Rants
Questions
Soapbox
Best Practices
Apply today for a FREE subscription to CIO Magazine!
Fri, Oct 10, 2008 11:28 EDT
|
Posted by: Panos in Best Practices Topic: Enterprise Management
Current Rating: |
Today, an increasing number of CIOs are embracing a new paradigm in the way they approach enterprise security. Previously, a significant amount of security resources were focused on protecting the perimeter. Now, however, a new, more dynamic and proactive approach is emerging as traditional reactive measures are no longer sufficient.
In this framework of change, CIOs must embrace an intelligence-led approach to security, one based on the premise that security occurs within a well-defined business ecosystem – employees, customers and partners - and not necessarily within an anticipated or physical perimeter. Since the business ecosystem is fragile by nature and falls outside the clearly defined lines of a network perimeter, securing it must be approached with a more offensive mindset.
What this means is that organizations need to use cyber intelligence to proactively identify and mitigate emerging threats before they can cause serious harm. Such intelligence provides CIOs with critical information regarding potential attacks to the organization and its customers, allowing the company to proactively address these threats before they reach their intended targets.
As a result of the growing sophistication of security threats and their many different attack vectors, it is imperative that a security strategy go beyond just protecting a company’s infrastructure with defensive tactics such as firewalls, intrusion prevention systems and intrusion detection technology; it must also utilize an early warning system that has high visibility into a wide range of possible and presumed attacks.
Backed by proprietary technology platforms and expert analysts that work with CIOs to identify risks and increase protection from possible attacks, these cyber intelligence solutions are vital to ensuring the security of an organization. Cyber intelligence solutions not only proactively identify threats to a company; they also provide services to thwart or stop criminals and their malicious schemes.
Cyber intelligence security initiatives are gaining momentum among leading CIOs as they are proving highly successful in protecting against cyber criminals who target specific brands and companies through phishing and malware attacks. In the absence of proactive monitoring, online criminals go undetected and undeterred from misusing a company’s brand for financial gain, putting the organization and its customers at significant risk for fraud.
How to implement this new security approach smoothly is one of the central challenges facing CIOs today. CIOs often find that they do not have the internal resources necessary to identify and monitor the online threats that can jeopardize their company’s security. CIOs need to rethink their security models and embrace an ecosystem approach that is modeled around leveraging cyber intelligence from a combination of internal resources and external cyber intelligence providers.
Each day we hear more horror stories of security breaches resulting in lost or stolen intellectual property and personal credentials. CIOs that fail to adopt security practices that rely on actionable cyber intelligence, will find themselves always one step behind the criminals.
Bio
Panos Anastassiadis is Chairman, CEO, and President of Cyveillance, a leader in cyber intelligence. He provides a thought leadership perspective on this topic to CIOs seeking to improve their company’s security posture so that their organizations can continue to thrive in today’s world economy.