


In an interview with Joel Earnshaw, Manager, Security and Risk, Perenti; expands upon the Cyber Security Space- its challenges, trends and predicaments. He also talks about the latest project that he’s been working on and what differentiates it.
1. What are some of the major challenges and trends that have been impacting the Cyber Security Space lately?
Particularly in the APAC region, we’re witnessing a new-wave of sophisticated social engineering campaigns; phishing, credential harvesting, BEC, and other similar sub-types. The rise and accessibility of AI powered tools such as ChatGPT have really lowered the technical barrier to entry for threat actors. We’re seeing AI being actively used to create increasingly genuine and convincing mixed media, ranging from more authentic and contextual phishing emails, through to ultra-realistic deepfake audio and video content.
The use of such technology, especially in the hands of nation-state affiliated threat groups with strategic motivations, could have catastrophic geopolitical implications globally. In particular, the potential for targeted disinformation campaigns, deception, and counterespionage are all becoming an emerging area of risk for governments and multinational organisations alike.
2. What keeps you up at night when it comes to some of the major predicaments in the Cyber Security Space?
Resourcing is one of our biggest challenges. In a previous article I wrote extensively about the global cyber security skills shortage and the realities of its effect on the global security market.
Contextually we’re at the height of the information age; cyber security is as prominent as ever, thanks to the recurring high-profile cyber-attacks we see publicised with such regularity, ripping across the global stage. And with the demand for cyber talent being at an all-time high, organisations are competing with one another more than ever before to acquire the scarce talent available. Yet the compounding nature of this is that it places additional pressure on our existing resources, which can and is leading to burnout and industry churn.
To that point, we have a duty of care as a global security fraternity that combines social and ethical responsibility to ensure the continued health and wellbeing of our people. Outcomes-based flexible working arrangements should be the new norm. And we need to be providing greater levels of support to our employees through meaningful health and wellbeing programs. This is more than a simple compliance exercise.
“The rise and accessibility of AI powered tools such as ChatGPT have really lowered the technical barrier to entry for threat actors.”
3. Can you tell us about the latest project that you have been working on and what are some of the technological and process elements that you leveraged to make the project successful?
Operationally, we’ve invested heavily into enhancing our cyber incident detection and response capabilities, and this is something we’ll continue to do indefinitely. In this age of assumed compromise, we all must adopt a breach mindset. To that end, we’re always looking at ways of both expanding and refining the level of visibility our analysts have across the digital estate. The richer and more contextual information we have available, the better our ability to detect active threats, via high-fidelity detections and alerting, all of which serves to improve the effectiveness of our response efforts.
This has been enabled via a close working relationship with our service delivery partners, augmenting our internal capability to aid in the development of new use-cases, connect new data sources, whilst continuously fine-tuning and tweaking our existing detection code and alerting mechanisms. We’ve also refined our processes and procedures as well, enriched by the lessons derived from periodic security incident simulations and testing.
Our adversaries will never stop, so neither can we. We must continue to shift the dial, and leverage all the tools in our collective arsenals, to stay in-step with the ever-changing threat landscape. This starts with a change in mindset, and a pragmatic approach to support it.
4. What are some of the technological trends which excite you for the future of the Cyber Security Space?
I’m absolutely intrigued and excited by the seemingly endless possibilities that both artificial intelligence (AI) and augmented reality (AR) introduce, particularly when viewed through a cybersecurity lens. These technologies have the ability to revolutionise the way we live, work, the services we consume, and the ways in which we interact with our environments.
From a defensive standpoint, AI and AI-driven tooling will continue to evolve. Able to make micro risk and threat-based decisions from correlated and contextual data feeds across the digital estate, and subsequently being used to detect and prevent cyber-attacks in near-real-time. These systems will quickly learn to recognise new threats, understanding patterns of attack and tradecraft markers, then responding to them faster than any traditional cybersecurity tooling or analyst ever could.
AR on the other hand has the potential to completely transform the way we work and interact with the physical and virtual world around us. Blending the two worlds, coupled with fully interactive real-time capabilities, AR would empower security professionals to combat new and emerging threats in a more timely and effective manner. Enabling enhanced situational awareness, facilitating real-time threat detection, rapid incident response, catering for new and immersive learning experiences, and presenting a variety of visual elements seamlessly. This will be a new frontier.