Friday, February 3, 2017

American Cybersecurity article by Pew Research Center

We care but don’t really care to do that much about it?“Many Americans expect that the coming five years will see significant cyberattacks on the country’s public infrastructure and financial systems. Fully 70% of Americans expect that the United States will definitely (18%) or probably (51%) experience a significant cyberattack on its public infrastructure (such as air traffic control systems or power grids).”
Men generally think about major cyberattacks is forthcoming on infrastructure/financial systems than woman but”Americans’ views on this subject do not differ substantially across demographic groups”.

Common “fear they have lost control of their personal information…many worry whether government agencies and major corporations can protect the customer data” perhaps due to “majority of Americans have directly experienced some form of data theft or fraud”.  However,
“many Americans are failing to follow digital security best practices in their own personal lives”.
64% have personally experienced major data breach and 49% feel personal info is less secure than 5 years ago but “despite their concerns and experiences, most Americans do not express profound worries about cybersecurity in their personal lives or in their expectations for various public institutions”.

Some Status from the study:
  • 41% of Americans have encountered fraudulent charges on their credit cards
  • 35% have received notices that some type of sensitive information (like an account number) had been compromised
  • 16% say that someone has taken over their email accounts, and 13% say someone has taken over one of their social media accounts
  • 15% have received notices that their Social Security number had been compromised
  • 14% say that someone has attempted to take out loans or lines of credit in their name
  • 6% say that someone has impersonated them in order to file fraudulent tax returns
All told, 64% of Americans maintain at least one of the online accounts listed above. College graduates and those with higher household incomes are especially likely to report having all four types of online accounts:
  • 55% of Americans report having an online account with banks or other financial service providers.
  • 36% have an online account with household utility providers.
  • 32% have an online account with their healthcare providers.
  • 39% have some other kind of online account that involves bill payments or transactions.
Regarding our infamous topic - Passwords:
  • 41% of online adults have shared the password to one of their online accounts with a friend or family member
  • 39% say that they use the same (or very similar) passwords for many of their online accounts
  • 25% admit that they often use passwords that are less secure than they’d like, because simpler passwords are easier to remember than more complex ones
  • Topic of encryption – national divide:
  • 46% believe that the government should be able to access encrypted communications when investigating crimes (often Republicans), while 44% believe that technology companies should be able to use encryption tools that are unbreakable even to law enforcement (typically Democrats and younger adults)
  • 52% of online adults have used two-factor authentication on their online accounts – but a substantial minority use similar passwords across many sites or share passwords with others
Trust in key institutions to protect data is also divided.  Ages over 50, express less protection (58%) (and are likely to use the same passwords) while under 50 (24%) say data more secure than 5 years ago “(and are also like to share passwords) But even so, a plurality of 18- to 49-year-olds (41%) feel their data are less secure now than in recent years.”
Maybe a topic of similarity between the ages is “More than one-quarter of smartphone owners do not use a screen lock, and many fail to regularly update the apps or operating system on their phones”
Also, on public Wi-Fi, 66% use it but only few 20% use it for bank/shopping transaction.

Exhaustive/Comprehensive details on: http://www.pewinternet.org/2017/01/26/americans-and-cybersecurity/

Monday, January 23, 2017

C-Level view - Global Application and Network Security Report

Radware's report:
  • C-suit cybersecurity awareness is up with 95% expressing important priority and 82% stating on CEO concern
  • With uncertainty, spending is up. Maybe (in)directly related by numbers show 2/3 of executives reported 10%-59% increase in cybersecurity spend last year (72% bought into cyber insurance and 42% implemented stricter security policies for telecommuting).
  • C-level may not be engaged in every breach (ransomware up from 16 to 25% in a year) visitbity is up with 54% admitted to paying ransom averaging $7500 in the US and 22K Euro.
  • Jobs for ex-hackers are on the rise with 23% of respondents leverage their skills and another 36% would do the same.  In addition, automated model and alerting has spiked to 40% over the last couple years and continues to grow.
  • Of course IoT and network infrastructure is a top concern with device takeovers and bots prevalent on a wide scale.  That said, security wearables policy have been in effect for about 2 years for almost half the respondents.
  • Over the last 2 year 44% have include suppliers and partners into the security process and another 33% will do so in the 2 years though 22% have not addressed. 
  • Greater emphasis are place in inbound/outbound packet inspection which is counterbalanced with increased SSL/encryption.
  • Impact of Security Threats on Business for Brand Reputation Loss averages 34% for US and UK and Operational Loss 31%, and Revenue Loss at 30%
  • Importance of thwarting security threats total 35% being changes to technology, followed by changes C-Level awareness at 33%, education/knowledge 32% and change in process at 28%
Refer to source for full details
https://www.radware.com/newsevents/pressreleases/execs-wont-pay-ransom-attacks-til-hacked/

Friday, January 20, 2017

40% spike in U.S. #DataBreach in 2016


1,093 from 780 from prior year with business sector topping the charts at 45.2% overall, followed by healthcare/medial industry with 34.5%.  And 55.5% (up from 17.7%) were related to hacking/skimming/phishing attacks.  Predominate were DEO spear phishing with related events to ransomware and SSN exposures.  Of course, the notification requirements may have trigger some but taking threshold for notification comes to balance out.
<source helpnetsecurity.com>

Monday, January 2, 2017

Top 2016 security breaches

2016 cybersecurity root cause:


·         #IAM - Unauthorized access to laptop

·         #DDoS likely

·         Still to be determined - Weebly

·         #SDLC - malicious code

·         #ThirdParty possibly

·         #VTM - vulnerability in portal

·         #PhysicalTheft

·         Just bad #securityPractices |

·         #Encryption

·         #DLP email and inadvertent leak

 

http://www.readitquik.com/articles/networking-2/data-breaches-that-shook-2016/


1.       HPE Navy Breach: In October, a grave access issue came to light, as the Navy identified that an HPE laptop had been accessed by "unknown individuals"... 

2.       Patient data gets exposed: 21st Century Oncology: Cancer care provider, 21st Century Oncology was hit by a cyber-attack that exposed its patient information to the order of 2.2 million patients globally... 

3.       Website builder Weebly is attacked: The web hosting and website building site was hit by a hack in October. It affected more than 43.5 million accounts including user names, passwords… 

4.       Oracle – Micros credit card systems hacked: One of the biggest data breaches was revealed in August, when Oracle-Micros data systems underwent a data breach, allegedly by a well-known Russian organized cybercrime group...

5.       State Fishing and Hunting Licence sites: The wildlife sports sites of four states, namely Washington, Kentucky, Oregon and Idaho were hacked in August. Hackers got unauthorized access to the personal information of 6 million users, including their Social Security numbers..

6.       Verizon enterprises systems: Verizon became sitting duck, as a hacking group broke into its enterprise network and dug into customer data of about 1.5 million... 

7.       US Dept. of Health and Human Services: This was a physical theft, with a laptop and some portable hard drives being stolen from the public entity... 

8.       Myspace breach: 360 million accounts were illegally accessed, primarily those accounts which were created before June 11, 2013. The breach was a result of not so great security measures...

9.       Yahoo: Yahoo was the scapegoat of two horrendous hacks- one that started in 2014, and involved more than 500 million users; and the other in December, that led to more than 1 billion user accounts being hacked  somewhere in August 2013... 

10.   Democratic National Committee: This was the biggest of the big, with direct repercussions on the US Presidential Elections. Numerous leaked emails from the DNC found their way to public forum, WikiLeaks... 

Wednesday, December 28, 2016

Cybercrime: $400 Billion in 2015 to over $6 Trillion in 2021

…according to Herjavec’s Cybercrime Revelation Report.  With Black-Hat hackers getting faster, more experienced and highly motivated by money, espionage and notoriety.
Another $1 Trillion spend for cybersecurity products and service over the same time frame – yet consistent/increased in cybersecurity workforce shortage.  Interestingly, nearly 50% of cyberattacks are committed on small business but the battle is in cyberspace where all things connected being affected.  Apparently, 90% of corporate executive reported they are NOT ready for a major cyber-attack.  Records are being broken yearly with increased/doubled malware, identity theft, victim counts, zero-day; and the 5 most cyber-attacked industries: Healthcare, Manufacturing, Financial Services, Government and followed by Transportation.  Oh, there Ransomware which grew 300% in 2016…

While it’s a foregone conclusion that no one can stop hackers completely, digital growth (size, complexity, convenience/convergence, etc.) will ensure it’s a catch up or reactive game. Stats show 12 people fall victim every second which is 1 million victims in the world daily. Moreover, Herjavec relates it to football terms, bad guys running no-huddle, hurry up offense while good guys require a huddle before any actions takes place…in situations where speed is of the essence.  Of course, you don’t always see the other/bad guys and they don’t stand in front of you to attack but instead remotely and with no set playbook (or rules).

Breaches can sound like a broken record and unfortunately, so one of the biggest solution to help combat which is, security awareness – employee training for the weakest link 
But there is a list of 500 top/hot cybersecurity companies to watch 

Thursday, December 22, 2016

Medical Device Cybersecurity...account for 42% of reported/related data breaches

With an uptick in FDA scrutiny, emerging requirements & expectations on Manufacturing is taking a hit - according to IRTC (Identity Threat Resources Center) 

Maybe indirectly, but devices can harm patients through interconnected medical devices allowing access to data as well as operations, if not tapering with device programming.  Devices connect to hospital networks, patient devices and healthcare worker...so key factors must come into consideration:
Pre-Design: requirements that address security plans, risks and critical cyber-documentation
Design Process: Connectivity characteristics should be analyzed and incorporated from the start with appropriate mitigation decisions along the way. An early start can result in less expensive remediation or retrofitting efforts
Prototyping: Assessing and conduct penetration testing allows correction of errors or security loopholes in the application, system or its use, allowing vulnerability identification and remediation
Post-Market Updates: Maintenance upon release is key to updating security patches via a security method and vulnerability management lifecycle to address and dedicate resources in addressing threats
Response Disclosure Policy: Ability and social responsibility to allow for reporting of vulnerabilities without legal reprisals and clear internal polices/plans that address reporting, correcting and communication important flaws or defects.


Sunday, December 11, 2016

SAP Cyber Report by Ponemon Institute

Key takeaways from "Uncovering the risk of SAPcyber breaches":

- Executives value importance to bottom line but ignore cyber risks; 63% of Exec underestimate the risks and 23% know what data resides in SAP systems
- Average cost of it being off line is $4.5B
- Responsibility for security is conflicted by 62% say SAP not company so ownership issue
- 25% say NO one is response for SAP security, only 19% say SAP security team is accountable and 18% Information Security team
- Consistently over 50% say, difficult to secure SAP app, high level of malware concern, believe one or more malware infections likely
- Less than 49% have the expertise to prevent, detect and respond to cyber attacks
- Visibility into security of SAP application is only at 34%
- 30% say remediation of incident is unknown
- 75% say detection of breach would be undetected at least for a week; in the other hand, 53% say detection would be within 1 Year
- Malware infection is rated at 33% to be Very Likely and 42% to be Likely
- 47% say increased sophistication of attack in next couple years
- New technology increases risks, mobile, IoT
- Only 43% consider the cyber security risks when moving SAP application to the cloud
- 73% say knowledge of recent threats will help identify security risks and zero-day is a significant is a significant threat
- segregation of duty improves SAP security
- Consistently over 80% say achieving security in SAP infrastructure requires zero-day detection, prioritizing threats and monitoring 
- SAP app most susceptible to attack:
  64% content and collaboration
  56% data management
  50% CRM - customer relationship management
  48% technology platform
  37% ERP - enterprise management
  35% financial management
  33% supplier relationship management
  25% human capital management

And study stats: 607 final sample, 35% Technicians, 21% Managers, 17% Directors. 15% Supervisors; 18% Financial Services, 9% Manufacturing, 8% Public Sector, 8% Retail, 7% Healthcare

Wednesday, December 7, 2016

Continuing predictions of 2017 for cybersecurity

from KnowBe4
1) ARTIFICIAL INTELLIGENCE.
Everyone and their brother will claim that they have machine learning and/or AI as an offering and/or built into their product/platform, yours truly included. It's going to be marketing buzzword hell, because at the moment AI is not nearly as smart as people would like it to be, so buyer beware.
However...
Machine Learning and AI *will* move forward with lightning speed. Some of them will pass the Turing test. You will be able to talk to supportbots and not know if it is a human or not. You will also see fully programmable digital avatars going into commercial use.
2) BLOCKCHAIN
Micropayments and Blockchain applications will go mainstream in 2017. Mobile payments will grow massively, and apps will use "micro-payments" built on digital protocols like the Blockchain. Perhaps Blockchain will allow us to vote from our own devices in the next election. We will see the first smart contracts built on Blockchain.
Ransomware-as-a-Service will become a major threat vector, with a new technical feature using Blockchain to deliver the decryption keys after ransom payment.
3) BOARD ROOM
During 2016, boards of directors have realized that InfoSec risk management is an enterprise risk equivalent to financial, reputational, and legal risk. In 2017, there will be a raft of boards demanding a corporate security culture starting from the C-level down.
4) CEO FRAUD aka BUSINESS EMAIL COMPROMISE
CEO fraud was the up and coming cyberfraud scheme right after ransomware these last 12 months. During 2017 it will be an epidemic, equaling the ransomware plague we are suffering now. Remember the Nigerian prince scams? These cyber gangs are really in Nigeria, but they have climbed up in the criminal food chain and CEO fraud is their focus now. Train your high-risk users within an inch of their lives.
5) ESPIONAGE
During 2017 it will become apparent that espionage will turn out to have gone massively mobile and nobody knew about it. Revelations about both Android and iPhone devices will show they have had 0-days for several years and the NSA was able to own any device they wanted at any time.
6) INTERNET OF THINGS
A major outage caused by a purely malicious Botnet of Things like Mirai will prompt the new U.S. Administration to enforce IoT device security standards and require certification from device vendors.
7) MOBILE MALWARE
Mobile malware will continue to grow at an exponential rate. During 2017 tens of millions of smartphones will be infected with auto-rooting malware. New strains can embed themselves in a phone's bootloader and remain persistent even after factory reset. Scary.
8) OPEN SOURCE
In 2017 we will see a very high-profile data breach based on an open source vulnerability that was disclosed in...wait for it... 2012. The average age of an open source vulnerability in commercial applications is more than five years, and almost everyone is using Open Source these days. Ouch.
9) RANSOMWARE
We have seen exponential ransomware infections in 2016, and this trend will continue in 2017. There are close to 250 different families at this point, this will triple in the next 12 months.
Locky will be the first strain with 1 billion dollar in criminal revenues. Organized Eastern European cybercrime will continue to specifically target health care, education and local government with updated ransomware strains.
10) STATE SPONSORED HACKING
Look, we have a low-grade cyberwar and massive cyber arms-race going on. It's simmering and now and then it flares up, basically with proof-of-concept attacks, except for Stuxnet which was the real deal. In 2017 we may very well see the first major real-world damage caused by state-sponsored hacking.

Sunday, December 4, 2016

CISO Executive Summit 2016

With over 200 CISO / Security Leadership in attendance this past week, a great day of session / breakout forums, networking a few vendor product / services solutions…

 

Key-note theme began with Silver Olympic winner John K. Coyle presenting on Apply Design Thinking concept: consisting of Understand, Empathize, Ideate, and Prototype i.e. clearly understanding the problem and uniquely develop solution – brings you to focus on strength and merely working around weaknesses.

 

Other key takeaways:

- SaaS is the new development model – trending to reality

- SAP is the shadow IT with limited security visibility (gap in patching and flow/integration)

- Ransomware will happen (to anyone) so weigh price of recovery vs. paying ransom (and do tabletop exercise)

- Mobile End-Points increase threats particularly without multiple factor authentication / MDM strategy, so a little friction is not always bad

- Security controls should weigh in on IT Operational cost – it's a shift in duty / control

- Directed attacks cannot be stopped; so position for response/detection more than position for prevention

- Hunting or spot-audits is necessary though resource is a constraint

- Lead in 2 directions, being normal security controls as well as user experience / expectation 

- We cannot be the CI"no" (user-centric security)

 

 

And, for an industry cyber security survey roll-up of over 700 CISOs (over 50% from Finance, Retail, Healthcare), see attached; summary being:

- Top Threats: IP theft, 3rd-Party risk and Reputational harm

- Top Priorities: Detect/Respond to adversarial threats, Build Security Awareness Organization, Communicate risk to stakeholders, Apply Risk Mgmt. to Security Strategy and Protect Cloud data/app/infrastructure

- 6% of overall IT spend is on Security

- 59% of CISO budgets expect to increase (modestly or significantly) on Vul mgmt., Incident Response and Awareness


Monday, October 24, 2016

Welcome IoT (Internet of Things)

A Mirai botnet hacked into IoT's cameras and routers (according to Flashpoint) which targeted Dyn (large Domain Name Server – translates domain names to IP addresses via hierarchical manner) with a Distributed Denial of Service (DDoS).  Ultimately rendering major websites off line including: Twitter, Spotify, Reddit, NY Times, Pinterest, PayPal, etc.  This same Mirai attack is the same that affect Brian Krebs website last month with packets/traffic peaking at 620 Gbps…with this recent case of internet vandalism as per U.S. intelligence reported by NBC News.

The Mirai source open-source code had been released to the public which showed itself in multiple waves on October 21 with the first approx.. 6:10am and the third realized around 2:30PM CST and lasted/resolved approx. 5:15pm.  While DDoS is not new to the industry/Internet, it becomes more persuasive in the industry with connected devices – particularly with default login or management/SNMP credentials… DDoS can come in flavors of simply flooding your routers or devices with too many packets that it simply cannot process, and more commonly are packets sent to obtain acknowledgement (e.g. TCP handshake, GET requests) with further overwhelms bandwidth and processing congestion.  And, the more sophisticated is this Mirai type which makes your individual PC become a DNS server which further floods the internet with bogus requests and response for name/IP requests.

Point being, early detection via monitoring network/bandwidth spikes can offer good triggers for your environment.  Also, obtaining high-capacity server and/or configuring scrubbing filters to prevent large traffic spikes (for at least tapering the slowdown); and finally opt for out-of-band connection from your hosting provider or a Content Delivery Network (CDN) for your company's primary websites. Not bullet proof but some counter measures.

Thursday, August 18, 2016

Some notable hacks reported since my last post

But first, news related to the Shadow Brokers posting keys-to-the-kingdom:
WHAT IF the National Security Agency’s topgun hacking tools/code were exposed on the Internet?  Reports indicate that TAO (Tailored Access Operations) members of the agency’s hacking division seem to point to legitimacy of the code (related to zero-day and other coding flaws) that potentially exposes commercial name firewalls such as Cisco and Fortinet – used by government and large corporations.
A group calling themselves the Shadow Brokers used BitTorrent nd DropBox to deliver the content and is auctioning off the rest of the code to the highest bidder.  Hacker hoax, diversion tactics by whom, oops/mistaken upload, political opportunity….we’ll see
Source: washingtonpost.com 

And from privacyrights.org, at least August's list of reported hacks which contains mostly medical-type of data exposed/unauthorized access – interesting

  • HEI Hotels & Resorts (Marriott, Starwood, Sheraton, Westin) – Payment processing systems breach in several states and District of Columbia – total records unknown/not reported yet
  • John Gonzales DDS – Stolen briefcase with external hard drive with patient records (SSN, DL, DOB, Health info) – total records unknown/not reported yet [July]
  • Bon Secours Health System – Files inadvertently left visible/accessible via Internet totaling 655K patients (containing names, health insurance ID, SSN, clinical info) [April]
  • Valley Anesthesiology & Pain Consultants – Medical information along with SSN may have been compromised via 3rd-party [June]
  • Prosthetic & Orthotic Care, Inc. – Medical, cyberattack of 23K+ records [June]
  • Autism Home Support Services – Medical, unauthorized access of 533 records 
  • Brian D. Halevia-Goldman MD – Medial, 2 laptops stolen resulting in 2K+ records [July]
  • Professional Dermatology Care PC – Medical, unauthorized access of 13K+ records
  • Oracle’s MICROS PoS – Retail and Bank information, via customer support portal and over 700 infected systems
  • Newkirk Products – Health insurance via cybersecurity incident
  • 7-Eleven – Personal employee data via database [June]
  • Center for Minimally Invasive Bariatric and General Surgery – Medical data of unauthorized access reported by HHS
  • Banner Health – Medical information through unauthorized access on server

Thursday, July 7, 2016

Leadership for Managers – succinct version

A 10 week Dale Carnegie class condense into 3 days…and the upshot is below – by virtue of 1-liners
  1. Set a VISION – without boundaries and is believable…and don’t put a timeframe since you may need to roll forward new things
  2. SMART goals are specific and measurable – and perfection should not be a goal
  3. LEADERS will reflect on what’s not working and adapt a plan to fit it
  4. Drivers for SUCCESS
    • Self-Direction, People, Skills, Process Skills, Communication, and Accountability
  5. Your MESSAGE: 
    • What I say counts for 7% 
    • How I say it (tone) counts for 38% 
    • What I do when I say it (body language) counts for 55%
  6. EMOTION is the single factor that drives thinking and alters decision
  7. Cycle of growth equates primarily to ATTITUDE and is the performance metric, otherwise the difference is called motivational gap
  8. MOTIVATION is single more important driver for effectiveness
    • Apply Maslow’s Hierarchy of Needs (Survival, Safety, Belongingness, Esteem, Self-Actualization) to the other person 
  9. COACHING using GROW 
    • Goal – Clarity with specificity 
    • Reality – self-reflection of today
    • Options – what to change to get there and why
    • Way Forward – prioritization and follow-up
  10. FAIRNESS is based on: Assurance, Belief, Relationship, Identity, and Control
  11. Understand areas of INFLUENCE and control the areas you have DIRECT CONTROL (anything else any be ignored)
  12. BUSY WORK is a waste of time/effort!  Time used will never get back
  13. Good FEEDBACK should be given by itself – Bad feedback does not necessary have to be sandwiched (between good)
  14. BELIEVE in yourself – never question what leadership looks like, it’s YOU
  15. Practice DRILLING – for factual details and ask WHY e.g. Why is it important to you or someone else
  16. Planning Process: Desired Outcome, Current Situation, Goals, Action Steps, Time Frames, Resources, Obstacles and Contingencies, and Tracking and Measurement
  17. I will remember others’ NAMES, only if I say/believe, I will (because it’s important to you)
  18. Our VALUES are our believe system – which drives our behavior so how one behaves speaks to their real values
    • Our perception of values might change but who we are do not
  19. Have a meaningful conversation, storytelling and injecting WHY - To learn about the situation and appreciating the other person 
  20. Understand and apply what’s most important to your organization, direct manager and to yourself i.e. Time, Cost or Quality trifecta / dimensions
  21. The Innovation Process: Visualization, Fact Finding, Problem OFI Finding, Idea Finding, Solution Finding, Acceptance Finding, Implementation, Follow-up, Evaluation
  22. Presentation effectiveness is rooted from personal SELF-CONFIDENCE and based on individual experiences
  23. LEADERSHIP involves people while MANAGERS involve processes
    • Lead the People, Manage the System
  24. Without managing your TIME properly, nothing else can be managed, Tyranny of the Urgent
  25. Employee ENGAGEMENT circles around: Pride in the organization, Belief in senior management and Satisfaction with Immediate Manager
  26. Problem solving TOOLS – Google it :)
    • Affinity Diagram
    • 4 Problem solving questions (What is, Cause, Possible and Best Solution)
    • Criteria method 
  27. DELEGATION Process: Select the person, Identify the need, plan the Delegatin, Hold a delegation meeting, Create a plan of action, Review the plan, Implement the plan, and Follow up
  28. Delegation to DEPUTIZING is truly giving total ownership and letting the other prosper
  29. PRAISE includes: Context, Specifics, Impact, Identity, Congratulate
  30. COUNSEL includes: Context, Specific, Impact, reinforcement, Seek Solutions
  31. FILTERS exist in all communication e.g. environment, assumptions, cultural, distortion becomes reality
  32. Right approach to handling MISTAKES: Research, Rapport, Reference, Restore, Reassure and Retain - otherwise Restate, reinforce, Replace
  33. Be Self-awareness
More to come...till then Plan-Do-Action based on Dale Carnegie's Golden Book