Home Blog Page 232

Most U.K. Firms Suffer Basic Cybersecurity Skills Shortage: Research

Cybersecurity Skill Shortage Leads U.K. Firms to Outsourced Security Services

A recent research into the U.K. cybersecurity labor market by the Department for Digital, Culture, Media & Sport (DCMS) found an increase in the basic cybersecurity skills gap in most organizations in the country. The research findings are based on the analysis of labor market databases, interviews with training providers and quantitative surveys with companies in U.K.

According to the research report, around 653,000 organizations (48%) in the U.K. are unable to carry out basic tasks defined in the government’s Cyber Essentials Scheme like setting up firewalls, storing data, and removing malware. The report claimed that 408,000 businesses (30%) lack advanced cybersecurity skills in areas like pen testing, forensics, and security architecture.

The report also found 64% of firms admitted that they suffered problems with cybersecurity skills gaps, with 25% complaining that this had impacted their business. 35% of employers reported that recruitment in the industry is bleak and vacancies in cyber roles are hard to fill because applicants lacked technical knowledge required for the job.

According to DCMS, the areas with the technical skills shortage in U.K. firms include:

  • Information risk management
  • Compliance or testing
  • Cybersecurity research
  • Implementing secure systems
  • Governance and management

Several industry experts stated that skills shortage will continue to affect several organizations until huge investments are made  in technical skills training in the cybersecurity industry.

Growth in the U.K.’s Cybersecurity Industry

According to DCMS, the number of active cybersecurity firms in the country increased by 44%, up from 846 firms in 2017 to over 1,200 in 2019, indicating a growth in the cybersecurity industry. In its earlier report, “The U.K. Cybersecurity Sectoral Analysis 2020,” DCMS stated the security industry in the U.K. has seen a significant surge in security investments, annual revenue, and employment. It also highlighted that around 43,000 full-time employees are currently working in the industry. The annual revenue in the cybersecurity sector rose by 46% to an estimated worth of £8.3 billion (approximately US$10.8 billion). The sector received more than £348 million (approximately US$452.4 million) of investment in 2019.

8 out of 10 U.K. CEOs Fear Cyberattacks

A similar survey by PricewaterhouseCoopers (PwC) revealed that nearly 79% of CEOs fear skills shortages and cyberattacks as some of the biggest threats to their enterprises. The report, which surveyed 1,600 CEOs in 83 countries, also stressed that 75% of respondents were worried about the speed of technological change as another major challenge. According to the report, most CEOs were concerned about the increasing level of sophistication of cyberattacks. In half the cases, the CEOs themselves deleted their social media apps fearing cyberattacks against them or their company.

COVID-19: EC-Council Announces free Cyber Training and Education Support Services

With COVID-19 restricting offices and workspace to homes and impacting the cybersecurity sector at a massive scale, the world’s largest cybersecurity certification body, EC-Council, announced that it will offer an array of its certification programs and courseware free for students, instructors, partners, and the information security community. The certification body stresses that the period of social distancing can be used to stay engaged in the industry while also, keep a career in cybersecurity on track. The initiative also aims to help the cybersecurity community maintain strong security during this time of uncertainty.

“For almost 20 years, EC-Council has proudly maintained core values that focus on putting students, instructors, partners, and community first. As your cybersecurity partner in the industry, we would like to offer extended support to reduce your stress in any way we can. We recognize the cyber community has a very important role to play during this crisis. While we battle the pandemic, we must also do everything within our control to empower others and ensure that organizations do not take cybersecurity lightly which could lead to threat actors causing more harm,” stated Jay Bavisi, Group President and CEO of EC-Council, and Editor-in-Chief of CISO MAG.

He continued, “There have already been headlines about healthcare organizations being hit with DDOS attacks and malware, showing that cybercriminals are taking advantage of the chaos and are continuing to exploit vulnerabilities wherever they can. Cybersecurity is more important than ever, especially now that so many workforces are suddenly working remotely for the first time. Remote work opens up risks to the organization that cybercriminals will not hesitate to take advantage of.”

As part of the initiative, EC-Council will provide free access to its subscription platform, CodeRed, which hosts over 1,500 high-quality cybersecurity videos bundled with over 25 socially curated cybersecurity courses from over 15 leading global industry experts. All-access, 30-day passes will be provided to subscribers immediately. The CodeRed has an exhaustive library of engaging materials on topics like GDPR, CCPA, Ubuntu Linux Fundamentals, Identity and Access Management, Ethical Hacking, among several others.

Certification voucher and iLabs Access Extensions

Apart from providing free cyber training and education support services, EC-Council is also extending expiration dates on all EC-Council Exam Vouchers by 90 days at no cost so that everyone has the appropriate time to prepare for their certification exams.

EC-Council is also offering existing iLabs users a 90-day extension by request to provide additional training time within EC-Council cyber ranges in light that they may have experienced disruptions and delay due to COVID-19. Any iLabs user who has purchased and redeemed an iLabs access code on or after January 1, 2020, can avail the special benefit by reaching out to the support team.

The company is also focusing on the enhanced delivery of its training programs. “All in-person EC-Council classes will now be exclusively delivered via our online platform. We already operate a robust online learning division with both online live and online on-demand options. Moving to online learning methods will allow users to continue learning amid the COVID-19 shutdowns across the globe. Each of these benefits will be implemented effective immediately through the end of June 2020,” Bavisi concluded.

Kaspersky and SAFCSP Sign an MoU for Cybersecurity Training in Saudi Arabia

Kaspersky and SAFCSP Sign an MoU for Cybersecurity Training in Saudi Arabia

Global cybersecurity firm Kaspersky Lab  and the Saudi Federation for Cybersecurity, Programming and Drones (SAFCSP) signed a memorandum of understanding (MoU) to enhance the cybersecurity skills of the youth in Saudi Arabia.

As per the MoU, Kaspersky will support the SAFCSP in its CyberHub initiative, which will gather students from 28 different universities from across the region to set up specialized cybersecurity clubs. Kaspersky will provide SAFCSP with training materials on cybersecurity and programming. The company will also contribute to CyberHub by organizing various conferences, workshops, and invite speakers to provide students with a first-hand overview of the requirements, opportunities, and challenges in the cybersecurity sector.

Industry experts opine that this kind of private and government entities’ alliance will enhance the technological advancements and increase the cybersecurity readiness of Saudi Arabia.

In a similar development, the National Cybersecurity Authority (NCA) of Saudi Arabia recently agreed to provide cybersecurity training to 800 young men and women working in the cyberspace under its cybersecurity training program called CyberPro. It also announced a Cybersecurity Scholarship initiative in partnership with the Ministry of Education and increased the number of places for foreign scholarships for the first year from 200 to 540 for both genders.

Cybersecurity Threats to Businesses in Saudi Arabia

A KPMG survey revealed that 20% of the CEOs in Saudi Arabia reached a consensus that cybersecurity risks are the biggest threats to their businesses today. In 2018, the second edition of the same survey ranked cybersecurity risks at sixth position with only 4% of the surveyed CEOs believing it as a top risk. According to survey findings, 14% of the CEOs believed they expect a cybersecurity risk or incidence in immediate future. While 60% of CEOs regard information security as a strategic function that gives their organizations an edge over their competitors. It highlighted that digitalization led to the potential growth of businesses in the country, which has been one of the core objectives of Saudi Vision 2030.

Growth of Cybersecurity Market in the Middle East

The Middle East cybersecurity market is expected to grow at a compound annual growth rate (CAGR) of 22.5% between 2018 and 2024. It’s believed that public and private enterprises in this region are the most targeted verticals of cyberattacks. Hence, it’s important for enterprises in the Middle East to be able to identify security gaps in their systems.

Australia’s Information Commissioner Charges Facebook Over Data Privacy Breach

Facebook copyright complaint

The Australian Information Commissioner lodged Federal Court proceedings against the social media giant, Facebook. The Information Commissioner found Facebook guilty of data privacy breach, which was also in conjunction with a breach of the country’s Privacy Act 1988. The breach affected 311,127 Australian Facebook users. If proven guilty, a maximum civil penalty of up to AUD$1,700,000 (approximately US$9,700,00) will be imposed on Facebook for each serious and/or repeated interference with privacy.

The notice filed in the Federal Court said that Facebook disclosed the private information of its Australian users to a third-party application “This is Your Digital Life”  between March 2014 to May 2015. This violates the Australian Privacy Principle 6 (APP 6) designated and amended for its citizens.

The provision of APP 6 mentions that, “If an APP entity holds personal information about an individual that was collected for a particular purpose, the entity must not use or disclose the information for another purpose (the secondary purpose), unless the individual has consented to the use or disclosure.” However, it was found that a majority of the compromised users did not install the app themselves, but found their personal information data shared because their friends who installed the app in question.

Facebook was also found guilty on another count of breaching the APP 11 provision. The Information Commissioner alleged Facebook for its inadequate measures and shortcomings in protecting the personal information of its Australian users. The APP 11 measure provides that ‘‘if an APP entity holds personal information, the entity must take such steps as are reasonable in the circumstances, to protect the information from misuse, interference and loss, and from unauthorized access, modification or disclosure.’’

Australian Information Commissioner and Privacy Commissioner, Angelene Falk, said, “We consider the design of the Facebook platform meant that users were unable to exercise reasonable choice and control about how their personal information was disclosed. Its default settings facilitated the disclosure of personal information, including sensitive information, at the expense of privacy. This was a systemic failure on behalf of Facebook to comply with Australian privacy laws.”

Earlier, the U.K.’s Information Commissioner’s Office (ICO) imposed a penalty of the £500,000 (approximately US$645,000) on Facebook for failing to safeguard the users’ data gathered by political data firm Cambridge Analytica. Facebook agreed to pay the fine amount and drop its legal appeal against the penalty. The ICO stated that Facebook could retain some documents that the ICO disclosed during the appeal process to use for its own investigation into issues around Cambridge Analytica.

Research Finds Supercharged AI Cyberattacks are Unavoidable

median dwell time, Supercharged AI Cyberattacks are Unavoidable

New research from AI cybersecurity firm Darktrace revealed that most security leaders are preparing for AI-powered cyberattacks. According to the research paper titled, “The Emergence Of Offensive AI,” conducted by Forrester Consulting on behalf of Darktrace, 88% of decision makers in the security industry believe offensive AI is inevitable, with 50% of them expecting the industry  to see these attacks in coming years.

The research also highlighted that 77% of respondents expect weaponized AI to lead to an increase in the scale of cyberattacks, while 66% of them felt that it would lead to new attacks. Over 80% of security decision-makers opined that organizations require advanced cybersecurity defenses to combat offensive AI, and 75% of security leaders are concerned over business disruption.

The findings are based on the responses from security leaders across different industries, including retail, financial services, and manufacturing sectors.  They were surveyed on the speed of attacks, the impacts of offensive AI, and businesses’ security strategies in the face of advanced threats.

Max Heinemeyer, Director of Threat Hunting at Darktrace, said, “I head up a team at Darktrace’s R&D Center in Cambridge, where we’re conducting research into AI attacks – securely developing offensive AI and using it to test and strengthen Darktrace’s algorithms. Businesses need to implement cyber AI for defense now, before offensive AI becomes mainstream. When it becomes a war of algorithms against algorithms, only autonomous response will be able to fight back at machine speeds to stop AI-augmented attacks.”

“If an organization is not operating with AI-enabled defenses to counter AI-enabled attacks, how can it expect to win? The goal is to fight these advanced attacks with advanced tactics that detect, interpret, and respond to the threat before it has a chance to make an impact,” Heinemeyer added.

SiteLock Partners with Aruba to Enhance Security

NCSC and Microsoft Cyber Accelerator program

SiteLock, a provider of cybersecurity solutions for small businesses, recently partnered with Italian hosting provider Aruba. The partnership enables Aruba to leverage SiteLock’s Patchman solution in over 700,000 websites to create a secure and safe hosting environment for its end-users. According to SiteLock, Patchman was designed for website hosting providers to detect and patch security vulnerabilities and identify malware on all servers.

Tom Serani, Chief Channel Officer at SiteLock, said, ” In the face of an ever-evolving threat landscape, today’s hosting providers require proven cybersecurity solutions that mitigate risk in order to stay competitive, increase customer retention, and drive new business.”

“As cyber threats continue to rise and make headlines, our top priority is ensuring that our customers’ business and data are secure. Partnering with SiteLock allows Aruba to provide our customers with a cleaner and safer hosting platform,” said Gabriele Sposato, CMO at Aruba.

Earlier, in its research, SiteLock revealed that small- to midsized businesses websites suffer 23,000 attacks annually, which means 63 attacks per day. The SiteLock Website Security Insider Q2 2017 threw light on the most common threats website owners faced, including malware trends, content management system risks, plugin risks, website attacks, common vulnerabilities, and social media risks. More than 85 percent of these attacks were reportedly caused by automated bots.

APT36 Uses Coronavirus to Spread Crimson RAT

coronavirus, covid-19

APT36, a Pakistan-based threat group, is using the novel Coronavirus pandemic scare to its advantage by spreading a data exfiltrating malware – Crimson RAT. As per a report from Malwarebytes, APT36 is mainly found to be using spear-phishing and watering hole attacks to target potential victims.

APT36 Threat Group

APT36 threat group has been long known to carry out cyber espionage campaigns against India to collect its critical and sensitive military information. They are allegedly backed by certain criminal organizations in the region to support the Pakistani military and diplomatic interests. In the past, the group has also deployed different types of RATs, such as BreachRAT, DarkComet, Luminosity RAT, and njRAT.

Coronavirus has caused panic in India, as the country readies itself for Stage 3 of the pandemic. Amid the chaos, the operators of this campaign are using a decoy health advisory– namely from the Government of India–to disguise a malicious macros attachment. The malicious file is targeting an old vulnerability in RTF (Rich Text File) format as recorded under CVE-2017-0199.

The Smart Crimson RAT

Once the malicious file is opened, two directories named as “Edlacar” and “Uahaiws” are created. In order to load the payload, the malware dropper first checks the OS type (32-bit or 64-bit). It then drops the payload into the Uahaiws directory and unzips its content to drop the Crimson RAT payload in the Edlacar directory. In the end, it executes the shell script to load the payload.

Crimson RAT then begins data exfiltration from the victims’ computer which includes stealing credentials from the browser, list running processes, collect anti-virus software information, number of drives in the system, and capture screenshots in certain cases.

COVID-19: C5 Forms Cybersecurity Alliance to Protect Healthcare Sector

Coronavirus, COVID-19

The Coronavirus outbreak has not only gripped the world but has also had a crucial impact on cyberspace. With reports emerging from all parts of the globe about cyberattacks surrounding COVID-19, leaders in cybersecurity have come together to combat cyberattacks particularly targeting the Healthcare sector in the wake of the pandemic—an additional threat level to overburdened hospitals, clinics, and research facilities.

The investment firm, C5 Capital, has created the C5 Alliance of leading cybersecurity firms like ITC Secure, IronNet, Haven Cyber Technologies, Enveil, 4iQ, and Blue Cedar to combat this new threat vector. The alliance is a response to a 150% increase in healthcare cyberattacks in the last two months, such as phishing emails pretending to be from the World Health Organization (WHO), and ransomware.

“Healthcare companies and organizations are facing growing threats, as seen with the NHS attacks in 2017. Now with the COVID-19 crisis, they are facing an unprecedented assault from cyberattacks. This initiative takes immediate action in helping to protect health services in the U.K. and Europe in the best way possible, with the knowledge of some of the world’s best cybersecurity experts,” said Andre Pienaar, Founder, C5 Capital in a release.

As part of the alliance, Collective Cyber Defence for Healthcare initiative has been launched to free access for hospitals, clinics and other medical facilities in the U.K. and Europe, to C5’s IronDome system.  The collective crowdsourcing defense product, based on IronNet’s collective defense solution, will be managed by ITC Secure’s SOC in London.

The alliance will help ensure hospitals and clinics protect their internal systems and databases for patients, healthcare workers, and volunteers. The alliance also aims to protect pharmaceutical research and development facilities while developing a vaccine to fight the COVID-19 virus both safely and efficiently.

“With the dramatic spread of COVID-19, a coordinated approach to the crisis is crucial. The cybersecurity industry has a key role to play, and this initiative addresses a growing and immediate issue. We are proud to be joining forces with a host of excellent cybersecurity companies to help tackle this problem within healthcare,” Paddy McGuinness, C5 Strategic Partner and former U.K. Deputy National Security Adviser for Intelligence, Security and Resilience, commented.

How Coronavirus is Impacting Cyberspace

COVID-19, Corona, Coronavirus

These are interesting times – the world is witnessing an unprecedented onslaught of upheavals not just in the ‘real-world’ but also in the cyber world. We greeted 2020 gingerly knowing the trade war between the U.S. and China was going to bring about economic uncertainty but little did we know a global pandemic was upon us, with the Coronavirus having an impact even on cyberspace.

By CYFIRMA RESEARCH

While healthcare workers are battling the COVID-19 virus, countries are in lockdown mode, and the global economy hangs in the balance, another war is raging in cyberspace.

Cyber risks and threats have multiplied with many more attack vectors, and hackers’ techniques evolving faster than ever, blending technical prowess with sophisticated social engineering. The current challenge with the virus pandemic is a test of nations’ and businesses’ preparedness and resiliency on all fronts.

CYFIRMA’s threat visibility and intelligence research revealed a massive increase of over 600% of cyberthreat indicators related to the Coronavirus pandemic from February to early March.

Threat indicators are made up of conversations observed and uncovered in the dark web, hackers’ forums, and closed communities. What our researchers have seen and heard in these communities do not bode well for governments and businesses – hackers are hard at work, actively planning how to leverage this climate of fear and uncertainty to attain their political and financial objectives.

The United States Computer Emergency Readiness Team (US-CERT) has sent out alerts on scams tricking people into revealing personal information or donating to fraudulent charities, all under the pretext of helping to contain and manage the coronavirus. The Federal Trade Commission has also warned about similar scams.

CYFIRMA’s research team and multiple security vendors have reported that threat actors have used fear tactics to spread malware, including LokiBot, RemcosRAT, TrickBot, and FormBook.

These hackers’ communities span far and wide, communicating in Cantonese, Mandarin, Russian, English, and Korean, unleashing campaigns one after another to wreak havoc on unsuspecting nations and enterprises.

On Dark Web forums, a group from Hong Kong hatched a plan to create a new phishing campaign targeting the population from mainland China. The group aimed to create distrust and incite social unrest by assigning blame to the Chinese Communist Party.

A deeper analysis of hackers’ conversations also revealed groups from Taiwan discussing similar phishing and spam campaigns, specifically targeting influential persons in mainland China to cause further unrest.

Korean-speaking hackers were planning to make financial gains using sophisticated phishing campaigns, loaded with sensitive data exfiltration malware and creating a new variant of EMOTET virus (EMOTET is a malware strain that was first detected in 2014 and is one of the most prevalent threats in 2019). These hackers were planning to target Japan, Australia, Singapore, and the U.S.

CYFIRMA’s researchers also observed North Korean hackers targeting South Korean businesses. The phishing email had the Korean language title “Coronavirus Correspondence”, tricking recipients into opening them and launching malware into machines and networks.

With COVID-19, many hacker groups were observed to be using brand impersonation with fake emails claiming to represent authoritative bodies such as the Centers for Disease Control (CDC) and the World Health Organization (WHO). The subject line and content of these emails were very enticing, offering news updates and cures to the ailment.

We also noticed coronavirus-themed emails designed to look like emails from the organizations’ leadership team and sent to all employees.

Embedded with malware that would infect corporate networks, these phishing attacks deploy social engineering tactics to steal data and assets.

Other than unleashing cyberattacks to steal data, we also witnessed the planning of fake websites to sell face masks and other health apparatus using bitcoin in China, Japan, and the US.

To aggravate matters, hackers were also strategizing to spread fake news to create further confusion. By investigating the dark web marketplace, CYFIRMA uncovered illicit groups selling organic medicine claiming to cure and eradicate the COVID-19 virus. These discussions in the hackers’ communities were carried out in Mandarin, Japanese and English.

A new malware called ‘CoronaVP’ was being discussed by a Russian hacking community; this could lead to a new ransomware or EMOTET strain, designed to steal personal information.

Hackers leveraging on the COVID-19 pandemic are motivated by a combination of personal financial gain as well as political espionage to cause social upheavals. Threat actors in the world of cybercrimes are well-equipped with tools, technology, expertise and financing to further both commercial and political agendas. In our hyper-connected digital world, cyber-crime is a lucrative business, and we should expect attacks to be more frequent and more sophisticated as the pandemic continues to cast a shadow over the global economy.

What we have witnessed in the field of cyber-intelligence has taught us the importance of staying vigilant, and frequently, the most dangerous forces at work are those we cannot see.

The importance of relevant and timely threat intelligence cannot be over-emphasized as early detection of cyber threats could save organizations from hefty financial penalties and irreversible brand damage.

Disclaimer: Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

 

Deloitte Acquires Zimbani to Boost its Cybersecurity Practice

Deloitte Acquires Zimbani to Boost its Cybersecurity Practice

Deloitte announced that it entered into a strategic agreement to acquire Australian security architecture specialist Zimbani. With the latest acquisition, Deloitte aims to build its professional security services in Australia and the Asia Pacific regions by combining Zimbani’s existing cybersecurity practice.

As per the acquisition deal, Zimbani’s Founding Partner and CEO Rene Morel will join Deloitte as a Partner, alongside Co-founder and Chief Security Architect Jason Paul.The company’s Chief Operating Officer Ben Smith will join Deloitte as a principal in the cyber practice.

Zimbani provides technical expertise to enterprises that function in threat & vulnerability management, cloud security, identity, access management, and data protection specializations. Industry experts opine that the acquisition of Zimbani will bolster Deloitte’s cybersecurity practice.

Commenting on the new acquisition, Deloitte’s CEO, Richard Deutsch, said, “Cybercrime is regularly listed as one of the major business risks globally, so it is critical that businesses are on the front foot, anticipating, monitoring and managing the threats and key risk events in real time. We are in an era of complexity where technology connects everything and cyber is everywhere. As technology continues to disrupt business models and processes; we see cyber readiness and resilience as a key enabler for our clients and are investing accordingly.”

Cyber partner and CEO of Zimbani, Rene Morel, said, “We help protect some of Australia’s most critical enterprises across the finance, energy, education, and airline sectors. Now we can do that at scale and more rapidly. Deloitte has a leading cyber practice, reflecting its commitment to continue investing in cyber expertise and technology. With the depth of our expertise, and the breadth of Deloitte’s geographic reach in Australia and beyond we will make a significant impact in keeping the region safe.”