Home Blog Page 117

Compliance Standards and the Changing Nature of Data Privacy

106 million Thailand visitors

As the world continues to embrace newer and better technologies like virtualization, SDN, or pure Cloud-based SaaS, coordinate values in all the 4V dimensions (Velocity, Variety, Volume, and Veracity) are growing exponentially. It means the threats and vulnerabilities continue to increase, and hence, safeguarding guidelines and standards get bigger and stronger. Stricter regulations like GDPR, CCPA, and India’s Personal Data Protection Act are evolving. Still, companies generally see them as a checklist item rather than ensuring that the data is completely secure. However, the EU’s GDPR has transformed how data is stored, accessed, and made available to stakeholders.

By Mahesh Kumar Gupta, Product Manager, Online at RMIT University, Australia

The world has been witnessing cases of massive data breaches at well-known global companies, making the headlines. Interestingly, most of these cases are not “attacks” but pure “theft.” In the world of security, we can’t assume a perfect world assuming any data you keep in the open will be left secure and sound. Physical lockers and safes have existed for centuries to protect valuables. One of the most critical reputation criteria for any bank is the availability and ability to secure valuables in lockers. Similarly, it is the data custodian’s responsibility to ensure that data is kept safe, especially when it is your customers’ data.

Data storage gets more vulnerable

Now let’s look at an example of how the new technologies have inadvertently made data storage more vulnerable. Most of the data breaches we just talked about were due to data being stolen from AWS S3 Objects. The “Simple Storage Service” (S3) of AWS has the concept of buckets and objects, very much like a traditional root folder and the leaf nodes. However, interestingly, a bucket can be marked “private,” yet one or more objects can be labeled “public.” And this can be on purpose, for example, keeping some marketing material in a public object for ease of access by any outsider. Here the issue is not about the integrity of the individuals managing these objects. Still, it is about the changing nature of responsibilities with the evolution of newer and newer technologies.

We all are familiar with the security practices of the last decade. As per the security book definitions, these can be categorized into the following areas:

1. Data hygiene: Keeping data free of any malware for both data at rest and data in motion.
2. Encrypt the data at all times to ensure integrity: Most of the IaaS vendors provide Key Management capabilities for both client-side and server-side encryption.
3. Robust Data Loss Prevention capabilities: In addition to basic templates around social security numbers, credit card numbers, behavioral analytics is becoming increasingly important in controlling access and preserving data.
4. Identity and Access Management: Enhanced RBAC, contextual assessment, and run-time controls for securing data are gaining popularity. For on-prem data centers, a quarantine would generally mean a file being taken out from the original location to a quarantine location. This term has sadly become very popular in these tough.

Need for a Data Quarantine

We are in COVID times. So, the analogy here is institutional quarantine. But in the case of the shared responsibility model, where IaaS vendors provide the infrastructure, a quarantine would generally mean access-based quarantine. The data doesn’t move from its own bucket/storage, but is accessed by a user, based on specific rules, is denied. It’s very much like home quarantine with almost no access to the patient’s room in the house.

With the SaaS model, and the need to comply with standards like GDPR and CCPA, there is a need to enhance transactional efficiency. Hence, the API-driven approach is becoming very popular. Earlier, APIs were considered an additional optional tool, while now, this has become a mainline business. In the past two to three years, we have seen many startups foraying in this area with humongous seed, angel, and VC funding. Mobile is a mini-computer, and an increasing number of financial transactions through mobile led to a surge in companies providing this value in a simple form. And thanks to COVID-19, I was forced by circumstances to install and activate some popular wallets to get my share of daily needs. And then, in the virtual yet fully connected world, audio-video is part and parcel of communication. All existing and new platforms and apps enable the need to communicate with users by dialing the phones, be it with a virtual number or a PSTN number. So, we saw many API-based startups in Telephony API becoming popular.

Now, let’s look at all these aspects together from a data security point of view. Related questions will be:

  • How to comply with the standards?
  • How to efficiently store data?
  • How do you quickly process data?
  • How to make the data available to qualified stakeholders?

All this with the underlying, non-negotiable goal of data security and privacy.

API-driven Privacy

Though I don’t use Apple Pay, it was interesting to learn about the way it operates1. The highlight here is not NFC, though it is a superior technology analogous to Bluetooth. Just wave the card, and the connection is set up with the merchant’s terminal. But the innovation is “tokenization.” No credit card data is stored on the iPhone or Apple’s servers. And no credit card data is ever transmitted to or stored on a merchant’s servers, not even in encrypted form.

Wonderful! Isn’t it? From a high-level view, the actual number is replaced with an identifier that’s of no value outside this system, even if stolen.

That’s the idea behind the modern way of protecting data — API driven privacy. It was all about signatures, policies, controls, contextual examination, integrity, access, and permissions on the data, while the new technology is about changing the data itself, at source, in a way that means nothing to the stakeholders outside the system.

A Token-based approach

OK, so the data is tokenized but then if a stakeholder needs a report, how would it work? Modern technology splits up data into various tokens and leverages the advancements in fields of encryption and others. For example, homomorphic encryption is an advancement, which encrypts the tokens, yet provides the ability to process the data through some basic operations. The result can then be decrypted, which is the same as if the original data was leveraged. The use case analysis has been the key to this ecosystem. End-users are not looking for real data, but they are looking for processed data, mainly reports. This way of storing and working with data leads to a win-win situation by protecting privacy and generating the stakeholders’ desired output.

The cons of this approach are limited. Technically, splitting the data, generating tokens, storing them separately, and then querying with many joins, is a process that can introduce a long latency. But this is being addressed by increasing computer speed and distributed computing. The rate of increase in computing speeds is going to be higher than the rate of data growth. Quantum computers may pose a risk in the future, but post-quantum cryptography advances seem promising, and the risk is small.

Stakeholders in the BFSI vertical are much advanced compared to others. Almost every transaction is electronic, whether through the internet or intranet. Hence, complying with PCI DSS is much easier with the modern approach to handling data privacy.

Compliance in health care

However, this is still a challenge in healthcare. The COVID outbreak has led to a sudden spike in getting hold of health data. CCPA allows citizens to ask for their health data; companies want to know about their employees’ health to help them and protect others; hospitals need to know the details for obvious reasons, and insurance companies have a long queue for claims. Two key issues still need to be addressed:

  1. Digitization of health records: Good progress has been made by multiple players in this space, but it is still a daunting task.
    2. Interoperability: Stakeholders of the healthcare ecosystem aren’t well connected yet. If investigated on priority, a full privacy complaint health care system can exist, which can help effectively, not only in treating reactively but also to analyze and predict disruptions pro-actively, powered by AI and analytics.

If a person falls sick, there is a cost for the treatment. It is an expense in the global GDP regardless of whether the individual paid for it, the insurance agency did, or someone else did. A healthier world population automatically increases the global GDP and boosts the economy of every county.

So, we see that compliance regulations help the end-user and become the catalyst for innovation, which has social benefits and business profits!


About the Author

Mahesh Kumar Gupta has been working in the security space since 2011. He is a CISSP and has almost 15 years’ experience in Product Management. Initially, he managed the disaster and system recovery global product portfolio at Symantec. From 2013 onwards, he was handling all storage security products. In his last role as the Head of Product Management at Broadcom, he was also responsible for the entire encryption products portfolio. Before his MBA, he was a core developer at IBM Software Labs for Tivoli Security Directory Server. An alumnus of IIM, Ahmedabad, and BITS Pilani, he has also worked at Adobe and IBM.

DISCLAIMER

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

U.K. Govt Introduces Digital Identity Trust Framework

UK Government, NCSC

The U.K. government revealed the Digital Identity Trust Framework to set-up new policies and standards to regulate the digital identity market in the country. The new trust framework is part of the government’s plan to build trust in the use of digital products and services.

The proposed framework lays out a set of rules that organizations must follow, including the principles, policies, procedures, and standards regulating the use of digital identity in these areas:

  • How organizations should handle and protect people’s data.
  • What security and encryption standards should be followed.
  • How user accounts should be managed.
  • How to protect against fraud and misuse.

The government asked the public to provide feedback on the proposed framework before March 11, 2021. Once finalized, the framework is expected to be brought into law imposing specific standards and requirements for organizations that provide/use digital identity services, which include:

  • Having a data management policy that explains how they create, obtain, disclose, protect, and delete data.
  • Following industry standards and best practices for information security and encryption.
  • Telling the user if any changes, for example, an update to their address, have been made to their digital identity.
  • Where appropriate, having a detailed account recovery process and notifying users if organizations suspect someone has fraudulently accessed their account or used their digital identity.
  • Following guidance on how to choose secure authenticators for their service.

The new move will make organizations aware if there are any issues with their online products and services, and also boost transparency.

“Establishing trust online is essential if we are to unleash the future potential of our digital economy. Today we are publishing draft rules of the road to guide organizations using new digital identity technology and we want industry, civil society groups, and the public to make their voices heard. We aim to help people confidently verify themselves while safeguarding their privacy so we can build back better and fairer from the pandemic,” said Digital Infrastructure Minister Matt Warman.

Myanmar’s Military Tables a Controversial Cybersecurity Bill

Facebook bans Myanmar Military Accounts

In what has been indicated as a draconian and punitive move, Myanmar’s military junta has drafted a cybersecurity bill that has caused an uproar among human rights campaigners. According to several activists, the new law will grant authorities sweeping powers over the internet including allowing the military to ban content it dislikes, restrict internet providers, and even intercept data.

The 36 pages outlining the proposed laws, which was sent to telecom operators and Internet Service Providers for review was leaked online, and nearly 158 civil society organizations have condemned the attempt by the military-controlled state to establish this law.

“The so-called bill includes clauses which violate human rights, including the rights to freedom of expression, data protection, and privacy, and other democratic principles and human rights in the online space,” said the statement, according to Reuters.

According to the Reuters report, the bill instructs internet providers to prevent or remove content deemed to “cause hatred, destroy unity and tranquility” to be “untruthful news or rumors” or to be inappropriate such as pornography.

The cybersecurity draft bill comes weeks after the democratically elected leader Aung San Suu Kyi was arrested in a military coup on February 1, 2021, by the Tatmadaw (the official name of the armed forces of Myanmar). Following the coup, the military rulers immediately banned Facebook, Twitter, and other social media platforms for the next couple of days where its critics had voiced opposition, and again banned the internet the following weekend. With 21 million Facebook users in Myanmar accounting for almost 40% of its population, Facebook is indeed the main portal to the internet for many.

The nation erupted in protests and violence in many parts after several young law students condemned the actions by the army online and in public demonstrations. According to the United Nations human rights office, more than 350 people, including officials, activists, and monks, were arrested.

The military takeover was condemned globally with U.S. president Joe Biden announcing sanctions on the junta’s leaders and freezing $1 billion of Myanmar government assets held in the U.S.

Ripples of the Accellion Hack Reach Australia; QIMR Berghofer Confirms ‘Likely’ Data Breach

Remote Access Scams

The SolarWinds attack, discovered in December 2020, was considered one of the biggest hacks of the decade. However, little did we know that it would have tough competition, just weeks after the SolarWinds hack. We are talking about the Accellion Hack, which was discovered around December 23, 2020.

Initially, the Accellion Hack was limited to only a few organizations. However, as the dust settled, critical organizations like the Office of the Washington State Auditor (SAO), the Australian Securities and Investment Commission (ASIC), and New Zealand’s Reserve Bank came forward and notified about their respective breaches. Joining this list is the Australian medical research institute, QIMR Berghofer. In a media release issued by the institute, QMIR Berghofer said that investigations are being carried out for a “likely data breach through their third-party file-sharing system Accellion.”

Effects of Accellion Hack on QIMR Berghofer

The medical research institute, which uses Accellion’s legacy FTP product for its clinical trials file sharing, first received a notification on January 4, 2021, to immediately apply a security patch. The institute obliged and immediately took the software offline to apply the patch. Post the patch application, no issues were reported. However, Accellion sent a second notification to QIMR Berghofer on February 2, 2021, informing the institute that it was “likely” affected by an indirect data breach that was targeted towards Accellion’s FTP product. The threat actors had exploited a zero-day vulnerability that existed in Accellion’s system for a long time.

Related News:

Bug in Accellion’s Software Exposes Data of 1.4 Mn Washington State Residents

On receiving the second notification, QIMR Berghofer’s IT team immediately took down the software and launched an internal investigation and cyber forensic analysis. Their preliminary investigation confirmed that about 4% (equivalent to 620MB) of the institute’s clinical trials’ data in Accellion was supposedly accessed by an unknown entity through the file-sharing system on December 25, 2020.

The institute was quick to confirm that only nine of QIMR Berghofer’s employees used the Accellion system for their anti-malaria drugs research and that the records did not involve any personally identifiable information (PII). As per the strict regulations of the clinical trials, the participants involved in these trials are given codes for reference instead of using their actual names — which act as a good practice in case of a data breach. Apart from these codes, the potentially breached data includes the following de-identified information:

  • Initials of the participant’s name
  • Date of birth
  • Age
  • Gender
  • Ethnic details of clinical trial participants
  • Participant codes
  • De-identified medical histories of the participants along with their codes

Apart from this, nearly 30 of the institute’s current and former research staff CVs were also stored in the Accellion system and could have potentially been accessed, informed QIMR Berghofer’s Director and CEO, Professor Fabienne Mackay.

Mackay apologized on the institute’s behalf and said, “We don’t believe that any of the information in Accellion could be used to identify any of these participants, but nonetheless, I want to apologize sincerely that some of their de-identified information could potentially have been accessed.”

He added, “Many of these files must be kept for 15 years. However, they did not need to be stored in Accellion. We are examining our protocols for using third-party file-sharing services and will put procedures in place to try to ensure that files are regularly reviewed and saved in the most secure location.”

Closing Notes

QIMR Berghofer is a member of the Australian Cyber Security Centre (ACSC) and, thus, has notified ACSC as well as the Office of the Australian Information Commissioner of the potential data breach.

Mackay also informed that since Accellion’s FTP product was a legacy solution, it was scheduled to be decommissioned in the coming month, but calamity struck before that. This reiterates the words of experts who have been promoting the importance of upgrading from legacy products to the latest solutions like Accellion’s very own Kiteworks. The new-age products and services have ingrained cybersecurity architecture from the bottom-up, which helps organizations to defend against such adversaries.

It’s about time you upgrade your security products!

Related News:

Australian Securities and Investment Commission Hit by a Cyberattack

SIM Swappers Detained for Stealing $100Mn in Cryptocurrencies from Celebrities

SIM Swapping

Eight cybercriminals have been arrested in England and Scotland for their involvement in a series of SIM Swapping attacks by hijacking phone numbers of high-profile individuals in the U.S. The recent arrests follow the earlier detentions in Malta and Belgium (1 arrest in each country) of other members belonging to the same criminal group.

The international investigation was jointly conducted by law enforcement authorities from the U.K., the U.S., Belgium, Malta, and Canada, with coordination from Europol. The investigation found that the attackers targeted thousands of victims in 2020, including popular sports stars, musicians, internet influencers, and their family members. It is suspected that the criminals may have stolen over $100 million in cryptocurrencies after illegally gaining access to the celebs’ mobile devices.

What’s a SIM Swapping Attack?

A SIM Swapping attack is one of the simplest ways for cybercriminals to bypass users’ 2FA protection. In a SIM Swap attack, the attacker calls service providers and tricks them into changing a victim’s phone number to an attacker-controlled SIM card. This allows the attacker to reset passwords and gain access to victims’ sensitive data.

The National Crime Agency (NCA) in the U.K. stated that the cybercriminal group worked together to take control of the victims’ mobiles and changed passwords of their applications and accounts. This allowed the attackers to compromise victims’ social media accounts and steal cryptocurrencies and sensitive information, including contacts synced with online accounts.

Preventive Measures

Authorities warned mobile users to be vigilant about suspicious activities. Besides, the officials recommended security measures to avoid such security incidents. These include:

  • Keep your devices up to date.
  • Do not reply to suspicious emails or engage over the phone with callers that request your personal information.
  • Limit the amount of personal data you share online.
  • Use two-factor authentication (2FA) for your online services, rather than having an authentication code sent over SMS.
  • Avoid associating your phone number with sensitive online accounts.

“SIM swapping requires significant organization by a network of cybercriminals, who each commit various types of criminality to achieve the desired outcome. This network targeted a large number of victims in the U.S. and regularly attacked those they believed would be lucrative targets, such as famous sports stars and musicians. In this case, those arrested face prosecution for offenses under the Computer Misuse Act, as well as fraud and money laundering as well as an extradition to the USA for prosecution,” said
Paul Creffield, Head of Operations at the NCA’s National Cyber Crime Unit.

“As well as causing a lot of distress and disruption, we know they stole large sums from their victims, from either their bank accounts or bitcoin wallets. Cyber criminality is not restricted by borders and our efforts to tackle it reflect that. This investigation is the result of successful collaboration with international partners in the U.S. and Europol, as well as our law enforcement colleagues here in the U.K.,” Creffield added.

Related story: U.S. Telcos Vulnerable to SIM Swapping Attacks: Princeton Research

Mobile Health Apps Expose Protected Health Information via APIs

healthcare cybersecurity, Nucleus:13

Health care providers have become the primary targets of cybercriminals. In 2020, several data breaches and cyberattacks were reported on health care organizations globally. Cybercriminals often focus on exploiting vulnerabilities on connected medical devices to pilfer patients’ sensitive information.

A new study from Approov and cybersecurity researcher Alissa Knight revealed that popular mobile health (mHealth) applications are potentially exposing millions of patients’ personally identifiable information (PII), including social security numbers, addresses, diagnosis history, birthdates, medications, protected health information (PHI), etc.

The survey “All That We Let In” found Application Programming Interface (API) vulnerabilities in the 30 popular mobile health apps, affecting over 23 million mHealth users. Since more than 318,000 mHealth apps are available on major app stores, it is suspected that the number of patients impacted is greater than expected.

Key Highlights

  • Of the 30 popular apps tested, 77% contained hardcoded API keys, some of which don’t expire, and 7% contained hardcoded usernames and passwords. Nearly 7% of the API keys belonged to third-party payment processors that warn against hard-coding their secret keys in plain text.
  • 50% of the APIs tested did not authenticate requests with tokens.
  • 100% of API endpoints tested were vulnerable to BOLA (Broken Object Level Authorization) attacks that allowed the researchers to view the PII and PHI for patients that were not assigned to the researcher’s clinician account.
  • 50% of the APIs tested allowed medical professionals to access the pathology, X-rays, and clinical results of other patients.
  • A replay vulnerability allowed the researcher to replay days-old FaceID unlock requests that allowed to take over other users’ sessions.

Remediation

mHealth platform developers are advised to follow safety measures to protect their customer data and sensitive resources. These include:

  • Recognize that synthetic traffic to the API is an issue and arises from bots and automated tools, not from genuine apps and legitimate data requests.
  • Secure the development process and harden apps but ensure that run-time protection is also in place.
  • Certificate pinning is critical but often left undone because expired certificates can block apps and impact the customer’s experience. However, when done correctly, certificate pinning does not impact either performance or availability.
  • Organizations and developers need to monitor the effectiveness of the controls they implement and adjust them easily – both for compliance with HIPAA mandates and to sustain data security and privacy.
  • Penetration testing and static and dynamic code analysis should be performed regularly.

“These findings are disappointing but not at all surprising. The fact is that leading developers and their corporate and organizational customers consistently fail to recognize that APIs servicing remote clients such as mobile apps need a new and dedicated security paradigm. Because so few organizations deploy protections for APIs that ensure only genuine mobile app instances can connect to backend servers, these APIs are an open door for threat actors and present a real nightmare for vulnerable organizations and their patients,” said David Stewart, Founder and CEO of Approov.

Good Governance and Controls for Ensuring Data Privacy

personal data collection, Personal data. Data Privacy

There has been a misconception about privacy that confuses many people. People tend to share seemingly related or unrelated personal information online, such as birthdays, addresses, contact details, marriage announcements, and holiday plans on social media. People are also inclined to share pictures of favorite foods, people, localities, and workplaces. And they provide opinions on sensitive issues (religious, national, political, etc.) throughout different social media platforms. On the other hand, new and exciting technologies are emerging almost on a daily basis, and people share their information in the guise of playing games online, attending virtual worlds, and doing shopping online. Similarly, organizations also collect and store relevant personal information for business purposes. Consequently, the privacy risk increases ubiquitously with every share. The shared data, individually or collectively, can be used for malicious activities.

By Muhammad Tariq Ahmed Khan, Head of Information Security Audit, Internal Audit Division, Arab National Bank, Riyadh

Before moving ahead, let’s have a clear understating of “Privacy” and related terminologies:

What is Privacy?

Privacy is the ability of individuals or groups to seclude themselves, or information about themselves, and thereby express themselves selectively. (Source: Wikipedia)

In other words, Privacy is an individual’s fundamental right to have control over the collection, usage, and dissemination of personally identifiable information.

Personally Identifiable Information (PII) – The Information that directly or indirectly identifies an individual. For instance: name, address, date, and place of birth, National Identity Number, biometrics (e.g., photo, fingerprint, iris, etc.).

What is Data Privacy?

“Data Privacy,” also called “Information Privacy,” is the technical aspect of information security that deals with the ability of an organization to handle PII, or an individual’s right to determine what kind of data can be collected/stored in a computer system, and can be shared with third parties.

Difference between Data Privacy and Data Security

People and organizations are sometimes confused by the differences between Data Privacy and Data Security. Both of them pertain to PII, but are distinct concepts. Data Privacy is about the control (related to usage and governance) over PII, such as policies and procedures being established to ensure that PII is collected, stored, used, and shared appropriately. Whilst Data Security is about ensuring that technical controls (related to confidentiality, integrity, and availability) are implemented to protect PII from malicious cyberattacks. In other words: Data Security is a technical aspect of PII, whereas Data Privacy is a legal aspect. In layman’s terms, privacy is the fundamental right to be left alone without any intervention.

Managing Privacy Risks

One of the biggest challenges faced by any organization is managing privacy risks. Since privacy awareness has increased over time, people are becoming more concerned with how organizations are handling their personal information.

Moreover, with the inception of privacy regulatory laws and associated penalties, it has become mandatory for organizations to take necessary steps in establishing and implementing a strong privacy risk management framework. Inadequate, or the lack of, a risk management framework may present numerous organizational risks, such as:

  1. Possible damage to the organization’s public image and reputation
  2. Potential financial or operational losses
  3. Regulatory sanctions and penalties/ fines
  4. Loss of customers’ trust and failure to attract customers
  5. Damaged business relationships

Recommended Good Privacy Governance and Controls

Digital records of PII demand unique forms of protection at each part of their lifecycle. It is paramount for an organization to implement effective privacy programs that include the following good privacy governance and controls in order to address the above privacy risks:

Privacy Governance

  1. Have a formal corporate governing structure to determine the level of privacy risk appetite acceptable for senior management.
  2. Have a privacy framework containing policies and procedures relating to the privacy of personal information address data classification, record management, retention, and destruction.
  3. A Privacy Risk Management Framework should be developed to identify, analyze & evaluate, and treat privacy risks.
  4. Define the roles, responsibilities, and accountability related to the privacy program during its life cycle.

Data Collection

  1. Document the business purposes for collecting personal information to ensure PII, which are not required and are not collected and retained.
  2. Identify what kind of PII the organization is required to collect, who will collect, how will it be collected, and who will define what is personal or private.

Permissions

  1. Be well-aware about where all personal information is stored and who has access to it.
  2. Implement a technical solution to set different permission levels for employees based on what PII they need to access such as Public, Private, and Restricted Access.

Data Confidentiality Assurance

  1. Ensure PII is encrypted at rest and in motion throughout the life cycle. PII should be encrypted at various levels — databases, networks, system platforms, application layers, and business process/functional levels.
  2. Identify the disclosure rules of PII to relevant third parties and not disclosed to unauthorized entities (people and systems).

Data Governance and Education

  1. Define an awareness program to provide employees the privacy awareness training and have guidance on their specific responsibilities in handling privacy requirements, issues, and concerns. Employees who handle or have access to personal information must have undergone the required training.
  2. Ensure that skilled resources are available to develop, implement, and maintain an effective privacy program.

Privacy Compliance Monitoring Framework

  1. Establish a compliance monitoring framework to periodically verify the compliance level to ensure that privacy policies and procedures are being followed and detailed enough to meet new or current requirements.
  2. Perform an assessment of privacy laws and regulations currently applicable for the organization or will be applicable in the future.

Privacy Incident Response Plan

  1. Develop a privacy incident response plan in the event of a breach or attempted breaches of personal information and report such breaches to authorized individuals or regulators or anyone who has been affected by a data breach. This includes breaches that occur on the part of third parties.

Data-Flow Map

  1. Establish a data-flow map that covers what kind of information is subject to transfer from one location to another, such as between departments, between individuals, to and from third parties, and through geographical borders.

Privacy Technical Solutions

  1. Any software or system or technology to be used for privacy should be fully evaluated and secured before deployment.
  2. Consider deploying hyper-automation to automatically redact PII from both static files and audio/video recordings.

Key Benefits of Good Privacy Governance and Controls

  1. Protecting the organization’s image and reputation.
  2. Protecting valuable data of the organization and its customers, employees, and business partners.
  3. Achieving a competitive advantage in the marketplace.
  4. Complying with applicable privacy laws and regulations and avoiding regulatory penalties.
  5. Enhancing an organization’s credibility and promoting confidence.

Conclusion

Protecting privacy cannot be separated from technological development, and these days, organizations are inclined to invest in security technology to reduce the risk of privacy exposure. However, there is no technology that will prevent and eliminate the risk of every data privacy breach. So, organizations should fully understand the nature of risk and take a layered approach to improve their security posture by taking the time to understand PII and re-evaluate how this privacy data can be managed and protected.


Caveat

This article doesn’t cover Data Privacy with respect to the collection, usage, storage, and dissemination of PII in physical form.


About the Author

Muhammad Tariq Ahmed KhanMuhammad Tariq Ahmed Khan is Head of Information Security Audit, Internal Audit Division, Arab National Bank, Riyadh. He has more than 21 years’ experience in the Banking industry, in areas such as IT, Information Security, and IT Audit. He has a solid understanding and application of Risk-Based Audit methodology, ISMS (ISO 27001), ISO 22301, NIST and COBIT, IT & Information Security regulatory compliance. To his credit, Khan also has sound technical knowledge in various IT platforms and IT project management – with experience in Disaster Recovery and Business Continuity Management.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


Read our exclusive coverage on Data Privacy Day 2021 here.

Why is Ransomware Still a Problem?

Ransomware Attacks, Graff ransomware attack

Ransomware has been with us now for over 30 years.  Let that sink in.  Ransomware predates the modern internet as we know it and the first example was distributed on floppy disks[1] in 1989.  While the floppy disk has been relegated to the recycle bin of history, ransomware is still with us and still poses a serious threat to businesses, governments, and individuals across much of the world.  Worse, modern ransomware attacks have evolved from simply encrypting files and demanding payment for a decryption key to complex attacks that add data extraction and extortion to the attacker’s playbook.

By Saryu Nayyar, CEO, Gurucul

It Used to be Easier

From the attacker’s perspective, ransomware is popular because it’s comparatively easy to go from initial infection to cash payout.  With stolen credit card information, for example, the attacker needs some way to get the payout from the card.  Whether that’s by selling the cards to someone else on the dark web or using the card themselves to make purchases or get cash advances, there are extra steps involved that make the attack less attractive and less lucrative.  Likewise, stolen personal information can allow a range of attacks and can be a valuable commodity on underground markets, there are additional steps between compromise and payout.

By using the initial attack to plant their malware and hold the victim’s encrypted files for ransom, the attacker eliminates a layer of complexity and the profit taken by middlemen – unless the attacker is using some kind of Crime as a Service, the ransom payout goes directly to them.  No extra steps, and no paper trail as could happen with stolen credit cards.  But the model wasn’t perfect.

We Learned to Defend

While ransomware originally just entailed encrypting the victim’s files and demanding payment for the decryption key, attackers still found there were weaknesses in that business model.  In some cases, flaws in the malware.  Weak encryption, or a sloppy implementation of the algorithm, made it reasonably easy to generate keys and break the encryption.   There were publicly available tools that could recover files encrypted by several different malware strains, which limited their effectiveness – to the great relief of their victims.

Disaster Recovery and Business Continuity plans also evolved to compensate for malware attacks, including, specifically ransomware.  There is an entire industry built upon providing rapid backup and restoration capabilities in the case of file loss.  The current generation of cloud backups is dramatically faster and more efficient than the tape backups of old, and made recovery from ransomware a fairly simple and relatively painless process.

Backups let an organization respond to a ransomware attack with “sorry, but no,” while they simply restored the damaged files from a secure backup.  This backup and restore capability was already baked into many disaster recovery plans, and this alone should have been enough to turn ransomware attacks from a massive and expensive outage to barely an inconvenience.

They Didn’t Go Away

As more and more organizations embraced operational plans that account for those attacks, we would have expected to see ransomware attacks fade.  And that’s not even taking into account cybersecurity technologies that could prevent, or at least slow, these attacks before they damaged more than a handful of files.  But that’s not what’s happened.

Faced with improved defenses, cybercriminals evolved their attacks.  Now, before their malware starts to encrypt files and throw up the disconcerting “your files have been encrypted!” banner, they copy large volumes of their victim’s data outside the organization and threaten to expose it if the victim doesn’t pay the ransom.

Now, even if the target can rely on a robust backup plan to rapidly recover from a ransomware attack, they are still subject to blackmail lest their company secrets are revealed.

Evolve and Adapt

It’s this evolution to hybrid attacks that includes holding data for ransom both through encryption and the threat of revelation, that has kept ransomware a near top-of-mind threat in the cybersecurity space.  Our existing ability to rapidly recover destroyed files doesn’t prevent the damage that comes from having the said files released to the public.  This change in attacker strategy forces us to shift our defense plan from one of recovering rapidly after the attack to one that must resist the attack in the first place.

Assume They Are Already In

In truth, resisting attacks in the first place is where cybersecurity should start.  It is always better to keep the bad guys out so they’re not in the environment doing damage in the first place.  Unfortunately, the reality is we know the bad guys will find their way in.  Yes, improved perimeter defenses can go a long way to keeping them out, as can risk-based user authentication systems and multi-factor authentication solutions.  But we must operate from an “Assume Breached” perspective.  After all, the best perimeter defenses in the world are of little use when an attacker bribes an insider to plant malware[2] or otherwise compromise the business.

The “assume breach” posture means we need to have internal defenses that can identify an attack before it does serious damage.  Whether that’s through micro-segmentation that helps thwart lateral movement, endpoint defenses that contain malware infections, deception systems that lead attackers into revealing themselves, or security analytics that can identify an attack by the attacker’s behaviors and tie them together through context, organizations need a comprehensive security stack that can thwart even a sophisticated attacker.

Back to The Question

To answer the ultimate question of why ransomware is still a problem, it’s because cybercriminals have evolved their business model to go beyond simple ransomware.  We evolved our defenses to thwart their attacks and they have evolved their attacks to get around our defenses in an unending cycle.

However, with a combination of solid disaster recovery and business continuity plans, and a comprehensive security stack that’s built around defenses in-depth and assuming attackers can find a way in, organizations can blunt the impact of ransomware attacks – if not eliminate the threat entirely.


RELATED STORY

Ransomware in 2020. How likely is it to advance?

Learn Penetration Testing and become a Certified Ethical Hacker. Help your company fight ransomware. More details here.


About the Author

Saryu Nayyar CEO GuruculSaryu Nayyar is an internationally recognized cybersecurity expert, author, speaker, and member of the Forbes Technology Council. She has more than 15 years of experience in the information security, identity & access management, IT risk & compliance, and security risk management sectors. She has held leadership roles in security products and services strategy at Ernst & Young, Oracle, Simeio, Sun Microsystems, Vaau (acquired by Sun), and Disney. She is passionate about building disruptive technologies and has several patents pending for behavior analytics, anomaly detection, and dynamic risk scoring inventions.

DISCLAIMER

Views expressed in this article are personal. The facts, opinions, and language in the article do not necessarily reflect the views of CISO MAG.


References

[1] The “AIDS Trojan” of 1989 – https://en.wikipedia.org/wiki/AIDS_(Trojan_horse)

[2} https://www.zdnet.com/article/at-t-employees-took-bribes-to-plant-malware-on-the-companys-network/


CISO MAG’s February issue on Ransomware is out. Get your preview here. To get your copy Subscribe now!

Love is Blind but Cybercriminals Are Not! Valentine’s Day-themed Phishing Attacks on Rise

Dating Apps

Like hardcore lovers who go the extra mile to fulfill their love-life goals, cybercriminals also try hard to accomplish their malicious operations. They always look for occasions or opportunities to take advantage of innocents. From fake dating apps to online romance scams, threat actors are everywhere online. Hence, being blindfolded in love is acceptable, but not in cybersecurity.

Research from security firm Check Point revealed that over 400 Valentine’s Day-themed phishing campaigns were active every week in January 2021. It also found a 29% year-over-year increase in Valentine’s Day-themed domains registered last month. Out of the 23,000 domains, 523 were malicious or suspicious.

“As people go online to purchase gifts for their loved ones during this period, Check Point Research (CPR) has observed a surge in malicious phishing email campaigns in the second half of January,” Check Point said.

Leveraging Imposter Sites

Check Point stated that the majority of the phishing emails are focused on buyer fraud with reused themes and webpages from past phishing campaigns. Attackers usually use phishing sites and text messages to trick users into clicking/downloading malicious URLs/attachments.

Check Point researchers found a phishing email pretending to be from Pandora (a Danish jewelry manufacturer), which was used in Black Friday-related phishing campaigns in November 2020. Attackers tried to attract users into purchasing jewelry items by offering unreliable discounted prices on a fake Pandora webpage.

“Since these attacks are specifically designed to exploit the human nature of wanting a good deal, it is extremely important to prevent these attacks from ever reaching their desired victims – because even the most vigilant and cyber-savvy amongst us can sometimes get fooled,” Check Point added.

Preventive Measures

Check Point recommended safe online purchasing measures to avoid security risks. These include:

  • Verify you are ordering online from an authentic source. Don’t click on promotional links in emails, and instead Google search your desired retailer and click the link from the Google results page.
  • Beware of special offers. An 80% discount on the new iPad is usually not a reliable or trustworthy purchase opportunity.
  • Beware of lookalike domains, spelling errors in emails or websites, and unfamiliar email senders.
  • Never share your credentials and always be suspicious of password reset emails.

Alison Partners With CODERED to Offer Cybersecurity Courses

hands-on android security

Alison, a popular online learning platform, announced that it has entered a publishing partnership with the CODERED, the largest cybersecurity course publisher. CODERED is part of the International Council of E-Commerce Consultants (better known as EC-Council), a global cybersecurity technical certification body.

EC-Council is an ANSI 17024 accredited organization and has earned recognition by the DoD under Directive 8140/8570, in the U.K. by the GCHQ, and a variety of other authoritative bodies that influence the entire profession. EC-Council provides internationally recognized cybersecurity programs and services to the largest global businesses.

First Online Course

The first online course published on the Alison platform by CODERED is “Hands-On Android Security,” which emphasizes on Android penetration and how to analyze existing Android apps.

The course focuses on the practical aspects of penetration testing, starting with the core concepts of the Android operating system, hardware security components, and native applications. Besides, users can learn about vulnerabilities and test their work to fully secure their Android environment. The course takes approximately 4-5 hours to complete.

EC-Council will certify users on successful completion of the Hands-On Android Security course.  The course will help users to:

  • Analyze Android Application
  • Define Android Device
  • Explain Android architecture and data structure
  • Distinguish between mobile security threats and risks
  • Evaluate attacks on Android devices
  • Outline new hacking tools and techniques

Since Alison is one of the free learning platforms for education and skills training, the partnership will help individuals study anywhere, at any time, and at any subject level. The other online courses from Alison and CODERED partnership include:

  • Black Hat Python
  • Python for Pentesters
  • Identity and Access Management
  • Secure Full Stack MEAN Stack Developer

“With almost three-quarters of smartphones being Android devices, compared to 26% on IOS devices, this course will be a welcome learning resource for the Android developer community. It covers the tools and software needed to test and protect apps from hackers,” Alison said. 

To know more about CODERED, click here.
Take the course here.