Home Blog Page 181

What are the Security Concerns of Working Remotely

remote working

Remote working has raised many concerns for businesses of all sizes.

 

By Stevie Nicks, Digital Editor at Just Another Magazine

How do you retain a high standard of workflow? How can you keep your team connected and open to collaboration when they’re separated? Is this the right time to upscale the business and pursue new markets or clients?

Perhaps most pertinent to the immediate future of businesses are concerns surrounding security. But what exactly are these concerns and how can you notice them before the crack gets too big to fill (especially if you’re looking at remote working as a long-term option?)

Equipment and Software Faults

Very few companies were fully prepared to transition to remote working.

 Those with limited access to essential digital tools and lacking in sophisticated HR practices have struggled to find a way to replicate the productivity and positive environment of their office from the comfort of their own homes.

Most importantly, however, many companies lacked the basic equipment to make remote working a possibility.

The absence of laptops, webcams and proper desk chairs has brought many companies to a halt and forced them to improvise for the time being. As some businesses rushed around for a solution there are many who likely did not make the most secure choice when it came to both software and hardware investments.

 Businesses transitioning to hardware more suited to remote working (such as trading in cumbersome PCs for lightweight laptops) were faced with a decision of balancing cost against security. If you’re not in the position to buy entire equipment straight from the manufacturer or a licensed retailer, you risk putting your business and private data on the line buying second hand. Whether it’s a window device or a used Macbook Pro, it’s imperative you buy from a respected retailer and online stores with brand cache, comprehensive contact details, and customer support systems.

 This also raises an important question for remote businesses – if your software systems fail are you in safe position to move to a new one, even temporarily? Any new software may not have the security preferences you require and while there is a general industry standard in place today it raises concerns regarding delays in your operation.

While often a great expense, especially during these financially difficult times, it pays to not skimp on security when upgrading your devices for remote working.

Poor Understanding of Online Security

A 2017 study from the Pew Research Centre showed a shocking lack of knowledge surrounding online security in America – a trend it’s not unreasonable to assume is common throughout the internet-using world.

Cybercrime and how to defend yourself from it is not a mainstream topic. It’s something we’re all aware of and do our best with – but these are often half-measures and we rely on the hope that our employers or insurance will protect us from or cover any damages.

Businesses have to be more thorough in their cybersecurity training efforts.

A team member cannot be accused of putting the business and sensitive data in harm’s way if they don’t understand the basics of protecting themselves online and haven’t been provided the tools to do so.

There are a number of low-cost online security training courses employers can ask their teams to complete to get them up to date with the basics of protecting their devices, help them understand the importance of secure connections and establish a company-wide protocol in the event of a security breach.

Employers should also look to provide staff with essential tools such as VPNs they can log into each day to create a firewall and ensure they’re working on a protected connection without requiring in-depth technical knowledge.

It’s also vital to consider the number of coronavirus and remote working-centric security issues that have popped up over the last few months. From scams concerning vital virus information to fake invites to Zoom meetings, these adaptive cybercrimes have been a thorn in the side of many businesses throughout the pandemic. As businesses progress with remote working they need to make sure their staff are acutely educated to this unique, potentially very harmful trend.

Poor Personal Diligence

Of course, there is only so much a business can do to protect both its physical and digital assets.

Companies can educate their staff, but those individuals need to pay due diligence to how safe their personal remote working environment is. This is one of the most immediate threats facing business security in an age of remote working.

Consider how a significant number of younger workforce lives. They’re in shared houses, often with people they’re not familiar with on a personal level. This does raise the possibility, albeit rare, for workers to compromise important security details through carelessness.

Outside of personal issues with people they live with, workers also face the possibility of theft – a growing concern as thieves realize more and more people are keeping important expensive equipment in their homes on a regular basis.

This is for the most part rectifiable through simple education, personal security and establishing a clear distinction between work and home life. Business equipment cannot be used for personal reasons and employees should be discouraged from having it available when not on work time. Having an acceptable use policy is a brilliant way to outline exactly what is expected from employees.

While there are many people out there discovering the joy of remote working and it is keeping us safe in one sense – in another, it is exposing a generation of workers not well-versed in online safety to the harsh reality of internet security issues.

A combination of sophisticated tools, basic training and keeping work and home lives separate should be enough for most businesses. However, all should consider the elements unique to what they do.

About the Author

Stevie Nicks is Digital Editor at Just Another Magazine – a website that covers the topics you care about. You’ll find articles about lifestyle, travel, fashion, trends and relationships on our site – each of which is written in our unique style. 

Disclaimer 

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

Data Concealment: An Innovative Weapon for Every Defender’s Toolkit

data

Despite investments in security modernization and layered security controls, cyberattacks are consistently occurring – particularly during the COVID-19 crisis, as businesses operate with highly distributed workforces and security limitations related to remote working. Attackers continue to successfully infiltrate corporate networks, gaining access to valuable data that they can then steal or subject to ransom demands, which businesses are unfortunately paying more than 50% of the time. One primary reason for the success of these tactics is that there are detection gaps in the security controls ostensibly designed to stop them. Attackers simply know them too well, meaning defenders require new tools and tactics to derail their attacks successfully.

By Carolyn Crandall, Chief Deception Officer, Attivo Networks

Layered Defenses Have Helped, but Not Enough

One of the most encouraging things about today’s cybersecurity landscape is that more businesses and organizations have begun to recognize that it is essential to have layered defenses, rather than relying on a single security solution or strategy to fight attackers. The combination of tools like EPP, EDR, and deception technology, each designed to perform a specific function at a particular level of the network, has dramatically increased the defender’s ability to detect potential threats. One recent study has shown that merely combining deception technology with EDR technology can increase detection rates by an average of 42%.

A standard security setup today might look something like this: EPP effectively functions as an antivirus, weeding out known threats before they can enter the network. The next layer of defense, EDR, is there to catch more unusual threats that might slip past EPP, observing things like suspicious endpoint processes. Finally, there are tools like deception, which provide the in-network detection capabilities necessary to identify lateral movement, privilege escalation, and other signs that an intruder is already within the network. Deception — as its name implies — can also help confuse attackers by concealing valuable data, which has become an increasingly useful tool in the fight against attackers using advanced persistent threat (APT) tactics.

APTs and Ransomware 2.0

One of the reasons this type of layered defense has become more important is that the threat landscape has changed dramatically. In the past, ransomware attacks were often “smash and grab” operations, where attackers would begin encrypting whatever information they could get their hands on as quickly as possible and hope for the best. Today’s ransomware threats are more insidious: attackers will attempt to enter the network undetected and spend time conducting reconnaissance to identify the most valuable data. They will try to acquire credentials, often by targeting Active Directory, which they can then use to move throughout the network and escalate their attack.

The longer these attackers can remain undetected, the better the odds they will be able to identify, encrypt, and steal valuable data — and the more damaging the attack will be. Ransomware enters the network by circumventing perimeter defenses, targeting human beings with spear-phishing emails and other social engineering attacks designed to trick users into giving them a foothold on a network endpoint. For this reason, effective in-network defenses are more critical than ever when it comes to stopping ransomware. Attackers will conduct reconnaissance as part of their discovery tactics, and defenders can fight them by improving their ability to detect lateral movement—and by hiding and denying access to their data.

Concealing Your Data Is Easier Than You Think

There is a wide range of things that attackers may target, such as files, folders, removable storage, cloud or network shares, AD information, and more. Data concealment works by preventing attackers from finding these assets. After all, attackers can’t encrypt or steal what they cannot see. While having useful detection tools in place is a critical component of a layered defense, actively concealing the data from attackers takes the strategy one step further by preventing them from advancing or escalating their attack. InfoSec teams can automatically receive an alert to the presence of an attacker and isolate infected endpoints.

Better still, the ability to actively feed attackers fake data can not only derail their efforts but make them believe that their attacks are succeeding. If they are unaware that they have fallen for a trick, they will still attempt to carry out their attack, allowing defenders to gain additional information on their TTPs and IOCs, and enabling them to better prepare for future attacks. And while this sort of trickery is a great way to keep attackers off balance, it is important to note that it does not disrupt employee operations. Despite the fact that attackers will not be able to identify the data they are seeking, employees will be able to access it without complexity or any disruption to how they operate.

Concealing Your Data Makes the Attacker’s Life Harder

After infecting an endpoint system, ransomware will try to encrypt files and local, network, or cloud folders while attempting to steal credentials to further its attack. By hiding and denying unauthorized access to these assets, defenders can prevent lateral ransomware propagation and data encryption, dramatically decreasing the attack’s effectiveness. By improving detection capabilities to identify recon and lateral movement, defenders significantly reduce the time attackers have to gather intelligence on the network as well. Additionally, by steering the attacker into a deception environment, the defender can turn the attack on its head, stop it, and gather adversary intelligence on the intruder for remediating infected systems and fortifying defenses.

Combining this type of data concealment with effective perimeter defenses can put the finishing touches on a truly comprehensive approach to cybersecurity. Ransomware attacks have proven notoriously difficult to stop over the years, but by concealing the very targets that attackers are after, defenders can gain the power to give themselves a major advantage.

About the Author

Carolyn CrandallCarolyn Crandall holds the roles of Chief Deception Officer and CMO at Attivo Networks. She is a high-impact technology executive with over 30 years of experience in building new markets and successful enterprise infrastructure companies. She has held leadership positions at Cisco, Juniper Networks, Nimble Storage, Riverbed, and Seagate. Crandall has received many industry recognitions including Top 25 Women in Cybersecurity 2019 by Cyber Defense Magazine, Reboot Leadership Honoree (CIO/C-Suite) 2018 by SC Media, Marketing Hall of Femme Honoree 2018 by DMN, Business Woman of the Year 2018 by CEO Today Magazine, Cyber Security Marketer of the Year 2020 by CyberDojo (RSA), and for 9 years a Power Woman by Everything Channel (CRN).

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Threat Alert! Amazon Alexa “One-Click” Attack Could Jeopardize Personal Data

Amazon Sidewalk

The researchers from Check Point discovered critical security flaws in Amazon’s Alexa virtual assistant platform that could allow threat actors to obtain users’ personal information or spy on user activities remotely by tricking them into clicking a malicious link. They found several web application flaws on Amazon Alexa subdomains, including a cross-site scripting (XSS) flaw and cross-origin resource sharing (CORS) misconfiguration.

“These exploits could have allowed an attacker to remove/install skills on the targeted victim’s Alexa account, access their voice history and acquire personal information through skill interaction when the user invokes the installed skill,” researchers said.

The vulnerabilities would allow attackers to perform malicious activities like:

  • Stealthily install skills (apps) on a user’s Alexa account
  • Get a list of all installed skills on the user Alexa account
  • Remove an installed skill without the user’s knowledge
  • Get the victim’s voice history with their Alexa
  • Get the victim’s personal information

One-Click Alexa Attack

  • The user clicks on a malicious link that directs them to amazon.com where the attacker has code-injection capability.
  • The attacker sends a new Ajax request with the user’s cookies to amazon.com/app/secure/your-skills-page and gets a list of all installed skills on the Alexa account and the CSRF token in the response.
  • The attacker uses the CSRF token to remove one common skill form the list we received in the previous step.
  • Then, the attacker installs a skill with the same invocation phrase as the deleted skill.
  • Once the user tries to use the invocation phrase, they will trigger the attacker skill.

Successful exploitation of vulnerabilities would have required the victim to just click on the Amazon link specially crafted by the threat actor. However, Amazon patched all the vulnerabilities after Check Point researchers disclosed their findings to the company.

“Amazon does not record your banking login credentials, but your interactions are recorded, and since we have access to the chat history, we can access the victim’s interaction with the bank skill and get their data history. We can also get usernames and phone numbers, depending on the skills installed on the user’s Alexa account,” researchers added.

Virtual assistants are used to control IoT devices like lights, A/C, entertainment, and other connected devices in a smart home. The proliferation of connected devices in consumer, enterprise, and healthcare organizations, and their internal vulnerabilities, have created a security blind spot for cybercriminals. With basic security measures and regular updates, connected devices can be secured against any intrusions.

 

Researchers Issue a Red Flag for RedCurl APT Group

red flag

The researchers at Group-IB, a Singapore-based cybersecurity company, have found that a Russian-speaking APT group, RedCurl, has been sniffing through the corporate networks since May 2018 and stealing insider information like employee data and company trade and financial secrets. The RedCurl operators have precisely targeted 26 organizations worldwide and are likely to spread its outreach in the near future.

 Key Highlights 

  • RedCurl is a Russian-speaking APT Group.
  • It has conducted 26 targeted attacks on commercial organizations, out of which 14 were successful.
  • Its targets are spread across multiple fields including construction, finance, consulting, retail, banking, insurance, law, and travel.
  • The targeted companies are located in Russia, Ukraine, the U.K., Germany, Canada, and Norway.
  • It uses phishing and spear-phishing campaigns for the spread.
  • Its operators use PowerShell script to go undetected against legacy security solutions.
  • The attackers used legitimate cloud storage services like Cloudme, koofr.net, pcloud.com, etc. for communicating with the victim’s infrastructure.
redcurl apt group
Image Credit: Group-iB

The Use of Phishing and Spear-Phishing Tact

Initially, the hacker group carried out extensive research about their targets and drafted a well-written phishing email posing as the target company’s HR staff. They sent emails to multiple employees in the same department, which made them less vigilant. For example, the employees would receive the same email of annual bonuses.

The attackers gave special attention while drafting the spear-phishing email content. The emails had legitimate-looking company addresses and logos and featured the sender address in the company’s domain name.

Delivering Through the Cloud

RedCurl operators also strategically placed the malicious links to its payloads in the emails. They used archives, which directed their potential victims to legitimate cloud storage software like Cloudme, koofr.net, pcloud.com, etc., making them believe that they were opening a legitimate file containing information about the annual bonus breakdown. On clicking the link, it would download a Trojan downloader on the victim’s network called RedCurl.Dropper (hence the name). Any person trying to open this file would initiate the malware installation, which in turn would drop other payloads to search the network and exfiltrate data from all types of files and folders back to the cloud.

What needs to be noticed is how the hackers used cloud technology for infection and exfiltration instead of the traditional CnC/2C (command and control) server. This shows that the threat vectors are evolving and cybercriminals are getting smarter by the day. What will be interesting is to see how the defenders evolve.

Attention Bug Hunters! FireEye’s Private Bug Bounty Program Goes Public

Sardonic, BitMart

Cybersecurity company FireEye, announced that it is making its private bug bounty program public, with a focus on business applications and corporate infrastructure security. The company stated the bug hunting event is open to all security researchers and ethical hackers who are willing to find vulnerabilities in FireEye’s services and domains including fireeye.com, fireeye.market.com, verodin.com, isightpartners.com, cloudvisory.com, fireeyecloud.com, and mandiant.com.

We provide the public research community the opportunity to engage, report, and receive credit for their work. While engaging with us, we ask that reporters honor responsible disclosure principles and processes and give FireEye an opportunity to evaluate, respond, and if necessary, remediate any confirmed security vulnerabilities prior to public disclosure

                          – FireEye  

The bug hunting event, which will run via the Bugcrowd platform, will pay a bounty of $50 to $2,500 depending on the severity of the bugs discovered. In addition, FireEye also asked researchers to submit their vulnerability reports to the FireEye Responsible Disclosure program, if they are not willing to be compensated for their bugs discovery.

Bounty Range

“We understand that — despite our best efforts — we cannot eradicate all security vulnerabilities. The technology landscape is constantly expanding, and as such, there will always be emerging threats. While we have been heavily involved with responsible disclosure, including helping other companies set up and modify their own programs, we are taking the next step in this effort,” FireEye added.

Organizations usually conduct bug bounties to find potential vulnerabilities in their network systems or products, which can be fixed before attackers exploit them. The bug bounties offer fiscal rewards to ethical hackers for finding technical flaws, making it a win-win situation for both. The bug hunting programs also ensure that an organization is continually improving its security posture.

Big Rewards for Bug Hunters

Microsoft recently announced its bug bounty program, The Azure Sphere Research Challenge, which offers security researchers up to $100,000 bounty to break into its Azure Sphere Linux IoT OS platform and discover vulnerabilities. The duration of the Azure Sphere Research Challenge is three months (from June 1 to August 31, 2020), and security researchers are required to execute codes on Azure Pluton and Azure Secure World. Earlier, the tech giant paid around $4.4 million to researchers as bug bounties at the Black Hat USA 2019 security event in Las Vegas.

 

LANDSCAPE: Be a Part of the Change

APAC Sponsor Banners PR

Mumbai, India – Aug 7, 2020: EC-Council’s CISO MAG is proud to announce The APAC CISO Summit, themed Cybersecurity in a Hyperconnected Ecosystem,’ on August 27, 2020, from 10:25 am to 14:30 pm SGT.

This year, CISO MAG has brought the essence of their physical events to a virtual domain, keeping up with the changing times.

Data breaches and cyberattacks are anticipated to increase in the due course of time as computer networks expand and organizations resort to long term work from home practices. With the Asian Professional Security Association as a Community Partner, the Summit has been planned to raise awareness on investing in innovations, to survive and sustain continuity across the region’s business intensive digital ecosystems.

With remote working, video chats and collaboration channels becoming the new normal, we are truly heading towards a world without borders.

The Summit will highlight strategies for futureproofing the digital business community in the times of a pandemic.

The deliberation aims to explore ways to mitigate the potential damages by throwing light on fraud detection and why it is imperative to Asia’s digital banking revolution. Proficient experts will offer exceptional insights to improve security posture and mitigate financial and brand damages.

The high-profile cyber breaches in the recent past have been proof that organizations not only incur significant financial losses but also face damaged market repute and customer loyalty. Security leaders will deliver practical security insights to enhance supplier and third-party risk management.

The Summit will also feature discussions on dynamic cybersecurity integration and zero trust architecture.

Eminent security maestros like Vinit Goenka, Ministry of Railways, Government of India, Author, Member-Governing Council – Centre for Railway Information Systems; Chia Hock Lai, Founding President, Singapore FinTech Association; Ts. Saiful Bakhtiar Osman, Head of Information Communication and Technology, Malaysian Aviation Commission; Namrata Jolly, Senior Advisor, pinBox Solutions, Singapore; Aman Dhingra, Associate Partner, McKinsey & Company Singapore and many more are scheduled to present their ideas to tackle the changing APAC security terrain.

Top infosec professionals and decision-makers from Singapore, Malaysia, Indonesia, Philippines, Thailand, Vietnam are expected to gather at the Summit.

With 2,00,000+ combined readership reach of EC- Council and CISO MAG, the Summit presents an excellent opportunity for brands to market their products, increase visibility and create new business opportunities by connecting with a highly motivated target audience.

Sponsors and partners will get a dedicated platform to reach out to the cyber-community through live interactive activities during the event, website and social media promotions, various event listings, press releases and other marketing collaterals.

Sponsorship opportunities can be explored by writing to [email protected]

You can interact and engage with APAC security pioneers during the Summit by registering here.

Additional details on the APAC CISO Summit are available at https://events.cisomag.com/APAC-CISO-Forum.html

About CISO MAG:  

CISO MAG, an EC-Council initiative, is a publication delivering cutting-edge updates about the latest happenings in the cybersecurity world. It is a handbook for CISOs, CXOs, and every responsible stakeholder of a secure Internet space. CISO MAG also presents a platform to reach out to the cybersecurity professionals across the globe through its Summits and Awards and Power List surveys. Learn more at https://cisomag.com/

About EC-Council:

International Council of E-Commerce Consultants, also known as EC-Council, is the world’s largest cybersecurity technical certification body. We operate in 145 countries globally and are the owner as well as developer of the world-renowned Certified Ethical Hacker (C|EH), Computer Hacking Forensics Investigator (C|HFI), Certified Security Analyst (ECSA), License Penetration Testing (Practical) programs, among others. Our certification programs are recognized globally and have received endorsements from various government agencies including the US Federal Government via the Montgomery GI Bill, the US Government National Security Agency (NSA), the Committee on National Security Systems (CNSS) and most recently EC-Council has received accreditation from the American National Standards Institute (ANSI). Learn more at https://www.eccouncil.org.

How to Leverage a Contact-free Authentication Solution for the Workforce

hybrid workforce

Employees face a challenge daily, actually multiple times per day, having to access multiple systems and applications throughout the day to do their job. They have to unlock their Windows desktop, log into internal and external web resources and apps, access a Unix server, the employer’s VPN technology, or even a facility. And, often, they are not using single sign-on, so each system and application requires different credentials for authentication.

By Michael Engle, Chief Strategy Officer, 1Kosmos, and Nick Roquefort-Villeneuve, Director of Marketing, 1Kosmos

Three Workforce Authentication Challenges

1. Leveraging Passwords

Some employees have no problem remembering different usernames and passwords.  And then some specify it incorrectly three tries, before they’re locked out,  and then they start speed dialing the Helpdesk. And a few choose to rely on the good old post-it note they stick on their monitor, openly and publicly.

To make matters worse, IT departments insist on complex formats for passwords: between eight and sixteen characters long with at least one uppercase letter, one number, and one special character. How is anyone going to memorize that type of password? Moreover, IT also enforces a password change every 30 or 60 days. For many folks, those requirements compounded by multiple systems can be overwhelming, resulting in a proliferation of the infamous post-it notes and Help Desk calls. To get round this challenge, some use the same password for multiple logins or services.

This ecosystem creates inefficiencies, such as loss of productivity and increased costs. Did you know, for example, that replacing one password can cost up to $70? Yes, that’s what it can cost in human capital and machine resources to handle one password reset request!

2. Leveraging 2FA and MFA Solutions

To avoid accounts from being compromised because a password was accidentally “stolen” and to strengthen the level of user authentication, many organizations have implemented two-factor authentication (2FA) or even multi-factor authentication solutions. That’s when you submit your username and password, and then you receive, for example, a text message prompting you to enter a code online.

Those solutions certainly make it slightly harder to compromise an account, however, they’re not foolproof. Ultimately, any hacker can steal a username, a password, and a mobile number stored inside a company’s centralized system. There are also MFA solutions that necessitate a piece of hardware like a security key (a hardware token like Google Titan), but that comes at a cost:  Pay for each physical token and allocate resources for the hardware’s maintenance. The security key can also be lost or stolen.

3. Leveraging Some Passwordless Solutions

To mitigate the risks MFA solutions incur, biometrics have been added into the mix. This is what passwordless applications offer with the following biometric features:  Touch ID, Face ID, or the more advanced iris recognition. A login page, a QR code to scan from a mobile application, a biometric-based authentication, and the employee is in. No more username and password needed! The mobile phone is something the employee has, and the biometric data is something the employee is. The problems with those solutions are high implementation costs and heavy data storage. For example, facial recognition requires top-quality cameras and advanced software to ensure accuracy and speed. Moreover, the high-quality images required for facial recognition take up a significant amount of storage.

So, is there an alternative?

Workforce Authentication Best Practices

A robust contact-free authentication solution for the workforce should focus on identity proofing and therefore be built on three identity pillars: Enrolling, authenticating and verifiable credentials. Each pillar needs to interact with one another to ensure that identity remains the number one priority. This is the core architecture of the BlockID platform.

1. Enrolling with Claim Triangulation

An employee’s enrollment should consist of triangulating a given claim with a multitude of company or government-issued documents and sources of truth, including advanced biometrics.

For example, by enrolling an employee’s driver’s license and passport (government-issued documents), we are able to verify, in real-time, the validity of each document by querying the proper databases (sources of truth) and triangulate several claims (first and last name, address, date of birth, photos) simultaneously, prior to adding an extra source of truth to our ID proofing process: a liveness test. The liveness test is performed to verify if the biometric traits of the employee are from a living person rather than an artificial or lifeless person.

We leverage more sources of validation, such as passport chips to validate the fact that the passport scanned during the enrollment process matches digitally signed data. We can also introduce credit cards, bank accounts or loyalty programs, among others, to reach the highest level of identity assurance per the NIST 800-63-3 guidelines, or IAL3.

2. Authenticating

BlockID uses advanced biometric authentication as a security process that relies solely on the unique biological characteristics of the employee to verify that he is who he says he is. Our advanced biometric authentication technology, using a liveness test, compares biometric data capture to stored, confirmed factual data in the BlockID Blockchain Ecosystem. A liveness test offers the added benefit of requiring users to capture a live video of themselves, which has a frightening effect on criminals who’d rather not share their face with the company they are targeting.

The BlockID authentication process reaches the highest level of authentication assurance per the NIST 800-63-3 guidelines, or AAL3.

3. Verifiable Credentials

The verification process leverages the attributes BlockID triangulates during the enrollment phase as well as verifiable credentials (in their digital form) that users can share with third parties and with explicit consent.

A verifiable credential is a credential that was issued by a trusted authority for, and only for, the user. It is a tamper-evident credential based on W3C standards and has authorship that can be cryptographically verified. Schematically, issuers create verifiable credentials, users can store some of them, and verifiers ask for proof-based upon them. When identity needs to be confirmed, the user chooses those credentials that must be verified.

The BlockID verification process eliminates all tedious back-and-forth communication between verifiers and issuers, since the verifier no longer has to contact the issuer to confirm the credential, thus reducing data verification costs in the process. This mechanism infers that the user remains in control and keeps ownership over his or her identity, by electing what they want to disclose, and to whom they wish to disclose it.

4. Employee Data Stored Encrypted in a Decentralized Ledger

BlockID leverages the BlockID Private Blockchain Ecosystem to store employees’ encrypted data. The benefits of using a decentralized system are multiple, from being virtually uncompromisable to initiating peer-to-peer transactions while ensuring the immutability of the data stored. Such a system promotes transparency and consequently creates trust between employers and their employees who need to access corporate systems and applications. Employees own their data and choose to share only the information that is required to access a specific solution. And it is W3C compliant.

Conclusion

BlockID is the next generation contact-free authentication solution for the workforce that leverages advanced biometrics and distributed ledger technology. The application unifies physical and logical access, allowing all employees to use a single smartphone app for all kinds of accesses, whether it is to enter a highly secure data center through a mantrap, to log into Unix or Salesforce or to unlock a workstation without connectivity.


ADVERTORIAL

About the Authors

Michael Engle Michael Engle is the Chief Strategy Officer at 1Kosmos. He is a seasoned information technology executive, leader, and entrepreneur. Engle is an expert in information security, business development and product design/development. He has experience running large teams and multi-million-dollar projects for a Fortune-100 bank as well as working with startups that need to set direction and go from “zero to one” as it is now commonly called. As a co-founder of Bastille Networks, he helped raise over $40 million in VC to create a powerhouse in the RF security sector. As a Senior VP at Lehman Brothers, Engle was instrumental in designing and implementing the bank’s security program.

Nicolas Roquefort-VilleneuveNicolas Roquefort-Villeneuve, a French and American bi-national, is the Director of Marketing at 1Kosmos. He is an influential technology and communication marketing executive and an entrepreneur at heart. Roquefort-Villeneuve has 22 years of marketing experience with Fortune 100 companies (Mattel, E*Trade), startups, and as an independent consultant. He is also an award-winning documentary filmmaker. In the last three years, Roquefort-Villeneuve has become an expert in marketing new technologies such as Blockchain. He has earned a MSc in Econometrics from the Université Paris 1 and an MBA from the University of San Francisco.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article. The facts, opinions, and language in the article are entirely those expressed by the authors and do not reflect the views of CISO MAG.  

Only 7 in 10 Organizations are Concerned About Cloud Security: Report

cloud, cloud security

A latest research by cybersecurity solutions provider Check Point highlighted the issues faced by security professionals in maintaining data and workloads in their public cloud deployments. The research “The Global 2020 Cloud Security Report” revealed that public cloud security remains the major concern for organizations, with 75% of respondents stating that they are “very concerned” or “extremely concerned” about it. Nearly 68% said their organizations uses two or more different public cloud providers.

Biggest Cloud Security Concerns

According to the research, the top cloud security challenges are about data loss (69% – up five percentage points since last year) and data privacy/confidentiality (66% – up four percentage points), followed by accidental exposure of credentials and incident response (44%).

Image Source: Check Point

Cloud Provider Preferences

The three biggest cloud service providers, according to the research include are Amazon web services (AWS), Microsoft Azure, and Google Cloud Platform.

Image Source: Check Point

Research Highlights

  • Among the key barriers toward cloud adoption are lack of qualified staff (37%) up from the fifth spot on last year’s survey.
  • When selecting a cloud security provider, most organizations look at cost-effectiveness (63%), ease of deployment (53%), and that the security tools are cloud-native (52%).
  • When asked what criteria organizations consider most important when evaluating a cloud security solution, they prioritize product features (66%), cost (65%), and vendor experience (55%) as the most important considerations.
  • Organizations rely on multi-cloud solutions with most organizations deploying more than three cloud solutions in their environment.
  • 82% said their traditional security solutions either don’t work at all, or only provide limited functions in cloud environments, up from 66% percent in 2019 – highlighting an increase in cloud security issues over the past 12 months.
  • Nearly 60% of organizations expect their cloud security budget to increase over the next twelve months. On average, organizations allocate 27% of their security budget to cloud security.
  • A majority of 59% said it is likely to very likely that they will deploy a new cloud security solution within the next 12 months.

The findings are based on the responses of 653 cybersecurity professionals surveyed in July 2020 to uncover how cloud user organizations are responding to security threats in the cloud environment.

 

89% CIOs Believe Cybersecurity is Top Priority for the Rest of 2020

Global Cybersecurity Outlook 2022,Cybersecurity, CEO, CISO

At the beginning of the year, the majority of businesses decide upon their budgets and spending options based on factors such as the previous year’s profits and trends, future expansion and scalability plans, expert forecasts, and many more. However, these budgets and business forecasts did not anticipate a pandemic this year, which brought things to a grinding halt. A lot has changed over the past six months, thus, Hitachi ID in collaboration with Pulse conducted a survey to find the shift in priorities of CIOs and IT heads from 131 companies worldwide. Out of these, 70% believed that long-term IT priorities have changed since the start of the year and that cybersecurity is now a top priority of their company for the remainder of 2020.

cybersecurity a top priority
Image source: Hitachi ID

 Key Highlights 

  • Hitachi ID and Pulse together conducted a survey called “Top IT Budget Priorities Through 2020.” 
  • 89% and 82% of the respondents believe that cybersecurity remote support are the top two priorities of their companies for the rest of 2020.
  • 86% of CIOs are looking forward to improving security standards across their business environment.
  • 43% of CIOs are investing in identity and access management tools.
  • 67% of the surveyed individuals are now willing to invest in emerging technologies due to the pandemic’s impact.

Why Cybersecurity is Emerging as a Top Priority

With the majority of the workforce still working in a distributed home environment and no signs of an immediate return to the office spaces post-COVID, coupled with the vulnerability that the fragmented workforce poses to business and network security, global CIOs are rooting to beef up their cybersecurity measures at the earliest. This is not just a temporary shift, in fact, 87% of IT leaders are wanting to increase their security by investing in emerging technologies for the long haul.

cybersecurity a top priority
Image source: Hitachi ID

In another interesting revelation, the CIOs prioritized identity and access management over endpoint security and security awareness training to its employees stating that it is a must for a long-term security posture.

cybersecurity a top priority
Image source: Hitachi ID

The survey also highlighted that security technologies based on AI and ML are hot favorites among CIOs with nearly 71% wanting to implement them. Karl Mosgofian, CIO, Gainsight, said, “The trend toward AI/ML in security has been accelerated by the current situation. In addition, some “old school” technologies like VDI and VPN are getting a lot more attention as circumstances have made office network security less relevant. However, the key to effective AI is structured learning. Just turning an algorithm loose against a dataset may not yield much, but with the combination of AI, human intelligence, and understanding, it’s amazing what we can achieve.”