Home Blog Page 186

Fake or Real? How to Spot Malicious or Fake Apps

Mobile Apps Security, mobile apps

Software applications are no more limited to smartphones; the app ecosystem has expanded from mobiles to watches, laptops, and television. Whether it is Google Play Store or Apple’s App Store, there are multiple apps available for  free download. However, most of these free apps come with several security risks.

By Rudra Srinivas, Feature Writer, CISO MAG

Even with multiple security checks and scans in place, several counterfeit and malicious apps remain undetected and make their way to the Play Store. In this article we will show you how to spot these malicious apps.

The Malicious Intent

Threat actors use imposter apps to perform various criminal activities like spreading malware, installing adware, stalking users’ movements, or accessing personal information. Recently, digital security solutions provider Avast reported a 51% increase in the use of spying and stalking apps globally between March and June 2020, compared to the preceding months, January and February 2020.The FBI issued a warning about threat actors targeting users with fake banking apps to compromise bank accounts. In an official statement, the FBI stated that online and mobile banking apps witnessed a 50% surge in usage since the beginning of 2020.

How to Spot Fake Applications

We often find multiple apps on the Play Store with the same name. An alert user can detect these imposter apps with proper security checks before downloading these. Securing your devices is essential when it comes to protecting your data against malicious apps. Here are some ways to detect fake apps:

1. Check for Discrepancies in the App Icon

Threat actors always use the legitimate app icon to trick users into downloading them. Whenever we search for a particular app on the Play Store,  a list of the similar names and app icons appear, which also includes the counterfeit apps. Try to differentiate fake and legitimate apps by observing the app’s icon. You will certainly find some inconsistencies between fake and genuine apps.

Recently, SonicWall researchers discovered several fake apps in India, which are named after the legitimate Aarogya Setu app, India’s official COVID-19 app. It is observed that the malware operators used the same code for fake apps, by re-branding the icon and application name. The researchers stated that the copy is imperfect, the icon appears stretched and can be identified by comparing it with the legitimate app (as shown in the image below).

Image Source: SonicWall

2. Observe App and its Developer’s Name

Though multiple apps have same name and icon, they are unlikely to have the same developer’s name. Fake apps usually have spelling mistakes in the app’s name or in its description.  Double-check the app’s name and its developer’s name, and make sure they are spelled correctly.

3. Watch the Download Count

Popular apps like WhatsApp and Facebook will have a higher download count. Security experts stated that if an app has 5,000 or less downloads, it is perhaps the wrong listing and maybe it is a fake one. Look for the download numbers before downloading a popular app.

4. Screenshots and Reviews

Counterfeit apps have misspelled words and strange photos in screenshots. Reading app reviews will give you a fair idea of what users think about it. Usually, fake apps have fake reviews, but you may find legitimate reviews from users who already downloaded the app and realized it was fake. A quick look at the screenshots and reviews will help you find the legitimacy of the app.

5. App Publish/Update Date and Permissions

A new app from a popular company will have a “recent publish date” and for old apps have “updated on date”. Imposter apps often have recent publish date. Look at the permissions that the app is asking for while installing. For instance, a third-party messaging app will ask for permission to access a user’s phone book and contacts, but if it is asking unwanted permissions like access to the audio, camera, or more, you have reason to be suspicious.

How to Delete Fake Apps

If a user deletes a fake app from the device by simple uninstalling it (i.e. long pressing the icon and selecting ‘Uninstall’), only the genuine app is removed, while the malicious app would still be available in the background of the device. The only way to remove the malicious apps is to remove it from Settings > apps > uninstall. After removing the malicious app, restart your phone, so all traces of it are completely removed from memory.

Don’t Just Remove, Report!

Finding a fake app or deleting it after knowing about it is not enough. You need to report it to Google  so that it is removed permanently from the Play Store. Google delists thousands of malicious/fake apps from its Store every year. If you find a fake app, report it by selecting the “Flag as Inappropriate” option so that Google can review and remove it from the Play Store.

Conclusion

Be responsible and prevent others from suffering the consequences of the malicious app that you just experienced. And do stay alert when installing new apps.

When downloading an app from the Google Play store, look for the Verified by Play Protect or Google Play Protect logo. That’s an assurance that the app has fulfilled Google’s rigorous internal safety standards and protocols.  But it does not necessarily mean that the app is always secure, as there have been past instances of malicious apps having earned this label only to be taken off the store later after their true intentions became known.

About the Author

 

Rudra Srinivas is a Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.

 

Cybersecurity Automation Defining the Future of Information Security Ecosystem

93% of Organizations Believe Human Error Cause Cloud Data Breaches

Cybercrime has gradually evolved into a thriving industry and is expected to inflict over $5 trillion worth of damages annually by 2021, making the prevention and detection of cyber vulnerabilities paramount. Persistent efforts by enterprises to combat and mitigate the risks arising out of cyberattacks have led to the convergence of AI and ML across the cybersecurity landscape, triggering the onset of automation practices. Cybersecurity automation is being hailed as the next big step in information security, attributed especially to the cumbersome endeavors required for manually managing cybersecurity policies. As multi-cloud environments push the boundaries of enterprise networks, cybersecurity automation will have an important role in preventing cybercriminals from gaining unfettered access to private data.

By Sachin Kasnale, Senior Research Analyst – Sustainable & Smart Technologies, Global Market Insights

Reports from cybersecurity experts and industry research have consistently highlighted the shortage of skilled IT security personnel. In 2019, it was estimated that over 40% of organizations lacked the required cybersecurity skills to improve their security posture. Ironically, this is also one of the biggest challenges while implementing cybersecurity automation, with only 30% of organizations featuring an in-house team capable enough to use security automation. One effective strategy for enterprises to overcome these challenges is to forgo universal automation and opt for specific requirements, which are those pain points where automation will benefit them the most. A few of such areas can be:

  • Integrating internal security data analytics with an external threat intelligence
  • Upgrading existing cybersecurity tools with automation functionalities
  • Basic remediation tasks should be automated on priority

One of the biggest potential areas of application for cybersecurity automation is vulnerability assessment. The global vulnerability assessment market is projected to exceed $10 billion by 2025, driven majorly by the need to identify, classify, and remediate vulnerabilities that attackers could exploit to access confidential data. However, as a greater number of devices are getting connected to the existing network, it becomes increasingly difficult for cybersecurity professionals to manage the network traffic while ensuring security. This is where cybersecurity automation can step in. It can effectively scan devices or apps in the existing network, detect vulnerabilities, and provide a detailed report that can be used to correct security threats proactively.

Another major trend making inroads into cybersecurity automation ecosystem is DevOps-based security automation. DevOps, which is a combination of various interrelated practices & tools to increase the speed of application development and delivery, can assist software development teams in testing the security of newly deployed code at a quicker pace compared to traditional software management processes. The newly committed code can be automatically tested for security vulnerabilities and faulty code can be instantaneously stopped from going into production. DevOps-based testing & development applications are witnessing a soaring rate of adoption, with estimates of the DevOps-based software testing industry exceeding $1.5 billion by 2025. DevOps will also provide a cultural shift of organizations with a more flexible, agile approach toward automation practices.

Cybersecurity exerts immense importance on achieving zero-day threat detection and malware protection. However, majority of enterprises are currently involved with issues, such as disparate security tools, manual management of processes, and an overwhelming amount of security data to be analyzed. It is worth noting that in 2019, enterprises in the U.S. took an average of over 200 days to detect a data breach and another 50 days to neutralize it. For every such breach that went undetected for over 100 days, the total damages inflicted were more than $8 million. This may seem as a major precursor to initiate a shift of enterprises toward cybersecurity automation. However, the implementation of AI and ML to achieve automation is still a challenging task. Enterprises must realize that implementation of cybersecurity automation will not yield them perfect results, there may also exist several false positives. Striking a balance between reducing false positives while not ignoring real threats requires large datasets and continuous training of ML models, which enterprises need to consistently upgrade and improve.

A plethora of cybersecurity tools & vendor sprawl is another intimidating issue while implementing cybersecurity automation. The complications in choosing an effective automation solution are further amplified by the prevailing trend of “best-in-breed” security strategy, where enterprises end up choosing the best possible vendor for each security requirement. While this may appear as the best go-to-strategy at the moment, its repercussions are felt later in the form of incompatibility between different solutions, lack of integration, and performance bottlenecks. The evolving cloud landscape also means that an increasing number of vendors & solutions needs to be evaluated. A few enterprises may find themselves lying on the other end of the spectrum marred by vendor lock-in issues. To address both the challenges, organizations need to embrace the open architecture culture and implement open platforms, which will offer them seamless integration with a broad gamut of third-party solutions and services.

The 10 most crucial steps while implementing a cybersecurity automation approach are:

  1. Formulating the exact requirements for automation and selecting the right tool
  2. Consistently monitoring the most vulnerable areas specific to the organization and developing automation policies around these areas
  3. Enterprises must clearly understand their capabilities and opt for automation tools that address their most crucial pain points
  4. Skills need to be upgraded. If the IT teams cannot function in sync with the evolving technology, the true value of automation cannot be realized.
  5. Security experts are a valuable resource and must only be deployed for the most important of tasks
  6. Data ingestion & analytics is a must. This data later serves as a foundation for improving automation ML models.
  7. Once enterprises get a feel of using automation, they can design their own policies & rules to achieve the required actionable intelligence
  8. Integration of ML across all threat prevention solutions
  9. Ensuring that tools and solutions are always updated and deliver high uptime
  10. Automation must not be underused or overused, and it is on the enterprises to achieve a middle ground.

About the Author

Sachin KasnaleSachin Kasnale is a Senior Research Analyst – Sustainable & Smart Technologies, Global Market Insights. He has over three years of experience in tracking emerging technology markets focusing on the evolution of the latest enterprise and telecom networking trends and their revenue impact on global and regional markets. Kasnale has an engineering degree in Computer Science and an MBA in marketing.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

American Consumers Want More Control and Visibility into How Companies Use Their Personal Data: KPMG

personal data collection, Personal data. Data Privacy

A new KPMG survey revealed that U.S. consumers are becoming increasingly concerned with, and distrustful of, how companies use, manage and protect their personal data. According to the survey, 56% of Americans reported wanting more control over their personal data and insisted that both corporations and government must play an active role in protecting personal data.

The findings in the “New Imperative for Corporate Data Responsibility” report are based on the results from a survey of 1,000 respondents in the U.S. The sample was balanced to reflect the national representation of age, race, gender, and region. The online survey was fielded between May 19, 2020, and May 21, 2020.



As per the report, 97% of American consumers indicated that data privacy is important to them, with 87% characterizing it as a human right. However, consumers are deeply suspicious of what companies are doing with their data: 68% don’t trust companies to ethically sell personal data and 54% don’t trust companies to use personal data in an ethical way.

With consumers indicating that they see data privacy as a human right, and new legislation expected in the years ahead, it is critical that companies begin to mature privacy programs and policies. Consumer demands for the ethical use of data and increased control over their own data must be a core consideration in developing data privacy policies and practices.

Orson Lucas, Principal, Cyber Security Services, KPMG 

Even though respondents indicated that data privacy is important to them, most Americans still engage in online behaviors they consider risky.

Key Findings

  • About 75% of Americans say they consider it risky to use the same password for multiple accounts, use public Wi-Fi, or save a card to a website or online Yet, more than 40% engage in those behaviors.
  • While 65% of Americans reported avoiding opening email attachments from unknown senders, only 31% install mobile device security software and 20% use their own virtual private network (VPN) when possible.

Part of the challenge for corporations will be getting employees and customers to do their part in protecting their own data. Developing defensible notices with understandable language and data protection controls that guide employees and consumers have to be embedded in the data security agenda.

– Steve Stein, Principal, Cyber Security Services, KPMG, and Co-author of the new report.

While most survey respondents indicated that consumers themselves have a responsibility to protect consumer data, even more, want the government and companies to play a role. KPMG found that:

  • 9 in 10 Americans insist companies (91%) and the government (90%), have a responsibility to protect consumer data.
  • Almost all (91%) agree the following data privacy rights of the California Consumer Privacy Act should be extended to all U.S. Citizens: the right to delete personal data, and the right to know how their data is being used.
  • More than nine in 10 Americans say companies should put data privacy guidelines and policies in place, be held responsible for corporate data breaches, take corporate data responsibility seriously, and take the lead in establishing corporate data responsibility.

Prior to  January 1, 2020, U.S. companies already had some regulation impacting the collection and use of consumer data including Gramm-Leach-Bliley Act, Fair Credit Reporting Act, Health Insurance Portability and Accountability Act, state data breach laws, and others (including General Data Protection Regulation for Europe). With the advent of the California Consumer Privacy Act, the expectations have been raised and consumers (at least in California) have increased the right to reject the sale of their data and additional rights to access and delete.  We would expect other states to follow and may see a Federal statute in the coming years that codifies these rights for all Americans.  Murkier perhaps is whether Americans, when given such rights, will act on these rights.

– Steve Stein

Business Recommendations

To be able to provide consumers with increased control over their data, KPMG recommends businesses to consider leveraging data discovery and protection tools, and explore novel uses of emerging technologies such as blockchain and artificial intelligence (AI). These technologies can help organizations better track the source of their data, assure its accuracy, make it easily discoverable, protect it and build greater external visibility into the data being collected.

In fact, according to a survey of 600 global technology executives conducted in late March/early April, KPMG found that improving cybersecurity and data privacy is one of the top four objectives for which their organizations are investing in emerging technologies such as process automation, smart analytics, cloud computing, artificial intelligence, and blockchain.

Additionally, KPMG also recommends:

  • Mature data privacy programs and policies. It is critical that companies begin to mature privacy programs and policies before new legislation come into effect. Specifically, companies should consider adopting a principles-based approach to retain the flexibility needed to comply with the evolving regulatory environment and technology landscape.
  • Provide customers with greater control over their data. With expanding requirements to give consumers greater control over their personal data — businesses should consider leveraging data discovery and protection tools, and exploring novel uses of blockchain, and artificial intelligence.
  • Conduct privacy assessments to manage data privacy challenges in light of COVID-19. As new return-to-work solutions are introduced amid COVID-19, companies should conduct privacy impact assessments. Specifically, where new technologies and processes are implemented, it is prudent to assess and document the potential implications and decisions around data privacy.
  • Make sure consumers are aware of your data privacy strategy. To build trust and goodwill with consumers, companies that develop strong data privacy controls will want to make sure consumers know about them.


90% Organizations Experienced Spike in Cyberattacks Due to the Pandemic

Australian Securities and Investment Commission Hit by a Cyberattack

A survey from endpoint management services provider Tanium revealed that 90% of security leaders experienced an increase in cyberattacks due to the pandemic and 93% admitted that they were forced to delay key security projects due to sudden remote work conditions. The research report “What Happened When the World Stayed Home?”  focuses on the ongoing effects of COVID-19 on private and government organizations. Nearly all the executives surveyed said they had to delay or cancel planned security projects.

Identity and asset management (39%) and security strategy (39%) were the top areas interrupted due to the pandemic. Patching was one of the major concerns for organizations, with 88% of respondents who have struggled in this area and 43% experienced difficulties in patching remote workers’ personal devices.

COVID-19 Exposed Security Gaps

The research report also discussed  the preparedness of security leaders when it came to remote work culture. Nearly, 85% said that they felt ready to shift to a fully remote workforce and 98% said they experienced security challenges within the first two months. The top three challenges were: identifying new personal computing devices (27%), overwhelmed IT capacity due to VPN requirements (22%), and increased security risk from video conferencing (20%). The most common of these were attacks involving data exposure (38%), business email or transaction fraud (37%) and phishing (35%).

Impact of Pandemic Lasts Long

Around 85% of respondents believe that the negative impact of the global pandemic will last for several months to come. Most security leaders are concerned that home IT would be difficult to implement long-term for multiple reasons, including compliance regulations (26%), managing cybersecurity risks (25%), and balancing cyber risk with employee privacy (19%). The respondents identified cybersecurity as a top priority, with 70% of respondents stating that they will make cybersecurity the  primary priority for remote work going forward. Nearly 48% of respondents plan to invest in endpoint management tools to improve visibility of IT assets, and 47% plan to make improvements to patch management processes.

Chris Hodson, Chief Information Security Officer at Tanium, said, “The almost overnight transition to remote work forced changes for which many organizations were unprepared. It may have started with saturated VPN links and a struggle to remotely patch thousands of endpoints, but the rise in cyberattacks and critical vulnerabilities has made it apparent that we’re still far from an effective strategy for the new IT reality. Whether companies choose to permanently move their operations remote, return employees to the office, or some combination of both, one thing is clear: the edge is now distributed. IT leaders need to incorporate resilience into their distributed workforce infrastructure. A key part of this is making sure organizations have visibility of computing devices in their IT environment.”

 

i3forum Brings Telecom Giants Together in the Fight Against A2P Messaging Fraud

Smishing attacks

i3forum, a non-profit body, has launched a “Messaging Fraud Work Group” that will help fight Application-to-Person (A2P) messaging frauds taking place across the telecom ecosystem. This group’s key roles include providing advanced insights, knowledge, and collaboration among industry leaders.

What is A2P Messaging?

Short message service (SMS) was first used nearly 25 years ago and has ever since been an integral part of private and business communications. This application of SMS has further made it evolve into two different categories – Person-to-Person (P2P) and Application-to-Person messaging.

P2P messaging is described as the exchange of text messages between two or more end users i.e. a medium of two-way peer communication. However, A2P messaging is an SMS message sent from an application, like a web or mobile app to a subscriber. These messages could be in the form of customer alerts, verification codes and/or marketing messages. Mostly, it is observed that A2P messaging provides one-way SMS to recipients and are not expected to reply.

Increase in A2P Messaging Fraud

According to a joint study of Mobilesquared and Tata Telecommunications, the A2P messaging industry was worth $11.86 billion in 2017 and is now on course to deliver $26.61 billion in revenue by 2022. However, the same report also highlighted the growing concern among mobile network operators (MNOs) amidst rise in malpractices associated with A2P. The MNOs regarded SIM farms, grey routes, and spam (smishing) as the top three threats related to A2P monetization. They believed that A2P messaging frauds were stealing nearly 9.4% of the total A2P revenue which accounted for almost $1.5 billion.

Fraudsters have begun abusing A2P text messaging with a combination of social engineering attacks and technical workarounds like, Spam, Smishing, access hacking, grey routes, SIM farms, SIM swaps and many more. Thus, it has now become more necessary to stop these malpractices before they cause more severe monetary and reputational damages.

Formulation of the “Messaging Fraud Work Group”

Considering these concerning numbers and varied observations, i3forum decided to bring together the telecom giants of the world on the same platform – called the Message Fraud Work Group – in the fight against A2P Messaging Fraud. The work group members include AT&T, BICS, Deutsche Telekom ICSS, Lanck Telecom, Orange, OTE Globe, PCCW Global, Sparkle and Tata Communications.

Its initial objectives are to promote information sharing and mutual education about combating messaging fraud amongst carriers, while identifying best practices across different regulatory environments. The work group will collaborate to fight messaging fraud across the industry and solve crucial market challenges with new insights and solutions.

Anurag Aggarwal, Chair of the Messaging Fraud Work Group said, “Messaging fraud impacts the entire telecoms ecosystem and can result in loss of revenue, reputation and trust. i3forum’s new initiative brings the international carrier community together to tackle this challenge and enables us to deliver a consistent and coordinated effort to combat messaging fraud. We are aiming to enhance fraud prevention measures and their adoption to protect all kinds of industry players, from carriers to aggregators, MNOs, enterprises and end users.”

The work group aims to promote a Code of Conduct and a Classification Document to define the various types of fraud schemes, the types of disputes and recommendations on how to address those issues for carriers. It will collaborate its findings and observations to mitigate all kinds of messaging fraud in the industry, including identity theft, data theft, network manipulation and commercial exploitation.

Collaboration with MEF

Additionally, the work group is going beyond the i3forum and collaborating with the Mobile Ecosystem Forum (MEF), a global trade body that acts as an impartial authority addressing issues affecting the worldwide mobile ecosystem. MEF has already been combating messaging fraud and for quite some time and its A2P SMS Code of Conduct has immensely helped in tackling major fraud types that have been identified, defined and mapped in the MEF’s Enterprise Messaging Fraud Framework. Thus, one of the i3forum’s work group’s first deliverables can be defined as its contribution to the MEF’s Code of Conduct.

Cybercriminals are “Jackpotting” ATMs in Europe to Steal Cash

Cybercriminals are “Jackpotting” ATMs in Europe to Steal Cash

ATM manufacturer Diebold Nixdorf warned that unknown threat actors have used its proprietary software in a series of attacks against Diebold’s ProCash 2050xe USB cash terminals to illegally dispense cash across Europe. In a security alert, the company stated that attackers are using an external device known as “black box” and a software stack of the compromised ATM to launch a “Jackpotting Attack”.

How Jackpotting Works

  • Attackers launch a jackpotting attack to withdraw cash from an ATM illegitimately.
  • To jackpot the ATM, hackers connect their personal device (black box) to the ATM’s communication system to obtain physical access to the ATM machine.
  • Then the attacker unplugs the communication cable between the CMD-V4 dispenser and the ATM PC, and connects it to the black box to send illegitimate dispense commands to the ATM.

Countermeasures

Diebold recommendeds certain security measures to defend against ATM threats:

  • Implement hard disk encryption mechanisms to protect the ATM from software modifications and access to secrets (offline attacks)
  • Introduce intrusion prevention mechanisms to identify deviating system behavior and protect the ATM during operation (online attacks)
  • Follow network security best practices including segmented and secured LAN/VLAN with intrusion, detection, and prevention
  • Implement a secure connection with the host via TLS and Message Authentication Code (MAC)
  • Ensure real-time monitoring of security relevant hardware and software events including unexpected opening of the top hat compartment of the ATM
  • Investigate suspicious activities such as deviating or non-consistent transaction or event patterns, which are caused by an interrupted connection to the dispenser
  • Keep your operating system, software stack and configuration up to date. This is of importance for the core security HW components like EPP, card reader and cash devices as well as all banking related software components
  • Implement secure software update processes and follow security best practices on password management of remote access tools

“Diebold Nixdorf is continuing to analyze these new attacks. During this process, the company would like to point to the recommendations for countermeasures against the known logical attack vectors and the importance of their implementation. Diebold Nixdorf also recommends customers verify whether these recommended countermeasures have been put into operation to better protect your ATM fleet. Where applicable, this should also include checking irregular event alerts generated by the monitoring system to interrupt such attacks,” the advisory added.

 

9 in 10 Security Pros Lack Proper Tools to Detect Cyberthreats

Top Cybersecurity Jobs in 2021

A research from cybersecurity services provider LogRhythm revealed that 93% of security professionals lack the necessary tools to detect cyberthreats and 92% stated that they are still looking for suitable preventative solutions to mitigate the security gaps. The research report “The State Of The Security Team Are Executives the Problem?” highlights that 75% of security teams  now experience more work stress compared to two years ago.

Lack of Executive Support

The research also stated that the stress of security teams increases when there is no executive leadership to guide, with 57% of respondents admitting that their security program lacks proper executive support to provide strategic vision, buy-in, and budget. 42% of security pros cited inadequate executive accountability for strategic security decisions as the top reason they want to leave their job.

Redundant Security Tools

According to the research, 68% of respondents admitted their organization has deployed redundant security tools and 56% confessed that this overlap is accidental. Despite duplicative tools, 58% of respondents said they still need increased funding for tools as an additional support for their security programs.

“Security professionals rate the value of solution consolidation highly, citing top benefits as less maintenance (63%), faster issue detection (54%), identification (53%), and resolution (49%), as well as lower costs (46%) and improved security posture (45%). Yet only one in three companies (32%) have a real-time security dashboard which provides a clear, consolidated view of all their security solutions,” the report stated.

How to Reduce Stress

LogRhythm asked respondents about ways that would help reduce their stress, the responses include:

  • Increased security budget (44%)
  • Experienced security team members (42%)
  • Better cooperation from other IT teams (42%)
  • Supportive executive team (41%)
  • Fully staffed security team (39%)

All employees, from the CEO to the frontline IT worker, need to feel that they play a significant role in maintaining the security of the company for which they work. Now, more than ever, security teams are being expected to do more with less leading to increasing stress levels. With more organizations operating under remote work conditions, the attack surface has broadened, making security at scale a critical concern. This is a call to action for executives to prioritize alleviating the stress and better support their teams with proper tools, processes, and strategic guidance.

 

– James Carder, CSO and VP LogRhythm Labs

The findings are based on the responses from 308 security professionals and executives from organizations located in North America, South America, Europe, Africa, Asia, and Australia.

 

How IIFL Finance Ensures Cybersecurity for Remote Workers Servicing 2,377 branches

Cybersecurity for remote workers

IIFL Finance is one of the leading players in the Indian financial services industry. The IIFL Group covers multiple markets, including wealth management, home loans, microfinance, and retail banking, and has 2,377 branches in more than 500 cities across India. The business is digital and dynamic. Rather than through acquisition, IIFL aims to grow by identifying opportunities in the market, customizing solutions, and moving quickly. The IIFL Group grew 37% in 2019 compared to 2018. With the onset of the pandemic, IIFL wanted their teams to be able to work from anywhere, at any time securely. It believes all endpoints on the network need to be secure, including the infrastructure of its employees working from home. The Group has a wealth of sensitive personal and financial data. To protect its corporate reputation in the eyes of regulators and customers, IIFL Finance must effectively manage security threats posed to its remote workforce and secure its financial data.

The Group wanted to strengthen cybersecurity for both, on-premises and cloud-based activity, and establish clear visibility of the threat landscape. IIFL Finance knows that the Cloud can help scale up its business quickly and aims to reach its customers through digital channels. But that presents both opportunities and challenges. And it believes that it can counter the challenges by effectively managing the security threats.

To address this requirement, IIFL Finance deployed security solutions from Palo Alto Networks. These solutions have helped IIFL in:

  • Establishing end-to-end threat visibility, from the cloud to on-premises to devices
  • Providing complete protection of applications and workloads in physical data centers, across LAN perimeters, and in multiple public clouds
  • Increasing cloud-native application visibility and control
  • Ensuring scale to accommodate business growth

According to an IIFL spokesperson who led the project, in 2018, the Group started its “security transformation.” The aim was to establish a coherent, long-term strategy that would support business growth and protect against threats. It would need to reflect the themes of cloud and mobility. IIFL conducted proofs of concept (PoCs) against agreed-upon criteria with several vendors. In addition to a PoC, Palo Alto Networks undertook a Security Lifecycle Review (SLR), a unique assessment offering that highlights vulnerabilities within an organization’s existing setup. The SLR identified high-risk applications, susceptibilities, and how the network might cope if traffic were to increase sharply.

“The PoC showed Palo Alto Networks to be way ahead of the others. Its features and functionality suited our growth strategy,” said the IIFL spokesperson. “It was clear Palo Alto Networks would give us scale and visibility.”

The Solution

Palo Alto Networks’ approach, based on the Strata network security suite, includes Next-Generation Firewalls; Panorama network security management for all firewalls — at the perimeter, in the data center, or in the cloud; and the WildFire malware prevention service.

The implementation across the perimeter, data center, and cloud was completed in February 2020, just weeks before the COVID-19 pandemic locked down the Indian economy.

Around half of IIFL employees were already enabled with remote working at that time, and the lockdown required the remainder to be equipped.

Anil Bhasin, Regional Vice President, India & SAARC at Palo Alto Networks, said, “The cybersecurity challenges – handling multiple clients and managing thousands of employees working remotely – that a large financial services company like IIFL face on a daily basis are immense. This has become even more critical in the wake of the current COVID-19 pandemic. We are confident that the dynamic nature of our platform will provide a secure environment for IIFL to safely access remote work capabilities now and in the future.”

IIFL now has clear visibility into its security posture. It is stronger today and more assured of its future. According to an IIFL spokesperson who led the project, the implementation ran smoothly, and Strata has proven no bottleneck to performance.

“Even as more transactions go digital and volumes increase, we’ve seen no downgrade in the experience for those working from home,” the spokesperson added.

Security Transformation at IIFL is not yet completed. However, the pandemic is likely to accelerate and advance IIFL’s roadmap. The spokesperson said IIFL is exploring the Cortex security operations suite by Palo Alto Networks with a view toward faster investigations, fewer alerts, and greater automation.

Cybersecurity for Rmote Workers

In an article written exclusively for CISO MAG, Diego Souza, Global Deputy CISO, Cummins Inc. said, “COVID-19 has not only created a new way to work but it has brought new challenges to the organizations to provide an adequate level of support to its employees aligned with security concerns in how to protect their data and system in this new extended work environment.”

In this article, Souza offers recommendations to security leaders to cope with the new security challenges posed to remote workers.

“Security leaders had to scratch their heads to provide quick security controls to support the business and enable the work from home opportunity,” writes Souza.

Read the complete article here.

Organizations Suffer $3.86 Mn Cost Per Data Breach on Average: Report

BlackMatter Group, Volvo Cars ransomware attack

A global survey on the financial impact of data breaches on organizations by IBM Security revealed that security incidents cost $3.86 million per breach on average for companies. The survey “Cost of a Data Breach Report 2020” stated that around 80% of security incidents resulted in the exposure of customers’ personally identifiable information (PII), which in turn led to huge losses for businesses. It is found that organizations in the U.S. continue to suffer the highest data breach costs in the world, at $8.64 million on average. This is followed by health care providers with the average breach cost at $7.13 million.

Cost of Data Leaks and Misconfigured Clouds

The survey highlights the financial losses that organizations suffer when employees’ sensitive data is compromised.  The stolen or compromised employees’ credentials and cloud misconfigurations were the most common causes of a malicious breach, with nearly 40% of malicious incidents reported in 2019.  Over 8.5 billion records were exposed in 2019, and threat actors used previously exposed emails and passwords in one out of five data breaches.

Attackers used cloud misconfigurations to breach networks nearly 20% of the time, increasing breach costs by more than half a million dollars to $4.41 million on average – making it the third most expensive initial infection vector.

AI and Automation Reduce Costs

The survey revealed a cost-saving difference of $3.58 million for studied companies with fully deployed security automation versus those that have yet to deploy advanced technology, with a cost gap of $2 million, up from $1.55 million in 2018. It is found that artificial intelligence (AI), machine learning, analytics, and other forms of security automation enabled companies to respond to breaches over 27% faster on average, than companies that have yet to deploy security automation. On average companies with no automation takes 74 additional days to identify and contain a breach.

Other Key Findings include:

  • 70% of companies that adopted telework amid the pandemic expect it will exacerbate data breach costs
  • 46% of respondents said the CISO/CSO is ultimately held responsible for the breach, despite only 27% stating the CISO/CSO is the security policy and technology decision-maker. The report found that appointing a CISO was associated with $145,000 cost savings versus the average cost of a breach
  • Organizations with cyber insurance cost on average nearly $200,000 less than the global average of $3.86 million. In fact, of these organizations that used their cyber insurance, 51% applied it to cover third-party consulting fees and legal services, while 36% of organizations used it for victim restitution costs. Only 10% used claims to cover the cost of ransomware or extortion
  • In incidents where attackers accessed corporate networks using stolen or compromised credentials, studied businesses saw nearly $1 million higher data breach costs compared to the global average – reaching $4.77 million per data breach. Exploiting third-party vulnerabilities was the second costliest root cause of malicious breaches ($4.5 million) for this group

Wendi Whitmore, Vice President, IBM X-Force Threat Intelligence, said,  “When it comes to businesses’ ability to mitigate the impact of a data breach, we are beginning to see a clear advantage held by companies that have invested in automated technologies. At a time when businesses are expanding their digital footprint at an accelerated pace and the security industry’s talent shortage persists, teams can be overwhelmed securing more devices, systems, and data. Security automation can help resolve this burden, not only supporting a faster breach response but a more cost-efficient one as well.”

 

Update Now! Dell EMC Releases Patch for iDRAC Path Traversal Vulnerability

Zyxel Devices Vulnerable to Secret Backdoor

Technology giant Dell EMC issued a security patch for a path traversal vulnerability found in the Integrated Dell Remote Access Controller (iDRAC) that could allow threat actors to get full control of server operations. The company urged users to update their devices with the latest firmware to avoid further risks. The vulnerability “CVE-2020-5366,” with a high CVSS rating of 7.1, was discovered by security researchers Georgy Kiguradze and Mark Ermolov from Positive Technologies.

iDRAC is designed for secure local and remote server management and allows IT administrators to deploy, update and monitor Dell EMC PowerEdge servers remotely. The researchers stated that an attacker can exploit this vulnerability to obtain full control of server operation by turning it on or off, as well as changing settings for cooling and power. The path traversal vulnerability is one of the three most common vulnerabilities that enables attackers to view the content of server folders that should not be accessible even to a logged-in ordinary site user.

A remote authenticated malicious user with low privileges could potentially exploit this vulnerability by manipulating input parameters to gain unauthorized read access to the arbitrary files.

– Dell said in a security advisory.

The vulnerability affects Dell EMC iDRAC9 controllers with firmware versions prior to 4.20.20.20.  To fix the vulnerability, users must install Dell EMC iDRAC9 firmware version 4.20.20.20, close the standard public and private SNMP communities, and use SNMPv3 in accordance with all security guidelines.

Dell EMC also recommended certain security practices for iDRAC use; these include:

  • Place iDRAC on a separate administration network. Do not connect it directly to the internet
  • It is recommended to use a dedicated Gigabit Ethernet port on servers for connecting iDRAC to a separate administration network
  • Along with placing iDRAC on a separate network, companies should isolate the administration network or VLAN (such as with a firewall) and restrict access to the subnet or VLAN to authorized server administrators only
  • Use 256-bit encryption and TLS 1.2 or later
  • It is recommended to use configuration options like IP address range filtering and system lockdown mode
  • Dell EMC recommends additional authentication such as Microsoft Active Directory or LDAP and strongly suggests updating iDRAC firmware

Kiguradze said, “The vulnerability makes it possible to read any file in the controller’s operating system, and in some cases, to interfere with operation of the controller (for instance during reading symbolic Linux devices like /dev/urandom). If attackers obtain the backup of a privileged user, they can block or disrupt the server’s operation. This attack can be performed externally — if an attacker has credentials, perhaps by brute-forcing, although this is unlikely given the product’s anti-brute-forcing protections — or internally, such as with the account of a junior admin with limited access to the server.”