Home Blog Page 374

Indian Home Minister urges critical infrastructure to conduct regular cybersecurity audits

75% Of Security Pros Say Remote Work Led to Changes in Financial Services Cyber Programs: Survey

Keeping up with the global trends and to better prepare and address impending cyber threats, Home Minister of India, Rajnath Singh has urged critical infrastructure bodies to conduct regular cybersecurity audits. These infrastructures include power, rail, and nuclear energy sectors. The minister made the statement while addressing the officers and cadets of Central Industrial Security Force (CISF) at 49th raising day of the paramilitary force at its Ghaziabad camp in the National Capital Region of India.

The domains under the purview of CISF includes airports, aerospace, nuclear and electrical power domains among others, where nearly 150,000 personnel are stationed. Singh stressed on the improving the cybersecurity strategy and keeping the infrastructures updated time to time. According to Singh, the biggest cybersecurity concerns are data theft, fraud, and hacking on the country’s critical infrastructure, and highlighted that there have been several attempts by hackers to penetrate the systems and breach the firewall. According to him, the best strategy was to stay prepared and vigilant against the threats of these likes.

With this regard, the Home Ministry also recently commissioned the National Critical Information Infrastructure Protection Centre (NCIIPC) at the federal level. “Cyber crimes have added a fourth dimension to industrial security and the response against them has to be effective,” he said. “I would suggest that you (CISF) should earmark 2018 as the year for planning and strive to be a newer and modern force by 2022 when India celebrates the 75th year of its independence.”

He highlighted that India is leaping towards becoming a $5 trillion economy from the current $2.5 trillion, and cybersecurity preparedness is key to the economy.

On the background, the country witnessed as many as 1,44,496 cyber attacks from 2014 to 2017. The data was tabulated by the Indian Parliament. According to the Indian Computer Emergency Response Team (CERT-In), major cyber incidents include cybersecurity incidents included phishing, scanning/probing, website intrusions and defacements, virus/malicious code and denial of service attacks.

Indian government plans to introduce cybersecurity in school curriculum

U.S. Schools Suffer Over 1,300 Data Breaches Since 2005

A top official from India’s Ministry of Electronics and Information Technology (MeitY) recently announced at an event that the central government is keen to introduce cybersecurity in the school curriculum. Vinod K Chauhan, scientist ‘C’, Cyber Security Group, MeitY, said the planning is in advance stage and the content for the subject has already been created.

“We are already working on a project whereby we have created content for CBSE (Central Board of Secondary Education) schools and we are closely interacting with Ministry of Human Resource Development (MHRD), we have already prepared the content and given it to them,” Chauhan said.

He also added that MeitY is coming up with a policy for public procurement preference to Make in India to promote domestic cybersecurity industry.

“We will come up with a list of cyber security tools which will be procured through government procurement and before notifying those cyber security tools we will go through with all testing and necessary specifications for those tools,” Chauhan said.

In September 2017, MeitY said Indian companies would get preference in government’s cybersecurity procurements including both hardware and software solutions. The notification published on the official website of the ministry stated, “Preference shall be provided by all procuring entities to domestically manufactured/ produced cybersecurity products as per the order.”

The notification defined ‘local supplier’ of domestically manufactured/ produced Cybersecurity Products as company incorporated and registered in India as governed by the applicable Act. The notification also mentioned that resellers, dealers, distributors, and support service agencies of foreign-developed products and services who have limited rights to a product’s intellectual property are exempted from the tentative mandate.

Former governor’s Senate campaign fears hack

Election campaign

Amid fears of cyber attacks in upcoming 2018 midterm elections, Ex-Tennessee Gov. Phil Bredesen’s Senate campaign has notified an apparent hack to the Federal Bureau of Investigation (FBI).

The campaign in a letter to the FBI stated that on February 28, 2018, it received several emails of a planned media buy that requested funds be transferred to an international bank account in Dubai.

According to a copy of the letter obtained by CNN, Bredesen’s campaign’s counsel Robert Cooper Robert Cooper stated that “due to the fact that the imposters knew the media buy was imminent, we are concerned that there has been an unauthorized intrusion into the extended campaign organization.”

The letter suggests that the imposter used identical to the actual media buyer’s and was aware of an upcoming TV campaign and its due dates.  Bredesen also notified people not to open a document that appears to be from him stating that counterfeit emails have the domain “bredesens.com,” instead of “bredesen.com”. “On Wednesday afternoon (March 7) you may have received an email, coming from a spoofed email address, that appeared to come from me, asking you to click a link to view a shared document,” Bredesen wrote. “Unfortunately, this email is part of a cyber intrusion into my extended campaign organization, including an unsuccessful attempt to divert campaign funds to offshore accounts. The FBI has been contacted and is involved.”

The campaign has now hired a cybersecurity firm which revealed that the emails were registered through an Arizona-based registrar.

This is an upsetting trend and may affect the upcoming elections and voter count. According to a survey by Carbon Black, one out of every four Americans would consider not voting in the upcoming elections due to the cybersecurity concerns. It also suggested the American voters are worried that the hackers would steal their personal information from voter rolls.

KPMG partners with Okta to strengthen its identity access management processes

KPMG

KPMG announced its partnership with Okta, an identity management solutions provider for improving their cybersecurity infrastructure. The audit and tax advisory firm will use Okta Identity Cloud to automate their identity and access management processes.

Charlie Jacco, Principal, KPMG Cyber Security Services, said, “Our alliance with Okta is accelerating KPMG’s status as a leading cyber security firm with the ability to help clients protect information as they pursue new digital interactions and enhanced productivity in the cloud. With Okta, we can deliver fast and reliable IAM solutions to help keep data safe, while enhancing the user experience.”

With this alliance, KPMG is looking to augment their identity and access management (IAM) capabilities, thus creating a robust infrastructure for data protection with agile enterprise for clients. The major competencies of the Okta Identity Cloud are single sign-on (SSP) facility, risk-based multifactor authentication, making customer identity access management easy by embedding Okta as the identity layer, automated account creation for employees and using Okta for use case interactions.

Patrick McCue, Senior Vice President of Worldwide Partners, Okta, said he was thrilled to partner with KPMG, as it would expand their reach and empower organizations to secure and manage their extended enterprises, also transforming customers’ experiences. “In today’s ever-evolving security landscape, organizations must protect data across an increasingly complex breadth of technologies, including cloud applications, mobile devices and legacy solutions. The Okta Identity Cloud — including our identity and security products, as well as our 5,500 pre-built integrations to applications and infrastructure providers — enables organizations to easily and securely adopt the technologies they need to fulfill their missions faster. We’re thrilled to partner with KPMG to expand our reach and empower organizations to both secure and manage their extended enterprise, and transform their customers’ experiences,” he commented. Okta recently announced 59% growth in its fourth quarter with a total revenue of $77.8 million.

 

#InfoSecSuperwomen: Christy Wyatt

Christy Wyatt

She is an eager beaver, always on her toes; Christy Wyatt is one of those #InfoSecSuperwomen who have made a place for themselves in the information security world that is still struggling to attract enough talent. Christy, who was recently announced as the finalist in the Security Champion of the Year category in Women in IT Awards, has already made it in the Inc. Magazine’s list of Top 50 Women Entrepreneurs in America. She was declared the CEO of the Year by the Information Security Global Excellence Awards in 2015, ranked among the top 100 women leaders in STEM in 2012, and has been among the “Most Influential Women in Wireless” several years in a row.

The CEO of Dtex Systems is a sought after name in the blue-chip of cybersecurity industry. Her masterstroke with regards to the acquisition of Good Technology by Blackberry is no less than history. Christy who has held leadership positions across both consumer and enterprise at Citigroup, Motorola, Apple, Palm and Sun, opened-up about her gumption in cybersecurity, Artificial Intelligence, and gaps in cybersecurity strategy.

Dtex is into cybersecurity innovation. Please share your views on the kinds of innovations we will get to see in cybersecurity in the near future, including AI?

There has never been a more tumultuous time in our industry.  The lines between hackers, hobbyists, and nation state attackers are continuously blurred with security leaders having to scramble to defend against an ever-evolving slate of attacks. A CISO today has no idea if valuable data is being taken to make a national statement by someone with a vested interest, or purely for the market value. Because of this, one of the more interesting trends we’ve been seeing is the focus on the vulnerable insider or employee – as a potential root cause of any of the three scenarios above.

As we move forward, however, and AI becomes a critical tool for both hacker as well as defender, the “why” will matter increasingly less. The ability of each side to fulfil their mission will rely on visibility and the agility. The CISO needs to focus on lightweight, high-fidelity data collection to be able to identify and respond to new risks in real time – coupled with transparency and rapid learning. Analytics engines running in batch mode to cope with massive amount of heavy, unfiltered data, will not scale to meet the challenge.

Dtex Systems was launched in Australia but it is now headquartered in Silicon Valley. Any reason in particular?

Australia continues to have a vibrant security community – but as we see with many other Australian startups, it became necessary for Dtex to move to Silicon Valley in order to connect with the talent and funding pool needed to grow and scale a business.

We were thrilled this year to be able to re-enter the Australian market, which is one of the more mature and forward-thinking at present.  It remains a high-growth business opportunity and area of focus for Dtex, and we will continue to invest.

How much would you rate Australia’s Cybersecurity infrastructure and workforce, on a scale of one to ten?

Unfortunately, you cannot look at any of these items as static. The only constant in the world of security is change and increasingly, our success both as vendors and defenders will be dependent on our ability to adapt – and how we respond to both the market and risk.  We have found, in working with Australian partners, customers and technologists, that there is a depth in both security understanding and ability.  And some of the most forward looking CISO’s that we have had the honor to work with have been within Australia.

The recent cyber breaches across the world show that there are gaps in the cybersecurity strategy. Where do you think the major faults are? Is the world really working on improving it?

Cyber is a world of change.  If the last decade has taught us nothing else, it is that whatever you fear today is not going to be what you fear tomorrow. The risk landscape is continuously evolving.  If I look at extremely mature industries – like financial services or the public sector, they have become much more aggressive in evaluating and embracing new technologies. Evaluation and procurement cycles that were previously measured in months, in some areas, have been cut in half.

This adaptability and capacity to absorb new technology is what is going to keep the enterprise immune system strong. The inverse is the enterprise’s ability to cycle out old, or underperforming technologies. This is an area where I believe there is more work to do.

What are your views on a collaborative cybersecurity platform for the world?

Ideologically, I am a believer that strength comes from transparency and collaboration. Practically speaking, however, this is much harder.  I think the concept of openly sharing data is entirely achievable – but a centralized, global cyber immune system is much less practical as every country has its own definition of ‘risk.’  We can all agree on the identity of an individual – but what the US deems to be a risk, may not be consistent with the view in China. I do believe we should invest in global information-sharing capabilities, which can still go a long way to providing a platform for creating compatible cyber systems.

Former ASIO boss David Irvine recently sent out a warning on Australia’s ‘relatively weak, uncoordinated’ cybersecurity infrastructure. How much do you agree with that? 

I think it’s important to recognize that David Irvine ran ASIO and ASIS up until 2014 – and since that time, the Australian cybersecurity market has matured significantly. However, I would tend to agree with his suggestion that a ‘single Commonwealth-led cooperative agency’ could help to break down silos and present a more coordinated approach to combating cybercrime.

It’s also important to note that the Australian Government has recently taken steps towards a more centralized approach by consolidating its cyber teams, including those of the DTA (Digital Transformation Agency) and the ASD (Australian Signals Directorate). This demonstrates a major shift towards the consolidated approach recommended by David.

 

World Economic Forum creates Fintech cybersecurity consortium

World Economic Forum

On March 7, 2018, the World Economic Forum created an industry consortium to improve cybersecurity of financial technology companies. Created to architect a framework to gauge the security levels of fintech organizations and data aggregators, the consortium brings together top companies such Citigroup Inc (C.N), the Depository Trust & Clearing Corporation, Kabbage, Zurich Insurance Group (ZURN.S), and Hewlett Packard Enterprise (HPE.N), according to Reuters. The consortium will work with the organization’s new Geneva-based Global Centre of Cybersecurity.

Fintech is a perfect foil for the consumers, businesses and financial institutions who in today’s connected, on-demand world want to transact in a convenient, timely, secured, and efficient manner. Traditional banks have realized that fintech is the future; they are either running for cover or trying to stay relevant by collaborating with the upcoming players in the sector.

“Many partnerships are forming between financial technology companies and incumbent institutions,” said Matthew Blake, head of the Financial and Monetary System Initiative at the WEF in an interview. “Through those linkages there is a potential introduction of risk.”

A recent WEF report highlighted the need for better cybersecurity assessment mechanisms as technology innovations such as robotics and biometrics was expanding the amount of customer data at risk.

“While we are excited by the innovation of fintech, it also creates risks that I think need to be identified and worked on to establish standards,” said Michael Bodson, president and CEO of DTCC.

#InfosecSuperwomen: Kelly Isikoff

Kelly Isikoff

An industry veteran with more than two decades of experience, Kelly Isikoff joined RenaissanceRe in 2016 with global responsibility for directing strategy, operations, and budget for the protection of information assets.

Before joining RenaissanceRe, Isikoff was an Executive Director for JP Morgan Asset Management, where she was responsible for setting security strategy and policies as well as managing operational security departments. Prior to her time with JP Morgan, she was a Senior Vice President for Citigroup and managed infrastructure, data management and security across departments. Previously, she has also worked at Warner Music Group, where she led security and new media initiatives to identify innovative revenue channels within technology.

In an exclusive interview with CISO MAG, she discusses cybersecurity practices in the insurance sector, women representation in the cyber world, and much more.

Please tell us about your role and responsibilities in RenaissanceRe.

I am the head of the information security for the global organization. I also manage all of the strategies, programs that will help us maintain our compounds across most of the regions. I also manage the additional groups that feed into security that have a role to support overall defenses. So that being said, a smaller organization unlike the larger organizations I worked with in the past were are using different types of managing security service providers for different capabilities to achieve the same level of security. So my role is to transform the organization and manage a lot of the overall security program and help it to maintain compliance and achieve compliance with pretty big regulations that are coming up and hitting a lot of other financial firms and worldwide global firms.

It looks like a lot of the states within the U.S. have started to fall in line with the same cyber regulations that we have in New York. It seems like every country around the world is starting to uplift their cyber regulations, so making sure that we get things right and follow a standard process and framework is the key to making sure that we don’t have to continue to go through our compliance checklist with each one of these different countries, states, and jurisdictions.

Cyber attacks in the insurance sector are growing exponentially, as companies are migrating toward digital channels in an effort to create tighter customer relationships.  What are the things RenaissanceRe is trying to keep the hackers away?

I mean there’s not one practice that we follow. We have a lot of partners that we work with and a lot of vendors that we manage and that (Third party security management) is a big issue for a lot of companies, not just a company of our size. There are a lot of new companies that are entering the space and provide you assessment services. Unfortunately, some of them are not robust than others.

So, third party security is a big issue and we are receiving more and more requests from clients for much more exhaustive security reviews of our control and a lot of my time is dedicated to calls with our investor group, different types of business clients to go over our security program with them and then go over their security program with us. So, there’s a lot of vetting of partner security that’s happening across the industry.

As you said, you are actually working with a lot of third parties and partners. What do you do to keep the data transfer absolutely secure?

Well we follow different frame works. Our strategy focuses on cybersecurity framework which is really flexible across the industries and really simple to follow, and we also follow top 20 critical security controls which were developed from a lot of industry practice within the community. So, that’s our strategy and that’s how we set our programs for the year.

How important is cybersecurity education or training for employees in keeping cyber threats at bay?

Security awareness training is very important to us. We have continuous programs as well as digital annual trainings and certifications. Also, there are company meetings on key security risks to the organization. Security is everyone’s responsibility, not just one department’s. As far as protecting ourselves against a cyber threat, we have a lot of controls on data access on an add need-to-know basis. We really have a strong program around building out our access control of critical data in critical systems.

What is your take on cyber insurance?

We’re really seeing an evolution of cyber as a specific product to cyber as a peril which can influence multiple insurance products. Most insurance products today focus on credit marketing and notification cost, and these costs are often required by a regulation. So we see a potential growth for risk managers as they asses a cyber risk for their business and starting to work more with our insurers and re-ensure a way to access monitor and mitigate risks. This could include a broader cover for system failure, and interruptions for example.

Do you think cyber insurance is keeping pace with cyber-exposure?

Definitely, I know that a lot of large finance institutions are increasing their coverage through larger cyber offerings and a lot of other multiple insurance products are starting to develop cyber policies within it. So, we’re saying more aesthetic cyber policies into multiple insurance clients.

The representation of women in cybersecurity has remained stagnant at 11 percent for the past four years, according to a report. This is despite growing awareness on cybersecurity, and expanding career options. Most of times, the reasons cited is the lack of women role model and the impression the industry carries. What can be done to break the gender stereotype so that women, even in their teens, are inclined to join the cybersecurity space?

Well, you’re right! There’s definitely a skill gap and I do feel like a minority in my profession. I think some of the things we can do is promote cybersecurity across universities to encourage young women because it is really dynamic and interesting field that’s constantly changing. It’s not something for programmers or people who like technology. It is much more diverse than that. You need to have an investigative type of mindset, you need to look at a lot of different ways that your systems, your information, your business can be compromised and have the ability to work with business to understand your risk, so you can protect against them. It’s really important for me to mentor young women who are interested and moving into security.

According to you, is there anything that the CISOs are doing wrong at a time when the threats are evolving with each passing day?

What we really need to learn from recent attacks is that CISOs need to understand the full scope of security. It’s not just infrastructure parameter anymore. It’s also about application, user behaviour, and other things. They need to know the overall threats that are targetting your organization. You need to follow the cybersecurity framework and employing it for your environment and understanding your risk level. For say, if you’re managing a company that has a lot of Web exposure, you really have to up your application security program. Overall, understanding the risk level of your organization and speaking closely with the business leaders to comprehend the key risks and how do you mitigate those risks and build a depth of control around those risks. That’s what I would recommend the CISOs or new CISOs entering into that space because that’s where I’ve seen a lot of CISOs who failed.

What advice would you give to a budding information security professional?

There are so many different areas within the security to grow into. So, getting a broader in-depth knowledge of various kinds of security domains and understanding the different domains and skills you’d be doing in each area. Basically, understanding what might interest you! That’s what I would recommend to anyone who’s getting into the security because there are so many different specialties within security. It wasn’t like that when I got into security. I worked between infrastructure and application groups, managing security process domain. There weren’t many specializations then, whereas now there are so many specializations and with that there are many opportunities to learn and develop unique skills that make you even more valuable in the marketplace.

Japan’s FSA disciplines seven cryptocurrency exchanges over regulatory flaws

Financial Services Agency

After losing $530 million in a recent cyber attack, the Japanese cryptocurrency exchange Coincheck, once again was in news for being served another notice by the Financial Services Agency. This is the second time they have been issued a warning regarding lapse in proper internal control systems. Six other cryptocurrency exchanges were also reprimanded and ordered to improve their risk management practices, of which Bit Station and FSHO were barred from operating for a month.

Interestingly, all these three cryptocurrency exchanges along with two others which have been taken to task are not unregistered. Minister for Internal Affairs and Communications told a news agency, “It’s problematic that these 16 unregistered exchanges have been able to continue trading. In the first place, should they have been allowed to operate while their applications for registrations are still incomplete?”

After the cyber heist in January 2018, Coincheck had been instructed by FSA to improve its operations and to submit an incident report by February 13. The cryptocurrency exchange which is to start compensating its customers from next week for the loss during the January cyber attack, issued a statement saying, “We will carry out a far-reaching review of our internal control and management systems to ensure proper and reliable business operations from the viewpoint of customer protection.”

The remonstration has led to a dip of more than 5% in the rates of bitcoin, already in trouble since the month of December 2017. The FSA is actively auditing cryptocurrencies for security flaws and implementation of quality security practices.

 

German government computer networks attacked

German Parliament

According to dpa news agency, German government’s computer networks were attacked by APT28, a Russia-backed hacker group. The isolated attack which was noticed in December targeted Germany’s foreign and defense ministries with an intention to steal data.

A spokesman for the German Interior Ministry said the situation has been brought under control and appropriate measures are taken to investigate the incident and protect data. “The attack was isolated and brought under control within the federal administration,” the spokesman said. He added that authorities are addressing the incident “with high priority and significant resources”. However, he did not comment on whether APT28 was involved in the attack.

This is not the first time APT28 has been associated with a cyber attack on German government. The infamous group was accused of carrying an attack on the German Parliament in 2015. It has also carried out notorious attacks on a number of entities in the US, Eastern Europe, and other parts of the world.

Reuters reports that the German parliamentary committee that oversees the intelligence agencies, and the digital committee will discuss the attack on Thursday. It has also been reported that authorities had been aware of the attack for some time.

Credit scores and data breaches don’t bother US adults: Research

Credit Score

Equifax breach has been dubbed as one of the biggest data breaches of 2017 which compromised sensitive information for 143 million American consumers. With several class-action lawsuits pressed against the company, the credit reporting firm has still not entirely recovered from the incident. The incident highlighted the vulnerability of companies belonging to the legion, but what was even more alarming was the fact that more than half of the U.S adults haven’t checked their credit report and credit score since the incident.

A survey of 1,164 U.S. adults commissioned by creditcards.com stated that only 32 percent had checked their credit scores and reports while but 50 percent had not. But that’s not all, the survey highlighted that several young adults were clueless about their credit, where nearly 27 percent of respondents between the age group of 18 and 37 stated that they never checked their credit reports. Even here, the most unaware ones were under 30 years of age. 27 percent of the respondents were also unaware of the breach. While 51 percent of the adults who came to know of the incident checked their credit score and reports, 29 percent of the respondents with the same level of knowledge of the incident chose to care a hoot of their credit reports. It may seem ironical but the survey showed that millennials were most protective of their cellphones than personal data due to reasons like disconnecting from social media.

According to Identity theft expert Rob Douglas, on the trend of people fearing phones suggested, “They may be recognizing that we keep everything on our phones – the apps we use, our contact lists, calendars and passcodes,” Douglas said. “Our lives are in our phones.”

The report called for more data sensitization for adults. It also how financial literacy sent to the back of the classroom due to recent developments in public education policy. “This is the group that came of age during the advent of No Child Left Behind and Common Core,” said Pamela Whalley, director of the Center for Economic & Financial Education at Western Washington University. “Schools have increasingly focused on math, language and arts, which are vital skills, but it’s come at the expense of things like civics, economics and personal finance.”