Home Blog Page 213

Ramsay: A New Cyber Espionage Toolkit to Steal Data from Air‑Gapped Networks

BazaCall BazaLoader

Security researchers from ESET recently discovered a new cyber espionage campaign codenamed “Ramsay” which is designed to steal sensitive documents from air‑gapped networks. Ramsay can infect air-gapped computers, collect Word, PDF, and ZIP files in a hidden folder, and then exfiltrate them, researchers said. An air-gap is a security measure to ensure computer networks are physically isolated from the rest of the company’s networks and from potentially unsecured networks like public internet.

“We initially found an instance of Ramsay in VirusTotal. That sample was uploaded from Japan and led us to the discovery of further components and versions of the framework, along with substantial evidence to conclude that this framework is at a developmental stage, with its delivery vectors still undergoing fine-tuning,” the researchers said in an official post.

Researchers stated that they found three different samples of the Ramsay malware, one discovered in September 2019 (Ramsay v1), and other two in early and late March 2020 (Ramsay v2.a and v2.b).

“Unlike most conventional malware, Ramsay does not have a network-based C&C communication protocol nor does it make any attempt to connect to a remote host for communication purposes. Ramsay’s control protocol follows the same decentralized philosophy implemented for collected artifact storage. Ramsay will scan all the network shares and removable drives for potential control files,” researchers said.

Researchers suggest each version of Ramsay malware was different and infected victims through different methods, but the primary role was to scan an infected computer, gather Word, PDF, and ZIP documents in a hidden storage folder, and exfiltrate later.

Ramsay malware shares several similarities with Retro, a backdoor malware associated with DarkHotel, a notorious APT group known to have conducted cyber-espionage operations since at 2004 and have targeted government entities in China and Japan.

In a similar security discovery, researchers from Check Point discovered a new Chinese hacker group “Naikon APT” which is behind an ongoing cyber espionage campaign targeting government entities in the Asia-Pacific (APAC) region. The group was reportedly being hunted for five years by spying organizations in the Philippines, Australia, Thailand, Indonesia, Vietnam, Myanmar, and Brunei. The researchers stated that the Naikon APT group has been active since 2015, carrying out a series of cyberattacks on government units, including ministries of foreign affairs, science and technology ministries, as well as government-owned companies using a backdoor called “Aria-body”.

 

Why It’s Time to Take Vendor Risk Management Seriously

third party and vendor risk management

Putting expensive locks on your doors helps secure your home. But what if you start giving away the keys? First, you give a set to your family and close friends, then the babysitter, then the maintenance worker, and so on. As the homeowner, you expect these third parties to treat those keys with the same sense of security as you do.

There are other third parties that matter to your home as well. Pest control, plumbers, road maintenance, security guards, delivery workers, and many more. They know where your home is, but you are willing to give them the address to outsource key tasks you don’t want to do yourself. These people too must be trusted.

Oh, and don’t forget about the vendors in use by your third parties, sometimes called 4th parties, subcontractors, or subprocessors.

Though from a flawless analogy, the general concept holds true: Do you know if your vendors (and their vendors) are safe to do business with?

According to Deloitte’s 2019 Global Survey on Third-Party Governance and Risk Management, 83% of organizations have experienced a third-party related incident in the last three years, with nearly 11% having a severe impact on the business. As for fourth parties? Just 2% of organizations claim to assess and monitor all fourth parties.

Enterprises have increased their dependence on third-party products and services for a competitive edge. But this broadens the attack surface, making it imperative to invest in third-party or vendor risk management solutions. This need is further solidified with increasing data collection, recent market volatility, and regulations like GDPR, CCPA, LGPD, PIPEDA, HIPAA, etc.

In the extended enterprise, the security of your data and systems is not entirely in your control. That’s why it is critical to assess and mitigate the risks posed by your entire supply chain.

Third-Party and Vendor Data Breaches in 2019

Need more convincing that it’s time to invest in your third-party risk management program? Here’s a quick glance at some of the most noteworthy vendor data breaches of 2019:

Major Social Media Company

#1 Data Breach:
  • A Mexico-based media company exposed 146 GB of user data containing over 540 million records.
  • The leaked data included details of users’ comments, likes, reactions, account name, ID, and other sensitive information.
#2 Data Breach:
  • An integrated third-party app exposed plaintext (i.e. unprotected) passwords of 22,000 users.
  • It was found to be exposed to the public internet via an unprotected web server.
  • The exposed database contained information such as user id, user name, interests, events, groups, and more.

Major American Billing Service Provider

  • A U.S. based medical billing service provider, fell victim to a data breach that lasted for over seven months from August 1, 2018 until March 30, 2019.
  • Approximately 20 million U.S. citizens were affected by this data breach.
  • The data breach included credit card numbers, bank account information, and even social security numbers of the patients.
  • Its corporate clients terminated its services forcing the company to file for Chapter 11 bankruptcy protection.

Major Delivery Service

  • On May 4, 2019, an on-demand food delivery service reported unauthorized third-party access to information on 4.9 million people.
  • The type of user data accessed included names, email addresses, delivery addresses, order history, phone numbers, as well as hashed passwords — a cipher mechanism was used to hide the actual password from third parties.
  • Approximately 100,000 drivers’ license numbers of the delivery services provider’s users were also accessed.

The Challenges of Modern Vendor Risk Management

Third-party and vendor risk management is a growing concern among board-level stakeholders. Many organizations have difficulty streamlining and adequately managing their vendor risks because of silos that exist internally, as well as a lack of systematic processes throughout the organization. This impacts the bottom line by slowing down innovation and supplier onboarding, while also causing undue risk (and sometimes even extravagant spending).

Third-party and vendor risk management is moving towards automated technology solutions, yet, a considerable number of vendor risk management programs are still being handled across spreadsheets and multiple systems. A decentralized and fragmented vendor risk management process makes it difficult for any company or organization to keep track of its vendors and poses a burnout-inducing project on already overwhelmed resources.

Keeping this in mind, let’s examine some of the best practices and risk mitigation steps in vendor management.

Best Practices in Vendor Risk Management Lifecycle

  • Evaluate: Regular audits and assessments of all vendors should be conducted to evaluate whether they are aligned to the compliance, security, and privacy standards relevant to your organization.
  • Monitor: Actively monitor risks and performance of all third and 4th parties with whom you share this information.
  • Control: Control what you share. Avoid giving unnecessary access to vendors. Instead, only share what is required to avoid loss of sensitive data even in case of a data breach.
  • Review: Periodically review your vendor management policies and programs to address the latest industry standards, framework, or regulatory updates.
  • Notify: Include a clause in your business agreement that makes it mandatory for the third-party to provide notification whenever any form of your proprietary, intellectual, or customer data is shared with others (4th parties) and/or when fourth parties change.
  • Collaborate: Ensure the onboarding and involvement of all stakeholders in the vendor risk management process. Collaborate, because the implementation and success of your vendor management depend on every stakeholder’s involvement.

A centralized technology or a vendor risk management platform enables companies to track their vendors effectively and efficiently, while advanced risk analytics empowers them with the intelligence required to identify a suitable set of vendors to do business with.

Conclusion

Your company’s risk management program shouldn’t be limited to only securing its own IT infrastructure but also include its third and Nth-party vendor risk management. Cybercriminals are aware that larger enterprises implement the best suited IT security measures to safeguard their data and business periphery. Thus, they have now shifted focus from the main target to its ancillaries – your vendors. Fragile third-party vendors can act as a backdoor to larger enterprises’ data.

About OneTrust Vendorpedia

The OneTrust Vendorpedia platform is purpose-built to identify, assess, analyze, mitigate, and monitor vendor risks and performance. The platform offers three key solutions to help third-party risk teams:

  • Cyber Risk Exchange: Research vendors and monitor performance with a research database and pre-completed assessments
  • Vendor Chasing Services™: Enlist a Vendorpedia agent to perform vendor risk assessments on your behalf
  • Third-Party Risk Management: Streamline supplier selection, assessment, mitigation, and approvals with workflow automation, manage the entire vendor risk management lifecycle.
See OneTrust Vendorpedia in action. Watch the 5-minute demo video.

UK’s Electricity Body Elexon Suffers Cyberattack

Elexon Cyberattack

The U.K.’s electricity middleman Elexon got a massive shock after the company suffered a cyberattack. The company’s internal systems were targeted in the attack. Elexon plays a key role in the balancing and settlement of the U.K. power system and has close ties with core power system programs and processes with the U.K. system operator.

The company in a statement said, “ELEXON’s internal IT systems have been impacted by a cyber-attack. BSC Central Systems and EMR are currently unaffected and working as normal. The attack is to our internal IT systems and ELEXON’s laptops only. We are currently working hard to resolve this. However, please be aware that at the moment we are unable to send or receive any emails.” In an ensuing statement, it added,  “We have now identified the root cause and we are taking steps to restore our internal IT systems.  BSC Central Systems (and their data) and EMR remain unaffected and are continuing to work as normal.”

The incident can be classified under the umbrella of an attack on the critical sector, as Elexon is also responsible for settling payments between generators, suppliers and traders, as well as handles EMR payments – government contracts for difference (CfDs) for renewable generators. It also works very closely with the National Grid ESO. In simpler words, Elexon is among the key companies that ensure the lights in the U.K. stay on.

To detail, Elexon calculates the volume of electricity produced by a certain power station against the quantity sold by the electricity suppliers. These are then compared with the organizations contractual numbers of production and selling of electricity.

Since Elexon’s operations have nothing to do with the actual power grid functioning, zero impact to power supplies was registered. This was also later confirmed by the National Grid ESO’s tweet, “We’re aware of a cyber-attack on ELEXON’s internal IT systems. We’re investigating any potential impact on our own IT networks. Electricity supply is not affected. We have robust cybersecurity measures across our IT and operational infrastructure to protect against cyber threats.”

This is not the first incident where critical U.K. body has been affected by a cyberattack. Earlier this year, the U.K.’s Financial Conduct Authority (FCA) apologized after it accidentally exposed the confidential details of around 1,600 consumers who complained against it.

U.K. Suffers Cyber Readiness Deficiency

Both the incidents highlight a trend of lack of cyber readiness among U.K. organizations. According to a survey from data security firm Clearswift, around 70% of financial firms in the U.K. reported security incidents in 2019, in which half of the incidents occurred due to internal errors. The research, which surveyed 100 senior business decision-makers from financial organizations in the U.K., highlighted that most of the attacks have originated due to employees who failed to follow proper data protection policies. Apart from employees’ errors, the survey also revealed other reasons that led to attacks, including downloads of malware or viruses from third-party devices like USBs, and file transfers to unsecured sources.

A Joint Analysis Reveals APT Group Spying Activities

Compromised Email Accounts

A joint analysis by digital security products provider Avast and internet security company ESET evaluated the samples used by an APT threat group targeting Central Asian companies and institutions. It found that the APT group allegedly spied on a telecommunications company, a gas company, and a governmental agency in Central Asia.

The analysis revealed that the group planted backdoors to gain access to corporate networks. It is suspected that the APT group was also behind the attacks in Mongolia, Russia, and Belarus. The implanted backdoors permitted threat actors to manipulate and delete files, take screenshots, alter processes, services, execute console commands, and exfiltrate data to a C&C server.

According to Avast, the group also used backdoor tools like Gh0st RAT and management instrumentation to move laterally within infiltrated networks. Gh0st RAT is a popular backdoor associated with East-Asian attackers. “It is commonly assumed that Gh0st RAT source code is widely available. Its presence is often indicated by a file named rastls.dll, using an export DLL name svchost.dll and containing a string Gh0st. A string uwqixgze} is used as a placeholder for the C&C domain,” Avast said in a report.

“Avast believes the group is from China, which has been known to be used by Chinese APT groups in the past and similarities in the code Avast analyzed and code recently analyzed in a campaign attributed to Chinese actors,” the report added.

Luigino Camastra, malware researcher at Avast, said, “The group behind the attack frequently recompiled their custom tools to avoid antivirus detection, which, in addition to the backdoors, included Mimikatz and Gh0st RAT. This has led to a large number of samples, with binaries often protected by VMProtect, making analysis more difficult. Based on what we have discovered and the fact that we were able to tie elements of these attacks back to attacks carried out on other countries, we assume this group is also targeting further countries.”

In a similar research, a threat intelligence team from Avast revealed that Adware (advertising-supported software) is responsible for 72% of all mobile malware and the remaining 28% related to banking Trojans, fake apps, lockers, and downloaders. Adware is a kind of software that hijacks mobile devices to spam the victim with unwanted ads.

Avast stated that Android adware is a rising issue with its number increased by 38% in the past year alone. Adware disguises itself in the form of gaming and entertainment apps to infect the devices when a user clicks on ads. These apps appear genuine while installing, but once opened, they start spamming the user with ads (mostly with malicious content). This happens when a user downloads apps that run stealthy activities without the user’s knowledge like downloading an encrypted .dex file in the background of a device.

 

Survey Finds 41% of Employees Use Personal Apps to Access Sensitive Company Data

Remote Work

Research by work management platform Wrike revealed that 41% of employees working remotely are accessing sensitive and confidential company information through unsecured personal applications, leaving valuable corporate data and trade secrets to cyber risks.

The research 2020 Remote Work Security Survey stated that while most companies are investing in remote work, security measures are not being communicated or used. Several remote workers are still taking risks while accessing corporate IP, primarily by using personal apps to share company data with clients and colleagues. This is adding further security concerns as many of these are likely to be less secure than corporate-issued ones.

According to research findings, 49% of employees don’t use a corporate VPN to access company data. One third (31%) of employees aren’t sure how their home network is encrypted. And 84% of respondents admitted that they understand common cybersecurity risks, while working with the company’s information. Employees at a young age are more likely to neglect guidelines than older ones when it comes to using personal apps to share corporate data, the survey revealed.

“Remote workers shouldn’t take security lightly during shelter-in-place initiatives. Even during challenging times, it’s important for companies to continue investing in secure collaborative platforms that protect corporate assets while keeping employees engaged, efficient, and safe,” said Andrew Filev, Wrike’s Founder and CEO.

Remote Workers Lack Cybersecurity Training

The surge in remote work brought a new wave of cyberattacks targeting remote workers. Several industry experts stated that the lack of cybersecurity training may increase cyber risks. A research from cybersecurity firm Promon found that 66% of remote workers in the U.K. haven’t been trained on cybersecurity in the past 12 months, whereas 77% said that they aren’t worried about the security while working remotely.

Around 61% said they are using personal devices when working from home. Cybercriminals are exploiting the current working conditions by carrying out COVID-19-related phishing campaigns and other malicious activities, the research stated. The findings are based on the responses from 2,000 remote workers in the U.K.

 

7 In 10 Financial Organizations Globally Have Suffered a Cyberattack

Financial Sector

A research from cybersecurity firm Keeper Security revealed that lack of cybersecurity resources and strategies lead to an increase in the number of cyberattacks on financial institutions. It is found that 69% of financial organizations globally have suffered a cyberattack in their lifetime. While half of the organizations reported experiencing an attack in the last 12 months.

In its report, “The Global State of Cybersecurity in Small and Medium-Sized Businesses,” Keeper Security revealed that security incidents on financial firms are increasing because most of the firms do not  have proper resources and strategies in place to protect themselves against cyber risks. Nearly 50% of organizations believe that they do not have sufficient budget to support strong cybersecurity posture and 47% do  not have a plan in place for responding to an attack. Only 39% of financial services firms believe their IT security posture is very effective.

Survey respondents admitted that cyberattacks are becoming more targeted (77%), severe (64%) and sophisticated (63%). According to the survey, data breaches in financial services resulted in an average of 7,095 customer and employee records lost or stolen and came with an average price tag of $1.06 million from the disruption of normal business operations. The findings are based on the responses from 2,391 IT security professionals in the U.S., U.K., and regions like DACH, Benelux and Scandinavia.

“The financial services sector is in the midst of a pivotal era of disruption, but transformation should not come at the expense of cybersecurity. As a highly regulated industry, it’s imperative that firms don’t let cybercriminals fill the gaps. Unfortunately, the majority of these businesses have already experienced a cyberattack and our research shows they’re still not going far enough to prevent the next one. The good news is there are easily-implemented solutions and strategies that enable financial institutions to transform securely,” said Darren Guccione, CEO and Co-Founder of Keeper.

Banking and Financial Sectors are Prime Target

A recent study from the cybersecurity firm Intsights revealed that the banking and financial sectors were hit with a constant stream of cyberattacks when compared to other sectors. According to the Intsights report titled, “Banking & Financial Services Cyber Threat Landscape”, around 25.7% of all malware attacks last year was targeted on banks and financial organizations. The study also exposed that the number of data breaches reported in Q1 2019 doubled to any of the quarters of 2018.

 

WeLeakData.Com Compromised, Hackers’ Private Messages Leaked

99% of Websites Are Prone to Cyberattacks Via JavaScript Plug-Ins: Report

A database of an infamous darknet forum called WeLeakData.com was breached, exposing private messages of malicious actors who used the site. Cybercriminals used WeLeakData.com for discussing, trading, and selling databases that are stolen during breaches and combo lists used in credential stuffing attacks.

According to cybersecurity firm Cyble, WeLeakData.com site was suddenly brought offline for unknown reasons in January 2020. It was rumored that the operator of this platform got arrested and that the forum database had been stolen or sold to another hacking group. A month after WeLeakData.com was closed, the content of its database, including hackers’ private messages were kept for sale on the dark web.

“Cyble researchers got the intelligence from the members of the forum that it was not the case though. The reputation of the forum is undoubtedly there and is seen as a competitor to RaidForums. The business model of the forum was quite straightforward- it was mainly a criminal forum that specializes in the trade of leaked databases and uses the third-party e-commerce platform Shoppy for membership upgrades,” Cyble said in a statement.

Cyble stated that its researchers managed to gain access to the WeLeakData.com’s database in April 2020, from a darknet market seller and identified information that belonged to forum’s members, which are mostly researchers, hackers, cybercriminals, and crackers. The researchers found information like email addresses, usernames, passwords, private messages, and IP addresses.

Cyble believes that the site was sold to a new member of the forum, however it was operated under a different domain name – leaksmarket.com, with the same content.

Earlier this year, the authorities of the FBI and the U.S. Department of Justice seized the domain “weleakinfo.com” for selling sensitive information that was hacked from other sources for the past three years. According to the official notice, WeLeakInfo sold more than 12 billion user records that included: names, usernames email addresses, phone numbers, and passwords for online accounts. The notice also claimed that WeLeakInfo provided its users with a search engine to access the data that was illicitly obtained from over 10,000 data breaches. The U.S. Department of Justice urged the public to help them in finding the website’s owners.

 

In a Sea of COVID-19 Tracer Apps Where Does Apple-Google Stand?

Apple and Google COVID tracing app

Toward the end of his recent webinar with CISO MAG, hacker, security researcher and CISO, Chris Roberts took questions from the audience on the security needs for contact-tracing apps surrounding the COVID-19 cases. He said, “I want to believe tracing apps will be amazing because it has a bigger purpose to serve. But it should also be clearly stated, what will be done to the data afterwards — post the COVID-19 situation.” His statement reverberates to the entire Apple cloud platform iCloud versus the FBI fiasco — privacy norms vs governance, and even the latest revision to Apple and Google’s latest automatic contact tracing proposal. Both Apple and Google have pledged to shut down the tracer apps as soon as the pandemic ends, after several complaints citing privacy concerns.

In the last joint COVID-19 notification effort, the technology giants refined its technical details along with the FAQ and have elaborated on the cryptography, Bluetooth communications, as well as the API framework for developers. According to the notification, among the methods used to contact trace is a system called exposure notification, where users will be informed if they have been exposed to an infected person. Exposure notification is part of the companies’ joint standard to accelerate adoption and interoperability. The companies have shared a library of reference code for both Android and iOS devices.

On the encryption front, Apple has stated that they have migrated to AES-based encryption, instead of the earlier used HMAC encryption. Apple noted that AES performed better in this application of the technology. Apart from that, both the companies also stressed on using temporary tracing keys, which are now randomly generated, making it difficult for attackers to reverse engineer how keys are derived. One of the other key advantages of the tracker apps by Apple and Google is faster rollout to the maximum number of people.

Several countries have touted for Apple-Google to be the staple format for contact tracing due to the reasons including:

  • Explicit user consent required
  • Doesn’t collect or use location data from your phone
  • Bluetooth beacons and keys don’t reveal user identity or location
  • User controls all data they want to share, and the decision to share it
  • People who test positive are not identified to other users, Google, or Apple
  • Will only be used for exposure notification by public health authorities for
  • COVID-19 pandemic management

Other reasons why Apple and Google appear to be the better ones in a sea of Coronavirus tracing apps are the transparency and quality. Currently, one of the largest downloaded COVID tracing app in the world is India’s Aarogya Setu app, which crossed the 100 million mark. However, the app received a skimpy two out of five points by the MIT Technology Review.

The review, which judges tracing apps on several parameters, gave two points to Aarogya Setu on benefits like useful data and deletion of data on time, while it lost on parameters like voluntary use, and transparency. The review also noted that India was the only democracy that has made the app mandatory for millions of people. Austria’s Stopp Corona App, Czech’s eRouska, Iceland’s Rakning C-19, Israel’s HaMagen, Italy’s Immuni, and Singapore’s Trace Together were among the apps that scored a perfect 5.

Uncertain Data Sharing Practices Keep Educational Organizations at Risk: Research

Uncertain Data Sharing Practices Keep Educational Organizations at Risk: Research

Weak data sharing security controls are keeping several organizations in the education sector at risk of data security incidents. A research from cybersecurity firm Netwrix revealed that the ongoing remote learning due to the COVID-19 pandemic is increasing the rate of cyberthreats.

The research, “2020 Data Risk & Security Report,” found that 82% of educational organizations don’t track data sharing. It is also found that employees at more than half of companies in the education sector use cloud applications to share sensitive data outside of IT control and knowledge.

Nearly 63% of organizations do not review data access permissions regularly and 24% of system administrators admitted to granting direct access upon user request. Around 28% of surveyed educational organizations had data outside of secure locations, which was left exposed for days (40%) or months (33%). The research stated that majority of educational organizations had weak data security controls even before the COVID-19 pandemic.

“The data storage stage turned out to be the most challenging stage for ensuring data protection. Nearly a quarter (24%) of organizations reported they had discovered data outside of secure locations, and it took them days (43%) or weeks (23%) to discover the incident. These figures represent the highest incident rate and the slowest detection time of all the stages,” a statement read from the research report.

Other Notable Findings include:

  • 61%of organizations that are subject to the GDPR collect more customer data than the law permits.
  • 100% of organizations that have hired a Chief Data Officer (CDO) have implemented data discovery and classification processes.
  • 91% of organizations claim they store sensitive and regulated data only in secure locations, but 24% of them admitted they had discovered such data outside of designated locations in the past year.
  • 54% of organizations said that they do not follow the security best practice of reviewing user access rights to data on a regular basis
  • 46% of organizations that had an unauthorized data sharing incident are subject to the GDPR. However, 38% of them are confident that employees don’t bypass IT control to share data.
  • 30% of system administrators granted direct access to sensitive and regulated data based only on a user request in the past 12 months.
  • 66% of CIOs don’t have cybersecurity and risk KPIs that are regularly reported to their executives.
  • 82% of educational organizations don’t track data sharing at all or do it manually, and 50% of them suffered a data breach due to unauthorized data sharing last year.
  • 63% of educational organizations don’t review permissions regularly, and 24% of system administrators admitted to granting direct access rights upon user request.
  • 28% of respondents discovered data outside of secure locations, which is the highest number of all industries surveyed. This data was left exposed for days (40%) or months (33%).
  • Only 8% of respondents have developed cybersecurity and risk KPIs to evaluate their security posture and track success.

“Organizations are investing more than ever in cybersecurity, yet data breaches and other security incidents are continuing to increase in both number and size. First, while security professionals successfully mitigate security issues at some of the six stages of data lifecycle, they often overlook other stages, leaving their organization’s content vulnerable. In addition, security professionals generally know very little about what data they have, how sensitive it is, where it is stored, and who has access to it,” the statement added.

Top 5 CyberTech Trends in India in Times of COVID-19 [INFOGRAPHIC]

cybersecurity pressure

Cybersecurity news: While the world struggles with the impacts of COVID-19, cybercriminals see it as an opportunity. Since February, IBM X-Force has observed a 4,300 percent increase in coronavirus-themed spam. While organizations worry about newly pressing concerns—workforce well-being, shift to remote work, finance availability,  and the resiliency of operations and supply chains—cybersecurity focus is being overshadowed and risks are rising. IBM has identified 5 CyberTech trends that will impact India in times of COVID-19.

The tendency toward ad hoc decision making during crisis only accelerates the opportunity to exfiltrate data or compromise business operations. The potential impacts are more dangerous, too. A distributed denial-of-service (DDoS) attack, for instance, can be far more damaging in an operational environment that is already strained for capacity than one launched when additional capacity is readily available.

Security leaders from SMBs to large enterprises need to continue their focus on the entire threat lifecycle which constitutes planning and detection, in-the-moment response and remediation –recovery. This will help to prepare for additional unforeseen scenarios.

Prashant Bhatkal, Security Software Leader, IBM India South Asia, says, “As an organization we have been working  with our clients even before the pandemic to build their Cybersecurity Incident Response Plan.  With COVID-19, organizations who were prepared managed to sail through while organizations that were insufficiently prepared in normal times have been caught completely off guard. With threat landscape evolving every day and work from home being the new normal, threat actors are finding newer ways to disrupt businesses. Clients today are looking for CyberTech which can help protect their data, provide end-to-end security across multiple environments, new authentication methods, monitoring services and most importantly re-imagine their risk assessment.”

IBM India identified 5 CyberTech trends which will help security experts maintain constant vigilance and organizational agility across sectors like Manufacturing, BFSI, Telecom, Government, Healthcare, Auto, Retail etc.

Top 5 CyberTech trends in India in times of COVID-19
Source: IBM India