Showing posts with label Cyber Security. Show all posts
Showing posts with label Cyber Security. Show all posts

Friday, 15 September 2017

VMworld Europe 2017 - General Session Keynote

I attended my second VMworld this year, which you may find odd as I rarely blog about virtualisation or VMware.  VMware is changing and security is now more apparent in the solutions and roadmap.  

On Tuesday 12th September, we had a General Session Keynote from Pat Gelsinger - VMware CEO.

The VMware vision was similar to the previous year, but there are new partnerships with telcos, moving the telco networks closer to cloud, as well as the growth of IoT.


Gelsinger talked about the mix of devices, applications, and platforms causing the core challenge.  There needs to be anywhere access for people to the applications, but it's complicated.  There is a mass of devices, applications, services and security.

He is only reiterating the challenges securities have been facing for a number of years, with the increase in Shadow IT, less complimentary but highly connected applications, and uncertainty of any associated security.


Workspace One is the solution, grown from AirWatch to supporting iOS, to work with many more operating systems, including Google Chrome.  


MDM (Mobile Device Management) solutions have had to grow into EMM (Enterprise Mobility Management) solutions, w here it's no longer just the management of the device, but also the applications, the content, the availability and in my world, the identity and security.

Gelsinger moved to security, highlighting the target has moved form just applications and data, to user infrastructure, including users and devices, but also cloud infrastructure of the network and compute, as these are seemingly under the control of the security team.




The gasps when some of the audience was shocked with this slide, where the security guys have been working with and understanding a number of different areas.  Security people know that security spend is increasing, but the cost of breaches are increasing even quicker.  As Gelsinger says, "your spending more and falling further behind", "something is broken" and "we the tech industry have failed you the customers".  "We need a new approach"



There needs to be move from infrastructure to secure infrastructure.  Security needs to be built in, not an after thought, as I have been saying for a number of years.  There needs to be an integrated ecosystem, leveraging quality solutions and products, where you do not excel.  All of this with cyber hygiene regime. 


I'm glad that a tech giant like VMware is embracing cyber security and embracing the areas, I believe are the most important.  The pillars of cyber hygiene are important for every environment.  

Least Privilege, Micro-segmentation, Encryption, Multi-Factor Authentication and Patching, have been evangelised by security experts for a number of years.  So great to these elements are now considered mainstream.


As expected the EU General Data Protection Regulation (EU GDPR) came up in the keynote, and of course VMware are able to support the regulation by securing the data, automating governance and secure operations.


Gelsinger introduced VMware AppDefense and how it helps the security challenge able to capture, detect and respond.


VMware approach is looking at the security challenges of a business, without the business itself becoming a security expert.

I think it's a very exciting time for a security person to be looking at VMware, and I'm glad I was at VMworld Europe 2017 to see this for myself.

For those unable to attend, the General Session is available to watch here: https://www.vmworld.com/en/europe/video/general-sessions.html (where I also got the screen grabs, as the photos didn't come out so well)

Friday, 26 May 2017

Pull the budget and suffer the consequences: the NHS ransomware attack [Link: Information Age]

I was asked to help source an article about WannaCry on the NHS. Here is the article that was published on the Information Age website: http://www.information-age.com/pull-budget-suffer-consequences-nhs-ransomware-attack-123466474/

=========================================

Why wasn’t more done to protect NHS organisations from the WannaCry ransomware attack?


Ransomware infects computers around the world every day. In the last 18 months, instances of it have surged so prolifically that today it is the most common type of malware. However, the WannaCry strain hit the headlines because it brought large parts of the NHS to a crunching halt.

This is the problem with malware, it can have devastating effects. We don’t know what the real-world physical implications of WannaCry have been, for instance, patient treatments. Perhaps we will never know.

At a first glance, it appears almost criminal to be running operating systems that are no longer supported, in the case of the NHS, Windows XP. This was in no way helped by the government pulling the plug on an XP support contract to save money.

The ransomware infection was so serious that the government chaired a Cobra meeting, code for official panic. While patching an operating system is a fundamental security step, there can be a number of issues that complicate the process.

For instance, an organisation with a desktop fleet consisting of thousands of PCs might simply have not set up its configurations correctly, leaving holes in its patching process through which malware can insinuate itself.


Risk register


Some organisations might be reluctant to automatically apply operating system patches because they could cause conflicts with business critical applications. In short, they might be unable to patch for fear of slowing down, or even halting other parts of the business.

In both these cases there should be at least an awareness of the potential risks. It could be that an IT team is stretched thinly and is juggling other issues such as networking or storage, and consequently security slides down the list of priorities. This isn’t uncommon.

In these cases IT should be creating a Risk Register which is essentially a list of system vulnerabilities of why they exist, how they can be remediated and why they haven’t been addressed. This could be because of budget limitations or some other reasons.

The C-level executive team should sign off on the ‘risk register’ to show that they are aware of the issues and have accepted responsibility. This protects IT from any fallout should a serious breach occur, and also illustrates that they are doing their job.

Finger pointing


The WannaCry breach led to a lot of finger pointing and within hours had also become a political hot potato. Many people in the industry were quoted saying that defences are only as strong as the weakest link.

This is a self-evident truth, but in this case a very large condemning finger was pointed at end users. The implication was that a naïve employee or cluster of employees had clicked on an email link which unwittingly unleashed the worm-like WannaCry ransomware.

Phishing emails are increasingly sophisticated and even the most alert and astute end user can be fooled if the mail is targeted and well-crafted. The only problem with blaming end users is that it smacks of scapegoating and is essentially an abnegation of responsibility. However, there has been no evidence to suggest that WannaCry was initiated by an email or spread by user interaction.


First lines of defence


End user education and training is important and should certainly be more than an annual box ticking exercise. As well as patching operating systems, it should be a last line of defence and certainly not the first line.

Any organisation that is serious about IT security will have a range of defences in place to safeguard against these types of attacks. For instance, an email security gateway with sandboxing will filter out ransomware even if a user clicks on a malicious link. A web security filter with sandboxing will protect against drive by downloads, in which someone has to just visit a website to inadvertently download malware.

Web filtering tools in conjunction with a good firewall can detect dubious websites, as well as flag traffic that is leaving an organisation for a questionable destination. Of course there is also heuristic and signature detection, so if malware does penetrate the network it is immediately detected and stopped.

Added to this are a raft of endpoint tools that can protect devices, and we’re not just talking about patching operating systems but also patching browsers, plug-ins and third party software for vulnerabilities. On top of this, admin rights should be removed from endpoints so software doesn’t automatically run by default.


Lack of willingness


In short, the tools are available to protect organisations from ransomware and other types of malware, and they don’t have to be the latest and the greatest either.  The real question is whether the willingness to take security seriously is there? Given the large number of attacks that happen regularly you’d have to say it’s not. For instance, if there’s commitment then budget is always made available to help over stretched IT teams.

Clearly in the case of the NHS the funding was missing, and if the government doesn’t yet fully understand the importance of comprehensive cyber security then who will? Will it take loss of life before someone sits up and takes security seriously?

Tuesday, 23 May 2017

So you have WannaCry 2.0, what next?


So you machine is infected, what can you do?

Immediate Action


  1. Find all the machines vulnerable to MS17-010.  This can be done using scanning tools or wholesale apply the patch to all machines.
  2. On the infected machines, don't pay the ransom - Research suggests that payment will get your files back two thirds of the time.
  3. Try the WannaCry decryption tool and skip to step 5 on.
  4. If the decryption tool fails, re-install your operating system - remembering to patch it.
  5. Install a good malware protection solution, switch on real-time updates and update it.
  6. Scan your machine with your newly installed and updated malware protection software.
  7. Re-install essential applications, remembering to check for patches, and switch on auto updates.
  8. Copy back data from backups, remembering to scan it as you do.  One of your backup files could be infected.

Next Steps


  1. Create a standard user account for general use, and keep the administrator account for configuration changes only.  Although WannaCry did not need administrator credentials, other ransomware does.
  2. Consider Application Whitelisting to ensure only known applications are able to execute on your machine.
  3. If you existing firewall allows it, switch on web filtering to prevent traffic to known malicious sites.
  4. Consider using an IPS (Intrusion Prevention System) to protect your network. 
  5. A Web Security Gateway to monitor and prevent traffic to malicious websites, and sandboxing to scan unknown packages.
  6. An Email Security Gateway can monitor and scan emails, working in combination of a sandbox to scan unknown attachments, and a Web Security Gateway to validate URLs within emails.  Although email was not the delivery mechanism for WannaCry, it is for pretty much 90+% of ransomware.
  7. Check existing backups and/or start doing backups.

Planning for the future


  1. User training is important, but it must be remembered that WannaCry 2.0 wasn't propagated by email and didn't require user interaction to install or spread.
  2. Ensure an open policy for users to report to IT Teams or Information Security Teams with any suspicious behaviour on their machines.
  3. Test the environment with simulated attacks to ensure the People, Process and Technology work hand in hand together.

WannaCry/WCRY 2.0 - What do we know?


On Friday 12th May, we were all made aware of a global ransomware attack, which hit nearly 200 countries, infecting over 300,000 Windows machines.  Named WannaCry/WCRY 2.0, it encrypts your data and demanded a ransom of US$300 payable in Bitcoins (electronic currency).

Timeline


Looking back to earlier in 2017, shows how WannaCry evolved.

14th March 2017 - Microsoft leased a patch it classified as Critical as part of its month patch cycle.  The patch was called MS17-010 which resolved a vulnerability in the SMBv1 server on machines running Windows workstation and server operating systems.

14th April 2017 - Shadow Brokers leak the NSA hacking tools which exploited the MS17-010 vulnerability.

14th April 2017 - WannaCry/WCRY 1.0 was released

12th May 2017 - WannaCry/WCRY 2.0 was released

History


WannaCry/WCRY 1.0 was a spam campaign, which delivered its payload via compromised or malicious Dropbox accounts.  To all intents and purposes, it felt like a typical ransomware attack, delivering an email with a link, the user clicking on the link to download the ransomware, the ransomware would exploit a vulnerability (in this case MS17-010) and then encrypt the data.

Why is WannaCry/WCRY 2.0 different?


It is believed that WannaCry/WCRY 2.0 was not distributed via email, nor was it caused by clicking on a link.

WannaCry/WCRY 2.0 scans for Windows machines that are running SMBv1, and will try to infect them.  I say try to infect them, because if the machine had the MS17-010 patch installed, it could not be infected.  The ransomware will exploit the vulnerability, install and encrypt the data.  WannaCry/WCRY 2.0 also has a worm like characteristic, where it will scan the local network and random external IP address to see if they are running SMBv1 and try to infect them as well.

The clever part of this ransomware, is that it requires no user interaction to initiate it or to spread it.

What as the criminal gain?


Some organisations have been monitoring the Bitcoin wallet and they estimate that the financial gains from this attack is in the region of US$65-70,0000, which doesn't sound like a great deal.

Whose vulnerable now?


Using Shodan it's possible to search for Windows machines on the internet using the SMBv1 protocol.  Of course, it doesn't show if these machines have been patched to prevent MS17-010 from being exploited.


Tuesday, 6 December 2016

Cyber security in 2016 – why is it still not happening? [Link - ITProPortal]

I was asked to write an article reviewing the cyber security challenges for 2016, Here is the article that was published on the ITProPortal website: 

===================================

It's 2016, and businesses are generally still not taking security seriously.

Image source: Shutterstock/jijomathaidesigners

Perhaps the surprising, and damning, thing about 2016 in terms of security is that businesses are generally still not taking security seriously. Nobody wants to admit to being slack when it comes to cyber security, but the indisputable fact is that during 2016, many organisations simply didn’t show up, whatever they claimed.  

The basics are still not being done. Updates aren’t being applied, patching strategies are not in place, admin credentials are easy to find. Let’s be blunt, people are still trying to do security on the cheap, using, for example, free antivirus software.  This was most evident in the amount of ransomware that infected companies. 

A Trend Micro report claimed that 45 per cent of UK businesses were hit by ransomware this year. We believe the figure is much higher, closer to 60 or 70 per cent. 


Ransomware scourge


In the US, hospitals have paid massive amounts of money when their databases have been encrypted by ransomware. The Hollywood Presbyterian Medical Center paid a $17,000 bitcoin ransom for the decryption key for patient data. It was infected by the delivery of an email attachment disguised as a Microsoft Word invoice. In the UK some hospitals had to cancel operations.  

Hundreds of planned operations, outpatient appointments, and diagnostic procedures were put on hold at multiple hospitals across Lincolnshire.  The damage done by ransomware in 2016 is largely attributable to the infamous Locky and its many variants. It was first identified in February and made it to the top of the ransomware charts only two weeks later. 

It initially used malicious macros in Office documents to infect its victim’s computer, and these documents were distributed attached to spam emails. Locky has been through several versions since then. A new version was released on October 24, and less than 24 hours later yet another version was launched. It’s carried through phishing campaigns and the email subjects are centred on pay cheques, receipts, invoices, orders, or wrong credit card charges all of which are themes designed to fool recipients into opening attached files.   

Heads in the sand


In a sense it’s staggering that people are still falling for these tricks, given the exposure about ransomware dangers. There still seems to be a general mindset that ‘it will never happen to me’, when it clearly is happening to lots of businesses and individuals.  It’s frustrating because basic security measures offer protection. Being on the front line we tend to get a good sense of what is happening on the ground and it can be best summed up with the phrase ‘blind panic’ when a company is hit.  

But this lack of awareness, or ‘head in the sand’ scenario, is also playing out across other areas. Security in 2016 can also be defined by the large number of replay attacks that have taken place. Ransomware is included in this but it’s not exclusive. Yahoo is perhaps one of the biggest culprits. 

In 2012, a security breach exposed 450,000 usernames and passwords from a site on the huge web portal with the company failing to take even basic precautions to protect the data. Two years later it happened again with 500 million account details stolen.

Enormous DDoS attacks


Yahoo cried ‘state-sponsored actor’ in its defence but clearly it’s still not adequately protecting its customer data. This defence is usually code for ‘don’t blame us, it was a really sophisticated attack’. And Yahoo only came clean in 2016. These serious errors are clearly an illustration of some fundamental flaws at the online giant. Is it any wonder that it’s gone from an operation worth close to $100 million at its peak to today’s evaluation of $4.8 million? 

Another large 2016 security event, which ironically few noticed at the time, was the largest DDoS attack recorded, a whopping 540Gbps directed at public facing websites belonging to organisations affiliated with the 2016 Rio Olympics. These attacks were sustained, sophisticated, and actually started months before the Olympics began.  

These attacks were clearly aimed at the global stage and foreshadowed the equally massive IoT botnet based DDoS attacks which, in contrast, caught the attention of the mainstream media because they were launched from compromised everyday household devices such as internet connected video recorders and cameras.  

Plundering millions


The industry, at large has been warning about the parlous state of IoT security for some time, but it seems no one really wants to listen until an attack hits home and hurts bank balances.  

The Swift’s global payments network hack that resulted in $81 million being siphoned from Bangladesh central bank was also noteworthy due to the huge amounts of money involved.  Hackers also exploited the Swift system to steal a reported $10 million from an unnamed bank in Ukraine, while back in Bangladesh an eye watering $1 billion cyber theft was only stopped when an eagle-eyed employee spotted a typo. 

In an ironic way it’s almost fitting that a hack to see out 2016 was the attack on Tesco Bank. The company was forced to repay £2.5 million of losses to 9,000 customers in a heist described as ‘unprecedented’ by regulators. It may seem small when compared to the Swift system hacks but there’s worrying significance that the company apparently ignored warnings that its vulnerable software was being targeted by cyber criminals for months before the attack. What is just as shocking is that the bank didn’t even encourage two-factor authentication for its customers. 

How many more financial organisations are going to be nailed by cyber thieves before the message gets through? If the EU General Data Protection Regulation had been in force, which is due to come into effect in 2018, Tesco would have been hit by a fine up to £1.9bn. And who could say that Tesco and other organisations with terrifyingly lax cyber security wouldn’t deserve it?

Monday, 5 December 2016

Cyber-security in 2017 – brace yourself [Link - ITProPortal]

I was asked to gaze into my crystal ball and write a piece around the Cyber Security challenges for 2017.  Here is the article as it appeared on the ITProPortal website: 

=================================

If there’s one thing you can say with certainty about cyber-security in 2017, it’s that many companies are going to fail because they are simply not doing the right thing. Fundamental flaws still exist.

Image source: Shutterstock/jijomathaidesigners

It's about the business


Until the technical people lift their heads up and see that security and business are different sides of the same coin, we will inevitably see more damaging attacks. When security people learn to speak in the language of business they will begin to understand just where in the organisation they need to apply their expertise. 

This might be smart configuration options, cautious security policies, vigilance and a willingness to read server logs like some people read the newspaper in the morning to identify targeted attacks.  

Of course, this won’t stem the malware tsunami but it will help defend against it. Leading the malware charge in 2017 will be ransomware. Like 2016 it will be more of the same, with an important and fundamental exception; ransomware will be more sophisticated.

Advanced attack vectors


Encryption keys are becoming more complex while ransomware attack vectors are becoming alarmingly advanced. Ransomware can mount previously mapped drives, encrypt them, and then unmount them, reaching deeper into the network.  

However, the efficiency of ransomware as a tool for fraud will also be slowly undermined. One misconception about ransomware is that once the ransom is paid, the victim receives the keys to unlock their files. Increasingly we are seeing instances of this not happening. The fraudsters are simply taking the money and running.

Criminals dumbing down


As ransomware is now available as-a-service, it is reaching down into the lower levels of the criminal underworld and organised crime networks. The type of villain who uses the ‘service’ might have previously been involved with keeping crooked books for instance.

As such they can’t be bothered to send decryption keys which of course will erode the value of ransomware as victims increasingly refuse to pay the ransom.

IoT security


Another major area of concern is the security of IoT devices. It’s fair to say that the existing state of device security isn’t great. Some devices are managed by web consoles that don’t even have encryption. Some devices have passwords hard coded into them that you can’t change. It would be good to see manufacturers take some responsibility but this is unlikely as they operate with tight margins and are unlikely to take on tasks that eat into thin profits. 

If we’re lucky, we will see the emergence of pressure groups consisting of industry vendors and third parties who are no longer willing to sit back and watch major hacks unfold. 

Questioning machine learning


Another area to keep an eye on is machine learning. As with any new technology it’s usually proclaimed with a loud fanfare and over exaggerated claims that often fall just short of guaranteeing freedom for all and world peace. In terms of security, machine learning does promise a lot of potential but when you drill down some serious questions need to be asked.  

In 2017 we’re likely to see these questions put forward with some force, as it becomes apparent that machine learning in the security realm has flaws. For instance, how are the machines learning, are millions of good and bad results being fed into the machine to ensure accurate analytics and what kind of input is coming from security labs and research teams?  

These are important questions and with the advent of next-generation endpoints, such as mobile devices and laptops designed to respond to machine learning security in depth is vital to ensure success. If machine learning vendors can’t answer these questions with confidence, then you can expect to see machine learning and security take a dive.

Shock of GDPR


An area where you can expect to see panic break out is the European Union’s General Data Protection Regulations or GDPR as it’s more commonly known. At the moment UK organisations are displaying naivety towards GDPR which comes into effect in May 2018. Many are hiding behind Brexit and taking the view that the UK won’t be in the EU come May 2018 so GDPR won’t affect them. However, if a business operates in Europe, it will.  

To meet GDPR requirements, measures need to be put in place in 2017. Many companies have already finalised budget for 2017 but haven’t made any provision for GDPR. With no budget provision, there’s going to be an awful lot of flapping when companies realise that it’s nowhere near compliance ready. 

Big fines, big panic


GDPR also reaches up to the board and any data breaches can result in enormous fines of up to 4 per cent of revenue. This can and will translate in some cases, to fines that run into millions of pounds. Are executive directors aware that if they show negligence in protecting customer data they’re going to be hit really hard?  

In summary, it would be uplifting to say that we’re not going to see any more major breaches, that fundamental flaws will be addressed, that new technologies are going to change the security landscape for the better and everyone is set for GDPR. In reality, while we will see some positives we also need to prepare our businesses for more breaches and more hacks. 

Tuesday, 8 November 2016

Trump or Clinton? DDoS or Protection? Who will be the winner?

In a recent blog post by Arbor Networks, it was shown that DDoS attacks increase significantly during global events.

With the Presidential election in the United States happening in a matter of hours, will we see another significant, sustained attack on major websites, such as US media sites, political parties websites, etc?

I suspect we will, but much like the US election, we won't know who wins for a couple of days.

We can only hope that these sites have adequate protection from such an attack.  As for the election, we'll see...

Thursday, 3 November 2016

How businesses can protect Office 365 from ransomware attacks [Link - MTI Bytes]

After a recent webinar from Chris Taylor, Director of Product Marketing from Trend Micro around Ransomware, I created a blog post around this: https://www.mti.com/mtibytes/how-businesses-can-protect-office-365-ransomware-attacks/

=============================

In the last year, businesses have seen a large increase in ransomware threats. The Guardian recently reported that 54 per cent of businesses have been threatened with ransomware in the last 12 months alone. When we consider the money that can be made from a career in cyber crime, this is hardly surprising.

Ransomware refers to malicious software (malware) which is designed to block access to a computer system until a sum of money is paid.

But how can you protect your cloud environments from it? In a recent webinar, Chris Taylor, Director of Product Marketing, Trend Micro, looked at exactly that:

How does malware work?


Email is a common method that attackers will use to infect their victims, most often businesses. The malware is embedded in an email either in the form of a web link in the body of the text, which vulnerable users click on or a link within the attachment.

It is becoming increasingly more common for malware to be laced within documents in email attachments. Embedded JavaScript within the text encourages users to unknowingly click, starting the download of malicious software. It can be more difficult to detect the malware via the email attachment as it could be compressed within a common office file, such as a CV from a job-hunter, or an invoice, which seem convincing.

Prevention is better than cure


There are a number of recommendations that can be made, such as always back up your system, make sure it’s fully patched and train users not to open suspicious attachments. However, there are opportunities to stop many ransomware attacks before it even gets to that point. The best way is to block ransomware before it has a chance to reach users. There are certainly fix measures that can come in and save the day should the worst happen, but this can take up a lot of the IT team’s time.

What can businesses do to protect their Office 365 environment?


Office 365 includes anti-spam and anti-malware protection, which block every known malware. But the majority of malware is unknown, as criminals are increasingly using automated tools to change their malware, to beat the system.

In order to remain one step ahead from threats, businesses can implement advanced threat protection, which looks for malware in different ways, malicious URLs in attachments as well as the body of emails, and full data loss protection.

To set up a free evaluation of your Office 365 protection, email ukmarketing@mti.com

Tuesday, 27 September 2016

CLOUDSEC takeaway – Cyber security is not just an IT issue [Link - Trend Micro Blog]

After attending CLOUDSEC 2016, I was asked to create a guest blog on the Trend Micro blog site, including standout statistics and take-away lessons: http://blog.trendmicro.co.uk/cloudsec-takeaway-cyber-security-is-not-just-an-it-issue/

===========================

With a fantastic turnout at CLOUDSEC 2016, attendees comprised of security and IT practitioners from numerous industries. Despite these varying sectors, one thing became abundantly clear: the same issues are keeping IT security professionals awake at night – securing cloud environments, securing privileged access accounts and user education.


Many enlightening statistics were shared. Trend Micro’s research found that in the last two years, 44% of UK businesses were hit by ransomware attacks, and a third (33%) of their employees were affected by the infection. We also heard that over $2.3 billion was lost to phishing attacks over the past three years (FBI), though the real figure is likely to be higher.

While this makes the somewhat abstract world of cyber threats very real indeed, if there’s one point to take away from CLOUDSEC, it’s that cyber security isn’t just an IT issue. When the entire workforce is educated around safe IT usage, the chance of a business network being hacked is significantly reduced.

Everyone needs best practice training 

Organisations can defend against cyber-attacks; they don’t have to be victims. While in any organisation the CIO ultimately takes responsibility for cyber security, the rest of the organisation needs to accept responsibility too and not just shrug their collective shoulders. Regardless of seniority, companies should invest in best practice training when using a corporate network.

Best practice knowledge should percolate through the entire organisation from board directors, to employees and IT people involved in daily operations. It should explain why businesses have approved channels for storing data, the risks of using personal cloud storage platforms for data storage, and the need to question email content if it arouses suspicion – even if it’s from the CEO’s office.

Employees must understand the importance of cyber defences within the context of the business and how to safeguard against internal and external intrusions. Are they aware of the importance of setting difficult to crack passwords, as well as understanding that password variations of existing passwords are a source of vulnerability when used in other parts of the network? Do they know that in the last six months or so, ransomware attacks have spiralled as ransomware-as-a-service kits became commonplace on the dark web?

Serious business implications

The whole organisation must realise the possible business implications of a major hack – spiralling revenues, lost customers and plummeting share price, and this could all happen well after the event. Furthermore, jobs could be on the line if declining income hits the business badly.

Despite the growing evidence suggesting otherwise, many organisations still believe they won’t be hacked. With that said, however, if cyber security education is a part of the organisational culture, the chances of a serious breach are dramatically reduced.

Wednesday, 14 September 2016

Are our data centres insecure? [Link - SC Magazine]

I was asked to contribute to an article on whether datacentres are secure following from the disclosure of the Fortinet and Juniper firewall vulnerabilities: http://www.scmagazine.com/are-our-data-centres-insecure/article/522463/

===============================


Likewise, Andrew Tang, service security director for MTI Technology said: “Data centres are only as secure as you configure them to be. You can have a top of the range burglar alarm and locking system on your front door, but if you don't use them, or use them incorrectly, they aren't going to be very secure. Most data centres will have two firewalls: the front firewall which will come from one manufacturer, and a second firewall from a different manufacturer, with the ‘crown jewels' inside. If you're using two different firewall manufacturers, it's rather unlikely that someone will find the first firewall and then go on to find the second firewall – though that can't be ruled out completely. But again, while bad programming causes some issues, bad configuration causes more issues in data centres than the actual manufacturer of the firewall.”

Tuesday, 6 September 2016

CLOUDSEC 2016

Today I attend CLOUDSEC 2016 in London, which gave an insight in how to take control of the cloud and have a good cyber security strategy.


The speaker of the day for me was Rik Ferguson, who made a few interesting points.

During the Panel Discussion: "Key Questions Every CEO Should be Asking About Cyber Security", he made the comment, that we should sandbox our users.  This may have brought a laugh to some of the more technically focussed audience who would blame users for everything!  What Rik clarified was that organisations should allow users to make mistakes safely, and be able to learn from their mistakes.

During his session "Take Control: Empower the People", there was a delay setting up the presentation, where Rik began to discuss the IT Skills Shortage.  Why do employers looks for certifications rather than people?  Many job adverts look for qualifications such as CISSP, CISA, CISM, etc but not character traits.  As Rik points out, organisations should be looking for people with tenacity, who are analytical, lateral thinkers, natural problem solvers, and people who can think differently.  Much like my belief, there isn't an IT Skills Shortage, employers aren't looking for the right things!

A few takeaways include:

  • "The board don't understand Security" - They don't need to, security need to understand the business.
  • "Compliance is the obligation, Security is the aspiration" 
  • Have an Information Security program in place
  • Ensure employees are educated, aware and engaged
  • Form an incident response team - Include technical, legal, finance, PR, marketing and the board
  • Investigate and fix incidents in a timely fashion - Look at people, process and technology
  • Notify customers in the event of a breach
  • Learn and Improve

Monday, 5 September 2016

How Technology and Employees Must Combine to Fight Cyber Crime [Link - VMware Blog]

VMware asked for my opinions around Cyber Security for a guest blog piece to appear on the VMware EMEA Blog site: http://vmwareemeablog.com/uk/guest-blog-how-technology-and-employees-must-combine-to-fight-cyber-crime/

=============================

Risk and security are two of the most often debated topics in IT in terms of the smooth and effective running of any organisation. Following our research campaign into the subject, we have been busy collecting the views of our partner community, gathering perspectives from across the market on all things security.



Here is Andrew Tang, Service Director of Security at MTI, a global provider of IT & security solutions and VMware partner, to share his views and explain how IT departments can make sure the board is listening…

Although used as a plot device for countless Hollywood movies – from Swordfish to Die Hard 4 – it is only more recently that cyber security breaches have become a significant talking point for businesses, especially when it is their reputation, IP and competitiveness that is at risk. Due to the misfortune of security breaches at brands such as TalkTalk, Sony and Ashley Madison, business decision makers are beginning to look to cyber security, not simply as an IT afterthought but as an important investment.

And it’s about time. Cyber security has never been so crucial.

The landscape is changing, with organisations becoming more open in how they manage data and IT services. This has caused difficulty for the tech community, and many IT departments are struggling to balance the demands of employee mobility with traditional security methods.

At the same time, we are seeing numerous specialised players popping up with new fixes for niche problems. However, these incremental tactics are proving ineffective – like trying to fix a broken leg by covering it in sticking plasters – and organisations are crying out for a holistic solution that can go beyond the perimeter defence and siloed data. This is where VMware NSX comes in.

However, technology is only half the story. Effective cyber security will always be limited if the end-users continue to let threats in through the back-door. Phishing scams and Trojan viruses often get their entrance through employee mistakes. It’s vital that everyone – from the CEO to the receptionist – is clear on the organisation’s security policies. And while all employees should have a basic understanding of cyber security, training can’t simply be a one-size-fits-all lecture. The board will be targeted in different ways than other roles in the business, so training should be bespoke and appropriately suited to the day-to-day risks employees can expect.

Ultimately, we advise customers to ask three critical questions to tackle the insider threat:

Where is your data?

Data is crucial, it is the lifeblood of your organisation. Keeping track of it means that you are best placed to protect it.

Who can access it?

This is just as much about who should access data, as who should not. To this end, MTI has a dedicated department of fully qualified Penetration Testers – also known as white hat/ethical hackers – who can test your infrastructure to identify weak points and ensure that your data is only seen by those with the right permissions.

How is it protected?

What safeguards do you have in place? Is this enough? Cyber attacks, especially using ransomware, have increased exponentially in recent years and its now a case of when – not if – an attack will occur. Have you secured all endpoints?

It might seem paranoid, but when it comes to cyber security paranoia is good! It’s vital that businesses are able to ask these questions. It is only when you can answer them that you know your organisation is once again safe. Additionally, putting into place solutions such as VMware NSX can help mitigate the inevitable insider threat. Thanks to microsegmentation even if an employee mistakenly clicks on a malware link the threat can be locked down and dealt with, instead of compromising the entire system. Although nothing is as effective as eradicating poor employee behaviours – after all, an ounce of prevention is worth a pound of cure – NSX offers a backstop in case something does go wrong. And the more checks and balances in place, the better.

Friday, 26 August 2016

Changing environments mean a fight to stay relevant [Link - Channel Pro]

While I was at the CyberArk Partner conference, I was asked to attend a roundtable to cover challenges we see in the UK marketplace.  Here is an article was written by Tim Goodwin, the EMEA Channel Director for CyberArk: http://www.channelpro.co.uk/opinion/10093/changing-environments-mean-a-fight-to-stay-relevant


========================================

UK resellers face a turbulent time, both currently and in the months to come. Against a backdrop of a changing threat landscape, new data regulations and the uncertainty following the UK referendum result, the opportunity to grow still remains, but channel partners and VARs will have to negotiate potentially treacherous waters to remain relevant for customers.

At a recent customer and partner EMEA event hosted by security vendor CyberArk, Kristian Alsing, a cyber security director at consulting firm Deloitte, together with panellists Andrew Tang from MTI and Hakan Cakar of NTT Com Security, examined these issues, the opportunities they present, and what approaches will be necessary to remain trusted partners for UK end users.

In the context of security, Alsing highlighted that there haven’t been any new crimes in the last thousand years. “People are still defrauding others, still stealing, still doing the things that humans have always done,” he said. “But what we do have that’s different is a connected world.”

The crime has now been decoupled from the location of the asset, explained Alsing, going on to detail what Deloitte are seeing. A notable trend is the service provider model being adopted within the organised crime industry - for example Hacking-as-a-Service for those who don’t possess this particular specialism - as well as the evolution of criminals, with who used to ‘just’ steal credit card details moving into much more complex and ambitious cyber heists.

Increased nation state involvement, malicious insiders and hacktivists form what Alsing referred to as the ‘threat actor’ environment. When combined with a very different looking end user, compared to the recent past, this creates some key considerations to understand for the UK channel community.

Organisations used to control their assets, whether that be money, data or anything else. With the huge use of outsourced and cloud services, plus the Internet of Things (IoT) and mobility, the risk for organisations is higher than it has ever been, because it is concentrated – people or data on a grand scale can be accessed from one access point. So it is critical to understand this in order to be credible for end users.

The panel also discussed how strong regulation in the Finance industry has led to the rising importance of cyber security within organisations (in many cases to c-level), as well as the sheer complexity of organisations driving security concerns. Acquisitions in particular were highlighted as a cause of security issues as legacy infrastructures and different approaches to security come together.

Both NTT and MTI addressed the perception that end users don’t necessarily really know how to separate what is important from the plethora of – sometimes mixed – messages from security vendors. Threats like ransomware were cited as helping people ‘get it’ as it is such a common threat.

An interesting part of the discussion involved education and the question of responsibility for it. There was a feeling on the panel that the industry (vendors and partners) shouldn’t sell a panacea to customers, but should instead concentrate  on finding out what is important to the end user on a case-by-case basis. Partners, with their huge reach, should be part of the education programme. Demand from end users in this area is what has driven NTT to invest in bigger security practices.

Unsurprisingly, the EU GDPR was highlighted as a driver for change. Alsing made the point that certain car manufacturers, decades ago, made safety a selling feature. At the time they were ridiculed, but now safety is very important for all mass-market vehicle manufacturers. In the same vein, data integrity, as enforced by GDPR, should be a partner opportunity.

Finally, the panel talked about Brexit, albeit in the context of what it would mean for the regulatory environment. Will it mean data protection reverts to the more ‘watered down’ form that we had before the EU version came along? The verdict was ‘probably not’; the UK had a leading role in designing the EU regulations.

Concluding, it was noted that collaboration would be the key to remaining relevant in a fast-changing UK. Vendors, partners and customers have to remain connected to maintain the right level of knowledge and expertise to meet IT and environmental challenges. This is the time to embrace change, not retreat into our shells.

Tuesday, 16 August 2016

How to protect against mobile threats [Link - Information Age]

I was asked to provide an insight into mobile threats, and this is the article that appeared in Information Age: http://www.information-age.com/technology/security/123461862/how-protect-against-mobile-threats

==============

Cybercrime is on the rise, and with the increasing mobility of today’s workforce, it is not just PCs that need to be protected but a whole range of mobile devices.

Whether owned and managed by the company itself or brought in by employees, all mobile devices now need to be considered in businesses’ security plans.

This is especially true when implementing bring your own device (BYOD) policies, where companies can have less control over their employees’ phones.

With 72% of organisations across the financial services, technology, healthcare, government and education sectors now supporting BYOD for all or some employees, it has never been more crucial to ensure company data can remain secure while allowing easy access for employees.

So what are the threats to mobile devices that businesses face and how can they mitigate them?


Public networks


One of the biggest threats facing businesses – especially those with employees travelling abroad – is the use of free Wi-Fi networks to avoid having to use up mobile data allowances or pay costly roaming charges.

Public, password-free Wi-Fi lacks sufficient encryption, which provides hackers with an opportunity to access and steal almost all information on a user’s device.

The Wi-Fi Pineapple, for example, makes man-in-the-middle attacks easy. In this type of attack, a hacker sits in between the device and the Wi-Fi it is connected to in order to extract information from the device while the user remains unaware.

By educating employees of the dangers posed by using unsecured Wi-Fi, organisations can help to mitigate at least some of this threat.

Also, teaching employees to check if the website uses a HTTPS protocol, and ensuring that they have access to encrypted data storage are two more methods that help in keeping valuable corporate information safe from unsecured Wi-Fi.

Apps and channels


It is important to consider where employees are storing data, and what apps they are using on their device.

Apps present a risk to businesses as potentially confidential data is entrusted to a third party’s security protocols. For example, employees storing data from their mobile phone have to rely only on the strength of passwords for protection, rather than robust end-to-end encryption.

Using the appropriate channels for storing information, such as an encrypted VPN that is available to employees’ mobile devices, is one step towards protecting business assets.

While most app stores vet malicious apps, a user can still download apps from third-party stores that appear harmless on the surface but contain malware. Once downloaded, these have the potential to lock users out of their device, install malware, or carry out other activities, as illustrated with the recent case of fake Pokémon Go apps.

Companies that issue a fleet of managed devices can place restrictions on what apps can be downloaded. But with BYOD, employees are free to download what they want.

By creating a separate, corporate app store on the device through an enterprise mobility management (EMM) platform, IT departments can ensure only approved apps can access corporate information, while still allowing employees the freedom to download whatever they wish to use on their device.

Mobile malware


Just as with a PC or laptop, mobile devices are susceptible to malware attacks.

The recent proliferation of HummingBad malware on Android devices is a prime example of highly-sophisticated malware affecting mobile users.

By attaching itself to infected versions of trusted apps, it puts in place applications that generate fraudulent advertising revenue, collecting personal data to sell on along the way.

The key here is prevention rather than cure. There are many anti-virus, anti-malware and firewall products on the market which can be distributed across a whole network of corporate devices, ensuring they can protect against the latest threats.

For BYOD, EMM platforms can mitigate the risk and protect corporate data by creating a ‘wall’ around sensitive information to prevent infection from compromising data. Meanwhile, robust security policies can be put in place on an employee’s personal phone without invading their privacy or forcing too much control over a personal device to an employer.

None of these are 100% fool proof, however, so educating employees has to be a priority.

Part of this process should involve advising employees of the dangers hacking poses, the reasoning behind approved corporate channels for storing information, and clearly defining the role they need to play in securing their device.

IT departments need to be working with the HR team and heads of departments to create a corporate culture around security, and convey that the protection of company data is as much their responsibility as it is for IT professionals.

OS vulnerabilities


While Apple is known to have complete control over its iOS update system, the same is not true of Android, which has to rely on vendors to patch issues.

This was highlighted in the StageFright attack in 2015, which exploited weaknesses in the Android source code and allowed hackers to execute malicious code remotely.

Therefore, it is imperative that IT departments enforce a strong update policy. With a fleet of corporate devices, these can be managed centrally and updated on a regular basis – however, it is also necessary to advise employees using BYOD to ensure their personal device is up to date with the latest patches for the best protection.

There are as many solutions as there are threats in the corporate mobile landscape, but educating staff is the key to preventing the loss or infiltration of corporate data.

This needs to come from the top down. IT professionals need to be sitting round the same table as the C-suite when discussing mobile, and working closely with all departments of a business to create a ‘culture’ around mobile security.

Monday, 4 July 2016

Stopping ransomware in the public sector [Link - MTI Bytes]

This is a blog piece that was created for the company blog site: http://blogs.mti.com/blog/stopping-ransomware-in-the-public-sector

===============================================

In just over 10 years, ransomware has become a serious threat for many organisations across the world. In 2016, we have already seen a 300 per cent increase in attacks, which roughly equates to approximately 4,000 a day. Worse still, this figure is predicted to double year on year.

While there is no perfect solution to stop organisations from ever fully preventing these attacks, arming yourself with knowledge is the first and best defence to mitigate them should they arise.

Risk to the public sector

The public sector in particular is at risk from ransomware attacks. With a great deal of important and personal data stored in these organisation’s databases, the potential damage caused by workers being locked out of their systems can be significant.

In January 2016, Lincolnshire County Council shut down its entire IT network after a new strain of ransomware demanding £1 million was found to have penetrated the system. This new malware forced the council to shut down to protect personal data – including those it provides social care for.

Triggered by one user, and on a system that was up-to-date with the latest protection, the intrusion meant that operations were left without any IT for a number of days, which of course has a knock on effect for service delivery.

The above example, along with a recent spate of attacks against hospitals in the US, Canada, Germany and New Zealand, show that public sector organisations in wealthy countries are amongst those at the highest risk, presumably due to the greater likelihood of them being able to pay the ransom.

Knowing the threat

Ransomware is a form of malware that can affect a device without the user knowing. The first instances of ransomware came to attention in 2005 and were comparatively crude. However, in the following 11 years, it has become far more sophisticated as hackers re-invest profits into new malware.

Recent evolutions have seen the virus become more effective and hard-line. Some now include a sleep timer, which means that the encryption process can begin at a time of the virus writer’s choosing and be executed over an extended period, which also makes it harder to notice.

The Petya strains of the virus, which came to light in the first quarter of 2016, takes encryption to a new level. Discovered after emails with Dropbox links to download a file containing ransomware were found, Petya encrypts the hard disk itself, deleting the backup files which were previously used as a solution to counter-act ransomware. It also avoids detection by signature-based anti-virus software, making it even harder to find.

This new strain could have massive implications for the public sector, leading to vital information being lost or even stolen while IT teams scramble to try and stop it from spreading across the whole system.

Education is essential

So how can councils, hospital trusts, and other public sector organisations protect themselves against this threat and remain online?

The attack on Lincolnshire County Council happened because a new strain of the malware had not been encountered before, therefore there was no protection against it. It was also a human error, as it took only one person downloading it onto their system to cause a significant issue.

While IT professionals are always trying to stay ahead of the game, there is no form of protection that is 100 per cent perfect all the time, especially when human error is factored in.

The main solution to mitigating attacks lies in educating staff to understand why security processes are in place, and what happens when they circumvent them or use applications not authorised by the company, for example, downloading files from unknown contacts via Dropbox.

Alongside educating staff, IT departments should enact a principle of least privilege when it comes to local administrators. This will be essential in ensuring that if a device is infected, the information it can encrypt will be minimal and does not spread through the system.

There also needs to be a protocol in place for when an attack does happen. Directors need to work with their IT departments to come up with a plan of action, deciding whether or not to take the precaution to shut down systems, to go public with the attack or keep it in-house and – crucially – if the ransom should be paid.

Ransomware is pervasive and very dangerous for public sector organisations, considering the sensitive data they hold, so education is vital. Get the knowledge and learn more best practises in our complete guide to ransomware by downloading it here.

Thursday, 19 May 2016

100 Million LinkedIn Accounts for sale

It was reported in the news that 100 million LinkedIn Accounts were for sale on the Dark Web.

LinkedIn previously reset the passwords of those accounts they believed were compromised in 2012, but it seems many more accounts were compromised than previously believed.

LinkedIn's response should have been to reset all the users passwords and implemented better protection for the new passwords.

From a user perspective, we need to ensure we are using different passwords for each of our web services.  Why?  Well if your LinkedIn password is the same as your email provider, other social media accounts, cloud storage, etc, then the compromised password could be replayed into a number of websites and services to gain access to those.

Although it's not two-factor authentication, two-step verification will give some additional security to your LinkedIn account.  Not only will this add security to your account, it's also free.  The instructions to switch on two-step verification for LinkedIn is relatively straightforward.

Don't forget your other web accounts, as two step verification is available for Google, Facebook, Microsoft, Twitter and many other site.  If the websites and services you use aren't taking your security seriously, should you be using them?

Monday, 16 May 2016

Home and mobile working - ’10 Steps to Cyber Security’

Mobile working is an established fact of life today, whether you’re accessing corporate data on the move or connecting to the company network from your home. Mobiles devices now make it easier for employees to do all they need irrespective of geographical location.  

While the mobile revolution provides flexibility for employees, it also brings risks. One of which is the simple physical loss of equipment, such as a laptop left on a train, or a smartphone left in a taxi. Being able to access all documents from a single location means that, should the device end up in the wrong hands, the security can be compromised.

Blunders and lapses

Should you happen to find yourself in a situation whereby your device goes missing, do not panic. Laptop lapse can easily be dealt with by encrypting hard drives, enabling remote access to wipe data and also by using extremely robust passwords.

A more immediate danger, however, are sophisticated exploits such as mobile botnets, where multiple smartphones can be infected with a virus or Trojan type software. This can result in a network of phones being programmed for malicious activity, such as stealing credit card data or malware, burrowing into a corporate network. As mobile computing becomes increasingly commonplace, hackers are also increasingly drawn to it.

World of many devices

In terms of home and mobile working, organisations need to secure and manage operating systems in a world of mixed-use devices, while at the same time incorporating identity, context, and privacy enforcement to set the appropriate level of access to enterprise data and services.

Organisations need to address three areas: device management, application management and content management.

In terms of device management, organisations need to be able to secure and manage a diverse range of mobile devices, automatically enable enterprise settings such as Wi-Fi and VPN, as well as providing end-users with secure access to corporate email.

With application management, a business should aim to deliver, secure and when appropriate, retire mobile apps. This provides IT with the ability to manage the application life cycle from making applications available to employees, securing applications on the device and when necessary, containerising corporate apps to keep them separate from personal apps.

Content management is the ability to enable end-users to securely access and manage enterprise documents that are kept in different content repositories, whether on-premises servers or in the cloud. It’s also important that corporate email attachments are encrypted. Ideally, users should also be able to securely browse corporate Intranet content without the need for a device-wide VPN.

Importance of policy

Policy guidelines also need to be in place in order for a business to dictate actions. For instance, if a mobile device falls out of compliance, IT can define remediation actions that will either notify the user of policy violations or remotely wipe corporate information.

In addition, stating how an employee should connect to the corporate network can also help with security. Connecting to a corporate network via secure socket layer virtual private networks alongside a two-factor authentication for identification will also ensure privacy and protect corporate data.

Sunday, 15 May 2016

Removable Media Controls - ’10 Steps to Cyber Security’

Removable media is anything that can be brought into an organisation and plugged into a computer ranging from a USB stick to external memory, smartphones and tablets, iPods, Bluetooth devices, recordable CDs and DVDs. It also includes wearable devices such as smartwatches, which are gradually becoming more popular.

Some people in the workplace may use a laptop to charge their smartphone or transfer files using a memory stick because it contains something they are working on. However, irrespective what it is you’re plugging in, there are dangers attached when inserting a USB into your laptop. Firstly, there’s the risk of the devices containing malware and secondly, there’s the danger that sensitive data can be downloaded and stolen.

The Stuxnet attack on the Iranian plant in 2013, illustrates the tremendous damage that can be wreaked from a small memory stick. It’s therefore essential not to overlook removable media controls when looking at cyber security.

Consider the consequences

In the corporate sphere, the risks of information theft, data loss and malware can all lead to reputational damage and financial loss for a company. If you have any doubt about the consequences of serious data loss, consider the case of US retailer Target. It was the subject of a hack in which millions of customer records were plundered and as a result, its revenues plunged by over 40 per cent.

Safeguarding against loss via removable media should ideally be planned when a security policy is being developed. As removable media in the workplace is now all too commonplace, and is one of the highest areas of vulnerability, it should be addressed as a matter of urgency.

Reducing the risk 

Even if your network is locked down to the point of disconnecting it from the Internet, that doesn't prevent someone from copying sensitive data onto a CD-ROM, or to a USB memory drive and walking out the door with it.

Removable media controls fall under data loss prevention and as a result, there is a raft of technologies designed to help protect the removable devices. The fast-paced business environment of today requires employees to have anytime, anywhere access to corporate data and business applications, therefore putting the block on removable media may seem draconian and counter-productive.

However, it can be managed. It’s possible to protect critical data from coming into and leaving the company through removable media with tools that monitor and control data transfers from desktops and laptops, irrespective of where users are and even when they are not connected to the corporate network.

Managing devices

Specifying which devices can and cannot be used, defining what data can and cannot be copied onto allowed devices and restricting users from copying data from specific locations and certain applications will help when managing devices.

Endpoint encryption for removable media is also another effective approach. It allows the encrypted device to be used on any machine without installing any software or requiring administrator privileges. It also allows encrypted files to be saved or edited safely, which ensures user flexibility is also maintained.

Remember, policy is essential. Identifying removable media devices, nailing down required actions and outlining the steps that are needed to ensure continued business flexibility will help protect your sensitive data.

Friday, 13 May 2016

Monitoring - ’10 Steps to Cyber Security’

Monitoring IT systems is central to the protection of an organisation. The government’s 10 Steps to Cyber Security points out that for monitoring to be successful, it must be comprehensive.

In other words, this means looking at everything from the networks, servers, desktop computers as well as host intrusion detection systems, prevention solutions and wireless intrusion detection.

The guide also states that all network traffic needs to be monitored, both inbound and outbound, and organisations need to be able to generate audit logs that identify unauthorised use and the users.

Dramatic surge

To a significant degree, if other points within the guide are adhered to, a level of monitoring will already be taking place.

In the past, it was a widely held belief that system monitoring was not really a core requirement for operational effectiveness. However, the dramatic and sustained surge in cyber attacks and the threat from insider data leaks, presents this argument as redundant. The need to protect sensitive data, whether it’s customer information, financial records or intellectual property has never been more pressing. 

Industrial scale tracking

For many organisations, monitoring needs to take place on an industrial scale with the tracking of thousands of devices. At its core, monitoring essentially needs to track activity as well as raising red flags if anything out-of-place happens. 

There are a number of ways to approach this. We recommend centralised technology platforms that detect threat activity as it provides the security team with the context and insights needed to minimise the potential fall-out.

Full insight

It’s not just a question of looking out for malware; it’s a question of having full insight into the IT estate and all its component parts. It needs to be comprehensive given that some threats are multi-vector advanced persistent threats carried out by external attackers, while others arise from malicious or accidental behaviour by insiders. 

A business needs to be able to detect even a partial fragment of sensitive data on a network endpoint with data loss prevention tools as well as guarding against data loss in the cloud and on premise.

Detailed analytics

Detailed analytics help you understand what is normal organisational behaviour as well as helping to highlight when something or someone deviates from the norm. 

Preconfigured policies are also important in that they allow you to get up and running quickly and more importantly, effectively. The importance of monitoring data and human behaviour can’t be overstated, especially as it can give you an early warning system that flags up if something is amiss. 

Thursday, 12 May 2016

Malware prevention - ’10 Steps to Cyber Security’

The scale of malware is enormous. Approximately 250,000 new malware sites are brought online every day. While the majority of these are only alive for around 24 hours, they can cause enormous damage.

This is particularly true when malicious sites are combined with different attack methods such as phishing or pharming or even search engine manipulation.

Wreaking havoc

All it takes is for malicious malware to end up in your network is an employee to fall for a phishing email, clicking on a poison link and then being redirected to a website where a Trojan is implanted into the network.

The CESG’s 10 Steps to Cyber Security outlines the potential in a rather prosaic manner: “Malware infections can result in the disruption of business services, the unauthorised export of sensitive information, material financial loss and legal or regulatory sanctions.”

Blackmail

Malware can lead to blackmail, the deletion of entire databases, key loggers that record every finger tap across a keyboard, backdoors that are used to implant malware, rootkits that provide full access to a system and passwords stealers.

As malware has been around for such a long time, everyone is familiar not only with the damage it can cause, but also its ubiquity. As a result, there is widespread understanding that it needs to be guarded against which is positive.

The most effective way of doing this is via robust and rigorous antivirus at the firewall. Antivirus needs to dovetail with other defence methods such as real-time threat detection and forms of detection that don’t just rely on detecting virus signatures. This is because host and client machines also need protecting.

Zero day threats

While signature detection is important to block the hundreds and thousands of malware variants that swarm the Internet, it’s not enough to detect newly- released malware, so called zero-day threats.  As more Internet traffic becomes encrypted via the HTTPS protocol, the need for layered malware protection becomes more acute.

It’s possible to use technology that not only sends an alert that an unknown file has entered your network, but also informs you whether it reached a computer, if it executed, what it did, when it ran, if it spread or deleted itself and so on. If the file is malicious, you can automatically stop it from executing. This enables you to rapidly prioritise alerts, investigate events, and remediate incidents.

Wide ranging defence

This holistic layered approach recognises that malware infections are, not only, too common, but the enterprise needs protecting across the range of its systems. From the perimeter firewall to endpoint devices, protection is needed at every stage.