Home Blog Page 86

Irish Health Services Shut Down After Being Hit by Ransomware Attack

Cyberattack on Ireland's Health care

Ireland’s health care services were temporarily disrupted after being hit by a ransomware attack. The Irish Health Service Executive (HSE) claimed that the attack affected several diagnostic services, disrupted COVID-19 testing operations, and forced hospitals to cancel many medical emergencies.

Zero-Day Attack!

According to Ossian Smyth, Ireland’s minister of e-government and head of the HSE, an international cybercriminal gang is behind the attack. It was found that the attackers exploited an unknown vulnerability in the IT systems that led to a Zero-Day attack, affecting IT systems services at all local and national health care facilities. While the attack may potentially affect sensitive information stored on central servers, health care officials stated that there was no sign of misuse of any patient data or connected medical equipment.

“These are cybercriminal gangs, looking for money. What they’re attempting to do is to encrypt and lock away our data, and then to try to ransom it back to us for money. It’s widespread. It is very significant, and possibly the most significant cybercrime attack on the Irish State,” Smyth said.

Patients – The Primary Victims

The attack primarily affected several patients who needed medical attention as the majority of the hospitals canceled all appointments.

No Ransom!

While there was no sign of any ransom demand from cybercriminal groups, the Prime Minister of Ireland Micheál Martin announced that they will not be going to pay any ransom.

Besides, Ireland’s Health Minister Stephen Donnelly stated the attack impacted most health and social care services severely.

Currently, the health care authorities in the country are working on restoring the IT systems to help patients who are in medical need. “We apologize for the inconvenience caused to patients and the public and will give further information as it becomes available. Vaccinations not affected are going ahead as planned,” HSE said.

What Experts Say…

Commenting on the security incident to CISO MAG, Mathieu Gorge, CEO and Founder of VigiTrust, said, “First hackers attacked a pipeline that directly affects the ability of Southeastern Americans to conduct their daily lives, and now they’ve attacked the Irish health care system in the middle of a pandemic. Their next target could be first responders or the banking system. Criminals see this as just yet another opportunity to strike, without any regard for the impact on human life.”

“What’s most worrying about this is that it has established a trend that you can attack critical infrastructure anywhere and everywhere. And these aren’t necessarily sophisticated attacks by nation-states; they are relatively low-skill attacks with huge consequences exploiting attack surfaces which frankly should be better protected. Clearly, there are deficiencies in our defenses,” Gorge added.

New InfoSec Leaders Community to Give Cybersecurity Leaders Outside the Fortune 2000 a Forum to Collaborate

Perhaps due to the nature of the position, the InfoSec leadership roles tend to be solitary ones. CISOs, or their equivalent decision-makers in organizations without the role, have so many constant drains on their attention – keeping their knowledge fresh, building plans to further secure their organizations – that they often find themselves on an island. It’s even more challenging for organizations outside the Fortune 2000 that are resource-constrained.

 SPONSORED CONTENT 

By George Tubin, Director of Product Strategy, Cynet

Security leaders are expected to know everything, and often don’t have anyone inside their organization with whom to bounce ideas or even go to for advice. When a crisis arises, they must often go with their gut or guess at the best solution based on their own experiences. Security leaders could often use advice, but don’t have an outlet for it. Chris Roberts, Chief Security Strategist at Cynet Security, offers a new Slack-based community for InfoSec leaders (register here) as a solution.

The new InfoSec Leaders Community will feature several channels and will offer security leaders and decision-makers a fresh opportunity to both get advice and new knowledge and share it with others. More importantly, the community is aimed not at the well-off InfoSec leaders, but at those found generally outside the Fortune 2000 who may be forgotten by vendors, researchers, and other talented analysts.

A New Kind of Forum for Security Leaders

This new InfoSec Leaders community is meant to be a place for a meeting of the minds. More than simply a mailing list or a newsletter, Roberts aims to create a place for real dialogue. Roberts will have a heavy hand in moderating and participating in the conversations, and security professionals are encouraged to share ideas, problems, thoughts, and interesting solutions to common problems.

Among other topics, Cynet’s InfoSec Leaders Community will include channels for:

  • Sharing ideas on solutions for common problems. members will be able to share their issues, as well as contribute potential solutions and fixes for others’ posts.
  • Asking questions about job-related issues. InfoSec leaders have a high-pressure job and little outlet. The goal of this channel is to let them discuss how they handle some of that pressure and how to do better at their own jobs.
  • Challenging other members of the community. Sometimes, it can be good to simply spin up the wheels and try to solve “intractable” problems. The community hopes to have a place for members to have fun and let off some competitive steam.
  • Creating better networks for security professionals. Most importantly, the InfoSec Leaders community hopes to foster a real network of professionals who can contribute knowledge and build stronger ties to help others in similar positions.

The new InfoSec Leaders Community was launched on April 29. You can register to the new community here.


About the Author

George Tubin is the Director of Product Strategy at Cynet and a recognized expert in cybercrime prevention. He was previously VP of Marketing at Socure and Senior Research Director at TowerGroup where he delivered thought leadership and insights to large enterprises on cybersecurity as well as identity and fraud management.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

How to Simplify Security and Compliance in Cloud

Security and Compliance in Cloud

Digital transformation was only a trend a few years ago; however, it has quickly become a reality for many organizations, including government agencies. The COVID-19 pandemic has pushed all kinds of government agencies to reconsider their timelines and potential impact of digital initiatives, whether this means moving core technology infrastructure to the cloud, rolling out more modern productivity tools for employees, or using artificial intelligence to better deliver public services.

By Jeanette Manfra, Global Director – Security and Compliance, Google Cloud

This accelerated demand for cloud services has thrust the issues of compliance and security squarely into the spotlight. The public sector is one of the most heavily regulated industries, and moving to the cloud requires protecting sensitive workloads while achieving and maintaining compliance with complex regulatory requirements, frameworks, and guidelines. In January, the Department of Defense (DoD) published the Cybersecurity Maturity Model Certification (CMMC), a new standard designed to ensure cyber hygiene throughout the DoD supply chain. It mandates that vendors meet a basic level of cybersecurity standards when responding to requests for proposals. This framework and countless others, such as NIST Special Publication 800-172 and the Federal Risk and Authorization Management Program (FedRAMP), have been introduced to encourage cybersecurity best practices as agencies adopt emerging technologies, including the cloud.

At Google Cloud, we understand first-hand the security challenges and opportunities the cloud can offer. That’s why security and data protection are among our primary design criteria for our cloud services. Security drives our organizational structure, training priorities, and hiring processes. It shapes our data centers and the technology they house. It’s prioritized in the way we handle customer data, and it’s the cornerstone of our account controls.

Compliance without compromise

Security and compliance topics dominate my conversations with government agencies. And rightly so. They are committed to protecting the information they’ve been entrusted to safeguard their constituents and employees. This commitment requires an understanding of how to navigate the complexities of compliance and privacy in the cloud. As government agencies and the enterprises that serve them adopt cloud technologies, security and compliance requirements such as data residency and administrative access, are key considerations. To meet these requirements, many cloud providers have built separate environments, with standalone data centers, to run government workloads. Because these “government clouds” are run through specialized, standalone data centers, they often have a lag-time in receiving new features.

In addition, these “gov clouds” don’t come with all the technology and benefits that a modern commercial cloud provides, and can impact the government’s access to new, innovative technologies — whether it’s data analytics, artificial intelligence, and machine learning, and even new security protections.

We believe that compliance shouldn’t require compromising functionality or service availability. For this reason, we recently introduced Assured Workloads for Government (currently in private beta), which gives agencies all the benefits of a public cloud, without the compromises of traditional “gov clouds.” It allows regulated customers to accelerate their path to running compliant workloads on commercial cloud environments by enforcing required security and compliance controls. It simplifies the compliance configuration process and provides seamless platform compatibility between government and commercial cloud services.

With Assured Workloads for Government, users can quickly and easily create controlled environments where U.S. data location and personnel access controls are enforced in any of Google Cloud’s U.S. cloud regions. Users can also limit personnel access based on predefined attributes such as a particular geographical location, citizenship, and background checks.

Assured Workloads for Government help government customers, suppliers, and contractors meet the high security and compliance standards set forth by the DoD (i.e., IL4), the FBI’s Criminal Justice Information Services Division (CJIS), and FedRAMP, while still having access to all the latest features. With just a few clicks, users can configure sensitive workloads to align with their security and compliance requirements. It is a prime example of how automation enabled by cloud services can improve government IT risk management.

Since we launched Assured Workloads for Government, we worked with a variety of local, state, and federal agencies to help configure their workloads to support compliance requirements. Early adopters were excited to take advantage of Assured Workloads for Government’s commercial cloud capabilities while maintaining regulatory compliance without the need for a legacy gov cloud.

Additionally, in the coming months, we plan to roll out new features and expand the general availability of Assured Workloads to include new capabilities, like new security and compliance monitoring tools, the ability to restrict products and services by compliance regime, support for additional regulated industries beyond the public sector, and compliance blueprints targeting specific customer use cases.

Putting your trust in Zero Trust

While the original motivation behind creating “gov clouds” was to meet rigorous FedRAMP standards, the result prolonged the embrace of antiquated, perimeter-based security models that were in vogue nearly a decade ago. These “gov clouds” are built under the assumption that all employees work exclusively on devices owned by an organization, and these employees are always operating within the company’s private network. In today’s modern work environment, we know this is no longer true. It is especially so during the current pandemic, in which remote work is at the forefront.

Nearly ten years ago, Google decided that every employee should be able to work from any network without the use of a VPN. This decision has drastically shifted the way Google — and today technology industry overall — thinks about ensuring security for remote workforces. Called “zero trust,” this model does not assume that being on or off the corporate network would make an employee more or less trustworthy. Instead, decisions are made based on a variety of factors such as a user’s IP address, behavior, or files accessed before granting access. Zero trust removes the requirement of building a perimeter that gives the illusion of a “digital fortress,” because users aren’t even trusted when they’re inside the perimeter.

A recent study found that federal government IT executives are now embracing this shift toward a perimeter-less environment, reporting that it greatly improves risk management and their security posture, while also providing better overall user experience. For example, we’re working with the Defense Innovation Unit (DIU) to build a secure cloud management solution to detect, protect against, and respond to cyberthreats worldwide.

As government agencies look to transform digitally, it’s imperative that they make security modernization a part of their journey. More than ever before, employees and users are on the move, agencies have an influx of remote devices and endpoints to secure, with data moving to the cloud from on-prem environments. A security model, built on the foundation of zero-trust networks, ensures government agencies can benefit from feature-rich cloud environments that have achieved industry certifications and standards. We continue to build and maintain the highest levels of security and trust in our technical infrastructure and services to empower government agencies to stay compliant in this ever-changing environment. In doing so, we’ve provided a framework for them to securely take advantage of the cloud so they can improve citizen services, increase their operational effectiveness, and deliver proven innovation.

This story first appeared in the November 2020 issue of CISO MAG.


About the Author

Jeanette ManfraJeanette Manfra is the Director for Government Security and Compliance within the Google Cloud Office of the CISO. Jeanette is focusing on helping customers, particularly those in regulated industries, build and maintain the highest levels of security and trust in their technical infrastructure and services.

Prior to joining Google, Manfra was the Assistant Director for Cybersecurity for the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) within the U.S. Federal Government.  In that role, she was responsible for driving security modernization across Federal civilian agencies as well as enabling the security of critical infrastructure across the US. Manfra spent more than a decade serving in various roles at the Department of Homeland Security and the White House focused on establishing the nation’s first civilian cyber defense agency.

Manfra is a proud veteran of the U.S. Army and alumna of the University of Wisconsin and the Johns Hopkins University.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same. CISO MAG did not test the products and services mentioned in this article.

Innovate Through Uncertainty by Managing Third-party Risk

third-party risk

Like beauty, risk is in the eye of the beholder, and business risk is no exception. While some organizations perceive risk as a potential hazard or negative consequence of uncertainty that should be avoided at all costs, others recognize that with risk comes significant opportunities for innovation, sustained growth, and competitive advantage. The difference between the two had to do with the firm’s ability to identify and analyze risks and decide which risk is worth taking. A prime example of this internal tug-of-war between risk and opportunity that plays out on the corporate stage is the strategy around third-party business relationships.

By Alla Valente, Senior Research Analyst, Forrester

Firms are increasingly outsourcing core and non-core systems, business processes, and data processing to third-party service providers. With the widespread adoption of software-as-a-service (SaaS) technologies, even among industries like financial services that traditionally wanted control and autonomy, build vs. buy is less of a debate than it was just five years ago.  As firms respond to changing market dynamics, global economic uncertainty, new “digital-first” competitors, and changing customer expectations, outsourcing helps firms focus on core competencies, increase innovation, reduce costs, and improve speed-to-market. It also introduces a variety of risks into the organization ranging from inconvenient (delay in delivery) to irreversible (large-scale data breach) to immeasurable (theft of intellectual property)1.

The Complexities and Consequences from Third-party Relationships Are Increasing

When we think of third-party relationships, we think of the direct supply chain of vendors, suppliers, and cloud providers. But the digital transformation taking place in businesses across all industries outsourcing business processes include sales, marketing, creative, social media, public relations, and others.

What adds to the complexity of the third-party ecosystem is that although companies have limited or no control over how third parties secure their technology infrastructure, their applications, or their data, they’re fully responsible for security, privacy, or regulatory missteps that occur during the relationship. As a result, companies are on the hook financially for fines, penalties, or revenue loss and risk their reputation when events lead to negative publicity, business disruption, or impact the customer experience. According to Ponemon Institute, third-party breaches account for over half of all data breaches in the U.S.2

It’s not surprising that breaches caused by third parties are among the most highly publicized. Some of the most notorious data breaches in recent times have occurred as a result of the organizations’ vendors. The 2013 Target breach caused by stolen credentials from HVAC vendor Fazio Mechanical Equipment continues to serve as a cautionary tale of vendor risk. In 2019, Facebook experienced a third-party app breach – the first from a digital media company, Cultura Colectiva, that exposed over 540 million records on a publicly accessible server3. In 2020, Bank of America was breached via the U.S. Small Business Administration (SBA) Platform for Paycheck Protection Program (PPP)4.

Unfortunately, cyberattacks caused by third parties are also among the costliest. A January 2020 Ponemon Institute report indicates that 53% of organizations have experienced at least one data breach caused by a third party in the last two years. And that, on average, the data breach costs $7.5 million to remediate5.

Compliance-Based Approach Fails to Capture Strategic Value

Even as regulatory compliance requirements seem to be expanding year over year, and despite the increased complexity of firms’ third-party ecosystems, little has changed in how organizations approach third-party risk management. Why? A few reasons.

1. Risk and compliance management is considered a cost center. Cost centers like accounting, human resources, and customer service contribute to a company’s profitability indirectly by creating efficiency or enhancing product value – they are not perceived as contributing directly to revenue and are not involved in setting strategy. Despite what we know about third-party risk directly impacting revenue, customer retention, brand reputation, and company valuation, many firms still perceive risk management as a regulator-imposed check-box bureaucracy that takes time, requires resources, and budget away from revenue-generating projects. A Forrester survey reveals security decision-makers believe risk management efforts increase costs (25%), tend to reduce performance (20%), and are misaligned with business objectives (19%)6.

2. Regulations vary by risk domain, region, and sector. Compliance terminology can be confusing. Although often used interchangeably, “regulations” and “standards” mean very different things. Regulations are mandatory requirements by federal or regulatory bodies and are enforceable by law. Standards, on the other hand, are guidelines or protocols that are meant to ensure consistency, quality, or safety. For context, HIPAA is a healthcare regulation that protects the privacy and confidentiality of personal health information (PHI) even when a breach occurs because of a third-party relationship. HIPAA penalties are enforced by the U.S. HHS’ Office of Civil Rights.

On the other hand, PCI is a data security standard for organizations that handle major credit cards such as Visa, American Express, and Mastercard.  These organizations aren’t forced to implement PCI’s recommended policies, procedures, and controls. However, if they wish to continue to offer this payment option to their customers, they will follow the guidance.

Currently, there are no global standards for third-party risk management that address all risk domains. Instead, companies are bound by a combination of requirements and standards that are based on industry (financial services, healthcare, medical devices, energy), risk domain (privacy, financial fraud, geopolitical sanctions, health, and safety), and others. This lack of consistency results in a disparity across the maturity and effectiveness of third-party risk management programs. Mature programs have made a concerted effort to centralize risk management so that an approved pool of third parties exists for the entire organization. They put in the energy to make their program more robust and proactive. Others will take a reactive approach with inconsistent or insufficient evaluation or treat compliance as an exercise to acquire signatures on contracts that legally obligate the third party to adhere to security and privacy practices.

3. Compliance focuses on non-strategic value. With no value-added, risk and compliance activities is a utility. That is a necessary process but not essential to the value creation of the business. The real problem is not the value of compliance but the lack of value in legal compliance tasks. A study in The Harvard Business Review reveals that auditors spent only 6% of their time analyzing strategic risks, but that the likelihood that strategic business risk failure would lead to significant losses in market value was 86%. Instead, organizations spent 94% of their time on operational, financial, legal, and compliance risks that collectively represent only 14% of value loss for the organization7. Risk and compliance are resource-intensive processes, yet most organizations lack the confidence that their efforts are highly effective. In contrast, some firms are overconfident in their ability to manage risks. Often, these firms have the technology but lack the ability to contextualize or operationalize risk analysis in business decisions or strategy. These two extremes will gravitate to being over-exposed or over-insured.

Risk Mitigation Strategies to Consider

Strategy #1: Understand who your third parties are and inventory all relationships, regardless of criticality or size of the engagement. Update your firms’ nomenclature beyond traditional vendor and supplier to also include subcontractors, data processors, service providers, resellers, affiliates, and non-traditional third-party relationships that meet the following criteria: i. Access or connect directly to your network; ii. Transmit, store, or process data that’s considered identifiable; and/or iii. Have access to sensitive, financial, IP, or otherwise proprietary data. Next, create an inventory of all third-party relationships. It’s critical you track which of your third parties have access to sensitive or identifiable information and whether any of your third parties are sharing your data with their third parties (your fourth parties). Currently, 65% of organizations don’t inventory or are unsure if their company inventories third parties8. Because of the COVID-19 pandemic, we are witnessing the damage created by not accounting for third-party risks through the disruption and systemic breakdown of most global supply chains.

Strategy #2: Manage risk throughout the lifecycle of the relationship. While there are no universally acknowledged guidelines for managing third-party risk, the Office of the Comptroller of the Currency (OCC), the regulating and supervising body for national, federal, and agencies of foreign banks in the U.S. released a bulletin with “guidelines” for effective third-party risk management practices that has been adopted as a best practice even by firms outside the OCC’s regulatory authority9. The guideline is a misnomer because the OCC has the power and authority to enforce and penalize those banks that don’t comply. OCC Bulletin 2013-29, and later updates, recommend that risk management activities are performed throughout the lifecycle of the relationship / contractual period, which include: i. Planning; ii. Due diligence and third-party selection; iii. Contract management; iv. Ongoing monitoring; and v. Termination. What’s notable is the notion that each stage of the relationship introduces new and different types of risks and the notion that third parties are not static, and their risk profile can change over time.

For many, risk evaluation is a process commencing at the onset of the relationship but rarely reviewed thereafter. Like all corporate entities, the risk level of a third-party organization is a dynamic reflection of global policy, financial markets, and sophistication of external adversaries and insider threats. For firms to maintain oversight and identify potential risks in time to mitigate them, it is critical they have in place a robust third-party risk management program and process that encompasses all aspects of risk, and the many stages of the lifecycle that a third-party relationship will transition through.

Strategy #3: Technology without process won’t make you compliant, but a process without automation can’t scale. As organizations grow, their third-party network becomes more complex, disparate, and global, and third-party risk management must become more mature and proactive. Third-party risk platform technology provides the automation and efficiency to support the additional risk identification, assessment, and analysis required for risk management and compliance. Even as many organizations today focus third-party risk efforts on streamlining due diligence and improving the efficiency of onboarding, the changing regulatory landscape, and new and emerging risks will require them to continuously monitor, and, if necessary, reassess the risks at different points throughout the relationship.

This story first appeared in the November 2020 issue of CISO MAG.


References

1 and 10 – Forrester’s Now Tech: Third-Party Risk Management Technology, Q3 2020

2 – “Cost of Third-Party Cybersecurity Risk Management” Ponemon Institute, LLC

3 – https://www.cybergrx.com/resources/research-and-insights/blog/the-worst-third-party-data-breaches-in-2019

4 – https://normshield.com/major-third-party-data-breaches-revealed-in-may-2020/

5 – https://www.forbes.com/sites/forbestechcouncil/2020/07/14/the-rise-of-third-party-digital-risk/#34652fdc480f

6- Forrester, Business Technographics Global Security Survey, 2019

7 – https://hbr.org/2015/07/how-to-live-with-risks

8 – “Data Risk in the Third-Party Ecosystem, Second Annual Study” Ponemon Institute, LLC

9 – https://www.occ.gov/news-issuances/bulletins/2013/bulletin-2013-29.html


About the Author

Alla ValenteAlla Valente is a Senior Research Analyst at Forrester, serving security and risk professionals. She covers governance, risk, and compliance (GRC) strategy, best practices, and technology, with a special focus on third-party risk management, procurement, and supplier risk management, and enterprise and cybersecurity risk management frameworks such as ISO 31000, ISO 27000, and NIST Cybersecurity Framework (CSF). She also assists with coverage of key regulatory compliance issues and technology; risk management, ethics, and trust in digital transformation; and achieving operational resilience.

Valente’s 20 years of B2B marketing experience includes marketing leadership and strategy, product marketing, and digital and customer marketing at privately held and publicly traded firms. Her risk management experience comes from marketing and customer advocate roles at RapidRatings, Rsam (now Galvanize), and BPS (now Resolver), where she helped launch and market successful software-as-a-service offerings and optimized the marketing mix to increase sales. She oversaw all aspects of brand development and rebrand, messaging, go-to-market activities, digital marketing, lead generation, and marketing communications. In these roles, she also ran key customer initiatives including communities, events, advisory boards, and value-add programs.

Valente holds a BA in English from Hofstra University and is currently studying business analytics at Harvard.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

“Privileged access must be scalable at the speed of cloud”

Sectona has been disrupting privilege access management with a global focus. The company helps enterprises mitigate the risk of targeted attacks to privileged accounts spread across data centers and the cloud. It delivers integrated privilege management components for securing dynamic remote workforce access across on-premises or cloud workloads, endpoints, and machine-to-machine communication.

 SPONSORED CONTENT 

Sectona with its light, integrated approach provides a single console for securing passwords and secrets in the embedded vault, secure access with cross-platform access technology & manage privileges over endpoints. The firm’s extended platform capability supports Just-in-Time privileged access for implementing zero standing privileges and provides automation capabilities with its built-in Privileged Task Automation and Account Lifecycle Management.

In a recent interaction with Augustin Kurian from CISO MAG, Nitish Kumar, CEO of Sectona, talks about the privileged access management (PAM) market, the trends in the space, and the future plans of Sectona. Kumar is also the co-founder of Sectona. He earned his bachelor’s degree in information technology from Mumbai University and MBA from Symbiosis Center of Information Technology. Kumar has more than a decade-long experience in the Identity Management & Cybersecurity field in capacities of consulting, marketing & business development.

When it comes to Privileged Access Management and the sudden rise in cloud adoption what’s the best possible way forward of securing privileged access to the cloud and employees working from home?  

Modern privileged access management starts with an assumption that every user is a remote user for an organization. Zero trust building blocks of continuous authentication and verifying the user, context-based privileges are required to secure modern privileged access. More and more customers are engaging with us in a conversation of delivering a frictionless experience for cloud infrastructure access.

When customers move to the cloud, they require technologies that provide an edge with automation and scale on demand. Legacy PAM solutions lack automation capabilities of discovery, cloud console management, security keys, etc.

Customers are engaging with more new age, and niche managed services providers for the cloud and primarily looking to secure and control privileged access from restricted locations for such users. We often get comparisons with native functionality provided by public cloud providers for access like AWS Session Manager. Such utilities lack PAM capabilities of managed passwords and session recordings as required.

Sectona is developed on a browser-first architecture without neglecting issues for enterprise-level users looking for sophisticated native access. So, whether you are securing remote privileged access or core privileged access, you can define your strategy and scale as you grow.

PAM and IAM is a mature market segment and what are the primary factors driving this demand during this pandemic?

PAM is a 20-year-old technology segment and fast-moving space, we find customer demand is primarily driven by digitization, adopting multi-cloud and regulatory issues.

In enterprise and government segments, there is increasing program maturity for IAM programs, and a security focus drives mid-market segments. Sectona collaborates with large service and consulting service providers, SOC, and MSPs to grow into these segments.

With the consolidation of competitors and several issues with legacy technologies existing for more than a decade, customers are looking to refresh the security layer with technologies that can scale with business requirements.

Technologies that are more integrated into the technology and security ecosystem are well accepted. Sectona collaborates with several global and region-specific IAM, MFA, and other security solution providers to bring a joint value proposition to customers.

It is estimated that the PAM market is a $2.2 billion market by revenue with a growth of up to $5.4 billion expected by 2025. Where do you see yourself and your company in 2025?

We have remained bootstrapped for the last four years and developed our niche as a boutique security solution company focused on customer value. We have moved to more than 50 employees with footprints in Eastern Europe, Middle East, Africa, and Southeast Asia and plan to increase service and sales force this year.

We have recently moved from a product-centric to a platform-centric approach and plan to spend more resources on developing this strategy.

This shift allows us to address adjacent markets of endpoint privilege management, DevOps Secrets management, and Privileged Access Governance. We are working towards penetrating our primary markets and investing in secondary markets for long-term growth.

Our ambition is to develop into an identity and privileged-focused security company. By 2025, we expect to gain 30-40% market share in our core markets, leveraging our components of Privileged Access Management, Endpoint Privilege Management, DevOps Secrets Management, or Access Governance.

Sectona was recently recognized by KuppingerCole as a Maturing challenger. It is pretty impressive that Sectona, in a span of three years, took on companies that have been in the space of PAM for over a decade. What were the key innovations and strengths that made Sectona stand out among its competitors?  

We have gradually built our credibility of delivering complex projects at startup speed and enterprise scale. Our thought process revolves around innovation-driven by value to customers. PAM solution purchasing is still dominated by on-premise or self-managed purchase models in our core markets.

There are growing signs of adoption via managed services and SaaS-delivered solutions, and we have plans to launch our SaaS offerings soon and are in the early design phases for this as of now.

Our experienced team and focus on differentiation with distinct competitive advantage have got us this far. For example, most of the competitive solutions require heavy appliance investments or heavy resources for deployment. Recent market trends are driven by huge demand from mid-market customers. Some of our tech strategies such as early alliance with Oracle combined with modern architecture have helped us reduce deployment overheads while delivering a scalable solution. When most of the companies are working to explore services-based architecture, Sectona has created an edge by building on such an architecture.

Sectona has a strong foothold thus far in India, Middle East, and African countries. How are the plans of the company towards further expansion to the rest of Western markets in Europe and North America going?  

There is initial hiring completed for South East Asia and Eastern Europe markets which are in line with our plans. You will find some movement in Australia by the end of this year.  We are in the process of defining our GTM for North America, but honestly, we’re trying some new things around our delivery methods and plan to leverage it for North America GTM.

How is Sectona staying relevant in a competitive market segment locally and in international markets?

Tech is always an unfinished problem. PAM or privilege management is a relatively large market segment dominated by standalone players and multi-product OEMs. We find a great niche in our browser-first technology along with GTM focused on customers embracing cloud & automation.

What lies ahead from the Sectona team in terms of company update and technology roadmap?

Sectona plans to work on a single stack integrated privilege management approach for protecting privileges across endpoints, applications, and workloads. With this vision, we have already launched the windows privilege management and privileged access governance components and soon will be launching our DevOps Secrets vault.

Further, Sectona plans to work on SaaS delivery models for our products by the end of this year.


Augustin KurianAbout the Interviewer

Augustin Kurian is the Assistant Editor of CISO MAG. He writes interviews and features.

Why Apple Removed Millions of Apps from App Store?

Apple App Store, Apple vulnerabilities

Identifying and preventing fraudulent apps have become a rising challenge for companies globally. Recently Apple disclosed that, in 2020, it prevented nearly 1 million vulnerable apps from entering its App Store. The iPhone maker also rejected over 215,000 apps for harvesting users’ data more than required. In addition, Apple’s sophisticated technology and human expertise protected customers from more than $1.5 billion in potentially fraudulent transactions last year.

“Threats have been present since the first day the App Store launched on iPhone, and they’ve increased in both scale and sophistication in the years since. Apple has likewise scaled its efforts to meet those threats, taking relentless steps forward to combat these risks to users and developers alike. It takes significant resources behind the scenes to ensure these threat actors can’t exploit users’ most sensitive information, from location to payment details,” Apple said.

Why Apple Rejected So Many Apps?  

  • Apple terminated more than 48,000 apps for containing hidden or undocumented features
  • Over 150,000 apps were rejected for being spam, copycats, or misleading users
  • 215,000 apps were stopped for privacy violations
  • Besides, Apple prevented 3 million stolen credit cards from making purchases, banned 1 million fraudulent accounts from transacting again.

Review Before Download

Apple claimed that App Store ratings and reviews help users know about the safety and security of the apps. Apple stated that it relies on a sophisticated system including machine learning, artificial intelligence, and human experts to moderate the ratings and reviews to help ensure accuracy and maintain trust.

The company has processed over 1 billion ratings and over 100 million reviews. In the last year, over 250 million ratings and reviews were removed for not meeting moderation standards. Recently, Apple also deployed new tools to verify rating and review account authenticity, to analyze written reviews for signs of fraud, and to ensure that content from deactivated accounts was removed.

“With online data breaches frustratingly common, these protections are an essential part of keeping users safe. But users may not realize that when their credit card information is breached or stolen from another source, fraudsters may turn to online marketplaces like the App Store to attempt to purchase digital goods and services that can be laundered or used for illicit purposes,” Apple added.

Related Story: German Security Researcher Claims Apple AirTag can be Hacked

Joe Biden Strengthens U.S. Cyber Defenses by Signing an Executive Order

Biden signs executive order for cybersecurity

The U.S. has been under cyberattacks for over a year now. It started with a persistent SolarWinds attack, which was discovered in December 2020 and was followed by the Accellion and Microsoft Exchange Servers hack. However, the last straw in this series of sweeping attacks is the unfortunate DarkSide ransomware attack on the Colonial Pipeline. The compromise of the Colonial pipeline’s systems crippled 5,500 miles long fuel supply lines that virtually dried the fuel supply across the East Coast. This prompted a stronger response from the Biden administration, which seems to have come in the form of the latest Executive Order (EO) signed by the POTUS for cybersecurity.

Biden’s Cybersecurity Initiatives

Joe Biden had already taken up the cybersecurity issue seriously as he took over the POTUS’ chair in Washington, D.C. On the recommendation of his intelligence unit and in collaboration with the Department of Energy (DOE) and CISA, Biden had recently revealed a 100 – days plan to enhance the electric grid security as the power sector was already seeing a notable spike in the cyberattacks. In response to this rising number, he decided that it was time for a change in the national cybersecurity protocols.

Related News:

Biden’s 100-Day Plan to Enhance Electric Grid Security

Biden’s Latest Executive Order for Improved Cybersecurity

The executive order of Biden is specifically aimed at improving the current state of the nation’s cybersecurity whose loopholes were exploited by the threat actors over the recent past. It includes the following:

  • The IT service providers are now mandatorily required to notify the government about cybersecurity breaches that could impact U.S. federal and public networks. The EO states that any contractual barriers that might stop providers from threat intel sharing can now be bypassed as it is in the best interest of the nation.
  • A standardized playbook and set of definitions that will help federal agencies to give a prompt response to future cyber incidents.
  • Recommendation to the federal government to upgrade their operations to secure cloud services and other cyber infrastructure. Apart from this, a mandatory deployment of multifactor authentication and encryption for all data accessed, stored, and communicated, is necessary.
  • Software service providers rendering services to the Federal Government agencies are now required to improve the security of the software sold to the government, which also includes its developers sharing certain security data publicly. The EO also recommends employing a zero-trust model and security in all software modules in a ground-up manner.
  • A new “Cybersecurity Safety Review Board” comprising public- and private-sector officials will soon be formed which can give expert advice and analyze the situation making recommendations post a cyberattack or breach incident.
  • The EO creates cybersecurity event log requirements for federal departments and agencies. Robust and consistent logging practices solve latency issues of investigation and remediation measures.
  • An intra-governmental robust information sharing will be established to provide Government-wide Endpoint Detection and Response (EDR) deployment.

This executive order is a reminder of the troubles that the U.S. is facing on the cyber front, but more than that, it is a ray of hope that the Biden administration is addressing the elephant in the room. Could this be a turning stone for a better and cyber safe tomorrow? Only time will tell.

Related News:

SolarWinds Hack Orchestrated by Russia’s SVR, Claims U.S. and U.K.

Snip3: A New Crypter-as-a-Service that Deploys Multiple RATs

Trojans, RAT, remote access trojan, Snip3 Crypter-as-a-Service

Microsoft discovered a spear-phishing campaign in the wild targeting airline, cargo, and travel industries with multiple Remote Access Trojans (RATs). The technology giant stated that attackers distributed malware payloads via phishing emails imitating legitimate businesses with malicious image and PDF attachments.

“The campaign uses emails that spoof legitimate organizations, with lures relevant to aviation, travel, or cargo. An image posing as a PDF file contains an embedded link (typically abusing legitimate web services) that downloads a malicious VBScript, which drops the RAT payloads,” Microsoft said.

Stealthy Malware Loader

Threat actors leverage multiple RATs to exfiltrate sensitive data from critical systems by adding extra malware payloads. According to cybersecurity firm Morphisec, RATs are delivered via a new and stealthy malware loader Crypter-as-a-Service that spreads them onto targeted machines.

The Crypter-as-a-Service, dubbed “Snip3,” is used to deploy Revenge RATAgent Tesla, AsyncRAT, and NetWire RAT payloads on compromised systems. Snip3 implements several advanced techniques to bypass detection, such as:

  • Executing PowerShell code with the Remotesigned parameter
  • Validating the existence of Windows Sandbox and VMWare virtualization
  • Using Pastebin and top4top for staging
  • Compiling RunPE loaders on the endpoint in runtime

Once the malicious attachment is downloaded, the first-stage VBScript VBS files will be installed simultaneously executing the second-stage PowerShell script, which in turn executes the final RAT payload using Process Hollowing.

“The Snip3 Crypter’s ability to identify sandboxing and virtual environments make it especially capable of bypassing detection-centric solutions. As a result, organizations with detection-focused stacks need to be wary of attacks like Snip3 and others. Morphisec customers can rest easy that they are protected against the evasive techniques Snip3 and other attacks like it employ,” Morphisec said.

Microsoft Fixes 55 Flaws

In a recent development, Microsoft’s May Patch Tuesday security update addressed over 55 vulnerabilities including four critically rated Zero-Day bugs. The now patched Zero-Day vulnerabilities include CVE-2021-31204 .NET and Visual Studio Elevation of Privilege Vulnerability, CVE-2021-31207 Microsoft Exchange Server Security Feature Bypass Vulnerability, CVE-2021-31200 Common Utilities Remote Code Execution Vulnerability, and Zero Day Initiative flagged CVE-2021-31166.

Designing a Secure Remote Future with Windows Remote Desktop Protocol

remote desktop protocol (rdp)

As COVID-19 drove many employees into remote work, IT departments rushed to get everyone online with access to the data and applications they needed to be productive. Chief information security officers (CISOs), however, were nervous. They understood many home computers lacked up-to-date protection, that the machines might also be shared by less security-minded household members, and that cybercriminals would be looking to exploit the situation by attacking remote desktop services as they become publicly available.

By Mike Jumper, CEO and Co-founder of Glyptodon

They were right. Microsoft’s Remote Desktop Protocol (RDP), already a common target, has become even more heavily targeted. According to research from cybersecurity firm ESET, Windows RDP attacks rose an astounding 768% in 2020. In fact, malware like Trickbot now includes RDP scanners to search for open ports, and distributed denial-of-service (DDoS) attacks have been using RDP as a way to amplify their impact.

To be fair, the issue here is not RDP itself. RDP is a very useful and functionally rich protocol, and the open-source project I work on, Apache Guacamole, uses it internally with great success. The issue is the attack surface created by the position of the remote desktop service within the operating system. This can be eliminated with proper system design.

Protecting Privileged Services

To enable a user to operate a machine remotely, RDP requires administrator-level privileges. Should an attacker exploit a vulnerability and execute arbitrary code, that code will inherit those privileges. A successful attack against a privileged service can be catastrophic mainly due to the privileges the attacker gains once they control that service.

Two of the vulnerabilities found in 2019, popularly known as BlueKeep and DejaBlue, can be exploited to do just that on unpatched Windows servers with public RDP services. This can result in the introduction of malware, the initiation of a ransomware attack, and allow hackers to move laterally across the network and infiltrate other computers.

As a privileged service, RDP should always be carefully guarded and never exposed publicly. Instead, all access should take place through an entirely independent service, one with tight controls and limited privileges so that a successful attack cannot result in gaining administrator status

Protecting Against the Unknown

A system should never remain unpatched. The reasons why are basic and abundantly clear: older, unpatched software possesses known vulnerabilities. That said, the foremost concern amongst CISOs regarding remote access should be unknown vulnerabilities. When a new vulnerability emerges, it is not always possible to patch the system before the vulnerability begins to be exploited, and it’s on the system’s design to protect against this.

When hackers exploit a vulnerability, they perform an action that a software’s security model should otherwise deny. CISOs must be sure IT sets boundaries that can be enforced independently through layers of protective services while limiting privileges to only what is essential for operation. Respectively, these are known as defense-in-depth and the principle of least privilege.

Authentication and authorization should not just be a part of connecting with RDP, they should be preconditions that are satisfied before RDP is even available. To this end, a remote desktop gateway should be the only way in and should be positioned in front of RDP. The gateway should provide access strictly to remote desktops assigned to specific users, and should operate with limited privileges to ensure an attacker cannot directly gain admin control if the gateway is compromised.

Virtual private networks (VPN) have been a popular approach for overcoming these hurdles. Unfortunately, they have a reputation for being sluggish and difficult to use, and deploying so generic a solution like a VPN can open up access to more of the private network than each user needs. With so many employees likely to remain remote post-pandemic, VPNs are not likely to provide a feasible solution for securing RDP at the enterprise level.

After deploying the gateway, IT should lock down the network firewall so that the gateway is the only means to access RDP from outside the network. Likewise, computers on the network should be locked down so that they allow access to RDP only via the gateway. By isolating remote desktops at the network level, a single hacked computer doesn’t put all computers in jeopardy.

The Remote Future

For CISOs, securing RDP is simply a matter of ensuring that it’s deployed carefully so malicious actors have nothing to leverage. Place RDP services behind a secure gateway, apply patches in a timely manner, and follow best practices, and you’ll have a long-term solution for your remote future.


About the Author

mike jumperMike Jumper is the original developer of Apache Guacamole, an open-source remote desktop access gateway. He is CEO and co-founder of Glyptodon, which provides a commercial build of Apache Guacamole with enterprise support.

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

FBI and ACSC Warn About Ongoing Avaddon Ransomware Campaign

Avaddon ransomware, Microsoft and Fortinet flaws, apt

International law enforcement authorities and the cybersecurity community are joining hands to thwart evolving cyberattacks from various threat actors operating across the globe. Recently, the FBI and the Australian Cyber ​​Security Center (ACSC) warned about the ongoing Avaddon ransomware campaign targeting manufacturers, airlines, and health care organizations globally.

Avaddon Ransomware

The Avaddon ransomware variant was first spotted in February 2019. The ACSC claimed that the Avaddon ransomware variant is leveraged as a Ransomware-as-a-Service (RaaS) in several cybercriminal campaigns in Australia. Operators behind Avaddon usually demand a ransom payment in Bitcoin (BTC), with an average demand of BTC 0.73 (approximately  $40,000) for a decryption key.

“Avaddon has an active presence on underground dark web cybercrime forums, notably advertising the Avaddon RaaS variant to potential affiliates via a number of high tiers cybercrime forums. Avaddon threat actors also utilize the data leak site (DLS) avaddongun7rngel[.]onion to identify victims who fail or refuse to pay ransom demands,” the ACSC said.

Avaddon Targeted Countries and Sectors

Image Courtesy: ACSC

TTPs of Avaddon Ransomware Group

  • Using phishing and malicious email spam campaigns to deliver malicious JavaScript files. These are often low in sophistication, containing a threat suggesting the attached file contains a compromising photo of the victim.
  • Using double extortion techniques as coercion and further pressure victims to pay a ransom
  • Threatening to publish the victim’s data (via the Avaddon Data Leak Site (DLS): avaddongun7rngel[.]onion
  • Threatening the use of DDoS attacks against the victim

How does Avaddon attack?

According to security firm Trend Micro, Avaddon downloads the ransomware from malicious sites and deploys them on critical systems. The ransomware is distributed via emails with mostly fake photo attachments named IMG{6 random number}.jpg.js.zip, which also contains a JavaScript file named IMG{6 random number}.jpg.js. Once the user downloads the attachment, the malware automatically downloads and runs the ransomware payload. The ransomware then encrypts the critical files in the system and appends them with the .avdn file extension.

A ransom note is displayed on the victims’ system, which reads: “All your files have been encrypted.”

Mitigation Measures

The ACSC also recommended certain security measures for improved security:

  • Patch operating systems and applications, and keep antivirus signatures up to date.
  • Scan emails and attachments to detect and block malware and implement training and processes to identify phishing and externally sourced emails.
  • Maintain offline, encrypted backups of data and regularly test your backups.
  • Regularly conduct backup procedures and keep backups offline or in separate networks.

Related Story: How Australia Plans to Thwart Ransomware Attacks