Home Blog Page 163

CYBERSEC: Data is Worth More Than You Think!

CYBERSEC Global 2020

If you thought that the first day of the CYBERSEC Global 2020 was exhilarating, then the second day of the virtual conference was no less than breathtaking. With distinctive speakers from both technological and political backgrounds on board, the conversational focus was highly on matters concerning the importance of data in business and defense sectors.

Apart from the engrossing and informative key notes delivered by Annegret Kramp-Karrenbauer, Federal Minister of Defence of Germany and Samir Saran, President of ORF – India, for defense and business streams respectively, other panel discussions that interested the attendees was the human negligence in cybersecurity, challenges of a data driven economy, the future in zero trust model, the emergence of 5G and the bureaucracy behind information warfare.

So let us take a brief look at some of the individual perspectives and important discussions of the day that will give us deeper insights on the underlying threats and responsibilities in the cyber space.

Data is Worth More than You Think!

Looking at company valuations in the current digital economy, technology has clearly outgrown largest sectors such as the oil and gas industries. However, this exposes the most valued asset of businesses today – Data. It would be naive to believe that this new strategic resource could go unnoticed by adversarial actors and the news we hear daily is the most visible proof.

Data is a valuable strategic resource for both, cybercriminals and businesses alike. Threat actors want to steal, encrypt, sell and/or get ransom for it. But this data, if harnessed properly, also forms the basis for business and military intelligence, which in turn is an important reason over which cyberwarfare takes place. In these settings, the strategic targets have shifted from oil resources to digital assets that can be attacked from remote locations.

CYBERSEC Global 2020, importance of data

“Data is being harnessed by both, public and private domains for useful purposes, but its cybersecurity is a huge question mark that we need to answer.”

– Dita Charanzová, Vice-President, European Parliament

 

 


Human – The Weak Link

The single point of failure – as Andrzej Dopierała, President of Asseco Data Systems Management Board pointed out – is humans. A social engineering attack is a psychological manipulation of people into performing malicious actions without their knowledge. It includes phishing emails and statistics suggest that 98% of cyberattacks were found to be based on this form.

CYBERSEC Global 2020, importance of data

“It’s much easier to use psychological tricks to make a person click a link to gain access than to break through firewalls and other security measures. It saves time!”

– Andrzej Dopierała, President of Asseco Data Systems

 

 


Targeting the Vulnerable

Global scenarios such as the COVID-19 pandemic showcased how cybercriminals and adversaries can rapidly adapt to the new circumstances. The amount of pandemic-themed cyberattacks rose exponentially in the first few months of the pandemic. This is what all involved in cybersecurity need to stay ahead of – not only to avoid attacks, but also to provide business continuity.

How? Answering this question Flavio Aggio, CISO at WHO, clearly states two strategies – implementation of zero-trust policies and cloud migration. He noted that organizations such as WHO, which migrated to cloud technology ahead of the pandemic, had a smooth transition to remote work. Zero-trust policies ensure that the security is difficult if not impossible to breach easily even with most employees working from outside of the secured office environment.

CYBERSEC Global 2020, importance of data

“Post pandemic we need to move towards a Zero Trust model. There is no doubt that this along with cloud is the future of technology and businesses.”

– Flavio Aggio, Chief Information Security Officer, WHO

 

 


Aggio added, “The information war is a deep and growing concern even for WHO. To counter this war many have invested a lot on technology but development in technology should consider the human factor and should be human-centric instead of just business-centric approach.”

Defense for Defense Forces

It is evident from the disruption caused that businesses need to think of their defenses. However, this is not the only sector that needs to be wary about it. Nation-states it seem are at an equal or even greater risks of cybersecurity.

CYBERSEC Global 2020, importance of data

“It is not enough to provide state-of-the-art IT security solutions alone, but we need to understand and establish a separate cybersecurity command/wing for military, which will solely concentrate on fortifying our cyber defenses.”

– Annegret Kramp-Karrenbauer, Federal Minister of Defence of Germany

 


The European Union already acknowledges the plans to maintain digital sovereignty with the establishment of GDPR and annulment of the EU-U.S. Privacy Shield framework. Annagret Kramp-Karrenbauer, Federal Minister of Defence of Germany, rightfully summarized five plans of action for defense forces in Europe:

  1. Using trustworthy technology from specialized service providers
  2. Building up key technologies
  3. Maintaining core command and control capabilities
  4. Increasing innovation capabilities
  5. Promoting digital consequences

5G is another exceptional technology for business and modern battlegrounds. Following Riho Terras – a European Parliament member and former Commander of the Estonian Defence Forces – although previously new technologies originated in the military and were populated to general users, the technology developed after the Internet invention worked the other way around. This creates a challenge for 5G that enables technologies such as Artificial Intelligence, Virtual and Augmented Realities and Autonomous Weapons on battlegrounds, but on the other hand have a lot of holes and backdoors since they were not designed with military standards.

The benefits that defense forces could gain outgrow the challenges of using 5G, however the technology needs to become secured as it will also become a part of strategic infrastructure. The 5G end-users can benefit from these circumstances with higher levels of privacy and security, building trust in using it.

Information Warfare

A certain way to lead conflicts is information warfare. Whoever knows more on the battlefield, gains advantage. This old ideology is exploited in a new manner today, using the open character of social media to spread misinformation and effectively create circumstances to suit one’s agenda. We are witnessing it even now, in the re-ignited conflict between Azerbaijan and Armenia over Nagorno-Karabakh, where social media is used to spread different narrations.

CYBERSEC Global 2020, importance of data

“Media is a strong medium through which misinformation can be spread easily. This in turn can reshape the minds of masses against their own country. This is dangerous and needs to be monitored, stopped, and corrected.”

– Artis Pabriks, Deputy Prime Minister, Minister of Defence of the Republic of Latvia

 


Fake news has been identified as an important challenge since the 2016 U.S. presidential election and actions have been undertaken to prevent them from spreading by bringing together stakeholders from governments, tech giants, and other parties involved. Effective rapid identification and blocking of fake news will allow us to contain information warfare from causing state-wide effects and preventing adversaries from manipulating social moods.

CYBERSEC Global 2020, importance of data

“Disinformation has a smaller lifecycle. The truth eventually comes out sooner than later.”

– JAROSLAV NAĎ, Minister of Defence of the Slovak Republic

 

 


As discussed on day one, cybersecurity is a global effort. However, there is an urgent need to not just secure the data and operations of our businesses but also our states and its defenses from whatsoever challenges lie ahead of us in the cyberspace.

September 30 is the last day of CYBERSEC Global 2020 and the registrations are still open at https://csglobal20.eu/register/.

RELATED REPORT:
CYBERSEC: Make Cybersecurity a Global Effort

CISO MAG is a Media Patron for CYBERSEC Global Cybersecurity Forum 2020.

 

 

FBI and CISA Warn About Threat Actors Spreading Disinformation on Elections

US Voters

The FBI and the Cybersecurity and Infrastructure Security Agency (CISA) warned citizens about the potential threat posed by disinformation about cyberattacks on voter registration databases or voting systems in the U.S. In a joint statement, the agencies stated that foreign actors are spreading fake and inconsistent information via various online platforms to influence or manipulate public opinion during the 2020 election season.

“These malicious actors could use these forums to also spread disinformation suggesting successful cyber operations have compromised election infrastructure and facilitated the hacking and leaking of U.S. voter registration data. The U.S. voter information can be purchased through publicly available sources. While cyber actors have in recent years obtained voter registration information, the acquisition of this data did not impact the voting process or the integrity of election results,” the agencies said.

In addition, the FBI and CISA urged American citizens to evaluate the sources of the information they receive. The agencies recommended certain steps to validate the information, which include:

  • Seek out information from trustworthy sources, verify who produced the content, and consider their intent.
  • Rely on state and local election officials for information about voter registration databases and voting systems.
  • View early, unverified claims with a healthy dose of scepticism.
  • Verify through multiple reliable sources any reports about compromises of voter information or voting systems and consider searching for other reliable sources before sharing such information via social media or other avenues.
  • Report potential election crimes — such as disinformation about the manner, time, or place of voting — to the FBI.
  • If appropriate, make use of in-platform tools offered by social media companies for reporting suspicious posts that appear to be spreading false or inconsistent information about voter information or voting systems.

Government Cannot Protect Election Infrastructure

A recent survey stressed that 70% of cybersecurity professionals most likely believe their local governments cannot defend election infrastructure against cyberattacks from domestic and foreign threat actors. The majority of cyberattacks targeting election campaigns come from automated machines that inevitably spread information and direct attacks on the vote-counting systems. Industry experts opine that the ongoing pandemic brings additional security hurdles to the election season. It is suspected that cybercriminals might take advantage of the crisis to spread false information and initiate cyberattacks, making security experts concerned about election data protection.

Seqrite Uncovers “Operation SideCopy” Cyber Espionage Campaign Targeting Indian Army

SideCopy Malware Campaign

Cybersecurity solutions provider Quick Heal revealed evidence of a cyber espionage campaign “Operation SideCopy” by an advanced persistent threat (APT) group targeting Indian Army personnel since 2019 to pilfer sensitive information. The team at Seqrite, Quick Heal’s Enterpise Security brand, related certain old campaigns and attacks in the past year to the Operation SideCopy group by common IOCs (Indicator of compromises).

Exploiting Equation Editor Flaw

Seqrite observed three infection chain processes in which attackers exploited equation editor vulnerability (CVE-2017-11882) as the initial infection vector. The attackers distributed malware embedded in an email attachment in the form of a ZIP file containing a LNK file or a DOC file.

“The victim receives LNK files, compressed into ZIP/RAR via emails. These files are shortcuts executing mshta.exe and providing remote HTA URL as the parameter. LNKs have a double extension with document icons, to trick the victim into opening the file. Victims just have to execute LNK files and rest all modules follow in the background,”  Seqrite stated.

Key Findings

  • This cyber-operation targets only the Indian defense forces and armed forces personnel.
  • Malware modules seen are constantly under development and updated modules are released after a reconnaissance of victim data.
  • Actors are keeping track of malware detections and updating modules when detected by AV.
  • Almost all CnC belongs to Contabo GmbH and server names are similar to machine names found in the Transparent Tribe report.
  • This threat actor is misleading the security community by copying TTPs that point at Sidewinder APT group.
  • We suspect this threat actor has links with Transparent Tribe APT group.

Growing Cyberattacks on Indians

Recently, the Computer Emergency and Response Team – India (CERT-In) stated that it recorded over 1.45 million cybersecurity incidents including breaches and hacks between 2015 and 2020. According to the India’s Ministry of Electronics and Information Technology (MeITY), Cert-In reported 49,455, 50,362, 53,117, 208,456, 394,499 and 696,938 cybersecurity incidents during the year 2015, 2016, 2017, 2018, 2019 and 2020 (till August) respectively. The figures were out after the ministry was asked about growing cyberattacks targeting Indian citizens as well as commercial and legal entities.

“To be successful, CISOs must have intentionality and focus”

CEO, cybersecurity, CISO, Future of the CISO

Most of today’s CISOs got into the role accidentally. Yet tomorrow’s CISO will have chosen this role by intent. It will be a chosen vocation. Therefore, CISOs will need to focus on the role and start cultivating the skills required to become a security leader. This was a key message from a presentation on The Future CISO by Jeff Pollard, Principal Analyst, Forrester Research.  Speaking at the Forrester Security & Risk Global 2020 Live Virtual Experience on September 22, Pollard urged CISOs to check if they are “Company Fit” and to prepare for what’s next. He also outlined the six different types of CISOs: transformational, post-breach, tactical/operational, compliance guru, steady-state, and customer-facing evangelist. Pollard showed how CISOs can build a roadmap for transitioning from one type to another and explore strategies for obtaining future CISO and related roles.

By Brian Pereira, Principal Editor, CISO MAG

Jeff Pollard, Principal Analyst, Forrester Research
Jeff Pollard, Principal Analyst, Forrester Research

“CISOs do an insanely challenging job under challenging circumstances. They have to worry about their company, adversaries who attack, insider threats, and also employee and customer experience. This is not easy. That’s why intent matters,” said Pollard.

He advised CISOs to plan for the role and make a meaningful contribution at the C-Level. Skills enhancement, both for the CISO and the security teams is also crucial.

Pollard alluded to the example of Pixar Animation Studios, which achieved immense success and bagged many awards because it has intent and focus.

“Pixar is a company that matches this intent. They know exactly what they want to do. They have a specific methodology for stories, how they think about content. Technology drives the stories that they tell. They are an incredibly innovative company. There is a secret history of Pixar that ties in with the CISO role,” said Pollard.

Pixar earned 16 Academy awards, 11 Grammys, and 10 Golden Globes.

“They earned all these awards because they operate with intent and focus. When you operate without intent and focus, and when you don’t plan for this role, and when you don’t actively cultivate all of the skills that you need, then this happens,” said Pollard.

By “this” he meant that CISOs lose focus and find their role challenging, which could even lead to burn out.

He urged security leaders to start writing their own stories and to think about their stories with intent, discipline, and rigor.

Why CISOs lose focus

The CISO was never a “No” department. In saying “Yes” to everyone and trying to do everything for everyone, CISOs lost their focus.

CISOs juggle many tasks like product security concerns, compliance concerns, regulatory issues, legal issues, beaches and attackers, and incident response. And then, there are new priorities that come up.

“0% of CISOs are great at everything. And that’s what most security leaders have had to do. You can’t do all of that and be effective. It’s not possible. But that’s what happened to the role — priority after priority and trade-off after trade-off. None of it results in the success that we want,” said Pollard.

He added, “CISOs haven’t operated with constraints, which lead to focus. And focus leads to innovation. We are just doing too much and not succeeding. We are too tactical. We say yes to a lot. The CISO is not the department of No.”

How many are C-level?

While most security leaders aspire for a seat at the table in the board room, very few make the cut.

A 2020 study by Forrester Research shows that just 13% of all security leaders are actual C-level titles or CISO.

The Forrester study considered those with an SVP or an EVP title and compared that to those with a VP, Director, or another title — across Fortune 500 companies. The other data point from this study is that the average tenure of the CISO is 4.2 years and not two or three years.

“Even those who got a seat at the table are not treated like a true C-level executive. They do not have the same access for authority that those others have. And most of the 13% are on their third or fourth CISO role. After the second one, they don’t take that laying down anymore. They demand to be an actual C-level,” said Pollard.

What CISOs need to do

CISOs need to plan for a four-year stay, and they can take some inspiration from Pixar by writing their own stories.

“The reason why this is so important is because you are looking at a four-year stay. It’s going to be hard for CISOs because they are going to do all their tasks for four years with all these limitations. They can make mistakes if they do not operate with intentionality and if they don’t fight for what they deserve. The good news is that CISOs can get this right and write their own story. It’s just about thinking about it in terms of intent and our own story,” advised Pollard.

Going back to the Pixar example, he urged CISOs to simplify and focus. Like Pixar, they should combine characters (or tasks) and hop over detours.

“You will feel like you are losing valuable stuff, but it is actually freeing you. Fire yourself. find a way to replace yourself. Get rid of activities that you don’t need to do. And don’t be afraid to empower the direct reports that work for you,” he said.

Reproduced with permission from Forrester Research 

The 6 types of CISOs

Forrester Research began thinking about the future or the CISO two years ago and came up with a concept that there were 6 types of CISOs. The roles could overlap, and one could have the attributes of other types as well.

Pollard said the CISO should consider these 6 types when thinking about their intent and focus. These types give one the opportunity to think about their roles and future careers —  and even life after being a CISO.

We started thinking about this concept of the future CISO two years ago. We figured out there were 6 types of CISOs out there.

1. The Transformational CISO

This is a more strategic type of CISO who thinks about customers and business outcomes. They focus on turn around and transformation of the security program. They take it from one that may be too insular and too internally focused to one that focusses on the outside of the organization. They do this to make the security program more relevant to the rest of the business.

2. The Post-breed CISO

This CISOs comes in after the organization has been breached. There is intense media and board speculation. Add to that, litigation, regulatory investigations, and potential fines. There is a lot of chaos and they must remediate the situation and lead through the turbulence.

3. Tactical / Operational expert

This is the action-oriented CISO who gets things done. They are adept at sorting out technical issues and building out cybersecurity programs for the company.

4. Compliance Guru

They have a thorough knowledge of compliance requirements and they operate in a heavily regulated industry. They help the company to figure out how to navigate international issues and wars as well as oversight from the FTC, PCI, HIPPAA, and other regulatory bodies. For them, Security is always a risk management conversation.

5. The Steady-State CISO

The minimalist who doesn’t rock the boat and change the status quo overnight. They maintain a balance between minimal change and keeping up. Maybe things are just fine at the company right now and security is working for them.

6. Customer Facing Evangelist 

This type is common at the tech and product companies. They evangelize the company’s products and services with a commitment to cybersecurity. And they speak about how security and privacy help customers.

CISO Company Fit

Forrester defines “CISO Company Fit” as the degree to which the CISO type at the company matches the type the company needs to maximize the success of both parties.

“If the company fit is not suitable, then security leaders have to deal with burn-out and angst.  And part of that burn-out comes from the fact that they may not have CISO Company fit,” said Pollard.

Life After CISO

What happens at the end of a CISO’s career? What are the avenues that one should pursue as one moves towards semi-retirement?

Forrester analysts speak to many security leaders, some who have led successful 20-year careers. And those discussions have identified typical post-career avenues.

“CISO roles are not terminal roles. There is life after CISO. You have got to start thinking about what comes after this for me,” urged Pollard.

Some of the avenues a CISO could take are:

CIO – If you think the CIO is a tough boss, try working for a former CISO – and be a CIO yourself.

Founder/CEO – Commercialize those DIY tools your teams built.

Board Member –  Help other CISOs by being a cybersecurity board member. Your company may need a cybersecurity expert on the board.

Author / Speaker – The storyteller who can write their story and help other leaders who are going through the journey that they are going through right now.


 

570% Increase in Bit-and-Piece DDoS Attacks: Research

DDoS Attacks

The second quarter of 2020 witnessed an unprecedented increase in DDoS attacks compared to the same period last year. According to Nexusguard Q2 2020 Threat Report, there has been a nearly 570% increase in bit-and-piece DDoS attacks in the Q2 of 2020.  Bit-and-piece attacks result from injecting doses of junk traffic of negligible size into a large pool of IP addresses across hundreds of IP prefixes, which eventually paralyze the target when the junk traffic starts to accumulate from different IPs.

According to the report, attackers leveraged “bit-and-piece attacks to launch various amplification and elaborate UDP-based attacks to flood target networks with traffic.”

Key Findings
  • 515% increase in DDoS attacks overall, compared to the same quarter last year
  • 51% of bit-and-piece attacks were smaller than 30Mbps
  • Bit-and-piece DDoS attacks increased more than 310% compared to the previous quarter

The analysts from Nexusguard also stated that unlike the often seen attacks the newfound ones were using much smaller sizes, where more than 51% of bit-and-piece attacks were smaller than 30Mbps. Due to this, the communications service providers (CSPs) were forced to subject entire networks of traffic to risk mitigation. The entire processes are too much for CSPs to handle making typical threshold-based detection difficult and even more difficult to pinpoint the specific attacks to apply the correct mitigation.

One of the best methods for CSPs to handle these fiascos is to switch to deep learning-based predictive models to quickly identify malicious patterns and mitigate them at the earliest.

“Increases in remote work and study mean that uninterrupted online service is more critical than ever,” said Juniman Kasman, Chief Technology Officer for Nexusguard. “Cyberattackers have rewritten their battlefield playbooks and craftily optimized their resources so that they can sustain longer, more persistent attacks. Companies must look to deep learning in their approaches if they hope to match the sophistication and complexity needed to effectively stop these advanced threats.”

Blending Multiple Attack Vectors

Earlier, hackers used bit-and-piece attacks only with single attack vectors making the attacks based on that vector and easier in mitigation. Lately, hackers are blending multiple attack vectors to launch a wider range of UDP-based attacks making them harder for CSPs to detect. In scenarios like these, CSPs also find it difficult to differentiate between malicious traffic and legitimate traffic.

Microsoft’s Unsecured Bing Mobile App Exposes 6.5TB of Users’ Data

Data breach in 100 U.S. cities

Microsoft’s Bing mobile app exposed users’ sensitive information through an unsecured Elastic server. According to researchers at WizCase, the misconfigured server leaked Bing’s mobile application users’ data, including device details, list of URLs visited, operating system, search queries, search timings, GPS locations, and three unique identifiers — ADID (Advertising to an ad), device ID, and device hash. However, the server did not expose any personal information like users’ names or addresses. The server is now secured after WizCase reported the issue to Microsoft Security Response Center.

Massive Data at Risk

The researchers found over 6.5TB cache of log files that were left online without any password protection, allowing access to the public. “Based on the sheer amount of data, it is safe to speculate that anyone who has made a Bing search with the mobile app while the server has been exposed is at risk. We saw records of people searching from more than 70 countries,” WizCase said.

Besides the data breach, the researchers also stated that the search engine server was targeted by the Meow attack twice. While there is no information about any misuse of the leaked data, but the researchers stated the data breach could lead to a variety of attacks.

Misconfiguration Expose 250 Mn Customer Records

Earlier in a security alert, Microsoft admitted to a security blunder of misconfiguring a customer service and support database that exposed 14 years of customer service and support data dating back to 2005, accessible to anyone with a web browser requiring no authentication at all. As per Microsoft’s blog, on December 5, 2019, a change was made to the said databases’ network security group. It was later found that appropriate measures were not taken to verify the Azure security rules and this misconfiguration further led to the data exposure. The exposure was discovered by a security research team at Comparitech led by Bob Diachenko. He uncovered a total of five Elastic Servers containing 250 million records including logs of communication between Microsoft’s support engineers and its customers.

Disclaimer:

The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.  CISO MAG is merely passing on what has been discovered and reported by the source mentioned in the article.

Google Announces a New Age Solution for New Age Threats

Google Cloud, Google bug bounty

Google Cloud has been proactively working towards securing its own security periphery and providing its customers with a host of solutions that will help in upping their own security fencing. It all began with the acquisition of “Chronicle” in October 2019. Nine months later, it followed up a partnership with Tanium that saw the integration of Tanium’s high-fidelity and real-time security telemetry and Google Cloud Chronicle’s analytics and cloud-scale data capacity. This meant delivering instantaneous search and cyber forensics capability to its customers was now a reality. Following this suit, with increased volumes of new threat vectors coming in every day and with the shortfalls in the legacy security solutions, Google has now launched a new age solution for new-age threats – The Chronicle Detect.

The Need

It is often difficult to run multiple rules in parallel and at scale in the legacy systems, which creates latency in response even if a threat is detected. Add to this majority of the analytics tools use a data query language for writing detection rules. This adds to the burden of the person writing them in the first place. Finally, early detections depend on proactive threat intelligence on attacker activity, which many vendors lack. As a result, legacy security tools are unable to detect most modern-day threats.

Chronicle Detect as a Solution

To address these concerns, Google Cloud announced the Chronicle Detect, a threat detection solution built on the capabilities of Google’s security infrastructure to help enterprises identify threats at high speeds and at scale. Chronicle Detect has a data fusion model that pieces all events into a unified timeline, has a rules engine to handle common events and a language for describing complex threat behaviors.

Chronicle Detect has the gen-next rules engine that operates at the speed of search with a regular stream of new rules and indicators added frequently by the Chronicle’s internal research team. It is easier for enterprises to move from legacy security tools to a modern threat detection system like Chronicle Detect because security teams can send their security telemetry to Chronicle at a fixed cost so that diverse, high-value security data can be taken into account for detections. This security data is then made useful by mapping it to a common data model across machines, users, and threat indicators, so that its users can quickly apply powerful detection rules to a unified set of data.

The rules engine makes use of a very flexible and widely used detection language in the world, YARA. This eases the pressure of writing the rules for detection tactics and techniques found in the commonly used MITRE ATT&CK security framework. Additionally, it is observed that many organizations are integrating Sigma-based rules across systems or converting their legacy rules to Sigma for portability. Thus, Chronicle Detect includes a Sigma-YARA converter, which allows porting of rules to and from the platform.

Chronicle Detect has integration with Uppercase as well. Uppercase acts as a directory that provides IOCs, indicators of APTs, and other information related to cybercriminal activities. Thus, this is an add-on privilege for the platform’s customers as they can take advantage of its detection rules and threat indicators.

In Google’s own words this is just the beginning of things to come. With threat actors evolving their techniques every day, Google plans to counter that with a more secure solutions suite offering to its customers.

CYBERSEC: Make Cybersecurity a Global Effort

CYBERSEC Cybersecurity Forum

The Kosciuszko Institute successfully launched CYBERSEC Global 2020 on September 28. For the 6th time, the conference becomes a platform to discuss various paths of building cybersecurity within our new digital reality. Opening keynotes were made by distinguished speakers such as The President of Armenia, Armen Sarkissian; Abigail Bradshaw, the Head of the Australian Cyber Security Centre; Mircea Geoana, Deputy Secretary-General of NATO; and Vinton Cerf, Vice President and Chief Internet Evangelist at Google. The three-day event has more than 100 speakers and several presentations and panel discussions.

Izabela Albrycht, the President of the Kosciuszko Institute
Izabela Albrycht, President of the Kosciuszko Institute

The new reality refers to the pandemic and technological advancements that enrich our societies and pose new risks. The COVID-19 crisis taught us that we need to do more to protect and remain competitive in the cyber technology field. Izabela Albrycht, the President of the Kosciuszko Institute, said the Internet not only empowers us, keeps us connected, and build our future, but also exploited to spy, steal money or identities, overpower law and order, and suffocate democracy. Many states faced malicious activities during the pandemic.

“The Internet has a design flaw and lacks security by design and privacy by design. Since we are moving more critical functions to the online world this has to be addressed,” said Albrycht. “This edition of the CYBERSEC Forum together with the theme ‘Together against Adversarial Internet’ brings a crucial conversation about cyber threats to our real world, at the right time.”

Abigail Bradshaw, the Head of the Australian Cyber Security CentreThe internet was not built with security in mind and today we face the consequences of its flawed design. One of the most vivid examples of such a state leads us to Australia. Although hacking activities have increased across the globe, Australia has been a target to one of the largest cyberattacks in history. As Abigail Bradshaw, the Head of the Australian Cyber Security Centre, admitted, many of their public and private sector participants, such as hospitals, universities, and businesses have become a target in 2020. Statistically, an attack occurred every 10 minutes in Australia alone.

“Since the pandemic onset more than six months ago, my centre has observed a sharp rise in email phishing, message scams, and ransomware attacks capitalizing on the uncertainty that is coming with COVID-19,” said Bradshaw. “Between July last year and the end of June this year, our cyber reporting tool received almost 60,000 cybercrime reports from individuals and businesses across Australia, or roughly one report every 10 minutes.”

Bradshaw said many of the lessons learned from COVID are applicable to the digital environment.

“Preventing and containing damage and elimination of the threat requires collective action and collective raising of defenses. Everyone has a role to play in that effort. It requires global collaboration with individuals, academia, industry and government,” added Bradshaw.

Global Conflicts and Risk

We’re living through peacetime in most parts of the world; however, not without any tensions and conflicts that pose a global risk. On the day before launching CYBERSEC Global 2020, Armenia and Azerbaijan declared martial law over the violence in parts of Azerbaijan, Armenia, and the Nagorno-Karabakh region, which is the source of conflict between those states for more than 30 years.

The conflicts have been a part of human history dating back but the way they are led has evolved with technology advancements and has driven them —  at the same time cyber warfare has become one of the most used weapons. It allows attacks across borders, possibly with a higher impact, and at a low risk that maybe even lowered by the fact it is so hard to identify the real sources of the attacks.

The real problem is that today, conflicted regions can be remotely destabilized, becoming a war zone for others not directly involved actors. We have yet to see how the Azerbaijan-Armenia conflict will develop, but learning from the conflict over Crimea – we need to be aware that cyberattacks can become a part of the actions in this region, and they don’t need to be led by the exact conflict sides.

President of Armenia, Armen SarkissianThe President of Armenia, Armen Sarkissian, argues that the solution to our new position should be found through dialog, not through technology. In an arms race, the force is continuously distributed. For every new weapon, a better one can be invented. On the other hand, inviting states, both superpowers and smaller ones, business technology giants, and other stakeholders to the table can lead us to form a new reality in which even with tensions, the situation is more stabilized and predictable.

Different Views 

Mr. Mircea Geoana, Deputy Secretary-General of NATOThe problem around the world’s cybersecurity is widely recognized. It was even referred to as the new “Sputnik moment” by Mr. Mircea Geoana, Deputy Secretary-General of NATO, making a race towards unleashing the most potential of new technologies for one over another being a multi-sided effort.

He said there are various concepts to maintaining the state’s immunity to cyberattacks – at least to most of them – and making them cyber powers. Some countries, such as China and Russia are investing heavily in the new technologies to increase control over their citizens and exert influence in the world.

“NATO recognizes the need to introduce rules that will act similarly to the Geneva Conventions. We need to have a set of rules that work both at the time of war and peace, making the core of the internet as safe as schools and hospitals even during military conflicts. Today, without any regulations, even hospitals fall to cyber strikes, which can lead to as far-going consequences as civilian casualties,” said Geoana.

Vinton (Vint) Cerf, Vice President and Chief Internet Evangelist at Google

The Western countries are following the path of introducing new regulations through dialog while keeping the Internet open. As Vinton (Vint) Cerf, Vice President and Chief Internet Evangelist at Google, also known as one of the fathers of the Internet, said, “The internet has been a great addition to our society and if we diminish its role in open information sharing, this will become a great loss to humanity.”

Cerf also said that the internet is insensitive to the boundaries of countries.

“An attacker can be in one country and the victim can be in another. So we need to think about how we are going to cooperate across those international boundaries to protect our citizens from harm. That will require serious cooperation across international boundaries to come up with common norms and practices that will help countries protect their citizens,” said Cerf.

The states need to take care of their cybersecurity on the infrastructure level as well. For example, the European Union has introduced a 5G Toolbox which creates a space for national security reviews and blocking telecom contracts with higher-risk vendors, such as Chinese ZTE or Huawei.

The Way Forward? 

What is the way out of our uncertain situation when it comes to cybersecurity? It begins with identifying the problems of the modern society, which is heavily rooted in the technology both to its benefit and harm. The next step is through having meaningful conversations with all parties invited to share their views openly to find a compromise for the global community.

One of the platforms for such dialogue is CYBERSEC Global 2020 which takes place from September 28-30. The registration is open throughout the whole event. Register here: https://csglobal20.eu/register/

Together with the 6th Edition of CYBERSEC Global 2020, a new issue of The European Cybersecurity Journal, a specialized publication devoted to cybersecurity, has been launched on cybersecforum.eu/journal.

About CYBERSEC Global Forum

EUROPEAN CYBERSECURITY FORUM – CYBERSEC is one of the leading cybersecurity conferences in Europe, organized by the Kosciuszko Institute since 2015. Throughout its six years of history, CYBERSEC has partnered with important international institutions such as NATO, European Commission and European Parliament and has organized 11 editions of CYBERSEC Forums in Europe (Warsaw, Kraków, Katowice and Brussels) and in the United States (Washington) including the participation of renowned figures from different walks of life invested in bringing awareness to cyber threats.

It has also been involved in other region-wide group efforts to provide a secure and safe framework to navigate cyberspace, chief among them the Three Seas Initiative. Furthermore, the EUROPEAN CYBERSECURITY FORUM has been an important advocate voice for a secure rollout of the 5G network, knowledge sharing and upholding good practices in the field of data privacy, and promoting respect in the EU for the NIS Directive among other endeavors.

Through the years, CYBERSEC has hosted 748 speakers from more than 45 countries, more than 400 accredited journalists, enjoyed the support of 293 Partners and Patrons and welcomed more than 5580 participants.


RELATED REPORT

CYBERSEC: Europe’s Most Anticipated Cybersecurity Conference is Here

CISO MAG is Media Patron for CYBERSEC Global Cybersecurity Forum 2020.

Ask Yourself These 4 Questions Before Shopping Online

Ask Yourself These 4 Questions Before Shopping Online

E-commerce has reshaped the shopping habits of consumers. From the convenience of buying at one’s fingertips to the endless discounted deals, online stores have grown in popularity in a short time. However, the growth in e-commerce has also led to various frauds and cyberattacks. Cybercriminals are tricking shoppers with imposter websites and products or stealing their payment card details.

By Rudra Srinivas, Feature Writer, CISO MAG

Multiple security incidents were reported on online stores by Magecart hackers. Recently, hackers compromised over 2000 Magento e-commerce platforms in the largest automated Magecart campaign. In Magecart attacks, (also called web skimming or e-skimming attacks) hackers inject malicious JavaScript code on the website checkout pages to exfiltrate customers’ payment information.

So, what can you do to defend against these attacks? Here are four questions to ask yourself to find out how secure your online shopping is: 

1. How secure is the website?

Cybercriminals create fake or lookalikes of legitimate e-commerce sites to collect sensitive information from users. Do thorough research to find out the authenticity of the website and its products before making any purchases.

According to a research report from Juniper Networks, e-commerce, money transfer, and banking services will lose over $200 billion to online payment fraud in the next five years. The increasing ubiquity of digital payments provides an ever-increasing attack surface for fraudsters.

Attackers often impersonate popular brands by creating a lookalike website, similar domain name, or URL of the original site. When a user clicks on these links, it redirects them to a fake website, which often contains a form intended to steal user credentials, payment details, or sensitive information. Avoid clicking on ads that lure users with unbelievable offers, as they could be malicious or intended to phish the users.

2. Is it safe to share personal information?

Be vigilant about the information you give to complete the payment process. Cancel the transaction if you feel the site is collecting additional information than required. Fill out what is necessary at the checkout page and remember not to save your payment information on the site. Make sure you delete your previously stored payment details from the account, as the data may fall into wrong hands if your account gets hacked.

3. How secure is your internet?  

Securing your internet connection is essential when it comes to protecting your data/device against cyberattacks. Unsecure internet might allow threat actors to break into your network or device. Never use public Wi-Fi to shop online. Even when accessing your home network, use a VPN (Virtual Private Network) for additional security. VPNs provide a secure connection to users when they join another network online. It also changes the IP address and location, making your browsing activity safe and private from threat actors.

4. Is your password strong enough?

We cannot underrate the importance of password management while talking about online security. According to a study by Microsoft, 44 million users were reusing their usernames and passwords. The survey also exposed that the largest percentage of passwords were weak and used for a long period.

Using a passphrase rather than a password will give you maximum security for your network, however, make sure the passphrase you choose is easy-to-remember and complex at the same time. Make sure you have a strong and complex password, which is difficult to guess. Change it on a regular basis to reduce the risk of threat exposure.

Final Note

Since e-commerce gives consumers the freedom to shop on multiple devices, it has grown to be a preferred option. As shopping habits evolve, so do cybercriminals. New social engineering techniques are leveraged to deceive and mislead consumers. We need to stay mindful, avoid clicking on third-party links, or download attachments before reviewing them.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

Saudi Auditing Bureau Adopts Cybersecurity Strategy Plan

Saudi Arabia

To combat rising cybercrime and cyberattacks targeted against the country and the institution, the General Court of Audit (GCA) of Saudi Arabia has adopted a new cybersecurity strategic plan. The plan aims to create safe and reliable cyberspace, support the bureau’s work, protect its information and technical assets, and promote best practices in the field of cybersecurity, and will thereby focus on strengthening and protecting the institution from both — internal as well as external threats.

President of General Court of Audit (GCA), H.E. Dr. Hussam Alangari approved the plan and pressed for the organizational structure of the cybersecurity department. The plan would incorporate key cybersecurity principles like confidentiality, safety, and availability of cybersecurity infrastructure, and awareness to make sure that the protection measures adopted by the nation would be accurate and appropriate.

“The cybersecurity strategy was designed to introduce recommendations related to cybersecurity in GCA that are consistent with the work nature of GCA. This move will enable work initiatives such as the governance, compliance, risk management, preventing and detecting cyber threats, longevity of cybersecurity, and building the capacity of human resources in the cybersecurity field in addition to providing a clear and unified vision to be circulated among GCA departments and branches,” GCA stated in a release.

It added, “the plan will be applied on all personnel related to the issuance of identities of users and management of these users and issuance of authorizations according to their roles in the systems of GCA. The cybersecurity strategy will be also applied on entities dealing with GCA and using its data or any information assets of GCA.”

Cybersecurity Greatest Threat to Saudi Businesses

An earlier survey by KPMG CEO Outlook saw 20% of the CEOs in Saudi Arabia reach a consensus that cybersecurity risks are the biggest threats to their businesses. According to the CEO responds of the survey 60% of CEOs regarded information security as a strategic function that gives their organizations an edge over their competitors while 14% believed they expect a cybersecurity risk or incidence in immediate future. The survey also highlighted that 56% of organizations in Saudi believe they are ready for a cyberattack while 54% stated that they have faith that a strong cybersecurity strategy creates trust among all its stakeholders.