Home Blog Page 328

Healthcare reports highest number of data breaches: Study

Healthcare Data Breaches, Premier Diagnostics data exposed

A recent report revealed that health care organizations suffered the highest number of data breaches in 2018 across any sector of the U.S. economy. According to Beazley Breach Response, a breach response management and information security insurance solutions provider, the healthcare entities have reported the highest number of data breaches, at 41 percent.

The report, dubbed as Beazley Breach Insights Report, stated that direct hacking, the presence of malware, or due to human error were the causes of data breaches in healthcare organizations.

The report also revealed the percentage of breaches in other sectors of the economy. The education sector accounted for 10 percent of security issues, financial institutions reported 20 percent of incidents, and professional services represent 13 percent of cases.

The cybercriminals are attempting to extort cryptocurrency from companies or individuals claiming to have embarrassing evidence of people using adult websites at work, which are related to extortion, the report added.

“A typical case of sextortion investigated by Beazley Breach Response (BBR) Services involves an email from someone claiming to have accessed the recipient’s work computer and found the addresses of pornographic websites they have viewed. The sender says they have simultaneously recorded footage of the recipient as they watched these sites using their webcam and threatens to share the files with their email contacts if demands are not met,” the report stated.

A report from security rating firm SecurityScorecard, named SecurityScorecard 2018 Healthcare Report: A Pulse on The Healthcare Industry’s Cybersecurity Risks, revealed insights on how the healthcare industry performs compared to others, and specific areas of cybersecurity weakness within healthcare organizations.

The research stated the healthcare industry ranks 15th when compared to 17 other major U.S. industries. 60 percent of the most common cybersecurity issues in the healthcare industry related to poor patching cadence. It’s one of the lowest performing industries in terms of endpoint security, posing a threat to patient data and potential patient lives, the report stated.

Wipro partners with RiskLens to offer Cyber Risk Quantification Solutions

Information technology company Wipro Limited recently announced a partnership with cyber risk quantification (CRQ) software provider RiskLens to deliver quantitative cyber risk assessments to enterprises and government organizations. The latest partnership deal will leverage the RiskLens’ CRQ platform to perform quantitative risk analysis and measure the effectiveness of cybersecurity controls.

RiskLens provides cyber risk quantification software and cyber risk management solutions to enterprises and government organizations to manage cyber risks. The company claims that it’s the only cyber risk quantification software provider that’s built on FAIR, the standard quantitative model for information security and operational risk.

RiskLens said that its solutions help organizations to decrypt their cyber risk exposure in financial terms, prioritize their risk mitigations, measure the ROI of their security investments, and optimize their cyber insurance coverage.

Speaking on the new investment Nick Sanna, the CEO of RiskLens commented, “After many devastating cybersecurity attacks on global companies, the realization that cyber risk equals business risk has been brought home to senior management and boards of directors, who are now demanding a quantitative accounting of the loss exposure their companies face. FAIR analysis and the RiskLens CRQ platform answer their questions in definitive terms. For Chief Information Security Officers (CISOs) and their teams, this cyber risk quantification enables better decision making from the strategic to day-to-day levels and finally aligns security operations to the needs of the business. Our partnership with Wipro expands our reach across the world, and we are delighted to work with a company of such stature and global reach to spread the benefits of cyber risk quantification through the RiskLens CRQ platform.”

“Wipro strives to deliver value and derive the most for our clients with regard to their security investments. Through this partnership, we look forward to maximum risk reduction for our clients through informed decision-making,” stated Sheetal Mehta, Senior Vice President, and Global Head, Cybersecurity & Risk Services, Wipro Limited.

Singapore government conducts second HackerOne bug bounty program

New Programming Language

BUSINESS WIRE: Singapore’s Government Technology Agency (GovTech) and Cyber Security Agency of Singapore (CSA) announced the successful conclusion of the latest Government Bug Bounty Programme (GBBP), HackerOne, the leading hacker-powered security platform, part of the Singapore Government’s ongoing initiative to build a secure and resilient Smart Nation. During the three-week hacking challenge, more than 400 hackers globally were invited to look for security weaknesses in the Singapore Government’s digital assets. Hackers won $11,750 in exchange for reporting 26 valid security weaknesses to GovTech so they could be safely fixed. Through their bug bounty program, Singapore is improving the security of its internet-facing government systems with help from hackers.

The GBBP ran from 27 December 2018 to 16 January 2019 and welcomed 400 ethical hackers to test five internet-facing government systems. Of the 26 valid vulnerabilities reported through the GBBP on HackerOne, seven were considered low severity, 18 were medium severity, and one was high severity. One-quarter of all participating hackers and seven out of the top 10 hackers who earned bounties were from Singapore. Following these successful programs, GovTech and CSA plan to expand the next edition of the GBBP to include more Government internet-connected systems and websites.

“National security cannot exist without cybersecurity,” said Marten Mickos, CEO of HackerOne. “The Singapore Government has fully realized this. They are governmental pioneers in safeguarding vital internet connected systems with the help of an army of over 300,000 ethical hackers. They realize that bug bounty programs allow us to bring the best minds together to counter the risks of today’s cyber environment.”

This is the Singapore government’s second successful bug bounty programme with industry leader HackerOne, following the first bug bounty programme by the Singapore Ministry of Defence (MINDEF). By bringing together a community of cyber defenders who share the common goal of developing a safe and resilient cyberspace, the GBBP builds collective ownership over the cybersecurity of Government systems and websites, which is vital to achieve Singapore’s Smart Nation goals.

HackerOne was selected to manage the bug bounty programme because of its largest credentialled global ethical hacker community and proven results with MINDEF and proven track record of success with governments globally. GovTech and MINDEF join government agencies like the U.S. Department of Defense, U.S. General Service Administration, and the European Commission who partner with HackerOne to find their critical security vulnerabilities with help from the global hacker community.

 

Forty percent of malicious URLs found on good domains: Report

Along several tried and tested attack surfaces that have been gaining traction, cyber-criminals are going strong with newer forms of attack that may seem alarming.  A report by cybersecurity firm Webroot points out that nearly 40 percent of malicious URLs were found on good domains. According to the study, legitimate websites have been frequently compromised to host malicious content.

The report also pointed out that home user devices are more than twice as likely to get infected as business devices with nearly sixty-eight percent infections in consumer devices than 32 percent in a business endpoint. According to it, phishing attacks increased 36 percent, with the number of phishing sites growing 220 percent over the course of 2018.

The report suggested, while ransomware was less of a problem in 2018, it became more targeted. “We expect major commodity ransomware to decline further in 2019; however, new ransomware families will emerge as malware authors turn to more targeted attacks, and companies will still fall victim to ransomware. Many ransomware attacks in 2018 used the Remote Desktop Protocol (RDP) as an attack vector, leveraging tools such as Shodan to scan for systems with inadequate RDP settings. These unsecured RDP connections may be used to gain access to a given system and browse all its data as well as shared drives, providing criminals enough intel to decide whether to deploy ransomware or some other type of malware,” read a release.

Other key findings including the method in which malware tried to install itself. According to the report, nearly a third  of malware tried to install itself in %appdata% folders which was at 29 percent, among others were %temp% at 24.5 percent, and %cache% at 17.5 percent. These locations were the most common hiding paths used by malware.

The report also pointed out that devices that use Windows 10 are at least twice as secure as those running Windows 7 and that despite the decrease in cryptocurrency prices, cryptomining and cryptojacking are on the rise.

“We wax poetic about innovation in the cybersecurity field, but you only have to take one look at the stats in this year’s report to know that the true innovators are the cybercriminals. They continue to find new ways to combine attack methods or compromise new and existing vectors for maximum results. My call to businesses today is to be aware, assess your risk, create a layered approach that protects multiple threat vectors and, above all, train your users to be an asset—not a weak link—in your cybersecurity program,” Hal Lonas, CTO, Webroot.

Symantec collaborates with 120 companies to cut cybersecurity cost

Symantec

Cybersecurity firm Symantec Corporation recently announced that it partnered with more than 120 companies to drive down the cost and complexity of cybersecurity. The California-based company stated it had forged partnerships with major players like AWS, Box, IBM Security, Microsoft, Oracle, ServiceNow, and Splunk, as well as dozens of other technology innovators.

Symantec, better known for its Norton security software suite, stated the acquisitions reinforces the company’s leadership in cybersecurity. The company stated that it’s developing more than 250 products and services that integrate with Symantec’s Integrated Cyber Defense (ICD) Platform. Symantec’s ICD combines cloud and on-premises security across endpoints, networks, email, and cloud protecting organizations against evolving cyber threats.

“There’s a seismic shift happening in cybersecurity,” said Art Gilliland, EVP and GM Enterprise Products, Symantec. “The old way of fighting cyber-attacks using fragmented tools has become too complex and expensive to manage. Integrated platforms are the future. We’re proud to be leading this platform shift with a clear vision and winning portfolio – along with hundreds of partners and thousands of experts working every day on the front lines to protect our customers. We are completely convinced that our best defense going forward is an integrated defense.”

Symantec recently announced the acquisition of Software Defined Perimeter and Zero Trust Innovator Luminate Security. Luminate Security, an Israel-based startup, allows security and IT teams to create Zero Trust Application Access architecture without traditional VPN appliances. Founded in 2017, Luminate Security claims its technology platform Secure Access Cloud can securely connect users from any device to corporate applications on-premises and in the cloud.

In 2018, Symantec acquired Appthority and Javelin Networks to strengthen its mobile and enterprise security products and services. Appthority offers comprehensive Mobile Application Security Analysis services, including automated app-vetting, app-threat scoring, and continuous app analysis. The acquisitions allow Symantec to use Appthority’s technology to analyze mobile apps for malicious threats and defend organizations against Active Directory-based attacks.

Security training company KnowBe4 raises $50 million

Funding

KnowBe4, a provider of security awareness training and simulated phishing platform, recently announced that it secured $50 million as a minority investment from private equity firm KKR along with the participation of Ten Eleven Ventures. The Florida-based company stated the new funds will support its ongoing global expansion and the development of its cybersecurity training platform, which helps companies to combat phishing and other data breaches.

Founded in 2016, KnowBe4 helps organizations reduce the risk of cyber-attacks by educating users to recognize, report, and avoid threats. The company claims that its security awareness training and simulated phishing tests are designed to help employees make smarter security decisions. The KnowBe4’s platform is used by more than 23,000 organizations across a variety of industries, including highly regulated fields such as finance, healthcare, energy, government, and insurance.

Speaking on the new investment Stu Sjouwerman, CEO of KnowBe4 said, “KKR is an important strategic partner for KnowBe4 as we continue to grow worldwide and bring new-school security awareness training to new markets. We have had 23 straight quarters of explosive growth and there is no slowing down. All organizations need to invest in the human side of their security defenses and there is no better way to build their capabilities than to continually train and test them on the constantly evolving threats that they will be exposed to.”

“We’ve seen global spending on cybersecurity solutions grow to $48 billion, yet despite this investment, breaches, and the severity of these breaches continue to be on the rise – over 90 percent of which involve inadvertent human error. We believe employees represent an organization’s first and last line of defense. That is exactly why we are so excited to be investing in KnowBe4, the leading cyber security solution that goes beyond the infrastructure and prioritizes empowering employees to make smarter security decisions,” said Stephen Shanley, Director at KKR.

Recently, KnowBe4 entered into the Brazilian market by purchasing El Pescador, a company previously owned by Tempest – a national cybersecurity firm. Through this new relationship, El Pescador will continue to operate, now as an independent subsidiary of KnowBe4, and maintain its brand.

Data breach affects 326,000 UConn Health patients

data breach

The University of Connecticut Health Center recently suffered a breach that potentially compromised personal data of around 326,000 individuals. In an official statement, the health center stated that unknown intruders accessed the email accounts of several UConn Health employees on December 24, 2018, affecting 326,000 patients’ information.

UConn Health provides health services to the citizens of Connecticut through innovative integration of research, education, and clinical care. The Connecticut-based academic medical center stated the breached data includes, names, dates of birth, addresses, social security numbers, billing and appointment information, and other medical information.

The health center stated that it’s enhancing the security of the impacted accounts to prevent further unauthorized access. It also notified the law enforcement and retained a forensic security firm to investigate for any personal information in the impacted email accounts.

“At this point, we are not aware of any fraud or identity theft to any individual as a result of this incident and do not know if any personal information was ever viewed or acquired by the unauthorized party. Nevertheless, because we cannot isolate exactly what, if any, information may have been accessed, we notified individuals whose information was in the impacted accounts. The incident had no impact on our computer networks or electronic medical record systems,” the health center said in a statement.

UConn Health is offering free identity theft protection services to the patients who impacted in the breach. It also suggested the affected individuals monitor their credit reports, account statements, and benefit statements for any suspicious activity.

“We take our responsibility to safeguard personal information seriously and apologize for any inconvenience or concern this incident might cause. We have taken and will continue to take steps to help prevent something like this from happening again, including evaluating additional platforms for educating staff and reviewing technical controls,” the statement added.

CyberCube teams up with Munich Re to boost Cyber Risk Analytics

96% of Cybersecurity Professionals are Happy With Their Roles

CyberCube, a provider of cyber risk analytics, announced that Munich Re has selected its cyber insurance analytics platform to support state-of-the-art quantification, modeling, and control cyber accumulation risk. Munich Re is the market leader in the swiftly growing cyber (re)insurance market and offers both insurance and reinsurance under one roof.

CyberCube delivers the world’s leading cyber risk analytics for the insurance industry. With best-in-class data access and advanced multidisciplinary analytics, the company’s Software as a Service platform helps insurance companies make better decisions when underwriting cyber risk and managing cyber risk aggregation.

Insurers and reinsurers are in the process of quantifying both the extent of the opportunity and the risk posed by cyber risk. It is critical for reinsurers to look at the cascading impact of largely aggregated cyber-attacks and prepare for it. CyberCube will provide advanced risk modeling capabilities to Munich Re with several cyber risk aggregation scenarios.

Speaking on the new initiative, Pascal Millaire, CEO of CyberCube said, “CyberCube is delighted to support Munich Re in making significant progress to tackle one of the largest opportunities – and threats – to the global P&C (re)insurance market in our generation. Our industry-leading cyber risk-modeling platform is powered by several best-in-class data sources and Symantec’s leading threat intelligence. We are pleased to use these capabilities to support a leader in the reinsurance market.”

Stefan Golling, Chief Underwriter of Munich Re said, “Cyber insurance is a key focus of our innovation strategy. We have made significant investments in our own cyber risk expertise and we seek to complement this with insights from the cyber ecosystem. Leveraging the capabilities of CyberCube will help our underwriting and risk modeling teams in better quantifying cyber risk and understanding potential cyber accumulation scenarios.”

Email security firm Tessian raises $42 million

Funding

Tessian, a machine intelligent email security platform, recently raised $42 million in a Series B funding round to accelerate its expansion in the United States and other global markets. The funding round was led by Sequoia Latitude along with the existing investors Balderton Capital and Accel.

Based out in London, Tessian provides email security platform that helps enterprises globally reduce the chances of human security breaches. Tessian was founded in 2013 by a group of security professionals. The company claims that it’s building the world’s first Human Layer Security platform to keep the world’s most sensitive data and systems private and secure.

Tessian also said that it uses machine learning to eliminate the huge security vulnerabilities surrounding enterprise email including spear phishing and misdirected emails. Tessian stated its email security platform automatically detect any anomalies by analyzing historical email data.

“We’ve entered the third era of enterprise cybersecurity. In the early days, network security sufficed. Then cloud apps and mobile devices proliferated, and we adopted endpoint protection. But in spite of these protections, data breaches are at an all-time high. The reason is humans. People are the most important decision makers in the enterprise and process extremely sensitive information on a daily basis, yet they’re more vulnerable than ever before. Tessian’s mission is to help organizations protect people processing data using technology that empowers, rather than restricts the way they work” explains Tim Sadler, CEO, and co-founder of Tessian.

Speaking on the new investment move, Matt Miller, Partner at Sequoia said, “For years the security market has focused mostly on protecting critical machine-driven points of vulnerability such as the network, the endpoint, the cloud or SaaS connection. To us, this has always seemed somewhat flawed because the biggest asset and vulnerability to any enterprise is its people. We are enthusiastic to partner with Tessian because we believe in this team and its ability to leverage machine learning to help enterprises protect their people.”

Lack of visibility, speed of cloud business initiatives hamstring the ability to secure and manage hybrid environments

FireMon announced the results of its inaugural State of Hybrid Cloud Security Survey. The survey polled over 400 information security professionals, ranging from operations to c-level, about their practices maintaining network security across hybrid cloud environments. The survey aims to shed a light on the challenges security and network professionals face as they expand hybrid cloud initiatives.

 Cloud Business and Cloud Security Misalignment

Cloud-based business initiatives are accelerating faster than security organizations’ ability to secure them. The 2019 State of Hybrid Cloud Security survey revealed 60% of respondents either agreed or strongly agreed that this was happening in their organizations. In many cases, security personnel are not even included in cloud business initiatives.

Additional key findings include:

  • Only 56% of respondents indicated that network security, security operations or security compliance teams are responsible for cloud security.
  • In the remaining 44% of cases, IT/cloud teams, application owners or other teams outside the security organization are responsible for cloud security.

Similarly, the relationship between security and DevOps is inconsistent across organizations, which can impact the consistency of cloud security controls, as more enterprises deploy “as-a-Service” models in the cloud. In some cases, DevOps and security are fully aligned and working well together. In other cases, the relationship is difficult or even dysfunctional:

  • 39% of respondents said they are using Infrastructure-as-a-Service (IaaS), Platform-as-a-Service (PaaS) and Software-as-a-Service (SaaS) models concurrently.
  • 7% of respondents said they are part of the DevOps team, as part of the emerging DevSecOps trend.
  • However, 30% indicated their relationship with DevOps is either complicated, contentious, not worth mentioning or non-existent.

Existing Security Tools Can’t Handle Scale and Complexity

The 2019 State of Hybrid Cloud Security survey found that enterprises are inadvertently introducing complexity into their environments by deploying multiple solutions on-premise as well as across multiple private and public clouds. That complexity is compounded by a lack of integrated tools and training needed to holistically manage and secure hybrid cloud environments. Respondents also cited a lack of integration across tools, and lack of qualified personnel or insufficient training for using the tools, as key roadblocks to achieving cross-environment security management.

Key findings include:

  • 59% of respondents use two or more different firewalls in their environment, with 67% also using two or more public cloud platforms.
  • More than 80% of respondents are challenged with the limitations and complexity of security tools used for managing security across hybrid cloud environments.
  • Only 28% of respondents said they were using tools that can work across multiple environments to manage network security.
  • Almost 36% indicated using native tools for each environment or manual process, which means they are managing security in a stand-alone fashion within each component of a hybrid environment.
  • 44.5% of respondents said their top three challenges for securing public cloud environments are: lack of visibility, lack of training and lack of control.

Mandate: Do More with Less

The transition to hybrid cloud environments has dramatically expanded the enterprise attack surface and, subsequently, the range of assets that must be secured, but security resources are not expanding at that same scale. Budget and staffing are the key resource constraints cited:

  • 57.5% of respondents indicated that less than 25% of their security budget was dedicated to cloud security.
  • 52% indicated they had security teams of 10 people or fewer.

“The results of our survey are compelling, but not surprising. In large, complex enterprise environments, budget constraints, lack of clarity around which team is responsible for cloud security, and the absence of standards for managing security across hybrid cloud environments are impairing organizations’ ability to secure their cloud business initiatives,” said FireMon Vice President of Technology Alliances Tim Woods. “This problem will only be solved with a new generation of security technologies and processes that fully integrate with DevOps and provide end-to-end visibility and continuous security and compliance across hybrid environments.”

Woods added that there is clear indication that many companies are no longer aligned to a central security policy or security doctrine that provides the necessary security guardrails across their hybrid environments. “In the absence of a concise security rule book, where departments are managing their own security controls, they will do so on a best-effort basis,” he said. “You can be guaranteed that this opens the door for increased risk.  If decentralized security responsibility is the future for cloud-first strategies, and we believe it is, then we must look for a way to reestablish a global security management strategy that aligns business intent, with compliance intent, with security intent.  Security implementations should closely reflect a central security doctrine. Security must be a component of application deployments where both are synchronized to each other.”

To download the FireMon State of Hybrid Cloud Security report, visit the FireMon website:https://www.firemon.com/2019-state-of-hybrid-cloud-security