Home Blog Page 90

Babuk Ransomware Group Changes Course; Moves from Encryption to Extortion

BlackMatter Group, Volvo Cars ransomware attack

The infamous Babuk ransomware group has announced that it is shutting down its operation. The group allegedly posted the blackout message on its data leak site, which was later taken down. The Russian-speaking gang has been very active since the beginning of 2021 and has targeted various organizations in sectors like healthcare, government agencies, manufacturing, and logistics. Recently, the Babuk ransomware operators infiltrated D.C. Police Department’s networks and threatened to leak confidential information like names of suspected gang member informants and data from crime briefings.

Series of “Hello World” Announcements

In their initial post titled Hello World 2, the Babuk ransomware gang claimed that they had achieved their goal and decided to stop their operations.

“We are happy to inform you that PD was our last goal, only now they determine whether the leak will be or not, in any case regardless of the outcome of events with PD, the Babuk project will be closed, its source codes will be made publicly available, we will do something like Open Source RaaS, everyone can make their product based on our product and finish with the rest of the RaaS,” Babuk’s message read.

However, the operators removed this message from their site shortly and posted another message titled Hello World 3. The operators stated that they will run an extortion model attacking method, without encrypting networks, demanding a ransom for information compromised.

“Babuk changes direction, we no longer encrypt information on networks, we will get to you and take your data, we will notify you about it if you do not get in touch, we make an announcement,” the message added.

Short Time, Plenty of Victims!

Babuk ransomware affected plenty of victims within a small time frame. The operators behind the group leveraged double extortion techniques to harass victims and demand high ransom payments ranging from $60,000 to $85,000. Babuk infected several organizations, including Houston Rockets, Phone House Spain, Metropolitan Police Department, and Telethon: biotech.

Given their success in a short period, it’s unlikely for Babuk operators to close shop so easily. The shutdown of its encryption operation is only to misguide law enforcement and make an even stronger comeback.

Cybersecurity Considerations with the Increasing Uses of Small Unmanned Aircraft Systems (sUAS) or Drones

Cybersecurity and Small Unmanned Aircraft Systems(sUAS) or Drones

The effort to produce this information resource results from a collaborative effort between the Bergen County Technical Schools (high school), through the advisor Andrea Buccino, and a cybersecurity expert mentor. High school senior members of this learning partnership are provided with an interactive learning experience. They gain an increase and knowledge in a particular area of study while under the topical guidance of a mentor. In this example, the high school senior is pursuing coursework in Aerospace Engineering, and this was combined with the focus of cybersecurity to expand the students’ cross-discipline knowledge. This collaborative work was done virtually, given the current pandemic situation.

By Matthew Kucharek, Senior, Aerospace Engineering Program, Bergen County Technical High School; and Stan Mierzwa, M.S., CISSP, Director and Lecturer, Kean University Center for Cybersecurity

Introduction

The use of Small Unmanned Aircraft Systems (sUAS), otherwise less formally known as drones, is expanding in use cases throughout work and commercial environments and personal and recreational purposes. One industry and critical infrastructure area expanding its use into drones include emergency services.  The Emergency Services Sector is considered by the United States Cybersecurity and Infrastructure Security Agency (CISA) as one of the sixteen critical infrastructure sectors (Cybersecurity & Infrastructure Security Agency, 2021).  Within this sector are housed fire stations, local town public works departments, police departments, and medical service providers. The use of technology drones is beginning to complement the emergency services sector’s response efforts.  With this, a greater demand to ensure the use of the devices remains free from cyber threats.

In a show of support of protecting drones, the National Science Foundation has funded the creation of a drone cybersecurity curriculum (Targeted News Service, 2020).  Creating such a curriculum will help train students on cybersecurity concerns and ways of assessing such risks. The need is warranted, given the U.S. Federal Aviation Administration (FAA) expects the growth of registered drones to reach 3.8 million by 2022 (Federal Aviation Administration. 2019; Tezza, Andujar, 2019).

This short article will outline the general growth and increasing use cases of drones, provide background to understand the blocks or components of a drone solution, and finally, detail awareness of the cybersecurity concerns to be aware of.

Background on Growing Uses of Small Unmanned Aircraft Systems (sUAS)

Concerning the use of drones, some common commercial areas include inspection of industrial facilities, real estate and aerial photography, agriculture, state and local government, including emergency management services (Tezza, Andujar, 2019).  In addition, growing research is being done in such sectors as product delivery; consider the research and work going on at Amazon via their PrimeAir that permits for 30-minute deliveries in certain areas using unmanned aerial vehicles or drones.  Other emergency services, including medical services, are investigating the prototypes of drones to provide logistic services and hospital deliveries for remote or rural areas (Nenni, M., et al. 2020). The use cases for drones seem endless and time will tell how far the technology may venture.

Understanding the sUAS Components

Actual Physical Drone

There are several Components in a drone. Some of the components are used to fly the drones, while others are tasked to collect data. Two essential components are used in flying the drone:  A small computer, and this is used to collect information from the satellite and the user. The second is the GPS chip. The GPS chip, which is connected to the computer, collects info from the satellite for the drone to know where it and it relays the information back to the user. Two components used in a drone to collect data are the camera and the microphone. If the malicious aggressor manages to get in, they can tap into and see/collect the data (Craiger, 2020).

Controller (Smartphone or Tablet) Application

Most drones use a software application on the device used to control the drone. These applications are installed on a smartphone or tablet, and then the smartphone or tablet is connected to another device that has controllers to fly the drone. As the people move the controllers to fly it, it sends a message to the application and the drone.

Connectivity/Communication

The way information is sent to and from the drone is with the use of satellites. With significant or big open areas where it is hard to connect to the Wi-Fi, drones use one of 4 civilian bands to relay information. These networks can be unsecured and unencrypted (Craiger, 2020).

Cybersecurity Concerns with sUAS Devices

Like any computing device, there are several different cybersecurity concerns with sUAS or drone devices. A malicious aggressor can attack drones via diverse methods to gain access to the drone or the information that the drone is collecting or that the drone contains. To bring attention to these cybersecurity concerns, several different vectors are outlined below.

Connectivity

Before delineating the different attacks on drones, there needs to be an explanation of why some of these attacks can happen in the first place. The biggest reason is that drones are connected, for the most part, to a network, whether a private or public connection.  Citizens who have drones can only use one of 4 civilian bands. The problem with them is that they are not encrypted, not authenticated, and have weak signals. These three problems help hackers get into the drone to either fly it or acquire data that the drone is collecting (Craiger, 2020).

Denial of Service (DOS)

With very similar components to computing devices, several different ways, and approaches would pertain to Denial of Service against drones.  In essence, a drone is essentially a flying computer.  As such, this means that they are subjected to similar attacks as your desktop computer. One such attack is Denial of Service (DOS).  In one scenario, if the drone operator is connected to an unsecured Wi-Fi, the malicious aggressor can connect to a proxy system and attack the drone. The attacker may have an opportunity to run as an administrator-level account through a proxy, such as “root” under Linux or “administrator” under Windows. Once the malicious aggressor gets into the drone, an attacker can use several destructive common Linux commands to cause damage to the drone or the user.

De-Authentication Attacks

Another attack against a drone is called a de-authentication attack. De-authentication can be compared to the act of hanging up or disconnecting from a telephone.  In one method, this attack uses the drone‘s Media Access Control (MAC) address. The malicious aggressor uses a modified drone with another computer from a stationary position and scans to certain MAC addresses. Once it identifies a MAC address, the address is compared to known MAC identifications to find out the vendor, such as DJI or Parrot, two very popular drone manufacturers (Craiger, 2020). If the malicious aggressor decided they want to target the drone, they send a hang-up package and disable the drone from the user.  In one example of sending a de-authentication or disconnection attack to a flying drone, a young 13-year-old person demonstrated such an attack at a cybersecurity and drone conference hosted in South Africa.  This demo was valuable in bringing awareness to such attacks with approaches that are not extensively sophisticated (VOA News, 2019).

GPS Spoofing

Two other possible attacks against drones include Global Positioning System (GPS) spoofing and GPS jamming. GPS spoofing can include the process when a malicious aggressor creates a stronger signal that overrides the weak signal from the satellite GPS and targets the drone (Craiger, J. P. 2020). As a result, the drone does not know where it is and has a false GEO location.  In such a case, the drone could fly aimlessly or even fall and crash to the ground. GPS jamming is when the malicious aggressor can create a stronger signal on the same communication frequency that is being used by the civilian GPS satellite; then the drone is unable to receive that GPS location information.

Suggestions to Guard Against Cyberthreats with Drones

Updates

Ensure that the devices (drones and applications) are kept up to date with security and other related software and firmware patches (Threat Report, 2019). Oftentimes these updates are designed by drone companies to fix any bugs or security gaps with the drone. To stay abreast of the updates, similar to how this is approached with other devices such as computer operating systems and software applications, timely patching to protect systems against vulnerabilities in drones needs to be undertaken. Routine checks with the drone manufacturer to determine the most up-to-date firmware and software are suggested.

Secure connection

Refrain from connecting to insecure Wi-Fi with the controller or drone device. Insecure Wi-Fi can lead malicious aggressors to infiltrate your drone quicker and easier. Connect only to a secured Wi-Fi if possible.  Consider using a Virtual Private Network (VPN) if connecting to Wi-Fi to ensure the communications cannot be hacked via such techniques as Man-In-The-Middle attacks.

Passwords

If passwords are utilized for connection or login to the drones or applications, use Multi-Factor Authentication (MFA) or Two-Factor Authentication (2FA), where possible (Hinkle, S. 2020). Use a password where it is possible since it adds an extra layer of protection to your drone. As is the case with other network-connected devices, refrain from using identical passwords in other services and systems to minimize the ease of a hacker gaining access.

Conclusion

Drones are essentially flying computers. This means they are assessable to cyber-attacks. From Denial-of-Service attacks to GPS Spoofing, drones have vulnerabilities that pose threats to itself or to the user. In this short article, the author’s aim was to bring attention and cybersecurity situational awareness to both drone professionals and hobby enthusiasts regarding cyber threats to drones.  A focus was placed on the components and operations of the drones.  It should also be noted that drone-related information can be housed within such repositories of drone manufacturer websites, where user accounts, address information and other personal-related knowledge may reside and need to be protected from threat actors.

The use of drones is expected to grow in various professional and personal interests, and the malicious potential of these platforms is inevitable and can no longer be avoided (Edwards, B. 2021). There is the possibility that drones could become as commonplace as the cellphone, which was not the norm not too long ago (Seqrite, 2019).

An unabridged version of this article appears in the May issue of CISO MAG.


References

Craiger, J. P. (2020). NYCTE Center An Introduction to Small Unmanned Aerial Systems (sUAS) Cybersecurity. As retrieved from: https://www.youtube.com/watch?v=vE3TDmsYrvg

Craiger, P., Kessler, G. & Rose, W. (2018). uUAS: Cybersecurity Threats, Vulnerabilities, and Exploits. National Training Aircraft Symposium (NTAS).

Cybersecurity & Infrastructure Security Agency. (2021). Critical Infrastructure Sectors. Retrieved from: https://www.cisa.gov/critical-infrastructure-sectors

Edwards, B. (2021). Cybersecurity and Drones: A Threat From Above. Forbes. Retrieved from: https://www.forbes.com/sites/forbestechcouncil/2021/02/25/cybersecurity-and-dronesa-threat-from-above/?sh=66e4e4627b0d

Federal Aviation Administration. (2019). Unmanned Aircraft Systems Forecast. Retrieved from: https://www.faa.gov/data_research/aviation/aerospace_forecasts/media/Unmanned_Aircraft_Systems.pdf

Hinkle, S. (2020). Drones and Cybersecurity – Smart Eye Explains How Cybersecurity Extends to Drone Operators. Retrieved from: https://mavicmaniacs.com/drones-and-cybersecurity

Nenni, M., Di Pasquale, V., Miranda, S. & Riemma, S. (2020). Development of a Drone-Supported Emergency Medical Service. International Journal of Technology. 11(4).

Seqrite. (2019). Consequences of cyberattacks on UAVs: The cybersecurity threats drones face and how to mitigate them. Seqrite Blog. Retrieved from: https://www.seqrite.com/blog/cybersecurity-threats-drones/

Targeted News Service. (2020). National Science Foundation Funds Development of First-of-Its-Kind Drone Cybersecurity Curriculum at Embry-Riddle. Washington, DC.

Tezza, D. & Andujar, M. (2019). The State-of-the-Art of Human-Drone Interaction: A Survey. IEEE Access.

Threat Report, (2019). Drone Technology a Rising Threat to Cybersecurity. As retrieved from: https://www.youtube.com/watch?v=h_GwkFOZHKI

VOA News. (2019). 13-Year-Old ‘CyberNinja’ Hacks Drone to Show Cyber Threat. As retrieved from: https://www.bing.com/videos/search?q=cybersecurity+threats+to+drones&&view=detail&mid=D444D976FAE65D92E304D444D976FAE65D92E304&&FORM=VRDGAR&ru=%2Fvideos%2Fsearch%3Fq%3Dcybersecurity%2Bthreats%2Bto%2Bdrones%26FORM%3DHDRSC4


About the Authors

Matthew KucharekMatthew Kucharek is a Senior at Bergen County Technical High School in New Jersey and currently partaking in a cybersecurity mentoring program collaborating with the Kean University Center for Cybersecurity. Kucharek possesses a black belt in Tae Kwon Do martial arts.

 

Stanley Mierzwa is the Director, Center for Cybersecurity at Kean UniversityStanley Mierzwa is the Director, Center for Cybersecurity at Kean University in the U.S. He lectures at Kean University on Cybersecurity Risk Management and Foundations in Cybercrime.  He is a peer reviewer for the Online Journal of Public Health Informatics journal, a member of the FBI Infragard, IEEE, ISC(2), and a board member of the global pharmacy education non-profit, Vennue Foundation. Mierzwa received his MS in Management of Information Systems at the New Jersey Institute of Technology and his BS in Electrical Engineering at Fairleigh Dickinson University.  Mierzwa is also a Certified Information Systems Security Professional (CISSP), a member of the FBI Infragard, and currently pursuing a Ph.D. Information Technology with a specialization in cybersecurity.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

The Last 11 Email Accounts You’ll Ever Need

Bait attacks, Email Attacks

When I was a kid, I watched a lot of terrible action movies. Maybe it was just growing up in the 1980s, and there were a lot of bad ones to watch. My dad was a Green Beret, and he blew my mind when he let me know that the hero of whatever movie I was watching hadn’t reloaded his gun in half an hour. From then on, I found myself developing an OCD habit of counting the number of shots and guestimating how many rounds might be left. I now judge movies based on how accurate they were.

By George Finney, CISO, Professor, Author, Keynote Speaker, Startup Advisor

So, now that I have a compulsion to count things, I count how many times I stir my coffee. I’ll count the number of cars in traffic or how many times I’ve checked social media today. It’s only natural, then, that I started counting how many email accounts I was using and wondered how many email addresses are enough.

Before I dive into emails, I should first say that I think counting is just another way of thinking about curiosity. And I think curiosity is one of the key traits that set us up for success in cybersecurity.

According to a survey by the Data and Marketing Association, an average person has 2.5 email accounts. The same survey suggests that 51% of people have had the same email address for more than 10 years.

I’m pretty invested in my email addresses; I feel like they’re part of my identity. But there’s another, equally valid perspective: email accounts are disposable. I wondered if I could do an experiment and see how many email addresses I need and whether I could organize them in a way that made me more secure and possibly more organized along the way.

It turns out, you should have 11 email accounts.

Why 11 email accounts?

It used to be that I was worried about my main email account being compromised. A hacker could use the same email and password to get into my other banking or shopping accounts. Most online services use your email address as your username, which exposes half of your credentials. Since most don’t enforce a periodic forced password change, this is even more of a problem.

Hopefully, your email or banking account uses two-factor authentication (2FA), but I’m still concerned about clever social engineering being able to bypass our defenses.

The list below separates the types of email accounts I think you’ll need based on some categories. I’ve grouped the categories by what they’re used for: banking or social media, for example, based on the level of risk if they’re exposed — and the frequency of changes that happen with that type of use. For example, work email addresses may change every few years while you may want a recovery email account to remain the same forever.

With smartphones, it doesn’t matter how many email accounts you have, as they’re all right there on the same device. So having multiple accounts isn’t inconvenient like it might have been 10 years ago. We know that different organizations you do business with will share, sell, or leak information about you, so dividing up your email accounts will show you when this happens more clearly.

You must be already using different passwords for your different email accounts. If not, sign up for a password vault and use random passwords for each account. I don’t know most of my passwords at this point.

Here are the last 11 email accounts you’ll ever need:

Work: This will change over time as you change jobs. I recommend keeping work and personal as separate as possible for lots of reasons. Any personal mail, important tax documents, or pictures you send will get lost after you change jobs. Each company will have different work email policies, so it’s best to keep this separate.

Personal: If any of your email addresses will stay the same forever, it will be this one. You will give this email out to friends and relatives who you want to stay in touch with, or who you might only hear from once in a while. To keep from having to change this email address frequently, it’s important to keep it separate from the others on the list.

Recovery Account: Lots of services today want you to provide them with an email account that can be used to recover your username and password. For this reason, I think this is one of the most important accounts you’ll set up. And because so many services want a recovery account, this will be one of the first accounts you’ll set up.

Social: Facebook, TikTok, and Snapchat aren’t your friends. We know that through breaches or by direct relationships, emails are exposed without us necessarily knowing about it. And it’s part of their business model to sell your data. Skimming these for your contact info, you can be targeted for well-crafted phishing messages. It’s good to separate these from your other accounts, like shopping, banking, or work.

Newsletters: This will be your miscellaneous category. This category by itself will fill up any inbox with junk that you won’t regularly read, like the weekly sale email from your favorite store. Newsletters mailing lists are also frequently sold from one company to another, so the likelihood of this category turning into a source of junk is high–so keep it separate.

Banking: Separating these into their own email will help you recognize when a phishing message from your bank. If it didn’t go to the right account, then it’s phishing and you’ll recognize that quickly.

Insurance and Taxes: Car, medical, home, taxes, etc.–many of these services collect your SSN or other highly sensitive financial information. You could combine this with your banking or shopping email account, but I like creating a firewall between.

Shopping/Bills: Since these sites collect your credit card, Paypal, Venmo, banking, or other payment info, you’ll want an address to keep them secure. I like to keep these separate from my banking sites so that I can more easily spot scams that try to collect my banking info.

Job Searching: I’ll talk more about this later, but I’ve found that job search sites are the absolute worst about keeping your email secure. It seems like every recruiter on the planet has my email address.

School: You’ll probably get one of these for life if you attend college. These are great for keeping in touch with former classmates. But administrative issues with these accounts can lead to accounts being full of spam and phishing messages.

Burner Email: I’ve listed this one separately from newsletters because, by definition, you may want to burn this address for some reason and get a new one. I’m thinking in particular about dating sites, but there could be several other uses for this category.

All these separate email accounts will most likely be stored on your mobile phone so that you can check them. This means the security of your device is the weak link in this chain. Setting up PINs, fingerprints, or facial recognition is good. Setting up your phone’s lost or stolen recovery app is also important. I’d also recommend downloading a mobile antivirus solution.

Is mobile phone antivirus important? More and more users report receiving fraudulent or phishing text messages. Texting fraud is on the rise, and it seems like we’re more likely to give our phone numbers out than email addresses. It’s harder to have multiple phone numbers, although you can use Google Voice or an app to create your own burner numbers.

Conclusion

Going back to my obsession with counting for a moment…phishing is up 600% just in the first few months following the COVID-19 pandemic. More than ever we need to be able to protect ourselves from social engineering. Having 11 different email accounts will help compartmentalize phishing attacks, but we also need to know how to leverage the habits of skepticism and vigilance when those phishing messages get through.

As the GI Joes are fond of saying, “Knowing is half the battle.” Our users know the red flags for phishing that we’ve taught them, but there’s still a gap in recognizing them, particularly in the afternoon. Just knowing this can help us better prepare — we can schedule more meetings in the afternoon so that we spend less time exposed to email. When we do read email, we can use the “slow down and frown” technique I’ve developed, which some psychology studies suggest can increase our vigilance by up to 20%.

My obsession with counting is what led me to look at my simulated phishing data differently. There wasn’t a view into the time of day in any of the tools I used, so I had to learn a bit about data science and Big Data to be able to visualize the problem in a new way. Counting, for me, is just another expression of curiosity about the world around me. And ultimately, I think it will be curiosity that will help us to solve our cybersecurity challenges.

This story first appeared in the October 2020 issue of CISO MAG.


About the Author

George FinneyGeorge Finney is a CISO, author, speaker, professor, and consultant who believes that people are the key to solving our cybersecurity challenges. He has worked in cybersecurity for nearly 20 years and has helped startups, global telecommunications firms, and nonprofits improve their security posture. As a part of his passion for education, Finney has taught cybersecurity at Southern Methodist University and is the author of Well Aware: Master the Nine Cybersecurity Habits to Protect Your Future. He has been recognized by Security Magazine as one of their top cybersecurity leaders in 2018 and is a part of the Texas CISO Council.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Data Protection Sustainability: A Self-compensating System

data protection

How substantial is cybersecurity compliance to engendering reliability in data protection processes? While we may defer answering this question, the importance placed on cybersecurity for ensuring compliance with internal or external regulatory requirements is evident from increased privacy and data protection regulations. In these exciting times of the COVID-19 pandemic, the myriad of cybersecurity threats the organization face has become more distributed and heightened. There is a greater need now than ever before for reassurance that the organization is secure and in compliance with internal and external requirements. The organization’s cybersecurity posture, partners, and third parties, including suppliers, are critical parts of the jigsaw that make up the regulatory environment.

By Favour Femi-Oyewole, Group Chief Information Security Officer, Access Bank Plc

Penalties that may arise from data breaches have the potential to affect the bottom line significantly, and businesses have become more aware of this; and to ensure its visibility and mitigation, privacy and cybersecurity risk items are increasingly accorded board-level priority. Two key things that stand out in the cyber front interactions are understanding that cyberthreats cannot be approached in isolation and that parties both within and outside the organization have a part to play in contributing to its overall cybersecurity posture.

Compliance gives insight into how well an entity can follow a set of rules, orders, or requests. Typically, for larger enterprises, risks related to compliance are often integrated into and managed as part of the Enterprise Risk portfolio. While being managed holistically from this enterprise point of view, security practitioners generally accept that being compliant does not necessarily translate to being secure for cybersecurity processes. Hence, it is not so shocking that even large organizations that had previously assessed their environment as being compliant to internal policies, subscribed standards, and external regulatory requirements find themselves announcing data breaches left undiscovered for extended periods. Such is the transient state of compliance; however, this need not be. An organization can continually meet the standards for data privacy and security applicable to them in their jurisdictions if a self-compensating methodology is employed.

An enterprise compliance program built on a model that encourages compliance as a tick-the-box exercise is on the pathway to produce an effect that derails the strategic thrust and hampers the chosen cybersecurity strategy’s tactical operations. Though it is easy to lose grasp of the fit, the internal gearings that move the cybersecurity system need to have, by integrating essential building blocks and designing an internal system that maintains a dynamic state awareness (includes tracking relative deviations and adversary activities) and compensates for them intuitively, this can be checked. By going beyond a tick-the-box exercise, organizations can better integrate security and compliance into the fabric of the organization’s processes. Granted, this is easier said than done. Building security and compliance into the organization’s fabric require a multi-dimensional approach that incorporates people, processes, and technology, and these three factors are referred to as the cornerstone of organizational efficiency.

The Human Element

To produce seamless collaboration, the human angle plays an important role. While the human element is known to be the main driver for the other elements, it also sculpts the form for the environment in which these actions are carried out. The program’s effectiveness depends on behavior patterns in the organization and what is perceived as normal behavior in relation to the cybersecurity practice. Specifically, the organization should understand its external requirements, internal environment, and its peculiarities, including process dissonance. These considerations include:

• The business environment in which it operates and the pace at which business is conducted.

• How the organization is structured and how these constituent groups, divisions, and departments take decisions.

• The incentives that are likely to help its stakeholders comply with policies and regulations.

• The obstacles that would prevent them from complying.

Another consideration is to center on the principal actors in the process and have feedback on how well stakeholders within the organization understand the policies and standards they are expected to follow. Due to limited knowledge on the part of a staff, non-compliance could occur. The same applies to an omission in a critical step that could unknowingly reduce the posture level, thereby creating a false sense of security. Another key behavior to look out for is the member’s disposition to complying with these rules. This can range from: could the disposition be as a result of positive attitudes built over time? Is it because there is an incentive that makes compliance attractive or perhaps because there is a monitoring program in place, and this serves as a deterrent? These serve as input in understanding the area of concern that relates to disposition. The two previous points provide an inroads into understanding the current extent to which internal stakeholders can comply with rules. Where external regulations are concerned, there is often a zero-risk tolerance set by management, and attaining this level will depend on these factors and an understanding of the base extent of reasonably attainable compliance.

By designing the program to consider these factors, a better understanding of how to engineer the human element of the program to deliver greater reliability values towards protecting the organization and its data can be attained, enabled through tight integration between security and compliance tracking. The human element provides part of the input that initiates and sustains the dynamic state awareness and compensatory mechanism for the security and compliance program. Examples of such capabilities are evident in the analyst’s ability to review events that have either been prioritized by analytic security controls or through threat hunting efforts to detect stealthy actions, perhaps, as a result of a successful targeted social engineering attack, to cut off the malignancy before it festers. Senior management has a part to play in supporting these functions and the level of support for the Chief Information Security Officer and its programs would greatly increase the effectiveness levels.

Technological Controls Maturity

Technical controls are implemented to reduce the identified inherent risk by bolstering the defenses or increasing the protection available. The risks could be due to a vulnerability or inadequacy identified within a system, a process, or the attainment of an objective. It suffices to say that automated security protection can be achieved through the proper deployment of security controls. After deployment, the usefulness lifetime countdown begins, and throughout its lifetime, maintenance will be needed. During this period, it is important to measure control effectiveness on an ongoing basis. These actions will help improve the proactive and reactive ability of the system to, for example, mitigate attacks or detect anomalies. It is working in tandem with the human analyst, who may be supported by artificial intelligence or machine learning-based systems, a much greater fidelity of proactive stance and reactive efficiency can be achieved. These tie in towards increasing the reliability of the system to self-compensate, self-heal, and deliver effective security.

While these are being implemented, it is necessary to be aware that such capability is rarely attained in an instant; hence, it takes time and effort. In the buildup or revamp process, effective prioritization is important, and there are resources available for security architects and engineers to leverage while strengthening the security stack. Basic security hygiene should be taken care of at the initial stages, and the top five, ten, and twenty controls can be implemented progressively to strengthen posture. These controls are deployed with an aim, and how well these objectives are met should be tracked as part of a compliance program. This should take cognizance of drifts from identified measures and provide for needed re-adjustments that may be needed from time to time in response to observed events or threat intelligence.

To read the full story,download the October 2020 issue of CISO MAG. Subscribe to CISO MAG

About the Author

Favour Femi-Oyewole is a Doctoral Student at Covenant University, Ota, Ogun State, Nigeria. She is the Group Chief Information Security Officer in the Access Bank Plc overseeing the Information & Cyber Security of the Group office and the Subsidiaries. Favour also holds several certifications in the IT & Information Security and Cybersecurity field. She is a Cisco Certified Security Professional, Checkpoint Security Administrator, 1st female COBIT 5 Assessor certified in Africa, Certified Chief Information Security Officer, Certified ISO 27001 Lead Implementer, and Lead Auditor. She is also the first female in Africa to be a Blockchain Certified Professional.

Favour is a Certified ISO 27001:2013 Lead Implementer Trainer. She is an Alumni of both Harvard Kennedy School (HKS, Harvard University, and Massachusetts Institute of Technology (MIT), USA. She is a member of the Cybercrime Advisory Council in Nigeria. Favour emerged as the 1st woman in the world to win the Global Certified CISO (C|CISO) of the Year 2017 from the EC-Council in the U.S.

Favour is also an active member of the Global Certified Chief Information Security Officer (CCISO) Advisory Board & Scheme Committee of the EC-Council in the U.S. She is a certified Data Privacy Solutions Engineer (CDPSE), a certification recently awarded to her in June 2020 by ISACA.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

G7 Nations Sign Declaration to Improve Online Safety

NCSC and Microsoft Cyber Accelerator program

G7 nations have signed a new ministerial declaration to enhance online safety and security worldwide. The digital and technology ministers from the U.K., Canada, Germany, France, Italy, the U.S., and the EU have agreed on a range of recommendations to tackle the rising cyberattacks across the world. The declaration outlines the agenda of G7 nations towards improving online safety, developing a collaborative approach to data security, and promoting an uninterrupted flow of information across the nations.

“Our collective recovery from COVID-19 must be rooted in a desire to build back a better, more productive, and resilient global economy, with digital technology at its heart. This should support open societies in the digital and data-driven age and be guided by our shared democratic values of open and competitive markets, strong safeguards including for human rights and fundamental freedoms, and international cooperation which drives benefits for our citizens, economies, and global well-being,” the declaration stated.

The new initiative will be delivered via six critical interventions which address:

  • Promoting secure, resilient, and diverse digital, telecoms, and ICT infrastructure supply chains
  • A framework for G7 collaboration on digital technical standards
  • A G7 roadmap for cooperation on data free flow with trust
  • G7 Internet Safety Principles
  • Deepening cooperation on digital competition
  • A framework for G7 collaboration on electronic transferable records

“We have decided to place the needs of open, democratic societies at the center of the technology debate and to work together towards a trusted, values-driven digital ecosystem. We believe that such ecosystems must enhance prosperity in a way that is sustainable, inclusive, and human-centric. We have also affirmed our opposition to measures which may undermine these democratic values, such as government-imposed Internet shutdowns and network restrictions,” the declaration added.

Security Incident in a Med-Tech Company Derails Treatment of Cancer Patients in U.S.

Only 44% of Health Care Providers Meet National Standards on Cybersecurity, OpenEMR vulnerabilities

Recent research titled “Moving Forward: Setting the Direction” highlighted that healthcare supply chain security is one of the lowest-ranked areas for the National Institute of Standards and Technology’s Cybersecurity Framework (NIST CSF) conformance. According to the research, only 44% of hospitals and health care providers are following the security protocols outlined by the NIST framework. And the healthcare industry does not seem to have learned much from this report. Yet another med-tech company – Elekta – has been allegedly hit by a cyberattack that has delayed scores of cancer patients from getting radiology treatment in the U.S.

The Attack

The cyberattack first grabbed headlines in the first week of April when a division of 12 News reported that two healthcare providers had to reschedule their cancer patients’ treatment appointments due to an “outage.” The outage was due to a cyberattack on their common service provider – Elekta – which hosted the hospital networks’ radiation oncology cloud service.

The Aftermath

The immediate effect of the attack was that appointments of at least 50 patients at Southcoast Health’s cancer centers in Fall River and Fairhaven and an unknown number of patients at Rhode Island Hospital and the Lifespan Cancer Institute in East Greenwich had to be canceled and rescheduled.  On learning about the cyberattack, the company took immediate measures to contain it and reported it saying that only a smaller “subset of U.S-based customers are affected.” However, the HIPAA Journal seems to suggest otherwise. According to their report, “around 170 customers in the U.S. that use its first-generation cloud system experienced service disruptions to one or more of their products.”

It further added that Connecticut-based Yale New Haven Health, who was also Elekta’s customer, was forced to take its radiation equipment offline until the issues were resolved.

The Remediation Steps

Elekta provides cloud-based software that is used to control linear accelerators for radiation treatments of cancer patients. However, the system service provider still works on the first-generation cloud-based storage system which eventually led to the said security compromise. Citing this issue, Elekta immediately initiated the process of migrating its customers to its new Microsoft Azure cloud and has been working around the clock to complete the process.

Closing Notes

Elekta did not give details about the exact nature of the attack and thus it is still unclear as to what type of malware was used in the cyberattack. However, looking at the recent history of ransomware attacks being precisely targeted at the healthcare sector, this could well be the job of a   ransomware gang.

It is not only time to pay attention to the cybersecurity of your hospitals and clinics but also the entire healthcare ecosystem, including third-party service providers.

Related News:

How Cyberattacks Cause Severe Hazards to Health Care Industry

The Cancer in the Health Care System

Ransomware Task Force Issues Framework to Combat Ransomware Attacks

ransomware, fonix, fonix ransomware, Cybereason Partners with Intel for Hardware-Enabled Ransomware Prevention, Kronos

Combating rising ransomware attacks has become a challenge for organizations globally. Several ransomware groups are targeting companies by encrypting their systems, paralyzing operations, and threatening to leak the stolen data on darknet forums. With a common goal to thwart the evolving cyberthreats, a global coalition of law enforcement agencies and technology organizations came together to form a comprehensive framework to combat ransomware attacks.

The Institute for Security and Technology (IST) formed the Ransomware Task Force (RTF) in January 2019, which is a coalition of more than 60 industry experts from government agencies, IT companies, cybersecurity vendors, financial services companies, civil society, and academic institutions. Recently, the RTF released a comprehensive framework Combating Ransomware – A Comprehensive Framework for Action that provides standardized guidance and actionable solutions to mitigate the growing ransomware threats across all verticals.

The framework consists of four goals: Detect, Disrupt, Prepare, and Respond.

Image Courtesy: IST
  • Deter ransomware attacks through a nationally and internationally coordinated, prioritized, and resourced, comprehensive strategy
  • Disrupt the ransomware business model and decrease criminal profits
  • Help organizations better prepare for ransomware attacks
  • Also, aid organizations respond to ransomware attacks more effectively

Ransomware – An International Cybercrime

The RTF identifies ransomware as an international cybercrime that continues to affect both the public and private sectors. The task force included representatives from various sectors— large and small, public, and private, including health care, financial, cybersecurity, technology, government, law enforcement, and civil society. The RTF is leveraging the expertise from all the industry experts to develop multifaceted solutions and build a comprehensive strategy to fight against ransomware.

“The cost of ransom paid by organizations has nearly doubled in the past year and is creating new risks, many that go far beyond monetary damage. In the past 12 months alone, we’ve seen ransomware attacks delay lifesaving medical treatment, destabilize critical infrastructure, and threaten our national security. We felt an urgent need to bring together world-class experts across all of the relevant sectors to break down silos and create a framework that government and industry can pursue to disrupt the ransomware business model, mitigate the impact of these attacks, and ensure the continued faith of the general public in its institutions,” said Philip Reiner, the CEO of IST and the Executive Director of the RTF.

What the NCSC Says…

Commenting on the RTF initiation, the National Cyber Security Centre (NCSC) stated that the objective of the RTF is to develop a robust plan to tackle the global ransomware threats via deterring and disrupting threat actors while helping ensure organizations are equipped to prepare and respond.

“The disruption it causes means that ransomware is no longer a cybersecurity issue for organizations; as the Task Force’s report notes, it has become a national security risk that has the potential to impact public safety, particularly when hospitals and other critical national infrastructure are targeted. And since there is little an organization can do once the ransomware hits, preparation is essential,” the NCSC said.

Supply Chain Security – A CISO Point of View

Supply chain

Recent news about the SolarWinds compromise and Trojan horse introduced in their software raises a question: How can organizations ensure the security of their supply chain?

By Kevin Reed, CISO at Acronis

I am not alone in this and there were a few takes on how one could guarantee the security of their suppliers. I think you cannot. Or, more specifically, it’s prohibitively expensive and unless you are a government organization, you cannot afford this. Here, I should highlight that there are reports of the U.S. Treasury (https://www.reuters.com/article/us-global-cyber-usa-idUSKBN28Y09L) and Department of Homeland Security (https://apnews.com/article/solarwinds-hack-email-top-dhs-officials-8bcd4a4eb3be1f8f98244766bae70395) being affected by the SolarWinds attack among others, so, apparently, even they failed at solving this problem.

Current approaches to supply chain security mostly boil down to two methods: questionnaires and third-party scans and evaluations.

In my experience, filling in generic questionnaires is mostly a waste of time for multiple reasons. First, your supplier may not even know the answers to some of the questions. For example, according to IBM (https://www.ibm.com/security/digital-assets/cost-data-breach-report/#/), it takes 280 days on average to identify a data breach. This means, a request to “indicate data breaches took place over the last 12 months” may make no sense at all because the organization is still to discover them.

Second, your questionnaires may not expose the full picture: indeed, setting the right question, one needs to know half of the answer. I am not saying, your suppliers will intentionally hide facts from you or openly lie in their answers, however, some may exaggerate a little, and others can exaggerate more. For instance, there was a supplier who claimed to have “robust and comprehensive security policies in place”, which turned out to be a page or two in the employee’s handbook. Although it’s still better than nothing, it’s quite a stretch from “comprehensive.” Worst of all, often, you cannot validate some of the answers, you simply have to believe what was claimed.

Another approach is to outsource risk evaluation to a third party in a form of technical vulnerability scans or compliance-like reports like SOC2. SOC2 report quality is largely dependent on the auditor’s professionalism and wiliness to present independent and honest opinions. We know that auditors are supposed to do so, but we also know about the role of Arthur Andersen in the Enron and WorldCom scandals. Of course, I am not saying every auditor is dishonest, however, bear in mind, that unless you are not paying for the audit, you are the customer. Also, experience tells me that the quality of reports done by larger auditors is often worse than those of smaller companies specializing in cybersecurity and cyber risk management.

Are third-party scans the solution?

Third-party security scans are slightly better, but not by much. Again, from my experience, they are vulnerable to what’s called the “Streetlight effect” – they are looking for what is easy to find and not for what matters. For example, TLS misconfigurations for public servers are easily testable: as a result, such reports are often filled in with warnings about how dangerous it is to have 3DES cipher enabled on a Web site. While 3DES is a legacy algorithm, there are no practical attacks on the algorithm itself and the SWEET32 is not really a threat for a typical Web site. At the same time, such third-party scans are completely blind to having a 20-year-old, not updated Linux box on the internal network and could be compromised with an off-the-shelf exploit by a script kiddie. They are blind to SQL injections or other kinds of attacks in custom Web applications, which is relatively easy to find with a semi-manual analysis, but not easy to scan for.

As a result, a company may focus on looking good on those scan reports instead of the underlying security issues. In a way, this is similar to a “compliance-driven security” phenomenon, where organizations are so focused on filling in the checkboxes, they miss the real security issues. An example would be Target’s data breach: Target was PCI DSS certified, yet cybercriminals managed to hijack its payment terminals at some 1800 stores and steal at least 40 million credit cards. I believe we will see companies with excellent third-party ratings successfully hacked.

So, are we doomed? How can you reliably validate the security of your supply chain?

Here are a few things to look at. There’s no guarantee, but they give me and my team more confidence than anything else.

Before you even start evaluating your vendor for security, consider the impact of their compromise on your company. You might not have the capacity to do a full risk assessment, but at least consider a worst-case scenario. What impact will there be, if the vendor’s systems were encrypted in a ransomware attack? How will you be affected if their source code was compromised and a Trojan horse was planted in their software? What will happen, if the vendor’s databases were compromised, data stolen, and/or sold? The answers will be different for a cloud provider where only your encrypted backups are stored versus a company you outsource your ERP or HR system to. Estimate your risk based on what this particular vendor does for you. Consider specific scenarios that are relevant to your relationships and work on them.

Next, you turn to the vendor. The first thing to look for is whether the company has dedicated and competent people focused on security. Do they have a security manager or maybe even a CISO? Not every company needs a CISO, small and medium businesses often don’t have an appointed CISO, and that’s fine. A CISO could be outsourced, that sometimes is fine, too. The important thing is, someone is responsible for the security and can respond to your questions if needed. Just don’t bother them with filling in questionnaires.

Now, when you know your risks and who is responsible for eliminating them on the vendors’ side, ask them, how are they doing it. This could be an email or a 30-minute meeting with a pre-arranged list of adjusted questions, or both. What works for me is email, followed by any clarifications over a call, but it all depends on you and your vendor’s working style, time zones, level of relationship, and risk.

By this point, you should have a basic risk assessment and risk mitigation plan. Now, you need to validate it.

Request for evidence of what’s being claimed. I find pentest reports useful, not even because of their content, but sometimes due to the very fact that the company does them. Watch for the pentest scope and ideally request a report for two consecutive tests to verify that the company is acting on the findings.

If they are your software supplier, ask for an independent source code review. Those are expensive and not every company can afford them, but if they do, it’s a good sign. Also, not every company is willing to share the full report for various reasons, often citing NDA due to the source code snippets included in the report. A lot of legal formalities could be involved, so sometimes an executive summary might be enough. Again, consider your level of exposure and the risks you are taking. Another important sign for a software supplier or a cloud provider is if they are running a bug bounty program. Bug bounty programs are great because they can act as an external validation of the software quality. However, equally important is how fast the company is able to fix the findings. Prioritization, say, based on CVSS score or other established methodology is a sign of a mature vulnerability management process. Public bug bounty programs are a sign of the company’s confidence in their ability to properly handle the reports, but private bug bounty programs have their advantages too, and they are perfectly acceptable especially at the early stages.

Will scanning help?

For cloud providers, it may make sense to scan their networks but first, taking a few things into account: chances are you will not find anything Shodan (a search engine for internet-connected devices) did not find already, so maybe a Shodan search will suffice. Alternatively, you can ask them for a report of their own scans.

Scanning is not hard, setting context is harder. Also, the very existence of the report is an indication they are managing their attack surface. Yet, if you are still willing to scan yourself, obtain a permit from them, and ask them to segregate customer addresses from their own, otherwise you will be scanning something irrelevant.

For non-cloud companies, it could be impractical to scan, because much of their applications will already not be on their networks, but in the networks of the aforementioned cloud, SaaS, and PaaS providers. However, what is useful for almost any kind of company is to request their patching reports: again, the very existence of such a report is a sign they are managing vulnerabilities and have software in place to look at it. Willingness to provide such a report shows their confidence in their patching practices. Ideally, the report should be produced by an independent entity, but this is hard to obtain in real-life situations.

There, now you have your risks identified in relation to this particular vendor, you understand the treatment of those risks and you have evidence that the necessary actions are actually taking place, you will be able to take a picture of the situation and will know how to proceed from there.

Conclusion

How often should you repeat such an exercise? The common approach is to do this annually. However, it can depend on the risk and potential impact. For a low-impact vendor, you may do it less often, and for one, you depend on significantly, you may need to develop a permanent evaluation process. The tricky question here is if the vendor will be willing to invest their time in this. Does the cash flow justify their involvement? You may discover that your leverage against large SaaS and IaaS providers is literally none so likely they will have a “take it or leave it” attitude. Luckily, these vendors can invest more in securing their networks and systems, and overall, they are not necessarily the weakest link.

A few takeaways:

  • Adjust your approach to risk you are exposed to by using a particular vendor. Most have little potential impact, focus on those that do.
  • Outsourcing risk evaluation to a third party may not work. They don’t know your risks and really important vulnerabilities are hard to uncover in an automated fashion.
  • Aim for consistency and watch for risk that changes over time — this is a marathon, not a sprint.

About the Author

kevin reedKevin Reed is the CISO at Acronis, a top global cyber-protection company. Reed has over 20 years of in cybersecurity and has supervised the security strategies of leading world banks, the 10 billion NASDAQ traded search engine, and more.

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Darkside Ransomware Gang Adopts New Extortion Technique by Targeting Stock Traders

Australian Securities and Investment Commission Hit by a Cyberattack

Cybercriminals often try innovative methods in their attacking techniques to increase their success rate and evade security detection (obfuscation). From new malware variants to different hacking methods, threat actors constantly change their approaches to encrypt victims’ data and pressurize them into paying the ransom. To prove their power, the operators behind the Darkside ransomware group announced that they are leveraging new extortion tactics by targeting companies that are listed stock markets like NASDAQ.

In a notification posted on a dark web portal, the Darkside operators stated they are coaxing certain crooked stockbrokers to use insider information of their corporate targets so that they can short-sell a victim company’s stock before they disclose the breach or leak any data. The operators believe that the impact of posting a traded company’s name on its website will cause the victim company’s stock price to fall and help insider traders make profits.

Besides, the announcement also represents a new method to indirectly threaten and pressurize the targeted companies into paying the ransom.

“Now our team and partners encrypt many companies that are trading on NASDAQ and other stock exchanges. If the company refuses to pay, we are ready to provide information before the publication, so that it would be possible to earn at the reduced price of shares. Write to us in ‘Contact Us’ and we will provide you with detailed information,” Darkside operators said.

Twice the Benefits

Several industry experts opined that Darkside actors could benefit in two ways with this new extortion technique. The ransomware group could demand a huge amount from any trader in exchange for insider information. If traders are not approached, threat actors can still monetize the situation by threatening the victim company by leaking sensitive corporate data online — a common scenario where most organizations avoid paying ransom demands.

“While other ransomware families previously discussed how to leverage the effect of a publicly disclosed cyberattack on the stock market, they have never made it their official attack vector. DarkSide becomes the first ransomware variant to make it formal,” said Dmitry Smilyanets, threat intel analyst at Recorded Future.

Impact of Cyberattacks on Company’s Stock

Cyberattacks impact an organization in many ways, including loss of trust from customers, clients, damage of brand image, and of course a shrink in market value. However, the impact on stock values will not cause long-term damage to the company’s market value. Certain security experts opine that these kinds of extortion techniques have little chance to work out.

HCL Technologies and IBM Join Forces to Build Modern SOC Platform

Partnership

On April 27, 2021, two tech giants – HCl Technologies and IBM – announced a collaboration, which will help streamline threat management services through a unified modern security operation center (SOC) platform. It will also help security teams with a unified security platform that consists of tools and processes across the threat lifecycle.

The Collaboration

As per the announcement, HCL’s Cybersecurity Fusion Centers will now be designed in a manner that it can smoothly integrate and take advantage of IBM’s Cloud Pak for Security. This collaboration adds to HCL and IBM’s recent alliance for helping organizations with digital transformation.

HCL’s Cybersecurity Fusion Centers

HCL’s Cybersecurity Fusion Centers (CSFC) provides threat management services to clients around the world through six global security operations and response facilities based across Europe, Asia, and North America. The CSFC integrates multi-domain security teams, processes, and cutting-edge analytics enabling organizations to detect threats faster and resolve incidents efficiently. Apart from monitoring, alerting, resolving and remediation of security incidents, HCL’s CSFC also helps organizations to comply with local data sovereignty regulations like GDPR.

IBM’s Cloud Pak for Security

Cloud Pak for Security is an open, containerized software platform that allows companies to quickly integrate a wide range of security data, tools, and clouds for deeper insights into threats across hybrid and multi-cloud environments. The increased visibility and flexible growth capabilities make it a hot choice amongst its customer bases. IBM’s Cloud Pak for Security will serve as the foundation to connect security tools, data, and workflows with HCL customers.

What the Collaborators Said

Maninder Singh, Corporate Vice President, Cyber Security Services at HCL Technologies said,

Enterprises operating in today’s fast-moving digital world need a cybersecurity strategy capable of tackling increasingly sophisticated threats. Collaboration is key in the cybersecurity industry to build and implement the solutions to stay one step ahead. This collaboration enables us to combine the threat detection and response technologies with the development of technological processes and the experience of our professionals across all areas of cybersecurity.

Adding to this, Justin Youngblood, Vice President, IBM Security said, “Many companies today are struggling with the complexity of security operations amidst cloud adoption and fragmented IT infrastructure, which can hamper their ability to discover and respond to threats. Modern security demands an open platform that leverages AI and automation to help security operations teams connect disparate tools, provide insights and orchestrate response across hybrid cloud environments.”

Related News:

Rushing to the Cloud to Support Remote Workers Poses New Security Risks: IBM Study