<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:dc="https://purl.org/dc/elements/1.1/"
     xmlns:dcterms="http://purl.org/dc/terms/"
     xmlns:media="http://search.yahoo.com/mrss/"
     xmlns:atom="http://www.w3.org/2005/Atom"
>
    <channel>
                    <atom:link href="https://www.nexttv.com/feeds/tag/network-security" rel="self" type="application/rss+xml" />
                            <title><![CDATA[ Latest from Next TV in Network-security ]]></title>
                <link>https://www.nexttv.com/tag/network-security</link>
        <description><![CDATA[ All the latest network-security content from the Next TV team ]]></description>
                                    <lastBuildDate>Tue, 21 Sep 2021 20:45:38 +0000</lastBuildDate>
                            <language>en</language>
                                <item>
                                                            <title><![CDATA[ Tech Groups Have Issues with FCC Device Security Proposals ]]></title>
                                                                                                                                                                                                <link>https://www.nexttv.com/news/tech-groups-have-issues-with-fcc-device-security-proposals</link>
                                                                            <description>
                            <![CDATA[ Say it is unclear commission has the authority to shift focus of reviews ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">Hr85DvcpDWGF5FQD6nB3wL</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/9Ghdiv2tScXVbKFSJ2qXM7-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Tue, 21 Sep 2021 20:45:38 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy]]></category>
                                                                                                <author><![CDATA[ john.eggerton@futurenet.com (John Eggerton) ]]></author>                    <dc:creator><![CDATA[ John Eggerton ]]></dc:creator>                                                                <dc:description><![CDATA[ http://cdn.mos.cms.futurecdn.net/ETjt8sjZcQr97v7yakQ4hP.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/9Ghdiv2tScXVbKFSJ2qXM7-1280-80.jpg">
                                                            <media:credit><![CDATA[Cavan Images via Getty Images]]></media:credit>
                                                                                                                                                                                                                                    <media:description><![CDATA[A child streams content on his phone while wearing headphones.]]></media:description>                                                            <media:text><![CDATA[A child streams content on his phone while wearing headphones.]]></media:text>
                                <media:title type="plain"><![CDATA[A child streams content on his phone while wearing headphones.]]></media:title>
                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/9Ghdiv2tScXVbKFSJ2qXM7-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>Technology industry groups are warning the <a href="https://www.nexttv.com/tag/fcc"><u>Federal Communications Commission</u></a> to exercise regulatory caution when changing its <a href="https://www.nexttv.com/news/fcc-poised-to-approve-pre-sales-marketing-of-tech-devices">device authorization process</a> in the name of <a href="https://www.nexttv.com/news/fcc-takes-next-steps-toward-network-security">network security</a>.</p><p><a href="https://www.nexttv.com/news/secure-networks-act-passes-senate"><u>Also Read: Secure Networks Act Passes Senate</u></a></p><p>In a notice of inquiry (NOI) and notice of proposed rulemaking (NPRM), the FCC is contemplating changes to its equipment authorizations for phones, computers and other devices that tap into FCC-regulated spectrum in its ongoing effort to better protect the network supply chain from national security threats.</p><p>Eight industry groups signed onto two letters to the commission targeting the NOI and NPRM. They included the Consumer Technology Association, CTIA–The Wireless Association, USTelecom and the Information Technology Industry Council (ITI).</p><p>While the signatories all said they supported protecting the supply chain against “foreign adversaries and nation-states,” the trade groups said the FCC effort raises a number of legal and implementation questions. It also raises the specter of unintended consequences the FCC should consider carefully before taking any action, the groups said.</p><p>The groups are particularly concerned about the FCC’s revocation of existing authorizations for equipment that may be in consumers’ homes or offices, or incorporated into other equipment.</p><p>“Devices sold at retail may be difficult or impossible to locate, and if a device has been incorporated into other equipment a replacement may require new engineering, testing, validation and manufacture,” the letter said. </p><p>The technology groups also have issues with the proposed criteria for evaluating suspect devices according to their country of origin, rather than the technology used. Historically the FCC’s authorizations have been based on technology and not, for example, <a href="https://www.nexttv.com/news/fcc-labels-five-chinese-tech-companies-security-risks"><u>whether a device came from China</u></a>. The groups said the FCC&apos;s legal authority to conduct this new type of review is unclear.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ Network Security Act Passes House ]]></title>
                                                                                                                                                                                                <link>https://www.nexttv.com/news/network-security-act-passes-house</link>
                                                                            <description>
                            <![CDATA[ Network Security Act Passes House ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">qDvBNz7tR5MGJcQf9ZfsM1</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/ZArz5V44GS2CFJKCAjJUdD-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 16 Dec 2019 21:49:48 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Policy]]></category>
                                                                                                <author><![CDATA[ john.eggerton@futurenet.com (John Eggerton) ]]></author>                    <dc:creator><![CDATA[ John Eggerton ]]></dc:creator>                                                                <dc:description><![CDATA[ http://cdn.mos.cms.futurecdn.net/ETjt8sjZcQr97v7yakQ4hP.jpg ]]></dc:description>
                                                                                                                                                                                                                                                <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/ZArz5V44GS2CFJKCAjJUdD-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/ZArz5V44GS2CFJKCAjJUdD-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <p>The Secure and Trusted Communications Networks Act (HR 4998) has passed the House by voice vote, according to the legislators who backed the bill. </p><p>It must still pass the Senate and be signed by the President.  </p><p>Related: Commerce Releases Suspect Tech Vetting Framework </p><p>Among other things, the bill would make at least $1 billion available for ripping and replacing suspect tech from existing networks. </p><p>The bill "prohibits the use of federal funds to purchase communications equipment or services from any company that poses a national security risk to American communications networks." (Funds for federal contracts are already barred from being used on Huawei and other allegedly suspect tech.)</p><p><a href="https://www.nexttv.com/news/huawei-scrubbing-5g-bill-introduced" data-original-url="https://www.multichannel.com/news/huawei-scrubbing-5g-bill-introduced">Related: Huawei-Scrubbing 5G Bill introduced </a></p><p>The FCC has already voted to exclude suspect tech from its Universal Service Fund broadband subsidy program and sought input on how to reimburse the smaller carriers who tend to purchase suspect tech because of the cost of the subsidized products and whether it should extend the prohibition beyond the USF fund to other networks. </p><p>Congress definitely wants the FCC to look beyond. The bill would require network providers to submit an annual report to the FCC on whether it had "purchased, rented, leased, or otherwise obtained" equipment from suspect tech providers.  </p><p>The bill specifically: </p><p>1. "Prohibits the use of federal funds, administered by the Federal Communications Commission (FCC), to purchase communications equipment or services from any company that poses a national security risk to American communications networks;</p><p>2. "Requires the FCC to establish the Secure and Trusted Communications Reimbursement Program to assist small communications providers with the costs of removing prohibited equipment or services from their networks and replacing the prohibited equipment with more secure communications equipment or services; and</p><p>3. "Helps the Federal government better share supply chain security information with carriers, particularly smaller carriers, to help keep this equipment out of our networks in the future." </p><p>“Securing our networks from malicious foreign interference is critical to America’s wireless future," said House Energy & Commerce Chairman Frank Pallone (D-N.J.), ranking member Greg Walden (R-Ore.), and Reps. Doris Matsui (D-Calif.) and Brett Guthrie (R-Ky.) in a joint statement. "Companies like Huawei and its affiliates pose a significant threat to America’s commercial and security interests because a lot of communications providers rely heavily on their equipment. This bipartisan legislation will protect our nation’s communications networks from foreign adversaries, and help small and rural providers remove and replace suspect network equipment. We look forward to swift action in the Senate so we can send this bill to the President’s desk and protect our national security,” the leaders said. </p><p>The FCC had no comment at press time on how much the bill differed from what it had already established in the order voted out unanimously last month.</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
                                <item>
                                                            <title><![CDATA[ As Cyber-Attacks Grow, So Do Defenses ]]></title>
                                                                                                                                                                                                <link>https://www.nexttv.com/news/cyber-attacks-grow-so-do-defenses-406381</link>
                                                                            <description>
                            <![CDATA[ As Cyber-Attacks Grow, So Do Defenses ]]>
                                                                                                            </description>
                                                                                                                                <guid isPermaLink="false">4HCagWkAQr3RowJRvcE1Tj</guid>
                                                                                                <enclosure url="https://cdn.mos.cms.futurecdn.net/SScHf3Ec8f3Ro9itREqTPV-1280-80.jpg" type="image/jpeg" length="0"></enclosure>
                                                                        <pubDate>Mon, 18 Jul 2016 12:00:00 +0000</pubDate>                                                                                                                                                                                                                                <category><![CDATA[Technology]]></category>
                                                    <category><![CDATA[Business]]></category>
                                                    <category><![CDATA[Distribution]]></category>
                                                                                                                    <dc:creator><![CDATA[ Craig Kuhl, Contributing Writer ]]></dc:creator>                                                                                                                                                                                                                                                                    <media:content type="image/jpeg" url="https://cdn.mos.cms.futurecdn.net/SScHf3Ec8f3Ro9itREqTPV-1280-80.jpg">
                                                            <media:credit><![CDATA[null]]></media:credit>
                                                                                                                                                                                                                                                                                                                                                    </media:content>
                                                    <media:thumbnail url="https://cdn.mos.cms.futurecdn.net/SScHf3Ec8f3Ro9itREqTPV-1280-80.jpg" />
                                                                                                                                                                    <content:encoded >
                            <![CDATA[
                            <article>
                                <figure class="van-image-figure pull-" data-bordeaux-image-check ><div class='image-full-width-wrapper'><div class='image-widthsetter' ><p class="vanilla-image-block" style="padding-top:56.25%;"><img id="SScHf3Ec8f3Ro9itREqTPV" name="" alt="" src="https://cdn.mos.cms.futurecdn.net/SScHf3Ec8f3Ro9itREqTPV.jpg" mos="https://cdn.mos.cms.futurecdn.net/SScHf3Ec8f3Ro9itREqTPV.jpg" align="" fullscreen="" width="" height="" attribution="" endorsement="" class="pull-"></p></div></div></figure><p>Few companies in the cable and telecommunications industries have escaped the cyber attacks that continue to wreak havoc on just about every layer of the supply chain.</p><p>Varying degrees of security breaches at Comcast, Cox Communications, Time Warner Cable and other cable providers have raised the red flag in the cybersecurity space and prompted a new mantra: Now is the time to raise the level of security.</p><p>“A fundamental evolution is taking place and the security implications are numerous,” Michela Menting, research director at consulting firm ABI Research, said. “Above all are the issues raised by the transition to all-[Internet protocol] networks, which are already highly exploited by threat actors and will be a boon for malicious cyber-agents — and all sectors are vulnerable.</p><p>“Investment in security services and corresponding hardware and software is not something they can ignore or put off , except at great cost to their services, reputation and client base,” she said.</p><p>Cybersecurity concerns have become so paramount that in its Charter Communications-Time Warner Cable merger order, the Federal Communications Commission required Charter to submit a plan to manage its increasing security risks during the transition.</p><p>And according to the Hewlett Packard Enterprise/Ponemon Institue “2015 Cost of Cyber Crime” study, hacking attacks cost U.S. firms, on average, some $15.4 million a year. Globally, U.K. insurance firm Lloyds estimates that cyber-attacks are costing businesses a staggering $400 billion a year.</p><p>There’s also the shaken confidence of clients and subscribers about the safety of their data. And not everyone is convinced the cable industry is prepared for any attacks.</p><p>“Cable networks are archaic in many respects, as they extend the life of existing systems, and frankly, the security posture of networks and the less time spent on security leads to a lot of holes,” Chris Simkins, CEO and co-founder of supply chain analysis and risk management firm Chain Security, said.</p><p>PricewaterhouseCoopers (PwC), a consultancy moving deeper into the cybersecurity space, believes cable companies are getting the message that shoring up their networks should be of the highest priority.</p><p>“There’s a lot going on with MSOs and we’re seeing the awareness lev el rising,” Mark Lobel, a principal in PwC’s U.S. advisory practice and Cybersecurity Technology, Information, Communications & Entertainment leader, said. “But cybersecurity is like a chess game with no kings, and trying to stay ahead of who’s across the board.”</p><p>And just who is across the board?</p><p>“There are many threat vectors,” Irfan Saif, a principal in Deloitte’s Cyber Risk Services practice, said. “There are service-disruption actors, those looking at the backbone to propagate malware and those who want to compromise customers. It’s a broad range of threat actors and companies must be cognizant of them all.”</p><p>That will require a holistic approach, Saif noted. “You must understand what behavior is considered normal and what indicates a threat of attack and what are the crown jewels that require higher-grade protection.”</p><p>Cisco Systems, another player in the cybersecurity space, concurred with Saif’s assessment.</p><p>“The best approach is a holistic look at security and where each layer builds on top of each other — firewalls, advanced malware protection, email and core technologies like conditional access, DRM and anti-piracy technology — a breadth of security,” Cisco senior product and solutions marketing manager Sam Rastogi said.</p><p>Another less glamorous threat, but just as dangerous, comes from the inside.</p><p>“Employees or vendors with access to information is a growing concern,” Rastogi sad. “Who’s accessing information and how, and is there abnormal activity? A risk-based program with alerts, authentication measures and more will give companies more insight.”</p><p>CableLabs, the cable industry’s research and development consortium, is accelerating its cybersecurity activity with two initiatives: It’s working with the Wi-Fi Alliance to ensure links to hotspot access points are secure, and it’s reaching more deeply into home managed access points.</p><p>“The level of engagement is very high and there are real questions being asked,” The mindset is changing,” CableLabs principal security architect Steve Goeringer said.</p><p>That’s a good thing, said Rick Michaels, CEO of CEA, a cable industry-focused investment bank. “It’s one thing that cable is carrying 60% of the Internet traffic, but now there are data centers and multiple services with different touch points in cable. Cybersecurity should be of paramount interest to the cable industry.”</p><p>Most cable companies are understandably reluctant to discuss their cyber security strategies. Comcast, which in March hired Noopur Davis as senior vice president of product security and privacy, offered a statement from Myrna Soto, senior vice president and global chief information security officer: “We’ve committed extensive resources with a focus on risk management and built resilient and smarter networks with many security layers that are monitored continuously. Using automation, tooling and analytics is key.”</p><p>Arris, another key equipment supplier to cable networks, said in a statement (in part): “Security remains a top priority at Arris, as it does for all manufacturers of Internet and network-connected devices” and that it “employs a variety of protective measures to help ensure the safe and reliable operation of our devices including, but not limited to, DOCSIS compliance, vulnerability scanning, and monitoring programs.” It works “actively with security organizations and our service provider customers to identify and quickly resolve any potential vulnerabilities to protect the subscribers who use our CPE devices.”</p><p>Breaches cut across both residential and business markets, added Sander Smith, president of Sericon Technology.</p><p>“It’s clear that very soon we’ll see consumers filling their home networks with IoT devices, and these devices will be rushed to market with very little thought given to security.”</p><p>Yet even with the increase in cyber attacks (PwC reported a 38% increase in 2015 vs. 2014), there is cautious optimism that with emerging cybersecurity innovations, an expanding community of cybersecurity companies and a heightened awareness among service providers, security is being strengthened.</p><p>“We’re seeing various levels of maturity in cable and telecom and a raising of awareness in those organizations,” PwC’s Lobel said. “But they can’t lose focus.”</p><p>The National Cable & Telecommuications Association is focusing its cybersecurity attention on two areas, senior vice president, science and technology and chief technology officer Bill Check said.</p><p>“We are leading the industry’s Cybersecurity Working Group and working with the FCC’s Communications Security, Reliability and Interoperability Council (CSRIC), along with various cybersecurity-related working groups,” he said. “The challenge is to anticipate current and future threats and design systems of early detection and resistance, because cyber-criminals will always look for new exploits.”</p>
                                                            </article>
                            ]]>
                        </content:encoded>
                                                </item>
            </channel>
</rss>