Home Blog Page 239

Kr00k Vulnerability Allows Wi-Fi Packet Decryption

Home Routers for botnets

At the ongoing RSA Conference USA 2020 in San Francisco, ESET, an antivirus company, shed light on Kr00k vulnerability that is affecting around a billion people having Wi-Fi chips manufactured by Broadcom and Cypress. It is a security bug or a flaw that forces devices to use a zero-encryption key to partly encrypt communication with the compromised device. Once the attack is complete, the attacker can easily exfiltrate information by intercepting and decrypting data packets sent over the WPA2 network.

These Wi-Fi chips have already been in use on many laptops, smartphones and IoT devices. In fact, ESET confirmed that before respective patches were applied to fix the flaw, the following devices were tested positive for kr00k vulnerability:

  • Amazon Echo / Kindle
  • Apple iPhone / iPad / MacBook
  • Google Nexus
  • Samsung Galaxy
  • Raspberry Pi 3
  • Xiaomi / RedMi
  • And certain Asus and Huawei products

How Kr00k Works

When data is transmitted over the Wi-Fi, it is sent in packets (in this case, over WPA2 network). For data security purpose these packets are encrypted using a unique key. Researchers found that this unique key was getting set to all-zero value.

Disassociation (i.e. disconnection) in Wi-Fi networks is a common phenomenon that happens on a regular basis due to a weak internet signal. But Wi-Fi networks are configured to automatically reconnect to the previously used networks. While reconnecting, the kr00k vulnerability allowed attackers to set the data packet encryption key value to all-zero. Thus, it became easy for the attacker to intercept and decrypt all-zero encrypted packets.

Initially, ESET didn’t go public with its findings. It wanted to help all the stakeholders involved to first rectify the issue and avoid kr00k’s exploitation. Instead, they contacted Broadcom and Cypress to fix the issue and release a security patch to contain the damages. ESET also reported the kr00k vulnerability issue to ICASI to alert other impacted vendors.

A CISO’s Guide to Managing Change and Politics

Board meeting, CISO, leadership

It seems that nearly all CISOs, regardless of whether they’re a transformational CISO or a steady-state CISO, currently are going through some kind of an uplift, transformation, or driving a major program (e.g., Zero Trust). While there are many challenges involved, it’s important to note that they are not technological. In fact, they are far from it – these challenges will be mostly organizational and political.

By Jinan Budge, Principal Analyst, Forrester

And yet most CISOs are not equipped to deal with this for several reasons. They are bombarded with tactical requests; they’re dealing with a security image that’s transcended the ages yet not everyone in the organization loves the security team, and will not always be welcoming to security initiatives; security professionals generally hate the idea of politics and avoid it at all costs; and change is difficult for many people. Because of these, many detractors come out of the woodwork when a CISO kicks off a new security program.

CISOs Need to Drive Change Using The 3 P’s: People. Process. Politics.

For CISOs to ensure the success of their security function and programs, they will need several qualities seldom discussed in the security industry: leadership, business insight, people skills, determination, pragmatism, and personal resilience. They can best navigate their way through organizations by paying attention to three crucial P’s: People. Process. Politics.

People: Supporters and Detractors 

The very best strategy in the world will go nowhere unless CISOs manage to execute it. In order to execute, they will need to convince stakeholders to undertake the journey with them, or at least support them in their respective journeys. Remember, everything comes down to human interactions, and human interaction is inherently complex and political.

Broadly speaking, stakeholders will fall into two camps: supporters and detractors. Each has its own set of needs, and like any other project, CISOs need to be methodical in their approach of engaging them. It’s not uncommon to see CISOs immediately resorting to reactive or one-off announcements about their strategy or program, typically acting too late. This only serves to fuel detractors and doesn’t give stakeholders the chance to support CISOs. Experience also indicates there’s a lot of fear of engagement, typically because no one likes criticism. Yet CISOs can achieve much more favorable and faster results if they follow these simple, yet often missed steps:

  • Understanding exactly who their key players are: Identify who needs to be on board with the strategy and role they assume in the approval, delivery, and maintenance of the plan.
  • Preparing the ground and socializing their strategy: Plant the seed of the need of the change, understand what each stakeholder needs and what they’re concerned about, and have socialization conversations one stakeholder at a time.
  • Listening and turning criticisms into a solution: You will improve your chances of influencing and convincing your stakeholders if you listen more than you talk.

Politics: Be ethical and maintain integrity to achieve great opportunity 

We as human beings tend to shy away from politics for good reasons, the most obvious one being because of what we see on television in our politicians. Typically, we equate elements of their rhetoric with backstabbing. But that is not in fact how senior leaders see politics – they see it as their greatest opportunity to really listen, really understand what people are saying, and persuade and build influence.  When CISOs listen, they have several advantages such as really hearing what the concerns of the stakeholder are and how to overcome them.  CISOs can then build a coalition of the willing for their strategy. By being transparent, CISOs are also building their reputation as a visible leader rather than a back-office operator.

Process: Utilize your persuasion and influence toolkit 

The conversation about politics, influence, and persuasion is not one that is discussed often in security. To the uninitiated, it may even sound like some high-level concept. Some might even confuse it with “begging on your knees.” Yet, CISOs can follow a thorough process with each of their stakeholders. This is professional political maneuvering at its finest that can absolutely be done with ethics, finesse and integrity. Follow these tools:

  • Collective Momentum: Socialize the security vision, strategy and change program and build momentum. When you finally present the vision, the CISO can list the engaged sponsors.
  • Authority: There’s nothing like influence from the top down. If the CEO believes in something, most of the time, the organization falls into line.
  • Mutual Exchange: If a CISO aids a potential sponsor over and above what’s required, they build goodwill. They may be able to use that later.
  • Scarcity: CISOs can use time or resource limits (such as regulatory deadlines or vendor discounts) to create urgency.
  • Foresight: CISOs need to keep their sponsors briefed and be transparent about all situations, positive and negative.
  • Relationship: CISOs need to build a positive relationship with the key players ahead of time, so that this relationship can influence the response.

CISOs Need to Decide Their Type and Flex Their Leadership Muscles Accordingly

CISOs should ask themselves how much of their current success is a result of their technical knowledge, and how much is the result of their ability to collaborate and persuade. Better still, they should do some self-reflection and decide the type of CISO they want to be. Currently, six types of security leaders exist: Transformational CISO, Post-Breach CISO, Tactical/Operational Expert CISO, Compliance and Risk Guru, Steady State CISO, and Customer-facing Evangelist.

Regardless of CISO type, CISOs will need to manage change, deal with politics and people. By doing this mindfully and understanding the type of CISO they are, CISOs can find their perfect organizational culture, be clear on which type background and characteristics serve best, know when to exit a toxic environment, plan for their future, be prepared for upcoming challenges, and build a positive, high performing team that reflects their type.

Additionally, they will execute security programs and likely deal with stakeholders at some level. This will require them to prioritize their role as a leader, and this involves them having to sharpen leadership skills, especially those that are unfamiliar. To help them do that, they should find mentors, executive coaches or mentors, as well as build a positive, high-performing team that reflects their CISO type. They will also need to manage their mental health to avoid burnout. Depending on respective CISO type, they should also seriously consider building their communication and public speaking skills.

And they should always remember, being political does not mean backstabbing, and change happens all the time, everywhere, whether they notice it or not. This leaves the CISO with a simple choice: help to drive change forward or simply follow change as it occurs.

About the Author

Jinan Budge, Principal Analyst, Forrester Jinan is an experienced leader serving security and risk professionals who specializes in transformational change and building sustainable cybersecurity, digital, and information risk management capabilities. Jinan has delivered outstanding results using strategic and innovative thinking in the cybersecurity field — building, standing up, and delivering significant cyber transformation strategies across the public and private sectors. Jinan’s research centers on building transformational and effective security programs by focusing and communicating the business issues and value of security to organizations and executives.

Views expressed in this article are personal. CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

U.K.’s Financial Conduct Authority Admits to Accidental Data Breach

biggest data breaches in India,data breach, Aptoide Android App Admits Data Breach, Suspends Sign-Up Option Temporarily, Panasonic

The U.K.’s Financial Conduct Authority (FCA) apologized after it accidentally exposed the confidential details of around 1,600 consumers who complained against it, in response to a Freedom of Information (FoI) request for data. In an official notice, the regulator stated that certain underlying classified information like names, addresses, and phone numbers of complainants may have been accessible on its website. However, the company clarified that no financial, payment card, passport or other identity information were exposed in the incident.

According to FCA, the exposed information is related to the individuals who complained between January 02, 2018, and July 17, 2019. FCA removed the relevant data from its website immediately after noticing the breach. “We have undertaken a full review to identify the extent of any information that may have been accessible. Our primary concern is to ensure the protection and safeguarding of individuals who may be identifiable from the data,” FCA said in a statement.

The regulator is reaching out to apologize the affected users and advise them of the extent of the data disclosed. It also reported the incident to the U.K.’s data privacy watchdog – the Information Commissioner’s Office.

 Lack of Cyber Readiness Among U.K. Businesses

According to a survey from data security firm Clearswift, around 70% of financial firms in the U.K. reported security incidents in 2019, in which half of the incidents occurred due to internal errors. The research, which surveyed 100 senior business decision-makers from financial organizations in the U.K., highlighted that most of the attacks have originated due to employees who failed to follow proper data protection policies. Apart from employees’ errors, the survey also revealed other reasons that led to attacks, including downloads of malware or viruses from third-party devices like USBs, and file transfers to unsecured sources.

Rising Cyberattacks on U.K. Businesses

A research from business and financial adviser Grant Thornton UK LLP discovered that cyberattacks are a present danger for businesses in the U.K. The research report, “Cybersecurity – the Board Report”, stated that the businesses are not prepared to manage the cyber risks. It also revealed that the mid-market businesses in the U.K. have lost around £30 billion (US$37 billion) in 2019 due to security breaches. Grant Thornton stated they surveyed over 500 U.K. mid-market companies, in which half of them reported losses of up to 10% of their income over cyberattacks.

NTT-AT and (ISC)2 Unite to Strengthen Cloud Security Workforce in Japan

U.S. and Australia to Jointly Develop Cyber Training Platform

The International Information System Security Certification Consortium (ISC)², a non-profit organization that provides training for cybersecurity professionals, announced an expansion of its strategic partnership with NTT Advanced Technology Corporation (NTT-AT) to strengthen cloud security workforce in Japan. The alliance is intended to bring more local-language cybersecurity training in the country.

Recognized as an Official Training Provider (OTP) of (ISC)2, NTT-AT offers public training on the official Certified Cloud Security Professional (CCSP) Common Body of Knowledge (CBK), helping reinforce cloud security capabilities of organizations throughout Japan. In addition to cultivating advanced security experts, NTT-AT is also focused on developing highly value-added security services and related products in order to support NTT Group’s businesses.

Clayton Jones, Managing Director at (ISC)², said, “There are few companies in Japan with the reach and scale that an organization like NTT-AT has, and our combined partnership will drive needed cloud security workforce development that helps to protect and defend critical data.”

“NTT-AT is committed to bringing top-quality cloud and cybersecurity training to Japan in order to help build a safe and secure cyber environment. Our collaboration with (ISC)2 enables us to provide official training to support a strong and skilled workforce,” said George Kimura, Chief Executive Officer at NTT-AT.

(ISC)² Partnership with Tokyo Police Department

In order to keep its forces updated with the latest cybersecurity trends and tactics, the Tokyo Metropolitan Police Department (TMPD) recently signed a Memorandum of Understanding (MoU) with the (ISC)². The alliance was aimed to revamp TMPD’s traditional law enforcement tactics and embrace the latest cybersecurity toolsets and expertise to counter the rising global cyber threat scenario.

 Cyberattacks on Japan Defense Sector

Multiple cyberattacks were reported by enterprises in Japan in recent times. Pasco Corp. and Kobe Steel, which render services to the Japanese armed forces, recently disclosed a data breach that took place in May 2018 and June 2015. Pasco Corp. is an aerial image surveillance provider and has tie-ups with the Japanese Ministry of Defense for delivering the latest satellite images to monitor the work and progress at various defense bases and other locations.

The other companies that reported data breaches targeting Japan’s defense secrets were NEC and Mitsubishi. On January 31, 2020, NEC, in a brief statement, accepted the data breach and stated that its network was penetrated and compromised to a cyberattack that was launched in December 2016. In January 2020, Japanese electronics manufacturer Mitsubishi Electric confirmed that it was hit by a cyberattack in June 2019. According to the internal investigation, which began in September 2019, the security incident compromised the information of Mitsubishi’s public and private business partners, defense-related details, and data on critical social infrastructure like electricity and railways.

Shadow IoT Devices Become Growing Risk Factor to Enterprise Security: Zscaler

IoT attacks

Cloud security company Zscaler stated in its report IoT Devices in the Enterprise 2020: Shadow IoT Emerges as Security Threat,that the shift in shadow IoT emerged as a security threat to enterprises’ security posture.

As enterprises embraced mobility and always-on connectivity for employees, the lines have blurred between company-owned and privately-owned devices, and between the workplace and the home. Zscaler stated that in many cases enterprise IT teams might not even be aware of some of the devices generating IoT traffic, and this new culture of shadow IoT is creating new IoT-based attack vectors for cybercriminals.

What are Shadow IoT Devices?

Shadow IoT devices are internet connected devices or sensors used inside an organization without the knowledge of the IT team in a company. A shadow IoT device can be any smart device like personal laptops, smartphones, fitness trackers, and smart home gadgets.

According to the report, the top unauthorized IoT devices include data collection terminals, digital signage media players, industrial control devices, medical devices, networking devices, payment terminals, printers, digital home assistants, TV set-top boxes, IP cameras, smart home devices, smart TVs, smartwatches, and even automotive multimedia systems. It also stated that new exploits are emerging to target unauthorized IoT devices like the RIFT botnet, which looks for vulnerabilities in network cameras, IP cameras, DVRs, and home routers.

The report also highlighted that the majority of IoT based transactions are insecure with 83% of IoT-based transactions occurring over plain-text channels, whereas only 17% use secure (SSL) channels. Zscaler claimed that it blocked 14,000 IoT-based malware attempts per month.

Deepen Desai, Vice President of Security Research at Zscaler, said, “We have entered a new age of IoT device usage within the enterprise. Employees are exposing enterprises to a large swath of threats by using personal devices, accessing home devices, and monitoring personal entities through corporate networks. As an industry, we need to implement security strategies that safeguard enterprise networks by removing shadow IoT devices from the attack surface while continuously improving the detection and prevention of attacks that target these devices.”

Shadow IoT Devices Become a Growing Risk Factor

An earlier report from cloud-managed services provider Infoblox revealed that organizations in the U.S. (46%), Spain (35%), and the U.K. (33%) believe that there are more than 1,000 non-business related IoT devices connected to their enterprise networks at a time.

The report, “What’s Lurking in the Shadows 2020” surveyed 2,650 security professionals across the U.S., U.K., Germany, Spain, the Netherlands, and UAE to know the role of shadow IoT devices in enterprise networks. Infoblox claimed that its research gained a better understanding of the challenges faced by security leaders in managing shadow IoT devices across their networks.

77% of Security Professionals Report Physical Security is Not Optimized

active directory
active directory

research by cloud security firm Morphean which surveyed over 1000 IT decision-makers across Europe revealed that physical security systems are not optimized. According to the research, 77% of IT managers stated that physical security is not optimized and 20% identified physical security as a priority for improvement in 2020. While, nearly 50% of IT managers stated that currently, they’re using cloud-based video surveillance (VSaaS) or access control (ACaaS) solutions.

The report also highlighted that the increased appetite for hosted security presents an opportunity for IT resellers and physical security installers to help businesses improve their physical security, while also educating them on the potential business intelligence when VSaaS and ACaaS are integrated in the cloud. Through partnering, both sides can deliver optimal system set up protecting both the physical environment and the cybersecurity of systems through a comprehensive overarching solution that will better serve the needs of the market.

Rodrigue Zbinden, CEO of Morphean, said, “As the in-house IT department becomes increasingly involved in the purchasing and on-boarding of network connected surveillance and access control devices, greater collaboration will be required between IT resellers and physical security installers. In effect, the fast and effective provision of these systems that are fully optimized and fit-for-purpose, requires cooperation between the IT and physical security industries that are speaking the same language.”

Security Professionals are Overconfident on their Security Tools

A similar survey from Keysight Technologies, a technology firm that helps enterprises, service providers, and governments accelerate innovation to connect and secure the world, revealed that security professionals are overconfident in their tools with 50% of respondents reporting that they have experienced a security breach because one or more of their security products was not working as expected.

The survey, “Security Operations Effectiveness”, found that just over half (57%) of security professionals were confident their current security solutions are working as intended. Yet only 35% of survey respondents stated that they conduct testing to ensure their security products are configured and operating as they expect. To close this gap, 86% of respondents see strong value in security test solutions that can actively test their company’s security products and posture, using both internal and external attack vectors.

What Early Adopters Need to Know About SASE

Cloud Security, 80% of Organizations Suffered a Cloud Data Breach in the Past 18 Months

Last year, Gartner introduced the term Secure Access Service Edge or SASE in their technology hype cycle. Almost immediately, it grabbed enormous attention from the vendors and enterprise consumers. Existing and new technology players began highlighting the benefits of SASE, marketing their offerings to attract customers. But what is this SASE? Why should we care about it? Is it truly a game-changer? In my opinion, the concept is not entirely new; the branding and the timing of the terminology attracted a lot of attention. SASE provides networking & security as a cloud-based service as opposed to discrete solutions, which are not relevant in today’s environment–where application and data access is needed from everywhere, and from any type of device. Before we delve into the world of SASE, let’s examine the technologies used by organizations for connecting and securing applications, and why do they need to look at newer alternatives.

By Parthasarathi Chakraborty, Director–Infrastructure & Cloud Security Architecture, Bank of Montreal

Enterprise applications used to be hosted in corporate datacenters and within the perimeters of the organization. Users had to backhaul to the company network for accessing applications. Introduction of cloud hosted applications, increasing dependency on third-party SaaS, and workforce mobility has made the traffic backhauling inconvenient, and perimeter centric security as less efficient. Nevertheless, a plethora of networking and security solutions made the integration even more challenging, security incident response is more cumbersome and responsible for lowering of the return on technology investments. That’s why organizations started looking for “integrated” solutions that bind networking with security services and make it a single pane of glass for easier operations. They offer better context and data sharing between controls for improved efficiency and increased portability of the solution suite to address the ever-changing form factor of user compute.

Gartner’s SASE concept is the reflection of the same in a cloud-based service offering. The future of networking and security will be in an integrated “as a service offering” from cloud to enable users to access data from anywhere, anytime and on any type of device.

Major components of a good SASE security plane may include a proxy-based secure web gateway, URL filtering, SSL interception, data leakage protection, content isolation, advanced threat protection including dynamic detonation, firewall/IPS as a service, DDOS/WAF as a service, DNS security, CASB or cloud access security broker (for SaaS) and other security controls based on zero trust security model.  Whereas the network plane integrated with security controls may include intelligent connectivity solutions like SD-WAN (software defined wide area networking). This is done to minimize connectivity cost & intelligent latency, to reduce routing to the applications hosted anywhere – cloud or corporate datacenter), VPN replacement with SDP (software defined perimeter), Content distribution service, WAN optimization, policy-based routing, class of service and quality of service assurance from the cloud. There is no prescriptive list of networking or security controls within the SASE framework, key is to have the integrated as a service offering. That’s where the industry vendors are stretching by offering solutions in their stronghold as SASE.

Challenges

The challenges early adopters will face here will be no different from what they see in on-premises technologies. Distinct technology controls offered as a service with minimal integration and context sharing between those, basically shifts the problem from datacenter to the cloud. The reason for it lies in the fact that there is no set definition of controls needed to be in the SASE space. Classic networking vendors are either building a few security features or acquiring some security companies devoid of tight integration, to emerge as a “new” SASE player. The same holds true for traditional security players: they lack expertise in the networking space and then “partner” with network players to provide “an on-paper integrated” SASE offerings.

Evaluation Criteria

Here is what an organization should consider while evaluating a SASE vendor.

  • Integrated networking & security as a service
    • Avoid a “stitching approach” which means multiple vendor products offered “together” as partners or acquired solutions with poor integration capabilities
  • Look for solutions built from the group up with offerings in the networking and security space
    • Look for solutions with better data and context sharing for a complete end-to-end picture
  • Prefer solutions written in cloud native technology
    • Hardware instances or virtualization will be less preferred compared to container-based offerings leveraging microservices technology
  • Identity-based security filtering based on the principles of zero trust networking
    • Select products allowing granular policies based on immutable identities of humans and machines
  • Prefer solutions with open APIs for better integration with the rest of the control suite
    • Built on next generation technologies like artificial intelligence and machine learning

Conclusion

To conclude, SASE is the direction organizations should be looking to embrace without repeating the same mistakes of on-premises network with too many independent solutions at the cost of higher level of complexity and lower integration capability. Industry solutions offered in this space fall into three distinct categories: strong network as a service offered by traditional networking vendors, strong security players providing security as a service or CDN providers helping with content distribution from cloud. Network vendors not having a stronghold in security can either acquire a security solution or partner with other security vendors. The same is true for classic security vendors entering into the SASE space.  The net impact is lack of context sharing, poor integration and operational complexity that defeats the core goals of the SASE concept. We should prefer solutions having the most depth & broader breadth covering network and security areas well enough to provide one integrated “as a service” solution written in cloud-native development platforms with open integration capabilities. The market is still full of network or security niche players. It would be prudent to take a  cautious approach of waiting till solutions are available with equally strong network & security offerings.

Everybody is selling the SASE concept in their offerings now, but to me, it is exactly the same as the on-premise problem moved to cloud except that few vendors are bridging the gap with an integrated cloud-based networking & security offering.

The goal here is not to be prescriptive but to present the facts, and the final decision stays with the individuals in charge of technology selections based on organizational objectives and risk appetite.

About the Author

Parthasarathi Chakraborty is Director – Infrastructure & Cloud Security Architecture at the Bank of MontrealParthasarathi Chakraborty is Director – Infrastructure & Cloud Security Architecture at the Bank of Montreal. Previously, he held executive leadership roles at Guardian Life, JP Morgan, Bank of America, and Merrill Lynch.

He is a member of the Forbes Technology Council, Rutgers University Cyber Security Advisory Board, and the New Jersey Institute of Technology CSLA Advisory.

He achieved certifications for CISSP, CCSP, CEH, CHFA, MS (Infosec-WGU), and MS (Technology Management-Columbia University).

Views expressed in this article are personal. CISO MAG does not endorse any of the claims made by the writer. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Japan, Canada and U.K. Welcome Google’s Titan Key

Google Cybersecurity Action Team Google, EU warns Google

Google introduced USB-C Titan Security Keys in Japan, Canada and the UK including countries like Austria, France, Germany, Italy, Spain, and Switzerland. The Google Titan Security Key is a piece of hardware that acts as a second line of defense against phishing and malicious threats.

Google Titan Security Key

Google first introduced the Titan Security Key with USB-A/NFC and Bluetooth/USB/NFC keys in August 2019. The Titan Security Keys provide an additional layer of security, more like a two-step or two-factor verification along with the regular login security.

google, google titan security key, google titan
Pic Credit: Google

These security keys make use of public-key cryptography to verify user identity and support FIDO protocol. In FIDO protocol, the attacker cannot access the targeted victim’s account despite having a legit username or password. To gain access, the public key for the URL is matched with the requestors’ private key (which in this case is the Titan Security Key). Thus, if the attacker does not possess the physical security key (which in a majority of cases holds true), then he/she is unable to access the said URL.

The Titan Security Key also ensures that a user is visiting a legit URL and not being a victim of a phishing attack. However, security keys work only on websites that support hardware security keys, which include personal and/or work accounts of Google, Dropbox, Facebook, GitHub, Twitter and many more.

Google’s Titan M Chip

Google had earlier also introduced the Titan M chip in its Android smartphone’s Pixel series. Titan M is an enterprise-grade security chip custom-built for Google’s smartphone brand, Pixel. This chip secures the most sensitive on-device data and operating system. Titan M helps the bootloader (the program that validates and loads Android when the phone turns on)—make sure that the latest Android version is loaded. It stores the last known safe Android version and restricts attackers from moving to an older and potentially vulnerable Android version on the device. Titan M also prevents attackers’ attempts to unlock the bootloader.

Veeam Software Announces Gil Vega as its New Chief Information Security Officer

Gil Vega

Veeam Software, a provider of Cloud Data Management solutions, appointed Gil Vega as its new CISO. Vega will be a part of the company’s executive management team and is responsible for establishing and maintaining Veeam’s vision and strategy to ensure its information assets and solutions are secure. His role will be pivotal in driving strategies to help customers protect their critical data across multiple environments and ensure regulatory compliance.

Previously, Vega served as a Managing Director and CISO at CME Group, Inc. and as the Associate Chief Information Officer & CISO for the U.S. Department of Energy and U.S. Immigration & Customs Enforcement in Washington, DC. Vega also held various cybersecurity leadership posts within the Department of Defense (DoD) and the Intelligence Community.

Veeam stated that the new leadership will help the company scale internal security and compliance processes and successfully navigate the complex and evolving Cloud Data Management market as customers strive to secure and protect critical data. Founded in 2006, Veeam provides backup solutions that deliver Cloud Data Management services. It also offers a single platform for modernizing backup, accelerating hybrid cloud, and securing data.

Bill Largent, CEO of Veeam, said, “Data is the most critical asset in any organization, but protecting it against threats, both external and internal, is becoming more complex. Cybersecurity is a top concern for business leaders, which is why they look to Veeam to ensure that their data is managed and protected no matter where it resides. To ensure that we continue to pioneer this space and help build out our offerings across all sectors.”

Infosys to Launch its New Cyber Defense Center in Indianapolis

Nearly Half of Global Consumers Affected by Data Breaches

Infosys, a provider of next-generation digital services and consulting, announced that it’s going to launch a new Cyber Defense Center in Indianapolis to strengthen security monitoring, management, and remediation services for organizations around the globe. The Cyber Defense Center, which is going to launch on March 3, 2020, will provide end-to-end, real-time, 24/7 cybersecurity monitoring, threat hunting, security analysis, incident discovery and response, compliance reporting, malware analysis, and protection services to support American businesses in their digital transformation journey.

The new center will be Infosys’ seventh addition to the network of cyber defense centers spread across North America, Europe, and Asia. The facility is dedicated to detect, assess, and respond to cybersecurity threats and breaches.

Vishal Salvi, Chief Information Security Officer & Head of Cyber Security Practice, Infosys, said, “At Infosys, we’re constantly investing in modern, cutting-edge security offerings and solutions to best protect our customers against current and future cyber threats. The Cyber Defense Center is staffed with expert security analysts with niche skills around threat research and intelligence gathering to deliver best-in class services to our customers. Additionally, advanced data analytics and machine learning models are deployed to detect zero-day threats by unknown threat actors. This supports our commitment to helping our customers build a resilient cybersecurity program that operates at scale, while increasing operational efficiency and reducing costs.”

Cybersecurity Become a Board Room Imperative: Infosys

According to new research by Infosys Knowledge Institute (IKI), the research arm of Infosys, titled “Assuring Digital-Trust,” 48% of corporate boards and 63% of business leaders were actively involved in cybersecurity strategy discussions. IKI surveyed 867 senior executives from 847 firms with annual revenues over US$500 million. These firms were from countries like the U.S., Europe, Australia, and New Zealand. The report pointed out that organizations are now finding it difficult to embed security in their enterprise IT architecture due to several factors like lack of cybersecurity talent, and inability to keep up with the technological advancements and evolving threat landscape.