Home Blog Page 154

Google is the Monopoly Gatekeeper to the Internet, says DoJ

Google

The U.S. Department of Justice (DoJ) filed a civil antitrust lawsuit against Google for unlawfully maintaining monopolies via anticompetitive practices in the search and search advertising markets. The lawsuit, filed in the District Court of Columbia, alleged that the search engine has reported over 90% of all search queries in the U.S. and used anticompetitive techniques to retain its monopolies in search and online search advertising.

“Google is the monopoly gatekeeper to the internet for billions of users and countless advertisers globally,” the DoJ said.

The lawsuit also claimed that Google has undergone several agreements that closed new opportunities to other search engine companies. Google has set as the preset default general search engine on billions of mobile devices barring its competitors.

According to the DoJ, Google illicitly maintained monopolies in search and search advertising by:

  • Entering into exclusivity agreements that forbid preinstallation of any competing search service.
  • Other arrangements that force preinstallation of its search applications in prime locations on mobile devices and making them undeletable, regardless of consumer preference.
  • Entering into long-term agreements with Apple that require Google to be the default – and de facto exclusive – general search engine on Apple’s popular Safari browser, and other Apple search tools.
  • Generally using monopoly profits to buy preferential treatment for its search engine on devices, web browsers, and other search access points, creating a continuous and self-reinforcing cycle of monopolization.

Attorney General William Barr, said, “Millions of Americans rely on the Internet and online platforms for their daily lives.  Competition in this industry is vitally important, which is why today’s challenge against Google — the gatekeeper of the Internet — for violating antitrust laws is a monumental case both for the Department of Justice and for the American people. Since my confirmation, I have prioritized the Department’s review of online market-leading platforms to ensure that our technology industries remain competitive.  This lawsuit strikes at the heart of Google’s grip over the internet for millions of American consumers, advertisers, small businesses, and entrepreneurs beholden to an unlawful monopolist.”

“As with its historic antitrust actions against AT&T in 1974 and Microsoft in 1998, the Department is again enforcing the Sherman Act to restore the role of competition and open the door to the next wave of innovation this time in vital digital markets,” said Deputy Attorney General Jeffrey A. Rosen.

Take a Unified Approach to Secure Your Software

Your software defines your business. It’s what sets you apart, but it’s also what can bring your organization down if it’s not secure. There’s a constant conversation around the need for a unified approach to software security. That’s really what DevSecOps is all about—and yet, the current AppSec model is anything but collaborative.

By John Worrall, CEO, ZeroNorth

This schism between security teams and developers, this cultural divide, comes into play primarily in the way it affects our ability to rapidly build and deliver secure products. CISOs and product security leaders must be able to answer the question, “Who owns security?” And the answer can’t just be “I do.” Even though DevSecOps promotes a mindset of shared responsibility, without accountability and executive-level support, “everyone” owning security can quickly lapse into “no one.”

And without this critical piece lodged firmly in place, there’s still lots of work to be done.

Dealing with Misalignment

Some valuable data has recently come out on this cultural divide between security and development. 77% of developers say this existing gap affects their ability to meet deadlines, while 70% of AppSec professionals say this misalignment puts the security of applications at risk.[1]

Both teams admit that working together is a challenge. When asked to rate the difficulty in working together on a scale of one to 10, 69% of developers and 66% of AppSec professionals rank it as 10 — extremely difficult. Their differences don’t end there. They don’t agree on the scope of the problem. Only 35% of developers say application risk is increasing, while 60% of AppSec professionals believe this to be true.

Different teams, different priorities, different perspectives. This means it’s not technology or even systems getting in the way — but people. Before you can even think about investing in new technology or expanding your AppSec program, you need to get your people aligned.

This starts by bringing business, security, and product team lead together to lay the groundwork. Level-set on the need for an alignment plan focused on collaboration and accountability to ultimately ensure secure software development. Discuss the importance of clearly defined and aligned objectives, ways to achieve them through incentives and SLAs, and how technology can support this people-centric approach. Then, you’re ready for step one: figuring out exactly who owns what.

Governance and Operations (Who owns what?)

Much of today’s fragmentation stems from a fundamental disagreement around responsibility for application security. The same industry study found 39% of developers believe their security is responsible, while 67% of AppSec practitioners say they are responsible. Who’s going to set up the policy? Who’s going to measure its performance? Who’s going to drive continuous improvement?  And then, who’s actually going to create secure code?

Who does what is important. This may look different from organization-to-organization, but the majority of businesses I’ve spoken with have adopted a hybrid model, where security is responsible for governance; development is charged with implementation. Security teams set standards, measure performance to standards, and work with all levels of the organization to communicate the current risk status and the progress of improvement initiatives. The most mature security teams have evolved the role of security champions from blockers to enablers, becoming advisors and coaches to the development teams.

In regulated industries with heavy compliance requirements, the governance function is particularly critical. Yet in many companies, DevOps and security teams still operate in isolation until the very end of the software development lifecycle, with developers moving fast to push out new code, only to be stopped in their tracks due to late-breaking reports from security on discovered vulnerabilities or quality issues.

With so much at stake, these regulated industries must adopt a governance model that gives security teams enterprise control and a global view of risk to meet consistent security and compliance standards. Yet these centralized policies must be enacted locally to empower developers to rapidly and securely deliver innovation. This flexibility makes it easier to incorporate tools that allow developers to fix issues while they’re coding.

Within this framework, developers can operate within their existing, preferred workflows (or choose their own security tools, if they want), while ensuring all tools and workflows contribute to a centralized, prioritized view of risk across the entire application portfolio. With one source of truth that is reported on, and trusted by, all parties, organizations can pinpoint key gaps and continuously improve the enterprise security posture.

Unification is the Key

Research tells us, there’s much work to be done to tear down siloes, reshape mindsets and unify teams. As companies accelerate their shift toward DevOps, this cultural disconnect will continue to expand until organizations find a way to bring security into the DevOps world. I believe unification is the only way organizations can make this reality.

Embracing the right technology platform will help accelerate this unification effort and make a shared responsibility model work in three key ways:

  • Provides the necessary structure. By activating unified, enterprise standards, policies, and analytics that power continuous risk and compliance enforcement, organizations can innovate with confidence.
  • Accelerates pipeline velocity. By orchestrating the continuous discovery and remediation of vulnerabilities across the SDLC, security and product teams can collaboratively accelerate application delivery.
  • Unburdens developers. By making AppSec programs transparent and friction-free, developers can meet corporate standards without changing their workflows or being flooded with non-priority tickets and issues.

Security Leaders at the Finish

You’ve aligned on objectives, crystallized responsibilities, and established a framework. Now, where do you go from here?

All team leads must agree to do their prescribed parts to make DevSecOps a reality. This requires a unified management approach, based on a shared desire to deliver secure software, define and support software security standards and hold themselves, and their teams, accountable. Yet every major organizational change initiative must have a champion.

CISOs are uniquely positioned to spearhead this unification effort at the management level and serve as “coach” for development teams, motivating them to prioritize security, improve practices, and embrace a more collaborative culture.

It will take more than good intentions, however, to move the needle. The same research shows lip service won’t get you far: nearly half (48%) of developers say their leadership teams are already trying to improve teamwork. An organizational shift of this magnitude also requires the right tools and processes in place to centralize AppSec management, orchestrate disparate security tools, automate manual processes, surface actionable intelligence, streamline remediation and deliver robust analytics and reporting. This is where CISOs need to take the reins, architecting an AppSec program that enables developers to drive security within their teams on a continuous basis and aligns security with the pace of development. In doing so, they will bring value to the executive leadership team and the business as a whole.

Software security is too important to get wrong. The time is now to get it right. It will take a commitment from all sides to build this type of shared vision for the future. Once all parties realize application security vulnerabilities put the business at risk in the same way as financial or market risk, they’ll hopefully begin to see the light — and to promote a vision of shared responsibility for the good of software.


References: [1] Revealing the Cultural Divide Between Application Security and Development


About the Author

John Worrall is CEO of ZeroNorth in 2019 as chief executive officer, leading the company in its delivery of the only platform for risk-based vulnerability orchestration across applications and infrastructure. As CEO, John heads up all aspects of the company’s strategy, product, operations, and go-to-market functions. In addition to leading ZeroNorth, John serves on the Board of Directors at FamilyAid Boston, a nonprofit that helps children and their parents facing homelessness in Greater Boston. He holds a bachelor’s degree in economics from St. Lawrence University.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

$1Mn Fund Booster Announced to Help Pandemic-Affected Organizations

Complete the Endpoint Security Survey and win lots of amazing goodies! Take the Survey Now!!!

The COVID-19 pandemic has brought to the fore the emergence of new cybersecurity threats to organizations of all sizes. It is worth noting that at a given time when the economic conditions of businesses have taken a beating, constrained budgets for technology and cybersecurity areas have become predominant around the globe. Thus, to help such organizations in regrouping and building their cyber resilience, Cybersecurity Collaborative, in association with its parent company, CyberRisk Alliance, announced a $1 million fund to assist them.

What this Means

The primary beneficiaries of this fund are organizations whose cybersecurity resources have been impacted inadvertently by COVID-19. The fund includes a limited number of complimentary memberships for academic and public sector organizations. The Cyber Resiliency Fund is intended to help companies better their cybersecurity operations by providing them immediate access to essential cybersecurity resources and tools — against widely exploited threats such as ransomware, phishing, and worms. Some tools also help in securing work-from-home environments. Additionally, it has also made grants available to commercial sector organizations at a subsidized first-year membership (50% of the total dues) in the Cybersecurity Collaborative group.


CISO MAG Endpoint Security SurveyComplete the Endpoint Security Survey and win lots of amazing goodies!

Take the Survey Now!!!


Perks of Cybersecurity Collaborative

Cybersecurity Collaborative provides members a wide range of strategic, technical, and leadership development benefits, including access to a private library of over 150 CISO-developed policy documents and guidance frameworks. It enables the members to consult a “CISO Rapid Response Team,” which gives advice on real-time business issues. The organization is led by an executive committee comprising of leaders from respected companies with exceptional cybersecurity operations background, including YUM! Brands, Kirkland & Ellis LLP, American Family Insurance, JP Morgan Chase, and others.

Related News:
Cyber Resilience is a Fork in the Road for Remote Workforce

The new fund is supported by CyberRisk Alliance, an integrated provider of content, event, digital media, and peer collaboration services to the cybersecurity community. John Whelan, CyberRisk Alliance President said, “Helping cybersecurity leaders raise the effectiveness of their operations is central to our mission. We recognize that it is a difficult time for many organizations to invest in new cybersecurity resources. Thus, we are pleased to offer this fund to make the Collaborative’s important services more accessible.”

The Cyber Resilience Fund grants for strengthening cybersecurity operations are available through December 31, 2020. Technology and security leaders interested in applying on behalf of their should contact the CyberRisk Alliance here.

Related News:
New Bill Grants US$400 Million to Address Cybersecurity Risks in the U.S.

 

Why the Public Sector is Most Worried About Cyberattacks

Misconfigured Cloud Storage Services Led to Over 200 Breaches in Past Two Years

A survey from cybersecurity firm Netwrix revealed that the public sector is extremely concerned about a variety of cyberattacks. Nearly 88% of government enterprises said that cloud misconfiguration is a top security threat, while only 25% said it was critical before the pandemic. It is found that 11% of security incidents reported during the first three months of the pandemic were caused due to cloud misconfigurations.

When asked about other attack vectors, 98% of respondents said they are concerned about supply chain compromise at present; 95% named VPN exploitation as a major threat, and 82% cited credential stuffing attacks. In addition, most incidents during this time include the human factor (53%) and 18% of respondents reported insecure sharing of sensitive data. Improper data sharing becomes a challenge for most government organizations, with organizations taking days (42%), weeks (32%), or even months (21%) to detect it.

Other Findings

  • 29% of government agencies feel that they are at greater security risk now than they were before the pandemic. 86% of them are worried about stronger or more frequent cyberattacks, which is the highest percentage among all the verticals studied in the report.
  • Concern about VPN exploitation grew from 10% pre-pandemic to 95% now.
  • 26% of government agencies reported experiencing ransomware or other malware.
  • 6% experienced data theft by employees. None were able to spot it in minutes and only 5% were able to flag the incident in hours. The rest (95%) required days, weeks, or months.
Related Story:

“Government agencies should focus their cybersecurity efforts on mitigating the insider threat, especially when many employees and contractors are accessing the networks remotely. Organizations must ensure that every user understands basic cybersecurity rules and completes security training on a regular schedule. IT teams should look for solutions to speed threat detection and streamline incident investigation. In addition, they should follow proven security best practices like network segmentation, privilege attestation, continuous auditing for malicious activity across data repositories, and alerting on suspicious activity and changes,” said Ilia Sotnikov, VP of Product Management at Netwrix.


Complete the Endpoint Security Survey and win lots of amazing goodies!
Take the Survey Now!

 


 

New Code of Ethics “ethicsfIRST” Shines its Light on Global Ethics Day

Global Ethics Day

“Global Ethics Day” is celebrated on the third Wednesday of October across the world. This year it is celebrated on October 21, 2020. Founded by Carnegie Council in 2014, it was instated to inspire and make people aware about the role of ethics in a globalized world. Following this inspirational lesson, the Forum of Incident Response and Security Teams (FIRST) has now decided to implement “The Code of Ethics” in the digital world. After doing a global consultation, FIRST is launching the new ethics guidelines for incident response and security teams called “ethicsfIRST. This code of ethics provides guidance for cybersecurity professionals on how to conduct themselves professionally and ethically during incidents.


CISO MAG Endpoint Security SurveyComplete the Endpoint Security Survey and win lots of amazing goodies!

Take the Survey Now!!!


What is “ethicsfIRST”

Developed by the FIRST Ethics special interest group, the ethicsfIRST framework covers a list of principles that explains how to apply each one. Every principle details the responsibility of a cybersecurity professional during an incident to ensure that the interest of the public is always at the core. Each principle has been thoroughly reviewed by senior practitioners and is based on real-life scenarios.

The ethicsfIRST website was developed and supported by diverse members of the FIRST community to empower security teams in handling difficult ethical situations in a confident and methodical manner. Some of the principles of ethicsfIRST seek to reinforce the duties of trustworthiness, coordinated vulnerability disclosure, authorization, team health, and recognition of jurisdictional boundaries, among others.

Jeroen van der Ham and Shawn Richardson, Ethics SIG co-Chairs of FIRST, stated, “Integrity and professionalism are paramount in our industry. The new ethicsfIRST principles were developed and examined by some of the world’s most senior cybersecurity experts with the aim of providing a universal language of how to deal with incidents and make the internet safe for everyone.”

Related News:
Ethical code crucial in digital age, survey says
Australia Introduces “Code of Practice” for All IoT Devices

Robinhood-like Ransomware Attacker Donates $20K to Charities

Robin Hood Like Ransomware Attacker Donates $20K to Charities

In a rather unexpected act, the operators of the Darkside ransomware group donated $20K from their ransom amount to two nonprofits charities. The threat actors claimed that they are planning to make more donations like this in future.

According to a report from the BBC, the hacker group posted payment receipts for $10,000 in Bitcoin donations to charities: Children International and The Water Project. Children International supports children, families and communities in India, the Philippines, Zambia, Colombia, Ecuador, the Dominican Republic, Guatemala, Honduras, Mexico, and the U.S., while The Water Project works to help improve access to clean water in sub-Saharan Africa.

“We think that it’s fair that some of the money the companies have paid will go to charity. No matter how bad you think our work is, we are pleased to know that we helped changed someone’s life. Today we sent the first donations,” the Darkside ransomware group said.

However, the Children International charity stated that they are not keeping the donations. “If the donation is linked to a hacker, we have no intention of keeping it,” the charity said.

The Flipside of Cybercriminals

Earlier, several ransomware groups came forward to assure that they would hold back from attacking health care organizations during the Coronavirus crisis. DoppelPaymer Ransomware, an infamous human-operated ransomware cybercrime group who stated that they usually avoid attacking hospitals and nursing homes, while also stressed that if they attack governments, they also don’t touch 911 even though emergency communications are hit due to network misconfigurations. They also stated that if any health care organization is hit by mistake, they would decrypt it for free. Maze ransomware authors also responded stating that, “We also stop all activity versus all kinds of medical organizations until the stabilization of the situation with the virus.”

Cybersecurity Approaches in the Coronavirus Era

For a world that is beset by numerous health and economic woes, one extra challenge seems anything but fair. But from the perspective of a cybercriminal, COVID-19 has opened a range of opportunities, a distraction that has caught victims off guard as they are forced to drastically change their usual working practices.

By Zak Gottlieb, Business Development Manager for Computers In The City

Firstly, there are the phishing, malicious domains, and online scams that exploit the fears of individual users by using virus-related keywords or claiming to be guidance or information from governments or medical authorities. These include emails that purport to be from the World Health Organization (WHO) with a link that initiates a malware download. According to Interpol, incidents of phishing, scam, and fraud increased by as much as 59% in the first four months of 2020.

Next, we must consider the en masse migration of millions of employees from a secure office location to working from home. This is a disruption that has given cybercriminals new possibilities in the methods and procedures they use. With a workforce of 348 working from home, Zaha Hadid Architects were victim to a security breach in April. With data backed up, the firm refused to pay the ransom and suffered minimal damage. But the same was not true of the University of California, which had its systems frozen by hackers and was forced to pay $1.14 million in bitcoin. The data that was seized included work on a cure for the coronavirus. In a 2020 mid-year report, BitDefender claims a year-on-year increase of 715% in ransomware.

Given this onslaught of new methods of cybercrime, businesses are advised to take their security measures to the maximum. It is a good idea to hire a reliable and trusted IT company specializing in IT security who can carry out all essential checks.

Cybersecurity Strategies

Employees working remotely can be more vulnerable to phishing, scams, and social engineering, but data from Orange Cyberdefense shows that the more serious attacks target remote access points and VPN gateways.

This shift in ordinary working arrangements has truly left the business and workforce in a completely different situation. In a recently created infographic, information is provided on the new trend, as well as the benefits, lifestyle advice, and useful cybersecurity tips.

For most businesses, security infrastructure is the first priority, yet human activity is still the cause of most breaches. Systems for monitoring and recovery are needed, as well as response teams that can effectively address a wide range of attacks.

Naturally, most businesses need to adjust to the larger remote workforce, which means hardware and software must meet company security standards for every employee. This has led to many businesses going through years of digital transformation in just a few short weeks – one of the few silver linings of the pandemic.

Many organizations adopt a zero-trust model of access, to ensure that users, devices, and applications will not be trusted by default. Another approach to take is the principle of least privilege, which allows only the minimal degree of access to the lowest possible number of users. With these approaches, verification comes before trust, and participants continually work as though there has been a breach.

Businesses can benefit from connecting with other organizations within the industry and sharing news and best practices. These include the Financial Services Information Sharing and Analysis Center (FSISAC), which allows fintech companies to collaborate on approaches to cybersecurity.

Cybersecurity Practices

Best practices vary depending on the size and nature of each organization, so it is important to develop a policy and set of procedures that are particular to your business.

Cybersecurity Policy

The global pandemic has changed everything and left us with different processes, architecture, and modes of working, so last year’s policy will probably need to be updated. Risk assessments can help to inform this, and enforcement mechanisms should be identified. Policies need to be clear and strictly followed throughout the organization.

Perimeter Protection

More remote connections leave a business more vulnerable to attacks. External perimeters can be protected by deploying Network Access Control (NAC) which can validate devices and promote security policies when connecting remotely. Detection and monitoring controls that are tested and proven can reduce the threat, as can limiting access to data.

Strengthen Endpoint Security

All devices must be checked for patches and protected against malware. Security software must be tested to ensure it is operational, then it can be used as part of a program for detection and monitoring.


Complete our Endpoint Security Survey and win lots of amazing goodies!

Take the Survey Now!


Remote Access Management

Multi-factor authentication (MFA) must be used as a minimum requirement for gaining access to VPN and other key software tools. There should be extra scrutiny of remote network connections, as well as IP whitelisting and limiting remote desktop protocol (RDP) access.

Collaboration Tools

Collaboration and workflow tools, as well as video conferencing tools, have been essential in 2020, but security settings need to be set to the maximum to avoid any potential breaches. Additional technologies can be used to improve operations, such as virtual reality and augmented reality.

Cybersecurity Incident Response Plan

If your business does not already have a cybersecurity incident response plan in place, then COVID-19 should make clear the need for one. If you already have an incident response plan, it should be updated to meet the current operational context. This can be coordinated with your disaster recovery and business continuity plans for consistency.

Employee Training

Members of staff should always be at the heart of cybersecurity policies and practices, and this should not be overlooked during the crisis. Employees need to be kept up to date with regards to current cyber threats, industry news, and any changes in protocol.

Now that most of us have become more adjusted to the new normal, we can expect the sharp rise in cybercrime to stabilize towards the end of the year. But even before coronavirus made its attack, cybercrime had been rising fast and demanding a greater commitment to security measures from businesses of all sizes. This means we need to be prepared for the worst in the future and show unwavering resilience.


About the Author

Zak GottliebZak Gottlieb is the Business Development Manager for Computers In The City, a London-based IT support organization focusing on small and medium-sized businesses. Zak is distinguished by his passion for cybersecurity, his focus on collaborative team-building, and his commitment to excellence.

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.


Related story: Cybersecurity Awareness – Act Now!

ESET and Credence Security Join Hands to Boost Cybersecurity in Middle East

U.S. and Australia to Jointly Develop Cyber Training Platform

IT security software and services provider ESET Middle East signed a strategic partnership deal with Credence Security to provide a series of specialized cybersecurity solutions, digital forensics, and GRC across the Middle East region. The new alliance creates additional opportunities for both the companies and helps to enhance their security solutions range across the region. Credence Security and ESET will work together to address certain security gaps and some of the industry-specific vulnerabilities across financial services, health care, and utility sectors.

The partnership integrates Credence Security’s technical expertise along with its extensive channel network and strong regional customer base, to further strengthen ESET’s stronghold and market dominance in the endpoint security space.

Commenting on the new partnership, Demes Strouthos, General Manager, ESET Middle East said, “ESET is the endpoint security provider in the EU and we believe that constant, real-time, multi-layered protection is required to assure the highest level of security. Our unique combination of endpoint-based and cloud-augmented technologies provide the most advanced security on the market. This partnership with Credence Security will act as a value-add for ESET Middle East, which will not only involve distribution through their extensive channel network but also extend to other areas such as technical competency and marketing to be perfectly responsive and ready for market needs and channel requirements.”

Garreth Scott, Managing Director, Credence Security, said, “EDR is a growing market in the region — we are seeing an increase in demand from our customers for an EDR solution and as a leader in this space, ESET helps address this gap in our portfolio.”

EC Council’s CISO MAG has planned a virtual roundtable engagement to create awareness on How Cyber AI Protects the Global Dynamic Workforce.

REGISTER HERE

NCSAM: Rushing Cloud Migration and Addressing Privileged Access Management

Privileged Access Management

Marking the National Cybersecurity Awareness Month (NCSAM), it is imperative that we assess the cybersecurity implications of COVID-19 and how several leaders had to expedite cloud migration plans due to the pandemic, and it is also important that we address problems surrounding Privileged Access Management (PAM). According to a recent survey by Centrify, a provider of Identity-Centric privileged access management solutions, nearly half of IT decision-makers’ companies had to accelerate their cloud migration plans (48%) and IT modernization overall (49%) during the COVID-19 pandemic.

The study also revealed that with the pandemic and shift to distributed workforces, 60% of companies had to review and adjust their cybersecurity postures and supporting tools. On the bright side, the challenges companies faced this year will have a positive effect on the cybersecurity workforce and IT budgets for the future, with 35% of respondents obtaining IT budget increases for 2021. With regards to headcount, it was revealed that 63% saw little to no impact on their teams.

Rushing toward cloud adoption also came with its own cup of risks. Research from IBM Security revealed that the ease and speed at which new cloud tools can be deployed can also make it harder for security teams to control their usage.

With businesses rapidly moving to the cloud to accommodate remote workforce demands, understanding the unique security challenges posed by this transition is essential for managing risk. While the cloud enables many critical business and technology capabilities, ad-hoc adoption and management of cloud resources can also create complexity for IT and cybersecurity teams. According to IDC, more than a third of companies purchased 30+ types of cloud services from 16 different vendors in 2019 alone. According to the IDC CloudPulse Summary Q119, this distributed landscape can lead to unclear ownership of security in the cloud, policy “blind spots” and potential for shadow IT to introduce vulnerabilities and misconfiguration.

COVID-19 and PAM

COVID-19 saw mass layoffs across several companies across the world. Several of these may have been employees with privileged access. It is also true that disgruntled employees are one of the biggest reasons for insider attacks.

“Losing employees with privileged access is not a problem if there are processes in place to understand who is accessing what, when, and from where. When someone leaves, it is simple to de-provision their access immediately and have a record that this has occurred. It is the role of the CISO to make sure that these policies and processes are in place, rigorously enforced, regularly reviewed, and updated as new systems are deployed across the corporate network,” said Laurence Pitt, Global Security Strategy Director at Juniper Networks to CISO MAG in a recent interview.

Best Practices to Keep in Mind During NCSAM

“NCSAM emphasizes on creating awareness about the importance of cybersecurity and helps available resources be safer and more secure online. With ‘Do Your Part. #BeCyberSmart,’ as the theme for the year, it reminds us that cybersecurity is a shared responsibility and each one of us has a role to play,” said Rohan Vaidya, Managing Director – India at CyberArk.

With remote working becoming the new normal, it has become a necessity for cybersecurity experts to provide guidance on the threats that pose the maximum risk to organizations and employees as well as ways to tackle them. Simple tips for securing their digital profile – from picking strong passwords and safeguarding connected devices with multi-factor authentication (MFA), to securing home networks and keeping software up-to-date really go a long way.

He added, “With remote working becoming the new normal, it has become a necessity for cybersecurity experts to provide guidance on the threats that pose the maximum risk to organizations and employees as well as ways to tackle them. Simple tips for securing their digital profile – from picking strong passwords and safeguarding connected devices with multi-factor authentication (MFA), to securing home networks and keeping software up-to-date really go a long way. Businesses must also do their part to make the digital world a safer place for customers, employees and partners. This begins with protecting access – especially privileged access – to their critical enterprise assets.”


Related story: State of Enterprise IT Landscape [INFOGRAPHIC]


Complete the Endpoint Security Survey and win lots of amazing goodies!

Take the Survey Now!

 

Notify Data Breaches Using New Zealand OPC’s NotifyUs

tech, tech provider

New Zealand’s Office of the Privacy Commissioner (OPC) launched a new data breach reporting tool “NotifyUs” to help organizations report data breaches and assess whether a security incident is notifiable or not.

The new online tool is launched ahead of New Zealand’s new privacy bill “The Privacy Act 2020,” which comes into effect on December 1, 2020. Under the new act, it is mandatory for organizations to notify the OPC if a breach occurs. Businesses which fail to report a notifiable breach to OPC may be penalized with a fine up to $10,000. “The Act strengthens privacy protections. It promotes early intervention and risk management by agencies (the name used for any organization or person that handles personal information) and enhances the role of the Privacy Commissioner,” an official statement said.

Privacy Commissioner John Edwards said, “We want the privacy breach pre-assessment and reporting process to be straightforward. NotifyUs has undergone extensive testing ahead of today’s launch to ensure the guidance is clear and easy to follow. I encourage people to use it in advance of the new legislation taking effect on 1 December.” 

Cyberattacks on New Zealand

Recently, the New Zealand Stock Exchange NZX Ltd. went offline for three days in a row due to a blow of successive cyberattacks. In a security alert, the bourse operator said that initially it had been hit by a distributed denial of service (DDoS) attack on August 25, 2020, from offshore, via its network service provider. The attack impacted the exchange’s network connectivity systems, including NZX websites and the markets announcement platform.

Earlier, a survey revealed that 45% of the companies in New Zealand rated themselves as not secure against cyberthreats; 50% of the firms claimed that they lack in cybersecurity confidence. Most of the businesses are not able to protect their company’s data when their employees are working remotely.

To address the surge in malware, phishing, and DDoS attacks, EC Council’s CISO MAG has planned a crisp half day virtual engagement, The Australia CISO Confluence, to create more awareness on the need for cybersecurity and its related implications in these testing times. Register Here

Australia CISO Confluence