Ways of dealing with cyber threats– May 2015
General:
One of the more prominent characteristics of the 21st century is the ever increasing dependence on communications and the digital world. Over the past 10 years, organisations, institutions and commercial bodies have, as the result of technological innovations in the field of communications, its spread and availability to the market, significantly changed the way they conduct their activities. At the same time, in the private sector as well, billions of people are connected to social networks and making calls with mobile telephones.
The following figures may seem to be imaginary, but they constitute a real reflection of the revolution taking place in the field of information transfer both in the business world and in our private lives. During a period of less than one minute the following activities take place:
More than nine billion email messages are sent, purchases are made on Amazon in excess of 3.5 million dollars, more than 90 million searches are made on Google and over 18,000 different applications are downloaded from the internet.
This is a phenomenal and almost unimaginable volume of information being transferred. It creates, for institutions, organisations and commercial companies as well as for private individuals, an endless number of opportunities that, in essence, change our lives.
Alongside these amazing benefits, a threat has also developed. A threat that has become more widespread and recognised over the past 10 years – the cyber threat. Even though its beginnings can be found in the power struggles between world powers during the 80s of the previous century, over the past years cyber threats have become a very real threat to many countries, organisations and commercial companies across the globe.
A survey published in Israel in 2015 shows that 50% of Israeli organisations have suffered cyber-attacks over the past three years. Some 20% of the companies were attacked by terror organisations and some 13% of managers were not even aware if their organisation had suffered some form of attack. The general assumption is that more than 60% of Israeli companies are unprepared to combat a cyber-attack. These are very worrying figures and we can assume that the situation in most Western countries is similar or even worse.
Today, it is clear to governments and their leaders that a cyber-attack is capable of causing significant damage and harm the country’s ability to maintain the constant functioning of critical systems essential for daily life. Managers of many commercial companies are also becoming increasingly aware that a cyber-attack could cause significant damage, both financially and in terms of the company’s image. Damage can be expected to levels of service, to clients and to monitoring and control systems. This could cause major damage to a company that was not prepared with the solutions necessary to hold of such an attack.
Where does your company stand in its preparedness against a cyber-attack?
Facts from the field:
It is estimated that by the year 2017 some 10% of large company and institution IT budgets will be devoted to providing protection from cyber-attacks.
Business organisations that have understood and accepted the need to find a solution to the ever increasing threat, have begun to identify solutions and answers that are capable of providing advance warning, filtering, blocking and neutralising a threat or damage to the organisational information systems. If, so far, the protection provided by a firewall, authorisation systems, classification and reports of identified abnormalities was sufficient, today the systems and mechanisms required to provide a solution must be far more advanced and complex.
Threats from outside the organisation, threats from inside the organisation (whether hostile or innocent), threats against external storage facilities, in the cloud, on servers, in communications and data transfer, threats when using a mobile phone and even more. All of these are examples of the many different areas that require a professional solution response.
Organisations have begun finding external experts and have hired them, even inside the company, for jobs that were previously unknown: CWS – cyber warfare specialist, CISO – Chief information security officer and other, similar positions. It is becoming increasingly understood that the human element, as part of the company’s assets, will make a difference in this field. The estimation is that terror and other hostile elements will also gain experience and increase their abilities. This can be expected to lead to increased technological developments and the need to identify, from all professions relevant to cyber threats, the best possible, highest quality manpower with unique characteristics at all levels.
Many companies have purchased external technological threat solutions and, at the same time, have recruited an internal leadership to coordinate and control activities in this area. Other companies have expanded their independent capability by recruiting an internal team that works with the company’s IT department to provide a constant and continuous answer to increasing threats. Some companies have established a ‘Cyber Room’ where a team operates throughout the week. Their task is to identify potential cyber-attacks against the system and to provide a warning and a solution as soon as possible in order to neutralise the threat and reduce damage to the minimum. Many companies also hold a quarterly exercise where a simulated attack is made on the company’s IT system. This is usually carried out by external companies with the expertise required to mount the attack using advanced tools. The aim of this simulated attack is to test the protection systems to see if they operate as expected.
The human solution:
Cyber has only become part of the academic curriculum over the past years. Many of those employed in this area became involved as the result of a need they identified and experience gained during their work. In contrast, we can point to the way in which professionals in this field are taught and trained in Israel. As the result of a national threat spanning many years and the development of world terrorism in this area as well as others, the State of Israel is exposed to a significant cyber threat and has been preparing to defend itself for many years. Many young people, just before they end their schooling, are identified as having the potential and the ability to develop into first rate experts in this field. Some are even identified as having sufficiently high qualities and abilities to qualify them to study for a degree whilst still at high school. These outstanding students are drafted into three years of Army service where they receive additional, specialised training to provide a defence against cyber-attacks and are posted to cyber defence positions that provide them a great deal of valuable experience in a highly intensive and innovative environment.
After their army service, these young people enter the job market having amassed knowledge and experience at a level that has no equal amongst others of their age around the world. Some remain in Israel’s security services, others are drawn into the many start-up companies working in this area in Israel, others resume their academic studies and many others are snapped up by commercial companies who, as already said, have understood the need to obtain protective capabilities against potential cyber-attacks.
Amongst these candidates there are those who are interested in taking on challenging positions outside of Israel. This may be to expand their professional experience and to experience working in a new country for a period of a few years before returning to Israel to establish themselves and build a family.
In addition to this unique 22 – 25 year old age range, we also find older people who have already amassed managerial experience in cyber defence systems. These are people who went through a similar process to that described previously and who progressed into managerial positions in Israeli commercial companies. There they gained practical, technical experience as well as managerial experience. They are now at a stage in their career were working in a company outside of Israel for a number of years could be attractive both from a professional, career viewpoint and a personal one.
As a result of this reality, there is increased competition for programmers and engineers with knowledge and experience in the cyber field which, in return, has led to increased wage demands from those working in the field. This trend is expected to continue and increase next year and, in all likelihood, the year after.
Whitepaper – executive summary May 2014
Cyber Security – how to find the right talent for multinational companies
1. Why should any multinational company already have its own cyber security defense strategy
Computer security (also known as cyber security or IT security) is information security as applied to computing devices such as computers and smartphones, as well as computer networks such as private and public networks, including the Internet as a whole.All of them are prone to multiple attacks, often from the inside. The trend to offload data into the cloud and allow employees to bring their own device ( BYOD ) accelerates the need of companies to gain in-house knowledge in the field of cybersecurity.
Not just since the public has learned of the potential size of intrusion into databases through the well-known NSA scandal in 2013 have multinational companies been aware of their own exposure. The next biggest threat to industrial espionage is by now organized crime.
Symantec, a security firm, estimated that cybercrime costs the world $113 billion a year; it puts the number of victims at 378m. The Ponemon Institute, another research outfit, reckons that in 2012 malicious attacks cost American companies $277 for each customer’s or user’s account put at risk, a lot more than the cost of leaks caused by technical glitches or mistakes by employees.
To find the right candidates to tackle the increasing amount of tasks turns often out to be a quite difficult challenge for the IT and HR departments alike. Either the talent is just not available if local citizenship is being required for lack of proper vetting processes or the quality standards are not being met by many applicants.
Companies as well as government agencies like the US department of homeland security struggle to find, vet and then keep such talent in sufficient quantity.
2. Trends in Israel
Israel is a natural leader in cyber defense and made it part of its core defense strategy.
The IDF, Israel’s defense forces, changed their defense strategy years ago after learning the hard way what it meant to underestimate cyber. By now, it has various divisions specializing in cyber warfare. This talent pool of which part finds its way on a regular basis into the non-military world offers a unique chance for the country, its newly developed industry “cybersecurity” as well as for companies around the world to tap into.
The IDF are building out a major base in the southern city of Beersheva. This city with its famous university of Ben Gurion has been also called “Cyber Security City” and is attracting major global IT companies as well as nurturing many start-ups in its cluster.
In fact, in early 2014, multinational players IBM, Cisco, EMC, Lockheed Martin RSA and Deutsche Telekom all announced plans to set up cyber-research facilities in Cyber park, Israel’s new cyber-security technology park in Beersheva .
This has been driving a unique start-up culture in cyber security all over Israel with considerable investment
According to Dr. Eviatar Matania, head of Israel’s National Cyber Bureau, Israel’s cyber-security exports in 2013 totaled about $3 billion – 5% of the global market and three times greater than Britain’s. And to top it off, 11% of all money raised for cyber-security firms in 2013 were raised for Israeli companies – a total of $165 million. There are at least 200 cyber-security start-ups in Israel, 100 of which were formed in the past year. And, he added, 20 multi-national companies had cyber-security R&D firms in Israel.
But this mushrooming trend which is reflected by curriculums of many Israeli universities and the demand of cyber security know-how by many established and newly founded companies made Israel very unique – effectively, it is the only country which has a certain surplus of talent in this area.
For many Israelis English is a natural second language and many young Israelis would like to gain work experiences abroad.
3. The choice is yours
Many IT departments insist to hire national talent believing that the vetting process is easier and safer. Already, companies might then fight for talent with national government agencies where such policy is often mandatory. It also contradicts the belief that Cyber Security is a global threat and a multi-cultural and diversified team is better suited to anticipate or deal with attacks or other IT incidents.
On the other hand, many multinational companies open of research centers or other forms of presence in Israel itself. This might help but won’t ultimately bring the solution to the problem.
Multinational companies need to protect their core IT infrastructure which is often based with or near their global headquarters. It is not feasible to “protect” core assets remotely using the global communication networks of third parties like telco operators.
It is therefore recommended to fine tune the HR policy for hiring based upon a well-defined IT strategy for cyber security.
4. Our solutions
We at ERELHR are first helping our customers to define and detail their search mandates. We engage with the respective HR departments as well as the actual business owners, often even offering fact finding trips to Israel, if required.
We work closely with the IDF, security organizations, universities and well connected to the business community in Israel.
Over the years we have relocated candidates globally, head hunted and recruited individuals and teams for international companies. Our presence in Israel and all the above allows us to conduct the best search for professionals in the field of cyber security.