Home Blog Page 193

CYFIRMA Brings Cyberthreat Intelligence to the Fore

Kumar Ritesh

In the last two decades, the cybersecurity landscape has evolved, but security processes and controls have failed to integrate quality outside — in view of new cyberthreats and risks. Cyberthreat intelligence is an increasingly overused terminology, confusing the industry and blurring the lines between information and quality intelligence. This is where CYFIRMA steps in.

By Mihir Bagwe, Technical Writer, CISO MAG

CYFIRMA is a cyberthreat intelligence analytics platform company with a flagship product called DeCYFIR. This product is designed using Artificial Intelligence and Machine Learning (AI/ML) to provide real-time insights, threat visibility, and situational awareness to prevent business losses. It helps organizations discover and decode unknown cyberthreats and mitigate potential risks. The platform aggregates, correlates and analyzes information from the open and dark web, to effectively identify and process potential threats at the planning stage of a cyberattack. It provides deep insights into the cyberthreat landscape, and amplifies the preparedness of organizations by providing relevant, predictive, and prioritized cyberthreat visibility and intelligence.

The predictive capability of the platform gives organizations deep insights that correlate data to form a threat story, providing context to every threat, increasing the accuracy of threat alerts, and helping clients prioritize resources for cyberattack prevention. It also equips organizations with a multi-layered approach to cybersecurity and helps form strategic, management, and tactical viewpoints.

3 Layers of DeCYFIR

A Company to Watch

The company’s growth and service offerings depend mainly on the leadership, guidance, and mentoring of its C-suite, and CYFIRMA has got the perfect piece to fit in this puzzle. CYFIRMA’s Chairman and CEO, Kumar Ritesh, has over two decades of experience in global cybersecurity leadership and has various certifications including PMP, CISSP, CISM, CISSP-ISSAP, TOGAF 9.1, CIPM, and CIPT, among others, to back his knowledge and skill set. He is a highly dynamic executive displaying a high grade of technological acumen and business skills, along with a strong track record of developing successful cybersecurity strategies, products, policies, standards, and solutions.

His resume also includes the development of prototypes for data loss prevention, social profile risk assessment, web content assessment management, intelligence-led cyber risk management, and adaptive cyberthreat intelligence tools.

Kumar Ritesh, CEO, CYFIRMA

“Cyberthreat intelligence is an increasingly overused terminology, confusing the industry and blurring the lines between information and quality intelligence. This is where CYFIRMA steps-in.”

 

Ritesh always observed that organizations struggled to understand the external threat landscape, as their cyber posture management was highly focused on internal protection, security controls, and building firewalls. This was proving ineffective, given that threat actors always kept modifying their approach, methodology, and techniques. A productized offering was needed to help organizations consume multi-dimensional intelligence driven by deep technology —thereby making cyber posture management efficient and effective.

CYFIRMA’s clients are exclusively provided with:
  • Client-tailored and customized Outside-in/Hacker’s view of the cyberthreat landscape.
  • Multi-dimensional strategic, management and tactical cyberthreat visibility and intelligence.
  • Threat indicators at the planning stage versus the execution and exploitation phase of a cyberattack.
  • Indicator centered threat hunting capabilities, which could be as simple as a conversation or geo-political issue driving the cyberthreats and risks.
  • An ability to integrate intelligence and insight into risk management, cyber posture management, and regulatory, compliance, governance, investment, and resource management.
  • Deeper analytical insights into situational awareness, cyberattacks and events, incidents, vulnerabilities, technology, or regulatory shift.

CYFIRMA has a team of highly experienced professionals with rich expertise in the cybersecurity domain along with AI and ML, among others. We believe CYFIRMA is the company to watch out for in 2020, especially with its core product DeCYFIR, which is being upgraded.

S N A P S H O T
Company CYFIRMA Holdings Pte Ltd
Founder Kumar Ritesh
Website https://www.cyfirma.com/

https://www.cyfirma.jp/

Core Solution CYFIRMA’s proprietary, cloud-based Cyber Intelligence Analytics Platform – DeCYFIR (CAP v2.0)
Social Media Handles LinkedIn: https://linkedin.com/cyfirma/

Facebook: https://facebook.com/Cyfirma/

Twitter: https://twitter.com/cyfirma

Location(s) Singapore, Japan, and India
Employees 40+
Estimated Annual Revenue $3 Million
Funding Seed Funding: Total investment in US$3million, as part of Antuit Group, CYFIRMA was Incubated since 2017

  • List of investors: Goldman Sachs, Zodius Capital
  • Lead Investor: Goldman Sachs

Series A Funding: Total investment in Series A, US$5 million.

  • List of investors: Goldman Sachs and Zodius Capital
  • Lead Investor: Goldman Sachs
Awards
  • CYFIRMA was selected as “Most valuable brand of 2019” by prestigious journal IndustryWired
  • Recognized in Aspioneer’s “10 Most Trusted Cybersecurity Solution Providers, 2019”
  • Selected in the  list of “Top 25 cybersecurity companies – 2019” by CIO Applications
  • CYFIRMA is Featured in ICE71’s latest Singapore Cybersecurity Startup Map
  • Acclaimed as one of the “Top 10 Artificial Intelligence-Driven Solution Provider 2019” by Enterprise Security amongst 230 competitors
  • Listed in the prestigious Cyber Startup Observatory – US CyberSlide, APAC CyberSlide, Singapore CyberSlide and Japan CyberSlide
  • Named in APAC Business Headlines Magazine’s “10 Sought After Risk Management Solution Providers in 2019”
Industry-wise Services
  • Defense & Security
  • Manufacturing
  • Health care
  • Travel & Hospitality
  • Retail

 

PRODUCTS & SERVICES
Offerings CYFIRMA’s proprietary and award-winning cloud-based Cyber Intelligence Analytics Platform essentially provides the following:

  • Broad range of cyber intelligence use cases
  • Real-time multi-layered intelligence
  • Early threat visibility
  • Holistic cyber situational insights
  • Cyber trending and current landscape
  • Deeper analysis and research
  • An illustrative dashboard

The following core DeCYFIR modules drive the consumption of CYFIRMA’s insights and intelligence:

Threat Visibility & Intelligence: Provides comprehensive multi-dimensional strategic, management and tactical intelligence and insight into the latest cyberthreats applicable to an organization, industry, and geography.

Cyber Awareness: Provides real-time cyber insights, trends, the latest cyber news, technology, and regulatory changes, emerging cyber-attacks, vulnerabilities, and exploits.

Cyber Incident Analytics: Enables analysis of malicious files and automatic correlation with threat landscape to present affiliations to any threat actors, campaigns, and indicators.

Besides these, CYFIRMA’s service offerings also include:

  • Daily Cyberthreat Intelligence reports
  • Weekly Security Updates
  • Cyber Education
  • Vulnerability Analytics
  • Brand/Individual Cyber Risk Monitoring and Cyber Risk Scoring

Company Timeline

CYFIRMA timeline

About the Author

CISO MAG Writer - Mihir Bagwe
Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 


Other Posts from the Author:

Biden Ups the Cybersecurity Game Ahead of Elections

Biden election cybersecurity

With four months toward the Election Day, and several state-sponsored cyberattacks already targeting the 2020 election, cybersecurity has taken the center stage. The presumptive Democratic nominee for President, Joe Biden hired former White House cybersecurity official Chris DeRusha as the CISO for his election campaign and Jacky Chang as Chief Technology Officer.

DeRusha is a credible cybersecurity executive with experience in managing federal and state government programs, coordinating cybersecurity operations, and developing and implementing strategy and governance. Prior to this, he was an advisor to the White House and also held cybersecurity positions with the State of Michigan, the Department of Homeland Security, and Ford Motor Co. Chang was a senior engineer on Hillary Clinton’s 2016 presidential campaign and worked for the Democratic National Committee’s voter protection team during the 2018 midterms.

“Biden for President takes cybersecurity seriously and is proud to have hired high-quality personnel with a diverse breadth of experience, knowledge, and expertise to ensure our campaign remains secure,” the campaign said in a statement. “Jacky and Chris will be central to strengthening the infrastructure we’ve built to mitigate cyberthreats, bolster our voter protection efforts, and enhance the overall efficiency and security of the entire campaign.”

Even though elections have been at the forefront of cyberattacks, lately, the concept of a CISO for a campaign is still a novelty. This was even after Russian hackers exposed emails of Hillary Clinton in the 2016 elections.

The upcoming election has already witnessed a slew of cyberattacks targeted against it. A recent survey stressed that 70% of cybersecurity professionals most likely believe their local governments cannot defend election infrastructure against cyberattacks from domestic and foreign threat actors.

The majority of cyberattacks targeting election campaigns come from automated machines that inevitably spread information and direct attacks on the vote-counting systems. Industry experts opine that the ongoing pandemic brings additional security hurdles to the election season. It is suspected that cybercriminals might take advantage of the crisis to spread false information and initiate cyberattacks, making security experts concerned about election data protection.

“When we think about threats to the upcoming elections, I would break them up into two groups. For undermining the election, disinformation operations supported by cyber operations pose the greatest threat,” said Marcus Fowler, Former CIA executive, and currently Director of Strategic Threat at AI security firm Darktrace, in an exclusive interview with CISO MAG. “Adversaries looking to hack a campaign to get the upper hand will likely be going after the information that could reputationally damage a candidate. This is less about broad disruption or undermining trust, and more about swaying individual voters and out-maneuvering a campaign. One would hope that we don’t see this type of targeting between campaigns, as we have enough to worry about from foreign actors”

He added, “As for best practices, the most immediate step that needs to be taken is that state and federal agencies and municipalities need to review their processes and communication plans around a ransomware event, especially one conducted around the election that could have an impact on voting. I think State, Local, and Federal agencies need to be more strategic–resourcing their cybersecurity teams more efficiently and more in-line with the current threats, and leveraging technology that will help buy back time for their security teams through autonomous response and investigation.”

Google-backed Delivery App Reports Data Breach

dunzo data breach

Dunzo, an India-based on-demand delivery provider app that has seen large investments from Google on the back of its top-notch services, reported a limited data breach that compromised its customer database. However, the breach has now been resolved and Dunzo has beefed up its security.

Mukund Jha, CTO of Dunzo, on Saturday, informed that an unauthorized access to its database had taken place potentially through a third-party service provider, which led to customer information compromise.

Things we know so far…

  • Threat actors initiated a breach through a third-party vendor of Dunzo
  • The data breach was only limited to user databases
  • User phone numbers and email addresses were compromised
  • No loss of payment information like credit card details was reported as per initial investigations

As per Mukund’s statement, Dunzo has always prioritized users’ data security and privacy and thus felt obligated to inform them about the immediate security safeguards implemented by the company post the data breach reporting.

Safeguarding steps taken

  • All networks and access points to Dunzo’s databases have been secured
  • All access tokens and passwords have been changed and updated
  • Security infrastructure has been upgraded and all potentially vulnerable ports are closed
  • All access privileges to network and system infrastructure have been reviewed and upgraded
  • All third-party plugins and integrations have been reviewed and upgraded
  • Logging and tracing have been further enhanced to monitor any suspicious activity

Data breach incidences can be complex and organizations handling customer data need to be doubly sure that no backdoors are present in the databases that will affect them in the future. Thus, Mukund said, “While our best teams are working on resolving and strengthening our security efforts, we’re also engaged with leading cybersecurity firms and experts to further strengthen these efforts. We are taking all necessary steps to resolve the security breach and will keep you updated if we know more.”

More Than Half of Canadians Have Been a Victim of Cyberattacks

cyberattack-on-canada

A new survey from the Cybersecure Policy Exchange (CPX) at Ryerson University in Toronto revealed that nearly 57% of Canadians have been the victims of a cyberattack. The survey “Advancing a Cybersecure Canada” highlighted Canadians’ online behavior and their priorities on cybersecurity and data privacy.

According to the survey, 31% of respondents suffered a cyberattack due to unintentional download of malware. 22% reported that unknown hackers compromised their accounts. 28% of respondents experienced a data breach, while 13% of them suffered a phishing attack.

Other Key Findings include:

  • Canadians have adopted new technologies to stay connected during the lockdown, making them more vulnerable to privacy and security risks. 55% of Canadians have used Facebook Messenger and 46% have used Zoom
  • Only 26% of Canadians with a smart speaker or voice-operated assistant have restricted the information it can access through its settings
  • Only 15% of Canadians trust Facebook to keep their data secure, compared to 62% who trust the federal government and 73% who trust health care providers
  • 68% of Canadians have at least one smart device in their home
  • 41% of Canadians are uncomfortable with being captured by video doorbells like Amazon’s Ring, and 15% support a ban on these products

Charles Finlay, Executive Director of Rogers Cybersecure Catalyst – Ryerson University, said, “We live and work in a time of unprecedented technology development and adoption further accelerated by events like COVID-19. We need urgent national policies that protect our security and digital privacy, while ensuring equal access for all. That is why we developed CPX–to be a platform for debating and advancing cybersecurity policy that is of critical importance to all Canadians.”

The Cybersecure Policy Exchange or CPX is an initiative from Ryerson University that is intended to advance cybersecurity and digital privacy policy in Canada. The survey findings are based on the responses from 2,000 Canadians surveyed in an online poll.

Cyberattacks on Canada

Multiple security incidents have been reported in Canada. Recently, the Chartered Professional Accountants of Canada (CPA) disclosed a security breach that affected over 329,000 members and stakeholders of the association. It is said that unknown hackers compromised the CPA Canada website and obtained information related to the distribution of its magazine. “There is no evidence that the encryption keys were affected in this incident and we have no reason to believe the encryption was compromised,” the company said in its security incident report.

Cybersecurity and Artificial Intelligence – It’s Complicated

AI

In this article, I will look at how Artificial Intelligence (AI) can help improve cybersecurity practices in an environment of ever-increasing threats and discuss the role of AI in alleviating the perennial talent shortage in the field of cybersecurity. Remember that the current wave of AI, driven by advances in deep learning, started around 2015, but the talent short- ages in cybersecurity precede that. I also caution that if we are not careful, AI can even be a double-edged sword when it comes to cybersecurity.

By Kashyap Kompella, CEO at RPA2AI Research

Let me start with a flashback. About a decade ago, I used to audit the information security practices and cybersecurity preparedness of large global enterprises. We found that the main concern and the weakest link in preparation was the talent shortage for security teams. This was true for different organizations across multiple geographies. Imagine if that was the situation in the pre-smartphone and pre-IoT age – and in the current scenario, when the threat landscape has become that much more complex!

Exponential growth in digital infrastructure and connected devices

Every year, millions of connected cars, hundreds of millions of wearable and IoT devices, plus more than a hundred billion lines of new software code are added to the existing digital infrastructure of our world. No doubt, digital technologies and smart devices have vastly improved customer experience, increased business agility, and ushered in an era of rapid digital innovation. But at the same time, we must acknowledge that from a cybersecurity point of view, there are now that many more threat surfaces and attack vectors.

If we had talent shortages in the pre-digital era, imagine the extent of the shortage now. Not surprisingly, industry surveys year after year reach the same conclusion – that there simply are not enough cyber- security experts to staff the roles required to navigate enterprises through this com- plex threat landscape and to safeguard our digital infrastructures and systems.

Cost to enterprises of attacks has gone up considerably

Compounding this problem are a few other factors related to the cost of attacks, data privacy concerns, regulatory compliance requirements, and fines for non-compliance or failure to adequately safeguard user data. So much so that cybersecurity insurance is one of the fastest growing segments of the insurance industry!

As more and more of our lives from commerce to citizen services move online, the cost of security breaches has gone up – not just from a regulatory point of view, but also from a brand reputation and a lost business opportunities point of view. There are in- stances of CEOs having lost their jobs because of cybersecurity breaches. Without doubt, cybersecurity is definitely a C-suite and a boardroom issue now.

What excites cybersecurity leaders and CXOs about AI?

At the current scale, because of the complexity and diversity of enterprise technology estates and infrastructures, traditional, manual-based cybersecurity approaches are coming apart at the seams. Given the talent shortages discussed above, it is as if cybersecurity leaders are fighting battles with their hands tied. AI, and the potential to automate repetitive tasks and relieve overworked teams to instead focus on value-added and pro- active analysis, is very attractive in this context.

AI Use Cases in Cybersecurity

In addition to AI’s potential for automation, there is also a great amount of interest in exploring the usage of AI to improve the current practice of cybersecurity. Note that by AI here, I refer more specifically to one of its branches called machine learning.

The majority of the use cases of machine learning for cybersecurity rely on supervised machine learning techniques (where human cyber analysts initially train the machine learning application using existing data). Unsupervised machine learning (where there is no such human training) use cases are still in an emerging phase and experimentation. This is true of use cases outside the realm of cybersecurity as well.

With that context, here are some examples where AI is being used to improve the current approach to cybersecurity:

Intrusion Detection: Machine learning helps detect and defend against intrusions, going beyond simple rules-based logic. Once the typical behavior is “learned by AI” for example, based on factors such as number of access attempts, frequency of queries, amount of data per query, outliers are automatically flagged as suspicious without the need for any human intervention.

Malware Detection: Typically, new malware is manually created by bad actors but once that is done, the creation of subsequent variants (that are intended to evade detection) is automated. Enhancing traditional signature-based systems of malware detection with machine learning techniques can identify such future versions and variants of malware and prevent their spreading.

Discovery of code vulnerabilities: This is a relatively new application area, where machine learning is used to scan vast amounts of code and automate the process of identifying any potential vulnerabilities (before the hackers do).

Enhanced Threat Intelligence: By combining traditional threat intelligence (i.e. using a list of all known threats to date) and using machine learning to detect new threats, better overall threat detection rates can be achieved.

Fraud Detection: Fraudulent transactions and activity can be flagged and prevented in real-time by detecting patterns and identifying deviations from the expected baseline behavior. Anomaly detection, as this technique is commonly known, is one of the best-known applications of machine learning. Manually sifting through the vast amount of event logs to identify outliers is not only humanly impossible but is also best left to AI.

As you can see from the above discussion, these use cases are not entirely new. These are certainly things that practitioners have been doing for a long time. The difference is that now, AI is being applied to these existing use cases with the goal to make them more robust and more secure. In this manner, enterprises can reduce the time taken to identify, analyze, and respond to threats by complementing and extending existing approaches with AI.

But AI can also increase the threat surface. AI systems, just like other IT systems, come with their own vulnerabilities. Attacks on AI systems mostly involve confusing the underlying ma- chine learning model and bypassing what the AI system is supposed to do. For example, generative adversarial networks (GANs are a type of artificial neural network technique) can be used to fool facial recognition security systems. GANs can even be used to attack speech applications and subvert voice biometric systems. Another example is that by fooling the AI system in a subtle way, a malware file may be made to be incorrectly classified as a safe file. As AI applications get more widely adopted, such risks will also increase. These risks first need to be understood before they can be mitigated. This also means that cybersecurity specialists need to have a very good understanding of how such applications work, what their susceptibility to adversarial attacks is, and how to become well-versed in machine learning technologies.

AI can be weaponized by malicious actors. Another note of caution is also in order. AI is a dual-use technology. That means it can be used for both good and evil. In the context of cybersecurity, we need to realize that the same AI technologies are also available to the malevolent actors and they are becoming adept at using AI and have started to employ them in a variety of ways. One such example is spear phishing, where emails are personalized using AI to maximize the chance of victims opening the emails and clicking through to unsafe links and sites. Not only that, hackers are also choosing their victims based on the likelihood of them “converting” – just like a regular marketer using AI.

Such risks can become even more heightened in a “work from home” and remote working scenarios where the workforce is much more likely to be distributed and outside the organizational security perimeter. How to mitigate such risks is going to be a big area of concern for cybersecurity teams in the future and a first step would be to hire AI experts into cybersecurity teams.

We discussed a wide range of topics and themes. But in the final analysis, the nature of cybersecurity is a constant cat-and-mouse game. There is no definite end point but it is a continuous cycle of identifying, preventing, and guarding against emerging threats and new risks. Artificial intelligence does not change this fundamental dynamic of cyber-security, but hopefully it provides an edge for enterprises that wield it smartly. Ultimately, the question boils down to whether your enterprise effectively harnesses artificial intelligence technologies or whether the hackers leverage AI better than you do.

About the Author

Kashyap ompellaKashyap Kompella is the CEO of RPA2AI Research, a global technology industry analyst firm. He is also the co-author of the bestseller “Practical Artificial Intelligence: An Enterprise Playbook.”

 

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

3 Ways to Solve the Cybersecurity Talent Gap

cybersecurty

The cybersecurity talent gap is well documented and well-known throughout the cybersecurity industry. Not surprisingly, CISOs believe this problem will continue to worsen resulting in understaffed security teams defending organizations against sophisticated cyberattacks.

By AJ Yawn, Cloud Security Expert

The recent CISO Mag Cloud Security Survey demonstrated the concern senior executives have regarding the industry’s talent shortage:

  • 45% of respondents stated that a skill gap in the security team is a top security concern
  • 34% of respondents stated that personnel being insufficiently trained on cloud security is a top security concern
  • 43% of respondents stated that a lack of skillset to understand security implications is a major concern

There is no magic bullet to solve the cybersecurity industry’s hiring and retention issues. However, I suggest CISOs and Senior executives consider the following three practices to help close the cybersecurity skills gap at their organizations.

Invest in Your Own People

The skills gap can be attributed to a self-inflicted wound — organizations are not investing in their current security employees. The employee training discussed here is not annual security awareness training but investment in upskilling your cybersecurity workforce. Organizations should be making monetary contributions to incentivize training such as reimbursement for certifications, paying for training resources, practice tests, promotions, pay raises, and more.

This investment may also involve cultural changes. The organization has to provide employees with time to spend on professional self-development. In their off time, employees should not be forced to choose between learning a new work-related skill or spending time with their families. A strong culture encourages and sets up systems to allow internal employees to work on personal development during work hours. This culture is okay with sending their best employees to training events that may take them away from the day to day operations, a week or more at a time.

The culture of relentlessly improving internal security professionals will have profound benefits for the organization. When hiring externally, organizations invest time and resources training new employees on internal business practices, tools, and culture. This is time and money that can be saved by investing the same time and resources into training internal employees who are intimately familiar with the business and tools.

Let’s make this concept tangible. An example organization (ABC Company) is hosted on Microsoft Azure and is considering expanding to a multi-cloud infrastructure. Management is planning to use Amazon Web Services (AWS) for its second cloud environment. ABC Company has a team of experienced Azure engineers and security professionals but no one comfortable leading an AWS migration project. In this situation, most organizations opt to hire an external AWS expert to lead and train their team.

There are benefits to hiring externally and, as I’ll discuss below, if an organization does hire externally they should clearly state the skills needed in the job description. However, this is a great opportunity to train an internal Azure engineer on AWS. Invest the time and resources in creating an internal multi-cloud and ABC Company expert. The benefits trickle down. ABC Company now has a multi-cloud expert to lead their migration to AWS as well as a more experienced team of Azure professionals who had to step up while the multi-cloud expert was being trained.

Change the Way Job Descriptions Are Written

When organizations do seek to fill cybersecurity positions from outside the company, creative job descriptions have been a hindrance to finding great candidates. Cybersecurity leaders must be intimately involved in creating, drafting, and refining job descriptions in order to attract the right candidate for the organization. Job descriptions that are poorly-worded, confusing, and unrealistic, will discourage qualified candidates from applying. Or worse, qualified candidates apply but are rejected by the applicant tracking system because they don’t meet arbitrary requirements that have little impact on a person’s ability to perform the necessary duties for the position.

CISOs and other cybersecurity hiring managers have a responsibility to maintain active involvement in the creating and publishing of job descriptions. By taking responsibility for the job description production process, security leaders can ensure that recruitment efforts are focused on the actual skills needed for the position, skills that are requisite for your budget, and the necessary duties. Job descriptions should not ask for an entry-level help desk candidate, offer to pay them below the average salary for an entry-level employee, and at the same time require 10 years of experience, 5 certifications, and a Master’s degree.

This does not make sense. Security hiring managers have an obligation to their organization and the cybersecurity industry to ensure job descriptions accurately reflect the needs for the position.

Hire More Minorities

It is impossible to solve the cybersecurity skills gap by continuing the same hiring and development practices in the industry. Studies have found that the U.S. cybersecurity industry has slightly higher representation (26%) than the overall U.S. minority workforce (21%). However, these studies revealed that minorities are not holding managerial positions, and they are being paid less than their white counterparts. Similarly, women in cybersecurity make up only 20% of the workforce and are paid less than their male counterparts on average. The lack of management positions, low percentage of women in the industry, and pay discrepancies are disturbing. Among the most disappointing data points, are the statistics of Black employees at top tech companies,

  • 9% at Salesforce
  • 8% at Facebook
  • 4% at Slack
  • 5% at Microsoft
  • 6% at Twitter
  • 6% of Google’s leadership is black

The industry can close the skills gap by hiring more women and minorities. Creating pipelines into the field from schools and regions where organizations do not currently invest time and resources should be a priority for cybersecurity leaders. Additionally, unconscious bias must be removed from hiring practices. These simple, essential steps will open the door for women and minorities to succeed in the cybersecurity workforce. A commitment to diversifying the field starts with individual CISOs finding new ways to attract, hire, and retain talented women and minorities.

Fixing the Talent Shortage Starts Now

Investing in internal employees, fixing job descriptions, and hiring diverse professionals are three actions CISOs and senior executives can take to shrink the cybersecurity skills gap. This problem will be solved at the individual practitioner and individual company level. Cybersecurity professionals are critically important. It is scary to think that, in times of increasing cybercrime, there will be 3.2 million unfilled cybersecurity jobs in 2021. To fix this, status quo hiring and development of cybersecurity professionals must change now, not only to close the gap but to protect our interconnected way of life.

About the Author

AJ Yawn, Cloud securityAJ Yawn is a cloud security subject matter expert that possesses over nine years of senior information security experience and has extensive experience managing a wide range of compliance assessments (SOC, ISO 27001, HIPAA, etc.) for a variety of SaaS, IaaS, and PaaS providers. He has earned several industry-recognized certifications, including the CISSP, AWS Certified Security Specialty, AWS Certified Solutions Architect-Associate, and PMP. AJ is involved with the AWS training and certification department, volunteering with the AWS Certification Examination subject matter expert program.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

 

How to Choose the Right VPN for Your Business and Remote Workers

Fortinet VPN, VPN, VPN devices

Governments, businesses, and various other entities are constantly monitoring the internet for various reasons. While at times their activities make sense, most of their programs are immoral and unethical because they don’t involve user consent. With data becoming a valuable and tradable commodity these days, the lengths to which various organizations go to collect it is surprising. In these precarious times, using a VPN is becoming imperative if one wants to browse the internet freely and securely.

But how do you pick the right VPN, when there is so much choice?

Why Ivacy?

Picking the right VPN these days can be tricky. Consumers are spoilt for choice but only a handful of services deliver as promised. That’s why it is crucial to know which service to trust. Ivacy is among the top ranked* VPN services with substantial ratings from various independent reviews and several accolades won at renowned stages.  It offers a comprehensive bundle of services in an affordable price which makes it incredibly irresistible.

*Disclaimer: CISO MAG has not verified this claim or tested this product, nor does it endorse this claim. This is a paid feature.

Some of the features that make Ivacy so popular include:

Servers

A VPN removes geographic restrictions on the internet by masking user IP addresses. This is done by rerouting data traffic to secure servers located around the world. Ivacy has more than 1,000 servers in 100+ locations across 55 countries. All these servers handle information in a secure and subtle manner, limiting the role of local Internet Service Providers (ISPs) as well as other entities in monitoring or regulating data traffic without checks. The spread of servers in most countries across the globe opens diverse possibilities for users to access the internet freely.

Encryption

A secure server is the first line of defense against online spying and cybercrime. The more robust and effective second line however is known as encryption. Ivacy offers AES 256-bit encryption for all the data traffic of its users making it almost impossible for any element to break through and steal or decode the information being sent over the airwaves. Users can use the internet assured that they are protected by a military-grade protection shield.

Malware protection

Malwares include a wide variety of viruses like adware, spyware, ransomware, Trojans, bugs, bots among numerous others. Without a VPN, these viruses are hard or impossible to detect. Using advanced technologies, Ivacy can spot potential malware intrusion attempts, alerting the user to impending threats. This allows for secure browsing and safeguards against potentially damaging threats from cybercriminals.

Unlimited internet freedom for streaming and downloading

Under ISPs, user internet connections are restricted both in terms of bandwidth as well as with the freedom for accessing foreign content. With Ivacy, all these problems are eliminated. Users can connect to their choice of server anywhere in the world and then enjoy buffer-free, unlimited bandwidth streaming which enhances the overall experience. All major platforms like Netflix, Spotify, Amazon Prime, Disney+, BBC iPlayer, HBO Go, Hulu and various others are all accessible through Ivacy quite easily.

Tailor-made products for individuals, businesses, and gamers

Different industries and disciplines have different requirements when it comes to internet usage. Businesses can have several employees who need separate protection for everyone. Similarly, gamers require heavy data transfer abilities, constant speeds, and protection against threats like DDoS attacks. Ivacy provides custom programs for each segment so that they can enjoy the best experience while executing daily tasks in a smooth, as well as secure environment.

Dedicated applications

Ivacy has dedicated applications for all leading operating systems. iOS, Android, Windows Phone, Blackberry, Mac, Windows, Linux, PS4, PS3, Xbox, Raspberry Pi along with several smart TV and internet router models are also supported by the service. With optimized applications available for each, users just need to install and activate with ease.

Conclusion

Ivacy is among the best services which the industry can offer. For more information you can visit their website and purchase a subscription at the earliest for the best internet experience you’ll ever find.

ADVERTORIAL

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by this company in the article. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

 

New Smishing Campaign Targets HSBC Customers in the U.K.

Smishing Campaign on HSBC

Security researchers from Griffin Law discovered that HSBC bank customers in the U.K. are being targeted by a new smishing campaign, which is intended to trick them into entering their bank login credentials.

The researchers stated that the smishing attack, also known as SMS phishing attack, begins with a fake text message that claims to be from the banker notifying the receiver about a new payment made via the HSBC mobile app from the victim’s device. The message asks the users to visit a site Security.hsbc.confirm-systems.com to report in case they have not done the transaction. If a user clicks on the link, it will redirect them to a phishing site impersonating  the legitimate HSBC bank site and asking users to enter their account login credentials and other personally identifiable financial information (PIFI). Griffin Law received complaints from around 47 people saying they have received fake text messages. The attackers also sent phishing messages to users who did not even use the  HSBC app.

Several industry experts warned that hackers often use smishing techniques to steal financial information from victims by attracting their attention with unauthorized payment messages.

Cyberattack on HSBC

Earlier, the HSBC officials revealed that some of its U.S. customers’ bank accounts were compromised. The bank stated the incident affected 1% of its American clients after cyber miscreants allegedly accessed customers’ names, addresses, date of birth, bank account numbers, account balances, statements, transaction histories, and payee details. HSBC suspended the internet banking access temporarily to the affected customers to prevent further loss and reported the incident to the California Attorney General’s Office. Further, the banker improved the authentication process of its online banking and also provided the users with a complimentary subscription to credit monitoring and identity theft protection services.

 

Joker Malware Laughs Again; Bypasses Google Play’s Security

joker malware, joker, malware, Android malware

It seems Google’s Play Store did not hear the joker laughing. Confused? Yes, it is true! An old yet familiar malware family, the Joker malware, has been found to be secretly hiding out in legitimate Google Play applications. According to the researchers, the new variant is an improvised version of the previously known malware, which downloads additional payloads and also subscribes app users to premium services without their knowledge and consent.

The Joker’s First Laugh

This Joker malware first surfaced in 2017. It was one of the most commonly infested type of Android malware used in carrying-out billing frauds and its spying capabilities meant that it was extensively used in stealing SMS messages, contact lists, and device information. Ever since, the Joker malware has been prevalent in several cybercriminal activities under various names, as researchers suggest.

Joker Malware’s Evolution

The new variant, which was first discovered by Check Point researchers Aviran Hazum, Bogdan Melnykov, and Israel Wernik, leverages the app’s manifest file that loads a Base64 encoded DEX file. The .dex file is hidden as Base64 strings and added as an inner class in the main application. This loads it via the reflection APIs.

Referring to its additional capabilities, Aviran Hazum said, “To achieve the capability of subscribing users to premium services without their knowledge or consent, the Joker utilized two main components — the Notification Listener as a part of the original application, and a dynamic dex file loaded from the C&C server to perform the registration.”

Joker Malware also has an additional feature that remotely issues a “false” status code from a C&C server under the threat actors’ control, which helps in disguising the malicious activity as a legit one.

Joker Malware IOCs

db43287d1a5ed249c4376ff6eb4a5ae65c63ceade7100229555aebf4a13cebf7 (com.imagecompress.android)

d54dd3ccfc4f0ed5fa6f3449f8ddc37a5eff2a176590e627f9be92933da32926 (com.contact.withme.texts)

5ada05f5c6bbabb5474338084565893afa624e0115f494e1c91f48111cbe99f3 (com.hmvoice.friendsms)

2a12084a4195239e67e783888003a6433631359498a6b08941d695c65c05ecc4 (com.relax.relaxation.androidsms)

96f269fa0d70fdb338f0f6cabf9748f6182b44eb1342c7dca2d4de85472bf789 (com.cheery.message.sendsms)

0d9a5dc012078ef41ae9112554cefbc4d88133f1e40a4c4d52decf41b54fc830 (com.cheery.message.sendsms)

2dba603773fee05232a9d21cbf6690c97172496f3bde2b456d687d920b160404 (com.peason.lovinglovemessage)

46a5fb5d44e126bc9758a57e9c80e013cac31b3b57d98eae66e898a264251f47 (com.file.recovefiles)

f6c37577afa37d085fb68fe365e1076363821d241fe48be1a27ae5edd2a35c4d (com.LPlocker.lockapps)

044514ed2aeb7c0f90e7a9daf60c1562dc21114f29276136036d878ce8f652ca (com.remindme.alram)

f90acfa650db3e859a2862033ea1536e2d7a9ff5020b18b19f2b5dfd8dd323b3 (com.training.memorygame)

Surge in Remote Work Drives BYOD; Security Remains Primary Concern

BYODs

A latest survey from cloud security firm Bitglass revealed that the surge in remote work has encouraged businesses globally to embrace BYODs (Bring Your Own Devices) concept in the workplace.

According to the survey “2020 BYOD Report”, 69% of businesses allowed their employees to use personal devices to perform their work, while some enable BYOD for contractors, partners, customers, and suppliers. It is found that the surge of personal devices in the work environment resulted in security incidents, with 63% of respondents said they encountered data breach incidents, 53% reported unauthorized access to data and systems, and 52% experienced malware infections.

The survey also highlighted that organizations are allowing BYOD without taking necessary security measures to protect corporate data. 51% of the surveyed organizations lack any visibility into file sharing apps, 30% reported they have no visibility or control over mobile enterprise messaging tools, and only 9% have cloud-based anti-malware solutions in place.

“The top two reasons enterprises hesitate to enable BYOD relate to company security and employee privacy. However, the reality is that today’s work environment requires the flexibility and remote access that the use of personal devices enable. To remedy this standoff, companies need comprehensive cloud security platforms that are designed to secure any interaction between users, devices, apps, or web destinations,” said Anurag Kahol, CTO of Bitglass.

BYOD- A Growing Risk Factor

As modern enterprises incorporate more BYODs, shadow IoT devices will become an ever-growing risk factor to enterprise network security, a similar research from Infoblox revealed. The study stressed that enterprise networks pose potential cyberthreats by shadow IoT devices. Shadow IoT devices are internet connected devices or sensors used inside an organization without the knowledge of the IT team in a company. The reportWhat’s Lurking in the Shadows 2020 revealed that 80% of IT professionals discovered shadow IoT devices connected to their company’s network. 9 in 10 security leaders (89%) were worried about shadow IoT devices connected to remote or branch locations of their businesses. The research also revealed that 78% of global organizations found more than 1,000 personal devices like laptops, smartwatches, and mobile phones connected to their corporate network.