Home Blog Page 189

Lazarus Hacking Group Strikes Again Using New Malware Variant “MATA”

Cryptocurrency Lazarus, North Korean TA406, Lazarus Group , Korea Atomic Energy Research Institute

Threat intelligence team at Kaspersky warned about a new malware campaign linked to the infamous North Korean Lazarus hacking group. Dubbed as “MATA,” the malware targeted e-commerce and IT firms in Poland, Germany, Turkey, Korea, Japan, and India to spread ransomware and steal sensitive information.  The MATA malware possesses several components like loader, orchestrator, and plugins to infect Windows, Linux, and macOS operating systems.

Researchers stated that the MATA malware campaign began as early as April 2018. “The actor behind this advanced malware framework used it aggressively to infiltrate corporate entities around the world. We identified several victims from our telemetry and figured out the purpose of this malware framework,” the researchers said.

Image Source: Kaspersky

How MATA Spreads

According to Kaspersky, MATA malware  is used to load plugins into the operating system’s running commands to infect and manipulate files and processes by injecting DLLs, creating HTTP proxies, and tunnels on targeted Windows devices. Once the malware successfully deployed, the attackers find databases with customers’ sensitive information and run database queries to acquire customer data.

“During our research, we also found a package containing different MATA files together with a set of hacking tools. In this case, the package was found on a legitimate distribution site, which might indicate that this is the way the malware was distributed. It included a Windows MATA orchestrator, a Linux tool for listing folders, scripts for exploiting Atlassian Confluence Server (CVE-2019-3396), a legitimate socat tool and a Linux version of the MATA orchestrator bundled together with a set of plugins,” the researchers added.

The Lazarus Timeline

The Lazarus hacking Group was involved in multiple cyberattacks earlier. In 2018, Kaspersky uncovered AppleJeus, a malicious operation by Lazarus Group to intrude on cryptocurrency exchanges and applications. In December 2019, the researchers discovered a malware dubbed as “Fileless” distributed by the Lazarus group.  According to the  security researchers, the hacking group was spreading malware targeting MacOS users, to create fake cryptocurrency trading applications.

 

“Meow” is on the Prowl; A New Attack Targets Several Unsecured Databases

“Meow” seems to be on the prowl of unsecured Elasticsearch and MongoDB databases on the web. We’re not talking about cute, furry four-legged creatures. Rather, a new form of attack that is “fast and searches and destroys new clusters pretty effectively,” tweeted Bob Diachenko, a cybersecurity specialist, known to find potentially threatened and unsecured databases in the cyberspace.

The speed and agility of the attack indicates that it is a bot attack, which detects and destroys its target almost immediately. He further notes that attackers do not have any monetary intention behind the “Meow” attack. It does not leave any ransom note or explanation behind the attack and simply deletes the data without intimation to its owner.

Meow’s Discovery

The attack is called “Meow,” due to the fact that the attacker renames databases, its tables, and indices by appending “-meow” to the end of the original or randomly generated alphanumeric names.

Meow Attack
Courtesy: Shodan Search Engine

Diachenko, who leads the cybersecurity research team at Comparitech, first discovered this type of attack on a Hong Kong-based VPN provider company, UFO VPN. It failed to secure a database consisting of user logs and API access records including plain text passwords and other information of their users. This discovery was made on July 1, 2020 and was spontaneously reported to the parent company. UFO secured the exposed database on July 15 only to be “Meowed” by the attackers within next four days.

On July 19, 2020, another dataset of UFO appeared on a different IP address, which seemed to have an even greater number of records exposed. This time though it was not noticed by anyone but by “Meow” bots. The user logs and API access records potentially included the following info:

  • Unencrypted user account passwords
  • VPN session and tokens details
  • User devices and connected VPN server IP addresses
  • Timestamps
  • Geo-tags
  • Device and OS information, etc.

Looking at the pattern and nature of the attacks, it is being said that the attacker can be a vigilante trying to teach a lesson on securing databases the hard way by destroying the unsecured ones.

Are We Cyber Confident? 64% Majority of Organizations Lack Confidence in Security Posture

Penetration Testing, continuous testing, security testing

A joint research report from cybersecurity firms Balbix and Cybersecurity Insiders revealed that security professionals globally are struggling with a lack of visibility into cyberthreats related to endpoint devices, access privileges, and other key security controls.  According to the “2020 State of Enterprise Security Posture Report,”   64% majority of organizations said they lack confidence in their security posture.  Around 68% of organizations have unpatched systems, followed by risk areas such as identity and access management (59%); phishing, web, and ransomware (48%).

Lack of Risk Visibility

Limited visibility and inability to prioritize are hindering the effectiveness of the organization’s vulnerability management programs. According to the research, 90% of organizations believe that phishing and ransomware are their top security concerns, but only 50% of them have sufficient visibility into these threats. 46% of respondents admitted that it is hard to tell which vulnerabilities are real threats. 37% said their visibility only extends to a small subset of the overall attack surface, while 25% feel they are flooded with too many alerts to act.

Phishing – An Evergreen Risk Factor

Employees being phished is a major risk factor for organizations, as threat actors target employees with malicious emails/links to take over systems or steal data. Around 89% of organizations said phishing is their greatest area of risk, with 48% having sufficient visibility into it. 53% of organizations stated that the exploitation of vulnerabilities in unpatched systems are their primary area of risks, followed by misconfigurations (47%).

Threat Response Time

Around 58% stated they can determine every vulnerable asset or exploit in their organization within 24 hours. Yet, 40% said they take 24 hours or longer to identify vulnerable systems, making it nearly impossible to stop fast-moving ransomware or malware attacks.

Other findings include:

  • 60% of organizations are aware of fewer than 75% of the devices on their network. This lack of asset awareness makes it difficult to improve security posture.
  • Nearly 1 in 5 organizations report that most or all users have more access privileges than required for their job.
  • 81% of organizations provide more access privileges than are necessary for users to do their jobs; 17% even say most or all users have too many privileges.
  • Cybersecurity leaders struggle to communicate their security posture to the board and senior management. Only 13% of cybersecurity leaders feel presentations to the board go very well and that the board understands the cyber risk posture of the enterprise.

The stronger the organization’s security posture, the lower the cyber risks. Understanding the organization’s security requirements and prioritizing areas of relevant risk is essential in building a robust security posture against cyberattacks.

 

Incorporating Cybersecurity in the Work from Home Business Model

work from home

The world is rapidly changing, and the evolution of technologies opens new ways to do business, where physical presence may not be a mandatory requirement for many jobs.

COVID-19 has expedited the process, where 88% of the organizations have requested or supported its employees to work from home during the pandemic.

By Diego Souza, Global Deputy CISO, Cummins Inc.

However, this not so newly created way to work has brought new challenges to the organizations to provide an adequate level of support to its employees aligned with security concerns in how to protect their data and system in this new extended work environment.

Security leaders had to scratch their heads to provide quick security controls to support the business and enable the work from home opportunity. Focusing on the security aspect of this challenge, security leaders should consider the following:

1. It is a non-trusted environment, and a zero-trust approach is mandatory. Most, if not all, the organizations do not have the luxury to provide security support to their home users’ network, making it unpredictable to validate the security configurations and controls in place. Security leaders need to have that in mind when planning to provide controls for network extension, especially if they do not trust that the environment has the minimum security requirement to establish a connection.

2. Reliable identity and access management controls became non-negotiable requests to enable the work from home business capability. Since the user is still the weak link in the process, leveraging multifactor certification-based authentication is imperative for controls to be in place. Enforcing system strength password configuration helps the organization to avoid having to deal with a weak user’s authentication keys, as a recent report from a security organization states that employees are reusing one password an average of 13 times, and 80% of the breaches are related to password issues.

Security Leaders must also pay close attention to least privilege access, ensuring users will only have access to what is required for their job, reducing the risk of attackers leveraging users’ access to make lateral moves into systems due to overprivileged access rights.

3. As previously mentioned, securing the source of the connection may be a challenge to almost all organizations. It is nearly impossible for business leaders to identify whether an employee is using their local wireless connection from home or a public Wi-Fi connection at a coffee shop. Hence, ensuring the privacy of the links becomes yet another mandatory requirement to enable the work from home capability. Many organizations rely on traditional VPN solutions, which create a secure point-to-point connection with encryption to protect the communication from a non-authorized actor.

Traditional VPNs do have some challenges, such as sub-nets conflict, substantial firewall opening challenges, routing problems, and others; however, it is still worth having. The connection of privacy is imperative to any organization that cares about their data protection. The good news is that there is a new technology, the next-generation VPN, where the connectivity to the business network is managed via a cloud service provider. The CSP transfers the responsibility of securing the source connected to them and delivering to business in a segmented channel, a unique connection to a specific application as pre-configure. For organizations looking to enhance their connection protection, this new technology could be a good option instead of the traditional VPN solutions.

4. You only protect what you can see. This is a classic quote within security organizations. Placing strong visibility and monitoring solutions are critical to any business that wants to ensure that non-authorized people are caught if they bypass the security controls in place. It goes from the traditional IDS (Intrusion Detection Systems), IPS (Intrusion Prevention System) to the most modern SOARs (Security Orchestration, Automation, and Response) and UBAs (User Behavior Analytics) solutions implementation. It is also important to highlight that any security application will be as good as the quality of the data it ingests.

Increasing visibility over remote connections is a critical path for cybersecurity organizations in order to provide appropriate response to any security incident or event. To perform their day to day job, employees from remote locations connect to the business network. It is imperative to have visibility into how they interact with your system and to have the ability to identify abnormal behaviors quickly.

As we see, enabling the business to expand its capability beyond its traditional network via remote access for users is not a simple plug and play activity. Cybersecurity organizations must be closely aligned with the business objects and ensure that all necessary controls are in place to safeguard the company and employee data, as assets in this new work environment are increasing exponentially due to the current pandemic of COVID-19. It is clear that working from home is not a palliative measure, but it is a new business model, which is not going anywhere, and is here to stay.

About the Author

Diego SouzaDiego Souza is the Global Deputy CISO – Cummins Inc. He is a savvy business executive with over 18 years of experience delivering innovative Cyber Security solutions and leading sizeable global cybersecurity teams such as United Airlines and General Electric. Souza is a thought leader very adapted to safeguarding the confidentiality, integrity and availability of corporate data, information systems and operational technology.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Wanted! Two Chinese Hackers Alleged for Targeting COVID-19 Research

U.S. and China

In an indictment released on Tuesday, July 21, the U.S. Department of Justice has charged two Chinese nationals, Li Xiaoyu and Dong Jiazhi, for their alleged involvement in attempts of hacking and targeting companies that are testing and developing the COVID-19 vaccines. As per the allegations, the duo has been active for the past 11 years and have since been carrying out targeted cyberattacks against countries like the U.S., Australia, Belgium, Germany, Japan, Lithuania, the Netherlands, Spain, South Korea, Sweden, and the U.K.

Key Highlights of the Indictment

  • The duo began malicious operations since September 2009.
  • They have already targeted multiple companies from nearly 11 countries
  • In the U.S. alone, 25 unnamed companies have been their targets.
  • The DoJ points out that personal gains were the prime motive behind this spree.
  • The duo also allegedly worked for China’s Ministry of State Security (MSS).
  • On behalf of MSS, they stole intellectual property and confidential information such as military satellite programs, wireless networks and communication systems, high-powered microwave and laser systems as well as a counter-chemical weapons system.

The first traces of their malicious practices came under the scanner when they compromised a U.S. Department of Energy network in Hanford, which is home to a decommissioned nuclear production complex located in the state of Washington. However, the last straw in their decade long hacking spree fell when they began targeting companies researching on treatment and vaccines for COVID-19.

Assistant Attorney General John Demers, who leads the Justice Department’s National Security Division, said, “These cybercriminals are working for the benefit of other state actors for their personal monetary gains. However, the goal was to feed China’s insatiable hunger for American and other non-Chinese companies’ hard-earned intellectual property, including COVID-19 research.”

Li and Dong also allegedly hacked selected accounts of Chinese dissidents, including those in Hong Kong at MSS’s discretion. As per the 11 indictments, the duo has been charged on various counts including identity theft, conspiracy to commit wire fraud, theft of trade secrets, and violation of anti-hacking laws, all of which account for a maximum sentence of over 40 years. However, both Li and Dong are both currently believed to be in China and thus an immediate arrest in the near future seems unlikely. However, the DoJ was adamant to lay the charges for exposing China’s stance to the global leaders.

New PowerShell Malware Increased 688% in Q1 2020: McAfee

BotenaGo, malware over encrypted connections

Device-to-cloud cybersecurity company McAfee Labs published its report “McAfee COVID-19 Threat Report: July 2020” that detailed the evolution of cybercriminal activities related to COVID-19 in Q1 2020.  McAfee stated that it found an average of 375 new cyberthreats per minute and a surge in COVID-19 related malicious apps, phishing campaigns, and malware attacks. New PowerShell malware increased 688% in Q1 2020, while the total malware grew 1,902% over the past four quarters. New ransomware declined 12% in Q1, while the total ransomware increased by 32% over the past four quarters. Among 458 publicly disclosed security incidents, 50% incidents took place in North America, followed by 9% in Europe. Nearly 47% of all publicly disclosed security incidents occurred in the U.S.

Key findings from the report include:

  • Ransomware attacks evolved into data breaches as cybercriminals steal data before encryption
  • Disclosed incidents targeting the public sector increased by 73%, individual sector increased by 59%, education industry increased by 33%, and manufacturing sector increased by 44%
  • New malware samples slowed by 35%; total malware increased by 27% over the past four quarters. New Mac OS malware samples increased by 51%
  • New mobile malware increased by 71%, with total malware growing nearly 12% over the past four quarters
  • Disclosed incidents targeting the Americas increased by 60%, incidents targeting Asia-Pacific increased by 27%, while Europe decreased by 7%
  • New coin-mining malware increased by 26%, while total coin-mining malware samples increased nearly 97% over the past four quarters
  • New JavaScript malware declined nearly 38%, while total malware grew nearly 24% over the past four quarters
  • New malware samples increased nearly 58%; total IoT malware grew 82% over the past four quarters

Raj Samani, McAfee Chief Scientist, said, “The dominant themes of the 2020 threat landscape have been a cybercriminal’s quick adaptation to exploit the pandemic and the considerable impact cyberattacks have had. What began as a trickle of phishing campaigns and the occasional malicious app quickly turned into a deluge of malicious URLs and capable threat actors leveraging the world’s thirst for more information on COVID-19 as an entry mechanism into systems across the globe.”

 

Beware! Counterfeit Cisco Switches Bypass Network Authentication

Beware! Counterfeit Cisco Switches Bypass Network Authentication

Cybersecurity solutions provider F-Secure published a report detailing how attackers look for backdoors via counterfeit devices. In its investigation report, F-Secure stated that it discovered a pair of counterfeit network switches  impersonating the  Cisco network switches.   The counterfeit devices were designed to bypass authentication processes to system components. The report also highlighted the security challenges faced by organizations with counterfeit components in their IT infrastructure.

Counterfeit Cisco Switches

F-Secure researchers investigated two counterfeit versions of the Cisco Catalyst 2960-X series switches. The counterfeit devices  were discovered by  an IT company after they experienced a hurdle in software updates.  F-Secure performed its analysis on the counterfeits to determine the security implications.  According to the investigation, the counterfeit devices did not have any backdoor functionalities, but  had  the ability to bypass security controls.  The counterfeits were physically and operationally similar to an authentic Cisco switch. Threat actors either invested heavily in imitating Cisco’s original design or had access to proprietary engineering documentation to create fake copy, the report said.

F-Secure also recommended certain measures to help organizations to avoid using counterfeit components, and these include:

  • Source all your components from authorized resellers
  • Have clear internal processes and policies that govern procurement processes
  • Ensure all components run the latest available software provided by vendors
  • Make note of physical differences between different units of the same product, no matter how subtle they may be

Andrea Barisani, F-Secure Consulting’s Head of Hardware Security, stated that enterprises face challenges while mitigating the security issues concerning counterfeit hardware. “Security departments can’t afford to ignore hardware that’s been tampered with or modified, which is why they need to investigate any counterfeits that they’ve been tricked into using. Without tearing down the hardware and examining it from the inside, organizations cannot possibly know if a modified device had a larger security impact. And depending on the case, the impact can be serious enough to completely undermine security measures intended to protect an organization’s security, processes, infrastructure, etc.,” Barisani added.

 

Stalk or Spy? Global Use of Stalkerware Apps Rise Amid COVID-19 Lockdown

Doxing attacks

COVID-19 has not only impacted global physical health, but also cyber health. The constant fixation on the Internet is indicative of the stalking behavior, and how perpetrators are using malicious online tactics to harass their targets. Digital security solutions provider Avast  reported a 51% increase in the use of spying and stalking apps globally since the lockdown in March until June 2020, compared to January and February 2020.

India witnessed a 20% increase in the use of spyware and stalkerware apps. Stalkerware is a software designed in stealth mode,  which allows people to spy on someone’s online activities like tracking their location, access their personal data, communications from WhatsApp and Facebook, eavesdrop on phone calls and make covert recordings of conversations without the target’s knowledge.

Image Source: Avast

Avast has protected over 43,000 users across the globe from such malware since March 2020, with 3,531 users targeted in the U.S., 3,332 in India, and 3,048 in Brazil.

Avast researchers discovered three stalkerware apps in India, which are named after  the Aarogya Setu app, India’s official COVID-19 app. If downloaded, the stalkerware installs along with the app and uses the original app permissions to get access to the AcessibilityService of the Android operating system. With these permissions, an attacker can access victim’s device data, make phone calls, get SIM serial number, read contacts, read and send text messages, record calls/audio, query call logs, and access device location and ID.

Avast research team has recommended certain security measures to defend against the threat of stalkerware:

  • Secure your phone against all unauthorized physical access
  • Install a good, mainstream antivirus product on your mobile phone
  • Look for hotlines and victims’ services providers

Jaya Baloo, CISO, Avast said, “Stalkerware is a growing category of domestic malware with disturbing and dangerous implications. While spyware and info-stealers seek to steal personal data, stalkerware is different: it steals the physical and online freedom of the victim. Usually installed secretly on mobile phones by abusive spouses, ex-partners, so-called friends, and even concerned parents, stalkerware tracks the physical location of the victim, monitors sites visited on the internet, text messages and phone calls, undermining a person’s individual liberty and online freedom.”

 

SACH – An AI-powered Ecosystem for Facts Check

true-false

With the exponential increase in the social media footprint on the internet, anti-social elements are finding newer ways of spreading fake news by exploiting social media platforms, manipulating algorithms and search engines with malicious intentions. The latest example on social media reads: “Does 5G really spread Coronavirus and weaken our immune system?” Such misinformation and fake news spreads like wildfire with a cascaded effect and causes the ‘infodemic.‘ Misinformation about Coronavirus can be equally intimidating, whether it’s bogus cures or conspiracy theories. Apparently, fake news is more contagious than the pandemic itself! It creates panic and disturbs social tranquility. The economies and ill effects of fake news are beyond imagination.

By Naveen Jakhar and Vineet Malik, ITS Officers

Cybersecurity organization CHEQ and the University of Baltimore conducted a study which revealed that the epidemic of online fake news now costs the global economy $9 billion dollars, as far as public health misinformation is concerned. The fake messages and misinformation instigate violence and mob killings. The consequences of fake news are also visible in the COVID-19 lockdown months in India, as it triggered the mass gatherings and exodus of migrant laborers from Delhi and Mumbai. The Palghar lynching incident has shown how fake news leads to communal tension.

Various surveys have reported that there has been an increase of up to 83% in the use of social media amid the lockdown, and netizens are spending approximately 4 hours a day on social media apps like Facebook, Whatsapp, etc.

With fake news spreading with the pandemic itself, it becomes equally important to develop a mechanism that will help reduce the spread of fake news and identify the same at the earliest.

Existing Acts and Regulations in India for Curbing Fake News

The Central and State Governments have invoked the provisions of Section 54 of the Disaster Management Act 2005, and the provisions of Section 66 of the Information Technology (IT) Act 2000 as a measurable warning to tap fake news peddlers and curb false alarms. Legal action will be taken against the perpetrators for spreading false alarms and warnings amid COVID-19. Some of the perpetrators who have already spread fake news regarding migrant workers and other schemes of the Government of India or State Governments have ended up in custody. A majority of the cases have been registered under existing provisions of the Indian Penal Code 1860, and the Epidemic Diseases Act 1897, since India does not have a dedicated “Fake news” law.

Present Mechanism of Handling Fake News in India

The Press Information Bureau’s (PIB) Fact Check is available on key social media platforms like Twitter, Instagram, Facebook, etc., where Indian citizens get all the information and updates about fake news being spread in the country.

PIB’s Fact Check platform https://factcheck.pib.gov.in/ enables the citizens of the country to submit a message for fact check by following a certain mechanism, in which the user is required to enter an email ID, OTP and the description along with attached screenshots or PDFs or URLs/web links. PIB Fact Check is an initiative to counter misinformation related to government departments/ministries or schemes.

However, the information related to government schemes is limited, considering the billions of messages exchanged and shared on social media platforms on a daily basis. Thus, if a citizen encounters a forwarded message or shared post on any social media platform, and is unsure of its veracity, they either use Google search or review two or three websites to determine its authenticity, and whether to forward it or not. But this is an overhead and difficult task, when forwarding is so simple. Globally, Snopes, and in India, Social Media Hoax Slayer and AltNews are some forums which expose fake news.

Motivation for Designing SACH

Fact-checking involves investigating and discerning the validity of a claim or post or message. Countering fake news has been high on the Government of India’s agenda. The fact check ecosystem should be user friendly, easy to use, and help citizens to detect the credibility of the claim of any nature. Identifying fake news is tough. The so-called ‘facts’ are complex to decode and difficult to check, as the text can be half spoken truth, or half lie, as perceived by different persons. The best way to check this menace is by comparing it from authenticated sources or we may call that super dataset as credible database.

SACH – AI powered Fact Check Engine

Every fake news has three important elements: who created it – the creator, what is being created – the payload, and Why it is being created – the target. Therefore, in order to develop a mechanism, we need to answer the three W’s: Who, What and Why.

SACH in Hindi means truth. A team of young ITS Officers is actively working on designing an AI-powered Fact Check engine named as SACHSamachar (NEWS) Analysis and Fact Checking mechanism. SACH will be a one stop solution that does the entire search for you. It takes a screenshot, image, link, text, WhatsApp forward as input and watermarks it with “FAKE” or “ORIGINAL” stamp after validating any claim. Here the user is asked to enter his claim for fact check, which triggers the SACH fact finding engine, and returns the result as Fake/Original/Not found.

How Does SACH System Work

SACH involves 3 steps as shown below:

sach

Step 1: The user shares a screenshot, containing a message whose facts need to be checked. Here, the complainant browses his system/gallery and selects an image whose facts need to be checked, it may be WhatsApp forward, or any article. The input image is converted into text by SACH AI engine. The user may enter plain text as well.

Step 2: The repository called “Credible Databases” is created containing images and their corresponding texts, along with an ID tag and category.

Step 3: The input image is converted into text and matched with the database (repository), and using Natural Language Processing (NLP) techniques, gensim  or machine learning, SACH derives the percentage of similarity between the user input and the credible database repository. If the similarity percentage is beyond a threshold for fake, the image or screenshot shall be considered fake.

The SACH model uses a combination of “Bag-of-Words” or corpus that is used to create a credible repository. By using NLP, word -2-vec conversions, TF (Term Frequency), TF-IDF (Term Frequency Inverse Document Frequency), the input (from the user) is vectorized and compared with the corpus using cosine similarity. SACH compares an arbitrary input text against the verified and credible repository. SACH finds out whether the claimed text is related to the texts/images/articles already stored in the repository under the fake ID tag. If it is related, then it generates an output “FAKE” and watermarks it. The similarity percentage is based on semantics, and has been kept at 85% during the testing phase, which means if 85% of the text matches with a credible database, the news/claim/text/screenshot shall be considered as fake. The repository may contain only fake news, as creating a repository with authenticated news is complex and computationally challenging.

Conclusion and Way Forward

Evolving databases will be the key for advancing the project. The SACH platform may share the results with all the social media platforms. An alliance of WhatsApp, Twitter, Facebook and other social media apps needs to come on a common platform, where fake news is detected by the SACH system, and sent in order to take appropriate action without fail, and within prescribed timelines, for removing such posts or messages.

This mechanism will also enable all central government ministries, departments and organizations to moderate the mechanism and create a repository of its own. As they say in the AI world: “The better the machine learns, the better it responds.”

The evolving SACH mechanism’s accuracy and responsiveness is what the team is focused on. Our team feels a government website/dashboard, along with current PIB mechanisms may take this challenge head-on, with a lot of potential, as we are moving ahead towards tech driven Atmanirbhar Bharat.

About the Authors

Naveen JakharNaveen Jakhar is an Officer at Indian Telecommunication Service (ITS). He is currently working as ADG (Security) in Ministry of Communications, Govt. of India, and taking care of Communications Network Security of Haryana LSA, implementation and monitoring of DoT Policies.

 

Vineet MalikVineet Malik is an Officer at Indian Telecommunication Service (ITS). He is Currently working as ADET (Data Services) in Ministry of communications, Govt. of India. Malik handles work related to ISP Licensing, fixed line broadband Networks.

 

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

CISOs Value Peer Advice Most on Cybersecurity Vendor Solutions

CISOs in remote working

A research from Merritt Group stated that most CISOs value advice from their peers more than any source when shopping for cybersecurity vendor solutions.

The research report “Marketing & Selling To The CISO” revealed that 64% of CISOs admitted that their colleagues   are the primary source for information related to security products and vendors. 13% said they rely on the sources from conferences and events, 9% rely on industry analyst reports, and 8%  depend on vendor content including webcasts and podcasts.

Expectations from Vendors

The research also explained how vendors make a good business relationship or leave a bad impression on security leaders. Around 28% of CISOs surveyed said calls from uninformed sales  personnel minimize the chance of building a business deal. Around 34% CISOs said vendors that understand a company’s security requirements will succeed in making a deal.

Image Source: Merritt Group

CISOs expect vendors to research and understand the company’s unique security needs before making a sales/marketing call.   Around 34% of respondents admitted that they prefer product demos than marketing calls. 24% of CISOs said virtual and digital meetings are their preferred follow-up methods, 22% stated in-person meetings, and 13% of CISOs said emails and phone calls as preferred follow-ups.

“Today’s CISOs don’t want to be passive recipients of sales pitches. They want to discuss, evaluate, and continue to educate themselves. Among our survey respondents in 2020, the most popular settings for evaluating cybersecurity vendor solutions were roundtable events and dinners, which 38 percent of respondents ranked as their top choice. Much has changed since these results came in,” the report stated.

“COVID-19 has put a pause on most in-person events, requiring CISOs to find new ways to meet face-to-face. Roundtables and conferences have gone virtual. Webinar/s, which 15% of CISOs named as preferred ways of evaluating vendor solutions, have also become more widespread. However, if you’re going to plan a virtual event you need to make sure it will be worthwhile for the CISO. Organizations are planning more events than ever before and the quality is being impacted,” the report added.