Home Blog Page 166

McAfee Consumer Security Portfolio Integrates Social Media and Tech Scam Protection

blockchain-based social media, Parental Consent for Minors, Iranian Facebook accounts

With the home, school, and the office now becoming a common space for employees, the attack surface broadens to includes consumers and endpoints. Employees tend to spend more time on social media and are susceptible to tech scams and phishing attacks. To address this, McAfee today announced its latest consumer security portfolio and said the enhanced offering has new features, including integrated social media and tech scam protection. Meeting consumers in their current realities, these new functionalities are designed to protect users from current threats as they navigate professional and personal life from home.

“With the convergence of home, office, and school, today’s consumers need end-to-end device and web protection that secures every aspect of their digital lives,” said Venkat Krishnapur, Vice President of Engineering and Managing Director, McAfee India. “Tailored to the increasingly connected world in which we live, McAfee’s evolved product suite is a holistic approach to securing every facet of the connected consumer’s life.”

Security and Privacy Get a Boost 

According to the McAfee COVID-19 Threat Report: July 2020, from McAfee Labs, there was an average of 375 new threats per minute via malicious apps, phishing campaigns malware, and more.

To address these threats and combat emerging Coronavirus-related scams, McAfee’s product lineup includes the following updates and enhancements:

  • Tech Scam Protection: McAfee WebAdvisor now provides a warning when visiting websites that can be used by cybercriminals to gain remote access to your PC, combatting the reported 128 crore total online fraud loss in India.
  • Advanced Malware Detection: McAfee enhanced its machine learning capabilities to improve overall time to detect emerging threats across devices as well as added protection against file-less threats.

Improving Customer Experience

Consumers default to convenience over security, making protecting themselves online an afterthought until it is too late, and they become compromised. Despite the increase in online frauds during the pandemic, online payments in India have soared, with UPI (Unified Payment Interface) recording close to 1.5 billion transactions in July 2020.

At a time where returning to previous routines is still uncertain and internet usage continues to climb, McAfee recognizes consumers need intuitive solutions that allow them to devote attention to what matters most to them right now, including:

  • A Better User Experience: An improved PC and app experience with easier navigation and readable alerts, and clear call to actions for faster understanding of potential issues.
  • Updated Password Protection: Access iOS applications even faster with automatically filled in user account information and passwords in both apps and browsers on iOS devices.

Safety Now – and Into the Future

As consumers globally continue to settle into a new way of operating, they rely on the internet to live their connected lives- to get work done, seek entertainment, connect with friends and family, conduct purchases, schooling, and more.

Key Features

  • Optimized Product Alerts: Redesigned product alerts, so consumers are better informed about possible security risks, with a single-click call to action for immediate protection.
  • Social Media Protection: To help prevent users from accidentally visiting malicious websites, McAfee now annotates social media feeds across six major platforms – Facebook, Twitter, YouTube, Instagram, Reddit, and LinkedIn.
  • Enhanced App Privacy Check: Consumers can now easily see when mobile apps request personal information, with app privacy now integrated into the main scan of Android devices.

Disclaimer: CISO MAG did not evaluate the products mentioned in this news report. Facts mentioned here were drawn from a McAfee Press Release and CIO MAG shall not be held liable for the performance of this product.

 

 

Key Questions for Implementing Strong Security and Compliance Programs

cybersecurity compliance

To arrive at the right answers, one first needs to ask the right questions! CISOs who discover that their actions do not generate the desired results to strengthen security and compliance postures may not be asking the right questions. Effectively managing data, information risk, and compliance is complex and ever-changing. There are many components and considerations in developing and implementing a robust program that encompasses and integrates all the elements needed to manage risk and achieve one’s compliance objectives effectively. A critical component is making sure to ask the right questions of the right people.

By Jason Taule, Vice President of Standards & CISO, HITRUST

The right questions include those that CISOs should ask themselves as well as the management team, the operations team, and other key stakeholders, including the Board of Directors. CISOs who come up with the questions on their own will likely tailor the questions to their situation and environment — often driven by functional and operational priorities that may not directly line up with the top-line business objectives. More specifically, an ad-hoc approach usually overlooks some of the
core questions that matter in establishing a strong security and compliance posture.

Answer the Right Questions to Drive Business Results

By collaborating with people from across the organization and asking questions focused on risks and controls tied directly back to the business, CISOs can drive decisions that truly get at what the organization needs to achieve the security and compliance postures the business is seeking. This, in turn, leads to an action plan to produce the desired business results.

The ad-hoc approach perpetuates managing the security and compliance program in a reactive fashion — where the focus is only on the immediate situation at hand. How should CISOs avoid situations where they have to ask themselves, “Where did I fail the business?” They can do this by taking a results-driven, proactive approach adopted by others in their industry. They can work with internal stakeholders to adopt a set of questions that demonstrate how to get to the “why” behind their security and compliance programs.

The Pitfalls of Creating Risk Profiles Based Purely on the Technical Environment

A key responsibility for every CISO is to seek the necessary information to understand their company’s security and compliance risks. The resulting risk profile can then be translated into recommendations and options that the internal security team and executive team members can understand, throw their support behind, and take action. Ultimately, it’s about the action; and action must have a purpose more significant than the technical elements that technology leaders lean on.

Early in a CISO’s career, it may seem that the questions to ask to find such information must be explicitly created for the technical environment that’s being secured and the business environment is supported. This, however, could lead to many issues:

  • Misaligned or missing questions
  • Baited or ill-timed questions
  • Yes/no questions that do not provide context
    • Questions that do not go deep enough or don’t connect to tell the full story
  • Questions that do not drive an understanding to get buy-in to act from the business

Instead, what is needed is a list of questions, in the right order, and a projection of what the answers could be, might be, and should be. Projecting the answers helps make sure the questions are on target and presented in an order that will elicit contextualized thinking. This may also result in the need to re-visit the questions once previous assumptions are confirmed or refuted.

Another critical facet is deciding when to ask the questions of each stakeholder. The results of each interview could influence the questions of subsequent discussions. So, the order in which the CISO connects with the stakeholders is critical. And after collecting the answers, the CISO needs to validate the information and investigate unforeseen responses to find out what is reasonable and if any of these provide incorrect information.

Similar to the assumptions made above, the more you understand as you move along this journey, the more likely you’ll want to re-visit other decisions taken along the way. CISOs need to find a delicate balance that is appropriate for their organization, which enables them to ask the right questions first, and methodically answer the questions through an investigatory process that appropriately assesses vulnerabilities. There is no room for poor decision making and misaligned actions.

Questions that Drive Security Action Plans

While well-constructed questions and a strategy for conducting interviews with key stakeholders will produce highly valid answers, there’s still no one-size-fits-all response to risk and security management. However, a consistent, transparent approach that spurs conversation as the organization assesses risk and drives toward decisions and actions will bring your organization closer to reaching the expected/desired responses.

Before engaging others, CISOs should consider their own high-level perspective: What is the organization’s security and compliance posture? Where do those postures need to be? How does the organization get there? Thinking along these lines helps CISOs digest what they hear from others to probe for issues surrounding compliance, risk, and assurance in a way that leads to the “why”:

  • What is our current risk exposure and security posture? What level of risk exposure is acceptable, and what security posture is desirable?
  • Do we have the most appropriate framework?
  • How do we compare to other organizations in our industry?
  • Where do we need to be? How do we select a program and tools that will scale within the organization?
  • Is what we are doing sufficient and, if not, what level of resources do we need to apply?
  • To which partners and customers do we need to provide or obtain security assurances, and what are our processes to do so?
  • What do we need to do to fulfill our due diligence expectations?
  • What do we need to do to qualify for cyber insurance? Can we obtain a better policy and/or reduce our premiums?
  • How do we keep up with new business services, expanded industry/market profiles, emerging threats, and changing regulatory requirements?

The above is just a consolidated sampling of crucial questions that have been an important starting point in my role as a CISO. Every CISO should identify their own set of questions along these lines, and evaluate each of them per the audiences they are meant for. This can include the executive team, the Board of Directors, partners, customers, third-party vendors, and the internal IT security team. The answers will give the CISO a broad perspective on what actions require the highest priority for bolstering the organization’s security, compliance, and privacy postures. We do not need to reinvent the wheel, thanks to others who have demonstrated methods and approaches that can be leveraged – not only to save time, but to ensure the right plans are put in place for the business.

Action Plans Help Implement Mitigating Controls to Manage Risk

While taking this approach, it’s vital to utilize a standard, proven approach—the HITRUST Approach™, as one example. It includes questions created and maintained by risk management experts in conjunction with industry leaders tied to a comprehensive privacy and security framework and world-class assurance program. This helps generate the required answers to drive actions while also identifying and understanding security risks transparently and accurately. The CISO can then better communicate the risks and mitigation options, and the required security and compliance controls and information risk posture.

A two-way approach with all relevant stakeholders combined with a self-assessment approach gives me the answers to do my job as CISO. To promote this I set up a campaign coined as the “Just ask Jason” program. It allows everyone to receive and contribute information and be part of the risk and security management solution. I even printed up buttons that read, “Just ask Jason” and handed them out to the Board as a reminder to keep an open channel for security communication.

It’s all about driving actions that result in implementing controls to manage risk. Each stakeholder within the organization has an answer to one or more questions that will help tell the story and paint the picture an organization needs to achieve security and compliance posture. Once the questions have been asked, we then analyze the answers to understand the necessary controls — using a consistent, independently-proven, and validated approach. CISOs will find that an ad-hoc approach will produce random results. Conversely, CISOs that answer the ultimate question “why?” via an approach described above, will find the results to be closer to what they desire and expect.

To develop strong security and compliance postures, every organization needs a “Just Ask Jason” campaign. For advice on how to set up a similar program for your organization, “Just Ask Jason” Taule by reaching out to him at [email protected] or visiting https://hitrustalliance.net/

About the Author

Jason Taule is an information security luminary who has served in most capacities within the industry. He started in the intelligence and government sectors first consulting to Federal agencies and then serving as inside Chief Security / Privacy Officer both within the Government and at large systems integrators like General Dynamics and CSC. Mr. Taule helped build the original DARPA CERT, helped develop the first computer security programs at the VA and NASA, and revised the Risk Assessment Methodology still used throughout DHHS. He enabled hundreds of systems to earn their accreditations and remain free from compromise. Mr. Taule currently serves as HITRUST VP of Standards and CISO overseeing the development and evolution of the HITRUST CSF to ensure its relevancy and continued sufficiency while also ensuring that HITRUST continues to earn and keep the confidence our customers and third parties who have entrusted us with the safekeeping of their data.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

India Witnessed Over 1.45 Million Cybersecurity Incidents in Five Years

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

Computer Emergency and Response Team – India (CERT-In) recorded over 1.45 million cybersecurity incidents including breaches and hacks between 2015 and 2020. According to the India’s Ministry of Electronics and Information Technology (MeITY), Cert-In reported 49,455, 50,362, 53,117, 208,456, 394,499 and 696,938 cybersecurity incidents during the year 2015, 2016, 2017, 2018, 2019 and 2020 (till August) respectively.

The figures were out after the ministry was asked about growing cyberattacks targeting Indian citizens as well as commercial and legal entities. According to the Internet Crime Report for 2019, released by the U.S. Internet Crime Complaint Centre of the Federal Bureau of Investigation, India stands third in the world among the top 20 countries that are victims of internet crimes. Reports also suggest that the number of internet users in India has grown six-fold between 2012-2017 with a compound annual growth rate of 44%.

“With the proliferation in the internet and mobile phone usage, there is a rise in the number of cybersecurity incidents in the country as well as globally. Proactive tracking by CERT-In including its Cyber Swachhta Kendra and National Cyber Coordination Centre (NCCC) and improved cybersecurity awareness among individuals and organizations across sectors has led to increased reporting of incidents,” according to NITI Aayog report by member VK Saraswat.

To combat the attacks, the government has also taken up several initiatives. These include:

  • Regularly issuing alerts and advisories regarding the latest cyber threats/vulnerabilities and countermeasures.
  • Issuing guidelines for Chief Information Security Officers (CISOs) regarding their key roles and responsibilities for securing applications/infrastructure and compliance.
  • Empaneling 90 security auditing organizations to support and audit the implementation of Information Security Best Practices.
  • Formulating Cyber Crisis Management Plan for countering cyberattacks and cyber terrorism for implementation by all Ministries/ Departments of Central Government, State Governments, and their organizations and critical sectors.
  • Conducting mock drills to enable assessment of cybersecurity posture and preparedness of organizations in Government and critical sectors.
  • Conducting regular training programs for network/system administrators and Chief Information Security Officers (CISOs) of Government and critical sector organizations regarding securing the IT infrastructure and mitigating cyberattacks.
  • The government has also launched the Cyber Swachhta Kendra (Botnet Cleaning and Malware Analysis Centre). The center is providing detection of malicious programs and free tools to remove the same.
  • Setting up of the National Cyber Coordination Centre (NCCC) to generate necessary situational awareness of existing and potential cybersecurity threats and enable timely information sharing for proactive, preventive, and protective actions by individual entities.

India Reports Twice as Many Attacks Compared to Other Countries

The recent Acronis Cyber Readiness Report 2020, from cybersecurity firm Acronis revealed how organizations are mitigating the effects caused by the pandemic to their business operations and security posture. The report revealed that 56% of organizations stated that their IT costs have increased significantly in the past months. India reported nearly twice as many cyberattacks as any other country, followed by the U.S. and the UAE.

“Adaptation of digitization is taking place at a faster pace, be it in businesses or in other walks of life. It is expected that we will be soon transiting wholly to newer technologies like cloud computing, Artificial Intelligence, Internet of Things, and 5G spectrum, which will naturally expand our dependency on digitization multifold. However, in the absence of stringent cybersecurity infrastructure, cyber threats can be disastrous for our entire social fabric. There has been a recent surge in cyberattacks on Indian digitals cape that are only increasing in scope and sophistication, targeting sensitive personal and business data and critical information infrastructure, with an impact on the national economy and security. Cyberwarfare is relentless in trying to erode the security fortification of several sectors in the country. This is certainly a wakeup call for India to have stronger policies in place,” said Nikhil Korgaonkar, Regional Director, India & SAARC at Arcserve.

Are You a Content Creator? Facebook’s New “Rights Manager” is for You!

Facebook

Facebook has just launched its “Rights Manager” tool to grant ownership control over to the user for images published on the Facebook and Instagram platforms. The Verge reports that Facebook has partnered with certain unnamed innovative tech solutions for this offering. This innovative tool will give content creators of both Facebook and Instagram platforms rights to claim ownership of their own images as it currently does for music and video rights.

How Does the “Rights Manager” Work

To access the “Rights Manager” tool, Facebook Page admins first need to apply for the content they’ve created and want to protect. Rights Manager will find matching content on Facebook and Instagram.

  1. Upload a CSV file to Facebook’s Rights Manager that contains all the image’s metadata. Adjust settings to match things like ownership applicable worldwide or only in certain locations and so on.
  2. Once you hit “Apply for Rights Manager” the internal algorithm verifies the metadata and matches the image.
  3. Once the process is complete it then displays the image and pages where it is showing up.
Facebook Rights Manager
Image Credit: Facebook
What if two parties claim ownership?

If another person claims ownership of the same image, then the two parties can dispute the claim. However, if no settlement is agreed upon, Facebook will eventually bestow it to the one who filed first. This decision can again be appealed in Facebook’s IP reporting forms.

Copyright and ownership of content has been a prolonged issue especially on social media platforms where sharing and posting is just two-clicks away. However, Facebook acknowledges the fact that quality content creation is a cumbersome task and thus, it is clearly the intellectual property of its creator. It believes that upending such solutions will put content creators in charge of their content and help clear the clutter of aggregated content (image) sharing and publishing, which at times robs them of their ownership, attribution, and credit.

DHS and CISA Warn Federal Agencies to Patch “Zerologon” Flaw

cyberthreats, bug

The U.S. Department of Homeland Security (DHS) and the Cybersecurity and Infrastructure Security Agency (CISA) asked federal authorities to update all their Windows systems that are vulnerable to the CVE-2020-1472 bug. In an emergency directive, the agencies urged to update all Windows Servers with the domain controller role in any information systems which collects, processes, stores, transmits, disseminates, or maintains agency information.

The vulnerability dubbed as “Zerologon” affects Windows Server 2008 and onwards. An attacker can exploit the flaw by leveraging the Netlogon Remote Protocol to get a connection to the domain controller.

Patch Unfinished

Microsoft patched the vulnerability in its August Patch Tuesday last month. According to CISA, several proof-of-concept exploits caused widespread concern across the industry and the bug was unpatched in many government agencies. The vulnerability could allow attackers to hijack the Windows domain controller. All an attacker requires is local network access, which is also why it cannot be performed directly over the internet. However, if an attacker sets their foothold in the target environment, they can change the administrator password on any Windows Domain Controller they can reach.

CISA stated that the vulnerability may cause severe security risks to the Federal Civilian Executive Branch. The determination of the vulnerability is based on:

The availability of the exploit code in the wild increasing likelihood of any unpatched domain controller being exploited.
The widespread presence of the affected domain controllers across the federal enterprise.
The high potential for a compromise of agency information systems.
The grave impact of a successful compromise.
The continued presence of the vulnerability more than 30 days since the update was released.

“Update all Windows Servers with the domain controller role.  Apply the August 2020 Security Update to all Windows Servers with the domain controller role. If affected domain controllers cannot be updated, ensure they are removed from the network. And ensure technical and/or management controls are in place to ensure newly provisioned or previously disconnected domain controller servers are updated before connecting to agency networks,” the emergency directive added.

It’s Jail Time! Australian Government Employee Sentenced for Mining Cryptocurrency

Cryptocurrency mining

In May last year, the Australian Federal Police (AFP) pressed charges against a 33-year old former resident of New South Wales (NSW) for his alleged role in manipulating Commonwealth Scientific and Industrial Research Organisation’s (CSIRO) computer system for mining cryptocurrency and presented him in the federal court.

What Happened

CSIRO is an Australian Government agency that collaborates with leading organizations around the world in the field of scientific research. The alleged cybercriminal was hired in CSIRO as an IT contractor in January 2018. His work profile gave him access to the servers and other IT systems in the organization. The AFP later found that the cybercriminal used these servers and systems in an unauthorized manner to manipulate and carryout mining of cryptocurrency, which totaled to approximately AU$9,400 (approximately US$ 6,830).

The AFP’s Cybercrime Operations unit investigated the matter after CSIRO reported a “serious impairment of its infrastructure.” The federal police got a search warrant and raided the man’s house in Sydney on March 5, 2018. During the raid, officials seized a laptop, personal phone, employee ID cards and many data files, which later proved his involvement. The AFP pressed two charges against him:

  • Unauthorized modification of data to cause impairment, contrary to section 477.2 of the Criminal Code Act 1995 (Cth)
  • Unauthorized modification of restricted data, contrary to section 478.1 of the Criminal Code Act 1995 (Cth).

The Conviction

The alleged misuse of CSIRO’s assets had caused nearly AU$76,000 (approximately US$ 6,830) of funds impairment that was irreparable. This was the hard-earned money of common Australian tax-paying citizens that went down the drain, and thus CSIRO demanded the toughest prosecution for the accused. Although the accused had pleaded guilty for his offenses in February 2018, all angles had to be taken into consideration and a detailed investigation was necessary.

After 16 months of his first hearing, the accused has been sentenced to a 15-month imprisonment term by way of an intensive community order, which includes 300 hours of community service.

Data Security Requires a Holistic View

small businesses cyberthreats

Public and private enterprises across all verticals must be concerned with the secure handling of personally identifiable information (PII) of their employees and customers, trade secrets and intellectual property (IP), financial, product and planning information, and other data critical to their business. Mishandling of PII data can result in a violation of stringent regulations, including the General Data Protection Regulation (GDPR) and the Gramm-Leach-Bliley Act (GLBA), opening the firm to financially and reputationally damaging fines. The loss of IP and other data can damage an enterprise’s ability to compete or do business effectively and result in reputation loss.

By Grant Evans, Chairman and Chief Executive Officer, SPYRUS

The Data Protection Conundrum

Protecting data is a daunting task and requires a view towards preserving the Confidentiality, Integrity, and Availability of data — also known as the CIA triad. Data must be protected when it is in motion, at rest and in use. The mobility of an enterprise’s workforce complicates matters further. The current pandemic has extended every office environment to every home and location with a hotspot, which is likely to be the new normal.

While telecommuting offers employers the flexibility to “extend the office” into environments where employees want to work, or must when circumstances demand, it also expands the threat landscape exponentially. Whether it is a home office, local coffee shop, or a hotel lobby, employees can continue contributing to the business from anywhere in any way. Unfortunately, perceived increased productivity could quickly become detrimental. Extending the office beyond a “controlled” building also extends the company’s network, stretching security thin and opening holes for hackers. Most often, hotel, home, and coffee shop Wi-Fi networks are not secure enough to protect sensitive data used by insurance, banking, and health care companies. This exposes the company to fines stemming from violations associated with Code of Federal Regulations (CFR) Standards for Safeguarding Customer Information, Health Insurance Portability and Accountability Act (HIPAA), General Data Protection Regulation (GDPR) and the growing number of privacy regulation at Federal and Municipal levels. While securing and managing endpoints with software protection and mandatory VPN usage mitigates the risks associated with data in motion, it does not address the protection of shared data and often hinders stakeholder collaboration.

How can teams effectively collaborate on projects if employees and managers and even third-party partners cannot see who made what changes and when to presentations, whitepapers, contracts, et al.? Perhaps more importantly, how can enterprises ensure that their stakeholders only share data with authorized persons and be confident that the data is still protected at its destinations? Most data protection schemes focus on either limiting access or sharing data and hoping for the best.

SPYRUS believes a true long-term data protection solution requires a holistic approach that quickly identifies and thwarts threats without extensive financial and labor resources.

SPYRUS Solutions

SPYRUS Solutions provides a holistic approach with cost-conscious and easy to use cryptographic solutions incorporating encryption, authentication, and management. The SPYRUS DevicePatrol™ Platform comprises of hardened endpoints and endpoint cryptographic management, in a secure collaboration environment.

SPYRUS hardened endpoints are the most secure in the industry — FIPS 140-2 Level 3 validated, ensuring both physical and logical security controls resulting in an anti-tamper design that provides Military-grade encryption and multi-factor authentication for any enterprise.

With the SPYRUS DevicePatrol management software, endpoint activity is audited and logged even when used offline. If the endpoint activity is concerning, an enterprise administrator can “disable” the token or “destroy” the endpoint keys remotely anywhere in the world, rendering all data on the drive useless (temporarily or indefinitely).

Enterprises also need to enable secure collaboration between employees and sometimes with external parties, protecting both the critical data and critical workflow. To that end, SPYRUS offers a unique and secure collaboration environment.

Secure Data Protection and Collaboration

The SPYRUS NcryptNshare application allows for individual documents, files, and folders to include digital signatures, ensuring the shared data source. NcryptNshare also creates a secure personal vault on each user’s personal computer(s) that cannot be accessed or viewed without applying and unlocking the user’s Rosetta token that protects the encryption and authentication/signature keys in FIPS 140-2 Level 3 hardware.

NcryptNshare provides the highest level of object encryption and controlled access so that cloud or other unsecured communication locations/paths can be used with the highest levels of confidence. For example, a user can share information with only the intended recipient(s) via email, instant message, or any medium in the public cloud. A user can create secret file folders only accessible to individuals in groups who have their own Rosetta token.

The SPYRUS patented “seal” of the encrypted file prohibits any tampering (for instance, by malware), ensuring data is protected wherever it is stored. SPYRUS also provides data recovery capability that can be managed by the enterprise should a user’s key be lost, disabled, or destroyed.

NcryptNshare is powered by the SPYRUS Hardware Roots of Trust (aka “Rosetta”). Rosetta is a FIPS 140-2 Level 3 validated security controller chip embedded in all DevicePatrol tokens. In addition to being anti-tamper, Rosetta offers a comprehensive list of cryptographic functions with RSA, elliptic curves, and custom algorithms. By leveraging Rosetta’s key protection, NcryptNshare allows users to dynamically assign access to encrypted objects to enforce multifactor authentication, ensuring that only the right user(s) have access to the information being shared.

In Summary

All enterprises have a myriad of data that must be secured — both on-premise, in the Cloud environment, and at any location its stakeholders find themselves. The financial and reputational impact of not securing data can be severe. Enterprises need to embrace intuitive solutions and business practices that enhance their stakeholders’ ability to protect data in motion, at rest and in use, avoiding mishaps that exacerbate the insider threat. For more than 20 years, SPYRUS has ensured public and private enterprises have security solutions to protect their data at the highest levels of confidence by exceeding CIA requirements. The SPYRUS DevicePatrol Platform and SPYRUS NcryptNshare enable enterprises to extend the office worldwide — and secure the collaboration of its employees and key third parties.

For more information, visit www.spyrus.com.

About the Author

Grant EvansGrant Evans was named Chairman and CEO of SPYRUS in late 2018. He is a seasoned senior executive and serial CEO with nearly 30 years of operating experience. He has served as Chairman and CEO of multiple public and private companies on a global basis, including NetFortris and ActivIdentity.

Evans is a notable industry leader and has received wide acknowledgment of his contribution to the security industry. He serves and has served on multiple company and industry boards that have included NetFortris, 3VR, Bell ID, Congressman Honda’s Blue Ribbon Security Board for Homeland Security, American Electronics Executive Advisory Committee, Comdex Advisory Board on Security, Pearl Street Ventures Advisory Board and TCSV-Trans Global Secure Communications Board.

Disclaimer

All views are personal and attributed to the author. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Ransomware Alert: NCSC Warns of Attacks Against Universities

54% of Universities in the U.K. Suffered a Data Breach Last Year, Herff Jones payments card breach

The U.K.’s National Cyber Security Centre (NCSC) has warned educational institutions to be vigilant of rising cyberattacks and urged them to follow required mitigation measures. The NCSC’s warning comes after the recent surge in the number of ransomware attacks targeting schools, colleges, and other academic institutions in the country. It was also found that threat actors demanded bitcoins as ransom from the victims, and threatened to expose the stolen data of students if not adhered to.

All the educational institutions have been asked to follow the NCSC’s guidelines to develop an incident response plan to defend against malware and ransomware attacks. “Institutions that have been infected with ransomware have seen their ability to operate effectively and deliver services significantly obstructed and, depending on an organization’s level of resilience, it can take weeks – and in some cases months – for services to return to normal,” NCSC said.

Paul Chichester, Director of Operations at the NCSC, said, “This criminal targeting of the education sector, particularly at such a challenging time, is utterly reprehensible. While these have been isolated incidents, I would strongly urge all academic institutions to take heed of our alert and put in place the steps we suggest, to help ensure young people are able to return to education undisrupted. We are absolutely committed to ensuring the U.K. academia is as safe as possible from cyber threats and will not hesitate to act when that threat evolves.”

Endless Phishing Attacks

A survey on the state of cybersecurity in the higher education sector, conducted by managed threat detection provider Redscan, revealed that nearly 54% of universities in the U.K. reported a data breach to the Information Commissioner’s Office (ICO) last year. The survey report titled “The State of Cybersecurity across U.K. Universities”  stated that around 46% of all university staff received no security training and 24% did not commission a penetration test from a third-party. Defending against the constant stream of phishing scams remains a challenge for all universities. Several universities receive millions of spam and phishing emails each year, with one institution reporting a high of 130 million.

91% of SMBs Looking for Right Cybersecurity Solutions

CISOs in remote working

Most small and medium-sized businesses (SMBs) believe they are prepared for a cyberattack, but only a few of them are ready to deal with the outcome of such incidents. However, cybersecurity remains a top priority for most SMBs globally, according to a research from ConnectWise. The research “ConnectWise SMB State of Cybersecurity” revealed that three-quarters of the respondents worried they will be the target of an attack in the next six months. Over 91% of SMBs admitted that they would use or move to a new IT service provider for the right cybersecurity solutions. While 86% of SMBs are positioning cybersecurity within the top five priorities for their organization, six in 10 organizations said they invest more in cybersecurity.

Around 68% of respondents stated that right cybersecurity offerings mean having confidence in a managed service provider’s (MSP) ability to respond to security incidents, while 58% stated it is having confidence in an MSP’s ability to minimize damage. The research also highlighted that 52% of SMBs admitted that they lack in-house security skills, which are required to handle cyber issues, and 49% of SMBs find more cybersecurity expertise as an added benefit of working with an MSP.

Jay Ryerse, CISSP, Vice President of cybersecurity initiatives for ConnectWise said, “Confidence remains a key factor for SMBs in choosing the right MSP offering for their business needs. Currently, only 13% of SMBs are having regular cybersecurity-related conversations with their MSP. Even more worrisome is the fact that 29% of SMBs talk to their MSP about cybersecurity only after they have suffered an incident. It’s clear that MSPs must work to reinforce that confidence and build closer relationships with their clients.”

The findings are based on the responses from 700 IT and security decision makers working across the U.S. (300), the U.K. (150), Canada (100), Australia, and New Zealand (150).

SMBs Rely on Free Cybersecurity Tools

A similar research from BullGuard revealed that one in three small businesses with 50 or fewer employees rely on free or consumer-grade cybersecurity tools. It also pointed out that one in five companies do not use any endpoint security whatsoever. The research, which surveyed small businesses in the U.K. and the U.S., suggested that nearly 43% SMB owners are not prepared for a potential cyberattack or breach leaving their most sensitive financial, customer, and business data at risk.

Is the Co-existence of Security and User Experience in Media Industry Possible?

Media Industry

The COVID-19 pandemic has propelled online media consumption to new heights. With people forced to stay indoors, the online engagement has blown the roof. However, the side shoot of this rise is the growing security concerns. But an added jacket of security hampers users’ experience on an online platform. So, who takes the back seat? Can security and user experience co-exist? Let us have a look at some key aspects from Akamai’s recently concluded Media Summit – APAC 2020.

By Mihir Bagwe, Tech Writer at CISO MAG

The Transformation

The media and entertainment industry has witnessed a dramatic transformation in the past few years, especially with new emerging trends that include the short-form video applications like TikTok, Instagram Reels, and numerous other over–the–top media services (OTT) platforms worldwide. The pandemic has further accelerated the internet penetration rate more than ever – for work, socializing, and most of all, entertainment – with consumers signing up for multiple streaming services and consuming an unprecedented volume of digital content.

However, the two most important pillars in the success of this digital medium is “Quality Content” and “User Experience” (UX). Without quality and value for money, content and user experience on a media and entertainment platform cannot gain popularity or become successful. So why exactly is user experience so critical?

To Prove: Better UX = Higher Digital Success

Remember how spiral buffering or loading icon that keeps going round in circles on your screen to annoy you? Reports from Google confirm that 53% of mobile site visits are abandoned if it takes longer than three seconds to load the webpage. It also revealed strong correlations between page speed and other key performance indicators like revenue, bounce rate, session duration, and viewability. The study stated that sites loading in under five seconds generated twice the revenue and recorded 25% higher viewability than those loading in 19 seconds. This difference in numbers can make or break the deal for customer retention. Thus, in the mathematical language of proving LHS = RHS, Better UX = Higher Digital Success.

The Shaky Third Pillar

A flourishing domain often attracts an evil eye, and the evil eye are the threat actors trying to target these video and media platforms for malicious and financial gains. People often tend to reuse login credentials across various mediums, and this increases the risk of compromise. The current supply chain is so stretched and unlimited that a compromise through a third-party can virtually lead to a leak of your customers’ credentials or personally identifiable information (PII). Once leaked, these credentials are sold on the dark web ranging from a few dollars (for simple site login) to thousands of dollars per user (in case of medical data). Due to the vulnerability of users reusing credentials across different channels, threat actors then carry out credential stuffing attacks using these leaked credentials.

According to Akamai’s State of the Internet Security Report, credential stuffing attacks against the media industry has seen a huge spike in the Q1 of 2020, especially in the month of March where more than six billion malicious login attempts were observed. Correspondingly, Akamai’s research also found a 98% YoY increase in credential stuffing attacks between 2018 to 2019.

security and user experience in media industry

Thus, the security of these populous video and media platforms is now an ever-growing concern. However, added security, such as a CAPTCHA or any other MFA process, during the login increases the number of steps and often leads to a degraded UX that eventually leads to a higher bounce rate. So, how do we solve this problem?

What Akamai’s Expert Says

Speaking at the Akamai’s Media Summit APAC 2020, Sid Deshpande, Security Technology & Strategy Director, Akamai Technologies, stressed that a good user experience is necessary for any platform’s digital success, however, better security is utmost critical in generating consumers trust and loyalty.

Consent is the new Currency

According to Sid, media consumers expect three important measures when it comes to the security of their online accounts or presence. They are:

  1. Transparent security controls
  2. Personal / PII data security
  3. Prevention of account/credential abuse

All these expectations collectively point to the fact that users are now demanding more control over their own data. As Sid correctly says, “Consent is the new currency.” A user’s consent in securing, collecting, and storing their data is very important.

Security architects need to design for the least common denominator of security awareness and work with the assumption that the user may not be in a position to make the correct security related decisions related to their accounts.

Best possible security measures for users’ data can only be achieved by collaborating with the users for the common good. Choosing between security and user experience is always a tug of war. Thus, we asked Sid whether media platforms and applications should give users an option to choose between security and UX, like we now choose which cookies can be stored and used under the GDPR compliance to render additional control of user consent. He answered, “I think to a certain degree it is good to give advanced/tech-savvy users some degree of choice in the deployment of advanced or value-added security features. However, security architects need to design for the least common denominator of security awareness and work with the assumption that the user may not be in a position to make the correct security-related decisions related to their accounts.”

Closing Notes

The debate between security and user experience in media industry will always feel like slacklining on a tight rope. Shift of weight on either side will lead to the downfall of the platform. In such a case, Sid Deshpande suggests three key prepositions for media CISOs and/or CIOs:

  1. Manageable security architecture: Design the security architecture as per the needs and usage of the respective media platform. Do not do too little or too much.
  2. Understand the attacker: Think like an attacker and you will get the answers for finding the weak spots in your network/architecture.
  3. Demonstrate the business value of security: Security helps in building loyalty, which in turn increases customer retention and eventually affects the growth of your media platform.
About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 


Other Posts from the Author: