Home Blog Page 321

Top Five Ways to Talk Cybersecurity with C-Suite and Board

Board meeting, mitigate risks from Log4j

Contributed by Craig Moss, COO, CREATe Compliance

Although Board Directors and the C-Suite are increasingly being educated about cybersecurity, it is quite likely that most have picked up their knowledge from reading the Wall Street Journal or talking with their peers. As a result, many get lost in the technicalities of cybersecurity. The challenge for you as a CISO is, how do you establish a common language and understandable metrics with your C-suite and the Board? Here are five ways to get the conversation started.

Make cybersecurity part of broader enterprise risk management

Learn about the language being used to describe other business risks and integrate it into how you talk about cybersecurity. Senior executives and boards are very familiar with assessing the probability and negative impact of risks, establishing a risk tolerance level and developing risk management plans. If you use the same approach and terminology, it will help them to understand the big picture and make more informed decisions about the actions you suggest. Senior management is focused on a broad range of business performance, compliance and regulatory risks. Showing them how cybersecurity fits into the broader enterprise risk management picture helps to break down the misperception that “cybersecurity is an IT issue.” Be ready with the technical details, but don’t lead with them

Talk about program maturity

Maturity models are embraced by senior management and the board because they are familiar with them from many other programs, like quality management. Edna Conway, Cisco’s Chief Security Officer, Global Value Chain believes that cybersecurity is a part of an overall security architecture – something she refers to as “Pervasive Security.”  “Security professionals need to speak the language of business – maturity and tolerance levels allow us to do that,” said Conway.

It is critical for you to make a clear distinction between program maturity metrics and performance metrics. For a practical example of the different type of metrics, let’s look at password use in your organization, a common issue. Cybersecurity program maturity metrics measure the actions taken to establish and communicate the password policies and procedures to the workforce. Has a practical policy been established with cross-functional input? Is the workforce communication part of a repeatable process? Is there recurring communication to reinforce the message? Are there records? How is workforce adherence to the policy monitored? Is the overall password procedure evaluated for effectiveness? By Comparison, performance metrics look at the number of incidents caused by weak or compromised passwords. Both metrics are useful, but the maturity metrics are a better indicator of your ability to manage cybersecurity risk.

Focus on people, processes AND technology

It’s becoming common wisdom that cybersecurity is a people, process and technology issue. Senior management needs to know how these three elements work together to reduce risk in a way that doesn’t impede efficient business operations.

Octavio Flores, Director, Information Technology, at P&G, stated, “It is all about effective risk management, to do it consistently companies need to make a strategic choice to lead and drive their security program by measuring program maturity in the areas of policy, people, process and technology. Performance metrics are also required, but program maturity focuses the company on critical capability building, coverage of those capabilities, and sustainability of performance operating those capabilities.”

Help senior management understand that cybersecurity requires the orchestration of people, processes and technology – and that they have a critical role in it.

Build buy-in across the organization and send a unified message

One of your goals is to embed cybersecurity into how people do their jobs – to create a culture of cybersecurity. To do this, the policies and procedures need to be practical or you will create a culture of “work-arounds.” The only way to develop practical policies is to get input from all of the departments and functions in your company – from finance to legal to HR to supply chain to sales. Every department needs to be involved in your mission to develop practical policies and procedures that people follow. It’s better to have someone tell you your policy idea is crazy before you release it. Getting buy-in from the department leaders lets you make a more powerful statement to senior management. Cross-functional support will help you answer practical questions from the CEO or the board, such as whether it will generate a better risk reduction ROI to spend more money on new software or on an employee training program.

 Reference leading standards and frameworks

Aligning your program with a widely used standard or framework allows you to benchmark your program against other companies. Inevitably, senior management is going to ask you, “how are we doing against other companies?” If your program can reference the NIST Cybersecurity Framework or ISO27001, you will be able to compare the maturity of your program with a broad, diverse group of companies.

In addition, the NIST Framework provides a common language and framework for assessing cybersecurity risk that senior executives and board members are increasingly familiar with as its use grows.

Craig Moss is COO of CREATe Compliance, an Ethisphere business; and Director of Content for the Cyber Readiness Institute.

Cybersecurity startup PlainID partners with SAP

PlainID, an authorization services provider, recently announced that it has partnered with enterprise software company SAP. PlainID stated the main intention of the alliance is to offer SmartAuthorization as an OEM component to be featured in the SAP Customer Data Cloud portfolio. PlainID’s identity authorization service will be featured in SAP’s customer data cloud portfolio as per the new alliance deal.

Founded in 2015 by Dmitry Tuchinsky, Gal Helemski, and Oren Ohayo Harel, PlainID is specialized in simplified authorization management services giving a clear idea of every authorization in the cloud, mobile, and on-premise applications. The Israel-based cybersecurity startup stated that its authorization platform allows the business leaders, data governance professionals, and security teams to get a complete control over the entire organization’s authorization process.

Speaking on the new investment Oren Ohayon Harel, the CEO and Co-founder of PlainID, said, “The ‘last mile’ of Identity and Access Management, Authorization, is a source of frustration for most companies, and many have attempted to build their own access management decision infrastructure,”

“Through our partnership with SAP, we will deliver an Authorization as a Service solution that simplifies and completes the lifecycle of IAM and offers the ability for companies to reduce the frustration of managing the complexities around who should have access to what. PlainID’s model is to put the business owner in charge, allowing the person in charge of the application, or the business line, or even delegated administration, such as a partner, to easily manage the access management scenarios. We are thrilled to be joining forces with SAP and look forward to adding our technology to help reduce or even remove friction from access management processes,” Harel added.

Earlier, SAP acquired customer identity and access management services company Gigya. Gigya’s customer identity and access management platform help companies build digital relationships with their customers. Its platform allows companies to manage customers’ profile, preference, opt-in and consent settings, with customers maintaining control of their data at all times. Customers opt in and register via Gigya’s registration-as-a-service, which addresses changing geographical privacy issues and manages compliance requirements such as the upcoming General Data Protection Regulation (GDPR). Gigya currently manages 1.3 billion customer identities in order to build identity-driven relationships for its enterprise clients.

Gigya’s technology provides new capabilities to consumers across channels and touchpoints, builds rich intelligent profiles and creates a consent-based approach to personalization across sales, service and marketing. Gigya, an SAP Hybris2 partner since 2013, has customers already using a solution extension from SAP Hybris and Gigya. This acquisition will enable the teams to further build upon this existing strong relationship.

Unprotected database affects 80 million households in US

An insecure database exposed sensitive information of around 80 million households in the United States. According to the security researchers Noam Rotem and Ran Locar from the security firm vpnMentor, the unprotected database leaked nearly 24 GB of data which is hosted by Microsoft cloud server.

The unprotected server contained personal information about U.S. people, including their full names, marital status, income bracket, age, and more. The researchers also discovered coded references to some information like title, gender, marital status, homeowner status, and dwelling type, vpnMentor reported.

The researchers stated the server was taken offline after they reported the issue to the owner of the database. “We have notified the owner of the database and are taking appropriate steps to help the customer remove the data until it can be properly secured,” the research team stated in a statement.

“Unlike previous leaks we’ve discovered, this time, we have no idea who this database belongs to. It’s hosted on a cloud server, which means the IP address associated with it is not necessarily connected to its owner. The data includes uniform entries for more than 80 million households, making it almost impossible to narrow down. The only clue we found lay in people’s ages: despite searching thousands of entries, we could not find anyone listed under the age of 40,” the researchers added.

There are multiple incidents reported about unprotected databases. Recently, a misconfigured MongoDB database, managed by the Indian government healthcare agency, was left online without a password exposing more than 12.5 million medical records of pregnant women. The incident came into light after the security researcher Bob Diachenko identified and reported the data breach to the Indian Computer Emergency Response Team (CERT), which immediately took the server down. The Ministry of Electronics and Information Technology clarified that they secured the leaky server on March 29, 2019.

Diachenko stated that he first identified the leaky database on March 7, 2019, which belong to the Department of Medical, Health, and Family Welfare of a state in India, that contained sensitive medical information, including the test reports of the women who were pregnant women who underwent an ultrasound scan, amniocentesis, and other genetic testing of their unborn child in 2014.

Banking and Financial sectors are prime target for hackers: Survey

Financial Sector

A recent study from the cybersecurity firm Intsights revealed that the Banking and Financial sectors were hit with a constant stream of cyber-attacks when compared to other sectors. According to the Intsights Q1 2019 report named Banking & Financial Services Cyber Threat Landscape Report April 2019, around 25.7 percent of all malware attacks last year was targeted on banks and financial organizations. The study also exposed that the number of data breaches reported in the Q1 2019 is doubled to any of the quarters of 2018.

IntSights is an Enterprise Threat Intelligence & Mitigation platform that provides an active defense system against digital threats. The company claims that its advanced data-mining algorithms and unique cyber reconnaissance capabilities continuously scan the clear, deep, and dark web to provide insights about potential threats to your organization and security professionals.

IntSights stated that cybercriminals exploited the vulnerabilities within SS7 telecommunication protocol to intercept messages that authorize payments from user accounts. According to the survey, hackers inject ATM Malware such as FASTCash and ATMJackPot in switch servers to spread a fake message to approve fraudulent withdrawal requests. Also, there was an increase of more than 212% in the theft of credit card information and 102% year-over-year increase in malicious applications.

“In recent years, threat actors have most frequently targeted banks and financial institutions in developing regions of the world. Our research shows that financial organizations based in Latin America, Africa, and South Asia – primarily India and Pakistan – are particularly susceptible to attacks because many of them lack the same comprehensive security systems that are common at large corporations based in more developed countries throughout North America, Western Europe, and parts of Asia, like Singapore and Japan. With fewer barriers, cybercriminals are able to exploit organizations in developing nations with far greater ease. However, this doesn’t mean organizations in developed countries are impervious to cyberattacks,” the report stated.

Recently, multiple banks and other financial companies in several West African countries have suffered from different hacking attacks, which are underway since mid-2017. According to a report published by Symantec, financial institutions in Cameroon, Congo (DR), Equatorial Guinea, Ghana, and the Ivory Coast have been hit by multiple cyber-attacks in 2017 and 2018.

Symantec stated that it has detected four distinct hacking campaigns targeted against financial firms in Africa. The first attack started in mid-2017 and has infected computers with a malware known as NanoCore (Trojan.Nancrat). The second type of attack began in late 2017, in which cybercriminals used malicious PowerShell scripts and credential-stealing tool Mimikatz (Hacktool.Mimikatz) to exploit their targets.

The third attack was targeted at banks in Ivory Coast using a malware called Remote Manipulator System RAT. The fourth attack started in December 2018. The intruders used a malware known as Imminent Monitor RAT (Infostealer.Hawket) to attack banks in Ivory Coast. Symantec stated that all the four attacks were discovered through alerts generated by its Targeted Attack Analytics (TAA), which uses artificial intelligence to analyze and spot targeted attacks.

Red Canary raises $34 million to boost cybersecurity operations

Cyber security operations

The security operations solutions provider Red Canary recently secured $34 million in a funding round led by global growth equity investor Summit Partners along with the participation from the existing investors Access Venture Partners and Noro-Moseley Partners. The five-year-old Colorado-based company stated the new funding will be used to expand its business and team size.

Founded in 2014, Red Canary provides Managed Detection and Response (MDR) and security orchestration, automation and response (SOAR) solutions to enterprises for greater data protection. Red Canary claims that it’s a pioneer in providing MDR solutions that integrate behavioral analytics and automated response.

“We are in the golden age of data insecurity. Security teams have more telemetry, tools, and budget than ever before but unfortunately, in many cases, this has not resulted in a meaningful improvement in security outcomes,” said Brian Beyer, CEO and co-founder of Red Canary. “We serve as a security ally for our customers, helping their teams get the most out of modern security technology, protect their valuable data and remain focused on the performance of their own business.”

“Our work in the trenches alongside security teams over the last five years has proven time and again that there is a huge need for Red Canary’s solutions. That need is reflected in our consistently rapid growth and off-the-charts customer satisfaction. But it is also readily visible in the incredible engagement from the security community through our blog, webinars, and open source projects like Atomic Red Team. We’re ecstatic to work with Summit to expand our reach and help more organizations make meaningful, measurable improvements to their security outcomes. We believe the best is yet to come,” Beyer added.

Recently, a managed detection and response (MDR) services startup, eSentire raised $47 million in a funding round led by majority investor Warburg Pincus and minority investors Georgian Partners and Edison Partners. The new investment validates eSentire’s strong leadership position and will accelerate innovation to address the complexity of protecting data that is widely distributed and at machine scale.

The company is innovating the MDR category again through the application of a proprietary AI methodology for threat hunting and advanced automation to enable our security experts to operate at machine scale, which solves some of the cybersecurity’s biggest challenges.

Orchestrated risk management firm ZeroNorth secures $10 million

Startup funding

ZeroNorth, a provider of orchestrated risk management services, recently procured $10 million in a Series A investment round led by ClearSky Ventures. Crosslink Capital, Rally Ventures, and existing investor Petrillo Capital also participated in the round. ZeroNorth, formerly known as CYBRIC, stated that the new funding will help to accelerate its newly-extended focus on software and infrastructure risk management. The company is planning to strengthen its research and development, marketing and services to meet the growing demand for its platform.

ZeroNorth accelerates and scales software and infrastructure risk management solutions by orchestrating the discovery and remediation of vulnerabilities. The company claims that it’s the first provider of orchestrated risk management services in the cybersecurity industry. Its orchestration platform named Mission-Control enables enterprises to manage the automated and consistent software security program.

Headquartered in Boston, ZeroNorth claims that many organizations rely on its Mission-Control software platform to discover and remediate evolving vulnerabilities. The platform also provides constant proof of compliance and more cost-effective risk management solutions.

Speaking on the new investment, Ernesto DiGiambattista, ZeroNorth’s CEO and founder, said “Proactively managing security and risk is about more than application security testing orchestration. Application vulnerability correlation and threat vulnerability management are important pieces of the puzzle that we’re delivering for customers grappling with the realities of digital transformation and managing risk in new environment. We now have a broader focus that called for an expanded team and a new brand to match. With these pieces in place and the support of world-class investors, we’re ready to make proactive security a reality for organizations worldwide.”

“Today every organization is in the software business. Software and the infrastructure it run on are critical assets and continuous deployment is essential – but not at the expense of security,” said Peter Kuper, managing director at ClearSky Ventures. “ZeroNorth makes it possible for organizations to have both fast and secure production software – something that was considered incompatible before. Most importantly, ZeroNorth makes it possible for organizations to easily discover and remediate vulnerabilities without disrupting the software development process. Its orchestration platform will be critical to protecting this software-defined world and why we are so excited to be a supporter of this effort.”

 

CUJO AI partners with Avira to provide premium cybersecurity services globally

U.S. and Australia to Jointly Develop Cyber Training Platform

CUJO AI, a network intelligence company recently announced that it’s partnered with cybersecurity firm Avira. Powered by proprietary Artificial Intelligence models, CUJO AI provides AI-driven protection, privacy, and device management solutions. It provides personalized broadband for network operators through advanced device identification, AI security, content controls.

Avira helps enterprises and individuals in protecting their connected devices against evolving threats. The company claims that its security solutions help people manage, secure, and improve the security of their digital assets. The latest partnership integrates CUJO’s AI platform with Avira’s threat intelligence to offer AI-driven home cybersecurity services.

Speaking on the new alliance, Santeri Kangas, the CTO of CUJO AI, said, “Avira provides us with real-time threat intelligence data from its massive customer base. Our algorithms comprehend the information and provide our own conclusions. This partnership enables us to optimize our resources and provide premium detection for all our customers. Overall, it makes our service more accurate.”

“We are confident that our combined efforts will make it easier for network operators to deploy security solutions that proactively enhance and protect their subscribers’ home networks. Together with Avira, we are ready to create new opportunities and enrich the cybersecurity landscape at scale,” Kangas added.

“Cyber threat feeds are a great way to enhance a security service. They provide intelligence that is easy to integrate, quick to bring online, and provide over-the-horizon visibility into emerging threats well before they affect a user’s security,” explained Matthias Ollig, Avira CTO. “We’re pleased to welcome CUJO AI to our portfolio of OEM customers to help protect their network operators and, ultimately, their subscribers.”

Recently, CUJO AI joined hands with AirTies, a provider of managed in-home Wi-Fi solutions to provide cybersecurity and Smart Wi-Fi software solutions for network operators around the world. The two companies will integrate their leading software solutions, making it easier to incorporate Wi-Fi management and enhanced cybersecurity on broadband gateways and in the cloud.

Initially, cybersecurity analytics from the CUJO AI Platform will be incorporated into AirTies’ Remote Manager, a cloud-based optimization suite that provides service providers with real-time visibility and historical performance analysis to manage the consumer Wi-Fi experience. The two companies will unify their gateway software agents that can be deployed as a firmware upgrade to new and existing broadband gateways, and they will collaborate on joint business opportunities with service providers.

 

IoT security startup VDOO raises $32 million

startup funding

The Internet of Things (IoT) security startup VDOO recently secured $32 million in a series B financing round led by WRV and GGV Capital along with the participation from NTT DoCoMo. The Tel Aviv, Israel-based starItup stated the new funds will be used to accelerate the development of its automated analysis capabilities and also expand the company’s partner and distribution network.

VDOO helps embedded device vendors increase the security level of their products by analyzing the security gaps of each device using the cloud or a closed local environment. The company claims that it uses advanced machine learning to build actionable security requirements. The startup helps vendors to take instant actions towards device runtime protection using a single platform.

Speaking on the new investment, Netanel Davidi, the Co-CEO and Co-Founder of VDOO, stated the funding will enable VDOO to increase market adoption of its IoT security platform. “At a time when embedded devices already deployed in the field not only collect data but actually control our physical environment, affecting both business operations and our personal lives, it’s hard to imagine a future where all of these devices can be exploited. The reality is that devices are highly vulnerable and there is a reasonable chance they will be under a massive attack in the near future. Our vision is to make them more secure as we continue to build an automated security platform that meets the demands of an increasingly connected world.” said Netanel Davidi

“VDOO brings a unique end-to-end security platform, answering the global connectivity trend and the emerging threats targeting embedded devices, to provide security as an essential enabler of extensive connected devices adoption. With its differentiated capabilities, VDOO has succeeded in acquiring global customers, including many top-tier brands. Moreover, VDOO’s ability to uncover and mitigate weaknesses created by external suppliers fits perfectly into our Supply Chain Security investment strategy,” said Glenn Solomon, Managing Partner at GGV Capital.

Sixty-one percent security professionals suffer serious data breaches: McAfee

McAfee

A recent research from the cybersecurity company McAfee revealed that around 61 percent of the security professionals have experienced serious data breaches in their current organization. The research dubbed Grand Theft Data II – The Drivers and Shifting State of Data Breaches exposed that organizations are still struggling to fully secure their digital assets and protect against breaches.

The research by McAfee also stated that cybercriminals are using sophisticated methods to steal organizations’ sensitive cyber information, including data and intellectual properties. According to the study, the regular methods used by cybercriminals to exfiltrate data are database leaks, cloud applications, and removable USB drives. The public disclosure of data breach incidents resulted the organizations in financial repercussions and damage to the brand and reputation.

“Threats have evolved and will continue to become even more sophisticated,” said Candace Worley, vice president and chief technical strategist at McAfee. “Organizations need to augment security measures by implementing a culture of security and emphasizing that all employees are part of an organization’s security posture, not just the IT team. To stay ahead of threats, it is critical companies provide a holistic approach to improving security process by not only utilizing an integrated security solution but also practicing good security hygiene.”

In December 2018, a similar research from McAfee revealed that the cybercriminals are generating 480 new threats per minute. In its report, “McAfee Labs Threats Report: December 2018,” McAfee highlighted the IoT malware increased to 73 percent, while the cryptocurrency mining malware was up to 71 percent in the third quarter of 2018.

The McAfee Advanced Threat Research team has noticed a shift in dark web platforms. Several individual sellers have moved away from large markets and have opened their own specific marketplaces. Further, the McAfee stated the mobile malware declined by 24% and new threats ranged from fake mobile applications to mobile banking Trojans. According to the report, the fake apps exfiltrated data, including location details, contact list, and listening to phone calls. McAfee evaluates the state of the cyber threat landscape based on its research, investigative analysis, and threat data gathered by the McAfee Global Threat Intelligence cloud each quarter.

 

ESET partners with Alphabet’s Chronicle to boost cybersecurity

Google 2VS

ESET, a developer of IT security software and services, recently announced that it has partnered with Chronicle, a subsidiary of Alphabet company, to provide essential validation on cybersecurity incidents and alerts.  As per the partnership deal, ESET uses Chronicle’s Backstory platform to offer enhanced data protection services. The Backstory is a cloud service used by various global companies to privately upload, store, and analyze their internal security telemetry to detect and investigate potential attacks.

Launched as a cybersecurity intelligence and analytics platform, Chronicle aims to filter and analyze constantly accumulating data for cyber threats applying Artificial Intelligence. Although much has not been revealed about how the Chronicle will work, it aims to lessen cyber-leak by scanning logs of old data.

The latest partnership will provide customers enhanced protection from advanced persistent threats. ESET provides industry-leading IT security software and services for enterprises and consumers globally. It also offers a range of solutions from the endpoint and mobile security, to encryption and two-factor authentication.

Chronicle targets making security signals easily recognizable, thus increasing the data processing speed. The aim of the firm is to speed up data search and analysis procedure, add more data storage space for customers while reducing costs and evaluating more data in less time. The company has already launched a preview version of its cybersecurity program, currently being tested by some Fortune 500 companies.

“Our partnership with Chronicle will lead to simpler, faster and more streamlined remediation of advanced persistent cyber threats,” said Tony Anscombe, global security evangelist and industry ambassador, ESET. “Together, customers will be able to quickly understand incidents in more detail, take the appropriate actions and stay one step ahead of bad actors. This truly will make the world a safer place,” added Anscombe.

“We are thrilled to bring onboard ESET as an Insight Partner,” said Ansh Patnaik, Chief Product Officer, Chronicle. “As a global platform designed to analyze enterprise security telemetry, Backstory provides more value to customers when it’s integrated with other key technologies within the customers’ networks. We believe our collaboration with ESET gives customers a broader, more accurate view of threats within their networks.”