Are the Chinese really out to get paranoid IT security pros?

happygeek 3 Tallied Votes 483 Views Share

A recent survey, conducted by IT risk management specialists nCircle, suggests that as many as 50% of IT security professionals think that the organisations they work for are a potential target for state-sponsored hackers. A number that Tim Keanini, nCircle Chief Research officer, thinks is rather on the low side in reality.

"The number of organizations that are potential targets for state-sponsored cyber attacks is probably much higher than 50%, because if attackers can’t break into a targeted organization, they will go after partners and suppliers" Keanini insists, adding "Frankly, I’m surprised that the level of paranoia among information security professionals isn’t higher."

Of course, to paraphrase a well known saying, just because you are a paranoid IT security professional doesn't mean that China isn't out to get you. Or, perhaps more accurately, just because the media says that China is the country most likely to be hacking your business doesn't mean that everyone else isn't also at it. The public perception of who is behind state-sponsored attacks is not only shaped by media reporting, but also mis-shaped if you ask me. Ask Keanini and he will say the same: "The reality is that nations that are really good at cyber attacks don’t make the news because they don’t get caught." Interestingly, when it comes to those IT security pros who were surveyed (more than 200 of them who attended the 2013 RSA Conference in San Francisco) some 48% go with China as being the best equipped for launching state-sponsored cyber attacks but 33% point the finger in the direction of the United States itself when it comes to advanced technical capability for such activity.

I'm not sure it really matters which direction state-sponsored hacking comes from, or where it is perceived to come from, or indeed if it is state-sponsored at all. Just look at the Worldwide Infrastructure Security Report from Arbor and you will see that quite clearly DDoS attacks are on the up: 76% of respondents experienced DDoS attacks towards their customers during the past year. Add to that the rise of hacktivism, with 33% reporting political and ideological disputes as the motivation behind those attacks, and it becomes clear that IT security professionals and the organisations they work for need to be focusing more on defense in depth and worrying less about apportioning blame.

As Dan Holden, Director of Arbor’s Security Engineering & Response Team, points out: "Global recognition for effective cyber security solutions in business is rising, but many still continue to bury their heads in the sand. The truth is that any business operating online - from the largest enterprise to an individual operator - can become a target for attack, because of who they are, what they sell or who they partner with. It’s extremely important that organisations of all size take best practice defensive steps to ensure they are adequately protected if, or more likely when, they become the target of an attack."

Dani AI

Generated

A focused addendum to the thread.

The identity of an attacker (country, criminal group, or lone operator) matters less than how an organisation prepares. As noted, shifting energy from “who did it” to layered defenses, detection, and recovery is the practical win. Attribution is frequently ambiguous because attackers hide tracks and use third parties, so resilience and response capability are the real measures of security.

To ’s point about manufacturing: the physical location of assembly is only one factor. The greater supply‑chain risks are tampered firmware, counterfeit components, insecure update channels, poor build controls, or opaque vendor practices. Moving manufacture is expensive and slow; improving procurement, verification, and technical controls delivers more immediate risk reduction.

Practical, high‑impact steps (prioritised):

  • Require vendor transparency and contractual protections (SBOMs, right‑to‑audit, documented update processes).
  • Insist on signed firmware and hardware attestation (Secure Boot, TPM/root‑of‑trust) from suppliers.
  • Run acceptance checks on new gear (firmware hashes, inventorying, configuration baselines).
  • Segment networks and restrict vendor/IoT devices to isolated VLANs with strict ACLs.
  • Enforce least privilege for management interfaces, use MFA, eliminate default credentials, rotate keys.
  • Centralise logging, deploy EDR/NIDS and egress filtering to detect anomalous outbound traffic.
  • Maintain an incident response plan that assumes supply‑chain compromise and use regular tabletop exercises.

To ’s question about change: improvements are incremental. The fastest gains come from stronger procurement requirements, routine verification, and better detection and response — not from hoping supply chains move overnight. Paranoia becomes useful when translated into concrete controls and testing.

Member Avatar for Member #949455
Member #949455

Ask Keanini and he will say the same: "The reality is that nations that are really good at cyber attacks don’t make the news because they don’t get caught." Interestingly, when it comes to those IT security pros who were surveyed (more than 200 of them who attended the 2013 RSA Conference in San Francisco) some 48% go with China as being the best equipped for launching state-sponsored cyber attacks but 33% point the finger in the direction of the United States itself when it comes to advanced technical capability for such activity.

I agree. The main reason is because most of the IT hardware and software are still manufacturing in China. It's like a blue-print. It should be manufacturing here in the US. But that's not going to change anytime soon.

Vincentas 6 Junior Poster in Training

do you think it will change at all? :)

Member Avatar for Member #949455
Member #949455

do you think it will change at all? :)

My opinion I don't know.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.