Home Blog Page 342

Under the Spotlight: Eng. Badar Ali Al-Salehi

Badar Ali Al Saleh

Eng. Badar Ali Al-Salehi is the Director of Oman National CERT, an e-Oman national initiative aiming at addressing cybersecurity risks, building local cybersecurity capabilities, and promoting cybersecurity awareness among public and private sector organizations in Oman. A veteran in this arena, Al-Salehi is a member of several regional and international forums and committees.

In an exclusive interview with CISO MAG, Al-Salehi discusses regulations and laws for cybersecurity, state of ethical hacking in Oman, and requisites for keeping critical infrastructures safe from cyber-attacks.

OCERT was established in 2010 to ensure the cyber safety and security of the country. How has the journey been in the last eight years and what are the key milestones OCERT has been able to achieve?

OCERT was established with a clear vision and objectives. The initiative has been able to accomplish the following:

  • Built highly skilled and expert professional team in cybersecurity and cyber incident management
  • Obtained regional and international membership and recognitions including GCC-CERT, OIC-CERT, FRIST, Malware alliance, APWG, and Honey Net Project.
  • Elected as the chair of OIC-CERT
  • Elected as the chair of ITU Arab Study groups 17
  • Hosted the ITU Arab regional cyber security center
  • Obtained the World Summit in Information Society (WSIS) award in the category of building confidence and security in the use of ICT

What are the key components of a solid framework that would facilitate the government to offer secure e-government services?

The framework we are adopting is based on a global cybersecurity agenda that addresses cybersecurity with regards to organizational structure, legal and technical measures, capacity building, and international cooperation.

Read More

Symantec and Fortinet partner to deliver comprehensive cloud security service

U.S. and Australia to Jointly Develop Cyber Training Platform

Cybersecurity company Symantec and integrated and automated cybersecurity solutions Fortinet have announced an expansive partnership agreement to provide customers security solutions. Fortinet’s Next-Generation Firewall (NGFW) capabilities are planned to be integrated into Symantec’s cloud-delivered Web Security Service (WSS). Additionally, Symantec’s endpoint protection solutions are also planned to be integrated into the Fortinet Security Fabric platform. The technology partnership provides essential security controls across endpoint, network, and cloud environments that are critical to enforcing the Zero Trust security framework.

WSS, a secure web gateways, is a cloud-delivered network security service that provides protection against advanced threats, provides access control, and safeguards critical business information for secure and compliant cloud application and web use. The integration of Fortinet’s  FortiGate Next-Generation Firewall with Symantec’s WSS will result in the a comprehensive set of cloud-delivered threat prevention capabilities in a single service offering on the market today.

“As the first step in this technology partnership, we plan to deliver best-of-breed security through the combination of enterprise-class advanced firewall controls to Symantec’s industry-leading network security service,” said Art Gilliland, EVP and GM Enterprise Products, Symantec. “Through this partnership, we hope to provide joint customers the power of Symantec’s Integrated Cyber Defense Platform bolstered by Fortinet’s leading NGFW in an integrated solution that’s easy to use and deploy.”

Additionally, Symantec’s endpoint protection solution is planned to be integrated into the Fortinet Security Fabric platform, to provide customers with real-time, actionable threat intelligence and automated response for exploit-driven attacks and advanced malware. Interoperability between Fortinet’s SD-WAN technology will also be certified to work with Symantec’s Web Security Service through Symantec’s Technology Integration Partner Program (TIPP). As part of the collaboration, both companies plan to engage in joint go-to-market activities.

“With today’s announcement, two industry leaders are coming together to provide enterprise-class capabilities across cloud, network, and endpoint security,” said John Maddison, SVP of products and solutions, Fortinet. “Upon completion of the integration, Symantec cloud web gateway customers will be able to benefit from Fortinet’s enterprise-class advanced firewall controls, and for the first time ever, Fortinet customers will be able to purchase the industry-leading FortiGate Next-Generation Firewall via FWaaS. With the addition of Symantec as a Fortinet Fabric-Ready Partner, Symantec’s endpoint security solution will be validated to seamlessly integrate with the Fortinet Security Fabric platform to provide more consistent and effective protection for joint customers.”

Elements of the Fortinet Security Fabric have been integrated with Symantec Endpoint Protection, and the companies plan to explore further integrations. The fully integrated Cloud Firewall Service within WSS is expected to be available in the first half of calendar 2019.

Most businesses suffered two or more business-disrupting cyber events in last 24 months: Report

cybersecurity

Contributed by Tenable, Inc.

Tenable, Inc., a company that provides cybersecurity solutions, recently released the Measuring and Managing the Cyber Risks to Business Operations Report, an independent study conducted by Ponemon Institute. It found that 60 percent of organizations globally had suffered two or more business-disrupting cyber events — defined as cyber attacks causing data breaches or significant disruption and downtime to business operations, plant and operational equipment — in the last 24 months. Further, the vast majority of respondents (91 percent) had suffered at least one such cyber event in the same time period.

Despite this documented history of damaging attacks, the study found that the majority of organizations (54 percent) are not measuring, and therefore don’t understand, the business costs of cyber risk. The report concludes that organizations are unable to make risk-based business decisions backed by accurate and quantifiable metrics, resulting in a lack of actionable insight for the C-suite and board of directors.

Digital transformation has created a complex computing environment of Cloud, DevOps, mobility and IoT, where everything is connected as part of the new, modern attack surface. This has created a massive gap in an organization’s ability to truly understand its Cyber Exposure at any given time. The research — which surveyed 2,410 IT and infosec decision-makers in six countries — found less than one third (29 percent) of respondents reported having sufficient visibility into their attack surface (i.e. traditional IT, cloud, containers, IoT and operational technology) to effectively reduce their exposure to risk. To further complicate this lack of visibility, more than half of respondents (58 percent) said their security function lacks adequate staffing to scan for vulnerabilities in a timely manner, with only 35 percent scanning when it’s deemed necessary by an assessment of risks to sensitive data.

Together, these data points reveal that the tools and approaches organizations are using fail to provide the visibility and focus required to manage, measure and reduce cyber risk in the digital era.

Of those organizations that measure the business costs of cyber risk, 62 percent are not confident their metrics are actually accurate. Thus, decisions about the allocation of resources, investments in technologies and the prioritization of threats are being made without critical information — such as the costs of IP theft, loss of revenue or loss of productivity. Organizations admit to not using the key performance indicators (KPIs) they consider important to assessing and understanding cyber risks:

  • 64 percent rated “time to assess” an essential KPI but only 49 percent actually measure it
  • 70 percent rated “time to remediate” an essential KPI but only 46 percent measure it
  • Only 30 percent of respondents believe their organizations can translate cyber risk KPIs into actionable steps

This lack of rigor leaves boards of directors in the dark about the true cost of cyber risks to their organizations. Without confidence in the accuracy of their measures, CISOs and other security executives are reluctant to share critical information about the business costs of cyber risks with their boards.

“In today’s digital economy, cyber risk equates to business risk. It’s shocking to learn that organizations are suffering business-impacting cyber events yet are struggling to accurately measure the resulting financial cost,” said Bob Huber, CSO, Tenable.  “This study powerfully highlights that most organizations have not implemented security metrics that reflect cybersecurity’s role as a core business function. CISOs need reliable metrics to help them make educated decisions on the allocation of resources, investments in technology and the prioritization of threats.”

The report is available here: https://www.tenable.com/cyber-exposure/ponemon-cyber-risk-report.

Reserve Bank of India fines Indian Bank for violating cybersecurity norms

The Reserve Bank of India (RBI) has imposed a fine of 10 million rupees ($1.4 million) on Indian Bank, a public-sector bank based out in the Indian state of Tamil Nadu, for violating cybersecurity norms. The central bank stated that the monetary penalty was imposed by an order dated November 30, 2018, for flouting of the Circular on Cyber Security Framework in banks.

“This penalty has been imposed in the exercise of powers vested in RBI under the provisions of the Banking Regulation Act, 1949 taking into account the failure of the bank to adhere to the aforesaid guidelines and directions issued by RBI,” an RBI stated in a statement noted.

“This action is based on deficiencies in regulatory compliance and is not intended to pronounce upon the validity of any transaction or agreement entered into by the bank with its customers,” the release added.

In order to advance the preparedness of Indian banks against cyber-attacks, the RBI is working on enhancing cybersecurity mechanisms. The central bank recently announced an enhanced security mechanism as part of its agenda for the fiscal year 2018-19 to provide high-level protection against cybersecurity threats.

The RBI’s new agenda includes taking effective steps to initiate the process of developing a cybersecurity culture, endeavor to make cybersecurity a responsibility, and ensure confidentiality, integrity, and availability of information system and resources. Also, to reinforce data protection and Know Your Customer (KYC) norms to make them more effective.

Large Indian companies lose $10.3 million from cyberattacks annually: Study

A recent study has revealed that a large-sized company in India loses an average of $10.3 million each year due to cyber-attacks, while a mid-sized company loses an average of $11,000.

The study named “Understanding the Cybersecurity Threat Landscape in Asia Pacific: Securing the Modern Enterprise in a Digital World,” conducted by Frost & Sullivan and led by Microsoft revealed that more than three in five Indian companies (62 percent) have either experienced a cyber-attack (30 percent) or are not sure about any cyber incident as they have not performed proper assessment (32 percent).

“Although the direct losses from cybersecurity breaches are most visible, they are but just the tip of the iceberg,” said Benoy CS, Director & Business Unit Head, Frost & Sullivan. “There are many other hidden losses that we have to consider from both the indirect and induced perspectives, and the economic loss for organizations suffering from cybersecurity attacks can be often underestimated.”

The study, that ranged from mid-sized organizations (250 to 499 employees) to large-sized organizations (more than 500 employees), surveyed 1300 businesses across different sectors. It also exposed the cyber-threats resulted in job losses in more than three in five (64 percent) of organizations.

“As companies embrace the opportunities presented by cloud and mobile computing to connect with customers and optimize operations, they take on new risks,” said Keshav Dhakad, Group Head & Assistant General Counsel, Corporate, External & Legal Affairs (CELA), Microsoft India “With traditional IT boundaries disappearing the adversaries now have many new targets to attack. Companies face the risk of significant financial loss, damage to customer satisfaction and market reputation—as is evident from high-profile breaches this year.”

The research also highlighted that 92 percent of organizations have either adopted or looking to adopt artificial intelligence (AI) to protect themselves from cyber-attacks and 22 percent of the organizations have already seen the benefits of using AI to detect threats faster and more accurately.

Google+ suffers second massive data breach

Google had earlier announced that it will be shutting down its social media platform Google+ for consumers by August 2019, after the disclosure of a vulnerability that exposed around 500,000 users’ personal information to third-party developers.

In a recent media statement, the California-based firm stated that it is moving the date to April 2019. The declaration came after Google+ encountered another data breach that exposed personal information of 52.5 million users. The tech giant admitted that the incident occurred due to an existing bug in its software update that was introduced in November 2018, before Google fixed it.

The flaw exploited Google’s APIs exposing users’ data, including usernames, email addresses, occupation, date of birth, age, gender, and other personal information. Google clarified that they found no evidence that any third-party developers were aware of the bug or misuse of any users’ data.

“We’ve recently determined that some users were impacted by a software update introduced in November that contained a bug affecting a Google+ API. We discovered this bug as part of our standard and ongoing testing procedures and fixed it within a week of it being introduced. No third party compromised our systems, and we have no evidence that the app developers that inadvertently had this access for six days were aware of it or misused it in any way,” the company said in a blog post.

“With the discovery of this new bug, we have decided to expedite the shut-down of all Google+ APIs; this will occur within the next 90 days. In addition, we have also decided to accelerate the sunsetting of consumer Google+ from August 2019 to April 2019. While we recognize there are implications for developers, we want to ensure the protection of our users,” Google added.

Earlier in November, Google had announced key security improvements to spruce the data protection measures of Google account users. According to Jonathan Skelker, product manager at Google, the search engine giant has been enhancing the account security by introducing a new step-by-step check-up, notifications, and JavaScript requirement.

Humble Bundle suffers cyber-attack

Humble Bundle

Humble Bundle, a digital storefront for video games, recently revealed that it has suffered a data breach in late November that might have compromised the information like customers’ account details and subscription status. Humble Bundle is a distribution platform that offers game bundles, and sells eBooks, software, and other digital content.

The company stated that hackers exploited a bug used to gather the subscriber information in the company’s server and illegally gained access to its customers’ email addresses and their Humble Bundle subscription details. However, Humble Bundle clarified that no sensitive information such as customer name, billing address, password, and payment information was exposed in the incident.

The company notified its users via emails about the intrusion. “Last week, we discovered someone using a bug in our code to access limited non-personal information about Humble Bundle accounts. The bug did not expose email addresses, but the person exploited it by testing a list of email addresses to see if they matched a Humble Bundle account. Your email address was one of the matches,” the email reads.

“Sensitive information such as your name, billing address, password, and payment information was NOT exposed. The only information they could have accessed is your Humble Monthly subscription status. More specifically, they might know if your subscription is active, inactive, or paused; when your plan expires; and if you’ve received any referral bonuses,” the email further read.

Further, Humble Bundle apologized its customers and recommended some safety precautions to prevent the future losses. “Even though the information revealed is very limited, we take customer trust very seriously. We want to make sure you are able to protect yourself should someone use the information gathered to pose as Humble Bundle,” the email stated.

In related news, it was disclosed last month that a group of Call of Duty (CoD) players were a part of a cybercrime syndicate that remotely stole $3.3 million in cryptocurrency by hacking several crypto wallets.

Data breach affects 100 million Quora users

Quora

Quora, a knowledge sharing website, recently reported a security breach to its users. The breach is expected to affect approximately 100 million users’ accounts on November 30, 2018.

The social platform wrote in its blog that a third party exposed users’ sensitive information, including names, email addresses, IP addresses, user IDs, encrypted passwords, user account settings, personalization data, public actions, and content such as questions, answers, comments, blog posts, and upvotes.

“On Friday we discovered that some user data was compromised by a third party who gained unauthorized access to one of our systems. We’re still investigating the precise causes and in addition to the work being conducted by our internal security teams, we have retained a leading digital forensics and security firm to assist us. We have also notified law enforcement officials,” Adam D’Angelo, the CEO of Quora, stated in a blog post.

Describing the incident as an identity theft, Adam D’Angelo, Quora CEO, stated that the company is taking additional steps to improve the security standards. “While the investigation is still ongoing, we have already taken steps to contain the incident, and our efforts to protect our users and prevent this type of incident from happening in the future are our top priority as a company,” he wrote.

Quora clarified that the questions and answers that written anonymously were not affected by the breach and they’re notifying the users whose data was compromised.

“Out of an abundance of caution, we are logging out all Quora users who may have been affected, and, if they use a password as their authentication method, we are invalidating their passwords. We believe we’ve identified the root cause and taken steps to address the issue, although our investigation is ongoing, and we’ll continue to make security improvements,” D’Angelo added.

ConnectWise acquires Security Solutions Provider Sienna Group

Acquisition

Information technology company ConnectWise recently announced that it has acquired Sienna Group, a managed security services provider (MSSP). The software company stated the Sienna Group’s expertise provides a means for ConnectWise clients to assess their own cyber vulnerabilities and protect themselves from cyber-attacks.

“The acquisition of Sienna Group will enable us to form the Cybersecurity Center of Excellence to educate MSPs on best practices of every aspect of cybersecurity,” said Arnie Bellini, CEO of ConnectWise. “The Sienna Group has more than 130 years of combined cybersecurity experience and understands how to provide those services to small- to medium-sized businesses (SMBs). Our mission is to leverage this expertise to educate, support and consult MSPs in the delivery of cybersecurity services because we want every MSP to learn how to safeguard its clients’ systems and critical data.”

The acquisition integrates Sienna Group’s expertise and ConnectWise’s strategy to provide an ecosystem of security solutions that help managed service providers reduce cybersecurity risks.

“At ConnectWise, we will continue to build our set of security offerings – both through acquisitions such as the one announced today and through partnerships with the channel’s best security vendors – to make it easier than ever for our partners to take advantage of the revenue opportunity that comes with being able to keep their customers safe from cyber-threats,” Bellini added.

Founded in 2011 by cybersecurity veteran John Ford, Sienna Group’s solutions includes managed data security services, governance, risk and compliance assessments, sensitive data discovery and classification, and security awareness training. The Tampa-based company claims that it’s focused on protecting organizations’ sensitive data and bringing their security posture to the CXO level.

Speaking on the acquisition move, John Ford said, “We’ve been working with ConnectWise for years, and we share both a vision and a commitment to ensuring that MSPs have the tools they need to protect themselves and their clients in a time when a disastrous cyber breach is often just a single click away,” he said. “We’re looking forward to being part of ConnectWise’s journey to provide a robust end-to-end security solution that will benefit the entire industry.”

Singapore announces new grant to enhance cybersecurity capabilities

Singapore

In order to strengthen the country’s financial sector technology, the Monetary Authority of Singapore (MAS) recently announced the launch of S$30 million (US$22 million) cybersecurity capabilities grant.  The new allocation helps Singapore’s financial institutions strengthen their cyber resilience and upskill local talent through cybersecurity-related training programs like security operations, cyberthreat surveillance, computer forensics, malware analysis, and cyberthreat hunting.

The grant provided under the Financial Sector Technology and Innovation Scheme (FSTI) will co-fund up to 50 percent of expenses in Singapore-based financial institutions to establish their global or regional cybersecurity centers of excellence in the country. It would also support the organizations with regional cybersecurity centers to expand their cybersecurity capabilities globally.

Speaking on the initiative, Tan Yeow Seng, the Chief Cyber Security Officer, MAS, said, “The Singapore financial sector has made significant progress in recent years in building up cyber resilience and managing cyber risk.  But the cyber threat landscape continues to evolve, and we have to constantly strengthen our cyber capabilities. The Cybersecurity Capabilities Grant will support financial institutions in advancing their cybersecurity technology and manpower needs.”

The Singapore government is trying to establish cybersecurity standards with the Association of Southeast Asian Nations (ASEAN) to strengthen the protection of critical information infrastructure. Several government officials highlighted the urgent need for stronger safeguards against cyber- attacks and called on the ASEAN to cooperate in the cross-border protection of internet-based systems.

Recently, the governments of Singapore and the United States joined hands to strengthen their collaboration in the infrastructure sector, digital economy, and cybersecurity. Both countries renewed their Collaboration Platform Memorandum of Understanding (MOU) and signed a Declaration of Intent (DOI) to work together on a Singapore-US Cybersecurity Technical Assistance Program for ASEAN (Association of Southeast Asian Nations).