Home Blog Page 108

“Cybersecurity is still not something that is discussed as an option”

It has been an age-old myth that women prioritize family over work. Women are under-represented in tech and leadership. According to an (ISC)² Cybersecurity Workforce Report, women working in cybersecurity account for about one quarter (24%) of the overall workforce. Though there’s a continuing inequity, things have begun to look brighter. Workforces – especially post-COVID-19 pandemic and lockdown – have been offering flexibility in timings, empowering women to lead, and showing support through digital mediums. Change happens with time, but it requires consistency. There is a need to go beyond the 24%.

Let’s hear what Roota Almeida, Chief Information Security Officer, Delta Dental of New Jersey and Connecticut, has to say about Women in Cybersecurity:

Less representation of women: There are several reasons for this. The first and the most important reason is that cybersecurity is still not something that is discussed as an option for a college degree in schools for graduating high schoolers. It gets buried under IT for these students and is seen by young women as “something only boys are interested in” or “geeks do”. I have spoken to many seniors in high school during career coaching events and have noticed that they do not know Cyber Security as an option to choose for college courses. Hence, few women take cybersecurity courses in college, and fewer join the workforce. The problem is at the grass-root level and needs to be fixed there.

There is also an issue with having women stay in this field for a longer time. Due to the stress and high demand of the job they do not pursue this career or choose other options.

In addition, the number of women supporting families on their own is increasing quickly. The proportion of families headed by a single mother is growing. These numbers are dramatically higher in certain demographics. Our country (U.S.) unlike many other countries like the EU, lag way behind in efforts to help parents take care of their children and stay in the workforce. Most companies have 6-8 weeks of maternity leave depending on regular delivery or a C-section. This significantly impacts the number of women who stay in the workforce after having children.

Lack of women role models: I don’t think so. There are many women role models in technology and cybersecurity. LinkedIn and Forbes have listed several women over the years who have been great role models in cybersecurity. It does not have to be women’s role models; men could be great role models too — for women. There are many men I have worked with that support women and can be amazing role models.

Cybersecurity scholarships for women: Scholarships can help the underprivileged and can boost confidence. It is a great way to open doors for women who traditionally might’ve not taken up that cybersecurity course or certification, if not for a scholarship.

What can men do? Like in any other field, it is important to have sponsors and mentors who can support you. Men can be great sponsors who can invest in and work actively to advance your careers, and they can be excellent mentors as well, who can guide you through your career aspirations. It is important you choose the right sponsor/mentor for you.


Roota-AlmeidaRoota Almeida is the Chief Information Security Officer at Delta Dental of New Jersey and Connecticut (DDNJ, Inc.). She believes more women should be encouraged to pursue STEM careers and has started a summer internship program at DDNJ, Inc. specifically designed to give graduating female high school students insight into the field of corporate cybersecurity.

Roota is a recognized industry thought leader who serves as a member of the Board of Advisors at several organizations, a governing body chair for Evanta’s NJ CxO Summits and other technology conferences, a faculty and a security awards judge.  Her in-depth experience and expertise in the field of information security and risk management can be measured by the various articles, eBooks, interviews, and podcasts she has to her credit. Roota is also working to build and encourage new talent and solutions in the security arena.

Roota holds CCISO, CISSP, CISM and CRISC certifications.

Disclaimer

Views expressed in this article are personal.

CISO MAG’s March issue on Women in Cybersecurity is out. Preview here. Subscribe now!

Beware! COVID-19 Vaccine-related Phishing Scams on Rise

covid-19 vaccine, vaccine

As the world steps up to COVID-19 vaccine campaigns, state-sponsored actors are tapping the situation with targeted cyberattacks and scams. From targeting vaccine research centers to spreading imposter vaccine versions on the dark web, threat actors are capitalizing on the pandemic with Coronavirus vaccine-related phishing campaigns.

A recent analysis from Barracuda, conducted between October 2020 and January 2021, found that threat actors are leveraging vaccine-related emails in their targeted spear-phishing attacks. The research revealed that the number of vaccine-related phishing campaigns increased by 12% after some pharmaceutical companies announced the availability of vaccines in November 2020.

“Cybercriminals use phishing attacks to compromise and take over business accounts. Once inside, more sophisticated hackers will conduct reconnaissance activity before launching targeted attacks. More often than not, they use these legitimate accounts to send mass phishing and spam campaigns to as many individuals as possible before their activity is detected, and they are locked out of an account,” Barracuda said.

Image Source: Barracuda

Types of Phishing Attacks

Barracuda researchers stated that attackers used two types of spear-phishing attacks: Brand Impersonation and Business Email Compromise attacks.

  • In brand impersonation attacks, scammers leveraged COVID-19 vaccine-related phishing emails mimicking popular pharmaceutical companies. The phishing emails contained links to fraudulent websites that are advertising early access to vaccines and asking victims for payment. Besides, the fraudsters impersonated health care professionals, tricking users to reveal their personal information to check eligibility for a vaccine.
  • In business email compromise (BEC) attacks, scammers posed HR specialists, recommending vaccines to their employees. In a BEC attack, cybercriminals first steal legitimate business email account credentials, which are later used to launch financial fraud campaigns like fraudulent email messages, requests for out-of-channel funds transfers, and deleted accounting trails.
Image Source: Barracuda

Barracuda researchers stated they found various phishing emails claiming: “offers to get the COVID-19 vaccine early,” “join a vaccine waiting list,” and “have the vaccine shipped directly to the home.” Researchers urged users to avoid clicking/opening such fraudulent links or attachments that they receive from unverified sources.

State-Sponsored Attacks on COVID-19 Vaccine Research

Recently, the U.K.’s National Cyber Security Centre (NCSC), Canada’s Communications Security Establishment (CSE), and the National Security Agency (NSA) of the U.S. stated that a cyberespionage group “APT29” which is linked to Russian intelligence services, tried to steal information and intellectual property related to the testing and development of Coronavirus vaccines. The group is using its custom malware known as WellMess and WellMail and other techniques to target government entities. Read the full story here…

Don’t Apply! U.S. DoJ Warns About Fake Unemployment Benefit Websites

Department of Justice

The U.S. Department of Justice (DoJ) is warning users and organizations about targeted attacks from cybercriminals stealing sensitive users’ data. In an official release, the agency stated that threat actors are creating fake websites mimicking legitimate sites of the State Workforce Agency (SWA) to illicitly capture consumers’ personal information.

It is found that fraudsters are sending spam text messages and phishing emails, claiming to be SWA members, to trick users enter into fake websites. “The fake websites are designed to trick consumers into thinking they are applying for unemployment benefits and disclosing personally identifiable information and other sensitive data. That information can then be used by fraudsters to commit identity theft,” the DoJ said.

The DoJ urged users to be vigilant and never click on links in text messages or emails claiming to be from the SWA asking to apply for unemployment insurance benefits. The agency also asked users to report if they receive any phishing text message or email claiming to be from the SWA.

“Phishing messages may look like they come from government agencies, financial intuitions, shipping companies, and social media companies, among many others. Carefully examine any message purporting to be from a company and do not click on a link in an unsolicited email or text message. Remember that companies generally do not contact you to ask for your username or password. When in doubt, contact the entity purportedly sending you the message, but do not rely on any contact information in the potentially fraudulent message,” the DoJ added.

Earlier, the department issued a fraud alert asking people to be vigilant when providing any sensitive information over the phone, after cybercriminals falsely represented themselves as DOJ authorities to obtain personal information from the call recipients as part of an imposter scam. The warning came after the Office of Justice Programs’ Office for Victims of Crime (OVC) received multiple complaints from individuals stating that they have received calls from unknown parties claiming to be from the DoJ.

Chinese Hacking Group “Hafnium” Exploiting Microsoft’s Email Software Server

microsoft, flaws in SonicWall SRA SMA

Security incidents where cybercriminals exploit critical vulnerabilities of Microsoft products have become rampant in recent times. Microsoft Threat Intelligence Center (MSTIC) recently identified a state-sponsored threat actor group targeting unpatched vulnerabilities in Microsoft systems.

Dubbed as Hafnium, the hacking group is suspected to be operating from China, with leased virtual private servers (VPS) in the U.S. Earlier, the group targeted several entities in the U.S. to exfiltrate sensitive data from multiple industry sectors, including infectious disease researchers, law firms, higher education institutions, defense contractors, policy think tanks, and NGOs.

Hafnium’s Attack Tactics

Microsoft’s research team stated that Hafnium is engaged in several attacks by leveraging unknown exploits targeting on-premises Exchange Server software. The Hafnium threat group’s attack vector includes three steps:

  • Initially, the group gains access to an Exchange Server either with stolen passwords or by using the previously undiscovered vulnerabilities to disguise itself as someone who should have access.
  • Next, they create what’s called a web shell to control the compromised server remotely.
  • Finally, the group uses that remote access – run from the U.S.-based private servers – to steal data from an organization’s network.

Microsoft has released security updates to protect customers running Exchange Server on their networks. The technology giant recommended all Exchange Server users and organizations to apply the patches as early as possible.

“Even though we’ve worked quickly to deploy an update for the Hafnium exploits, we know that many nation-state actors and criminal groups will move quickly to take advantage of any unpatched systems. Promptly applying today’s patches is the best protection against this attack,” Microsoft said.

Microsoft Flaws Raise Fears at White House

Cybersecurity experts recently discovered security flaws in Microsoft software for email and contacts that raised severe concerns at the White House and the highest levels of the U.S. government. The organizations are asked to immediately apply patches to avoid any threats.

“This is a significant vulnerability that could have far-reaching impacts.  First and foremost, this is an active threat.  Everyone running these servers — government, private sector, academia — needs to act now to patch them,” said Jen Psaki, the White House press secretary.

Tech Tip: How to Avoid Online Scams

Senior citizens data

Online scams are getting sophisticated as cybercriminals are using advanced techniques and tools. Stay alert to stop scamming attempts and protect your data or money from falling into the wrong hands. Advanced online scams are targeted at people from all walks of life. Irrespective of an individual’s age, income, and background, they can become victims of online fraud. All of us are equally vulnerable, and no one can stay safe without learning how to avoid such deceptive hoaxes.

By Caroline Jones

The success mantra of online scams

Scammers fine-tune their campaigns to make them sound real and trap you when you’re expecting it the least. These perpetrators are smart and use the latest technology and tools, along with advanced products and services to create stories that can easily convince their targets to give away personal information or money. Exploiting people’s fears and concerns is one of the most popular schemes ever. Hence, you should know how to stay calm when a scam targets you.

Tips to protect against online scams

1. Accept that online scams exist

Scammers are for real, and they’re just waiting around the corner with phishing. Every time you start dealing with an unknown person or a contact over the phone, mail, or message, you must consider it a possibility that you’re dealing with a scammer. Don’t believe something that sounds ridiculously good. Nothing in this world comes free, and everything has a price tag attached to them. So, if one fine morning you receive an email message about winning a million-dollar lottery, chances are very high that it’s an ugly trap.

2. Dig deeper before committing

If you ever have doubts in your mind regarding a business’s legitimacy or the intentions of an unknown person, you should dig deeper before committing. An online search for an individual or a company is easier with advanced search engines like Google. You can carry out an in-depth search for an individual or business based on the basic details they share. If you ever receive a request for money or undue favor from a friend, always call them up to verify.

3. Don’t click on suspicious messages, links, or pop-ups

A classic style followed by scammers is to share malicious messages and links via email or messengers. Thus, you must avoid clicking on anything that looks or sounds remotely suspicious, including pop-up windows on a website. Additionally, you can install a Virtual Private Network or VPN like Atlas VPN that automatically blocks access to potentially malicious pages and pop-ups. In addition, it encrypts your web traffic, making it more difficult for scammers to intercept or modify your online communications.

4. Don’t give remote access to your device

Remote access scams imply that people encounter criminals impersonating legitimate IT technicians or other service representatives. Usually, cybercriminals will insist that there is a problem that can only be fixed by them after giving them remote access rights. However, scammers can install malicious applications and even steal critical information stored on your device, so remote access is a big no-no.

5. Securing personal data

Scammers are always on the prowl to sneak into your device to steal personal information or trick you into revealing them. Thus, securing data stored on your computer is equally important. Use encryption software coupled with a data locking application to secure the data stored on your computer or phone. Install the application on your PC or phone to lock the folders and files. Even if someone manages to sneak into your PC or phone, they won’t be able to decipher anything as all data would be unreachable.

6. Password protect your computer and mobile devices

This is probably the oldest and easiest way of securing personal data stored on your computer and mobile devices. However, passwords should also be a priority for each account you operate. Generate complex combinations and apply them only once. Also, do not leave your Wi-Fi without a network password.

7. Choose passwords carefully

You must choose difficult passwords while updating them from time to time. It’s always better to use a mix of numbers, letters, and special symbols. Avoid using the same password for different accounts; a breach in one application will open up the floodgates to others as well.

8. Check the security and privacy setting for your social media accounts

All popular social media platforms offer advanced privacy and security settings on their platforms. You must check if the settings are as per your requirements and, if possible, block the visibility of your profile beyond your connection or friend list.

Apart from the above steps, you must never entertain any unusual requests from strangers asking for your details. Never share your banking information, credit card details, and other online account details with strangers or people you don’t trust. It’s easier to avoid online scams by using common sense and increasing awareness about data security.

SPECIAL FEATURES

About the Author

Caroline JonesCaroline Jones is an enthusiastic writer, gamer, and foodie, interested in helping people and becoming a veteran in all things technical. Cybersecurity is her passion, and the fight for digital privacy is one of her favorite subjects to dig deeper on a regular basis.

 

Disclaimer

CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

 

“Diversity has to be a KPI at the board level”

It has been an age-old myth that women prioritize family over work. Women are under-represented in tech and leadership. According to an (ISC)² Cybersecurity Workforce Report, women working in cybersecurity account for about one quarter (24%) of the overall workforce. Though there’s a continuing inequity, things have begun to look brighter. Workforces – especially post-COVID-19 pandemic and lockdown – have been offering flexibility in timings, empowering women to lead, and showing support through digital mediums. Change happens with time, but it requires consistency. There is a need to go beyond the 24%.

Let’s hear what Dr. Judith Wunschik, Chief Cyber Security Officer, Siemens Energy, has to say about Women in Cybersecurity:

Less representation: One issue is that cybersecurity recruits are mainly from the tech professions – IT, engineering, and math – which also have low gender diversity. The gender gap will hopefully start shrinking when we overcome our unconscious bias about girls’ capabilities, and also when we start from the top by recruiting diverse management teams.

Lack of women role models: To become a role model in the tech world is even harder for women than in other fields because there’s a much stronger unconscious bias in this domain in almost all cultures. In many countries, biased behavior on the part of teachers, society, and even parents has been revealed in STEM education. Even in fields where there are female role models, the gender gap is still large: for example, politicians in Germany. We need to actively work on diversity and equity and reverse the bias in society itself, by driving countermeasures like laws and regulations.

Cybersecurity scholarships for women: Scholarships may be able to increase the number of female tech experts, but they won’t close the gap in terms of the visibility of women in the upper levels of the hierarchy and the unconscious bias in some cultures.

What can men do? First, diversity has to be part of the CEO Agenda and a topic for the Board. It needs to be a KPI at the board level and should be implemented in the sustainability path of the enterprise. Diversity also has to be integrated with the culture and the work environment. Only then will we have a chance to change the bias in society so that role models will be there by default and the gender gap will shrink in all enterprises.


Dr. Judith Wunschik has served as Chief Cyber Security Officer for Siemens Energy since October 2019. She is accountable for securing Siemens Energy’s business operations, products, data, and assets as well as for ensuring compliance with cybersecurity regulations. She is serving as a thought leader for cybersecurity as well as an advisor to Siemens Energy’s senior leadership on cyber risks related to products, services, and operations. In her current professional role, she is building the future global cybersecurity capabilities for Siemens Energy, including Information Security Operations, Supply Chain Security Management, and Product & Solutions Security Services.

Previously, Dr. Wunschik held senior management roles in the European banking sector, most recently as Chief Information Security Officer for ING Germany and ING Groep N.V. in Amsterdam. She is highly experienced in working with deeply skilled expert groups and is a renowned public speaker and valued member of prestigious international security committees. Dr. Wunschik holds a Ph.D. in Solid State Physics and Computational Theoretical Physics from the University of Erlangen-Nuremberg.

Disclaimer

Views expressed in this article are personal.

CISO MAG’s March issue on Women in Cybersecurity is out. Preview here. Subscribe now!

Cloud Misconfigurations Pose Severe Threat to Mobile Apps Security

Mobile Apps Security, mobile apps

Inadvertent data leaks due to cloud misconfigurations continue to be a major risk for organizations. Here, cybercriminals often try to exploit vulnerabilities or setup errors in the cloud storage infrastructure. A recent analysis from mobile security firm, Zimperium, revealed that these cloud exposures also pose a severe threat for iOS and Android mobile applications. The research found that nearly 14% of mobile apps that use cloud storage had unsecure configurations and were vulnerable to various cyberattacks. Critical issues in mobile applications globally exposed users’ personal information, enabled fraud, and/or exposed IP or internal systems and configurations.

Zimperium’s researchers discovered misconfiguration issues on apps that were using popular public cloud services like Amazon Web Services (AWS), Google Storage, Google Firebase, and Microsoft Azure. In an automated analysis, the researchers found misconfiguration issues in more than 1.3 million Android and iOS apps. The company stated that certain apps are exposing the entire cloud infrastructure scripts and SSH keys.

Misuse of Data

Leak of sensitive information could allow an attacker to penetrate an organization’s computing infrastructure. “Having access to all of the infrastructure information can also allow an attacker to take over the backend infrastructure of the company, which in turn can allow the attacker to potentially jump to other infrastructure and hurt other products,” Zimperium said.

How to Boost Mobile App Security

Cybercriminals often rely on malicious apps to compromise sensitive information from millions of users. It is imperative for users and organizations to boost their mobile application security to defend against evolving cyberthreats. Not only manufacturers, but end-users must also follow the required security precautions while installing and using mobile apps. Organizational applications are prone to greater cybersecurity risks as they can provide access to the entire corporate systems and employees’ personal information. Read more…


EC-Council’s CISO MAG brings to you a webinar on “The Current State of Application Security.”  Register now!

Want to Close the Cyber Skills Gap? Get Women Involved!

The cybersecurity skills gap continues to pose challenges for organizations of all sizes and across all industries. And changes to the economy as a result of the COVID-19 pandemic are compounding the skills gap. In fact, the pandemic has made it clearer than ever before that the security skills gap is a severe problem. The rapid shift to remote work that companies around the globe undertook laid that bare.

By Sandra Wheatley, Senior Vice President, Threat Intelligence, Customer Marketing and Influencer Communications, Fortinet

As the model of remote work becomes the norm and infrastructures become more distributed, the need for IT professionals who have timely security skills and knowledge will only grow. More than ever before, organizations need to be creative and look to new solutions to address the cybersecurity skills gap. It has been a major problem for years, and it’s one that everyone talks about but that no one seems to know how to fix.

In parallel, there are still relatively few women in the industry. According to (ISC)2’s Women in Cybersecurity report, men outnumber women three to one. These two problems can be addressed in tandem; the skill shortage can be partially addressed by getting more women involved.

Getting women into cybersecurity

Women are half of the total population but only 24% of current cybersecurity professionals, according to recent surveys. Prior research by (ISC)2 showed women occupied only 11% of cybersecurity roles, so the number is growing, but it’s still not keeping up with the percentages of men in the workforce. Cybersecurity presents a valuable career opportunity for women, and it gives organizations a viable option for filling the skills gap that currently plagues the industry.

Women bring a broader skill diversity to cybersecurity roles. Recruiting and including more women in this space will not only fill some of the gaps, but research shows these actions will simultaneously create higher-performing organizations.

The Women in Cybersecurity report found that women who work in cybersecurity tend to have higher education levels and are in the beginning of their careers. The latter detail matters because the industry needs a continued pipeline of skilled security professionals who can rise up the ranks as others retire.

The report also found that 44% of men in cyber hold a post-graduate degree while 52% of women do. This means women tend to be more educated, which bodes well for a strong cyber future. In addition, 45% of women in cyber are millennials, compared to 33% of men. This is significant because in the previous generation, Gen X, men comprise a larger percentage of the workforce (44%) than women (25%). Clearly, this younger generation of women is moving into cybersecurity.

It starts at the beginning – early-career and students

Building the talent pipeline for cybersecurity means starting earlier, with programs through high schools, colleges, and universities as well as apprenticeships and internships. There needs to be increased focus on promoting these programs to young women. Organizations should work with the public education sector to incorporate training and certification programs at the pre-career level.

Cybersecurity providers play an invaluable role here, as they are on the cutting edge of technology and current threats; they can provide up-to-date training that would be obsolete by the time someone obtained a four-year degree.

Creating a culture of mentorship and continued support

It can’t end at getting women into entry-level cybersecurity roles – there needs to be continued support and mentorship, not to mention equitable compensation. The aforementioned report found that women’s salaries still lag behind men’s. A 2020 report by Exabeam found that U.S. male respondents took home an average annual salary of $91,000, compared to $62,000 for women.

The good news is that the more women we see in cyber positions, the more likely it is that other women will start getting into this field – because cybersecurity will no longer be perceived as male-dominated or for men only. Biden’s selection of Anne Neuberger as deputy national security advisor for cybersecurity on the National Security Council will likely serve as a major inspiration for women of all ages.

At the same time, the onus isn’t only on women to bring other women into the field. Men have to be a part of the solution since they still dominate the cybersecurity workforce. They can help by serving as supportive allies as they recognize the need for a diversity of voices and skillsets within the industry.

Two birds, one stone

There’s nothing quite as satisfying as overcoming two problems with one solution. That’s the case with the cybersecurity skills shortage and the low number of women in cybersecurity. The global shift to remote work has significantly increased the threat landscape at a time when there already aren’t enough skilled professionals to keep networks secure. But by making strategic efforts to educate, mentor and ally with women, the cybersecurity industry moves closer to bridging the skills gap and benefiting from the education and particular skill sets that women bring it.


About the Author

Sandra Wheatley is responsible for Fortinet’s threat intelligence, customer marketing, security academy, and veteran’s training programs. Sandra has served on multiple non-profit boards and is a founding board member of US2020, a White House Initiative to improve STEM learning and increase the pipeline of STEM workers in the U.S. She holds a B.S. degree from Santa Clara University, a diploma in Community Leadership from Boston College, and a diploma in Corporate Responsibility from U.C. Berkeley.

Disclaimer

CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

CISO MAG’s March issue on Women in Cybersecurity is out. Preview here. Subscribe now!

“Don’t be afraid to ask about opportunities; fortune favors the bold”

Globally, gender stereotype has been a perennial impediment for women in all walks of life. Expressions like “girls are not good at math” and “engineering is more male-friendly,” continue to impact women in the workplace. Nevertheless, over the last two decades, women have challenged the status quo and spearheaded social, political, and economic battles. Similarly, they have excelled and gained significant ground in the world of cybersecurity, which was once considered an exclusive domain for men. And though men and women have equal access to participation in leadership and mentorship development programs, women face unconscious bias from their male counterparts.

To discuss the alarming gender gap in cybersecurity, Pooja Tikekar, Feature Writer at CISO MAG, engaged in a conversation with Lisa Ventura, CEO and Founder of the UK Cyber Security Association (UKCSA). Lisa is an award-winning cybersecurity consultant and her journey into the cybersecurity industry was a non-linear one as she spent many years in the entertainment industry working with Chris Tarrant, the first host of “Who Wants to Be a Millionaire” in the U.K. She made the move into cybersecurity in 2009. She is part of the Advisory Group for the newly created West Midlands Cyber Resilience Centre, sits on the board of Think Digital Partners, and is part of Cyber Security Valley U.K. Lisa is also a strong advocate for women in cybersecurity, the cyber skills gap, and neurodiversity.

Edited excerpts of the interview follow:

Your career path had predominantly been into content marketing and PR. What inspired you to switch to cybersecurity and to founding the UK Cyber Security Association?

I didn’t enter the cybersecurity industry straight away. After I completed my studies, I spent many years in the entertainment industry working with the host of “Who Wants to Be a Millionaire” in the U.K., Chris Tarrant, at his management company. I also worked with other high-profile TV and Radio presenters in the U.K. such as John Kettley, Richard Allinson, and Ed Doolan during my time there. Alongside this, I was very active with the organization of festivals in my local community, and I founded a highly successful literary festival and was actively involved in the start of a music festival as well, which all kept me very busy.

My first husband was an ethical hacker and I used to be fascinated with his work. He couldn’t tell me a lot about it as he undertook a lot of government-related and MOD work in this area, but I was always passionate about computers, technology, and gadgets, and this extended to hacking, the psychology of hacking, and what motivates hackers to do what they do. In 2009, I was at a crossroads career-wise and decided to join my first husband’s cybersecurity software development company to help him with his workload. I was actively involved in all areas of the business and when we separated and subsequently divorced in 2012, I knew I wanted to stay in the cybersecurity industry, and that is exactly what I did.

At this point I worked for BT on their Assure Cyber product, then I became a cybersecurity awareness consultant working mainly with professional services organizations to help train their workforce to be more cyber aware through things like phishing email simulation exercises and cyber escape room activities. In 2018 I founded the UK Cyber Security Association, and today along with this I am a published writer and author in cybersecurity, as well as a participant in many events and webinars as a keynote speaker.

How is the UKCSA helping the public in educating and raising awareness about the importance of cybersecurity, especially in the unprecedented situation of COVID-19?

The UK Cyber Security Association is a membership organization for individuals, small businesses, SMEs, and corporate companies who are involved in the cybersecurity industry or who want to gain access to information to help them be more cyber aware. Members receive a wide range of benefits, including access to the latest cybersecurity industry news, networking events (virtual at the moment due to COVID-19), a yearly conference (also virtual at the moment), training, discounts on cybersecurity software products, insurance, and much more.  The UKCSA also raises awareness of cybersecurity awareness, cyber skills, training, and best practice as well as helping more women enter careers in the industry, neurodiversity in cybersecurity, the cyber skills gap, and education as to the importance of cybersecurity and why businesses should take it seriously.  In addition, much of our work currently focuses on educating as many organizations and individuals as possible as to the importance of staying safe online especially during the pandemic where there has been an unprecedented rise in the number of cyberattacks.

The pandemic has led to a surge in the usage of the Internet, which leaves businesses at the mercy of cybercriminals. And while the industry uses cybersecurity tools, there’s still a shortage of skilled and diverse personnel to address the risks and challenges. What could be the reason?

I think the main reason for this is that there is a misconception that you need to have a technical background or be technical to enter the industry. But this is simply not the case, and I realized that there must be many in the cybersecurity industry like me who had a non-linear journey into it, or who didn’t start their careers in cybersecurity or tech. I went from the entertainment industry working with high-profile celebrities in the U.K. to the cybersecurity industry, and I wanted to give space to those who, like me, transitioned into cyber from a different industry. This was the genesis of my books “The Rise of the Cyber Women” and “The Varied Origins of the Cyber Men.” I was honored to be able to feature those from all walks of life from all over the world in the books, and one thing that was clear to me was that not having a technical background was not a barrier to entering the industry. More needs to be done to raise awareness of this, particularly in schools, colleges, and universities.

According to a survey conducted by SANS Institute, 35% of women said their gender was the number one challenge to career advancement. This indicates a worrying gap in the representation of women in the industry. How can we bring in improved hiring practices?

One of the things I think would help to attract more women to take up careers in cybersecurity is to make job postings more inclusive. Language such as “cybersecurity ninja” or “cybersecurity rockstar” often alienates female applicants, but if the more straightforward language is used in job ads, more women are likely to apply for roles. Some companies utilize apps that use data science to highlight problematic words or phrases in job descriptions or ads, and that suggest new words and phrases that will attract more diverse applicants.

You were diagnosed as being #ActuallyAutistic in June 2018. And you’ve been a campaigner for neurodiversity in cybersecurity. Tell us more about it.

When I was diagnosed as autistic it was like a lightbulb had gone off in my head! So much made sense about why I am the way I am, and I used that knowledge to put new processes and things in place to help me in my day-to-day life. Since I was diagnosed, I have campaigned for neurodiversity in cybersecurity, and to encourage those who are neurodiverse to consider a career in the industry. I’ve written about my diagnosis extensively on the MeDecoded site, it was a safe space to help me understand my diagnosis and process it.

Women in cybersecurity still hold fewer positions of authority. Why is gender discrimination still going unchallenged?

I think we are doing better to attract more women to the industry, but much more still needs to be done. Supporting flexible working hours, a flexible working location, job sharing, or three weeks on/one week off enables people to set their hours and location where they feel at their most productive, while still delivering on deadlines and projects. Trust that people can be productive even if they don’t work in the same way or at the same time as others. In addition, those who are neurodiverse often get stressed when a deadline is approaching and undertake their work as far as possible in advance, while others find that they need the adrenaline rush that comes when waiting until (almost) the last minute to deliver a project. Finding the right ways for women to work at their best and around other commitments, especially childcare, can pay dividends.

Cybersecurity is a male-dominated industry, but times are slowly changing. What are the first steps that women can take to start their path toward a career in cybersecurity?

Firstly, identify your transferrable skills. Unlike other professions, cybersecurity experience is often not needed to get into the industry, but many will come from roles that have similar skillets. If you can demonstrate relevant existing experience, your transferable skills as they are known, there is no reason why you can’t get a foot on the ladder in cybersecurity. Also, network and make as many industry connections as possible. Meeting people is a great way to hear about opportunities when they become available. Attend as many cybersecurity events and conferences as you can, even if you have to do them remotely at the moment due to the pandemic. Qualification is another way to get a foothold in the industry. Which ones you need will depend on your career path, but you should seek out a course that covers general topics and gives you a good oversight into cybersecurity and what it entails.

Young girls, who want to pursue a career in cybersecurity, might experience self-doubt. As a thought leader and mentor, what is your advice to them?

Don’t be afraid to ask about opportunities, the worst that can happen is that the answer is No. One of my favorite mantras is “fortune favors the bold” — women often tend to feel that their knowledge isn’t good enough and put themselves down – impostor syndrome is rife in cybersecurity. As the industry is vast and constantly changing and evolving, it is very easy to fall into this trap of self-doubt. My advice is to stay confident about the skills you bring to the table and be just as assertive about your thoughts. Cybersecurity is a great line of work with a lot of varied opportunities. Knowing that you work in an industry that makes someone’s life a little safer will keep you going for a long time in this career.


About the Author

Pooja Tikekar is a Feature Writer and part of the editorial team at CISO MAG. She writes news reports and feature articles on cybersecurity technologies and trends.

More from the author.

CISO MAG’s March issue on Women in Cybersecurity is out. Preview here. Subscribe now!

Data Security – A Layered Approach

tech, tech provider

It’s the Data Stupid!, is the re-wording of former President Clinton’s famous campaign slogan, “It’s the economy stupid,” used when running for president in his attempt to resonate with voters about the obvious systemic issues during that time. Fast forward to 2020, and the same thing can be said for securing your data. Keep the “main thing, the main thing.”

By Zachery S. Mitcham, MSA, CCISO, CSIH, VP and Chief Information Security Officer, SURGE Professional Services-Group

The CISO is designated by the enterprise to safeguard the confidentiality, integrity, and availability of all enterprise data. The CISO is tasked with the responsibility to develop and implement a security strategy that will satisfy this charge.

In keeping with basic security principles, you should never implement a security control that is more expensive than the data you are trying to secure. Each situation and enterprise are different. Therefore, your approach to securing your data should be tailor-fitted to meet your individual industry’s needs. There is no one size fits all industry solution when it comes to securing your data. The approach or strategy that you employ to secure your data will largely depend on the nature of the industry that you’re in: Government Organization (GO), Non-Government Organization (NGO), Industrial, Scientific, Medical (ISM), Professional, or Technical. Additionally, it helps to understand the regulatory requirements mandated for data security.

If your data is critical to you and important enough for you to secure it, you should do so with a comprehensive layered approach. The crucial components of this layered approach are:

  1. Enterprise Policies
  2. Network Segmentation
  3. Multi-factor Authentication (MFA)
  4. Data Encryption
  5. Digital Rights Management (DRM)
  6. Data Loss Prevention (DLP)
  7. Common Vulnerability Exposure (CVE) Scanning
  8. Offline – Standalone Security Controls

Let’s discuss each one independently.

Enterprise Policies

The institution must develop strong and ubiquitous policies that address responsibilities, responsible use, classification, security, and handling of data maintained within the organization. Such policies are paramount to the overall collective approach that must be taken in ensuring confidentiality, integrity, and availability of it.

Educating your constituents on these policies is a must in order to ensure stakeholders buy into the program.

Network Segmentation 

Network segmentation is necessary when you need to isolate your sensitive data from being accessible to those who don’t need to know what it is. Network segmentation is a means to help satisfy certain industry data security requirements. Payment Card Industry Data Security Standard (PCI DSS) v 3.2, for example, states that scope reduction of sensitive information in the form of credit cards that is compartmentalized, separated/ isolated from other data that is stored within the enterprise can be achieved through network segmentation. Network segmentation is simply the division of an enterprise technological network into subnets, making it easier for administrators to control the flow of information via specialized policies. This type of segmentation is often done by establishing Virtual Local Area Networks (VLANs), which is simply the partitioning of a computer network at the Open Systems Interconnection (OSI) Layer 2, otherwise known as the Data Link Layer.

Multi-Factor Authentication (MFA)

Gaining access to a technological system utilizing multiple verification methods adds additional complexity when augmenting the overall hardening of the enterprise computing environment. Access mechanisms consist of something that you are, something that you have, something that you know, or any combination thereof. MFA is a tool utilized as a part of access control measures, serving as an essential computing gateway to ensure valid permission to the data is granted to those that are authorized to have it. Employing MFA to develop the enterprise’s tactical plan for data security is paramount.

Data Encryption

Encoding/encrypting the data that you want to protect places a logical lock on it that will only make it accessible to those who can decode/decrypt it. Its purpose is to protect digital data confidentiality. It is only as good as the type of encryption that is used for this purpose. Case in point, a deprecated encryption algorithm that is easily cracked cannot protect data confidentiality. Therefore, strong encryption is recommended if the data’s confidentiality is worth safeguarding.

Digital Rights Management (DRM)

Sensitive data in the form of personally identifiable information (PII), intellectual property, research, trade secrets, or any combination thereof account for more than 99% of an enterprise’s data that needs to be safeguarded. The security of this data begins with the creation of it. Several document development suites containing spreadsheets, presentations, word processing, and database management applications incorporate DRM within them.

DRM allows the creator to restrict access to only those that need to know, develop time restrictions on user access, disallow screen capture, restrict printing, downloading, and forwarding specific information. This is an essential fail-safe feature that protects the data if it falls into the wrong hands.

Data Loss Prevention (DLP)

DLP tools are those that are used to inspect data that resides within a computing system in accordance with provisions outlined in predefined regulatory requirements such as the Health Insurance Portability Accountability Act (HIPAA), General Data Protection Regulation (GDPR), Payment Card Industry Data Security Standard (PCI-DSS) or Gramm-Leach-Bliley Act (GLBA) for example. These tools are implemented on computer systems to assist with preventing data egress either intentionally or unintentionally.

Common Vulnerability Exposure (CVE) Scanning

The enterprise must develop a routine CVE scanning strategy to identify weaknesses/vulnerabilities within its technological network. Security features and systems can become deprecated over time. They must be updated to address emerging threats developed by intruders to circumvent control measures put in place to safeguard data.

Offline – Standalone Security Controls

Often the enterprise overlooks the importance of safeguarding their data that exist in paper form. Paper documents must be treated with the same level of sensitivity as logical data. Sensitive information in paper form must be kept under lock and key when not in use. Clean desk policies must be established and enforced to maintain the security of the data continually. A data breach is a data breach, no matter if it takes place virtually or in the form of paper.

I once asked a major data security vendor that if I purchased every security product, he had available, could he guarantee that my data would never be breached? He answered without hesitation, no. The bottom line is, as long as your network has human interaction, it will never be 100% secure nor impenetrable. Given that this is the best case that you can ever make, endeavor to make your data as inaccessible as possible, to unauthorized entities. The most effective way to do this is through a layered security approach to defense. Utilizing all the tools mentioned above in tandem will provide a comprehensive strategy for safeguarding your data.

It’s the Data Stupid!

This story first appeared in the September 2020 issue of CISO MAG. Subscribe now!

About the Author

Zachery S. MitchamZachery S. Mitcham, MSA, CCISO, CSIH is the VP and Chief Information Security Officer at SURGE Professional Services-Group. He is a 20-year veteran of the United States Army where he retired as a Major. He earned his BBA in Business Administration from Mercer UniversityEugene W. Stetson School of Business and Economics. He also earned an MSA in Administration from Central Michigan University. Zachery graduated from the United States Army School of Information Technology where he earned a diploma with a concentration in systems automation. He completed a graduate studies professional development program earning a Strategic Management Graduate Certificate at Harvard University extension school. Mr. Mitcham holds several computer security certificates from various institutions of higher education to include Stanford, Villanova, Carnegie-Mellon Universities, and the University of Central Florida. He is certified as a Chief Information Security Officer by the EC-Council and a Certified Computer Security Incident Handler from the Software Engineering Institute at Carnegie Mellon University. Zachery received his Information Systems Security Management credentials as an Information Systems Security Officer from the Department of Defense Intelligence Information Systems Accreditations Course in Kaiserslautern, Germany.

Disclaimer

CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.