Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Who is Winning the Internet Security War?
Articles

Who is Winning the Internet Security War?

ISBuzz TeamBy ISBuzz TeamAugust 3, 20156 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Internet Security War?
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Internet may have transformed every aspect of business and personal life but the truth is that it is still in its infancy. As a result, there is a clear lack of sophistication and maturity regarding the way the Internet is used and abused today.

Data security is without doubt the primacy concern. The continuous innovation in the way in which businesses and individuals operate online is only matched by the level of invention and diversification in the hacker’s armoury. Mark Kedgley, CTO, New Net Technologies, argues that the only way to win the Internet Security war is to approach it like any traditional war, with a variety of tactics to win each individual battle and a clear focus on intelligence.

Mark Kedgley, CTO, New Net Technologies :

Rising Fear

What will make businesses and individuals take the online security threat seriously? Right now, whether it was the hacks of federal targets like the IRS and the Office of Personnel Management or the news that a major league baseball team had been hacked by a rival, suddenly there is a serious awakening to just how much confidential personal and corporate data is at large – somewhere – on the Internet and just how vulnerable that information could be.

The problem is that while fear is rising, few people have any real idea how to counter the threat. And of those that do have an understanding of security best practices, many do not have the stomach to implement and operate these to an effective level.

Which is why so many are willing to embrace any ‘silver bullet’ on offer from the Cyber Security Market.  From Anti-Virus (AV) software to Next Generation firewalls, Threat Intelligence networks to Sandboxing, the market is muddled and those tasked with deploying technology are confused. While security responsibility is slowly creeping out of the wiring cupboard and onto the board agenda, most companies still perceive security best practice to be too complex, arduous and time consuming to deploy and can be easily enticed by the latest security promise.

But each new wave of technology is nothing more than an inspiration or challenge to a determined hacker. A recent example that illustrates this point perfectly was the Rombertik malware, clearly engineered to undermine the highly expensive and – certainly as far as the vendors of such products would have you believe – impenetrable sand-box technology. While this might be deemed a rare, one-off exception to the general rule, the knowledge is out there and will be commonplace within months. As such, the attack surface is continually evolving, with new weak-spots inexorably being exploited. So where does that leave those organisations that believed by investing in the latest prevention-technologies they had security nailed?

Changing Attitudes

To be blunt, there is no way to guarantee a company will not be breached. In fact the only option is to complement any threat prevention measures with a way of rapidly detecting breach-activity before it causes any significant damage – from stealing customer information to gaining invaluable intellectual property, or just wreaking havoc across the corporate network. And that means evolving from an emphasis on stopping the breach, to one of stopping AND spotting the breach.

The good news is that this model is beginning to gain traction. According to Gartner, 40 percent of large organisations will have formal plans to address “aggressive” cyber-security business disruption attacks by 2018. In its “Attack on Sony Pictures Is a Digital Business Game Changer” report, the firm says that while there are currently no companies adopting such a strategy, which would see CISOs and business continuity managers (BCMs) increasingly move from prevention to detecting and responding to attacks, attitudes are changing, fast.

Indeed, there is a wider effect of raised awareness as a result of these high profile breaches, with Gartner insisting these events’institutionalise more-proactive thinking about cyber-security risks’. This attitude will without doubt affect the way individuals perceive suppliers, customers and business partners alike and will ensure far more people at every level of the business are attuned to the issues of online security.

However, expecting just 40% of companies to have made this shift by 2018 is not good enough; it is time to get real with respect to combined breach prevention/detection and plan for the inevitable successful attacks right now.  Companies need to embrace a combination of intelligence, process and technology. Merging security best practices with intelligent automation of functions like change control and breach detection enables a company to successfully identify and track every single unexplained and unexpected change or action across the infrastructure, without being overwhelmed by noise, in order to respond fast to suspected incidents.  It is only by spotting and, more critically, responding to these breaches that any company can attempt lock down against the raging cyber threat today.

Conclusion

Over time this situation will change. With time comes sophistication and maturity and, without doubt, cyber security behaviour will become more of an essential, basic life skill, like learning to cross the road safely. Consumer awareness will also continue to rise and those companies failing to adopt the right approach will be named, shamed and pilloried. But how long will this take? Five years; ten? Even longer, perhaps. In the meantime there will be a constant process of balancing the ingenuity of the foe with the dogged determinedness of the friend; organisations will get better at attaining security best practice; and, hopefully, it will become less onerous to get that best practice in place as technology solutions evolve.

However, one message remains clear – no one can expect to stop every single new breach. Whether the security threat is internationally funded terrorist organisations, governments, industry competitors, organised crime or even still the clichéd teenage geek, it will continue to expand and also evolve. And facing this kind of future, any organisation not prepared to mobilise a full range of tactics to both stop – and spot – a breach will, inevitably, end up as another casualty of the Internet War.[su_box title=”Mark Kedgley, CTO, at New Net Technologies” style=”noise” box_color=”#336588″]New Net TechnologiesNew Net Technologies a global provider of data security and compliance solutions. The company is firmly focused on helping organizations protect their sensitive data against security threats and network breaches in the most efficient and cost effec­tive manner.

New Net Technologies’ easy to use security monitoring and change detection software com­bines Device Hardening, SIEM, CCM and FIM in one integrated solution, making it straightfor­ward and affordable for organizations of any size to ensure their IT systems remain secure, malware-proof and compliant with the corporate build-standard at all times.

New Net Technologies safeguards customers’ systems and data, freeing their clients to focus on delivering on their corpo­rate goals.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}