{"id":11657,"date":"2015-03-13T08:58:06","date_gmt":"2015-03-13T15:58:06","guid":{"rendered":"http:\/\/www.enxmag.com\/twii\/?p=11657"},"modified":"2016-09-15T10:02:35","modified_gmt":"2016-09-15T17:02:35","slug":"logicnows-ian-trump-raises-awareness-for-the-new-breed-of-security-threats","status":"publish","type":"post","link":"https:\/\/www.enxmag.com\/twii\/the-week-in-imaging-twii\/security\/2015\/03\/logicnows-ian-trump-raises-awareness-for-the-new-breed-of-security-threats\/","title":{"rendered":"LogicNow\u2019s Ian Trump Raises Awareness for the New Breed of Security Threats"},"content":{"rendered":"<div id=\"attachment_11660\" style=\"width: 310px\" class=\"wp-caption alignleft\"><img aria-describedby=\"caption-attachment-11660\" loading=\"lazy\" class=\"size-medium wp-image-11660\" src=\"http:\/\/www.enxmag.com\/twii\/wp-content\/uploads\/2015\/03\/ian-trump-300x295.png\" alt=\"Ian Trump\" width=\"300\" height=\"295\" \/><p id=\"caption-attachment-11660\" class=\"wp-caption-text\">Ian Trump<\/p><\/div>\n<p>When you talk to Ian Trump, Security Lead at LogicNow, you\u2019re talking to someone who knows IT security inside and out. Trump is an ITIL (Information Technology Infrastructure Library) certified IT consultant with 20 years of experience in IT security and information technology. His experience on security integration projects, facilitating technological change, and promoting security best practices have been embraced and endorsed by his industry peers. As a result, when Trump speaks about security, people listen&#8230;or should. You know how that goes.<\/p>\n<p>Seeing how security is one of those hot topics within document imaging industry circles, I couldn\u2019t resist chatting with Trump when the opportunity was offered. In the interest of full disclosure, part of our conversation centered on LogicNow\u2019s security initiatives.<\/p>\n<p>He explains that LogicNow takes three approaches to security, starting with technology and a suite of products with a layered defense strategy against what he calls \u201ccyber bad guys.\u201d The second approach, which Trump describes as \u201crevolutionary,\u201d is partnering with one of LogicNow\u2019s managed services security providers to educate the MSP on how to sell security and compliance solutions.<\/p>\n<p>\u201cThis is unchartered territory in terms of the other platforms out there,\u201d emphasizes Trump. \u201cWe\u2019re seeing a need for MSPs to move up market and continue their success in the marketplace. This is important with the introduction of hosted services such as Office 365.\u201d<\/p>\n<p>He notes that MSPs made big money from servers, now servers are going away in favor of rented services located in data centers.<\/p>\n<p>Trump contends this is an opportune time for MSPs to branch out, especially with all the media coverage of security breaches that are raising awareness and scaring the heck out of the small and medium business where LogicNow\u2019s core product is focused. Actually, many of its products are focused on the SMB via the MSP channel.<\/p>\n<p>The third approach finds Trump in the role of security evangelist, addressing LogicNow\u2019s MSP community with educational materials and webinars as well as educating them as to what the various threats look like and what\u2019s coming, including pointing out some noteworthy trends.<\/p>\n<p>One of those trends is what Trump describes as \u201canother seminal moment in IT history.\u201d That\u2019s the end of life cycle of the 2003 server platform. \u201cHaving history as a guide, we saw what happened with Windows XP and where it went end of life cycle.\u201d<\/p>\n<p>He\u2019s referring to attacks on ATM machines and POS systems.<\/p>\n<p>\u201cI suspect the 12 million 2003 machines and other virtual machines from 2003 will come under cyber attack via a worm or targeted attack very shortly after the final patches are dropped,\u201d predicts Trump. \u201cThis is one of the biggest IT security issues for 2015. It\u2019s easily preventable and we\u2019ve created some white papers and videos as to what that looks like in terms of securing your infrastructure.\u201d<\/p>\n<p>Another trend that will impact IT security is the adoption of the Internet of Things. That\u2019s because many of those devices connected to the Internet can be considered insecure. Trump cites recent demos in the UK of a smart TV from Samsung that does not encrypt the voice recognition from itself and its third-party provider.<\/p>\n<p>\u201cThere\u2019s no encryption being used and there are many devices, including children\u2019s toys that are capable of being exploited by bad guys,\u201d cautions Trump. \u201cThis is a huge concern. The industry in its rush to put an IP address on virtually everything, including dishwashers and kettles has not absorbed the ramifications of that and the possible liability should hackers either flood your house or set your house on fire by hacking into the kettle or dishwasher. These attacks that two or three years ago we thought were ridiculous have now become more plausible as we\u2019ve seen wide-scale exploits that have been completely across platform.\u201d<\/p>\n<p>Examples of those are the Heartbleed virus and the FREAK bug.<\/p>\n<p>Complicating matters, or exacerbating the threat, is the growing adoption and implementation of wireless devices and wireless communication.<\/p>\n<p>\u201cBecause the Internet of Things will be a wireless implementation and this is problematic in putting a device that maybe has a cavalier attitude towards security on the same network you\u2019re doing your banking or the same network where you\u2019re working on confidential documents,\u201d states Trump. \u201cThe threat landscape for SMB is elevated by the sudden appearance of all these devices that are going to be dropped into the wireless environment, not to mention the spectrum problems and channel interference that\u2019s degrading the performance of folks\u2019 wireless. That\u2019s a huge concern and something we\u2019re going to see more of as more wireless devices are spooled up and more devices [communicate] wirelessly.\u201d<\/p>\n<p>A third trend to be vigilant about is the new Internet Protocol, IPv6. \u00a0\u201cIn the last 20-25 years we\u2019ve figured out how to do networking using IPv4,\u201d explains Trump. \u201cWe can secure networks comfortably using the techniques and tools we\u2019ve developed, including hardware platforms like firewalls to secure the IBP4 environment. IPv6 is going to get wide scale adoption pushed in part by the Internet of Things. This is a concern because the amount of knowledgeable people around IPv6 is very limited and the classroom environment for IPv6 is just starting to mature. Unfortunately, the hackers are going to take advantage of our lack of knowledge and rules in the IPv6 space.\u201d<\/p>\n<p>He explains that the initial introductions of those technologies will be quite expensive for SMBs and there\u2019s a concern the ISP may turn on or enable IPv6 without the knowledge of the business owner or MSP.<\/p>\n<p>\u201cAs a result under particular circumstances and type of hardware IPv6 will be transparent to a router or firewall that is an IPv4 device,\u201d adds Trump. \u201cThere are huge concerns on the security side as we move forward in 2015 driven in large part by the desire of companies to Internet enable almost everything they can possibly Internet enable.\u201d<\/p>\n<p>Even though there\u2019s plenty of cause for concern, Trump has some positive news as well.<\/p>\n<p>\u201cSecurity doesn\u2019t have to be expensive or complex,\u201d he says citing an Australian study regarding the various security options. \u201cNumber four is patching and updating your operating system and patching and updating third party applications\u2014these are the strongest defenses against these threats and exploits.\u201d<\/p>\n<p>Another ounce of prevention is aggressively preventing devices and\/or humans from visiting devices that are dangerous as well as something as obvious as updating one\u2019s anti-virus platform. \u201cIt\u2019s a good defense against known attacks,\u201d emphasizes Trump. \u201cIn the criminal underground most Trojans used now are known to anti-virus and their activity is fairly easy to detect by modern anti-virus platforms. Where it gets sticky is with the next generation of threats.\u201d<\/p>\n<p>Returning to a previous point and one also trumpeted by his LogicNow colleague Dave Sobel, Trump contends the MSP is in a unique position when it comes to security options because they understand their customer\u2019s business almost as well as the business itself. \u201cWhen knocked off line or out of service the MSP is the one who puts that business back in business after a hack,\u201d notes Trump.<\/p>\n<p>In closing, he offers some common sense advice for anyone selling security as part of their Managed IT offerings. \u201cWhen [a client] asks me what\u2019s the best firewall, my response is \u2018the one I know the best.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When you talk to Ian Trump, Security Lead at LogicNow, you\u2019re talking to someone who knows IT security inside and out. Trump is an ITIL (Information Technology Infrastructure Library) certified IT consultant with 20 years of experience in IT security and information technology. His experience on security integration projects, facilitating technological change, and promoting security best practices have been embraced and endorsed by his industry peers. As a result, when Trump speaks about security, people listen&#8230;or should. You know how that goes. Seeing how security is one of those hot topics within document imaging industry circles, I couldn\u2019t resist chatting with Trump when the opportunity was offered. In the interest of full disclosure, part of our conversation centered on LogicNow\u2019s security initiatives. He explains that LogicNow takes three approaches to security, starting with technology and a suite of products with a layered defense strategy against what he calls \u201ccyber bad guys.\u201d The second approach, which Trump describes as \u201crevolutionary,\u201d is partnering with one of LogicNow\u2019s managed services security providers to educate the MSP on how to sell security and compliance solutions. \u201cThis is unchartered territory in terms of the other platforms out there,\u201d emphasizes Trump. \u201cWe\u2019re seeing a need for MSPs to move up market and continue their success in the marketplace. This is important with the introduction of hosted services such as Office 365.\u201d He notes that MSPs made big money from servers, now servers are going away in favor of rented services located in data centers. Trump contends this is an opportune time for MSPs to branch out, especially with all the media coverage of security breaches that are raising awareness and scaring the heck out of the small and medium business where LogicNow\u2019s core product is focused. Actually, many of its products are focused on the SMB via the MSP channel. The third approach finds Trump in the role of security evangelist, addressing LogicNow\u2019s MSP community with educational materials and webinars as well as educating them as to what the various threats look like and what\u2019s coming, including pointing out some noteworthy trends. One of those trends is what Trump describes as \u201canother seminal moment in IT history.\u201d That\u2019s the end of life cycle of the 2003 server platform. \u201cHaving history as a guide, we saw what happened with Windows XP and where it went end of life cycle.\u201d He\u2019s referring to attacks on ATM machines and POS systems. \u201cI suspect the 12 million 2003 machines and other virtual machines from 2003 will come under cyber attack via a worm or targeted attack very shortly after the final patches are dropped,\u201d predicts Trump. \u201cThis is one of the biggest IT security issues for 2015. It\u2019s easily preventable and we\u2019ve created some white papers and videos as to what that looks like in terms of securing your infrastructure.\u201d Another trend that will impact IT security is the adoption of the Internet of Things. That\u2019s because many of those devices connected to the Internet can be considered insecure. Trump cites recent demos in the UK of a smart TV from Samsung that does not encrypt the voice recognition from itself and its third-party provider. \u201cThere\u2019s no encryption being used and there are many devices, including children\u2019s toys that are capable of being exploited by bad guys,\u201d cautions Trump. \u201cThis is a huge concern. The industry in its rush to put an IP address on virtually everything, including dishwashers and kettles has not absorbed the ramifications of that and the possible liability should hackers either flood your house or set your house on fire by hacking into the kettle or dishwasher. These attacks that two or three years ago we thought were ridiculous have now become more plausible as we\u2019ve seen wide-scale exploits that have been completely across platform.\u201d Examples of those are the Heartbleed virus and the FREAK bug. Complicating matters, or exacerbating the threat, is the growing adoption and implementation of wireless devices and wireless communication. \u201cBecause the Internet of Things will be a wireless implementation and this is problematic in putting a device that maybe has a cavalier attitude towards security on the same network you\u2019re doing your banking or the same network where you\u2019re working on confidential documents,\u201d states Trump. \u201cThe threat landscape for SMB is elevated by the sudden appearance of all these devices that are going to be dropped into the wireless environment, not to mention the spectrum problems and channel interference that\u2019s degrading the performance of folks\u2019 wireless. That\u2019s a huge concern and something we\u2019re going to see more of as more wireless devices are spooled up and more devices [communicate] wirelessly.\u201d A third trend to be vigilant about is the new Internet Protocol, IPv6. \u00a0\u201cIn the last 20-25 years we\u2019ve figured out how to do networking using IPv4,\u201d explains Trump. \u201cWe can secure networks comfortably using the techniques and tools we\u2019ve developed, including hardware platforms like firewalls to secure the IBP4 environment. IPv6 is going to get wide scale adoption pushed in part by the Internet of Things. This is a concern because the amount of knowledgeable people around IPv6 is very limited and the classroom environment for IPv6 is just starting to mature. Unfortunately, the hackers are going to take advantage of our lack of knowledge and rules in the IPv6 space.\u201d He explains that the initial introductions of those technologies will be quite expensive for SMBs and there\u2019s a concern the ISP may turn on or enable IPv6 without the knowledge of the business owner or MSP. \u201cAs a result under particular circumstances and type of hardware IPv6 will be transparent to a router or firewall that is an IPv4 device,\u201d adds Trump. \u201cThere are huge concerns on the security side as we move forward in 2015 driven in large part by the desire of companies to Internet enable almost everything they can possibly Internet enable.\u201d Even though there\u2019s plenty of cause for concern, Trump has some positive news as well. \u201cSecurity doesn\u2019t have to be expensive or complex,\u201d he [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":11660,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[88,1638],"tags":[1805,2131,2132],"_links":{"self":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/11657"}],"collection":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/comments?post=11657"}],"version-history":[{"count":4,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/11657\/revisions"}],"predecessor-version":[{"id":11663,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/posts\/11657\/revisions\/11663"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media\/11660"}],"wp:attachment":[{"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/media?parent=11657"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/categories?post=11657"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.enxmag.com\/twii\/wp-json\/wp\/v2\/tags?post=11657"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}