About
Services
Courses by Matthew
-
Five Biggest Mistakes of Cybersecurity Programs1h 20m
Five Biggest Mistakes of Cybersecurity Programs
By: Matthew Rosenquist
Articles by Matthew
Activity
200K followers
Experience & Education
Licenses & Certifications
Publications
-
When Does Customer Cybersecurity Trump the Government’s Demands?
medium.com
Technology is taking center stage in a debate between national security and individual privacy. Governments are challenging encryption practices and requesting backdoors to products, to the concern of many companies and customers. The debate is heated and at risk are unintended consequences. Matthew Rosenquist, Intel’s cybersecurity strategist, provides insights and recommendations. He wants rational thoughts, facts, and for the global community to gain from a long term understanding of the…
Technology is taking center stage in a debate between national security and individual privacy. Governments are challenging encryption practices and requesting backdoors to products, to the concern of many companies and customers. The debate is heated and at risk are unintended consequences. Matthew Rosenquist, Intel’s cybersecurity strategist, provides insights and recommendations. He wants rational thoughts, facts, and for the global community to gain from a long term understanding of the challenges before decisions are made. Everyone wants security and privacy. The challenge is finding the optimal balance.
Other authors -
Defending Ourselves in an Increasingly Connected World
Motherboard
As we race to embrace technology, we make ourselves increasingly vulnerable to cyber attacks. This is a calculated risk we all take. But recently, the threat has evolved in ways both startling and inventive. Whereas a few years ago hackers had focused on crashing websites or harvesting data, a new type of attack—an “integrity” attack—quietly compromises the internal workings of companies or organizations, allowing criminals to pilfer exorbitant sums of money with minimal fuss. As these methods…
As we race to embrace technology, we make ourselves increasingly vulnerable to cyber attacks. This is a calculated risk we all take. But recently, the threat has evolved in ways both startling and inventive. Whereas a few years ago hackers had focused on crashing websites or harvesting data, a new type of attack—an “integrity” attack—quietly compromises the internal workings of companies or organizations, allowing criminals to pilfer exorbitant sums of money with minimal fuss. As these methods become more popular, our desperate need for trained cybersecurity professionals to combat them becomes more acute.
Motherboard spoke with Matthew Rosenquist, a cybersecurity strategist and Intel Evangelist with over 20 years of experience, about the evolving methods of attackers and what we can do to defend ourselves in this digitally intertwined world.Other authors -
A field guide to insider threat
Intel Corporation
See publicationIntel IT hopes enterprises can use our Insider Threat Field Guide to understand and prioritize insider threats to further improve enterprise security strategies.
-
Intel Security Group’s McAfee Labs Threats Report - August 2015
Intel Security Group's McAfee Labs
See publicationCybersecurity Industry quarterly threat report and 5-year retrospective
-
Top 10 Cybersecurity Predictions for 2015 and Beyond
Intel Security
See publicationCybersecurity is poised for a notorious year. The computer security industry had a tumultuous 2014, with significant breaches, compromises, and vulnerabilities permeating the news. Governments, businesses, and huge swaths of everyday people were affected. In the next twelve to eighteen months will see even greater, bolder, and more complex attacks emerge.
This year’s installment for the top computer security predictions highlights how the threats are advancing, outpacing defenders…Cybersecurity is poised for a notorious year. The computer security industry had a tumultuous 2014, with significant breaches, compromises, and vulnerabilities permeating the news. Governments, businesses, and huge swaths of everyday people were affected. In the next twelve to eighteen months will see even greater, bolder, and more complex attacks emerge.
This year’s installment for the top computer security predictions highlights how the threats are advancing, outpacing defenders, and the landscape is becoming more professional and organized. New targets will emerge and the expectations of security will rise. As the industry changes, there will be struggles, setbacks, victories, and surprises. Although the view of our cybersecurity future is obscured, one thing is for certain, it will be an exciting ride. -
Top 10 Security Predictions for 2013 and Beyond
See publicationAs the chapter of 2012 has come to a close and the blank pages of 2013 open before us to be written, it is time once again to look into the future and predict what the next 12 months hold for the cyber and information security domain.
-
Improving Healthcare Risk Assessments to Maximize Security Budgets
Intel
Whitepaper: Increasingly, healthcare organizations are realizing the value of risk assessments as much more than a regulatory or compliance checkbox. Risk assessments also bring a targeted and measured approach to privacy and security. Risks can be mitigated through application of safeguards until the residual risks are below the acceptable level set by the organization. Risk assessments can be improved with attention to threat agents, for example internal Curious or Disgruntled Healthcare…
Whitepaper: Increasingly, healthcare organizations are realizing the value of risk assessments as much more than a regulatory or compliance checkbox. Risk assessments also bring a targeted and measured approach to privacy and security. Risks can be mitigated through application of safeguards until the residual risks are below the acceptable level set by the organization. Risk assessments can be improved with attention to threat agents, for example internal Curious or Disgruntled Healthcare Workers, or external Prescription Fraudsters. This guides budget allocation to highest priority risks, and avoids information privacy and security becoming a budgetary black hole.
Other authorsSee publication -
Prioritizing Information Security Risks with Threat Agent Risk Assessment
See publicationIntel IT has developed a threat agent risk assessment (TARA) methodology that distills the immense number of possible information security attacks into a digest of only those exposures most likely to occur. This methodology identifies threat agents that are pursuing objectives which are reasonably attainable and could cause unsatisfactory losses to Intel.
It would be prohibitively expensive and impractical to defend every possible vulnerability. By using a predictive methodology to…Intel IT has developed a threat agent risk assessment (TARA) methodology that distills the immense number of possible information security attacks into a digest of only those exposures most likely to occur. This methodology identifies threat agents that are pursuing objectives which are reasonably attainable and could cause unsatisfactory losses to Intel.
It would be prohibitively expensive and impractical to defend every possible vulnerability. By using a predictive methodology to prioritize specific areas of concern, we can both proactively target the most critical exposures and efficiently apply our resources for maximum results. The TARA methodology identifies which threat agents pose the greatest risk, what they want to accomplish, and the likely methods they will employ. These methods are cross-referenced with existing vulnerabilities and controls to pinpoint the areas that are most exposed. Our security strategy then focuses on these areas to minimize efforts while maximizing effect. -
Information Security Defense In Depth Whitepaper
See publicationIntel developed a defense-in-depth strategy to optimize information security using interlocking prediction, prevention, detection and response capabilities. It is a structure designed to support consistent and comprehensive security controls throughout the organization while allowing flexibility needed to manage risk.
It promotes continual improvement, maturity of security services, and adaptability to evolving threats. At Intel, proliferation of the defense in depth methodology has…Intel developed a defense-in-depth strategy to optimize information security using interlocking prediction, prevention, detection and response capabilities. It is a structure designed to support consistent and comprehensive security controls throughout the organization while allowing flexibility needed to manage risk.
It promotes continual improvement, maturity of security services, and adaptability to evolving threats. At Intel, proliferation of the defense in depth methodology has resulted in more efficient business decisions. The fundamental aspects allows for consolidation of support resources, helps highlight alternative methods for managing risk, aligns programs across environments, and keeps focus on achieving optimal security. -
Measuring the Return on IT Security Investments
See publicationQuantifying value for security programs is difficult at best. Intel IT developed a model for measuring Return on Security Investment (ROSI) in our manufacturing environments that produces a much higher level of accuracy than other methods currently available. Although not the silver bullet to measure all security programs, it does show in some circumstances, value can be quantified to the level needed to make sound business decisions.
Patents
-
Hardware-Generated Dynamic Identifier
Filed US US20170187525A1
In an example, there is disclosed an electronic apparatus, comprising: a hardware-encoded internal private key; and one or more logic elements comprising a key generation engine to: receive an third-party key; and operate on the third-party key and the internal private key to generate a hardware-generated dynamic identifier (HGDI). There is also disclosed a method of providing an HGDI engine, and one or more computer-readable mediums having stored thereon executable instructions for providing…
In an example, there is disclosed an electronic apparatus, comprising: a hardware-encoded internal private key; and one or more logic elements comprising a key generation engine to: receive an third-party key; and operate on the third-party key and the internal private key to generate a hardware-generated dynamic identifier (HGDI). There is also disclosed a method of providing an HGDI engine, and one or more computer-readable mediums having stored thereon executable instructions for providing an HGDI.
Other inventorsSee patent
Languages
-
English
Native or bilingual proficiency
Recommendations received
2 people have recommended Matthew
Join now to viewOther similar profiles
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content