The high growth of problems related to the security of corporate IT networks, combined with the obvious difficulties in dealing with these threats, lead to constant development in all sectors related to IT and Cyber ​​Security: Cyber ​​Intelligence, Cyber ​​Security Operations, Identity Management , IT Security Engineering, Vulnerability Assessment, Penetration testing. Concerns raised by growing cyber threats are in fact leading public and private organizations to implement highly specialized units in cyber warfare. Computer networks continue to be under attack from malicious users and well-developed exploits, and organizations increasingly need to protect network-connected infrastructures. 

The rapid evolution of technologies has had a profound impact on our society and our lives. The presence of wireless networks that can be accessed practically anywhere has encouraged the widespread diffusion of devices capable of connecting to the network: from tablets to mobile phones to the most recent wearable devices, traditional objects such as watches or glasses that can connect to the web.

But connecting to the network, in addition to allowing access to a huge amount of information and possibilities, also makes our devices potentially vulnerable, with everything they contain, from personal data, to profiles on social networks, up to access to online services. banking. This happens both for individuals and for large companies, such as banks, energy companies or hospitals, which use the network to exchange information, organize the provision of services, coordinate activities.

In other words, access to the internet opens us up to the world, but makes people, companies and institutions potentially exposed to risks of fraud, information theft or sabotage. The danger should not be underestimated. The vulnerability of computer systems allows access in seconds to industrial secrets, patents and innovations that have required years of research. Cybercrime can decree the bankruptcy of companies and therefore enormous economic damage. For companies, which focus on innovation as an element of development, the potential damage can be enormous. Not only people and businesses are at risk, national security can potentially be endangered as well. Think of the consequences that could derive from the alteration of the systems that regulate transport, energy networks or military command and control systems.

A recent simulation estimated that, in the event of an attack on the electricity grid, an energy blackout lasting a few weeks would cause a total collapse, producing unimaginable damage. This is not a distant future or a science fiction scenario. Cyber ​​crime is already a reality today and is growing rapidly in the world. Critical infrastructures, such as energy distribution networks and telecommunications networks, are increasingly being targeted by cybercriminals. In summary, we are all exposed to the risk of intrusions, which can have devastating effects on personal life, on the economic life of the entire country. These are therefore real dangers that can no longer be underestimated. Developing new capabilities and new tools to improve cyber security therefore represents a challenge of great importance for the growth, well-being and security of citizens, which can no longer be postponed.

 

The following took part in the meeting:

Charles Del Bo

Executive Security Advisor of STE SpA Rome

 

Robert Lipari

Managing Director of BFK HR Consulting SA 

 

Massimo Vanotti

Lawyer Law Firm Baer & Karrer 

 

Guido Travaini

Professor in Criminology at the Vita-Salute San Raffaele University of Milan

 

Lorenza Bernasconi Moser

Safety Group Management SA

 

Angelo Consoli

SUPSI Safety Laboratory Manager

Eduardo Grottanelli de'Santi

Ticino Welcome editorial manager.

The meeting was held on Thursday 20 October 2016 at the Metamorphosis Theater for Events - Palazzo Mantegazza - Lugano-Paradiso

The issue of Cyber ​​Security has become a key player on the political-economic scene. But why is it so important and what is it for?

Lorenza Bernasconi Moser:

«As is well known, Cyber ​​Security is the most recent evolution of security understood in the traditional sense and defines the process that allows the protection of information through activities of prevention, detection and response to attacks originating from 'Cyberspace'. Therefore, not only the protection of corporate information, but also everything that, through the use of ICT technologies, can be exposed to risks; for example, the corporate reputation linked to communication through social network channels represents a very sensitive context. Cyber ​​Security is a process and not a technological solution. The Cyber ​​Security frame works, i.e. the models that guide companies in managing information risk, are a set of activities, roles and responsibilities, approaches and methodologies, and technologies, which support each organization in defining, implementing and constantly improving the strategy of adequate protection. It is necessary to take into account the fact that we work in a world, the virtual one, which by its nature has no borders, therefore it is particularly difficult to locate and thwart the origin of the attacks. In any case, in a very significant number of cases, e-mails are the keys to access the attacks. At the basis of everything there is therefore education and awareness of the need for prevention ».

Charles Del Bo:

"We must start from an unequivocal fact: from the moment a person writes something on a social network or talks on the phone, the news is no longer private but becomes public domain. There are already 7 billion on the planet, in 2019 there will be 25 billion devices and 5 billion machines that will transmit data without interruption and without human intervention. Therefore, it is easy to understand how many attacks we can suffer every day. Paradoxically, in order not to take risks one would have to completely renounce communication, but this is clearly impossible. It is therefore necessary to focus above all on the human element because it is precisely in his behavior that the flaws that can open the way to cyber attacks lurk ».

Massimo Vanotti:

“When we talk about cybersecurity breaches, we very often refer to companies or organizations. But the problem also arises for individuals. What with a term that has now entered common use is indicated as privacy is the right to the confidentiality of personal information and one's private life, that is, an instrument set up to safeguard and protect the private sphere of the individual, to be understood as the right to prevent information concerning this personal sphere from being disclosed in the absence of the authorization of the interested party, or even the right not to interfere in the private sphere by third parties. This right ensures the individual has control over all information and data concerning his private life, while providing him with the tools to protect this information. We only think of the consequences that the violation of this right can have towards people, in particular young people who tend to underestimate the problem, with all the dramatic consequences that can derive from it, as the news teaches us every day ».

Guido Travaini:

“We have to consider that cybercrimes are basically old crimes with new clothes. Theft, for example, has been the same for centuries, but thieves today also use technology. This means that on the one hand we have a criminal on the other hand we can find someone who can make it easier to commit the crime perhaps because the victim does not protect himself and does not protect himself.This is very evident for cybercrime too. due to the lack of knowledge of the phenomenon by many people. Think, for example, of the risk of disclosing information or images via mobile phones. It is impressive the amount of intimate photographs that people often, even minors, move to social networks and chats.

The exchange can appear intimate and harmless. But what if someone were to illegally gain access to such images and start storing them? It is not difficult to imagine a criminal use of this archive. We often imagine the cyber attack as coming from the outside, but, on reflection, the greatest threats come from our own behaviors that create criminal opportunities for others. This is true not only for people but also for companies ».

Robert Lipari:

"The digitization of processes and activities that is increasingly pervasive, also due to the use of innovative channels and approaches offered by technology (mobile, cloud, etc.) and the creation of increasingly large information assets from which to extract value (big data and data analytics) are contributing to the relevance of Cyber ​​Security issues. The news reports the increase in security threats both in terms of numbers and in terms of differentiation of the types of 'attackers' and methods of attack. If up to the middle of the previous decade, cyber attacks were mainly attributable to hostile individuals operating independently (or limitedly organized) and, in most cases, with limited skills, in the last decade an increasing number of attacks have been detected coming from real structured organizations, of a criminal or hostile governmental nature, able to leverage large economic and technological resources. I am convinced that by now companies must not ask themselves whether or not they will be the target of a cyber attack, but when and through what methods. The most correct question every company should ask is how to respond to these kinds of events. Therefore, the ability to understand and evaluate all the possible impacts linked to an attack is of great importance, in order to adopt effective solutions to contrast and restore normal operations ».

 

The picture you have outlined is certainly very worrying. If you want to think positively, what are the measures that can be taken to counteract the phenomena outlined?

Lorenza Bernasconi Moser:

«If we consider that around 117.000 attempts to breach computer security are perpetrated every day in the world, we have an immediate perception of the magnitude of the phenomenon. The weakest link in the cybersecurity chain, too often overlooked by those who focus on technological aspects, is the human element, which is now assuming the role of an unaware vector of attacks as well as a target. In fact, many cyber attacks use social engineering techniques. There are various types of attack: the attacker can steal information with minimal contact with the target, or establish a bond with the victim and feed on the information for a long time. To better tackle the problem, we need to understand the nature of social engineering attacks. This means defining a profile of the possible actors, knowing their attack methods and their resources and applying the related controls to reduce the risk of success of an attack by adopting an approach based precisely on people, processes and technologies. The problem that therefore arises at the basis of every possible defense against cyber attacks is the formation of the human element ».

Robert Lipari:

“Unfortunately, many companies are convinced that having an antivirus is enough to be totally protected from cyber attacks. Thinking like this, one does not realize the risks that are run through the use of cell phones, personal computers and other computer equipment that continually put the company in contact with the outside world. In many cases, the personnel, and not only those in charge of safety but every human resource employed, become an "unaware operator" who risks causing serious damage to the company with his behavior ».

Charles Del Bo: 

«During my professional career I have had the opportunity to deal with security problems on behalf of companies operating in different fields. Well, I must say that while some sectors have gained a good awareness of IT security, others are still in the year zero and their systems have large flaws that continually expose them to the risk of all kinds of violations and attacks. An aspect that is not sufficiently taken into consideration concerns, for example, the vulnerability of external consultants and other professionals who interact with the company and who perhaps keep sensitive data of great importance on their computer. Thus, a company that perhaps appears super-protected in Europe suffers an attack from Japan brought about through an intrusion into the computer of one of its consultants who is around the world.

Massimo Vanotti:

«For a law firm like ours, the problem of protecting the data acquired by our clients is of crucial importance. Companies hold a huge amount of confidential and sensitive information and law firms are at the forefront, as they are particularly exposed to cyber security threats and “thefts”. Hackers are increasingly targeting companies in our industry in order to tap into the gold mine of data and information in their possession. Hackers don't just target global giants - financial institutions around the world, energy multinationals or pharmaceutical companies. The reality is that the younger you are, the more vulnerable you are (in the eyes of cyber criminals), as they are less prepared and with fewer defenses ». 

Guido Travaini:

«If it is true that the world of crime is looking at the network with increasing interest to carry out criminal actions, it is not that there is no lack of opportunities to undertake valid counter actions. Think of the illegal drug trade. According to the most recent research, it has achieved a global turnover of 75 billion dollars. In Europe, this illegal market has grown a lot in the last decade and is estimated to be worth 10.5 billion euros in turnover. All this has not only economic but also health consequences. The risk is to be treated with fake drugs that have no healing capacity. To defend ourselves from criminals and to spread knowledge and good practices among citizens, the European project FakeCare led by Ecrime of the University of Trento has just ended after three years of interdisciplinary work involving criminologists, sociologists, jurists and computer scientists. A research project that has won prizes in Europe and is considered of fundamental importance in the fight against online pharmaceutical counterfeiting. ». 

Angelo Consoli:

"The security of our data online and the fight against cybercrime are two opposite sides of the same problem: guaranteeing the use of the Internet and digital technologies without abuse or abuse, neither by cybercriminals nor by the supervisory authorities . SUPSI has been working on these issues for years with courses and masters that provide for various levels of learning. Last year we won a European project dedicated to social engineering and the role of the human element as an active and passive subject of safety. In fact, 97% of cyber attacks have at least one factor linked to humans and their behaviors. 

How is cybersecurity legislation changing at European level?

Massimo Vanotti:

«The most interesting aspect does not concern so much the repression of crimes, which as was said at the beginning are more or less always the same but perpetrated with different means, but rather the procedural one of assistance and international cooperation. Another issue concerns the communication obligations that are incumbent on the company that has been the object of an attack ».