54% of Senior Executives Struggling to Keep up with Threat Landscape

54% of Senior Executives Struggling to Keep up with Threat Landscape

According to a new report by Fujitsu, more than half (54%) of senior executives have struggled to adapt security policies to changes in the threat landscape and working practices.

The survey, which Fujitsu carried out in September 2020, provides further evidence that many organizations are at higher risk of cyber-attacks due to the shift to remote working during COVID-19, with cyber-criminals taking advantage of the rising number of connections and devices to target corporate systems.

The findings also indicated that current cybersecurity training techniques are not suited to the current situation. Close to two-thirds (61%) of employees surveyed said they believe their security training is ineffective, while around three-quarters (74%) of non-technical staff do not find it engaging enough. Additionally, 32% thought their company’s training courses were too long, and 35% said it was too boring or technical.

These feelings may be partly explained by many organizations having a standardized approach to cybersecurity training: 60% of senior executives surveyed for the study admitted that all employees in their business receive the same type of training irrespective of the type of function they perform.

Senior executives also recognized a degree of apathy among their employees when it comes to cybersecurity, with 45% stating that most people in their organization believe this has nothing to do with them.

In response to these issues, encouragingly, over two-thirds (68%) of senior executives stated they recognize that training is most effective when it involves games, rewards or quizzes.

Commenting on the findings, Mike Smit, head of enterprise & cyber security at Fujitsu UK & Ireland, said: “Thanks to the pandemic forcing organizations to move to remote or hybrid working, a number of weak points have been exposed when it comes to cybersecurity and employees are one target that has come under increasing fire from cyber-criminals. 

“Business leaders must understand that having a robust and effective cybersecurity approach relies on more than just IT and technical defenses, it also requires a ‘human firewall’ of trained, vigilant employees.

“In our new hybrid-working world, it is critical that organizations invest in a strategy where all employees receive tailored training that addresses the threats they encounter in their specific roles. This means cybersecurity teams have to get closer to the business areas to understand their specific challenges. Putting the right training in place to ensure your employees are aware of the risks will make a significant difference to an organizations’ overall security posture. And, ultimately, it will build a sense of collective responsibility where every employee is engaged in the security process.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Government Wants Startups to Build a More Secure Nation

Government Wants Startups to Build a More Secure Nation

The government has issued a call-to-arms to the UK’s burgeoning cybersecurity startups to help it defend the country from malicious online activity.

GCHQ’s National Cyber Security Centre (NCSC) used the Cheltenham Science Festival on Friday to launch NCSC for Startups.

The new program will invite applications from UK startups to develop products designed to defend critical areas of the economy and society.

It’s the successor to the NCSC Cyber Accelerator, a program that reportedly helped over 40 tech companies raise over £100m in external investments.

However, where it differs is that, whereas the accelerator required startups to participate in 10-week programs at set points of the year, NCSC for Startups will see continuous onboarding of successful applicants over the coming 12 months.

The idea is to drive more opportunities for these companies in the process.

Those chosen to participate will receive support from NCSC and GCHQ experts and NCSC partner Plexal, which is described as an “innovation center” with its own industry partners across the UK’s cybersecurity ecosystem.

Participating startups will be eligible to apply for funding, although there were no further details on how much.

“We want to work with the UK’s thriving cybersecurity industry to explore new ideas that will make the UK the safest place to live and work online,” said NCSC deputy director for cyber growth, Chris Ensor.

“NCSC for Startups offers the potential for even greater collaboration than ever before, and I would encourage startups to come forward and help us in our mission.”

The industry appeared to get a welcome boost from the pandemic last year, as demand for security services surged due to the mass switch to remote working.

According to one report, funding for UK cyber startups surged 940% in the first few months of the pandemic. That amounted to £496 million raised by investors in the first half of 2020, almost as much as the total figure for 2019 (£521 million).

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

G7 Turns Up the Heat on Putin Over Ransomware Attacks

G7 Turns Up the Heat on Putin Over Ransomware Attacks

G7 leaders confirmed their commitment to urgently tackling ransomware on Sunday, as a senior British security chief will warn today that cyber-criminals represent a more significant threat than state-sponsored espionage.

The Carbis Bay communique, published after a three-day summit of world leaders in Cornwall, singled Russia out by name — urging Vladimir Putin to “identify, disrupt and hold to account” cyber-criminals operating from the country.

“We commit to work together to urgently address the escalating shared threat from criminal ransomware networks,” it added. “We call on all states to urgently identify and disrupt ransomware criminal networks operating from within their borders, and hold those networks accountable for their actions.”

Lindy Cameron, CEO of GCHQ offshoot the National Cyber Security Centre (NCSC), will reportedly tell an audience today that Britain’s failure to tackle ransomware is “far more worrying” than the “malicious strategic threat” of state-backed online espionage.

She will reportedly add that, in a dangerous development, the ransomware-as-a-service (RaaS) model has democratized the ability to launch attacks and that such raids are “often enabled and facilitated by states acting with impunity.”

Hostile states such as Russia are long thought to have tolerated cybercrime groups operating from within their borders, as long as attacks are targeted at organizations in rival nations.

However, with recent attacks on key fuel and food supply chains in the US, the scrutiny of world leaders has been turned towards such policies.

Despite the rhetoric, the lines between financially motivated cybercrime and nation-state activity are, in fact, increasingly blurring.

An HP report from April claimed that governments now routinely buy exploits and hacking tools from the cybercrime underground and often recruit criminal operators to help with specific stages of threat campaigns.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Global Police Close Record Number of Fake Pharma Sites

Global Police Close Record Number of Fake Pharma Sites

A global policing operation has led to the closure of over 110,000 websites and online marketplaces selling fake pharmaceuticals, according to the international organization Interpol.

The organization said that Operation Pangea XIV involved law enforcement, customs and regulatory officers from 92 countries.

As well as the removal of 113,020 fake sites — the largest number since the long-running operation began in 2008 — counterfeit medicines and COVID-19 testing kits were seized after raids and checks on suspicious packages.

In the UK, for example, the authorities shut down 43 websites and removed 3100 ad links and seized three million fake medicines and devices worth over $13 million.

Many drugs were hidden amidst other items such as clothing, jewellery, baby toys and food.

In Qatar, officials apparently discovered 2,805 painkillers secreted inside tins of baked beans.

During the week of action, May 18-25, fake and unlicensed COVID-19 kits accounted for over half of all medical devices obtained by police. Some 277 arrests were also made worldwide, and potentially dangerous pharmaceuticals worth more than $23 million were seized, Interpol said.

In Italy, the authorities recovered over 500,000 fake surgical masks and 35 industrial machines used for production and packaging — illustrating the scale of many underground operations.

In total, global police took nine million devices — including syringes, catheters, masks and testing kits — and pharmaceuticals, including painkillers, steroids and anti-cancer drugs.

Interpol secretary-general, Jürgen Stock, warned that fake pharmaceuticals and testing kits are putting public health at risk at a dangerous time.

“As the pandemic forced more people to move their lives online, criminals were quick to target these new ‘customers’,” he added.

“Whilst some individuals were knowingly buying illicit medicines, many thousands of victims were unwittingly putting their health and potentially their lives at risk.”

In March last year, a previous iteration of Operation Pangea led to the seizure of $14 million worth of fake goods.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

McAfee a Leader in The Forrester Wave™ Unstructured Data Security Platforms

The mass migration of employees working from home in the last 14 months has accelerated the digital transformation of businesses.  Cloud applications are no longer a “nice to have,” they are now essential to ensure that businesses survive.  This introduces new security challenges in being able to locate and control sensitive data across all the potential exfiltration vectors regardless of whether they are in the cloud; on premise via managed or unmanaged machines.  Attempting to control these vectors through multiple products results in unnecessary cost and complexity.

McAfee anticipated and responded to this trend, solving all these challenges through the launch of our MVISION Unified Cloud Edge solution in 2020. Unified Cloud Edge doesn’t simply offer data protections controls for endpoints, networks, web and the cloud; rather, Multi-Vector Data Protection provides customers with unified data classification and incident management that enables them to define data workflows once and have policies enforced consistently across each vector. Because of the unified approach and our extensive data protection heritage, we are delighted to be named a Leader in The Forrester Wave™: Unstructured Data Security Platforms, Q2 2021. In our opinion, we were the top ranked dedicated cyber security vendor within the report.

We received the highest possible score in nine criteria with Forrester Research commenting on our “cloud-first data security approachand customer recognition of our “breadth of capabilities (in particular for supporting remote work and cloud use)”.

We continue to innovate within our  Unified Cloud Edge solution through the introduction of remote browser isolation to protect against risky web sites (our “heavy focus in supporting security and data protection in the cloud), which uniquely to the market allows us to continue applying DLP controls even during isolated sessions. Delivering on increased customer value through innovation isn’t just limited to new features, for instance we continue to drive down costs through an unlimited SaaS application bundle.

Click below to read the full report.

The Forrester Wave™: Unstructured Data Security Platforms, Q2 2021

McAfee is delighted to be named a Leader in The Forrester Wave™ Unstructured Data Security Platforms, Q2 2021 report. We received the highest possible score in nine criteria with Forrester Research

Download Now

 

The Forrester Wave™: Unstructured Data Security Platforms, Q2 2021, 17 May 2021, Heidi Shey with Amy DeMartine, Shannon Fish, Peggy Dostie

The post McAfee a Leader in The Forrester Wave™ Unstructured Data Security Platforms appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Finding Success at Each Stage of Your Threat Intelligence Journey

Every week it seems there’s another enormous breach in the media spotlight. The attackers may be state-sponsored groups with extensive resources launching novel forms of ransomware. Where does your organization stand on its readiness and engagement versus this type of advanced persistent threat? More importantly, where does it want to go?

We believe that the way your organization uses threat intelligence is a significant difference maker in the success of your cybersecurity program. Just as organizations take the journey toward cyber defense excellence at their own rate of speed, some prioritize other investments ahead of threat intelligence, which may impede their progress. Actionable insights aren’t solely about speed, though fast-emerging threats require prompt intervention, they’re also about gaining quality and thoroughness. And that’s table stakes for advancing in your threat intelligence journey.

What is a Threat Intelligence program?

A Threat Intelligence program typically spans five organizational needs:

  • Plan — prepare by identifying the threats that might affect you
  • Collect — gather threat data from multiple feeds or reporting services
  • Process — ingest the data and organize it in a repository
  • Analyze — determine exposure and correlate intelligence with countermeasure capability
  • Disseminate — share the results and adjust your security defenses accordingly

When you disseminate a threat insight, it triggers different responses from various members of your security team. An endpoint administrator will want to automatically invoke counter-measures and security controls to block a threat immediately. A SOC analyst may take actions including looking for signs of a breach and also recommend ways to stiffen your defense posture.

Better threat intelligence provides you with more contextual information — that’s the key. How will this information help your company, in your particular industry, in your region of the world?

The Threat Intelligence journey comes in stages. Where is your program now?

Stage 1: Improving and adapting your protection

Within this stage most companies want to prevent the latest threats at their endpoint, network and cloud controls. They mostly depend on their security vendors to research and keep products up to date with the latest threat intelligence. However, in this stage companies also receive intelligence from other sources, including government, commercial and their own cyber defense investigations, and can use the extra intelligence to further update controls.

Stage 2: Improving the SOC and responding faster

At this stage, organizations advance beyond vendor-provided intelligence and adapt their protection by adding indicators from third-party threat feeds or from other organizational SOC processes such as malware analysis.

Within this stage, companies want to do more than prevent known threats with their tools. They want to understand the adversaries who might target them, improve detection and respond faster by prioritizing investigations.

Stage 3: Improving the Threat Intelligence program

Organizations with this goal know that their industry faces targeted threats every day and they have already invested significantly in their threat intelligence capability. At this stage they most likely have a team utilizing commercial and open-source tools as well as threat data feeds. They’re looking for specialized analysis services and access to raw data.

These organizations can proactively assess their exposure and determine how to reduce the attack surface. They apply threat intelligence to empower their threat hunting, either on a proactive or reactive basis.

Enter new actionable insights, next steps

Until recently it was difficult for security managers to know not just whether their organization has been exposed to a particular threat but whether they have a good level of protection against specific campaigns.

McAfee MVISION Insights is helpful at each stage of your threat intelligence journey because it proactively assesses your organization’s exposure to global threats, integrating with your telemetry, and prescribes how to reduce attack services before the attack occurs.  For stage one, organizations can proactively assess their exposure and determine how to reduce the attack surface. For stage two and three, organizations can apply threat intelligence to empower their threat hunting and analysis, either on a proactive or reactive basis.

 

MVISION Insights Dashboard

One way we help is by integrating data from both McAfee Threat Intelligence feeds such as our Global Threat Intelligence and Advanced Threat Defense, and also third-party services via MVISION APIs. While McAfee Global Threat Intelligence is one of the world’s largest sources of this information, with more than 1 billion global threat sensors in 120+ countries, and 54 billion queries each day, the key thing to know is that we have 500 plus McAfee researchers providing this form of threat intelligence as a service.  The idea is to help you elevate your threat intelligence at each step of your organization’s journey.

 

Check out the latest threats from a Preview of MVISION Insights.

 

 

 

The post Finding Success at Each Stage of Your Threat Intelligence Journey appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk