Home Blog Page 304

Anaesthetic machines vulnerable to cyber-attacks: Researchers

Anaesthetic machines

Security researchers revealed that an anaesthetic machine can be hacked and controlled remotely if left accessible on a hospital computer network. Cybersecurity firm CyberMDX discovered a security flaw in a number of GE Healthcare devices used by the National Healthcare Services (NHS) hospitals that could allow hackers to manipulate the amount of anaesthetic delivered to patients.

The company stated the remotely exploitable flaw could enable hackers to silence device alarms, alter the date and time settings, adjust anaesthetic dosages, and switch anaesthetic agents. It’s believed that the Aespire, Aestiva 7100, and 7900 devices could be targeted by hackers if left accessible on hospital computer networks, according to the researchers.

“On July 9, 2019, ICS-CERT disclosed the first vulnerability discovered specifically impacting anesthesia machines. If exploited, the vulnerability would allow an attacker to silence alarms, alter date and time settings, adjust gas composition inputs, change barometric pressure, and switch between anesthetic agents — all without authentication,” CyberMDX said in a stated

“Affecting GE Aestiva and GE Aespire (models 7100 and 7900) machines that are ported to the network via terminal servers, the exploitation chain for this vulnerability is actually quite simple — provided you know your way around the communication protocol that these machines use,” it added.

A recent report revealed that healthcare organizations suffered the highest number of data breaches in 2018 across any sector of the U.S. economy. According to Beazley Breach Response, a breach response management and information security insurance solutions provider, the healthcare entities have reported the highest number of data breaches, at 41 percent.

The report, dubbed as Beazley Breach Insights Report, stated that direct hacking, the presence of malware, or due to human error were the causes of data breaches in healthcare organizations. The report also revealed the percentage of breaches in other sectors of the economy. The education sector accounted for 10 percent of security issues, financial institutions reported 20 percent of incidents, and professional services represent 13 percent of cases.

The cybercriminals are attempting to extort cryptocurrency from companies or individuals claiming to have embarrassing evidence of people using adult websites at work, which are related to extortion, the report added.

Safe-T’s Zero+ Access Network: Phased Deployment

Network Security

By Safe-T 

Safe-T provides a secure application and file access solution with 1) An architecture that implements Zero Trust Access, 2) A proprietary secure channel that enables users to remotely access shared sensitive files, and 3) User behavior analytics.

Safe-T’s package of access control software is called: Safe-T Zero+. Best practices guidelines require organizations to implement a phased deployment. This enables your organization to progressively migrate to a Zero Trust network architecture.

By implementing Safe-T’s Zero+ in steps you gain these advantages:

  • Your organization learns to use the new system gradually.
  • Information acquired from early deployment stages can be applied to the rest of the process.
  • Your organization lowers its risks because any issue that might occur only affects a small group of users.
  • IT administrative implementation burden is limited.
  • Software evaluation trial period cost is limited.
Overview: Network Security Challenges

This section describes the contextual background of existing IT problems Safe-T’s Zero+ model can solve.

Security Perimeter: Most data centers implement a security perimeter model that establishes zones of trust based on ranges of IP addresses. They deploy back-to-back firewalls creating a DMZ that separates their trusted internal network from the external untrusted internet.

This type of fixed perimeter no longer accurately reflects the typical topology of users and servers.

Trusted Zones: A hacker who infiltrates the inner firewall of an organization is inside what is regarded as a trusted area. The hacker can then move about laterally stealing credentials and using them to capture and exfiltrate valuable digital resources.

Cloud Applications: Companies are increasingly deploying web applications and data on public clouds such as Amazon Web Services and Microsoft Azure. These public clouds are located in geographical locations remote from an organization’s trusted firewalls and perimeter network.

Mobile Workers: Company networks are expanding in size and complexity. Employees, contractors, and partners use laptops and other mobile devices offsite in locations external to the trusted perimeter network.

VPNs: Using VPNs to access an internal network can create a vulnerability if an administrator grants overly broad permissions to users. VPNs are often configured enabling users to access the inner network as if the user was onsite in a company office.

Malware: A serious problem with the use of VPNs is they create a high level of risk that malware in a user’s device can spread to an inner network.

What Is Zero Trust Network Access

These are key principles of a Zero Trust network:

Trust Nothing: Users and network traffic are not trusted until verified. Users whether inside or outside the organization’s network should never be trusted by default.

Visibility: Backend servers are not visible to unauthenticated users.

Authentication: Authentication workflows for a user or group should include context-aware data such as device ID, geographic location, and the time and day the user requests access.

Granularity: Zero trust supports network micro-segmentation isolating IT resources to limit threats. It also implements a policy of least privilege by enforcing controls that enable users to have access only to resources needed to perform their jobs.

Logs: All traffic internally as well as externally is logged to detect malicious or anomalous events.

Main Components

The Cloud Security Alliance is the leading proponent of SDP standards and research. The CSA working group on SDP has devised a security framework that can be deployed to protect applications from network-based attacks.

SDP architectures offered by different vendors may support different characteristics. Safe-T’s SDP architecture is designed to substantially implement the essential capabilities delineated by the CSA architecture. Safe-T’s Zero+ is built using these main components:

Safe-T Access Controller

The Access Controller is the SDP system’s centralized control and policy enforcement engine. The Access Controller is designed to function as a trust broker by governing the process flow between end users and backend services. The Access Controller has the responsibility for managing end user authentication and authorization.

Safe-T Access Gateway

The Access Gateway acts as a front-end to all backend services published to an untrusted network (e.g. Internet).

Safe-T Authentication Gateway

The authentication gateway presents to the end user in a clientless web browser a pre-configured authentication workflow provided by the Access Controller. The authentication workflow is a customizable set of authentication steps such as: captcha, user name/password, No-Post, OTP.

If the user successfully authenticates, the Authentication Gateway displays links enabling the user to connect to authorized backend services.

Unauthorized backend services are not visible to the end user. As stated by Safe-T: If you can’t be seen, you can’t be hacked®.

Safe-T’s Software Perimeter

The following image shows the basic Safe-T SDP architecture.

Safe-T Software Defined Perimeter

3

Safe-T Zero+ Capabilities
  • Users who want to access a protected server must successfully authenticate and be authorized at an authentication gateway.
  • Configurable policies define orchestrated authentication steps each user or group member is required to perform.
  • Backend servers are not visible to unauthenticated users. The probability of successful attacks is minimized following Safe-T’s axiom: If you can’t be seen, you can’t be hacked®.
  • Eliminates the possibility of users establishing a direct connection from an untrusted network to specific hosts in the internal Provides URL rewriting to hide backend services.
  • Implements a patented technology to eliminate the need to open incoming ports in the internal firewall. Eliminates the need to store sensitive data in the DMZ.
  • Support a variety of communication protocols: HTTP/S, SMTP, SFTP, APIs, RDP, WebDAV.
  • Extends to on-premises, public, and hybrid cloud. Zero+ can be deployed on AWS, Azure, and other cloud infrastructures protecting both cloud and on-prem resources.
  • Provides user behavior analytics capability that monitors the actions of protected web applications. A dashboard displays security related events and aggregated statistics. Administrators work at the dashboard to inspect details about anomalous behavior that can trigger alerts and identify suspicious activities.
  • Provides a unique, native HTTPS-based file access solution for NTFS file system, replacing the vulnerable SMB protocol. Users can create a standard mapped network drive in their Windows explorer providing a secure, encrypted, and access-controlled channel to shared backend resources.
Types Of SDP Architectures

Customers can select an SDP architecture that meets their on-prem or cloud-based requirements:

  • The customer deploys three VMs: 1) Access Controller, 2) Access Gateway, and 3) Authentication Gateway. The VMs can be deployed on-premises in an organization’s LAN, on Amazon Web Services (AWS) public cloud, or on Microsoft’s Azure public cloud.
  • The customer deploys the 1) Access Controller VM and 2) Access Gateway VM on-premises in their LAN. The customer deploys the Authentication Gateway VM on a public cloud such as AWS or Azure.
  • The customer deploys the Access Controller VM on-premises in their LAN and Safe-T deploys and maintains two VMs 1) Access Gateway and 2) Authentication Gateway both hosted on Safe-T’s private global cloud.

Info: The third SDP architecture option described above implements a hybrid SaaS model with shared deployment responsibilities. Safe-T deploys and manages two of the SDP VMs in the Safe-T private global cloud and the customer deploys one node the Access Controller VM on their premises.

How To Configure Phased Deployment

This section describes the basic steps for a limited SDP deployment involving a small number of users (e.g. 20) and backend servers (e.g. 5). Best practices are outlined below but your organization may deploy Safe-T Zero+ according to your site requirements.

Note: It is assumed you have selected the SDP architecture you want to deploy.

Phased Deployment of Backend Services

Select a small number of backend servers that contain low sensitive data. For example, choose a server used primarily by experienced users such as DevOps or QA personnel. This ensures risk is minimal if any problem occurs during the phased deployment of SDP access in your organization.

In the Access Controller web interface you must configure a reverse access rule for each backend server. The example below shows two reverse access rules: 1) a rule to connect to the Safe-T Authentication Gateway, and 2) a rule to connect a backend github server.

Figure 1: Safe-T Reverse Access Rules For Phased Deployment

4

Phased Deployment Of User Groups

The Safe-T Access Controller provides a configuration feature called: Trusted Services. Using the admin web interface you can connect one or multiple groups to one or multiple backend services.

Example: To configure an organization’s AD server as a trusted service you could configure the following:

  • Group name: Sales;Marketing
  • Service name: AD
Replacing Your VPNs With SDP

The following list describes some problems that may be experienced by an organization using VPNs for remote access:

  • Grants all-or-none access to the assigned network.
  • Does not offer different levels of access for different users.
  • Cannot easily adjust to dynamic changes in your network.
  • Generates administrative complexity and cannot easily handle cloud or multiple network environments.
  • Secures remote users but not users who are on-prem.
  • Follows a site-centric model instead of user-centric.
  • Requires installation of end-user VPN software clients.

Info: According to Gartner consultants, by 2021, 60% of enterprises will phase out network VPNs for digital business communications in favor of software-defined perimeters.

Safe-T suggests the following paths for phasing in SDP as a VPN replacement or for using VPNs and SDP in parallel.

Using VPNs and SDP In Parallel

This deployment solution implements a parallel VPN and SDP architecture. You start the migration by selecting a group of VPN users (e.g. Partners). Ask these users to log into the SDP Authentication Gateway web UI instead of using their VPN client.

Evaluate SDP access and when the advantages of using SDP are demonstrated to the satisfaction of your IT department remove the VPNs from that group of SDP users. Continue reducing the number of VPN users while simultaneously granting them SDP access.

Using VPNs As The Front End For SDP Access

This strategy uses your organization’s existing VPN framework as a front end for accessing the SDP Authentication Gateway.

The process flow is as follows:

  1. A user opens their SSL or IPsec VPN client and logs into the VPN gateway.
  2. The VPN gateway transfers the user’s credentials over a RADIUS connection to the SDP Authentication Gateway.
  3. The Access Controller retrieves the credentials from the Authentication Gateway over a reverse access connection and authenticates the user with a third-party IAM/IDP solution such as Microsoft Azure AD.
  4. If the user is authenticated, the Access Controller sends a RADIUS response via the Authentication Gateway to the VPN client indicating the user is authenticated.
  5. The Access Controller instructs the Access Gateway to provide reverse access to the user’s virtual IP address that is provided by the VPN gateway.
  6. The user can access the authorized services.

Info: The above deployment architecture can be used as a migration path to SDP-only access if your organization chooses to phase out using their SSL or IPsec VPN

Note: If you use VPNs as a front end for SDP access the end user does not log into the SDP Authentication Gateway.

SDP Market Trends

A recent survey by the Cloud Security Alliance indicates SDP awareness and adoption is still in its early stage of growth. This is an excerpt from the CSA Survey:

The State of SDP Survey: A Summary, Cloud Security Alliance, July 2, 2019

https://blog.cloudsecurityalliance.org/2019/07/02/the-state-of-sdp-survey-a-summary/

“The survey indicates it is still early for SDP market adoption and awareness, with only 24% of respondents claiming that they are very familiar or have fairly in-depth knowledge of SDP. The majority of respondents are less knowledgeable, with 29% being “somewhat” conversant in SDP, 35% having heard of it, and 11% knowing nothing about it.”

“A majority of organizations recognize the need to change their approach to a Zero Trust Architecture– 70% of respondents noted that they have a high or medium need to change their approach to user access control by better securing user authentication and authorization.”

Conclusion

Safe-T’s Zero+ network access can help manage and improve an organization’s network security.

Organizations want to protect their applications and data whether on-prem, hybrid, or in a public cloud. They also want to secure network access for users who are working in any geographic location.

IT professionals across a wide range of industries are learning about the advantages of a Zero Trust access network.

CISO MAG does not evaluate the advertised product, service, or company, nor any of the claims made by the advertisement. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Hackers injected older versions of Pale Moon browser with malware

Patchwork BADNEWS, APT31 threat group

Open source browser Pale Moon was breached, and hackers plugged malware into the browser. The hack which occurred in 2017 went undetected for nearly 18 months. It was by sheer accident that Pale Moon developers found the malware in the older versions of the browser which was stored in the “archive server,” meant for users to downgrade to an older version for stability.

“According to the date/time stamps of the infected files, this happened on 27 December 2017 at around 15:30. It is possible that these date/time stamps were forged, but considering the backups taken from the files, it is likely that this is the actual date and time of the breach,” Straver, lead developer of Pale Moon stated in a Forum about the time of the attack.

“A malicious party gained access to the at the time Windows-based archive server (archive.palemoon.org) which we’ve been renting from Frantech/BuyVM, and ran a script to selectively infect all archived Pale Moon .exe files stored on it (installers and portable self-extracting archives) with a variant of Win32/ClipBanker.DY (ESET designation). Running these infected executables will drop a trojan/backdoor on your system that would potentially allow further compromise to it,” he said, while adding, “The moment this was reported to me on 2019-07-09, I shut down access to the archive server to prevent any potential further spread of infected binaries and to start an investigation.”

According to the developers, all Pale Moon 27.6.2 and earlier versions were infected. But, older versions of the Basilisk web browsers were not affected. This was even despite the browsers being hosted on the same server.

Earlier, Web browser developer Mozilla announced that it has patched its Firefox browser’s vulnerability in response to a spear-phishing campaign targeting employees of cryptocurrency exchange Coinbase. The company has released the latest version of the Firefox browser and urged the users to update their browsers.

The Coinbase security team and a security researcher Samuel D. Gross from Google discovered a “Zero-day” vulnerability in the Mozilla Firefox browser, which can be used to launch a cyber-attack using JavaScript objects, ZDNet reported.

“The bug can be exploited for RCE [remote code execution] but would then need a separate sandbox escape in order to run code on an underlying operating system. However, most likely it can also be exploited for UXSS [universal cross-site scripting] which might be enough depending on the attacker’s goals,” Gross said in a statement.

Attackers infect millions of Android phones with fake Samsung app

A suspicious third-party app called “Updates for Samsung” had more than 10 million download attempts to trick Android-based Samsung phone users into paying for their firmware updates. According to a report from CSIS Security Group, the original Updates for Samsung app was meant to provide operating updates for free. But the hackers used the fake application to infect the users’ devices with malicious codes after downloading the fake application.

Detailing how the app worked Aleksejs Kuprins, a security researcher at CSIS Security Group, said “The app is called Updates for Samsung and pledges to deliver any OS update for any Samsung device ever released. It also offers to unlock phones regardless of the network operator and provides Android-related content from the developer’s website, updato[.]com,”

“Besides being stuffed with advertisement frameworks and not being affiliated with Samsung (yet distributing their firmware), the app offers paid subscriptions for the downloads of the said firmware. A user can get an annual subscription for Samsung firmware update downloads for a small fee of $34.99.  Interestingly, that doesn’t happen through the official Google Play subscriptions,” he added.

Recently, security researchers revealed an ongoing Android malware campaign dubbed ViceLeaker that has been active since 2016. According to the researchers from Kaspersky, a hacker group has been found targeting Israel citizens and other Middle East countries with surveillance malware named Triout.

The malware is designed to steal sensitive information, including call recordings, text messages, photos, videos, and location data without users’ knowledge. Apart from spying features, the malware also has backdoor capabilities, including upload, download, delete files, record surrounding audio, takeover camera, and make calls or send messages to specific numbers, according to the researchers. The researchers said that attackers used Smali injection technique, that allows hackers to disassemble the code of an original application and add malicious code.

Canonical’s GitHub account hacked

GitHub

Canonical, the maker of the Ubuntu operating system, recently revealed that it has suffered a hacker attack. In an official statement, the company stated that hackers have compromised its GitHub account, a code-sharing site, on July 6, 2019, and created 11 new repositories. It’s believed that the attackers apparently didn’t access any sensitive information or manipulated source codes, ZDNet reported.

“We can confirm that on 2019-07-06 there was a Canonical owned account on GitHub whose credentials were compromised and used to create repositories and issues among other activities. Canonical has removed the compromised account from the Canonical organization in GitHub and is still investigating the extent of the breach, but there is no indication at this point that any source code or PII was affected,” the Ubuntu said in a Twitter post.

The security officials at Ubuntu stated they’ll publish an update to its customers once it finishes the investigation into the security incident. “Furthermore, the Launchpad infrastructure where the Ubuntu distribution is built and maintained is disconnected from GitHub and there is also no indication that it has been affected,” it added.

Github faced a similar issue when a Chinese drone maker Da-Jiang Innovations (DJI) landed itself into a cybersecurity row over a bug bounty issue. On November 21, 2017, Kevin Finisterre, an independent security researcher, claimed that he found a private key publicly posted on code sharing site Github, after which he was able to access confidential and sensitive customer information and saw “unencrypted flight logs, passports, drivers’ licenses and identification cards.”

After discovering the flaw in the security system, he approached the firm that in-turn initially offered a bug bounty reward of up to $30,000 (£23,000) and offered to hire him as a consultant. Finisterre also claimed that the company tried to make him sign a non-disclosure legal contract, that he refused to sign. The Next Web reported that DJI threatened to charge him with the Computer Fraud and Abuse Act (CFAA).

IBM closes Red Hat acquisition for $34 billion

IBM

In what can be called as one of the largest tech acquisitions of all time, IBM acquired the cybersecurity company Red Hat in a cash deal of around $34 billion. The computer manufacturing giant stated the acquisition will help it to adopt cloud-related technologies and securely move all business applications to the cloud.

According to the acquisition deal, IBM will maintain Red Hat’s open source innovation legacy and Red Hat will work as a separate unit within IBM’s hybrid cloud team. Together, IBM and Red Hat help clients create cloud-native business applications faster, drive greater data security with consistent cloud management.

“Businesses are starting the next chapter of their digital reinventions, modernizing infrastructure and moving mission-critical workloads across private clouds and multiple clouds from multiple vendors,” said Ginni Rometty, IBM chairman, president and CEO. “They need open, flexible technology to manage these hybrid multicloud environments. And they need partners they can trust to manage and secure these systems. IBM and Red Hat are uniquely suited to meet these needs. As the leading hybrid cloud provider, we will help clients forge the technology foundations of their business for decades to come.”

“When we talk to customers, their challenges are clear: They need to move faster and differentiate through technology. They want to build more collaborative cultures, and they need solutions that give them the flexibility to build and deploy any app or workload, anywhere,” said Jim Whitehurst, president and CEO, Red Hat. “We think open source has become the de facto standard in technology because it enables these solutions. Joining forces with IBM gives Red Hat the opportunity to bring more open source innovation to an even broader range of organizations and will enable us to scale to meet the need for hybrid cloud solutions that deliver true choice and agility.”

Cybersecurity firm Palo Alto Networks recently announced the launch of Palo Alto Networks Cybersecurity Academy in collaboration with IBM Canada and the British Columbia Ministry of Education. The Santa Clara-based company stated the latest facility is intended to bridge the skills gap by preparing students for careers in cybersecurity.

The 12-month academic program gives students, across selected high schools in British Columbia, hands-on training on evolving cyber threats and how to prevent them. The special curriculum, jointly designed by Palo Alto Networks, British Columbia’s Ministry of Education and IBM Canada, focuses on firewall installation, antivirus software, zero-day vulnerabilities, and other security skills. Founded in 2005, Palo Alto Networks covers several segments like firewalls, cloud-monitoring and compliance, endpoint protection, and threat detection services.

Menlo Security raises $75 million to accelerate growth

Startup funding

Cloud security provider Menlo Security recently secured $75 million in a Series D funding round led by JP Morgan Asset Management along with the participation from the existing investors General Catalyst, Sutter Hill Ventures, Osage University Partners, American Express Ventures, HSBC, JP Morgan Chase, and Engineering Capital. Along with the investment, Jonathan Ross, the portfolio manager and managing director at JP Morgan Asset Management, is going to join the company’s board.

The Palo Alto-based company stated the new proceeds will support the company’s vision that focuses on cybersecurity protection for enterprises and Government agencies from malware and phishing attacks.

Menlo Security protects organizations from cyber threats by eliminating malware from the web, documents, and email applications. The company claims that its clients are from Fortune 500 like General Catalyst, Sutter Hill Ventures, Engineering Capital, Osage University Partners, American Express Ventures, Ericsson Ventures, HSBC, and JP Morgan Chase.

“Menlo Security’s innovative security solution protects against threats and attacks that bypass many advanced security products used by companies today,” said Jonathan Ross, portfolio manager and managing director at JP Morgan Asset Management. “Menlo Security’s solution delivers a Zero-Trust Internet by keeping all email and web content off of end user computers and devices, thereby seeking to eliminate malware attacks from these prominent threat vectors.”

“Menlo Security’s global cloud is protecting millions of end users, isolating over 500 million websites per day,” said Amir Ben-Efraim, CEO of Menlo Security.  “While our customers have deployed the most advanced security products, we see a constant stream of phishing and malware attacks evading their defenses. Menlo Security stops these attacks, validating Internet Isolation as being essential to modern security architectures.”

 

NTT Security acquires application security provider WhiteHat Security

NTT

NTT Security, an end-to-end cybersecurity solutions provider, recently announced that it has completed the acquisition of WhiteHat Security, an application security provider committed to securing applications that run enterprises’ businesses. The latest acquisition strengthens NTT Security’s ability to address the security needs of enterprises that range from IT infrastructure to critical business applications, covering the full lifecycle of digital transformation.

The acquisition expands NTT Security’s portfolio, allowing its customers and partners to benefit from WhiteHat Security’s industry-leading, cloud-based application security platform. WhiteHat’s customers and partners will have access to NTT Security’s consulting and advisory services, along with their next-generation platform based Managed Security Services.

WhiteHat provides services that are required for organizations to secure the entire software lifecycle (SLC) from the development through deployment and operation. The WhiteHat Application Security Platform technology solutions include Software Composition Analysis (SCA), Static Application Security Testing (SAST), and Dynamic Application Security Testing (DAST).

“With the cyberthreat landscape constantly growing and applications being central to digital businesses, application security is more important now than ever before. As part of the NTT Security family, we are well-equipped to provide global solutions to meet the rising demand for application security,” said Craig Hinkley, CEO, WhiteHat Security. “The WhiteHat Security team looks forward to the next phase of our journey. Our customers, partners and the market continue to appreciate the strategic nature of this acquisition and the combined cybersecurity solutions we can now offer.”

“At NTT Security, our goal is to provide comprehensive, game-changing cybersecurity solutions that address the broad needs of digital transformation. With the acquisition of WhiteHat Security, we are now able to offer the full spectrum of cybersecurity solutions to protect digital businesses,” said Matthew Gyde, CEO, NTT Security. “We look forward to formally welcoming the global WhiteHat Security team and its impressive customer-base to NTT Security.”

Recently, WhiteHat Security announced its partnership with the U.S.-based IT outsourcing services provider Rural Sourcing to offer enhanced solutions to identify and remediate application level exposures.

The new alliance will integrate the SaaS-based WhiteHat Application Security Platform with Rural Sourcing’s vulnerability remediation services to alleviate the challenges of DevSecOps and help organizations in digital transformation.

Data Privacy on Your Mind? Tips to Secure Employee Data

Employee habits

By Chaitanya Peddi, Co-founder, Darwinbox

The implementation of GDPR norms in the past year has led to an industry-wide discussion regarding data privacy and the idea of data collection in public and private spaces. Among these spaces, organizational workplaces have emerged as a prime focus area, given the importance given to monitoring employee efficiency. The integration of technology within this space to aid in this form of surveillance has led to the collection and storage of vital employee data. It is this data that is now in jeopardy as multiple stakeholders raise the question of data privacy and security at the workplace. The need of the hour is for organizations to analyze their internal as well as the industry scenario to determine the best practices that can address this question.

Understand your data

The first step to be adopted is for companies to categorize the data that is captured and stored in their servers. According to GDPR standards, information deemed ‘sensitive’ includes personal aspects such as financial details, elements of identity and legal information as well as professional aspects such as company blueprints and details of inner workings. With respect to employee data, the former takes greater precedence as this information is normally entrusted by the employees to the company, making them responsible for its protection. The access to this information must be defined based on the data requirements of the role requesting the information. For example, social security information such as Aadhar cannot be mandated unless a use case for the data is established.

Construct an organized policy framework

The analysis of the data possessed by the organization directly feeds into the next step where these insights are used to create valid data policies for the firm. This involves looking at the timeline of data usage and removing it from the system when it is no longer valid. This ensures that in the vent of a breach, lesser damage is incurred due to proper data disposal. The first step to creating an organizational policy document is the understanding of the business compliance. Legal aspects must be ironed out and regulatory and reputational obligations must be considered. Each of these activities will ensure that the final document acts as a set of guidelines in key areas such as consent, access and breach management.

Ensure awareness across all stakeholders

Once this document has been created, every member of the organization must be made aware of its provisions. This involves being transparent and explaining the process of data collection to the employees, detailing what information is being recorded and for what purpose. By clearly stating the advantage using this data will have for the employee, the company helps create a more conducive work environment for all stakeholders. Those who handle the collected data must also be trained to process it in a manner that is in compliance with the protection obligations. Another advantage of doing so ensures that all data sharing remains consensual, an idea that the Indian government too espouses, as shown by the Supreme Court judgement in 2017.

Getting security right

While obtaining consent and compiling data is a massive endeavor, the subsequent step in the timeline is just as massive and important: data security. Ensuring both systems and processes are structured with the best interest to protect data becomes most critical. Organizations will need to thoroughly evaluate primary systems of record with respect to their ability to protect employee data.  Some of the certifications that can help with this verification process are ISO 27001 (information security), GDPR compliance (legal information processing) and SOC 2 compliance (cyber protection). Both organizations internal processes and the HR technology solutions holding employee data should comply with these certifications to ensure safety.

Combatting data leaks

Certifications aside, one of the most pressing data threats that organizations must fight today is the theft/leakage of data, by internal staff especially in many cases. Access management systems in such situations must guard against unauthorized access by strengthening security checks. Along with this, companies must establish regular data backups for disaster recovery and also assess vulnerability of their systems from time to time. One should understand if their systems have undergone a VAPT (vulnerability assessment & penetration testing) test in the last 6 months to safeguard their data from threats.  Ensuring data compliance once these policies and technologies are deployed will also ensure security remains a priority at all times.

Conclusion

As companies continue to navigate an increasingly digital landscape, data privacy will come to be a determining factor in the push for growth and success. HR departments in particular must be cognizant of the industry scenario and adopt best practices to ensure their employee’s data is not compromised. The evolution of internal data policies and measures is a necessity now and the efforts taken by companies today will determine the path the industry will take in the near future.

The opinions expressed in this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Marriott International faces $123 million GDPR fine

Marriott International’s Data Breach Exposes Records of 5.2 Million Guests

The UK’s Information Commissioner’s Office (ICO) has imposed a £99,200,396 ($123,705,870) fine on Marriott International, a popular hospitality group, for the data breach reported in 2018. The ICO stated that Marriott has failed to protect its customers’ information, thus violating the EU’s General Data Protection Regulation (GDPR) regulations.

Marriott faced a massive data breach affecting up to 500 million guests last year. Hackers extracted people’s personal data as well as a loyalty program, payment, and reservation information. That’s not all, encrypted credit card data of 100 million customers was also stolen.

The first breach originated in 2014 at Starwood, which was acquired by Marriott International in 2016. It was uncovered after four years in September 2018, when a security tool alerted about an unauthorized data access. Consequently, the company faced a class-action suit, and its shares also fell around 5.6%.

According to the investigation, hackers stole 383 million guest records, 18.5 million encrypted passport numbers, 5.25 million unencrypted passport numbers, 9.1 million encrypted payment card numbers, and 385,000 card numbers that were still valid at the time of the breach.

“The GDPR makes it clear that organizations must be accountable for the personal data they hold. This can include carrying out proper due diligence when making a corporate acquisition and putting in place proper accountability measures to assess not only what personal data has been acquired, but also how it is protected,” said Elizabeth Denham, the Information Commissioner. “Personal data has a real value so organisations have a legal duty to ensure its security, just like they would do with any other asset. If that doesn’t happen, we will not hesitate to take strong action when necessary to protect the rights of the public.”

“We are disappointed with this notice of intent from the ICO, which we will contest,” said Marriott International’s President and CEO, Arne Sorenson. “We deeply regret this incident happened. We take the privacy and security of guest information very seriously and continue to work hard to meet the standard of excellence that our guests expect from Marriott.”

The proposed fine on Marriott comes a day after the ICO announced a £183.39 million ($230 million) GDPR fine against British Airways. The proposed fine relates to a data breach notified to the ICO by British Airways in September 2018, that exposed around 500,000 customers’ personal information.

The ICO said its investigation found that the breach compromised customer details, including login, payment card, name, address, and travel booking information which is collected after being diverted to a fraudulent website. The data breach, which began in June 2018, occurred due to the poor security measures to protect customer information, ICO stated.