Tuesday, 1 December 2015

5 factors driving growth in the UK cyber security industry

The UK cyber security industry is developing, with money and talent helping it grow. Here are five reasons things in the sector are looking positive.

Government funding

As part of his recent Spending Review, Chancellor George Osborne pledged to put £1.9bn into cyber security. Of critical importance to the UK industry was £165m of these will go toward establishing a Defence and Cyber Innovation fund, a considerable boosts to the country’s cyber security start-ups.

Clusters bringing in talent

The UK is getting good at developing, and funding, tech clusters – areas where a variety of similar firms can be based, sharing knowledge and resources. It’s not just London’s Silicon Roundabout either. Europe’s largest technology cluster is in Cambridge, and there are also clusters in Bristol, Bath, and Malvern Hills. This help attracts talent and corporates to areas where firms are based.

Incubators

Incubators provide start-ups with the time and space to develop their products. They can also play a vital role in connecting this burgeoning firms with mentors, or advisors to sit on their board. Examples include Cyber London, and SetSquared in Bristol. For the full article click here 



from cyber security caucus http://ift.tt/1NkhFHQ
via IFTTT

Cybersecurity Bills Would Add Secrecy to Public Records Laws

WASHINGTON: A proposed law meant to encourage companies to share information about cyberthreats with the U.S. government includes measures that could significantly limit what details, if any, the public can review about the program through federal and state public records laws.

The legislation — already passed in both houses of Congress but not yet finalized — would keep secret any information a company hands over to the Obama administration under a new cybersecurity agreement, including specifics the firms decide themselves shouldn’t be disclosed. It’s not clear whether that secrecy would extend to learning whether particular companies are even participating.

The cyberagreement passed with bipartisan support, despite privacy concerns over Senate language from some lawmakers and technology companies, including Apple Inc. and Dropbox Inc. It’s the culmination of a roughly six-year effort made possible by recent additions of antitrust and consumer-liability protections for the companies’ participation. For the full article click here 



from cyber security caucus http://ift.tt/1NkhGLW
via IFTTT

Fixing Australia’s “backward” national cybersecurity posture requires “fresh thinking” on skills, resources: ACSC

The process of developing a national cybersecurity capability requires a complete overhaul of technology and R&D processes that will take 10 to 20 years to complete, according to a government-security academic who warns that it will be “problematic” if Australia fails to retain a leadership role in the fast-evolving transformation.

Australia has always been “a little bit backward” in general ICT posture and military planning around cybersecurity, Dr Greg Austin, a visiting professor at the UNSW-ADFA joint venture Australian Centre for Cyber Security (ACSC), told CSO Australia in the wake of a recent conference exploring forward requirements for Australia’s cybersecurity capability.

Improving that capability would require the kind of candid public discussions that the government had historically shied away from in the name of security, Austin said, noting “reluctance in the highest levels to embrace these ideals publicly.”

Growing concern over cybersecurity – and an ever-growing hit list of successfully hacked organisations – had increasingly led to demand for “a clear public strategy from the government”, Austin said, so that the academic and research community “can do all that we have to in terms of public research, mobilising the industry, and mobilising the population in terms of having people knowing what we’re doing and training up for it.” For the full article click here 



from cyber security caucus http://ift.tt/1Xu6hUL
via IFTTT

China, US to hold high-level talks on hacking, cybersecurity

Top US and Chinese officials will convene this week in Washington for the first round of cybersecurity talks following the signing of an anti-hacking accord in September.

China’s Public Security Minister Guo Shengkun is in Washington until Sunday and will meet US Secretary of Homeland Security Jeh Johnson, Chinese state media reported. US Attorney General Loretta Lynch is also expected to take part in the discussions.

The talks on Tuesday and Wednesday are seen as potentially significant in establishing acceptable norms for cyber espionage. It also marks an ongoing effort to repair relations after China withdrew from a working group last year in response to the US indictment of five members of its military on charges it hacked six American companies. For the full article click here 



from cyber security caucus http://ift.tt/1Xu6hEt
via IFTTT

Monday, 30 November 2015

How to improve international cyber-security

THE VAST stores of digital information generated by everyday lives—communications data, CCTV footage, credit-card records and much more—are now yielding invaluable clues about the terrorist attacks in Paris and are helping guide the hunt for the surviving plotters. But prevention is better than cure. The attacks have highlighted the failure of the authorities to share information across borders and agencies. How can this be improved?

Each government sets different rules for what data may be looked at, by whom and with what authority. This is partly due to politics (Belgium has numerous squabbling police forces); and partly because of legal restrictions—the European Parliament takes privacy extremely seriously, as does the German government. Many Europeans fear that any data shared with America will be snooped on by spy agencies. The attacks also reignited a long-running debate about encryption—encoding messages such as e-mails, in ways that even government intelligence agencies cannot break (it is easy to make a code, even with an ordinary computer, and much harder to break it). There is no proof, however, that the Paris attackers used encrypted communications. They seem to have mostly communicated by sending innocuous-seeming messages over regular mobile phones. Banning encryption, or forcing companies to weaken the services that they provide, would be ineffective: there are plenty of free encrypted-messaging services available. It would also be misguided: for security against the huge wave of cybercrime now afflicting individuals, businesses and governments, we should be using more and better encryption, not less and worse. For the full article click here 



from cyber security caucus http://ift.tt/1lTHpox
via IFTTT

A third of Singapore firms lack confidence in their ability to detect cyber attacks: survey

SINGAPORE – At least a third of Singapore organisations lack confidence in their ability to detect cyber attacks, going by a recent survey on Monday.

This is in line with the global figure, which stands at 36 per cent.

The annual survey, conducted by financial services consulting firm EY, also found that a large 56 per cent of the Singapore respondent believe their IT security budgets should be increased by up to 50 per cent to align their organisation’s need for protection with its management tolerance for risk. For the full article click here 



from cyber security caucus http://ift.tt/1OzhrQB
via IFTTT

Data breach at Hong Kong toy maker VTech highlights broader problems

The theft of toy maker VTech Holdings Ltd’s database highlights a growing problem with basic cyber security measures at small, non-financial companies that handle electronic customer data, industry watchers said on Monday.

The hacked data at VTech included information about customers who download children’s games, books and other educational content, the Hong Kong-based toy maker said. The breach also included information relating to children.

As more devices are connected to the Internet and as companies increasingly collect personal information about their customers, such attacks are expected to increase.

“Smaller companies might be targeted less often, but the implications … can be just as serious,” said the chief technology officer of cyber security firm FireEye Bryce Boland. “As larger companies implement stronger security measures, smaller companies become relatively easy targets for cyber crime.” For the full article click here 



from cyber security caucus http://ift.tt/1NDhM7R
via IFTTT