Home Blog Page 136

From Data Leak to Dark Web: What Happens to Your Stolen Credit Card Data?

From Data Breach to Darknet

There might be various cybercriminal activities operating online, but stealing users’ sensitive information and peddling it on darknet markets is the primary activity for most threat actors. Cybercriminals focus more on pilfering financial data like credit and debit card details, bank account numbers, and login credentials. A recent survey revealed that the rate of cyberattacks in the financial industry increased exponentially. Nearly, 65% of major financial services organizations have suffered a cyberattack in the last 12 months.

This article explains how attackers obtain financial data, what happens to stolen data, and how do criminals sell stolen credit card details on the dark web.

By Rudra Srinivas, Feature Writer, CISO MAG

 How do Attackers Obtain Financial Data?

Usually, threat actors obtain credit card or payment information in two ways: after a data breach and/or via the e-skimming technique. Scammers pilfer sensitive data by exploiting a vulnerability/unsecured database containing valuable data. For instance, consider the Capital One data breach. Attackers exploited a specific configuration vulnerability in its digital infrastructure and allegedly accessed the data of over 100 million individuals in the U.S. and approximately six million in Canada.

In an e-skimming attack, also known as Web-skimming or Magecart attack, adversaries inject malicious JavaScript code into website payment processing pages to steal payment card details from customers. The malicious code then collects the payment info from users while making purchases on the infected site. Recently, Magecart operators compromised over 2,000 Magento online stores and stole tens of thousands of customers’ personal information. They injected malicious code on the website checkout pages to exfiltrate payment information.

What Happens to the Stolen Data?

Ever wondered where your stolen financial data is moved? Well, it is mostly misused by attackers for their criminal activities or it ends up on the dark web for sale. Cybercriminals often use the stolen financial data to make fraudulent purchases online or to compromise other accounts via credential stuffing attacks. Most scammers obtain credit card numbers and other financial data from various darknet forums.

An investigation from security research firm Cyble disclosed that threat actors kept details of 80,000 credit cards on the darknet forum for sale in exchange for cryptocurrency. It was found that the stolen credit card details include both Visa and MasterCard users from various countries, including 33,000 credit card details from the U.S.; 14,000 from France; 5,000 from the U.K.; 2,000 from Canada; 1,200 from Singapore; and 1,300 from India. The exposed information included cardholder name, CVV code, billing details, and expiration date, which were selling at $5 per card, paid in cryptocurrency.

How do Criminals Sell Stolen Credit Card Details on the Dark Web?

Cybercriminals trade their illicitly acquired data on various dark web/hacking forums by advertising or leaking a sample of the data to lure other malicious actors in the community. Recently, adversaries illicitly obtained over three million customers’ credit card information after compromising Dickey’s BBQ Pit Point-of-Sale (POS) systems in 156 restaurant locations. Attackers posted the stolen data for sale on Joker’s Stash, a dark web marketplace that exclusively trades stolen card data. The hackers’ group advertised a massive collection of payment card details for sale, dubbed “BLAZINGSUN,” at $17 per card.

Dark Web – The Hackers’ Paradise

From gamers’ cheat codes to users’ login credentials, everything is traded on darknet markets.  Several new cybersecurity scams and malicious activities originate from these underground forums. Threat actors discuss and share knowledge on new hacking techniques and tools. Some senior threat groups even provide tutorials and share their attacking procedures to the budding hackers.

What’s the Worth of Your Stolen Data?

The stolen information is usually sold in exchange for Bitcoins. In some cases, cybercriminals leak the data they obtain on the dark web for free to threaten the victims in case they don’t receive the demanded ransom.

According to a recent investigation from Privacy Affairs, stolen users’ personal information like credit card details, online banking credentials, and social media logins are put up for sale on several darknet forums at low prices. Forged documents including passports, driving licenses, and auto-insurance cards are also available on these platforms. While online banking credentials cost an average of $35 on the dark web, credit card details including associated data are available for $12 to $20, respectively. Forged or counterfeit documents can be obtained for $1,500.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

 

 

Barracuda Alerts APAC Holiday Shoppers of Possible Bot Attacks

bot attack, Google recaptcha bypass

Christmas is around the corner and the festivities have just begun. In a year that was rather dull and marred with the COVID-19 pandemic, this season brings a breath of fresh air. Market experts believe the festive season is changing public sentiments and people are now spending positively. However, with social distancing and other stricter protocols in place, people are preferring online shopping now, more than ever. But this has its own issues. Enterprise cybersecurity provider, Barracuda, has warned APAC users of a substantial threat arising from bots that can run DDoS attacks while you shop online.

The Bad Bot Attacks

As part of their research activity and continuous analysis, Barracuda’s researchers ran their proprietary Bot Protection solution on a test web application. In just a few days, it detected millions of attacks coming from multiple IP addresses. The researchers said, “Attacks like these are often used to make fraudulent purchases while helping cybercriminals to scan for any vulnerabilities they can exploit.”

Known as the “bad bot personas,” these bots are malicious in nature and are grouped together by User-Agent. The trouble is, that some User-Agents include “good bots”. For example, GoogleBot. GoogleBot crawls sites and adds them to search rankings. It is highly difficult to differentiate between the two without deeper investigation, as bad bots will often spoof good User-Agents.

Another trait that Barracuda researchers observed was that these cybercriminals have “a regular working day.” Usually, bot attacks peak at midnight to avoid the human eye. However, in this case, their activity peaks late in the morning and does not go down until 5 p.m.

Image source: Barracuda

It’s clear that cybercriminals are powering up for the Christmas rush, so with holiday shopping season now in full swing across the region, it’s crucial that e-commerce teams take the appropriate steps to safeguard their applications against bad bots.

 

Mark Lukie, Engineer Manager, Barracuda, APAC

The To-Do for Avoiding Bot Attacks

Researchers suggest that to protect yourself from such attacks, one should install properly configured web application firewalls or WAF-as-a-Service solutions. Additionally, the application security solutions must include anti-bot protection to effectively detect advanced automated attacks. Also, to prevent account takeover attacks, inclusion of credential stuffing protection is mandatory.


CISO MAG, in partnership with Rapid7, is hosting a virtual roundtable on Effective Security Incident Handling on December 15, 2020.
For more information visit: https://cisomag.com/cyber-security-webinars/ Register now!

Beware! Fake COVID-19 Vaccines Circulating on Dark Web

covid-19 vaccine, vaccine

As the world begins preparations to deploy a vaccine for the Coronavirus, law enforcement authorities in the U.K. are warning about imposter vaccine versions distributing across various darknet forums. According to the Europol, the European Union Agency for Law Enforcement Cooperation, counterfeiting pharmaceutical products is increasing on a large scale and is becoming highly lucrative for cybercriminals.

“Organized crime has reacted swiftly to adapt its methods and product offerings to the COVID-19 pandemic. The expected arrival of a genuine COVID-19 vaccine has already inspired criminal activities and will likely be exacerbated once vaccines become available,” Europol said.

Counterfeit Vaccine in Dark Web

Europol stated that certain dark web markets are advertising fake COVID-19 vaccines by imitating genuine pharmaceutical companies. The World Health Organization (WHO) found a fake influenza vaccine in Mexico in October 2020, which was being distributed with a different batch number and expiry dates than the original one.

“The detection of a fake influenza vaccine confirms that criminals seize opportunities as soon as they present themselves. Owing to the pandemic, the demand for the influenza vaccine has been higher than usual and their risks being a shortage. Criminals have reacted quickly by producing counterfeit influenza vaccines. The same scenario is also likely to happen when COVID-19 vaccines do become available,” Europol added.

State-Sponsored Attacks on COVID-19 Vaccine Research

Recently, the U.K.’s National Cyber Security Centre (NCSC), Canada’s Communications Security Establishment (CSE), and the National Security Agency (NSA) of the U.S. stated that a cyber espionage group “APT29,” which is linked to Russian intelligence services, tried to steal information and intellectual property related to the testing and development of Coronavirus vaccines. The group is using its custom malware known as WellMess and WellMail and other techniques to target government entities, diplomats, think-tanks, health care providers, and companies under the energy sector. Read the full story here…

Winter Driving as a Comparison to Ransomware Realities

ransomware, ryuk ransomware, cox media

Driving in winter can be a perilous, high-risk, and minimal risk all at the same time in the colder areas of the world.  And when someone buys a car, often they buy one that is not the best suited or engineered for colder conditions, and yet, such a purchase can be both risky, and not risky at the same time, depending on driver skill (also called the driver mod/modification by enthusiasts).  For example, front-wheel-drive (FWD) cars are notorious for getting stuck in snowbanks or understeering under a variety of conditions, but they are purchased often because they are cheap or more fuel-efficient.

By Ron Brash, Director of Cybersecurity Insights at Verve Industrial Protection

If you drive regularly, then statistically, you may be more likely to wind up in an accident (insurance claims increase by over 49%).  So what are your choices from a preparative standpoint? This article draws analogies between driving safety/risks and ransomware.

  • Have mandatory compensating controls such as quality winter tires for snow and ice
  • Have mandatory car insurance to recover some losses
  • Have secondary measures to reduce the impact of a snowy excursion (candles and an empty tin, matches, blanket, water, snack bars, a flashlight, and an automobile association membership for towing)

And from a driving perspective?

  • Keep the car parked, and drive when conditions are clear
  • Selectively choose and navigate your route while sticking to cleared/sanded roads
  • Drive slower vs. at posted speeds
  • Sell the vehicle

Obviously, if you need the car, you should not be reckless and driving at full speed, but the likelihood of winding up in a snowbank or hitting “black ice” is something most logical decision-makers would acknowledge.  So – selling the car isn’t an option, but being prepared, driving selectively, and not panicking is likely the best-path forward right?  Similarly, it would be nonsensical to sell your business because you cannot terminate the ransomware risks or falsely believe that ransomware will never affect to your organization’s assets & operation.

Unfortunately, ransomware is not seasonal like winter driving, but in the first half of 2020, ransomware accounted for 41% of all cybersecurity insurance claims with no signs of slowing  What are we doing wrong?

Well, most organizations are generally poorly prepared from a governance and/or procedure perspective, but they lack adequate implemented cybersecurity basics.  There are often relevant technology investments present, but they are not being leveraged sufficiently.  There is a purported resources gap of sufficiently minded individuals, and asset owners do not need “experts in everything” – we need largely decent administrators, technicians, and architects

In short, it’s not necessarily a technology problem, but a combination of incomplete operationalizing of current/commodity investments, and an industry focused on selling you “detection and monitoring” vs. tangibly reducing your residual risks & impacts.

The Realities of Ransomware

Imagine having a warning system that alerts if you are about to slide across the ice and hit a wall?  Not really because the value of it is poor (except in aviation where ground avoidance is the primary idea) so – let’s look at the realities of ransomware:

  • Has a high chance of occurring in ANY environment, and accidental insiders are everywhere.
  • Leverages aging or not net-new vulnerabilities more often than not, and unhardened legacy configurations of commodity systems.
  • Small clusters of hosts are easy to manage, widescale outbreaks are hard to manage.
  • Likely does not need a kill chain analysis – it needs containment and recovery ASAP.
  • Cost equation is in the attacker’s favor: (systems affected) * (burn rate + recovery costs).
  • Attackers are usually opportunistic vs. skilled “nation affiliated” (although they exist).
  • Time window for security teams detecting the dropper, isolating systems, and preventing a laterally moving infection is very small (less than an hour).
  • Paying the ransom is generally illegal, but cheaper than recovering.

And all the above assume the organization is consistent, no scheduled disruptions or periods of high-availability, and not having other fires/incidents to put out.  Basically, if you see ransomware, you will end up pulling the “emergency” switch and moving to recovery ASAP (especially so if margins are tight due to 2020 revenue loss).  It’s a whack-a-mole game, but cutting ransomware off at the head, fixing the issue, changing credentials, and getting systems back up and running ASAP is critical.

And in industrial control systems (ICS) or Operational Technology (OT) environments are no different in this respect, but the time between just calling it a day to recover safely is nearly instantaneous.

So, what I am trying to say candidly – is that I’ll probably wind up in a snowbank this winter, and you too will likely have ransomware in the future, but it doesn’t need to be scary or expensive.  Why? Well just like our car analogy – here is a table to compare a few elements:

Car Organization

Insurance assuming several conditions

Insurance IF due diligence was present

Route being traveled

Network architecture & segmentation

Traction control/stabilization

Native OS/product features

Dashboard warning lights

SIEM & alerts

Pre-trip / walkaround

Detailed automatic asset inventory

Winter tires with adequate tread

Perimeter security controls (e.g., firewall)

Assisted driving features

Application whitelisting & policy enforcement

Frequent maintenance

Vulnerability & systems management

Maintenance manual & oil/brake changelog

Policy & Procedures

Road-side survival kit

Secondary lines of communication, call bridges, & incident management infrastructure

Road-side issue handling

Incident isolation & recovery/restoration

Replacement car or reparation strategy

Widescale disaster backup & restoration

Spare tire and jack

Careful removable media management

 

It has been trivialized a bit, but it is an apt comparison.  And just like with automobiles, there are AFFORDABLE/FEASIBLE activities that can be performed to adjust tolerable levels and reduce/prevent catastrophic failures through avid follow up on maintenance (especially for consumables) and prescriptive procedures.  Unfortunately, OT/ICS systems cannot be swapped out like enterprise systems, but OT/ICS systems are often in easily defensible positions easily inventoriable, can leverage much of what is already there, and pragmatic OT-safe solutions that enable action are possible.  Really.

Instead of flailing and wasting efforts, I want to reassure you that developing an adequate response AND recovery strategy for ransomware is possible, and it is more feasible than many leaders believe.  Fancy detection and threat hunting will not help me as the car is sliding forwards, but other compensating controls already in place can prevent a 100km/h calamity and result in a 30 km/h strike.  Let’s start 2021 with the pragmatic application of Protection, Identify & Respond for cybersecurity basics or asset inventory control, and less on Detection-only capabilities; it’s far too easy to raise an alert, but much harder to act upon it.


About the Author

Ron is an experienced technology consultant and seasoned cybersecurity specialist with deep expertise in critical systems, network security, deep packet inspection, data analytics, and secure embedded software development. He leads Verve’s research on vulnerabilities, cyber risk, and reverse engineering network protocols & firmware in OT/critical infrastructure. Ron’s insights and analysis help inform the company’s technology direction and provide valuable guidance in client engagements.  He created the watershed S4 ICS detection challenge datasets, advised in aviation, and is globally recognized as a leading speaker for technical topics.

Verve Industrial Protection is an ICS/OT based cybersecurity company that has been providing & implementing solutions for over 25 years in oil & gas, pharma, energy, utilities, and packaged consumer goods. Verve delivers definitive action vendor agnostically beginning with detailed asset inventory-based technologies & cybersecurity for all types of assets (commodity systems, endpoints, network infrastructure, embedded devices, and control systems).

Disclaimer

CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. Views expressed in this article are personal.

Mikko Hyppönen is CISO MAG Cybersecurity Person of the Year (2020)

Miko Hypponen is CISO MAG Cybersecurity Person of the Year

CISO MAG Cybersecurity Person of the Year recognition honors some of the biggest cybersecurity personalities. These are individuals who have, over the years, been committed to bringing awareness into the realm of cybersecurity – to whom the information security industry is profoundly indebted. The parameters of selection include experience, contribution to industry, spreading cybersecurity awareness, authorship, speaking roles, awards & recognitions, influencer status, and patents.

We are proud to announce that Mikko Hyppönen is the CISO MAG Cybersecurity Person of the Year (2020). The finalists of Cybersecurity Person of the Year (2020) were Kim Zetter, Katie Moussouris, and Robert M. Lee. Apart from that, we have also selected Lisa Ventura as the Infosec Superwoman of the Year (2020) and Theresa Payton as Cybersecurity Crusader of the Year (2020).

Mikko Hyppönen is the Chief Research Officer for F-Secure. He has worked with F-Secure in Finland since 1991. He is known for the Hyppönen Law about IoT security, which states that whenever an appliance is described as “smart,” it is vulnerable.

Hyppönen responded on Twitter by saying:

Hyppönen has led his team through the largest outbreaks in history. His team took down the world-wide network used by the Sobig.F worm. He was the first to warn the world about the Sasser outbreak. He named the infamous Storm Worm and has done classified briefings on the operation of the Stuxnet worm.

Hyppönen has assisted law enforcement in the U.S., Europe, and Asia on cybercrime cases. He has written for magazines such as Scientific American and Foreign Policy, and for newspapers like The New York Times. Hyppönen has addressed the most renowned security-related conferences worldwide. He is also an inventor and holds several patents, including U.S. patent no. 6,577,920 “Computer virus screening.” He has been the subject of dozens of interviews in global TV and print media, including one in Vanity Fair.

So how could we forego an opportunity like this to grab an exclusive one-on-one with the man of the hour. View the video below to see what Hyppönen thinks of cybersecurity in the current digital age and his suggestions for the road ahead:

Born in 1969, Hyppönen was selected among the 50 most important people on the web by the PC World magazine. He also received the Virus Bulletin Award, awarded every ten years, as “Best in industry.”

He has delivered hundreds of talks in over 40 countries over the last 20 years, including keynotes in the most important security conferences. In 2010, he was awarded the Virus Bulletin Award as the best educator in the industry.

Hyppönen has also been credited by Twitter to help improve Twitter’s security.


Our December issue on Endpoint Security is now live. Subscribe now!

 

5G Adoption Comes with Its Own Share of Security Apprehensions: Research

5G, 5G Networks, 5g security

While 5G technology is taking the world by storm with its incredible high speeds and low latency, several organizations have their own set of concerns around the cybersecurity risks related to 5G adoption. A new poll by Deloitte indicates that 76.4% of professionals at organizations that currently use 5G and 80.7% of professionals at organizations that plan to adopt 5G in the year ahead, say that their organizations are apprehensive of 5G cybersecurity.

“The U.S. 5G bandwidth availability has expanded and accelerated considerably in recent months, offering competitive advantages technologically, financially and otherwise to early adopters,” said Wendy Frank, Deloitte Risk & Financial Advisory Cyber 5G leader and principal, Deloitte & Touche LLP, in a release.  “Of course, with all the technological advancement 5G enables, the cyberthreat landscape and attack surface areas expand considerably.  Working proactively to mitigate cybersecurity risks posed by 5G adoption is the hallmark of a well-designed program.”

The key concerns differ for organizations and employees with 5G and without 5G. For professionals who are already using 5G technologies in their companies, the main concern is the talent gap. Nearly 30.1% of professionals felt appropriately skilled security professionals will be needed for implementation, maintenance, and operations in a 5G environment. While for companies that are still in the planning phase for 5G adoption, data is their primary concern (26.8%) followed by data mismanagement risks – and third parties (24.3%).

“For organizations leveraging 5G, cyber risk will mount quickly if challenges — like a lack sophisticated encryption, decentralized operations or security monitoring functioning to the detriment of performance speeds – are not resolved,” Frank said. “Securing the vastly expanded threat landscape resulting from 5G adoption will demand two equally important efforts:  getting the right talent in place or upskilled; and, leveraging artificial intelligence and machine learning to automate areas like security policy configuration, compliance monitoring and threat and vulnerability detection.”

The COVID-19 pandemic also had an impact on the adoption of 5G technology. While 32.2% of organizations currently using 5G increased its adoption speed, 21.8% of those at organizations planning to adopt 5G decreased adoption speed.

“The faster movement of data, the creation of new types of data and the ability to develop countless new IoT devices through 5G networks will disrupt most industries.  But, just as with pandemic disruption, leading programs are working to keep security at the fore of 5G adoption,” Frank concluded.

All in all, the booming 5G tech is gradually shaping up to be the mainstay of digital economies going forward. When there is so much at stake, governments and service providers need to make sure the network deployment is flawless in terms of security. Cybercriminals will undoubtedly look for ways to compromise the emerging communication protocols and thereby orchestrate massive data breaches. The concerns escalate considering the tightening connection between 5G and ubiquitous cloud computing. Read More…

Money Mule Activity Surges Amid Unemployment, FBI Warns

BlackMatter Group, Volvo Cars ransomware attack

The FBI issued a warning about online scammers targeting unemployed youth in the U.S. by recruiting them into their cybercriminal activities. Various threat actor groups are using unwitting users in various money mule schemes to launder their illegal funds.

According to the FBI’s Internet Crime Complaint Center (IC3), money mule-based frauds tripled from $1.1 billion in 2015 to $3.5 billion in 2019. “As these numbers increase, 2020 is offering a new set of challenges including fraudsters preying on those looking to work from home during the COVID-19 pandemic. As many companies are being forced to lay off workers or shut down completely during the pandemic, more work from home job opportunities are being advertised, even on reputable job sites,” the FBI said.

How do Money Mules operate?

A money mule is a person who unknowingly transfers (mostly a victim) illegally obtained money on behalf of cybercriminals using their legit bank accounts. Malicious actors often lure victims via attractive job postings and phishing emails to recruit them as money mules. According to the FBI’s Criminal Investigative Division (CID), jobless individuals are more prone to falling for money mule schemes due to the surge in unemployment resulting from the COVID-19 pandemic.

Performing financial transactions on behalf of cybercriminals will jeopardize your financial security and compromise your personally identifiable information, the FBI warned.

How to know if you’re a victim of a Money Mule Scheme?

  • You receive an unsolicited e-mail or contact over social media promising easy money for little to no effort.
  • The employer you communicate with uses web-based e-mail (such as Gmail, Yahoo, Hotmail, or Outlook).
  • You are asked to open a bank account in your own name, or in the name of a company you form, to receive and transfer money.
  • As an employee, you are asked to receive funds in your bank account and then transfer funds via a wire transfer, mail, or money service business (such as Western Union or MoneyGram).
  • You can keep a portion of the money you transfer.
  • Your duties have no specific job description.
  • Your online companion, whom you have never met in person, asks you to conduct financial transactions that they should reasonably be able to do for themselves, and offers to share the proceeds of that transaction with you.
  • Your online companion is adamant that you keep the relationship and the associated financial transactions secret.

 Preventive Measures

  • Do not respond or click on any suspicious links in the email. Inform your local police or the FBI.
  • If you believe that you are participating in a money mule scheme, stop transferring money immediately and notify your bank, and also the service you used to conduct the transaction, and law enforcement.

21-Year-Old California Cybercriminal Jailed for Nintendo Proprietary Info Theft

Nintendo data breach, data breach

The U.S. District Court in Seattle, on December 1, 2020, sentenced 21-year-old Ryan S. Hernandez aka Ryan West, to three years of imprisonment. The court found Hernandez guilty on two separate counts: one that involved a computer hacking scheme against gaming giant Nintendo and the other of having child pornography videos on the personal devices recovered from his home. Hernandez had pleaded guilty in January 2020 and was awaiting a verdict, which probably got delayed due to the pandemic.

A Repeated Offender

As per the records filed with the DoJ, Hernandez was a repeated offender. In 2016, when he was a minor, Hernandez and one more of his associates ran a phishing campaign against Nintendo’s employees and successfully broke into one of the employees’ official accounts. They then traversed deeper into the network and gained Nintendo’s confidential files and projects. The duo leaked the pre-release information of the anticipated Nintendo Switch Console in the public domain. The FBI tracked Hernandez and warned him and his parents of the consequences if he repeated the act.

However, two years down the line, Hernandez was back to his old ways. Only this time, he hacked into multiple Nintendo servers and stole confidential proprietary information about various popular video games, gaming consoles, and developer tools. The culprit also started an underground chat forum called “Ryan’s Underground Hangout,” in which he discussed Nintendo products and shared information about possible Nintendo network vulnerabilities based on the confidential info in his possession.

The Cat and Mouse Game Ends

Finally, in 2019, the FBI again raided Hernandez’s home as they had conclusive proof of his involvement. This time they confiscated all his devices including computers, hard drives, and others that were used to bypass and download pirated content. While the FBI conducted cyber forensic analysis on his devices, they were looking for data on Nintendo’s files that were stolen and leaked on underground forums.

However, the investigation revealed that Hernandez had a folder named “Bad stuff,” which contained sexually explicit content involving minors. This is a heinous crime in the U.S. Thus, the FBI filed a charge sheet against the offender on two counts.

The Verdict

As said earlier, Hernandez pleaded guilty for the charges pressed, and thus, both prosecutors and defense attorneys recommended three years imprisonment for him, under the terms of the plea agreement. Additionally, Judge Coughenour recommended Hernandez be incarcerated at a Bureau of Prisons facility for inmates with cognitive challenges. Hernandez has also agreed to pay $259,323 in restitution to Nintendo for the remediation costs caused by his conduct.

Episode #5: How Do We Help Small and Medium Businesses with Cybersecurity?

Podcast, Chris Roberts

A survey from the Nationwide Agent Authority, a provider of diversified insurance and financial services, revealed that nearly 50% of cyberattacks are aimed at small businesses, but only 37% of small business owners reported believing they are at risk to fall victim to a cyberattack. About one-third of businesses said they are not confident they could recover if their business was attacked.

In this episode, Brian Pereira, Principal Editor, CISO MAG interviews Chris Roberts, Researcher, Hacker, and CISO, to discuss the impact of cyberattacks on small and medium businesses. Chris offers good advice on what these businesses should do, and what are the questions they should ask when going to security service providers.

Chris possesses a rich experience within the domain of information security and is globally recognized as one of the pioneering wizards on vulnerability research and counter-threat intelligence. He has worked on a multiplicity of projects specializing in intelligence gathering, DarkNet research, deception technologies, and cryptography with several organizations and has been credited by many of the top Information Technology and Security disciplines.

Chris is also on the CISO MAG Writers Board.

Listen to our previous podcast episodes here.


About the Host

Brian PereiraBrian Pereira is the Principal Editor of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

 

U.S. and Australia to Jointly Develop Cyber Training Platform

U.S. and Australia to Jointly Develop Cyber Training Platform

To strengthen cybersecurity practices and boost partnerships in cyberspace, the U.S. and Australia have signed “The Cyber Training Capabilities Project Arrangement,” which allows both nations to jointly develop a virtual cyber training program. The bi-lateral agreement enables the U.S. Cyber Command to incorporate Australian Defense Force feedback into USCYBERCOM’s simulated training domain: the Persistent Cyber Training Environment (PCTE).

The PCTE provides a joint training environment, enabling cyber forces globally to develop and re-use existing content for cybersecurity training. “PCTE continues to showcase training opportunities for our cyber equities, and as we evolve this capability we look forward to the ongoing progression and engagements with our partners. Our recent Cyber Flag events in June and September 2020 were prime examples of Five Eyes partner training and collaboration,” said Rear Adm. Christopher Bartz, Director, USCYBERCOM Exercises and Training.

This is the first agreement related to a cybersecurity project arrangement established between the U.S. and Australian governments. “To counter known and potential adversarial threats, the Army has recalibrated our strategic thinking; we’ve made smart decisions to refocus our efforts to invest in the new, emerging and smart technologies that will strengthen our ability to fight and win our nation’s wars,” said Elizabeth Wilson, the U.S. signatory and Deputy Assistant Secretary of the Army for Defense Exports and Cooperation.

“Australia and the U.S. have a strong history of working together to develop our cyber capabilities and train our people to fight and win in cyberspace. This arrangement will be an important part of the ADF’s training program,” said Australian Army Maj. Gen. Marcus Thompson, the Australian signatory, and head of Information Warfare for the Australian Defense Force.

Australia and U.K. Alliance

Earlier, Australia and the U.K. pledged to intensify the fight against state-sponsored cyberattacks. The announcement was made by British Prime Minister Theresa May and Australian Prime Minister Malcolm Turnbull after both the leaders released an agreement joint declaration by the 53 nations of the Commonwealth on the dangers to civilian and military networks. Read more here…