Microsoft’s security experts identified a novel malware campaign targeting several IT, non-profit, and government organizations based in Ukraine. Tracked as WhisperGate, the activities of the destructive malware campaign were first spotted on January 13. As per a report from Microsoft Threat Intelligence Center (MSTIC), the malware used by this campaign is designed to look like ransomware but lacks a ransom recovery mechanism. It’s found that the campaign is intended to compromise the targeted systems rather than to obtain a ransom.
“Our investigation teams have identified the malware on dozens of impacted systems, and that number could grow as our investigation continues. These systems span multiple government, non-profit, and information technology organizations, in Ukraine. We do not know the current stage of this attacker’s operational cycle or how many other victim organizations may exist in Ukraine or other geographic locations. However, it is unlikely these impacted systems represent the full scope of impact as other organizations are reporting,” MSTIC said.
While the attackers behind this malware campaign are unknown, Microsoft stated it had notified the affected users and organizations about WhisperGate.
WhisperGate Campaign Infection
The WhisperGate malware is capable of overwriting the Master Boot Record (MBR) on victim systems with a fake ransom note. The ransom note contains a Bitcoin wallet and Tox ID. The malware executes when the compromised device is powered down. Once infected, the malware resides in various working directories, including C:\PerfLogs, C:\ProgramData, C:\, and C:\temp, and is often named stage1.exe.
“The malware executes when the associated device is powered down. Overwriting the MBR is atypical for cybercriminal ransomware. In reality, the ransomware note is a ruse, and the malware destructs MBR and the contents of the files it targets,” MSTIC added.
Mitigations
Review all authentication activity for remote access infrastructure, focusing on accounts configured with single-factor authentication, to confirm the authenticity and investigate any abnormal activity.
Enable multifactor authentication (MFA) to mitigate potentially compromised credentials and enforce MFA for remote connectivity.
Use the included indicators of compromise to investigate whether they exist in your environment and assess for potential intrusion.
Several organizations started the New Year globally with hacker intrusions and data breaches, but few cybercriminal groups benefitted from their malicious activities. A recent analysis from blockchain firm Chainalysis revealed that North Korean threat actors stole over $400 million worth of cryptocurrency in 2021 by compromising multiple crypto exchanges and investment companies. It is no surprise that hackers target the booming cryptocurrency economy after the value of cryptocurrencies like Bitcoin and Ethereum skyrocketed recently.
According to the analysis report, North Korean crypto hackers launched around seven attacks on cryptocurrency platforms by targeting investment firms and centralized exchanges.
A hot wallet allows users to store, send, and receive digital coins linked with public and private keys that help facilitate transactions. Since hot wallets are connected to the internet, they are vulnerable to cyberattacks and unauthorized intrusions. Hackers reportedly leveraged phishing lures, code exploits, malware, and advanced social engineering techniques to siphon crypto funds from hot wallets.
Lazarus Group – The Main Culprit
Researchers suspect that the infamous Lazarus group is behind these crypto hacks. Lazarus is a North Korean hacking group active since 2014 and accused of several cybercriminal activities. The group is better known for its cyberattacks on international organizations with multiple malware variants such as AppleJeus, Fileless, ThreatNeedle, and MATA. Initially, Lazarus gained notoriety from its 2017 WannaCry 2.0 global ransomware attack, but the group turned to cryptocurrency crimes.
Researchers stated that North Korean hacking activity was on the rise in 2021. From 2020 to 2021, the number of cryptocurrency hacks grew by 40%.
“Interestingly, in terms of dollar value, Bitcoin now accounts for less than one-fourth of the cryptocurrencies stolen by DPRK. In 2021, only 20% of the stolen funds were Bitcoin, whereas 22% were either ERC-20 tokens or altcoins. And for the first time ever, Ether accounted for a majority of the funds stolen at 58%,” the researchers said.
Money Laundering to Cash Out
It is found that Lazarus operators used multiple money laundering processes to cash out after stealing the funds. North Korean hackers’ typical money laundering process include:
ERC-20 tokens and altcoins are swapped for Ether via decentralized exchange (DEX)
Ether is mixed
Mixed Ether is swapped for Bitcoin via DEX
Bitcoin is mixed
Mixed Bitcoin is consolidated into new wallets
Bitcoin is sent to deposit addresses at crypto-to-fiat exchanges based in Asia for potential cash-out points
“These behaviors, put together, paint a portrait of a nation that supports cryptocurrency-enabled crime on a massive scale. Systematic and sophisticated, North Korea’s government—be it through the Lazarus Group or its other criminal syndicates—has cemented itself as an advanced persistent threat to the cryptocurrency industry in 2021. Nonetheless, the inherent transparency of many cryptocurrencies presents a way forward. With blockchain analysis tools, compliance teams, criminal investigators, and hack victims can follow the movement of stolen funds, jump on opportunities to freeze or seize assets, and hold bad actors accountable for their crimes,” the researchers added.
IT experts rise to the rank of chief information security officer (CISO) because they have mastered the science and engineering involved in that discipline. But for a CISO to thrive, leadership skills are critical. And leadership is an art.
By Prasad Jayaraman, Principal, Advisory at KPMG
Blending the science of technology with the art of leadership is the challenge facing many CISOs, who are regularly thrust into the spotlight as companies continually deal with cybersecurity threats and events. Indeed, 81% of CISOs report to a firm’s board of directors at least annually; most do so every quarter.1
If that is not exactly what you signed up for when you got into computer science or IT, and you are feeling the stress of this high-profile position, you are not alone. The overwhelming majority of CISOs (88%) are “moderately” or “tremendously” stressed in their job – and why not? Two-thirds (66%) said their organization had at least one security breach in the past 12 months. Plus, they feel the pressure of performance, as 97% of their C-suite stakeholders believe IT security should deliver more value for the cost.2
While the demands on a CISO are considerable, the job can be more satisfying and less stressful when CISOs work to refine the “art” part of their responsibilities: leadership. And many of the leadership qualities and skills that can breed success (and less stress) for CISOs can be learned, practiced, and mastered.
Five CISO Leadership Attributes
As CISOs, CIOs, and other technology leaders gain more importance within organizations, they also undergo more scrutiny as expectations for their roles continue to rise and expand. Not only are they expected to guide and oversee a critical element of the business, but they also do this with the realization that their performance plays a key role in the organization’s reputation.
Central to their responsibilities is helping their organizations gain and maintain the trust of stakeholders, something we have coined as “The Trust Imperative.” The importance of this cannot be overstated. As we see it, trust is the ultimate business enabler. When enterprises inspire trust in all their stakeholders, they create a platform for better business performance – including responsible growth, bold innovation, and sustainable advances in performance and efficiency.
To succeed against this challenge, CISOs must inspire confidence, help strike a pragmatic balance between threat and opportunity, and demonstrate the ROI on their recommendations – in short, they must emerge as respected and integral company leaders. But trust is hard-earned and easily lost. And nothing will break trust faster than a security breach. This leaves the CISO in a precarious position, shouldering outsized responsibility for the organization’s brand affinity.At KPMG, we have delved deeply into the technology leadership arena and unearthed what we believe are five key attributes that make a CISO or other technology executive a strong and effective leader – one who will help the company earn the trust that stakeholders seek.
1. Create value. While CISO and related cybersecurity roles are primarily created to address compliance issues and security, that mindset is evolving. The C-suite demands all functions generate active value, and IT (or broader) security is no different. That requires a broad view of risk to the organization and the courage to make hard choices.
According to a KPMG survey,4 CEOs are well aware of the importance of digital technologies in creating value for the company. Indeed, about two-thirds said they had plans to invest in disruption detection and innovation processes to spur growth, demanding new approaches to managing data and information risk.
The key to this is determining the boundaries of digital security to enable growth and value without exposing the company to undue peril. CISOs who adroitly apply risk management to decision-making and recommendations will sync with their fellow business leaders.
2. Influence. While most corporate leaders have control of their budget and infrastructure, the CISO depends on others to implement and embed security policies and standards. Yet, even if your budget is “owned” elsewhere, you will be measured – and appreciated for – the influence you and your teams have on the company as it strives to keep cyber threats at bay.
You need to understand how and when to use your influence to motivate, enact change or propel a project forward. This requires some skillful maneuvering. If you can positively influence stakeholders with recommendations that will benefit the organization, your leadership will be respected, and your influence will grow. When you raise concerns, they will be listened to, treated seriously, and acted upon.
Influence is such a critical leadership attribute that the KPMG Executive Leadership Institute for Women devotes a course to this topic, but its principles apply to leaders of any gender.
3. Willingly collaborate. The days of the IT security team working stealthily in a dark room, with little interaction with business leaders, are long over. While CISOs may often be seen as “servant leaders,” as they put the needs of the business divisions they serve, their true value will stem from their ability to be seen as true partners with their C-suite colleagues. Those who develop and exercise collaboration skills will earn a seat at the decision-making table that extends well beyond cyber events.
Moreover, CISOs must extend their influence and integration abilities outside the company’s four walls. An organization is truly safe from cyber threats only if its broader ecosystem is. So forging relationships with vendors and partners is a critical aspect of CISO function – especially since 79% of CEOs say that protecting the partner system and supply chain is just as important as building the company’s cyber defenses.5
4. Top off your tech skills. Sure, technology acumen is a given for the CISO job, just as mastering accounting and finance is for the CFO. But it is imperative to stay on top of your game. Cybersecurity is a mercurial field, and CISOs must keep abreast of the latest technology developments, threats, and compliance issues; when it comes to IT and data security, no one likes surprises – and you will be in the hot seat if one emerges.
5. Become immersed in the business. The CISO ultimately exists to protect the organization and the data, which is its lifeblood. To be the most effective CISO leader, you require understanding of the nuances of technology as well as the nuances of the industry in which your firm competes. The more you understand the business, the more you will be able to weave cybersecurity into the company’s DNA.
CISOs must speak the language of the C-suite and learn how to navigate company politics. It is the only way to build trust, be involved in forming consensus, and ensure your fellow leaders fully recognize how strategic decisions impact – and are impacted by – digital technology and cybersecurity.
So, now that we have identified some of the skills needed to be a successful CISO leader, the question remains: How do you acquire them?
That can be an especially vexing problem for IT natives who have little background in business management. But there are several tactics you can employ to acquire leadership techniques and the confidence to use of them.
An excellent place to start is to learn from more experienced leaders, be they in IT or other functional areas. Seek out a mentor, inside or outside your organization, who can serve as both a sounding board and a counselor as you face new and unfamiliar challenges.
It is also important to hone your communications skills further through one-on-one or group training sessions that focus on public speaking or interpersonal communications. Do not let shyness or an affinity for staying in the background disrupt your ability to lead effectively.
You may also seek the services of executive leadership training & development programs offered by universities or consultancies. The best programs cater to the busy, working executive with online options, or you can participate on evenings or weekends.
But most of all, you should seek to forge strong alliances with other business leaders in your organization, especially those in adjacent areas such as the top risk, digital, and information officers. These alliances are key to influencing, broader understanding, and to mutual challenge and support.
As a CISO, you may have embarked on a career path you were not anticipating. But if you embrace the challenge, honestly assess your strengths and weaknesses, and reach out for assistance to build your leadership muscle, you will earn your seat at the corporate decision-making table.
Prasad Jayaraman is a Principal in KPMG’s Advisory Services practice with more than 17 years of experience in identity management and a strong track record of performance in technology professional services organizations.
Disclaimer
Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG, and CISO MAG does not assume any responsibility or liability for the same.
Ransomware in a triad is the title of a recent cybersecurity article that caught my attention. The same repetitiveness can be found in aviation and dates back to poor radio communications where it was necessary to repeat a message. Repetitiveness such as Mayday! in triplet or Eject! in a triad ensures everyone knows what to do in a critical situation. While using the same term repeatedly is a great way to get readers’ attention and create a sense of urgency, it is far less effective when the concept, the word is meant to represent is poorly defined. So, let’s not fall for the hype of it all – let’s better understand the problem to determine how it can be solved.
First and foremost, we must appreciate that ransomware is a result. Results cannot be replicated or easily mediated if we do not understand the causes. While crying “ransomware” in triads creates a sense of urgency, it fails to tell us anything about the actual crisis, which is a problem. Paradoxically, the attention created by such articles subverts progress because we focus too much on the result instead of understanding the cause. In the case of ransomware, this problem resides within a broader context and a much larger issue called cybersecurity.
Reductionism – break it up to solve it
Reducing problems into smaller problems is reductionism. Reductionism involves breaking down a problem into smaller parts that are more manageable and easier to understand and solve, which is an effective problem-solving strategy. Reductionism is necessary when we cannot solve problems directly or entirely. However, blind reductionism (i.e., focusing exclusively on a partial problem) has a cost, even if reductionism is best suited to solving a specific problem. And this is, a greater problem with ransomware. It does not matter how often we say it if we conceive it as independent of cybersecurity.
Reductionism defines the cybersecurity market. Consider point products that have become very common in cybersecurity and especially popular for many machine learning start-ups. The reason is that it helps early-stage companies get out of the door and provide a complete solution to a partial problem to acquire a customer. However, it comes at the expense of addressing all requirements that might otherwise be met with a multipurpose solution. Therefore, essential aspects of the cyber problem keep falling into blind spots.
Even traditional SIEMs which market themselves as multipurpose solutions are composed of many partial solutions but implemented separately and are therefore reductionist. In the cyber context, smaller parts may include rule and signature-based detection, behavioral analytics based on threat vectors, or indicators of compromise. However, when implemented individually and independently, a solution will adhere to the approach known as separation of concerns.
Separation of concerns
Separation of concerns is a design principle for separating a computer program into distinct sections. Each section addresses a particular concern, but we may lose sight of the overall problem or the entire solution. We cannot get lost in a part of the problem or part of the solution. Instead, we must oscillate between parts of a problem and the whole and thus, between reductionism and holism.
Oscillating between parts of a problem and the whole is vital because practical problem-solving requires understanding where to start and stop. We must figure out the problem, what it means, where it starts and ends. These are boundaries that all need to be understood because boundaries tell you what to do and not to do. Ransomware fails us because it tells us nothing about the problem. If we fail to know anything about the problem, we will not know where to start or stop.
Blind reductionism and fragmentation of both the cybersecurity problem and market are the reasons why the industry needs to focus on the whole problem and still use reductionism to understand each problem. Therefore, the best solution uses a meta-algorithm for distributed learning over the whole cybersecurity problem. Meta-algorithms are important in iterative and adaptive computations that show dispersed and often continuous problem-solving. The general idea of combining information from multiple sources and creating a strong solution by combining and orchestrating many partial solutions can be applied broadly to the cybersecurity problem.
To be sure, ransomware is a severe threat, but it requires broader thinking to prevent. At the same time, this is not a hopeless critique of reductionism. Instead, blind reductionism is a problem if we forget adjacent problems. In other words, for complex problems like cybersecurity, we must reduce problem size to a size small enough to solve, but not forget that they are parts of a much larger problem that needs to be solved. Of course, all that in a triad isn’t as clickable.
About the Author
Rich Heimann is Chief AI Officer at Cybraics Inc. Cybraics is a fully managed cybersecurity company. Founded in 2014, Cybraics operationalized many years of cybersecurity and machine learning research conducted at the Defense Advanced Research Projects Agency.
Disclaimer
Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG, and CISO MAG does not assume any responsibility or liability for the same.
State-sponsored hackers from Russia continue to prevail in the cyberthreat landscape. Government authorities and organizations globally are warning about frequent cyberespionage campaigns from Russian actors. Recently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), FBI, and National Security Agency (NSA) released a joint advisory on detecting, responding, and mitigating security threats from Russian state-sponsored actors. The advisory provides an overview of Russian hackers’ cyber operations, including their commonly used tactics, techniques, and procedures (TTPs).
“CISA, the FBI, and NSA encourage the cybersecurity community—especially critical infrastructure network defenders—to adopt a heightened state of awareness, conduct proactive threat hunting, and implement the mitigations identified in the advisory,” the advisory said.
Russian APT Actors
The federal agencies stated that Russian state-sponsored advanced persistent threat (APT) actors leveraged various attacking vectors like spearphishing, brute force, and exploiting known vulnerabilities to break into targeted network systems.
Vulnerabilities known to be exploited by Russian state-sponsored APT actors for initial access include:
Russian actors reportedly targeted a variety of U.S. and international critical infrastructure organizations in the Defense, Health Care, Public Health, Energy, Telecommunications, and Government Facilities Sectors.
The advisory stated that organizations detecting potential APT activity in their network systems should:
Immediately isolate affected systems.
Secure backups. Ensure your backup data is offline and secure. If possible, scan your backup data with an antivirus program to ensure it is free of malware.
Collect and review relevant logs, data, and artifacts.
Consider soliciting support from a third-party IT organization to provide subject matter expertise, ensure the actor is eradicated from the network, and avoid residual issues that could enable follow-on exploitation.
Mitigation
CISA, the FBI, and NSA recommended organizations implement the below security measures to increase their cyber resilience against rising threats:
Develop internal contact lists. Assign main points of contact for a suspected incident and roles and responsibilities and ensure personnel knows how and when to report an incident.
Minimize IT/OT security personnel availability gaps by identifying surge support for responding to an incident.
Ensure IT/OT security personnel monitor key internal security capabilities and identify anomalous behavior. Flag any identified IOCs and TTPs for immediate response
Create, maintain, and exercise a cyber incident response and continuity of operations plan.
Require multi-factor authentication for all users, without exception.
Require accounts to have strong passwords and do not allow passwords to be used across multiple accounts or stored on a system an adversary may have access to.
Identify, detect, and investigate abnormal activity that may indicate lateral movement by a threat actor or malware.
Since digitalization began, there has been a significant increase in organizations turning to cloud computing. Most companies leverage multiple cloud environments to host their critical IT infrastructures, a primary target to cybercriminals. Cybersecurity experts from Cisco Talos recently uncovered a cyberespionage campaign actively exploiting public cloud services like Microsoft Azure and Amazon Web Services to deploy multiple commodity remote access trojans (RATs) like Nanocore, AsyncRAT, and Netwire.
Since October 2021, the campaign mainly targeted organizations in Canada, the U.S., Italy, and Singapore. Attackers reportedly stole sensitive information from the compromised systems.
“These variants of Remote Administration Tools (RATs) are packed with multiple features to take control over the victim’s environment to execute arbitrary commands remotely and steal the victim’s information. The threat actor, in this case, used cloud services to deploy and deliver variants of commodity RATs with information-stealing capability,” the researchers said.
Infection Chain
The infection chain begins with a spearphishing email that contains a malicious ZIP file attachment. The ZIP file holds an ISO image containing the loader in JavaScript, Visual Basic script, or a Windows batch file format. Hackers prompt the users to open the attachment mimicking it as an invoice document.
Once a victim downloads the attachment, the initial script will be executed on the device and automatically connects to a download server to install the next stage. Operators behind this campaign maintained a distributed infrastructure consisting of download servers, command and control servers, and malicious subdomains to distribute the malware payload.
Indicators of Compromise (IOC)
Some of the observed ZIP file names include:
WROOT_Invoice_Copy.zip
YUEOP_Invoice_Copy.zip
HOO8M_Invoice_Copy.zip
TROOS_Invoice_Copy.zip
TBROO1_Invoice_Copy.zip
“Organizations should deploy comprehensive multi-layered security controls to detect similar threats and safeguard their assets. Defenders should monitor traffic to their organization and implement robust rules around the script execution policies on their endpoints. It is even more important for organizations to improve email security to detect and mitigate malicious email messages and break the infection chain as early as possible,” the researchers added.
In security, you always need to be thinking ahead about what might come down the pipeline. As we wrapped up the year 2021, I saw several areas across security where CISOs and other security leaders will likely concentrate their efforts and focus. One of those is the need to protect supply chains and the hybrid workforce.
ByJason Lee, Chief Information Security Officer at Zoom
First, more companies will adopt the Zero-Trust security model to adapt to hybrid working environments. Conversations around protecting the hybrid workforce from risk will lead security professionals to adopt modern tools and technologies, like multi-factor authentication and the Zero-Trust approach. Companies need these tools to ensure their employees can get work done as safely as possible from wherever they are—commuting, traveling, or working from home—and that all of their endpoints are secured with continual checks.
Second, security leaders will step up their protections against third-party risks. From SolarWinds in December 2020 to Colonial Pipeline and Kaseya in 2021, our industry saw a distinct increase in supply chain attacks. CISOs and CSOs will need to confirm their vendors are also secure, look at third parties related to the business and assess how to manage risks best.
Third, more public technology companies will create dedicated cybersecurity committees on their boards of directors. One of the most impactful things we did at Zoom this past year was to institute a three-person committee on our board dedicated to cybersecurity matters. Having security industry experience at this level is incredibly valuable, allowing us to address concerns and issues in industry shorthand readily. And I’ve heard peers express strong interest in recreating this approach at their own companies, which leads me to expect this will be a priority for organizations in the new year.
Lastly, the security hiring boom will continue. Cybersecurity professionals are a hot commodity across industries, due to more available jobs than trained applicants. The U.S. Bureau of Labor Statistics reported that employment for information security analysts is projected to grow 33% from 2020-2030. We’ll see the cybersecurity talent pool grow as more professionals choose to enter the field due to increased demand and, in many cases, the ability to work from anywhere.
Jason Lee has 20 years of experience in technology, with a specialization in information security and operating mission-critical services. He was recently the Senior Vice President of Security Operations at Salesforce, where he was accountable for the global organization delivering critical end-to-end security operations to customers and employees including company-wide network and system security, incident response, threat intel, data protection, vulnerability management, intrusion detection, identity and access management, and the offensive security team.
Prior to Salesforce, he held the position of Principal Director of Security Engineering for the Windows and Devices division at Microsoft with the charter of protecting the online services of Windows Update, XBOX Live, and the Microsoft online store. He was also the Senior Director of Developer Services, where he was responsible for the design and management of the mission critical PKI for all products across Microsoft. This included cryptographic services in products such as Windows and SQL Server and cloud services such as Azure and Office 365. Additionally, Lee was responsible for the co-designing and anti-malware services supporting Microsoft in that role.
Security experts from SentinelLabs uncovered a high severity vulnerability in the KCodes NetUSB component used manufacturing of Wi-Fi routers from EDiMAX, Netgear, TP-Link, Tenda, D-Link, and Western Digital. NetUSB is a product developed by KCodes. It is designed to allow remote devices in a network to interact with USB devices connected to a router. The vulnerability tracked as CVE-2021-45608 is a buffer overflow flaw that could enable hackers to execute malicious code remotely in the kernel and compromise the device, affecting millions of routers globally.
“While going through various paths through various binaries, we came across a kernel module called NetUSB. As it turned out, this module was listening on TCP port 20005 on IP 0.0.0.0. Provided there were no firewall rules in place to block it, that would mean it was listening on the WAN as well as the LAN. Who wouldn’t love a remote kernel bug,” the researchers said.
Mitigation
Given the flaw’s severity, millions of users who are using the vulnerable devices are exposed to hacker intrusions. The researchers stated they had reported the vulnerability to the manufacturers. The only way to fix this vulnerability is by updating the router to the latest available firmware.
“This vulnerability affects millions of devices worldwide and may be completely remotely accessible in some instances. Due to the large number of vendors that are affected by the vulnerability, we reported this vulnerability directly to KCodes to be distributed among their licensees instead of targeting just the TP-Link or the Netgear device in the contest. This ensures that all vendors receive the patch instead of just one during the contest,” the researchers added.
Routers – Hackers’ Favorite Target
With most employees working remotely, cybercriminals increased their hacking attempts targeting vulnerable commercial IoT devices like Wi-Fi routers. Recently, a security research report from Eclypsium revealed that over 300,000 IP addresses related to MikroTik devices were exposed to remotely exploitable security vulnerabilities. The flaws in MikroTik devices could expose users and enterprises to various security risks. They can allow remote access to hackers to exploit and penetrate the network.
Unresolved security issues serve as frequent attack vectors for opportunistic cybercriminals. It is known that threat actors often target publicly known or unpatched security vulnerabilities to break into organizations’ critical network systems. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added 15 new security flaws to its Known Exploited Vulnerabilities Catalog, which adversaries are actively exploiting. The agency stated that these vulnerabilities have become a constant attack vector for malicious actors and pose a significant risk to federal enterprises.
Of the 15, four vulnerabilities were disclosed between 2020 and 2021, and the rest date back to 2013 and 2015. Some of the newly added vulnerabilities are rated as medium risks in severity. CISA urged federal agencies to address these susceptibilities as early as possible by applying the available patches to prevent ongoing cyberthreats.
CISA recently issued a Binding Operational Directive (BOD) to reduce the risk of actively exploited vulnerabilities. The new Directive, which applies to all software and hardware found on federal information systems, requires federal civilian agencies to remediate such vulnerabilities within specific timeframes. According to CISA, over 18,000 vulnerabilities were identified in 2020. Public and private sector organizations find it difficult to remediate the growing security flaws. From 2015-2018, the number of new flaws surged from 6,487 to 17,305, and 9,883 of these were rated high and critical. Read More Here…
Trend Micro opened a new office in Mumbai last month. Located in Bandra Kurla Complex, the 6,879 sq. ft. office space has a Center of Excellence (CoE) and Executive Briefing Center (EBC). With the launch, Trend Micro aims to expand its cloud business in Indiaand grow its incident response and local support teams. The company aims to continue its current focus on BFSI and specific areas in government, including defense and state data centers. It is considering additional investment in the SMB and mid-market segments, due to the surprising growth observed last year.
Image credit: Trend Micro (India)
CISO MAG was invited to visit Trend Micro’s cozy Mumbai office in December 2021. On this visit, Brian Pereira, Editor-in-Chief, CISO MAG, met Nilesh Jain, Vice President, Southeast Asia and India, Trend Micro, and Vijendra Katiyar, Country Manager, India & SAARC, Trend Micro. In an hour-long interview they spoke about the company’s achievements and plans for India. They also discussed security challenges and how organizations can cope.
Edited Excerpts from the interview follow:
How was the year 2021 for you in terms of business performance?
Nilesh Jain: We had unprecedented growth this year (2021), and we just published our financial results for Q3; we outperformed what we forecasted. We did an upward correction on the forecast for the rest of the year. We recorded 11% year-on-year growth and significant growth in our SaaS business (double-digit), so retention is good. All the regions, including the Americas, Japan, Europe, and EMEA, performed tremendously well.
This growth is due to multiple reasons. Firstly, digital transformation has increased budgets for enterprises to invest in cybersecurity. We have been seen as a frontrunner for most cybersecurity technologies. In early 2019, we invested in XDR, the next generation of cross-generation detection and response capabilities. And we immediately saw the results. We had tremendous growth in the XDR product in America, Europe, and EMEA. Then we started acquiring new logos (new customers) across verticals. Many customers are looking to switch over from the struggling vendors, who probably can’t catch up.
What kind of transformation is happening with the cloud, and what (security) challenges does it raise for business?
Nilesh Jain: Cloud is getting more complex because suddenly you are trying to take a journey in six months or one year, which otherwise would have taken four or five years. Because of the pandemic, you have been forced to do something very quickly while your employees are working from home. Your competitors are born in the cloud companies, and you started competing with those players who never existed before. Business models change. There are born in the cloud companies, Internet companies, new business model companies.
Look at any domain, whether it is FMCG, retail, or the financial sector — the people we are competing with now have an IT background. The promoters of Fintechs and e-commerce companies are all IT people. So, technology started building competition for the so-called “legacy enterprises,” which were never seen as competition. I’m using legacy in a very positive way; I would call these “stabilized enterprises.” But stabilized enterprises who thought they could do this digital transformation project in three or four years never had that time.
Secondly, cloud adoption increased fast. New services were introduced in a short time. For instance, AWS launched as many new services (120) in the past two years as they previously launched in 10 years. Suddenly, the complexity of managing services and different threats come up because those services were not expected or explored. An organization lacks the skills to deal with all these new services, and it does not have a complete understanding of cloud architecture from a security perspective. And that’s why hackers can break into systems. It is because you lack the skills to protect those systems.
About the challenges. On the one hand, CIOs and CISOs are moving quickly to support business functions. Then they realized that security was left behind. So, that is one challenge we have seen. When employees started working from home, the second challenge was that the perimeter they built up for security was not there anymore – firewall and the IPS (intrusion prevention system). They are not working within those perimeters anymore. The endpoint moved away from the office, and servers in the local data center moved out of the office (to the cloud). Within your office environment and network, you have adequate security measures, but these are no longer relevant. Critical data has now moved to the cloud, and your endpoint computing has moved to the home. That’s why the biggest concern for CIOs and CISOs biggest is how they can still get centralized visibility (like before the pandemic).
Vijendra Katiyar: No company was prepared for 100% work from home. The CISOs and CIOs we spoke with said the first problem was providing the assets (laptops). And when employees started accessing corporate applications from home, that posed a big risk to the corporate infrastructure since they were not adequately protected. Standard security policies for home users were not yet implemented. And it became a challenge to protect those endpoints and personal devices. The applications had to be protected. And that became a challenge because the applications are hosted in the cloud. And this is the reason for adopting zero-trust architecture and SASE (Secure Access Service Edge).
CISOs were now asking how to do all this to secure applications and endpoints. They were wondering how to introduce more controls without compromising user flexibility. At the same time, we do not want to put in too many controls because security should not be considered a hindrance. We should ensure that the right access is given to the right individual.
To summarize, the cloud has new challenges because of the very fast adoption and complexity of services, which leads to a lack of security understanding. And they wanted centralized visibility of what’s happening on their virtual network. These are the two major challenges we have seen for CISOs in the last two years.
What security advice would you give to businesses transitioning to the cloud and adopting emerging technologies like IoT, blockchain, and AI/ML?
Nilesh Jain: I have three pieces of advice. One, do not do digital transformation or cloud adoption for the sake of it, or just because someone else has done it. Please do not do it because it is popular, and you want to keep up. Because if you do that without careful consideration, you are bound to fail.
Two, look at your business objective. Cybersecurity is more about business objectives and more proactive than reactive. Understand where your business is trying to go. Understand why you want to do something.
Third, which facet of your business do you want to transform first? If you want to go the B2C way, you want to engage with customers in very different ways or create a different delivery mechanism. You want to pass on the cost advantage.
So, understand what it is that you are trying to do. Get your business priorities right.
There is a lot of virtualization going on. Even desktops are being virtualized with VDI. It is going towards the data center. I see the whole responsibility of security shifting to the cloud service provider. How are you working with data center providers? Because the infrastructure is not on-premise anymore. It’s on the cloud. That’s where the data and applications reside – which need to be secured.
Nilesh Jain: We don’t have to worry about that because we have been providing data center security for many years. Today, the endpoint includes both: servers and clients. So, this question should not worry people who thought an endpoint would always remain an endpoint.
We always had custom design server security for a reason; it was designed to protect the data centers. The only thing that changed is that they started moving from the private cloud to the public cloud or using a hybrid cloud. New services emerged. We moved from legacy applications and shifted to the DevOps side. In this scenario, 20% – 30% of large enterprises use Kubernetes containers, which are more serverless. We know this game very well, so we don’t have to catch up. I mean, we don’t have to learn because we know how server applications work. We know how the data flow and data movements happen. That’s why we have been leaders with almost 30% global market share for Server Security. We started working with AWS way back in 2011 – 2012 when we were still teaching the world about cloud computing. Because of this, our learning curve gave us very good anticipation of what’s coming next, and we have been able to build a product, which is future ready.
So, while everyone was talking about shift-left, which is the DevOps side, we already had DevOps security for reasons there. Deep security was primarily deployed on-premise, on the virtualization security side – and we quickly shifted back to DevOps. We changed the entire architecture of our product to make it DevOps ready. And because of this, we have host-based security; we have file storage security; we do cloud cluster management; we do cloud-native application security; we do Kubernetes security. And that’s our USP.
Here’s what’s happening today. CISOs are offered one dozen different solutions for Kubernetes security. They are told to buy this, but they need a different solution if they are going serverless. If they are going on file storage, they must buy something else. And this goes back a few years when, for endpoint, you had to buy different solutions and load it up on endpoints, which is not practical. Instead, we offer comprehensive cloud security, which does everything. It is all integrated, all bundled into one customer solution.
We believe customers should not buy a product. They should buy a partner. If you happen to choose the right partner, you don’t have to keep on scouting for the right products. Your partner does it for you. We are building everything that they will require through integrations. And we work with most of the cloud services: Azure, Google, AWS, and do the integration.
There is always going to be the question about ROI in Security. Earlier, ROI was more on qualitative terms. Now you define it in quantitative terms and see how much impact it has on business. When customers deploy Trend micro’s Cloud One, we can immediately show tangible results. And if you use it over, say, five years, we will be on that journey with you, and you do not need to re-architect your cloud security posture. The same product can scale up to your future needs. So, we protect a lot of manpower efforts and customer investment.
Let’s talk about your investment in Cloud One data centers. How much are you investing? How does this fit in your India plans?
Vijendra Katiyar: I won’t put a number on it. Of course, it is very important and relevant to us. We see a lot of interest in the cloud from both private enterprise, government, and public sector companies. Many of our customers are from the banking sector, the financial vertical, regulated by different bodies. So, data sovereignty and data residency become very important. If you want customers to adopt cloud services, you must address this.
When customers move from on-premises to the cloud, you need to think about how to secure their infrastructure. How do you ensure that the journey is smooth without worrying about those security concerns? So, one of those critical initiatives was to have a Cloud One data center hosted in India. The platform is hosted with a cloud service provider in Mumbai. It is offered to any customer, any enterprise in India, or to the government. Very recently, the government introduced a data privacy law. It released guidelines for data residency. While this applies to certain verticals, we see it also coming to other industries that are not so regulated. They will also start insisting on data sovereignty.
So, it made a lot of business sense to support our customers to ensure that we are there to secure their applications, servers, and workloads in the cloud if they are using any of the cloud service providers.
Where do you see the biggest potential in India for your solutions? And how are you going to address that market?
Nilesh Jain: In India, the biggest potential has to be unleashed from the SMB and mid-enterprise markets. They yearn for an SOC operation at affordable pricing. One can provide that affordability only through a locally delivered ecosystem. It calls for local SOC partners who can deliver that value at economical value. And that is what we are delivering. We can unleash the potential today through XDR. But it’s been adopted only by a few large enterprise customers who have multi-million dollar budgets and some compliance to fulfill.
The biggest potential lies in the mid-market — SMB or lower pie of large enterprises. And that’s a potential that we are trying to unleash by creating a comprehensive service delivery at much more economical prices. For that, we need to have SOC partners who can do a much better job.
We are working with SOC partners and integrating our products there, scaling them up. The backbone of that SOC is still Trend Micro Vision One. Itcan consume data and information and respond. It is based on Trend Micro’s Vision One engine. And then, we can not only respond on Trend Micro products by leveraging SOC partner capabilities but also on third-party products. Customers don’t want to depend on only one product; they want best of breed on endpoint and server from Trend Micro, but for CASB, they might prefer someone else; for firewall, they may opt for another vendor. That’s why we must support the customer through an SOC. If you are to be successful in XDR, you must learn to work with an SOC partner. Yes, some large enterprise customers, like the large banks, have their own internal SOC and may not need an external SOC partner. We can work with their internal teams as well.
What is your vertical focus for India? How many customers do you have in India?
Vijendra Katiyar: BFSI is number one for us, and there is also a focus on digital-native companies. We have formed a business vertical focusing on the cloud, which will work with many digital-native companies whose entire business is born in the cloud. We have been working with a lot of other enterprises, especially in manufacturing, pharma, and IT/ITES.
Nilesh Jain: In 2021, we gained 120 customers in India. But in the last two years, we acquired nearly 300 customers. These are mid-enterprise to large customers. There was a surprising surge in SMB in the last two years. So, we might invest more into the SMB business and scale it up.
And we work closely with AWS. They open many accounts that we might not even have visibility into. But customers who adopt AWS would like to partner with us.
How do you serve the government and public sector?
Vijendra Katiyar: We have a very strong government team that focuses on central and state government. One area where we see a lot of potential is Smart Cities. We have participated in many leading smart city projects to make smart cities more secure.
Defense is another area, and we built a team to focus on this sector. It’s an important sector for the government, and the sector is seeing a lot of cyberattacks. We know that there are guidelines, policies, and government initiatives being digitalized, and we want to help the government securely do this. We are working towards that.
Ensuring that you get the best experience is our only purpose for using cookies. If you wish to continue, please accept. You are welcome to provide a controlled consent by visiting the cookie settings. For any further queries or information, please see our privacy policy.
This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
Cookie
Duration
Description
cookielawinfo-checkbox-analytics
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional
11 months
The cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance
11 months
This cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy
11 months
The cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.