Home Blog Page 177

NSW Government Announce $60 Mn to Create Cyber Army

New South Wales data breach disclosure bill

In a bid to drive cybersecurity innovation and harness cybersecurity talent in the region, the New South Wales (NSW) government is going to quadruple the size of its central cybersecurity team.

Recently, the Minister for Customer Service Victor Dominello announced an investment of $60 million over three years for creating cybersecurity experts and broadening the scope of Cyber Security NSW to incorporate small agencies and councils.

“The $60 million is not only a four-fold increase in spending on cybersecurity but allows Cyber Security NSW to quadruple the size of its team in the battle against cybercrime. Cyber Security NSW will train the next generation of cybersecurity experts and ensure there is a cross-government coordinated response, including advance threat intelligence sharing, cybersecurity training and capability development. This will further ensure NSW has world-class cybersecurity infrastructure to protect the government services of the future,” said Dominello.

The latest investment is a part of the NSW government’s $240 million Cyber Security NSW commitment announced in June 2020. Cyber Security NSW plays a key role in strengthening the security capabilities in government agencies, collaborating with emergency management, law enforcement, the private sector, and other jurisdictions.

“It is important to increase capability across the whole of the State. Councils provide us all with important online services and we must ensure the capability of councils is increasing at the same time as NSW Government’s capability is increasing,” said, the Acting Chief Cybersecurity Officer Executive Director Charlotte Wood.

Boosting Cybersecurity Investment

With the surge in cybercrime the country, the Prime Minister of Australia, Scott Morrison, recently announced that the country is going to spend A$1.66 billion (US$ 1.19 billion) over the next decade to bolster the cybersecurity defenses for enterprises. Cyberattacks on private businesses and households incurred a cost of A$29 billion (US$ 20.83 billion) or 1.5% of Australia’s gross domestic product (GDP) to the country. The increased security investment is aimed at fortifying critical infrastructure, boost police efforts to disrupt malicious activities on the dark web and to strengthen community awareness on security.

New Zealand Stock Exchange Halted Operations Due to DDoS Attacks

Multiple Banks and Telecoms in Hungary Affected in a DDoS Attack

The New Zealand stock exchange NZX Ltd. went offline for three days in a row due to a blow of successive cyberattacks. In a security alert, the bourse operator said that initially it had been hit by a distributed denial of service (DDoS) attack on August 25, 2020, from offshore, via its network service provider. The attack impacted the exchange’s network connectivity systems, including NZX websites and the markets announcement platform.

The trading halted temporarily for the second time, on August 26, 2020, after the second attack. In DDoS attacks, attackers try to overwhelm the target with useless traffic to obstruct the availability of services provided by the target.

“NZX decided to halt trading in its cash markets at approximately 15.57. A DDoS attack aims to disrupt service by saturating a network with significant volumes of internet traffic. The attack was able to be mitigated and connectivity has now been restored for NZX,” the NZX said in a statement.

Commenting on the incident, Satnam Narang, Staff Research Engineer from Tenable, said, “Stock exchanges are a critical function of national and global economies, making them an attractive target for cybercriminals. It is certainly concerning that a DDoS attack was successful at halting trading on the New Zealand stock exchange for multiple days, whether financial information was accessed. These events should serve as an alarm bell for the exchange to investigate its defenses against cyberattacks as well as launch a broader investigation into the strength of its overall security posture.”

Narang added, “Similar DDoS attacks have been attempted on other stock exchanges in the past. However, that was quite a long time ago and DDoS attacks have gotten more sophisticated. As financial organizations become more reliant on the Internet of Things (IoT), cybercriminals can leverage unpatched devices to launch stronger, more sophisticated DDoS attacks. Until organizations get their hands around the new devices and vulnerabilities in their environments, DDoS attacks will continue to be a threat.”

Weaponizing Documents for DDoS Attacks

Several industry experts stressed that DDoS attacks have evolved into weaponized instruments used to disseminate ransomware, as well as to launch disruptive attacks against their targets. Attack vectors targeted for weaponization include mobile devices, documents, browsers, and the current favorite being IoT devices. Researchers from Sophos discovered a weaponized document serving the dual purpose of delivering ransomware to the system, as well as exploiting it for potential DDoS attacks. The weaponized document was sent as a spear phishing email which upon opening launched Microsoft Word and initiated embedded macros, which enabled elevated privileges for the malicious document to execute an encoded VBscript.

NHA India Opens Doors for Discussion on Securing eHealth Infrastructure

Only 44% of Health Care Providers Meet National Standards on Cybersecurity, OpenEMR vulnerabilities

India celebrated its 74th Independence Day on August 15, 2020. On this occasion, the Hon. Prime Minister of India, Narendra Modi, in his address to the nation said, “Threats from cyberspace can endanger all aspects of Indian life, and the government is alert on this.” Thus, to protect the data sovereignty and privacy of all its citizens, PM Modi announced that India was soon going to introduce a new cybersecurity policy. The “soon” seems to have come “sooner” this time as the National Health Authority (NHA) of India has now released the first draft of the health data management policy for the National Digital Health Mission (NDHM).

What is the National Digital Health Mission (NDHM)

National Health Stack (NHS) was formulated in 2018 by the Government of India (GoI), whose sole motive was to provide foundational components required for the health IT programs in India under the able stewardship of J. Satyanarayana, former Secretary of MeitY and UIDAI. This committee studied the current health infrastructure in India, the need and integration of IT, and the most important part – the laws and governance of the eHealth infrastructure. Post its findings, a report was submitted to the GoI called the National Digital Health Blueprint (NDHB), which is now being placed in the public domain for open discussion. Based on this report, the government has formulated a framework to integrate digital technology in the health care sector under the name National Digital Health Mission (NDHM).

Key Features of National Digital Health Blueprint

The key features of the blueprint provided by the NDHM include:

  • A federated architecture
  • Set of architectural principles
  • 5-layered system of architectural building blocks
  • Unique Health ID (UHID)
  • Privacy and consent management
  • National portability
  • EHR (Electronic Health Records)
  • Applicable standards and regulations
  • Health analytics
  • Multiple access channels like call center, Digital Health India portal and MyHealth App.

NDHBs Building Blocks

The NDHB identified 23 building blocks in total, however, based on the existing health systems and discussions with other stakeholders, the following 5+2 layered architecture building blocks have been identified as the most critical.

National Digital Health Mission
Image Credit: NDHM Draft

As seen in the above image, the National Digital Health Mission has made security and privacy of health data and its associated networks the basis of this framework (refer to Infrastructure Layer/Layer 1 in the image). This pretty much sums up the Government of India’s strict stand on digital security and the fact that it is looking forward to building a strong framework on the sturdy foundation of data security and privacy. According to the draft, any “sensitive personal information” can be collected only in accordance with the policy and consent of all stakeholders.

Talking to the media, Dr. Indu Bhushan, CEO of NHA, said, “The Draft Health Data Management Policy is the maiden step in realizing NDHM’s guiding principle of “Security and Privacy by Design” for the protection of individual’s data privacy. It encompasses various aspects pertaining to health care data such as data privacy, consent management, data sharing, and protection, etc.”

For further discussions on the draft, the government has sought comments from the public latest by September 03, 2020.

High Fidelity Alerts from XDR Tools can Reduce Alert Fatigue: Trend Micro

Armor Piercer

Did you know that the average organization receives 10,000 security alerts every day? A large organization, such as a bank, receives 100,000 – 200,000 alerts. This volume of alerts is causing alert fatigue as it is tedious to look at SIEM logs, co-relate events, and try to identify actual threats. It is also causing stress among personnel at Security Operations Centers (SOCs) who scan these logs for several hours every day. A Gartner report titled “Innovation Insight for Extended Detection and Response,” released earlier this year, says SIEM tools are good at collecting logs, but rarely improve “detection fidelity.”  What is therefore needed is a tool that offers high fidelity in reporting threats for quicker detection and response. It will greatly reduce alert fatigue and improve detection rates and response time.  And Trend Micro’s new XDR (Extended Detection Response) tool comes with this feature.

By Brian Pereira, Principal Editor, CISO MAG

“It has become a huge challenge for organizations to detect the actual alerts and 76% of organizations agree that threat detection is more difficult today than it was two years ago. This is because 80% of those alerts are false positives,” said David Ng, Head of Enterprise Business, Singapore, Trend Micro. He was speaking at the virtual launch of Trend Micro XDR (Extended Detection and Response) on August 24, 2020.

David also quoted a study from the Ponemon Institute that reveled 65% of SOC professionals felt like quitting their jobs due to burnout and lack of visibility. And the security skills gap is compounding the problem.

“EDR technology was supposed to reduce the meantime to detect threats. But we don’t see that happening. In fact, there was a marginal increase over the last three years, and that will lead to a longer mean time to respond,” David added. “Today an incident takes 3.5 days to respond.”

The other problem is uninvestigated alerts and 70% of alerts go uninvestigated.

“There are too many alerts in the SIEM, and security professionals are unable to detect these,” said David. “This will lead to cost fatigue.”

A key finding of the Gartner report shows that “Security and risk management leaders are struggling with too many security tools from different vendors with little integration of data or incident response.”

What is Extended Detection and Response (XDR)?

Gartner defines XDR as a unified security incident detection and response platform that automatically collects and correlates data from multiple proprietary security components.

According to Gartner, XDR products:

  • …are beginning to have real value in improving security operations productivity with alert and incident correlation, as well as built-in automation.
  • …may be able to reduce the complexity of security configuration and incident response to provide a better security outcome than isolated best-of-breed components.
  • …have significant promise, but also carry risks such as vendor lock-in. The XDR market is immature, and capabilities vary widely across products from different vendors.

Gartner also says that while XDR overcomes some of the limitations of SIEM, it is not a replacement for decades-old SIEM technology. XDR is not a replacement for all SIEM use cases, such as generic log storage or compliance.

However, XDRs are differentiated by the level of integration of their products at deployment, and they focus on threat detection and incident response use cases.

Moreover, while the SIEM solution is now delivered as SaaS, most XDR products are developed using new cloud-native architectures and services, making them an emerging alternative or complement to existing SIEM tools. And since businesses are moving more infrastructure to the cloud, XDR is better suited to protect their cloud-native environments.

Infamous Lazarus Group Now Targets Crypto Firms Via LinkedIn

Cryptocurrency Lazarus, North Korean TA406, Lazarus Group , Korea Atomic Energy Research Institute

A research from security firm F-Secure revealed about a new phishing campaign linked to the scandalous North Korean Lazarus hacking group. In its research report “Lazarus Group Campaign Targeting the Cryptocurrency Vertical,” F-Secure stated that the hacking group is targeting the admin staff in cryptocurrency and financial organizations via fake LinkedIn job messages.

It is found that the group specifically focusing on stealing credentials of cryptocurrency wallets and online bank accounts. Here, the attackers send a malicious document disguised as a job advertisement in cryptocurrency and blockchain technology firms. The document claims to be protected by General Data Protection Regulation (GDPR) and stated that the content is needed to be enabled in Word for access. “The enablement of content would then result in the malicious embedded macro code to execute,” the researchers said.

“Lazarus Group’s activities are a continued threat: the phishing campaign associated with this attack has been observed continuing into 2020, raising the need for awareness and ongoing vigilance amongst organizations operating in the targeted verticals. It is F-Secure’s assessment that the group will continue to target organizations within the cryptocurrency vertical while it remains such a profitable pursuit, but may also expand to target supply chain elements of the vertical to increase returns and longevity of the campaign. In addition, some of the newer C2 infrastructure suggests the group may be looking to target organizations in the financial investment vertical,” the researchers added.

History of Lazarus Group Attacks

The Lazarus hacking Group was involved in multiple cyberattacks earlier. In 2018, Kaspersky uncovered AppleJeus, a malicious operation by Lazarus Group to intrude on cryptocurrency exchanges and applications. In December 2019, researchers discovered a malware dubbed as “Fileless” distributed by the Lazarus group.  According to the security researchers, the hacking group has been spreading malware targeting MacOS users, to create fake cryptocurrency trading applications. Also, the malicious activities of the group include the creation of a malware used in the 2017 WannaCry 2.0 global ransomware attack, theft of $81 million from Bangladesh Bank in 2016, attack on Sony Pictures Entertainment in 2014, and numerous other intrusions on the entertainment, financial services, defense, technology, virtual currency industries, academia, and electric utilities.

Misconfigured AWS S3 Bucket Exposes PII of up to 350,000 SSL247 Customers

Misconfigured AWS S3 Bucket Exposes PII of up to 350,000 SSL247 Customers

Security researchers Noam Rotem and Ran Locar from security firm vpnMentor discovered a misconfigured AWS S3 bucket exposing sensitive files related to SSL247, a reseller of internet security products. The leaky database exposed the personal information of up to 350,000 customers (150 GB), who made purchases through SSL247 between 2012-2020. The data breach affected customers in South America, the Middle East, North America, Europe, and Africa.

Information Exposed

According to the research, the S3 bucket contained over 465,000 files, and due to misconfigured permissions and privacy settings, the data was exposed to the public. SSL247 used this database to host various files and documents of its customers including, invoices, purchase orders, account documents, and customer lists in CSV format.

The exposed documents hold various forms of Personally Identifiable Information (PII) of private individuals and companies using SSL247’s services. The exposed PII data included full names, email addresses, contact numbers, personal and business addresses, company details, profile photos, credit filings, financial data, and SSL247 account information like account ID, start dates, and products purchased.

“Many of these files would have been publicly available, and any risk from them being exposed minimal. However, the fact that they were stored on an unsecured S3 bucket alongside significantly more sensitive records may further damage SSL247’s reputation,” vpnMentor stated.

Issues with Exposed Data

Leaked data is prone to various security risks if it is obtained by threat actors. “Using the details of individual customers, hackers could create effective phishing emails impersonating SSL247 to commit corporate mail fraud, e.g., posing as SSL247 and sending their customers an invoice with the hacker’s bank account number. They could also trick victims into providing credit card details and other sensitive, valuable information used to steal from them. The same emails could be used to embed malware, spyware, and other malicious software on an SSL247 customer’s devices,”  vpnMentor added.

Misconfigurations Increase the Risks

A similar survey, “The State of Cloud Security 2020,” revealed that inadvertent database exposure continues to be a major risk for organizations, with misconfigurations exploited in 66% of reported attacks. Besides, 33% of organizations reported that attackers gained access through stolen cloud provider account credentials.  A quarter of organizations stated that managing access to cloud accounts is a primary concern to them. Nearly 96% of respondents admitted that they face issues with their current level of cloud security, while 44% of respondents reported data breaches are the top security concern. Only one in four respondents stated lack of staff expertise as a top concern.

Panaseer – Delivering Enterprise Security Through Continuous Monitoring

The growth in digitization has resulted in a proportionate demand for cybersecurity solutions, as the volume and variety of cyberattacks on businesses and users have increased. Every few weeks we see a new security tool or technology being launched, giving security leaders new ways to identify new threat vectors and test the effectiveness of their cybersecurity measures.

By Mihir Bagwe, Technical Writer, CISO MAG

A recent survey from Forrester revealed that this very abundance of technological investments leaves security teams reeling with how to cobble together data from disparate systems to truly understand their organization’s cybersecurity posture. This is a very reactive, labor-intensive, and not easily scalable approach. Security leaders are understandably looking for new technology and tools to improve their cybersecurity posture, but an evolving threat landscape, compliance, and regulatory hurdles coupled with limited budget and resources make it tedious to effectively implement the best measures.

Before launching Panaseer, CEO Nik Whitfield and his founding team were building advanced threat detection tools at BAE Systems Applied Intelligence, an international business and technology consulting firm. It was here that they observed a majority of the businesses were mature in their cybersecurity methodologies, had cutting-edge technologies, and great talent to handle them. What they tended to lack was visibility into their own IT and security systems. They noticed a need for a platform that could unify IT and security data, establish total visibility, and automate the reporting processes. And thus, was born a new tool for enterprise security, Panaseer’s Continuous Controls Monitoring (CCM) Platform.

What’s the Need for a CCM Platform?

A Continuous Controls Monitoring platform gives CISOs visibility of all their assets and the confidence that security controls are working effectively. It can help businesses make informed risk-based security decisions using technology that cleans, normalizes, aggregates, de-duplicates, and correlates data from any security data source — creating a continuous feed of unified asset and controls insights.

Panaseer’s Continuous Controls Monitoring (CCM) Platform improves enterprise security by offering the following:

  • It provides the ability to automatically validate whether proper controls and safeguards are in place and turned on across all asset types such as devices, databases, applications, people, and accounts.
  • CCM helps uncover gaps in controls coverage, aligns security with framework standards, automates security metrics and stakeholder reporting, substantiates regulatory compliance, prioritizes risk remediation, and tracks improvement – all while reducing headcount requirements and costs.
  • It empowers enterprises to take a proactive approach to security so a control failure does not become a security incident.
  • With the launch of Business Risk Perspectives (BRP) as part of the CCM platform, it enables enterprises to pin-down technology risk of mission-critical business processes and operations.
  • BRP can isolate and group risks to all asset types of the crown jewels of the business. For example, it helps isolate and understand risks to your trading systems, accounts receivable, or systems with sensitive data such as PII.
  • BRP continuously monitors the interrelated risks across asset types aligned to critical parts of the business by conducting a 360-degree, cross-security-domain analysis of everything that needs to be protected across the organization.
  • It allows security and risks teams to effectively prioritize risk remediation and maintain a strong security posture

Editor’s note: The material in this article was curated from the data sources provided by Panaseer. CISO MAG has not verified and does not endorse any claims suggested in the product features.

Can CCM Evolve and Scale with Your Growing Needs?

As businesses grow, new data is added, new endpoint nodes are created, and more importantly, new security data sources are added under the cybersecurity periphery of an enterprise. However, scalability is the biggest hurdle in an organization’s expansion plan. Without a scalable security solution, any business will be unable to keep up with growth.

However, the CCM platform has been architected in a way that it can be scaled depending on the customer’s use case requirements and size. Updates to the product are primarily managed by the Customer Success team as part of customer support and maintenance and are not often affected significantly by the size of the deployment. Each customer influences the product’s roadmap individually.

Panaseer’s product team consists of engineers and data scientists that are continually engaged in R&D initiatives based on the feedback received from customers to drive innovation in data-driven security insights. They have made major advancements in delivering the following:

  • A distributed graph-based entity resolution algorithm to resolve unique devices. By amalgamating dozens of siloed data sources, a “Smart Inventory” is built. This gives a complete and accurate picture of devices on the network.
  • Novel visualizations to intuitively communicate insights represented in complex multi-dimensional data sets.
  • Data science delivering unique risk mitigation insights built on an in-depth understanding of security data semantics and key security drivers.
  • Sophisticated data engineering applied to build the data pipelines required to prepare diverse security data sets for consistent and trusted analysis. The pipelines perform the ETL required to collect, standardize, and enrich data from a range of sources.
  • Campaign tracking capability using data to actively monitor remedial work leading to cyber risk reduction.

Existing products in the marketplace provide partial solutions and many organizations have attempted to build internal solutions, but scaling is always an issue with these approaches. Panaseer claims it has a complete solution that is effective in providing a 360° view of the entire IT infrastructure and can scale with growing business needs.

Nik Whitfield
Nik Whitfield, CEO, Panaseer

“Traditional security tools are insufficient for proactive cybersecurity as they don’t provide a complete, real-time view of cybersecurity risk. Threats are becoming more advanced, attackers savvier, and regulation is tightening. This has created a clear market requirement for automated continuous controls monitoring, a new category of solution that provides real-time visibility of assets.The ability to make informed security decisions based on data and metrics will enable security leaders to have validated confidence that their company and customer data is protected.”

 A Continuous Controls Monitoring Platform enables enterprises to:

  • See every asset, application, user, and data-set in real-time.
  • Uncover gaps in controls coverage.
  • Spend less time on reporting.
  • Priorities risk remediation based on mission-critical parts of their business.
  • Enhance board-level decision-making.
  • Establish regulatory compliance via integration with GRC systems.
  • Achieve cost efficiency and prove ROI.
S N A P S H O T
Company Panaseer
CEO Nik Whitfield
Website https://www.panaseer.com/
Consulting Partner Optiv
Tech Partners CISCO, AWS, RSA
Social Media Handles
Location(s) London and New York
Employees 50
Estimated Annual Revenue 300% year-over-year revenue growth
Funding
  • Nov 2015
    • Total investment: $2.25 million
    • Key investors: Albion Ventures, Notion Capital, Winton Technology Ventures, C5 Holdings, and Elixirr
  • May 2017
    • Total investment: $3.25 million
    • Key investors: Albion Ventures, Notion Capital, Winton Ventures, Paladin Capital Group and Evolution Equity Partners
  • Series A
  • June 2018
    • Total investment: $10 million
    • Lead Investor: Evolution Equity Partners
    • Key investors: Albion Ventures, Winton Ventures and Paladin Capital Group and Cisco Investments
Awards
  • 2019:Cyber Defense Magazine Editor’s Choice for Continuous Controls Monitoring platform’
  • 2019: Europe’s Hottest CyberTech Startup at the Europas awards
  • 2018: Best Newcomer Security Company of the Year’ at the SC Awards Europe 2018
  • 2018: Cyber Defense Magazine Editor’s Choice for ‘Cutting Edge Cyber Security Intelligence Platform’
Industry-wise Services
  • Financial
  • Healthcare
  • Retail
  • Technology

 

PRODUCTS OFFERINGS
Offerings
  • Continuous Controls Monitoring (CCM) Platform: CCM automatically and continuously consumes data from sources across your security, IT, and business domains. By unifying all your data, it can identify previously unknown or unmanaged assets and control coverage gaps in real-time. It then substantiates those insights through automated reports. These can be segmented by market, business unit, or service line and mapped to your goals and structure, providing business context for security metrics.
  • Business Risk Perspectives: Panaseer recently launched ‘Business Risk Perspectives’, an element of Panaseer’s CM platform, which provides a continuous view of the risks associated with the most mission-critical processes. It helps security and risk teams by aligning risk management to frameworks, regulations, and internal policies and reduces the time required to produce stakeholder reports and security metrics.

Company Timeline

Panaseer-Timeline

About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 


Other Posts from the Author:

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by Panaseer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article. The material in this article was curated from brochures and other sources as provided by Panaseer.

Palo Alto Networks to Acquire Incident Response Firm Crypsis Group

FireEye Acquires Respond Software

Cybersecurity firm Palo Alto Networks entered into an acquisition agreement  with risk management and digital forensics consulting firm Crypsis Group in a proposed deal of $265 million.

Palo Alto Networks covers several segments like firewalls, cloud-monitoring and compliance, endpoint protection, and threat detection services. The Santa Clara-based company stated that the acquisition deal will expand its security platform in the incident response space. The Crypsis Group, currently operating as part of the ZP Group, is an enterprise with a portfolio of businesses that are specialized in breach response and national security solutions.

The proposed acquisition strengthens Palo Alto’s security platform Cortex XDR by combining with Crypsis Group’s security consulting and forensics capabilities and enables in collecting rich security telemetry, manage breaches, and initiate rapid response actions. Palo Alto is also planning to integrate Crypsis Group’s processes and technology into Cortex XDR to further enhance its ability to safeguard organizations at every stage of the security lifecycle.

“As threat actors continue to professionalize and grow in sophistication, the risk of revenue and reputational impact of a security breach increases dramatically. In order to focus on the health and growth of their business, organizations need trusted partners to not only quickly and efficiently respond to and contain attacks but also leverage their learning and insight to prevent future attacks,” Palo Alto said in a statement.

Commenting on the acquisition proposal, Nikesh Arora, Chairman and CEO of Palo Alto Networks, said, “The proposed acquisition of The Crypsis Group will enhance our position as the cybersecurity partner of choice, while expanding our capabilities and strengthening our Cortex strategy. By joining forces, we will be able to help customers not only predict and prevent cyberattacks but also mitigate the impact of any breach they may face.”

Ransomware Resolve: University of Utah Pays $457K to Restore Data

Ransomware Attacks, Graff ransomware attack

The University of Utah’s College of Social and Behavioral Sciences (CSBS) suffered a ransomware attack in July 2020 which affected .02% of the college’s data, including personal information of students and employees. In a security update, the university stated that unknown threat actors compromised and encrypted the data stored on its CSBS computing servers, which was no longer accessible. According to the university’s Information Security Office (ISO), the attackers stole certain unencrypted data before encrypting the systems.

No central university IT systems were compromised by the ransomware attack, however as a precautionary measure, the CSBS servers were immediately isolated from the rest of the university networks.

“The university notified appropriate law enforcement entities, and the university’s Information Security Office (ISO) investigated and resolved the incident in consultation with an external firm that specializes in responding to ransomware attacks. The ISO assisted the college in restoring locally managed IT services and systems from backup copies. No central university IT systems were compromised by the attack on the college,” the University of Utah said in a statement.

Ransom Demand

The university paid a ransom of $457,059.24 to the attackers in order to retrieve the decryption key to the seized information. The ransom was paid to prevent hackers from leaking the stolen data online.

“The university’s cyber insurance policy paid part of the ransom, and the university covered the remainder. No tuition, grant, donation, state, or taxpayer funds were used to pay the ransom,” the statement added.

The affected database has been shut down temporarily. The university authorities asked the students and staff to change their passwords as a precautionary measure.

Is the University Safe Now?

The authorities noted, “Despite these processes, the university still has vulnerabilities because of its decentralized nature and complex computing needs. This incident helped identify a specific weakness in a college, and that vulnerability has been fixed. The university is working to move all college systems with private and restricted data to central services to provide a more secure and protected environment. The university is also unifying the campus to one central Active Directory and moving college networks into the centrally managed university network. These steps, in addition to individuals using strong passwords and two-factor authentication, are expected to reduce the likelihood of an incident like this occurring again.”