Home Blog Page 96

India’s Data Breach Saga Continues; Country’s Second Largest Stockbroker, Upstox, Hit!

Upstox data breach

The dust of the MobiKwik data breach was just beginning to settle as another data breach takes center stage. This time it is India’s second-largest stockbroker, Upstox. Out of the total user base of nearly three million users, reportedly two and a half million were affected in the alleged data breach. Indian security researcher Rajshekhar Rajaharia (who also disclosed the MobiKwik data breach) brought it to light when he tweeted that the notorious threat group “ShinyHunters,” was behind the leak.

Related News:

Security Researchers Call Out MobiKwik for KYC Data Leak

Details on the Data Breach

Rajaharia attached morphed screenshots of various leaked KYC (know your customer) details, which Upstox had collected while opening the user accounts on their stockbroking platform. As per the information disclosed, the following details were leaked:

  • Full Names
  • Email
  • Date of Birth
  • PAN (Permanent Account Number)
  • KYC details including copies of passport, canceled cheques, signature pics, etc.

According to Rajaharia, Upstox’s data leak reason is similar to the MobiKwik incident. In both cases, the company’s Amazon Web Service (AWS) key was compromised, which led to illicit access to its database.

Upstox CEO Addresses the Issue

On the other hand, Upstox has neither confirmed nor denied the data breach. However, the company’s co-founder and CEO, Ravi Kumar announced on its website that “enhanced security measures” have been taken for Upstox user accounts “in light of recent events.” Kumar added that Upstox has roped in a global cybersecurity firm to increase the manifolds in its security system.

While Kumar did not confirm the claims, he did suggest that, as per claims from security experts, “some contact data and KYC details may have been compromised from third-party data-warehouse systems.” Also, further assuring his users, he exclaimed that none of the platform users’ funds and securities were compromised and are safe and protected.

Upstox has already reported the incident to the relevant authorities and is taking all preventive measures, including real-time monitoring and restricted access to the allegedly impacted database. Further throwing caution to the wind, Upstox has also initiated a secure password reset to all its users via OTP.

Aditya Narang, Co-founder & MD, SafeHouse Technologies, told CISO MAG, “It is quite unfortunate to witness data breaches time and again. We have seen how cybercrimes and attacks are on the rise for the last couple of months. Data breaches at Facebook, Linkedin, Mobikwik, and now Upstox! It is time that the users accept that hackers out there are innovating methods to hack them and leave their data vulnerable on the dark web. While organizations are trying to find solutions to protect their stakeholders, these stakeholders also need a real-time security for their digital identity especially in today’s times.”

Related News:

Alleged Facebook Data Leak Affects 6 Mn Indian Users

“Security leaders must communicate consistently and with transparency to build trust”

security leaders, CISO communication strategies

In turbulent times organizations need to focus on business priorities and restructure processes and teams. How should security leaders set their priorities and how do they tackle the security incidents at scale – even as security budgets remain flat? And what are the communication strategies that CISOs need to adopt while communicating with Board members and other stakeholders?

Caroline Wong, Chief Strategy Officer at Cobalt.io, answers all these questions in an interview with Brian Pereira, Editor-in-Chief, CISO MAG.

Cobalt is a cybersecurity company with a focus on Pentesting as a Service.

Caroline was featured as an Influencer in the Women in IT Security issue of SC Magazine, named as one of the Top 10 Women in Cloud by CloudNOW, and received a Women of Influence Award in the One to Watch category from the Executive Women’s Forum. She authored the popular textbook Security Metrics, A Beginner’s Guide.

Caroline is a strategic leader with strong communications skills, cybersecurity knowledge, and experience delivering global programs. Her close and practical information security knowledge stems from broad experience as a Cigital consultant, a Symantec product manager, and day-to-day leadership roles at eBay and Zynga.

Edited excerpts from the interview follow:

In times of austerity, organizations have to make do with lean teams. What should be the priorities for security leaders when their teams are reduced?

Leaders should always ensure that the basics are covered. At a bare minimum, this includes incident response planning (logging and monitoring) and security awareness (make sure folks know what to do and who to contact if they suspect anything potentially malicious).

CISOs are used to constant change, and often try to cover as many gaps as possible. While this can work in the short term, I believe it’s more important to prioritize, allow the right balls to drop, and communicate transparently. A security leader must effectively communicate what is covered and what is not for any given business situation. The more consistent a leader can be in their communications, the more trust they can build with executives and stakeholders.

How do teams scale up and innovate without additional resources or budgets?

First, it’s critical to understand the way your company manages budgets, so you can accurately evaluate your options. For example, maybe your hiring plans have to be put on hold, but you still have discretionary OPEX to spend. Or vice versa. Having this type of specific knowledge will help you determine the best balance of technology, people, and process — whether you choose to build these in-house or outsource them to a third-party.

We observe an increase in security incidents during the pandemic. In an approach to handling these incidents, to what extent can automation help in scaling? What role do humans play here?

Automation can play a large role in scaling, but it’s important to remember that some types of activity may be a better fit for automation than others. Tasks that are well-defined and repeatable are good candidates for automation, whereas those that rely on judgment, creativity, and opinion are not. Remember that scaling can happen not only via automation but also by leveraging SaaS services and products. If you can get the same work done using a SaaS solution (rather than building teams and technology internally), it might also help you to scale cost-effectively.

How does a security leader communicate the importance of growth and scale top-down? What are the communication strategies to adopt for the Boardroom discussions?

Transparency and trust are key. The more a security leader understands the strategic goals of the business, the more they can effectively communicate them to their teams and help folks to understand how their day-to-day security work helps to impact the top-level organizational objectives.

Every organization goes through “ebbs and flows,” and it benefits security leaders and their teams to stay aware of what type of phase an organization is going through at any given point in time. During an “ebb,” security teams may be less likely to get new budget allocations or an increase in resources. In this case, scrappy and frugal behavior might be the best fit. During a “flow,” however, especially in times of rapid growth, there may be an opportunity to consider simple and efficient solutions that will scale easily without complex overhead, even if (on the face of it) it may not appear to be the most cost-effective solution.

I always recommend to security leaders to consider not only the upfront cost of any initiative but also the ongoing cost to maintain and operate security activity going forward.

Similarly, it benefits security leaders to really understand what the board cares most about (is the company making progress towards its strategic goals?) and to frame security programs within this context.

What approaches work best to make the organization more “security aware”?

Security awareness is not something that is one and done. Security requirements are constantly changing so training should be a continuous process. Because of this, having 2-3 min on-demand, “learn when you need it” training can be very useful to enable team members to learn about security concepts “on-demand” and at the moment when they need it. Additionally, security leaders should develop relationships with leaders at similar companies. The more that someone, like a CISO, can reach out to his network, he can bring those anecdotes to his business conversations and say, “Well, so and so at this company is doing this, and we should be aware of that and consider if we should follow suit or not.”

About the Interviewer

Brian PereiraBrian Pereira is the Editor-in-Chief of CISO MAG. He has been writing on business technology concepts for the past 26 years and has achieved basic certifications in cloud computing (IBM) and cybersecurity (EC-Council).

 

U.K. NCSC Urges Brits to Avoid Pet’s Names as Passwords

common password of 2021,Password Protection, password spray attacks, Microsoft accounts passwords

One cannot ignore the importance of a strong password while improving security online. Using hard-to-guess passwords or passphrases provide optimum security to your devices and online accounts. However, despite several security awareness programs, users fail to form strong passwords, leaving their online security at risk.

Recently, the National Cyber Security Centre (NCSC) of the U.K. issued a warning to its citizens to use stronger and unique passwords, after a survey revealed that 15% of Britishers use their pet’s name as passwords to most of their online accounts. Apart from their pet’s names, most of the Brits often use easy-to-guess passwords including family members’ names (14%), a significant date (13%), or their favorite sports team (6%).

Besides, 6% of the users admitted using “password” as all or part of their password. This makes it easy for threat actors to break into millions of accounts by using simple trial-and-error password guessing techniques. The NCSC recommended users to have passwords comprising at least three different words. 

The Bright Side

While some users are repeating the same mistakes over and over, nearly 27% of the participants stated that they now have four more new password-protected accounts compared to last year, with 6% reported to have added more than 10 new accounts last year.

NCSC Director for Policy and Communications, Nicola Hudson, said “We may be a nation of animal lovers, but using your pet’s name as a password could make you an easy target for callous cybercriminals. I would urge everybody to visit cyberaware.gov.uk and follow our guidance on setting secure passwords which recommend using passwords made up of three random words. You can even use our Cyber Action Plan tool to generate tailored, free of charge advice to improve your security against online attacks.”

Boosting Password Security

The NCSC’s Cyber Aware campaign advised users and organizations to follow certain password practices to enhance online security. These include:

  • Use a strong and separate password for your email. If a hacker gets into your email, they could reset your other account passwords and access information you have saved about yourself or your business. Your email password should be strong and different from all your other passwords.
  • Create strong passwords using three random words – when you use different passwords for your important accounts, it can be hard to remember them all.
  • Do not use words that can be guessed (like your pet’s name). You can include numbers and symbols if you need to. For example, “RedPantsTree4!”
  • Saving your passwords in your web browser will help you manage them and can protect you against certain cybercrimes, such as those invoked through fake websites.

Improving U.K.’s Cyber Resilience

In her first virtual speech as the new CEO of the NCSC, Lindy Cameron warned about the cyberthreats against organizations and users in the U.K. and explained how they are aimed to improve the country’s cyber resilience.

“The cybersecurity landscape we see now in the U.K. reflects huge progress and relative strength – but it is not a position we can be complacent about. Cybersecurity is still not taken as seriously as it should be, and simply is not embedded in U.K. boardrooms. The pace of change is no excuse – in boardrooms, digital literacy is as non-negotiable as financial or legal literacy. Our CEOs should be as close to their CISO as their Finance Director and General Counsel,” Cameron said. “And we want to help them to develop this knowledge, as we’re all too aware that cyber skills are not yet fundamental to our education – even though these are life skills like wiring a plug or changing a tire as well as skills for the future digital economy.”

Related Stories:

Another Israeli Cyber Sabotage Attempt on Iran’s Natanz Nuclear Facility?

Israel and Iran, Iran cyberattack, cyber war

On April 11, 2021, Iran’s Natanz nuclear power plant reportedly faced yet another “sabotage” attempt when a fire caused by an explosion severely damaged the main uranium enrichment facility. The Atomic Energy Organization of Iran’s (AEOI) spokesman, Behrouz Kamalvandi, initially reported that the incident was a result of an “accident” in the nuclear facility’s electricity distribution network. However, Ali Akbar Salehi, AEOI’s chief, stated that the incident was not an accident but a full-blown attack, which he termed as an act of “nuclear terrorism.”

The attack on the Natanz nuclear facility came just a day after the “National Nuclear Technology Day,” on which Iran began injecting uranium hexafluoride gas into the advanced IR-6 and IR-5 centrifuges. The attack after the activation of advanced centrifuges concerned many. However, officials monitoring the situation said that there were no injuries and neither any nuclear contamination was reported.

Not the First Time

A similar attack was reported first in 2010, which is popularly known as the Stuxnet attack. Stuxnet was a computer worm designed specifically by the U.S. and Israel to target the industrial control systems (ICS) made by Siemens, which were also used by Iran in its Natanz nuclear power plant. The worm reportedly damaged more than 1000 centrifuges of the Natanz facility.

A second such attempt was made a decade later. On July 2, 2020, a fire in the main hall of the Natanz nuclear facility destroyed its roof. Although no affirmation of the exact impact was publicly given by Iran, a report from Al-Jarida quoted an unnamed senior source confirming Israel’s involvement in the cyberattack.

However, the most recent attack has been blamed on the Israeli intelligence agency Mossad, which is been called out by Iran multiple times for reportedly carrying out offensive operations on the cyber front. Saeed Khatibzadeh, a spokesman for the Iranian Foreign Ministry, informed that the affected centrifuges were old and first-generation, which is the IR-1 type. These can be replaced with advanced equipment shortly. However, the attack already seems to have pushed back the proceedings at the Natanz nuclear facility by at least nine months, forcing Prime Minister Benjamin Netanyahu to call an urgent security cabinet meeting to assess the situation and determine Iran’s response.

Related News:

Was it Stuxnet 2.0? Cyberattack on Iran’s Natanz Nuclear Facility

Over 45 Mn Egyptians Affected in Recent Facebook Data Leak

egyption-content

A few days back, security researcher Alon Gal revealed that the personal details of nearly 533 million Facebook users from 106 countries were allegedly exposed and kept on the dark web market for free. The leaked details included users’ sensitive data including full names, gender, occupation, marital and relationship status, date of joining, and place of work. However, a recent analysis from cybersecurity experts at Surfshark claimed that 4.76% of Facebook users had their email addresses exposed, while phone numbers of over 90% of the users were leaked in the incident.

“The data set also allows matching names and phone numbers with additional data like location (60.58%) and employer name (18.30%) that helps to both choose the targets (especially for spear-phishing attempts targeting specific companies) or to make hacking attacks more believable,” Surfshark said.

Risk of Smishing Threats

The biggest and the most threatening concern is that scammers can misuse the contact details exposed in the data breach. They can launch SMS phishing or Smishing attacks by imitating legitimate services to steal affected users’ sensitive data or commit financial frauds.  In Smishing attacks, cybercriminals send specially crafted messages to targeted users, provoking them to click on the malicious link in the message that eventually leads to a phishing attack.

Egyptians are the most affected

According to Surfshark, Facebook users in Egypt are the most affected victims of the latest data leak. Reportedly, the private details of around 45 million Egyptians were leaked, compared to 36 million users from Italy and 32 million users from the U.S. Almost all Facebook users in Egypt may have been affected by the incident, as the number of Facebook users in Egypt likely ranges between 42-50 million.

The other affected countries include Saudi Arabia, France, Turkey, Morocco, Colombia, Iraq, South Africa, Mexico, Malaysia, U.K., Algeria, Spain, Russia, Sudan, Nigeria, and Peru. 

Whether it’s a message or email, always check the sender and beware of any malicious URLs and attachments.

How to Boost Your Facebook Profile Privacy

  1. Use Off-Facebook Activity

Facebook harvests a lot of user information by partnering with third-party services like apps and websites. These third parties send Facebook information about users’ interests based on their activities online, which is eventually used for targeted attacks. To access the Off-Facebook Activity –  Click on the top right of the Facebook home page > Settings & Privacy > click Settings > Your Facebook InformationOff-Facebook Activity > click Manage Your Off-Facebook Activity. From here, you can manage your Facebook activities, clear all history, and turn off any future activity to your account.

  1. Limit Your Identity

Leaving your sensitive data open to the public may lead to identity thefts. Manage who can view your posts by changing your privacy settings. For this,

Go to Settings & Privacy > click on Settings > click on Privacy > select Who can see your future posts? > select your preference

  1. Login Alerts

Go to Settings > Security and login > Scroll down to Get alerts about unrecognized logins and click Edit. Choose where you want to receive your alerts, such as from your email account or with a Facebook notification from a recognized device. Finally, click Save changes.

  1. Two-factor authentication

Keeping your location details private and enabling two-factor authentication (2FA) services will give additional privacy protection to your accounts. Choose a security method of your choice (email or phone) to receive a verification code in case of login from an unrecognized device or browser.


Related story:

Hackers Have an Appetite for Indian Power Companies

power

Tearing a page from the bad actor’s handbook was a recent China nation-state attack against 10 Indian power sector companies. Tensions between China and India are running high over a disputed border. What appears to be a textbook attack patterned from another nation-state attack five years earlier, which saw Russia attack the power grid of Ukraine. This attack occurred during an ongoing cyberwar brought on by Ukrainian succession threats.

By Tari Schreider, C|CISO, CRISC, MCRP, ITILF, Senior Analyst at Aite Group

These attacks against India’s power infrastructure are not new. The following demonstrates the hacker’s appetite for Indian power companies:

  • 2020: Jammu and Kashmir State Power Development Department – ransomware
  • 2019: Andhra Pradesh Eastern Power Distribution Company Limited (APEPDCL) – ransomware
  • 2018: Uttar Haryana Bijli Vitran Nigam Limited (UHBNVL) – ransomware
  • 2017: West Bengal State Electricity Distribution – ransomware

In these examples of ransomware attacks, hackers attempted to extort US$100,000’s in ransom demands. Power company impacts ranged from essential data loss, critical utility applications rendered inoperable, and customers widely affected.

We’re Air-gapped, all Good Here

Cyberattacks against utility companies occur less frequently, primarily due to their diversity of technology platforms. Cybercriminals are adept at back office systems; however less proficient at supervisory, control, and data acquisition (SCADA) systems or industrial control systems (ICS). SCADA and ICS systems tend to be “air-gapped from the Internet, further distancing them from bad actors. The issue with believing that SCADA and ICS systems are secure is that most utility companies forget these systems are dependent on many support services that are not air-gapped from the Internet. Utility companies rely on internal systems such as applications to field trouble calls, create repair orders, pay bills, coordinate repair materials, dispatch contractors, pay invoices, and handle service disconnections.  When these systems become impacted by a cyberattack, the whole of the utility becomes disrupted. This interdependency attack damage scenario will become more common as more utility companies fuse operational technology with information technology.

The Dominos Fall

One such example occurred 4,300 miles from India’s Capital in Johannesburg, South Africa. In July of 2019, City Power, Johannesburg’s electric utility companies, suffered a crippling ransomware attack that encrypted a significant portion of their IT operations, preventing many essential services from continuing. The Achilles heel of progress in this outage example came when an application that allows customers to buy and sell electrical power unit credits using prepaid vending ceased to function, causing power disruptions throughout the city.  The magnitude of City Power’s cyberattack can be appreciated when you realize 245,433 of their customers rely on prepaid power credits.

China, Russia, Hacking Oh No!

In December of 2016, the world saw one of the most brazen cyberattacks on a sovereign country by another country. Just days before Christmas, Russian hackers attacked Ukraine’s national power grid operator Ukrenergo causing a system-wide blackout for one hour. Cybersecurity firm Dragos, Inc. reconstructed the attack, learning that the attack’s intent appeared to cause mass destruction of the power grid. Only through a misstep by the hackers and a little luck on the side of Ukrenergo did the attack’s full brunt become unwittingly thwarted. You can read a comprehensive analysis of Drago’s investigation at New Clues Show How Russia’s Grid Hackers Aimed for Physical Destruction. In a tale of history repeating itself, Russia attacked Ukraine’s power infrastructure in 2017 when a ransomware attack against Ukraine caught the Energy Company of Ukraine in its crosshairs.

Glass Half Full?

A 2019 study by Siemens and Ponemon Institute stated that “54% of the 1,726 utility professionals expected a cyberattack on their critical infrastructure in the next year.”1 What concerns me is the 46% that believed just the opposite were doing in 2020 to prepare to fend off a cyberattack?  What are you doing this year to defend against a clear and present threat to your organization’s critical infrastructure?


References

1 2019, October 8, Utilities Vulnerable to Cyber Attacks, Finds Study, T&DWorld

About the Author

Tari SchreiderTari Schreider is a distinguished technologist and nationally known expert in the fields of cybersecurity, risk management, and disaster recovery. He is currently a Senior Analyst with Aite Group covering cybersecurity technologies and practices for Aite Group, LLC. was formerly Chief Security Architect at Hewlett-Packard Enterprise and National Practice Director for Security and Disaster Recovery at Sprint E|Solutions. Schreider is an instructor for EC-Council where he teaches advanced CISO certification and risk management courses.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

 

Top 10 Neglected Data Security Best Practices

healthcare-data

Ensuring data security becomes harder every day. Firstly, sensitive data is often spread across on-premises and cloud-based storage locations, which makes it more difficult to maintain security controls. Secondly, the volume of data, including sensitive information, continues to grow, which means that more data requires protection. Finally, cybercriminals get more innovative all the time. As a result, securing data in compliance with increasingly complex regulations is a challenge.

By Ilia Sotnikov, Vice President, Product Management, Netwrix

A Netwrix IT Risks Report explored how organizations were working to ensure compliance and beat cyber threats. Unfortunately, the results indicated that organizations weren’t doing enough to defeat the bad guys. Here are the 10 most neglected security best practices:

1. Classify data based on its sensitivity

secure and private compute summit, data, data science

Security experts recommend that organizations classify data at least twice a year, so they can reset access rights and ensure that only the right people have access to data.

Reality check: 64% of organizations admit that they classify data based on its level of sensitivity just once per year or even less frequently.

Pro tip: Many organizations rely on users to classify data, which rarely works well. Look for data discovery and classification products that automate the classification process.

 

2. Update data access rights

Vulnerabilties

To prevent unauthorized access to data, security experts recommend strictly enforcing the least privilege principle, as well as reviewing access rights every six months and after important events like an employee termination.

Reality check: 51% of organizations do not update data access rights even once a year.

Pro tip: Look for governance solutions that can assess and control access rights, both as part of an ongoing process as well as ad hoc. Also, look for reporting and alerting tools that can ensure it’s all being done correctly and securely.

3. Review data available to everyone

cybersecurity

To reduce the risk to sensitive data, security experts say that at least every three months, organizations should check that folders and shares available to everyone don’t contain sensitive data.

Reality check: 76% of organizations are not doing this frequently enough, and some never do it at all.

Pro tip: Look for solutions that can automate a continuous program to discover, classify and secure content regardless of where it resides, so you can reduce your attack surface.

4. Get rid of stale data

School apps sharing students’ data

When you no longer need data for daily operations, it should be archived or deleted. To mitigate security risks, experts recommend doing this every 90 days.

Reality check: Only 18% of organizations delete unnecessary data once a quarter, meaning that 82% of organizations are needlessly increasing their threat exposure.

Pro tip: Deploy an automated solution that can find stale data and collaborate with the data owners to determine which data can be archived or permanently deleted.

 

5. Conduct asset inventory regularly

Experian API Flaw

Security experts encourage you to identify all your assets (e.g. databases, software, and computer equipment) and determine who is responsible for them at least once a quarter.

Reality check: Just 29% of organizations stick to the recommended schedule.

Pro tip: Choose an asset tracking solution that streamlines data collection and analysis to locate every asset within your company. Make sure it is easy to use and fits your needs.

6. Update and patch software promptly

Microsoft September 2021 Patch Tuesday

Installing security updates to your software in a timely manner enables you to mitigate vulnerabilities. The recommended frequency depends on patch and system importance and other factors; it varies from weekly for critical security patches to quarterly for less urgent patches, such as maintenance patches.

Reality check: 33% of organizations do not update their software even once in 90 days.

Pro tip: Establish a dedicated testing environment or at least a segment for patch testing to avoid incompatibility or performance issues.

 

7. Perform vulnerability assessments

Cisco Routers Vulnerability

Regular vulnerability assessments help you locate security gaps and reduce your exposure to attacks. Security experts recommend running these assessments at least once a month.

Reality check: 82% of organizations do this only twice a year or don’t do it at all.

Pro tip: Find products that can continuously evaluate threats to your data and make sure you know which threat actors do the most harm to your business. Even better, find tools that provide alerts to reduce the number of false alarms.

8. Create and maintain an incident response plan

Incident Response

There are several parts to a resilient security response plan: Draft a plan, get it approved, regularly train employees, and do test runs.

Reality check: 83% of organizations admit to failing to execute all these stages.

Pro tip: Conduct random tests to see how admins and regular users react to security threats and evaluate how your plan is working in real life.

9. Update admin passwords regularly

How to Detect Weak Passwords Using Google Chrome

If an administrator’s credentials are compromised by attackers, whether the credential is shared or not, the entire IT infrastructure is at risk. Security experts recommend changing admin passwords at least every quarter.

Reality check: Only 38% of organizations change their admin passwords at least once every 90 days.

Pro tip: Don’t use shared admin passwords, even if you update them every week. Each privileged user should have their own admin credentials and the passwords should be changed regularly.

10. Update user passwords regularly

common password of 2021,Password Protection, password spray attacks, Microsoft accounts passwords

While the goal of threat actors is to get administrative credentials, the gateway to that information is oftentimes accessing a user’s credentials. A security best practice is to require users to change their passwords at least every 90 days.

Reality check: 42% of organizations mandate a password change less frequently than once a quarter.

Pro tip: Require users to choose strong passwords (with a minimum number of characters and symbols) and change them once every 90 days. Also, consider deploying multifactor authentication and single sign-on.

Following these security best practices can help you reduce your attack surface and minimize the risk of security and compliance issues. Rigorously implementing security basics such as finding, classifying, and securing your data is essential to preventing attackers from stealing your sensitive data and ruining your company’s reputation.


About the Author

Ilia SotnikovIlia Sotnikov is responsible for Netwrix product vision and strategy. He has over 15 years of experience in IT management software market. Prior to joining Netwrix in 2013, he was managing SharePoint solutions at Quest Software (later acquired by Dell).

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Crucial Cybersecurity Assessment Steps Before Merger or Acquisition

Ping Identity Acquires Symphonic Software to Boost Enterprise Security

Technology and data are at the heart of almost every business. Cybersecurity should be a concern at the same priority level as legal and financial considerations when contemplating any merger or acquisition. As the number of mergers and acquisitions increases every year, so do the dollar amounts associated with such transactions. In 2018, the value of announced mergers reached nearly $3.9 trillion, with an average deal size of $384 million. With deals this size, companies risk a lot by not having a thorough approach.

By Greg Reber, CEO/Founder, AsTech Consulting/ former Partner at Moss Adams

During the past five years, we’ve seen a number of merger and acquisition deals where companies acquired organizations without performing adequate information security digital due diligence, only to discover woefully inadequate security of assets and even previously unknown breaches – Verizon and Yahoo, Marriott and Starwood come to mind. The consequences of these breaches become the responsibility of the new owner. As a result, the buying company must address these issues, leading to potential financial consequences not taken into consideration when determining the original acquisition pricing.

Often, these security vulnerabilities exist in the actual source code of internet applications or software packages that the buyer intends to acquire to complement their technology to expand market share. Sellers have to realize that not disclosing these issues could delay or reduce payments as the depth of the problems is understood.

Preparing for a Merger or Acquisition

So, what can be done to lower these risks? Depending on the type of business, you may want to emphasize different aspects of the target company. Below are steps to consider including in the due diligence process for different transaction scenarios.

1. Buying Any Company: Understand Security Policies and Processes

Every company should have a defined security program in place and be able to demonstrate its appropriateness to the company’s needs. Acquiring companies will want to know how seriously a target company has approached securing its assets and request a review of the security program for components such as:

  • Data classification schema that drives data handling policies
  • Incident response procedures and recent test results
  • User awareness efforts, especially as they relate to suspicious emails
  • Security organization and coordination of functional responsibilities

Many companies are beholden to compliance frameworks such as the Federal Deposit Insurance Corporation (FDIC), Health Insurance Portability and Accountability Act (HIPAA), or Payment Card Industry Data Security Standards (PCI DSS) and may provide reports on security compliance. Those that don’t should have the acquiring company thoroughly review their programs’ documentation and interview key employees to understand the security posture of the target company.

2. Buying a Software Company or Product: Assess the Security at the Source Code Level

Several researchers pointed out that source code security issues overtook network security vulnerabilities as the top attack vector. These issues may be easy targets for nefarious actors who know how to exploit them because network or perimeter security measures are more mature than software security measures.

To assess software vulnerability, begin with mapping the attack surface of the target applications by looking at how security is handled at data ingress and egress points. These include authentication and authorization components providing log in and authorization privileges, calls to databases, and data collection pages. From there, an adequate assessment will consider what the program does with the data it acquires and assist in confirming that it’s encrypted in transit and when it’s at rest.

Automated tools can quickly scan the software and typically identify half the types of vulnerabilities present. To achieve a comprehensive understanding of the security footprint of a website or application, the automated scan, combined with a manual inspection of the source code, will identify security issues within the source code. A business logic assessment (BLA) focuses on discovering built-in vulnerabilities that aren’t coding vulnerabilities but present risks due to as-designed application logic flaws.

3. Buying a Company that Comes with IT Infrastructure: Assess Network Security

Networks and IT infrastructures are a favorite target for culprits attempting to infiltrate a company to steal information. At a minimum, automated tools should also be used to perform a scan of networks, both internally and externally, to discover vulnerabilities that may be exploited.

As with source code scanning, if these automated scans expose lax security within the target network, a deeper dive performed by security advisors may be warranted. These individuals review firewall and server configurations and look at the network architecture and its design to compare it to best security practices.

The 2014 Target stores breach demonstrates the importance of this discovery process. The retailer’s heating, ventilation, and air conditioning vendors was hacked, and because there was inadequate segmentation in the Target network architecture, the culprits gained access to Target’s entire network even though the company only required access to environmental control systems within store locations. These functions could have been isolated within Target’s network. The breach resulted in more than $200 million in damages.

Third-Party Advisors

Bringing cybersecurity professionals with expertise in all aspects of information security — source code and website, infrastructure, and programmatic security — to your due diligence team can further help protect your company and identify overlooked risks. An advisor can help find vulnerabilities and vet them against real-world risk. For example, their analysis will reduce potential false-positive security issues that most automated tools call out.

Source code security professionals should have software development backgrounds, so they understand how software development processes work. This allows them to hone in on vulnerabilities in the source code, determine how much risk they present to the company, and the level of effort to remediate them.

By taking these due diligence steps you can move your transaction forward with confidence and focus on planning for the future of your combined business.


About the author

Greg Reber has specialized in IT security consulting since 1995. His expertise includes building effective risk management practices, developing information security programs, C-level security consulting for information security organizations, and merger and acquisition security due diligence.

 

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

In ByteChek, Companies Can Find the “X” Factor for Cybersecurity Compliance

ByteChek

In today’s hyper-connected world, cyberthreats are continuously evolving. This is why establishing a risk-based control to protect the integrity, confidentiality, and accessibility of business information, both in-house and customer data, is of the utmost importance. However, regulatory compliance and data privacy issues have long been an IT security nightmare. The EU’s General Data Protection Regulation (GDPR), France’s Digital Republic Bill, and the much-debated California Consumer Privacy Act (CCPA) in the U.S., are all making IT compliance issues stand at the forefront of corporate concerns.

SPONSORED CONTENT

The cyber gurus have for ages debated that there are a great number of tools available to aid pure information security, but when it comes to data governance or compliance frameworks, you can number them at your fingertips. Numbers suggest that a lot of companies still do their compliance auditing and analysis manually. Thus, hoping to revolutionize cybersecurity assessment and automate compliance audits and reporting, AJ Yawn and Jeff Cook came together to kickstart their new venture ByteChek.

It Takes Two to Tango!

Since his high school days, AJ Yawn, who grew up in Oceanside, California, has been an athlete at heart. He was an active member of his High School Basketball team and always dreamt of making it to the NBA. His dream looked within touching distance as he made it to the Florida State University’s team in his senior year. However, as destiny would have it, some critical injuries forced him on the sidelines.

But playing a sport teaches you to “Never Back Down.” And so, Yawn persevered. His grit and determination toward long-term achievement helped him serve in the U.S. Army for six efficient years. We call it efficient because this is where Yawn was introduced to the field of cybersecurity intelligence, which eventually shaped his entire career and mindset. His thirst for knowledge and inquisitiveness encouraged him to dig deeper into the field of cybersecurity assessments and audits, and the result of it is now for everyone to see.

bytechek

His business partner and CFO of ByteChek, Jeff Cook, also matches the same wavelength. All thanks to sports. Cook himself is a qualified 4th Degree Black Belt Karate champion. Taking reference to the “Karate Kid” movie, we are not sure if he is a Miyagi-Do fan or a Kobra Kai, but one thing is certain, like Yawn, Cook never shied away from any adversary. Be it his Karate Black Belt test or the CPA exam. He’s fought all the battles and emerged victorious every single time. This grit and motivation are what led to the foundation of ByteChek in November 2020, when the world was reeling through one of the greatest adversities of the current century – the COVID-19 pandemic.

 The Cyber-Aware CEO  
AJ Yawn - ByteChek
AJ Yawn, Co-Founder, and CEO, ByteChek

AJ Yawn is the Co-Founder and CEO at ByteChek. He is also a founding board member of the National Association of Black Compliance and Risk Management Professionals (NABCRMP). Yawn has earned six AWS certifications, including the AWS Solutions Architect-Professional and AWS Security-Specialty. Before ByteChek, He spent over a decade in the cybersecurity industry, both in the U.S. Army and as a principal consultant.

 CFO with Extensive IT Audit Experience 
Jeff Cook - ByteChek
Jeff Cook, Co-Founder, and CFO, ByteChek

Cook brings his information assurance and public accounting experience to ByteChek as a professional with over nine years of IT audit and consulting experience and over 20 years of public accounting and auditing experience. He has worked extensively on SOC in addition to providing IT audit support for traditional financial statement audits. Jeff is also heavily involved with the AICPA, volunteering with the development of the SOC and CITP programs. Cook was part of the SOC 2 working group, helping to develop the 2018 version of the AICPA SOC 2 guide, has developed numerous training for the AICPA, and is a prior recipient of the AICPA IMTA Standing Ovation Award for outstanding professional achievement in the IT specialization area. He is also a part of the AICPA CITP credential committee, the AICPA IMTA SOC task force, and the AICPA Eye on Technology task force.

The Kickstart

Both Cook and Yawn had been colleagues and had always dreamt of venturing together to start a compliance audit automation company because of Cook’s expertise in CPA and Yawn’s in cybersecurity. But last spring, when both men parted ways with their previous employer, things finally got serious, and Cook reached out to Yawn to materialize their dream team.

“I know it’s a global pandemic, but do you want to start this thing?” Cook remembers discussing with Yawn. The answer was a no-brainer for Yawn. “Yes,” he enthusiastically responded. The two rushed to the drawing board, and fittingly ByteChek was launched on Veteran’s Day as a gesture of Cook’s appreciation and respect for his Co-Founder Yawn, who served as a captain in the U.S. Army.

Let’s Check ByteChek

Cybersecurity processes can be overwhelming and laboriously time-consuming, even for the market’s more prominent players. However, to counter this problem and speed up the process of proving compliance, ByteChek has introduced a cloud-based SaaS solution to automate IT audits and streamline cybersecurity reporting. This platform fits well for companies of all sizes. The ByteChek platform provides a stable security program, automates cybersecurity readiness assessments, and completes SOC 2 audits faster, and the best part – it does all of this from a single platform.

The ByteChek platform is well diversified and provides a ground-up approach to building information security policy. Once done with defining the policies, the platform then connects with the applications that companies use daily to eliminate evidence collection and vague auditor requests.

 ByteChek’s product features include the following: 

  • Full suite of integrations
  • Information security policy generator
  • NIST CSF risk manager and register
  • System description generator
  • Automated & actionable recommendations
  • Real-time chat functionality with your auditors
  • Complete access reviews, vendor management, annual policy tests, and much more.
ByteChek has recently become the first cybersecurity software company selected for the accounting-focused startup accelerator sponsored by the Association of International Certified Professional Accountants (the Association) and CPA.com.

 

S N A P S H O T
Company ByteChek, LLC.
CEO/CFO CEO and Co-founder – AJ Yawn

CFO and Co-founder – Jeff Cook

Website https://www.bytechek.com/
Consulting Partners Maryland Association of Certified Public Accountants, Hire Military, and Missouri Society of Certified Public Accountants.
Tech Partners Splunk, AWS Technology Partner, and Slack App Directory
Social Media Handles
Location(s) Miami, Florida, United States
Employees Up to 10
Awards & Rewards:
  • AJ Yawn2020 LinkedIn Top Voice Award
  • First cybersecurity software company selected for the accounting-focused startup accelerator sponsored by the Association of International Certified Professional Accountants (the Association) and CPA.com
Industry-wise Services
  • SaaS
  • Accounting
  • Compliance
  • Cybersecurity
  • Information Technology
  • Risk Management

CISO MAG Writer - Mihir Bagwe
 About the Author 

Mihir Bagwe is a Tech Writer and part of the editorial team at CISO MAG. He writes news features, technical blogs, and conducts interviews on latest cybersecurity technologies and trends.

 

 

Related Articles:

Hackers Taste the Bitterness of Their Medicine; Darknet Marketplace Swarmshop Hacked

BlackMatter ransomware

“Karma” is defined as “What goes around, comes around.” When Karma is at play, there is no need for revenge. Just sit back and wait. And if one is lucky, they might be able to witness Karma take its course. That day is here! Believe it or not, but a group of cybercriminals, who go by an alias name of “Swarmshop” on the underground forums selling stolen credit/debit card data, has been hacked.

Swarmshop’s Data Hacked

Swarmshop is a mid-sized store for stolen personal and payment records. The card shop has been operational since at least April 2019, and by March 2021, it had more than 12,000 users. The total amount deposited in user accounts was at $18,145.73 by March 2021, as users of card shops do not store large amounts of money on their accounts and top up the balance to make payments if necessary.

Coming to the leaked database, Group-IB, a global cyberthreat intelligence company, first discovered this data set on March 17, 2021. On analyzing the data further, it was traced back to the user data of the Swarmshop card shop operators. The leaked database was posted on a different underground forum and contained 12,344 records of the card shop’s four admins, 90 sellers, and 12,250 buyers. The data was so detailed that it included their nicknames, hashed passwords, contact details, history of activity, and the current balance in their wallet.

Other Data Leaked

In addition to user data, the database exposed all compromised data traded on their forum, including 623,036 payment card records issued by the banks from the U.S., the U.K., Canada, China, Singapore, France, Brazil, Saudi Arabia, and Mexico.

Also, 498 sets of online banking account credentials and 69,592 sets of U.S. Social Security Numbers (SSN) and Canadian Social Insurance Numbers (SIN) were leaked from the Swarmshop.

While the source of the breach remains unclear, the exposed records show that two users of the card shop attempted injecting a malicious script searching for website vulnerabilities in the contact information field. It’s impossible to determine if the two events are connected to the breach.

Not the First Time

Interestingly, Swarmshop was targeted by fellow cybercriminals earlier in January 2020 as well. And the same story had played out. The card shop’s records were leaked on an underground forum by a user likely motivated by revenge.

swarmshop data hacked
Image Credit: Group-IB Threat Intelligence & Attribution

The user wanted to sell the Swarmshop user database and posted an alleged screenshot from the card shop’s admin panel.

swarmshop data hacked
Image Credit: Group-IB Threat Intelligence & Attribution

The Russian-speaking admins of the card shop never commented on this thread, however, the website went down temporarily due to “the transfer to the new server.

Now, more than a year later, when a newly registered user posted a similar thread with the link and a password to the database of the Swarmshop card shop on different forums, the admins of the card shops eluded the argument saying it came from the last year’s breach which they have already “fixed.”

swarmshop data hacked

swarmshop data hacked
Image Credit: Group-IB Threat Intelligence & Attribution

A week after the appearance of the post, Swarmshop users were redirected to an under-maintenance page when trying to log in. The users were then recommended to change the passwords shortly after the breach report came out.

What the Experts Say…

Dmitry Volkov, Group-IB CTO, whose team unearthed and studied the entire Swarshop data hacking incident, said,

While underground forums get hacked from time to time, card shop breaches do not happen very often. In addition to buyers’ and sellers’ data, such breaches expose massive amounts of compromised payment and personal information of regular users. Although the source remains unknown, it must be one of those revenge hacks cases. This is a major reputation hit for the card shop as all the sellers lost their goods and personal data. The shop is unlikely to restore its status.

Related News:

Hackers Hacked a Hacking Forum!