Home Blog Page 20

Harness Your System, No More a ‘Whack-a–Mole’

Harness Your System, Free Decryptor, federal government, cybersecurity

Every day there are multiple reports from government, state municipalities, and corporates about their being hacked, held for ransomware or becoming victims of denial of service (DoS), phishing, malware, trojans, and a whole array of other cyberattacks. All cyberattacks result from the systems talking with the outside world where it is not meant to communicate. There is a need to have a solution that can effectively safeguard the systems or mitigate the risk.

Meetings at Spaceport America, Virgin Galactic’s human spaceflight headquarters, and common work interest on suborbital space tourism got the innovators together to work on their idea of solving the cybersecurity challenge through innovation. In a virtual interaction, the Co-founders of Fraisos spoke to Minu Sirsalewala, Editorial Consultant at CISO MAG, and shared their mission, vision, and solution, as it appraises a non-traditional IPO as its next growth step.

Fraisos is a U.S. based company founded in 2017 through a Department of Defense Small Business Innovation Research (SBIR) Program. It believes it discovered the solution to the government’s cybersecurity challenges based on its next-generation cyber-defense innovation.

Also Read: Rags to Riches! The Evolution of Ransomware Operators

A common love for innovation and technical expertise in semiconductors, computer science and hardware engineering, mathematics, physics, electrical engineering, and U.S. Government programs brought the three founding members, Dr. Lindsay O’Brien Quarrie, Dr. Lawrence John Dickson, and Robert Montgomery Fryer, together to collaborate and offer solutions to cybersecurity challenges.

Dr. Lindsay O'Brien QuarrieDr. Lindsay O’Brien Quarrie, the Chief Executive and Technology Officer (CETO), articulated, “The challenges basically come from an excess of complexity, allowing communication to penetrate to places where it isn’t supposed to. The solution we came up with is to impose simplicity and force communication to happen only with those communication partners as intended by the actual needs of the program. We have devised a way to apply a simple old technology from the 1980s, called Communicating Sequential Processes, the Best Way of Doing Parallel Programming. A book that I published in 2014 described a very simple approach to it, using standard software. And, it gives you a hardware-software equivalent if applied correctly.”

Elaborating on the technique, Quarrie shares that this technology fits in well with the current scenario due to the hardware-software equivalent. The software can be made to behave exactly like an isolated piece of hardware communicating through a point-to-point link; it’s one intrinsically subordinated operating system.

On the software side, it is like putting a wrapper around your system, monitoring the communications, and restricting the communication – both internal and external.

“The advantage here is that when there are updates and a new version releases, there is no need to look at the binary code of the program. The solution will ensure that there is no access to the actual kernel of the device, and any attempt at execution of non-approved activity will be denied,” explained Quarrie.

Lower Cost Cyber Defense

There is a direct cost implication when there are version upgrades, there is a restriction and futile costs are avoided both on upgrades and security. The system has the intelligence to identify which upgrade is required and what app needs to be on the system, thereby ensuring no communication from within, which could open a window and make the system vulnerable to any cyberattack.

The isolation approach is about securing the critical parts of the system by controlling the access in a simplified way. This allows securing the system at multiple levels without compromising its performance and efficiency. As a result, it reduces cyber defense’s total implementation and maintenance costs by avoiding version skew.

The Solution

The products and service offerings include defined systems, formally and physically verified cyber defense (maps to physical reality) for embedded systems, smartphones, tablets, laptops, desktops, industrial controls, medical devices, and all embedded systems that boots and their associated systems. Quarrie opines, “We deal in realism, and run counter to the trend of abstraction and avoidance of detail. This enables us to be strong in the whole area of computer programming and design that has ‘gone fallow’ due to an increasing monoculture of trendy, ultra-abstract languages. We can step in wherever necessary, to get a tight grip on a device’s actual behavior (100% of the time, not just 99%). This includes strict security in the age of ransomware.”

Math and the Physical Sciences provide many ways to look at a large array of problems. These basics, plus a large dose of innovation, often illuminate an approach outside the mainstream and where new opportunities can be found. This is true, especially since technology provides many new tools to apply to old problems.

A Quantum Proof cyber defense, based on realism — rejects the abstraction trend and insists on verifiable, simple, predictable device behavior. “Components in our designs communicate according to explicit protocols which are exposed and not hidden, thus imposing restrictions that make security and predictability possible and understandable.”

Mission and Vision

Dr. Lawrence John Dickson’s book, Crawl-Space Computing (Amazon, 2014), is inspired by the classic computing paradigm, Communicating Sequential Processes (CSP), its implementation in the language OCCAM, the 1980-1995 era Transputer chip, and the product series. This is the basic premise on which the three members built their solution, with a mission for the consumers to take back control of the computer and the embedded systems. The consumer is the custodian and true owner, versus the hacker owning you.

A property that is central to all their design: Hardware-Software Equivalence (HSE), means that it is formally verifiable that software written in this way is equivalent to hardware devices communicating by point-to-point data-passing channels. (It is related to Rushby’s separation kernels but more general.)

This opens up a massive variety of design approaches that behave predictably. As overly-abstracted devices run into walls of failure and malware, our mission is to uphold this ‘countercultural’ alternative that can solve the same problems clearly and understandably. HSE allows us to devise approaches that combine an outer CSP-type structure (the Finite Resource Allocator, or FRA) with inner ring-fenced nodes using standard computing tools (the Intrinsically Subordinate Operating Systems, or ISOSs), thus giving a shortcut to understandable effectiveness and explaining the company name FRAISOS (Finite Resources Allocator Intrinsically Subordinated Operating Systems).

With a vision to create a niche in the cyber security market, Fraisos is actively building its customer base with targeted research and production projects, emphasizing government customers, especially military and local government, protecting cities, municipalities, large and small businesses.

Quarrie emphasizes, “We have a simple, common-sense approach and tools. Predictability, reliability, and security of complex computing devices have been failing around the edges, and our approach solves this and makes clear the reason why it is solved.”

With a professional market evaluation of $155.1 M from Foresight Valuation in Silicon Valley, Fraisos’s principal investor is Space Sciences Corporation, from the research and development domain.

The current reality is that hackers can penetrate through these existing methods because the existing approach consists of layers and patches with holes for gaining access and are mostly “whack a mole.”

Quarrie echoes, “We are innovative by opposing complexity, where we try to make things more simple, not more complex. A system can be as complex as they like, but when they get to the outside world, they get to it through a very simple interface and a well-defined way of communication that’s been known since the 1980s. For example, take any classic car — we can still do a complex task without computers. But the task gets subdivided into simple components that interact with each other in a well-defined fashion. And that’s the path we’re taking. And there’s a lot of room for that path to be taken in the future.

Complexity causes disaster, and a lot of rocket ships have blown up. Fraisos believes in going ‘Back to the Future,’ and essentially being future proof at the same time.”

———————————————————————————————

References

Multiple Peer reviewed Formal Verification Proofs and acceptance Validated by IEEE Computer Society, COPA 2021, NSA, DoD.

Competitive SBIR awards Phase I and Phase II.

Follow-up in the N152-087 (Secure Electronic Kneeboard Across Multiple Security Levels on COTS Devices).

Founders of the new IEEE Concurrent Processes Architectures (IEEE COPA) and Embedded Systems group stepped in when CPA went offline due to COVID-19 and published a peer-reviewed conference proceeding in 2021.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

About the Author:

Minu

About the Interviewer

Minu Sirsalewala is an Editorial Consultant at CISO MAG. She writes news features and interviews.

More from Minu.

There Will Be More Focus on Data Privacy, IT-OT Security, and Vendor Consolidation

Cybersecurity Predictions

By the end of 2023, modern privacy laws will cover the personal information of 75% of the world’s population. Data privacy is gaining momentum in India, especially after the Supreme Court declared the Right to Privacy a fundamental right. The introduction of the Personal Data Protection bill (now called as Data Protection bill, after the inclusion of non-personal data in the scope), is aiming at providing a framework to ensuring an individual’s privacy by providing the proper use, access, accountability to the personal as well as non-personal data of Indian Citizens. The bill is yet to be passed across the two houses in Parliament before it becomes an Act, putting nearly 800 million internet users under the scope.

By Prateek Bhajanka, Senior Principal Analyst, Gartner, Inc.

GDPR was the first major legislation for consumer privacy. Still, others quickly followed it, including Brazil’s General Personal Data Protection Law (LGPD) and the California Consumer Privacy Act (CCPA). The sheer scope of these laws suggests you’ll be managing multiple data protection legislation in various jurisdictions, and customers will want to know what kind of data you are collecting and how it is being used. It also means you will need to focus on automating your privacy management system. Standardize security operations using GDPR as a base and then adjust for individual jurisdictions.

By 2025, threat actors will have weaponized operational technology environments successfully enough to cause human casualties. 

Also Read: Data Privacy Week: The 3 Ps Vital to Enhancing Your Online Data Privacy

With India’s emphasis on increasing the GDP contribution from the manufacturing industry to 25%, the industry is expected to see advancements in the areas of technology, business models, and value creation. With multiple factors such as a significant percentage (12%) of the workforce employed in the industry; IT-OT convergence and malware spreading from IT to OT; an increase in the number of nation-state attacks – it shifts the discussion from business disruption to physical harm with the liability likely ending with the CEO. The security and safety of the workforce would also become a key responsibility for CISOs. Focus on asset-centric cyber-physical systems, and make sure there are teams in place to address proper management.

By 2024, 30% of enterprises will adopt cloud-delivered secure web gateway (SWG), cloud access security broker (CASB), zero-trust network access (ZTNA), and firewall as a service (FWaaS) capabilities from the same vendor. 

Indian organizations are rapidly becoming digital businesses to increase their value proposition, introduce new channels, reach new markets, find efficiencies in business models, etc. They adopt cloud technologies in various forms and embrace a hybrid architecture to become digital. Also, with the need for working from anywhere and anytime access, the security controls that existed in the corporate networks should be available irrespective of the source of the connection. On the other hand, organizations are leaning into optimization and consolidation. Security leaders often manage dozens of tools, but they plan to consolidate to fewer than 10. SaaS will become a preferred delivery method, and consolidation will impact adoption timeframes for hardware.

About the Author:

Prateek BhajankaPrateek Bhajanka is a Senior Principal Analyst for the IT Leaders (ITL) constituency, focusing on Security and Risk Management for Gartner Research. His areas of research include Endpoint protection platforms/Endpoint detection and response (EPP/EDR), malware and ransomware prevention, etc. His key tasks encompass creating high-quality, actionable and consumable written research and give clients insights and advice on various security problems they face. Bhajanka also helps organizations save money on new contracts and renewals on endpoint protection platforms and endpoint detection and response.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Ransomware: To Pay or Not to Pay?

Ransomware Attacks, Graff ransomware attack

In 2021, ransomware remains the most prominent malware threat with an attack occurring every 11 seconds. Total ransomware costs are projected to exceed $20 billion with an average of 21 days downtime (Coveware, 2021) and $1.85 million in recovery costs (Sophos State of Ransomware Report, 2021) for those who fall victim.

There are numerous examples of publicly recorded incidents showing the cost to rebuild as significantly more than the ransom requested. Over the last few years, the cost of remediation has increased from $0.78 million in 2020 to $1.85 million in 2021. With 54% of attacks succeeding in encrypting data and only 65% of that data being restored on average, CEOs and business leaders need to weigh up the cost of downtime and the impact on their business. But even if the ransom is paid, there is no guarantee that a decryptor will be forthcoming or that, if provided, it will even work.

This February, CISOs and cybersecurity experts from across Europe will gather in London on the 22 – 23 February to share lessons learned and benchmark resilience and business continuity planning at the Ransomware Resilience Summit Europe, enabling you to better protect your businesses from attack.

Join PaloAlto alongside Paul Haywood, Global CISO at BUPA; Munawar Valiji CISO of Trainline, Erez Liebermann, Partner and Co-Chair of US Data solutions at Linklaters, and Katherine Demidecka, Strategic Consultant from Mandiant as they highlight the importance of an effective response plan and how you can effectively determine roles and responsibilities during an attack.

Over the two days, you’ll focus on how to prevent, detect, respond, and recover from ransomware attacks, with first-hand encounters from Graeme King, Cyber Managing Director of Volante Global alongside interactive discussions and experience sharing with Sanne Group, The Cyber Resilience Centre and Scottish Power Offshore Renewables.

Are you a CISO or cybersecurity expert looking to share your experiences and knowledge with others? Get in contact with Simon today to find out how you can join the discussion at [email protected]

Join us this 22 – 23 February in London. Find out more today.

Use your exclusive discount code CISOMAG10 for 10% off.

Based in the USA? Check out our Washington D.C. event instead.

The risk of intrusion will increase as companies add more suppliers in a shift to just-in-case supply chains

Proactive Cybersecurity Paradigm, cyberwar, IoT, 5G, Boardroom, Identity Detection and Response, Predictions, supply chains, hybrid workforce

Tattleware will degrade employee experience by 5% and increase insider threats. With Anywhere Work here to stay, employers have added platforms that add insights into employee activity and productivity. But employee backlash against what they perceive as surveillance tools and employer overreach will also impact insider threat programs. Employees might confuse security tools for productivity platforms and react poorly, eroding the security team’s ability to detect insider threats. Security leaders will need better messaging, policies, and clarity around insider threat programs to avoid being lumped into surveillance platforms masquerading as productivity tools.

 

Jeff Pollard

 

By Jeff Pollard, VP and Principal Analyst, Forrester

 

Nearly 60% of security incidents will result from issues with third parties. Hyper-efficiency leads to fragility, as seen over the last two years with just-in-time supply chains. More and more companies will reduce their concentration risk by adding more suppliers in a shift to just-in-case (JIC) supply chains. More suppliers bring more connectivity, and more connectivity brings more opportunities for intrusions, which equals more risk that one of those suppliers will serve as the bridge into your environment. Improving the maturity of your third-party risk program and adopting zero-trust approaches will help reduce the likelihood and impact when it happens.

Also Read: What the Cybersecurity Leaders Are Saying About Data Privacy

At least one security vendor collapses in an Enron-Theranos-esque scandal. In recent years, record levels of investment and merger & acquisition activity give us hope that cybersecurity problems will start getting solved. And more capital flows in every day. Plenty of unsolved problems still exist, but easy access to capital also incentivizes fraudsters and charlatans to exploit investors, shareholders, and customers. At least one vendor will get brought down by “accounting irregularities” in the next twelve months. Security leaders should diversify their vendor portfolio, think twice about publicly endorsing early-stage vendors as public customer references, pay special attention to vendor-provided financials and compare these with what’s provided to regulators or investors to identify potential areas of concern.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Researchers Found New Ransomware DeadBolt Targeting NAS Servers

DeadBolt, Shutterfly ransomware, Cuba ransomware

Security experts from QNAP Systems uncovered a new ransomware variant actively targeting all Internet-connected Network-attached storage (NAS) devices. Tracked as DeadBolt, the ransomware reportedly compromises NAS devices that are not secured, encrypting users’ sensitive information for Bitcoin ransom. It is found that the DeadBolt ransomware campaign mostly encrypted the NAS devices located in the U.S., Hong Kong, Taiwan, Germany, France, Italy, South Korea, the U.K., the Netherlands, and Poland.

Based in Taiwan, QNAP is a manufacturer of NAS devices. QNAP researchers recommended that all QNAP NAS consumers follow the security setting instructions and update their products to prevent unauthorized intrusions.

How to check whether your NAS is exposed to the Internet

The researchers stated that the NAS devices are prone to various cyberthreats if they are exposed to the Internet. To check whether your NAS device is exposed to the Internet:

  • Open the Security Counselor on your QNAP NAS.
  • Your NAS is exposed to the Internet and at high risk, if it shows “The System Administration service can be directly accessible from an external IP address via the following protocols: HTTP” on the dashboard.”

QNAP suggested the below security instructions for NAS security:

1. Disable the Port Forwarding function of the router

Go to your router’s management interface, check the Virtual Server, NAT, or Port Forwarding settings, and disable the NAS management service port (port 8080 and 443 by default).

2. Disable the UPnP function of the QNAP NAS

Go to myQNAPcloud on the QTS menu, click the “Auto Router Configuration,” and unselect “Enable UPnP Port forwarding.”

NAS Devices Under Attack!

This is not the first that QNAP NAS devices have been under attack. Earlier, QNAP released a security advisory warning its users about a new cryptomining malware targeting its network-attached storage (NAS) devices. A NAS device is an internet-connected storage device that allows data storage and retrieval from a central location for authorized network users and clients. Once the malware infects a NAS device, the CPU usage becomes unusually high, where a process named “oom_reaper” could occupy around 50% of the total CPU usage. QNAP stated the infection could be removed by rebooting the affected devices. Read More Here

Focus on Consolidating and Simplifying Operational Systems

Cybersecurity Predictions

The unprecedented events of 2021 have accelerated the growing network of technology integrations, which has automated business workflows and data exchange. However, this has involuntarily allowed lateral movement by attackers, thereby making cybersecurity a top focus area. Malicious threats from outside and within organizations, coupled with increasingly stringent data regulations, are putting the onus on organizations to step up their security and data use precautions, thereby making cybersecurity a C-suite level issue. This is putting pressure on security leaders to focus on consolidating and simplifying operational systems, allowing users to have a cohesive view of things rather than everything being siloed.

By Rajesh Dhuddu, VP & Practice Leader Blockchain & Cybersecurity Tech Mahindra

Today, cyber threats and attacks are pervasive, and the surface area of attack has also increased with the Work from Home (WFH) model. Organizations must focus on re-evaluating IT strategy, ensuring an end-to-end, robust, and strategic infrastructure design based on zero-trust architecture to improve overall infrastructure security posture, including business and network security lifecycles. Enforcing agile perimeter security, and attack surface anonymization and reduction will enable enterprises to detect, mitigate, and prevent network threats while securing remote workplaces simultaneously.

While remaining in sync with these emerging cybersecurity trends, we at Tech Mahindra attempt to help customers navigate the uncertain future and remain secure. We have also strengthened the internal security policy for the benefit of our associates. In all this, I believe, security leaders will be focused on consolidating and simplifying operational systems, allowing users to have a cohesive view of things rather than everything being siloed. Companies will seek to use low-code automation to harness the collective knowledge and form a centralized record system, with appropriate fail and foolproof points, for operational data.


About the Author

Rajesh Dhuddu leads Blockchain & Cybersecurity practice for Tech Mahindra. He is responsible for guiding a team of 500+ highly accomplished Cybersecurity professionals empowering Global customers in EMEA, APJ & India to strengthen their enterprise wide Cybersecurity posture and build a highly resilient security organization. He works closely with Global CISOs, advising them to leverage best practices both in technology and operations covering Cloud Security, Network Security, Advance Threat Management, Zero Trust, Offensive Security, Cyber-risk Quantification & SASE.

 

U.S. Government to Adopt The Zero-Trust Security Model

zero-trust, Counter-Ransomware Meeting , Biden Administration and Tech Giants

The Office of Management and Budget (OMB) in the U.S. released a national strategy to move the government towards a zero-trust security model for better cybersecurity outcomes. The strategy is a part of delivering President Biden’s Executive Order on Improving the Nation’s Cybersecurity, intended to boost the security of the nation’s critical digital infrastructures against rising cyberattacks.

The agency opined that the growing sophisticated cyber threats could not be mitigated with the conventional perimeter-based defenses. Citing Log4j vulnerability as the latest evidence, OMB stated that adversaries continue to find new gateways to penetrate the targeted systems.

The Zero-Trust Security Model 

A zero-trust security model is a process of designing a cybersecurity architecture based on the “never trust, always verify” concept. OMB stated the zero-trust strategy allows organizations to detect, isolate, and respond to different types of cyber risks. It will serve as a roadmap for shifting the Federal government to a new cybersecurity model.

OMB’s new federal zero-trust strategy envisions a Federal government where:

  • The federal staff has enterprise-managed accounts, allowing them to access everything they need to do their job while remaining protected from even targeted, sophisticated phishing attacks.
  • The devices that Federal staff use to do their jobs are consistently tracked and monitored, and the security posture of those devices is taken into account when granting access to internal resources.
  • Agency systems are isolated, and the network traffic flowing between and within them is reliably encrypted.
  • Enterprise applications are tested internally and externally and can be made available to staff securely over the internet.
  • National security and data teams work together to develop data categories and security rules to automatically detect and ultimately block unauthorized access to sensitive information.

Also Read: Step Up Cybersecurity! White House Warns About Rising Ransomware Attacks

“In the face of increasingly sophisticated cyber threats, the Administration is taking decisive action to bolster the Federal government’s cyber defenses. This zero-trust strategy is about ensuring the Federal Government leads by example, and it marks another key milestone in our efforts to repel attacks from those who would do the U.S. harm,” said Acting OMB Director Shalanda Young.

“Security is the cornerstone of our efforts to build exceptional digital experiences for the American public. Federal agency CIOs and IT leaders are leaning into this challenge, and the zero trust strategy provides a clear roadmap for deploying technology that is secure by design and responsive to the needs of our workforce so they can better deliver for the American public,” said Federal Chief Information Officer Clare Martorana.

Back to Basics: What Security Leaders Need to Do to Protect their Organizations

Cybersecurity can feel quite overwhelming and complicated for business leaders. That poses a challenge to the CISO who must communicate the impact of security breaches and attacks, in business language. Business leaders need to understand more about data security, and the impact of data breaches – on customers, shareholders, partners and employees.  At the end of the day, it’s important that business leaders get back to the basics to stay secure: identifying their assets, backing up those assets, identifying vulnerabilities, and patching those vulnerabilities. Physical security is often neglected and should also be given its due importance.

In a video interview with CISO MAG, Caroline Wong, Chief Strategy Officer at Cobalt said it is a myth that business leaders do not understand cybersecurity. But the complication occurs because cybersecurity is about measuring risks and it is a challenge to put straightforward metrics on that, as we do with everything else in business. Wong says there are so many parameters in cybersecurity. She says everyone is trying to come up with a number for the dollars that would be lost if an organization is breached. Instead, the value number to have is the cost of a plan to achieve an objective. Cybersecurity leaders should begin with risk management objectives. Caroline offers seven risk management objectives. Business leaders should agree on a risk management objective and a common goal.

Caroline is a strategic leader with great communications skills, deep cybersecurity knowledge, and a lot of experience in delivering global programs. Her practical information security knowledge stems from broad experience as a Cigital consultant, a Symantec product manager, and day-to-day leadership roles at eBay and Zynga.

In all Caroline has 15+ years of deep and practical cybersecurity expertise, including leading teams at eBay, Zynga, Symantec, and Synopsys.

She authored the popular textbook Security Metrics: A Beginner’s Guide;  hosts the cybersecurity podcast Humans of Infosec, and teaches cybersecurity courses on LinkedIn Learning.

Most recently, Caroline published a new book called The PtaaS Book. To learn more about it, click here.

Cobalt is a global, remote-first cybersecurity company with a focus on Pentest as a Service (PtaaS).


Also Read:

Our 2021 interview with Caroline Wong.

In this interview Caroline offered advice on how security leaders should communicate with Board members and other stakeholders.

What the Cybersecurity Leaders Are Saying About Data Privacy

Data Privacy Week 2022

Security intrusions and data breaches continue to be severe concerns for organizations and users’ data privacy. Despite constant cybersecurity awareness campaigns, several people still fail to comprehend how businesses leverage their sensitive information. Internet users must understand where their sensitive data is going in the current digital world. Amid rising security incidents, organizations must enhance their data privacy online.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

To shed light on the importance of data privacy and bring better cybersecurity awareness, CISO MAG has procured suggestions and recommendations from cybersecurity experts worldwide. Take a look:

1. Cyber situational awareness and hygiene will continue to play a key role as one of the pillars of data privacy.

“As we increasingly blur the line between our online and offline lives, Data Privacy Day is the little reminder we need at the start of each new year to ensure our personal information is protected.  Even though we live in a digital world, we are often not fully cognizant of data privacy until our data has been compromised.

In the age of the work-from-anywhere economy, business leaders should realign their security priorities to manage risks affecting sensitive information. To guarantee a seamless flow of data from endpoints to cloud-based services and data centers, it is becoming more important to protect the data in transit as well. India’s crucial business data can be protected through investment in the modernization of security infrastructure, using secured collaboration and information-sharing platforms, leveraging threat intelligence for proactive cyber defense, and using security orchestration and automation (SOAR) to streamline SecOps and performing periodic security and risk assessments.  Individuals must take control of their digital footprints and privacy as we continue to telecommute in 2022. Moving forward, cyber situational awareness and hygiene will continue to play a key role as one of the pillars of data privacy.”

2. Brands must go above and beyond to meet their users’ expectations towards data security

 “The AppDynamics App Attention Index 2021 showed that security is the number one component of a high performing ‘total application experience’ for consumers. And 90% say that their expectation of brands to keep their data secure has increased since 2020. It shows that brands must go above and beyond to meet their users’ expectations towards security. In this post-pandemic era, a strong security posture means organizations have the necessary processes to protect their applications and business from vulnerabilities and threats. In a world where sensitive data is constantly at risk of being compromised by malicious actors, they must be prepared and strengthen their security posture, enabling them to predict, prevent and respond to threats.”

“The DevSecOps methodology, a modern approach to software development, takes things a step further and incorporates security enhancements at the beginning of the application development lifecycle for a more proactive approach to reduce risks of threats to sensitive customer data. But for a DevSecOps approach to be fully effective, teams need to implement a full-stack observability solution. This approach will give them in-depth visibility into the entire IT stack, including traditional legacy systems through to new, native cloud environments and hybrid deployments. It is a vital step in the right direction.”

3. Data privacy compliance has become a critical consideration driving critical business decisions as companies look to digitally transform

 “In recent years, data privacy compliance has become a critical consideration driving critical business decisions as companies look to digitally transform. Cybersecurity vulnerabilities continue to increase as companies grow their digital footprints due to the generated massive amounts of data. Due to the increasing complexity of data flows, enterprises need to evolve past securing data at rest to a posture of continuous governance where all data is protected. The Data Privacy Day comes as a reminder for organizations to assess their cyber risks and ensure strong data privacy protections are in place but in such a way that will not impede innovation within the digital economy.

Increasingly, we see enterprises place, manage and analyze data at the edge, closer to their users, services, and clouds. Meanwhile, concerns over the security and privacy of data in motion and the cloud have also increased. This situation is more critical in Asia-Pacific and has driven the need for better technology and infrastructure solutions that improve data accessibility, security , and control while meeting increasing data privacy requirements. It is a balancing act.”

4. Businesses of all sizes must take data privacy seriously and proactively protect personally identifiable information

 “While it is great that we are all more connected than ever before, the shift to remote work in response to the pandemic has presented inherent security issues. Recent large-scale data breaches have made data privacy a hot topic in the last two years. As of 2021, CERT-In had documented and reported more than 11.5 lakh incidents of cyberattacks. Data Privacy Day is an excellent opportunity for companies to commit to cyber security and implement robust data management solutions.

Today, data privacy is a matter of paramount importance. Businesses of all sizes must take data privacy seriously and proactively protect personally identifiable information. Cybercriminals can target any organization, no matter its size, location, or industry. So, if you want to safeguard your organization’s data, you need to build a cyber-secure and human-centric corporate culture.

Establishing a security-aware culture begins with an open discussion of data privacy. Employers are the source of the greatest privacy risks, and as such, they can play a vital role in minimizing these risks. Changing behavior is how leading organizations educate their employees about their risks. Employees will be less likely to share sensitive information online if they understand how websites and companies use their data. Data Privacy Day is the perfect occasion to kickstart an ongoing focus on security and privacy.”

5. Take the time to learn what privacy controls are available in all the apps and online services you use

“Take the time to learn what privacy controls are available in all the apps and online services you use. Unfortunately, every app and social network seems to do things differently, with privacy and security options often scattered liberally across numerous “Settings” pages. But don’t be afraid to dig through all the options, and don’t just rely on the default settings.  Start by turning off as many data sharing options as you can, and only turn them back on if you decide you want and need them.

Suppose a service demands you to share more than you are willing to hand over. In that case, your address, phone number, or birthday, for example – or asks for data that you don’t think is relevant for what you are getting in return, ask yourself, “Do I need to sign up for this, or should I find somewhere else that isn’t so nosy?”

Don’t let your friends talk you into airing and sharing more than you’re comfortable with – after all, it’s your digital life and your data, not theirs. Remember: if in doubt, don’t give it out. and be aware before you share.”

6. Organizations face an emboldened world demanding greater accountability and trustworthiness

“Data privacy reform has changed our global community forever. As we begin 2022, organizations face an emboldened world demanding greater accountability and trustworthiness. The recent steps taken by several countries to bolster their consumer privacy rights and processing activities (such as China’s Personal Information Protection Law) will have a far-reaching global impact on privacy rights and data protection practices.

People are more empowered than ever to exercise their rights, submit Subject Rights Requests (SRRs) and reclaim control of their information. They want to understand how their data is used and access, correct, delete and restrict use. To meet these data-intensive demands and overcome a scarcity of resources to support key business activities, organizations must embrace process automation for SRR response and apply case management tools that best track its performance and effectiveness. A well-executed program that delivers a strong experience will be critical to improving customer satisfaction and loyalty.”

7. This Data Privacy Day, we highlight how we can better protect the data they access from being exposed

 “It’s not just humans that are susceptible to clicking on the wrong link or are perhaps a little too cavalier about what they share about themselves. Software bots have sharing issues too, and this Data Privacy Day, we highlight how we can better protect the data they access from being exposed.

The privacy problem arises when you start to think about what these bots need to do what they do.  Much of the time, it’s access: If they gather together sensitive and personal medical data to help doctors make informed clinical predictions, they need access to it. If they need to process customer data stored on a public cloud server or a web portal, they need to get to it. If bots are configured and coded badly, they can access more data than needed. The output might leak that data to places where it shouldn’t be. We’ve seen the problems that can arise when humans get compromised, and the same can happen to bots – and at scale. Likewise, we hear about insider attacks and humans being compromised to get to sensitive data virtually every day.”

8. Data Privacy Day serves as a reminder that cyber asset management should be a top priority for every organization

“In the U.S. alone, there are several disparate federal and state laws, some of which only regulate specific types of data – like credit or health data, or specific populations – like children. Combining these regulations with the many different international laws that aim to ensure data privacy, such as GDPR, and compliance for companies with global operations becomes an extremely complex undertaking.

Data Privacy Day serves as a reminder that cyber asset management should be a top priority for every organization. Enterprises cannot ensure compliance and data security unless all assets are properly known, tagged, and mapped in the cloud. To avoid jeopardizing sensitive company or customer data, organizations must take the first step of cyber asset management to secure visibility of all cyber assets in their IT environment and understand connections between business services. This includes identifying misconfigurations and automatically prioritizing risks to improve overall security posture, allowing for real-time visibility and management of all sensitive data.”

9. With more data moving to the cloud every day, it is imperative to have a re-architecture of the cyber strategy

Nitin Verma

“Over the last 2 years, there has been a significant rise in cyberattacks all over the world. The pandemic has increased our dependency on mobile devices and remote access to core business functions. While remote working became the saviour, it also introduced a new set of security challenges by raising concerns regarding identity-based threats, privacy breaches and the loss of essential data from unprotected devices and systems. Despite the best efforts of security teams, attackers consistently took advantage of vulnerabilities, discovering new ways of infiltration and taking advantage of people’s curiosity as well as their fears around Covid-19, leveraging socially engineered lure files and tactics.

There is a huge digital shift that has been created by the pandemic where many industry sectors have witnessed an accelerated approach towards digital transformation and their erstwhile perimeter has moved beyond their enterprise firewalls to cloud; either a public cloud, hybrid cloud or a private cloud. This has added complexity to the IT architecture stack and also increased the potential attack surface for adversaries to exploit; and often under-resourced security teams to protect.

Today’s new perimeter needs to be buttoned up with operations and security collaborating to create a secure network. With more data moving to the cloud every day, it is imperative to have a re-architecture of the cyber strategy which should go around all three dimensions of security i.e. people, process and technology.”

10. Data security and privacy must work like hand in glove because data security is the technical implementation of what data privacy dictates

Kartik Shahani

“In a time when trust in organizations is easily lost and hard to gain, companies must do everything they can to ensure their customers’ data is secure and adhere to high privacy standards. Data security and privacy must work like hand in glove because data security is the technical implementation of what data privacy dictates. As the economic value of data increases, so do the risks involved. Organizations need to ensure that data security forms an integral part of their overall privacy strategy. By leveraging technical controls and making data privacy a business priority, organizations can outline policies for data usage and access while ensuring transparency and reducing their overall cyber exposure.”

About the Author

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.

 

Act Sooner to Prepare for the Increasing and Emerging Security Challenges

Cybersecurity Predictions

Ransomware attacks are growing in sophistication, with threat actors employing new technologies and affiliate models. Last year saw new models like Ransomware as a Service, with specialists working together to support ransomware attacks. They are now observing the OT-IT merger and looking for vulnerabilities to exploit in operational technology (which is not as secure as information technology). That is why organizations must prepare for more such attacks in 2022.

By Muhammad Tariq Ahmed Khan, Head of Information Security Audit, Internal Audit Department, Riyad Bank, KSA

Here are my three trends.

1. The Surge in Ransomware Attacks. Ransomware attacks have become worse in the last two years, and it is expected that the curve will continue surging in 2022. While the volume of ransomware attacks is alarming, the usage of technologies adding up their capabilities is a matter of concern that will continue to target the organizations. This is probably due to the growing convergence of Information Technology (IT) and Operational Technology (OT) networks, which has enabled attackers to target organizations through the vulnerable home and remote workers’ devices.

2. Evolving Artificial Intelligence.  Since artificial intelligence is evolving unprecedentedly and providing more opportunities to organizations, the cybercriminals will continue leveraging AI to circumvent all controls, gain privileged access to organization’s data and erase traces to avoid detection. It is expected that cybersecurity vendors will combine the strengths of AI, Machine Learning Algorithms (ML) and Deep Learning (DL) networks, enhancing the capability of AI making it more effective and efficient.

3. Scarcity of Cybersecurity Talent. With the increase of cybersecurity threats and the diversity of the attack landscape, cybersecurity talent is expected to remain scarce in 2022. The demand of cybersecurity professionals will rise to cope with the constant battle against cybercrime. This imbalance will result in salary hikes for cybersecurity professionals.

Also read:

Ransomware! Ransomware! Ransomware! The Problem of Blind Reductionism


About the Author

Muhammad Tariq Ahmed KhanMuhammad Tariq Ahmed Khan is Head of Information Security Audit, Internal Audit Division, Riyad Bank, KSA. He has over 21 years of experience in the Banking industry, in areas such as Information Technology, Cyber & Information Security, Business Continuity Management & Disaster Recovery and related Audits. He has a solid understanding and application of Risk-Based Audit methodology, ISMS (ISO 27001), ISO 22301, NIST and COBIT, IT & Information Security regulatory compliance.

He is double Graduate (Finance and Computer Science) with one Master’s Degree in Computer Science. In addition, he holds a number of professional certifications such as CISA, CISM, CRISC, CDPSE, CISSP, PMP, CEH, ISO 27001 ISMS Lead Implementer & ISO 22301 BCMS.

Tariq has published articles on different topics of Cyber & Information Security and IT Audit and also spoken at regional and international seminars and conferences.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.