Home Blog Page 389

Cybersecurity leaders urge US senators for stricter data protection regulations

Capitol

Cybersecurity industry leaders and experts have urged U.S. Senators Mark Warner (D-VA) and Senate Minority Leader Charles Schumer (D-NY) to advance data-centric cybersecurity technology and its capability to protect the sensitive data of both consumers and businesses in the event of a security breach. The group of infosec industry experts recently travelled to Washington to meet the senators.

The cybersecurity leaders and experts who met with the senators include: Jim Varner, President and Chief Executive Officer of SecurityFirst; Ricardo Bueno, Co-founder and Chief Executive Officer of Trivalent; Dr Aviel Rubin, Professor of Computer Science and Technical Director of the Information Security Institute of John Hopkins University; and Robert Roy, Chief Technology Officer of the U.S. Public Sector Cybersecurity Team at Micro Focus. The group also urged the senators to make data-centric security a core requirement for all government agencies and businesses dealing with Personally Identifiable Information (PII) or Personal Health Information (PHI). Warner is the co-chair of the Senate Cybersecurity Caucus and Schumer has long been a proponent of stronger consumer cyber protections.

Recent high-profile cybersecurity breaches, notably those involving the U.S. Office of Personnel Management (OPM) and Equifax, are stern reminders of the poor state of data protection across government and commercial industries. Without federal regulations requiring stricter data protection measures, sensitive consumer and business data will continue to be at risk from cybercriminals or hostile nation-states and other nefarious foreign entities. Regulations require a basic level of data security compliance for some industries and government agencies, but the message from these industry leaders is this is not enough and more must be done.

SecurityFirst CEO Jim Varner, who led the discussions, noted, “It was important for us, as industry leaders, to voice our concerns to key members of our legislative branch of government about the value and capabilities of advanced data-centric cybersecurity technology. Strategies built to keep cybercriminals out of the network and away from the data will eventually fail. But advanced data-centric strategies built to ensure cybercriminals walk away with nothing of value – providing protection from the point of data creation to deletion – succeed.”

Unlike network-centric solutions, advanced data-centric solutions built around both strong encryption at the source and advanced capabilities such as cryptographic splitting, user authentication, access controls, and least privileged access, ensures data privacy far above the standards of network access or secured storage.

Another key point made by Varner was, “Compliance and basic encryption does not equal effective security. Some are just looking to ‘check the encryption box’ by utilizing simple full-disk and storage encryption. Those technologies were designed with physical theft in mind, only protecting the data if a disk is stolen.”

“The mandate for more serious data protection is here and now. Advanced data-centric cybersecurity tools – even certified by the NSA as Top-Secret capable – are available today. These tools have the potential to greatly improve the data protection and privacy needs of our country and its industries,” concluded Varner.

Amid rising IT threats, energy sector prioritizes cybersecurity concerns

Energy cybersecurity

Amid rising concerns over IT threats, the energy sector is taking measures to reduce the risk of cybersecurity breach.

Menelaos Ioannidis, Chief Technology Officer at Lightsource Labs said “hackers might target renewable energy companies for the fun of it or to hold plant operations for ransom”, while adding “it’s not difficult to hack the system”.

Graham Harding, Managing Director and Chief Financial Officer at British Solar Renewables said “we believe any firm dealing with technology has a duty to ensure that cybersecurity is considered in everything they do.”

“We are taking measures to ensure cybersecurity is baked into our designs, solutions and activities in the same way as physical security is”, he said.

In September this year, Siemens Gamesa Renewable Energy (SGRE) gave its Chief Information Officer Alan Feeley an added role as chief cybersecurity officer.

Last month, Berkeley Lab also announced it was launching a project to mitigate cyber-vulnerabilities in rooftop solar panels integrated into the grid.

Since 2015, a group called Dragonfly has been targeting the European and North American energy sectors.

In July this year, the United States Federal Bureau of Investigation and the Department of Homeland had issued warnings to the energy companies being target of cyberattacks.

US introduces new bill to increase security of networked medical devices

Dr. Reddy’s Lab Attacked Days After India Approves Russia’s COVID-19 Vaccine Trial

A bill called the Internet of Medical Things Resilience Partnership Act was introduced on October 5, 2017, by Republican representatives David Trott and Susan Brooks. The bill calls for the US Food and Drug Administration (FDA) to set up a “working group” with representatives from other federal agencies, industry and academia to “develop recommendations for voluntary frameworks and guideline to increase the security and resilience of networked medical devices.”

Since 2014, the FDA has held three public workshops on cybersecurity and has issued final guidance on pre and post market cybersecurity.

“There are millions of medical devices susceptible to cyber-attacks and often times, we are wearing these networked technologies or even have them imbedded in our bodies”, Republican Brooks said.

“Bad actors are not only looking to access sensitive information, but they are also trying to manipulate device functionality. This can lead to life-threatening cyber-attacks on devices ranging from monitors and infusion pumps, to ventilators and radiological technologies”, he added.

Specifically, the “working group” would include representatives from FDA, the Department of Health and Human Services (HHS), Federal Trade Commission (FTC), Federal Communications Commission (FCC), National Institute of Standards and Technology (NIST) and the National Cyber Security Alliance.

On the industry side, the bill calls for at least three members from each of a number of private sector areas, including medical device manufacturers, healthcare providers, insurers, enterprise security firms, as well as hardware and software developers.

If passed, the bill would require FDA to submit a report to Congress within 18 months identifying current and developing cybersecurity standards, gaps where new or revised standards are needed and a plan to address those gaps.

It is yet to ascertained how the working group would fit in with FDA’s ongoing cybersecurity efforts, including its memorandum of understanding (MoU) with the National Health Information Sharing and Analysis Center (NH-ISAC) and the Medical Device Innovation, Safety and Security Consortium (MDISS).

Besides, the bill does not mention the Department of Homeland Security (DHS) in the list of working group representatives, despite the agency’s role in coordinating cybersecurity efforts through its Industrial Control Systems Cyber Emergency Response Team (ICS-CERT).

Poland PM to set up new cybersecurity department

Beata Szydło

Poland Prime Minister Beata Szydło recently announced that a new department of cybersecurity will be set up in her office.

Speaking at the launch of the third “Cybersec” European Cybersecurity Forum in Kraków, southern Poland, Szydlo said “I have decided to create a department, which is currently being set up at many offices of the EU’s prime ministers, whose task will be analyze, monitor, and serve as my network of experts.”

While acknowledging that cyber​​security is among the most important challenges for the modern world, Szydlo said “This is about the economy, security, it’s a question of stability, but also — I think we all realize — of peace”.

The head of the government also said that an expert team was needed in her chancellery in order to meet the challenges of the present day and to have a modern PM’s office.

Speaking at the Cybersec, Antoni Macierewicz, Polish defense minister, said “Poland is going to have a “cyber army” of at least 1,000 soldiers within several years capable of waging warfare in cyberspace”.

“We are aware of how much responsibility falls on Poland because of the key role it plays on NATO’s eastern flank”, he said.

In June this year, it was reported by Kosciuszko Institute that Poland may become a global leader in the cybersecurity sector.

In April this year, Juliusz Brzostek, Director of Poland’s National Cybersecurity Center, said “Computer Emergency Response Teams (CERT) Poland is one of the most active teams in the world and has very experienced researchers.”

In March 2017, Poland’s digital affairs ministry released the draft cybersecurity strategy for the years 2017 to 2022 after concluding the phase of inter-ministerial consultation.

North Korea hacked Seoul-Washington secret joint war plans: Reports

Konni Malware, North Korean threat actors target AstraZeneca

North Korean computer hackers have stolen a vast cache of highly classified military documents from South Korea involving its U.S. ally, a media report said on October 10, 2017.

South Korean lawmaker Rhee Cheol Hee told Chosun Ilbo that the hackers had broken into the South’s military network in September 2016 and gained access to 235 gigabytes of sensitive data.

The daily quoted Rhee as saying that “Operational Plans 5015 and 3100” and a contingency plan contained the South Korean military’s plan to remove the North Korean leader Kim Jong Un, referred to as the “decapitation strike” plan, were among the leaked documents.

“80 percent of the leaked documents that were compromised is yet to be identified”, Rhee added.

According to the South Korean government, Pyongyang has a 6,800-strong unit of trained cyber-warfare specialists.

In May this year, the isolated country had reportedly hacked into Seoul’s military intranet, but it wasn’t revealed what was leaked.

Recently, the U.S. President Donald Trump had tweeted saying that diplomatic efforts with North Korea have consistently failed, adding that “only one thing will work”.

SiteLock analysis reveals 23,000 website attacks annually

Trickbot Malware

Small- to midsized (SMB) businesses websites suffer 23,000 attacks annually, which means an astonishing 63 attacks per day, a new analysis by Sitelock, a company that provides website security solutions, revealed.

The SiteLock Website Security Insider Q2 2017 threw light on the most common threats website owners faced in Q2 2017, including malware trends, content management system risks, plugin risks, website attacks, common vulnerabilities, and social media risks. More than 85 percent of these attacks were reportedly caused by automated bots.

To receive notifications about potential cyber threats, many websites depend upon third parties and search engines. The study showed that four in 10 site owners continued to erroneously believe their hosting provider was responsible for website security.

In the study, it was revealed that browsers correctly flagged only 23% of infected websites while remaining 77% of infected websites provided no warning to users at all because search engine and browser makers tend to be overly cautious about marking sites as being potentially unsafe

To conduct the study, Sitelock analyzed data of over six million websites and surveyed more than 20,000 website owners.

Logan Kipp, WordPress evangelist at SiteLock said “Many website owners are unaware that website security is their responsibility and rely too heavily on popular search engines and other third parties to notify them when they’ve been compromised.”

Content management system risks

SiteLock’s analysis also showed that a website’s content management system had an impact on overall security. Forty-four percent of websites using WordPress CMS had not been updated for over a year at the time of filing this report.

Nearly seven in 10 infected WordPress websites had the latest security patches installed, but were compromised because of vulnerable plugins. An insight into malware trends showed that 62 percent of infected files contain spam.

Equifax was warned of cyber security issues last year: Report

Equifax Settles Indiana Lawsuit Over Data Breach for $19.5 Mn

After a massive data breach, Equifax has been left battered and bruised and to make matters worse, now it has been reported that the credit reporting firm was warned of an imminent threat last year itself.

As per a report published in The Wall Street Journal, analysts at the credit reporting agency, MSCI, had warned Equifax in August 2016 that it was not well-equipped to protect personal data of its millions of customers.

While scrutinizing Equifax records, the index provider MSCI did not find any evidence that the credit scoring company conducted regular cybersecurity audits or provided training to employees on identify risks, nor did they have any emergency plans to handle a data breach or leak. Equifax was then removed by the MSCI from its stock indices.

Speaking to the WSJ, Jon Hale, head of sustainability research at Morningstar Inc. said “If you’re an investor or asset manager and you see these rock-bottom evaluations of Equifax, it had to have given you pause. This is an instance where environmental, social and governance (ESG) analysis was really ahead of the curve.”

Embattled Equifax on October 4 announced that the cybersecurity firm Mandiant has completed the forensic portion of its investigation of the cybersecurity incident disclosed on September 7 to finalize the consumers potentially impacted.

According to Reuters, the U.S. consumer finance watchdog agency, Consumer Financial Protection Bureau (CFPB) is expected to punish Equifax for its cyber breach with the wide-ranging powers it has used with Wall Street.

Malaysian armed forces seek more funds to counter cyber threats in 2018 budget

Malaysian armed forces

Malaysian security forces have sought more funds to counter cyber threats and counter-terrorism operations for the 2018 budget.

Speaking at the Sabah state honors and awards investiture ceremony at Istana Negeri, Inspector-General of Police Tan Sri Mohamad Fuzi Harun said, “We hope the government will give attention to this especially in enhancing the use of information and communication technology widely, in particular related to cyber and social media that have become a problem to us.”

“Other than that, logistic issues such as needs for transport to carry out duty, especially Sabah and Sarawak are required. We need four-wheel-drive among others because the terrain (in the two states) is different from the peninsula. Moreover, we are also gearing up for the upcoming election so such logistic needs must be intensified as so to strengthen the force,” he told reporters.

Notably, Malaysia ranked third most committed country in the world in strengthening cyber capabilities, in a survey by United Nations International Telecommunication Union (ITU).

In Malaysia, National Cyber Security Agency (NSCA) came into existence in 2016 and uses a variety of existing laws — including the Communication and Multimedia Act of 1998, the Defamation Act of 1957, and the Sedition Act of 1948 — to fight cyber threats.

To thwart rising cyber-attacks, country’s defense ministry in January 2017 launched the Cyber Defense Operations Centre (CDOC) to monitor sabotage against government networks.

The Southeast Asia state suffered 2,428 cyber-crimes from January to April this year while online fraud cases in 2016 had risen by 20 percent as compared to 2015.

Protecting citizens against cyber attacks as important as fighting terrorism: GCHQ new head

GCHQ

The United Kingdom’s Government Communications Headquarters (GCHQ) new director Jeremy Fleming on October 9, 2017 warned that Britain is being hit by major cyber attacks twice a day, while adding that cyber experts received 1,131 reports of hacks and 590 of them were classified as ‘significant’.

In a column in Telegraph, Fleming wrote, “I have spent my whole career, in MI5 and now as head of GCHQ, working to counter the most serious threats to our national security. If I’ve learned one thing, it’s that our adversaries are quick to spot new ways of doing us harm. We see that in the way terrorists are constantly changing their weapons or states are using their full range of tools to steal secrets, gain influence and attack our economy”.

“If GCHQ is to continue to help keep the country safe, then protecting the digital homeland – keeping our citizens safe and free online – must become and remain as much part of our mission as our global intelligence reach and our round-the-clock efforts against terrorism”, he further added.

On September 22, 2017, Ian Levy, technical director of the NCSC warned that “category one” cyber attack, the most serious tier possible, will happen “sometime in the next few years”.

Levy further said that organizations should focus on managing risk, understanding the data they hold, the value it has, and how much damage it could do if it was lost, rather than obsessing about buying the right security products.

Post Equifax breach, rival TransUnion ups the ante

A month after Equifax reported a massive data breach, the credit-reporting agency TransUnion hired a full slate of new cybersecurity-focused lobbyists in Washington D.C. According to a federal ethics disclosure, TransUnion revealed it would focus on “issues affecting data security, privacy and cyber-security in its filing”.

In an email to Recode, a spokesperson for TransUnion said it had “engaged additional lobbyists to help us monitor and respond to legislative and regulatory reaction to the Equifax breach announcement.”

Without revealing that TransUnion has faced any breach similar to that in Equifax, the credit-reporting firm acknowledged that it has “felt the fallout from Equifax’s cybersecurity crisis”.

Todd Cello, the CFO of the TransUnion, at an investor conference in New York on October 2, 2017, said that the company is spending more money on call centers as consumers seek answers and credit freezes.

Both the Equifax and the TransUnion use same software, but TransUnion maintained that its software is up-to-date.

On September 26, 2017, San Francisco Superior Court sued Equifax for failing to protect the personal data of 15 million Californian residents. Equifax on October 4 announced that the cybersecurity firm Mandiant has completed the forensic portion of its investigation of the cybersecurity incident disclosed on September 7 to finalize the consumers potentially impacted.