Home Blog Page 352

Darktrace raises $50 million in Series E funding, gets valued at $1.65 billion

Darktrace

Cybersecurity firm Darktrace has raised $50 million in Series E funding. The investment round was led by Vitruvian Partners, along with existing investors like KKR and 1011 Ventures. With the new series funding, the company has reached a total valuation of $1.65 billion, making it one of the largest information companies that heavily deploys artificial intelligence to thwart cyber attacks.

“Darktrace has built a unique combination of world-class AI capabilities, deep cyber domain expertise, and a highly effective business model. This has rapidly created scale and a leading edge over all competitors. Most excitingly, the sophistication and quality of Darktrace’s AI is evidenced by the rapid success of its autonomous response system, Antigena, the first of its kind in the market. We are delighted to be leading this financing round, as Darktrace represents exactly the type of highly innovative company Vitruvian seeks to invest behind and support,” Sophie Bower-Straziota, Managing Director at Vitruvian, said in a release.

The company has been on a roll since early 2018. It recently launched second version of Antigena. The new version has an email module to that users can protect email users targeted by email attack campaigns. “Within seconds of a malicious attack being detected, Antigena v2 not only stops the threat from escalating on the compromised device but also stops other people in the organization from being hit in the first place,” Darktrace stated in a release.

The employee count reached 750, globally, this year which marked nearly 60 percent over the previous one. Apart from these the company tripled its Asian headquarters as well as opened eight new offices by in locations like Los Angeles, Mexico City and São Paulo

“Darktrace continues to enjoy strong growth in new and existing geographies, and is now the most widely used Enterprise AI on the market,” said Darktrace CEO, Nicole Eagan. “The increase in our valuation in just a few months is testament to the fundamental power of our Enterprise Immune System. As we begin to see real-world attacks leveraging offensive AI, Darktrace will be indispensable in keeping defenders one step ahead.”

NHS Digital appoints first Chief Information Security Officer

NHS

In order to meet the government’s new minimum cybersecurity standards, NHS Digital named Robert Coles as the new chief information security officer (CISO). Starting his job from October 2018, Coles will lead the healthcare sector’s response to cyber-attacks.

Previously, Robert served as a CISO at GlaxoSmithKline for four years and previously held the same posts at National Grid and investment bank Merrill Lynch.

The appointment comes after the ‘lessons learned review of the WannaCry ransomware attack’ authored by NHS England’s CIO Will Smart. The review stated 22 recommendations, including the appointment of a CISO to work alongside the Department of Health and Social Care, NHS England, NHS Improvement, and NHS Digital.

“The role will lead national cyber working groups, help inform policy and drive improvements and standardization,” the review stated.

Speaking on the appointment, Deputy Chief Executive of NHS Digital Rob Shaw said, “We have listened to the recommendations made in the lessons learned review into last year’s WannaCry attack and acted on the commitment we made to the public a former GlaxoSmithKline security chief Robert Coles has been named the new chief information security officer (CISO) at NHS Digital Accounts Committee to appoint someone to lead the national cyber and security agenda for health and care. Robert will build on the excellent work that the NHS Digital Data Security Centre has already done to reach out across the health and care to support improved cybersecurity across the system.”

In his role, Robert Coles will work with CEOs and CIOs of local healthcare organizations to ensure they meet the government’s minimum cybersecurity standards and Cyber Essentials Plus (CE+) certification.

The WannaCry Ransomware hit Microsoft Windows OS during May 2017. It affected the operations of nearly 200,000 systems across 150 countries. The National Health Services hospitals in England and Scotland were amongst the worst affected; the impact included disturbing critical devices like MRI scanners, blood-storage refrigerator, even theatre equipment.

On October 27, 2017, the United Kingdom claimed that it believes that North Korea was behind the devastating cyber-attack. WannaCry malware that led to havoc across the world did grievous temporary damage to the network security of Britain’s National Health Service (NHS).

Ensign InfoSecurity joins hands with IronNet Cybersecurity to develop cyber analytics center

cybersecurity

Singapore-based cybersecurity firm Ensign InfoSecurity has partnered with US cybersecurity startup IronNet Cybersecurity to develop a Cyber Analytics Center for Excellence (COE) in Singapore.

Announcing the strategic partnership at the GovernmentWare conference, the alliance stated that the new facility will integrate the intellectual property and tradecraft of both firms to address cybersecurity issues through research in big data analytics and machine learning.

Headquartered in Singapore, Ensign InfoSecurity claims to be one of Asia’s leading cybersecurity services provider. Its machine learning and proprietary big data capabilities allow enterprises to gain access to advanced threat detection and continues monitoring services against cyber-threats.

Speaking on the new association, EIS Executive Chairman Mr. Lee Fook Sun said, “We are honored to partner with IronNet, one of the world’s most formidable cybersecurity and analytics firm to jointly develop security solutions. Our clients are transforming digitally, and analytics will become central to defending networks well. This is part of EIS’ strategy to build focused capabilities that will make a real difference to the defense of critical sectors and our clients. By bringing the best cyber researchers from two continents into this Center of Excellence, we will develop solutions for next-gen challenges, and also provide an avenue for young and talented cybersecurity talent to grow and have world class exposure.”

Founded by General (Ret.) Keith B. Alexander and a team of cybersecurity veterans, IronNet Cybersecurity provide a cyber defense platform to organizations using behavioral modeling, big-data analytics, and advanced computing capabilities.

“We are pleased to partner with EIS on the heels of its formation. This partnership will build on the critically important work IronNet is doing in the United States and in key allied nations around the world to develop collective defense systems that will defend against the most serious threats facing our industries at the plant, the company, the industry sector, and the national level. Companies serving in essential infrastructure roles are particularly important to protect, as they are key to public health and safety, to economic vitality and are the repositories of the core intellectual property one which the competitiveness of our economies and our national security depend,” said Gen. (ret.) Keith Alexander, the Founder and CEO of IronNet Cybersecurity.

ICO fines Equifax for 2017 customer data breach

Equifax breach

Atlanta-based consumer credit reporting agency Equifax has been issued a £500,000 ($660,000) fine by the Information Commissioner Office (ICO) for failing to protect the personal and financial data of 15 million customers in the 2017 data breach.

The Information Commissioner’s Office, which carried out the investigation, stated that Equifax had been warned about vulnerabilities in its systems by the US Department of Homeland Security in March 2017. However, Equifax failed to take proper steps to fix the vulnerabilities, according to the ICO.

“The loss of personal information, particularly where there is the potential for financial fraud, is not only upsetting to customers, it undermines consumer trust in digital commerce,” said information commissioner Elizabeth Denham. “This is compounded when the company is a global firm whose business relies on personal data.”

The U.S. Government recently released a detailed report on how the Equifax hack happened, and the consequences of the incident that exposed the personal details of 145.5 million users, including Social Security numbers, credit card numbers, and driver’s license numbers. The report stated that the incident occurred because Equifax failed to segment its databases into smaller networks, allowing the attackers to get access to all of its customers’ data.

On July 29, 2017, Equifax’s security team observed suspicious network traffic associated with its U.S. online dispute portal web application and blocked the suspicious traffic that was identified. But the company waited until after the close of trading nearly six weeks later to disclose the breach to consumers and Equifax’s investors. After discovering a vulnerability in the Apache Struts web application framework as the initial attack vector, Equifax patched the affected web application before bringing it back online. Equifax also identified unauthorized access to limited personal information for certain U.K. and Canadian residents and is working with regulators in those countries. Equifax made a public disclosure of the incident on September 7, 2017, after hackers exfiltrated data for 76 days.

An Equifax spokesperson said the firm was “disappointed in the findings and the penalty. The criminal cyber-attack against our US parent company last year was a pivotal moment for our company. We apologize again to any consumers who were put at risk.”

Apptega raises seed round to expand its cybersecurity platform

Startup funding

Cybersecurity management startup Apptega recently raised $700,000 in a round led by Circadian Group. The other investors in the round include TiE Atlanta Angel group, Ascent Capital, Triton Claims Management, and individual family offices. The company stated the new capital will be used to increase their workforce and expand sales and marketing channel.

Founded in 2017 by CEO Armistead Whitney, the Atlanta-based startup offers end-to-end cybersecurity platform for organizations.

“Organizations of every size were trying to build, manage and report their cybersecurity program, both for maintaining a great security level to protect their enterprises from the threats of today, to having to report their programs in new ways for board meetings, executive meetings, to their customers,” said CEO of Apptega Armistead Whitney. “Our customers span every industry — from retail, law firms, and healthcare to real estate, manufacturing and technology. Our biggest market right now is businesses between 200 and 1000 employees, so those that don’t have dozens of security people on staff to manage all this. They’re really looking for cyber automation.”

Apptega’s cybersecurity platform helps organizations to build, manage, and report all the cybersecurity operations through a series of specialized apps. The company claims that their applications provide unprecedented visibility and control of an organization’s entire cybersecurity program.

Speaking on the new investment move, Mike Dowdle, Managing Partner at Circadian Group said, “Apptega’s immediate customer traction is impressive and shows the enormous demand companies have for managing their cybersecurity programs. The experience of Apptega’s management team operating in the hyper-growth cybersecurity field makes this a very attractive investment.”

Training Camp awarded EC-Council Accredited Training Center of the Year

Award recognition

Training Camp recently announced that the company was named winner of the Accredited Training Center of the Year (North America) award by EC-Council. Training Camp received this prestigious honor during a reception at EC-Council’s 2018 Global Awards in Atlanta.

“Training Camp is honored to receive this award that recognizes our successful partnership with EC-Council and our clients,” said Mike McNelis, Training Camp. “Our exceptional success is the result of our great team that helped us to grow to where we are now. EC-Council programs have been a central part of our Valor Program, helping our veterans in finding IT employment when readjusting to civilian life. We will continue to leverage our partnership with EC-Council and are committed to helping organizations in building innovative cybersecurity training solutions”

Each year, EC-Council honors Accredited Training Centers and Certified Instructors that have made distinguished contributions to the success of EC-Council certification programs and have made a difference in the rapidly evolving information security and ethical hacking domains. Chosen from over 700 training centers, 107 countries and a wide range of EC-Council certified instructors, EC-Council conducts extensive surveys of credential holders, and their responses factor heavily in determining the rankings.

 

Tata Communications partners with SASTRA to launch specialized cybersecurity lab

U.S. and Australia to Jointly Develop Cyber Training Platform

With an aim to build an ecosystem to address cybersecurity concerns, Tata Communications has launched a specialized cybersecurity lab at Shanmugha Arts, Science, Technology & Research Academy (SASTRA) in India.

The digital infrastructure provider stated that the new partnership move aims to co-create a talent pool by partnering with universities globally. The alliance will focus on training, developing, and strengthening the practical application of cybersecurity.

“This lab will act as a catalyst to spark student interest in specializing in cybersecurity. As a result of this launch, we have already begun to see huge interest among our graduate and post-graduate students”, said Dr. Vaidhyasubramanian, Dean – Planning & Development at SASTRA. “The new facility will help our students gain hands-on knowledge with access to mentors and guest lectures from senior Tata Communications staff, and real-life case studies on how to mitigate cybersecurity risks with the latest cutting-edge technologies. The investment, active involvement and support from Tata Communications will also help our faculty members get better exposure to the latest updates in cyber security which will go a long way in making their classroom lectures more interactive.”

The association stated that they’ve built a curriculum to provide training on the process and technology elements of cyber threat detection and mitigation. It also added that they’ve committed to investing in young talent and offering coaching, mentorship, and technology access to university students.

While inaugurating the lab, Madhusudhan Mysore, CEO, Tata Communications Transformation Services, said, “While there is a higher impetus to opt for STEM courses, the challenge is getting the right kind of industry support, exposure, and hands-on practical experience. These university students are the next generation of professionals and business leaders in the making. Private organizations have the means, expertise and the technology to offer to Academia in order to create the right conditions and environment for students to learn and build on their theoretical and practical knowledge. We are very excited to play a role in enabling these young students to develop specialized skills and thrive, as they go on to become confident and accomplished professionals.”

Recently, Tata Communications unveiled an advanced cybersecurity response center in Dubai. The new response center will provide round-the-clock cybersecurity services to help customers thwart cyber threats in the Middle East region. Inaugurated by Omar bin Sultan Al Olama, UAE Minister of State for Artificial Intelligence and Indian Ambassador to the UAE Navdeep Suri, the Dubai facility marks Tata Communications’ fourth dedicated security center. The rest of the three centers are located in Chennai, Pune, and Singapore.

Bristol airport’s information screens go blank due to cyber-attack

A recent cyber-attack at Bristol Airport caused technical issues which led to the malfunction of flight information screens. The airport authorities notified that the customers were unable to read any arrival or departure information as the flight information screens went blank. The authorities used manual processes to inform passengers about flights information.

“We believe there was an online attempt to target part of our administrative systems and that required us to take a number of applications offline as a precautionary measure, including the one that provides our data for flight information screens,” said Bristol Airport spokesman James Gore “The indications are that this was a speculative attempt rather than targeted attack on Bristol Airport.”

Mr. Gore stated that they were using whiteboards and flipcharts to provide flight information to the passengers and also asking them to allow extra time to complete check-in and boarding formalities.

“Given the number of safety and security critical systems operating at an airport, we wanted to make sure that the issue with the flight information application that experienced the problem was absolutely resolved before it was put back online,” James Gore added.

In a similar cyber-attack incident, cybercriminals hacked British Airways payment system to compromise 380,000 payment-card details of its customers. The airlines in a statement notified its customers that “From 22:58 BST August 21, 2018, until 21:45 BST September 5, 2018, inclusive the personal and financial details of customers making or changing bookings on our website and app were compromised.” The airline also assured that it will compensate for all the losses (if any) to its customers. “Every customer affected will be fully reimbursed and we will pay for a credit checking service. We take the protection of our customers’ data seriously and are very sorry for the concern that this criminal activity has caused.”

Researcher says British Airways hack caused by the same group that pwned Ticketmaster

British Airways

A hacker group dubbed Magecart were responsible for the recent data breach on the British Airways website that affected 380,000 customers’ transactions between August 21 and September 5, a research expert stated.

According to the security researcher Yonathan Klijnsma from cybersecurity company RiskIQ, the attackers allegedly used a skimming script, a malicious code, designed to steal the data from the British Airways website.

“This particular skimmer is very much attuned to how British Airway’s payment page is set up, which tells us that the attackers carefully considered how to target this site instead of blindly injecting the regular Magecart skimmer,” the researcher wrote in a report. “The infrastructure used in this attack was set up with British Airways in mind and purposely targeted scripts that would blend in with normal payment processing to avoid detection.”

On September 6, the British airlines notified its customers that “From 22:58 BST August 21, 2018, until 21:45 BST September 5, 2018, inclusive, the personal and financial details of customers making or changing bookings on our website and app were compromised.” Around 380,000 payment-card details were stolen by hackers during the period.

RiskIQ stated that they’ve discovered some similarities in the British Airways situation and the Ticketmaster heist that happened in June. The hackers used a similar approach in both the cases and RiskIQ thinks it could be performed by the same group of hackers, according to the researcher.

On June 27, 2018, Ticketmaster, a ticketing website, became the victim of a cyber-attack and data breach after hackers stole data from the website including payment information of several customers. The website issued an alert after noticing a malicious software on a customer support product hosted by its third-party, Inbenta Technologies. The company stated that the affected customers may include UK citizens who purchased or attempted to purchase tickets between February and June 23, 2018, as well as international customers who purchased, or attempted to purchase tickets between September 2017 and June 23, 2018.

Few minutes with Ravi Shanker Rao Ulapu

Ravi Shanker Rao Ulapu

Ravi Shanker Rao Ulapu is one of the reputed names in information security. As the Chief Information Security Officer of Hexagon Manufacturing Intelligence, a leading metrology and manufacturing solution provider, Ravi has implemented critical operational strategies to protect the business from cyber threats.

He sat down with CISO MAG Feature Writer Rudra Srinivas for a quick chat and discussed the threats in manufacturing intelligence space,  artificial intelligence, importance of employee awareness, and much more.

Tell us a bit about your journey. What are the biggest challenges you face as a CISO? 

I have been in the information technology and information security field for more than 20 years now. I joined Hexagon Manufacturing Intelligence last year. Prior to that, I was working with Intergraph, a part of Hexagon Companies. I have been fortunate to get all required support from business units and top management in implementing various IT and Security Projects. I have always worked very closely with business teams and most of the time with top management. That helps me to understand business requirements clearly and prepare appropriate strategies accordingly.

I believe some of the biggest challenges a CISO faces are related to integration of security solutions and services, lack of security awareness, and increasing regulations and compliance requirements among others.

According to you, which industries are most vulnerable to cyber-attacks?

In my point of view, financial, health care, and manufacturing sectors are most vulnerable to cyber-attacks.

What are the major cybersecurity concerns in the space of manufacturing intelligence?

With the increasing demand of adding intelligence to manufacturing solutions, this field is evolving rapidly, but at the same time becoming a major target for cyber criminals. This holds true for a company like Hexagon Manufacturing Intelligence (HMI) which is there from past 200 years and incorporated some of the biggest names in measurement and industrial metrology providing new measurement technologies, integrated manufacturing solutions, and process standards of the future.

What is Hexagon’s approach toward automation and orchestration of cyber threats?

We want to ensure our skilled professionals focus more on identifying critical threats and resolving them on priority instead of spending time on handling routine tasks. This can be possible by automation and orchestration of cyber threats and we are in the process of deploying right solutions to achieve this.

Do you think artificial intelligence (AI) will drive the future of cybersecurity?

I would like to say yes. As of now, AI is implemented in mostly experimental level with regards to cybersecurity. Some of the current solutions can identify the problem, but not many can clearly execute required critical security steps. Therefore, I think there is a long way to go.

Do you think cybersecurity awareness and training to employees play a key role in strengthening organization’s information security?

An organization’s security structure is majorly depends on employee’s security awareness. Even after implementing so many intelligent security solutions if people are not trained well, all efforts will be wasted. Cybersecurity awareness training is very critical for all the organizations

What are the essentials you would want an organization to adopt as cybersecurity practices?

Some things they can do are as follows:

  • Prepare the threat profile of the organization and involve business teams to identify threats
  • Top management must lead the cybersecurity programs
  • Organization must maintain clear data of organization assets
  • Review and Control Access Rights
  • Patch systems and applications
  • Regularly train employees to improve security awareness