Home Blog Page 76

Paying Ransom is the Primary Solution for 60% of Organizations: Study

paying ransom, Conti Ransomware Attacks

Despite several notices and awareness programs, most organizations are still paying ransom for data decryption post a ransomware attack. Earlier, the FBI warned companies to avoid ransom payments as it encourages others to follow suit. Recently, the U.S. Department of the Treasury’s Office of Foreign Assets Control (OFAC) also announced that paying ransom to cybercriminals is illegal. Besides, several industry experts stated that the total cost of recovery from a ransomware attack almost doubles when organizations pay ransom to threat actors.

New research from the Neustar International Security Council (NISC) revealed that over 60% of organizations admitted that they would consider paying ransom in the event of a cyberattack. One in five organizations said they would consider paying 20% or more of their company’s annual revenue.

Key Findings

  • Nearly 28% of respondents said they are very confident that all members of their organization know the appropriate measures to take in the event of a ransomware attack, and a similar proportion (26%) lack confidence that this is the case.
  • Over 35% perceive guidance from government/official bodies to be insufficient and 26% perceive existing cybersecurity technology to be insufficient.
  • Ransomware, DDoS, and targeted hacking were most likely to be perceived as increasing threats to organizations during March-April 2021.
  • 56% of enterprises surveyed in May 2021 outsource their DDoS mitigation, in line with the previous reporting period.
  • Enterprises were most likely to take between 60 seconds and 5 minutes to initiate DDoS mitigation in May 2021, in line with previous reporting periods.

“Companies must unite in not paying ransoms. Attackers will continue to increase their demands for ever-larger ransom amounts especially if they see that companies are willing to pay. This spiral upwards must be stopped. The better alternative is to invest proactively in mitigation strategies before the attacks, including the use of qualified providers of ‘always-on’ monitoring and filtering of traffic as part of a layered security approach,” said Rodney Joffe, NISC Chairman, SVP, and Fellow at Neustar.

Ransom Paying Trend Continues

Cybersecurity professionals are trying to place more emphasis to prevent the rising ransomware threats. Most organizations are turning to pay the ransom when their current solutions are not sufficient in detecting, mitigating, and preventing cyberthreats.

Recently, multiple popular organizations have paid huge ransoms to recover their data after a ransomware attack. The largest meat-processing giant JBS confirmed that it had paid $11 million to the REvil ransomware gang after attackers compromised its systems. The U.S. Colonial Pipeline reportedly paid $4.4 million ransom after sustaining a sophisticated ransomware attack that caused panic and massive fuel shortages in the country. Also, several industry experts raised concerns over CNA’s failure in detecting the ransomware attack, which led the company to pay a $40 million ransom to recover its systems.

Another Case of Unprotected Database: 5 Bn Records from Previous Data Breaches Leaked

106 million Thailand visitors

Unsecured databases are potential cyberthreats for organizations. Perpetrators often look for unprotected/misconfigured servers to infiltrate and compromise sensitive corporate data. A recent security research by Comparitech, led by cybersecurity researcher Bob Diachenko, revealed that cybercriminals attacked an unsecured ElasticSearch database that affected over 5 billion records.

According to the report, the exposed database belongs to cybersecurity analytics firm Cognyte, which was exposed online without password protection, allowing open access to strangers. The exposed database was stored by Cognyte, a cybersecurity analytics firm that stores data as part of its cyber intelligence service, which is then used to alert customers about third-party data breaches. “If a client’s contact information appeared in the database, for example, they could receive an alert notifying them that one of their accounts had been compromised. Or if they use a password that has previously been breached, they could get a notification to change it,” Cognyte said.

The leaky database is now secured after Bob Diachenko reported the issue to Cognyte.

“Cognyte was able to rapidly respond to and block a potential exposure. We appreciate such a responsible and constructive approach, which helps to raise awareness and induces companies and organizations to implement security safeguards and better protect their data,” Cognyte said.

The Data Breach Timeline

While it is unknown whether any attackers misused the leaked data, the researchers stated that the database was exposed online for at least four days:

  • May 28, 2021: The database was indexed by search engines.
  • May 29, 2021: Diachenko discovered the leaky database and immediately notified Cognyte.
  • June 2, 2021: Cognyte secured the database.

What data was exposed?

The database held over 5,085,132,102 records that contained information including, name, email address, password, and data source. “Not all of the data breaches from which the data was sourced included passwords, however, we could not determine an exact percentage of records that contained a password. We do not know if any other third parties were accessing the data when it was exposed, nor do we know for how long it was exposed before being indexed by search engines. Our honeypot experiments show that attackers can find and access exposed data in a matter of hours,” Cognyte added.

Security Risks from Data Leaks

Cybercriminals often exploit the personal information obtained from data breaches to steal identities and misuse it to launch credential stuffing attacks, phishing, and other fraudulent scams. Several threat actor groups often get hold of such leaked data and threaten companies to expose it online or demand ransom.

Every minute is an opportunity for threat actors if they find an unsecured server left online. Attackers can find and access exposed data in a matter of seconds or hours. Another security experiment by Comparitech discovered that cybercriminals attacked a model of an unsecured database 18 times in a single day. The company set up a honeypot to know how quickly the hackers would attack an Elasticsearch server with a dummy database and fake data in it. It found 175 attacks in just eight hours after the server was deployed, and the number of attacks in one day totaled 22.

Bob DiachenkoTalking about the incident to CISO MAG, Diachenko said, “It is not the first time I encounter this type of exposure. The amount and sensitive nature of previously leaked data is tremendous, so should be the efforts of any organization in possession of this data to keep it as secured as possible and prevent it from “re-leaking”. In my opinion such incidents are no less dangerous as the original data breaches collected in such troves.”

RedFoxtrot Group Linked to Chinese PLA Unit 69010 Targets Indian Organizations

Chinese actors target telecom

Cyberespionage campaigns by Chinese state-sponsored actors disrupted operations of several organizations globally. After targeting Indian organizations in the power sector earlier this year (RedEcho), the Chinese state actors are now targeting multiple sectors bordering China’s Western Theatre Command notably India, Pakistan, and Central Asia. Cybersecurity experts from Recorded Future uncovered a cybercriminal group, dubbed RedFoxtrot, targeting aerospace, defense, government, telecommunications, mining, and research organizations in Afghanistan, Kazakhstan, Kyrgyzstan, Pakistan, India, Tajikistan, and Uzbekistan.

Recorded Future suspects specific ties between RedFoxtrot cybercriminal activities and the Chinese military-intelligence apparatus, the People’s Liberation Army (PLA) Unit 69010 within the Strategic Support Force (SSF). RedFoxtrot maintains a huge operational infrastructure and leverages publicly available malware families including Icefog, PlugX, Royal Road, Poison Ivy, ShadowPad, and PCShare.

Key Findings

  • Active since 2014, RedFoxtrot predominantly targeted multiple sectors in Asia by aligning with the operational remit of PLA Unit 69010.
  • RedFoxtrot maintains large amounts of operational infrastructure and has likely employed both bespoke and publicly available malware families commonly used by Chinese cyberespionage groups.
  • RedFoxtrot activity overlaps with threat groups tracked by other security vendors such as Temp.Trident and Nomad Panda.
  • It is assessed with high confidence that RedFoxtrot is a Chinese state-sponsored threat activity group based on identified links to a specific PLA unit and the use of shared custom capabilities considered unique to Chinese cyberespionage groups.

“The recent activity of the People’s Liberation Army has largely been a black box for the intelligence community. Being able to provide this rare end-to-end glimpse into PLA activity and Chinese military tactics and motivations provides invaluable insight into the global threat landscape. The persistent and pervasive monitoring and collection of intelligence is crucial to disrupt adversaries and inform an organization or government’s security posture,” said Dr. Christopher Ahlberg, CEO, and Co-Founder, Recorded Future.

RedFoxtrot Focuses on India

Researchers from Recorded Future stated that the cyber operations of RedFoxtrot are more focused on Indian organizations.

“Activity over the past six-month period showed a particular focus on Indian targets, which occurred at a time of heightened border tensions between India and the People’s Republic of China (PRC). Notable RedFoxtrot victims over the past six months include multiple Indian aerospace and defense contractors; telecommunications companies in Afghanistan, India, Kazakhstan, and Pakistan; and several national and state institutions in the region,” the researchers said.

Addressing a media briefing today, Jon Condra, Director, Strategic and Persistent Threats at Recorded Future said, “One of the characteristics of RedFoxtrot is that they make heavy use of Dynamic DNS (DDNS) domains that often contain hints regarding geographical targeting or spoof specific organizations. Some examples are Indian telecom provider –  BSNL (inbsnl.ddns.info), Indian defense contractor and electronics manufacturer –  Advanced Design Technologies (adtl.mywire.org), and Indianmail.zyns.com.”

Earlier, a China-linked threat actors group, dubbed RedEcho, targeted 12 Indian organizations, 10 of which were in the power sector. Researchers uncovered a subset of the servers that shared some common tactics, techniques, and procedures (TTPs) with several previously reported Chinese state-sponsored groups.

These are the 5 Biggest Data Breaches in India in H1 2021

biggest data breaches in India,data breach, Aptoide Android App Admits Data Breach, Suspends Sign-Up Option Temporarily, Panasonic

In November 2020, cybersecurity service provider Kaspersky had forecast an increase in the number of cybercriminal activities in India during 2021. With the wider adoption and acceptance of digitization in the year gone by, a large number of end-users was expected to join the digital bandwagon. It was only a matter of time for Kaspersky’s prediction to come true. However, what no one probably anticipated was that big names like Air India and Domino’s would fall prey to these nefarious cybercriminal activities.

Here’s a look at the five biggest data breaches in India that took place in the year 2021, so far.

1. Domino’s India Data Breach

domino's data breach

When: April 2021
Records Impacted: 180 million order details
Data Breached: Name, e-mail, mobile number, order numbers, delivery address, GPS location

Domino’s Pizza is one of the most popular pizza chains in India. However, a preliminary report from UpGuard had awarded Domino’s Pizza’s security posture a “B-grade” rating. It scored 713 out of 950 points, which were awarded based on UpGuard’s internal parameters and standards. This came to haunt Domino’s India in April 2021 as a data breach discovery was brought to light by Alon Gal, a renowned cybersecurity researcher and chief technical officer at an Israeli cybersecurity firm, Hudson Rock.

According to Gal’s findings, apart from the order (180 million) and credit card (1 million) details, threat actors claimed to have critical insider data of Domino’s India’s 250 employees across various departments such as IT, legal, finance, marketing, operations, etc. The threat actors behind the leak published a sale post on an underground forum demanding 50 Bitcoins from the pizza giant if it did not want the data to “go public.”

2. MobiKwik Data Leak

MobiKwik data breach

When: February 2021
Records Impacted: 110 million
Data Breached: KYC, passport, e-mail, phone number, PAN and Aadhaar details

The MobiKwik data breach was first reported by an independent security researcher, Rajshekhar Rajaharia, in February 2021. As per Rajaharia’s series of tweets, data of 11 crore (110 million) Indian cardholders was leaked from a company server in India, and the initial leak contained 6 TB of KYC data and 350 GB of compressed MySQL dump. However, MobiKwik thwarted his claims stating, “We thoroughly investigated his allegations and did not find any security lapses.”

However, another researcher going by the name “Elliot Anderson,” on March 29, 2021, tweeted that MobiKwik’s data was indeed breached and the threat actor had subsequently created a forum on the dark web for its sale. Given the growing number of voices against them, MobiKwik eventually stated that “it will get a third party to conduct a forensic data security audit,” yet, reiterated that all their customer data was safe and that no MobiKwik user accounts and/or wallets were affected due to the alleged incident.

3. Upstox Data Breach

Upstox data breach

When: April 2021
Records Impacted: 2.5 million
Data Breached: Name, e-mail, mobile number, Aadhaar and bank account details

Just when the dust of the MobiKwik data breach was beginning to settle, another big banner data breach took center stage. This time it was India’s second-largest stockbroker, Upstox. Out of the total user base of nearly three million users, reportedly two and a half million were affected in the alleged data breach, which was perpetrated by the notorious threat group “ShinyHunters.”

According to Rajaharia, who incidentally also found this data breach through a darknet forum, Upstox’s data breach reason was similar to the MobiKwik incident. In both cases, the company’s Amazon Web Service (AWS) key was compromised, which led to illicit access to its database.

4. Air India Data Breach

Air India Data Breach

When: February 2021
Records Impacted: 4.5 million
Data Breached: Name, passport, credit card details, birth dates, contact information, passport information, ticket information, and Air India’s frequent flyer data

Recently, one of India’s premier national airlines, Air India, revealed that it sustained a sophisticated data breach in February 2021. The breach impacted over 4.5 million of its passengers globally and was attributed to a compromise in its data management service provider SITA Passenger Service System (SITA PSS).

SITA PSS, which is responsible for storing and processing of personal information of Air India passengers, leaked nearly a decade worth of critical passenger information to the threat actors. However, the company said that there were no signs of any misuse of users’ leaked data and urged passengers to update their passwords at the earliest to avoid any security risks. SITA provides services to several global airlines, and hence, Star Alliance and One World airlines group were also impacted by this data breach.

5. Juspay Data Leak

Juspay data breach

When: January 2021
Records Impacted: 35 million
Data Breached: “non-anonymized” customers’ user metadata information containing email IDs and phone numbers

Initially, on January 3, 2021, Rajaharia first revealed the findings of the Juspay data breach stating that the data of 10 crore (100 million) Indian cardholders was up for sale on the darknet. However, Juspay quickly corrected these numbers stating that only 35 million records were compromised, as opposed to the claims of 100 million, which was “grossly inaccurate.”

The company further added that although 35 million credit and debit card details were leaked, it included only masked card data, meaning, six digits out of 16-digit card numbers were masked (hashed). Apart from this, the only non-anonymized form of data leaked during the data breach was the plain text email ID and phone numbers. When Juspay’s incident response team investigated the incident, it found the root cause to be an unrecycled access key behind the mega data breach incident.

Though data breaches across the globe have seen a sudden spike since the pandemic hit, growing cyberthreat incidents in India call for better security solutions by small, medium, and big businesses. Enhancing security posture and protecting customer data is more vital than ever.

U.S.-Russia Summit: Biden Tells Putin “Critical Infrastructure Should Be Off-limits” to Cyberattacks

U.S.-Russia Summit

Cyber intrusions have existed for decades. They still do, however, much of the cyber espionage today comes from geopolitically-inclined state actors, impacting both governments and critical businesses. This was one of the agendas of the recent U.S.-Russia Summit, where the POTUS, Joe Biden and Russian President Vladimir Putin discussed cybersecurity and arms control.

According to a report, both leaders discussed the bilateral relationships between their countries and the control of nuclear weapons during the meeting. In a separate press conference after the highly anticipated meeting, President Putin said, “The conversation was constructive.” The Russian leader also stated that they have agreed to start consultations on cybersecurity.

Addressing reporters, President Biden stated that he, along with Putin, specifically spoke about the rising ransomware attacks on the U.S. infrastructure by Russian hackers. “Another area we spent a great deal of time on was cyber and cybersecurity.  I talked about the proposition that certain critical infrastructure should be off-limits to attack — period — by cyber or any other means,” Biden said.

The discussion specifically focused on the ransomware attack on Colonial Pipeline, which halted all pipeline operations and affected some of its IT systems. The attack was allegedly carried out by the DarkSide hacking group, which is likely based in Russia.

Furthermore, Biden reportedly gave Putin a list of 16 specific critical infrastructure entities, from the energy sector to water systems, that should be “off-limits” from future cyberattacks.

“The principle is one thing.  It has to be backed up by practice.  Responsible countries need to take action against criminals who conduct ransomware activities on their territory. So, we agreed to task experts in both our — both our countries to work on specific understandings about what’s off-limits and to follow up on specific cases that originate in other countries — either of our countries,” Biden added.

The U.S. agencies have been suffering from a series of cyberattacks for years.  From the persistent SolarWinds attack, Accellion data leak to Microsoft Exchange Servers hack, the threat landscape has grown more sophisticated and raised concerns of national security threats by rival nations, including Russia. However, the Russian government has denied the allegations. Putin claimed that most cyberattacks originate from the U.S. and their attempts to get information about the origin of such attacks are being ignored.

G7 Asks Russia to Act on Ransomware Gangs

Recently, the member states of the G7 group asked Russia and other countries to take stringent action on ransomware gangs, after a series of high-profile ransomware attacks caused severe chaos in the U.S. and Europe. The joint statement was signed by the governments of Canada, France, Germany, Italy, Japan, the U.K., and the U.S.

“We call on all states to urgently identify and disrupt ransomware criminal networks operating from within their borders and hold those networks accountable for their actions. In particular, we call on Russia to identify, disrupt, and hold to account those within its borders who conduct ransomware attacks, abuse virtual currency to launder ransoms, and other cybercrimes,” the G7 group said.

Despite the uncertainty in developments, the global cybersecurity community is expecting that the recent summit will improve the relations between the U.S. and Russia.

“IoT technology will always improve but it will never be 100% secure”

Chukwudum Chukwudebelu

The proliferation of the Internet of Things (IoT) in consumer, enterprise, and health care sectors, and their internal vulnerabilities, have created a security blind spot where cybercriminals can launch a Zero-day attack to compromise the connected devices. In tandem with technology and deployment, the growth of IoT devices also resulted in a variety of cyberthreats.

In an interview with Rudra Srinivas, Sr. Feature Writer, CISO MAG, Chukwudum Chukwudebelu, Chief Strategic Officer and Co-Founder at Simius Technologies Inc., discusses the major cybersecurity concerns associated with IoT devices. Chukwudum is experienced in product management, strategy, marketing, and sales in simplifying the consumer cybersecurity industry.

Edited excerpts from the interview follow:

The surge of the Internet of Things (IoT) is forcing many businesses to reconsider their approaches towards cyber risk management. How is the explosion of IoT devices changing the cybersecurity landscape?

The explosion of IoT is an unprecedented phenomenon. It is one thing for a computer with a screen to be connected to the internet, where you would notice something wrong. But it’s another issue for IoT devices. There was an incident of a casino that was hacked through a smart thermometer. IoTs make your networks vulnerable, and they are not designed to be secure. Even if they are, it is only the hardware that is secure due to the changing nature of vulnerabilities. Embedded firmware becomes insecure over time. This is especially true when you consider very few manufacturers provide regular firmware patches. Because of this, they become the backdoor for hackers, and without proper network security scans on those devices, how would an organization or even a consumer know when these devices have been breached? Businesses have to understand that they need consistent surveillance on these IoT devices because they may not know when they have been hacked. And if they have been breached, one may be thinking that it is just a smart thermometer. However, one single breach can amount to the domino effect, as intruders pivot from device to device. They might be able to navigate with impunity onto other devices, creating a backdoor to sensitive files or systems. Businesses and consumers need full holistic solutions for the cybersecurity landscape of today because every small breach in any organization could have a domino sitting there, waiting to be tipped.

According to a survey, the total number of IoT devices is expected to reach 83 billion by 2024, from 35 billion in 2020, which represents a growth of 130% over the next five years. Will IoT ever be 100% secure? What will be the state of IoT security in the next five years?

The IoT technology will always improve but it will never be 100% secure. As long as it is connected to the internet, there is always a risk. The best chance at cybersecurity is to reduce that risk. Since the internet was not built to be secure, rather, it was designed to be shared.  Industries are increasing the use of IoTs, and consumers are doing the same. As with anything, Moore’s law applies. An example would be for smart homeowners, where consumers have fully automated homes. Many smart homeowners have had their devices breached. We can also dive into the agricultural sector with the rise of fully automated farms, manufacturing industries using autonomous robotics, etc. In the next five years, many of these industries will become fully dependent on IoT devices. They will need to be secure to reduce risk, and the manufacturers of these devices together with the cybersecurity companies and government have to find a way to work together to deliver 100% secure IoT devices. By constantly keeping up with the threats and vulnerabilities, while being on point to thwart or prevent an attack at a moment’s notice. There’s no such thing as the cyber police yet, but I am sure that it will become recognized and more prominent as a need with most law enforcement agencies.

Based on a report, nearly 80% of IT professionals discovered shadow IoT devices connected to their company’s network. What are the major cybersecurity concerns associated with shadow IoT devices and how enterprises can deter potential threats from them?

The major cybersecurity concern is fear of the unknown. We don’t know what we do not know. That is part of being human. However, shadow IoT devices offer a unique attack vector for cybercriminals. We’re talking about connected devices or sensors that are actively in use within an organization’s network without their IT department’s knowledge. This includes everything from PCs, smartphones to personal health monitors and other smart devices. So, organizations and consumers need to keep a tight-knit around access to their networks. The value of keeping passwords away from employees or strange acquaintances cannot be underestimated. How can one prepare to mitigate against shadow IoT attacks if they do not keep their network access controlled?

Organizations and consumers alike should consider change management practices. Should there be any breach through a shadow IoT attack, it will keep recurring, and the businesses or consumers will keep having to deal with damage control. Until those loose ends are kept under wraps, shadow IoT attacks will remain a large point of risk.  It is difficult to discover problems without proper visibility for these IoT devices. Enterprises could do a network reset, with the devices connected to their network, but this can require significant coordination and effort on the part of their staff with guidance from the IT department. But this is much similar to doing a body cleanse. Flushing out unwanted devices and rebooting the ones you have is always a good practice. Discovering shadow IoT devices is tricky without proper network security in place. You could also have scenarios where an employee’s device is still connected to the network long after they are no longer in the organization, so be sure to change password or logon credentials often. Certain security policies and protocols have to be put in place to reduce the frequency of those issues. When enterprises and consumers are aware of the potential threats with Shadow IoT devices, they can prepare for it.

As Chief Strategic Officer, how do you help prevent information theft through IoT devices?

They say simplicity is an art. The most basic way of theft through an IoT device is using the breached passwords. Who creates these passwords? Is there a solid password policy enforced by the organization? Or do smart home consumers even have a standard to the passwords they use? These are basic but important questions. The users of these devices are also a target for phishing campaigns and various malware vectors which can breach a network from the fault of user activities. Even though someone may accidentally click a bad link, even the most sophisticated network security systems can be breached by that error in judgement. Why do we think that accessibility means identity? Someone can access your IoT device with your password does not mean they are authorized to log in. This is how two-factor authentication is designed to operate. How do the users manage their passwords though? That is the first line of defense. Most times they do not like to manage passwords effectively. Instead, they leave their own passwords out to dry. 64% of people still use the same passwords online. Also, when these IoT devices are hacked, users do not know because they do not have a screen or visibility. No notifications are available to warn them. Users of IoT devices can use certain tools to scan for vulnerabilities and prevent them before they happen such as updating your firmware. But we have to go back to the fundamentals, “Are you authorized to access this IoT device?” User training with basic cybersecurity fundamentals is quintessential for success.

Insider threats are one of the important concerns for security leaders today. Besides, remote work has also encouraged businesses to embrace Bring Your Own Devices (BYODs) concept at workplaces. How can enterprises stop non-business IoT devices from connecting to corporate networks? Is there a middle-ground solution that you see enterprises using?

There is a middle ground somewhere between. Enterprises and consumers need to segment their network, through VLANs as an example. They can make trusted or untrusted devices connect only to the specified VLAN for which they are authorized to access. This also prevents any unauthorized access to the main enterprise or smart home network.

Businesses and homeowners alike can set up a network that needs multiple layers of security before a new device is connected to it, not just a password. Hence the usefulness and ease of two-factor authentication. That way there is an additional security layer. Enterprises have to create new security compliance policies and treat any foreign device as a threat immediately until it is determined to be a safe or trusted device. Smart homeowners are no exception. But this way, only authorized devices can connect to these networks. This is how to simplify things. We are treating devices and users into buckets of being trustworthy versus not.

In what way will artificial intelligence drive the future of the IoT landscape? And what should manufacturers be wary of to prevent the security of IoT devices from being compromised?

AI will continue to assist with automation, but there will be points of high risk that require human intervention. Manufacturers will have to be wary of viruses, threats generated from adversarial networks of cybercriminals. These threats will likely remain persistent since all IP addresses are public. The bad guys will constantly be scanning these lists to see if there are any vulnerabilities worth exploiting. Manufacturers will need sufficient infrastructure in place to prepare for these kinds of attacks. They will need to consistently ask for feedback, and test for vulnerabilities. After all, this is a great game of cat-and-mouse we play with the cybercriminals.

About the Interviewer

Rudra Srinivas

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

Read More from the author. 

 

 

Cyber Risk Management: Does cyber risk get enough boardroom airtime?

Cyber Risk Management

Cybercrime is not a burgeoning criminal industry; it is an established threat with severe consequences that cannot be ignored by businesses – and it is up to the board to lead the fight back. This eBook from Camms – a leading global business software solution provider – explores why and how the board should be taking a proactive approach to managing cyber risk.

 SPONSORED CONTENT 

As Benjamin Franklin once said: “Out of adversity comes opportunity”. Unfortunately, for businesses the world over the rapid spread of COVID-19 has created a perfect storm for cybercriminals – fear, uncertainty, vulnerability, widespread remote working, and increased online activity – who have seized this opportunity to escalate their nefarious activities. This poses the question: has it taken a crippling global pandemic for cyber risk to evolve from an IT issue to a top board priority and for organizations to realize the importance of establishing a proactive cyber risk strategy?

Camms Cyber Risk ManagementCyberattacks were clearly on the risk radar before the pandemic. Awareness of the cyberthreat has grown rapidly in recent years, driven by businesses increasing reliance on data and IT systems – and an escalation of high-profile incidents. So much so that cybercrime has evolved into the world’s biggest criminal growth industry – it is estimated that global cybercrime costs will reach $10.5 trillion annually by 2025, up from $3 trillion in 2015.

With businesses forced to shutter their doors and shift to remote working at scale following the introduction of lockdown restrictions, the pandemic has accentuated what was already a serious problem. Operating models have been altered and digital footprints expanded, widening the attack surface for cybercriminals almost overnight. These unscrupulous actors are subsequently cashing in on increased workloads, unfamiliar ways of working, and heightened stress levels by developing themed social engineering attacks that use COVID-19 as bait.

This cyber onslaught against businesses throughout the world and across all industries poses the question: what is at stake for them? The financial, operational, and reputational implications of cybercrime can be crippling – and are a serious wake-up call for boards to prioritize cybersecurity:

  • Intellectual property losses
  • Legal expenses
  • Reputational damage
  • Business disruption
  • Administrative cost

Having outlined the ever-growing threat posed to businesses by cyberattacks, their consequences, and the impact at the board level, this eBook from Camms answers two pertinent questions:

  • What is the role of the board?
  • How can an integrated risk management system help a business mitigate cyber risk?
Camms Cyber Risk Management Find out the answer to these questions, and much more, by downloading the Whitepaper here.

 

How Surge in Remote Work Led to Rise of BYODs and Security Risks

IoT attacks

The sudden surge in remote work due to the pandemic has encouraged organizations globally to embrace Bring Your Own Devices (BYODs) in the workplace. The use of personal devices for work also resulted in a significant increase in security and privacy risks, making it hard for organizations to handle evolving threats.

A recent survey from Bitglass revealed insights on the state of securing mobility, the technology choices organizations are making, and their response to the growing security risks associated with remote work and enterprise mobility. The survey “2021 BYOD Security Report” revealed that security professionals continue to lack the visibility and technology needed to secure unmanaged personal devices against modern threats.

Key Findings

  • Overall, 82% of organizations actively enable BYOD to at least some extent. BYOD is typically associated with company employees bringing unmanaged devices into the workplace (70%), but also applies to other groups like contractors (26%), partners (21%), customers (18%), and suppliers (14%).
  • The main barriers to BYOD adoption are the concern about information security (30%), employee privacy concerns (15%), and support cost concerns (9%). Regardless of the specific barrier, the fact is that organizations need to think differently when it comes to securing BYOD.
  • While 22% of organizations confirmed that unmanaged devices accessing corporate resources downloaded malware in the last 12 months, an alarming 49% were unsure or unable to disclose whether the same could be said of them. This lack of visibility can prove fatal.

Security Concerns Associated with BYODs

Over 47% of organizations reported an increase in the use of BYOD. This trend will challenge the use of security measures designed for managed endpoints. In addition, security professionals continue to report a variety of security concerns over BYOD such as data leakage or loss (62%), users downloading unsafe apps or content (54%), lost or stolen devices (53%), and unauthorized access to company data and systems (51%). While 22% of organizations surveyed can confirm that unmanaged devices accessing corporate resources have been used to download malware in the last 12 months, an alarming 49% were unsure or unable to disclose whether the same could be said of them.

BYOD – A Growing Risk Factor

As modern enterprises incorporate more BYODs, shadow IoT devices will become an ever-growing risk factor to enterprise network security. A similar research“What’s Lurking in the Shadows 2020” revealed that 80% of IT professionals discovered shadow IoT devices connected to their company’s network. 9 in 10 security leaders (89%) were worried about shadow IoT devices connected to remote or branch locations of their businesses. Shadow IoT devices are internet-connected devices or sensors used inside an organization without the knowledge of the IT team in a company.

Episode #11: Supply Chain Attacks and Vulnerability Disclosures

Supply Chain vulnerabilities

In the past year, we have seen accelerated adoption of digital platforms and technologies. For instance, more businesses and individuals are turning to e-commerce platforms to survive. The interconnections between partners and suppliers for these platforms have increased. So, it has become crucial to ensure the security of both the organization network and partner systems, particularly for the software supply chain. But why has it taken so long for CISOs to acknowledge this? This has resulted in an increase in supply chain attacks.

SolarWinds, giant aviation digital services provider SITA, and DevOps tool provider Codecov are among this year’s victims of supply chain attacks that continue to create a ripple effect of data breaches across their customers, exposing millions of records. The latest attack on supply chains is on Edward Don and Company, a known distributor of foodservice equipment and supplies in the U.S. And earlier this month, there was an attack on JBS, the world’s largest meat producer.

As businesses increasingly leverage tech partners and third-party solutions to add functionality to their online presence, hackers turn their focus towards cheaper, easier targets that are much harder for security teams to discover.

In particular, misconfigured cloud buckets, DNS hijacking, and malicious code injections (such as those seen in Magecart attacks) continue to be threats to an enterprise’s external attack surface, disrupting supply chains.

These devastating attacks are such a growing concern that CISA recently issued guidance on how to defend against them.

RSS: https://feeds.soundcloud.com/users/soundcloud:users:899202688/sounds.rss

Spotify: https://open.spotify.com/show/7pBhvwEVAaL4uUJnzD5rWO

Ran Nahmias, Co-Founder and Chief Business Officer at Cyberpion, and Brian Pereira, Editor-in-Chief, CISO MAG, discuss weaknesses in the supply chain. They also talk about the Magecart attacks and the growing ransomware attacks.

As Co-Founder & Chief Business Officer, Nahmias leads global sales and marketing at Cyberpion (Cyber-pie-on). He has over 25 years of experience in cybersecurity. He is a technology evangelist with a proven track record of entrepreneurial product management in both startups and Fortune 100 companies, focused on building high-growth, cutting-edge products, and solutions.

Formerly, Nahmias was the Global Head of Cloud Security at Check Point, and he has also held positions at Microsoft as a Director of Business Development and Field Engagement and as a solutions architect.

Dump the Password! 80% CISOs say They are Not an Effective Means of Data Protection

CISOs in remote working

Ever since the pandemic began, organizations globally encountered drastic changes in their business operations.  The swift adoption of remote working significantly impacted the role of Chief Information Security Officers (CISOs) and other security leaders, making it difficult to deal with new cybersecurity challenges and combat/mitigate security threats.

Security leaders globally have changed their cybersecurity strategies according to the changing attack vectors. A recent survey from cybersecurity firm Ivanti revealed that remote working culture has shifted CISO priorities in handling cybersecurity matters. The study revealed that 88% of CISOs admitted that remote work has accelerated the demise of the traditional network perimeter and has subsequently given rise to a host of new IT security challenges. And around 90% of CISOs stated that mobile devices have become the focal point of their cybersecurity strategies.

The study surveyed over 400 CISOs across Europe, the Middle East and Africa (EMEA) and 80 CISOs in Australia.

Key Findings

  • Over 80% of CISOs opined that passwords are no longer an effective means of protecting enterprise data.
  • Over half (58%) of respondents cited employees leveraging unsecured Wi-Fi to access business resources as a top IT security challenge during the pandemic.
  • Nearly 46% cited mobile phishing attacks as a top IT security challenge.
  • Over two-fifths, (44%) of CISOs cited employees using their own devices to access corporate data as a top IT security challenge.
  • Over 83% of respondents expect their IT security budgets to increase over the next 12 months to better enable remote workers.
  • Around 64% of CISOs plan to invest in mobile threat detection software. And 58% noted that enhancing user experiences, improving authentication to remote applications (57%), and moving critical business applications to the cloud (52%) will be top priorities this year.
  • The average IT security budget for an Australian CISO last year was over $6 million.
  • When pressed on the specific software solutions they plan to invest in during the next year, unified endpoint management (UEM) and biometric authentication solutions came out on top.
  • Despite CISOs indicating that almost half (49%) of their overall security budget was spent on UEM software in the last year, 86% said they expect investment to increase over the next year in specialized UEM software.
  • Over 78% of CISOs expect that their organization’s reliance on biometric authentication to enable remote access to business data would increase.

“With remote working now firmly established as standard practice across many ANZ industries, it is critical that CISOs ensure, long-term that working from anywhere and on any device is just as safe as doing so from the office, on a corporate-owned laptop. IT infrastructures are dispersed and employees need access to corporate data anywhere, at any time. The rise of the Everywhere Workplace has dramatically changed the role of the CISO, with a firm focus now placed on enabling, securing, and optimizing mobile work environments,” said Matthew Lowe, Area Vice President ANZ Ivanti.

“The pandemic has acted as a catalyst for CISOs to ensure that working from anywhere, on any device, is just as safe as working from the office, on a corporate-owned laptop. The emergence of the everywhere enterprise – where IT infrastructures are everywhere, and distributed employees need access to corporate data everywhere – has dramatically changed the role of the CISO and put mobile device security firmly under the spotlight. CISOs must now place greater emphasis on enabling, securing, and optimizing mobile work environments,” said Nigel Seddon, VP of EMEA West at Ivanti.

Most CISOs Unprepared to Handle Cyberattacks

Similar research from Proofpoint revealed that 2020 elevated the CISO role and the expectations from the businesses. The survey 2021 Voice of the CISO report stated that 66% of CISOs feel their organization is unprepared to handle a cyberattack and 58% consider human error to be their biggest cyber vulnerability.