We’re often distracted as an industry by the latest big-name threats. The marketing departments of security vendors and research institutes have had a great time of late dreaming up catchy, doom-laden names for them. KRACK, Heartbleed, Spectre, Meltdown, WannaCry – the list goes on. But it only serves to reinforce the old hunter-hunted dynamic.
It might be more constructive to think of cybersecurity not in terms of a lion and its prey but of a running with the bulls. After all, the threat landscape is similarly chaotic and random; there is no end in sight, just new bulls and an endless stretch of road to run.
If we follow this analogy, we recognize that the chaos and unpredictability introduced by an adaptive adversary are our constant companions and that constant awareness, engagement, re-assessment, realism and adaptation must characterise our response.
In this chaotic world there’s little correlation between what you invest into security, and how much risk-reduction you can expect to enjoy as a result. There’s also no such thing as “baseline” security. Doing security better than your rivals is not enough, and compromise of some sort remains a question of “when” not “if”.
The Bigger Picture
Basic cyber-hygiene like patch and vulnerability management are vital elements which will keep the organisation as resilient as it can be – there’s little point in investing in sophisticated, expensive security if you haven’t got these basics right.
However, the truth is that we live in a chaotic world with no end game in sight. This is a reality the security industry needs to come to terms with and embrace, rather than perpetuating the lion-and-its-prey narrative.
If organisations better understand their online foes, adapt their strategies accordingly and work to master the basics of cyber-hygiene, they stand a great chance of outrunning as many of these bulls as possible. But just as important is appreciating that you can’t outrun them all. To view the full blog please visit https://www.secdata.com/run-with-bulls/
The SecureData Scottish Cybersecurity forum will bring together cybersecurity professionals, from CISOs to IT Managers, especially those overseeing security, risk or compliance strategies, for a series of seminars on the issues that pose the biggest threats to organisations today.
The event will kick off with an overview of the issues in information security by examining the big picture of cybersecurity with reference to the issues shaping our field today and in the future. The drivers behind cybercrime and how this impacts compliance and our ability to comply with regulations in general.
The guest speaker is Keith McDevitt, responsible for Defence, Security and Cyber Resilience Division for the Scottish Government will give a keynote on his strategy and actions plans for Scotland and also be available to answer any questions.
Core conference themes include:
- Building a cyber resilient Scotland
- The “lions and bulls” analogy
- Securing the Endpoint
- Cloud Security
- GDPR
Sponsoring vendors will be discussing:
- Check Point – Securing the End Point
- Fortinet – Securing your Cloud Applications and Data
- F5 – Securing in-house and Cloud Applications
- Okta – Authentication
- Symantec – Enabling Business Transformation
- Varonis – Data Discovery
- ForeScout – Security through visibility
- Pulse Secure – No Barriers inside Networks
Delegates will also have the opportunity to talk to the representatives from cybersecurity vendors and take a tour of the Murrayfield Stadium.
Is this forum relevant to you? Click here to check out the agenda and register to attend this event.






