It does not matter if cyber security is at the top or the bottom of your budget list, if the choice is ever "better cyber security" or "do more business", cyber security is always going to lose that battle. You will never convince a company to use E2E encrypted email for all communications with all customers and vendors, no matter how high on the budget list cyber security is, because doing so would actively hinder the day to day operations of the business.
Security vulnerabilities come from the same place they always have. Where IO happens, where transactions happen, and where an operating system does a lot of work. How attackers get to these points, what happens when they do, and then how the system reacts when a malicious event occurs are the factors that matter.
In today's world of complex technologies, I have yet to meet a single organization that is invulnerable to these threats. I've seen a lot of organizations limit damage, patch vulnerabilities, and generally manage their risk profile effectively - but losses are a part of the business.
IMO, the only thing that will really make a difference is when we have technologies that are sufficient enough to male the user more resilient. Only then can we have a truly safer web.
I am not sure I would enjoy working at the second place but I would really hope we weren’t an easy target
Cf. eg., https://www.schneier.com/blog/archives/2013/10/air_gaps.html and https://www.schneier.com/blog/archives/2020/05/ramsey_malwar...
Yes maybe, but now you changed the topic and started talking about money and how expensive things are. Have a nice day anyway
...really?
I find this extremely hard to believe on its face. Sure an attacker can infect a system via a USB drive, but they need to get physically close to the victim (at least at one point in time). That both dramatically decreases the number of possible attackers and increases their personal risk.
It also becomes far more difficult for an attacker to exfiltrate any data.
As for the attack method, there's always the good ol' "flash drive found on a parking lot" vector.
Right, which requires the attacker to be physically near the parking lot at some point! That decreases the number of possible attackers by several orders of magnitude at least.
> Exfil may be tricky if the system is actually airgapped - I take GP's use of scare quotes to mean that most systems are "airgapped" by means of software-enforced security policies, which should correctly be referred to as "not airgapped".
Ah, that makes more sense! I do think tpmoney was quite clearly talking about truly airgapped systems, however.
Very much so. My point being that a truly air gapped system is objectively more secure than one that is networked, and yet, a bank or social network company that only operates with truly air gapped systems will be strictly worse off than their competitors in their actual business of banking or social networking. And so since their actual job is not objectively better cyber security, but banking or social networking, then they are inherently at a disadvantage compared to Attackers whose business IS attacking (or at one step removed, selling the resources obtained from attacking). In the name of making their business better, Defenders will chose weaker security, and attackers will chose stronger attacks.
I have worked at 20+ companies and the ones that had little to no security got ransomwared at LEAST yearly (with 50m+ in revenues) and the ones that had basic and standard security practices got zero network wide intrusions (at least at lower then say, a nation state level.)
Now, COULD they have been exploited with an 0day? Sure, in theory these networks could be both exploited with the same technology or by a dedicated actor likely without an issue - they're internet connected corporate networks mostly with probably out of date tech; and in practice most attacks corporations need to mitigate are the drive by trash that consumers also face.
Look at any cloud provider. They get it right because they employ the best security management systems.
Some examples:
https://www.theverge.com/2023/8/3/23819237/microsoft-azure-b...
https://www.theverge.com/2023/9/6/23861890/microsoft-azure-d...
https://www.reuters.com/technology/microsoft-warns-azure-cus...
https://www.bleepingcomputer.com/news/microsoft/microsoft-st...
Well, I'd prefer incapable people to build secure rocks over them building insecure non-rocks.
Replace "security" with "safety" for, IDK, space engineering or nuclear power. Does it still make sense?
Safety and security need to be integral parts of processes. It is not something you can acquire from a vendor or split out as the responsibility of separate team(s) who have to internally battle for resources and interface with the core development through escalation requests...
Safety systems take over if your chemical reaction overheats the reactor; they prevent your logistics team from moving a train while it's being loaded with dangerous chemicals (real example, the safety system was disabled by the logistics people - ironically the company put those with poor safety record from production to logistics, because they could do no harm there).
You're mixing up safety systems with the property of "doing X is safe by construction" - but most plants inherently are not: e.g. in a small reactor that's manually fed, your employees can just input the wrong recipe by accident; the safety systems should then take care of the mess. Or your junior chemist (who needs an expensive, senior chemist for an established process?) can mess up the improvement to the recipe, resulting in rapid unscheduled disassembly of you poorly maintained reactor, including the building and one of its operators (sadly a real example).
Humans are reckless idiots. If circumventing safety systems means they can go home 15 minutes earlier (or if it's the only/simplest easy to get reach some unrealistic high daily goal dictated from higher ups), some of us will happily risk their own health, and that of a whole city, to do so.
Still though, security is fighting against an opponent who searches for weak points and exploits them to the max. "Safety" protects against random natural accidental events (either internal or external in origin). If someone is just trying to get home, they want to get the job done quickly sure, but their intent is not to cause damage, their actions aren't targeted. It's a different risk profile.
Maybe my examples are bording on sabotage, eg "sabotage by accident".
Here's a question: Why do most safety regulations require the force of law to get companies to enact, but no laws were necessary to get companies to adopt the internet? "Safety" is in a similar boat to security, with the benefit that you usually don't have people actively trying to harm your employees. But Safety often gets tossed out the window when it gets in the way of accomplishing the real goals of the organization. Why is the US military exempt from a number of safety regulations that private companies are beholden to? Because the military believes those regulations will hamper their real mission, which is not keeping individual soldiers safe.