Krebs: The Key Element Of Cyber Defense Is ...

image

NASHVILLE—Security expert Brian Krebs had a cautionary message for FIs that all the firewalls and layers of technology they have in place to defend against cyberattacks are only as effective as the people managing them.

Meanwhile, Krebs warned that sophisticated phishing scams are targeting senior executives at companies—and often working–while also offering additional insights into why IT and security often end up working against each other.

“Organizations buy into the idea that doing security right is layering on the right mix of technology software and services, and that this magic combination will block 99% of attacks,” said Krebs, author of the well-respected Krebs on Security blog. “It’s just not true. It’s very expensive to do security right, and that’s partly because the actual security of your organization comes from security specialists.”
Speaking at the TMG Executive Summit here, Krebs used Target’s 2013 data breach as an example, saying the company had all the right technology in place, and some of it was even providing alerts that there was a threat. According to Krebs, however, “There were no people in the seats to tell them what those alerts were saying.”

No Substitute
“There’s no substitute for the human,” said Krebs, who added that fundamentally, cybersecurity challenges don’t change all that much from year to year. “Different organizations face different threats, but one of the stubbornly static truths of breached organizations is that they had all the data telling them they were hacked, but no one looked at it until after the incident.”
It’s not uncommon for an organization to look at its event logs for the first time after someone like him gives them a call, said Krebs, who devotes a significant energy to breach notification. Comparing the experience of being notified of a breach to the five stages of grief, Krebs says the people he notifies are almost always in denial. “Those with a high degree of security maturity skip through the first stages and go straight to depression,” Krebs said.

To investigate the evolving methods used by cybercriminals to steal and profit from stolen data, Krebs said he spends much of his time “lurking on forums to get an idea of what’s coming.”

Krebs

Brian Krebs

Phishing, he said, is becoming increasingly sophisticated, even though some cybersecurity experts talk about it as a solved problem. Over a span of three weeks, Krebs notified several different companies of phishing threats facing their C-suites. He had seen actual communications spoofing CEO email addresses on the dark web. No one from any of these vulnerable organizations returned his calls, he said.
According to Krebs, cybercriminals are so good at their tricks thanks in part to the emergence of sophisticated criminal call centers, which staff people who speak multiple languages 24x7.

“If you want to change someone’s billing address or cash out an account, but you don’t speak their language, you hire these guys,” said Krebs. “For $10, you give them a script and they run through it for you.”

For this reason, Krebs says he’s interested to watch how financial institutions execute voice biometrics strategies in their overall security plans.
As for stolen credit cards, Krebs believes the market is seeing “a historic glut of credit card data.” It’s never been easier to buy stolen credit cards, he said, largely due to an explosion of sophisticated and criminal-centric fraud sites intent on delivering a great experience for the criminal element.

Crooks Refocused On Service

“They have refocused their entire business on customer service,” said Krebs. “If you buy 100 stolen credit cards and only 50 work, that’s poor service. So they want to change that and are pre-testing the cards for their customers. Also, they are watching what kind of cards you like to buy and then they will target market. The business acumen of these criminal marketplaces has been fun to watch.”
As the U.S. moves toward full implementation of EMV, Krebs expects card-not-present fraud to increase, but noted the more critical threat is account takeover. “This is why we should be looking at improving authentication. The way we do things today – saying, ‘You must be that person because you know their social security number’ – that’s bananas.”

Ransomware and distributed denial of service attacks will increase, as well, Krebs said.
Krebs concluded by saying the head of security should always report to the COO, CEO or the board of directors. Organizations with what he calls a high degree of security maturity have created separation between IT and security. “The surest way to deny your security people any say is to have them report to the head of IT,” Krebs said.

Section: Standard
Word Count: 955
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Krebs-The-Key-Element-Of-Cyber-Defense-Is