Showing posts with label Ransomware. Show all posts
Showing posts with label Ransomware. Show all posts

Friday, 26 May 2017

Pull the budget and suffer the consequences: the NHS ransomware attack [Link: Information Age]

I was asked to help source an article about WannaCry on the NHS. Here is the article that was published on the Information Age website: http://www.information-age.com/pull-budget-suffer-consequences-nhs-ransomware-attack-123466474/

=========================================

Why wasn’t more done to protect NHS organisations from the WannaCry ransomware attack?


Ransomware infects computers around the world every day. In the last 18 months, instances of it have surged so prolifically that today it is the most common type of malware. However, the WannaCry strain hit the headlines because it brought large parts of the NHS to a crunching halt.

This is the problem with malware, it can have devastating effects. We don’t know what the real-world physical implications of WannaCry have been, for instance, patient treatments. Perhaps we will never know.

At a first glance, it appears almost criminal to be running operating systems that are no longer supported, in the case of the NHS, Windows XP. This was in no way helped by the government pulling the plug on an XP support contract to save money.

The ransomware infection was so serious that the government chaired a Cobra meeting, code for official panic. While patching an operating system is a fundamental security step, there can be a number of issues that complicate the process.

For instance, an organisation with a desktop fleet consisting of thousands of PCs might simply have not set up its configurations correctly, leaving holes in its patching process through which malware can insinuate itself.


Risk register


Some organisations might be reluctant to automatically apply operating system patches because they could cause conflicts with business critical applications. In short, they might be unable to patch for fear of slowing down, or even halting other parts of the business.

In both these cases there should be at least an awareness of the potential risks. It could be that an IT team is stretched thinly and is juggling other issues such as networking or storage, and consequently security slides down the list of priorities. This isn’t uncommon.

In these cases IT should be creating a Risk Register which is essentially a list of system vulnerabilities of why they exist, how they can be remediated and why they haven’t been addressed. This could be because of budget limitations or some other reasons.

The C-level executive team should sign off on the ‘risk register’ to show that they are aware of the issues and have accepted responsibility. This protects IT from any fallout should a serious breach occur, and also illustrates that they are doing their job.

Finger pointing


The WannaCry breach led to a lot of finger pointing and within hours had also become a political hot potato. Many people in the industry were quoted saying that defences are only as strong as the weakest link.

This is a self-evident truth, but in this case a very large condemning finger was pointed at end users. The implication was that a naïve employee or cluster of employees had clicked on an email link which unwittingly unleashed the worm-like WannaCry ransomware.

Phishing emails are increasingly sophisticated and even the most alert and astute end user can be fooled if the mail is targeted and well-crafted. The only problem with blaming end users is that it smacks of scapegoating and is essentially an abnegation of responsibility. However, there has been no evidence to suggest that WannaCry was initiated by an email or spread by user interaction.


First lines of defence


End user education and training is important and should certainly be more than an annual box ticking exercise. As well as patching operating systems, it should be a last line of defence and certainly not the first line.

Any organisation that is serious about IT security will have a range of defences in place to safeguard against these types of attacks. For instance, an email security gateway with sandboxing will filter out ransomware even if a user clicks on a malicious link. A web security filter with sandboxing will protect against drive by downloads, in which someone has to just visit a website to inadvertently download malware.

Web filtering tools in conjunction with a good firewall can detect dubious websites, as well as flag traffic that is leaving an organisation for a questionable destination. Of course there is also heuristic and signature detection, so if malware does penetrate the network it is immediately detected and stopped.

Added to this are a raft of endpoint tools that can protect devices, and we’re not just talking about patching operating systems but also patching browsers, plug-ins and third party software for vulnerabilities. On top of this, admin rights should be removed from endpoints so software doesn’t automatically run by default.


Lack of willingness


In short, the tools are available to protect organisations from ransomware and other types of malware, and they don’t have to be the latest and the greatest either.  The real question is whether the willingness to take security seriously is there? Given the large number of attacks that happen regularly you’d have to say it’s not. For instance, if there’s commitment then budget is always made available to help over stretched IT teams.

Clearly in the case of the NHS the funding was missing, and if the government doesn’t yet fully understand the importance of comprehensive cyber security then who will? Will it take loss of life before someone sits up and takes security seriously?

Tuesday, 23 May 2017

So you have WannaCry 2.0, what next?


So you machine is infected, what can you do?

Immediate Action


  1. Find all the machines vulnerable to MS17-010.  This can be done using scanning tools or wholesale apply the patch to all machines.
  2. On the infected machines, don't pay the ransom - Research suggests that payment will get your files back two thirds of the time.
  3. Try the WannaCry decryption tool and skip to step 5 on.
  4. If the decryption tool fails, re-install your operating system - remembering to patch it.
  5. Install a good malware protection solution, switch on real-time updates and update it.
  6. Scan your machine with your newly installed and updated malware protection software.
  7. Re-install essential applications, remembering to check for patches, and switch on auto updates.
  8. Copy back data from backups, remembering to scan it as you do.  One of your backup files could be infected.

Next Steps


  1. Create a standard user account for general use, and keep the administrator account for configuration changes only.  Although WannaCry did not need administrator credentials, other ransomware does.
  2. Consider Application Whitelisting to ensure only known applications are able to execute on your machine.
  3. If you existing firewall allows it, switch on web filtering to prevent traffic to known malicious sites.
  4. Consider using an IPS (Intrusion Prevention System) to protect your network. 
  5. A Web Security Gateway to monitor and prevent traffic to malicious websites, and sandboxing to scan unknown packages.
  6. An Email Security Gateway can monitor and scan emails, working in combination of a sandbox to scan unknown attachments, and a Web Security Gateway to validate URLs within emails.  Although email was not the delivery mechanism for WannaCry, it is for pretty much 90+% of ransomware.
  7. Check existing backups and/or start doing backups.

Planning for the future


  1. User training is important, but it must be remembered that WannaCry 2.0 wasn't propagated by email and didn't require user interaction to install or spread.
  2. Ensure an open policy for users to report to IT Teams or Information Security Teams with any suspicious behaviour on their machines.
  3. Test the environment with simulated attacks to ensure the People, Process and Technology work hand in hand together.

WannaCry/WCRY 2.0 - What do we know?


On Friday 12th May, we were all made aware of a global ransomware attack, which hit nearly 200 countries, infecting over 300,000 Windows machines.  Named WannaCry/WCRY 2.0, it encrypts your data and demanded a ransom of US$300 payable in Bitcoins (electronic currency).

Timeline


Looking back to earlier in 2017, shows how WannaCry evolved.

14th March 2017 - Microsoft leased a patch it classified as Critical as part of its month patch cycle.  The patch was called MS17-010 which resolved a vulnerability in the SMBv1 server on machines running Windows workstation and server operating systems.

14th April 2017 - Shadow Brokers leak the NSA hacking tools which exploited the MS17-010 vulnerability.

14th April 2017 - WannaCry/WCRY 1.0 was released

12th May 2017 - WannaCry/WCRY 2.0 was released

History


WannaCry/WCRY 1.0 was a spam campaign, which delivered its payload via compromised or malicious Dropbox accounts.  To all intents and purposes, it felt like a typical ransomware attack, delivering an email with a link, the user clicking on the link to download the ransomware, the ransomware would exploit a vulnerability (in this case MS17-010) and then encrypt the data.

Why is WannaCry/WCRY 2.0 different?


It is believed that WannaCry/WCRY 2.0 was not distributed via email, nor was it caused by clicking on a link.

WannaCry/WCRY 2.0 scans for Windows machines that are running SMBv1, and will try to infect them.  I say try to infect them, because if the machine had the MS17-010 patch installed, it could not be infected.  The ransomware will exploit the vulnerability, install and encrypt the data.  WannaCry/WCRY 2.0 also has a worm like characteristic, where it will scan the local network and random external IP address to see if they are running SMBv1 and try to infect them as well.

The clever part of this ransomware, is that it requires no user interaction to initiate it or to spread it.

What as the criminal gain?


Some organisations have been monitoring the Bitcoin wallet and they estimate that the financial gains from this attack is in the region of US$65-70,0000, which doesn't sound like a great deal.

Whose vulnerable now?


Using Shodan it's possible to search for Windows machines on the internet using the SMBv1 protocol.  Of course, it doesn't show if these machines have been patched to prevent MS17-010 from being exploited.


Sunday, 14 May 2017

So you have Ransomware, what do you do?

I've put a lengthy blog post about ransomware, but you just want a quick and simple answer?

Your machine is infected and your have this screen:


  1. Don't pay - Research suggests that payment will get your files back two thirds of the time
  2. Re-install your operating system - remembering to patch it!
  3. Create a standard user account for general use, and keep the administrator account for configuration changes only.
  4. Install a good malware protection solution, and update it
  5. Scan your machine with your newly installed and updated malware protection software.
  6. Re-install essential applications, remembering to check for patches, and switch on auto updates.
  7. Copy back data from backups, remembering to scan it as you do.  One of your backup files could be infected.
Going forward:
  • Be mindful of any email attachments or links within emails
  • Continue to update malware protection, operating system and applications
  • Ensure backups are happening to prevent data loss, and even consider multiple backup destinations
  • Only use the admin account for configuration changes
This advice is more based for home users, but your can see the relevance to organisations as well.  For a more detailed look at ransomware, and what approach a organisation can take, have a look here.

Saturday, 13 May 2017

The Anatomy of Ransomware - and How to Prevent from Impacting You

After the global cyber attack with ransomware, there is much advice out there suggesting the problem would have been prevented with point products, training or procedures.  I'm going to outline a generic ransomware attack below, so that the defences can be understood.  I'm going to outline what you can do as a home user, corporate user, or corporate IT team.


Delivery of Ransomware


Depending on the research you read, you can see that 93-98% of ransomware is delivered by email.  The remaining delivery methods can be via websites, whether a drive by download, malvertising or malicious website; or via removable media.

As a home user, a good quality endpoint protection solution would be recommended.  Try not to click on email attachments, dubious weblinks or using removable media you are unsure about.  Look to only have standard user profiles and not administrator rights on your everyday profile, and enter the admin credentials when needed.

As a corporate user, the advice is similar to a home user, try not to click on email attachments, dubious weblinks or using removable media you are unsure about.

As a corporate IT team, email and web gateway solutions should be protecting the email and web traffic.  The endpoint should have good quality multi layered protection.  Ensure that users do not have local administrator rights.  Sandboxing solutions on the network would analysis the unknown traffic coming into the network and ensure the email, web and endpoint vectors are covered.  Consider device control solutions if removable media is a big entry point into the network.  User education can help, but it needs to short and regular, and not many hours once a year.

Exploit the Endpoint


The ransomware's next task is to find a vulnerability on the endpoint, in order to exploit it and install the ransomware.  This is when the advice is to patch your operating system, or check and install the updates to your machine.  It's lesser known that the other software on your machine also has vulnerabilities, such as the third party software, like Java, Adobe Reader, etc, as well as the internet browsers and add-ons.

As a home user, change the settings on the operating system and software to automatically check and install the updates. Consider removing applications that are rarely used, as some may not check for updates until they are used.

As a corporate user there is typically little you can do, as this should be controlled by the administrators.  If you are able to run the updates, check regularly.  If you are able to install applications, consider what you are installing and switching on auto updating.

As a corporate IT team, ensure there is a robust patching regime.  Ensure patches are deployed to Microsoft operating systems as close to "Patch Tuesday" as possible, to prevent there being a "Hack Wednesday".  Ensure the patching regime goes beyond operating systems, covering off the third party applications, browsers and add-ons.  Consider Application Control solutions to limit the applications on the endpoints.  With the server environment, consider using IDS/IPS or "Virtual Patching" solutions in order to protect the servers until patch remediation can be carried out in a scheduled maintenance windows, allowing for testing of patches prior to deployment.


Installation of Ransomware


The installation of the ransomware will typically be disguised as a system process, so can go undetected by traditional or single layers of defence.

As a home user with the administrator rights removed as mentioned before, the software may not be able to install.  Again a good quality anti-malware solution may help prevent the ransomware from being installed.

As a corporate user there is typically little you can do, as this should be controlled by the administrators.

As a corporate IT team, look to Application Whitelisting, so unknown applications can't be installed.  Also giving the known good software will check fingerprints of applications, so even if the ransomware is masquerading as a system process, it will not be allowed to execute.  Again good multi layered anti-malware protection and limited local admin rights will help.  Sandboxing solutions should detect this traffic, and consider tools that can monitor file integrity, analyses the memory or offers memory injection protection.

Command and Control


Once installed, the ransomware will typically talk back to the "Command and Control" servers, communicate with the ransomware and customise what the machine will do, such as detect language settings of the computer and then get the correct interface installed in the matching language.  A Chinese demand for a ransom would not be very effective to a machine using Russian language.  There can be communication of the unique encryption key as well.

As a home user, beside the reliance on the endpoint protection having a good malware detection and possibly a host based firewall, there is very little that can be done at this point.

As a corporate user, the situation is much the same as the home user, as there is little that can be done.

As a corporate IT team, the use of Next Generation Firewalls and/or web gateway solutions should be able to see this traffic travelling to and from the network, and prevent the communication.  Logging or SIEM solutions should be able to take the feeds from various point throughout the network to detect this activity.


Data Encryption


The ransomware will now start to encrypt a portion of each of the files, allowing it to work quickly through all the files.  It will check for connected devices, so it will be able to encrypt network file shares and removable media connected to the machine.  It also knows to leave the operating system files, so the machine is still able to run and demand the ransom.

As a home user, beside the reliance on the endpoint protection having a good malware detection and possibly a host based firewall, there is very little that can be done at this point, aside from ensuring that there are system backups.

As a corporate user, the situation is much the same as the home user, as there is little that can be done.

As a corporate IT Team, the anti-malware solution may be able to detect this and stop it from running, or the use of application control could have prevent the application from executing as mentioned before.  Beyond that the the dependence will be on having system backups.


Ransom Demand


At this point, whoever you are, all is lost with out system/data backups.

The advice is not to pay as research currently shows that the payment of the ransom will to the decryption of the data around two thirds of the time, and increases your possibility of being targets again.


The Advice

As a home user, don't click on links without validating if they are legitimate, get a good quality endpoint protection solution and patch your computer regularly.  Remember to backup your data, whether to the cloud, portable hard drives or USB devices, and try not to physical devices connected when not in use.  Make your account a standard user, so the administrator password is required for tasks that are altering the configuration of your computer.

As a corporate user, don't click on links without validating if they are legitimate, but work with IT, if you think you have.

As a corporate IT Team, ensure the endpoints have good quality malware protection that can be centrally managed and centrally logs information.  Ensure there web and email gateways installed and configured.  If you don't have a NGFW, consider getting one and using the features available.  Patch the operating systems, applications and browsers on endpoints and servers.  Consider investing in Device and Application Control solutions, if you don't already have them.  Sandboxing solutions will help deal with the unknown and new threats, so are well worth the investment.  Review the rights the users have on their devices, as they typically don't need to be local administrations.  SIEM solutions with security features will help detect this early on.  End user training is important, but keep it short and regular for it to be effective.


Conclusion


Ransomware attacks will continue to happen, but stopping the chain of events as soon and as quickly as possible will minimise the damage.

I hope this guide has been useful in helping understand how ransomware works, and the measures that can be taken to prevent if from impacting you.  If you have any questions, please feel free to email me: blog@andytang.com

Wednesday, 15 February 2017

Can AV stop Ransomware?


I've read a few articles recently questioning whether "traditional" anti-virus solutions can stop Ransomware. There have also been articles comparing "traditional" and "next generation" solutions, all with their own agenda, both questioning the others ability to prevent Ransomware.

I feel that it's a simplistic approach to ask whether solution "X" or "Y" will prevent Ransomware, especially without understanding how Ransomware works.

If a majority (93-98%, depending on which survey your read) of Ransomware comes into an environment via email, then the first point of preventing Ransomware, is using an email security solution. Other entry points can be via drive by downloads or malvertising, so a web security solution can also help prevent the delivery of Ransomware.

Once on the computer, the malware will look for a vulnerability whether it's the operating system, browser or third party applications. Patching the computer will protect your computer from known vulnerabilities, whether it's carried out manually or using a patch remediation solution.

Once your computer is exploited, the Ransomware can be installed. This is assuming that the user had local administrative rights onto the computer. Application Control solutions could also prevent the installation of the Ransomware. This is the point where an anti-virus/anti-malware solution would be expected to stop the installation of the Ransomware.

Once the Ransomware is installed, it will typically communicate back to the Command and Control server. This traffic will need to cross a perimeter solution, so could be seen by a NGFW solution, web security solution or via SIEM or logging solutions.

After this, the Ransomware will encrypt the computer's hard drive and demand a ransom. At this point, it's recovering from backups or paying a ransom in the hope a decryption key will be provided.

Can (traditional or next generation) anti-virus or anti-malware solutions stop Ransomware? Potentially, but that's assuming there is no email security solution, no web filtering solution, no patch remediation, no application control, users have local admin rights, no NGFW, no SIEM solution, no next generation firewall, and no back ups are in place.

Let's not get stuck in trying to find a silver bullet, but understand the attack and therefore apply appropriate measures to prevent this from happening to you.

Tuesday, 6 December 2016

Cyber security in 2016 – why is it still not happening? [Link - ITProPortal]

I was asked to write an article reviewing the cyber security challenges for 2016, Here is the article that was published on the ITProPortal website: 

===================================

It's 2016, and businesses are generally still not taking security seriously.

Image source: Shutterstock/jijomathaidesigners

Perhaps the surprising, and damning, thing about 2016 in terms of security is that businesses are generally still not taking security seriously. Nobody wants to admit to being slack when it comes to cyber security, but the indisputable fact is that during 2016, many organisations simply didn’t show up, whatever they claimed.  

The basics are still not being done. Updates aren’t being applied, patching strategies are not in place, admin credentials are easy to find. Let’s be blunt, people are still trying to do security on the cheap, using, for example, free antivirus software.  This was most evident in the amount of ransomware that infected companies. 

A Trend Micro report claimed that 45 per cent of UK businesses were hit by ransomware this year. We believe the figure is much higher, closer to 60 or 70 per cent. 


Ransomware scourge


In the US, hospitals have paid massive amounts of money when their databases have been encrypted by ransomware. The Hollywood Presbyterian Medical Center paid a $17,000 bitcoin ransom for the decryption key for patient data. It was infected by the delivery of an email attachment disguised as a Microsoft Word invoice. In the UK some hospitals had to cancel operations.  

Hundreds of planned operations, outpatient appointments, and diagnostic procedures were put on hold at multiple hospitals across Lincolnshire.  The damage done by ransomware in 2016 is largely attributable to the infamous Locky and its many variants. It was first identified in February and made it to the top of the ransomware charts only two weeks later. 

It initially used malicious macros in Office documents to infect its victim’s computer, and these documents were distributed attached to spam emails. Locky has been through several versions since then. A new version was released on October 24, and less than 24 hours later yet another version was launched. It’s carried through phishing campaigns and the email subjects are centred on pay cheques, receipts, invoices, orders, or wrong credit card charges all of which are themes designed to fool recipients into opening attached files.   

Heads in the sand


In a sense it’s staggering that people are still falling for these tricks, given the exposure about ransomware dangers. There still seems to be a general mindset that ‘it will never happen to me’, when it clearly is happening to lots of businesses and individuals.  It’s frustrating because basic security measures offer protection. Being on the front line we tend to get a good sense of what is happening on the ground and it can be best summed up with the phrase ‘blind panic’ when a company is hit.  

But this lack of awareness, or ‘head in the sand’ scenario, is also playing out across other areas. Security in 2016 can also be defined by the large number of replay attacks that have taken place. Ransomware is included in this but it’s not exclusive. Yahoo is perhaps one of the biggest culprits. 

In 2012, a security breach exposed 450,000 usernames and passwords from a site on the huge web portal with the company failing to take even basic precautions to protect the data. Two years later it happened again with 500 million account details stolen.

Enormous DDoS attacks


Yahoo cried ‘state-sponsored actor’ in its defence but clearly it’s still not adequately protecting its customer data. This defence is usually code for ‘don’t blame us, it was a really sophisticated attack’. And Yahoo only came clean in 2016. These serious errors are clearly an illustration of some fundamental flaws at the online giant. Is it any wonder that it’s gone from an operation worth close to $100 million at its peak to today’s evaluation of $4.8 million? 

Another large 2016 security event, which ironically few noticed at the time, was the largest DDoS attack recorded, a whopping 540Gbps directed at public facing websites belonging to organisations affiliated with the 2016 Rio Olympics. These attacks were sustained, sophisticated, and actually started months before the Olympics began.  

These attacks were clearly aimed at the global stage and foreshadowed the equally massive IoT botnet based DDoS attacks which, in contrast, caught the attention of the mainstream media because they were launched from compromised everyday household devices such as internet connected video recorders and cameras.  

Plundering millions


The industry, at large has been warning about the parlous state of IoT security for some time, but it seems no one really wants to listen until an attack hits home and hurts bank balances.  

The Swift’s global payments network hack that resulted in $81 million being siphoned from Bangladesh central bank was also noteworthy due to the huge amounts of money involved.  Hackers also exploited the Swift system to steal a reported $10 million from an unnamed bank in Ukraine, while back in Bangladesh an eye watering $1 billion cyber theft was only stopped when an eagle-eyed employee spotted a typo. 

In an ironic way it’s almost fitting that a hack to see out 2016 was the attack on Tesco Bank. The company was forced to repay £2.5 million of losses to 9,000 customers in a heist described as ‘unprecedented’ by regulators. It may seem small when compared to the Swift system hacks but there’s worrying significance that the company apparently ignored warnings that its vulnerable software was being targeted by cyber criminals for months before the attack. What is just as shocking is that the bank didn’t even encourage two-factor authentication for its customers. 

How many more financial organisations are going to be nailed by cyber thieves before the message gets through? If the EU General Data Protection Regulation had been in force, which is due to come into effect in 2018, Tesco would have been hit by a fine up to £1.9bn. And who could say that Tesco and other organisations with terrifyingly lax cyber security wouldn’t deserve it?

Monday, 5 December 2016

Cyber-security in 2017 – brace yourself [Link - ITProPortal]

I was asked to gaze into my crystal ball and write a piece around the Cyber Security challenges for 2017.  Here is the article as it appeared on the ITProPortal website: 

=================================

If there’s one thing you can say with certainty about cyber-security in 2017, it’s that many companies are going to fail because they are simply not doing the right thing. Fundamental flaws still exist.

Image source: Shutterstock/jijomathaidesigners

It's about the business


Until the technical people lift their heads up and see that security and business are different sides of the same coin, we will inevitably see more damaging attacks. When security people learn to speak in the language of business they will begin to understand just where in the organisation they need to apply their expertise. 

This might be smart configuration options, cautious security policies, vigilance and a willingness to read server logs like some people read the newspaper in the morning to identify targeted attacks.  

Of course, this won’t stem the malware tsunami but it will help defend against it. Leading the malware charge in 2017 will be ransomware. Like 2016 it will be more of the same, with an important and fundamental exception; ransomware will be more sophisticated.

Advanced attack vectors


Encryption keys are becoming more complex while ransomware attack vectors are becoming alarmingly advanced. Ransomware can mount previously mapped drives, encrypt them, and then unmount them, reaching deeper into the network.  

However, the efficiency of ransomware as a tool for fraud will also be slowly undermined. One misconception about ransomware is that once the ransom is paid, the victim receives the keys to unlock their files. Increasingly we are seeing instances of this not happening. The fraudsters are simply taking the money and running.

Criminals dumbing down


As ransomware is now available as-a-service, it is reaching down into the lower levels of the criminal underworld and organised crime networks. The type of villain who uses the ‘service’ might have previously been involved with keeping crooked books for instance.

As such they can’t be bothered to send decryption keys which of course will erode the value of ransomware as victims increasingly refuse to pay the ransom.

IoT security


Another major area of concern is the security of IoT devices. It’s fair to say that the existing state of device security isn’t great. Some devices are managed by web consoles that don’t even have encryption. Some devices have passwords hard coded into them that you can’t change. It would be good to see manufacturers take some responsibility but this is unlikely as they operate with tight margins and are unlikely to take on tasks that eat into thin profits. 

If we’re lucky, we will see the emergence of pressure groups consisting of industry vendors and third parties who are no longer willing to sit back and watch major hacks unfold. 

Questioning machine learning


Another area to keep an eye on is machine learning. As with any new technology it’s usually proclaimed with a loud fanfare and over exaggerated claims that often fall just short of guaranteeing freedom for all and world peace. In terms of security, machine learning does promise a lot of potential but when you drill down some serious questions need to be asked.  

In 2017 we’re likely to see these questions put forward with some force, as it becomes apparent that machine learning in the security realm has flaws. For instance, how are the machines learning, are millions of good and bad results being fed into the machine to ensure accurate analytics and what kind of input is coming from security labs and research teams?  

These are important questions and with the advent of next-generation endpoints, such as mobile devices and laptops designed to respond to machine learning security in depth is vital to ensure success. If machine learning vendors can’t answer these questions with confidence, then you can expect to see machine learning and security take a dive.

Shock of GDPR


An area where you can expect to see panic break out is the European Union’s General Data Protection Regulations or GDPR as it’s more commonly known. At the moment UK organisations are displaying naivety towards GDPR which comes into effect in May 2018. Many are hiding behind Brexit and taking the view that the UK won’t be in the EU come May 2018 so GDPR won’t affect them. However, if a business operates in Europe, it will.  

To meet GDPR requirements, measures need to be put in place in 2017. Many companies have already finalised budget for 2017 but haven’t made any provision for GDPR. With no budget provision, there’s going to be an awful lot of flapping when companies realise that it’s nowhere near compliance ready. 

Big fines, big panic


GDPR also reaches up to the board and any data breaches can result in enormous fines of up to 4 per cent of revenue. This can and will translate in some cases, to fines that run into millions of pounds. Are executive directors aware that if they show negligence in protecting customer data they’re going to be hit really hard?  

In summary, it would be uplifting to say that we’re not going to see any more major breaches, that fundamental flaws will be addressed, that new technologies are going to change the security landscape for the better and everyone is set for GDPR. In reality, while we will see some positives we also need to prepare our businesses for more breaches and more hacks. 

Thursday, 3 November 2016

How businesses can protect Office 365 from ransomware attacks [Link - MTI Bytes]

After a recent webinar from Chris Taylor, Director of Product Marketing from Trend Micro around Ransomware, I created a blog post around this: https://www.mti.com/mtibytes/how-businesses-can-protect-office-365-ransomware-attacks/

=============================

In the last year, businesses have seen a large increase in ransomware threats. The Guardian recently reported that 54 per cent of businesses have been threatened with ransomware in the last 12 months alone. When we consider the money that can be made from a career in cyber crime, this is hardly surprising.

Ransomware refers to malicious software (malware) which is designed to block access to a computer system until a sum of money is paid.

But how can you protect your cloud environments from it? In a recent webinar, Chris Taylor, Director of Product Marketing, Trend Micro, looked at exactly that:

How does malware work?


Email is a common method that attackers will use to infect their victims, most often businesses. The malware is embedded in an email either in the form of a web link in the body of the text, which vulnerable users click on or a link within the attachment.

It is becoming increasingly more common for malware to be laced within documents in email attachments. Embedded JavaScript within the text encourages users to unknowingly click, starting the download of malicious software. It can be more difficult to detect the malware via the email attachment as it could be compressed within a common office file, such as a CV from a job-hunter, or an invoice, which seem convincing.

Prevention is better than cure


There are a number of recommendations that can be made, such as always back up your system, make sure it’s fully patched and train users not to open suspicious attachments. However, there are opportunities to stop many ransomware attacks before it even gets to that point. The best way is to block ransomware before it has a chance to reach users. There are certainly fix measures that can come in and save the day should the worst happen, but this can take up a lot of the IT team’s time.

What can businesses do to protect their Office 365 environment?


Office 365 includes anti-spam and anti-malware protection, which block every known malware. But the majority of malware is unknown, as criminals are increasingly using automated tools to change their malware, to beat the system.

In order to remain one step ahead from threats, businesses can implement advanced threat protection, which looks for malware in different ways, malicious URLs in attachments as well as the body of emails, and full data loss protection.

To set up a free evaluation of your Office 365 protection, email ukmarketing@mti.com

Tuesday, 27 September 2016

CLOUDSEC takeaway – Cyber security is not just an IT issue [Link - Trend Micro Blog]

After attending CLOUDSEC 2016, I was asked to create a guest blog on the Trend Micro blog site, including standout statistics and take-away lessons: http://blog.trendmicro.co.uk/cloudsec-takeaway-cyber-security-is-not-just-an-it-issue/

===========================

With a fantastic turnout at CLOUDSEC 2016, attendees comprised of security and IT practitioners from numerous industries. Despite these varying sectors, one thing became abundantly clear: the same issues are keeping IT security professionals awake at night – securing cloud environments, securing privileged access accounts and user education.


Many enlightening statistics were shared. Trend Micro’s research found that in the last two years, 44% of UK businesses were hit by ransomware attacks, and a third (33%) of their employees were affected by the infection. We also heard that over $2.3 billion was lost to phishing attacks over the past three years (FBI), though the real figure is likely to be higher.

While this makes the somewhat abstract world of cyber threats very real indeed, if there’s one point to take away from CLOUDSEC, it’s that cyber security isn’t just an IT issue. When the entire workforce is educated around safe IT usage, the chance of a business network being hacked is significantly reduced.

Everyone needs best practice training 

Organisations can defend against cyber-attacks; they don’t have to be victims. While in any organisation the CIO ultimately takes responsibility for cyber security, the rest of the organisation needs to accept responsibility too and not just shrug their collective shoulders. Regardless of seniority, companies should invest in best practice training when using a corporate network.

Best practice knowledge should percolate through the entire organisation from board directors, to employees and IT people involved in daily operations. It should explain why businesses have approved channels for storing data, the risks of using personal cloud storage platforms for data storage, and the need to question email content if it arouses suspicion – even if it’s from the CEO’s office.

Employees must understand the importance of cyber defences within the context of the business and how to safeguard against internal and external intrusions. Are they aware of the importance of setting difficult to crack passwords, as well as understanding that password variations of existing passwords are a source of vulnerability when used in other parts of the network? Do they know that in the last six months or so, ransomware attacks have spiralled as ransomware-as-a-service kits became commonplace on the dark web?

Serious business implications

The whole organisation must realise the possible business implications of a major hack – spiralling revenues, lost customers and plummeting share price, and this could all happen well after the event. Furthermore, jobs could be on the line if declining income hits the business badly.

Despite the growing evidence suggesting otherwise, many organisations still believe they won’t be hacked. With that said, however, if cyber security education is a part of the organisational culture, the chances of a serious breach are dramatically reduced.

Tuesday, 5 July 2016

The scourge of social engineering [Link- SC Magazine]

I was asked to write a piece on Social Engineering for SC Magazine.  It's in a section called "Last Word" and as it's the last print copy before it moves to digital only, I literally have the last word in SC Magazine! http://www.scmagazineuk.com/the-scourge-of-social-engineering/article/504950/



==============================

Today, social media platforms are no longer just a forum for online chat but an important every day work and communication tool. Facebook alone has more than a billion users, while social media business platform LinkedIn has more than 400 million users.

Going after the big guns


A well-publicised incident was a three-year social engineering campaign carried out by Iranians. It targeted US military officials, diplomatic and congressional staff, and defence contractors in the country and abroad.

The Iranian spies used Facebook, LinkedIn, Twitter and Google+ to carry out a sophisticated attack. They developed fake social media personas and posed as recruiters from major international companies including Northrop Grumman and General Motors. The targets were largely in telecom, government and defence industries.

When a connection was established emails were sent to victims with malware hidden in links and attachments. The aim was to get the target to download malware into their computers which would give the hackers access to highly sensitive information. The striking thing about this social engineering-based attack was its scope and sophistication. It's certainly not an isolated event; for some cyber-criminals it's a career path.

You don't need state resources or an encyclopaedic knowledge of psychology and social media surfing habits. You don't even need to be well-versed in the dark arts of black hat coding. All you need is a bit of patience to trawl the web and the knowledge that too many people put far too much information online than is necessary.

It doesn't take much to create a complete profile including place of work, employment history, address, age, family, likes, dislikes, bank, shopping, recent purchases, family members, their locations and so on.

All information to create a complete profile can be gleaned within a few hours. There are even open source tools designed to help trawl social media platforms and scoop up as much information about any one individual as possible.

This information can be used for targeted phishing attacks at a place of work or brute force password attacks on a company's network. Personal information is gathered on the ‘target' from social media and a phishing email is sent to their place of work.

Malware-laden messages


A phishing email is usually mocked up to look as though it's from an organisation the target has recently dealt with. For instance, the victim may have posted something about his or her brand new iPhone, so the hacker creates an email that purportedly comes from Apple with a message about the phone. A link in the email is clicked by the ‘target' and malware is downloaded into the retailer's system. This provides the means for a hacker to steal the contents of a customer database.

This data is put up for sale on a deep net website that trades in credit card and identity information. The hacker is set to make hundreds of thousands of pounds for a task that in all likelihood took a few days to carry out.


A need to click


Organisations today are, by and large, aware of cyber-threats that come from malware such as trojans, viruses and to some extent, ransomware. However, many haven't yet fully grasped the implications of social engineering with people freely giving away information and casually downloading files from the Internet. As a result, education and awareness programmes for employees can make a significant difference.

At the very least, education programmes will hammer home the point that there are cyber-criminals circling corporate firewalls who are only too keen to get into the network.

Education will make employees aware of sophisticated phishing techniques and how sharing too much of their personal information on a social media platform could well provide the starting point for a crippling network attack.

This can also make personal practice tighter so they don't post workplace information or inadvertently reveal pathways to corporate crown jewels.

Monday, 4 July 2016

Stopping ransomware in the public sector [Link - MTI Bytes]

This is a blog piece that was created for the company blog site: http://blogs.mti.com/blog/stopping-ransomware-in-the-public-sector

===============================================

In just over 10 years, ransomware has become a serious threat for many organisations across the world. In 2016, we have already seen a 300 per cent increase in attacks, which roughly equates to approximately 4,000 a day. Worse still, this figure is predicted to double year on year.

While there is no perfect solution to stop organisations from ever fully preventing these attacks, arming yourself with knowledge is the first and best defence to mitigate them should they arise.

Risk to the public sector

The public sector in particular is at risk from ransomware attacks. With a great deal of important and personal data stored in these organisation’s databases, the potential damage caused by workers being locked out of their systems can be significant.

In January 2016, Lincolnshire County Council shut down its entire IT network after a new strain of ransomware demanding £1 million was found to have penetrated the system. This new malware forced the council to shut down to protect personal data – including those it provides social care for.

Triggered by one user, and on a system that was up-to-date with the latest protection, the intrusion meant that operations were left without any IT for a number of days, which of course has a knock on effect for service delivery.

The above example, along with a recent spate of attacks against hospitals in the US, Canada, Germany and New Zealand, show that public sector organisations in wealthy countries are amongst those at the highest risk, presumably due to the greater likelihood of them being able to pay the ransom.

Knowing the threat

Ransomware is a form of malware that can affect a device without the user knowing. The first instances of ransomware came to attention in 2005 and were comparatively crude. However, in the following 11 years, it has become far more sophisticated as hackers re-invest profits into new malware.

Recent evolutions have seen the virus become more effective and hard-line. Some now include a sleep timer, which means that the encryption process can begin at a time of the virus writer’s choosing and be executed over an extended period, which also makes it harder to notice.

The Petya strains of the virus, which came to light in the first quarter of 2016, takes encryption to a new level. Discovered after emails with Dropbox links to download a file containing ransomware were found, Petya encrypts the hard disk itself, deleting the backup files which were previously used as a solution to counter-act ransomware. It also avoids detection by signature-based anti-virus software, making it even harder to find.

This new strain could have massive implications for the public sector, leading to vital information being lost or even stolen while IT teams scramble to try and stop it from spreading across the whole system.

Education is essential

So how can councils, hospital trusts, and other public sector organisations protect themselves against this threat and remain online?

The attack on Lincolnshire County Council happened because a new strain of the malware had not been encountered before, therefore there was no protection against it. It was also a human error, as it took only one person downloading it onto their system to cause a significant issue.

While IT professionals are always trying to stay ahead of the game, there is no form of protection that is 100 per cent perfect all the time, especially when human error is factored in.

The main solution to mitigating attacks lies in educating staff to understand why security processes are in place, and what happens when they circumvent them or use applications not authorised by the company, for example, downloading files from unknown contacts via Dropbox.

Alongside educating staff, IT departments should enact a principle of least privilege when it comes to local administrators. This will be essential in ensuring that if a device is infected, the information it can encrypt will be minimal and does not spread through the system.

There also needs to be a protocol in place for when an attack does happen. Directors need to work with their IT departments to come up with a plan of action, deciding whether or not to take the precaution to shut down systems, to go public with the attack or keep it in-house and – crucially – if the ransom should be paid.

Ransomware is pervasive and very dangerous for public sector organisations, considering the sensitive data they hold, so education is vital. Get the knowledge and learn more best practises in our complete guide to ransomware by downloading it here.

Monday, 25 January 2016

A Year in Vendor Patching: Does an Increase in Patches Mean we are More or Less Secure? [Link - Infosecurity]

I'm very proud to have a blog piece published by Infosecurity.

http://www.infosecurity-magazine.com/blogs/a-year-in-vendor-patching/

===============

Vulnerabilities and subsequent vendor patches are part and parcel of a company’s use of different operating systems and product software. However, a significant increase in the number of vendor patches released in 2015, in comparison to 2014, alongside the number of high-profile breaches prompts the question: Why was 2015 such an insecure year for vendors and why did cyber-threats see a marked increase?

A recent report by PricewaterhouseCoopers suggests that incidents of cyber-attacks or breaches have risen by 38% from 2014. A study by HP Enterprise Security found that this growing phenomenon is costing UK firms an average of £4.1m a year.

In terms of patching, Apple lead the vendor list by experiencing 654 vulnerabilities, up an enormous 179% from 288 vulnerabilities in 2014. Microsoft was in second place with 571 vulnerabilities discovered, up from 376 vulnerabilities the year before.

Vendor Patches and the Inherent Risks

There are some basic recommendations when using a computer to access the internet such as; use anti-malware software, don’t use the same password for all your accounts and ensure the operating system and applications are regularly patched.

When it comes to vendor patches, the issue is that the user is only secure once the vulnerabilities are addressed. This leaves a window of exposure where everyone, including malicious hackers, is aware of the vulnerabilities, prior to the user applying the patches. The most appropriate recommendation is to ensure the application of patches as soon as possible, as well as using solutions that can shield the devices from vulnerabilities until the patch is applied.

A Reason for Concern

There were 273 patches from four vendors in just one week in December 2015. The four vendors included Apple, Adobe, Microsoft and Google. This means that organizations who operate devices which run on the software these vendors produce will have experienced a very busy week of implementing patches.

On one hand, companies should be comforted by the diligence of these vendors in picking up vulnerabilities and creating patches – however, a healthy fear and appreciation of the changing security landscape should also be evident for CISOs or CIOs.

The security industry has dealt with more targeted and sophisticated attacks in the past year, with attackers finding ways around existing security protection from vendors. A good example is the clever exploitation of the XGhost app development code, that allowed malware to be uploaded by unsuspecting app developers.

Are We More or Less Secure Than a Year Ago?

The security threat landscape has evolved considerably in the last 12 months. Not only have there been more DDoS and ransomware attacks, big software giants like Adobe and Facebook have both been under attack from bugs and malware that infect their software. These two breaches resulted in major data loss for both companies, in the form of contact and payment details, which attackers can use for brute force attacks or phishing scams.

The entire online community seems to be more at risk than a year ago. Cybersecurity has risen to the top of the agenda for the C-suite, who may have experienced or watched their peers deal with embarrassing leaks.

It may be the vast rewards that attackers can gain from data or the greater access to internet connected devices, but one thing is clear; attacks on software providers will only grow in frequency and sophistication throughout 2016, which will mirror the wider cyber-attacks on companies.

Wednesday, 23 December 2015

Cyber security in 2016: Cyber extortion, data breaches and legal reform [Link - v3]

My comments around Cyber extortion were used in an interesting article for v3.

http://www.v3.co.uk/v3-uk/feature/2438545/cyber-security-in-2016-cyber-extortion-data-breaches-and-legal-reform

============

Cyber extortion

The rapid expansion of online tools available for purchase on the dark web, including ransomware and denial of service (DoS) programs, will increase the threat of extortion.

"Ransomware and DoS attacks will increase in frequency in the next year. There have been a growing number of blackmail attempts, threatening a company's resources with distributed DoS attacks if they do not paid a sum of money," warned Andrew Tang, service director at MTI Technology.

"They do not demand high levels of technical ability and the rewards can be great. Many companies cannot afford lengthy downtime on their servers and will pay the sum demanded, even without any guarantee that the attackers will not return."

Tuesday, 22 December 2015

Biggest security fails of 2015 and a look ahead to emerging threats in 2016

This year has seen IT security at the forefront of the news agenda for all the wrong reasons. Various breaches and hackings such as those on TalkTalk, Carphone Warehouse and Ashley Madison have heightened discussion around IT security and the protection required to counter virtual incursions.

However, many of the attacks over the course of the year were avoidable. Had the companies in question been more diligent over their testing and security protocols, some of the breaches would not have been as successful.  

Security fails of 2015

The biggest security failing of 2015 is arguably the vulnerability of companies to simple web application attacks. Organisations with large volumes of online customer interactions were targets for web application attacks, where cyber-criminals gain access to sensitive customer data. Techniques such as SQL injection and brute force techniques were used to access valuable data for fraud or resale to third parties.

The other security failing this year has been phishing attacks, a method that can result in malware entering a network, leading to data theft. Phishing attacks can come in the form of a legitimate email from a company that redirects the user to a fake external site. Personal information will then be requested and captured for future brute force attacks.

Prevention is simple

Following simple guidelines like OWASP is the first step to prevention. Regular testing of web facing applications before publishing them can also help avoid attacks such as TalkTalk.

Education within the company and targeted solutions aimed at monitoring data exfiltration should be a priority. A company’s security cannot be reliant on only using their security solutions as a shield – their workforce can and often will be a weak spot in their armor. Employee education on data governance, access and removal of data should be at the top of a company’s IT security resolutions for 2016.

Emerging security threats in 2016

As Ransomware threats are so effective, they are predicted to continue to increase in use in 2016, in conjunction with the level sophistication behind attacks.  This is especially the case, as corrective measures to protect from attacks are rarely in place.

In addition, DDoS (distributed denial-of-service) attacks aimed at extracting data have been getting stronger and harder to defend against, as shown by the high profile TalkTalk and Carphone Warehouse breaches.

There have also been a growing number of blackmail attempts, threatening a company’s resources with DDoS attacks, unless they receive a sum of money.

What is interesting is that these two techniques do not demand high levels of technical ability, but the rewards can be great. Many companies cannot afford lengthy downtimes on their servers and will pay the sum demanded, even without any guarantee that the same attackers will not return.

Who will they affect the most?

Ransomware can affect a majority of computer users.  Assuming you will not be a victim of a cyber-attack is a major mistake and the risk of such an attack should be taken seriously.

Blackmail attacks/DDoS attacks on the other hand, will be targeting medium to large sized companies, who have the budget to pay the ransom money.

Invaluable security solutions for businesses in 2016

As Ransomware is predominately distributed via email and internet, a sandboxing solution is essential. The relevant solution has to be able to scan emails and internet traffic delivered to computers on the network, remote workers using a VPN or BYOD users, who use wireless or mobile connections. 

An attacker using Ransomware infiltration techniques will execute with the user-credentials of the user who opens it, so there is a need to look at controlling administrative credentials of all computers, whether they are servers, workstations or laptops. 

Monday, 21 December 2015

Cyber-Security Predictions for 2016 [Link - Information Security Buzz]

I was asked to write a piece about Cyber Security predictions for 2016, which was published on Information Security Buzz.

http://www.informationsecuritybuzz.com/articles/cyber-security-predictions-for-2016/

================

Cyber-security Predictions for 2016

What will be the emerging IT security threats in 2016 and do you expect as many or even more attacks as 2015?

Although Ransomware attacks have been talked about a lot in 2015, the number of attacks has risen significantly during Q4 2015. Ransomware attacks are so effective that the number of attacks will rise, as well as the level sophistication behind the attack. Especially as corrective measures to protect from the attack are rarely in place.

DDoS (distributed denial-of-service) attacks aimed at extracting data have been getting stronger and harder to defend against, as evidenced by the high profile TalkTalk and Carphone Warehouse breaches.

There have also been a growing number of blackmail attempts, threatening a company’s resources with DDoS attacks if they are paid a sum of money.

Ransomware and DDoS attacks will only increase in frequency in the next year. They do not demand high levels of technical ability and the rewards can be great. Many companies cannot afford lengthy downtimes on their servers therefore will pay the sum demanded, even without any guarantee that the same attackers will not return.

Who will they affect the most?

Ransomware can affect a majority of computer users. Assuming you will not be a victim of a cyber-attack is a major mistake, and the risk of such an attack should be taken seriously.

Blackmail attacks with a threat of DDoS attacks will affect medium to large sized companies who have the budget to pay the sum of money demanded. The transaction is usually in the form of crypto-currency, bitcoin.  The companies that have the same budget to invest in the right protection against these types of attacks are likely to be the ones under attacked.

What security solutions will become invaluable to businesses in 2016?

As Ransomware is typically distributed via email, an email sandboxing solution will be required. The relevant solution has to be able to scan emails whether they are being delivered to computers on the network, remote workers using a VPN or BYOD users, who use wireless or cellular connections. As Ransomware will execute with the user-credentials of the user who opens it, there is a need to look at controlling administrative credentials of all computers, whether they are servers, workstations or laptops.

How will the IT security cope with the lack of talent in the UK?

There is not a lack of talent in the IT Security sector, but rather qualified talent.  The challenges have been the roles that have been advertised where the skills required are beyond many technical people, or looking for specific certifications and accreditations.  I believe there are many good universities in the UK producing excellent candidates for IT Security, as well as many people with the right aptitude and attitude to learn. Although this may not give companies the “right” skillsets immediately, they can be learnt with the right program of education and mentorship.

Wednesday, 21 January 2015

Explaining Ransomware to a five year old [Link - TechWeek Europe]

I was asked to write a piece about explaining Ransomware to a five year old.  Here was my response:


“Imagine that your house is like a computer and your toys are the games on the computer. Ransomware is like a stranger coming into your house and hiding all of your toys so you can’t find them. The stranger will ask for money to tell you where your toys are, but if you don’t pay, you will never see your toys again. If you pay the money, the stranger might give back your toys, but they might also leave the toys hidden anyway. To stop the stranger from hiding your toys, you need to stop the stranger from coming into your house, or you need to ask a grown up to find the stranger before they can hide your toys.
“Just like keeping your toys safe, to stop the ransomware from entering a computer, or to find any ransomware on your computer, you would use anti-malware or anti-virus software.”