enterprisesecuritymag

A featured contribution from Leadership Perspectives, a curated forum for enterprise security leaders, nominated by our subscribers and vetted by the Enterprise Security Magazine Editorial Board.

Leonardo

Invisible Enemies on the Rise

Germano Matteuzzi, Head of Cyber Security Competence Center – Delivery, Leonardo

Germano Matteuzzi serves as the Head of Cyber Security & Digital Centre- Sales technical Support, Leonardo Cyber Security Division. He is a Graduate in Information Engineering and with an University Master in Cyber Security, both in “La Sapienza” – Rome, member of International Cyber Security Organizations (ISACA, ISC2) with relevant Cyber Security Certifications, CISA, CISSP, CISM, CRISC, CDPSE. More than 20 years of working experience in ICT, focusing on SW Engineering, System Engineering and Network Management, 13 years of Cyber Security working experience. Working in Leonardo, since 2009, previously in a Telco company, currently Head of Cyber Security & Digital Centre- Sales technical Support, in the Cyber Security Division of Leonardo, formerly responsible for the Cyber Security Presales unit.

Cyber Information Superiority is the technological suite designed by Leonardo to increase analysis and intelligence capabilities and allow institutions, companies, and critical infrastructures access to information that can be immediately used to prevent threats and implement rapid actions of defence and containment of attacks. Cyber Information Superiority allows for management of structured intelligence activities, analyzing threats in a global and detailed way while simultaneously orchestrating the various technologies necessary to anticipate threats and detect an attack before it spreads into the IT / OT infrastructure.

● What are some of the major challenges and trends that are impacting the “Cyber information Superiority” space lately?

The security and sovereignty of countries and international institutions are increasingly threatened by cyber-attacks that aim to undermine essential services for social and economic ecosystems, such as public administration, banks, energy, transport, and communications. Whether the reasons are of state, paramilitary organizations or groups acting for profit – espionage or ideal – these attacks can considerably impact the real life of citizens. They are perpetrated by increasingly organized groups with growing economic and technological resources. Invisible enemies, who often hide under different identities, with our only strategic advantage being knowledge.

● What keeps you up at night when it comes to some of the major predicaments in cyber security space?

Cyber-physical attacks are becoming bigger threats, as the digitalization and Internet of Things expand. These attacks are not only conceived to steal information or disabling it, but to take control over physical objects with real physical consequences. These attacks are mainly directed against civil or military infrastructures, which are more exposed to cyber-attacks than in the past due to the advent of digital transformation and Internet of Thing.

"The Security and Sovereignty of Countries and International Institutions are Increasingly Threatened by Cyber-Attacks that Aim to Undermine Essential Services for Social and Economic Ecosystems, Such as Public Administration, Banks, Energy, Transport, and Communications"

Some recent examples could be the attack on a water treatment plant in Florida in 2021 and the attack to the Health Service Executive (HSE) of Ireland, which suffered a major ransomware cyberattack, causing all of its IT systems nationwide to be shut down. 80 percent of the HSE IT environment was encrypted, severely disrupting healthcare services throughout the country.

● Can you tell us about the latest product that you have been working on and what are some of the technological and process elements that you leveraged to make this product successful?

The suite consists of three modules: the first is the Leonardo's threat intelligence system, which uses a dedicated high[1]performance computer capable of 500,000 billion operations per second, automatically analyzing over 4.7 million indicators of compromise every year (digital traces of IT incidents), the huge amount of data from social media (SOCMINT), and open sources (OSINT) including websites and media, databases, or public reports, photographic images, or satellite data. The result is real profiling of threats, potential victims and the most fearsome malevolent actors, summarized in over 8,500 annual reports shared within the intelligence analyst community.

● Which are some of the technological trends, which excite you for the future of the Cyber Information Superiority product?

The growing digitization and massive use of smart devices, sensors, and IT or IoT applications has increased the number of terminals like servers and workstations, the so-called endpoints, which are the gateway to attacks. To identify the threat and detect intrusions in a timely manner, it is essential to have a system that analyses not only what happens outside an organization, but also inside it. This is the goal of the second module of the Leonardo suite, called LENS, which studies the behaviour of endpoints in search of cyber security violations and, once an anomaly has been identified, immediately implements response actions, automatically or supported by analysts.

The malware detected by LENS is then analysed by ARGO, a platform developed by Leonardo making it possible to “detonate” malicious software in a virtual operating environment isolated from the network and the protected information system – and not exposed to risks. It is possible to analyse the behaviour of malware, complementing the results of the investigations carried out by other modules of Leonardo's Cyber Information Superiority suite, updating both the threat archive and procedures and activities for endpoint security.

● How can budding and evolving companies reach you for suggestions to streamline their business?

We design and develop Security Strategy & Governance and Cyber Resilience for Governments, Critical National Infrastructures and strategic industries through consulting services and the design of on-premise cyber security and intelligence solutions. Having more than 25 years’ experience in cyber security, we draw on a dedicated organisation, a consolidated approach and constant investment in resources and technology, we provide public and private organisations with a comprehensive security strategy and solutions covering organisational, technological and compliance issues. Moreover, Leonardo has recently launched the Leonardo’s Cyber & Security Academy to enable institutions, companies and organisations responsible for critical infrastructure to train and certify their teams on security issues, at technological, regulatory, methodological and process levels, providing the tools to promote a secure digital transition and contributing to the wider spread of a culture of security.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.