Home Blog Page 211

Financial Organizations Lack Trusted Data to Make Security Decisions: Report

Financial Sector

A research from security firm Panaseer revealed that cybersecurity leaders in financial organizations are facing issues due to the lack of trusted data that is required to make security decisions and reduce the risk of cyberthreats.

The research “2020 Financial Services Security Metrics Report” found concerns on security measurement and metrics that include data confidence, resource wastage, manual processes, and request overload.

The report exposed multiple issues with the processes, people, and technologies required to have a full understanding of an organization’s cyber posture and the preventative measures. Nearly 96.77% of respondents admitted that they use metrics to measure their cybersecurity posture. While the primary use for security metrics is risk management (41.69%), demonstrating the success of security initiatives (28.04%), supporting security investment business cases (19.11%), and for executive reporting (10.17%).

Around 36.72% of security leaders said that their biggest challenge is trust in the data when creating metrics to measure and report on risk. However, 47.75% could claim to be confident that they are using the right security metrics to measure cyber risk.

Other Key Findings include:

  • Metrics have become increasingly important for security leaders. 96% of security leaders use metrics for measuring cybersecurity posture and reporting to a growing group of stakeholders, such as the board, regulators, auditors, and customers.
  • The security team is facing an overload of requests for metrics. This overload of requests can also have a serious knock-on effect as security teams divert resources from investigation and response to emerging threats.
  • Teams are wasting an inordinate amount of time processing and reporting on metrics. Security teams are spending more than 290 work hours per month on reoccurring and ad-hoc reporting to various stakeholders (outside of security department); most reporting time spent is for IT (44 hours or 5.5 days) and lines-of business (43 hours or 5.4 days).
  • Many security leaders do not trust the data they use. Over a third (37%) of security leaders said that the biggest challenge in creating metrics to measure and report on risk was trust in the data.
  • Reliance on manual processes fuels the metrics mistrust. Nearly 60% of security leaders are reliant on spreadsheets to calculate security metrics, while 53% use custom scripts.
  • Security leaders are aiming for better metric maturity. Nearly half describe their program as basic, elementary, or intermediate. However, two-thirds (65%) claim they want to be at upper intermediate or advanced stages for all audiences by 2021.

The research findings are based on the responses from more than 400 security decision-makers, working in companies within the financial services sector in the U.K. and the U.S.

“Financial service organizations in particular need trusted and timely metrics into their technology risk, segmented where possible to critical operations. With this information, the Board can then have better understanding into what risks it is and isn’t accepting to keep customer data safe,” said Nik Whitfield, CEO, Panaseer.

 

4 Critical Responsibilities of a CISO Post COVID-19

CEO, cybersecurity, CISO, Future of the CISO

Since the outbreak of the novel Coronavirus disease, organizations across the globe encountered dramatic changes in their business operations.  The swift adaption of the work from home strategy has increased the risks more than ever.  In addition, the ongoing crisis has significantly impacted the role of CISOs and other security leaders globally, making them digitally empathetic to deal with new cybersecurity challenges.

By Rudra Srinivas, Feature Writer, CISO MAG

The new cybersecurity priorities post COVID-19 that will become the new normal for most CISOs, will include:

1. Securing Remote Employees

With organizations working remotely, the security of employees’ devices became a major concern for security leaders across the globe. There was a rise in the need to secure endpoints,  as multiple access points from multiple locations are connected to a corporate network. However, the lack of security in remote work environments exposes vulnerable devices to potential cyberattacks.  New security policies  have been created and certain permissions are relaxed due to the swift change  in the remote work culture. Several industry experts stated that the surge in remote work increased the risks of cyberthreats like never before. The ongoing crisis forced CISOs to work uphill in order to meet the risk assessments.

2. Quick Actions Required

The ongoing crisis has forced organizations to go digital, overlooking potential cyber risks. These sudden developments could lead to cyberthreats like DDoS, defacements, and data breaches. At this point in time, it is essential for CISOs to patch the holes in their network security as quickly as possible.  This indicates that product research, purchasing tools, testing, developing, and deployment should ramp up quickly. CISOs across the globe are now looking for security tools that are configured instantly and easily to prevent new cyber risks.

3. Tackling New Attack Vectors

The threat actors have reinvented their attack approaches during the ongoing pandemic. COVID-19-related phishing scams, disinformation campaigns, weaponized websites, and malware infections have become widespread across the internet. Recently, a security firm discovered that threat actors distributed malware disguised as “Coronavirus Map” to steal personal information that is stored in the user’s browser. Attackers designed multiple websites related to Coronavirus information to prompt users to click/download an application to keep themselves updated about the situation.

In addition, the number of ransomware attacks on remote workers has also increased in recent times. Ransomware operators are forcing companies to pay a high ransom in order to get decryption keys. According to a recent survey, the average enterprise ransom payments increased 33% ($111,605) in Q1 of 2020 from Q4 of 2019.

4. Security Concerns with Third-Party Applications

Endpoint security at home is not as secure as it is in the office. Large swaths of remote workers are depending on third-party video conferencing apps, cloud-based productivity tools, and other virtual private networks during the lockdown. These are, in turn, exposing remote workstations to potential vulnerabilities that already exist within these applications.  Malicious actors are misusing  the crisis to exploit the loopholes in third-party products and services. Several privacy and security concerns associated with these apps resulted in severe criticism and cyberthreats globally.

For instance, the Zoom videoconferencing app  was flagged unsafe due to its vulnerability to cyberthreats.  Over 500,000 account credentials of Zoom users are being sold on the darknet. According to a research, hackers have shared a database containing more than 2,300 usernames and passwords of Zoom accounts on dark web forums. The FBI slammed Zoom for not maintaining proper privacy and security measures for its users. The authorities also warned that the video meeting app is prone to hacking, as it contains certain unpatched bugs.

Conclusion

When employees work from office, they are protected by a strong security infrastructure that has been put up in corporate network systems. But when the same workstation is operated from a different location and different network, it automatically increases the level of risk.  At this moment, it is crucially important to build an integrated cybersecurity architecture to secure the remote workforce. It is certainly a greater challenge for security leaders to monitor and protect the employees against malicious attacks with new demands coming in due the changing business model.

About the Author

 

Rudra Srinivas is part of the editorial team at CISO MAG and writes on cybersecurity trends and news features.

Automatically Update Cached Credentials for Remote Users

reusing passwords

The COVID-19 pandemic has completely changed our daily routines, including how we work. Businesses around the globe have asked their employees to implement work from home strategies in response to the outbreak. However, without the supporting infrastructure, technologies, and contingencies to enable a secure remote workforce, many businesses will face the shortcomings of their business continuity plan.

By Darren James, Product Specialist, Specops Software

Most users are working from home for the first time and lack basic cybersecurity training. IT admins are now tasked with managing this new infrastructure, and the vulnerabilities that come with it. To ensure the long-term continuity of their businesses, they need to secure the work from home network periphery.

The basis of any security, however, comes from having a strong base, and this base is built upon a strong password. A unique password is the first line of defense for any business system, be it the organization’s VPN network, official email service, or the employees’ endpoint devices.

“Password Reset” a Recurring Problem

A recent study showed that 78% of the surveyed respondents had reset the passwords for at least one of their personal accounts within the last 90 days. It also claimed that 57% of them had to perform a password reset for their work account. These numbers are concerning as Forrester Research estimates an average single password reset cost up to $70. According to META Group, an organization’s service desk receives an average of 21 calls per user every year, of which Gartner’s research estimates 20-50% of all calls are for password resets.

Managing the volume of password resets at the service desk can be time-consuming. Some of the most typical tickets are:

  • I forgot my Windows login password.
  • Help! I am unable to log in to my account.
  • Someone changed my password. I want to reset it now.
  • I want to recover my account. How can I change my user password?

And the list continues…

IT Admins and service desk managers must resolve passwords reset tickets quickly, otherwise, business continuity takes a hit. However, this becomes difficult when these requests are received from remote users, especially with no proper process in place for verifying the identity of the user.

The Problem with Remote Password Reset

Most organizations do not have a secure remote password reset process in place. Asking for employee IDs or answers to security questions for user verification is common, and leaves the service desk exposed to social engineering attacks. Even if the service desk successfully validates these users, additional challenges await.

When there is no domain controller in reach, cached credentials are used for user authentication. Employees working remotely will not have the means to update their cached credentials, even if the service desk does a manual password reset. When changing the password in AD, the service desk needs to untick the “user must change password at next logon” setting for remote users to allow the user to connect to the VPN, without the cached credentials stopping them. But, while doing so, they will now know the user’s password. This poses a new security risk at the service desk. Additionally, since most service desk employees use default passwords like test1, reset123456, 123@abc, during a password change, guessing the user password will be easy if left unchanged.

These problems cumulatively add to the woes of the IT Admins who receive large volumes of remote password reset tickets. The best way to overcome this barrier is to implement a self-service password reset solution.

AD Self-Service Password Reset

AD Self-Service Password Reset allows users to reset their passwords without contacting IT or the service desk. Be it an expired password, or a forgotten password issue, users can quickly unlock their account and reset their password, and continue working from the home, office, or on the go. One such AD Self-Service Password Reset tool is available from Specops Software.

With security features like multi-factor authentication and geo-blocking, the Specops password reset solution provides the high level of security you expect. It enables end-users to initiate the remote password reset process from any browser, mobile device, or right from the Windows logon screen of their remote workstations. The password reset solution from Specops also eliminates the cached credential problem for remote users by automatically updating the local credentials during a password change or reset.

Conclusion

Supporting a remote workforce can stretch the limits of your technology. In most organizations, there is a strain on the service desk, and remote password reset requests only consume more valuable time. The same amount of time, however, can be used to address other pressing issues in the organization’s business continuity plan.

Thus, to reduce the call volumes to the service desk due to account lockouts, IT teams need to use a self-service password reset solution which also provides an excellent ROI for efficiently managing remote users.

Learn more about how Specops can help you manage password reset requests.

Disclaimer

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Sodinokibi Operators Threaten to Hold ‘Online Auction’ of Madonna’s Stolen Data

Hive Ransomware

REvil operators, or better known as Sodinokibi operators, recently carried out a cyberattack on New York-based law firm Grubman Shire Meiselas & Sacks. In the attack, the cybercriminals claimed to have stolen nearly 756 GB data of several high-profile celebrities like Lady Gaga, Elton John, Robert DeNiro, and Madonna. After publishing the legal information related to Lady Gaga, the Sodinokibi operators have now threatened to hold an online auction of pop sensation Maddona’s stolen data, on May 25, 2020, at a reserve price of $1 million. Grubman Shire Meiselas & Sacks is a premier entertainment and media law firm handling the legal profiles of Hollywood A-listers. However, the firm was a target of Sodinokibi ransomware attack, which compromised confidential data including contracts, personal messages, email addresses, phone numbers, and other private and sensitive information of its clients.

The Sodinokibi operators are demanding a ransom of $42million. The cybercriminals threatened to release this highly confidential data in parts if the firm did not pay heed to their demands. In fact, as proof of withholding this information, they published the legal data of Lady Gaga online, which was immediately blocked and taken down.

A Glance at the Sodinokibi Ransomware

In a recent article by David Balaban, he explained the emergence, spread, and worry related to Sodinokibi ransomware. In late April 2019, researchers from CISCO Talos came across a strain of ransomware that raided a web server. The entry point was a remote code execution vulnerability in Oracle WebLogic Server software discovered about a week earlier. The analysts dubbed this infection Sodinokibi. Back then, it seemed that the predatory program was just another ransom Trojan resembling hundreds of others. However, Sodinokibi operators proved this impression wrong a few months later.

The Sodinokibi ransomware lineage is dominating the extortion landscape. It has made dozens of high-profile victims, including healthcare facilities and local governments. Furthermore, its distributors’ toolkit has expanded way beyond leveraging unpatched software flaws to gain a foothold in computer networks. It follows a Ransomware-as-a-Service (RaaS) model and the ransoms raked in by the crooks reportedly reach hundreds of thousands of dollars per compromised organization.

Ransom Payments Up 33% in Q1 2020; Sodinokibi and Ryuk Top the List

Owing to the higher penetration and success rate, the average enterprise ransom payments increased by 33% ($111,605) in Q1 of 2020 from Q4 of 2019, according to the Coveware Ransomware Marketplace Research report. It was found that Sodinokibi (used in 26.7% of attacks), Ryuk (19.6%), and Phobos and Dharma (7.8%) were the top three most used ransomware variants in Q1 of 2020.

Cyberattacks Increase As Cybercriminals Innovate Faster: NTT Report

New Programming Language

A research by technology services provider NTT Ltd. revealed that threat actors are developing sophisticated hacking tools and increasingly automating their attacks. The research, “2020 Global Threat Intelligence Report,” highlighted the challenges that organizations face and the importance of secure-by-design and cyber-resilience.

The research found that attackers are trying to financially gain from the COVID-19 pandemic crisis. It is revealed that malicious websites posing as official information sources of COVID-19 exceeded 2,000 new sites per day.

According to the report, organizations that rely more on web presence like customer portals, retail sites, and supported web applications are exposed to higher risks. Nearly 55% of all attacks in 2019 were a combination of web-application and application-specific attacks which wasup from 32% in 2018. Around 20% of attacks targeted CMS suites and more than 28% targeted technologies that support websites.

IT Industry- The Most Targeted Sector

The research findings also stated that the technology sector is the most attacked, accounting for 25% of all attacks. Over half of attacks targeted at the technology sector were application-specific (31%) and DoS/DDoS (25%) attacks, as well as an increase in weaponization of IoT attacks. The government sector is in the second position, driven largely by geo-political activity accounting for 16% of cyberthreats. Finance was third with 15% of all threat activity, threats on business and professional services accounted for 12% at fourth position, and education sector at fifth position  with 9% of attacks.

Other Key Findings Include:

  • DoS/DDoS attacks in APAC region were higher than the global average, and about three times of the DoS/DDoS rate in EMEA, regularly appearing in the top five common attack types (Singapore #4 and Japan #5)
  • Web-application and application-specific attacks dominated the region. They were the two most common attack types in Japan, and application-specific attacks were the most common attack types in Singapore and Hong Kong
  • Attackers are innovating by leveraging artificial intelligence and machine learning and investing in automation. Some 21% of malware detected was in the form of a vulnerability scanner, which supports the premise that automation is a key focus point of attackers
  • Attackers leveraged old vulnerabilities that have not been patched by organizations, such as HeartBleed, which helped make OpenSSL the second most targeted software with 19% of attacks globally. A total of 258 new vulnerabilities were identified in Apache frameworks and software over the past two years, making Apache the third most targeted in 2019, accounting for over 15% of all attacks observed

Matthew Gyde, President and CEO of the Security division, NTT Ltd., said, “The current global crisis has shown us that cybercriminals will always take advantage of any situation and organizations must be ready for anything. We are already seeing an increased number of ransomware attacks on healthcare organizations and we expect this to get worse before it gets better. Now more than ever, it’s critical to pay attention to the security that enables your business; making sure you are cyber-resilient and maximizing the effectiveness of secure-by-design initiatives.”

 

Cosmetics Brand Natura Suffers Data Breach; Personal Details of 250,000 Customers Leaked

data breach

Natura, a provider of personal care and beauty products, suffered a data breach which compromised the personal information of more than 250,000 customers. The Brazilian cosmetics firm unknowingly leaked the personal information of customers who had ordered products from its official website.

Security firm SafetyDetective discovered two unsecured Amazon-hosted servers of 272GB and 1.3TB in size, that belongs to Natura. The unprotected servers consisted of more than 192 million records.

In addition, the unprotected server also had a secret Privacy Enhanced Mail (PEM) file that contained the password to an Amazon cloud-based server where the Natura website is hosted. If exploited, it could have allowed an attacker to install a digital card skimmer into the company’s website to steal users’ payment card details in real time.

It was found that payment information of 40,000 customers related to a third-party company Wirecard was also affected in the incident. Though the data breach was first discovered on April 12, 2020, researchers at SafetyDetective stated that they were able to confirm that hundreds of gigabytes of information was exposed since March 26, 2020.

“Since the data leak was discovered and Natura being informed, the size of the data leak has been reduced from 272GB to 27.2GB, according to server logs — this is a strong indication of purposeful impropriety aimed at concealing the severity of the leak. For example, an ill-intentioned hacker removing a precise number of records to conceal their actions,” SafetyDective said in a statement.

According to SafetyDetective, the exposed data includes personally identifiable information (PII) of customers like name, mother’s maiden name, DoB, nationality, gender, hashed login passwords with salts, username, and nickname. The other valuable data that leaked in the incident include, MOIP account details, API credentials with unencrypted passwords, recent purchases, telephone number, email and physical addresses, an access token for wirecard.com.br, their account login cookies, along with the archives containing logs from the servers.

After the discovery, SafetyDetective immediately reported the incident to Natura authorities. The unprotected server is now secured. “Instances of personally identifiable information being exposed could potentially lead to identity theft and fraud since they can be used by attackers for identification in various sites and locations. The risk of phishing and phone scams is also raised by the Natura data leak,” SafetyDetective added.

 

EasyJet Hacked; Details of 9 Mn Customers Compromised

EasyJet cyberattack, EasyJet hack

EasyJet admitted that it has been a target of a cyberattack from a highly sophisticated source.  It first learned of the attack in January 2020. The European airline stated that the threat actors accessed the email addresses and travel details of more than nine million customers. However, the company clarified that out of the nine million affected customers, only 2,200 customers’ credit card details were compromised.

In an official statement, the airline stated that it informed the U.K.’s privacy watchdog, the Information Commissioner’s Office (ICO), and also the National Cyber Security Centre (NCSC) about the incident

While the investigation is ongoing, EasyJet stated that there is no evidence of any misuse of customer information. EasyJet urged its customers to change passwords, monitor their credit card accounts, and be vigilant of any phishing emails.

“We are communicating with the approximately 9 million customers whose travel details were accessed to advise them of protective steps to minimize any risk of potential phishing.  We are advising customers to continue to be on alert as they would normally be, especially should they receive any unsolicited communications. We also advise customers to be cautious of any communications purporting to come from EasyJet or EasyJet Holidays,” EasyJet said in a statement.

EasyJet’s Chief Executive Officer, Johan Lundgren, said, “We take the cybersecurity of our systems very seriously and have robust security measures in place to protect our customers’ personal information. However, this is an evolving threat as cyber attackers get ever more sophisticated. Since we became aware of the incident, it has become clear that owing to COVID-19 there is heightened concern about personal data being used for online scams.”

“We are contacting those customers whose travel information was accessed and we are advising them to be extra vigilant, particularly if they receive unsolicited communications,” Lundgren added.

Cybersecurity  on the Airline Industry

Keeping in mind the growing cyberattacks on the Aviation industry, ResearchAndMarkets.com released a report titled Aviation Cybersecurity Market – Growth, Trends, and Forecast (2019 – 2024). According to the report, the aviation cybersecurity market is expected to register a CAGR of around 11% during the forecast period of 2019-2024.

The industry relies heavily on IT infrastructure for its ground and flight operations. The security of these airline systems has a direct impact on the operational safety and efficiency of the industry, and also indirectly impacts the service, reputation, and financial health. The report discusses cybersecurity in the aviation sector by solution and application spanning from airline management, air cargo management, air traffic control management, and airport management.

 

Preparing a Breach Readiness Plan? ID Assist Can Help!

4 in 10 Organizations Struggle with SOC Staff Shortages: Report

The unprecedented rise of cloud technologies, and the emergence of the Internet of Things (IoT) and Software Defined Networks (SDN) have accelerated the digitization of businesses. The very fabric of traditional business methodologies has been transformed by advanced data-driven technologies that elevate business growth to the next level. However, one thing that has grown together with the digital revolution in recent years is the compliance and regulatory landscape, and a parallel need for a comprehensive breach readiness plan.

The impact that personal data protection, compliances, and regulators such as Canada’s PIPEDA (Personal Information Protection and Electronic Documents Act) and European Union’s GDPR (General Data Protection Regulation) have had on data privacy is humongous, and the numbers do not lie, as we see next.

Recap through Numbers

According to the observations mentioned in a blog named, “A full year of mandatory data breach reporting,” the Office of the Privacy Commissioner of Canada (OPC), reported a six-fold increase accounting to a total of 680 data breaches since PIPEDA’s implementation on November 01, 2018. Here are some other observations from the year:

  • Overall, 28 million Canadian citizens were affected by these data breaches which included known headline-grabbers like LifeLabs, Desjardins and Capital One.
  • Of the 680 breaches reported to the OPC:
    • 397 were due to Unauthorized Access
    • 147 were from Accidental Disclosure
    • 82 of them accounted for Physical Loss
    • 54 of the breaches were due to Physical Theft of things
Data Breaches in Canada, types of data breaches reported to OPC
Source: Office of the Privacy Commissioner of Canada

PIPEDA addresses the responsibilities of non-public organizations in disclosing data breaches of personal information. However, in a recent record tabled in the House of Commons in response to an order paper question filed by Conservative MP Dean Allison, it has come to light that personal information belonging to 144,000 Canadians has been mishandled by federal departments and agencies over the past two years. The nearly 800-page response not only underlines the lack of cybersecurity practices of federal agencies but also exposes their lack of a breach readiness plan. Other statistics that include records between January 2018, and December 2019 are as follows:

  • In total, 7,992 breaches were found to have occurred at 10 different agencies and departments.
  • The Canada Revenue Agency (CRA) was the worst offender, with 3,020 breaches affecting nearly 60,000
  • Health Canada reported 122 breaches affecting close to 24,000
  • Canadian Broadcasting Company (CBC) was breached 17 times and data of 20,000 employees was leaked.
  • The Canadian Immigration Department recorded a very high volume of data breaches accounting to 3,005 instances, affecting 4,268
Data Breaches in Canadanian Federal Agencies
Source: Results of Ontario Conservative MP Dean Allison’s query

Cybersecurity Awareness a Big Problem for Canadians

Canadian Internet Registration Authority (CIRA) is a non-profit organization that manages the [.]CA domain name registry on behalf of Canada. Its Cybersecurity Survey 2019,  found that 71% of the organizations in Canada reported at least one cyberattack in the past year, and yet, only 41% of its respondents had mandatory cybersecurity awareness training in place for its employees. The lack of basic cybersecurity education has a ripple effect as it feeds the organization’s reputational risks.

Another example of Canada’s complacency towards cybersecurity and personal data security can be found in a survey conducted by the credit bureau, Equifax. For instance, 92% of the survey respondents agreed that online fraud and identity theft is a serious issue. However, only 29% of them said they checked their credit report over the last 12 months to help protect their personal data, and surprisingly, only 38% of them indicated they would report fraud to a credit bureau. The data also revealed a contradictory picture as Canadians now feel less vulnerable to fraudsters online (80% in 2019 to 72% in 2020), on-the-go (59% in 2019 to 44% in 2020), at home (37% in 2019 to 27% in 2020), and in-store (38% in 2019 to 25% in 2020) as compared to the year before. So how do we address the elephant in the room?

  • Breach Preparedness Plan – Choose a knowledgeable person to lead the Breach Preparedness and Response Team, someone like a CISO, CIO, or CO (Compliance officer). The team should consist of members with special skill sets mainly including IT security, legal and public relations, and privacy experts. Have a data breach or cyber insurance policy to cover all the losses and expenses in case of a cyberattack. Also implement the best-suited cybersecurity technologies for your business, like anti-virus, intrusion detection and prevention system, etc.
  • Train your Employees – Even those having a basic knowledge of cybersecurity might not be updated with the evolving threat vectors. Thus, invest in your employee’s cybersecurity training and make them aware of various aspects of data hygiene such as proper handling and storage of data, role-based data access levels, latest scams and threats to be aware of, SOPs and reporting procedures in case of a data breach, etc.
  • Perform Risk Assessments – Conduct scheduled risk and vulnerability assessments. Perform penetration testing to ensure timely threat identification. Focus on the entire operations and supply chain, including third parties collecting personal information of your employees and customers. Identify and fill-up the cracks in your security before a breach exploits it.
  • Stay Alert and Updated of Other Breaches – Stay updated with the latest breaches related to your business segment. Threat actors prefer re-use of the same attack vectors against multiple organizations in a similar industry. Subscribe to alerts and newsletters from your industry’s association and other sources of news.

Although these risk mitigation steps lower the risk of a data breach and loss of one’s digital identity, an important question still persists: It isn’t about if your data will be compromised, but when? So, what does one do in the case of a cyberattack or a data breach episode? The answer is Incident Response Plan.

Incident Response – Dialing Plan Z for Crisis Management

Prompt incident response or crisis management is very important for any organization and it should mainly focus on the following five steps:

  • Containment – Don’t let it spread. The moment you detect a breach, terminate any or all unauthorized practices, recover as much data as possible, shut down the system and isolate the network that was breached; perform a mandatory password reset for all employees and customers, and patch all vulnerabilities in physical or electronic security.
  • Investigation – Ask your breach response team to lead the initial breach investigation. They should have the appropriate authority and knowledge to conduct the initial investigation and make recommendations. If necessary, a more detailed investigation may subsequently be undertaken from external cybersecurity experts.
  • Notification – Determine who needs to be made aware of the incident internally, and externally, at the preliminary stage. Escalate internally to inform the person within your organization who is mainly responsible for privacy compliance. And above all do not hide anything; tell the truth.
  • Preservation – Be careful not to destroy evidence that may be valuable in determining the cause of the breach or allows you to take appropriate corrective measures.
  • Restoration – Support your customer. Even before you restore your systems, start rebuilding customers’ faith. If the data breach affects one of your online services, then make sure to focus on this as a separate and important issue. Ignoring your customers’ problems can quickly turn this situation into a reputation risk and not only tarnish the brand name but eventually lead to loss of business and revenue.

In the current scenario, it is not as if businesses do not take adequate cybersecurity measures or follow best practices. The fact is, the threat landscape is evolving at a faster pace than many predicted. Thus, safeguarding and securing the digital identities of both, employees and customers are putting businesses under significant strain. Add to that the worry of failed compliance audits, large overhead costs, limited pool of skilled workforce, and a weak digital identity management. They all contradict the recommendations of a regulatory body like PIPEDA and hence, a data breach and loss of digital identity are considered inevitable.

However, the answer to these problems lies in the questions itself. Breach preparedness with an incident response plan is highly recommended in such situations. And for this, we look at turnkey solutions like ID AssistTM.

About ID AssistTM

ID AssistTM is an online identity theft monitoring solution provider. This breakthrough platform simplifies your digital identity monitoring and restoration process in case of a data breach. Its immediate deployment facilitates businesses to limit their brand’s reputation risks and controls potential damages to your customers. Additionally, it provides monitoring from both Canadian Credit Bureaus — Equifax® and TransUnion® —to its customers.

Other Features

  • 24/7 Monitoring – It includes credit and/or debit cards, chequing and/or savings account numbers, social insurance number, driver’s license number, passport numbers, email addresses, and phone numbers.
  • Fraud Alerts – Alerts the customers of any suspicious activity to minimize the damage and resulting stress. Correspondingly, ID AssistTM also contacts Equifax Canada and TransUnion Canada on your behalf to have an alert placed on your file.
  • Monthly Credit Score and Quarterly Credit Report – Provides a full snapshot of a customer’s financial history from Equifax to keep track of their credit standing and any unexpected changes or credit inquiries.
  • Guided Restoration – A dedicated Fraud Investigator will confirm your identity was stolen, put all the pieces back together, complete all the paperwork, and follow up with the respective agencies and the victim throughout the process.

Emerging technologies, stricter compliances, limited pool of skilled resources, and dubious ROIs are straining business models to the optimum. It is creating visible cracks in the physical, virtual, and network infrastructures of many organizations. Cybercriminals are exploiting these gaps and further adding to the strain. However, a smart breach readiness plan including specialized services like ID AssistTM helps in minimizing this strain. It not only enhances and adheres to the cybersecurity and compliance needs of the organization but safeguards your brand reputation and customer and employees’ digital identities.

Start your breach readiness plan today – make sure your organization is ready with ID Assist.

Disclaimer

CISO MAG did not evaluate the advertised/mentioned product, service, or company, nor does it endorse any of the claims made by the advertisement/writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Lurking in the Shadows: Potential Cyberthreats and How to Prevent Them

cyberthreat

Working from home may make sense to reduce your employee’s risk of contracting COVID-19. It does, however, make life more difficult for your security team. At the office, you have complete control over the network’s cybersecurity. At home, employees might inadvertently make mistakes that compromise that security.

The article was contributed by legaljobsite.net

In this post, we will look at the less obvious threats that lurk in the shadows and how to defend against them.

Charging Cables

Most employees understand the dangers of plugging in an unknown USB flash drive. Are they aware that fake lightning charging cables might also pose risks? The O.MG cable, released toward the end of last year, looks and works exactly like your standard iPhone charger.

It has got a lot of processing power, memory, a radio, and a web server built into it. In other words, it has everything that a hacker needs to hack any phone or computer it is plugged into.

It’s a concept that has been around for a while. Up until now, though, having the cables mass-produced was problematic. The original costs around $120, but we can expect to see cheap knock-offs on the market pretty soon.

The only real way to ensure that the lightning cable your employees use is legitimate is to open the cable. Hackers can enable or disable the software to avoid detection. It is safer for employees to stick to original cables bought from the manufacturers of their phones.

Supply Chain Attacks

At our office, we are frequently reminded not to upload any software from an unknown vendor. We are also told to check for updates for the software that we use regularly. Supply chain attacks are devious in their simplicity.

It is important to warn employees about malware being delivered through seemingly innocuous updates created by a trusted vendor. The Asus attack in 2018 saw hackers using a legitimate security certificate to sign the updates.

Again, these attacks are nothing new, but it is worth briefing employees during security awareness training. There was an uptake of these attacks in 2019. Most seemed to be highly targeted — while many computers were infected, hackers launched a second stage attack on selected computers.

Watch Out for Geotagging

Employees will inevitably use their work devices to post on social media. Blocking social media sites on company devices is helpful, but you must raise this in security awareness training, too. Geotagging is dangerous from a physical security perspective.

Your employee’s home security might not be as strict as yours. By posting geotagged photos of them working from home, for example, they are giving away their location. An enterprising hacker might opt to steal the computer from their home.

Naturally, you will have encrypted the data, but no encryption software is perfect.

Insecure Home Networks

You have taken steps to ensure that the office network connections are secure. Can you say the same for your employees? Where possible, employees should use a dedicated connection while working. This connection should not be used for anything else.

If that’s not practical, and employees must use their home networks, your department should:

  • Use software to scan each employee’s home network for weaknesses.
  • Assist employees in securing their routers and connection devices better.
  • Ensure that the software on all devices is up to date.
  • Help employees set up a private connection through their devices for when they need to work. You know the drill here. Use secure passwords, do not connect any other devices unless essential to work, turn off network discovery for the devices.

Phishing and Smishing

Six out of ten businesses experienced these kinds of attacks last year. The indications are that these attacks will increase in intensity going forward.

Employees know better than to click on a link in an email from an unknown source. You have taught them to verify known links in emails by navigating to the site address that they have on record.

All that training might go out the window, thanks to the panic the crisis creates. Will employees be as circumspect about emails and SMS purportedly coming from human resources detailing payment procedures?

Phishers and smishers are taking full advantage of the current panic. To better protect your company, it may be wise to send out some phishing and smishing tests. Are employees distracted? These tests will highlight areas to improve upon.

It could also help to set up a clear email structure so that employees can whitelist key personnel responsible for sending out messages. Any messages coming from outside this list should be treated with extra caution.

Further to this, it might be advisable to set up an internal system to verify messages. This could be in the form of a codeword or specific format that internal emails must take. Finally, it might be wise to set up a system of checks and balances when it comes to verifying financial instructions.

Similar principles can be applied to and agreed upon with key clients.

Final Notes

The idea of sending employees home to work can rightly fill the cybersecurity team with dread. A few simple precautions and reinforcing security awareness training will go a long way toward easing the risk.

Disclaimer

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

Hackers Target Indian banks Using Adwind Java RAT Campaign Amidst COVID-19

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

Seqrite, an enterprise arm of security firm Quick Heal Technologies, detected a new wave of Adwind Java Remote Access Trojan (RAT) campaign targeting Indian co-operative banks by taking advantage of COVID-19 pandemic.

Seqrite warned that attackers were trying to take control of employees’ devices to steal sensitive data like SWIFT logins. “These banks are usually small in size & may not have a large team of trained cybersecurity personnel, which, potentially, has made them a target for cybercriminals,” Seqrite said in a statement.

Attack Methodology

According to Seqrite, the Java RAT campaign begins with a spear-phishing email, which claims to have originated from the Reserve Bank of India or a nationalized bank. The email refers to the COVID-19 guidelines or a financial transaction detailed in an attachment, which is a zip file containing a JAR-based malware. Seqrite observed that the JAR-based malware can run on any machine which has Java runtime enabled and can impact a variety of endpoints, irrespective of their base Operating System.

Once the Trojan is installed, the hacker can take over the victim’s device, send commands from a remote machine, and spread across the network. The malware can also capture screenshots, download additional payloads, log keystrokes, and extract sensitive user information. “These attack campaigns can effectively jeopardize the privacy and security of sensitive data at the co-operative banks and result in large scale attacks and financial frauds,” the statement added.

Quick Heal urged users to exercise proper security measures and avoid opening email attachments and clicking links in unsolicited emails.

Cyberattacks on Indian Banks

A number of cyberattacks have been reported on banks in India, causing a huge financial impact on the banks and their users. Recently, cybersecurity firm Group-IB detected a database containing over 460,000 payment card records of Indian banks on the darknet for sale. The database, named “INDIA-BIG-MIX (full name: [CC] INDIA-BIG-MIX (FRESH SNIFFED CVV) INDIA/EU/WORLD MIX, HIGH VALID 80-85%, uploaded 2020-02-05 NON-REFUNDABLE BASE”, was kept on “Joker’s Stash”, a dark web marketplace for trading stolen cards data.

While the source of the database remains unknown, Group-IB notified Indian Computer Emergency Response Team (CERT-In) about the database leak. According to Group-IB, the database contains 461,976 payment records, card numbers, expiration dates, CVV/CVC codes, cardholders’ full name, email IDs, contact details, phone numbers, and addresses. It is estimated that the underground market value of these cards’ data would be more than $4.2 million.