Home Blog Page 45

Cybersecurity Career Awareness: The Growth of Cybersecurity in IT Industry

cybersecurity career

The cybersecurity industry is a booming sector that promises technology growth and multiple career opportunities. This industry has proven its ability to grow even in challenging times of the global pandemic was contrary to other sectors that had shown a significant decline. The senate RPC report has stated that there is a 29% of skill gap for cybersecurity in the U.S., and with cybersecurity being the number one risk and finding the right talent is a concern for businesses. The gap between skill demand and supply is increasing day by day. Hence, it is imperative for the infosec community to discuss and spread awareness among the aspirants about various career options available and its demand.

By Rajiv Sharma, Vice President, EXL Service

Building a Strong Cybersecurity Workforce

Raising public awareness about cybersecurity career starts with understanding the new skill requirements and demand to build a strong cybersecurity workforce by the organizations. With the rise in sheer volume and diversity of cyberattacks, organizations are looking to bring effectiveness and efficiency in securing, testing, and continuously monitoring their digital assets. Automation of processes and up-skilling the task force are the need of the hour. This has led to a sharp increase in the demand for cybersecurity skills. Emerging technologies such as cloud computing and storage, IoT, blockchain, etc., have further increased skill demand due to the integration of technologies with the business processes, leading to a new attack surface for malicious users and hackers to target. Hence, hiring the talent to maintain and manage security posture has become equally important as having a robust architecture in place for information security.

See also: How to Learn Ethical Hacking from Scratch and Start Your Career

For organizations building a workforce involves planning, implementing, and assessing the cybersecurity readiness of their security workforce. Prior to establishing a workforce, organizations need to determine their risk exposure and risk tolerance, which influences the need to address their cybersecurity workforce gaps. The NICE framework for the cybersecurity workforce provides guidance to organizations on how to recruit cyber talent and develop professional opportunities for their cyber workforce.

Cybersecurity Career Demand and Opportunities

Cybersecurity roles are among the fastest-growing career opportunities available in the STEM field. The U.S. Bureau of Labor Statistics (BLS) jobs will grow 31% by 2029, which is seven times greater than the U.S. average growth rate for jobs. Hence, indicating that information security will be in demand as technologies keep evolving alongside the growth in cyberthreat. It could be safely assumed that the growth of cybersecurity jobs will be proportional to the increase in volume and diversity of the cyberattacks, which by the way, have grown over 50% since 2020 and are estimated to cost the world $6 trillion annually in 2021.

Hundreds of breaches each year and the loss of millions of records have tremendously increased the demand for information security posture and professionals to maintain it. The global pandemic has further boosted threat incidents, with reports highlighting the rise in cybercrime by 600% in the Asia Pacific alone due to its impact. This displays the fragile nature of the current security posture that is susceptible to different threat factors. To combat such malicious cyber intent, businesses need the assistance of professional expertise. Hence, making it is imperative for organizations to foster cybersecurity skills and talent alongside efforts for implementation of rigorous cybersecurity awareness programs, prevention and detection controls, and best practices. Multiple studies have indicated that security job roles and skills related to application development, cloud computing, incident handling, threat intelligence, risk management, security compliance and governance, data privacy, identity and access management, etc., are expected to grow the fastest in the near future.

Cybersecurity Career Pathways

There exist multiple job roles and career pathways for cybersecurity aspirants to choose from and pursue. In the era of Digital Transformation, emerging technologies and the constantly evolving digital security industry further add to these pathways that could be roughly be categorized in broad skillsets viz management, technical, and leadership.

  • Management: The security management category deals with tasks and roles associated with compliance and governance within the security posture. This area tends to be less technical, but it is, nonetheless, important for professionals in these positions to know the technicality behind cybers risk in order to manage them better. The roles and responsibilities in this domain call for the need to be business savvy and got skills programmatically manage the organization’s security posture. Awareness training, audits, compliance, IT risk management, including third-party risk management, project management, etc., are some of the functions involved with these roles.
  • Technical: As suggested, this pathway covers more technical roles such as diving deep into technicalities of systems, data, tools, networks, hardware, software programming, etc., with an aim to detect, prevent, respond, and mitigate cyber threats. These skills are essential in deploying cybersecurity solutions in an organization. Some of the prime roles of pathways could be listed as in the figure below.
  • Leadership: This position is of extreme importance as this connects security goals to that of business processes, hence playing a critical role in the success of the business. Some of the widely popular roles in this domain include CISO (Chief Information Security Officer), directors and managers, which includes thorough leadership skills at all levels.
Cybersecurity Career Pathway
Cybersecurity Career Pathway

The career pathway listed could be an exciting journey for aspirants as the entry to the security domain could be considered as interdisciplinary, i.e., any pathway or combination of roles could be adopted based on the market demand. As there is no set pathway, choosing accordingly helps individuals gain exposure to various technologies and processes, hence allowing them to work with what they are most comfortable to adopt rather than what is available in the mainstream. One skill set which is need of the hour and common to the above-listed areas is the aptitude to adopt automation i.e., to automate manual or repetitive processes through deploying Artificial Intelligence, BOTs, ML, or BIG Data.

The Untapped Potential of an Underrepresented Population

Diversity is the need of the hour, as a diverse team is most likely to make better business and security decisions compared to a non-diverse one. Workforce development frameworks should accommodate and promote increased participation from women, veterans, persons with disabilities, minorities, and other underrepresented populations. Diversity is purposeful and should be voluntarily worked upon and be committed to by organizations aligned to their business goals. Organizations should be mindful that any security initiative or operation should involve equitable representation of the underrepresented groups. A number of organizations are running with various diversity programs and conscious efforts have been made to tap cyber talent, to name a few WiCyS, NCI’s IWICS, Palo Alto, Purdue, EC-Council, Fortinet, Facebook, etc. Such organizations aim to increase the representation of women and veterans in cybersecurity, through various training and sponsorship opportunities.

Conclusion

With cybercrimes growing multifold in volume, the demand for corresponding cybersecurity skills is also increasing exponentially. The statistics suggest that cybersecurity careers will be in high demand in the upcoming decade, and may grow by 31% in the U.S alone. This provides individuals in both STEM and other fields to pursue a career in cybersecurity.


About the Author

Rajiv Sharma, EXLRajiv Sharma is currently the Vice President of EXL Service and has more than 25 years of experience in information technology, cybersecurity, information security governance and compliance, and disaster recovery and business continuity planning. His wide range of experience involves the identification of cybersecurity risks in an ever-changing cyber threat landscape, as well as designing/recommending, and implementing/establishing control environments to mitigate the risks. Rajiv has in-depth, hands-on experience in the field of cybersecurity risk and implementation across multiple industries like fast-moving consumer goods (FMCG), automobile, telecom, manufacturing, retail financial services (banking and capital market), insurance, and ITeS.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Security Intelligence Report: CISO Point of View – Analysis of Storage & Backup Security in the Financial Services & Banking Sector

storage and backup

Cyber-protected storage has been gaining more attention with all the news around data storage hacks, ransomware attacks, and immutable storage erased in the banking and financial services sector. In the security architecture, the storage and backup environment act as the last line of defense. The fact that so many victims eventually choose to pay the ransom gives rise to serious concerns about the market’s storage and backup security maturity.

 SPONSORED CONTENT 

Security Intelligence Report: CISO Point of View Fueled by the expansive media coverage and dramatic financial repercussions of data-centered crimes, organizations, vendors, and regulators alike are in a race to identify and close the gap. Intending to address this gap, a collaborated effort between CISO MAG and Continuity™ produced a structured survey to analyze the market maturity, challenges, and gaps. Conducted between June and August of 2021, the analysis of responses by banking and financial service experts revealed that very little work had been done to address the need for storage security.

Some of the key findings from the survey are:

  • More than two-thirds of the respondents believe an attack on their storage environment will have a ‘significant’ or ‘catastrophic impact.
  • Almost 60% of the respondents are not confident in their ability to recover from a ransomware attack.
  • The significance of securing storage and backup systems is widely recognized by Infosec and GRC teams alike. Over two-thirds of the respondents mentioned it had been addressed explicitly in recent external audits.
  • And yet, storage and backup systems are the two lowest focus areas of organizations’ vulnerability management programs.
  • Continuously changing priorities, organizational silos, and lack of skilled personnel were chosen to be the most prominent challenges to achieving practical storage and backup security.
Security Intelligence Report: CISO Point of ViewTo view the complete analysis and reportage, hit the download button now!

 

 

Unsecured Server Exposes Scraped Data of 2.6 Mn Social Media Users

2.6 Mn scrapped data exposed

Security researchers from Safety Detectives discovered an unsecured ElasticSearch server containing scraped social media profiles taken from Instagram and TikTok. The leaky database, which belonged to the social media analytics site IGBlade.com, reportedly exposed more than 2.6 million records of user accounts. The records contained screenshots and URLs to social media profile pictures and other forms of scraped personal data.

Data Exposed

IGBlade’s server contained different types of personal data, including users’ full names, usernames of social media handles, images, picture links, users’ bio, email addresses, contact numbers, location, media counts, followers count, and engagement rate metrics.

“IGBlade’s server was live and being updated at the time of discovery. The size of IGBlade’s breach suggests more than 2 million social media users could be immediately affected by the leaked content of the server. We found several examples of high-profile accounts on the server too. Prominent influencers, such as food bloggers, celebrities, and social media influencers, all featured. Public forms of data for huge, verified celebrity accounts, such as Alicia Keys, Ariana Grande, Kim Kardashian, Kylie Jenner, and Loren Gray, had all been scraped and stored on IGBlade’s open ElasticSearch server,” the researchers said.

Impact of the Leak 

The leaked content from the unsecured server could impact both the company and social media users. Threat actors often misuse scraped or leaked data for various cybercriminal operations like identity thefts and financial fraud.

Is Data Scraping Legal?  

Data scraping is a practice of extracting users’ private information from a website or social media platform without their knowledge, which is against the data privacy policy. Primarily, marketing agencies leverage social analytics tools like IGBlade for advertising purposes. Data scraping enables companies to obtain more user insights to plan their marketing strategies effectively.

Certain social media companies allow third-party vendors and web developers to scrape users’ data for market research purposes. However, some social media companies like TikTok and Instagram don’t allow data scraping methods on their platforms.

The discussion around data scraping practices has been making rounds for a while. While the security community feels the practice makes user data vulnerable, data brokers argue that scraping publicly available data is legal. Earlier, Facebook Ireland imposed legal action against two people in Portugal for scraping users’ personal information from their Facebook pages.

FIN7 is Running a New Fake Company Called ‘Bastion Secure’ for Ransomware Attacks

Skimmer, formjacking

Researchers at Recorded Future’s Gemini Advisory unit released an advisory revealing the hacking group FIN7’s malicious operations under the guise of a cybersecurity services firm Bastion Secure. Through this phony company, the group is recruiting IT specialists, to conduct pen testing and carry out ransomware attacks.

Researchers from the Gemini Advisory group posed as IT professionals and applied for the role of IT executives. They were asked to analyze tools and network files. The company appears legitimate as it has closely replicated other service companies in its recruitment process. They conduct a series of practice tests, which are typical for an IT position.

The motive is to hire pen testers, as system administrators, who would have the skill to map compromised corporate systems, perform network checks, and locate backup server files and components needed to initiate any malware attack.

FIN7 can use the dark web forum to get entry into the compromised networks but at a high price. Whereas recruiting its staff would make them execute the attack at a much lower cost without having to share the bounty.

What is Pen testing? 

A penetration test, colloquially known as a pen test or ethical hacking, is an authorized simulated cyberattack on a computer system, performed to evaluate the security of the system; this is not to be confused with a vulnerability assessment. The test is performed to identify weaknesses (also referred to as vulnerabilities), including the potential for unauthorized parties to gain access to the system’s features and data, as well as strengths, enabling a full risk assessment to be completed.

FIN7 and Ransomware 

The financially motivated Russian threat groups Carbanak and FIN7 have at times been used to refer to the same group. Per a Trend Micro release, organizations such as MITRE identify them as two separate entities that manipulate the use of the Carbanak backdoor in their attacks.

“However, the groups use not just the Carbanak backdoor but also other types of malware such as Pillowmint, a point-of-sale malware, and Tirion, which is said to be geared to replace Carbanak,” Trend Micro said.

The two groups focus on their areas of expertise and targets; Carbanak focuses on banking institutions, FIN7 targets food, hospitality, and retail establishments.

Since 2015, FIN7 has successfully pilfered data for more than 16 million payment cards, which have been sold on dark web forums and online marketplaces for stolen data.

Earlier, the group had set up “Combi Security” to recruit hackers to engage in a malware campaign with criminal intent.

Conclusion 

Ransomware incidents are making headlines every week. Sinclair Broadcast Group, Cox Media Group, JVCKenwood are some recent incidents reported in October alone.

There are visible efforts both at the community and policymakers’ level but not a solution yet. Experts have been reiterating the attacks will continue to grow; we need to have a better threat detection capability and incidence response plan in place. With the onset of global action plans to combat ransomware, it will be some time before we actually can taste the fruits.

DDoS Attacks in Russia Surge 2.5 Times in 2021

DDoS Attacks in Russia , RDDoS attacks, DDoS attack on New Zealand Banks

Russian state-sponsored threat actor groups are known for innovative attack techniques and malware campaigns, ruling the underground darknet markets with various cybercriminal activities. Russian attackers have extended their targets from small organizations to critical infrastructures across the globe. Surprisingly, the country that made the world concerned about cyberattacks is now facing constant security threats. The number of DDoS attacks on Russian organizations surged 2.5 times in 2021 compared to last year, a report from Rostelecom revealed.

In a DDoS attack, cybercriminals make a targeted network or service unavailable to its users by flooding it with unwanted incoming traffic from different sources.

DDoS Attacks in Russia

The report revealed that DDoS attackers mainly targeted finance, online trading, and public sector organizations. The most significant DDoS attacks were focused on organizations located in Moscow, accounting for 60% of the total number of incidents, with the highest power of DDoS attacks – more than 70 Gbps. The attackers continue to leverage already known techniques for organizing DDoS attacks and large-scale botnets to increase the power of attacks. The most common DDoS attacks reported were UDP flood, SYN flood, and fragmented packet attacks (FRAG), which are usually organized using botnets.

“The power and complexity of DDoS attacks are increasing every year. This is due to the active use of larger botnets by hackers. They consist of a multitude of devices, which are exploited with new vulnerabilities. In particular, in September, cybercriminals organized the largest DDoS attack using the Meris botnet, which is estimated to scale 200,000 devices. Such sophisticated attacks are already directed at well-protected organizations and companies, whose resources can only be disabled by a very powerful DDoS. For example, it can be banks, large industrial or energy enterprises, etc.,” said Timur Ibragimov, Head of Anti-DDoS and WAF Cybersecurity Services Platform Solar MSS of Rostelecom-Solar. 

DDoS Attack Trends in Russia

The Russian internet service provider Yandex recently sustained the largest DDoS attack in the history of the Russian Internet (RuNet). Security experts claim that the attack was implemented via a new botnet tracked as Meris. It was found that the DDoS attack power was more than 20 million requests per second (RPS), affecting over 30,000 host devices.

In terms of attacking trends, DDoS actors appear to be changing their game plans and are turning to ransom distributed denial of service (RDDoS) as a new ransom vector. In an RDDoS attack, cybercriminals either launch a DDoS attack and then demand ransom to stop, or they may ask for the ransom first by threatening with a DDoS attack if not paid.

DDoS Mitigation

To mitigate the risk of DDoS attacks, experts from Rostelecom recommended organizations and users detach web applications from the critical resources by deploying them in separate databases. Adding a Web Application Firewall (WAF) with the existing anti-DDoS solution also helps prevent data thefts or unauthorized intrusions.

Episode #16: Crisis Management and Resilience in Cybersecurity

Crisis Management and Resilience

Business cyber resilience programs fail when organizations are attacked, and there are certain reasons for this. Vanessa Vaughn Mathews, founder and Chief Resilience Officer of Asfalis Advisors works with many organizations across different sectors. She has also worked closely with corporate security departments to help them mitigate risks, conduct exercises, gain executive sponsorship, and establish the budget necessary to increase resiliency. In this episode, crisis management and business resilience expert Vanessa Vaughn Mathew shares her observations and offers some good advice and recommendations.

Vanessa has authored an article on this same topic and the article will appear in the November issue of CISO MAG.

Write to Vanessa here.

Vanessa Vaughn Mathews is the founder and Chief Resilience Officer of Asfalis Advisors. She has been on the front lines of the crisis management and business resilience profession throughout her career.

She is the first female in the state of Georgia to graduate with a degree in Homeland Security and Emergency Management, she has worked with a Tier 1 intelligence agency, Fortune 500 companies, and has received local, national, and international recognition for her work to restore business and community resilience.

She is a much sought-after speaker for conferences and professional events as well as civic and private sector initiatives.

As the Founder and Chief Resilience Officer of Asfalis Advisors, Vanessa has helped clients  in real estate, health care, information technology, transportation, logistics, professional services, and government to develop, validate, and maintain their business resilience programs.

 

Cyberattacks Rise in APAC Region, India Most Targeted: Acronis Cyber Readiness Report

Acronis Cyber Readiness Report, cyberattacks in India, cybercrime in India, India’s Private Sector

The comprehensive overview of the present cyberthreat landscape has changed drastically, with threat actors leveraging new hacking techniques more often. Besides, the pandemic gave additional opportunities to hackers in targeting users with various COVID-19 themed attacks. The global crisis has forced organizations and the remote workforce to encounter severe security challenges while transiting to the new normal. According to the Acronis Cyber Readiness Report 2021, more than 80% of organizations globally admitted they were unprepared to transition to remote work.

Attacks Growing in Record Volume

The Acronis report revealed that organizations across the APAC region are facing severe cyberattacks. The report revealed that companies in Singapore encountered the most phishing attacks (74%), followed by India (58%), and Australia (50.5%). Around 50% of Singapore companies suffered malware attacks last year, far above the global average of 36%, followed by India at 46%. At the same time, video conferencing attacks have declined globally since 2020 but are still reported by 46% of companies in India, 32.6% in Australia, and 23% in Singapore.

India Becomes Primary Target of Cyberattacks

The report found organizations in India were attacked most frequently, with 32% of IT managers being attacked at least once a day and 16% at least once an hour. The adoption of multi-factor authentication is also observed; however, it is picking up slower than expected in the APAC region.

India and Australia have the lowest adoption rates of MFA technology among IT managers, with 50% and 48% of respondents admitting they don’t use it at all or only use it on some accounts. Only a small number of security admins use MFA on all accounts – 26% in Singapore, 21% in Australia, and 18% in India.

Security Challenges Face by Organizations

The new normal has forced organizations to defend against rising remote attacks. While 68% of IT managers in Singapore reported that instructing employees on remote work is an additional challenge, 67% of remote employees in India reported Wi-Fi connectivity as a top issue.

The most technically challenging aspects for IT Managers

  • Enabling/instructing employees on remote work
  • Securing remote workers
  • Ensuring availability of corporate apps and networks
  • Software not working properly
  • Employees installing unauthorized software
  • Lack of hardware or hardware failure

The most technically challenging aspects for Remote Workforce 

  • Wi-Fi connectivity
  • Inability to use internal network and applications
  • Difficulty adding new devices to a corporate network
  • Using a VPN and other security measures
  • Lack of hardware or hardware failure
  • Lack of IT support

“The cybercrime industry proved to be a well-oiled machine this year – relying on proven attack techniques, like phishing, malware, DDoS, and others. Threat actors are increasingly expanding their targets, while the growing complexity of IT infrastructure holds organizations back. Only a few companies have taken the time to modernize their IT stack with integrated data protection and cybersecurity. The threat landscape will continue to grow, and automation is the only path to greater security, lower costs, improved efficiency, and reduced risks,” said Candid Wuest, Acronis VP of Cyber Protection Research.

U.S. Govt to Control Export of Cybersecurity Items to Regions with Despotic Practices

CISA VDP platform, U.S. export ban on cybersecurity items

The Commerce Department’s Bureau of Industry and Security (BIS) in the U.S. announced new policies to control the export of cybersecurity items to regions with despotic practices. Russia and China are the more popular names that are associated with such authoritarian practices.

The Biden government since its time in office, has been taking a stern stand towards the issue of cybersecurity and sanctioned a host of cybersecurity plans.

State-sponsored cyberattacks and espionage have been cresting and need to be contained. Per the announcement by BIS, the control would ban the U.S. companies from exporting and reselling software and hardware tools that are proliferating and nourishing the autocratic practices that use malicious hacking activities and human rights abuse.

Per the Commerce Department’s statement, “This rule establishes a new control on these items for National Security (NS) and Anti-terrorism (AT) reasons, along with a new License Exception Authorized Cybersecurity Exports (ACE) that authorizes exports of these items to most destinations except in the circumstances described.

The rule will become effective in 90 days and will effectively ban the export of “cybersecurity items” for National Security (NS) and Anti-terrorism (AT) reasons.”

It continues to state that these items warrant controls because these tools could be used for surveillance, espionage, or other actions that disrupt, deny, or degrade the network or devices on it.

This proposed ban also aligns the U.S. with the 42 European and other allies that are members of the Wassenaar Arrangement, which sets voluntary export control policies on military and dual-use technologies — or products that can be used for both civilian and military purposes.

The Wassenaar Arrangement (WA)

The Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies is a multilateral export control regime (MECR) with 42 participating states including many former Comecon (Warsaw Pact) countries established in 1996.

The Wassenaar Arrangement has been established to contribute to regional and international security and stability, by promoting transparency and greater responsibility in transfers of conventional arms and dual-use goods and technologies, thus preventing destabilizing accumulations. The aim is also to prevent the acquisition of these items by terrorists.

Participating States seek, through their national policies, to ensure that transfers of these items do not contribute to the development or enhancement of military capabilities which undermine these goals and are not diverted to support such capabilities.

In Perspective

The Pegasus spyware was one such incident, which highlighted the problem of surveillance in the name of national security. The spyware was extensively being used for snooping on activists, journalists, and politicians. The NSO Group Technologies, that created Pegasus spyware vehemently denied any involvement. It said it just creates the tool and sells it to governments and intelligence or security agencies, which use it for anti-terrorism surveillance and national security.

This proposed control will ban the misuse of these cybersecurity tools and help contain the widespread abuse at the hands of countries with malicious intentions.

Governments around the world are waking up to the need to collectively address the issue of cybersecurity and take joint action to curb cyberattacks. The White House National Security Council facilitated an initiative where 31 countries came together to deliberate the efforts to improve national resilience, addressing the misuse of virtual currency, laundering ransom payments, disrupting the ransomware ecosystem, and prosecuting the cybercriminals.

Concerted efforts like these must be pursued to address the global cybersecurity issue; countries must unite to disrupt the safe heavens which are sheltering the threat vectors if they do not want to see disruption in their critical services.

3 Digital Assets That Are High in Demand on Dark Web Forums

digital assets on dark web forums, Know the Worth of Your Data on the Dark Web Price Index 2021

The demand for trading sensitive stolen data and other malicious activities has reached new highs across underground dark web marketplaces. The global pandemic and related trends fortified various cybercriminals groups to extend their criminal activities. Today, threat actors trade from counterfeit money, stolen credit card details, and compromised login credentials.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Worth of Stolen Data on Dark Web

Most threat actors seek digital assets on dark web forums such as stolen information in exchange for cryptocurrency. Sometimes, the attackers encrypt victims’ personal data and threaten to leak it on the dark web in exchange for ransom. According to Dark Web Price Index 2021, personal data such as credit card details, online banking credentials, and social media logins are put up for sale on darknet markets at low prices. While online banking logins cost an average of $120, credit card details are available for $150 to $240.

Most Traded Data/Services on Dark Web

While various forms of data are traded on the dark web, some sensitive information is always high on demand. These include:

1. Financial Data

Sensitive financial data such as credit/debit card numbers and banking logins are always a primary target for cybercriminals. Threat actors and their affiliates often purchase this data from the dark web to break into users’ bank accounts and steal money. Regardless of the data type, the goal of cybercriminals is to seek financial advantage. A survey from Verizon unveiled that money remains the key motivator for cybercrimes, as 9 in 10 (86%) data breaches were investigated and proved to be financially driven.

Also Read: How to Protect Your Credit Card Data Online

2. Login Credentials

Attackers leverage stolen login credentials to break into user accounts or launch account takeover attacks. Threat actors often compromise user accounts using stolen credentials, leading to identity thefts and impersonation attacks. Threat actors target social media profiles to harvest sensitive information like images and full names, which is further utilized to compromise other user accounts. Earlier, the FBI issued a warning stating that people involved in such social media trends could be making themselves vulnerable to cyber fraud and scams. Fraudsters could exploit the information posted by users to reset account passwords and take control of the data stored within.

 3. Malware and Exploit Kits

Demand for exploit and malware kits on darknet forums increased dramatically. Cybercriminals and their affiliates purchase these tools to compromise websites by exploiting vulnerabilities, deploying malware, and carrying out other attacks.

Threat actors can easily buy and own malware and ransomware via underground message boards and dark web market networks. The easy availability of malware and malicious tools like ransomware builders, data stealers, Remote Access Trojans (RATs), and other viruses makes adversaries evolve and enhance their hacking techniques.

Conclusion

Your personal data will always be vulnerable, with dark web forums continuing to provide hacking requirements to attackers. It’s high time organizations and users realize the value of their personal data and how it can cause damage if it falls into wrong hands.

About the Author:

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

More from the Rudra.

 

Why Every Business Needs a Cybersecurity Incident Response Team

Incidence response

In order to get back on track from the ongoing pandemic, organizations have to take into account a completely altered reality, which is very different from what we’ve been taught so far. Many companies have restructured their business continuity plans to stay afloat during this unprecedented time. Many of these measures are not only point-in-time responses to the current crisis but are also expected to continue after COVID-19. With accelerated digitization across businesses, cyberattacks are becoming more sophisticated, precise, and targeted than ever before. To this, add the sheer volume of security alerts and false positives; it’s like searching for a needle in a haystack. The IT team is suffering from burnout, leaving organizations with hulking security risks and corresponding financial risks.

By Satya Machiraju, VP, Information Security, Whatfix

The threat of cybercrime is ever increasing and is having a significant impact on enterprises. To protect against cyberattacks, companies need to get back to the basics of security by design and integrating cybersecurity into their entire system life cycle. Almost every organization nowadays is vulnerable to being breached, whether it is due to its own security weaknesses or the weaknesses of its critical suppliers. Because of this, digital platforms need to be treated as critical infrastructure – a centralized mechanism for detecting and responding to security incidents should be put in place. If data or functionality are lost, it can be crippling, regardless of the threats. Having an incident response plan and disaster recovery plan allows you to minimize risks and prepare for a variety of events.

What is an Incident Response Team?

Incident response teams, also called incident response units, plan for and respond to IT incidents, such as cyberattacks, system failures, and data breaches. Additionally, these teams can develop incident response plans, identify and resolve system vulnerabilities, enforce security policies, and evaluate security best practices.

An organization’s incident response teams should be made up of subject matter experts from various domains/departments with reasonable authority and expertise to respond to an incident as soon as it is noticed. Organizations with an incident response team are able to handle incidents in a structured manner. Documenting and testing an incident response plan allows an organization to respond and recover from an incident faster, with minimal impact on its customers and stakeholders.

Incident Response Team: A Blueprint for Success

An average company generates around 30 GB of security log data that is close to 30,000,000 events per day. Almost all security operations teams find it challenging to separate the “Wheat from the Chaff” and thereby not being able to connect the dots to identify the critical chain of events resulting in breaches going undetected or not responded immediately. This is primarily owing to too many error-prone manual processes, lacking the highly skilled talent to solve all of this, and the inability of a human to crunch or process large chunks of data.

Automating incident response enables the security operations team to let tools or systems address the known issues with known resolutions. This allows them to focus on more critical issues or enhancements of the business. There are various commercial and open-source SOAR (Security Orchestration, Automation and Response) solutions that help the security teams in their journey towards automation.

SOAR is typically a collection of software solutions or tools that allow security teams to streamline security operations in threat and vulnerability management, incident detection and response, and security operations automation. SOAR allows security teams to collect threat-related data from a range of sources and automate the responses to the threat.

Building an Effective Incident Response Plan

In every industry, data breaches have become an inevitable part of doing business. For organizations to minimize damage, while also reducing costs and recovery times, it is important to have incident response plans in place. The use of incident response plans allows organizations to respond quickly and effectively to security incidents. In order to respond quickly to cyber incidents, organizations must develop a proactive and responsive set of capabilities as part of their incident response plans. The basic process could be summarized as follows:

  • Establish an Incident Response team
  • Identify your assets and crown jewels
  • Identify the threat vectors associated with your assets and crown jewels
  • Implement monitoring capabilities to identify the threats/attempts
  • Document your threat response guidelines
  • Document the incident communication processes
  • Train employees to be vigilant, to alert stakeholders
  • Test the Incident response plan
  • Document the learnings
  • Incorporate the learnings

An incident could have implications from legal, regulatory, privacy, and contractual perspective too. An inadequate or incorrect approach in handling an incident could have serious ramifications in the aforesaid areas. Having a team responsible for incident detection and response helps organizations and the workforce to be able to consult the subject matter experts for any specific suspicious activity thereby ensuring that immediate action is taken. The incident response team can also ensure that the response to suspicious activity or a breach is performed in line with the Incident response plan and would be able to address any situation that is not captured in the plan.

Securing the Digital Workforce

As a result of a mostly or entirely remote workforce, organizations are more susceptible to security breaches and less able to respond to potential security incidents. A remote workforce incident can be effectively handled by identifying the impacts, updating the incident response plan, and communicating the new plan with the incident response team. In light of increasing cyberattacks that threaten business operations and reputation, developing an effective Cyber Incident Response Plan (CIR) becomes essential for organizations to stay on top of the cybersecurity curve.


About the Author

Satya MachirajuSatya Machiraju is the VP of Information Security at Whatfix. Satya leads Whatfix’s security team by developing and deploying processes and solutions to minimize and mitigate cybersecurity and regulatory compliance risks. Satya is based in India and is passionate about protecting customers’ information, as well as creating a culture of cybersecurity preparedness across Whatfix by putting “security first.”

Satya brings over two decades of experience in cloud security and architecture, global cyber security and enterprise risk management, regulatory compliance consulting, information security strategy consulting, IT governance and project management, vendor and partner risk management, and privacy and regulatory compliance. Prior to Whatfix, Satya was VP/CISO at Qualfon, Senior Director of Information Security at [24]7.ai, and Senior Manager of Information Security at Aditya Birla Minacs Worldwide, Ltd.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.