Home Blog Page 401

State Department’s Cybersecurity office rumored to be shut down by White House

State-Department

Rumors are flying high regarding the closure of the State Department’s only cybersecurity office by White House after Christopher Painter, the Coordinator for Cyber Issues, decided to quit at the end of the month after spending more than two decades in the office.

Painter’s office, which reportedly handles negotiations with other countries on political infrastructure protection, development of cyber norms and other related issues, may be closed by Secretary of State Rex Tillerson who plans to converge the cyber security office with an office in Bureau of Economic and Business Affairs.

Painter, who earlier held top positions in National Security Council, Federal Bureau of Investigation, and the Justice Department, may return to the DOJ. A successor is yet to be found, but as per Tim Maurer, co-director of the Cyber Policy Initiative at the Carnegie Endowment for International Peace, the appointment is quite “an important and urgent task.” Painter’s departure would also make the State Department’s responsibility of presenting an international cyber strategy to Trump by late September an uphill task.

Reacting to the news of Painter leaving the office, James Lewis, a cyber expert at the Center for Strategic and International Studies said, “Chris will be hard to replace. This will be an easy one to mess up.”

Other cyber-policy experts also feel that the shutting down of the office will bear negative impact on the cybersecurity issues. Jason Healey, a senior cyber researcher at Columbia University, said that the loss of Painter would be a great loss to United States. He further added that shutting the cybersecurity office “would mean the United States would be the only major country without a lead diplomat to discuss cyber norms and trying to reduce the ever-escalating cyberattacks we see around the world. It is not just a shame if the U.S. were to surrender that leadership, but would mean the future internet will have more Russian and Chinese characteristics.”

Cybersecurity issues scaring voters away, a survey says

cybersecurity-issues

Cybersecurity firm Carbon Black recently came out with a poll which suggested one out of every four Americans would consider not voting in the upcoming elections due to the cybersecurity concerns. The survey, which had a margin error of less than two percent, was conducted among 5000 people. The survey suggested the American voters are worried that the hackers would steal their personal information from voter rolls.

The concerns of the Americans regarding the hacking of information are not invalid, especially after the 2016 presidential elections where Russia allegedly hacked into voter databases and software systems in a few states.

“There is no question, none, that the U.S. voting process is vulnerable,” Carbon Black Chief Executive Patrick Morley told The Hill. He went on to add that poor security of the voting machines make them vulnerable to hacks.

According to the poll by Carbon Black, 44 percent of the participants think that state authorities are capable of protecting the voter information. Fifty-four percent said they now feel elections are less secured than they previously thought before the election. Also, 45 percent believe that the midterm elections will be influenced by cyberattacks.

The survey result was refuted by the National Association of Secretaries of State as they claimed that Carbon Black is publishing the survey as they stand to benefit from the efforts made to improve cybersecurity issues. The association released a statement in which they wrote, “American voters deserve fair and impartial research on elections, just as much as they deserve fair and impartial elections.”

UK government pledges £21 million to increase NHS cybersecurity

cyberattacks on U.K. organizations

In the wake of the recent WannaCry ransomware cyberattack, the UK government has pledged £21 million to boost cybersecurity of National Health Service. The announcement was made by Jeremy Hunt, the health secretary to prevent attacks on the healthcare sector.

Twenty-seven major trauma centers in NHS’s network across England will receive the grant. “The NHS has a long history of safeguarding confidential data but with the growing threat of cyber-attacks, including the WannaCry ransomware attack in May, this government has acted to protect information across the NHS,” said Lord O’Shaughnessy, the health minister. “Only by leading cultural change and backing organisations to drive up security standards across the health and care system can we build the resilience the NHS needs in the face of a global threat.”

Recipients of the grant will use the allowance to update their IT infrastructure, train their staff and become more resilient in the wake of another cyberattack.

WannaCry has been dubbed as one of the most infamous ransomware attacks ever, affecting more than 150 countries and 230,000 computers. The global attack which unfolded on Friday, May 12, 2017 used a flaw in Microsoft’s Windows operating system. The cyrptoworm targeted Windows computers using the EternalBlue exploit taking advantage of the Windows’ Server Message Block (SMB) protocol, installing a backdoor implant tool called Double Pulsar. NHS was one of the first and biggest victim.

Months before the attack occurred, Dame Fiona, the chair of Oxford University Hospitals NHS Trust, had warned health secretary Jeremy Hunt that an “external cyber threat is becoming a bigger consideration”. She had also noted that there is lack of understanding of security issues.

“New technological advances offer extraordinary opportunities for patient data to be used to improve people’s individual care and to improve health, care and services through research and planning”, she said. “We will only be able to harness those opportunities if the public trusts that the health and care system is doing all it can to keep patient data secure, to meet their expectations on confidentiality and to be transparent.”

Trump backs away from working with Russia on cybersecurity

trump backs away from working with russia on cybersecurity

The United States President Donald Trump appears to back away from working with Russia on cybersecurity unit after facing a widespread criticism over the idea. Trump and Russian President Vladimir Putin were engaged in a lengthy conversation earlier this month, where cybersecurity was one of the key points. The meeting was held on the sidelines of the G20 summits in Hamburg, Germany.

After the two-hour long meeting, Trump tweeted “Putin & I discussed forming an impenetrable Cyber Security unit so that election hacking, & many other negative things, will be guarded… and safe.” The discussion was described as a “very important step forward” by Steve Mnuchin, Trump’s treasury secretary. Mnuchin added, “What we want to make sure is that we coordinate with Russia, that we’re focused on cybersecurity together, that we make sure that they never interfere in any Democratic elections or conduct any cybersecurity. And this is like any other strategic alliance, whether we’re doing military exercises with our allies or anything else. This is about having capabilities to make sure that we both fight cyber together, which I think is a very significant accomplishment for President Trump.”

However, within a few hours, Trump again tweeted “The fact that President Putin and I discussed a Cyber Security unit doesn’t mean I think it can happen. It can’t-but a ceasefire can, & did!”, which makes the viability of the cybersecurity pact ambiguous.

Any endorsement of forming a cybersecurity pact drew immediate flak from many State Senators, and Marco Rubio, the Republican nominee against Donald Trump in the 2016 presidential elections, described the whole situation as,” Partnering with Putin on a ‘Cyber Security Unit’ is akin to partnering with Assad on a ‘Chemical Weapons Unit.” He added, “We have no quarrel with Russia or the Russian people. Problem is with Putin & his oppression, war crimes & interference in our elections.” Another of his tweet said, “While reality & pragmatism requires that we engage Vladimir Putin, he will never be a trusted ally or a reliable constructive partner.”

In response to the criticism face by the U.S. government, Nikki Haley, the ambassador to the United Nations, defended the move made by Trump saying, “We can’t trust Russia and we won’t ever trust Russia. But you keep those that you don’t trust closer so that you can always keep an eye on ‘em and keep them in check. Everybody knows that Russia meddled in our elections.”

The overall situation related to the Hamburg interaction got into murky waters due to the investigation into the alleged interference of the Russian interference in 2016 presidential election. Trump and as well as the Moscow representatives denied any involvement into the matter, but is still unable to dissolve the tensions associated with it.

Cybersecurity bill released by Singapore for public consultation

Cybersecurity Singapore

A cybersecurity bill was released by Cyber Security Agency (CSA) in Singapore on July 10, 2017 for public consultation that will end on Aug 3. This step was taken to make the owners of critical information infrastructure (CII) responsible to report security breaches in 11 key essential sectors that include telecommunication, transport, healthcare, banking and energy. It would also require the vendors dealing with highly sensitive services to obtain a license for practicing. The bill was drafted following the announcement of high level cybersecurity strategy by the Critical Information Infrastructure (CII) in October last year. The CSA spent almost two years to prepare the draft.
The bill, that aims to plug security gaps in CII, attempts to clarify the obligations of public and private sector organizations to share information if an investigation of a cybersecurity incident or threat is undertaken by CSA. It also gives the CSA the power to supersede any banking or privacy rules that forbids sharing of confidential information. The proactive measures that should be mandated by the CII comprises the following steps

  • Notify the commissioner of the CII suffering a cybersecurity attack
  • Conduct regular system audits by a commissioner-approved third-party
  • Conduct regular risk assessments of the CII
  • Comply with directions issued by the commissioner, including providing access to premises, computers or information during investigations

As per the draft, Chief of CSA will take over the post of commissioner of cybersecurity. The chief will be responsible to investigate threats and incidents, and ensure that no disruption of essential services occurs during a cyberattack. The bill proposes a fine of $1.00.000 or a jail term of 10 years, in case of non-compliance.
The bill also requires the vendors involved in investigative cybersecurity services or non-investigative cybersecurity services would be required to have a valid license to continue practicing. Anyone found in violation of the rule will attract a fine of $50,000, or a jail term not exceeding two years, or both.

India and Israel join hands to boost cybersecurity

India-Israel

India and Israel have issued a joint statement that has confirmed a partnership between the two countries to tackle security issues in the cyberspace. it was decided during the Indian Prime Minister Narendra Modi’s three-day state visit to Israel.

India is already planning to counter the frequent and severe digital threats by holding dialogues with United Nations Group of Government Experts or UNGGE, and signing bilateral agreements with several countries, including Russia and the United States. The Indian government had signed cyber agreement with Russia and a framework agreement with the U.S. within the last one year. Getting into a diplomatic tie with Israel can provide a much-needed boost to the information technology (IT) sector.

Israel is one of the major contributors in the field of cybersecurity and an agreement will help both the countries to fight the menace of cyberterrorism by establishing a proper platform to share information regarding security issues, incidents, threats and the best practices to promote innovation in cybersecurity.

India is among the countries which have a higher number of instances of digital security breaches which can be addressed if the contract is signed between these countries. Israel, on the other hand, would benefit from the large amount of foreign investment that would flow in their market.

U.S. nuclear plants warned for potential cyberattacks

cyberattacks

The United States Federal Bureau of Investigation and the Department of Homeland have issued warnings to the energy companies being target of cyberattacks. According to reports, suspected Russian hackers have intruded into American power plants. Wolf Creek Nuclear Operating Corporation in Burlington, was one of the several nuclear plants targeted by hackers. No specific victims have yet been identified. A report from New York Times suggests that hackers have been trying to penetrate into the energy facilities since May.

“Historically, cyber actors have strategically targeted the energy sector with various goals ranging from cyber espionage to the ability to disrupt energy systems in the event of a hostile conflict,” Reuters quoted the report as stating.

Wolf Creek have stated that no operations systems were not affected. Jenny Hageman, Wolf Creek Communications Manager, assured that the facility continued to “operate safely”. “There has been absolutely no operational impact to Wolf Creek. The reason that is true is because the operational computer systems are completely separate from the corporate network. The safety and control systems for the nuclear reactor and other vital plant components are not connected to business networks or the internet. The plant continues to operate safely.”

The Department of Energy has earlier sent a letter to President Donald Trump stating that, “Russians and other foreign actors have the capability, and potentially the intent, to cause significant damage to our economy by attacking our critical energy infrastructure, including our electric grid.” The letter had appealed to Trump administration to reverse the cut on the cybersecurity budget the president had introduced.

Sixty percent Romanian organizations to increase their cybersecurity budget

Cybersecurity Investment Estimated to Grow up to 6% in 2020

Nearly 60 percent organizations in Romania are considering to increase their cybersecurity budget from the next fiscal year, stated a joint survey by PwC Romania and Microsoft Romania. The survey titled ‘Security in the Digital World’ examines investments in cybersecurity sector. According to the survey, investments in this sector is often driven by regulation and not due to the need to have a secured architecture in place.

The survey stated that nearly 40 percent of the companies did not have proper cybersecurity strategy in place.

“With less than 1 year until enforcement the European Directive for the General Data Protection Regulation (GDPR) is becoming an increasing concern for local organizations. However, the study reveals that very few respondents have already created an execution plan in relation to the provisions of the GDPR”, said Oana Terteleac, Digital Sales Incubation Unit Lead, Microsoft Romania, in a statement.

Commenting about perceived threats, nearly 87 percent of respondents stated that they are preoccupied with potential data leaks, 73 percent stated malware attacks is their biggest concern, 70 percent spoke about disruptions in business continuity, while another 70 percent were preoccupied with ensuring protection against targeted attacks like DDos.

The study highlighted that information security was fully understood and supported at Board of Directors level. “Information Security Officer appears not to be heard at Board level unless there is a crisis or a compliance issue – they need more support, including hiring more resources or acquiring security intelligence, as technology is a business wide matter today – information security risks are business wide risks,” stated Mircea Bozga, Risk Assurance Partner, PwC Romania, in a statement.

Three Egyptian content pirates sentenced

egyption-content

Following multiple piracy raids by a collaborative investigation between Egyptian Cybercrime Police, MAL, a provider of video entertainment services in Africa, and Irdeto, a digital platform security, three Egyptian content pirates were sentenced to a two-year jail term and fine of $4,100. The raids also unearthed a huge cybercrime syndicate which controlled word sharing equipment and illegal pirate subscriptions for sale. The syndicate allowed 163,802 viewers unauthorized access to content from several broadcasters.

“Engaging in any form of piracy comes with consequences, and this ruling clearly indicates that piracy will not be tolerated,” said Frikkie Jonker, General Manager, Africa Piracy Department, MultiChoice Africa. “These convictions are critical to sending a message to the pirate community that piracy is a serious offense that damages the media and entertainment industry. Our collaboration with Irdeto and the unbelievable support of the Egyptian Enforcement Authorities, without whom this would not have been possible, demonstrates the importance of working together to combat the growing problem of piracy.”

“These convictions are a testament to the seriousness of the piracy offense and the commitment of law enforcement worldwide to crack down on these cybercrime networks,” said Rory O’Connor, Vice President of Cybersecurity Services, Irdeto. “Our partnership with MultiChoice Africa epitomizes our commitment to content owners, rights holders and operators to combat smartcard sharing and other forms of piracy. We will continue to work closely with law enforcement around the globe to shut down criminal pirate networks and ensure that justice is served.”

Senator Cantwell urges reversal of DoE cybersecurity budget cut

cybersecurity-budget

United States Senator Maria Cantwell (D-WA), a ranking member of the Senate Energy and Natural Resources Committee, has appealed to President Donald Trump to reverse the 32 percent cut to the Department of Energy’s cybersecurity budget.

The remark came in the wake of the recent ransomware cyberattack which affected nearly 65 countries. “These recent attacks are another sign that we must improve the cyber security of our energy networks. The Trump Administration has been dragging their feet on this urgent task-we need action now to keep our energy networks safe. I am calling on President Trump to reverse his harmful 32% cut to the Department Of Energy’s cyber security budget and lay out a comprehensive cybersecurity plan without further delay,” said Cantwell in response to the attacks,” said Cantwell.

The Senator along with 18 fellow Senate colleagues, in a wordy public letter dated June 22, 2017, had urged the U.S. President to analyze Russian capabilities attacks on the U.S. energy infrastructure.

“Instead of responsibly performing the requested assessment, your administration has proposed slashing funding to the very offices tasked with protecting our grid from Russian cyber attacks. Indeed, the Department of Energy’s Congressional Budget Request for Fiscal Year 2018 proposes to dramatically reduce funding for the Office of Electricity Delivery and Energy Reliability by more than 40% How can our government protect our national security assets if the administration does not allocate the necessary resources?” the senators wrote.