Home Blog Page 366

State of industrial cybersecurity in dilemma: Kaspersky report

cybersecurity

“More than three-quarters of the operational technology (OT) and Industrial control systems (ICS) companies feel that they are likely to become a target of a cybersecurity attack,” said the Kaspersky Labs’ recent report on “The State of Industrial Cybersecurity 2018”.

The survey, carried out by PAC on behalf of Kaspersky Lab of 320 worldwide professionals with decision-making power on OT/ICS cybersecurity, is aimed at finding the needs of OT/ICS companies, their priorities, concerns, challenges they face, as well as external and internal factors that impact industrial cybersecurity, and the best practices adopted.

According to the survey, over three-quarters of the participants stated that OT/ICS cybersecurity is a major priority. These companies also felt the likelihood of cyber attacks. “Despite this, only 23% are compliant with minimal mandatory industry or government guidance and regulations around cybersecurity of industrial control systems. On the other hand, the vast majority of the companies surveyed are increasing their OT/ICS cybersecurity investments or keeping them at least steady,” the survey pointed out.

On the bright side, more than half of the companies did not experience any incident in the last one year. But most of these companies seemed underprepared, and they have only joined the digitization bandwagon. Moreover, many a time, companies do not detect or even track attacks. And for the rest that witnessed incidents and attacks, it had a “relevant negative impact” on their business.

One alarming trend was that there has been a low maturity rate, given the nature of ICS/OT industries. The report points out the criticality of collaborations between IT and OT teams. “IT and OT people have different goals, processes, tools, and languages, but they must collaborate if they want to protect the OT/ICS space that is more and more blended with the IT space,” the report stated.

“Although it appears there are incremental improvements in several areas of addressing OT cybersecurity risk, it is discouraging to see that for the most part we still lack significant progress across the board when it comes to dedicating resources to these challenges. As we increase the level of automation in our critical infrastructures, we MUST take security issues seriously,” Marty Edwards, Managing Director, Automation Federation, USA, was quoted.

House of Representatives passes legislation to strengthen industrial cybersecurity

House of Representatives

The U.S. House of Representatives passed legislation aimed at protection of industrial control systems from cyber attacks. The bill presented by Don Bacon (U.S. Representative for Nebraska) was passed in a voice vote Monday, June 25, 2018.  The bill, officially known as the “DHS Industrial Control Systems Capabilities Enhancement Act of 2018,” cleared the House Homeland Security Committee in May.

“Industrial controls are the critical interface between the digital controls in an operational process. Disruptions or damage to these systems have the potential to cause catastrophic and cascading consequences to our nation’s national security, economic security and our public health and public safety.” Bacon said earlier this month.

The Department of Homeland Security is presently working on mitigating the cyber threats to industrial control systems which are used for maintaining the critical services like the electric grid, water systems, and manufacturing plants.

The idea of legislation was initiated when the Homeland Security officials found hackers associated with the Russian government are getting access to industrial information after they breached some networks. These exposures caused threats to the U.S. power grid and other industrial control systems.

The Legislation allows the Homeland Security to offer cybersecurity assistance to end users and manufacturers to respond to and resolve cyber vulnerabilities in industrial control systems. It would also allow the department in disclosing the earlier unidentified flaws in these systems to the private sector.

In March, House Lawmakers Ted Lieu and Ted Yoho proposed ‘Hack the State Department’ bill which would set up a bug bounty program to boost cybersecurity preparedness in the department. The program seeks the department to establish a Vulnerability Disclosure Program (VDP) which would enable white hat hackers to penetrate the systems to find vulnerabilities.

Western Australia Govt. establishes Office of Digital Government to improve public sector cybersecurity

Western Australia

In a move to further strengthen the public sector’s cybersecurity, the Government of Western Australia recently announced that it will be establishing a new Office of Digital Government. The Government will also invest more than $500,000 to form a dedicated cybersecurity team for the cause.

Launching on July 1, 2018, the $7.4 million Office of Digital Government will be a separate entity under the Department of the Premier and Cabinet. The McGowan Government is working on the recommendations of the Service Priority Review, which suggested the government reinforcing cybersecurity.

Innovation and ICT Minister Dave Kelly says, “Creating this office within DPC ensures that digital capabilities are embedded within the McGowan Government’s public-sector renewal program and are better coordinated and implemented.”

“These initiatives build on action was already taken since March 2017, including a revised whole-of-government Digital Security Policy; cybersecurity briefings for directors general and CEOs; and a $5.6 million investment in the national Cyber Security Cooperative Research Centre, headquartered at ECU Joondalup,” Minister Kelly added.

The McGowan Government is also in the process of creating a Cybersecurity Reference Group that includes representatives from nine public sector agencies to strengthen government cybersecurity.

In March, the Government of Australia launched Joint Cyber Security Centre (JCSC) facility in Sydney which aims to promote cybersecurity systems across government, business, and academia. The facility is a part of the government’s $47 million JCSC program that bridges the gap between several public and private sectors. These include defence, finance, transport, energy, health, mining, and education.

Led by the Computer Emergency Response Team (CERT) Australia, the JCSC facilities will strengthen the cybersecurity infrastructure of the country and will also be involved in sharing sensitive information, including actionable cyber threat intelligence among myriad bodies in both public and private space, thus flowing amid all domains without any commercial bias.

Cybersecurity concerns make US Marine Corps ban drones

US Marine Corps

Citing the cybersecurity concerns in the commercial off-the-shelf (COTS) drones, the Department of Defense banned the United States Marine Corps from using them.

“The DoD Inspector Normal discovered that the DoD has not carried out an enough course of to evaluate cybersecurity dangers related to utilizing COTS Unmanned Aerial Programs,” stated a policy memo signed by the Deputy Secretary of Protection Patrick Shanahan.

As a part of the ‘Quads for Squads’ program, the Corps had received 600 of the ‘Instant Eye’ quadcopters and 200 more are yet to be received. The drones, designed to navigate compact spaces, would have been used for local surveillance. According to the memo, the drones will be banned “until the DoD identifies and fields a solution to mitigate known cybersecurity risks,” the memo states.

This is not the first time cybersecurity concerns have been raised for drones. Last year, PacSec researcher Jonathan Andersson developed a hardware that is capable of hijacking drones. Dubbed as the Icarus (creator of Labyrinth) from the Greek mythology, the hardware module only needs to be with the range of a drone to hijack it with commands. A video posted by Kaspersky Labs showed Icarus taking control of a drone mid-air within 11 milliseconds of launch. In fact, it can affect any radio controlled device which uses the popular DSMx radio platform.

DDS Dental Technology partners with Identillect’s Delivery Trust

Dental cybersecurity

GLOBE NEWSWIRE: Identillect Technologies Corp., a trusted provider of HIPAA compliant email security, recently announced that DDS Dental Technology has selected Delivery Trust to secure email communications for their dental customers to guarantee HIPAA compliant communication.

DDS Dental Technology Inc. provides the technology solutions to dentists. They also help evaluate everything, from existing hardware, upgrades, security, and encrypted backup service, anti-virus, malware protection, and secure communication. Their services are designed exclusively for dentists in the Chicago area. They work with customers to create a secure IT infrastructure meeting all technology requirements.

Riju Alex, Operations Manager of DDS Dental Technology, stated, “DDS Dental Technology proudly serves the Chicago Dental Community for their IT and security needs. We are excited about the partnership with Identillect Technologies to assist our clients on meeting rigorous HIPAA standards. Delivery Trust will ensure the simplest experience for our clients and streamline the secure recipient process.”

HIPAA Journal recently showed email is one of the most vulnerable ways to communicate due to the cyber-attacks being experienced which includes social engineering, phishing attacks and misdirected emails. Email communication was the second most common location of breached PHI. There’s a myth that including a confidentiality notice or disclaimer in an email makes the email compliant with HIPAA and allows a dentist to send PHI via unencrypted or unsecure email. The myth is false. Even the best-worded notice or disclaimer will not make an unencrypted email comply with HIPAA.

Todd Sexton, CEO of Identillect Technologies comments, “Dental Service Organizations such as DDS Dental Technology provide an invaluable service to their customers by advancing technology for practices of all sizes. Identillect has continued to make a significant impact with these organizations by securing all their client communication and we are seeing a significant rise in our user base in the dental community. We are proud to be partnering with such a quality organization like DDS Dental and anticipate continued growth with similar firms throughout 2018.”

Few minutes with Alexander Stein

Dr. Alexander Stein

Dr. Alexander Stein is the founder of Dolus Advisors, a consultancy providing actionable predictive insight in human risk. The company helps senior corporate leaders and boards understand and resolve human factor issues in organizational ethics, culture, compliance, and governance, and to proactively detect, mitigate, and respond to insider threats, executive misconduct, and white-collar and cyber malfeasance risks. We talked to him regarding the menace of insider threats and how companies can more effectively mitigate them.

You’ve had a very diverse career. Please tell us about that journey so far.

My graduate degrees and training are in psychoanalysis, and I started my career as a psychoanalyst in clinical practice—treating patients, publishing scholarly papers in peer review psychoanalytic journals, teaching, and speaking at conferences. I found myself both gratified and frustrated by that career. Then I was directly affected by the events of September 11, 2001, and that deeply altered my view of what was going on in the world, and catalyzed a shift in my thinking about how to respond, both personally and professionally. From that experience, I decided to take my expertise to a broader marketplace, to deploy psychoanalysis rather than practice it.

I repositioned myself to work with business leaders in their organizations, not just treat individual patients, to have an influence and beneficial impact with people who themselves have tremendous influence and responsibility. I began writing a monthly column for Fortune Small Business magazine on the psychology of leadership and entrepreneurship (currently, I’m a contributor to Forbes writing on the psychology of leadership and misbehavior in business), and launched a consulting practice advising senior business leaders, entrepreneurs, and boards. This advisory work combines clinical insight with practical business strategies to address issues involving people, culture, ethical decision-making and other aspects of corporate and organizational life with complex psychological underpinnings. It remains a core part of my business practice to this day.

Not long afterwards, I was approached by a prominent fraud and corruption litigator who asked for my help in understanding and applying a more psychologically sophisticated framework to bring fraudsters to book and recover the assets they’d stolen and sequestered in serious fraud and grand corruption matters.

I joined forces with members of ICC-FraudNet, a global network of elite fraud and asset recovery professionals, working in multidisciplinary teams as an embedded human factors expert in large-scale international fraud cases.  This was my initial entry into the malfeasance and misconduct space, which is enormous. From a social justice-humanitarian perspective, for all the people, companies, and communities victimized by it, fraud is unfortunately a growth industry. But as an entrepreneur uniquely positioned to help and add value, that experience was and continues to be important. First, I seized the opportunity to innovate and refine Psychodynamic Intelligence Analysis, my gap-leaping architecture and strategic methodology for addressing fraud. I also became alert to the massive problem of institutional and enterprise risk mitigation and defense, recognizing it as an area with significant opportunities distinct from those in fraud and asset recovery cases which are always post-facto and reactive. Organizations are, or ought to be, focused on and better prepared for trying to prevent bad things from happening—malicious incident defense, deterrence, and mitigation. Of course, post-crisis response and recovery is critical for those who will inevitably require it, and it remains an important function in my offerings. But I also began purposefully expanding my practice into an area I’ve developed which I call Human Risk Forecasting: specialist expertise-driven proactive address of the human element and organizational psychodynamics in white-collar misconduct and cybersecurity.

Do you think that cybersecurity is more about humans than machines?

The answer is yes. At core, cybersecurity is about people, not technology. The underpinning drivers and all the other so-called “soft” components—what I call the “shadow risks”—that give rise to malicious incidents are deeply embedded parts of the human condition. The introduction of contemporary technology only provides different mechanisms and vehicles—faster and from distance—for perpetrating the same sorts of nefarious shenanigans—dishonesty, manipulation, espionage, surveillance, theft, extortion, misinformation, unscrupulous practices—that people have inflicted on each other since the dawn of civilization. It’s a mistake for business leaders to consider cybersecurity issues to be more weighted to the technical and technological than to the human psycho-social dimensions.

You head a firm that employs expertise in human risk forecasting, and one of the biggest risks that organizations face now is insider threat. What do you think companies can do to counter or better protect them against this? What is your company doing in that regard?

The insider threat is of course a serious problem for every company. Insider threats, first of all, are never going to be absolutely neutralized. But to take ground, there needs to be a broadening of perspectives on what constitutes both an insider and a threat. Human threats won’t be effectively mitigated without involving a more sophisticated understanding of human psychology, particularly the underpinning drivers of intent and malicious action. The human element in cybercrime is typically categorized as either a bad actor, a weak link, or an agent of prevention and repair. Those categories suit—they’re not entirely wrong—but they’re insufficient and oversimplified. To address insider threats, business leaders really need to understand the depth, substance, and impact of something which is finally being recognized more broadly—cybersecurity is a holistic business and enterprise issue. It isn’t confined just to IT or info-sec.

One of the only ways to mitigate the potential threats from insider malice is to create a culture of principled, moral leadership, and ethical governance and business practices. Of course, info-sec, physical security, and all other forms of technological securitization are crucial. But genuinely potent, effective cybersecurity, especially against negligent and malicious insiders—who have already compromised the perimeter no matter how well fortified it supposedly is—is unachievable if the company’s focus is excessively technical. It must involve the interdisciplinary collaboration of GRC—governance, risk, and compliance—not just each of those disjointedly, with business line heads across the enterprise and a CISO all of whom are excellent leaders in their own rights not just knowledgeable subject matter experts, and who all have authorized channels to each other and to the organization’s upper echelon, including an informed and involved board. Also needed are sophisticated human factor programs involving security awareness and response education and training, and expertly designed and implemented mechanisms for identifying, airing-out and resolving the kinds of people issues that if overlooked or ignored can ignite a crisis seemingly without warning.

Do you think cybersecurity education of employees plays a role in making an organization safe from any kind of insider threats?

Absolutely, yes. That being said, the type, depth, scope, and sophistication of training and education matters. There are too many organizations that consider various forms of perfunctory training and the periodic issuance of memoranda that update their workforce on policies and procedures to be satisfactory. Or they’ll offer fun and engaging training videos (which is certainly preferable to threatening workers with punitive action if they make a mistake). But these are not sufficient.  It really does require a more robust understanding of what happens in human ecosystems, how and why people do the things that they do, not just giving them guardrails to try to prevent them from doing what they do. Behavior cannot be controlled or legislated even if the company—and hopefully not!—is run as a totalitarian dictatorship. But even so, malicious dissent is just waiting to explode.

Enterprises need to prepare their workforce through policies, procedures, and training. But also through authentic example; hypocrisy from managers and senior leadership fatally undermines all other measures. Equally critical are building fundamental shock absorbers into policies, culture, and operations—like tall buildings and suspension bridges which are designed to sway with powerful forces, not just attempt to rigidly withstand them. Companies have to be able to contend with how people actually are, and not just continually insist they be more ideal or aspirational versions of themselves so that problems can be completely prevented. Just to put a tag on that, the short answer is yes, training is very important. But what will truly make a difference is how that training is planned, constructed, and deployed, and how it’s specifically geared to that organization’s culture, population, and business needs, not just in accordance with industry best practices, standards, or regulatory insistence.

A number of C-level executives have repeatedly mentioned that insider threats are often the consequence of bad hiring decisions. According to you, what are the recruiters  doing wrong when hiring cybersecurity talent, especially at a time when a number of companies are focusing on several artificial interventions to get the hiring done?

You’ve expanded the question considerably by bringing in AI and so-called intelligent agents to the process. Let me leave that to the side for the moment and say that in some respects, you already started answering the question by how you asked it: any organization that looks to fill a critical role with somebody who isn’t committed and dedicated to that role, but is looking at it opportunistically, is already undermining the exercise. You could say that there’s something actually self-destructive about hiring somebody to perform a critical function who isn’t qualified to perform in that role at the highest standards. Any organization that does that is choosing to hire a potential insider threat! The damage will come, if not by outright malice then through inadequacy.

What can organizations do? They can apply stringently high standards of excellence to everything that they do. I understand that in certain jurisdictions or sectors, there may be a shortage of highly qualified talent—and the skills gap is a real problem, which the industry is trying to address—but at some point that’s only an excuse, not a valid reason, for not having the human capital the organization requires.

As to the second part of your question, whether AI and other emerging automation technologies are being deployed for hiring or other purposes, the industry is way over its skis. In other words, there’s a radical overestimation of what its capabilities are at this point in respect of both what’s actually needed and what it can do. I understand that intelligent technologies can process vast quantities of data and triangulate an analysis of data sets at a magnitude and velocity that human beings cannot. But in making assessments of people or other aspects of decision-making, even if we are still left having to deal with issues of bias, poor judgment and a host of other intrinsic and unavoidable human qualities and characteristics, there are many elements to the process which technology really is not able to take over and which should not be outsourced to it. My work with both technology companies which develop or sell and organizations looking to onboard and integrate automated technologies into their operations involves helping decision-makers more clearly strategize and mitigate the unintended consequences of misunderstanding the interface of the human and the technological.

One of aspects we discussed earlier is the skill gap. We are all aware that it exists, and a number of C-level executives agree that one of the reasons behind rising cyber threats is the lack of enough people to handle those threats. However, on the contrary, a recent survey asserted that 45% of companies have no cybersecurity managers in their company. Do you think we need more role models in the field?

Let me try to parse my answers to briefly touch everything you’re raising.

I am familiar with that study, and the statistics it lays out are sobering, but at the same time really not surprising. The issue of developing role models is enormously important, within an organization as well as across industries. However in itself, it is not going to close a skill gap. Developing talent is something that needs to begin early, and it includes issues relating to the social inequities that give rise to lack of access to technology and lack of Internet connectivity in low-income or rural areas. In other words, it needs to begin by developing more technological natives in young children, and allowing them to become knowledgeable, fluent, and interested in all of the issues that relate to cybertechnology as just another part of maturation and development, while at the same time, redressing some of the socio-economic issues that are factors in a lack of diversity in the talent pool. The later stages of education, in high school and in university, are equally important for further developing and strengthening interest, understanding, and fluency with technology and how to use it responsibly. But also, constructing curricula which go beyond education in technology and computing but also delves into the arts and humanities, teaches ethics, conflict resolution, and fair-play, and instills pro-social values.

Being a thought leader or some form of mentor will certainly be an enticement for people who are out in the workforce and hunting for jobs. But that’s not going to solve a workforce skills gap issue across the board. I would also add to that that there can be different types of influencers and leaders in a company besides just those credentialed or expert in a particular area of technology.  Leaders who demonstrate integrity, fairness, social awareness, and understand how to treat their workforce—with respect and as valuable contributors—and who understand how to motivate people to do their best are the kinds of roles models who will not only attract talented young professionals but will also indirectly mitigate insider threat risks.

Do you have any thoughts as we wrap up the interview?

First, thank you so very much for inviting me to be interviewed. I’m a specialist in people—mental architecture, human behavior and organizational psychodynamics, not a CISO or technologist. I’m delighted to have this opportunity to shine a light for your subscribers and readers on the critical but too often overlooked and misunderstood human factor aspects of cybersecurity.

The key takeaway I’ll emphasize first is how important it is for senior leaders and other decision-makers in enterprises to appreciate the complexity and ferocity of human psychology. The ways in which the human element is marginalized or subordinated under technology, front-line operational efficiencies, and dutiful but flat-footed compliance and business practices is detrimental, and creates clusters of otherwise avoidable unintended consequences, nearly all of which remain invisible and unconsidered—literally unknown unknowns—until they’re not.

Though most business leaders would agree that prevention is preferable to recovery, reactive crisis triage is the norm, and proactive pre-emption the exception. Many companies go about their business falsely assured, unaware of human rakes-in-the-grass and shadow risks to which they remain vulnerable. These include recognizing that good solutions start with accurately understanding the problem. The tendency to be reductive and simplistic in explaining the drivers of malicious decision-making and behavioral triggers, and then misdiagnosing the root causes, invariably leads to cyclical repetitions of the problem, and frequently the pseudo-solutions also leave the original issue intact and then create entirely new problems as well. Insider threats and other cybersecurity issues aren’t avoided or resolved with good plans alone—there’s a large delta between blueprint and reality regarding ideal conduct and actual human propensities. These and other blind-spots inevitably degrade functions intended to monitor, regulate, mitigate, control, or remediate various risks. Many other countermeasures are compromised by the resultant compounding technical and conceptual debt. And these, in turn, give rise to clusters of waterfall issues with which compliance, risk, info-sec officers, and other business line directors aren’t anticipating and are at a loss to address.

Companies that are truly serious about mitigating enterprise malfeasance—insider threats and other cybersecurity vulnerabilities—need to know that understanding the human element is central to that project.

 

CrowdStrike raises $200mn funding, reaches an evaluation of $3bn

H20.ai raises $72.5 million

Cybersecurity firm CrowdStrike has closed a series funding of $200 million in a round led by investors General Atlantic, IVP, Accel Partners CapitalG, and March Capital. With this, the company has tripled its evaluation to more $3 billion.

In last May, the company joined the ranks of the unicorns reaching a valuation of $1billion. The company has increased 140 per cent in its last fiscal year, and the value of was up 172 per cent making the company reach the $3 billion mark. “We are building the business to support massive volume across the globe,” CrowdStrike president, CEO and co-founder George Kurtz stated in a blogpost announcing the Series E financing. “This round of funding will accelerate the growth of our operations and the pace of our innovation and technology development.”

The company had recently announced $1 million warranty to cover the costs of any data breach within a customer network protected by its CrowdStrike Falcon Endpoint Protection Complete service. CrowdStike was the company that had discovered Russian hackers inside the servers of the Democratic National Committee.

It was also announced as a, “Leader in The Forrester Wave: Endpoint Security Suites, Q2 2018 report.” According to the report, “CrowdStrike has helped shaped the mold for the modern endpoint security suite.”

In its assessment, Forrester states, “Compared to others in this study, CrowdStrike has superior exploit and behavioral detection capabilities, with customers reporting an above-average admin experience and easy deployments. Buyers appreciate the large ecosystem of partners and services, especially the aggressively-priced OverWatch service, which provides proactive threat hunting for teams without advanced security expertise. Forrester expects CrowdStrike to continue showing up on the endpoint security suite shortlist among large and small enterprises for the foreseeable future.”

 

Keep your employees interested in cybersecurity awareness training with these tips

Cybersecurity Training

By Center for Internet Security

As organizations work to make internal company processes and personnel more secure it’s worth asking, “Are we doing enough?” Rehashing an annual awareness training or a yearly email phishing campaign may not be enough to thwart ever-evolving attacks and nefarious activity.

To combat “training fatigue,” which can lead to users not practicing what is preached as best controls, it makes sense to implement more interactive methods of cybersecurity policy awareness and training. These come in many forms:

  • Phishing campaigns: Conducted by an internal “red team,” internal phishing campaigns can train employees to spot and report suspicious emails they may receive.
  • Desktop/tabletop exercises: These cybersecurity exercises help employees learn how they would handle an incident such as a DDoS attack or website defacement.
  • USB drops: Are your employees trained to handle a mysteriously-found USB device? Find out with these exercises.

Be sure that these training methods aren’t simply tested and then forgotten; cybersecurity awareness comprises continual processes of integrating behavioral change into the business process. While technical controls can significantly improve security posture – implementing SPF, DKIM, or DMARC to reduce the risk of a successful phishing campaign, for example – it is important that the technical controls are not the only assessment performed against your organization. In addition to conducting training and awareness programs, managers should invest in understanding the analytics resulting from these programs.

Improving privacy and awareness

With GDPR now into effect, it’s essential that organizations implement security in the form of role-based access controls (RBAC). Privacy, a key component of GDPR, has become a highlighted requirement for organizations, especially those who manage and safeguard personally identifiable information (PII). Each industry (healthcare, finance, academia, etc.) maintains data that requires a form of protection. As this data becomes more integrated across business units and functions, knowing what types of data you’re managing will allow specific training programs to be built.

Often, awareness training requires multiple approaches. For example, you might conduct a phishing exercise against a particular department or utilize a multi-email phishing approach for the whole organization. This can allow the organization to more authentically gauge clicks, versus the exercise-defeating murmurs of “Hey, don’t click that!” which can spread through an office quickly. You’ll also want to take into account different learning styles. For some, a PowerPoint may be enough; others might require a more hands-on approach to security training. A strong training program will comprise multiple approaches to cover a variety of training techniques and learning styles.

This article was originally published on https://www.cisecurity.org/ and has been posted here with their permission.

FactSet hires new Chief Information Security Officer

Appointment

GLOBE NEWSWIRE: FactSet, a global provider of integrated financial information, analytical applications, and industry-leading services, recently announced that Alan Daines will join the company as the Chief Information Security Officer (CISO).

Daines joins FactSet from Dell Technologies, where he was the Chief Information Security Officer and responsible for leading Dell’s global cybersecurity organization. During that time, his team helped secure Dell products, protect the enterprise environment, manage cyber risk, and maintain compliance. Most recently, he was responsible for bringing together Dell and EMC’s security organizations as part of the largest technology acquisition in history. Daines has more than 20 years of experience in information technology security and infrastructure roles.

As FactSet’s CISO, Daines will oversee FactSet’s security organization, leading its highly skilled and dedicated team.  “We are excited to have Alan join FactSet and bring his extensive leadership and expertise to further enhance our cybersecurity program,” said Cindy Finkelman, Chief Information Officer, FactSet. “FactSet has been a trusted partner to our clients worldwide for nearly 40 years, and the addition of Alan to our team exemplifies our commitment to building on that strength.” 

Bithumb suffers massive breach; Bitcoin price dropped by $200

Bithumb

Bithumb, the world’s sixth-largest and South Korea’s second-largest cryptocurrency exchange, suffered a massive breach after hackers stole 35 billion won ($31 million) from the platform. The exchange immediately halted deposit and withdrawal services from its servers.

The company is yet to disclose which and how much cryptocurrency had been stolen. “We checked that some of cryptocurrencies valued about $30,000,000 was stolen,” Bithumb said on Twitter. “Those stolen cryptocurrencies will be covered from Bithumb and all of assets are being transferring to cold wallet.”

The company has assured that it will cover all losses, so that users will not be affected. Within an hour of information going public, the price of Bitcoin price dropped nearly $200, erasing much of the recovery that the markets had seen over the previous two days.

The hack marks the second incident in less than two weeks in South Korea. On June 10, cryptocurrency exchange, Coinrail lost approximately $37.2 million worth of coins. Following the hack, the value of Bitcoin dipped an all-time low of at $6,790.88. The currency exchange lost about 30 percent of the coins it traded. Its website has temporarily suspended trading and is currently working with investigators. The site reassured users that remainder of the coins were “safely stored.”

“This is not the first time that Bithumb was reportedly hacked. As previously reported by CoinDesk, the platform was compromised last year with as many as 30,000 users impacted. At that time, Bithumb later announced that it would repay each victim with 100,000 Korean won each, an amount worth about $85,” suggested a report on CoinDesk.