Home Blog Page 379

Australia’s small businesses division launches guide for best practices

In view of the increasing cybersecurity attacks on small businesses, the Australian Small Business and Family Enterprise Ombudsman has launched a cybersecurity guide, to aid small businesses in intercepting and blocking cyber-breaches. Most of these businesses are ignorant of the intensity of these attacks, relying on elementary firewalls as security measures. The guide was published after intensive analysis depicting, sixty percent small-scale trades shut down within six months of a cyber-attack. The study also showed that the Australian economy lost more than $1bn every year to cybercrime.

“It would be an incredible shame if small businesses shut themselves out of the online market because of fears about cybersecurity. There are risks attached to most activities, even crossing the road. Taking sensible precautions broadens opportunities and heightens the rewards,” said Ombudsman Kate Cornell.

The guide contains some easy recognition and prevention measures to educate business owners, such as use of two-step authentication, limit access, communicating safe practices and restore backups among others.  The guide briefly describes the variations of phishing and cyberattack methods that one needs to guard themselves against. The manual also advises users to speak to trusted advisers and communicate about safe Internet practices, thus spreading a wise word and educating each other.

Changing Role of the CISO

cybersecurity professionals

By Grant Bourzikas, CISO, McAfee

With the growth of digital world, we have seen growth in cyberthreats. These range from the annoying to the downright catastrophic. And as these threats evolve and permutate, we have also seen the evolution of a formerly overlooked player: the Chief Information Security Officer, or CISO.

Not only is the CISO’s role changing, but so is his/her relationship to the organization they work in. Where once many reported to the Chief Information Officer (CIO), many now report directly to the CEO or the Board. In their new role, the CISOs also need new skills.

The CISO was first brought into the modern business organization to monitor and analyze potential security risks for the company. Traditionally, CISOs have come more from the technical side, and perhaps did not have to understand the whole business. Leadership and communication or an in-depth business background may not have been a job requirement.

But this is changing.

With the advent of some high-profile hacks (last summer’s Equifax debacle comes to mind — the CEO lost his job), it’s fair to say the top of C-Suite is seeing the importance of cybersecurity.  The challenge for the modern CISO is to discuss the business issues causing the security challenges (versus just talking technology).  When CISOs bring ideas to the executive table that are put in terms of choices and business integration, it is more likely that issues will be addressed and remediated.

How do the roles of the CIO and CISO differ? They are both involved with Information Technology, but from different angles. The CIO’s charter is to ensure information is available to run the business; the CISO’s charter is to ensure security without affecting availability of business services. This could be an adversarial relationship, but approached properly – from a holistic viewpoint – it can work well.

Every organization handles security differently, based on its needs and internal structure. The CIO has traditionally worked on the management side of a company and is internally and operationally focused. CISOs by their nature are outwardly-focused. In this case, silos can be fatal to a company. Also, since the CISO often reported to the CIO, they weren’t always seen as peers. One perception is that CIOs are seasoned veterans and leaders, and CISOs are younger and more specialized. But as reality changes, neither should be put in a box.

The CISO’s role has become more elevated because of the importance of data management in the Digital Age. We see that without cybersecurity, a company can be seriously compromised, both monetarily and in reputation. For many companies, information and security are not part of the business; they are the business.

The CISO has also become the go-to person when working with cybersecurity vendors. Since there are over 1,000 cybersecurity companies of varying sizes and scope, the role frequently means getting different flavors of software to work together. Once that is accomplished, the CISO also needs to communicate what they are doing to the rank and file of an organization.

As I travel the U.S. and the world, I am frequently asked along on sales calls, and I am often asked questions about strategy, Board of Directors reporting, metrics, Security Operations, and product delivery. However, when I address these topics, I stress that CISOs must look at the business as an organic whole versus focusing on technology. If you force just on technical choices, one might look at cybersecurity as a cost. The right approach to focus on the business and managing the environment, as well communicating how security is important to company success.

In sum, today’s CISO has an important and expanded role in managing a company’s security heath. They should a have a relationship with both the CEO and the Board, so that organizations can accurately assess their threat landscape. A good CISO is also a good leader and communicator, but someone who can influence the organization to be able to drive towards the outcome of ensuring security and availability of systems. In short, the role has evolved from specific function to a vital part of a company’s management.

What’s your view? I’d like to hear it.


This article was originally published on McAfee’s website (https://securingtomorrow.mcafee.com/business/changing-role-ciso/) and is published on cisomag.com with their permission.

Yet Again, North Korea Accused of Stealing Cryptocurrencies

Sardonic, BitMart

They did it in the past and they are doing it again. There’s a good possibility of North Korea burrowing through accounts and scooping away cryptocurrencies. The monster has matured, it is not into data theft anymore, it is now robbing money. This is not for the first time that North Korea has broken-in into a cryptocurrency vault, though now their intentions seem more evil, with the intensification of their nuclear missile program, leading to the imposition of new sanctions. While investors have shown considerable interest in digital currencies in the last few years, the cyber-attack threat from this country is a clear indication of fast approaching thunder and storm.

The scandalous Lazarus Group, allegedly backed by North Korea is the prime suspect in these cyber-muggings. Andariel, one of the ill-famed tributaries of the country has already swindled 70 Monero from a South Korean cyrptocurrency exchange in 2017. While South Korea is in the process of passing some strong cybersecurity laws as combat measures, the danger still hovers. North Korea already stands accused of the WannaCry ransomware attack, and as in most cases the group has dismissed the claims by United States.

Through the years, North Korea has been linked to series of cyber-attacks, either to display its cyber prowess or just to fund their activities. One of the most brazen attacks occurred in February 2016 when hackers tried to steal $101 million from a Bangladesh Central bank account at the New York Federal Reserve and move it to Sri Lanka. Only a spelling error caused the banks to realize they were under attack. Un’s minions got away with nearly $81 million––most of which is yet to be recovered. “Security researchers later established that similar tactics had been used to attack banks in Ecuador, the Philippines, and Vietnam. But that was only part of the picture: Researchers at cybersecurity firm Kaspersky Lab said in April Lazarus also attacked financial institutions in Costa Rica, Ethiopia, Gabon, India, Indonesia, Iraq, Kenya, Malaysia, Nigeria, Poland, Taiwan, Thailand, and Uruguay,” according to CNN. “The Lazarus hackers carefully routed their signal through France, South Korea, and Taiwan to set up their attack server, according to Kaspersky. But researchers noticed one mistake: A connection that briefly came from North Korea.”

Indeed, we are on the verge of a cyber-war but the question is, are we better prepared or is our enemy better equipped?

John McAfee’s Twitter Account Breached

CISO MAG Desk: John McAfee recently declared that his twitter account was hacked and used to endorse some minor-league cryptocurrencies. Although, he claimed to have enabled the two-factor authentication, his mobile phone was jeopardized leading to the cyber attack on his social media account.

 

The former presidential candidate said that he got the first indication of his phone being hacked when he turned it on, to see a dubious error message on the screen. In an interview to BBC John mentioned, “I knew at that point that my phone had been compromised. I was on a boat at the time and could not go to my carrier (AT&T) to have the issue corrected. All that the hacker did was compromise my Twitter account. It could have been worse.” Considering that only the Twitter account of the former owner of one of the world’s first anti-virus companies was attacked, led to a lot of witticism from different corners.

While cybersecurity experts are assessing the perils of AI empowered cyber breaches, it is indeed worrisome that the frequency of break-ins have increased and the targets can be any avenues, irrespective of their influence, importance or seriousness. Although John McAfee’s account hacking is debatable, but the rapid surge in cyber attacks has led to reconsidering the present cybersecurity guidelines and methodologies.

Cyber-Break-In in EtherDelta – Are Your Funds Crypto-safe?

The holiday plans seem to have gone awry for the popular cryptocurrency exchange EtherDelta, as it announced the possibility of its DNS server being hacked on the Wednesday of December 20, 2017. Listed amongst the top trading platforms of the world, the decentralized exchange could do little than warn people by making announcements on social media.

Its tweet declaring the likelihood of the attack and prohibition to use the website, sent a wave of fret to its customers, once again raising eyebrows on the rising instances of compromises on cryptocurrency and exchange platforms.


Although, an intelligent move to keep the customers informed and adopt safety measures, EtherDelta could only make a comeback two days later. As a damage control move, the company quickly floated out a maneuver for their customers to help them distinguish any future phishing attempts.


Reports suggested that the hackers whisked away with around 308ETH tokens, amounting to nearly $270,000 by asking the customers to redirect to a phony scam site.

However, it has brought to question the vulnerability of cryptocurrencies and how it has been subjected to frequent cyber-larcenies. Recently, YouBit, a South Korean cryptocurrency exchange called quits on December 20, 2017, after being targeted by cyber-attacks in a gap of less than eight months. YouBit had lost 4,000 bitcoins during a breach in April.

With South Korea announcing new regulations on cryptocurrency trading, it seems that new can of worms will be opening for these decentralized exchanges and cryptocurrency trading platforms.

To CISOs, with love! The epitaph of endpoints

endpoint protection

Contributed by Chris Roberts, Chief Security Architect, Acalvio Technologies

Open letter, let’s see. I like the CISO opening, it’s truthful and it’s part of the spark for this. I’ve been vocal about endpoint being the mythical silver bullet for a while. Too many companies still rely upon it as the be-all/end-all for security and they typically can’t implement it all correctly, or monitor it. More and more organizations are selling the utopia of “secure endpoint and all will be forgiven.”  This is a challenge to that thinking AND hopefully somewhat of a mindset change for people. We might as well start with the worst-case scenario and go from there, but I encourage you to read to the end as there IS hope! So, without further ado, here are my initial feelings about end point protection in blunt bullet points:

  • A hiding to nothing?
  • A waste of time and resources?
  • Snake oil in a slick marketing campaign?
  • All flash and no go?

It’s arguable that the endpoint has already been compromised. Devices are still one of the core points of access into most organizations, therefore, don’t bother with endpoint security, give up, go home and have a good cup of tea. That’s what I really want to say BUT there must be some hope, some ray of light, otherwise why would we still have a vibrant and active commercial sector doing all they can to stave of what seems to be the inevitable onslaught of attacks launched at the very systems we strive to protect?

So, lets take a step back and look at what is working, what’s not, and what we can do for the future. After all, there is little we can do to secure the actual user who still, after 25 years of InfoSec, wants to click on anything that comes into vision or is happy to jot down their passwords on post-it notes and leave them all over the office like confetti.

As an attacker, my goal is quite simple: get you or your computer to do something against your/its will, against (hopefully) company policy and against your best interest. To do this I need to facilitate a behavior change or get lucky and hit the systems that are not patched or protected (too often this is the case, but for this exercise we’ll take the utopian view that you have ALL your protection active.).

Now, before we go on, let’s take a quick look at what you and your endpoint have to have to be protected in today’s world:

  • Antivirus
  • Antimalware or whatever that’s called these days
  • Heuristic detection capabilities
  • HIDS (Host Intrusion Detection)
  • Network behavior analytics
  • UBA (User Behavior Analytics)
  • OS patches
  • Application patches
  • Web browser patches
  • We browser all protected too, meaning no flash, popups, redirects, Java, etc. Basically plain, vanilla text, and nothing else!
  • Web browser outbound analysis, DNS validation, and ensuring you ARE going to the right cloud
  • Application containerization
  • Encryption
  • Email filtering
  • Email anti-malware, anti-anything-useful removal of all attachments enabled
  • NOT admin on your local machine
  • You, yes, you the squishy bag of flesh – you’d better have done your regular (monthly?) security training and know NOT to click sh*t, open attachments, give out your passwords, or anything else.

So, a nice tidy list, easy to implement AND keep up-to-date daily (hourly would be preferable, but we don’t want to completely saturate the network with updates).

And we didn’t even get to the good stuff – the technology that is starting to make a difference, like the intelligent systems that are now being deployed within enterprises to facilitate the deceptive technologies, the preventative and proactive systems that monitor and watch traffic, logs, systems for behavioral anomalies and/or the logging systems surrounding them.

So, now we have all of this in place: we have the reactive, the proactive, and the preventative systems fired up, ready to protect us –and hopefully an army of staff behind the scenes watching, monitoring, managing, and generally causing a nuisance to the business by demanding security be considered at every corner. They’ll be standing by eagerly watching all the logs ALL the time for that one time the bad guy tries to get lucky.

Hopefully this sounds familiar to you all. Hopefully this situation is how you are operating, how you are protecting your users – you have not only their work systems wrapped up in an InfoSec condom but also all their portable devices, their phones, watches, wearables, home systems, kids’ systems, doorbells, Nests, and anything else that might somehow break into them to get to you. After all, you are the CISO and you have your hands firmly around all of this – right?

Ok, now reality has set in, you’ve grabbed yourself a good glass of something Scottish and peaty, and realized that this task is something more than slamming another product into the stack. It’s more than relying upon the latest vendor presentation and if you have your wits about you, it’s going to have a positive impact on that maturity model the last penetration test helped put together so you can finally track changes, risks, and report up to the board how you are being successful. You have looked at the statistics and realized that endpoint protection can be a useful tool in the defense-in-depth model as long as it’s implemented with other controls and procedures. Lets take a look at some of those:

  1. Users will still click sh*t even with protection in place. Protection does its best to mitigate, therefore, let’s train the users more effectively and combine some user grey matter with whatever brand of machine learning employed by the endpoint.
  2. Users will be users – some won’t listen and will do their best to avoid the protections we put in place. Therefore, both evaluate what is necessary and required against a good risk model to ensure both the business and users can actually be productive and you can protect all the necessary assets. On top of this add in a set of tasks to ensure exceptions are handled correctly and documented accordingly and when the user doesn’t listen for the third time, you have disciplinary processes in place to deal with them accordingly.
  3. Not all endpoint users are to be treated equally. Therefore, remove everyone’s ability to administer their own systems and provide the required support structure and polices to deal with the special snowflakes that need and can justify the elevated privileges.
  4. Endpoint can’t work effectively in a vacuum. Therefore, support it with a well-architected log management system that is also bolstered by more proactive, predictive, and preventative measures. Look beyond the traditional IDS/IPS stack towards the deceptive and other technologies that exist to complement the endpoints and other security systems. Chose wisely and don’t be fooled by the thousands of vendors that can solve all your problems.
  5. Be aware that the attackers focused on your environment already have the upper hand; they have the time and resources to research not only you and your enterprise but also your people and technologies. The less you put out there about what is protecting you, the less you let your vendors and partners talk about how they’ve protected you in a public forum, the better chance you have of slowing them down. You won’t stop them, but you will buy yourself valuable time. Combine this with an internal training focused on data, intelligence gathering, and other social engineering tactics that the users can use both in the work environment and at home and you’ll have added another layer to what is traditionally the weakest link –us, the humans, the employees, the people at the keyboards.

Revisiting those opening statements, let’s add a little more context:

  • A hiding to nothing?
    • Relying on basic antivirus and some basic web browsing heuristics is not going to protect you. If you are going to look at endpoint, then you need to focus on it, work through what you need for your enterprise, and approach it as carefully as you would a major overhaul of an ERP or other enterprise level system. It’s complex and requires both technical and human resources to be completely effective. Treat it with the necessary respect and you will have built yourself another effective layer of defense – treat it as a quick software purchase and you will find yourself living a lie, believing you are protected when you are not.
  • A waste of time and resources?
    • No, but as with any product that is going to be integrated into an environment, careful planning and implementation will be key. Simply buying the software or solution and not also getting the professional services and training for your teams or ensuring adequate coverage for the solution is going to end in failure and another product gathering dust on the shelf of useless ideas and wasted money.
  • Snake oil in a well wrapped marketing campaign?
    • Yes, there are a number of vendors who wrap their solution in artificial intelligence, threat analytics, and other verbiage designed to entice and blind you to the simple fact that they’ve spent more on the marketing than the actual product. Some of these vendors are well known names, so do your due diligence, trust the team you employ to dissect the entire thing, and involve the end users in the selection process. Worst case call me – I’ll help!
  • All flash and no go?
    • When they’ve spent more developing the GUI than the engine behind the tools, when the CLI has more horsepower than the flashy graphics, and the executive report has more colors to choose from than the latest car brochure, back away slowly and look for a vendor that allows you to talk with the geeks, where they are proud of what they have built, and they are willing to go geek-to-geek with your team at any point. Chose someone who actually is willing to work with you and not simply integrate you into this quarter’s sales numbers.

Hopefully this has been helpful, insightful, and a little provocative. As a researcher and security architect, I’m in a unique position to be able to both assess what’s out there, break it, and implement it. In my experience, there ARE good tools out there the challenge sometimes is looking through the FUD to see the diamonds (sometimes still in the rough).

Good luck and thanks for reading to the end.

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

45% companies don’t have cybersecurity leader: Study

Research Finds Increase in Botnet and Exploit Activity in Q2 2020

A recent survey conducted by a software industrial company indicated that a number of industrial companies are not taking cybersecurity seriously enough. The “Putting Industrial Cyber Security at the Top of the CEO Agenda” survey, that was conducted by Honeywell in collaboration with LNS Research, included responses from 130 strategic decision makers from industrial companies across North America, Europe, and other parts of the globe.

Forty-five percent of the respondents agreed to the fact that their organization lacks a reliable enterprise leader for cybersecurity. Forty percent have a chief of cybersecurity while 15% plan to get a cybersecurity incharge within the next year. When it comes to the companies’ manufacturing plant, only 35% of the organizations have an established role for cybersecurity.

The survey also suggested the hesitation of the industrial companies in adopting the best practices for cybersecurity. One-fifth of the respondents admitted that they do not conduct regular risk assessments while 25% don’t carry out regular penetration testing on their firewalls. “These results may not be all that surprising, considering some of the newer solution providers are offering passive monitoring for the industrial control systems and networks; the benefits are clear and the upfront costs have been dramatically slashed,” the survey said.

The study also made some suggestions to enable industrial organization capture the value of next-generation technology. “Use an Operational Excellence model of people, process, and technology capabilities to enable Digital Transformation and build industrial cybersecurity capabilities into the model. Focus on best practices adoption – across people, process, and especially technology capabilities,” said Matthew Littlefield, President and Principal Analyst, LNS Research.

The report is available at: https://www.honeywellprocess.com/en-US/online_campaigns/lns-cyber-report/Pages/Honeywell-LNS-Study_PuttingIndustrialCyberSecurityattheTopCEOAgenda.pdf

Survey: Understanding Trends and the Cybersecurity Skills Gap

Skill Gap

EC-Council recently surveyed its pool of Certified CISOs to discover what is important to information security executives in four categories: hiring their teams, current and past employment, looking for a job, and career success.

First, the survey collected basic geographic and industry demographic data, which is important to keep in mind when interpreting the results from other categories. Represented in the survey were the following regions:

  • South America: 5.6%
  • Europe: 16.7%
  • Asia: 16.7%
  • Middle East: 16.8%
  • USA: 38.9%
  • Africa: 5.6%

As for industries represented in the survey, there was quite a diverse range:

  • Banking, finance, insurance: 33.3%
  • Consultancy or business services: 11.1%
  • Government, public service, military: 22.2%
  • IT: 11.1%
  • Manufacturing or construction: 11.1%
  • Transportation, utility, telecommunication: 11.1%

The last area of demographics collected was on the CCISOs current level within their companies:

What level is your current position?

  • C-Level, VP, SVP, etc.: 23.5%
  • Consultant: 29.4%
  • Director: 35.3%
  • Manager: 11.8%

The first section of questions dealt with how CCISOs hire new employees for their teams. This section as important because it highlights challenges that managers, directors, and C-Level executives have when it comes to filling their teams. EC-Council was interested in determining where these leaders are feeling the known information security skills gap the most. The results point to some interesting conclusions. First, the leaders were asked how many job openings on their teams they are currently looking to fill. Over 57% of them reported they had between 1-5 job openings currently available. Another 31% have over 5 job opportunities with one survey respondent reporting 300 jobs needing SOC analysts!

How many information security positions are you currently looking to fill with new hires?

  • Zero: 5.3%
  • 1 to 3: 47.4%
  • 3 to 5: 10.5%
  • I don’t make hiring decisions: 5.3%
  • Over 5: 31.6%

The next question asked how many jobs had already been filled in the current year, finding that most leaders had only filled between 1 and 3 jobs.

How many information security positions have you filled in the last year?

  • Zero: 6.3%
  • 1 to 3: 50.0%
  • 3 to 5: 6.3%
  • Over 5: 37.5%

When asked which jobs are the hardest to fill with qualified candidates, the CCISO reported a range of problem areas, which the most popular job being Security Analyst with 31.3% of respondents pegging it as the most difficult to fill.

What position is the most difficult to hire due to a lack of skilled candidates?

  • CISO, Director of Information Security, CSO: 18.8%
  • Computer Forensics Investigator or Forensic Analyst: 12.5%
  • Consultant: 6.3%
  • Information Security Manager: 6.3%
  • Penetration Tester: 18.8%
  • Security Analyst: 31.3%
  • Security Architect: 6.3%

The next subsection of the survey dealt with what is most important to infosec leaders when deciding whom to hire. The results point to many different facets of a resume all being crucial to landing an information security job. The most important, however, is finding a good personality fit for the culture or the team, which 81.3% of CCISOs rating that quality as either extremely or very important. Limiting hires to people with specific personality traits can be troubling, as studies have shown managers tend to hire people with their own personality traits, leading to teams without diversity in point of view or other areas. Conversely, it’s easy to understand why looking for a good fit for a team can lead to better cohesion. As long as hiring practices are fair and openminded, hiring based on cultural fit can be a good option.

The next highest rated characteristic for a job-hopeful to have is experience that exactly matches the job, with 62.5% reporting this as either extremely or very important. Requiring experience that exactly matches the job has been flagged as problematic by industry experts over the years for the simple reason that it is difficult to gain experience in a particular role when all the jobs available for that role require previous experience exactly matching what the employee will be doing. This means that companies are trying to lure employees to make lateral moves with better salaries and benefits. No security leader has an endless budget, so it might make better fiscal sense to find new hires that show potential or whose previous roles and certifications make them good candidates to grow into new roles, for potentially smaller salaries.

However, it is easy to understand why leaders might want turnkey solutions to their problems. It takes time to train new employees, even those who have the exact experience needed for a new role. When an employee both has to learn new skills as well as a new company, independence in their work will take significantly longer. This may point to an opportunity in the industry for education providers to offer customized solutions to help teams overcome this obstacle and hire for potential rather than on specific experience.

Other top finishers for candidate qualifications were relevant certifications and years of experience, each with 56.3% of respondents finding those qualities extremely or very important.

How important is experience that exactly matches the job in hiring decisions?

  • Extremely important: 43.8%
  • Important: 37.5%
  • Very important: 18.8%

How important is personality fit with culture/team when making hiring decisions?

  • Extremely important: 50.0%
  • Important: 12.5%
  • Very important: 31.3%
  • Somewhat important: 6.3%

How important are relevant industry certifications when making hiring decisions?

  • Extremely important: 12.5%
  • Important: 31.3%
  • Very important: 43.8%
  • Somewhat important: 12.5%

How important is years of experience when making hiring decisions?

  • Extremely important: 12.5%
  • Important: 18.8%
  • Very Important: 43.8%
  • Somewhat Important: 25.0%

The second main section of the survey dealt with the current and past employment and salaries of the leaders themselves.

When asked how long they had been in their current role, most respondents reported only 1-5 years of tenure at their current organization. This fits the common wisdom in the industry that CISOs tend to change jobs every 18 months. It was interesting, however, to see that over 23% of CCISOs have actually been in their jobs for over 10 years, showing the maturity of the information security market.

How important is years of experience when making hiring decisions?

  • Less than one year: 11.8%
  • 1 – 5 years: 41.2%
  • Over 5 years: 23.5%
  • Over 10 years: 23.5%

The next question dealt with salaries. All salaries have been converted to US dollars for the sake of comparison. Very few CCISOs earn less than $75,000 per year, with most making between $150,001 – $200,000. EC-Council expects salaries to grow for security leaders every year that they continue this survey.

In what range is your current salary in USD?

  • Less than $75,000: 6.3%
  • $75,001 – $100,000: 6.3%
  • $100,001 – $150,000: 31.3%
  • $150,001 – $200,000: 37.5%
  • Over $200,000: 18.8%

The third section of the survey dealt with how CCISOs go about finding new jobs. Asking about a number of aspects of a new job, the survey found the CCISOs value the culture of an organization and the compensation package on offer, with 82.4% of respondents rating these things as extremely or very important. In second place was having an alignment in the vision for the security program with the organization, with 76.5% of CCISOs finding this extremely or very important. Coming in just behind alignment of security vision was the work to life balance offered by the organization with 75% of the survey participants rating it as extremely or very important. The rest of the results can be found below:

When looking for a new job, how important is an adequate budget for security program?

  • Important: 29.4%
  • Very important: 41.2%
  • Extremely important: 29.4%

When looking for a new job, how important is alignment in vision for security?

  • Important: 23.5%
  • Very important: 29.4%
  • Extremely important: 47.1%

When looking for a new job, how important is Culture of organization?

  • Important: 17.6%
  • Very important: 35.3%
  • Extremely important: 47.1%

When looking for a new job, how important is the number of direct reports you will have?

  • Not at all important: 5.9%
  • Somewhat important: 23.5%
  • Important: 52.9%
  • Very important: 5.9%
  • Extremely important: 11.8%

When looking for a new job, how important is the prestige of company/organization?

  • Not at all important: 6.3%
  • Somewhat important: 18.8%
  • Important: 25.0%
  • Very important: 18.8%
  • Extremely important: 31.3%

When looking for a new job, how important is compensation including salary, signing bonus, stock options, etc.?

  • Important: 17.6%
  • Very important: 17.6%
  • Extremely important: 64.7%

When looking for a new job, how important is the title?

  • Somewhat important: 20.0%
  • Important: 20.0%
  • Very important: 46.7%
  • Extremely important: 13.3%

When looking for a new job, how important is to whom you will report (CIO, CEO, CFO, etc.)?

  • Somewhat important: 5.9%
  • Important: 23.5%
  • Very important: 35.3%
  • Extremely important: 35.3%

When looking for a new job, how important is work/life balance?

  • Somewhat important: 6.3%
  • Important: 18.8%
  • Very important: 43.8%
  • Extremely important: 31.3%

When looking for a new job, how important is the opportunity for advancement?

  • Not at all important: 10.5%
  • Somewhat important: 5.3%
  • Important: 26.3%
  • Very important: 31.6%
  • Extremely important: 26.3%

The final section of the survey asked CCISOs about the factors that contributed the most to their success. The overwhelming winner for this category was networking. 83.3% of respondents said that networking was very or extremely important to the success of their careers. It’s easy to understand why there are so many information security conferences around the world with results like these. Cultivating relationships, sharing information, and increasing their spheres of influence are all things that can be done at conferences. The second key to CCISOs’ success is education, with 58.8% of respondents saying their college or university educations have been extremely or very important to their success. The rest of the categories can be found below:

How important has earning industry certifications been to the success of your career?

  • Not at all important: 27.8%
  • Somewhat important: 5.6%
  • Important: 27.8%
  • Very important: 27.8%
  • Extremely important: 11.1%

How important has college/university education been to the success of your career?

  • Not at all important: 17.6%
  • Somewhat important: 5.9%
  • Important: 17.6%
  • Very important: 35.3%
  • Extremely important: 23.5%

How important has effective networking been to the success of your career?

  • Not at all important: 5.6%
  • Important: 11.1%
  • Very important: 50.0%
  • Extremely important: 33.3%

How important have executive recruiting services been to the success of your career?

  • Not at all important: 23.5%
  • Somewhat important: 35.3%
  • Important: 23.5%
  • Very important: 11.8%
  • Extremely important: 5.9%

How important have executive recruiting services been to the success of your career?

  • Not at all important: 23.5%
  • Somewhat important: 17.6%
  • Important: 64.7%
  • Very important: 11.8%
  • Extremely important: 5.9%

How important has mentorship been to the success of your career?

  • Not at all important: 5.6%
  • Somewhat important: 22.2%
  • Important: 22.2%
  • Very important: 33.3%
  • Extremely important: 16.7%

Conclusion

The skill gap in the cybersecurity industry spans all levels, from CISOs to security analysts. It appears that the shortage of skilled professionals is not a problem that will be solved in the conceivable future. Most CISOs have several job openings yet to be filled and CISOs and the others involved in the recruiting process are looking for prospects with relevant certifications and experience. A major hurdle in the recruitment process is finding the right fit both with culture, personality, and experience that matches the job.

Another key finding was that most infosec professionals were holding onto their seats for years, with several CCISOs serving the same position for almost a decade. The reasons cited for this were work culture, pay scale, the organization’s approach towards security, and worklife balance. For most infosec experts, networking is one of the key components of their success. Several respondents also felt  mentorship and earning industry certifications were crucial for success.

Automation and Orchestration: The Big Picture

Automation and Orchestration

This whitepaper is contributed by Tari Schreider, Chief Cybersecurity Strategist and Author, Prescriptive Risk Solutions, LLC

Today, CISOs have a dizzying array of cybersecurity technologies offering the promise of a securer tomorrow. Each technology performs its appointed mission of protecting assets and information with aplomb. Layer by layer, one security technology is stacked upon another hoping to achieve defense in depth. However, the bad actors somehow still find a way around our defenses. No wonder CISOs have trouble asking for funding for the next galactic malware cure. CFOs may not say it, but they are thinking it, “if you cannot make what we have work together to reduce our risk, we’re just throwing good money after bad.”

If there were only way to leverage our growing complexity of desperate cybersecurity technologies and force multiply our limited SecOps personnel with machine agility and speed. Well there is my fine CISO friend, there is. The age of automation and orchestration is dawning. Solutions now exist that allow you to automate your cybersecurity playbooks. With an extensible automation and orchestration platform, you can programmatically curate from your inventory of countermeasures your response to various threat scenarios.

Market Adoption

You may have already seen their booths at RSA or received marketing grams from various security automation and orchestration vendors and wondered does this thing have legs? To answer in a word, yes. MarketandMarkets Research published a report in 2016 forecasting the security orchestration market will grow from $826.1 Million in 2016 to $1.682.4 Billion by 2021, at a Compound Annual Growth Rate (CAGR) of 15.3%.

Some companies jumped on the security automation and orchestration train early by announcing integration partnerships.

An example of seemingly early adoption would be the Tufin Orchestration Suite integrating with Cisco Firewalls. These partnerships were generally a space holder to allow vendors to figure this market out and create products that actually live up to the promise of security automation and orchestration.

The field of players is becoming crowded and I expect an aggressive 2017 M&A season to follow on previous year’s activity. In 2016, we witnessed IBM acquiring Resilient Systems and FireEye acquiring Invotas as well Cisco Systems acquiring Tail-F in 2014.

Key Players

At my last count, there were over thirty providers of products claiming placement within the security automation and orchestration market. If you attended RSA in February, you should have noticed these products were all the rage. Some claim they are a full automation and orchestration suite while others are carving out narrow niches in areas like policy orchestration or automated incident response.

Below are the ones creating the most chatter:

  • Bradford Networks – Network Sentry
  • Cisco Systems – Process Orchestrator
  • Cyberbit SOC 3D
  • CyberSponse Inc.
  • Demisto
  • DFLabs – IncMan
  • Exabeam Security Intelligence Platform
  • FireEye, Inc. – Security Orchestrator
  • Gemini Atlas Platform
  • Hexadite AIRS
  • IBM Corporation – Resilient Incident Response Platform
  • Intel – Open Security Controller
  • Komand Security Orchestration & Automation Platform
  • Phantom Cyber Corporation
  • Resolve Systems
  • Swimlane LLC
  • ThreatNexus Orchestration Engine
  • Tufin Orchestration Suite

When looking at these products you will need to recognize that half of them will no longer either be in business or operate as an independent company within the next two years. You should also note that this is an arms race with feature advantage changing sides often.

I have not mentioned the girth of log management and security incident and event management (SIEM) products that have just created white papers to convince us they are a security automation and orchestration solution.

The Promise of Automation & Orchestration

The promise of automation and orchestration solutions lies in use cases. Depending on your solution, you can improve just about any SecOps function or process.

Below are some of the use cases best served by these solutions:

Use Case Rational
Alert Resolution Reduce effort to aggregate, correlate, and resolve alerts from multiple sources.
Detect & Patch Automate risk scoring of patch advisories, scan for missing patches and remediate in one continuous motion.
Incident Response Execute incident response playbook in real-time.
Integrate Cybersecurity Countermeasures Automate security technologies to work as a cohesive integrated workflow.
Metrics & Report Consolidation Reduce time required to chase down metrics, consolidate results and produce reports.
Threat Intel Fusion Reduce time and effort to source, analyze and report on threat intelligence from multiple sources.

 

From what I can see from these products, your imagination is your only limitation on how deep you can automate SecOps.

All That Glitters is not Gold

If you are waiting for the other shoe to drop, well listen – thud there it is.  Security automation and orchestration solutions are the next best thing to sliced bread, but they are not magic. You have to model your processes in advance before you can automate and orchestrate them. These solutions have no idea what you want to accomplish unless you tell them. Remember that old adage “garbage in, garbage out?

Modeling a process is a 360-degree exercise. You will need to consider People, policies, procedures, processes, products and proof (metrics). It is only through the union of these domains does automation and orchestration occur.

I know what you are thinking, “I can get rid of all my SecOps staff through automation and orchestration. I will have a lights out SecOps.” Wait what? Nice try but it does not work like that, you will still need people. Your goal is to root out the rote tasks of SecOps freeing your people up to focus on the strategic aspects of your cybersecurity program. Yes, you may be able to stave off hiring more staff addressing the growing skills gap, but don’t go into acquiring a security automation and orchestration solution thinking you’re going to cut staff.

Secret Sauce: Playbooks & Partners

Sometimes the difference in being compromised or not is a matter of seconds. Security and automation software provides the ability to respond to attacks at machine speed. Designed to execute preset detection protocols, these solutions reduce the dependence on manual intervention. Some of the solutions already come with playbook templates.

Solutions that offer the broadest partner eco system and customizable library of playbooks should be at the top of your evaluation list. However, for them to acquire either, they will have had to log time in the seat. You will want a company; whose product has a reasonable size customer base (25+) and can provide evidence of automating and orchestrating dozens of security products within the same client.

Eliminating Your MSSP

Security automation and orchestration has been the secret of Managed Security Service Providers (MSSP) for years. However, their solutions where mostly hybrids of service management tools or custom code written specifically for their SOCs. Having managed SOCs around the world, I know thing or two about what goes on behind the scenes. I can also say that some of you are perfect candidates for replacing your expensive MSSP contract through the introduction of an automation and orchestration solution.

Most organizations gravitate to an MSSP because they do not have the people to watch their network around the clock. In addition, when a critical event does happen, most companies still want a call in the middle of the night. What if you could eliminate all the white noise of SecOps, automate your incident response and receive a call only in times of emergency? It can happen when you implement security automation and orchestration solutions.

DevOps

DevOps has produced one of the most profound changes in IT in the past five years. In many ways, it is a disruptive technology forever changing the landscape of application development and operations. Security automation and orchestration solutions are perfect for facilitating DevOps by supporting a playbook that integrates security-testing, validation and monitoring throughout the lifecycle of application development to deployment. Playbooks support the integration of security testing into the domain of application programmers rather than security personnel. Application development becomes their own gatekeeper and they no longer can blame deployment delays on the security department. Also, imagine the economies of scale of automating patching and hardening into release builds. In my mind, DevOps justifies moving toward a security and automation solution alone.

A Word of Caution

I am a huge believer in taking stock of the past to ensure I do not repeat an incident as a future failure. I searched my disaster archives and found an extreme example of an automation blunder that serves as a cautionary tale. In June 2012, Royal Bank of Scotland’s (RBS) NatWest and Ulster Bank subsidiaries descended into chaos following a glitch in their software workflow automation product.

The outage was so profound it got its own Wikipedia page. During the one-month outage, 1,200 branches had to remain open past normal hours, call center staff was doubled and millions of customers suffered. The CEO had to forego his bonus because of the fiasco’s impact on roughly 20 million customers, and RBS canceled its presence at Wimbledon that year. Game, set, match.

Conclusion

Orchestration and automation solutions are not new, but advances in technology has made their time finally come. As we try to maneuver around a critical shortage of IT personnel, manage an average of 60 security products, adapt to DevOps and strive to be more effective and efficient, few choices to accomplish all are left. As the CISO of your organization, you should be leading the charge toward SecOps automation.

Cybersecurity pit stop necessary for connected cars

Automotive cybersecurity

We are inching toward an era where every car of the future will sip fuel, tick all econoboxes, and finally will be an extension of the connected world. Every automaker, every now and then, comes up with a newer and better illustration. With connected vehicles proliferating and multiplying, we can well be sure of one thing: microprocessors and sensors will continue to drive your cars. But, vehicle cybersecurity deserves the same amount of attention. A new survey commissioned by Irdeto, a cybersecurity firm, points out that people have been increasingly concerned about automotive cybersecurity. The survey was conducted between October 25, 2017, and November 9, 2017, where 8,354 representing six countries, including Canada, China, Germany, Japan, United Kingdom and United States, participated.

One of the most startling revelations of the survey was that most owners did not believe that they owned a connected car. “The survey found that 93 percent of consumers indicated that they do not own or do not know if they own a connected car. Further, of the consumers surveyed, 49 percent stated that they do not own a connected car and do not plan on purchasing one in the future,” the report stated. It concluded that “the percentages of consumers stating that they do not own and/or will never buy a connected car are very high, this simply could be a product of consumers not being aware of the features and functionality that make up a connected vehicle.”

On the bright side, several respondents stated that they understood vehicle cybersecurity and the vulnerability to cyber attacks, with nearly 59 percent stating that they were concerned that their vehicle would be compromised. Also, most consumers were aware that autonomous cars may invite cybersecurity risks.

Region wise, 90 percent of consumers from Canada and the UK were concerned about cyber attacks on cars, while consumers from China were least convinced, where only 23 percent of consumers felt that automotive cybersecurity scenario is highly likely.

The survey also pointed out that “awareness may come with age. The percentage of consumers who believe that a connected vehicle has the potential to be targeted by a cyber attack increased with each age group. Millennials (18-24 years-old) were the age group that most believe this scenario is not possible, with only 24 percent stating this isn’t possible, while 88 percent of consumers 55+ believe that vehicles are targets for cyber attacks.”

The survey concluded that even though consumers still lack awareness and knowledge on the subject and “may not completely understand what components in their vehicle make up a connected car, they do understand that vehicles have the potential to be targeted by a cyber attack. It is possible that recognizing the cybersecurity risks associated with connected cars could be impacting the number of consumers who stated they are not planning on purchasing a connected car. With 49 percent stating that they do not own a connected car and do not plan on purchasing a smart vehicle in the future, the safety implications of not properly securing a connected car could impact purchasing numbers of connected vehicles.”