Home Blog Page 21

89% of Organizations Are Non-compliant With CCPA Law

California Consumer Privacy Act, Hanna Andersson to Pay $400K to Settle CCPA-related Class-Action Lawsuit

Data regulations and privacy laws will go in vain if users and organizations do not obey them. Recent research from Cytrio, a data privacy compliance company, revealed that only 11% of organizations are fully meet California Consumer Privacy Act (CCPA) requirements, especially when managing Data Subject Access Requests (DSARs). And 89% of companies are either non-compliant or somewhat compliant.

The research, State of CCPA Compliance: Q1 2022, report found that 44% of organizations did not provide any mechanism for consumers to exercise their data rights, disconnecting themselves in compliance. Most organizations failed to implement CCPA regulations despite stating they needed to comply.

What is California Consumer Privacy Act?

The California Consumer Privacy Act (CCPA) was passed in 2018 and took effect on January 1, 2020. The Act gives California citizens data and privacy rights regarding how organizations use their data. Under the CCPA, users have the right to:

  • Know what personal information is being collected.
  • Know whether their data is being traded.
  • Say “No” to the sale of their information.
  • Request an organization to delete their sensitive data.
  • Not be victimized for exercising their privacy rights .

Organizations that fail to meet compliance with the CCPA may attract a penalty ranging between $2,500 to $7,500, based on the data violation type.

Companies Being Non-Compliant to CCPA

The research found that 45% relied on inefficient and costly manual processes such as email and web forms for submitting and responding to data requests. Less than 11% of companies use DSAR management automation solutions. Only 15.6% of companies in California had a DSAR management automation solution, and 59.3% of them used manual processes.

The research surveyed over 5,175 U.S. companies with revenues ranging from $25 million to more than $5 billion.

Also Read: California Consumer Privacy Act Puts Additional Pressure on Financial Organizations

“The findings of our research show that companies are woefully unprepared for CCPA compliance, especially when it comes to enabling and responding to consumers’ data privacy rights. An overwhelming majority manually responds to data requests, with only a small number implementing DSAR management automation solutions. The reliance on manual processes exposes them to high DSAR compliance costs, long response times, errors that will erode consumer trust, and non-compliance actions by the California Privacy Protection Agency (CPPA),” said Vijay Basani, founder and CEO of CYTRIO.

Other Key Findings:

  • Although B2C companies collect more consumer data, there was no statistically significant difference in the number deploying DSAR management automation solutions compared with B2B companies (11.3% for B2C vs. 10.3% for B2B)
  • Large companies (with more than 10,000 workers) were more likely to have a commercial DSAR management automation solution. Over 60% did so with the increasing number of DSARs and streamlining related costs as potential reasons.
  • Highly-regulated industries lagged in commercial solution deployment, including health care, financial services, and insurance.
  • There is a strong correlation between revenue and deploying a DSAR management automation solution. High revenue earners (companies over $100 million) were more likely to have an automated solution, with companies over $5 billion in revenues especially eager.

“Overall, the survey results show that more needs to be done for CCPA compliance, and many lack the right resources and tools to meet the requirements. The prevalent reliance on manual processes and the inability to address DSAR may increase the risks of a company’s operations and shows we have more work to do in building awareness,” said Darshan Joshi, Chief Technology Officer at CYTRIO.

Avoid Negotiating with Extortioners and Implement Solutions for Recovery and Resilience

Cybersecurity Predictions

Once impacted by ransomware and other attacks, organizations spend a lot of time and money trying to recover systems. Many negotiate with attackers and even pay off the ransom. This is a reactive approach. My advice would be avoid negotiating with extortioners. Rather, they should deploy resilient technology like immutable backups that will help recover from attacks like ransomware. Here are my three predictions for 2022.

By Zachery Mitcham, MSA, CCISO, CSIH, VP and Chief Information Security Officer, SURGE Professional Services-Group

1. Introduction of Artificial Intelligence (AI) into cyberattacks. We can’t just dismiss cybercriminals as being unsophisticated imbeciles. It would be a mistake if we did. Cybercriminals are now using computer generated hacking algorithms to create more persistent and efficiently resilient cyberattacks, yielding incredibly favorable results. AI-generated attackers don’t have the weaknesses associated with their human counterparts. They don’t grow weary of trying heuristically to access their targets’ networks. Consequently, they continue until they achieve their ultimate objective.

2. Increase in Cryptojacking. Criminals hacking criminals does not get a lot of press. After all, who cares, right? Wrong! Cryptojacking, if left unchecked, will bleed over to legitimate enterprise activities. Cryptomining of blockchain-generated cryptocurrency has become more attractive to cybercriminals of late. Hackers are leveraging the resources of legitimate computer systems to launch attacks against dark side extortioner sites. The criminals feel like they will go unpunished in that they are attacking the financial resources of a hacker, and no one would care. In the final analysis, who can the criminals being victimized, voice their complaints to?


Also see: How Cryptojacking and Cryptomining Assaults Work

3. Increase in the implementation of immutable backup systems. This will reduce the impact of ransomware attacks.  More organizations have established positions of not negotiating with cyber extortioners. They are deploying technology that will assist them in recovering quickly from cybercrime in the form of ransomware. One technology, in particular, is that of immutable backups. Regular backups offer some resilience against such attacks, but not much. If they themselves are compromised, they are rendered useless. On the other hand, an immutable backup is a backup that cannot be modified or altered by the intruder, thereby making it easier for an organization to recover from a ransomware attack.

Read more predictions from other experts in our January 2022 issue.


About the Author

Zachery-MitchamZachery S. Mitcham is a 20-year veteran of the United States Army where he retired as a Major. He earned his BBA in Business Administration from Mercer University Eugene W. Stetson School of Business and Economics. He also earned an MSA in Administration from Central Michigan University. Zachery graduated from the United States Army School of Information Technology where he earned a diploma with a concentration in systems automation. He completed a graduate studies professional development program earning a Strategic Management Graduate Certificate at Harvard University extension school. Mr. Mitcham holds several computer security certificates from various institutions of higher education to include Stanford, Villanova, Carnegie-Mellon Universities, and the University of Central Florida. He is certified as a Chief Information Security Officer by the EC-Council and a Certified Computer Security Incident Handler from the Software Engineering Institute at Carnegie Mellon University. Zachery received his Information Systems Security Management credentials as an Information Systems Security Officer from the Department of Defense Intelligence Information Systems Accreditations Course in Kaiserslautern, Germany.

Global Affairs Canada Hit by Cyberattack

canada

Unknown cybercriminals targeted Canada’s foreign ministry Global Affairs Canada (GAC), in a cyberattack. The incidents affected certain critical services and disrupted some online services temporarily.

“Critical services for Canadians through @GAC_Corporate are currently functioning. Some access to the Internet and internet-based services are not available as part of the mitigation measures, and work is underway to restore them. There is no indication that other departments have been impacted by this incident. There are systems and tools in place to monitor, detect, and investigate potential threats, and to take active measures to address and neutralize them when they occur,” said a statement from Canada’s Treasury Board

Investigation is Ongoing

While the officials did not mention the attackers behind the security incident, the security officials stated that a probe had been initiated to find the details.

Also Read: Canada Revenue Agency Shut Down Services after Cyberattacks

“This investigation is ongoing. We are unable to comment further on any specific details for operational reasons. Our cyber defense and incident response teams work 24/7 to identify compromises and potential alert victims within the GC and Canadian critical infrastructure. The incident response team offers advice and support to contain the threat and mitigate any potential harm,” the statement added.

Canada’s Cybersecurity Guidance

The cyberattack news comes immediately after the Canadian Centre for Cybersecurity warned critical infrastructure operators to raise awareness and take mitigations against known Russian state-sponsored hackers.

The Cyber Centre urged Canadian critical infrastructure network defenders to:

  • Be prepared to isolate critical infrastructure components and services from the internet and corporate/internal networks if those components would be considered attractive to a hostile threat actor to disrupt. When using industrial control systems or operational technology, perform manual controls to ensure that critical functions remain operable if the organization’s network is unavailable or untrusted.
  • Increase organizational vigilance. Monitor your networks, focusing on the TTPs reported in the CISA advisory. Ensure that cybersecurity/IT personnel are focused on identifying and quickly assessing any unexpected or unusual network behavior. Enable logging to better investigate issues or events.
  • Enhance your security posture: Patch your systems with a focus on the vulnerabilities in the CISA advisory to enable logging and backup. Deploy network and endpoint monitoring (such as anti-virus software), and implement multifactor authentication where appropriate.
  • Have a cyber incident response plan, a continuity of operations, and a communications plan, and be prepared to use them.
  • Inform the Cyber Centre of suspicious or malicious cyber activity.

What is DNS Tunneling and How is it Prevented?

DNS attacks

Hacker intrusions on organizations’ Domain Name Systems (DNS) have become prevalent in recent times. According to the 2021 Global DNS Threat Report from network security automation solutions provider EfficientIF, nearly 90% of organizations sustained a Domain Name System (DNS) attack last year. Threat actors exploit vulnerabilities in the DNS to access the targeted network systems. Cybercriminals use various hacking tactics to compromise critical digital assets, and one of them is DNS Tunneling.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

DNS is an important protocol that plays a critical role in web browsing and email services. DNS enables applications and service platforms to use domain names (like cisomag.com) rather than IP addresses.

What is DNS Tunneling?

DNS tunneling is a malicious activity leveraged by threat actors to bypass the firewall and tamper with DNS queries and responses protocols. In a DNS tunneling attack, hackers use data payloads to compromise the targeted DNS server and remotely take over operations.

How Does DNS Tunneling Work?

Initially, hackers deploy the malware into DNS queries to create a covert communication channel bypassing security scans. This will enable bad actors with a backchannel to exfiltrate sensitive data from the compromised DNS.

DNS attackers then tunnel protocols like SSH or HTTP in the DNS server and stealthily tunnel IP traffic. DNS tunneling technique allows attackers to transfer files, download additional payloads to the existing malware, and gain complete remote access to the targeted system.

How to Identify DNS Tunneling Attacks

DNS misuse can be identified in two ways:

  1. Payload analysis – Identifying unnecessary or unusual information received by the DNS server. Security admins can look for odd hostnames, a new DNS record type, or unique character sets.
  2. Traffic analysis – Evaluating the number of DNS domain requests received compared to the normal traffic. DNS attackers usually send huge traffic to the compromised DNS server, traffic that is greater than a normal DNS exchange.

How to Prevent DNS Tunneling

  • Keep a close track of suspicious domains and IP addresses from unknown sources.
  • Configure all internal clients to send queries to an internal DNS server to filter any suspicious domains.
  • Always monitor DNS traffic and be vigilant for suspicious domains to mitigate the risks of DNS tunneling.
  • Configure a DNS firewall to identify and prevent any hacker intrusion.
  • Enable real-time DNS solutions that detect unusual queries and patterns on the DNS server.

About the Author

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.

 

Shifting from a Reactive to a Proactive Cybersecurity Paradigm

Proactive Cybersecurity Paradigm, cyberwar, IoT, 5G, Boardroom, Identity Detection and Response, Predictions, supply chains, hybrid workforce

For too long organizations have taken a reactive approach to dealing with threats and breaches. Incident reporting and incident response have been slack. But as the volume and sophistication of attacks have increased, it is time for organizations to take a more proactive approach. So among my three predictions, I mention proactive cybersecurity. Federal agencies will institute more aggressive and proactive requirements for operations and resources under their direction.

By Christina M. Gagnier, Shareholder, Carlton Fields

Here are my three key things that policy makers and organizations need to do in 2022.

Implementation of new requirements from government agencies on cybersecurity. Federal agencies will institute more aggressive and proactive requirements for operations and resources under their direction. The Transportation Security Administration is a prime example, as in December it announced requirements for passenger and freight rail operators to conduct vulnerability assessments, create incident response plans, and institute recovery mechanisms to avoid disruptions in operations in the wake of potential security breaches. Agencies will further prioritize reporting and oversight, creating focal points and coordination for data security incident reporting. The White House has announced programs to bolster the protection of the United States’ water supply, instituting cybersecurity measures to close the vulnerability gaps that exist due to the multiplicity of organizations that have a hand in the stewardship of this critical national resource.

Regulation of consumer data privacy and security at the device and product level. The privacy and security conversation surrounding the Internet of Things has centrally developed around the applications that leverage these advancing technologies, with much focus on companies creating applications that can be applied to certain devices or products rather than evaluating the devices and products themselves. In the United Kingdom, newly introduced legislation, the Product Security and Telecommunications Infrastructure bill, aims to share the cybersecurity burden with manufacturers and distributors of IoT devices, ranging from smartphones and tablets to smart home appliances. The change is a reflection of the identification of these devices and products as a point of vulnerability and target for hackers. A whole new sector of businesses will need to turn their attention to implementing robust privacy and security programs.

Incentives for businesses to develop cybersecurity infrastructure: Across the United States in recent years, state legislatures considered a variety of bills that would have created incentives for businesses that invest in cybersecurity. In Connecticut, H.B. 6161 was introduced, which had it been adopted, would have created a safe harbor tax incentive for any business that had a cybersecurity plan reflecting industry best practices. In Hawaii, H.B. 454 would establish an income tax credit centered on businesses that innovate in the fields of cybersecurity and artificial intelligence. This “carrot versus stick” approach has traction, and the 2022 state legislative cycle will likely see more bills of this nature.

Read more predictions from experts in our January 2022 issue.


About the Author

 Christina M. Gagnier, Shareholder, Carlton FieldsChristina Gagnier, a shareholder in Carlton Fields’ Los Angeles office, is an experienced technology lawyer whose practice focuses on cybersecurity and privacy, blockchain technology, international regulatory affairs, technology transactions, and intellectual property. She advises clients on digital strategy to help them navigate uncharted legal territory, and guides a variety of technology companies and consumer brands through emerging legal and policy issues such as digital currency, the sharing economy, network neutrality, and the ever-changing area of consumer privacy law.

Over Half of Medical IoT Devices Found Vulnerable to Cyberattacks

Medical Devices

After a year of unprecedented cyberattacks on several hospitals and medical centers across the globe, the health care sector has become a primary target to threat actors. In addition to exploiting patients’ data and disrupting hospital networks, cybercriminals are now targeting critical connected-medical devices deployed in hospital environments.

According to research from Cynerio – a health care IoT security platform, several medical IoT devices are prone to cyberattacks exposing hospitals and patients’ data to various cyberthreats. In its 2022 State of Healthcare IoT Device Security Report, Cynerio stated that medical IoT security has remained unaddressed despite increased healthcare cybersecurity investments. It’s found that nearly 53% of connected medical devices and other IoT devices in hospitals have known critical vulnerabilities. If compromised, these vulnerabilities could allow an attacker to perform multiple criminal activities like impacting service availability, data confidentiality, or patient safety.

Key Findings:

  • IV pumps make up 38% of a hospital’s routine health care IoT footprint, and 73% of these have a vulnerability that could jeopardize patient safety, data confidentiality, or service availability if it were to be exploited by an adversary.
  • Devices running versions older than Windows 10 account for most devices used by pharmacology, oncology, and laboratory devices and make up a plurality of devices used by radiology, neurology, and surgery departments, leaving patients connected to these devices vulnerable.
  • The most common IoMT and IoT device risks are connected to default passwords and settings that attackers can often obtain easily from online manuals, with 21% of devices secured by weak or default credentials.
  • Network segmentation can address over 90% of the critical risks presented by connected medical devices in hospitals and is the most effective way to mitigate most risks presented by connected devices.

Also Read: How Brainjacking Became a New Cybersecurity Risk in Health Care

“Health care is a top target for cyberattacks, and even with continued investments in cybersecurity, critical vulnerabilities remain in many of the medical devices hospitals rely on for patient care. Visibility and risk identification is no longer enough. Hospitals and health systems don’t need more data – they need advanced solutions that mitigate risks and empower them to fight back against cyberattacks, and as medical device security providers, it’s time for all of us to step up. With the first ransomware-related fatalities reported last year, it could mean life or death,” said Daniel Brodie, CTO, and co-founder, Cynerio.

Medical IoT Devices and Cybersecurity

With multiple intrusions and attacks on connected medical devices, the health care providers continued to be the primary target for cybercriminals. However, the most concerning issue for the health care sector is cyberattacks on implanted medical devices. Several cybersecurity experts stated that threat actors can hijack certain connected medical devices implanted in a human’s body or brain — they are calling this Brainjacking. Read More Here

Data Privacy Week: The 3 Ps Vital to Enhancing Your Online Data Privacy

Data Privacy Week

With cybersecurity awareness being a primary topic for security leaders, Data Privacy Week (January 24-28) is a good time to reflect on the importance of data protection and privacy against rising cyberattacks. According to a Pew Research Center Study, nearly 79% of U.S. adults reported concerns about how organizations are using their data. And 81% of them feel they have little to no control over data being collected by companies.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Targeted data breaches have surged exponentially after peddling stolen data on dark web forums became a lucrative revenue model for cybercriminals. Most users are unaware of how their sensitive data is collected, used, or shared in the current digital world. Not only companies, but it is also the responsibility of users to know where their sensitive data is going, and how to protect it against misuse.

Data Privacy Week

Data Privacy Day observes the first legally binding international treaty dealing with privacy and data protection, signed on January 28, 1981. The day is recognized every year on January 28 in the U.S., Canada, and Europe. In 2022, National Cybersecurity Alliance (NCA) has expanded the Data Privacy Day campaign into Data Privacy Week, which is observed from January 24 to 28. The Data Privacy Week helps spread data privacy awareness and alerts users on protecting their information online.

3 Ps to Enhance Your Data Privacy Online

1. Practice

One cannot become cyber-aware overnight, but practicing certain security measures will help prevent most security risks online.

Users’ sensitive information is like money for threat actors. Personal data like usernames, passwords, geolocation, purchase history, IP address, full names, birthdates, and banking details have a huge demand on darknet forums, where hackers often trade stolen data. Following cyber hygiene practices like keeping strong passwords to all your online accounts and limiting your personal data available online will eventually enhance your data privacy. Own your data privacy by securely deciding whether to share or not to share your data with all service providers online.

2. Protect

Threat actors often exploit/compromise targeted devices to steal sensitive information. Recently, security researchers from Doctor Web discovered a new Trojan that infected over 9.3 million Android devices. The Trojan, dubbed “Android.Cynos.7.origin,” is a new kind of malware that disguises itself as a legitimate app and steals information from a victim’s device, such as contact details, and displays unwanted ads.

Device protection is imperative for users and organizations as hackers leverage various malicious or Trojanized applications to penetrate network systems and steal personal data. To protect your data and prevent unauthorized intrusions you should regularly update your devices and fix any unpatched vulnerabilities.

3. Prevent

Ignoring unwanted emails and texts from unknown sources will help prevent hacker intrusions. Several cybercriminal campaigns leverage different kinds of phishing lures and social engineering tactics to trick unwitting users into downloading malware.

As we head into Data Privacy Week, it’s the right time for users and organizations to evaluate their security measures and boost the overall cybersecurity posture.

What the Experts Say…

KeithCommenting on the significance of Data Privacy Day with CISO MAG, Keith Neilson, Technical Evangelist at CloudSphere, said, “In the U.S. alone, there are several disparate federal and state laws, some of which only regulate specific types of data – like credit or health data, or specific populations – like children. Combining these regulations with the many different international laws that aim to ensure data privacy, such as GDPR, and compliance for companies with global operations becomes an extremely complex undertaking.

Data Privacy Day serves as a reminder that cyber asset management should be a top priority for every organization. Enterprises cannot ensure compliance and data security unless all assets are properly known, tagged, and mapped in the cloud. To avoid jeopardizing sensitive company or customer data, organizations must take the first step of cyber asset management to secure visibility of all cyber assets in their IT environment and understand connections between business services. This includes identifying misconfigurations and automatically prioritizing risks to improve overall security posture, allowing for real-time visibility and management of all sensitive data.”

About the Author

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.

 

Countries Now See Cyberspace as a Legitimate Realm to Create Strategic Outcomes

Proactive Cybersecurity Paradigm, cyberwar, IoT, 5G, Boardroom, Identity Detection and Response, Predictions, supply chains, hybrid workforce

More countries are now leveraging the cyberspace in warfare and you can see that with the most current news (the Russia-Ukraine conflict). This year you will see nations conniving with APT groups to deploy new methods of attack for cyberwar. Here are my three predictions for 2022.

By Dick Wilkinson, Chief Technology Officer at Proof Labs

2022 will see more proliferation of ransomware and likely a higher average payout for each attack. This trend has been ongoing for several years and does not seem to be nearing a peak or plateau. The relative impunity available to ransomware criminals means there is no end in sight other than the market capacity of how much companies are willing to pay. If you successfully robbed a bank and knew you couldn’t get caught, wouldn’t you do it again?

The good news for 2022 is the increase in cyber professionals entering the workforce. The labor shortage in cyber skills has been well documented, with projections showing the gap widening soon. The projections may be wrong. The recent upheaval in so many people’s careers has caused a significant shift to security roles where a new certification vs. a new degree could land you a great job. Barriers to entry in the security market are also being identified and actively changed by many industry hiring managers. The skills gap won’t close this year, but the tide has likely shifted in the right direction.

I believe we may globally see some cyber “firsts” where nation-states or APT groups deploy a new method of attack that was previously held back for political concerns. Many countries now see cyberspace as a legitimate realm to create strategic outcomes. The unspoken agreement to use cyberspace as a battlespace for proxy agitation, and escalation will be more obvious this year and some players will not hold back on the more damaging attacks any longer. Criminal APT groups are already part of the proxy nature of cyberwar being directly controlled and funded by nation states. Their involvement will rise, but the veil of secrecy on who they work for will become thinner.

Also see:

With Cyberwars, Cyber Espionage has Reached New Level


About the Author

Dick_WilkinsonDick Wilkinson is the Chief Technology Officer at Proof Labs. He also served as the CTO on staff with the Supreme Court of New Mexico. He is a retired Army Warrant Officer with 20 years of experience in the intelligence and cybersecurity field. He has led diverse technical missions ranging from satellite operations, combat field digital forensics, enterprise cybersecurity as well as cyber research for the Secretary of Defense.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

40 Billion User Records Exposed Globally in 2021

data breaches, Verizon Data Breach Investigation Report

Cybercriminals often exploit leaked/stolen sensitive user information to perform various cyberattacks, including phishing and identity theft. The rising information leaks on dark web forums show that no one is immune to data breach incidents. As per research from Tenable, a cyber exposure company, over 40 billion records were exposed worldwide in 2021.

Tenable’s Security Response Team analyzed 1,825 data breach incidents disclosed between November 2020 and October 2021. The analysis included in the 2021 Threat Landscape Retrospective (TLR) report revealed an overview of the attack vectors, vulnerabilities, and insights that will help organizations prepare for the upcoming security challenges in 2022.

Some 21,957 common vulnerabilities and exposures were reported in 2021, representing a 19.6% increase over the 18,358 reported in 2020 and a 241% increase over the 6,447 disclosed in 2016. From 2016 to 2021, vulnerabilities increased at an average annual percentage growth rate of 28.3%.

The top vulnerabilities in 2021 include:

  1. CVE-2021-26855 — Proylogon, Microsoft Exchange Server
  2. CVE-2021-34527 —  Printnightmare, Windows Print Spooler
  3. CVE-2021-21985 —    VMWARE VSPHERE
  4. CVE-2021-22893 —  Pulse Connect Secure
  5. CVE-2020-1472 —  Zerologon, Windows  Netlogon Protocol

Also Read: Suffered a Data Breach? Here’s the Immediate Action Plan

Other key findings from the report:

  • Ransomware had a monumental impact on organizations in 2021, responsible for approximately 38% of all breaches.
  • 6% of data breaches were the result of unsecured cloud databases.
  • Unpatched SSL VPNs continue to provide an ideal entry point for attackers to perform cyberespionage, exfiltrate sensitive and proprietary information, and encrypt networks.
  • Threat groups, particularly ransomware, have increasingly exploited vulnerabilities and misconfigurations in Active Directory.
  • When security controls and code audits are not in place, software libraries and network stacks commonly used amongst OT devices often introduce additional risks.
  • Ransomware groups favored physical supply chain disruption as a tactic to extort payment, while cyberespionage campaigns exploited the software supply chain to access sensitive data.
  • Health care and education experienced the greatest disruption from data breaches.

“Migration to cloud platforms, reliance on managed service providers, software, and infrastructure as a service have all changed how organizations must think about and secure the perimeter. Modern security leaders and practitioners must think more holistically about the attack paths within their networks and how they can efficiently disrupt them. By examining threat actor behavior, we can understand which attack paths are the most fruitful and leverage these insights to define an effective security strategy,” said Claire Tills, Senior Research Engineer, Tenable.

‘Illegal Crypto Mining is a Huge Drain on a Nation’s Power Resources’

Illegal Crypto mining

Hackers and ransomware groups have benefitted immensely by leveraging blockchain and cryptocurrencies to secure multi-million-dollar payouts. Cryptocurrency transactions are untraceable and not regulated by any government or authority. But hackers are now taking this further by attacking crypto exchanges and stealing coins from user wallets. They also indulge in illegal crypto mining activities – using thousands of compromised computers to mine coins. Crpto mining utilizes a great amount of electricity from the grid. Due to this, there have been power shortages in some countries.

CISO MAG got in touch with Amit Jaju, a Senior Managing Director with Ankura Consulting, to discuss these challenges.  It was startling to learn from Amit that global temperatures will increase by two degrees by 2024 due to crypto mining activities. You will be amazed to learn how much power is consumed for every cryptocurrency transaction when the blockchain ledgers are updated. Amit offered some suggestions for crypto exchanges during our discussion to protect user wallets. He also suggests what regulators and governments can do to protect consumers.

Amit leads the Data & Technology Segment at Ankura Consulting in India. He has over 17 years of experience in forensic technology consulting covering data analytics, cyber, e-discovery, software licensing, and information governance. He has created market-leading solutions around financial crime, cyber incident response, analytics, and software licensing and delivered engagements for global and Indian clients in over 20 countries. His experience spans multiple sectors, including Financial Services, Information Technology, Pharmaceuticals, and Media & Entertainment.

He has led many complex global data analytics engagements, including implementing and managing enterprise-wide fraud and AML monitoring solutions for banks and implementing terrorism monitoring over the internet for defense services. He has delivered sanctions diagnostics, and investigation engagements across Europe and the Middle East for large US sanctions matters and has developed a sanctions analytics platform to deliver end-to-end sanctions diagnostics and monitoring.

Before joining Ankura, Amit was a Senior Managing Director and India head for FTI Consulting, Partner with Ernst & Young for nine years as Head of Forensic Technology in India and Markets. He was responsible for setting up and leading Forensic Technology in EMEIA. Before EY, Amit was the Forensic Technology lead at KPMG in India for five years. Previous to joining the Big Four, Amit worked with a boutique information security consulting firm.

Edited excerpts from the interview follow:

We have seen a lot of illegal crypto mining activities around the world in countries like Iran, Venezuela, Malaysia, the UK, Kazakhstan, and the U.S. Tremendous computational power is required for Bitcoin mining, which even leads to power outages directly impacting electricity prices. Are there any studies to back this? What impact will this have on the environment and resources like power?

That is a very important point, and it is getting missed out in many conversations around crypto. I think this is one of the most important points on adopting  crypto and the blockchain itself. A few months ago, I made a LinkedIn post to initiate a conversation with my network on this aspect. One study said that just with crypto mining, the global temperature will shoot up by two degrees centigrade by 2024. That is two degrees in two years, and it is a significant increase.

A Cambridge Institute study says that around 0.5% of global electricity production could be utilized by crypto mining. That is roughly the annual energy utilization of small countries like Sweden or Malaysia. That is how bad it is. And when you look at carbon emission, we have some data points, but of course, it needs further verification. I see a trend in terms of where all the numbers are. So, just for larger countries where a lot of this mining is happening, for instance, in China, they say that 130 million metric tons of CO2 is the net contribution.

I talked to a friend of mine running a carbon credit trading company. It is a listed company. I was surprised by the numbers he gave me. And very few know about these numbers. Look at it in terms of a single cryptocurrency transaction. You are running complex mathematical calculations to validate that transaction. This requires tremendous computational power, which consumes a lot of power. In terms of energy consumption, if you do a Bitcoin transaction, it uses the equivalent power to process two million standard credit card transactions. That is the energy it takes to watch up to 160,000 hours of YouTube videos. So, imagine YouTube servers running and consuming all that energy. You have to watch 160,000 hours of video for one Bitcoin transaction because you need certain numbers of confirmations to validate a transaction at the end of it. This transaction will replicate across all ledgers at the end of the day. So, by the time that replication happens, that is the amount of energy it will use. In simpler terms, it is equivalent to 70 days of the total energy that a typical U.S. household will consume for one Bitcoin transaction.

What impact could this have on the energy resources of a nation? How do governments address this?

I think we need to at least start talking about the problem. Awareness related to the environmental impact of cryptocurrency and crypto mining is not at the forefront. We need to discuss it, get different experts to provide their opinions, and formulate some policies. You must create a framework around it and involve the experts. For example, if you need to identify illegal crypto miners who use hundreds or thousands of machines for illegal crypto mining, you need to use data analytics for that. In Venezuela, for instance, they have a history of illegal miners, and because of this, they had a power crisis. So, they used data analytics to identify 100 miners and take legal action.

We need regulation and then analytics. I know India has a draft bill on cryptocurrencies. It will be interesting to see whether crypto mining is addressed in it — or is it just about trading cryptocurrencies, because mining itself is an important piece. This is especially true for India, where most of our power gets generated from non-renewable sources. Today, we are fast moving towards renewable sources. And I have seen that a lot of miners go towards colder regions. That is because less cooling is required, and it is a very thin margin kind of enterprise. So, if you can reduce your cooling bill, that is a lot of savings. It is generally concentrated towards colder regions of the world where they do that. I think governments need to proactively address this through various means.

Cryptocurrency Exchanges are the new attack targets for hackers. A recent example is BitMart, which lost approx. $150mn in cryptocurrency assets. Attackers had stolen a private key and compromised two of the exchange’s hot wallets on the Ethereum (ETH) blockchain and the Binance smart chain (BSC), making off with approximately $150 million worth of assets; in a “large-scale security breach.”

What can the exchanges do to protect themselves and their users? What do users need to do to protect their Hot Wallets? Since these are not centrally regulated, what kind of legal provisions are in place to enable the exchanges to penalize attackers when they are traced? We have seen how the big exchanges were brought down completely, and some went out of business overnight. And that is the weak link; crypto exchanges do not make only trades, but they are quasi custodians of your wallet, and they have access to your wallet because your private key is stored with them. It is on the blockchain, though. It is impossible to offer 100% protection for exchanges, because cyber is an area where you always have to plan for contingencies.

But I am reading more about the zero-trust model, which I think is valuable for exchanges. It is often an insider attack, or the attack vector is within the company, which gets exploited. It could be an employee or vendor who has access to maintenance. Or perhaps a developer writing the code for the trading platform has intentionally created some backdoors. There are incidents where ransomware hackers pay employees a commission of up to 20% to run a file on the server. You can never rule out insider involvement.

To address this, you need to look at independent custodians; for our capital market exchanges, we have CDSL (Central Depository Services Limited) and NSDL (National Security Depository Limited) as independent custodians of our DMAT accounts. That is where our shares reside. So, these independent custodians will ask us for an OTP verification for the transaction – and not the exchanges. Similarly, we could have independent custodian firms as custodians of the wallets. There could be a model where the offline wallets are with the end customer. And the offline wallet could automatically sync with the exchanges. So, the exchanges are not keeping your coins or tokens.

The offline wallet (cold wallet) could be backed up to a USB pen drive, laptop, or phone. It could be on a piece of paper. You could print out certain words, and that is your coin. So having a tiered approach to storing these coins is more secure. On the other hand, having all your coins with the exchange is risky because they also have your private key.

So, to strengthen their defenses, a zero-trust model with independent custodians, plus a hybrid wallet model, also de-risks the exchanges. Of course, that will result in some disruption to their business models. For example, some exchanges deposit your coins for an annual percentage return. This may not be possible in such cases, but the risk is far higher for an exchange that has your wallets online with them (hot wallets).

Are you suggesting a mix of cold and hot wallets? What else could be done to ensure resiliency and minimize downtime due to code vulnerabilities being exploited?

Yes, hybrid wallets. You have the wallet at the exchange keeping the user data, but then it gets transferred T +1 or end of the day to the user’s wallet (cold wallet), which resides with them offline. Both cold and hot wallets could be used during a trading session.

I think trading platform resilience is very important. That is always the case, with capital market exchanges or crypto exchanges. Trading platforms are high-frequency platforms, so you have millions of texts transmitted in one second, resulting in an order getting placed. The coding of that must be robust to facilitate the performance. But at the same time, looking at it from a security perspective is very important. It is about making sure every source code or application developed is reviewed thoroughly by multiple parties. Changes should be tracked from a security perspective, not just a functionality perspective. If something goes down, they should revert to the older version to ensure that the exchange runs. Crypto exchanges run 24×7 unlike our captive market exchanges, which shut down in the afternoon or the evening. Market exchanges have time for maintenance and upgrades. But that is more difficult for crypto exchanges since they run 24×7. So, they must have backup environments. And it’s slightly complicated, but by ensuring that the trading platform is thoroughly checked, they can provide defenses to implement two-factor at every stage. And when you implement a zero-trust model, a lot of that gets addressed.

What do you see as the big trends coming in 2022? What are the opportunities that exist?

I closely monitor the developments around quantum computing. Some companies are very close to building a retail version of a quantum computer. Whenever such a computer is available, it will transform this space overnight.

I also look at the zero-trust model and how it is evolving because I think that is a very good model to address all the challenges we face with our existing perimeter security and access control model.

I am also looking at the personal data protection regulation and the new challenges and opportunities that it will create. Compliance is a challenge for corporations trying to protect their data assets. It is also about individuals knowing their privacy rights and options if that data gets stolen or compromised.

There are opportunities too. The multinationals will have to build an infrastructure within India to address all the data-related challenges within the country (data residency). There is a huge demand for workforce and technology components, which India can address because we have a lot of talent. But we must see how different sectors adopt it. We already see financial services adapting to data localization, even though some companies take longer. I am seeing this with other industries such as pharmaceutical and life sciences, from data privacy and data confidentiality perspectives. Here they will focus more on protecting their IP and their data within the country. I see the measures they must put in place because these companies also deal with sensitive personal information of many people.

Take hospitals, for instance. Many U.S. hospitals have been impacted by ransomware in the past two years because they have sensitive personal data. Hackers know that they will not benefit much if they attack a steel company. But hospitals have critical data on which they rely for their operations, so the risks are higher.

In terms of technologies, we will see more use cases for blockchain. It will be used for transmitting documents and maintaining integrity, which is crucial.

Cybersecurity and forensics will also use blockchain. If you have an evidence chain of custody logs, how do you maintain the integrity and authenticity of that data? This is most important when something goes wrong. The insider threat is an area where companies will not trust a user because they are employees. They have to look at a customer, a vendor, or an employee, and observe how they behave. Based on that, they will profile the person and then create rules and access controls around the person’s behavior. Machine learning will play a key role because it is a rule-based analysis, and it cannot be done manually. All of this will be machine learning-based with human input for authorization. We will see more use of machine learning and artificial intelligence in cybersecurity. This is a space to watch out for.


About the Interviewer

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 27 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

More stories from Brian