In-depth

Why the FUD around APT does more harm than good

Davey Winder calls on the security industry to stop using scare tactics, and start using education, in the fight against APTs

OPINION: ISACA, which used to be known as the Information Systems Audit and Control Association, published a report last week that sheds some interesting light on another acronym which annoys the hell out of me. And that is APT, which stands for either Advanced Persistent Threat or Absurdly Pointless Terminology depending on whether you are selling something or not.

The term APT is often flagged by vendors as some kind of bogeyman problem to scare you into buying the solution. It reminds me, more often than not, of a salesmen shouting 'FIRE! FIRE!' through your letterbox before embarking on a sales pitch for fire extinguishers.

ISACA isn't selling anything in particular, so I read the report. What I discovered was that 1 in 5 enterprises had experienced an APT attack and two thirds are scared enough to think it's only a matter of time before they are attacked this way.

It reminds me, more often than not, of a salesmen shouting 'FIRE! FIRE!' through your letterbox before embarking on a sales pitch for fire extinguishers.

Unsurprisingly, only 15 per cent thought they were prepared to defend themselves against one.

I am not surprised by this lack of preparation, simply because the hype surrounding APT is so rife that confusion rules the roost.

That confusion results in 40 per cent of the enterprises questioned in that survey not using security training and controls to defend themselves against this kind of stealthy and ongoing threat, and 70 per cent not using mobile controls despite this being a preferred route to kick-start such attacks.

I'm not arguing that vendors, or anyone else for that matter, should stop spreading the word about any type of threat to enterprise data but I am dead set against FUD being used to sell stuff rather than a focus on education. So here's a thought, and one that will probably get me kicked off a few more vendor lunch invite lists (like I care.)

It's time to focus more on education and less on the hard sell. Concentrate on ensuring your customers understand the basics of data security, really understand I mean, and the FUD surrounding APTs will start to melt away.

So if users know how to spot and deal with phishing (even persistent phishing) via email, social media or text message, then many APT attacks will go nowhere, slowly.

Featured Resources

Key considerations for implementing secure telework at scale

Identifying the security risks and advanced requirements of a remote workforce

Download now

The State of Salesforce 2020

Your guide to getting the most from Salesforce

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Rethink your cybersecurity strategy for the new world

5 steps to secure the enterprise and be fit for a flexible future

Download now

Recommended

Russia hacked Liam Fox's personal email to steal trade documents
phishing

Russia hacked Liam Fox's personal email to steal trade documents

4 Aug 2020
British teenager charged over Twitter hack
hacking

British teenager charged over Twitter hack

3 Aug 2020
Mid-year report says vulnerabilities up 22% in 2020
hacking

Mid-year report says vulnerabilities up 22% in 2020

30 Jul 2020
BlackRock banking Trojan targets Android apps
trojans

BlackRock banking Trojan targets Android apps

27 Jul 2020

Most Popular

How to find RAM speed, size and type
Laptops

How to find RAM speed, size and type

3 Aug 2020
How to use Chromecast without Wi-Fi
Mobile

How to use Chromecast without Wi-Fi

4 Aug 2020
How do I fix the Windows 10 Start Menu if it's frozen?
operating systems

How do I fix the Windows 10 Start Menu if it's frozen?

3 Aug 2020