Home Blog Page 299

When more data means less noise

Nearly Half of Global Consumers Affected by Data Breaches

Contributed By Oren Yunger, Investor at GGV Capital, and Omer Singer, Senior Director of Security at Snowflake

For every hour that security teams spend triaging alerts, how many minutes do they spend applying their cybersecurity expertise? In our experience, it’s only a small fraction of the time. Why such a ratio? The complexity of their environment requires analysts to rely on intimate familiarity with the organization to determine whether an alert represents an actual breach. In this article, we’ll share how data-driven security teams are breaking down data silos, improving alerts telemetry and enjoying a 90% reduction of false positive alerts.

Most security professionals are probably familiar with Target’s classic example of alert triage failure. In 2013, Target’s Security Operations Center disregarded a generic alert that could have provided early warning of its massive data breach. Some observers might call out the SOC’s actions as negligent. But that would not be taking into account the challenge of dealing with thousands or millions of daily alerts in a complex and dynamic environment like that of Target.

While this challenge is well recognized, the prevailing approaches each suffer from major drawbacks.

Approach Description Drawbacks
Hire more people As data volumes increase, throw more bodies at the problem.  Companies hire more analysts and gatekeepers to sift through false positives. Many consider the skills shortage as the top challenge in cybersecurity. This approach raises questions about working harder vs. working smarter.
Limit data scope Drowning in alerts, security organizations avoid adding additional data sets. Security teams typically have a long wishlist of data sources that are blind spots “for now”. Missed opportunities for effective threat detection and response. Might miss the one “slip up” that would have given the attackers away.
Artificial Intelligence Machine learning to the rescue, analyst robots will do the basic triage and correlation automatically. Automated security analytics are not yet producing high fidelity, actionable results. Solutions tend to be limited in scope and user experience, with high levels of false positives and negatives.

Security engineers and vendors should consider a fourth approach – adding more data into the mix. While too much data seemed to be a part of the problem, it turns out that more data can reduce noise for security teams that join together diverse data sets.

Consider a situation where an AWS user terminates ten Linux servers. A typical threat detection solution may alert on this anomaly as a possible indication of compromise, so that an analyst or automated playbook may disable the user and prevent further destruction. Triage is required before a decision can be made because there are a few possible explanations with very different outcomes.

One possible explanation is that a DevOps engineer was cleaning up old test servers that haven’t been used in a year. Alternatively, the same activity might be a compromised service account being hijacked to bring down core business servers during peak hours.

The correct triage depends on the context – there is a big difference between a DevOps engineer, who is a trusted privileged user, operating from the office with a company managed device, authenticated through Okta, as opposed to a recently terminated IT admin who’s logging in from Starbucks.

Understanding these differences makes up most of the time that people spend on alert triage. Automatically differentiating between those two scenarios requires additional data beyond the activity logs. The additional data must provide context to the decision making, changing the logic from a single dimension (“what happened”) to multiple dimensions, which include user context (“who is this user”) and asset context (“what is this system”).

As the field of security analytics matures, contextual information is increasingly applied to the alert logic. Multi-dimensional detection logic can avoid raising alerts that would be disregarded by analysts. Even better, breaches that would otherwise be missed can be surfaced to security teams in time.

For example, resources in AWS may be tagged by role: production, sandbox, etc. While AWS CloudTrail activity logs do not include these tags, detection logic that can access stored instance configuration data can avoid alerts for sandbox resources and elevate severity on production ones. Another application for context can be HR data – even routine activity by someone that’s been recently fired or given notice of termination should set off alarm bells.

The catch? The correlations described above require analyzing data that is not found in most organizations’ SIEM solutions or security data lakes. As such, security teams looking to cut noise and improve detection capabilities through better security analytics need to start by getting the data into a single, queryable location. For many of these data sources, that means reaching across the organization to teams that have never before thought of their data as “security data”.

Examples of data sources that can enrich context and improve alert fidelity include:

  • Human Resources (HR) records with data on employee termination
  • User directory records with data on employee team affiliation
  • Endpoint activity logs describing what was running on the laptop of an admin while their user was making changes to the cloud environment
  • Email activity logs indicating possible phishing prior to unusual user activity
  • Vulnerability management findings for at-risk servers
  • AWS tag data linking resources to environments and data classifications

Unfortunately, not all of this information is readily interconnected and accessible for security teams today. Let’s dive into what analytics stack is available for organizations that are looking to tap into the potential of contextual data for improving their security analytics. Some threat detection solutions are optimized for search rather than joining myriad datasets. Traditional SIEM solutions, such as HP’s ArcSight, support correlation along a single dimension but suffer from performance limitations on joins and actually warn users against going beyond very limited data joining. These limitations prevent the needed contextual enrichment. For that purpose, modern data warehouses are increasingly becoming the platform for multi-dimensional threat detection and response, the kind of “connecting the dots” that frees up analysts and catches intrusions that would have otherwise been missed.

Not all organizations will be able to go beyond aggregating data to their data warehouse. For more advanced threat detection and mitigation capabilities, emerging vendors combine existing datasets to provide actionable insights. A new breed of security startups is focusing on effective analytics instead of adding more sensors. Customers should ask security vendors to demonstrate that they are able to combine multiple datasets to see the full picture and achieve high-fidelity results.

Even with access to a modern data warehouse, many security teams may not be able to create the analytics and correlation needed to take advantage of the technology. There is a great amount of knowledge siloed across different organizations. This is a great opportunity for open source collaboration to lower the barriers and improve security teams telemetry. In the area of data connectors, open source can be used to standardize how event logs, asset inventory and configuration data is collected from the relatively short list of commonly used cloud-based sources. For connecting the dots among the same common sources, open source detection logic can be written, shared, and maintained by the community. The fact that JSON and SQL are standard across data sources and analytics systems means that rules can be vendor agnostic more than ever before.

To conclude, we believe that with a modern approach to data, security teams can move from a “more data equals more noise” paradigm to one where “more data equals more context and less noise”. Join this shift by initiating conversations within the organization to collect more internally available data as well as data from external third-parties. As customers, ask vendors to collect more contextual data and to use it to reduce false positives. Let’s encourage collaboration and knowledge sharing with like-minded security teams, and make our industry a less noisy place to do good security.

The opinions expressed in this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Cybersecurity startup Trinity Cyber raises $23 million

Start up funding

Cybersecurity startup Trinity Cyber recently secured $23 million in funding from top institutional investors led by Intel Capital. Along with the funding, the company also announced that former White House Cyber Chief and Homeland Security Advisor Thomas P. Bossert has joined its management team.

Founded in 2016 by security veterans Steve Ryan and Marie O’Neill, Trinity Cyber provides proactive, adaptive, and invisible military-grade cybersecurity services to stop adversary attacks. The company claims that its technology intercepts and control cyberattacks using stealth interception of external threats before they reach a customer’s network. Trinity Cyber also claimed that its patent-pending technology Proactive Threat Interference stops attacks before they reach the target’s internal networks.

“This investment by Intel Capital and other strategic backers is significant,” said Steve Ryan, the CEO of Trinity Cyber. “I co-founded Trinity Cyber to transform the way the world addresses the cyber problem. No one is doing what Trinity Cyber is doing. No one else can. We make the adversary fail, and we feel this strategic support validates the elegance of our solution.”

“As cyberattacks become more sophisticated, technology to counter them needs to stay one step ahead,” said Wendell Brooks, Senior Vice President of Intel Corporation and President of Intel Capital. “As the threat landscape continues to grow, so does the opportunity to provide cutting edge technology to protect a company’s valuable data. We are excited about being part of Trinity Cyber’s innovative commitment to helping companies stay secure.”

“The trend in global cyber-attacks has been going in the wrong direction for some time, and American businesses are paying the price. It’s time we meet this problem with a truly preventive solution,” said Bossert. “Trinity Cyber provides a high calibre solution to U.S. businesses that is capable of defeating nation-state level attacks and long overdue.”

Cloud computing risks are on rise: Report

Uncertain Data Sharing Practices Keep Educational Organizations at Risk: Research

Cybersecurity management platform Skybox Security stated that vulnerabilities in the cloud containers are increasing at a rapid pace. The report named Vulnerability and Threat Trends, which analyzed the vulnerabilities, exploits, and threats over the first half of 2019, stated that cyber risks in cloud container software have increased by 46 percent in the first half of 2019 compared to 2018, the Forbes reported.

In the report, Skybox highlighted a container vulnerability which was discovered earlier this year, known as CVE-2019-5736, that allowed a malicious actor to allegedly gain administrative privileges and break into the physical server.

“Cloud technology and adoption has obviously skyrocketed, so it’s no surprise that vulnerabilities within cloud technology will increase,” said Skybox Director of Threat Intelligence Marina Kidron. “What is concerning, though, is that as these are published, the race is on for attackers to develop an exploit because launching a successful attack on a container could have much broader consequences. Compared to other technology, containers can be more numerous and quickly replicated. The attack footprint could expand rapidly, and a number of victims may be extremely high.”

Cloud computing ranks as the top risk concern for executives in risk, audit, finance and compliance, according to the survey by Gartner, Inc. While cloud computing presents organizations with novel opportunities, a number of new risks — including cybersecurity disclosure and General Data Protection Regulation (GDPR) compliance — make cloud solutions susceptible to unexpected security threats.

In Gartner’s quarterly Emerging Risks Report, 110 senior executives in risk, audit, finance and compliance at large global organizations identified cloud computing as the top concern for the second consecutive quarter. Additional information security risks, such as cybersecurity disclosure and GDPR compliance, ranked among the top five concerns of the executives surveyed.

The top two fast-moving, high-impact risks — those which have the ability to cripple an organization quickly — are also related to information security threats. Social engineering and GDPR compliance were cited as most likely to cause the greatest enterprise damage if not adequately addressed by risk management leaders, according to Gartner. However, only 18 percent of the cross-functional executives surveyed currently considered social engineering to be a significant enterprise risk.

How to prevent new cyberthreats with continuous patching?

Cybersecurity

Contributed by Ryan Riggs, VP of Cloud Services at ProKarma  

Rogue In-Flight Data Load (RIDL), ZombieLoad and Fallout are among the new supervillains of cybersecurity. More widely known as Microarchitectural Data Sampling (MDS) attacks, they compromise Intel processors at the microarchitecture level and skim sensitive data from users.

Understandably, the ramifications are enormous because Intel is the largest semiconductor company in the world and these side-channel attacks affect every chip made since 2011. One more piece of bad news: These supervillains can also compromise public clouds. Information leaks like passwords and credit card numbers from individual users of public clouds may have already happened with no trace of the security lapse.

Intel, Apple, Google, Amazon and others have pushed out operating system patches to counteract MDS attacks, but the only guaranteed way to prevent an MDS attack is to disable Intel’s Hyper-Threading Technology, which could result in a 25 to 35% drop in performance. While Google preemptively shut down hyper-threading on its Chromebooks, most other companies’ patches only upgraded their security parameters. Cyber threats like MDS attacks – which could result in massive data breaches of public clouds, where networked computers transfer and share data between millions of users — will become increasingly prevalent as hackers develop more sophisticated tools to tap into a richer tapestry of data.

One viable long-term solution is to use continuous, near real-time patches and microcode updates to combat this ever-evolving threat. Although continuous patching requires sustained effort and can frustrate end users who don’t want to have to reboot their computers, these barriers pale in significance when considered alongside the likelihood of a data breach that can cost millions and degrade customer confidence.

To achieve near real-time patching, organizations will need to take a different approach to updates. Developing a unique approach to systems, audit and support will enable greater agility and time-to-market for releases.

Design to tolerate outages

While designing systems and platforms for failure may strike IT folks as risky, it is far less risky than the consequences of a breach. Near real-time patching can be well managed with today’s centralized management and monitoring tools. As with a ship taking on water, it’s essential to seal off the compromised sections while plugging the leak. When systems and platforms are designed in such a way that outages are compartmentalized, they can continue to operate optimally when an outage happens. Solutions designed in this way enable automatic updates at a much higher frequency. It’s still possible to utilize a more traditional approach to testing updates, but it gets moved to a subset of the production infrastructure, and any issues are resolved before a wider rollout of patching.

Keep your eye on the ball

Successful implementation of continuous patching requires appropriate levels of observation. Consider the following minimum areas of coverage before automating patch rollout:

  • Service availability: Measure of a system’s performance to deliver when demanded
  • Application functionality: The set of functions or capabilities associated with computer software
  • System and application errors: Occurs when an operating system halts, because it can’t operate safely
  • Application performance: The performance and availability of software applications

By establishing baselines for each of these areas and creating an infrastructure that will sound the alarm when a given parameter exceeds its threshold, updates and other changes can be implemented more rapidly and with a reduced risk of issues.

Up-level your IT support

IT departments need regular processes to identify and manage the risk of new vulnerabilities. My cybersecurity team evaluates Common Vulnerabilities and Exposures (CVEs) for our operating systems, network devices, application software and embedded devices daily. With processes in place to escalate issues that impact the environments, we ensure awareness and timely response. Thanks to automated patching, we’ve reduced the number of escalations required by more than 90%.

Consider future risks

While public and private clouds often steal the limelight when it comes to MDS attacks, don’t overlook the impact on Internet of Things (IoT) devices. Intel chips power many smart devices and shutting down their hyper-threading to prevent an MDS attack isn’t an option. The 25 to 35% hit to performance isn’t feasible for IoT systems that are already running on modest computing power due to cost considerations and power requirements. With 75 billion IoT devices expected to be on the market by 2025, the next big hack could come via your Roomba or integrated manufacturing plant. Remaining vigilant with near real-time patching and microcode updates will need to be the norm to prevent actual harm.

The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Data breach exposes personal information of 2,500 LAPD officers

LAPD

The officers at the Los Angeles Police Department (LAPD) are the latest victims of a data breach that exposed the personal information of about 2,500 officers and 17,500 officer applicants. The exposed information included names, date of birth, employee serial numbers, email addresses, and passwords, the NBCLosAngeles reported.

According to an official statement, a suspected hacker emailed the LAPD authorities and stated about compromising officers’ personal information. The Los Angeles Police Protective League urged the victims to monitor their financial accounts, credit reports, and also asked to file a complaint with the Federal Trade Commission.

“Data security is paramount at the Los Angeles Police Department, and we are committed to protecting the privacy of anyone who is associated with our agency,” the Protective League said in a statement. “We also call upon the city to provide the necessary resources and assistance to any impacted officer who may become the victim of identity theft as a result of this negligence, so that they may restore their credit and/or financial standing.”

“We are investigating a data event that was discovered on July 25, and involved limited information about City of Los Angeles job applicants in a database that is no longer used by the Personnel Department. We take the protection of personal data very seriously, and the City has informed the individuals who may have been affected. The City’s Information Technology Agency has added additional layers of security to guard against future events of this kind,” said Eric Garcetti, the Office of Mayor.

Earlier, a security researcher from technology company Nuix revealed that police body cameras are easy to hack and manipulate. Speaking at the DEFCON hacker conference in Las Vegas, cybersecurity expert Josh Mitchell demonstrated how to manipulate a footage from police body cams.

The researcher used Vievu, Patrol Eyes, Fire Cam, Digital Ally, and CeeSc cameras to showcase the hack program. The hacking process included deleting or altering footage or amending crucial metadata, including where and when the footage was shot. The researcher also stated that it could help the bad actors to track the location of police officers.

The researcher also suggested various prevention mechanisms like digitally signing all evidentiary information and device firmware, randomizing all SSID and MAC information, and keeping software up-to-date in order to mitigate the potential vulnerabilities.

Louisiana declares state of emergency due to ransomware attack

Louisiana

John Bel Edwards, Governor of Louisiana, has issued a state of emergency after a wave of ransomware attacks hits school districts. According to an official statement, the incident affected school systems in Sabine, Morehouse, and Ouachita parishes in North Louisiana. The attack infected the school’s computer and network systems with ransomware. The Emergency Declaration allows Louisiana’s cybersecurity experts to assist local governments in securing their networks systems.

“On Wednesday, July 24, Gov. John Bel Edwards issued a statewide Emergency Declaration in response to an ongoing cybersecurity incident that is affecting several local government agencies. The declaration makes available state resources and allows for assistance from cybersecurity experts from the Louisiana National Guard, Louisiana State Police, the Office of Technology Services and others to assist local governments in responding to and preventing future data loss,” stated a press release by the Louisiana Office of the Governor.

“The state was made aware of a malware attack on a few north Louisiana school systems and we have been coordinating a response ever since,” Gov. Edwards said. “This is exactly why we established the Cyber Security Commission, focused on preparing for, responding to and preventing cybersecurity attacks, and we are well-positioned to assist local governments as they battle this current threat.”

Earlier, San Diego Unified School District reported a data breach that affected more than 500,000 students and staff members. According to the official statement, a phishing scam led to unauthorized access to the staff’s log-in information, including the network services and students’ database.

The security officials at the school district stated they discovered the breach in October 2018. It’s believed that the incident occurred between January 2018 and November 2018. The school district declared the compromised students’ information included social security numbers, names, date of birth, mailing address, home address, attendance records, ID numbers, and phone numbers. Some staff members’ information like payroll, deduction information, tax information, direct deposit financial institution name, account number, salary, and leave information was also compromised.

Debunking five myths in cloud security

Cloud Security, 80% of Organizations Suffered a Cloud Data Breach in the Past 18 Months

While there are several companies that are jumping on the cloud bandwagon, a lot of businesses are shying away from it as well. There are several myths due to which many companies think it is better to have data stored on-premises than over the cloud. We here take a look at five myths that surround cloud and cloud security while busting them.

1. On-premise security is better than cloud security

This is by far one of the most common myths about cloud security. Several companies still feel that on-premises data center and security is better than cloud security. But on the contrary, there are far fewer breaches on a public cloud while the breaches on on-premises overpower it on a gargantuan scale. Often, it is the glitches and configuration errors that lead to a debacle around the security of cloud buckets. Cloud is inherently safe by design. A recent survey from the Cloud Security Alliance showed that nearly 22 percent of respondents linked a data breach due to compromised credentials. One key area is to focus on Identity and Access Management (IAM) policy for cloud apps.

2. Accessing data in cloud is relatively easier 

In simple words, it isn’t. Several companies are moving toward cloud and major public cloud offerings have over time being sprucing up their security to an extent that having such defenses for small enterprises are a difficult and an expensive affair. Even with AWS buckets, the security teams from Amazon apply security policies for the entire cluster of containers by providing security to each pod. Even when you are trying to communicate or troubleshoot with the pod, the insight will stop traffic between the host and the cluster. There are reasons why AWS is the behemoth in the space, it is one among the most reliable ones out there. All you need to do is check all the boxes for any configurational glitches.

3. Cloud witnesses more breaches

This is another major myth. Like we have established above, the number of attacks on public cloud offerings are far less than the number of attacks companies and enterprises handle from several other vectors. Often times, cloud security deploys several firewalls and layers on both external and internal networks. The external layers protect the enterprises from threats like malware while the internal security layers prevent errors from the consumer level. There is also a belief among several cybersecurity leaders of large enterprises that storing data on-premises means better control and visibility, which is not often the case when the data is moved to cloud servers and containers, which is entirely a false claim.

4. Security is the job of a vendor

You have probably moved to the cloud to make sure that data management is easier and free of risk, not to make it even more complicated. But security must take your precedence. Your cloud vendor will surely try their best to make sure their buckets are configured well and you do not become a cause of vulnerability. At an organization’s end, it is important that you limit tour access to data and revoke access for employees with whom you have ended your business relationship et al. It is also imperative that you make sure employees are trained and are aware of threats emerging from the space.

5. Compliance is a difficult aspect while deploying cloud

The necessity for cloud adoption varies from company to company. And in most cases, the benefits of cloud computing depend on the kind of business the organization is. Just like with any tool, organizations ultimately must consider their risk profiles, staffing and access, resource allocation, and regulatory policies within the organization, and risk appetite before making a decision about cloud storage. Compliance should be a part of the ethos of companies. The scenario isn’t much different for cloud security as well.

What are the cloud security challenges that your organization is facing? Let us know by participating in this short survey. Click here to take the survey and get $20 off on CISO MAG’s subscription.

We at CISO MAG are set to publish the Power List, a comprehensive publication which will explore critical areas of cloud security while elucidating best practices to adopt for securing the cloud space. Ahead of it, we are discussing several trends and vendors in the space while we tell you what differentiates each product from the rest. To know more about it, click here: http://bit.ly/CISOMAGPowerList

FaceApp unnecessarily accessing your Facebook Friends List?

FaceApp

FaceApp, the application that took the internet by storm over the past few weeks due to its controversial privacy policy recently hit the headlines with one more issue. The AI-powered photo-morphing app is found collecting the list of users’ Facebook friends unnecessarily, the hackernews reported.

According to an Indian security researcher Athul Jayaram, who flagged the issue, the app contains a feature that allows users to download and edit photos from their Facebook accounts. However, this option will only work when a user enables when a user accesses the FaceApp account via ‘Login with Facebook’ option.

Jayaram said whenever a user logins to FaceApp with Facebook credentials, the app enables a feature called “Social Stylist,” designed to allow users to invite their Facebook friends to vote for their posts. However, the researcher clarified that the feature was discontinued after reporting the issue to FaceApp.

“We don’t have this data anymore and planning not to request this permission soon. We used to have some social features (Social Stylist: you could invite your friends to vote for the best style, have a feed, etc.), those features needed this permission,” FaceApp CEO Yaroslav Goncharov said in a statement. “Please note that don’t require a Facebook login for FaceApp to work, so only a few users are logged in.”

It all began after several experts and users finally read the terms and conditions of the app. Over user content, It reads, “You grant FaceApp a perpetual, irrevocable, nonexclusive, royalty-free, worldwide, fully-paid, transferable sub-license to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, publicly perform and display your User Content, and any name, username, or likeness provided in connection with your User Content in all media formats and channels now known or later developed, without compensation to you.”

The app is over two years old and was created by a Russian developer. “I would be cautious about uploading sensitive data to this company that does not take privacy very seriously, but also reserves broad rights to do whatever they want with your pictures,” said Justin Brookman, a former policy director for the Federal Trade Commission’s Office of Technology Research and Investigation to CNBC.

NSA launches new cybersecurity directorate to defend from foreign adversaries

National security Agency

The National Security Agency (NSA), the intelligence agency of the United States Department of Defense, recently announced the launch of a new division intended to protect the country’s intelligence and critical digital assets against foreign cyber threats.

The newly established Directorate will integrate the agency’s foreign intelligence and cyber operations to enhance the country’s vulnerability assessments and cyber defense expertise. The new establishment, which is launched by the NSA Director Gen. Paul Nakasone, is scheduled to be working from October 1, 2019.

“The Cybersecurity Directorate will reinvigorate our white hat mission opening the door to partners and customers on a wide variety of cybersecurity efforts. It will also build on our past successes such as Russia Small Group to operationalize our threat intelligence, vulnerability assessments, and cyber defense expertise to defeat our adversaries in cyberspace,” NSA said in a statement. “This new approach to cybersecurity will better position NSA to collaborate with key partners across the U.S. government like U.S. Cyber Command, Department of Homeland Security, and Federal Bureau of Investigation. It will also enable us to better share information with our customers, so they are equipped to defend against malicious cyber activity.”

With an aim to protect the United States communications and computer networks from “foreign adversaries”, President Donald Trump has declared a national emergency over threats against American technology. The president signed an executive order which effectively bars U.S.-based companies from using foreign telecoms, which are believed to pose national security risks, the White House said.

The executive order does not name any company, but it’s believed that the move is expected to precede a ban on U.S. firms doing business with the Chinese telecommunications company, Huawei. According to the White House statement, Trump’s order aims to “protect America from foreign adversaries who are actively and increasingly creating and exploiting vulnerabilities in information and communications technology infrastructure and services”.

Cybersecurity firm CyVent partners with Deep Instinct to accelerate growth

Collaboration, partnership, alliance, KnowBe4 and Agari Partner to Prevent Identity-Based Email Attacks

Cybersecurity firm CyVent recently announced its partnership with Deep Instinct, a company that applies deep learning to cybersecurity. The new alliance allows CyVent customers to leverage Deep Instinct’s deep learning predictive capabilities to ensure multi-layer protection across all endpoints, servers, mobile devices, and operating systems.

CyVent uses true deep learning to offer a unique effective suite of products and services to strengthen cybersecurity. The company claims that its AI-driven solutions help organizations transition from the classic remediation approach to security. By leveraging deep learning’s capabilities, Deep Instinct provides zero-time threat prevention platform for organizations to protect themselves against zero-day threats and APT attacks.

“It’s an exciting time to be part of Deep Instinct,” said David Roth, Senior Vice President of Sales, North America at Deep Instinct. “As we develop and deploy our expansion into the Americas, CyVent has been an invaluable strategic partner providing keen market knowledge, deep experience in growing new business lines and full access to sizeable growth opportunities in the region.”

“As cybersecurity threats continue to evolve, the speed at which an organization is able to respond has become of the utmost importance,” stated Yuda Saydun, President of CyVent. “We evaluate dozens of innovative solutions, but only focus on effective technologies that help corporate teams plan, protect and pre-empt threats. Detection and response-based solutions, which wait for the execution of an attack to react, are no longer enough. Businesses need cybersecurity solutions that allow them to respond instantly before a breach becomes a problem.”

Recently, deep learning management platform Determined AI raised $11 million in a funding round led by GV, formerly known as Google Ventures. The company stated the new investment will be used to expand its market reach and bring new features to its deep learning model development tool for machine learning engineers to help developers identify and process data sets. Determined AI also stated that it’s going to employ more data engineers to build its AI applications.