Home Blog Page 101

Reviewing Critical Infrastructure Information Governance Practices in the Aftermath of Recent Attacks

Power and Utility

There are necessary and important data security needs in the nation’s public sector critical infrastructure services, such as water and wastewater treatment facilities, transportation, chemical, and energy sectors. Data security is to protect against intelligence gathering, distribution, maleficence against integrity, industrial espionage, and special initiatives from the government programs to protect the country (Smallwood, R. F. 2020). Given the intimate connection between technology and critical infrastructure services, one must contemplate the effects of incapacitation and unavailability of these services to a country’s economy, safety, and public health. Technology is instrumental in contributing to providing critical infrastructure to a nation.  In essence, the physical production of critical infrastructures, such as power distribution, is vital to modern-day life, but in the current environment of cyberattacks, the information and data created, collected, disseminated, and monitored are equally significant.

By Stan Mierzwa, M.S., CISSP, Director and Lecturer, Center for Cybersecurity, Kean University

With the recent international attacks on electrical power infrastructure, the threat actor motives could be a timely opportunity for those with accountability in this critical sector to review their Information Governance (IG) programs. Similar to other such efforts that partake in steps of continuous improvements, an IG driver should not be considered static, but more of living energy.  To many, the idea of an IG program may seem vague – so as a brief reminder, IG programs include the ways an organization maintains its security, works to comply with regulations and laws in the respective industry, and maintains ethical standards (Smallwood, R. F. 2020).  As part of the effort, those organizations recently attacked should consider studying, or if unavailable, employing proper Information Governance strategies to help with the protection of data, as an invaluable asset. This effort will entail going back to the drawing table to study the legal and sector-related regulations, so that they are met, but more importantly so that they are exceeded! This focal action will include a process to employ tasks to help categorize the most critical and important information and data. Ensure to engage appropriate Information Governance policies that will help to enforce security-related information technologies, such as encryption, strict access controls, information rights management, digital shredding capabilities, auditing, and logging (Smallwood, R. F. 2020).  One other component often considered and approached with Information Governance procedures is to work towards efficient evolutionary enhancements.  Given the changing landscape of technology solutions being upgraded and implemented as part of new efforts or replacement products, it is critically important to review the security and possible unmet needs concerning cybersecurity.  It is often the case that when carrying out new solutions (hardware or software), one is eager to ensure everything is simply working and meeting the end-user and stakeholder needs. However, there must be an effort to review for deficiencies in security defense.

One other important element of an IG program involves properly managing data and the organizations’ records. Records in the power industry can come from many different and varied sources, and each of them can have the potential of providing a threat actor with access to valuable information that can be used against the power provider. ARMA International has published a set of eight critical principles that can be followed to stand-in an excellent recordkeeping operation. These “Principles” are referred to as the Generally Accepted Recordkeeping Principles and are associated with proper information governance framework (Smallwood, R. F. 2020).

During a crisis of a cybersecurity incident, it is natural to consider what ways to put in place technology layers to help defend against further such attacks. Such efforts are important and may certainly be necessary, however, as part of the de-briefing after attacks, it may be valuable for those with accountability to reach a level or two above the technology and consider the Information Governance, Data Governance and IT Governance approaches in place to set in motion changes to protect stakeholders.


References

  1. Smallwood, R. F. (2020). Information Governance – Concepts, Strategies, and Best Practices. Second Edition. John Wiley & Sons, Inc., Hoboken, New Jersey.
  2. Tallon, P. 2013. Corporate Governance of Big Data: Perspectives on Value, Risk, and Cost. IEEE Computer Society.
  3. ARMA International. 2017. Generally Accepted Recordkeeping Principles. As retrieved: www.arma.org/principles.

About Author

Stanley Mierzwa is the Director, Center for Cybersecurity at Kean UniversityStanley Mierzwa is the Director of, Center for Cybersecurity at Kean University in the United States. He lectures at Kean University on Cybersecurity Risk Management, Cyber Policy, Digital Crime and Terrorism, and Foundations in Cybersecurity.  He is a peer reviewer for the Online Journal of Public Health Informatics journal, a member of the FBI Infragard, IEEE, (ISC)², and a board member (Chief Technology Officer) of the global pharmacy education non-profit, Vennue Foundation. Stan holds an MS in Management with specialization in Information Systems from New Jersey Institute of Technology and a BS in Electrical Engineering Technology from Fairleigh Dickinson University, is also a Certified Information Systems Security Professional (CISSP).

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Get Cybersecurity Projects Approved by Articulating the Value of the Data

Cybersecurity is standard business practice for most large companies: Survey

Cybersecurity projects are often balked at because businesses rarely realize the value of their data. For many organizations, data is something that accumulated over years of operations but is seldom looked at as an asset. So, getting approval for a cybersecurity project can be difficult. It is hard for decision-makers to understand the actual value of their data assets. This article addresses an approach in fair valuation that helps contextualize the cost of a cybersecurity project against the value of the data it is protecting.

By Ray K. Ragan, MPM, PMP, ITIL, AgilePro

Examining the value of data seems like a subjective task full of intangible considerations. The mid2000s changed that when the U.S. markets saw several commercial data breaches. History, with its sense of irony, now provides an auditable asset valuation of data from the liabilities sheets of these breached companies. There are many commercial data breaches that resulted in settlements, which can establish a par value of data.[1]

Reviewing commercial data breach settlements from 2008 to 2017 where the settlement, along with the number and disposition of compromised accounts, is publicly available is key for establishing the lower limit of data value.[2] These breaches are then qualified on severity based on the nature of data involved in the compromise. In this nine-year period of consideration, there are eight commercial data breaches that meet these criteria.

Types of data breaches, by severity

For the purposes of this value exercise, the severity is assessed on a numerical scale. A Severity 1 data compromise is data that can be reasonably changed by the victim and includes limited personally identifiable information (PII) with no financial information (e.g. usernames and passwords). A Severity 5 data compromise is data that is immutable and/or contains financial information that could reasonably cause a high degree of harm (e.g. health records and detailed financial records).

These eight commercial data breaches range between $0.17 and $6.73 per compromised account. Target’s Severity 2 breach represents the lower limit and Premera Blue Cross Severity 5 represents the upper limit. Incidentally, Equifax’s notorious 2017 data breach was only US$4.90 per account, suggesting settlements place a premium on health record protections over financial records. It is important to note the settlements may be the sum of damages and punitive considerations. This distorts the valuation but still serves a purpose in bracketing the value.[3]

This information allows an organization to establish a minimum value of their data. To do this, an organization must determine the nature of their data and which severity group best aligns. For instance, if the organization is a bank or credit union, using Severity 3 might be sensible depending on how detailed the customer data is. In this class, the average is $0.97 per customer record, based on data from data breach settlements.

This valuation is only of the data at rest and not being actively used in the interest of the organization. The data is static. Now an organization must consider this data in its ideal state of use. If the data is used in its optimal state of utility, what would the fully realized value be? This seems to be an exercise in intangibles, but organizations often know more about the value of their data than it may seem.

Using the methodology described in the seminal book, “How to Measure Anything,” a fair estimate range of data utility value can be determined. This is done by applying the Rule of Five. Sampling as little as five calibrated subject experts on what the ideal use of the organization’s data is will yield a usable bracket of data value with a confidence interval above 90% that the real value lies in the range of answers.[4] If a calibrated expert provides an answer far outside the range it produces, it should be considered an outlier.[5]

In the example presented in the table below, answers from our fictional experts range between $48 – $738 per year, with Sara from Accounting providing $738 based on the current most profitable customers. We like Sara, she uses data. These estimates are based on the organizational assumption that the data is 50% of the revenue and the organizations’ operations account for the other 50% of value. Some organizations may put a higher premium on the data, but this approach allows for a starting point in estimating.

Going back to the bank example, this is now iteration two on establishing value. The settlement data provides what is the lower-class value for static data. The input of the internal experts provides what will likely be an upper-class of the value of the organization’s data. Now, add a third input to the valuation of an organization’s data that is auditable and repeatedly verifiable by another. This is done by reviewing how the organization currently obtains value from its data – usually in terms of customer revenue.

Ask most people in an organization what the average customer revenue is, and likely answers will vary from blank stares to philosophical debates. This data is easier to work with in terms of estimating value, as it is directly derived from the data on hand. Remember Sara from Accounting, hero of the expert estimation. Ask her what the average annual revenue of a customer is. This establishes an auditable estimate of data utility value. In this notional example, it is $52.01.

These data sources provide a composite of what the organization’s data value is. The data breach settlements provide a static value of similar data while the expert estimation and the values from Accounting provide the real data utility value of an organization’s data value. Staying with the banking example and using Severity 3 data, the data’s value is a range between $0.97 and $738. If this bank has 500k customers, that means their static data is worth about $485,000, while the utility value is likely between $26 and $369 million. It is unsurprising that the utility value of data is worth much more to an organization than the static value. After all, data’s value is derived from its utility.
There are more sophisticated approaches for estimating the value of data like using parametric estimating. Parametric estimating allows more control in estimating. For example, in Sara’s estimate, $738 will only represent a small portion of customers, say 15%, even under the best conditions. In parametric estimating, the calibrated internal subject experts will break down the spread of customer revenue and establish ranges for each that can be combined for a whole. This way it can create a more accurate picture of the value.

Regardless of approach, this organization took an important step in understanding that data has value. Presenting this information in a cybersecurity project business case makes the conversation much easier. Now decision-makers can see the value of the data asset and how the project costs relate to protecting that asset. This moves the conversation to a simple ROI discussion: a $400,000 project to secure $26 million in data assets makes the cybersecurity project seem like a bargain. Not to mention it can help an organization avoid the painful cost of data breach remediation, but that is a different valuation.

References:

  1. Pietsch, Bryan, “Largest U.S. Data Breach Settlements with Government Include 3 Insurers,” Insurers Journal, July 23, 2019. Retrieved January 13, 2020, web address: https://www.insurancejournal.com/ news/national/2019/07/23/533657.htm.
  2. Armerding, Taylor, “The 18 Biggest Data Breaches of the 21st Century,” CSO Online, December 20, 2018. Retrieved January 13, 2020, web address: https://www.csoonline.com/article/2130877/the-biggest-data-breaches-of-the-21st-century.html.
  3. Ibid.
  4. Hubbard, Douglas, W., How to Measure Anything, May 2007, pp. 210 – 214. More broadly, Part III, Measurement Methods.
  5. Ibid, pp. 204-210.
This story first appeared in the June 2020 issue of CISO MAG. Subscribe to CISO MAG

About the Author

Ray K. Ragan is an expert in leveraging technology for mass communication and collaboration in both military and civilian environments. He successfully changed state law to give Veterans parity in small business, mobilized voters to unseat an incumbent, and as a Service member, engaged the enemy in the public information space. Ray holds a Master’s degree in Administration (M.Ad) from Northern Arizona University with an emphasis in Project Management and a Certificate in Strategic Decision and Risk from Stanford University.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

Demystifying Cyber Insurance to Enable Adoption

cyber insurance, Axio for SolarWinds Impact

The top three identified obstacles to cyber insurance adoption remain “not understanding exposures” (73%), “not understanding coverage” (63%), and “cost” (46%), according to Advisen’s 2019 Cyber Insurance Market View survey. These obstacles are quite similar to general insurance obstacles of the past. In the 1850s, boiler explosions were occurring at the rate of one every four days. Despite thousands of boilers in operation, there was widespread ignorance about the causes of boiler explosions. It was generally assumed that boilers would explode resulting in severe injuries or loss of lives. However, a few, namely the future founders of The Hartford Steam Boiler Inspection and Insurance Company thought otherwise, and brought coverage innovation that reshaped the insurance market.

By Jack Kudale, Founder and CEO, Cowbell Cyber

Cyber Incidents: Underinsured with Exploding Risk Exposures

A cyberattack takes place every 39 seconds, for a total of 750 million worldwide per year. Cyberattacks come in many forms: malware, phishing, SQL injection, denial-of-service, ransomware, cryptojacking, man-in-the-middle, zero-day-exploit, and many more.

From the 2013 Target breach that resulted in the CEO resignation to the exposure of 56 million debit and credit cards due to a breach at Home Depot, or the 2018 Marriott incident that revealed personal details of 500 million users, and now the series of ransomware attacks on cities and businesses, the impact of cyber incidents is significant. Impacted companies had procured cyber insurance in the hundreds of millions, yet they reported breach-related expenses way above their elected coverage. They also faced broad consumer-driven class-action lawsuits that lasted for years.

These cases illustrate the need for thoughtful deliberation when deciding how much cyber insurance to buy. The decision is no trivial matter, and the responsibility should rest squarely with the CEO and the Board of Directors.

The Need for Risk Observability

Cyber insurance contracts should be contingent on the level of cyber protection (external and internal) deployed by the insured organization. Insurers’ inability to observe an organization’s internal protection efforts has posed significant challenges to cyber insurance. The observability gap is an even bigger challenge for claims and the near impossibility to correlate losses to a specific cyber incident. There is a dire need for adequate risk observability.

Businesses, especially in the small and mid-size market, are under-insured for cyber liability, primarily due to the lack of insights into risk and adequate quantification of exposures that are required to obtain insurance. There is also a myth that only large organizations get targeted by cybercriminals. This misperception is fueled by only large company data breaches making the news headlines and regulations carving small businesses out of the requirement to report breaches unless they process personal health care information (medical records) or personally identifiable data that are regulated (credit card, Social Security Number, etc).

According to Gartner, businesses invested upward of $125 billion in 2019, in security tools that are mostly focused on threat prevention and mitigation. By comparison, cyber insurance premiums are estimated at about $5 billion, or 25 times less. As security expenditure shifts from prevention and mitigation to response and recovery, there is an opportunity to not only measure the severity (financial impact) of cyber events but also their probability (% likelihood). With probability and severity data, threats become insurable and can be mapped to risk exposure and insurance coverages.

Continuous Risk Assessment for Continuous Underwriting and Resiliency

Businesses should view the cyber insurance application process as an opportunity to assess their risk exposures. The cyber environment of modern enterprises changes continuously: new technologies, new business initiatives that modify the level of exposure or the type and quantity of data processed. For fast-growing businesses, the number of regulated records under management might double in a year. Every time a business’ cyber policy lags the state of the business, there is an opportunity for expenses and liability costs in the aftermath of a cyber incident to be significantly higher than the aggregate limit and sub-limits in the cyber policy in force. Insureds (enterprises) need to continuously re-evaluate risks to be covered; insurers need to update coverage accordingly — continuous underwriting is becoming imperative for cyber insurance.

Continuous risk assessment and continuous underwriting benefit insureds and insurers equally:

  • Coverage remains aligned with the enterprise risk exposure.
  • Continuous risk assessment can proactively feed into the enterprise cybersecurity strategy rather than a limited exercise that informs a once-a-year policy renewal process.
  • For insurers, risk and exposure accumulation are reduced.

Most importantly, with always up-to-date coverage, businesses gain the peace of mind that, in the unfortunate event of a cyber incident, their insurance will adequately cover incident-related expenses, allowing them to recover faster to normal operations and minimizing the disruption to their business. As such, continuous underwriting is critical to achieving greater cyber resiliency.

Demystifying Cyber Coverage

For effective protection and cyber risk transfer, businesses should consider the following when evaluating cyber insurance:

Standalone cyber coverage – Compared to coverage bundled in Errors and Omissions (E&O), standalone coverage brings clarity over what’s covered. Cyber coverage usually includes security breach expenses, regulatory fines, public relations, notification expenses, extortion threats, computer & funds transfer fraud, social engineering, business interruption with aggregate and sub-limits.

Individualized policy – Every enterprise has its own unique cyber environment and risk exposure. Loss mitigation in the aftermath of an incident is dependent on coverages selected, aggregate and sub-limits, deductibles, and other parameters. Coverage should also be individualized based on the business risk appetite and risk transfer strategy.

Coverage options available – Insurability gaps have been increasing due to new technologies: cloud migration, new architectures, AI, IoT—as well as new regulations–EU GDPR, CCPA. The inclusion of innovative coverage for cloud workload and social engineering, for example, will help close the gaps. Enterprises need clarity over technology deployed and seek comprehensive coverage aligned to their risk footprint.

State-admitted insurance programs – Insurance programs are regulated at the state level. Fees and forms of state-admitted insurance products have been reviewed and approved by the state insurance commissioner. Most important, admitted insurance products are backed by the state’s guaranty fund if the insurance carrier becomes insolvent. In this case, the state will pay claims on admitted products up to a state-specified limit.

Redefining Cyber Insurance for the 2020s

As the digitization of every industry sector accelerates, cyber is one of the top risks facing many businesses in the 2020s. As a starting point, there is a significant opportunity for insurance professionals to demystify how cyber coverage contributes to the resilience of businesses of any size. But threats and technology will continue to evolve; insurers and security professionals have the opportunity to collaborate and to deliver technical and financial protections that complement each other while accelerating innovation on risk exposure and risk quantification.

A true innovation in cyber will go beyond the move to standalone and individualized coverage. Continuous risk assessment supports innovation across all three insurance pillars: underwriting, distribution, and claims. We already have examples of monthly construction reporting forms or annual true-up aligned to payroll for workers’ compensation. In 2020, a century and a half later, observability and customized coverage are becoming a reality, this time for cyber.

This story first appeared in the April 2020 issue of CISO MAG. Subscribe to CISO MAG

About the Author

Jack Kudale is a 25-year enterprise software veteran who founded cyber Insurance startup, Cowbell Cyber in 2019, with an aim to make enterprises more insurable in cyber liability. Previously, he led three venture-backed Silicon Valley cybersecurity and data analytics startups after a long stint as an executive in charge of distribution at a Fortune 500 software company.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Mamba Ransomware is Weaponizing DiskCryptor: FBI

Bitcoin, Ransomware Attacks

The FBI is warning users and organizations about the Mamba ransomware that is targeting various entities including local governments, legal agencies, transportation services, technology providers, industrial, commercial, manufacturing, and construction businesses. In a security advisory, the FBI stated the Mamba ransomware is abusing the DiskCryptor – an open-source tool to encrypt files, drives, and operating system. Also referred to as HDDCryptor, the Mamba ransomware is active for the past five years.

Ransomware operators globally succeeded in targeting popular organizations and forcing ransom payments. The Mamba ransomware, used in 4.8% of cyberattacks, was listed as one of the top ransomware variants in Q1 of 2020. The operators behind Mamba misused the company’s content before encrypting the data and holding it hostage,  threatening to post it unless the target agrees to pay.

How Mamba Ransomware Works  

  • Mamba ransomware often abuses freeware or open-source software like DiskCryptor to restrict victim access.
  • The ransomware encrypts the victim’s hard drives by a modified bootloader. It can encrypt resources in network shares like folders, files, drives, printers, and serial ports.
  • Once encrypted, the system displays a ransom note including the actor’s email address, ransomware file name, the host system name, and a place to enter the decryption key.
  • Victims are instructed to contact the actor’s email address to pay the ransom in exchange for the decryption key.

Mamba Ransom Note

Image Courtesy: FBI

Mamba’s Limitation

The FBI also revealed a weak spot in the Mamba ransomware encryption process that could help victim organizations recover their corporate data without paying any ransom.

As stated earlier, Mamba ransomware relies on DiskCryptor to encrypt victim systems which require the system to restart and add necessary drivers within two minutes. While the encryption key and the shutdown time variable are stored in DiskCryptor’s configuration in a plaintext file myConf.txt, a second restart happens after the encryption process two hours later. The FBI claims that this two-hour time gap is a chance for the victims to decrypt their locked files by paying the ransom.

“If any of the DiskCryptor files are detected, attempts should be made to determine if the myConf.txt is still accessible. If so, then the password can be recovered without paying the ransom. This opportunity is limited to the point in which the system reboots for the second time,” the FBI said.

Mamba’s Key Artifacts

Mitigation Measures                                         

The FBI also recommended certain security measures to prevent ransomware attacks. These include:

  • Regularly back up data, air gap, and password-protect backup copies offline. Ensure copies of critical data are not accessible for modification or deletion from the system where the data resides.
  • Implement network segmentation. Require administrator credentials to install the software.
  • If DiskCryptor is not used by the organization, add the key artifact files used by DiskCryptor to the organization’s execution blacklist. Any attempts to install or run this encryption program and its associated files should be prevented.
  • Implement a recovery plan to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, secure location (i.e., hard drive, storage device, the cloud).
  • Install updates/patch operating systems, software, and firmware as soon as they are released.
  • Focus on awareness and training. Provide users with training on information security principles and techniques as well as overall emerging cybersecurity risks and vulnerabilities (i.e., ransomware and phishing scams).

FBI on Paying Ransom

FBI stated that it is against ransom payments, as it encourages threat actors to continue their ransomware attacks by targeting other companies. The agency urged users and organizations to report ransomware incidents to the FBI’s Internet Crime Complaint Center (IC3) at https://ic3.gov.

“The FBI does not encourage paying ransoms. Payment does not guarantee files will be recovered. It may also embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware, and/or fund illicit activities. However, the FBI understands that when victims are faced with an inability to function, all options are evaluated to protect shareholders, employees, and customers,” the FBI said.

Related Stories:

Malware Intrusion Disrupts Honeywell’s “Limited” IT Systems

Armor Piercer

On March 23, Honeywell, a well-known U.S.-based industrial tech giant, revealed that it was under a malware attack. The firsthand account states that the intrusion seems to be detected in the early stages of penetration since only a “limited number” of IT systems were disrupted.

Although the IT services have been restored completely and regular work in the office resumed subsequently, an investigation into the incident is ongoing. Honeywell was quick to disclose that there were no traces of attackers being successful in exfiltrating any company or customer data until now. The systems that store customer information were still intact. However, based on the statement: “If we discover that any customer information was exfiltrated, we will contact those customers directly” – it cannot be completely ruled out that some customer data may have been compromised.

Related News:

Chinese Hacking Group “Hafnium” Exploiting Microsoft’s Email Software Server

Honeywell also mentioned that, during the ongoing investigation, they have partnered with Microsoft “to assess and remediate the situation.” Does this have to do anything with the recently detected Microsoft Exchange Server attacks, which have been widely carried out by a Chinese hacking group called “Hafnium?”  If so, then Honeywell will join a long list of researchers, law firms, education institutions, defense contractors, policy think tanks, and NGOs who have been targeted by the same attackers.

We cannot rule out the possibility that a ransomware gang may have tried to infiltrate Honeywell’s IT system. The recently disclosed ProxyLogon vulnerabilities in the Microsoft Exchange Server has opened this door for ransomware operators and proof of this is the DearCry ransomware, which is human-operated and highly target-centric.

CISO MAG reached out to Honeywell to confirm these doubts but no response was received until the time of publishing.

However, Honeywell did reiterate in its statement that the point of entry to all compromised systems has been identified and “have since been secured.” And adhering to the breach guidelines, all respective law enforcement agencies have also been notified.

Related News:

After Hafnium, DearCry Ransomware Targets Microsoft Exchange Servers

Why Zero Trust Model is a Top Priority for Security Leaders Today

endpoint security

Ever since the pandemic hit, companies globally are trying to progress their digital capabilities and rapidly undertaking business transformation initiatives. Despite the revenue declines amid COVID-19, most of the organizations are increasing their cloud security and digital transformation budgets.

Recent analysis from security firm CyberArk revealed that 97% of senior-level security executives stated that cybercriminals are trying to steal one or more types of credentials. While organizations globally are increasing third-party access to corporate resources and moving their digital assets to the cloud for a sustained remote work model, opportunistic cybercriminals are catching up with the situation by increasing their cyberattacks on organizations’ cloud facilities. The analysis, “The CISO View 2021 Survey: Zero Trust and Privileged Access,” found that threat actors are targeting users and organizations that are not adequately protected.

The analysis revealed that security leaders are embracing the Zero Trust model for securing privileged access to the company’s critical data.

Key Findings

  • The most widely reported group facing increased attacks is end-users – including business users with access to sensitive data. A majority of respondents (56%) report such users as being increasingly targeted by attackers.
  • Attacks are also on the rise against senior leadership (48%), third-party vendors and contractors (39%), and DevOps and cloud engineers (33%).
  • Widespread increases in credential theft attempts were reported for personal data (70%) and financial systems and data (66%). This is clear evidence of attackers’ interest in gaining high-value access – access to highly sensitive systems that are often held by end-users rather than administrators, for example.

What is a Zero Trust model?

Zero Trust is a security model that recommends a strict identity verification process in an organization. The model directs that only authorized devices and users can access the company’s critical data, applications, and services. First introduced in 2010 by security analyst John Kindervag at Forrester Research Inc., the Zero Trust model protects users against advanced threats online.

Embracing Zero Trust Model

The model has become a primary requirement for modern-day digital transformation and network security. Now, several security leaders implementing the Zero Trust model in their organizations to boost their enterprise systems and data security.

The analysis found:

  • Nearly, 88% of respondents said adopting more of a Zero Trust approach is very important or important.
  • To implement a Zero Trust model, the top priority was controls focusing on Identity and Access Management (IAM), chosen by 45% of respondents.
  • Several types of IAM controls were favored to protect access to sensitive systems. Just-in-time access controls were highly valued, with 87% of respondents saying reducing standing privileges is an important or very important aspect of Zero Trust.
  • Endpoint security remains an operational challenge for 94% of respondents – 46% said that installing and maintaining agents made endpoint security challenges.
  • Over 86% said user experience optimization is important or very important, highlighting a need for security tools and policies that will not be bypassed or ignored due to security fatigue.

Cybersecurity experts say…

Commenting on the Zero Trust model approach, Mike O’Malley, Senior Vice President, CyberArk, said, “Reverberations from the SolarWinds attack continue to underscore the need to protect privileged credentials and break the attack chain to organizations’ most valuable assets. As new identities multiply across the enterprise, this survey emphasizes the importance of a Zero Trust-based approach to Identity Security. For security leaders seeking to mitigate the risks of spear-phishing, impersonation attacks, and other forms of compromise, we believe the peer experiences captured in the CISO View reports will serve as an invaluable tool, no matter where their organization is on the Zero Trust maturity curve.”

Companies of All Sizes Now Recognize That They Are Potential Targets

Seth P. Berman leads Nutter’s Privacy and Data Security practice group and is a member of the firm’s White Collar Defense practice group. As a data privacy attorney, corporations and their boards engage Berman to address the legal, technical and strategic aspects of data privacy laws and cybersecurity risk, and to prepare for and respond to data breaches, cybercrime, and other cyberattacks. In addition to being a cybersecurity attorney, Berman also represents clients in white-collar criminal matters and has particular expertise in conducting cross-border internal investigations and in the data privacy implications of such matters.

In an exclusive interview with Augustin Kurian of CISO MAG, Berman shares his thoughts on several things including the landscape of cyber insurance, cyberattacks on the health care industry, and data protection laws like CCPA.

 

Tell us a bit about your journey from becoming an Assistant United States Attorney in the District of Massachusetts, where you investigated and prosecuted economic and computer crimes — to now at Nutter.

I have had an atypical career as a lawyer in the years since I left the US Attorney’s office in 2007. At that time, very few firms had lawyers devoted to privacy and cybersecurity issues – there simply wasn’t enough business in the area for firms to hire lawyers who were so specialized. Thus, instead of going to a law firm, I joined a digital forensics consulting company that specialized in helping lawyers and their clients respond to computer crime and hacking incidents. I eventually moved to London with that consulting company and oversaw their expansion into European and Asian markets, advising international corporations on preparing for and responding to hacking and data breaches. After I returned to Boston, I decided to join a law firm – Nutter – once the market had grown to the point that it was possible to practice as a lawyer specializing in cybercrime, privacy, and data security.

In the years since you first started prosecuting computer crimes, how has the industry evolved?

I first started prosecuting computer crime cases more than 20 years ago. In that time, computer crime has gone from a niche concern to one of the most common types of non-violent criminal activity today.  When I first entered the private sector in 2007, IT departments were focused on cybersecurity, but CEOs and General Counsels did not view it as a significant concern. Nowadays not only do CEOs and GCs routinely list cybersecurity as, among their biggest worries, but the issue is also widely considered one that requires board-level oversight. As a result, a whole industry of technical experts, consultants, and lawyers has grown up to assist corporations in navigating these issues.

The cyber insurance landscape is booming and constantly changing. However, there is a complexity that still makes cyber insurance coverage intimidating to many. What are the key obstacles to writing and issuing cyber insurance?

Cyber insurance is still a relatively new product. As a result, there is an unusually high number of uncertainties for all players in the market. For example, there are well over 100 years of claims history for fire insurance, making it relatively easy to determine the likelihood of loss, the amount of coverage needed and the typical issues that might arise later impacting coverage. By contrast, there is a very little history of cyber insurance claims. Thus, it is not clear how much cyber coverage a company needs; how likely it is that a company will suffer a breach; or even whether an as-yet-unthought-of new type of attack will even be covered by a cyber insurance policy. The limited claims history is compounded by an even bigger problem – there is little reason to believe that past experience with cyberattacks is predictive of the scope or severity of cyber claims in the future. Given the continued rapid increase in the sophistication and scope of cyberattacks, it is likely that the next few years will see much larger claims than the last few – perhaps even a storm of claims impacting many companies all at the same time.  

There seems to be an increasing number of cyberattacks in the health care industry.  What is driving this trend? 

The health care industry presents a tempting target for at least two reasons. First, health insurance information is currently more valuable on the black market than credit card information, which means that health care companies hold a valuable asset that hackers are trying to steal. Second, because doctors and hospitals are routinely dealing with life-threatening situations, a computer failure that impacts basic patient care can quickly lead to a life-threatening emergency. This real-world urgency makes hospitals and health care entities very tempting targets for attackers, who want to leverage these dire consequences for their extortionate demands.

How do you see the uptick in ransomware, as compared to, say, two years ago?

Ransomware has become a particularly easy way for hackers to quickly make money. Indeed, ransomware doesn’t even require any real hacking expertise anymore. Ransomware can now be purchased on the dark web just like any other software. There are even ransomware-as-a-service providers who will provide the software and technical services and split the proceeds with the individuals who select the targets and send the phishing emails that initiate a ransomware attack. The attackers have also gotten more discerning about their targets and changed their business model. A few years ago, it was common for a vast number of individuals to be targeted at random and asked for small ransoms – often only a few hundred dollars – to recover their personal computers. Now, ransomware attackers are more typically targeting large organizations such as cities, towns, or hospitals – and demanding much greater ransoms, knowing that many of the attacked entities will find it far cheaper to pay hundreds of thousands or even millions of dollars in ransom than to go dark while attempt to recover their data and systems on their own. Until society figures out how to cut off the flow of money to ransomware attackers, this problem is only going to get worse.

From which types of businesses (small, medium, large) do you see the most increase in awareness of the need for improved cybersecurity? (Nearly half of all cyberattacks in the U.S. target SMBs).

The initial wave of well-publicized corporate hacking targeted very large companies. Sometimes hackers sought to steal credit card data, sometimes they sought merely to disrupt a company, and sometimes they were seeking valuable intellectual property. Regardless of their goal, the hacks that became public almost invariably targeted large companies. This led to a popular perception which was common as a few years back had been that only large companies had to worry about hackers. That perception has changed dramatically in the last few years. Companies of all sizes now recognize that they are potential targets. As a result, small and medium-sized businesses are now beginning to invest in cybersecurity, and – at least as importantly – starting to establish the governance and management structures necessary to ensure that cybersecurity is taken seriously.

What kinds of policies should companies devise so that they are better prepared for cyberattacks?

Too many people think of cybersecurity as a purely technical problem – one that can be solved with better firewalls, better threat detection, or some other new tool. Though all of those things are in fact crucial to good security, tools alone are not the answer. Governance is at least as important as new tools – after all, if the CISO isn’t getting the budget and attention needed from senior management and the board, the new tools either won’t be bought or won’t be fully implemented for fear of “breaking” IT. In the end, good planning, testing, employee education, as well as a culture of security all the way to the CEO is as important to improving cybersecurity as the latest firewall, SIEM, PAM or DAM.

What do you think is the next trend in the industry?

I fully expect hacking and other cyber threats will continue to grow and evolve, and I expect security rules and regulations to continue to evolve with them. Additionally, I am keeping my eye on another trend – the increasing number of jurisdictions that have privacy laws – laws that limit what companies can do with personal data they hold – in addition to the more traditional security rules and regulations. Europe led the way in this with its General Data Protection Regulation (GDPR), and the baton has now been taken up here in the US by California with its California Consumer Protection Act (CCPA). Several other state legislatures are considering similar legislation, and there are competing proposals in Congress addressing some of the same issues. As a result, I expect that over the next few years those of us in the industry will be spending almost as much time thinking through privacy issues – whether governance and systems are designed to comply with privacy laws – as we do thinking about security – how to prevent others from stealing or corrupting that data.

_______________________________________________________________________

Augustin KurianAbout the Interviewer

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

 

CISO MAG’s March issue on Women in Cybersecurity is out. Preview hereSubscribe now!

 

 

Wait! Read This Before You Post a Story on Instagram

Instagram

Instagram is currently hands-down one of the most popular photo-sharing platforms in the world. With more than 1 billion users (1.16 billion as of Q3 2020) of which 500 million are active daily users posting “Stories” – one of Instagram’s most utilized features – it is topping all charts. The user and gender demographics of Instagram also make it a hotspot for marketers. According to recent statistics, 70% of Instagram users are aged under 35, and 51% of the total are from Venus (pun intended; we mean female). Also, a whopping 130 million users tap on shopping posts every month, and it does not end there. 81% of users say that they use Instagram to research products and services.  But have you ever wondered how do these product and service marketers and business accounts reach your feed in the first place? We have an answer; you may not like it, but you need to hear it. It is because Instagram shares 79% of users’ personal data with third parties.

Instagram most data invasive app
Image Credit: pCloud

Surprisingly, TikTok, which has been banned by India and came under severe criticism of the former U.S. President Donald Trump, shares only 36% of data with third parties and ranks 12th on the list.

 Key Highlights 

  • 52% of all the apps share your data with third parties.
  • Instagram shares 79% of your data including browsing history and personal information with others online.
  • When it comes to collecting your data, social media platforms are the worst offenders. On average 80% of apps use your data to market their products in their respective apps.
  • Netflix, Signal, Microsoft Teams, Skype, and Clubhouse top the list of safest to use apps.

Instagram: The Most Invasive App?

Did all these numbers break your heart? Well, if not, then be prepared for one more strike of lightning. A study by cloud storage platform, pCloud, has dubbed Instagram as the most invasive app. Instagram shares this title with its parent company Facebook since both use 86% of its users’ data to sell more of their products and serve relevant ads to them on behalf of their clients.

Instagram most data invasive app
Image Credit: pCloud

Also, when it comes to the percentage of data shared with third parties and used to target users for marketing purposes, Instagram again takes the first spot here with 62%.

Instagram most data invasive app
Image Credit: pCloud

Mirror-Mirror on the Wall, Who is the Safest of them All?

pCloud’s study was mainly based on the new Apple privacy labels that are featured in the App Store and aimed at finding how and where users’ private data is being gathered and used. In doing so, the company also found the safest apps which collect the least data from users and/or share or use it for marketing purposes.

Statistics revealed that privacy-centric messaging apps like Signal and Telegram, video conferencing and calling platforms like Zoom, Skype, and Microsoft Teams as well as streaming giant Netflix top the list of the safest to use apps. Clubhouse, Google Classroom, Shazam, Etsy, BooHoo, Amtrak, Shop, and IRS2Go are the list of other apps that do not share any data with third parties.

Related News:

WhatsApp vs Signal vs Telegram: Which is More Viable and Secure?

Data Scraped from Instagram, TikTok and YouTube Exposes 235 Mn Social Media Profiles

The Cancer in the Health Care System

Health care data breaches

The red and white webpage with the message that reads “Ooops, your files have been encrypted!” with a digital timer running on the left is something that still scares doctors across the globe. Even weeks after the infamous WannaCry ransomware attack crippled organizations and health care facilities across the world, doctors were still resorting to documenting patient history with a pen and paper. Wannacry was an incredibly sophisticated ransomware attack that made a huge impact, infecting nearly 200,000 computers across 150 countries, with total damages ranging from hundreds of millions to billions of dollars. It also reaffirmed the fact that cyberattacks have huge real-world consequences, in this case including canceled outpatient appointments, elective and emergency admissions to hospitals, accident, and emergency room staffing, and even avoidable deaths. WannaCry is just one example and over the next two years, the attacks on the health care sector continued. In fact, the health care sector is the most breached industry in the world. According to HIPAA, between 2014 and September 2019, nearly 198 million health care records were breached. But why? Why is the health care sector attacked so frequently? What motivates criminals? Why do hackers find health care data so lucrative? Why aren’t we able to stop it?

By Augustin Kurian, Sr. Feature Writer, CISO MAG

What makes health care data valuable?

One of the key reasons why health care data is so frequently attacked is because it is good business for criminals. On the black market, personal health information (PHI) fetches more money and is more valuable than financial details or even regular personally identifiable information. In the survey report Health care Cyber Heists in 2019, Carbon Black found the health care sector being targeted because of how lucrative PHI is when compared to other personal data like credit card numbers. It’s said that personal health information is worth three times more than other personal information.

This is because, unlike a credit card or personal details which can be changed whenever the user spots any discrepancies, the personal health history of any person doesn’t change—their illnesses, ailments, surgeries—these remain the same for the most part of one’s life. “Health information never changes, and can be used by cybercriminal groups for extortion or compromise,” asserts the Carbon Black report. Apart from this, with access to one’s medical records, criminals can target victims with scams and frauds that leverage the information in a victim’s medical history. Another use of stolen medical records is to gain access to prescriptions for their own use or resale. There are some reports of criminals creating fake insurance claims to purchase and resell medical equipment. But it gets even scarier.

What makes health care data vulnerable?

Innovation in technology has brought everything under the digital umbrella. Harking back to the Hyponnen Theory, “If you plug something into the electrical grid in the future, you will also plug it into the internet grid” and “whenever an appliance is described as being smart, it is vulnerable.” The rule applies to the health care sector as well. Yury Namestnikov, head of global research and analysis team for global cybersecurity research firm Kaspersky, pointed out at the recent Cyber Security Weekend gathering in Yangon, Myanmar that “76% of devices in health care facilities in the Philippines were infected by malicious code.” Even though most of these devices were not breached by attackers and were a result of employees connecting unsecured USB sticks to these machines, these inherently led to massive vulnerabilities. The capabilities of these malicious codes are alarming. In July, U.S. Department of Homeland Security’s CISA issued a warning about several GE medical machines, including GE Aestiva 7100, 7900, MRI; GE Aespire 7100, 7900, 100, Protiva, Carestation, View; GE Aisys, Aisys CS2 Avance, Amingo, Avance CS2; and GE Carestation 620, 650, 650c. According to CISA, “vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.” GE released updates for these devices and put forth mitigation methods along with CISA.

The proliferation of IoT devices in the medical field must be credited with the increase in the number of attacks. “The health care of the future is going to look very different from the health care of today. We can begin to expect to see the implementation of many IoT devices into health care and with every device comes extreme risks, not only of the device being hacked and health care data exposed but also a great risk of the hacker gaining control of the IoT device and endangering the patient’s life,” said Dr. Carmit Yadin, CEO of ArcusTeam, an IoT security firm. In October, the FDA identified 11 vulnerabilities in pacemakers and insulin pumps which allowed “anyone to remotely take control of the medical device and change its function, cause a denial of service, or cause information leaks or logical flaws, which may prevent device function,” stated the FDA. Ransomware campaigns and phishing emails are a few of the key threat vectors in the health care industry. According to the report obtained by Egress on data breaches on the Information Commissioner’s Office (ICO) in 2019, nearly 60 percent were caused by human error, where health care suffered the most. A report titled Assessment of Employee Susceptibility to Phishing Attacks at the US Health care Institutions, authored by Dr. William Gordon of Brigham and Women’s Hospital and Harvard Medical School in Boston stated that many U.S. health care organizations remain vulnerable to phishing attacks. William specified that when the researchers sent simulated phishing emails, nearly one in seven of the emails were clicked by employees of health care organizations. The survey also stated the importance of employee awareness of the risks associated with phishing emails. “Cybersecurity is a really important issue for hospitals and health care organizations and it’s only getting more important. One of the biggest risks for them is their own employees and it’s manifested through a phishing attack,” said Gordon.

Application security is also among the key threat vectors for the health care sector. The breach portal of the U.S. Department of Health and Human Services Office for Civil Rights has listed more than 580 breaches (at the time of writing this article) within the last 24 months that are currently under investigation by the Office for Civil Rights, where web application security took up a huge chunk of cyberattacks. According to SecurityScorecard, “The health care industry’s adoption of mobile technologies occurred in response to patient requests. Digital transformation and interoperability led to ad hoc and homegrown application creation. As such, the rapid adoption of new technologies created a patchwork quilt based on functionality rather than security.”

This story first appeared in the January 2020 issue of CISO MAG. To read the full story, click here. Subscribe to CISO MAG

Augustin Kurian

About the Author

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.