Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Do You Know Your Customers?
Articles

Do You Know Your Customers?

ISBuzz TeamBy ISBuzz TeamJanuary 18, 20197 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Responsibility for Cyber Security
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Every third Thursday of each quarter, ‘Know Your Customer’ Day is held. The day transcends all industries, aimed at businesses and designed to serve as a reminder of how important it is to take the time to understand your customer.

In the cybersecurity industry, it is equally important. When it comes to knowing the ‘customers’, it is predominantly the users of the network, or the need to support customer and user activities. Information Security Buzz spoke to a variety of technology professionals to gauge exactly what ‘Know Your Customer’ Day means to them and their business, and how it impacts cybersecurity.

Knowing your customers

Rupert Spiegelberg, CEO of IDnow argued that as companies do more online, knowing your customers has become more important than ever before, particularly in the banking sector. “Digital IDs are becoming the new currency, so companies need an easy, trusted and compliant way of finding out who their customers really are,” he explained. “But with diverse, international customer bases, growing regulation and a whole host of other challenges to contend with, doing that is much easier said than done. Online identity verification is a growth market because, from a consumer perspective, it enables customers to ID themselves in a fast, convenient manner on the same device they will use to transact with a particular supplier and from a supplier perspective, it can satisfy local regulation requirements that the potential customer is who they say they are, as well as onboard new customers with ease and speed. In short, knowing your customer technology is building consumer trust and helping make the connected world a safer place.”

Customers in the workplace

Anurag Kahol, CTO at Bitglass cited mobility, flexibility and accessibility as some of the most important words that underpin the requirements of today’s workforce. He continued, “Failure to provide a working environment that supports these requirements can mean the difference between attracting and retaining staff – or being left on the proverbial shelf. The mobile security challenges have been exacerbated in recent years by the rapid uptake of BYOD. These unmanaged or employee-owned devices require access to corporate data, but this increases the risk of sensitive data being leaked, especially if a device is lost or stolen. A further vulnerability is that BYOD devices represent a potential entry point for introducing viruses and malware to the rest of a corporate network.”

When it comes to knowing customers – in other words, employer’s workforce – IT teams must address a real dilemma – how to strike a balance between the security needs of corporate data and how employees want to use corporate data. Kahol continued, “Developments in cloud-based security tools have given rise to a new set of mobile security solutions that means encryption of sensitive data can be extended to whichever popular cloud apps their customers are using – be that G Suite, Office 365, Slack or Salesforce, which means that data is secure regardless of what application a user is accessing via their personal device.”

“The cloud has brought analytics back into the hands of business users, particularly in HR,” stated Liam Butler, AVP at SumTotal, a Skillsoft company. “In the ‘old days’, business analytics tools were shrouded in secrecy and owned by IT and MIS as part of the on-premise ERP system. Analytics are now part of our daily life, being used to enable insightful decision-making and to predict business outcomes. For example, the linking of workforce management data with training data allows manufacturers to predict workforce capacity planning issues in advance of a product launch, train employees prior to manufacturing demand or move shift patterns to meet demand.”

Securing the network

Living in an increasingly networked world has its advantages, but it also leaves organisations vulnerable to exploitation by malware, inadvertent employee actions and malicious attacks. Jan van Vliet, VP and GM EMEA at Digital Guardian discussed that for security analysts, spotting security incidents arising from within their company, which is arguably their own customer base, is particularly tricky because the attacker may have legitimate access. “If the credentials being inputted are valid, the same alarms are not raised as when an unauthorised user attempts entry from the outside,” he explained. “Deploying data-aware cyber security solutions removes the risks around the insider threat because even if an adversary has legitimate access to data, they are prevented from copying, moving or deleting it. What’s important when it comes to insiders, in whatever guise, is to be able to detect malicious or suspicious activity and produce real-time, priority alerts that analysts know must be addressed immediately.”

Todd Kelly, CSO at Cradlepoint agreed, “In order for industries to do more with their business and grow naturally, they have to embrace the cloud. Even with sensitive information on their applications and networks, enterprises can use the cloud without a great deal of risk. By utilising a cloud manager, businesses will be able to monitor and configure capabilities so that one person can manage the SD-WAN, IoT and 5G connectivity and keep users secure while using the network.”

Network intruders

Securing the network is fundamental to protecting the business, and a variety of tools exist to understand traffic flow over a network and to analyse security impacts from that flow. However, despite the capabilities of these tools, attacks and breaches continue to happen. It is time to expand the definition of network profiling to include the riskiest asset on the network: the user.

Nir Polak, CEO at Exabeam emphasised, “Advances in data science, combined with computing power and applied to data already collected within most organisations, can connect the dots and provide a useful profile of network user activity. While data science – i.e. machine learning –has become an overused buzzword, in practice it can provide very useful answers in certain applications. For example, machine learning can discover the connections between seemingly unrelated bits of identities, to create a map of all of a user’s activities, even when the identity components are not explicitly linked.

“Other techniques can create baselines of normal behaviour for every user on the network, making it easier to understand whether each user is acting normally or not. Still other techniques can build better asset models, including which machines are likely “executive assets” and at higher risk of attack. Profiling individual users enables an organisation to understand in great depth and with deep context exactly who is on the network; what they are doing; whether they should be doing it; and what it means to an organisation’s risk and security posture.”

Garry McCracken, VP Technology at WinMagic expanded on this, describing that in a world where IT environments are becoming increasingly virtualised and hyper-converged, the attack surface is significantly expanding. “This means securing the data itself has become a top priority. Enterprises need to take appropriate steps to ensure that sensitive data never appears in the public domain,” he reasoned. “The solution is to ensure protection resides within the data by utilising in-guest encryption with keys that remain under the control of the virtual machine (VM) owner – the enterprise itself. VM-level encryption not only protects workloads wherever they may be within the enterprise infrastructure and beyond. It also delivers a significant number of additional advantages, including making it easy for IT departments to control all aspects of data security. It ensures that data can only be accessed by authorised users, even in the event that a cloud system is breached.”

As the threat landscape continues to expand, it is becoming more important for businesses to know their customers –to help implement the right technologies and embrace new offerings to improve organisations’ security postures.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}