Home Blog Page 405

Looming shortage of cyber security staff in Europe

EU Joint Cyber Unit

It is feared that Europe may be facing a serious shortage of information security technicians as soon as 2022. This at a time when cyber attacks — especially from Russia — are on the rise and present an ongoing security threat. According to a recent report based on the 2017 Global Information Security Workforce Study, 40 percent of European companies plan to expand their cyber security operations by at least 15 percent over the next 12 months.

Over 19,000 individuals were surveyed in the making of the Workforce Study, with 3,700 being European. It appears that by 2022, Europe may be facing a shortage of up to 350,000 workers in the information and network security sector. The report recognizes that Europe is already plagued by labor scarcity in the field, with an unemployment rate of just 1 percent. The report calls on employers to ramp up training and do more to seek out and welcome new employees into the cyber workforce.

With 92 percent of hiring managers saying that they give priority to applicants with prior cyber security experience, while most employees are recruited from within the managers’ professional networks, it is feared that a closed loop is in place that cannot deal with the long-term demand for a more robust cyber workforce. Globally, a whopping 70 percent of companies are planning on increasing the number of workers in their cyber security divisions. But a shortage of skilled workers and a lack of investment in training — combined with aggressive recruitment targets — is creating a “seller’s market” that not only drives up wages, but also leaves many positions vacant.

A significant portion of the global cyber workforce, 21 percent, reports having changed jobs in the past year. Salary pressure is one factor why organizations are facing serious challenges in retaining staff, as over 33 percent of the workforce in Europe is now making in excess of $100,000 (€95,000/£78,000) annually.

One obvious weakness in the labor market is the scarcity of women in cyber security. The report highlights the lack of focus on women in recruitment campaigns and the ongoing gender pay gap as issues exacerbating the problem. Also cited is the continued emphasis on technical skills over more general skills that can then be refined with training, and the general recruitment bias against millennials.

This gap in demand and supply is happening as a number of cyber security issues continue to develop. Data exposure was the top concern of professionals around the world. The upcoming General Data Protection Regulation (GDPR), scheduled to go into effect in Europe on May 25, 2018, is also creating a bottleneck in the information security sector. Organizations found violating this new regulatory system face fines of up to €20 million or 4 percent of global turnover, whichever is greater.

The report emphasizes that recruiters need to leave their comfort zone and look for potential employees from a broader spectrum of applicants. It was advised that companies needed to focus on finding applicants who can, with training, do what is needed and not to be so dependent on prior qualifications.

Seclore expands presence in Middle East

Infosec-Middle-East

Expanding and developing its presence and impact in the Middle East, Seclore Technologies, provider of Enterprise Digital Rights Management (EDRM) solutions has appointed Redington Gulf, a distributor of IT products in the Middle East and Africa region – as a Value Added Distributor for the region. This follows the opening of a new regional office in Dubai, in April 2017.

“We are already active in the GCC with a particular focus on the UAE, where our GCC regional office provides technical expertise and support closer to our customers. Data losses are at all-time high and information centric security is gaining momentum, highlighted by the recent global ransomware attacks, so our timing is very appropriate as data security is pushed to the top of the corporate agenda,” said Amit Malhotra, VP Sales India Middle East & Africa, Seclore,

A recent report titled, ‘Securing Information in the Age of External Collaboration,’ notest that more than one in four companies believes it’s very likely that sensitive data has been stolen by third party vendors. 98 percent of respondents cited the loss of sensitive data as a top or significant concern. Commonly stated reasons for data loss include emails sent to the wrong person (67 percent), unauthorized access (64 percent) and lost portable storage devices (61 percent).

“Seclore helps organizations secure their sensitive data regardless of how or where it travels. Protection remains with the files when open or stored on mobile devices and laptops and if they are shared via any file sharing service or email solution. File owners can also dynamically modify usage controls or revoke access on previously distributed files,” Amit Malhotra added.

Confirming the appointment, Ramkumar Balakrishnan, President – Redington Value commented, “Cyber security is at an inflection point in Middle East region. Redington, as market leader, is well positioned to deliver Seclore solutions to customers and ensure that all the requirements of the channel are met under one-roof, supported by our in-house pre-sales expertise, regular sales and technical training and programs.”

“This new agreement with Redington will help extend our reach and impact across the region, with almost 1,600 partners across the Middle East and Africa and a range of enterprise customers,” added Rohit Oberoi Director of Channel Sales in India, Middle East and Africa for Seclore.

RBI mandates lenders to spruce cybersecurity

RBI

Identifying the threats and security emerging from cyberspace, Reserve Bank of India has appealed lenders to place a cybersecurity policy immediately to combat the issue. “It is essential to enhance the resilience of the banking system by improving the current defenses in addressing cyber risks. Banks should immediately put in place a cyber-security policy elucidating the strategy containing an appropriate approach to combat cyber threats.” the RBI said in a statement.

The Indian central bank have also requested banks to identify potential risks under, low, moderate, high and very high categories, and also report any unusual cybersecurity incident to the RBI.

According to the RBI, the new cybersecurity policy should also reflect the bank’s information technology policy. It also mandated continuous surveillance, “Testing for vulnerabilities at reasonable intervals of time is very important. The nature of cyber-attacks are such that they can occur at any time and in a manner that may not have been anticipated. Hence, it is mandated that a SOC (Security Operations Centre) be set up at the earliest, if not yet been done. It is also essential that this Centre ensures continuous surveillance and keeps itself regularly updated on the latest nature of emerging cyber threats,” the statement added.

According to the central bank, the recent attacks in the financial sector called for an ‘urgent’ need to have a robust cybersecurity technology in place. This was after the $81 million being stolen from Bangladesh central bank account with the New York Federal reserve.

ZingBox in Gartner Cool Vendor report

ZingBox

Internet of Things (IoT) security provider Zingbox announced its annexation in Gartner’s May 2017 Cool Vendors in IoT Security report.

“ZingBox is the industry’s first and only IoT security solution provider to leverage the individual personalities of IoT devices to provide accurate visibility and protection of an organization’s IoT assets,” said May Wang, CTO and Co-Founder of ZingBox. “We believe our selection as a Gartner Cool Vendor validates our vision to protect organizations from both insider threats as well as external cyber-attacks across a wide range of verticals.”

The annual Cool Vendor reports rates evolving vendors that provide pioneering technologies. According to Gartner, “2017 Cool Vendors in IoT security bring notable approaches to software composition analysis, enterprise mobility management and asset discovery.”

“IoT Guardian, ZingBox’s SaaS-based security solution, leverages machine learning to discover, assess risk, baseline normal behavior, detect anomalous activities and provide real-time remediation across an organization’s entire IoT footprint. The patent-pending solution has a deep grasp of each IoT device’s personality, analyzing communication to and from every device, watching constantly for deviations in behavior and providing alerts for suspicious behavior,” May Wang added.

Kathleen Patentreger elected in PCI Security Standards Council

PCI-Security

Kathleen Patentreger, Senior Vice President of Programs, CIS (Center for Internet Security) has been selected to the Board of Advisors of the PCI Security Standards Council.

PCI Security Standards Council (PCI SSC) works on securing payments by providing data security standards and programs that help businesses detect, mitigate, and prevent cyberattacks and breaches.
Patentreger will join 28 other PCI Board members. They will act as strategic partners to bring industry, geographical, and technical insight to PCI SSC plans and projects.

“Kathleen is a proven leader in our industry with a strong resume of support for public-private sector entities. Her perspective leading dozens of volunteer communities from across the globe to build proven security benchmarks and cloud-based products will be a unique and valuable perspective to the PCI Board,” said Steven J. Spano, CIS President and COO. “Kathleen’s contributions will no doubt help raise the bar for PCI compliance across public and private entities,” he added.

“We need voices from across vertical industry sectors, countries, and regions to help ensure we are providing the best standards and the best protection against today’s modern cybercriminal. We’re pleased to have Kathleen Patentreger from CIS on the PCI SSC Board of Advisors to provide critical insights and help us build on the great efforts that are already being done to increase payment security globally,” said PCI SSC International Director Jeremy King.

New Cyber Security Laws Implemented in China

Chinese actors target telecom

China — in an attempt to counteract cyber warfare and data breaches — implemented a contentious new law that allegedly imposes strict requirements on data storage and scrutiny.

Approved in November of 2016 by China’s National People’s Congress, it prohibits service providers from recording and selling the personal information of Internet users. In the case of these prohibitions being violated, it also gives users greater information security rights, including requirements that their data be wiped clean.

A statement from the official Xinhua news agency states: “Those who violate the provisions and infringe on personal information will face hefty fines.” This is China’s first attempt to implement sweeping protections and regulations for the data of Internet end users. Previously, a wide range of uncoordinated laws and regulations has governed the Internet in China.

International corporations and trade organization had opposed the new Chinese regulations, at a minimum pushing for a delay in implementation, arguing that the new rules would hamper business activities on the Internet in China. There is widespread concern that the law is vaguely worded and gives wide latitude to Chinese authorities to gain access to data.

The claim is that the new laws might prevent foreign tech companies from being competitive in sectors that China has declared “critical.” There is specific concern about the fact that data possibly harmful to individuals if hacked is now required to be stored on China-based servers, which are subject to a security review by members the Chinese governmental agencies. There is fear that the intellectual property of international corporations may be put at risk.

The new requirements are especially onerous for smaller companies, since moving data to Chinese domestic servers and getting permission from Chinese authorities before moving large blocks of data abroad will be costly and hard to absorb in limited budgets. It also means some companies that don’t yet store information in China will have to reorient their data storage systems and incur the cost of setting up cloud-sharing services in China.

Inadequate budgets barrier to cyber security, U.S. Local Governments CIOs report says

Cybersecurity meeting, Biden Administration and Tech Giants, Zero-Trust Model

The ability of local governments across the United States to protect against cyber attacks is limited due to a shortage of funding. This is particularly troubling because not only do local governments hold a vast amount of data about individual citizens, but they are also the primary manager of U.S. elections. Given the ongoing investigation into possible Russian hacking of the 2016 election, this is a critical weakness in the cyber security of American government.

The recently released Cybersecurity 2016 Survey, sponsored by the International City/County Management Association (ICMA), contacted over 400 local government chief information officers (CIOs). The survey found that the number of cyber security incidents is on the rise. An increase in cyber attacks in the prior 12 months was reported by a third of respondents.

It also found that local governments couldn’t compete in the cyber security labor market, which is driven by the ever-expanding need for highly skilled information security professionals and the shortage of workers with those skills. This leaves local governments unable to keep up with the rising risk of cyber attacks.

Salaries are much higher in the private sector and it is widely believed this labor shortage will only worsen. After increased funding to pay better salaries, survey respondents highlighted the need for better cyber security policies. But this is a difficult task, since without experienced staff it is a challenging assignment to create better procedures.

A research associate at ICMA, Berna Öztekin-Günaydin, discussed in an interview with 21st Century State & Local steps that local governments could take. They include training current staff to raise their awareness of specific kinds of malware and other common violations of network security. Also, the inherent risks of using email and especially opening unknown files needs need to be stressed as a low-cost first step towards better information security.

Other steps that can be taken include creating a layered defense system that can recognize the different types of security risks that are faced, doing a thorough assessment of the government’s system to find potential vulnerabilities and better allocate what funding is available, doing regular testing and virus scans of the network system, and having backup and recovery plans in place in case of an incident.

Öztekin-Günaydin also stressed that local government should communicate with one another, sharing strategies, system improvements, and current threats. She stated that sharing best practices would help all cash-strapped governmental entities, and highlighted DeKalb County, Georgia, Las Vegas, Nevada, and Jefferson County, Alabama, as local governments on the leading of cyber security efforts.

Cisco, IBM team up to fight cybercrime

CISCO-IBM

Cisco and IBM have entered a partnership to combat global cyber threats. The major partnering wings will be IBM X-Force and Cisco Talos security.

As part of the partnership, Cisco will also build new applications for IBM’s QRadar. IBM’s Resilient will integrate with Incident Response Platform (IRP) and Cisco’s Threat Grid to help security staff manage incidents faster.

“By combining Cisco’s comprehensive security portfolio with IBM Security’s operations and response platform, Cisco and IBM bring best-of-breed products and solutions across the network, endpoint and cloud, paired with advanced analytics and orchestration capabilities,” said David Ulevitch, SVP and general manager, Cisco Security.

This isn’t the first time the two companies are working together. During the infamous WannaCry ransomware attack which crippled nations across the world, Cisco and IBM shared intelligence to fight the threat. The teams monitored spread of the malware and exchanged insights with one another.

Cyber Crime Leads to Sensitive Patient-Data Leak

Lapse in Pfizer’s Security Exposes PII of U.S. Prescription Drug Users

The network security of a cosmetic surgery facility in Lithuania was hacked by a group calling itself the “Tsar Team.”The group subsequently attempted to blackmail the company and the individuals whose personal information was released.

The refusal to pay the $800,000 ransom after the cyberattack resulted in the publication of 25,000 photos and sensitive patient data from the Grozio Chirurgija clinic in March of 2017. Some of the images released were nude photos of clients.

After the clinic’s owners refused payment, the hackers then attempted to extort money from patients whose personal information and images had been stolen. The data of individuals from over 60 nations was compromised in this information security breach.

“It’s extortion. We’re talking about a serious crime,”
said Andzejus Raginskis, the deputy chief of Lithuania’s criminal police bureau. Lithuanian authorities are coordinating with other countries’ security agencies. They also note that downloading and storing the data from this cyberattack is subject to prosecution.

The demands made on the individual victims were for payments anywhere from $65 to $2,600, based on how sensitive and embarrassing the stolen data was judged to be. In addition to nude photos, information attained in this cyberattack included individual’s insurance numbers and scanned images of passports. It has not been reported if any patients followed through with payments.

The initial blackmail request in this cybercrime was a demand for 300 bitcoins ($772,178) in return for releasing the contents of the clinic’s database. A subsequent request lowered the price to 50 bitcoins ($120,750).

Like the WannaCry ransomware attack that seriously compromised the U.K.’s National Health Service in May — and many other non-health related systems as well — cyber attacks on healthcare IT infrastructures are an increasing concern. Both the immediate safety of patients and their private information are being put at greater risk by a continuing string of network security breaches.

IBM announces cyber security workforce training

In the face of a projected shortage of technicians in the cyber security field, IBM has announced a new skills initiative. It is designed to reach more potential employees by targeting trainable skills and aptitudes, while deemphasizing academic training. The program is, according to IBM’s announcement, a new approach to “‘new collar’ cyber security workforce strategy.” One in five employees hired by IBM since 2015 were part of this wave of “new collar” employees.

With studies showing a global shortage of up to 1.8 million information and network security looming, many organizations both private and public are struggling to prepare for this crunch in the supply of workers.

IBM announced that it would be collaborating with Hacker Highschool, an open-source training program that states its mission is to provide “Cyber Security Skills for the Real World.” Increased investment in Pathways in Technology Early College High School (P-TECH) was also announced, along with funding for other training programs at alternative education institutions.

According to General Manager of IBM Security Marc van Zadelhoff, the cyber crime landscape is evolving rapidly, but many companies are approaching the issue in ways that haven’t really changed in the past two decades. He emphasized that the skills needed today are oftentimes not dependent on four years of traditional academic training and that innovative educational models needed to be emphasized.

It was also noted that only 11 percent of the cyber security workforce is made up of women. Clearly, an emphasis on recruiting and training young women is a priority in dealing with the ongoing shortage of workers in the field. Developing new hiring models and recruiting at a wider range of educational institutions were also goals that needed to be pursued, according to the IBM announcement.

Hacker Highschool will receive skilled guidance and access to IBM security tools as part of their skills lessons targeted at entry-level security operations center (SOC) analysts. The announcement emphasized that this position is in particularly high demand. Access to IBM Security QRadar software will be part of providing students with direct experience using a deep security analytics tool.