Home Blog Page 370

Five Cyber Changes Homeland Security is Making—and a Warning to Digital Foes

Homeland Security

Here’s a bulletin from RSA: I just watched Secretary of Homeland Security Kirstjen Nielsen issue a warning to cyber attackers of all types.

“I have a news flash for America’s adversaries. Complacency is being replaced by consequences.” I first reported this in my Live Blog: Lost at RSA 2018.

That warning is a definite change of tone, and it is all part of what the Secretary described as a “more forward-leaning strategy” on the cyber front.

Five changes Homeland Security is making around cybersecurity

Secretary Nielsen told the audience that we’re at the point where regular Americans (not just those in InfoSec) are starting to see that our security as a nation is linked to cybersecurity. And DHS is changing its stance in five key areas to go along with that new urgency.

  • Systemic risk will be hit head on. We must be more aware of weaknesses and the cascading consequences because of our interconnectivity.
  • “Hyperconnectivity means my risk is now your risk, your risk is now my risk. We have a weakest link problem,” she says. Collective defense is the key to long-term strategy. We must crowdsource to warn of attacks and crowdsource the proper response. “We need your help.”
  • Federal efforts around cybersecurity will increase implementation. DHS will help enable better supply chain security. “We want to help companies move from first to market, to first to market and secure.”
  • Encouraging redundancy in cybersecurity. “In an era of APT, we must focus on advanced persistence resistance. We must be obsessed with redundancy” so that when systems fail in an attack, they fail gracefully. That is, our technology doesn’t crash; instead, it switches to a backup, so any loss of connectivity is very limited. Think how this could apply to attacks on critical infrastructure or America’s financial system.
  • Our digital lives depend on cyber deterrence. “I have a newsflash for America’s adversaries. Complacency is being replaced by consequences.“ She says the days are coming to an end where America is attacked without implications for the other side—although she didn’t give any details on this.

The Secretary says these changes are needed so the benefits from our connectivity do not get outweighed by the downside of that connectivity. And if we don’t make these changes? Well, expect to pay a price.

“The threat picture is getting dimmer, not brighter,” she says. “Cyber is not just a target, it is also a weapon.”

This article was originally published by SecureWorld

Survey shows raise in salary bars of cybersecurity experts

Information Security salary

A recent survey by salary.com, a Massachusetts-based consultancy for compensation data and software, depicted that CIOs will be drawing nearly $250,000 annually, along with CTOs and CISOs. The new salary structure, which has been in effect from March 29, 2018, has augmented the remunerations for job profiles in IT, data management, and software development. Professionals holding job profiles of Information Security Director, Business Intelligence Director are now receiving more than $160,000 while Data Warehousing Director is drawing close to $156,000.

Although these benefits will vary in different regions and industries, this raise also indicates growing demand for these profiles. The new salaries are expected to boost applications in these fields, thus helping bridge the skill gap the industry is currently facing. In January 2018, a report by ESG showed cybersecurity among the biggest areas with skill shortage. More than 50% respondents of the survey had agreed that their company was facing a grave shortage of cybersecurity skills.

The current increments also include data and analysis experts as BI and data privacy matters gain momentum. Although UK is below US in the remunerations list for cybersecurity experts, with GDPR implementation in May 2018 the demand for data privacy officers and cybersecurity executives is expected to intensify in EU region, including Britain.

NHS to spend £150m toward cybersecurity

NHS

The National Healthcare Services (NHS) of United Kingdom is set to spend £150 million ($206 million) to safeguard its cyber infrastructure. Jeremy Hunt, the health secretary, said: “We know cyber attacks are a growing threat, so it is vital our health and care organisations have secure systems which patients trust. We have been building the capability of NHS systems over a number of years, but there is always more to do to future-proof our NHS against this threat. This new technology will ensure the NHS can use the latest and most resilient software available – something the public rightly expect.”

This was after the health care body was recently slammed for ‘alarming’ lack of cybersecurity defenses, amid warnings that Russian hackers were trying to infiltrate the critical infrastructure critical national infrastructure, including power networks. “Despite 22 recommendations created by the Department of Health and Social Care, NHS England and NHS Improvement to help the NHS improve its cyber defences, the PAC noted it was “alarmed” that these measures had not yet been implemented,” suggests a report on The Inquirer.

The announcement traces its root back to the infamous WannaCry cyber attack that had crippled the infrastructure. According to the Department of Health and Social Care, “the package would enhance security intelligence and give individual trusts the ability to detect threats, isolate infected machines and kill malicious processes before they are able to spread.”

Earlier, the UK government had pledged £21 million to boost the cybersecurity of the NHS. “Careful consideration of how to secure your legacy business systems, what, if any, network security appliances are needed, and which lower-cost solutions can be implemented will give management a better idea of what their needs are in terms of a cybersecurity budget,” According to Crowe Horwath, one of the largest public accounting, consulting, and technology firms. “Once these needs are mapped into the organization’s long-term plan, the available capital can be allocated for new development. When the budget for new projects is combined with the budget for ongoing maintenance and monitoring requirements, an organization will be able to determine its annual budget for both people and money.”

Indian state sets up cybersecurity operation center

Penetration Testing, continuous testing, security testing

Last week, Chief Minister of Indian state of Andhra Pradesh, N Chandrababu Naidu unveiled the Cyber Security Operations Center (CSOC) in the capital region of Amaravati. The center is aimed at averting threats looming over the region’s cyber space. “The Center will combat cyber security threats and provide real time intelligence sharing and threat analysis to all state government departments and entities,” Naidu said in a statement. “At the heart of the security operations center (SOC), is a blended security analytics platform that ingests, correlates and analyses massive amounts of data. The state has also roped in Pricewaterhouse Coopers (PwC) as cybersecurity consultants to the Government in helping the state frame and adopt best-in-breed practices and frameworks in this domain.”

Information Technology firm, Tech Mahindra, will operate the SOC. “The state government is already using vast data, drones and implementing real time governance to serve the people of AP. He felt the CSOC would be very useful to face the cyber threats posed to the state and the government,” stated a report in The Hans India, a regional daily.

The State also hosted the Andhra Pradesh Cybersecurity Summit at its Fintech Valley in Vizag which aims at providing a platform for eminent infosec experts to share strategies and solutions to combat the growing cyber threats. A Memorandum of Understanding (MoU) was signed between the Government of Andhra Pradesh and Mastercard to establish best practices.
J A Chowdary, Special Chief Secretary & IT Advisor to the Chief Minister, Andhra Pradesh; Ravi Aurora, Executive Director, Community Relations and Public Policy, Mastercard; and Nara Lokesh, Minister for IT, were part of the summit which convened more than 450 delegates.

“Andhra Pradesh has been a pioneer in implementing digital solutions for delivery of public services and creating a global fintech ecosystem. Therefore, cybersecurity for individuals and businesses is a high priority for the Government of Andhra Pradesh. We believe that the Andhra Pradesh Cybersecurity Summit, in partnership with Mastercard, was an important step towards implementing the best practices in the field of cybersecurity in the state,” said Nara Lokesh, while speaking at the summit.

Andhra Pradesh has been setting an example for other states in the country with their approach toward remediation of threats and ensuring security in the information security space. Apart from conducting regular cybersecurity conferences and setting up operation centers, the state has embarked on novel techniques to address cyber frauds and privacy-related concerns.

“The government is proposing to have AP CODE, which is a secured platform, which will arrest any misuse of data and would like to bring this initiative through an enactment by state legislation. The government has set up new state-of-the-art State Data Centre (SDC), central repository of the state, online delivery of services, citizen information portal, state intranet portal, remote management and service integration, and disaster recovery,” said J A Chowdary, in an earlier interview with CISO MAG. “ePragati is the nodal agency to implement blockchain initiatives across departments in association with blockchain technology companies in AP and agency is taking every step in protecting the interests of common man through securing various digital assets.”

Infosec startup protects $1 billion worth of ICO funding from cyber attacks

French Regulator Fined Google

A cybersecurity startup from Brisbane, Australia, has claimed to have protected $1 billion worth of initial coin offerings (ICOs) funding from cyber attacks. Entersoft, which provides penetration testing, anti-phishing, wallet, operations, and smart contract security firm, achieved the feat without a single hack or lost token value.

The Brisbane-based startup has been on the circuit for just 10 months. “Entersoft has since mid-2017 helped more than 30 companies launch ICOs, including blockchain startup Havven,” suggests a report in Business Insider.

In March this year, Havven raised $39 million in what is seen as Australia’s largest ICO. The firm hired Entersoft to shut down 24 phishing sites and 17 Medium pages where scammers were trying to the ICO.

“We have been able to successfully shut down these scams in all ICOs we have supported,” said Mohan Gandhi, CEO and co-founder of Entersoft. According to Gandhi hackers see ICOs as opportunities to make money. In fact, it is estimated that over $400 million has already been lost through hacks since 2015. “The majority of the hacks happen due to phishing scams through fake URLs and social media accounts, a lack of security around token sale websites or through smart contracts flaws being exposed. We have been able to successfully shut down these scams in all ICOs we have supported.”

While discussing Australia becoming a potential ICO hub, Gandhi said: “With its highly-regarded financial services regulation, and other fintech-friendly policies, Australia should be a natural world destination for ICOs. Other countries have generally taken a neutral or hostile position to ICOs, while Australia has laid out a roadmap for how they can be undertaken. ICO fund-raises can bring significant investment into Australia, as they generally require cybersecurity and legal support, along with the need to construct a white paper and build technology platforms. Despite the recent volatility in digital currencies, there is still huge global interest in ICOs with some many hundreds of these fund-raises expected across the globe over the next six months. This is an industry Australia should be chasing.”

The company also has a range of services and focuses on fintech and banking community. Entersoft was also selected to participate in SuperCharger FinTech 2.0 accelerator program, post which the company opened an office in Hong Kong and began working with around 100 Fintechs from the city and Singapore.

ICS market to grow at CAGR of 8.6% to reach $21.68 billion by 2023

Industrial Cybersecurity

The global industrial cybersecurity (ICS) market is set to grow at a Compound Annual Growth Rate (CAGR) of 8.6 percent from 2017 to 2023, which roughly translates to $13.20 billion in 2017 to $21.68 billion by 2023. The trend was suggested by a market research report titled “Industrial Cybersecurity Market by Type (Network, Application, Endpoint, Wireless, Cloud, Others), Product (Gateways and Networking Devices), Solution and Service, End-User Industry, and Region – Global Forecast to 2023.”

According to the report, few of the major factors driving the tendency were increasing government funding to improve the cybersecurity of the industrial environment, the growing incidents of breaches and rise of connected devices in industrial systems.
The report also examines geographical segments of the industrial cybersecurity market thereby providing a complete understanding of the market and its strategies. According to the report, North America leads the ICS market in terms of size. “The region is one of the fastest-growing markets in terms of technological advancements, manufacturing operations, and infrastructure. It is an early adopter of innovative technologies and is home to a large number of industrial cybersecurity solution providers. This is contributing to the growth of the market in the region,” the report suggests.

The power industry has been consistently holding the largest share in the industrial cybersecurity market due to its nature and its capability to create a larger impact. Added to this, experts feel that with extra attention, ICS may soon jump into the cyber insurance game. Eddie Habibi, founder and CEO of PAS in an interview with Automation World suggest that because most operations technologies are “invisible to security personnel, insurance companies have long faced challenges understanding true risk within a facility and will continue to struggle with writing policies specific to these environments.” He, however, feels that industrial companies that can “gain visibility into all their cyber assets, as well as monitor and mitigate risk, will have better options for insuring the heart of their operations,” he said.

The report is available here: https://www.marketsandmarkets.com/Market-Reports/industrial-cybersecurity-market-37646764.html

Australia and United Kingdom join forces to thwart state-sponsored attacks

Australia and UK

Australia and United Kingdom have pledged to intensify the fight against state-sponsored cyber attacks. The announcement was made by British Prime Minister Theresa and Australian Prime Minister Malcolm Turnbull after both the leaders released an agreement joint declaration by the 53 nations of the Commonwealth on the dangers to civilian and military networks.

“The rules-based international order must be upheld online, just as it is offline,” said their declaration issued after bilateral talks. “Australia and the United Kingdom are concerned by the increased willingness of states and their proxies to pursue their objectives by undertaking malicious cyber activities contrary to international law. We will develop a joint assessment identifying the most nefarious state and non-state actors affecting our shared cyber security,” the leaders said.

The written agreement commits both nations to a new era of practical cooperation. “Our responses will be proportionate to the circumstances of the incident and consistent with our support for the rules-based international order and our obligations under international law,” the statement read.

Among the cited examples were Russia’s use of the NotPetya malware attack on critical infrastructure and North Korea’s use of the WannaCry ransomware. The leaders also noted that “The internet is increasingly being used for malicious purposes by terrorists, child abusers and criminal syndicates,” the declaration said. “We reaffirm, as agreed at the 2017 G20, the rule of law applies equally online as it does offline.”

“Whether it is in chemical weapons, whether it is in the threat of terrorism, cyber security, you see so many challenges to the rule of law,” Turnbull later told reporters. “The maintenance of which is essential to not just our security, but our prosperity.”

Earlier, U,S, and UK also issued an “unprecedented joint alert” with regard to cyber attacks that may have infected millions of computers especially in the US, UK, and Australia that was perpetrated from Russia. “Specifically, these cyber exploits are directed at network infrastructure devices worldwide such as routers, switches, firewalls, and the Network Intrusion Detection System (NIDS).”

The alert issued by US-CERT stated that “DHS, FBI, and NCSC urge readers to act on past alerts and advisories issued by the U.S. and U.K. Governments, allied governments, network device manufacturers, and private-sector security organizations. Elements from these alerts and advisories have been selected and disseminated in a wide variety of security news outlets and social media platforms. The current state of U.S. network devices—coupled with a Russian government campaign to exploit these devices—threatens the safety, security, and economic well-being of the United States.”

This is not the first time Russia was linked to a state sponsored attack. The blame for NotPetya attacks still looms around the corner when Russian hackers initiated the recent attacks on infrastructure. According to Australian Defense Minister Marise Payne “The Australian Cyber Security Centre (…) believes that potentially 400 Australian companies were targeted, but don’t believe there has been any exploitation of significance.”

India and Sweden to set up common cybersecurity taskforce

India and Sweden

India and Sweden are working toward setting up “a common task force on cybersecurity,” where both the countries will join hands to find innovative solutions to combat threats looming the cyberspace. The announcement was made after leaders of both countries, Indian Prime Minister Narendra Modi and Swedish PM Stefan Lofven held bilateral talks at the Swedish capital Stockholm.

Addressing a press interaction Modi said, “One of the main pillars of our bilateral relations is defence and security cooperation. Sweden has been a partner of India in the defence sector for a long time. I am confident that in this sector, especially in the defence production sector, there will be new opportunities for cooperation in future. In security cooperation, especially in cyber security cooperation, we have decided to strengthen our cooperation.”

The leaders also agreed on strengthening their defense and security ties as well as finalizing bilateral agreement on exchange and mutual protection of classified information for cooperation in defense. The decided on the Joint Action Plan, under which India and Sweden, through relevant ministries, agencies and actors will aim to “Enhance Indo-Swedish dialogue on defence cooperation. Proceed with India-Sweden defence seminars in India and Sweden in 2018-19 and explore, together with the ISBLRT, opportunities for investment in Defence Production Corridors in India,” as well as “Encourage industry partners to develop supply chains for small and medium sized enterprises (SME) with major Defence & Aerospace Original Equipment Manufacturers (OEMs),” stated a joint notification.

The statement also stated that both the nations would work on a stronger international partnership to counter terrorism. “They emphasised that the global counter-terrorism legal framework should be regularly updated to address the changing threat of terrorism with strength, and underscored that any measures taken to counter terrorism comply with international law. In this regard both countries called for an early finalisation of the draft Comprehensive Convention on International Terrorism,” it said.

Billions of users’ personal data vulnerable due to third-party code

Data leak

Several apps transmit unencrypted user data over insecure HTTP protocol risking user data exposure, pointed out a research by Kaspersky Lab while analyzing several popular dating apps. The research was presented in the segment titled “Leaking ads – is user data truly secure?” at the ongoing RSA Conference.

According to researchers, the reason for the vulnerability was due to applications using third-party ready-to-go advertising Software Development Kits (SDKs), popular among advertising networks. The researchers pointed out that several of these applications had a billion installations worldwide, “and a serious security flaw means private data can be intercepted, modified and used in further attacks, leaving many users defenseless.”

SDK often go unmonitored as authors focus more on the main elements of the application, relying heaving on the ready-to-go advertising tools. “For instance, advertising SDKs collect user data in order to show relevant ads, thus helping developers monetize their product. The kits send user data to the domains of popular advertising networks for more targeted ad displaying.”

Researchers while digging deeper found that most of the data were sent out unencrypted and over HTTP, making the data highly vulnerable while travelling through servers. Lack of encryption may mean that the data can be deciphered and intercepted by anyone. The research also suggested that these data can be modified and can be infused with malware endangering the user data.

“The scale of what we first thought was just specific cases of careless application design is overwhelming,” said Roman Unuchek, security researcher, Kaspersky Lab. “Millions of applications include third-party SDKs, exposing private data that can be easily intercepted and modified – leading to malware infections, blackmail and other highly effective attack vectors on your devices.”

Personal information, mostly in the form of the user’s name, age and gender, were the most found data. Several kits may also include user’s income, phone numbers and email addresses, the researchers warned. Device information, such as the manufacturer, model, screen resolution, system version and app name and device location, were other data that was transmitted unencrypted.

The researchers advised users to follow preventative measures like checking app permissions and using VPNs.

Northern Territory govt. to set up cybersecurity operation center

Northern Territory Cybersecurity Center

The Northern Territory (NT) in Australia will be setting up a cybersecurity operations center which will serve as a centralized base for cyber analysts, engineers and forensic specialist staff to collaborate and respond to cyber incidents in real-time. NT will spend $1.5 million to establish the office. “The Territory Labor Government is strengthening the NT Government’s cybersecurity capability with a $1.5 million investment over three years as part of Budget 2018. The funding is in response to the escalating cyber threat environment and supporting the new NT Government Cyber Security Governance Framework,” stated a release.

The Office of Digital Government will “advance government’s digital initiatives and address ICT strategy, design and direction at the enterprise level,” budget documents state. It will be under the purview of Department of Corporate and Information Services. As part of the creation of the agency, government’s digital team has been shifted from the Department of the Chief Minister to DCIS.

“$1.5 million will be invested over the next three years and $850,000 ongoing to strengthen cyber security protection,” said Treasurer, Nicole Manison. “Every single Territorian, no matter where they live, deserves to be and feel safe, to have access to high-quality services.”

The government is moving has earmarked $12.4 million on a developing a technology platform to manage its infrastructure assets.  “The Territory Labor Government is investing in cyber protection to ensure sensitive citizen data is protected and government services are not disrupted through cyber-crime. This investment will enhance security controls to government’s ICT network, establish a Cyber Security Operations Centre and improve cyber security awareness across government and the community,” Manison said. “With cyber-crime and attacks an ever present threat to our privacy, security and financial bottom-line, cyber security is now one of the most critical strategic issues for organisations globally. While digital connectivity is vital for government’s business, the escalating threat of cyber intrusion, with the potential to compromise or steal information or disrupt services, presents a significant and increasing business risk.”

The key focus of the agency will be on risk mitigation, as well as making Territorians cybersecurity aware and vigilant. Several sensitizations programs are in the pipeline to address several vulnerable user groups. “While the key focus is risk mitigation, preventing successful cyber-attacks requires a community of cyber-aware, vigilant users. To this end, cyber security awareness programs will be contemporised, digitised and expanded both within government and to broader audiences, including vulnerable user groups such as seniors and Aboriginal Territorians, along with community sectors that may not realise their risks such as youth and local small businesses,” Manison concluded.