<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Banks told to attack themselves in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41590#M5155</link>
    <description>&lt;P&gt;So Rob, I disagree with you in general.&amp;nbsp; I believe there is a huge difference in banks and their relationships.&amp;nbsp; Why do I day this:&amp;nbsp; Canada and the US have diversely different banking rules/regs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;see:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.visualcapitalist.com/canada-u-s-banking-differences/" target="_blank"&gt;https://www.visualcapitalist.com/canada-u-s-banking-differences/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the US, banks may well be incestuous (with 7000 different banks, it is inevitable).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The concept of attacking one's own organization is not new (hence why we have penetration testing companies and CEH.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem with self testing is getting management to buy into it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not wild about using Universities/hackatons to do the testing but it is an option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will be interesting to see how this all flushes out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Dec 2020 23:10:55 GMT</pubDate>
    <dc:creator>dcontesti</dc:creator>
    <dc:date>2020-12-11T23:10:55Z</dc:date>
    <item>
      <title>Banks told to attack themselves</title>
      <link>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41561#M5144</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now this is an interesting strategy from Australia, which will probably creep into New Zealand as well, given that Australian Banks control New Zealand ones - but due to the APRA and BS11 regulations they have to work independently and be up and running with 6 hours to ensure that financial transactions keep going.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.afr.com/companies/financial-services/banks-ordered-to-simulate-cyber-attacks-20201209-p56lun#:~:text=Banks%20have%20been%20ordered%20to,against%20institutions%20to%20expose%20weaknesses" target="_blank"&gt;https://www.afr.com/companies/financial-services/banks-ordered-to-simulate-cyber-attacks-20201209-p56lun#:~:text=Banks%20have%20been%20ordered%20to,against%20institutions%20to%20expose%20weaknesses&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a). Someone is going to make a regular monetary sum out of this, unless they do it internally&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;b) How to ensure objectivity and rotation to ensure that they don't get into a group think situation or attempt to repeat the results from the previous test and find a subsequent compromise which then comes under investigation and vast penalties.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;c). Use it as a training opportunity for Universities, and Hackathons to see what they can?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:43:41 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41561#M5144</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-10-09T09:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: Banks told to attack themselves</title>
      <link>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41577#M5148</link>
      <description>&lt;P&gt;Much like my rules for auditing, I don't want to see the same person more than once every two years, nor do I want to see the same testing regimen used over and over again. I have no idea how large, small or incestuous the New Zealand/Australian banking industry is by size or business relationship may be. Putting good starting rules and controls shouldn't be a high hurdle to cross here provided you have a third party bank or regulator overseeing the audit process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are able to successfully self regulate you need to be able to prove your good works to the public by self-certifying the results and publicizing the redacted or cleaned up results for public inspection. Hiding the results will only make you appear to be hiding something and we already have enough of that. Explanation of the results should be simple and complete enough for the public to understand but not a roadmap as to how to compromise the institution your trying to protect. Yes, its tricky to pull off but that's why we have lots of smart people in the room.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for outside hack-a-thons and what not goes. Having worked for major US banks as both an auditor and architect means seeing any real hacking attempts are not made by college level students, not without substantial assistance as much banking losses are due to fraud and fraudulent wire transfers not direct hacking. Perhaps its different outside of the US as I have no foreign banking experience.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Good luck with the solution.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- b/eads&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 15:28:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41577#M5148</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2020-12-11T15:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: Banks told to attack themselves</title>
      <link>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41584#M5153</link>
      <description>&lt;P&gt;&amp;gt; Beads (Advocate I) posted a new reply in Industry News on 12-11-2020 10:28 AM in the (ISC)Â² Community :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;gt; I have no idea how large, small or incestuous the&lt;BR /&gt;&amp;gt; New Zealand/Australian banking industry is by size or business relationship&lt;BR /&gt;&amp;gt; may be.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As far as I can tell, pretty much all of the banking industry is fairly incestuous ...&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 18:25:50 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41584#M5153</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-12-11T18:25:50Z</dc:date>
    </item>
    <item>
      <title>Re: Banks told to attack themselves</title>
      <link>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41588#M5154</link>
      <description>&lt;P&gt;M &amp;amp; A has a tendency to do that, yeah. Since I am only familiar with the US side I thought I'd bring it up for comment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- b/eads&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 21:38:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41588#M5154</guid>
      <dc:creator>Beads</dc:creator>
      <dc:date>2020-12-11T21:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Banks told to attack themselves</title>
      <link>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41590#M5155</link>
      <description>&lt;P&gt;So Rob, I disagree with you in general.&amp;nbsp; I believe there is a huge difference in banks and their relationships.&amp;nbsp; Why do I day this:&amp;nbsp; Canada and the US have diversely different banking rules/regs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;see:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.visualcapitalist.com/canada-u-s-banking-differences/" target="_blank"&gt;https://www.visualcapitalist.com/canada-u-s-banking-differences/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the US, banks may well be incestuous (with 7000 different banks, it is inevitable).&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The concept of attacking one's own organization is not new (hence why we have penetration testing companies and CEH.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem with self testing is getting management to buy into it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not wild about using Universities/hackatons to do the testing but it is an option.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Will be interesting to see how this all flushes out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 23:10:55 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41590#M5155</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2020-12-11T23:10:55Z</dc:date>
    </item>
    <item>
      <title>Re: Banks told to attack themselves</title>
      <link>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41601#M5157</link>
      <description>&amp;gt; dcontesti (Community Champion) posted a new reply in Industry News on 12-11-2020 06:10 PM in the (ISC)Â² Community :&lt;BR /&gt;&lt;BR /&gt;&amp;gt; So Rob, I disagree with you in general.&lt;BR /&gt;&lt;BR /&gt;So what else is new? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I believe there is a huge difference in banks and their relationships.&amp;nbsp; Why&lt;BR /&gt;&amp;gt; do I day this:&amp;nbsp; Canada and the US have diversely different banking&lt;BR /&gt;&amp;gt; rules/regs.&lt;BR /&gt;&lt;BR /&gt;Well, I'm not talking about regs (or even mergers and acquisitions, Brent), I'm&lt;BR /&gt;talking more about actual incest. (I'm rather amazed we've been able to talk about&lt;BR /&gt;this for all this time without falling afoul of the dreaded "community" pr0n filter.)&lt;BR /&gt;Banks tend to try and keep social interactions within the bank, or the bank&lt;BR /&gt;community. I assume this is kind of an attempt to deal with insider attacks: keep&lt;BR /&gt;your enemies really, really, really close and they won't be able to do anything.&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@gmail.com rmslade@outlook.com rslade@computercrime.org&lt;BR /&gt;has/bin: The proper term for out-of-date software on Unix/Linux&lt;BR /&gt;systems -&lt;A href="https://twitter.com/SecurityHumor/status/552175603374637056" target="_blank"&gt;https://twitter.com/SecurityHumor/status/552175603374637056&lt;/A&gt;&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413" target="_blank"&gt;https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413&lt;/A&gt;</description>
      <pubDate>Sat, 12 Dec 2020 18:52:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41601#M5157</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-12-12T18:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: Banks told to attack themselves ( (ISC)Â² Community Subscription Update)</title>
      <link>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41602#M5158</link>
      <description>(And, Diana, of course I kid because I know you can take it, and are one of the&lt;BR /&gt;people whose posts I do take seriously &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@gmail.com rmslade@outlook.com rslade@computercrime.org&lt;BR /&gt;Once you were a child. Once you knew what inquiry was for.&lt;BR /&gt;There was a time when you asked questions because you wanted&lt;BR /&gt;answers and were glad when you had found them. Become that child&lt;BR /&gt;again: even now. - C. S. Lewis, `The Great Divorce'&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413" target="_blank"&gt;https://community.isc2.org/t5/forums/recentpostspage/user-id/1324864413&lt;/A&gt;</description>
      <pubDate>Sat, 12 Dec 2020 18:55:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41602#M5158</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2020-12-12T18:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: Banks told to attack themselves ( (ISC)Â² Community Subscription Update)</title>
      <link>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41606#M5160</link>
      <description>&lt;P&gt;Rob,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know you jest....never worry there.....I will always push back&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;d&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2020 19:53:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Banks-told-to-attack-themselves/m-p/41606#M5160</guid>
      <dc:creator>dcontesti</dc:creator>
      <dc:date>2020-12-12T19:53:57Z</dc:date>
    </item>
  </channel>
</rss>

