Home Blog Page 123

TikTok Fixes Critical Vulnerability in its ‘Find Friends’ Feature

TikTok Security Vulnerabilities Could Expose User Data, tiktok, tiktok child data mishandling

Security researchers from Check Point uncovered a critical vulnerability in TikTok’s Find Friends feature, which could have allowed threat actors to pilfer users’ phone numbers and sensitive profile information linked to their accounts. The social media app has now fixed the flaw after Check Point reported the issue.

The Find Friends Flaw

Check Point researchers said TikTok’s contacts syncing feature Find Friends allows the users to synchronize their phone contacts to find other TikTok users. If exploited, threat actors could potentially misuse the users’ information or build a database of users’ private details to perform malicious activities in the future. Even though the vulnerability only affects the users who have linked their phone number to their TikTok account, the vulnerability can be exploited to illicitly obtain users’ sensitive information.

“As our main purpose was to examine the privacy of TikTok, we focused on all actions in the app which relate to users’ data. We found the app enabled contacts syncing, meaning that a user can sync their phone contacts to easily find people they may know on TikTok. In simple terms, this makes it possible to connect users’ profile details to their phone numbers. If exploited, this vulnerability would have only impacted those users who have chosen to associate a phone number with their account (which is not required) or logged in with a phone number,” Check Point said.

“With those phone numbers and profile details, attackers could potentially access further information related to users, obtained outside of TikTok such as searching for other accounts or data available,” Check Point added.

Multiple Vulnerabilities in TikTok

Earlier, Check Point researchers found multiple vulnerabilities in the TikTok application that could have allowed hackers to break into user accounts and manipulate their content, such as deleting videos, uploading unauthorized videos, making private hidden videos public, and revealing personal information saved on the account. However, TikTok deployed a security solution to ensure the safety of its users.

Australian Securities and Investment Commission Hit by a Cyberattack

Australian Securities and Investment Commission Hit by a Cyberattack

The Australian Securities and Investment Commission (ASIC) became aware of a security incident that affected one of its servers that is used to transfer files like credit license applications. The securities regulator stated that cybercriminals may have viewed certain information; however, it clarified that there is no evidence of misuse of the credit license forms, attachments, and other sensitive information. ASIC immediately disabled the server to avoid the extent of the breach.

“While the investigation is ongoing, it appears that there is some risk that some limited information may have been viewed by the threat actor,” ASIC said.

According to a report, the security incident occurred due to a vulnerability in Accellion’s file-sharing software, which was also used by New Zealand’s Reserve Bank that recently faced a cyberattack. In a statement, the Bank acknowledged that a malicious actor reportedly hacked and accessed one of its data systems, which stored sensitive information. The issue occurred in a third-party file sharing service that potentially led to the access of critical banking information.

Data Sharing Issues Continue to Rise in Australia  

Recently, Google notified that it would stop its search engine services in Australia if the Australian Competition and Consumer Commission (ACCC) implements the proposed News Media Bargaining Code in the country. Social media giant Facebook is also concerned about the controversial policy, making technical companies pay for hosting news links and snippets from news publishers. Read the full story

How the disposable nature of tech is putting your businesses data at risk

data breach

It has become common practice for people to chase the latest technology trends. As tech becomes part of our everyday life, the lifecycle of our devices becomes smaller and smaller.

This is posing a huge issue to the sprawl of data.

By Rick Vanover, Senior Director of Product Strategy for Veeam Software

With the lifecycle of tech shortening, many are abandoning old devices at second-hand stores (thrift shops) and selling them to new owners without thinking about the data and personal information that is left on there.

Many people are now working from home and opting to use a personal computer to get work done. This is making the challenge of controlling and managing your organization’s data near impossible. With data now sprawling across the company and personal devices, there is no control over it, especially when it is sold on to its next home, left behind at a second-hand store, or thrown away.

To add to this, workplace trends like BYOD (Bring Your Own Device) are gaining popularity and making it harder for organizations to keep track of data. IT teams have less control over employees’ personal devices and so protecting the data on it becomes a challenge. Things like a lack of encryption or outdated operating systems can lead to potential hacks and data loss.

This is something organizations need to consider when implementing a cybersecurity strategy. This means educating staff in understanding the risks involved with discarding old devices and setting up the right protections within an organization.

Educating staff

The first step in managing this is for IT teams to educate employees about the risks involved with using personal devices for work purposes and then eventually discarding them. Employees should be trained in the security practices of an organization and also understand how that translates to personal devices.

Part of this should be educating staff on how to properly wipe the contents of their phones if they eventually discard them to a second-hand store. This is not something that is considered by most organizations, but it should be as one in 10 Australian mobile consumers are choosing to participate in the second-hand phone market.

Employees also need to be briefed to understand how to identify potential malware, phishing, or ransomware attacks on their personal devices. If employees are able to identify these threats, it mitigates the risk of data being lost at all.

Protections

If educating staff fails, there are some protections IT teams can manually put in place to mitigate risk even further.

  • Constant software updates – if employees opt to use their devices for work purposes, this has to be under the precedent that the phone is updated regularly. Be sure to provide employees with the support necessary to deliver these updates.
  • Password security – to minimize security risks, roll out a compulsory monthly password change. Also, ensure that you are putting up restrictions around the type of passwords employees are using, making it less obvious to potential hackers.
  • Encrypt data for protection – smartphones and tablets have encryption options that will provide protection of storage. Smartphones that are encrypted have a lower risk of being hacked.
  • Clear all phone data – if employees decide to move on to a new device or stop using their current device, ensure you manage the deletion of all data from that phone and a strict policy around discarding devices.

As work from home has become the new normal this year, it is becoming increasingly complicated to manage the sprawl of a company’s data. While these agile work trends had been predicted for the next 5-10 years, organizations were not prepared for them to become so mainstream in 2020. As we look to the future, this is only going to become more and more complicated.

It’s important for IT teams to understand all the risks as their companies take on more flexible working arrangements in the new future. A huge part of this is of course understanding the risks that come with using personal devices, particularly in the process of discarding them or sending them to a new home.


About the Author

Rick Vanover

Rick Vanover (Cisco Champion, VMware vExpert) is the Senior Director of Product Strategy for Veeam Software based in Columbus, Ohio. Rick’s experience includes system administration and IT management; with virtualization, cloud, and storage technologies being the central theme of his career recently. As a blogger, podcaster, and active member of the IT community, Rick builds relationships and spreads excitement about Veeam solutions.  Before becoming the “go-to” guy for Veeam questions, Rick was in system administration and IT management.  His community designations include VMware vExpert and Cisco Champion.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

As Cybercriminals Evolve, So Must AI

Artificial Intelligence

Cyber actors are continually evolving, changing and strengthening their attack methods but also changing their attack vectors and targets. As we’ve seen during the rise of remote work due to the pandemic, cybercriminals are about as opportunistic as they come. They will use almost anything available to attack their targets. And that means cybersecurity teams must be just as stealthy. They must work to stay ahead of bad actors and never let their guard down.

By Derek Manky, Chief of Security Insights & Global Threat Alliances, FortiGuard Labs

Doing this requires the use of AI – there’s just no way that humans alone can keep up, especially as cybercriminals also make increasing use of AI, automation, and machine learning for their nefarious activities.

The evolution of AI is critical for future defense against evolving attacks. This will include using local learning nodes powered by machine learning as part of an integrated system, similar to the human nervous system. AI-enhanced technologies that can see, anticipate, and counter-attacks will need to become reality in the future, because cyberattacks of the future will occur in microseconds. The primary role of humans will be to ensure that security systems have been fed enough intelligence to not only actively counter live attacks but actually anticipate those attacks so that they don’t happen in the first place.

AI is being used on both sides

We have observed bad actors using AI and machine learning to their advantage. They’re building platforms to deliver malicious payloads at unheard-of speeds and scale. And no industry or organization is immune to these attacks. So, think of the adage about fighting fire with fire. When you’ve got bad actors using AI, the only way to combat their efforts will be to also use AI.

But that means AI in cybersecurity will need to continuously evolve, as well – faster and farther than ever before. Combined with rich media services and increasingly intelligent endpoint devices, 5G will soon be able to create dynamic, ad hoc edge networks that will fundamentally change how data is generated, distributed, and used. Add billions of semi-intelligent IoT devices and dynamic edge routing resources, and we are on the verge of another dramatic shift that will impact how we work and live.

Using AI and ML for maximum impact

To stay ahead of bad actors, organizations must adopt a proactive, strategic approach that relies on threat intelligence that’s timely, accurate, and actionable. Strategic and tactical information gathered from a global threat intelligence network—and analyzed with sandboxing and AI/ML techniques—enables an organization to transition to a proactive security posture. To achieve this, organizations should look for solutions that train their systems using all three learning modes of ML—supervised, unsupervised, and reinforcement learning—as such systems will become increasingly accurate over time.

Joining AI-enhanced security systems with real-time, reliable threat intelligence and networking technologies creates a security-driven network approach that can function as one unified system. A system of this kind is designed to match pace with and secure these increasingly complex and dynamic networks–and relies on tiers of security. It starts with systems woven throughout the network, such as segmentation, behavioral analytics, and zero-trust network access. These systems work non-stop to ensure that the traffic coming into and moving across the network is free of threats.

An additional piece of the puzzle is a distributed security system that replaces traditional sensors with learning nodes. This system is not only able to gather threat information but also function as the first line of defense. It does so by using stored knowledge supplemented by machine learning to detect a threat and provide a coarse-grain response.

The role of humans

By adopting technologies that automate tasks or use AI-driven security operations, CISOs are able to hire a broad range of cybersecurity professionals while reducing the learning curve needed for new or junior staff to become highly effective in the security operations center. Using next-generation cybersecurity technologies enables integrated, enhanced user interfaces that take advantage of the automation of tasks. This allows new and junior staff to be effective sooner, thereby reducing the need for senior-level staff oversight.

In addition, these technologies can help fill holes left by the cybersecurity skills gap. This provides for more meaningful and high-value work across the range of cyber professionals and can also increase staff retention.

The future of security is AI

The networks being built today are extremely complex. They require a level of awareness and response to defend users, devices, and data that humans simply cannot achieve, no matter how experienced, skilled or intelligent. Cyber assailants are using increasingly complex and sophisticated threats powered by AI and machine learning. AI-enhanced systems, coupled with humans who continue to train and refine those systems, are essential for protecting our digital society going forward.


About the Author

Derek MankyAs chief of security insights and global threat alliances at FortiGuard Labs, Derek Manky formulates security strategy with more than 15 years of cybersecurity experience. His ultimate goal is to make a positive impact on the global war on cybercrime. Manky provides thought leadership to the industry and has presented research and strategy worldwide at premier security conferences. As a cybersecurity expert, his work has included meetings with leading political figures and key policy stakeholders, including law enforcement, who help define the future of cybersecurity. He is actively involved with several global threat intelligence initiatives, including NATO NICP, INTERPOL Expert Working Group, the Cyber Threat Alliance (CTA) working committee, and FIRST, all in an effort to shape the future of actionable threat intelligence and proactive security strategy.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Researcher Finds New Android Malware Spreading Via WhatsApp Messages

WhatsApp and Indian governmentWhatsapp Hack

Researchers have uncovered a new Android malware that disguises itself as a WhatsApp message to spread across victims’ contact lists.  According to Lukas Stefanko, a researcher from security firm ESET, cybercriminals are targeting unsuspecting WhatsApp users for their malicious adware campaign.

“This malware spreads via victim’s WhatsApp by automatically replying to any received WhatsApp message notification with a link to a malicious Huawei Mobile app. Message is sent only once per hour to the same contact. It looks to be adware or subscription scam,” Stefanko said.

Imposter Huawei Mobile App

The malicious link is directed to a fake Huawei Mobile app that redirects users to a fake Google Play Store website. Once installed, the fake app prompts victims to grant it notification access to carry out account takeover activities. The malware abuses WhatApp’s quick reply feature to send quick responses automatically, along with the hidden malware.

In addition to accessing notifications, the fake app requests intrusive permissions to run in the background. Using the fake app, hackers can exploit other applications in the device to steal account credentials and other sensitive information.

The researcher explains…

https://www.youtube.com/watch?v=XXi29noe2NE

“I don’t remember reading and analyzing any Android malware having such functionality to spread itself via WhatsApp messages. I would say it could be via SMS, mail, social media, channels/chat groups etc.,” Stefanko added.

What Australia’s “News Media Bargaining Code” Means for Google

Cryptocurrency scams in Australia

Google notified that it would stop its search engine services in Australia if the Australian Competition and Consumer Commission (ACCC) implements the proposed News Media Bargaining Code in the country. Social media giant Facebook is also concerned about the controversial policy, making technical companies pay for hosting news links and snippets from news publishers.

What is News Media Bargaining Code?

Developed by the ACCC, the News Media Bargaining Code is a mandatory code of conduct to address bargaining power imbalances between Australian news media businesses and digital platforms, especially Google and Facebook. The ACCC released a draft Code for public consultation on July 31, 2020. After multiple consultations and recommendations, the final legislation was introduced in the House of Representatives on December 9, 2020, which is yet to be approved.

If approved, the Code would allow news media enterprises to bargain with tech giants like Google and Facebook to pay them for the inclusion of news on their services.

The Code also includes certain standards for technology companies, which include:

  • Providing advance notice of changes to algorithmic ranking and presentation of news.
  • Appropriately recognizing original news content.
  • Providing information about how and when Google and Facebook make available user data collected through users’ interactions with news content.

What’s the Concern?

As per the proposed Code, Google and Facebook have to pay news websites for using their links on various platforms like Facebook News Feed, Instagram, Google Search, Google News, Facebook News Tab, and Google Discover. So far, the Code applies to Google and Facebook only. However, the ACCC said that it may include other companies if they were found to hold a significant bargaining power imbalance with the news publications in Australia.

Currently, no search engine pays to connect users to other sites through links, however, this law would force Google to pay for the links that appear in search results (as snippets) and the brief description underneath.

What Google Says…

Google has shared its concerns with the Senate Committee, which is reviewing the new draft of the proposed Code. Speaking before the Senate Economics Legislation Committee recently, Google Australia and New Zealand’s Managing Director Mel Silva said that the company is most concerned with the Code’s requirements.

“The ability to link freely between websites is fundamental to Search. This Code creates an unreasonable and unmanageable financial and operational risk to our business. If the Code were to become law in its current form, we would have no real choice but to stop making Google Search available in Australia. That is the last thing I or Google want to have happened—especially when there is a way forward that allows us to support Australian journalism without breaking Search. We think that would be a bad outcome not just for us, but for the millions of people and businesses across Australia who use Google Search every day,” Silva added.

SonicWall Hacked Through Zero-Day Vulnerabilities in its VPN Product

Beware of these “fleeceware” VPN apps on Apple App Store, SonicWall hacked

Cybersecurity firm SonicWall, popularly known to provide security products like firewall and VPN access tools, in the wee hours of Friday night disclosed that it was compromised by attackers who targeted zero-day vulnerabilities in its  VPN tools. Initially, SonicWall reported that the impacted products included the NetExtender VPN client version 10.x (released in 2020) and Secure Mobile Access (SMA) version 10.x. However, an updated release on the following day stated that NetExtender VPN was safe to use while investigations for SMA were still ongoing.

What was Compromised in the SonicWall Hack?

The coordinated successful attack on SonicWall’s internal systems meant that the attackers had access to the company’s GitLab repository. This repository hosts the source codes of its various product offerings, including the NetExtender VPN and Secure Mobile Access, which the company had reported as “affected” in its first Security Notice.

In the age of working from home, the NetExtender VPN client and SMB-oriented SMA 100 series provide employees/users of SonicWall’s clients with secure remote access capabilities to internal resources. However, the exploitation of the zero-day vulnerabilities sure rings some alarm bells. The company was also quick to state that its other product series, the SMA 1000, was not susceptible to the vulnerability and utilizes clients different from NetExtender.

SonicWall’s Advisory

In the security note published by the company to update its customers on the ongoing investigation, it asked organizations to enable two-factor or multi-factor authentication, disable NetExtender access to the firewall, follow restricted access to users and admins from public IP addresses, and configure whitelist access on the SMA directly to mitigate the flaws.

However, the recommendations can be implemented based on the products that its clients use because SonicWall’s updated version deemed its Firewalls, NetExtender VPN Client, SMA 1000 Series, and SonicWave APs as “Not Affected” and completely fit to continue operations without any actions required from its customers or partners. However, as informed earlier, SonicWall’s flagship product – SMA 100 Series – is still under investigation, and the cybersecurity firm has asked its current SMA 100 customers to continue using NetExtender for remote access with this series.

With several cybersecurity vendors such as FireEye, Microsoft, Crowdstrike, and Malwarebytes being targeted by cyberattacks amid the SolarWinds supply chain hack, the latest breach of SonicWall has again sent tremors across its clients, mainly because if the source code were accessed then the threat actors behind this attack could have searched for vulnerabilities that could be exploited in future. It is also probable that they could have planted various malware, like in the SolarWinds attack, to exploit and move laterally into its clients’ networks. For the time being, we can only hope it is not the same as the SolarWinds hack.

Related News:

Update Before it’s Late: SonicWall VPN Portal Critical Flaw Could Result in DoS Attacks

SolarWinds Hack Affected Yet Another Tech Giant – Microsoft

ShinyHunters Strikes Again! Data of 2.28 Mn “MeetMindful” Users Leaked

BlackMatter ransomware

Members of the popular dating site MeetMindful encountered bitter news over the weekend after the cybercriminals group ShinyHunters leaked private data of more than 2.28 million of the site’s registered users. According to a report, the hacker group shared a file (1.2 GB in size) for free download on the darknet marketplace, where breached databases are traded. It was found that hackers posted an advertisement with a sample of data on the dark web as proof of compromise.

The leaked file included massive sensitive user information such as names, email addresses, birth dates, city, state, ZIP codes, dating preferences, marital status, IP addresses, Bcrypt-hashed account passwords, Facebook user IDs, and Facebook authentication tokens. However, the private messages between the users were not exposed in the incident.

The Breach Impact

The exposure of sensitive data may bring severe consequences to the MeetMindful account holders. The data dump is freely available on the darknet, and cybercriminals can easily misuse the dating profiles for personal gains. Attackers can also compromise users’ accounts by committing spear-phishing or credential-stuffing attacks on users whose data has been exposed in the incident. It is suspected that the leaked file has been viewed more than 1,500 times and likely downloaded several times.

ShinyHunters vs. Data Leaks

Recently, the operators of ShinyHunters traded databases of three India-based enterprises – ClickIndia, ChqBook, and WedMeGood – on Darknet forums. The data dump contained over 8 million records of ClickIndia (name, email, mobile and other personal details), 1 million records of ChqBook (name, email, mobile, full address, and other personal details), and 1.3 million from WedMeGood (name, email, hashed password, other sensitive personal information).

How Data Protection Can Replace Network Protection in the WFH Era

Experian API Flaw

Before the COVID-19 crisis, remote work was considered a luxury option for a relatively lucky few workers in select industries such as technology companies and startups.

Oftentimes, there was even a stigma associated with working from home.

Now, that stigma has totally disappeared.

By Stephen Wright, President, CEO – Wright Business Technologies

Remote work has become a key strategy for businesses to protect their employees’ health and safety while still participating in the larger economy.

However, the mass shift to remote working has exposed many companies to a new generation of organized cybercrime and sophisticated hacking operations.

With so many employees remotely connecting to and accessing valuable company data, including sensitive consumer information and financial records, cybercriminals now have manifold more potential vectors (employees themselves) through which to compromise vulnerable systems.

Increased Reliance On Remote Workforce Leads to More Attacks

The portion of the U.S. workforce pivoting to a remote work arrangement is staggering.

According to Gallup, the percentage of full-time employees working remotely increased to 61% from 33% through the second half of March.

Working remotely is the new norm for many service sector workers, and it’s likely a trend that is not going away even when the COVID-19 pandemic subsides.

Companies such as Microsoft and Facebook have already announced that many of their employees will be working from home indefinitely. Microsoft is even letting employees relocate to other parts of the country.

This sudden shift from working on-site to working from home also means companies and organizations are struggling to strike a balance in providing flexibility for their employees while maintaining information security.

The hard truth is that an employee’s home office will likely not be as secure as a closely-monitored and regularly audited office environment. Even companies that utilized Managed IT Services will not set up and monitor every worker’s individual home office setup.

This struggle is real and can be evidenced by the dramatic increase in cybersecurity threats. According to a Malwarebytes Lab report Enduring from Home: COVID-19’s Impact on Business Security, the data shows that 20% of respondents faced a security breach due to their remote workforce. The results from the Global Threat Report from VMware Carbon Black is also shocking – 91% of over 3,000 globally surveyed companies had seen an increase in overall cyberattacks due to employees working remotely due to COVID-19.

How do companies deal with this massive uptick in cyberattacks and breaches in a work-from-home era?

Most companies are cash-strapped, so the question becomes, how do we prioritize limited resources to best secure and protect critical data?

The following discussion distinguishes between two schools of thought – directing your resources towards protecting a company’s network vs. directing your resources towards directly protecting your company’s data.

Protect the Perimeter: The Old School Approach

Network protection, also known as perimeter security, protects network traffic by controlling incoming and outgoing connections.

The theory is that if hackers and malware are prevented from entering and spreading through a network, the network assets are protected and secured.

This is done using a combination of tools such as firewalls, scanning, patching, the use of virtual private networks (VPNs), and access management to secure the boundaries of a company’s private network from the rest of the Internet, apart from key applications that reside outside of a company’s private network.

This approach is suitable when there are clear physical and digital boundaries. It is equivalent to putting up a fence to secure the perimeters and placing guards at the entrances. But that is not the world anymore. Boundaries are no longer static and manageable.

The following are some of the reasons why the perimeter is vanishing:

  • Entry points are no longer finite. Data traffic can bypass perimeter security and flow directly from devices to applications on the cloud.
  • Employees can log-on from anywhere. To collaborate and work productively, employees not only access a company’s internal network, but also access applications on the cloud.
  • Work is done across an expanded set of devices, from company-issued laptops to personal laptops, mobile phones, and tablets. Devices are at risk of being comprised off-site and then brought onsite when they connect to an organization’s internal network, where infections can spread.

Protect the Data: The New Approach

Let’s now distinguish data protection from network protection.

Data protection adopts a zero-trust approach, which means no one should be trusted, even users inside or within a secured network. Credentials can be hacked, and cybercriminals can virtually tailgate authorized users to bypass network security and then move laterally within to wreak havoc.

With a data protection paradigm, protection starts by securing the data itself, first. Even if the network or perimeter is breached, cybercriminals would have limited access to the data. On the other hand, the network approach focuses resources on protecting the perimeter first and leaving valuable data open to attack.

The data protection approach recognizes that data itself is the ultimate asset and the organization’s heartbeat. When cybercriminals make a move to attack or infiltrate your business, their ultimate target is your company’s data. Therefore, it stands to reason that instead of protecting the devices and the networks that contain the data, the best approach is to protect the data itself no matter where the data resides.

The following are four guiding principles to a data-centric approach:

  • Data discovery and classification
    There must be measures first to identify personal identifiable information (PII) and other sensitive and/or critical information as it is stored, accessed, and used across your company. Companies often overlook this principle because while it is the first logical step, it is more difficult than it seems. Companies must be able to sort through a vast volume of data and identify what needs to be secured.
  • Data transformation
    Once data is discovered and classified, critical data should be masked or anonymized using encryption, redaction, or other techniques to prevent exposing its contents. Encryption is the most effective way to protect critical data against theft and breaches by transforming data into an unreadable form (ciphertext). Only users with the right credentials can decrypt it and then transform it back to something comprehensive (plaintext). Complex mathematical algorithms are used to scramble the data, whether it is stored or being transmitted across a network.
  • Identity and Access Management
    Only the right people should have access to the right information at the right time and for the right reasons. This means trusting no one and improving authentication. One of the simplest and most effective ways to achieve access authentication is to use multifactor authentication. But verifying identity is not effective without assigning roles to users and grant specific access permissions. Always follow the principle of giving the fewest people access to data and information (i.e., least privilege access). By limiting users’ access, you reduce the likelihood of cyber attackers gaining access to large volumes of data with a single comprised account.
  • Monitoring and logging
    Analytics must be in place 24/7, so you can tell the difference between a normal login and suspicious logins or behaviors. Once suspicious traffic or behavior is detected, procedures must be put in place to suspend access privileges quickly and investigate the incident. This sort of automated analytics is not your basic security technique and can be difficult to achieve — but detecting anomalies in real-time is a key component in your defense strategy.

A Case Study

Recently, a Russian hacking group known as Evil Corp. launched ransomware attacks against 31 major U.S. companies by targeting employees working remotely due to COVID-19.

Evil Corp. leveraged remote workers by deploying sophisticated malware on common websites (e.g., news sites or blogs) that employees visited on a device they also use for work.

The malware infected the device, and as soon as the remote employee connected to their company’s network via VPN, the malware released a ransomware program that locked the company’s systems and data to extract a ransom payment.

Using this real-life example, let’s see how the consequences may differ depending on which approach is taken.

Network Protection Approach

  • A company with this approach would have directed its resources to patrol its network perimeter. Thus, it is ill-equipped once the malware bypasses the perimeter by tailgating an authorized user’s connection to a VPN.
  • The company would end up coughing up between $500,000 to a million dollars to access their own data and systems.
  • The damage would not only be limited to financial loss, but it would also impact productivity, revenues, and brand credibility.

Data Protection Approach

  • A company with this approach would know to encrypt their critical and sensitive data, so even if the malware gained access, it would not understand the data and release it to unintended parties (e.g., to the public).
  • Resources may also be spent on monitoring technology that can block suspicious applications from gaining access to data or block ransomware from encrypting data and systems.
  • Even if the malware successfully locks up a company’s systems and data, a company with a data-centric focus would have contingency plans such as backups in an off-site location. With backups, the company could easily restore critical data and systems with minimal recovery time.

A data-centric approach may not prevent ransomware attacks. Still, companies can maintain control of their data without the financial loss of paying the ransom and suffer any other detrimental consequences.

The Perfect Time to Protect What Really Matters

The difference between network protection and data protection is not the technology or tools per se. The difference is acknowledging that data is what really matters. That realization will help direct your finite resources to protect data first and then build layers of additional network security.

With malicious actors taking advantage of the work-from-home era to launch sophisticated cyberattacks, the old school approach of focusing on network and perimeter security is no longer sufficient, just like castles and moats are strategies of the past.

This is the perfect time to shift focus from protecting networks to protecting the data itself. After all, losing data is not just an IT matter; it is a business matter.


About the Author

Stephen WrightStephen Wright is the founder and CEO of Wright Business Technologies. He is responsible for the overall success of the company, clients, employees, and vendor partners who support the business. Stephen graduated from Texas Tech University with a degree in business management and established Wright Business Technologies in 1992. He later earned his MBA, also from Texas Tech University, and established Wright Business Technologies in 1992. He later earned his MBA, also from Texas Tech University.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Market Trends Report on Endpoint Security – 2020

CISO MAG Market Trends Report on Endpoint Security - 2020, endpoint security market trends, endpoint security 2020, endpoint security, endpoint security report,

With organizations going remote in the year 2020 thousands of desktops, workstations, laptops, mobile phones, tablets, access points, printers, IP-cams, USB devices, cloud VMs, and virtual desktops, which previously acted as personal devices and machines, suddenly became Endpoints of the corporate world. Thus, the need for endpoint security became of paramount importance, now more than ever.

The global endpoint security market is projected to reach $30.83 billion by 2027, growing at a CAGR of 8.68% from 2020 to 2027.

CISO MAG Market Trends Report on Endpoint Security - 2020, endpoint security market trends, endpoint security 2020, endpoint security, endpoint security report,

A key trend from an earlier study by CISO MAG pointed that endpoint protection is now moving to the cloud, with SaaS-based services for monitoring endpoints.

The demand for endpoint security services also increased as cloud security improved. The report concluded that organizations are increasingly adopting advanced endpoint security solutions to counter the increased sophistication and volume of threats to endpoints.

To get a better understanding of the current trends, CISO MAG conducted a Market Trends Survey on Endpoint Security in December 2020. This survey has been formulated into a Market Trends Report and offers an in-depth analysis of the global market trends in Endpoint Security along with qualitative and quantitative analysis, history, and estimated projections about the market size and share during the forecast period.


CISO MAG Market Trends Report on Endpoint Security - 2020, endpoint security market trends, endpoint security 2020, endpoint security, endpoint security report,