PARTNER CONTENT

CYBER INITIATIVE TOKYO 2023

CYBER INITIATIVE TOKYO 2023 CYBER INITIATIVE TOKYO 2023
CYBER INITIATIVE TOKYO 2023 CYBER INITIATIVE TOKYO 2023

Cisco Systems

Speech Title Cyber Resilience against Unpredictable Threats

Ensuring business continuity with solutions that make up for security personnel shortages

Mitsuhiro Nakamura

Mitsuhiro Nakamura

Senior SE Manager, Global Security Specialist Organization

Cisco Systems G.K.

Security for preventing cyber threats faces numerous challenges. Mitsuhiro Nakamura of Cisco Systems talked about three of these that are especially serious. First is the shortage of security personnel. Second is the large number of security tools available, so that it is hard to become familiar with all of them. Third is the growing diversity of attacks, which makes it difficult to cover all of them on the defense side. Noting that the advantage today is on the attack side, he said that as security measures, “threat detection and response that are considerably faster than up to now are demanded.”

Mitsuhiro Nakamura

More important even than preventing intrusions is cyber resilience

He further stressed that, rather than the conventional priority on preventing intrusions, what is most important from the standpoint of protecting business is “cyber resilience,” the ability to recover to a state in which operations can continue even if an attack is received.

What can be done to raise the cyber resilience of an organization? Cisco Systems organizes seven high-priority initiatives broadly along the lines of “people/processes/culture” and “architecture.”

Belonging to the first group are (1) Establishing management-level support, (2) Fostering a security culture, and (3) Obtaining resources, while the second group consists of (4) Simplifying the hybrid cloud environment, (5) Implementing and maturing Zero Trust, (6) Strengthening detection and response capability, and (7) Implementing security at the edge.

Zero Trust, XDR, and SASE are all about enhancing resilience

Cisco Systems published a Security Outcomes Report that shows the extent of achievement in each of the seven areas as differences in average resilience scores. For (5), for example, there is a score difference of +30% between an organization that has implemented a mature Zero Trust program and one that has not.

Similarly, for (6), a company that has deployed and matured Extended Detection and Response (XDR) technology, for accurately determining the pathway of an attack, the damage status and causes, and responding to the situation, earns a score difference of +45% over a company that has not done so. Furthermore, in the case of (7), there is a score difference of +27% between an organization that has introduced Secure Access Service Edge (SASE), which unifies security functions with network functions to ensure a secure environment, and one that has not.

In other words, considering and implementing Zero Trust, XDR, SASE are steps that enhance resilience.

Mr. Nakamura pointed out that “Countermeasures need to be devised on the premise of Zero Trust (Never Trust, Always Verify).” He spoke about the importance also of managing the security measures as a policy integrating four approaches, namely, “establishing trust,” “trust-based access control,” “continual trust verification,” and “responding to changes in trust.”

In a situation where infrastructure is becoming more complex and security risks are increasingly challenging, he said SASE is one effective solution. A SASE provided to leading SMEs by Cisco Systems is Cisco+Secure Connect, an integrated package that can be deployed quickly on a turnkey basis and is easy to use.

Security by design as a key point in approaching security

A key to XDR is artificial intelligence (AI). To deal with attacks that have evolved by making use of AI, since around 2020 the defense side has also been using AI. In this way, cybercrime has come to take on the appearance of “AI vs. AI.”

In 2023, Cisco Systems brought out two security solutions using generative AI: SOC Assistant as an XDR service and AI Assistant as a firewall product. Since a huge investment is required for AI development and the like, Mr. Nakamura added that “users should also closely examine the trends in the financial base of each company.”

He ended his presentation by noting the importance of “security by design” in approaching security, and also of reducing point solutions to make things simpler and ease the management burden.

Related Links

CYBER INITIATIVE TOKYO 2023 Overall TOP