Home Blog Page 315

Nearly 140 million user data leaked in Canva hack

Ransomware gangs

Australian online design tool, Canva, is the latest to join the bandwagon of victims of cyber attacks after hackers penetrated into the systems and stole data of nearly 140 million users.

The company stated in a release that usernames and email addresses of customers were accessed as part of the hack which occurred on May 24. On the bright side, the passwords remain encrypted, thereby being unreadable to external parties. A majority of users use Google and Facebook accounts to log in to passwords. According to the firm, even these credentials remain unreadable as they were encrypted like the former. But, as a precautionary measure, the startup has asked customers to change their passwords at the earliest.

Also, no credit card details or designs were accessed by hackers in the attack. “As soon as we became aware, Canva immediately took steps to determine the nature and scope of the problem, and alerted law enforcement,” read a statement from Canva. “We are working with a forensics team that specializes in these types of attacks and the FBI to diagnose exactly what happened and are putting processes in place to help prevent another attack. We are committed to protecting the data and privacy of all of our users and will be implementing every possible safeguard to ensure this doesn’t happen again.”

Canva had recently acquired stock photo companies Pexels and Pixabay, and also had recently raised $100 million in funding. Currently, the firm is valued at $3.6 billion. Launched in 2012, the company currently has millions of users strewn across in nearly 180 countries. According to Canva, users create 10 design every second using their online design tools.

Amid this, Canva has also been criticized by cybersecurity experts for the way it handled the attack and notified the customers. The statement from the company about the hack began with the news of the company’s latest acquisitions and then went on to notify the customers about the attack as a side note. Several experts have called it a marketing fluff.

Sigmadots partners with Telit to strengthen IoT cybersecurity

Collaboration, partnership, alliance, KnowBe4 and Agari Partner to Prevent Identity-Based Email Attacks

Cybersecurity startup SigmaDots, a subsidiary of Essence Group, recently partnered with Telit, a global enabler of the Internet of Things (IoT), to expand IoT security and strengthen business continuity. Essence Group is a provider of LTE-based connected devices and IoT platforms.

SigmaDots provides distributed cybersecurity solutions to IoT ecosystems using advanced blockchain technology. The company claims that it’s the first to develop blockchain-based cybersecurity solutions for IoT and IIoT systems.

Telit provides Internet of Things (IoT) enablement, with a portfolio of wireless connectivity modules, platforms, virtual cellular IoT operator services, and professional services. The new partnership allows both the companies to use the blockchain technology for routers, control panels, IoT gateways, and a host of IoT devices, reducing vulnerabilities to cyberthreats.

Commenting on the new alliance Alon Segal, the SVP of Software & Services at Telit, said, “The ubiquity of IoT devices makes them attractive targets for cyber mischief,”. “Our collaboration with SigmaDots adds another layer of security and communications resiliency using distributed technologies to offer advanced, secure infrastructure solutions for our customers.”

“IoT is finally delivering on its promises of complete connectivity – wearables, mobile apps, home safety, smart meters and in industry – generally anywhere” said Itsik Harpaz, General Manager of SigmaDots. “However, this connectivity brings significant threats – an attack on a single device can spread throughout the entire network.”

“SigmaDots technology was developed out of the need to strengthen the security of our IoT devices,” said Dr. Haim Amir, CEO and founder of Essence Group. “We’ve been creating innovative connected device solutions for more than 25 years, so we fully understand the challenges and the necessity of creating airtight cyber protection.”

One Plus 7 Pro hacked using a rather simple method

One Plus has often been touted as the flagship killer and the subsidiary of Oppo has always lived up to its name for several reasons including build, cameras, display, speed with value for money topping it up.  With that in mind the latest outing from the smartphone maker, One Plus 7 Pro, the flagship of flagship killers came loaded with everything you could have ever asked for, but also came with a lofty price the purist fans were not so used to. Nevertheless, the 12 GB version indeed continues to be one of the best One Plus phones to ever roll out. But then, soon after the launch, came the biggest security hindrance.

The One Plus 7 Pro like several other phones is almost bezel-less, has one of the best in class pop out selfie cameras and also has an on-screen or under the screen, whichever you prefer calling it, fingerprint unlock. It seems like device security wasn’t always the forte for the brand. The new One Plus 7 Pro is no exception as well.  Days after the phone was launched, someone has managed to hack the fingerprint scanner. And all the One Plus 7 Pro need was a gum fingerprint. The host of the Max Tech video used a hot-glue gun, tinfoil, some white school glue, and made a gum fingerprint to unlock the phone and voila the phone was unlocked. The method is one of the oldest fingerprint hacking technique.

In the same video, he explains how Samsung Galaxy S10+ did not let the fingerprint bypass using the same technique, but both the One Plus 6T and 7 Pro were pretty easily hacked. And with a pop-up camera for One Plus 7 Pro to detect faces, it is all the more evident that people will be using fingerprint more than facial recognition. And this is something One Plus should have kept in mind.

In 2017, when Samsung had just launched an iris scanner for the S8, it was also a big let down after researchers staged a rather simple technique to hack the phones. All the researchers at Chaos Computer Club needed was a picture of the eye and a pair of contact lenses. The researchers first registered a volunteer’s eyes using the iris scanner. They then took a photograph of the volunteer’s eyes with infra-red night vision settings on a digital camera. In the next step, they printed the photograph of the eyes and placed a contact lens over it. And lo, the biometrics-enabled smart security feature was hacked. As the trick bypassed the security test. Like the One Plus 7 Pro, the research team also posted a video of the hack using the false eye, which was now trending at that time.

GDPR: One year down the line

GDPR Fines

Contributed by Anil Chiplunkar

General Data Protection Regulation (GDPR) is the regulation established by the European Union with the main intention of protecting personal information of EU citizens. It empowers the citizens, ‘data subject’ as referred in GDPR, to decide who use the citizen’s personal information, how, for what purpose and how is kept secured.

In nutshell, the General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679)

  • Regulation by the European Parliament, the Council of the European Union and the European Commission
  • To give control to citizens and residents of EU over their personal data
  • To strengthen and unify data protection for all individuals within the EU
  • Covers export / transfer of personal data outside the EU
  • To simplify the regulatory environment for international business by unifying the regulation within the EU

Timelines

  • The regulation was adopted on 27 April 2016
  • It is enforced on 25 May 2018

Penalties for Non-compliance

  • Up to EUR 20 Million or 4% of Global turnover, whichever is higher

Considering multiple requirements within the GDPR and the fact that this rule is already enforced, business organizations have started working towards achieving compliance. A systematic approach is required for identification of data to be protected, privacy impact assessment and implementation of various operational, technical, procedural and human related controls.

In order to devise the approach, it is required that the key definitions and requirements within GDPR should be understood. Following are some key definitions: (These can be put in box / column / as a call-out text)

  • Natural Person and Legal Person:

In jurisprudence, a natural person is a person (in legal meaning, i.e., one who has its own legal personality) that is an individual human being, where as a legal person, which may be a private (i.e., business entity or non-governmental organization) or public (i.e., government) organization

  • Personal data:

“Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.

  • Sensitive Personal Data:

“Sensitive Personal Data” are personal data, revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership; data concerning health or sex life and sexual orientation; genetic data or biometric data. Data relating to criminal offences and convictions are addressed separately (as criminal law lies outside the EU’s legislative competence).

  • Processing:

“Processing” means any operation or set of operations performed upon personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

  • Controller:

“Controller” means the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by EU or Member State laws, the controller (or the criteria for nominating the controller) may be designated by those laws.

  • Processor:

“Processor” means a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller.

  • Pseudonymisation:

Means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person

  • Consent:

“The consent of the data subject” means any freely given, specific, informed and unambiguous indication of his or her wishes by which the data subject, either by a statement or by a clear affirmative action, signifies agreement to personal data relating to them being processed.

  • Personal Data breach:

“Personal Data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

  • Binding corporate rules:

Means personal data protection policies which are adhered to by a controller or processor established on the territory of a Member State for transfers or a set of transfers of personal data to a controller or processor in one or more third countries within a group of undertakings, or group of enterprises engaged in a joint economic activity.

  • Data concerning health:

“Data concerning health” means personal data relating to the physical or mental health of an individual, including the provision of health care services, which reveal information about his or her health status. It expressly covers both physical and mental health.

  • Genetic Data:

Personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question

  • Biometric Data:

Personal data resulting from specific technical processing relating to the physical, physiological or behavioral characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data

Key principles for data processing

  • Processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’);
  • collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes;
  • adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimization’);
  • accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’);
  • kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed
  • processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures (‘integrity and confidentiality’)

The controller shall be responsible for, and be able to demonstrate compliance with the above principles (‘accountability’)

High-level approach for achieving compliance

The organizations should identify what kind of personal data is collected as part of business operations and then perform an assessment to identify ‘as-is’ conditions related to the GDPR compliance requirements. This will enable to prepare the plan for establishing and implementing processes, technical and other controls to achieve the GDPR compliance.

The organization should look at following areas for the ‘as-is’ or current state assessment and planning for next steps towards compliance:

  • Data Privacy Impact Assessment (DPIA)
  • Governance documentation (including data privacy policy, information security policy, data subject rights etc.)
  • Technical and Operational Measures to protect the data including
    • Accountability
    • Privacy by design
    • Security
    • Policies and procedures
    • Awareness at all levels across the organization
  • Management of data subject consent including withdrawal of consent
  • Data transfer processes
  • Data retention policies
  • Adherence to rights of data subjects
    • Data subject access request
    • Data subject correction request
    • Data subject ‘rights to be forgotten’ request
    • Data subject objection to automatic processing of data
  • Management of data breach (privacy breach)
  • Agreements with third parties, if any, to ensure similar controls are covered as part of the agreements
  • Periodic verification / assessment post implementation of GDPR related policies, procedures, controls etc. to ensure the continuance of compliance

 

1 Year post GDPR enforcement

Quite a few organizations have devised processes and implemented controls to achieve the compliance to GDPR and the major reason seems to be the consequences the organization might face due to non-compliance. There are few organizations who got penalized under GDPR or similar EU country specific data privacy regulations. A €50m fine for Google from the French data protection authority as reported by ZDNet; Facebook was under the scanner for possible GDPR violence by UK Information commission office (ICO); Microsoft Telemetry was reported to be having GDPR concerns by the Dutch authorities etc. So the effect or impact of GDPR is getting visible and organizations need to look at this seriously.

As reported by Alpin.io, following are some of the fines issued under GDPR non-compliance:

 

Impact in APAC

Since GDPR is applicable across the globe, any organization dealing / handling EU residents’ personal data (personally identifiable data or personal health information) or offering services within EU are subject to GDPR regulations. So the organizations within APAC also are no exceptions to this. According to my knowledge, there are no non-compliances to GDPR reported as of date from an APAC based organization. However, the organizations in APAC should not overlook the compliance. In some of the recent conferences few views were expressed such that for the APAC organizations, the enforcement or compulsion to meet GDPR requirements would be mainly from the EU counterparts rather than directly the regulators. So, it would become prudent for the APAC organizations to implement necessary processes, controls to achieve the GDPR related compliances.

Although the impact is not yet visible as part of ‘penalties for non-compliance’, but the organizations need to invest in people, processes, technology and time to ensure they achieve the required level of compliance to GDPR.

Following are few areas where the organizations will need to invest:

  • Get GDPR related competencies
    • Organizations need to have personnel with required competencies to implement GDPR requirements. These personnel can be hired from outside or people can be trained within the organization. In either of the options, the organizations need to invest time and costs to acquire these competencies.
  • Identification of ‘data to be protected’ and implementing controls
    • Organization will need to set up process to identify the ‘data’ which needs protection under GDPR
    • It may need to invest in tools to automate certain part of the process and provide protection based on the identification of the required data
    • Tools required for encryption, pseudonymisation etc. for protecting data privacy (as advised in GDPR)
  • Training across the organization
    • All the stakeholders including senior management and employees needs to be trained on GDPR so organization will need to invest in imparting this training either through internal resources or can outsource this training
    • Organization will also need to periodically conduct refresher program to ensure all are up-to-date with the requirements of GDPR and related privacy rules
  • Third party contracts
    • It is important that the organization need to ensure all the third parties, contractors, consultants etc. who interact / handle the GDPR related data / processes are also in compliance with the requirements. This would involve revising all related contracts to include the GDPR code of conduct
    • To add GDPR terms in the contracts, organization will need to engage internal or external legal expertise that would require investment of time and money
    • Organization would also require to ensure that the third parties, sub-contractors, consultants are adhering to the revised requirements / terms and for this organizations will need to conduct periodic compliance assessments either through internal mechanism or through external agencies
  • Data subject rights
    • Mechanism need to be established for obtaining consent from the data subject which will involve privacy notices / disclaimers etc.
    • Processes need to be implemented for full-filling the requests from data subjects (Refer to ‘rights of data subjects’)
  • Data privacy breach notification and investigation
    • The timeline for notification of breach are comparatively stringent such as 72 hrs from the incident getting noticed so organizations need to set-up processes, tools etc. for identification, notification and responding to data privacy breach
    • People will need to be trained and responsibilities assigned for the same (including dealing with EU authorities)
    • Mechanism should also be established for communicating the information about the breach to the stakeholders including the data subjects who are impacted due to the breach
    • Communication channels and responsibilities need to be assigned to ensure all relevant entities get the required information about the breach / incident and the action plan, as required
  • Assigning a role of Data Protection Officer (DPO)
    • Organization will need to assign the role of DPO to an individual within the organization or can engage with a third-party provider to shoulder the DPO responsibilities
    • One of the essential requirements for DPO is that the DPO should have competencies in data privacy rules and practices; so essentially the legal competencies in this area
  • Having a representative in EU who will be able to communicate with the EU regulators / authorities
    • Organizations within APAC will need to have an EU representative who would be co-ordinating with local EU authorities for all the GDPR related compliance requirements

Considering the above areas, it can be noted that although the ‘direct impact’ of GDPR is not yet visible within APAC organizations, but the investment in all of the above-mentioned areas will need the organizations to sanction separate budget for the same. Some of the surveys / studies done for APAC organizations, who have their data centres or have hired data centre services, indicate that only 12% of the organizations have implemented reasonable level of compliance to GDPR. Looking at the global scope of GDPR, it is essential for organizations outside EU, to ensure the necessary compliance is achieved. Number of countries within APAC, like Philippines, Singapore, South Korea, Malaysia etc., have country specific data privacy / data protection laws so for the APAC organizations it is required to meet the compliance to ‘law of the land’ and also to align the practices to meet GDPR compliance if the organizations are handling data of EU residents.

To summarize, APAC organizations need to move quickly to achieve the GDPR compliance because cost of non-compliance could be far greater than achieving compliance.

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Singapore issues new guidelines on Data Breach Notification and Accountability

Singapore cybersecurity bill

In order to boost cybersecurity and tackle next-generation cyber threats, the Singapore government recently updated the guidelines on data breach notification and accountability. Unveiled by the Personal Data Protection Commission (PDPC), the new guidelines are intended to help companies manage data breaches more effectively.

As per the new procedures, which are expected to be included in the upcoming data protection act, the companies in Singapore should not take more than 30 days to complete an investigation into a suspected data breach. The companies are also required to notify the authorities about the incident before 72 hours after discovering a data breach.

The PDPC stated the businesses are required to notify authorities if a breach affects more than 500 individuals. The data intermediaries also need to report potential data breaches to their parent organization within 24 hours after identifying a security incident.

In addition, the PDPC also introduced three initiatives to support innovation and strengthen accountability among organizations – Establishing public consultation to seek opinions on proposed data portability and data innovation provisions, Introducing a new guide on Active Enforcement to drive for organizations shift from compliance to accountability, and an updated guide to managing data breaches.

“Data is a key enabler of digital transformation, but a balance must be achieved between data protection and business innovation. We are taking firm steps to position Singapore as a trusted data hub in the global Digital Economy by seeking feedback on the proposed data portability and innovation provisions, as well as test bedding data breach notification measures. The PDPC also recognizes the importance of being responsive and agile in enforcing data protection in an environment of fast evolving data use, coupled with sweeping technological advances,” said Yeong Zee Kin, the Deputy Commissioner of PDPC.

“Hence, the PDPC has converted its knowledge and experience in investigations to practical enforcement approaches in a Guide to Active Enforcement which businesses can refer to, and also updated the Guide to Managing Data Breaches,” Yeong added.

A recent research stated that cyber-attacks increased in the last 12 months, causing security breaches affecting 96 percent of Singapore businesses surveyed. According to the research report from endpoint security firm Carbon Black, 90 percent of the Singapore businesses have been breached in 2018. In its report named Singapore Threat Report, Carbon Black examined the survey results from different industries, organization sizes, and IT team sizes to show modern attacks and cyber defense landscape in Singapore region.

The Maritime and Port Authority (MPA) of Singapore recently announced the launch of its new 24/7 cybersecurity center, Maritime Cybersecurity Operations Center (MSOC). Inaugurated by Niam Chiang Meng, the Chairman of the Maritime and Port Authority of Singapore (MPA), the new center is operated by ST Engineering, a private contractor.

Designed to strengthen Singapore’s cybersecurity readiness through early detection, monitoring, analysis, and response, MSOC will conduct 24/7 monitoring services across all the port’s information infrastructure. The MSOC can detect vulnerabilities and potential threats by analyzing activities in the IT environment and respond with available technological solutions, according to the MPA.

Cybersecurity startup Hunters.AI emerges from stealth mode with $5.4 million funding

Startup Funding

Cybersecurity startup Hunters.AI recently emerged from stealth mode and completed a $5.4 million seed funding round led by YL Ventures and Blumberg Capital. The Israel-based startup stated the first investment will be used to accelerate growth.

Hunters.AI, also called as Cyber Hunters Ltd., is specialized in autonomous threat hunting. The company develops an autonomous system that connects to multiple channels within an organization and detects the signs of potential cyber-attacks, according to Uri May, the CEO of Hunters.

Founded in 2018, Hunters.AI says its cloud-based and autonomous solution platform is designed to help security professionals and security operations center (SOC) identify threats by collecting data from existing management, visibility, monitoring, and security tools. The company claims its security solutions platform unveils hidden breaches and security risks, including locations, paths, targets, and potential impact.

In a similar investment round, another Israel-based cybersecurity startup Perimeter 81 recently raised $5 million. Perimeter 81, a network security provider, stated the new funds will help to develop new cloud firewall capabilities and accelerate growth. The company is also planning to expand the company’s sales, marketing and R&D teams in its Tel Aviv and New York offices. The funding round was led by Spring Ventures and private US-based investors along with the participation of existing shareholders.

Founded by Amit Bareket and Sagi Gidali in 2018, Perimeter 81 is a Zero-Trust Software Defined company focussed on transforming the secure network access to the modern and distributed workforce. Perimeter 81 offers automatic gateway deployment, easy multi-tenant management, and full network visibility to enterprises. The company claims that its Software-Defined Perimeter solution securely connects employees to cloud-based and internal network resources.

“With Perimeter 81, we took our knowledge of what worked for the consumer market, and ultimately, the end-user, and transformed the complex and outdated technology that so many businesses rely upon, into a seamless and user-friendly SaaS service,” said Sagi Gidali, Co-Founder and CPO. With this new funding round, we look forward to expanding our reach and further enabling companies of all industries and sizes to become fully, securely mobile and confidently cloud-based.”

Siemens partners with Alphabet’s Chronicle

Siemens

Global engineering and technology firm Siemens recently partnered with Alphabet’s cybersecurity subsidiary Chronicle to protect the energy industry’s infrastructure from cyber threats. Chronicle is a cybersecurity intelligence and analytics platform aimed to filter and analyze constantly accumulating data for cyber threats applying Artificial Intelligence. Chronicle targets making security signals easily recognizable, thus increasing the data processing speed.

Siemens, the German-based conglomerate, said the new alliance integrates the Chronicle’s Backstory platform with Siemens’ cybersecurity tools​ to jointly provide industrial monitoring and detection for the energy industry. The Backstory is a cloud service used by various global companies to privately upload, store, and analyze their internal security telemetry to detect and investigate potential attacks.

The latest partnership gives energy customers unmatched visibility across the information technology (IT) and operational technology (OT) to provide operational insights and confidentially act on evolving threats. It also helps energy companies leverage the cloud to store and categorize data, by applying analytics, artificial intelligence, and machine learning technologies.

“The innovative partnership between Siemens and Chronicle demonstrates a new frontier in applying the power of security analytics to critical infrastructure that is increasingly dependent on digital technology,” said Leo Simonovich, Vice President and Global Head, Industrial Cyber and Digital Security at Siemens Gas and Power. “Cyber-attacks targeting energy companies have reached unprecedented speeds, and our cutting-edge managed service unlocks the analytics ecosystem offering a new level of protection from potential operational, business and safety losses.”

“Energy infrastructure is an obvious example of cyber-attacks affecting the physical world and directly impacting people’s lives,” said Ansh Patnaik, Chief Product Officer, Chronicle. “Backstory’s security telemetry processing capabilities, combined with Siemens’ deep expertise, gives customers new options for protecting their operations.”

Recently, the Chronicle partnered with ESET, a developer of IT security software and services, to provide essential validation on cybersecurity incidents and alerts.  As per the partnership deal, ESET uses Chronicle’s Backstory platform to offer enhanced data protection services. The Backstory is a cloud service used by various global companies to privately upload, store, and analyze their intern ESET, a developer of IT security software and services, al security telemetry to detect and investigate potential attacks.

The latest partnership will provide customers enhanced protection from advanced persistent threats. ESET provides industry-leading IT security software and services for enterprises and consumers globally. It also offers a range of solutions from the endpoint and mobile security, to encryption and two-factor authentication.

Software-defined perimeters challenge the corporate VPN on security

By Etay Bogner, CEO of Meta Networks

When it comes to network security, interest is heating up around software-defined perimeter solutions (SDP)—and for good reason.

The traditional approach that organizations have used for connection and protection, the perimeter-based VPN, has well-known shortcomings. These issues are leading to alternative solutions to the conventional VPN – especially as organizations migrate to the cloud amid growing concern for cloud security.

Let’s review several ways that VPN solutions have become the less effective options for business:

  • Security issues. Enterprises have become more vulnerable in this era of worker mobility and cloud migration, making it harder to effectively secure the perimeter. Traditional VPN access is overly permissive, granting remote workers access to more of the network than is required to complete their tasks. As a result, network resources are unnecessarily visible, overly vulnerable, and open to attack.
    Unreliable end-user experience. For anyone who has used a VPN, slow and unreliable performance is common. If you use applications in multiple locations, then you’ll face the aggravation of needing to repeatedly connect and disconnect—and of course you have to keep track of where you are connecting to, based on the app you need.
  • Administrative headaches. Whenever cloud migration is involved, VPN management balloons in complexity, leaving IT administrators to configure and sync VPN and firewall policies across multiple locations. This makes it even more difficult to eliminate unwarranted access.
  • Lack of affordable scaling. As organizations require additional user connections and deployments across multiple cloud instances, VPN/firewall costs escalate rapidly due to the need for additional licenses and more powerful appliances.
  • Flexibility, at a cost. VPNs do offer flexibility since they can be used to connect multiple sites, datacenters, and virtual private clouds (VPCs). However, these connection options can be resource-intensive and drive up costs.

 

You have likely already noticed the limitations of VPNs based on your organization’s own experience. Either way, the time has come to seek alternative solutions that are better suited to today’s mobile workers and hybrid environments.

With these realities in mind, it is no wonder that a growing number of innovative organizations are embracing software-defined perimeter solutions, which focus on the user and overcome the security and operational problems inherent in perimeter-based remote access.

A Comparison

Gartner notes that a Software-Defined Perimeter “defines a logical set of disparate, network-connected participants within a secure computing enclave. The resources are typically hidden from public discovery, and access is restricted via a trust broker to the specified participants of the enclave, removing the assets from public visibility and reducing the surface area for attack.” A key component of an SDP platform is that it securely enables remote access. Part of the power of SDP solutions—and what allows them to be more effective than traditional solutions—is that they are designed around user identity-based policies, which restrict access only to specified applications.

In other words, an SDP solution can enforce a customized policy for each user device. Any resource on the network that is unauthorized to a specific user is invisible to that individual, significantly reducing the potential surface for attackers. As Gartner has said, “SDP technology enables organizations to provide people-centric, manageable, ubiquitous, secure and agile access to networked systems, services, and applications.”

Let’s go head-to-head with SDP and VPN to better understand the advantages:

  • Better experience for end users. VPNs have a reputation for being slow and unreliable. In contrast, the new generation of SDP solutions offer a more transparent user experience. To assure high performance, the solution should be based on a dense network of PoPs around the world, for global user connectivity. Keep in mind that different types of users have different needs. For managed employee devices, an agent-based connection enables the user to work normally, while delivering always-on security, for the Internet as well as corporate applications. Alternatively, for unmanaged personal devices, and for contractors, partners and customers, a browser-based solution that requires no client or agent installation is ideal. With an SDP solution, end users can also be freed from the need for repeated, multiple VPN connections when they want to access apps located in different locations. One connection provides access to the applications you need, wherever they are.
  • Zero-trust remote access for users, isolation for the network. SDP solutions have several security advantages over VPNs. First, there are no trusted zones. The IT administrator must grant users explicit permission to access specific applications. Beyond these designated one-to-one connections that are created for user devices, all other network resources remain isolated from view and completely invisible. Some SDP solutions allow continuous authentication and verification of the user and/or device at the packet level using identity-based networking technology. Security isn’t left to chance; all network traffic is logged for audit and investigation.
  • Simple, as-a-service, solution. Compared to configuring and syncing VPN policies, you can onboard each network resource to an SDP platform once and manage all policies centrally in the cloud, avoiding the need to configure and sync across different locations. An advantage of a fully-cloud based SDP solution is that there is little to setup or maintain and upgrade in the data center or VPC that you are enabling access to. All of the intelligence as well as the security enforcement is done in the cloud.
  • Unlimited, cost-effective With cloud-native SDP solution, capacity is never an issue. Regardless of the number of users that need to connect or the number of applications that they need to access, the solution should scale automatically. There’s no need to sink additional time and funds into installing more powerful appliances.
  • Connect anything, without complexity. While VPNs are satisfactory at connecting clouds and datacenters, it can be complex and costly to do so. On the other hand, software-defined perimeters enable more efficient connectivity without the hardware and management resource requirements.

As you can see, there are substantial advantages to using SDP solutions over perimeter-based VPNs, with one of the biggest positives being improved security. VPNs and firewalls were designed for a site-centric world and are thus overly permissive in granting access to the corporate network. They also create vulnerability by exposing services to the Internet. In contrast, the innovative SDP network security model creates IT-assigned network connections between each user and only the specific resources that he or she needs to access. SDPs can also provide an integrated internet security stack so that users who work offsite need not sacrifice Internet security.

In the modern era where the common usage patterns include cloud applications, remote workers and insecure locations, trust-based network designs put the organization at risk. In contrast, the user-centric SDP approach provides assurance that any endpoint attempting to access an application gets properly authorized and authenticated before it even gets visibility to enterprise services.

In addition to improving security, SDP solutions also help address compliance and regulatory requirements by providing a comprehensive record of network usage and application access. With a world-wide, cloud-native platform, some SDP solutions are distributed and infinitely scalable, with the ability to leverage their advantages across all applications. At the same time, management costs and complexities are significantly reduced. All of this adds up to a true transformation—and a welcome alternative to VPNs and firewalls.

We, at CISO MAG, are set to publish the Power List, a comprehensive publication which will explore critical areas of cloud security while elucidating best practices to adopt for securing the cloud space. Ahead of it, we are discussing several trends and vendors in the space while we tell you what differentiates each product from the rest.

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

Hackers took the Baltimore city government hostage!

Regina police station hacking, hacking, email and passwords hacked

Several of the Baltimore city services were halted after a ransomware attack hit city computers. According to the news portal Baltimore Sun, hackers infected about 10,000 of Baltimore city government’s computers on May 07, 2019, with ransomware called RobbinHood. The attackers asked the city officials pay 13 bitcoins (about $100,000) to release the city’s systems, warning that price would go up every day after four days, and after the tenth day, the affected files would be lost permanently.

“We’ve been watching you for days and we’ve worked on your systems to gain full access to your company and bypass all of your protections,” the ransom note read.  “We won’t talk more; all we know is MONEY. Hurry up! Tik Tak, Tik Tak, Tik Tak!”

The authorities stated the attack taken the Baltimore city government hostage. The city government can’t access email accounts, parking fines database, process payments to employees and the citizens remain unable to make utility payments, property taxes, and vehicle citations.

“We established a web-based incident command, shifted operations into manual mode and established other workarounds to facilitate the continued delivery of services to the public. We continue to adjust and refine the delivery of those services that were only partly interrupted and to pursue ways to reactivate any services that were completely interrupted,” Baltimore Mayor Bernard Young said in a media statement. “We are well into the restorative process, and as I’ve indicated, are cooperating with the FBI on their investigation. Due to that investigation, we are not able to share information about the attack. To the extent that we can, we will continue to keep you informed about our process.”

Young added that they’ve informed the FBI and working with cybersecurity experts to resolve the issue and implement updated tools to ensure that it won’t happen again.

“Like any large enterprise,” Young explained, “we have thousands of systems and applications. Our focus is getting critical services back online and doing so in a manner that ensures we keep security as one of our top priorities throughout this process. You may see partial services beginning to restore within a matter of weeks, while some of our more intricate systems may take months in the recovery process.”

In a similar incident, the Los Angeles Times and several Tribune Publishing newspapers recently faced printing and delivery issues after encountering a cyber-attack that reportedly involved a ransomware. The Associated Press quoted the Chicago Tribune reporting that the publishing and printing systems of several Tribune Publishing newspapers were affected due to a computer virus. The Los Angeles Times reported that some people said the attacks appeared to be in the form of Ryuk ransomware.

The Chicago Tribune’s print edition on Saturday, December 29, 2018, was published without paid classified ads and death notices due to the attack. However, the publisher clarified that no customer and financial information was leaked.

Cloud security startup Guardicore raises $60 million

Nanocore Netwire AsyncRAT, Cloud security, cloud computing

Guardicore, a provider of internal data center and cloud security, recently announced that it has raised $60 million in a Series C funding round led by Qumra Capital along with the participation from the new investors DTCP, Partech, and ClalTech. Existing investors Battery Ventures, 83North, TPG Growth, and Greenfield Partners also participated in the investment round. Founded in 2013, GuardiCore develops and sells cybersecurity defense software for data centers and cloud systems.

The Tel Aviv-based cybersecurity startup stated the new investment will fuel its growth and accelerate investments in sales, marketing, and customer service. Guardicore is also planning to expand its security platform to enterprise organizations seeking to protect the dynamic data center and cloud infrastructure environments. The company claims that its security solutions provide a simpler, faster way to consistent security for any application and in any IT environment.

“Any organization has critical IT assets that need to be secured. Our distributed, software-defined segmentation solution is the simplest way to secure these assets whether they reside in the cloud or on premises. The days of being chained to legacy firewalls are over,” said Pavel Gurvich, CEO and co-founder of Guardicore.

“Since our last round of funding, we have successfully been able to articulate our vision and demonstrate that the market is ripe for disruption. With consistent revenue growth the past three years and large-scale deployments with numerous Fortune 500 customers, we have proven that our product is more intuitive, flexible, and makes security easier to apply than traditional firewall technology currently being used to protect internal and cloud infrastructure. We are displacing incumbent players and newcomers alike as we strive to help our enterprise customers quickly secure their business-critical applications and data, reduce the cost and burden of compliance and secure cloud adoption,” Gurvich added.