Follow us on Twitter
Add me on Linkedin
RSS
About CARM Why CARM
Why CARM
Documents
Videos
Request a Demo
Threat Centre
There is nothing so frightening as a fatal disease with no cure. The race is on to find the vaccine to prevent Ebola from devastating West Africa and spreading the epidemic to other parts of the world.
Traditional security systems at ports and airports are ineffective. Perimeters are meaningless, and individuals are mobile enough to cross borders without encountering checks. Carriers of disease are typically unaware, and often don’t exhibit symptoms for some time after getting infected. The virus itself has mutated hundreds of times already, and will continue to do so.
As the human tragedy of Ebola unfolds, it’s hard to ignore the common lessons it teaches about the nature of all complex threats to society, industry and life in general. Cyber threats – and the defences they face – are remarkably similar to the situation I’ve just described. Deperimeterisation, mobility, firewall bypassing, malware mutation, threats lying dormant… we’ve seen all of this.
And as we’re seeing with Ebola, the only sensible reaction is a federated multi-agency approach where resources and expertise are coordinated to mitigate the impact of the threat. Finding the ‘signature’ to the virus is only one part of the eco-system based response that’s required.
I think this is the rationale behind Palo Alto Networks and Fortinet joining forces to co-found the Cyber Threat Alliance . They’ve since been joined by fellow security heavy-hitters McAfee and Symantec, and the mission of the alliance is to drive a coordinated industry effort against cyber-adversaries through deep collaboration on threat intelligence.
I’ve said before, and I could carry on all day right now, about how CARM is the optimum solution to countering the cyber attack menace at the practical level. This is exactly the federated, platform approach I’m talking about. CARM will continue to evolve, as will the threats it faces.
All of this ends up at the feet of the reseller, and the vital role they need to play with their customers. A crisis is no time for championing individual vendor technologies. Instead, resellers need to be the UN or World Health Organisation in this equation; the honest brokers whose value lies in finding the right solution quickly, and implementing it.
Not quite Ban Ki-moon, but not far off it either…
In the quest for completeness of partner resources – ensuring the now ubiquitous ‘partner portal’ is fully stocked with anything that any reseller partner could ever need – many IT vendors are in fact missing the central purpose of their partner strategy: the quest for effectiveness. If a big fat partner portal risks draining resources that could be better spent instead on proven, targeted channel activities, then we would all be better off without it.
I’ve long taken issue with the futility of overinflated partner portals, but there is another branch of vendor complacency to expose: the accreditation programme.
Partner accreditation programmes used to be Gold, Silver and Bronze, mirroring the Olympian prizes for ‘best’, ‘almost best’ and ‘recognition for trying your best’, and signifying rarity as well as value. Now you’ll find Platinum, Diamond and – for all I know it – Asteroid. In many partner programmes, the exciting new names represent the sum total of the imagination that anyone has ever invested in them.
Incidentally, Platinum isn’t the most valuable, or rare, metal. Students of the periodic table will be familiar with Rhodium (Rh), known for its shininess, density and ability to appear new despite its age. Like a few reseller salespeople I could mention!
The purpose of the partner programme is to efficiently run individual partner relationships at the most effective level possible, investing the vendor’s limited technical and pre-sales resources where they count most, and providing a strong and equal commercial framework for rewarding and incentivising sales activity that makes a real difference. Partner programmes are also the communications point for knowledge transfer, new opportunities, propositions and other important sales and technical information.
Often, these objectives are simply lost in the context of a tiered accreditation programme. And as with the partner portal argument, resources are wasted where they could so easily be focused on driving great results.
Indeed, many vendors are sucking their thumbs with partner programmes – getting comfort from a fake substitute for some genuine care and nourishment.
Here are some examples:
– The communications flow is frequently ‘broadcast’ orientated rather than a real two-way conversation where partners feel they are listened to and where the vendor can apply its expertise to channel issues.
– Tiers are typically based on size rather than commitment, meaning a big partner with minimum commitment is better supported than a smaller partner with total commitment.
– Too little effort is invested in understanding the DNA of the most successful partners, and trying to copy, develop and improve their blueprints for success
All IT vendors that pursue a tiered accreditation programme do so to avoid giving a ‘one-size-fits-all’ solution to every partner. Think of it like a T-Shirt – the one-size-fits-all never fits anyone! But providing Large/Medium/Small, in the manner of Gold/Silver/Bronze is not the answer either. Remember we are talking about partners creating market opportunities for disruptive, high margin enterprise technologies. They will benefit from tailored support, and benefit the vendor in return.
Global analyst group Gartner is supremely influential in our industry, but let’s be honest – they aren’t always the quickest off the mark. However its ‘Prevention is Futile’ paper from a year ago, forecasting how the IT security sphere will look in 2020, drove a new market acceptance for the reality of inevitable data breaches and how to address them. Gartner’s gloomy prediction still has six years to go, and I think that’s looking very optimistic.
That’s what was running through my mind the other day, being whizzed through the streets of Paris by ‘Moto Joe’, my regular motorcycle taxi and (I imagine) former get-away driver.
Taking this picture was probably illegal as well.
Moto Joe has the laissez-faire riding style of a crazed adrenaline junkie on LSD, so it’s a wonder that I could think about anything at all, other than hoping to see my children again before being decapitated by a bus and swept into a storm drain.
On the Parisian super-highway, it is normal for Moto Joe and I to bust red lights, go the wrong way down one-way streets, cut-up other road users and bunny hop over lane barriers. In fact, it’s normal behaviour for most of the turbo-charged Honda Goldwings you’ll see. What ISN’T normal behaviour are the riders dutifully following in line with traffic flow, indicating at junctions and keeping to the speed limit. No – these are deeply suspicious – and I have it on good authority from Moto Joe and his contacts in les gendarmes that these are typically drunk drivers, bag thieves or other ‘no good boyos’.
Establishing what’s normal – even if (as with Moto Joe et al) ‘normal’ is different to what you expect – is a critical part of the battle to address so-called ‘malops’ (malicious operations) or APTs. In a network environment, using the CARM platform to establish ‘normal behaviour’, you may find that unsociable and discourteous activity is standard activity and is largely harmless as a threat. Riskier non-standard activity that might otherwise look very innocent can be better identified in this regime, with a wealth of potential actions such as being sent to a sandbox to be detonated, inspected or monitored closely.
It was the union of taxi drivers’ turn to be on strike in Paris recently, and it was sad to think I wouldn’t be taken back to the airport by my favourite motorcycle maniac, Joe. I texted him to say as much… “Don’t worry,” he replied. “Walk 500 metres to the corner and I will meet you there!” And that’s where I found him, along with 40 other bike taxis – breaking all the rules …as normal!
It can be very hard for IT security vendors to convince their customers to ‘go public’ about choosing them. Often the customer will claim it could harm them to tell the world what security system they use. Rubbish! The real truth is that it’s more likely to harm them if they keep it a secret.
Any cybercriminal worth their salt can interrogate the security infrastructure of any organisation in seconds to find out what vendor solutions it uses – and even see what threats would fail or succeed in penetrating that organisation before launching them. This destroys the myth that somehow agreeing to a press release will somehow make an organisation a target. This mindset really is dangerously ignorant; it suggests that the organisation believes it can continue being invisible to cybercriminals so long as it doesn’t appear in a PR story in ‘IT Security Magazine’. Has no-one ever told them there is no security in obscurity?!?
To make an analogy: if cybercriminals think you’re a good target they can not only tell what kind of underwear you’ve got on, they know precisely how much longer you can wear it until the elastic breaks!
In today’s security landscape we’ve all come to terms with this Perfect Storm of innovative threat vectors, diversionary attack tactics, bigger threat volumes, frequencies and the persistent ingenuity of cybercriminals. Any organisation could become the next ‘data breach’ headline and have their reputation put under scrutiny as a result. If so, then surely it would be a good idea to be consistently loud and proud about your strong security posture up to that point?
Someone suggested to me recently that this state of affairs could even result in this being flipped on its head with security companies being the ones who don’t want to be associated with the companies they’ve sold to, in case they are made to look weak if the customer is ever breached in future. I’m not so sure… Does the armoured money transport company get blamed if two guys with masks and shotguns hijack their van full of Euros?
So, the next time your IT security supplier ask for help with publicity, look at is an opportunity to differentiate yourself in the market – it’s a strength and an asset that should be amplified not hidden away on the risk register!
With cybercrime insurance, insurance companies charge money to cover the risk of cybercrime exposure and underwrite any losses up to an agreed level. In practice, there’s lots of legal ‘small print’ to navigate detailing the many exemptions and get-out clauses. Your car insurance is invalidated if you leave your doors unlocked, so it makes sense that your cybercrime insurance won’t cover you if you don’t have your security systems running properly.
Cybercrime is increasingly referred to in legal documentation. Most people will recognise force majeure (Act of God) from the small print of their airline ticket; the part where it says you can’t claim a refund in the event of your plane being sucked into a tornado or hit by an asteroid. Unbelievably, this common contract clause is also included in many legal documents in relation to cyber security.
I have a lot of respect for people’s religious beliefs, but – I’m sorry – you are crazy if you think that it’s the Almighty hammering out code to exploit the cyber security weaknesses of target organisations.
Providers of IT services have legitimate claims to use the force majeure exemption when it applies to their datacentre being flooded or demolished by an earthquake. However, I don’t think these protections against corporate risk should be used as a get-out clause when hackers, viruses and security breaches strike!!
The opportunities for good cybercrime insurance are long overdue, especially if they stay away from defining cybercriminal activity in the same way as a bolt of lightning.
The earliest business insurance related to ships and their cargo. A ship container full of plasma TVs undoubtedly has its contents insured. Consider for a moment just how much vital data cargo is being held and transported everyday between organisations. Shouldn’t this be insured too?
Having car insurance doesn’t stop you trying to avoid accidents. In fact, it stops working when you stop trying! Cybercrime insurance policies could be a great idea for business to adopt, but it won’t stay in force if you fail to keep your cybercrime protection updated.
Major office fires don’t happen very often, but that doesn’t lessen the importance of conducting a regular drill. Drills are important because people are often desensitised to alarms. Be honest – when you hear a burglar or car alarm bleeping do you automatically throw on your superhero costume and run to the rescue? No, you think someone’s alarm has been accidentally set off!
Fire drills are vital, but surely it should be the same with ‘Incident Response’ planning for the chance of cyber attack?
Fire safety non-compliance can be punishable with prison terms and unlimited fines. Government advice says:
Have fire detection/warning systems with different kinds of detectors for the different kinds of threats
Have fire-fighting equipment installed, tested and maintained; ensuring staff are regularly trained to use them effectively in emergency situations
Conduct regular checks of: Alarm systems Escape routes/plans e.g. don’t use the elevators! Communications processes People traffic controls; fire door closures etc
Alarm systems
Escape routes/plans e.g. don’t use the elevators!
Communications processes
People traffic controls; fire door closures etc
Conduct at least one drill per year and record the results
If you know anything about IT security then you’ll immediately recognise the similarities here, and the need to address post-breach scenarios with rapid remediation and mitigation. Addressing these issues goes to the heart of the Exclusive Networks CARM initiative .
Here’s how these fire safety measures might translate into a cyber attack drill – or what’s commonly referred to as an IR (Incident Response) Plan:
Appoint an IR Team
Have a single system for detecting threats that has multiple specialised threat detectors feeding into it
Have the ability to get the threat under control, contain and extinguish it
Conduct regular checks of: Security alert systems Contingency plans e.g. don’t use the routers! Shutting all ‘Internet Doors’ Communications processes Network traffic controls
Security alert systems
Contingency plans e.g. don’t use the routers!
Shutting all ‘Internet Doors’
Network traffic controls
One final thing: regulations typically call for organisations to appoint and train enough fire marshals to help maintain safety in a fire situation.
In our cyber attack scenario, this is the IR Team led by the CISO – wearing a high visibility jacket! – instructing people what is happening and what the plan is. What do you have in place to be effective and not spread panic and confusion in an already dangerous situation?
Some call it lazy journalism, but I’m always drawn to a news story with a surprising statistic in it. So imagine my complete lack of intrigue when I heard that 52% of US enterprises consider themselves defenceless against APTs .
Tell us something we don’t know!
But thinking about it more, I couldn’t help wondering – how many large US enterprises (or EMEA enterprises for that matter) fail to meet their regulatory obligations for security compliance? My guess is zero or thereabouts – especially as regulators make it easier rather than harder to achieve these obligations.
That’s because security is too often maligned as a box-ticking, arse-covering compliance exercise where the objective is to discharge your responsibility as a corporate manager, rather than address the challenge of actually securing your organisation.
This is crazy! It’s like driving a car that’s on fire, but thinking it’s OK because you’re sticking to the speed limit!
Too many major corporations have implemented big security solutions but only utilise the tiny part of it that allows them to meet compliance demands. It’s the enterprise technology equivalent of buying a foot spa, using it once and then putting it in the attic to rot forever .
Take SIEM and its crucial role in combating APTs by collecting and interpreting massive swathes of log data into actionable intelligence on new threats . Having the solution up and operating seems to meet compliance, but actually leveraging it to its fullest extent to flag zero-day anomalies and deploy complementary anti-threat solutions is sometimes an after-thought!
Yet another reason to get involved with CARM !
IT security intelligence has had to become stealthier because cybercriminals are getting smarter at evading IT security measures . It’s like the police, who typically have a strong uniformed presence to prevent trouble in places it’s likely to occur, but also a ‘plain clothes’ presence to gather intelligence and mitigate the impact of crime at source.
If you drive the same stretch of road often enough, you can recognise the unmarked police patrol cars. At least you think you can. Years ago I’d grown accustomed to slowing down to 75mph whenever overtaking a certain green coloured BMW 5-series with two suited men in it, believing them to be traffic cops. Then one day I saw them being pulled over for speeding by the real unmarked police car (a giant Volvo with a missing hub-cap, no less)!!
Unmarked cyber patrols is a great metaphor for the Exclusive Networks CARM initiative – the subject of a 27-date roadshow right across Europe and the Middle East this spring. I first talked about CARM (Cyber Attack Remediation and Mitigation) back in November last year and ever since then this integrated solution platform, that goes right to the heart of the post-breach security opportunity, has been a runaway success.
As value added distributor for key vendors like Arbor, Bit9, FireEye, Fortinet, Impreva, Infoblox, LogRhythm, Mandiant and Palo Alto Networks, we’re seamlessly bringing their best-of-breed ingredients together into a complete, fully demonstrable end-to-end solution that enables enterprises to identify, contain, respond, remediate and mitigate the impact of security breaches.
I’m still learning that English language metaphors and sayings don’t always translate very well. For instance, the one about “shutting the stable door after the horse has bolted” as a way of describing a solution that comes too late. Every language has something equal though. In Dutch they simply say: “ Vijgen na pasen ” (Figs after Easter). But then the Dutch are very sophisticated…
However you say it – you can’t avoid the wisdom that a solution is useless if it arrives too late. I’m only interested in solutions that anticipate demand and disrupt the status quo. In fact, we want solutions that almost arrive too early! That’s where the value is for the channel; right at the peak of technology innovation.
However, I’m prepared to totally contradict myself when it comes to post-breach security.
If you accept that security breaches are unavoidable, then you must accept there will be times when the problem of keeping attacks at bay is no longer the priority. It’s like vaccinating against a virus. No vaccine is 100% effective. Hence, if the patient becomes infected, use of the vaccine stops being important and a ‘too late’ solution is urgently needed.
That’s why we believe that post-breach security will be a massive issue for European enterprises, and a huge opportunity for resellers. This group of technologies – which we describe under the banner of Cyber Attack Remediation and Mitigation, or CARM – is essential in identifying, isolating, closing down, clearing up and learning from the mess of a security breach.
So is it worth shutting the stable door after the horse has bolted? You bet it is!
Across Europe, we’ve already been working closely as value added distribution partner with FireEye, Fortinet, Palo Alto Networks, LogRhythm, Mandiant, Bit9 and Imperva to orchestrate these solutions under our CARM initiative. More details coming up in an announcement soon…
Why you need an ecosystem to fight an ecosystem December 5, 2014 - 12:27 pm
Outsourcing is not a dangerous word October 29, 2014 - 3:54 pm
All that glitters ain’t gold September 3, 2014 - 9:05 am
How good becomes bad when breaking the rules is the new normal June 26, 2014 - 12:45 pm
Why it pays to shout about your security June 19, 2014 - 2:09 pm
Exclusive Networks Group is the only international ‘SuperVAD’; focused upon growing the businesses of innovative security, networking and infrastructure technology companies.