Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Value Of An Open Approach When Defending Against Attacks
Articles

The Value Of An Open Approach When Defending Against Attacks

ISBuzz TeamBy ISBuzz TeamSeptember 15, 20175 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The latest HBO hack and leaked episodes of Game of Thrones shone a spotlight on the need for protecting proprietary data. For every new encryption or password management point solution enterprises put in place, there are likely hundreds of hackers figuring out a way to compromise those security countermeasures. Enterprises need to rethink their strategies to stay one step ahead; otherwise, they are just going to experience breaches over and over again.

Ankur Laroia, Solutions Strategy Leader, Alfresco Software, speaks to Information Security Buzz about how businesses can implement open, transparent processes and change their way of thinking to help protect against cyberattacks.

  • What does the latest HBO hack reveal about data security?

The HBO hack highlights that every industry is susceptible to a cyberattack, even entertainment, with sometimes devastating consequences to reputation and finances. It also underscores the vulnerabilities associated with the inevitable proliferation of digital data and – when left ungoverned – the exposure sustained by enterprises. Studies have shown the next year represents a turning point in the digitisation of enterprise content. In fact, Alfresco recently commissioned a Forrester study that found the number of firms with virtually all digital content will shift from 14 percent today, to 50 percent in just two years. It also showed that 67 percent of end users have to reference external content every time they onboard new customers or partners, address customer service requests, or manage financial or accounting processes. This scattered content, whether it’s saved in Dropbox vs. on-premises, or some other non-integrated solution, poses a major security risk to enterprises.

  • While this was “just” an entertainment hack, are you aware of other industries, such as insurance, accounting and medical, being proactive in preventing the same from happening?

The theft and/or compromising of vital information is becoming a fairly common phenomenon. This tends to be a two pronged issue; there are threats from outside the company and there are also rogue actors lurking within the organisation’s firewalls. Companies that store PII (personally identifiable information) such as financial institutions, as well as those that deal with patient data (hospitals, labs, health insurance companies) find themselves especially susceptible to attacks. Equifax is a great example of a very recent hack that leveraged a Zero-Day Exploit attack vector to compromise the PII of 143 million people, some of them citizens of the EU. Equifax like most large corporations have hardened their perimeter and put in infrastructure centric measures to thwart hackers from the outside. But to date, little has been done to address the internal environment to effectively inventory, secure, manage and dispose of data/information in the enterprise. Management of data, using an open source platform such as Alfresco’s digital business platform will help to reinforce security defence measures.

  • Do the ways companies protect their data change if they have employees working all around the world?

We live in a global economy and the threats are both exponential and global. With the advent of outsourcing and offshoring, data theft/data compromise are existing risks that organisations must mitigate against. The challenges they face relate to the increasing amount of data,  its volume, variety and velocity, which proliferate across systems and span the globe. Companies must adopt good information management practices along with modern technologies and platforms to effectively thwart bad actors.

  • Are data breaches the “new normal” for companies?

Data breaches will happen. Most CSOs or CISOs have resigned themselves to the fact that their ecosystems will be penetrated at some point in time. This means that they should have a renewed focus on minimising the exposure, especially of sensitive information and limiting the surface area vulnerable to attack.

  • Are hackers getting more sophisticated? Or are companies just not keeping up with cybersecurity?

Hackers are only getting more sophisticated and organised. There are nation states that have “elite, militarised hacking units” that constantly look for vulnerabilities in closed, black box software, where the code is available for perhaps a few divisions of developers to review. The hacking methodologies as well as techniques and tooling are growing ever more complex and this represents a challenge for companies to evolve their own defences.

  • What are the three questions any company should be able to answer about its data security?

Whenever a company examines their own data security defences, they should be able to answer yes to these questions:

  • Do we effectively inventory our most vital/precious/sensitive information?
  • Are we effectively securing it?
  • Do we have consistent protocols that are followed and updated policies that are in place to ensure effective governance/data lifecycle management of these assets?

If they answer no, then it is imperative that they perform an in depth assessment and audit of their security practices. Failure to do so leaves them more vulnerable to attack.

  • What is the biggest issue companies will have to watch out for on the security front over the next year?

In the next year, we will see the further evolution of cyber threats. Hacks like the ones we’ve seen this year and last (e.g. Dropbox, Yahoo, HBO and the NHS), where a handful of vulnerable servers were compromised and then used to take down and steal information will become more common. Those attacks were meticulously planned, well-orchestrated and impeccably executed. That level of diligence on the part of the black hat community will only continue to grow.

  • Where do you see the technology in 3-5 years in regard to preventing security breaches?

The approach to cybersecurity must be multi-layered. Processes within an enterprise should serve to underscore and bolster perimeter defences, as well as gather intelligence about external threats. For this reason, I predict that there will be a greater emphasis on business processes/protocols that help govern information through its lifecycle, coupled with investment in modern platforms such as Alfresco’s to inventory, curate, secure, archive and manage information effectively.

[su_box title=”About Ankur Laroia” style=”noise” box_color=”#336588″][short_info id=’103383′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}