Friday, 1 May 2015

State Higher Ed board taps cyber security expert, Navy professor to lead university system

BISMARCK, North Dakota — The State Board of Higher Education selected Mark Hagerott as the next chancellor of the North Dakota University System on Thursday.

The board unanimously tapped Hagerott to replace Interim Chancellor Larry Skogen, whose term ends in July.

The announcement concluded a monthslong process that saw more than 20 candidates vying for the position, including one of the system’s former chancellors. Hagerott beat out finalists Paul Turman and Robert Donley for the top spot.

Hagerott is a Mandan native and Rhodes scholar who became a leading cybersecurity expert and professor with the Navy. He has held several academic leadership positions over the past seven years at the Naval Academy in Annapolis, Maryland, where he currently serves as the senior civilian and deputy director of the new Center for Cyber Security Studies.

“I am honored to be here and to be your chancellor choice from a field of very qualified candidates,” Hagerott said in a statement. “You have a great system framework and I thank you for putting your faith in me and allowing me the opportunity to take the system forward into the future.”

Hagerott will formally take over on July 1. His contract includes a salary of $372,000 per year, standard benefits package and $15,000 in moving expenses.

Skogen has served as interim chancellor since June 2013, when he took over for Hamid Shirvani following complaints about Shirvani’s leadership style. Skogen will return to his duties as president of Bismarck State College when his term ends.

Source: http://ift.tt/1AqtPJW



from cyber security caucus http://ift.tt/1OMxdL6
via IFTTT

Social media & cybersecurity

This week on “Fed Access”, host Derrick Dortch interview Chris Cullison, chief technology officer, and C.W. Walker, cyber defense analyst at ZeroFox.

They will talk about the changing cybersecurity landscape and how it is being impacted by social media.

Cullison and Walker will discuss how the Islamic State and other terrorist groups, for example, are using Twitter, Youtube, and Instagram to spread propaganda and recruit new members.

They say outside groups are using some of the same tactics to get involved in the protests and riots in Baltimore.

Cullison and Walker will also talk about how hackers are creating fake Facebook and LinkedIn profiles to breach the security networks at private companies and government agencies.

Finally, they will discuss what you can do to protect your business or agency from a cyber attack, and will explain how ZeroFOX can help you in that effort.

Source: http://ift.tt/1OKhUma



from cyber security caucus http://ift.tt/1DPDT0v
via IFTTT

GAO: Comprehensive Cybersecurity Approach Needed for NextGen Transition

The FAA faces cybersecurity challenges protecting air-traffic control information systems, protecting aircraft avionics used to operate and guide aircraft, and clarifying cybersecurity roles and responsibilities among multiple FAA offices, and it needs a more comprehensive approach to cybersecurity as it transitions to the NextGen transportation system, GAO has said.

The agency will continue to be challenged in protecting ATC systems because it has not developed a cybersecurity threat model, according to GAO-15-370.

It said that while the FAA has taken some steps toward developing such a model, it has no plans to produce one and has not assessed the funding or time that would be needed to do so.

The FAA has begun to clarify cybersecurity roles and responsibilities among multiple FAA offices, such as creating a Cyber Security Steering Committee to oversee information security, but GAO recommended that the Office of Safety – AVS, be made a full committee member instead of included only on an ad hoc basis.

GAO also said the Surveillance and Broadcast Services Subsystem – which enables satellite guidance of aircraft and is currently deployed in parts of the nation – needs to adopt all April 2013 changes to NIST security controls, such as intrusion detection improvements.

The FAA generally agreed with the recommendations but maintains AVS is sufficiently involved in cybersecurity.

Source: http://ift.tt/1Q7TKiN



from cyber security caucus http://ift.tt/1I3bieH
via IFTTT

Above Security / Seccuris Giving Cybersecurity Presentations at Several North American Conferences in May and June

In February, Above Security, a global IT security service provider, acquired Seccuris, a security consulting and managed services firm. Together, the two companies have considerably extended their service offerings to help clients safeguard themselves against the ever-evolving cyber risks and threats they face today. As part of their push to help the business community, Above Security and Seccuris will be giving educational presentations at several conferences in Canada and the United States during May and June.

Below is a list of the conferences, speakers and topics:

  • Western Canada Information Security Conference (May 5) / Winnipeg, Man. Canada

Speakers: Ivo Wiens / “Identifying Threat Management Requirements”
Oleksiy Vasylyuk / “Lack of security in process automation or how to own an automated system”
URL: wcisc.ca

  • Saskatchewan Connections (May 5-6) / Regina, Sask. Canada

Speaker: Ivo Wiens / “Identifying Threat Management Requirements”
URL: skconnections.ca

  • iTech Conference (May 12) / Ottawa, Ont. Canada

Speaker: Jefferson Dance / “Lost and Found: The New Landscape of Data Breaches”
URL: http://ift.tt/1c2R6MP

  • Secure360 Conference (May 12-13) / Saint Paul, Minn. USA

Speaker: Patrick Hayes / “Building A Business-Driven Security Program”
URL: secure360.org

  • Toronto Tech-Security Conference (May 14) / Toronto. Ont. Canada

Speaker: Jefferson Dance / “Lost and Found: The New Landscape of Data Breaches”
URL: http://ift.tt/1GCz1N6

  • iTech Conference (May 14) / Toronto. Ont. Canada

Speaker: Jefferson Dance / “Lost and Found: The New Landscape of Data Breaches”
URL: http://ift.tt/1c2R6MT

  • Ontario Connections (May 20-22) / Toronto. Ont. Canada

Speaker: Ivo Wiens / “Identifying Threat Management Requirements”
URL: ontarioconnections.ca

  • HIMSS-Minnesota Sprint Conference (May 21) / Bloomington, Minn. USA

Speaker: Jefferson Dance / “Lost and Found: The New Landscape of Data Breaches”
URL: mn.himsschapter.org

  • Total Security Summit (June 1-2) / Houston, Tex. USA

Speaker: Patrick Hayes / “Trust Modeling for Cloud Outsourcing”
URL: http://ift.tt/1GCz1N8

  • SC Congress (June 10-11) / Toronto. Ont. Canada

Speaker: Ivo Wiens / Panel on “Protecting Customer Information – When Threats Come From The Inside”
URL: http://ift.tt/1c2R6MV

  • ISSA-Minnesota Chapter Meeting (June 16) / Minneapolis, Minn. USA

Speaker: Ivo Wiens / “Identifying Threat Management Requirements”
URL: mn.issa.org

  • Tech-Security Conference (June 18) / Calgary, Alb. Canada

Speaker: Ivo Wiens / “Identifying Threat Management Requirements”
URL: http://ift.tt/1GCyZot

To attend these conferences and presentations, please visit the individual URLs listed above for registration information.

ABOUT ABOVE SECURITY

Founded in 1999, Above Security is a Global IT Security Service Provider who builds and delivers customized services for monitoring and protecting the most critical and sensitive IT assets in our clients’ infrastructures 24/7. Their mission is to harness the full potential of connecting people and businesses together to build trust relationships that can be the catalyst of worry-free collaboration and limitless innovation. Above Security caters to small and medium size businesses as well as Fortune 500 companies in important, highly-regulated industries – such as financial services and government – where the need to process or store considerable quantities of confidential data is paramount. From its four Security Operations Centers (SOCs) in Canada, Mexico and Switzerland, Above Security has accumulated experience guarding the systems of over 250 private and government-owned organizations in over 45 countries around the world. For more, please visit abovesecurity.com.

ABOUT SECCURIS

Since 1999, Seccuris, a subsidiary of Above Security, has been helping clients with business-driven security solutions through consulting, risk management, and managed security services. Seccuris is the unique alternative because it assesses each client’s security needs in relation to their entire enterprise, not just their technology, and then tailors a program that will help them make effective risk-based decisions at every level. Seccuris helps protect companies when and where they need it most. To learn more, visit seccuris.com.

For the original version on PRWeb visit: http://ift.tt/1GCyZov



from cyber security caucus http://ift.tt/1c2R6N1
via IFTTT

Cybersecurity now high on the risk list for global companies: survey

Concerns over cybersecurity and hacking have become a top 10 risk for businesses, according to an annual survey of global companies and managers.

The 2015 Global Risk Management Survey, released this week by risk management and insurance firm Aon, queried more than 1,400 respondents at public and private companies around the world, with cyber risk emerging as a major concern for the first time, along with damage to brand and reputation.

“The connection between these two risks has been felt around the world in 2014, as a rash of data breaches demonstrated the fragile nature of consumer trust in leading corporations,” said Greg Case, president and chief executive of Aon.

“Damage to reputation/brand” was ranked the most formidable risk faced by respondents’ companies, ahead of “economic slowdown/slow recovery” or “regulatory/legislative changes”. Concerns about “computer crime/hacking” were also prevalent.

“The high profile cyber attacks in the news only represent the tip of the iceberg,” the report said.

“Every company that has a website or smart phones has global exposure to such risks.”

Respondents’ concerns are not without reason. According to PricewaterhouseCoopers, the number of detected cyber attacks rose 48 per cent in 2014, compared to the year before. This rise is expected to continue in 2015, with more than 100,000 attacks taking place every day.

The Centre for Strategic and International Studies, a Washington-based think tank, estimates that the annual cost of cyber crime and economic espionage to the world economy could be as high as US$445 billion, or one per cent of global income.

Last month, US president Barack Obama signed an executive order declaring a national emergency due to the threat posed by cyber attacks.

The order empowered the US Treasury to use financial sanctions against foreign actors who threaten critical infrastructure, seek to steal financial data or trade secrets, or launch denial-of-service attacks.

Obama said that he found “the increasing prevalence and severity of malicious cyber-enabled activities originating from, or directed by persons located, in whole or in substantial part, outside the United States constitute an unusual and extraordinary threat to the national security, foreign policy, and economy of the United States.”

Source: http://ift.tt/1JdjGW7



from cyber security caucus http://ift.tt/1c2GEVN
via IFTTT

China Condemns US Cybersecurity Strategy Against Beijing

The Chinese government has expressed its concerns regarding Washington’s threats of using cyber-weapons. The Chinese defense ministry expressed its concern Thursday regarding the Pentagon’s latest cyber-security strategy. The document accuses China of launching massive cyber-attacks, a claim Beijing has repeatedly denied. Furthermore, it stresses the United States’ ability to retaliate with cyber-weapons, a measure which the Chinese consider will only increase tensions. “This will further exacerbate contradictions and up the ante on the internet arms race. We are concerned and worried about this,” said defense ministry spokesman Geng Yansheng. Geng pointed at the hypocrisy of the U.S. singling out China, given the revelation in recent years of the National Security Agency’s (NSA) global espionage program codenamed Prism. RELATED: China Dismisses ‘Groundless’ Cyber-Theft Claims The defense ministry also raised concerns about recent drills between the U.S. and the Philippines in the South China Sea, a strategic waterway which is 90 percent claimed by China. Regarding the drills, Geng the question of who is really threatening security and stability in the region, clearly hinting at Washington’s involvement. According to the Center for Strategic and International Studies, criminal activity online is estimated to cost the United States about US$100 billion annually. Last week the Pentagon unveiled a updated version of the U.S. online security policy. The document named China, Russia, North Korea and Iran as potential sources of threats to US cyber-security, and accused the Chinese government of spying U.S. companies.

This content was originally published by teleSUR at the following address:http://ift.tt/1zizTJg.



from cyber security caucus http://ift.tt/1JepvCJ
via IFTTT

Changes Are Afoot for the C-suite/IT Perception Gap

When it comes to corporate executives’ view of cybersecurity risks, and their confidence and preparedness in the event of a security breach, it’s well-known that a gap has persisted between perception and reality. Security staff assessments of cyber-postures have until now tended to diverge rather significantly from that of those in the C-suite (who are traditionally more optimistic), indicating a need for more communication across departments.

A study from Dimensional Research on improving the cybersecurity literacy of Fortune 500 boards and executives found that this is beginning to change. In fact, C-level executives were found to be less confident (68%) than non C-level executives (80%) that cybersecurity briefings adequately convey the urgency and intensity of the cyber-threats targeting their organizations.

They were even less confident than IT executives (78% respectively) in the accuracy of the tools their organization uses to present cybersecurity risks to the board.

Further, as a testimonial to the growing awareness of the seriousness of the cyber-attack landscape, 100% of C-level executives and 84% of non C-level executives in the survey said that they consider themselves “cybersecurity literate.”

“The lower level of confidence on the part of C-level executives reflects a change in the way that executives handle cybersecurity risks,” said Dwayne Melancon, CTO for Tripwire, which sponsored the survey. “The good news is that this study signals that conversations are beginning to happen at all levels of the organization. This is a critical step in changing the culture of business to better manage the ongoing and rapid changes in cybersecurity risks.”

While the results indicate an increased preparedness on the part of IT professionals, they also expose the uncertainty at the C-level and point toward the need to increase literacy in cybersecurity and its attendant risks in the near-term. Competitive pressures to deploy cost-effective business technologies may affect resource investment calculations for security; these competing business pressures mean that conscientious and comprehensive oversight of cybersecurity risk at the board level is essential.

“The reality is that an extremely secure business may not operate as well as an extremely innovative business,” Melancon said. “This means executives and boards have to collaborate on an acceptable risk threshold that may need adjustment as the business grows and changes.”

The lack of confidence also comes, in large part, from the networking and informal benchmarking that takes place among C-level executives at the peer level.

“There is a lot of ‘comparing notes’ that happens between C-level peers,” Melancon said. “When this happens, you are able to get a more informed view of where you are in your overall cyber-risk preparedness. This is in direct contrast to IT professionals, who generally have a more insulated view of their own cyber-risk, which can lead to a false sense of security.”

Source: http://ift.tt/1Jdidz4



from cyber security caucus http://ift.tt/1c2nbnZ
via IFTTT