Home Blog Page 170

Five Practical Steps to Implement a Zero-Trust Network

4 in 10 Companies Expose Unsafe Network Services Online, network and security

While the concept of Zero Trust was created 10 years ago, the events of 2020 have thrust it to the top of enterprise security agendas. The COVID-19 pandemic has driven mass remote working, which means that organizations’ traditional perimeter-based security models have been broken up, in many cases literally overnight.  In this new normal of remote working, an organization’s network is no longer a single thing in one location: it is everywhere, all of the time. Even if we look at organizations that use a single data center located in one place, this data center is accessed by multiple users on multiple devices.

By Professor Avishai Wool, Co-founder and CTO at AlgoSec

With the sprawling, dynamic nature of today’s networks, if you don’t adopt a Zero-Trust approach, then a breach in one part of the network could quickly cripple your organization as malware, and especially ransomware, makes it way unhindered throughout the network. We have seen multiple examples of ransomware attacks in recent years: organizations spanning all sectors, from hospitals to local government and major corporations, have all suffered large-scale outages. Put simply, few could argue that a purely perimeter-based security model makes sense anymore.

So how should organizations go about applying the Zero Trust blueprint to address their new and complex network reality? These five steps represent the most logical way to achieve Zero-Trust networking, by finding out what data is of value, where that data is going, and how it’s being used. The only way to do this successfully is with automation and orchestration.

1. Identifying and segmenting data

This is one of the most complicated areas of implementing Zero-Trust since it requires organizations to figure out what data is sensitive.

Businesses that operate in highly regulated environments probably already know what that data is since the regulators have been requiring oversight of such data. Another approach is to separate systems that humans have access to from other parts of the environment, for example, parts of the network that can be connected to by smartphones, laptops, or desktops. Unfortunately, humans are often the weakest link and the first source of a breach, so it makes sense to separate these types of network segments from servers in the data center. Naturally, all home-user connections into the organization need to be terminated in a segregated network segment.

2. Mapping the traffic flows of your sensitive data and associate them to your business applications

Once you’ve identified your sensitive data, the next step is knowing where the data is going, what it is being used for, and what it is doing. Data flows across your networks. Systems and users access it all the time, via many business applications. If you don’t know this information about your data, you can’t effectively defend it.

Automated discovery tools can help you to understand the intent of your data – why is that flow there? What is the purpose? What data is it transferring? What application is a particular flow serving? With the right tooling, you can start to grow your understanding of which flows need to be allowed. Once you have that, you can then get to the Zero-Trust part of saying “and everything else will not be allowed.”

3. Architecting the network

Once you know what flows should be allowed (and then everything else deserves to be blocked), you can move onto designing network architecture, and a filtering policy that enforces your network’s micro-perimeters. In other words, architecting the controls to make sure that only legitimate flows are allowed.

Current virtualization technologies allow you to architect such networks much more easily than in the past. Software-defined networking (SDN) platforms within data centers and public cloud providers all allow you to deploy filters within the network fabric – so placing the filtering policies anywhere in your networks is technically possible. However, actually defining the content of these filtering policies: the rules governing the allowed flows – is where the automatic discovery really pays off.

After going through the discovery process, you are able to understand the intent of the flows and can place boundaries between the different zones and segments. This is a balancing act between how much control you want to achieve and how secure you want to be. With many tiny islands of connectivity or micro-segments, you have to think about how much time you want to invest in setting that up and managing it over time. Discovering intent is a way to make this simple because it helps you decide where to logically put these segments.

4. Monitoring

Once the microsegments and policies are deployed, it’s essential to monitor everything. This is where visibility comes into its own. The only way to know if there is a problem is by monitoring traffic across the entire infrastructure, all the time.

There are two important facets of monitoring. Firstly, you need continuous compliance. You don’t want to be in a situation where you only check you are compliant when the auditors drop in. This means that you need to be monitoring configurations and traffic all the time, and when the auditor does come, you can just show them the latest report.

Secondly, organizations have to make the distinction between the learning phase of monitoring, and the enforcement stage. In the discovery’s learning phase, you are monitoring the network to learn all the flows that are there and to annotate these with their intent. This allows you to see what flows are necessary before writing the policy rules. There comes a point, however, where you have to stop learning and decide that any flow that you haven’t seen is an anomaly that you will block by default. This is where you can make the big switch from a default ‘allow’ policy to a default ‘deny,’ or organizational ‘D-Day.’

At this stage, you can switch to monitoring for enforcing purposes. From then on, any developer who wants to allow another flow through the data center will have to file a change request and get permission to have that connectivity allowed.

5. Automate and orchestrate

Finally, the only way you will ever get to D-day is with the help of a policy engine, the central ‘brain’ behind your whole network policy. Without this, you have to do everything manually across the entire infrastructure every time there is a need for a change.

Your policy engine, enabled by automation orchestration, is able to compare any change request against what you have defined as your legitimate business connectivity requirements. If the additional connectivity being requested is in line with what is defined as acceptable use, then it should move ahead with Zero-Touch, in a fully automated manner. This can be achieved with the deployment of necessary updates to the filters in minutes. Only requests that fall outside the guidelines of acceptable use need to be reviewed and approved by human experts.

Once approved (automatically or after review), a change needs to be deployed. If you have to deploy a change to potentially hundreds of different enforcement points, using all kinds of different technologies, each with their own intricacies and configurations, this change request process is almost impossible to do without an intelligent automation system.

Focus on Business Outcomes, Rather than Security Outcomes

Removing the complexity of security enables real business outcomes since processes become faster and more flexible without compromising security or compliance. Right now in many organizations, even with the limited segmentation that they have in place already, pushing through a change post ‘D-Day’ is very slow – sometimes taking weeks to get through the approval stage on the security side because there is a lot of manual work involved. Micro-segmentation can make this even more complex.

However, using the steps I’ve outlined here to automate Zero Trust practices means that the end-to-end time from making a change request to deployment and enforcement goes down to one day, or even a few hours – without introducing risk.  Put simply, automation means organizations spend less time and budget on dealing with managing their security infrastructure, and more on enabling the business.  That’s a true win-win situation.

About the Author

Avishai WoolAvishai Wool is the Co-founder and CTO at AlgoSec. He has served on the program committee of the leading IEEE and ACM conferences on the computer and network security. Wool has published more than 110 research papers and holds 13 U.S. patents with more pending. He is also a professor in the School of Electrical Engineering at Tel Aviv University and deputy director of the Interdisciplinary Cyber Research Center at TAU. He’s is the creator of “Unlocking information Security”, a successful massive open online course (MOOC). When he’s not busy evangelizing AlgoSec’s solutions, Wool enjoys tinkering with all sorts of computer and network security technologies, most recently focusing on in-vehicle communication networks, industrial control systems, side-channel cryptanalysis.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Ransomware Attacks: The Major Cause of Cyber Insurance Claims in H1 2020

Ransomware attacks, ransomware, Sinclair Broadcast group

A report published by Coalition, a provider of cyber insurance services in North America, revealed that ransomware incidents accounted to 41% of cyber insurance claims filed in the first six months of 2020. The report “H1 2020 Cyber Insurance Claims Report” highlighted that the average ransomware demand increased by 100% from 2019 through 2020. Several organizations stated that ransomware attacks are the most prevalent and destructive cyberthreats.

The severity of ransomware attacks increased by 47%, with a 100% spike from 2019 to Q1 2020. New and malicious strains of ransomware variants such as Maze and DoppelPaymer are leveraged to demand heavy ransom and expose organizational data. An average Maze demand is six times larger than the overall average ransom demand, the report stated.

Ransomware: A Lucrative Attack Model

Coalition reported a 35% increase in funds transfer fraud and social engineering claims filed by their policyholders since the beginning of the pandemic. The losses from these types of attacks ranged from thousands of dollars to well above $1 million per incident. In addition, the COVID-19 outbreak resulted in a surge of business email compromise (BEC) attacks, with a 67% increase in the number of email attacks during the period.

Image Source: Coalition

According to the report, ransomware (41%), funds transfer loss (27%), and BEC incidents (19%) were the most frequent types of losses, which accounted for 87% of reported incidents and 84% of claims payouts in the first half of 2020.

Joshua Motta, CEO and Co-founder of Coalition, said, “When it comes to cyber loss, the conventional wisdom is that it’s not ‘if’ it will happen, but ‘when’. We are in a heightened state of cyber vulnerability: human errors are more likely to be made remotely, new technology is being deployed on a daily basis to support remote work setups, and cybercriminals are taking advantage. Our report showcases where organizations are most at risk, and the fact that we, at Coalition, are in a unique position to proactively help organizations prevent incidents, provide emergency response when they occur, and, most importantly, help organizations recover operationally and financially in the aftermath.”

Zoom Beefs Up Security with Two-Factor Authentication

Zoom, video conferencing, webinar, zoom two-factor authentication, top data breaches of 2020

The usage of video conferencing and calling applications has skyrocketed since the beginning of the pandemic, which has drawn eyeballs of threat actors towards this new attack surface. This inadvertently means that video calling platforms have been on the radar, and Zoom just happened to walk into their trap as it previously did not support end to end (E2E) encryption for free users. It received a lot of flak, especially from the infosec community. It, however, rectified the mistake and provided E2E encryption to all its users. Yet, it lacked some basic security features like the two-factor authentication (2FA). It seems that it has finally obliged and has now introduced the two-factor authentication for its users, reassuring them of an added jacket of safety over the existing ones.

How Does 2FA Help Zoom

Zoom’s 2FA adoption primarily provides the app an added layer of security and helps prevent potential security breaches. Other benefits include:

  • Improved security: It reduces the risk of identity theft and security breaches by preventing bad actors from accessing accounts by guessing passwords, or credential stuffing or gaining access to employees’ or students’ devices to get into the main network.
  • Reduced costs: SSO or other forms of login and authentication can punch a hole in the pocket for smaller organizations. However, Zoom’s 2FA provides a free and effective way to validate users’ authenticity.
  • Enhanced compliance: 2FA implementation helps organizations fulfill compliance and regulatory needs for sensitive data and customer information.
  • Easier credential management: Password management can be a task especially in this digital normal where you have online accounts for even ordering your daily veggies and groceries. Thus, a 2FA provides an additional level of security without the hassles of constant password management.

Enabling Zoom’s 2FA for Your Organization

As per Zooms blogpost, Zoom not only offers 2FA but a host of other authentication methods such as SAML, OAuth, and/or password-based authentication, which can be enabled or disabled for an account based on user/admin preference. To enable the 2FA at account-level for password-based authentication, the admins need to follow these steps:

  1. Sign into your Zoom Dashboard.
  2. Go to navigation menu, first select Advanced, and then click on Security.
  3. Make sure the Sign in with Two-Factor Authentication option is enabled.
  4. Select one of these options to enable 2FA for:
  • All users in your account:Enable 2FA for all users.
  • Users with specific roles:Enable 2FA for specific user roles. Click Select specified roles, choose the roles, then click OK.
  • Users belonging to specific groups:Enable 2FA for users in a specific group. Click pencil icon, choose the groups, then click OK.

5. Finally, once you are done click ‘Save’ to confirm your changes made to the 2FA settings.

“Psychology of Human Error” Could Help Businesses Prevent Security Breaches

small businesses cyberthreats

Several organizations are concerned about human errors that cause accidental exposure of a company’s critical data. A joint study from Stanford University Professor Jeff Hancock and security firm Tessian revealed that nine in 10 (88%) data breach incidents are caused by employees’ mistakes. The study “Psychology of Human Error” highlighted that employees are unwilling to admit to their mistakes if organizations judge them severely.

Understanding the psychology behind human errors helps organizations to know how to prevent mistakes before they turn into data leaks. According to the study, nearly 50% of the employees stated that they are “very” or “pretty” certain they have made an error at work that could have led to security issues to their company.

Young v/s Old Employees

The study also revealed that younger employees are five times more likely to admit to errors, while 50% of employees aged between 18-30 years stated they have made mistakes compared to 10% of workers aged over 51.

“For older generations, self-presentation and respect in the workplace is hugely important. They may be more reluctant to admit they have made a mistake because they do not want to lose face. Businesses, therefore, need to deshame the reporting of mistakes,” Hancock said.

Young Employees are Easy to Phish

The study highlighted that one in four employees (25%) said they have clicked on a phishing email at work. Men are twice as likely as women to fall for phishing scams, with 34% of male respondents stating that they have clicked on a malicious link in a phishing email compared to 17% of women.

Surprisingly, older employees are less vulnerable to phishing scams. Only 8% of workers aged over 51 said they clicked on a phishing link. Around 32% of 31-40-year-old employees admitted the same. “The older generation have, in many ways, the potential tools and mindsets needed for detecting phishing attacks. They have more life experience, and they tend to have strong, close networks, which means they are good at detecting when something does not ‘feel’ quite right. But if you are less experienced with these kinds of attacks, they are going to be harder for you to spot,” Hancock added.

Other Findings include:
  • Nearly 45% of respondents cited distraction as the top reason for falling for a phishing scam.
  • 57% of remote workers admit they are more distracted when working from home.
  • The top reasons for clicking on phishing emails are the perceived legitimacy of the email (43%) and the fact that it appeared to have come from either a senior executive (41%) or a well-known brand (40%).

“Your employees are focused on the job you hired them to do and when faced with to-do lists, distractions, and pressure to get things done quickly, cognitive loads become overwhelming and mistakes can happen,” the study report concluded.

Eterbase Exchange Hacked, Attackers Stole $5.4 Mn Crypto Funds

Eterbase cryptocurrency Exchange hacked, OpenSea

Cryptocurrencies have always been a primary target of cybercriminals. Recently, Slovakia-based Eterbase Exchange admitted that it became a victim of a security incident in which unknown hackers accessed its network systems and stole $5.4 million worth of crypto funds. In an official notice it stated that hackers compromised Eterbase’s six hot wallets that held multiple cryptocurrencies including Ether, Bitcoin, ALGO, Tezos, Ripple, and TRON riches. However, most of the crypto funds stolen were in the form of Ether.

Following the incident, Eterbase suspended its operations temporarily and reported the attack to law enforcement authorities for further investigation. In a tweet, the company said that it noticed the movement of stolen funds transferring into other exchanges including Binance, HitBTC, and Huobi.

“Law enforcement authorities have been informed and we will assist as much as we can in the ongoing investigations. We want to inform our users that we have enough capital to meet all our obligations. After the security audit of renowned global companies, our operations will continue. We will announce the date of the re-opening of the Eterbase exchange platform as soon as possible,” the company said in the notice.

Cryptocurrency Heists Continue to Rise

In a similar security incident, attackers nabbed $25 million worth of cryptocurrency from Uniswap exchange and the Lendf.me lending platform. The hacker took advantage of a known vulnerability that concerned the ERC777 token standard in the Ethereum blockchain technology. Experts believe that the two attacks could have been carried out by the same hacker as a similar exploit termed as a “reentrancy attack” was used in both the cases. Lendf.Me faced a major blow with 99.95% of funds or 24.5 million dollars being stolen. The attack involved the theft of imBTC, an ERC-20 token that was designed by the dForce Foundation but is now run by a separate company called Tokenlon.

Episode #1: How Digital Risk Management (DRM) is Changing During the Pandemic

Podcast, Sameer Saxena, Business Development Head- Cybersecurity & MSSP, Inspira Enterprise India Pvt Ltd

 Episode #1 

When the pandemic came along earlier this year, more businesses increased their reliance on digital infrastructure. Today, businesses rely heavily on digital processes to run their operations. Clearly, the risk has shifted to digital platforms and DRM is the next evolution in enterprise risk and security for organizations.

The ultimate objective of digital risk management is to build digital resiliency, where an organization’s systems and operations are designed to detect digital threats and respond to events to minimize business disruption and financial losses.

Sameer Saxena, Business Development Head- Cybersecurity & MSSP, Inspira Enterprise India Pvt. Ltd. discusses the evolution and future of Digital Risk Management with Brian Pereira, Principal Editor, CISO MAG.

 

Sameer is a Cyber Security practitioner with over 20 years of industry experience of which 10 years has been in the Cybersecurity Education, Skill Development, Awareness function. He has led organizations to develop and strengthen cross-functional teams and establish relationships with the Industry ecosystem. Sameer is the winner of the Cyber Security Social Media Influencer of the Year 2020 by CISOMAG, an EC-Council Publication.

Being an outlier, he had been instrumental in creating the need for an Indian version of the Information Assurance Workforce Skills Framework, which was the only one approved by the National Skills Development Corporation (NSDC).

EC-Council Teases Its Next BIG Thing!

The world-renowned cybersecurity certification body, EC-Council, has teased what is touted to be the “new methodologies to revolutionize the future of cybersecurity education.” The official announcement will be made on September 16, 2020.

The cybersecurity certification giant detailed on how even failing economies due to COVID-19 did not deter cybersecurity aspirants from learning. In fact, the demand for Certified Ethical Hacker (CEH) skyrocketed during the pandemic. It also shed light on the surge in cyberattacks owing to the new work from the home format.

“Our Certified Ethical Hacker certification continues to be the gold standard, particularly during these changing times,” said Jay Bavisi, President and CEO of the EC-Council Group. “We have learned from its increased demand and are working to up our game even further to create a cyber training platform like no other.”

The cybersecurity market is projected to reach $258.99 billion by 2025, and a lot of it is due to the newer, innovative routes hackers are adopting, making it a bigger concern for the future. Cybersecurity experts also have raised the alarm that dangers like insider threats such as voice and video spoofing, including by those impersonating C-level management, may go undetected. To counter this issue, EC-Council launched its CEH Master Scholarship Program in May 2020 to support national and global security efforts to combat cyber-terrorism. The initial program included total scholarships valued at $550,000 for the ethical hacking community. But as cybersecurity professionals and enthusiasts across the globe began applying for the scholarship in large numbers, the EC-Council Award Committee raised the scholarship cap, awarding over $1 million in scholarships, covering the CEH Practical Exam fee for 1,900 recipients in under 60 days.

With more than 5,500 scholarship applications worldwide, it is clear there is an increased demand for the CEH as cybercrime remains on the rise. Applicants from countries around the world have included the U.S., Singapore, South Africa, India, Philippines, Turkey, and Nigeria, as well as Uruguay, Rwanda, Vietnam, and Slovenia, which are some of lowest ranked countries on the Global Cybersecurity Index.

Register for the event here.

About EC-Council

EC-Council is an ANSI 17024 accredited organization and have earned recognition by the DoD under Directive 8140/8570, in the U.K. by the GCHQ, and a variety of other authoritative bodies that influence the entire profession. Founded in 2001, EC-Council employs over 400 people worldwide with 10 global offices in the USA, Canada, U.K., Malaysia, Singapore, India, and Indonesia. Learn more at http://www.eccouncil.org.

Vulnerabilities in PAN-OS Could Compromise Internal Networks

Vulnerabilties

Security researchers Mikhail Klyuchnikov and Nikita Abramov from Positive Technologies uncovered four severe vulnerabilities in Palo Alto Networks’ PAN-OS, a software that runs on the company’s next-generation firewalls used by over 66,000 companies in 150 countries. Cybercriminals could exploit the vulnerabilities to obtain sensitive corporate data or compromise internal network systems.

“The vulnerabilities could be leveraged by attackers to obtain maximum privileges in the OS, perform any actions on behalf of an administrator within the Palo Alto application, run arbitrary system commands with maximum privileges, or cause a denial of service for the product’s management web interface,” the researchers said.

Out of four security flaws, three vulnerabilities are rated as high severity and one as medium severity. These include:

CVE-2020-2036

This is a Reflected Cross-Site Scripting (XSS) vulnerability that exists in the PAN-OS management web interface. A remote attacker can convince an administrator via social engineering to click on a malicious link to potentially execute arbitrary JavaScript code in the administrator’s browser and perform administrative actions.

CVE-2020-2037

This is a Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. Attackers could exploit this flaw to access a special firewall section, inject malicious code in one of the web forms, and obtain maximum privileges in the OS.

CVE-2020-2038

This is a PAN-OS Command Injection vulnerability in the management web interface. It allows authenticated administrators to execute arbitrary OS commands with root privileges.

CVE-2020-2039

This vulnerability allows an unauthorized user to upload arbitrary files of any size to a certain directory on the server, which might lead to Denial of Service (DoS). Palo Alto Networks remediated all the four vulnerabilities in PAN-OS and urged users to update to the latest version to fix the flaws.

Klyuchnikov said, “We performed black-box testing of the NGFW management web interface to detect this vulnerability, which results from the lack of user input sanitization. During a real attack, hackers can, for example, brute force the password for the administrator panel, perform RCE, and gain access to the Palo Alto product, as well as the company’s internal network. The administrator panel may be located both inside and outside the corporate network, whichever is more convenient for the admins. But, of course, for security reasons, it is better to have it inside. And therefore, such attacks may be conducted both from the internal and external networks.”

OT-ISAC Virtual Summit Brings Together the Best Minds in APAC for OT/ICS Security

OT-ISAC Virtual Summit 2020

It is not every day that you witness a star-studded lineup of CISOs and cybersecurity veterans come together on one platform with a common agenda–collectively shaping the OT/ICS security landscape –but this unbelievable feat was achieved at the inaugural edition of the OT-ISAC Virtual Summit 2020.

By Mihir Bagwe, Tech Writer at CISO MAG

Since the last decade, Cyber-Physical world damages have become more real, relevant, and predominant. In fact, the recent attacks on the administrative network of Kudankulam Nuclear Power Plant (KKNPP) in India and the one at Iran’s Natanz nuclear facility on July 2, 2020, which inflicted physical damage to the facility, are prime examples of how state and threat actors are taking the game a notch higher by attacking OT/ICS for bringing down nations and businesses.

To address these issues and help build a resilient OT/ICS cybersecurity posture, OT-ISAC decided to conduct a virtual meet where experts from the infosec community could come together and share their thoughts, expertise, and analysis for the collective good of the industry.

Keynote at OT-ISAC Virtual Summit 2020

The keynote for the event was jointly given by David Koh, Commissioner of Cybersecurity & Chief Executive of Cyber Security Agency of Singapore (CSA); William Nelson, Chair & CEO of Global Resilience Federation (GRF); and Dale Peterson, CEO, Digital Bond.

David Koh said, “OT cybersecurity is an increasingly pressing issue with the growing convergence of OT and IT. Regardless of the seniority or the domain (engineering or IT) we all need to work together for defending the OT environment from cyberthreats.”


OT-ISAC Virual Summit 2020
David Koh, Commissioner of Cybersecurity & Chief Executive of CSA Singapore
“Cybersecurity is like a seat belt in the car. It has to be there, and it is mandatory for your safety.”

OT systems were traditionally considered as solid entities, which could not be penetrated without a physical access to it. However, this is not the case anymore. Explaining the cause of this scenario, Koh explained, “OT systems in the past were often isolated from business networks and the internet, which allowed the OT systems to remain secure by obscurity as they were typically air-gapped from other systems. Therefore, a possibility of a cyber incident was deemed to be remote. However, then came the digitalization wave and the industrial processes started to shift from the systems based on the proprietary computing to those based on open source IT computing platforms. OT and IT began to converge and there was no longer an air gap between the two. This evolution has dramatically changed the OT cyberthreat landscape. With increased interconnectivity between OT and IT systems comes large attack surfaces for malicious cyberattackers who are always looking out for these gaps.”

He further informed the attendees about three specific security challenges to OT systems:

  1. Poorly authenticated remote access.
  2. Exploitation of known vulnerabilities in OT systems.
  3. Malicious activity that can go undetected as system operator can mistake anomalous behavior for system error as OT systems are not regularly patched and rarely have a centralized dashboard.

Keynote speaker, Bill Nelsen, before joining the GRF, worked as the President and CEO of FS-ISAC for 12 years. He is well-versed with the importance of working together and thus shared his thoughts on the need for collaboration in the ICS Community. If adversaries can share their attack tactics and promote their tools as a service, then why should we not collaborate? Bill stressed, “This is the key to cyber resilience.”

Similarly, Dale Peterson, a veteran with over 20 years of experience in ICS security, gladly shared his thoughts on “The future of ICS security products.”

The key topics related to OT/ICS security covered during the event included evolving industrial cybersecurity, governance, risk and compliance, third-party and supply chain risk, and ICS & CIIs.

OT-ISAC Virtual Summit Key Points
Key Touchpoints of OT/ICS Security in OT-ISAC Virtual Summit 2020

Fireside Discussion

Based on the key touchpoints related to OT/ICS security, panelists in a fireside discussion spoke about the need for cross-pollination of OT and IT realms.


OT-ISAC Virual Summit 2020
Del Rodillas, Director of OT Industry Solutions at Palo Alto Networks
“There is no miracle box to protect your OT. It needs different technologies and collaboration between OT and IT teams.”

Gary Kessler, President of Gary Kessler Associates, suggested how engineers need to adopt a “Security by design” approach at the very beginning, and not as an afterthought post a breach or security lapse. Kessler also stressed on the need to equally focus on inside vulnerabilities rather than only on outside threats. He added, “Threats come from the outside which are uncontrollable in nature. However, vulnerabilities are already present in the systems and processes. Thus, we need to equally see on both sides of the spectrum.”

Moving towards the touchpoints of governance, third-party risks, and its associated compliances, Dr. Ong Chen Hui, CTO in Trustwave, said, “The supply chain in OTs these days are beyond control. Thus, vendors and third parties need to have their vulnerability assessments and monitoring systems. Collaboration and partnership at all levels is the key to securing critical information infrastructure (CII).”

Shawn Thompson, CISO, Dept. of Transport, seconded Chen Hui and highlighted the need for a practical or risk-based approach for strengthening an organization’s cyber defense posture.


OT-ISAC Virtual Summit 2020
Shawn Thompson, CISO, Dept. of Transport
“Organizations and their supply chains should adopt a risk-based approach rather than a compliance-based approach. Risks are different for different industries and there is no ‘one size fits all’ rule.”

 

 

The APT Threat

Due to the lack of hardened security measures and fragmented operations, OT/ICS systems are also predominant targets of APT attacks. Victims of such attacks include power plants, chemical manufacturers, seaports, and military objects. APT groups often have the backing of nation-states and are therefore more interested in analyzing and exfiltrating specific confidential data rather than penetrate networks and systems for monetary gains.


OT-ISAC Virual Summit 2020
Anastasiya Tikhonova, Head of APT Research at Group-IB
“APT attacks on critical infrastructure can start with small things, as small as an employee connecting an MP3 player to a critical system.”

Referring to the origin and duration for which threat actors can stay hidden in the network to only analyze what’s worth, Anastasiya Tikhonova, Head of APT Research at Group-IB said, “APT attacks on critical infrastructure can start with small things, as small as an employee connecting an MP3 player to a critical system. It has happened before and provided threat actors a free entry into the victim’s network. APTs also stay in the system for a longer period, sometimes as long as four years to analyze, penetrate, and exfiltrate targeted data.”

Conclusion

OT-ISAC’s efforts of hosting this event and bringing the top OT security experts together on a virtual platform is noteworthy. The main intent of the event, as its name suggests, was information sharing. Attacks and attack vectors targeted towards OT/ICS industry have spiraled upwards, especially since the onset of the pandemic; however, discussions like these help in shaping the security posture of the OT/ICS infrastructure.

CISO MAG was the official Media Partner of the OT-ISAC Virtual Summit 2020, and had exclusive access to the content. We take this opportunity to thank Image Engine, the event producer and organizer, for providing the required technical assistance for event registration.

About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 


Other Posts from the Author:

Employees’ Social Media Use on Work Devices Lead to Security Risks: SMBs

blockchain-based social media, Parental Consent for Minors, Iranian Facebook accounts

The surge in remote work brought a new wave of security concerns, as many organizations believed that cyber habits of employees could compromise business systems or make corporate data vulnerable to cyberattacks. According to a new survey by the Cyber Readiness Institute, small and medium-sized businesses (SMBs) are concerned that their employees’ social media activities may bring security risks to organizations.

The survey revealed that 56% of SMBs believe that their employees’ social media use poses a cybersecurity threat to their business. Around 64% stated that more than 50% of their employees have social media applications on devices they use for work.  Despite these concerns, 82% of employers allow their employees to use personal devices to access work email or other data.

While 56% of employees admitted that they have social media applications on their work devices, only 30% said their organization has issued regulations on the use of personal social media accounts on office devices. Nearly, 22% of employees ignore their company’s cybersecurity guidelines on a daily or weekly basis.

Most used Social Media Apps

According to the survey, 50% of employees used Facebook on their work devices. It is the most used social media app on organizational devices, followed by Instagram (39%), Twitter (26%), LinkedIn (22%), Spotify (19%), TikTok (13%), and Snapchat (15%).

 Other Findings include:

  • 67% of business owners allow employees to use social media applications on work devices.
  • 42% of business owners say that more than 75% of their employees have social media applications on devices they use for work.
  • 36% of employers are considering adding new policies regarding social media apps or modifying existing policies as employees have had to work from home.
  • 46% of employers say they are not sure or have no clue what social media apps their employees are using on work devices.

Mitigation Measures

The Cyber Readiness Institute recommended certain measures for organizations to protect their employees, customers, and businesses’ critical information. These include:

  • Provide company-owned devices to all employees.
  • Develop comprehensive policies that address the personal use of work devices.
  • Conduct ongoing employee education initiatives focused on the risks of using social media applications on work devices.

The findings are based on the responses from 400 SMB owners and 1,059 employees working across the U.S.

Kiersten Todt, Managing Director of the Cyber Readiness Institute, said, “It is clear that small business owners are fully aware of the cybersecurity risks associated with mixing personal and work activities on the same device. SMBs now need to issue policies that address these risks. More than 4-in-5 owners allow employees to use personal devices for work and only about half have policies regarding the apps that can or cannot be on devices used. It is a recipe for cyber insecurity.”