Hi, I'm Tracy, getting my information security media group. I'm joined today by Brian Engel, who heads up the Retail Cyber Intelligence Sharing Center in the U.S. Brian, tell us a little bit about the R6. It's a hard time pronouncing that.
And it is a U.S. organization, but there are plans to work more globally. Yes, we're based in the U.S. from an operations perspective.
We have members that are participating, that are multinational, with operations across the globe, but it's a threat that we're seeing. It's definitely not divided by boundaries of borders or even oceans. So we definitely see that the operations of U.S. based entities are affected by the same threats that are operating overseas.
Yeah, that's a good point that you and I were talking earlier about the fact that retail organizations here in the U.K. often have ties to the U.S. and the same types of attacks that we're seeing, or has seen in the U.S. for quite some time, have actually been taking place here for that amount of time as well.
Yeah, I mean, absolutely. We're not seeing certain threats go away on a basis, and they just continue to have prolonged life and the fact that they're not going in waves across different geographies or continents. They're pretty consistently attacking at all corners of the globe. So let's talk a little bit about the formation of the Retail Cyber Intelligence Sharing Center.
So you're working closely with the Financial Services Information Sharing Analysis Center in the U.S. Are you also doing work with the FSISAC based here in the U.K.? Our work with them is, again, sort of centered around the type of information, the type of threats that we're seeing, and the consistency of best practices that are successful in supporting those threats. So as far as their expansion across the globe, I think that what we can see in our relationship and partnership with them doesn't necessarily get limited by the fact that we are operating in the U.S.
and their primary operations are in the U.S. We're also working with other information sharing analysis centers and other sharing organizations here. As a member of the National Council of ISACS, we are definitely seeing a lot of the same types of threats across healthcare, aviation. And to a degree, the automotive industry is going to have a different set of threats, but we'll probably see a lot of commonalities as that sharing organization starts out as well.
So in the Financial Services space, sharing has been going on for quite some time, but it's only been in the last four years that it's really become more of an automated and formulated process. In the retail space, it's a little bit newer. I'm just going to remember here, but in a way that the target resource itself is pushed to get retailers involved in information sharing. How has information sharing on the retail side evolved in the last 12 to 18 months?
Well, so first, going from something that in the 2014 timeframe, didn't have any degree of formality to it outside of relationships with individuals to the place that we are today, where it's a much more programmatic exchange of information. Not all automated, but at the same time systemic. It's things that are being ingrained in processes. It's analysts being purposed towards the sharing of information that's helpful into the industry itself, but the individual organizations.
So what we've seen in the past year and a half, essentially, is many organizations learning how that their sharing can be increased at the same time as how to utilize the information that they're receiving. And as the facilitator, the exchange of that information, and we know we are just being able to add a degree of analysis inside cultivation and curation to the information being shared, helping to draw a prioritization around the information that is coming forth from individual organizations. And as we spoke about today in the session, trying to see the trends and the types of things that are not based on attacks, solely against individual organizations, but things that are happening in multiple organizations at the same time. Right, because it's not just one type of attack that's attacking retail and another type of attack that's attacking financial or even healthcare.
They're the same types of attacks across the board. Yeah, I mean, we're definitely seeing an organized element of criminal behavior that is able to leverage common infrastructure and tools and tools that's being used by organizations and the common vulnerabilities that exist in those, and the common ability to exploit those being aggregated into an organizational delivery that's occurring and able to escalate the number of organizations that can be attacked concurrently and somewhat arbitrarily by industry type, much of it driven by financial instruments, but information in general being exfiltrated from organizations, whether it's healthcare, retail, financial services, and that's just happening with an organization and a capability that is really staggering in some sense. So you're the executive director of the R6 and the U.S. and of course, as you mentioned, you're working to help expand more globally.
What types of hurdles have you had to jump to get retailers on more of a shared more information? Well, so everyone has a lack of resources. No one will claim to have enough people on task for everything that they need to do in a cybersecurity program. So when the consideration is around sharing, most are looking at it as how to push information out rather than necessarily the amount of information that you can receive in and how that can help to spot light on the right things and the right focus that you would have to react and respond to.
So the biggest thing is kind of getting folks to understand that this is an enabler and something that can somewhat by time back rather than just be time spent. When someone looks at a cybersecurity program and says, look, we don't have enough people to really do all of the things that we would need to do. We're working off of a risk-based approach as it is. We're focusing on priorities.
Sharing information isn't a priority for us. You've got to look at it in a sense of a receipt and a send. And when folks see that they can be participating in something that helps bring the information that they're lacking as much as being able to contribute and being able to then see what the insights that that brings, the types of solutions that can be formulated when done in a collaborative sense, the effectiveness of those solutions then can be escalated. I think that the biggest change that we've probably seen is understanding that it's not a subscription to a threat feed that's giving more information when you're under a delusion information.
It's the type of thing that can really bring focus and prioritization to the information that you're looking for. Yeah, and that's a great point because I think everyone's a little bit reluctant to release information that they don't want to make themselves vulnerable to their competitors. So it's a different way of thinking about threat intelligence. Absolutely, yeah.
And the degree of being able to share and leverage a platform and not just a technology but the enablement through the analysts and the people that they are just employees to be able to help facilitate that. So it doesn't always have to be with attribution. It could certainly be questions asked with a degree of anonymity so that you can gather information. Thinking in terms of in the middle of a cybersecurity incident, it's a critical time to be getting information from the outside world and to be able to ask certain questions, understand whether attacker behaviors are being observed in other organizations during a time when you're kind of back down in the war room is a tremendous benefit.
And to be able to leverage an organization purpose around helping to facilitate that degree of sharing versus trying to gather that information independently is a huge benefit. Information sharing is something that we've talked so much about over the last three years. And even I guess the point that seems like every time I was talking to people they were bringing up information sharing. But it's not something that's going away.
I mean, I'm hearing about information sharing all the time. If you and I were to have this conversation a year from now, how would you say information sharing will have or should have it all by then? Well, one of the things that I hope that we can do, and I'm not sure if a year is going to be enough time, but we're seeing everything escalating on a large scale as far as time frame to, would be our ability to really see. The enablement organization to organization is one thing, but to enable this type of information to be shared industry to industry between and backward and forward to government, I think would be a tremendous benefit.
To somewhat remove some of the silos of industries, not just the silos of organizations would help us a great deal. A year might be a bit aggressive, but at the same time efforts to help enable the type of information sharing that we're able to do inside of an industry to go very broadly. Other industries, other aspects of industries, as well as to just increase the amount of organizations that can participate, that see their ability to benefit as much as to just provide, not just to reach sort of a corporate gift backstage, but to really see the benefit of participation. The more growth in the space of sharing, the more information that's available to be shared, and the more information that we have.
Hopefully and again by adding the right analysis to the equation, being able to draw the right priorities out of that information sharing and help organizations focus on the information most valuable, would be just a huge benefit at all. Yeah, well hopefully we'll have it again in the next two years, if not the next year. Sure, sure. Well, thank you, Brian.
Again, we just heard from Brian Engle, who is the executive director of the Retail Cyber Intelligence Sharing Center for Information Security Behavior. I'm Tracy Kidman.