Home Blog Page 301

Taking control of third-party risk in healthcare

Medical healthcare

By Brian Parks, Senior Vice President, Security Services, Intraprise Health

Data breaches are on the minds of every C-suite executive in healthcare. Third parties (i.e., vendors) with access to organizations’ protected health information (PHI) and/or personally identifiable information (PII) represent a significant risk for data breaches to the organization.

The Information Systems Audit and Control Association (ISACA) defines TPRM as “The process of analyzing and controlling risks presented to your company, your data, your operations and your finances by parties OTHER than your own company.”

Data breaches in healthcare organizations continue to make the front page and the struggles of organizations to get a handle on their third-party risk are well documented. A study conducted by the Ponemon Institute notes, “Despite the number of publicized data breaches throughout the U.S., there continues to be a significant lack of confidence and understanding within companies as to whether their security posture is sufficient to respond to a data breach or cyberattack … Companies also need to do more than depend on business associate agreements to ensure that consumer information is being protected. Business should perform audits and assessments with vendors.”

Most organizations are aware of the information security risk posed by third parties. They also admit their current vetting process is ineffective or non-existent.

Why don’t organizations focus more on TPRM?

Building and maintaining a solid TPRM program can be difficult, time consuming and resource-intensive, especially when starting from scratch. Executives admit to several barriers:

  • Some organizations don’t have a complete and accurate list of vendors that have access to sensitive organizational data.
  • The prospect of starting a new program or beefing up an existing one without subject matter expertise can be daunting.
  • It takes money and people – something that is often in short supply and competing with other priorities.
  • There is an assumption that the third party is responsible and is protecting sensitive data.
  • Third-party risk is seen as something outside the four walls, so it doesn’t get the priority it deserves.
  • There is a lack of perceived value versus the expertise, time and effort required to build and maintain a program.

These reasons, while valid, do not absolve an organization of its responsibility to protect the PHI/PII with which it is entrusted.

Thanks to the HITECH regulation and associated Meaningful Use program, as well as related technology advances over the last 15 years, healthcare is becoming less insular and increasingly interoperable. The dependency on third parties by covered entities to adhere to the regulation and deliver the best coordinated care possible is inextricable, increasing the technical integration requirements, which raises the risk profile greatly.

However, making risk-based decisions on whether to engage a third party require reliable, consistent information related to a third party’s policies, procedures, practices and overall information security risk profile; this is essential for risk mitigation for a healthcare organization.

How can you raise TPRM’s profile in your organization?

To overcome the many perceived barriers to getting started with an effective program, you need a champion. The chief information security officer (CISO) or equivalent leader needs to get the buy-in of the C-suite executives, and together they must evangelize the importance of TPRM for the entire organization, not just the IT department.

Knowing about the risk posed by third parties and appreciating the need to assess and remedy those risks will improve the program’s success rate greatly. These are messages everyone in the organization — from the leadership on down — needs to hear and understand implicitly.

Your organization’s Compliance department needs to be actively engaged; they’re often terrific champions in managing third-party risk. Once a program is implemented, Compliance staff often has ultimate responsibility for enforcing the organization’s adherence.

Any organizational channel that introduces third parties and the associated exposure of PHI/PII needs to be an integral part of a complete TPRM program that includes assessments and monitoring. These channels include department heads (where the vendor relationship often originates) and procurement, legal, contracting and IT/IT security departments, to name a few.

A strong TPRM program is vital to the health of your organization. Understanding the requirements for TPRM and how to create buy-in throughout your organization is critical to creating a strong security posture. Don’t wait until one of your third parties is compromised to begin implementing your own TPRM program.

The opinions expressed in this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Huawei employing China-sponsored hackers: Research

Huawei

Security reports have alleged that the Chinese telecommunications company Huawei has been recruiting high-level operatives linked to China’s military and intelligence agencies, the express.co.uk reported.

According to Professor Christopher Balding, who conducted the research, around 100 Huawei’s employees had connections with the Chinese military and state-sponsored hacking operations. The professor described the employees as representatives of the Ministry of State Security (MSS) at Huawei. He also claimed that they’ve worked on “building lawful interception capability into Huawei equipment”.

“Huawei’s co-founder Ren Zhengfei held a senior position within China’s People’s Liberation Army (PLA) before starting the company,” Balding said in a media statement.

Recently, security researchers from cybersecurity firm Swascan revealed that they have discovered multiple vulnerabilities in Huawei’s Web Application and Servers. Swascan stated cybercriminals can exploit the critical vulnerabilities to access sensitive information. The research team said they’ve identified three vulnerabilities that could impact regular operations if exploited.

According to Swascan, the three discovered flaws in Huawei’s web applications include: CWE-119 (Improper Restriction on Memory Buffer) — The hacker can access the memory and can possibly execute malicious codes. CWE-125 (Out-of-bounds Read) — This flaw allows an attacker to read sensitive information. CWE-78 (OS Command Injection) — The attackers can use this flaw to execute unauthorized commands to crash the software and access the restricted data.

Cybercrime a $45 billion industry: Report

Security researchers revealed that cybercrime incidents are on a dramatic rise. According to a report from the Internet Society’s Online Trust Alliance (OTA), cybercrime has become a $45 billion industry in 2018.

The report, Cyber Incident & Breach Trends, was prepared from the sources including the Federal Bureau of Investigation, Symantec, Risk Based Security, the Identity Theft Resource Center, and the Internet Society’s internal data.

The report stated that the number of ransomware, data breaches, and DDoS incidences came down in 2018. However, the financial damage due to ransomware rose by 60 percent. It also said that losses from business email compromise (BEC) doubled while damage from Cryptojacking tripled.

“It is difficult to get a complete, accurate picture of the overall cyber incident landscape. Much like putting together a jigsaw puzzle with only a handful of key pieces, it is possible to get a sense of the overall picture, but many of the details are missing. In tracking cyber incidents, many key data “pieces” exist, but are limited for a variety of reasons – they often represent only one vendor’s view of their user base, they are typically regional and not global, it is easier to measure attacks than measure which are successful, there is a lack of consolidated reporting mechanisms, and finally, it is still the case that most incidents go unreported,” OTA said in a statement.

Security experts opined that Phishing and Ransomware attacks are the most reported types of cyber-attacks on financial services firms. According to the Audit and Consulting firm RSM International in the United Kingdom, around 819 cyber incidents were reported by Financial services firms to the Financial Conduct Authority (FCA) last year.

RSM said that Retail Banks were the most frequently affected by cyber-attacks (486 security incidents) followed by wholesale financial markets (115 attacks), and retail investment firms (53 incidents). In 2018, financial firms reported around 93 cyber-attacks, in which half of these (48 attacks) were phishing attacks while 20 percent (19 attacks) were ransomware attacks.

RSM said the sudden increase in the companies reporting security incidents was due to the introduction of the European Union’s General Data Protection Regulation (GDPR) laws that took effect last May.

OpenAI raises $1 billion from Microsoft

Brand Phishing Attacks

Artificial Intelligence company OpenAI recently raised $1 billion from the tech giant Microsoft Corporation. Along with the funding, OpenAI also made an exclusive computing partnership with Microsoft to build new Azure AI supercomputing technologies.

Formed by technology veterans Elon Musk and Sam Altman, OpenAI was established with the aim of doing research and development to steer the growth of artificial intelligence. The collaboration supports OpenAI’s efforts to build Artificial General Intelligence (AGI) platform and to extend Microsoft’s Azure capabilities in large-scale AI systems.

“The creation of AGI will be the most important technological development in human history, with the potential to shape the trajectory of humanity,” said Sam Altman, CEO, OpenAI. “Our mission is to ensure that AGI technology benefits all of humanity, and we’re working with Microsoft to build the supercomputing foundation on which we’ll build AGI. We believe it’s crucial that AGI is deployed safely and securely and that its economic benefits are widely distributed. We are excited about how deeply Microsoft shares this vision.”

“AI is one of the most transformative technologies of our time and has the potential to help solve many of our world’s most pressing challenges,” said Satya Nadella, CEO, Microsoft. “By bringing together OpenAI’s breakthrough technology with new Azure AI supercomputing technologies, our ambition is to democratize AI — while always keeping AI safety front and center — so everyone can benefit.”

Recently, Microsoft invested $15 million on nsKnox– a provider of corporate payment protection solutions based on its innovative cooperative cybersecurity technology platform. The funding will enable nsKnox to expand its global customer base and to further develop its corporate payment protection platform – helping to ensure verified and secure business transactions, mitigate reputational risk and prevent billions in corporate losses. The company also stated that it will focus on advancing its go-to-market strategy and enhancing its capabilities to ensure customer success globally.

Google offers Big Rewards for Bug Hunters

Google Cybersecurity Action Team Google, EU warns Google

Google recently announced the increase in bug bounty rewards, making them more lucrative to security researchers. The search engine giant stated that it has raised the bounties for Chrome and Google Play bugs.

Google launched the vulnerability rewards program in 2010 and provides cash rewards to security researchers who report vulnerabilities in Google code. The company stated that they’ve received around 8,500 vulnerability reports and paid rewards over $5 million (£4 million).

According to Google’s Chrome security experts Natasha Pabrai and Andrew Whalley, the company has doubled the maximum reward on High-Quality Reports from $15,000 (£12,000) to $30,000 (£24,000) and tripled the baseline reward amount from $5000 ((£4 million) to $15,000 (£12,000) for good measure.

“Today, we’re delighted to announce an across the board increase in our reward amounts! Full details can be found on our program rules page, but highlights include tripling the maximum baseline reward amount from $5,000 to $15,000 and doubling the maximum reward amount for high quality reports from $15,000 to $30,000. The additional bonus given to bugs found by fuzzers running under Chrome Fuzzer Program is also doubling to $1,000,” Google said in an official post.

“But that’s not all! On Chrome OS we’re increasing our standing reward to $150,000 for exploit chains that can compromise a Chromebook or Chromebox with persistence in guest mode. Security bug in firmware and lock screen bypasses also get their own reward categories,” Google added.

Scammers are making phishing attacks, by abusing Google Calendar services, to trick users into giving away sensitive information like passwords, card details, and other financial data. The threat intelligence and cybersecurity firm Kaspersky stated that it detected many unsolicited pop-up calendar notifications sent to Gmail users by cybercriminals as a sophisticated spam email attack.

The scam occurs when an attacker sends an unsolicited calendar invitation carrying a link to a phishing URL and encourage the recipient to click on the link. The user then redirected to a fake website, appears to be original, that features a simple questionnaire and offered a prize after completion. The victim will be asked to fill in personal details like name, phone number, address, and bank details in order to steal the victim’s money or identity.

Attackers compromise Russia’s Secret Intelligence Agency servers

Russia becomes the latest victim of a hacking attack that compromised the country’s Federal Security Service (FSB). According to the official statement, the hackers allegedly gained access to 7.5 terabytes of data from a major contractor Sytech.

The incident exposed FSB’s secret projects like how Russia is trying to carry out de-anonymization of users of the Tor browser collecting information of users’ social networks, and separating the Russian internet operations from the rest of the world.

The attack occurred on July 13, 2019, by an unknown hacking group named 0v1ru $. Hackers allegedly accessed into SyTech’s Active Directory server from where they gained access to the company’s entire IT network and defaced the company’s website with a “yoba face,” an emoji used in Russian for trolling.

Hackers then posted screenshots of the company’s servers on Twitter and later shared the stolen data to another hacking group called Digital Revolution, which later shared the stolen files on their Twitter account and with Russian journalists.

According to a threat report from cybersecurity firm CrowdStrike, hackers tied to Russian intelligence agencies are 8 times faster than North Koreans, Chinese, and Iranians in hacking. In its report dubbed Global Threat Report 2019: Adversary Tradecraft and the Importance of Speed, CrowdStrike stated the Russians are the most sophisticated among the many nation-state adversaries that are regularly hacking government and private computers in the United States.

In August 2018, Microsoft Corporation revealed that hackers linked to Russian military intelligence tried to hack the websites of two conservative think-tanks in the United States ahead of November’s midterm elections. It said that it detected and seized websites that were created by hackers linked to the Russian unit to mimic the pages of the International Republican Institute and the Hudson Institute.  These sites are designed to redirect the users to fake web pages where they were asked to enter usernames, passwords, and other credentials.

 

Sectigo partners with NetObjex to jointly prevent Botnet attacks

Partnership

Sectigo, a provider of purpose-built and automated PKI management solutions, recently announced its partnership with computing technology firm NetObjex. Sectigo offers enterprises purpose-built and automated PKI management solutions to secure websites, connected devices, applications, and digital identities.

NetObjex is an Intelligent Automation Platform for tracking, tracing, and monitoring digital assets using AI, Blockchain, and Internet of Things (IoT). The latest partnership provides enterprises and customers a secured and trusted computing infrastructure that extends from IoT edge devices to the cloud and blockchain. The alliance also combines Embedded Device Hardening, AI, and Blockchain, helping companies against Data Breaches and Botnet Attacks.

“With the growth of IoT and the rising cost of data breaches, enterprises need a secure computing infrastructure more than ever,” said Damon Kachur, Vice President, IoT Solutions, Sectigo. “This partnership combines the strengths of Sectigo and NetObjex to deliver a truly robust security infrastructure that addresses an acute need for enterprises.”

“By collaborating with Sectigo, we can extend our comprehensive platform and offer enhanced security to our enterprise customers,” said Raghu Bala, CEO, NetObjex. “The growth of edge devices has increased the risk of devastating data breaches. Offering Sectigo’s embedded device hardening technologies and purpose-built third-party certificate issuance and management allows enterprises to protect their important data.”

Microsoft reveals election-related investigation findings

Brand Phishing Attacks

Microsoft says it has detected more than 740 intrusion attempts by state-sponsored attackers last year targeting the U.S.-based political parties, campaigns, and other democracy-focused organizations, who are subscribed to Microsoft’s AccountGuard service.

The Microsoft AccountGuard provides free cyber threat detection services to election-related candidates, campaigns, and other groups. The Tech giant revealed the probe findings at the Aspen Security Forum, where it demonstrated a voting system ElectionGuard software. Microsoft said the new voting system offers secure and verifiable voting experience.

“Since the launch of Microsoft AccountGuard last August, we have uncovered attacks specifically targeting organizations that are fundamental to democracy. We have steadily expanded AccountGuard, our threat notification service for political campaigns, parties, and democracy-focused nongovernmental organizations (NGOs), to include 26 countries across four continents,” Microsoft said in a blog post.

According to the Microsoft Threat Intelligence Center, most of the attackers originated from Iran, North Korea, and Russia. Microsoft has identified the multiple hacker groups named Holmium and Mercury operating from Iran, Thallium operating from North Korea, and Yttrium and Strontium operating from Russia.

“Cyberattacks continue to be a significant tool and weapon wielded in cyberspace. In some instances, those attacks appear to be related to ongoing efforts to attack the democratic process. As we head into the 2020 elections, given both the broad reliance on cyberattacks by nation-states and the use of cyberattacks to specifically target democratic processes, we anticipate that we will see attacks targeting U.S. election systems, political campaigns or NGOs that work closely with campaigns,” Microsoft said.

Earlier, Microsoft said hackers linked to Russian military intelligence tried to hack the websites of two conservative think-tanks in the United States ahead of November’s midterm elections. It also stated that it has detected and seized websites that were created by hackers linked to the Russian unit to mimic the pages of The International Republican Institute and The Hudson Institute.  These sites are designed to redirect the users to fake web pages where they were asked to enter usernames, passwords, and other credentials.

Equifax to pay $700 million for data breach settlement

Equifax

The Federal Trade Commission and Consumer Financial Protection Bureau have fined Equifax for around $700 million following a massive data breach in 2017 that leaked a massive amount of information of more than 143 million people in the U.S. alone.

According to the official reports, the proposed penalty could be between $650 and $700 million. It’s said that the final amount could vary depending on how many people file claims and their expected compensation.

On September 7, 2017, the Atlanta-based consumer credit reporting agency disclosed that its databases had been breached between May and June 2017, and hackers had gained access to Company data that potentially compromised sensitive information for 143 million American consumers, including Social Security numbers, credit card numbers and driver’s license numbers.  Equifax discovered the breach on July 29, 2017, but had waited until after the close of trading nearly six weeks later to disclose the breach to consumers and Equifax’s investors, after hackers exfiltrated data for 76 days.

Earlier, Equifax was charged with a fine of £500,000 ($660,000) by the Information Commissioner Office (ICO) for failing to protect the personal and financial data of customers. The Information Commissioner’s Office, which carried out the investigation, stated that Equifax had been warned about vulnerabilities in its systems by the US Department of Homeland Security in March 2017. However, Equifax failed to take proper steps to fix the vulnerabilities.

UK mid-market businesses lose £30 billion to cyber-attacks

United Kingdom

The mid-market businesses in the UK have lost around £30 billion ($37 billion) in the past 12 months due to security breaches. A research from business and financial adviser Grant Thornton UK LLP discovered that cyber-attacks are a present danger for businesses in the UK. The research report, named Cyber Security – the Board Report, stated that the businesses are not prepared to manage the cyber risks.

Grant Thornton stated they surveyed over 500 UK mid-market companies, in which half of them reported losses of up to 10 percent of their income over cyberattacks. The research revealed that 63 percent of the companies don’t have a cybersecurity team. Only 36 percent stated that they’ve provided cybersecurity training to their employees. And more than half of the businesses (59%) don’t have a cyber incident action plan, according to the research.

“Boards have a key role to play in ensuring an effective cyber strategy is in place. Putting cyber-crime onto the board’s agenda is one of the most effective ways to minimise the chances of a successful attack and reduce the financial impact if a breach occurs. With that in mind it is worrying that almost two thirds of the businesses we interviewed do not have a board member responsible for cyber security,” said James Arthur, the head of cyber consulting at Grant Thornton UK LLP.

“While commitment from the top is vital, ensuring your people are properly trained is also essential. Often, companies make themselves vulnerable to attack simply by failing to get the basics right. Training to raise employee awareness can have a hugely positive impact on cyber security. People are often unaware of the important role they play in helping a business to stay protected, so companies of all sizes need to ensure they have regular and ongoing cyber security training in place.”

Earlier, a survey from analytics software company FICO revealed that 62 percent of UK firms lack complete cybersecurity insurance. According to the research, only 38 percent of UK firms surveyed have cybersecurity insurance that covers all risks. Telecommunications firms lag other industries regarding cybersecurity insurance, 17 percent of firms reported that they have no coverage. Most of the respondents stated that their premiums are based on inaccurate analysis or unknown factors.