Skip to main content

More collaboration needed to improve national cyber resilience, says Bank of Canada exec

More candid threat sharing between companies and governments is needed to help protect critical infrastructure and residents from cyber attacks, said experts, including a senior official of the Bank of Canada.

Filipe Dinis, Bank of Canada.

“We need to urgently step up the spirit of collaboration throughout the Canadian economy,” Filipe Dinis, the bank’s chief operating officer said at a meeting on Tuesday with the Information Technology Association of Canada (ITAC). “We need to encourage regular exercises that present companies with complex scenarios to test their cyber defenses and response capabilities. Even the process of designing risk scenarios can help companies determine potential sources of risk.”

He also suggested that regulators who oversee various industries might create “trusted secure channels” so sensitive threat-related information from a victim can be exchanged while protecting them from being publicly shamed.

“Further, governments could also consider strengthening minimum requirements around cyber resilience and mandate industry-wide and cross-sectoral testing that requires institutions to fix problems identified by the tests.”

The Bank of Canada plans to hold “regular, realistic and stringent” tabletop tests with financial institutions.

“I don’t expect that we’ll design the perfect regulations here today,” he told the meeting. “But I would suggest that there is room to enhance our current regulatory frameworks that rely on financial penalties, albeit not exclusively. After all, if company management is unable to accurately gauge the risk of a systemic cyber event, it may well decide the fine for non-compliance is a cost that is worth paying.”

A number of sectors are doing some collaboration, he added, citing the work of ITAC — which represents some of the country’s biggest tech companies — and the CIO Strategy Council.

But significant challenges remain, he added.

“What’s more, we need to act quickly and forcefully to deal with them,” he said.

He urged industry groups to work with public sector authorities, including regulatory bodies and intelligence agencies, to design and implement national cyber exercises and penetration tests.

“It’s now time to build exercises that involve multiple economic sectors, to provide a more demanding and realistic test of our economic cybersecurity.

“We need to build mechanisms that will significantly increase the sharing of cyber threat information and cyber defense best practices between public and private sector organizations. This will be particularly important for smaller companies that have fewer resources to dedicate to cybersecurity.

“We should also consider opportunities to build sector-wide cyber defense approaches and systems to protect many companies at a time. These would maximize resilience, rather than having each company solely responsible for its own defenses. Think about how cloud computing companies work to provide specific services for many companies, freeing those smaller firms to concentrate on their core lines of business.”


Related story: Canadian cyber attack led to new mining industry threat sharing centre


Billed by ITAC as a cybersecurity update, the meeting also featured an expert panel, all of who agreed on the need for more threat intel and remediation collaboration but pointed out a number of obstacles.

Michele Mullen, CCSC.

Jack Pagano, director of cybersecurity for Cisco Systems Canada, said his firm collaborates with “fierce competitors”, but that collaboration only works if you remove it from the business and focus on the greater good to “help solve the cybersecurity problems we’re all facing.”

But, he added, “the minute the business gets their fingers into it if you find a threat it becomes a competitive advantage.” Then “you do a press tour and a whole bunch of marketing around it, which defeats the purpose.”

Michelle Mullen, director-general of partnerships and risk mitigation at the federal government’s Canadian Cyber Security Centre, said it’s “really great to talk about collaboration and singing ‘Kumbaya’ when it’s peacetime [meaning there are no cyber attacks] … but when the chips are down and you’re in the middle of an incident we find it’s much harder for anybody to be open and collaborative and sharing of what’s happening to them because of the reputational risk.”

“Ask everyone…to learn to be a good victim and collaborate even through the worst times,” she urged.


Related story: Threat sharing efforts still fall short, says McAfee


Mohammad Qureshi, enterprise chief information officer and chief information security officer for the province of Ontario, noted that the new government has promised to set up a cybersecurity centre of excellence for sharing information. It’s still being worked on.

He also noted provincial and territorial governments are increasingly talking to each other: Once a month provincial CISOs network through a teleconference, and meet face to face every six months, sharing threat intelligence and experience on what technology solutions work, or don’t work.

Interestingly, no one mentioned the Canadian Cyber Threat Exchange (CCTX), which has created a special pricing model to entice local governments, hospitals and institutions of higher education to join the not-for-profit data exchange and participate in newly set-up private sector discussion forums.

Mullen said now that the Canadian Cyber Security Centre — which is just over a year old — has a mandate not just to secure federal IT networks but also to work with the private and public sectors it is increasingly working with the provinces.

But she also said companies should be more willing to call the Centre for help if attacked. The Centre won’t tell the media it is working with a victim firm, nor report it to a regulator, she said. In fact, she added, it requires a letter of request for help from a firm, and in return gets a non-disclosure agreement from the Centre. No incident information is shared without permission.

However, Mullen also said spreading the word about the Centre’s capabilities and knowledge is “my biggest problem.” She’s looking for industry associations, managed service providers, sectoral entities to reach organizations.

On the other hand, spreading the message about cybersecurity within certain federal departments is still a problem. There are “different viewpoints on how serious this problem really is,” Mullen said, “all of that continues to shock us” at the Centre.

Ray Boisvert, currently an associate partner at IBM Security and former deputy director of the Canadian Security Intelligence Service (CSIS), said permission for organizations to collaborate is a matter of corporate leadership.



Udimi - Buy Solo Ads from IT World CanadaIT World Canada https://ift.tt/2pficfE
via IFTTT

Comments

Popular posts from this blog

9 VCs in Madrid and Barcelona discuss the COVID-19 era and look to the future

Spain’s startup ecosystem has two main hubs: Madrid and Barcelona. Most observers place Barcelona first and Madrid second, but the gap appears to close every year. Barcelona has benefitted from attracting expats in search of sun, beach and lifestyle who tend to produce more internationally minded startups. Madrid’s startups have predominantly been Spain or Latin America-focused, but have become increasingly international in nature. Although not part of this survey, we expect Valencia to join next year, as city authorities have been going all-out to attract entrepreneurs and investors. The overall Spanish ecosystem is generally less mature than those in the U.K., France, Sweden and Germany, but it has been improving at a fast clip. More recently, entrepreneurs in Spain have moved away from emulating success in pursuit of innovative technologies. Following the financial crisis, the Spanish government supported the creation of startups with the launch of FOND-ICO GLOBAL, a €1.5 billi

How to Stay Creative and Keep SEO in Mind

Information Technology Blog - - How to Stay Creative and Keep SEO in Mind - Information Technology Blog Search engine optimization (SEO) refers to customizing your website’s content to ensure that web browsers give your website a high SEO score. The sites with the highest SEO scores are featured on the search engine’s first page of search results for relevant searches.  71%  of the click-throughs happen with articles listed on the first page of results on the search engine. This means that if your website’s article is the second (or third, or fourth page), it’s less likely the search user will even see your article. You want your article to be ranking as close to the top of the first page of results as possible. In order to have a good SEO score your site’s content needs to feature keywords and relevant phrases. It must be optimized for easy navigation between pages. It also needs to be referenced via external links that drive traffic to your site. Incorporating all of these elem

Digital World And SEO Challenges In 2020

Information Technology Blog - - Digital World And SEO Challenges In 2020 - Information Technology Blog Can you imagine a life without any digital intervention? Certainly not! We are dependent on the assistance of smart gadgets from ordering food to our tables to book tickets for vacations. Humans are utterly reliant on a masterpiece they have built with their incredible intellects. I am amazed by this. Let’s have a broader look into it. The Era Of Digital Marketing We exist in a time where every single business entity requires assistance from the digital market. It has now put an end to conventional marketing practices. To get your product the desired popularity, one must choose an E-commerce business approach. According to a survey , almost 3.4 billion people (approx. 85% of users) spend about six and a half hours browsing the web. Your customers will be more likely to do an online purchase rather than buying it from a nearby store. So, get a cool website built, use the best pos