Home Blog Page 196

Data Breach Affects 384,319 BMW Customers in the U.K.

BMW Data Breach

KELA, a darknet intelligence firm discovered that a hacker group “KelvinSecurity” compromised the personal information of 384,319 BMW customers in the U.K. and put them for sale on various darknet forums, SC Magazine reported.

The hacker group claimed that they got the BMW database from a call center that handles customers’ information of various automobile brands. The stolen database contains over 500,000 customer records dated between 2016 and 2018, affecting U.K. owners of other car manufacturers, including Honda, Mercedes, SEAT, and Hyundai in the U.K.

The exposed BMW owners’ information included sensitive information such as surnames, email iDs, vehicle registration numbers, residential address, dealer names, car registration information, names of dealerships. KELA also discovered multiple databases exposed by KelvinSecurity, including  data related to the U.S. government contractors and the Russian military weapons development. The hacker group also exposed over 28 databases on various darknet forums for free, affecting organizations in Iran, Australia, Mexico, U.S., Sweden, Indonesia, and France.

OceanLotus Targets BMW

Earlier, a notorious APT hacker group “OceanLotus” compromised the network systems of BMW and installed a hacking tool known as “Cobalt Strike” to spy and control its systems. According to a research report from Bayerischer Rundfunk, the attack was traced back to state-sponsored hackers from Vietnam. Security analysts from BMW stated that they identified the hacker’s penetration into their company’s network system.

BMW  took down the compromised computers and blocked the path that was used by hackers to penetrate the network. To get access to other computers, hackers created a fake website that gave the impression of belonging to the BMW branch in Thailand, as they can monitor networks and find out which folders and files that users logged in. The report also claimed the hackers behind the BMW attack targeted the South Korean automotive manufacturer Hyundai.

 

Are You Remotely Secure?

remote work

COVID-19 pandemic has pushed the concept of remote working beyond any preconceived growth expectations. It doesn’t appear a short-term situation as many organizations and their employees benefit from this new business structure. Rightfully so, IT and security teams should be “virtual” fist-bumping to celebrate rapidly transitioning operations and, in most cases, avoiding any extensive downtime or security breach. After a momentary breath, businesses must now look to long term operational sustainability and security. Organizations must soon revisit and reassess the security gaps or corners cut in haste to deliver services so as not to leave convenient doors open for attacker exploitation. We’ve seen before that attackers seek to capitalize on times of disruption like these both for quick wins and establishing a foothold for a more sophisticated attack.

By Carolyn Crandall, Chief Deception Officer and CMO at Attivo Networks

An Uptick in Cyberattack Frequency

According to the FBI, cybercrime has increased 300% since the start of the COVID-19 pandemic. If there was ever a time for attackers to open their crime toolboxes, it is now. We also may not have seen the worst of things. Dwell time – the time to detect attackers within the network – currently averages months. With this in mind, advanced attackers may not have come forward yet to reveal their inside presence or to present their demands. During this next phase of supporting remote workers, organizations must have robust detection capabilities that can not only alert security teams promptly when an adversary evades prevention defenses but also deliver company-centric threat intelligence on attacker methods and targets.

Altered Employee Behavior = Unpredictable Attack Surface

With an increase in the number of remote workers and changing behavioral patterns, traditional security controls can’t reliably protect an organization’s network infrastructure or remote employees. Many organizations dramatically increased their company bandwidth to support remote operations and split-tunneled VPNs to separate work from personal traffic. Unfortunately, this created new risks as security tools like network firewalls, Intrusion Prevention Systems, web gateways, and others don’t operate well for such VPNs. With split- tunneling, employee traffic doesn’t always traverse the company network, and under these circumstances lacks the same protections as onsite employees. Security teams also see increased risks as they may not gain access to monitoring and incident response systems without creating gaps in perimeter firewalls. Additionally, detection technologies that rely on network behavior anomalies will be inaccurate, as employees connect from different networks and systems, and change baseline behaviors.

Organizations must also prepare for the risks of distracted employees working remotely on personal or unpatched home computers, which may use less-secure emails. System hygiene may also be harder to monitor as employees may not stay updated on patching or may load unauthorized software, creating risk. Many security teams fear that attackers are hiding silently within these systems, awaiting the day they connect directly to the company network.

System compromises are virtually inevitable, and organizations must prepare with a safety net that detects when systems connect, and the attacker attempts to swim upstream to find their target. Many organizations have learned first-hand the value of cyber deception, which provides efficient and non-disruptive “eyes inside the network” visibility to attackers across all attack surfaces and threat vectors. The concept is to create a detection net over the endpoint and a deception fabric throughout the network to discover attackers regardless of how they attack. An effective way to look at this is through the MITRE ATT&CK framework. There are 12 consolidated steps an attacker will take, from initial compromise, lateral movement, privilege escalation, to data exfiltration. Deception works to derail the attacker in 11 out of 12 of these steps. However, many find the most value in detecting lateral movement activity and closing gaps that Endpoint Detection and Response (EDR) solutions don’t cover. Network decoys project throughout along with endpoint credentials, mapped shares, deception data, or applications that breadcrumb attackers to an engagement server, away from production assets, and alert on their presence. Notably, using the MITRE ATT&CK testing methodology, Attivo demonstrated a 42% improvement in detection rates over EDR solutions alone.

Insider Threats, Former Employees, and Third Parties

With the advent of remote working, data may also be leaving the organization in ways not accessed or stored before. Additionally, there have also been unprecedented levels of employee turnover, which challenges security teams to keep up with employee or supplier access rights. It can also make using traditional data loss prevention tools less effective as behaviors, systems, and locations of access have changed.

Deception presents a unique way to detect exposed credentials as well as policy violations associated with the unauthorized use of employee, cloud, or VPN credentials or prohibited attempts to access systems. For example, since a deception asset has no employee production value, any attempt to scan, access, or exploit a decoy automatically triggers an alert, as will using legitimate credentials on a decoy application. Advanced deception can also go so far as to hide and deny access to threat actors attempting to enumerate AD, access files, folders, network or cloud mapped drives, or that may try to fingerprint servers. Collectively, these tools arm the defender in ways that they simply can’t with other security controls.

Implement Tools That Enable SOCs to Do More with Less and Reduce Alert Fatigue

Simply put, we know that the new volume of security alerts are taxing security departments that are not used to the load of so many employees working remotely. Traditional prevention devices and behavior-based detection tools may not accurately do the job at the required scale.

Defenders need a new tool for their toolbox that covers the gaps, delivers actionable alerts, and augments existing controls, not more of the same. Here are some of the things that Attivo Network does specifically to secure VPN access to corporate networks and ensure the delivery of prompt and accurate alerts.

  • Provides deceptive credentials for VPN accounts on remote worker endpoints and accurately notifies of attempted
  • Projects decoys into the VPN subnets for internal connections. This method provides an extremely effective tool for detecting and alerting unauthorized scanning behavior. It is also essential to consider that most VPN deployments are in bridged mode, resulting in all connections existing on the same broadcast domain. Anyone who gains unauthorized access via VPN can take advantage of this while running network scans, ping sweeps, etc. because it would be difficult for security teams to identify the activity
  • Protects Active Directory (AD) by alerting on any attacker seeking to enumerate AD. The solution goes beyond merely alerting and responds to the unauthorized query with fake data that leads the adversary into a decoy that records telemetry
  • Delivers company-centric threat intelligence on indicators of compromise (IOC) and tactics, techniques, and procedures (TTPs) and can automate isolation, blocking, and threat hunting through native integrations with existing security infrastructure.

Conclusion

While it is impossible to prevent adversaries from attacking a company, using deception technologies will provide early and accurate detection of threats, visibility to attacker lateral movement, and the opportunity to pre-emptively derail attackers from establishing a foothold or conducting their exploit. Now more than ever, security teams need to know what is lurking in their networks, and as such, need the proper tools in place to do so accurately.

About the Author

Carolyn CrandallCarolyn Crandall holds the roles of Chief Deception Officer and CMO at Attivo Networks.  She is a high-impact technology executive with over 30 years of experience in building new markets and successful enterprise infrastructure companies. She has held leadership positions at Cisco, Juniper Networks, Nimble Storage, Riverbed, and Seagate. Crandall has received many industry recognitions including Top 25 Women in Cybersecurity 2019 by Cyber Defense Magazine, Reboot Leadership Honoree (CIO/C-Suite) 2018 by SC Media, Marketing Hall of Femme Honoree 2018 by DMN, Business Woman of the Year 2018 by CEO Today Magazine, Cyber Security Marketer of the Year 2020 by CyberDojo (RSA), and for 9 years a Power Woman by Everything Channel (CRN).

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

How India’s Federal Bank Blocks Debit Card Fraud in Real-Time

Federal Bank Blocks Debit Card Fraud

The Federal Bank is one of India’s largest private sector commercial banks that serves a customer base of more than 10 million. The Bank does over 600,000 debit card transactions every day. It has more than 2,800 touchpoints (over 1,200 branches and over 1,600 ATMs), spread across the country. The bank is a leading technology adopter and was one of the first Indian banks to computerize all its branches. With an increase in fraudulent transactions in the industry, Federal Bank was proactively looking for a counter-fraud solution for both its cardholders and merchants, with real-time and near real-time facilities and mission-critical features that are easy to deploy, responsive and reduce the financial impacts of fraud.

The fraud landscape in India is evolving at a very rapid rate, with fraudsters finding new and innovative ways to game the system and trick banking officials and customers. Customer awareness is also low.

Shalini Warrier, Executive Director, Federal Bank
Shalini Warrier, Executive Director, Federal Bank

In an email interview with CISO MAG,  Shalini Warrier, Executive Director, Federal Bank said,We have noticed that a lot of frauds are of the vishing type, where customers are tricked by fraudsters and end up sharing their secured credentials to fraudsters over the phone. The fraudsters are becoming increasingly sophisticated in their methodologies, and sometimes, even educated individuals fall prey to their attacks.”

According to RBI data (India’s banking regulator), from October to December 2019, debit card fraud alone reached 11,058 cases involving INR 94.5 crore (approximately US$12.4 million). While traditional rules-only fraud detection systems are adequate at detecting known threats, they are not as effective or efficient at uncovering new criminal fraud strategies or zero-day attacks, putting banks and their customers at risk.

“Our core challenge was the absence of a robust online real-time capability to prevent frauds on debit card transactions,” said Warrier. “We had the capability for post facto analysis, based on which we could make changes for the future. However, that is akin to closing the stable door after the horse has bolted! Further, our overall debit card spends were increasing courtesy the changes we made on the business front. Hence, in order to ensure our risk mitigation strategies kept pace with changes in the environment and the demands of the business, we really needed an effective online real-time monitoring system.”

To address the evolving threat of fraud and offer additional security for digital transactions, Federal Bank sought to deploy a rules-based solution with real-time monitoring for deterring, detecting and blocking fraud.

“The first criteria for us was the ability to handle volumes in a robust, resilient, consistent, and stable manner.  Further, we were looking for a system that could provide a high level of flexibility and agility so that changes in rules could be made dynamically, as and when required.  Of course, with the increasing use of online digital channels, we needed to ensure that the solution had an ability to interact, seamlessly, with online channels,” said Warrier.

Federal Bank opted for ACI Worldwide’s customized fraud and risk management solution at two action levels: cards and merchants. After deploying UP Payments Risk Management for real-time monitoring of card transactions, the bank saw a considerable drop in fraudulent transactions, including vishing fraud. In addition to alerting customers of risks, the solution also includes automated alerts that have helped the bank recognize and decline potential fraudulent transactions on more than 2,700 cards over a recent six-month period.

“Our Debit Card Switch is an ACI product, and we have worked effectively with ACI over the last 10 – 15 years. After taking all the above criteria into account and evaluating various solutions, we concluded that ACI’s PRM (Proactive Risk Manager) would be the best suited for our requirement.  It also enabled us to ensure seamless integration without Debit Card Switch,” added Warrier.

Through ACI’s solution, the bank can enhance fraud detection capabilities with insights into real-time status of card transactions based on pre-defined parameters, empowering the bank to provide better customer experience and security.

Warrier informs that the initial solution was deployed in March, 2015. However, several enhancements and upgrades were made in the last few years. The most recent upgrade was done in December 2019.

“Our objective was to equip Federal Bank with real-time reactivity and adaptation to emerging fraud trends, enabling faster decision-making,” said Kaushik Roy, Vice President and Country Leader – South Asia, ACI Worldwide.

Business Benefits

Warrier informs us that the solution gives the business the ability to confidently market debit card products, knowing that there is an effective risk management tool that can ensure minimal fraud.  The PRM solution enables businesses to grow with full assurance of risk mitigation. She acknowledges that the bank has realized a return on investment.

Going forward, Federal Bank wants to make continual investments in upgrades and enhancements. Its plans include:

  • Usage of past data in identifying suspicious transactions with the help of an analytical engine using AI-ML.
  • Real-time step-up authentication mechanism for highly suspicious transactions.
  • Ability to make use of customer profile data and customer device profile in transaction authorization.

ACI Worldwide is a Universal Payments (UP) company that powers electronic payments for more than 6,000 organizations around the world. More than 1,000 of the largest financial institutions and intermediaries, as well as thousands of global merchants, rely on ACI to execute $14 trillion each day in payments and securities. In addition, myriad organizations utilize its electronic bill presentment and payment services.

———————-

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the Bank or the Solution provider. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Medfin Australia Reports Targeted Cyberattack

Remote Access Scams

Medfin Australia, a subsidiary of National Australia Bank (NAB), confirmed that they were targeted with a sophisticated cyberattack that was spotted on June 14, 2020. Although the attack could have been severe, however, no loss of customer data has been noted to date.

While acknowledging the cyberattack, Medfin’s CEO Paul Freeman said that the cyberattack by a malicious actor was identified and due to the proactive measures it was stopped instantaneously without affecting the business operations.

Medfin’s wide network, which is spread across various cities in the country including Sydney, Canberra, Melbourne, Brisbane, Adelaide, and Perth, along with its services to the healthcare industry and medical practitioners — makes it a vital supply chain in the nation’s critical infrastructure. Thus, the possibility of a state actor’s involvement in this cyberattack attempt cannot be ruled out.

The internal team of Medfin terminated this cyberattack and carried out a detailed investigation with the help of cybersecurity experts from NAB and the Australian Cyber Security Centre (ACSC) to know the extent of damages. On the question of why Medfin took so long to come out in open about the cyberattack, Mr. Freeman added, “We were completing a full and thorough investigation. We wanted to be sure that customer information is not being affected.” Medfin also confirmed that the cyberattack was limited to its own network and did not spread laterally into a third-party network.

Australia Under Constant Threat

Earlier, the Australian Prime Minister Scott Morrison briefed the nation about sustained cyberattacks carried out by a sophisticated state-sponsored actor. To fortify the cyberspace, the ACSC has been ever since taking countermeasures and giving advisories to businesses around the country to defend themselves from cyberattacks. In continuation, Australia has now decided to add yet another defensive shield in the cyberspace – the AUSHIELD.

Read more about the AUSHIELD platform here!

DDoS Attacks and Credential Abuse Doubling Year-on-Year: Akamai

DDoS Attacks

The key message that came through at the Akamai Edge Live APAC Virtual Summit 2020 on  July 2, 2020, was that the nature of cyberattacks on organizations was growing in scale and sophistication. And the only way to contain DDoS and other attacks and mitigate the impact was to opt for automation, sophisticated monitoring tools, and expertise provided by security operations centers (SOCs) and managed service providers (MSPs).

–Brian Pereira, Principal Editor, CISO MAG

Dr-Tom-Leighton_CEO-and-Co-Founider_Akama
Dr. Tom Leighton, CEO and Co-Founder, Akamai

Delivering the keynote, Dr. Tom Leighton, CEO and Co-Founder, Akamai, spoke about Internet security and some of the trends observed in the past few months.  Dr. Leighton said, “There is a lot of business disruption out there… companies are dealing with the new reality. There are workforces working remotely, people are unable to travel, and this is creating a lot of security concerns. The trends that we are seeing on the Internet have been pretty much stable over the past few months. Traffic continues to be at a very high level and the attack rates continue to be very high. The bad actors are not disrupted by having to work remotely because they have been doing it for a long time, and they are trying to take advantage of the new situation, where the security levels could be lower with remote workforces.”

Dr. Leighton pointed out that there were a lot of DDoS attacks happening and companies in all industries were getting attacked. In recent weeks, there were targeted DDoS attacks on gaming companies, financial services, and internet and telecom firms.

He gave an example of a global DDoS attack against an internet hosting provider on June 4. The attack was huge and was directing 385 million packets per second at the server or 1.44 Tbps (Terabits per second) over a two hour stretch; there were 9 different attack vectors. Dr. Leighton said the bulk of the attack was “automatically and instantly mitigated” by Akamai Prolexic Services, which is a DDoS mitigation service for Terabit scale attacks. The remainder was mitigated by Akamai’s SOCC (global Security Operations Command Center).

“Our customer was able to maintain operations through a large DDoS attack,” said Dr. Leighton. The point he was trying to make was, the attacks are getting more sophisticated and targeted, and no single organization can block these on its own. DDoS attacks can be contained only with SOCC expertise and managed services, with automated capabilities.

DDoS attacks by vertical
Source: Akamai

Dr. Leighton also disclosed an on-going attack against a major gaming company. “There are 30 billion bot requests against this website and 6 billion malicious login attempts. These anomalies were identified and blocked by the Akamai Bot Manager and Akamai SOCC,” informed Dr. Leighton.

He also noted that web application attacks have grown 42% year-on-year. Web apps and their APIs continue to be exploited. Commerce, high-tech and financial services are the most targeted sectors for these types of attacks.

Credential Abuse doubles
Source: Akamai

“Credential abuse attempts have nearly doubled compared to last year.  Credential abuse attacks are the toughest and criminals are trying to take over accounts to steal merchandise, personal information and money,” said Dr. Leighton.

The other type of attacks that are increasing are malware injected by third-party scripts on retail websites. This is called Formjacking and the MageCart malware is the most infamous example.

“Third and fourth parties add their scripts to a shopping website, so most of what comes to a customer’s browser isn’t authored by the shopping website,” said Dr. Leighton. “61% of desktop content and 68% of mobile content comes from third parties.”

Compromised third-party scripts and domains can result in data breaches wherein customer credentials and card details are stolen.

John Summers, SVP and CTO, Akamai said there are typically 20 – 50 Javascripts executing on customers’ browsers when a web page downloads at their end. And each Javascript calls additional fourth and fifth-party scripts to enhance the customer experience.

Akamai offers a tool for anyone to test their page integrity at akamai.com/pageintegrity. With this tool one can determine from where their third-party and fourth-party content is coming from.

1 in 5 Risky Links Contain Hidden Malware: Report

BotenaGo, malware over encrypted connections

Opening or downloading malicious links or attachments could result in severe security issues. With employees working remotely across the globe,  corporate data security has become a challenge for organizations. A research from security firm NetMotion revealed that cyberthreats soared as remote workers visited risky websites outside of corporate networks. The analysis found that remote employees clicked on 76,440 links that redirected them to malicious websites.

NetMotion highlighted that they collected a sample of network traffic data to find users who accessed blocked URLs or risky content. All these sites were visited on office laptops while working from home via home or public Wi-Fi or a data network.

Image Source: NetMotion

“Several primary risk categories, which were identified using machine learning and based on the reputation scores of over 750 million known domains, include more than 4 billion IP addresses and in excess of 32 billion URLs. The assumption is that a large number of employees connected to protected internal (non-public) networks would have been prevented from accessing this risky content,” the research stated.

Other notable findings include:

  • Employees, on average, encounter 8.5 risky URLs per day, or 59 per week.
  • Remote workers also access around 31 malware sites per month, and 10 phishing domains, that equates to one malware site every day, and one phishing domain every 3 days.
  • The most common types of high-risk URLs encountered, in order of prevalence, were botnets, malware sites, spam and adware, and phishing and fraud sites.
  • Over a quarter of the high-risk URLs visited by employees were related to botnets.
  • Almost 1 in 5 risky links led to sites containing spam, adware, or malware.
  • Phishing and fraud, which garner an outsized proportion of news, account for only 4% of the URLs visited.
  • The other category, representing 51% of the data in the chart above, is made up of ‘low-severity’ risky content, such as websites that use proxies, translations and other methods that circumvent URL filtering or monitoring.

“Remote workers are frequently accessing risky content that would normally be blocked by firewalls and other security tools that monitor internal network traffic. Naturally, this poses an enormous threat to the enterprise. Added to this, many organizations have no visibility into the activity taking place on external networks, let alone any means to prevent it. With such a rapid shift to remote work, enterprise security teams have been left flat-footed, unable to adequately protect users in the face of increasingly sophisticated cyberattacks,” the research added.

The NetMotion analysis is based on the aggregated data sourced from anonymized network traffic gathered between May 30, 2020, to June 24, 2020.

 

CISA Issues Advisory on Mitigating Risks Originating from Tor

Tor Network

The Cybersecurity and Infrastructure Security Agency (CISA) in the U.S. issued security guidelines on how to  mitigate cyber risks  originating from anonymity networks like Tor. In collaboration with the FBI, CISA released an advisory explaining how attackers use Tor’s network infrastructure.

Tor, also known as the Onion Router, is a software that provides user anonymity by automatically encrypting and rerouting web requests through multiple layers of Tor nodes. Threat actors often use Tor services to hide their identity and IP locations when performing malicious activities.

“The risk of being the target of malicious activity routed through Tor is unique to each organization. An organization should determine its individual risk by assessing the likelihood that a threat actor will target its systems or data and the probability of the threat actor’s success given current mitigations and controls. This assessment should consider legitimate reasons that non-malicious users may prefer to, or need to, use Tor for accessing the network. Organizations should evaluate their mitigation decisions against threats to their organization from advanced persistent threats (APTs), moderately sophisticated attackers, and low-skilled individual hackers, all of whom have leveraged Tor to carry out reconnaissance and attacks in the past,” the advisory said.

Image Source: US-Cert.Gov

Security Guidelines

CISA recommended certain protective measures for organizations to reduce the risk posed by threat actors who use Tor. These include:

  • Block all web traffic to and from public Tor entry and exit nodes. (It does not completely eliminate the threat of malicious actors using Tor for anonymity, as additional Tor network access points, or bridges, are not all listed publicly.)
  • Tailor monitoring, analysis, and blocking of web traffic to and from public Tor entry and exit nodes: orgs that do not wish to block legitimate traffic to/from Tor entry/exit nodes should consider adopting practices that allow for network monitoring and traffic analysis for traffic from those nodes, and then consider appropriate blocking. This approach can be resource-intensive but will allow greater flexibility and adaptation of defensive.
  • Block all Tor traffic to some resources, allow and monitor for others. This may require continuous re-evaluation as an entity considers its own risk tolerance associated with different applications. The level of effort to implement this approach is high.

Productivity and Stress Concern Risk Managers While Working from Home

Productivity and Stress Concern Risk Managers While Working from Home

A survey from the Global Association of Risk Professionals (GARP) revealed that risk managers across the world effectively handled the sudden transition to work-from-home amid COVID-19. According to the survey, 87% of risk professionals globally are working remotely compared with only 2% before COVID-19. It is found that 89% and 82% of respondents, respectively, admitted risk and incident reporting to be functioning properly than prior to the pandemic.

However, a few respondents said challenges related to key data and systems (5%), cybersecurity issues (5%), business operations (4%), and firm communications (4%)  worsened  due to remote work. While 60% of respondents admitted that they are working more than before COVID-19, 44% said they witnessed a drop-off in productivity. Also, 46% reported feeling more stressed out by their work than before, and 71% said their work hours have become irregular.

“Despite company-wide adaptations and successes in working from home, risk professionals reported experiencing a noticeable reduction in work-life balance. Respondents said they are working more, but at the same time, feel less productive and engaged,” the report stated.

Other key findings from the survey include:

  • Risk professionals in Asia appear to be experiencing the most challenges — 56% reported lower productivity, compared with only 36% and 42% for North America and Europe — though it may be too soon to tell whether successes or failures can be evaluated geographically.
  • Risk managers in Asia were noticeably less positive about their work-from-home experience; 30% said cybersecurity issues worsened and 28% said access to systems deteriorated.
  • Risk professionals at banks were more likely to be working longer (60%), more irregular hours (80%) and be experiencing more work-related stress (51%) than respondents at asset managers and consulting companies.
  • Companies with 100 or fewer employees faced the largest increase in risk across three key areas: market risk, cybersecurity risk, and credit and counterparty risk.
  • Nearly all financial institutions, regardless of size, type or location, have experienced elevated levels of risk as a result of the COVID-19 pandemic. On a scale from 1-9, with 1 meaning decreased sharply, and 9 meaning increased sharply, risk managers rated market risk, credit and counterparty risk, and liquidity risk at a striking 7 or higher, with banks reporting the highest overall increases in risk levels since the start of the pandemic.

Chris Donohue, Managing Director of GARP, said, “In addition to showcasing the resilience of firms and professionals, the survey results indicate that risk management has functioned well on a remote basis. However, there are still necessary improvements to be made on the work-life front. Professionals cannot be primed and ready to tackle risks that may arise if productivity, engagement, and stress-levels are suffering.”

The findings are based on the responses from 250 certified risk managers to understand the effect of the COVID-19 pandemic on the remote work culture on both companies and risk professionals.

 

Cloud-Ready Shared Responsibility TPRM Tips for CISOs

Misconfigured Cloud Storage Services Led to Over 200 Breaches in Past Two Years

Third-Party Risk Management (TPRM), commonly referred to as vendor or supply chain risk management, is not a new concept. It was originally founded with a more traditional on-premises IT mindset and was centered on an expectation of always having a significant level of visibility into and control of an organization’s most prized cyber assets; this meant companies asked their most important business partners to share their internal security posture with them.

By Becky Swain, Director of Standards, HITRUST

Then came cloud computing, a catalyst that fundamentally changed how companies do business and consume technology. The cloud, as the epicenter of IT, led to the need for the TPRM model to adapt, necessitating a fundamental change in the mindset to address the emerging risks posed by off-premises cloud-hosted technology services.

Most of the time, it is the obvious 1:1 connection that most organizations consider. They forget the fact that, even though the supply chain by name can be viewed as a “chain,” the growth of technology and the cloud, in particular have turned this chain into more of a mesh. And, as the saying goes, a chain is only as strong as its weakest link.

The question is, where is that weak link in the mesh? Maybe, more importantly, who owns security and risk management for that link — or links? A change in mindset here involves two primary transformations:

(a) A more externally facing view of risk and policy enforcement.

(b) A realization that in the cloud, controls are shared with the use of common technology platforms.

As a result, this realization has forced a new “we” rather than an “us vs. them” dialogue with cloud service providers.

At first, these conversations were uncomfortable, if non-existent. Therefore, this realization and related mind shift did not happen overnight. It took two key changes in industry trends to start the TPRM-in-the-cloud journey that finally got us to where we are today:

The democratization and consumerism of IT: With the birth of the cloud — and its ease of accessibility and consumption — emerged a new “shadow-IT” developer community, which was no longer bogged down by the traditional, enterprise IT, process-heavy red tape. With the shadow IT approach, developers bypassed all the existing enterprise security controls baked into those processes.

In turn, this renewed sense of empowerment enabled developers to accelerate their time-to-market. They could also deliver new, innovative solutions to keep pace with an emerging competitive landscape of technology service providers that demanded increased shareholder value and revenue growth.

From the TPRM perspective, this became problematic when customers sought answers to their supplier risk due-diligence questionnaires. But no one within the enterprise IT function could respond, as had been the prior modus operandi.

This forced CISOs — along with their CIO partners — to redefine their cross-functional engagement model to strengthen their partnerships with the company’s lines of business and associated product teams. They did this in hopes of building a similar partnership to the one they had previously matured with their enterprise IT counterparts. Further, it accompanied the new addition to the company’s set of most prized cyber assets: customer data.

With this new supply chain risk perspective on customer data protection — along with the expansion of global privacy regulation — there emerged a new set of security and privacy industry standards and unified compliance control frameworks. These frameworks were more suitable for addressing the cloud security risks that CISOs would need to adopt and integrate into their information security and governance, risk, and compliance (GRC) programs. The frameworks also helped CISOs safeguard and appropriately manage both their own supply chain risks and the supply chains of their customers.

Technology innovation and cloud supply chain ecosystem complexities: With the promise of the cloud came the next big innovation and a new term added to our tech-savvy vernacular: “Big Data.” Since then, there have been significant advancements in the types of technology solutions commonly used by consumers and businesses today—with further growth expected to continue in the future — e.g., artificial intelligence (AI), robotics, and the Internet-of-Things (IoT), to name a few.

These advancements have resulted in the creation of a vast and complex ecosystem of cloud service providers, solution partners, and consumers. They all share a common cloud platform, characterized by a comingled and integrated set of varying types of technologies, which are primarily hosted off-premises — e.g., web and mobile applications that are hosted on highly-mutable virtual infrastructures.

From the TPRM perspective, the CISO’s quality of engagement with their cloud service providers to appropriately manage supply chain risk is paramount. In addition to gaining transparency, visibility, and auditability to understand third- and fourth-party risk factors, CISOs will need to transform their existing GRC programs to support continuous compliance monitoring of the cloud services they consume. This is obviously counter to their more traditional IT enterprise approach to SRCM, with its much slower rate of change that warrants a much longer supplier risk assessment cycle of cadence — e.g., on an annual or biennial basis.

The Journey is Just Beginning

Traditionally, TPRM processes have been disengaged, with one-way forms of communication by way of questionnaires. With the continued optimization of the cloud, the risk management landscape has evolved; however, we have not seen TPRM evolve at the same rate.

The time for dynamic, cooperative engagement between cloud service providers and their tenants is now upon us and grows more prevalent every day.

The “new normal” of managing risk in the cloud grants CISOs the opportunity to embrace being an advocate — not only for their own corporate innovation, but also the customers they serve, thus leading to new revenue potential.

The journey to TPRM in the cloud is just beginning. The cloud service provider you choose to partner with will go a long way in determining just how smooth or bumpy that road will be. The HITRUST Shared Responsibility Program simplifies and streamlines the process for determining shared control roles and responsibilities between organizations and third-party service providers for greater clarity on the ownership and operation of security controls.

Key Questions to Ask When Vetting Cloud Service Providers

As your business makes the transition to a cloud-ready TPRM program, the following questions can assist a CISO during the early stages of the procurement process in vetting cloud service providers and achieving an appropriate level of quality engagement:

  1. Does the cloud service provider have an adequate understanding and appreciation for your concerns pertaining to the required information security and privacy measures to protect the data and cyber assets you have entrusted to them? Similarly, does the cloud service provider acknowledge your compliance obligations that they must inherit?
  2. Can the cloud service provider readily articulate which information security and privacy standards and/or control frameworks they comply with, align to, and benchmark against?
  3. Does the cloud service provider demonstrate a higher level of assurance with independent third-party validation or attestation for the applicable standards and compliance frameworks? Are you able to inspect the validation to ensure any potential supply chain risk gaps are addressed?
  4. Does the cloud service provider go into further detail with respect to scope and depth, specifying how each of the control requirements for the applicable standards and compliance frameworks are implemented?
  5. Does the cloud service provider explain which control requirements are common and therefore shared with their customers based on which cloud services have been purchased? Can they explain why the responsibility is shared for these controls?
  6. Does the cloud service provider allow customers to “inherit” the common — or shared — controls from the applicable standards and compliance frameworks to prevent supply chain risk gaps while alleviating waste in duplicative assessments and audits?

It is also important to check the cloud service provider’s contractual agreements to ensure the level and quality of the engagement persists post-procurement. You also want to make sure they actively involve customers in their security and privacy incident planning, notification, and response processes. Another key attribute to look for is a service provider that ensures customers maintain awareness of any changes that may impact the cloud supplier’s risk posture and thus warrant a risk re-assessment.

There is a lot that should be available to you as you embark on this path — are you getting the visibility necessary to effectively and efficiently evaluate the security posture of the cloud services you are using?

Learn more at: https://hitrustalliance.net/hitrust-shared-responsibility-program/

About the Author

Becky SwainBecky Swain is the Director of Standards and Shared Responsibility Program Lead, HITRUST. Her expertise encompasses cybersecurity, privacy, supply chain assurance, and GRC frameworks, in addition to IT audit and compliance. Swain has been a contributor for cloud standards as co-founder and author of the Cloud Security Alliance Cloud Controls Matrix (CSA CCM) and project co-editor for ISO/IEC 27036- 1:2014.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

72% of Remote Workforce Gained Cybersecurity Awareness in Lockdown: Report

CISO, Cybersecurity

A survey from cybersecurity solutions provider Trend Micro revealed that nearly 72% of remote workers are more conscious about their organization’s cybersecurity and data handling policies since the lockdown began.

The survey “Head in the Clouds” stated that 85% of respondents admitted that they take instructions from their IT team seriously, and 81% agreed that cybersecurity within their organization is their responsibility. Nearly 64% of respondents stated that using non-work applications on a corporate device is a security risk.

The survey also highlighted that certain employees are still neglecting security practices because of limited understanding or resource constraints. 56% of employees admitted to using a non-work application on a corporate device and 66% of them have uploaded corporate data to that application. 80% of respondents confess to using their work laptop for personal use, while only 36% of them fully restrict the sites they visit. 39% of respondents stated they often access corporate data from a personal device, almost breaking corporate security policy.

The survey findings are based on the responses from 13,200 remote workers across 27 countries on their attitudes towards corporate cybersecurity and IT policies.

Bharat Mistry, Principal Security Strategist at Trend Micro, said, “In today’s interconnected world, unashamedly ignoring cybersecurity guidance is no longer a viable option for employees. It’s encouraging to see that so many take the advice from their corporate IT team seriously. Having said that, there are individuals who are either blissfully ignorant or worse still, who think cybersecurity is not applicable to them, and will regularly flouter the rules. Hence, having a one size fits all security awareness program is a non-starter as diligent employees often end up being penalized. A tailored training program designed to cater to employees may be more effective.”

Remote Work Threatens Businesses

A similar study from HiveIO revealed that nearly 85% of organizations anticipate a larger remote workforce will threaten operations because of new risks. “The IT departments are working at a deficit in their ability to support and maintain business continuity while optimizing IT support,” the report said. The study stated that several organizations are unable to introduce new security solutions designed to improve the efficiency of work-from-home employees. Around 70% of respondents admitted that they have suffered increased costs due to the ongoing pandemic. And 25% of respondents reported shrinking staff support and another 18% fear additional staff reductions.