Light Reading

AT&T's Amoroso: To Battle New Threats, Mobilize Your People

Dan Jones

Your biggest online concern these days might be those embarrassing nude selfies suddenly appearing on the web, but AT&T Chief Security Officer (CSO) Ed Amoroso is here to tell you that there are far worse things lurking in cyberspace.

Amoroso highlighted one of the key security areas that CSOs should be concerned about as a new wave of advanced persistent threats (APT) loom, and they're aiming to do more than just swipe thousands (or millions) of credit card numbers.

"The next step is probably terrorists trying to destroy critical infrastructure," he told Light Reading over breakfast Wednesday morning, "with the emphasis on destructive," he added, as he demolished a "broken yolk sandwich" (which looked a lot better than the name suggests).

Amoroso doesn't seem like a man given to idle fear-mongering, despite his job title. In fact, he's one of the more informative and jovial speakers you're likely to see on the often sawdust-dry tech conference circuit. (See AT&T's Ed Amoroso on Mobile Security for proof of how entertaining he can be.)

An advanced persistent threat is one organized by a specific group, sometimes using multiple methods, to break into a particular target. Recent examples would include data breaches at Home Depot and Target.

Amoroso says the APT pattern started with nation states and the military, moved on to criminal gangs, and is shifting to terrorist groups. "The one thing you won't be able to rationalize is the destructive stuff," he suggested in his keynote at the AT&T Cyber Security conference in New York City Thursday.

This is not, of course, an unknown concept. Former US Defense Secretary Leon Panetta has long warned of a "cyber Pearl Harbor." Even if the idea of what constitutes cyber terrorism is still somewhat cloudy, the broad idea is that groups could attack critical communications, energy and water networks and cause damage and wide-scale disruption.

Need to know more about mobile network security? Then check out the agenda for Mobile Network Security Strategies 2014, December 3 at the Westin Times Square, New York City.

Where Amoroso may differ is that he isn't suggesting that there is a pure technological solution to widespread security problems. The basic thrust of his keynote Thursday was: Be safer by training your employees not to do dumb stuff.

Advanced firewalls and network appliances are useful tools but people are the weakest link in the chain, he suggested. "All the times I've been hacked in my career, it was because of something that was off my radar," he said at the keynote, adding that systems are just too complicated to be 100% secure.

The focus cannot just be on technology, he suggested: People also have to be involved. Which, in the corporate environment, means pumping up the security awareness team.

"We've kind of punted on that before," he told Light Reading Wednesday. "A typical awareness document will put you to sleep."

In AT&T's case, the new approach meant using video to show employees what not to do. The funny, cutesy videos that Amoroso showed at the Thursday keynote targeted phishing attacks. They emphasized that people should not open attachments from suspicious senders, that they should run their mouse over URL links to see where they actually lead, and be very careful about information shared on social media.

AT&T has been working on this during the past six months. The amount of employees now not clicking on the faux phishing email tests that the security office sends out suggests that awareness about phishing attacks is up by 54%.

"Making the video doesn't have to be expensive," Amoroso said. The animated AT&T videos were made in-house: Firms could even use interns from film school for great results, he suggested.

"They'll love it," he said.

For more insights from Amoroso, see:

— Dan Jones, Mobile Editor, Light Reading

(2)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View        ADD A COMMENT
User Rank: Light Sabre
9/8/2014 | 1:08:35 PM
Ent or SP
Is he referring to AT&T the enterprise or the service-provider?
User Rank: Blogger
9/5/2014 | 2:44:51 PM
I had sliced grapefruit BTW
From The Founder
The comms industry is rallying to the cause of open, independent interoperability testing.
Flash Poll
Live Streaming Video
CLOUD / MANAGED SERVICES: Prepping Ethernet for the Cloud
Moderator: Ray LeMaistre Panelists: Jeremy Bye, Leonard Sheahan
Telecom Innovators Video Showcase
Tail-f, Cisco & What the Future Holds

10|9|15   |   8:17   |   (0) comments

Steve Saunders meets with Tail-f's Director of Technology, Carl Moberg, in Stockholm to discuss becoming part of Cisco, ETSI MANO, virtualization and the need to combine science and business in order to create opportunities for service providers.
LRTV Interviews
Broadband Forum Embraces SDN & NFV

10|9|15   |   02:42   |   (0) comments

At Gigabit Europe 2015, Robin Mersh and Kevin Foster from the Broadband Forum explain how the industry body is adapting to meet the SDN, NFV and cloud needs of the access network sector.
LRTV Interviews
Top Tips for FTTH Operators

10|8|15   |   02:26   |   (0) comments

At Gigabit Europe 2015, Ventura Team co-founder Richard Jones talks about some of the key business case considerations for FTTH network operators.
LRTV Interviews
M-net Calls for FTTx Unity

10|8|15   |   03:45   |   (0) comments

At the Gigabit Europe event, Jörn Schoof from M-net, the Munich city network operator, calls for industry collaboration on fiber broadband access rollouts.
LRTV Documentaries
The Business Case Challenge for NFV

10|7|15   |   03:47   |   (0) comments

Virtual CPE is one of the early success stories for network functions virtualization, as service providers are finding flexible, programmable CPE solves a lot of logistics problems and reduces their cost. But even here, Masergy Communications faced a business case challenge, says CTO Tim Naramore.
LRTV Interviews
JT Offers Some Gigabit Lessons

10|7|15   |   4:08   |   (1) comment

Barna Kutvolgyi, managing director, Global Consumer, at JT, the incumbent operator on the island of Jersey, talks about how other service providers can learn from his company's gigabit broadband rollout experiences.
LRTV Interviews
AT&T's Chiosi on the Potential of Open Source

10|6|15   |   06:27   |   (0) comments

AT&T Distinguished Network Architect Margaret T. Chiosi talks to Light Reading's Carol Wilson about the potential for open source technology to liberate communications service providers.
LRTV Interviews
Network Security in a Gigabit World

10|6|15   |   05:52   |   (0) comments

Masergy's James Harrison talks about some of the network security and data center issues network operators need to consider as they expand their broadband services portfolios.
LRTV Documentaries
Telefónica: In Search of Virtual Simplicity

10|5|15   |   07:30   |   (0) comments

Francisco-Javier Ramon Salguero, head of Telefónica's NFV initiative, admits virtualization initially means greater complexity, but with the right abstraction layer, it is possible to create a services-driven network architecture. He explains how Telefónica's current trials and initiatives are aimed at doing that, and what his company and other carriers need to ...
LRTV Interviews
Gigabit Europe Takeaways

10|5|15   |   03:47   |   (0) comments

Participants from the inaugural Gigabit Europe event in Munich share their key takeaways from the conference.
Women in Comms Introduction Videos
Intel Urges Women to Take Advantage of Their Seat at the Table

10|5|15   |   4:27   |   (1) comment

Have inclusive and constructive conversations, attach a bigger meaning to your work and get involved in the cause, Intel's Monique Hayward advises women in comms.
LRTV Interviews
BT Updates on Plans

10|2|15   |   03:16   |   (2) comments

Peter Bell, CIO at Openreach, the access network division at UK incumbent BT, provides an update on the operator's trials and how Openreach is planning to deploy the broadband technology in its street cabinets.
Upcoming Live Events
October 14-15, 2015, New Orleans Ernest N. Morial Convention Center, New Orleans, LA
November 5, 2015, Hilton Santa Clara, Santa Clara, CA
November 17, 2015, Santa Clara, California
December 1, 2015, The Westin Times Square, New York City
December 2, 2015, The Westin Times Square, New York City
All Upcoming Live Events
Network appliances have a strong value proposition in today's networks and will continue to do so in the NFV and SDN-enabled networks of tomorrow.
Hot Topics
M&A Speculation Swirls Around Juniper
Ray Le Maistre, Editor-in-chief, 10/6/2015
Cisco's Chambers Rules Out Political Bid
Mitch Wagner, West Coast Bureau Chief, Light Reading, 10/6/2015
Cord Cutting? 'Fraid so.
Brett Sappington, 10/7/2015
Infinera Fleshes Out Its Metro 100G Story
Ray Le Maistre, Editor-in-chief, 10/7/2015
Cisco Makes 'Martian' Connection
Mitch Wagner, West Coast Bureau Chief, Light Reading, 10/9/2015
Like Us on Facebook
Twitter Feed
Webinar Archive
BETWEEN THE CEOs - Executive Interviews
With so many new and exciting communications technologies now under development, it's easy to get caught up in the industry's escalating hype cycle. That's why the ...
Last week saw a big day in the 15-year history of Light Reading when Editor-in-Chief Ray Le Maistre and I were invited to interview the Deputy Chairman and Rotating ...
Cats with Phones
"What?! I'm on with Finisar about their stock price tanking" Click Here