Home Blog Page 402

Ghana Communications Ministry appoints Antwi Boasiako as the Cyber Security Advisor

Ghana Ranks 9th on World Bank’s Vulnerable Countries List in Sub-Saharan Africa

The Communications Ministry of Ghana has appointed Albert Antwi Boasiako as the Cyber Security Advisor. He will be responsible in implementing the National Cyber Security Policy and Strategy (NCSPS). For this role, he will build a secure information security management architecture which will bridge the gap between cybersecurity services and government functions.

He will also be involved with assisting the government on implementing policies aimed at addressing the country’s cybersecurity challenges. “The technology environment of today requires the urgent implementation of important cybersecurity activities and programs to address Ghana’s cyber security challenges and Mr. Antwi-Boasiko is expected to assist the ministry to implement the policy in this regard,” read a statement from the Communications Ministry.

Boasiako is the principal consultant of cybersecurity firm, E-Crime Bureau as well as a cybersecurity expert with the Interpol Global Cybercrime Expert Group (IGCEG). During his tenure, he was involved with several cybersecurity incidents in Accra, Ghana.

An expert with the Council of Europe’s Global Action on Cybercrime Extended (GLACY+) Project, Boasiako has worked in Europe, Middle East and Africa (EMEA) Market and presently he is a PhD Research Fellow with the University of Pretoria, South Africa.

Cyberattacks cost banks $1.75 million

BlackMatter Group, Volvo Cars ransomware attack

A recent Kaspersky Lab and B2B International survey points that cybersecurity incidents in the financial and online banking services cost banks an average of $1.75 million, which is twice the cost of convalescing from a malware incident that stands at considerably skimpy $825,000.

Among the 800 odd respondents of the survey, nearly 61 percent felt that incidents in the banking services often comes coupled with added costs like loss of brand reputation, data theft, and theft of confidential information.

The hardest hitters are DDos attacks, which cost banking sector $1.17 million in recovery cost. The other industries spend $952,000 to recover from these attacks.

“In the banking sector reputation is everything, and security goes hand-in-hand with this,” said Kirill Ilganaev, head of Kaspersky DDoS protection, Kaspersky Lab, in a statement. “If a bank’s online services come under attack, it is very difficult for customers to trust that bank with their money, so it’s easy to see why an attack could be so crippling. If banks are to protect themselves effectively from the price tag of an online banking cybersecurity incident, they first need to become more prepared for the dangers DDoS attacks pose to their online banking services. This threat should be featuring higher on banks’ security priorities.”

While Banks fear DDoS the most, a recent study by MediaPro pointed that out of 809 people employed in the U.S. financial services sector, 80 percent of respondents were considered as risks or novices, “meaning their actions could lead to a potentially serious cyber incident or data breach.” The results from the survey suggested that, “financial sector organizations need to consider a comprehensive data protection strategy that includes employee training to ensure security and privacy concerns are top-of-mind for their employees.”

Ready to have company’s source code examined: Kaspersky to US government

kaspersky-lab

Following the draft of the new bill by the United States Senate that seeks ban on all Kaspersky Labs products from Department of Defense budget, Kaspersky Chief Executive Officer Eugene Kaspersky has appealed to the U.S. government for reconsideration.

Eugene in an interview with The Associated Press at his Moscow headquarters stated that he is ready to have his company’s source code examined by U.S. government officials to dispel any suspicion. “Anything I can do to prove that we don’t behave maliciously I will do it,” he said. He also added that he is ready to share his research work to the U.S. to help counter rumors. According to him, the rumors dates decades back and has popped up out of professional jealousy.

The bill came to fore after the U.S. Senate became suspicious of Kaspersky Lab’s ties to the Kremlin. Commenting on why the concerns crept in, he said, ‘I do understand why we look strange. Because for Russia it’s very unusual, a Russian IT that’s very successful everywhere around the world. But it’s true.’

He acknowledged the company having former Russian intelligence workers amid his staff, but assured that the company’s internal network was too segregated for a single rogue employee to abuse it.

“It’s almost not possible,’’ he said. ‘‘Because to do that, you have to have not just one person in the company, but a group of people that have access to different parts of our technological processes. It’s too complicated.”

“We stay on the bright side. And never, never go to the dark side,” he concluded.

Israel Aerospace invests in Dutch, Hungarian cyber firms

Israel-aerospace

In a bid to expand its cybersecurity reach, state-owned Israel Aerospace Industries Inc. (IAI) is investing in two cybersecurity companies – Inpedio BV in Netherlands and Cytrox in Hungary. The financial details of the investments have not been revealed.

The Dutch-Israeli startup founded by Avi Rubinstein and Rotem Farkash, Inpedio BV offers cybersecurity solutions to governments and enterprises. It’s product Zerox, is capable of detecting and preventing exploitation attacks. It is also equipped with an anti-ransomware module. Inpedio BV’s second product, Mercury, protects Android and iOS devices from external threats.

While the Hungarian cybersecurity firm Cytrox specializes in implementation of cyber intelligence for governments. It is also equipped with engines that can gather intelligence from devices and cloud.

These new investments add to IAI’s existing cyber operations in Israel, Switzerland and Singapore where it operates research and development (R&D) and innovation centers.

Infosec industry, a new favorite for venture capitalists

Infosec-Industry

A spate of rising global cyberattacks have triggered a new trend among investors and the venture capital (VC) industry who are now investing in companies providing cybersecurity solutions. In fact, January itself the market saw $279 million in financing volume.

Cybersecurity company Symantec, in March, also announced the formation of Symantec Ventures to back cybersecurity startups accelerate the delivery of core innovation to the security marketplace by contributing capital. Symantec CEO Greg Clark said in a statement, “We are launching Symantec Ventures to catalyze innovation in the cybersecurity space. (…) We can help startups by allowing them to build on our extensible Integrated Cyber Defense Platform. For example, a new algorithmic approach to anomaly detection can be built on top of our endpoint platform or run on top of our network and cloud security drive train. This strives to enable Symantec’s more than 385,000 enterprise customers – which includes many of the largest enterprises in the world – to tap into the rich ecosystem of ideas in the marketplace and allow entrepreneurs to dramatically reduce their time to market.”

According to PitchBook, the VC activity in information security sector across Europe and Israel saw a consistent rise since 2012. All the 337 investors in the region have been involved in at least one of the 302 cybersecurity deals across Europe and Israel since 2012. The report show a rise by almost 13 percent from 2016. One of the recent and biggest deals was led by Sapphire Venture, which invested $27.5 million Wandera at the Series C round.

Microsoft to acquire Cloudyn

Microsoft-cloudyn

Microsoft has signed a definitive agreement to acquire Israel-based Cloudyn, a company that helps enterprises and managed service providers optimize their investments in cloud services. According to The Algemeiner, the deal took place for an estimated $50-$70 million.

“As customers grow their cloud usage across many projects, it can be challenging to gain visibility and understand costs for existing projects, to optimize those investments and to project future usage. It is critical that customers have access to enterprise-grade management capabilities for detailed visibility into their Azure consumption, cost and performance in order to stay within budget and ensure business success,” wrote Jeremy Winter, Microsoft director of program management, Azure security and operations management, in an announcement post. “It is critical that customers have access to enterprise-grade management capabilities for detailed visibility into their Azure consumption, cost and performance in order to stay within budget and ensure business success.”

The acquisition is subject to regulatory approvals and is expected to close later this year.

Israel has been a hot favorite and an investing hub for the information technology industry. This is a second major acquisition of an Israeli company for Microsoft. Earlier this year, Microsoft had acquired Hexadite for $100 million. Also, Intel acquired Mobileye for $15 billion in what has been dubbed as the largest-ever acquisition of an Israeli technology company.

WannaCry makes companies wanna‘hire’ talent

WannaCry

For decades, the cybersecurity industry has been suffering from perpetual skill shortage. In fact, a study by Cybersecurity Ventures reveals that the cybersecurity job openings will hit 3.5 million by 2021, with a median salary for information security professionals at $92,600.

“I see the demand continuing to increase in the cybersecurity field. We as a society are putting more and more of our lives, our systems, and our data online. More has to be protected. More has to be secured,” says Kenneth Knapp, director of cybersecurity programs at The University of Tampa while talking to Bizjournals.

Among the industries with crying needs for cybersecurity are finance, retail and health care, thanks to legal and industry standard requirements. Fortunately, there has been a surge in demands has been for fresh infosec graduates due to the recent cyberattacks like WannaCry and Petya. According to Economic Times, the student from Gujarat Forensic Sciences University in India with masters in cybersecurity programs received 70 offers from international conglomerates, which in comparison was 125 percent more than the previous year.

“The demand for cyber-security specialists has shot up so much after the recent spate of cyber-attacks that six companies have already rolled out about 30 pre-placement offers to batch 2018,” said Digvijaysinh Rathod, training and placement officer at the university, while talking to Economic Times.

The fastidious talent buying spree is not only among multinational companies, but also young and budding startups. Even consulting firms are on a hiring spree across countries with trained infosec professionals like from US, the UK and Israel. May technology giants are hiring expats at mid and senior levels and have tied up with global universities for both education and hiring purposes.

Among the industries with crying needs for cybersecurity are finance, retail and health care, thanks to legal and industry standard requirements, Knapp says. But as the Internet of Things broadens, as well as the scope of connected devices and systems, all sectors of our economy will see a growing need for experts, he said.

Knapp and his colleagues at UT are working to address the demand with rapidly growing programs at both the undergraduate and graduate levels meant to train the next generation of cybersecurity professionals.

Cybersecurity professionals in new layer of M&A scrutiny

Security

The 2014 Yahoo! Inc cyberattack that affected more than 500 million user accounts not only tarnished the reputation of the company but also impacted it financially. Verizon Communications Inc. which was on the process of acquiring Yahoo! cut the initial offer by $350 million.

The incident triggered a trend among other investors and enterprises, who started to add an extra level of scrutiny for the whole mergers and acquisition (M&A) process by hiring information security experts to screen targets for potential security risks.

Michael Bittan, head of Deloitte’s Cyber Risk Services unit in France, while talking to Bloomberg said, “There’s a risk you’re buying an empty shell. Cybersecurity is not about getting technical, it’s about business impact, and ultimately valuations. It will become a pillar of M&A decisions.”

According to a survey by NYSE, nearly 85 percent of the executives have found critical flaws and vulnerabilities at the audit stage. This affected the company’s decision to mend or even backing out from the M&A deals. “Beyond the obvious threats to cybersecurity, conducting an audit of cybersecurity protocols can also reveal vulnerabilities that could require significant expenditures for the acquiring company,” the survey report added.

The bigger concern, according to the report, was the lack of necessary technical skills among the people involved in the M&A process.

Fortunately, the trend of employing cybersecurity professionals during M&A process is growing. According to hackmageddon.com, there were as many as 1061 cyberattacks in 2016, which is poised to surge in the coming years. With cyberattacks hogging the limelight, experts feel that the likelihood of seeing more companies devaluating targets or even backing out after spotting vulnerabilities will increase.

Official Ohio websites hacked to spread IS propaganda

Ohio-websites-hacked

Several United States government websites were hacked by hacker group Team System DZ which allegedly has ties to the terrorist organization, Islamic State. The page displayed anti-Trump slogans and threats. The hacked websites included Ohio Department of Rehabilitation and Corrections, Casino Control, Ohio First Lady, Office of Workforce Transformation, Office of Health Transformation, Inspector General, Ohio governor, and Medicaid.

Every visitor to the website was greeted with an Arabic symbol with a pitch black page with an Islamic prayer played in the background. Also, a line appeared on every page, that said, “Hacked by Team System DZ.” The text on the landing page read: “You will be held accountable Trump, you and all your people for every drop of blood flowing in Muslim countries”, and “I Love Islamic State.”

All the affected agencies were working on resolving the issue. Tom Hoyt, spokesman for the Ohio Department of Administrative Services, in a statement, said, “All affected servers have been taken offline and we are investigating how these hackers were able to deface these websites. We also are working with law enforcement to better understand what happened.”

Team System DZ has been involved in numerous hacks including Canadian food truck’s sandwich site, University of New Brunswick’s student union site, and even an English rugby team’s site.
Joseph Marquette, President and Founder of Accellis Technology Group in Cleveland, in an interview with WKYC called the incident “more of something called hacktivism.” She said, “they’re just looking to promote their own cause, create some measure of fear, but if they were truly looking to steal information or data, odds are they were gonna do it in a much more subversive and secretive way.”

New Cyber Security Startup Fund from Trend Micro

cybersecurity-startup

Another cyber security corporation has entered the startup investment sector. Trend Micro announced a $100 million fund in a statement declaring that is looking to fund efforts in the Internet of Things (IoT) area, though detailed investing strategies were not shared. Its goal is “to dive into new areas without disrupting core business resources.”

It is becoming common for tech firms to set-up startup venture funds that will help create new technology that can then be incorporated into their products.

Trend Micro is a major player in the information and network security landscape. It’s based in Japan and listed on the Tokyo Stock Exchange, valued at approximately $7.5 billion. It was founded in the United States in 1988 and is active in over 50 countries and employs over 5,000.

It markets a wide variety of cyber security merchandise for multiple operating systems, including threat detection and antivirus products. Hybrid cloud security, network defense, user protection, and small business products are at the core of its product line.

By funding startups, Trend Micro hopes to learn more about the “emerging ecosystem opportunities, disruptive business models, market gaps, and skillset shortages” in the IoT sector.

With the outlook for ever-increasing numbers of devices to be added to the Internet in coming years, the opportunity for already established cyber security firms like Trend Micro is significant. Malware, botnets, and a whole host of cyber crime products will have ever more access to networks as more and more devices are added to the IoT.

The statement says the $100 million is an “initial” investment, so this may be only the first salvo by Trend Micro. The company has enjoyed 72 quarters of consecutive profitability and is “well-positioned” to invest on behalf of its corporate strategy. The company claims that its network of clients and customers represents more than 28,000 companies.