Home Blog Page 403

Cybersecurity Training in Mission, Texas

Texas Court Systems Affected by Ransomware Attack

The Mission Economic Development Corporation (MEDC) in Mission, Texas, and State Senator Juan “Chuy” Hinojosa announced $100,000 in state grants to implement cybersecurity training programs. The funding was contained in House Bill 728, which recently passed the Texas Legislature.

The bill provides increased computer science opportunities for Texas high school students, with the State Board of Education directed to implement stronger computer science curriculum. Computer science credits will now be equal to advanced math or science credits in meeting graduation requirements. Prior to the bill’s passage, computer science was considered an elective, but now is a core element of secondary education.

Hinojosa noted that the bill “… fits right in with STEM (Science, Technology, Engineering, and Mathematics)” and that by making computer science a core subject it will push more students into the field.

An initial class of 40 students recently completed an eight-week cyber-security-training program earlier in June. The students were paid for their time spent in the classroom and began the process of gaining certification as cybersecurity analysts.

These positions are in high demand as the impact of cyber crimes and hacking continue to be a serious challenge. According to the U.S. Bureau of Labor Statistics, the number of information security analysts will increase by 37 percent by 2022.

The new grant will help students pay for books, expenses, certification costs, and also will help pay students $500 per month in order to make the training economically feasible for students of all income backgrounds.

The current training program is in partnership with CompTIA, a national organization dedicated to giving voice to the information technology (IT) industry. It invests heavily in “IT education, IT certification, IT advocacy and IT philanthropy.” CompTIA has over 2,000 members nationally and 3,000 academic and training partners.

Over 200 students applied for the initial offering, with only 40 slots available. Classes were for eight hours a day over an eight-week period, with a path to CompTIA certification a possibility.

It is hoped that tech training in the Mission area will heighten economic opportunities for local people by making it a more attractive location for tech businesses to relocate, since a trained workforce is already being developed.

New Israel–U.S. Cyber Security Partnership

USA-Israel

A new cooperative agreement relating to cyber security issues between the United States and Israel was announced by U.S. Homeland Security Adviser Tom Bossert at Tel Aviv University’s Cyber Week. The focus of the partnership is on “stopping adversaries in networks and identifying ways to hold bad actors responsible.”

He went on to say it would concentrate on protecting critical infrastructure and developing forward-thinking research assets.

The prime minister of Israel, Benjamin Netanyahu, also spoke at the event, noting that one of his goals had been to “establish Israel as one of the five leading cyber powers in the world” and that he felt that goal had been accomplished. He also noted that cyber safety is a job that is never accomplished, since threats continue to be developed and implemented.

According to Netanyahu, the volume of serious attacks that Israel regularly faces and the technological know-how that Israel has developed in the cyber security sector has made “Israeli companies very, very attractive.” Israel is home to several leading companies in the global cyber security field and over 400 startups in the tech security sector are active in Israel.

The “Israeli-US bilateral cyber working group” will begin meeting immediately, according to Bossert. An initial meeting at the U.S. embassy in Tel Aviv has already taken place, with Bossert being joined by White House Cyber Security Coordinator Rob Joyce.

The United States will be represented by officials from the Department of Homeland Security, the Federal Bureau of Investigation (FBI), and the State Department. It is expected that joint cyber teams will shape cyber policy and cooperation between the two allies.

This new effort comes in the aftermath of President Donald Trump’s visit to Israel in late May.

New Cyber Insurance Products from Apple–Cisco Partnership

CISCO

At an event sponsored by Cisco in Las Vegas, Apple CEO Tim Cook made public a partnership between the two tech sector giants that will make available cyber security insurance at discount rates.

The argument made by Cook, as reported by Reuters, is that companies using Cisco and Apple products together will be less vulnerable to cyber attacks and thus the cost of insuring such businesses will be less. Cook pledged that the partnership was a new venture that “… we’re going to spend some energy on. You should reap that benefit.” He went to stress how sophisticated hacking was becoming and that other platforms were not able to keep up with the rising threat of cyber attacks.

Apple and Cisco have been collaborating in several other areas in recent years. The announcement came only one week after Cisco CEO Chuck Robbins proclaimed the company’s “next era” was at hand with the rollout of its new artificial intelligent (AI) network products.

Cook noted that part of the collaboration with Cisco was to bring “Apple’s legendary ease-of-use and simplicity” to the cyber security sector. It was also announced that an already established partnership in high-speed mobile Internet between Cisco and Apple was being expanded to include Mac computers.

The partnership fits in with Cisco’s move away from legacy technology and into cutting-edge areas such as the Internet of Things‎ (IoT) and cloud-based security. Robbins is quoted as saying: “In my 20 years at Cisco, I have never been more excited about our innovation than I am today.”

For Apple, the new joint venture fits into its recent forays into the business market, as opposed to the personal consumer market that’s long been its prime focus. Cook noted that in 2015 Apple was bringing in over $25 billion a year in revenue in its business market and, along with Cisco, has partnership deals with IBM and SAP.

Cybereason Attracts Another $100 Million Startup Funding

cybereason attracts another $100 million startup funding

Approaching the $1 billion valuation, Cybereason has raised another $100 million in funding from SoftBank Group Corp. According to an unnamed source familiar with the company, the new round of fund raising brings Cybereason — an Israeli startup founded by former members of the Unit 8200 military intelligence division — to a current value of over $850 million.

Cyber security startups that have reached the $1 billion benchmark include Cloudflare, Cylance, Crowdstrike, and Zscaler. In previous rounds of funding, Cybereason has attracted investment funds from Charles River Ventures, Lockheed Martin, and Spark Capital.

This round of financing was entirely from SoftBank and not from its Vision Fund, which is a $93 billion venture capital fund whose backers include Apple, Qualcomm, and Saudi Arabia’s Public Investment Fund. In 2015, SoftBank invested $59 million in Cybereason.

Like another cyber security startup Cylance, Cybereason specializes in using artificial intelligence to identify network security incursions, and thus mobilizes countermeasures more quickly. Its Chief Executive Officer Lior Div says AI will allow cyber security defenders to better keep up with hackers as they switch tactics and produce ever more aggressive attack strategies.

Div points out that the pace of attacks has picked up, with the “cadence [switching] from years, to months, and then to weeks” and stresses that governmental agencies from around the world are now focusing on potential terrorist activities in the cyber realm.

Founded in 2012 by Div, Yossi Naar, and Yonatan Striem-Amit, Cybereason develops “military-grade technology” to counter advanced cyber attacks. Their strategy is based on immediate detection of an attack, finding a component that is part of the attack, and using this as the starting point to seek out other pieces of information that are part of the attack.

Team8 Adds to Impressive List of Strategic Partners

team8 adds to impressive list of strategic partners

Intel is the latest major tech company to become a strategic partner with Team8, a company specializing in helping startups in the cyber security sector. Based in Israel, Team8’s impressive list of syndicate members include Accenture, AT&T, Bessemer Venture Partners, Cisco, Citigroup, Innovation Endeavors, Microsoft, Nokia, and Qualcomm.

Israel is a hotbed of cyber startups, with at least 450 businesses currently active that receive about 20 percent of the global investment in the cyber security sector. The first two Team8 cyber companies, Claroty and Illusive, have already launched and there are two more about to go live, one within a few weeks and another in early 2018.

Team8, which went public in 2015 with $15 million in investment funding from Bessemer Venture Partners, Innovation Endeavors, a Marker LLC, is a cyber security think tank and venture creation foundry. Its goal is to develop disruptive technologies that will challenge the cyber security threats that are on the horizon and give organizations better tools of fight cyber attacks. It brings together innovation leaders, researchers, and entrepreneurs.

The co-founder and CEO of Team8, Nadav Zafrir, stressed to Reuters that the wide variety of strategic partners that are working with his company provide a wealth of perspectives on the cyber security sector. For example, Citi “enables us to see the world from a financial standpoint,” while Intel will bring to the table the “challenges going forward in cyber security like computing, automotive, cloud, mobile, and IoT (Internet of Things).”

One aspect of the partnership with Intel will be its working directly with Illusive, which will focus on extending from software to hardware its deception-based cyber security protocols and strategies. The collaboration will focus on Advanced Persistent Threats (APTs), which attack networks from multiple vectors and entry points simultaneously and can be extremely difficult to defend against.

According to the general manager of Intel’s platform security division Jacob Mendel, these kinds of attacks oftentimes “go undetected and pose a great threat to enterprises and individuals.”

Former DHS Head Speaks Openly of Russian Election Hacking

Nobelium

Approaching the $1 billion valuation, Cybereason has raised another $100 million in funding from SoftBank Group Corp. According to an unnamed source familiar with the company, the new round of fund raising brings Cybereason — an Israeli startup founded by former members of the Unit 8200 military intelligence division — to a current value of over $850 million.

Cyber security startups that have reached the $1 billion benchmark include Cloudflare, Cylance, Crowdstrike, and Zscaler. In previous rounds of funding, Cybereason has attracted investment funds from Charles River Ventures, Lockheed Martin, and Spark Capital.

This round of financing was entirely from SoftBank and not from its Vision Fund, which is a $93 billion venture capital fund whose backers include Apple, Qualcomm, and Saudi Arabia’s Public Investment Fund. In 2015, SoftBank invested $59 million in Cybereason.

Like another cyber security startup Cylance, Cybereason specializes in using artificial intelligence to identify network security incursions, and thus mobilizes countermeasures more quickly. Its Chief Executive Officer Lior Div says AI will allow cyber security defenders to better keep up with hackers as they switch tactics and produce ever more aggressive attack strategies.

Div points out that the pace of attacks has picked up, with the “cadence [switching] from years, to months, and then to weeks” and stresses that governmental agencies from around the world are now focusing on potential terrorist activities in the cyber realm.

Founded in 2012 by Div, Yossi Naar, and Yonatan Striem-Amit, Cybereason develops “military-grade technology” to counter advanced cyber attacks. Their strategy is based on immediate detection of an attack, finding a component that is part of the attack, and using this as the starting point to seek out other pieces of information that are part of the attack.

British Intelligence Agency Tracks Malware

British-Intelligence-Agency

The WannaCry malware that spread quickly through much of the world in May, doing grievous temporary damage to the network security of Britain’s National Health Service (NHS), is now believed to have been the work of hackers operating from North Korea. This is the conclusion of the British National Cyber Security Centre (NCSC), a department of the Government Communications Headquarters. It led an investigation of the attack that had widespread cooperation from other cyber security agencies from around the globe.

The BBC has reported that security officials believe the hacking group known as Lazarus was behind the attack. This group is believed to have carried out a significant attack on Sony Pictures in 2014, which was in retaliation of the Seth Rogan movie The Interview, a satirical spoof of the North Korean leadership.

It is also suspected of other cyber crimes, including the electronic theft of bank funds, the most high profile case being an $81 million heist in 2016 from the central bank of Bangladesh. This cyber crime used weaknesses in the international transfer system SWIFT to launder money in various ways and is one of the biggest bank robberies of all time.

Lazarus is known to be based in North Korea, but its relationship with the secretive leadership in the country in unknown. Another attack that it has been linked to, which also featured ransomware, was against a South Korean supermarket chain.

It is not believed the ransomware — which encrypted data on computers and then demanded payment in Bitcoin to provide the key to un-encrypt the data — was specifically targeting Britain or the NHS. The conclusion is that it was a theft operation that grew out of control. It does not appear that the hackers received any ransom payments during the widespread incident.

The head of cyber threat intelligence at BAE Systems, Adrian Nish, recognized code in WannaCry that was familiar from prior Lazarus malware. He stated that the code-overlaps “are significant.” BAE is a defense and security multinational and is one of many private sector professionals who examined the WannaCry code. It is believed the NCSC assessment was deeper, using more robust examination tools.

The U.S. National Security Agency also assessed the attack, but since the malware was not as prevalent in the United States, the British probe had more resources at its disposal. There have been no credible reports of any other culprits being suspected of this crime.

New, Modern High-Tech Girl Scout Badges

Infosec

The classic Girl Scouts badge is getting a cutting-edge, cyber-age update. It was recently announced that a joint venture between the Girl Scouts of the USA and Palo Alto Networks would result in new cyber security badges that will represent achievement in the field of Internet security.

There will be 18 badges on offer, with Girl Scouts CEO Sylvia Acevedo freely admitting that the development of the cyber security program was due to advocating by current scouts, who are responding to the role technology plays in their lives.

It is a priority of the Girl Scouts leadership to boost interest in science, technology, engineering, and mathematics (STEM). Other current partnerships are with NASA and toymaker GoldieBlox, both are creating engineering curricula for girls.

Palo Alto Networks is, according to its website, a “… next-generation security company maintaining trust in the digital age by helping tens of thousands of organizations worldwide prevent cyber breaches.”

The Girl Scouts have an alumni list of women now holding power positions in Silicon Valley, including the CEO’s of YouTube (Susan Wojcicki), IBM (Ginni Rometty), and Eventbrite (Julia Hartz). Over a third of the people who have flown on Space Shuttle missions have been women who were Girl Scouts earlier in life.

But in the current tech field, only about 18 percent of graduates majoring in computer science are women and only 10 percent of professionals in the information security sector are women.
One way of increasing those numbers is to provide mentorships with young women at a critical age. Research sponsored by Accenture and Girls Who Code reported that girls were 16 percent more likely to pursue computer science studies if they had mentors in middle school.

Acevedo has a strong STEM background herself, having worked at NASA’s Jet Propulsion Laboratory before forging a career in the tech field at IBM and Dell. She holds an advanced degree from Stanford in Systems Engineering.

The low percentage of women in the cyber security field is a growing issue, since there are currently about 300,000 vacant jobs in the sector. The need for professionals in cyber security is expected to grow by 1.5 million globally within the next five years and more women choosing the field is an obvious solution.

Five Steps to Mitigate Cyber Crime Risks

Cyber-Crime-Risks

The need for constant countermeasures against hackers focused on committing cyber crimes is simply a fact of modern business operations. The recent WannaCry malware attack — the cost of which already runs in the billions of dollars and which severely compromised the United Kingdom’s National Health Service (NHS) — is the latest example for normalizing aggressive cyber security measures.

The lack of awareness amongst the owners/operators of small businesses is especially severe and dangerous. It seems like such an intimidating technological problem, while media reports tend to concentrate on the issues facing large enterprises, like the NHS and power companies. Although a recent U.K. government study did find that a larger percentage of big businesses reported being victims of information security breaches (90 percent), a significant 74 percent of small businesses did so as well, and many small businesses may not even pick up on some issues.

Here are five steps that will help you protect data and cut down on the risk of a catastrophic data emergency.

The first step is to identify risks. A full risk assessment will identify what data cyber criminals might be interested in, which usually includes private customer data, the loss of which may open you up to fines, lawsuits, and a collapse in trust in your customer base. Track down where your company’s data is stored and who has access to it, including employees using personal laptops and phones on your business network.

Next is to give thought to who may have plans to capture your data. It’s worth researching the kinds of attacks your type of business is usually subjected to. Also, give thought to disgruntled employees or “undercover hackers” who may have recently become employed by you in order to gain access to your network.

Finding the vulnerabilities in your network security system before anyone else does is the best solution and comes next. There are off-the-shelf software tools and dedicated specialists who can carry out these kinds of intrusion detection and prevention system examinations. A penetration test mimics an attack on your information security system. It’s like a cyber “war game” testing your defenses.

Next is to build a realistic idea of what a successful attack on your system would mean. How much damage would occur and what data would be lost? This business-impact analysis will help focus decision-making and create an order of priorities.

Finally, prioritize the potential risks that have been discovered and begin resolving them as quickly as possible. Make a list of what needs to be done to protect not only your data, but also the data of your customers and vendors, and start crossing things off the list.

You’ll never guarantee complete and permanent safety from cyber attacks, but by prioritizing vulnerabilities and taking countermeasures you can mitigate the chances that your business suffers a catastrophic cyber security breach. By having mitigation procedures in place, action can happen more swiftly and effectively in case the worst does occur.

Cognosec Continues Acquisitions, Purchases Intact Software Distribution

Cognosec-and-Intact

A supplier of cyber security solutions in Europe, Africa, and the Middle East, Cognosec has acquired the South African company Intact Software Distribution. The acquisition adds to Cognosec’s portfolio in the areas of innovative portal technologies for the sale of cyber security solutions, products, and services. The current strategy of Cognosec is to expand into Internet distribution of software technologies.

Cognosec specializes in products and professional services to help reduce the threat posed by cyber crimes. They help organizations become more resilient to cyber attacks by assessing processes, procedures, and systems, including supply chain systems. It is headquartered in Sweden and operates subsidiaries in the United Kingdom, Austria, Germany, the United Arab Emirates, Kenya, and South Africa.

Intact is expected to cease operations at the close of the third quarter of 2017 after due diligence exercises have been carried out. It is a South African registered company headquartered in Cape Town and Johannesburg. The company has focused on the distribution and support of technical knowledge transfer.

This acquisition complements Cognosec’s recent purchase of A-tek Distribution, which provides specialist distribution services in sub-Saharan Africa. A-tek is a platform that is believed to provide scalability and a potentially innovative global distribution methodology.

The expansion of Cognosec provides advantages for both vendors and customers, including enhanced cyber security solutions for their portfolio that revolves around secure operation centers, network operation Centers, data centers, mobile platforms, and critical fraud prevention solutions.