Insecure Future – PC.COM talks to Albert Chai, Managing Director for Cisco in Malaysia.

2000px-cisco_logo-svg

As digitisation and the move to the Cloud become more important, the threat of cyber attacks on key IT infrastructure also increases every year. PC.COM talks to Albert Chai, Managing Director for Cisco in Malaysia. He is responsible for all of Cisco’s sales and marketing activities in the country.

 

Albert joined Cisco in July 2009, as the Regional Manager for Service Provider, managing the sales and business development for Service Provider customers in Malaysia.

 

What’s Cisco’s view on the security challenges in 2016 and beyond?

 

As we progress into a more digitally connected world, the implications for security continue to grow. While organisations are strengthening their security posture, attackers continue to become bolder, more flexible and resilient by the day. As a result, the urgency and concern around security will only continue in 2016, primarily around these four pressing issues:

 

Growing networks, growing exposure

As organisations digitise their operations, we are seeing the growth of devices and a corresponding increase in networks. 2015 alone saw a surge in mobile data traffic by 74 percent, an increase we observe exponentially year after year. While digitisation brings valuable insights to the enterprise, the growing number of network connections increases risk exposure and points of possible attacks.

 

Efficient and innovative threats

Findings from Cisco’s Annual Security Report 2016 demonstrate that nimble attackers are tapping into legitimate resources to launch campaigns for profit gain. This is one example of how hackers are continuously innovating their approaches, making their attacks harder to detect and therefore, far more pervasive.

 

Aging infrastructure

According to Cisco’s 2016 Annual Security Report, the number of organisations that said their security infrastructure was up-to-date dropped by 10 percent between 2014 and 2015. The survey discovered that 92 percent of Internet devices are running known vulnerabilities. Thirty-one percent of all devices analysed are no longer supported or maintained by the vendor.

 

Decline in defender confidence

Cisco’s 2016 Annual Security Report also revealed that less than half of businesses are confident in their ability to assess and remediate breaches. However, regulators and investors today expect companies to provide greater transparency on future cybersecurity risk. This points to security as a growing boardroom concern.

 

Do you think Internet of Things (IoT) devices can ever be completely hack proof?

The IoT industry today is still evolving, estimated to grow to 50 billion connected devices by 2020. This means there is large potential for diverse threats, with cybercriminals leveraging on the influx of new devices and connections.

 

Security environments today not only consist of more devices, but also a patchwork of solutions from multiple vendors. This is costly and complex for professionals to integrate and manage, and it still may leave security gaps. Point products or a purely preventive approach is no longer sufficient.

 

Instead of hoping for that silver bullet for IoT devices, Cisco believes that the ongoing development of IoT and its associated risks are driving the need for an architecture that can defend itself against those threats. The question of “what do you do when you are compromised” highlights the need for organisations to invest in a threat-centric security approach, combining visibility, control, intelligence and advanced threat protection across the entire attack continuum – before, during and after and attack, remediating the network that connects each device together.

 

What is the level of encryption required in consumer devices and software to make them hack proof?

 

Encryption is a rational approach. Consumers need to protect their personal and sensitive data, and businesses are emphasising on both the protection of their intellectual property and customers’ privacy. However, encryption can be far from the ultimate answer in securing hardware and software from threats, instead creating a false sense of security and blind spots.

 

Although encryption can help protect consumers, it also can undermine the effectiveness of security products, making it more difficult for the security community to track threats.

 

The answer to the encryption “problem” is to have more visibility into what’s happening on consumer devices or networks. Integrated security platforms can help to provide this.

 

What is your view on governments demanding back doors into corporate software?

 

With the collection of data and its conversion into business critical insights, several alarms ring around the possibility of entities gaining access to personal data, disqualifying the protection that exists for consumers.

 

From the public sector’s perspective, national security will always be a key concern. However, while general legislation permits the use of physical searches and interference in communications where warranted, businesses have an ethical responsibility to protect consumers’ personal and private data, intended for improving products and services. Companies would therefore have to evaluate the extent to which the existing information they hold falls under the jurisdiction of data protection acts, redesigning their policies to reflect the values it stands for.

 

Another key concern would be the security of this data once it has been passed from one entity to another. Hackers are aware of the demand for critical information for national security and are prepared to intercept this information, even in encryption. Once this is compromised by third parties, there is arguably little to justify in obtaining valuable information for national security.

 

Is there a way to balance national security against personal privacy?

 

Governments around the world are doing their best to ensure the security of national assets to protect its citizens. However, some of these measures remain questionable, extending towards the collection of private data without full consent.

 

It is clear that there needs to be a wider discourse regarding balancing the trade-off between upholding national security objectives and protecting the privacy of individuals. A transparent approach is key, primarily by engaging and consulting stakeholders such as public officials, businesses, and civilians. From this, a guideline or standards of conduct can be formed to regulate any data collection activities so that national security objectives meet with personal privacy concerns.

 

While real and significant threats exist, we must also respect the industry’s relationship of trust with our customers. Failure to restore that trust and integrity could not only jeopardise our dependency on the Internet, but also any progress towards realising the full benefits of a digitised way of life.

Share this post:

Comment what you think!