This week, the White house is hosting the third International Counter Ransomware Initiative (CRI) summit bringing together 48 countries, the EU and Interpol to discuss several new initiatives including a pledge from member states not to pay ransoms.
The CRI will begin using a new information sharing platform enabling member countries to easily exchange details of threat indicators so “if one country is attacked, others can quickly be defended against that.” Officials hope to establish “collective threat information to enable countries to better and more effectively defend themselves.”
Also, debuted is a new project leveraging AI to analyze blockchain as a way of identifying illicit funds used to pay ransomware demands. CRI will also share a “blacklist of wallets” through the U.S. Department of Treasury to track where illicit funds are flowing so officials can “alert their virtual assets service providers to block or freeze those transactions.”
Also, the CRI will offer “innovative mentorship and tactical training” programs for newer members, citing how Israel has coached Jordan on countering ransomware as one example.
Stephen Gates, Principal Security SME, Horizon3.ai had this comment:
“Not paying criminals the ransoms they demand and following the money trail is an honorable initiative to undertake. However, non-government organizations like financial services, higher education, healthcare, manufacturing, retail, gaming, and many others have been forced to pay ransoms so they could get their operations back up and running. Their livelihoods have been at stake. The impact on commercial organizations not paying their ransoms may end up being worse than the alternative.
“Therefore, a paradigm shift in the mindset of all organizations needs to happen. That shift includes augmenting their completely defensive security approach with an offensive approach designed to actually find where they are most vulnerable to human-operated ransom-based attacks and fixing those issues before they fall victim. This preemptive security approach, using specifically designed autonomous systems, can majorly reduce the likelihood of falling victim to a targeted attack.
“The first step to using these autonomous systems is assuming your defenses have already been breached. Once that happens, these systems will help you find, fix, and verify that your exploitable vulnerabilities are drastically reduced. This is not a one-and-done thing performed on an annual basis. Instead, it becomes part of your everyday, good cyber-hygiene due diligence.”
Any effort to disrupt the flow of money to ransomware gangs is a good thing. So is co-ordinating with allies on that. Hopefully this effort bears some fruit and put these gangs out of business.
Cyber Skills Gap Climbs To 4 Million…. Yikes!
Posted in Commentary with tags Security on November 1, 2023 by itnerdAccording to the ISC2 2023 Cybersecurity Workforce Study released this week, the global cybersecurity workforce gap has increased by 12.6% since 2022 reaching four million people.
Despite an 8.7% increase in the global cybersecurity workforce compared with 2022, reaching 5.5 million professionals, of professionals surveyed, 92% said they had skills gaps in their organization and 67% reported a shortage staff needed to prevent and troubleshoot security issues.
47% of respondents said they had experienced cyber-related cutbacks in the past year, including layoffs, budget cuts and hiring or promotion freezes, and, of that group, 22% were impacted by layoffs, both first- and second-hand.
Furthermore, 47% of respondents admitted they have no or minimal knowledge of AI and risks associated while AI and emerging technologies was cited as the biggest challenge facing cybersecurity professionals over the next two years (45%), followed by worker/skill shortages (43%).
Encouragingly, 52% of cyber professionals said their organizations are encouraging the use of AI internally and that advancements in AI is the third most positive impact on their ability to secure their organization, behind zero trust (34%) and automation (40%).
Dave Ratner, CEO, HYAS:
“The combination of the cybersecurity skills gap, overall personnel shortage, and rising and increasingly sophisticated attacks is a perfect storm for bad actors and nefarious activity. Without solutions like Protective DNS to automatically pinpoint and identify anomalous activities, organizations are increasingly at risk for exploitation, and are one of the only ways to confidently address the growing storm.”
This skills gap is a threat to us all as it gives more opportunities for threat actors do all sorts of evil things. Everyone needs to address this or we’ll be in all sorts of trouble that there will be difficult to exit from.
Leave a comment »