Cybersecurity industry “Fighting the Wrong Battle for 20 Years”

Nuix has published a provocative white paper by cybersecurity veteran Chris Pogue arguing that the technology industry has been “fighting the wrong battle with the wrong weapons” against cybercrime for the past two decades. The paper contends that for technology to fight cybercrime and insider threats effectively, it must solve human vulnerabilities.

  • 8 years ago Posted in
“In the more than 2,500 data breaches I have investigated, I can count exactly zero that were caused by non-human-initiated system failure—like it or not, people are the problem,” said Pogue, Nuix’s Senior Vice President, Cyber Threat Analysis.
The white paper examines five cognitive biases—“bugs in our brain software”—that cause people to make poor decisions. It examines how other industries have learned to deal with these biases by concentrating on changing human behavior, and applies these lessons to the fight against cybercrime.
“Our focus with Nuix Insight technology is to reduce the number of human decision points, thereby dramatically reducing the opportunity for mistakes and failure,” said Pogue. “To do this we’ve baked into the products decades of experience from experts in incident response, malware reverse engineering, threat intelligence, data analysis, insider threats, and digital forensics.”
The white paper includes a strategic battle plan and practical action plan for organisations to focus on using technology, people, and processes to address the people problems of cybersecurity.
“Do we have what it takes to outsmart our own brains and stop ourselves from repeating the mistakes of the past?” said Pogue.  “Hopefully we can set ourselves up for the next 20 years, get serious about security, address the real human vulnerability, and start reclaiming surrendered ground.”
Nuix Insight Adaptive Security—a continuous-protection platform for threat prevention, detection, response, and remediation—will be available in May. Nuix Insight Analytics & Intelligence—a four-dimensional security intelligence platform that connects people, objects, locations, and events for breach investigations, deep-dive forensics, and big data visual analysis—will follow in the second half of the year.
Research shows ‘game needs to be changed,’ with security innovation years behind that of the...
73% of organizations lack automated patch management, and 62% experienced incidents involving...
Quest Software has signed a definitive agreement with Clearlake Capital Group, L.P. (together with...
Dell EMC PowerProtect Cyber Recovery for AWS provides a fast, easy-to-deploy public cloud vault to...
Aqua’s cloud native application protection platform becomes the only solution that protects cloud...
54% of organisations working on a security transformation project now or in the next 12 months.
Node4 has released its Mid-Market IT Priorities Report 2021. The independent report reveals that...
Zscaler Zero Trust exchange cloud-based architecture enables superior green security capabilities...