case study
Security Trends Forum
Between now and the last day of class (Saturday, August 13, 2016), you will be using the Security Trends forum to hold discussions on current trends in security based on the criteria below.
Original Thread - You are to create at least three (3) original threads about current trends in security. These can be sub-topics of a similar idea or three different topic areas. Just make sure there is differentiation among the three.
Basically, you are to find a security news item, paper, or journal article, analyze it, and provide your summary. Your initial post should be at least three paragraphs showing your critical thinking of the security topic area .
The topic can be almost anything regarding cyber, IT, or security. Be ready to justify whether or not it is a trend and how it relates to cybersecurity .
You can use the Security Engineering book for many ideas and references.
You may post these any time starting in week 4 . Your initial posts are due at the end of week 8 (Sunday, July 31). This is to allow time for any concluding discussions.
Reply posts - You need to have at least twelve (12) reply posts by the end of the term . Provide constructive feedback on the original post and any other reply posts. Ask questions in addition to providing feedback. At least nine (9) of your replies must be on other student's threads and must be spread out on multiple days .
In both your original post and replies, reflect on whether or not the item being discussed is really a security trend or an outlier. Consider what organizations could or should do to protect themselves. Explain the risks associated with the threat, vulnerability, or exploit.
Listed above is the minimum requirements. More participation and greater analysis will be rewarded with a higher grade. Also, make sure your writing and analysis is in line with a finishing graduate student. That means you need to proofread for grammar, spelling, punctuation, etc.
This assignment is worth 100 points and will only be graded at the end of the term. The professor will provide feedback throughout the term either on the discussion board or in email.
A search of the Internet using the phrase ‘cyber security news trends’ returned an interesting article, after reading it, I chose to investigate further and in turn, found numerous other articles related to and supporting the information detailed in the article. I decided to use the original article as the foundation for my initial security trends forum post on ‘Cloud Services’ as a cyber security trend.
‘5 cybersecurity trends to watch for 2016’, an article / blog post authored by Michelle Drolet, founder of Towerwall, a data security services provider in Framingham, MA published by NetworkWorld lists 5 trends she believes will dominate 2016. They are: “cloud services, ransomware, spear phishing, known vulnerabilities and The Internet of Things” (Drolet, M., 2016).
‘Cloud Services’ is the first cyber security trend the author mentioned in her article. A rudimentary Google search of the following phrase; ‘cloud services cybersecurity trends’ returned approximately 1,180,000 hits in 0.40 seconds. The sheer volume of information about cyber security trends in cloud services is a clear indicator cloud services is in fact a cyber security trend and not an outlier.
The author states “As more and more of the services we use reside in the cloud, IT departments can lose oversight and control”. (Drolet, M., 2016) This assertion is supported by another article on the subject of ‘Cloud Services’ authored by Rick Randall titled “2016 Cyber Security Trends to Watch”.
What caught my attention within Mr. Randall’s article was a specific statistic which referenced “a worldwide online study” conducted by PwC. According to the study cited by the article “…clients and readers of CIO and CSO from May 17 to June 12, 2015…” surveyed, responded and stated “69% were using cloud-based cyber security services in 2015” (Randall, R., 2016) In essence; outsourcing cybersecurity ‘Cloud Services’ is near 70% and all indications are it will continue to grow in popularity; Cloud Service cyber security is a definitely a trend.
Another declaration the author makes states “Employees are bypassing IT to snag the services they feel they need, and there’s a real danger that they’re bypassing security protocols and systems in the process. (Drolet, M., 2016) She also recommends anyone reliant on cloud services remain skeptical because in her words “Even approved cloud vendors must be scrutinized on an ongoing basis”. (Drolet, M., 2016)
In this section I’ll address the critical thinking requirement and summarize the ‘Cloud Services’ portion of the article. In my opinion, the author’s message is cyber security Cloud Services are great and they’re here to stay as long as the outsourcing organization ensures the organization they’ve entrusted is held accountable. Secondly, the outsourcing organization continues to ensure they’re getting what they paid for and what they pay for meets the needs as their organization changes. Third, Cyber security is not a Ronco Rotisserie product where you can ‘set it and forget it’.
This is the second of my cyber security trend discussion forum posts. I am still referencing the original Internet search I conducted using the phrase ‘cyber security news trends’. As previously stated, I decided to use the trends from the original article cited in my first post as the foundation for my security trends forum posts. This time I’ll discuss the second cyber security trend identified by the author as ‘ransomware’. (Drolet, M., 2016)
Ransomware is the next trend discussed by the author. She states “The impact of ransomware is growing. (Drolet, M., 2016) The author cites a report by Cyber Threat Alliance , which states “the recent CyrptoWall v3 threat has cost hundreds of thousands of users worldwide more than $325 million so far. For those who are unfamiliar with Ransomware, the author describes it as an attack that “…encrypts important files, rendering data inaccessible until you pay the ransom. It often relies upon social engineering techniques to gain a foothold”. (Drolet, M., 2016) She further asserts “It works, and we expect to see a lot more of it over the next 12 months, because the easiest way for many individuals and businesses to get their data back is just to pay the ransom”. (Drolet, M., 2016) My father-in-law fell victim to this last year. Fortunately for him, I was able to resolve the issue without him paying any money or losing any crucial files.
I can say with absolute certainty the author is correct; this is a trend and not an outlier. Why, because once something is successful, people will continue to use it until it’s no longer successful and then morph it slightly and use it again to try and drain every last dime they can out of the scam and unsuspecting new victims. Think of the ‘Nigerian Prince’ scam; each time you think no one could fall for it again, the criminal element changes it slightly and someone falls victim to it.
With a bit of forethought, better education and real-time security protection, not to mention a regular, robust backup routine, the threat of ransomware can be cut down to size.” (Drolet, M., 2016) Drolet, M. (2016, January 6). 5 cybersecurity trends to watch for 2016. Retrieved June 14, 2016, from http://www.networkworld.com/article/3019235/security/5-cybersecurity-trends-to-watch-for-2016.html
Lucrative Ransomware Attacks: CryptoWall Version 3 Threat. (2015, October). Retrieved June/July, 2016, from http://cyberthreatalliance.org/cryptowall-report.pdf
This is the third of my cyber security trend discussion forum posts. Nothing has changed; as I am still relying on the original Internet search I conducted using the phrase ‘cyber security news trends’. As previously stated, I decided to use the original article cited in my first post as the foundation for my security trends forum posts. This time I will discuss the third cyber security trend identified by the author; ‘Spear phishing’ as a cyber security trend. (Drolet, M., 2016)
‘Spear phishing’ is the third trend the author mentioned, She states “Cybercriminals follow the path of least resistance and the easiest way for them to gain access to your precious data is usually by tricking a person into handing over the keys, not by writing a clever piece of code. Phishing attacks are growing more sophisticated all the time, as official-looking messages and websites, or communications that apparently come from trusted sources, are employed to gain access to your systems. The targeting of high-level execs or anyone with a high security clearance is on the rise. If cybercriminals can hack a CEO’s account, for example, they can use it to wreak havoc and expose a lot of sensitive data. Educating potential targets about the dangers is not enough. You need a combination of real-time monitoring and scanning systems, with protective blocking capabilities. That said, sometimes laying down a security policy for employee education is all you need.” (Drolet, M., 2016)
In this section I’ll address the critical thinking requirement and summarize the ‘Spear phishing’ portion of the article. In my opinion, the author’s message is Spear phishing
This is the fourth of my cyber security trend discussion forum posts. Nothing has changed, as I am still relying on the original Internet search I conducted using the phrase ‘cyber security news trends’. As previously stated, I decided to use the original article cited in my first post as the foundation for my security trends forum posts. This time I will discuss the fourth cyber security trend identified by the author; ‘Known vulnerabilities’ as a cyber security trend. (Drolet, M., 2016)
‘Known vulnerabilities’ is the fourth of the five trends the author discussed. She states “The open source movement has leveled the playing field for many companies, and there are also lots of off-the-shelf software packages that are very popular. Integrating this software will often make more business sense than developing something in-house, but you have to keep vulnerabilities in mind. Publicly known vulnerabilities are one of the biggest threats for IT departments. Consider that HP’s 2015 Cyber Risk Report found that 44% of 2014 breaches came from vulnerabilities that are two to four years old, and you can see the problem. Software must be patched regularly, and expertise is required to avoid common misconfigurations that offer attackers an easy way in.” (Drolet, M., 2016)
This is the fifth of my cyber security trend discussion forum posts. Nothing has changed; as I am still relying on the original Internet search I conducted using the phrase ‘cyber security news trends’. As previously stated, I decided to use the original article cited in my first post as the foundation for my security trends forum posts. This time I will discuss the fifth and final cyber security trend identified by the author; ‘The Internet of Things’ as a cyber security trend. (Drolet, M., 2016)
‘The Internet of Things’ is the last trend the author discussed. She states “We’ve seen a wave of mobile devices and wearables stream into the workplace, each offering a new potential inroad for a cybercriminal, but the Internet of Things represents another looming threat. As connectivity spreads into every corner of our lives and businesses, it becomes more and more challenging to maintain a clear view of entry points and data flow. The IoT may herald some exciting business opportunities, but we must be mindful about ensuring that access is limited and secure. Sensitive data should be encrypted, access must be restricted, and oversight is needed. It’s important to be able to manage and block access to enterprise devices and networks when necessary. If you expect to enjoy success in 2016, and you want to ensure that your plans aren’t derailed, then make sure that these cybersecurity trends are on your radar.” (Drolet, M., 2016)
References:
Drolet, M. (2016, January 6). 5 cybersecurity trends to watch for 2016. Retrieved June 14, 2016, from http://www.networkworld.com/article/3019235/security/5-cybersecurity-trends-to-watch-for-2016.html
Randall, R. (2016, March 5). 2016 Cyber Security Trends to Watch. Retrieved June 14, 2016, from http://www.electriclightwave.com/2016-cyber-security-trends-to-watch/