July 11, 2016 By Douglas Bonderud 2 min read

Corporations aren’t known for sharing. With so many employees, partners, providers and customers to manage, there’s always a chance for data compromise — so why risk it by sending more information around? And thanks to the rise of wearables, always-connected devices and the industrial IoT, these risks are growing.

The bigger problem? Malicious actors have no trouble swapping stories of compromise and successful attacks, putting the onus on companies to embrace security collaboration if they want to keep their networks safe. How do businesses trump the trust issue?

Is Security Collaboration Counterintuitive?

As noted by CIO, security firm Carbon Black is now “opening a line of communication” between companies with its new platform, the Detection eXchange. The idea here is to go beyond surface information such as virus signatures or IP addresses to share actual data about attack patterns and threat vectors. After all, it’s nothing for attackers to swap out a flagged IP address, but if they find typical attack patterns blocked at every turn, they’ll be left scrambling to change their ways.

Of course, security-savvy IT pros have raised a valid concern: If the goal of security firms is to protect key data, does it really make sense to share critical information? In the case of Carbon Black, for example, the government ultimately acts as a clearinghouse for shared data. It’s not a stretch to imagine this repository as a high-value target for cybercriminals, and once they have the inside track on how companies plan to deal with emerging threats, they can simply change tactics.

So while security collaboration sounds great, many companies balk at the idea of actually participating or share only the bare minimum required to ensure their own critical processes can’t be compromised.

Building a Better Mousetrap

The calls for national and global threat sharing frameworks are getting louder: As noted by SC Magazine, a recent cybercrime report from the U.K.’s National Crime Agency (NCA) argued that greater threat sharing is essential now that digital crime has outpaced traditional lawbreaking in the country. Additionally, TechCrunch made the case for a worldwide cyberthreat sharing program to help combat adaptive attackers.

Already, the Cybersecurity Information Sharing Act of 2015 (CISA) makes it possible for companies to share security information with the Department of Homeland security without facing legal ramifications for reporting data breaches in good faith. According to Dark Reading, however, any type of threat sharing framework is effectively a gamble since cybercriminal access to threat feeds negates any positive impact.

The piece does offer a few suggestions, however. For example, machine-to-machine-only threat feeds integrated with SIEM tools could be an option, along with completely anonymous reporting and the elimination of opt-in programs. Since corporations understandably value their privacy and freedom of action, this may be a case where anonymous, mandated reporting outweighs the benefit of opting to stay silent.

Companies are right to be wary of large-scale security collaboration initiatives. What if attackers grab control of this emerging threat playbook and use it to run an entirely new game? But hunkering down behind supposedly secure digital walls does nothing to improve the outcome. Trumping the trust issue is a rough ride but — win or lose — a unified security front gives companies a fighting chance.

More from

When ransomware kills: Attacks on healthcare facilities

4 min read - As ransomware attacks continue to escalate, their toll is often measured in data loss and financial strain. But what about the loss of human life? Nowhere is the ransomware threat more acute than in the healthcare sector, where patients’ lives are literally on the line.Since 2015, there has been a staggering increase in ransomware attacks on healthcare facilities. And the impacts are severe: Diverted emergency services, delayed critical treatments and even fatalities. Meanwhile, the pledge some ransomware groups made during…

AI and cloud vulnerabilities aren’t the only threats facing CISOs today

6 min read - With cloud infrastructure and, more recently, artificial intelligence (AI) systems becoming prime targets for attackers, security leaders are laser-focused on defending these high-profile areas. They’re right to do so, too, as cyber criminals turn to new and emerging technologies to launch and scale ever more sophisticated attacks.However, this heightened attention to emerging threats makes it easy to overlook traditional attack vectors, such as human-driven social engineering and vulnerabilities in physical security.As adversaries exploit an ever-wider range of potential entry points…

4 trends in software supply chain security

4 min read - Some of the biggest and most infamous cyberattacks of the past decade were caused by a security breakdown in the software supply chain. SolarWinds was probably the most well-known, but it was not alone. Incidents against companies like Equifax and tools like MOVEit also wreaked havoc for organizations and customers whose sensitive information was compromised.Expect to see more software supply chain attacks moving forward. According to ReversingLabs' The State of Software Supply Chain Security 2024 study, attacks against the software…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today