Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Don’t get mad – get smart: your future in information security
News & Analysis

Don’t get mad – get smart: your future in information security

ISBuzz TeamBy ISBuzz TeamJuly 22, 2013Updated:July 3, 20247 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

My last blog argued that the technical reliance on anti-malware must end if we are to meet the challenges of contemporary cyber threats to both consumers and enterprises. So what can the industry do to move on and develop new ways of thinking and technologies that can adapt to these broad based threats.

The simple answer is “intelligence”. The industry needs to rapidly innovate to embrace intelligent security systems (with anti-malware as standard – it still has a part to play) that incorporates what I describe as full-risk situational awareness. This applies to technology and the culture of risk in the business.

In other words, stop believing that you can stop attacks and breaches, and move to a position of breach acceptance and learn from that – after all it is widely believed that many organisations are already infiltrated without their knowledge and that number is increasing.

This new awareness should apply to policy and strategic thinking by information security practitioners. Theory in applying full-risk situational awareness should also be developed in higher education establishments, especially those currently teaching information security so that new professionals are ready for the world they seek to protect.

Just as so-called Advanced Persistent Threats (APT) can sit undetected in the background of an organisation gathering data by stealth so defensive systems should be developed that adopt the same technique and shadow such cyber weapons and learn from them once detected. Don’t kill the tools of your enemies, instead watch and learn – much as a government intelligence agencies watch enemy agents rather than arrest them.

Both Amazon and Google have developed and continue to develop extraordinarily sophisticated algorithms to help them predict what you want to buy and what you are searching for. It is surely not impossible to adapt such technology to analyse and predict the behaviour of malicious cyber actors and the software that they develop to attack organisations. In fact why do we continue to assume that information security technology should come from information security companies? Why not adapt Google and Amazon’s tools or indeed those from any cutting edge tech firm working in the big data space. Making sense of the extraordinary mass of malware today means learning from those research clusters investigating how we can manage big data and build intelligent computing devices. But such clusters are not found in many security firms.

All together now, big data and artificial intelligence:

A report in the world renowned MIT Technology Review reveals that the latest advances in AI are now finally coming close to the dream of creating sentient devices – but it isn’t just about building chess playing supercomputers. It describes the advances as “deep learning” which could herald a new age of predictive technologies. And Google is at the forefront of such research.

“Last June, a Google deep-learning system that had been shown 10 million images from YouTube videos proved almost twice as good as any previous image recognition effort at identifying objects such as cats.” it reports.

The theory behind deep learning is that machines develop memories from experience which then influences their behaviour when faced with similar circumstances or can apply learned behaviour when faced with a new situation.

Why not apply deep learning to the behaviour of malware and malicious cyber actors to comply with our full-risk situational awareness? In other words – develop systems that learn and fight back to meet offensive malware programs head on. Perhaps even by learning from previous malware behaviours and attack routes, such deep learning anti-cyber systems could conceivably block attacks before they happen, or allow them to get to the point of attack and then kill them. Of course it sounds fanciful – but not completely. And do you know of better, current security techniques being developed among the vendor community?

You can change your mind:

For the technology to work we also need a fundamental change in information security thinking to accompany such radical technology. A conversation I had with William Beer, Director Information & Cyber Security at PwC UK, demonstrates the kind of leadership we need from those at the top of information security today.

“We need more thinking, more research – not just more technology. The industry needs more research. The vendors trot out the same cliches and so called insights.” he told me.

“There is a lack of innovation, a lack of creative thinking. I don’t want to hear about ISO 27001 or defence-in-depth. Clients are not getting the solutions they want. How can we do things differently? That’s the big question.”

“We have so much to learn from the past but we don’t look at history. We don’t look at medicine, or cancer research or how viruses spread. We don’t do enough information sharing. We’re thinking with blinkers on. Why not employ criminal psychologists, religious experts – why not “know your enemy”? It’s not a skills shortage – it’s the thinking that’s wrong and the people recruited into information security.”

And he is, of course, right. How many security conferences and exhibitions have you been to where you heard anything new? When were you last challenged to think differently about what you do? You will hear about  “reporting to the board” and “cutting edge” reports on the “future of threats”. Plus, of course, everyone’s favourites BYOD and Cloud etc…it’s all bread and butter stuff.

It’s still important and still worth discussing but they are missing the point of what “information security” is and how it should be applied. The level of malicious cyber activity is such that we need to radicalise our technology and thinking rapidly. And that means shifting away from even thinking about information security at all. Instead move to an awareness that the best way to be secure is to assume you are not and act accordingly. That way we may yet stand a chance of protecting our businesses and the economies that depend on them. The alternative is just information security noise.

About the Author:

is17Paul Fisher | @Pfanda | Pfanda.co.uk

Paul Fisher has worked in the technology media and communications business for the last 22 years. In that time he has worked for some of the world’s best technology media companies, including Dennis Publishing, IDG and VNU.

He edited two of the biggest-selling PC magazines during the PC boom of the 1990s; Personal Computer World and PC Advisor. He has also acted as a communications adviser to IBM in Paris and was the Editor-in-chief of DirectGov.co.uk (now Gov.uk) and technology editor at AOL UK.

In 2006 he became the editor of SC Magazine in the UK and successfully repositioned its focus on information security as a business enabler. In June 2012 he founded pfanda as a dedicated marketing agency for the information security industry  – with a focus on content creation, customer relationship management and social media.

His heroes include David Ogilvy, Ludwig Mies van der Rohe, Ken Garland, William Bernbach, Andy Warhol, Richard Branson, Charles & Ray Eames, Steve Jobs and Paul Rand. And George Best. He comes from Watford but he thinks he comes from Manchester. If you came from Watford, you would too.
As an impulsive adopter of new technologies and an inability to stick to one ecosystem, he can be spotted around London’s finest WiFi hotspots variously sporting a Chromebook Pixel, an old Blackberry, Nexus 7 and a Nokia 920. He also has a Mac and an Xbox at home.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}