Home Blog Page 254

Cyberattack Hits P&N Bank, Confirms Data Breach

biggest data breaches in India,data breach, Aptoide Android App Admits Data Breach, Suspends Sign-Up Option Temporarily, Panasonic

Western Australia-based P&N Bank informed its customers of a data leak that happened on December 12, 2019, which exposed customers’ personally identifiable information (PII) and sensitive account information.

In an official notice, the financial services provider stated that the information breach occurred due to a cyberattack on its customer relationship management (CRM) platform during a server upgrade. However, the incident has not caused any loss of customer funds, customers’ credit card details, or banking passwords. Other data like driver’s license numbers, passport numbers, social security numbers, tax file numbers, or health data were not contained in the CRM, and hence not exposed.

The exposed information includes customer names, age details, residential addresses, email addresses, phone numbers, customer numbers, account numbers, and account balances.

P&N Bank was formerly known as the Police & Nurses Credit Society, hence most of the P&N Bank customers are police officers and nurses. P&N Bank stated that it is working with the Western Australian Police Force (WAPOL) and federal authorities to investigate the incident.

Describing the security incident, Andrew Hadley, CEO of P&N Bank, said, “Upon becoming aware of the attack, we immediately shut down the source of the vulnerability and have since been working closely with WAPOL, other federal authorities, our third-party IT provider involved, regulators and independent expert advisers to investigate and protect customers from any further risk. The safety and security of our members’ information and funds is our highest priority.  Data protection continues to be a focus around the world, and financial systems will always present some degree of risk, so it is important to stress that in line with best practice, we have highly sophisticated security measures and controls in place to protect our customers’ accounts.”

Microsoft Fixes Critical Bug in Patch Tuesday, Credits NSA for Findings

Brand Phishing Attacks

Microsoft’s first Patch Tuesday of 2020 saw a total of 49 CVEs (bugs) being fixed, however, the one that matters the most in the cybersecurity space is the Windows CryptoAPI Vulnerability tracked under CVE-2020-0601

This Windows CryptoAPI spoofing vulnerability was found by the National Security Agency (NSA) during its research and analysis. Microsoft, for the first time, has publicly acknowledged the reporting done by the government body and Anne Neuberger, NSA’s Director of Cybersecurity, has accepted the credit given in a press call.

According to the Microsoft’s Advisory, “a spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.” NSAs Cybersecurity Advisory confirms this revelation and gives further insights of the CryptoAPI vulnerability. It says, “The certificate validation vulnerability allows an attacker to undermine how Windows verifies cryptographic trust and can enable remote code execution. The vulnerability affects Windows 10 and Windows Server 2016/2019 as well as applications that rely on Windows for trust functionality. Exploitation of the vulnerability allows attackers to defeat trusted network connections and deliver executable code while appearing as legitimately trusted entities.”

A successful exploit can also allow a potential attacker to conduct Man-in-the-Middle (MITM) attacks and decrypt confidential information of users. Microsoft worked on the findings of NSA’s research team and released a security update that addresses the vulnerability by ensuring that Windows CryptoAPI completely validates ECC certificates.

Both, NSA and Microsoft, have requested all its Windows 10 and Windows Server 2016/2019 system users to install all January 2020 Patch Tuesday updates at the earliest to mitigate the CryptoAPI vulnerability.

As an additional periphery of mitigation steps, Symantec also recommends the following:

Block external access at the network boundary, unless external parties require service.
If global access isn’t needed, filter access to the affected computer at the network boundary. Restricting access to only trusted computers and networks might greatly reduce the likelihood of successful exploits.

Run all software as a nonprivileged user with minimal access rights.
To reduce the impact of latent vulnerabilities, run all applications with the minimal amount of privileges required for functionality.

Deploy network intrusion detection systems to monitor network traffic for malicious activity.
Deploy NIDS to monitor network traffic for signs of anomalous or suspicious activity including unexplained incoming and outgoing traffic. This may indicate exploit attempts or activity that results from successful exploits.

Cybersecurity in Middle East Expands, BIoT to be in Focus

BIoT

With the Middle East cybersecurity market expected to grow at a compound annual growth rate (CAGR) of 22.5 percent between 2018 and 2024, it is also imperative for cities in the region that are ready to jump on the smart bandwagon to address the needs and security of connected and smart building systems. Ahead of the upcoming Intersec 2020, in the Dubai World Trade Center (DWTC) between January 19 and 21, 2020, technology conglomerate, Honeywell, has released its predictions on emerging trends that will shape cybersecurity for buildings.

Honeywell pointed out that Building Internet of Things (BIoT) will likely see a spur in cyberthreats as they become more connected. The surge of smart buildings will also put data and reputation of companies at potentially greater risk. Among the reasons for the trend were less-guarded entry points for buildings and lack of focus on cybersecurity when managing OT (Operational Technology). Another prediction was around cybersecurity for OT in buildings. The technology giant suggested that with buildings becoming smarter, they tend to produce more connected data, thereby attracting more potential threats.

The third prediction was around the cybersecurity talent and how it will shape the security of smart buildings. Honeywell pointed out that with IT and OT security responsibilities overlapping, the demand of infosec professionals—who will cater to the needs of both the worlds—is simultaneously set to increase. It is suggested that most of these professionals are highly likely to start their career in one function but grow their skillset over time as they gain more overarching security experience.

The last important prediction was around standardization and regulation. It stated that with cybersecurity standards becoming a top priority across industries, there would be a greater focus on the standardization for BIoT. It is also anticipated that at least one framework would emerge as a staple guide for securing a building’s OT system.

George Bou Mitri, Vice President and General Manager for Honeywell Building Technologies in the Middle East, Turkey and Africa, commented, “Honeywell’s software, hardware and data analytics capabilities are helping to shape the future of the region’s smart buildings and cities, and we are proud to be helping businesses create robust cybersecurity strategies to protect Operational Technology (OT) across key industries. 2020 is likely to be a transformative year for building technology as businesses make great strides toward optimizing their OT systems and securing them against increased cyber threats.”

Earlier, another report titled “Cyber Security in Smart Commercial Buildings 2017 to 2021,” noted, “The cybersecurity market of smart commercial buildings is largely immature and poorly defined.” The reasons for poor understanding, as the report suggests, are the perennial confusion in the cybersecurity industry itself. Many important stakeholders still lack the understanding of cyberthreats. “Without a more comprehensive understanding of threats posed, they are struggling to find the right strategies and strategic partners to address the issue,” the report suggests.

According to the report, an increase in the number of cyberattacks on buildings may spur innovation and growth in this specific sector, but if the attacks are of a sizeable number, it may even undermine the very adoption of security in connected buildings.

While defense against cyberattacks might be one single element in the cybersecurity market, human causalities from cyberthreats pose a new challenge. “Many organizations simply do not have the experience or training necessary to develop a viable security policy, protect critical assets and network environments, or identify and respond to today’s more sophisticated attacks,” the report adds.

Cloudflare to Offer Free Cybersecurity to Federal Campaigns

Cloudflare, a web infrastructure and security firm, will offer free cybersecurity services to the U.S. Federal Election campaigns.

The San Francisco-based firm stated the new move is intended to prevent any data leaks of election campaign emails and documents. It’s said that Cloudflare will be providing a range of its security services, which includes enhanced protection of firewalls and protection & mitigation of denial-of-service attacks.

Cloudflare claimed that it’s already providing free security services to eight 2020 presidential candidates. In order to avail free services, a U.S. House candidate’s campaign and a U.S. Senate candidate’s campaign must have received at least US$50,000 and US$100,000 in contributions, respectively.

Recently, Cloudflare acquired browser security provider startup S2 Systems. The acquisition aims at integrating S2 Systems’ browser isolation technology that combines speed, reliability, and protection to prevent browser-based attacks with Cloudflare’s new product offering, Cloudflare for Teams.

Cloudflare for Teams has been built with a view to helping build a better, faster and safer internet for the future. It will also help secure mobile and cloud-enabled internet in a better way. The acquisition was closed for an undisclosed amount on December 31, 2019. S2’s team of 10 members from Kirkland, Seattle, is now officially a part of the Cloudflare team. Cloudflare, which already has 200 plus centers across the globe, will now expand services in Seattle to accommodate its new employees.

Big Prize Money Offered in Indian IT Ministry Cybersecurity Startup Challenge

Startup

India’s Ministry of Electronics & Information Technology (MeitY) and Data Security Council of India (DSCI) today launched the Cyber Security Grand Challenge, which will award INR 3.2 crore (approximately US$451,754), to promote a culture of innovation and entrepreneurship in the cybersecurity startup ecosystem. It was formally launched by Ajay Sawhney, Secretary, MeitY and registrations are now open.

A press release issued to the media today stated: “MeitY invites Startups and budding entrepreneurs who comply with the start-up definition as defined by DIPP at http://startupindia.gov.in to participate in the Grand Challenge. Individuals who are not yet registered can register as a startup and participate. A unique feature, the IPR of the product being developed as part of the challenge will be owned by the respective startup. DSCI will be administering the Grand Challenge and the whole process will run for nine months under various stages.”

Details about the challenge

Under Grand Challenge, participants need to create solutions around six defined Problem Statement areas which include: Microservices, IoT, Biometrics, Hardware Security, etc. In the Idea stage, 12 shortlisted teams will receive INR 5 Lakh each (approximately US$7,000) and six teams will receive INR 10 Lakh each (approximately US$14,000) in the MVP stage. Multiple mentorship workshops will be conducted to guide the participants throughout the grand challenge. The winning team with the best judged solution will receive a grand prize of INR 1 Crore (approximately US$141,362) whereas 1st runner up and 2nd runner up will receive INR 60 Lakh (approximately US$84,766) and INR 40 Lakh (approximately US$56,500) respectively.

More information about the challenge and registrations can be submitted at: https://innovate.mygov.in/cyber-security-grand-challenge/

Launching the challenge, Ajay Sawhney, Secretary, MeitY, said, “The Grand Challenge is a first of its kind initiative encouraging cybersecurity entrepreneurs to innovate and develop solutions for critical cybersecurity problems and demonstrate capabilities. It is an opportunity to gain mentorship and guidance under the best cybersecurity experts. Start-ups will receive intensive mentoring on various aspects such as technology, building global solutions, go to market strategy, etc.”

Dr. Gulshan Rai, Former National Cybersecurity Coordinator, Govt. of India, said, “This initiative of Ministry of Electronics & IT and DSCI will have a far-reaching constructive impact on innovation and indigenous technology creation to suit the need of the country when one looks at it from the larger perspective of entrepreneurship and national security. My congratulations for the successful launch of Grand Challenge and putting up strong problem statements that can cater to solutions in cybersecurity.”

Rama Vedashree, CEO, DSCI, said, “We are proud to partner with the Ministry of Electronics & Information Technology to conceptualize and launch the Cyber Security Grand Challenge, which endeavors to solve critical cybersecurity problems and give impetus to innovation and entrepreneurship in the Indian Cybersecurity Start-up ecosystem. We had the privilege of working with the Government and Industry to curate compelling problems statements and orchestrate a first-of-its-kind Grand Challenge.” 

Data Security Council of India (DSCI) is a premier industry body on data protection in India, set up by NASSCOM, committed to making cyberspace safe, secure and trusted by establishing best practices, standards and initiatives in cybersecurity and privacy. DSCI brings together governments and their agencies, industry sectors including IT-BPM, BFSI, Telecom, industry associations, data protection authorities and think tanks for public advocacy, thought leadership, capacity building and outreach initiatives.

TUXGUARD Vows to Strengthen IT Network Security, Joins Germany’s BISG

CynergisTek Partners with Awake Security to Boost Cybersecurity in Health Care

A Federal Association of IT Experts and Assessors eV (BISG) of Germany, has onboarded TUXGUARD in its elite list of members, with a view to strengthening the country’s IT network security. TUXGUARD’s “Made in Germany” cybersecurity solutions, and in-depth knowledge and understanding of the local, as well as international small and medium-sized businesses in the country, place them at the forefront of the German cybersecurity solution providers’ list.

Every company today knows that it is only a matter of time before it becomes a victim of a cyberattack. Therefore, having an appropriate security strategy that anchors every company—be it SMEs or larger corporations—during a cyberattack is the need of the hour. Smaller companies, however, often lack the resources to deal with this topic in detail. This is where TUXGUARD can help them out.

Uwe Hanreich, Managing Director of TUXGUARD GmbH, said, “Membership in the BISG opens up completely new ways for us to convey our IT security expert knowledge to medium-sized companies. With its large network, the BISG offers us an optimal platform for exchanging ideas with other security manufacturers or with consultants and IT service providers.”

The BISG was (formulated in Germany to bring together IT experts from different domains. Collectively, these companies share and recommend each other’s expertise, solutions and product offerings. BISG also holds IT events such as conferences, round tables, training and certification programs for its members which acts as a knowledge-sharing platform.

“Business firewalls and endpoint protection solutions are now a part of the basic equipment of every IT security concept,” says Holger Vier, board member of BISG. “The experts at TUXGUARD have many years of experience in the German cybersecurity market.”

Protected Private Information of British Citizens Exposed Online

106 million Thailand visitors

As per Wired, an unprotected AWS (Amazon Webservices) S3 database containing personal and private information of British citizens was discovered by security researchers Noam Rotem and Ran Locar of the security firm vpnMentor. It included passport scans, tax documents job applications, background checks, expense forms, scanned contracts complete with signatures, salary information, emails and more.

Researchers found no security protection on this AWS database, also known as bucket, and thus were able to see all the files stored in it. The files contained a wide range of Personally Identifiable Information (PII), including names, addresses, phone numbers, dates of birth, gender, national insurance number–in short, everything that a threat actor requires to complete identity theft, fraud, or any cyberattack targeted towards the user or against him. “It’s everything you need to steal someone’s identity, to open a bank account in their name, or a lot of other malicious things,” say researchers.

Data found in the unprotected database dates as far back as 2011, but mostly from 2014 and 2015. This data has been collected and stored from multiple HR-related consultancy companies, the majority of which have already shut shop. vpnMentor contacted Amazon about this unsecured and in the wild AWS S3 database. Amazon responded promptly to secure it and made it offline.

Researchers came across this data while working on a web-mapping project that scans for data leaks. Rotem said, “We’re scanning large parts of the internet and trying to find data that is lying around within open databases that don’t require any hacking.”

A few months back the same pair of researchers had found another unprotected database run by an American-based communications company and bulk SMS services provider, TrueDialog. The leaky database, which hosted 604 GB of data, contained around one billion entries of TrueDialog’s customers exposed private text messages, millions of account usernames and passwords, years of information on TrueDialog’s business model, conversations with its customers, and account details.

In a separate incident, the same team of researchers found another unprotected database that exposed sensitive information of around 80 million households in the U.S. The unprotected server contained personal information about the U.S. nationals, including their full names, marital status, income bracket, age, and more. The researchers also discovered coded references to some information like title, gender, marital status, homeowner status, and dwelling type.

CYFIRMA Makes a Leap for Growth with New Appointments

Leadership team

CYFIRMA, a predictive cyberthreat visibility and intelligence analytics platform company backed by Goldman Sachs and Zodius Capital, today announced key management appointments as part of its market expansion plan.

CYFIRMA has appointed Gosuke Nakae as President of Alliance Strategy and Administration, Shuhei Igarashi as President of Business Development, Koichi Saito as Vice President of Business Development, Saurabh Lal as President of Delivery and Operations, Anna Koh as Senior Vice President of Marketing and Business Enablement, and Vinod KM as Assistant Vice President of Product Engineering. All appointments take immediate effect.

Headquartered in Singapore and Tokyo, CYFIRMA is a leading Predictive Cyberthreat Visibility & Intelligence Platform company. Its cloud-based AI and ML-powered Cyber Intelligence Analytics Platform (CAP) v2.0 helps organizations proactively identify potential threats at the planning stage of cyberattacks, offers deep insights into their cyber landscape, and amplifies preparedness by keeping the organization’s cybersecurity posture up-to-date, resilient, and ready against upcoming attacks.

CYFIRMA works with many Fortune 500 companies. The company has offices and teams located in Singapore, Tokyo, and India.

CISO MAG contacted Kumar Ritesh, Chairman and CEO of CYFIRMA, to ask how these appointments will reshape the strategy of this startup.

“With the new leadership team appointment, I see CYFIRMA taking a new leap of growth and it will strengthen our ability to deliver better value to our clients, partners and shareholders,” said Kumar. “Our focus will continue to build world-class threat visibility and intelligence product, expand to new markets and integrating our product with other software and services.”

These six new senior appointments, under the leadership of Kumar Ritesh, will chart new growth in the areas of sales, marketing, service delivery, and operations. Their combined experience will see the company accelerating the development of its flagship product, Cyber Intelligence Analytics Platform (CAP v2.0), bringing innovative solutions to clients across multiple geographies, amplifying its brand and opening new markets.

Gosuke Nakae will lead the company’s alliance and channel strategy to build a strong partner ecosystem as well as overseeing corporate development efforts. Nakae comes with over 30 years’ experience managing global businesses across the ICT industry. In his prior role as President and CEO of Mitsubishi France S.A.S., he built successful alliances with cross-cultural businesses and put the company on a growth trajectory. Today, Nakae brings his executive expertise in the satellite and space, national security, and cybersecurity domains to CYFIRMA international clients.

Shuhei Igarashi is a sales and business development veteran with over two decades of solution selling experience in the IT industry. Igarashi was previously leading sales with technology giants IBM, McAfee, and Splunk. He has helped companies shape their cybersecurity strategies with his consulting expertise and will oversee client acquisition and account management in Japan.

Koichi Saito is a proven sales leader in the cybersecurity and threat intelligence domain. He brings with him over 20 years’ experience in the IT industry, holding various responsibilities across the business. Before joining CYFIRMA, Saito was the sales leader for FireEye K.K. with the remit to manage and grow large enterprise accounts in the high-tech and manufacturing industries. A proven sales maverick, Saito has held sales and business development positions with MessageLabs Japan, Symantec K.K., AMD, MCI Japan, and Nippon Information and Communication.

As President of Delivery and Operations, Saurabh Lal will oversee all service delivery and technical operations of CAP v2.0. He has over two decades of global industry experience in helping businesses improve IT operations and service delivery with extensive accolades for running Cybersecurity Operations & Delivery. He had held leadership roles with Prudential, BHP, and Nokia.

Anna Koh has been appointed Senior Vice President of Marketing and Business Enablement overseeing CYFIRMA’s branding and marketing strategy. She has helped IBM and Acclivis Technologies and Solutions define their brand and chart their digitization journeys. In a prior role, she oversaw the company’s branding and marketing efforts, contributing towards the increased valuation of the company and the ensuing merger with a global telco.

Heading Product Engineering is Vinod KM. Vinod is a senior technology and software development leader across technical management, product development, and software architecture. He brings with him 21 years’ experience helping organizations realize their business strategies by developing innovative products across banking, finance, procurement, field force automation and retail cybersecurity.

“As a digital business enabler, we have a mission to help organizations rethink cybersecurity strategy and reinvent cyber-risk management. We want to equip governments and businesses with advance threat intelligence to strengthen their organizational resilience so they can deliver successful innovation and growth. With the new leaders on-board, we are now ready to scale the business and be the cybersecurity partner of choice for every forward-thinking organization,” added Kumar.

Card Fraud Under Strict Check in Australia: AusPayNet Report

one million card data exposed

The popularity of the e-commerce industry and an exponential increase in online shopping has led to the problem of online payment frauds. However, as per a report from AusPayNet, a self-regulating Payments Industry Body, Australia’s card fraud numbers have seen a steady decline. The drop continues the trend of declining card fraud numbers observed in the data for 2018, which was released in August 2019.

The report states that:

  • Data collected over 12 months up to June 30, 2019 (FY19) showed an increase of 4.2 percent in total card spending of OZ’s amounting to $799.4 billion, whereas the overall card fraud dropped by 6.9 percent to $527.8 million.
  • The CNP fraud accounts for 86.3 percent of all card frauds issued in Australia.
  • CNP fraud dropped by 5 percent on the previous FY to $455.5 million.
  • Fraud involving lost or stolen cards fell by 16.1 percent to $43 million in FY19.
  • Card skimming fraud fell by 19.2% to $18.6 million, extending a consistent trend since chip technology was progressively rolled-out in the card system over the last decade.

This success of declining numbers was awarded to the industry’s adoption of secure technologies such as tokenization, EMV 3-D Secure, real-time monitoring and machine learning.

Andy White, CEO of AusPayNet, said, “While the reduction in fraud was encouraging, there was no room for shoppers to be complacent. Fraud involving CNP transactions remains by far the largest category of fraud. eCommerce volumes have grown rapidly, and this space has attracted criminal groups as security technology makes other types of card fraud less attractive. But that’s no reason to be complacent–fraud protection needs to happen at every level and it’s important that online shoppers also take steps. Only provide your card details on secure and trusted websites. Look for the locked (green) padlock icon and be wary of offers that look too good to be true–fraudsters count on shoppers being less careful during busy periods.”

With a view to further reduce online card fraud in Australia, AusPayNet has designed and implemented a CNP Fraud Mitigation Framework, effective July 1, 2019. The CNP Fraud Mitigation Framework is the result of extensive collaboration with the e-commerce community. Inputs were taken and implementation was done by including various stakeholders such as card issuers, retailers, merchant acquirers, card schemes, payment gateways, payment service providers, regulators and industry bodies. Key elements include targets for card issuers to reduce CNP fraud, and increased use of multi-factor authentication, including biometrics, in verifying CNP transactions.

Traditionally, Australians are not liable for fraud on their cards for payments made online and will be reimbursed if they take due care and fulfill precautionary requirements.

“We are seeing very tailored attacks targeted against very specific businesses”

Rik Fergusen, Trend Micro

Rik Ferguson is one of the biggest cybersecurity influencers in the world. He is the Vice President of Security Research at Trend Micro and has been involved in the information technology industry for over 25 years. He has witnessed the development of the cybersecurity sector over that time. He has constantly been on the lookout for how the latest infrastructure changes will impact security for both end-users and businesses. Rik has also been a Special Advisor to Europol’s European Cyber Crime Centre (EC3) and was inducted into the Infosecurity Hall of Fame in 2011. 

Rik was one of the key personalities at the Cyber Security Nordic 2019 at Messukeskus, Heslinki. In an exclusive interview with Augustin Kurian of CISO MAG, Rik spoke about the emerging threat landscape, Bot wars, corporate espionage and state-sponsored attacks, and the skill gap in cybersecurity among several other things. 

Briefly tell us a bit about what the impending threats are that are lurking in cyber space. How is the attack surface evolving?

I kind of touched on it in the presentation; criminals and attackers don’t innovate unless you force them to. And it is still too easy, far too easy, to break into an organization, to fly under the radar, to stay hidden, to steal information or steal access to resources on an ongoing basis. The average time that an attacker is in an organization before they even become aware of it is still the better part of a year–it’s like 170 days or something like that, according to the Verizon Data Breach report.

So, attack methodology isn’t going to change if the defender methodology doesn’t. There are still too many old vulnerabilities out there: operating systems, poorly configured servers, poorly configured clients, etc. So, the threats that you will continue to see on an ongoing basis are the threats that you have already been continuing to see.

A lot of the time we do see stuff being repurposed. Ransomware, for example, has been in decline for a year and a half, or two years; beginning of this year, we saw for the first time, an uptick in ransomware behavior, but it’s not targeted against individuals. Now, it’s very tailored attacks targeted against very specific businesses like government entities or healthcare providers or industrial victims.

It’s an old tool repurposed in a new way. So, that’s kind of what we must be on the lookout for. Take phishing for example. In the first half of this year, we saw a decline in the number of phishing websites that our customers were attempting to access, and obviously, we were blocking that. But we saw a significant increase in the number of those phishing websites that were Office 365 clones.

So, phishing is moving away from being a consumer-focused exercise to gathering corporate credentials. That’s what Office 365 is focused on. So, attackers are definitely at the moment, repurposing existing techniques and tools to more effectively target businesses because the profit per attack is much higher. If your victim is a business, you ask for a half a million ransom, if you’re a victim as an individual you ask for a US$50 ransom. That’s the difference.

Corporate espionage is on the rise and so is activity from state-sponsored actors. Which is the larger problem?

It’s a difficult question to answer because there is a significant crossover in attackers. It’s not very often you will see state entities subcontracting the online illegal activities to independent hackers. And that’s what I found interesting in a presentation specifically about Russia. A lot of the Russian military capability around cyber, was actually recruited directly from criminals.

And their problem is that they then expect these criminal recruits to stop being criminals while they’re now in the army, and that’s an unrealistic expectation to have. So, there is, and always has been a significant crossover between patriotic hackers and nation state employees. But I would argue that, from a victim perspective, victims of criminal attacks are far more than victims of nation sponsored attacks. It is much more numerous because the aim of a nationally aligned attack, whether it’s sponsored or not, are much more restrictive than the aims of a financially motivated attack. So, your potential victim pool is much smaller.

You have written and spoken several times about fake ransomware attacks on individuals. How can consumers safeguard themselves from such attacks?

Basically, sextortion is already a thing, and is primarily targeted at younger victims capturing footage of them that they would be ashamed of, and then threatening to publish that footage online if they don’t pay the attacker. And we have unfortunately seen people committing suicide because of those kinds of attacks. So, this is a threat with serious physical real-world consequences for individuals.

Even if the attackers don’t get what they need by spying on your computers, they resort to deepfakes to achieve that. All the attacker has to do is take the image or the likeness of that person from their social media accounts, and create a fake video using pre-existing phone footage or simply generated from nothing. Once the algorithms are capable of doing that kind of thing, you have a no way to overcome the attacker than to let the attacker extort you because the victims believe their friends aren’t going to care if it’s real or not.

One of the best ways to prevent it is through awareness. Education is one way, the more the general population is aware that this kind of fakery is a possibility the less the victim is going to feel threatened by the fact that people will believe it.

So, there should be general societal education of what those kinds of capabilities are. And like I said, as a security issue as well; we have to take into account the fact that attacks are going to evolve in this way. And we have to make sure that from a protection perspective we are capable of recognizing fakes as fakes.

How do we do that? That’s a question for product development to dig into right now. We have to, if we’re going to provide effective protection, take into account that the new threat model exists.

Another impending threat is the bot wars–machines fighting machines. With the evolution of AI and Machine Learning, bot wars are at a tremendous pace. Where do you think this new and super-dangerous attack vector is heading? And what can we do about it?

That is in the real world physical or kinetic weaponry. It’s a real concern. It doesn’t have to be machines fighting machines, it can be machines fighting people, which is even more horrific. We have to address that at an international level. We have to address that through bodies like the United Nations and that’s happening right now. The best that we can hope for is that societal acceptance or societal realization, that that kind of warfare is unacceptable. We have achieved it with other kinds of warfare, in general, the use of poison gas, the use of nuclear attacks on civilian populations. You know we have international norms in place that forbid these kinds of activities. And by and large, it’s successful. And if someone contravenes those agreements and those rules, then there are consequences. Bot wars are another thing that we need to add to that list. It must be controlled.

A major problem in the infosec industry is the skill gap. Inclusivity including gender diversity, racial diversity, and neurodiversity is usually pointed to as a leading strategy, but the problem remains. What are your ideas on fixing it?

It won’t go away, and we are going to fix it.

What we are attempting to address it, right now it is a pipeline problem, in terms of humans having enough humans in the pipeline–gender diverse, racially diverse, neurodiverse. That’s great. Definitely, that needs to be done particularly addressing those diversity requirements, but we are addressing it by saying we need enough humans in the pipeline to be able to deal with the roles that are currently vacant. ISC2 estimates that there would be lack of 1.8 million cybersecurity professionals. That’s an incredible number. But that number’s not going to go down, if we don’t address the data pipeline. There is more data being generated that needs to be dealt with from simply a security perspective, let alone anything else. We have to re-tool to be able to do the donkey work of that data. Because the amount of data is growing exponentially. So, we have to address not only the human part but also address how do we deal with that data pipeline as well.

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

Augustin traveled to Finland on invitation of Business Finland and F-Secure to attend Cyber Security Nordic 2019 at Messukeskus, Heslinki.