Home Blog Page 368

Five cloud migration mistakes that will sink a business

Nanocore Netwire AsyncRAT, Cloud security, cloud computing

By Jon-Michael C. Brook, Principal, Guide Holdings, LLC

Today, with the growing popularity of cloud computing, there exists a wealth of resources for companies that are considering—or are in the process of—migrating their data to the cloud. From checklists to best practices, the Internet teems with advice. But what about the things you shouldn’t be doing? The best-laid plans of mice and men often go awry, and so, too, will your cloud migration unless you manage to avoid these common cloud mistakes:

“The Cloud Service Provider (CSP) will do everything.”

Cloud computing offers significant advantages—cost, scalability, on-demand service and infinite bandwidth. And the processes, procedures, and day-to-day activities a CSP delivers provides every cloud customer–regardless of size–with the capabilities of Fortune 50 IT staff. But nothing is idiot proof. CSPs aren’t responsible for everything–they are only in charge of the parts they can control based on the shared responsibility model and expect customers to own more of the risk mitigation.

Advice: Take the time upfront to read the best practices of the cloud you’re deploying to. Follow cloud design patterns and understand your responsibilities–don’t trust that your cloud service provider will take care of everything. Remember, it is a shared responsibility model.

“Cryptography is the panacea; data-in-motion, data-at-rest and data-in-transit protection works the same in the cloud.”

Cybersecurity professionals refer to the triad balance: Confidentiality, Integrity and Availability. Increasing one decreases the other two. In the cloud, availability and integrity are built into every service and even guaranteed with Service Level Agreements (SLAs).The last bullet in the confidentiality chamber involves cryptography, mathematically adjusting information to make it unreadable without the appropriate key. However, cryptography works differently in the cloud. Customers expect service offerings will work together, and so the CSP provides the “80/20” security with less effort (i.e. CSP managed keys).

Advice: Expect that while you must use encryption for the cloud, there will be a learning curve. Take the time to read through the FAQs and understand what threats each architectural option really opens you up to.

“My cloud service provider’s default authentication is good enough.”

One of cloud’s tenets is self-service. CSPs have a duty to protect not just you, but themselves and everyone else that’s virtualized on their environment. One of the early self-service aspects is authentication—the act of proving you are who you say you are. There are three ways to accomplish this proof: 1) Reply with something you know (i.e., password); 2) Provide something you have (i.e., key or token); or 3) Produce something you are (i.e., a fingerprint or retina scan). These are all commonplace activities. For example, most enterprise systems require a password with a complexity factor (upper/lower/character/number), and even banks now require customers to enter additional password codes received as text messages. These techniques are imposed to make the authentication stronger, more reliable and with wider adoption. Multi-factor authentication uses more than one of them.

Advice: Cloud Service Providers offer numerous authentication upgrades, including some sort of multi-factor authentication option—use them.

“Lift and shift is the clear path to cloud migration.”

Cloud cost advantages evaporate quickly due to poor strategic decisions or architectural choices. A lift-and-shift approach in moving to cloud is where existing virtualized images or snapshots of current in-house systems are simply transformed and uploaded onto a Cloud Service Provider’s system. If you want to run the exact same system in-house rented on an IaaS platform, it will cost less money to buy a capital asset and depreciate the hardware over three years.  The lift-and-shift approach ignores the elastic scalability to scale up and down on demand, and doesn’t use rigorously tested cloud design patterns that result in resiliency and security. There may be systems within a design that are appropriate to be an exact copy, however, placing an entire enterprise architecture directly onto a CSP would be costly and inefficient.

Advice: Invest the time up front to redesign your architecture for the cloud, and you will benefit greatly.

“Of course, we’re compliant.”

Enterprise risk and compliance departments have decades of frameworks, documentation and mitigation techniques. Cloud-specific control frameworks are less than five years old, but are solid and are continuing to be understood each year.

However, adopting the cloud will need special attention, especially when it comes to non-enterprise risks such as an economic denial of service (credit card over-the-limit), third-party managed encryption keys that potentially give them access to your data (warrants/eDiscovery) or compromised root administrator account responsibilities (CSP shutting down your account and forcing physical verification for reinstatement).

Advice: These items don’t have direct analogs in the enterprise risk universe. Instead, the understandings must expand, especially in highly regulated industries. Don’t face massive fines, operational downtime or reputational losses by not paying attention to a widened risk environment.

Jon-Michael C. Brook, Principal at Guide Holdings, LLC, has 20 years of experience in information security with such organizations as Raytheon, Northrop Grumman, Booz Allen Hamilton, Optiv Security and Symantec. He is co-chair of CSA’s Top Threats Working Group and the Cloud Broker Working Group, and contributor to several additional working groups. Brook is a Certified Certificate of Cloud Security Knowledge+ (CCSK+) trainer and Cloud Controls Matrix (CCM) reviewer and trainer.

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same!

This blog was originally published at www.cloudsecurityalliance.org and has been posted here with their permission.

Airplane cybersecurity under the radar of DHS

Bangkok Airways

Researchers of the United States government have come to believe that a cybersecurity event in the sky is imminent. Documents obtained by news site Motherboard suggest that according to researchers it is “only a matter of time” that an incident where an airplane is hacked occurs.

The news may come in light of the event where the Department of Homeland Security (DHS) had successfully hacked a Boeing 737 to highlight the vulnerabilities in several commercial aircraft. “We got the airplane on Sept. 19, 2016. Two days later, I was successful in accomplishing a remote, non-cooperative, penetration,” said Robert Hickey, aviation program manager within the Cyber Security Division of the DHS Science and Technology (S&T) Directorate while delivering a keynote address at a recent summit. “[Which] means I didn’t have anybody touching the airplane, I didn’t have an insider threat. I stood off using typical stuff that could get through security and we were able to establish a presence on the systems of the aircraft.”

A section of a presentation from the Pacific Northwest National Laboratory (PNNL), a Department of Energy government research laboratory, read, “Potential of catastrophic disaster is inherently greater in an airborne vehicle.”

The documents obtained by the news site also suggest that the DHS may have already conducted another test against an aircraft and suggested that how aircraft still use little to no cybersecurity protection. “Today’s commercial aviation backbone is built upon a network of trust; most commercial aircraft currently in use have little to no cyber protections in place,” it said.
The documents suggest that DHS team are moving from penetration testing to mitigation development. John Hultquist, director of intelligence analysis at cybersecurity firm FireEye, in an earlier tweet wrote, “ The actors who shut off the lights twice in Ukraine and caused over a billion dollars in economic damage with NotPetya have probed airports,” while pinning at a Russian hacker group.

Irdeto and SafeRide partner to steer automotive security to the right direction

Cybersecurity firm Irdeto and automotive cybersecurity SafeRide have entered a strategic partnership to floor the accelerator pedals of connected car to a safe and secured destination.
The companies will develop joint software solutions that will combine network security with software security on the ECU, “allowing OEMs and Tier-1 suppliers to detect tampering and anomalies to protect against and respond to cyberattacks,” the companies stated in a release. The application provides “multi-layer protection for securing both the vehicle connectivity perimeter and the in-vehicle core layer from known and unknown cyberattacks, including zero-day threats and anomalies.”
“Hackers deploy a number of tactics in order to gain root access to a device and compromise system security,” said Niels Haverkorn, General Manager, Connected Transport, Irdeto. “Our partnership with SafeRide provides a joint security solution that assumes system vulnerabilities have been exploited by an attacker, focusing on protecting a compromised system from misuse. By safeguarding critical files and data as well as preventing tampering of the ECU, we are providing OEMs and Tier-1s with the ability to secure vehicle software and telematics systems from damaging cyberattacks.”
“We feel excited about the aggregated value that this solution brings to the automotive industry as automakers look to deploy connected vehicle applications, including Connectivity Gateways and IVI systems, with reliable cybersecurity support that leaves no room for mistakes,” said Yossi Vardi, SafeRide Co-Founder and CEO. “Irdeto’s Cloakware technology and industry leadership combined with SafeRide’s platform cybersecurity with in-vehicle big-data analytics enables OEMs to offset the security liability, while driving value add applications and new business models.”
The companies will showcase the joint security solution at TU Automotive in Novi, Michigan.

Israeli startup Panorays receives early stage funding of $5 million

Israeli startup Panorays recently closed an early stage funding round of $5 million. The round was led by noted venture capital fund, Aleph and had Amichai Shulman, co-founder and former CTO of Imperva, Elevator Fund, Moshe Lichtman and Michael Dolinsky and several cybersecurity veterans in attendance.
The company also launched its flagship automated platform that secures and strengthens the security of organizations in the supply chain. The platform enables companies to view, manage, and engage with third-parties to reduce their cyber risk.

“We’re seeing increasing demand for our solution, which solves third party security issues. The Panorays platform delivers a 360-degree view of cyber gaps. It does this by automating thousands of activities that mimic those that hackers would apply, combined with internal policy enforcement. Based on the findings and leveraging big data analytics, the platform provides context-based ratings and actionable intelligence,” founder and CEO Matan Or-El said.

Founded by Matan Or-El, Meir Antar and Demi Ben-Ari, the company has several infosec behemoths in its executive team who have held leadership roles in companies like Imperva, AVG, ironSource, Windward, WalkMe and enSilo.

“As a new company in the third-party risk space, Panorays has taken advantage of seeing what other solutions are not doing well to create a solution that will close coverage gaps. By actively engaging third-parties in the business cyber-security risk management program, Panorays uses the web of symbiotic relationships to create a broad ecosystem where all companies involved benefit from each other’s success in reducing risk,” said David Monahan, managing research director, security and risk management, Enterprise Management Associates, Inc.

PumpUp exposes sensitive user info on unsecured Amazon server

Data leak

Ontario-based fitness company PumpUp was recently found to have stored sensitive consumer health data and private messages between users on an unsecured Amazon cloud server. Independent researcher Oliver Hough discovered the vulnerability and notified the team of news site ZDNet to investigate further the matter.

Hough discovered that the consumer data including email addresses, location, workout records, health information like height and weight of the user as well as credit card information was accessible on the unsecured server.

Following which ZDNet tried to inform PumpUp of the breach, most of which landed on deaf ears. The vendor also did not immediately respond to an ISMG request for comment on the breach. “The MQTT server did not have any authentication enabled; anyone with the knowledge to connect to an MQTT could connect and view all messages in transit,” Hough says. “They quietly closed off access; the MQTT server no longer responds at all,” Hough says. “I can’t say much more as PumpUp won’t speak to me or anyone else.”

According to ZDNet, PumpUp has about 6 million users in its apps. It is unclear how many of the data was exposed.

However, according to several reports other than Hough, the officials of PumpUp stated that they aren’t aware of anyone else who had accessed the information. “Beyond the security researcher who originally came across the vulnerability, we are not aware of any other individuals who were aware of this situation or who had access to any of the data,” CEO Garrett Gottlieb wrote in a statement to Global News.

Cyber Insurance and the Liability Paradox

cyber insurance

This article appeared in a CISO MAG’s edition.

Addressing the gathering of CISOs at the 3rd Annual CISO Summit held in Mumbai, India, in July 2017, Sunil Varkey, CISO of Wipro Technologies, pointed out, “The role of CISOs is way more  complex because they handle a domain called cybersecurity. CISOs pester the management to increase the cybersecurity spending. When asked by the management if higher spending would mean the organization would not be compromised, the CISOs often respond by saying, ‘I don’t know.’”

However, complexity often derives new solutions and one of them is cyber insurance. Cyber insurance is not a hot topic and has been around for over a decade and a half. It was designed to alleviate losses incurred from cyber attacks and is a key tool that plays crucial roles. According to the United States Department of Homeland Security, “A robust cybersecurity insurance market could help reduce the number of successful cyber attacks by: (1) promoting the adoption of preventative measures in return for more coverage; and (2) encouraging the implementation of best practices by basing premiums on an insured’s level of self-protection.”

Timetric, in its recent ‘Insight Report: Developments in Cyber insurance,’ concluded that the growing number of attacks have turned cyber insurance into a key mitigation tool.

“Although cyber insurance does not replace the need for cybersecurity technology, it has the ability to complement cybersecurity standards through mitigating cyber risk.”

According to Allianz SE, organizations are paying roughly $3.25 billion each year in annual premiums for cyber insurance. But that number is small considering the cyber insurance market is expected to reach $20 billion by 2025.

Who needs Cyber Insurance?

Everyone! Cybercriminals are not Robin Hood, they do not differentiate between a large company and a small company, and they will do what they do best– steal. While big corporations fortify themselves with several layers of protection, small businesses often underestimate the potential impact of cyber attacks. Many small business owners believe that hackers only attack high-profile organizations when the reality is just the opposite. In fact, nearly 90 percent of breaches occur in small businesses. A bigger concern is that  nearly 60 percent of small businesses who face cyber attacks shut down within six months of the attack.

Because news coverage of attacks primarily focuses on big corporations, small businesses are unaware of the threat they face. “For small businesses, nothing is more important than protecting their livelihood. Cyber liability insurance is another tool they can use to prevent financial disaster in the event of a malicious attack,” stated Natalie Cooper, editor of BankingSense.com, in a report from Cyber Insurance Guide.

The Mismatch

While cyber threats have drastically evolved from the time cyber insurance was first offered, the cyber insurance market hasn’t. One of the reasons is that the cyber insurance market is largely based on old-fashioned ideas about information security and what kind of coverage a breached company will actually need.

A study by Marsh and the UK Government in 2015 concluded that cyber insurance premiums are almost three times higher than commercial general liability policies. But even here, there has been a huge gap between the damage incurred and the breadth of policy coverage.

For example, in 2014, when PF Chang’s, a U.S.-based dining restaurant chain, was hacked and credit card information of nearly 60,000 customers were leaked, Chubb cyber-insurance, the insurer, only covered the cost incurred for investigation of the data breach, legal advice, and the expenses for notifying authorities and customers.

PF Chang’s policy with Chubb stated that it would “address the full breadth of risks associated with doing business in today’s technology-dependent world,” but, PF Chang’s argued, much of the cost of having been breached was not, in fact, covered. Due to this discrepancy, PF Chang’s sued Chubb to recover an additional $2 million the company was required to repay credit card companies whose details were stolen in the hack and subsequently used tomake fraudulent transactions. The suit was rejected by the court upon hearing the argument from Chubb that the policy signed by PF Chang’s did not cover any external contract or agreement the company held.

Perhaps if more companies find themselves in situations like PF Chang’s did, cyber insurance policies will be forced to evolve in accordance to the needs of the market. As it stands now, high premiums keep  cyber insurance out of reach for most medium and small businesses, but as insurance companies strive to beat their competition with better, more comprehensive policies, prices will fall too.

Solution for the present perils

The PF Chang’s case is an example of a company not fully understanding its insurance policy, or at least, not fully understanding how that policy could be defended in court and leave them vulnerable. According to a report by JLT Re and JLT Specialty Limited, “Traditional P&C (property and casualty) products were not designed to protect against today’s fast-moving cyber risk landscape.

And there are now growing fears that future losses may bring unanticipated accumulations due to potential ‘silent’ exposures.” Silent cyber risks are things like “(re)insurers’ potential exposure to cyber losses within P&C products where no explicit exclusions are included. And even where exclusions are included, gaps can emerge in the event of unforeseen causes of loss. As exposures evolve, the lack of understanding around silent cyber risks could pose a material threat to (re)insurers’ future solvency.”

While there is an increased number of takers for cyber insurance, the underwriters are concerned over the unquantified cyber coverage (like the incident of PF Chang’s). The report points out the need for, “greater certainty, expertise, capacity and stability from the (re)insurance market in a complex and growing risk area.” It also notes that the “standalone insurance market holds the promise of unlocking the potential for meaningful coverage for both insurers and buyers.” This means that traditional insurance companies’ longstanding history in the insurance business could actually be holding them back from offering the solutions that an industry as dynamic as information security really needs. The structures they have in place may not apply to cybersecurity because threats are often unforeseeable, the impacts of known threats aren’t easy to predict, and there is so much ongoing change that long-term policies can be out of date long before they expire.

Sources:

https://www.dhs.gov/cybersecurity-insurance

https://www.firstdata.com/downloads/thought-leadership/Small_Businesses_Cost_of_a_Data_Breach_Article.pdf

https://www.reportlinker.com/p04956456/Developments-in-Cyberinsurance.html

https://www.marketplace.org/2017/06/30/tech/kidnapping-and-extortion-insurance-your-computer

https://blog.constructaquote.com/wp-content/uploads/2017/07/CAQ-Cyber-Insurance-Guide-v3.pdf

https://www.royalholloway.ac.uk/isg/documents/pdf/technicalreports/2017/rhul-isg-2017-9-payne.pdf

https://www.law360.com/articles/804825/pf-chang-s-loss-highlights-common-holes-in-cyber-coverage

https://www.jltre.com/~/media/files/sites/jltre/insights/viewpoint/jlt_re_viewpoint_cyber_april_2017.pdf?la=en-gb

Infosec Superman: Dan Bowden

Dan Bowden

Contributed by Renee Small

Dan Bowden, the vice president and chief information security officer at Sentara Healthcare, is helping the next generation of cybersecurity specialists grow and develop with his year-round student program.

Dan spent several years in the United States military in the early 1990s, which was a time when people were transitioning from mainframe systems to distributed computing. “We’re transmitting classified data,” Bowden remarked of his work in the military, where such things as operational security and encryption are important to keep an enemy from figuring out one’s plans. “When you’re in the military and you deal with technology, it’s all about security.”

After leaving the Air Force, Dan spent time in the retail space, then got involved in systems architecture in the banking industry for eight years – work which required a lot of cybersecurity. He has since spent the last decade in the healthcare industry, nine of which were spent evenly divided between doing work in the healthcare industry and academia, as he was also the CISO at the University of Utah.

When asked if he’s hired someone who had no prior cybersecurity experience but who has the skills and aptitude for the role, Dan remarks: “I’ve actually had the opportunity to do that many times.” Dan’s present deputy is one such hire. The deputy was a skilled network architect, and over the past year has learned and excelled in his current role.

Thanks to Dan, Sentara has a program where students work part-time, year-round in cybersecurity. There’s no down time for the student hires or interns working with Dan and his team. They are given ongoing, meaningful projects such as doing malware analysis on links and e-mail attachments. “It’s not the traditional internship where they’re here with you for six months and you find stuff for them to do and then they go away,” Dan notes.

At present, Sentara has ten students who are considered as part-time staff, and who are treated like any other staff member. They are given more work and more unique challenges as their skills and abilities expand. “They’re just working shorter hours and need a little more on-ramp training,” Dan notes, when comparing them to full-time staff members. “We miss them when they’re not here and so we go look for more students,” he concludes.

Dan considers the student program at Sentara to be an investment for both the company and the community, pointing out that fresh graduates who say, in their resumé, that they were “a junior cybersecurity analyst at Sentara Healthcare” won’t have any difficulty finding a job.

He also points out that companies, as a way to fill up their cybersecurity staff, consider getting people who have the aptitude and the skills but don’t know or have “every single thing” companies need in a cybersecurity position. “90% of those people if you give them a 90-day on-ramp, they can do 80% of what you need done after a few months, then learn the rest in the months following,” he notes.

Renee Small is the CEO of Cyber Human Capital, a human resources business partner in the field of cybersecurity, and author of Magnetic Hiring: Your Company’s Secret Weapon to Attracting Top Cybersecurity Talent.

“Elvis of Business” is Palo Alto Networks’ new CEO

Palo Alto

Former Chief Business Officer of Google and Chief Operating Officer of SoftBank, Nikesh Arora, is appointed by Palo Alto Networks as the new chief executive officer and chairman of the Board of Directors. Arora will succeed Mark McLaughlin, who is now transitioning as the vice chairman of the Board for Palo Alto Networks.

Arora was fondly christened as the “Elvis of business” by Fortune magazine a few years ago. Although this may be Arora’s foray into the realm of cybersecurity, he has a proven prowess in building corporate behemoths. He is often credited with helping Google transform into the profit-spinning dynamo it is today leading to the employment of more than 20,000 employees, as well as developed a substantial track record of driving innovation and delivering business success. While at Softbank, he was touted to transform the corporation into the Berkshire Hathaway of technology by Fortune, again.

“I am thrilled and honored to join Palo Alto Networks. I have developed a deep appreciation for the company’s culture, values and pioneering spirit as innovators and disruptors and I look forward to working with the entire Palo Alto Networks team on our mission of protecting our customers in the digital age,” Arora stated in a release.

“The company is executing extremely well and is the clear leader in next-generation security. Over the course of several quarters, I have been discussing succession planning with the Board and I couldn’t be more pleased that we have found a leader in Nikesh who is ideally suited to take the company on the next leg of its journey,” said McLaughlin, who will be the Vice President of the Board.  “I look forward to working with Nikesh as we transition and serving as vice chairman of the Board.”

Dubai to up the automotive cybersecurity ante before 2030

Dubai cybersecurity

Ahead of the smart transport project of Dubai by 2030, where 25 percent of the passenger trips will migrate to driverless vehicles, the government of Dubai is now mulling on sprucing cybersecurity of smart and driverless vehicles. The initiative comes in the light of several driverless cars causing fatal accidents to pedestrians around the world. “Cybersecurity is paramount in shaping the future of autonomous vehicles,” Amer Sharaf, director of compliance support and alliances at the Dubai Electronic Security Center told The National. “Any oversight may result in compromising the safety of passengers. The futuristic vision of driverless cars can be realised only with a high level of cybersecurity.”

The smart project of 2030 is touted to be the emirate’s strategy to become the smartest city in the world and achieve a sustainable economy in the UAE. The project is a joint venture between the Roads and Transport Authority and Dubai Future Foundation. A trial run of an autonomous vehicle on a pre-programmed route was also held. The government has entered a partnership with Chinese startup EHang to bring a closed-top passenger drone, as well as with Uber to testing flying cars in its skies. Mid last year, the emirate showcased the first public test of its drone taxi service.

“Cybersecurity is the biggest concern for companies evaluating risk in the nascent self-driving vehicle industry, according to a survey by the world’s second-biggest reinsurer Munich Re. Car makers are developing self-driving technology to reduce deaths on the highway but it could be a bumpy road to get there: they have to find ways to prevent vehicles from being accessed remotely by hackers. This becomes more difficult as the cars will have higher levels of connectivity than those currently on the road. Given the Middle East’s focus on smart cities and its vulnerability as one of the most prone regions to cyber threats, it needs to take a closer look on how to address these risks,” Sharaf said. “Dubai, which is currently working on what it dubs the Cyber Security Standard with the Roads and Transport Authority and other government entities, is studying steps to mitigate cyber risks in autonomous mobility. The first stage was an “extensive” survey of threats to the security of the vehicle’s communications system, software, hardware and supply chain.”

What do you need in your cyber incident checklist?

Cybersecurity Checklist

Contributed by Center for Internet Security

Establish Reliable Facts and a Way to Stay Informed

  • Who is reporting the problem? How did they become aware?
  • What do we know so far about what happened?
  1. What networks/systems are affected?
  2. What data/information was compromised (e.g., stolen, deleted, altered)?
  • When did the breach occur?
  1. When did we find out about it?
  2. When did we begin to do something about it?
  3. When will we know the full scope of the problem?
  4. When do we estimate that the problem will be remediated?
  5. Where did the breach occur (what office, activity, locale, etc.)?
  • How much do we know, with certainty, about how the breach occurred? The source of the attack?
  • How will we stay informed of efforts to remediate the breach and restore normal service?

 

Mobilize a Response

  • Who has the lead in directing operational response efforts?
  • What role will your office play? Has the EI-ISAC been notified (1.866.787- 4722)?
  • Who else should be notified at this point (e.g., citizens, business and industry, other state, local, federal officials, etc.)?
  • Has law enforcement been notified?
  • What expertise is on hand to work the problem? What additional help do you need? Who will provide it?
  • What measures are needed to secure the networks/systems from further exploitation?
  • What additional steps are needed to secure data holdings?
  • How will the remediation efforts to limit/ repair the damage and restore normal services be prioritized?
  • What special notifications should be prepared for victims?
  • What other actions do your breach notification laws require?
  • What are the legal implications of the incident?

 

Communicate What You Know

  • Here, as elsewhere, bad news does not get better with age, but remember the general rule that the first report is always wrong.
  • Release your initial public statement as soon as you have a reasonable command of the problem and can explain what you are doing about it.
  • Describe what you know so far about what happened and what is being done to correct it.
  • Be prepared to explain the preexisting cybersecurity posture and the measures that were in place to prevent events of this kind.
  • Be prepared to explain the steps you will take to prevent future unauthorized intrusions. Start with basic cyber hygiene and the CIS Controls.
  • Establish a regular cadence of updates for victims, media, and other stakeholders—including your own workforce.

This was published here with permission from Center for Internet Security

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same!