{"id":2174,"date":"2023-12-08T20:42:00","date_gmt":"2023-12-08T20:42:00","guid":{"rendered":"https:\/\/www.darkreading.com\/ics-ot-security\/larger-attacks-could-lead-to-increased-cyber-regulation"},"modified":"2023-12-08T20:42:00","modified_gmt":"2023-12-08T20:42:00","slug":"increased-cyber-regulation-in-the-offing-as-attacks-mount","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/12\/08\/increased-cyber-regulation-in-the-offing-as-attacks-mount\/","title":{"rendered":"Increased Cyber Regulation in the Offing as Attacks Mount"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt2b00f4d1d71157ba\/65733fef434df1040aab915f\/Jeff_Moss_BHEU_Dan_Raywood.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">BLACK HAT EUROPE 2023 \u2014 London \u2014<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;Expect governments to impose greater levels of cybersecurity regulation if businesses cannot defend against major attacks and stop breaches from happening.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">That&#8217;s a prediction from Black Hat founder Jeff Moss, speaking at Black Hat Europe in London this week. He believes that eventually, the world will come to a tipping point where too many highly impactful breaches and escalating infrastructure hits from nation state-sponsored attackers will spur governments to act.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Self-regulation is not working,&#8221; he noted from the keynote stage.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Moss also said that security could head towards a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cybersecurity-operations\/what-the-boardroom-is-missing-cisos\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Sarbanes Oxley<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (SOX) moment, a US law implemented after the 2001 collapse of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/time.com\/6125253\/enron-scandal-changed-american-business-forever\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Enron<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that protects investors by auditing for fraudulent accounting and shady financial practices at publicly traded companies. Achieving <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.sarbanes-oxley-101.com\/sarbanes-oxley-audits.htm#:~:text=The%20Sarbanes%20Oxley%20Act%20requires,reports%20are%20also%20a%20requirement\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">SOX compliance<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> requires financial reports to include an internal controls report to show that a company&#8217;s financial data is accurate, and adequate controls are in place to safeguard financial data \u2014 and one can easily see how that could translate to cybersecurity auditing.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Regulation Needs to Be Nuanced<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Meanwhile, Black Hat Europe keynote speaker and former Uber CISO <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/6-years-of-silence-former-uber-ciso-speaks-out-on-data-breach-solarwinds\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Joe Sullivan<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> (who himself has been convicted of and on probation for fraud for failing to alert regulators of a 2016 cybersecurity breach at the ride-share giant) stresses that regulators need to be level-headed in terms of who should be held accountable for keeping people safe, and consider the realities of how data breaches and their containment play out on the ground. Should someone face jailtime for succumbing to social engineering, for instance? Is the CFO who doesn&#8217;t think two-factor authentication fits the company budget on the hook for fines when an account takeover leads to a ransomware attack? What about the security team who failed to appropriately make the case for it?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Speaking to Dark Reading, Sullivan uses the example of the SEC&#8217;s newly implemented data-breach reporting rules; when the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.sec.gov\/news\/press-release\/2023-139\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">SEC put a request out <\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">for feedback on a draft set of the rules, it failed to incorporate insight from those working in the trenches, he alleges.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;I wish the security community would actually give them feedback, not just the [victims affected by breaches],&#8221; he says. &#8220;I think most of the people who have sat in those government seats have never sat in the CISO seat or the security engineer seat, and they&#8217;re not going to have empathy.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Even so, a regulatory approach, if done correctly, could make security a whole-of-company focus, which could lead to positive outcomes in terms of preparedness and defenses, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;[The] regulators&#8217; message is, &#8216;if you&#8217;re not going to keep people safe, there is going to be consequences,'&#8221; he notes. &#8220;We need that to be heard at the highest levels of the company, not just at the security level of the company, and then we&#8217;ll get real change.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/ics-ot-security\/larger-attacks-could-lead-to-increased-cyber-regulation\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>BLACK HAT EUROPE 2023 \u2014 London \u2014&nbsp;Expect governments to impose<\/p>\n","protected":false},"author":12,"featured_media":2175,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2174","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount-scaled.jpg?fit=2560%2C1928&ssl=1",2560,1928,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount-scaled.jpg?fit=300%2C226&ssl=1",300,226,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount-scaled.jpg?fit=640%2C482&ssl=1",640,482,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount-scaled.jpg?fit=640%2C482&ssl=1",640,482,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount-scaled.jpg?fit=1536%2C1157&ssl=1",1536,1157,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount-scaled.jpg?fit=2048%2C1542&ssl=1",2048,1542,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount-scaled.jpg?fit=1024%2C771&ssl=1",1024,771,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/increased-cyber-regulation-in-the-offing-as-attacks-mount-scaled.jpg?fit=2560%2C1928&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2174","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2174"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2174\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2175"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2174"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2174"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2174"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}