Home Blog Page 373

Online travel company Orbitz loses customer data to hackers

Orbitz

Travel metasearch engine and fare aggregator website Orbitz became the victim of a grim cyber heist on Tuesday, March 21, 2018. Orbitz, a subsidiary of Expedia Inc., fears that hackers may have accessed crucial payment cards data of nearly 880,000 customers. According to Orbitz, their investigation shows that their old website was hacked some time during the beginning of the year 2016 and the end of the year 2017, adding that the new website of the company wasn’t affected.

The hackers might have been able to pick up crucial customer information which include names, phone numbers, email IDs and billing addresses, said the online travel services provider. “To date, we do not have direct evidence that this personal information was actually taken from the platform and there has been no evidence of access to other types of personal information, including passport and travel itinerary information,” informed Orbitz. The company found out about the breach in the beginning of March 2018, following which the shares of Expedia fell to 1.9 percent.

Orbitz is offering a year of free credit monitoring and identity protection service to those affected, which include both consumers and business partners.

Chinese hackers targeting WhatsApp, Indian Army warns users

WhatsApp and Indian governmentWhatsapp Hack

The Indian Army has issued a warning to users of social messenger application, WhatsApp, alleging that Chinese hackers are targeting them to extract personal data. The Army took to the microblogging site, Twitter to urge users to use WhatsApp with caution. Indian Army’s official handle, the Additional Directorate General of Public Interface (ADGPI) also posted a video that said, “Stay cautious, stay alert, stay safe! The Chinese were penetrating the digital world.”

The video urged users to save contacts by name and to constantly keep a vigil on all WhatsApp groups and numbers. “Chinese are using many platforms to penetrate your digital world. WhatsApp groups are a new way of hacking into your system. Chinese numbers barge into your groups and start extracting all the data,” it advises. “If you change your mobile number, inform the group admin; if you change your SIM card, destroy it completely,”

A few months ago, the army had ordered its personnel stationed in borders to uninstall several applications and format their phones to safeguard its data from Chinese hackers. According to the notifications issued earlier, the army had suspected that Chinese-developed applications were scripted with malware which could potentially endanger the national security of India. Smartphones manufactured by Chinese firm Xioami were under the radar of the Indian Army and the Indian Air Force over security hazards. “As per reliable inputs, a number of Android/iOS apps developed by Chinese developers or having Chinese links are reportedly either spyware or other malicious ware. Use of these apps by our force personnel can be detrimental to data security having implications on the force and national security,” the advisory read.

According to an Indian Directive, “Any device sold in the country should be compliant with global security standards. If companies fail to comply, further action will be taken.”

Michigan’s new legislation safeguards public release of cybersecurity information

Michigan

Governor of Michigan Rick Snyder signed legislation on March 19, 2018 exempting open-records disclosure of cybersecurity-related information. “Michigan is a leader in addressing cybersecurity and I’m proud that this legislation takes an additional step toward addressing the safety and security of information systems and cybersecurity plans,” Snyder said. This new law received a 104-4 vote, with the supporters saying that it might help in shedding the reluctance for companies in the event of a security breach. The legislation includes cybersecurity assessments, plans, past and ongoing breaches. It also safeguards situations that could trigger future security breach.

Republican Brandt Iden initiated the venture to amend the Freedom of Information Act to prevent sharing of selected electronic data related to cybersecurity. Iden had commented earlier, “We’ve been working to ensure that Michigan is number one when it comes to cybersecurity. That other states, when they look at how to do cybersecurity, they look at Michigan.”

The legislation will prevent circulation of sensitive cybersecurity information with state police and other public bodies. The Michigan Press Association has opposed this exception stating that it creates ground for excessive exemption-taking. Lisa McGraw, the public affairs manager for Michigan Press Association remarked, “We understand the need for cybersecurity, but we are always concerned when you exempt things from FOIA. FOIA should be across the board and uniform as possible.” Although Iden maintained that agencies will disclose all information of public interest and the legislation will only ensure that sensitive information is not compromised.

Scotland Digital Office appoints Andy Grayland as CISO

Scotland

To support local authorities against the risk of cyber attacks, Scottish Digital Office for Local Government has appointed Andy Grayland as the chief information security officer (CISO) to the department.

Grayland will be involved in providing leadership to help local authorities achieve goals of the Cyber Resilience Strategy for Scotland, the National Cyber Security Strategy as well as the recently announced Action Plan on Cyber Resilience which involves “developing the cybersecurity workforce, raising public awareness, and increasing cyber resilience in the workplace,”. Other stakeholders in the action plan include education and skills development sectors of Scotland.

Grayland will also assist CEOs and several council management teams so that organizations are prepared to avert cyber attacks at all levels, also while helping IT managers, cybersecurity officers and data protection officers to review cybersecurity regulations and compliance to develop collaborative actions plans.

‘In the current climate of evermore sophisticated cyber-attacks that private and public sector experience day-to-day, Andy and his experience is a great asset for the Digital Partnership to accelerate and enhance our cyber credentials,’ Martyn Wallace, chief digital officer for Scotland, said in a statement.

Garyland envisages Scotland to become a safe place to conduct digital business and aims to achieve this by leading the public sector by example. “Prior to this role, Andy worked for the Ministry of Defence promoting collaboration on cyber programs across Central Government and between International Partners. This period in his career taught him that we are stronger standing together shoulder-to-shoulder against common threats than working as individuals solving the same problems. The proudest moment in his career so far has been the delivery HMS DEFENDER from build in Scotstoun, Glasgow, as the engineer responsible for the safety and security of the communications and information systems on board,” reads his on the Scottish Digital Office page.

Palo Alto Networks acquires Cloud Security Platform Evident.io

Palo Alto

Palo Alto Networks announced the takeover of cloud security platform, Evident.io. The deal worth $300 million will be completed during Palo Alto Networks’ third fiscal quarter. Founded in 2013, Evident.io is a privately held firm backed by Google Venture, Bain Capital Ventures, True Ventures, and Venrock. Their Evident Security Platform (EVP) scans the customers’ public cloud footprint, thus, identifying and analyzing risks in the system ad aiding security staff with remediation guidance.

Tim Prendergast, co-founder and CEO of Evident.io, commented on the acquisition, “We founded Evident.io to secure our customers’ public cloud infrastructure and services without slowing down innovation. The combined capabilities of Evident.io and Palo Alto Networks will provide customers the confidence they need to run better, faster, and more securely in the cloud.”

A new cloud security study conducted by Palo Alto Networks highlighted that around 70% of cybersecurity experts, especially those working in large organizations across Europe and the Middle East, agree that hastily shifting to the cloud environment also means ignoring some accounts of security risks. The next gen security company announced in its press release that in order to ensure complete and secured move into public cloud, security, DevOps and compliance teams need to work on an automated and frictionless approach.

“We believe enterprises will become even more cloud-centric in the future and require prevention methods that have been designed for the cloud. With Evident as part of our platform, Palo Alto Networks will be the only vendor that can deliver a holistic cloud offering to address the critical security needs of today’s enterprise customers as they journey to the cloud,” said Mark McLaughlin, chairman and CEO of Palo Alto Networks. The company’s fiscal second quarter revenue for 2018 was recorded at $542.4 million.

 

Fintech: Rooted in the Past, Borrowed from the Future

Fintech

New innovations in financial technology tend to be discussed as if the financial industry is only now being impacted by technological innovation. The fact is that banks and technology have always complemented each other.

Technology making financial innovation possible can perhaps best be seen by looking at the 1950s when Diner’s Club introduced the first credit cards. By the 1960s, Chemical Bank of the United States installed ATMs aimed at replacing branches and tellers which dispensed cash when users inserted a specially coded card. The 1970s brought electronic stocks and by the 1980s, banks started using sophisticated computers to monitor financial data. The nineties and naughts brought internet and ecommerce to the fore and the Wall Street replaced telephone stock brokering with online stock brokerage websites.

Cut to the present and fintech, a new abbreviation simply meaning financial technology, found its way into the Oxford Dictionary as a term originated in the early 21st century. Fintech aims to leverage modern technology to craft innovative financial services that bring consumers and businesses closer.

The fintech industry is one of the fastest growing segments to emerge out of cyber space – the global investment in Fintech sector skyrocketed from $928 million in 2008 to $12.7 billion by 2016.

Fintech innovations like mobile wallets, payment apps, roboadvisors, etc all are largely enhancements to existing banking services, but with the direction the industry is going, the future could see fintech replacing banking services or even competing with banks outright. This is the disruptive nature of startup technologies at work.

Haskell Garfinkel and Dean Nicolacakis, PwC’s US Fintech Practice co-leads, have this to say about the emerging industry: “We think about all the players in a larger fintech ecosystem, which we refer to as the As, Bs, Cs, and Ds. As are large, well-established financial institutions; Bs are big tech companies; Cs are companies that provide infrastructure or technology that facilitates financial service transactions; Ds are disruptors, fast-moving companies, often startups, focused on a particular innovative technology or process.”

The evangelists of fintech have been predicting the demise of banks in the face of fintech’s explosive penetration. However, a bankless reality may be further away than some think, according to Garkinkel: “Fintech isn’t static. When we talk about the As, Bs, Cs, and Ds, we think of them as sectors in motion, all moving toward each other over time. For example, financial institutions are becoming more technology focused. At the same time, big tech companies are offering peer-to-peer payment solutions over social networks and email. Meanwhile, disruptors are providing financial services that, until recently, you could get only from banks or financial advisors,” adds Haskell Garfinkel.

However, given the complexity of financial technology, one of the inevitable challenges is with regard to cybersecurity. It is highly likely that there will be vulnerabilities, and those will be exploited.

Key Challenges

The first step towards securing any industry must begin with a fundamental acknowledgment of the importance of security. Instead of thinking of how to aggressively get to the market quickly (a scenario prevalent among startups), companies must first focus of securing their product. However, securing architecture cannot be a one-step process. There should be continuous testing and dedicated quality assurance teams to create less breakable and secure codes.

Blockchain is often seen as an added advantage and a natural fit for fintech. However, there has not been a mass exodus of the general population migrating from physical to digital currency. But, if such an exodus does occur, blockchain and cryptocurrency could lead to the demise of banks and other middlemen that fail to adapt to the new reality. Of course, even blockchain is not hack proof. For example, digital currencies like bitcoin are vulnerable to hackers stealing end-users’ wallets and bitcoin exchange private keys, mining DDoS bitcoins, or even exploiting code flaws. Added to this, bitcoin is famous among the hacker community and is the currency of ransomware. It is often impossible to trace or recover data and financial losses from attacks that have been triggered from blockchain-based systems.

Another key challenge is protecting the identity of end users, which often is the most complex part of the equation. Once a hacker reaches a user’s bitcoin wallet, the outcome can be as catastrophic as bankruptcy.

Compliance and Regulations

The security risks of fintech are now being recognized by organizations with special attention toward application vulnerabilities. Several standardization and regulatory measures have also been mandated while several others are in the pipeline. The existing measures include Basel II, Federal Financial Institutions Examination Council (FFIEC) Uniform Rating System for Information Technology (URSIT), Gramm-Leach-Bliley Act, Fair Credit Reporting Act (FCRA), Federal Trade Commission Act (FTC Act), among several others.

Basel II focused on, “The risk of loss resulting from inadequate or failed internal processes, people and systems or from external events.”

Basel II helps organizations evaluate and mitigate operational risk losses. FFIEC established URSIT as a rating system. “The primary purpose of this rating system is to evaluate the examined institution’s overall risk exposure and risk management performance and determine the degree of supervisory attention necessary to ensure that weaknesses are addressed and risks are properly managed,” states FFIECon its website.

FS-ISAC in its 2015 report pointed out the implementation of open source management policy to boost Fintech cybersecurity. It also recommended creation of open source Bill of Materials (BOM) to identify open source components.

The existing regulations also include open source vulnerability scanning and review, incorporating risk assessments into supply chains, audits on internal controls, cyber risk governance, cyber risk management, internal and external dependency management, examination of IT assets, among several other measures standard to other technology in the industry.

Upcoming regulations like the European Union (EU) General Data Protection Regulation (GDPR) mandates all companies must protect personal data (including financial information) of citizens. The governing bodies will verify the protection measures adopted.

At present, fintech is one of the most regulated industries in the world. But the key challenge is the presence of too many governing bodies but no universal standards – a singular regulatory policy or framework for the industry is lacking.

Fortunately, fintech is on the right track, with enough attention on ensuring secured architecture. Cybersecurity is being incorporated into new layers in mergers and acquisition processes even in the fintech industry. Standardizations are also playing a crucial role. The National Economic Council in a statement of principals have provided “a framework for stakeholders in the Fintech ecosystem to assess their role in contributing to the policy objectives. These principles represent practical and actionable propositions to help the fintech ecosystem contribute to a well-functioning and inclusive financial system and to the economy as a whole.”

Fintech is revolutionizing the financial services industry and is contributing to its growth. All it needs is optimum utilization with enough attention to security.

Sources:

https://www.cbinsights.com/research/report/fintech-trends-2016/

https://www.bis.org/publ/bcbsca07.pdf

https://ithandbook.ffiec.gov/it-booklets/supervision-of-technology-service-providers-(tsp)/risk-based-supervision/uniform-rating-system-for-information-technology.aspx

https://blog.blackducksoftware.com/effective-open-source-security-management/

Global Fintech Investment Boom Is Benefitting London Most, Says Accenture Study

 

 

New DHS bill has some cybersecurity trimmings

Homeland Security

A number of changes were debated upon the Homeland Security Act of 2002 earlier this month. The new DHS bill includes a headquarter for DHS and advanced strategies for the department. It authorizes new responsibilities for chief privacy officer and chief information officer. The department, which was enacted more than ten years ago, will soon see some new changes including like remodeling the National Protection and Programs Directorate as the Cybersecurity and Infrastructure Security Agency (CISA), which will be headed by the director of national cybersecurity and infrastructure security.

Senator Claire McCaskill commented, “For those of us that serve on the Armed Services committee … our Department of Defense is so much better because we have gotten into the discipline of authorizing the Department of Defense every single year. So we look at all their programs, we have hearings on posture. We are really on top of all the various programs — not that things don’t get by, because they do, and we constantly try to find them — but that discipline of authorizing every year is something I would like to see this committee get to.”

The suggested modifications include reorganizing DHS’ National Protection and Programs Directorate, securing personally identifiable information, along with supporting cybersecurity research. The new legislation would also allow Customs and Border Protection to remove personally identifiable information like social security numbers, passport numbers and residential addresses from manifests before demonstrating in public.

The House Homeland Security committee passed the Cyber Incident Response Teams Act, empowering DHS’ National Cybersecurity and Communications Integration Center to form cyber hunt and incident response teams. The act allows this department to fill the Cyber Incident Response Teams with cybersecurity experts from the government and private sector.

The amendments will not be easy to implement considering the multiple committees that share DHS’ scope. Senator McCaskill has stressed on creating leadership in a joint way to help in getting proper attention for the department.

 

EC-Council gears up for a big announcement

EC-Council major announcement

The world today faces the unforgiving, relentless surge of cyber scourge globally, impacting hundreds and thousands of businesses and governments. It is, therefore, ironical that many trainers remain unprepared to undertake the behemoth transformation required to offer critical cybersecurity training to the millions who are going to be at risk.

While some may argue that presently we have the highest number of cybersecurity trainers and consultants, a look around at the recent cyber attacks of varying intensity is enough evidence that there are many parameters we as a collective global society lack at.

More often than not, such issues highlight the importance of contemporary cybersecurity capacity building – for individuals, organisations and governments. In this context, while classroom training sessions in leading universities across the globe can be found, there are several cybersecurity experts around the world who would not have the requisite time to attend such courses owing to the pre-existing work schedules. Online courses, therefore, would come to the rescue as the most seemingly obvious option.

But will taking online exams really solve the alarmingly growing demand of cybersecurity professionals around the world? According to CSO Online, there is 0% unemployment in cybersecurity with a million jobs that go unfulfilled each year. With this crisis expected to continue until 2021, can we leave the fate of a potentially cybersecure world in the hands of professionals certified by online courses?

A 2008 study done by professors of the University of Troy to ‘enhance the quality of courses in the online environment’, led to the recommendation of many pedagogical strategies based on their findings and an extensive literature review. One of the concerns that they found from online examinations was ‘ensuring the student‟s identity (is student taking the test him/herself or getting outside help)’. The research gave credence to the assumption that online course rigor can be enhanced by requiring proctored exams.

Wellman discovered in his research on 120 college students in a Doctor of Pharmacy program at Ferris State University that on-line delivery paired with proctored testing was more effective in promoting learning than un-proctored testing as measured by “improvement from medical terminology pre-test to post-test”.

Simply put, the credibility of one’s academic knowledge is often attributed to their alma mater. An alumnus of a ranking institute is expected to have been forged in the fire of the highest standards and put through invigilated exams that resulted in them graduating from that fine school. Not much of our learning would matter, if we publicly disclosed that our exams were non-proctored, would it? We would end up losing all the credibility of our degrees.

In the domain of cybersecurity, where the world beckons cybersecurity professionals with open arms and fat pay checks, shouldn’t their credibility also be measured against a proctored exam, even if it happens online?

EC-Council, the world’s leading cybersecurity training company that is committed to bettering the global landscape at protecting its highly protected turf, is making a huge announcement on the 14th of March. Jay Bavisi, President and CEO, EC-Council Group, says: “Today, you can find an EC-Council certified professional in almost every Fortune 1000 company. But we still wonder, what is it that we can do more at EC-Council, to help an ever-digitizing world? We’ll be unveiling something big that we truly, deeply care about. We believe it’ll meet the demands of the industry. Join us on the 14th of March to learn more about these innovations and what we can expect in the next 10 years to help professionals, organisations and government institutions meet the scourge of insecurity.”
Event Starts at 14th of March 7:00 AM PST. Click here to register.

Cybersecurity skill demand in India triples in last one year

cybersecurity skill gap

Cybersecurity industry is marred by a perennial skill gap. While there are several efforts by organizations to close this skill gap, the numbers and data show otherwise.  In fact, surveys have projected that the gap between cybersecurity professionals and unfilled positions will expand to 1.8 million globally by 2022. That again is an impending concern. At the macros, there are other key concerns.

According to a survey by outbound hiring firm, Belong, the demand for cybersecurity professionals in India has gone up three times in past 12 months creating an eminent skill gap.  “As companies seek to bolster their defence against data security breaches, the demand for cybersecurity experts in India has outstripped supply of these professionals by three times over the past 12 months,” the company stated in a release. The research was based on data posted by companies on hiring requirement for a period of 12 months.

With the penetration of internet and knowledge of cybersecurity, the demand is only going to increase, suggested Rishabh Kaul, co-founder of Belong. “With the demand escalating, there may also be rise a in expats hiring, especially for the mid-level or senior level roles where experience is needed. There is also a possibility of companies hiring senior level professional, who will be based from some other country, to lead a team here in the country.”

The research also pointed that currently in India alone there are nearly 15,000 open jobs related to cybersecurity in technology and non-technology domains. A major chunk of the demand came from banking, financial services and insurance (BFSI) sectors. “Further within the technology sector, the demand is spread between ITeS (25 percent), software product (non-security) or shared services or captives (24 percent) and security companies (9 percent),” suggested a report on PTI. According to the report, “most companies are struggling by either giving more responsibilities to their mid-senior level executives or depending on third-party players.”

An earlier survey by EC-Council has concluded that “The skill gap in the cybersecurity industry spans all levels, from CISOs to security analysts. It appears that the shortage of skilled professionals is not a problem that will be solved in the conceivable future. Most CISOs have several job openings yet to be filled and CISOs and the others involved in the recruiting process are looking for prospects with relevant certifications and experience. A major hurdle in the recruitment process is finding the right fit both with culture, personality, and experience that matches the job.”

Another key finding of the same survey was that “most infosec professionals were holding onto their seats for years, with several CCISOs serving the same position for almost a decade.”

McAfee acquires VPN provider TunnelBear for safe connect

McAfee

Toronto-based TunnelBear was recently acquired by McAfee for an undisclosed amount. The Virtual Private Network service provider will be helping McAfee boost Wi-Fi security progressions for its product Safe Connect.

Christopher Young, chief executive officer, McAfee said, “This investment is strategic for McAfee’s consumer business as it further showcases our commitment to help keep our customers’ online data and browsing private and more secure at a time when the threat landscape is growing in volume, speed and complexity.” This is McAfee’s second acquisition since it pulled out of Intel in 2016. The company acquired Skyhigh Networks for cloud services in November 2017.

TunnelBear announced the takeover in a blog on its official website, saying that after reaching the benchmark of 22 million users on their own, they know that they can reach out to a wider audience with McAfee. They also mentioned that both the companies will continue to carry out and publish annual security audits, a practice started by TunnelBear in 2017.

Ryan Dochuk, co-founder, TunnelBear commented, “McAfee’s acquisition of TunnelBear is an exciting opportunity for our company. TunnelBear will continue to develop the products our customers have come to love, now with the backing and resources of a leading cybersecurity company. McAfee shares our passion to help everyone browse a more secure and private internet. The acquisition provides us with the resources to develop our service, expand into new regions, and continue leadership of privacy and security practices in the VPN industry.” TunnelBear will be operating as an independent team within McAfee and continue to work from their Canada office, also creating their own products.