Home Blog Page 138

Over 8.5 Mn User Records from Free Image Site 123RF.com Leaked

data breach

123RF.com, a royalty-free image website, has notified its users and authorities of a compromised SQL database that contained users’ sensitive data. A report by CyberNews indicated that, unidentified malicious actors leaked a sample file, 3GB in size, on a Russian hacker forum.  The Malaysia-based digital stock content agency stated that the exposed database holds over 8,500,246 user records including users’ full names, email addresses, IP addresses, Facebook Ids, locations, and passwords that have been hashed using the MD5 hashing algorithm.

123RF.com clarified that the exposed sample file appears to be a user data table ranging from as far back as 2006 to March 2020. The company also assumes that the database is about a year old and not the latest 2020 version.

“The latest data contained in the database appears to have been exfiltrated from 123RF.com data center on March 22, 2020, and presumably used for malicious purposes for more than eight months. According to 123RF.com, the source of the breach was traced to an unauthorized access at the company’s data center. After breaching the data center, the attacker “proceeded to copy the membership data,” 123RF.com said in a statement.

What’s the Impact?

Cybercriminals could use the leaked data to launch a variety of cyberattacks against 123RF.com users. Attackers can compromise users’ accounts by committing spear-phishing or credential stuffing attacks on users whose data was exposed in the incident. In addition, scammers can spam the victims’ emails, phones, and Facebook accounts.

What’s Next?

123RF.com recommended the affected users to follow certain security measures for further protection. These include:

  • Immediately change your 123RF.com, PayPal, and Facebook passwords and consider using a password manager to create strong passwords
  • If the user has been using an identical password for any other online services, change it on those other websites as well
  • Enable two-factor authentication (2FA) on all other online accounts
  • Watch out for potential phishing emails and messages. Do not click on anything suspicious or respond to anyone the users do not know

COVID Vaccine Frontrunner AstraZeneca Targeted by Suspected North Korean Threat Actors

AstraZeneca targeted by North Korea

According to Reuters, suspected North Korean threat actors have carried out targeted cyberattacks against COVID vaccine frontrunner, AstraZeneca, by means of phishing links disguised as job offers.

The race to finding a vaccine for the ongoing COVID-19 pandemic is heating up. Many of the probable candidates are on the verge of concluding their third and last round of human trials. Some have already done that with more than 90% efficacy against the virus.

The Frontrunner AstraZeneca

One of the frontrunners in this race is the European candidate AstraZeneca Pharmaceuticals. Since the outburst of the pandemic, all eyes have been on this pharma giant because researchers at Oxford had already partnered with them prior to the pandemic to develop a vaccine on the previously known strain of SARS-CoV-2, the virus that causes COVID-19.

However, in late October, while the company claimed success with its second phase of human trials, it began to worry about another possible attack, but that of a computer malware. According to Reuters, suspected North Korean threat actors began attempting to break into the systems of the pharma giant, and the attacks only intensified by November 2020.

We Have a Job Offer for You!

According to sources, the threat actors disguised themselves as recruiters on social networking site LinkedIn and messaging platform WhatsApp, to approach AstraZeneca staff with fake job offers. These offers consisted of documents and links to malicious codes that downloaded malware that exfiltrated victim’s computers’ credentials and eventually granted access to their machine.

Reuters said that sources who spoke on condition of anonymity said, “the tools and techniques used in the attacks showed they were part of an ongoing hacking campaign that U.S. officials and cybersecurity researchers have attributed to North Korea. The campaign has previously focused on defense companies and media organizations, but pivoted to COVID-related targets in recent weeks.”

North Korea – The Problem Child

Cyberattacks against the health care industry, vaccine researchers, and pharma companies have sky-rocketed during the pandemic to tamper with the research of other countries. However, there is one name that keeps popping up now and then: North Korea. This is not the first time that North Korea has been linked to such cyberattacks. Previously, governments around the globe, including the U.K., the U.S., Russia, and their immediate neighbors South Korea have all been accused of carrying out such activities. The most infamous of the lot was the WannaCry attack on the U.K.’s National Health Service (NHS) in 2017, which led to grievous temporary damage to the network security of the NHS.

Related News:

North Korea behind ‘WannaCry’ NHS cyberattack: UK

North Korea hacked Daewoo Shipbuilding, took warship blueprints: South Korea lawmaker

How to Detect Weak Passwords Using Google Chrome

User Verification Policy, zero trust approach

Your online security is highly dependent on your password habits. Using a strong password or passphrase will provide maximum security to your network and the devices you use. To prevent users from using weak passwords, Google Chrome has introduced a new safety check feature that will warn the users if their passwords are not strong enough. The upcoming feature automatically detects and reports weak passwords by performing a safety check scan.

How to Enable the New Password Check Feature?

While the new password safety check functionality is not yet available, Google says users can enable it in Chrome Canary.

Here’s how to do it:

Install Chrome Canary >> Enter Chrome://flags in the address bar and press enter >> Enable the “Safety check for weak passwords” and “Passwords weakness check” features.

To check the weak passwords, go to Settings >> Safety Check >> click on the Check Now option. Google Chrome will automatically scan your saved passwords and highlight the weaker ones. Users can change their weak passwords with the “Review” option.

Earlier, Chrome’s safety check issued warnings about potentially malicious extensions and passwords leaked in a data breach. With the latest update, the safety check feature becomes even more secure.

Related Story: 6 Practices to Strengthen Your Password Hygiene

Avoid Reusing Passwords

A recent study by the Microsoft threat research team revealed that 44 million users were reusing their usernames and passwords. The survey exposed that the largest percentage of passwords were weak and used for a long period. Using a common password for various accounts might seem convenient, but it could be a potential threat for other accounts if an attacker broke into one account. Even if you have a strong password, try to use different passwords for every account you use. Also, make sure that you change your passwords regularly. Read the full story here…

BEC Scammers Exploit Email Auto-Forwarding Rules, FBI warns

BEC Scammers Exploit Email Auto-Forwarding Rules, FBI warns

The FBI is warning organizations in the U.S. about the risks posed by email auto-forwarding rules. According to a Private Industry Notification (PIN) from the FBI’s Cyber Division, threat actors are exploiting auto-forwarding rules on victims’ web-based email accounts for launching business email compromise (BEC) attacks. The agency stated that the sudden shift to remote working increased the risk of email scams.

“The FBI is sharing this information to inform companies of this email rule forwarding vulnerability, which may leave businesses more susceptible to BEC,” the notification stated.

What are BEC Attacks?

In a BEC attack, cybercriminals first steal legitimate business email account credentials, which are later used to launch financial fraud campaigns like fraudulent email messages, requests for out-of-channel funds transfers, and deleted accounting trails. BEC actors create auto-forwarding rules within email accounts after they obtain employee credentials to decrease the victims’ ability to observe fraudulent communications.

How to Mitigate BEC Attacks?

The FBI recommended certain security measures to defend the evolving BEC attacks. These include:

  • Ensure both the desktop and web applications are running the same version to allow appropriate syncing and updates.
  • Be wary of the last-minute changes in established email account addresses.
  • Carefully check the email addresses for slight changes that can make fraudulent addresses appear legitimate and resemble actual clients’ names.
  • Enable multi-factor authentication for all email accounts.
  • Prohibit automatic forwarding of email to external addresses.
  • Frequently monitor the Email Exchange server for changes in configuration and custom rules for specific accounts.
  • Create a rule to flag email communications where the “reply” email address differs from the “from” email address.
  • Add an email banner to messages coming from outside your organization.
  • Consider the necessity of legacy email protocols, such as POP, IMAP, and SMTP, that can be used to circumvent multi-factor authentication.
  • Ensure changes to mailbox login and settings are logged and retained for at least 90 days.
  • Enable security features that block malicious emails, such as anti-phishing and anti-spoofing policies.

The FBI also highlighted that BEC scams reported more than $1.7 billion in worldwide losses in 2019. The agency urged users to report information concerning suspicious or criminal activity to their FBI’s 24/7 CyberWatch.

When your CSP has an outage, what does it mean for your SOC 2?

Misconfigured Cloud Storage Services Led to Over 200 Breaches in Past Two Years

Last Wednesday (November 25), as people across the world began preparing for a very different 2020 Thanksgiving, a large part of the internet experienced an outage. Amazon Web Services (AWS) announced early Wednesday morning that several of their key services were impaired causing API errors and other issues, including AWS’s ability to update their own status page.

By Jeff Cook, Co-Founder & CFO at ByteChek and AJ Yawn, Co-Founder and CEO at ByteChek

This type of outage may have an impact on your SOC 2 when you use CSPs such as AWS as your infrastructure provider.  In your SOC 2, it all comes down to your commitments and system requirements regarding service delivery to your customers.

What happened?

AWS is the market leader in cloud computing services and this outage demonstrated how many well-known companies were impacted, including Tampa Bay Times, The Philadelphia Inquirer, ByteChek, Glassdoor, Coinbase, and Adobe Spark. The issue appeared to be focused solely on the US-East-1 region and AWS informed The Verge that the issue was only impacting one of the 23 geographic regions.

Fortunately, the issue was resolved within 24 hours and all impacted companies appear to be operating normally. The root cause of the issue was outlined in detail by AWS here. Many CISOs and other executives of the organizations who relied on Amazon’s US-East-1 region are re-evaluating their business continuity and disaster recovery strategies in the cloud. One could argue that this incident makes the case for multi-cloud, or at least a multi-region deployment, but those decisions should be made based on the unique needs of each organization. Something that all CISOs and other executives should be aware of is the impact of this outage on their own SOC 2 reports.

AWS (or similar CSP) and your SOC 2

If you’re hosted on AWS, they very likely are listed in your SOC 2 report as a subservice organization. Hopefully, this doesn’t come as a surprise. The AICPA defines a subservice organization as “a vendor used by a service organization that performs controls that are necessary, in combination with controls at the service organization, to provide reasonable assurance that the service organization’s service commitments and system requirements were achieved.”

In non-accountant language, this means that AWS or any other subservice organization is a critical part of your control environment. Since AWS is a part of your control environment, for SOC 2 this most likely means that they impact the commitments you make to your customers regarding the security and availability of your system or application.

According to Description Criteria 7 Complimentary Subservice Organization Controls (CSOCs) for your system description (section 3), you have to disclose your subservice organization(s) and the criteria they help you meet.  In our example, you would have AWS helping you meet criterion A1.2 by providing controls relevant to backup, recovery, and redundancy.  Think of the cloud provider shared responsibility model. The providers are responsible for the physical security and environmental security of the cloud. If they fail to meet those requirements, you fail to meet criteria in your SOC 2 report associated with physical and environmental security controls.

In the SOC 2 guide, it discusses how if there are CSOCs, your CPA will have to perform procedures to determine if you found any deficiencies in the suitability of design or operating effectiveness of controls at AWS. The CPA will also have to review the AWS SOC report to determine if they agree with your evaluation.

If it is determined that the effect of the outage did not result in you failing to achieve one or more of your service commitments and system requirements, and the CPA agrees with that evaluation, it would not be necessary to modify your SOC 2 opinion on the suitability of design or the operating effectiveness (type 2) of controls because of the effect of the outage.

However, if you believe, and your CPA agrees, that the effect of the outage at AWS resulted in you failing to achieve one or more of your commitments and system requirements, modification of your SOC 2 assertion and the CPA opinion may be necessary (likely a qualified opinion). In that case, the service auditor would include an explanatory paragraph in the SOC 2 report to describe the outage at AWS and its effects on your failure to achieve one or more of your commitments and system requirements.

This incident’s impact on your SOC 2

Keep in mind that every scenario needs to be evaluated on an individual basis, and these types of situations are not always clear as to their effect on your report.  You should always discuss these situations with your CPA or trusted advisor to determine how you are impacted by your subservice organization(s), their responsibilities, and their performance.

Back to this specific outage, let’s say you commit in your SLA that you will deliver 99.99% service availability in any given month to your customers.

Scenario 1:

Since AWS was able to resolve the issue in a timely manner, it’s fair to assume that they have still met their availability commitments in the aggregate with no modifications to their SOC 2 opinion. In that case, you would review their SOC 2 Type 2 report that includes this period of time with the outage.  In your review, you determine that the outage did not materially affect availability, and you still met your commitment to 99.99% uptime. The CPA evaluates your review, looks at the AWS SOC 2 report and agrees with your determination.  No modification of your SOC 2 report is needed.

Scenario 2:

Now, let’s hypothetically determine that this outage did last for a significant amount of time which resulted in AWS not meeting their availability commitments (qualifying their SOC 2). Because of this AWS outage, your service availability for November dipped to 96%.

Due to AWS’s deficiency in their controls to deliver backup and recovery, and they’re being an integral part of your control environment (as a subservice organization) you have determined that you, in turn, have failed to meet your availability commitments to customers. This would potentially cause your SOC 2 opinion to be modified (qualified) with an explanatory paragraph stating the modification is due to failures at AWS.

What about DC4 (system incidents)

In the system description, DC4 discusses incidents and their effect on causing you to not meet your commitments and system requirements.  Similar to what we talked about above, if an incident causes the failure to meet commitments and system requirements, then you would disclose it in DC4 even if it came from the subservice organization.

We usually say a good rule of thumb (not official by any means) is if the organization sent out a press release, mass email, or something else to discuss an incident, then it likely would need disclosure.  With the AWS outage last week, they sent out emails and it was widely publicized, so likely that will require disclosure, even if it doesn’t modify the SOC 2 report.

Conclusion

The lessons learned from this outage will continue to develop as we learn more information and assess internal practices and processes. One lesson that you should immediately consider is how these outages from major cloud service providers impact your compliance efforts, specifically SOC 2 examinations. Security leaders must understand the long-term impacts beyond uptime and downtime of any incident and ensure all levels of management are aware of what this means to the organization.


About the Authors

Jeff Cook brings his information assurance and public accounting experience to ByteChek as a professional with over 9 years of IT audit and consulting experience and over 20 years of experience in public accounting and auditing. Jeff has worked extensively on SOC in addition to providing IT audit support for traditional financial statement audits. Jeff also has a functional knowledge of ISO standards, CSA STAR, C5, FISMA, and FedRAMP.

Jeff is also heavily involved with the AICPA, volunteering with the development of the SOC and CITP programs. Jeff was part of the SOC 2 working group, helping to develop the 2018 version of the AICPA SOC 2 guide, has developed numerous trainings for the AICPA, and is a prior recipient of the AICPA IMTA Standing Ovation Award for outstanding professional achievement in the IT specialization area.

Jeff is a part of the AICPA CITP credential committee, the AICPA IMTA SOC task force, and the AICPA Eye on Technology task force. Jeff is also a Board Member for Community IT, a Washington, DC-based managed service provider for non-profits. Jeff is a prior board member for the Maryland Association of CPAs.

AJ Yawn, Cloud securityAJ Yawn is the Co-Founder and CEO of ByteChek. He is a seasoned cloud security professional that possesses over a decade of senior information security experience with extensive experience managing a wide range of cybersecurity compliance assessments (SOC 2, ISO 27001, HIPAA, etc.) for a variety of SaaS, IaaS, and PaaS providers.

AJ advises startups on cloud security and serves on the Board of Directors of the ISC2 Miami chapter as the Education Chair, he is also a Founding Board member of the National Association of Black Compliance and Risk Management professions, regularly speaks on information security podcasts, events, and he contributes blogs and articles to the information security community including publications such as CISOMag, InfosecMag, HackerNoon, and ISC2.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Watch Out for These Three Cyberthreats in 2021

Avaddon ransomware, Microsoft and Fortinet flaws, apt

The unexpected crisis in 2020 impacted almost every business globally. The turmoil resulted in several changes in the traditional business operation models. Even cybercriminals changed their attack vectors with innovative hacking tools and techniques. Threat actors launched creative social engineering scams and phishing attacks by leveraging the fear surrounding the COVID-19 pandemic.

By Rudra Srinivas, Feature Writer, CISO MAG

Many organizations experienced security incidents in 2020. Here is a glimpse of threat areas that could change in the year ahead and become troublesome for businesses in the coming years.

1. Weaponized AI/ML for Advanced Cyberattacks

With Artificial Intelligence (AI) and Machine Learning (ML) becoming more prevalent in organizations, cybercriminals are also considering advanced AI tools to launch sophisticated cyberattacks. Threat actors often misuse advanced technologies to create new kinds of malicious operations. According to a research from the United Nations Interregional Crime and Justice Research Institute (UNICRI), Europol, and cybersecurity firm Trend Micro, cybercriminals are rampantly leveraging AI to spread a wide range of digital threats for ill purposes.  It is said that AI systems are being developed to enhance the effectiveness of malware and disrupt anti-malware and facial recognition systems.

2. Evolving Social Media Attacks

Threat actors are not limiting their social media-based attacks just for the sake of user credentials. Compromised social media accounts are used to tamper with elections, disinformation campaigns, and to spread fake news. Social media attacks could become more prevalent in 2021 if users continue their poor authentication practices. According to a report, nearly 48% of the U.K.’s CEOs deleted their social media accounts and erased their personal information online. It is also found that four-in-five CEOs (around 80%) have changed their online behavior fearing cyber risks.

3. Illicit Trading of Human Identities

Cybercriminals are known to pilfer users’ personal data and trade it on various hacking forums. According to an investigation, stolen users’ personal information like credit card details, online banking credentials, social media logins, and malware codes are put up for sale on several darknet forums at really low prices ranging from $12 and $70.

A Silver Lining

As cyberthreats emerge, so does our collective responsibility to safeguard the digital space.  To alleviate disastrous losses, most organizations across the globe are looking forward to enhancing their security measures to build malware defense mechanisms. After the pandemic forced businesses to go virtual, it became a challenge for organizations to protect their distributed work environment.

Recently, a security research highlighted that COVID-19 boosted security investments in the industry. Amid growing cybersecurity risks during the pandemic and the fear of compliance audit failure, most of the CISOs stated that boards are in plan to step up their cybersecurity budgets. Nearly, 90% of organizations are increasing their digital transformation budgets amid the pandemic.

At a time when every organization is thinking of improved cybersecurity, we wish the coming year witnesses even stronger security standards, making it near difficult for cybercriminals to survive.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

 

Apodis Pharma Exposes Over 1.7 TB of Confidential Company Data

data leak

French healthcare software company, Apodis Pharma, was notified by researchers at CyberNews about a possible data leak. CyberNews researchers discovered a misconfigured and unencrypted ElasticSearch database on October 22, 2020, which contained 1.7TB of Apodis Pharma’s confidential business data including information of their partners, business, and employee accounts, and some unsuspected patients’ information.

As per standard reporting procedure, the researchers promptly reported their findings to the company but did not get any response. Taking into consideration the gravity of the leak, the researchers then reported their findings to CERT France but even their efforts of reaching out failed. Eventually, CyberNews researchers established direct communication with Apodis Pharma’s CTO, Mathieu Bolard, who got the issue fixed instantly.

Related News:

Unprotected Elasticsearch Server Leaks 5 Billion Records

The researchers said they are not sure who accessed the database, “however, the database has already been indexed on at least one popular IoT search engine, which means that there is almost no doubt that the data has been accessed and possibly downloaded by outside parties for potentially malicious purposes.”

According to CyberNews, the Apodis Pharma database possibly leaked the following set of information:

  • Archived confidential pharmaceutical shipment data, shipment storage status, the precise time and locations of the shipments, and the quantity of pharmaceuticals in the shipments.
  • An archive of Apodis Pharma’s 25,000+ partner and client organizations, such as pharmaceutical laboratories and pharmacies.
  • Two archives of products stored in Apodis Pharma client warehouses, containing 17,324,382 entries and 32,960,114 entries each. It included product data like product quantities and IDs, as well as warehouse data.
  • Confidential product sales data containing 17,556,928 quarterly entries that include information such as sales dates, locations, prices, and quantities sold between pharmaceutical laboratories and pharmacies.
  • User data containing 4,436 entries, including full names of Apodis Pharma clients, partners, and employees.
  • Consumer and client data visualizations and analytics, including consumer gender statistics, and presumably, confidential client sales and warehouse stocks charts.

Experts suggest that at the very least, an ElasticSearch or any other database for that matter, hosted on any server with an IP address should have a strong and unique username and password. This is a basic yet often neglected technique of defense.

Related News:

Elasticsearch Database Leaks 100 GB Data of Peekaboo Moments App

GO SMS Pro Android App Still Vulnerable to Data Exposure

GO SMS Pro Android App Still Vulnerable to Data Exposure

Security researchers are warning users about a critical vulnerability in Android’s GO SMS Pro mobile application that has more than 100 million installs on the Play Store. According to Trustwave researchers, the instant messaging app is exposing the images, videos, and privately shared messages of millions of GO SMS Pro users. If exploited, the flaw could allow cybercriminals to obtain unrestricted access to users’ personal data.

“Any sensitive media shared between users of this messenger app is at risk of being compromised by an unauthenticated attacker or curious user,” Trustwave researchers said.

Vulnerability Disclosure

The vulnerability affects GO SMS Pro v7.91 versions. “It is unclear which other versions are affected but we believe this is likely to affect previous and potentially future versions as well,” the researchers added. Like all messenger apps, the GO SMS Pro app, allows users to send private text and media to other users. If the recipient does not have the app, the text/media file is delivered as a URL via SMS. The user is required to click on the link to view the files via a browser.

It is found that the link can be accessed without any authentication, allowing any user with the link to view the content. It is also suspected that a malicious user can abuse this procedure to access any text/media files sent via this process.

A new version of the app was introduced on the Play Store after Trustwave researchers notified the users about their vulnerability discovery. The researchers stated the new version of the app did not fix the issue.

“It seems like GOMO is attempting to fix the issue, but a complete fix is still not available in the app. For v7.93, it appears that they disabled the ability to send media files completely. In v7.94, they are not blocking the ability to upload media in the app, but the media does not appear to go anywhere. So, it appears they are in the process of trying to fix the root problem,” the researchers concluded.

CISA Alerts About Path Traversal Vulnerability in Fortinet VPNs

Fortinet VPNs Vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) is warning users about the potential password leaks on Fortinet devices. In an official notification, the agency stated that certain Fortinet VPN devices, located in the U.S., are vulnerable to a CVE 2018-13379 flaw. If exploited, the vulnerability could allow an attacker to illicitly access FortiOS system files.

Affected Products:

  • FortiOS 6.0 – 6.0.0 to 6.0.4
  • FortiOS 5.6 – 5.6.3 to 5.6.7
  • FortiOS 5.4 – 5.4.6 to 5.4.12

Fortinet also confirmed the vulnerability in a security advisory stating, “A path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource. If users fail to upgrade to the versions listed above, they can still mitigate it by enabling two-factor authentication for SSL VPN users. An attacker would then not be able to use stolen credentials to impersonate SSL VPN users.”

CISA has urged users and administrators to apply the necessary updates – FortiOS 5.4.13, 5.6.8, 6.0.5 or 6.2.0 immediately, to avoid potential online intrusions. It also recommended Fortinet users to conduct a review of logs on any connected networks to find any additional threat actor activity.

Update Before it’s Late

Recently, security researchers found a stack-based buffer overflow flaw in SonicWall Network Security Appliance (NSA) which could affect nearly 800,000 SonicWall VPNs across the globe, if left patched. According to the researcher Craig Young from Tripwire VERT, the vulnerability CVE-2020-5135 can be exploited by an unauthenticated HTTP request involving a custom protocol handler. The issue exists in the HTTP/HTTPS service, which is used for product management and for SSL VPN remote access. Read the full story here…

Defend Your Data with a Sense of Sertainty

Sertainty self protecting data platform

Sertainty Self-Protecting-Data is an advanced technology that provides data the awareness to act and react, enabling security directly at the data layer.

Have a look at its data security product suite below…

 

In recent years, CISO’s have increasingly invested in cybersecurity tools and processes that focus on data supply chain operations, user-based event analytics, and automated threat hunting capabilities. Security professionals have implemented countless defensive measures and complex encryption solutions, but attackers have somehow always managed a way to circumvent them. Attackers and threat actors have evolved, stolen, and exploited the most valuable customer and company asset – DATA. The size of the organization and the quantity of data does not matter, big or small, they are all TARGETS for attackers.

SPONSORED CONTENT

Data is a passive and defenseless participant in systems that are inherently vulnerable. Systems were never designed to control data but to protect it. The problem with data is that it is neither self-protecting nor self-aware, it can be manipulated, exposed, and exploited. But imagine a solution that transforms your data into a self-reliant, self-aware, and self-protecting asset.

Sertainty Quote

Have ‘Sertainty’ in Your Data Security

The Sertainty Self-Protecting-Data technology enables developers to mix intelligence into data-files, giving data an ability to act and react to its environment. It shifts data control and risk mitigation from an indirect/re-active paradigm to a direct/active paradigm by delivering “data-layer” governance, provenance, and protection into your intra and inter-network data workflow solutions.

Sertainty Self-Protecting-Data (SPD) reduces the dependency on trusted insiders and system hardware. SPD enables the data-owner to store and share valuable information without increasing the risk of data leak or manipulation. No longer is there a perimeter or extraneous control of data exerted by an application like a firewall or other system; the data controls, protects, and mitigates risks itself – in real-time.

Salient Features

 Governance 

With Sertainty, data governs itself by first determining its environment (physical device, location, time, etc.) when an entity attempts access to important information. If an anomaly is detected, the self-governing data takes appropriate action. This includes denial of access to data, alerting the data-owner, requesting access permission from external authority, presenting an alternate or hoax view to the user or process, and in certain scenarios self-destruct to mitigate risk.

 Provenance 

Sertainty deploys anti-tampering technology and maintains a record of ownership which assures integrity of the data. The record of ownership includes environment(s), access attempts and event occurrences. These event logs are irrefutable, provide a chain of custody, and are protected with Sertainty SPD technology.

 Protection 

Sertainty technology provides security and controls within the data file, reducing the dependency on infrastructure (hardware, firewalls, endpoints, etc.) for protection and governance. Encryption keys are never exposed. Instead, your data manages the keys internally, removing the vulnerability of shared/stolen keys.

Product Offering                                    

 Sertainty Self-Protecting-Data Technology Platforms 

Enterprise Self-Protecting-Data platforms include the Self-Protecting-Files Platform, Self-Protecting-Messages Platform and the Self-Protecting-Cloud Platform.  Each are augmented with Mobile Channel add-ons (Android, iOS) and SIEM plug-ins (Splunk, Devo, Elastic).  Sertainty SPD technology is agnostic to OS and cloud architectures.

 Self-Protecting-Files Platform 

The SPFiles Platform includes a developer’s kit (SDK) allowing custom build of an SPD application. SPD’s ability to selectively decrypt information in the data file for any given user ensures that the right user, at the right time, has the right information, without exposing any other information in the file.

 Self-Protecting-Messages Platform 

The Self-Protecting-Messages (SPMessages) Platform provides an effective way to implement secure machine-to-machine or node-to-node messages where encryption is heavy and maintenance intensive. SPMessages is a light-weight mechanism for IIoT, SCADA, ICS communication environments for machines, devices and applications to guarantee the integrity of the message and ensure both the sender and receiver to be legitimate.

 Self-Protecting-Cloud Platform 

Compliance with regulations such as GDPR, CCPA, HIPPA, PCI and NIST 800 is increasingly required of all participants in the supply chain and Sertainty’s SPD Platform enables an elegant and simple solution to comply with these regulations.