Retire General Keith Alexander on Collective Defence, current insights on new payment industry fraud schemes, and the ISEMG editing gives the lowdown on RSC-2020 highlights. These stories and more in this week's ISEMG security report. Hello, I'm Nick Holland. Another year, and another RSA conference is nearly in the bag for the ISEMG team.
The thing with the human element for RSA this year was extremely apt, both in terms of the new recessions and discussions at the conference, but also in the ever present concerns relating to the spread of COVID-19. However, it didn't impact ISEMG's interview schedule, with well over 100 interviews conducted with a cast of characters covering the entire gamut of the cybersecurity industry, proverbial who's who in the cyber zoo. Later in this podcast, myself and other members of the onsite editorial team, discuss some of our key takeaways from discussions and interviews we've had. But first up is an excerpt from an interview that ISEMG's SVF editorial, Tom Field, conducted with Retire General Keith Alexander, where he discusses the definition of collective defence.
There's two analogies that I would give you for Collective Defence. The first is if you think about Collective Defence and you think about air traffic control. When you flew out here, the radars created a picture that allowed your plane to be seen seamlessly as it crossed the country. In that regard, you had a good picture of what's going on, because the radars share information at network speed.
In cyber, each company works by itself and shares what's important, but you don't get the whole picture, so you don't see what's going on. So we want to change that. And so from our perspective, Collective Defence is imagine 90 companies all with 10 people. Today, those 10 people defend their company and do as much as they can in a day.
Now take the other 89, let's take all 900 people and work them together so that they can see the events that are hitting all of them. 900 people working together will accomplish more than 10 working by themselves. And the power of the network can be realized in doing something like that. Imagine the big shift that we have.
So there's a couple of things that you have to do to make that work in terms of technical observations of the network traffic in terms of visualization and bringing all this together. But when you do that, it will change the way we defend our country, our allies, our states, our sectors and individual companies. I think that's the journey that we're on, and we need to do it. Even if you think about this in talking to a series of bank directors, when you think about the fact that the amount of information is doubling every year, the number of devices going on in that work is increasing exponentially.
There's not types of protocols and other things. All this is coming together. Your security ops center people don't double every year. So their workload is doubling every year.
How do you keep up with it? And the answer is, they don't. So we look at them. When something happens, we beat them up.
We have to invest in it. So you have two opportunities. Double your security ops center every year or do collective defence and go get a 90 times improvement right away. So a board, the C-suite, I think we'll see the opportunity to make that shift.
It's the future. Even the biggest companies are going to have to do something like that. You're listening to the ISMG security report on ISMG Radio, ISMG, your number one source for information security news. Another interesting area of discussion, RSA this year, was the use of biometrics in banking and payments for fraud mitigation.
And I got to sit down with Robert Capps, new data securities vice president of marketplace innovation. New data was acquired by MasterCard in 2017, and therefore Robert's lens on the world is very much focused on what is happening in the payment fraud landscape. I asked him, what new types of fraud are bubbling to the surface in 2020? Here he is.
Automation with the number of data breaches we see on a daily basis. You just pick up the newspaper to speak. People read newspapers. People read newspapers.
People read newspapers. Yeah, you heard about the latest data breach. People are just, they're used to this every single data is released. Well, on the back side, as we look at how this data is being used, we're seeing more and more use of the stolen credential data to try and access consumer accounts and to try and create new accounts under consumers names using their credit using their reputation and what have you.
What we've really seen is that most organizations have now deployed technologies for basic automation detection. So those attacks are really high speed. There's not a lot of attempt to hide the volumes of attack traffic. Most organizations have technology in place to resolve those issues.
And so we've seen a movement over the last six to eight months of consumer account attacks going from high speed automation to very nuanced attacks, very low speed. They're not using the same data points over and over again. They're spreading their traffic out across a large of volume IP addresses. They're actually executing things like JavaScript and they're allowing collection of type of mandatory mouse movements and other behavior elements so that those transactions look a lot more human.
And so organizations that don't have more advanced techniques looking at those data points don't have the protection of some of the organizations that do have them deployed. How about there? And you think that is primarily, I guess, can't take over fraud types of things. Can't take over and do it.
Yeah, no account fraud. Because it's synthetic as well as real identity. So, and I mean, I believe as well, some of these are in it for the long haul as well. They're developing, sit in the identity, you know, years.
Absolutely. Yeah. So that's, that's an emerging area. But it does require a lot of investment.
When we talk about stolen data, it has a defined shelf life before it starts to become stale. And that data gets cycled out as people are aware of the attacks and it gets used at the places where it's valid. Things like synthetic identity attacks are really about the long game, creating an identity that will be durable. They will allow you to build, build, build that credibility until you get to the point where you have a breakout fraud where it's tens of thousands of dollars of loss.
And finally, myself and the ICEMG team are all still at the RSA conference and continuing to conduct interviews even as I speak. But after three days in Italian over a hundred discussions recorded, we have a fairly good overview of the key themes for 2020. Following yet another magnificent breakfast at Mel's Dine this morning, myself and the other on-site editor sat down to compare notes. Here's our collective thoughts.
Hello, this is Nick Holland with Information Security Media Group. And I'm joined by the rest of the editorial team on-site at the RSA 2020 conference. We have obviously, for instance, we have Tom Fields and we have Matthew Schwartz. Gentlemen, morning.
Morning. Morning. So the conference theme this year, I always had a theme. The conference theme this year has been the human element.
What sessions have you seen? What key themes have you come across that's probably tied into that overall arching umbrella theme of the human element? Well, I'll go first, Nick. I think a lot of it for me was leading up into November.
So election security, Christopher Krebs was here. He did a main keynote. He touched on a lot of themes related to what his organization is going to be doing into the lead-up. The organization being CSSA.
The organization being CSSA and the Department of Homeland Security, what they're doing to work up towards the 2020 election to sort of cut down on some of those issues we saw in 2016. So that's also working with a lot of state and local officials to get that done, also set to another panel where they were talking about machines in elections, securing voting machines, securing the apps that are coming up there. Over and over again, even though there was technical discussions, a lot of it focused on how people interact with this sort of technology, getting your paper ballots, having backups, etc., etc. So nothing much more human than democracy.
Exactly. For me, it wasn't attending sessions. It was sitting in our studios where we had literally scores of people coming through and talking about different topics. On themes with the human element, I would say the predominant message was about the insider threat, not the malicious threat, but the accidental insider who makes some mistake or is taken advantage of.
As the organization's awakening to this becoming a bigger issue for them and looking for ways to address that. Wonderful. And Matt, yourself. A lot of great themes this year.
On the human element, one of the big ones I said is Zero Trust. That was a huge theme that we heard and talked about. And of course, there's a human element involved in that. Securing the organization as humans bringing in all their different devices, connecting all their different ways.
I think with the human element, there was also kind of an unintentional connection with the news of the day, with the coronavirus. Absolutely. And that being a wild card, maybe, obviously not just with cyber security, implications in the industry is here in the biggest conference of the year. There was definitely some impact in attendance and with the energy of some of the events, I think.
But... Matt, is it fair to say that we walk out of here with Zero Trust being the official buzzword of RSA 2020? It seems to be. I mean, it was previewed, I think, as being what was going to be the big thing.
Of course, marketing budgets are behind that, so you go on the exhibits floor and you see a lot of zero trust. I've been hearing a lot of zero trust in the studio. And in a good way, I think, in a much more articulate and detailed way, not just about the concept, but about how you make it actionable and useful, which is obviously where we need to get to with anything with solid-effect intelligence. And clearly, we're now seeing more of zero trust.
And suddenly, we've seen zero trust in handshakes this year. That's true. Yep. Facebook, unfortunately, if you...
Even elbow bumps, I think we did. Elbow bumps, exactly, a little bit of a wave. Also on the trust front, supply chain is a huge theme this year, in RSA. There is been a lot of discussion about Huawei, and it's a wonderful panel with Bruce Schneider, of Huawei's A Decree, also the Defense Department's CISO for acquisitions, Katie Errington, among others.
And they were talking about the difficulty of the Huawei debate. Schneider said something fascinating, which was, supply chain is impossible to secure. Unless you own the software, the hardware, every aspect, you can't secure it. He said, there's been a push to say, well, maybe Cisco is the answer.
We're ericing. They don't build their equipment domestically. It's all manufactured in China. And it might be back again back to the coronavirus, I don't want to bang on that.
That's too much, but that does tie into exactly what we might be seeing as it's something of a breakdown, potentially, in the components of that supply chain, based on... Apple's already reported that they think they're not going to be able to need them manufacturing targets for us, for example. Yes. Microsoft, Microsoft, too, also came on the same yesterday.
They're also falling behind on some of their projections for the next quarter coming up. So that was a big news that broke late in the show there. So a very human element, again, is actual biology. Yeah.
Okay. Well, gentlemen, thanks so much. We're in a wonderful week working with you all. Shall we commit acts of journalism again next year?
I was looking forward to it. Very good. That's it for this week's iOS and security report. Thing news is why you think audio?
I'm Nick Collins. Catch you next time.