October 11, 2017 By Kelly Kane 3 min read

Speaking at the Cambridge Cyber Summit hosted by CNBC and the Aspen Institute in Cambridge, Massachusetts, last week, Marc van Zadelhoff, IBM Security’s general manager, provided the audience with the three pieces of advice he’d like to share with a company’s business leaders six months before it suffers a data breach.

“The truth is, while we love to talk about the advanced nature of the attacks, the actual defense side is still lacking in basic hygiene,” said van Zadelhoff.

In this letter, van Zadelhoff said he would tell the CEO to focus on security basics, leverage artificial intelligence (AI) for the basics and beyond, and prepare for the response as much as you would to prevent it.

Watch Marc van Zadelhoff’s speech at the Cambridge Cyber Security Summit

Never Give 95 Percent When You Can Give 100 Percent

Van Zadelhoff described how organizations and the security industry love to talk about the advanced nature of cyberattacks. However, he’s seen many examples where organizations could have helped prevent a major cyberattack by following the basics 100 percent. For example, one company had 95 percent of software vulnerabilities patched, but the unpatched 5 percent led to a breach and significant system outages.

“Security hygiene needs to go in the direction of other programs that we have in the private sector. Think, for example, safety. If you’re running an oil rig, you don’t say we were 95 percent safe this month,” said van Zadelhoff.

Leverage Artificial Intelligence for the Basics and Beyond

He also noted that security basics are becoming much more difficult to manage because organizations are faced with an overwhelming amount of security data coupled with a significant skills shortage. With 60,000 cybersecurity blogs published every month, no security analyst can physically read and ingest all of that information, which is where machine learning and AI can help.

Van Zadelhoff shared the example of his team responding to a breach and applying user behavior analytics (UBA) to an organization’s basic logs, along with three different types of machine learning, bringing in active directory and HR information. After doing this, van Zadelhoff said his team was able to determine which identities had been taken over by the attackers, quarantine the endpoints and deprovision the identities to make sure the fraudsters were removed from the system quickly.

“This is a huge opportunity where AI does something that wasn’t possible a year or two ago,” said van Zadelhoff.

Prepare Your Response to a Data Breach

The final thing van Zadelhoff shared was the importance of understanding what it’s like to experience a cyberattack and how to deal with it before it happens.

This includes the entire timeline of a cyberattack, both before and after what IBM calls the “boom” event, or when the attack is made public. Many companies want to focus on what happened before the boom event, or left of boom, which is all about detecting a breach. But companies don’t often think about right of boom and what will happen after the attack. To get a handle on this area, security professionals should ask the following questions:

  • What is going to happen next?
  • Who do you call, and how can you get in touch with them when systems are down?
  • What would you say to the media to explain what happened?

“A lot of times the response to the breach can be more damaging than the breach itself,” van Zadelhoff said in his closing statement. “A focus on practicing response can help organizations get through a breach and make a game-changing difference.”

Click here to watch the video of Marc van Zadelhoff’s complete talk at the Cambridge Cyber Summit.

More from

NIST’s role in the global tech race against AI

4 min read - Last year, the United States Secretary of Commerce announced that the National Institute of Standards and Technology (NIST) has been put in charge of launching a new public working group on artificial intelligence (AI) that will build on the success of the NIST AI Risk Management Framework to address this rapidly advancing technology.However, recent budget cuts at NIST, along with a lack of strategy implementation, have called into question the agency’s ability to lead this critical effort. Ultimately, the success…

Researchers develop malicious AI ‘worm’ targeting generative AI systems

2 min read - Researchers have created a new, never-seen-before kind of malware they call the "Morris II" worm, which uses popular AI services to spread itself, infect new systems and steal data. The name references the original Morris computer worm that wreaked havoc on the internet in 1988.The worm demonstrates the potential dangers of AI security threats and creates a new urgency around securing AI models.New worm utilizes adversarial self-replicating promptThe researchers from Cornell Tech, the Israel Institute of Technology and Intuit, used what’s…

Passwords, passkeys and familiarity bias

5 min read - As passkey (passwordless authentication) adoption proceeds, misconceptions abound. There appears to be a widespread impression that passkeys may be more convenient and less secure than passwords. The reality is that they are both more secure and more convenient — possibly a first in cybersecurity.Most of us could be forgiven for not realizing passwordless authentication is more secure than passwords. Thinking back to the first couple of use cases I was exposed to — a phone operating system (OS) and a…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today