Light Reading

AT&T's Amoroso: To Battle New Threats, Mobilize Your People

Dan Jones

Your biggest online concern these days might be those embarrassing nude selfies suddenly appearing on the web, but AT&T Chief Security Officer (CSO) Ed Amoroso is here to tell you that there are far worse things lurking in cyberspace.

Amoroso highlighted one of the key security areas that CSOs should be concerned about as a new wave of advanced persistent threats (APT) loom, and they're aiming to do more than just swipe thousands (or millions) of credit card numbers.

"The next step is probably terrorists trying to destroy critical infrastructure," he told Light Reading over breakfast Wednesday morning, "with the emphasis on destructive," he added, as he demolished a "broken yolk sandwich" (which looked a lot better than the name suggests).

Amoroso doesn't seem like a man given to idle fear-mongering, despite his job title. In fact, he's one of the more informative and jovial speakers you're likely to see on the often sawdust-dry tech conference circuit. (See AT&T's Ed Amoroso on Mobile Security for proof of how entertaining he can be.)

An advanced persistent threat is one organized by a specific group, sometimes using multiple methods, to break into a particular target. Recent examples would include data breaches at Home Depot and Target.

Amoroso says the APT pattern started with nation states and the military, moved on to criminal gangs, and is shifting to terrorist groups. "The one thing you won't be able to rationalize is the destructive stuff," he suggested in his keynote at the AT&T Cyber Security conference in New York City Thursday.

This is not, of course, an unknown concept. Former US Defense Secretary Leon Panetta has long warned of a "cyber Pearl Harbor." Even if the idea of what constitutes cyber terrorism is still somewhat cloudy, the broad idea is that groups could attack critical communications, energy and water networks and cause damage and wide-scale disruption.

Need to know more about mobile network security? Then check out the agenda for Mobile Network Security Strategies 2014, December 3 at the Westin Times Square, New York City.

Where Amoroso may differ is that he isn't suggesting that there is a pure technological solution to widespread security problems. The basic thrust of his keynote Thursday was: Be safer by training your employees not to do dumb stuff.

Advanced firewalls and network appliances are useful tools but people are the weakest link in the chain, he suggested. "All the times I've been hacked in my career, it was because of something that was off my radar," he said at the keynote, adding that systems are just too complicated to be 100% secure.

The focus cannot just be on technology, he suggested: People also have to be involved. Which, in the corporate environment, means pumping up the security awareness team.

"We've kind of punted on that before," he told Light Reading Wednesday. "A typical awareness document will put you to sleep."

In AT&T's case, the new approach meant using video to show employees what not to do. The funny, cutesy videos that Amoroso showed at the Thursday keynote targeted phishing attacks. They emphasized that people should not open attachments from suspicious senders, that they should run their mouse over URL links to see where they actually lead, and be very careful about information shared on social media.

AT&T has been working on this during the past six months. The amount of employees now not clicking on the faux phishing email tests that the security office sends out suggests that awareness about phishing attacks is up by 54%.

"Making the video doesn't have to be expensive," Amoroso said. The animated AT&T videos were made in-house: Firms could even use interns from film school for great results, he suggested.

"They'll love it," he said.

For more insights from Amoroso, see:

— Dan Jones, Mobile Editor, Light Reading

(2)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
User Rank: Light Sabre
9/8/2014 | 1:08:35 PM
Ent or SP
Is he referring to AT&T the enterprise or the service-provider?
User Rank: Blogger
9/5/2014 | 2:44:51 PM
I had sliced grapefruit BTW
Educational Resources
sponsor supplied content
Educational Resources Archive
From The Founder
Steve Saunders provides an overview of white box networking and introduces a new "slim line" version of the OSI 7-layer model.
Flash Poll
Live Streaming Video
CLOUD / MANAGED SERVICES: Prepping Ethernet for the Cloud
Moderator: Ray LeMaistre Panelists: Jeremy Bye, Leonard Sheahan
Between the CEOs
Centec on Ethernet Switching

11|26|15   |   09:58   |   (0) comments

Centec CEO James Sun talks to Steve Saunders about Ethernet switching and the white box revolution.
LRTV Custom TV
Delivering Service Agility in the Virtualization Era

11|25|15   |   5.41   |   (0) comments

Interview with Massimo Fatato, WW OSS Business Lead, Hewlett Packard Enterprise.
Wagner’s Ring
How Might Open Source Fail?

11|24|15   |     |   (9) comments

Open source, SDN, and NFV are looking inevitable – but performance, standards proliferation and regulatory capture could derail the movement.
LRTV Custom TV
NFV Lifecycle Orchestration – a Fresh Vision for Telco

11|23|15   |   6.40   |   (0) comments

Simon Osborne, CTO Comptel, and Heavy Reading's Caroline Chappell reveal the business impacts of new SDN and NFV, and what the term service orchestration actually means. Together they define Lifecycle Service Orchestration and how the virtualized future will look for telecoms operators.
Between the CEOs
Cisco's Virtual Role in Saudi

11|20|15   |   12:15   |   (2) comments

Light Reading founder and CEO Steve Saunders talks with Zayan Sadek, Regional Manager at Cisco Systems, about the competitive communications services market and advance of virtualization in Saudi Arabia.
LRTV Huawei Video Resource Center
Huawei Leads With Kubernetes for Cloud PaaS

11|19|15   |   08:26   |   (0) comments

Huawei is looking to Kubernetes as a key tool for building robust open source technologies for customers and partners, said Ying Xiong, chief architect of cloud platform at Huawei, in an interview with Light Reading West Coast Bureau Chief Mitch Wagner at the recent Kubecon conference.
Women in Comms Introduction Videos
WiC in London: The Highlight Reel

11|19|15   |   5:33   |   (1) comment

NetCracker's Mervat El Dabae headlines an inspiring morning in London with help from leading women from Vodafone, TalkTalk, Hyperoptics and Ciena.
LRTV Documentaries
Why Saudi's So Hot for New Tech

11|19|15   |   05:07   |   (0) comments

Light Reading's Steve Saunders reports from Saudi Arabia, a hyper-competitive market desperate to embrace the next generation of communications technologies and services.
LRTV Custom TV
Why Data Models Deliver More Value Than Information Models

11|19|15   |   5.08   |   (0) comments

Stefan Vallin argues that more automation is needed to manage end-to-end services and the hybrid networks they run on, and that data models are key to achieving this.
Telecom Innovators Video Showcase
SDN Management & Orchestration in the WAN

11|17|15   |   7.20   |   (0) comments

Carol Wilson and Packet Design CTO Cengiz Alaettinoglu discuss CSPs' SDN service delivery and assurance requirements. Learn about a modular approach to building automated control, orchestration and management functions for the WAN that are policy- and analytics-driven.
LRTV Custom TV
Flash Networks: Optimizing for Radio Spectral Efficiency

11|17|15   |   3:34   |   (0) comments

Today most optimization vendors only focus on optimizing voice or data. Ofer Gottfried, Flash Networks' CTO, shows how improving data throughput and maximizing spectral efficiency reduces capital and operating expenses while also providing a platform for user engagement.
LRTV Custom TV
Making Pay-TV User Experiences Millennial-Friendly

11|16|15   |   6:42   |   (0) comments

The unique challenge of reaching and engaging Millennials is driving pay-TV video experience transformation that can include higher quality UIs, viewing of multiple content streams at once and seamless transitions between handheld devices and the television.
Allot MobileTrends Report H2/2015 reveals how daily online behavior can be used to discover smarter ways to profile customers and propose valuable, real-time offers to them.
Hot Topics
Samsung to Sell Wireless Networking Unit?
Dan Jones, Mobile Editor, 11/23/2015
Samsung: No Sale of Wireless Unit
Dan Jones, Mobile Editor, 11/25/2015
How Might Open Source Fail?
Mitch Wagner, West Coast Bureau Chief, Light Reading, 11/24/2015
Sprint to Get $1.2B From New Leasing Venture
Dan Jones, Mobile Editor, 11/23/2015
Networking Shines in HP's Gloomy Final Earnings
Mitch Wagner, West Coast Bureau Chief, Light Reading, 11/25/2015
Like Us on Facebook
Twitter Feed
December 15, 2015
Virtualizing Cable Services
Webinar Archive
BETWEEN THE CEOs - Executive Interviews
Centec CEO James Sun talks to Steve Saunders about Ethernet switching and the white box revolution.
Light Reading founder and CEO Steve Saunders talks with Zayan Sadek, Regional Manager at Cisco Systems, about the competitive communications services market and advance of virtualization in Saudi Arabia.
Cats with Phones
Can't Find the Phone on Thanksgiving? Click Here
Check under the cat! (hint: bottom right)
Live Digital Audio

Broadband speeds are ramping up across Europe as the continent, at its own pace, follows North America towards a gigabit society. But there are many steps to take on the road to gigabit broadband availability and a number of technology options that can meet the various requirements of Europe’s high-speed fixed broadband network operators. During this radio show we will look at some of the catalysts for broadband network investments and examine the menu of technology options on offer, including vectoring and for copper plant evolution and the various deployment possibilities for FTTH/B.