Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - With cyber friends like these…
News & Analysis

With cyber friends like these…

ISBuzz TeamBy ISBuzz TeamJuly 22, 2013Updated:July 3, 20247 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
cyber
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The phrase “threat landscape” is a cliche of information security discussions but like many cliches it still means something.

In our case it usefully describes the actual type and level of threats that businesses face on a daily basis. And as we have seen those threats have moved on from malware into something far more sophisticated and wide ranging – malware is still a threat but it is simply a means to an end and its never ending stream has made it virtually impossible to deal with, as discussed in a previous blog and in FireEye’s most recent report on advanced threats.

Much of the threat landscape is made up of criminal hackers doing what they have always done; use malware, rootkits and botnets to steal data for financial gain. These have been the traditional enemy of those working in information security. However recent events suggest that businesses and organisations are facing much more than criminal hackers as they seek to protect data – they now face the might of state-funded cyber espionage. Whatever you think of Edward Snowden, his activities have certainly lifted the lid on what governments across the world are doing to gain competitive advantage (and much more) through covert cyber techniques.

Putting aside what the US government (probably rightly) defines as the treasonable activities of the now on-the-run NSA whistleblower, and the revelations of electronic surveillance of the US population, possibly the most amusing part of this whole episode is the US reaction to the accusation that it has been electronically spying on China – probably for years.

The accusation, based on Snowden’s revelations, is a gift to the Chinese government which has been on the backfoot after years constantly denying using cyber methods to infiltrate US and other Western companies and organisations. The US response to this has been muted and it has not actually denied such activity, instead it is concentrating on trying to extradite Snowden.

Well hoo-hah to all that but the US silence says a lot. There are two points about all this. First, is anyone surprised? Does anyone seriously think that the US is not capable of and willing to spy on its only serious global rival? It has the means and it has the motivation. And whether you believe Snowden’s revelations or like his methods, he has demonstrated to the world the true extent of state sponsored cyber activity that is taking place. We have learnt that the US spies on its friends as well as its enemies and its own citizens. It is the extent of the activity that is shocking rather than the activity itself. Cyber has made it possible to conduct mass surveillance on an unprecedented scale.

And the second point is that there is, anyway, very little morality in cyberspace just as in the real world of geopolitics. In reality, everyone is spying on everyone else. Here in the UK, the giant metallic doughnut that is GCHQ has not only been listening to its own citizens but also those allies visiting the country to attend such events as the G8 Summit.

The outrage expressed by governments that their enemies are using cyber attacks is for public consumption only – behind closed doors they are undoubtedly ramping up their own cyber efforts. And they would be foolish not to. Espionage was not invented in the internet age but cyber methods have made it so much easier to do and much harder to stop. It’s a case of fighting fire with fire.

If Snowden has achieved anything (apart from a rather lengthy stay in transit at Moscow Sheremetyevo Airport) is that he has blown the hypocrisy surrounding cyber espionage wide open.

The other curious nature of the cyber phenomenon is how long it took the US government to get round to accusing the Chinese openly of using such techniques. For many years its economic dependence on China tended to help turn a blind eye to the activities of China (while possibly maintaining its own cyber activities in return). But that has changed in recent years as Obama decided enough was enough and time to speak out. This co-incided with a huge budget increase for America’s cyber defenses – no surprise there.

The same attitude cannot be said of much of America’s business community who remain extremely reluctant to accuse China of anything lest it jeopardize contracts in the Chinese market – which don’t forget will soon be the largest market in the world for virtually everything. Surprisingly, this attitude is especially true of the high-tech sector – the very sector that the US government seeks to protect from Chinese snooping.

The UK, for its part, has a mixed approach. Like the US before it, it has so far refrained from actively naming or accusing China, instead it talks of the need for “international co-operation on cyber security” (usually at international conferences on cyber security) which is short hand for doing nothing.

Chinese telecom giant Huawei has been providing BT with infrastructure equipment for years despite security fears that it gave the Chinese a physical foothold in the country to perform cyber activities.

BT did the deal without telling the UK government and it was made mostly on cost, i.e. the Chinese option was much cheaper. Somewhat belatedly, a U.K. parliamentary committee earlier this month released a report saying Huawei’s strong presence in the country’s telecom sector raises potential national-security issues.

The US has banned Huawei from entering its own telecom equipment market. The UK of course, being a far weaker economy than the US cannot afford to be so bellicose. We need the Chinese more than they need us.  Or perhaps we are smarter than we know. Could the chaps in the silver doughnut in Cheltenham be also monitoring what all those bits of Huawei kit, now embedded in BT exchanges up and down the UK, are actually doing? I have no idea but I’d like to think so.

About the Author:

is17Paul Fisher | @Pfanda | Pfanda.co.uk

Paul Fisher has worked in the technology media and communications business for the last 22 years. In that time he has worked for some of the world’s best technology media companies, including Dennis Publishing, IDG and VNU.

He edited two of the biggest-selling PC magazines during the PC boom of the 1990s; Personal Computer World and PC Advisor. He has also acted as a communications adviser to IBM in Paris and was the Editor-in-chief of DirectGov.co.uk (now Gov.uk) and technology editor at AOL UK.

In 2006 he became the editor of SC Magazine in the UK and successfully repositioned its focus on information security as a business enabler. In June 2012 he founded pfanda as a dedicated marketing agency for the information security industry  – with a focus on content creation, customer relationship management and social media.

His heroes include David Ogilvy, Ludwig Mies van der Rohe, Ken Garland, William Bernbach, Andy Warhol, Richard Branson, Charles & Ray Eames, Steve Jobs and Paul Rand. And George Best. He comes from Watford but he thinks he comes from Manchester. If you came from Watford, you would too.
As an impulsive adopter of new technologies and an inability to stick to one ecosystem, he can be spotted around London’s finest WiFi hotspots variously sporting a Chromebook Pixel, an old Blackberry, Nexus 7 and a Nokia 920. He also has a Mac and an Xbox at home.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Roundcube RCE Vulnerability Disclosed Early Amid Active Exploitation

June 10, 20255 Mins Read

Fake Indian Government Portal Used to Spread Cross-Platform Malware in Suspected APT36 Campaign

May 13, 20253 Mins Read

New Federal Alert Warns U.S. Businesses of Medusa Ransomware Surge

March 13, 20254 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}