<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>media - RiskInsight</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/tag/media-en/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/en/tag/media-en/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Tue, 19 May 2020 07:28:35 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>media - RiskInsight</title>
	<link>https://www.riskinsight-wavestone.com/en/tag/media-en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Deep dive into deepfake &#8211; How to face increasingly believable fake news? (2/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/05/deep-dive-into-deepfake-how-to-face-increasingly-believable-fake-news-2-2/</link>
		
		<dc:creator><![CDATA[Carole Meyziat]]></dc:creator>
		<pubDate>Mon, 18 May 2020 08:25:27 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[deepfakes]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[media]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Strategy]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13034</guid>

					<description><![CDATA[<p>We have seen in the first part of the article the risks that represent the deepfakes for the businesses. In this part, we are going to focus on the strategies available to pre-empt deepfakes and the concrete actions to implement...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/05/deep-dive-into-deepfake-how-to-face-increasingly-believable-fake-news-2-2/">Deep dive into deepfake &#8211; How to face increasingly believable fake news? (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">We have seen in the first part of the article the risks that represent the deepfakes for the businesses. In this part, we are going to focus on the strategies available to pre-empt deepfakes and the concrete actions to implement as of now to reduce their risks.</p>
<p>&nbsp;</p>
<h2>DIFFERENT STRATEGIES TO safeguard AGAINST DEEPFAKES</h2>
<p style="text-align: justify;">Concurrently with the legal framework, public and private organisations get organised to put forward solutions allowing to detect and prevent the malicious spread of deepfakes. We can distinguish <strong>four strategies to safeguard against deepfakes.</strong></p>
<p>&nbsp;</p>
<h3>1/ Detecting the imperfections</h3>
<p style="text-align: justify;">Detecting the deepfakes by their imperfections is one of the main existing methods. Some irregularities remain in the generated contents, such as the lack of blinks and of synchronisation between the lips and the voice, distortions of the face and accessories (arms of the glasses), or the inaccuracy of the context (weather, location).</p>
<p style="text-align: justify;"><strong>The deepfakes are however built to learn from their mistakes </strong>and generate a content that is increasingly alike the original, making the imperfections less perceptible. The tools using this deepfake detection strategy can be effective but require a constant improvement to <strong>detect ever more subtle anomalies</strong>.</p>
<p style="text-align: justify;">We can cite in this category Assembler, a tool intended for journalists developed by Jigsaw (branch of Alphabet, parent company of Google). It enables to verify the authenticity of contents through their analysis via five detectors, amongst which the detection of anomalies of patterns and colours, of copied and pasted areas, and of known characteristics of deepfakes algorithms.</p>
<p>&nbsp;</p>
<h3>2/ Screening and comparative analysis</h3>
<p style="text-align: justify;">Comparing the contents with a <strong>database of authentic content</strong> or by <strong>looking for similar content</strong> on search engines to see whether they have been manipulated (for instance, by finding the same video with a different face) is another strategy allowing to pre-empt deepfakes.</p>
<p style="text-align: justify;">In 2020, the AI Foundation should make available a plugin, Reality Defender, to integrate to web browsers and over time to social networks. It will allow the detection of manipulations of contents, targeting first the politicians. Users will be led to adjust the sensitivity of this tool, according to the manipulations they will want to detect or not, not to be notified for every manipulation of content, notably for the most ordinary manipulations (photo retouch on a web page done on Photoshop for example).</p>
<p>&nbsp;</p>
<h3>3/ Watermarking</h3>
<p style="text-align: justify;">A third method consists in marking the contents with a watermark, or digital tattoo, to <strong>facilitate the authentication process</strong> by filling in their source and following the manipulations undertaken on these contents.</p>
<p style="text-align: justify;">A team from the New York University works on a research project to create a camera embedding a watermarking technology meant to mark the photographed contents, in order not only to authenticate the original photography, but also to mark and follow all the manipulations carried out on it throughout its lifecycle.</p>
<p>&nbsp;</p>
<h3>4/ Involving the human factor</h3>
<p style="text-align: justify;">Involving the users in the detection process allows <strong>both mitigating deepfakes’ impacts</strong> by making them realise that the alteration of the acceded contents is possible, and to <strong>reduce deepfakes’ occurrence</strong> by allowing them to report the ones they suspect.</p>
<p style="text-align: justify;">The plugin Reality Defender already mentioned will give users the possibility to report the contents they judge as fake so as to inform the other users – which once added to the analysis realised by the tool, will be able to see if the contents have been reported by other users, offering a second level of indication.</p>
<p>&nbsp;</p>
<p style="text-align: justify;">Some <strong>initiatives carried by cooperation of cross-sector actors combine these four strategies</strong> for a maximal efficiency against deepfakes. Some are already used or tested by journalists. It is the case of InVID, initiative developed within the scope of the European Union Horizon 2020 program of financing of research and innovation, used by the French press agency (AFP).</p>
<p style="text-align: justify;">Solutions and strategies are therefore emerging, the market is developing, and new innovative solutions should appear very shortly with the results of the Deepfake Detection Challenge. This contest anti-deepfake was launched by Facebook upon the approach of the American presidential election, and more than 2,600 teams signed up. Results the 22<sup>nd</sup> of April!</p>
<p style="text-align: justify;">Below a table presenting examples of initiatives combining different strategies to safeguard against deepfakes.<strong><br />
</strong> <strong><br />
</strong></p>
<figure id="post-13038 media-13038" class="align-none"><img fetchpriority="high" decoding="async" class="aligncenter wp-image-13038 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image6.png" alt="" width="1198" height="655" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image6.png 1198w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image6-349x191.png 349w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image6-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image6-768x420.png 768w" sizes="(max-width: 1198px) 100vw, 1198px" /></figure>
<p>&nbsp;</p>
<h2>Different means to protect one’s activity</h2>
<p style="text-align: justify;">The risk deepfakes present for businesses is genuine, and a few actions can be taken to protect one’s activity and mitigate its impacts from now on.</p>
<ul>
<li style="text-align: justify;"><strong>Estimating the exposure: </strong>The use cases of deepfakes and the worst-case scenario of their use must be determined on the <strong>perimeters of the company</strong>, taking the fraud and undermining risks into consideration, and identifying the appropriate security strategies.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li style="text-align: justify;"><strong>Raising awareness: </strong>The collaborators must be made aware of the <strong>detection </strong>of deepfakes (to avoid the cases of fraud) but also of the <strong>limitation of shared contents </strong>on social media that can be reused to create deepfakes (to avoid the undermining). Just like anti-phishing campaigns, this awareness campaign focuses both on the detection of technical faults (form) of the deepfakes (although they will be led to disappear with the improvement of techniques), but mostly on the detection of the suspicious nature of information (content), encouraging the audience’s suspicion, cross checking of information and notification of the suspicions to the appropriate teams (what to do if I see a suspect video of my head of communications on the social networks during the weekend? What to do if I receive a vocal message of my chief asking me to execute a punctual operation that is slightly out of my perimeter?).</li>
</ul>
<p>&nbsp;</p>
<ul>
<li style="text-align: justify;"><strong>Adapting the verification processes: </strong>The existing anti-fraud plans can be redesigned to be applied to deepfakes. For instance, for a Fake President fraud via deepfakes, one of the recommendations is to suggest to the interlocutor to hang up and call him back (if possible on a known number, and after an internal check). For the <strong>most</strong> <strong>sensitive fraud scenarios, </strong>these reaction processes must be <strong>finely defined,</strong> and the concerned collaborators regularly <strong>trained to the reflexes to adopt</strong>. Tools such as the ones defined earlier can also be used to verify all or any part of the media used by the collaborators.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li style="text-align: justify;"><strong>Protect the contents: </strong>The contents representing collaborators shared internally or externally by the company can be <strong>controlled to avoid them being reused to generate deepfakes. </strong>Businesses can limit the <strong>diversity </strong>(angle of the people and types of media) of the data potentially usable by malicious actors, and play on the <strong>digital quality</strong> (definition) of the shared contents. In fact, the more the malicious actors benefit from diverse and good quality contents representing the collaborators, the more it facilitates their reuse to generate deepfakes. Moreover, businesses can limit their means of communication to an <strong>official channel, verified social networks and their official websites </strong>– which creates contents’ consumer habits for the audience, that will be suspicious of all diffusion out of these habits.</li>
</ul>
<p>&nbsp;</p>
<ul>
<li style="text-align: justify;"><strong>Anticipate the crises: </strong>The communications requirements in the case of a <strong>proven incident</strong> linked to deepfakes must be anticipated, and the management of the deepfake case must include the “generic” communications scenarios addressed in the crisis communication plans.</li>
</ul>
<p>&nbsp;</p>
<figure id="post-13040 media-13040" class="align-none"><img decoding="async" class="aligncenter wp-image-13040 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image7.png" alt="" width="1092" height="545" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image7.png 1092w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image7-383x191.png 383w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image7-71x35.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image7-768x383.png 768w" sizes="(max-width: 1092px) 100vw, 1092px" /></figure>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/05/deep-dive-into-deepfake-how-to-face-increasingly-believable-fake-news-2-2/">Deep dive into deepfake &#8211; How to face increasingly believable fake news? (2/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Deep dive into deepfake &#8211; How to face increasingly believable fake news? (1/2)</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/05/deep-dive-into-deepfake-how-to-face-increasingly-believable-fake-news-1-2/</link>
		
		<dc:creator><![CDATA[Carole Meyziat]]></dc:creator>
		<pubDate>Tue, 05 May 2020 17:00:18 +0000</pubDate>
				<category><![CDATA[Cyberrisk Management & Strategy]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Digital Identity]]></category>
		<category><![CDATA[deepfakes]]></category>
		<category><![CDATA[fraud]]></category>
		<category><![CDATA[media]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Strategy]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=13024</guid>

					<description><![CDATA[<p>Online media and social networks expand the attack surface usable by the malicious actors, and deepfakes are the ultimate weapon. Well-known as a disinformation tool for the society, they bring about other risks to be considered by businesses. The recent...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/05/deep-dive-into-deepfake-how-to-face-increasingly-believable-fake-news-1-2/">Deep dive into deepfake &#8211; How to face increasingly believable fake news? (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;"><strong>Online media and social networks expand the attack surface usable by the malicious actors, and deepfakes are the ultimate weapon. Well-known as a disinformation tool for the society, they bring about other risks to be considered by businesses. </strong></p>
<p style="text-align: justify;">The recent events linked to the COVID-19 outbreak have proven the necessity of acceding to reliable and true news for all the society. More than the epidemic, we have witnessed an « <strong>infodemic</strong> », rapid spread of false or misleading information on the social networks, raising the question of the trust given to the platforms relaying the news and of the authenticity of the information they pass on.</p>
<p>&nbsp;</p>
<figure id="post-13025 media-13025" class="align-none"><img decoding="async" class="aligncenter wp-image-13025 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Capture.png" alt="" width="1000" height="213" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Capture.png 1000w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Capture-437x93.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Capture-71x15.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Capture-768x164.png 768w" sizes="(max-width: 1000px) 100vw, 1000px" /></figure>
<p>&nbsp;</p>
<p style="text-align: justify;">The use of deepfakes is a topical phenomenon affecting <strong>firstly the general public</strong>. It is inherently linked to the importance gained by the social and online media in our daily life.</p>
<p style="text-align: justify;">In September 2019, we counted near 15,000 deepfake videos online, twice more than in December 2018. If 96% of these videos were pornographic deepfakes posted on specialised websites, the extent of the affected topics has however increased to reach all the famous social networks (YouTube, Vimeo, Dailymotion).  Amongst the deepfakes posted on YouTube, <strong>20% already represented politicians, business owners and journalists</strong><a href="#_ftn1" name="_ftnref1">[1]</a>. Their <strong>disinformation power</strong> on the general public allows them to <strong>influence major political and societal events </strong>from the moment they star famous personalities.</p>
<p style="text-align: justify;">Deepfakes keep getting better, while the tools to generate them become more accessible (such as Lyrebird, for the audio deepfakes, Zao, for face-swapping, and the most recent one, Avatarify, integrated to Zoom and Skype, for the video). <strong>Their harmful power weighs more and more not only on public actors and organisations, but also on private ones, and must be taken into account in every business sector.</strong></p>
<p><strong> </strong></p>
<h2>A RISK WORTH CONSIDERING FOR BUSINESSES</h2>
<p style="text-align: justify;">Deepfakes can also be used against businesses. They offer a new playground for malicious actors, particularly through two means of action:</p>
<ul>
<li style="text-align: justify;"><strong>The improvement of Fake president frauds, </strong>whose impacts and probability are increased by deepfakes. The fraud becomes more credible thanks to photos, videos and audios copying the person who is impersonated. The targeted collaborators therefore consider these contents as an authentication in itself of the interlocutor, and the chances of successful attacks are increased – which is an incentive to ask for larger sums. Besides, the tools to generate deepfakes being accessible to the large public, the use of these frauds by malicious people increases.</li>
<li style="text-align: justify;"><strong>The undermining of the business </strong>through relayed false information can strongly damage its image, leading to a certain number of consequences, notably financial and legal. We can wonder what would be the impacts of an ExCom member’s video speech sharing fake results or strategic orientations on the price of his firm’s share or on the trust of its prospects; or those of the disclosure of a product anomaly on the direct order intake. Moreover, denying the rumours is harder when deepfakes are used. Today, many businesses still feel afar from the subject: <strong>How many have already wondered what would the impacts of a deepfake be on their activities?</strong></li>
</ul>
<p><strong> </strong></p>
<figure id="post-13027 media-13027" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-13027 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image5.png" alt="" width="880" height="701" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image5.png 880w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image5-240x191.png 240w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image5-49x39.png 49w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/05/Image5-768x612.png 768w" sizes="auto, (max-width: 880px) 100vw, 880px" /></figure>
<p><strong> </strong></p>
<h2>A legal framework IN PROGRESS</h2>
<p style="text-align: justify;">The states start putting together an answer to the deepfake concern and legislating to regulate their diffusion. Some countries such as <strong>China</strong> criminalise the diffusion of deepfakes without notifying the audience about it (since the 1<sup>st</sup> of January 2020). In the <strong>United States</strong>, the treatment of the deepfakes’ question is speeding up as the presidential election of November 2020 approaches, and it is dealt with both at the federal level (bills prohibiting the diffusion of deepfakes in California, Virginia and Texas) and at the national one (the DEEPFAKE Accountability Act<a href="#_ftn2" name="_ftnref2"><em><strong>[2]</strong></em></a>  is being discussed by the Congress to “combat the spread of disinformation through restrictions on deep-fake video alteration technology”). In <strong>France, </strong>the question of deepfakes is included in the law of the 22<sup>nd</sup> of December 2019, related to the fight against the manipulation of information – and is therefore not dealt with specifically.</p>
<p style="text-align: justify;">These legal frameworks remain dawning and heterogeneous, and only represent one part of the answer to provide to this technology. <strong>More than condemning their malicious use, the issue is mostly to be able to detect and avoid them. </strong></p>
<p>&nbsp;</p>
<p style="text-align: justify;">In this first part, we have given an overview of the risks presented by deepfakes for the businesses. In the second part of the article, we will focus on the technical and organisational means available today to safeguard oneself.</p>
<p>&nbsp;</p>
<p><a href="#_ftnref1" name="_ftn1">[1]</a> Study published by Deeptrace in September 2019.</p>
<p><a href="#_ftnref2" name="_ftn2">[2]</a> <em>Defending Each and Every Person from False Appearances by Keeping Exploitation Subject to Accountability Act.</em></p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/05/deep-dive-into-deepfake-how-to-face-increasingly-believable-fake-news-1-2/">Deep dive into deepfake &#8211; How to face increasingly believable fake news? (1/2)</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cybercrisis, a fully-fledged media topic</title>
		<link>https://www.riskinsight-wavestone.com/en/2018/04/cybercrisis-media-topic/</link>
		
		<dc:creator><![CDATA[Swann Lassiva]]></dc:creator>
		<pubDate>Sat, 14 Apr 2018 11:21:16 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[communication]]></category>
		<category><![CDATA[crisis]]></category>
		<category><![CDATA[crisis management]]></category>
		<category><![CDATA[cyber]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[media]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=10728/</guid>

					<description><![CDATA[<p>Although they are based on similar objectives, methods and tools, crisis management and crisis communication necessarily appropriate the specifics of the issues they deal with to be relevant and therefore effective. In the case of a crisis of cyber origin,...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/04/cybercrisis-media-topic/">Cybercrisis, a fully-fledged media topic</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><em>Although they are based on similar objectives, methods and tools, crisis management and crisis communication necessarily appropriate the specifics of the issues they deal with to be relevant and therefore effective. In the case of a crisis of cyber origin, considering its characteristics and its exposure to often large numbers of users, requires specific anticipation and preparation. The first step is understanding the expected scale of media exposure.</em></p>
<p>&nbsp;</p>
<h2>Addressing the need to know and the need for reassurance</h2>
<p>Supported by the increased number of incidents and attacks on information systems, the cybercrisis has moved into the public realm. The democratisation of its vocabulary is a clear indicator of the place that this subject takes up in the media. Data leakage, ransomware, hacktivist, DDoS, phishing, whistle-blower, these terms have left the server rooms and specialist blogs to make their way into national newspaper columns and most people’s vocabulary. The cybercrisis is no longer a mere quality incident discreetly handled in-house but has become an event that arouses the interest of a broad audience. This interest transforms the cybercrisis into a communicational crisis. However, while this theme’s new popularity is logically transposing into an increase in coverage, other elements justify a significant increase in solicitations, whether internal or external to the organisation in crisis.</p>
<p>When the cybercrisis results in data leakage, for example, it is not only the subject of the crisis that is newsworthy, but its very object. In fact, when the data leaks or is stolen, its nature arouses curiosity, whether it is personal data, a State secret or simply a private conversation. This mechanic logically generates for many audiences both the need to know the unknown, and to make sure that they are not the victim. These two primary needs of curiosity and reassurance are the essential drivers of media coverage and more generally encourage the information consumer, the stakeholder, the client to fill that need and seek to obtain this information. The same logic assumes that the source of this information, in this case the legitimate data holder, addresses these requests and communicates on the incident.</p>
<p>Whether it’s strategic events such as presidential elections or everyday private conversations on digital media that are compromised, the crisis’ media effect is magnified by the extraordinary nature of the event. This is the result of both its supposed impossibility and the confidence that the public entrusts it. The sudden rupture of the trust placed in these &#8220;institutions&#8221; of major importance, erected in good stead in a 2.0 version of Maslow’s pyramid, then generates itself the interest and the need to know, translated into an explosion of the number of requests for information to the organisation in crisis.</p>
<p>&nbsp;</p>
<figure id="post-10730 media-10730" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-10730" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2018/05/Image1.png" alt="" width="600" height="497" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2018/05/Image1.png 1160w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/05/Image1-231x191.png 231w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/05/Image1-768x636.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2018/05/Image1-47x39.png 47w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>
<p style="text-align: center;"><em>Figure 1: Maslow Pyramid Example</em></p>
<p>&nbsp;</p>
<h2>Communication war between the attacker and the communicator</h2>
<p>Cybercrisis communication is thus a specific exercise given the subject it deals with, but also by the nature of the actors present. In fact, when immeasurable sums of money are stolen without warning or institutions fall under &#8220;citizens&#8221; hacktivist attacks, opinion tends to sympathise towards the attacker perceived as a modern hero, a romantic pirate or a anonymous vigilante.</p>
<p>This public figure, aware of its image and the codes of the communication world, will of course be able to play this environment. Thus, the very methods of the attackers reinforce the central place of communication in the management of cybercrises. Attacks on political, ideological and militant grounds are no longer confined to the compromise of a system but send a message whose publicity must be maximised.</p>
<p>This obvious appropriation of the activists’ specific methods is illustrated in several ways: prior warning of a DDoS, defacing a website, publication over time of proofs of a theft on social networks, dissemination of information such as exchanges of compromising private mail conversations, etc. If the attackers have learned to maximize the reputational impact of their attacks, they also use this lever to disrupt their target’s crisis management and make a noise that will buy them time once their attack is discovered. While one of crisis management’s key success factors of is regaining control of this rhythm and the publication of new elements, the cybercrisis inevitably leaves this power to a malicious third party.</p>
<p>This third party can also, if the compromise goes deeply, alter the company’s means of communication. While it tries to respond to the need to express itself urgently and widely, this can severely hinder the fluidity of its communication. Without email, how to spread a message to employees? Without social networks, how to be close to the community and answer their questions?</p>
<p>&nbsp;</p>
<h2>Restoring the trust relationship through communication</h2>
<p>Fascinated by the attackers and the magnitude of the attacks, the general public is nonetheless intransigent at a time when trust and data are the very value of a company. Intrinsically, preserving the first assumes the protection of the second. When the organisation fails to achieve this goal, crisis communication is the only one able to restore this relationship of trust on which depends the future of the relation with customers and partners, who will or will not continue to entrust their data or the management of their tools, as well as their services to an organisation.</p>
<p>This trust requirement also brings about, when it’s is broken, the search for whom to point the blame. Although the reality of the facts is much more complex, the general public will easily assume that information system attacks are made possible by exploiting a vulnerability and therefore a fault.</p>
<p>A data leak is thus not only perceived as an attack perpetuated by a malicious third party, but also as negligence in the defences of the company victim to the theft. The latter is automatically designated as responsible and its reputation is logically impacted. Even as the attackers have become professional, the attacks complexify and the absence of vulnerabilities is a myth, cyber-attacks are now a subject of crisis management and communication in their own right. Because of its potential impact on the general public’s daily life and therefore its newsworthy nature, it forces the victim, considered to be co-responsible for its loss, to express itself.</p>
<p>&nbsp;</p>
<h2>Try to Keep It Simple for Better Crisis Communication</h2>
<p>Beyond defining a clear, shared and timely strategy, managing a cybercrisis with its particular rhythm and the obstacles caused by the attackers must be accompanied by a special communication which implies a final effort: keeping it simple.</p>
<p>Confronted by a cybercrisis, like any type of crisis, communicating implies being able to translate the events and corrective actions into clear impacts and to address them in a coherent manner. Of course, the complexity of the terms and the mechanics of a cybercrisis makes this exercise tricky and is another particularity to take into account.</p>
<p>In this context, through their ability to translate the technical cause into business consequences and more generally into layman’s terms, the CISO and their team’s role is central. During business as usual as well as in times of crisis, the CISO’s mission is the responsibility for translating the facts and technical components not only into business impacts but also into understandable and convincing impacts for diverse non-expert audiences. They may also have to conceive or even bear responsibility for elements of crisis communication language in the same way that a human resources representative is exposed during a social crisis.</p>
<p>Without presupposing their exposure on a major TV channel’s news programme, information security experts’ words will be expected on social networks, on professional networks, in the specialized press or in-house. In crisis communication, everyone is responsible for everything and everyone has to be prepared for it.</p>
<p>Thus, the subject of cyber carries a media power of its own; the immediate consequence of which is the considerable increase in expectations and requests to be informed from different divisions of an organisation as well as from the public. If the impending occurrence of an information security incident involves a specific defence and continuity of operations planning, it also requires anticipation of these requests and an active preparation for this overall communication effort.</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2018/04/cybercrisis-media-topic/">Cybercrisis, a fully-fledged media topic</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
