Cybercrime has emerged as the default front-page article in various publications around the world. As a new enemy battling an unprepared army, a fire brigade approach is mostly employed by both public and private organizations worldwide to tackle its vices. Regulators in their attempt to manage cyber risk encourage and enforce compliance with various information security standards. Though their goals may be noble, this has pushed in the compliance-check-box mentality. What we now witness is that organizations are racing to get compliant as opposed to having a culture that promotes continuous improvement of their security processes.
In any crime, there has to be a perpetrator, a victim and an avenue that brings both the perpetrator and victim together. For example, a bank customer that gets robbed at an Automated Teller Machine (ATM), the victim is obviously the customer, the perpetrator is the person that steals from the bank customer while the avenue that brought them together is the ATM. For such a scenario one might blame the bank customer for not being security conscious especially if this happened at night. However, the flip side is, what if this is a recurring issue at this ATM point? I’m sure the bank responsible for providing the ATM needs to be questioned as well.
One would expect the bank to put certain measures in place such as have security guards, security cameras, proper lightning when it is dark and if possible have Police protecting the area in other to satisfy its customers going forward. The same should apply to cybercrime. There has to be a perpetrator, a victim and an avenue. For cybercrime, the avenue is usually the Internet. The anonymous and faceless nature of the Internet does not help in this regard as normal face-to-face interaction or physical evidence during regular crimes is often lost. The good news is that the Internet does not just appear; it is provided by an Internet Service Provider (ISP).
As Internet penetration increases and more businesses and social activities come online, Internet users would clamor for increased speed at reduced cost. A lot has been done is this regard; we have moved from the era of dial up modems to broadband connections. In some parts of Lagos, there are options to have fiber optics cables directly to people’s home from their ISPs. There is still a long way to go while we also try not to forget the several challenges of doing such a business in Nigeria. This won’t be discussed in this article rather what I hope to bring to bear is the role of ISPs in the cyber security landscape. ISPs have ample opportunities to contribute to cyber security improvements based on the advantage of their positioning in the Internet’s ecosystem.
Regulation is important, as we need to have an agile approach to cybersecurity, constantly updating our laws to both reflect and anticipate realistic threats. However, regulation may not be as fluid enough to tackle the onslaught of cyber security attacks and threats. This is where ISPs nationwide need to approach cybersecurity from a responsibility perspective. Regulation is usually too slow to create and implement in such a rapidly evolving world.
As at 2012, ISPs in the U.S. voluntarily committed to taking steps to combat three major cyber security threats, based on recommendations from their Federal Communications Commission (FCC) advisory committee. This included implementing measures to fight botnets, domain name fraud and Internet route hijacking. Also, Internet customers in the UK are prohibited from accessing a range of web sites by default, because they have their Internet access filtered by their ISPs. Categories of content blocked across the major ISPs range from Drugs, File sharing, Gambling, Pornography, Weapons, Criminal Skills to Hacking tools and techniques. It is worthy to note and stress that the mentioned examples were voluntary actions even though there have been a number of attempts to introduce legislation to move it onto a mandatory footing.


0 comments :
Post a Comment