Feeds

Think-tank to infosec: You're doing it wrong

Cyber risks 'similar to 2008 crash'

Choosing a cloud hosting partner with confidence

Tomorrow's Internet is a scary, scary place, according to think-tank The Atlantic Council, so much so that we're all apparently on the brink of “a cyber sub-prime meltdown”.

The council has published a report co-prepared with Zurich Insurance which among other things recommends that ISPs should have redundancy in their peering connections, and countries should create redundant telecommunications and power suppliers (we're not making this up: you can read the announcement for yourself, here).

The full report says cyber risks are assessed “one at a time” rather than with reference to the whole system, which is says is “painfully similar to how financial risks were assessed prior to the 2008 crash”.

“Just imagine if a major cloud service provider had a ‘Lehman moment,’ with everyone’s data there on Friday, and gone on Monday. If that failure cascaded to a major logistics provider or company running critical infrastructure, it could magnify a catastrophic ripple running throughout the real economy”, the report states.

“Risk managers, regulators, and organisations with system-wide responsibility all need to focus more on resilience and agility rather than simply prevention.”

The report suggests Internet governance initiatives which include a “G20+20 Cyber Stability Board”, with formal recognition of what it calls “Global Significantly Important Internet organisations”.

More prosaically, organisations are urged to follow standard infosec procedures such as application whitelisting, prompt patching, and a minimum of users with admin privilege, while larger companies should have better board-level risk management, and should increasingly demand resilient and secure products.

“Cyber attacks of the future can and will affect globally interconnected systems like electrical grids and worldwide logistics systems. This Internet of tomorrow will be a source of global shocks for which risk managers, corporate executives, board directors, and government officials are not prepared,” The Atlantic Council states. ®

Beginner's guide to SSL certificates

More from The Register

next story
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
China is ALREADY spying on Apple iCloud users, watchdog claims
Attack harvests users' info at iPhone 6 launch
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.