Home Blog Page 83

Heightened Use of Internet Observed in Older Population: ACMA Survey

Cryptocurrency scams in Australia

The use of the internet differs from person to person. Factors like age and lifestyle define their online behavior. Besides, the impact of the COVID-19 outbreak changed people’s views towards data privacy. According to a survey from the Australian Communications and Media Authority (ACMA), privacy is a major concern for 70% of Australians. 9 in 10 people chose “choice and control” over their personal information.

The ACMA released two reports recently, the first report provides the digital preferences of Australians aged 65 and above, and the second report provides a similar kind of data for Australians between 18 to 34 years old.

The survey analyzed how older people adapt to the digital world and their behavioral shifts towards the internet. It revealed that while younger individuals are still leading the charge in the extent and types of online behaviors, there is a significant change in the online habits of those aged 65 and older.

Key Findings

  • Older people increased their online activities during the COVID-19 pandemic, particularly for communication and entertainment.
  • Nearly, 93% of older people had internet access in their homes in June 2020, up from 68% in 2017.
  • On average, 26% of older people used 5 or more types of devices to go online in the 6 months to June 2020, compared to 6% in 2017.
  • 55% of older people used an app to communicate in the previous 6 months to June 2020, compared to 33% in 2019.
  • While young people are significantly more positive than older people about digital technology, and new developments in this space, 60% of them feel that computers and technology give them more control over their lives.
  • Almost 50% of young people used on average 5 or more types of devices to go online in the 6 months to June 2020, up from 30% in 2017.
  • Over 76% of young people used a smart device, with an average of 1.3 different types of smart devices.
  • Mobile phones are the most common device used by young people to access the internet (97%), followed by laptops (82%) and tablets (51%).

“Our engagement with technology continues to evolve at a rapid pace as the capability and capacity of online technology expand. While younger age groups are quick to embrace this change, for some older people whose internet journeys typically began later in life, keeping up has been more challenging,” the survey stated.

Biggest Privacy Risks for Australians

According to the 2020 Australian Community Attitudes to Privacy survey, the major privacy risks identified by Australians in 2020 include:

  • Identify theft and fraud (76%)
  • Data security and data breaches (61%)
  • Security threats from digital services, including social media sites (58%)
  • Threats from smartphone apps (49%)
  • Surveillance by foreign entities (35%) or Australian entities (26%)

In addition, 59% have encountered issues with how their personal information was handled in the past 12 months. The majority of problems are regarding unwanted marketing campaigns or companies collecting personal information without their consent.

Cyberthreats: The Stealthily Spreading Cancer in the Health Care Sector

cyberthreats in health care

Public health plays a major role in determining the quality of life. As seen during the pandemic, public health and the health care sector are intrinsically linked. However, the health care industry is plagued with chronic cyberthreats. From clinicians to pharmaceutical companies, the entire ecosystem and value chain has moved to a highly inter-connected model.

 SPONSORED CONTENT 

Before “Industry 4.0,” which revolutionized digital transformation, health care followed a straightforward path – from provider to patient. But with digitization taking center stage, everything from monitoring, detecting, controlling, and responding, is done by interconnected or IoT-based devices. While the health care sector across the board embraces the shift into the modern digital era, cyberthreats have equally continued to grow stealthily in both sophistication and volume. Thus, governing cybersecurity and privacy measures is now a chief priority for health care C-suite leaders and their organizations.

The other arm of health care is the pharmaceutical sector. And with countries like India, the U.S., the U.K., Australia, China, and Russia running the rat race in pursuit of manufacturing and exporting these vaccines, heightened activities among state-sponsored cybercriminals have also been observed recently.


cyberthreats in health care industry

Want to know more about the cyberthreats lurking in the darker depths of the health care industry? 


Cyberthreats to the health care and pharmaceutical organizations are real, and regulations are only a single step towards addressing the bigger issue at hand. Cybersecurity efforts must be a business initiative with equal weightage on people, processes, and technology to combat the threats at bay.

Today, at a time when the entire world’s health care system is reeling through the aftermath of the COVID-19 pandemic, what if WannaCry hits back? The entire health care infrastructure will simply collapse. Thus, there is a dire need of knowing these risks and countering them beforehand. But how?

To get a deeper understanding of the latest health care-related cyberthreats, and be better equipped to protect their people, data, and assets, CISO MAG editors worked closely with CYFIRMA’s cyber threat intelligence (CTI) team, who burrowed through the trenches of the threat landscape to provide critical and resourceful information that can help today’s decision-makers in making well-informed decisions.

To know more


cyberthreats in health care industryCYFIRMA’s CTI is predictive, outside-in, and personalized, based on the Industry type and landscape. To connect the dots between the hacker, motive, campaign, and method, visit us on www.cyfirma.com

These are the Top 5 Cybersecurity Jobs in 2021

Top Cybersecurity Jobs in 2021

Digital security is becoming more critical than ever with organizations moving towards rapid digital transformation and automation.  Securing valuable data, programs, intellectual property, and other digital assets has become paramount as everything is stored online. Organizations globally are focusing more on recruiting cybersecurity professionals to secure their digital infrastructure from evolving cyber threats. The demand for security specialists in the industry is high as cybersecurity jobs have gained mainstream momentum.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Cybersecurity Job Landscape

Amid growing cybersecurity risks, most organizations are stepping up their cybersecurity and digital transformation budgets, which in turn increases opportunities for skilled security professionals. A recent analysis from Gartner revealed that investment in information security and risk management technology and services is expected to grow 12.4% to reach $150.4 billion in 2021. Organizations are looking ahead to growing automation and further adoption of machine learning technologies in support of AI security to combat evolving cyberattacks. According to Cyber Seek, there are nearly 465,000 open job positions in cybersecurity in the U.S. as of May 2021, with a very low cybersecurity workforce supply ratio.

 Here are some of the most demanding cybersecurity jobs:

1. Chief Information Security Officer

Role: Senior level

The Chief Information Security Officer (CISO) is a senior-level executive responsible for meeting the company’s cybersecurity plans with the business goals. Most organizations have a CISO on their management team to oversee the company’s security and IT operations, implementing security strategies and budgets to protect the organization’s critical infrastructure. CISOs keep abreast with the latest industry happenings and offer real-time analysis of threats that might arise during big business moves such as mergers and acquisitions.

To become a CISO, one should have sound experience in different cybersecurity job profiles.

Required Skill Set

  • Good experience IT sector
  • Incident management and supervisory skills
  • Business expertise
  • Strong communication and presentation skills
  • Risk management

EC-Council’s C|CISO Certification provides a real-world experience to succeed at the highest executive levels of information security.

2. Ethical Hacker

Role: Mid-level

An Ethical Hacker, also called a Penetration Tester or Pen Tester, is responsible to perform in-depth tests across a company’s network systems and web applications to find vulnerabilities or any security loopholes before they are exploited by cybercriminals.

Ethical hackers need to possess strong understanding about the psyche and motives of cybercriminals in order to conduct pen testing to discover security vulnerabilities and gaps in the network.

Required Skill Set

  • Good networking skills
  • Knowledge of Java, Python, and Perl platforms
  • Black box testing
  • Strong reporting and presentation skills

EC-Council’s certificates like Licensed Penetration Tester (LPT) and Certified Ethical Hacker (CEH) will certainly help in the pursuit of this role and opportunity.

3. Security Architect

Role: Senior level

A Security Architect is responsible for designing IT security structures, develop architecture patterns, and new security approaches for an organization. Besides, the security architect is responsible to educate staff on security policies and provide security assistance to prevent cyber risks.

Required Skill Set

  • Strong IT background
  • Knowledge in cyber risk management
  • Network hardware configuration
  • Knowledge of security protocols and cryptography
  • Analytical and problem-solving skills

EC-Council’s Certified Security Specialist (CSS) will benefit the security architect aspirants in anticipating possible breaches.

4. Network Security Engineer

Role: Senior level

A Network Security Engineer fronts an organization’s digital and physical assets and prevents them from cyberthreats. They oversee IT infrastructure, operational data center systems, and networks. A network security engineer is also responsible for the maintenance of firewalls, routers, switches, VPNs, and other network monitoring tools.

Required Skill Set

  • Sound networking skills
  • Knowledge security architecture and management of operating systems
  • Knowledge of C, C++, Python, and Java is required
  • Strong communication and presentation skills

EC-Council’s Certified Network Defense Architect (CNDA) and Advanced Network Defense will boost opportunities in the field.

 5. Digital Forensic Analyst

Role: Mid-level/Senior

A Digital Forensic Analyst is a cybersecurity detective required at the crime scene to investigate the severity of the incident. A DF Analyst studies cyberattacks, collects digital evidence and supervises and trains the team to follow suit. They are responsible for retrieving deleted, lost, manipulated, or stolen data. the digital forensic analysts are required to work closely with the police and law enforcement authorities to investigate cybercriminal activities.

Required Skill Set

  • Networking skills
  • Knowledge in cyber law and criminal investigation
  • A sound analytical mind with attention to detail

EC-Council’s Computer Hacking Forensic Investigator Certification will help aspirants in achieving the desired job.

Cybersecurity is an interesting field, to say the least. And there are multiple reasons to pursue a security career.

About the Author:

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

Read More from the author.

 

“I think it’s extremely unproductive to have individual state privacy standards”

Armistead Whitney is the Founder and CEO of Apptega, the software platform helping businesses around the world build, manage and report their cybersecurity programs. He has over 25 years of experience in creating and leading enterprises in the security, software, and Internet industries including raising over $75 million in venture capital and participating in a successful IPO. His passion is developing creative go-to-market business strategies, launching new products, implementing predictable metrics-driven sales models, and fostering team culture in industries ripe for change.

In an exclusive interaction with Augustin Kurian from CISO MAG, Armistead talks about Industry 4.0, its cybersecurity implications, traditional multi-layered defense techniques, and the cybersecurity skill gap.

Edited excerpts of the interview follow:

Industry 4.0 is progressing at a very fast pace and creating disruptive challenges in the day-to-day life of mankind. What lies behind this phenomenon — the fourth industrial revolution — and what will be its impact on the cybersecurity landscape?

The transfer of power from humans to software, devices, and robotics in manufacturing in a fourth industrial revolution world will have major impacts on the cybersecurity landscape. IIoT (Industrial Internet of Things) devices often exist across flat networks that are unprotected, giving threat actors multiple entry points to penetrate them. IIoT ecosystems that include prized IP and commerce (transactions) will be at the highest risk for hackers to focus on. The impact of this risk will likely include the creation of new regulations and standards to protect businesses and global economies, software-driven security solutions that operate in real-time and can monitor the entire vertical IIoT system, and the need for more interoperability between security products that can work more seamlessly together across the entire network.

According to a study on good practices for IoT security, and smart manufacturing, cybersecurity is a key enabler for Industry 4.0 adoption. What are your thoughts on that? Do you believe the global approach towards cybersecurity has changed, and a model of security-by-design is standard?

I’m not convinced that cybersecurity is a key enabler for Industry 4.0 adoption. If history proves correct, we can look back to the Third Industrial Revolution — the invention and proliferation of networks, computers, and then the Internet itself with all of the breakthroughs replacing human, manual labor in some way — make things better/faster/cheaper as the cliche goes — which fundamentally were created by scientists and engineers first followed by entrepreneurs who developed businesses to capitalize on those technologies. It’s unlikely these two essential stakeholders — scientists and entrepreneurs — took a “cybersecurity first” approach. Rather, as technology is embraced in the wider mainstream market, cybersecurity became an essential element to maintain the speed of the revolution. As we look to Industry 4.0 adoption, cybersecurity will likely be more at the forefront than in any previous industrial revolution, but not at the risk of completely stifling innovation and monetization, at least early on. It tends to follow disruptive innovation, not lead it.

How will the role of a CISO evolve in Industry 4.0?

First, the CISO will likely have a bigger seat at the table early in the innovation curve than ever before. A lot is at stake for an organization to win early in a new industrial revolution and CEOs and Boards will want to eliminate as much risk as possible around their IP, revenue growth, and brands — things all at stake with either great or poor cybersecurity. Second, the CISO will have a daunting task to sort through an ecosystem of 5,000+ cybersecurity tools and solutions to build the right ecosystem with as few vendors as possible. Interoperability between products needs to improve significantly to make this easier for the CISO. We’re already seeing several leading brands partnering together to bring more “total solutions” to the market, but that needs to happen much more and on a larger scale. And not just leading brands, but emerging brands and start-ups need to participate as well. CISOs are caring less and less about working with the biggest providers, and more about the stitching that can occur between multiple providers to make vendor management, implementation, and investments much more favorable.

Regulators around the world are taking notice and implementing new controls for cyber risk to address the growing threat to enterprises. In recent years, there has been a paradigm shift in the way attackers are exploiting the source, behavior, vector, and motives. Even COVID-19 changed the dynamics of cybersecurity. Is traditional multilayered defense that enterprises already have adequate to protect against attackers?

Even before COVID-19, many enterprises were finding that they didn’t have good cybersecurity hygiene, even despite multilayered defense systems, due to a number of issues like short-staffed cybersecurity teams, keeping up the increase in enterprise apps, and moving more infrastructure to the cloud. With the average enterprise using 50+ security-specific tools to protect data and intellectual property, understaffed security teams are forced to manage toolsets they don’t know or understand how to fully utilize.

The pandemic has highlighted the importance of strong cybersecurity systems, especially as a large portion of the workforce adapts to working from home and stretches the boundaries of distributed networks.

According to research, 91% of all enterprises follow a cybersecurity framework, which equates to 400,000 companies and over 2.8 million cybersecurity professionals are searching for ways to find the right vendors. There appears to be a need for a B2B e-commerce marketplace dedicated solely to cybersecurity and compliance. How is Apptega helping enterprises on this specific front?

As more enterprises turn to cybersecurity frameworks such as SOC 2, PCI, ISO, and NIST as their playbooks to build and implement their cybersecurity programs, implementing the hundreds of requirements is very complex. PCI alone has over 250+ and not one vendor can satisfy all of them. So, CISOs and their teams in IT are forced to navigate 5,000+ security vendors to find the best solutions and none of them talk to each other. Traditional channels for buying security are very cumbersome and inefficient and include sifting through hundreds of choices on Google, attending trade shows and conferences (not possible today with COVID), or dealing with constant cold calls and cold emails from security company sales reps.

CyberXchange by Apptega maps cybersecurity products and services to exact framework requirements on the subcontrol level enabling a buyer to easily search, self-educate, compare pricing, and purchase solutions all in one place matched to their framework in a way that’s simple and easy to navigate. The underlying technology in CyberXchange is a proprietary mapping engine with AI, called Harmony. Harmony pulls in the criteria and configurations of thousands of security products and services and maps it to 10,000+ security framework controls and categories. It also contains a predictive model that ingests vendor data and assigns it to the right search results. Users get super accurate search results and insights. CyberXchange also shows how a particular solution maps across multiple requirements in a framework, which helps eliminate vendor overlap and redundancy and improves a company’s ROI on its cybersecurity investments.

From a cybersecurity standpoint, there are several cybersecurity guidelines and compliance norms across different countries and regions, like SOC 2, PCI, HIPAA, NIST, CMMC, CCPA, and GDPR. Do you believe there should be a standard global cybersecurity compliance instead of multiple ones?

For the foreseeable future, we’ll continue to see multiple industry-specific cybersecurity compliance standards like SOC 2 (cloud), HIPAA (healthcare), and PCI (retail/e-commerce) applying to U.S. companies. However, privacy may be a different story. With GDPR being the new European privacy standard widely adopted globally and CCPA being out for many months to protect California consumers, it’s likely other states in the U.S. will follow suit and push ahead with their own privacy standards. I think it’s extremely unproductive to have individual state privacy standards. The amount of effort for companies of all sizes to manage 50+ compliance standards for doing business with consumers across state lines is unimaginable. I believe one national compliance standard for consumer protection makes the most sense and is inevitable. However, given that it’s an election year and the impact of COVID, any initiatives to create a national privacy standard are likely paused for now. It’s a real struggle for security and IT professionals to implement solutions to satisfy the hundreds of controls mandated by the standards. Translating the control requirements to a specific product is not an easy task and it ends up creating overlaps, excessive spending, and vendor overload.

By 2022, it is estimated that 1.8 million new cyber experts will be needed globally. Inclusivity including gender diversity, racial diversity, and neurodiversity is usually pointed to as a leading strategy, but the problem persists. What is your take on that, and what solutions do you suggest?

There is a huge lack of cybersecurity talent in the market, exceeding 1 million open jobs. Interestingly, cybersecurity is one of the highest paying jobs in IT — averaging well into the six figures annually, and it’s an industry that will continue to grow for many years. Yet, it’s been very challenging to fill the gap. One issue is the amount of training it takes to learn the cybersecurity trade. All the school coursework and degrees in the world are no substitute for real-world experience. It can take years to achieve the knowledge and experience needed to be great at it. With the average new worker switching jobs every two years, continuity is also an issue. I believe the solution lies in education, government, and private enterprises working together to foster young career seekers to focus on cybersecurity. A great example of this is the Cybersecurity Talent Initiative sponsored by Workday, Mastercard, and Microsoft. It is an initiative (https://cybertalentinitiative.org/) where students get up to $75,000 in student loan forgiveness to get into cybersecurity and get real-world experience. In addition, I believe there is an underserved pool of gender-diverse, racially diverse, and neurodiverse workers that need new channels opened for them to enter cybersecurity through programs similar to the Cybersecurity Talent Initiative.

This interview first appeared in the November 2020 issue of CISO MAG.


Augustin KurianAbout the Interviewer

Augustin Kurian is the Assistant Editor of CISO MAG. He writes interviews and features.

Belgium’s National Security Council Approves Cybersecurity Strategy 2.0

RAT, Trojan, Remote Access Trojan

At the beginning of the month, Belgium faced a widespread internet outage across the country. Reportedly, the country’s leading internet service provider (ISP), Belnet, was targeted with multiple waves of DDoS attacks that forced nearly 200 organizations, including government websites, to go offline. Incidentally, around the same time, Belgium’s National Security Council (NVR) was finalizing the country’s Cybersecurity Strategy 2.0, whose first version was introduced in 2012 and implemented in the preceding year. The original strategy, which contains 11 of the 15 strategic goals of the European Union Agency for Cybersecurity (ENISA), has been renewed to add six more specific areas that it will concentrate on in the next five years.

Cybersecurity Strategy 2.0: Six Strategic Areas of Focus

Belgium’s various industrial sectors and even SMEs are taking huge strides towards cutting-edge technological adoptions. The country’s cyberspace is continuously evolving and thus the challenges that come with it have evolved too. However, the country has always paid attention to this and invested in securing its cyber front. Cybersecurity is one of the main pillars of their National Plan for Recovery and Resilience, which the government submitted to the European Commission at the end of April.

Cyberthreats are dynamic and require evolving countermeasures. Thus, to take its cyber defenses a notch higher, Belgium’s National Security Council has approved adding and adopting a new and more refined cybersecurity strategy based on six specific objectives:

  • Strengthen the digital environment and confidence in it.
  • Protect the computers and networks of both, end-users and service providers.
  • Protect critical organizations from cyberthreats.
  • Raise awareness and educate all stakeholders to tackle all possible cyberthreats.
  • Improve partnerships and sharing of expertise between government, industry, and academic institutions.
  • Make a clear international commitment concerning cybersecurity.

Miguel De Bruycker, Director of the Center for Cybersecurity Belgium (CCB), who will be responsible for the implementation of this new strategy, said,

The outlined cybersecurity strategy 2.0 aims to make Belgium one of the least vulnerable countries in Europe in terms of cybersecurity by 2025.

The CCB will work closely with various government services for which cybersecurity is of central importance. A brief overview of Belgium’s cybersecurity governance can be seen in the image below.

Belgian Cybersecurity Governance
Image Credit: Centre for Cyber Security Belgium

Alexander De Croo, the Prime Minister of Belgium, said, “Cybersecurity is not only a priority for Belgium, but also represents a huge opportunity for our companies and SMEs, which have a lot of expertise in this field. We will continue to invest in the protection of our citizens and our systems against cybercriminals and at the same time, we will do everything in our power to develop an ecosystem that promotes innovation in cybersecurity in Belgium.”

Related News:

DDoS Attack on Belnet Takes Down Belgian Government Websites

After Tested.me, ICO Fines Amex For Sending Millions of Unwanted Emails

ICO fines American Express

We often receive calls from different bankers promoting their products and services. While these calls are largely ignored, very few question the rationale behind unsolicited calls. Owing to the data privacy of customers, organizations are forbidden to use their personal data for marketing or promotional campaigns, without their consent.

Recently, the European unit of American Express (Amex), a multinational financial services corporation, was fined £90,000 (around US$127,409) by the U.K.’s privacy watchdog, Information Commissioner’s Office (ICO), for sending more than four million spam/marketing emails to its customers within a year. The ICO stated that Amex had violated the Privacy and Electronic Communications Regulations (PECR) 2003 Act by sending marketing emails to over 50 million customers without their consent.

The ICO’s investigation found that Amex deliberately sent marketing emails for promotional and monetary gains. The issue came to light after several Amex customers complained to the ICO after receiving unwanted emails even after they opted out.

“Nearly 12 months, between 1 June 2018 and 21 May 2019, 4,098,841 of those emails were marketing emails, designed to encourage customers to make purchases on their cards which would benefit Amex financially. It was a deliberate action for financial gain by the organization. Amex also did not review its marketing model following customer complaints,” the ICO said.

“This is a clear example of a company getting it wrong and now facing the reputational consequences of that error. The emails in question all contained marketing material, as they sought to persuade and encourage customers to use their cards to make purchases. Amex’s arguments, which included, that customers would be disadvantaged if they weren’t aware of campaigns, and that the emails were a requirement of its Credit Agreements with customers, were groundless,” said Andy Curry, ICO Head of Investigations.

As per the PECR and GDPR regulations, organizations in the European Union are restricted to send unsolicited marketing campaigns via phone, fax, email, text, or any other electronic medium without customer consent. The companies are required to get approval from the customers by asking them to tick opt-in boxes to receive marketing calls, texts, or emails.

The fine on Amex comes hard on its heels after the ICO announced that it imposed an £8,000 fine (approximately US$11,300) on contact tracing service provider Tested.me for sending over 84,000 unwarranted marketing emails to its customers without their consent.

EU Regulators Impose 661 GDPR Violation Fines Totaling €292 Mn to Date

GDPR Fines

Ever since the General Data Protection Regulation Act (GDPR) was introduced, the data regulators in the European Union (EU) have imposed sizable penalties on various organizations that misused or failed to protect customer personal information.

GDPR requires organizations that handle customer personal data to follow certain guidelines and transparency in the way they collect, store, and use the data collected from customers. It has restricted businesses from using their customer data without consent. Owing to the fear of high penalties, most organizations are now focusing more on user data protection and data privacy.

The data protection authorities in the EU have issued 661 fines for a total of €292 million (approximately US$35,65,13,020) in the three years since the GDPR took effect (on May 25, 2018). According to a recent analysis from Privacy Affairs, Italy received the highest fines (€76,217,601), followed by France (€54,661,300), Germany (€49,186,833), the U.K. (€44,221,000), and Spain (€29,372,510). While Spain issued the greatest number of GDPR fines (222), Italy issued 73 penalties, followed by Romania with 54 fines, Hungary with 39, and Germany with 30. All the 28 EU nations, including the U.K., issued at least one GDPR fine.

Top Five GDPR Fines

  1. The highest GDPR fine to date remains at €50 million (about US$61 million) imposed by the French data protection regulator on Google, for alleged infringements of GDPR’s transparency principle and lack of valid consent., followed by Germany with 32.2 million and Italy with 27.8 million.
  2. Popular fashion retailer Hennes & Mauritz Online Shop A.B. & Co KG (H&M) was fined €35.2 (about US$41.1 million) by the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI) for violating the General Data Protection Regulation (GDPR).
  3. The Italian Data Protection Authority (Garante) imposed a €27.8 million (US$31.5 million) fine on telecommunications operator TIM for violation of the GDPR guidelines.
  4. British Airways was fined €22 million (approximately US$26 million) for failing to protect its customers’ sensitive information in a cyberattack in 2018.
  5. Marriott International Inc. was penalized €20 (around US$24 million) for failing to protect the personal data of millions of its customers.

The Highest Fines Issued to Private Individuals

  • €20,000 (US$24,420) issued to a private person in Spain for unlawful video surveillance of employees.
  • €11,000 (US$13,431) issued to a football coach in Austria who was found to be filming female players in the shower.
  • €9,000 (US$10,988) issued to a person in Spain for illegal video surveillance of employees.
  • €2,500 (US$3,052) issued to an individual in Germany who sent out emails to several persons, where each could see the other recipient’s email addresses.
  • €2,200 (US$2,686) issued to a person in Austria for having illegally filmed public areas using a personal CCTV system.

“While GDPR sets out the regulatory framework that all EU member states must follow, each state legislates independently and is allowed to interpret the regulations differently and impose their own fines to organizations that break the EU law,” the report from Privacy Affairs stated.

Rising GDPR-related Breaches  

A survey by multinational law firm Linklaters revealed that GDPR-related data breach notifications across European countries have increased by 66%, compared to the first year of the GDPR (from May 25, 2018, to May 24, 2019). The analysis stated that the surge in data breach notifications is because the companies were aware of their data security obligations.

Personal Data of 4.5 Mn Passengers Exposed in Air India Data Breach

Air India Data Breach

While most flight passengers want to make their air travel hassle-free during the pandemic, the growing cyberattacks on the aviation industry have become a challenge for several airlines. Travelers are skeptical and cautious about sharing their personal information with airlines in the wake of heightened security breaches.

Recently, India’s national airline Air India revealed that it sustained a sophisticated data breach in February 2021, which affected over 4.5 million passengers globally, after its data management service provider SITA Passenger Service System (SITA PSS) was hacked by unknown threat actors. SITA PSS is responsible for storing and processing of personal information of Air India passengers.

“While we had received the first notification in this regard from our data processor on February 25, 2021, we would like to clarify that the identity of the affected data subjects was only provided to us by our data processor on March 25 and April 05, 2021. The present communication is an effort to apprise of accurate state of facts as on date and to supplement our general announcement of March 19, 2021, initially made via our website,” Air India said.

 A Decade Worth of Passenger Data

Air India stated the data breach affected passengers who had registered between August 26, 2011, and February 3, 2021. It was found that the attackers managed to access a decade worth of passenger data including names, passport, credit card details, birth dates, contact information, passport information, ticket information, and Air India’s frequent flyer data from the SITA’s systems. However, the company clarified that CVV/CVC numbers were not exposed in the incident.

Measures Taken by Air India After the Data Breach:

  • Investigating the data security incident
  • Securing the compromised servers
  • Engaging external specialists of data security incidents
  • Notifying and liaising with the credit card issuers
  • Resetting passwords of Air India FFP program

While there is no sign of any misuse of users’ leaked data, Air India urged passengers to update their passwords at the earliest to avoid any security risks.

 Multiple Airlines Affected

While SITA disclosed the cyberattack in February 2021, the consequences of it are being exposed recently. SITA provides its services to several global airlines including airports and government agencies. Alongside Air India, Star Alliance and One World airlines were affected by the security incident. Other popular airlines like Finnair, Japan Airlines, Jeju Air, Lufthansa, Air New Zealand, Malaysia Airlines, Cathay Pacific, and Singapore Airlines, which also use SITA’s services, were affected by various security breaches earlier.

Things Affected Flyers Need To Do

If you have booked an Air India flight between August 26, 2011, and February 3, 2021, update all account passwords of online banking and debit/credit card PINs as a precautionary measure. Also, keep a tab on your account transactions. If you find any suspicious transaction, immediately report it to your banker. Usually, cybercriminals leverage leaked data to target users in various phishing attempts. Don’t click on any suspicious links received via SMS or email from an unknown source.

Conti Continues Targeting U.S. Health Care Sector but Acts as a Good Samaritan in Ireland

Ransomware attack on Nunavut, Emotet Cobalt Strike

The Federal Bureau of Investigation (FBI), on May 20, released a “Flash” alert stating that the notorious Conti ransomware gang, which reportedly targeted the Irish health system last week, has hit at least 16 healthcare and emergency first responder networks in the U.S. Its victims’ list includes law enforcement agencies, emergency medical services, 9-1-1 dispatch centers, and municipalities of various districts.

Conti Continues its Merry in the U.S.

According to the FBI,  the Conti ransomware gang has victimized more than 400 organizations worldwide, of which 290 are in the U.S. alone. Their average recorded dwell time in the victim’s network ranges between four days to three weeks. Moreover, when it comes to the ransom demands, there is no fixed number quoted by its operators. It widely varies depending on the targeted organization’s size. However, the highest recorded bid of the Conti ransomware gang stands at $25 million.

The TTPs of Conti Ransomware

According to the FBI’s Cyber Watch (CyWatch) researchers, Conti’s operators infiltrate victim networks through phishing emails (malicious links or attachments) or stolen/cracked remote desktop protocol (RDP) credentials.

“Conti weaponizes Word documents with embedded Powershell scripts, initially staging Cobalt Strike via the Word documents and then drops Emotet onto the network, giving the actor access to deploy ransomware.”

The deployment phase of Conti is generally a three-stage process:

  1. In the first stage, Conti operators use tools that are readily available on the network to penetrate further inside.
  2. In the second stage, they add tools such as Windows Sysinternals1 and Mimikatz as per requirement, to escalate privileges and move laterally through the network. In some cases, where additional resources are needed, the actors use an additional step where they deploy the Trickbot malware.
  3. In the final stage, the Conti operators deploy the ransomware, exfiltrate critical data useful for negotiations, and finally encrypt data on victims’ computers. Post-deployment, the operators may stay in the network and beacon out using Anchor DNS.

Conti ransomware gang leaves a ransom note on the victim’s computer with its contact details, which is generally a ProtonMail email ID. However, if there is no initiative taken by the victim, then after a week from the ransomware deployment, they call their victim using single-use Voice Over Internet Protocol (VOIP) numbers.

Conti’s IOCs

This gang specifically uses remote access tools, which are connected through domestic and international virtual private server (VPS) infrastructure over ports 80, 443, 8080, and 8443. In case of persistence in the victim’s network, they may use port 53. The CyWatch researchers suggest IT and cybersecurity teams of organizations to lookout for “large HTTPS transfers going to cloud-based data storage providers like MegaNZ and pCloud servers.” Conti is known to use these services as command and control (C2) servers.

Other indicators of Conti’s activity include the creation of new accounts and tools which were not installed by the organization, as well as disabled endpoint detection and constant HTTP and domain name system (DNS) beacons.

Conti Becomes a Good Samaritan in Ireland

As reported by the FBI, the Conti ransomware gang has targeted all industries over the world and late last week, the Irish Health Service Executive (HSE) faced its heat as well. However, Micheál Martin, the Prime Minister of Ireland, announced and made it clear that they “will not pay any ransom” to these cybercriminals.

The attack, which took place due to “an unknown vulnerability in the IT systems,” impacted the IT systems of all local and national health care facilities in Ireland. The effect of the attack was also felt on COVID-19 response as many diagnostic and testing centers were suspended briefly. Many experts deemed the attack as “morally inappropriate” as the health care sector is already stretched owing to the current pandemic and an attack like this could crumble the entire sector in one go.

This might have led to a change of heart for Conti operators because the cybercriminals have reportedly handed over the decryption tool to their victims for free. On the darknet website controlled by Conti, it left a message for the Irish HSE stating, “We are providing the decryption tool for your network for free.” On receiving this news, the Irish Prime Minister was elated but said, “Enormous work is still required to rebuild the system overall.”

Conti’s handover of the decryption key cannot be considered a complete success and its disruption cannot be overlooked because the operators are still threatening to publish or sell the critical data which they exfiltrated during the attack. The ransom amount demanded stands at $20 million (or £14 million), which the Irish government is refusing to pay. Meanwhile, Health Minister Stephen Donnelly told Irish broadcaster RTÉ: “Our technical team is currently testing the tool and the initial responses are positive.”


Related Articles

Paying Ransom is Now Illegal! U.S. Dept of Treasury Warns

Irish Health Services Shut Down After Being Hit by Ransomware Attack

Report to Your Management with the Definitive ‘Incident Response for Management’ Presentation Template

Incident Response

Security incidents occur. It’s not a matter of ‘if’ but of ‘when.’ There are security products and procedures that were implemented to optimize the IR process, so from the ‘security-professional’ angle, things are taken care of.

 SPONSORED CONTENT 

By George Tubin, Director of Product Strategy at Cynet

However, many security pros who are doing an excellent job in handling incidents find effectively communicating the ongoing process with their management a much more challenging task.

It’s a little surprise — managements are typically not security savvy and don’t really care about the bits and bytes in which the security pro masters. Cynet addresses this gap with the IR Reporting for Management PPT template, providing CISOs and CIOs with a clear and intuitive tool to report both the ongoing IR process and its conclusion.

The IR for Management template enables CISOs and CIOs to communicate with the two key points that management cares about — assurance that the incident is under control and a clear understanding of implications and root cause.

Control is a key aspect of IR processes, in the sense that at any given moment, there is full transparency of what is addressed, what is known and needs to be remediated, and what further investigation is needed to unveil parts of the attack that are yet unknown.

Management doesn’t think in terms of Trojans, exploits, and lateral movement, but rather it thinks in terms of business productivity — downtime, man-hours, loss of sensitive data.

Mapping a high-level description of the attack route to resulted damage is paramount to get the management’s understanding and involvement, especially if the IR process entails additional spending.

The Template follows the SANS\NIST IR framework and comprises the following stages:

Identification

Attacker presence is detected beyond doubt. Was the detection made in house or by a third party, how mature the attack is (in terms of its progress along the kill chain), what is the estimated risk, and will the following steps be taken with internal resources, or is there a need to engage a service provider?

identification - threat and risk

Containment

First aid to stop the immediate bleeding before any further investigation, the attack root cause, the number of entities taken offline (endpoints, servers, user accounts), current status, and onward steps.

Eradication

Full clean-up of all malicious infrastructure and activities, a complete report on the attack’s route and assumed objectives, overall business impact (man-hours, lost data, regulatory implications, and others per the varying context).

Recovery

Recovery rate in terms of endpoints, servers, applications, cloud workloads, and data.

Lessons Learned

What were the attack’s enablers (lack of adequate security technology in place, insecure workforce practices, etc.), and how they can be mended, and reflection on the previous stages across the IR process timeline searching for what to preserve and what to improve.

Naturally, there is no one-size-fits-all in a security incident. For example, there might be cases in which the identification and containment will take place almost instantly together, while in other events, the containment might take longer, requiring several presentations on its interim status. That’s why the template is modular and can be easily adjustable to any variant.

Communication to management is not a nice-to-have but a critical part of the IR process itself. The definitive IR Reporting to Management PPT template enables all who work hard to conduct professional and efficient IR processes in their organizations to make their efforts and results crystal clear to their management.

Download the Definitive IR Reporting to Management PPT template here.

About the Author

George TubingGeorge Tubin is the Director of Product Strategy at Cynet and a recognized expert in cybercrime prevention. He was previously VP of Marketing at Socure and Senior Research Director at TowerGroup where he delivered thought leadership and insights to large enterprises on cybersecurity as well as identity and fraud management.

DISCLAIMER

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.