Home Blog Page 375

Cybersecurity startup Morphisec finds new investor in Orange Digital Ventures

Startup funding

In its Series B round of funding, Morphisec, an Israel-based cybersecurity startup has raised $12 million. The new investor in the firm is Orange Digital Ventures, the strategic Corporate Venture Fund of the Orange Group. The startup specializing in moving target defense expert (MTD) has GE, Jerusalen Venture Partners, and Deutsche Telekom Capital Partners as its existing investors.

Yann Kandelman, head of Investment at Orange Digital Ventures, commented, “Morphisec is successfully building a rapidly growing customer portfolio based on its truly unique prevention-based approach. We are thrilled to support the Morphisec team in their acceleration and global reach to fundamentally change cyber protection.”

Founded in 2014, Morphisec patented MTD that creates a seamless memory-defense layer merging with the existing security infrastructure to form a prevention stack. Ronen Yehoshua, CEO and president of Morphisec, mentioned, “We built Morphisec to become an essential part of every company’s security and IT operation, and to defeat attacks that other endpoint technology cannot. Our growth has been exponential and this funding will help Morphisec continue on that trajectory. We continue to grow our customer list, our partner ecosystem and our headcount so we can deliver the most groundbreaking technology advancements in a powerful and simple product that prevents advanced threats and exploits like no other.”

The company showed more than 1000% growth in 2017 through its Endpoint Threat Prevention product. It also raised $7 million in its Series A funding in 2015.

Australian startup Penten awarded defense contract

partnership

Canberra-based company Penten has won the Australian army’s contract for providing secure wireless devices to be used for communicating classified information in the headquarters of the Australian Defence Force (ADF). The initial trials for the device will be conducted on ADF’s coalition partners. The AU$1.3 million ($1.03 million) contract is for building AltoCrypt Stik, an easily transferrable, network penetrating device that allows seamless yet secured accessing and sharing of information. The announcement for Penten’s AltoCrypt Stik was made in August 2017 by the Australian Cyber Security Growth Network (ACSGN).

Christopher Pyne, Minister for Defence Industry commented, “This advanced communication technology can be rapidly deployed to individual computers, which will change the way classified information is shared, used, and accessed. The development of these devices aims to increase agility, reduce complexity, and enable better decisions by ADF commanders and their staff in a tactical environment.”

This is not the Penten’s first government project; they are already the exclusive distributors and support service providers in Australia and New Zealand for Amiosec, a UK based security technology provider. Penten’s project is part of Australia’s Defense Innovation Hub (DIH), an initiative taken during the 2016 Defense Industry Policy Statement.

Last year, the ACSGN announced the expansion of the country’s cybersecurity sector from AU$2 billion ($1.58 million) to AU$6 billion ($4.73 billion), along with AU$730 million ($575 million) investment in Australia’s Defence capability and innovation.

 

Britain partners with AI startup to bracket extremist content

Amber Rudd

Britain’s Home Secretary Amber Rudd, currently visiting the Silicon Valley, announced United Kingdom’s partnership with a London-based startup to develop an algorithm which will be used to identify terrorist content on the Internet. ASI Data Science, the company that worked in collaboration with UK Home Office, announced on its official Twitter handle that the accuracy of the algorithm is close to 99.9%.

Tweet

ASI Data Science is a Data and AI specializing firm that has clients from the sports, media, aviation, retail industry among others. The tool, which mounted up to £600,000, has been created and tested by passing massive amount of ISIS material for automatic identification of extremist content. Rudd elaborated, “It’s a very convincing example of the fact that you can have the information you need to make sure this material doesn’t go online in the first place. The technology is there. There are tools out there that can do exactly what we’re asking for. For smaller companies, this could be ideal.”

Rudd said that she still believed an ‘industry-led forum’ was the best solution to the hateful content being spread by radicals through different channels. She was referring to social media companies for content monitoring. In the last few years, social media especially Facebook is under scanner for their unsupervised content.

Former Information Security Bureaucrats, now cybersecurity top guns elsewhere

Government officials

The Information Security Officers who have walked through regency corridors are now assisting enterprises in constructing their cybersecurity retreats, as the increasing incidents of cyber heists continue to be a cause of worry for governments and businesses across the world. The last few years have seen top guns in bureaucracy changing gears to propel the cybersecurity infrastructure in different business domains. While Nathaniel Gleicher’s move to Facebook was received gladly, allowing for adoption of essential information security measures on the social media platform, stepping down of Cory Louie and Gregory Touhill on the other hand were not bargained for.

Announcements of ex-White House Information Security officers, former CISO Feds, even Homeland Security officers migrating into the commercial sectors are making regular news. Being actively signed by cybersecurity innovators, leading financial, healthcare, aerospace, and diverse professional service sectors, these information security professionals seem to be holding the reins tight against cybercrime. Here’s a list of some of these cyber custodians who have made their way from the red tape to the pecuniary world.

Cyber Defenders Past Title Current Designation
Dr. Alissa Johnson Deputy Chief Information Officer at Executive Office of the President at The White House

 

Vice President, Chief Information Security Officer at Xerox
Cory Louie Chief Information Security Officer at The White House Chief Information Security Officer at a confidential Healthcare firm
Jeremy Haas Cyber R&D and Telecom Officer at United States Air Force Chief Security Officer at LookingGlass Cyber Solutions, Inc.
Antoine Creux Inspector General at Ministry of the Armed Forces of France Director of Group Security at Société Générale
Michael Taxay 22 years in bureaucracy, last worked as Senior Advisor to Asst. Director, Cyber Division at the Federal Bureau of Investigation General Counsel & Chief Risk Officer at LookingGlass Cyber Solutions, Inc.
Gregory Touhill United States Chief Information Security Officer. The first CISO of U.S. President of the Federal Group at Cyxtera Technologies
Drew Orsinger Protective Security Advisor at U.S. Department of Homeland Security Chief Security Officer at SpaceX
Macy Dennis Advisor to California Governor’s Cyber Taskforce Chief Security Officer at EVOTEK
Nathaniel Gleicher Director for Cybersecurity Policy at National Security Council of the White House

 

Head of Cybersecurity Policy at Facebook
James Turgal 21 years of service at the Federal Bureau of Investigation, last worked as Assistant Director Managing Director of Cyber Risk Services at Deloitte & Touche, LLC
Renitalynette K. Anderson 19 years in bureaucracy, last worked as Chief Technology Officer at Federal Retirement Thrift Investment Board President at QuTech
David Ferbrache 17 years in establishment, last worked as Head of Cyber & Space at the UK Ministry of Defense Chief Technology Officer, Cyber at KPMG UK
Linda Walsh Supervisory Special Agent at the Federal Bureau of Investigation Managing Director for Cyber Risk Services, Deloitte & Touche LLP

 

Cyber Invasion at Pyeongchang Winter Olympics

Winter Olympics

Reports of the Winter Olympics being the target of cyber criminals had been doing rounds for some time.  Finally, the organizers of Pyeongchang Winter Olympics have accepted the possibility of being under a cyber attack. The website, television, and Internet access were affected by this cyber heist. The attacks took place during the opening ceremony, however, it didn’t affect any critical operations. “The best industry practice is that you don’t talk about an attack at this stage,” commented Mark Adams, spokesperson for the International Olympic Committee (IOC).

It was also confirmed that all the issues were resolved by Saturday (February 10, 2018) morning and the source of the attack was also identified, although the organizers chose not to reveal it. For a long time, whispers of North Korea planning a cyber attack on its unfavorable neighbor was being conjectured, though Russia is being guessed as the new suspect. The country has been banned from this year’s games after IOC investigators found it guilty of carrying out state-supported doping program. However, 169 unblemished Russian athletes have been permitted to compete under a neutral flag.

The Russian foreign ministry in its statement clarified, “We know that Western media are planning pseudo-investigations on the theme of ‘Russian fingerprints’ in hacking attacks on information resources related to the hosting of the Winter Olympic Games in the Republic of Korea. Of course, no evidence will be presented to the world.”

Olympics have been a hot target of cyber criminals in the past too. The 2012 London Olympics also faced six cyber invasions, out of 97 security instances. Also, warnings of cyber outbreaks during the 2014 Sochi Olympics had gathered considerable attention.

Ukrainian cybercrime forum brought down

Infraud, DCPCU fraud police

In one of the biggest crackdowns on cybercrime, Sergey Medvedev, a darknet kingpin, has been arrested in Bangkok. The 34-year-old Ukrainian, who co-ran Infraud, a cybercrime network operating as an online discussion forum, reportedly had 100,000 bitcoins which were all seized by the police.

Infraud was shut down by the U.S. Justice Department, according to an announcement made on Wednesday, February 7, 2017. The cybercrime ring had been in existence since 2010 and worked under the slogan ‘In Fraud We Trust’. Svyatoslav Bondarenko, a 34-year-old Ukrainian who created the group, had been able to involve people from United States, Australia, the United Kingdom, France, Italy, Kosovo, and Serbia in the cybercrime ring. Currently, 36 people have been indicted on the charges of identity theft, bank fraud, wire fraud, and money laundering.

Bondarenko is alleged to have created the forum for people interested in hacking and trafficking of credit cards, banking details, and other personal information. According to the U.S. Justice Department, Medvedev took over the forum in April 2016. The group had a chain of command to regulate its activities, while stolen information was promoted and malware on sale could be advertised; sale or purchase of stolen devices duped from Russians was not allowed.

Although some of the accused are at large, this cessation is being considered a big step, in the words of Deputy Assistant Attorney General David Rybicki “a significant step in the battle against transnational cyber crime.” The prosecution statement mentions login credentials of more than 750,000 HSBC accounts, also listing PayPal logins and credit card credentials. The cyber heists amount to losses of more than $500 million through buying and selling of social security numbers, passwords, and other personal customer information on a global scale.

Booz Allen Hamilton awarded $621 million federal cybersecurity contract

Homeland

In a press release on its official website Booz Allen Hamilton, a leading U.S. based consultant in cybersecurity, analytics and digital solutions provider, announced that is has won the contract for Department of Homeland Security’s (DHS) DEFEND program. The six-year contract falls under the government-based Continuous Diagnostics and Mitigation (CDM) and Evolving Federal Enterprise Network Defense (DEFEND) Program.

Posting the news on its official Twitter handle, the technology consulting firm wrote:

Twitter_1

The technology solution provider has been partnering with the U.S. Defense Department since 1940. The company declared revenue of $5.80 million in March 2017. The new CDM program aims to reduce the cyber threat looming over the federal department through innovating solutions and creating dynamic Agency environments.

Brad Medairy, SVP and leader of Booz Allen Hamilton’s civil cyber business, commented on winning the new deal, “The cybersecurity threats facing government agencies today are growing increasingly dynamic and sophisticated, making them more challenging to defend against. We are well positioned to help in this fight, applying experiences that our analysts, threat hunters and engineers gain by working on the cutting edge of cybersecurity. We are embedded in the nation’s most important missions and will continue to help drive toward innovative solutions like CDM to make the world a safer place in the face of ever-evolving cyber threats.”

Cisco, Apple, Aon, Allianz introduce a first in cyber risk management

Apple, Apple security update

This is a press release taken from Apple Newsroom.

Cisco, Apple, Aon and Allianz recently announced a new cyber risk management solution for businesses, comprised of cyber resilience evaluation services from Aon, the most secure technology from Cisco and Apple, and options for enhanced cyber insurance coverage from Allianz. The new solution is designed to help a wider range of organizations better manage and protect themselves from cyber risk associated with ransomware and other malware-related threats, which are the most common threats faced by organizations today.

Cybersecurity risk is growing. Losses from cyber threats are outpacing investment in IT security.1 This fact, combined with low adoption of cyber insurance,2 an active adversary, a fragmented security technology market and a security skills shortage, means it is difficult for many organizations to understand and manage this risk effectively.

The new solution covers the primary dimensions of cyber protection for businesses. The key elements of the offering include:

  • Cyber Resilience Evaluation: Aon cybersecurity professionals will assess interested customers’ cybersecurity posture and recommend ways to help improve their cybersecurity defenses.
  • Cyber Insurance: Allianz evaluated the Cisco and Apple technical foundation of the solution and determined that customers using Cisco Ransomware Defense, and/or qualified Apple products can be eligible for the Allianz-developed enhanced cyber insurance offering, acknowledging the superior level of security afforded to businesses by Cisco and Apple technology. This, in combination with individual risk insights gained through the Cyber Resilience Evaluation, makes possible the enhanced cyber insurance coverage to Cisco and Apple business customers. Enhancements include market-leading policy coverage terms and conditions, including potentially qualifying for lower, or even no, deductibles in certain cases. The cyber insurance coverage is underwritten by Allianz Global Corporate & Specialty (AGCS).
    • Cisco Ransomware Defenseis part of Cisco’s integrated security portfolio that leverages industry leading threat intelligence from Cisco Talos to see threats once, and block them everywhere. The solution includes advanced email security, next-generation endpoint protection and cloud-delivered malicious internet site blocking, to strengthen an organization’s defenses against malware, ransomware and other cyber threats.
    • Apple products: iPhone, iPad and Mac give employees the best experiences at work with the strong security that businesses need. The tight integration of hardware, software and services on iOS devices ensures that each component of the system is trusted, from initial boot-up to installing third-party apps. Users benefit from always-on hardware encryption, as well as support for secure networking protocols like Transport Layer Security (TLS) and VPN out of the box.
  • Incident Response Services: Organizations will have access to Cisco and Aon’s Incident Response teams in the event of a malware attack.

The new solution is available today. For further information visit https://cisco.com/go/cyberinsurance

“At Cisco, security is foundational to everything we do.  As the leading enterprise security company, we know that in a digital world security must come first, and our integrated security architecture reduces customers’ overall risk of exposure to ransomware and malware attacks,” said Chuck Robbins, Chairman and CEO, Cisco. “Cisco Security technology is central to the new holistic risk management solution and we are excited to bring another important benefit to our customers with greater options for cyber insurance.”

“The choice of technology providers plays a critical role in any company’s defense against cyber attacks. That’s why, from the beginning, Apple has built products from the ground up with security in mind, and one of the many reasons why businesses around the world are choosing our products to power their enterprise,” said Tim Cook, Apple’s CEO. “iPhone, iPad and Mac are the best tools for work, offering the world’s best user experience and the strongest security. We’re thrilled that insurance industry leaders recognize that Apple products provide superior cyber protection, and that we have the opportunity to help make enhanced cyber insurance more accessible to our customers.”

“Ransomware is an evolving risk that impacts every level of an enterprise. Organizations urgently need to be managing these risks from both the technical and the financial perspective,” said Jason Hogg, CEO, Aon Cyber Solutions. “This holistic solution provides our clients with an integrated approach to addressing ransomware risk. We can provide customers with guidance on what cyber defenses, resources and processes to deploy to improve their cyber posture. It’s the improved cyber posture that makes them eligible for enhanced/broader cyber insurance protection.”

“Proactive analysis coupled with the latest technology creates an ideal defense against today’s ever-changing ransomware and malware attacks,” said Bill Scaldaferri, President and CEO, AGCS North America. “This strategic alliance with Aon, Apple and Cisco allows us to provide a unique solution to companies using this integrated platform to manage risk and ultimately strengthen their battle against high-profile threats.”

 

Cybersecurity in spotlight: Stephen M. Ross’s RSE Ventures acquires Oxford Solutions

Acquisition

Matt Higgins and Stephen M. Ross co-owned RSE Ventures have completed the acquisition of cybersecurity firm Oxford Solutions. Post the acquisition, the Oxford Solutions has been rechristened as Skout Secure Intelligence and it will continue to provide cybersecurity solutions and allied activities for its clientele across the globe.

Stephen M. Ross is also the owner of the Miami Dolphins and developer of New York’s Hudson Yards. The acquisition has been dubbed as Ross’s bet on cybersecurity for small and mid-sized enterprises.

According to data from PwC and CB Insights, venture capital funding in cybersecurity has grown by 40 percent to record $3.7 billion. “There’s a lot of money chasing deals in this space,” Higgins stated in an interview with The Financial Times. “We’ve invested in tech in a much less significant way,” Higgins said, adding that the VC’s stakes in Palantir and Coinbase were significantly less.” With regards to financial impact, the average cost due to holistically handling cyber attacks and incidents has increased from $879,582 to $1,027,053.

“We are hearing a consistent message from our portfolio; there is a gap in the marketplace for a company that serves the needs of small to mid-sized businesses, makes cybersecurity understandable, reassures business leaders about their security, and addresses the severe lack of human engagement in the industry. That’s what led us to Skout,” said Higgins in a statement. “Our relationship with Skout will also help position them to expand their offerings and insights globally. We are putting our full support behind this brand and believe there is unlimited potential for growth in this untapped space.”

Skout taps on the need for cybersecurity in the mid-sized companies by blending cloud-based technologies and data analytics. Skout’s personal, human communication makes technology security solutions accessible even to non-experts.

“Cybersecurity is like healthcare. We all need access to it. With 1.5 million job openings in the industry, a shortage in expertise, and the increasing cost of technology, many small to midsize firms understand they are at risk, but don’t know how to protect themselves. That is where Skout comes in,” stated Co-Founder and CEO, Aidan Kehoe while underscoring the need for companies to adapt to the changing cyber landscape.  A CEO’s biggest nightmare is having their company experience a security breach and not having the resources to solve the problem. Not only are there huge financial repercussions, but also damage to their reputation and the loss of consumer confidence in them (…) The team at Skout understands how to partner proprietary technology with the highest level of customer service to help companies protect themselves.”

Aidan Kehoe will be joined on the Board by Stephen M. Ross and Matt Higgins. In addition, Michael Pascucci and the Pascucci family will remain on as investors. Skout Secure Intelligence, earlier Oxford Solutions was originally founded in 2013 to provide cybersecurity monitoring and customer service to organizations, around the globe. The company has over 800 clients, globally.

 

Texas Hospital Association partners with Clearwater Compliance for hospital cybersecurity

Thoma Bravo Acquires Sophos for US$3.9 Billion

Texas Hospital Association (THA) has entered a partnership with Clearwater Compliance, a healthcare cyber risk management and regulatory compliance solutions company, to bolster hospital cybersecurity in nearly 85 percent of the state’s acute-care hospitals and healthcare systems, which falls under the purview of THA.

“As we’ve learned over the last year, hospitals and medical devices in the United States are extremely vulnerable to cybe rattacks,” said Ted Shaw, president and CEO of the Texas Hospital Association. “This threat represents what could be a significant and destructive result on operations and financial health of our hospitals, but more importantly, the healthcare quality our patients depend on.”

THA has collectively employed more than 365,000 healthcare professionals statewide. The partnership will enable THA member hospitals to avail Clearwater Compliance’s risk assessments, respond strategically to cyber threats, assistance with several risk management tools, compliance and regulatory issues.  “Clearwater Compliance’s services include comprehensive risk assessments, assistance with the U.S. Department of Health and Human Services’ Office for Civil Rights investigations and audits, ongoing education and expert consulting services to meet member hospitals’ regulatory and risk management goals,” Clearwater Compliance stated in a statement.

“We are honored to earn the Texas Hospital Association’s trust and confidence,” said Barry Mathis, senior vice president and chief business development officer, Clearwater Compliance. “We show outcomes and results and see firsthand how we are improving the lives of our customers. We will help Texas hospitals better identify and manage cyber risks to ensure access to timely, quality care.”