Home Blog Page 148

Make Passwords Great Again

1Kosmos panel discussion

CISO MAG recently hosted a panel discussion with Michael Engle, Chief Strategy Office, 1Kosmos; Christian Adam, MD Cybersecurity Technology, BNY Mellon; and Jerry Kowalski, Deputy CISO, Jefferies LLC. The panel discussion, which was moderated by Jyoti Punjabi, Deputy Business Head, CISO MAG, EC-Council, was on “Vaccine Release against Identity Theft and Fraud.” A slew of cybersecurity experts comprising of CEOs, CISOs. CIOs, Vice Presidents, and executives from countries like the U.K, the U.S., Singapore, Spain, Australia, India attended the virtual panel discussion.

Fraudsters are creating scam posts and emails with fake information about COVID-19, and there is also an increased number of hackers creating malicious websites that spoof legitimate public health resources. The panel discussion began with dialog on the rapid deployment of remote working solutions, and cybercriminals are already exploiting weaknesses due to reduced IT staffing and especially the use of personal devices and insecure public and home networks.

Jerry Kowalski took the lead and explained how multifactor authentication and password management solutions have been the key areas that industries have been focusing on. He stressed how Zero-Trust policies for managed devices has been helping several organizations adopt a better cybersecurity posture. Kowalski is the Deputy Chief Information Security Officer at Jefferies LLC. As a Deputy CISO, he is responsible for designing, building, and operating the cybersecurity program that enables Jefferies to run its core businesses securely. At Jefferies, he heads Security Engineering, Operations Security, Access Identity Management, and Application Security practices.

Michael Engle highlighted Gartner’s latest research on password management. He said, “ By 2022, 60% of large and global enterprises, and 90% of midsize enterprises, will implement passwordless methods in more than 50% of use cases — up from 5% in 2018.” He also stressed how to replace legacy passwords with more multifactor authentication systems, including biometrics.

Engle is the  Chief Strategy Officer at 1Kosmos. He is a seasoned information technology executive, leader, and entrepreneur. Engle is an expert in information security, business development, and product design/development. He has experience running large teams and multi-million-dollar projects for a Fortune-100 bank as well as working with startups that need to set direction and go from “zero to one” as it is now commonly called.

Christian Adam called for a shift from legacy systems to a more forward-thinking one. He also exhibited his apprehensions over the feasibility of hardware tokens and how they have been compromised several times in the past. Adam leads Bank of New York Mellon’s global cyber technology team that builds and runs global information security controls to protect the bank.  He has more than 20 years of experience in information security, planning, building, operating, and assessing controls for financial services companies. Christian’s experience includes executive leadership positions at Experian, BlackRock, Goldman Sachs, Barclays, and Lehman Brothers.

The panel also stressed leveraging private blockchain to secure financial institutions and even discussed how passwordless solutions are the future. According to the panel, passwordless authentication eliminates the problem of using weak passwords. It also offers benefits to users and organizations. For users, it removes the need to remember or type passwords, leading to a better user and customer experience. For organizations, there’s no longer a need to store passwords, leading to better security, fewer breaches, and lower support costs.

They highlighted how early adapters of passwordless solutions would be at the better end when the mass migration toward passwordless solutions, ending on a quip, “make passwords great again!”

The panelists also spoke about a few interesting COVID-19-projects they recently worked on and took questions from the attendees. Attendees of the panel also took part in a snap poll.


Do check out our November issue on “Compliance and Risk Mitigation.” Get Your Copy Now!

Endpoint Security SurveyWe also invite you to participate in our year-end Endpoint Security Survey, the aggregated results of which will be shared in our December issue. Take Survey Now!

Endpoint Security

California Voters Say “Yes” to Proposition 24 for Expansion of Data Privacy Law

CCPA Expands

California is popularly known as the state that laid the foundation of a stringent data privacy law in the U.S. With its historic amendment of the California Consumer Privacy Act (CCPA), some infosec pundits termed it as the boldest move by the people of California against the data mining heavyweight corporations.

It gave the citizens of the state the right to know what information companies collect about them online, get that data deleted, and, if required, opt-out of the sale of their personal information. However, in an act of further strengthen their data privacy protections, the voters of California have once again voted in favor of “Proposition 24,” which expands the existing data privacy law.

Related News:

Mozilla Firefox Adopts CCPA for Worldwide Audience

What is Proposition 24?

According to the advocates of Proposition 24, it expands the data privacy law and closes some of the loopholes that big businesses exploited to get around it. The new measure includes a three-fold increase in fines for companies that violate kids’ privacy or break laws on the collection and sale of children’s private information. A special annual budget of $10 million has also been allocated to establish a dedicated state agency that will specifically look after the enforcement of the new law.

All in favor

The adoption of the Proposition 24 was supported by Consumer Reports, Common Sense Media, Consumer Watchdog, and Alastair Mactaggart, a San Francisco-based real estate developer who has been voicing his support for the data privacy law since the 2018 law and has been pushing to update it.

The voting for the measure was held on November 4, 2020, which saw over 11 million voters pouring into the ballot booths. The ballot was counted on November 5, 2020, resulting in 56% of voters saying “Yes” to amending Proposition 24 into the existing CCPA.

Proposition 24 approved

Speaking on the approval of Proposition 24, Alastair Mactaggart said, “We will now be able to stop businesses from using our most intimate, most personal information — our health information, our religion, our sexual orientation, our race. Proposition 24 will put a floor under privacy. There will now be much, much more robust enforcement of the law”.

Stance of the critics

However, the amendment was not welcomed by all. It has been criticized by some privacy and consumer advocates like the Consumer Federation of California, who said it was not tough enough on big business and made concessions that did not fully benefit consumers. In a statement issued by the Federation, it stated, “We will continue to champion the privacy rights of Californians, work with our allies to reverse the harmful portions of Prop. 24, and oppose its adoption as a model for the nation.”

Related News:

California Consumer Privacy Act Puts Additional Pressure on Financial Organizations

Japanese Gaming Giant Capcom Hit by a Cyberattack

Gaming

Japanese game developer and publisher Capcom suffered a security incident on November 2, 2020, which impacted its operations, including email and file servers. The developer of popular game franchises like Monster Hunter, Resident Evil, Devil May Cry, Mega Man, and Street Fighter claimed that an unknown third party illicitly accessed its internal network systems. After realizing about the incident, the company temporarily stopped a few systems in its network to prevent the spread.

While there is no indication of misuse of any customer information, Capcom clarified the incident has not affected any connections for playing the company’s games online or access to its websites. The company reported the incident to cyber sleuths and the related authorities for further investigation, and is also taking measures to restore its systems.

Gaming Industry Suffered 10 Bn Attacks

Even after the improved security measures, cyberattacks have become common in the online gaming industry. Attackers often target online video games and gamers by compromising their accounts and launching attacks. A research from Akamai Technologies revealed that the gaming industry suffered high volumes of attacks between 2018 and 2020. The research “State of the Internet/Security report, Gaming: You Can’t Solo Security” highlighted that the COVID-19 lockdown resulted in the increase of attack traffic through credential stuffing and phishing attacks.

Gamers Turning into Hackers

Another research revealed that most young gamers are increasingly turning into hackers to commit cybercrime. The research found that 82% of teens and young adults recruited by online criminals had developed their cybercrime skills through video games. The U.K.’s National Crime Agency (NCA) held a forum and published a special report about the problem. Read more…

CYFIRMA’s Threat Landscape Report Reveals Interesting Trends and Threat Actors Targeting India

SideCopy Malware Campaign

CYFIRMA, a Singapore-based cybersecurity firm, has released the India Threat Landscape Report 2020. The researchers at CYFIRMA have been actively observing global cyberattack trends and major state-sponsored threat actors using its cyber threat intelligence (CTI) platform, DeCYFIR. From time to time, it has warned private establishments and Indian Computer Emergency Response Team (CERT-In) authorities about the impending cyberattacks. It has helped them thwart some vicious campaigns aimed at top private companies, media, and the government itself.

 Key Highlights 

  • Top threat actors targeting India’s digital frontier include the Lazarus group, APT36, MISSION2025, Stone Panda/APT10.
  • The upcoming trends used to target Indian audience include ransomware, phishing and social engineering, reconnaissance activities, brute force and DDoS attacks, and commodity malware.
  • Top attack methods used include attack on Linux servers, Email Servers, and web applications.

CYFIRMA’s India Threat Landscape Report 2020

In the Indian Threat Landscape Report’s summary, Kumar Ritesh, Founder and CEO of CYFIRMA, said,

India is a haven for startups, a fertile ground for technological innovation, sparking the generation of massive amounts of data that attracts cyber criminals. While digital adoption is breaking new grounds, the corresponding cyber maturity is low and not keeping pace with technological strides. All these factors are prompting more nations, especially India’s geopolitical foes, to partake in the cyber game targeting India. The Big 3, namely China, North Korea and Russia, authoritarian regimes that are suspected of aiding state-sponsored cybercriminal activities have shown interest in breaching India’s security perimeters.

The report highlights key findings such as top threat actors, evolving malware and their methodologies, tools used for targeting organizations in India, and much more.

Threat Actors and Their Attack Methods Targeting India

  • Lazarus Group: The North Korean threat actors’ activities surged in 2020, which involved fileless attack, spreading new malware samples, attacking cryptocurrency businesses and more. They are believed to be using a new malware variant, known as COPPERHEDGE RAT, to target crypto exchanges.
  • APT36/ Mythic Leopard: These are reportedly backed by the Pakistani government and known to have targeted Indian diplomats in the past. In H1 2020, the threat actors impersonated the Indian Government to send emails containing malware. These emails contained bogus health advisories on COVID-19. A spear-phishing campaign, aimed at computers belonging to the Indian Railways, was also detected.
  • MISSION2025: Suspected to be a Chinese state-sponsored threat actor, this group has been active since as early as 2012. MISSION2025 is suspected of carrying out various campaigns against multiple industries such as Automotive, Retail, Healthcare, Energy, Media, Finance, and many more. The group is believed to have targeted other nations such as the U.S., the U.K., Japan, France, South Korea, Hongkong, and Thailand, for financial gains and/or corporate espionage.
  • Stone Panda/ MenuPass/ APT 10/ Cloud Hopper: This Chinese threat actor group had traditionally shown interest in stealing international trade data and supply chain information from various enterprises across several countries such as India, Japan, Canada, Brazil, etc. It also tends to target Managed Service Providers (MSP), alongside Government agencies, Financial institutions, and entities in the Energy & Resources domain.

Top Attack Methods Used to Target India

The researchers at CYFIRMA observed a steady increase in attacks in H1 2020. They further studied these attack vectors and have listed the following methods as being the most potent forms of attacks to be used in H2 2020 and beyond.

CYFIRMA India Threat Landscape 2020
Image Credit: CYFIRMA’s India Threat Landscape 2020

Malware Trends to Watch-out

H1 2020 saw criminal organizations, state-actors, and even well-known businesses being accused of deploying various malware targeting Indian businesses and organizations. Listed below are malware trends with a likely impact on India through H2 2020 and beyond.

CYFIRMA India Threat Landscape 2020
Image Credit: CYFIRMA’s India Threat Landscape 2020

Related News:

CYFIRMA’s DeCYFIR Platform Can Predict Hacker Motives Before an Attack!

CYFIRMA Brings Cyberthreat Intelligence to the Fore

1 in 4 Cyberattacks Handled by U.K.’s NCSC Were Related to COVID-19

covid-19 vaccine, vaccine

Over one in four security incidents handled by the U.K.’s National Cyber Security Centre (NCSC) last year were COVID-19 related cyberthreats. In its annual threat review report, the agency stated the number of attacks surged from an average of 600 incidents over the past three years to 723 incidents now. It was found that organizations in the U.K. suffered an average of 60 cyberattacks per month from September 2019 to August 2020. The report revealed details of 160 high-risk and critical vulnerabilities with trusts, including 51,000 indicators of compromise (IOCs).

The NCSC’s defense system took down over 15,000 COVID-related malicious campaigns last year and blocked nearly 260 Sender IDs for sending malicious SMS messages. In addition, the agency prevented over 166,000 phishing URLs, in which 65% were within a day and 2.3 million suspect emails were forwarded to its new Suspicious Email Reporting Service (SERS).

The NCSC also highlighted that it performed threat hunting on 1.4 million National Health Service (NHS) endpoints, and scanned over one million IP addresses to detect security weaknesses and applied its Active Cyber Defense services to 235 frontline health care providers with web, email security, and DNS protection.

Paul Chichester, NCSC Director of operations, said, “We condemn these despicable attacks against those doing vital work to combat the coronavirus pandemic. Working with our allies, the NCSC is committed to protecting our most critical assets and our top priority at this time is to protect the health sector. We would urge organizations to familiarize themselves with the advice we have published to help defend their networks.”

NCSC’s New Vulnerability Reporting Toolkit

Recently, NCSC released a new “Vulnerability Reporting Toolkit,” which is intended to help organizations manage their vulnerability disclosure processes in a simplified manner. The Toolkit is helpful for all types of organizations that are planning to implement a vulnerability disclosure process in their system. Read more…

Ping Identity Acquires Symphonic Software to Enable Enterprises to Prevent Fraud

Ping Identity Acquires Symphonic Software to Boost Enterprise Security

Intelligent identity solutions provider Ping Identity has acquired authorization solutions provider Symphonic Software to help enterprises prevent cyber risks and enhance their cybersecurity posture. The acquisition integrates Symphonic’s authorization platform with Ping’s data privacy and consent products, allowing enterprises to centralize administration and enforcement to critical resources.

Symphonic helps organizations in enforcing complex policy decisions across multiple channels for their workforce, customers, third party providers, and business partners. Ping Identity enables enterprises to achieve Zero Trust identity-defined security and more personalized user experiences. Its security platform provides customers, workforce, and partners with access to cloud, mobile, SaaS and on-premises applications across hybrid networks.

The joint solutions would offer enterprise-grade features like delegated administration, deployment workflows, integrated testing, and analysis of policies. The companies will offer a rich set of policy enforcement methods for API and web-based applications without requiring custom integration code. Customers can also avoid costly custom integrations by leveraging native services that are core to identity platforms like users, groups, entitlements, consents, and risk.

Commenting on the new acquisition, Andre Durand, CEO and Founder of Ping Identity, said, “With increasing data privacy regulations, users are demanding that enterprises give them better digital experiences with more transparency and control. The acquisition of Symphonic accelerates our vision for enterprises to not only maintain security and compliance with confidence, but to easily deliver personalized, trustworthy experiences.”

5G Security: Possible Risks and Challenges

5G is taking the world by storm. This game-changing technology takes mobile connectivity to a whole new level by introducing jaw-dropping speeds and low latency. Furthermore, its network capacity can reach a million devices per square kilometer, which is ten times the maximum number supported by 4G.

By David Balaban, Computer Security Researcher, Privacy-PC.com

Whereas the dramatic change in the millimeter-wave frequency spectrum used by 5G compared to its predecessor doesn’t really explain anything to the average person, there are tangible benefits that make a difference and can be noticed with the naked eye. The speeds can reach 2Gbit/s at the dawn of 5G deployment and will theoretically grow to 100Gbit/s as the technology evolves. That’s up to 100 times faster than 4G. Reduced latency is another breakthrough, allowing data to arrive at its destination about five times quicker.

A simple example of how this improves the user experience is that there is absolutely no buffering time when watching a 4K quality video on a mobile device. Uploading and downloading gigabytes of data is a matter of mere seconds in 5G networks, which transforms the way users interact with numerous cloud-based services. Also, wirelessly connected entities that constitute the Internet of Things (IoT), including self-driving cars and smart home appliances, will be able to operate reliably and seamlessly. An extra factor on the plus side of 5G is that people can enjoy fully-fledged connectivity in places where cable modem and Wi-Fi are unavailable.

Having started with field testing and somewhat scattershot regional rollouts in 2019, the deployment of 5G is currently accelerating around the globe. In the United States, the European Union, and East Asia, the process of launching next-generation commercial networks is in full swing, occasionally taking place ahead of schedule.

To keep up with this telco evolution, all major smartphone manufacturers have already released devices that support 5G. Furthermore, market analysts predict that these gadgets will account for 15% of all global smartphone shipments in 2020. Aside from smartphones, a plethora of different IoT solutions will be heavily relying on high-speed connectivity in the near future.

All in all, the booming 5G tech is gradually shaping up to be the mainstay of digital economies going forward. When there is so much at stake, governments and service providers need to make sure the network deployment is flawless in terms of security. Cybercriminals will undoubtedly look for ways to compromise the emerging communication protocols and thereby orchestrate massive data breaches. The concerns escalate considering the tightening connection between 5G and ubiquitous cloud computing.

The government-level 5G risk assessment process is now underway in the EU. A report released by the member states singles out the security and privacy pitfalls that may accompany fifth-generation network rollouts. Below is a summary of the experts’ findings.

5G Vendor Monopoly Issue

One of the key points expressed in the report is that the EU will have to rely on a single manufacturer of network equipment, the Chinese vendor Huawei. Even though the name of this technology company isn’t directly mentioned in the document, the implied cooperation is common knowledge.

The potential problems stemming from the monopoly position of the supplier include a possible lack of equipment, dependence on the contractor’s commercial welfare, and cyberattacks targeting its digital infrastructure. The recent outbreak of the Coronavirus in China could become an additional factor undermining mainstream 5G deployment.

Researchers emphasize that such a collaboration has a single point of failure. The manufacturer can be subject to economic sanctions or other forms of commercial pressure. A hypothetical merger or acquisition scenario may also prevent the company from following its obligations.

One more thing to consider is that there are close ties between the vendor and the government of the state it’s headquartered in. This can be a source of politically motivated tampering with the company’s business processes. Moreover, the scarcity of data protection commitments shared by the EU and the country of the supplier’s origin is yet another possible obstacle to a hassle-free partnership.

According to the EU officials, an increasingly strong link between the member states’ telecommunication networks and third-party software underlying them is a serious threat as well. Since the vendor will have a significant scope of access to all the data in transit, malicious actors will be tempted to hack these solutions and intercept the information.

Extra Stumbling Blocks to Tackle

In addition to the solo vendor issue that implies a major dependency on third-party telco gear and applications, secure 5G implementation may also be hampered by quite a few more circumstances revolving around the technical nature of these systems. Here is the lowdown on these vulnerabilities.

  • A greater number of attack vectors

The growing role of software in fifth-generation networks is deemed as one of their weak links. It makes them highly susceptible to compromise that piggybacks on security loopholes, including zero-day exploits that may be unearthed down the road. Such imperfections can become a launchpad for cyber incursions that will allow an adversary to gain a foothold in different tiers of the 5G network architecture. The potential outcomes can range from man-in-the-middle (MITM) attacks to large-scale disruption of the services based on wireless connectivity.

For instance, malefactors may insert a backdoor into an application involved in the 5G implementation chain. To do it, they can take advantage of a known or undocumented vulnerability arising out of the supplier’s poor software development practices. Aside from that, a phishing hoax might be used to wheedle out the sensitive credentials of the software engineers and thereby get unauthorized access to the application. The backdoor will allow the attackers to modify the program’s behavior, deposit malware, or steal users’ data.

Cybercriminals may also try to execute an ARP spoofing attack against a mobile carrier’s IT network by flooding it with rogue Address Resolution Protocol packets. This way, the MAC address of the attacker’s device will become associated with the IP address of the default gateway in the telco service provider’s network. In plain words, the threat actor will be able to impersonate a trusted user to intercept, change, or stop any traffic intended for that IP address.

Distributed denial-of-service (DDoS) attacks pose a growing risk to 5G networks and the entities relying on them. According to Statista, the total number of IoT devices in use worldwide will reach 75 billion by 2025, up from 30 billion in 2020. This ecosystem will be expanding dramatically and so will botnets that harness crudely secured IoT devices to fuel massive DDoS incursions targeting major web services.

As a matter of fact, incidents like that have already occurred in the past. The notorious Mirai malware outbreak in 2016 demonstrated how disruptive this attack vector can get. The infection enslaved more than 600,000 unprotected CCTV cameras and routers to execute a series of 1 Tbps DDoS raids. With the rapidly increasing number of 5G-enabled smart gadgets, the likes of Mirai will be booming and the issue will undoubtedly escalate.

  • Network slicing security needs an overhaul

5G is expected to bolster the functioning of virtualized ecosystems referred to as “slices,” which host critical services and utilities used by businesses and government networks. Providing proper security of these independent logical networks that reside within the same physical infrastructure is an increasingly serious challenge. Experts have yet to develop effective mechanisms for isolating these slices in the all-new 5G paradigm to thwart data leaks and other forms of intrusions.

  • Meager software update procedures

As previously mentioned, next-generation wireless networks will depend on software to a much bigger extent than the predecessors did. Obviously, seamless application maintenance practices are going to be the pivot of their uninterrupted operation. In particular, software update management will need to catch up with security trends in terms of vulnerabilities and technical bugs and address these flaws before threat actors add them to their repertoire.

  • Obsolete standards

Aligning the peculiarities of 5G networks with international and state-level security regulations is a work in progress. The protocols developed by the 3rd Generation Partnership Project (3GPP) organization, which are currently in effect, extensively cover requirements for earlier mobile telephony systems (GSM, UMTS, and LTE) but don’t fully embrace all aspects of 5G standardization at this point. Elaborating the entirety of new security regulations is a matter of trial and error combined with in-depth research that has yet to be conducted.

  • Lack of trained personnel

As promising as it is, the 5G technology is also a Pandora’s box filled with opportunities for cybercriminals who will explore it for weaknesses. With that said, the security industry should work proactively to stay on top of new methods as they complement the malefactors’ toolkit. An important prerequisite for bridging this imminent gap is to nurture the expertise of security professionals so that they can identify and fix network imperfections by means of penetration testing and other techniques.

The personnel will need to collaborate more tightly with software suppliers to get a profound understanding of how the new applications work and what exploitation mechanisms they are potentially susceptible to. Furthermore, penetration testers who think like attackers can probe the IT infrastructure of 5G providers and contractors for weaknesses by orchestrating trial network incursions. This will allow the industry to prioritize the areas that need urgent improvement in terms of security.

Final Thoughts

5G will become one of the core elements of the global digital economy in the years to come. Therefore, securing these high-tech networks is a top priority for governments and all the parties involved in the deployment workflow. Hopefully, the white hats will team up and succeed in staying one step ahead of the adversaries to make sure people benefit from this awesome technology to the fullest.


About the Author

David BalabanDavid Balaban is a computer security researcher with over 15 years of experience in malware analysis and antivirus software evaluation. David runs the Privacy-PC.com project which presents expert opinions on contemporary information security matters, including social engineering, penetration testing, threat intelligence, online privacy, and white hat hacking. As part of his work at Privacy-PC, Mr. Balaban has interviewed such security celebrities as Dave Kennedy, Jay Jacobs, and Robert David Steele to get firsthand perspectives on hot InfoSec issues. David has a strong malware troubleshooting background, with a recent focus on ransomware countermeasures.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


Related story: 5G Networks Present New Risks and Security Challenges


 

Compliance: A Chief Tenet for the Future of Cybersecurity

compliance and risk mitigation

COVID-19 has questioned the status quo of the business world. Businesses are transforming digitally and integrating newer technologies to deliver value to customers. However, digital transformation has brought unprecedented cyberthreats. And CISO MAG’s latest issue highlights why regulatory compliance is the key to address these challenges.

A recent survey of North American CISOs stated that CISOs are preparing for an average of 3.3 security compliance standard audits over the next six to 12 months. It is more important than ever for a CISO to ensure their organization is adapting to the compliance regulations like the GDPR and HIPPA.

Cloud Security Expert and NABCRMP Board Member, AJ Yawn, in “CISOs Must Declare an End to the War between Security and Compliance,” states that cybersecurity audits are viewed as “check-the-box” exercises where auditors are paid to produce a report, so the Board, executives, and interested third parties (customers and vendors) feel good about the perceived security status of the organization. It isn’t acceptable when these assessments are expensive, time-consuming, and extremely important to the bottom line.

Bryan Cline, Chief Research Officer at HITRUST, in his special feature, “Emphasize the Spirit of Compliance Over Simply Checking All the Boxes,” discusses the three levels of compliance maturity. He writes, “The correct solution involves moving beyond the binary state of the letter of compliance and, instead, striving to achieve compliance in a way that meets the intent of the regulations and standards.”

“Cybersecurity is vast, and compliance is a weird beast,” says Chaitanya Kunthe, Co-founder and Chief Operating Officer at Risk Quotient. Kunthe, in his article, “How Organizations Should Adopt Changing Compliance Standards,” talks about combining the Progression Model and Capability Maturity Model into a Hybrid Model to help CISOs understand where their frameworks currently are and how to improve them.

The articles: “SOC 2 Compliance and Cloud: What You Should Know,” by Narendra Sahoo, Founder and Director of VISTA InfoSec; and “Innovate Through Uncertainty by Managing Third-Party Risk,” by Alla Valente, Analyst at Forrester, cover the significance of SOC 2  for cloud service providers, vendors, and businesses, and the essential risk mitigation strategies for the value creation of the business, respectively.

Finally, the Cover Story of the issue titled, “How to Simplify Security and Compliance in the Cloud,” is about how Google is trying to simplify compliance for governments and the public sector in the cloud. It is written by Jeanette Manfra, Director for Government Security and Compliance, Google Cloud Office of the CISO.

We hope you enjoy reading the other articles and interviews in this issue as well.


Get your copy today: https://cisomag.com/magazine/

Endpoint Security SurveyWe invite you to participate in our year-end Endpoint Security Survey, the results of which will be shared in our December issue. Take Survey Now!

Endpoint Security

Marriott International Slapped with $123 Mn GDPR Fine for 2014 Data Breach

Marriott International’s Data Breach Exposes Records of 5.2 Million Guests

The U.K.’s Information Commissioner’s Office (ICO) imposed £18.4 million ($23.92 million) fine on Marriott International Inc. for violating the GDPR guidelines. The data privacy regulator stated that Marriott has failed to protect the personal data of millions of its customers. Around 339 million guest records worldwide were affected after a cyberattack on Starwood Hotels and Resorts Worldwide Inc. in 2014, remained undetected until September 2018, by when the company had been acquired by Marriott.

Attack Background

In 2014, an unknown attacker installed a malware code in the Starwood systems to obtain access to the contents remotely. With unrestricted access to the infected device, attackers distributed malware to other devices on the network to steal customers’ sensitive information. The exposed information included names, email addresses, unencrypted passport numbers, phone numbers, arrival/departure information, guests’ VIP status, and loyalty program membership number.

Related Story: Four Biggest GDPR Fines of 2020

Violation Penalty

The ICO’s investigation found that Marriott failed to put appropriate security measures to protect its customers’ data being processed on its systems, as per the GDPR.

In July 2019, the ICO issued Marriott with a notice of intent to fine up to £99,200,396 ($123 million) for violating the data breach regulations. However, the regulator decreased the penalty amount considering the economic impact of COVID-19 on their business.

Information Commissioner, Elizabeth Denham said, “Personal data is precious, and businesses have to look after it. Millions of people’s data was affected by Marriott’s failure; thousands contacted a helpline and others may have had to take action to protect their personal data because the company they trusted it with had not. When a business fails to look after customers’ data, the impact is not just a possible fine, what matters most is the public whose data they had a duty to protect.”

Related Story: Marriott International faces $123 million GDPR fine