& cplSiteName &

AT&T's Amoroso: To Battle New Threats, Mobilize Your People

Dan Jones
9/5/2014
50%
50%

Your biggest online concern these days might be those embarrassing nude selfies suddenly appearing on the web, but AT&T Chief Security Officer (CSO) Ed Amoroso is here to tell you that there are far worse things lurking in cyberspace.

Amoroso highlighted one of the key security areas that CSOs should be concerned about as a new wave of advanced persistent threats (APT) loom, and they're aiming to do more than just swipe thousands (or millions) of credit card numbers.

"The next step is probably terrorists trying to destroy critical infrastructure," he told Light Reading over breakfast Wednesday morning, "with the emphasis on destructive," he added, as he demolished a "broken yolk sandwich" (which looked a lot better than the name suggests).

Amoroso doesn't seem like a man given to idle fear-mongering, despite his job title. In fact, he's one of the more informative and jovial speakers you're likely to see on the often sawdust-dry tech conference circuit. (See AT&T's Ed Amoroso on Mobile Security for proof of how entertaining he can be.)

An advanced persistent threat is one organized by a specific group, sometimes using multiple methods, to break into a particular target. Recent examples would include data breaches at Home Depot and Target.

Amoroso says the APT pattern started with nation states and the military, moved on to criminal gangs, and is shifting to terrorist groups. "The one thing you won't be able to rationalize is the destructive stuff," he suggested in his keynote at the AT&T Cyber Security conference in New York City Thursday.

This is not, of course, an unknown concept. Former US Defense Secretary Leon Panetta has long warned of a "cyber Pearl Harbor." Even if the idea of what constitutes cyber terrorism is still somewhat cloudy, the broad idea is that groups could attack critical communications, energy and water networks and cause damage and wide-scale disruption.


Need to know more about mobile network security? Then check out the agenda for Mobile Network Security Strategies 2014, December 3 at the Westin Times Square, New York City.


Where Amoroso may differ is that he isn't suggesting that there is a pure technological solution to widespread security problems. The basic thrust of his keynote Thursday was: Be safer by training your employees not to do dumb stuff.

Advanced firewalls and network appliances are useful tools but people are the weakest link in the chain, he suggested. "All the times I've been hacked in my career, it was because of something that was off my radar," he said at the keynote, adding that systems are just too complicated to be 100% secure.

The focus cannot just be on technology, he suggested: People also have to be involved. Which, in the corporate environment, means pumping up the security awareness team.

"We've kind of punted on that before," he told Light Reading Wednesday. "A typical awareness document will put you to sleep."

In AT&T's case, the new approach meant using video to show employees what not to do. The funny, cutesy videos that Amoroso showed at the Thursday keynote targeted phishing attacks. They emphasized that people should not open attachments from suspicious senders, that they should run their mouse over URL links to see where they actually lead, and be very careful about information shared on social media.

AT&T has been working on this during the past six months. The amount of employees now not clicking on the faux phishing email tests that the security office sends out suggests that awareness about phishing attacks is up by 54%.

"Making the video doesn't have to be expensive," Amoroso said. The animated AT&T videos were made in-house: Firms could even use interns from film school for great results, he suggested.

"They'll love it," he said.

For more insights from Amoroso, see:

— Dan Jones, Mobile Editor, Light Reading

(2)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
Atlantis-dude
50%
50%
Atlantis-dude,
User Rank: Light Sabre
9/8/2014 | 1:08:35 PM
Ent or SP
Is he referring to AT&T the enterprise or the service-provider?
DanJones
50%
50%
DanJones,
User Rank: Blogger
9/5/2014 | 2:44:51 PM
Breakfast
I had sliced grapefruit BTW
Educational Resources
sponsor supplied content
Educational Resources Archive
From The Founder
Light Reading today starts a new voyage as part of a larger Enterprise.
Flash Poll
Live Streaming Video
Charting the CSP's Future
Six different communications service providers join to debate their visions of the future CSP, following a landmark presentation from AT&T on its massive virtualization efforts and a look back on where the telecom industry has been and where it's going from two industry veterans.
LRTV Interviews
No Stopping Cable's Ethernet Gains

12|9|16   |     |   (0) comments


Vertical Systems' Erin Dunne explains why US cable operators, which now command a record-high 26% of the Ethernet market, will keep boosting their share.
LRTV Interviews
Fixing IoT Security Is an Ecosystem Challenge

12|9|16   |   05:34   |   (1) comment


Level 3 Communications' Chief Security Officer Dale Drew says service providers, manufacturers and even consumers must combine to halt massive DDoS attacks using IoT devices in botnets. The solution he has in mind includes reputation-based routing by the service provider but also more secure endpoint devices and greater consumer awareness.
LRTV Interviews
Cox Clears $2B in Business Revenue

12|8|16   |     |   (0) comments


Cox's Jeff Breaux discusses how the third-largest US MSO will reach the $2 billion revenue mark this year and plans to hit $3 billion by 2021
LRTV Interviews
Can Cable Climb Upmarket?

12|7|16   |     |   (0) comments


Carol Wilson and Alan Breznick assess cable's prospects for winning more enterprises in a landscape rocked by corporate M&A activity.
Women in Comms Introduction Videos
TalkTalk Exec: Find Your North Star at Work

12|7|16   |   3:38   |   (1) comment


Women need to find their purpose, a professional North Star, and create a personal board for themselves, according to Alex Tempest, director of partners at TalkTalk Business.
LRTV Interviews
Verizon: Beware Unknown Unknowns

12|7|16   |   04:58   |   (0) comments


Chris Novak, director of the Verizon Enterprise Solutions Risk Team, explains that enterprises who don't conduct a thorough audit of their assets often leave some things unprotected because they don't know they exist. Many times these unprotected assets are part of corporate M&A activity but left unshielded they can become a hacker's playground, he tells Light ...
LRTV Interviews
ETSI's CTO Talks NFV, 5G & NGP

12|5|16   |   09:45   |   (0) comments


Adrian Scrase, CTO at standards body ETSI, talks about the various initiatives and specifications developments related to NFV, 5G and NGP (next-generation protocols) that will underpin next-gen networks.
Women in Comms Introduction Videos
Korn Ferry Consultant: How to Find, Cultivate & Be the Best Talent

11|30|16   |   4:10   |   (2) comments


Erin Callaghan, a managing consultant for Korn Ferry Futurestep, shares strategies for companies to improve how they recruit and for women to ensure they don't get lost in the pipeline.
LRTV Custom TV
We Can Make the World More Sustainable

11|29|16   |     |   (0) comments


GeSI is a global e-Sustainability Initiative organization bringing together 40 big multinational companies around the world. According to GeSI's report, information and communication technology can make the world more sustainable. Luis Neves, chairman of GeSI, shared with us his opinion at Ultra-broadband Forum (UBBF2016).
LRTV Custom TV
Finding a New Way to Engage Customers & Drive Revenue

11|29|16   |     |   (0) comments


Mobile revenues are declining. Digicel, a player in the Caribbean telecommunications/entertainment space, has found a new way to engage customers and drive revenue. John Quinn, CTO of Digicel, shared with us its story at Ultra-broadband Forum (UBBF2016)
LRTV Custom TV
Do You Really Need Gigabit Infrastructure?

11|29|16   |     |   (0) comments


Altibox is the biggest fiber-to-the-home (FTTH) player and the largest provider of video and TV in Norway. They started out with zero customers in 2002. Now they have close to half a million households and companies attached to their FTTH business. Nils Arne, CEO of Altibox shared with us their story and insight on 5G at Ultra-broadband Forum (UBBF2016).
LRTV Custom TV
BTís Openreach Strategy & Its Updates in 2016

11|29|16   |     |   (0) comments


A lot of developments at Openreach this year in terms of strategy and planned investments. Peter Bell, CIO of Openreach BT, shared with us the updates of Openreach at Ultra-broadband Forum (UBBF2016).
Upcoming Live Events
May 16-17, 2017, Austin Convention Center, Austin, TX
All Upcoming Live Events
Infographics
Hot Topics
Cable Nodes Becoming a Choke Point
Brian Santo, Senior editor, Test & Measurement / Components, Light Reading, 12/5/2016
Consolidated Snaps Up Fairpoint for $1.5B
Iain Morris, News Editor, 12/5/2016
Small Arctic ISP Caches Netflix in New Way
Mari Silbey, Senior Editor, Cable/Video, 12/7/2016
Like Us on Facebook
Twitter Feed
BETWEEN THE CEOs - Executive Interviews
Eyal Waldman, CEO of Mellanox Technologies, speaks to Steve Saunders, CEO of Light Reading, for an exclusive interview about the 100 GB cable challenge, cybersecurity and much more.
Join us for an in-depth interview between Steve Saunders of Light Reading and Alexis Black Bjorlin of Intel as they discuss the release of the company's Silicon Photonics platform, its performance, long-term prospects, customer expectations and much more.
Animals with Phones
A Mobile Safari Click Here
Literally.
Latest Comment
Live Digital Audio

Even when there's a strong pipeline of female talent in the comms industry, it tends to leak all the way to the top. McKinsey & Company says women experience pipeline leakage at three primary points: being unable to enter, being stuck in the middle or being locked out of the top. Each pipeline pain point presents its own challenges, but also opportunities to stop the leak. Wireless operator Sprint is making a conscious effort to improve its own pipeline from new recruits to the C-suite, and it wants the rest of the industry to do the same. In this Women in Comms radio show, WiC Board Member and Sprint Vice President of Enterprise Sales Nelly Pitocco will give us her take on the industry's pipeline challenges. Pitocco, who joined Sprint in May and has spent 20 years in the comms industry, will also offer solutions, share how Sprint is tackling the challenge within its own organization and take your questions live on air.