Showing posts with label FOSE 2014. Show all posts
Showing posts with label FOSE 2014. Show all posts

Wednesday, 13 August 2014

Cybersecurity: What the U.S. Can Teach Europe

Article originally published in FCW magazine.


By Edwin Bentley (Senior Software Developer, Titania) 

About the Author

Edwin joined Titania in 2011 and has since become a key member of development team, having primary involvement in advancement of both the Nipper Studio and Paws Studio software. He has a keen interest in Information Security and the role that the industry will play in the future advancement of technologies.


Having attended two reputable information security conferences this year, one on each side of the Atlantic, a few observations emerged on the differences and similarities of opinion on cybersecurity issues in the U.S. and Europe.

Although similar questions were raised at both conferences, the response manner was notably different. Europe took a reactive stance by signaling problems and bringing them to the attention of government agencies and legislators. The U.S., however, had a top-down approach, with industry searching for viable solutions in response to already adopted government directives.

The first event was Infosecurity Europe. The 2014 edition was hosted in London and attended by more than 11,000 information security professionals. With a 20-year tradition, the event is considered a reference point for the cybersecurity industry to find out about the latest trends and tools and keep up-to-date with European laws and compliance policies.

This year, the discussion focused on big data, the accelerated increase in organized cybercrime, the need to stay ahead of threats and an honest admission from Europol that cybercrime is best mitigated or disrupted because law enforcement lacks the resources to prosecute all crime. Staying ahead of threats was high on the agenda. Finally, there were comments on security issues in the cloud, which just like the bring-your-own-device trend, needs to be accommodated in its own right from a protection point of view.

Similar points were made at FOSE. (Editor's note: FOSE is owned and produced by FCW's parent company, 1105 Media.) As an industry event, FOSE is recognized as an official source for voicing the latest concerns in government IT. Among the issues discussed at the conference, cybercrime and cyber terrorism figured high on the agenda for defense and policy.


Continuous Diagnostics and Mitigation


In terms of security tools and trends, automation and continuous monitoring were held in high regard at the U.S. conference. The conversation on the FOSE floor focused on the Department of Homeland Security's Continuous Diagnostics and Mitigation (CDM) program. It comes on the heels of the National Institute of Standards and Technology's Cybersecurity Framework and is part of achieving the last step of that directive: monitoring security on an ongoing basis with the use of automation tools.

Released as a best-practice guidance document, the framework was embraced by the federal sector. After the latest high-profile breaches in the retail industry, a wide range of other companies have started to look at the framework as a template for assessing security practices.

In order to understand why CDM is seen as the best solution by IT professionals, below are a few well-debated problems it answers:

  • Top of the agenda for information security experts is how best to integrate security with business processes. Reducing user disruption and enabling business innovation will be more easily addressed with the introduction of automated security.
  • Although CDM does not guarantee that its users will stay ahead of threats, it does offer a near-real-time state of security with risk-based assessments reported and analyzed at network speed to ensure ongoing awareness and protection.
  • A challenge for chief information security officers and CIOs everywhere is the compliance versus security conundrum. CDM implies moving away from layer upon layer of compliance in favor of perpetual alertness and security.
  • The other issue in compliance is log aggregation and reporting. Continuous monitoring would produce automated event logs that can be filed for audits or analyzed for patterns in forensic investigations.
Continuous monitoring does not promise to answer every cybersecurity problem, but it offers a practical way forward. The voluntary adoption within the U.S. business community reflects that its advantages have been recognized.


Cyber directives in Europe and U.K.

Source: fcw.com
Meanwhile, that shift in security perception has yet to happen in Europe. The latest European Union cyber directive -- Network and Information Security (NIS) -- has been taken with a pinch of salt by the industry, and some organizations fear that the stick of compliance will come down hard on their budgets while doing very little for the state of their security.

In a similar way to the NIST framework, the U.K. government released a Cyber Essentials Scheme as a best-practice guide for organizations. Operating in a less intrusive manner with smaller, more practical steps, the scheme has been received with cautious but definite approval by the business spectrum.

Although a promising start, neither the Cyber Essentials Scheme nor the NIS directive alone is sufficient to bring forward the visionary changes the industry needs. The European efforts are moving in the right direction, but compared to the older, more experienced industry in the U.S., they need further development. The Cyber Essentials Scheme might be too small, while NIS could be seen as too complicated and faces an uncertain fate amid changes to the European Parliament.

If the cybersecurity industry is to address the issues raised at Infosecurity Europe 2014 such as staying ahead of threats, mitigating cyber crime, transforming security into a business enabler and dissipating the predicament of compliance versus security, then Europe needs to continue to move in the right direction and could be inspired by the top-down approach to security in the U.S.

Thursday, 15 May 2014

FOSE 2014 - Highlights from Titania

Ian Whiting introduces the FOSE audience to Titania's flagship
product Nipper Studio
On the first day of FOSE, the leading annual event in Washington DC for technology providers to meet with government, Titania CEO, Ian Whiting presented to an audience of delegates among the 8000+ attendees on Titania's flagship network security and compliance audit suite Nipper Studio

US government agencies in defense, homeland security and law enforcement, who are already users of Nipper Studio, were able to learn about the many new features included in the latest version of Nipper Studio which has just been released.

Visitors to Titania's stand at the FOSE Expo were also able to learn how the company's suite of audit software solutions will be able to help the US government move to a Continuous Diagnostics and Mitigation (CDM) posture across all federal agencies, which is the subject of a $6 bn budget allocated over the next 5 years, via the Department of Homeland Security. Released by the DHS, the CDM program is intended as a shift from the current static safeguarding of network security in favor of a more dynamic, constant monitoring policy. 


Titania #727 stand


Many visitors to Titania's stand commented favorably on Titania's remarkable record as a small, specialist UK software company in successfully acquiring as valued clients so many of the largest federal government agencies within the US military and civil government communities. 



The second day at FOSE saw many US government officials stopping by at the Titania booth to learn about our innovative solutions for network security and compliance auditing. 
Ian Whiting explaining how the product he created works

Representatives from the Navy, DHS, the State Department and NOAA, among others, were able to hear about the latest updates to current Titania products as well as learning about a major new product launch coming soon.

Nicola Whiting networking at FOSE

Tuesday, 13 May 2014

First@FOSE 2014 Exhibitor Gallery

This year at FOSE, there is a healthy focus on the first time exhibitors at the show. Titania is delighted to present during the F1rst@FOSE sessions, along with other companies and government organizations, on Tuesday, the 13th of May 2014. 

Below, you can find a gallery of other exhibitors that will showcase new solutions on the F1rst stage over the next three days:




Monday, 12 May 2014

FOSE 2014 - 10 Exhibitors To Watch & Listen


FOSE, the Federal Office Systems Expo, is the event with the longest legacy (over 37 years) in serving the government technology community, by reuniting the best vendors, tools and practices, under one roof with government representatives for training, opinion exchange and networking. The  2014 event takes place for three days, during 13th - 15th May, at the Walter E. Washington Convention Center in Washington D.C. 

FOSE at a glance:
  • Access to 3 additional conferences:
GovSec - the largest most dynamic government security event 
TREXPO (law enforcement conference)
- CPM (Contingency Planning Management)
  • Keynote, panels and technical sessions taking place across 8 tracks:
- Cloud & Virtualization
- Cybersecurity
- Mobile Government
- Big Data & Business Intelligence
- Records & Information Management
- Acquisition & Procurement
- Project Management 
- Cybercrime & Cyberterrorism


  • A newly added track for FIRST @FOSE will provide an opportunity for new exhibitors to showcase their products and solutions in a 15 minute session. Titania will be introducing its cybersecurity tools on Thursday. 

  • Over 200 exhibitors offering solutions in cyber security, information management, big data and cloud migration. Below is a selection of 10 exhibitors worth visiting, whether it's to watch a demo, listen to the talks or test a new tool:


1. Titania
@TitaniaLimited
Booth #727




Titania will be exhibiting for the first time at FOSE 2014 and will showcase its products Nipper Studio, the automated security and compliance auditing software for firewalls, switches and routers and Paws Studio, the automated compliance auditing software for workstations and servers. Already popular with governmental agencies and departments, including the FBI, Treasury and DoD, these tools have been recommended by pentesters and auditors as a thorough, fast and cost effective way to securely audit networks. Drop by, meet the CEO and find out about the new continuous monitoring product Titania will be releasing soon - TEC.

2. ESET North America
@ESETNA
Booth #826

A developer of security solutions for home and corporate users, ESET North America will be exhibiting at FOSE to showcase their multi-layered, in-depth security solutions for government organizations. They also promise two presentations for those who want to learn about using technology and people to reduce threats of full-spectrum malware attacks. The presentations will provide welcome ideas of how to efficiently integrate people with technology and discusses the need for multiple levels of malware protection.   

3. Laserfiche
@laserfiche
Booth #731

Laserfiche provide efficient streamlined ECM (enterprise content management) for small to large organisations. This year at FOSE, aside from live demo’s of their automation tools, Evan Anderson, Laserfiche Director of Strategic Solutions will deliver a discussion explaining the benefits of shared services in ECM – Adopting a Shared Services Model for Enterprise Content Management. Taking into account risk management, he brings together the DoD 5015.2 directive on record management functionality with automation tools. These are used for efficiently streamlining processes such as account processing, employee onboarding or contract management.

4. BlueCat
@BlueCatNetworks
Booth #615

An IPAM (IP Adress Manangement) innovator and a provider of DNS and DCHP solutions, BlueCat comes to FOSE with a session on 'Leveraging Core Services to Protect Your Network' and a recent release of the BlueCat Threat Protection, which promises to stop threats at DNS level - “the starting point of all network connectivity”. 

5. Redsky Technologies
@RedSkyE911
Booth #837

RedSky Technologies is the leading provider of E911, the enhanced 9-1-1 emergency service, which was proven to save lives by pinpointing the exact location of a 911 caller in a busy environment. In the context of complex organizations, such as Federal and Governmental agencies, RedSky Technologies brings 'Solutions for Cloud, Compliance and Complex Enterprises'. The talk is delivered by the Director of Business Development, Ken Rosko. 

6. Stoneware Inc. 
@stoneware_inc
Booth #841

Stoneware, a manufacturer of cloud computing and classroom management software, presents a session on 'Delivering IT Services Securely in a Mobile World' delivered by Marketing Director, Gregory Tan. The talk will address the problem of security in a highly interconnected workplace. Stoneware webNetwork promises freedom and flexibility to access apps and legacy systems from any device, without denting the central control held by the IT department.  

7. Aerva Inc.
@Aerva
Booth #1014

Aerva brings AerWave, a cloud-based platform for managing and scheduling content across any kind of screen (be it browsers, tablets, or LCD displays). Aerva CEO,  Sanjay Manandhar, will speak on the Mobile Government track: From Concept to Implementation – Organization-Wide Digital Networks. 

8. Nylte Software
@nlyte
Booth #812

Nlyte Software, provider of software for planning, managing and optimizing data centers, will announce Nlyte 7.6 at FOSE.  They will also deliver a talk 'A Smooth Data Center Consolidation Project: It’s Not an Oxymoron!' to be presented by Mark Harris, VP of Marketing and Data Center Strategy. This will discuss the planning and execution of a data center consolidation and the financial, IT and productivity implications.  

9. University of Fairfax
@UoFAcademics
Booth #1837

The University of Fairfax prides itself as being the only online graduate school in the US, 100% focused on cyber security, with master and doctoral programs for senior information security professionals.  President, Dr. Christopher Feudo, will deliver a spotlight session on 'The Challenge of Winning the Cyber Security Workforce Talent', which addresses the cyber security skills gap against the backdrop of globalization. 

10. BAE Systems
@BAESystemsInc
Booth #1240

BAE Systems offers SIBA, a recently launched tool for simplified and secure data collaboration and dissemination for government and commercial customers. With customizable access level and integration with Microsoft Office products, SIBA makes it possible to share critical intelligence with multiple partners in real-time, at reduced costs. Peter Jungck, VP and Chief Technologist in the Intelligence & Security department, will share some of the 'Lessons Learned in Migrating to a Virtualised Desktop Environment'.