Home Blog Page 82

Have I Been Pwned Goes Open Source; Partners with FBI

Have I Been Pwned teams with FBI
Image Source: troyhunt.com

Compromised credentials pose severe security threats to both organizations and individuals. Attackers often leverage stolen/leaked passwords in brute force attacks to compromise user accounts. Most victims use the data breach search website Have I Been Pwned? (HIBP) to check whether their email ID or phone number has been compromised in any data breach. Created by web security consultant Troy Hunt, HIBP indexes all the data breaches – the largest and the most recent – once a user enters the required details.

Recently, Troy Hunt announced that HIBP now allows the FBI to upload new content into its database. With this, the FBI can feed compromised passwords, which are found during law enforcement investigations, into the section, Pwned Password. The passwords will be provided in SHA-1 and NTLM hash pairs.

“The FBI play integral roles in combatting everything from ransomware to child abuse to terrorism and in the course of their investigations, they regularly come across compromised passwords. Often, these passwords are being used by criminal enterprises to exploit the online assets of the people who created them. Wouldn’t it be great if we could do something meaningful to combat that?” Hunt said.

Hunt stated the latest alliance removes a huge barrier for many organizations considering using Pwned Passwords.

“We are excited to be partnering with HIBP on this important project to protect victims of online credential theft. It is another example of how important public/private partnerships are in the fight against cybercrime,” said Bryan A. Vorndran, Assistant Director, Cyber Division, FBI.

HIBP Goes Open Source

Hunt also made Password Pwned open source via the .NET Foundation to accelerate the new partnership with the FBI. The company also asked developers to help create a Password Ingestion API to help the FBI and other law enforcement agencies feed compromised passwords into the Password Pwned database.

“The .NET Foundation folks have helped me out with the former and the Cloudflare folks with the latter. They’ll continue to help to support as community contributions come in and as the project evolves to achieve the objectives above re-supporting the FBI with their goals. Running an open source project is all new for me and I’m enormously appreciative of the contributions already made by those mentioned above. Bear with me as I navigate my own way through this process and a massive thanks in advance for all those who decide to contribute and support this initiative in the future,” Hunt added.

Fujitsu’s “ProjectWEB” Stands Suspended Amid Japanese Government Hacks

Fujitsu ProjectWEB

Just a couple of weeks ago, fearing a repeat of the Colonial Pipeline-like hack, Japan had announced stringent regulations for critical services in the private sector. It had already tightened the screws in the public sector in 2018 by restricting procurement of foreign equipment in government purchases. However, no obligations were imposed on its local service providers. Call it complacency or pure coincidence, but the island nation is currently facing one of its worst nightmares because of a local tech giant Fujitsu. A hack in Fujitsu’s Software-as-a-Service (SaaS) platform, “ProjectWEB,” has affected multiple Japanese government offices that have reported incidents of data theft.

Fujitsu’s ProjectWEB

Introduced in 1998 due to the increasing number of security incidents, Fujitsu’s ProjectWEB was initially developed as an in-house knowledge management tool for the company itself. Later in the mid-2000s, looking at the benefits it had for enterprises, the platform was then introduced as a cloud-based SaaS for public-facing offices and businesses in Japan. ProjectWEB was probably Fujitsu’s very own “Microsoft Teams” platform back in the day. It allowed collaboration and file-sharing both with internal and external stakeholders for ease of work. As per Fujitsu’s 2009 datasheet, it had 3,000 clients using ProjectWEB, including government and private enterprises.

Japanese Government Offices Hacked

Japan’s local news daily NHK, on Wednesday, first reported that multiple Japanese offices were hacked resulting in leaks of many critical datasets. As per the initial investigation, the cybercriminals reportedly first gained access to Fujitsu’s software at Narita Airport near Tokyo. There, they stole the Air Traffic Control’s critical information and then moved to other governmental offices. In a separate report, the Ministry of Land, Infrastructure, Transport, and Tourism also reported unauthorized “third-party” access on its information-sharing system (which again is Fujitsu’s ProjectWEB) that leaked around 76,000 email addresses of its contractors and employees.

Japan’s Cabinet Cyber ​​Security Center informed that the leak took place on May 24 and asked all agencies and private enterprises using Fujitsu’s ProjectWEB to stay alert and look out for any signatures or suspicious activities and possible leaks through their network. The Cabinet did not confirm other governmental agencies that were affected in this compromise but a report from Radio Taiwan suggests that even the National Center of Incident readiness and Strategy for Cybersecurity (NISC), which is responsible for information security countermeasures in the Japanese government, fell prey to it. It added that data such as equipment and composition used by the information system in the center were also stolen.”

However, the NISC itself is leading the investigation behind the hack and asked Fujitsu to temporarily suspend its ProjectWEB services. Fujitsu has obliged and is further analyzing the scope and impact of the hack. The company has issued a press release stating, We take this case very seriously and will continue to consult with the relevant authorities and make every effort to support the victims.”

A similar supply chain attack that shook the world earlier in the year was Accellion’s FTA hack. The company’s legacy file transfer sharing software, which was reaching its end of life, was exploited by cybercriminals who targeted multiple sectors with it across the globe. Supply chain attacks have seen an uptick since the SolarWinds attack in December 2020, and Fujitsu’s ProjectWEB could very well be Japan’s very own SolarWinds.

Related News:

Japan to Impose Strict Regulations on Private Sector’s Adoption of Foreign Equipment and Technology

Japan Confirms Defense Data Breach After Cyberattack on Mitsubishi Electric

New Malvertising Campaign Found Distributing Trojanized Version of AnyDesk

BotenaGo, malware over encrypted connections

Digital advertising is one of the fastest-growing media. The entire world is hooked to cell phones and hence digital ads are often found on social media and through Google AdWords/keywords. Owing to its growing popularity, adversaries use it as a solid platform to push their attacks on web users. Recently, security experts uncovered a sophisticated malvertising campaign (malware advertising) distributing the weaponized AnyDesk installer via targeted Google ad searches for the keyword “anydesk.” According to a security investigation from CrowdStrike Falcon Complete team,  cybercriminals are spreading a malicious file “AnyDeskSetup.exe” masquerading as a legitimate AnyDesk Remote Desktop application.

AnyDesk is a remote desktop application that provides independent remote access, file transfer, and VPN functionality to computer systems and other devices running the host application.

“Falcon captured AnydeskSetup.exe running from the user’s Downloads directory. A quick review of the file and the behavior observed from its execution revealed that this was not a normal AnyDesk installer,” CrowdStrike said.

How does Malvertising work?

In malvertising, malware code or script is spread via legitimate-looking ads on websites. Malware authors purchase ad space on popular websites to run their malware-infused ads on their web pages. With malicious codes hidden inside these ads, they often redirect the users to fraudulent websites or install malware on their devices.

CrowdStrike researchers stated the malicious executable file appeared to have been manipulated to evade detection and automatically installs a PowerShell script with the command line: C:\Intel\rexc.exe” -exec bypass \Intel\g.ps1. They also detected a “rexc.exe” executable file that appeared to be a renamed PowerShell binary to bypass and avoid detections.

The AnyDesk Malvertising Campaign

Attackers created specially crafted malicious Google ads to target users using Google to search for AnyDesk. The malvertising campaign, which is active since April 21, 2021, leveraged intermediary sites that redirect the users to a social engineering page hosted at the URL: https[:]//domohop[.]com/anydesk-download/, which auto-downloads the trojanized installer from the link: https://anydesk.s3-us-west-1.amazonaws[.]com/AnydeskSetup.exe.

CrowdStrike found that threat actors could have spent over $3,500 to get some 2,000 clicks for the single keyword – “anydesk.”

Indicators of Compromise

IP Address: 

176.111.174.126

176.111.174.125

Domains: 

Domohop.com

Anydesk.s3-us-west-1.amazonaws.com

Zoomstatistic.com

Anydeskstat.com

Turismoelsalto.cl

Rockministry.org

curaduria3.com

“CrowdStrike’s internal available data suggests that 40% of clicks on this malicious ad turned into installations of this trojanized AnyDesk binary, and 20% of installations included follow-on hands-on-keyboard activity. While it is unknown what percentage of Google searches for AnyDesk resulted in clicks on the ad, a 40% Trojan installation rate from an ad click shows that this is an extremely successful method of gaining remote access across a wide range of potential targets,” CrowdStrike added.

Endpoint Security: Protecting Businesses and Remote Workforce in the New Reality

Endpoint Security

Market research institutions and analysts have been predicting the rise of endpoints for years. Analysts project the rise of IoT devices due to 5G networks, which the U.S. and other countries have started deploying. The weak security of IoT-enabled devices has raised serious concerns. But when the pandemic was announced in March, the narrative changed — as employees packed up and moved their workstations to their homes. The surge in connected devices used by work from home employees worries CIOs and CISOs, who are already under pressure to accelerate digital transformation plans.

By Brian Pereira, Editor-in-Chief, CISO MAG

By Gartner estimates, in 2019, there were 365 million desktops used in offices worldwide. Today, over 1 billion people work from home – employed by 90% of organizations. Employee endpoints have tripled. In recent months, the demand for PCs, laptops, and tablets shot through the roof – there are times when retailers run out of stock. But the apprehensions are not due to the shortage of devices and poor connectivity at home; the bigger concern is inadequate security of those devices that could lead to data breaches.

Enterprise networks and devices behind corporate firewalls are protected by technology stacks and layers of security controls, governed by security policies and compliance. Security and operating system updates are regularly pushed to devices. USB ports and selective network ports are blocked. Storage and backups are frequently conducted on enterprise-approved cloud services. Protective firewalls encircle the network and there are various tools like identity and access management. But at home, it’s a different scenario, akin to leaving your front door open for anyone to walk in.

As employees transitioned to their home offices, there was little time to reconfigure laptops and enforce new controls and security policies. The cybersecurity strategies for most organizations are not designed for remote work environments and need major changes to address the cyber threats posed by remote work.

Home networks and endpoints operate in non-trusted environments and definitely up the risk quotient for corporate networks. Zero trust? Ha! The threat of data leakage looms high. There are all kinds of threats posed by remote workers. The probability of remote workers violating corporate security policies is high. And that’s a worry for organizations that have intellectual property and customer data.

The responsibility of managing endpoint security fell squarely on the remote worker. Months later, security may have vastly improved as IT enforced new policies and controls. But, what’s to stop an employee from clicking on a malicious link or malicious attachment in a phishing e-mail? Is the IT team really checking if an employee is using the office laptop to watch a movie on Netflix, or watching something far worse? How many adopt URL filtering or block social media? And what’s to stop an employee from backing up enterprise data to their personal cloud storage or removable storage media? Then there are home routers with factory-default passwords, susceptible to hacking from that kid next door (step-by-step instructions on YouTube and other websites)

To counter these challenges, some organizations opted for VDI (Virtual Desktop Infrastructure) and desktop-as-a-service. But could this solution entirely prevent risks like data leakage? How do you stop an employee from using their phone camera to take snapshots of what is shown on the screen? Keep the webcam on all day?

IT mandated the use of corporate-approved VPNs and anti-malware. A CISO MAG 2020 survey found that one in three employees do not use a VPN. In any case, VPNs are notorious for their rigid rules and cannot check abnormal user behavior.

Changing Attack Surface

Cybercriminals are taking advantage of the surge in remote work to exploit new attack vectors exposed by reliance on telework infrastructure with weak infrastructure. CISO MAG online reports on attacks on remote workers with COVID-related themes. The numerous scams are themed on fake news about the spread of the virus, and availing N95 masks and PPE kits in bulk, at “dirt cheap” prices. These days there are BEC (Business Email Compromise) attacks with themes around COVID vaccine research breakthroughs and the availability of vaccines. These scams are engineered to exploit a human weakness — FUD (fear, uncertainty, and doubt).

Operation Falcon conducted by INTERPOL is a recent example. Three Nigerian BEC scammers, who are part of a larger cybercriminal group dubbed TMT, were arrested in the city of Lagos. The analysis of their operations has revealed that the gang focuses on the distribution of phishing emails that contain popular malware strains under the guise of purchasing orders, product inquiries, and even COVID-19 aid impersonating legitimate companies. The attackers then use Gammadyne Mailer and Turbo-Mailer to send out phishing emails, which are then tracked using MailChimp, to see whether a recipient victim has opened the message. This is another example of an attack through the endpoints.

“The most common attacks are the results of using the endpoint segment as an entry vector, to get into the organization,” says Prateek Bhajanka, Senior Principal Analyst, Gartner. “It is ransomware campaigns and the ransomware infections that we generally know about — WannaCry, NotPetya, and other ransomware campaigns and infections. Besides ransomware, there are phishing campaigns, spear-phishing campaigns, attacks like social engineering, and business email compromise. Data breaches result in data exfiltration and these propagate through an endpoint segment.”

And as you connect the endpoint to the corporate network, these attacks spread laterally. Hackers target endpoints as an entry point, with the intention of moving laterally in the network, to take over privileged accounts.

Evolving Technology

Over the years, endpoint protection has evolved from prevention (antivirus, data encryption, intrusion prevention, data loss prevention) to detection and response (EDR). So, we now have various types of endpoint security and endpoint security tools and endpoint services.

“When we talk about endpoint security technology, it is not just the anti-virus that we need anymore. We need a technology stack that can protect the organization across the layers, not just endpoint, and not just from malware, but also from phishing attacks. It should protect the endpoints from malicious websites that you may be browsing on a daily basis,” says Bhajanka.

The attacks on endpoints may result in account takeover and credential theft. That’s why endpoint security goes beyond antivirus.

A New Approach

Traditional approaches to protecting endpoints from behind corporate firewalls are no longer applicable in today’s context and need a new approach.

“There is no perimeter anymore, and the organization has become boundary-less,” says Bhajanka. “And at the same time, the attack surface of an organization has also become wider and endless for the reason that now you may have one associate working from different locations in different cities. That makes endpoint security a top priority for CISOs and security professionals.”

Bhajanka suggests that security should be deployed in such a way that it should not matter where you work from – it should offer the same level of security.

According to Check Point, a modern-day endpoint security strategy must include the following:

Prevention-first Approach: The number and sophistication of cyberthreats are growing rapidly. A focus on prevention is essential to ensuring that lean security teams are not overwhelmed and for minimizing the cost and impact of cyberattacks on the organization.

AI-driven Security: Security teams lack the ability to scale to meet their growing workloads. Leveraging AI to automate and expedite threat detection, investigation, and response maximizes the efficiency and effectiveness of limited security personnel.

Strong Remediation and Recovery Capabilities: With a remote workforce, employee computers will be compromised by cybercriminals. Security teams need to have the policies, procedures, and tools required to rapidly, and effectively remediate a security incident.

Consolidated Security: Reliance on an array of standalone security solutions means that security analysts waste valuable time switching between dashboards and lack the comprehensive visibility required to detect and respond to incidents. Next-generation security requires a consolidated security architecture with single-pane-of-glass visibility and management.

Strong Real-Time Threat intelligence: The cyber threat landscape evolves rapidly, with many campaigns active for only minutes or hours. Access to real-time, strong threat intelligence is essential to an organization’s ability to protect against the latest threats, not ones from days or weeks ago.

Unified to Reduce TCO: Deploying separate solutions for EPP, EDR, NGAV (next-gen antivirus), VPN, etc. creates a complex environment that is difficult and expensive to configure and maintain. Deploying a unified security solution is essential to minimizing the total cost of ownership (TCO) of enterprise cybersecurity.

Cloud-Based: As corporate resources move to the cloud it is essential that cybersecurity solutions follow. A cloud-based security solution provides native protection to cloud assets as well as taking advantage of the flexibility and scalability offered by the cloud.

Additionally, it should be policy-driven. Ensure that there are tight security controls at all endpoints, backed by stringent security policies. Apply a zero-trust, least privilege access for all endpoints by default.

Conclusion

Traditional approaches to endpoint protection are no longer adequate in a distributed or remote work environment. Organizations need to deploy enterprise-grade security controls and update security policies for remote working.

There are various endpoint solutions available in the market. Look for a unified solution to simplify the management of- and increase the effectiveness of endpoint security solutions. Deploying a unified security solution is essential to minimizing the total cost of ownership (TCO) of enterprise cybersecurity.

Create a rapid action task force and strategy to remediate and protect endpoints.

As corporates move more infrastructure to the cloud, one needs to think holistically — to not just secure endpoints but also “workloads” and infrastructure. Deploy “intrinsic” security with AI, analytics, and predictive capabilities. And take a prevention-first approach.

This story first appeared in the December 2020 issue of CISO MAG.


Brian PereiraAbout the Author

Brian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

Has Your Organization Addressed These 3 Common Employee Habits?

Employee habits

Cybersecurity risks are a major concern for most organizations globally. Cyberattacks are often seen as threats from outside, but sometimes inadvertent actions from employees might collapse a company’s security defense. According to the study Psychology of Human Error, nearly 88% of data breach incidents are caused by employee mistakes. Around 50% of the employees stated that they are “very” or “pretty” certain they have made an error at work that could have led to security issues for their company.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Several organizations are concerned about the insider errors that cause accidental exposure of the company’s critical data. Here are the three most common yet risky employee actions that might expose your business to the risks of cyberattacks.

1. Clicking Unknown Links

Cybercriminals often lure employees with malicious URLs to automatically download malware and infect their devices. Attackers mostly leverage sophisticated phishing emails by mimicking an employee or a security admin from the same company.

How to Fix:

Ask your employees to be vigilant about what they click online as it could be malicious. Never click on suspicious links in emails, messages, and social media platforms received from unknown sources. Investigate the sender/resource before clicking any links.

2. Downloading Malware

Organizations may suffer severe security risks if a single employee unintentionally opens a weaponized email attachment that has malware embedded in it. Cybercriminals often use malicious email attachments that contain executable files which, if downloaded, installs malware into the targeted employee device or network. Attackers also send dangerous malware like Adware, Spyware, Banking Trojans, ransomware, and cryptocurrency miners that cause a severe impact to users and organizations.

How to Fix:

Always cross-check the sender source before opening/downloading any attachment in the email. The attachments might contain Trojans and viruses, which, if downloaded, cause enormous security issues.

 3. Responding to Phishing Emails

A phishing attack is a common cyberthreat in which hackers target a particular employee or group of employees with fake websites and phony login pages to pilfer user credentials. In phishing attacks, threat actors often ask users to act immediately such as: “click on this link to reset your password” or “visit this site to recover your suspended account.” Once a user clicks/visits on the link, it redirects the user to a fake login page tricking the user into entering login credentials.

Read more: Five Phishing Baits to Know

How to Fix:

Never respond to suspicious emails. Look for spelling mistakes or errors in the email. Always enquire with your security team whenever you receive such kind of emails.

Conclusion

The only way to prevent employee errors is by enhancing their cyber behavior. Organizations must encourage employees to practice robust online security measures to avoid any cybersecurity mishap. Besides, make them use strong passwords and provide training to spot phishing emails and other security threats before they turn into potential data breaches or cyberattacks.

About the Author:

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

Read More from the author.

 

Audio Equipment Manufacturer Bose Confirms Data Breach Following Ransomware Attack

Bose suffers ransomware attack

Organizations globally encountered a series of high-profile ransomware attacks this year.  From the U.S. fuel supplier Colonial Pipeline, laptop maker Acer to affecting Irish health services, ransomware attacks continue to loom over cyberspace.

The latest victim of a ransomware-fueled data leak is Bose Corporation. In an official breach notification to New Hampshire’s Office of the Attorney General, the premier audio equipment manufacturer admitted that it has sustained a data breach due to a ransomware attack in March.  The threat actors behind the attack are yet unknown, however, Bose claimed that they accessed some of its employee information including employee names, social security numbers, and compensation-related data.

“Immediately upon discovering the attack on March 7, Bose initiated incident response protocols, activated its technical team to contain the incident, and hardened its defenses against unauthorized activity. In conjunction with expert third-party forensics providers, Bose further initiated a comprehensive process to investigate the incident. Given the sophistication of the attack, Bose carefully, and methodically, worked with its cyber experts to bring its systems back online in a safe manner. As the systems have been restored, Bose has worked with its forensics experts to determine the data that may have been accessed and/or exfiltrated,” Bose said in a statement.

Bose found that data related to six of its former New Hampshire employees was accessed and potentially exfiltrated in the incident. “The forensics evidence at our disposal demonstrates that the threat actor interacted with a limited set of folders within these files. However, we do not have evidence to confirm that the data contained in these files were successfully exfiltrated, but we are also unable to confirm that it was not,” Bose added.

While there is no indication of misuse of impacted employee data, Bose has reported the incident to the FBI and engaged security experts to monitor for any signs of exploitation of leaked data.

As a precautionary measure, Bose has also implemented certain mitigation strategies. These include:

  • Enhanced malware/ransomware protection on endpoints and servers to further enhance our protection against future malware/ransomware attacks.
  • Performed detailed forensics analysis on the impacted server to analyze the impact of the malware/ransomware.
  • Blocked the malicious files used during the attack on endpoints to prevent further spread of the malware or data exfiltration attempt.
  • Enhanced monitoring and logging to identify any future actions by the threat actor or similar types of attacks.
  • Blocked newly identified malicious sites and IPs linked to this threat actor on external firewalls to prevent potential exfiltration.
  • Changed passwords for all end-users and privileged users.
  • Changed access keys for all service accounts.

In addition, Bose informed that it would be providing free identity protection services to the affected individuals for 12 months.

Talking to CISO MAG, Adam Laub, General Manager, Stealthbits (now part of Netwrix), said, “Assuming the information Bose has shared is true, it would appear the organization was reasonably well-prepared for what many would consider the inevitable. As ransomware preys and thrives on lax foundation-level controls, the fact that only ‘a very small number of individuals’ were impacted, and they did not have to resort to paying the ransom, would indicate that Bose may have addressed many of the weaknesses ransomware tends to easily exploit. Furthermore, the immediate inclusion and involvement of a third-party specialist to diagnose the extent of the damage and restore infected systems would indicate that Bose knew what to do if and when such an event occurred.

So often organizations wait too long to understand that they lack the knowledge or capability to deal with these situations alone or adequately. While there for sure will be some lessons learned from this event, Bose was either extremely lucky or had done a more exemplary job of mitigating, detecting, and responding to what so many organizations have failed so miserably with. Given the efficiency and pervasiveness of ransomware in the world today, it’s much more likely the latter than the former.”

NASA Plans to Realign its Cybersecurity Strategy

NASA

In a recently released audit report, the Office of Inspector General (IG) stated that “attacks on NASA networks are not a new phenomenon.” However, the complexity and severity of these attacks are increasing by the day. But still, NASA’s cybersecurity strategy seems to be “disorganized,” and requires immediate realignment, added the IG. Jeffrey Seaton, NASA’s CIO, agreed to the IG’s findings, which further stated their concern that the Office of the CIO (OCIO) has struggled to implement an effective IT governance structure that aligns authority and responsibility with the agency’s overall mission.

Is NASA’s cybersecurity readiness in question?

NASA has a large digital footprint with over 3,000 websites and more than 42,000 publicly accessible datasets. No wonder, the national space agency has faced more than 6,000 cyberattacks in the past four years alone.

types of cyberattacks on NASA, NASA cybersecurity strategy
Table: Types of Cyberattacks at NASA. Source: OIG presentation of NASA data.

Having agency-wide, strong cybersecurity practices is vital for NASA to protect itself from current and future threats in cyberspace. However, the IG’s report said, “We found that NASA’s ability to prevent, detect, and mitigate cyberattacks is limited by a disorganized approach to Enterprise Architecture (EA).”

The IG appreciated that the OCIO has made notable efforts to improve NASA’s cybersecurity readiness. In September 2019, NASA updated its IT strategy to identify critical activities, milestones, and resources needed to manage IT as a highly strategic resource. To further polish this strategy, the OCIO is also currently working on two important initiatives:

  1. Mission Support Future Architecture Program (MAP) – NASA’s various services like IT, human resources, finance, and procurement have been managed and operated separately at each center and/or headquarters. However, the MAP is being devised to bring it under centralized control so that it can be governed by consolidated cybersecurity capabilities rather than individualistic. The agency expects the MAP assessment to be complete by the end of 2021, and proceed with its implementation in January 2022.
  2. The Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Contract – It is a broad cybersecurity management contract that aims to eliminate duplication of cyber services amongst various centers of the agency. CyPrESS is not officially a subset of MAP but tends to work in tandem with it to deliver a centralized service model.

The IG is pleased with these initiatives but has suggested advancement in the CyPrESS to include services like security operations center (SOC), penetration testing, vulnerability management, supply chain risk management, training, and knowledge sharing, as well as identity, certificate, and access management. As per a government contracting database maintained by Deltek, the solicitation for awarding the contract to an experienced enterprise was scheduled to be published on May 17. However, according to the Federal System of Awards Management, the proposal is still in the pre-solicitation stage, which may put its February 2022 work initiation deadline in a jeopardy.

NASA has agreed to its shortcomings and based on the recommendations given by the IG’s audit report, create an enterprise architecture program; monitor metrics on the efficacy of its enterprise security architecture; and perform a cost evaluation for the agency’s 526 IT systems that have been classified in one of three risk exposure levels ranging from Low to High.

Related News:

DopplePaymer Gang Claims it Hit NASA Contractor with Ransomware Attack

Information Security Governance Guide For the CISO

Confidential Information

We’re not in an information age anymore. We’re in the information management age. ~ Chris Hardwick.

Information governance is a corporation’s core information policy. The IT Governance Institute (ITGI) defines governance as:

“The set of responsibilities and practices exercised by the board and executive management to provide strategic direction, ensure that objectives are achieved, ascertaining that risk is managed appropriately and verifying that the enterprise’s resources are used responsibly.”

The method of organizing, guiding, monitoring, and affecting strategic decisions, activities, and behaviors is known as information security governance (ISG). One of the goals of information security governance is to assure that the security framework is correct and reaches the organizational vision.

By Irfan Shakeel, Founder and Lead Trainer at EH Academy

Information security governance is a collection of standardized modules; that promises top management that the companies’ primary goals reflect their overall security. Once the modules are in position, executives get confident that efficient information security protects the firm’s most sensitive and valuable resources.

The Information Security Governance Ensures:

  • Strategic alignment: It is aligned with the corporate plan to achieve goals.
  • Risk management: Decreases threat and severe consequences to decent amounts.
  • Value delivery: Getting the best out of security expenditures to achieve targets.
  • Resource optimization: Security skills and services use wisely.
  • Performance measurement: Monitoring and supervising are done to confirm the achievement of goals.
  • Integration: Incorporate assurance components to enhance the operations run smoothly from stem to stern.

Roles and Responsibilities

Information security governance necessitates thorough planning and implementation. It requires dedication and assets, along with delegating responsibility to professionals for information security. Information security governance allows the committee to assess whether the corporation’s priorities are achieved or not. Following is a list of the various positions and responsibilities:

  • The Senior Management oversees providing overall information security governance guidance and assistance.
  • Executive management is responsible for defining operational security goals and setting efficient security governance to accomplish them.
  • The Chief Information Security Officer (CISO) oversees designing security policy, overseeing business security operations, and engaging with business owners.
  • Security Steering Committee (SSG) identifies the security plan and implementation efforts. Particularly an attempt to align security with company unit operations.

Chief Information Security Officer (CISO)

Company with the most security issues, professional leadership is still needed. The CISO’s job is to do the same. As a part of the leadership board, the CISO is known as a mentor, trainer, and security leader. The CISO oversees and directs security activities throughout the organization, such as IT, HR, marketing, legal, and other departments. The most effective CISOs find a balance between stability, efficiency, and creativity. The CISO proponent of security as a company imperative while still bearing in mind the necessity to safeguard the company from unintended damage. This role usually corresponds to top management (CFO, CEO, COO) and has direct access to the executive board.

  • In managing risk, the Chief Information Security Officer (CISO) assesses risks, determines risk reduction strategies, and ensures compliance.
  • In terms of value delivery, the Chief Information Security Officer (CISO) is responsible for effectively managing and maximizing the use of security assets.
  • In terms of resource management, the CISO oversees creating, tracking, and evaluating recent progress and asset use.
  • The Chief Information Security Officer (CISO) oversees the implementation of measures to track security operations in performance management.
  • In terms of integration, the CISO responsible for establishing a connection with other assurance roles and facilitating integration on an ongoing process.

To better understand the position of the CISO, follow a hypothetical scenario through the conceptual information security governance mechanism.

  • The CISO decides that an incident response plan is necessary.
  • The CISO collaborates with the information security consulting committee for guidance on the proposal’s requirements.
  • The information security consulting panel or the CISO appoints a task team to develop an incident response plan.
  • The advisory committee assesses the document in conjunction with security service teammates.
  • The CISO receives a suggestion from the information security consulting panel that the document is approved.
  • The CISO evaluates and approves the document.
  • Using the IT governance score sheet, the CISO decides if this ought to proceed to IT governance.
  • For analysis, the CISO delivers a document to the Technology Support subcommittee.
  • The Technology Support subcommittee evaluates and ratifies the document with slight modifications that the CISO approves.
  • The CISO provides the Strategic IT Committee with a fully updated incident response plan for evaluation.
  • The Strategic IT Committee evaluates and approves the strategy.
  • The CIO advances the incident response plan to the point that it becomes a policy.

Final Thoughts

The method of organizing, guiding, monitoring, and affecting strategic decisions, activities, and behaviors is known as information security governance (ISG). Outcomes of information security governance are strategic alignment, risk management, value delivery, resource optimization, performance measurement, integration. Move towards multiple roles and responsibilities. Then discuss the Chief Information Security Officer (CISO) with an example.


About the Author

Irfan ShakeelIrfan Shakeel is the founder and a lead trainer at EH Academy (training portal of ehacking.net). He teaches OSINT, penetration testing, threat intelligence, and cybersecurity leadership courses. He also writes for many publications such as AT&T Security, Infosec Institute, etc. Podcasts and webcasts hosted by Irfan can be found all over the internet.

DISCLAIMER

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Verizon 2021 DBIR: Cyberattacks Continue to Rise During Pandemic

data breaches, Verizon Data Breach Investigation Report

From phishing attacks, identity theft to brand impersonation attacks, cybercriminals leveraged all kinds of attack vectors during the pandemic. This resulted in a huge number of cyberattacks being reported since last year. According to the “Verizon Business 2021 Data Breach Investigations Report (DBIR),” phishing and ransomware attacks increased by 11% and 6% respectively, and misrepresentation increased by 15% due to remote working conditions. The report analyzed 29,207 quality incidents, out of which 5,258 were breaches from 83 contributors across the globe.

“The COVID-19 pandemic has had a profound impact on many of the security challenges organizations are currently facing. As the number of companies switching business-critical functions to the cloud increases, the potential threat to their operations may become more pronounced, as malicious actors look to exploit human vulnerabilities and leverage an increased dependency on digital infrastructures,” said Tami Erwin, CEO, Verizon Business.

Key Findings

  • Over 85% of breaches involved a human element, while over 80% of breaches were discovered by external parties.
  • Breach simulations found the average financial impact of a breach is $21,659, with 95% of incidents falling between $826 and $653,587.
  • The report also highlighted the challenges facing businesses as they move more of their business functions to the cloud – with attacks on web applications representing 39% of all breaches.

Affected Industries

  • In the financial and insurance sector, 83% of data compromised in breaches was personal data, whilst in Professional, Scientific, and Technical services only 49% was personal. The financial sector frequently faces credential and ransomware attacks from external actors.
  • Basic human error continues to beset the health care sector for many years. The most common error continues to be misdelivery (36%), whether electronic or paper documents.
  • Social engineering and phishing attacks are at an alarming high in the public administration
  • The retail industry continues to be a target for financially motivated cybercriminals looking to cash in on the combination of payment cards and personal information. Social tactics include pretexting and phishing, with the former commonly resulting in fraudulent money transfers.

Cyberattack Landscape During the Pandemic

The 2021 DBIR received insights from over 83 contributors who provided specific data inputs about regional cyber trends. These include:

  • Asia Pacific (APAC) – Many of the security breaches in APAC were caused by financially motivated attackers phishing employees for credentials, and then using those stolen creds to gain access to mail accounts and web application servers.
  • Europe, Middle East, and Africa (EMEA) – The region continues to be beset by web application attacks, system intrusion, and social engineering.
  • Northern America (NA) – NA is often the target of cybercriminals searching for money or easily monetizable data. Social engineering, hacking, and malware attacks continue to be the favored tools utilized by actors in this region.

“When you read the contents of the report, it is tempting to think that a vast array of threats demands a sweeping and revolutionary solution. However, the reality is far more straightforward. The truth is that, whilst organizations should prepare to deal with exceptional circumstances, the foundation of their defenses should be built on strong fundamentals – addressing and mitigating the threats most pertinent to them,” said Alex Pinto, Lead Author of the DBIR.

Ransomware Attacks Will Become More Prevalent in H2 2021: ISACA Survey

ransomware, ryuk ransomware, cox media

From the recent Colonial Pipeline attack to the D.C. Metropolitan Police Department and numerous small and medium enterprises (SME), the world has witnessed a barrage of high-profile ransomware incidents in the past few months. In the aftermath of these sweeping attacks, a global IT association, ISACA, exclusively surveyed IT risk, security, and governance experts to weigh in their opinion on the ransomware menace. And one of the biggest revelations of the survey was that 84% of the respondents believed ransomware attacks will become more prevalent and gain further momentum in the second half of 2021.

To Pay or Not to Pay?

The Colonial Pipeline attack not only disrupted gasoline distribution in the Eastern Coast of the U.S. but also brought questioned issues concerning the ransomware attack preparedness of critical infrastructures to the front-burner. Owing to the chaos caused by this sudden disruption, Colonial Pipeline’s CEO reportedly authorized a ransom payment of $4.4 million. However, a striking majority of surveyed individuals did not agree to this. Only 1 in 5 people (22%) said that critical infrastructure organizations should pay the ransom if attacked.

Concurring to it, Dustin Brewer, senior director of emerging technology and innovation at ISACA, said, “In a vacuum, the guidance not to pay makes total sense. We don’t want to negotiate with criminals. But when you need to get your business back online, a cost/benefit analysis is going to come into play, and a company is going to do what it needs to do to have continuity.”

Image Credit: ISACA

Key Findings

  • 85% of the respondents believe that they are at least somewhat prepared for a ransomware attack, however, the concern here is that only 32% of them are confident of being “highly prepared.”
  • 4 in 5 said their organization is better prepared for ransomware attacks now as compared to 2017, when the WannaCry, Petya and NotPetya attacks inflicted major damage.
  • Two-thirds of the respondents expect their organization to take further precautions in the aftermath of the Colonial Pipeline incident.
  • 46% consider ransomware to be the most likely cyberthreat to impact their organization in the next 12 months.
  • 38% of the surveyed individuals say their company has not conducted any ransomware training for their staff.

Looking at these numbers, Brewer added, “The fact that more than 80% of organizations are more prepared for ransomware incidents now than they were during the 2017 attacks — and that so many will be taking new precautions after Colonial Pipeline — is wonderful news. Open reporting of cyberattacks appears to be working, and in this transparency, we can expect to see newer threats mitigated earlier with faster response times.”


Related News:

U.S. Introduces Security Bills to Secure Critical Infrastructure