Home Blog Page 99

Alleged Facebook Data Leak Affects 6 Mn Indian Users

Facebook Data leak, Facebook bans cyber mercenary

Days after the MobiKwik data breach incident, wherein, 3.5 million MobiKwik users’ KYC details were allegedly leaked, another major data leak event concerning Facebook seems to have hit the Indian shores along with 106 other countries. Alon Gal, CTO of cybercrime intelligence company Hudson Rock and the first to discover the data leak, stated that the personal details of nearly 533 million Facebook users from 106 countries were allegedly leaked and posted for free on an underground hacking forum. The leaked details included users’ PII, including full names, gender, occupation, marital and relationship status, date of joining, and place of work.

Related News:

Unprotected Database Exposes Millions of Facebook users’ Contact Numbers

A New Discovery Linked to the Old?

The database, which was first found in 2019, had leaked 419 million records. However, Facebook claimed that it had fixed the vulnerability and the case was closed only until January 2021, where an updated version of the same database resurfaced on a popular messaging platform, Telegram. The data was initially being sold on Telegram using a bot for a minimal fee of $20 per search. Gal previously said, “It was severely underreported (in 2019) and today the database became much more worrisome.” The vulnerability was the same. It allowed users to search for a person’s number.

Related News:

Phone Numbers of 533 Mn Facebook Users on Sale via Telegram Bot

However, three months later, on April 3, 2021, Gal once again shared the details of the leaked database, and alerted Facebook users that “it is extremely likely the phone number used for the account was leaked.” According to the database of the latest alleged leak, details of as many as 1.2 million from Australia, 3.8 million from Bangladesh, 8 million from Brazil, 32 million from the U.S., 11 million from the U.K., and 6.1 million from India had been put up for free on several darknet forums.

India Needs Data Protection…Now!

As mentioned earlier, this is the second major incident in just a matter of few days where the data privacy and data rights of Indian citizens have been flouted repeatedly. India needs a strong user data protection bill and hefty fines for those not adhering to it. The Personal Data Protection Bill, which is said to contain these provisions is still in the works since 2019. However, we look up to the future in hope as the Joint Parliamentary Committee, which is responsible for drafting the bill, is said to be set to present it in the first week of Parliament’s Monsoon Session.

To Read more about India’s first Data Protection Bill, click here.

Related News:

All You Need to Know About India’s First Data Protection Bill

Airtel to Provide Cybersecurity Services After CERT-IN Empanelment

Bharti Airtel, a popular telecommunications provider in India, has been selected by the Indian Computer Emergency Response Team (CERT-IN) to offer its cybersecurity solutions to government organizations and corporate consumers. CERT-IN is India’s National Incident Response Center for cybersecurity incidents across the country.  “With this empanelment, Airtel will be able to offer its cybersecurity solutions to Union and State Governments as well as Public Sector entities, in addition to corporate customers,” Airtel said in a release.

How the new empanelment helps Airtel

Bharti Airtel launched a group of cybersecurity solutions under Airtel Secure for large, medium, and small businesses last year as per the increasing need to protect critical data from cyberattacks. The cybersecurity suite – Airtel Secure – provides end-to-end managed security services to enterprise customers. The Indian telecom giant claimed that it created a state-of-the-art Security Intelligence Centre with access to advanced technology like artificial intelligence and machine learning to track and mitigate potential threats.

Under Airtel Secure platform, the company is providing multiple cybersecurity solutions like endpoint protection, email protection, and cloud DDoS protection. Airtel has created a comprehensive security solutions portfolio via strategic partnerships with global firms like Radware, Cisco, VMWare, and Forcepoint.

“Airtel is trusted by over one million enterprises of all sizes. The CERT empanelment is a major milestone in our journey to becoming the preferred partner for enterprises when it comes to security, which is a top priority in today’s digitally connected world,” said Ajay Chitkara, Director & CEO, Airtel Business.

Cybersecurity – A New Revenue Model for Telecoms

The latest announcement from Airtel proved a previous analysis from IBM that claimed cybersecurity will become a major revenue opportunity for Indian telecom operators. It is said that telecoms would offer security-as-a-service to enterprises along with security-related products.

Will it benefit the consumer?

As per the notice, information on providing security solutions to end-users is unknown. Along with telco services, Bharti Airtel also provides payment banking services to its consumers. Thus, data privacy and protection must be a priority as the company holds a huge customer base in the country.

In February 2021, cybercriminals exposed the personally identifiable information of nearly 2.5 million Indian subscribers of Airtel and posted it on the dark web for sale. The exposed information included users’ sensitive data like phone number, address, and Aadhaar card number.

Cybersecurity Concerns on Indian Telecom Sector

The telecommunication sector has always been a target for cybercriminals, as it connects and communicates with millions of users globally. Telecom providers operate complex networks and store massive amounts of sensitive data related to users and organizations, which makes the industry more lucrative to bad actors. Besides, the recent cyber espionage campaigns from Chinese attackers targeting multiple Indian organizations in the power and transportation sectors brought severe security concerns to the telecom industry.

Threat to Advance Telecom Technology

Recently, cybersecurity experts discovered a cyber espionage campaign targeting telecom operators globally to steal sensitive information. The campaign is aimed at pilfering trade secrets and other technical details related to 5G technology. Dubbed “Operation Diànxùn,” the campaign tricks employees in the telecom sector with a fake Huawei career page asking them to provide personal data. McAfee researchers suspect that Chinese state-sponsored hackers are behind Operation Diànxùn because the tactics, techniques, and procedures (TTPs) used in the campaigns are similar to the ones used by Chinese threat actor groups RedDelta and Mustang Panda.

“Zero Trust is overhyped because vendors are overusing it”

Jon Green is VP and Chief Security Technologist at Aruba, a Hewlett Packard Enterprise Company. He is responsible for providing technology guidance and leadership for all security solutions including authentication and network access control, UEBA, encryption, firewall, and VPN. He also manages Aruba’s Product Security Incident Response Team (PSIRT) and Aruba Threat Labs, an internal security research group. Green joined Aruba in 2003 and helped it grow from a small startup to today’s position as a leading provider of network mobility solutions. Prior to Aruba, he held product management, marketing, and sales positions with Foundry Networks, Atrica, Nortel Networks and Bay Networks. Green holds a B.S. in Information Security from Western Governor’s University and a M.S. in Computer science/concentration Information Security from James Madison University.

In an exclusive interview with Augustin Kurian, Sr. Feature Writer at CISO MAG, Green talks about his journey that led to Aruba, IoT security and examination of data, myths surrounding Zero Trust, and the future of AI and ML in cybersecurity.

You started your career as a technical engineer with Nortel Networks. You have donned the hats of both technology and marketing leaders. Tell us a bit about yourself and the journey that led to Aruba. How do you think Enterprise security has evolved during this time?

I got my start even before Nortel, doing tech support for a dialup ISP in the very early days of the commercial Internet. Later, I went to work for Bay Networks, which was bought by Nortel. That was where I first worked for Keerti Melkote, who had also joined Nortel by way of acquisition. A few years later after Keerti founded Aruba, I called him up wondering what Aruba was and what I could do for him. At that point he was still hiring QA engineers and he asked if I wanted to do that. In hindsight, I should have said yes, but I waited another six months and then joined Aruba as a combination product manager and technical marketing engineer; in early startup days you do whatever needs to be done and wear as many hats as necessary. In many ways, 16 years later, that’s still true even as part of a Hewlett Packard Enterprise (HPE)–I took an interest in security, found a lot of work that needed to be done and started doing it.

In many ways, security hasn’t changed much at a technical level since the early days of computers. What has changed is the business and personal impact. We’ve always had IT security vulnerabilities, and we’ve always had bad actors seeking to use those vulnerabilities for their own purposes. In 2020, we still see the same sorts of technical weaknesses– poor programming, misconfiguration and a lack of effective threat modeling. What HAS changed over the years has been the impact. In 1995, the financial rewards for computer crime were relatively low. Today, that is not the case, and as a result, you now see professional attackers who are being paid to do what they do. Today’s practical scope of security then is tied to authentication, identity, creation of policy and the monitoring of bad behavior.

A big part of IoT security revolves around a close examination of data (from sensors). What are the primary methods you recommend for examining the data generated by IoT devices for security purposes?

This is one of those “it depends” answers that security people are so fond of. As IoT device growth continues to proliferate, the emergence of sensors and other connected things has jumped dramatically–we’re seeing something like 14 million IoT devices entering the network daily. If we’re not paying attention, this creates a massive problem in the form of large blind spots for organizations that are essentially growing the attack surface, that they also need to manage from a security standpoint. The question then is, what does “manage” mean? Are we worried about the data, or the device? It depends.

From a security standpoint, we do need to worry about ensuring that the devices themselves do not compromise enterprise security; the nowfamous “Wi-Fi fish tank thermostat” has become the classic example for that. The primary control method here is network segmentation down to the most granular level you can get to—a single device if your infrastructure supports it. In a nutshell, we want to make sure the device can get to its approved services and nothing else. The data generated by the devices could be a different story depending on the impact of a security breach. If I’m running uranium centrifuges (ala Stuxnet) then my sensor data matters a great deal to my mission. If it’s a Wi-Fi fish tank thermostat and I’ve got some inexpensive goldfish, then maybe not. There are some security products out there which are specifically focused on industrial control systems and ensuring the data flowing through those systems is correct, but in general these systems are going to be very application specific.

How does the corporate IT team balance the needs of security vs. connectivity, especially when IoT devices can often be brought onto the network outside the purview of the IT organization?

They shouldn’t necessarily have to–they can do both. From the start, when Aruba was designing first generation products back in 2002, we were building WLANs and we considered security as a critical requirement–the idea that devices or users could not be inherently trusted, and the idea that Wi-Fi would be a multiuser, multi-access network that needed to support different classes of users and devices on the same network. We needed policies for all users and devices, and then ways to enforce them such as a user-facing firewall. Today we provide that capability for Wi-Fi, wired networks, remote access, and SD-WAN. To a great extent, it’s OK if people plug in IoT devices without talking to IT, as long as those devices are prevented from doing damage to the enterprise.

What can be the best approach to secure connectivity to the cloud and how can enterprises harness IoT while keeping the network and sensitive corporate assets safe?

Knowing where your sensitive data is now, and where it is going to be in the future, is the number one rule of security for the cloud. It needs to be protected through best practices like encryption. Be it in the cloud, or the edge network, businesses are ultimately responsible for any loss of data that impacts customers. Additionally, organizations need to ensure they are thoroughly vetting any edge device and applying the right level of access control to the device and encryption toward the data being generated that is eventually flowing into the cloud. This means that organizations of all sizes need to develop processes to apply security rigor and thoroughly test any device or set of devices being used to support business functions.

Aruba’s single switching platform runs on a network operating system from the enterprise edge to the core to the data center. Tell us a bit about this new technology. What makes it so unique and innovative?

We, like other players in the networking industry, have years and years of legacy technology behind us. I don’t mean “legacy” in a negative way—there’s tremendous value in having deep expertise in the field going back decades. However, our customers are looking for some consistency in the technology they deploy, largely because a smaller number of people are having to support larger and larger networks. Having a single operating system and consistent set of silicon across an entire edge-todata-center network provides huge advantages when you consider both network management and policy enforcement, because suddenly you are managing and monitoring an entire network as one single entity. This takes away one of the biggest security challenges, ensuring that all the assets are not only accounted for, but have the correct policy settings to control users, devices and, in turn, be able to discover anomalous behavior that may be the precursor to a costly hack.

How do you define Zero Trust Networking? It is difficult or impossible to adapt legacy infrastructure for a zero trust world. You’ve said that things like IoT don’t fit in a zerotrust world and are more towards network access control.

Zero Trust (ZT) in a nutshell means your access to an IT resource does not hinge on your mere presence on a network. It doesn’t give you access you would not have otherwise. In other words, just being there does not mean being authenticated. It’s the direct opposite of the “fortress mentality” where everything outside the perimeter is bad and everything inside the perimeter is good.

ZT security is an important concept being applied to a lot of things over the past several years, but the most important thing to think about is that ZT is not a destination that you magically arrive at with new equipment; it’s a journey. It’s not a product you buy; it’s a design philosophy.

My comments around IoT and ZT have reflected the fact that IoT devices often come with minimal security capabilities. They don’t have secure credentials, can’t authenticate with anything and may not even support encryption. My point is, you can plan for a ZT framework but you’re always going to have pieces that don’t play in that world—so plan for that. Have a way to connect those devices and let them get their job done without letting them be a risk to the rest of the enterprise.

What are the myths around zero trust? You have often been quoted stating that users don’t always understand what a Zero Trust approach entails or how to necessarily move in that direction–do you think security vendors are confusing that perspective?

In a word, “yes.” ZT is overhyped because vendors are overusing it, which happens with many terms in the industry—how many vendors have used “AI” or “blockchain” to sell you legacy technology with a new name? The problem is that hype confuses the marketplace. User identity needs to be tied to strong credentials, and the use of two-factor authentication. You cannot just trust a device. Access must be the same inside or outside the building. Furthermore, there needs to be a monitoring step, so after authentication, events are also logged.

Overall, ZT is an aspirational journey that brings together many elements to create a single concept (or rule to live by). But, be very careful of vendors who tell you that you can buy ZT from them. They might have products that can help move you toward a ZT framework, but nobody can provide the entire solution.

Can zero trust and network access control co-exist today? Or will zero trust make Network Access Control obsolete?

Depending on how you look at the definition of ZT, the two technologies are either simply two parts of the same spectrum, or at the very least are complementary technologies. Network Access Control (NAC) is focused on authenticating and controlling access to enterprise networks, while in most people’s definition, ZT is about controlling access to applications. I tend to think of NAC as being “zero trust for networks” — it’s saying that just because you can connect to a Wi-Fi network or a wired port, that doesn’t let you have wideopen access to all services. Access is based on identity and context. ZT, using the popular definition, is doing the same thing, but the object being accessed is an application instead of a network.

One of the more famous instantiations of ZT actually uses NAC as a context source — a device that is authenticated to a corporate network provides information to the access proxy that devices on external networks can’t provide. So, I don’t see a conflict here — NAC is going to be around for a long time, even as ZT frameworks come into prominence and the technologies will easily co-exist.

Lastly, AI and ML have been driving innovation in the space of cybersecurity. How can enterprises leverage technologies like AI/ML, or other tools to further automate IoT and network security?

As security becomes more complex, and organizations continue to experience skills and resources gaps, technologies like AI/ML are going to become increasingly important to ensure security scales with the business infrastructure. To start with, ML is simply a sub-category of AI–and most of the work in security today is using ML so that’s the term I will use. We would typically contrast ML with “rules.” I want to discover if a certain risk exists, or if a certain event has taken place, or if a series of events has taken place — any of which could indicate a security problem. Sometimes I can do this with rules, but very often the number and complexity of the rules can become overwhelming for a human and that’s where ML can potentially step in. ML can look at huge amounts of data, pull out very weak signals and classify that data or, at the very least, identify things that are interesting.

I’ll give a practical example: Most organizations today are regularly running vulnerability scanners on their networks. These scanners are great for finding misconfigured systems and common weaknesses, but they are also notorious for throwing off piles of false positives. Unfortunately, those false positives end up in my mailbox often as our customers demand to know why their Aruba equipment is vulnerable to a 20-year-old CVE that was found in a long-dead IBM database product (answer:It’s not). This is a place where a properly trained ML engine could look at the results, consider the number of times and the circumstances under which vulnerability findings were real versus false and then weed out the false positives. We’re actually working on something like this right now, first as an internal tool but possibly something we’ll release externally in the future.

Just as with other industry buzzwords, buyers beware with AI and ML! If a vendor wants to sell you an AI-enabled security product, ask carefully what the product does using AI that it could not do without AI. That one question will help you separate those who are really using the technology from those who are jumping on the buzzword bandwagon.

This interview first appeared in the April 2020 issue of CISO MAG. Subscribe now!


Augustin Kurian

About the Interviewer

Augustin Kurian is part of the editorial team at CISO MAG and writes interviews and features.

How does HIPAA Compliance help in protecting the PHI data?

Accellion Lawsuit, Google and Apple, Excellus to Pay $5.1 Mn to Settle Potential HIPPA Violations

For those of you who are involved in the Healthcare Industry must be well aware of the Health Insurance Portability and Accountability Act (HIPAA) Compliance. The regulation is a standard framework and statement of best practices for healthcare industries to follow. Although the regulation may seem daunting, anyone connected to the healthcare industry must understand the Regulation. In this article, we have briefly explained the HIPAA Regulation and how it helps in protecting PHI data. So, moving ahead, let us first understand what is HIPAA Compliance?

By Narendra Sahoo, Founder and Director, VISTA InfoSec

Brief on HIPAA Compliance

The Health Insurance Portability and Accountability Act (HIPAA) is landmark legislation established in 1996 in the United States for the Healthcare Industry. HIPAA was initially designed to address the issue of health insurance coverage for people. However, the Regulation is now more widely known for improving the data privacy and data security of sensitive PHI information in the healthcare industry. HIPAA Security and Privacy Rules were introduced to address the growing concerns of data breaches in the industry. Addressing the evolving security issues, critical changes concerning how organizations to store, handle and use sensitive patient information was eventually covered in the HIPAA regulation.

Today, the HIPAA Regulation requires covered entities (healthcare providers, health plans, healthcare clearinghouses, and business associates) to put in place technical, physical, and administrative measures to secure the Protected Health Information (PHI). This is to ensure not just securing the privacy but also the integrity and accessibility of the data.

What is PHI data?

PHI which stands for Protected Health Information is personally identifiable information in the medical record which is often used, or disclosed in the course of providing health care services. Defined under the HIPAA Regulation, PHI can be a type of patient information relating to their past, present or future physical or mental health. But, it does not just limit to the healthcare records and goes beyond, to include health insurance details or any information relating to payment for healthcare that results in identifying the individual concerned.

So, when it comes to determining the type of data as PHI or not simply comes down to any health-related data resulting in identifying the individual. It is the connection of the health data which is the key in determining the PHI data. However, it does not include information held in education or employment records. As per HIPAA, there are 18 identifiers that make health information PHI as in the below-given table

1 Name 7 Medical record numbers 13 Device identifiers and serial numbers
2 Geographic data 8 Account numbers 14 Internet protocol addresses
3 Dates 9 Health plan beneficiary numbers 15 Full face photos and comparable images
4 Telephone numbers 10 Certificate/license numbers 16 Biometric identifiers (i.e. retinal scan, fingerprints)
5 Fax numbers 11 Vehicle identifiers and serial numbers including license plates 17 Social number
6 Email addresses 12 Web URLs 18 Any unique identifying number or code.

What is e-PHI?

ePHI is Electronic Protected Health Information that includes individually identifiable health information created, maintained, or transmitted electronically. This includes PHI on desktop, web, mobile, wearable, and other technology such as email, text messages, or other similar applications.

How HIPAA Compliance help in protecting PHI data?

The Health Insurance Portability and Accountability Act (HIPAA) of 1996 was developed to improve the efficiency and effectiveness of the healthcare system in the US. Eventually, several new rules were added to HIPAA focusing on securing sensitive patient information. For healthcare organizations, HIPAA provides a framework that secures access to Protected Health Information and restricting with whom the information can be shared. So, any organization dealing with PHI must have in place Administrative, Logical and Technical controls to be compliant. Today with HIPAA Regulations in place it has reformed how healthcare professionals operate. HIPAA’s Security and Privacy Rules were introduced as measures to improve efficiency in protecting PHI data. Especially in the transition of health information from paper records to electronic forms ensuring complete safety. Given below details explain how HIPAA Privacy and Security Rules help in protecting PHI information.

HIPAA Privacy and Security Rules

HIPAA Privacy Rule establishes standards for protecting the privacy of PHI information. The HIPAA Privacy Rule is a national standard set to protect individuals’ medical records and other personal health information. The rules outline the rights of patients over their health information, including the right to examine and obtain a copy of their health records, and the right to request corrections.  The Rule requires covered entities to protect the privacy of personal health information, and set limits and conditions on the uses and disclosures of Protected Health Information, especially without patient authorization.

As a subset of the Privacy Rule, the Security Rule applies specifically to electronic PHI or ePHI. The HIPAA Security Rule is a standard that guides covered entities to protect individuals’ electronic personal health information and ensure the confidentiality, integrity, and security of this information.  It requires protecting e-PHI by using administrative, physical, and technical security measures. Given below are three safeguards outlined by the HIPAA Regulation which is summarized for your understanding and implementation.

Administrative Safeguards

Administrative safeguards can be defined as administrative actions to be taken concerning the policy and procedural implementation for protection against a breach. This typically involves establishing documentation processes, roles, and responsibilities, training requirements, data maintenance policies to name a few. Administrative safeguards include ensuring that the physical and technical protections are implemented appropriately.

  • Security Management Process – The Administrative Safeguards require covered entities to conduct a Risk Analysis as part of their Security Management Processes. This is to identify and analyze potential risks to e-PHI and implement security measures to reduce risks to a reasonable level.
  • Appoint Security Personnel – A covered entity must as a part of the HIPAA Security requirement appoint a security official who will be responsible for developing and implementing relevant security policies and procedures. 
  • Access Management Aligning with the Privacy Rule covered entities must limit the access and disclosures of PHI to a bare minimum or maybe on a need basis.  The Security Rule calls for covered entities to implement policies and procedures for authorizing access to e-PHI only when such access is necessary and is role-based access.
  • Workforce Training – A covered entity must train all its employees and members dealing with e-PHI regarding the implemented security policies and procedures. They must have in place measures to ensure its enforcement with appropriate sanction policies in place for members violating the policies and procedures.
  • Evaluating security measures A covered entity is required to perform a periodic assessment of the security policies and procedures established to meet the security requirements as stated in the Security Rule.

Physical Safeguards

Physical safeguards involve ensuring physical protection of the stored PHI data. This would include having in place Security Systems, CCTV Cameras, door locks, and similar security measures. It would even include security safeguards for workstations and electronic devices and gadgets storing PHI data.

  • Facility Access and Control A covered entity must limit physical access to the facility storing PHI data. They must ensure only authorized access to such facilities which should be role-based.
  • Security measures for Workstation and Devices – A covered entity must implement policies and procedures to implement and enforce necessary security measures at workstations and electronic devices contain PHI data.  The policies and procedures also include measures concerning the transfer, removal, disposal, and re-use of e-PHI to ensure the protection of the data.

Technical Safeguards

Technical safeguards are measures related to policies that protect data from unauthorized access. The covered entity needs to determine and implement relevant security measures for protecting ePHI. The covered entities are expected to proactively identify potential risks and measures to secure the e-PHI.

  • Access Control – A covered entity is expected to have in place appropriate access controls by implementing policies and procedures that limit access to only authorized personnel.
  • Audit Controls  A covered entity must deploy hardware, software, and/or procedural mechanisms to record and examine access and other activity in systems that contain or use e-PHI.
  • Integrity Controls – A covered entity must have policies and procedures established to ensure that e-PHI is not altered or destroyed unknowingly. Necessary measures need to be in place to ensure the same.
  • Transmission Security  A covered entity must have technical security measures to guard against unauthorized access and transmission of e-PHI over an electronic network.

Enforcement of Security safeguards with Non-Compliance Penalties

The HIPAA Privacy and Security Rule are established to secure the confidentiality, integrity, and availability of e-PHI. The Department of Health and Human Services (HHS), Office for Civil Rights (OCR) is responsible for administering and enforcing these rules and has the authority to conduct investigations and compliance reviews. While the OCR prefers to resolve HIPAA violations using non-punitive measures, like voluntary technical guidance or issuing warnings to help covered entities address non-compliance, serious violations persisting for a long time, or multiple areas of noncompliance, will result in financial penalties. However, the financial penalties are levied based on the penalty structure set by the enforcement bodies as given below –

Tier of penalties Violation explained Penalty structure
Tier 1 A violation that a covered entity was unaware of and could not have realistically avoided and had taken reasonable measures to abide by HIPAA Rules Minimum fine of $100 per violation up to $50,000.
Tier 2 A Violation that a covered entity should have been aware of but could not have avoided even with a reasonable amount of measures taken. (not  wilful negligence of HIPAA Rules) Minimum fine of $1,000 per violation up to $50,000
Tier 3 A Violation due to willful negligence of HIPAA Rules but where an attempt has been made to correct the violation. Minimum fine of $10,000 per violation up to $50,000
Tier 4 A Violation of HIPAA Rules constituting wilful negligence and, wherein no attempt was made to correct the violation. Minimum fine of $50,000 per violation

 Conclusion

Keeping the Health Information secure is a critical ongoing process for covered entities of the Healthcare Industries. HIPAA Regulation was established to ensure covered entities abide by the rules and ensure compliance. It provides a framework that works as a guide for the covered entities to protect their PHI data.

The regulation was designed to be flexible and scalable for covered entities, keeping in mind evolving technology and threat landscape. So, Covered entities can determine reasonable and appropriate security measures based on their environment and accordingly implement necessary measures. By following the standard framework with diligence will not just help covered entities secure their data, but also prevent incidents of breaches and further ensure compliance to HIPAA Regulation.

WRITE FOR CISO MAG

Do you want to write for CISO MAG? Please read our guidelines here.


About the Author

Narendra SahooNarendra Sahoo (PCI QSA, PCI QPA, CISSP, CISA, and CRISC) is the Founder and Director of VISTA InfoSec, a global Information Security Consulting firm, based in the U.S., Singapore, and India. Sahoo has more than 25 years of experience in the IT Industry, with expertise in Information Risk Consulting, Assessment, and Compliance services.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Why do Organizations Need a Virtual CISO?

Virtual CISO

Hiring a chief information security officer (CISO) may not be in the budget for small or midsize organizations as their total cash compensation can range between $208K to $337K. However, at the same time, these organizations recognize the growing importance of being more strategic and the necessity of having a leader responsible for program creation and guidance.

By Jeffrey Wheatman, Research VP, Gartner Research

The good news for such organizations is that Gartner has seen an uptick in what we are calling “virtual CISO” offerings. For organizations that need to fill the need for leadership but are not in a position to bring in a full-time, and often very costly qualified CISO, the virtual CISO (or vCISO) — a combination of staff augmentation, consultant, advisor, and strategist — might be an option.

Virtual CISO offerings are a hybrid of:

  1. Traditional staff augmentation, involving an on-site or virtual presence in meetings, events, operations, and strategy planning.
  2. Consultative engagement and management to drive creation and implementation of security and risk program artifacts, such as strategic and tactical roadmaps, architecture, and policy, and to run risk management and risk assessment processes.
  3. Project management of architecting and deploying security and risk solutions.
  4. Coaching or advisory services to train full-time staff on how to leverage created artifacts, develop communicating plans, and train the next generation of security and risk leaders.

That’s not to say there aren’t organizations that seek to defend their lack of a leader with some shortsighted rationalizations. It’s useful to take a look at four of the most common rationalizations to help show the reasons why smaller enterprises should seriously consider bringing in a virtual CISO role.

We are not regulated, so we don’t need a CISO.

Yes, but you’re not immune. Not being regulated may not obligate an organization to staff a CISO position; however, that doesn’t mean it doesn’t have risks to manage as part of achieving its business goals. Having a program leader, and the associated governance and strategic vision also provides defensibility.

Maybe, but you’re not an island either. The dramatic increase in broad ransomware attacks such as WannaCry and Petya/NotPetya means that nobody is immune from attack. Also, the increasing connectedness of digital business ecosystems expands and extends enterprise risks, so while your organization may not be a target, your partners may be.

We don’t have anything anybody would want.

Are you sure — absolutely sure? This outlook may be accurate if you have no customers, no employees, no intellectual property, no business processes, and no shareholders or stakeholders — but that would also mean that you don’t have a business.

We can’t afford to hire a CISO, so we’ll put the engineer (or architect or administrator or system administrator) in charge of security.

Beware — this is at best a band-aid fix. In theory, this tactical approach might work in the short term, but as a long-term approach, there will be an overemphasis on tools and tactics and not enough on people and process.

Engineers, architects, and administrators have specific skill sets and responsibilities for managing technical outcomes. In practice, you need a dedicated, focused role to guide the program and ensure, over time, a shift to a more strategic approach that can be communicated to business leaders with the appropriate level of business context.

A virtual CISO can help by sitting outside the tactical day-to-day activities. From there, they can provide vision and guidance to drive a more programmatic approach, which clarifies the scope of the program. This then begins the shift toward a more proactive approach to security and risk management.

WRITE FOR CISO MAG

Do you want to write for CISO MAG? Please read our guidelines here.


About the Author

Jeffrey Wheatman is a Research VP in Gartner Research. He regularly advises clients on a wide range of security and IT risk management issues, with a focus on strategy, team building, metrics, and reporting, communicating techniques, and risk management. As an experienced analyst within Gartner’s S&RM team, he works with senior security and risk management leaders to help them identify, assess and treat IT-related risks within their environments.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

How Automation Can Protect Against Data Breaches

Panasonic network breach

The digital era is awash with potential threats including malware, spyware, ransomware, and denial of service attacks that threaten the security of workplaces everywhere. To ensure security, organizations use multiple protocols including encryption, authentication, and firewalls to safeguard crucial information against hacking and breaches. Several threats can be controlled by having such measures in place.

By Geeman Yip, CEO, BitTitan   

However, one compromised account can throw everything into chaos and open the door to countless attacks and data losses. Cyberattacks across industries have placed critical information at constant risk, increasing the need for cybersecurity protection.

The Data Security Council of India (DSCI) estimated that the cybersecurity market will grow from US$1.97 billion to US$3.05 billion by 2022, at a CAGR of 15.6 percent. This will be supported by increased digitalization, as well as an increase in cyberattacks. In India, data breach incidents have been on the rise. According to data gathered by the Ministry of Electronics and Information Technology, 696,938 cybersecurity incidents have been reported as of August 2020.

The effects of these data breaches impact the reputations and sales of organizations when the public and partners loses confidence. However, loss of public trust is not the sole source of cost. Post-breach forensic analysis can also be expensive. Organizations need better risk and cost management strategies to address these issues.

Traditional security is reactive. A firewall can stop a virus and a login screen can require a complex password, but neither give a user the details necessary to prevent future attempts to breach the system. These excluded details might reveal critical intelligence in the war against cybercrime. For example, a business may discover that several employee login attempts originate from a location where it has no employees. Such login attempts likely originate from attackers attempting to gain access to employee accounts. Most enterprises would want to do something about the situation if made aware of it.

A hard-line stance would block all employee login attempts coming from this location, but other options are available. Multi-factor authentication targeted application security, and other defenses can be tailored to a specific region. An enterprise may also want to reset and strengthen passwords in response to an upsurge in suspicious login attempts. Adding login attempt limits further reinforces system security against brute-force attacks. Organizations that are prepared have many options. However, no action can be taken if an enterprise isn’t made aware of the problem.

How can an enterprise acquire the information it needs?

In this example, an enterprise may have needed a specialist to determine the location of the login information, if it could be found at all. Once the specialist compiled all the login details, they would need to identify the region from which the false login attempts originated. This was a complicated, time-consuming process rife with human error that often saw results pushed to the bottom of the priority list, overlooked, or dismissed entirely.

Automating security allows vital data, such as the location of suspicious login attempts, to be tracked without the need for a costly and time-consuming campaign. Without writing code, an enterprise can receive detailed login records with the press of a button. Armed with data free of human error, there can be no doubt about the scale of the mysterious logins. Automation can also assess multi-factor authentication enablement to further harden system security against false logins. When an enterprise with an automated platform notices suspicious login attempts, it can respond quickly.

The transformation from manual processes to agile automation processes is rapidly taking place. Several studies conclude that automation has been successful at reducing the lifecycle of a data breach and the expenses associated with it. When businesses automate end-to-end standard operating procedures across systems, they can create uniformity and repeatability of IT tasks. Even partial implementation of security automation can reduce the cost by tens of thousands of dollars. Protecting systems from illegitimate login attempts is just one small part of those numbers. With secured data, organizations will be able to boost innovation and productivity in the long run as they regain control over critical information.

Automation not only reduces the cost of attacks but increases enterprise awareness of risk. The old maxim “knowledge is power” has never been more relevant, and businesses need to be empowered with an efficient security automation platform to be prepared for illegitimate login attempts and other significant security incidents.


About the Author

Geeman Yip is the Founder and Chief Executive Officer of BitTitan, guiding the aggressive growth and execution of all strategic company initiatives. He has over two decades’ of experience in the software and IT spaces, including email services, identity management, telephony systems, and business productivity applications. Geeman holds a bachelor’s degree in Information and Computer Science from the University of California, Irvine, and is the author of multiple U.S. software patents.

Disclaimer

Views expressed in this article are personal. The facts, opinions, and language in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Double Whammy: Meet Ransomware 2.0

ransomware

Ransomware operators and their ransomware attacks are becoming more rampant and successful than ever. Ransomware groups are always leveraging a combination of factors to easily obtain access to corporate networks and demand high ransom. With the rise of ransomware-as-a-service, cybercriminals are getting more involved in ransomware attacks.

According to a recent analysis from F-Secure, double extortion ransomware attacks increased drastically in 2020. Today, most of the ransomware operators are also stealing data from organizations and threatening to post it on the darknet with double extortion tactics.

Double-Extortion

In a double-extortion approach, ransomware operators initially steal data before encrypting it and demand ransom. Later, the attackers threaten victims by leaking the stolen data on the dark web for additional ransom.

F-Secure’s researchers stated they have found a new kind of extortion dubbed Ransomware 2.0 that has been growing significantly from 2019. The double extorsion technique involves threat actors stealing critical information from targeted organizations in addition to encrypting files. This means, along with demanding a ransom, attackers can threaten victims to expose the compromised data if an additional ransom is not paid.

Spread of Ransomware Families

Researchers observed over 15 different ransomware families using a double-extortion approach to target organizations. Besides, nearly 40% of ransomware families discovered last year utilized this Ransomware 2.0 method. The major active ransomware families using the double-extortion method include Ragnar Locker, Doppelpaymer, Clop, Conti, and ChaCha.

“The Maze ransomware group was the first to do this in late 2019. But by the end of 2020, this approach was being used by 15 different ransomware families,” F-Secure said.

 Key Findings

  • Attackers using Excel formulas – a default feature that cannot be blocked – to obfuscate malicious code tripled in the second half of 2020.
  • Outlook was the most popular brand spoofed in phishing emails, followed by Facebook Inc. and Office365.
  • Nearly three-quarters of domains used to host phishing pages were web hosting services.
  • Email accounted for over half of all malware infection attempts in 2020, making it the most common method of spreading malware in ransomware attacks.
  • Malware that automatically collects data and information from victims (infostealers) continues to be a threat; the two most prevalent malware families in the latter half of 2020 were both infostealers (Lokibot and Formbook).

“In recent years, the trend in ransomware attacks has been to move away from entirely automated attacks to more manual hands-on keyboard intrusions. Ransomware groups are also qualifying victims and looking to boost profits by ensuring maximum damage is done. These intrusions have significant commonalities in tooling and malware usage with other crimeware intrusions,” F-Secure added.

 Related Stories:

Cybercriminals Make Twitter a Playing Field to Target Indonesian Banks

Twitter hack

Cybercriminals have been putting an added strain on the financial sector for the past few years. A report in November 2020, showed that 65% of the financial services firms suffered a cyberattack last year. However, the majority of these cyberattacks originated from phishing or ransomware attacks. But it seems like the new year has brought in a new methodology of attacks in the cybercrime world. A cyber intelligence report from Group-IB, a global threat hunting company, has found traces of an ongoing fraudulent campaign based on Twitter targeting Indonesia’s largest banks.

The Massive Cybercriminal Campaign

To lure and gain the trust of its victims, cybercriminals are posing as bank representatives or customer support team members on Twitter and laying the booby trap. This massive campaign, which began in January 2021, has already ballooned 2.5-fold (from 600 in January) to a total of 1,600 fake Twitter accounts impersonating banks, until early March.

Digging deep, the security analysts found evidence of at least seven large Indonesian financial institutions that have been targeted under this campaign. The scam affects over two million Indonesian bank customers who are active on the legitimate bank handles on Twitter. Upon discovery of this fraud, Group-IB has informed the banks impacted so that they take the necessary steps to remedy the situation.

The Modus Operandi

Indonesian Banks
Image Credit: Group-iB

Cybercriminals zero down on their victims after a bank customer asks a question or leaves their feedback on the bank’s official Twitter page. They are then promptly contacted by fraudsters who use fake Twitter accounts with a profile photo, name, header, and description, identical to those of the real ones. After engaging in a talk with the victim, attackers soon invite them to take the conversation off-line on a third-party messenger – WhatsApp or Telegram. Furthermore, fraudsters send the bank customers a link asking them to log in there for solving their problem through a complaint. The link redirects to a phishing website identical to the official one. Once they enter their online banking credentials, which include username, email, and password, cybercriminals exfiltrate this data.

Twitter Chats of Fraudsters targeting Indonesian Banks
Image – Scammers contacting potential victim from a fake Twitter account; Image Credit: Group-iB

Group-IB DRP analysts have recorded similar attempts of implementing a fraudulent scheme on other social media channels, like Facebook, however, the number of such cases is insignificant compared to Twitter.

Ilia Rozhnov, Group-IB head of Digital Risk Protection in APAC, said, “The case with the Indonesian banks shows that scammers have managed to solve one of the major challenges of any attack — the issue of trapping victims into their scheme. Instead of trying to trick their potential victims into some third-party website, cybercriminals came to the honey hole themselves. This campaign is consistent with a continuous trend toward the use of multistage scams, which helps fraudsters lull their victims. They become successful due to the lack of comprehensive digital asset monitoring by financial institutions.”

How to Identify such Scams

The fact that the fraudulent scheme begins on the bank’s official Twitter account makes it challenging for a victim to identify it. To avoid being a victim, one should carefully check the account they are being contacted from. The majority of known brands have verified accounts on social media. If the account does not have “verified” status, then you can check the account’s ID and map it with the ID mentioned on the company’s official website. Also, look out for any phishing links. Spend some extra seconds to check if the link you are going to click is identical to the domain of the official website. Fraudsters often register domain names mimicking official ones, changing one letter in it, or adding a punctuation mark. As rightly suggested by the Group-IB’s DRP team, “The critical examination of any website on which you plan to enter your data is a habit that must be developed by everyone willing to keep their money safe.”

Related News:

Group-IB Finds Half a Million Credit Cards of Indian Banks on Darknet

The Pandemic-hit World Witnessed a 150% Growth of Ransomware

Fleeceware Apps Continue to Deceit Consumers; Scammers Earn S400 Mn

Fleeceware Applications

Cybersecurity experts discovered hundreds of fleeceware mobile applications on the Apple Store and Google Play Store tricking thousands of unwitting users into paying unnecessary subscription fees. Security researchers from Avast found over 204 fleeceware apps with nearly a billion downloads. Threat actors reportedly earned around $400 million by spreading fleeceware apps on different app markets.

Avast’s Findings  

  • Nearly 134 apps were spotted on the iOS platform, which had 500 million downloads with projected revenues of $365 million.
  • Around 70 fleeceware apps have been identified with 500 million downloads with projected revenues of $38.5 million on Google Play Store.
  • Most fleeceware apps are circulated as astrology, horoscopes, musical instrument apps, QR code/PDF document scanners, cartoon creation, palm readers, image editors, camera filters, fortune tellers, QR code and PDF readers, video clip editing apps, and slime simulators.
  • Users are charged as much as $66 per week, totaling $3,432 per year. Most of the discovered applications range from $4 to $12 per week, which equates to $208 to $624 per year.

“With nearly a billion downloads and hundreds of millions of dollars in revenue, this model is attracting more developers and there is evidence to suggest several popular existing apps have updated to include the free trial subscription with high recurring fees. Unfortunately, this endeavor can be lucrative even if a small percentage of users fall victim to fleeceware,” Avast said.

What are Fleeceware Apps

“Fleeceware” is a term introduced by SophosLabs in September 2019. It has been named fleeceware due to its defining characteristic of overcharging users for functionality that is widely available in free or low-cost apps. Though these apps do not cause harm to the victims’ devices or data, they trick users into a free trial and later overcharge them through subscriptions and simply perform fleeceware scams.

How Fleeceware Apps work

Typically, fleeceware apps target individuals who are not familiar with subscriptions on mobile devices. The apps charge them even after they’ve deleted the apps from the device.

  • Fleeceware apps lure consumers with a promise of a free three-day trial.
  • The apps attach a subscription fee that commences at the end of the trial.
  • Once the trial is over, the user is charged a recurring high subscription fee, which eventually goes to malicious app developers.

These apps continue to take advantage of consumers and charge from their saved cards, even after they have deleted the offending apps. It is also believed that these malicious apps are gaining popularity by advertising on various social media platforms such as Facebook, Instagram, and TikTok.

“Uninstalling the application doesn’t cancel the subscription — as a result, the user is likely to be charged further until they cancel the subscription within their device’s app market settings. There’s also the possibility that users forget to cancel the free trial, resulting in inexpensive fees. Either way, these scams make use of deceptive behavior that relies on the user not being informed about how subscriptions work and draw them into the scheme through a free trial,” Avast added.

Fleeceware App Prevention

Avast researchers recommended certain security measures to stay cautious about fleeceware apps. These include:

  • Be careful with free trials of less than a week
  • Read the fine print
  • Be skeptical of viral advertisements
  • Shop around
  • Secure your payments
  • Discuss the dangers of fleeceware with your family

What to do if you fall victim to fleeceware apps?

 On iOS platform

  • Open settings
  • Tap on your Name
  • Select the Subscription option
  • Select the desired subscription that you want to end
  • Tap on the cancel subscription

 On Android platform

  • Open Google play store
  • Check whether you are signed in with the correct Google account
  • Select the Three Lined menu from the upper right corner
  • Select the subscription that you want to cancel
  • Tap on the cancel subscription option

Is Automated Vulnerability Remediation the Answer?

Optiv automated vulnerrability remediation guide

What is your mean time to remediate (MTTR). Unless you’re measuring it in minutes, it’s too long. Is automated remediation the answer? We understand being cautious about a new “process.” But what if you knew, before diving in, where time savings are and how to start? In this field guide, Optiv tackles automated remediation, including six use cases with time saved. From your ancient, time-consuming process to one that leverages new change management processes and recent technological advances, read on to evolve.

SPONSORED CONTENT

What are Common Vulnerability Remediation Delays?

What’s slowing you down? Usually one of two issues. The first can be mechanical – perhaps your organization lacks the technology to automatically distribute patches across all its assets. The second is more cultural and related to change management policy or the processes and procedures that your organization has to minimize the risk of disruption during production changes. This field guide can help you manage both of these and accelerate your response.

The Guide: Automated Remediation Areas Covered

At a high level, “remediation” generally means the required actions to eliminate a security vulnerability. But, designing a solution to solve remediation automation’s technical complexities can be challenging. In this field guide, we look at the various unique-to-your-environment steps you can take. You’ll find topics like mapping the environment, automated remediation solution types, and automation in action to help you build your solution path.

How you manage existing asset types directly affects approaches and the types of solutions employed. You need a highly detailed view of the environments in your vulnerability management program’s scope. Since you’ll be following an automation path, you’ll need a way to interface with the assets in question and determine which solutions or technologies are in play.

Evaluating automated vulnerability remediation solutions can be tricky: it hasn’t been treated as a separate category by the industry and analysts. Your foundation – The solution shall identify the appropriate remediation action based on identifying a vulnerability and providing a mechanism for the remediation action to be triggered.

Why automate the remediation process? To reduce the vast window of opportunity for attackers. Your vulnerability remediation program could be entirely self-guiding or contain built-in human oversight with the same impact as self-guided. To make this strategy viable across many organization types, you’ll need to account for blocking factors that would interfere with faster remediation.

Evolve from a time-consuming process to one that leverages new processes and recent technological advances. Get your guide – and get started today.