breach still goes undetected for months. That’s an eternity for malware and Advanced Persistent Threats to be loose in your systems. And most of the largest vendors continue to make a lot of money selling the same old security architecture, doing nothing to truly fix the problem.
There are new security techniques that are proving to be effective and that do not require the enterprise or agency to cut off Internet connectivity.  One such strategy is called the “Zero Trust” or “No Trust” model.
The old security architecture is built with the idea that you can use a firewall to keep unauthorised people out of the enterprise systems. This internal network is considered to be “trusted” and users who are authenticated and given access are likewise assumed to be “trusted.” This trust model is obsolete as every major data breach since the Target hack has shown.
Instead, enterprises are starting to adopt a “No Trust” model that assumes no network, user, device or application can ever be fully trusted. Instead, you assume that the network is already compromised, that a user actually is a hacker with stolen credentials, or that a device contains malware. With that assumption, how do you design the IT security architecture to minimise the damage?
IT security architects are deploying more sophisticated internal controls, segmenting and isolating applications by enforcing stronger rules on who should access them, even when the user is inside the network. Role-based access control is one such technique, inspecting the internal network traffic at various points and blocking attempts to access applications by users who don’t meet certain rules. Another technique is to use strong encryption to isolate internal applications so that if a hacker compromises a network device, the hacker cannot access the application traffic flowing through it.
But in addition to these better internal controls, the security industry as a whole must focus on making security easier to deploy and easier to manage. The typical security architecture is fragmented and splintered across IT silos, with different tools, different access policies, and different controls in the LAN, WAN, Internet, mobile network, Cloud, data centre and elsewhere. This means setting up and managing consistent, uniform security policies across all of these silos is extremely hard.
Until the security industry makes it easier for organisations to deploy a simpler, more consistent security architecture, the gaps left by fragmentation are going to remain the gateway for hackers to exploit. It is only by changing the way the security architecture is viewed that positive advances in the industry will really be seen.

FacebookTweetLinkedIn
ShareTweetShare
Previous Post

Artificial Intelligence may hold the key to sustaining the data centre industry

Next Post

Teenager Pleads Guilty to TalkTalk Hack Offences

Recent News

cybersecurity training

Only 10% of workers remember all their cyber security training

March 30, 2023
Pie Chart, Purple

New API Report Shows 400% Increase in Attackers

March 29, 2023
Cato Networks delivers first CASB for instant visibility and control of cloud application data risk

Cato Networks Recognised as Leader in Single-Vendor SASE Quadrant Analysis

March 29, 2023
Outside of cinema with advertising

Back and Bigger Than Ever! The Inside Man Season 5 Takes a Stab at Power Hungry Adversaries

March 29, 2023

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Events
    • Most Inspiring Women in Cyber 2022
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2019 IT Security Guru - Website Managed by Calm Logic

This site uses functional cookies and external scripts to improve your experience.

Privacy settings

Privacy Settings / PENDING

This site uses functional cookies and external scripts to improve your experience. Which cookies and scripts are used and how they impact your visit is specified on the left. You may change your settings at any time. Your choices will not impact your visit.

NOTE: These settings will only apply to the browser and device you are currently using.

GDPR Compliance

Powered by Cookie Information