Home Blog Page 316

Security, Quality & Agility: Maintaining a balance!

UK-Cybersecurity

Contributed by Rajesh Laskary

Cybersecurity threats are evolving by every passing day and so the level of sophistication with which an attack can be planned, organized and executed. In the past organizations have been more focused around ‘Quality’ and less on ‘Security’. Now we are witnessing a shift wherein organizations have started considering ‘Security-By-Design’ in their products or applications alongside quality while embracing the ‘agility’ of fast-paced agile software development. What we need to keep in mind is, ‘Security’, ‘Quality’ or ‘Agility’ is not just about tools and processes, it’s more about a cultural change in an organization, understanding vulnerabilities, it’s about the change in the mind-set of people working for your organization to view things from a different angle.

The Plot:

Let’s assume a scenario (and trust me it’s omnipresent in one form or the other in every organization) before we start and let me set the background.

“ Your system/business analysts are always on their toes as business keeps changing the requirements and there is always a never-ending discussion taking place on the scope or the priority of a business requirement and hence your development teams are also under tremendous pressure with ever-changing scope or priority of business requirements, last-minute design changes, CI/CD (Continuous Integration and Continuous Delivery) issues, daily scrums and other meetings, pressure to deliver at a fast pace and in a short sprint etc.

Similarly, the Testing and Quality Assurance teams are testing something which they have just received late in the sprint, they have just encountered something that was changed and they were not aware of it till the very last moment, they haven’t yet finished their SIT (System Integration Testing) and sprint is about to complete and they do not have sufficient time to regression test the system or for performance testing. (Do you think they’ll have time to think of ‘Security’?)”

The ‘Security’ and the ‘Quality’ tussle:

‘Quality’ of the product has always been of utmost importance to any organization and now ‘Security’ has started sharing the time, resources and budget which once only belonged to ‘Quality’.

We’ve seen budget and resource constraints in the past while delivering a quality product and unfortunately quality/testing teams have always suffered from budget cuts, ratio of number of developers to testers/quality personnel has always been in midst of debate as most of the project managers most of their budget will be consumed in to product development itself.

Today when there are hundreds of players in market full of competition, organizations are not only shifting left and trying to fix the ‘Quality’ issues in early stages of the SDLC (System Development Life Cycle), they have already started considering ‘Security’ an integral part of their SDLC equally to ‘Quality’ while maintaining a pace with the ‘Agility’ of the agile project management.

This article tries to give an insight into today’s fast-paced organizational developments as to how Agility, Security & Quality should be seen or perceived together and not in silos.

Security is everyone’s responsibility, so the Quality is:

Few things to keep in mind, when you think about securing your information assets versus the quality of the product being developed.

o   You can’t secure ‘everything’, you shouldn’t and you won’t be able to but that does not mean you should leave everything in open.

o   On the same lines, There will be quality issues no matter how hard you test

o    Do consider that you’ll be hacked one day or probably you’re being hacked now as someone said, so keep a plan B ready.

o   You can’t always go behind the attacker and you shouldn’t.

o   Security is everyone’s responsibility but ensure the accountability is taken care of equally.

o   There are companies which were fined millions for a product quality issue or lost some reputation but there are companies that went bankrupt because of one security incident.

Shifting left, No matter it is Security or Quality:

If ‘quality’ is ‘right’ when you’re on the steering wheel, ‘security’ is to your ‘left’. You need to take both into account while you’re on a driver’s seat and decide whether to take a left or right at each turn depending upon where you’re heading to. Shifting left is not just about moving left on the project timeline or to move to earlier stages of your System Development Life Cycle, it also means going back to the basics and doing the right thing, at the right time (when it is needed the most). A defect (be it a security issue or a quality issue) identified in early development phase will save you an enormous amount of money and resources.

Agility will impact both Security and Quality:

Now after all this how confident you are on quality or the security of the product? Do you know what issue can be left untested, what security requirements were missed (maybe not at all considered in the first place), maybe not developed at all (or even if developed, the developer left some back doors or did not implement a certain portion of it due to time pressure), or who knows if security requirements were considered by system analysts, developed and implemented by developers, tested by testers BUT still are you sure that there will be no quality issue in production or there won’t be any security incident due to a bug which was never revealed during SDLC?

While ‘Agility’ is like an ‘Accelerator’ of a running car, ‘Security & Quality’ can be compared to ‘Breaks’ and a balance must be maintained with an equal focus on both on each stage of product development. There is no harm in slowing down, taking a pause for a moment and take a cognitive decision in the direction you’re heading to.

What’s your plan ‘B’ for ‘Security incidents’ and for ‘Quality issues’ and where does it all overlap?

Everyone can be and everyone will be hacked one day or the other or there is a high probability it’s happening now. It’s just that you don’t know when it will happen. There will be quality issues, bugs once an application or a change is deployed to the production environment and there will be security incidents no matter how hard you test or how strong your quality or security processes are. So does that mean we should not be testing enough or we should not build enough security controls in our systems? How much enough is ‘enough’?

o   What is your project budget?

o   How much of the budget, time and resources should you allocate for product quality & how much for security testing?

o   Is it possible to combine both?

o   How does the SDLC process ensure that quality and security go hand in hand and there are controls in place to validate both?

o   What is the criticality of information the system is handling?

o   Is it an internal application or an internet facing?

o   What could be the potential impact of a quality issue?

o   What could be the potential impact of a security incident?

o   And, many more such basic questions.

Once you have answered the above questions, the immediate next question is, what is your plan ‘B’ if any of quality issue or security incident take place? And, how does plan ‘B’ addresses the impacts at following fronts:

o             Customer

o             Reputation

o             Regulatory

o             Legal

o             Financial

The One Perfect Solution:

There is no perfect solution to any of the problems mentioned above and the focus should always be on the best available solution and the most optimum one catering your security and quality needs. While thinking of a solution, one thing that is of the paramount importance is that the change should always begin at the top and both quality and security should be endorsed equally by the ‘C’ level while maintaining the agility in the organizational processes.

Yes we know a lot about quality, however, we can always balance it with security by:

o   Bringing a cultural change and including security in the organizational processes.

o   Security training and awareness among all the employees.

o   Imbibe the security requirements in early system design and ensuring that security is integrated into the development process.

o   Building, implementing and validating security controls in each phase of SDLC.

o   Training and educating the developers on best application security practices or secure system development.

o  Training the testers on basics of cybersecurity and security testing.

o  Automate as much as possible.

The resources should be deployed to ensure that there are no controls remaining which have not been validated thoroughly. We cannot completely eliminate a risk (and we should not try to) but we can definitely lessen the impact on the organization. And most importantly ‘Bring-Security-In’ before you plan to ‘Build-Security-In’.

We at CISO MAG are set to publish the Power List, a comprehensive publication which will explore critical areas of cloud security while elucidating best practices to adopt for securing the cloud space. Ahead of it, we are discussing several trends and vendors in the space while we tell you what differentiates each product from the rest.

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Instagram data breach! 49 million users’ sensitive data exposed online

Another data leak in Facebook’s timeline. This time it’s the Facebook-owned photo-sharing application Instagram. An unprotected server containing personal information of millions of Instagram influencers, celebrities, and brand accounts have been found online, the TechCrunch reported.

According to the security researcher Anurag Sen, who discovered the leak and notified TechCrunch, the database had over 49 million records exposed online, allowing anyone to access. The exposed data included users’ biodata, profile picture, the number of followers they have, their location by city and country, and contact information like the Instagram account owner’s email address and phone number.

Anurag stated the leaky database belongs to a social media marketing firm Chtrbox, which is based in Indian state Mumbai. The database was taken offline and called for an investigation on the incident, Chtrbox stated.

Commenting on the security breach Facebook said, “We’re looking into the issue to understand if the data described – including email and phone numbers – was from Instagram or from other sources. We’re also inquiring with Chtrbox to understand where this data came from and how it became publicly available.”

A week ago, Facebook-owned messaging application WhatsApp revealed that it discovered a vulnerability in its network system that allowed hackers to install spyware via an infected WhatsApp voice call. The social messenger stated the spyware can exploit the mobile device, its calls, texts, and other data. It can also activate the phone’s camera, microphone, and able to perform other malicious activities. According to Facebook, the malicious spyware was developed by Israel-based cyber intelligence company NSO Group.

According to Facebook, the mobile devices with WhatsApp or WhatsApp Business installed in them are affected, including Apple’s iPhone (iOS), Android phones, Windows Phones, and Tizen devices. However, the company clarified that it’s unclear on the number of people spied on by hackers. Facebook has advised its users to update their WhatsApp applications for further protection. The company said it has implemented a server-side change to protect users and pushed out updates for the various smartphone WhatsApp versions.

“A buffer overflow vulnerability in WhatsApp VOIP stack allowed remote code execution via specially crafted series of SRTCP packets sent to a target phone number. The issue affects WhatsApp for Android prior to v2.19.134, WhatsApp Business for Android prior to v2.19.44, WhatsApp for iOS prior to v2.19.51, WhatsApp Business for iOS prior to v2.19.51, WhatsApp for Windows Phone prior to v2.18.348, and WhatsApp for Tizen prior to v2.18.15,” Facebook said in a statement.

DDoS attacks on the rise in Q1 2019: Kaspersky Lab

DDoS Attacks

A new research from cybersecurity firm Kaspersky Lab revealed that the number of Distributed Denial of Service (DDoS) attacks increased by 84 percent in the first quarter of 2019 compared to Q4 of 2018. In its research report dubbed DDoS Attacks in Q1 2019, Kaspersky stated that cybercriminals are once again turning to DDoS attacks after a sustained time period.

The Moscow-based cybersecurity firm also revealed that it discovered a considerable growth in the number of attacks that lasted more than an hour. According to the research findings, China reported the highest number of DDoS attacks (67%) while the U.S. reported second largest attacks (17.17%) and Hong Kong stood third (4.81%).

“The DDoS attack market is changing. New DDoS services appear to have replaced ones shut down by law enforcement agencies. As organizations implement basic countermeasures, attackers target them with long-lasting attacks. It is difficult to say if the number of attacks will continue to grow, but their complexity is showing no signs of slowing down. We recommend that organizations prepare themselves effectively, in order to withstand sophisticated DDoS attacks,” the report stated.

In a similar research, Kaspersky uncovered AppleJeus, a malicious operation by North Korea’s cyber-hacking outfit ‘Lazarus Group’ to intrude on cryptocurrency exchanges and applications. According to an official report, Kaspersky Lab’s Global Research and Analysis Team (GReAT) discovered the unusual activity of attackers who penetrated the network of an Asia-based cryptocurrency exchange using Trojanized trading software to steal cryptocurrencies. Vitaly Kamlut, the head of GReAT, stated that the cryptocurrency exchange did not encounter any financial losses during the incident.

The security team at Kaspersky stated that the incident occurred after an employee downloaded a cryptocurrency application from a look-a-like website of a company which is dedicated to crypto trading. The malicious update installs a Trojan known as Fallchill that provides the hackers unlimited access to the compromised computer network system, allowing them to steal sensitive information or to deploy other viruses for exploitation.

Through the years, the scandalous Lazarus Group was linked to a series of cyber-attacks. One of the most brazen attacks occurred in February 2016 when hackers tried to steal $101 million from a Bangladesh Central Bank account at the New York Federal Reserve and move it to Sri Lanka. Only a spelling error caused the banks to realize they were under attack.

Identity services startup Auth0 raises $103 million to accelerate growth

Startup funding

Auth0, an Identity-as-a-Service (IDaaS) startup, recently secured $103 million in a series E financing round led by Sapphire Ventures, bringing its total capital to over $210 million. The other existing investors participated in the investment round are Bessemer Venture Partners, K9 Ventures, Trinity Ventures, Meritech Capital, Telstra Ventures, and World Innovation Lab. The Washington-based startup stated the new funding will fuel the company’s innovation pipeline and global expansion.

Founded in 2013, Auth0 provides login and authentication services to enterprises for a secure login system used to authenticate the identity of employees. The company also provides identity services for a variety of device types, including Internet of Things devices and in different formats, including single sign-on, multi-factor authentication, and passwordless logins. The six-year-old startup claim that its IDaaS platform prevents data breaches from unauthorized logins and improper access.

“Auth0 has demonstrated incredible momentum and continues to be a shining model for unparalleled technology, leadership, and growth,” said Anders Ranum, managing director at Sapphire Ventures. “You can see Auth0’s ethos in the product itself — a highly sophisticated cybersecurity platform that’s universal, scalable, and extensible. The company is changing the approach to business by offering a platform that any company can use to protect digital identities.”

“This Series E funding is validation that what we are doing and the platform we are providing are imperative for the success of our customers,” said Eugenio Pace, CEO and co-founder of Auth0. “Businesses cannot afford a data breach, and this investment is a key indicator that identity management is an industry worth investing in. We are truly grateful for the continued support from our investors for Auth0.”

With Greg Clark stepping down, Symantec appoints interim CEO

Symantec

Cybersecurity company Symantec appointed board member Richard Hill as interim Chief Executive Officer and President after Greg Clark stepped down from the company. The U.S.-based company made the announcement after publishing its fourth quarter and full year financial results for the fiscal year 2019.

Symantec, better known for its Norton security software suite, helps organizations, government, and people secure their digital assets. The company claims that organizations across the world uses its strategic and integrated solutions to defend against sophisticated attacks across endpoints, cloud, and infrastructure.

Greg Clark, who served as CEO since Symantec’s acquisition of Blue Coat in 2016, said, “It has been a privilege to lead this great organization and I am proud of all that the team has accomplished in nearly three years. Together, we’ve built a large installed base of customers and brought to market some of the world’s most powerful cyber defense solutions. As Symantec enters its next phase of growth and value creation, it is the right time for the Board to identify the next generation of leadership. With Rick as Interim President and CEO and a world class team in place, I have no doubt this will be a seamless transition for our customers, partners, employees and shareholders.”

Speaking on the new appointment Richard Hill, who served as a Director since January 2019 and who has been named Interim President and CEO of Symantec, said, “I’d like to thank Greg Clark and the full team at Symantec, who have done an outstanding job of building a strategy and solutions that defend enterprises and consumers from the ever increasing cyber threat landscape. Symantec is the only company in the world with a platform built on extensive cyber telemetry and advanced cyber analytics to dynamically defend and inoculate its customers against sophisticated cyber-attacks. I look forward to working closely with the Board and management team in executing on the market opportunity within cybersecurity and am proud to lead Symantec during this interim time while we transition to permanent leadership in the Company.”

Symantec recently announced that it become a member of the United States’ Department of Defense’s (DOD) Defense Industrial Base (DIB) Cybersecurity (CS) program. The DIB CS program is a voluntary cyber threat information-sharing initiative established by the DOD to enhance and supplement DIB participants’ capabilities to mitigate cyber-attacks. The program features a collaborative information-sharing environment where members voluntarily report cyber threats as well as information on how to prevent/mitigate those threats.

Symantec also partnered with more than 120 companies to drive down the cost and complexity of cybersecurity. The California-based company stated it had forged partnerships with major players like AWS, Box, IBM Security, Microsoft, Oracle, ServiceNow, and Splunk, as well as dozens of other technology innovators.

Symantec, better known for its Norton security software suite, stated the acquisitions reinforces the company’s leadership in cybersecurity. The company stated that it’s developing more than 250 products and services that integrate with Symantec’s Integrated Cyber Defense (ICD) Platform. Symantec’s ICD combines cloud and on-premises security across endpoints, networks, email, and cloud protecting organizations against evolving cyber threats.

Exabeam joins hands with Deakin University to fortify security management

CISO appointment

Exabeam, a cybersecurity and security information event management (SIEM) company, recently partnered with the Deakin University in Australia to strengthen its security management and reinforce its distinguished cybersecurity degree program.

Founded in 2013, Exabeam helps organizations by providing security intelligence and management solutions to strengthen their information security. The company claims that its Security Intelligence Platform leverages big data, machine learning, and analytics to detect and respond to cyber threats. It’s one among the number of security information and event management (SIEM) platforms that analyze companies’ log data sources to flag abnormal activities.

Deakin University combines research and teachings with a focus on supporting the communities it serves. The Geelong-based university stated that it deployed Exabeam’s Advanced Analytics platform to streamline alerts, analyze behavioral patterns, and identify the critical anomalies on its network.

“Working with a dynamic educational organization like Deakin University mirrors our overarching vision: to dramatically improve the way that security analysts work while fostering the next generation of cybersecurity talent,” said Nir Polak, CEO, Exabeam. “Exabeam has given the university a smarter way to identify anomalies on their network, and their team has given us the opportunity to mentor and prepare their students to work in the field. We are proud to be growing our footprint in Australia through this incredible partnership and look forward to watching a new wave of security leaders emerge from our work together.”

“When we tested Exabeam Advanced Analytics, we were drawn to the fact that security operations analysts can respond to alerts out of the box, without too much customization,” said Deakin’s Chief Digital Officer William Confalonieri. “This allows our security engineers to focus all of their time on improving our cyber defenses, instead of learning how to create anomaly detection and events correlation queries, which was incredibly time consuming. Compared to all of the other solutions in the market, the support and operational overhead associated with a SIEM solution are minimal with Exabeam.”

Recently, Exabeam secured $75 million in a Series E funding round jointly led by new investor Sapphire Ventures and Lightspeed Venture Partners along with the participation from other existing investors. The San Mateo-based startup stated the new funds will be used for expanding sales reach and accelerate new product lines.

Commenting on the new investment, Nir Polak, the CEO of Exabeam said, “Over the last year, we’ve seen our strategic value increase, and our average deal size has grown by 100 percent from just two years ago. This is because we’re listening to our customers and delivering the innovative technologies they need, including, most recently, the ability to detect threats in the cloud. With the win rates we’re seeing and market opportunity in replacement business, we’re raising money to accelerate our go-to-market and enhance our products to bring additional innovation to modern SOC environments.”

OneDrive vs iCloud Data Security: Which One is Better?

Contributed by Devin Smith

The use of cloud storage was made a reality when individuals and corporations urgently needed for instant real-time storage. Cloud storage was not taken seriously until individuals explored its possibilities, vulnerabilities and adopted it as a safe storage facility.

To confirm the scenario as mentioned earlier, 73 percent of companies were aligned and questioned. The questioning found all of the companies rely on at least one of the cloud storage applications.

The benefit of using such apps are exceptional because it allows accessing, saving and using information from anywhere. Also, the data can be accessed from anywhere in the world and can be restricted to a single use as well. This process allows motivation to increase among teammates and employees because data is shared instantly that enhances productivity.

In the current cyber state, keeping data protected and secure is a big challenge as hackers are always looking for ways to harvest user data that leads to blackmail and exploitation.

They mostly hunt for methods to access files in the cloud storage that creates disturbance in the performance of the cloud through (viruses, malware). Usually, it would take more than 191 days for a company to come across the issue and a further 66 days to compress and control it.

Among the multiple Cloud Storage available online, OneDrive and iCloud are the most common cloud solutions that host millions of users globally. But which cloud storage will keep your online privacy protected? To answer that we shall review which encryption and security these two offers.

Microsoft OneDrive – Security

OneDrive by Microsoft is a multinational company working as a leading tech giant having its roots in manufacturing, production and delivering high-end quality products and services. Among these services, “OneDrive” is a leading Cloud storage tool famous for offering useful features for online data protection.

Can you confirm if its encryption is safe to safeguard sensitive files? OneDrive cloud has a built-in SSL encryption tunnel that keeps all data safe in it. With that being said, a small conflict of encryption arises because your data saved on cloud storage will not be protected and encrypted until unless you are a business account holder.

This took us back, as a majority of the companies using OneDrive have a business account while small scale businesses use a free account that has a 5GB limit. Would a free account cloud service keep user information hidden and safe in their folders and files? That is not yet disclosed or tested, but users can make sure to keep a lookout on websites SSL certificate to protect their devices.

OneDrive includes a feature that syncs all the attachments in Outlook to the Cloud servers which is a cause of breach and security issue if the data being transferred has sensitive files. Business account holders will still benefit because the encryption used for their account, data and files are on a file-by-file basis which decreases the probability of a potential attack.

To be more firm about security, two-step verification needs to be manually activated in the settings as it is not turned on by default. All you need to do is sign up on the account from a different device or browser and Microsoft will send security code for verification. Enter the code, and your access will be granted.

Apple iCloud – Security

Apple is known to be a first-class brand that provides high-end products that boost user confidence. They offer products and services that have a niche in the market which make a difference in aiding users. Among its products they support and provide a famous cloud service namely “iCloud.” The cloud storage is a secure tool that has the ability to withstand cyber attacks at a certain extent.

Yet it falls prey to one or the other vulnerability like other cloud storage tools. Among the biggest cyber attacks faced by iCloud was where famous celebrities including Jennifer Lawrence and Kirsten Dunst whose privacy was invaded by a breach in their Apple accounts. Attacks as similar to this would cause serious damage to the property and sensitive files of the celebs that will evidently lead to a major lawsuit filed.

Multiple breaches have occurred in the past which have been fixed with new upgrades, and Apple takes serious countermeasures against these encryption flaws. To increase safety, they introduced a two-factor authentication just as OneDrive offers that sends a six-digit code every time you log in from a different browser or device.

Two-factor authentication is now a significant need because, without it, the security of any cloud storage or account would not be safe. Logging in to the account may take your time depending on your internet connection as the two-factor authentication follows a process. But hands down it is the best reliable option to keep files and data safe.

Two-factor authentication comes with a TLS/SSL and 128-bit AES encryption that is not as tough as the AES 256-Bit encryption. iCloud is developed to enhance and maximize the security of files being sent and received to minimize and remove the danger of unauthorized access.

They also include a “key chain” data protection which handles critical information of passwords and credit card details inclusive of messages and apps.

Conclusion

Many similarities and differences can be seen in both the Cloud storage platforms and iCloud encryption is dependent on the robust firewalls they provide.

On iCloud even if the data remains for an extended period, the data will remain safe and encrypted.

For business accounts, OneDrive is a better pick over iCloud as for the per-file security present that won’t affect all the files if one file gets corrupted.

Both services provide two-factor authentication, and iClouds keychain tool cannot be overlooked. It is hard to differ and chose between the two as both cloud platforms are a dire need.

We at CISO MAG are set to publish the Power List, a comprehensive publication which will explore critical areas of cloud security while elucidating best practices to adopt for securing the cloud space. Ahead of it, we are discussing several trends and vendors in the space while we tell you what differentiates each product from the rest.

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Hackers can steal your identity and bank details from a coffee machine!

Hackers can exploit smart home appliances like coffee machines and TVs to steal people’s sensitive information. According to Vince Steckler, Chief Executive at security firm Avast, the Internet-connected devices used in the home, like laptops, mobile phones, and other smart gadgets, aren’t secure as they allow hackers to use them to get hold of bank details and other personal information.

Steckler stated that cybercriminals can make use of potential vulnerabilities in the Internet of Things (IoT) devices and compromise them to steal their owner’s sensitive details.

“Coffee machines are not designed for security. TVs are not designed for security. What they are is additional vectors to get into your network. And you can’t protect them,” Steckler said in a media statement.

Many of the recent surveys discovered the unknown vulnerabilities in the smart devices that we use often. Recently, cybersecurity expert Yossi Atias took the stage at Mobile World Congress to demonstrate a live hack of the Amazon Ring video doorbell, exposing a previously unknown vulnerability in the popular IoT device. The hack revealed unencrypted transmission of audio and/or video footage to the Ring application allows for arbitrary surveillance and injection of counterfeit video traffic, effectively compromising home security and putting family members’ safety at risk.

Earlier in 2018, a research from cybersecurity solutions provider Check Point revealed how organizations and individuals are vulnerable to hacking through their fax machines. The researchers at Check Point stated that fax machines have security vulnerabilities which could possibly allow a hacker to steal data through a company’s network using just a phone line and a fax number. The researchers also showed how they were able to exploit security flaws in a Hewlett Packard all-in-one printer. The findings were presented by Check Point’s researchers Yaniv Balmas and Eyal Itkin at DEFCON 26.

Also, the security experts from the University of Texas stated the hackers can make use of internet-connected light bulbs as a covert channel to exploit the user’s private data. The researchers have taken the LIFX and Phillips Hue smart light systems for the study. The research stated the hackers can launch an attack by manipulating the infrared light by creating a communication channel between the smart lights and a device that senses infrared light. And by installing a malicious agent on the phone the attackers can encode the private data and transfer them through the infrared covert channel.

The researchers also specified that the proposed threats can be mitigated by enforcing strong network systems and reducing the light transmittance and the brightness of the bulbs that stops the attacks to perform.

Automation and Response startup Siemplify secures $30 million

Automation and Orchestration

Siemplify, a provider of security orchestration, automation and response (SOAR), announced that it has secured $30 million in Series C funding round led by Georgian Partners along with the existing investors – 83North, G20 Ventures, and Jump Capital. The New York-based company stated that it will use the new funds to expand its global go-to-market strategy and enhance its market-leading security operations platform.

Founded in 2015, Siemplify provides security orchestration, automation and response services to enterprises and MSSPs worldwide. The company claims that its orchestration platform enables security teams to manage their operations from end to end, respond to cyber threats with speed and precision.

Siemplify’s security solutions combine security automation and response with robust management tools. Its cloud platform can create customizable and repeatable processes that orchestrate security utilities from McAfee, Symantec, Splunk, Carbon Black, Micro Focus, VirusTotal, and other vendors.

“Our security operations platform alleviates the most pressing pain points faced by security operations teams,” said Amos Stern, CEO and co-founder of Siemplify. “This significant investment and expertise from Georgian will allow us to expand our global presence and drive further innovation to make security operations smarter, more efficient and more collaborative. And as we continue our journey, nothing makes us more grateful than working alongside and solving challenges for the people to whom we owe our success: our customers and partners.”

“Siemplify is rapidly solidifying its position as the leading independent SOAR provider, with a differentiated offering and a clear vision of enabling organizations to manage security operations from end to end. We are excited to lead the Series C funding round and to support Siemplify as it continues its fast growth,” said Steve Leightell, partner at Georgian Partners.

Singapore government launches new Cybersecurity Center

Singapore

The Maritime and Port Authority (MPA) of Singapore recently announced the launch of its new 24/7 cybersecurity center, Maritime Cybersecurity Operations Center (MSOC). Inaugurated by Niam Chiang Meng, the Chairman of the Maritime and Port Authority of Singapore (MPA), the new center is operated by ST Engineering, a private contractor.

Designed to strengthen Singapore’s cybersecurity readiness through early detection, monitoring, analysis, and response, MSOC will conduct 24/7 monitoring services across all the port’s information infrastructure. The MSOC can detect vulnerabilities and potential threats by analyzing activities in the IT environment and respond with available technological solutions, according to the MPA.

Apart from setting up MSOC, the MPA also collaborated with the Singapore Shipping Association and Singapore Polytechnic to develop a new “Maritime Cybersecurity (Intermediate) Training Course” for maritime personnel to strengthen their security readiness.

“Cyber threats come in many forms and have been rising steadily across the globe. As the world’s busiest transhipment hub, it is important that we safeguard our maritime and port critical infrastructure to prevent a major disruption to port operations and delivery of services,” Niam said.

A recent research stated that cyber-attacks are increased in the last 12 months, causing security breaches affecting 96 percent of organizations surveyed. According to the research report from endpoint security firm Carbon Black, 90 percent of the Singapore businesses have been breached in 2018. In its report named Singapore Threat Report, Carbon Black examined the survey results from different industries, organization sizes, and IT team sizes to show modern attacks and cyber defense landscape in Singapore region.

According to the research findings, 96 percent of surveyed Singapore-based companies reported breaches last year and 92 percent of them said they’ve seen an increase in attack volumes. Also, 95 percent of the organizations stated the attacks have become more sophisticated and 97 percent of them stated they’ve planned to increase spending on cyber defense.

Also, the Singapore government recently formed Telecom Cybersecurity Strategic Committee (TCSC), a committee that is expected to publish a strategy for telecommunication operators to develop cybersecurity capabilities. It would also give other recommendations, including capability development, technology innovation, regulation, and international partnerships. While addressing at the inaugural of Infocomm Media Cybersecurity Conference, Senior Minister of State for Communications and Information Janil Puthucheary announced the road map to secure Singapore’s telecommunications infrastructure.