EASA Proposes New Aircraft Cybersecurity Certification Amendments
Avionics International – The European Aviation Safety Agency (EASA) is proposing new cybersecurity amendments to the way aircraft electronic networks and systems are certified. Under the new amendments, manufacturers and operators seeking certification of new aircraft systems and networks or modifications to existing ones will be required to address threats that can lead to unauthorized access and disruption of electronic information or electronic aircraft system interfaces. EASA is proposing the new amendments to address the growing presence of connectivity within modern aircraft network designs.
Protecting your ATMs, Part II: Understand your adversary
ATM Marketplace – The vast majority of criminals are in it for the money, not the challenge, so they’ll always pursue the easiest route to a payoff. Naturally, then, the best-protected ATMs are those that make a thief’s work the hardest — by minimizing attack surfaces and focusing first on the “handoff” points in a system that present the most likely targets for criminal exploits.
Daily briefing. February 21, 2019.
CyberWire – Social media posed enough operational security problems for Russian forces operating against Ukraine that the Russian Army cracked down on their soldiers’ online presence. It’s a general problem: a NATO red team reports that military personnel put enough personal information online to render them vulnerable to influence and social engineering. Troops also discuss matters better left undiscussed.
Protecting your ATMs, Part I: ‘You don’t have to run faster than the bear’
ATM Marketplace – “You don’t have to run faster than the bear. You just have to run faster than the other guy running from the bear.” It’s possibly not the most empathetic way to look at ATM industry security, but it is certainly realistic, pragmatic and smart. Because try as they might, ATM deployers will never outrun the bear — the bear in this case being criminals looking for easy money.
Renowned Architecture and Threat Modeling Visionary Brook S.E. Schoenfield Joins IOActive World-Class Advisory Practice
Industry Programmatic Security Expert Will Advise IOActive’s Global 1000 Clients with Strategic Security Programs Seattle, Wash., February 20, 2019 — IOActive, Inc., the worldwide leader in research-driven security services, today announced that Brook S.E. Schoenfield has joined the company’s Advisory Services team, bringing more than three decades of development and security expertise to the team. In his role as Advisory Services Director at IOActive, Schoenfield is focused on leveraging threat modeling and building robust software security programs for IOActive’s Global 1000 customers. “Brook’s thorough understanding of cyber risks and the…