Home Blog Page 116

India Eases Restrictions on the Collection, Storage, and Sharing of Geospatial Data

geo-spatial data in India

In 2018, tech giant Google had asked permission from the Indian Government for collecting data for its mapping application – Google Street View. This application provides Google users across the globe a 360⁰ view of any place of their liking from their lounging chair. However, Hansraj Gangaram Ahir, the then union minister of state, informed Google that “the government has not agreed to the proposal.” Lok Sabha, the lower house of the Indian Parliament, had rejected the proposal based on an argument that it did not suffice the country’s mapping policy.

Fast forward to 2021: The Government of India (GoI) – aligning to its “Atmanirbhar Bharat” and “Vocal for Local” (self-reliance) campaigns – has decided to ease the mapping policy. The government will allow local startups and businesses to collect, generate, store, publish and update geospatial data of the country but within its territorial boundaries.

Updated Mapping Policy

As per the new guidelines issued by the GoI, any Indian company or business will no longer be required to apply for additional licenses or permissions from the government to gain access into the country’s geospatial data, which includes maps from the Survey of India (SoI), terrestrial mobile mapping survey, street view survey, and surveying of Indian territorial waters. Additionally, the companies applying for such data will be given access to Indian ground stations and augmentation services for real-time positioning (also known as CORS – Continuously Operating Reference Stations).

GoI added, “The availability of data and modern mapping technologies is crucial for achieving India’s five trillion-dollar GDP vision. India presently relies on foreign resources for mapping technologies and services. Liberalization of the mapping industry and democratization of the existing data sets will spur domestic innovation and enable Indian companies to compete in the global mapping ecosystem.”

Echoing the same notion, India’s Prime Minister Narendra Modi, in a series of tweets, described this as a “massive step” towards Digital India.

Amid the current stir and protests against the three farm laws in the country, PM Modi tweeted that Indian farmers will also benefit from this.

The flip side of the new mapping guidelines is still the fact that no foreign company or foreign-owned or controlled Indian company can have this privilege. However, foreign entities can license the digital maps and/or geospatial data from Indian entities only to serve their customers in India. And to keep a strict vigil, the geospatial data shared with any foreign entity will only happen through an API. This will ensure that the data belonging to Indian counterparts stays on local servers and helps maintain data localization.

Related News:

Uniformed Engineers Gearing Up to Confront Hooded Cybercriminals in India

India Reported More than 2.9 Lakh Digital Banking Security Incidents in 2020

EC-Council Unveils the Certified Ethical Hacker Hall of Fame 2021

EC-Council, the world’s leading global cybersecurity certification body, today announced the launch of the Certified Ethical Hacker Hall of Fame. The Certified Ethical Hacker Hall of Fame will celebrate some of the most accomplished CEHs around the world. Organizations with cybersecurity teams that have a keen eye for the best talent across the world will be able to benchmark their teams’ capability against the best in the industry.

The CEH credential is recognized as the gold standard of ethical hacking. Established in 2003, the CEH program is the world’s first and longest-running sole ethical hacking certification.

Jay Bavisi, CEO of EC-Council Group
“We believe that positive role models are extremely important in today’s world and that our best and brightest CEH certification holders should be held up for others to emulate. Only those Ethical Hackers that have achieved a score of 90% or above will make the Hall of Fame, as competition is intense.”

 

The launch of the Certified Ethical Hacker Hall of Fame is an effort to recognize the remarkable capabilities of ethical hackers. Any EC-Council member holding a CEH certification with at least a 90% score will be invited to apply. However, making it to the Hall of Fame requires more than just passing the CEH exam. A selection committee will carefully review applications based on the accomplishments of the applicants with a key focus on their contribution to society, their career transformation story, and their role in the organization where they are employed. The selection committee will thereafter present the finalists to the CEH Advisory Board for their final selection.

“This program is all about highlighting the fact that experience and contribution to the industry are just as important as education excellence,” added Jay.

The 17-year-old Certified Ethical Hacker program has enthralled the cybersecurity community worldwide, gaining the respect and acceptance of various cyber-defense forces, and is recognized by the U.S. Marine Corps, U.S. Army, U.S. Navy, USAF, Federal Bureau of Investigation (FBI), British National Cyber Security Centre (NCSC), and many other elite defense bodies. About half of Fortune 500 enterprises have CEHs as part of their cybersecurity teams. Now into its 11th Version, the CEH once again finds itself being voted as one of the most in-demand IT certifications in the world for 2021.


About EC-Council:

EC-Council’s sole purpose is to build and refine the cybersecurity profession globally. We help individuals, organizations, educators, and governments address global workforce problems through the development and curation of world-class cybersecurity education programs and their corresponding certifications and provide cybersecurity services to some of the largest businesses globally.

Trusted by 7 of the Fortune 10, 47 of the Fortune 100, the Department of Defense, Intelligence Community, NATO, and over 2,000 of the best Universities, Colleges, and Training Companies, our programs have proliferated through over 140 Countries and have set the bar in cybersecurity education. Best known for the Certified Ethical Hacker program, we are dedicated to equipping over 230,000 information age soldiers with the knowledge, skills, and abilities required to fight and win against the black hat adversaries.

EC-Council is an ANSI 17024 accredited organization and has earned recognition by the DoD under Directive 8140/8570, in the U.K. by the GCHQ, and a variety of other authoritative bodies that influence the entire profession. Founded in 2001, EC-Council employs over 400 people worldwide with 10 global offices in the USA, Canada, U.K., Malaysia, Singapore, India, and Indonesia.

Learn more at https://www.eccouncil.org/

 

Episode #8: Intel Labs’ Breakthrough Research on Data Privacy and Encryption Technologies

Intel Labs, Federated Learning, Homomorphic Encryption

Data privacy is now a big concern, not just for individuals, but also for organizations and governments. There’s data at rest, in transit, and while it is being processed. Now we know that it can be encrypted at rest or in transit. But it must be decrypted for processing. And that window is an opportunity for the bad guys to come in and steal data or change it. So, it becomes mutable.

Researchers at Intel Labs have found a way to process encrypted data sets without the need to first decrypt them. However, there are a few challenges to overcome before the technology becomes mainstream. Homomorphic Encryption is a new cryptosystem that allows applications to perform computation directly on encrypted data, without exposing the data itself. The technology is emerging as a leading method to protect the privacy of data when delegating computation.

Federated Learning can solve the challenges of sharing large data sets between entities. It uses machine learning tools to offer valuable insights from the data.

In this episode, we have Rosario Cammarota (“Ro”) – Principal Engineer at Intel Labs, and Jason Martin – Principal Engineer in the Security Solutions Lab and manager of the Secure Intelligence Team at Intel Labs.  They explain how Federated Learning and Homomorphic Encryption are solving data challenges in health care research – and the possible applications in other industries.

RSS: https://feeds.soundcloud.com/users/soundcloud:users:899202688/sounds.rss

Spotify: https://open.spotify.com/show/7pBhvwEVAaL4uUJnzD5rWO

Jason Martin is a Principal Engineer in the Security Solutions Lab and manager of the Secure Intelligence Team at Intel Labs. He leads a team of diverse researchers to investigate machine learning security and privacy in a way that incorporates the latest research findings and Intel products. Jason’s interests include machine learning, authentication and identity, trusted execution technology, wearable computing, mobile security, and privacy. Prior to Intel Labs, he spent several years as a security researcher performing security evaluations and penetration tests on Intel’s products. 

Rosario Cammarota (“Ro”) is a Principal Engineer at Intel Labs, where he leads the effort on privacy-enhancing cryptographic technologies, their application, and standardization. He received his Ph.D. degree in Computer Science from the University of California, Irvine.

Ro’s research is at the intersection between cryptography and computing, focusing on fully homomorphic encryption, secure multi-party computation, and their application to artificial intelligence and statistics. Furthermore, his research interests include hardware and system security.

Ro is one of the technical advisory board members at the Semiconductor Research Corporation (SRC), where he contributes to developing research programs in hardware security and artificial intelligence hardware. In this role, he acts as a technology transfer facilitator. He is one of the US-experts at the International Organization for Standardization (ISO), where he contributes to developing standards on trustworthiness in artificial intelligence and privacy-enhancing technologies.

Ro is a Senior Member of IEEE. He is a prolific author and inventor. His research appears in journals and conferences such as ACM TECS, DAC, IEEE HOST, among others. He is one of the recipients of the SRC Outstanding Industry Liaison Awards in 2017, 2018, and 2019.

Listen to our previous podcast episodes here.


About the Host

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 26 years.

Adorcam App Leaks Millions of User Records via ElasticSearch Database

Data leak

ElasticSearch has been in the news for a very long time now. And mostly for all the wrong reasons. Yet again, an unsecured ElasticSearch database exposed a massive number of users’ sensitive information online. According to the security researcher Justin Paine, the leaky database belongs to Adorcam, a webcam application for viewing and controlling several webcam models.

Justin Paine stated that the database contained over 124 million rows of data (around 51 GB in size) that belonged to several thousands of Adorcam app users. The unsecured database has been leaking users’ information since January 4, 2021. The exposed data included user email addresses, hashed passwords, Wi-Fi network name, client IP, user Id, web camera serial number, web camera settings including microphone state, country geolocation, SSID / wireless network, name, and images captured by the web cameras.

The leaked information also included sensitive details about the MQTT server, a common standard messaging protocol for the Internet of Things (IoT) server. Adorcam secured the database after Paine reported the issue to the concerned authorities.

“I was browsing BinaryEdge and Shodan when I discovered yet another exposed ElasticSearch database. This database was eventually identified to be owned by Adorcam. The Google Play Store indicates that the Android version of their mobile app has 10,000+ installs,” Paine said.

Paine also discovered that the camera was uploading captured pictures from the webcam to Adorcam’s cloud storage. He suspects that the database was updating live, capturing the latest information from the app.

Data Leak Impact

Threat actors could exploit the exposed information for various social engineering and phishing attacks. They can leverage the leaked credentials, hostname, and port for the MQTT server to download, delete, or modify the information.

“The malicious actor would have plenty of details to establish trust and credibility with the victim of the phishing attack. The attacker also had geographic information to launch a targeted attack in the user’s native language,” Paine added.

IRS Alerts U.S. Taxpayers About e-File Identity Theft via Phishing Attacks

phishing scam, fake CV phishing scam

The Internal Revenue Service (IRS) had previously issued several warnings regarding scammers using the IRS name and/or logo to dupe people into giving access to their financial data and subsequently steal their assets. This is a popular tactic employed by fraudsters because the IRS name is recognized by most consumers; consumers have had prior communication with or from the IRS, and/or have previously provided financial data to the IRS. However, the latest alert released by IRS and Summit Partners has warned U.S. taxpayers of an emerging phishing campaign, which the identity thieves are using to gain exclusive consumer information like the Electronic Filing Identification Numbers (EFINs).

The Latest Phishing Campaign

The U.S. taxpaying season begins in the coming month. Leveraging it, scammers are bombarding phishing e-mails, impersonating IRS professionals to potential victims, and trying to steal their data and identities, which allows them to file fraudulent tax returns for refunds. The phishing emails are baiting U.S. taxpayers by using a subject line such as “Verifying your EFIN before e-filing.” The content in the letter forces the user to take immediate action by clicking the link or attachment as it says, “failing to so, will disable the account.” Some of the e-mails are also asking their victims to revert with important documents that contain their identities and EFINs. IRS has also warned of additional malware getting installed through these phishing links and attachments such as the keylogger spyware which would leak the victim’s login credentials.

Related News:

Five Phishing Baits You Need to Know [INFOGRAPHIC]

Additionally, the warning issued is not just for U.S. taxpayers or preparers but also for tax professionals. The tax professionals have been asked to beware of scammers posing as potential clients especially during the ongoing pandemic, where many are resorting to remote tax filing. Targeting and compromising tax professionals gives the scammers access to a larger pool of data from multiple clients. This piece of data contains EFINs, Preparer Tax Identification Numbers (PTINs), and/or e-Services usernames and passwords, etc.

The IRS has asked the tax professionals who have received such phishing emails to save them as a file and send it as an attachment to [email protected]. This should also be notified to the Treasury Inspector General for Tax Administration at www.tigta.gov as an IRS impersonation scam.

Experts Take

Purandar Das, CEO and Co-Founder of Sotero Software, told CISO MAG, “This is another attempt at how criminals continue to evolve their trade. On the face of it, it appears as though this a new scheme. In reality, it is the same old phishing scam targeting a new area. This is a cat and mouse game in many ways. As organizations attempt to fix a previous fault, criminals adapt and target the “fix”. What this demonstrates is, that criminals are nimbler and can adapt faster. Awareness is certainly a key aspect of addressing this issue. Making consumers and individuals less susceptible to manipulation is critical.”

“The other aspect of this is rethinking the technology and security implementations. Building and designing solutions that enable consumers to be in control of their data is one. Enabling a secure process of accessing and enabling second party access is another. Revisiting technology platforms that are more flexible and implementing a continuous improvement focus on security has to happen,” Das added.

Related News:

Large Scale Phishing Operation: 615,000+ User Credentials Stolen Using Facebook Ads

Ukraine’s PrivatBank Suffers Data Breach; 40 Mn Customer Records on Sale

Compromised Email Accounts

This is not the first time PrivatBank – Ukraine’s largest commercial bank – is in trouble. Security experts from Cybernews found an unknown cybercriminal group selling  PrivatBank’s database on an underground hacking forum. The database contained over 40 million customers’ entries, with sensitive information like full name, birth dates, taxpayer identification number (TIN), place of birth, passport details, family status, car availability, Viber contacts, education details, and contact details.

While it is unknown how the cybercriminals obtained the database, Cybernews stated that the threat actor group advertised the database, asking $3,400 in Bitcoin.

“When we looked at the Bitcoin address provided, it appears that no one has purchased the database yet from that particular wallet. However, it is also possible that the post author is generating a new wallet for each sale, a process that can be done automatically,” Cybernews said.

In addition, the adversaries also found trading passports, driver’s licenses, vehicle databases, and other sensitive data from Ukraine, Russia, and Mexico on multiple dark web markets.

The Breach Impact

The data breach may have affected 93% of Ukraine’s population, considering the exposed records (40 million) to Ukraine’s population (over 44 million). The leaked database contains sensitive information that might result in severe consequences as cybercriminals could misuse customers’ information for personal gains, including identity theft and phishing attacks.

How to Prevent Further Damage

To avoid cybercriminals from exploiting your personal information, PrivatBank has advised the following measures:

  • Set up identity theft monitoring to make sure that no loans, credit cards, or other financial activities have been undertaken in your name.
  • Change your passwords immediately and set up multi-factor authentication on important online accounts, as cybercriminals may use the leaked data in social engineering.
  • Use a unique password for each account you create.
  • Watch out for suspicious emails or phone calls, as they may be phishing attempts. Avoid clicking on links from suspicious emails, and practice caution with any claims or demands made via phone call.

Protecting the COVID-19 Vaccine Supply Chain from ‘Cold’-hearted Phishers

Dr. Reddy’s Lab Attacked Days After India Approves Russia’s COVID-19 Vaccine Trial

Recently, the world learned about a cyber-espionage attempt focused on the international vaccine supply chain. The threat was leveled as a precisely targeted phishing campaign against the companies involved in the “cold chain” used for preserving and controlling the strict storage temperatures of Pfizer’s COVID-19 vaccine in transit.

By Samantha (Sam) Humphries, Head of EMEA Marketing & Security Strategy, Exabeam

While the identity of the attackers remains unclear, the methods used in the cyber offensive are thought to be indicative of a nation-state. It is no coincidence that governments around the world, including the U.S. and the U.K., had previously warned of adversarial countries targeting aspects of vaccine research.

This particular cyber assault is believed to have started in September, and to increase the likelihood that target recipients would engage with the phishing emails, the attackers successfully mimicked an executive from a Chinese company involved in the cold chain equipment optimization platform (CCEOP) supply chain. Since vaccinations have already begun, it is important to note that the Pfizer-BioNTech vaccine was not the direct focus of the phishing campaign. The emails were sent to organizations that are providing transportation for the medicine, and those messages contained malicious code and asked for users’ login credentials.

The more things change, the more they stay the same

You might think that this far into the digital revolution, most people are already familiar with the look and feel of an electronic scam attempt. However, you would be wrong. Typically, the emails show no sign of being malicious, making them hard to spot. In combination with people’s naïveté to phishing risks, the hook is baited. In fact, when people fall for these attacks each year, it often leads to compromise not just of their personal data, but their company’s networks, too.

According to the 2019 Symantec Internet Security Threat Report, phishing emails are used by almost two-thirds (65 percent) of all known groups carrying out targeted cyberattacks. The same report indicated that intelligence gathering was the primary motive of 96 percent of targeted phishing attacks. In the case of the cold chain attacks, the breach may have allowed the mischief-makers to gain a familiarity of the infrastructure that was intended for vaccine distribution.

To err is human

Security teams can prevent phishing scams from succeeding in the mission to either deposit malware or exfiltrate data logs – or both! A well-informed workforce is a good first line of defense, specially trained eagle eyes that can spot phishing schemes before an email is even opened. However, even security-savvy employees can fall victim to mistakes and their own humanity, allowing malware to slip into the network via a single click, and data to be stolen. To help staff in the fight against digital adversaries, enterprises, particularly those involved in this critical vaccine supply chain, should consider the following defensive methods:

Open sesame: Security access rules

While the simple phrase “open sesame” worked to gain access to the treasure in the folk tale of “Ali Baba and The Forty Thieves,” in real life, you want security measures to be far more robust. To ensure a secure approach, the principle of least privilege can be applied. The least privilege states that access is granted or applied only according to what is necessary for that user to complete his/her work. To prioritize the security needs of the organization first, security teams can limit the access of all non-administrators. Should an adversary compromise an employee’s credentials, gaining access to the network may not be successful if the stolen credentials have the least privilege. Pro tip: As part of a strong security routine, perform a best practice check of user account settings and minimize how many people have higher-tier access.

Is this thing on? Filtering email systems

Although software can help lock down employee emails, they should already have spam filters provided by the email solution the company uses. Encourage users to mark any spam email that makes it through to his or her inbox to ensure that the information helps the filters do a better job.

 This is a test; it is only a test

As mentioned above, mistakes are bound to happen when humans are involved. A company cannot protect against a threat of which they are unaware. To determine the actual risk level for phishing scams more accurately, a company can run a simulated phishing test using a range of available tools. Basically, the security team should send employees a convincing email message that may appear to be a phishing email but will not actually harm anyone or anything. Depending upon which tool is used, it might track results such as which employees opened the email, or which employees clicked links that were embedded in the email.

Learn from Eisenhower: Planning is indispensable

These days, regardless of how completely a company may plan, an attack is always a possibility. One way to ensure that long-term damage isn’t inevitable is to take to heart the words of Dwight D. Eisenhower – ‘In preparing for battle, I have always found that plans are useless. But planning is indispensable.’ In other words, prepare the company well before any adversary or threat is looming. Invest in modern security tools and planning for a response with the latest intelligence technology, like behavioral analytics. This alerts security teams and helps identify odd behavior and abnormal activity such as an unusual attachment or the source country of an email. If this is indicative of a phishing attack, the company can immediately take protective measures. On top of a well-informed base of users, this technology is an added layer of security to ensure devices and servers remain safe.

For the foreseeable future, heightened awareness and a strong security posture are vital to the protection of the COVID-19 vaccines. The health of the global population, as well as the global economy, depending upon how well we can guard the vaccine supply and distribution chain until vast swaths of people are inoculated against a deadly virus. At the close of the very trying and unusual 2020, we were reminded to focus time and energy on what we can control, and it’s about deploying strong security best practices. Perhaps through the steps shared above, we can make 2021 more challenging for the attackers, but brighter for the rest of us.


About the author

Sam HumphriesSamantha (Sam) Humphries has been happily entrenched in the cybersecurity industry for over 20 years. During this time, she has helped hundreds of organizations of all shapes, sizes, and geographies recover and learn from cyberattacks, defined strategy for pioneering security products and technologies, and is a regular speaker at security conferences around the world. In her current regeneration, Sam is part of the global product marketing team at Exabeam, where she has responsibility for anything that has “cloud” in the name. She authors articles and blogs for various security publications has a strong passion for mentoring and often volunteers at community events, including BSides, The Diana Initiative, and Blue Team Village (DEFCON).

DISCLAIMER

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Compliance Standards and the Changing Nature of Data Privacy

106 million Thailand visitors

As the world continues to embrace newer and better technologies like virtualization, SDN, or pure Cloud-based SaaS, coordinate values in all the 4V dimensions (Velocity, Variety, Volume, and Veracity) are growing exponentially. It means the threats and vulnerabilities continue to increase, and hence, safeguarding guidelines and standards get bigger and stronger. Stricter regulations like GDPR, CCPA, and India’s Personal Data Protection Act are evolving. Still, companies generally see them as a checklist item rather than ensuring that the data is completely secure. However, the EU’s GDPR has transformed how data is stored, accessed, and made available to stakeholders.

By Mahesh Kumar Gupta, Product Manager, Online at RMIT University, Australia

The world has been witnessing cases of massive data breaches at well-known global companies, making the headlines. Interestingly, most of these cases are not “attacks” but pure “theft.” In the world of security, we can’t assume a perfect world assuming any data you keep in the open will be left secure and sound. Physical lockers and safes have existed for centuries to protect valuables. One of the most critical reputation criteria for any bank is the availability and ability to secure valuables in lockers. Similarly, it is the data custodian’s responsibility to ensure that data is kept safe, especially when it is your customers’ data.

Data storage gets more vulnerable

Now let’s look at an example of how the new technologies have inadvertently made data storage more vulnerable. Most of the data breaches we just talked about were due to data being stolen from AWS S3 Objects. The “Simple Storage Service” (S3) of AWS has the concept of buckets and objects, very much like a traditional root folder and the leaf nodes. However, interestingly, a bucket can be marked “private,” yet one or more objects can be labeled “public.” And this can be on purpose, for example, keeping some marketing material in a public object for ease of access by any outsider. Here the issue is not about the integrity of the individuals managing these objects. Still, it is about the changing nature of responsibilities with the evolution of newer and newer technologies.

We all are familiar with the security practices of the last decade. As per the security book definitions, these can be categorized into the following areas:

1. Data hygiene: Keeping data free of any malware for both data at rest and data in motion.
2. Encrypt the data at all times to ensure integrity: Most of the IaaS vendors provide Key Management capabilities for both client-side and server-side encryption.
3. Robust Data Loss Prevention capabilities: In addition to basic templates around social security numbers, credit card numbers, behavioral analytics is becoming increasingly important in controlling access and preserving data.
4. Identity and Access Management: Enhanced RBAC, contextual assessment, and run-time controls for securing data are gaining popularity. For on-prem data centers, a quarantine would generally mean a file being taken out from the original location to a quarantine location. This term has sadly become very popular in these tough.

Need for a Data Quarantine

We are in COVID times. So, the analogy here is institutional quarantine. But in the case of the shared responsibility model, where IaaS vendors provide the infrastructure, a quarantine would generally mean access-based quarantine. The data doesn’t move from its own bucket/storage, but is accessed by a user, based on specific rules, is denied. It’s very much like home quarantine with almost no access to the patient’s room in the house.

With the SaaS model, and the need to comply with standards like GDPR and CCPA, there is a need to enhance transactional efficiency. Hence, the API-driven approach is becoming very popular. Earlier, APIs were considered an additional optional tool, while now, this has become a mainline business. In the past two to three years, we have seen many startups foraying in this area with humongous seed, angel, and VC funding. Mobile is a mini-computer, and an increasing number of financial transactions through mobile led to a surge in companies providing this value in a simple form. And thanks to COVID-19, I was forced by circumstances to install and activate some popular wallets to get my share of daily needs. And then, in the virtual yet fully connected world, audio-video is part and parcel of communication. All existing and new platforms and apps enable the need to communicate with users by dialing the phones, be it with a virtual number or a PSTN number. So, we saw many API-based startups in Telephony API becoming popular.

Now, let’s look at all these aspects together from a data security point of view. Related questions will be:

  • How to comply with the standards?
  • How to efficiently store data?
  • How do you quickly process data?
  • How to make the data available to qualified stakeholders?

All this with the underlying, non-negotiable goal of data security and privacy.

API-driven Privacy

Though I don’t use Apple Pay, it was interesting to learn about the way it operates1. The highlight here is not NFC, though it is a superior technology analogous to Bluetooth. Just wave the card, and the connection is set up with the merchant’s terminal. But the innovation is “tokenization.” No credit card data is stored on the iPhone or Apple’s servers. And no credit card data is ever transmitted to or stored on a merchant’s servers, not even in encrypted form.

Wonderful! Isn’t it? From a high-level view, the actual number is replaced with an identifier that’s of no value outside this system, even if stolen.

That’s the idea behind the modern way of protecting data — API driven privacy. It was all about signatures, policies, controls, contextual examination, integrity, access, and permissions on the data, while the new technology is about changing the data itself, at source, in a way that means nothing to the stakeholders outside the system.

A Token-based approach

OK, so the data is tokenized but then if a stakeholder needs a report, how would it work? Modern technology splits up data into various tokens and leverages the advancements in fields of encryption and others. For example, homomorphic encryption is an advancement, which encrypts the tokens, yet provides the ability to process the data through some basic operations. The result can then be decrypted, which is the same as if the original data was leveraged. The use case analysis has been the key to this ecosystem. End-users are not looking for real data, but they are looking for processed data, mainly reports. This way of storing and working with data leads to a win-win situation by protecting privacy and generating the stakeholders’ desired output.

The cons of this approach are limited. Technically, splitting the data, generating tokens, storing them separately, and then querying with many joins, is a process that can introduce a long latency. But this is being addressed by increasing computer speed and distributed computing. The rate of increase in computing speeds is going to be higher than the rate of data growth. Quantum computers may pose a risk in the future, but post-quantum cryptography advances seem promising, and the risk is small.

Stakeholders in the BFSI vertical are much advanced compared to others. Almost every transaction is electronic, whether through the internet or intranet. Hence, complying with PCI DSS is much easier with the modern approach to handling data privacy.

Compliance in health care

However, this is still a challenge in healthcare. The COVID outbreak has led to a sudden spike in getting hold of health data. CCPA allows citizens to ask for their health data; companies want to know about their employees’ health to help them and protect others; hospitals need to know the details for obvious reasons, and insurance companies have a long queue for claims. Two key issues still need to be addressed:

  1. Digitization of health records: Good progress has been made by multiple players in this space, but it is still a daunting task.
    2. Interoperability: Stakeholders of the healthcare ecosystem aren’t well connected yet. If investigated on priority, a full privacy complaint health care system can exist, which can help effectively, not only in treating reactively but also to analyze and predict disruptions pro-actively, powered by AI and analytics.

If a person falls sick, there is a cost for the treatment. It is an expense in the global GDP regardless of whether the individual paid for it, the insurance agency did, or someone else did. A healthier world population automatically increases the global GDP and boosts the economy of every county.

So, we see that compliance regulations help the end-user and become the catalyst for innovation, which has social benefits and business profits!


About the Author

Mahesh Kumar Gupta has been working in the security space since 2011. He is a CISSP and has almost 15 years’ experience in Product Management. Initially, he managed the disaster and system recovery global product portfolio at Symantec. From 2013 onwards, he was handling all storage security products. In his last role as the Head of Product Management at Broadcom, he was also responsible for the entire encryption products portfolio. Before his MBA, he was a core developer at IBM Software Labs for Tivoli Security Directory Server. An alumnus of IIM, Ahmedabad, and BITS Pilani, he has also worked at Adobe and IBM.

DISCLAIMER

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.