Home Blog Page 270

Hackers Demand US$14M in Ransom to Unlock Systems in U.S. Nursing Homes

Only 44% of Health Care Providers Meet National Standards on Cybersecurity, OpenEMR vulnerabilities

Virtual Care Provider, a technology services provider for nursing homes and acute care sites, was hit with a ransomware attack that seized access to patients’ health records. The Milwaukee-based company reported that unknown attackers injected ransomware known as “Ryuk” inside its network systems.

The company stated that hackers demanded US$14 million to restore access to its hijacked servers. Virtual Care Provider said around 110 nursing homes across the country are unable to access their patient records, use the Internet, pay employees, and order crucial medications.

According to the Chief Executive and owner of Virtual Care Karen Christianson, the incident had affected 80,000 computers and other facilities, including Internet service and email, access to patient records, client billing, phone systems, and payroll operations.

“We have employees asking when we’re going to make payroll. But right now, all we’re dealing with is getting electronic medical records back up and life-threatening situations handled first,” Karen Christianson said in an interview with KrebsOnSecurity.com.

“We’ve got some facilities where the nurses can’t get the drugs updated and the order put in so the drugs can arrive on time. In another case, we have this one small assisted living place that is just a single unit that connects to billing. And if they don’t get their billing into Medicaid by December 5, they close their doors,” Christianson added.

Ransomware attacks on healthcare organizations have become a rising concern. With sensitive information about their patients, healthcare providers have become a hot favorite for attackers.

Recently, multiple hospitals and health service providers from the U.S. and Australia were forced to shut down some of their operations after being hit by ransomware attacks. According to an official statement, the attack affected and disrupted the IT systems of the DCH Regional Medical Center, Northport Medical Center, and Fayette Medical Center from West Alabama’s Tuscaloosa, Northport, and Fayette.

The Victorian Government stated that seven hospitals and health services from south-west Victoria and Gippsland have lost access to their IT systems and went into manual operations.

The affected hospitals are turning away new patients and even canceling some surgeries. The government authorities stated that they’re working with the impacted health services and cybersecurity professionals to investigate the incident.

Hundreds of Users Impacted in Twitter and Facebook Data Breach

blockchain-based social media, Parental Consent for Minors, Iranian Facebook accounts

Facebook and Twitter admitted that hundreds of users inadvertently gave access to their personal data through third-party apps. The companies stated the affected users have been using their social media accounts to log in to certain Android applications.

The social media giants were notified about the issue by third-party security researchers, who discovered that One Audience and Mobiburn software development kits (SDK) provided access to users’ sensitive data. The exposed information included usernames, email addresses, recent tweets and posts on both the platforms.

“We recently received a report about a malicious mobile software development kit (SDK) maintained by One Audience.  We are informing you about this today because we believe we have a responsibility to inform you of incidents that may impact the safety of your personal data or Twitter account,” Twitter said in a post.

It’s said that the breach reportedly affected Android users who accessed the Giant Square and Photofy apps using their Facebook or Twitter accounts. However, there are no reports that i0S users have been impacted by the incident.

Twitter and Facebook stated that they will notify the affected users. Twitter said that it has also informed Google, Apple, and other industry partners about the malicious SDK to take further action if needed.

“We will be directly notifying people who use Twitter for Android, who may have been impacted by this issue. There is nothing for you to do at this time, but if you think you may have downloaded a malicious application from a third-party app store, we recommend you delete it immediately,” Twitter added.

In a similar security incident, Twitter exposed phone numbers and email addresses of its users who opted for two-factor authentication (2FA) protection. The company stated that user contacts had been used for targeted advertising purposes. Twitter stated that an error in its “Tailored Audiences and Partner Audiences advertising system” unintentionally used the information, provided by users, to run targeted ads.

Also, Facebook admitted a data breach involving roughly 100 third-party app developers who had improper data access. In a blog post, Facebook’s Konstantinos Papamiltiadis, Director of Platform Partnerships revealed that app developers had access to user data such as group member names and profile pictures through the Group API.

Google’s Bug Bounty: Your Chance to Win US$1.5 Million

Google

Google’s bug bounty program has always raised eyebrows with the huge bounties given to researchers for their exploits. But Google made an eye-popping announcement by declaring a US$1.5 million bug bounty reward for cracking Pixel’s Titan M secure element chip.

What is Titan M?

Titan M is an enterprise-grade security chip custom built for Google’s smartphone brand, Pixel. This chip secures the most sensitive on-device data and operating system. Titan M helps the bootloader (the program that validates and loads Android when the phone turns on)—make sure that the latest Android version is loaded. It stores the last known safe Android version and restricts attackers from moving to an older and potentially vulnerable Android version on the device. Titan M also prevents attackers’ attempts to unlock the bootloader.

The other salient features of Titan M are:

  • Lock screen and On-Device Disk Encryption protection
  • Secure Third-Party App Transactions
  • Insider Attack Resistance

Google Bug Bounty Program

As per official records, Google’s Android bug bounty reward program (better known as Android Security Rewards (ASR)  was introduced in 2015 to reward researchers who find and report security issues to help keep the Android ecosystem safe.

This program covers security vulnerabilities discovered in the latest Android versions for Pixel phones and tablets. The set of devices change over time, but as of November 1, 2019 it covers:

  • Pixel 4
  • Pixel 3a and Pixel 3a XL
  • Pixel 3 and Pixel 3 XL

Google introduced the Titan M chip for the first time in a Pixel 3 device and kept a bounty of US$ 1 million. But none could claim it. Why? Because it comes with an asterisk mark “*”.

The actual reward amount is at the discretion of the rewards committee and depends on several factors, including (but not limited to):

  • A detailed writeup describing how the exploit works.
  • The initial attack vector (i.e. remote exploitation versus local).
  • Whether the exploit is device or build-specific, or whether it works across a broad set of builds and devices.
  • The amount of user interaction required for the exploit to work.
  • Whether the user could feasibly detect that an exploit is in progress or completed.
  • How reliable the exploit is.
  • Exploit chains found on specific developer preview versions of Android are eligible for up to an additional 50 percent reward bonus.

Google is determined to work towards cybersecurity and that’s evident from the fact that in 2019 alone it has paid out over US$1.5 million in bug bounty, wherein the top reward pay-out was US$ 161,337.

Also, Google recently launched a new bug bounty program Developer Data Protection Reward Program (DDPRP) and the expansion of Google Play Security Reward Program (GPSRP), which are intended to detect and mitigate data abuse issues in Chrome plugins, Android apps, and OAuth projects.

TrueCaller Fixes Critical Flaw in its Application

Truecaller Denies Data Leak After 4.75 Mn Users’ Info Emerges on Darknet

Popular caller-identification app Truecaller recently fixed a security flaw that could expose sensitive user data, location, and system information to attackers. The flaw came to light after an India-based security researcher Ehraz Ahmed reported the issue.

The Truecaller app provides a set of features to smartphone users including call-blocking, flash-messaging, caller-identification, call-recording, and Chat & Voice services. The globally available platform is popular in India with 500 million downloads and 150 million active users.

In a video post, the researcher described how a malicious link can be injected as a profile URL to potentially target attacks on users clicking on the profile. According to Ahmed, the malicious script will get executed without user consent.

“The flaw could allow attackers to mount serious attacks on target machines, although this was not the scope of the proof of concept and has been played down by the company,” Ahmed said in a statement.

Truecaller confirmed the issue to Forbes, stating that “it was recently brought to our attention that there was a small bug in our app services which allowed the modification of one’s own profile in an unintended way. We thank the security researcher for bringing this to our notice and collaborating with us. The bug was immediately fixed.”

Truecaller thanked the researcher for reporting the vulnerability and urged all the users to update with the latest version.

“We have partnered with a community of researchers and will shortly announce a bounty program where we, as a transparent and responsible organization, will also reward researchers for their contributions,” the company said in a statement.

“Cyber security is quickly becoming an arms race”

Sean Pea, Head of Threat Analysis, Asia Pacific, Darktrace

Sean Pea, Head of Threat Analysis, Asia Pacific, Darktrace joined the company in 2017 after serving DSO National Laboratories, where he worked as a computer security researcher. Darktrace is the world’s leading cyber AI company and the creator of Autonomous Response technology. Its self-learning AI is modeled on the human immune system and used by over 3,000 organizations to protect against threats to the cloud, email, IoT, networks and industrial systems. This includes insider threat, industrial espionage, IoT compromises, zero-day malware, data loss, supply chain risk and long-term infrastructure vulnerabilities.

The company has over 1,000 employees, 40 offices and its headquarters are in San Francisco and Cambridge, UK. Every 3 seconds, Darktrace AI fights back against a cyber-threat, preventing it from causing damage.

Please tell us about the cybersecurity practices Darktrace follows.

As a leading cyber AI company, Darktrace naturally takes cyber defense and Information Security (IS) practices seriously. There are stringent policies put into place, along with rigorous employee training programs and regular internal security audits to ensure compliance with these policies.

In terms of certification, Darktrace is ISO 27001 certified and maintains the UK’s Cyber Essentials certification. The ISO 27001 certification is one of the most well-known and significant IS accreditations and is globally respected. In order to achieve and retain it, we are audited by an independent third-party against the standard. In our case, this is by BSI (who themselves have an accreditation saying they are competent to do so, from both the UK and US awarding bodies). The audits take multiple on-site days per year, and this level of inspection is why the certification is such a strong statement of our own IS management. 

Do you think the current cybersecurity practices would be relevant in the next two years?

Globally, the average cost of a data breach is US$3.92 million in 2019, with the average time taken to identify and contain a breach standing at 279 days – and these figures continue to rise year-on-year.

Beyond simple data theft, recent data breaches have managed to influence our trust in public institutions, and even our energy grids face the threat of cyber-attack. This troubling state of affairs is the product of several fundamental weaknesses with the traditional approach to cyber defense, which relies on rules and signatures to detect threats of the past, at a time when criminals launch never-before-seen attacks on a daily basis. Moreover, modern strains of malware strike at machine speed, meaning that even when legacy security tools do successfully catch a threat, organizations often cannot respond on time. Cybersecurity is quickly becoming an arms race – machines fighting machines on the battleground of corporate networks.

If we continue to rely on legacy cybersecurity practices to defend against modern threats, the reality is that these practices would not be relevant in the next two years. The advanced attacker will always find his way in, and you can’t rely on yesterday’s attack to predict tomorrow’s threat.

Be it today or two years from now, defense strategies must prepare for the threat that gets in – or the insider turned bad. And crucially, it must constantly keep up with the attackers’ changing tactics. Artificial intelligence (AI) is now the fundamental ally to corporations and governments in the fight against the threats that no one can predict–the threat that gets through perimeter defenses, and the threat that is already inside. 

When it comes to cloud security, what are the major challenges organizations face?

As the market increasingly moves to the next wave of computing models, over 90 percent of organizations are expected to adopt hybrid infrastructures by 2020. This move to the cloud brings undeniable benefits for most organizations–from start-ups looking for minimal up-front costs to large organizations striving to boost efficiency, scale-on-demand, and to benefit from constant availability of services and increased agility.

Alongside this growth, the challenge of securing critical data in the cloud has taken on a new dimension. Organizations are adopting cloud infrastructures that expand and evolve as needed, but configuring firewalls and other endpoint protections to remain properly positioned can be a daunting challenge. These conventional security tools are designed to defend the digital perimeter—an antiquated strategy given today’s borderless networks.

Internal servers are so commonly affected by malware infections or insider threats that there exists a common misconception that the data stored within the cloud is somehow more secure than the data resting on company file servers. However, this is not necessarily the case – the information stored on cloud infrastructure may be just as unsafe as any other corporate data store.

Moreover, modern developers now have the ability to spin up a cloud instance in minutes, often without having to consult their firm’s security team. As a consequence, the overwhelming majority of organizations lack visibility over their own cloud environments.

Much of this risk comes from the misconception of the network position of cloud servers themselves. Although rented out for use by the company and used every day as part of fundamental business purposes, connections to cloud servers cross the perimeter of the network and traverse the public internet. This means that data uploaded to and from the cloud –if unencrypted–is a prime target for man-in-the-middle attacks, carried out by opportunistic actors hoping to sniff usernames, passwords, and other sensitive details that they could then leverage for direct corporate data theft.

The reality is that while organizations can outsource their IT services, they cannot outsource their security function altogether. In fact, protecting the cloud comes with its own challenges, with most of the existing native security controls and third-party security solutions suffering from significant limitations. 

What are the questions organizations need to ask while selecting a cloud security service provider?

The questions to ask are:

  1. How compatible is the solution across different cloud platforms?

Organizations are adopting cloud infrastructures that expand and evolve as needed, and if their existing cloud provider is not able to service their needs, these organizations will look to move their data and information to another provider. In fact, many organizations rely on several cloud providers at once, so effective security solutions must be able to work equally across these multi-cloud environments.

  1. Is it cloud-native or does it require a physical appliance to be installed on-premise?

More and more organizations are looking to move to the cloud, either as part of a hybrid deployment or fully to the cloud. With this increased agility, organizations will need to consider if the cloud security service provider is able to fully work in the cloud, or would require a physical appliance to be installed on-premise.

For organizations looking to fully move to the cloud however, the latter option will pose a challenge since the solution is not fully compatible with a full cloud deployment.

  1. Does the security tool rely on logs or on raw network traffic?

The reality is that security tools that use log-based analytics are rarely robust and unified enough to provide sufficient coverage – both because they continue to encourage a ‘stove-pipe’ approach to security, and because they rely on rules, signatures, or prior assumptions and therefore fail to detect novel threats and subtle insiders before they have time to escalate into a crisis.

  1. Will the organization have complete visibility over their cloud environment?

Human error on the customer end is inevitable. Today’s threat-actors are increasingly gaining access to cloud services through the front door, necessitating a fundamentally different security approach that can detect when credentialed users behave — even ever so slightly — out of character.

Too often, subtle anomalies are obscured by the cloud or lost in the noise of the network. Traditional security tools tend to have limited visibility of cloud activity, and even then, they only look for known threats. This points to the critical need for an AI solution capable of identifying never-seen-before threats across cloud environments. 

What are the key elements in managing and automating security across multiple clouds and applications?

There is no silver bullet when it comes to cyber defense — and that goes double for the cloud. Motivated attackers will inevitably find a way inside the nebulous perimeters of IaaS, PaaS and SaaS environments, whether via insider knowledge, critical misconfigurations, personalized phishing emails, or mechanisms that have yet to be seen. The path forward, then, is to use AI to understand how users behave within those perimeter walls, an understanding that shines a light on the subtle behavioral shifts indicative of a threat.

In order to reduce risk and identify atypical or suspicious behavior, full visibility of all cloud services is critical, as the usage of cloud services can create dangerous blind spots and makes it harder to spot subtle threats that circumvent traditional signature-based tools.

This interview first appeared in the July 2019 issue of CISO MAG. Download and read the issue here.

Ransomware Attack: French Hospital Reverts to Pen and Paper

Ransomware attack on Nunavut, Emotet Cobalt Strike

Rouen University Hospital Center (CHU) in northern France suffered a major ransomware attack. Nearly 6,000 hospital computers were infected forcing the staff to resort to pen and paper usage for data entry and daily operations.

CHU is spread over five sites, consisting of more than 8,000 employees and nearly 1,300 beds. The entire chain and all its departments operate on networks and applications designed specifically for healthcare providers. On 15 November, around 19:00 hours, a crypto-ransomware virus infected the entire chain of networks. This “made access to most business applications inaccessible, but also infected some of the workstations,” said head of communications, Remi Heym in an official statement.

He further continued, “Many services operated in degraded mode and hospital staff were confronted with disruptions, particularly in regard to computerized prescriptions, reports or admissions management, which had to be transmitted via telephone or paper.” The laboratory and the radiology department also faced a lot of inconvenience. “The doctors only prescribed the necessary blood tests. And the staff was asked to pick up the paper results manually,” said an emergency department nurse.

Heym also said, “No medical or personal data have gone missing as a result of the attack. We have not received any ransom demand, and neither are we going to pay any ransom in return for restoration.”

France’s national cyber-crime agency, ANSSI, helped limit the scale of the outbreak, as per reports from France’s Le Monde newspaper. Based on the critical importance of various units in the hospital, ANSSI began the network and system restoration process. The paper reported that French hospitals are rare targets for ransomware attacks. But hospitals and healthcare industry have become a favorite target of cyber-attackers off late because the patient data they retrieve is highly valuable on the dark web.

In a recent example, Multiple hospitals and health service providers from the U.S. and Australia were forced to shut down some of their operations after being hit by a chain of ransomware attacks. According to an official statement, the attack affected and disrupted the IT systems of the DCH Regional Medical Center, Northport Medical Center, and Fayette Medical Center from West Alabama’s Tuscaloosa, Northport, and Fayette. The affected hospitals had to turn away new patients and also cancel some surgeries.

One Plus Confirms Data Breach, Sends Security Notification

OnePlus

The security team at One Plus confirmed a data breach that exposed sensitive details from certain customers’ orders which included their contact numbers, names and addresses.

As per the FAQ page on the  One Plus website, the data breach took place last week due to an existing vulnerability on its website. One Plus stressed that hackers found this loophole and exploited it to gain only the order details of certain customers and not the confidential payment information and account passwords. One Plus said, “While monitoring our systems, our security team discovered that some of our users’ order information was accessed by an unauthorized party. We can confirm that all payment information, passwords and accounts are safe, but the name, contact number, email and shipping address in certain orders may have been exposed.”

One Plus also clarified that all the users were not affected by this data breach. The affected users have been sent a security notification via email that explains the possible cause of breach and respective remedial measures taken. It has asked the affected customers to stay extra vigilant as the leaked information could be used for malicious activities like phishing, identity theft, spamming, etc.

As part of beefing-up the security, One Plus announced, “We are continually upgrading our security program — we are partnering with a world-renowned security platform next month and will launch an official bug bounty program by the end of December.”

This is not the first data breach incidence of One Plus. In January last year, OnePlus disclosed that up to 40,000 customers were affected by a data breach that forced the smartphone maker to shut down credit card payments on its online store.

It’s not just the One Plus vendors website that seems to be vulnerable though. In May this year, One Plus launched its One Plus 7 series with a lot of fanfare. Days after the phone was launched, someone managed to hack the fingerprint scanner using a simple dummy gum fingerprint. This method is one of the oldest fingerprint hacking techniques and yet went unchecked from One Plus.

Elasticsearch Server Exposed 1.2 Billion People Data

biggest data breaches in India,data breach, Aptoide Android App Admits Data Breach, Suspends Sign-Up Option Temporarily, Panasonic

Security researchers discovered an open Elasticsearch server that contains unique data records of around 1.2 billion users. According to the security analysts Bob Diachenko and Vinny Troia, the server holds more than 4 terabytes of data, without password protection or authentication.

The exposed data included names, email addresses, phone numbers, LinkedIn, and Facebook profile information. It’s believed that the exposed data appear to have originated from two different data enrichment companies namely People Data Labs (PDL) and OxyData.Io (OXY).

“The data discovered on the open Elasticsearch server was almost a complete match to the data being returned by the People Data Labs API. The only difference being the data returned by the PDL also contained education histories. There was no education information in any of the data downloaded from the server. Everything else was the same, including accounts with multiple email addresses and multiple phone numbers,” the researchers said in a statement.

“Analysis of the ’Oxy‘ database revealed an almost complete scrape of LinkedIn data, including recruiter information. Upon contacting OxyData, I was also informed that the server did not belong to them. Oxy was not willing to give me access to their API to test/compare profiles, but they were nice enough to send me a copy of my own record for analysis. The data they sent contained mostly scraped LinkedIn profiles and appears to be a match for the data,” the statement added.

Multiple security incidents were reported on Elasticsearch servers earlier. Recently, almost everyone in Ecuador became a victim of a massive data breach that exposed the personal information of over 20 million individuals, including the country’s president and WikiLeaks founder Julian Assange, who was granted asylum by Ecuador in 2012.

Security firm vpnMentor discovered the breach on a Miami-based Elasticsearch server owned by an Ecuadorian company Novaestrat. It’s said that the exposed data appears to have come from various sources, including the Ecuadorian national bank, Ecuadorian government registries, and an automotive association called Aeade.

Also, an unprotected Elasticsearch database exposed around 198 million personal records of car buyers’ online. Jeremiah Fowler, a security researcher at Security Discovery, stated that he discovered a database, that contained 413 GB of data, that was left online without any password protection.

Check Point Software Technologies Has New IoT Cybersecurity Solution

IoT attacks

Check Point Software Technologies, a leading provider of cybersecurity solutions globally, today announces a new IoT cybersecurity technology.  Check Point claims to be the first company to provide a consolidated security solution that hardens and protects the firmware of IoT devices and makes them secure against the most sophisticated attacks. The technology is provided through the acquisition of Cymplify, a startup based in Tel Aviv.  The new technology will be integrated into Check Point’s Infinity architecture.

The proliferation of Internet-of-things (IoT) devices in Consumer, Enterprise, Industrial and Healthcare organizations, and their inherent security weaknesses, have created a security blind spot where cybercriminals launch 5th  and 6th  generation of cyber-attacks to breach devices (IP camera surveillance), manipulate their operation (medical device infiltration) or even take over critical infrastructure (manufacturing plant) to generate colossal damage.

With the technology, it is now possible to take an IP camera, a Smart TV, an elevator controller or a medical device such as an infusion pump, and in a rapid manner, harden and protect it against advanced zero-day attacks.

“Today’s announcement represents our continuous effort to provide the best cybersecurity on all digital platforms” said Dr. Dorit Dor, Check Point’s VP of Products. “The 5th and 6th generations of cyber threats are leveraging the growing usage of new and developing platforms, including IoT devices which require extending cybersecurity solutions capabilities. Incorporating Cymplify into Check Point’s Infinity architecture will strengthen our ability to reduce our customers’ exposure to the IoT cyber risk, and proactively tackle IoT related threats and vulnerabilities without disrupting critical operations”.

 About Check Point Software Technologies

Check Point Software Technologies Ltd. is a leading provider of cybersecurity solutions to governments and corporate enterprises globally.  Check Point’s solutions protect customers from 5th generation cyber-attacks with an industry-leading catch rate of malware, ransomware, and advanced targeted threats. Check Point offers a multilevel security architecture, “Infinity Total Protection with Gen V advanced threat prevention”, this combined product architecture defends an enterprises’ cloud, network, and mobile devices. Check Point provides the most comprehensive and intuitive one point of control security management system. Check Point protects over 100,000 organizations of all sizes. 

About Cymplify

Cymplify based in Tel Aviv, Israel, developed a cutting-edge firmware analysis engine, combined with an on-device software security hardening module for IoT Security. Cymplify provides highly detailed cybersecurity posture reports, which are yielded to an on-device agent. This optimizes the agent’s protection controls, and provides a tailor-made, embedded security suite for every device, protecting from known vulnerabilities and zero-day exploits.

EC-Council’s CISO MAG to host Nigeria Cybersecurity Confluence

Nigeria Cyber Security Confluence

Nigeria is one among the few countries in the MENA region that is marching ahead in the space of ICT and is set to draw comparisons to its European counterparts with respect to technological innovations. Several initiatives taken by the Government and the Ministry of Communications Technology validate the fact that Nigeria will soon see a larger share of the Global Digital Economy. The rise of Nigerian technology startups reverberates across the world. It is also an established fact that the nation is among the countries that are geared toward closing the technological divide between Africa and Europe.

Addressing this trend, EC-Council’s CISO MAG is set to host the Nigeria Cyber Security Confluence on November 28, 2019, at Hotel Lilygate in Lagos, Nigeria. The prestigious event is endorsed by the National Information Technology Development Agency (NITDA).

While there have been several advancements in the space of innovation, Nigeria was also plagued by several high-profile privacy and cybersecurity breaches within and outside the nation. The companies based out of Nigeria were also not immune to the spree of cyber-attacks and data breaches that marred the world. And like the rest of the world, which continues to be beleaguered by the lack of a cybersecurity talent pool, Nigeria is also facing a similar predicament. Today, information technology leaders are pressed with the herculean task of being constantly vigilant to secure critical business data. It has now become imperative for organizations to devise and implement the right cybersecurity framework to address the key security challenges in an ever-evolving digital business landscape.

The Nigeria Cyber Security Confluence will harness some of the best minds of Nigeria to deliver realistic insights on how to redefine security frameworks and efficiently mitigate risks while evaluating business strategy and security.

The confluence will set the stage for over 25 information security experts from across the region to share their views on some burning issues within today’s digital business ecosystem.

The event would be graced by Prasanna Kumar Burri, Group Chief Information Officer, Dangote Group; Dr. Dimie Wariowei, Ag. Director of Cyber Security Department, NITDA; Ogunkoya Taiwo Olufemi, Head of IT (Lagos), Central Bank of Nigeria; Bharat Soni, Chief Information Security Officer, Guaranty Trust Bank; Daniel Adaramola, Chief Information Security, Officer (CISO), Unity Bank Plc; and Steve Isitua Obiago, Group Head – Information Technology, Chicason Group among several other esteemed guests.

The confluence would also witness a slew of panel discussions, technical rounds and Keynotes. The event is sponsored by Cyfirma (Associate Partner), eProcess Consulting (Exhibit Partner), ISSAN and CSEAN (Supporting Association) and EC-Council University (Academic Partner).

The Confluence will pave the way for attendees to attain a refreshing perspective on the latest technological advancements within the gambit of cybersecurity through a series of focused discourses and interactive discussions.