July 11, 2016 By Douglas Bonderud 2 min read

Corporations aren’t known for sharing. With so many employees, partners, providers and customers to manage, there’s always a chance for data compromise — so why risk it by sending more information around? And thanks to the rise of wearables, always-connected devices and the industrial IoT, these risks are growing.

The bigger problem? Malicious actors have no trouble swapping stories of compromise and successful attacks, putting the onus on companies to embrace security collaboration if they want to keep their networks safe. How do businesses trump the trust issue?

Is Security Collaboration Counterintuitive?

As noted by CIO, security firm Carbon Black is now “opening a line of communication” between companies with its new platform, the Detection eXchange. The idea here is to go beyond surface information such as virus signatures or IP addresses to share actual data about attack patterns and threat vectors. After all, it’s nothing for attackers to swap out a flagged IP address, but if they find typical attack patterns blocked at every turn, they’ll be left scrambling to change their ways.

Of course, security-savvy IT pros have raised a valid concern: If the goal of security firms is to protect key data, does it really make sense to share critical information? In the case of Carbon Black, for example, the government ultimately acts as a clearinghouse for shared data. It’s not a stretch to imagine this repository as a high-value target for cybercriminals, and once they have the inside track on how companies plan to deal with emerging threats, they can simply change tactics.

So while security collaboration sounds great, many companies balk at the idea of actually participating or share only the bare minimum required to ensure their own critical processes can’t be compromised.

Building a Better Mousetrap

The calls for national and global threat sharing frameworks are getting louder: As noted by SC Magazine, a recent cybercrime report from the U.K.’s National Crime Agency (NCA) argued that greater threat sharing is essential now that digital crime has outpaced traditional lawbreaking in the country. Additionally, TechCrunch made the case for a worldwide cyberthreat sharing program to help combat adaptive attackers.

Already, the Cybersecurity Information Sharing Act of 2015 (CISA) makes it possible for companies to share security information with the Department of Homeland security without facing legal ramifications for reporting data breaches in good faith. According to Dark Reading, however, any type of threat sharing framework is effectively a gamble since cybercriminal access to threat feeds negates any positive impact.

The piece does offer a few suggestions, however. For example, machine-to-machine-only threat feeds integrated with SIEM tools could be an option, along with completely anonymous reporting and the elimination of opt-in programs. Since corporations understandably value their privacy and freedom of action, this may be a case where anonymous, mandated reporting outweighs the benefit of opting to stay silent.

Companies are right to be wary of large-scale security collaboration initiatives. What if attackers grab control of this emerging threat playbook and use it to run an entirely new game? But hunkering down behind supposedly secure digital walls does nothing to improve the outcome. Trumping the trust issue is a rough ride but — win or lose — a unified security front gives companies a fighting chance.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today