Microsoft recently hosted the third edition of its popular CISO Executive Series in Oman, where industry experts and Chief Information Security Officers gathered to share and discuss current trends in cybersecurity. The event, held at Hormuz Grand in Muscat, was titled “Insights for the Progressive CISO”, and allowed the region’s security professionals to engage in candid exchanges with some of the world’s most renowned experts, in a day of insights, networking and learning.
Microsoft released the 23rd edition of its Security Intelligence Report, a bi-annual publication that the company creates for customers, partners, and the industry to educate organizations about the current state of threats, recommended best practices, and solutions. The analysis on threat intelligence gathered from a global customer base across 100+ countries and millions of computers revealed three important trends in 2017. First, the impact of Botnets, and how they continue to impact millions of computers globally, infecting them with old and new forms of malware. The second most notable trend was low-cost attack methods being used by Hackers for potentially higher returns. Third and still trending was Ransomware, which is still does not seem to be slowing down.
A live survey of Oman-based PCs, conducted by Microsoft in the first quarter of 2017, revealed that 16% of computers experienced malware of some kind, compared with a worldwide average of about 7.8%. Another research conducted by Microsoft among Chief Information Security Officers in the Gulf region in 2017, showed that 60% of regional organisations still use usernames and passwords to authenticate users to corporate networks. Only 30% use two-factor authentication (2FA) – the combination of username-password with SMS or some other form of mobile notification. About 5% said they used facial recognition.
Dr. Erdal Ozkaya, Cybersecurity Architect at Microsoft, spoke on the pressing need for “Intelligent Security”, as GCC CISOs continue to battle against increasingly sophisticated threats. “An alarming number of regional organisations are still using outdated strategies and authentication models, even as international headlines continue to illustrate the intensity of the ongoing battles against bad actors,” said Ozkaya. “The good news is that the intelligent cloud is armed with weapons that can match the sophistication of the attacks. Microsoft will continue to strengthen those capabilities on behalf of our customers, as we progress with forums like The CISO Executive Series, where security professionals can hear from seasoned White Hat experts and likeminded CISOs.”
Along with Microsoft’s security experts, other industry leaders also addressed attendees at the event. Megha Kumar, Research Director at IDC, presented “The Evolving Security Landscape’ and Sung Pong, Chief Security Officer, bank muscat discussed ‘The Evolving role of the CISO’.
“There are malicious parties out there that seemingly never sleep; so CISOs need to take a 24-7, 360-degree view of cyber security. The challenge has always been to find a workable middle ground between the rigidity of IT policy and the flexibility needed to be an agile, digital business,” said Megha Kumar.
The Microsoft Gulf CISO survey also revealed that 24% of CISOs said their users had clicked on links within emails and discovered they led to websites of unknown origin. Only 21% reported having a data-classification solution in place, with almost half (47%) saying they were still in the process of acquisition and 32% saying they had yet to make progress.
“Cyber strategies need to be holistic,” said Mohammed Arif, Regional Director, Modern Workplace and Security, Microsoft Gulf. “You need to consider that you will be breached. And then you need to consider what happens next. What do you do? Who do you call? How do you get back on your feet? Never forget that business continuity is as important as the protection of intellectual property.”
Microsoft invests around US$ 1 billion annually in cyber security, so that customers can be confident that the Microsoft cloud is a safe home. The Azure cloud platform is built from the ground up with industry-leading, AI-driven protection built into every layer. Data is encrypted at rest and in transit, and 24-hour event-remediation services are provided by a dedicated team of experts.