Home Blog Page 111

BIoTs can alleviate security concerns for both owners and tenants

Dr. Rishi Mohan Bhatnagar is an international speaker and thought leader in the Internet of Things and digital space. He co-authored the book “Enterprise IoT” along with a team from Bosch. He is the recipient of the “ET Now Business Leader of the Year 2019,” Voice&Data “Leadership Recognition Award” – India 2019, Indian ISV “IoT CEO of the Year 2018” and BTVI “Business Leader of the Year 2018.” Currently, as President of Aeris Communications India Private Ltd. (100 % subsidiary of the privately held, Silicon Valley headquartered Aeris Communications Inc., pioneers in the m2m/ IoT business since 1992), Dr. Bhatnagar is leading the Aeris business in the Indian subcontinent, MEA, and the APAC region.

In an exclusive interview with Augustin Kurian from CISO MAG, Bhatnagar talks about his journey, the future of Building the Internet of Things, integrating IoT with farming in India, and also addresses the threats and concerns surrounding 5G.

Edited excerpts from the interview follow:

It has been nearly three decades since the inception of Aeris. Aeris evolved from being a cellular network to now a world-renowned IoT enabler. How has your journey with Aeris been and what were the key milestones for the company?

Aeris was founded in 1992 and is a cellular network designed and built exclusively for machines. Because it was made for machines, Aeris delivers the most reliable, flexible, and efficient global cellular network for M2M data transmission available today. The growth of Aeris mirrors the development and growth of M2M communications and the Internet of Things (IoT). It has operational reach in over 180 countries and has offices in the Americas (Chicago & San Jose), Europe (U.K.), and India (Delhi NCR). We announced our joint venture with Softbank in Japan in 2016 known as Aeris Japan K.K., to provide IoT and telematics services globally using the Aeris IoT solutions platform. We are also part of Ventic LLC, a joint venture that is the result of a long-term commitment between Volkswagen and Aeris in the development and operations of connected vehicle platform technologies.

Today we have 14 million devices managed on our IoT Platform, worldwide. Aeris is at the forefront of the technology industry, building networks and applications to enable Fortune 500 clients to fundamentally improve their businesses. We offer global connectivity for machines as well as IoT solutions and services to multiple sectors which include Automotive, Finance & Insurance, Telecom, Utilities, Manufacturing, Agriculture, and more. From telematics to medical devices to remote machines, Aeris’ customers enjoy solutions tuned for high performance and mission-critical reliability. We entered the Indian market in 2016, and with our joint go to market engagements, we have successfully established an end-to-end IoT ecosystem, cracked the IoT monetization code and today we provide flexible business and commercial models for IoT, for the price-conscious markets, going beyond India, and, creating our presence in SAARC, APAC, Middle East and the APAC region.

With no hardware choke points and several small-cell antennas relying on 5G’s Dynamic Spectrum Sharing feature enabling multiple data streams to share bandwidth partitioned in slices that may each introduce cyber risk, do you feel with 5G technology comes to the emergence of tens of billions of smart devices susceptible to cyberthreats related to IoT networks?

5G comes with the promise of download speeds of up to 10 times faster and there is a huge concern over this from a security perspective as faster speeds may present an opportunity for hackers to target more devices and launch bigger cyberattacks.

But let’s not forget that we witnessed similar concerns and threats when the Internet was growing and maturing to gain the critical mass and adoption. Similar concerns were raised when cloud technology was at its hype. Therefore, it is quite natural that any new and advanced technology will bring with it a gamut of new security challenges. We need to remind ourselves that the security of the “thing” is only as secure as the network in which it resides. This includes the people, processes, and technologies involved in its development and delivery. Managing the security of 5G networks and services requires a new approach, where security is an integral part of the end-to-end architecture and ‘security by design’ is a must.

You have spoken about integrating IoT with agriculture to revolutionize the landscape. What is the feasibility of that? What is your response to the apprehensions surrounding cyberthreats that may arise to unsuspecting farmers?

For IoT deployments, irrespective of the industry vertical whether it is manufacturing or finance or agriculture or even a social sector engagement, security should never be an afterthought.

Keeping connected devices and their data safe starts during device design and at device provisioning and deployment. Deploying IoT programs at scale calls for simplifying device onboarding processes and reducing manual steps. A common goal is to set up each deployed device to immediately be able to communicate over networks to the right destination in the cloud. But doing that securely requires examining all the steps in the process and setting the right parameters for those devices.
Farmers adopting connected technology can tie up with IoT solution and service providers who allow them to securely provision and connect their devices to the cloud with minimum (near zero) effort and help them do this securely with identity and access management best practices being deployed during the entire device deployment lifecycle.

When it comes to the concept of Building Internet of Things (BIoT), it is often said that immaturity and poor definition of the concept are a few of the biggest risks in smart buildings. Do you think there is still a need for a more comprehensive understanding of threats posed on BIoT?

The Commercial Real Estate (CRE) industry is perhaps uniquely positioned to implement the latest technologies using IoT-enabled building management systems (BMS) or BIoT to make building performance more efficient and also use sensor-generated data to enhance building user experience. The value created from the information generated by BIoT has the potential to widen the lens on value creation beyond location, and associated benefits of low-hanging fruit such as cost savings and operational efficiency through improved energy management increased level of efficiency with enhanced building performance and effectiveness that could distinguish buildings within a marketplace from a desirability and profitability standpoint.

BIoTs can alleviate security concerns for both owners and tenants. Real-time monitoring can bolster internal security, and specialized weather sensors provide advance warnings of adverse weather events. As the frequency and severity of hurricanes, floods, and tornadoes increase under a changing climate, so does the value of disaster preparedness and resilience.

From a security point of view, CRE companies can minimize the security and privacy risk that IoT technology presents by taking several measures mentioned below to become secure, vigilant, and resilient:

  • Use purpose-built BIoT devices or addons, rather than generic IoT solutions.
  • Define clear responsibilities for the players in the ecosystem and institutionalize data governance.
  • Selection of secure communication protocol is required for building automation systems, which can help integrate with enterprise management solutions.

When all these systems are unified to work together, we have a resilient Building Internet of Things (BIoT). In the security industry, the integration of the three major segments has been successful to a large extent. Physical Security Management Systems (PSIM) have been used for interoperability between safety & security systems including fire detection, extinguishing, evacuation, mass notification in both large and small projects.

With COVID-19 and employees working from home, there are even bigger threats from the IoT landscape. What are your thoughts surrounding that?

It is true that while the underlying network is relatively easy to secure, like the internet, smart devices and sensors create an ecosystem that is complex and widespread. IoT devices vary widely in their uses, and so do their security needs, which means it’s very easy to either overspend or underspend on the necessary precautions. Each component is vulnerable, and their internetworked communication is instantaneous. That means a hacker can take down an entire system in a second, long before any human or network fail-safes can respond. A disgruntled worker could sabotage devices during design or manufacturing. Criminals could steal a device shipment, reprogram the devices, and return the devices on their journey. A hacker could fake a device malfunction in an existing system, alter the device software, and then bring the device back online — security personnel would simply assume it was a minor glitch. In every case, the breaches might never be detected.

Knowledge and preparedness are key determinants for how successful any IoT security implementation will be, even when facing the unknown. By building comprehensive security measures into the ecosystem first, before a single device is activated, you can create a secure foundation that will last well into the future.

With increasing cyberattacks during the COVID-19 crisis, what are your thoughts on the need for asset inventory management?

For many enterprises, tracking an asset at every step of its journey, in real-time, is a business-critical requirement and the COVID-19 crisis reinforced this hard fact to enterprises of all sizes – big and small!

Connected asset tracking solutions provide compliance oversight, enhances owner/operator behaviors, improves productivity, and reveals granular insights for optimizing operational efficiencies. With remote tracking and monitoring, managers can make smart decisions based on factual data, driving performance, and creating significant competitive advantages for their companies.

Finally, what changes do you foresee in the post-COVID-19 world? Has the lockdown period been an enabler for security advancements in the IoT space or has it been an obstacle?

Having proper security in place makes common sense but too often this has been an afterthought. The outbreak of COVID-19 mandated remote working of the employees with country-wide lockdowns leading to an upsurge in the Bring Your Own Device (BYOD) trend, and, thus, higher vulnerability. The demand for endpoint security rose during the lockdown period. COVID-19 has accelerated the demand for managed IoT security services to safeguard the data of employees as well as organizations. In addition, regulations are now forcing device and sensor manufacturers to take security into account and not to ship without it – security by design.

This interview first appeared in the August 2020 issue of CISO MAG.Subscribe now!

Augustin KurianAbout the Interviewer

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

Chinese Hacking Group “RedEcho” Targets Indian Power Sector

Cyber-Security-Threat-to-National-Power-Grids, Recorded Future

Relations between India and China have worsened after troops from both sides engaged in a skirmish in May 2020. While diplomacy factors have thwarted a direct war, cyber espionage operations from state-sponsored attackers continue to disrupt organizations in India. Cybersecurity experts recently uncovered a Chinese hacking group’s cyber campaign targeting India’s power grid and transmission sector.

Related News:

China Attempts Cyber War on India; Over 40,000 Cyberattacks in 5 Days

Research from security firm Recorded Future found a China-linked threat actors group dubbed RedEcho, targeting 12 Indian organizations, 10 of which are in the power sector. Recorded Future’s threat research team Insikt Group uncovered a subset of the servers that share some common tactics, techniques, and procedures (TTPs) with several previously reported Chinese state-sponsored groups.

 Key Findings

  • The targeting of Indian critical infrastructure offers limited economic espionage opportunities; however, we assess they pose significant concerns over potential pre-positioning of network access to support Chinese strategic objectives.
  • Pre-positioning on energy assets may support several potential outcomes, including geostrategic signaling during heightened bilateral tensions, supporting influence operations, or as a precursor to kinetic escalation.
  • RedEcho has strong infrastructure and victimology overlaps with Chinese groups APT41/Barium and Tonto Team, while ShadowPad is used by at least 5 distinct Chinese groups.
  • The high concentration of IPs resolving to Indian critical infrastructure entities communicating over several months with a distinct subset of AXIOMATICASYMPTOTE servers used by RedEcho indicates a targeted campaign, with little evidence of wider targeting in Recorded Future’s network telemetry.

“We’ve determined that a subset of these AXIOMATICASYMPTOTE servers share some common infrastructure tactics, techniques, and procedures (TTPs) with several previously reported Chinese state-sponsored groups, including APT41 and Tonto Team. Despite some overlaps with previous groups, Insikt Group does not currently believe there is enough evidence to firmly attribute the activity in this particular campaign to an existing public group and therefore continue to track it as a closely related but distinct activity group, RedEcho,” Recorded Future said.

Update on March 2, 2021

Mumbai Power Outage a “Cyber Sabotage” Attempt: Minister

The latest security incident raises doubts about a possible connection to a power blackout that crippled the financial capital of India – Mumbai – in October last year. At first, it was considered to be a technical failure at a power sub-station; however, later reports suggested that this could well have been an effect of a cyberattack on the power grid. The Maharashtra Cyber Cell department was summoned by the state’s Minister of Energy and Home Minister to carry out a thorough investigation into the possibilities of a cyberattack and asked to submit a subsequent report.

Related News:

Did a Cyberattack Cause Power Outage in India’s Financial Capital?

Yesterday, on March 1, 2021, a preliminary report of the investigations was submitted to Maharashtra’s Home Minister, Anil Deshmukh, and Energy Minister, Nitin Raut. Based on the findings in the report presented to them, Deshmukh in a press conference said,

An analysis of the Supervisory Control and Data Acquisition System (SCADA) has shown that there is a possibility that this incident was a cyber sabotage. 

Deshmukh also said that the preliminary report from the Cyber Crime Cell has noted three possible ways in which the sabotage was attempted:

  • Malware attack on one of the MSEB servers.
  • Transfer of 8GB unaccounted data from a foreign server to an MSEB server.
  • An attempt by several blacklisted IP addresses to log into MSEB server.

Ryuk Ransomware Gets Intelligent, Spreads on its Own!

ransomware, ryuk ransomware, cox media

Ryuk ransomware has spelled doom on organizations since its discovery in August 2018. At the end of 2020, Ryuk operators carried out a series of Ryuk ransomware attacks against multiple hospitals in the U.S. The success of their operations can be gauged from the fact that the Ryuk ransomware gang collected a ransom of more than $150 million in Bitcoins.

Related News:

A Tsunami of Ryuk Ransomware Attacks Hits U.S. Hospitals

Owing to their success, Ryuk operators seem to have further evolved the ransomware rendering its new and unique capabilities. Its new variant, which self-replicates over the local network, can cause unimaginable devastation, reported the French national cybersecurity agency, Agence Nationale de la Sécurité des Systèmes d’Information (better known as ANSSI). The self-spreading capabilities were found to work only on machines based on the Windows domain and through specific tasks.

 Key Highlights 

  • Ryuk ransomware’s new variant has self-replication capability over a local network.
  • It makes use of a Privileged account and machines based on Windows domain only for propagation.
  • The ransomware contains lines of code allowing files and subfolders encryption.
  • No mechanism (like MUTEX) for blocking the execution of the ransomware has been identified.
  • The files are encrypted using Microsoft CryptoAPI with AES256 algorithm.

Ryuk Ransomware’s New Capabilities

ANSSI said that Ryuk’s new variant uses scheduled tasks of the Windows operating system to propagate itself over the local network. It then lists all the IP addresses in the local ARP cache and disguises them as Wake-on-LAN (WOL) packets while sending them to all the discovered devices. Further, it adds all sharing resources found for each device so that it can encrypt maximum content.

ANSSI’s analysis found that the legitimate schtasks.exe Windows tool is being used to execute scheduled tasks on each subsequently compromised network host. The analysis also suggested the absence of an exclusion mechanism that is generally present to prevent the ransomware from re-encrypting devices.

Ryuk officially does not use the Ransomware as a Service (RaaS) model. However, it is observed that several different attackers are involved in designing multiple infection chains leading to the deployment of Ryuk. Thus, having common remediation steps for all deployment methods is practically impossible. But in the case of this new variant, ANSSI says that infection can be contained by stopping the spread to other hosts on the network. It suggests “One way to tackle the problem could be to change the password or disable the user account (according to the used account) and then proceed to a double KRBTGT domain password change. This would induce many disturbances on the domain – and most likely require many reboots but would also immediately contain the propagation. Other propagation containment approaches could also be considered, especially through the targeting of the malware execution environment.”

With the amount of success that Ryuk ransomware operators garnered through 2020, its latest variant could be one to beware of in the year 2021.

Related News:

Ryuk Ransomware Gang Made More Than $150 Mn in Ransom

TikTok Finds Itself on the U.S. Judicial Radar; Agrees $92 Mn Payout Over Privacy Lawsuit

TikTok, TikTok data privacy, TikTok children's privacy

TikTok, the China-based social media company, has agreed to pay $92 million to settle multiple privacy lawsuits for violating users’ data privacy. The lawsuits alleged that TikTok harvested users’ private information including facial recognition data without their consent and shared it with third-party vendors based in China. The proposed settlement is related to over 89 million TikTok users in the U.S. who claimed that TikTok allegedly tracked and sold their data to advertisers, violating data privacy laws.

“The complaint also alleges violations of a number of other statutory, common law, and constitutional claims arising from Defendants’ alleged taking and transmission of other private, legally protected data. Plaintiffs assert claims for violations of the Computer Fraud and Abuse Act (CFAA), California Comprehensive Data Access and Fraud Act (CDAFA), California Constitutional Right to Privacy, California Unfair Competition and False Advertising laws, Video Privacy Protection Act (VPPA),” the TikTok lawsuit said.

The settlement comes because of 21 federal lawsuits filed in California and Illinois last year mostly on behalf of children that claimed the company accessed their data for various purposes, including tracking users by age, gender, location, operating system, and interest to attract targeted marketing and ad sales.

Mishandling Children’s Data

Last year, South Korean telecommunication watchdog, Korea Communications Commission (KCC), found TikTok guilty of mishandling child data in the country and thus imposed a 186 million won (approximately US$155,000) fine. The KCC’s investigation that originally began to investigate the secret extraction of user data by the Chinese government through this app led them to these findings: TikTok illegally collected a minimum of 6,007 pieces of child data between May 31, 2017, and December 6, 2019, of users younger than 14 years.

T-Mobile Suffers Data Breach…Again!

T-Mobile data breach

Mobile telecommunication company T-Mobile has revealed a security incident that compromised its customers’ sensitive data, including personal identification numbers (PINs). In a data breach notice,  the company stated that an unknown hacker gained access to customers’ account information. T-Mobile alerted the affected customers and reported the issue to the U.S. attorney generals’ offices.

While there is no evidence whether the attackers gained access to the employees’ accounts, T-Mobile claimed that there is a chance of SIM Swapping attacks as the attackers were able to port mobile numbers.

Sensitive Data at Risk 

The information accessed by threat actors included customers’ full names, addresses, email addresses, account numbers, social security numbers, account details, account security questions and answers, birth dates, plan information, and the number of lines subscribed to their accounts.

“An unknown actor gained access to certain account information. It appears the actor may then have used this information to port your line to a different carrier without your authorization. T-Mobile identified this activity, terminated the unauthorized access, and implemented measures to protect against reoccurrence,” a T-Mobile spokesperson said.

T-Mobile urged the affected customers to change their account’s password, PIN, and their security questions and answers for further security. The telecom giant is also offering two years of free credit monitoring and identity theft detection services to the impacted customers in the incident.

One Telecom – Multiple Data Breaches

This is not the first time that T-Mobile has faced a data breach. In 2020, the company alerted customers about the attack against its email vendor that led to unauthorized access to certain T-Mobile employee email accounts, which contained account information of customers and employees.

In 2018, a data breach compromised the personal information of around two million T-Mobile users. The compromised data included names, email addresses, account numbers, and other billing information of its customers.

IoT Security Trends and Challenges in the Wake of COVID-19

IoT attacks

Finally, we have arrived in the age of an Internet of Things (IoT) ecosystem, with connected devices deployed in our homes, workplace, and public places. According to research analyst Omdia’s most recent “IoT Devices Market Tracker,” the global IoT installed base is expected to reach 27.5 billion in 2020, growing to 45.9 billion in 2025. With that number of devices deployed and even more on the way, it is anticipated that the volume of cybercrime or attempts to thwart cybersecurity will only increase. With threats from both criminal and rival nations evolving, it is important that defensive strategies are put in place to protect IoT systems, especially with threats to the digital scape looming large.

By Vikas Bhonsle, CEO, Crayon India

This is again, a pre-pandemic world’s observation. Omdia believes that industrial markets will continue to drive IoT demand, but growth in the communications and medical fields will accelerate. Overall, only a few markets are projected to remain strong amid COVID-19, and IoT security is one of them. COVID-19 has accelerated the security trends in the direction of integration, consolidation, and cloud transformation. According to an April 2020 report from IoT Analytics, since the early months of 2020, there has been an increase in cyberattacks that has raised the importance of IoT security considering the growing demand.

Securing an IoT infrastructure requires a precise in-depth strategy that includes securing cloud data, data integrity, data devices, any device or system connected to a network, or that is online and has the potential to reveal personal information to cybercriminals. Hence it is important to ensure the security of the IoT network of devices or appliances.

Procrastination towards security

There is a general attitude of procrastination among enterprises about employing security measures for their digital network and devices. When deploying data systems in any environment, security teams traditionally look for three things: speed, security, and budget-friendliness. Unfortunately, organizations tend to choose only two, leaving security out of the equation while cost and convenience remain the bane of data protection efforts for years to come.

Strengthening Assent Inventory Management

Organizations must prioritize strengthening the security measures of their devices and the network, especially during the pandemic. As data and devices are getting scattered with remote working in practice, it is vital to review corporate security strategies and ensure a decent overview of the inventory of assets and IoT devices. It’s recommended to build a broad review of asset inventory with a much deeper knowledge of individual assets including asset tracking, traffic pattern analysis, updating the assets, and rapid-response in the case of a cyberattack.

Shadow IoT Devices

The COVID-19 crisis has led to another issue known as shadow IoT devices, which is when employees working at home introduce unauthorized IoT devices to the enterprise. This increases a significant level of vulnerability for the organization and its data as these devices are not layered with security measures and can easily give access to an enterprise network.

A leading cloud security provider reported that during the early months of 2020, there was a 1500% increase in IoT device usage at enterprises. These are unauthorized IoT devices that include digital home assistants, TV set-top boxes, IP cameras, smart home devices, smart TVs, smartwatches, and even automotive multimedia systems. Each of these assets can be used as a point of exposure to get access to an enterprise network. Hence, it is crucial that IT and security professionals pay heed to the digital security hygiene practices of the workforce.

Cloud Security

As most people have moved their work off-premise since COVID-19, experts conclude that there will be a massive rate of cloud adoption during this period.

Cloud security tools with other cloud-hosted applications can help scale new assets quickly, remotely apply software patches, and integrate with other tools through standardized APIs with ease. Cloud connections can, on the other hand, face an increasing risk of data breaches. It is, therefore pivotal for IT and security departments to do a thorough risk assessment to decide which apps should be on the cloud and which should be on-premise.

Security Automation with AI

There has been a huge improvement in Machine Learning and AI technology, including AI-based security tools, which deliver better and often faster outcomes. It is therefore advised that organizations look for a predictive and detective strategy when it comes to IoT security. With AI, applications can now be programmed to automatically trigger a reaction to specific abnormalities, which is helpful when a rapid response is needed. The traditional Security Information & Event Management (SIEM) solutions are also witnessing AI-enhancement by models that provide streaming data analysis and threat modeling.

Conclusion

COVID-19 has led to a hike in cyberattacks that have in turn led to a surge in the need for IoT and IoT security adoption. It is high time organizations come to acknowledge that pandemic or not, adoption of technology has increased multi-fold, and we have now moved from an also-digital to an only-digital phase. Cybersecurity must include best practices for a robust and healthy IoT ecosystem to flourish.

This story first appeared in the August 2020 issue of CISO MAG. Subscribe now!

About the Author

Vikas Bhonsle is the Chief Executive Officer (CEO) at Crayon Software Experts India Pvt. Ltd. and has been leading it across India since June 2014. Vikas is an alumnus of the University of Mumbai where he completed his graduation in the field of physics and did his MBA. He is well versed with the disciplines of Business Management, Sales, Marketing, Strategy Formulation, Operational Management, and Relationship Management with over 20 years of experience.

Disclaimer

The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Cybersecurity Top 5 Lessons Learned from COVID-19

COVID-19 Cyberthreats

At last, I went to a grocery shop with enough precautions after using multiple online delivery services for weeks. And I found that most people are following health advice and keeping safe distances, although it makes it hard to recognize anyone wearing a mask. This was, and still is, an unusual experience for everyone. COVID-19 is the biggest challenge that we face today. The COVID-19 pandemic has forced us to stay home to save lives and has given us time to rethink our actions and prepare for a healthier future.

By Hemanta Swain, Global Head of Information Security, II-VI Inc.

Through my personal experiences and learning from COVID-19, I realize that this pandemic resonates closely with my Infosec professional life. This may not be new for cybersecurity professionals, but I will outline a few of my experiences here. In the minds of many people, this transition from physical to digital is inevitable, unstoppable, and irrevocable, even though cash is still used for most retail purchases globally (COVID-19 influence aside).

1. Basic (Health/Security) Hygiene:  The pandemic has reminded us all that the most basic of hygiene strategies, handwashing, first to be discovered to be effective against spreading disease in the 1850s, is still one of the most important ways to stop the spread of diseases in 2020.

As for cybersecurity, we should be reminded that basics cannot be ignored in our industry either. It’s not uncommon to see security professionals lagging behind in the adoption of the latest technologies that address challenges (advanced threats) and support business priorities. We are also reminded of the number of breaches that happen because of haphazard patching and other basic requirements not being met. Just like with handwashing, all cybersecurity professionals know that keeping up to date with patches is key to protecting the organization from easily avoided breaches. Moreover, we tend to overlook the basic health of our infrastructure, systems, and applications. This becomes evident during a security breach.

In my view, both are needed, but there should be a continuous effort to keep basic security hygiene intact. This is essential to build a sustainable security posture. One can and should follow CIS top 20 controls and OWASP top 10 list with secure access using multi-factor-authentication, regular patching, vendor risk assessment, email security, and endpoint security protection. But basic security hygiene is the key.

2. Segmentation (Shelter-in-place and Isolation): During this pandemic, we’ve seen, perhaps for the first time, the entire world sheltering in place simultaneously. We’ve seen how isolating people from their networks of friends and extended family drastically helps contain infection rates.

The parallels in cybersecurity are obvious: understand your business, infrastructure, applications, and the most valuable assets. Appropriately segment your network, systems, and applications to allow access to only those who require it. This is beneficial to minimize impact during a crisis, allowing you to contain any breaches and will be a foundation for your zero-trust framework.

3. Security (Health) Leadership and Culture: If this pandemic has taught us anything, it’s that when health leaders, politicians, and local culture are in line with best practices for limiting the spread of the disease, the effects of COVID-19 are minimized more quickly and with fewer deaths. When messaging to the public is unclear, valuable time is lost and local culture doesn’t shift quickly enough to impact results.

For cybersecurity, it’s imperative to clearly define roles and responsibilities to take appropriate action in a timely manner, especially during a crisis. Security leadership helps to build a security-aware culture, which is essential to reduce risk and costs related to security. Yes, there is no infinite budget, and this will impact your bottom line and resource requirements, but it is crucial to present the risks with impacts to senior leadership and come to agreements on the next steps.

Security professionals recommend options based on the risks they discover, but if senior management cannot make quick decisions, there can be significant impacts on handling crises. Security leadership reporting is very important, not only to enable a quick decision-making process but to build a security-aware culture. Employees will follow not only the CISO but also senior management because they highlight the importance of security. To be successful, create an executive security leadership council consisting of business and IT senior executives for business alignment and continuous risk management to build a security-aware culture.

4. Quick Action and Communication: Infectious disease experts have long known that quick action at the first sign of a pandemic is key to mitigating its impact. In order to act quickly, adaptable plans must be in place and teams must be trained and kept on standby in the case of a crisis. Attempting to piece together an ad-hoc plan in the middle of active pandemic wastes critical time. Having plans in place allows leaders to accurately communicate to the public what steps have been taken, what they should expect next, and what they need to do to avoid infection. Communicating on the progress of the response to the pandemic and successes and failures in a transparent way is very important to ensure public compliance with any measures they are being asked to take.

It’s obvious that this is just as true in cybersecurity. Processes should be in place to facilitate quick action in a timely manner. Security councils, senior leadership, and Boards of Directors communication protocols should be in place. Upper management must make quick decisions to minimize the impact based on security leadership recommendations. Unfortunately, security breaches are unavoidable and security professionals should be prepared to handle breaches when they occur.

The most important action while handling a breach is communication. Communication with customers, partners, and supply chain networks should be considered in the planning process. Additional help from industry experts inside and outside the company should be called in to help during a crisis.

5. Quick Recovery: We’ve seen successful and botched re-openings around the world and the difference between the successes and failures seems to be how much planning and data went into each decision to re-open. Those locations that rush to re-open in order to get back to business have risked more infections and more deaths, which further hamper economic recovery. A balance must be struck in order to ensure that any re-opening is safe and appropriate for the level of recovery of the state or country.

In a breach or other cyber incident, business continuity and service recovery are extremely important to minimize the impact and return business back to normal. However, rushing to get back to business can have similar effects if the incident has not been properly remediated or fully understood. Continuously review your preparedness, including the current disaster recovery plan, and backup and restore capabilities. Have frequent tabletop exercises with stimulated security breach situations to test your recovery plan.

This story first appeared in the August 2020 issue of CISO MAG. Subscribe now!

About the Author

Hemanta Swain is the Global Head of Information Security, II-VI Inc. Hemanta has 24+ years of IT experience including 18+ years of Cybersecurity & Risk Management expertise. Hemanta performed various security technical leadership roles for companies like GE, Wipro & a few early-stage startups. Hemanta holds multiple Industry-standard technology certifications including CISM and CISSP.

Disclaimer

The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Why Network Security is Important in Today’s Digital World

importance of network security

In the current uncertain times of the ongoing COVID-19 pandemic, one of the most integral parts of our day-to-day life has significantly changed – our office and work. The pandemic has impacted the global workforce, in all aspects – the way we conduct business, communicate with our colleagues and clients, and even our work-life balance. Working virtually, there is no boundary now between home and office. Alongside this, a significant number of cyberthreats have grown exponentially targeting the remote workforce and giving the IT C-suite like the CTO, CIO, CISOs across the world sleepless nights.

The Remote Workforce

Remote working saw a huge spike in the utilization of home networks like never before. Businesses began leveraging technology to unlock a remote approach to work. The evidence of this can be found in the 70% jump in the usage of Microsoft Teams – a collaboration tool from Microsoft – in the first month of the pandemic itself. Unsecured home and public networks are now supporting business continuity plans of organizations of every scale. The increase in usage of technologies such as Blue Jeans, Microsoft Teams, Skype for Business, Virtual Private Networks (VPNs), and Zoom, on these unsecured networks, amplified the global cybercrime scene amid the pandemic.

Related News:

Remote Work Jeopardizes Corporate Network Security: Report

The IT and network security teams who were entrusted to protect the endpoints on the office networks suddenly faced a new challenge of securing the old and additional endpoints that were beyond the traditional security perimeter. As days passed, business needs grew, endpoints grew, and correspondingly, networks grew. A network engineer who many didn’t know existed in their organization until a few months back, was suddenly the go-to man for every office staff. But just having a network engineer on board is not enough. Organizations today need a network security engineer.

The Importance of Network Security

Network security is one of the most important aspects of any business. With people working from their beds and sending business emails from their couch, networks are pervasive – they are all around your home. Thus, it is now more than ever necessary to make network security your priority.

While no network is immune to attacks, a stable and efficient network security system is essential to protecting your data which is considered a gold mine. A good network security system helps businesses reduce the risk of data theft, sabotage, client mistrust, reputational and monetary damages, and the list goes on. However, like a ship needs a good captain to keep it safe, any business network needs a good network security engineer who can defend them and steer them past troubled waters.

But how does one progress from being a simple network engineer to becoming a network defender?  The answer is, become a Certified Network Defender (CND) with EC-Council’s Certified Network Defender program.

Why Sign-up for EC-Council’s CND Course

We give you not one but multiple reasons to believe this. When it comes to choosing the best career options, a network security engineer is a profile that will consolidate your position. As the world increasingly relies on digital platforms in the times to come, the demand for network security professionals is only going to rise. And hence having a certification in this field will help you lead the pack.

Related News:

EC-Council Unveils the Certified Ethical Hacker Hall of Fame 2021

As per Cybersecurity Ventures, it is expected that by 2021, there will be 3.5 million unfilled cybersecurity jobs worldwide. And if you believe in numbers, then be rest assured that there’s a growing demand for cybersecurity professionals. With a network security engineering certification, you will be on the radar of recruiters. Add to this, the lucrative salary you can draw. As per Glassdoor, the base pay of a network security engineer starts from $83,114, and it only goes skywards from here, with some earning up to an average of $167,500.

Now talking about the course structure, Certified Network Defender (CND) v2 has been designed by industry experts to help IT Professionals play an active role in the protection of digital business assets. It covers all aspects right from detection to the response of cyberthreats, by leveraging threat intelligence to predict incidents before they happen.

So, take the leap and become a Certified Network Security Engineer.
For more information on EC-Council’s next-gen Certified Network Defender training and certification, hit the button below!

EC-Council’s Certified Network Defender Course

Over 6,700 VMware Servers Vulnerable to Takeover Attacks

Data breach in 100 U.S. cities

Cybersecurity researchers from threat intelligence firm Bad Packets revealed that enterprise software provider VMware’s 6,700 servers are exposed online and vulnerable to cyberattacks. Threat actors can exploit the unsecured servers to deploy the malware into unpatched devices and compromise entire corporate networks.

Researchers claimed that they’ve identified mass scanning activity of cybercriminals targeting vulnerable VMware servers. Besides, a Chinese security researcher published a proof-of-concept code for a vulnerability “CVE-2021-21972” in VMware servers.

Affected products from CVE-2021-21972 flaw include:

  • VMware ESXi
  • VMware vCenter Server (vCenter Server)
  • VMware Cloud Foundation (Cloud Foundation)

VMware Fixes the Issues

VMware issued security fixes for multiple flaws including CVE-2021-21973, CVE-2021-21974, and CVE-2021-21972. “Multiple vulnerabilities in VMware ESXi and vSphere Client (HTML5) were privately reported to VMware. Updates are available to remediate these vulnerabilities in affected VMware products,” VMware said.

The remote code execution vulnerabilities in the vCenter Server plugin could allow a malicious actor with network access to port 443 to execute commands with unrestricted privileges on the underlying operating system that hosts the vCenter Server.

VMware stated that more than 6,700 vCenter servers online are now vulnerable to takeover attacks if administrators failed to apply the patches. The company urged customers to update their systems as early as possible to avoid any cyber risks.

Ransomware Operators Exploit VMWare Flaws

According to a recent report, ransomware operators are reportedly exploiting two previously known vulnerabilities in VMWare ESXi logged under CVE-2019-5544 and CVE-2020-3992 to target their victims’ virtual hard disks. ESXi is a solution that allows multiple virtual machines to share the same hard drive storage. Read more…

Lazarus Group Hits Defense Industries with “ThreatNeedle” Malware

Konni Malware, North Korean threat actors target AstraZeneca

Security experts found the North Korean-backed advanced persistent threat (APT) group Lazarus is targeting the defense industry across multiple countries since 2020. According to researchers at Kaspersky, the attackers are using a malware payload dubbed “ThreatNeedle” to penetrate corporate network systems. The malware can access and steal critical data from segmented portions of a network that is not connected to the internet.

“We have seen Lazarus attack various industries using this malware cluster before. In mid-2020, we realized that Lazarus was launching attacks on the defense industry using the ThreatNeedle cluster, an advanced malware cluster of Manuscript (a.k.a. NukeSped). While investigating this activity,” Kaspersky said.

How ThreatNeedle Affects

Kaspersky claimed that the ongoing ThreatNeedle malware campaign leverages a multistep approach that begins with a spear-phishing attack to eventually gain control over the victim’s device.

Before launching an attack, attackers research the targeted organization to identify and create similar email addresses belonging to various departments of the company. The phishing emails, with a malicious link or infected Microsoft Word Document attachment, are sent to several employees in various departments. Upon opening the malicious document, the malware is dropped and proceeds to a multistage deployment procedure to compromise the victim’s device.

ThreatNeedle Traits

Once the final payload of ThreatNeedle malware is deployed on the victim’s system, it allows a remote attacker to execute multiple functions including:

  • Manipulate files/directories
  • System profiling
  • Control backdoor processes
  • Enter sleeping or hibernation mode
  • Update backdoor configuration
  • Execute received commands

“Our investigation showed that the initial spear-phishing attempt was unsuccessful due to macros being disabled in the Microsoft Office installation of the targeted systems. To persuade the target to allow the malicious macro, the attacker sent another email showing how to enable macros in Microsoft Office. The document contains information on the population health assessment program and is not directly related to the subject of the phishing email (COVID-19), suggesting the attackers may not completely understand the meaning of the contents they used,” Kaspersky added.