HomeinetCyber ​​Security, secrecy and responsibility

Cyber ​​Security, secrecy and responsibility

Cyber Security; Today we will dare something different. The following introduction is necessary to get better into the atmosphere. iGuRu.gr, as well as our friends from SecNews.gr, publish from time to time large titles of online attacks.

Here we note that we publish ONLY the attacks that were successful.

Cyber Security Cyber Security Cyber Security

Import

Can you imagine then what happens on a global level if some decided to publish attacks that were not successful?

Checking the logs on the server hosting iGuRu.gr, we observe daily hundreds of such attacks, automated by bots as well as by aspiring hackers who seem to have studied the website's structure quite a bit.

It is also known that our website and our friends from SecNews sometimes publish vulnerabilities in important websites and online infrastructures.
So while these publications abroad are something normal, and help to disclose the vulnerability and force an immediate fix, in Greece it is always a risk.
In Greece we are used to hiding all this under the carpet, and it stays there, accumulating until someone lifts it.

However, the phenomenon of the carpet is not observed only in Greece.

Cyber ​​Security

Information about the somewhat successful or successful cyber attacks on companies and government services often remains hidden. Despite the efforts of specialized and reliable security companies, services and companies rarely share critical information, rarely cooperate for security audits, and very rarely issue timely warnings for other organizations that may be at risk.Cyber Security Cyber Security Cyber Security Cyber Security Cyber Security

However, let's also talk about today's companies that work in the field of cyber security defense. Each piece of information remains locked in their “cabinets” as they translate it into dollars. Have you noticed security companies collaborating for the common good? The phenomenon is very rare, like exceptions that confirm the rule.

Why is it so difficult to understand that the exchange of such information and collaboration can contribute to solving problems and managing risks in many other areas?

What lies behind this long‑standing corporate reluctance to share information about attacks (successful or not) in cyberspace?

Why every time we want to publish such information, we examine 1000 possibilities, fearing a legal system that was created before the Internet?

The report of each incident can only bring good to the collective interest, but individual participants may face all kinds of legal problems, reputation problems, or market decline if it is heard that they are victims of hacking.

The Internet has no limits, and there are no armored doors. Digital locks consist of binary digits. Thus, breaches are inevitable, and as we have seen, they also happen in “best families.”

Hesitation and secrecy protect no one, and sustain a myth as well as a legal system that cannot protect today's digital world.

The release of data can help us understand the full magnitude of a vulnerability, something that will play a crucial role in our defense.

Proposals?

All of the above is not easy, as it contains words that many do not like: Responsibility and Exile.

Beyond each of our individual responsibilities, service providers, security companies, and governments also bear responsibility.

Perhaps recently we have seen examples (that confirm the rule) of suppressing attacks by alliances of security companies (Microsoft, Symantec, Kaspersky, etc.) but one rooster does not bring Spring.

A framework should be organized that will allow businesses to share incident data with others anonymously. This approach will limit the risk of a bad reputation, through exposure.

States now, because everyone needs the support of the government.

Legal tiers and lawmakers should seriously consider the possibility of waiving legal liability for companies or individuals who choose to exchange incident data for the purpose of combating cyber attacks, providing timely warning to others at risk.

Advanced? Probably not, for the simple reason that the Internet now runs faster than us.

Why scandal? This goes to security companies, which should start acting collectively… overlooking profits…. or discovering new sources of wealth.

With a final account we understand that the least utopian scenario is the release of data by law.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS