Home Blog Page 199

The State vs. Julian Assange: An Old Case with New Allegations

Julian Assange, Julian Assange indictment

The U.S. Department of Justice (DoJ) has charged the founder of WikiLeaks, Julian Assange, with a fresh indictment superseding the previous one on counts of planned conspiracy in compromising classified military and government information. The new indictment does not add additional counts to the previous 18-count indictment against Assange that was filed in May 2019. However, the DoJ says, “it does broaden the overall scope of conspiracy.”

In May last year,  the DoJ charged Assange under the a 102-year-old U.S. Espionage Act, on 18 different counts of espionage against the country and sharing of classified information on a public platform in the year 2010. The earlier charges, however, only concentrated on the unlawful outcome and the data that was leaked but no one thought about how and why it was leaked. The DoJ seems to now cover that base as well in the new allegations.

As per the DoJ, in August 2009, Assange attended the “Hacking at Random” conference held in the Netherlands. It was here that he initially instigated hackers to search, steal and send classified information to WikiLeaks. He even conducted a separate session for those interested to work with WikiLeaks and explained how he exploited “a small vulnerability” in the document distribution system of the  U.S. Congress to gain confidential data. He used this technique in many other conferences worldwide to woo and recruit potential hackers for working with WikiLeaks.

It is not certain whether Chelsea Manning, who was then working in the U.S. Department of Defense as an intelligence analyst, was also influenced or simply fell prey to these tactics, but it was proved that he did indeed leak the confidential files to Assange which he had access to with respect to his duties. The DoJ also confirmed that Assange assisted Manning to break a hashed password on one of the Department of Defense computers, which again is a clear case of conspiring against the nation’s security.

The indictment also accused Assange of intruding a government computer system of a NATO country in 2010, and publishing of emails from a data breach committed against a U.S. intelligence consulting company by a hacker affiliated with the “Anonymous” and “LulzSec” groups.

Assange is currently in a U.K. prison post his arrest in London in April 2019. The U.S. DoJ is trying hard to extradite him back to the U.S. where if convicted for all 18-counts, he could face a maximum sentence of 175 years of imprisonment.

U.K.’s Privacy Watchdog Receives a Million Phishing Emails Reports

xss vulnerability in UPS, Phishing Attack, spear phishing, phishing mails

The U.K’s privacy watchdog, National Cyber Security Centre (NCSC), received one million phishing email reports in two months, with an average of 16,500 email reports a day. In addition, the NCSC reported that it blocked around 10,000 malicious URLs linked to 3,485 individual sites, with more than 50% of these phishing scams related to cryptocurrency schemes.

In April 2020, the NCSC urged people to report suspicious emails to Suspicious Email Reporting Service (SERS) in order to prevent COVID-19 related phishing attacks during the ongoing pandemic. The agency asked people to forward any suspicious emails or links to [email protected]. The new reporting initiative is part of the government’s “Cyber Aware” campaign, which was launched to advise people on protecting passwords, devices, and social media accounts.

The NCSC also claimed that it has taken down a large number of Coronavirus-themed online scams intended to steal personal information, fake online shops selling fraudulent Coronavirus products, and malware distribution sites.

Digital Secretary Oliver Dowden, said, “I urge everyone to continue reporting suspicious emails and follow our Cyber Aware campaign top tips for staying secure online alongside our world leading National Cyber Security Centre advice.”

5,000 Phishing Reports on Day One

Earlier, NCSC received over 5,000  suspicious email reports and  took down more than 80 malicious campaigns on the first day of the SERS launch. The NCSC’s SERS campaign has been co-developed with the City of London Police.  SERS acts as a reporting system for U.K.’s public but more so, provides the U.K. police live time analysis and reports, and helps identify new patterns of online scams and frauds.

 

Cryptocurrency Heist: CryptoCore Hacking Group Stole $200 Mn Since 2018

Coinbase, QNAP Devices

A new report from cybersecurity firm ClearSky revealed that a hacking group “CryptoCore” is targeting cryptocurrency exchanges via spear-phishing campaigns. CryptoCore, also known as Dangerous Password and Leery Turtle,  stole cryptocurrency worth $200 million in two years. It is found that  the hacking group was targeting companies in the U.S. and Japan since 2018.

“We have been tracking CryptoCore group campaigns for almost two years, with no conclusive understanding of the operators’ origin; however, we assess with medium level of certainty that the threat actor has links to the East European region, Ukraine, Russia or Romania in particular. The key goal of CryptoCore’s heists is to gain access to cryptocurrency exchanges’ wallets, be it general corporate wallets or wallets belonging to the exchange’s employees. For this kind of operation, the group begins with an extensive reconnaissance phase against the company, its executives, officers and IT personnel,” the ClearSky reported.

Spear-Phishing Attacks

ClearSky stated that CryptoCore initiates a reconnaissance phase to identify the email accounts of the cryptocurrency exchange’s employees and security executives before conducting a spear phishing attack. These attacks are performed by using fake domains impersonating affiliated organizations, sending emails that impersonate employees, and spreading malicious links and documents via emails.

Cryptocurrency Heist: CryptoCore Hacking Group Stole $200 Mn Since 2018
Image Source: ClearSky

“After gaining initial foothold, the group’s primary objective is obtaining access to the victim’s password manager account. This is where the keys of crypto-wallets and other valuable assets – which will come handy in lateral movement stages are stored. The group will remain undetected and maintain persistence until the multi-factor authentication of the exchange wallets will be removed, and then act immediately and responsively,” ClearSky added.

Other Notable Findings on CryptoCore Group include:

  • CryptoCore group maintains the same general course of action regarding the infection and post-exploitation stages. While the bait document type, the services the phishing sites mimic, the exact tooling and others may vary, an overarching strategy remains the same.
  • The group also appears to steadily use the same titles for its bait documents and even some payloads.
  • The group often uses Google Drive as the storage for its files, specifically the baits. Sometimes, the phishing emails contain links claiming to be from Drive, while directing to a copycat site, and sometimes it uses the actual Drive service. Again, Drive is not the only service they use, it is just common.
  • We have seen the attackers hide LNK shortcuts behind icons and titles of other file types, mostly text files. Sometimes it could be a password file needed to open the main document, sometimes it could be the main document that is a shortcut, but LNK files are a staple for this group. These files are used to connect to the command and control (C2) server and download next-stage files.
  • The group’s infrastructure is continuously and rapidly changing. While in some cases we have seen the same infrastructures being constantly reused, perhaps against multiple victims, the group is generally quick to register and employ new domains and links.

 

Data Breach Affects Millions of Telegram Users

Telegram

Telegram, a cloud-based messaging app, suffered a data breach after unknown hackers exposed personal details of its users on darknet forums, according to a report from Russian publication Kod.ru. The exposed database contains phone numbers, unique Telegram user IDs, and other sensitive information. While it is unclear exactly how many users were affected in the incident, the exposed database is about 900 megabytes.

According to Kod.ru, the information was exposed via the Telegram app’s built-in contact export feature, which is used for user registration. Most of the exposed data is outdated, with 84% of it collected before mid-2019 and around 60% of it is irrelevant. It is said that 70% of the leaked accounts are related to users in Iran and the remaining 30% were from Russia.

“When checking through the program, the editors of Kod.ru found telephone numbers by nicknames in Telegram, including the numbers of the editors. In addition, the file also contains a unique user identifier in the messenger. At the moment, it is unclear exactly how many users were in the database,” Kod.ru reported.

All Apps are Vulnerable

Telegram stated that built-in contact export feature vulnerability is a primary concern for all contact-based messenger apps, Cointelegraph reported. “Like other phone-based messengers (Facebook Messenger, WhatsApp, Viber), Telegram allows you to see which of your contacts are also using the app. Unfortunately, any contacts-based app faces the challenge of malicious users trying to upload many phone numbers and build databases that match them with user IDs – like this one,” Telegram said in a statement.

Not the First Time

This is not the first time that Telegram’s user data is being exposed. In June 2019, Telegram suffered a DDoS (Distributed Denial of Service attack) attack that affected the users in the U.S., Hong Kong, and in other countries. Telegram took to Twitter to notify its users. “We’re currently experiencing a powerful DDoS attack, Telegram users in the Americas and some users from other countries may experience connection issues,” Telegram said in a Twitter post. Describing the attack Telegram said, A DDoS is a Distributed Denial of Service attack: your servers get GADZILLIONS of garbage requests which stop them from processing legitimate requests. Imagine that an army of lemmings just jumped the queue at McDonald’s in front of you – and each is ordering a whopper.

 

Demystify Regulatory Compliance in the Cloud

Security and Compliance in Cloud

In the recent CISO Mag Cloud Security Survey – June 2020, one of the questions posed to respondents was “What are some of the biggest security concerns raised when you choose a cloud service provider (CSP)?” A notable finding was that more than two-thirds of respondents stated that regulatory compliance is a key security concern when choosing a cloud service provider. The major cloud service providers — Amazon, Google, and Microsoft — address regulatory compliance head-on and painstakingly educate their customers on the shared responsibility model. This article will aim to help security leaders solve the dynamic and evolving problem with regulatory compliance on the cloud.

By Aj Yawn, Cloud Security Expert

An understanding of the shared responsibility model and its relationship to regulatory compliance will assist security leaders in preparing for regulatory compliance assessments when hosted on the cloud. Cloud security is a shared responsibility, this shared responsibility extends to regulatory compliance. The cloud shared responsibility model outlines that CSPs are responsible for the security of the cloud and customers are responsible for security in the cloud (securing the data they put in the cloud). Customer or CSP responsibility shifts depending on the cloud computing deployment type – IaaS, PaaS, or SaaS.

Regulatory compliance should be viewed through this same security shared responsibility model. The CSPs are responsible for maintaining and proving the regulatory compliance of the cloud, while customers are required to maintain and prove regulatory compliance of the data and applications they host in the cloud. The CSPs do a great job of demonstrating compliance and making this information available to its customers.

AWS, Microsoft, Google, and the other CSPs make information regarding their achieved compliance certifications readily available to all their customers. A quick glance at the three major CSPs security and compliance web pages, and you can see that they all maintain several recognized industry certifications such as SOC 2, ISO 27001, and HIPAA.

Google Cloud Compliance

Microsoft Trust Center

AWS Artifact

My CSP is compliant, how does this impact my organization?

These compliance certifications enable an organization to leverage the cloud service providers but they do not replace the cloud consumers’ requirement to perform their own third-party assessments. In certain instances, compliance frameworks allow organizations to leverage the controls in place at their CSPs for their compliance assessments. For example, in a SOC 2 assessment, you will see CSPs referred to as “subservice organizations.” This means that the CSP is implementing certain controls on behalf of their customers; these controls include physical and environmental security controls for the facilities where the data resides.

These physical and environmental security controls are only a subset of a complete cybersecurity audit. This is where customer responsibility begins with regulatory compliance in the cloud. The customer, your organization, is responsible to prove how they are addressing other common domains such as access control, risk management, onboarding procedures, termination, network security, change management, and vendor management. This is generally accomplished through evidence collection procedures, interview discussions, and observations with third-party auditors.

Ok, I understand shared responsibility, but what about data sovereignty? Is that shared too?

A regulatory compliance concern that is fairly common amongst security professionals as they are migrating to the cloud is regarding data sovereignty laws. In fact, 59% of survey respondents noted data ownership as a key security concern when choosing a cloud service provider and 47% of respondents cited data location as a security concern.

Data sovereignty is the idea that your data is subject to the laws and governance structures within the nation where it is collected. The concept of data sovereignty is closely linked with data security, cloud computing, and technological sovereignty. Understanding the shared responsibility model addresses data sovereignty concerns because you understand your responsibility and control with respect to the data hosted in the cloud. As a reminder, you, the customer, are responsible for security in the cloud. Specifically, you are completely responsible for your data. Pursuant to this responsibility, organizations have complete control over where their data is stored and how it is managed (backup, retention, encryption, etc.).

With a few clicks within the CSP management console, your organization can begin reaping the control and flexibility benefits that are inherent in the shared responsibility model.

Shared responsibility of the cloud is foundational to understanding cloud security. Armed with an understanding of this model, organizations can make smart and quick decisions when architecting solutions on the cloud. This clarity should also reduce the security concern of regulatory compliance on the cloud. As you understand where the line is drawn between the customer and the CSP, regulatory compliance becomes straightforward and easier.

About the Author

AJ Yawn, Cloud securityAJ Yawn is a cloud security subject matter expert that possesses over nine years of senior information security experience and has extensive experience managing a wide range of compliance assessments (SOC, ISO 27001, HIPAA, etc.) for a variety of SaaS, IaaS, and PaaS providers. He has earned several industry-recognized certifications, including the CISSP, AWS Certified Security Specialty, AWS Certified Solutions Architect-Associate, and PMP. AJ is involved with the AWS training and certification department, volunteering with the AWS Certification Examination subject matter expert program.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Oh Yes! It’s War, the Other War, the Cyber War!

Cyber war

The tensions between India and China are escalating by the day over the border dispute between the two nations in the Ladakh region. However, a series of no-arms combat peace treaties signed in 1993, 1996 and 2005 for maintaining peace across the region seems to prohibit the two from entering the stage of armed combat. But this does not mean it is the only attack surface where the two can lock horns. According to a top police official of the cyber cell, China has reportedly exploited the cyberspace to wage cyber warfare against India. Their state-backed threat actors have attempted over 40,000 cyberattacks on India’s Information Technology infrastructure and banking sector in the last five days.

Most of these attacks originated from the Chengdu region in China.

Yes, it is China!

Yashasvi Yadav, Special Inspector General of Police of the Maharashtra Police’s cyber wing, informed the media that his team collated all the information about these attempts and found that most of these attacks originated from the Chengdu region in China.

Yadav said,“These cyberattacks were attempted in the last four-five days on the resources in Indian cyberspace. The attacks were aimed at causing issues such as denial of service, hijacking of Internet Protocol and phishing.”

With very little hope of immediate de-escalation of the tension across the border, Yadav suggested Indian internet users need to pay attention to such threats and attacks, and create robust firewalls, along with regular cybersecurity audits at set intervals.

Are We Already in the Middle of Cyber Warfare?

Earlier, a survey from cybersecurity firm Venafi revealed that 88% of security leaders and professionals believed the world is already in a state of cyber war. The survey findings, based on the responses of 485 security decision-makers, found that 90% of security pros are concerned about the future of digital infrastructure due to rising cyber epidemic.

These risks are unlikely to change in the near term because most organizations are just beginning to understand the impacts of these risks.

Kevin Bocek, Vice President of security strategy and threat intelligence at Venafi, said, “Security professionals are under constant siege from very sophisticated threat actors targeting government, military and private organizations. Powerful attack methods, like establishing backdoors with machine identities, are now available as commodity malware, making it harder for security professionals to defend against these attacks.

The sophisticated cyberattacks are the hallmark of nation/state attacks and unfortunately, these risks are unlikely to change in the near term because most organizations are just beginning to understand the impacts of these risks.”

McAfee Reveals Most Targeted Online Entertainment Titles

Media Industry

With stay-at-home orders across the globe due to the ongoing pandemic, there has been a surge in online video consumption. Security solutions provider McAfee warned that consumers are exposed to potential risks when browsing online for popular entertainment content, especially the content available for free.

McAfee found the top ten web risk list on both television and films from more than 100 popular entertainment titles available on various streaming platforms in the U.S. According to McAfee’s analysis, web series Brooklyn Nine-Nine and Warrior film are identified as the top titles targeted by cybercriminals. Most of the consumers look for free and accessible content for the original TV series. It is found that threat actors follow consumer trends and behaviors to create their scam strategies. Children’s movies account for almost half of the top film titles.

“With cybercriminals regularly tracking changes in social trends like school closures, parents need to be extra vigilant when it comes to searching online for content for their children to watch,” McAfee said.

Top 10 Web Risk TV List:

  1. Brooklyn Nine-Nine
  2. Elite
  3. Harlots
  4. Letterkenny
  5. Poldark
  6. Lost
  7. You
  8. Gentefied
  9. PEN15
  10. Skins

Top 10 Web Risk Movies List

  1. Warrior
  2. Zombieland
  3. The Incredibles
  4. Step Brothers
  5. Bad Boys
  6. Aladdin (2019)
  7. The Lion King (1994)
  8. Swingers
  9. Frozen 2
  10. The Invitation

Baker Nanduru, VP of Consumer Endpoint Segment at McAfee, said, “With consumers increasingly going online to stay entertained during lockdowns it has created the perfect storm for web crime. History has proven that cybercriminals follow consumer trends and behaviors to educate their scam strategies. It’s important that consumers stay alert while online and avoid malicious websites that may install malware or steal personal information and passwords.”

Mitigation Measures

McAfee offers certain protective measures to stay safe online, these include:

  • The safest thing to do is to subscribe to a streaming site that offers the content or download the movie from sources like iTunes or Amazon, instead of downloading a free version from a website that could contain malware.
  • Many illegal streaming sites are riddled with malware disguised as pirated video files. Do your device a favor and stream the show from a reputable source.
  • Use parental control software. Kids are tech savvy and may search for movies by themselves. Ensure that limits are set on your child’s device and use software that can help minimize exposure to potentially malicious or inappropriate websites.

McAfee analysis is based on the web results for searches of the entertainment titles with search terms – free download, free login, free, torrent, and pirated download.

 

Cyber Defense Media Group Launches Women in Cybersecurity Scholarship

Women in Cybersecurity Scholarship

Cyber Defense Media Group (CDMG) recently launched its first annual “Women in Cybersecurity” scholarship program to encourage women in the field of security. CDMG urged high school women to apply for the scholarship. CDMG offers cutting-edge knowledge, practical case studies, and awards for the best ideas, products, and services in the information technology industry.

Commenting on the new initiative, Gary S. Miliefsky, Chairman & CEO of CDMG and Publisher of Cyber Defense Magazine, said, “Recent social events have underscored the critical need for Diversity & Inclusion in the workplace, and CDMG wants to do our part to promote much-needed change in the cybersecurity ecosystem.”

Carolyn Crandall, Chief Deception Officer at Attivo Networks, said, “Now is a fantastic time for young women to plan out their future careers in cybersecurity. It’s a hot field with hundreds of thousands of career openings and unlimited opportunities for those who wish to make a positive impact on today’s digital world.”

Women in Cybersecurity

The debates on the skill gap and gender gap in cybersecurity have off late become few of the most redundant topics. But both continue to escalate even after significant efforts by several organizations. A study by the Global Information Security Workforce Study from (ISC)² and its Centre for Cyber Safety and Education revealed that women make up only 11% of the global cybersecurity workforce, which has been a stagnant figure since 2013. This is a dangerous trend considering the fact that the same survey had projected that the gap between cybersecurity professionals and unfilled positions will expand to 1.8 million globally by 2022.

 

The MIDDLE EAST CISO FORUM: Cybersecurity in a Hyper Connected Ecosystem

Middle East CISO Forum

EC-Council’s CISO MAG is all set to host you at their virtual Middle East CISO Forum on June 29, 2020, from 0955 hours to 1330 hours (GST).

With remote working becoming the new normal during this global pandemic, CISO MAG has decided to transform their valuable interactions into a virtual digital model.

The Middle East CISO Forum will bring together experts from across the GCC region to deliver realistic insights on redefining security frameworks and efficiently mitigating cyberthreats in the ever-changing digital realm.

With the attendance of a gamut of infosec professionals from across the GCC region and support from associations such as CXO Insights and UAE Business, the Middle East CISO Forum aims to help the cyber community stay connected and updated in the face of its ever-evolving cyber landscape.

The partners for the summit believe in this initiative too and have agreed to come together to share their thoughts during these crucial times.

Title Partner Trend Micro is a leader in hybrid cloud, endpoint, and network security solutions. It is a multinational cybersecurity and defence company and will be sharing their thoughts on Securing the Digital Transformation in the MENA Region. Platinum Sponsor Attivo too has joined this summit to share their inputs on cyber deception.

Gold Partner Google Cloud will be addressing the Blind Spots While Leveraging Artificial Intelligence and Machine Learning, which have proved to be business disrupters.

Another Gold Partner, Darktrace has been associated with CISO MAG for several years now and has been working together with them to ensure they stay connected to the market and provide solutions as per the market needs. On June 29, 2020, they will be sharing their thoughts on the Crucial Issues in Combatting Email Impersonation with AI.

Last but not the least, Silver Partner is CyberX, a platform that aims to spread cybersecurity awareness among individuals & organization by developing a variety of products. CyberX will be the joining the panel on Cybersecurity as a Transformation Enabler in an Era of Hyper Connectivity and Cloud.

While technology leaders will be addressing the technical concerns, we also have our guardians of the public sector sharing their thoughts with us. The Forumwill feature special addresses by Dr. Sohail Munir, Advisor – Emerging Technologies and Digital Innovation, Smart Dubai Government and Eng. Meshal Abdulla BinHussain, Information Technology Director, Ministry of Finance, UAE. 

The event will also witness expert contributions from notable GCC leaders including Sultan Altukhaim, Director, Information Security Department (CISO), Risk Management, Capital Market Authority; Abdullah Biary, Chief Information Security Officer, Salama Cooperative Insurance CompanyThomas Heuckeroth, Group Cybersecurity Lead, Emirates Group; Saqib Chaudhry, Chief Information Security Officer, Cleveland Clinic Abu Dhabi; Dr. Erdal Ozkaya, Managing Director & Regional Chief Information Security Officer, Standard Chartered Bank (UAE);Piyush Kumar Chowhan, Group CIO, Lulu International; Ali Abdulla Alsadadi, Head of IT, National Oil and Gas Authority (Bahrain); and Mohamed Saad Mousa, Chief Information Security Officer, IKEA.

Join the dynamic Middle East CISO Community as they share their ideas, stories, and innovations with the world.

To access the full agenda, visit the event website.

To explore partnership or sponsorship opportunities, write to us at [email protected]

Stay connected, engaged, inspired, and impactful. #stayCISOMAG

About CISO MAG

CISO MAG is a publication from EC-Council, which provides unbiased and useful information to the professionals working to secure critical sectors. The information security magazine includes news, comprehensive analysis, cutting-edge features, and contributions from thought leaders, that are nothing like the ordinary. Within the first year of launch, the magazine reached a global readership of over 50,000 readers. The magazine also has an Editorial Advisory Board that comprises some of the foremost innovators and thought leaders in the cybersecurity space. Apart from this, CISO MAG also presents a platform that reach out to the cybersecurity professionals across the globe through its Summits and Awards and Power List surveys.

“Today, the global demand for MSS is largely driven by SMEs”

Sridhar S.

Sridhar S. heads the Managed Services businesses of Cloud, Hosting and Security for Tata Communications. He has been in the IT industry for nearly 30 years, and has held several leadership roles in blue-chip companies such as Dell, IBM, Intel and HCL, working across markets such as India, Asia and the US.

In a recent interview with CISO MAG, Sridhar talks about managed security services, its uptake and current trends in the cybersecurity world.

How do you see the uptake for managed security services today, as compared to, say, two years ago?

The Managed Security Services (MSS) market is maturing and witnessing a wide-scale adoption. A report concluded that the global MSS market is expected to reach USD 64.73 billion by 2025, growing at a CAGR of 15.2%, primarily driven by increased digitisation and the expanding landscape of sophisticated cyberattacks using advanced technologies. The need for enterprises to move beyond simply protecting a fast-vanishing perimeter is evident and CISOs of this era recognise the urgency to protect a growing digital infrastructure that is global, scalable, dynamic, and mobile.

Further, with the COVID-19 pandemic accentuating the need to enable anytime, anywhere monitoring of remote workers and their endpoints, organisations are increasingly seeking next-generation security capabilities which focus on securing the edge. Organizations are now looking to augment their security operations with the help of latest threat intelligence that provides the right quality and context, Artificial Intelligence (AI)/Machine Learning (ML) and user and entity behaviour analytics (UEBA) capabilities, next generation security analytics and managed detection and response (MDR) capabilities.

Amidst this, the perennial problem of skills playing catch-up with technology and shortage of security specialists continue to accelerate the development of the MSS market. While in-house teams are essential for day-to-day security operations, MSSPs are complementing organisations’ initiatives and helping them build specialisation and effectively deliver services to help organisations reduce their dependency on in-house specialists.

The growth of MSS has increased further as organisations add newer cloud security solutions with the increase in their cloud footprint. This further complicates the process of managing multiple standalone and discrete technologies forcing organizations to look at a more comprehensive security operations management processes and governance to help them through their security journey – from design to deployment to management.

From which types of businesses (small, medium, large) do you see the maximum uptake for outsourced security services? (Nearly half of all cyberattacks in the U.S. target SMBs).

With enterprises across sectors establishing their digital future on advanced platforms, more and more companies are now considering outsourcing their security services. After being driven by large enterprises for decades, the MSS market is witnessing an increasing demand from Small and Medium Enterprises (SMEs), who are now sensing an escalated threat environment.

Today, the global demand for MSS is largely driven by SMEs, as their limited awareness and financial constraints make them an easy target for cybercriminals. A recent report notes that 43% of all cyberattacks worldwide are aimed at SMEs.

On the other hand, larger organisations are more dynamic and complex and require fully secured access points. While these organisations generate a significant share of demand and dominate the market, verticals, such as Banking, Financial Services and Insurance (BFSI) and Information Technology (IT) and Information Technology Enabled Services (ITeS) are top spenders followed by Oil and Gas, Utilities, Retail and Logistics.

What is driving demand for managed security services? Can you list the factors as per the company segments (as listed in the previous point)?

Today, most enterprises are embracing the cloud first approach, which is driving the adoption of Managed Security Services (MSS), IoT and AI across segments. Add to that, the Government of India’s push for digitalisation and data security, has added greater urgency to focus on aligning with global standards.

On one hand, larger organisations, who are in different stages of upgrading their technologies, are adding more analytics. Their multiple operations and processes accompanied by humongous data flow make it challenging to monitor and ensure security of all their endpoints. These open-ended gaps and vulnerable servers invite hackers to access data without having to even break in. So, organizations are increasingly focused on users and user authentication making end point detection and response a key tool in security tool repertoire. In addition, as pointed out previously, businesses that already have a SOC are looking at introducing automation and newer security technologies that leverage Artificial Intelligence (AI)/Machine Learning (ML) and next generation security analytics. Also, with an ever-increasing cloud footprint, there is a growing need to deploy the right cloud security solution which could be a combination of Cloud Access Security Broker (CASB) with Cloud Security Posture Management (CSPM) – along with the native cloud security tools provided by the Cloud Service Providers (CSPs).

SMEs, on the other hand, can leapfrog and leverage the cloud and remote business models. Disparate technologies and products in the enterprise environment that often fail to enable a unified control and execution model for comprehensive security are the key drivers for increased demand for MSS in the segment. Additionally, lack of visibility, control, and compliance in a hybrid environment, security posture, readiness to respond to breaches, and risk management capabilities are further driving the demand of MSS.

However, all organisations, irrespective of their size, are rapidly heading towards digitisation and realising the need for a preventive cybersecurity strategy. Growing complexities of malware attacks globally continue to trigger adoption of security services. Shortage of skilled in-house cybersecurity professionals is one of the major drivers for enterprises to extend their responsibility of building a reliable security framework. Moreover, increased cases of employees and insiders of the business organisation attempting to leak confidential and sensitive data has led businesses to adopt the managed cybersecurity services and solutions significantly.

What type of services are in demand? Why?

There are several types of MSS and their deployment varies depending on the organisational need. While traditional defences, such as firewalls, Intrusion Detection Systems/ Intrusion Prevention Systems and antivirus software are a must-have, organisations are opting for a layered approach to security. One such approach is threat management, which has seen a rapid increase in demand globally. Threat management facilitates proactive identification of threats and enables faster detection with AI and ML powered comprehensive threat indicator scoring methodologies, such as real-time monitoring of the deep and dark web, social media, and underground forms for specific threat intelligence monitoring. User and Entity Behaviour Analytics for analysing deviations from usual user patterns to highlight anomalies, and forensics are also in great demand.

Next, the adoption of multi-factor authentication as a managed service has also augmented recently. A report found that the Multi-factor Authentication market, which was valued at $9.17 billion in 2019, would grow at a CAGR of 15.2 and reach $21.44 billion by 2025. The cloud-based delivery model enables businesses to implement an additional security layer that verifies the legitimacy of a transaction and secures access to corporate networks. The rise of enterprise trends, such as bring your own device (BYOD), increased use of cloud-based services and network-based application deployment, makes added user authentication measures vital – especially within industries such as e-commerce and banking. We are also witnessing an increased popularity for Vulnerability Management Services (VMS) that enables discovery, policy creation, scanning, reporting and remediation workflows to quickly and accurately identify and remediate security vulnerabilities. VMS is preferred as it an on-demand service that includes four-service levels to meet unique requirements of large-scale global enterprises as well as small and remote offices.

Lastly, with growing cloud adoption the need for CSPM solutions is also growing. CSPM helps respond to the growing need to correctly configure public cloud infrastructure. This is because cloud misconfigurations continue to be a prevalent source of security risk across organizations.

There is more automation and intelligence coming into these services. Can you please elaborate on the threat intelligent services, automatic threat hunting and incident response?

The relentless attacks on IT networks and systems make it critical for organisations to find new ways to recognise, hunt and respond to cyberthreats. End-point detection and response (EDR) is one such solution, which integrates real-time monitoring and collection of end-point data from users, servers and infrastructure with automated response and analysis capabilities. Threat intelligence services help increase the effectiveness of EDR solutions by providing superior context about emerging or ongoing threats, thereby increasing an EDR’s ability to identify exploits. Automating the steps in an investigative process by leveraging AI and machine learning helps take the effectiveness to another level.

Secondly, Automation and orchestration (SOAR) capabilities are essential for security teams to scale and respond to incidents quickly. Automating security processes can enable more efficient use of security staff, enable teams to investigate more (if not all) alerts, improve effectiveness and efficiency of detection and response, and enable better decision-making.

When deployed collectively, threat intelligent services, automatic threat hunting and incident response facilitate real-time threat detection, prioritisation, and rich and actionable insights to guide further investigations – helping security teams to quickly identify and respond to threats.

We see a trend of increasing attacks on Managed Security Service Providers. What steps should MSSPs take to protect their infrastructure and their client’s infrastructure that they manage?

In today’s digital economy, security is not something that businesses deploy and set aside. As the digital scenario evolves, security needs continuous management and MSSPs need to look at data and information across its lifecycle across environments and deliver security for the cloud and from the cloud to global enterprises. They also need to keep in mind the ever-changing security landscape and deploy a security infrastructure that boasts strong competencies in cloud security, data security and privacy, risk and compliance, and identity and threat management. At the same time, service providers need to ensure that their approach is supported by analytics to predict cyberattacks and ensure network and infrastructure security, intelligence, scalability, and flexibility demanded by today’s businesses. Lastly, MSSPs need to ensure that they constantly support their customers and bring these offerings as a 24×7 service to help businesses fight cyberthreats.

How do you see MSS and MSSPs evolving in the future?

In a connected world, businesses are vulnerable to a range of evolving threats like never before. As organisations increasingly migrate to the cloud and adopt IoT devices, the horizons for threat landscape are growing larger and more complex.

This has triggered organisations to rapidly opt for a partner, who can help them break out of this cyber-siege and provide them with the necessary intelligence to protect all the elements of the business’s architecture. MSSPs, on the other hand, will increasingly combine the power of analytics, cutting-edge technologies and deep knowledge of data environment to offer businesses early warnings and actionable advice on globally emerging threats. Further, as MSS market matures, service providers would widen their offerings and include specialised technologies to lock up the systems we rely on most – the Operational Technology (OT). As more organisations adopt Software-and-Infrastructure-as-a-Service (SaaS and IaaS), OT will help MSSPs address a wide range of needs and move up the value chain.

Additionally, as regulators tighten data security laws, businesses will turn to a managed service provider that offers data privacy and can help the business with its compliance requirements, right from identifying and remediating risks, to providing end-user training and necessary documentation. MSSPs will also continue to emerge as important channel partners that allow the product vendors to propose more effective monitoring and management as adjuncts to their technology products.