Home Blog Page 106

Unsecured Server Exposes PII of 50,000 Patients in Utah

Healthcare Data Breaches, Premier Diagnostics data exposed

A Utah-based COVID-19 testing service, Premier Diagnostics, accidentally exposed the personally identifiable information (PII) belonging to 50,000 patients through an unsecured server. The exposé was done by Comparitech’s lead researcher Bob Diachenko, who discovered the unsecured database of Premier Diagnostics during one of his routine scans. The exposed data included patients’ sensitive information like scanned passport copies, medical/health insurance IDs, driver’s licenses, and so on. According to Diachenko’s investigation, the exposed data majorly belonged to people from Utah and the neighboring states of Nevada and Colorado.

About the Exposé

As per Comparitech’s blog, Diachenko found two large unsecured Amazon S3 Buckets of Premier Diagnostics, however, he was initially unaware of who they belonged to. One of these S3 buckets was named patient-images and contained 207,524 images of patients’ photo ID scans. Whereas the second S3 bucket, which was named paper-records, included a tabular database of names, dates of birth, and test sample IDs from patients who took COVID-19 tests from their 11 diagnostic centers across Utah. Giving a detailed case study of how things panned out, Comparitech published the following timeline:

  • January 25, 2021 – The first of the two databases was indexed by a search engine.
  • February 22, 2021 – Diachenko discovered the exposed data and began his investigation to identify the owner.
  • February 24, 2021 – Unable to identify the owner, Diachenko sent an alert to the Amazon Web Services security team. He received a response that the owner would be informed via internal channels.
  • February 25, 2021 – After further examination of exposed data, Diachenko identified Premier Diagnostics as the likely owner, and sent a disclosure accordingly.
  • March 1, 2021 – After several days with no response, Comparitech’s editorial team was able to establish contact with Premier Diagnostics. The data was secured later in the day.
  • March 5, 2021 – Premier Diagnostics requested additional time for security experts to review their infrastructure.

Related News:

Cybercriminals Attacked Unsecured Databases 18 Times Per Day

Doing the math, the number of images exposed was more than 200,000 however, the number of patients affected was only over 50,000. Something did not add up correctly. Comparitech reached out to Premier Diagnostics and found that “each patient is associated with four images: the front and back of a medical insurance card, and the front and back of a second ID such as a driver’s license or passport. That means roughly 52,000 patients are affected.”

The data has now been secured by Premier Diagnostics and no exploitation of the details has been registered as of now. However, the type of data exposed in this incident can lead to identity theft, phishing attacks, health insurance fraud, etc. against the patients who have been affected. Owing to this we request all the patients who have taken the COVID-19 tests at Premier Diagnostics to be alert and monitor all financial and important services associated with them that are linked with the exposed data.

Related News:

Microsoft’s Unsecured Bing Mobile App Exposes 6.5TB of Users’ Data

NimzaLoader: Malware Written in Rare Programming Language

WhisperGate malware campaign, Flagpro malware, MosaicLoader Malware, drinik

Security experts uncovered a new kind of phishing campaign in which threat actors are using newly crafted malware written in a rare programming language to evade security detection. Researchers from Proofpoint found a cybercriminal group tracked as “TA800” distributing malware dubbed as “NimzaLoader.” The attackers used reverse engineering techniques to trick users and pilfer their sensitive data online.

NimzaLoader Malware

Proofpoint researchers stated that the TA800 group previously used BazaLoader malware, but from February 2021, the group has been distributing NimzaLoader malware. One of the distinguishing features of Nimzaloader malware is that it is written in the Nim programming language, which makes it a rare malware in the threat landscape. “Malware developers may choose to use a rare programming language to avoid detection, as reverse engineers may not be familiar with Nim’s implementation, or focused on developing detection for it, and therefore tools and sandboxes may struggle to analyze samples of it,” the researchers said.

What is Nim?

Developed by a German programmer Andreas Rumpf in 2008, Nim is a compiled programming language that draws on concepts from languages like Modula-3, Delphi, Ada, C++, Python, Lisp, and Oberon.

BazaLoader vs NimzaLoader

Earlier, some analysis on the malware suggested that NimzaLoader could be another variant of BazaLoader malware. However, Proofpoint research asserted that this malware is not a BazaLoader variant. The researchers also listed certain differences between NimzaLoader and the BazaLoader variants, which include:

  • The malware is written in a completely different programming language
  • They don’t use the same code flattening obfuscator
  • They don’t use the same style of string decryption
  • They don’t use the same XOR/rotate based Windows API hashing algorithm
  • They don’t use the same RC4 using dates as the key command and control (C&C) response decryption
  • Doesn’t use a domain generation algorithm (DGA)
  • Makes use of JSON in C&C communications

NimzaLoader’s Phishing Campaign

Researchers found TA800’s campaign leveraging users’ personal details in its phishing mails, including the recipient’s name and the company’s name. The email contained links, which when clicked redirects the user to phishing pages to compromise users’ sensitive information.

“Based on our observations of significant differences, we are tracking this as a distinct malware family. There has been some evidence suggesting NimzaLoader is being used to download and execute Cobalt Strike as its secondary payload, but it is unclear whether this is its primary purpose. It is also unclear if Nimzaloader is just a blip on the radar for TA800—and the wider threat landscape—or if Nimzaloader will be adopted by other threat actors in the same way BazaLaoder has gained wide adoption. TA800 continues to integrate different tactics into their campaigns, with the latest campaigns delivering Cobalt strike directly,” the researchers added.

“Never let anyone have you think that you cannot achieve something because you are a woman”

International Women’s Day is a time to reflect on the progress we’ve made to encourage women in all environments. It is also a day to celebrate all the men who have mentored and supported their female counterparts. And though men are helping in axing gender stereotypes, multiple surveys still suggest that women are underrepresented in the tech world. Businesses need to come forward and educate young women about the fact that cybersecurity is chic, and the jobs cover a vast and diverse number of positions. Achieving gender equity is as important as changing the negative stereotypes about the industry.

Today we’re fighting cyber wars and our adversaries know we’re understaffed. To discuss the shortage of talent pool, initiatives for women’s education in cybersecurity, and lack of industry awareness, Pooja Tikekar, Feature Writer at CISO MAG, had a conversation with Monica Verma, Chief Information Security Officer (CISO) at The Norwegian Directorate of Health. Monica has more than 13 years of experience in information and cybersecurity, and has previously held the CISO role and worked as Head of Security, Risk, and Business Continuity for the finance sector. After supporting the financial industry for more than a decade with security, privacy, risk management, digitalization, vendor management, and cloud security, she wanted to contribute to and promote the health sector with her passion and expertise in this area.

Monica is also a board member of Cloud Security Alliance Norway and Women in Cybersecurity Norway. As her contribution towards a safer and more secure society and business world, she leads initiatives such as MonicaTalksCyber.com and the We Talk Cyber podcast series. In 2019, she also won the “The Outstanding Security Performance Awards” for Outstanding Security Adviser in Norway, which is awarded by The Norwegian Business and Industry Security Council.

Monica got interested in technology at the age of 10 when she was invited to see the inside of a cockpit for the first time. She started her career as a developer and an ethical hacker.

Edited excerpts of the interview follow:

The world continues to battle COVID-19, and most industries continue to suffer. Right from the time the pandemic hit, many organizations suffered ransomware and phishing attacks. How are CISOs collaborating in the use of technologies, tools, people, and processes in a smart way?

Over the last decades, we have talked about various technical controls that to date are an important part of basic cyber hygiene. CISOs understand the importance of getting the basics right, even as the digital landscape evolves and gets complex. A lot of the investment done today still goes into that basic hygiene, which in return can help reduce the odds, the impact, or both, when organizations are hit by ransomware or phishing attacks. These include, but are not limited to, backups including offline backups on tapes, (virtual) network segmentation, layered defense approach, multi-factor authentication, antivirus, and spam filters, patching, zero-trust approach to identity and access management, etc.

However, time and again, we have realized that investing in people and protecting the human aspect of cybersecurity is equally critical. The human element and controls around it are an equally important part of basic hygiene. One can have the best technical controls in place but when a user unintentionally clicks a malicious link and these controls are bypassed, the overall consequences can be huge. In fact, we have seen various ransomware attacks and breaches happen as a result of simple but successful phishing attacks. We are seeing a gradual shift in the mindset, from “Humans are the weakest link” to “How can we better protect our users and the human aspect of cybersecurity.” This shift in mindset is critical and needs to continue and take precedence in every organization.

In addition to basic hygiene and preventive controls, it’s equally important to be prepared for when the worst comes. Things can and will go wrong. CISOs are deploying detection and response capabilities, incorporating failsafe and adaptive mechanisms, ensuring up-to-date business continuity plans, and conducting table-top exercises for timely and efficient incident and crisis management. We are also seeing higher collaboration with the national cybersecurity centers and law enforcement agencies in case of cyberattacks, like ransomware, to handle them efficiently and lawfully as well as to reduce the impact on the organizations, their employees, customers, and other actors in the supply chain.

The nature of cyberattacks on health care related to COVID-19 varied greatly and affected the digital landscape. How has it affected the Norwegian Directorate of Health and what key measures have you focused on?

The pandemic changed our (digital) lives drastically and the way we interact, work, and collaborate. It made us more dependent on digital solutions that became even more tightly integrated into our everyday lives. At the same time, our digital life also makes us more vulnerable to loss of information and other consequences as a result of malicious actions, accidents, and mistakes. As a key player in COVID-19 management, the Norwegian Directorate of Health is exposed to an increased threat and risk profile. To support national crisis management, as we go through a challenging time, there has been an increased focus on robustness and our capabilities to better manage risks and cyber crises. Therefore, information security has been and continues to be a high priority within the organization and towards COVID-19 crisis management.

Additionally, there has been an increased focus on security awareness among the employees with regards to the changing digital landscape, increase in cyber risks, and measures to prevent falling prey to phishing and ransomware attacks. The key has been to train the users to educate them, not to trick them. Norwegian Directorate of Health has worked in a structured way to ensure a strengthened security culture, secure work from home, and effective business continuity and crisis management towards increased cyber risk as a result of COVID-19.

On one hand, there has been continued focus to ensure basic cyber hygiene is in place, such as the principle of least privilege, network segmentation, patching, etc. On the other hand, there’s been a risk-based approach to include different aspects of people, processes, and technology as a part of the overall information security plan. To ensure that we understand our increased risks and that they are managed effectively, there has been an increased focus on the human aspect of cybersecurity and security awareness, in addition to vendor management, increased robustness, and effective crisis management. Information security is and continues to be an integral part of the overall work done by the Norwegian Directorate of Health.

Leveraging personal devices for working from home became the new normal. But BYODs have a real impact on cybersecurity if not properly accounted for. How are CISOs developing an overarching plan for the security of end-users and clients?

Securing the human element and the endpoints is an important part of the overall cybersecurity strategy and plan. We need a continuous shift in the mindset from “Humans are the weakest link” to “Mistakes will happen.” How can we protect, prevent, adapt and respond better? Additionally, as BYODs and work from home come into the picture, the cybersecurity strategy and plan also require addressing the cyber risks that this evolved digital landscape brings along. To ensure a safer and more secure working environment, the following are some of the key things to consider as a part of the overarching plan:

  • The line between the personal and the professional lives has blurred over time. It’s important to adapt your security policies to fit these integrated worlds.
  • Perimeter-based security is no longer effective. Apply a zero-trust approach to both your architecture, and identity and access management. Always verify.
  • Regular user awareness training is still key. Cybersecurity is about people, processes, and technology. The human aspect of cybersecurity is equally critical and must be addressed.
  • When conducting phishing training, keep in mind that the goal behind such training is to educate the users, not to trick them.
  • Define and implement your BYOD security policy to ensure acceptable use.
  • Maintain your BYOD policy up-to-date and include secure practices such as restricting access to critical and sensitive information from non-managed devices, providing managed devices as alternatives when possible, and defining and implementing which apps are whitelisted, etc.
  • Implement technical measures and controls such as Mobile Device Management (MDM), remote secure wipe, Data Loss Prevention (DLP) to safeguard company apps and data on BYOD.
  • Shadow-IT is a real concern and often difficult to manage. Deploy discovery tools, monitor your network regularly, and scan for unknown devices.

March 8 is celebrated as International Women’s Day, and women who rise to the position of a CISO are a rare sight. The low representation of women in cybersecurity is linked to a broader problem of their low representation in science and technology. What is the reason for this gap? Is it a business issue or a gender issue?

It’s a social issue. It’s an issue that has affected our society for decades. We as a society, including family, school, businesses, universities, etc. have a social responsibility towards closing the gender gap. Getting girls and women interested in STEM education at schools and in universities is good and important, but it starts way earlier. It starts at home. It starts in kindergarten. It starts with encouraging girls to dream and supporting them in pursuing their dreams.

There is a lot that can be done by everyone for girls and women at different ages and in different environments from home, school, and universities to the corporate world. There is still a huge gender gap because not enough is being done by everyone, and not always for the right reasons. Many, over the last decades, have fought for equal rights and equal opportunities for women. However, there are still many who don’t believe that the gender gap is a real issue that plagues our society. Others want to help, but don’t really know what they can do to contribute and then some do contribute but for the wrong reasons. Unless and until we understand and agree that this is a social issue that needs to be tackled at all levels in all environments, we won’t be able to close the gender gap, in a sustainable way.

There’s a perception that information technology/cybersecurity is an occupation for men. Is it true that women are generally not presented with career opportunities in the industry, or is it because most women are unaware of them?

The key issues are (a) lack of inclusion and openness (b) stereotype that women aren’t best suited for these roles (c) boys’ club culture and (d) “that’s how we have always done it” mindset. The perception is slowly changing. However, breaking the barrier and becoming a part of something that has mostly been a boys’ club with strong stereotypes isn’t easy and requires an active effort and openness from corporations, colleagues, and your network.

Another important aspect that contributes to fewer women approaching or being interested in technology or cybersecurity, is the lack of diverse opinions within the organization and around the table. Women can bring different perspectives to the table, in their ways of thinking, approaching, and solving problems. Many women are not considered for a career opportunity within technology or cybersecurity because of stereotypes. Many others don’t get to know about those opportunities due to lack of inclusion or not being a part of the boys’ club. Many women feel the resistance or are shy to be a part of a world that is more often than not run by the “That’s how we have always done it” mentality. In addition, many corporations still don’t support a work-life balance. In fact, in many cultures, working extremely long hours is considered productive, whereas exactly the opposite might be true.

A sustainable change requires a leadership that is open, diverse, and inclusive. To build such a leadership, one needs a balanced representation. However, representation is not only about diversity in what we see but also diversity in what we hear. This inclusion of diverse opinions and varied representations of what we hear can help bring different perspectives and openness around the table, allowing more women to be interested in technology and cybersecurity.

Is it viable for governments or educational institutes to launch funding/incentive/scholarship programs for women’s education/ training to create a pool of skilled IT professionals?

Many organizations, governments, and educational institutions have started to build initiatives and scholarship programs to attract more women to STEM education programs or to pursue a career in technology and cybersecurity. It’s not a level playing field yet. We still have a huge gender gap. We need more of these incentives and funding. However, it’s extremely important to ensure these programs are built for the right reasons. Gender equality, diversity, and inclusion are not about fulfilling a quota. They are not about giving scholarships or jobs to a less deserving woman instead of a more qualified man. Gender equality is about allowing equal access to rights, resources, and opportunities. Yes, we absolutely need such initiatives and programs, but they need to be done for the right reasons, with the underlying goals of closing the gender gap and building a diverse and inclusive society. It’s about encouraging more women to consider and get interested in fields that stereotypically have been male-dominated. It’s about providing these women the necessary tools to break those stereotypes with their qualifications, passion, and purpose. It’s about ensuring that our corporate world has a diverse workforce, including at the leadership level.

Gender stereotype is a common phenomenon everywhere. What recruitment efforts must SMBs adopt to welcome higher female enrollment?

Step one is awareness and acceptance of the issue at hand. Step two is changing the mindset at the leadership level. These are the prerequisites to ensure your practical next steps to build diversity are successful and sustainable. Companies can adopt various measures to recruit more women but even before that, it is important to have an open, inclusive, and diverse mindset and leadership.

Organizations can apply both a top-down and a bottom-up approach. Recruiting a diverse and inclusive leadership not only sets the right tone at the top but also provides a better platform for building a diverse and inclusive workforce within the entire organization. Organizations can have internship programs to attract more women in tech. Mentorship programs can be used as an effective tool to help them build skills, self-confidence, and network.

Many other efforts can be done. Encourage, mentor, and support more women within the organization to become a part of the leadership team. Many women don’t apply for jobs unless they fit 100% of the criteria. Advertise your tech or cybersecurity roles in a gender-neutral way and with realistic qualifications, so you are not already excluding a huge chunk of talented applicants from the process. Create maternity and paternity programs for your employees. Encourage and support work-life balance. Have equal pay grades for equally qualified candidates, independent of gender. Provide these benefits and equal opportunities as a part of your recruitment process. Build an inclusive and open environment within your organization to keep your employees motivated and productive. However, for any women’s initiative to be successful and sustainable, it has to be done for the right reasons.

Lastly, what is your advice to young women who wish to climb the upper echelons of security leadership?

There are two key elements to this. The first is understanding and implementing what it takes to be a great leader. The second is to learn to communicate security effectively and tailored to the audience.

1. Good leaders are self-confident but humble. They believe in their mission but also promote and enable others. Women have had to fight for decades for equal opportunities in a male-dominated industry. Knowing your worth is the first step. Knowing and believing that women can have it all, is the second. Women bring diversity and varied perspectives to the table that organizations can benefit from. There is a phrase that my dad used to tell me and my sister while we were growing up – “Never let anyone have you think, even for a moment, that you cannot do or achieve something because you are a woman.” Leadership starts from within.

2. Effective communication is yet another critical element to increase your odds of becoming a part of the security leadership. Independent of which role you have today, if you wish to be an effective security leader, you should train yourself to think and work like a security leader. Understanding, learning, and communicating security effectively and tailored to your audience is critical. To be an asset and a part of the leadership team within an organization, it’s critical that you understand your audience and their needs. Invest time in learning about their overall goals and challenges with security. Invest time in learning the business language. Invest time in conditioning your mind to think like a security leader. Keep an eye out for opportunities and focus on providing value to the leadership. There will be failures. When that happens, reflect on the actions you took, note down your learnings, go back to element one above, remind yourself of your worth, and start again.


About the Author

Pooja Tikekar is a Feature Writer and part of the editorial team at CISO MAG. She writes news reports and feature articles on cybersecurity technologies and trends.

More from the author.

CISO MAG’s March issue on Women in Cybersecurity is out. Preview hereSubscribe now!

“Women have tough choices to make, and many rightly prioritize household over the office”

As the world celebrated womanhood and women’s contribution to society on International Women’s Day, we at CISO MAG decided to devote the month of March to all the women leaders of cybersecurity. This was in the light of the revelation that women’s representation in cybersecurity has been less than a quarter and has remained that way for almost a decade, if not more. Most of the problems faced by women can be traced back to the earliest days of their education, where stereotypes begin.

Here’s what Jill Orhun, VP of Customer Success at Devo, has to say about gender disparity, representation, and diversity in cybersecurity:

On how the female workforce in cybersecurity has evolved over recent years and where it’s heading: Security people were early to recognize the benefits of having a diversity of perspectives. Beyond women to all minority populations, good security means guarding against a wide variety of attacks and the innovative humans who launch them, threat modeling thus benefits from holistic situational reviews that take social relationships into account,  which plays to women’s strengths. Women are also amazing at open-source intelligence (OSINT) and social engineering, which only adds to the tool kit of security teams looking for novel ways to gather information and protect their organizations.

While we’ve been heading in the right direction in diversifying the security industry, I worry that the pandemic is going to have a material and long-lasting effect on forwarding progress. Since the beginning of the pandemic and lockdowns, women have disproportionately borne the burden of childcare, household responsibilities, at-home education, and more in their households. Women have tough choices to make, and many rightly prioritize household over the office. As a result, we’re seeing an exodus of women from the workforce. The only way to stop this regression is for organizations to step up and establish a different value structure and culture, that helps organizations and their people to thrive in this new normal.

On how to get more women to evolve in cybersecurity: Women need to take the plunge, and organizations need to welcome them (and other minority groups) with open arms to help take the anxiety out of entering a male-dominated field. Many security people believe diversity adds value, evangelizing this belief will help women to understand the true benefit they can bring. With remote work is more accepted than ever before, organizations need to make security holistically an attractive opportunity for women, in terms of benefits, flexibility or work/life balance, company cultures, training, etc.

Advice to young women looking to enter the cybersecurity field: Women (and men) looking to enter into cybersecurity need a sense of curiosity and tenacity, to have faith in themselves and resilience to adversity as they build their individual approach. Security is still a male-dominated environment; awareness and tolerance of this reality will help women persevere past expected obstacles to an organization that fits them. The good news is, the security industry is growing so fast and companies want to bring women into open roles, so there’s plenty of opportunities for women to get into the industry. Security teams that have embraced diversity will benefit by being able to hire from this rich group of talent.


Disclaimer

Views expressed in this article are personal.

CISO MAG’s March issue on Women in Cybersecurity is out. Preview hereSubscribe now!

Women need to take the plunge, and organizations need to welcome them

As the world celebrated womanhood and women’s contribution to society on International Women’s Day, we at CISO MAG decided to devote the month of March to all the women in cybersecurity. The purpose of this article is to highlight the role of women in the industry and address several issues they face. This was in the light of the revelation that women’s representation in cybersecurity has been less than a quarter and has remained that way for almost a decade, if not more. Most of the problems faced by women can be traced back to the earliest days of their education, where stereotypes begin.

Here’s what the women in cybersecurity have to say on gender disparity, representation, and diversity in the industry.

1. Debra Danielson, CTO, Digital Guardian

Debra

“I’ve been very involved in efforts to increase the participation of women in tech for more than 15 years, and while there have been some successes, we haven’t made enough progress. When it comes to increasing diversity in the industry, it’s still largely male and white. Women and minorities are either not choosing the field or are not staying in the field. Women make up between 11 and 20% of the global cybersecurity workforce, suggesting some progress is being made, but women are still paid less, promoted less, and hired less. The research out there is massive, and frankly, sometimes overwhelming.

So, what can companies do to support and progress the careers of women working in technology? First, stop and take a hard look at your numbers. Create a framework identifying established biases backed by empirical science. Shine a light on them so that when subtle (or not so subtle) bias behavior is exhibited it can be called out. Enroll men in the calling out process too. Some of the greatest proponents for increasing the participation and success of women in tech have been men. Fathers can be deeply committed allies, as they work to ensure that their daughters get a fair shot at the success they’ve had.

We all have biases, and these societal gender roles are deeply, deeply ingrained into all of us. It’s not just men that discriminate (consciously or unconsciously) against women. Women do it too. Think about how you change the system to balance the bias. Be really clear that this isn’t giving a “leg up” to a less deserving woman (to the disadvantage of a man), but it is a way to level the field and flatten the “leg down.”

We can all do a lot more than we realize to minimize and mitigate bias and prejudice. Think about how you recruit, manage, or simply carry out your day job. Don’t assume: research, educate and inform. Look for ways to challenge and change.

2. Jessica LaBouve, Solutions Architect, Bishop Fox

“The cybersecurity industry knows there is a shortage of qualified security professionals, which means there’s too much work to go around to remain the same exclusive boys’ club. Fortunately, this growth is leading to a steady uptick in inclusion events and scholarships. Companies are realizing this more welcoming culture shift is key to building and retaining a talented, diverse workforce capable of keeping up.

A good start to getting more women involved in the industry is working with programs and organizations that encourage young women to become passionate about technology. For example, the Girl Scouts have a STEM weekend program that I’ve been involved with in the past. As for young women aiming to enter the cybersecurity field, I suggest finding a supportive network, community, or mentor they trust. This industry can be overwhelming and hard to navigate on your own.”

3. Sigalit Shavit, Chief Information Technology Officer, CyberArk

“The people that the industry looks for in cyber are curious, versatile, and can handle varied professional challenges with aplomb. The background that is a good fit is often IT systems engineering, but people with this skill set will often move to the next hot area of IT; DevOps has been a popular choice in recent years. So, in cybersecurity, for it to be an attractive development path, employers need to create that same buzz.

Cybersecurity as a discipline is starting to come through in secondary and tertiary education, but we need younger kids to say that they want to be in cyber. Coding is now taught in many junior and middle schools and smartphones are everywhere once children get to be 11 or 12, so that familiarity with technology is already there. Cyber could and should be put into the same context as teaching children about how to stay safe online. Ultimately, we need to get to boys and girls while they remain unbiased about what they want to do later in life and make cyber an exciting career choice.”

4. Heather Ricciuto, Talent Outreach Program Manager, IBM Security

“With three million unfilled jobs in cybersecurity globally, we must open up the aperture on the search for talent.  By focusing on skills and expanding pathways to good-paying jobs in cybersecurity through new collar programs like P-TECH, apprenticeships, veteran hiring, and tech re-entry for women, not only can we build a strong talent pipeline, but we can build a more diverse and inclusive workforce.

Promoting inclusion: A focus on diversity and inclusion includes attracting and retaining more women in cybersecurity. Before the global pandemic, we had a gender gap. In the wake of the global pandemic, women have exited the workforce by the millions. We believe that a focus on skills and flexibility can help keep women in the workforce and bring those who had dropped out back into the workforce.

At IBM, we are focused on equipping both students and professionals from a variety of backgrounds and education levels with the in-demand skills needed for a career in cybersecurity. Promoting diversity and inclusion in our workforce helps us ensure that innovations benefit the many, not just an elite few—which is one reason why IBM has partnered with Hacker Halted in recent years to sponsor free attendance to the annual conference for women and veterans.”

“CISO needs to speak the language which the CIO, CEO, and the Board speaks or understands”

current state of cybersecurity industry

Until a few years ago, “cybersecurity” was a word limited only to the IT teams of your organization. But the high-profile data breaches and hacking attempts in recent years have made this “offbeat” word one of the most searched one across various search engines. Cybersecurity is no longer just a computer-related issue, but a real-life threat too. We have seen this from the very recent cyberattack on Florida’s water supply unit, which was aimed at poisoning nearly 15,000 people in the state.

To discuss the gravity of the issue at hand, we got onboard Pawan Chawla, CISO of Future Generali India Life Insurance Company Limited. Chawla has an overall experience of over 18 years in companies of diverse sizes and sectors including Banking, Financial service and Insurance (BFSI), FMGC, Business Process Outsourcing, E-Commerce, and Business & Technology Consulting. His core technical expertise lies in the understanding of network, web, thick client, and mobile application vulnerabilities and the ability to perform static and dynamic security assessments. Additionally, he has sound knowledge of CVSS and Bash Shell scripting to complement his understanding of regulatory and statutory compliances such as ISO 27001: 2013, NIST SP 800-53, PCI DSS v3.2, COBIT, HIPAA, SOX, IRDA’s Cyber Security Framework, and GDPR Framework.

This exclusive interview was conducted by CISO MAG’s Technical Writer, Mihir Bagwe.

Edited excerpts follow:

You have been in the field of cybersecurity for over a decade now. Leaping into this field has many origins. What’s your story? How did you land where you are today?

I started working with computers in the mid-1990s. Back then as a student, I had access to x486 machines of many kinds, various types of PCs, and other devices. Also, in the late 1990s, InfoSec was a subset of IT. Post-identification, what used to be called a bug is now called vulnerability. There was limited/no exploitation. In the early 2000s, I saw Infosec evolving as a professional field in itself. In the day, there weren’t enough information security certifications, except a few in the network domain like CCNA, CCNP, and MCSE.

I have always emphasized hands-on experience over certification. I always told myself, “Be an expert “from” and “away” from the keyboard. And that is how I began my journey. It was my quest that led me into this field.

To be in cybersecurity, an individual should have only one overwhelming passion, that is, ‘the passion to play with new technologies’

The state of cybersecurity in the strange times that we are living in today is far different from what it was a few years ago. What’s your view on the role of cybersecurity today for SMBs alike?

Cybersecurity has evolved vastly over the past 20 years, and one of the biggest changes is its ubiquity. In earlier times, we only had to worry about a computer being infected with a virus, whereas, now we live in a more connected world. Our homes, workplaces, and public spaces, smart devices such as speakers, watches, and smartphones are all digitally connected.

I remember the days when the discussion on cybersecurity was surrounded by the fact that we need to add more hurdles and additional layers of complexity into the technology.

It was argued that cybercriminals will have a harder time breaking into systems that were complex and had numerous barriers at the entry points.

However, things have changed drastically over the years. There’s a growing understanding of the relevance of behavioral science techniques, and a realization of how machine learning and data analytics can support cyber awareness, behavior, and culture programs. Cybersecurity is now being led this way.

Digitization was always on the cards for future growth. But the digital flux that came in the year gone by, many believe was not accounted for. Do you think this has thrown an open challenge for cybersecurity teams? If yes, then what kind of challenges are they facing? 

We have experienced that the COVID-19 pandemic has accelerated technological adoption. Yet, it has exposed cyber vulnerabilities, the unpreparedness of businesses, and correspondingly, exacerbated the tech inequalities within and between societies.

Looking at the year ahead, it is critical to continue elevating cybersecurity as a business issue and develop more partnerships between business leaders and regulators. Just like any other strategic challenge, cybersecurity cannot be addressed in silos.

Here is a list of three cybersecurity challenges that should be considered and tackled in 2021:

 Digital Adoption  – Digitalization increasingly impacts all aspects of our lives and industries. After seeing rapid adoption of machine learning (ML) and artificial intelligence (AI) tools, as well as an increasing dependency on software, hardware, and cloud infrastructure this is one vertical that every business needs to take care of.

 Dependency on Third Parties  – We operate in an ecosystem that is likely more extensive and less certain than many may recognize. Organizations must consider the breadth of their exposure to third parties and must take steps to assess the real extent of their entire attack surface and resilience to threats. A cross-collaborative process involving teams across different business units is required to make sure there is an acceptable level of visibility and understanding of digital assets.

 Lack of Cybersecurity Expertise  – Cyberattacks like ransomware are growing fast and the COVID-19 pandemic has aggravated this threat furthermore. Preventative measures for ransomware or any other cyberattack should include preparations assuming that you are going to be hit eventually. Backup IT resources and data, and put in place measures to ensure continuity of operations. It is important to conduct regular drills and train the IT teams in realistic cyber response plans.

Speaking about cybersecurity teams, is the cybersecurity talent shortage a reality or myth?

The cybersecurity industry is facing a talent shortage, so yes, it is very real.

Companies are failing to find right resources with the right talent and skillset.

The problem is most candidates applying for cybersecurity positions do not have prior experience or an understanding of cybersecurity. Candidates think it is a buzz word which they shall add to their profile, hence they hit and try to get through a position in the organization.

A key contributor to such a shortage is the fact that candidates are underqualified. Even if qualified candidates exist, companies are struggling to find them and wasting resources clearing out applicants that cannot fulfill the duties of the role. Luckily, if you find a good trainable resource, it takes time for inexperienced workers to become truly “qualified” by gaining on-the-job experience in modern IT processes.

AI and ML technologies are considered “million-dollar” babies and being projected as the future of cybersecurity. But are they capable of filling the void of talent shortage? Or are they just means to enhance security measures?

The internet has become a part of our lives, growing every second with us each day. A new change takes place every day, making the current system obsolete. Adjusting to this change is not always easy. The risks associated with the internet are many and affect the security of individuals to a great extent. With the introduction of Artificial Intelligence and Machine Learning, processes are being automated. These technologies will make things convenient for internet users but at the same time also help hackers who use AI to organize multiple and synchronized cyberattacks.

AI and ML are data-driven approaches to make decisions with no explicit programming involved. It can help cybersecurity experts in analyzing high volumes of data sources and streamline it in many ways.

Following are the advantages of AL and ML:

 Building correlation of events  – Since cyberattacks are nothing more than various events, hence correlation of events becomes information for identification, execution, and protection. AI and ML help in correlating various data sets by organizing them in a specific pattern, scanning various possible threats, making a predictive analysis, and forecasting the next attack, with which we can take proactive steps to protect the same.

 Data cleaning  – Using data cleansing techniques, continuous auditing of data protection techniques can be done to safeguard the users and other relevant parties, checking if the restrictions placed are working effectively.

 Threat actors’ detection  – With the help of AI and ML, various malware and infections can be easily detected by setting up a security platform that has a built-in mechanism of scanning huge amounts of data, data networks and recognizing any possible threats.

Back in the day, communicating the importance of cybersecurity to the C-Suite was a task. But cybersecurity is no longer a corner piece in the newspaper, it has moved to center stage and there is a growing awareness of the monster beneath. So, has this changed the mindset of the C-Suite? And have they finally begun prioritizing it?

Cyberattacks on businesses are never going to end. As long as technology continues to advance, the sophistication of cyberattacks will increase. While such attacks are becoming sharper and more malicious, there are still a significant number of businesses falling victim to the same old tricks.

It is important to understand cybersecurity is not a CIO, CISO, or IT department risk. Breaches, leaked documents, and cybersecurity attacks impact the entire organization and can cause irreversible damage to its reputation and competitive edge. Thus, thwarting a cyberattack or breach is a responsibility that must be shared amongst all employees, and not just C-suite and board members led by the CISO.

The C-suite and senior leadership are now actively involved in defining an organization’s risk strategy and risk tolerance levels.

This helps in developing a comprehensive and robust cybersecurity risk plan for the organization. The C-Suite along with the CISO ensures that they know how their divisions affect the company’s overall cyber risk. Also, regular discussion with the company’s board of directors regarding these risk decisions now ensures visibility to all company decision-makers.

The C-Suite and senior leaders are now actively constructing policies rolled from the top to down to ensure everyone is empowered to perform the tasks related to their role in reducing cybersecurity risk. A top-down policy defines roles and hence limits the power struggles that can hurt IT security.

Apart from the fact that it helps maintain customers’ trust, why do you think businesses need to prioritize cybersecurity in today’s times?

We all agree cybersecurity is the need of the hour today. Cybersecurity needs to match the business needs by adopting the changing needs of stakeholders along with the right mandate to introduce new products or services. Similarly, businesses need to understand and involve the security team right at the beginning, not at the end. Businesses need to reinvent themselves to ensure smooth and continuous delivery.

Cybersecurity is a continuous, proactive activity, not a task or a single point in a process. It is a holistic strategy including people, processes, and technologies that integrates security at every level, instead of downstream, which is often too late.

With the acceleration in technology development, it is important to have adopted strategies that meet the increased throughput with the flexibility that will empower developers to focus on product delivery without compromising organizational risks.

Just as it is important to promote security organization-wide, businesses need to understand the full impact of an agile approach. Business functions shall integrate themselves as vital partners with diverse teams and support them in multiple ways.

To ensure security, investment is to be done in strategic automation across the software delivery life cycle (SDLC) to ensure the longevity of the security program in the organization.

You are now leading security operations for one of the top insurance companies in India. Can you give us an overview of what a cyber-risk policy or cyber-insurance covers? What is the primary reason to buy a cyber-risk policy?

A data breach not only damages just computer systems in an organization, but it also damages the reputation of the organization.

As technology has become increasingly integrated into individuals’ lives, the risks of getting sensitive and personal data compromised, including Aadhaar numbers, bank, and credit card information, will continue to be on a rise.

The term ‘Cyber Insurance Policy’ is used to define a range of covers in very much the same way the word cyber is used to define a broad range of information security-related tools, processes, and services.

My advice for your readers would be to cover the following points while opting for a Cyber Insurance Policy:

 Data breach/privacy crisis management cover  – This includes the expenses related to the management of an incident, the forensic investigation, the remediation, customer notification, call management, legal costs, court attendance, and regulatory fines.

 Multimedia/Media liability cover   – It should cover third-party damages that include specific defacement of website and intellectual property rights infringement.

 Extortion liability cover  – This includes losses due to an extortion threat and professional fees related to dealing with the extortion.

 Network security liability  – Should include third-party damages as a result of denial of access costs related to data on third-party suppliers and costs related to the theft of data on third-party systems.

Lastly, what piece of advice would you give to the modern-day CISO or a person who aspires to be one in the coming years?

Two pieces of advice:

Always remember a security leader is a seeder of building security culture in an organization. It is important to build a robust security culture that requires constant nurturing and development. As a CISO, it is your responsibility to nourish the same in the organization.

A strong security culture not only interacts with the day-to-day procedures of the organization but also defines how security influences things that an organization provides to others. A sustainable security culture is persistent, not a once-a-year event, but embedded in everything we do.

CISO needs to speak the language of the CIO, CEO, and what the Board speaks or understands.

Following are the practices which I follow:

 Ensure not to use technical terminology  – The C-suite does not want to know how things work, they want to be assured the system will always be up and running.

 Present facts and numbers  – Explain the problem through numbers and facts. Be a solution enabler, not a problem creator.

 Business first  – When preparing slides, talking with security employees, and analyzing field reports, always correlate that information with the core business of the company.

 Talk business  – When with management, I always refer to how actions will affect the company’s service. Explaining the impact in case of certain disapprovals is the most important part of the job.

 Don’t scare  – Data is important to be shared, share data in a way that allows management to make informed decisions like where is it best to place their security investment to mitigate their greatest risk.

 Get to the point  – Get to the point right from the start. The management wants to know upfront why you’re there in the first place.

About the Interviewer

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity tech and trends.

 


Other Interviews from the Author:

Why France Digitale Filed Privacy Complaint Against Apple

Apple, Apple security update

France Digitale, a French startup lobby representing many digital entrepreneurs and venture capitalists, has filed a complaint against Apple for violating European Union (EU) data privacy laws. As per the complaint launched with the French data privacy watchdog CNIL, France Digitale has alleged that Apple’s iOS 14 does not comply with EU’s privacy requirements.

What’s the issue?

France Digitale claimed that though iPhone users are asked permission to use key identifier information to define targeted and campaign ads, the default settings in iOS 14 allow Apple to carry its own targeted ad campaigns without users’ consent. It also claimed that Apple’s tracking functionality allows it to share the data it collects with associated businesses without users’ knowledge.

As per EU data privacy requirements, organizations should take users’ agreement to use their data for advertisement purposes. The data guidelines also provide the right to users to ask businesses how they are harvesting users’ data and how they are going to use it.

“It’s a startup version of David versus Goliath, but we are determined,” said Nicolas Brien, CEO of France Digitale.

“The allegations in the complaint are patently false and will be seen for what they are, a poor attempt by those who track users to distract from their actions and mislead regulators and policymakers,” Apple said.

Flaws in iOS Call Recording App

The complaint by France Digitale comes after researchers found a security vulnerability in the iOS call recording app “Automatic call recorder” that gave access to the conversations of thousands of app users. According to Anand Prakash, security researcher and founder of PingSafe AI, who discovered the flaw, the vulnerable app used open-source intelligence and exposed hostnames and other sensitive data from its cloud storage. Read more…

Ryuk Ransomware Takes Down Systems of Spanish Government Agency, SEPE

Ransomware attacks, LockBit Ransomware

The network systems of the State Public Employment Service (SEPE) were taken down temporarily after a ransomware attack hit more than 700 agency offices across Spain. In an official statement, the SEPE director Gerardo Guitérrez claimed that Ryuk ransomware operators were behind the security incident. Reportedly, the attackers encrypted the systems with Ryuk ransomware. However, Guitérrez clarified that payroll information, unemployment benefits, and other personal data were not affected by the ransomware attack.

SEPE is a Spanish government agency for labor that provides employment opportunities to the public. The ransomware attack disrupted hundreds of thousands of users who had their appointment scheduled with the agency. The ransomware is said to have spread beyond SEPE’s workstations and also targeted the agency’s remote working employees’ devices.

“Currently, work is being done to restore priority services as soon as possible, among which is the portal of the State Public Employment Service, and then gradually other services to citizens, companies, benefit and employment offices. The application deadlines for benefits are extended by as many days as the applications are out of service. In no case will this situation affect the rights of applicants for benefits. Confidential data is safe. The payroll generation system is not affected and the payment of unemployment benefits and ERTE will be paid normally,” Guitérrez said.

Ryuk Ransomware Gang Made Over $150 Mn

Ryuk is a ransomware-as-a-service (RaaS) active since August 2018. The group attacked more than 20 health care organizations last year. A series of Ryuk ransomware attacks targeted multiple hospitals in the U.S. Cybercriminals compromised critical network systems across six hospitals in a single day. A recent analysis found that the Ryuk ransomware operators earned more than $150 million worth of Bitcoins from ransom payments after their cyber intrusions globally.

150,000 Security Cams Hacked; Tesla, Cloudflare, Equinox on the Victims’ List

vulnerability in IoT devices

Verkada, a video surveillance and AI security-based company, was reportedly breached on March 7 by a Swiss hacker named Tillie Kottmann (also known as ‘Till’). Kottmann is a representative of the threat group known as “APT 69420 Arson Cats,”  and had also targeted multi-national automobile companies like Nissan and Mercedes, to expose their system vulnerabilities. The Verkada security breach has led to the leak of the video feed from nearly 150,000 cams worldwide. Its victims’ list includes Tesla, Cloudflare, Equinox, prisons, hospitals, schools, and many more.

 Key Highlights 

  • Tillie Kottmann, part of a hacktivist group dubbed “APT 69420 Arson Cats,” published the screenshots and footage of the leak on her Twitter feed. Twitter has since suspended her account.
  • The attack was targeted at a Jenkins server used by Verkada’s support team to perform bulk maintenance operations on customer cameras.
  • The attackers gained illicit access into this server on March 7, 2021 and retained it until the noon (PST) of March 9, 2021.
  • Verkada has confirmed that the security breach compromised its video and image data from a limited number of cameras (although Kottmann claims that feeds from 150,000 cameras were accessed), a list of client account administrators including names and email addresses, and Verkada’s sales orders.

The Verkada Security Breach: As it Happened

Bloomberg first broke the news post Kottmann’s tweets showing evidence of the leaked footage. It contacted Kottmann to know the complete details of the compromised data. Responding to the question of the motive behind the hack, Kottman said,

Lots of curiosity, fighting for the freedom of information and against intellectual property, a huge dose of anti-capitalism, a hint of anarchism — and it’s also just too much fun not to do it.

On the other hand, when Verkada was informed about the security breach, it took immediate action and set up a team of experts to curtail the issue. Their internal investigation found out that the attackers gained access to their data through a Jenkins server, which is used by Verkada’s support team for maintenance work like adjusting camera image settings upon customer request. Once the threat actors got access to the server, it was easy to obtain client account administrator credentials that helped them bypass Verkada’s authorization and two-factor authentication security measures.

Further internal investigation, which is being carried out with the expert help from two external firms – Mandiant Solutions and Perkins Coie – has also noted that, until now, no evidence of Verkada’s user passwords or password hashes, internal network, financial systems, or any other business systems being compromised have been found.

However, Filip Kaliszan, CEO, Verkada Inc., did acknowledge the breach, stating,

Attackers gained access to a tool that allowed the execution of shell commands on a subset of customer cameras; however, we have no evidence at this time that this access was used maliciously against our customers’ networks. All shell commands issued through our internal tool were logged.

Kottman’s Side of the Story

Kottmann’s side of the story, however, contradicts what Kaiszan’s update says. Talking to CBS News, Kottmann revealed that her group first found a Verkada internal administrator username and password stored on an unencrypted subdomain. According to her, the company had kept an internal development server exposed to the open internet that contained “hard-coded credentials” for a system account with “super admin” rights. Kottmann added,

We did not access any server. We simply logged into their web UI with a highly privileged user (account).

Kottmann shared around 5GB of archives with CBS and Bloomberg that included videos and images from the hack. As per her claims, the threat group was able to download the feed from nearly 150,000 security cams placed in locations like hospitals, prisons, schools, public areas, and even in the vicinity of some known companies like Tesla, Nissan, Equinox, and Cloudflare, among others.

Experts Speak…

Asaf Hecht, Cyber Research Team Leader at CyberArk says, “The potential for breaching common IoT devices, like security cameras, is something we’ve been talking about for years. Cameras, much like other hardware devices, are often manufactured with built-in or hard-coded passwords that are rarely, if ever, changed by the customer.

While Verkada reportedly took the right steps to disable all internal administrator accounts to prevent any unauthorized access, it was likely too late. The attackers had already landed. Based on what’s been reported, this attack follows a well-worn attack path – target privileged accounts with administrative access, escalate privileges to enable lateral movement, and obtain access to highly sensitive data and information – effectively completing the intended goal. What we’ll need to especially watch in this case is the potential for far-reaching implications for privacy regulations including HIPAA.

Talking about the gravity of the attack and the seriousness of cybersecurity in physical security professionals, Christian Morin, CSO & Vice-President of Integrations & Cloud Services, Genetec, said, “As an industry, and as manufacturers in physical security, we cannot take these hacks lightly. The potential broad reaching impact of these hacks on physical security systems, including providing a beachhead to facilitate lateral movement onto networks, resulting in data and privacy breaches or access to critical assets and infrastructure, cannot be understated.

In one of our recent surveys, the State of Physical Security, we uncovered that only about 30% of security professional respondents were prioritizing cybersecurity initiatives in 2021. I can only hope this most recent incident acts as the wakeup call required to ensure every organization in the chain understands and acts upon the critical importance of privacy and security in the design, development, implementation, and operations of physical security systems.

Related News:

Hacking Alert! Footage of 50,000 Singaporean Homes Lands on the Internet

Over 100,000 Security Cameras in U.K. Are Hackable: Report

How Australia Plans to Thwart Ransomware Attacks in the Country

Cryptocurrency scams in Australia

Ever since ransomware attacks in the country increased, the Australian government stepped up its cybersecurity standards to thwart cyberattacks. Committed to the same, the government developed and launched Australia’s Cyber Security Strategy 2020 last year.

Ransomware – A Rising Threat in Australia

Ransomware attacks have become the highest impacting cyberthreat in Australia. The attacks forced many organizations to spend millions in ransom payments to recover their encrypted data. According to government analysis:

  • One in three users in Australia were impacted by cybercrime in 2019.
  • There are over $29 billion annual costs of cyberattacks on the Australian economy.
  • Nearly, 61% of executives consider ransomware attacks likely in the next 12 months.
  • And 62% of small to medium businesses have experienced a cybersecurity incident.

Tackling Australia’s Ransomware Threat

The federal government has provided advice for businesses and users in Australia on how to counter ransomware attacks. The advisory “Locked Out: Tackling Australia’s Ransomware Threat,” which is prepared by the Cyber Security Industry Advisory Committee and the Department of Home Affairs, brings awareness for all Australians and their businesses on the current ransomware threat landscape.

The newly released advisory recommended users and organizations to:

  • Use of multifactor authentication.
  • Keep software up to date, archive data, and back-up.
  • Build-in security features to systems and train employees on good cyber hygiene.

 Don’t Pay Ransom

The Australian Cyber Security Centre (ACSC) advised organizations not to pay ransom to cybercriminals, as it is illegal under any circumstances. Whenever an organization pays a ransom to a threat actor group, there is a potential risk that paid ransom may be used by terrorist organizations.

“But for an organization which is under attack the decision to pay or facilitate payment of a ransom can be further complicated – and pressured – as the legal position is unclear. At worst, payment of these amounts may be unlawful and involve committing a criminal offense,” ACSC said.

Increase in Cybersecurity Investment

Amid growing ransomware attacks and the fear of compliance audit failure, the majority of the organizations are in plan to step up their budgets for cybersecurity. The federal government announced a cybersecurity investment of $1.67 billion to build new cybersecurity and law enforcement capabilities. The investment assist organizations to protect themselves from evolving cyberthreats.