Home Blog Page 362

Cybersecurity stocks to do well in anticipation of meddling in midterm elections: Goldman Sachs

Australian Securities and Investment Commission Hit by a Cyberattack

Cybersecurity stocks would be a good bet for investors ahead of the U.S. 2018 midterm elections, Goldman Sachs stated recently. The investment bank anticipated that the rise in cybersecurity spending and concerns about the possibility of meddling in the elections might lift the cybersecurity stocks in the near future.

Arjun Menon, an analyst from Goldman Sachs, said, “Recent press reports suggest rising concerns about the possibility of meddling in the U.S. midterm elections this November,”

“A rise in allocation to security spending – the top spending priority among chief investment officers according to the most recent GS IT Spending Survey – in anticipation of potential threats would boost the top-line of cybersecurity stocks.”

“Cybersecurity stocks are expected to grow sales faster than the Info Tech sector and S&P 500 in 2019 and trade at below-average relative valuations,” Menon added.

Apart from the election perspective, Goldman Sachs presented a favorable uptick for the cybersecurity industry. “Reasonable relative valuations and favorable fund positioning relative to history should benefit fund returns,” it wrote to clients. “Exposure to high-growth stocks, insulation from tariffs, and stronger-than-average balance sheets also represent near-term tailwinds to cybersecurity stocks despite their mixed long-term outlook.”

The Goldman Sachs statements are seen as influential after 12 Russian intelligence officers were mentioned in a new indictment issued on Friday, July 13, 2018, by Special Counsel Robert Mueller that charges the Russian government for its meddlesome in the election.

Putin proposes joint investigation with US on election meddling

Vladimir Putin

The Russian President Vladimir Putin recently proposed a joint cybersecurity group between the U.S. and Russia to investigate Russian meddlesome in the 2016 U.S. presidential election.

While speaking at the Helsinki summit, Putin said, “Once again, President Trump mentioned the issue of the so-called interference of Russia (during) the American elections and I had to reiterate things I said several times.”

“Any specific material, if such things arise, we are ready to analyze together. For instance, we can analyze them through the joint working group on cyber security, the establishment of which we discussed during our previous contacts.” Putin added. He said Russia favors “continued cooperation in counter-terrorism and maintaining cybersecurity.”

“The most recent example is their operational cooperation within the recently concluded World Football Cup,” Putin went on to add. “In general, the contacts among the special services should be put to a system-wide basis should be brought to a systemic framework. I reminded President Trump about the suggestion to re-establish the working group on anti-terrorism.”

Putin’s latest suggestion comes on the heels of Special Counsel Robert Mueller mentioning 12 Russian intelligence officers in a new indictment for their meddling in the 2016 U.S. presidential election. Putin comments also prompted Trump’s cybersecurity proposal endorsed in a tweet on Jul 9, 2017.

While speaking at a cybersecurity conference in Moscow on July 10, 2018, the Russian President stressed upon the importance of mutual collaboration from all nations to defend from cyber threats. Putin described Russia’s association with European nations for the protection of personal data rules as a positive move toward international cooperation.

Putin also stated that they are developing an automated system that enables enhanced communication between businesses and law enforcement agencies to strengthen cybersecurity. However, Putin didn’t speak on the accusations that Russian hackers have intruded in the U.S. 2016 presidential elections.

 

Domestic companies to be preferred for Indian government’s cybersecurity procurements

India cybersecurity

In an attempt to promote government’s much-ambitious program, “Make In India”, Indian companies will now get preference in government’s cybersecurity procurements including both hardware and software solutions, the country’s Ministry of Electronics and Information Technology (MeitY) notified.

In a cybersecurity product notification issued on July 2, 2018, the Ministry of Electronics and Information Technology (MeitY) said that it “hereby notifies that Cyber Security being a strategic sector, preference shall be provided by all procuring entities to domestically manufactured/produced Cyber Security Products.”

The notification is based on Public Procurement (Preference to Make in India) Order 2017 which was intended to enhance the revenue and employment in the country. The notification in 2017 stated, “Preference shall be provided by all procuring entities to domestically manufactured/ produced cybersecurity products as per the order.”

“The Government has issued public procurement order to encourage ‘Make in India’ and to promote manufacturing and production of goods and services in India with a view to enhancing income and employment,” the notification further declared.

As per the draft, cybersecurity product means a product or appliance or software manufactured/ produced for the purpose of maintaining confidentiality, availability, and integrity of information by protecting computing devices, infrastructure, programs, data from attack, damage, or unauthorized access.

The notification defined ‘local supplier’ of domestically manufactured/ produced Cybersecurity Products as company incorporated and registered in India as governed by the applicable Act.

The notification also mentioned that resellers, dealers, distributors, and support service agencies of foreign-developed products and services who have limited rights to a product’s intellectual property are exempted from the tentative mandate.

Indicative list of cybersecurity products includes 20 items such as Big Data Analytics, Secure Access, Web Security, Antivirus/ Antimalware and Mobile Payment among others.

While commenting on the move, eminent cybersecurity lawyer and expert Prashant Mali told a news agency, “The mandate will prevent sensitive data being illegally accessed from outside the country or being sold by the state-sponsored companies of different foreign countries. This was a serious concern and a grey area, and now this gets addressed”.

Note: The updates regarding July 2 notification have been added to this article. 

Israel sets up cybersecurity operations center to protect railway system

Israel railway

An Israeli government-owned defense technology company, Rafael, recently established a cybersecurity center to strengthen its railway network system, according to a news agency.

The new cybersecurity operations center (CSOC), to be operated by Israel Railways’ cyber unit, is worth $8.25 million and located in the city of Lod in central Israel. The new cybersecurity center aids in developing measures to strengthen the information security structure of the railway network systems. According to the rail authorities, around 10 million attempts intended to compromise the railway network information and insert malicious content are blocked every month.

In related news, the personnel of Israel Defence Forces (IDF) recently faced a honey trap when Palestinian Sunni-Islamist fundamentalist organization Hamas created fake dating and FIFA World Cup 2018 applications to entice soldiers into downloading malware onto their mobile phones with the intention to gather sensitive information about the military activities around the Gaza strip.

According to the reports, several Israel Defence Forces personnel were contacted through social media to download dating apps like WinkChat and GlanceLove. Hamas also created bogus profiles with the stolen identities of young women, asking to chat on WhatsApp and interact with soldiers and later requesting them to download their Trojan Horse apps on Google Play Store. The applications allowed the creators to know the user’s location, contact list, access the phone’s audio device to tap calls as well as access video camera to monitor activities.

The Australian government opens its fourth joint cybersecurity center

Perth

With an aim to protect its energy and resources sector, the state of Western Australia recently opened a Joint Cyber Security Center (JCSC). The public-private partnership center located in Perth is the first of its kind in Western Australia and fourth in Australia.

The new facility will enable cybersecurity experts from government organizations and universities to share information on security threats via an organized portal. Inaugurated by the Attorney-General Christian Porter, the facility will organize workshops throughout the year to address cybersecurity issues and challenges.

“Being a trading and export economy, we have the most mature and deep links with a range of countries – China, Malaysia, Indonesia, Singapore”, the Attorney-General said.

“Our mining and resource companies are particular companies that need to be very hard targets against cyber security threats and cyberattacks.” he added.

The other three cybersecurity centers are based in Sydney, Melbourne, and Brisbane, respectively. Another center is expected to open in Adelaide later this year.

On July 3, 2018, an inspection by the Australian National Audit Office (ANAO) exposed the failure of key Australian government agencies to implement cybersecurity requirements. The ANAO’s fourth report on the cyber resilience of government departments and agencies stated that except the Treasury Department, both the National Archives and Geoscience Australia failed to implement the top four mandatory cybersecurity strategies instructed by the Australian Signals Directorate (ASD). The top four mandatory strategies include application whitelisting, application patching, OS patching, and the control of administration rights.

Also, there are four non-mandatory, but recommended cybersecurity mitigation strategies for all the government bodies. According to ANAO, execution of these four measures has been mandatory since April 2013. The ANAO also revealed that Geoscience Australia is vulnerable to cyberattacks due to its lack of compliance with any of the essential eight cybersecurity guidelines.

Twitter suspends two accounts mentioned in Robert Mueller’s indictment

PM Modi Twitter

Social networking site Twitter suspended two accounts connected to 12 Russian intelligence officers accused of meddling in the 2016 U.S. presidential election. The officers were mentioned in a new indictment issued on Friday, July 13, 2018, by Special Counsel Robert Mueller that charges the Russian government for its meddlesome in the election.

According to the statement, Twitter suspended two fictitious accounts; @DCLeaks and @Guccifer_2 which are involved in hacking the voters’ information to influence the election.

“The accounts have been suspended for being connected to a network of accounts previously suspended for operating in violation of our rules.” A Twitter official said in a statement.

A number of social media handles have acknowledged that Russia meddled in 2016 U.S. presidential elections. On November 1, 2017, Twitter announced that it shut down 2,752 accounts linked to Russia’s Internet Research Agency, which is known for promoting pro-Moscow messages. It also said that Russia-linked accounts posted 1.4 million election-related tweets from September 2016 to November 2016, nearly half of them are automated.

Last year, Facebook also claimed that a Russian group posted more than 80,000 times on its service between January 2015 to August 2017. Nearly 29 million Facebook users directly received its posts in their news feeds. The social networking company disclosed these numbers to the Senate Judiciary Committee on October 31, 2017. Search engine giant Google also mentioned in a blog that it found 18 YouTube channels hosting 1,108 videos with 43 hours of material, that got 309,000 views between June 2015 to November 2016.

 

Six massive insider breaches in the last five years

Insider threat

By Rudra Srinivas

Insider threat is a primary concern for every information security leader. Several organizations are seen spending massive resources to keep the bad guys out, but they fail to address the insiders within their own company.

As a result, a number of data breaches happen due to the employee negligence or unintentional actions like responding to a phishing email with sensitive information or downloading malicious content. We take a look at six notable data breaches that were caused due to insiders:

SunTrust Bank

On April 20, 2018, Atlanta-based financial services firm SunTrust encountered a data breach that might have compromised around 1.5 million customers’ personal information. The financial firm notified its customers that an ex-employee of SunTrust gained unauthorized access to the data related to bank accounts such as customer’s names, account numbers, addresses, and contact details.

Fortunately, the information that was stolen did not include sensitive data like social security numbers, PINs, user IDs and, passwords. While the issue is still under the investigation, the SunTrust bank announced that it took appropriate measures to heighten its data security.

Anthem Medicare

In July 2017, Anthem, an American health insurance company, reported a massive data breach that resulted in an identity theft of 18,000 Anthem’s Medicare members. In April 2017, the company discovered that an employee who worked for one of the Anthem’s healthcare consulting firms was stealing and misusing the information of Medicaid members since July 2016.

The employee illegally sent a file containing the company’s data to his personal email address. The stolen data included Medicare ID numbers, social security numbers, health plan ID numbers, names of members, and dates of enrollment. The employee was suspended from the services and placed under the investigation.

Central Bank of Bangladesh

In February 2016, a group of hackers attempted a heist of $951 million from the Central Bank of Bangladesh. The cyber thieves attempted to move the funds into five different accounts held at Rizal Commercial Banking Corporation in the Philippines. While the bank succeeded in recovering $870 million, an internal investigation later revealed that the breach happened due to five low-level and mid-level officials.

“They were negligent, careless and indirect accomplices,” Bangladesh Central Bank Governor Mohammed Farashuddin told Reuters.

Morgan Stanley

In 2015, the financial service provider was exposed to an insider breach which compromised more than 730,000 customer records. It was discovered soon after that an employee Galen Marsh, who worked as financial adviser in Morgan Stanley´s private wealth management division, was the culprit.

During negotiation for a new job, Marsh stole important information including customer names, addresses, account numbers and other credentials. He soon pleaded guilty and Morgan Stanley ended up paying $1 million as a penalty

JP Morgan & Chase

The American multinational investment bank and financial services company experienced a massive data theft in 2014 which exposed 76 million customer records. The company described that hackers compromised an employee’s personal computer and went onto gain unauthorized access to the company’s server over a period of two months.  The bank declared that customer names, email and postal addresses, and phone numbers of account holders were compromised. However, the account login credentials such as social security codes, PINs and passwords remained safe.

The cyber attack was carried out in June, discovered in late July, and could not be stopped till the middle of August 2014. The FBI officials later arrested the suspects involved in the incident.

Korea Credit Bureau

Nearly half of the South Korean population got affected when their sensitive information was compromised by an insider at Korea Credit Bureau in 2014. The credit rating company stated that around 20 million records were stolen, which included customer names, phone numbers, social security numbers, credit card numbers and their expiration dates.

The investigation concluded the data breach was done by a temporary consultant at the Korea Credit Bureau (KCB), who gained unauthorized access to the customers’ data from the company’s server and sold it to marketing firms. The culprit and the people who purchased the stolen data from him were later arrested.

Cryptocurrency exchange Bancor suffers massive breach

cryptocurrency hack

The decentralized cryptocurrency startup Bancor recently fell victim to a cyber heist after hackers stole $23.5 million in three different cryptocurrencies.

In its social media update, Bancor stated that the hackers breached its wallet that was used to upgrade the user contracts. It was then later used to steal $12.5 million of Ether Tokens, $1 million of Pundi X, and $10 million of Bancor Network Tokens.

The Switzerland-based startup offers a low-cost cryptocurrency exchange platform for users to convert tokens directly from their wallets. Post the breach, Bancor froze the BNT tokens and limited damage to its own coins. However, they declared that they can’t freeze or recover the theft of the Ether tokens. The security officials at Bancor stated that they will be able to reduce the losses to $13.5 million of Bancor Network Tokens after finding the compromised wallet.

“We are now working with dozens of cryptocurrency exchanges to trace the stolen funds and make it more difficult for the thief to liquidate them,” Bancor said in a statement.

Cyberattacks on cryptocurrency exchanges have increased in recent times. According to a report from US-based cybersecurity firm CipherTrace, the first six months of this year experienced a huge surge in cryptocurrency exchange thefts. The report stated a total of $761 million was stolen from cryptocurrency exchanges in the first half of 2018. The amount already exceeds the whole amount, $266 million, of 2017 by three times. The company also estimated the losses could rise to over 1.5 billion in the current year.

The missing link to finding insider threats: Human Resources

Human Resources

Contributed by Renee Small

According to the Ponemon Institute’s 2017 Cost of Data Breach study, 47% of the organizations represented stated that the root cause of the security breaches they suffered was a malicious or criminal attack. Respondents reported that breaches caused by criminal attacks were costlier than system glitches and human error. Some of the largest and most infamous breaches have been classified as insider threats. There are numerous technologies in the marketplace that do their part to help organizations protect themselves against insider threats, but having the right technology isn’t enough to stop these kinds of threats. A thoughtful insider threat program that addresses technologies, policies, and procedures is needed to combat insider threats. There is a human element in every single breach. Sometimes, it’s a malicious actor with the intent to harm the company and ensure that they benefit; other times, it’s an employee who accidentally clicks on a phishing email, for example, and unexpectedly exposes the organization to malware. So, the question remains: What can we do to prevent this from continuing to happen at this scale and how quickly can the incident response team find the breach when it inevitably does occur?

One area of the organization that seems to be overlooked or underutilized for using detection strategies and combating the insider threat is Human Resources. It’s typically not the first area that security leaders think of when focusing on insider threats, but it should be. HR professionals bring a diversity of thought that is inherently focused on human psychology and is typically different from the technologist’s point of view. Similar to how the enterprise risk management groups in larger organizations are viewing and assessing all types of risk across the company, HR sees the patterns of various employee issues that are happening across the organization and may be able to spot trends in certain departments or employees before they do harm to the company.

HR should play an integral role in an insider threat program with multiple touch-points throughout an employee’s career (beginning at the hiring stage) according to the CERT Insider Threat Center. CERT also provides a list of best practices that organizations can adopt to shore up their insider threat programs. The ones that are easier to implement and provide the biggest impact include:

Mature your insider threat program

Implement or mature your current insider threat program to include the broader organization––IT, HR, legal, enterprise risk management, and other areas of the company. Due to the sensitivity and confidentiality of this work (potentially probing into an employee’s private life), it is important to utilize HR as a starting point for policies and for ensuring that HR employment laws align with the program.

Track terminated employees 

Since 70% of insider threat incidents are completed within 60 days of an employee leaving the organization, you should have HR provide an automated list of voluntary and involuntary terminated employees.

Improve employee engagement 

Preliminary studies show that engaged employees who are fulfilled in their jobs are less likely to pose an insider threat. Partner with HR to understand best practices for maturing employee engagement programs.

Develop a watchlist of employees with behavioral indicators

HR will be essential in creating a list of employees who are exhibiting behaviors that could be an indicator for insider threats. Some examples are frequent policy violations, disruptive behavior, financial hardship, and job performance problems. Disgruntled employees are a consistent factor when it comes to insider threats.

Add insider-threat awareness training to overall security awareness training 

At this point, a majority of organizations have security awareness training for their employees. Partner with HR to add insider threat awareness to the security awareness training. Like other training that is mandatory, ensure all users have completed the training and provide refreshers throughout the year so employees stay abreast of red flags and can spot malicious or accidental threats when they see them.

Companies have been successful by making updates to:

Pre-hiring practices

Larger organizations have pretty robust background check processes when hiring employees; however, some of the smaller companies must continue to mature their hiring practices by updating policies to include Google searches and social media searches. Since past performance is an indicator of future performance, this additional data check can help with hiring decisions and determining if the candidate could pose future employee issues.

New hire on-boarding

During on-boarding, the new employee is provided with mandatory training. Insider-threat awareness training should be added to the training deck an employee must complete. It can also be administered during the times of the year that there may be higher cases of security breaches or insider threats.

Mandatory vacation policies

Many organizations have roles––typically in finance, payroll, or trading––where the employee is subject to mandatory vacation. These policies should be expanded to some high-risk IT roles where employees have access to admin rights that could be a threat to the company if used maliciously.

In conclusion, there is no question that policies, procedures, and technologies are necessary in trying to prevent and detect insider threats; however, in order to minimize the damage of breaches in the future, there should be a multifaceted approach with an emphasis on a partnership with HR to provide the best barrier of protection against your own employees.

Renee Small is the CEO of Cyber Human Capital, and author of the Magnetic Hiring: Your Company’s Secret Weapon to Attracting Top Cyber Security Talent. Download a free copy at www.magnetichiring.com/book.

AT&T acquires AlienVault to strengthen enterprise security solutions

AT&T Inc.

The world’s largest telecommunications company AT&T announced that is has acquired cybersecurity startup AlienVault, according to a press release. The acquisition enables AT&T to fortify its security measures for small and medium-sized enterprises.

“Regardless of size or industry, businesses today need cyber threat detection and response technologies and services,” said Thaddeus Arroyo, CEO, AT&T Business. “The current threat landscape has shifted this from a luxury for some, to a requirement for all.”

“AlienVault’s expertise in threat intelligence will improve our ability to help organizations detect and respond to cybersecurity attacks. Together, with our enterprise-grade detection, response, and remediation capabilities, we’re providing scalable, intelligent, affordable security for business customers of all sizes,” said Arroyo.

Headquartered in San Mateo, AlienVault offers preventive measures to address cybersecurity threats via its Unified Security Management platform. The company also owns an Open Threat Exchange online platform that allows security professionals to share information on data threats.

Speaking on the new initiative, Barmak Meftah, president, and CEO of AlienVault said, “We’re thrilled to join forces with AT&T. They bring a robust cybersecurity portfolio with an industry-leading technology ecosystem. This deal accelerates our ability to deliver on the AlienVault mission, which is to democratize threat detection and response to companies of all sizes.”