Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - RSAC 2015 Keynotes: InfoSec Big Data, Cloud Transparency & Control
Articles

RSAC 2015 Keynotes: InfoSec Big Data, Cloud Transparency & Control

ISB Editorial StaffBy ISB Editorial StaffApril 28, 2015Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
notes on RSAC 2015
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Last week, I attended keynotes and sessions at the RSA conference hosted at the Moscone Center in San Francisco, taking notes as furiously as possible and sprinting back and forth between rooms – leaving little energy and time left to live-blog coherently after. As a result, I’ll be blogging about some of the more interesting talks this week as a retrospective.

True, many of the keynotes are available as videos online, but here’s my summary and top takeaways from some of the speeches from the Microsoft and Intel leaders:

Enhancing Cloud Trust

Scott Charney, Corporate VP of Microsoft’s Trustworthy Computing, gave a keynote on Tuesday, April 21 following RSA President Amit Yoran’s speech on security’s age of enlightenment.

His talk centered on the need for transparency and control as we move into the cloud. Despite improving security innovations, threat models have gotten worse. In order to build a more preventative infrastructure, we need to deal with the identity problem. Credentials are often harvested by attackers in order to look like a legitimate user, logging into our cloud infrastructure.

The threat model is changing – attacks have become more destructive. Charney questions how we can protect the fabric of VMs (virtual machines) from attackers, since it’s not only users that are signing up for cloud subscriptions – attackers are also signing up and leveraging the same technology to launch malicious attacks.

Charney also mentioned that in a “post-Snowden world, we’re concerned about each other.” This was not the first and only mention of the insider threat, which seemed to be a new theme this year at the RSAC conference among speakers. Threats are changing and taking on new threat actors, including not just external actors, but also potentially your own employees.

He made a good point that customers are happier when they feel like they’re in control – while its not necessarily safer to drive than fly, people still feel like they have more control when they’re behind the wheel.

Cloud providers need to think differently when it comes to control and transparency. Not everything is in the cloud – some things are still on-premises. And we’re still dealing with identity management problems.

There are two major areas cloud providers and organizations that use cloud services should focus on:

  1. How you authenticate to your device
  2. Personal computing – when a machine recognizes you based on your behavior, devices and location

For more control, cloud services should also allow people to manage their encryption better, by giving them the functionality to deny cloud providers access to their environment and cloud if needed, for any reason.

When you’re on-premises, you get to decide which logs and what to deploy, but when you move technology to the cloud, you lose some of that control.

Charney made the point that “sophisticated” attackers harvest credentials and move laterally across networks – making domain authentication a major problem. He suggests updating regularly and better management of domain list authentication. People also need to know what’s happening to their data on the network, and they need to see a list of who has access to their data.

With the recent high-profile destructive attacks in the media, the world has finally woken up. That means the markets have woken up – and when the markets create demand, people that build technology must rise up and meet the demand.

Security on Offense

Christopher Young, Senior VP and GM of Intel Security Group, gave a keynote with a sports metaphor twist. While in pro sports, defense is said to win championships, without offense it’s hard to score the points needed to triumph. Young claims the same holds true for information security.

He made the point that we need to use big data to inform and prioritize our actions, based on analyzed insights, as well as to map threats and alerts into a threat campaign. Ok, I admit I wrote “something something moneyball sportsball metaphor” in my notes, but he did use the great example of Moneyball – a baseball movie that featured the use of big data to monitor an athlete and team’s actual performance.

He even brought Oakland Athletic’s general manager, Billy Beane, who was played by Brad Pitt in Moneyball, onstage to share a few words, which appeared to be a crowd-pleaser. Beane was a major proponent and leader of the use of big data in changing the game of baseball.

Please read the rest of this article on Duo Security’s blog here.

By Thu Pham, Information Security Journalist, Duo Security | @Thu_Duo

Thu Pham covers current events in the tech industry with a focus on information security. Prior to joining Duo, Thu covered security and compliance for the infrastructure as a service (IaaS) industry at Online Tech. Based in Ann Arbor, Michigan, she earned her BS in Journalism from Central Michigan University.

 

About Duo Security

Duo Security is on a mission to provide advanced security solutions for organizations of all sizes. Duo’s innovative technology protects users, data and applications from credential theft and breaches with a focus on streamlined usability. The company was co-founded by CEO Dug Song, a major contributor to the security community, and CTO Jon Oberheide, expert cloud, mobile, and malware security researcher.

 

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}