Home Blog Page 65

CISA Unveils Joint Cyber Defense Collaborative to Boost Cybersecurity

CISA Unveils Joint Cyber Defense Collaborative to Boost Cybersecurity

The increase in the number of cybercriminal groups and ransomware cartels makes it difficult for organizations to stop the threat single-handedly. Cyber collaborations from public and private entities would help boost the nation’s cybersecurity landscape. After a series of high-profile attacks, the U.S. government announced that it is partnering with private tech firms to jointly bolster the country’s cybersecurity defenses.

The Cybersecurity and Infrastructure Security Agency (CISA) recently unveiled a new initiative —The Joint Cyber Defense Collaborative (JCDC)  — to improve cybersecurity planning and information sharing between public and private organizations, and combat ransomware attacks on cloud computing providers.  With the new authorities provided by the National Defense Authorization Act (NDAA) of 2021, the JCDC will bring public and private sectors together to implement and execute incident response plans to defend malicious activities against U.S. critical infrastructure.

Public and Private Collaboration

The JCDC’s representatives are from across the federal government, including the Department of Homeland Security (DHS), Department of Justice (DOJ), U.S. Cyber Command (USCYBERCOM), the National Security Agency (NSA), the FBI, and the Office of the Director of National Intelligence (ODNI). Organizations from the private sector include Google, Microsoft, Verizon, Amazon Web Services, AT&T, FireEye, Lumen, Crowdstrike, and Palo Alto Networks.

CISA director Jen Easterly stated the new cyber defense collaboration will collectively implement protective cybersecurity measures.

Easterly said, “Through the JCDC, we will coordinate cyber defense planning and operations by partnering with our interagency; state, local, tribal, and territorial governments and private sector stakeholders to improve cyber defense operations and prevent and reduce impacts of cyber-attacks.”

She further explained that the JCDC will:

  • Share insight to shape our understanding of cyber defense challenges and opportunities
  • Design whole-of-nation cyber defense plans to address risks
  • Support joint exercises to improve cyber defense operations
  • Implement coordinated defensive cyber operations

“The JCDC leads the development of the Nation’s cyber defense plans by working across the public and private sectors to unify deliberate and crisis action planning, while coordinating the integrated execution of these plans. The JCDC aims to prevent adversarial attacks through the execution of cyber defense operations plans. Such plans will promote national resilience and facilitate the disruption of malicious cyber activity targeting U.S. critical infrastructure or national interests,” CISA stated.

Ransomware Reality in 2021: Victims Paid Up to $45 Million in Payouts

Ransomware Attacks, Graff ransomware attack

A 2021 report from Atlas VPN pegs ransomware cost to victims at $45 million in 2021. The year also boasts of some largest payouts made by victims.

In a ransomware attack, threat actors exploit the system vulnerability, encrypt data, block or lock users and demand payment. These are digital demands through cryptocurrency in exchange for the decryption key. And as the attacks get viler, the modus operandi is to steal sensitive data and threaten to publish it on the dark web, invoking panic and triggering mayhem at the victim’s end, in turn forcing them to give in to the ransomware demand.

Leading payments

  • Conti, REvil/Sodinokib, DarkSide and RagnarLocker were the much talked about ransomware groups that extorted millions from the victims.
  • Conti ransomware group received the most payments in ransom, nearly $13 million, due to its double extortion technique, which not only encrypts data but also threatens to leak it online.
  • The second on the charts is the Russia-based REvil/Sodinokibi group, which extorted $12.13 million in 2021 alone. REvil is one of the most prominent ransomware-as-a-service provider (RaaS).
  • The DarkSide group extracted $4.67 million in ransom. They announced their RaaS in August of 2020 and became known for their professional operations and large ransoms.
  • Close at heel were RagnarLocker at $4.54 million and MountLocker at $4.22 million in ransom from the exploits.

William Sword, cybersecurity writer and researcher at Atlas VPN, opined, ”Cybercriminals can shut down huge organizations, highlighting a massive issue — many companies have left their infrastructure and cybersecurity vulnerable to hackers. Businesses must take responsibility and secure their systems before hackers can launch even more disruptive attacks.”

The Ransom Loot

Large organizations, essential services, and infrastructures across the globe have been thoughtfully targeted to cause significant disruption and loss to business and brand image. Few names that continue to be quoted as examples for their colossal payouts are JBS USA, Colonial Pipeline and Exagrid.

The world’s largest meat producer, JBS suffered a ransomware attack, which disrupted its meat slaughter operations, and the company was forced to shut down some of its food production sites on May 31, affecting thousands of employees. The FBI attributed the attack to the REvil group. In a media statement, JBS confirmed paying a ransom of $11 million (301 Bitcoins).

The  DarkSide ransomware attack on Colonial Pipeline cost the organization $4.4 million (75 Bitcoins). Due to the attack, many Americans had to deal with gas shortages and price spikes for weeks. Joseph Blount, Colonial Pipeline’s CEO, said, paying ransom is “highly controversial.”

Backup appliance maker Exagrid paid $2.6 million (50.75 Bitcoins) to Conti ransomware hackers. 800GB of data related to employees, customers, and other confidential information was at stake. Hackers threatened to sell the stolen data on the dark web if Exagrid did not pay the ransom.

While ransomware attacks continue to wreak havoc and disrupt businesses, the defenses too need to evolve and effectively detect the new strains to avoid further damage. With evolving technologies, organizations need to have strong end-to-end security with a zero trust approach.

How a 12-Year-Old Path Traversal Flaw Went Unnoticed

Log4Shell

Security issues and unpatched vulnerabilities in Wi-Fi devices like routers enable threat actors to infiltrate into other vulnerable IoT devices in the same network. An analysis from security firm Tenable uncovered a 12-year-old vulnerability in the web interface software of Arcadyan and Buffalo routers. Tracked as CVE-2021–20090, the vulnerability is a path traversal bug that allows a remote attacker to bypass authentication to the web interface and compromise the vulnerable devices, affecting millions of users globally.

Over 20 routers and modems across 17 different vendors were discovered, including 13 Internet Service Providers (ISPs) used in Argentina, the U.S., Australia, Canada, Germany, Japan, New Zealand, Mexico, Netherlands, Russia, and Spain. Almost all routers identified by Tenable are affected due to CVE-2021-20090. Attackers can leverage this vulnerability to obtain authorized access to other devices on the same home/corporate network.

“Consumers shouldn’t have to worry whether the device provided to them by their ISP is secure or vulnerable to attack. We’re reliant on providers to sell quality equipment that’s secure by design. Hopefully, the vendors affected by this vulnerability will take steps to mitigate the impact of these vulnerabilities on their products and customers,” said Evan Grant, staff research engineer at Tenable.

The Flaw Went Unnoticed for 12 Years

The vulnerability going unnoticed for more than a decade indicates that the manufacturers or vendors did not perform their due diligence before sending it to the consumer market. The researchers stated the issue could have been identified by a thorough review of the web interface code, which was not done in this case. If this vulnerability had been discovered by a cybercriminal, the damage could have been worse.

End Users at High Risk

The vulnerability has left millions of home and corporate routers at risk. The rise of consumer IoT devices enabled users to share their personal information with online businesses and services. The use of IoT and other remote working tools has been increased with the rise in distributed work culture. So, the CVE-2021–20090 flaw affects home and corporate networks, exposing organizations’ critical systems to supply chain attacks.

“This type of supply chain risk is particularly concerning given the prevalence of remote work. Consumer devices are being used to conduct business operations. Now, employees’ home networks are an extension of the corporate attack surface and home routers are the virtual gateway,” Grant added.

“I am eagerly waiting for more innovation in incident response and supply chain security”

innovation

According to Israel National Cyber Directorate, Israeli cyber companies raised $3.36 billion in the first half of 2021, an amount that constitutes about 41% of the total recruitment in the world, in about 50 transactions. This figure stood at $1.2 billion in 2020. It highlights that a third of the world’s cyber unicorns are represented by seven Israeli cyber companies. As venture capitalists have a field day with easy cash flows for these cybersecurity startups, we see these ventures looking for disruptive innovation in ideas and the people who will lead.

In an exclusive interaction with Minu Sirsalewala, Editorial Consultant at CISO MAG, Ryan Gurney, CISO-in-Residence, YL Ventures, shares insight on the booming cybersecurity startup industry, his role as a newly appointed CISO-in-Residence, and what areas of innovation are seeing heightened activity.

As a full-time CISO-in-Residence, Gurney will work directly with entrepreneurs pre-and post-investment, supporting their ideation processes, highlighting greenfield market opportunities, validating their value propositions, refining go-to-market strategies and optimizing their early-stage success in closing paying customers.

Prior to joining YL Ventures, Gurney was the former Chief Security Officer (CSO) at Looker, a business intelligence software and Big Data analytics platform acquired by Google for $2.6B, now part of the Google Cloud Platform. Prior to the acquisition, he served as Looker’s CSO, leading security and compliance and helping Google and Looker integrate and centralize key security processes post-acquisition. Previously, Gurney led all security functions at Zendesk in his role as VP of Information Security, where he played a key role in the company’s successful IPO. Additionally, he held security leadership roles at Engine Yard, eBay and PwC.

Edited excerpts of the interview follow:

In your varied leadership roles, right from PwC, eBay, Engine Yard, Zendesk, Looker (now part of Google Cloud Platform), and now YL Ventures, how has the journey been? How has the cybersecurity landscape evolved over the years?

It has been a highly rewarding journey and a privilege to work with such innovative companies and leaders. The cybersecurity landscape has really grown since I began my career. When I started, the CISO role was still relatively new.  It is reassuring to see how vital companies feel about it now and how far the security industry has come as a whole.  It is also pretty inspiring to see so many brilliant minds rise to the occasion and tackle the hard security problems companies struggle with today.

What brings you to YL Ventures as a CISO, and what piece of advantage do you bring to the table?

I had already been working with YL Ventures as a Venture Advisor for a number of years consulting seed-stage cybersecurity entrepreneurs on their early product and market strategies.  My industry experience, especially as a cybersecurity leader and often target-customer, gave the entrepreneurs I worked with vital insight into customer needs, preferences, and decision-making. Joining YL Ventures in this new role allows me to do that in a far more involved and hands-on way.

This seemed like the most natural and meaningful step for me to take at this point in my career. Following Google’s acquisition of Looker (where I was the CSO), I spent a year helping transition our security program over.  Once that was complete, I took some time off, and had a desire to do something different.  I had always enjoyed advising and investing in startups and now wanted to understand more closely the business aspects of how a VC firm operates. At YL Ventures, the CISO-in-Residence role provides a perfect platform for me to provide value and learn the business.

Hopefully, I can offer a wealth of first-hand knowledge through my time as a CISO at various fast-paced, engineering-focused SaaS companies.  Specifically, I’ve scaled high-growth companies and teams, been a part of multiple acquisitions, seen companies fail, prepared a company for a successful IPO, and been acquired by a heavyweight company like Google. In each role, I’ve managed product feature development and budgets that required critical due diligence when it came to selecting what vendors I partnered with. Entrepreneur access to this kind of knowledge and experience can dramatically accelerate their company journey.

What traction do you see in the cybersecurity startup space today? What are some of the frontiers/opportunities that you are looking for in this space?

There are so many opportunities, and it has been exciting to talk to passionate founders and hear how they are innovating and disrupting traditional security approaches. Our recent, joint-published CISO Survival Guide, on which we partnered with Cisco Investments, Forgepoint Capital, and Norwest Venture Partners, outlines four areas that I am particularly interested in at the moment – namely SASE, DevSecOps, Privacy Engineering, and Security Automation. I am also eagerly waiting for more innovation in incident response and supply chain security.

As per ‘The Rise of Global Cybersecurity Venture Funding’ report, Israel is the second leading country after the U.S. with over 20% of the country’s venture funding finding its way to cybersecurity companies in 2020. Is that a result of the pandemic for a sustainable growth model? 

Israel has been a hotbed of innovation in security for years, and that can absolutely be attributed to a sustainable growth model.  The combination of mandatory military service (and the cyber education received), constant threat from known and active adversaries, national interest in producing top technical talent, and a relatively small population size (leading to a tight-knit community) results in an extraordinary ecosystem for cybersecurity startups to thrive.

When it comes to disruptive technologies, what kind of startups interest you? Which areas of cybersecurity are seeing increased adoption?

Adoption tends to be reactionary and fluctuates according to what is in the news.  Recent breaches associated with supply chains and ransomware have led to more companies investing more dollars in third-party risk and compliance, identity management, EDR/XDR, Zero Trust / SASE technologies.

There is a noticeable shortage of cybersecurity professionals. How big is the problem and how can this gap be bridged?

It is a huge problem, and it is not improving at the rate the industry needs. There are way more job openings than dedicated security professionals available, and that gap seems to grow with every public data breach announcement as executive boards react. For years, we have acknowledged that an important solution lies in automating our security stacks, but it is also time to recognize that security is everyone’s responsibility and delegate more security-related tasks to other departments within an organization. Finally, security leaders must be willing to take chances on hiring and mentoring those that may not have traditional security experience but are eager to learn.  It is imperative that security leaders take the time to get to know employees outside the security organization who may be interested and have the aptitude to become great security professionals.

There is much talk around API security and management. Can you share your thoughts on the changing landscape and current challenges?

APIs have long been a difficult challenge for CISOs to manage. With increased cloud adoption, specifically SaaS, CISOs have lost visibility and control over how these applications are being configured in their environments. They are blind to who has access, what data is housed, and how APIs are being managed.  This can make it challenging to protect data properly and defend their organizations against third-party data breaches. Rising up to the challenge, we see an increase in API security startups and tools that attempt to address these risks. We have even invested in a few ourselves, including build.security and Grip Security,  who are addressing API authorization and SaaS discovery challenges. And we will continue to talk to founders about other API management ideas to further improve the space.

With remote working as the new norm, compromised IoT devices are an obvious threat. How can we mitigate this risk, and how foolproof is this approach?

This is an interesting question because it can affect industries differently. In any case, IoT devices have always been a challenge to secure as they were not traditionally designed with security in mind. They are often fairly lightweight, and in some cases, not easily patched if a security vulnerability is discovered.  Their lightweight nature also makes it difficult to add additional controls, such as encryption, access control, or deeper logging and monitoring. Companies today attempt to secure IoT devices instead through a combination of approaches, including network segmentation, authentication, patching, and encryption. However, managing and coordinating the activity necessarily is challenging without tooling.  Startups, including our portfolio company Medigate, which provides a dedicated security solution for medical devices, are innovating this space with the promise of asset management to manage the important risks that these devices place on their administration.

Medigate’s journey is an excellent example of how IoT is transforming traditional sectors; the healthcare industry received quite the shock as COVID-19 accelerated our dependence on personal and connected devices to manage health. This includes laptops, cellular phones, tablets, and a range of remote patient monitoring devices – everything from an Apple Watch to a device used to treat chronic disease. As hospitals bureaucratically catch up to the digital age, more of these devices are attempting to connect to unprepared healthcare networks from unsecured sources. This lack of preparedness cannot go on, considering the sensitivity of the data stored in such organizations.

What are some technology business drivers and strategies that are affecting or influencing innovation in the security realm?

As I mentioned, publicly reported attacks are key drivers of cybersecurity industry innovation. However, we have also seen a heavy influence from emerging regulatory requirements and the COVID pandemic as well. A significant increase in ransomware attacks has led to more conversations about least privilege access, especially on authorization, zero trust access, incident response, supply chain management and business continuity practices. GDPR single-handedly transformed the regulatory landscape and increased interest in “privacy by design,” leading to more founders exploring data discovery and privacy engineering solutions. Finally, the COVID-19 pandemic forced companies to revisit, and in some cases, completely reorganize their distributed workforce practices.  This has allowed for more urgency and dialogue around remote employee security, zero trust principles and SaaS security — the latter of which is finally being addressed by our latest portfolio company, Grip Security.


Minu

About the Interviewer

Minu Sirsalewala is an Editorial Consultant at CISO MAG. She writes news features and interviews.

 

 

 

 

 

After Power Sector, Chinese Threat Actors Prey on Telcos in Southeast Asia

Chinese actors target telecom

Threat actors often target high-profile organizations in critical sectors to spread their attack vector to a larger extent. From power plants to food processing units, cyberattacks on essential services have been increased in recent times. Security experts from Cybereason Nocturnus discovered three different malicious campaigns targeting multiple telecommunication companies located across Southeast Asia since 2017.

Tracked as DeadRinger, the three campaigns are focused on obtaining sensitive information by compromising critical digital assets like billing servers and Call Detail Record (CDR), including network components like Web Servers, Domain Controllers, and Microsoft Exchange servers. Cybereason linked the campaigns to three Chinese threat actor groups, namely Gallium (also known as Soft Cell), Naikon APT (also known as APT30 and Lotus Panda), and TG-3390 (also called as APT27 and Emissary Panda).

Attackers are leveraging advanced techniques to maintain persistence on the compromised devices and changing their hacking tactics to evade security detections. Successful compromise of the telecom networks enables attackers to perform various attacks, including credential theft, network reconnaissance, and data exfiltration.

The main activities of the campaigns include:

  • Reconnaissance and information gathering about infected hosts
  • Reconnaissance activity to collect information about the endpoint and network
  • Searching for security tools and attempting to disable or kill their processes
  • File and process manipulation
  • Execution of arbitrary commands
  • Privilege escalation
  • C2 communications using raw sockets
  • RC4 data encryption for communication between the C2 and the target

Three Groups One Target

Despite targeting as three individual groups, the campaigns share similarities in various aspects. Cybereason’s researchers suspect that the three groups are working under one cybercriminal group.

“In some instances, all three clusters of activity were observed in the same target environment, around the same timeframe, and even on the same endpoints. At this point, there is not enough information to determine with certainty the nature of this overlap — namely, whether these clusters represent the work of three different threat actors working independently, or whether these clusters represent the work of three different teams operating on behalf of a single threat actor. Regardless, we do offer several plausible hypotheses that might account for this observation,” Cybereason said.

Chinese Hackers Target Indian Power Sector

In the recent past, security research from Recorded Future found a China-linked threat actors group, dubbed RedEcho, targeting 12 Indian organizations, 10 of which were in the power sector. The researchers uncovered a subset of the servers that share familiar tactics, techniques, and procedures (TTPs) with several previously reported Chinese state-sponsored groups. Read More Here

Federal Agencies Score Poor in Securing Sensitive Data: Senate Report

Russian hackers, Senate Homeland Security Report, Electronic Warfare Associates

Companies lose trust when they fail to protect user data or implement necessary security advancements. Organizations bear the blame whenever attackers exploit unpatched vulnerabilities or compromise sensitive information.

A report from the Senate Homeland Security and Governmental Affairs Committee in 2019 found severe cybersecurity gaps in eight government entities, which failed to address unpatched vulnerabilities and protect users’ personal data. However, the 2021 update revealed that the agencies had made only limited security improvements in two years.

The report further stated that, of the eight federal agencies that underwent security audits – the State, Transportation, Agriculture, Health & Human Services, Housing & Urban Development, Education, and the Social Security Administration —  only the Department of Homeland Security showed improvements in 2020.

The report also stressed the rising cyberthreats from state actors across Russia and China. “It is clear that the data entrusted to these eight key agencies remain at risk. As hackers, both state-sponsored and otherwise, become increasingly sophisticated and persistent, Congress and the executive branch cannot continue to allow (personally identifiable information) and national security secrets to remain vulnerable.”

Key Findings

  • Seven agencies failed to maintain accurate and comprehensive IT asset inventories, failing to protect users’ sensitive information.
  • Six agencies operated systems without current authorizations to operate.
  • Seven agencies used legacy systems or applications no longer supported by the vendor with security updates.
  • Six agencies failed to install security patches and other vulnerability remediation controls.

Commenting on the rising threat landscape and the security posture of the government agencies, Senator Portman said, “From SolarWinds to recent ransomware attacks against critical infrastructure, it’s clear that cyberattacks are going to keep coming and it is unacceptable that our federal agencies are not doing everything possible to safeguard America’s data.”

“This report shows a sustained failure to address cybersecurity vulnerabilities at our federal agencies, a failure that leaves national security and sensitive personal information open to theft and damage by increasingly sophisticated hackers. I am concerned that many of these vulnerabilities have been outstanding for the better part of a decade – the American people deserve better. In the coming months, I will be introducing legislation to address the recommendations raised in this report so that America’s data is protected,” Portman added.

High-profile security incidents like SolarWinds supply chain attacks and Microsoft Exchange hacks represent the state of risks posed by federal agencies. Enhancing cybersecurity standards with updated incident handling measures will certainly strengthen network security.

A CEO’s Guide to Cybersecurity

CEO, cybersecurity, CISO, Future of the CISO

Agile methodologies and cloud-based services and models have become popular, and in accordance with this change, the c-suite has restructured processes within their organizations. Microservice architectures are facilitating super-fast delivery of even large, intricate, multi-faceted applications. There is a rise in DevOps teams going the continuous integration/continuous delivery (CI/CD) way to stay flexible, scalable, and relevant. However, these changes are presenting Chief Executive Officers (CEOs) with both opportunities and security risks. Traditional controls need a revamp to meet fast-changing cybersecurity requirements.

By Ram Mohan, President and CEO of Infrastructure Management and Security Services Business Division, Happiest Minds Technologies

The COVID-19 pandemic has further accentuated the role of CEOs in securing the enterprise. Maintaining the security of their network in this digitally advanced age is becoming challenging, but a truth that cannot be avoided. Hence, senior executives must develop a strong foundation of security realities and make sure the organization is prepared to identify and defend cyberthreats.

Cybersecurity Threats Lurking in Every Organization

External threats to organizations are increasing in the form of malware and ransomware. Virus attacks carry the potential of self-replicating throughout the network. Cybercriminals have also been using spyware to secretly track and collate user information. CEOs need to be aware of these threats and invest in advanced endpoint security solutions. In addition to making software updates and patches mandatory, leadership teams should run effective awareness programs to train employees to identify suspicious behavior on their devices and distinguish between genuine and spam or phishing e-mails.

Considering the significant growth in the number of internal attacks, the importance of training and awareness programs cannot be stressed enough. Social networking sites and platforms have further increased this risk. Cyber awareness workshops can help avoid accidental leakage of confidential information, the company’s intellectual property (IP), customer credentials, and other private information to the external world.

Proper, ethical usage of software licenses is extremely important. Decision-makers should ensure the enterprise has the right controls to block non-secure downloads. Users should be made aware of the consequences of downloading pirated and illegal software versions—the way it can ruin the reputation of the brand, cause legal and financial complications due to lawsuits, etc.

Adherence to the General Data Privacy Regulation (GDPR) and various country- and state-specific mandates that safeguard user and data privacy is becoming quite a challenge for organizations. While having legal counsel on board is a must, it is time that CEOs also stay up-to-date on the constantly evolving regulations and drive necessary changes across the organization. Protecting personally identifiable information (PII) of customers and employees should be considered a moral obligation. The goal should be to fully secure the enterprise and implement security best practices to eliminate privacy breaches. Proactively establishing robust data protection controls and having a strong incident response plan will help improve the organization’s security posture.

Digital Transformation in the Pandemic Era

Quite a few companies have transitioned from need-based work-from-home options to a 100% remote workforce due to the pandemic. This, however, seems to be an ideal environment for hackers and cybercriminals. There has been an increase in cyberattacks, phishing campaigns, cyber espionage, and other interruptions to business. While it does look like the pandemic is here to stay a little longer, business leaders need to be prepared for continued work from home and other new situations caused by COVID-19.

Investments in Secure Access Service Edge (SASE), zero-trust network access (ZTNA), and other cloud-based security models are witnessing increased adoption. CEOs need to make the right investments that will not only offer the highest level of security but also offer ease of use and uninterrupted access to authorized assets and applications, irrespective of user and application location.

Cybersecurity should be considered a crucial element in digital transformation initiatives. DevSecOps embeds security at every step in the software development lifecycle, and business leaders must give this concept serious thought. A change in mindset toward security investments as business enablers and innovation accelerators will help organizations realize the complete benefits from new initiatives. By embedding security into every new system, process and application, and streamlining risk-modeling practices, teams will be able to proactively mitigate and manage cyberthreats before damage is caused to the business — its users, data, and reputation.

Board-level Cybersecurity Discussions for Better Threat Management

The CEO should make sure a risk management committee is constituted at the board level where IT and information security threats, risks, and mitigation plans can be discussed. Constantly assessing risks and then communicating derived insights during board-level meetings helps plan security management budgets and investments better. Engaging in these discussions at the leadership level offers all decision-makers a better understanding of how their respective departments contribute toward the enterprise’s overall cyber risk. Business leaders should be fully aware of the security challenges that can affect the organization and its stakeholders. They should be prepared to address and mitigate known and unknown cyber threats and attacks that can impact the business.

Awareness of the organization’s risk posture can help CEOs and Chief Information Security Officers (CISOs) define an effective risk management policy. It can enable them to rethink and reallocate security spends wisely. It is the right time to automate, fast-track, and redefine the threat defense lifecycle to counter sophisticated cyberattack vectors. The c-suite should set up top-down cybersecurity policies so that every participant consciously contributes toward lowering cyberthreats and risks.

The Way Forward

A pandemic in the digital era has offered social engineering fraudsters and hackers the desired environment. But it has also driven C-suite executives to relook at their digital transformation initiatives and restructure them to include security as an essential element of everyday operations. The challenging time calls for stronger collaboration between CEOs, CISOs, and other decision-makers in the organization. They need to act fast—invest in powerful cybersecurity tools and technologies, traverse the DevSecOps path if they haven’t done so yet, upgrade the organization’s cybersecurity insurance, and drive awareness to have cybersecurity-aware employees and leaders.


About the Author

Ram Mohan is currently working as President and CEO of Infrastructure Management and Security Services Business Division in Happiest Minds Technologies. He is also a member of the Executive Board of Happiest Minds.

Prior to Happiest Minds, Ram was EVP and Global Head of IMS, Enterprise Integration, Mainframe services and APAC business in Mindtree Ltd. He was CISO for Mindtree and also was responsible for Automation Initiative across the organization. He is the winner of the coveted Chairman’s award in Mindtree and is a CSO 100 award winner.

Ram has 30+ years of experience in Infrastructure Management and Tech Support. He has been in senior management positions for the last 20 years. Ram also worked in the Support division of Wipro for 11 years in various capacities from customer support to business development. He helped the formation of Wipro’s Global Support division in 1997, now the Global Infrastructure Services division.

Ram holds a Bachelor of Electronics Engineering degree with distinction from Bangalore University.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Suffered a Data Breach? Here’s the Immediate Action Plan

data breach

Sensitive information is like money to cybercriminals. Attackers leverage personally identifiable information (PII) exposed in data breaches to launch various cyberattacks or trade it on darknet forums, affecting organizations and users in multiple ways. Organizations must boost their data security to avoid severe repercussions from data breaches.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Cost of a Data Breach

Hacker intrusions, insider threats, and accidental data leaks affect organizations in multiple ways. From identity thefts to brand damage, the impacts of data breaches are severe. According to a survey from IBM, data breaches cost businesses over $4.24 million per incident. The survey also observed that security breaches became more prevalent and difficult to thwart during the pandemic. The sudden shift to the distributed work environment and the majority of the organizations moving to cloud operations led to more expensive data breaches.

How can we prevent data breaches?

1. Monitor Digital Infrastructure

Cloud environments have seen a surge in recent times as most organizations are moving to cloud computing. Since these virtual servers carry large amounts of corporate data, continuous security monitoring is necessary to find if the servers have any vulnerabilities, misconfigurations, or other security issues. Besides the cloud environment, organizations need to ensure all the devices and the network systems associated with the corporate network are secure and able to defend against any authorized intrusion.

2. Perimeter Defense

Employ penetration testers to determine the strength of your internal network defenses. Performing regular security audits to find gaps in the organization’s networks and mitigating them will eventually boost the overall security posture.

3. Educate Your Staff

We can’t ignore employees while talking about the organization’s security. In addition to cloud misconfigurations, multiple data leaks have been reported due to employees’ inadvertent actions or errors. Training the workforce on what to and what not to click/download; identifying phishing emails and messages; spotting suspicious activity in the system will help prevent authorized intrusions.

What should a company do after a data breach?

1. Notify

Notify your clients, customers, and the data privacy authorities after sustaining a breach. Rather than covering up or delaying, reporting a security incident immediately after it happens helps organizations in damage control and regaining customers’ trust.

2. Investigate

Having a disaster recovery plan would help organizations restore the affected operations during these situations. Engage cybersecurity experts or a digital forensic team to investigate what data has been breached and how many are affected. Inspect the data leak to identify the root cause and the perpetrators responsible for it.

3. Damage Control

Isolate the critical systems and suspend all the operations temporarily after discovering the breach to limit hackers’ access to the corporate data. Access to the leaked data could lead to phishing and ransomware attacks. Ensure your employees and customers know the effects of a data breach and ask them to be vigilant while responding to unknown emails, messages, and calls.

Conclusion

From exploiting vulnerabilities to launching phishing and social engineering attacks, threat actors leverage various attack vectors to obtain sensitive information. It is high time organizations strengthen their security capabilities to defend against evolving threats, as no one is immune to security incidents.

 About the Author:

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

 

Read More from the author.

CISA Provides Details on Top Routinely Exploited Vulnerabilities in 2020 and 2021

Vulnerabilities in Zimbra

Organizations can boost their overall cybersecurity posture by regularly updating their network systems and patch vulnerabilities. Understanding how attackers leverage malicious techniques and the security gaps to exploit flaws and bugs will help businesses develop better defensive measures to thwart evolving threats. Several international cybersecurity agencies stated that threat actors are targeting publicly known or existing flaws to break into organizations’ network systems.

Recently, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre (ACSC), the U.K. National Cyber Security Centre (NCSC), and the FBI published a joint cybersecurity advisory listing the top exploited security flaws in 2020 and 2021. The advisory provides technical details of over 30 vulnerabilities that are constantly exploited by cybercriminals.

Top Routinely Exploited Vulnerabilities in 2020:

Top Routinely Exploited Vulnerabilities in 2020:

Top Routinely Exploited Vulnerabilities in 2021:

The advisory stated that threat actors mostly targeted security flaws in perimeter-type devices in 2021. These include:

Microsoft Exchange

CVE-2021-26855

CVE-2021-26857

CVE-2021-26858

CVE-2021-27065 

Pulse Secure

CVE-2021-22893

CVE-2021-22894

CVE-2021-22899

CVE-2021-22900

Accellion

CVE-2021-27101

CVE-2021-27102

CVE-2021-27103

CVE-2021-27104

VMware

CVE-2021-21985

Fortinet

CVE-2018-13379

CVE-2020-12812

CVE-2019-5591

Inconsistent Patch Management

The federal agencies stated that most of the vulnerabilities stemmed due to the distributed work environment amid the COVID-19 pandemic. The increased use of remote working tools like virtual private networks (VPNs) and cloud computing environments become an additional burden to security admins, making it difficult to keep pace with the regular patch management procedures.

Mitigate Risk 

The best way to mitigate the vulnerabilities is to update the systems with the latest software versions whenever they are available. In case the patch is unavailable, apply temporary fixes provided by the vendor to mitigate the risks. Addressing the critical vulnerabilities on priority will help to defend against potential cyber intrusions.

“Cyber actors continue to exploit publicly known—and often dated—software vulnerabilities against broad target sets, including public and private sector organizations worldwide. However, entities worldwide can mitigate the vulnerabilities listed in this report by applying the available patches to their systems and implementing a centralized patch management system,” the advisory stated.

Risk-based Vulnerability Management – Overdue for Automation

Microsoft 2022 flaw, Cybersecurity interest, Personnel Security Program

The digital world is a blink-and-you’ll-miss-it environment, and organizations need to move aggressively to shrink the exploitable vulnerability window. Adversaries are breaching the security periphery through 0day exploits, social engineering, and phishing attacks, among other tactics. Based on current priorities, security teams tend to focus on known vulnerabilities that can be identified with established assessment practices and have prescribed remediation solutions.

However, for long-term risk reduction, simply relying on patch management isn’t enough. More important is finding the biggest areas of exposure and having the foresight to understand how critically they can affect operations in case of a compromise. For this, reliance on legacy manual approaches is inadequate – we need to move toward automation and leverage all of the available technologies to tackle the problem at hand.

By John Bock – Sr. Research Scientist, Research & Development, Optiv

 SPONSORED CONTENT 

Introduction

Automation itself is a deep discussion, but for the C-Suite it needs to be articulated in terms of strategy vs implementation. While organizations are well aware of the workload associated with patching vulnerabilities, the workload growth curve is usually expressed in trajectory graphs, not real numbers. The numbers are illuminating, though. Just looking at Microsoft patch volume since 2016, we have had some pretty dramatic growth in recent years:

Year

Microsoft Patches*

2016

5,528

2017

10,502

2018

11,314

2019

20,443

2020

30,480

In other words, if you’re struggling to keep pace with the patch volume now, the future is only going to be more difficult.

Looking at the future, you will have an increasing number of vulnerabilities to track, which also means you have predictable workload growth. If this isn’t a headache for your security team already, it will be soon. Automation combined with new remediation strategies, then, is your best way forward.

Understanding Your Remediation Pipeline

If you track the lifecycle of an individual vulnerability from its identification to its final fix, it generally traverses multiple systems with multiple stakeholders. Each step along the way can (and probably will) introduce delay deriving from both mechanical and policy concerns. Additionally, many organizations don’t have an integrated, comprehensive view of all the operations involved or the stakeholders and their respective responsibilities within the workflow. Security and IT teams, for example, work in silos when it comes to getting a vulnerability remediated.

Security teams can often feel they’re only responsible for notifying IT about a vulnerability; it’s then IT’s job to fix it. IT, on the other hand, may feel little urgency to act unless they’re prodded by Security. What’s needed to bring a shared vision between both teams is a comprehensive, complete and accurate workflow model that tracks each vulnerability management step as it weaves through the organization. This becomes the foundation for an automation roadmap that drives modernized change management policies.

Linking Vulnerability and Patch Management

How much integration can you foster between the platform that identified the vulnerability (e.g., Tenable, Rapid7, Qualys) and the solution that will deploy the remediation action (e.g., Microsoft SCCM, HCL BigFix)?

Recently, Tenable announced support for direct integration with BigFix, and there are other products on the market, like Vulcan.io, which translate between a CVE and an applicable patch. Without this link, you’ll have to run this function through an ITSM and rely on an analyst to manually review the vulnerabilities involved. Once that’s done, you need to find an appropriate patch for the target asset and then coordinate its deployment. These time-consuming manual tasks delay remediation, and the longer the delay the more opportunity an attacker has to exploit your network and compromise your systems.

Also read: Risk-based Vulnerability Management – Time to Move Away From the Whack-a-Mole Model

Managing Reliability Risk at Speed

One of the most common reasons organizations don’t deploy every patch shipped to them is that rarely do these patches cause stability problems and downtime. To mitigate that risk, a patch deployment cycle may be distributed to small groups at first, and absent complaints sent out to the wider population. While this can help lessen the risk of a bad patch causing major damage, it’s also not very scientific in terms of testing the patch compatibility, and it relies on time to obtain a result.  The time that other systems will remain vulnerable wait to see how if the canary in the proverbial coal mine survives.

One of our alternatives is to leverage robotic process automation to build a set of automated test cases akin to what you would see in unit testing for application development.  With RPA, you can build a target virtual machine image that is configured as a user workstation, with the appropriate set of applications installed.  Then the RPA can be trained to perform user activities sufficient enough to validate that the patch in question wouldn’t disrupt normal operations.  With this method, the patch rollout cycle becomes a testing loop with each update being pushed to the target images and after a successful RPA run the update can be cleared for wider distribution.

The big advantages here are that the entire process itself can be initiated as soon as a patch is received from a vendor, that a more intensive and auditable testing process will occur, and that specific issues related to the patch can be spotted without relying on the user’s noticing the behavior in the wild.  With RPA being leveraged as the patch vetting mechanism, it enables the IT and Security team to spot issues such as a specific application not being able to perform a function with the patch in place, but now with the foreknowledge that allows IT to build a workaround or the CISO and CIO to have all the options when balancing the security risk vs. operational stability.

Alternative Remediation Strategies

The automation discussion presents the opportunity to ask another question: “Should we try to patch this, or just take down the asset?” Unmanaged or undermanaged hosts are a frequent entry point for breaches. Even when they’re discovered, getting a system updated that hasn’t been patched for say, five years, will take considerable effort. Ideally, Security and IT should collaborate on a process to continually assess whether a service or system needs to be on the network. Instead of keeping it as part of the patching workload, it should be disabled if not in use.

Continual attack surface pruning can be based on login events, user activity, network traffic, or any other available data indicating whether it’s being used.  There are various mechanisms that can be used for “Weeding” network assets, the basic set being authentication and traffic logs, along with regular validation from the listed owners that it is still needed.   When it comes to cloud environments like AWS or Azure this becomes easier since the resource can be tied to a dollar value, and statements along the lines of “This is costing us 10k a month and no one has used it in a year” tend to hasten the debate.

Conclusion

Even in a current context where more and more functions are being automated, vulnerability remediation holds onto manual processes in too many cases. Staying ahead of the curve requires the implementation and execution of an automation-first remediation lifecycle. Additionally, a review of change management policies and procedures that create remediation delays is overdue for modernization.  Policy models that can trace their origin to an era of low attacker and vulnerability volume alongside monolithic computing don’t work in today’s landscape with a massive increase in the number of hostile actors and vulnerabilities, while at the same time computing has become more resilient than ever.

To learn more about vulnerability management and automation Download our free field guide or drop us a line if you have questions.