IT security professionals ‘secure society’

SMART Cybersecurity Handbook 2022 Training & Education

The role of information security professionals has become a critical one as the world enters the second phase of the Internet revolution in which computers run everything and everything is connected.

This emerged at the inaugural KB4-CON cybersecurity event for EMEA, where Mikko Hyppönen, chief research officer at F-Secure and a worldwide authority on computer security and privacy issues, outlined the impact of the Internet and changing cybersecurity risks.

Hyppönen said: “We are the first generation to live our lives partially in the real world and partially in the online world and now we see that the Internet will be part of mankind’s future forever.”

The first wave of the Internet revolution – which took all the computers online – is already behind us, he said. “We are now living the second wave of the Internet revolution, which will take everything else online. I’m not just speaking about IoT or smart devices, I’m speaking about everything. If we plug it into the electricity grid, we will also eventually plug it into the Internet grid. It’s going to happen whether we like it or not. This second wave will bring us great benefits and great new risks: it’s always a trade-off.”

Hyppönen highlighted how lucrative ransomware attacks are for criminals, noting that business email compromise is even more so. “The amount of money moving around in these ransomware attacks is remarkable, there is a lot of money to be made in online crime. But even more money is being made with business email compromise (BEC) attacks. They always say crime doesn’t pay, but it obviously pays very well if criminals are driving around in a fleet of Rolls Royces.”

In this environment, the role of the information security professional has changed, he said. “We are no longer securing computers: we are securing society, because computers are everywhere and run everything.”

Complexity is the enemy of security

Hyppönen said: “Complexity is the biggest enemy of security. The more complex our systems are, the harder they are to secure. The more complex they are to use, the easier it is for people to make mistakes. The more complex the systems our users are using, the more prone they are to human error.”

While the solution to this should be to reduce complexity, systems were becoming more complex. “If you look at the size of Windows 10 on your hard drive, it is 1000 times bigger than Windows 95. If you look at the complexity of the code base, Windows 10 has 5,7 million source code files. So, we are just shooting ourselves in the foot as we build more and more complex systems which have more room for bugs, which then become vulnerabilities and which are more complex to use, which means our users are more prone to make human errors and mistakes. But we must not blame the users.”

Data is the new uranium

Pointing to changing attack methods, Hyppönen said: “People say data is the new oil, but it is more like the new uranium. Like oil, it is also expensive, but it is also very damaging and some data – like medical data – stays dangerous forever when it is compromised. I don’t think we fully understood the challenge of this.

“We see a big shift from traditional V1 ransomware groups into ransomware V2. In January 2020, the Maze ransomware gang from Moscow innovated V2 by not only encrypting the files of the victim company, but also stealing the files and threatening to leak the stolen files if the ransom was not paid. This means that suddenly the backups don’t matter at all. Even if you have perfect backups of everything and you can recover them in an hour, the attackers still have your files and they can leak them. This is the reason we have seen so many multi-million-dollar ransom payments – V2 ransomware has proven to be highly beneficial for the attacker.

“If we track down the root causes of any data breach, leak or malware, it’s always a technical problem or a human problem. Technical problems can be hard to solve, but once you find and fix the bug, you have solved the problem. However, patching human brains isn’t straightforward at all. You need to educate users and make sure people remember what they are taught and whenever we teach users what to look out for, the attackers will look for new ways of going around what they have learned.”

Boost user training and awareness

Stu Sjouwerman, founder and CEO of KnowBe4, announced during the event that KnowBe4 sponsored a new vendor-neutral certification by H Layer Credentialing, the Security Awareness and Culture Professional (SACP) certification for security awareness programmes.

KnowBe4 has also launched a set of 24 mobile-first training modules and its Security Snapshots (a set of 12 stand-alone security ‘micro modules’ in 34 languages, which may be particularly interesting to organisations on the continent where many users consume training on their mobile devices).




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Value and industry insight
Securex South Africa Training & Education News & Events
Securex South Africa 2025, co-located with A-OSH EXPO, Facilities Management Expo, and Firexpo, drew thousands of security professionals from across the continent and beyond, offering a platform for networking, product discovery, and knowledge sharing.

Read more...
Gallagher Security achieves ISO 27001 recertification
News & Events Training & Education
Gallagher Security has successfully achieved certification to the updated ISO/IEC 27001:2022 standard for Information Security Management Systems (ISMS). This accomplishment builds on previous certifications and reflects a continued commitment to the highest standards of information security.

Read more...
A new generational framework
Editor's Choice Training & Education
Beyond Generation X, and Millennials, Dr Chris Blair discusses the seven decades of technological evolution and the generations they defined, from the 1960’s Mainframe Cohort, to the 2020’s AI Navigators.

Read more...
Key design considerations for a control room
Leaderware Editor's Choice Surveillance Training & Education
If you are designing or upgrading a control room, or even reviewing or auditing an existing control room, there are a number of design factors that one would need to consider.

Read more...
The deepfake crisis is here and now
Information Security Training & Education
Deepfakes are a growing cybersecurity threat that blur the line between reality and fiction. These AI-generated synthetic media have evolved from technological curiosities to sophisticated weapons of digital deception, costing companies upwards of $600 000 each.

Read more...
CCTV control room operator job description
Leaderware Editor's Choice Surveillance Training & Education
Control room operators are still critical components of security operations and will remain so for the foreseeable future, despite the advances of AI, which serves as a vital enhancement to the human operator.

Read more...
Strong industry ties set Securex South Africa apart
News & Events Training & Education
Securex South Africa, co-located with A-OSH EXPO, Facilities Management Expo, and Firexpo, is a meeting place of minds, where leading security, safety, fire, and facilities professionals come together, backed by strong ties with the industry’s most influential bodies.

Read more...
Gallagher Security expands Digital Badge Programme
News & Events Access Control & Identity Management Training & Education
Following a successful launch and roll out across Australia and Papua New Guinea in 2023, Gallagher announced its Digital Badge programme is now available to channel partners and end users across the rest of APAC IMEA.

Read more...
The need for integrated control room displays
Leaderware Editor's Choice Surveillance Training & Education
Display walls provide a coordinated perspective that facilitates the ongoing feel for situations, assists in the coordination of resources to deal with the situation, and facilitates follow up by response personnel.

Read more...
The need for integrated control room displays
Editor's Choice Surveillance Training & Education
Display walls provide a coordinated perspective that facilitates the ongoing feel for situations, assists in the coordination of resources to deal with the situation, and facilitates follow up by response personnel.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.