spotlight with Rich (Latayan360@Outlook.com) - espresso to Security Business Leadership - splash of key note speaker @CISOmd
Friday, February 3, 2017
Cisco 2017 Annual Cybersecurity Report
American Cybersecurity article by Pew Research Center
Men generally think about major cyberattacks is forthcoming on infrastructure/financial systems than woman but”Americans’ views on this subject do not differ substantially across demographic groups”.
Common “fear they have lost control of their personal information…many worry whether government agencies and major corporations can protect the customer data” perhaps due to “majority of Americans have directly experienced some form of data theft or fraud”. However,
“many Americans are failing to follow digital security best practices in their own personal lives”.
64% have personally experienced major data breach and 49% feel personal info is less secure than 5 years ago but “despite their concerns and experiences, most Americans do not express profound worries about cybersecurity in their personal lives or in their expectations for various public institutions”.
Some Status from the study:
- 41% of Americans have encountered fraudulent charges on their credit cards
- 35% have received notices that some type of sensitive information (like an account number) had been compromised
- 16% say that someone has taken over their email accounts, and 13% say someone has taken over one of their social media accounts
- 15% have received notices that their Social Security number had been compromised
- 14% say that someone has attempted to take out loans or lines of credit in their name
- 6% say that someone has impersonated them in order to file fraudulent tax returns
- 55% of Americans report having an online account with banks or other financial service providers.
- 36% have an online account with household utility providers.
- 32% have an online account with their healthcare providers.
- 39% have some other kind of online account that involves bill payments or transactions.
- 41% of online adults have shared the password to one of their online accounts with a friend or family member
- 39% say that they use the same (or very similar) passwords for many of their online accounts
- 25% admit that they often use passwords that are less secure than they’d like, because simpler passwords are easier to remember than more complex ones
- Topic of encryption – national divide:
- 46% believe that the government should be able to access encrypted communications when investigating crimes (often Republicans), while 44% believe that technology companies should be able to use encryption tools that are unbreakable even to law enforcement (typically Democrats and younger adults)
- 52% of online adults have used two-factor authentication on their online accounts – but a substantial minority use similar passwords across many sites or share passwords with others
Maybe a topic of similarity between the ages is “More than one-quarter of smartphone owners do not use a screen lock, and many fail to regularly update the apps or operating system on their phones”
Also, on public Wi-Fi, 66% use it but only few 20% use it for bank/shopping transaction.
Exhaustive/Comprehensive details on: http://www.pewinternet.org/2017/01/26/americans-and-cybersecurity/
Monday, January 23, 2017
C-Level view - Global Application and Network Security Report
- C-suit cybersecurity awareness is up with 95% expressing important priority and 82% stating on CEO concern
- With uncertainty, spending is up. Maybe (in)directly related by numbers show 2/3 of executives reported 10%-59% increase in cybersecurity spend last year (72% bought into cyber insurance and 42% implemented stricter security policies for telecommuting).
- C-level may not be engaged in every breach (ransomware up from 16 to 25% in a year) visitbity is up with 54% admitted to paying ransom averaging $7500 in the US and 22K Euro.
- Jobs for ex-hackers are on the rise with 23% of respondents leverage their skills and another 36% would do the same. In addition, automated model and alerting has spiked to 40% over the last couple years and continues to grow.
- Of course IoT and network infrastructure is a top concern with device takeovers and bots prevalent on a wide scale. That said, security wearables policy have been in effect for about 2 years for almost half the respondents.
- Over the last 2 year 44% have include suppliers and partners into the security process and another 33% will do so in the 2 years though 22% have not addressed.
- Greater emphasis are place in inbound/outbound packet inspection which is counterbalanced with increased SSL/encryption.
- Impact of Security Threats on Business for Brand Reputation Loss averages 34% for US and UK and Operational Loss 31%, and Revenue Loss at 30%
- Importance of thwarting security threats total 35% being changes to technology, followed by changes C-Level awareness at 33%, education/knowledge 32% and change in process at 28%
https://www.radware.com/newsevents/pressreleases/execs-wont-pay-ransom-attacks-til-hacked/
Friday, January 20, 2017
40% spike in U.S. #DataBreach in 2016
1,093 from 780 from prior year with business sector topping the charts at 45.2% overall, followed by healthcare/medial industry with 34.5%. And 55.5% (up from 17.7%) were related to hacking/skimming/phishing attacks. Predominate were DEO spear phishing with related events to ransomware and SSN exposures. Of course, the notification requirements may have trigger some but taking threshold for notification comes to balance out.
<source helpnetsecurity.com>
Monday, January 2, 2017
Top 2016 security breaches
2016 cybersecurity root cause:
· #IAM - Unauthorized access to laptop
· #DDoS likely
· Still to be determined - Weebly
· #SDLC - malicious code
· #ThirdParty possibly
· #VTM - vulnerability in portal
· #PhysicalTheft
· Just bad #securityPractices |
· #Encryption
· #DLP email and inadvertent leak
http://www.readitquik.com/articles/networking-2/data-breaches-that-shook-2016/
1. HPE Navy Breach: In October, a grave access issue came to light, as the Navy identified that an HPE laptop had been accessed by "unknown individuals"...
2. Patient data gets exposed: 21st Century Oncology: Cancer care provider, 21st Century Oncology was hit by a cyber-attack that exposed its patient information to the order of 2.2 million patients globally...
3. Website builder Weebly is attacked: The web hosting and website building site was hit by a hack in October. It affected more than 43.5 million accounts including user names, passwords…
4. Oracle – Micros credit card systems hacked: One of the biggest data breaches was revealed in August, when Oracle-Micros data systems underwent a data breach, allegedly by a well-known Russian organized cybercrime group...
5. State Fishing and Hunting Licence sites: The wildlife sports sites of four states, namely Washington, Kentucky, Oregon and Idaho were hacked in August. Hackers got unauthorized access to the personal information of 6 million users, including their Social Security numbers..
6. Verizon enterprises systems: Verizon became sitting duck, as a hacking group broke into its enterprise network and dug into customer data of about 1.5 million...
7. US Dept. of Health and Human Services: This was a physical theft, with a laptop and some portable hard drives being stolen from the public entity...
8. Myspace breach: 360 million accounts were illegally accessed, primarily those accounts which were created before June 11, 2013. The breach was a result of not so great security measures...
9. Yahoo: Yahoo was the scapegoat of two horrendous hacks- one that started in 2014, and involved more than 500 million users; and the other in December, that led to more than 1 billion user accounts being hacked somewhere in August 2013...
10. Democratic National Committee: This was the biggest of the big, with direct repercussions on the US Presidential Elections. Numerous leaked emails from the DNC found their way to public forum, WikiLeaks...
Wednesday, December 28, 2016
Cybercrime: $400 Billion in 2015 to over $6 Trillion in 2021
Thursday, December 22, 2016
Medical Device Cybersecurity...account for 42% of reported/related data breaches
Sunday, December 11, 2016
SAP Cyber Report by Ponemon Institute
- Executives value importance to bottom line but ignore cyber risks; 63% of Exec underestimate the risks and 23% know what data resides in SAP systems
- Average cost of it being off line is $4.5B
- Responsibility for security is conflicted by 62% say SAP not company so ownership issue
- 25% say NO one is response for SAP security, only 19% say SAP security team is accountable and 18% Information Security team
- Consistently over 50% say, difficult to secure SAP app, high level of malware concern, believe one or more malware infections likely
- Less than 49% have the expertise to prevent, detect and respond to cyber attacks
- Visibility into security of SAP application is only at 34%
- 30% say remediation of incident is unknown
- 75% say detection of breach would be undetected at least for a week; in the other hand, 53% say detection would be within 1 Year
- Malware infection is rated at 33% to be Very Likely and 42% to be Likely
- 47% say increased sophistication of attack in next couple years
- New technology increases risks, mobile, IoT
- Only 43% consider the cyber security risks when moving SAP application to the cloud
- 73% say knowledge of recent threats will help identify security risks and zero-day is a significant is a significant threat
- segregation of duty improves SAP security
- Consistently over 80% say achieving security in SAP infrastructure requires zero-day detection, prioritizing threats and monitoring
- SAP app most susceptible to attack:
64% content and collaboration
56% data management
50% CRM - customer relationship management
48% technology platform
37% ERP - enterprise management
35% financial management
33% supplier relationship management
25% human capital management
And study stats: 607 final sample, 35% Technicians, 21% Managers, 17% Directors. 15% Supervisors; 18% Financial Services, 9% Manufacturing, 8% Public Sector, 8% Retail, 7% Healthcare
Wednesday, December 7, 2016
Continuing predictions of 2017 for cybersecurity
Everyone and their brother will claim that they have machine learning and/or AI as an offering and/or built into their product/platform, yours truly included. It's going to be marketing buzzword hell, because at the moment AI is not nearly as smart as people would like it to be, so buyer beware.
However...
Machine Learning and AI *will* move forward with lightning speed. Some of them will pass the Turing test. You will be able to talk to supportbots and not know if it is a human or not. You will also see fully programmable digital avatars going into commercial use.
2) BLOCKCHAIN
Micropayments and Blockchain applications will go mainstream in 2017. Mobile payments will grow massively, and apps will use "micro-payments" built on digital protocols like the Blockchain. Perhaps Blockchain will allow us to vote from our own devices in the next election. We will see the first smart contracts built on Blockchain.
Ransomware-as-a-Service will become a major threat vector, with a new technical feature using Blockchain to deliver the decryption keys after ransom payment.
3) BOARD ROOM
During 2016, boards of directors have realized that InfoSec risk management is an enterprise risk equivalent to financial, reputational, and legal risk. In 2017, there will be a raft of boards demanding a corporate security culture starting from the C-level down.
4) CEO FRAUD aka BUSINESS EMAIL COMPROMISE
CEO fraud was the up and coming cyberfraud scheme right after ransomware these last 12 months. During 2017 it will be an epidemic, equaling the ransomware plague we are suffering now. Remember the Nigerian prince scams? These cyber gangs are really in Nigeria, but they have climbed up in the criminal food chain and CEO fraud is their focus now. Train your high-risk users within an inch of their lives.
5) ESPIONAGE
During 2017 it will become apparent that espionage will turn out to have gone massively mobile and nobody knew about it. Revelations about both Android and iPhone devices will show they have had 0-days for several years and the NSA was able to own any device they wanted at any time.
6) INTERNET OF THINGS
A major outage caused by a purely malicious Botnet of Things like Mirai will prompt the new U.S. Administration to enforce IoT device security standards and require certification from device vendors.
7) MOBILE MALWARE
Mobile malware will continue to grow at an exponential rate. During 2017 tens of millions of smartphones will be infected with auto-rooting malware. New strains can embed themselves in a phone's bootloader and remain persistent even after factory reset. Scary.
8) OPEN SOURCE
In 2017 we will see a very high-profile data breach based on an open source vulnerability that was disclosed in...wait for it... 2012. The average age of an open source vulnerability in commercial applications is more than five years, and almost everyone is using Open Source these days. Ouch.
9) RANSOMWARE
We have seen exponential ransomware infections in 2016, and this trend will continue in 2017. There are close to 250 different families at this point, this will triple in the next 12 months.
Locky will be the first strain with 1 billion dollar in criminal revenues. Organized Eastern European cybercrime will continue to specifically target health care, education and local government with updated ransomware strains.
10) STATE SPONSORED HACKING
Look, we have a low-grade cyberwar and massive cyber arms-race going on. It's simmering and now and then it flares up, basically with proof-of-concept attacks, except for Stuxnet which was the real deal. In 2017 we may very well see the first major real-world damage caused by state-sponsored hacking.
Sunday, December 4, 2016
CISO Executive Summit 2016
With over 200 CISO / Security Leadership in attendance this past week, a great day of session / breakout forums, networking a few vendor product / services solutions…
Key-note theme began with Silver Olympic winner John K. Coyle presenting on Apply Design Thinking concept: consisting of Understand, Empathize, Ideate, and Prototype i.e. clearly understanding the problem and uniquely develop solution – brings you to focus on strength and merely working around weaknesses.
Other key takeaways:
- SaaS is the new development model – trending to reality
- SAP is the shadow IT with limited security visibility (gap in patching and flow/integration)
- Ransomware will happen (to anyone) so weigh price of recovery vs. paying ransom (and do tabletop exercise)
- Mobile End-Points increase threats particularly without multiple factor authentication / MDM strategy, so a little friction is not always bad
- Security controls should weigh in on IT Operational cost – it's a shift in duty / control
- Directed attacks cannot be stopped; so position for response/detection more than position for prevention
- Hunting or spot-audits is necessary though resource is a constraint
- Lead in 2 directions, being normal security controls as well as user experience / expectation
- We cannot be the CI"no" (user-centric security)
And, for an industry cyber security survey roll-up of over 700 CISOs (over 50% from Finance, Retail, Healthcare), see attached; summary being:
- Top Threats: IP theft, 3rd-Party risk and Reputational harm
- Top Priorities: Detect/Respond to adversarial threats, Build Security Awareness Organization, Communicate risk to stakeholders, Apply Risk Mgmt. to Security Strategy and Protect Cloud data/app/infrastructure
- 6% of overall IT spend is on Security
- 59% of CISO budgets expect to increase (modestly or significantly) on Vul mgmt., Incident Response and Awareness
Monday, October 24, 2016
Welcome IoT (Internet of Things)
A Mirai botnet hacked into IoT's cameras and routers (according to Flashpoint) which targeted Dyn (large Domain Name Server – translates domain names to IP addresses via hierarchical manner) with a Distributed Denial of Service (DDoS). Ultimately rendering major websites off line including: Twitter, Spotify, Reddit, NY Times, Pinterest, PayPal, etc. This same Mirai attack is the same that affect Brian Krebs website last month with packets/traffic peaking at 620 Gbps…with this recent case of internet vandalism as per U.S. intelligence reported by NBC News.
The Mirai source open-source code had been released to the public which showed itself in multiple waves on October 21 with the first approx.. 6:10am and the third realized around 2:30PM CST and lasted/resolved approx. 5:15pm. While DDoS is not new to the industry/Internet, it becomes more persuasive in the industry with connected devices – particularly with default login or management/SNMP credentials… DDoS can come in flavors of simply flooding your routers or devices with too many packets that it simply cannot process, and more commonly are packets sent to obtain acknowledgement (e.g. TCP handshake, GET requests) with further overwhelms bandwidth and processing congestion. And, the more sophisticated is this Mirai type which makes your individual PC become a DNS server which further floods the internet with bogus requests and response for name/IP requests.
Point being, early detection via monitoring network/bandwidth spikes can offer good triggers for your environment. Also, obtaining high-capacity server and/or configuring scrubbing filters to prevent large traffic spikes (for at least tapering the slowdown); and finally opt for out-of-band connection from your hosting provider or a Content Delivery Network (CDN) for your company's primary websites. Not bullet proof but some counter measures.



































































