Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Dark Territories – Do You Know Where Your Information Is?
Articles

Dark Territories – Do You Know Where Your Information Is?

ISBuzz TeamBy ISBuzz TeamMarch 24, 2014Updated:July 3, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Dark_Territory
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

In this era of instant access to news, information as it happens, or in some cases before it happens how can we not know where something is? Between traditional media and social media, not to mention public on-line web sites, along with big data powered government (or private) surveillance using radar, cell-phone or other radio based, not to mention satellite tracking, how can we not know where things are?

Do you know where your data and information are or have been?

Do you have positive control over where you data and information have been?

Is your data and information exposed to dark territories?

With the recent disappearance of Malaysian Airlines flight 370 (MH 370) a Boeing 777 flying from Kula Lumpur to Beijing China, how can we not know where it is? After all, we all have public access to sites such as FlightAware and FlightRadar among many others, not to mention sites we in the public may not have access to. Same with using Cell phones or other forms of electronics, surely in the 7×24 non-stop, always connected world we should have insight and situational awareness as to where things are always at, right?

Wrong!

As MH 370 is showing, we still have what are referred to as “dark territories” a term that dates easily back decades if not centuries including with Rail Roads. A “Dark Territory” is known as an area where there is no direct or positive control and tracking such as when a train used to be out in the middle of nowhere, something that has for the most part if not completely been addressed with GPS, cell phones and other RF (Radio Frequency) based technologies. What about an airplane, why cannot we see where they are all the time?

We assume that all radars always can see where planes, trains and other things are all the time yet there are gaps in coverage or dark territories. For example, use FlightAware or FlightRadar among other tools and when a flight is overland with good coverage there is good positive control and tracking, that is unless the plane is blocking its transponder signal, or the flight is being blocked by the site for security reasons.

On the other hand, once the plane goes into dark territory such as out over the ocean where Radar and other tracking sites are few, radio signals weaker, and keep in mind, not all vehicles or planes have the same tracking capabilities yet that your cell phone has in your living room, you have questionable tracking data. In other words, garbage data or information in, garbage results and insight or awareness out.

What does this have to do with information security?

In the transportation industry, terms such as “dark territory” have historically been used by railroads (among others) to indicate areas with minimum to no management or positive control coverage. Other transportation related terms include “blind spots” or “flying blind” to indicate lack of situational awareness that can result in loss of management control.

Possible areas information data and storage “dark territory” or gaps in coverage:

– Public or private clouds that lack visibility into how and who is accessing resources
– Shipping containers containing storage systems or media (SSD, disk, tape or CD)
– Lack of leak detection on public and private networking links
– Physical and logical tracking of where data or storage mediums are during transit
– Who has access to eDiscovery, search or data classification tools and audit logs
– What physical access and audit logs or trails exists, how they are preserved
– Inventory tools including RFID for tracking fixed and removable assets
– Physical security and logical or encryption for data in-flight and at rest

Dark_Territory

Figure 1 “Eliminating “dark territory”, “dark clouds” and blind spots

In the top left of figure 1, various technologies and techniques are shown that are used at the source and destination for managing digital assets and media. Also shown are issues and lack of real-time management insight while assets are being moved in blind spots.

When it comes to moving data electronically via a network transfer or via shipping physical media, you may know when and where it left as well as of its estimated time of arrival (ETA), but do you know where the data was during transit or while in flight? Do you know who may have had access to it or been able to view its content, particularly if it was not encrypted? Can you provide auditable trails or activity logs of where the data moved or deviated from planned routes or paths?

General action items include:

– Gain situational awareness to eliminate dark territory or blind spots for security
– Establish multiple layers of defense leveraging physical and logical technologies
– Leverage different technologies and tools in different places to counter various threats
– Many issues are common across physical, virtual and cloud environments
– Establish a security model that enables while protecting

So ask yourself this question, do you know or can you find out where you data and information has been while in transit, both physical as well as via electronic transmissions?

Ok, nuff said (for now)

About the author

Greg Schulz is Founder and Sr. Analyst of independent IT advisory and consultancy firm Server and StorageIO (StorageIO). He has worked in IT at an electrical utility, financial services and transportation firms in roles ranging from business applications development to systems management and architecture planning. Mr. Schulz is author of the Intel Recommended Reading List books “Cloud and Virtual Data Storage Networking” and “The Green and Virtual Data Center” via CRC Press and “Resilient Storage Networks” (Elsevier) and a four time VMware vExpert. Learn more at www.storageio.com

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}