APRIL - JUNE 2022CIOAPPLICATIONSEUROPE.COM9IT industry is plagued by this. This also impacted the application development process. Historically, we were able to overcome this by the ability to reuse or re-deploy code. The boom of use of open-source libraries is the best example here. I believe that such approach will be changed after recent events like log 4J or just one with NPM libraries. From an IT Security perspective, we need fully vested and trustful code at least for critical systems. That is why in the short term we should see some changes in a way how code will be re-tested and validated before the newer version is accepted. IT Security industry is looking now at Big Data processing and Artificial Intelligence to resolve complexity and resource challenges. This concept is sold as the "ultimate solution" for the industry. Currently, Artificial Intelligence technology gained adequate maturity that allows finding some practical applications. This happened due to a processing power increase. However, in my opinion, we are not there yet. Full process automatization is not possible and we are struggling to find a correct spot between seeing too much or too little due to lack of system calibration. Constant human supervision and action are still necessary. However, I have to admit the use of AI is on a good path here and will be present more and more as the preferred solution.Finally, the IT Security industry is and will be in a disadvantageous position. Our role is to make sure we are able to protect everything. For our opponents the objective is much easier find the weakest element. There is no easy solution available. To protect the commercial enterprise IT environment we should make it simple enough to achieve reasonable benefits of scale similar devices are by far easier to protect than trying to have an individual approach. At the same moment, we need to avoid the situation that the whole IT environment is compromised using one vulnerability present everywhere that is limit services to a minimum, keep a fast pace of patching. In a commercial environment, taking into account technological progress, there is no way to keep valid business offering using such limitations. More and more devices are being connected to the Internet (we should exceed 18 billion this year) enterprises also tend to clutter their internal network with them. Our users demand "smart" projectors, TVs, printers, thermometers, light controls,etc. This comes at cost of increased interconnectivity and environment complexity. The IT Security can always help here by supporting the implementation of such programs like Vulnerability Management, Zero-Trust, or just basically challenging the status quo by "red-team" exercises. However, this usually is not adequate in comparison to depict clearly needs to decision-makers. To summarize the future for IT Security will be challenging here and as an industry, we will be still struggling here as long as the pace of progress of the IT Industry and the possibilities of IT applications is increasing. To be honest, this is part of our job. Michal Niezurawski
<
Page 8 |
Page 10 >