# The State of Information Security - Liran Markin

- Channel: [Edge City](https://streameth.org/edge_city)
- Date: 2024-11-06
- Duration: 13:00
- Watch: https://streameth.org/watch/672b69c0f861dff095ee6002
- Download: https://vod-cdn.lp-playback.studio/raw/jxf4iblf6wlsyor6526t4tcmtmqa/catalyst-vod-com/hls/b850o86bf3udwlt9/1080p0.mp4

## Transcript

Thank you Trent. Okay, so we have a lot of bio so far. This is going to be a spin-off to the more defensive side of the act. And we're going to talk about information security. So why I'm choosing information security, basically it's like a more broader term than cyber security. It encapsulates the confidentiality, integrity, and availability of information. So it goes way back also for physical security when all the data used to be stored physically. So this is the distinction between information security. Cyber security progressed through digitization. And for this talk, we're going to focus on what is the current state of information security, what is happening all along, so we can accurately predict what is going to be in the future and what should we focus on. A bit about myself. I'm from Israel, the cyber nation state. I used to serve in the military doing some stuff I cannot describe too much then I worked for data security company and we served enterprises and small to medium businesses with some data security issues and provided solutions and now after i pivoted to the blockchain space we are building e oracle which is a decentralized oracle built from first principles so how attack how is attack is currently happening there are are a few tactics. They probably merge together. And this is statistics of the known tactics. So you can see first is use of stolen credentials. It's not that the credentials are very weak. Yes, some passwords are weak. But it's very easy currently today to just stole credentials from someone or buy them. All the cybercrime and all darknet is filled with credentials you can just buy. So this is like a machine that feeds itself and people get some weak credentials, they do something with it because they have some kind of leverage with some exploit and then they sell higher credentials. So this is a very common tactic. Next is very high on recent years is ransomware. Ransomware is a big problem in the last years. It's way worse for company to lose their data and like quit operations for a while than just to leak the information and maybe set it online or like hurt the consumers. And some other things that worth mentioning here is like pretexting and phishing. This is more on the human element side. And it's very easy to leverage humans as we'll see. The initial attack vector, like how attacks usually start, they combine from multiple tactics, but the first and most popular are phishing or stolen compromised credentials, some misconfigurations, and this is from a report by IBM, like about over 10,000 data breaches. Something to note here is of the whole attack, if you take it and break it into the component, 68% involve any kind of human element. So humans are really easy to fool. This is something we should keep in mind maybe when we plan the next technology for defensive. So this is like how an attack progressed, but who are the actors? There are two main categories of actor. One is nation states, and usually their motive is power or control. They want to control the world and affect it to how they wish. And the other one is cybercrime, which is they usually do profit or hacktivist groups that are powered by ideology. The meaning of cyberattack for, for the corporate world, is money. So the cost is getting higher each year, and that is what companies are really worried about. It's going to cost them money, but the money is, like, translated. It's computed from maybe reputation hurt
