Thursday, September 3, 2009

2nd APWG/NCSA Online Consumer Messaging Convention

Last week I attended the 2nd APWG/NCSA Online Consumer Messaging Convention meeting in Washington DC. Rising to an important challenge laid out by the Obama Administration, http://preview.tinyurl.com/n9jobu the Online Consumer Messaging Convention has formed a public/private partnership to craft and propagate essential online safety messages for the general public. Like the "Smokey the Bear" and "Friends Don't Let Friends Drive Drunk" campaigns, a new cyber security ad campaign will seek to create broad awareness and education among the US population about the importance of cyber security best practices.

The Coalition believes that this education is essential to secure and make safe our governmental, military, financial and banking, healthcare and other corporate IT infrastructures and use of the Internet.The Coalition includes private companies such as Microsoft, Google, Facebook, MySpace, Intuit, SAIC, Paypal, Verisign, Symantec, McAfee, ESET, RSA, Costco, Wal-mart, and association and government members such as National Cyber Security Alliance, Anti Phishing Working Group (the primary organizers of this effort), American Banking Association, US Chamber of Commerce, FTC, IRS, Department of Homeland Security and The White House.

The context of this Coalition is wholly agnostic and nonpartisan. The group is working actively to add members to raise our profile in a "big tent" approach that will ensure the Coalition's success and therefore the benefits the general public.

The first 2 working meetings have focused on group organization, establishment of a clear and concise agenda and education of Coalition members about the issues involved. This has included educational presentations about cyber security education by Carnegie Melon University http://preview.tinyurl.com/66lvtt and Palo Alto Research center http://www.parc.com/, legal advisement around legal entity and IP matters, and cause marketing by The Ad Council http://preview.tinyurl.com/dandg7

The next meeting will take place at Microsoft's offices in Seattle in early to mid November of this year.

Saturday, July 11, 2009

Unified Messaging Meeting Held in Los Angeles

I had the opportunity to be part of a very interesting meeting recently in Los Angeles. Held at the offices, of Myspace (part of the News Corp's Fox Interactive Media Group), a group of 25+ companies gathered to discuss the need for unified messaging for cyber security education.

The companies in attendance included Myspace, Facebook, Microsoft, Google, RSA, Costco, Wal-Mart, Intuit, Symantec, McAfee, Trend Micro, AVG and my company ESET. Background and educational lectures where provided by experts from Carnegie Mellon and Palo Alto Research Center.

The mission of this group was to develop an action to develop unified messaging as part of a a national umbrella awareness campaign similar to the 1970s "Give a hoot, don't pollute" http://preview.tinyurl.com/dlt9ku anti-pollution campaign and the Smokey the Bear "Only you!" http://www.smokeybear.com/ a campaign which is now 65 years old.

On May 29th, 2009, President Obama's in his "Remarks by the President on Securing our Nation's Infrastructure" http://preview.tinyurl.com/n9jobu called for a public/private partnership to develop a national campaign. I think our group is working to rise to the occassion.

The next step's for our working group is meet in August in Washington D.C. to meet with government leaders from the Department of Homeland Security and a number of other stakeholders such as the US Chamber of Commerce to enroll their support for the initiative.

Sunday, July 5, 2009

12th Annual 2009 NYS Cyber Security Conference

I particpated in excellent panel discussion on June 3-4 in Albany, New York at 12th Annual Cyber Security Conference. The event brought together top experts in cyber security (see presenter bios) http://www.cscic.state.ny.us/security/conferences/security/2009/call.cfm

The 2009 Conference was co-sponsored by the NYS Office of Cyber Security and Critical Infrastructure Coordination (CSCIC) and the University at Albany's School of Business and College of Computing and Information. CSCIC's has been leading and coordinating New York State's cyber security efforts and the University's academic excellence in information assurance combine made it a must-attend event.

The event has become New York State's premier cyber security conference, and attendance has increased five-fold since it began.

I participated with Securing The Perimeter: A Public-Private Sector Discussion on Cyber Security with a number of other panelists including:

Perry Blanchard , Albany CountyThomas Duffy , Deputy Director, NYS Office of Cyber Security and Critical Infrastructure CoordinationMatthew Eggers , Manager, National Security and Emergency Preparedness Department, U.S. Chamber of CommerceCarlos Kizzee, Director, Strategic Initiatives, Critical Infrastructure Cyber Protection and Awareness, National Cyber Security Division, U.S. Department of Homeland SecurityAlan MacQuoid , Associate, Booz Allen Hamilton

The panel discussion focused on the fact that business leaders must not overlook the importance of cyber security as a national concern and policy issue. Last year, federal prosecutors cracked one of the largest cyber crime operations ever committed. They charged nearly a dozen people from five different countries with identity theft and credit card fraud. Also, U.S. members of Congress reported that hackers gained access to Congressional office computers over a period of several months. Both incidents, and several others more recently, indicate a need for greater urgency to protect U.S. communications and information systems.

The U.S. Chamber of Commerce and the U.S. Department of Homeland Security have been visiting several cities in recent months to increase businesses' awareness of, and investments in, cyber security from an enterprise risk management perspective. The Chamber-DHS partnership allows leading experts from federal, state and local government, and industry to bring cyber security practices to the wider business community.

Through its network of state and regional partners, Chamber is coordinating grassroots outreach to business owners and operators and incorporating participation from government stakeholders. In short, the partnership aims to increase greater awareness of the potential consequences from a cyber attack, and to underscore the importance of integrating cyber security into enterprise risk management, emergency management, and business continuity planning, preparedness, and training initiatives.

Monday, June 29, 2009

Obama Grappling with the Politics of Cyber Security

Defense Secretary Robert Gates sent a memo to the Pentagon last week creating a new military command dedicated to cyber security. Gates' memo mandates that the National Security Agency (NSA) is to lead this effort, at least as it pertains to matters of national defense.

Gates' approach signals the Obama Administration’s plans to centralize and elevate cyber security as a major national-security issue. Obama was quick to point out later in the week that Gates' memo intended to set policy for military related issues only, including the use of both defensive and offensive weapons to counteract cyber threats.

This approach still leaves the matter of what the government's role in protection and hardening the public Internet will be, though it's widely known that the NSA will not be able to successfully accomplish its mission without some regulation or control of the public Internet.

Mr. Gates said that he intends "to recommend that Lt. Gen. Keith Alexander, director of the National Security Agency, take on the additional role as commander of the Cyber Command with the rank of a four-star general."

There was no comment from the Melissa Hathaway camp. Hathaway is currently the acting senior director of cyber-security for the National Security and Homeland Security Councils.

In late April Hathaway spoke about a public-private collaboration and threats to national information security at the annual 2009 RSA Conference in San Francisco. Her plans at the time were less than concrete and some speculate that there was some displeasure inside the Obama Administration about Hathaway 60-day review of the plans, programs, and activities throughout the government that address the US' communications and information infrastructure (i.e., cyberspace).

A white house blog on March 2nd stated that "the purpose of the review is to develop a strategic framework to ensure that our initiatives in this area are appropriately integrated, resourced and coordinated both within the Executive Branch and with Congress and the private sector."

The Obama Administration appears to be a bit perplexed about how to manage privacy advocates who are leery of NSA leadership in cyber security vs. the Dept. of Homeland Security which has never fully built competency to handle the many complex technical and infrastructure related issues.

Saturday, May 30, 2009

Reuters Story about ESET's "Securing Our eCity" Initative

ESET is sponsoring an important new educational campaign called Securing Our eCity. Launched initially in San Diego, this progam seeks to provide cyber security training to businesses across the nation.

You can find the full story at http://www.reuters.com/article/pressRelease/idUS203859+20-May-2009+BW20090520

An excerpt follows:

The Securing Our eCity initiative was developed as a way to educate and protectconsumers and businesses from the growing threat of cybercrime. The regionalevents will include discussions about online risk factors, including today`sfive biggest online threats, the various ways computer users can fall victim tocybercrime and real-life San Diego cybercrime case studies. Attendees will alsoreceive tips on how to stay safe online and will learn about technologies andtools that help reduce and/or prevent cybercrime.

When/Where:

* Wednesday, May 27, 2009, 12:15 - 1:15 p.m. PTSan Diego State University, Arts & Letters (AL) 101, 5500 Campanile Dr., SanDiego, Calif. 92182*

Thursday, May 28, 2009, 7:30 - 8:30 a.m. PTSan Diego State University, Geology, Math & Computer Science (GMCS) 313, 5500Campanile Dr., San Diego, Calif. 92182

* Thursday, May 28, 2009, 12:15 - 1:15 p.m. PTSan Diego State University, Geology, Math & Computer Science (GMCS) 313, 5500Campanile Dr., San Diego, Calif. 92182

* Friday, May 29, 2009, 5 - 6 p.m. PTSan Diego Chamber of Commerce, Golden Boardroom, 402 West Broadway, San Diego,Calif. 92101

* Monday, June 1, 2009, 8 - 9 a.m. PTUniversity of California, San Diego Extension Sorrento Mesa Center, Room 116,6925 Lusk Blvd., San Diego, Calif. 92121

* Tuesday, June 2, 2009, 8 - 9 a.m. PTUniversity of California, San Diego Extension Mission Valley Center, Ste. 102,404 Camino Del Rio South, San Diego, Calif. 92108

* Wednesday, June 3, 2009, 12 - 1 p.m. PTSan Diego Chamber of Commerce, Golden Boardroom, 402 West Broadway, San Diego,Calif. 92101

* Thursday, June 4, 2009 6 - 7 p.m. PTBonita Library, 4375 Bonita Rd., Bonita, Calif. 91902To register for the event, please visit www.securingourecity.org/news.php, and,to find out how you can become involved in the initiative, please visitwww.securingourecity.org.

Tuesday, May 12, 2009

I was recently interviewed as part of a cyber security expert roundtable by The San Diego Transcript. Note that I have included the entire article below as viewing at the source requires a paid subscription.

Roundtable discussion
The Daily Transcript
Panel: San Diego could become cyber security leader

By ERIN BRIDGES
Monday, May 11, 2009

San Diego could become the primary hub for cyber security, according to participants of a recent Daily Transcript roundtable.

As cyber security becomes an ever-more important aspect in daily life, local companies could establish themselves and this region as the leaders.
Benito Hobson, corporate relations manager for Integrits Corp., said he thinks the military concentration in the San Diego area makes it a good option.
“You have the military industrial complex, which has spent a lot of time, effort and energy gearing up for the cyber war,” he said. “Years ago we were saying it’s the next frontier. It’s today’s frontier. I think the uniqueness of having that level of concentration right here in such a small and lovely geographic region really helps us.”
Four areas were named as possible leaders -- Boston; Silicon Valley; the Washington, D.C. area; and San Diego.

Roundtable participants discussed the current state of cyber security and the way cyber warfare is developing and changing. They agreed it is becoming an increasingly greater threat that must be thwarted at all levels.

Some participants speculated that with the San Diego defense industry’s efforts in the realm of cyber security and cyber warfare already established, it gives the region a competitive edge.
“San Diego has a very strong core in defense, far more than Silicon Valley, which you could argue is more technical,” said Eric Basu, president of Sentek Consulting. “We also have a strong basis in health care. So I think what we need to do is take a lot of what we’re doing in defense, become the best in that and become known as the area for cyber warfare, for defending defense contractors, and then we apply that to other areas like biotech and health care as well.
“I think if we focus on that, we can target some of the stimulus funds.”
There is money in cyber security and cyber warfare right now, making it an attractive area to do business. And if San Diego can become the center for all things cyber, it will bring that funding into the area and provide a boost to the economy.

Darin Andersen, chief operating officer of ESET, said he thinks cyber security is becoming a more commonly discussed issue on many levels from top government agencies down to the average technology user. And the more it affects individuals’ lives, the more support the industry will get.“I think, because it can have a lot of economic benefit and be something that helps San Diego come out of the current economic doldrums, there’s going to be a lot of economic interest -- people at the chamber and so forth that want to get involved in that,” Andersen said.

“We should be actively competing for that cyber security mind share throughout the world.”

Thursday, May 7, 2009

ESET Sponsors Major National Cyber Security Initiative “Securing Our eCity”

“The economy may be weak, but cybercrime has never been stronger” is reason that ESET created an important cyber security initiative aimed at educating business and home users acalled Securing Our eCity. The Securing Our eCity initiative is designed to address cyber security on a global scale through educational programs, tools and technologies, and coordination with legislative and law enforcement agencies. The first phase of Securing Our eCity has already begun on a local level with a series of regional educational events organized with the U.S. Chamber of Commerce. The most recent event, entitled, “Securing the Perimeter: A Public-Private Sector Discussion on Cyber Security,” took place on April 10 at San Diego State University and brought together more than 100 technology and security experts to address the topic of cyber security.

The initiative’s website at www.securingourecity.org also includes educational resources developed by cyber security experts to help users better understand cybercrime and how to protect themselves. Available tools include educational videos, podcasts, articles and best practices guides.

In announcing the initiative nationally at RSA earlier this month, ESET’s CEO, Anton Zajac said that “As a member of the global community, ESET is dedicated to helping computer users understand and protect themselves from the growing risks associated with online activity. We believe that education starts in our own backyard, and in leading this initiative, we aim to educate and promote best practices for cyber security. We would like to help make the U.S. the world’s safest online nation.”

Securing Our eCity was created to educate computer users about online risk factors, including the various ways they could fall victim to cybercrime, and how to protect themselves. Additional objectives include:

Developing resources and funding for cybercrime prevention.
Introducing home and business computer users to technologies and tools that help reduce and or prevent cybercrime.
Develop a voice of advocacy which encourages legislative engagement at the local, state and national levels

“We are proud to live in one of America’s most wired cities,” said Ruben Barrales, president of the San Diego Chamber of Commerce. “But as we all know, with that Internet connection comes risks. We are thrilled to support ESET’s Securing Our eCity initiative, as it provides the education and advocacy needed to encourage legislative engagement around this important and topical issue.”

As the program expands, our goal will be to create elements that our business partners can use to educate their employees, business partners and customers. Stay tuned for more . . .

Monday, April 6, 2009

Experts to Discuss Threat of Massive Cyber Assault

I was recently interviewed by the San Diego Business Journal for an article on Cybersecurity:

By BRAD GRAVES
San Diego Business Journal Staff
It’s more than just protecting your personal computer from a rampaging software worm.
Cybersecurity — as it relates to personal security and national security — will be the topic on the table at a panel discussion April 10 at San Diego State University.
An assault on the nation’s computer networks could be "the next way that the bad guys are going to get at us," said Darin Andersen, chief operating officer of ESET, a San Diego maker of anti-virus software.

Click here to read the rest of the article.

Tuesday, December 2, 2008

Malware Numbers Prove Cybercrime on the Rise

The lastest numbers support growing awareness that cybercrime is on the rise. We have just learned that the US economy has officially fell into recession in late 2007. This means that recession is already 4 quarters old. It is well known that cybercrime tends to rise during recessionary times as more people turn to a less than honest means to make a living.

A recent online study supports the growth of malware and cybercrime. Microsoft Windows users face an unprecedented number of virus and othe malware threats from a widening variety of sources. New virus and spyware programs are appearing at an alarming rate. In September 2008, Kaspersky Lab reported that the number of virus, adware, Trojan, and other malicious programs tripled during the first six months of 2008 versus the previous six months. In all, the lab’s statistics indicate that some 440,311 new malware programs appeared from January through June, compared to just 136,953 for the preceding six months.

Malware programs continue to mutate; many take advantage of social networking sites, which make it easier to distribute infections via simple e-mail messages supposedly sent by trusted friends. From dangerous rootkits to continually evolving viruses and spyware, Windows users require an anti-malware application that provides effective protection without robbing a system of its computing capacity. Of course, no single program or application is capable of completely protecting a Windows user from all threats, but some applications are better than others.

Private and public entities will need to begin pooling resources to stave off this growing threat. Nearly 10% of all retail purchases are made online. This represents billions of dollars worth of e-Commerce which may be threatened if people begin to distrust online shoppoing and buying.