How prepared are you to overcome the misuse of AI

How prepared are you to overcome the misuse of AI

Overcome the Misuse of AI Have you ever considered that the AI system integrated into your organisation's computing infrastructure could possess a threat? What if it is indeed true? Will it wreck your entire organisation and cause massive breaches of sensitive information? We can only
Data Policy is Fundamental for Trust

Data Policy is Fundamental for Trust

Data Policy Trust Consumers once owned and protected their data independent of anyone else. Handwritten letters, paper bank statements, medical records locked up in a doctor’s office were once the norm. The online era of digitalization and social media has ensured this is no longer

WikiLeaks’ Vault 7

If you haven’t heard of the Vault 7 WikiLeaks data dump, you’ve probably been living under a rock. The leak unveiled new, yet unsurprising, classified material from the CIA; allegedly sharing information on the U.S. agency’s hacking tools. While individuals are concerned about these CIA tactics and whom they might be spying on, enterprises should be also be paying close attention.

The Good News: Encryption Remains a Staple in Cybersecurity

Despite all the hacking tools and malware at the CIA’s disposal, they were unable to read encrypted content from messaging services such as WhatsApp. While you may be surprised to discover the CIA struggled to read protected information, this is great news for enterprises using encryption to protect sensitive data from unsanctioned access. The CIA isn’t the only federal agency struggling to crack encryption codes. The FBI famously went to court last year to access records from an iPhone when investigating the San Bernardino shooting. Clearly, encryption presents challenges for those trying to gain access to data, and if our federal agencies are having trouble, that means hackers are struggling, too.

The Bad News: Devices are Top Security Targets

(Image Source: Shodan)

In the face of these hurdles, the CIA has also gone to great lengths to obtain information by other means – investing a lot of time into figuring out how to physically compromise data itself. Consequently, they’ve developed tools and mechanisms to access operating systems and devices. This poses an entirely new concern to enterprises trying to keep their information safe from malicious hackers.

Our society produces huge amounts of data that are constantly transmitted from device to device. Today, content and information is shared on phones, tablets, PCs, USBs, Smart TVs, and IoT devices – the list goes on and on, and it’s not going to get any shorter as we become a more connected world. You may think anti-virus tools or security software will keep your information safe, but even those resources can be shut down and used against an enterprise.

So, what’s a company to do? Is your data destined to be sucked into a hacker void? Well, no. But it does mean enterprises need to keep track of a lot more.

Tips for the Ugly Side of Enterprise Security

For enterprises conducting business across geographic boundaries, it’s important IT security teams keep tabs on the total number of devices being used, especially as users change habits and new vulnerabilities emerge. Data, more often than not, is confiscated by users losing their devices, and by weak and/or stolen passwords. Since employees typically reuse passwords, there is even more risk when a password is lost, as hackers take advantage of reusability and enter the same password to gain access to even more critical systems.

But what does security in a mobile and cloud-first world look like? If the WikiLeaks story showed us anything, it’s that enterprises need an information security strategy across devices, on-premises and in cloud networks. Enterprises can achieve this by:

  • Seeking tools that provide end-to-end encryption;
  • Ensuring mobile security through a secure container on each user’s device that is independent of its native OS security;
  • Protecting data that is on the move, especially as it is transfers across geographic boundaries or between business partners;
  • Providing secure, user-friendly tools that hackers won’t find a work-around and put company data at risk; and
  • Setting permissions so only the right users can access and share company information.

Reconciling the Good, Bad, and the Ugly

Although the WikiLeaks Vault 7 data dump didn’t reveal many revelations as to whom the CIA is spying on and how they’re doing it, it did provide some valuable lessons for enterprises. Despite having a slew of resources at their disposal, the CIA couldn’t crack WhatsApp encryption codes.

While this is great news, it also means hackers will follow the examples of the CIA and are turning to other attack methods by targeting devices and operating systems, which means enterprises need to employ the right tools and strategies to keep information safe. While the task is daunting, it’s not impossible. Keeping up with new attack methods and implementing a successful multi-layer security strategy, especially in the cloud, will be key as tools and user habits change in the years to come.

By Daren Glenister

Daren Glenister

Daren is the Field Chief Technology Officer for Intralinks. Daren serves as a customer advocate, working with enterprise organizations to evangelize data collaboration solutions and translate customer business challenges into product requirements.

Glenister brings more than 20 years of industry experience and leadership in security, compliance, secure collaboration and enterprise software, having worked with many Fortune 1000 companies to turn business challenges into real-world solutions.

View Website
Winning the data intelligence game

Winning the data intelligence game

Data intelligence A case can be made that every company is now a data company. But, it is the effective ...
Big Pivot Podcast: How To Become A More Effective CIO

Big Pivot Podcast: How To Become A More Effective CIO

Become A More Effective CIO The Big Pivot podcast, put together by IDG and Informatica, looks at how CIOs are ...
GDPR Compliance

System Vulnerabilities Are an Issue for Everyone in the Cloud Environment

System Vulnerabilities Are an Issue for Everyone Over the past decade, we have seen a drastic increase in the number ...
Backups And Disaster Recovery Are Not The Same Thing

Backups And Disaster Recovery Are Not The Same Thing

Backups And Disaster Recovery Most business owners are aware of the consequences of losing data. Much of the value of ...
2019 Big Data and Data Science Predictions Through the Lens of Comedy Movies

2019 Big Data and Data Science Predictions Through the Lens of Comedy Movies

2019 Big Data and Data Science Predictions It’s that time of year again when I look into the Crystal Skull…er, ...
Canadians Would Warm to Open Banking with Assurance of Increased Security

Canadians Would Warm to Open Banking with Assurance of Increased Security

TORONTO; April 17, 2019 – Open banking technology is poised to change the way the world completes transactions, but three quarters (75 per cent) of Canadians say they are wary of the concept, citing concerns ...
Apple, allies seek billions in U.S. trial testing Qualcomm's business model

Apple, allies seek billions in U.S. trial testing Qualcomm’s business model

(Reuters) - Apple Inc and its allies on Monday will kick off a jury trial against chip supplier Qualcomm Inc in San Diego, alleging that Qualcomm engaged in illegal patent licensing practices and seeking up ...
EU approves tougher EU copyright rules in blow to Google, Facebook

EU approves tougher EU copyright rules in blow to Google, Facebook

BRUSSELS (Reuters) - Google will have to pay publishers for news snippets and Facebook filter out protected content under new copyright rules aimed at ensuring fair compensation for the European Union’s $1 trillion creative industries ...