The Illusion of Control: What the Second Line Gets Wrong—and What Regulators and Failures Reveal

By Jeremy Swenson

Thirty-one. That is how many unaddressed safety-and-soundness supervisory warnings Silicon Valley Bank was sitting on when it collapsed in March 2023—roughly triple the number carried by comparable banks. The warnings existed. Examiners had written them down. Committees had reviewed them. And the bank failed anyway, in 36 hours, taking $209 billion in assets down with it.[1]

This figure isn’t really just about Silicon Valley Bank; it’s a broader story about how governance can falter right when it was meant to prevent failure. Across modern sectors like finance, healthcare, insurance, and tech—especially under heavy regulation—the structure is quite similar: a First Line managing risks, a Third Line (Internal Audit) independently evaluating effectiveness, and a Second Line acting as an oversight layer to challenge and ensure risk remains within boundaries before issues arise.

The uncomfortable pattern across nearly every major governance failure of the last fifteen years is not that the second line was absent. It was there, busy, and documented—and it still didn’t work.

That is the uncomfortable pattern across nearly every major governance failure of the last fifteen years: the second line of defense (2LOD) was rarely absent. It was there, it was busy, and it was thoroughly documented. JPMorgan’s Chief Investment Office had risk managers. Credit Suisse’s Prime Services division had a dedicated risk team. Wells Fargo had a corporate risk function, a legal department, and an audit group that all reviewed the Community Bank. Danske Bank’s Estonian branch had internal audit and a chief risk officer. In each case, the paperwork existed. The risk did not go away.

This raises the question at the center of this piece, and one that boards, regulators, and chief risk officers are increasingly asking out loud: is the modern second line of defense actually reducing risk—or is it primarily producing evidence that governance activities occurred? The two are not the same thing, and the gap between them is where some of the costliest failures in recent corporate history have lived.

What the Second Line Is Supposed to Do

The three-lines model that underpins risk governance at virtually every large regulated institution was formalized by the Institute of Internal Auditors in 2013 and substantially updated in 2020. The first line is operational management—the traders, lenders, engineers, and business unit leaders who own risk because they create it in the course of doing their jobs. The third line is internal audit, an independent function that reports to the board and periodically tests whether the first two lines are actually working. The second line sits in the middle: risk management, compliance, information security, and similar functions that provide, in the Institute’s own language, “complementary expertise, support, monitoring, and challenge” to the business.[2]

In U.S. banking specifically, this structure is not just best practice—it is regulatory expectation with teeth. The Office of the Comptroller of the Currency’s (OCC) 2014 heightened standards for large national banks explicitly require an independent risk management function, organizationally and financially separate from the business lines it oversees. The Federal Reserve’s 2011 guidance on model risk management, SR 11-7, assigns the second line an independent validation role specifically because business lines have an inherent incentive to trust their own models.[3]

Notably, when the Institute of Internal Auditors rewrote its guidance in 2020, it deliberately dropped the word “defense” from the model’s name, worried that the martial framing had encouraged organizations to treat risk management as purely defensive—blocking and reviewing—rather than as a function that helps an organization take the right risks well. That single word change is a useful preview of this piece’s argument: a second line built entirely around defense metrics—how many reviews were completed, how many policies exist, how many attestations were signed—can satisfy every requirement on paper while missing the actual point.[4]

Where the Model Breaks Down

Strip away the acronyms, and the recurring failure modes of the second line reduce to a short, uncomfortable list. Each one, on its own, sounds like a minor process gap. Together, and when combined with real money and real institutions, they have produced some of the largest corporate governance failures on record.

Documentation Instead of Risk Reduction

The clearest symptom is a second line that measures itself by volume: reviews completed, policies published, attestations collected, meetings held. Every one of those activities can be running at full capacity while the underlying risk grows untouched, because none of them require anyone to verify that a control actually works—only that someone said it does.

Self-Attestation Over Independent Verification

Much of traditional second-line practice depends on the first line telling the second line the truth: attestations, self-assessments, and point-in-time control tests that sample a narrow window and assume it represents the whole. When Danske Bank’s Estonian branch was later examined, the bank’s own lawyers conceded that “major deficiencies in controls and governance made it possible to use Danske Bank’s branch in Estonia for criminal activities such as money laundering,” and that internal reporting simply never reached the people positioned to stop it.[5]

Individual Exceptions Over Systemic Patterns

Second lines are often organized to catch one broken control at a time—a missed reconciliation, a late report, an expired certificate—rather than to notice that dozens of small, individually explainable exceptions are actually one large, systemic problem wearing different clothes.

Compliance Treated as a Proxy for Safety

Perhaps the most persistent conflation in second-line practice is the assumption that a control environment which satisfies a regulation is therefore a control environment that manages the underlying risk. The two frequently travel together. They are not the same claim, and treating them as interchangeable is exactly how organizations end up technically compliant and substantively exposed at once.

A Challenge Function That Doesn’t Actually Challenge

Effective second-line challenge requires two things that are hard to combine: enough independence to say no to a profitable business line, and enough technical and commercial fluency to know when “no” is actually warranted. Many second lines have one without the other—independent enough to be disliked, but not fluent enough in the actual business to be heeded, or so embedded in the business that independence quietly erodes.

Struggling to Govern What It Doesn’t Understand

Every one of the weaknesses above compounds sharply the moment the underlying risk is technical: artificial intelligence models, cloud migrations, third-party data pipelines, or novel cyber threats. A second line built to review loan files and sales scripts is not automatically equipped to evaluate a machine learning model’s training data lineage or a cloud vendor’s shared-responsibility boundary—and regulators are now saying so explicitly. NIST’s AI Risk Management Framework (RMF) and the broader push toward AI-specific governance exist precisely because traditional control catalogs were not written with adaptive, probabilistic systems in mind.[6]

Five Failures, One Pattern

These are not abstractions. They are the documented findings of regulators, board-appointed investigators, and congressional committees—and read together, they describe the same failure recurring in different industries, different countries, and different decades.

1. JPMorgan’s “London Whale” (2012)—When Risk Managers Don’t Know What the Business Is Doing

In 2012, JPMorgan Chase’s Chief Investment Office lost more than $6.2 billion on a series of synthetic credit derivative trades that came to be known as the “London Whale.” The U.S. Senate Permanent Subcommittee on Investigations spent nine months and reviewed more than 90,000 documents before concluding that the unit had mismarked its trading book to hide losses, disregarded multiple indicators of increasing risk, manipulated its own risk models, and evaded regulatory oversight.[7]

The Subcommittee’s report found that JPMorgan’s firm-wide risk managers—the second line—“knew little about” the trading strategy and had no role in approving the positions that produced the loss, even as the bank’s own public statements insisted the trades were consistent with firm-wide risk management. This was a second line that existed on the org chart and was functionally absent from the transaction that mattered most.[8]

2. Wells Fargo’s Sales Practices Scandal (2011–2016)—When Egos and Tenure Silence the Second Line

Between 2011 and 2016, Wells Fargo employees opened millions of unauthorized accounts to meet aggressive sales quotas, ultimately leading to the termination of roughly 5,300 employees and $185 million in regulatory penalties. When the bank’s independent directors released their own 110-page investigation in 2017, the findings went well beyond a rogue sales culture.[9]

The report found that Carrie Tolstedt, the long-tenured head of the Community Bank, and other Community Bank leaders “resisted and impeded scrutiny or oversight from corporate risk management and the Board,” and “minimized the scale and nature of problems” when they were forced to report them. Then-CEO John Stumpf, the report found, relied on “the Bank’s decades of success” and was “too slow to investigate or critically challenge” the sales model—a textbook description of tenure-driven bias, where years of past success become evidence against present-day concerns rather than a reason to look harder.[10]

Just as tellingly, the report found that Wells Fargo’s control functions were structurally weakened by internal politics: risk, legal, HR, and audit were “decentralized” and had “parallel units” embedded inside the Community Bank itself, reporting up through business-aligned structures that deferred to the business rather than challenging it. Audit reviewed the relevant controls and largely found them effective—but, the report notes pointedly, “it did not view its role to include analyzing more broadly the root cause of the improper conduct.” That is the governance-activity trap in a single sentence: the review happened, the box was checked, and the actual problem sailed through untouched.[11]

3. Credit Suisse and Archegos (2021)—When the Second Line Is Afraid to Say No

In March 2021, the collapse of Archegos Capital Management, a lightly regulated family office, cost Credit Suisse $5.5 billion—more than any other bank exposed to the same client. The board-commissioned investigation by Paul, Weiss found no fraud and no missing risk architecture. The controls existed. What failed was the willingness to use them.[12]

The investigation found a “persistent failure” to manage and remediate known risks connected to Archegos, and, more specifically, that Credit Suisse’s risk managers had intended to demand additional margin from Archegos to reflect its mounting credit risk—but were prevented from doing so because the business “deemed” it not to be in the bank’s commercial interest to upset the relationship. One outside review summarized the underlying dynamic bluntly: this was “a business more scared of losing a client than addressing the risks that client was bringing to the bank.” The report also found the Prime Services risk team itself was understaffed, had failed to replace departing senior risk staff, and lacked leadership experience—the second line, quite literally, hollowed out from within.[13]

4. Danske Bank Estonia (2007–2018)—When the Second Line Covers Its Own Mistakes

Danske Bank’s Estonian branch moved an estimated $230 billion in suspicious transactions, much of it linked to Russia, between 2007 and 2015—one of the largest money-laundering cases in European history. It might never have come to light if not for Howard Wilkinson, a British trader who filed four internal whistleblower reports to the bank’s audit unit and Copenhagen management between 2013 and 2014.[14]

Wilkinson later testified before the Danish and European Parliaments that the bank had “deliberately ignored” his warnings and that an Estonia branch executive told him the bank was “not the police.” An internal Danske audit team eventually validated the substance of his concerns, yet the bank still failed to take meaningful action until the money-laundering scandal became public in 2018—four years later. As Wilkinson departed the bank, he was reportedly presented with a nondisclosure agreement. This is the sharpest version of the pattern this piece was asked to examine directly: not a second line that failed to notice a problem, but one that noticed, confirmed it internally, and chose containment over correction—protecting the institution’s narrative rather than fixing the underlying failure.[15]

5. Silicon Valley Bank (2023)—When Periodic Reviews Can’t Keep Up With Real-Time Risk

SVB failed in 36 hours following a bank run, but the vulnerabilities behind it built for years. The Federal Reserve’s own review, led by Vice Chair for Supervision Michael Barr, is remarkable for how directly a regulator indicted its own supervisory process: SVB’s board and management “failed to manage their risks,” Federal Reserve supervisors “did not fully appreciate the extent of the vulnerabilities” as the bank grew, and—critically—even when supervisors did identify problems, they “did not take sufficient steps to ensure that Silicon Valley Bank fixed those problems quickly enough.”[16]

The report also found that SVB itself had changed its own risk-management assumptions specifically to reduce how its interest rate risk was measured, rather than managing the underlying exposure—a second-line control quietly redefined until it stopped producing uncomfortable answers. Barr’s report is also a rare admission that periodic, point-in-time supervisory cycles are structurally too slow for a risk that can move at deposit-run speed; a regulator reaching the same conclusion this piece reaches about the second line more broadly.[17]

What Regulators Learned—And Where Their Own Findings Converge

The most useful evidence that this is a systemic problem, not a string of unrelated scandals, comes from the regulators themselves. On April 28, 2023, the Federal Reserve and the Federal Deposit Insurance Corporation (FDIC) each released their own self-critical report on the same weekend of bank failures—an unusually candid coincidence that let the two reports be read side by side.

The Fed’s report on SVB, discussed above, found that supervisors identified real vulnerabilities but did not escalate forcefully enough once they had. The FDIC’s own report on Signature Bank reached a strikingly similar structural conclusion through a completely separate investigation: the bank’s failure was rooted in poor management, but the report also found that FDIC examiners had downgraded Signature’s liquidity rating as early as 2017 while its overall composite rating stayed at a healthy “2-Satisfactory” for six more years—a gap between what examiners were seeing and what the supervisory rating actually communicated.[18]

The U.S. Government Accountability Office (GAO) took a further step by reviewing both agencies together rather than separately. It concluded that this supports the main argument of this piece concerning federal banking regulation: the Federal Reserve and FDIC “identified numerous concerns at the banks as early as 2018, but did not issue enforcement actions.” Additionally, the GAO pointed out that the Federal Reserve’s “procedures for moving from a lower-level concern to an enforcement action often weren’t clear or specific.” This indicates that a regulator, assessing itself, independently recognizes the same core idea discussed here: identifying a risk is not the same as forcing a change. An institution can recognize risks on a large scale for years without reliably enforcing change.[19]

Read together with the NIST AI Risk Management Framework’s push for governance built around measurable, continuous risk assessment rather than static control catalogs, and the IIA’s 2020 shift away from purely defensive framing, a consistent regulatory direction emerges across otherwise unrelated bodies: less faith in point-in-time review, more emphasis on forcing identified risk into actual remediation, and explicit skepticism that documentation volume is a reliable proxy for safety. None of these bodies coordinated with each other. They arrived at overlapping conclusions anyway, because they were all looking at the same underlying failure pattern from different angles.[20],[21]

Figure 1. Most second-line functions do not lack activity—they sit in the high-activity, low-reduction quadrant, producing evidence of governance without changing risk outcomes.

The 2LOD governance trap and its four related boxes.

The Part Nobody Puts in the Org Chart: Tenure, Ego, and Internal Turf Wars

Every case above shares a dynamic that rarely appears in a governance framework diagram but shows up in nearly every post-mortem: the people closest to a mistake are often the ones best positioned to prevent its discovery, and organizational tenure tends to make that worse rather than better.

Long-tenured leaders accumulate something more dangerous than complacency—they accumulate authorship. A risk model, a sales program, a client relationship built over a decade is not just a business asset to the person who built it; it is proof of their own judgment. Wells Fargo’s Board Report describes exactly this pattern in Carrie Tolstedt, who had run the Community Bank for years and treated challenges to the sales model as challenges to her track record, not as useful information. John Stumpf’s decades at the company produced the same effect at the top: reliance on “decades of success” became a reason to discount new evidence rather than investigate it.[22]

Ego compounds this in a specific and predictable way inside the second line itself: once a risk function has signed off on something—approved a model, cleared a client, blessed a control—reversing that judgment later means admitting the earlier review was wrong. The Credit Suisse-Archegos investigation found that risk staff who wanted to tighten margin requirements were overruled by colleagues managing the client relationship, who prioritized the commercial relationship over the escalation. That is not a hypothetical about incentives; it is a documented instance of one part of the organization protecting a prior decision instead of correcting course.[23]

The most direct evidence of internal fighting to cover mistakes is Danske Bank. Wilkinson’s own account describes a bank that did not simply fail to notice a problem—it received internal confirmation that the problem was real, from its own audit function, and chose a non-disclosure agreement and years of silence over disclosure and remediation. That is not a control gap. It is a second line, or the executives who supervise it, actively managing the appearance of the problem rather than the problem itself—the containment instinct that shows up whenever an admission of error threatens a career, a bonus cycle, or a carefully maintained reputation.[24]

A second line that cannot survive telling the truth about its own prior mistakes will eventually stop looking for them.

None of this requires malice to be dangerous. Most of the people in these stories were not villains; they were professionals whose incentives, tenure, and self-image quietly bent the direction of ambiguous judgment calls toward “this is probably fine.” A modern second line has to be designed with the explicit assumption that this bending will happen—through rotation of long-tenured reviewers, external validation of internally cleared decisions, and protected channels for escalation that do not depend on the goodwill of the person whose earlier judgment is being questioned.

Governance Activity Is Not the Same as Risk Reduction

Every case study mentioned earlier successfully passed a compliance test before turning into a scandal. This is the key point repeatedly emphasized here: governance that merely shows evidence of compliance is different from governance that genuinely reduces risk. An organization can generate a lot of documentation proving compliance but still fall short in actually altering risk outcomes.

Evidence-of-compliance governance is legible, defensible in an exam, and relatively cheap to produce: a signed attestation, a completed checklist, a policy that has been “reviewed and approved.” Outcome-based governance is harder and more expensive: independently tested controls, risk metrics tied to actual loss experience, escalation paths that get used even when the news is bad. The first kind of governance protects the organization in an audit. The second kind protects the organization in a crisis. Wells Fargo, Credit Suisse, and Danske Bank all had abundant supplies of the first and a critical shortage of the second.

Figure 2. Modernizing the second line means shifting the underlying operating model, not just increasing the volume of existing activity.

Two columns showing the legacy model of checkbox compliance and the new model of continuous risk governance.

What a Modern Second Line Actually Looks Like

None of this argues for a weaker second line—every case study here shows the cost of that. It argues for a fundamentally different operating model, one that a growing body of regulatory guidance and industry practice is already pointing toward.

Risk-Based, Not Checklist-Based

Oversight intensity should scale with actual risk and complexity, not with how many items happen to be on a standard control list. A stable, well-understood process and a novel AI model deployed into a regulated decision workflow should never receive the same depth of review simply because both appear as line items on the same checklist.

Continuous Monitoring, Not Periodic Snapshots

The Barr report on SVB is itself an argument for this shift: point-in-time exams cannot keep pace with risks—interest rate exposure, deposit concentration, model drift—that can move materially between review cycles. Where technology allows it, continuous, automated monitoring should replace calendar-driven review as the default, with periodic deep-dives reserved for the risks continuous monitoring cannot yet see.

Evidence Over Attestation

Self-reported control effectiveness should be treated as a starting hypothesis, not a conclusion. Independent data validation—sampling actual transactions, actual model outputs, actual system logs—is more expensive than collecting a signature, and it is the only version of assurance that would have caught what self-attestation missed at Danske Bank.

Genuine Business and Technology Fluency

A second line cannot challenge what it does not understand. This means recruiting and developing risk professionals with real technical depth—in derivatives, in cloud architecture, in machine learning—rather than treating the second line as a generalist compliance career track. JPMorgan’s risk managers not knowing what the CIO’s synthetic credit portfolio actually did is the clearest cautionary tale on this point.

Escalation That Survives Internal Politics

Escalation paths need to be structurally protected from the relationship dynamics that killed escalation at Credit Suisse and Danske Bank—which means routing serious concerns to a level of the organization with no commercial stake in the outcome, and protecting the people who raise them, not just on paper but in how the organization actually treats them afterward.

Outcome-Based Metrics

A second line’s effectiveness should be measured by risk events avoided, losses prevented, and issues resolved before they compound—not by the number of reviews completed, policies published, or meetings held. Volume metrics are easy to game and easy to satisfy without changing anything; outcome metrics are harder to fake.

Real Oversight of AI, Cloud, and Third Parties

Emerging-technology governance needs its own competency track within the second line, built around frameworks purpose-designed for these risks—NIST’s AI Risk Management Framework, cloud shared-responsibility models, and structured third-party risk programs—rather than an attempt to stretch legacy control catalogs over technology they were never built to evaluate.[25]

Clear Accountability Between the First and Second Lines

Wells Fargo’s decentralized risk structure, with control functions embedded inside and reporting up through the business they were meant to oversee, shows what happens when the line between “owns the risk” and “challenges the risk” blurs. Modern governance requires those roles to remain organizationally and, where possible, financially distinct—precisely what the OCC’s heightened standards were written to enforce.[26]

Constructive Challenge, Not a Permanent Bottleneck

None of the above is a case for more friction everywhere. A second line that slows every decision equally will be resented, routed around, and eventually ignored—which is its own form of failure. The goal is targeted friction: fast, low-touch review for well-understood, lower-risk activity, and genuinely rigorous, well-resourced challenge concentrated on the decisions that could actually sink the institution.

Conclusion: Measuring the Right Thing

Return to Silicon Valley Bank’s 31 unaddressed supervisory warnings. Every one of them was, in a narrow sense, evidence that governance was happening: someone had identified a risk, written it down, and tracked it. And every one of them failed to change what actually happened to the bank. That is the second line’s central modern challenge, in miniature.

None of this is solvable by better metrics alone. Every case study in this piece also involved someone for whom the honest answer was personally expensive—a bonus, a reputation, a decade of authorship over a program now under question. A second line rebuilt around outcome-based measurement but layered on top of the same career incentives that rewarded Carrie Tolstedt’s silence and cost Howard Wilkinson his job will simply produce more sophisticated versions of the same evasions. The measurement has to change. So does the price of telling the truth.

It is also worth taking seriously what the regulators’ own convergence implies about where this is heading. The Federal Reserve, the FDIC, the GAO, NIST, and the IIA did not coordinate their findings—they arrived at the same conclusion independently, from different mandates, within the same few years. Convergence without coordination is usually a sign that a standard is hardening, not that a moment is passing. Institutions that treat this argument as a post-SVB overreaction, rather than the new baseline expectation, are likely to be rereading their own supervisory letters in a few years and wondering how they missed it.

The stakes of getting this right are also rising, not leveling off. Every failure examined here involved a risk that a sufficiently empowered reviewer could, in principle, still understand—a trading book, a sales incentive, a margin call. The AI models now moving into underwriting, claims, and credit decisions will not extend that same courtesy; their behavior can shift with a single retraining cycle in ways no annual attestation was ever built to catch. A second line that could not reliably catch a mismarked trading book will not reliably catch a model that has quietly drifted—not without first becoming the kind of second line this piece has been describing.

The organizations in this piece did not fail because nobody was watching. They failed because watching, on its own, was mistaken for managing. A modern second line has to be judged by a harder, more honest standard than whether the reviews got done: whether the risks that mattered actually got smaller. Everything else—the frameworks, the dashboards, the attestations—is only useful to the extent it serves that one outcome. Where it doesn’t, it is not governance. It is just paperwork with better branding.

Endnotes


[1]  Board of Governors of the Federal Reserve System, Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank (Washington, DC: Federal Reserve, April 28, 2023), https://www.federalreserve.gov/publications/files/svb-review-20230428.pdf; “Fed’s Barr: ‘Weaknesses in Supervision and Regulation Must Be Fixed,’” American Banker, April 28, 2023, https://www.americanbanker.com/news/feds-barr-weaknesses-in-supervision-and-regulation-must-be-fixed.

[2] The Institute of Internal Auditors, The IIA’s Three Lines Model: An Update of the Three Lines of Defense (Lake Mary, FL: IIA, July 2020), https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf.

[3]  Office of the Comptroller of the Currency, OCC Guidelines Establishing Heightened Standards for Certain Large Insured National Banks, Insured Federal Savings Associations, and Insured Federal Branches, 12 C.F.R. Part 30, Appendix D (2014); Board of Governors of the Federal Reserve System, “Supervisory Guidance on Model Risk Management,” SR Letter 11-7 (Washington, DC: Federal Reserve, April 4, 2011).

[4]  “IIA Unveils New Three Lines Model,” Radical Compliance, July 22, 2020, https://www.radicalcompliance.com/2020/07/22/iia-unveils-new-three-lines-model/.

[5]  “Howard Wilkinson,” Kohn, Kohn & Colapinto Whistleblower Case Archive, accessed August 2026, https://kkc.com/whistleblower-case-archive/howard-wilkinson/.

[6]  National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (Gaithersburg, MD: U.S. Department of Commerce, January 26, 2023), https://doi.org/10.6028/NIST.AI.100-1.

[7]  U.S. Senate Permanent Subcommittee on Investigations, Committee on Homeland Security and Governmental Affairs, JPMorgan Chase Whale Trades: A Case History of Derivatives Risks and Abuses (Washington, DC: U.S. Senate, March 15, 2013), https://www.hsgac.senate.gov/subcommittees/investigations/library/files/report-jpmorgan-chase-whale-trades-a-case-history-of-derivatives-risks-and-abuses-march-15-2013/.

[8]  JP Morgan Chase Whale Trades: A Case History of Derivatives Risks and Abuses, summarized in Demos, https://www.demos.org/research/jp-morgan-chase-whale-trades-case-history-derivatives-risks-and-abuses.

[9]  Independent Directors of the Board of Wells Fargo & Company, Sales Practices Investigation Report (San Francisco: Wells Fargo & Company, April 10, 2017), https://lowellmilkeninstitute.law.ucla.edu/wp-content/uploads/2018/01/WF-Board-Report.pdf.

[10]  Wells Fargo Newsroom, “Wells Fargo Board Releases Findings of Independent Investigation of Retail Banking Sales Practices and Related Matters,” press release, April 10, 2017, https://newsroom.wf.com/news-releases/news-details/2017/Wells-Fargo-Board-Releases-Findings-of-Independent-Investigation-of-Retail-Banking-Sales-Practices-and-Related-Matters/default.aspx.

[11]  “Summary of the Report of the Independent Directors of Wells Fargo & Company into Sales Practices,” Lexology, October 11, 2017, https://www.lexology.com/library/detail.aspx?g=9b82dbcc-146d-4921-847c-526ccbf505a2; Brad S. Karp, Roberto J. Gonzalez, and Vikas Desai, “Lessons Learned from the Wells Fargo Sales Practices Investigation Report,” Harvard Law School Forum on Corporate Governance, April 22, 2017, https://corpgov.law.harvard.edu/2017/04/22/lessons-learned-from-the-wells-fargo-sales-practices-investigation-report/.

[12]  Credit Suisse Group AG, Report of the Special Committee of the Board of Directors of Credit Suisse Group Regarding Archegos Capital Management, prepared by Paul, Weiss, Rifkind, Wharton & Garrison LLP (July 29, 2021), as reported in “Credit Suisse Publishes Independent Review of Archegos Losses,” Paul, Weiss news release, July 29, 2021, https://www.paulweiss.com/practices/litigation/internal-investigations/news/credit-suisse-publishes-independent-review-of-archegos-losses.

[13]  “Unpacking the Report on Credit Suisse’s Archegos Disaster,” Euromoney, July 29, 2021, https://www.euromoney.com/article/28usrfe6tdwq9fkpayosg/capital-markets/unpacking-the-report-on-credit-suisses-archegos-disaster/; “Credit Suisse and the Archegos Collapse – Lessons in Risk Management and Governance for All,” BDO, February 21, 2025, https://www.bdo.co.uk/en-gb/insights/industries/financial-services/credit-suisse-and-the-archegos-collapse-lessons-in-risk-management-and-governance.

[14]  “Whistleblower in Danish Banking Scandal: Bank Ignored Me,” Associated Press via Seattle Times, November 19, 2018, https://www.seattletimes.com/business/whistleblower-in-danish-banking-scandal-bank-ignored-me/; “Danske Bank Money Laundering Scandal – Tip of the Icebergs,” National Law Review, accessed August 2026, https://natlawreview.com/article/danske-bank-money-laundering-scandal-tip-icebergs.

[15]  “Howard Wilkinson,” Kohn, Kohn & Colapinto Whistleblower Case Archive, accessed August 2026, https://kkc.com/whistleblower-case-archive/howard-wilkinson/; “Thanks to Danske Bank Whistleblower, SEC Sets Aside $178 Million for Harmed Investors,” Whistleblower Blog, April 4, 2023, https://whistleblowersblog.org/corporate-whistleblowers/sec-whistleblowers/thanks-to-danske-bank-whistleblower-sec-sets-aside-178-million-for-harmed-investors/.

[16]  Board of Governors of the Federal Reserve System, Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank, i-iii; “Federal Reserve Board Announces the Results from the Review of the Supervision and Regulation of Silicon Valley Bank,” press release, April 28, 2023, https://www.federalreserve.gov/newsevents/pressreleases/bcreg20230428a.htm.

[17]  Board of Governors of the Federal Reserve System, Review of the Federal Reserve’s Supervision and Regulation of Silicon Valley Bank, 3.

[18]  Federal Deposit Insurance Corporation, FDIC’s Supervision of Signature Bank (Washington, DC: FDIC, April 28, 2023), https://www.fdic.gov/news/press-releases/2023/pr23033a.pdf; “FDIC Signature Bank Report Summary,” prepared for the U.S. House Committee on Financial Services, May 2, 2023, https://financialservices.house.gov/uploadedfiles/2023.05.02_-_fdic_signature_bank_report_summary_final.pdf.

[19]  U.S. Government Accountability Office, Bank Supervision: More Timely Escalation of Supervisory Action Needed, GAO-24-106974 (Washington, DC: GAO, 2024), https://www.gao.gov/products/gao-24-106974.

[20]  National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0) (Gaithersburg, MD: U.S. Department of Commerce, January 26, 2023), https://doi.org/10.6028/NIST.AI.100-1.

[21]  The Institute of Internal Auditors, The IIA’s Three Lines Model: An Update of the Three Lines of Defense (Lake Mary, FL: IIA, July 2020), https://www.theiia.org/globalassets/documents/resources/the-iias-three-lines-model-an-update-of-the-three-lines-of-defense-july-2020/three-lines-model-updated-english.pdf.

[22]  Independent Directors of the Board of Wells Fargo & Company, Sales Practices Investigation Report.

[23]  “Credit Suisse and the Archegos Collapse,” BDO; “Unpacking the Report on Credit Suisse’s Archegos Disaster,” Euromoney.

[24]  “Whistleblower in Danish Banking Scandal: Bank Ignored Me,” Seattle Times; “Howard Wilkinson,” Kohn, Kohn & Colapinto.

[25]  National Institute of Standards and Technology, Artificial Intelligence Risk Management Framework (AI RMF 1.0).

[26]  Office of the Comptroller of the Currency, OCC Guidelines Establishing Heightened Standards, 12 C.F.R. Part 30, Appendix D; Independent Directors of the Board of Wells Fargo & Company, Sales Practices Investigation Report.

The Mythos Moment: Why AI Cyber Capabilities Just Crossed the Governance Rubicon

Fig. 1. How Mythos Evolved to Become a Recursive Threat, ChatGPT and Jeremy Swenson, 2026.

In April 2026, a quiet but profound shift occurred in cybersecurity—one that many organizations are still underestimating. Anthropic’s Claude Mythos Preview did not simply advance AI capability. It crossed a threshold. For the first time, a commercially developed model demonstrated the ability to autonomously discover and exploit software vulnerabilities at a near-expert level, including executing multi-step attack chains end-to-end.¹²

This is not incremental progress. It is a structural break. And with that break comes a new reality: the governance, security, and policy frameworks we have relied on are no longer theoretical exercises. They are operational requirements.


From Capability to Consequence—The End of the “Future Risk” Debate:

For years, discussions about AI-enabled cyber offense lived in the realm of hypotheticals—what could happen if models became sufficiently capable. That debate is now over. Mythos achieved a 73% success rate on expert-level capture-the-flag challenges and became the first AI system to complete a full 32-step enterprise network attack simulation.¹ What previously required elite human operators over many hours can now be partially automated.

At the same time, real-world testing has already shown that similar systems can uncover large volumes of previously unknown vulnerabilities. Reports indicate thousands of zero-day findings—including flaws that persisted undetected for decades—are now within reach of AI-assisted discovery.⁹ External validation reinforces this trajectory. A collaboration involving Mozilla used Mythos-like capabilities to identify hundreds of vulnerabilities in Firefox, demonstrating how quickly defensive gains—and offensive risks—can scale simultaneously. This dual-use dynamic is the defining characteristic of the Mythos moment: the same system that strengthens defense can accelerate exploitation.


The Government Contradiction—Risk, Reliance, and Reality:

What makes this moment even more consequential is not just the technology, but the policy response. In March 2026, the U.S. Department of Defense designated Anthropic as a supply chain risk after the company refused to allow unrestricted use of its models for autonomous weapons and surveillance applications.³ This effectively barred Anthropic from Pentagon contracts.

Yet within weeks, reporting confirmed that the National Security Agency—which operates within the same defense ecosystem—was actively using Mythos under controlled access.⁵⁶ At the same time, the Office of Management and Budget began negotiating a framework to deploy a modified version of the model across civilian agencies, including energy and financial regulators.⁷

This creates a striking contradiction:

  • One part of government labels the system a national security risk.
  • Another part actively deploys it.
  • A third is designing policy to scale its adoption.

This is not just bureaucratic inconsistency—it is a preview of how difficult governing frontier AI will be.


The Real Precedent—Governing AI as a Cyberweapon:

What is being negotiated right now matters far beyond Mythos itself. The White House–led framework under development is effectively the first attempt to govern an AI system with cyberweapon-level capabilities, not just data privacy or model safety.

Three emerging principles define this model:

1. Data Sovereignty Sensitive code and infrastructure data must remain within isolated government-controlled environments.

2. Model Integrity Inputs cannot be used to retrain or improve the underlying model, preventing unintended knowledge transfer.

3. Human-in-the-Loop Oversight No autonomous execution—human validation remains mandatory before action.

These are not minor guardrails. They represent the likely baseline for how governments—and eventually regulated industries—will manage high-capability AI systems. If history is any guide, these standards will propagate outward, much like FedRAMP reshaped cloud security procurement. Within 12–18 months, similar requirements are likely to appear in enterprise contracts, regulatory expectations, and audit frameworks.


The Industry Signal—This Is Already Scaling:

The private sector is not waiting. Through Project Glasswing, Anthropic has already deployed Mythos capabilities to a controlled group of major technology and infrastructure organizations, including cloud providers, semiconductor firms, and financial institutions.²

At the same time, companies like Microsoft are moving to integrate similar AI-driven vulnerability discovery into their secure development lifecycles, signaling that this capability will become embedded—not optional—in modern engineering practices. The implication is clear. AI-assisted vulnerability discovery is becoming a standard feature of cybersecurity—not an edge capability.


The Hard Truth—Containment Is Likely Temporary:

Perhaps the most important—and uncomfortable—reality is this:

Containment will not hold indefinitely. History shows that advanced AI capabilities diffuse rapidly. Model architectures leak, competitors replicate breakthroughs, and open-weight alternatives emerge. Even today, non-frontier models can replicate meaningful portions of Mythos-like capability at far lower cost and with fewer restrictions.¹⁴ That means the current environment—where only a limited set of organizations have access—is a temporary window. Organizations that treat this as a policy issue rather than an operational priority are making a critical mistake.


What This Means for Enterprise Leaders:

The Mythos precedent is not a niche technical development. It is a strategic inflection point. Three implications stand out:

1. The Attack Surface Is No Longer Static:

AI compresses the timeline between vulnerability discovery and exploitation from weeks or months to hours. Legacy assumptions—especially around “safe” unpatched systems—are no longer valid.

2. Patch Velocity Becomes a Board-Level Issue:

Organizations with slow remediation cycles are structurally exposed. If critical vulnerabilities can be identified and weaponized faster, governance processes must accelerate accordingly.

3. Defense Must Become Structural, Not Reactive:

Emerging approaches like confidential computing—hardware-isolated execution environments—offer a path to reducing the impact of exploits regardless of discovery speed.

In other words, the goal shifts from “find and fix everything” to “limit what can be compromised at runtime.”


The Strategic Window—Act Before the Curve Flattens:

There is still a narrow window of advantage. Today, frontier capabilities are relatively concentrated. Tomorrow, they will not be. Organizations that move now—by modernizing vulnerability management, accelerating patch cycles, and adopting structural defenses—can get ahead of the curve. Those who wait for regulatory clarity or broader market adoption will likely find themselves reacting under pressure.


Final Thoughts—How to Mitigate These Risks Now:

Here are the most practical, high-impact actions organizations can take right now to mitigate risks associated with advanced AI systems, data exposure, and model misuse—especially in light of incidents like large-scale leaks or “model mythos” exposures:

1) Lock Down Data at the Source:

The most immediate risk reducer is controlling what goes into AI systems in the first place.

  • Classify and tier data (public, internal, confidential, restricted).
  • Prohibit sensitive data (e.g., IP, credentials, client info) from being entered into external AI tools.
  • Implement data loss prevention (DLP) policies across endpoints, SaaS, and APIs.
  • Tokenize or anonymize sensitive datasets before AI usage.

2) Enforce Strong Access Controls:

AI systems often inherit weak identity governance from the broader environment.

  • Apply least privilege access to AI tools, datasets, and model pipelines.
  • Require multi-factor authentication (MFA) everywhere AI is accessed.
  • Monitor and restrict API key usage (rotate keys frequently).
  • Segment environments (dev/test/prod) to prevent lateral movement.

3) Introduce AI-Specific Governance:

Traditional IT governance is not sufficient for AI risk.

  • Stand up a lightweight AI governance council (security, legal, data, business).
  • Define acceptable use policies for generative AI tools.
  • Maintain an AI system inventory (models, vendors, datasets, use cases).
  • Require risk assessments before deploying AI into production.

4) Monitor for Data Leakage and Model Abuse:

You can’t protect what you don’t observe.

  • Log all prompts, outputs, and API interactions (where legally permissible).
  • Deploy behavioral analytics to detect unusual model usage patterns.
  • Scan outputs for sensitive data leakage (prompt injection, exfiltration attempts).
  • Red-team models with adversarial testing scenarios.

5) Harden Third-Party and Vendor Risk:

Many AI risks enter through vendors, not internal builds.

  • Conduct AI-focused vendor due diligence (data handling, training sources, retention policies).
  • Require contractual clauses on: Data ownership Model training boundaries Breach notification timelines.
  • Prefer vendors offering private model instances or zero data retention.

6) Implement Prompt and Output Controls:

The interface layer is a major attack surface.

  • Use prompt filtering and sanitization to block injection attempts.
  • Apply output guardrails to prevent harmful or sensitive responses.
  • Restrict high-risk capabilities (e.g., code execution, system access).
  • Use retrieval-augmented generation (RAG) with vetted internal sources only.

7) Train Employees (Fast, Not Perfect):

Human behavior is still the biggest variable.

  • Roll out short, targeted training on: Safe AI usage, Data handling do’s and don’ts, Prompt injection awareness.
  • Provide approved AI tools so employees don’t default to shadow AI.
  • Reinforce “don’t paste what you wouldn’t email externally”.

8) Prepare for Incident Response:

Assume exposure will happen—speed matters.

  • Update incident response plans to include AI-specific scenarios.
  • Define playbooks for: Data leakage via prompts, Model compromise or abuse, Third-party AI breaches.
  • Run tabletop exercises simulating AI-related incidents.

9) Control Model Inputs and Training Data:

What shapes the model shapes the risk.

  • Vet training datasets for: Sensitive information, Copyright/IP exposure, Bias and integrity issues.
  • Maintain data provenance tracking.
  • Avoid uncontrolled fine-tuning on raw internal data.

10) Start Small with Secure Architectures:

Don’t boil the ocean—secure what’s already in motion.

  • Use private or on-prem AI deployments for sensitive workloads.
  • Isolate AI systems within secure cloud environments.
  • Gate external model access through controlled middleware or APIs.
  • Adopt a “human-in-the-loop” approach for high-risk decisions.

Endnotes:

  1. UK AI Security Institute, “Our Evaluation of Claude Mythos Preview’s Cyber Capabilities,” April 2026.
  2. Anthropic, “Project Glasswing: Securing Critical Software for the AI Era,” April 2026.
  3. CNBC, “Judge Presses DOD on Why Anthropic Was Blacklisted,” March 24, 2026.
  4. CNBC, “Anthropic Loses Appeals Court Bid to Temporarily Block Pentagon Blacklisting,” April 8, 2026.
  5. TechCrunch, “NSA Spies Are Reportedly Using Anthropic’s Mythos,” April 20, 2026.
  6. Axios, “NSA Using Anthropic’s Mythos Despite Defense Department Blacklist,” April 19, 2026.
  7. CSO Online, “White House Moves to Give Federal Agencies Access to Anthropic’s Claude Mythos,” April 2026.
  8. Fortune, “Anthropic Acknowledges Testing New AI Model,” March 26, 2026.
  9. TechCrunch, “Anthropic Debuts Preview of Powerful New AI Model Mythos,” April 7, 2026.
  10. Axios, “Anthropic to Have Peace Talks at White House,” April 17, 2026.
  11. CNBC, “Trump Says He Had ‘No Idea’ About White House Meeting,” April 17, 2026.
  12. Washington Post, “Anthropic CEO Visits White House Amid Hacking Fears,” April 17, 2026.
  13. Council on Foreign Relations, “Six Reasons Claude Mythos Is an Inflection Point,” April 2026.
  14. Evron, Mogull, Lee et al., “The AI Vulnerability Storm: Building a Mythos-Ready Security Program,” CSA/SANS/OWASP, April 2026.

Four Key Emerging Considerations with Artificial Intelligence (AI) in Cyber Security

#cryptonews #cyberrisk #techrisk #techinnovation #techyearinreview #infosec #musktwitter #disinformation #cio #ciso #cto #chatgpt #openai #airisk #iam #rbac #artificialintelligence #samaltman #aiethics #nistai #futurereadybusiness #futureofai

By Jeremy Swenson

Fig. 1. Zero Trust Components to Orchestration AI Mashup; Microsoft, 09/17/21; and Swenson, Jeremy, 03/29/24.

1. The Zero-Trust Security Model Becomes More Orchestrated via Artificial Intelligence (AI):

The zero-trust model represents a paradigm shift in cybersecurity, advocating for the premise that no user or system, irrespective of their position within the corporate network, should be automatically trusted. This approach entails stringent enforcement of access controls and continual verification processes to validate the legitimacy of users and devices. By adopting a need-to-know-only access philosophy, often referred to as the principle of least privilege, organizations operate under the assumption of compromise, necessitating robust security measures at every level.

Implementing a zero-trust framework involves a comprehensive overhaul of traditional security practices. It entails the adoption of single sign-on functionalities at the individual device level and the enhancement of multifactor authentication protocols. Additionally, it requires the implementation of advanced role-based access controls (RBAC), fortified network firewalls, and the formulation of refined need-to-know policies. Effective application whitelisting and blacklisting mechanisms, along with regular group membership reviews, play pivotal roles in bolstering security posture. Moreover, deploying state-of-the-art privileged access management (PAM) tools, such as CyberArk for password check out and vaulting, enables organizations to enhance toxic combination monitoring and reporting capabilities.

App-to-app orchestration refers to the process of coordinating and managing interactions between different applications within a software ecosystem to achieve specific business objectives or workflows. It involves the seamless integration and synchronization of multiple applications to automate complex tasks or processes, facilitating efficient data flow and communication between them. Moreover, it aims to streamline and optimize various operational workflows by orchestrating interactions between disparate applications in a cohesive manner. This orchestration process typically involves defining the sequence of actions, dependencies, and data exchanges required to execute a particular task or workflow across multiple applications.

However, while the concept of zero-trust offers a compelling vision for fortifying cybersecurity, its effective implementation relies on selecting and integrating the right technological components seamlessly within the existing infrastructure stack. This necessitates careful consideration to ensure that these components complement rather than undermine the orchestration of security measures. Nonetheless, there is optimism that the rapid development and deployment of AI-based custom middleware can mitigate potential complexities inherent in orchestrating zero-trust capabilities. Through automation and orchestration, these technologies aim to streamline security operations, ensuring that the pursuit of heightened security does not inadvertently introduce operational bottlenecks or obscure visibility through complexity.

2. Artificial Intelligence (AI) Powered Threat Detection Has Improved Analytics:

The utilization of artificial intelligence (AI) is on the rise to bolster threat detection capabilities. Through machine learning algorithms, extensive datasets are scrutinized to discern patterns suggestive of potential security risks. This facilitates swifter and more precise identification of malicious activities. Enhanced with refined machine learning algorithms, security information and event management (SIEM) systems are adept at pinpointing anomalies in network traffic, application logs, and data flow, thereby expediting the identification of potential security incidents for organizations.

There will be reduced false positives which has been a sustained issue in the past with large overconfident companies repeatedly wasting millions of dollars per year fine tuning useless data security lakes that mostly produce garbage anomaly detection reports [1], [2]. Literally the kind good artificial intelligence (AI) laughs at – we are getting there. All the while, the technology vendors try to solve this via better SIEM functionality for an increased price at present. Yet we expect prices to drop really low as the automation matures.  

With enhanced natural language processing (NLP) methodologies, artificial intelligence (AI) systems possess the capability to analyze unstructured data originating from various sources such as social media feeds, images, videos, and news articles. This proficiency enables organizations to compile valuable threat intelligence, staying abreast of indicators of compromise (IOCs) and emerging attack strategies. Notable vendors offering such services include Darktrace, IBM, CrowdStrike, and numerous startups poised to enter the market. The landscape presents ample opportunities for innovation, necessitating the abandonment of past biases. Young, innovative minds well-versed in web 3.0 technologies hold significant value in this domain. Consequently, in the future, more companies are likely to opt for building their tailored threat detection tools, leveraging advancements in AI platform technology, rather than purchasing pre-existing solutions.

3. Artificial Intelligence (AI) Driven Threat Response Ability Advances:

Artificial intelligence (AI) isn’t just confined to threat detection; it’s increasingly playing a pivotal role in automating response actions within cybersecurity operations. This encompasses a range of tasks, including the automatic isolation of compromised systems, the blocking of malicious internet protocol (IP) addresses, the adjustment of firewall configurations, and the coordination of responses to cyber incidents—all achieved with greater efficiency and cost-effectiveness. By harnessing AI-driven algorithms, security orchestration, automation, and response (SOAR) platforms empower organizations to analyze and address security incidents swiftly and intelligently.

SOAR platforms capitalize on AI capabilities to streamline incident response processes, enabling security teams to automate repetitive tasks and promptly react to evolving threats. These platforms leverage AI not only to detect anomalies but also to craft tailored responses, thereby enhancing the overall resilience of cybersecurity infrastructures. Leading examples of such platforms include Microsoft Sentinel, Rapid7 InsightConnect, and FortiSOAR, each exemplifying the fusion of AI-driven automation with comprehensive security orchestration capabilities.

Microsoft Sentinel, for instance, utilizes AI algorithms to sift through vast volumes of security data, identifying potential threats and anomalies in real-time. It then orchestrates response actions, such as isolating compromised systems or blocking suspicious IP addresses, with precision and speed. Similarly, Rapid7 InsightConnect integrates AI-driven automation to streamline incident response workflows, enabling security teams to mitigate risks more effectively. FortiSOAR, on the other hand, offers a comprehensive suite of AI-powered tools for incident analysis, response automation, and threat intelligence correlation, empowering organizations to proactively defend against cyber threats. Basically, AI tools will help SOAR tools mature so security operations centers (SOCs) can catch the low hanging fruit; thus, they will have more time for analysis of more complex threats. These AI tools will employ the observe, orient, decide, act (OODA) Loop methodology [3]. This will allow them to stay up to date, customized, and informed of many zero-day exploits. At the same time, threat actors will constantly try to avert this with the same AI but with no governance.

4. Artificial Intelligence (AI) Streamlines Cloud Security Posture Management (CSPM):

With the escalating migration of organizations to cloud environments, safeguarding the security of cloud assets emerges as a paramount concern. While industry giants like Microsoft, Oracle, and Amazon Web Services (AWS) dominate this landscape with their comprehensive cloud offerings, numerous large organizations opt to establish and maintain their own cloud infrastructures to retain greater control over their data and operations. In response to the evolving security landscape, the adoption of cloud security posture management (CSPM) tools has become imperative for organizations seeking to effectively manage and fortify their cloud environments.

CSPM tools play a pivotal role in enhancing the security posture of cloud infrastructures by facilitating continuous monitoring of configurations and swiftly identifying any misconfigurations that could potentially expose vulnerabilities. These tools operate by autonomously assessing cloud configurations against established security best practices, ensuring adherence to stringent compliance standards. Key facets of their functionality include the automatic identification of unnecessary open ports and the verification of proper encryption configurations, thereby mitigating the risk of unauthorized access and data breaches. “Keeping data safe in the cloud requires a layered defense that gives organizations clear visibility into the state of their data. This includes enabling organizations to monitor how each storage bucket is configured across all their storage services to ensure their data is not inadvertently exposed to unauthorized applications or users” [4]. This has considerations at both the cloud user and provider level especially considering artificial intelligence (AI) applications can be built and run inside the cloud for a variety of reasons. Importantly, these build designs often use approved plug ins from different vendors making it all the more complex.

Furthermore, CSPM solutions enable organizations to proactively address security gaps and bolster their resilience against emerging threats in the dynamic cloud landscape. By providing real-time insights into the security status of cloud assets, these tools empower security teams to swiftly remediate vulnerabilities and enforce robust security controls. Additionally, CSPM platforms facilitate comprehensive compliance management by generating detailed reports and audit trails, facilitating adherence to regulatory requirements and industry standards.

In essence, as organizations navigate the complexities of cloud adoption and seek to safeguard their digital assets, CSPM tools serve as indispensable allies in fortifying cloud security postures. By offering automated monitoring, proactive threat detection, and compliance management capabilities, these solutions empower organizations to embrace the transformative potential of cloud technologies while effectively mitigating associated security risks.

About the Author:

Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist / researcher, and senior management tech risk consultant. He is a frequent speaker, published writer, podcaster, and even does some pro bono consulting in these areas. He holds an MBA from St. Mary’s University of MN, an MSST (Master of Science in Security Technologies) degree from the University of Minnesota, and a BA in political science from the University of Wisconsin Eau Claire. He is an alum of the Federal Reserve Secure Payment Task Force, the Crystal, Robbinsdale and New Hope Citizens Police Academy, and the Minneapolis FBI Citizens Academy.

References:


[1] Tobin, Donal; “What Challenges Are Hindering the Success of Your Data Lake Initiative?” Integrate.io. 10/05/22: https://www.integrate.io/blog/data-lake-initiative/

[2] Chuvakin, Anton; “Why Your Security Data Lake Project Will … Well, Actually …” Medium. 10/22/22. https://medium.com/anton-on-security/why-your-security-data-lake-project-will-well-actually-78e0e360c292

[3] Michael, Katina, Abbas, Roba, and Roussos, George; “AI in Cybersecurity: The Paradox.” IEEE Transactions on Technology and Society. Vol. 4, no. 2: pg. 104-109. 2023: https://ieeexplore.ieee.org/abstract/document/10153442

[4] Rosencrance, Linda; “How to choose the best cloud security posture management tools.” CSO Online. 10/30/23: https://www.csoonline.com/article/657138/how-to-choose-the-best-cloud-security-posture-management-tools.html

Top 16 Ways SMBs Can Mitigate Cyber Risks and Threats.

Fig. 1. Stock Cyber Brain Graphic, 2022.
  1. Sign up for DHS CISA e-mail alerts specific to your company and industry needs and review the alerts:
    1. Sign up here.
    2. Use the free DHS developed CSET (Cybersecurity Evaluation Tool) to assess your security posture – High, Med, or Low. CSET is downloadable here.
  2. Educate Employees About Cyber Threats and Hold Them Accountable:
    1. Educate your employees about online threats and how to protect your business’s data, including safe use of social networking sites. Depending on the nature of your business, employees might be introducing competitors to sensitive details about your firm’s internal business.
    2. Employees should be informed about how to post online in a way that does not reveal any trade secrets to the public or competing businesses. 
    3. Use games with training and hold everyone accountable to security policies and procedures.
    4. This needs to be embedded in the culture of your company.
    5. Register for free DHS cyber training here.
    6. Use the free DHS SMB cyber resource toolkit.
  3. Protect Against Viruses, Spyware, and Other Malicious Code:
    1. Make sure each of your business’s computers are equipped with antivirus software and antispyware and updated regularly. Such software is readily available online from a variety of vendors. All software vendors regularly provide patches and updates to their products to correct security problems and improve functionality. Configure all software to install updates automatically. Especially watch freeware which contains malvertising.
  4. Secure Your Networks:
    1. Safeguard your Internet connection by using a firewall and encrypting information. If you have a Wi-Fi network, make sure it is secure and hidden. To hide your Wi-Fi network, set up your wireless access point or router so it does not broadcast the network name, known as the Service Set Identifier (SSID).
    2. Have a secure strong password to protect access to the router (xeeityyg18695845%&*&RELxu78IGO) — example.
    3. Lastly, use a VPN (virtual private network).
  5. Control Physical Access to Computers and Network Components:
    1. Prevent access or use of business computers by unauthorized individuals. Laptops can be particularly easy targets for theft or can be lost, so lock them up when unattended. Make sure a separate user account is created for each employee and require strong passwords.
    2. Administrative privileges should only be given to trusted IT staff and key personnel.
  6. Create A Mobile Device Protection Plan:
    1. Require users to password-protect their devices, encrypt their data, and install security apps to prevent criminals from stealing information while the phone is on public networks.
    2. Use a containerization application to separate personal data from company data.
    3. Be sure to set reporting procedures for lost or stolen equipment.
  7. Protect All Pages on Your Public-Facing Webpages, Not Just the Checkout and Sign-Up Pages:
    1. Make sure submission forms can block spam and can block code execution (cross-side scripting attacks).
  8. Establish Security Practices and Policies to Protect Sensitive Information:
    1. Establish policies on how employees should handle and protect personally identifiable information and other sensitive data. Clearly outline the consequences of violating your business’s cybersecurity policies and who is accountable.
  9. Base Your Security Strategy Significantly on the NIST Cybersecurity Framework 1.1: Identify, Detect Defend, Respond, and Recover:
    1. The NIST Cybersecurity Framework Small Business Resources are linked here.
No alt text provided for this image
Fig. 2. NIST Cyber Security Framework Sub Tasks, NIST, 2022:
  1. Require Employees to Use Strong Passwords and to Change Them Often:
    1. Consider implementing multifactor authentication that requires additional information beyond a password to gain entry. Check with your vendors that handle sensitive data, especially financial institutions, to see if they offer multifactor authentication for your account. Smart card plus passcode for example.
  2. Employ Best Practices on Payment Cards:
    1. Work with your banks or card processors to ensure the most trusted and validated tools and anti-fraud services are being used. You may also have additional security obligations related to agreements with your bank or processor. Isolate payment systems from other, less secure programs and do not use the same computer to process payments and surf the Internet. 
    2. Outsource some or all of it and know where your risk responsibility ends.
  3. Make Backup Copies of Important Business Data and Use Encryption When Possible:
    1. Regularly backup the data on all computers. Critical data includes word processing documents, electronic spreadsheets, databases, financial files, human resources files, and accounts receivable/payable files. Backup data automatically if possible, or at least weekly, and store the copies either offsite or on the cloud. 
    2. Having all key files backed up via the 3-2-1 rule — three copies of files in two different media forms with one offsite — thus reducing ransomware attack damage.
  4.  Make Sure Your Vendors Have the Required Security Compliance Attestations and Insurance:
    1. SOC 2, PCI, and HIPAA for example.
    2. Cyber/data breach insurance should be separate from general business liability, and you should know the exclusions and sub-limits.
  5. Use A Password Management Tool and Strong Passwords:
    1. Another way to stay safe is by setting passwords that are longer, complex, and thus hard to guess. Additionally, they can be stored and encrypted for safekeeping using a well-regarded password vault and management tool. This tool can also help you to set strong passwords and can auto-fill them with each login — if you select that option. Yet using just the password vaulting tool is all that is recommended. Doing these two things makes it difficult for hackers to steal passwords or access your accounts.
  6. Use Only Whitelisted Sites Not Blacklisted Ones or Ones Found Via the Dark Web:
    1. Use only approved whitelisted platforms and sites that do not expose you to data leakages or intrusion on your privacy. Whitelisting is the practice of explicitly allowing some identified websites access to a particular privilege, service, or access. Backlisting is blocking certain sites or privileges. If a site does not assure your privacy, do not even sign up let alone participate.
  7. Mimic Your Likely Threats with a Threat Modeling Methodology that works for your Industry:
    1. PASTA, VAST, and FAIR are just a few.

Abstract Forward Podcast #10: CISO Risk Management and Threat Modeling Best Practices with Donald Malloy and Nathaniel Engelsen!

Fig. 1. Joe the IT Guy, 10/17/2018

Featuring the esteemed technology and risk thought leaders Donald Malloy and Nathaniel Engelsen — this episode covers threat modeling methodologies STRIDE, Attack Tree, VAST, and PASTA. Specifically, how to apply them with limited budgets. It also discusses the complex intersection of how to derive ROI on threat modeling with compliance and insurance considerations. We then cover IAM best practices including group and role level policy and control best practices. Lastly, we hear a few great examples of key CISO risk management must-dos at the big and small company levels.

Fig. 2. Pasta Threat Modeling Steps (Nataliya Shevchenko, CMU, 12/03/2018).

Donald Malloy has more than 25 years of experience in the security and payment industry and is currently a security technology consultant advising many companies. Malloy was responsible for developing the online authentication product line while at NagraID Security (Oberthur) and prior to that he was Business Development and Marketing Manager for Secure Smart Card ICs for both Philips Semiconductors (NXP) and Infineon Technologies. Malloy originally comes from Boston where he was educated and has M.S. level degrees in Organic Chemistry and an M.B.A. in Marketing. Presently he is the Chairman of The Initiative for Open Authentication (OATH) and is a solution provider with DualAuth. OATH is an industry alliance that has changed the authentication market from proprietary systems to an open-source standard-based architecture promoting ubiquitous strong authentication used by most companies today. DualAuth is a global leader in trusted security with two-factor authentication include auto passwords. He resides in southern California and in his spare time he enjoys hiking, kayaking, and traveling around this beautiful world.

Nathaniel Engelsen is a technology executive, agilest, writer, and speaker on topics including DevOps, agile team transformation, and cloud infrastructure & security. Over the past 20 years he has worked for startups, small and mid-size organizations, and $1B+ enterprises in industries as varied as consulting, gaming, healthcare, retail, transportation logistics, and digital marketing. Nathaniel’s current security venture is Callback Security, providing dynamic access control mechanisms that allow companies to turn off well-known or static remote and database access routes. Nathaniel has a bachelor’s in Management Information Systems from Rowan University and an MBA from the University of Minnesota, where he was a Carlson Scholar. He also holds a CISSP.

The podcast can be heard here.

More information on Abstract Forward Consulting can be found here.

Disclaimer: This podcast does not represent the views of former or current employers and/or clients. This podcast will make every reasonable effort to verify facts and inferences therefrom. However, this podcast is intended to entertain and significantly inform its audience based on subjective reason-based opinions. Non-public information will not be disclosed. Information obtained in this podcast may be materially out of date at or after the time of the podcast. This podcast is not legal, accounting, audit, health, technical, or financial advice. © Abstract Forward Consulting, LLC.

8 Effective Third-Party Risk Management Tactics

In this increasingly complex security landscape with threat actors and vendors changing their tools rapidly, managing third-party risk is very difficult, ambiguous, and it’s even more difficult to know how to prioritize mitigation spend.

Fig 1. Risk, Stock Image, 2019.

The key to any vendor risk management program or framework is measurement, repeatability, and learning or improving from what was repeated as the business and risks change. These are the nine best practices you can follow to help assess your vendors’ security processes and their willingness to understand your risks and collectively mitigate both of them.

1) Identify All Your Vendors / Business Associates:

Many companies miss this easy step. Use RBAC (role-based access controls) when applicable – windows groups or the like. Creating a repeatable, written, compliance process for identifying them and making updates to the list as vendors move in and out of the company is worthwhile.

2) Ensure Your Vendors Perform Regular Security Assessments:

Risk assessments should be conducted on a weekly, monthly, or quarterly basis and reviewed and updated in response to changes in technology and the operating environment.

At a minimum, security risk assessments should include:

a) Evaluate the likelihood and potential impact of risks to in-scope assets.

b) Institute measures to protect against those risks.

c) Documentation of the security measures taken.

Vendors must also regularly review the findings of risk assessments to determine the likelihood and impact of the risk that they identify, as well as remediate any deficiencies.|

Fig. 2. Stock Image, Third-Party Risk Mgmt Inputs, 2019.

3) Make Sure Vendors Have Written Information Security Policies / Procedures:

a) Written security policies and procedures should clearly outline the steps and tasks needed to ensure compliance delivers the expected outcomes.

b) Without a reference point, policies and procedures can become open to individual interpretation, leading to misalignment and mistakes. Verify not only that companies have these written policies, but that they align with your organization’s standards. Ask other peers in your industry for a benchmark.

 4) Prioritize Vendors Based on Risk – Use Evidence and Input from Others – NOT Speculation:

a) Critical Risk: Vendors who are critical to your operation, and whose failure or inability to deliver contracted services could result in your organization’s failure.

b) High Risk: Vendors (1) who have access to customer data and have a high risk of information loss; and / or (2) upon whom your organization is highly dependent operationally.

c) Medium Risk: Vendors (1) whose access to customer information is limited; and / or whose loss of services would be disruptive to your organization.

d) Low Risk: Vendors who do not have access to customer data and whose loss of services would not be disruptive to your organization.

5) Verify That Vendors Encrypt Data in All Applicable Places – At Rest, In Transit, etc:

a) Encryption, a process that protects data by making it unreadable without the use of a key or password, is one of the easiest methods of protecting data against theft.

b) When a vendor tells you their data is encrypted, trust but verify. Delve deeper and ask for details about different in-transit scenarios, such as encryption of backup and what type of backup. Ask them about what type of encryption it is and get an infographic. Most people get lost when you ask this question.

c) It’s also imperative that the keys used to encrypt the data are very well-protected. Understanding how encryption keys are protected is as vital as encryption itself. Are they stored on the same server? Is multi-factor authentication needed to get access to them? Is there a time limit on how long they can have access to the key?

6) Ensure Vendors Have A Disaster Recovery Program:

In order to be compliant with the HIPAA Security Rule and related rules, vendors must have a detailed disaster recovery program that includes analysis on how a natural disaster—fire, flood or even a rodent chewing through cables—could affect systems containing ePHI. The plan should also include policies and procedures for operating after a disaster, delineating employees’ roles and responsibilities. Finally, the plan should clearly outline the plan for restoring the data.

7) Ensure Access Is Based on Legitimate Business Needs:

Fig 3. Stock Image, RBAC Flow, 2019.

It’s best to follow the principle of least privilege (POLP), which is the practice of limiting access rights for users to the bare minimum permissions they need to perform their work. Under POLP, users are granted permission to read, write, or execute only the files or resources they need to do their jobs. In other words, the least amount of privilege necessary. RBAC is worth mentioning here again.

8) Vet All New Vendors with Due Diligence:

a) Getting references.

b) Using a standard checklist.

c) Performing a risk analysis and determining if the vendor will be ranked Critical, High, Medium or Low.

d) Document and report to senior management.

Contact us here to learn more.

3 Key Points From “Unsecurity” By Evan Francen

UNSECURITY-1200x628-adNational author, speaker, consultant, and entrepreneur Evan Francen got into information security long before it was cool and buzzing in the media, and long before every so-called IT consultancy started chasing the money. In fact, he and I both dislike the money chasers. He and his growing consultancy, FRSecure are for-profit, but they don’t do it for the money.

Like a patriot who delays college to join the army amid dire national conflict, Francen offers a fact-based call to arms to fix the broken cybersecurity industry in his 2019 book “Unsecurity”. Having known him and his company for a few years, and having read the book and many on this subject, this content is worth sharing because too few people write or talk about how to actually make this industry better. Here are my three unbiased key points from his book.

1)    We’re Not Speaking the Same Language:

614hGPZRmJL._SY600_Francen opens his book with a lengthy chapter on how poor communication between cybersecurity stakeholders exacerbates trouble and risk. You can’t see or measure what isn’t communicated well. It starts because there are five main stakeholder groups who don’t share the same vocabulary amid conflicting priorities.

  1. IT: Speaks in data tables and code jargon.
  2. Cyber: Speaks in risk metrics and security controls.
  3. Business: Speaks in voice of the customer and profits.
  4. Compliance:Speaks in evidence collection and legal regulatory frameworks.
  5. Vendor: Speaks in sales and marketing terms.

Ideally, all these stakeholders need to work together but are only as strong as the weakest link. To attain better communication and collaboration between these stakeholders, all must agree on the same general security framework best for the company and industry, maybe NIST CSF with its inferred definitions or maybe ISACA Cobit. However, once you pick the framework you need to start training, communicating, and measuring against it and only it –going with its inferred definitions.

Changing frameworks in the middle of the process is like changing keys in the middle of a classical song at a concert – don’t do it. That’s not to say that once communication and risk management gets better, that you can’t have some hybrid framework variation – like at a jazz concert. You can but you need proof of the basic items first.

Later, in the chapter Francen describes the communication issue of too many translations. That’s too many people passing the communication onto other people and giving it their spin. Thus, what was merely a minor IT problem ticket turns into a full-blown data breach? Or people get tied up arguing over NIST, ISSA, ISACA, and OWASP jargon – all the while nothing gets fixed and people just get mad at each other yet fail to understand one another. Knowing one or two buzz words from an ISACA conference or paper yet failing to understand how they apply to NIST or the like does not help. You should be having a framework mapping sheet for this.

The bigger solution is more training and vetting who is authorized to communicate on key projects. The issue of good communication and project management is separate from cybersecurity though it’s a critical dependency. Organizations should pre-draft communication plans with roles and scope listed out, and then they should do tabletops to solidify them. Having an on-site Toastmasters group is also a good idea. I don’t care if you’re a cyber or IT genius; if you can’t communicate well that’s a problem that needs to be fixed. I will take the person with much better communication skills because likely they can learn what they don’t know better than the other.

2)    Overengineered Foundations:

In chapter two, Francen addresses “Bad Foundations”. He gives many analogies including building a house without a blueprint. However, I’m most interested in what he says on page 76:

  • “Problem #4 Overengineered Foundation – too much control is as bad as too little control, and in some cases, it’s even worse than no control at all.”

What he is saying here is that an organization can get so busy in non-real world spreadsheet assessments and redundant evidence gathering that their heads are in the sand for so long that they don’t see to connect the dots that other things are going array and thus they get compromised. Keep in mind IT and security staff are already overworked, they already have many conflicting dials and charts to read – amid false alarms. To bog them down in needless busywork must be weighed against other real-world security tasks, like patch management, change management, and updating IAM protocols to two-factor.

If you or your organization have an issue figuring this out, as Francen outlines, you need to simplify your risk management to a real-world foundational goal that even the company secretary can understand. It may be as simple as requiring long complex (multicharacter) passwords, badge entry time logs for everyone, encrypting data that is not public, or other basics. You must do these things and document that they have been done one at a time, engraining a culture of preventative security vs. reactive security.

3)    Cultivate Transparency and Incentives:

In chapter five, “The Blame Game” Francen describes how IT and business stakeholders often fail to take responsibility for security failings. This is heavily influenced by undue bias, lack of diversity, and lack of fact-based intellectualism within the IT and business silos at many mid-sized and large organizations. I know this is a hard pill to swallow but its so true. The IT and business leaders approving the bills for the vendors doing the security assessments, tool implementations, and consulting should not be under pressure to give a favorable finding in an unrealistic timeframe. They should only be obligated to give timely truthful risk prudent advice. Yet that same advice if not couched with kid gloves can get a vendor booted from the client – fabricating a negative vendor event. Kinda reminds me of accounting fraud pre-Sarbanes Oxley.

The reason why is because risk assessors are creating evidence of security violations that the client does not agree with or like, and thus you are creating legal risk for them – albeit well justified and by their own doing. From Francen’s viewpoint, this comprehensive honest assessment also gives the client a way to defend and limit liability by disclosing and remediating the vulnerabilities in a timely manner and under the advisement of a neutral third party. Moreover, you’re going to have instructions on how to avoid them in the future thus saving you money and brand reputation.

Overall, transparency can save you. Customers, regulators, and risk assessors view you more positively because of it. That’s not to say there are not things that will remain private because there are many, trade secrets, confidential data, and the like. My take on Francen’s mention of the trade off’s between transparency and incentives in a chapter called “The Blame Game” is that it’s no longer acceptable to delay or cover up a real security event – not that it ever was. Even weak arguments deliberately miscategorizing security events as smaller than they are will catch up with you and kick your butt or get you sued. Now is the time to be proactive. Build your incident response team ahead of time. It should include competent risk business consultants, cyber consultants, IT consultants, a communication lead, and a privacy attorney.

Lastly, if we as an industry are going to get better we’re going to have to pick up books, computers, pens, and megaphones. And this book is a must-read! You can’t be passive and maintain your expert status – it expires the second you do nothing and get poisoned by your own bias and ego. Keep learning and sharing!

Cybersecurity Firm Imperva Discloses Data Breach

Imperva, formally Incapsula, disclosed on 08/27/19 a data breach impacting its many customers. The company focuses on cyber-security and DDoS mitigation and consulting, heavily via its cloud web application firewall (WAF).

Fig. 1. Imperva, 2019.incapcloud

The breach was discovered 08/20/19 via a third-party. Unfortunately, the exposure goes back to 09/15/17 which means they were compromised at least in part for more than two full years! Clearly, this is evidence of poor internal controls. The exposed data includes customer email addresses, hashed and salted passwords; and API keys and customer-provided SSL certificates — for a partial portion of the exposed data.

Don’t count on cyber security and software firms to be more secure than any other type of company. This breach is likely to negatively impact sales, product design, and will trigger a few investigations, and at least one lawsuit. Additionally, the insurance claim question is a loaded one — and is dependent on how much due diligence the company did before the breach.

To learn more about how to stop data breaches like these at your organization consider attending the Cyber Security Summit this fall.

  • The Ninth Annual Cyber Security Summit, “Pushing the Cyber Security Envelope,” takes place Oct. 28-30, 2019, at the Minneapolis Convention Center in Minneapolis, Minn.
  • The Summit has given awards to top leaders in industry, government and academia since 2015. However, for 2019 the awards program was expanded to include a wider array of visionaries.
  • New this year, women in Cyber, PLUS 16 Tech Sessions, along with Healthcare & Med Device Cyber Security.  Check out this Star Tribune piece from Summit co-chair Catharine Trebnick and colleague Kyle Bauser on this very important topic.
  • To stay up to date on the Summit and top cyber security issues, follow the Cyber Security Summit on social media: TwitterFacebookLinkedInYouTube. Follow the hashtag #cybersummitMN for the latest conversations on this top matter.

As Summit co-founder Eileen Manning stresses in a well-circulated cover story for Upsize Magazine, cyber security is fundamental for small businesses that work with larger companies, which require it – not to mention for pure survival.

Data breaches like the one at Imperva are likely to increase so interested parties should come together to learn, debate, and flesh out solutions for a more secure future!

Top Ten Ways Companies Can Reduce Cyber Risk

cost-of-cyber-attacks-to-business-mq593szq6dt3vzuawhu5qtm2upt66jfkqpxzl18l8sMid-sized businesses are defined from about $50 million to $800 million in revenue. A 2017 report published by Keeper Security and the Ponemon Institute found more than 50% of small and medium business had been breached in the past 12 months, but only 14% of them rated their ability to defend against cyber-threats as “highly effective” (Keeper / Ponemon, 2017). According to the 2017 Verizon Data Breach Investigations Report, 75% of the breaches were caused by outsiders with 51% involving organized criminal groups and the remaining involved internal actors. Not surprising, malware installed via malicious email attachments was present in 50% of the breaches involving hacking(Verizon, 2017). Here are ten steps (applicable to any size business) you can take to shield your mid-sized business from cyber-attacks:

10) Train Staff Often:

Most cyber-attacks take the form of phishing and spear phishing which is hackers targeting individuals rather than computer systems – typically with the help of good social engineering (IT Governance Blog, 2017). Therefore, employees need to be educated to roll back what they share on social media and to opt out of data harvesting when they can. Training needs to be ongoing because the threat landscape and technology change so fast. For example, ransomware was not a serious attack vector 6 years ago, but it is front and center today. Additionally, crypto-currency mining networks is an exploit vector that is arguably less than 2 years old and growing rapidly. Lastly, training more often improves the company security culture and that is directly related to keeping a good business reputation and core customer base. Here are a few more training necessities:

1. Follow cyber security best practices and conduct audits on a regular basis – based on your selected one or two frameworks (Cobit 5, ISO 2700, etc)

2. Use games contest and prizes to teach cyber safety – leadership must do this as well.

3. Notify and educate staff of any current cyber-attacks – have a newsletter.

4. Teach them how to handle and protect sensitive data – do lunch and learns.

9) Secure Wireless Networks:

Wireless networks can be easily exploited by cyber attackers, unknowing guests, and even angry customers. Your network is not like a coffee shop community room but rather it’s like a bank vault with many segmented areas – map the segments and know their rank order value. To harden your wireless network, avoid WEP (Wired Equivalent Privacy) encryption (which can be cracked in minutes) and use only WPA2, which uses AES-based encryption and provides better security than WPA.

Fig 1. (WPA2 Selection Screen Clip).

wpa_top

If you have a Wi-Fi network, be sure access to the router is secured by a password and hidden so that it does not broadcast the network name. To hide your Wi-Fi network, set up your wireless access point or router so it does not broadcast the network name, known as the Service Set Identifier (SSID). Also, remember to password-protect access to the router. Additionally, for protection against brute-force attacks, protect your network with a complex passphrase containing at least 25 characters and including a mix of letters, upper and lower case and numerals and symbols. Use a firewall and encryption to safeguard your internet connection.

8) Physically Secure Your Environment:

Focusing on web tools and monitoring is needed, but it’s also important to remember there are physical concerns about securing your network as well. To a threat actor overcoming all of your security measures may be as easy as walking up to your router and pressing the reset button. Make sure that your key pieces of in-office infrastructure are secure, and that you’re monitoring them with video, sensors or other physical security controls. Make sure to be creative and thorough about how you define a physical security connection point including: doors, public lobbies, windows, air vents, turnstiles, roofs, printer room, network closet, and USB ports on machines, etc. Lastly, employees should keep their devices near them at all times.

7) Double Down on Firewalls:

While most routers have a firewall built in that can protect your internal network against outside attacks, you should know that it may not be automatically activated. It’s generally called something like SPI (stateful packet inspection) or NAT (network address translation). Either way, turn it on (Chelsea Segal, Cox Blue, 09/16/18).

It’s also important to ensure that your own software isn’t sending information out over the network or the internet without your permission. For that, you’ll want to install firewall software on your PC as well. PC Magazine’s top pick is Check Point ZoneAlarm Pro, but the default firewall that comes with Windows 8 and 10 is also a good start.

6) Evaluate Your Operational Resilience and Cyber-Security Practices Quarterly: 

A good start is the US-CERT’s Cyber Resilience Review (CRR), which helps organizations assess enterprise programs and practices across 10 domains including risk management, incident management, service continuity, and more (SBA, 2018). They can also use the CSET (Cyber Security Evaluation Tool), which is a free customizable multi-framework DHS created general cyber security assessment.

5) Review Control Access / IAM and Audit Access Regularly:

Administrative access to your systems should only be granted on a need-to-know basis – least privilege principle. The correct job roles should be in the correct windows access groups. Keep sensitive data – such as payroll – out of the hands of anyone who doesn’t need it to do their job, marketing for example. Remove unused, stale, or unnecessary IAM users/credentials. Also, consider decommissioning old systems for risk reduction and cost savings – with the appropriate project analysis done. Use a secure strong password especially for single sign on interfaces – two factor authentication. Organizations should audit their IAM user activity to see which users haven’t logged into AWS for at least 90 days and revoke their permissions. Monitor user activity in all cloud services (including IAM user activity) to identify abnormal activity indicative of threats arising from a compromised account, or malicious/negligent internal employee – when corroborated with event logs and related intelligence.

4) Back up and Secure Your Systems and Data but Don’t Over Retain:

Ransomware, or viruses used by hackers to encrypt an organization’s computer files and detain them until a ransom is paid, has emerged as a serious and growing threat to businesses worldwide, according to the FBI (FBI CISO Report 2018). Whether data is stored in the cloud, on-premises, or in a hybrid data center, businesses should back up all files to hard drives stored in a safe place outside the reach of cyberthieves. These are some key data backup subpoints.

1. Limit access to sensitive data to only a few authorized employees.

2. Encrypt all your sensitive data – do not over-classify.

3. Backup your data periodically and store it in an offsite location.

4. Protect all devices with access to your data – third party vendor implications.

5. If you accept credit cards transactions, secure each point of sale.

3) Create a Guidebook for Mobile Security:

While mobile devices allow for work anywhere, anytime, they create significant security challenges. The FCC suggests requiring users to password-protect their devices, encrypt data, and install security apps to prevent criminals from stealing information while the phone is on public networks (FCC, Feb 2018). Plus, set reporting procedures for lost or stolen mobile devices. Draft a BYOD policy that separates personal vs. corporate data and covers the below points.

1. Ensure your equipment has the latest security software and run anti-virus/malware scans regularly. If you don’t have good anti-virus software installed, buy and install it.

2. Install all software updates as soon as they are available, including all web browsers.

3. Have the latest operating systems on your devices with access to regular updates.

4. Make sure your internet connect is protected with firewall security.

5. Make sure your Wi-Fi network is encrypted, hidden, and password protected.

2) Use Encrypted Websites for E-commerce Via Strong Third-Party Risk Management Policies:

Only buy from encrypted websites by looking for https on every page. Don’t’ be teased in by super low prices or the like, it may be a drive by download set-up. Ensure that the owner of the website is reputable and is who they say they are. This kind of gets at third party and supply chain risk management, which should be based on some applicable security framework for your industry, etc.

1) Avoid When Possible and Rigorously Evaluate Freeware:

There are a lot of free options for software including anti-virus (AVG), graphic design (GIMP), marketing and sales applications, some of which are quite reliable. However, many are not reliable and pose risk because they often come with malvertising, utility ad ons that slow things down, or direct malware. All of this complicates cyber risk and blurs sight lines into the infrastructure stack. Cyber security isn’t a good place to cut costs so pay for a good antivirus and firewall tool-set. If you are going to use a robust free graphic design tool like GIMP make sure it is documented, always updated, and that it is run in a limited area.

Bonus) Have a Sound Way To Prioritize Patching.

Establish a process to risk-rate vulnerabilities based on: ease of exploit and potential impact of the vulnerability (reference the CVE scores), if other working defenses are in place, and lastly by grouping the assets they may impact.

Reach out to me here for questions.

British Airways Data Breach Likely The First GDPR Rollback Test.

On 08/21/18 British Airways (BA) suffered the start of a data breach which ended on or about 09/05/18. A UPS (uninterruptible power supply) failure and subsequent power surge was partly how the breach was exacerbated. It was also indicated that a third party (vendor) was involved in some way which complicates liability and brings supply chain security more into scope.

The breach allowed cyber criminals to steal personal and financial information from about 380,000 customers who booked directly with the airline in the preceding two weeks (Ivana Kottasová, CNN, 09/07/18). When a passenger makes a booking through the BA website, they must submit their name, e-mail address, address, and credit or debit card details including: the number, expiration date, date, and the security code or “Card Verification Value” (CVV) — all of this was compromised.

Yet most interestingly, this is one of the first major data breaches since GDPR came into effect in May this year, Walters said (Samuel Gibbs, the Guardian, 09/07/18). “It appears that the company notified the Information Commissioner’s Office and customers within the GDPR’s mandatory 72 hours but the breach will now be investigated and the company could be penalized if it did not take all the necessary measures to protect customer data” (Samuel Gibbs, the Guardian, 09/07/18).

The GDPR rules now in force could see a great increase in the penalties slapped on firms for past data breaches, with fines levied at a maximum of 4% of global revenues. For British Airways’ this amounts to about $630 million dollars based on last years revenue (Gwyn Topham, the Guardian, 09/06/18).

Yet many observers see fines this hefty as counterproductive and the catalyst to push business outside of the EU. Moreover, many international law firms and economists have doubts about the applicability of the GDRP outside of the EU, citing state sovereignty, and free enterprise protection in the United States, etc. The courts will likely further define the context of GRPRs applicability and may roll its reach back some. It is way to early to know what GDPR means in practicality but pushback is coming from well funded, well organized, well researched powerful law and business interest groups. GDPR is dangerously overbroad and ambiguous as echoed in this law firm newsletter (Wendy Butler Curtis and Jeffrey McKenn, Orrick, Herrington & Sutcliffe LLP, 09/09/18). We welcome the debate for a better more modern GDPR.