Thursday, August 18, 2016

Some notable hacks reported since my last post

But first, news related to the Shadow Brokers posting keys-to-the-kingdom:
WHAT IF the National Security Agency’s topgun hacking tools/code were exposed on the Internet?  Reports indicate that TAO (Tailored Access Operations) members of the agency’s hacking division seem to point to legitimacy of the code (related to zero-day and other coding flaws) that potentially exposes commercial name firewalls such as Cisco and Fortinet – used by government and large corporations.
A group calling themselves the Shadow Brokers used BitTorrent nd DropBox to deliver the content and is auctioning off the rest of the code to the highest bidder.  Hacker hoax, diversion tactics by whom, oops/mistaken upload, political opportunity….we’ll see
Source: washingtonpost.com 

And from privacyrights.org, at least August's list of reported hacks which contains mostly medical-type of data exposed/unauthorized access – interesting

  • HEI Hotels & Resorts (Marriott, Starwood, Sheraton, Westin) – Payment processing systems breach in several states and District of Columbia – total records unknown/not reported yet
  • John Gonzales DDS – Stolen briefcase with external hard drive with patient records (SSN, DL, DOB, Health info) – total records unknown/not reported yet [July]
  • Bon Secours Health System – Files inadvertently left visible/accessible via Internet totaling 655K patients (containing names, health insurance ID, SSN, clinical info) [April]
  • Valley Anesthesiology & Pain Consultants – Medical information along with SSN may have been compromised via 3rd-party [June]
  • Prosthetic & Orthotic Care, Inc. – Medical, cyberattack of 23K+ records [June]
  • Autism Home Support Services – Medical, unauthorized access of 533 records 
  • Brian D. Halevia-Goldman MD – Medial, 2 laptops stolen resulting in 2K+ records [July]
  • Professional Dermatology Care PC – Medical, unauthorized access of 13K+ records
  • Oracle’s MICROS PoS – Retail and Bank information, via customer support portal and over 700 infected systems
  • Newkirk Products – Health insurance via cybersecurity incident
  • 7-Eleven – Personal employee data via database [June]
  • Center for Minimally Invasive Bariatric and General Surgery – Medical data of unauthorized access reported by HHS
  • Banner Health – Medical information through unauthorized access on server

Thursday, July 7, 2016

Leadership for Managers – succinct version

A 10 week Dale Carnegie class condense into 3 days…and the upshot is below – by virtue of 1-liners
  1. Set a VISION – without boundaries and is believable…and don’t put a timeframe since you may need to roll forward new things
  2. SMART goals are specific and measurable – and perfection should not be a goal
  3. LEADERS will reflect on what’s not working and adapt a plan to fit it
  4. Drivers for SUCCESS
    • Self-Direction, People, Skills, Process Skills, Communication, and Accountability
  5. Your MESSAGE: 
    • What I say counts for 7% 
    • How I say it (tone) counts for 38% 
    • What I do when I say it (body language) counts for 55%
  6. EMOTION is the single factor that drives thinking and alters decision
  7. Cycle of growth equates primarily to ATTITUDE and is the performance metric, otherwise the difference is called motivational gap
  8. MOTIVATION is single more important driver for effectiveness
    • Apply Maslow’s Hierarchy of Needs (Survival, Safety, Belongingness, Esteem, Self-Actualization) to the other person 
  9. COACHING using GROW 
    • Goal – Clarity with specificity 
    • Reality – self-reflection of today
    • Options – what to change to get there and why
    • Way Forward – prioritization and follow-up
  10. FAIRNESS is based on: Assurance, Belief, Relationship, Identity, and Control
  11. Understand areas of INFLUENCE and control the areas you have DIRECT CONTROL (anything else any be ignored)
  12. BUSY WORK is a waste of time/effort!  Time used will never get back
  13. Good FEEDBACK should be given by itself – Bad feedback does not necessary have to be sandwiched (between good)
  14. BELIEVE in yourself – never question what leadership looks like, it’s YOU
  15. Practice DRILLING – for factual details and ask WHY e.g. Why is it important to you or someone else
  16. Planning Process: Desired Outcome, Current Situation, Goals, Action Steps, Time Frames, Resources, Obstacles and Contingencies, and Tracking and Measurement
  17. I will remember others’ NAMES, only if I say/believe, I will (because it’s important to you)
  18. Our VALUES are our believe system – which drives our behavior so how one behaves speaks to their real values
    • Our perception of values might change but who we are do not
  19. Have a meaningful conversation, storytelling and injecting WHY - To learn about the situation and appreciating the other person 
  20. Understand and apply what’s most important to your organization, direct manager and to yourself i.e. Time, Cost or Quality trifecta / dimensions
  21. The Innovation Process: Visualization, Fact Finding, Problem OFI Finding, Idea Finding, Solution Finding, Acceptance Finding, Implementation, Follow-up, Evaluation
  22. Presentation effectiveness is rooted from personal SELF-CONFIDENCE and based on individual experiences
  23. LEADERSHIP involves people while MANAGERS involve processes
    • Lead the People, Manage the System
  24. Without managing your TIME properly, nothing else can be managed, Tyranny of the Urgent
  25. Employee ENGAGEMENT circles around: Pride in the organization, Belief in senior management and Satisfaction with Immediate Manager
  26. Problem solving TOOLS – Google it :)
    • Affinity Diagram
    • 4 Problem solving questions (What is, Cause, Possible and Best Solution)
    • Criteria method 
  27. DELEGATION Process: Select the person, Identify the need, plan the Delegatin, Hold a delegation meeting, Create a plan of action, Review the plan, Implement the plan, and Follow up
  28. Delegation to DEPUTIZING is truly giving total ownership and letting the other prosper
  29. PRAISE includes: Context, Specifics, Impact, Identity, Congratulate
  30. COUNSEL includes: Context, Specific, Impact, reinforcement, Seek Solutions
  31. FILTERS exist in all communication e.g. environment, assumptions, cultural, distortion becomes reality
  32. Right approach to handling MISTAKES: Research, Rapport, Reference, Restore, Reassure and Retain - otherwise Restate, reinforce, Replace
  33. Be Self-awareness
More to come...till then Plan-Do-Action based on Dale Carnegie's Golden Book


Thursday, June 23, 2016

What was your last team building event? Your next, and why?

It’s not an event but a process to work on interpersonal relations…with intended benefits such as improved performance, alignment and reduced ambiguity within a TEAM.  You can google for the definitions…but the entire activity and should be "cycle", from planning, agreeing, participating and reflecting is all part of the experience.  Envision the problem-solving skill that is required to gain agreement on the activity alone i.e. there’s no “i” in team, the event that focus on results-based outcomes, simply promoting full engagement, or whatever the theme might be.  Feeling like you’re a member and helping to motivate each other is essential to driving downstream productivity – because feeling valued is second to none.
APA’s Psychologically Healthy Workplace Program – deemed most effective activity:

  • Volunteering
  • Physical Activities
  • Field Trips
  • Professional Development Activities
  • Shared Meals

Considerations points: Its about problem-solving and communication, self-examination, underlying leadership (from facilitator or host), theme / goal hopefully with some analytics, and feedback

Constant improvement: The upshot is everyone learns differently and each take away will be based on personal experience and self-discovery.  Answering the question WHY during the entire process / activity will allow each person to get the most of the experience.  Oh, don't forget to celebrate!

Tuesday, June 21, 2016

Synopsis of IIA’s Managers Forum on IT Security

With good presenters and maybe over half of the 70+ registered in attendance, the focus centered on cyber security, CEO/executive concerns on the topic, and M&A exposures i.e. breach trends and controls on the topic

  • Among the culprits of cyber hacking include Morpho group – no association with nations yet but linked to 49 corporate data breaches / theft in 2013 i.e. who knows how many more under investigation and cannot be published yet; and Psuedo-nation state group – operating in hostile countries with no evidence of government funding and focuses on avoiding R&D costs
  • Many statistical studies and publications including Version security breach mentions 2015 being height of data breach thus far i.e. approx. 4000 incidents, 1854 occurred with for profit organizations, and 736 Million records exposed 
  • Key points mentioned was cyber-espionage up-tick in Manufacturing (overall #2) and 90% of incidents related trade secrets, e.g. Pharma manufacturing, newspaper/magazine paper mills with PHI data...
  • Companies conduct due diligence during M&A including: value of trade secret, market analysis on brand and of course capability/viability…but a hidden danger is for unreported breach due to non-customer PI data since public disclosure is not necessary
  • Additional considerations include: determining security posture/risk and efforts to sustain your security requirements/controls, ability/agility to activity react to log activities i.e. proactive threat vectors, and having a eye on data inventory and distribution/flow including 3rd-party connects

Finally, when out with executives or senior leadership, have your elevator speak ready.  Know with confidence where your highest security risks / threats are; your capability and diligence to react/correct/recover (tools, processes, SMEs); awareness strategy; and put a healthy plug for budget to ensure delivery of your security goals.

On M&A, my personal take/experience is try analyzing the “value” of the company data and analytics on related exposure cost (due to non-compliance or lack of security controls); and have the value clause written into the contract.  If anything, might be used to leverage the price/bid of the company being acquired!  Can you put an ROI on that math/benefit?

Monday, June 6, 2016

Cyber shift from banking to healthcare / education

Tripwire Inc. reports an increase in cyber attacks in generally all major sectors except banking and finance.  Citing 3 trends / examples:

  1. Anti-Phishing Report Group noted 250% increase in phishing activity between 10/2015 and 3/2016 and nearly 300K unique phishing sites just in Q1 of 2016
  2. UK’s Telegraph noted about 80% drop in digital attacks
  3. University of Calgary reported a digital state of emergency when malware infection resulted in shutting down the university’s infrastructure just as an international academic event was being hosted for over 8000 participants.  A similar event happened to MedStar, a healthcare provider.

So while banks are heavily investing in securing systems/infrastructure, cyber programs may be a step behind in general, or are not as mature for Internal Audit departments, for example.  A few industry comments summarized on where to begin, from Linkedin post:
Approach:

  • Continuious / non-static review and as important as the framework maybe, value of output is key
  • Study Governance structure and IT framework which will lead to 2-4 year audit program/cycle

Major to-dos:

  • Map IT audit universe
  • Determine risk and gap assessment
  • Conduct risk assessment

Audit types listed: Operational, management, business risk, HR, financial, IT, incident, problem, backup, log, data center, outsourcing, application, 3rd-party management
And, prevalent topics offered: Access control – on/off-boarding, Change management, Anti-malware.
We'll update as more weigh in on the IA topic...

Friday, May 27, 2016

Pharma: Valeant says NO to joint Takeda and TPG takeover

...giving Papa time to run the ship as the newly appointed chief executive.  So, the Quebec keeps the embattled but said to be world-class franchise known for therapeutic areas with dynamic workforce and affordable products...
The rejection came after a "premium" offer in a time when Valeant stocks had been plunging this year - perhaps due to debt load scandal and prompting to sell off non-core assets.  Valeant won a bid over Takeda last year of Salix which Valeant predictors think it's could be worth $1B in sales this year.  Upon news, VRX traded +6% to $28.  For Takeda, the takeover would have provided a spark to Xifaxan and uplift to Entyvio - reportedly.
Read more on Wall Street Journal

Hillary's email printer = 24.187.234.188

and on the campaign news (again)
Internet / IP-based printer was setup from clintonemail.com domain called, printer.clintonemail.com.
I wonder if it had a config banner that said print to me or please capture packets now… Hacking 101 seeks the obvious is searching for target names (or derivatives – but not needed here, a bit obvious), identify / scanning open and clear-text ports to attain available or vulnerable services; and listen (packet capture / man-in-the-middle), store info. and/or exploit vulnerabilities for exfiltration, extortion, etc.  That said, encryption/VPN was not mentioned…Krebs on Security also noted passive DNS records adjacent to:
24.187.234.186 rosencrans.dyndns.ws
24.187.234.187 wjcoffice.com
24.187.234.187 mail.clintonemail.com
24.187.234.187 mail.presidentclinton.com
24.187.234.188 printer.clintonemail.com
24.187.234.188 printer.presidentclinton.com
24.187.234.190 sslvpn.clintonemail.com

Thursday, May 26, 2016

Buzz to business or bust – Google Life Sciences’ Verily

The Baseline Study - Integration of personal and external information/population of human health and transition to disease e.g. understanding the mutations over time and before onset of disease through exams

Collection and analysis of viruses / malware to credit history or spending trends may have been the normal for some (long) time but health data collection in fitness bands and rapid digital health records might be unique identifiers that cannot be easily changed/replaced in comparison.  Yet the corresponding data confidentiality/integrity protection is finally being noticed.  Of course, the centerpiece bringing it to the forefront is availability and affordability of digital/wearable devices, for example, but the ramification on personal life and health is invaluable.  The launch of the
spinoff Verily, preceded / advanced the stacking of leading researchers and biomedicine experts including Harvard grad Medical Officer, Technology officer from Univ of Washington and other Google principals in business developments.  Moreover, it will also land itself in competing with tech companies including Apple as well as a furry of bio-tech startups.  Aside from running experimental genetics and clinical studies, the company makes miniaturized medical devices with intelligence/software and licenses them to medical companies and pharmaceutical…
Key pursuits reported by recode.net including:

  • Diabetes partnerships (Novartis, Dexcom, Sanofi)
  • Multiple sclerosis partnerships (Biogen Inc. for wearable sensors)
  • Nanodiagnostics (by taking a tiny pill and monitoring with wearable devices)
  • Liftware (Parkinson’s disease study)
  • Heart Disease (diabetes with American Health Association’s $50M funding)
  • Metal Health
  • And, probably most known/hyped for Robots (Johnson & Johnson robot joint venture)
And of course, Baseline – underplayed genomic, molecular and cellular science but really big data of volunteers prepped for studied.  A record 10,000 patients records are to be collected over the next 5 years which has sparked some so-so debate about ethical and privacy, including resonance of the patients or profiling such as socioeconomic, psychosocial, geospatial and genetic data.  Of course, some of the turmoil is occurring internally as the scientist and business worlds collide. But patient health and ethnics will align; or at least preventive health will prevail, right

The upshot is basically preventative care by merging technology and life sciences by identifying trends / synergy of health and reactive approach to disease management.  So, the innovation and ecosystem of disease and treatment will offer Patient Management set of Services in a Healthcare centric platform.

netflow and OODA loop

Circling back to the beginning with each step/phase is a must for OODA - Observe | Orient | Decide |Act
Observation points for what occurred is identified through various logs including firewall, IDS/P, Proxy services, and to local system logs; and helpful is a central / aggregated store or SIEM.  Perhaps one of my favorite these scenario is the use of netflow data.  A couple options exist for exports including: Taps, Span, mirror ports and virtual machine installs on WMware ESX servers.  Of course, advances in technology stretch the capabilities and blur analysis of full data packet capture including APTs, virtualized data centers, DDoS, IPv6, etc. so whats equally important is proper kill chain.  Starts with Reconnaissance and understanding the Exploitation, and determining/detecting the command-and-control methods which can lead to data exfiltration, corruption, and harvest (or hold hostage) of critical information.  So, having the appropriate toolset is complemented by having the right escalation, communication path and SMEs.  Recovery strategy and capability will come to bear in terms of recovery as much as Dwell Time (time of infection to detection to recovery).
Specific considerations for Netflow include: flow assembly, flow deduplication and retention (allows efficient storage and eliminates false positives), and behavioral analysis/recognition (algorithm and visualization).  Finally, related analytics and visual representation will offer the best indexes, alarms, and reactionary awareness.  An available source of info: lanscope.com

Monday, May 23, 2016

Healthy Big Data for Biomakers

Pharmaceuticals have been on the tabloids lately due in part for infamous company price gouging but today 3 firms are uniting to make their contributions by analyze data of healthy adult volunteers.  By studying health data patients, it can used to compare/contrast other patient stratification in with a global footprint and perhaps accelerate innovation of other drugs and discovery.  Though the initial focus on therapeutic areas, the power of big data and analytics is contagious.  The 3 biomakers are Astellas, Daiichi Sankyo, and Takeda.
Article Source: The Financial

Monday, May 16, 2016

Have you seen the red clock counting down - Cybercrooks

Ransomware is the biggetst online threat…as if it came as a surprise
Numbers include 4 Million reported during this time/Q2 of 2015, and who’s got the number for unreported cases?
With the playing field contributing to strong/open encryption algorithms, anonymous communication protocols and digital currencies, the landscape is prime. Why wait to resell confidential and/or time-sensitive information (or processes) in the black market when you get paid directly by the victim, right?  The evolution of randsomware started with files being encrypted or zip to immobilized the computers by overwriting master book record; and from Windows to Linux and now, just about anything, iPhone, Android phones.  True to malware form, there are variants and derivatives that have become prevalent within other software.  Even more terrifying is your own web servers infected and distributes malware so social engineering is not required i.e. Samsam – which includes capabilities to create backdoors and leaves the entire network at risk.
So, prompt patching, signature updates and quarantine, good backups with effective recovery solution and sound behavioral-based defenses / APT…are all solutions that need to be immediately addressed.
Article source: The Economist

Wednesday, May 11, 2016

Failed action plan for UK cybersecurity

According to zdnet.com, 2/3 of largest UK business suffered a breach within the last 12 months and 1/4 of them suffer a breach 1/month.  And  51% of medium firms also suffered cyber attacks, 33% small firms and 17% for micro firms. These number are even more staggering when factoring in just breaches that were reported.  The cause of the cyber breach is reported to be virus, malware and spyware.
By the numbers...
Of the over 13,000 businesses surveyed, a few key breakdowns

  • Manufacturing totaled 687: Small/Micro 150 | Medium 313 |Large 224
  • Retail/Wholesale/Vehicle Repair totaled 657: Small/Micro 324 | Medium 192 | Large 141
  • Finance or insurance totaled 1315: Small/Micro 718 | Medium 277 | Large 320
  • Health or social care totaled 432: Small/Micro 113 | Medium 248 | Large 71

Summary Results:

  • 69% of business claim cyber security is a high priority for senior managers but only 51% have taken recommended action plans to identify and 29 have formal written cyber security policies
  • 65% of firms detected cyber breach within the past year due to 68% being virus/malware/spyware and 32% impersonation of the organization
  • $3.4 Million was the most costly breach identified…average for large firms was $41,600
  • 51% have taken 5 or more Government’s 10 steps to Cyber Security, of which 28% include technical measures
  • 13% have cyber security standards for their suppliers (25% medium and 24% large firms)
Source: Cyber Security Breaches Survey 2016

Thursday, May 5, 2016

FBI will be allowed to hack computers worldwide

A downstream affect of US-EU Safe Harbour debacle is that the FBI have been given authority to hack computers and devices anywhere in the world – based on a recent US supreme court action.  The European Parliament is pending vote on the Privacy Shield as a means to address data-protection responsibilities but this new order just a formality AKA Snowden’s revelation on surveillance, etc.  Hence, warrants and process of search/seize may go by the wayside and has no boundaries. More developments and rulings, I'm sure....
Article source: IrishTimes.com