Home Blog Page 139

Spoofed Wi-fi: A Major Threat to Your Device Security

KCodes NetUSB, FragAttacks on Wi-Fi connected devices

Public hotspots are great. No matter whether there’s an issue with your service provider or you simply don’t want to waste your data plan, free wi-fi is a blessing to many. The thing is, though, that it might not entirely be free. Another surprise is that you won’t even have to pay for it with money. What they want is something different yet much more valuable – your data.

By Rene Mulyandari

But that’s kind of cryptic. What does it mean exactly, and how would you even pay with your data? Well, it’s not that you actually pay with it. They just take it from you without you even being aware of the whole process. Luckily, there’s a solution to it, and it’s not ditching hotspots once and for all.

Criminal Modus Operandi

There’s a way hackers do it. If you know it, you might be able to get one step ahead of them. That’s why it’s so important to understand how they operate. Although it might sound intimidating at first, it’s really not that hard to understand. After all, as you’ll see, the attack is so simple that virtually anybody can do it, making it even more dangerous as all you need is the right tools and close to no knowledge.

Preparation

In order to proceed with a wi-fi attack, we need a network. An ideal one would be used by many people. Therefore, public places such as coffee shops, hotels, airports are a great choice. The network itself can be either official, so set up by the owner, or created by the criminal only pretending to be legitimate. As long as people will connect to it, it doesn’t really matter.

Process

If you connect to a hotspot, the data you send and receive from the Internet will go through a router, which will then connect you to the web. That means that it can be intercepted, and that’s exactly what happens in the attack called man-in-the-middle. The name is pretty self-explanatory – the hacker places themselves between your device and the router.

By telling your device that they’re the router and the router that it should forward the information to their device, and not yours, they can see everything, you send and receive. Of course, that data is then forwarded again to the ‘real’ destination, meaning you will still see what you want.

Aftermath

Once the hacker can see everything that flows through the network, they can not only see sensitive data such as your bank credentials but also add something to it. Then, even after you disconnect from the network, your device will remain compromised, and the virus can then spread to other devices using the same network once you go back home, for example.

Solution

Luckily, there’s a simple way you can utilize. It takes advantage of how the system works, just like hackers do. The difference is that here, the goal is to actually help you.

What’s a VPN?

You’ve probably heard about it as this tool has been all over the media recently. It’s equally possible that you don’t fully know what it does or let alone have it installed on your device. A virtual private network is an extra layer between you and the Internet. Before you connect with the world, your connection will go through a server located anywhere in the world, making you invisible.

There’s so many

Just like with everything in the age of the Internet, we have too much to pick from. The same goes for VPN software, where you’ll find multiple options. They can offer more servers to which you can connect as well as locations of those servers. In addition to that, there could be limits of data you can send and receive. That’s why it’s so crucial to pick the one that will suit your needs the best as only you know what you really want.

Not only hackers

Using virtual private network software, you will not only become invisible to those who want to steal from you but also to those who claim to have no malicious intentions. That includes your internet service provider, or ISP, as well as government agencies, both of which might be interested in what you’re up to for different reasons.

The bottom line

Spoofed wi-fi is a major threat, but that doesn’t mean you can’t protect yourself against it. In fact, it turns out that it’s much easier than we think. All you need is one of the best ever VPNs, and you’ll be ready to go. It doesn’t matter whether you use public networks regularly or not, it’s always good to have this tool on your device as you never know why you might need it, and when the right time comes, it could turn out to be too late to get it.


SPECIAL FEATURES

Disclaimer

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Operation Carding Action 2020 Cracks Down Credit Card Scammers

one million card data exposed

In a joint operation dubbed as “Carding Action 2020,” lead by Police authorities of Italy and Hungary, and assisted by authorities of the U.K. and Europol, nearly 90,000 pieces of card data that were being sold and purchased on the dark web, has been seized.

The operation was also assisted by a private cybersecurity firm, Group-IB, whose security researchers helped in tracking down the scammers’ activities on various underground forums. As per reports, the crackdown has prevented losses of approximately €40 million ($47 million).

Operation Carding Action 2020

The law enforcement agencies undertook the operation Carding Action 2020 with just the aim of targeting fraudsters selling and purchasing compromised credit card details on the dark web. Europol played a pivotal role in coordinating between the agencies of different countries, including their private sector partners. Europol’s experts provided an operational analysis of larger subsets of data and lent their expertise in the field of payment card fraud and scams.

In the operation that lasted over three months’ time, over 90,000 pieces of card data were analyzed by the authorities and Group-IB. This data included credit card data compromised during phishing attacks on websites and endpoint devices infected with banking Trojans, hijacked e-commerce websites, and JS-sniffers.

Related News:

Group-IB Finds Half a Million Credit Cards of Indian Banks on Darknet

Edvardas Šileris, Head of Europol’s European Cybercrime Centre (EC3), said, “Cybercrime can affect all aspects of our daily life, from paying in the supermarket, transferring money to our friends to using online communication tools or Internet of Things devices at home. Cybercriminals can attack us in different ways, and this requires a robust response not only from law enforcement but also from the private sector.”

E-skimming or Magecart attacks have surged in the recent past as the pandemic meant more and more people shopped online. Thus, Edvardas Šileris’s suggestion of a collaboration between private players and law enforcement agencies needs to be given a serious thought.

Related News:

Operation Falcon: INTERPOL Nabs Three Nigerian BEC Scammers

Delaware County to Pay $500,000 Ransom After Experiencing Cyber Disruptions

Ransomware attacks, LockBit Ransomware

Delaware County in Pennslyvania is in the process of paying $500,000 to the ransomware operators who compromised its local government’s network system. In an official release, Delaware County stated that it discovered an intrusion in some parts of its computer networks.

Delaware County immediately took the systems offline and has started working with computer forensic specialists to determine details of the incident. The County also confirmed that the Bureau of Elections and Emergency Services Department were not impacted by the incident.

“We commenced an immediate investigation that included taking certain systems offline and working with computer forensic specialists to determine the nature and scope of the event. We are working diligently to restore the functionality of our systems. The investigation is ongoing, and we are working with computer forensic specialists to understand the full nature and scope of the event and confirm accurate information before sharing the details. County employees have been notified and provided with information and instructions,”  Delaware County stated in its notice.

Majority of Ransomware Attacks in U.S.

Organizations in the U.S. witnessed a greater number of ransomware attacks than any other country. According to the research report, “The State of Ransomware in 2020,” nearly 57% of all ransomware attacks tracked in 2020 were reported in the U.S., with cybercriminals demanding $176,000 ransom per victim, on average. Australia stood second with 7% of ransomware attacks, followed by Canada (6%), the U.K. (5%), and Germany (4%). It is found that ransomware operators focused mostly on organizations that are having tens of thousands of employees. Most of the attacks were operated by infamous hacker groups like Maze (17%), REvil/Sodinokibi (16%), NetWalker (14%), and Ryuk (13%), making 60% of ransomware attacks globally. Read the full story here… 

ATMs in Italy Targeted with Black Box Jackpotting Attacks

Cybercriminals are “Jackpotting” ATMs in Europe to Steal Cash

The Carabinieri of Monza (Italian Police department) found a threat actor group that stole cash in over 35 ATMs and post office cash machines in Italy using a black box attack technique. According to a report, the police stated that the cybercriminal group stole about €800,000 in seven months by jackpotting ATMs.

The Italian Carabinieri identified 12 people linked to the threat group. The gang had their bases in the provinces of Monza, Milan, Modena, Bologna, Rome, Viterbo, Mantua, Vicenza, and Parma.

How Black Box Jackpotting Works

  • Black Box attacks are a type of Jackpotting attack.
  • In a Jackpotting attack, threat actors use an external device known as Black Box and a software stack of the compromised ATM to launch Jackpotting attacks.
  • To jackpot an ATM, hackers connect their personal device (Black Box) to the ATM’s communication system to obtain physical access to the ATM.
  • The attacker then unplugs the communication cable between the CMD-V4 dispenser and the ATM PC, and connects it to the Black Box to send illegitimate dispense commands to the ATM.
  • Unsecured/poorly secured ATMs are more vulnerable to jackpotting attacks as attackers can easily manipulate the cash machines.

Popular Technique

Jackpotting attacks are popular among the underground cybercriminal groups. Earlier, National Cash Register (NCR) Corporation and Diebold Nixdorf, two leading financial self-service providers in the United States, issued warnings against cyber breaches that make ATMs gush out cash incessantly. Terming the hack as Jackpotting, the self-service kiosk makers accepted to having informed their clients about the vulnerability. Although there is no available data on the losses due to these incidents, the ATM manufacturers have admitted to the rising cases of jackpotting across the world. Read the full story here…

“We’ll see more attacks that target cloud misconfiguration issues”

Ravi Ivaturi is Sr. Vice President – Digital Security Architecture at Citi. He is a cybersecurity leader with deep expertise in building cybersecurity programs for emerging technologies. In his current role, Ravi heads the Cloud Security Architecture function for Citi’s Consumer division, providing security leadership for financial products used by millions of individuals across 19 countries. He also serves on Citi’s apex Security Architecture Council, providing oversight to enterprise-wide security architecture. With over 15 years of cybersecurity experience in the Financial sector, Ravi brings together a well-rounded experience and thought leadership in emerging-technology risks, security assessments, compliance, and technology risk management. Ravi holds a master’s degree from New York University in Computer Science.

In an email interview, with Brian Pereira, Principal Editor, CISO MAG, Ravi talks about the mistakes that companies are making as they rush to adopt cloud computing, during the pandemic months. Why do data breaches happen on the cloud and who should be responsible? How does one get around the challenge of cybersecurity challenges? These are some of the questions that Ravi addresses in this interview.

Excerpts from the interview:

As organizations rushed out to adopt cloud, they found that there were numerous security challenges due to misconfiguration, etc. How big is the problem and what are the reasons for this? In what way is the cloud security provider responsible? What does the tenant /customer need to do to mitigate these security risks on cloud?

I’d describe the scale as “unheard of.” If we look at the count of records exposed over the past three years, we are looking at billions each year. In the current year, the number already exceeded 27 billion records by Q2, 2020. Research reports indicate that over half of these records were due to misconfigured Internet-based storage services or Cloud-based services.

That said, businesses need to adopt Cloud for staying relevant and competitive. When building use cases on Cloud, organizations will need to evolve and refine all the processes, controls, risk-assessments, and cyber defense capabilities associated with software development.  The evolution must be towards delivering software relying on “as-a-Service” architecture.  Organizations that fall short on this front are likely to have security incidents – like the ones that make headlines.

With regards to the role of service providers – I’d not yet blame the Cloud service providers. The breaches we have seen so far stem from gaps in the use cases – “security-in-the-cloud” bucket as opposed to “security-of-the-cloud.”  That said, I think the major cloud providers can do better when it comes to educating cloud adopters on the major differences with the on-premise equivalent services.

During the pandemic months, new types of attacks on infrastructure changed the security paradigm. How does this compare with the pre-COVID days and even the early days of online security?

From what I gather, COVID times have led to a greater number of attacks on VPN infrastructure and endpoints. That said, organizations that had invested in cloud-based virtual desktop interfaces (VDI), switching from laptops, have fared significantly better.

In general, as the adoption of cloud-based solutions increases, we’ll see a lot more attacks that target cloud misconfiguration issues. We already have crawlers that look for storage repositories like S3 and Mongo DB instances exposed on the Internet with default or no passwords. We can expect to see much more sophisticated attacks, and the scary part is that these attacks will quite likely bypass an organization’s existing monitoring tools. For instance, take the Capital One breach of 2019. The attacker downloaded the data from an S3 bucket over the Internet – not via the Capital One network, thus bypassing all their security monitoring tools.

Studies show that cybersecurity skills needed for the cloud are lacking and this is a problem that organizations are grappling with. What are the new skillsets that are in demand? What is the way for organizations to work round the skillset shortage?

Cybersecurity requires a deep understanding of the technologies as well as their pitfalls. Cloud platforms have led to the introduction of several new services, nuances, and design patterns. So, individuals that bring a strong understanding of the cloud platforms are in great demand. This is the case for not just cybersecurity but also for compliance, infrastructure, and development functions. While training is an essential response to skill shortage, it’s not adequately tactical in my view. I’d think organizations can overcome the challenge by hiring “cloud specialist” resources at senior levels and leveraging them as force-multipliers.

The cloud presents numerous advantages, especially for Cloud Security. But organizations have not yet tapped these for advantage. How should they go about it?

That’s a great question. Let me draw your attention to AWS CEO Andy Jassy’s statement at 2019 Re:Invent: “About 97% of the IT is still in corporate data centers.” Over the past two decades organizations have developed or employed tools, processes, systems that are suitable for this footprint. While Cloud is making rapid inroads, an overnight evolution to a similar degree of maturity is not easy. Further, the cloud services themselves are constantly evolving and at a rapid pace. This raises the bar even higher. Organizations will start building out capabilities gradually as they increase their cloud presence. I certainly think there’ll be a major role for cybersecurity vendors in speeding up the capability transformation that’s underway.

What are some myths and misconceptions about challenges on Cloud Security? What is the reality and how should organizations deal with it?

That’s a tricky one … from what I have witnessed, the single biggest challenge for Cloud Security is a general lack of understanding that Cloud services while they look all familiar to their on-premise equivalents, the underlying architectures and the attack surfaces are significantly different. The simple fact is Cloud adoption requires deliberate analysis and planning. There are no shortcuts to it.

Can you elaborate on this? What are you observing in the industry?

Compliance programs have been reactive; people and process heavy.  Usually, management teams are looking at reports for the state of affairs about two to four weeks ago. This often results in conversations that end up being subject and often, political. All these factors limit the effectiveness and value addition that compliance programs bring to the business. Cloud offers this very unique opportunity to make compliance pro-active, automated, and even provide telemetry that is current. There are a few vendor products that help build out “compliance-as-code” and seem quite promising.  How swiftly the compliance teams, industry standards, and the larger ecosystem adapts itself is yet to be seen.


Brian Pereira
About the Interviewer
Brian Pereira is the Principal Editor of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

Disclaimer

The views expressed in this article are entirely personal. The facts and opinions in the article do not reflect the views of Citi.

China Readies the First Draft of Personal Information Protection Law

Chinese actors target telecom

In the past few years, China has been notoriously known to find ways to violate users’ data privacy. However, in a step towards strengthening its stance towards individual data, China announced the first draft of the Personal Information Protection Law (PIPL). This law is a part of the three fundamental laws on cybersecurity and data protection that China holds, the other two beings: Cybersecurity Law and Data Security Law (which is also in the draft version).

Dissecting the Personal Information Protection Law

The PIPL’s draft version consists of eight chapters and 70 articles, covering topics that include personal information processing, cross-border data transfer, rights of individuals for data processing, etc.

Various types of information recorded in electrical or other formats related to identified and identifiable individuals are referred to as personal information in PIPL. Some of the key provisions of the draft PIPL are mentioned below:

Departments Exercising Personal Information Protection

As per the Draft PIPL, the Cyberspace Administration of China (CAC), the Department of the State Council, and the relevant department of local government at the level of the county or above are all responsible for personal information protection.

Scope of Application

The Draft PIPL provisions say this law can be applicable outside of China to the extent necessary for protecting the interests of Chinese citizens. The Draft PIPL also comes into effect where the purpose of data processing outside of China is to provide products or services to individuals in China or to analyze their behavior in China.

The Seven Pillars of Data Processing

The Draft PIPL is based on seven data protection principles, including the legality, explicit purpose, minimum necessity, transparency, accuracy, accountability, and data security. Let’s take a closer look at them.

1. Consent and Exceptions for Consent

Under the PIPL, a data processor may process personal data based on:

  1. Consent of the individual.
  2. The necessity of executing or performing a contract.
  3. The necessity of performing a legal obligation or legal duty.
  4. A response to an emergency public health event or the necessity of protecting the safety of an individual’s life and property.
  5. The publication of news and the supervision by public opinion for the public interest within a reasonable scope.
2. Joint Data Processing and Data Processing by Entrustment

In the event of data processors processing personal information together, the co-processors shall also bear joint liability in cases of infringement of personal interests.

Where a data processor entrusts a third-party to process personal information, both parties shall execute an agreement that includes the purpose of data processing, the processing mode, the types of personal information processed, protection measures and both parties’ rights and liabilities.

3. Provision of Personal Information to a Third-Party

When providing personal information to a third-party, a data processor is bound to inform the data subject of the identity and contact information of the third-party, the purpose of data processing, the processing mode and the type of personal information covered, as well as obtain separate consent from the data subject.

4. Sensitive Personal Information

The Draft PIPL stipulates more restrictions on the processing of sensitive personal information. Sensitive personal information is defined as information that once leaked or abused may cause damage to personal reputation or seriously endanger personal and property safety, and includes race, nationality, religion, biometric information, health, financial account, personal whereabouts and other information. Only if the personal data processor has a specific purpose and sufficient necessity, and obtains separate consent or written consent from the data subjects, is processing sensitive personal information allowed.

The data processor shall also inform the data subject of the necessity of processing sensitive personal sensitive information and the impact on the data subject.

5. Personal Image Collected by the Equipment Installed in Public

A personal image and personally identifiable information collected by image acquisition and personal identification device installed in public may only be used for the purpose of maintaining public security and may not be disclosed or provided to others unless consent is obtained from the individual or otherwise provided by relevant laws and regulations.

6. Cross-Border Transfer of Personal Information

The Draft PIPL provides three methods for cross-border transfers of personal information. In general, cross-border transfers of personal information shall be certified by recognized institutions, or the data processor shall execute a cross-border transfer agreement with the recipient located outside of China and ensure that the processing meets the protection standard provided under the Draft PIPL. Where the data processor is categorized as a critical information infrastructure (“CII”) operator or the volume of data processed by the data processor exceeds the level stipulated by the CAC, the cross-border transfer of personal information must pass a security assessment conducted by the CAC.

In cases of cross-border transfer of personal information, the data processor shall inform the data subjects of the identity and contact information of the overseas receiving party, the purpose of data processing, the processing mode, the type of personal information to be processed, and the way data subjects can exercise their rights provided under the Draft PIPL, as well as obtain separate consent from the data subjects.

7. Rights of the Individuals with Respect to Data Processing

Individuals have the right to know, the right to decide on, and the right to limit or object to the processing of their personal information by others. They also have the right to access and copy their personal information from data processors and the right to request that data processors correct or complete their personal information. Under certain circumstances, individuals have the right to request deletion of their personal information, the right to withdraw consent, and the right to request that the data processor explains the processing rules.

The data processor shall establish the mechanism for the data subject to exercise his or her rights.

Legal Liabilities

The Draft PIPL amplifies the range of penalties beyond those provided in China’s Cybersecurity Law. In addition to rectification, confiscation of illegal gains, warnings, penalties under 1 million RMB, business suspensions, business halts for rectification, and the revocation of relevant permits or business licenses under Cybersecurity Law, the draft version of the PIPL also stipulates that in serious cases, data processors also are subject to fines under 50 million RMB or under 5% of the previous year’s revenue.

Home Depot Settles 2014 Data Breach Lawsuit for $17.5 Mn

home depot data breach

The popular U.S. home improvement retailer Home Depot Inc. has agreed to pay $17.5 million to settle a multistate investigation related to a data breach, which occurred between April 10, 2014, and September 13, 2014. The threat actors illicitly accessed the payment card details of 40 million customers. The investigation was led by Connecticut, Illinois, and Texas.

How Home Depot was Hacked

Cybercriminals misused a vendor’s username and password to break into Home Depot’s network and install a malicious code to obtain customers’ payment card data. The breach, exposed by Brian Krebs, affected the customers who used self-checkout terminals of Home Depot stores across the U.S. and Canada. It is also estimated to have affected over 52 million customers’ data.

Home Depot did not confess liability to the settlement but agreed to comply with the security provisions like hiring a CISO and increasing security standards and training.

“Companies that collect sensitive personal information from customers have an obligation to protect that information from unlawful use or disclosure. Home Depot failed to take those precautions,” said Connecticut Attorney General William Tong.

Relief for the Affected

In a similar data breach settlement, Hanna Andersson, U.S.-based kids wear retailer, agreed to pay $400,000 to settle a data breach lawsuit related to the California Consumer Privacy Act (CCPA). The class-action lawsuit, which is the first monetary settlement under CCPA, was filed in the U.S. District Court for the Northern District of California in February 2020. Also, Health insurer Anthem agreed to pay $39.5 million to settle another class-action suit related to a cyberattack in 2015 that exposed the personal data of nearly 79 million people. Read the full story here…

Google Delists Chinese Baidu Apps for Stealing Users’ Data

Google Play

Google has delisted two Chinese apps – Baidu Maps and Baidu Search Box – from the Play Store for leaking users’ sensitive data. An investigation from the security firm Palo Alto Networks claimed that the two apps used a code that harvested information without the users’ knowledge, even after the device was switched off. The apps, with a combined download count of 6 million, potentially exposed information including users’ MAC address, IMSI number, carrier information, phone model, and IMSI (International Mobile Subscriber Identity) number.

In addition to the China-based apps, the researchers stated they have identified multiple Android applications on the Play Store that were leaking users’ data through their machine learning-based spyware detection system.

Palo Alto researchers suggested that Android app developers must follow best practices to properly handle users’ data. They said, “Android users should stay informed about the required permissions requested by applications on their devices.”

“While not a definitive violation of Google’s policy for Android apps, the collection of identifiers, such as the IMSI or MAC address, is discouraged based on Android’s best practice guide. Palo Alto also notified Google’s Android team, who confirmed the findings, identified unspecified violations, and removed the applications from Google Play globally on October 28, 2020. A compliant version of Baidu Search Box became available on Google Play globally on November 19, 2020, while Baidu Maps remains unavailable globally,” the researchers added.

Android Adware: A Rising Issue

Adware is a kind of software that hijacks mobile devices to spam the victim with unwanted ads and steals user data. Recently, Google removed 21 malicious Android apps from its Play Store after discovering intrusive adware and Trojans in them. According to security solutions provider Avast, the fraudulent apps were disguised as gaming apps and contained “HiddenAds Trojan.” Read the full story here…

Cloud Security Spending to Grow 250.3% in 2021: Gartner

Cloud Forensics

Indian companies are expected to spend more on Information Security and Risk Management in 2021 and a chunk of that investment goes towards Cloud Security, said market research firm Gartner.  In its latest forecast report, Gartner projects total Information Security to reach $2,199 mn (8.8% growth) compared to 2020. Spending on cloud security will reach $30 mn (250.3% growth).

Overall, IT spending in India is projected to total $81.9 billion in 2021, an increase of 6% from 2020, according to the latest forecast by Gartner. Total IT spending in 2020 is expected to total $79.3 billion, down 8.4% from 2019. 

“The COVID-19 pandemic stalled many digital transformation projects for Indian enterprises, mainly because of the market uncertainties and reduced cash flows,” said Arup Roy, research vice president at Gartner. “Organizations that were digitally sound in a pre-pandemic world could contain the impact on their business. The pandemic situation was a wake-up call for many organizations to relook and revive their IT strategies and increase their spending on IT in 2021.”

Table: Total Information Security and Risk Management End-User Spending for All Segments in India, 2018-2021 (Millions of U.S. Dollars)

Market Data Year
2018 YR 2019 YR 2020 YR 2021 YR
Application Security Sum of End User Spending (M) 72 78 79 82
Growth (%) 9.2% 0.8% 3.9%
Cloud Security Sum of End User Spending (M) 1 4 9 30
Growth (%) 215.9% 128.9% 250.3%
Consumer Security Software Sum of End User Spending (M) 134 138 131 134
Growth (%) 2.7% -4.8% 2.2%
Data Security Sum of End User Spending (M) 77 91 98 114
Growth (%) 18.4% 8.2% 16.3%
Identity Access Management Sum of End User Spending (M) 157 172 173 185
Growth (%) 8.9% 0.8% 7.1%
Infrastructure Protection Sum of End User Spending (M) 180 207 208 228
Growth (%) 15.4% 0.4% 9.4%
Integrated Risk Management Sum of End User Spending (M) 65 79 95 121
Growth (%) 22.9% 19.4% 27.5%
Network Security Equipment Sum of End User Spending (M) 229 266 277 303
Growth (%) 16.4% 4.3% 9.1%
Other Information Security Software Sum of End User Spending (M) 24 26 25 26
Growth (%) 7.2% -1.9% 3.6%
Security Services Sum of End User Spending (M) 863 928 925 975
Growth (%) 7.5% -0.3% 5.4%
Total Sum of End User Spending (M)   1,801 1,989 2,021 2,199
Total Growth (%) 10.4% 1.6% 8.8%

 

Prateek Bhajanka, Senior Principal Analyst, Gartner

CISO MAG spoke to Prateek Bhajanka, Senior Principal Analyst, Gartner to discuss factors driving increased spending on Information Security, particularly for Cloud Security. He said cloud security spending is increasing primarily because enterprises are using more SaaS applications.

“If you look into the definition of cloud security spending, as per the forecasting report that we put out, that is more on the CASB side, which is Cloud Access Security Broker. It is about securing enterprise resources like ERP and Salesforce, which are delivered through SaaS models,” said Bhajanka.

He said organizations want to maintain the same set of policies across these cloud applications.

“You want to make sure that all the identity orchestration and access management happens consistently. And that is the reason why cloud security expenditure has been increasing in India and also worldwide,” he added.

Related Story:

Endpoint Security is a Lot More Than Just Technology: Gartner

Wi-Jungle: Keeping Intrusions Away From Your Network Jungle

Six months ago, while we toasted the turn of the decade, no one imagined the world would come to a grinding halt because of a biological virus. But it did, and it forced us to stay confined to our homes and work remotely. With the lines between work and home further blurring due to the indefinite nature of the ongoing pandemic, another type of virus seems to be spreading fast – Cybercrime.

By Mihir Bagwe, Technical Writer, CISO MAG

It’s a Jungle Out There!

Remember Disney’s famous animated movie “The Lion King”? What was Simba restricted from? He was forbidden from going beyond a certain boundary. Why was he forbidden? Because the threats in the valley were unknown and thus made him vulnerable to attack. The same applies to our urban digitally connected jungle; the threats are unknown, and we need to protect our boundaries.

In the early days of the pandemic, cybercriminals vowed not to attack healthcare facilities and systems that are at the forefront of the COVID-19 war, thus drawing a protected boundary around these services. However, it is a known fact that they use these global episodes and the associated fear among the masses for personal gain. And they did just that. Add to this the vulnerability of the humongous number of people working from home outside the company’s usual security perimeter. No wonder a recent study suggested that 85% of organizations anticipated a threat to business operations from remote workers.

While businesses are pushing to integrate digitization as an indispensable part of the personal and professional lives of the people, it is worth noting that vulnerability and misuse of personal and professional data are ringing serious alarm bells. It is like the threat actors are employing the jungle rules; attack and spread fear, and only the fittest survive. So how can you defend your digitally connected urban tribe from these intrusion threats to your cyberspace? WiJungle, an Indian based startup, may have an answer to this.

The WiJungle Story

Co-founded by Karmesh Gupta and Praveen Gupta in 2017, the company provides a Unified Network Security platform that is trusted by businesses spread across 25+ countries worldwide. Karmesh, due to his keen interest in cybersecurity, had previously worked with Lucideus (a cybersecurity firm founded by his college alumni, Saket Modi). The learnings from his time at Lucideus, the deep understanding about the distributed architecture followed within the cybersecurity industry from their first two ventures in computer networks, and its allied security products, coupled with their failures, helped them persevere in being successful the third time around, with a unique solution that served the need of the hour. The duo did not just succeed but excelled and the world took note of it by showering them with accolades such as ‘Most Innovative Product of The Year in 2018’, Frost and Sullivan – ‘New Product Innovation Award of the Year 2019’, etc. Karmesh’s perseverance was further rewarded when he was selected by Forbes in its annual 30 Under 30 Asia 2020 list.

As they say, all great stories have humble beginnings, and so is it the case with this duo. When asked about the challenges faced in bringing up the startup, the duo mentions, “We had already failed twice, so there was no chance to get capital from any sort of third-party for trying a new venture. Bootstrapping was the only way to take it forward. Consequently, we had a very limited period to develop a minimum viable product (MVP) and turn it into a successful sale to ensure cashflow. If the launch period were missed, the MVP product would have failed to hit the expected sales volume and we would have again been in a deadlock. So, ensuring to be lean was a prime challenge in the starting days.”

The Unified Network Security Gateway

This platform comprehensively offers the capabilities of NextGen Network Firewall, Secure Web Gateway, Web Application Firewall, Hotspot Gateway, DLP, Vulnerability Assessment, etc. with an all-in-one device. The AI and ML-enabled devices help businesses to seamlessly manage and safeguard their entire network through a single window.

WiJungle has a wide range of models to cater to the needs of businesses of all sizes in various sectors such as enterprises, education, hospitality, healthcare, BFSI, transport, retail, defense, smart city, real estate, events, etc.

With many industry giants telling their employees to continue working from home even in the post-pandemic world, in some cases as long as “forever,” it has now become more important than ever to secure your work cum home security perimeter with competent solutions like the Unified Network Security Gateway offered by WiJungle.

KEY DIFFERENTIATORS
  • Both unified threat management (UTM) / Firewall and Hotspot Gateway features in a single device.
  • Inbuilt storage of User logs for a period of one year along with search option.
  • Auto-Feature update via cloud.
  • Provision for PMS/HIS/third party integration and custom development.
  • Real-time activity notifications.

 

S N A P S H O T
Company
  • HttpCart Technologies Pvt. Ltd. (Registered Company Name)
  • WiJungle (Product Brand Name)
CEO/Co-Founders
Website www.wijungle.com
Tech Partners CISCO, AWS, RSA
Social Media Handles
Location(s) New Delhi, Jaipur
Employees 70
Awards
Industry-wise Services
  • Defense
  • Healthcare
  • Hospitality
  • Education
  • Smart City
  • Transportation
  • Enterprises (Services & Manufacturing)
  • BFSI
  • Retail

Company Timeline

Wi-Jungle Company Timeline

About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 


Other Posts from the Author:

 **Disclaimer** 

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by WiJungle. The facts, opinions, and language in the article do not reflect the views of CISO MAG and thus we do not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.