The Macrosite for News, Analysis and Opinion about the Future of the Internet

Jody R. Westby, CEO, Global Cyber Risk LLC

Internet Evolution's instant message board - join the crowd...
You must login to participate in this chat.

This is a very enlightening webcast...thank you

 

Rank: Cave Painter

Jody,

Cyber risk will grow with usage...Mel

Rank: Cave Painter

interesting info, sorry to hear about SSN got stolen

Rank: Cyborg

good day to all :)

Rank: Cyborg

@LIN-yes u got lucky.

Thinkernetter

@aum007  Wasn't bad.  My doppelganger was a fairly responsible person.  Didn't open credit cards or bank accounts.  Seemed like all she used my card for was to obtain work.  

IQ Crew

must hv been very tough.

Thinkernetter

@Lin-Sorry to hear abt that!

Thinkernetter

incredible

Rank: Cave Painter

My SSN was stolen and used for years.  After a few years of using my SS number and name, the person changed the name with the SS office.  Didn't figure any of this out until I went to change my name with the SS office when my kids started kindergarten -- had trouble because I couldn't produce an ID with this person's name.  I was annoyed, but impressed with the chutzpah of the person who stole my SS number and then decided to change the name to something she liked better. 

IQ Crew

All: Jody is leaving the chat, but please feel free to stay online if you like.

Thinkernetter

Many thanks, Jody. Terrific interview and excellent chat.

Thinkernetter

Ok, folks, I am signing off now.  Thanks very much for your questions.  They were very good ones!  Cheers,
Jody

Rank: Cave Painter

Re the govt protecting identities, I actually think the govt does a pretty good job.  The govt has an enormous amount of data and when one considers how much data it has, there really have not been very many breaches. 

Rank: Cave Painter

My CyLab report shows that the financial sector is doing the best job, but even they have lots of room for improvement.  The energy/utilities and industrials sectors had the lowest rankings in security practices.

Rank: Cave Painter

I was reading the case of this 8year old kid whose SSN was stolen and used multiple times,I feel Govt does a very poor job of protecting identities.

http://www.dailyfinance.com/2012/06/04/identity-thieves-are-targeting-our-kids-what-parents-must-know/

Thinkernetter

I think cybercrime continues to rise and certainly tough economic times makes it more tempting.  But the economy could fully recover and be going gangbusters and cybercrime would still be high.  The bad guys are winning....we need to turn the tide on that. 

Rank: Cave Painter

@Jody-which industries do u feel does the best job of protecting Customer Data and which does the worst today?

Thinkernetter

@Jody-do u feel that thanks to the economic downturn,cybercrime cases have shot up considerably today?

Thinkernetter

Re Daniel Brian's question on IPv4 and IPv6....I do not know the answer to that question.  I would have to ask some of the researchers and technical people that I work with.  Sorry!

Rank: Cave Painter

@Jody-Wow! I read ur forbes Blog.Good stuff!I had no idea that none of these firms provide a Phone number for contacting them(sorta slipped my mind!).

Thinkernetter

reposting Daniel-Brian's quesion for Jody because I really want to hear what she has to say on the topic -- What are some specific precautions/best practices do you recommend, the government and really all of us take (before during and after) moving to IPv6 IPv4 dual stack? 

IQ Crew

Re my study, companies are showing great improvement in organizational activities, such as establishing a board risk committee and cross-organizational teams of senior executives to discuss privacy and security issues.  These are very good.  They are doing very poorly, however, in assigning key roles and responsibilities, staying abreast of cyber attacks, and reviewing cyber risks to operations.

Rank: Cave Painter

There are lots of people engaging in cyber attacks, including nation states. I am not going to single out any one country; that would be silly.  There are a few countries that appear to be more active than others, but that is just that.....it is possible that an inactive country could be more damaging in one attack.  So we can view cybercriminals in categories, such as script kiddies, rogue single actors, organized cyber criminals, terrorists, and nation states, and also, of course, the insider.

Rank: Cave Painter

Jody, a question regarding your recent study results: Are there any specific practices that US companies are engaging in that are good, should be encouraged?

Thinkernetter

I am not against cloud services all together, but I do not think companies are adequately examining the security risks and ensuring that the cloud vendor is providing adequate security and will respond appropriately and swiftly and provide the client with information needed to advance the investigation.  Clouds and social media sites have serious security issues.  Also see my Forbes blog on Social Media Companies Contribute to Cybercrime

Rank: Cave Painter

@Jody-Nowadays,its very tough to figure out who is behind which cyber attack and where.Its all a massive colloborative effort.So should u want to single out any single Nation(even if its politically expedient to do so)?

Thinkernetter

Google did not, as I recall, single out China.  They just said they would alert users if they suspected activity was coming from a nation state.  It could come from a lot of countires, including some US allies.

Rank: Cave Painter

Reviewing budgets helps security because the security needs of the organization are tied to budget line items and if senior management is approving them, then they are taking responsibility for adequate security or taking responsibility for not providing funding to achieve it.

Rank: Cave Painter

@Jody-its not possible today to avoid the segregation issue.It just happens as company try to make do with less.

Thinkernetter

Will the United States share continuous monitoring data with China?  Under what kind of agreement?

Will

Thinkernetter

Continuous monitoring can be justified and a good idea if the work situation requires it.  It is a tool that can very effectively protect business interests.  It is also a tool that can be abused, so it should be used within a reasonable context.

Rank: Cave Painter

A person should not be responsible for several positions.  A CIO should not also be a CISO unless they are in a small company and the needs of the organization can be met by one person and that person has both substantial IT and security expertise.  CISOs also should not be CPOs, something a lot of companies do, but it creates a segregation of duties issue. 

Rank: Cave Painter

Jody:

  What do think of Continuos Monitoring?  Is it a real paradigm change?

Is it a only US solution?

Thanks,

Wiill

 

Thinkernetter

@Jody-If that is so.then the UTAH Data center would never have been in operation.

Thinkernetter

interesting

Rank: Cyborg

Logs should be stored for as long as necessary to protect operations.  It will depend on the type of operations being undertaken.  Logs are often archived. 

Rank: Cave Painter

How does reviewing budgets improve security?

Rank: Cave Painter

@Jody-What happens when one person is responsible for several posts?like CIO/CISO,etc?

Thinkernetter

My question after your mention of social media's dangers is, How can companies help to guard against threats on social sites?

Thinkernetter

Yes, intelligence agencies are forbidden by US law from spying on US citizens.  There are special courts to get permission when necessary to do so that are set up by the Foreign Intelligence Surveillance Act

Rank: Cave Painter

@Jody-what do u do about all that data?How long do u store transaction logs for instance?

Thinkernetter

Jody has joined us. Thank you, Jody!

Thinkernetter

There was a question about best practices.  At a very basic level, companies should be ensuring they have key personnel assigned, such as CIO, CISO, CPO, and they should review annual budgets, review assessments of security programs, and receive reports on security breaches and incidents and risks the company faces from IT.

Rank: Cave Painter

We're waiting for Jody to arrive here on the chat board. In the meantime, please restate your questions if they weren't answered on the audio.

Thinkernetter

Thanks Jody.Very much appreciate the interview.

Thinkernetter

Thanks Jody.

Thinkernetter

Thanks Jody !

Rank: Cave Painter

@Jody-Do u need to have 24/7/365 Monitoring in the Enterprise with Logs,etc to keep up with the Speed of Zero Day attacks?

Thinkernetter

Hi everyone. Thank you, Jody Westby, for a terrific interview!

Thinkernetter

My question for Jody: Are you against cloud services altogether for security reasons?

IQ Crew

What are some specific precautions/best practices do you recommend, the government and really all of us take (before during and after) moving to IPv6 IPv4 dual stack? 

Rank: Cave Painter

I think we can be certain criminals are using social media sites, for example for spear pfishing.

Thinkernetter

@Mark-How do u do that?Was just listening to a blackhat ppt.Its so so difficult for anyone with a lot of organization to keep up with this flow.

Thinkernetter

Will, InfoWeek: If you could re-post your questions so Jody can see them up top, that'd be great. And anyone else who has questions, please share them now! Aum, lin, kkohli, etc.!

IQ Crew

I think a few hard-hitting negligence suits would concentrate enterprises' minds wonderfully.

Thinkernetter

Hey everybody: Jody is coming over to the live chat. So please start posting your questions for her.

IQ Crew
Borefest
Rank: Cave Painter

Have to agree, Mark K.  Combatting cybercrime is a noble objective, but enterprises can't wait for victory.  Like waiting for victory in the war on drugs.

Thinkernetter

Most of the laws and international effort are too slow and too late.  Like closing the barn door after the cows are out.  Prevention is key.

 

Rank: Cave Painter

Thanks Will. We'll get your question asked on air or here on the board after the show.

IQ Crew

What frightens me most is that they have the capability to store every single message/Email/Webpage for posterity.It freaks me out!

Thinkernetter

Jody:

  Is Continuous Montioring a paradigm shift and what will be its impact on cybersecurity?

 

Will

Thinkernetter

We pursue bank robbers, but banks have locks.

Thinkernetter

@lin: Gotcha. Was just curious if it was all Web mail or specifically Gmail you were concerned about.

IQ Crew

@Kim-Who said they can't?

Is'nt that what the UTAH Datacentre is for is'nt it???

http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/all/1

Thinkernetter

Intelligence agencies are forbidden from spying on citizens?

IQ Crew

@LIN-Couldnt agree more.GMAIL is different.

Thinkernetter

I am having some difficulty with the proposition that the intelligence community can't spy on US residents.

Thinkernetter

@Nicole - Gmail is different.  I don't believe Hotmail or Yahoo put out their mail products with the intention to aggregate/mine the data and extract revenue from it.   Also, I don't believe that Hotmail/Yahoo keep every email forever.

IQ Crew

In-Q-Tel comes up! Yes.

IQ Crew

Finally she hits on the key point-THE PLANTS ARE NOT HERE ANYMORE!!!

Thinkernetter

@aum: I don't think she said no cloud at all just yet.

IQ Crew

Google mines my gmail, finds names of people I don't know or who I corresponded once, and recommends them for my Google+ circles.

Shameless and stupid.

Thinkernetter

@lin: Do you think Gmail is different than Hotmail or Yahoo mail in that regard?

IQ Crew

Wow! No cloud at all?? I am amazed.

Thinkernetter

Totally agree re gmail.  Never have used this for business.  My understanding is that Google never discards an email and they have some incredibly impressive data mining tools created to extract information from aggregated data.  Plus I got scared when I read some of the patents that google put out that talk about mining data from mail.  

IQ Crew

hellooooo!!!

Thinkernetter

Did she say how we knew for sure it was China Google was referring to? My audio cut out for a moment.

IQ Crew

That's what I was wondering Kim.

IQ Crew

So, Jody's firm avoids cloud altogether?

Thinkernetter

US moral high ground. Phrase makes me giggle a bit.

IQ Crew

Yeah I feel pretty confident about that story, Kim.

IQ Crew

I have to say, multiple sources in a Times story can't be dismissed so easily.  The Times knows the names of the people Sanger spoke to, and the Times editorial staff is not dumb.

Thinkernetter

Kind of not surprising, of course, that the government wouldn't admit that...

IQ Crew

@InfoWeek: Thanks for the question. Feel free to keep them coming.

IQ Crew

@wfoster I saw your email -- are you hearing the audio loud and clear?

IQ Crew

? In your opinion, is the usage of Cloud more prevalent in the consumer area or business arena

Rank: Cave Painter

The US is in good shape compared to the rest of the world. So, does that mean we're doing well? Or the rest of the world is just doing horribly?

IQ Crew

US cybersecurity: good, but not as good as it should be.

Thinkernetter

I do want to hear about her work w/In-Q-Tel, the CIA's investment arm...

IQ Crew

Here we go.

Thinkernetter

Here we go. The audio is now LIVE.

IQ Crew

If anyone wants to get questions in early, please feel free to post them here.

IQ Crew

Hi InfoWeekRGS. Welcome!

IQ Crew

Good day to all.

Rank: Cave Painter

Jody Westby is ready to chat once the audio closes at 2:30 ET.

Thinkernetter

Excellent! We'll ask as many of your questions as we can on the air, but in case we don't get to them, she'll answer them here on the chat board after the live audio program.

IQ Crew

I have read a couple articles by Jody Westby and have some questions for her

 

Thinkernetter

Say "helloooooooo!" when you arrive.

IQ Crew

Hey everybody! Getting excited for this show.

IQ Crew

Hello to all :)

Rank: Cyborg

I'll be there

Rank: Cave Painter
IBM information resources
IETV: the thinkerNet on film
5
of
John Kennedy
How Big-Data Is Changing Marketing

6|13|13   |   1:07   |   1 comment


Big-data and analytics tools enable marketers to understand customers as individuals, identifying unmet needs and addressing each customer as a "segment of one," says John Kennedy, VP corporate marketing, IBM.
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   10 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   1 comment


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
2pm EDT
Fri
Jun 21st
an IBM information resource
sponsored content
big blue blog
Todd Watson
Todd Watson   6/18/2013   Post a comment
The IBM Smarter Commerce Global Summit in Monaco kicked into high gear today, and we've already begun to see news emerging from that lovely city-state by the sea.
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Taking a Dim View of Home Energy Management Tech
Mary E. Shacklett
Energy consumption is a primary contributor to
global warming. At the end of 2012, 40 percent of energy consumption in the US came from commercial and residential buildings.

CLICK FOR MORE