Home Blog Page 88

Top Security and Risk Trends for 2021

Zero Trust, cybersecurity

Cybersecurity and regulatory compliance are the top two biggest concerns of corporate boards, according to a recent CEO Agenda Survey by Gartner. Adding a cybersecurity expert directly to the board is just one of the eight security and risk trends for 2021, many of which are driven by recent events such as security breaches and the COVID-19 pandemic.

By Peter Firstbrook, VP Analyst, Gartner

In the past year, the typical enterprise has been turned inside out. As the new normal takes shape, all organizations will need an always-connected defensive posture and clarity on what business risks remote users elevate to remain secure.

This year’s security and risk trends highlight ongoing strategic shifts in the security ecosystem that aren’t yet widely recognized but are expected to have a broad industry impact and significant potential for disruption.

Trend No. 1: Cybersecurity mesh

The cybersecurity mesh is a modern conceptual approach to a security architecture that enables the distributed enterprise to deploy and extend security where it’s most needed.

When COVID-19 accelerated digital business, it also accelerated the trend wherein many digital assets — and individuals — are increasingly located outside of the traditional enterprise infrastructure. Additionally, cybersecurity teams are being asked to secure countless forms of digital transformation and other new technologies. This requires security options that are flexible, agile, scalable, and composable — those that will enable the organization to move into the future, but in a secure manner.

Trend No. 2: Cyber-savvy boards

With an increase in very public security breaches and increasingly complex security setups, boards are paying more attention to cybersecurity. They recognize it as a huge risk to the enterprise and are forming dedicated committees that focus on discussing cybersecurity matters, often led by a board member with security experience (such as a former CISO) or a third-party consultant.

This means that the organization’s CISO can expect increased scrutiny and expectations, alongside an increase in support and resources. CISOs will need to improve their communication and should expect tougher questions from the board as a result.

Trend No. 3: Vendor consolidation

The reality of security today is that security leaders have too many tools. Gartner found, in the 2020 CISO Effectiveness Survey, that 78% of CISOs have 16 or more tools in their cybersecurity vendor portfolio; 12% have 46 or more. Too many security vendors result in complex security operations and increased security headcount.

Most organizations recognize vendor consolidation as an avenue for reduced costs and better security, with 80% of organizations interested in a vendor consolidation strategy. Large security vendors are responding with better-integrated products. However, consolidation is challenging and often takes years to roll out. Although lower cost is often a driver of this trend, more streamlined operations and reduced risk are often more achievable.

Trend No. 4: Identity-first security

The perfect storm of several events made identity as the new perimeter a trend, including COVID-19’ resulting in remote work and technical and cultural shifts. Identity-first security has been considered the gold standard for a while, but because many organizations remained in more traditional setups, it wasn’t a focus.

Now that the pandemic has pushed organizations to fully (or mostly) remote, this trend has become vital to address. The result of these technical and cultural shifts is that “identity first security” now represents the way all information workers will function, regardless of whether they are remote or office-bound.

Trend No. 5: Managing machine identities as a critical security capability

As digital transformation progresses, organizations are seeing increased numbers of nonhuman entities, which means managing machine identities has become a vital part of the security strategy. Included in machine identities (as opposed to human identities) are workloads (i.e., containers, applications, services) and devices (mobile devices, desktop computers, IoT/OT devices).

As the number of devices increases — and continues to grow — establishing an enterprise-wide strategy for managing machine identities, certificates and secrets will enable the organization to better secure digital transformation.

Trend No. 6: Remote working is now just work

According to the 2021 Gartner CIO Survey, 64% of employees are now able to work from home, and two-fifths actually are working from home. As a result of COVID-19, what was once only available to executives, senior staff and sales are now widely available, with plans to shift some employees to remote permanently post-pandemic. From a security perspective, this requires a total reboot of policies and tools and approved machines to better mitigate the risks.

Trend No. 7: Breach and attack simulation

A new market is emerging to help organizations validate their security posture. Breach and attack simulation (BAS) offers continuous testing and validation of security controls and tests the organization’s posture against external threats, as well as offering specialized assessments and highlighting the risks to high-value assets like confidential data. Plus, BAS includes training to enable security organizations to mature.

These tools will help immediately identify issues when it comes to the efficacy of security controls, configuration issues, and detection capability. The ability to run this kind of assessment repeatedly and across a range of attack techniques enables better security assessments in near real-time.

Trend No. 8: Privacy-enhancing computation techniques

Privacy-enhancing computation (PEC) techniques are emerging that protect data while it’s being used — as opposed to while it’s at rest or in motion — to enable secure data processing, sharing, cross-border transfers, and analytics, even in untrusted environments.

This technology is rapidly transforming from academic research to real projects delivering real value, enabling new forms of computing, and sharing with reduced risk of data breaches.


About the Author

Peter FirstbrookPeter Firstbrook utilizes his 20+ years of experience as an industry analyst to help clients improve their security posture to defend and respond hacking, ransomware, and phishing attacks. As a Research VP with Gartner, Firstbrook is responsible for endpoint protection platform (“EPP”), Endpoint Detection and Remediation (“EDR”), extended detection and response (XDR), and Secure Email gateways (“SEG”). He is the Lead Analyst for Cisco Systems inc. and prepares the annual top Security and risk management trends. He helps companies implement best practices, select strategic technologies, and negotiate the best deal.

Before joining Meta Group in May 1997, Firstbrook worked as a financial analyst, implemented retail and branch office networks, developed software for tax reporting/invoicing programs, and was a database administrator.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Protecting Intellectual Property from Cyberattacks

intellectual property

Many organizations rely on unique and valuable ideas, innovation, and knowledge to gain a competitive edge in the market. This is commonly referred to as Intellectual Property (IP) which consists of trade secrets, trademarks, patents, copyrights, drawings, and sensitive business information. For example, for a pharmaceutical manufacturing organization, the formula for a groundbreaking medication is considered IP or for a gaming software organization, the upcoming copy of a game pre-release is considered IP.

By Kartik Shahani, Country Manager, Tenable India

IP is one of the most valuable assets of an organization as it is how an organization differentiates itself from its competition. Cybercriminals understand the value of IP and are therefore constantly looking for ways to steal and monetize it. According to i-Sight, the estimated global value of counterfeit and pirated products is $500 billion higher today than it was in 2015 (1.7 trillion). IP theft is more common than you might think. Attacks using IP theft have also begun to manifest themselves in the form of theft/ransom schemes, where the attacker will steal valuable IP, then threaten to release this IP unless a ransom is paid. Within India, during 2020 one in four Indian organizations suffered business-impacting cyberattacks resulting in the theft of IP, a Forrester study commissioned by Tenable revealed.

Having an organization’s IP stolen has far-reaching negative consequences in the form of damage to competitive position, lost revenue, legal fees, and damage to brand reputation. Losing IP could mean forfeiting the first-to-market advantage, or in the worst case — losing entire lines of business to competitors.

Protect the crown jewels of an organization

CISOs should work in tandem with business leaders to determine the organization’s crown jewels and prioritize cybersecurity efforts accordingly. Understanding which threats pose the greatest business risk and aligning cybersecurity strategies with business objectives is crucial to protecting IP.

Embrace foundational cyber hygiene

All organizations must implement foundational cyber hygiene practices such as asset inventory, vulnerability scanning, patch application, antivirus and anti-malware tools, firewalls, and company-wide security policies – as a first step.

In looking at the top 10 routinely exploited vulnerabilities, publicly known but unpatched flaws provide cybercriminals with a window of opportunity to gain a foothold into the organization’s network. This is because many organizations struggle to keep pace with the sheer volume of newly discovered vulnerabilities.

A risk-based approach to vulnerability management is key in helping organizations prioritize risks based on threat context and the potential impact on businesses. A risk-based approach takes the position that vulnerabilities that expose the organization to the greatest risk should be mitigated first. Understanding the actual and not theoretical impact of vulnerabilities and focusing remediation efforts based on business risk is a more effective way to protect IP.

Understand your network and the expanded attack surface

With remote work being the new normal, keep an inventory of all the hosts and devices connected to the network. Pay special attention to personal devices as these may not include the same protections as company-issued ones. Also, be mindful of applications running on a network. Unauthorized, unknown, or dormant apps are red flags.

Not all IP theft comes from external sources. Theft can be perpetrated by insiders with legitimate access to the network. It is therefore critical to identify internal systems and users that have access to the IP. Access and permissions given to employees, service contractors, temporary workers and systems accounts must be monitored. By empowering organizations to prioritize their vulnerability management results based on the privileges afforded to each end-user in the system, security teams can effectively disrupt the attack paths cybercriminals use to install malware, move laterally and exfiltrate data.

In a highly digitized environment, IP is highly lucrative. Organizations must therefore endeavor to identify and patch known vulnerabilities, constantly monitor their network, and have visibility over who has access to systems and resources at all times.


About the Author

Kartik Shahani is the Country Manager for Tenable India. He is responsible for spearheading strategic initiatives in the enterprise security market, managing operations, and channel activities in the region. With over 30 years of experience, Kartik has extensive knowledge in sectors such as telecommunications, finance, and government. Shahani joined Tenable from RSA Security, a division of Dell EMC, where he was Director for Channel in the Asia Pacific and Japan.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Bigger Organizations Have Multiple Attack Surfaces

Upendra Mardikar is a prolific inventor and cybersecurity and digital identity executive with an “art of possible” mindset who led global teams to secure world-class organizations including American Express, Visa, and PayPal. He is credited with 95+ patents issued and pending. He is the Chief Information Security Officer at Snap Finance, a leading omnichannel digital-first fintech and POS lender, where he leads cybersecurity while building new platforms to enable growth opportunities. This includes securing innovative multi-cloud platforms and products, artificial Intelligence, client-facing technology, and customer and developer experiences.

SPONSORED CONTENT

‍He is a regular speaker at esteemed conferences for Stanford University, Global Big Data Conference, NFC forums, European Identity Conference, KNOW Identity Conference, Global Retail Conference in Canada, IOT conference, and others. Featured in Genius Journal, he helped pioneer blockchain in Amex and filed patents on blockchain and DLTs. He and his team worked on IoT security and payments and participated in several industry-standard bodies like EMV, Global Platform, PCI-DSS, FIDO, etc.

‍In this interview, we have John Jeremiah, Marketing Director, Traceable.ai, interviewing Upendra Mardikar on several cybersecurity threats and trends.

Edited excerpts of the interview follow:

John Jeremiah: At Snap Finance you are really on the cutting-edge of connecting consumers to merchants and streamlining financial processes. As a CISO, this has to be really challenging because there’s regulatory requirements, the sensitive nature of transactions and, you have to manage risk. How do you prioritize those risks? What are some of the biggest risks you’re facing in your role?

Upendra Mardikar: If you think about it, these are challenging times, especially with COVID-19, the things happening in the industry right now, and the U.S. government has just put sanctions on Russia. Typically, attackers go after the three most critical industries. The first is critical infrastructure that includes electricity, power plants, nuclear plants, water supplies, etc. The second is the healthcare industry. And then the third, and not necessarily in that order, the financial industry.

In general, financial institutions and financial services have been soft targets for attackers.  In terms of prioritizing risks, as we transition our organization to API-first, cloud-first, mobile-first, and AI-first mentality across multiple services, these services using APIs are exposed and vulnerable.  So that’s why having secure APIs is one of our highest priorities to make sure that we mitigate risks.

One of the top three biggest risks currently for the industry is ransomware and malware. The second risk is identity takeovers, which we are seeing in the industry, and the third risk is data loss or data leakage. I would have said DDoS if it were 2019 or the early part of 2020 but since late 2020, we are increasingly seeing data leakage as a big threat. Given these three risks,  we prioritize our work based on how our services are exposed.

Jeremiah: Now that’s really fascinating how data leakage and the other threats have become bigger threats than DDoS. One of the things I noticed when I looked at your profile is that you’ve come from a strong background in security and incredibly large financial services institutions. So, in your experience at Snap Finance as a CISO, how is it different? How do you compare and contrast the difference from being in a large company to being in a much smaller organization?

Mardikar: Problems are generally amplified in bigger organizations as there are multiple attack surfaces and it’s a larger problem to protect them.  Problems are also larger in scale and you have to move the organization at scale.

Smaller organizations have similar problems, except that the velocity of changes is very high. However, it’s potentially easier to get things done, though there are limited resources and three types of constraints in smaller organizations – region constraint, resource constraint, and skill constraint. So, you just have to manage these challenges differently.

In a bigger organization, it’s more about selling and getting collaboration across multiple business units and therefore, a different part of your brain is being activated versus smaller organizations where you still have to juggle with the resources and different constraints.

Jeremiah: You said you’re going to move towards mobile-first, API-first, and cloud-native – you’re really pivoting on how you develop applications. How do you see the next wave of security problems that are going to happen as you move towards these new technologies?

Mardikar: Historically, security has been addressed within closed walls. When you had just four walls of your organization, all you had to do to protect your perimeters was to lock your windows, lock your doors, put up some CCTV cameras, and those were enough to protect your four walls.

Nowadays, protecting within the organization is table stakes, and we have to go beyond the four walls, we have to go and make sure that not only do we protect our organization, we also have to consider the ecosystem of our partners, the supply chain consisting of other third parties. These third parties and multiple stakeholders are going to interact with our systems, and we are going to interact with their systems using APIs. So, when we start interacting with APIs, cloud and SaaS models, the overall system is no longer within four walls or defined boundaries.

Now, the security model needs to address not just North-South traffic, but we need to think beyond that and protect East-West traffic in addition to North-South traffic. And it’s really all in a spaghetti kind of architecture, so it’s not just the egress and ingress traffic we need to pay attention to.

When you’re talking to third parties, vendors, or partners providing value-added services to your organization, we need to secure those transactions as well.  Some of them will be real-time, some of them will be batch mode, and some of them will be non-real-time.  And so, how do you guarantee delivery with high potency, with high availability architecture, and how do you make sure that these spaghetti-like connections are secure?

Jeremiah: It’s an incredible challenge because the pace of change is so fast. The business expects that technology will iterate really fast, I mean it, not only is technology going fast, but one would argue that the attackers are moving faster too. Now, as a CISO,  you have to lead your team and create a way to have your team keep up with all of this change, the pace.  How do you lead your team to keep up with both the developers, who are going continuously fast and the attackers, who are equally fast?

Mardikar: There are two principles that we follow.

The first is a “saying yes” principle — we are here to support our business and we always want to say yes to the business. And there is the notion we call the “art of the possible,” and that we always try to support.

Secondly, to keep up with the velocity of changes, we have an automation first mentality – you have to strengthen your foundation by automating every workflow and technology that you are using.

Those are the two primary principles we follow.

We are trying to become a completely engineering-based organization and automate the metrics, the KPIs, and managing security risks.

Practicing “the art of possible,” “automation first,” and “security as an engineering discipline” are the three key factors we follow to keep up with velocity.

Jeremiah: Amazing. I think it really resonates, the idea that security, which has always been perceived in the past, as the “department of no – we can’t do this” moves to a model where you’re automating continuously and embracing the principles of engineering to move at the pace of business. This is really inspiring.  

As you talked earlier about APIs and the API risks, how do you see these API risks evolving, and how do you see protecting APIs different from protecting other more traditional security threats?

Mardikar: If you squint a little bit, everything is an API or soon will be. It would be wrong to say that the traditional web 1.0 HTML pages were not APIs. In fact, those were also APIs. POST is an API, and then it evolved to REST, and other kinds of things. Everything is an API, whether you’re talking about native applications, mobile native applications, or whether it’s developer platforms.  There are several developer platforms that we have been involved in developing and exposing it or developer first companies.  To really think about it, even in the traditional sense, everything was an API.

What is happening now is that these APIs are going more and more towards devices. For example, when you consider SPAs (single page applications), and when you have the entire orchestration move out from your four walls boundary and into the application, that’s where the orchestration is happening.

Now suddenly APIs are becoming stateless and the orchestration is happening outside.  With that kind of transition, it’s very difficult for you to know you have an attacker, because they don’t have to use API 1, API 2, API 3 in a very sequential way, now they can call API 3 directly and you cannot expect a sequence.

So, with your partners with ingress and egress traffic that entire thing you have to think beyond just North-South traffic- you have to think about East-West traffic and you have to think about all those tentacles that come out of that – so that is the new paradigm. When you are moving to single-page applications, when you have multiple partners and stakeholders, and when you are talking about ingress and egress APIs – that’s where the paradigm has completely shifted.

Jeremiah: If you think about the culprits that are the cause of some of the vulnerabilities we’re talking about, some of them might be attackers trying to penetrate the systems. But isn’t another reason for the vulnerabilities of some of the technology and processes we’ve adopted? We’ve evolved in such a way that we’re doing continuous development, we’re doing DevOps, and delivering fast. 

What do you think we have to do differently, both in educating people and bringing people along? API security is a unique vector. How do you see this as a change and how do we have to change or educate our IT professionals?

Mardikar: Traditionally, auditors will ask – Do you have a good hardware asset inventory? Do you have a good software asset inventory? Are you doing continuous vulnerability assessments? Are your firewalls secure and are your ports closed? These are very typical audit activities that are fair and absolutely necessary. But today, these are necessary but insufficient.

So, the way to think about it is – vulnerabilities, as mentioned in CVEs are primarily directed in the technologies you are using. For example, let’s say you’re using JVMs, or jQuery, or a particular version of firewall, and it has the kind of vulnerabilities reported in CVE’s, you go ahead and patch it. That is one class of vulnerability for which it is extremely critical for us to protect.

But in addition, what is happening is that with API security, there exists some APIs that are not written to get published (Apple uses this distinction which I really like- “published APIs and non-published APIs”), but then other developers using the API in a different context might expose them without knowing they weren’t meant to be published. And when you think about the way we are exposing multiple APIs, intentionally or not, it causes the potential for vulnerability in the whole application.

Now we are suddenly talking about security at the application layer. And when we are doing threat modeling typically what happens is that, especially when you are in scrums and scaled agile type models, we are asking, “I am going to expose this particular API, Is it okay?” And then we do a security review. But the problem with this particular approach is that if you look at one API it might not be so risky, but if you are using and exposing that API in conjunction with another API, it suddenly increases the risk. So, the risk can grow exponentially.

To give you an analogy, if I just state a nine-digit number, it will be somebody’s social security number, but as soon as I say the first name and the last name, along with their social security number, the paradigm changes.

Jeremiah: Thank you. That’s fair. APIs aren’t going away. Developers are going to keep shifting left and we’re going to keep going faster. What do you have to change to keep up? Is there a technology that can help level the playing field to help security teams protect APIs and our applications? Do you see a solution to address this problem?

Mardikar: If you think about it, this problem has been created by technology.  API is a technology and it’s created by technology. I don’t see the process as a solution for a technology problem. I see technology as a solution to a technology problem. And for that, when we talk about shift-left, we need to have a proper understanding of the requirements and then apply the threat modeling exercise.

When you expose a particular API to enable a particular product feature, what is the first thing you do? You do the threat modeling. So, it all starts with threat modeling in my mind and automation where technology like Traceable AI is certainly going to help as a next-generation security tool. That can be baked in right from shift left, then go in the middle, and then we go to the right as well, so that there is a closed loop for security.

Jeremiah: So, it’s about automation, understanding threats, detecting them early, and then being able to not only apply that to the developers in the early stages of development, to help them understand those risks but also, as you test and then eventually deploy those applications to understand what’s happening in reality.

Mardikar: Exactly, and then doing a closed loop back into the threat model.

Jeremiah: That’s right! That cycle has to start again because as we’ve talked about earlier, the attackers are only getting faster and more creative.

Mardikar: That’s right. This will be automated – again, going to the art of possible and automation-first mentality.


About the Interviewer

John Jeremiah is an enterprise DevOps evangelist and the Marketing Director at Traceable.ai.  He is a multifaceted IT software leader from places such as GitLab, HP, and HPE with over 20 years of IT leadership and software experience including developing and shaping DevOps positioning and go-to-market strategy as well as an application developer, project/program manager, and IT Director. Jeremiah has led software delivery transformation, adopting an agile and mature process framework, and has held a variety of leadership roles with the U.S. Navy, IT consulting, and Fortune 500 IT organizations.

Disclaimer

CISO MAG does not endorse the views of the interviewer and interviewee. Facts, opinions, and language in the interview are personal and CISO MAG does not assume any responsibility or liability for the same.

60% of School Apps Disclose Students’ Data to Third Parties

School apps sharing students’ data

The pandemic forced school and college students to rely on various e-learning mobile applications to help them with their education. However, most of these e-learning apps are allegedly harvesting students’ information and sharing it with third-party vendors, without users’ knowledge. A research from a non-profit organization Me2B Alliance revealed the irregular data sharing practices of education apps used by school authorities. It was found that over 60% of school apps in the U.S. are transferring students’ data to various third parties, including ad networks like Google and Facebook. The virtual learning apps are being used by at least half a million people including students, educators, and parents.

The researchers analyzed around 73 mobile apps used by 38 schools across 14 U.S. states. All the 73 apps were examined by analyzing the Software Development Kits (SDKs) of each application.

Most mobile apps were collecting and storing details including name, age, and other personally identifying information (PII), including access to users’ camera, microphone, device ID, and call data.

Key Findings

  • Over 48% of apps sent student data to Google and 14% to Facebook. Furthermore, each app sent data to 11 different third parties.
  • Public schools (67%) were more likely to send student data to third parties than private schools (57%).
  • Nearly 18% of public-school apps sent data to very high-risk third parties, which further share data with possibly hundreds or thousands of networked entities.
  • Android apps are three times more likely than iOS apps to be sending data to third parties.
  • 91% of Android apps send data to high-risk third parties compared to only 26% of iOS apps, and 20% of Android apps sent data to very high-risk third parties, compared to 2.6% of iOS apps.
  • There is an unacceptable amount of student data sharing with third parties – particularly advertisers and analytics platforms – in school apps.
  • iOS apps were found to be safer than Android apps, and with ongoing improvements, the privacy gap between iOS and Android apps is expected to widen unless Google makes some changes.
  • People still have too little information about which third parties they’re sharing data with, and the app stores must make this information clearer.

“The findings from the research show the pervasiveness of data sharing with high-risk entities and the number of people whose data could be compromised due to schools’ lack of resources,” said Lisa LeVasseur, Executive Director of Me2B Alliance.

Qualcomm’s MSM Chips’ Vulnerability Affects 40% of All Mobile Phones

vulnerabilities in DSP Chip, vulnerabilities in Qualcomm MSM Chip

Researchers at Check Point found a vulnerability in Qualcomm’s mobile station modem (MSM) chips, which are trusted with cellular communication in nearly 40% of the world’s Android phones. Researchers said, If exploited, the vulnerability would have allowed an attacker to use Android OS itself as an entry point to inject malicious and invisible code into phones, granting them access to SMS messages and audio of phone conversations.

What is Qualcomm’s MSM Chip?

Designed by Qualcomm, this system on chip (SoC) is an ongoing series of a 2G/3G/4G/5G capable system being manufactured since the early 1990s. MSM has been specifically designed for high-end phones and supports advanced features like 4G LTE and high-definition recording. This chip communicates with the operating systems (OS) using the 3rd Generation Partnership Project (3GPP) technology. However, when it comes to Android, the chip uses Qualcomm’s proprietary protocol the MSM Interface (QMI). This protocol enables the communication between the software components in the MSM with other peripheral subsystems on the device including cameras and fingerprint scanners.

Related News:

Google Fixes Critical Remote Code Execution Vulnerabilities in Android

The Exploit

The vulnerability, which can now be tracked under CVE-2020-11292, could allow the attackers to exploit a “heap overflow” weakness in the QMI interface. This is used by the company’s cellular processors to interface with the software stack. Once successful, it gives rights to the attackers for controlling the modem and dynamically patching it from the application processor.

This vulnerability could help malicious apps disguise their activity under the modem chip, thus, masking it from Android’s security controls. Additionally, it could also enable attackers to unlock the SIM details of the targeted mobile that included network authentication info and contact information.

Check Point’s researchers found the vulnerability in October 2020 and immediately informed Qualcomm in responsible disclosure. Qualcomm notified all its vendors about the issue and sent a security update to them by December 2020. However, it took time in disclosing the vulnerability to the end-users, and thus it was finally made public only on May 6, 2021.

Not the First Time

Earlier in 2020, Qualcomm’s Snapdragon Digital Signal Processor (DSP) chips were riddled by six high severity vulnerabilities that allowed attackers to take control of users’ mobile devices without their knowledge. Click here to know more.

Peloton’s API Vulnerability Exposes Users’ Personal Information

Peloton Data Leak

Exercise equipment company, Peloton, is facing severe criticism after it failed to protect its users’ personal information. Cybersecurity researcher Jan Masters discovered a vulnerability that allowed anyone to make unauthenticated requests to Peloton’s API and pull users’ activity details and sensitive account data, despite their profiles being on private mode. The servers allegedly exposed sensitive information like user IDs, instructor IDs, group membership, location details, workout statistics, gender, and age.

Peloton provides connected stationary bikes and treadmills that come with cameras, microphones, and tablets attached. Users can live stream fitness classes and communicate with others. The company has more than three million subscribers, making it an attractive target for cybercriminals.

Peloton uses unauthenticated APIs that are vulnerable to Broken Object Level Authorization (BOLA). An unauthenticated attacker could illicitly obtain this personal information simply by querying the API, even of customers who kept their profiles private. While there is no evidence of the misuse of users’ data, the researcher claimed that Peloton acknowledged the security disclosure and fixed the bug.

With a large user base along with celebrities using Peloton services, including President Biden, the security incident could result in a massive data breach. “The mobile, web application and back-end APIs had several endpoints that revealed users’ information to both authenticated and unauthenticated users. This endpoint could have been polled by an unauthenticated user, but the fix now requires a user account, which anyone can self-register to. This still exposes the same data to any other Peloton user. Some of these classes can reach 800+ users at one time, which increases how much data someone could harvest,” Masters said.

Talking to CISO MAG about the security incident, Roshan Piyush, Security Research Engineer at Traceable, said, “It’s very common to see unauthenticated APIs and especially BOLA vulnerabilities. It mostly occurs due to overlooked authentication and authorization protection for the APIs in the development process. Some APIs are left without protections to be integrated with Authorization controllers in API gateways, which is another step for misconfiguration. Unauthenticated APIs are most dangerous as they make it so easy to exfiltrate data, especially if exposing sensitive, PII or PHI. As in the case of Peloton, even members who kept their profile private could have been a victim of an attack. It is yet to be established if there was a misuse.”

“Enterprises must focus on improving API security posture and reevaluating their API security strategies. For an API under development, developers need to seek guidance during the design of the authentication procedures. The goal should be to enforce the security in the design of the authentication procedure by considering human and bot factors.”

In related news, Peloton was forced to recall its treadmills over lack of safety precautions that led to a child’s death. Tread machines sold in the U.K are also being recalled due to faulty display consoles. Peloton CEO John Foley apologized for refusing to act quickly.

DDoS Attack on Belnet Takes Down Belgian Government Websites

DDoS Attacks

On Tuesday, May 4, Belgium faced a widespread internet outage when the country’s leading internet service provider (ISP), Belnet, was reportedly bombarded by multiple waves of DDoS attacks.

DDoS Attack on Belnet

According to Belnet’s security update, the first wave of attacks hit the ISP company around 11 a.m. The security teams immediately sprang into action to mitigate the attack and to build alternate paths for the traffic to normalize the situation. Additionally, they contacted the Center for Cybersecurity Belgium (CCB) for teaming up with their resources to quickly contain the attack. However, its ripple effects were soon felt elsewhere as nearly 200 organizations, including universities, public administrations, and research institutes reported: complete or partial cut off from the Internet.

Related News:

What is DDoS and How Can I Better Defend My Business Against this Threat?

The Known Casualties

One such incident was reported in the parliament of the Wallonia-Brussels Federation. It was forced to suspend its committee meeting on the situation of Uyghurs in China,as the parliamentarians working remotely via the Cisco Webex were unable to continue their debate because of the internet outage. Similarly, the online reservation systems for COVID-19 vaccinations in Belgium also went down, temporarily halting the vaccination program for a while.

Around 4:30 p.m, Belnet gave another update saying, The attack is still in progress and takes place in successive waves. But exactly two hours later, Belnet’s security team was finally able to contain it and saw the effect of the attack “diminishing.”

Dirk Haex, Technical Director at Belnet, said,

We are fully aware of the impact on the organizations connected to our network and their users and we are aware that this has profoundly disrupted their functioning. Belnet continually invests in cybersecurity. However, yesterday’s DDoS attack was of such a scale that our entire network was saturated. The fact that the perpetrators of the attack constantly changed tactics made it even more difficult to neutralize it.

Belnet stated that the attack did not seem like a data breach or theft of data attempt. No networks were infiltrated during the attack and the attack was probably initiated with the sole intent of “saturating” Belnet’s network.

The investigation is still ongoing and the culprit behind the targeted DDoS attack on Belnet is yet to be identified. However, MP Wouter De Vriendt suggested that China may well be behind the attack.

Related News:

U.K.’s Crypto Exchange EXMO Halted Operations After DDoS Attack

Here’s what the experts have to say about World Password Day

World Password Day 2021

Today is World Password Day. A day meant to remind everyone about the importance of protecting themselves through strong passwords. World Password Day is an annual observance that falls on the first Thursday of every May, also meant to commemorate security researcher Mark Burnett’s book, Perfect Password: Selection, Protection, Authentication, where he encouraged people to not only have safe and smart passwords but to also have a password day.

Burnett’s tips were taken up by Intel Security, which took the initiative to declare the first Thursday in May as World Password Day, in May 2013, following which the Registrar of National Day Calendar formally designated it.

To observe this day, CISO MAG interacted with several cybersecurity experts from around the globe about the relevance of World Password Day, the trends in authentication technologies, and the best practices that need to be established.

1. User frustration is ever-increasing with forced password resets 

“When World Password Day was established in 2013, the world recognized that passwords were a necessary evil, despite being a flawed and insecure method of authentication. But the root of the problem goes back to the foundation of the ‘commercial internet’ in the mid-1990s, when Netscape and others enabled widespread access and consumer accounts, prompting a massive need and meteoric rise in password use, and beginning an era of consumer insecurity and exposure.

Fast forward to today and the problem has ballooned. Verizon’s 2020 Data Breach Investigations Report (DBIR) revealed that 80% of breaches use stolen credentials, collected either through database leaks or phishing attacks. And even if you follow recommendations for password hygiene, criminals can still get their hands on your password through a range of means – from fraudulent ‘phishing’ sites to insecure password databases and even commandeering your phone to intercept password reset messages.

The industry has responded by putting an even greater burden – not to mention blame – on consumers, to compensate for what can only be described as a complete systemic failure and an unwillingness to upset the market apple cart by refusing to fix the foundational issue. Complexity and user frustration are ever-increasing with forced password resets, cumbersome password creation requirements, and extra steps for multi-factor authentication (MFA). In summary, consumers must expect and demand better internet security and end the ‘stupid user’ blame game. The industry itself is headed in this direction with corporations and groups advocating for the eradication of passwords – but the industry is not moving fast enough, and the technology exists to make change now.”

 

2. Password-sharing behavior may stem from early childhood 

“While a lot of the coverage about passwords focuses on business users, it’s really important not to overlook children and teens in this discussion. They will typically make some of the same types of common mistakes as adults when creating and using online passwords, but there are several that stand out the most for this age group.

One of the worst is sharing credentials with friends, boyfriends/girlfriends, etc. At that age, relationships tend to be shorter in duration and some kids end up using the shared access against each other such as posting inappropriate messages on social media accounts or conducting surveillance over account activity. This type of password-sharing behavior may even stem from early childhood when parents would share their credentials with their kids for accessing devices or online sites. This should be avoided at all costs.

Secondly, kids and teens are exposed to devices everywhere they go from the library, to school, to over a friend’s house, etc. It’s important to avoid entering your credentials on untrusted devices that you do not own, control, or completely trust. Devices in public places should only be used for anonymous web browsing and not for logging into any of your online accounts since passwords can be easily stolen from these types of computers.

Finally, it’s important to avoid using personal information when creating any of your passwords. Young kids, and even adults for that matter, want to generate a password that is easy enough to remember. So they’ll use their name, birthdate, address, phone number, etc. These are all details that can be either easily guessed or end up further exposing you if a website is ever compromised.”

 

3. Passwordless authentication is picking up steam

“World Password Day is a timely reminder of how important it is for enterprises to recognize the importance of secure sign-in credentials and its shifting landscape. An estimated 80% of hacking-related breaches can be attributed to lost or stolen credentials, which leads to millions of dollars in financial damages and creates a snowball effect of stolen data. Protecting passwords has become an industry-wide concern that continues to remain an ongoing problem. It is therefore imperative for organizations to prioritize password security by adding in multiple authentication layers, limit employee privileges and consider passwordless alternatives.

Two-factor authentication has been one popular way companies are addressing password and login security. While it’s a helpful and beneficial security step to incorporate, it isn’t without its flaws. Building in an additional security feature does thwart more attacks, but two-factor is also becoming more and more vulnerable to advanced hacking techniques that can steal phone numbers or redirect codes to access accounts.

Passphrases that are much lengthier and more effective than passwords are also another option security teams have been implementing. These 20 – 30-character phrases drastically limit brute force attacks, but also have similar pitfalls to passwords. A more interesting future might be a world without passwords or passphrases altogether. Passwordless authentication is picking up steam, with over 150M people currently using passwordless login methods each month. The passwordless option doesn’t necessarily solve this entire security problem, but it would force attackers to extract and replay tokens, a much more difficult process than using brute force for weak passwords, password reuse, phishing, or credential stuffing.

Adopting a Zero Trust security model can further help limit password exposure in on-premises or cloud environments, while also ensuring that proper network access is strictly granted to authorized individuals. It’s intended to use several factors to authenticate users (to establish trust) other than a username, password, and overall user profile. And should a compromise occur to user credentials, it’s mostly limited to an isolated, single-threaded incident and won’t compromise the network’s system, data, or applications.”

 

4. Use MFA paired with contextual access policies

“The dark web contains over 15 billion stolen account logins, including credentials, usernames, and password pairs, a massive amount of data that is mostly being offered for free. With most breaches resulting in the distribution of duplicate files that are shared amongst cybercriminals, it makes it incredibly difficult to track down stolen data and find the source of stolen information. While hackers have access to a substantial amount of data that can lead to unauthorized organizational access and data breaches, multi-factor authentication is an effective means of thwarting attacks while bolstering and improving password protections.

Multi-factor authentication requires knowledge (password or pin), possession (one-time code, ID card, or digital key), and inherents (fingerprint or scan) to verify user identity. While digital codes or tokens to a device can potentially end up in the wrong hands, adding another blanket of security like inherents alleviates the risk should a smartphone fall into the wrong hands. Another approach is to use multi-factor authentication paired with contextual access policies (e.g. device, geography) in a step-up fashion. This uses a tiered security system, allowing access to different types of resources that then require additional, stronger verification methods for more sensitive information. By utilizing multi-factor and step-up authentication, enterprises are strategically prepared to protect the high-priority organizational data and user passwords across platforms.”

 

5. Password brute-forcing is exploited in the wild

 

“When we look at API security, we can see that the most common attack vector exploited in the wild is different forms of password brute-forcing, such as credential stuffing and dictionary attacks. If you expose a password-based login endpoint to the internet, it’s just a matter of time until someone will try to attack. From the attacker’s perspective, the exploitation of these endpoints is simple, generic, and easy to scale while the reward is high.

From a defender’s perspective, protecting your authentication mechanism from password-based attacks (such as credential stuffing) should always involve three aspects: 1. enforce your users to use strong passwords (according to industry standards); 2. implement rate-limiting on the server-side to block attacks; 3. use multi-factor authentication.

  • Inon Shkedy, Security Researcher, Traceable

 

6. Use passphrases that are far harder to crack

“Our recently released State of Email Security Report found increases in all attack types over the past year, as the pandemic and switch to remote work created new vulnerabilities that cybercriminals are working hard to exploit. In response, organizations should build greater cyber resilience by implementing updated security controls and prioritizing regular cybersecurity awareness training to protect employees – and the business – from attack.

Effective training is engaging, interesting, frequent and, among other things, encouraging users to regularly update their passwords. Users should always use passphrases, as these are far harder to crack, make use of IT-approved password managers, and ensure they aren’t using the same password across multiple platforms. Having unique passwords across personal and company platforms will ensure that if a person’s social media profile is phished, for example, they aren’t at risk of having a corporate account compromised. Effective cybersecurity awareness training should be the bedrock of any modern organization’s cybersecurity efforts.”

  • Duane Nicol, cybersecurity expert, Mimecast

 

7. Hackers are interested in passwords that open doors to privileged access

“Passwords are the entry gates to voluminous data especially from the accounts that have privileged access. Weak and reused credentials are at the centre of such breaches. In April, shocking news came to light based on the findings of a massive 100GB data set called COMB21. As per this data, 3.2 billion passwords were leaked out of which 1.5 million email addresses were exposed mainly belonging to government departments. 625,505 passwords alone belonged to the U.S. government. This monstrous number of compromised credentials is why people now more than ever need to be sensitized about password etiquette. This is why since 2013, the first Thursday of May every year is observed as ‘World Password Day.’ What many fail to realize is that it’s not just random passwords that hackers are interested in. Their primary targets are passwords that open doors to privileged access. The overall security of an enterprise or a government agency reflects on how the network credentials are managed. Comprehensive authentication and access control should always be the number one priority.

The reasons for passwords getting compromised are – firstly, employees want to reuse their existing or old passwords. Secondly, if authentication mechanisms are overly burdensome, employees resort to risky or poor password practices. Finally, reusing the same password for different accounts make it easier for hackers to gain access to multiple accounts in one go. To prevent this, one needs data with industry-leading endpoint security solutions that include comprehensive encryption, strong authentication, and leading-edge malware prevention.

Though education and training are important in raising employee awareness, putting effective tools in place – like a password manager and multi-factor authentication – ensure that best practices are default and embedded into the company’s security culture.”

  • Gurpreet Singh, Managing Director, Arrow PC Network (Dell Technologies Titanium Partner)

 

8. Standalone password protection is insufficient

“World Password Day is an opportunity to take a step back and examine what the future holds for secure logins. To date, over 600 million passwords have been exposed through data breaches. Needless to say, standalone password protection is an insufficient and ineffective method of protecting organizations and sensitive information. Weak, insufficient, and stolen credentials are common causes for breaches and hacks that often result in millions of dollars in damages and data loss. It’s more important than ever before for companies to rely on two-factor authentication that also incorporates additional login tokens or one-time codes to fully obtain access. This adds in another layer of security to help address the password problem but still hasn’t solved it entirely as hackers can still gain access through authentication code interception techniques and SIM swapping.

While two-factor is a step up from traditional password safety, modern-day problems require modern solutions, and passwordless authentication may hold the future key to more effectively securing credentials. Passwordless authentication is an intriguing and hopefully superior option in the near future, but it’s not a standalone panacea for security concerns. Coupling in additional measures such as Zero Trust, crowdsourced cybersecurity and proactive threat detection will keep enterprises secure and information safely protected in the future.”

  • Ashish Gupta, CEO & President, Bugcrowd

 

9.  Implementing 2FA is critical

“World Password Day is an excellent time for individuals and businesses to reflect on their current password practices and ensure they are building the safest habits to protect themselves and their company from cybercriminals. Many are under the assumption that if they are taking the steps to create unique passwords for each platform and application, they are secure. But it’s not enough.

The number of headline-grabbing breaches that have taken place over the last year highlight the critical need for safeguards across the entire company network. While there are a few different ways to protect login credentials beyond a simple username and password, one of the most popular and effective options is two-factor authentication (2FA). Implementing 2FA provides an extra layer of security by making users confirm their identity, most often via a unique code sent to the user’s phone, email address, or through an authenticator app, after entering their username and password. It’s getting easier for cybercriminals to breach even the most complex password, which is why implementing 2FA is critical.

Email is a common point of attack because it often contains sensitive and valuable communications. Organizations should also consider implementing an email security solution that conducts a security audit to analyze its admins, users, mailboxes, and rules for vulnerabilities such as outdated passwords so they can be resolved before a breach happens. Organizations should use World Password Day to evaluate their internal Password Policies and send reminders to employees and customers alike about the importance of good password hygiene.”

  • Dave Wagner, CEO, Zix

 

10. Password policies need to advance

“Optiv strongly recommends all enterprises implement a password complexity of 12 characters, including uppercase, lowercase, numbers, and symbols. As technology is ever-advancing, the password policies we put in place also need to advance to keep up with would-be attackers. With most things, password cracking will continue to be a ‘cat and mouse’ game that can only be resolved through a fully implemented password policy, including password blacklisting, rotation, multi-factor authentication, complexity requirements, and security awareness training.”

  • Brett Little, Senior Consultant (Threat Management), Optiv

 

11. 77% of people reuse passwords

“World Password Day is a great reminder to take inventory of our passwords, including where they are stored, whether you reuse them for multiple accounts and their complexity. Tessian’s recent report found that 77% of people reuse passwords, and 21% use predictable cues like their favorite football team, their pet’s name, or birthdays when crafting passwords. The problem? These personal details are likely to be found on people’s social media channels, making it easy for hackers to scan publicly available information to try to crack passwords or even answer security questions.

To prevent account takeover and business email compromise, CISOs and their teams should help educate employees about their social media footprint, cybersecurity best practices, and how to spot impersonation attacks. They should also reinforce the need for strong passwords that don’t include names or names of pets, birth dates, location, or other information that’s easy to find online. Even better, use a password manager like 1Password to randomly generate impossible-to-hack passwords. And while it can be tempting to reuse passwords that are easy to remember, never reuse or duplicate any passwords for personal or professional accounts. A bad actor could guess just one password and gain access to multiple accounts.”

  • Tim Sadler, CEO and Co-founder, Tessian

 

12. Best passwords are unique and long

“World Password Day is the perfect day for a reminder that best passwords are unique, long, include letter case, numbers, and characters like “#”, “$”, “&”. Additionally, here are two key steps to improve your password security:

  1. Password manager: Remembering passwords for different sites is difficult. A password manager can generate long, complex passwords and store them on a site-by-site basis. But you must protect it with a master password.
  2. Check for leaked passwords: With data thefts, breaches over the years, it is possible that your password is leaked. Searchable databases like Avast HackCheckcan help to find if any password is compromised. If you find your password lost, change it immediately. If you don’t use the website, close the account entirely.”
  • Christopher Budd, Senior Global Threat Communications Manager, Avast

 

13. Attackers will always look to new tactics and techniques

“At the enterprise, most organizations have implemented password policies and expirations along with federated identity technology such as Active Directory as well as 2FA. While this has protected organizations to a degree, attackers will always look to new tactics and techniques to achieve their goals as evidenced by this year’s HAFNIUM and SUNBURST attacks. World Password Day is a good time to ensure systems running identity and federation services are hardened, and your endpoint detection systems are able to spot the tactics, techniques and procedures associated with attacks on credentials and the single sign-on infrastructure.”

  • Anthony Di Bello, VP, Strategic Development, OpenText

 

14. Change passwords frequently

“With millions of people working from home for more than a year now, organizations have adopted various password policies across the globe. While password policies are being implemented, cybercriminals continue to find ways around them, and data breaches are still on the rise. World Password Day 2021 is an opportunity for organizations not only to enhance awareness but also to strengthen their password policies as a step towards preventing cyberattacks. Use strong, unique passwords along with multi-factor authentication, change passwords frequently, avoid using similar passwords for all accounts are useful tips that help prevent data from being stolen or exploited.”

  • Huzefa Motiwala, Director, Systems Engineering (India & SAARC), Palo Alto Networks

 

15. Move to passwordless authentication

“While it is important to highlight the weaknesses of passwords, any message that you can make passwords “strong” is egregiously misleading. Given today’s enhanced threat landscape, relying on passwords alone is imprudent, even reckless. Adding an extra factor, such as a token, to enable multifactor authentication (MFA) is a minimum good practice, but the top practice is to move to passwordless authentication. In short, the only strong password is no password.”

  • Ant Allan, Vice President Analyst, Gartner

 

16. Be discreet while setting passwords

“It is always advisable to be careful and discreet while setting your password and not share it with anyone.

Things to keep in mind while creating/managing passwords:

  • Make sure that no one is watching while you enter your password
  • Always select “never” when your Internet browser asks for your permission to remember your passwords
  • Passwords should always be long and complex – which cannot be hacked easily
  • Regularly change passwords – Between three to six months interval

The best way to create a strong password is to think of a word or sentence and replace some letters with numbers or special characters.

It is raining cats and dogs! becomes 1tsrAIn1NGcts&DGS!

It is our responsibility to keep our information/data safe and secure.” 

 

17. Bulletproof your passwords

“Protecting our privacy begins with strengthening our password. Password day is designated to remind us of the importance of this first line of defense against ransomware, spyware, and other bad actors. It acts as a key to our digital identity; the more unique the key, the lesser the chances of a stranger being able to unlock it. Hence, in today’s digital world where technology is ruling the world, creating a strong password is a must and it should be our foremost priority for everyone, especially when the hacker is becoming more advanced.

We have to understand that how vulnerable a poor password can leave us, especially when our lives and all our data has moved online. There are many things we should keep in mind while creating a password: bulletproof your passwords, enable two or multi-factor authentication, keep it impersonal, layer them up and last but not least use a password manager.

I believe multi-layered data protection strategies – such as those employing strong passwords combined with thorough backup practices – will help to ensure, our data, and our organization remains protected in the event of a simple accident, cyber-attack, or any other disaster.”

  • Prashanth GJ, CEO at TechnoBind

 

18. Password with your pet’s name isn’t going to protect you

“In today’s digital-everything world, so much of our lives are available online and accessible across multiple devices. We have grown accustomed to sharing our personal information online, sometimes without giving thought to the potential consequences.

“Personally identifiable information has become an attractive target for cybercriminals and unfortunately a password with your pet’s name isn’t going to protect you. Weak or predictable passwords are akin to having a door with no hinges, a thief can get through. Far too many scams focused on tricking individuals to disclose their passwords have occurred in India and the negative consequences as a result cannot be understated.

“Rather than relying on passwords alone, add additional layers of security. Implement authentication methods [multi-factor authentication (MFA)], such as the use of biometrics or one-time passcodes [OTPs]. This is simple and prevents identity theft and other cybercrimes.”

  • Kartik Shahani, Country Manager, Tenable India

Fine-tune Your Passwords this World Password Day 2021

World Password Day 2021

Passwords – the most common and effective authentication method to securely log in systems and keep data secure – have now become a potential security risk, making our data vulnerable more than ever before. Despite security awareness and training, poor password hygiene like reusing passwords easy-to-guess/weak passwords pose a serious threat to both corporate data and users’ personally identifiable information (PII). According to a recent survey by Visual Objects, 63% of employees in the U.S. have reused their passwords on work accounts and devices. It was found that employees are 6.5 times more likely to reuse work passwords.

By Rudra Srinivas, Senior Feature Writer, CISO MAG

Another survey revealed that 15% of Britishers use their pet’s name as passwords to most of their online accounts. Apart from their pet’s names, most of the Brits often use easy-to-guess passwords including family members’ names (14%), a significant date (13%), or their favorite sports team (6%). In response, the U.K. National Cyber Security Centre (NCSC) issued a warning to its citizens, urging them to use stronger and unique passwords.

To encourage users to practice strict password habits, security expert Mark Burnett, in 2005, launched a book, Perfect Passwords: Selection, Protection, Authentication. The book also floated around the idea of dedicating a day each year to change passwords.  Later in 2013, Intel took the initiative and declared the first Thursday in May to be observed as World Password Day. But the current scenario is different. With users having multiple email accounts, social media accounts, passwords must be changed more often rather than waiting for a year.

One of the most common challenges faced by users today is managing multiple account passwords. Hence, more often, they end up reusing passwords, which only validates the magnitude of the problem. A relatively safe way to remember passwords is using a password manager that stores all passwords in an encrypted database. Some of the password managers also offer features such as a strong password generator, which fulfills all security requirements.

2FA and Future of Authentication

Poor password habits have resulted in several data breaches and cyberattacks. With users opting for easy-to-remember passwords rather than focusing on security, organizations are looking for alternate authentication procedures.

Although two-factor authentication (2FA) protects against phishing and social engineering, authentication solutions need to go beyond because even 2FA is vulnerable and can be bypassed if implemented poorly. Proofpoint revealed critical flaws in 2FA implementation in cloud environments, which could allow attackers to bypass 2FA and access cloud applications that use Microsoft 365.

Brute-forcing 2FA codes, real-time phishing, and channel hijacking are some of the common flaws used by attackers to evade security.

Recently, Microsoft’s GitHub announced that it is going to stop accepting account passwords to authenticate Git operations from August 13, 2021, and move to a token-based authentication method. Search engine giant Google, in its Chrome OS version 88 update, recently introduced web authentication (WebAuthn), or passwordless authentication, which allows users to sign in to websites using their fingerprint. With this, users can sign into websites, including Google, Dropbox, GitHub, Okta, Twitter, and Microsoft, by simply scanning their fingerprint that is registered to unlock their Chromebook.

Expert’s Take in The Issue

Talking to CISO MAG on the importance of passwords, Ritesh Chopra, Director Sales and Field Marketing, India & SAARC Countries, NortonLifeLock, said, “The remote working trend and the heightened dependence on digital platforms brought about by the ongoing pandemic have contributed to an increase in cyberattacks, with cybercrime rising through unsecured networks, websites, and emails. We often save financial data, personally identifiable information (PII), contacts, credit, and debit card information on our personal devices.”

“All this data is at risk online. One of the ways we can secure it is by using password managers that allow us to keep multiple and more complicated passwords. It is good that consumers today recognize the need for cyber safety and that it can start with something as simple as having stronger passwords,” Chopra added.

Ritesh Chopra also suggested a few tips to make passwords more secure. These include:

  • Make your password a sentence. A strong password is a sentence that is at least 12 characters long. Use quirky sentences that are not commonly used. Some sites even allow you to use spaces in passwords.
  • Have a separate password for each account; it helps to thwart cybercriminals. At a minimum, separate your work and personal accounts, and make sure that your most important accounts have the strongest passwords.
  • People often tend to forget passwords. So, keep a list of your passwords and store it in a safe, secure place away from your computer. Alternatively, you use a service like a password manager to keep track of your passwords. Every account you log into, and every device that you use has so much information that could harm us if it falls into the wrong hands.

 About the Author

 

Rudra Srinivas is a Senior Feature Writer and part of the editorial team at CISO MAG. He writes news and feature stories on cybersecurity trends.       

Read More from the author.

Most Americans Lack Confidence in Government’s Cybersecurity Preparedness

Top Cybersecurity Jobs in 2021

Cyberattacks can have a long-lasting impact on organizations in many ways and on many levels. Consumers lose trust in the companies’ security standards if they fail to protect their personal information. Citizens may even lose confidence in government institutions due to poor cybersecurity practices.

The survey “Americans on Cybersecurity,” from cybersecurity firm PC Matic, revealed that 57% of Americans surveyed don’t believe that the U.S. state and the federal government is prepared to defend itself from evolving cyberthreats. The survey is based on the responses from nearly 1,400 Americans across 50 states.

Key Findings

  • Around 61% of Americans believe the federal government should be doing more to protect American citizens from cyberthreats.
  • 46% of IT professionals lack confidence in the U.S. Government’s ability to defend itself against a cyberattack.
  • Just over 40% of Americans would like to see the U.S. Congress pass cybersecurity-related legislation.
  • Only a quarter of Americans believe that the U.S. Congress needs to allocate more funding to preventing cybersecurity attacks.
  • Nearly 85% of respondents are worried about losing access to their personal computers and other devices.
  • Over 90.01% are worried about identity thefts.
  • Around 88% are worried about personal privacy attacks.

“Cybersecurity should be a regular part of the conversation, especially as we become more reliant on internet-connected devices. The average American household has over 10 internet-connected devices. Businesses have more, especially when you factor in the likelihood of employees to connect the personal devices, they travel with to a work network. Americans must have confidence in their government’s ability to defend itself against cyber threats. Cybersecurity is the most imminent threat to our national security, and considering the findings of this survey, it’s important systems be reworked to provide better security and to instill more confidence from the public,” said Rob Cheng, CEO, and Founder of PC Matic.