Home Blog Page 240

Cybersecurity Market is Estimated to Exceed US$281.74 Billion by 2027: Report

A recent survey from Fortune Business Insights revealed that global cybersecurity market value is projected to reach US$281.74 billion by 2027, exhibiting a CAGR of 12.6% during the forecast period from 2020 to 2027. According to the report, the requirement for advanced cybersecurity solutions is growing exponentially with the growth in the number of cyberthreats. The survey also highlighted that cybersecurity market growth is driven by the rising adoption of e-commerce online platforms and the emergence of disruptive technologies like Artificial Intelligence, Internet of Things, Blockchain, and others.

It’s said that the traditional cybersecurity solutions are not enough accomplished for securing the organizations from advance threats of cloud, network, endpoint security, among others. In addition, huge algorithms are required for cybersecurity solution providers to develop technically advanced solutions. Further, the high cost associated with cybersecurity solutions and services limits the adoption among small and medium enterprises.

The report also highlighted that the adoption of cybersecurity solutions is expected to grow with increasing investments from countries such as India, Italy, Spain, Canada, Oman, South Korea, Qatar, and others. Also, rising demand for enterprise security solutions from industries including banking, financial services and insurance (BFSI), manufacturing, along with aerospace & defense and healthcare sectors is anticipated to boost the market size in the forthcoming years.

“One of the key trends that enable the overall growth of cybersecurity market is the rising adoption of cloud computing. Cybersecurity solutions are based on complex mathematical prediction models, handling large amounts of data. This data monitoring can only be fulfilled by cloud technology in a secure and reliable environment at low cost. Key players such as IBM Corporation, Cisco System and others, are focusing on integrating cloud computing with cybersecurity solutions. These cloud computing services are backed up by Analytics as a Service (AaaS) offerings, allowing users to detect and mitigate uncertain threats quickly,” he added.

Jim Scholefield Joins Marriott International as CIDO

Marriott International announced the appointment of Jim Scholefield as Chief Information and Digital Officer (CIDO). The appointment came into effect on February 24, 2020. In this new role, Scholefield will be responsible for leading all aspects of the company’s information technology and digital strategies.

“Jim will play a pivotal role in driving our technology modernization efforts as we embark on a new chapter in the company’s technology journey to support our future growth, both within our core lodging business and new ventures,” said Stephanie Linnartz, Group President, Consumer Operations, Technology & Emerging Businesses.

The appointment of Scholefield comes after the retirement of Bruce Hoffmeister, former Chief Information Officer at Marriott, who stepped down from his position after working for 30 years with Marriott.

Cybersecurity Pressure at Marriott

Scholefield will have a huge pressure toward guiding the cybersecurity policies of Marriott. Marriott was at the epicenter of a massive breach affecting up to 500 million guests. Hackers extracted people’s personal data as well as loyalty program, payment, reservation information as well as encrypted credit stole card data of 100 million customers. The first breach originated in 2014 at Starwood, which was acquired by Marriott International in 2016. It was uncovered after four years in September 2018, when a security tool alerted about an unauthorized data access. Consequently, the company faced a class-action suit, and its shares also fell around 5.6%.

In July 2019, the UK’s Information Commissioner’s Office (ICO) imposed a £99,200,396 (US$123,705,870) fine on Marriott International, for the data breach. The ICO stated that Marriott failed to protect its customers’ information, violating the EU’s General Data Protection Regulation (GDPR) regulations.

Organizations Need a Combination of Security Products and Operational Security Posture: Satya Nadella

Satya Nadella, Microsoft

Microsoft CEO Satya Nadella kicked off his three-day visit to India on February 24, 2020 by addressing a gathering of over 150 business leaders at the “Microsoft Future Decoded: CEO Summit” in Mumbai, India. Nadella’s presentation centered on the theme of tech intensity and using digital technology inclusively to build the economy. Cybersecurity is included in Microsoft’s tech stack. Nadella emphasized the combination of security products and operational security posture when he spoke about cybersecurity. He also warned about microtargeted attacks on infrastructure.

By Brian Pereira

“When you look out to the next ten years, we need broader productivity and broader cross-sectoral impact of digital technology. In other words, the next ten years are going to be defined by digital technology,” Nadella said. “Technology must drive more inclusive economic growth. To do this you need core trust in technology, whether it is privacy, ethics around AI, cyber–that’s going to be huge.”

Security is a crucial part of Microsoft’s tech stack, which includes endpoint security, security services from the cloud, security intelligence, threat protection, IoT security, and a Zero Trust model.

“There needs to be trust in technology that you all create, whether you are a retailer or a healthcare company. Trust comes down to four attributes: privacy, responsible AI, digital safety and security. It is trust in privacy, trust in AI that you apply. Trust has to be human right. AI has to be ethical.”

Nadella said that the economic losses due to cybercrime are “one of the most stunning issues of  our times.” He showed that the losses in 2018 were US$600 billion and it increased to US$1 trillion in 2019.

“One of the areas we focused a lot on is building both the security products, but more importantly, the operational security posture that we have in real-time, where we see trillions of data signals each day. And we go to work so that we can protect all your infrastructure, applications and devices. So, what we have is comprehensive security… starting with identity, to devices, to applications, to your infrastructure. But backing it up not just with the products that help secure your data and applications, but also bringing this operational security,” said Nadella.

VIDEO: Cybersecurity from 50:19 mins.

He then spoke about hackers and targeted attacks.

“The attacks, just like microtargeting in advertising, are being targeted at specifically, most vulnerable populations,” he revealed.

Nadella gave the example of an incident in Northern India where 11,000 users or nodes were targeted for bitcoin mining. That attack was essentially co-opting 11,000 user compute cycles, for bitcoin mining.

“Our operational security posture gives us that early warning signal and then we go inoculate these 11,000 users, using, in this case, Microsoft Defender. That ability to see in real-time, as an attack happens and then to remediate it—is that combination of both the security product and the operational security posture–both coming together,” he said.

Brian Pereira is the Principal Editor at CISO MAG and was hosted at this event by Microsoft India.

Cybersecurity Greatest Threat to Businesses: Saudi CEOs

Saudi Arabia

A KPMG CEO Outlook survey saw 20% of the CEOs in Saudi Arabia reach a consensus that cybersecurity risks are the biggest threats to their businesses today. In 2018, the second edition of the same survey ranked cybersecurity risks at sixth position with only 4% of the surveyed CEOs believing it as a top risk.

Saudi Arabia’s geopolitical strain combined with the vast natural resource reserves make it an obvious target for attackers and the same has been identified by its businesses. Organizations in Saudi are upgrading their cyber posture by recruiting skilled workforce, partnering with cybersecurity service providers and implementing the latest cyberspace technology suited for their business. The survey highlights that digitalization has led to the potential growth of businesses in the country, which has been one of the core objectives of Saudi Vision 2030.

Other Key Takeaways from KPMGs CEO Outlook Survey

KPMG surveyed around 50 CEOs from 11 key industries in Saudi Arabia including automotive, asset management, banking, consumer and retail, energy, infrastructure, insurance, life sciences, manufacturing, technology, and telecommunications.

  • 14% believed they expect a cybersecurity risk or incidence in immediate future
  • 56% of organizations in Saudi believe they are ready for a cyberattack
  • 60% of CEOs regard information security as a strategic function that gives their organizations an edge over their competitors
  • 54% have faith that a strong cybersecurity strategy creates trust among all its stakeholders
  • 64% say that organizations growth and customer loyalty depend upon how well customer data is protected

In a bid to strengthen Saudi Arabia’s cybersecurity stance, the National Cybersecurity Authority (NCA) agreed to provide cybersecurity training to 800 young men and women working in the cyberspace under its cybersecurity training program called CyberPro. It has also announced a Cybersecurity Scholarship initiative in partnership with the Ministry of Education and increased the number of places for foreign scholarships for the first year from 200 to 540 for both genders.

76% of Firms in Australia Ready to Adopt Public Cloud: Survey

Cloud Security

A new study from Barracuda Networks revealed that more than 76% of organizations in Australia will operate their IT infrastructure in the public cloud in the next five years. The study, The Cloud Is the New Network,” stated that security remains the biggest roadblock to public cloud adoption for 80% of respondents, which is higher than the global average of 70%. The study, which surveyed 750 global IT decision-makers, is intended to capture security leaders’ experiences with moving infrastructure to the public cloud, concerns restricting adoption, as well as the security and networking solutions being implemented to overcome them.

According to the survey, the leading cloud security concerns for Australian organizations include the security of public cloud infrastructure (42%), the impact of cyberattacks (28%), shadow IT (28%), and the security of applications deployed in public cloud (24%). After security, network concerns come in second for Australian organizations in terms of public cloud adoption, which includes integration of public cloud with legacy technologies, better integration with private cloud, and enhanced integration with on-premises infrastructure.

The study findings are based on the responses from 50 security leaders in Australia. The respondents in Australia stated that the greatest threats to their public cloud infrastructure include open vulnerabilities in cloud applications (44%), sophisticated hackers (38%), ransomware (38%), and corporate network exposure to intrusions (38%). Also, 68% of them stated that they were targeted by a cyberattack, which is lower than the global average of 75%.

Andrew Huntley, regional director at Barracuda, said, “While adoption rates for public cloud continue to grow, security is still the leading roadblock for Australian organizations, which is understandable considering the volume and variety of threats they face today. As more IT infrastructure moves to the public cloud, providers will offer more native network capabilities and public cloud will expand to include more network functionality. The vast majority of Australian organizations need their security vendors to offer advanced security and cloud connectivity tightly integrated with the major cloud platforms.”

Barracuda Acquires Indian Bot Technology Startup

Earlier, Barracuda acquired the bot detection technology firm InfiSecure Technologies to enhance its bot protection capabilities. As per the acquisition deal, Barracuda acquired intellectual properties and other digital assets from InfiSecure. The alliance integrated Barracuda’s Global Threat Intelligence Infrastructure with the InfiSecure technology to detect and prevent advanced Bot-attacks.

Upstream Security Partners with Microsoft to Defend Against Automotive Cyber Threats

Automotive cybersecurity

Upstream Security, a popular automotive cybersecurity company, announced that it joined Microsoft Intelligent Security Association to establish an ecosystem of leading software vendors that have integrated their solutions to better defend against cyberattacks. The company also revealed a new integration between its C4 platform and Microsoft Azure Sentinel enabling detection, investigation, and remediation for threats targeting connected vehicles and smart mobility services. Through this integration, alerts from Upstream C4 can be used to automate responses based on an OEM vehicle manufacturer’s or connected fleet’s unique security policies.

Upstream Security is the first cloud-based cybersecurity solution purpose-built for protecting smart vehicles from cyber threats and misuse. It provides cloud-based automotive cybersecurity solutions which not only help in achieving cybersecurity for vehicles but also help build a secure perimeter around vehicles’ other integrated services. Upstream’s C4 platform leverages existing automotive data feeds to detect threats in real-time and delivers cybersecurity insights supported by AutoThreat Intelligence.

Speaking on the alliance, Yoav Levy, Chief Executive Officer and Co-founder at Upstream Security, said, “Connected vehicles require a purpose-built approach that utilize the data produced by the vehicles, telematics and automotive applications. Through the Microsoft Intelligent Security Association and by integrating with solutions like Upstream C4, Microsoft is enabling the next frontier of cybersecurity.”

Scott Woodgate, senior director, Azure Security at Microsoft, said, “Upstream Security’s integration with Azure Sentinel enables automotive customers to have a best-in-class solution for their vehicle security operations. By connecting normalized automotive data and real-time detection alerts from Upstream Security’s C4 platform with Azure Sentinel customers benefit from extended visibility across their automotive cloud and connected vehicle assets.”

Recently, Upstream Security closed a US$30 million Series B funding round led by a Global Syndicate consisting of Renault Venture Capital. The company also made a technology and go-to-market partnership with Arilou, a provider of in-vehicle network security for carmakers. Combined, Upstream Centralized Connected Car Cybersecurity (C4) technology and Arilou Intrusion Detection and Prevention (IDPS) technology aimed to create a fully integrated cybersecurity offering for vehicle OEMs. Upstream Security and Arilou are engaged in joint go-to-market initiatives including joint marketing and demonstration of their integrated solution.

U.S. DoD Reveals Data Breach Against Defense Information Systems Agency

The U.S. Department of Defense (DoD) revealed a data breach against the Defense Information Systems Agency (DISA), which occurred between May and July 2019. According to breach notification, the incident is said to have compromised employees’ personally identifiable information (PII) and social security numbers.. However, the agency didn’t reveal the number of employees impacted in the incident.

DISA is a combat support agency of the Department of Defense (DoD). It handles IT and telecommunications support for President Donald Trump, the White House, the U.S. diplomats, and military troops. The DOD and DISA didn’t provide further details about the incident, however, they clarified that there is no evidence to suggest that employees’ personal data was misused. The agency stated that it is offering free credit monitoring services to the impacted employees.

Security Incidents on Defense Agencies

This is the second data breach the DOD exposed in the last two years. In October 2018, the agency suffered a data breach that compromised the personal and credit card information of the U.S. military and civilian personnel. The attackers allegedly gained unauthorized access to sensitive information through a system that stores travel records. The system was maintained by a third-party contractor. The incident affected around 30,000 military and civilians personal and payment card details.

New Cybersecurity Standards for Defense Sector

Recently, the DoD published a new set of cybersecurity standards, known as the Cybersecurity Maturity Model Certification (CMMC) version 1.0. The new standards will require defense companies to adhere to a set of rules and mandates if they want to do business with the Pentagon procurement programs. According to the DoD, any company that does business with the Pentagon will have to get some level of certification and their defense acquisition workforce will need to be trained on how to apply the model to their contracts.

Malware Attack Hits Danish Service Provider ISS World

Armor Piercer

ISS World, a Danish workplace experience and facility management company was hit by a malware attack on February 17, 2020, which disrupted its global operations. As per the company’s standard operating procedure (SOP), the entire global computer network of ISS World, including its website, were pulled offline to isolate the attack. In a press release, ISS World explained that this malware attack had minimal impact on the company’s daily operations as the service provider mainly delivers services on-site (i.e. on client site).

ISS World neither disclosed the severity and type of attack, nor the extent of the damages caused by it. However, it confirmed that their internal investigation team identified the root cause of the malware attack. To further investigate the security incidence, ISS World took help from its hosting provider, cyber forensic experts in the industry and a special task force.

The company website was restored by Friday evening and its entire IT workforce was working tirelessly towards a complete system and network restoration. No customer data leak or compromise was reported by ISS World. The team of investigators is also looking out for any potential financial impact that the malware attack could have on ISS World.

The JhoneRAT Incident

Earlier, security researchers from Cisco Talos discovered a new version of remote access trojan (RAT) malware attack, which targeted a victim’s device via malicious Microsoft Office documents. The RAT malware, tracked as “JhoneRAT,” was developed using Python and targeted a set of Middle East countries by checking keyboard layouts of the infected devices.

The researchers identified three malicious MS Office documents that were used to infect the device.  The first document named “Urgent.docx,” discovered in November 2019, asked the victim to enable English and Arabic-language editing.  The second document named “fb.docx,” discovered in January 2020, claimed to contain data on leaked Facebook accounts from 2019. The third document, found at the end of January 2020, contained blurred content and is alleged to be from a legitimate United Arab Emirates (UAE) organization.

Snyk Launches Global Channel Program with Security-Focused Partnerships

96% of Cybersecurity Professionals are Happy With Their Roles

Snyk, an Israel-based developer-first security firm, announced multiple partnerships with modern security-focused companies as part of its global channel program. The partnering companies in the program include Optiv Security, a security solutions integrator focused on end-to-end cybersecurity; GuidePoint Security, a provider of customized cybersecurity strategies and services; and Trace3, an elite IT consultancy and solutions integrator focused on Cloud, DevOps, Security and Data Intelligence. With an aim of helping its customers in modern security solutions, the three companies are adopting developer-first security  practices.

Snyk stated that the new partnerships integrate open source vulnerability intelligence from Snyk with the three firms’ (Optiv Security, GuidePoint Security, and Trace3) comprehensive ability to detect vulnerabilities for teams operating in a DevOps environment.

Snyk helps enterprises in detecting and fixing the vulnerabilities and license violations in open source dependencies. The company claims that its security solutions platform is built on a comprehensive, proprietary vulnerability database, and maintained by security veterans in Israel and London.

The launch of the global partner program comes after the recent Synk’s Series C fundraise of US$150 million. The company also added key customers like Google, Salesforce, Intuit, and Nordstrom.

Commenting on the partnership deal, Peter McKay, CEO of Snyk, said, “For businesses today, security is a critical aspect of digital transformation. Combined with the ever-growing threat landscape, there is an urgent need to secure software development. We believe developer-first security benefits every software-driven business. To accelerate that mission, we are creating an ecosystem of partners that share our vision to help businesses scale and secure their application development processes.”

“As a Snyk channel partner, Trace3 is strengthening our existing application security and DevSecOps practices,” said Jimmy Xu, Director of DevSecOps, Trace3. “Many security solutions do well in identifying issues rapidly and accurately, but they are still not addressing the core issue of how to make it easier for developers to remediate those issues with minimal impact to their productivity, a core requirement for true DevSecOps. Snyk is unique in the way that it is truly developer-first and makes it easy for the dev team to apply fixes and help the app sec team to scale.”

Snyk’s Partnership with Trend Micro

Last year, Snyk made a strategic partnership with the cybersecurity and defense company Trend Micro to help businesses cope with potential vulnerabilities without interrupting the software delivery process. The alliance integrated open source vulnerability intelligence from Snyk with Trend Micro’s comprehensive ability to detect vulnerabilities for teams operating in a DevOps environment.

One in Three SMBs Rely on Free Cybersecurity Tools or Nothing

credential phishing campaigns

One in three small businesses with 50 or fewer employees rely on free or consumer-grade cybersecurity tools stated a research commissioned and published by BullGuard. The research also pointed out that one in five companies do not use any endpoint security whatsoever. The research, which surveyed small businesses in the U.K. and the U.S., suggested that nearly 43% SMB owners are not prepared for a potential cyberattack or breach leaving their most sensitive financial, customer, and business data at risk.

“Small businesses are not immune to cyberattacks and data breaches and are often targeted specifically because they often fail to prioritize security,” said Paul Lipman, CEO of BullGuard. “Caught between inadequate consumer solutions and overly complex enterprise software, many small business owners may be inclined to skip cybersecurity. It only takes one attack, however, to bring a business to its knees.”

The research also pointed out massive discrepancies between what SMB owners think versus the real-world scenario. According to the research 60% of SMB owners feel that they will not face any kind of cybersecurity incidents, while in the actuality, nearly 19% SMBs suffered cyber incidents last year. Here, companies that fell victims to cyberattacks not only experienced a huge down time, but even had to spend US$10,000 or more to resolve the attack. Nearly 50% SMB owners stated that their employees did not receive any cybersecurity training. While 65% SMBs managed cybersecurity in-house, and less than 10% have a dedicated IT staff member.

It is now of paramount importance that SMBs understand the threat that looms in the cyber space. While big corporations fortify themselves with several layers of protection, small businesses often underestimate the potential impact of cyberattacks. Many small business owners believe that hackers only attack high-profile organizations when the reality is just the opposite. In fact, nearly 90% of breaches occur in small businesses. A bigger concern is that nearly 60% of small businesses shut down within six months of a cyberattack.

According to an earlier research, SMBs in the U.K. revealed that potential cyberattacks and malware infections trigger severe concern than staffing or cash flow issues. The research report“Securing Growth:  How Cyber Risks Among Smaller U.K. Companies Change With Size and Time”, from cybersecurity firm Sophos, states that SMBs in the U.K. are being targeted by determined threat actors or have their network systems infected by malware. It’s said that the organizations don’t have enough resources or expertise to maintain a standard cybersecurity posture, which represents poor cyber-readiness.