Josiah Dykstra and I have a new draft at Arxiv, Handling Pandemic-Scale Cyber Threats: Lessons from COVID-19 The devastating health, societal, and economic impacts of the COVID-19 pandemic illuminate potential dangers of unpreparedness for catastrophic pandemic-scale cyber events. While the nature of these threats differs, the responses to COVID-19 illustrate valuable lessons that can guide preparation and response to cyber events. Drawing on the critical role of collaboration and pre-defined roles in pandemic response, we emphasize the need for developing similar doctrine and skill sets for cyber threats. We provide a framework for action by presenting the characteristics of a pandemic-scale cyber event and differentiating it from smaller-scale incidents the world has previously experienced. The framework is focused on the United States. We analyze six critical lessons from COVID-19, outlining key considerations for successful preparedness, acknowledging the limitations of the pandemic metaphor, and offering actionable steps for developing a robust cyber defense playbook. By learning from COVID-19, government agencies, private sector, cybersecurity professionals, academic researchers, and policy makers can build proactive strategies that safeguard critical infrastructure, minimize economic damage, and ensure societal resilience in the face of future cyber events.
Cybersecurity Innovation Trends
Explore top LinkedIn content from expert professionals.
-
-
Your Smarthome Is Talking—But Who’s Listening? Smart home devices offer incredible convenience, allowing us to control lights, locks, appliances, and cameras remotely. However, each of these Internet of Things (IoT) devices also represents a potential vulnerability in your home’s digital perimeter. Many users install these gadgets without changing default settings, leaving them wide open to cyber intrusions. Threat actors have exploited poorly secured devices to spy on households, manipulate smart locks, or gain access to broader home networks. To avoid these risks, we must treat IoT devices with the same caution as computers or smartphones. That means using strong, unique passwords, enabling two-factor authentication where possible, and consistently updating firmware. Network segmentation is another smart move—placing IoT devices on a separate Wi-Fi network to prevent them from interacting with sensitive systems like work laptops or home servers. Finally, it’s important to evaluate the necessity of each new connected device. Ask yourself if the benefits truly outweigh the privacy risks. Not every gadget needs to be online, and sometimes convenience can come at the cost of security. In an age where even your thermostat or baby monitor can be exploited, a little common sense goes a long way in protecting your privacy and peace of mind. #cybersecurity #IoT #smarthomes #securitycameras #babymonitors #webcams #smartappliances
-
Privacy by Design and Default are more than just buzzwords They're fundamental principles that can make or break trust with your users. Yet, many professionals still struggle to grasp their importance. Let me break it down using a timely example from Telegram Messenger: The Good: Privacy by Design Telegram gets it right when it comes to Privacy by Design. Their settings are a masterclass in giving users control, offering three privacy levels for most options: -Everybody - Contacts - Nobody This shows they’ve integrated privacy into the very fabric of their app, giving users the power to decide who sees what (in the design). The Miss: Privacy by Default But here’s where Telegram drops the ball—Privacy by Default. Despite offering granular privacy controls, all options are set to ‘Everybody’ by default. This is a major oversight. Why does this matter? Privacy by Default means that the most secure, private setting should be the default. Telegram should have set all options to ‘Nobody’ by default, allowing users to opt into less privacy if they choose. This approach not only protects users but also demonstrates a commitment to their privacy from the get-go. A Timely Reminder: The recent arrest of Telegram’s CEO highlights the importance of getting privacy right—it’s not just about ticking boxes; it’s about safeguarding your users and the integrity of your platform. In an era where trust is easily lost, these principles are not optional; They are essential. Your Actionable Takeaways: Embed Privacy by Design: Start with privacy as a core principle, not an afterthought. Make it easy for users to control their data. Default to Safety: Always set the most private option as the default. This small step goes a long way in protecting users. Educate and Empower: Make sure your team understands these principles and can apply them. Privacy isn’t just the responsibility of the legal team—it’s everyone’s job. The Bottom Line: In today’s digital landscape, privacy is power. Build it into your product from the start. Always put your users first by defaulting to the most privacy friendly settings. This ensures compliance and also builds a foundation of trust that will set you apart. ----------- 👋 I'm Jamal! I want to help you become a world-class privacy expert so you can have the thriving career you deserve. 🔔 Hit that bell for more inspiration, insights and tips. ♻ You've made it this far - so why don't you, repost to your network now so they can benefit too
-
Thrilled to share our latest episode of “All into Account,” J.P. Morgan’s podcast covering the fast-moving world of cybersecurity. I was joined by lead analyst for our annual report, Amy Ho (Strategic Research), Brian Essex, CFA , CFA (Security Software Equity Research), Pat Opet (Global Chief Information Security Officer), and JF L. . (Deputy CISO & Global Technology Chief Control Manager) for a deep dive into the trends shaping the industry. Key insights from our discussion and new report: ➡️ Cybercrime costs are projected to soar to $10.5 trillion in 2025—nearly 50x global cybersecurity investment. ➡️ AI is transforming the threat landscape, making attacks faster and more sophisticated, but it’s also strengthening defenses through smarter network monitoring and threat detection. ➡️ State actors are increasingly targeting critical infrastructure, and the number of active ransomware groups have doubled in the past three years. ➡️ AI-driven fraud and digital payment losses are set to triple to $40 billion by 2027. ➡️ Quantum computing is on the horizon, with the potential to break today’s cryptographic standards by 2035, with greater government investment anticipated. ➡️ The shortage of cybersecurity professionals continues to drive up the cost and impact of breaches. ➡️ Cyber insurance adoption is rising, yet regulatory approaches remain fragmented across regions. Thank you to my colleagues for sharing their expertise on these critical issues. Tune in for our perspectives on the future of cybersecurity, industry investment, and risk management! Listen to the full podcast here: https://lnkd.in/ep-bAm2k
-
The 2024 Global Chief Information Security Officer Organization and Compensation Survey provides a comprehensive analysis of the roles, challenges, and compensation trends for CISOs worldwide. Key highlights include: 1. Organizational Trends: • 14% of CISOs report directly to the CEO, up from 5% in 2023, signaling a closer alignment with business strategy. • Most CISOs are spending more time on AI, cloud transformations, and cybersecurity governance. 2. Risks and Expertise: • Ransomware remains the top cybersecurity risk globally, followed by nation-state threats and AI-related risks. • Over the next 5 years, CISOs see AI, machine learning, and application security as critical areas for skill development. 3. Compensation Insights: • U.S. CISOs have the highest average total compensation, reaching $1.6M, followed by Europe ($595K) and Australia ($414K). • Financial services firms offer the highest salaries, while equity and sign-on bonuses are significant contributors in the U.S. and India. 4. Challenges: • Recruitment is increasingly difficult due to high compensation expectations and job stress. • Nearly half of organizations lack an internal CISO successor, indicating a gap in leadership pipelines. 5. Diversity: • Gender diversity remains low, with only 11% of respondents identifying as women. • Non-white representation among U.S. respondents decreased to 20%, raising concerns about inclusivity. The survey underscores the growing importance of CISOs in addressing both technological and organizational challenges, particularly as AI adoption and cybersecurity threats evolve. #CISO #CybersecurityLeadership #CISORole #CyberRisk #AIAndCybersecurity #Ransomware #InformationSecurity #DigitalTransformation #CyberCompensation #LeadershipPipeline #CyberTalent #DiversityInTech #CyberTrends2024 #BoardroomCyber #CyberResilience #CISOChallenges #FutureOfCybersecurity #TechLeadership #SecurityInnovation #CyberStrategy
-
AIM Research has just Launched its GenAI-Powered Cybersecurity Vendor Landscape Report. The cybersecurity landscape is undergoing a significant transformation with the integration of Generative AI. Here are some key Insights: ✢ Major cybersecurity providers are not just adding GenAI features—they're fundamentally rethinking their platforms to incorporate AI agents, copilots, and context-aware assistants. This shift is moving tools from private previews to public availability, signaling a readiness for broader implementation in 2024. ✢ The industry faces a skill-gap and burnout crisis. GenAI-powered tools are emerging as a solution to alleviate these challenges by handling repetitive and intricate tasks. ✢ Vendors are expanding beyond traditional solutions. We're seeing the rise of AI agents that autonomously monitor and respond to incidents, copilots that assist IT teams in real-time, and platforms that simulate attacks to test and strengthen security postures. ✢ The new wave of tools brings capabilities like intelligent summarization, natural language querying, multilingual conversational functions, proactive security measures, alert prioritization, decision-ready analysis, guided recommendations, and automation. ✢ Vendors are focusing on enhancing functionalities in autonomous threat detection and providing transparency in how AI systems reach conclusions. Access the complete report here: https://lnkd.in/gxj8vY3N Darktrace, Deep Instinct, Dropzone AI, ExtraHop, Fortinet, Mandiant (part of Google Cloud), Prophet Security, Torq, Radiant Security, ReliaQuest, SentinelOne, Simbian, Swimlane, Sysdig, Wiz, Stream.Security, Sysdig, CrowdStrike, Palo Alto Networks, Orca Security, Cisco, ZEST Security, Proofpoint, Aqua Security, Netskope, Dazz, Sweet Security, Zscaler, Sentra, Tenable, Mitiga, Rapid7, Trend Micro, Lacework, Uptycs
-
Two weeks ago, at a private CISO 🏛️ gathering in Silicon Valley, and one theme stood out: "Enterprise AI" is quietly rewriting our Security assumptions. Here are a few insights that stuck with me and why they matter today: 🔎 Shadow AI is everywhere. We’re seeing AI tools slip into orgs through side doors like browser plugins, embedded features in existing SaaS, unmanaged API endpoints. 💪🏾 Why this matters today: When devs and non-tech teams experiment with AI outside of sandboxed environments, they create security gaps that can’t be patched especially if they’re not even seen. The need for visibility into AI use both authorized and unauthorized is important to maintain or be aware of the growing exposure to the current risk & compliance posture of the organization. 📧 Email remains the No1 way in but now with an AI twist. Phishing hasn’t gone away, it’s gotten smarter & targeted with AI. 💪🏾 Why this matters today: MITRE still lists Phishing as the top cloud entry point. AI-generated messages are cleaner, more human-like, and increasingly context-aware. They’re harder to detect and often skip traditional defenses entirely. The attack surface is expanding as email clients and platforms diversify, too. Email security must evolve alongside other endpoint defenses to have detection and response actions against new relevant attacks not just existing ones. 🌐 The Browser: Today's most active and risky employee workspace We do 60%+ of our work in a browser. That’s where AI tools live now too. 💪🏾 Why this matters today: Prompt injection, LLM misuse, AI-generated scripts they’re all happening in your browser. Today, in addition to the technical teams, business users are also “coding” with AI, whether they realize it or not (You can see the python script written by Claude in many use cases on the browser). The browser is no longer just a user interface. It’s an active execution environment that needs monitoring. and similar to emails and endpoints need to brought into detection and response actions against new relevant attacks not just existing ones. If you're defending enterprise environments in 2025, these are places I’d keep a close eye on. 🎬 Thank you to the Palo Alto Networks team for hosting the CISO event and that too in a cinema, a fitting space to reimagine where security needs to go next. 🔗 If you would like to know how Palo Alto Networks is thinking about these new threat surfaces. Link - https://lnkd.in/e-sw2UR9 Question for you: What’s the most surprising AI-related security blind spot you’ve seen recently? #PaloAltoNetworksPartner #AI #Cybersecurity
-
𝗢𝗧 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗶𝗻 𝟮𝟬𝟮𝟱: 𝟱 𝘁𝗿𝗲𝗻𝗱𝘀 𝗜 𝘀𝗮𝘄 𝗮𝗰𝗿𝗼𝘀𝘀 𝗰𝘂𝘀𝘁𝗼𝗺𝗲𝗿𝘀, 𝗽𝗿𝗼𝗷𝗲𝗰𝘁𝘀, 𝗮𝗻𝗱 𝗳𝗶𝗲𝗹𝗱 𝗱𝗶𝘀𝗰𝘂𝘀𝘀𝗶𝗼𝗻𝘀 👇 1️⃣ 𝗔𝘁𝘁𝗮𝗰𝗸𝘀 𝗮𝗿𝗲 𝘂𝗽 — 𝗯𝘂𝘁 𝗮𝘀𝘀𝗲𝘁 𝘃𝗶𝘀𝗶𝗯𝗶𝗹𝗶𝘁𝘆 𝗶𝘀 𝘀𝘁𝗶𝗹𝗹 𝘁𝗵𝗲 #𝟭 𝗽𝗮𝗶𝗻 𝗽𝗼𝗶𝗻𝘁 If you don’t know what you have, you can’t protect it — and most programs still struggle here. 2️⃣ 𝗦𝗸𝗶𝗹𝗹 𝗱𝗲𝗳𝗶𝗰𝗶𝘁 𝗶𝘀 𝗿𝗲𝗮𝗹 (𝗮𝗻𝗱 𝗴𝗲𝘁𝘁𝗶𝗻𝗴 𝘄𝗼𝗿𝘀𝗲 𝗳𝗮𝘀𝘁𝗲𝗿 𝘁𝗵𝗮𝗻 𝘄𝗲 𝗮𝗿𝗲 𝘂𝗽𝘀𝗸𝗶𝗹𝗹𝗶𝗻𝗴) We need more accessible, high-quality, hands-on OT security learning — not just awareness slides. 3️⃣ 𝗥𝗲𝗴𝘂𝗹𝗮𝘁𝗼𝗿𝘆 𝗺𝗼𝗺𝗲𝗻𝘁𝘂𝗺 𝗶𝘀 𝗿𝗲𝗮𝗹 𝗮𝗰𝗿𝗼𝘀𝘀 𝗴𝗹𝗼𝗯𝗲 Australia adopting IEC 62443, CRA coming into effect, and India’s power-sector draft regulation by CEA discussions — plus initiatives like QCI/NCIIPC maturity & certification efforts. Regulation is no longer “future tense”. 4️⃣ 𝗥𝗶𝘀𝗸 𝗮𝘀𝘀𝗲𝘀𝘀𝗺𝗲𝗻𝘁 𝗶𝘀 𝘀𝘁𝗶𝗹𝗹 𝗶𝗴𝗻𝗼𝗿𝗲𝗱 — 𝗯𝘂𝘁 𝘁𝗲𝗰𝗵 𝗮𝗱𝗼𝗽𝘁𝗶𝗼𝗻 𝗶𝘀 𝗽𝘂𝘀𝗵𝗲𝗱 Many programs are buying tools before agreeing on: crown jewels, credible scenarios, zones & conduits, and risk acceptance. 5️⃣ 𝗔𝗜 𝗶𝘀 𝗲𝘅𝗽𝗹𝗼𝗱𝗶𝗻𝗴 — 𝗳𝗼𝗿 𝗮𝘂𝘁𝗼𝗺𝗮𝘁𝗶𝗼𝗻 𝗮𝗻𝗱 𝗰𝘆𝗯𝗲𝗿𝘀𝗲𝗰𝘂𝗿𝗶𝘁𝘆 From SOC efficiency to OT workflows — AI is moving from “pilot” to “production curiosity”. The key is governance + safety + validation. 𝗠𝘆 𝘁𝗮𝗸𝗲𝗮𝘄𝗮𝘆: 𝟮𝟬𝟮𝟲 𝘄𝗶𝗹𝗹 𝗯𝗲𝗹𝗼𝗻𝗴 𝘁𝗼 𝘁𝗲𝗮𝗺𝘀 𝘄𝗵𝗼 𝗴𝗲𝘁 𝘁𝗵𝗲 𝗯𝗮𝘀𝗶𝗰𝘀 𝗿𝗶𝗴𝗵𝘁: ✅ Asset visibility → ✅ risk-driven prioritization → ✅ skills → ✅ compliance → ✅ sustainable automation What did you see in 2025 in your plants / utilities / manufacturing environments? Drop one trend you strongly agree (or disagree) with. #OTSecurity #ICS #IEC62443 #CriticalInfrastructure #CyberSecurity #RiskAssessment #AI #Governance #IndustrialCybersecurity Disclaimer: Views are personal and not of the organization I am associated with.
-
Your biggest cybersecurity threat might not be your employees — it might be your coffee machine. Everyone’s worried about employees clicking phishing emails… …but who’s worried about the smart thermostat leaking your sensitive data? (You should be.) When we talk about human cyber risk, it’s not just laptops and emails. It’s the people who plug in devices they don’t understand — or don’t think about — that open the backdoor. The truth is: The Internet of Things (IoT) is your weakest (and most ignored) security link. 📺 Smart TVs. 🏅 Fitness trackers. ☕ Coffee machines. 🔔 Video doorbells. 💡 Smart lighting. 🌡️ Even that “harmless” Wi-Fi-enabled fish tank thermometer in your lobby. (Yes, that actually happened to a casino in 2019 where the whole high roller database was exfiltrated through an IoT connected fish tank thermometer. Ouch.) If it connects to the internet, it can connect a threat actor to you. ACTIONABLE TAKEAWAYS: ✔️ Audit your IoT Devices: List everything in your business and home that’s internet-connected. If you don’t track it, you can’t protect it. ✔️ Segregate Networks: Keep IoT devices on a separate Wi-Fi network from business operations and sensitive information. ✔️ Change Default Credentials: Most IoT breaches happen because devices are left on factory settings. Change all passwords — immediately. ✔️ Update Firmware: Your smart devices need updates just like your computer does. Patch regularly or retire them if they’re no longer supported. ✔️ Train Your People: If they’re plugging it in, they’re opening a portal. Awareness matters. Train users to think before they connect. Bottom line: Human risk isn’t just about bad passwords and phishing clicks. It’s about our instinct to trust technology we don’t fully understand. If you employ humans, if you use IoT, you have risk. Manage your humans. Manage your tech. Or someone else will. #HumanRisk #Cybersecurity #IoTSecurity #InsiderThreat #CyberHygiene #Leadership #SecurityAwareness
-
Australia is fortunate to have a thriving #cybersecurity community. From the Australian Information Security Association (AISA), ACS (Australian Computer Society), ISC2 Chapters, ISACA Chapters, AWSN - Australian Women in Security Network, Day Of The Month (DOTM) Club and many other passionate groups, there’s no shortage of people dedicated to making our digital world safer. But with that passion has come fragmentation. Too often, our collective efforts are siloed. Duplicate events, overlapping initiatives, and at times, competing priorities. This can create confusion for practitioners, dilute our impact, and ultimately leave gaps and differences for adversaries, both criminal as well as self-serving in the industry, to exploit. During my time as Director of Cybersecurity Advocacy at ISC2 and on the Board of Directors at Australian Information Security Association (AISA), I made it a personal mission to try to bring these groups together, encouraging collaboration and alignment. My vision was for each organisation to play to its strengths ... whether that was technical skills development, policy influence, professionalisation of the sector, or community outreach, so that, collectively, we could deliver something far greater than the sum of our parts. Cybercriminals don’t compete with one another. They collaborate. They share ideas. And they are winning. If we are to meet the scale and sophistication of the threats we face, we must do the same. Imagine what we could achieve with shared strategy, pooled resources, and a unified voice advocating for Australia’s cybersecurity future. The talent, energy, and willpower are there. It should be about bringing it all together. While working and industry cyber practitioners splinter into their own little tribes and clubs, the #technology companies have unified under lobby groups such as the Tech Council of Australia - and tech policy in this country is now poorer as a result. It is my view that it is past due to unify our ecosystem. Collaboration isn’t just nice to have. It’s absolutely essential for building a resilient, secure digital Australia. How can we unify the disparate #IT and #Cybersecurity practitioner groups together under a common mission and vision?