Home Blog Page 158

Are You Cyber-aware? EC-Council’s Aware App Gamifies Learning

Ec-Council-Aware App

The world is reforming. Technology has become an integral part of our lives and businesses are undergoing a radical digital transformation. And digital transformation brings with it an array of cyber risks. CISOs and security professionals are always on the go to confront cyberattacks or data breaches. A joint study from Stanford University Professor Jeff Hancock and security firm Tessian revealed that 88% of data breach incidents are caused by human error. So, what is the best way to create a cyber-aware environment?

By Pooja Tikekar, Feature Writer, CISO MAG

Recently, EC-Council launched its cybersecurity training solution, Aware. Aware is a user-friendly and easy-to-access training app that helps end-users understand security risks on a cyber battlefield. Aware is for all in the organization — C-levels, managers, executives, employees, contractors, temporary workers — who are looking for information to defend their organizations from cyberattacks.

EC-Council Aware is available on Android and iOS platforms. The setup does not require technological acumen, and users can Sign Up to create a new profile or use their existing social media profiles (Google, Facebook, and LinkedIn).

Aware’s Salient Features

  • Automatic Enrolment: Users will be automatically enrolled in the training they need based on their success during phishing simulations.
  • Upload Your Training Content: Once an organization is registered, the admin is authorized to upload training videos/modules, limit no bar. The training modules are required to be SCORM-compliant (Sharable Content Object Reference Model). Organizations can also add a company logo to the training videos/modules, which would help in branding and promotion.
  • Customizable E-learning Content: Users can customize their training programs to suit their requirements.
  • Scheduled Reminders: To ensure the completion of training, the app sets deadlines and reminds users of the timeframe they set in the beginning.
  • Advanced and Automated Reports: Aware’s advanced reports helps users know how well they are performing on phishing simulations and testing, and more. Reports can be generated using the in-built templates to keep the teams/staff informed about the areas they need to improve on.
  • Customizable Training Certificates: Complete the training and voilà! Aware pats your back with a Certificate of Training with customizable text options.

Learn with Fun

Science has proved that learning is fun. And the idea of having fun while learning makes information processing an enjoyable experience. Do you remember the last time you sat down to hone your skills at work?

EC-Council Aware makes learning fun and effective. It is power-packed with challenging games and quizzes to offer its users a memorable screen time. Users can choose from millions of live games and host quizzes on the go, in the classroom, or at parties. Teachers can now save time and assign homework using creative challenges and track learning progress.

The app also offers premium plans —  Aware! Plus and Aware! Pro — for corporate trainers to engage in exciting remote training.

An Assembly for All

Creativity, trivia, and training, EC-Council Aware is a cyber assembly for everyone. It nurtures a cyber-aware culture to better understand cyberthreats and their potential to incapacitate a business and its information assets. In tough times like the pandemic, raising appropriate awareness about ransomware or phishing is a must. It’s more important than ever to encourage collective effort to minimize the risk of cybercrimes.

And with the Aware app, organizations can not only train employees but also pave the way to a compliant digital future. #BeCyberSmart

Put on your quizmaster hat and download EC-Council Aware from the Google Play Store or Apple Store. For more information, visit https://aware.eccouncil.org.

About the Author

Pooja Tikekar is a Feature Writer and part of the editorial team at CISO MAG. She writes news reports and feature articles on cybersecurity technologies and trends.

More from the author.

 

NCSAM: Hybrid Workforce and its Cybersecurity Implications

In an interview at the TIME100 Honorees: Visions for the Future event, Alphabet CEO Sundar Pichai said “We firmly believe that in-person, being together, having a sense of community is super important when you have to solve hard problems and create something new so we don’t see that changing. But we do think we need to create more flexibility and more hybrid models.” It is safe to say that the pandemic has changed the workforce for good, and a hybrid model— a blend of both remote and in-office methods of working, will eventually take precedence. But the security of a hybrid model is still a far cry. During this year’s National Cybersecurity Awareness Month, let us look at how the changing workforce dynamics will change cybersecurity for good.

In its 17th year, National Cybersecurity Awareness Month (NCSAM) continues to work towards raising awareness about the importance of cybersecurity globally, ensuring that every nation has the required resources to be safer and more secure online. With this year’s theme as ‘Do Your Part. #BeCyberSmart’, each one of us needs to cooperate and work towards a cybercrime free world.

 

– Anil Bhasin, regional vice president, India & SAARC, Palo Alto Networks.

Cybersecurity has become a critical part of our lives, especially with the COVID-19 pandemic forcing us to accept the new normal, its importance has risen more than ever, everywhere: in organizations irrespective of its size, government offices to the individual home user.”

According to a study by cybersecurity firm Tessian, half of all the organizations experienced cybersecurity incidents during the remote working period. In its research titled, “Securing the Future of Hybrid Working,” Tessian also noted that phishing remained the most prevalent threat facing employees working remotely. The study also noted that working in an office five days a week will be “a thing of the past.” According to the majority of IT leaders surveyed, three-quarters of IT decision-makers (75%) believed the future of work will be “remote” or “hybrid” — where employees choose to split their time between working in the office and anywhere else they’d like. The study also found that most employees prefer hybrid working environments, with just 11% exclusively preferring office work.

Tim Sadler, CEO and Co-Founder of Tessian noted, “While remote working was an option for some employees pre-pandemic, and while some companies are more familiar with flexible working arrangements, not all employees got to experience it because of scheduling and business demands which meant they still needed to physically be in the office. Now, the majority of office workers are working from home. And it’s going to be hard for businesses to justify why their workers need to come into the office every day of the week, post-pandemic.”

Sleepless Nights for IT Leaders

Tessian also derived the findings from its previous survey titled “The Psychology of Human Error,” where it revealed that 43% of employees had made mistakes that led to security incidents, in turn jeopardizing the organization’s cybersecurity. Due to this trend, IT leaders now (from the current research) fear employees’ unsafe data practices could compromise their company’s security and lead to more data breaches and phishing attacks.

The “Securing the Future of Hybrid Working” study also revealed that 43% of security incidents that occurred between March and July 2020 were caused by malicious insiders and over a quarter of businesses (27%) experienced more security breaches caused by insider threats during this period, compared to the five months before the pandemic. It also revealed a 25% increase in the number of employees attempts to exfiltrate data to unauthorized email accounts between March to July 2020, compared to the five months prior.

Ransomware Attacks Continue to Loom Over Cyberspace

Ransomware attacks, ransomware, Sinclair Broadcast group

A report from global investigations firm Kroll revealed that ransomware attacks were the most observed security threats in 2020, accounting to one-third of all cyberattacks as of September 1, 2020. It highlighted that the impact of rising ransomware attacks on organizations globally of all sizes and sectors, with IT, professional services, telecoms, and health care sectors being the most targeted and affected.

Common Attack Gateways

Kroll stated that in most of the ransomware incidents, attackers leveraged Open Remote Desktop Protocol (RDP) (47%), Phishing (26%), Vulnerability Exploits (17%), and Account Takeovers (10%). Attackers exploited Microsoft’s proprietary network communications protocol, Citrix NetScaler CVE-2019-19781, and Pulse VPN CVE-2019-11510 vulnerabilities to compromise user accounts. Besides ransomware, business email compromise (BEC) attacks remain a top threat for organizations globally followed by Unauthorized Access, Web Compromise, Malware attacks.

Image Courtesy: Kroll

 

Top Ransomware Variants

Ransomware such as Ryuk, Sodinokibi, and Maze are the most observed variants so far in 2020, according to Kroll’s report. “After launching several high-profile attacks earlier in 2020, the actors behind Ryuk ransomware seem to have gone on a hiatus near the end of Q2. However, in Kroll’s experience, crimeware and their developers often have periods where they go dormant or spend time re-tooling, followed by a resurgence of activity,” Kroll said.

Ransomware actors target victims by encrypting their sensitive files, paralyzing operations, and demanding high ransoms. Kroll observed a new tactic of attackers threatening victims by posting the stolen data on darknet forums. Around 42% of ransomware variants are connected to a threat group actively exfiltrating and publishing victim data on the dark web.

Devon Ackerman, Managing Director and Head of Incident Response, North America, said, “While actors say they will delete data upon payment of the ransom, recent events belie that claim. Rogue members of ransomware groups have approached and demanded a second payment from at least two victims who had already paid a ransom. When one of the victims balked at paying the second time, the data, which was supposed to be destroyed upon the first payment, ended up on an actor-controlled site.”

McAfee’s Latest SaaS-based Suite Delivers Unified Cybersecurity Solution

SaaS

McAfee, a cybersecurity company providing device-to-cloud solutions, has extended its MVISION product’s portfolio and now extends cybersecurity for all – endpoints, web, and cloud. With the three-all-in-one software-as-a-service (SaaS) solution offering, these suites will help those customers adopting a cloud-first stance and desire a simplified solution for device-to-cloud protection.

What’s more? All three suites include McAfee MVISION Insights, which lends a proactive and actionable threat posture capability that prioritizes risk, predicts the success of countermeasures, and prescribes remedial actions to its customers.

McAfee’s MVISION Suite

The tag line of MVISION suite, “Stop more, manage less, and protect uptime,”  perfectly sums up what the suite does. It allows users to stop a greater number of attacks and empowers them to do so with the least number of tasks to manage thereby protecting their uptime.

In recent months, the very definition of the workplace has expanded.  Thus, McAfee observed a need for a device-to-cloud suite, which would help ensure visibility, and the ability to control and effectively manage cybersecurity across hybrid IT environments. McAfee’s device-to-cloud suite options include:

  • MVISION Advanced: A proactive endpoint threat prevention solution that renders next-gen defense mechanisms and rollback remediation features to protect against the latest forms of ransomware and other advanced malware.
  • MVISION Premium: An endpoint and data protection solution that takes the help of an AI-powered Endpoint Detection and Response (EDR) and Data Loss Prevention (DLP Endpoint), to defend devices and data from advanced attack vectors.
  • MVISION Complete: This is McAfee’s unified endpoint security portfolio with MVISION Unified Cloud Edge, that combines McAfee’s Secure Web Gateway (SWG), advanced DLP, and Cloud Access Security Broker (CASB) to deliver complete device-to-cloud protection. MVISION Complete enables organizations to better safeguard their digital transformation efforts and distributed workforce, with unified threat and data protection across all threat vectors – endpoints, web, and cloud.

Related News:
McAfee Consumer Security Portfolio Integrates Social Media and Tech Scam Protection
McAfee Report Predicts 2020 to be Year of Mobile Sneak Attacks

McAfee’s Device-to-Cloud Solution is a Boon

McAfee’s MVISION portfolio has a booster shot with the release of these newly designed suites. It provides security that spans across devices, networks, and clouds. If we dissect it further, McAfee’s device-to-cloud solution provides simple cloud management with better visibility and control; automated responses and updates that increase staff productivity; and unified policies on endpoints, web, and cloud that help lower the total cost of ownership at a time where many organizations are looking to trim budgets.

Anand Ramanathan, Vice President of Product Management, McAfee, said, “Customers are facing a rise in cyber activity that can expose them to damaging threats. At the same time, they are struggling with control, management, and visibility across their organization as they enable their teams to work from anywhere. McAfee device-to-cloud suites provide all-inclusive security that sits alongside an organization’s device and cloud footprint, offering the end-to-end protection that dynamic modern environments need today – and for what may lie ahead.”

These newly launched solutions will be showcased as part of MPOWER Digital 2020, which is McAfee’s virtual event to be held from October 29 through November 13, 2020.


**Disclaimer**
CISO MAG did not evaluate the products mentioned in this news report. Facts mentioned here were drawn from a McAfee Press Release and CISO MAG shall not be held liable for any discrepancies, inconsistency, and performance claims of this product.

 

Find the Fake! Disinformation Cited as Biggest Cybercrime Concern

ProxyShell Vulnerabilities

Misinformation is a greater concern than other online security risks like cyber bullying or fraud schemes, according to Lloyd’s Register Foundation World Risk Poll. The online poll, which conducted more than 150,000 interviews across 142 countries, found that 57% of internet users believe fake news was the biggest threat, followed by online fraud (45%), and cyberbullying (30%).

According to the survey, Western Europeans are most concerned about online fraud, including two-thirds of internet users in Portugal (78%), France (74%), Spain (71%), the U.K. (69%) and Italy (67%). It revealed that concerns about cyberbullying are high in low-income economies, with young internet users more likely to worry about online bullying than older users.

Professor Richard Clegg, Chief Executive at Lloyd’s Register Foundation, said, “A crucial part of making the world safer is understanding the range of risks that people face and how they view them. The Lloyd’s Register Foundation World Risk Poll provides the first global picture of how the world’s citizens see risk and safety and the differences between perception of risk and actual experience. This brings a new depth to our understanding of risk. They were interviewed face to face in the majority of cases, including in some of the most remote and challenging parts of the world. Their responses give us a window into lives in which danger and the threat of injury, and sometimes death, are an everyday part of life.”

Online Frauds Surged During Lockdown

Action Fraud, the U.K.’s National Fraud and Cybercrime Reporting Center, reported that consumers have lost more than £17 million (US$21 million) to online frauds during the COVID-19 lockdown. It received multiple reports of online shopping frauds since March 2020, affecting over 16,352 online shoppers. It was found that young shoppers aged between 18 to 26 are the most affected (24%). Read the full story here.

Cyber Resilience is a Fork in the Road for Remote Workforce

Let’s face it, your network perimeter has changed for the foreseeable future and maybe forever.  Remote workforce has become the new normal. What is worse is remote workers are working out of poorly secured network environments, and they are sharing these environments with vulnerable devices like unpatched routers, mobile devices, and Smart TVs. “There is no more chaotic time on the internet than right now,” said a security researcher during the Kaspersky Security Analyst Summit. Attackers, like the invisible coronavirus, thrive on chaos.  They love to sneak in under the cover of darkness to kick us when we are down and stressed out.  Uncertainty and confidence don’t make the best bedfellows.

By David Hillman, Senior Security Consultant, Securicon

Criticality of Cyber Resilience for Remote Workforce

According to a March 2020 Gartner’s pandemic preparedness study, many organizations and their leaders are unsure whether their risk mitigation strategy is sufficient. One area of particular concern is operational resilience. Many security leaders are getting even less sleep because they are thinking of the potential fallout if a critical piece of network or VPN technology fails and their people are cut off from the resources they require to do their jobs remotely. Not being able to access the systems which keep an eye on security could spell disaster.

COVID-19 is now amusingly being referred to as the greatest change agent in the history of the internet. It is the straw that breaks the camel’s back for those that are unprepared.

In a recent survey conducted by industry group YL Ventures, VPNs and DDoS mitigation have come up as issues that CISOs are very concerned about. This is a justifiable concern because the shift to work from home (or anywhere) has now placed many enterprises in the unenviable position of being service providers to their own workforce. DDoS vulnerabilities that would have impacted business continuity are now being proactively looked at. Non-critical network activities are now being cut off. The business continuity concern is so great that organizations such as the Department of Defense (DoD) have had to block YouTube and other social media activities from their networks. COVID-19 is now amusingly being referred to as the greatest change agent in the history of the internet. It is the straw that breaks the camel’s back for those that are unprepared. Change is hard, but inaction can be deadly, both from a network resiliency and a health standpoint. So, what should organizations focus their energies and investments on?

Integrative Problem Solving is the New Norm

How about a better response system based on a combination of best practices and training?  Until a few years ago, only backups and disaster recovery were considered as integral parts of the response system that would help the business maintain or recover normal business operations. COVID-19 has added an extra dimension to this problem. However, this should come as no surprise because according to the Center for Financial Professionals (CeFPro), the operational risk landscape has changed tremendously over the last ten years.

Collaboration is in and silos are out.

Smart organizations that are reporting no significant impact during the coronavirus pandemic have already shifted to more holistic risk management practices and are paying closer attention to emerging trends. Collaboration is in and silos are out. Infrastructure groups are now encouraged to learn from software development groups. Integrative problem solving is the new norm. Terms like automation and DevOps are being whispered in boardrooms. Even regulatory bodies are placing more focus on enhanced standards for operational resilience through better network intelligence, problem identification, and mitigation.

How to Improve Operational Resiliency

Some organizational leaders have expressed concern there is not enough guidance from the regulatory bodies on how to deal with resiliency from an operations perspective. In that case, an approach that could work is to create an action plan which consists of taking high-level best practices from something like the NIST Cyber Security Framework and combining them with vendor-provided recommendations to create a hybrid organizational framework for dealing with the problem of operational resiliency. Vendors such as Cisco have published their Service Provider Infrastructure Security whitepaper. Utilizing a six-phase approach to service provider security, the whitepaper talks about a framework for deploying edge security systems in a resilient way. These six phases are:

  1. Preparation
  2. Detection
  3. Classification
  4. Traceback
  5. Mitigation
  6. Post-mortem

Designed specifically to counter DDoS attacks in service provider type networks, the framework provides a “good overall approach to securing service provider environments.”  Despite being geared towards Cisco edge equipment, these recommendations can be adapted to vendors such as Palo Alto Networks and Juniper Networks. Some surveys suggest that organizations are only utilizing 20% of the total capabilities of their network equipment when it comes to guarding against DDoS attacks. Most of this is due to the lack of training and unfamiliarity with these features. That must change if critical networks are to become more resilient.

Q’s to Ask for Becoming a Hero in Operational Resiliency

When the features are already available, even a modest increase in spending on training and awareness can result in huge gains – sometimes up to 30% – in operational resiliency.

Going from zero to operational resiliency hero does not have to involve ripping out what is already in place to replace it with something bigger. It just takes security leaders to ask the right questions, such as:

  • Does our current equipment have features such as Packet Buffer Protection to guard against DDoS attacks?
  • What would it take to enable those features?
  • What are the risks involved if we do enable the extra protection features?
  • Why haven’t those features been enabled before?

Nine out of ten times, security leaders will find these advanced features not been enabled because their operations people either are not aware of them or have not been properly trained on how to make use of those features. In the same 2020 Gartner study, it was mentioned security leaders are putting training on the back burner to focus on network availability and VPN connectivity instead. This will not work in the new era of holistic, integrative network security, and cyber resiliency – continuous training and skills development must be part of the prescription.

About the Author

David HillmanDavid Hillman, who is currently working as a Senior Security Consultant with Securicon, has more than five years of experience in designing, testing, and deploying network security solutions.  Mr. Hillman has led and/or participated in the development of security architecture and policy framework solutions for many complex projects. That includes experience in implementing information technology (IT) solutions to ensure compliance with audit requirements, deployment of Supervisory Control and Data Acquisition (SCADA) firewalls for segmentation, and he has also built, tested, and installed large-scale packet capture solutions.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and our publication does not assume any responsibility or liability for the same.

Q3 2020: COVID-19 still Top Trending

coronavirus, covid-19

Even into the third quarter of 2020, organizations and enterprises continue to be plagued by ransomware and phishing attacks with subject lines on COVID-19. The Q3 2020 Top-Clicked Phishing Report by cybersecurity firm KnowBe4, highlighted that simulated phishing tests with a message related to the coronavirus was the most popular one, with a total of 50% of tens of thousands of email subject lines that the firm examined.

Another key highlight from the study was that social media messages were another area of concern when it came to phishing, where LinkedIn phishing messages dominated as the top social media email subject to watch out for, holding the number one spot at 47%.

“During this pandemic, we’ve seen malicious hackers preying on users’ biggest weak points by sending messages that instill fear, uncertainty and doubt,” said Stu Sjouwerman, CEO, KnowBe4. “Our Q3 report confirms that coronavirus-related subject lines have remained their most promising attack type, as pandemic conditions weaken judgment, and lead to potentially detrimental clicks.”

The scenario sheds its light on a dire state of affairs where the pandemic continues to be relevant for all three quarters of the year, and may even continue to be a part of the last quarter, if not more. From the onset of the pandemic, Malware and Ransomware campaigns targeting individuals and enterprises rose to alarming levels. An earlier survey from Bitdefender pointed out that 86% of security pros believed common attacks rose during COVID-19. According to the study, 50% of infosec professionals did not have a contingency plan to face a situation like the COVID-19 pandemic. The survey stated that lack of forward planning from organizations resulted in a surge of cyberthreats.

Earlier this year, a hacker group targeted the World Health Organization (WHO) via a sophisticated phishing attack, which involved an email hosted on a phishing domain that tried to trick the employees into entering their credentials. Researchers also discovered threat actors distributing malware disguised as “Coronavirus Map” to steal personal information that is stored in the user’s browser.

2020 was also the year which was a spike in espionage attacks from state-sponsored actors in a bid to steal vaccine development. At a time when ransomware kits are sold on the Dark Web, hackers leveraging COVID-19 for malicious activities have become even more concerning.

“With ransomware being sold as a service, it doesn’t matter for the victim companies where the attack comes from. The only factor that companies need to consider is that they’re attacked by professionals, they are probably going to give them the key if they pay the ransom, because if the word gets around that they’re not getting the key, no one’s going to pay the ransom anyway. So, if a company wanted to pay the ransom in case they weren’t fully protected, they might hope that the perpetrator is a professional and knows how to provide the key. Of course, paying ransom is never a long-term solution and serves to exacerbate the problem,” said Jeff Lanza, retired FBI Special Agent to CISO MAG in an earlier interview.

How COVID-19 Impacted IT-OT Security

Technology Governance

According to a research from security firm Claroty, most of the industrial enterprises suffer an increase in cyberattacks since the pandemic began. The study, “The Critical Convergence of IT and OT Security in a Global Crisis,” found over 56% of IT (Information Technology) and OT (Operational Technology) professionals at industrial enterprises are struggling to cope with the rise of cybersecurity threats. Around 70% of the respondents stated they noticed that cybercriminals are using new attack tactics to target their organizations. The pharmaceutical, oil and gas, electric utilities, manufacturing, and building management systems are the top five sectors vulnerable to cyberattacks.

Union of IT and OT Networks

The survey revealed security professionals’ attitudes, perceptions, and concerns regarding OT security. Over 72% of respondents stated their jobs have become more challenging. While 67% believe their IT and OT networks have become more interconnected since the pandemic began and 75% expect they will become even more interconnected as a result of it.

Besides, 81% agreed that IT and OT have become more connected and 92% said they will become even more connected because of the pandemic. Around 81% have found that the collaboration between the IT and OT teams within their organization was more challenging during the pandemic.

Cyberattacks on Industrial Control Systems

According to Kaspersky’s report, the industrial control systems (ICS) sectors globally have seen a gradual decline in the number of cyberattacks targeted towards them. However, experts observed that the limited number of attacks have now become more complex, targeted, and exclusive in nature. Nearly 37.8% of computers associated with the ICS sectors suffered a cyberattack in the H1 2020. This increased the tally by a mere 2% in comparison to H2 2019. However, this increase is purely associated with the growing number of cyberattacks on ICS sectors of oil and gas along with systems in the building automation space, which again saw a 2% increase and a total of 39.9% of threats in the first half.

GovWare Focus 2020 Sets the Tone with “Partnerships for Resilience and Advancement”

The COVID-19 pandemic has added new and salient challenges to the current demands of cybersecurity programs. Experts believe that information sharing and collaboration on critical industry insights, trends, and solutions have become more imperative than before. Thus, with a purview of serving as an information resource and connectivity platform, GovWare Focus – 2020, in its premier virtual conference has succeeded in bringing the global cybersecurity community on the same stage.

By Mihir Bagwe, Tech Writer, CISO MAG

With the theme for the virtual conference set to “Partnerships for Resilience and Advancement,” the organizers showed a visible intent of tackling the current cybersecurity challenges with collective intelligence and collaborations. The GovWare Focus series is known for providing commercially neutral content, dynamic conversations that fuel new ideas and the means of increasing global connectivity. It provides a defined lens towards the key trends and developments in the realm of cybersecurity.

The Agenda

Being held online for the first time since its inception, GovWare Focus brought together 40+ industry and public agency speakers and over 60 virtual exhibitors showcasing the latest in cutting-edge technologies. GovWare’s primary focus in this virtual edition was on examining and discussing the critical developments in both threats and defense within the industry. However, it laid a specific emphasis on cybersecurity across geographic boundaries, technology sectors, and user industry verticals.

GovWare Focus 2020 at a Glance

  • 8 Keynote Addresses
  • 10 Tracks
  • 50 Keynote Addresses, Conference Sessions and Fireside Chats
  • 60+ Exhibitors in the Virtual Exhibition Hall

Key Highlights

CSA – Singapore Chief’s Keynote Address

The stellar line-up of speakers at GovWare Focus 2020 included Mr. David Koh, Commissioner of Cybersecurity & Chief Executive, Cyber Security Agency of Singapore. He said, “The pandemic has accelerated digitalization and increased its scope and reach. We are now even more dependent on connectivity and technology; they drive how we live, work and play.”

GovWare Focus 2020, David Koh
David Koh, Commissioner CSA
Cybersecurity is a collective responsibility, and we need the digital community to be on board with us to strengthen our defense against cyberthreats.

 

 

“Underpinning all of this is cybersecurity. It is the key enabler to our new digitalized world. The criticality of cybersecurity has only grown more pronounced, as the attack surface has expanded tremendously, and the range of threats and potential challenges posed by an equally diverse range of malicious actors has also increased. Governments, businesses, and individuals are dependent on a reliable, safe, and secure cyber environment in which to transact, interact, and do business.”

Koh added, “We in the cyber community need to ask ourselves what our response should be, and how we can contribute towards an expanded cyber space safe for a world already reeling from so many challenges.”

Addressing the issues related to the tasks on hand, Koh also suggested a possible solution – Security by Design. According to him, security by design is a comprehensive approach that helps formulate the organization’s infrastructure design, which in turn provides a deeper view of security concerns. This allows automation of security controls to build security across every part of IT management process. This is not a new approach, yet the rise of cloud technology has made it a more simplistic and adaptable option.

The Fireside Chat
GovWare Focus 2020, Prerana Mehta
Prerana Mehta, Chief of Ecosystem Development, AustCyber
Diversity is increasingly important, not just from having a young female in the team or from a research and development perspective, but from mindsets including top-down leadership. Through diversity, a myriad of solutions will help solve a wide set of problems.

 

Being a virtual conference, the impact of a fireside chat was questionable before the event started. However, these apprehensions went out of the window with some very fruitful and important discussions like the one on the role of a CISO in the evolving cybersecurity space.

The panel discussed a wide range of challenges based on the current scenario of geography, compliance, and more. One of the most prominent statements made during this discussion came from Prerana Mehta, Chief of Ecosystem Development, AustCyber. She highlighted that diversity is very important when it comes to problem-solving. It is important because a single point of view and vision at times hampers the problem-solving capability. A team with diverse roles and players ought to do better than others, and this applies to a cybersecurity team as well.

Other Highlights

Other highlights included the Startup Pavilion, which provided a platform for promising local companies to showcase their technology and solutions. Apart from this, the budding startups also battled it out in the GovWare-ICE71 Startup Pitch Pit. In its second run, the Startup Pitch Pit featured four up-and-coming cybersecurity startups from ICE71’s community as they pitched their solutions to a panel of Infosecurity industry veterans.

Closing Notes

When it comes to cybersecurity readiness, Singapore currently ranks the world’s most prepared. Experts across the globe have always wondered what makes this nation cyber efficient. And we might have just cracked the code to it. It is initiatives like the GovWare Focus 2020 and the Singapore International Cyber Week (SICW) that keeps them ahead in this game. Cyber space and cybersecurity, both, are constantly evolving and it is only through such collaborations that we can together work towards better cyber resilience and security.

About the Conference

Govware Focus – 2020 was a two-day virtual event held on October 7 and 8, 2020, as part of the Singapore International Cyber Week (SICW) that took place between October 5 – 9, 2020.

CISO MAG, a Media Partner for the event, would like to thank the organizers of GovWare Focus 2020 for exclusive access and patronage to their services.

About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 


Other Posts from the Author:

Protect the Connected! Will IoT Ever be 100% Secure?

The National Cybersecurity Awareness Month (NCSAM) for the U.S., which started on October 1, continues to raise awareness on the significance of cybersecurity in protecting the cyberspace. The theme “Do Your Part. #BeCyberSmart” empowers users to defend themselves regardless of the location. This week the NCSAM highlights “Securing Devices at Home and Work,” encouraging individuals and organizations to defend their network by taking proactive security measures, as the Internet of Things (IoT) has become a regular part of our lives.

By Rudra Srinivas, Feature Writer, CISO MAG

The proliferation of IoT devices and their unpatched internal vulnerabilities allow cybercriminals to launch zero-day attacks, compromising various connected devices like webcams, security systems, routers, printers, and smart home connected appliances (like thermostats and doorbell ringers). In addition, these devices store users’ private information, which could be easily misused if it falls in malevolent hands. In light of knowing what cybersecurity risks these devices could pose, it is imperative to enhance their security at the consumer and enterprise level.

Future of IoT

IoT devices are gaining more popularity year-over-year. According to a survey from Juniper Networks, the total number of IoT connections is expected to reach 83 billion by 2024, from 35 billion connections in 2020, which represents a growth of 130% over the next 4 years. A significant rise of IoT networks is also expected in various sectors like Industrial, Manufacturing, Retail, and Agriculture, accounting to over 70% of all IoT connections by 2024.

Growing Attacks on IoT

In tandem with technology and deployment, the growth of IoT devices also resulted in a variety of cyberthreats. The surge in IoT threats is an ever-growing concern to enterprise network security. Organizations need to implement the necessary steps to maximize security in all layers of the IoT ecosystem. A recent survey claimed that nearly 57% of IoT devices are vulnerable to cyberattacks. It found that the number of non-business IoT devices connecting to corporate networks increased over the last year. The devices that regularly connect to corporate networks include smart teddy bears (34%), medical devices (44%), electric vehicles (27%), and connected kitchen appliances (43%).

IoT Security Regulations

To address the growing risks around connected devices, governments across the globe are implementing stringent regulations for users’ data security and privacy. Recently, the U.S. House of Representatives passed the IoT Cybersecurity Improvement Act, which is intended to improve the security of IoT devices in the country. As per the proposed bill, all IoT devices purchased by the government must fulfill minimum security requirements.

The Australian government introduced the “Code of Practice,” which is a basic cybersecurity standard for all IoT devices in the country. A new proposal from the U.K. government stated that insecure IoT devices that are used in households and businesses could be banned from sale or removed from the market if they fail to meet certain security standards. The latest regulations are intended to protect the digital infrastructure from the evolving cyberattacks on connected devices.

How to Secure Your IoT

  • Do a thorough research before purchasing an IoT device, as companies provide different levels of security. Compare similar devices with different manufacturers and choose a reliable one.
  • Always encrypt your IoT devices with a strong password and update it regularly. Ensure your Wi-Fi network is secure, as this is the first gateway for hackers to try to break into your devices. Remember to turn off the device when it is not in use.
  • Connected devices become smart based on the data they collect. Be vigilant on what data the device is storing and with whom it being shared. Know how the device’s manufacturer collects, stores, and protects your sensitive information. Erase all personal information from your connected device when you are removing it from your network.

Do Your Part. #BeCyberSmart  

Owing to the pandemic, remote working has led to both opportunities and challenges for users across the globe. Thanks to the increased use of IoT devices, our homes and businesses are more connected than ever. And it has paved way for newer vulnerabilities. It is essential to be conscious of the evolving threats, manage risks, and assess compliance through GDPR, HIPPA, and other regulations before cybercriminals attempt to exploit any vulnerabilities.

Being cyber smart is the only way forward to help protect our interconnected ecosystem.

About the Author
Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.