David D'Amato notes the lack of unified reporting standards for corporate board cybersecurity oversight compared to standardized financial reporting like 10-Ks and 10-Qs.
Opinion
D'Amato: Corporate board focus on China and Russia is a distraction
“They're simply really interested in things that are in the news. So if you look at things like China and Russia that don't impact most organizations, they want to know who's attacking and where they're from, what they're doing. And to be honest with you, that'…”
Opinion
D'Amato: Cyber attack attribution does not matter for private corporations
“And for most organizations, the attribution doesn't matter. For the government, it absolutely matters. But as a corporation, what will you be able to do? You're not going to be able to hack back that, that country.”
Assertion Not checkable as stated
D'Amato: Cyber attackers often understand target networks better than defenders
“Most organizations don't really understand their own organization, their environment, and that in many cases, attackers understand the environment much better than the defenders do.”
Assertion Not checkable as stated
D'Amato: Chief Security Officers commonly do not know their endpoint count
“When I asked them how many systems they had in their organization, how many endpoints they had, computers and servers and things like that, They had no idea. So that's pretty common.”
Assertion Not checkable as stated
D'Amato: Penetration testers breached top secure facilities in under two hours
“I'll be honest with you, I was not very good, but within about a week or less, I think my best was about two hours, we were able to break into some of the most secure locations in the world. Physically and Based on information technology.”
Insight
D'Amato: Integrity attacks are most devastating because they go undetected
“And integrity tends to be one of the most devastating attacks, because you typically don't know what's happened.”