Home Blog Page 161

Small Businesses are Not Prepared for Evolving Cyberthreats: Report

CISO, Cybersecurity

A survey from the Nationwide Agent Authority, a provider of diversified insurance and financial services, revealed that most of the businesses and consumers in the U.S. are not prepared to defend against evolving cyberthreats. The survey uncovered four scenarios in particular, these include:

1. Small Businesses are Underprepared

Nearly 50% of cyberattacks are aimed at small businesses, but only 37% of small business owners reported believing they are at risk to fall victim to a cyberattack. About one-third of businesses said they are not confident they could recover if their business was attacked.

While 50% of small business owners believe they are prepared to handle a cyberattack, only 39% of independent agents believe that their customers are prepared to prevent one. Only 17% of small business owners say they have cyber liability insurance, and half (53%) say they do not offer cybersecurity training to their employees. Eight in 10 agents admitted that most of their clients are unsure of how they are exposed to cybersecurity risks and they do not know what is covered in a cyber insurance policy.

2. Middle Market Businesses have Better Cyber Footing

According to the survey, the middle market businesses have a greater awareness and are more prepared for cyberattacks compared to small businesses. Though 70% of middle market business owners are concerned about cyber risks, over 79% said they are confident and well prepared to address cyberattacks.

“This confidence may be warranted as they are more likely than small business owners to have taken key security precautions, including purchasing cybersecurity insurance (71%). They also appreciate the support they are receiving from agents, with 70% indicating they trust their agent to provide insurance council on cyberthreats,” the survey stated.

3. Consumers Underrate their Cyber Risk Exposure

The survey found that consumers have limited knowledge of cyberthreats. Around 40% of consumers stated that they have never been a victim of any kind of cyberattacks. It is also observed that consumers are unaware of what it takes to recover from an attack, with just 51% believing they could recover. Four in 10 do not know how much it would cost to recover from a cyberattack. Only 62% reported being knowledgeable about ID theft, 56% stated they know about malware, and only 57% know about phishing attacks. While 32% said they feel prepared to protect themselves from evolving threats, only 13% of consumers indicate that they are cyber insured.

4. Cyber Insurers Help Clients with Evolving Cyberthreats

The survey stated that insurance agents can make their clients aware of evolving cyber risks, with 52% of agents surveyed said they discuss cybersecurity threats with their customers often. Over 50% of agents said they are familiar with emerging cyberthreats, including 58% – IoT security breaches, 58% – Mobile point of sale malware, 53% – Denial of Service (DoS) attacks, and 47% – Deep fake attacks.

“It is encouraging that middle-market business owners appear to be more attune to risks and are proactively preparing their defense. But regardless of the type of client, now is an important time for insurance agents to talk to their customers about cybersecurity solutions and best practices,” said Catherine Rudow, Vice President of Cyber Insurance for Nationwide.

“From an IAM perspective, human and device identities are treated equally”

Amruta Gawde_interview

From dispersing office spaces to remote working, COVID-19 forced organizations to have a holistic approach to cybersecurity. Business continuity transformed overnight to navigate through the pandemic. The industry also experienced a paradigm shift in embracing human error, addressing cyberthreats, and securing data.

In a digitally enabled economy, Identity and Access Management plays a critical role in the security and resiliency of an enterprise. Hence, IAM and data security are inseparably linked. IAM empowers its users to self-authenticate, thereby reducing time-consuming tasks such as help-desk tickets and password resets.

To dive deeper into how IAM systems enhance productivity in today’s cut-throat business world, Pooja Tikekar, Feature Writer at CISO MAG, engaged in a conversation with Amruta Gawde, Practices Program Manager – IAM, Simeio Solutions.

Amruta has around 14 years of experience in Information Security, with 12 of those in IAM domain, spanning across organizations like Vaau, Sun Microsystems, PwC and Simeio Solutions. While in Simeio, Amruta has worn multiple hats on the delivery side from techno-functional to customer engagement. Backed by her extensive customer-facing experience, she took the responsibility of heading the IAM practices for Simeio to build Simeio’s Center of Excellence. Her program combines technical innovation with IAM thought leadership to build innovative solutions.

Edited excerpts of the interview follow:

2020 is an alarming year for data security. Exposure of PII is at an all-time high. Although two-factor or multi-factor authentication is a standard remedy, how does Identity and Access Management (IAM) help in safeguarding digital identities compared to the traditional security practices?

Traditional security practices either focus on perimeter protection (assuming all the threats are external) or on the post-breach detective approach.

While this is obviously an important aspect of security, a significant percentage of breaches are a result of privileged/administrative access being abused by staff either inadvertently or intentionally. In addition to two-factor or multi-factor authentication (which falls under the gamut of IAM),  IAM focuses on building a strong framework of access control and access enforcement for ensuring the “Least Privilege” security principal – Provide minimum required access. As a result, you cannot employ the privileges that you do not have. Additionally, every access provided and subsequently utilized, has supported the audit trail, which helps in compliance.

COVID-19 and the dispersed work from home format has intensified security risks. What is the role of IAM in securing enterprise networks in decentralized environments?

The need for ‘Any Time Any Where Any Device Any Content’ (ATAWADAC) services have significantly increased. Thanks to this new era of remote working and decentralized environments, IAM which was always relevant to any organization’s security strategy, has gained a lot more traction.

An IAM solution provides a centralized platform for automated provisioning and de-provisioning of required privileges to vendors, employees, partners, and mobile or IoT devices alike.

IAM solutions also have analytical intelligence to add contextual references during authentication and authorizations. For example, if an employee usually logs in between 9-5, any logins outside of those hours would require additional authentication. Static administrative privileges and shared admin credentials, that can be stolen, are a history with just-in-time privilege escalation using advanced privileged access management solutions.

As technology evolves, so does Identity and Access Management. How are IAM systems evolving to get better at authenticating users, apps, and devices to enhance security posture?

The IAM space has been constantly evolving. Recently introduced GDPR regulations require privacy protection and consent management in consumer transactions. IAM solutions provide fine-grained authorization and consent management during logins and data access as a result. Increased WFH has increased the need for ATAWADAC and secure remote access. Striking the right balance of security and user experience gave rise to zero trust (don’t trust, authenticate every time) and a need to go passwordless, which are the latest trends in IAM. Increase in the IoT devices has resulted in adaptive/contextual authentication and artificial intelligence in IAM solutions. Analytical intelligence/threat analytics are commonplace. The need for self-sovereign identity (user-created and controlled identity) has caused significant advancement in IAM solutions as well. We are also seeing one major change that is – the traditional IAM solutions were administrator friendly – complex to configure and use, and centrally managed. The modern IAM solutions are business-friendly, keeping the synergy between business, security, compliance, and user-friendliness a priority over customizations and technical complexities.

It is said that single sign-on (SSO) requires a focus on the safety of user credentials, and hence deemed critical. How does SSO authenticate third-party applications or websites? Is it practical?

Single sign-on is definitely practical given that most organizations leverage third-party cloud applications to better help deliver products and services to their customers.

Given the increase in complex eco-systems that contain multiple applications, IAM solutions inherently provide the capability of SSO.

This provides the ability to access both internal and third-party cloud application using a single ID, such as an Enterprise ID or a Social ID (Facebook or Google)

The Trust establishment with third-party applications is achieved through a concept of federation, which is like a digital third-party agreement between the identity provider (IAM solution) and the service provider (third-party applications).

Another relatable scenario that you would have witnessed is sometimes when you play a quiz online, in the end, it asks your permission to post the results to your Facebook page. In this case, the quiz app wants access to your Facebook profile. As a user, you do not want your Facebook account to share your credentials with this third-party, while allowing this temporary access. Also, you want to select what data should be exchanged. This is all achieved in the backend through IAM.

The Internet of Things (IoT) landscape is experiencing a paradigm shift. Businesses are now concerned with managing multiple “things” connected to their network. How does IAM provide security against IoT devices that are trying to access the network?

From the ­­­IAM perspective – human and device identities are treated equally. As we saw earlier, ATAWADAC is the need of the hour. Just like a human identity, every IoT device needs to authenticate itself and it is only allowed to access, what it is authorized to access within the given context. It needs to establish trust with third-party applications, all its transactions are audited, and so on.

Additionally, advanced API security and end-point privilege management devices ensure that the access is secure.

Tell us a bit about Cloud IAM and its role in cloud security. How can it help prevent data breaches and possible financial losses?

Cloud IAM, like other cloud services, are IAM solutions offered as-a-service. Customers do not need to pay for licenses, infrastructure, upgrades of the IAM platform. It is completely built, managed (availability, auto-scaling based on load, performance, etc.), run, and maintained for you. Cloud IAM allows you to unbundle the services and choose what you want to use, you pay for what you use. The accountability of data security is outsourced to the IAM service providers. It also gives you the flexibility to change the IAM service provider should you wish to do so. It integrates with native cloud platforms for key security features such as API security and provides identity management for the users of the cloud platform itself.

Choosing an IAM solution can be a daunting task, especially in these testing times. What primary factors determine an accurate IAM framework and what are its compliance requirements? Is it cost-effective for consumers and businesses alike?

I would recommend finding an IAM consultation partner who would help you define the IAM roadmap and help you determine what solution would work for your requirements.

An IAM solution covers multiple areas such as governance, identity management, authentication, authorization, SSO, privileged identity management, threat analytics, and intelligence under the IAM umbrella, which address a variety of business problems.

Pretty much all IAM partners offer you most of the functionalities with cost variation. The consumer-only products are light and may cost lesser. However, if you are looking to address different types of users including employees, B2B partners and consumers, enterprise IAM solutions are a better fit.

While some organizations do build their own IAM solutions, this is not recommended.

The key is to identify and prioritize business problems/objectives with respect to audit & compliance, security, operations simplification, risk management, cost-saving, digital transformation, number and types of assets, and types of identities.

There are multiple research firms such as Gartner, Forrester, KuppingerCole that publish market trends, and leading vendors analysis periodically.

Technology selection alone is not sufficient. It is important to align processes supporting your IAM roadmap and an adoption and maintenance plan. Outsourcing to professionals for implementation of IAM solution or opting for cloud IAM or Identity-as-a-Service (IDaaS) platforms is a better way to ensure that you are realizing maximum value out of your investment.

In fact, a customer-owned IAM solution requires significant investment in infrastructure and license costs during implementation and/or maintenance alike. Whereas, IDaaS platforms ensure that the customer does not have to bear the cost of infrastructure, licensing, upgrade, maintenance and you can switch shop without a second thought.

What is the IAM strategy of Simeio in a post-pandemic world?

Simeio has always been customer-centric and IAM focused. The pandemic has triggered significant digital transformation. Everything has gone online, from shopping to government services to doctor’s consultations, and you no longer require physical presence and access. As a result, the importance of secure virtual presence and verification of digital identity has increased exponentially. IAM has hence become the need of the hour. We have supported multiple of our customers through this digital transformation and their key security challenges. Our only target has been to make this transition to the secure digital world as smooth, secure, and fast as possible. We are focusing on combining our years of experience in this space, to enable customers to realize quick ROI through ready-to-consume, business-friendly, secure, feature-rich, modern Identity-as-a-service solutions.


About the Author

Pooja Tikekar is a Feature Writer, and part of the editorial team at CISO MAG. She writes news and feature stories on cybersecurity trends.

More from the author.

 

COVID-19 Becomes an Enabler for Better Cybersecurity for SMBs

CISOs in remote working

Even though COVID-19 saw an unprecedented number of layoffs and budget cuts for enterprises across the world, cybersecurity remained to be one of the key areas of investments, especially for SMBs. A new report by Kaspersky titled “Investment adjustment: aligning IT budgets with changing security priorities” suggested that SMBs on average spent $275k for cybersecurity in 2020, which was $8000 more than the previous year.

The report highlighted that 71% of SMBs and bigger enterprises are planning to increase their cybersecurity spending in the next three years, while only 17% plans to keep its spending unchanged.  “For those SMBs looking to increase their security spend, one of the top three drivers was cited as wanting to increase security spend in response to the increased complexity of IT infrastructure (43% compared to 36% the previous year),” the report added. “This is followed by the need to improve internal specialist security expertise (39%) and for a third (34%) of SMBs, senior-level management wants to increase budgets to improve company defenses.”

The report also found that the share of security in overall IT budgets has grown from 23% in 2019 to 26% in 2020 within SMBs, and from 26% in 2019 to 29% in 2020 for enterprises. Another key finding was that the average cost of data breaches decreased to $101k for SMBs and $1.09 million for enterprises in 2020, compared to $108k and $1.41 million in 2019. While for companies and SMBs who were looking at reducing their cybersecurity spending, the only driving factors were senior management within enterprises who had no reason to invest so much in the future at 32%, while SMBs which are cutting down their overall expenses at 29%.

“MSMEs are doing the best they can but having to account for a suddenly expanded network to manage employees who will be using a mix of home and corporate devices for their role. They must rely more upon the security awareness of users to prevent the spread of malware, but this is a challenge,” Laurence Pitt, Global Security Strategy Director at Juniper Networks, told CISO MAG in a recent interview.

To conclude, COVID-19 has brought cybersecurity into the limelight even for many SMBs.

“SilentFade” Chinese Malware Campaign Targets Facebook’s Ads Platform

Malware and Vulnerability Trends Report, Mobile malware threats

Security experts from Facebook disclosed details about a sophisticated malware campaign “SilentFade” linked to Chinese actors that targeted Facebook’s ad platform between late 2018 and February 2019. In a security conference, the researchers stated that SilentFade exploited a vulnerability in Facebook’s ad platform by leveraging a combination of a Windows Trojan and browser injections to stay undetected; however, it was patched soon after. Facebook also took legal action against the threat group in December 2019.

The hacker group used a malware Trojan to compromise the users’ browsers and steal passwords and browser cookies to eventually obtain authorized access to their Facebook accounts. They mainly targeted for accounts that had the payment method linked to their profiles. The malware campaign ran ads from compromised Facebook accounts and used cloaking elements to escape detection.

“Our investigation uncovered a number of interesting techniques used to compromise people with the goal to commit ad fraud. The attackers primarily ran malicious ad campaigns, often in the form of advertising pharmaceutical pills and spam with fake celebrity endorsements. The attackers also created detection challenges. They cloaked their landing pages and made purchases appear valid by using the legitimate credit cards and PayPal accounts linked to the compromised user accounts. Industry investigators are rarely able to see an end-to-end picture of credential compromise directly leading to abuse on a particular platform,” the researchers said.

Facebook Takes Down Hundreds of Fake Accounts

Recently, Facebook took down two separate networks that originated from China and the Philippines for violating its Coordinated Inauthentic Behavior (CIB) policy. In an official release, the social networking giant stated that it has removed 155 fake accounts, 11 pages, 9 groups, and 6 Instagram accounts for breaching its guidelines against foreign or government interference. Facebook stated that state-sponsored actors from China are using these accounts to influence public opinion across the Philippines, the U.S., and Southeast Asia. The actors behind this network posted global news and current events in Chinese, Filipino, and English languages.

VMware Delivers Digital First Security Solutions for Securing the Remote Workforce

VMware digital infrastructure
Image Credit: VMware

Experts had anticipated a pandemic-like situation for long, but what they never expected was the degree of impact it would have on human life and businesses. In the months gone by, businesses scampered towards digitization through the rapid adoption of the cloud technology for ensuring business continuity. As cloud computing scaled to new heights, corresponding vulnerabilities also increased. In response to this proportionate growth, VMware has unveiled new innovations to deliver ingrained security solutions to the world’s digital infrastructure.

VMware’s Security Solutions for Digital Infrastructure

Attacker sophistication, security threats, breaches, and exploits are currently more prevalent than ever. Security strategies are taking into account the increasing attacks on modern cloud workloads. Therefore, VMware’s solutions are designed for the public and private clouds, security operations, distributed workforces, and future-ready digital infrastructure.

At the recently concluded VMworld 2020, the company announced a range of solutions and services to help customers survive and thrive in the most turbulent times.

 Security for the Private and Public Cloud 

As businesses continue their journey towards cloud transformation and application modernization, they require modern security solutions that are both powerful and easy to operationalize. To fulfill this requirement, VMware, in collaboration with Carbon Black, introduced the VMware Carbon Black Cloud WorkloadTM.

The solution combines Carbon Black’s security expertise with VMware’s deep knowledge of data centers to build security directly into workloads. It delivers advanced protection by providing prioritized vulnerability reporting and foundational workload hardening with comprehensive prevention, detection, and response capabilities to protect workloads running in virtualized, private, and hybrid cloud environments. This unified solution enables security and infrastructure teams to automatically help secure new and existing workloads at every point in the security lifecycle.

Workload security is complicated in the hybrid data center architectures that employ everything from physical, on-premises machines to multiple public cloud infrastructure as a service (IaaS) environment to container-based application architectures. For security teams, VMware Carbon Black Cloud Workload will offer the following:

  • Visibility to Identify Risk and Harden Workloads: This solution will help security and infrastructure teams to focus on the most high-risk vulnerabilities and common exploits across their environments. It enables them to prioritize vulnerabilities based on a combination of the Common Vulnerability Scoring System (CVSS), real-life exploitability and real-life frequency of attack, and increase patching efficiency.
  • Prevention, Detection and Response to Advanced Attacks: Security teams often lack visibility and control in highly dynamic virtualized data center environments. However, Carbon Black Cloud Workload protects workloads running in these environments by combining vulnerability assessment and workload hardening with next-generation antivirus (NGAV), workload behavioral monitoring, and endpoint detection and response (EDR) for workloads.
  • Simplified Operations for IT and Security Teams: The VMware’s intrinsic approach builds security directly into the virtual fabric, enabling protection wherever workloads are deployed, eliminating the trade-off between security and operational simplicity. Carbon Black Workload accomplishes the same level of security risk visibility into VMware vCenter, as seen in Carbon Black Cloud – giving them a single source of truth. This not only accelerates response to critical vulnerabilities and attacks but also foster greater collaboration between IT and security teams.

VMware will introduce expanded offerings for Carbon Black Cloud Workload later this year including a new module for hardening and better securing Kubernetes workloads. The new capabilities will give security teams governance capabilities and control of Kubernetes environments.

 Security for the Distributed Workforce 

The distributed workforce introduces multiple challenges ranging from employee on-boarding, visibility and compliance, security, employee safety, and more. To address these challenges and successfully embrace the future of work, organizations need to re-think how they approach security, experience, and operational complexity associated with the IT environment. Security must not only be intrinsic; it needs to be thought of in the context of employee experience to maximize productivity and engagement. To enable that differentiated approach, VMware also introduced expanded capabilities for the VMware SASE Platform, Workspace Security VDI, and Workspace Security Remote.

These new solutions will deliver end-to-end zero trust security controls and simplified management – where VMware’s Secure Access Service Edge, Digital Workspace, and Endpoint Security technologies work harmoniously across applications on any cloud to any device.

Paying Ransom is Now Illegal! U.S. Dept of Treasury Warns

Ransomware Attacks, Graff ransomware attack

The U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) announced that paying ransom to cybercriminals is now illegal. In an official advisory, the agency stated that organizations that facilitate ransomware payments to hackers on behalf of ransomware victims, including financial institutions, cyber insurance firms, and companies involved in digital forensics and incident response, are violating OFAC regulations.

“Ransomware payments made to sanctioned persons or to comprehensively sanctioned jurisdictions could be used to fund activities adverse to the national security and foreign policy objectives of the United States. Ransomware payments may also embolden cyber actors to engage in future attacks,” OFAC said.

“OFAC may impose civil penalties for sanctions violations based on strict liability, meaning that a person subject to U.S. jurisdiction may be held civilly liable even if it did not know or have reason to know it was engaging in a transaction with a person that is prohibited under sanctions laws and regulations administered by OFAC,” OFAC added.

The agency also highlighted that ransomware attacks have become more sophisticated and costly, with a 37% annual increase in reported ransomware cases and a 147% annual increase in associated losses from 2018 to 2019. Not only popular/large organizations, cybercriminals targeted numerous small- and medium-sized corporations.

Ransom Demand Increase by 100%

A report published by Coalition, a provider of cyber insurance services in North America, revealed that ransomware incidents accounted to 41% of cyber insurance claims filed in the first six months of 2020. The report “H1 2020 Cyber Insurance Claims Report” highlighted that the average ransomware demand increased by 100% from 2019 through 2020. Several organizations stated that ransomware attacks are the most prevalent and destructive cyberthreats. The severity of ransomware attacks increased by 47%, with a 100% spike from 2019 to Q1 2020. New and malicious strains of ransomware variants such as Maze and DoppelPaymer are leveraged to demand heavy ransom and expose organizational data. An average Maze demand is six times larger than the overall average ransom demand, the report stated.

CYBER WARFARE: The Fight Beyond Enemy Lines [INFOGRAPHIC]

cyber warfare

Digitization has helped businesses immensely, especially, in the ongoing pandemic. It has allowed robustness through business continuity, remote working capability, and online supply chain management.  However, this has given birth to a new threat landscape that stretches from our critical assets to as close as our homes, which we once thought as the most secure place to be in. With a number of international peacekeeping sanctions and treaties in place, it has been difficult for prominent nations to begin a full-blown war upfront. Thus, these nations have now resorted to exploiting the newly found threat landscape for targeted surgical destruction.

Moreover, risking a soldier’s life on the battleground is no longer necessary as enemy assets deep beyond borders can now be penetrated easily with a new form of warfare – the Cyber Warfare.

Let’s have a look at the what, which, when, where, and how of cyber warfare through this insightful infographic that has been developed by the editors at CISO MAG in collaboration with researchers at CYFIRMA, a cyber threat intelligence (CTI) platform and cybersecurity solutions provider.

Related Post

Cyber Warfare: The Battle Tact of the Digital Age


Cyber Warfare, Cyber Warfare WhitepaperDownload this whitepaper now and read about “Cyber Warfare” and CYFIRMA’s pledge towards protecting your businesses, enterprises, and governments from such attacks.

 

 

Top Cyberthreats to Financial Service Providers

FBI Warns About Fake Mobile Banking Apps, Trojans

With so much banking being done online, financial service providers are no stranger to cyberthreats. However, the recent COVID-19 pandemic is being blamed for a 238% increase in cyberattacks against banks and other financial institutions, according to the latest cybersecurity statistics. These entities must be prepared for these attacks and know how to quickly respond to minimize harm to their institution and customers’ private data.

By Ben Hartwig, Web Operations Director at InfoTracer

According to one survey of IT executives, approximately two-thirds of financial organizations experienced at least one cyberattack in 2016. Here are some of the biggest cybersecurity threats financial service providers are facing today.

1. State-Sponsored Attacks

While many people think of a cybercriminal as a one-man operation or a group of criminals in for financial gain, some cyberattacks are actually encouraged and launched by foreign governments. The increasing frequency of such attacks led to NATO officially defining cyberspace as the fifth domain of warfare, in which it recognized the critical role that a country’s infrastructure plays in its stability. Foreign factions may try to attack banks, stock exchanges, and other financial institutions to destabilize a country and make citizens concerned about their economy.

In some instances, governments may hire their own hackers to attack the financial industry in other countries. In others, they may spread fake news about the market to influence trade volume. Researchers from the MIT Sloan School of Management and the Yale School of Management found that the past impact of article writers had a large impact on abnormal trading behavior and that a fake article was more likely to cause greater market disruption than a real article.

2. Regulatory Inaction 

While many banks may feel overregulated, others believe there are not enough regulations or consumer protection laws in an age of rapidly-evolving technology. Regulatory action is often short-sighted and reactionary, so banks must consider more effective and timely methods to protect their institutions and customers.

3. Credential Theft and Identity Theft

A particularly dangerous type of cybersecurity threat to customers is account takeover, in which a criminal gains access to a customer’s account and then changes information on it so that the real owner does not have access to it nor receives updates about the account. This attack is often a result of credential stuffing, in which hackers use computers to keep inserting various credentials until they break into an account. Some criminals go a step further by using that login information to access other accounts owned by the customer since many people use the same username and password combinations across multiple platforms. They may also use the gathered information to commit identity theft.

Account takeover statistics show that rates of account takeover have steadily increased over the last few years. Losses rose 122% from 2016 to 2017, and then another 164% in 2018. The number of these attacks nearly doubled from 2017 to 2018.

4. Employee Errors

While banks are very careful about hiring employees, who will not steal from them, a major cybersecurity risk occurs from employee errors, not due to intentional wrongdoing. For example, employees may open a phishing email that installs viruses on the bank’s network. This was the most common type of cyberattack in 2016. Given the COVID-19 pandemic and that many banking employees are working from home, simple employee errors and technological vulnerabilities may subject financial institutions to additional cybersecurity threats.

5. Data Theft and Manipulation

In some types of cyberattacks, criminals make slight changes to data, which may not be immediately detectable. Because nothing is stolen at the time, employees may not recognize the attack. However, once the criminals gain access to this data, they can manipulate algorithms in the system for their own financial gain.

6. Phishing Attacks

The last four Verizon Data Breach Investigations Reports have identified the use of stolen credentials as the number one method hackers use to gain unauthorized access to accounts. Many of these cyberattacks occur when bank customers or employees click on an email or link or download an attachment in an email. The email may state that their account has been compromised and they need to log in with new information, which is then used by the criminal to access the account. Alternatively, this strategy may be used to install malware on the computer system.

7. Ransomware

Ransomware is a particularly dangerous type of malware that takes over a victim’s computer system by encrypting data and making it impossible for the owner to access it unless they pay a large fee. Many of these attacks target banks because the criminals are after large payouts.

8. Cloud Providers

Many banks store information on the cloud to avoid expenses related to data storage. However, if these servers are not secure, the banks can still lose important data if destructive malware is installed and erases information. Unsecured cloud providers may also be the cause of a massive data breach that exposes customers to identity theft and other privacy concerns.

9. Third-Party Vendors

Even if banks have secure systems, if they use third-party vendors to deliver certain services, they may have a greater risk of being breached. With more system entry points, there are more ways hackers can enter your system.

10. Complex Technologies

As technology continues to evolve, criminals find new security vulnerabilities and methods to exploit financial institutions, such as using AI and IoT to increase cyberattacks. A recent report by VMware Carbon Black said that 82% of surveyed CIOs said that cyberattack methods are becoming more sophisticated. Social engineering was one example the report pointed to, regarding the exploitation of human weakness.

Ways Banks Can Protect Themselves from These Cyberthreats

Banks can harness the same technology that is used against them to protect themselves, including:

  • Adopting AI that can more quickly identify threats
  • Encrypting data so that it is not compromised even if a breach occurs
  • Monitoring cloud security
  • Limiting access to cloud security
  • Making frequent updates
  • Devising a recovery plan if an attack occurs
  • Instructing employees and customers to only access bank data in a secure location
  • Updating security frequently
  • Increasing budgets for IT resources
  • Updating security systems and protocol
  • Using multi-factor authentication
  • Training employees on cybersecurity risks

Conclusion

Implementing the strategies above and being conscious of the potential threats to your financial institution can help you prevent an attack.

About the Author

Ben HartwigBen Hartwig is a Web Operations Director at InfoTracer. He guides on marketing and entire cybersecurity posture and enjoys sharing best practices. You can contact him via LinkedIn.

 

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

Turbo-charge Your SaaS Evaluation Capability, Now!

SaaS

The year 2020 saw over 27 billion records exposed in the first half and 2019 saw about 14 billion records exposed. The driving force behind these incidents has been exposed databases and cloud service misconfiguration. Now, while enterprises may be deliberate and be cautious about adopting cloud, the ones that leverage SaaS solutions in ever-increasing numbers, have been pioneers at adopting public cloud services. This necessitates a solid SaaS evaluation capability. Taking the industry-standard checklists approach can help with basic hygiene. However, this approach has proven to be hardly adequate to build a comprehensive risk profile and help deter breaches, especially for mission-critical journeys. Here are four steps that can turbo-charge your organization’s SaaS evaluation capability:

By Ravi Ivaturi, Sr. Vice President – Digital Security Architecture at Citi

1. Understand the Product Architecture

Let loose your security architects on the SaaS product. A clear and comprehensive understanding of the product’s intended use and its implementation architecture is critical. Several facets of the architecture – logical, data flow, control flows, deployment architecture, and existing controls architecture need to be explored and understood. Any shortcomings in building this degree of detail will potentially lead to inadequately protected attack surfaces. Any assessment or checklist evaluation will be incomplete and even inaccurate without a deep understanding of the product’s architecture. Essentially, you need to get not just under the hood, but deep into the engine block.

2. Benchmark Against Known-good

Once the product architecture is well understood, the next step is to determine what is acceptable and what is not. A time-tested and proven approach is to benchmark against good design patterns. Let me elaborate with an example: public cloud platforms provide multiple ways to encrypt data stored on a file repository (e.g. AWS S3). Have a clear standard and design pattern on what option is acceptable, and for which scenarios it must be established internally. Any SaaS product leveraging S3 for storage can be evaluated against these patterns to determine risks owing to deviation. Now, obviously, this approach will require a good-sized library of design patterns with relevant controls. The good news is that a small set of services are used extensively. This makes it feasible to build an effective pattern-library in a short duration of time. A threat-based approach could also be adopted – given most data exposures happen due to misconfigured datastores; start with developing acceptable patterns for datastores. This will equip your SaaS security evaluation program to protect against threats that resulted in half of the data-exposures in the past two years!

3. The Misconfiguration Problem

Most SaaS vendors choose from one of the top three public cloud platforms. The single biggest security challenge faced by cloud deployments is a misconfiguration. We all are aware that Gartner predicts that, “Through 2025, 99% of cloud security failure will be due to a customer’s fault.” Sounds incredulous? Well, consider the Twilio S3 security incident from July 2020: Twilio distributes a JavaScript SDK that allows its clients to easily interact with its product. This SDK is hosted on an AWS S3 bucket for clients to download. Attackers were able to modify Twilio’s SDK and inject it with malicious code. The root cause is S3 bucket misconfiguration that allowed anyone on the Internet to write to the S3 bucket. While little has been disclosed on how the company was alerted to the breach, the bucket had been misconfigured since 2015. A security solution that actively looks for misconfiguration would have detected this issue within minutes.  Twilio is not alone – you’ll be surprised to know how few vendors have implemented this control and in an effective way. So, absolutely insist that the SaaS provider implements a solution for actively detecting and alerting against misconfiguration.

4. Risk Visibility

As cloud adoption continues to explode, more and more organizations will end up with their data islands on public cloud platforms. Despite all the best efforts, there is going to be a varying degree of control implementation and operational effectiveness. The risks are only further augmented by lift-and-shift strategies that don’t account for the inherently different architectures of public cloud platforms. It is therefore imperative to ensure that the senior leadership has a clear line-of-sight into the SaaS product adoption, control state, and inherent risks. Any SaaS evaluation program will fall short despite its best efforts with the leadership being provided clear and explicit visibility into this aspect.

It would be remiss to not touch upon the people aspect. For implementing the above four steps effectively, teams with appropriate skills and specialization are a must. Unless an enterprise already has a proven team of security architects, operationalizing these four steps will require the infusion of external resources and upskilling the existing teams.

Conclusion

With the ever-growing data breaches, driven by misconfigured cloud services, it is imperative that enterprises enhance their SaaS evaluation capabilities. This can be achieved by ensuring that the evaluation process includes steps to gain a deep understanding of the SaaS product architecture, benchmark against known good patterns, and providing a direct line of sight to leadership teams.

References

https://www.securitymagazine.com/articles/93093-data-breach-reports-down-52-in-the-first-half-of-2020-number-of-records-exposed-increase-to-27-billion#:~:text=The%20two%20largest%20breaches%20ever,2020%20surpassed%2090%20million%20records

https://www.gartner.com/smarterwithgartner/is-the-cloud-secure/

About the Author

Ravi IvaturiRavi is a cybersecurity leader with deep expertise in building cybersecurity programs for emerging technologies. He enjoys authoring technology articles, engaging with cybersecurity startups, and above all, solving problems. In his current role, Ravi heads the Cloud Security Architecture function for Citi’s Consumer division, providing security leadership for financial products used by millions of individuals across 19 countries. He also serves on Citi’s apex Security Architecture Council, providing oversight to enterprise-wide security architecture. With over 15 years of cybersecurity experience in the Financial sector, Ravi brings together a well-rounded experience and thought leadership in emerging-technology risks, security assessments, compliance, and technology risk management. Ravi holds a master’s degree from New York University in Computer Science.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

Anthem to Pay $39.5 to Settle Data Breach Lawsuit

Surveillance Legislation (Identify and Disrupt) Amendment Bill

Health insurer Anthem agreed to pay $39.5 million to settle another class action suit related to a cyberattack in 2015 that exposed the personal data of nearly 79 million people. The settlement is related to an investigation brought by the U.S. states’ attorneys general, including New York, Indiana, Connecticut, Illinois, Kentucky, Massachusetts, and Missouri. The cyberattack, which, in its time, was considered one of the biggest cybersecurity attacks the nation had ever witnessed, had compromised users’ names, addresses, social security numbers, and medical identification numbers.

In a recent statement, Anthem stated that it is also committed to enhance its ongoing data protection measures. “The company is pleased to have resolved this matter, which is the last open investigation related to the 2015 cyberattack. Anthem does not believe it violated the law in connection with its data security and is not admitting to any such violations in this settlement with the State Attorneys General,” Anthem said.

“Anthem’s first priority was to ensure that its systems were secure and immediately engaged the FBI and a world-class security organization. The company took immediate action to investigate and assist consumers and customers and to meet and exceed its legal obligations to provide notice and cooperate with law enforcement. Following the investigations, no evidence has been found that information obtained through the 2015 cyberattack targeting Anthem has resulted in fraud,” Anthem added.

Not the First Settlement

The recent settlement is separate from a class action suit over the breach that Anthem settled in 2018. In July 2017, Anthem reported a massive data breach that resulted in an identity theft of 18,000 Anthem Medicare members. In April 2017, the company discovered that an employee who worked for one of the Anthem’s health care consulting firms was stealing and misusing the information of Medicaid members since July 2016.

As part of the settlement, Anthem agreed to pay a total of $115 million to resolve the litigation. The final resolution also pays for credit monitoring and identity protection services to all the victims for two years, including the costs of sending notices to class members, administering claims, and the attorneys’ fees. Anthem also clarified that there is no evidence of any fraud or misuse of the compromised data.