Qatar
Call to make cyber security top priority
Call to make cyber security top priority
March 07, 2012 | 12:00 AM
By Ross JacksonStaff Reporter
The greatest threat countries today face is the theft of intellectual property by nation-states and cyber criminals, a cyber security expert yesterday told the Connect Arab Summit. Roger Cressey, senior vice president trust and security, Booz Allen Hamilton, said that the global cyber threat is no longer just “script kiddies”, but also “hacktivists” as well as countries and organised criminal groups launching constant attacks, using sophisticated techniques to attack networks and steal information.“The most important thing the United States has is its intellectual property, the same thing is true in Qatar, the same thing is true in Oman, and the same thing is true in the region,” said Cressey. He said that the “decisions that your government is going to make on natural gas, where the next investments that you are going to make, what critical infrastructure that you want to invest in, that is very valuable information and there are many nations out there that are actively seeking to steal that information.” Cressey said that the best way to deal with a “persistent threat environment” is to determine and prioritise the most valuable information and secure it. “It is hard to find a network that has not been penetrated, so you should assume that your network has already been penetrated.” Cressey made these comments during a panel discussion on cyber security, where other Computer Emergency Response Team (CERT) specialists agreed that security should not be reactive but proactive.Mohamed al-Ghanim, director general, Telecommunications Regulatory Authority (TRA), UAE, said that most GCC countries have focused on e-government and e-commerce, although key players have identified the need for, and followed up with, the creation of a virtual GCC CERT. Al-Ghanim explained that the objective was to instill in GCC countries the belief that cyber protection must not be responsive but proactive, highlighting the importance of training people and focusing on process and procedures. Panelists agreed that the greatest liability of any secure network is the people using it, and so proper training is an absolute necessity regardless of the software and equipment installed. They said that regional and international cyber security frameworks need to be re-evaluated, as a pan-Arab task force is currently working to this aim. The International Telecommunications Union and the UN Office on Drugs and Crime (UNODC) have recently signed an MoU to help build capacities and improve the capability of the UNODC in fighting cybercrime, but one panelist believes that a new specialized UN agency may be needed to deal with this unique and complicated threat. Cyber crime costs $1tn globally every year, and $626mn in the UAE alone.John Sandage, director, Division for Treaty Affairs, UNODC, said that his agency is currently the centre of judges, prosecutors and lawyers tackling cyber crime, but they struggle to deal with a threat that crosses borders and requires its own methods of forensic examination, investigation and prosecution.He said that a survey is currently being conducted, reaching out to thousands of people involved in the cyber crime field including the private sector, governments and academia to evaluate cyber security issues.Datuk Mohamed Noor Amin, chairman, International Multilateral Partnership Against Cyber Threats, said that cyber crime has risen exponentially, while successful prosecutions have not met that increase. “Usually, these are multi-jurisdictional crimes. It is really only a matter of time until there is a new global framework to deal with cyber crime,” Amin pointed out.Cressey warned that 9/10 new regulations designed to fight this threat have already been overtaken by technology by the time they are enacted, so any response will need to be flexible. Sandage said that the international and regional legislative landscape will be clearer in a year or so as assessments continue to establish what the legal issues in cyber security are, what the regulation framework looks like and where the problems are. While it may not be necessary to completely rewrite laws, they can certainly be improved to meet new threats.
| A panel of cyber security experts at the Connect Arab Summit 2012 yesterday |
March 07, 2012 | 12:00 AM