Home Blog Page 22

Bank Indonesia Suffers Ransomware Attack, Suspects Conti Involvement

Sardonic, BitMart

Banks and financial institutions are always on a hacker’s target list. Cybercriminals recently targeted Bank Indonesia (BI), disrupting its operations temporarily. According to a report, the central bank of the Republic of Indonesia confirmed that it had sustained a ransomware attack. However, the bank also clarified that the attack did not impact its operations or compromise any critical data, adding mitigation measures were undertaken.

“We were attacked, but so far so good as we took anticipatory measures and most importantly public services at Bank Indonesia were not disrupted at all,” said Bank Indonesia’s spokesperson in a media statement.

Cybercriminals leverage ransomware to penetrate targeted network systems, infect critical files, and encrypt them, making them inaccessible to others. Threat actors often demand a ransom to decrypt the infected systems.

Conti Ransomware Suspected

While Bank Indonesia did not reveal the ransomware operators behind this attack, security experts suspect this could be from the Conti ransomware group. Conti is a Russian-speaking ransomware group that reportedly victimized more than 400 organizations worldwide, of which 290 are in the U.S. alone. Conti attackers infiltrate victim networks through phishing emails (malicious links or attachments) or stolen/cracked remote desktop protocol (RDP) credentials. These cyber actors then steal files, encrypt servers and workstations, and demand ransom.

Also Read: Cybercriminals Make Twitter a Playing Field to Target Indonesian Banks

Cyberattacks on Indonesia

Security incidents on Indonesian financial organizations have become prevalent in recent times. A cyber intelligence report from Group-IB recently found traces of an ongoing fraudulent campaign based on Twitter targeting Indonesia’s largest banks.  Cybercriminals posed as bank representatives or customer support team members on Twitter to lure and gain the trust of targeted victims. This massive campaign, which began in January 2021, ballooned 2.5-fold (from 600 in January) to a total of 1,600 fake Twitter accounts impersonating banks until early March. It is found that over seven large Indonesian financial institutions have been targeted under this campaign. The scam affected over two million Indonesian bank customers active with legitimate bank handles on Twitter.

Episode #20: Digital Trust – An Imperative for Business Innovation

Digital Trust

Coming out of the cybersecurity, privacy, and data ethics fields, Digital Trust is becoming a requirement for doing business in the modern, hyperconnected world.

There is a significant trust deficit – people are increasingly saying that they don’t trust science or technology (and especially not technology focused companies) to improve their lives.

A global survey by PwC in 2020 found that people have concerns about security and privacy, but often feel trapped with their service providers due to a lack of trusted alternatives. Consumers want trusted alternatives, with 83% wanting control over their data and 85% wishing for companies they can trust with their data. Given a trustworthy option, consumers would not only change providers but are also willing to pay for more enhanced security.

In order to build back trust in technology and in technology innovators and developers, we need to focus on building more trustworthy technology. That includes focusing on cybersecurity at the beginning, but also on being transparent about our uses of tech and making sure they adhere to the values of users and citizens.That’s why the World Economic Forum launched a new initiative on Digital Trust.

The World Economic Forum’s Digital Trust initiative was established to create a global consensus among stakeholders on what Digital Trust means. Digital Trust is part of the Forum’s Centre for Cybersecurity Platform.

In this episode Daniel Dobrygowski, Head of Governance & Trust, World Economic Forum explains what Digital Trust means in the context of business and why it is so important for business innovation.

Consumers are losing their faith in businesses as they sell their personal data to marketers. More consumers are mistrusting technology, for instance, connected technology in smart homes. And this is highlighted in The World Economic Forum’s State of the Connected World 2020 report. Big tech companies can track consumers closely and have a deep understanding about consumer habits, preferences and behaviors. It’s also about lapses in security that are leading to data leaks. Dobrygowski talks about the governance required to reaffirm consumer confidence in both, business and technology.

An attorney and educator with two decades of experience at the intersection of technology, civil rights, law, and policy, Dobrygowski came to the Forum as a Global Leadership Fellow and was one of the founding staff of the Forum’s Centre for Cybersecurity. Previously, he practiced law with international firms in San Francisco and Washington, DC in the areas of antitrust, consumer protection, IP, and privacy. He conducts research and publishes in the fields of cybersecurity & resilience, digital trust, election protection, internet rights, and corporate governance.

Daniel holds an MPA from Harvard University’s Kennedy School of Government, a JD from the University of California, Berkeley, School of Law, and a BA from the Johns Hopkins University. He sits on the board of the Cyber Risk Institute and has been recognized by the NACD as one of the most influential leaders in the corporate governance community.


Also see:

U.K. Govt Introduces Digital Identity Trust Framework

Crypto.com Suffers Unauthorized Activity Affecting 483 Users

Liquid Exchange Hack

Cryptocurrency exchange platform Crypto.com announced that unknown threat actors compromised its user accounts. In an official release, the company stated that a small number of users encountered unauthorized crypto withdrawals on their accounts. The intrusion reportedly affected 483 Crypto.com user accounts. The unauthorized withdrawals totaled 4,836.26 Ethereum coins worth $15,132,516, 443.93 in Bitcoin worth $18,613,630, and over $66,200 in other cryptocurrencies.

How Did the Intrusion Happen?

Crypto.com stated that it identified an unauthorized activity on its user accounts on January 17, 2022, where transactions were being approved without the 2FA authentication from the user side. The crypto platform suspended all withdrawals as a precautionary measure and launched an investigation to find additional details.

Mitigation

As a security measure, Crypto.com invalidated all customer 2FA tokens and asked its customers to re-login and set up their 2FA token to ensure only authorized users can log in. While the threat actors behind the intrusion are unknown, Crypto.com stated it will notify and compensate the affected customers.

Also Read: Lazarus Group Stole $400 M Worth of Cryptocurrencies in 2021

“Full audit of the entire infrastructure has been conducted internally, with a number of improvements being implemented to further harden the security posture. While Crypto.com already performs internal and external penetration tests, Crypto.com has immediately engaged with third-party security firms to perform additional security checks on our platform, as well as initiating additional threat intelligence services,” the release said.

What Crypto.com is Doing to Prevent Intrusions

Crypto.com has introduced the Worldwide Account Protection Program (WAPP) to provide additional protection and security for its users’ funds. It is said that WAPP is designed to protect user funds in cases where a third party gains unauthorized access to their account and withdraws funds without the user’s permission.

To qualify for the WAPP program, users must:

  • Enable Multi-Factor Authentication (MFA) on all transaction types where MFA is currently available
  • Set up an anti-phishing code at least 21 days before the reported unauthorized transaction
  • Not be using jailbroken devices
  • File a police report and provide a copy of it to Crypto.com
  • Complete a questionnaire to support a forensic investigation

“The safety of our customers’ funds is our highest priority, and we are continually enhancing our Defense-in-Depth security and protection measures. While we are reminded of the existence of bad actors intent on committing fraud, this new Worldwide Account Protection Program, along with our new MFA infrastructure, gives our users unprecedented protection of their funds, and hopefully, peace of mind,” said Kris Marszalek, co-founder, and CEO of Crypto.com.

NATO and Ukraine Sign Deal to Boost Cybersecurity

NATO Ukraine

The North Atlantic Treaty Organization (NATO) recently entered into a deal with Ukraine to boost cybersecurity capabilities in the country. The NATO Communications and Information (NCI) Agency and Ukraine signed a renewed Memorandum of Agreement to continue working on cybersecurity and other technology-related projects.

The agreement comes after a series of cyberattack incidents in Ukraine and heightened tensions over Russia’s invasion. According to a statement from NATO’s Secretary-General Jens Stoltenberg, cybersecurity experts from NATO will be working together with Ukraine to confront the rising cyberthreats in the region. The new cybersecurity collaboration allows Ukrainian access to NATO’s malware information sharing platform along with enhanced cyber cooperation.

NATO is an intergovernmental military alliance between 27 European countries, two North American countries, and one Eurasian country. It constitutes a collective security system and mutual defense against any attacks from external parties.

“We have successfully worked with Ukraine for several years, delivering key capabilities and exchanging knowledge. Under this renewed agreement, we will deepen our collaboration with Ukraine to support them in modernizing their information technology and communications services while identifying areas where training may be required for their personnel. Our experts stand ready to continue this critical partnership,” said NCI Agency General Manager Ludwig Decamps.

Also Read: Russian Networks Accused of Carrying Out Massive Cyberattack on Ukraine

“The Memorandum signed today continues our cooperation established in 2015. With NATO’s support, we plan to further introduce modern information technologies and services into the command and control system of the Armed Forces of Ukraine,” said Ambassador Nataliia Galibarenko, Head of Mission of Ukraine to NATO.

Ukraine Russia and Cyberattacks

This is not the first instance to raise cyberattack tensions between Ukraine and Russia. There were multiple cybersecurity incidents in Ukraine, allegedly by Russian hackers. Ukraine claimed that Russia specifically targeted its security services, governmental offices, the Defence Council, and other enterprises. However, Moscow has always denied Ukraine’s previous claims of targeted cyberattacks, but Ukraine persists that the former is using “hybrid war” tactics against their country. Read More Here

Cybercriminals Will leverage IoT and 5G for Large-Scale Attacks

Proactive Cybersecurity Paradigm, cyberwar, IoT, 5G, Boardroom, Identity Detection and Response, Predictions, supply chains, hybrid workforce

In 2022, Cybercriminals will leverage the combination of IoT and 5G to conduct large-scale attacks, and attributing these attacks may become much more challenging. Given the speed and capacity available through 5G, hackers will hitch this to their tradecraft to project 2022 as the year 5G enabled cybercrime hits the front burner. Smart cities that have adopted 5G and are ingraining its power within their communities are more at risk. The burgeoning use of IoTs, and these being supercharged on 5G networks, will come as a ready tool for hackers to disrupt the high-tech social order within these communities.

By Favour Femi-Oyewole, Global Chief Information Security Officer (CISO) at Access Bank Plc.

In addition to this, I also predict the following trends:

The rise in Cybercrime Innovation and Commercialization. We will see an increase in cybercrime innovation, which will lead to increased compromise of organizations as hackers leverage more use of zero-day attacks. The commercialization of hacking as a service will draw skills from the underground and formal cybersecurity job market where brilliant minds with a dark side converge for bounty and bug hunting as they are induced or rewarded to discover vulnerabilities in demand on the dark web. The ability of well-known corporate brands to offer comparative reward incentives may skew discoveries in their favor.

Security Misconfiguration in SaaS Application will be widely felt. Security misconfigurations related to identity and access management in the CI/CD pipeline at a critical supply chain provider would cause a cyber-incident like the SolarWinds debacle. At the same time, organizations will be stretched thin regarding fighting cyber threats on all fronts, the ability of organizations to maintain a presence of mind approach to cybersecurity by ensuring excellent security hygiene & posture re-assessment.  This should scale and withstand the rigors of time, and operations will be a differentiating factor for global service providers. Sadly, this often forgotten corner piece of cybersecurity will once again come to the fore in 2022 as someone drops the ball.

Also see:

The Importance of 5G Security in Today’s World


About the Author

Favour Femi-OyewoleFavour Femi-Oyewole is a Doctoral Student at Covenant University, Ota, Ogun State, Nigeria. She is the Group Chief Information Security Officer in the Access Bank Plc overseeing the Information & Cyber Security of the Group office and the Subsidiaries. Favour also holds several certifications in the IT & Information Security and Cybersecurity field. She is a Cisco Certified Security Professional, Checkpoint Security Administrator, 1st female COBIT 5 Assessor certified in Africa, Certified Chief Information Security Officer, Certified ISO 27001 Lead Implementer, and Lead Auditor. She is also the first female in Africa to be a Blockchain Certified Professional.

Favour is a Certified ISO 27001:2013 Lead Implementer Trainer. She is an Alumni of both Harvard Kennedy School (HKS, Harvard University, and Massachusetts Institute of Technology (MIT), USA. She is a member of the Cybercrime Advisory Council in Nigeria. Favour emerged as the 1st woman in the world to win the Global Certified CISO (C|CISO) of the Year 2017 from the EC-Council in the U.S.

Favour is also an active member of the Global Certified Chief Information Security Officer (CCISO) Advisory Board & Scheme Committee of the EC-Council in the U.S. She is a certified Data Privacy Solutions Engineer (CDPSE), a certification recently awarded to her in June 2020 by ISACA.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Organizations Suffer 270 Attempts of Cyberattacks in 2021

Global Cybersecurity Outlook 2022,Cybersecurity, CEO, CISO

Cyberattacks and data breaches can be devastating to an organization’s growth. Fuelled by the COVID-19 pandemic, enterprises worldwide sustained significant losses due to cyberattacks, especially ransomware. Apart from information theft, cyberattacks could cause a range of problems to victim organizations, including loss of customer trust, business, clients, penalties, etc.

According to the Global Cybersecurity Outlook 2022 report from the World Economic Forum (WEF), after suffering a data breach incident, an average share price of a victim company underperformed the NASDAQ by -3% even six months after the event. The research found that ransomware attacks rose by 151% in 2021. There were nearly 270 cyberattacks per organization, with each successful security breach costing a company over $3.6 million.

According to the report, personal cybersecurity concerns of security leaders include:

  • Loss of personal assets by a cyberattack (10%)
  • Ransomware attacks (20%)
  • Infrastructure breakdown due to a cyberattack (42%)
  • Identity theft (24%)
  • Other (4%)

The estimated amount of data created on the internet in one minute:

  • 28,000 Netflix subscribers watching
  • 695,000 Instagram stories shared
  • 9,132 LinkedIn connections made
  • 69 million WhatsApp messages sent
  • 5,000 TikTok downloads
  • 2 million Twitch views
  • 2 million Tinder swipes
  • 6 million emails sent
  • 500 Youtube hours of content uploaded

Also Read: Emerging Cybersecurity Technologies to Know for 2022

The top three cyberattacks organizations are most concerned about are:

  1. Ransomware
  2. Social engineering
  3. Malicious insider activity

The top three cyberattacks security leaders are most personally concerned about are:

  1. Infrastructure breakdown due to a cyberattack
  2. Identify theft
  3. Ransomware

Other Key Findings:

  • Nearly 80% of cybersecurity leaders stressed that ransomware is a dangerous and evolving threat to public safety.
  • The survey confirmed that ransomware attacks are at the forefront of cyber leaders’ minds. 50% of respondents indicated that ransomware is one of their greatest worries in cyber threats.
  • Around 39% of organizations affected by third-party cyber incidents in the past two years.
  • Small and medium-sized enterprises (SMEs) are considered a crucial threat to supply chains, partner networks, and ecosystems.
  • Around 88% of respondents stated they are concerned about the cyber resilience of SMEs in their ecosystem. And over 81% of respondents believe that digital transformation is an indispensable element in improving cyber resilience.
  • Organizations require 280 days on average to identify and respond to a cyberattack.

“We are at a crossroads, a point at which cyber resilience has become the defining mandate of our time – beyond foundational security controls – to anticipate future threats, withstand, recover from cyberattacks, and adapt to likely future digital shocks,” the report said.

Accellion Agrees to Pay $8.1 M in Data Breach Lawsuit Settlement

Accellion Lawsuit, Google and Apple, Excellus to Pay $5.1 Mn to Settle Potential HIPPA Violations

Accellion, a provider of hosted file transfer services, recently agreed to pay $8.1 million to settle a class-action lawsuit related to a data breach in December 2020. The lawsuit, filed in a California Federal Court, claims that Accellion failed to protect the sensitive information of millions of users after threat actors exploited a vulnerability in Accellion’s file transfer appliance (FTA).

Based in California, Accellion is a private cloud solutions company providing software for third-party secure file transfers. The data breach occurred due to a bug in Accellion’s file-sharing software, used by several organizations globally.

The data breach affected many Accellion clients. It impacted millions of users’ sensitive data such as names, birthdates, Social Security numbers, banking details, medical and drivers’ license information. The lawsuit stated that Accellion failed to identify vulnerabilities in its FTA platform and implement necessary data security measures to secure client and user classified information.

One Bug – Multiple Attacks

Accellion detected a zero-day vulnerability in its FTA platform in December 2020 and released a patch to fix it. However, in February 2021, the company found four additional flaws in the platform. Several cybercriminal groups started exploiting the flaws to steal sensitive corporate data.

Accellion also issued a statement regarding the constant attacks that exploited its legacy FTA product. The company claimed that cybercriminal group UNC2546 is likely behind the hacks and data breaches. The threat group sent several extortion emails to the victims threatening to publish their sensitive data on their CL0P LEAKS site on the dark web.

Also Read: Bug in Accellion’s Software Exposes Data of 1.4 Mn Washington State Residents

The Bandwagon of Accellion Data Breaches

The ripples of Accellion’s flaw resulted in several data breach incidents, impacting the numerous companies that use Accellion file transfer services. Threat actors attacked several organizations globally by exploiting the Accellion vulnerability.  Critical organizations like the Office of the Washington State Auditor (SAO), the Australian Securities and Investment Commission (ASIC), and New Zealand’s Reserve Bank suffered security breaches.

A recent victim of Accellion hacks is Morgan Stanley. The global financial services provider reported a data breach after unknown hackers pilfered private data of its customers by exploiting the bug in Accellion’s FTA server hosted by a third-party vendor.

Cybersecurity Will Become the Top Agenda in Boardroom Discussions

Cybersecurity Predictions

Among my three cybersecurity predictions for 2022, the one that I am optimistic about is cybersecurity getting more mindshare in the boardroom.  Expect to see cybersecurity-focused board members taking an active role in understanding the organization’s cybersecurity posture, including requests for additional metrics and frequent board updates. Here are my three predictions:

By Sriram Tarikere, Senior Director with Alvarez & Marsal’s Global Cyber Risk Services in New York

1. Ransomware threats will continue to evolve. Ransomware threats will continue to dominate the rest of 2021 and into 2022. Cyberthreats actors will continue to get creative, and their attacks will become more sophisticated to ensure that the organizations cannot recover normal business operations without paying the ransom. In a shift from a single group managing the full attack life cycle, threat actors will form specialized groups to gain access into organizations that then sell that access to ransomware operators. The malware  deployed by these groups will not be limited to one single vulnerability; rather, the malware will dynamically modify and adapt to the wide range of vulnerabilities available for corporate IT as well as operation technology (OT) systems.

2. Cybersecurity enters the boardroom: Cybersecurity will be on the top of mind for the Board of Directors and Executive leadership teams. Expect to see cybersecurity-focused board members taking an active role in understanding the organization’s cybersecurity posture, including requests for additional metrics and frequent board updates. This is due to the regulatory pressure from agencies like Federal Trade Commission (FTC) and Security Exchange Commission (SEC) that have made strong statements on enforcement against organizations failing to protect customer data. Gartner predicts that by 2025, about 40% of the Boards will either have dedicated cybersecurity committees or have qualified board members focused on cybersecurity overseeing organizations’ cybersecurity maturity, up from less than 10% today.

3. Heightened scrutiny by cyber insurance companies on organizations’ cyber hygiene: Cyber liability insurance is a type of business insurance that organizations acquire to cover the losses, penalties, and other liabilities associated with cyberattacks and data breaches. Considering that ransomware incidents are becoming more prevalent, it is reported that the insurance claims and payouts are exceeding the premiums being paid. As a result, cyber insurance companies will enhance their due diligence and start performing a comprehensive assessment of the organizations’ cyber hygiene and security posture when issuing or renewing the policies. We can also expect to see cyber insurance premiums increasing exponentially and, in some cases, cyber insurance providers excluding ransomware coverage when issuing or renewing the policies.

Also see:

Mastering Art and Science Is Imperative for CISOs to Be Successful


About the Author

Sriram Tarikere, Senior Director with Alvarez & Marsal’s Global Cyber Risk Services in New YorkSriram Tarikere has over 15 years of experience in executing cybersecurity and privacy risk assessments, ranging from very detailed ISO 27001/NIST, HIPAA, PCIDSS and Risk Quantification assessments, to technical cloud and blockchain secure design and architecture reviews, application and network security assessments, red teaming, threat hunting and social engineering exercises. He has led and coordinated incident response and forensic investigation efforts for some of the largest and high-profile breaches in the recent past. He also advises clients on some of the most complex cybersecurity initiatives and acts as a trusted security adviser to organizations, C-Suite and board members.

Tarikere earned a master’s degree in computer sciences/cybersecurity from New York University. He holds the Chief Information Security Officer (CISO) certificate. He is a CISSP, PCI-QSA, GWAPT, GCIH and ISO 27001 Lead Auditor.

Blockchain-Based Social Media Will Be More Secure

blockchain-based social media, Parental Consent for Minors, Iranian Facebook accounts

Platforms based on blockchain technology are currently garnering much public interest worldwide since they have always been an entry point for billions of individuals to build social communications. LeewayHertz says by 2025, social media is expected to rise at a CAGR of 32%, from $94.83 billion in 2020 to $308.96 billion in 2025. The majority of people who use social media platforms are concerned about the security and privacy of their personal information. Decentralized platforms that enable applications and smart contracts are what blockchain-based social media is all about. Blockchains could make social media more secure and instill confidence in consumers.

By Elbachir Haimoud, Information Security and Compliance Officer at TÜRKKEP A.Ş.

What is Blockchain-Based Social Media?

Blockchain has emerged as a feasible alternative for fixing numerous challenges, including social media; many specialists and experts believe that blockchain-based digital networks are the way of the future for social media, especially on a security basis. Blockchain-based social platforms provide end-to-end encryption for all interactions due to their decentralized nature.

Users that utilize such decentralized social networks will be compensated with tokens and rewards for creating and sharing high-quality content. Consumers have more privacy when using these networks, and a data breach is almost impossible.

The Need to Replace Traditional Applications

Traditional social media has made a tremendous impact on the way people communicate. Any social media site tracks user behavior. They also control individuals/users’ data stored in servers, owned, and governed by the organization’s centralized networking architecture.

Traditional social media applications are used for advertising and market businesses, sharing information and political views, raising awareness, and generating funds for people in need. But its nefarious use has also led to issues such as:

  • Cyberbullying, political misinformation, scams, etc., are examples of the dark side of social networking platforms.
  • The loss of personal data protection and information ownership is the key disadvantage of social media.
  • The most popular social media platforms are also the most active data miners, frequently invading users’ privacy to sell more profitable advertisements.

For instance, some known social networking platforms make money from their users’ data by either sharing information such as online activity, user behavior, and content or using it for marketing and advertisements.

How can Blockchain Improve the Chances of Social Media?

Blockchain-based social networking applications are a vast decentralized platform that can develop applications and smart contracts. Some of the main advantages of such platforms are related to digital security, giving users more privacy and control over their data.

Protected Data Storage

Many organizations still use centralized storage systems for storing the data, which is a vulnerable point because a hacker needs only one vulnerable location to access all the information stored in these systems and gain access to sensitive data through an attack. With blockchain, decentralized data storage is created where essential data is protected. It would be difficult for hackers to breach any data storage system data.

Privacy concerns

Any social media platform user’s primary concern is privacy. Cybercriminals are skilled at deceiving social media users into disclosing critical information, stealing personal data, and gaining access to accounts that are supposed to remain private. Blockchain provides better anonymity and gives users the freedom to express themselves freely with this decentralized consensus framework, implying that no one can hack into the user’s account without their permission. Users can conduct the transactions privately because only the recipient and sender know its content. Consider the ultimate level of privacy; this can be expected from blockchain-based social media platforms.

Look for copyrights

The social media platforms are built with a specific goal of allowing people to express themselves and broadcast content that traditional media often fails to reveal. On the other hand, most devices have resulted in multiple tech corporations controlling social media data flow due to the concurrent structure. If social media networks adopt blockchain technology, the platforms will become censorship-resistant. However, people can communicate to the world without fear of having their profile blocked or, worse, being detained.

Copyrights are still a challenge in blockchain-based social media platforms, as no copyright registry reference exists. Yet all platforms use this. A blockchain that serves as a global registry based on time-stamp might solve this challenge. Using such systems will guarantee a high level of copyrights reservation. It is an idea already under discussion.

Traditional vs. Blockchain-Based Social Media

Though blockchain-based social media platforms are open-source like traditional ones, they offer free and paid service, and user data is not sold for profit. The significant difference is that blockchain-based applications allow users to earn and spend cryptocurrency through the application. Users make tokens by doing the following: posting, commenting, receiving upvotes, and inviting others to join the site. In some applications such as Minds, the earned tokens can be used to improve posts and obtain access to any content and the opportunity to become verified users and delete all boosted posts from their feed. Apart from allowing users to earn cryptocurrency, these blockchain-based social networking applications also help with information security, freedom of expression, and privacy. From the security perspective, blockchain-based applications enable end-to-end encryption for messages and allow users to have security rights on all information they access.

Conclusion

Blockchain-based social networking applications and platforms are probably the new future of social media. Its benefits focus on securing data and personal information by providing end-to-end encryption for all interactions, storage & device security, transaction verification, etc. They allow consumers to exercise greater control over their data, among other things.


About the Author 

Elbachir Haimoud is an information security and compliance officer at TÜRKKEP A.Ş. and is an experienced infosec professional with practical knowledge of application development, security, and penetration testing. Haimoud also has practical experience imparting his IT security knowledge to engineering students and cybersecurity aspirants.

Invest in Advanced Identity Detection and Response Solutions

Proactive Cybersecurity Paradigm, cyberwar, IoT, 5G, Boardroom, Identity Detection and Response, Predictions, supply chains, hybrid workforce

The perimeter disappeared when remote working came along, and all the security mechanisms for protecting information assets behind a firewall, were no longer adequate. The attack surface has broadened to include home networks, and the attack vectors are directed towards home users. There are also devices and applications that are connecting to the enterprise network, from outside. Identity management becomes crucial in this scenario. Enterprises need to invest in Identity Detection and Response (IDR) solutions to secure the broadened attack surface (and remote workers).

By Carolyn Crandall, Chief Security Advocate, Attivo Networks

Enterprises will increase their investment in identity security solutions. The rise in third-party attacks, remote working security risks, and the continuing evolution of ransomware have driven home the fact that traditional security solutions are no longer enough. And while existing solutions like Identity and Access Management (IAM), Privileged Access Management (PAM), and Identity Governance and Administration (IGA) provide basic identity protections, their focus on authorization and authentication leave gaps for attackers to exploit. To close these gaps, enterprises need to be investing in Identity Detection and Response (IDR) solutions capable of providing expanded exposure visibility and detection specific to credential misuse, excess entitlements, privilege escalation, and other common identity-based attack activities. 

Misdirection and concealment capabilities rise to the forefront of cyber defense. With the assumption that attackers can and will get inside networks, companies will see a greater need for in-network lateral movement prevention and privilege escalation defense measures. Uncovering and derailing attacks in real-time requires proactive concealment to hide and deny access to assets (credentials, Active Directory objects, and data) and decoys to misdirect attackers away from their targets. With the speed of attacks today, businesses need proactive visibility and measures that detect attacker lateral movement. The focus centers on preventing the attacker from breaking out from its initial infected system regardless of whether it is a managed or an unmanaged device.

Ransomware defenses must get a badly needed refresh. Ransomware 3.0 is here. Characterized by double extortion, where cybercriminals not only encrypt files but also leak information online, it can drastically impact everything – the company’s image, profits, and stock price. There’s no longer a one-size-fits-all approach to defending against these attacks. With over 300 variants, stopping ransomware requires a multi-faceted approach. One that starts with protecting Active Directory and privileged credentials. In 2022, organizations will be unable to understand how each group operates and, instead, will need to improve their visibility to exposures and add detection measures based on technique. Setting up traps, misdirections, and speed bump lures along the way will also serve as strong deterrents to keep an attacker from being successful.


About the Author

Carolyn Crandall is the Chief Security Advocate at Attivo NetworksCarolyn Crandall is the Chief Security Advocate at Attivo Networks, the leader in preventing identity privilege escalation and detecting lateral movement attacks. She has worked in high-tech for over 30 years and has been recognized as a top 100 women in cybersecurity, a guest on Fox News, and profiled in the Mercury News. She is an active speaker on security innovation at CISO forums, industry events, and technology education webinars. Carolyn also co-authored the book Deception-Based Threat Detection: Shifting Power to the Defenders.