Papers
Is it time to consider a radical change in the way we organise and manage the response to cybercrime?
Simon Newman, Co-Founder, Cyber London, UK
Abstract ▼
The growth of cybercrime continues to be a major threat to national security. With high-profile cyberattacks disrupting supply chains around the world, policy makers are constantly looking at ways to tackle it effectively using the levers available to government. But as we have seen over the last few years, the problem continues to grow, forcing policy makers to reconsider their thinking in how to reduce the threat and impact of cybercrime. The election in the UK of a new Labour Government in July 2024 with a large majority provides an opportunity to review the existing approach and implement a more radical solution, informed by best practice elsewhere. The challenge, however, is in building a model that not only brings together a complex group of stakeholders across government and beyond, but which also improves accountability and transparency while future-proofing the response to a rapidly changing policy area.
Keywords: cybercrime; strategy; coordination; international; accountability
Rethinking user password management
Bryan Christ, Chief Information Officer and Chief Technology Officer, Bravura Security, USA
Abstract ▼
This paper critically examines the continued reliance on passwords despite its flaws. It explores how the inherent cognitive limitations of users — exemplified by Miller’s Law and the challenges of short-term memory — contribute to insecure practices such as password reuse and reliance on easily remembered, yet predictable, password structures. The paper reviews historical and contemporary research on user behaviour in password creation, highlighting how increasing complexity requirements often lead users to adopt counterproductive shortcuts and coping mechanisms. In addition to dissecting the cognitive challenges, the paper evaluates current security practices including multi-factor authentication (MFA) and highlights some prominent weaknesses. The paper proposes abandoning current password practices, which are user-centric, and adopting a new paradigm. In this model, principles are drawn from solutions in the privilege access management (PAM) and password manager realms to craft an architecture that balances security and convenience while eliminating cognitive burden. Readers will take away a comprehensive understanding of the limitations of traditional password systems, insights into modern authentication methods, and a roadmap for adopting more user-friendly and robust security practices that shift the responsibility of password complexity away from the end user.
Keywords: password management; password fatigue; password hygiene; forgetting passwords; password rotation; password complexity
Developing cyber resilience through cyber incident response capability improvement: Presenting the cyber incident response capability development life cycle model
Murray Goldschmidt, Executive Director for Cyber Capability, Education and Training, CyberCX, Australia
Abstract ▼
In the face of a deteriorating cyber threat landscape, it has never been more important for entities to prepare for a cyber incident. This paper presents the cyber incident response capability development life cycle, a cumulative and iterative approach to considering cyber threats from multiple dimensions to identify capability gaps and providing the opportunity for focused skill uplift. The life cycle addresses all aspects of cyber incidents and provides innovative approaches to accommodating the needs of all stakeholders across all roles in an entity, from simplified exercises to complex simulated events. Exercising incident response plans and the associated playbooks is a feature of all standards and frameworks, and consistently recommended through government and regulatory advice.
Keywords: cyber resilience; incident response; threat actors; nation state threats; organised crime; ransomware; cyber extortion; insider threats; board and director duties; first responders; incident response plan; playbooks; runbooks; crisis communications; critical infrastructure; cross domain threat hunting; cyber security framework; cyber security incident; cyber security risk management; incident handling; incident management; incident response
SPOT: A data-driven threat detection framework with knowledge-enhanced scoring
Derek Lin, Chief Data Scientist, Exabeam, USA
Abstract ▼
In an era when digital threats are becoming increasingly sophisticated and pervasive, the need for robust cyber security measures has never been more critical. Traditional methods based on fact or correlation rule matching are insufficient. Machine learning (ML) for dynamic behaviour modelling and automated scoring is now crucial for effective threat detection. This paper introduces SPOT, a practical threat detection and scoring framework and system for user and entity behaviour analytics (UEBA). The framework comprises layered modules: data-driven ML for event scoring; event organisation into meaningful threats; and threat re-prioritisation based on business knowledge factors. The system architecture supporting this framework leverages a stream-based distributed computing platform enabling Cloudscale processing for high-fidelity threat identification.
Keywords: threat detection; scoring; prioritisation; machine learning; UEBA
Govern once/comply many: Leveraging cyber security framework experience to support AI governance
F. Paul Greene, Partner, Harter Secrest & Emery, USA
Abstract ▼
Data protection is notoriously complex and artificial intelligence (AI) has only added to that complexity. In addition, many organisations are floundering as they seek to adopt AI in an ethical and trustworthy manner. This paper addresses skill sets and frameworks familiar to IT and cyber security professionals that can be leveraged to help build a robust approach to AI governance. Adopting the maxim of ‘govern once/comply many’, the paper compares and contrasts existing cyber security frameworks and approaches that address the governance concerns that arise with AI. It also uses the National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework as a lens through which to assess the utility of cyber security frameworks to inform AI governance efforts. Generally, the map, measure, manage and govern functions of the NIST Artificial Intelligence Risk Management framework align well with the confidentiality, integrity, and availability foci of established cyber security frameworks, forming the beginnings of a common language, when it comes to issues of data protection and AI governance.
Keywords: artificial intelligence; cyber security; governance; framework
The art of cyber war: Sun Tzu’s ancient wisdom in modern threat intelligence
Lior Arbel, Ex-Chief Executive Officer, Elemendar, UK
Abstract ▼
This paper explores the enduring relevance of Sun Tzu’s The Art of War, written in the 5th century bc, to modern cyber security practices. It examines how the ancient strategist’s principles can be applied to enhance threat intelligence and cyber defence strategies in the digital landscape. The paper discusses five key principles from Sun Tzu’s work: knowing oneself and the enemy, the use of deception, winning without combat, the importance of speed and adaptability, and the use of alliances. Each principle is contextualised within current cyber security challenges and illustrated with real-world examples and case studies. The paper emphasises the critical importance of making cyber threat intelligence more accessible and actionable. It concludes by highlighting the enduring value of combining timeless strategic wisdom with cutting-edge technology to create more robust and effective cyber defences.
Keywords: Sun Tzu; cyber security; threat intelligence; cyber defence; strategy; deception; proactive defence; information sharing
Security audits on artificial intelligence systems
Robert Kemp, Senior Security Manager, University of Portsmouth, UK
Abstract ▼
Auditing is important for ensuring security and compliance for artificial intelligence (AI) systems. Unlike traditional software security audits that primarily address well-documented vulnerabilities, AI systems introduce distinctive challenges due to their reliance on complex machine learning (ML) models and expansive data pipelines. This paper presents key considerations for a security audit specifically tailored for AI systems, emphasising core components such as model robustness, adversarial defences, penetration testing, data privacy compliance and continuous monitoring. It systematically identifies crucial areas of focus, including data sources, ML models and application interfaces, while also detailing specialised security tools such as the IBM Adversarial Robustness Toolbox and Microsoft Counterfeit. Furthermore, the paper integrates established security standards and methodologies, including the MITRE Adversarial Threat Landscape for AI Systems (ATLAS) and the NIST AI Risk Management Framework, to address the unique threats posed by AI technologies. By adopting this holistic auditing approach, organisations can enhance the resilience of their AI systems against evolving cyber threats, thereby ensuring their operational reliability and compliance with regulatory standards.
Keywords: artificial intelligence; audits; cyber security; assurance; frameworks
Why failure to comply with state contract cyber security and privacy requirements is increasingly likely to result in State Attorneys General enforcement
Ashley L. Taylor, Jr.,Partner, Troutman Pepper, USA, Gene Fishel, Counsel, Troutman Pepper, USA and Dan Waltz, Associate, Troutman Pepper, USA
Abstract ▼
State Attorneys General (AGs) are increasingly leveraging state false claims laws to enforce cyber security and privacy requirements in government contracts. This shift poses significant risks for state and local government contractors, as non-compliance can lead to penalties exceeding the contract’s value. Following the Department of Justice’s (DOJ) success with the False Claims Act and the Cyber Fraud Initiative, State AGs are recognising the potential for substantial revenue and public approval through these statutes. Traditionally used for Medicare and Medicaid violations, state false claims acts are now being applied to a broader range of contractual obligations, including cyber security. Recent DOJ settlements with contractors highlight the serious consequences of non-compliance. Contractors must be proactive in ensuring compliance with cyber security requirements to mitigate the risk of false claims litigation. This involves robust compliance policies, clear communication channels and thorough documentation of efforts to meet contractual obligations.
Keywords: state false claims laws; cyber security requirements; privacy obligations; government contractors; qui tam provision; data breach notification; civil cyberfraud initiative; compliance programme
The AI security zugzwang
Lampis Alevizos, Head of Cyber Defence, Volvo Group, The Netherlands
Abstract ▼
In chess, zugzwang describes a scenario where any move worsens the player’s position. Organisations face a similar dilemma right now at the intersection of artificial intelligence (AI) and cyber security. AI adoption creates an inevitable paradox: delaying it poses strategic risks, rushing it introduces poorly understood vulnerabilities, and even incremental adoption leads to cascading complexities. In this paper we formalise this challenge as the AI security zugzwang — a phenomenon whereby security leaders must make decisions under conditions of inevitable risk. Grounded in game theory, security economics and organisational decision theory, we characterise AI security zugzwang through three key properties: forced movement, predictable vulnerability creation and temporal pressure. Additionally, we develop a taxonomy to categorise forced-move scenarios across AI adoption, implementation, operational and governance contexts and provide corresponding strategic mitigations. Our framework is supported by a practical decision flowchart, demonstrated through a real-world example of Copilot adoption, thereby showing how security leaders can manage zugzwang positions balancing risk and innovation.
Keywords: AI cyber security; zugzwang; security decision making; cyber security strategy; forced security moves; innovation