Home Blog Page 382

Uber paid $100,000 to cover up breach that affected 57 million users

Uber Data Breach

It is reported that Uber paid hackers $100,000 to keep data breach a secret. The personal information of about 57 million accounts was reportedly compromised in a hack that took place in October 2016. The incident was first reported by Bloomberg on November 21, 2017. The company reportedly fired its chief security officer, Joe Sullivan, and a deputy, Craig Clark, this week for concealing the hacking incident.

Dara Khosrowshahi, who replaced co-founder Travis Kalanick as CEO in August, wrote in a blog post, “None of this should have happened, and I will not make excuses for it.” He also revealed that he got to know about the breach recently.

Kalanick learned of the breach within a month in November 2016, but he reportedly chose not to share the incident with fellow board members. He still continues to be on Uber’s board and Khosrowshahi said that he regularly consults the former CEO.

While announcing that the expose led to the sacking of two employees, Khosrowshahi said “the stolen information included names, email addresses and mobile phone numbers of Uber users around the world, and the names and license numbers of 600,000 U.S. drivers.”

Khosrowshahi was quoted saying as “While I can’t erase the past, I can commit on behalf of every Uber employee that we will learn from our mistakes. We are changing the way we do business, putting integrity at the core of every decision we make and working hard to earn the trust of our customers.”

To investigate the breach, Khosrowshahi said that his company has hired Mandiant, a cybersecurity firm owned by FireEye and Matt Olsen, former general counsel of the U.S. National Security Agency, to restructure the company’s security teams and processes.

In a statement, Uber said “Uber passengers need not worry as there was no evidence of fraud, while drivers whose license numbers had been stolen would be offered free identity theft protection and credit monitoring.”

The company alleged that two hackers gained unauthorized access to information on Github and stole Uber’s credentials for a separate cloud-services provider where they were able to download driver and rider data.

Meanwhile Uber spokeswoman said the hack was not the result of a failure of GitHub’s security while adding that the New York attorney general has opened an investigation.

In 2014, Uber had acknowledged that its employees had used a software tool called “God View” to track passengers.

 

Countdown to GDPR: Brace yourself

GDPR Fines

This article featured in a CISO MAG’s edition.

Contributed by Raymond Teo, Senior Vice President, Business Development, APAC, NTT Security.

In an uncertain world, one thing international organizations can be sure about is the need to mark 25 May 2018 in their calendars. Why? Because on that date, the new General Data Protection Regulation will come into effect. This will impact every organization in the world that collects or retains personal identifiable data from any European individual.

Four years in the making, this European data protection initiative aims to harmonize the fragmented data privacy framework across the European Economic Area (EEA), and ensure that fundamental rights are protected in today’s digital economy. Legislators believed that an increase in legal certainty would both reduce compliance costs and encourage long-term consumer confidence in the safety of the global digital marketplace. This is why GDPR’s jurisdiction cannot be limited to the EU and requires extraterritoriality to be addressed.

In our experience, many organizations that are located outside Europe but have a global employee and customer base, remain behind the curve in assessing the risks and opportunities of GDPR. They do not have clear visibility, understanding and control over the personal data they process, nor appropriate access to its movement across multiple geographical locations. This lack of engagement could be a risky strategy. With massive fines and requirements for notification that will push more breaches into the public eye, GDPR promises to make data privacy a potential public relations challenge. With proposed penalties for falling short of compliance – including fines of up to four percent of total worldwide annual turnover, these potentially staggering numbers have a purpose: to put privacy and data security on the boardroom agenda by bringing it in line with the highest sanctions for regulatory non-compliance – such as anti-bribery and anti-trust laws.

This article aims to highlight the areas of GDPR that international businesses need to consider, and the practical steps they can take to ensure that they are ready for the 2018 deadline.

GDPR: a framework for a digital world

In seeking to transform data protection culture as well as practice, GDPR has bold ambitions. It encourages organizations to make privacy and data protection core business values, instead of a casual afterthought. By placing the principle of ‘data protection by design and default’ at its heart, GDPR requires organizations to only process the personal data necessary for the specific purpose for which it was collected, and to implement controls to protect that data throughout the process lifecycle. And what counts as personal data? GDPR defines this as “any information relating to an identified or identifiable natural person.” This may include data such as physical address, email address, IP addresses, age, gender, location, health information, search queries, items purchased, cookies and RFID tags for any EU citizen.

As well as trying to investigate how the directive applies to their businesses, many of the organizations that we talk to are using GDPR as an opportunity to review and fully understand the personal data that they retain. Many wish to find practical ways to minimize data to reduce risk. Organizations are also actively revising processes for data storage and – perhaps most challengingly – how access to personal data is controlled and restricted.

However, as we embrace the commercial opportunities of the digital world, should we allow GDPR to be a constraint? Or will consumer demand for new and innovative global services not be matched by an expectation that their personal information is protected? Not only does much of the directive build on existing EU legislations, it also aligns with the direction of travel of other jurisdictions. While differences exist between countries in their approach and the level of legislative development, there are signs of upward convergence towards important data protection principles in particular in certain regions of the world.2 This variety of global data protection initiatives, some driven by GDPR and some not, is one of the reasons that organizations seek to work with data protection advisors with international knowledge and up to date, relevant experience of these frameworks.

Don’t forget the PR in GDPR

For GDPR, or indeed any compliance to be effective, failure must carry a reputational risk. Organizations that think this is just an IT issue have missed the fundamental necessity for every department within the business to think hard about data privacy. Sales, Marketing, HR, Finance: all process data and therefore may introduce risk. The new requirements for data breach reporting within 72 hours will be a challenge for many organizations – not just in how and what to report to the regulators, but in actually having the right systems in place to assess and analyze a breach. Not forgetting that the regulators could come knocking at any time to ensure that adequate protections are in place and a failure to satisfy them may result in a fine, even if an organization has not suffered a breach.

The principle of accountability within the regulation requires clear lines of responsibility and reporting. The GDPR therefore mandates the appointment of a data protection officer (DPO) for certain types of businesses – either because they are ‘public’ organizations, or because their activities include regular and systematic monitoring of data on a large scale.

Organizations are at varying stages of readiness for GDPR – from identifying and clarifying the exact requirements and effect of GDPR to reviewing the adequacy of their existing program or seeking to create audited evidence of implemented controls and compliance with GDPR (see Figure 1). Wherever you are on your journey, this will require security and DPO executives to work together on assessing their GDPR readiness:

GDPR

Where are you on your journey to GDPR?

Protecting and exchanging personal data are not mutually exclusive. A strong data protection system facilitates data flows by building consumer confidence in companies that care about the way they handle their customers’ personal data.3 In our experience, organizations across the globe are at very different stages in their preparations for GDPR. But whatever stage they are at, it is clear

that international businesses wishing to operate in the global digital market must think about the impact of GDPR in order to seize its commercial opportunities, as well as mitigate risk. But as we have said, GDPR is just another milestone on the continuous road of privacy compliance, as in the race for increasingly innovative technologies that strive to make human life more efficient or fun. Consequently, businesses cannot afford to let GDPR constrain their digital aspirations. If the road gets bumpy, organizations may want to consider qualified external partners ready to help them navigate the long compliance journey ahead.

Sources: 

  1. 1.Techcrunch: General Data Protection Regulation: A Milestone Of The Digital Age https://techcrunch.com/2016/01/10/the-biggest-privacy-law-in-the-world-has-arrived/
  2. Data protection regulations and international data flows: Implications for trade and development, UNCTAD (2016): http://unctad.org/en/PublicationsLibrary/dtlstict2016d1_en.pdf
  3. European Commission – COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL. Exchanging and Protecting Personal Data in a Globalised World: http://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52017DC0007&from=EN

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Drone maker DJI and cybersecurity expert embroiled in allegation war

Da-Jiang Innovations

Chinese drone maker Da-Jiang Innovations (DJI) has landed itself into a cybersecurity row over a bug bounty issue. One of the world’s largest drone makers has reportedly accused a cybersecurity researcher of hacking its servers, BBC reported.

Kevin Finisterre, an independent security researcher, claimed that he found a private key publicly posted on code sharing site Github, after which he was able to access confidential and sensitive customer information and saw “unencrypted flight logs, passports, drivers’ licenses and identification cards.”

After discovering the flaw in the security system, he approached the firm that in-turn initially offered a bug bounty reward of up to $30,000 (£23,000) and also offered to hire him as a consultant. Finisterre also claimed that the company tried to make him sign a non-disclosure legal contract, that he refused to sign. The Next Web reported that DJI threatened to charge him with Computer Fraud and Abuse Act (CFAA).

In a detailed 31-page security vulnerability report to DJI in late September this year, Finisterre has revealed that “one of the clauses stated that he could not publicly disclose his research without written consent from DJI.”

On November 16, 2017, Finisterre described the general issues in a blog post and refrained from publicly disclosing the full findings.

Meanwhile, DJI has maintained that the server accessed by Finisterre was “unauthorized”. In a statement, DJI said “DJI takes data security extremely seriously, and will continue to improve its products thanks to researchers who responsibly discover and disclose issues that may affect the security of DJI user data and DJI’s products”.

“The hacker in question refused to agree to these terms despite DJI’s attempts to negotiate with him and threatened DJI if his terms were not met,” the company further said.

Cybersecurity expert Prof Alan Woodward from Surrey University termed DJI’s actions as “outrageous” and said “cybersecurity is one of those areas where there is no government organization or central body or standards agency holding these people to account. It’s ethical hackers and security researchers. The public has a right to know when there’s a security problem”.

Democrats, Republicans join hands with Harvard to prevent hacking in elections

Harvard University

In the run up to 2018 midterm Congressional elections, bipartisan Harvard panel recently launched a “Cybersecurity Campaign Playbook” to safeguard polling process from hacking and propaganda. The Belfer Center for Science and International Affairs, based at the Harvard Kennedy School of Government, have charted out the guidelines in collaboration with top politicians and security experts.

According to a report published in Reuters, the Harvard University will soon release a 27-page guidelines on how the U.S. can prevent hacking attacks during elections. The recommendations reportedly suggest campaign leaders to focus on enhancing security and to implement measures such as two-factor authentication process for email access and end-to-end encryption messaging via Signal and Wickr services.

The contents of the playbook include topics such as The Vulnerable Campaign Environment, The Threats Campaigns Face, Managing Cyber Risks, and Steps to Securing Your Campaign, among other pressing issues. The handbook is a result of Belfer’s four-month-old effort called “Defending Digital Democracy” (DDD) program.

Interestingly, Belfer’s effort to protect elections from cyber crimes has gathered support from top officials of Republicans as well as Democrats. Democrat’s Robby Mook, who organized Hillary Clinton’s 2016 presidential election bid and Republican’s and Matt Rhoades, who led Mitt Romney’s 2012 campaign, were the prominent faces of this program, Silicon.co.uk reported. Cybersecurity experts from tech giants like Google, Facebook, and computer security company CrowdStrike also provided their insights in Belfer’s program.

Belfer co-director Eric Rosenbach said another guidebook aimed at state election officials will be released in Spring. “Deterring information operations is inherently a government responsibility, and the technology firms will decide how to act on their platforms, but state organizations are the victims”, Rosenbach told Reuters.

Debora Plunkett, a 31-year veteran of the National Security Agency (NSA) who joined the Belfer Center in July this year was quoted as saying “we heard from campaigns that there is nothing like this that exists. We had security experts who understood security and election experts who understood campaigns, and both sides were eager to learn how the other part worked.”

To make its program a success, Belfer Center has told its students to go out in various states to observe, understand and analyze elections procedures and voting technologies.

Automotive Cybersecurity: A new market with a distinct challenge

Automotive cybersecurity

Innovation in the automotive industry has led to a scenario where a car being manual may simply mean it has a steering wheel. Once composed of only mechanical and electrical parts, cars have now turned into complex systems that comprise sensors, microprocessors, software, and much more.

The proliferation of autonomous vehicles means that microprocessors and sensors will soon take a much more active role in driving cars. However, even before self-driving cars become commonplace, modern cars are already vulnerable to hackers via in-car technology like Wi-Fi. These “connected cars” are becoming standard. In 2015, there were around 6.5 million connected cars on the road and by 2017, the figure almost doubled to 12.5 million. According to estimates, there will be as many as a quarter billion connected vehicles on the road by 2020.

This new technology has also opened a floodgate of security threats. While you might be behind the wheel, potentially vulnerable software control your car’s functions. “There is almost nothing in your car that is not mediated by a computer,” said Professor Stefan Savage, Department of Computer Science, UC San Diego, while speaking to Motherboard magazine for a short documentary on car hacking.

Fear of car hacking has not yet penetrated the general population’s psyche, as demonstrated by a 2016 Kelley Blue Book survey of drivers. The results of the survey show that among its sample size, very few drivers fear car hacking and most consider connected apps and Wi-Fi networks nice features to have.

Worries over security have also not slowed down the pace at which connectivity features continue to be rolled out due to the real benefits all this technology can bring with it. Connectivity technologies in commercial vehicles not only improve efficiency and streamline logistics, they also lower occurrences of road accidents and reduce preventive maintenance costs. Incorporating connectivity technologies can also reduce 62 percent of all trucking costs, it is estimated.

A Real Threat

Vehicle hacking isn’t just a theory or seen only in Hollywood movies. In 2016, Nissan had to shut down its proprietary app NissanConnected EV for its Leaf line-up after it was found that hackers could access the cars’ climate control and other battery operated features to drain the batteries. Also, in 2015, automaker Fiat Chrysler had to issue a recall for almost 1.4 million vehicles after researchers Charlie Miller and Chris Valasek of Wired demonstrated a wireless hack on Jeep Grand Cherokee, taking over the controls of the dashboard, steering wheel, powertrain, and even the brakes.

Recently, WikiLeaks released documents blowing a whistle on the CIA suggesting journalist Michael Hastings’s fatal car crash was triggered by a car hack. In 2013, Hastings died after the car he was driving abruptly sped up and crashed into a tree. The media has largely covered this idea as a fringe conspiracy theory, but many of the details are consistent with how a hacked car could behave.

Regulators, Industry Respond

Autonomous vehicles are no longer a pipe dream and all vehicles soon will come with smartphone connectivity embedded into their systems. Fortunately, all manufacturers prioritize the satisfaction and safety of their customers. The burgeoning field of automotive cybersecurity will grow in partnership with regulatory and compliance bodies, original equipment manufacturers (OEMs), technology companies, insurance companies, and other stakeholders pressing for safe and secure architecture. Connected and autonomous automobiles are dynamic threat environments and numerous patrons are collaborating with groups like the newly formed Auto-ISAC, to sketch guidelines, standardizations, and best practices.

These bodies endorse integration of cybersecurity into the entire lifecycle of a vehicle – from concept to production, maintenance, and decommission. Even governments are taking notice of this. Earlier this January, a bipartisan bill titled ‘Security and Privacy of Your (SPY) Car Study of 2017’ was introduced in the United States focusing on the cybersecurity of automobiles. The bill mandated that the National Highway Traffic Safety Administration create

appropriate cybersecurity standards for vehicles. Other nodal agencies mentioned in the bill were the Department of Defense, National Institutes of Standards and Technology, and the Federal Trade Commission, among others. The bill stressed the importance of isolation measures to separate critical software from trivial programs and take measures to detect anomalous codes.

The European Union Agency for Network and Information Security (ENISA) has also envisaged similar scenarios and come up with a report on ‘Cyber Security Resilience of Smart Cars.’

Growing Tech, Broader Safety Net

Security cannot be an afterthought—it must be integral throughout the design process. Automotive cybersecurity is a new emerging market. According to report titled ‘Automotive Cyber Security – Global Forecast to 2021,’ the global automotive cybersecurity market is projected to grow at a compound annual growth rate (CAGR) of 13.2 percent by 2021, to reach a market size of $31.8 million by 2021.

A sizeable number of private firms are also venturing into automotive cybersecurity. Israeli startup Karamba Security unveiled security systems for connected cars that prevent hackers from running any malicious code on the car system like lane assist, infotainment, and GPS tracking. Another startup working in the same field is Argus Cyber Security. Argus helps car manufacturers, their Tier 1 suppliers, and aftermarket connectivity providers protect connected cars and commercial vehicles from hacking.

This is the Internet of Things (IoT) era and cars are no longer basic modes of transportation. Connected cars could be a new and refreshing use of big data and a business model worth leveraging as insights from these data can be monetized. A McKinsey report states that, “Once autonomous driving and car connectivity combine, customers might be offered mobility services in exchange for watching targeted advertisements, providing product feedback, or making purchases while in the car.”

Businesses in the future might also leverage these systems to offer free rides to stores to retain customer loyalty. The initial architecture of car networks is now almost 30 years old and was devised for various reasons, but security was not one of them. The systems were designed without an inkling that vehicles could be hacked, but it’s not too late. It’s time for cybersecurity professionals to step in and do what they do best–clean up the tech to avert disaster.

Resources used for writing the article

 http://www.gartner.com/newsroom/id/2970017

http://mediaroom.kbb.com/special-reports

https://www.trucks.com/2016/05/17/long-haul-trucking-connectivity-brings-hacking-risks/

http://www.businessinsider.com/nissan-leaf-hack-app-flaw-2016-2?IR=T

http://www.bbc.com/news/technology-33650491

https://www.thesun.co.uk/news/3041856/michael-hastings-conspiracy-theory-car-hacked-cia/

https://www.congress.gov/bill/115th-congress/house-bill/701/text

https://www.enisa.europa.eu/publications/cyber-security-and-resilience-of-smart-cars/

http://www.marketsandmarkets.com/PressReleases/cyber-security-automotive-industry.asp

https://www.karambasecurity.com/media

https://www.mckinsey.de/files/mckinsey_car_data_march_2016.pdf

Cyber insurance startup At-Bay raises $6 million in seed funding

Startup

California-based cyber insurance startup At-Bay has successfully raised $6 million in a seed funding round led by investors Lightspeed Venture Partners, LocalGlobe LLP, and Check Point Software Technologies Ltd co-founder Shlomo Kramer. Additionally, it has partnered with Connecticut-based The Hartford Steam Boiler Inspection and Insurance Company (HSB) to bring to market a product to insure and defend organizations against cyber risks.

Launched in 2016, insurtech company At-Bay offers its clients a customized cyber insurance policy. It has a mission to empower enterprises to take on tomorrow and embrace technology fearlessly.

In a statement given to Business Wire, At-Bay founder and Chief Executive Rotem Iram said “we founded At-Bay with the belief that controlling for cyber risk enables businesses to embrace technology and unlock great value to customers. We match deep insights on a company’s IT security with financial exposure that cyber attack vectors create, to enable insurance brokers and risk managers to more clearly and accurately assess and manage cyber risk. Our insurance products and supporting risk management services provide organizations with the confidence that they can take on the challenges of tomorrow.”

Iram said that his firm plans to utilize $6 million funding to go to market and build up the firm’s sales force. “We will probably be raising quite a bit more money in the next few months to increase our footprint,” he further said.

Dave Mercier, senior vice president for HSB said, “we are very excited about working with At-Bay and continue to be impressed by the technology and expertise they bring to customers. At-Bay’s data and knowledge-driven business model aligns with HSB’s own system of managing and underwriting cyber risk. Their offering truly leverages the strengths of both companies.”

It’s either Eden or Perdition, there is no middle way for infosec startups

Aviatrix Funding

There is a wave of people joining the entrepreneurial bandwagon. And it might seem like the only hipster thing you’ll do while it’s still cool. Whether you are tapping your keyboard perfecting a company that will take on technology giants or you are creating a company that may become a wing of a much larger conglomerate, you are all part of a wave that results in a startup.

Cybersecurity is one of the stakeholders of the new world and has significantly been influenced by this new wave. In fact, in the last half a decade, it has grown tremendously. “Security is a space where you see a lot of startups,” said Sarah Guo, an investor at Greylock Partners, told The Business Insider. “Everything is increasingly internet connected and if it’s internet connected, it’s vulnerable. There’s a lot of new opportunity, and I personally believe the market will grow for a long time.”

The worldwide cybercrime expenses are expected to grow to $2 trillion by 2019. An astonishing 36 percent startups have already raised seed money while the number was just 15 percent a year ago. In 2016, cybersecurity funding deals reached a record high of $3.5 billion. According to an IDC projection, companies will spend $81.7 billion on cybersecurity solutions, and the market will continue to grow at a steady rate of 9 percent through 2020.

There are newer categories in this sphere like automotive cybersecurity, cybersecurity insurance, IoT security, etc. Apart from these, there are companies that offer artificial intelligence and machine learning. Most of them are either acing the autonomous game or have been already been acquired by tech giants. At present, there are more than five cybersecurity startups that have reached the legions of Unicorns (companies evaluated at more than $1 billion).

Most of these new companies were formed by young teams – founders with only a few years of experience in cybersecurity domain from established companies. Whereas earlier, the only experienced team climbed cybersecurity mountains to start companies of their own.

Despite a growing market need, however, not all cybersecurity offerings are the same, and there isn’t any assurance that your startup will become a Unicorn. Late Raimund Genes, former CTO of Trend Micro, was of the opinion that most cybersecurity startups in the future will either be acquired by a bigger company or will completely cease to exist. In one of his interviews, he had stated that, “Whenever someone pitches me an idea, I simply ask them, ‘what is your cash burn rate?’ I do get a lot of funny faces. But I believe that you need to have a strong customer and also a certain sustainability longevity. If there is an entry plan, there should be an exit plan too. And if your exit plan is to be acquired by a bigger company, then good luck with that. Because, as a buyer, we have a huge catalog to choose from. There are plenty of products on the market. So, if I am buying out a company, it definitely needs to have a proven customer base and credentials.”

It is also important for cybersecurity startups to look for investors who have deep knowledge in cybersecurity sector. A mentor with a cyber DNA can guide your startup through various rounds of funding. Also, throwing cybersecurity buzzwords and jargons like end-to-end encryption, artificial intelligence, etc., is not going to help, for many have tried and didn’t make it.

Lastly, not all startups receive funding early on. The road to entrepreneurship needs patience. You must be prepared to endure years of Lent with no real guarantee of Easter.

Cybersecurity firm VeroGuard Systems to create 596 jobs in Adelaide

Adelaide

Melbourne-based cybersecurity firm VeroGuard Systems is all set to establish its base in Adelaide’s north and create almost 600 jobs. The company on November 18, 2017, announced that it will begin manufacturing in Adelaide by 2018 to enable hyper-secure online transactions. It also plans to launch an operations center to provide global customer service and digital support infrastructure.

It recently raised $6.2 million in state government funding to set up a base at Edinburgh Parks industrial estate in north of Adelaide. The company claims to create 596 jobs in initial three years, with an investment of $57.5 million. Out of 596 required employees, it plans to recruit 424 from the northern Adelaide region, which will also include former automotive workers, a news report said.

State Premier Jay Weatherill was quoted saying as “the revolutionary technology developed by VeroGuard will make remembering numerous PINs and giving credit card details over the net a thing of the past. It essentially gives you bank-level security for individual transactions. That will massively improve security and protect people from identity fraud.”

Weatherill further said the state government had contributed a $6.2 million grant from its Economic Investment Fund to help VeroGuard establish its operations in Adelaide.

Revealing why VeroGuard Systems chose Adelaide as its base, the company’s Co-CEO Nick Nuske said that he sees South Australia as a base for an “opportunity to be part of an ecosystem that had already become well developed for future technologies.”

He further stated that the construction that will be completed in eight months will begin early next year. For future placements, the company will reportedly collaborate with the University of Adelaide.

Air Force awards $50 million contract for cybersecurity research

KBR to Strengthen Cybersecurity of USAF Systems

The research laboratory of the U.S. Air Force has awarded Colorado-based Ball Aerospace & Technologies Corp a defense contract of nearly $50 million for securing its weapons from cyber threats.

“Ball Aerospace & Technologies Corp., Boulder, Colorado, has been awarded a $47,900,000 modification (P00003) to a previously awarded contract (FA8650-16-D-1878) for research and development to provide investigation and development of methodologies, tools, techniques, and innovative solutions to identify susceptibilities and mitigate vulnerabilities in Air Force weapon systems, and protect those systems against cyber-attack,” the Air Force stated in a statement. “Work will be performed at Wright-Patterson Air Force Base, Ohio, with an expected completion date of March 29, 2023.  Air Force Research Laboratory, Wright-Patterson Air Force Base, Ohio, is the contracting activity.”

This might follow the operationalization of several key elements the Air Force had identified in its recent comprehensive cybersecurity plan which gave key importance in averting cyber attacks and building resilience to new weapons systems. Lt. Gen. John F. Thompson, former Air Force Life Cycle Management Center commander in an interview had earlier stated that mitigating cyber attacks is “paramount” for the Air Force.

The Air Force leaders also constituted new unit tasked with handling cyber threats called Cyber Resilience Office for Weapons Systems, or CROW. “It is like a response team that can go to program offices and help them analyze an incident. They do an analysis and postmortem on what happened,” stated Lt. Gen. Arnold Bunch, Jr., military deputy, Office of the Assistant Secretary of the Air Force for Acquisition in an interview with DefenseSystems.com.

Earlier, U.S. Army’s Logistics Support Activity (LOGSA) awarded IBM a contract to continue providing cloud services, software development and cognitive computing, constituting the technical infrastructure for one of the U.S. federal government’s biggest logistics systems. IBM was tasked with, “improving cybersecurity by applying the risk management framework (RMF) security controls to LOGSA’s IT enterprise. RMF is the unified information security framework for the entire U.S. federal government; it replaces legacy IT security standards, etc.

Financial CERT to combat cyber threats, says MoS home affairs

CERT

To tackle cyber threats to India’s financial institutions, the central government is mulling to establish a financial Computer Emergency Response Team (CERT).

Addressing the 15th Asia Pacific Computer Emergency Response Team (APCERT) Open Conference in New Delhi on November 15, 2017, IT Secretary Ajay Prakash Sawhney said, “right now, the one which is directly being worked on is the financial CERT. We are getting the framework in place and once that is there, we will look at other sectors. It will oversee the entire financial sector including banks and financial institutions.”

In March this year, the power ministry had announced to create four sectoral CERTs for cybersecurity in power systems: CERT (Transmission), CERT (Thermal), CERT (Hydro), and CERT (Distribution).

Udbhav Tiwari, program manager at the Centre for Internet and Society, a Bengaluru-based think tank, highlighted the responsibilities of the financial CERT in a conversation with Live Mint.  “The biggest task of sectoral CERT is to share information with the others in the industry. For example, if a bank undergoes an attack, normally the bank will perform all the necessary actions to limit the attack and to prevent it from happening in the future. But the obligation of sharing how the attack happened with all the other banks in India to make sure that they can protect their respective systems from such an attack, can be carried out by a financial CERT,” he said.

Cybersecurity Chief Gulshan Rai, who was also present at the event, said “from April to October 2017, around 50,000 cyber security incidents have been handled by CERT-In; including phishing, malware attacks, attacks on digital payments and targeted attacks on some of the critical industries.”

On August 1, 2017, MoS home affairs Hansraj Gangaram Ahir had said “as per the information by the Indian computer emergency response team (CERT-In), 50 incidents affecting 19 financial organizations have been reported during the period of November, 2016 to June, 2017.”