Home Blog Page 247

Cyber Startup Hub in Israel Declines as Global Competition Rises: Elron VP

Candiru DevilsTongue

With rising global competition in the cybersecurity market, Israel is dealing with a decline in the cyber startups ecosystem, according to Zohar Rozenberg, Vice President (VP) of Cyber Investments at Elron and RDC. Rozenberg, who has been elemental in shaping the Israel Defense Forces’ (IDF) cyber policy, graced the cybersecurity conference Cybertech Tel Aviv.

Rozenberg said, “Markets saturate, power consolidates, and competition grows stronger. Nothing runs on its own without energy. We must tirelessly fuel innovation, boldness, and ingenuity without letting our guard down.”

Innovation vs Revenue

Public and private ventures invested incredible dividends to make Israel a vibrant cyber hub. The country has always valued bold innovation and planning, however investment in cybersecurity is slowing down. Israel saw only 40 new cybersecurity startups in 2019, a 33 percent decline compared to 60 new startups in 2016. Investors are preferring rapid revenues over innovation, whereas, global technology corporates are competing over talent with entrepreneurial capacities.

Tech companies are helping young talent design enterprise-grade solutions, with an aim of making Israel a technological leader. Graduates from IDF’s coveted 8200 unit have a choice to either join a global corporate or become an entrepreneur. Both big and small businesses are appreciating novel ideas from talented individuals, further motivating them to take cybersecurity challenges head-on.

As cyber challenges grow in Fintech, Insurtech, automotive, and manufacturing industries, Israel needs investment and critical mass support to boost its talent and infrastructure.

Cybersecurity Startup Exits in 2019

According to the IVC Research Center report, Israel has 436 cybersecurity companies operating across various verticals of development. The cybersecurity exit totaled to US$11.3 billion within a timeframe of 2013 to 2019.

Seed Funding in Israel

In July 2019, railway cybersecurity startup Cervello Ltd. secured US$4.5 million in a seed funding round led by Tel Aviv-based North First Ventures of Israel and Toronto-based Awz Ventures, along with the participation from the founder of Israel-based Comsec Consulting Ltd., Nissim Bar-El. The funding was used to tackle cyber incidents in the day to day railway operation.

SpiceJet Breach Leaves 1.2 million Fliers Data Exposed

spicejet

SpiceJet, India’s low cost and privately owned airlines, suffered a data breach due to an unsecured database that contained personally identifiable information (PII) data of 1.2 million fliers. According to TechCrunch, a security researcher from U.S. discovered the flaw but resisted naming the ethical hacker, as the research was likely in conflict with certain U.S. computer hacking laws.

The researcher used a brute-force attack against a SpiceJet system to gain access. He insisted that the compromised system’s password was easily guessable. On gaining control over the compromised system, the researcher discovered an unencrypted database backup file, which contained PII of more than 1.2 million passengers.

The exposed database included a month’s worth of flight information and details of all passengers, including state officials who used the airline services for official work-based commute. The data breach also included passenger information such as their first and last name, phone number, email address, and date of birth.

SpiceJet was contacted by the researcher to patch this flaw, but due to a delayed response, the researcher went ahead and alerted CERT-India. On affirming the researcher’s findings and the concurrent lapse, CERT-In notified SpiceJet about the possibility of a data breach due to the unsecured database. Only then, SpiceJet’s IT department patched the critical vulnerability.

When TechCrunch contacted SpiceJet to know more about the data breach, a company spokesperson said, “At SpiceJet, safety and security of our fliers’ data is sacrosanct. Our systems are fully capable and always up to date to secure the fliers’ data which is a continuous process. We undertake every possible measure to safeguard and protect this data and ensure that the privacy is maintained at the highest and safest level.”

The SpiceJet data breach highlighted the need of basic cybersecurity training across all levels and hierarchies in any organization.

Singapore Airlines’ KrisFlyer Account data breach

In January last year, a software glitch possibly exposed personal information of 285 members who used the Singapore Airlines (SIA) services. The bug exposed KrisFlyer, a frequent flyer account of Singapore Airlines, and personal information including the passengers’ full name, email address, membership tier, account number, the accumulated miles/rewards, travel history, passport, and flight information.

The officials at SIA stated that the incident occurred on January 04, 2019, from 2:00 am to 12:15 pm when two or more users logged in to their KrisFlyer accounts at the same time. The airline stated that it had informed Singapore’s Personal Data Protection Commission about the customer data breach and notified the affected customers.

Louisiana Governor Calls for Cyberthreat Readiness

Department of State, state dep

The State of Louisiana took a huge hit in the past year with a large volume of cyberattacks recorded since July 2019, including Louisiana’s municipal and government offices; the Sheriff’s office, and even public-school systems. Owing to this spate of cyberattacks, the Louisiana State Governor, John Bel Edwards, urged the local Government authorities and leaders to show cyber readiness, as cyberthreats have now become the new normal.

What the Governor Thinks

While addressing a local crowd during the inauguration at the state Capitol in Baton Rouge, Governor Edwards said, “You may not have been hit (by a cyberattack) yet in your town or your city. But it’s a question of when, not if. I don’t want anybody paying that ransom because if you do, then their business model is affirmed, and they’re going to keep doing this over and over.”

Governor Edwards suggested that individuals and businesses should frequently take a data backup. This backup needs to be saved remotely and away from the core network architecture so that in case of a cyberattack, the infection can be contained. The backed-up data can then be reinstated causing lesser loss of data and zero ransom payment worries (only in case of ransomware).

With the help of the State Government, Governor Edwards has now established a cybersecurity emergency response team including key persons from the technology services office, the homeland security department, the Louisiana State Police, the Louisiana National Guard, and university experts. A cybersecurity commission has also been established, which aims at finding better risk mitigation and incidence response techniques to cyberattacks.

History of Cyberattacks in Louisiana

Public schools: In July 2019, a state of emergency was declared by the Louisiana Governor after three public-schools (Sabine, Morehouse, and Ouachita parishes in North Louisiana) fell victim to ransomware attack.

Government IT systems and websites: In November 2019, a ransomware infection impacted the public state government’s email, websites including the Office of the Governor, Louisiana State Legislature, Office of Motor Vehicles, Department of Corrections, the Louisiana Division of Administration, and the Department of Transportation & Development, along with other online applications.

Municipality and Health care: In continuation of the November attack, a state of emergency was re-invoked when the ongoing ransomware attack affected 10 percent of Louisiana’s 5,000 network servers and more than 1,500 computers.

Federal Agencies Come Together to Enhance Cybersecurity in Energy Sector

CISA VDP platform, U.S. export ban on cybersecurity items

The U.S. Departments of Defense (DoD), Department of Energy (DoE), and Department of Homeland Security (DHS) have agreed to jointly work on a new initiative “Energy Sector Pathfinder”, which is intended to protect the U.S. Energy Critical Infrastructure and bolster cybersecurity partnerships in the sector. The three federal departments recently signed a Memorandum of Understanding (MOU) to partner on the new initiative, which aims to improve training and education to understand cyber risks, advance information sharing, and develop joint operational preparedness and response activities to cybersecurity threats.

According to the official statement, the Pathfinder program is envisioned to address challenges facing the U.S. energy infrastructure in preventing and responding to the evolving cyberthreats. The new initiative also reinforces the partnership among the three departments to enable intergovernmental co-operation to proactively address cyberthreats to critical energy infrastructure.

Commenting on the new initiative, Kenneth Rapuano, Assistant Secretary of Defense for Homeland Defense, said, “The Energy Sector Pathfinder is a priority initiative for the Department of Defense.  This MOU enables us to work even closer with our Federal Government partners as well as our private sector partners.  We are committed to collaborating with our partners so that they can address the challenges facing America’s energy critical infrastructure, including constantly evolving cyber threats, so that DoD can more effectively defend against foreign threats.  This collaborative effort is complementary to the DoD Cyber Strategy objective to defend U.S. critical infrastructure from malicious foreign cyber activity.”

DoD and NSA’s Initiative Against Cyberthreats

Earlier, the DoD, along with its intelligence wing the National Security Agency (NSA), launched a new division to protect the country’s intelligence and critical digital assets against foreign cyberthreats. This initiative made NSA collaborate with key partners across the U.S. government like U.S. Cyber Command, Department of Homeland Security, and FBI. The new division integrated the agency’s foreign intelligence and cyber operations to enhance the country’s vulnerability assessments and cyber defense expertise.

8 out of 10 U.K. CEOs Fear Cyberattacks as Biggest Threat to their Businesses

UK Government, NCSC

It was recently reported that the U.K.’s cybersecurity market is currently worth £8.3 billion (approximately US$10.8 billion), witnessing an annual increase in revenue in the cybersecurity sector by 46 percent. The sector also received more than £348 million (approximately US$452.4 million) of investment compared to the previous year. However, cyberattacks continue to be the top concern for U.K. enterprises.

A survey by PricewaterhouseCoopers (PwC) pointed out that nearly 79 percent of CEOs fear skills shortages and cyberattacks as some of the biggest threat to their enterprises. The report, which surveyed 1,600 CEOs in 83 countries, also stressed that 75 percent of respondents were worried about the speed of technological change as another major challenge.

According to the report, most CEOs were really concerned about the increasing level of sophistication of cyberattacks. In half the cases, the CEOs themselves deleted their social media apps fearing cyberattacks against them or their company.

“Technology can help businesses upskill at scale. And by improving skills, they can tackle the other major challenges they are most concerned about, such as cyber threats and the climate change,” Kevin Ellis, Chairman and Senior Partner at PwC UK, said in the report. “So, while uncertainty is the watchword for CEOs everywhere, there are also significant opportunities for those that can successfully navigate the uncertainty.”

The study also pointed out that there is a public fear over data privacy, data regulations, vulnerabilities in supply chains and cybersecurity skill gaps, which are also the key issues driving CEOs in their cybersecurity strategies.

Companies are not Cyber Insured

A study by Gallagher, which surveyed nearly 1000 businesses, revealed that even though cyberattacks are the biggest concern for U.K. enterprises, several companies do not have cyber insurance to cover attacks and mitigation. The survey indicated that only 18 percent of U.K.-based companies had standalone cyber insurance policies due to a popular belief that traditional insurance alone will suffice even for cyberattacks.

The scenario has not changed much in the last two years as well. In an earlier survey, NTT Security also suggested that nearly two-thirds of British organizations are not insured for cyber incidents. According to the study, less than a third (29 percent) of firms have dedicated cybersecurity insurance in place. Among them, six percent said their insurance covers only for information security breaches, while 11 percent covered data loss alone. This was despite the fact that 81 percent of the respondents felt that it is important for their organizations to be cyber insured.

Cybercriminals Exploit Popularity of Pop Stars in UAE and Nigeria

cybercriminal, music

Grammy Award nomination is a prestigious affair for its nominees and cybercriminals are using this opportunity to abuse them by spreading malware through their songs. Kaspersky researchers have found a staggering 39 percent rise in attacks which includes attempts to download or run malicious files disguised as nominees’ work in 2019, compared to 2018.

Researchers say cybercriminals are targeting the popularity of pop stars such as Ariana Grande, Taylor Swift and Post Malone, with over half (55 percent) of detected malicious files named after them. Another teenage pop music sensation, Billie Elish, has seen a tremendous increase in fan following owing to her notable hits like, Bad guy, Xanny and Everything I wanted. This has led to a subsequent rise in cybercriminals abusing her name and songs to target her followers.

The regions most affected with these malware attacks are the UAE and Nigeria. The number of users attacked by malware disguised as Billie Eilish songs in UAE accounted for 31,782, whereas in Nigeria this number totaled  9,722. Overall, the UAE saw 61 such malicious files distributed in this region in 2019, with a total of 100,961 cyberattacks. Similarly, Nigeria saw 55 such malicious files distributed in 2019, with 94,630 cyberattacks.

Since these malware attacks are annual trends, Kaspersky researchers also analyzed the most attention-grabbing records and songs nominated for a Grammy in 2019. This list of songs with the most malware attacks was topped by Post Malone’s ‘Sunflower’, followed by Khalid’s ‘Talk’ and Lil Nas X’s ‘Old Town Road’.

To avoid such malware attacks targeted via songs, records and albums of popular music artists’ and bands in future, Kaspersky has recommended the following precautionary measures:

  • While listening to, or downloading famous artists’ songs online, use trusted music and audio services like Apple Music, Amazon Music and Spotify Premium–or download songs legally.
  • Do not click on suspicious or untrusted links promising exclusive music content.
  • Cross-check and double-check the respective artist or musicians’ official social media accounts to make sure that such content exists.
  • Check the extension name of the downloaded file. Song, music and album files have an mp3, .avi, .mkv or .mp4 extension and not .exe or .lnk.
  • Before opening the file, scan it using a security solution, such as an anti-virus or EDR (Endpoint Detection and Response) software.

Why CISOs Should Worry About Sodinokibi Ransomware

ransomware, fonix, fonix ransomware, Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention, Kronos

In late April 2019, researchers from Cisco Talos came across a strain of ransomware that raided a web server. The entry point was a remote code execution vulnerability in Oracle WebLogic Server software discovered about a week earlier. The analysts dubbed this infection Sodinokibi. Back then, it seemed that the predatory program was just another ransom Trojan resembling hundreds of others. However, Sodinokibi operators proved this impression wrong a few months later.

Contributed by David Balaban

Sodinokibi ransomware lineage is dominating the extortion landscape. It has made dozens of high-profile victims, including healthcare facilities and local governments. Furthermore, its distributors’ toolkit has expanded way beyond leveraging unpatched software flaws to gain a foothold in computer networks. The ransoms raked in by the crooks reportedly reach hundreds of thousands of dollars per compromised organization. What is it that has allowed this campaign to soar in only half a year’s time?

Dissecting the Sodinokibi business model

Also known as REvil, Sodinokibi ransomware is backed by an underground affiliate program with quality at its core. While the Ransomware-as-a-Service (RaaS) model is nothing new, in this case, it’s an ecosystem with select players that have gained a reputation on the Dark Web.

The campaign got the first major boost in July when a user, who goes by the alias UNKN, posted a recruitment announcement on a popular hacking forum. This anonymous individual invited other members of the cybercrime community to join the Sodinokibi distribution network that had a “limited number of seats.” Wannabe ransomware peddlers were required to show evidence of quality in terms of the installations they could provide.

One of the perks mentioned in the ad is that the affiliate share starts with 60 percent and goes up to 70 percent after the first three ransom payments. The rest is a “royalty” that goes to the proprietors of the Sodinokibi code. The forum post emphasized that it’s forbidden to do business in the Commonwealth of Independent States (CIS) region, including Ukraine, Russia, Belarus, and Moldova.

This RaaS quickly got several endorsements from trusted members of the black hat environment, who claimed to be very satisfied with the cooperation and encouraged like-minded crooks to get on board. UNKN also shared a snapshot of the recent incoming payments, where most victims submitted 0.4 BTC (about $3,000), and one coughed up a whopping 26 BTC (worth nearly $200,000 at the time of this writing). According to follow-up comments in the thread, infecting large computer networks is a priority for Sodinokibi authors. This focus explains such a big ransom paid by one of the victims.

The elite crew of affiliates

Shortly after this enrollment began, the Sodinokibi epidemic ran rampant. According to McAfee researchers’ findings, this spike is a result of cybercriminal syndicates with a substantial malware distribution background coming on stage.

The analysts identified more than 40 unique affiliate IDs in this campaign, with some of these players operating very similarly to the most successful participants of the GandCrab RaaS. For the record, GandCrab was a highly prolific ransomware family whose decline co-occurred with the Sodinokibi debut last spring. Experts have since spotted numerous ties between the two lineages, which I will highlight in more detail further down.

Obviously, quite a few best performing GandCrab affiliates appear to have switched to spreading Sodinokibi. These crooks are competent in their nefarious enterprise, and their dodgy portfolio includes a diverse set of infection vectors – from RDP hacks to spear phishing and exploit kits. A particularly effective technique is to compromise MSPs (managed service providers) and thereby access large networks of customers associated with them. This is how the felons perpetrated a massive attack against 22 municipalities in Texas in mid-August, demanding $2.5 million for data recovery. All in all, the team of seasoned cybercriminals distributing Sodinokibi is the mainstay of its top position in today’s ransomware landscape.

Connection with GandCrab

As previously mentioned, there are distinct links between Sodinokibi and GandCrab, a species that was once considered the world’s most serious ransomware menace. The similarity isn’t only about the same threat actors in charge of the propagation and the fact that the former emerged as soon as the latter faded away. Analysts have also unearthed patterns in the code that speak volumes about the same source of both infections.

An obvious trait shared by the two pests is the principle of generating unique URLs for communication with the Command & Control server. The hard-coded values for producing sub-path attributes of these URLs are an exact match.

Furthermore, the beta version of Sodinokibi had several debug paths containing clues about its legacy. An example is the “gcfin” (GandCrab Final) project name. Another hint is the “gc6” debug path, which is most likely a reference to GandCrab 6, a version that was probably supposed to become the next iteration of the predecessor but never went live. In addition to this, researchers found that REvil and GandCrab v5.03 had a 40 percent code overlap.

The main striking difference, though, boils down to the behavior of the ransomware architects. GandCrab operators would often include fun functionality in their code. When malware experts analyzed it, they could stumble upon jokes about themselves with subtle shades of mockery and some smileys here and there.

Contrary to this easygoing attitude, Sodinokibi makers adopt a business-only approach and don’t initiate any interaction with the white hats. At the same time, they appear to have a solid reputation and influence in the ransomware community. These facts suggest that Sodinokibi isn’t run by the same people who were behind GandCrab, although there are evident ties between these malefactors. One of the theories is that the new strain is being operated by former GandCrab coders, who chose to continue the dirty business while the original proprietors called it quits.

Recent attacks

In September, a wave of the Sodinokibi plague swept across China via a tricky spam stratagem. The infection arrived with booby-trapped emails pretending to be from the DHL courier company. Camouflaged as notifications about delayed delivery of a package, these messages instructed the recipients to download and fill out the attached document, presumably a customs declaration, so that the shipping process could be successfully completed. However, this file was a ransomware executable in disguise.

The trick is that the attachment had a *.doc.exe extension. Since Windows hides file extensions by default, the embedded object looked like a regular Word document with the right icon. Once opened, though, it instantly launched the ransomware attack on the computer.

Another recent campaign relied on a more intricate tactic. A Sodinokibi affiliate hacked several popular WordPress websites and injected rogue JavaScript in their HTML code to display a phony Questions and Answers page on top of the original content. Mimicking real discussion between the site admin and a visitor who has a question related to the site’s materials, this faux page looks trustworthy and may entice the user to scroll down the Q&A section.

In response to the alleged asker’s query, the pseudo admin provides a link to download the document of interest. If clicked out of curiosity, this link leads to a ZIP file containing a JScript item that invokes a series of commands to infect the user’s system with Sodinokibi. This multi-layered hoax is clever a combo of social engineering and obfuscation mechanisms that allow the payload to slip below the radar of antivirus tools.

The bottom line

Sodinokibi, REvil, the new GandCrab – no matter what you call it, it’s the nastiest ransomware on the cyberthreat map at this point. Its developers and distributors seem to always have new unexpected tricks up their sleeve, and flawless crypto implementation means that victims must pay up; otherwise, they lose all their data. What about the countermeasures? A little bit of extra vigilance, especially with dubious-looking emails, plus up-to-date backups of the most important files, make any extortion attempt go down the drain.

Sodinokibi

David Balaban is a computer security researcher with over 15 years of experience in malware analysis and antivirus software evaluation. David runs the Privacy-PC.com project which presents expert opinions on contemporary information security matters, including social engineering, penetration testing, threat intelligence, online privacy, and white hat hacking. As part of his work at Privacy-PC, Mr. Balaban has interviewed such security celebrities as Dave Kennedy, Jay Jacobs and Robert David Steele to get firsthand perspectives on hot InfoSec issues. David has a strong malware troubleshooting background, with the recent focus on ransomware countermeasures. 

The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG has not tested, nor does it endorse the products and services mention in this article.

NCC Boosts Cybersecurity to Protect ICT Networks

Nigeria Increases Cybersecurity Protocols to Protect ICT Networks, Nigeria BEC scammers arrested

The Nigerian Communications Commission (NCC) has collaborated with major cybersecurity participants in Nigeria to build a robust cybersecurity ecosystem to protect the country’s Information and Communication Infrastructure (ICT) networks. Until now, the commission initiated nationwide cybersecurity awareness campaigns to educate security professionals and students to guide them against cybercrimes like internet fraud and identity theft.

Executive Vice Chairman of NCC, Prof. Umar Danbatta stated that unsecured internet exposes to harmful contents and vulnerable cyber threats. Danbatta stressed that the NCC wanted to make sure that Nigerian youth are protected from cyberattacks.

According to Danbatta, the NCC is involved in the process of making the National Cybersecurity Policy, strategy, and the cybercrimes ACT, 2015 which is soon going for a review. The commission is also establishing a Cyber Security Incidence Response Team (CSIRT) for the communication sector which will focus on international coordination of cybersecurity incidents in Nigeria.

Danbatta stated, “The pervasiveness of the Internet and proliferation of mobile phones make it difficult for parents/guardians to effectively monitor the online presence of their wards in comparison to the old system of connecting to the Internet via desktops and laptops. We have also established the Internet Industry Code of Practice, in place for industry-wide standard/obligation of minimum Cyber Security provision for the protection of children online and protection of communications infrastructure.”

Speaking on Nigeria’s cybersecurity roadmap, the Minister of Communications and Digital Economy, Isa Pantami said that Nigeria is working toward becoming a producer of cybersecurity professionals and youth with digital literacy.

Pantami stressed, “No one will want to do online transactions with our banks if campaign the one knows that online transactions are not safe. “We want to make sure that people can feel safe when they are online. We know that Nigeria is given a bad name when it comes to issues of cybersecurity; people commit crimes and claim to be Nigerians.”

In 2018, Nigeria and Israel made a partnership to implement measures to mitigate cybercrime, security, and privacy issues in the telecom ecosystem and online media database.

Attackers Target Industrial Control Systems with EKANS Ransomware

Ransomware attacks, ransomware, Sinclair Broadcast group

A threat intelligence report from security firm Dragos recently uncovered “EKANS” ransomware targeting industrial control systems (ICS). Researchers said EKANS is the first kind of file-encrypting malware intended to infect the network systems that control operations in manufacturing environments.

While investigating EKANS, researchers found a list of command processes linked to ICS operations.  It’s said that EKANS ransomware was designed to disrupt the ICS processes on victims’ devices. Attackers deploy the ransomware to compromise the targeted devices and encrypt the data, while victims are presented with a note asking for ransom.

EKANS is SNAKE Spelled Backwards

Dragos stated that EKANS, spelled backwards as SNAKE, initially emerged in December 2019 and targeted Windows systems that are used in industrial environments. Explaining the similarities between EKANS and SNAKE ransomware, Dragos said, “Although referred to as both SNAKE and EKANS in public reporting, Dragos will refer to this malware as EKANS due to the existence of other malware previously discovered and labeled as “Snake” and attributed to the Turla threat actor. Any further or future reference to “Snake” by Dragos will refer to Turla-associated activity, while the ransomware variant under discussion will be referenced as EKANS.”

EKANS vs Megacortex Ransomware

Dragos’ report also discovered the relation between EKANS and Megacortex ransomware, which was discovered in January 2019 and is considered a major threat. According to the report findings, Megacortex ransomware poses similar ICS processes.

“While the list of processes targeted in EKANS is relatively short and focused (64 total items), the newer version of MEGACORTEX contains over 1,000 referenced items. The vast majority of the processes listed relate to security solutions or similar tools. However, all of the items referenced in the EKANS ICS list are also present in the MEGACORTEX list, and no additional items are present in the MEGACORTEX list with ICS significance. Based on this information, it appears EKANS is not unique, or at least not first, in targeting ICS-related processes,” the report stated.

Critical Concerns Over Cybersecurity Soar in Ireland

Global Cybersecurity Outlook 2022,Cybersecurity, CEO, CISO

Ireland is among the leading EU member states when it comes to uptake and use of digital technologies (ranks 7 out of the 28 EU member states in the European Commission Digital Economy and Society Index [DESI] 2019). This indicates that the internet and technology are a part of the Irish lifestyle. However, these same technologies have introduced an embedded risk set and vulnerabilities, which have put the nation’s cybersecurity readiness under the scanner.

Ireland’s National Cybersecurity Strategy (2019-2024)

Recently, the Government of Ireland defined the second National Cyber Security Strategy for the period 2019 – 2024, in a bid to bring cybersecurity readiness to the nation. The report stated that over 30 percent of all EU data is housed in Ireland, as nine of the world’s largest tech companies have their headquarters located in Europe. Security of the network and information systems is therefore crucial for the continued economic and social development of Irish nationals.

The key objectives of Ireland’s National Cybersecurity Strategy are:

  • To ensure Ireland’s cybersecurity readiness and respond to, and manage cybersecurity incidents, including those concerning national security.
  • To protect and manage any disruption of services involving critical national infrastructure from cyberattacks.
  • To further grow and develop the cybersecurity sector in Ireland and be cyber-ready.
  • To implement the best technology and measures available internationally in Irish businesses.
  • To increase awareness and develop skill sets among organizations and private individuals around cybersecurity.

The report also highlighted that although nearly 6,500 cybersecurity professionals are present in the nation, critical cybersecurity issues continue to exist in Ireland.  It suggested that the Government should consider the advice given by the Commission for Communications Regulation (ComReg) to allow intelligence on threats to national security to be shared between State agencies and the private sector. ComReg says it cannot guarantee secure telecom networks in the absence of access by private companies to intelligence on national security risks.

Ireland’s 5G Technology Concerns

5G technology is on its way and the nation-states or groups acting on their behalf pose the biggest threat to cybersecurity, as per the consultations submitted to the Government on this issue. “The new 5G technology will benefit society and the overall technology ecosystem but will also increase the attack area of the network. It will result in an increase in (cyber) threats to, and vulnerability within a network,” wrote ComReg Director of Markets George Merrigan.

U.K., in particular, has demonstrated concerns over Huawei’s close links to the Chinese government in manufacturing 5G technology and its corresponding vulnerability to cyber espionage. However, ComReg recommends a mechanism for sharing and accessing national security intelligence in a controlled manner among State agencies and believes that the government should grant access to public companies involved in communication networks.