Site navigation

Who Uses The Users? DIGIT Asks ZoneFox What Normal Looks Like

Dominique Adams

,

Jamie Graves

The more things a company has connected to the Internet – be they users, or be they ‘things’ – the greater the risks to security. DIGIT spoke to Zonefox CEO Dr Jamie Graves to find out why identifying ‘normal’ behaviour can help avoid disaster.

According to many cyber security experts, users are a problem. Rogue employees with access to sensitive information, can play havoc with the resilience of even the most security-conscious company. That’s compounded by the growing number of threats to the rest of the staff. Phishing e-mails, Smishing text messages (yes, that’s a real thing) and social engineering can cause even the happiest and most loyal employee to inadvertently allow threat actors (i.e. ‘baddies’) access to things they shouldn’t.

In addition, a growing number of companies are allowing ever more devices to connect their systems, from printers and office equipment, to industrial sensors, controllers and even personal gadgets like streaming music players and AI assistants. Each device increases the risk to the business and can leave an opportunity for an attack. As DIGIT recently reported, even the office fish tank can be a huge potential threat for anyone with a desire to keep their data secure and company protected.

With threats on the rise, the types of x-shing attacks increasing and the challenge of making every employee aware of the dangers, how can companies be sure they know what’s actually going on? DIGIT spoke to cyber security expert Dr Jamie Graves, CEO and founder of ZoneFox, to find out more.

DIGIT: Is the threat to companies changing?

Dr Jamie Graves: “We’ve certainly come a long way since the BonziBuddy days of the early 2000s, whereby a purple monkey — known as the most friendly malware on the internet — would crowd the desktops of those who failed to protect themselves with anti-virus. Fast forward and, in 2015, malvertising attacks on sites such as Plenty of Fish dominated headlines. The following year, the likes of Yahoo! and Ashley Madison made 2016 the year of the data breach. In 2017, WannaCry and its effect on the NHS ensured that ransomware was on everyone’s lips.

“Now, organisations are feeling the cyber pressure most acutely from insider threats — ramping up detection, prevention, and remediation accordingly. This is partly due to the rise in risk from regular employees, who look to set to overtake privileged users this year in terms users who pose the highest risk for organisations, whether through malicious intent or — more likely — being phished in order to give up important information.”

DIGIT: In such a rapidly evolving landscape, how can companies keep up?

Jamie: “User and Entity Behaviour Analytics (UEBA) is a technological approach that is being considered by more forward-thinking business leaders, as it provides the data visibility that is so vital for mitigating cyber attacks. What’s more, with the upcoming General Data Protection Regulation (GDPR), compliance has never been more important. Businesses need a clear overview of problem points they need to address.

“These new regulations are of real importance to companies. ZoneFox has just updated its own platform to spot behaviour that has fallen foul of specific regulatory frameworks, so it’s hugely beneficial for companies striving for compliance. Compliance is a vital part of a company’s security strategy, so this capability helps to clearly display where they might be non-compliant.”

DIGIT: How does the system spot potential problems?

Jamie: “Essentially, the technology builds a picture of ‘normal’ user behaviour, and alerting on deviations from that behaviour. Suspicious behaviours might include uploading sensitive information to Dropbox or tunnelling data through the dark web. All of these instances would be monitored and flagged through UEBA technology.
Combined with an effective education programme, ZoneFox’s UEBA technology can consistently and accurately monitor behaviour to a level that would normally need a full team of staff to do so by monitoring both on and off the network and using machine-learning technology.

“The value is lost, however, if the interface for all this information isn’t clear. From the CEO and CSO through to the average employee, the information — especially around threats — needs to be crystal clear. We have been aware of that and consistently looking to streamline data visibility and rich insights, so at ZoneFox we make sure the UI details all alerts in one place, giving those looking, even if they’re not security experts, a clear and understandable picture of their organisation’s behaviour.”

DIGIT: What about companies who don’t have security experts?

Jamie: “ZoneFox’s Cloud-hosting service means that companies don’t need to hire a specialist team or need to cover the computing costs to deploy the technology, opening it up to countless sectors in the process. Industries may range from retail to financial services to oil and gas — all can enjoy the same level of protection, which can be hosted externally.

“This means that, yes, the technology is the same for a small business all the way through to a major enterprise — the only details that change are the delivery and hosting method.”

Scottish CyberSecurity Forum Banner

DIGIT: How can companies create a more security conscious culture?

Jamie: “Frequent and truly interactive training is crucial — which means banishing the likes of 30-slide decks. Regular social engineering tests with staff and rewarding winners with prizes can help foster a strong cyber security culture, as well as being transparent and communicative about security hygiene. Even simply printing out some informative engaging posters to stick on the walls can help encourage vigilance. At the very least, this is a better option than hiding tips in a staff handbook, buried on a shared drive.

“A cultural shift within a company or organisation also needs to be ‘top-down’, and not just come from the security team. CEOs, CFOs, other members of the leadership team; these roles need to be security-savvy and, importantly, vocal about this. That is how a true cultural change will emerge.

“What all of this does is foster an open security culture, encouraging independent security evangelists across the entire company, rather than just siloed within IT teams.”

 

Dominique Profile Picture

Dominique Adams

Marketing Content Manager, Trickle

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data