Home Blog Page 376

National Data Guardian’s cybersecurity bar “quite high” for NHS Trusts

NHS

During a hearing on the WannaCry attack that hit the healthcare industry in 2017, the National Health Service (NHS) Deputy Chief Executive Rob Shaw accepted that all the National Health Services trusts evaluated for cybersecurity regulations have failed to meet the set standards. He further elaborated that all the assessed 200 institutions found it difficult to meet the National Data Guardian Dame Fiona Caldicott’s requirements.

“The amount of effort it takes from NHS Providers in such a complex estate to reach the cyber essentials plus standard that we assess against as per the recommendation in Dame Fiona Caldicott’s report, is quite a high bar. So some of them have failed purely on patching which is what the vulnerability was around WannaCry,” Rob said. Presenting the findings to the Commons’ public accounts committee, the NHS digital deputy chief executive clarified that although some of the trusts have a substantial work to do, it is not like they haven’t worked at all on the issue. Testing of dataflow against standard practice principles, emphasizing on confidentiality and information security alertness amongst all NHS staff, and following the best principles when designing health information systems are some of the recommendations in the in Dame Fiona Caldicott’s report.

The WannaCry Ransomware hit Microsoft Windows OS during May 2017. It affected the operations of nearly 200,000 systems across 150 countries, including automobile companies like Nissan and Renault which had to halt productions at several sites to stop the ransomware from spreading. The National Health Services hospitals of England and Scotland were amongst the worst affected; the impact included disturbing critical devices like MRI scanners, blood-storage refrigerator, even theatre equipment. According to a report released by National Audit Office, the complete extent of the damaged caused by the ransomware might never be known.

Amid several ambiguity and concerns, Singapore passes cybersecurity bill

Singapore cybersecurity bill

Recognizing the fast-evolving cybersecurity landscape and the impending cyber threats that loom over the Singapore cyber space, the Singapore Parliament has passed the Cybersecurity Bill. Under the bill, the owners of key bodies like national security, defence, foreign relations, economy, public health, public safety or public order, which the bill calls critical information infrastructure (CII) will have to comply to the standards and regulations mandated by the bill. The bill also mandates CIIs to conduct cybersecurity audits and risk assessments, and routinely participate in cybersecurity exercises.

Minister for Communications and Information Yaacob Ibrahim said, “no action will be taken against CII owners for cybersecurity breaches if they comply with their obligations. However, non-compliance will be an offence that will entail a maximum penalty of S$100,000, two years in jail, or both.”

According to the bill, the chief executive of Cyber Security Agency of Singapore (CSA) will be appointed as the Commissioner of Cybersecurity. He will be entrusted with administering the bill and to designate any computer or computer system as CII, in accordance with the earlier issued draft bill.

Earlier in 2017, Ministry of Communications and Information (MCI) and the CSA had issued a public consultation as part of the Draft Cybersecurity Bill. Heavy inbound feedback had made the agencies extend the consultation period. With most feedback in, the agencies had released a ‘Report on Public Consultation on the Draft Cybersecurity Bill.’

The draft bill had garnered responses from industry experts, cybersecurity professionals, and academics who had called for more comprehensiveness and broader approach, requesting elaboration powers given to the CSA, and most importantly the state of licensing cybersecurity professionals. According to the report, “The earlier proposed licensing framework for cybersecurity service providers involved licensing penetration testing service providers and individuals under an investigative cybersecurity service license and managed security operations centre (SOC) monitoring services providers under a non-investigative cybersecurity service license. The framework would apply to these providers and individuals serving the Singapore market. In-house provision of cybersecurity services is exempted.”

Currently, the agencies only intend to “license penetration testing and managed SOC monitoring service providers, including resellers of such services.” This has been implemented because according to the agencies, penetration testing and managed SOCs are very highly prevalent in the region.

The draft bill also mulled on exempting in-house penetration testing and managed SOC monitoring services, stating that “we do not intend to require organisations to be licensed for providing these services to their affiliated organisations.”

According to Dr Yaacob, penetration testing and managed security operations centre monitoring, “have access to sensitive information from their clients, and the services are also relatively mainstream in our market, and hence have a significant impact on the overall cybersecurity landscape.” He said while introducing the bill in the Parliament, “The requirement will not apply to in-house work, and providing licensable services to related companies, he said. Failure to get a license for a licensable service will mean a maximum penalty of S$50,000 fine, two years in jail, or both,” according to Channel News Asia.

Several MPs also raised several questions on privacy, cost of compliance, to which Dr Yaacob only responded by saying, “Let me assure the House that the powers under the Bill are not intended to intrude into privacy.”

Philippines to devise rules for cryptocurrency trading

Following the footsteps of South Korea, Philippines has also announced drafting of rules to regulate usage of cryptocurrency in the country. The directive will include launch and registration of cryptocurrencies, along with standard rules on cybersecurity of cryptocurrency markets, and qualification of cryptocurrency issuers. The law will also cover the details of officials and the technology used and financial literacy of investors too.

Emilio Aquino, SEC commissioner in charge of enforcement and investor protection, commented, “We need to act because initial coin offerings (ICOs) are sprouting especially in 2017. We want to come up with our own set of regulations. “You have to be extra careful how investors in this new space are protected.”

Recently, Japan has been in news for losing nearly $530 million in the Coincheck cyber-attack. This is being considered the biggest cryptocurrency heist till date. The increased cryptocurrency cyber heists have raised concerns among nations on the safety of blockchain and similar ledger technologies. The shaky reputation of ICOs is also a cause of concern with incidents of scamming investors coming to light. A few countries such as China and South Korea have debarred ICOs and closed down local trading platforms. Recently Dallas-based Arise Bank came under Securities and Exchange Commission’s scanner for raising unregistered investments through its cryptocurrency AriseCoin’.

In order to create a collaborated platform against increasing cyber attacks, this year’s World Economic Forum at Davos launched a new Global Centre for Cybersecurity.

 

Israel combating cybersecurity threats with key partnerships

Israel

Israel’s reputation as a cybersecurity force has attracted considerable attention from different countries, which are looking for strong cybersecurity associates. The country has entered into key partnerships with other countries in an effort to make the cyber world a safe place. The latest of the partnerships is the news of Polish power grid operator, Polskie Sieci Elektroenergetyczne’s (PSE) with Israel Electric Corporation Limited to secure its energy sector. The deal resonates with the cybersecurity leader’s tie-up with Canada in 2017. The Israel Electric Corporation (IEC) had partnered with the Canadian Hydro-Quebec utility to boost the security of their grid infrastructure.

Eryk Klossowski, Chief Executive at PSE, commented on its partnership with Israel, “We gain an experienced partner, effective in fighting cybercrime. This is extremely important at a time when cybercriminals and cyber-terrorists develop cooperation among themselves and create more and more advanced tools of attacks.”

On his first visit to India in January 2018, Israeli Prime Minister Benjamin Netanyahu and his Indian counterpart Narendra Modi shook hands on cybersecurity collaboration, which would include training, B2B assistance, and enablement of industrial summits to enhance skill development in the country.

With countries becoming more alert on the cybersecurity threats in the energy and telecommunications sectors among other domains, they are showing more interest in collaborations with expert nations who can provide a robust infrastructure to help them raise their cybersecurity standards. Israel collaborates with U.S. on the cybersecurity arena, even though the countries have strained relations on other fronts. Off late the near east country has been showing interest in exploring the Chinese information security market too.

Two questions for every security leader

CISO, Cybersecurity

Contributed by Richard Seiersen, SVP & Chief Information Security Officer, LendingClub

The actual science of logic is conversant at present only with things either certain, or impossible, or entirely doubtful, none of which (fortunately) we have to reason on. Therefore, the true logic for this world is the Calculus of Probabilities, which takes account of the magnitude of the probability which is, or ought to be, in a reasonable man’s mind. —James Clerk Maxwell

There are two basic questions I ask myself, my teams, and security folks at large. First, “How do I know I have the right security capabilities?” and second, “What would I see occurring that would let me know my capabilities are improving?” I might add to that last one, “… while the business scales?”

Do I Have the Right Security Capabilities?

My co-author Doug Hubbard and I provide a detailed answer for the first question in our book, How to Measure Anything in Cybersecurity Risk (Wiley 2016)[1]. Measurement experts such as scientists, actuaries, mathematicians, statisticians, some engineers, and data scientists will find our approach familiar. Especially actuaries because the green book (as we affectionately call it) will become required reading for The Society of Actuaries exam prep from 2018 onward.

These experts would most certainly take a quantitative approach to my first question. Their tactics are grounded in the logic of uncertainty, aka probability theory. Please don’t be scared off by that “mathy” turn of phrase. You just need to know that probability theory simply counts up all the ways an event can happen and puts more weight on those possibilities that are most plausible. It’s a centuries old shortcut born out of laziness, boredom, and the desire to beat the house.

Truth Is Not the Goal, Better Is.

Adopting a probabilistic approach means not looking for the “perfectly correct” answer to intangible questions like “do I have the right capabilities?” You want the most plausible answer(s) given your current state of uncertainty. This means being resourceful with what little empirical data you have. And if you lack empirical data you may be left with modeling your subject matter experts’ beliefs. You likely paid a lot for their expertise, you might as well model it. Now that is being resourceful!

This is a key point for security folks. Security by its very nature is mired in uncertainty. We have uncertain sentient and artificially intelligent adversaries attacking a myriad of systems all in transient states. Our understanding, or model, of that world is by its very nature, woefully incomplete.

The statistician George Box made this point of view popular by saying, “all models are wrong, but some are useful.”  Which my co-author embellishes with, “…and some models are measurably more useful than others.” Your goal is improvement over your current model at a reasonable cost. Don’t let your uncertainty caused by a lack of perfect data stand in your way.

Better Decision Making

Models, wrong or very wrong, exist to aid you in decision making as opposed to substituting for it. The model for answering my first question would help you figure out which capabilities best reduce risk (breach) given your risk tolerances[2]. It should also take into consideration any reduction in opportunity loss[3] (lost sales) as well as the cost of controls[4] (cost of people and gear etc.). That’s how we get the best return on investment (ROI) i.e. the best bang for our buck in reducing probable future loss.

ROI becomes a type of score[5] for organizing our choices in order of importance. It’s a huge improvement over risk registers, heat maps, and other qualitative scoring systems in the security marketplace. We and other experts in our book enjoy saying that those approaches are “worse than doing nothing.”

But Wait, We’re Different!

Security folk may argue that the combination of systems complexity and chaotic actors make the possibilities of compromise uncountable (not that they have tried) and thus immune to probabilistic means. They say this as if fields that use probabilistic approaches must have easier problems to solve; fields like nuclear engineering, military logistics, epidemiology, seismology, and cytology (name your ology as long as it’s not astrology … it doesn’t work). The point is that measurement experts adopt probabilistic approaches because of uncertainty, not in spite of it.

Making Security Rigorous

If you haven’t guessed it by now, I believe it’s time for security to start measuring more like the sciences do, or like anyone with serious treasure at stake would do. And you don’t have to be a scientist or a statistician to do this (I’m not). Statisticians, similar to cooks, do what they do for others to consume. Take plumbers for example: they don’t need to know squat (pun intended) about the physics of fluid dynamics to fit the right pipes given the water pressure coming into a house. They just know which tools and materials to use for the particular problem at hand. Likewise, you don’t necessarily need to understand the math[6] as much as you need to understand the problem you are trying to solve. From there you are just fitting the appropriate quantitative materials together to make what will ultimately be a wrong (all models are wrong) but hopefully better model than you are currently using.

Think More, Do Less

A problem well defined is a problem half solved.” – Charles Kettering.

If your problem is framed badly then no model, no math, no concoction of any kind can magically save you from yourself. In my experience, most security folks don’t spend enough time thinking or framing their problems. The current trend is to knock out tasks (be a doer/builder) and deploy taken-for-granted technology in the hope things will improve. Task obsession is a sure-fire way to lose the forest for the trees in security. The bad guys would love nothing more than to have you whittling away the hours on low impact, uncoordinated busy work.

By way of example, I consulted with an organization not too long after the Equifax breach. I used what we knew of the breach[7] as a tabletop exercise to determine the state of the current organization’s end-to-end vulnerability management program. While they had historically knocked out numerous tasks related to the topic and made several key investments, they profoundly underperformed Equifax. Why? They couldn’t rank-order what big outcomes were important in a systematic way. What they did have was “more security tasks … faster.” That was their model. Now, after improving their vulnerability management program and focusing on ranking important outcomes, their results should beat their old model, which had near zero measurable outcomes, and Equifax to boot (at least I hope it will).

The improvements were fundamentally about shifting their thinking from being task-oriented/busyness-obsessed to big picture strategizing for the organizations’ assets.

As a security leader, don’t be fooled by busyness and don’t let your teams be fooled by it either. It’s faux noble and will not be effective in light of increasing platform uncertainties and talented adversaries. Perhaps it’s time to think more and do less? Specifically, thinking more about our capabilities and doing less busy work so you can focus on big impact, ROI-based, outcomes.

In my next article, I will address the second question. And who knows, I may throw in some code!

 

[1] Doug Hubbard was my co-author: https://www.linkedin.com/in/dwhubbard/

[2] Risk tolerance could be your cyber insurance coverage or it could be multiple factors. Also consider that the NIST CSF, amongst others, expects risk management to consider tolerance.

[3] Opportunity loss is reduced when security meets customer, industry or regional requirements and allows for new and expanded sales.

[4] Security gear, people and etc.

[5] It’s a mathematically unambiguous score. Unlike a “High” or a 10 on a 1-10 scale.

[6] Data analysis is an applied art. Analysts are API/tool users. Deeper math, statistics, probability theory and etc. is not required. But, it would certainly help in better understanding what is going on under the hood. Those people designed tools for you use to answer questions in your particular domain. Go for it!

[7] Use big breach announcements, new zero days, etc. as a form of table top. Collect the evidence from an article about the event and turn it on yourselves to see how well you would do. This is a much more productive way to read all the security blather that is out there. Ask “what if it were me?”

Alleged GoGet hacker gets bail

GoGet

What happens when a skilled hacker takes inept advantage of his skills? He can hack into databases, obtain IDs and payment details of different people, make 30 bookings for luxury cars, bill strangers, and, of course, go on free excursions without worrying about the cost. Nik Cubrilovic, who was arrested by the New South Wales police on Tuesday, 30th January, 2018, has been accused of doing all this and more. Granted bail by Wollongong Local Court a day later, he has been abstained from using the Internet and ordered to report to the police regularly. It was reported that the NSW police had strongly objected to accepting his bail plea on the grounds that he might be able to delete some of the evidence and use his skills to evade police and courts.

Interestingly Nik had once been in the good books of his reported victim, GoGet, an Australia based car-sharing company. The security consultant had pointed out weaknesses in the vehicle service-provider’s operating systems during 2016, for which he was rewarded by the company.

However, for the last six months, the same patron had allegedly turned into a villain and was taking undue advantage of the flaws in GoGet’s systems. The company found out about the hacking during the month of July 2017 and informed the State Crime Command’s cybercrime unit of the same.

On the advice of the police, the company didn’t inform its customers of the database hack, so as not to alert the culprit. GoGet sent out a mail to its customers on Wednesday morning, informing them about the hack and their success in arresting the accused. The mail also confirmed that the stolen data has not been shared by the alleged hacker, “Based on advice from the NSW Police Cybercrime Squad, at this time there is no evidence of misuse of, or that the suspect has disseminated any of, your personal information… [that] includes your name, address, email address, phone number, date of birth, drivers licence details and other GoGet administrative account details.”

Incedo opens cybersecurity center in India

India

San Francisco-based Incedo, a firm specializing in data management, analytics, product engineering and emerging technologies, has announced the launch of International Cyber Security Center in Pune, India. The center will be crucial in handling real-time threat detection and financial fraud management. Christened as the Cyber Security Centre of Excellence (CoE), the center has been setup in a strategic partnership with Tripwire.

The $2 million infrastructure will serve as a body that will protect critical national data from several vectors of cyber attacks and breaches. The company will also utilize the IT talent pool of the country and has been in an aggressive yet fastidious hiring spree.

“Incedo is delighted to set up its newest delivery centre in Pune. The cyber security practice at Incedo is set to grow exponentially and we are committed to investing heavily towards building our engineering expertise to serve a rapidly evolving, critical sector,” Anupam Wahi, Senior Vice President & Head of Communication Engineering at Incedo said, “Incedo’s partnership with Tripwire is a testament to our commitment towards clients’ business needs. Our engineers in Pune will work very closely with Tripwire product specialists in Portland, Oregon thus enhancing Tripwire’s R&D capabilities and greatly accelerating their product development velocity.”

The engineers will also set up analytics for several Tripwire offerings. “For over two decades now, Tripwire has helped companies navigate an ever-evolving cyber security landscape. As intensity of data breaches continue to grow, cybersecurity is becoming a part of every organization’s risk agenda. The need for accelerated innovation and expanded engineering capabilities could not get more significant for us. We are thrilled to partner with Incedo for product engineering and R&D at their Pune development centre. Over the years, Belden has had a trusted technology partnership with Incedo, I can’t think of a better ally for Tripwire,” Dhrupad Trivedi, Executive Vice President at Belden & President at Tripwire, said.

 

Dutch banks and tax office fall victim of coordinated attacks

Tech Against Corona: A Cybersecurity Campaign to Fight COVID-19-related Cybercrimes in the Netherlands

Critical nodal agencies and several banks in the Netherlands were hit by a series of cyber attacks. The national tax office went offline for a brief span after the servers crashed following a Distributed Denial of Service (DDoS) attack. The national digital signature system which is used by more than 12 million citizens in the country of 17 million was also hit. Most companies resumed function at the earliest. Banks like ABN Amro and ING notified that the companies were targeted by hackers who had disrupted online and mobile banking services over the weekend. As per reports, ABN Amro suffered three attacks over the weekend and overall seven over the last week.

Even Rabobank was a victim of an attack. “We have been targeted by a DDoS attack since 9.10 am this morning and our clients don’t have access or very little access to online banking,” Rabobank spokeswoman Margo van Wijgerden said. “We are working to resolve the problem as quickly as possible.” However, Dutch news reports later said that the problem had been fixed by 11.00 am.

According to reports, Dutch intelligence was spying on the infamous Moscow-based hacker group Cozy Bear, which was earlier linked in the alleged hacking of the U.S. democratic elections in 2016. Dutch cybersecurity expert Rickey Gevers pointed out that it is too early to pinpoint any particular hacker group behind the incident. “Timing is the only thing that links the two so far,” he said. “If an individual is behind these [DDoS] attacks, we’ll probably figure it out soon. If a country is behind the attacks, we won’t ever know for sure which country it is.”

“’Cat-and-mouse game’ It is not the first time Dutch banks have been targeted in a DDoS attack, central bank chief Klaas Knot told a TV news channel Buitenhof. “I think these (recent) attacks are serious, but our own website is being attacked thousands of times per day. That is the reality in 2018.”

UK issues cybersecurity directive for operators of essential services

Banks in United Kingdom

Following EU’s Network and Information Security Directive (NIS), the United Kingdom government will now penalize operators of essential services, if they fail to meet the conventional cybersecurity standards. The directive includes 14 principles centered around the prevailing global standards and guidance. This fine which can be up to £17 million will be the last recourse to be adjudged on the level of cooperation shown by the companies with their regulators, termed as Competent Authorities. However, critics argue that the glitch is visible in the reference ‘Operators of Essential Services’. Although, the memorandum defines that these essential services are meant to safeguard health, energy, transport and digital infrastructure, it leaves out government, chemicals, food, and agriculture.

The directive handed out by the Department for Digital, Culture, Media and Sport is based on the UK government’s proposals published in August last year conferring to the NIS Directive. Although on the verge of Brexit, the UK government had agreed on the implementation of EU’s NIS Directive for securing its technology, data and networks. A list of Competent Authorities is being prepared who will act as regulators, and overview incident reporting. There will be separation of powers between these Competent Authorities and National Cyber Security Centre. The NCSC will have more of an advisory role on the Computer Security Incident Response Team (CSIRT), limiting it from enforcing any actions on the digital service providers..

The level of penalty will vary for different sectors and the Competent Authorities will consider qualifying factors when penalizing the companies. The procedure of incident reporting has also been elaborated in the directive, whereby the regulators will determine the level of impact caused by the laxation on the basis of the number of users affected, period of the incident, and its geographical range. The foundation of the directive is laid on the grounds of national security, potential threat to public safety, and the likelihood of a substantial hostile social or economic impact resulting in huge losses.

it-sa forays into India: An interview with CEO Sajid Desai

Sajid Desai

The Indian chapter of NürnbergMesse, one of the fastest growing exhibition companies in Europe, under the tutelage of Sajid Desai will be bringing the it-sa – IT security expo and conference to India on May 24 and 25, 2018. it-sa India will provide a podium for industry experts and solution providers to showcase, discuss, and deliberate on latest technologies in the realm of cybersecurity. In an exclusive interaction with CISO MAG Feature Writer Nishtha Pathak, Sajid Desai, CEO of NürnbergMesse India, unfolds his plan for it-sa  foray in the Indian sub-continent and the cybersecurity trends, it-sa  will be addressing.

 

The first edition of it-sa India will be centering on digitalization and the cyber landscape. Please elaborate on that.

Cybersecurity landscape in India has changed significantly in the past decade. Previously, basic virus protection and security controls were sufficient to deter threats. However, in the present times, advanced security analytics tools are deployed to prevent advanced persistent threats (APTs) and tackle malicious insiders. Attackers too have evolved with time. Well-funded and technically adept attackers have the capability to bring an entire enterprise or sector to a halt – something that was unimaginable a decade or two ago. As per the information reported to and tracked by Indian Computer Emergency Response Team (CERT-In), security incidents have increased from 44,679 in 2014 to 50,362 in 2016. In the first half of 2017 (till June), 27,482 cybersecurity incidents were already reported. At the other end of the spectrum, transition to digital era has ushered in a new security paradigm at a national level and has brought to fore the challenges of cybersecurity. As India continues to aggressively pursue the Digital India vision, we continue to see significant data breaches and cyberattacks across all sectors. Prevention is possible, and that means prioritising our risks and focusing efforts to minimize those risks is important. it-sa India will provide a perfect platform for Industry experts and solution providers to discuss, deliberate and showcase latest technology which is the need of the hour.

 

On a scale of 1 to 10, how much will you rate the enthusiasm shown by India for the first CyberSecurity expo?

It’s an absolute ten on ten. The industry is looking forward to explore an expo-based model, strongly supported by a high level conference program and workshop focused on training and skill enhancement. Together with our partners Deloitte, Tele Trust, and Techombay the response that we have received for it-sa India is very encouraging. The parent show in Germany, it-sa, is the leading show in Europe on the topic of cybersecurity with more than 620 exhibitors and over 9800 square meters of exhibition space.

 

How much has India’s cybersecurity awareness and practices advanced in the last two years?

In the last four years since the announcement of the Cybersecurity Policy, India’s cyber landscape has witnessed growing digitization as part of the Government’s Digital India push, as well as more sophisticated cyber threats, particularly the WannaCrypt and Petya ransomware attacks. Enterprises are now investing in next generation firewalls with advanced threat protection capabilities for advanced malware detection, and their spend on cybersecurity now forms over 10% of their IT budget and is growing at a (CAGR) compound annual growth rate of 13.5% annually.

 

Which sectors/industries would you say are most attentive towards information security?

The banking and financial sector, government and security forces, the telecom and the E-Commerce sector are some of the industries which have already realized the paramount importance of IT and cybersecurity, especially banking and e-commerce as a chunk of transactions take place online and are this more vulnerable to cyber-attacks.

 

Which sectors/industries would you say are least attentive towards information security?

No industry is safe from cyber attacks. From healthcare and banking to retail, every industry faces cybersecurity threats. While some industries have taken a head start in terms of securing their data and network, others such as Healthcare, Hospitality, Retail and Education are also getting there, and are in the process of implementing processes and safety measures.

 

What are the two things you would want all businesses to adopt as primary cybersecurity practices?

IT Security and technology advancements need to be aligned to ensure that security dimension of emerging solutions are not compromised. Businesses are willing to adopt new technology and take measures to keep the IT security agile. Convenience and security in technology needs to go hand-in-hand.  An organization irrespective of scale and size should have a strong cybersecurity policy and this should be communicated clearly to the employees.

 

Which segments of cybersecurity are CISOs planning to target in 2018?

In view of the current scenario, IT-Security Heads and experts would definitely focus on the adoption of more sophisticated security technologies to counter AI powered cyber attacks for example or IoT ransomware attacks. Privacy and personal data protection will be the focus in 2018. Companies are expected to invest in encryption and key management technologies in order to secure customer data. Furthermore, securing organizational data will also be a top priority – whether in physical data centres or in the cloud. Encryption, access control, cloud security, and secure DevOps will be some of the key initiatives in 2018.