Archive
The failure of enterprise to prepare for cyberattacks
Late last month, Zeitgeist went with friends to his local theatre to see “Teh [sic] Internet is a Serious Business”. The play, a story of the founding of the hacktivist group Anonymous, was the most well-publicised dawn of cyberattacks on businesses and governments. The organisation, at its best, set it sights on radical groups that promoted marginalisation of others, whether that was the Church of Scientology in the US or those trying to dampen the Arab Spring in Tunisia. This collective, run by people, some of whom were still in school, showed the world how vulnerable institutions were to being targeted online. We wrote about cybersecurity as recently as this summer, summarising the key points in a recent report from The Economist on what was needed to mitigate against future attacks and how to reduce the damage such attacks inflict. The issue is not going away (and in fact is likely to become worse before it gets better).
It was back in January that management consultancy McKinsey produced a report, ‘Risk and responsibility in a hyperconnected world: Implications for enterprises’, where they estimated the total aggregate impact of cyberattacks at $3 trillion. There is much to be done to avert such losses, but the current picture is far from rosy. Most tech executives gave their institutions “low scores in making the required changes”, the report states; nearly 80% of them said they cannot keep up with attackers’ – be they nation-states or individuals – increasing sophistication. Moreover, though more money is being directed at this area, “larger expenditures have not translated into an increased maturity” yet. And while the attacks themselves carry potentially devastating economic impact on a company, their prevention comes at a price too for the business, beyond the financial. McKinsey reports that security concerns are delaying mobile functionality in enterprises by an average of six months. If attacks continue, the consultancy posits this could result in “a world where a ‘cyberbacklash’ decelerates digitization [sic]”. Revelations about pervasive cyberspying by Western governments on their own citizens could well be a catalyst to this. Seven points are made in the report for enterprises to manage disruptions better:
- Prioritise the greatest business risks to defend and invest in.
- Provide a differentiated approach to defence of assets, based on their importance.
- Move from “simply bolting on security to training their entire staff to incorporate it from day one into technology projects”.
- Be proactive; develop capabilities “to aggregate relevant information” to attune defence systems
- Test. Test. Test again.
- Enlist CxOs to help them understand the value in protection.
- Integrate risk of attack with other corporate risk analysis
Given the amount of business and social issues that involve digital processes – “IP, regulatory compliance, privacy, customer experience, product development, business continuity, legal jurisdiction” – there is a huge amount of disagreement about how much state involvement there should be in the degree to which enterprises must take steps to protect themselves. This is an important point for discussion though, and we touched on it when we wrote about cyberattacks previously.
But that report was way back in January, things must have solved themselves since then, right? Last week, PwC reported that corporate cyber security budgets are being slashed, even while cyberattacks are becoming far more frequent. The FT reported that global security budgets fell 4% YoY in 2014, while the number of reported security incidents increased 48%. Bear in mind these are only reported incidents. This is potentially no bad thing, if we’re to go by McKinsey’s diagnosis of too much money being thrown at the problem in the first place. At the same time, it’s not exactly comforting.
Only a few days after PwC’s figures were published, JP Morgan revealed that personal data for 76 million households – about two-thirds of total US households – had been “compromised” by a cyberattack that had happened earlier in the year. Information stolen included names, phone numbers and email addresses of customers. It was also revealed that other financial institutions were probed too. Worryingly, the WSJ reports that investigators disagree on what exactly the hackers did. It was also unclear who was to blame; nation state or individual. Such disagreements over the ramifications of the attack, the identity of the attackers as well as the delayed revelation of the attack itself, illustrate just how necessary transparency is, if such attacks are to be better protected against and managed in the future.
For those in London at the end of the month, The Economist is hosting an event for those who apply, on October 21, examining “how businesses can and should respond to a data breach, whether it stem from a malicious insider, an external threat or simple carelessness”. Hope to see you there.
The Piracy Pivot – A new heading for copyright enforcement?
Pretty much seven years ago to the month, Zeitgeist was putting the finishing touches to his Master’s dissertation. It centered on intellectual property rights, and the infringement of those rights by consumers who were downloading content they weren’t paying for. Zeitgeist conducted multiple interviews, including several with key people at studios and industry bodies in Europe and Los Angeles. It was a time when the industry were trying to curtail piracy using massive fines and jail sentences, at the same time providing few legal alternatives for content consumption online (this latter issue is still a problem today). Needless to say, there were a fair amount of heads buried in the sand. We’ve talked about piracy before, from its murky impact on the bottom line to the stricture of copyright law.
It was refreshing to see the news reported by industry trade mag Variety that Comcast – a large cable operator in the US, which also owns NBCUniversal – is investigating new methods of disrupting piracy online. Specifically, they are planning to push pop-ups to those who are downloading content illegally, providing them with links to alternative domains where the same product can be downloaded legally. There are privacy concerns here, undoubtedly. What was most reassuring about the idea though was crystallised below by journalist Andrew Wallenstein, which for Zeitgeist hits the nail on the head:
Using pirated content as a platform to drive legal transactions reflects an alternate philosophy regarding copyright infringement, one that sees the illegal activity less as a crime that requires punishment and more as lead generation to a consumer whose behavior is borne out of inadequate legitimate digital content options.
Is Sony back in the game?
After an annual loss of $6.4bn in 2011, Sony has since seen a new CEO come to the fore in the form of Kazuo Hirai, who immediately made it clear that major changes were needed, including significant job cuts, and a renewed focus on, among other sectors, videogames.
Last week at Gamescom, the company fared extremely well, “after unveiling wildly inventive new games for the PS3 and PS Vita, and fleshing out the appeal of its Wonderbook”. The Wonderbook – which consumers in London will get to try out this bank holiday weekend – in particular is of interest as it is a wholly separate device that works with your gaming device, and one of the few platforms that has an proprietary deal with author J.K. Rowling.
Mobile is another one of the significant sectors that Sony will be focussing on. The end of the company’s partnership with Ericsson will only help with this focus. The company tried to integrate gaming and mobile before the end of the partnership in the iteration of Xperia Play, with limited success. Beyond creating their own handset with PlayStation capabilities, they are now branching out. In June, Geek ran an article saying HTC has been given the rights to produce a certified PlayStation phone. Secondly, a company called GameKlip now allows you to play games on your Android phone with a PlayStation controller.
The Geek article talks about the initiative being “part of their attempt to broaden the PlayStation brand and increase total market share”. But since when has PlayStation been suffering as a brand? If you look at the social media fan base, PS has far greater affinity than the Sony brand. Is Sony giving away one of its biggest advantages (be it proprietary content, IP) to its biggest competitors in the mobile space, or is the bigger picture about simply extending the PlayStation brand as far and wide as possible?