Home Blog Page 25

Attackers Steal 1.1 M User Accounts Through Credential Stuffing

Credential stuffing attacks

User login credentials continue to become a primary target for cybercriminals, as they provide access to organizations’ critical infrastructures. Threat actors increasingly use various attack vectors like credential stuffing to steal classified data like usernames and passwords.

The New York State Office of the Attorney General (OAG) recently revealed that threat actors compromised over 1.1 million user accounts of 17 companies using credential stuffing attacks. The investigation conducted by OAG stated that credential stuffing attackers mostly targeted organizations in online retailers, restaurant chains, and food delivery services.

What is Credential Stuffing Attack?

In credential stuffing attacks, threat actors leverage stolen or leaked credentials like usernames and passwords to break into user accounts illicitly. Adversaries launch a credential stuffing attack by adding a list of compromised usernames and passwords to botnets or automated tools that initiate the authentication process on various websites.

OAG’s investigation found thousands of posts containing login credentials across various darknet forums, allowing other bad actors to leverage them.

Also Read: How to Prevent Credential Stuffing Attacks

“Unlike many other types of cyberattacks, credential stuffing attacks often require little technical knowledge to mount. Attackers typically use free, easily accessible software capable of transmitting hundreds of login attempts simultaneously without human intervention. A single attacker can easily send hundreds of thousands, or even millions, of login attempts to a single web service,” OAG said in a statement.

Mitigation

The OAG notified the affected organizations to be vigilant on the ongoing credential stuffing attacks and maintain necessary security precautions to protect against them. “Every business that maintains online accounts for its customers should therefore have a data security program that includes effective safeguards for protecting customers from credential stuffing attacks in each of four areas: defending against credential stuffing attacks, detecting a credential stuffing breach, preventing fraud and misuse of customer information, and responding to a credential stuffing incident,” OAG added.

Earlier, CISO MAG reported rising credential stuffing attacks and recommended security measures to protect online accounts. These include:

  • Enable passwordless authentication process.
  • Use continuous authentication systems like biometrics or behavioral patterns to verify the user’s authenticity.
  • Enable Two-Factor Authentication (2FA) or Multi-Factor Authentication (MFA).
  • Avoid reusing leaked/breached credentials.
  • Check whether your credentials or personal data have been leaked in any data breach at haveibeenpwned.

Today’s CISOs Wear Multiple Hats; The Role is Evolving

Cybersecurity Predictions

Today’s hyper-connected workplace requires CISOs to wear multiple hats – technologist, evangelist, investigator, negotiator. It is now widely understood that cyberattacks can disrupt business operations and impact revenue growth and that managing and mitigating risk is a responsibility shared by everyone within the organization.

By Prasad Jayaraman, Principal, Advisory, KPMG

CISOs roleSecuring the organization is more important than ever. Three-quarters of CEOs believe a strong cyber strategy must engender trust with key stakeholders. Thus, the role of cyber professionals is transforming from enforcer to influencer. Their primary function is evolving beyond promoting awareness of potential cyberattacks to include keeping senior leaders from becoming complacent by challenging assumptions that the organization will not be the next ransomware target.


Also see:

How to Generate CISO Buy-In For Active Directory Protection


Organizations Will Adopt a Privacy-first Mindset

Historically, cyber security and data privacy were seen as separate disciplines. But several new regulations such as CCPA or GDPR that aim to protect consumer data have renewed focus on data rights, privacy, and security. Effective data privacy practices require a multidisciplinary approach, a cultural shift in which privacy and security are embedded into organizational change, processes, technology, and products.

With so many fast-evolving regulations across the globe, the regulatory landscape is becoming increasingly difficult to navigate. It will lead to more organizations embracing automation to manage privacy risk identification and reporting.

Cyber Professionals Will Focus More on Their Organization’s Full Ecosystems

This pandemic has taught us that collective action is the only way to enact meaningful change. Most organizations are no longer single, monolithic entities but rather deeply operationally dependent on a robust supply chain, and myriad traditional and non-traditional partners that often have direct access to business systems and data.

It is paramount that CISOs enact risk management frameworks that look both inward and outward to more closely monitor and secure any relationships with third parties such as suppliers and vendors. As a result, CISOs will need to move to a more proactive approach that puts continuous monitoring, usage of AI/ML-based solutions, threat intelligence, and zero trust at the heart of their ecosystem security model.

Researchers Find New Web Skimmer Campaign Targeted Over 100 Sites

Skimmer, formjacking

Supply chain attacks can devastate organizations’ critical infrastructures as one single weak link can enable threat actors to victimize the entire network. Recently, security experts from Unit42 found a supply chain attack using a cloud video platform to spread a formjacking skimmer. The researchers claim they’ve detected over 100 real estate sites compromised by the same skimmer attack.

In formjacking attacks, hackers inject malicious JavaScript code into the victim’s website to compromise and steal sensitive information. The deployed malware code alters the behavior of the targeted website without a user’s knowledge.

The researchers stated the skimmer has harvested victims’ sensitive information such as names, emails, phone numbers and sent them to a collection server – https://cdn-imgcloud[.]com/img, which is also malicious.

Also Read: Indian Users Third Most Affected by Formjacking Attacks

“The skimmer itself is highly polymorphic, elusive, and continuously evolving. When combined with cloud distribution platforms, the impact of a skimmer of this type could be very large. For these reasons, attacks like this raise the stakes for security researchers to untangle their sophisticated strategies and trace them to the root cause. We have to invent more sophisticated strategies to detect skimmer campaigns of this type since merely blocking domain names or URLs used by skimmers is ineffective,” the researchers said.

Hackers Deploy Malicious Code in Video

Unit42 researchers stated that attackers injected the skimmer codes into the player of the cloud video platform. It automatically downloads whenever a user imports the video embedded with malicious codes. Explaining how hackers injected the skimmer into the video, the researchers added, “When the cloud platform user creates a player, the user is allowed to add their own JavaScript customizations by uploading a JavaScript file to be included in their player. In this specific instance, the user uploaded a script that could be modified upstream to include malicious content. We infer that the attacker altered the static script at its hosted location by attaching skimmer code. Upon the next player update, the video platform re-ingested the compromised file and served it along with the impacted player.”

Lapsus$ Ransomware Targets Media Firms in Portugal

Lapsus$ Impresa, Amedia data breach

A few days into 2022, ransomware operators have already started targeting organizations with various extortion schemes. Security experts were alarmed about a novel ransomware variant – Lapsus$, disrupting operations of media firms in Portugal. The ransomware reportedly targeted Impresa, a popular media giant in Portugal. In an official release, the company confirmed that a “computer attack” affected operations of its Expresso newspaper, TV channel SIC, and other Impresa-owned websites. The suspected ransomware attack also compromised Impresa’s server infrastructure and Twitter account.

“The Expresso and SIC websites were temporarily unavailable, preventing access to all the information we produce day-by-day, hour-by-hour, minute-by-minute, telling what is happening in Portugal and in the world. Now, and while we make every effort to recover what is ours (what is yours), we have decided to create a temporary website, this one that is opening now, that will allow us to bring you our news again — the ones that we have been coming to publish only on Expresso’s social networks,” the release said.

Lapsus$ – The Culprit

The Lapsus$ group reportedly confirmed that it’s behind the attack. The group took credit by posting a ransom note on the affected systems. While Impresa stated that it regained control over the affected systems and sites, the ransomware group claimed it still has access to the company sites.

“We will give everything we have to not let you down on these important days in our history. We do this because today, as since the day it was born, the Expresso does not give up fighting for the rule of law. We are doing everything we can to re-deliver our exclusives, as well as to guarantee the delivery to newsstands of the next weekly edition of Expresso – also on paper, of course,” the release added.

Cyberattacks on Media Firms

Security incidents on media organizations have become prevalent in recent times. Amedia, a leading Norwegian media company, was exposed to a serious data breach resulting in the disruption of its services. In a news release, the company revealed that on the night of Tuesday, December 28, 2021, several of Amedia’s central computer systems were shut down. A significant data breach by third-party threat actors impacted Amedia’s central computer systems. The extent of the damage is yet to be ascertained, and the company has taken measures to contain the attack. Read More Here

Think Beyond Holiday Hacks: Putting DevSecOps Into Practice

devsecops

Every year, during the holiday season, we see major attacks on organizations or critical infrastructure. In Dec. 2020, it was ransomware attacks on health care institutions. And last month, it was the Log4j vulnerability, which has affected myriad applications. According to news reports, there have been millions of cyberattacks on companies since Friday, December 10, because of this vulnerability. Our proactive response to holiday hacks should be DevSecOps practices.

By Daniel Kaar, Global Director, Application Security Engineering at Dynatrace

Organizations need to stop and ask, “Are we ready to prevent hacks?” If cybersecurity isn’t built into developer operations, the answer is no.

Even if the answer is yes, given the ever-changing threat landscape, it might be time to fortify organizational security measures by putting DevSecOps — which automates the integration of security at every phase of the software development lifecycle — into practice.

Traditionally, developers have addressed application security through a checkpoint after a completed sprint but in a team functionally separate from DevOps. This antiquated and siloed approach creates risk and slows the development process and the reaction time, contrary to a modern software development approach.

By putting DevSecOps into practice, organizations can ensure applications are released without risk. Gartner defines DevSecOps as “the integration of security into emerging agile IT and DevOps development as seamlessly and as transparently as possible.”

DevSecOps connects three different disciplines: development, security, and operations. The goal is to seamlessly integrate security into a continuous integration and continuous delivery (CI/CD) pipeline in pre-production (dev, or development) and production (ops or operations) environments.

More Threats Places Primacy on DevSecOps

In advance of the 2021 Labor Day weekend, the FBI and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint alert outlining increased cyber-targeting during holidays. According to the release, holidays and weekends are appealing times for cybercriminals to act; make it a holiday weekend, and the risk is even greater.

“In some cases,” the alert notes, “this tactic provides a head start for malicious actors conducting network exploitation and follow-on propagation of ransomware, as network defenders and IT support of victim organizations are at limited capacity for an extended time.”

All cyberthreats are on the rise, even in potentially overlooked domains. In 2022, for example, exploitation of containers in Kubernetes environments is predicted to increase. Surges come as DevSecOps teams continue to grapple with greater application, cloud, and IT complexity while also dealing with employee burnout during the height of the pandemic.

In short, businesses need a stronger approach to security to avoid holiday hacks and beyond. Moving security sooner in the development process (shift-left) brings security to the forefront of all developer, business, and innovation functions. At the same time, it is critical to have a shift-right strategy in place, i.e., continuous monitoring of (high-risk) production environments, a very common gap in most organizations’ application security tooling landscape. Here are a few best practices.

Automate Where You Can

The goal of DevSecOps is to release better software faster – and goes beyond DevOps to detect and mitigate software vulnerabilities in production efficiently and fast. In short, DevSecOps supports speed and innovation safely from the start.

The degree of automation present in most CI/CD toolchains requires complete automation of DevSecOps security tooling.. It needs to provide information about the security of your application in parallel with development and testing so that vulnerability scans and other security measures don’t slow down development. Ideally, there should be no manual steps, configurations, or custom scripts.

Automation tools streamline and simplify security practices like vulnerability scanning and evaluating the use of vulnerable libraries, which also helps mitigate security team burnout. By automating mundane security tasks in the development cycle, DevSecOps teams are free to drive faster, more secure release cycles and accelerate innovation for the organization and its customers.

Shift Left, But Do Not Forget Right

While the benefits of “shifting left” — conducting security assessments early in the software development lifecycle before vulnerabilities find their way into production — are clear, DevSecOps should also extend to production environments, known as shift right. After all, production is where most attacks happen, and the biggest damage eventually occurs, posing the biggest risk to organizations.

Observing an application while it is running in production provides greater insight than just scanning source code alone. Detecting new zero-day vulnerabilities, for example, requires monitoring existing applications in the production environment. Some applications in production may not have been properly run through delivery, and important security controls were bypassed. As a result, apps could not be scanned by security tools in the development phase.

Avoid Holiday Hacks and More

Cyberattacks disrupt business, cost significant amounts of money, and damage reputations. A malicious attack during the holidays could be especially detrimental. Knowing it’s prime time for bad actors, it’s a good time to examine the security gaps in the application development process.

In today’s multi-cloud and hybrid environments, the most resilient applications, IT ecosystems, and businesses will have security as a top priority all along the development process. DevSecOps makes this possible.

With real-time security intelligence across pre-production and production environments and automation that can help manage every stage of the DevSecOps workflow, teams can produce better, higher-performing, more secure software faster and with less effort.


About the Author

DevSecOpsDaniel Kaar is the Global Director of Application Security Engineering at Dynatrace. With his team, Kaar helps organizations around the globe to embrace a modern, next-generation approach to application security.

Kaar had worked in various software engineering roles before moving to a customer-facing role. Over the past decade, he has been involved in hundreds of customer engagements, hosted dozens of webinars, and created several thought-leadership articles.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG, and CISO MAG does not assume any responsibility or liability for the same. 

Hackers Spread Purple Fox Rootkit via Fake Telegram App

Purple Fox

It has become routine for cybercriminals to spread their customized malware via fake mobile applications. Security experts from Minerva Labs recently found threat actors leveraging malicious Telegram applications to distribute customized malware dubbed Purple Fox on targeted devices.

“This threat actor was able to leave most parts of the attack under the radar by separating the attack into several small files, most of which had very low detection rates by AV engines, with the final stage leading to Purple Fox rootkit infection,” the researchers said.

Purple Fox Infection

The malicious Telegram installer is a compiled AutoIt freeware script called Telegram Desktop.exe, which creates a new folder named TextInputh under C:\Users\Username\AppData\Local\Temp\ and drops a legitimate Telegram installer and a malware downloader file TextInputh.exe. The TextInputh.exe file acts as a downloader of additional payloads for the next attack stage that installs Purple Fox Rootkit without being detected.

Usually, rootkits allow remote hackers to access the operating system on the infected machine illicitly. Threat actors could monitor and steal sensitive information leveraging rootkits.

The information gathered by Purple Fox include:  

  • Hostname
  • CPU – by retrieving a value of HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0\ ~MHz registry key
  • Memory status
  • Drive Type
  • Processor Type

Also Read: How to Spot Malicious or Fake Apps

“We found a large number of malicious installers delivering the same Purple Fox rootkit version using the same attack chain. It seems like some were delivered via email, while others we assume were downloaded from phishing websites. The beauty of this attack is that every stage is separated to a different file which are useless without the entire file set. This helps the attacker protect his files from AV detection,” researchers added.

New Malware Variants on the Rise

Despite several security measures, threat actors managed to spread various malware variants. A recent analysis uncovered an info-stealing malware dubbed Redline targeting web browsers like Opera, Chrome, and Edge to harvest login credentials. According to a report from AhnLab ASEC, the Redline malware campaign targets users who enable the auto-login feature on their browsers.  Active since 2020, when Redline Stealer first appeared on the Russian darknet forum, the malware is peddling for $150-$200, allowing bad actors to leverage it. Read More Here

Blockchain Technologies Will Be Integrated with Information Security and Cybersecurity Products

Cybersecurity Predictions

Making predictions in cybersecurity or any discipline or field can be quite challenging. First, it is virtually impossible to predict the future – consider the emergence of the pandemic and how that has affected so many different functions, including cybercrime and cybersecurity! Still, it can be fun to consider some of the existing or current trends and what direction they will proceed. One of my predictions is incremental movements to integrate Blockchain technologies into resource identity solutions, information security, and cybersecurity-related products.

By Stan Mierzwa, M.S., CISSP, Director and Lecturer, Center for Cybersecurity, Kean University

The following three predictions are just that, predictions, but in varying sectors of cybersecurity.  These include the potential for cybercrime, concerns about critical infrastructure, and a look to the future with emerging technologies that can be leveraged in information and cybersecurity.

Increases in cybercrime through ransomware events and incidents. Through the Federal Bureau of Investigation’s Internet Crime Report, an upward trend of ransomware events has been reported. In just the past three years, ransomware incidents have grown from 1,493 in 2018, 2,047 in 2019, and 2,474 in 2020. The numbers for 2021 are not yet available, but it is anticipated that the resulting number will increase.   In the past three years, there has been an increase of more than 65.7% of reported ransomware events with the FBI IC3 (FBI, 2020). 

Greater attention to protect industrial technology, partly through Industrial Internet of Things (IIoT) devices, to protect our critical infrastructure and supply chain functions. The use and value of industrial systems have gained interest in the past year, given some notable attacks on critical infrastructures, such as the ransomware attacks to the energy pipeline in the United States. Such attacks can have far-reaching health, safety, and substantial negative impacts on customers and the general citizen.

Incremental movements to integrate Blockchain technologies into resource identity solutions, information security, and cybersecurity-related products. One example of the innovation being approached related to the use of Blockchain, or Bitcoin specifically, surrounds the work by Microsoft with the open-source project called ION (Cuen, 2019).  The solution provides for a decentralized and permission-less identity system. There is no centralized repository of identity qualities for providing access with this product.  Regardless of this product, which has been under development for four years, if successful, it opens up the door to other potential critical applications that utilize Blockchain technology in actual use cases.

Also see:

How Blockchain Is Shaping Cyber Security and Causing Technology Disruptions for Global Enterprises


About the Author

Stan-MeirzwaStanley Mierzwa is the Director of, Center for Cybersecurity at Kean University in the United States. He lectures at Kean University on Cybersecurity Risk Management, Cyber Policy, Digital Crime and Terrorism, and Foundations in Cybersecurity. Stan has over 15 published research publications and is a peer reviewer for the International Journal of Cybersecurity Intelligence and Cybercrime, Online Journal of Public Health Informatics and an Editorial Review Board member for the International Association for Computer Information Systems. He is a Certified Information Systems Security Professional (CISSP) and member of several associations, including the FBI Infragard, IEEE, and (ISC)². He is a board member (Chief Technology Officer) of the global pharmacy education non-profit, Vennue Foundation. Stan holds an MS in Management with a specialization in Information Systems from the New Jersey Institute of Technology and a BS in Electrical Engineering Technology from Fairleigh Dickinson University.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. 

Microsoft Issues Fix for Exchange 2022 Security Flaw

Microsoft 2022 flaw, Cybersecurity interest, Personnel Security Program

As we roll into the new year, many new vulnerabilities are being uncovered, exposing organizations’ critical digital assets to various cyber risks. It seems Microsoft welcomed the year 2022 with a security issue that prevents its Exchange servers from sending and receiving emails. The technology giant recently released a patch to address a security vulnerability affecting email messages to get stuck in transport queues of on-premises Exchange Server 2016 and Exchange Server 2019.  The technology giant stated the issue is related to a date check failure with the change of the year and not an issue with malware scanning, malware engine, or a security-related problem. Microsoft clarified that Edge Transport servers are unaffected by this vulnerability.

“The version checking performed against the signature file is causing the malware engine to crash, resulting in messages being stuck in transport queues. We have now created a solution to address the problem of messages stuck in transport queues on Exchange Server 2016 and Exchange Server 2019 because of a latent date issue in a signature file used by the malware scanning engine within Exchange Server,” Microsoft stated.

Also Read; Microsoft Fixes 6 Zero-day Flaws in December 2021 Patch Tuesday Update

The vulnerable applications show the below error message/code when the issue occurs:

  • Log Name: Application
    Source: FIPFS
    Logged: 1/1/2022 1:03:42 AM
    Event ID: 5300
    Level: Error
    Computer: server1.contoso.com
  • Description: The FIP-FS “Microsoft” Scan Engine failed to load. PID: 23092,
  • Error Code: 0x80004005
  • Error Description: Can’t convert “2201010001” to long

Mitigation

To fix the issue, Microsoft urged users to download a PowerShell-based scan engine reset script that executes on each Exchange mailbox server used for downloading antimalware updates.

Fixing the Issue Automatically

  • Download the script here: https://aka.ms/ResetScanEngineVersion
  • Before running the script, change the execution policy for PowerShell scripts by running Set-ExecutionPolicy -ExecutionPolicy RemoteSigned.
  • Run the script on each Exchange mailbox server that downloads antimalware updates in your organization (use elevated Exchange Management Shell).

Fixing the Issue Manually

  1. Remove existing engine and metadata and stop the Microsoft Filtering Management service.
  2. Use Task Manager to ensure that updateservice.exe is not running.
  3. Delete the folder: %ProgramFiles%\Microsoft\Exchange Server\V15\FIP-FS\Data\Engines\amd64\Microsoft.
  4. Remove all files from the folder %ProgramFiles%\Microsoft\Exchange Server\V15\FIP-FS\Data\Engines\metadata.
  5. Update to the latest engine and start the Microsoft Filtering Management service and the Microsoft Exchange Transport service.
  6. Open the Exchange Management Shell, navigate to the Scripts folder (%ProgramFiles%\Microsoft\Exchange Server\V15\Scripts), and run Update-MalwareFilteringServer.ps1 <server FQDN>
  7. Verify engine update info in the Exchange Management Shell, run Add-PSSnapin Microsoft.Forefront.Filtering.Management.Powershell.
  8. Run Get-EngineUpdateInformation and verify the UpdateVersion information is 2112330001.

Microsoft stated the script (patch) might take some time to run, based on the size of the organization and the number of messages queued up.

Redline Malware Campaign Reveals Risks of Saving Passwords in Browsers

Redline malware, Gummy Browsers attack

Today’s browsers have an auto-login feature that saves passwords for frequently used online services. While saving passwords in browsers is convenient, it is not a good idea. A new analysis uncovered an info-stealing malware dubbed Redline targeting web browsers like Opera, Chrome, and Edge to harvest login credentials. According to a report from AhnLab ASEC, the Redline malware campaign targets users who enable the auto-login feature on their browsers.  The analysts stated that the Redline malware, also called Redline Stealer, compromised a VPN account of a company by targeting a remote employee device that saved passwords in the browser. Threat actors reportedly leveraged the leaked VPN account to hijack the company’s internal network three months later.

“The targeted employee used the password management feature provided by the web browser to save and use the account and password for the VPN site on the web browser. While doing so, the PC was infected with malware targeting account credentials, leaking accounts and passwords of various sites, which also included the VPN account of the company,” the analysts said.

Also Read: 3 Digital Assets That Are High in Demand on Dark Web Forums

Redline Available on Darknet

Active since 2020, the Redline Stealer first appeared on the Russian darknet forum. The malware is peddling on the dark web for $150-$200, allowing bad actors to leverage it. In addition to the malware, credentials leaked using Redline malware are sold on the dark web.

The main features of Redline malware include:

  • Collecting and stealing information saved to browsers like login account and password, cookies, autofill, credit card information
  • Collecting default system info such as the IP address of system and OS info
  • Collecting hardware information such as the processor of the system, memory size, and GPU
  • Collecting information of browsers and software installed in the system
    Collecting processes and anti-malware programs installed
  • Controlling target system via SOAP protocol communication
  • Uploading and downloading files
  • Accessing arbitrary URLs and running files

Redline Expose 6M Records

Recently, security expert Bob Diachenko unveiled that Redline Stealer malware exposed more than 6 million records online. It found that the Redline malware campaign is the key source for trading stolen sensitive information on various cybercriminal and dark web forums.

Compromised credentials pose severe security threats to both organizations and users. Recently, the data breach search website Have I Been Pwned? reportedly added 441,657 unique email addresses stolen by RedLine malware operators. Data breach victims use Have I Been Pwned? platform to check whether their email ID or phone number has been compromised in any security breach. The users, who find their email address exposed, are required to update their passwords for all online accounts on the device, including corporate VPNs, email accounts, and other personal accounts.

How to disable auto-login in browsers

Firefox

  1. Click on Menu > Settings
  2. In the Privacy & Security section, uncheck the option “Ask to save logins for passwords and websites”
  3. Also uncheck the option for Autofill logins and paswords
  4. Uncheck Allow Windows single sign-on…
  5. Near Logins & Passwords, click the Saved Logins button
  6. Delete any login credentials that you see.

If you do not use Firefox as your default browser, you will find similar settings in other browsers. Look in the Privacy & Security section under Settings or Advanced Settings.

The Real Value of Professional Certifications

professional certifications, certificates, PKI, PKI Automation

Whether Lean Six Sigma (LSS), Project Management Professional (PMP®), IT Infrastructure Library (ITIL®), the EC-council’s Certified Chief Information Security Officer (CCISO), or Certified Information Systems Security Professional (CISSP) (the list goes on), the real value of professional certifications comprises multiple perspectives. This brief article highlights the immediate impact, return on investment (ROI), and competitive edge as value-added considerations for seeking professional certifications in cybersecurity.

By Dr. Charlotte M. Farmer, Independent Director

Rapid Impact

Faced with rapid changes in technology and evolving cyberthreats, leaders quickly find themselves overwhelmed by knowledge and capability gaps.  For example, organizations are encountering a significant change in processes and protocols to operate and secure the enterprise effectively.  Realizing that the skills needed to execute are becoming radically different, leaders are compelled to reset or upskill the workforce.  With the heightened emphasis on mobility, organizations seek application skills that enable the development and management of various cloud services.  Organizations and their service providers are upskilling employees through acquisitions, training, retraining, or talent acquisition mechanisms.

Given that certifications deliver targeted guidance in a timely fashion, leaders look to certifications as a rapid approach to keep skills fresh and relevant whenever, wherever needed.  Pursuing a degree program is not always a practical option.  In some cases (e.g., cybersecurity, AI, data analytics, etc.), textbooks are outdated by the time they are published.  Certifications have rapidly become a stop-gap solution to help keep pace with technology acceleration.


Also see: EC-Council Launches a Specialized Web Application Hacking and Security Certification

Return On Investment

With the rapidly changing demand for new solutions, (e.g., AWS Certified Solutions Architect – Professional, Certified Cloud Security Professional [CCSP], Certified Data Privacy Solutions Engineer [CDPSE], etc.), some organizations may not understand the available capabilities or how to employ them. This cripples leaders as they strive to actualize strategies. Playing the long-game: Once the strategic direction is established, a 2–3-year Information Technology (IT) roadmap should be established to identify: 1) business needs, challenges, and aspirations, 2) functional capabilities needed to tackle challenges and achieve aspirational goals, 3) the talent needed to perform capabilities, and the 4) professional development needed for the workforce.

In situations where individuals are faced with trade-off decisions between pursuing a certification or degree, it can be helpful to establish decision criteria that will be used to measure ROI.  Criteria could include (but is not limited to):

  • salary impact
  • urgency (needed to address the emerging threat or enable business transformation)
  • intent (professional positioning/growth or intellectual fulfillment)
  • organizational risk (ensure sustainability, drive compliance, etc.)

With personal, professional, and corporate ROI in mind, this author is adding CISSP to her portfolio of certifications along with free online courses by Harvard, MIT, Berkeley, and more (via EDx).  EDx offers access to 2,000 free online courses from 140 leading institutions worldwide.

Professional Certifications for the Competitive Edge

In this “micro-wave” economy, lifelong learners may turn to certifications to stay sharp in their area of expertise while banking on rapid ROI.  In this environment, certifications appear to offer a high-value, fast-paced means to enhance skills.  CAUTION:  Certifications are not panaceas and should not

be treated as such.  Depending on the circumstances, certifications may not substitute for formal education or experience.  Appropriate certifications should be included as part of a holistic professional development plan that includes a proportionate amount of:

1) learning on the job through hands-on stretch assignments

2) learning via engagement with subject matter experts using an apprentice model, and

3) formal training in relevant classes/degree programs, seminars, and workshops.

Keep in mind that professional development plans should align with the individual’s learning style, environmental drivers (e.g., industry, technology, processes, etc.), and strategic direction of the organization.  Most importantly, individuals should co-create a development plan with their management team to determine the most appropriate certification and optimal balance of work, mentorship, and training.

Conclusion

Arguably, professional certifications offer a value-added approach to rapidly skill-up the workforce.  While certifications help enhance skills and experience, they should be included in a holistic professional development plan that includes a proportionate amount of learning on-the-job, engagement as an apprentice, and formal training.  Many venues are offering free courses to help gain new skills and earn a certificate of completion. Pick one and join today.


About the Author

Charlotte FarmerDr. Charlotte Farmer is an experienced Director and Board Member with proven value creation across blue chip companies and top-tier general management consulting firms. Over the last 25 years, she has served as Board Chair, Committee Chair, or Board Advisor to 16 non-governmental organization (NGO) boards. Currently, she serves as Board Chair of a tech start-up and advisor to a private equity company in The Carlyle Group portfolio. Her board expertise includes strategy, governance, and turnaround with proven results building high-performing, growth organizations. Her leadership roles in high-tech manufacturing, global operations, finance, and digital transformation would also be an asset to companies eager to expand their footprint or companies in need of turnaround guidance.

Dr. Farmer is also on the CISO MAG Editorial Advisory Board.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.