July 11, 2016 By Douglas Bonderud 2 min read

Corporations aren’t known for sharing. With so many employees, partners, providers and customers to manage, there’s always a chance for data compromise — so why risk it by sending more information around? And thanks to the rise of wearables, always-connected devices and the industrial IoT, these risks are growing.

The bigger problem? Malicious actors have no trouble swapping stories of compromise and successful attacks, putting the onus on companies to embrace security collaboration if they want to keep their networks safe. How do businesses trump the trust issue?

Is Security Collaboration Counterintuitive?

As noted by CIO, security firm Carbon Black is now “opening a line of communication” between companies with its new platform, the Detection eXchange. The idea here is to go beyond surface information such as virus signatures or IP addresses to share actual data about attack patterns and threat vectors. After all, it’s nothing for attackers to swap out a flagged IP address, but if they find typical attack patterns blocked at every turn, they’ll be left scrambling to change their ways.

Of course, security-savvy IT pros have raised a valid concern: If the goal of security firms is to protect key data, does it really make sense to share critical information? In the case of Carbon Black, for example, the government ultimately acts as a clearinghouse for shared data. It’s not a stretch to imagine this repository as a high-value target for cybercriminals, and once they have the inside track on how companies plan to deal with emerging threats, they can simply change tactics.

So while security collaboration sounds great, many companies balk at the idea of actually participating or share only the bare minimum required to ensure their own critical processes can’t be compromised.

Building a Better Mousetrap

The calls for national and global threat sharing frameworks are getting louder: As noted by SC Magazine, a recent cybercrime report from the U.K.’s National Crime Agency (NCA) argued that greater threat sharing is essential now that digital crime has outpaced traditional lawbreaking in the country. Additionally, TechCrunch made the case for a worldwide cyberthreat sharing program to help combat adaptive attackers.

Already, the Cybersecurity Information Sharing Act of 2015 (CISA) makes it possible for companies to share security information with the Department of Homeland security without facing legal ramifications for reporting data breaches in good faith. According to Dark Reading, however, any type of threat sharing framework is effectively a gamble since cybercriminal access to threat feeds negates any positive impact.

The piece does offer a few suggestions, however. For example, machine-to-machine-only threat feeds integrated with SIEM tools could be an option, along with completely anonymous reporting and the elimination of opt-in programs. Since corporations understandably value their privacy and freedom of action, this may be a case where anonymous, mandated reporting outweighs the benefit of opting to stay silent.

Companies are right to be wary of large-scale security collaboration initiatives. What if attackers grab control of this emerging threat playbook and use it to run an entirely new game? But hunkering down behind supposedly secure digital walls does nothing to improve the outcome. Trumping the trust issue is a rough ride but — win or lose — a unified security front gives companies a fighting chance.

More from

How will the Merck settlement affect the insurance industry?

3 min read - A major shift in how cyber insurance works started with an attack on the pharmaceutical giant Merck. Or did it start somewhere else?In June 2017, the NotPetya incident hit some 40,000 Merck computers, destroying data and forcing a months-long recovery process. The attack affected thousands of multinational companies, including Mondelēz and Maersk. In total, the malware caused roughly $10 billion in damage.NotPetya malware exploited two Windows vulnerabilities: EternalBlue, a digital skeleton key leaked from the NSA, and Mimikatz, an exploit…

3 Strategies to overcome data security challenges in 2024

3 min read - There are over 17 billion internet-connected devices in the world — and experts expect that number will surge to almost 30 billion by 2030.This rapidly growing digital ecosystem makes it increasingly challenging to protect people’s privacy. Attackers only need to be right once to seize databases of personally identifiable information (PII), including payment card information, addresses, phone numbers and Social Security numbers.In addition to the ever-present cybersecurity threats, data security teams must consider the growing list of data compliance laws…

ICS CERT predictions for 2024: What you need to know

4 min read - As we work through the first quarter of 2024, various sectors are continuously adapting to increasingly complex cybersecurity threats. Sectors like healthcare, finance, energy and transportation are all regularly widening their digital infrastructure, resulting in larger attack surfaces and greater risk exposure.Kaspersky just released their ICS CERT Predictions for this year, outlining the key cybersecurity challenges industrial enterprises will face in the year ahead. The forecasts emphasize the persistent nature of ransomware threats, the increasing prevalence of cosmopolitical hacktivism, insights…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today