Home Blog Page 377

Societal relevance of cybersecurity and human risk culture

small businesses cyberthreats

By Darren Argyle, Group Chief Information Security Officer, Qantas

Cybersecurity is moving from having purely technical relevance to increasingly societal relevance, affecting the way we live our lives and honour our obligations. Business leaders must respond by engaging cybersecurity specialists who understand psychology, sociology and criminology aspects, but also know how to leverage technological innovation that can scale to meet the challenges head on. This expanded viewpoint feels natural for those of us who have been in the cybersecurity industry long enough and have the relevant experience to know that building a risk aware culture is a priority.

At the heart of most corporate cyber crisis lie the risks involved in managing people. After a host of scandals during the present century, companies recognize that policies and procedures count for very little if they ignore the human element. Efforts to tackle the matter are being made, yet major breaches keep happening. Credit-checking group Equifax this year blamed “human error and technology failure” for one of the largest data breaches in history, affecting more than 145 million people in the U.S. alone. Poor communication of risk and execution at the people level was the suggested cause.

“People risk” can range from deliberate acts of fraud or sabotage to failure to follow rules, poor training, strategic miscalculations or someone opening a virus-infected email. Globalization and technological changes add complexity to the risks companies face and the speed with which problems can escalate. The effects of poor human risk management can be long-lasting, costing millions of dollars in clean up activity, heavy fines, and lost customer trust. A culture of hiding mistakes, compounded by human weaknesses in understanding the basic cyber security principles can often be the root cause.

The purpose of cyber risk management, however, is to allow risk to be taken safely; innovation depends on risk. On the whole, financial firms are getting better at managing cyber risk; they have more money to throw at the challenge, or because they have been regulated to do it. They have deployed safeguards, such as enterprise risk management (ERM) systems, and Governance Risk and Compliance (GRC) platforms, however, these create a false sense of security because they are not directly engaging with employees on a regular basis to manage human risk. The outcome of great human risk management is the success and resilience of the business. Available research suggests there are five principles needed to achieve business resilience: 1) the ability to anticipate problems; 2) adequate resources to respond to changing conditions; 3) a free flow of information up to board level; 4) the capacity to respond quickly to an incident; and 5) a willingness to learn from the experience.

CEOs and business leaders still need to set the tone at the top, define the corporate culture and standards of behavior, but it’s the CISO and their security teams who need to build trust among employees. Employee relationships with the cyber security teams can become more detached if we simply rely on legacy outdated methods of education and awareness. It’s important to understand how to improve decision-making, to identify vulnerabilities, remain in compliance and reduce unsafe behaviours; by bringing together quantitative tools of risk management with a qualitative psychological perspective, to build a risk aware culture.

The human risk factor and increasingly societal relevance of cybersecurity means we must go beyond simple tick box exercises and not assume our people are engaged because they passed an annual test or didn’t click a phishing simulation link. It’s undeniable that organizations need to lift their cybersecurity culture game to address the elephant in cyber security’s room – the “human factor.” Organizations can do a better job by calling data sources together they already have, using a scalable technology platform solution to deliver tangible rewards from improvements in human risk management. Stop looking at your people as the weakest link, engage with them often, build trust and empower them to become the strongest link, because without people….your proccesses, your technology simply won’t work!

Let me know your thoughts, please comment and/or direct message me here to continue the conversation. Happy to discuss how I’ve applied human risk management strategies to build a more cyber resilient business, and by using an innovative scalable technology platform and how I’ve been able to accelerate human risk reduction and build a sustainable risk aware culture.

This post appeared as a LinkedIn post by Darren Argyle and is published with his permission. 

It’s time to get back to basics

Back to Basics

This article is contributed by Chris Roberts, Chief Security Architect at Acalvio Technologies.

So, the CISO MAG staff and I were talking about an end-of-year article that might get people reflecting on 2017 AND concentrating on 2018. The prediction thing is too fuzzy and I have an aversion to crystal balls, the financial thing is pretty much sorted (everyone got their 2018 budgets locked and loaded? More blinky lights for everyone, right?), and if I hear again that AI or ML is going to solve everything I will be whipping up another batch of Molotov cocktails to distribute. So, we decided to go back to basics.

The human, the poor sap we sit between the chair and the keyboard, is the one we expect to defend against people like me on a daily basis. We ask them to do this all the while juggling their regular jobs on systems that are either ancient or changing every 5 minutes with that annoying call of “where’s my damn icon NOW?” ringing out across the office. We ask them to defend our companies after we take them for 1 hour each year and sit in a room with a geek who simply tells them to “Please don’t click sh*t, please don’t send sh*t, and please stop using P@ssw0rd1 as your Facebook, bank, AND company log in.” That’s one whole hour, once a year and you then expect them to remember that for the remaining 2,086 work hours in the year (I’m now waiting for someone to tell me it’s 2,080 and I’ll point out leap years and calendar fluctuations. Trust me, HR folks need advanced degrees in quantum math to work out holidays and work periods!)

Here’s another thing you’re probably not paying enough attention to: those servers. Yes, you know the ones, the ones sitting in the remote office, or the warehouse (yeah, you though I forgot about those didn’t you). They’re sitting on the same network segment as the rest of the organization, aren’t they? The users, servers, printers, doors, AD, and probably even the IoT office-dogs bowl are all sitting on the same network. Just because it’s easy, just because you don’t know how DHCP or VLANS work, doesn’t excuse you from putting some simple separation, segmentation, or other controls in place. Oh, also back to those Windows XP servers in the warehouse, just because the vendor or supplier is too lazy to upgrade them doesn’t excuse you from taking adequate protection to reduce the risks accordingly.

And another thing. Recently we were on an IR engagement and the attackers hit at 22:30 on a Friday night. They were done and out with “job done” left all over the screens 3 hours later (NOT the normal 12 hours AVERAGE it takes to get in and get out without being detected). It took them 3 hours and nobody watching the logs until 0800 MONDAY morning. Get some logging in place, get someone to watch them 24×7, and pony up the minimal money it costs to have some peace of mind!

Don’t forget about the computers themselves. You’ve given each employee a new, shiny computer and you’ve entrusted them (you fool) with all your data. You’re left praying that the sales guys don’t trade their laptop for a round of drinks at the next client appreciation golf outing. Why? Because you didn’t bloody encrypt them! Seriously, it’s free, it’s simple, easy, secure, and can be locally or centrally managed. Just do it! That way, the next time you lose the security plans for a major airport or government you won’t be on the 9 o’clock news!

You have lost the battle for the perimeter; accept that and you might be able to focus accordingly. Look at the simple fact that in essence “computer number 1” has been compromised and work accordingly. The concept of predictive, proactive, deceptive technologies should not be alien to you. Neither should you buy next year’s purple blinky light F/W and expect it to do anything more than this year’s did, EVEN if it has UBA or “Next Gen” or “AI/ML” on it. You have the basic tools; now it’s time to elevate them with something OTHER thank the same sh*t that hasn’t secured you for the last “x” years. Your presence on the Internets, all of the Internets, the open, dark, and deep – what do you know about yourself that might be out there, what do others know that is out there, and more importantly, what are your users, vendors, suppliers, partners, and trusted resources putting out there about you? Learn what’s outside of your four walls and it might help you to focus better on how to protect what’s inside them.

Oy vey, physical security still gets overlooked. The systems that are in place can still can be bypassed (in many cases) with a fake business card (Sprint/AT&T, Cable Company), an official looking folder, and a box that looks like an Internets upgrade. Failing that, we’re going to go in via your shipping entrance, your vendor (HVAC, water, etc.), or some other way that gets us into your facility. When we get in, we’ll find your surveillance is probably on the LAN and if it’s working, nobody’s watching it. It’s still too easy, too simple to walk far enough into many facilities (not always the main office! Got to love satellite offices or warehouses on the LAN) and simply park yourself in their offices and let loose the dogs of war (or a scanner – both are equally effective). Fix the physical and you’ll be amazed at the uptake in people caring about how they look after “their” company.

Ok, now on to communications. Let’s NOT be another Uber. Sh*t happens – acknowledge it, learn from it, and move on. Humans can be forgiving if you ask for forgiveness, are contrite, accept the blame, and actually do better in the future. How do you avoid becoming another Uber? Communicate across the ranges – the basics of communication are fundamental to our understanding of our environments. Talk with people regularly, explain why decisions around security and integrity are being made, educate them as to the logic for protecting the organization, and help them implement the same protections at home and with their own family. Communication is free and it’s a troublingly underutilized tool!

A good friend of mine (F1nux) has a somewhat amazing yet grounded-in-reality statistic. He talks about the number of accounts that are already breached in global organizations at any one point in time and it’s ridiculous how many there are. It’s more than you’d think, and it’s right here, right now. If we can’t keep control of our credentials what hope do we have of keeping control of our data?

Embrace the distributed workforce and their desire to connect into the mother ship and then make sure you throw the public facing RDP server off the bloody roof.

All your SQL, MySQL, Oracle, NoSQL and other types of databases that are sitting on the Internets belong to us. This has nothing to do with patching (you are already underwater on that and running round trying to patch things every day of the week isn’t going to work). This is back to the fundamentals: certain things should NOT be on the Internets! There’s no excuse, there’s no way of lying your way out of this one, VPN’s are free, easy to implement, and simple to integrate: get the low hanging fruit OFF the firing line!

Lastly, the employees, those folks you continue to overlook: we started with them, so it’s fitting we close with them. Let’s look at a couple of things that you do wrong:

  1. You trust them! Why on this great green planet do you do that? You are not nice to them yet you expect them to be loyal and look after your assets and then you are surprised when they turn against you and you have to call us in on the forensics to see what the heck happened and why they dropped all your dirty secrets out to WikiLeaks.

2. You don’t train them and then wonder why they email all your PII/PHI/EHR all over the place?

3. You don’t give them any incentives to help secure not only YOU (the company) but also their own families and friends, and you still trust them with everything and are surprised when they turn on you.

Good grief, look in a mirror and realize YOU, the capitalist corporation, are the problem. WE ARE NOT A NUMBER, OR A STATISTIC, we are HUMANS. Treat us as such, please.

So, in closing, when 2018 comes for us (or 5775 for those of you currently in a different set of though processes) and the vendors line you up in their sights for golfing, fishing, dinner, and other events to woo you into buying the next NGFW, UBA, purple-blinky light POS, please for all those of us out there fighting the good fight, take a step back, evaluate how that technology will fix the very basics that are crippling your organization (probably without you knowing it) put down the fork or golf club, say NO THANK YOU and spend the time, effort, and money on fixing some of the things I’ve covered above.

I promise you, if you miss your vendor steak, come to Colorado and I’ll buy you one. I live on a golf course so you can go catch that one missed game and your enterprise will thank you a lot more for simply doing the basic things you need to do to protect them and their assets.

To listen to Chris Roberts and his views on cybersecurity basics, click here:

https://ciso.eccouncil.org/global-ciso-forum-podcast-with-chris-roberts/

 

Facebook hires former White House cybersecurity director as cybersecurity head

Facebook

In yet another move to strengthen its cybersecurity efforts, Facebook has hired Nathaniel Gleicher, as its first head of cybersecurity policy. After acquiring Confirm.io, a startup that authenticates government-issued IDs for third-party vendors, this is the social media giant’s new addition to its cybersecurity realm. Gleicher has served in the U.S. Department of Justice, Criminal Division, and as the director of Cybersecurity Policy at the National Security Council of White House. An engineer and lawyer, Gleicher was also the Head of Cybersecurity Strategy at Illumio, a data and cloud computing firm.

Facebook has been under the scanner for its cybersecurity structure that reportedly allows easy spreading of fake news, hate speech and unmonitored propaganda, especially during the 2016 US presidential election. The rising number of fake news on Facebook has led to questioning of the un-scanned content going live.

Facebook and Whatsapp have been used to share malicious links in the past, letting hackers gain access to messages, username and passwords. Gleicher’s hiring looks like a precursor to critical information security strategy being put in place. However, little has been revealed about which team will Gleicher be part of. Speculations of a new cybersecurity team being formed are also doing rounds.

Hackers are now ‘Jackpotting’ ATMs in US

Cybercriminals are “Jackpotting” ATMs in Europe to Steal Cash

National Cash Register (NCR) Corporation and Diebold Nixdorf, two leading financial self-service providers in the United States, have issued warning against cyber breaches that make ATMs gush out cash incessantly. Terming the hack as ‘jackpotting’ the self-service kiosk makers accepted to having informed their clients about the vulnerability. Although there is no available data on the losses due to these incidents, the ATM manufacturers have admitted to the rising cases of jackpotting across the world.

NCR cautioned, “This should be treated by all ATM deployers as a call to action to take appropriate steps to protect their ATMs against these forms of attack.” These ATM cyberattacks took off in 2015 in Asia, Europe and Mexico, however, now their new target is U.S, raising concerns for US Secret Service, which has advised financial institutions to be cautious.

KrebsOnSecurity, a leading blogging site for cybersecurity, raised the alarm about these ATM attacks spreading in US, elaborating on how these attackers, dressed up as technicians, target isolated ATMs. The cyber attack is usually carried out by accessing the machine physically and interlacing it with hi-tech electrical hacking equipment. Diebold Nixdorf issued a circular, mentioning, “In a Jackpotting attack, the criminal gains access to the internal infrastructure of the terminal in order to infect the ATM PC or by completely exchanging the hard disk (HDD). In recent evolutions of Jackpotting attacks portions of a third party multi-vendor application software stack to drive ATM components are included. In cases where the complete hard disk is being exchanged, encrypted communications between ATM PC and dispenser protects against the attack.”

Japanese cryptocurrency exchange suffers massive breach

Coincheck hack

Japanese cryptocurrency exchange Coincheck lost 58 billion yen ($530 million) in what has dubbed as biggest cryptocurrency heist ever recorded. On Friday, the website halted sales and withdrawals of the currency NEM, and later extended restrictions to other cryptocurrencies except Bitcoin. According to Kyodo News service, Koichiro Wada, President of Coincheck, made a public statement apologizing to the customers, and stated that that company may seek financial assistance.

Meanwhile, Japan’s finance regulator Financial Services Agency instructed the company to improve its operations and to submit an incident report by February 13, where the company would highlight the preventive measures adopted by it to prevent any further incidents. The regulator may also conduct an onsite inspection for the same.

Coincheck has assured that it would return about 90 percent with internal funds, but hasn’t released a scheduled date. The regulator is yet to confirm whether the company has sufficient funds for reimbursement processes.

According to a Reuters report, “The NEM coins were stored in a “hot wallet” instead of the more secure “cold wallet”, outside the internet (…) It also does not use an extra layer of security known as a multi-signature system.”

“It’s been long said that cryptocurrencies are a solid system but cryptocurrency exchanges are not,” said Makoto Sakuma, research fellow at NLI Research Institute to Reuters. “This incident showed that the problem has not been solved at all. If Coincheck screws up its crisis management, that could deal a blow to the current cryptocurrency fever.”

Following the incident, the price of NEM fell from $1.01 to $0.78, though it “reached $0.97 by Monday” suggested CoinMarketCap.

The incident highlights the volatile state of handling cryptocurrencies and underscores security and regulatory concerns around this latest global boon. “In 2014, Tokyo-based Mt. Gox, which once handled 80 percent of the world’s bitcoin trades, filed for bankruptcy after losing around half a billion dollars worth of bitcoins. More recently, South Korean cryptocurrency exchange Youbit last month shut down and filed for bankruptcy after being hacked twice last year,” states a report in CNBC.

Alphabet Inc. launches Chronicle to boost cybersecurity and data intelligence

Alphabet

Alphabet Inc., the parent company of Google, launched a new subsidiary by the name of Chronicle on 24th January 2018. Launched as a cybersecurity intelligence and analytics platform, Chronicle aims to filter and analyze constantly accumulating data for cyber threats applying Artificial Intelligence. Although much has not been revealed about how Chronicle will work, it aims to lessen cyber-leak by scanning logs of old data.

Stephen Gillett, the CEO of Chronicle, founded the company in 2016 with Google’s cybersecurity pioneers Shapor Naghibzadeh and Mike Wiacek. Stephen elaborated on the new venture in his blog post, “Now we’re ready to unveil our new company, which will have two parts: a new cybersecurity intelligence and analytics platform that we hope can help enterprises better manage and understand their own security-related data; and VirusTotal, a malware intelligence service acquired by Google in 2012 which will continue to operate as it has for the last few years.”

Stephen has been with Google since 2015, contributing his skills to Moonshots at Google (X)out of which Chronicle branched, and GV or Google Ventures. Stephen has also served as the COO at Symantec and CIO at Starbucks Corp.

Chronicle targets making security signals easily recognizable, thus increasing the data processing speed. The aim of the firm is to speed up data search and analysis procedure, add more data storage space for customers while reducing costs and evaluating more data in less time. The startup is still expanding its team, while getting guidance from some Fortune 500 companies. Although a part of Alphabet, Chronicle has its own contracts and data policies. The company has already launched a preview version of its cybersecurity program, currently being tested by some Fortune 500 companies.

Facebook acquires Confirm.io for robust authentication process

Facebook Data leak, Facebook bans cyber mercenary

In its latest move to become a distinctly secure social media platform, Facebook acquired Boston based Confirm.io, its 66th acquisition since 2005. The startup creates software to authenticate government-sanctioned IDs by third parties, even including biometric interface. Founded in 2015, Confirm.io has clients from finance, healthcare, insurance, retailer and other sectors. The company has already raised $4 million since its establishment.

The company announced the takeover on its website. “When we launched Confirm, our mission was to become the market’s trusted identity origination platform for which other multifactor verification services can build upon. Now, we’re ready to take the next step on our journey with Facebook. However, in the meantime this means all of our current digital ID authentication software offerings will be wound down,” the message on the website read.

Facebook’s last acquisition was in October 2017 when it bought tbh, an anonymous social media app accessible in US, intended for high school students. It is being assumed that the acquisition of Confirm.io is a part of the social media giant’s plan for making data and account recovery more secured and easier through expedited identification, with the probability of facial recognition functionality too. Facebook has been experimenting with technologies to make accounts safer and enhance the authentication process when users are locked out of their accounts or during cyber breaches.

In an interview with an online tech news publisher, Facebook commented, “We are excited to welcome the Confirm team to Facebook. Their technology and expertise will support our ongoing efforts to keep our community safe.” It is a complete takeover entailing shutting down of services for Confirm.io, as they merge with Facebook. The amount for the takeover has not been revealed.

Data of Malaysian organ donors disclosed in latest breach

Malaysia

The memory of the last data leak, which compromised information of more than 45 million mobile phone subscribers, is still fresh in the minds of Malaysian citizens and now they have been hit by a new blow. This time it is more than 200,000 organ donors and their next of kin who have been exposed. Although the Malaysian Communications and Multimedia Commission (MCMC), responsible for Internet regulation in the country, has not commented on the incident so far, it is being considered that the breach was from a central database.

The leaked data reveals the donors’ names, their identification numbers, nationalities, race, addresses and phone numbers.  A popular Malaysian Internet forum and technology magazine, which revealed the news, mentioned in its post that with the inclusion of the information on the donors’ kins, the leaked records amount to nearly 440,000. Interestingly, this data has been available for over a year now. The police suspects that the instigators of both the data leaks are the same. The Inspector General of Royal Malaysia, Mohammad Fuzi Harun commented, “We find it suspicious, and we will be in contact with the website administrators regarding this case. The case is being investigated by the Commercial Criminal Investigation Department.”

Although Malaysia ranks third in the Global Cybersecurity Index, these latest cyber breaches indicate there’s still space for improvement in their cybersecurity legislation. As pointed out in a survey, ASEAN are still not spending enough in the cybersecurity areas. Although the latest attack caused lesser damage than the one in November, the criticality of the situation cannot be undermined. With the data still available online, the degree of risk only rises with the passage of time.

 

Amazon acquires cybersecurity startup Sqrrl

Amazon

Amazon Web Services acquired Sqrrl Data Inc., a cybersecurity startup. The Massachusetts firm established in 2012 owes its origins to Unites States Intelligence Community and National Security Agency. It has earned a name for itself in the software markets for big data and cybersecurity. The deal is said to be closed above $40 million, however, the actual price hasn’t been confirmed yet.

Mark Terenzoni, CEO of Sqrrl, announced on the website, “We’re thrilled to share that Sqrrl has been acquired by Amazon. We will be joining the Amazon Web Services family, and we’re looking forward to working together on customer offerings for the future. For now, it is business as usual at Sqrrl. We will continue to work with customers to provide advanced threat hunting capabilities. And, over time, we’ll work with AWS to do even more on your behalf. Thank you for your support. We really appreciate the trust customers have put into Sqrrl over the past five years, and we are excited about the next phase of our journey.”

Sqrrl specializes in mapping, analysis, and quick discovering cyber-threats in data. The startup raised nearly $12 million in June 2017 from Accomplice, Spring Lake Equity Partners, Matrix Partners, and Rally Ventures. After taking over Blink in December 2017, a firm manufacturing connected devices such as cameras and video, this is Amazon’s second take over, assumingly to strengthen its cybersecurity measures.

ASEAN is not spending enough on cybersecurity: A.T. Kearney

ASEAN

A recent report by A.T. Kearney, a global management consulting firm, suggests that ASEAN should spend nearly $171 billion on cybersecurity by 2025, in order to safeguard the bloc’s budding digital economy. The report which was published to elaborate on the opportunities of ASEAN in becoming a digital economy gave an insight into some important cybersecurity aspects. The report advises that the bloc needs to create a unified agency to thwart off cybercrimes.

In its comparative analysis with the European Union, the consulting firm pointed out that on the grounds of consumer protection, primarily for data privacy and cybersecurity, EU has a common privacy initiative for data protection and cybersecurity, making it an important part of regional priority. Only Malaysia, Singapore, and Philippines have privacy laws in place in the ASEAN bloc so far.

In an interview to a leading daily, Gareth Pereira, principal of media and technology practice, A.T.Kearney, said, “The region’s nascent cybersecurity industry faces a shortage of home-grown capabilities and expertise, fragmented products and solutions and few comprehensive solution providers. Multiple vendor relationships and product deployments are creating operational complexity and increasing vulnerability in some cases.”

In a time where cybersecurity threats call for immediate attention, ASEAN underspends on the same while planning to become a thorough digital economy. As per the report, the region needs to increase its GDP expenditure on cybersecurity by 0.35-0.61% between 2017 and 2025.