Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Managing Distrust: The Key To Cybersecurity
Articles

Managing Distrust: The Key To Cybersecurity

ISBuzz TeamBy ISBuzz TeamMay 28, 20184 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Cybersecurity
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Trust is a huge issue in most sectors. Borne from years of ruthless competition, battles for customers and getting ‘one up’ on rival companies, trusting partners and customers with valuable information is difficult for businesses.

Distrust derives through the fear of giving away valuable product information and business data you don’t want leaked or customer contact details. But it is also because of basic security. If competitors or cyber criminals can access data and find information they can use against your business, you’re opening yourself up to a whole host of threats, reputational damage and the potential loss of customers.

The concept of sharing insights with those outside of an organisation is an awkward proposition given the current high levels of cross-border and competitive distrust. Ironically, trust forms a fundamental part of many business models in industries such as the public sector or aerospace, yet distrust is often highest in the organisation where sharing knowledge is imperative.

This needs to change. Especially in the cybersecurity industry where it’s becoming increasingly important for businesses to work together and share information to stay one step ahead of the ever evolving threat landscape.

Beating cybercrime through knowledge

Trust and openness are both complex issues that differ depending upon the nature of the business sector – yet, to ensure a business is properly protected against malicious cyberattacks, both are vital. With this in mind, the security industry needs a process for managing distrust, as opposed to pushing for ubiquitous openness which is, quite frankly, an out of reach utopian view.

Businesses need to work closely with their trusted partners and digital security experts to develop ways of sharing insight and data on new cybersecurity threats that don’t also share valuable industry knowledge with their competitors.

There are already ways of sharing data that provide insight without the full intelligence – zero knowledge data sharing and making use of blockchain sharing methods for threat intelligence, for example. These methods can provide enough information to stop an attack without threatening the competitive industry spirit that has been built up over many years.

 

This is also where standards such as STIX (Structured Threat Information eXpression) – itself a community-driven effort, STIX relies on information sharing all while making threat intelligence flexible, automatable and understandable for humans – and TAXII (Trusted Automated eXchange of Indicator Information) can help to re-align IT security efforts. The ability to express threat intelligence in a structured format allows you to more easily separate potentially sensitive data from that which is easily shareable. Adding granular data markings to the entity level, based on that sensitivity, means you can have full visibility on how your data can be shared and what the potential impact may be.

Protection through sharing

Business owners and IT leaders responsible for digital security need to be fully informed on the various ways of sharing that provide cybersecurity experts with insight without full intelligence.

Consider last year’s WannaCry attack which saw ransomware hit millions of computers, taking down vital NHS systems, a large telecom in Spain, and hundreds of other businesses and institutions worldwide. Victims were held ransom and their computers frozen until the hacker’s demands of around $300 in bitcoin were paid.

Thankfully, cybersecurity expert MalwareTech saved millions of users and businesses across the globe from what could have been one of the worst cyberattacks in history by discovering a universal kill switch. What if that it wasn’t a universal kill switch but a local one that needed to be shared with all of those millions of victims to be able to implement? Remediation needs to keep pace with the scale of the impact.

To really be able to stop cyberattacks in the future, especially those on the same scale of WannaCry, threat intelligence must be accessible and available to all. Standards such as STIX and TAXII will be able to help all organisations and industry groups organise their security efforts based on real-time information.

While it is obvious that this is the best path for organisations across the globe to follow, changes need to be made. The use of these standards currently seems to be a conscious effort and not something businesses are taking as seriously as they should. Now more than ever though, it the time for security professionals within businesses to drive a culture of openness and stay on top of the inevitable cyberattacks which are yet to come.

[su_box title=”About Chris O’Brien” style=”noise” box_color=”#336588″][short_info id=’104394′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}