Home Blog Page 235

Trend Micro Says It Blocked 12.7 Million Email Threats in 2019

Business Email Compromise Attacks

Trend Micro revealed that it thwarted 12.7 million potential email threats for customers leveraging cloud-based email services. In its report, “2019 Cloud App Security Roundup”, Trend Micro stated that more than 11 million of emails threats blocked last year were phishing related. The number of unknown phishing links in these kinds of attacks increased from 9% to 44% in 2019.

The report also highlighted that cybercriminals are getting better at using sophisticated methods to overcome the first layer of defense against Business Email Compromise (BEC) attacks. The number of BEC attacks caught by AI-powered authorship analysis increased from 7% in 2018 to 21% in 2019, according to the report. As of now, Trend Micro blocked around 400,000 attempted BEC attacks, which is 271% more than in 2018.

Trend Micro recommended enterprises to follow certain mitigation steps to defend against email threats, which include:

  • Move away from a single gateway to a multi-layered cloud app security solution
  • Consider sandbox malware analysis, document exploit detection, and file, email, and web reputation technologies to detect malware hidden in Office 365 and PDF documents
  • Enforce consistent data loss prevention (DLP) policies across cloud email and collaboration apps
  • Choose a security partner that can offer seamless integration into their cloud platforms, preserving user and admin functions
  • Develop comprehensive end user awareness and training programs

Wendy Moore, Vice President, product marketing at Trend Micro, said, “Organizations are leveraging the power of SaaS-based applications in greater numbers to drive productivity, cost savings and growth. However, in doing so they may be opening themselves up to risk if they only rely on built-in security. As our report shows, built-in security is not enough on its own to stop today’s cybercriminals. Businesses must take ownership of cloud protection and find a multi-layered third-party solution to enhance their platform’s native security functionality.”

Threat actors using stolen email credentials to breach cloud accounts

Earlier a survey revealed that threat actors used previously stolen login credentials to launch brute-force attacks on high-profile cloud-based business systems that use multi-factor authentication (MFA). According to the research by enterprise security firm Proofpoint, hackers used IMAP-based password spraying attacks to breach Microsoft Office 365 and G Suite accounts which are protected with multi-factor authentication. This technique allows malicious actors to perform credential stuffing attacks to compromise sensitive data.

Securing Email Data When the Office Computer Comes Home

e-mail

The office laptop is finding its way into living rooms and bedrooms, as more organizations allow their employees to work from home. Traveling staff work out of hotel rooms, lobbies, libraries and cafés. In light of the current Coronavirus epidemic, companies are advising their employees to work from home. The laptop is an endpoint to the corporate network. It also holds important data of the organization, and that data may be valued much more than the cost of the laptop. That presents a lot of risks, and the employee needs to be vigilant and take certain precautions. A stolen/misplaced laptop or a malware infection from an insecure home network or public Wi-Fi network can spell doom for the organization. That data could fall into the wrong hands or, if not backed up, could be lost forever.  And tech support may not be immediately available when malware infects or an application gives an error while loading.

By Victor Bobrov, Recovery Toolbox

Microsoft Outlook is one of the most used applications on the office laptop. It’s used for communicating with colleagues and clients. Files are exchanged (as attachments) and meetings are planned. Skype calls can be scheduled through Outlook.

Imagine a day when you are expecting an important email from a client. As usual, you load the Outlook application, and then you are confronted with the following message on the screen:

Outlook data file cannot be accessed.

Or

The operation failed. An object could not be found.

Recovery Toolbox for Outlook

If you go online and scan for this message in support newsgroups, you will see that this issue occurs due to any of the following reasons:

  • OST file corruption (Outlook profile)
  • Incorrect configuration
  • Faulty mail synchronization between the Outlook client (on the laptop) and the  Microsoft Exchange server
  • Slow internet connection
  • Malware attacks

But for now, there’s no tech support person around, and you need to fix this yourself, to check if that important mail has come in.

What does “Outlook data file cannot be accessed” mean? Just because everything looks bad and it is not clear, what should you do with it? As per the error text, it is clear that Outlook is unable to open your mailbox and download the messages to your laptop. The reason itself is not provided, of course. In my case, it is most likely the power outage, but there could be a variety of reasons, from hard drive issues to viruses. By the way, if you suspect a malware infection, it is essential to remove it first. Otherwise, everything could happen again, as soon as you repair Outlook!  Guess what is the best way to restore data? Correct if you said, time-honored backups.

The Solution

You can resolve this problem by using Recovery Toolbox for Outlook and fix the issue in 30 minutes.

The Inbox Repair Tool

In the case of Outlook issues, Microsoft suggests using a free recovery method named Inbox Repair Tool. By the way, there is no need to download it separately, it represents a part of the Microsoft Office package and is installed together with the Outlook email client. Try it, maybe happiness is right there, and it can help you. However, it did not help me. Therefore, I am not going to provide detailed instructions. There are more useful services for email repairing. Most of them have only one disadvantage: the cost. But it is crucial to sort out priorities and think, what is more critical: your mailbox or US$50? That is the cost of a license to use the Recovery Toolbox for Outlook – a third-party tool.

Recovery Toolbox for Outlook

Recovery Toolbox for Outlook

Note that there is no need to purchase the tool right now. Try the free version of Recovery Toolbox for Outlook to evaluate if the recovery is possible at all. When you install it, the application recreates the mailbox structure and allows previewing messages and other objects, without a possibility to save data. This option can save you money and time. For example, there is no need to restore the whole file. It is often enough to open it with Recovery Toolbox for Outlook and make screenshots or written notes of the most critical data: phone numbers, logins, and passwords to access bank accounts or something else of similar importance. You will be asked to pay for this tool if you opt to recreate your mailbox, and save it for a connection to Outlook.

You should perform the steps below:

  1. Download the latest version of Recovery Toolbox for Outlook from the developer website.
  2. Install the program by clicking on the downloaded file.
  3. Use the software shortcut, located on the desktop, to start working.
  4. Choose a mailbox in the Outlook format that shows the following error: “Outlook data file cannot be accessed”.
  5. Perform the restoration of the selected e-mail box and estimate results.
  6. If you have purchased the program, the results can be saved.

In general, Recovery Toolbox for Outlook supports any version of Microsoft Outlook, and it can be installed on any computer running Windows, even without the Internet connection. Moreover, in some cases, the network connection can harm: What else can you do to make sure the application does not send your personal data to somebody else? The best way is to switch OFF all possible connection channels. On the other hand, this option is mostly for paranoiacs because the absence of outgoing traffic from Recovery Toolbox for Outlook can be easily tracked using another method, the firewall, for example.

Recovery Toolbox for Outlook

Online service for recovering Outlook data files

If the license fee (US$50) is beyond your budget, then try the online data recovery service. For US$10 you can recover 1 GB of data. The online email repair service works from any device, not only a PC. You can also upload files from a tablet or a mobile phone. Just make sure the internet connection speed is good enough. The service works as follows:

  1. Open this link https://outlook.recoverytoolbox.com/online/
  2. Search your hard drive and find the required file of *.PST format to upload to the remote site.
  3. Provide an email address and CAPTCHA.
  4. Complete the payment process for using this service.
  5. Download the successfully repaired file.
  6. Connect the file of *.PST extension to Outlook.

Recovery Toolbox for Outlook

Despite all guarantees of privacy and safety offered by the developer, those worried about the confidentiality of their data would hesitate to upload it to an online data recovery service. If that’s the case then download the offline version instead, but you will need to pay the license fee to use it.

For other users, the service is simple and advantageous. Think about the business losses if you are unable to respond to an important email in time. Or you need to connect to a client, but his contacts are stored in the mailbox, and you do not remember them. Or maybe, you need to send some money, but the Internet bank account details are stored in that e-mail box that cannot be opened due to corruption of the OST file.

In such instances, a fee of US$10 or US$50 is negligible.

Some may want to look for another free solution, but that would take some time to discover.

Regardless of whether you opt for a free or paid solution, always make it a practice to backup your Outlook data file (OST).

For more information visit: https://outlook.recoverytoolbox.com/outlook-data-file-cannot-be-accessed.html

CISO MAG did not evaluate/test the products mentioned in this article, nor does it endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG does not guarantee the satisfactory performance of the products mentioned in this article.

SPONSORED FEATURE

 

Australia Climbs 12 Positions High in Cybersecurity Rankings

Cryptocurrency scams in Australia

A study on global comparison of cybersecurity defenses ranked Australia as the world’s 15th secure country. According to security research firm Comparitech, Australia climbed 12 positions in its latest cybersecurity ranking report. The study evaluated 76 countries’ exposure to security vulnerabilities to find which countries are well prepared for cyberattacks.

Comparitech stated that it found improvement in Australia’s cybersecurity readiness with an overall score of 13.95 when compared to the previous year’s 16.34 (lower scores represent better ranking). The scores are based on the indicators of compromise like the percentage of mobiles infected with malware, the frequency of financial malware attacks, and the number of computers infected with viruses in a country. It’s found that 4.86% of mobiles in Australia were infected due to malware attacks, which is twice the rate of higher-ranked countries like Denmark, Turkey, Norway, and Croatia.

Least Cyber-Secure Country in the World

According to the study, Algeria is the least cyber-secure country in the world with computer malware infection rates (19.75%) and its preparation for cyberattacks (0.262).

Most Cyber-Secure Country in the World

The study findings revealed Denmark as the most cyber-secure country in the world with low scores across the most of categories. The other top-performing countries included Sweden, Germany, Ireland, and Japan.

Australia has taken some recent initiatives to increase its cyber capabilities. In January, it added a new cybersecurity innovation node to AustCyber (Australian Cyber Security Growth Network).

Tasmania’s Cybersecurity Innovation Node, which was launched in Launceston on January 30, 2020, is the new addition to AustCyber, which is a  national network of cybersecurity innovation nodes. AustCyber nodes are designed to strengthen and accelerate Australia’s cyber capabilities and technical innovation.

AustCyber is a non-profit organization established by the Australian Government, under its roadmap for growing a cybersecurity sector for Australia at par with its international counterparts. The Tasmanian node now joins five other state and territory nodes in the country. These nodes are bound by bilateral partnerships between AustCyber and Australia’s State and Territory governments. Each node commits to the national priorities, as defined by the AustCyber’s business strategy and Cybersecurity Sector Competitiveness Plan, and is co-funded with AustCyber in its state and territory and primarily focuses on local cybersecurity workforce and business development and challenges, as long as they are not in conflict with national needs.

Facebook Charges Namecheap for Domain Name Fraud

Facebook announced that it has filed a lawsuit against Namecheap in Arizona, a provider of domain name registrars online, for refusing to cooperate in an investigation to find malicious domains that have been registered through its services. The social networking giant said that Namecheap impersonated its brand name and refused to share details about the owners of the suspicious domains. The malicious domain names were used to trick people into believing they are legitimate.

According to Christen Dubois, the Director and Associate General Counsel at Facebook, security experts at Facebook tracked down 45 suspicious Facebook lookalike domains which are registered via Namecheap. It’s said that Namecheap had the owners’ details hidden through its proxy service platform “Whoisguard.” Dubois also stated that lookalike domains were often used for fraud, phishing, and scams.

Commenting on the lawsuit, Dubois said, “We sent notices to Whoisguard between October 2018 and February 2020, and despite their obligation to provide information about these infringing domain names, they declined to cooperate. We regularly scan for domain names and apps that infringe our trademarks to protect people from abuse. We found that Namecheap’s proxy service, Whoisguard, registered or used 45 domain names that impersonated Facebook and our services, such as instagrambusinesshelp.com, facebo0k-login.com and whatsappdownload.site.”

“We don’t want people to be deceived by these web addresses, so we’ve taken legal action. We filed a similar lawsuit in October 2019 against OnlineNIC, another domain registrar, and its proxy service. Our goal is to create consequences for those who seek to do harm and we will continue to take legal action to protect people from domain name fraud and abuse,” Dubois added.

 Facebook Sues NSO Group for Violating Computer Fraud

Earlier Facebook sued the Israel-based cyber intelligence company NSO Group for violating the Computer Fraud and Abuse Act. According to the lawsuit filed in the federal court, the NSO Group deployed its custom malware on around 1,400 WhatsApp installed mobile devices in April and May 2019. WhatsApp revealed that it discovered a vulnerability in its network system that allowed hackers to install spyware via an infected WhatsApp voice call. It stated that the spyware can exploit the mobile device, its calls, and texts; it activates the phone’s camera, microphone, and it is able to perform other malicious activities. The malicious spyware was developed by the NSO Group, according to Facebook.

Accenture Acquires Context Information Security to Accelerate Growth

CynergisTek Partners with Awake Security to Boost Cybersecurity in Health Care

Accenture acquired a U.K.-based cyber defense consultancy firm Context Information Security. Accenture said, the new acquisition will accelerate the growth of its cybersecurity platform Accenture Security globally, strengthen its existing portfolio, and become part of Accenture’s cyber defense offerings. Accenture Security has a global network of cybersecurity labs and a deep industry understanding across client value chains and services that span the security lifecycle. It offers services that include strategy and risk management, cyber defense, digital identity, application security, and managed security.

Context Information Security provides enterprises with high-end cyber defense, intelligence-driven red team, vulnerability research, and incident response services. The company helps government organizations, including financial institutions, aerospace, defense, and other critical infrastructure respond to the threat of advanced cyberattacks.

“Context has a remarkable set of cybersecurity skills, capabilities and reputation in the U.K. as well as in the international financial services industry to complement the growth we have already driven for more than a decade in this market,” said Nick Taylor, UKI lead at Accenture Security.

Commenting on the acquisition, Mark Raeburn, CEO of Context Information Security said, “Accenture’s industry-focused approach across adversary simulation, red teaming, incident response and more, matches Context’s own strategy. Accenture’s family culture is a great fit for Context. We’re genuinely excited to join forces to help clients better defend themselves against the world’s most advanced adversaries. Combining our skills and expertise under one roof to help us do more for our clients and create more opportunities for our people was an easy decision.”

Earlier this year, Accenture acquired Symantec’s cybersecurity services business in an undisclosed deal. The acquisition made Accenture Security a leading provider of managed security services, and further enhanced its ability to help companies rapidly anticipate, detect, and respond to cyber threats.

Symantec’s portfolio of cybersecurity services includes global threat monitoring and analysis through a network of security operation centers (SOCs), real-time adversary and industry-specific threat intelligence and incident response services. Its managed security services business is supported by a proprietary cloud-based platform that delivers a steady stream of technical and cyber adversary threat intelligence through a customizable portal.

Increasing Ransomware Attacks on Japan Impacts its State of Cyber-Readiness: Study

Japan restricts foreign equipment and tech, Japan Embraces AI Tools to Fight Cyberattacks with US$237 mn Investment

A study of 60 countries reveals that Japan is in the top five most cyber-secure country. However, increasing mobile and computer ransomware attacks targeted at Japan has seen the country dropping in this ranking. But Japan has taken a number of steps to prepare for cyberattacks and cryptominer attacks.

The study was conducted by tech firm Comparitech and considered seven criteria:

  • The percentage of mobile devices infected with malware
  • The percentage of computers infected with malware
  • The number of financial malware attacks
  • The percentage of all telnet attacks by originating country
  • The percentage of users attacked by cryptominers
  • The best-prepared countries for cyberattacks
  • The countries with the most up-to-date cybersecurity legislation

Specific to Japan’s cybsersecurity readiness, the study reveals that it is the fifth most cyber-secure country. However, its ranking for this parameter dropped four places since the previous year’s study. Denmark tops the list as the most cyber-secure country.

The study attributes a weaker score for Japan due to the increase in mobile ransomware (from 1.34% to 1.97%), an increase in computer ransomware (from 8.3% to 9.17%), and telnet attacks from the country (while these reduced from 1.23% to 1.06%, this was still a higher figure than quite a few other countries). However, Japan’s score for preparation for cyberattacks and cryptominer attacks has improved. Japan has the lowest percentage of attacks by cryptominers – 0.17% of users. It is the fourth country on the list with the lowest malware infection rates in computers — 22.24%.

Japan’s cybersecurity readiness

Japan is gearing up for the Tokyo 2020 Olympic and Paralympic Games this summer, however, the website for Olympics and Paralympic Games might be vulnerable to cyberthreats, such as ransomware, fake entry passes, and leaks of personal information.  Owing to the high volume of tourists and possible threat analysis conducted by the governing authorities, Japan’s Communication Ministry has tabled a set of an emergency proposal that includes guidelines to mitigate risks and incidence response for cyberattacks.

The Communication Ministry panel identified certain devices and technologies including IoT (Internet of Things) devices that are vulnerable to cyberattacks. The emergency package says that, “it is desirable to consider publishing information on cyberattacks swiftly at the point in which leaks of personal information are suspected,” calling for information-sharing with relevant organizations.

Becoming the Face of Change

One of the biggest reasons for gender disparity in cybersecurity was the lack of a role model. The problem here is the fact that men make up for a majority of key commenters and high-profile influencers.

Trade shows and industry events are also usually dominated by men, which might be another key turn-off point in the career path choice for young women. “Most young people (69% ) haven’t met anyone who works in cybersecurity at all and even fewer (11%) have met a woman working in cybersecurity. But when they have, their opinion of the role skyrockets, with 63% of women thinking more positively about cybersecurity after meeting someone who works in the sector. This clearly shows the power of role models in promoting the industry as a whole and how inspirational female personalities can be utilized to make cybersecurity a more attractive proposition for women and help to reduce today’s skills shortage,” suggested the same study by (ISC)² and its Center for Cyber Safety and Education. Without someone to look up to, it is difficult for young women to roll into the alien territory of cybersecurity.

To gain an insight into the lack of women representation, CISO MAG gauged a few women security influencers to understand the cause of this alarming trend. This article is part of a series of interviews from women cybersecurity experts who shed light representation of women in cybersecurity. In this they also talk about initiatives taken by them as well as their companies to bridge the gender gap.

1. Carolyn Crandall, Chief Deception and Marketing Officer, Attivo Networks:

I strive to be a catalyst of change and a role model for changing that trend. New and diverse perspectives are the key to innovation and it is critical for the advancement in the cybersecurity and technology spaces. I am a strong advocate both in my work environment as well as in volunteer activities to help educate and drive advancement of women in technology. Attivo Networks has been aggressive in its college graduate hiring program and I have taken this opportunity to bring several millennial women on to the team. I often speak with undergrad and MBA students at Santa Clara University and I have spoken at When She Speaks, WITI, and most recently at the Silicon Valley TIE CMO Inflect event. This helps me build relationships, introduce cybersecurity as a career path, and actively recruit. For our newly hired recruits, we conduct weekly training on cybersecurity, our technology, and how to apply our technology to solve cybersecurity issues. We also encourage the team to participate in external training forums like ISC2, SANS, ISSA and Cybrary. Notably, my team is ¾ women.

I believe I have the ability to retain and continue to attract women because they feel welcome, the company culture promotes learning, and we offer on-the-job training to help them gain additional technical expertise. We also appreciate that people are learning, and openly provide opportunities for employees to apply their learnings while providing direct feedback on what went well and where they need to focus to advance. I also encourage the women on the team to stretch beyond their comfort zone. I have found that many women want to master an area before they make a commitment to advance. They sometimes tend to shy away from jobs or projects where they don’t have all the skills, whereas their male counterparts tend to be willing to go out on a limb and apply for jobs they are not fully qualified for. Throughout my career,

I have always sought out jobs that had scared me in some way. The skill or experience that I was missing, presented me with the opportunity to grow and be challenged. I encourage others to take big steps, but to also do this smartly by learning from others who have the skills, taking classes, or reading everything you can so that you become an expert in these new disciplines as well.

2. Kavya Pearlman, Founder and CEO of XR Safety Initiative:

I can finally say it with ease that my hope is to become the catalyst as well as the role model in the space. Being a head-covered Muslim brown woman who has endured discrimination and faced biases with courage, I must carry the mantle and help others feel safe to pursue a career in cybersecurity. This issue is very close to my heart as we are at one of the most critical moments in human history – a crossroads between emerging technologies, data sciences, and cybersecurity – fueled by a renewed, global necessity of diversity and inclusion (D&I) in each domain. This is why just last month, February 2020 – XR Safety Initiative (XRSI) announced the Cyber-XR Coalition: A Diversity & Inclusion Effort by XRSI.

The CyberXR coalition brings together D&I-focused leading organizations to advance diversity and inclusion within the fields of XR and Cybersecurity.

3. Lekshmi Nair, Senior Managing Consultant and Route to Market Leader- IBM Security, APAC & EMEA:

Role models will help to craft the goals that one aspires. I believe that catalysts are more instrumental to improve the diversity ratio in the field of cybersecurity. There is no better place than IBM to be in to drive this cause.

At IBM India, our prime D&I focus is the advancement of women in leadership roles, engaging and developing women across the organization and work-life integration. We also focus on wholesome inclusion on all other dimensions, which allows our employees to work without facing any kind of bias.

The achievement of gender equality cannot sit on the shoulders of women alone. When we take shared ownership, men and women, that’s when we stride forward together. Here are some of the programs where I am part of the global leadership team and lead in India:

Women in Security Excelling (WISE): The mission is to bring awareness in women on Cyber Security as a career option and thus to improve the gender ratio in this space. At present, this community connects about 400+ women from security services and software across India and South Asia. Additionally, we drive programs like IBMCyberDay4Girls for school girls and Hackathon competitions for college going girl students.

Guidance, Resource and Outreach for Women (GROW): Intended to foster the growth of women technologists in the newer technologies such as cloud, cognitive and security. The program involves speed mentoring, learning events and specific career counseling sessions for women.

I am also a volunteer in AnitaB.Org Delhi chapter to promote security as part of their agenda.

4. Vandana Verma, Global Board of Directors at OWASP Foundation & InfoSecGirls:

I am trying to do my bit by nurturing people right at the grassroot level by coaching, mentoring and most importantly conducting free workshops, training and meetups. I also co-run two conferences – OWASP Seasides and BSides Delhi, with a single determined goal of inclusion. I believe in the millennial era of digitization- knowledge and learning are basic humanitarian rights, they should be provided to people without any costs. All my conferences/talks/ training are pro-bono. We have just started the baby-steps a few years ago with infosec girls and we have to solve the big jigsaw puzzle which technology has to offer.

Our results in terms of quantitative. We have the following 14 active chapters in India.

We’re looking to expand and increase our reach over the world. For that we require more exposure. The event is followed and watched by the world. People take up notice when they see something working. We have a working model and there are allies within who would want to collaborate but don’t have the right means.

Through this platform we intend to get all mentors and the mentee under an umbrella to move forward. If there are any collaboration or sponsorship opportunities, we will be happy to take it further.

Closing the Skill Gap With More Women in Cybersecurity

The cybersecurity space faces an acute skills shortage, which is predicted to hit 3.5 million by 2021. This skill gap may further be exacerbated by a distinct lack of female representation. One thing that many fail to understand is that gender diversity means better pay not just for females, but for everyone. “After accounting for various other factors that may affect Female Labour Force Participation Rate (FLFPR) and wage growth, models suggest that every 10% increase in the female labor force participation rate in a metropolitan area is associated with a 5% increase in median real wages—for both men and women,” This is a conservative estimate, as some models suggest an even higher increase in median real wages, of up to 13% for every 10% increase in FLFPR.” suggested Amanda Weinstein for Harvard Business review. Lastly, a dearth of women may also signify that the marketplace for female-oriented products may also lack tech-driven innovation, let alone cybersecurity innovations.

To gain an insight into the lack of women representation, CISO MAG gauged a few women security influencers to understand the cause of this alarming trend. This article is part of a series of interviews from women cybersecurity experts who shed light representation of women in cybersecurity.

1. Kavya Pearlman, Founder and CEO of XR Safety Initiative:

According to research by Cybersecurity Ventures, the gender gap means a smaller pool of potential workers in an industry looking to face 3.5 million unfilled positions by 2021. As the founder CEO of the XR Safety Initiative (XRSI), an organization dedicated to helping build safe immersive environments, my bigger worry these days is about the diversity and other biases creeping into our emerging technologies including machine learning and artificial intelligence.

With the rise of AI-based solutions, the issue is becoming more and more relevant, and the over-representation of white men in the design of these technologies could undo decades of advances in gender and racial equality. Equally important is a concerted effort to incorporate gender and racial balance in machine learning. It is crucial to prevent algorithms from perpetuating ideologies that disadvantage under-represented groups.

But this is not just an ethical problem: while we have not even fully addressed the cybersecurity challenges with existing technologies, a whole new wave of emerging technologies including virtual augmented and mixed reality (collectively known as XR), Brain-computer Interface (BCI) and rollout of 5G communication infrastructure is bringing a whole new set of novel cybersecurity challenges that we need to address as soon as possible. It is imperative that we get more women and minorities involved: it is the only way we will be able to close some of the identified gaps in the existing and emerging domains of technologies.

2. Lekshmi Nair, Senior Managing Consultant and Route to Market Leader- IBM Security, APAC & EMEA:

I love cooking as much as I love my security job. I was born in Kerala, a state down south in India. We prepare a mixed vegetable dish called “avial”. The more diverse and variety of vegetables that we use in this dish, the tastier it becomes. Every distinct vegetable that we add brings its unique taste and texture to the dish.

I would like to take the same example of diversity in Cybersecurity. A wide range of skills such as business knowledge, analytics skills, cultural diversity, education, and cultural background will help the teams to address some of the most complex issues in the Cybersecurity field today.

Some of the traits include:

  • Analyze the attacker surfaces- thinking from different ethnical, language, cultural and educational backgrounds
  • Cognitive cybersecurity: avoid unconscious biases in the cognitive algorithms
  • Complex problem solving: Use the right mix of business skills, technical acumen, and cultural diversity to derive innovative and faster solutions

We talk about women more in the field of diversity because that is where we have more supporting data available. Women historically score highly when it comes to social intelligence and emotional intelligence. They have high EQs typically. When we have more women in a group, the intelligence of the group increases. And it’s not a case of women are better than men, it just signifies and signals that when men and women come together and work together, there are better outcomes.

3. Vandana Verma, Global Board of Directors at OWASP Foundation & InfoSecGirls:

Specifically, with cybersecurity, it’s a specialized niche where you want a varied group of folks to provide that input. Security is an aptitude to look into details and no one is better than women at it. Security is inbuilt in their DNA. The drawback of not having women participation is that we miss out on the most inquisitive minds that the universe has to offer.

The tech industry is grappling with two big challenges. First, it is struggling to fill jobs with qualified candidates. The second, the remedies to which will also help cure problem #1, is diversifying beyond the current homogeneous band that fills the high-tech halls. Both problems are even more acute in the cybersecurity sector.

It’s not a woman or race issue, it’s a people issue that we need to know and be aware of.

Tracing Back to the Roots

Women in Cybersecurity

To dive deeper into the subject of lack of women representation, Kaspersky Labs and Arlington Research conducted an online survey, titled “Beyond 11%.” This was to address the stagnant representation of women of 11% in between 2013 and 2017. According to the study, “A surprisingly high percent (72%) of respondents to our survey, both male and female, had already decided on their future career paths, with female respondents being slightly more likely to have decided than their male counterparts (74% vs. 71%).” The average age at which young women have decided on their future career is fifteen years and ten months, and those that haven’t decided by this time expect to have made a decision by the age of twenty-one and nine months, making it very difficult for cybersecurity firms to influence their choices after this point,” the study revealed. In 2010, even though 57% of undergraduate degree recipients were female, only 14% of them pursued majors in the same field. The study highlighted the fact that a lack of interest in the space of cybersecurity traces back to school.

To gain an insight on the lack of women representation, CISO MAG gauged a few women security influencers to understand the cause of this alarming trend. This article is part of a series of interviews from women cybersecurity experts who shed light representation of women in cybersecurity.

1. Kavya Pearlman, Founder and CEO of XR Safety Initiative:

Oftentimes, it goes back to early education. There lies an opportunity to direct female students to choose technical education and building the soft skills necessary for the STEM career paths. We need to build a more robust pipeline for cyber talent. Schools should follow programs and frameworks such as U.S. cyber challenge, National Initiative for Cybersecurity Education (NICE), K-12 cybersecurity framework that offer a set of best practices that help providers of cybersecurity education and training in the United States better prepare their students to enter the cybersecurity workforce and help employers to manage workforce shortages and recruit the talent needed to secure their systems. Privately organized Capture the Flag (CTFs) are also a great way to cultivate interest and desire to learn within young students.

“School must also be considered a potential boost for a cultural change in the way cybersecurity careers are seen. Despite the fact that women are more likely to enroll in university than men, tech jobs are still facing high levels of gender inequality. This will take time, but it’s crucial to use the aforementioned tools to mark a deeper transformation. In a way, given that some cultural constructs follow the society, this will naturally happen as demography is already making the world more diverse. The educational system plays a decisive role in making the change faster.”

2. Lekshmi Nair, Senior Managing Consultant and Route to Market Leader- IBM Security, APAC & EMEA:

Cybersecurity is not “the” default career option for anyone even now. However, with the technology landscape evolving some of the industry data predicts 22M+ unfilled cybersecurity jobs by 2022, yet there are fewer takers for these jobs. While I agree this is something to be addressed at the school level, I see a fundamental problem in the way we currently present the cybersecurity career to the students. Many of the cybersecurity jobs today are shown as the job of ethical hackers or penetration testers, which gives the perception that this is highly technical. On the contrary, Cybersecurity needs diverse skills:

  • Technical skills: Penetration testing, vulnerability assessments, encryption, secure coding, etc.
  • Consulting and communication skills: Program management, operations, awareness, risk assessments, compliance, regulatory, etc.
  • Analytical skills: We need good analysts who can monitor the security alerts and derive the right inferences out of it by relating to the threat vectors and likelihood of occurrence.
  • Industry knowledge: Security is intervened in the fabric of the business. So, we need people who understand the business to translate business risks to security risks and business needs to security opportunities.

So, we need to educate school and college kids to understand that security is really about the proactive thought process, thinking based around risks, based around budgets and making better business decisions around risk. Technology is just one of the skills needed. This messaging will help us to take security jobs beyond STEM to areas such as law, HR, auditing and even psychology.

Early last year, IBM announced significant collaborations across India to advance the skills and careers of more than 200,000 (2 lakh) female students in Science, Technology, Engineering and Math (STEM) fields. The STEM for Girls program is a 3-year program launched across 10 states in India to cover 200,000 girls and 100,000 boys focused in Tier 2 and Tier 3 cities to enable girls with 21st-century skills. 80% of the jobs of the future are going to have elements of STEM in them and this program would help the kids of today, prepare for the jobs of tomorrow.

Further, IBM has partnered with two National Implementation Partners, Quest Alliance and American India Foundation Trust who then take this STEM curriculum into the hundreds of schools across these states. Since the launch of the program, over 69,000 girls have been on-boarded to the program in 6 states with the remaining 4 states starting this program before May 2020. We have also onboarded over 38000 boys in these six states who are currently in the program. As of date, the program is running in 714 schools across  six states and 80 districts.

3. Vandana Verma, Global Board of Directors at OWASP Foundation & InfoSecGirls:

I would definitely second that the disparity traces its roots back to school. I have often heard people preaching that “Tech is for men and kitchen is for women”. On the contrary, I have witnessed some unparalleled men in the baking business and women in the tech space. It has nothing to do with gender. It is not just women but everyone in general who needs to be enlightened. Not much has been done about educating students about cybersecurity. I believe there has to be a separate program for bringing up cybersecurity awareness amongst the kids. The pros and cons of cyberspace need to be assimilated deep down into their roots right from the start. This is how we can make a change and our nation cybersafe. One more approach other than the awareness programs would be giving them exposure to unmediated scenarios in the form of game or challenges. This will catch their attention and make them brainstorm about the importance of security of their device and their data. This is how they would use their gadgets in a safe manner.”

At 24%, the Needle Moves Toward More Women

For the most part, discussions around the representation of women have stayed redundant. The Global Information Security Workforce Study from (ISC)² and its Centre for Cyber Safety and Education in 2017 revealed that women only make up 11% of the global cybersecurity workforce. And that 11% was a stagnant figure since 2013 and had not spotted a blip in the trend until 2019. In 2019, another survey by (ISC)² titled 2019 Women in Cybersecurity report, revealed that women now represent 24 percent of the cybersecurity workforce. The report also called for stronger representation of women in the cybersecurity workforce. On the bright side though, the needle has moved.

To gauge an insight on the lack of women representation, CISO MAG gauged a few women security influencers to understand the cause of this alarming trend.

This article is part of a series of interviews from women cybersecurity experts who shed light on the representation of women in cybersecurity.

1. Kavya Pearlman, Founder and CEO of XR Safety Initiative:

“Two things come to mind: Pipeline and Retention. Pipeline- Cybersecurity is still portrayed as a career for “hooded hacker dude”, and our cultural biases around gender roles and careers contribute to the issue. This male-dominating mindset exhibits very much a “dude-bro” culture, deterring more diverse candidates from entering the domain. On top of this, a misconception amplifies the trend that cybersecurity is a high-stress career with no work-life balance. This is only true for a small set of careers. For example, a Chief Information Security Officer (CISO) for a FinTech or high-risk organization may have less control over their lifestyle. Retention- Burnout, status-quo tech culture, biases, discrimination, harassment, and Diversity & Inclusion simply being used as a tool for PR, etc. are just some of the reasons why women are leaving the cybersecurity career for other more welcoming and diverse career options.”

2. Lekshmi Nair, Senior Managing Consultant and Route to Market Leader- IBM Security, APAC & EMEA:

The dearth of women is prominent in the whole STEM (Science, Technology, Engineering, and Mathematics) majors across the globe including India. Women today are exploring various opportunities in the technology sector and interest in Cybersecurity is growing as a career choice. However, there are not enough platforms today to enable and guide them to the right resources. Above all, the current industry recruitment and talent management practices are not enabling women to make this switch from other areas. We look for easily available options for fulfilling the Cybersecurity positions in the organizations. As Cybersecurity is still an acquired skill, there may not be many women profiles readily available.

“The industry recruitment practices must change to put a conscious effort to source as many diverse profiles before choosing the right one. The hiring managers must emphasize the need to see profiles from different genders, education, diverse cultures, experiences, ideas and approaches to choose the most suitable ones. IBM with its 109-year-old journey has constantly been at the forefront of inclusion. Whether it is recruiting our first women and African-American employees in 1899, or people with disabilities in 1914. These were business imperatives for us even before any civil rights acts or legislations. We established our “Equal pay for equal work” policy in 1935. Our hiring practices are constantly updated to include the inclusive and diverse needs for all areas.”

3. Vandana Verma, Global Board of Directors at OWASP Foundation & InfoSecGirls:

It has been widely preached that women lack adroitness in technical subjects. And to some extent it has been imbibed in their beliefs as well. They are said to be good in creativity. What people don’t get is that the crux behind cybersecurity which is the figurative thinking of great minds who are enthusiastic about exploring and exploiting cyberspace. So, the day we change the thought process of women that they are born with the skills required to survive in the field, is the day these trends will favor their growth. All that is required is a little practice and patience. It’s all about the mindset.”