Las Vegas Review-Journal (Sunday)

The Black Hat cybersecur­ity conference expects record attendance in Las Vegas.

Cybersecur­ity conference expects record attendance in LV

- By Todd Prince

Black Hat USA, the largest annual cybersecur­ity conference, is expecting record attendance in Las Vegas this week as high-profile breaches and election meddling fears dominate headlines.

More than 17,000 cybersecur­ity profession­als from government, academia and the private sector are expected to turn out for the six-day show to attend some of the 80 training sessions and 120 briefings on offer. The show has nearly doubled in size since 2014.

“Security has become mainstream. It really has its hands in everything these days,” said Steve Wylie, the general manager of the show. “Companies are having to send more and more people to get training” as threats grow, he said.

The show kicked off Saturday at the Mandalay Bay Convention Center and wraps up Thursday.

Black Hat will feature 300 exhibitors, such as Cisco Systems, offering a range of services and products to protect networks or detect, identify and respond to breaches. Cisco announced Aug. 2 it will buy Duo Security for

$2.4 billion, at least the company’s fourth acquisitio­n of a cybersecur­ity firm since 2013.

Show attendees represent

some of the largest companies in the U.S., including JPMorgan Chase, Blue Cross Blue Shield, Amazon, Nike, AT&T and Exxon Mobil, underscori­ng the ever-growing importance of security to all industries.

Show highlights

The first four days of Black Hat are dedicated to training sessions that focus on topics such as advanced hacking techniques, social engineerin­g and cloud security to give employees the tools to better protect their companies and organizati­ons.

The last two days of the show consist of briefings dedicated to a wide range of current issues. Election hacking will be a hot topic again this year along with critical infrastruc­ture vulnerabil­ity, Wylie said.

A Black Hat survey of cybersecur­ity profession­als published in June showed that nearly 70 percent now expect a successful attack against critical infrastruc­ture, up from 60 percent last year.

Carsten Schuermann, a professor at the University of Copenhagen, will deliver a briefing Thursday on the vulnerabil­ities of the voting machines used extensivel­y in Virginia elections during 2004 and 2015.

Other briefings will focus on hacking connected cars, cash machines and implanted medical devices.

Job shortage

Black Hat will occupy more space at the Mandalay Bay this year as the show grows alongside the industry, Wylie said.

But the breakneck growth is causing a severe industry labor shortage, security specialist­s said. Some companies and organizati­ons, like the FBI, come to Black Hat in part to recruit.

There are currently about 250,000 jobs openings in cybersecur­ity around the U.S., according to Sam Olyaei, principal research analyst at Gartner Inc., a global research and advisory firm.

While that is down by half since 2016, the global shortage is forecast to balloon. Olyaei said the industry now expects there will be more than 3 million unfilled cybersecur­ity jobs globally by 2021, up from an earlier forecast of 1.4 million.

“The demand for cybersecur­ity specialist­s is insane. [The country] cannot produce enough to meet the demand,’’ said Giovanni Vigna, the chief technology officer of Lastline, a company that provides network and email security products to detect and fight cyberattac­ks.

Lastline, which will be exhibiting at Black Hat, has nearly doubled its head count to about 140 over the past year amid growing demand for its products.

Vigna, who also serves as the director of the Center for Cybersecur­ity at the University of California, said he recruits from the university as well as at hacking competitio­ns.

Olyaei said companies too often search for cybersecur­ity profession­als with a certain skill set, such as knowledge of specific malware tools that may become obsolete in a few years.

They should widen their search to include people not just with strong technical skill sets but also with business background­s so they can understand the security needs of an organizati­on, he said.

Vigna said other companies have been looking at machine learning and artificial intelligen­ce to combat cyberattac­ks while simultaneo­usly reducing their demand for security personnel. However, the technology hasn’t matured to that level.

“People are starting to understand that it’s not a silver bullet,” Vigna said.

Inevitable

Facebook, footwear maker Under Armour, bakery chain Panera Bread and marketing firm Exactis are among the U.S. companies that have announced major data breaches in the last few months. Breaches can cost large companies tens of millions of dollars in lost business and lawsuits.

That has driven companies and organizati­ons across the board to spend more on cybersecur­ity and enhance employee training. Zion Market Research earlier this year forecast cybersecur­ity firms will generate annual revenue of $187 billion in 2021, nearly double the amount for 2015.

Companies have historical­ly spent the overwhelmi­ng majority of their cybersecur­ity investment on protection tools, such as firewalls and anti-virus software.

However, over the past few years they have shifted more toward breach detection and response as they come to realize the odds of stopping every attack is slim, Olyaei said.

“You will be breached. There is no such thing as perfect protection,” he said, describing a breach as inevitable as death.

His blunt comment was supported in a survey published in July by Osterman Research that showed U.S. companies and organizati­ons face a “major” attack on average every 6.7 months.

Phishing — the act of soliciting personal informatio­n often through emails purporting to be from a trustworth­y sender — continues to be the most common type of attack against organizati­ons followed by spyware and ransomware infections, according to Osterman.

 ?? Richard Brian Las Vegas Review-Journal @vegasphoto­graph ?? Attendees check their devices during the 2017 Black Hat informatio­n security conference at Mandalay Bay. This year’s conference started Saturday.
Richard Brian Las Vegas Review-Journal @vegasphoto­graph Attendees check their devices during the 2017 Black Hat informatio­n security conference at Mandalay Bay. This year’s conference started Saturday.
 ?? Mark Schiefelbe­in The Associated Press file ?? Visitors stand in front of an electronic data display showing a map of China in April at the Global Mobile Internet conference in Beijing.
Mark Schiefelbe­in The Associated Press file Visitors stand in front of an electronic data display showing a map of China in April at the Global Mobile Internet conference in Beijing.

Newspapers in English

Newspapers from United States