Home Blog Page 103

“Introduce cybersecurity as a career path, and actively recruit”

As the world celebrated womanhood and women’s contribution to society on International Women’s Day, we at CISO MAG decided to devote the month of March to all the women in cybersecurity. The purpose of this article is to highlight the role of women in the industry and address several issues they face. This was in the light of the revelation that women’s representation in cybersecurity has been less than a quarter and has remained that way for almost a decade, if not more. Most of the problems faced by women can be traced back to the earliest days of their education, where stereotypes begin.

Here’s what Carolyn Crandall, Chief Security Advocate and CMO, Attivo Networks, has to say about gender discrimination and career opportunities in cybersecurity:

Gender discrimination: Working in the tech industry as a woman is inherently difficult, even with a deep technical background or degree. Sadly, I’ve found that perceptions about women in the cybersecurity world are even harder to break. This can range from how people interact with me, to acceptance as a conference speaker, to being turned down as a volunteer contributed writer, despite being more qualified than many of their current male writers. I am not a person who typically points out unfairness, but sometimes it can be blatant. I have worked hard in my career to become a CMO that truly understands technology. I speak regularly at conferences, write technical bylines, regularly blog on technology, and create and deliver a significant amount of content on product and solution offerings. However, it is irritating when certain organizations automatically rule me out for opportunities simply because I am a female CMO.

I encourage all women to walk with swagger and believe that they do belong in cybersecurity. I find that doing this, it makes it easier to gain acceptance. I also love working at Attivo Networks as I have not once felt that people think twice about gender, race, or religious beliefs. Everything is all based on the impact you can make. It’s quite refreshing and appreciated.

Opportunities: New and diverse perspectives are the key to innovation, and it is critical for the advancement in the cybersecurity and technology spaces. I am a strong advocate both in my work environment as well as in volunteer activities to help educate and drive the advancement of women in technology. Attivo Networks has been aggressive in its college graduate hiring program and I have taken this opportunity to bring several millennial women on to the team. I often speak with undergrad and MBA students at Santa Clara University and I have spoken at When She Speaks, WITI, and most recently at the Silicon Valley TIE CMO Inflect event. This helps me build relationships, introduce cybersecurity as a career path, and actively recruit. For our newly hired recruits, we conduct weekly training on cybersecurity, our technology, and how to apply our technology to solve cybersecurity issues.

Beyond comfort zone: We also encourage the team to participate in external training forums like (ISC)2, SANS, ISSA, and Cybrary. Notably, my team is ¾ women. I also encourage the women on the team to stretch beyond their comfort zone. I have found that many women want to master an area before they commit to advance. They sometimes tend to shy away from jobs or projects where they don’t have all the skills, whereas their male counterparts tend to be willing to go out on a limb and apply for jobs they are not fully qualified for. Throughout my career, I have always sought out jobs that had scared me in some way.


Carolyn holds the roles of Chief Security Advocate and CMO at Attivo Networks. She is a high-impact technology executive with over 30 years of experience in building new markets and successful enterprise infrastructure companies. She has a demonstrated track record of effectively taking companies from pre-IPO through to multi-billion-dollar sales and has held leadership positions at Cisco, Juniper Networks, Nimble Storage, Riverbed, and Seagate.

She is recognized as a global thought leader in technology trends and for building strategies that connect technology with customers to solve difficult operational, digitalization, and security challenges. Her current focus is on breach risk mitigation by teaching organizations how to shift to an active security defense that prevents, detects, and derails cyberattacks.

Disclaimer

Views expressed in this article are personal.

CISO MAG’s March issue on Women in Cybersecurity is out. Preview hereSubscribe now!

Everything You Need to Know About Dictionary Attacks

User Verification Policy, zero trust approach

Cybercriminals leverage several ways to illicitly obtain users’ login credentials and break into their systems. At the same time, poor password practices of users like reusing old passwords or using weak passwords make a hacker’s job easy. Despite continuous advice on the importance of keeping strong login credentials, most users end up having the same passwords for multiple accounts.

 By Rudra Srinivas, Senior Feature Writer, CISO MAG

As per the 2021 Credential Exposure Report, over 60% of the credentials were reused across multiple accounts, making it easy for an attacker to misuse one stolen password to hijack other accounts. It was found that most users are not creating a new password after expiry, rather using the old one with minute changes. The most common password found was “123456,” followed by “123456789” and “12345678.” “Password” and “111111” showed up more than 1.2 million times each.

This kind of poor password hygiene allows hackers to easily compromise users’ credentials by leveraging password guessing techniques through brute force attacks or dictionary attacks.

What is a Dictionary Attack?

A dictionary attack is a trial-and-error tactic used by attackers to decode passwords, passcodes, and other forms of login credentials by leveraging automated software tools.  In dictionary attacks, cybercriminals use a predefined dictionary list of possible combinations of passwords/passphrases, or stolen credentials from previous data breaches, to crack victims’ passwords. Hackers often exploit commonly used passwords like 123456, qwerty, password, and admin, which are rated as the most frequently used passwords by millions of users globally. It would hardly take seconds for an attacker to crack such passwords.

How does a Dictionary attack work?

Cybercriminals do their research before launching a dictionary attack. Users often use easy-to-remember passwords/passphrases involving names of their children, favorite celebrities, hobbies, etc. Unfortunately, users also share this information on social media platforms, allowing hackers to snoop into users’ interests and prepare a possible combination of passwords list. Hackers use advanced password-cracking software to crack possible combinations by generating various character alterations to match the victim’s password.

How to prevent Dictionary Attacks

  • Enable the automatic lock-account feature to avoid multiple intrusions from threat actors.
  • Use two-factor or multi-factor authentication for all your online accounts.
  • Keep long and strong passwords with special characters. For example, a password like “Password1” can be easily cracked, but one like “P@$$$word” is not so easy to guess.
  • Change your passwords regularly and never reuse them.
  • Don’t overshare your interests on social media platforms.
  • Use different passwords for different accounts.

Conclusion

Though a dictionary attack may be a serious security threat, it is powerless when people use strong passwords in the first place. Remember, our poor password hygiene would be a hacker’s greatest advantage. So, if your password is easy-to-guess, change it ASAP before any attacker cracks it in a snap!

Related Story: 6 Practices to Strengthen Your Password Hygiene

About the Author

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

India Leaps Ahead in API Economy, Yet Lags in API Security: Report

Application Security

The API economy is on a growth trajectory in India with increased digitalization. As more Indian consumers began to work from home last year, they started expecting richer digital experiences. In response, Indian companies offering digital services or digital content sped up their digital transformation efforts in the past year. As applications were increasingly deployed on multiple clouds, organizations began moving towards an API-driven economy; APIs (Application Programming Interfaces) interconnect all the applications residing in different clouds. And API orchestration between apps on different clouds makes the digital experience seamless for consumers. Large applications are also broken up into loosely coupled microservices, which are interconnected by APIs. However, the F5 annual survey titled the 2021 State of Application Strategy report reveals gaps in API security, especially in India.

By Brian Pereira, Editor-in-Chief, CISO MAG

“By 2023, the number of applications that will be born in the cloud (and data centers) will reach 3.7 billion. In 2018, it was 702 million,” said Keiichiro Nozaki, Senior Marketing Evangelist, APCJ at F5.

API Security in India

 

API surge in India due to application modernization

India leads globally as well as regionally, in terms of application modernization.

Per the survey, 82% of Indian respondents said they are adding a layer of APIs to enable modern user interfaces and/or participate in ecosystems, but not refactoring (modifying the application code itself). So, the API deployment is in “full bloom” in India.

The other options presented to the respondents were:

  • Moving to the public cloud (lift and shift), but not modernizing.
  • Refactoring – modifying the application code itself.
  • Adding modern application components to enable modern user interfaces and/or participate in ecosystems but not refactoring.

Gaps in API security

In the context of Open API, the APIs are publicly accessible on public clouds. So, in this scenario, API security becomes crucial. However, there are gaps in API security.

93% of Indian respondents said they deployed an API gateway. However, only 74% said they deployed API security solutions. Globally, the gap is smaller: 68% of global respondents deployed API gateways and 59% had API security.

“People are aggressively moving to the API architectures that deploy API and do the control and traffic management through API calls. While they may not be prioritizing the idea of how to protect, how to secure those APIs as much as the global average respondents. It is truly great that people are aggressive moving to the API economy in India. However, it is important to ensure that your architecture and the deployment model cover the security portion of this API,” said Nozaki.

API Security in India

However, some believe that the gap for India is much larger than what is shown in the report.

“While the gap here is, you know 74 to 93, in my personal view the gap is much higher because security comes as a strap on, not as a DNA, to most of the Indian organizations,” said Dhananjay Ganjoo, Managing Director, India & SAARC at F5. “And a lot of them spend the money to develop the APP and then (they say) oops! let’s try to figure out how to secure the stack. And that’s what we’re facing in the market in India today. API security is no different —  it’s an afterthought.”

Conclusion

To close the gaps in API security, organizations need to move to a DevSecOps culture, which is commonly known as “shift left” in the development cycle. API developers need to think about security at the beginning of the development cycle. Security lapses could lead to leakage of application data, and exfiltration of customer PII could mar the reputation of companies that deliver digital services. So, API security becomes a crucial consideration in an API economy and for Digital India.

Brian Pereira

About the Author

Brian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 26 years.


EC-Council’s CISO MAG brings to you a webinar on “The Current State of Application Security.” Register Now!

 

REvil Ransomware Hits Acer; Threat Actors Demand $50 Million in Ransom

Ransomware attacks, LockBit Ransomware

Computer manufacturer Acer is the latest victim of a ransomware attack. According to a report, the Taiwanese company has been hit by a REvil ransomware attack, with the attackers demanding over $50 million ransom. It is found that the ransomware operators compromised Acer’s network systems and allegedly shared images of stolen files as proof of compromise. The exposed images included the company’s sensitive documents like financial spreadsheets, bank balance statements, and other private communications with the bank.

What Acer said…

While it is unknown whether Acer paid any ransom to the cybercriminals, the company did not disclose anything about the security incident.

“Acer routinely monitors its IT systems, and most cyberattacks are well defended. Companies like us are constantly under attack, and we have reported recent abnormal situations observed to the relevant law enforcement and data protection authorities in multiple countries. Acer discovered abnormalities from March and immediately initiated security and precautionary measures. Acer’s internal security mechanisms proactively detected the abnormality, and immediately initiated security and precautionary measures,” Acer said.

Possibly a Microsoft Exchange exploit?

Several industry experts suspected that ransomware operators could have launched the attack by exploiting vulnerabilities in Microsoft Exchange Servers on Acer’s domain. This assumption comes after the threat actors behind the DearCry ransomware recently exploited the ProxyLogon vulnerability in their attacks.

REvil in the wild!

Recently, the operators of REvil ransomware, better known as Sodinokibi, have launched an auction website on the dark web, Happy Blog, to sell stolen data from victims who have denied paying the ransom. REvil is auctioning the stolen data of a U.S. food distributor and a Canadian agricultural company, for a starting price of $100,000 and $50,000 respectively.

The threat actor group also made headlines last year when it attacked London-based money transfer service Travelex, demanding a ransom of $6 million in exchange for five gigabytes of its customer data. This attack made large British banks like Barclays, Lloyds Bank, Tesco Bank, HSBC, Westpac Banking, and Royal Bank of Scotland unable to take or process foreign currency orders from customers in branches that rely on Travelex.

Akamai Says Its Phish-Proof Solution Bridges MFA Security Gaps

Akamai MFA

Akamai Technologies, a cybersecurity solutions provider, today announced the launch of Akamai MFA, a cloud-based solution to close the security gaps that exist in the multi-factor authentication technique, which has now become an industry norm. Akamai MFA is a phish-proof solution designed for enterprises to quickly deploy FIDO2 multi-factor authentication without the need to deploy and manage hardware security keys. The solution does so by using a smartphone application that turns the existing smartphones of users into a hardware security key, delivering a frictionless user experience.

The Need for a New Solution

In May 2020, researcher Elmer Hernandez, of Cofense Phishing Defense Center (PDC), discovered a new phishing campaign that could bypass multi-factor authentication (MFA) on Office 365 to access victims’ data stored on the cloud and use it to extort a ransom in Bitcoin. This tactic leveraged the OAuth2 framework and OpenID Connect (OIDC) protocol, which is commonly used by most MFA service providers. Along with a malicious SharePoint link, threat actors could easily trick users into granting permissions to a rogue application.

Soon after, in August 2020, Abnormal Security research found a spike in overall BEC campaigns, which were credited to hackers successfully bypassing multi-factor authentication and conditional access controls. The report pointed that most of these campaigns leveraged legacy applications to ensure the MFA did not hinder these attacks.

Thus, it was time to find a way to block this MFA bypass and fill the security gaps with a new protocol – enter FIDO2 protocol.

Time for FIDO2 Takeover

FIDO2 is a term used for a password-less and user-less authentication open standard developed by the Fast Identity Online (FIDO) Alliance. This is a consortium comprised of technology heavyweights and other service providers. FIDO2 consists of two core components. First is the WebAuthn API, which is integrated directly into browsers such as Chrome, Edge, Mozilla, and WebKit; and second, the Client to Authenticator (CTAP) protocol that provides FIDO2 capable devices an interface for external authenticators via NFC, USB, or Bluetooth.

The current MFA approaches that do not make use of the FIDO2 protocol can be easily manipulated and replayed by attackers using phishing or man-in-the-middle (MITM) attacks. It is now an industry standard and to obtain this level of security, enterprises currently need to distribute and manage hardware keys, which adds additional costs and baggage of “complexity.”

Akamai’s MFA Solution

Akamai designed its MFA in a manner that would deliver a phish-proof, easy-to-use experience using the strongest known standards-based authentication method available, and via a smartphone application in place of a physical security key. The FIDO2 standard used in this case provides end-to-end cryptography and a sealed challenge/response flow, allowing enterprises to get the best multi-factor security without additional costs.

Rick McConnell, President and General Manager, Security Technology Group, at Akamai said, “Standard second-factor push notifications are easily compromised unless enterprises deploy and manage hardware security keys, which adds significant complexity. Akamai MFA delivers all the benefits of FIDO2 standards using a phish-proof push on a smartphone.”

Adding to this, Jay Bretzmann, Program Director, IDC Security Products said, “When it comes to MFA technologies, push is king; nothing is easier, and adding the phish-proof FIDO2 protection makes it secure. Akamai understands the need for low-friction authentication approaches and access technology and is increasingly lending expertise to workplace implementations as we all deal with COVID-19 remote employee realities.”

Akamai MFA, which is deployed on the Akamai Intelligent Edge Platform, can be activated and managed centrally via Enterprise Center. This service integrates with market-leading identity providers, including Microsoft Azure AD, Okta, and Akamai’s Enterprise Application Access. Additional integrations are supported for Secure Shell (SSH) and Windows Login use cases.

For more information on Akamai MFA visit the website here.

Related News:

DDoS Attacks and Credential Abuse Doubling Year-on-Year: Akamai

Is the Co-existence of Security and User Experience in Media Industry Possible?

How COVID-19 Affected the Application Security Space

application security, API, API Security

When the COVID-19 pandemic hit, all businesses were shaken awake by the rapid transmission of this virus. The disruption it unleashed on the global economy was beyond anyone’s comprehension. As they developed overnight responses to ensure business continuity, many were left vulnerable and exposed to security breaches. Amidst the pandemic, while most people work from home, cybercriminals have upped the ante and are not taking any time off. With many employees working remotely and organizations shifting their focus to their employees’ health and safety, security and risk management teams need to be more vigilant than ever before. There is a need for eternal vigilance.

By Rohan Vaidya, Regional Director of Sales – India, CyberArk

The pandemic has impacted industries in several ways:

1. Risks from Self-service Applications

The deployment of self-service applications has become de rigor. Organizations have rationalized help desks to save time and labor. End-users reset passwords and unlock their accounts. They may use multi-factor authentication. It enables them to access apps and other services without adding load to the help desk.

2. Impact on Third-party Vendors

Just-in-time provisioning for third-party users, while looking to mobilize the workforce, has increased the number of third-party vendors. These users are a new challenge since they are outside the company directory and tracking them could be problematic. The attack surface can be reduced through solutions that automatically allow and block access through one-time onboarding. Hence, vendors can gain just-in-time access and just the right amount of access without manual intervention to allow or disallow access.

3. Risks from Remote Working, Learning

With many companies allowing employees to work from home and students now attending virtual classes, virtual private network (VPN) servers have become the lifelines for companies and educational institutions. But security remains a vital concern.

There are concerns that an organization’s lack of preparedness would expose sensitive information on the Internet and also expose the devices to cyberattacks. Users that utilize their personal computers for official duties may put an organization’s security at risk. Thus, employees should be advised against using personal computers for official purposes.


EC-Council’s CISO MAG brings to you a webinar on “The Current State of Application Security.” Register Now!


 

4. Possible Delays in Cyberattack Detection and Response

The functioning of security teams was impacted by the pandemic, making detection of malicious activities difficult, and response complicated. Security patches and updates on systems proved a challenge as the security teams were offsite. Organizations are now forced to study security defenses and consider co-sourcing with external consultants in areas where the key risks are known.

5. Exposed Physical Security

Allowing discretionary work from home, where power supply and Internet connectivity are inconsistent, may force employees to work from public spaces like cafés or friends’ homes. This could expose the endpoints and the confidential information they hold. Working or attending classes from public spaces needs to be checked; firms should leverage technologies to ensure that confidential information is secure on these devices in case of device theft or damage.

6. Pandemics Now Part of Business Continuity Plans

While most big organizations have established a Business Continuity Plan (BCP), the impact of an epidemic and a prolonged one like the current COVID-19 pandemic was never a factor considered in most BCPs. Corporations are now having to rewrite their BCPs and incident response plans to consider epidemics that impact global supply chains. Revised risk assessments are being done to ensure sustainable business processes for minimal disruption in the event of another global catastrophe.

7. Cybersecurity Front

At one stage, it seemed as if the global economy would be brought to its knees due to the pandemic, and by any measure, it caused the considerable strain. The global recession has begun to bite, with most countries seeing their economies contracting. A significant number of organizations have downsized during the pandemic, and this strategy includes downsizing business lines they perceive as non-critical, which may include cybersecurity operations. However, this short-term plan might prove “penny wise and pound foolish” in the long haul. It can result in increased attacks on the organization. Hence, it has become imperative for organizations to update their BCPs and remote working policies/practices while prioritizing cybersecurity during the post-COVID-19 re-strategizing process.

Conclusion

During the pandemic, organizations are mostly focused on business continuity and employee health. The way forward would be to take pre-emptive steps to fix any bugs that would arise and to ensure uninterrupted operations, resilience, and security. The elements who attack are looking for chinks in the organization’s operations and security.

COVID-19 has changed lives for eternity with new formats of working, new cybersecurity issues, new policy proposals, hygiene, and a laundry list of other items. A joint effort on all fronts is a necessity. It is now apparent that post-COVID-19, organizations need to re-look at their cyber risk management measures.

While apps have ensured convenience for everyone, the legacy of security issues continues to dodge them. The COVID-19 emergency has only given more opportunities for malicious elements to disrupt everyday lives. That’s why security companies and cybersecurity professionals must double up with greater use of tech solutions to ensure a future of more significant and safer possibilities.

This story first appeared in the October issue of CISO MAG. Subscribe now!

About the Author

As the Regional Director of Sales – India at CyberArk, Rohan Vaidya is responsible for managing sales operations and profitability of the business in the sub-continent. He joined CyberArk in May 2016 with more than 18 years of experience in successfully building brands and businesses in India and the wider Asian region.

Rohan has served in a variety of capacities in an expansive career including sales, marketing operations, technical consulting, and business management with mostly multinational organizations in India, Southeast Asia, and the Middle East. His track record for engaging deeply and productively with clients has delivered measurable success in industries including telecommunications, financial services, publishing, media, IT, and IT-enabled services (ITES).

Prior to joining CyberArk, Rohan was the Head of Region for the Indian sub-continent at K2 Partnering Solutions, a European consulting firm specializing in ERP and Cloud. He has also co-authored a book “That’s Naut My Business.”

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


EC-Council’s CISO MAG brings to you a webinar on “The Current State of Application Security.” Register Now!

 

Skills CISOs Need to Have in 2021

These are turbulent times with the global pandemic impacting business. The threat landscape has also changed significantly. So, having good technical skills is not enough to be an effective security leader today.

Soft skills are now much sought after. Communication skills are invaluable. How effective is a CISO in communicating the potential impact of a security breach on the business, to the board? Team leadership, empathy, and patience are rare skills that will be in demand.


CISO MAG and the EC-Council University (ECCU) designed a survey to determine the state of preparedness of candidates for cybersecurity roles in the industry. The survey will include responses from academic partners, CISOs, and those responsible for hiring in organizations. Take Survey Now


Having business skills, understanding core business processes, and being able to juxtapose that with information security – will put the CISO in a different league.

And yes, technical skills will continue to be in demand, as the attack vectors are becoming increasingly sophisticated. So, security leaders will need to upgrade their skills and knowledge to keep up.

Brian Pereira, Editor-in-Chief, CISO MAG interacted with industry experts to understand the essential skills to be an effective business leader. Here’s what they have to say:

1. Is security certification enough to be an effective CISO?

Organizations are beginning to realize that proven performance matters more than years in a particular role. The bias toward hiring CISOs based on their previously held CISO positions diminishes as a useful barometer of a successful CISO. A dirty little secret of CISO turnover is that CISOs do not necessarily churn jobs based on opportunity; they are managed out because of poor performance. Companies recognize CISOs must have security program architecture experience, executive persona, and serve as operational risk management visionary. I find companies today are increasingly looking for their next generation of information security managers to be certified CISO.

2. What are the core technical skills in demand this year?

The Cybersecurity space is dynamic and continually evolving in the wake of the pandemic. This year, there has been a shift in the demand for specific technical skills across many cybersecurity tech platforms.

Some of these core skills include Application Development Security, which involves security Automation, SecDevOps, Predictive Analysis, and machine learning; others are cloud security, threat Hunting and Incidence Response, and finally, Data Security / Privacy. While it is pertinent to have a Risk-Based Management approach to the above, it is important to note that soft skills remain the same over the past five years. Although technical skills have been overwhelmingly emphasized, there is also a need to develop soft critical skills such as communication, reporting, and cost-benefit analysis.

3. Why are communication skills so important?

The most in-demand skill for CISOs directly in 2021 will be the ability to communicate with the Board of Directors. We are in a turbulent moment in history, with the pandemic and geopolitical tensions playing out in real-time. Being able to communicate with the Board in clear, concise, relatable terms will be a differentiator for CISOs.

The skills CISOs will be looking for overall for the teams that report to them will fall into these areas in terms of technical skills.:

  • Zero Trust Architecture skills – being able to architect, deploy, and operate a Zero Trust network.
  • Application Security – especially for firms selling products and services to enterprises.
  • CIAM (customer identity and access management) – with customer engagement models changing and becoming increasingly digital, practitioners with the skills in customer identity and access management will be at a premium this year.

Of course, communication skills, empathy, and patience are always in demand – and rare – which makes them constantly sought after but not always easily found for any leader or practitioner.

4. What are the top three skills that CISOs need to have in 2021?

I would consider these as the top three needed skills for CISO’s in 2021:

A great communicator – having the ability to acquire information about the business and possible threats and opportunities from multiple sources and distill that information into direct business impact statements that leadership and business owners can understand — will be key to the organization’s success.

Focused on Collaboration – the CISO must exhibit a collaborative approach to securing the organization, the business must be the priority and the CISO must find creative ways to foster a secure environment based on the risk tolerance of the organization while ensuring the organization has operational functionality. Security for the sake of security is a failure on the part of a CISO — collaborative security and functional operability are where everyone is successful.

Have and maintain Technical acumen – The CISO must have demonstrated capability to understand the holistic computing environment and how the overall security protocols impact each of those environments while managing risk to and from the organization, the customer base, and the partners/suppliers within the parameters of the risk management program.

While there are many other skills needed in the toolkit, these three will position the effective CISO with becoming that business partner and organizational asset the leadership can depend on to manage risk for their overall success.

5. As a CISO, what are the top skills you would be looking for when you recruit people?

People generally think cybersecurity is all about hacking into or breaking things, but actually, cybersecurity is all about learning how technology (and people) work. The key is not a technical background; they are value additions, but a willingness and desire to learn how the technology works is more important along with the zeal to never stop playing with tools and technology.

Cybersecurity skills do not focus on solving technical problems; they instead focus on human-focused problems such as misconfiguration, a programming error, etc. As a CISO, the skills I look up to which a candidate must possess are soft and technical. Soft skills such as understanding of privacy, security awareness, and training, knowledge of governance, security communications, or cyber law and ethics.

Technical skills such as Coding – Candidates must have a basic understanding of markup language. Systems – Must understand the administration of Linux and Windows systems through a command-line interface (CLI). Applications – Knowledge of configuration, running, and maintenance of common applications such as web servers, databases, and DNS servers and Networking – Knowledge of how the network works is invaluable. Years of practical experience depending on the profile to be added along with soft and technical skills.

6. What are the security skills that will be in demand this year?

2020 made a lot of people much more tech and security savvy. The renewed focus has caused many people to consider changing careers and to look for new jobs in the IT security field. Hiring managers like myself will be focused on a few key skill sets in 2021. Cloud security skills and understanding the roles of the service vendor, the cloud provider, and the end customer will be a critical need for many companies this year. The single pane of glass security observation tools will continue to flourish and the skills of a SOC analyst to quickly read, understand, and respond to threats on that monitor will become sought after at all organizations even smaller offices without a robust SOC team or facility.

7. As you interact with security leaders, what are the security skills they look for when hiring staff?

We have an extensive network of advisor CIOs and CISOs who are looking at two things:

  1. People with the right cybersecurity skillset. But that pool of talent is very small relative to the needs in the market. The best way to address that problem is using the latest cybersecurity platforms to automate as much vulnerability management on the secondary security alert and complement it with the scarce security analyst talent to identify and proactively fix the most critical high priority alerts in the enterprises.
  2. Long term, we need colleges and universities to focus on educating and graduating new security talent to help fill the void for small and large companies. Secondly, companies need to implement formal training programs to continue to educate and train their talented employees as the sector continues to evolve daily.

Beware! Malware Posing as Clubhouse App Making Rounds

BotenaGo, malware over encrypted connections

Clubhouse, a popular invite-only audio chat app, ran into severe security issues after threat actors allegedly misused the app’s popularity. Security experts recently found cybercriminals distributing a malicious app mimicking the Android version of Clubhouse. The Clubhouse platform is only available to iOS users. The company is planning to launch the Android version of its app soon.

According to researchers from ESET, the fake malicious app aims to steal users’ login information for a variety of online services.  Dubbed as “BlackRock”, the app is delivered from a phishing website which is an imposter of the genuine Clubhouse website.

Once downloaded, the BlackRock targets various apps on the victims’ devices including financial and e-commerce apps, cryptocurrency exchanges, social media, and messaging platforms along with popular mobile applications like Twitter, WhatsApp, Facebook, Amazon, Netflix, Outlook, eBay, Coinbase, Plus500, Cash App, BBVA, and Lloyds Bank.

“The website looks like the real deal. To be frank, it is a well-executed copy of the legitimate Clubhouse website. However, once the user clicks on ‘Get it on Google Play, the app will be automatically downloaded onto the user’s device. By contrast, legitimate websites would always redirect the user to Google Play, rather than directly download an Android Package Kit or APK for short,” the researchers said.

How to protect against malicious apps?

ESET researchers recommended certain security measures to find out malicious apps and boost mobile security. These include:

  • Use only the official stores to download apps to your devices
  • Be wary of what kinds of permissions you grant to applications
  • Keep your device up to date, ideally by setting it to patch and update automatically
  • If possible, use software-based or hardware token one-time password (OTP) generators instead of SMS
  • Before downloading an app, do some research on the developer and the app’s ratings and user reviews
  • Use a reputable mobile security solution

Related Story: Is Clubhouse App Leaking Users’ Sensitive Data to Chinese Govt?

Cybercrime Costs Americans $4.2 Bn in 2020: FBI

Cybercrime, internet crime

The FBI received nearly 800,000 cybercrime complaints in 2020, with reported losses of $4.2 billion. In its latest Internet Crime Report for 2020, the agency stated that it received a significant number of complaints about various cybercrimes, including COVID-19-themed cyberattacks. The staggering figure was a 69% increase in total complaints from 2019.

“In 2020, while the American public was focused on protecting our families from a global pandemic and helping others in need, cybercriminals took advantage of an opportunity to profit from our dependence on technology to go on an Internet crime spree. These criminals used phishing, spoofing, extortion, and various types of Internet-enabled fraud to target the most vulnerable in our society — medical workers searching for personal protective equipment, families looking for information about stimulus checks to help pay bills, and many others,” the report said.

The most prevalent scams during the pandemic were government impersonators. According to the Internet Crime Complaint Center (IC3), threat actors targeted users via social networking sites, emails, or phone calls pretending to be from the government. The scammers then attempted to gather personal information or collect illicit money through charades or threats.

What the FBI found

  • The Internet Crime Complaint Center (IC3) received a record number of complaints – 791,790 from the American public in 2020, with reported losses exceeding $4.1 billion.
  • Business E-mail Compromise (BEC) schemes continued to be the costliest, with 19,369 complaints with a loss of approximately $1.8 billion.
  • Over 241,342 complaints were reported on phishing scams, with a loss of over $54 million.
  • The number of ransomware incidents also continues to rise, with 2,474 incidents reported in 2020.

The Silver Lining

IC3 stated that it is working along with the law enforcement agencies to mitigate the financial losses resulting from various online frauds and scams. Until now, IC3’s recovery asset team successfully froze around $380 million of the $462 million in reported losses in 2020, with a success rate of 82%. Besides, IC3 dismantled organizations that transfer funds obtained illicitly.

How to Protect Against Online Frauds

IC3 also recommended users to follow certain security measures to protect themselves from various fraudsters and scammers online. These include:

  • Using extreme caution in online communication. Verify the sender of an email. Criminals will sometimes change just one letter in an email address to make it look like the one you know. Also, be very wary of attachments or links. Hover your mouse over a link before clicking to see where it is sending you.
  • Questioning anyone offering you something that is “too good to be true” or is a secret investment opportunity or medical advice.
  • Relying on trusted sources, like your own doctor, the Center for Disease Control, and your local health department for medical information and agencies like the Federal Trade Commission and Internal Revenue Service for financial and tax information.

“As we continue to battle COVID-19, protect yourself from fraud and scams. Do not give out your personal information to unknown sources. If you are a victim of an online crime involving COVID-19, report at IC3.gov,” the report added.

F5 Annual Survey Highlights Accelerated App Modernization and Edge Computing across Asia Pacific

Mobile Apps Security, mobile apps

F5 just announced the availability of its 2021 State of Application Strategy report. In its seventh iteration, this annual survey identifies several converging trends, many of which have been significantly impacted as organizations revamp digital experiences to address the evolving realities of COVID-era consumers. Companies have significantly sped up their digital transformation efforts in the past year, a theme anticipated to persist beyond the pandemic. With limited in-person interactions, applications — and the digital experiences they facilitate — have become synonymous with an organization’s presence and ability to thrive.

“This year’s report highlights the many contrasting priorities that IT teams are currently facing. Of course, there’s the familiar one of flexibility and convenience versus security, but then you also have organizations generating an immense amount of data while seeking ways to extract meaningful insights from that data,” said Kara Sprague, EVP, and GM, BIG-IP at F5. “Similarly, we find companies relying more on automation to reduce operating costs while increasingly tailoring applications for customer-centric digital experiences. Many of these are a function of the speed in which the industry has responded to COVID — in that it forced a myriad of operational considerations, concerns, and opportunities to be addressed simultaneously almost overnight.”

What’s driving demand for Edge applications?

Improving connectivity, reducing latency, ensuring security, and leveraging data insights are now even more essential, as IT teams have found it nearly impossible to keep pace with the rate of change and digitization of experiences. Moreover, while microservices, APIs, and containers may accelerate individual application rollouts from a DevOps perspective, the reach and pervasiveness of modern apps have also resulted in heightened complexity—with many organizations lacking the skill sets to truly streamline deployments. This is especially the case when managing broader application portfolios that span multiple generations of application architectures. Correspondingly, this new research centers on the following four trends, pointing to an elevated interest in cloud and as-a-service offerings, edge computing, and application security and delivery technologies that require less expertise to deploy and manage while providing out-of-the-box insights.

“In today’s digital-first world, every organization is in the digital experience business. Consumers are increasingly reliant on digital connections in every aspect of their lives and this reliance has propelled applications to be even more central to a business’s strategy – further emphasizing the pivotal role that apps continue to play in our economy,” shared Adam Judd, Senior Vice President, Asia Pacific, China, and Japan, at F5. “This year’s report is a clear reflection of this growing trend. As businesses continue to invest in their application portfolios, it is critical to ensure that their apps are able to adapt, scale and self-heal across different app environments. With more opportunities for growth as we reshape our world post-COVID, businesses need to architect strategies that hinge on technologies such as edge computing and data analytics to harness the full potential of their application portfolio to meet consumer demands for world-class digital experiences.”

1. Continued Modernization of Apps and Architectures to Enable Better Digital Experiences

According to the survey, 87% of organizations operate both modern and traditional architectures, with modernization deemed necessary when legacy systems are too rigid to adapt to rapidly changing business conditions. More than three-quarters of respondents (77%) reported that they are presently modernizing internal or customer-facing applications, with APIs as the primary method given their ability to combine capabilities of traditional and modern application components. In addition, the percentage of organizations maintaining multiple app architectures is growing, with the survey also affirming that as-a-service and managed service offerings continue to be viewed as replacements for some applications where vendors can provide cloud-friendly alternatives.

2. The Rise of the Edge as Containerization Expands

Edge computing generally refers to operations performed outside of a centralized data center. With employees and consumers logging on from increasingly distributed locations, edge computing has been identified as a significant means to reduce latency and increase the real-time responsiveness required by today’s applications. Accordingly, the edge must evolve to better support modular application components such as containers residing across multiple cloud locations. In addition to promoting faster and more efficient deployments, placing containerized applications at the edge can improve scalability and the customer experience. Demonstrating an appetite for these advantages, survey results note that 76% of organizations have implemented or are actively planning edge deployments, improving application performance, and collecting data/enabling analytics as to the primary drivers.


EC-Council’s CISO MAG brings to you a webinar on “The Current State of Application Security.” Click here to Register Now!


3. Accelerating Growth in SaaS and Cloud Deployments, Balancing Flexibility and Security

With the percentage of applications deployed in the cloud rising‚ more than two-thirds of respondents (68%) are also hosting at least some of their application security and delivery technologies in the cloud. Simultaneously, organizations are positioning themselves to address the architectural complexity that results from adding SaaS and edge solutions, maintaining on-premises and multi-cloud environments, and modernizing applications. Successful integration of these elements within a cohesive application strategy will require up-leveling how tools, skill sets, IT processes, and analytics are applied across dynamic architectures. Security continues to be a key driver, with efforts to stay ahead of attackers frequently requiring capabilities beyond what organizations have the resources to manage on-premises. Further highlighting this challenge, SaaS for security was identified as the top strategic trend among survey respondents.

4. The Importance of Telemetry in Meeting Evolving Customer and Business Expectations

Harnessing telemetry to turn large volumes of data into business insights is essential for adaptive applications. Even still, an overwhelming 95% of respondents believe they are missing insights related to performance, security, and availability, indicating a desire for a much clearer end-to-end picture than their current monitoring and analytics solutions provider. Individuals across organizational roles were in uniform agreement on the topic, citing the top three insights missed as the root cause of application issues; performance degradation causes; and potential attack details. In parallel, nearly three-quarters of respondents intend to leverage AI to better utilize telemetry data, and more than half are looking toward AI to help their organizations transition to applications that can automatically adapt to better defend themselves and respond to changing conditions.

The report represents more than 1,500 respondents worldwide, with a significant portion of respondents coming from the Asia Pacific, from a breadth of industries, organization sizes, and professional roles. Fundamentally, the survey focused on IT decision-makers to best highlight the priorities, concerns, and expectations of those most responsible for meeting the toughest challenges of today’s digital economy. Together, their responses form a compelling perspective of how organizations are evolving application strategies to better serve the current and anticipated needs of customers.


EC-Council’s CISO MAG brings to you a webinar on “The Current State of Application Security.” Click here to register or simply fill the form below