Data Loss Impacts 40% of SaaS App Users

Data Loss Impacts 40% of SaaS App Users

New research has found that 40% of Software as a Service (SaaS) users across a range of industries have lost data stored in their online tools. 

The survey by Rewind, a provider of cloud backups for SaaS applications, was commissioned ahead of World Backup Day on March 31. 

A total of 631 respondents answered questions related to how they use SaaS apps in a professional context.  

Key findings were that more than half (53 percent) of respondents use SaaS tools while at work, with some (43 percent) utilizing four or more apps.

Most users said that the data in their SaaS applications was either “somewhat” (47 percent) or “very” (42 percent) critical to the performance of their work. Despite this, more than half lacked vital knowledge regarding the security of that data.

“Many users (45 percent) still were not aware of the Shared Responsibility Model,” said a spokesperson for Rewind.

“They, therefore, do not realize that while SaaS providers actively back up their own cloud infrastructure, they do not make the account-level, business-critical information stored in their apps available to users.”

Under the shared responsibility model, service users and providers share portions of the security responsibilities between them, allowing the user to maintain a secure environment with less operational overhead. 

The model relies on each party’s clearly defining their security ownership and maintaining complete control over the assets, processes, and functions that they own.

“If I had known online tools don’t provide complete protection of my business’s data, I would have been backing up everything on day one,” said Matt Davis, owner of Whisker Seeker.

“The loss of vital data from our ecommerce store days before the holiday shopping season started nearly crippled our operation. It was the biggest nightmare of my life; one that I never want to happen again.”   

Sharing the findings, Rewind encouraged every business to review its current cloud data protection strategies and ensure that backups for primary business apps are in place. 

“We want every single day to be backup day,” said Mike Potter, CEO and co-founder of Rewind. “As business users entrust more and more of the data they rely on into the cloud with SaaS apps, understanding the associated risks and how to manage data loss is critical.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

McAfee Partners with College to Help Address Cyber-Skills Shortage

McAfee Partners with College to Help Address Cyber-Skills Shortage

McAfee has announced a partnership with London South East Colleges in a bid to provide students with insights into working in the cybersecurity industry.

The initiative is part of efforts to encourage younger people to pursue a career cybersecurity and address the skills gap in the sector. Earlier this week, a report from the Learning & Work Institute found that the number of students enrolling in ICT at GCSE level fell by 40% from 2015 to 2020, which means the UK could be heading towards a “catastrophic” digital skills shortage.

In the partnership, McAfee will run a variety of panel events, workshops and placements to demonstrate the kinds of roles available and the skills required to be successful in the industry. This will include the creation of a platform profiling individual McAfee employees.

Forming part of the London South East Colleges’ Career Advantage program, the collaboration is designed to inspire students to pursue a career in cybersecurity. The first event will take place next week on March 30 2021, consisting of a virtual session encouraging students to consider their employment aspirations. McAfee representatives will then take part in a Q&A, offering tips and advice for a successful career in cyber.

Andrew Cox, who is heading up the partnership for London South East Colleges, commented: “We know that students need more than just qualifications if they are to secure the best employment opportunities. They need direct access to employers and genuine insight into new and expanding industries. 
“Our partnership with McAfee will enable our students to find out more about the opportunities that this global company offers. Students will also discover the many different career pathways that exist within the business, which they are unlikely to have considered before.” 

Adam Philpott, EMEA president at McAfee, said: “London South East Colleges has a powerful role to play in illuminating the many career possibilities available to its diverse, student population. We are delighted to be working with them in our outreach to engage with communities that can both benefit from careers in the technology and cybersecurity sector. In doing so, we are supporting society more broadly as it becomes increasingly connected digitally in doing so safely and securely.   

“As a leader in the cybersecurity industry, McAfee is seeking to address the talent and diversity shortfall in our market as part of our pledge. Our objective is to highlight the fulfilling career opportunities that exist in our domain and inspire students to seek these out as they move from education into the workplace.” 

Experts believe that more collaboration between industry and academia is a key step in addressing the skills shortage in cyber, by ensuring courses are preparing students for jobs in the industry.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

CNA Suffers “Sophisticated” Cyber-Attack

CNA Suffers “Sophisticated” Cyber-Attack

The website of insurance giant CNA is out of action following a cyber-attack that took place over the weekend.

Visitors to the website of the Chicago-based firm are greeted with a notice explaining that threat actors have disrupted the company’s network. 

In a statement released Tuesday evening, CNA described the assault as a “sophisticated cybersecurity attack.” The company said that certain systems, including corporate email, had been impacted.

The attack triggered the global company to implement a network shutdown.  

“Out of an abundance of caution, we have disconnected our systems from our network, which continue to function,” revealed CNA.

“We’ve notified employees and provided workarounds where possible to ensure they can continue operating and serving the needs of our insureds and policyholders to the best of their ability.”

The incident has been reported to law enforcement, and CNA has sought outside help to determine how the attack was carried out. 

“Upon learning of the incident, we immediately engaged a team of third-party forensic experts to investigate and determine the full scope of this incident, which is ongoing,” said the company.

“We have alerted law enforcement and will be cooperating with them as they conduct their own investigation.”

To handle claims and billing during the outage, five dedicated email inboxes have been set up by CNA. 

No evidence has been found to suggest that the cyber-attack on CNA resulted in a breach of customer data.

“The security of our data and that of our insureds’ and other stakeholders is of the utmost importance to us,” said CNA.

“Should we determine that this incident impacted our insureds’ or policyholders’ data, we’ll notify those parties directly.”

CNA Financial is one of the biggest commercial property and casualty insurance companies in America and has 5,800 employees located around the world.

Commenting on the security incident, Isabelle Dumont, vice president of market engagement at Cowbell Cyber, said: “Every business, regardless of industry, can be targeted and should apply security best practices. 

“Working with a breach coach dedicated to cyber, and an experienced incident response team to understand the scope of the incident with the type and volume of data impacted, is paramount when a cyber incident occurs.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Rise in Attacks on ICS Computers in Second Half of 2020

Rise in Attacks on ICS Computers in Second Half of 2020

Attacks on industrial control system (ICS) computers went up by .85 percentage points in H2 of 2020 compared to H1, according to new research from Kaspersky.

The analysis also found that the variety of malware families targeting ICS computers increased by 30% in this period, with cyber-criminals significantly ramping up attacks against these sectors amid the COVID-19 lockdowns.

While industrial organizations have traditionally been an attractive target for malicious actors due to the highly sensitive data they hold, Kaspersky noted a decline in the proportion of ICS computers on which malicious objects were detected from the second half of 2019. However, this trend changed in the second half of 2020, with COVID-19 likely changing the tactics employed by cyber-criminals.

Compared to H1, in the engineering and ICS integration sector, the proportion of ICS computers attacked grew by nearly eight percentage points to 39.3%, while there was a rise of nearly seven percentage points in building automation, reaching 46.7%. There was a 6.2 percentage rise in oil and gas found, meaning the percentage of ICS computers in this sector targeted was 44%.

Additionally, the researchers revealed that 62% of the countries they examined experienced a growth in the percentage of ICS computers targeted, while the proportion of ICS computers on which malicious email attachments were blocked went up in 73.4% of countries.

The most commonly employed malwares were backdoors, spyware, other types of Trojans and malicious scripts and documents.

Evgeny Goncharov, head of ICS CERT at Kaspersky, commented: “2020 was an unusual year in nearly all aspects, and this appears to have led to some unusual trends across the ICS threat landscape. We typically see a decline in the percentage of ICS computers attacked in the summer months and December as people go on holiday. However, with borders closed and countries on lockdown, it’s likely many didn’t take their vacation, and we did not see any noticeable decrease.

“In addition, while ransomware attacks declined globally, in developed countries, such as the US and Western Europe, the number of attacks actually significantly increase, perhaps because, amidst the current economic downturn, criminals thought these places had businesses with the means to actually pay. With the pandemic still ongoing, it will be important that all industries take extra precautions; with the rest of the world in flux, it’s hard to predict what cyber-criminals will do.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Two-Thirds of Large Firms Attacked as #COVID19 Hampers Security

Two-Thirds of Large Firms Attacked as #COVID19 Hampers Security

Nearly two-thirds of medium and large-sized businesses suffered a cyber-attack or breach last year, with security efforts suffering during the pandemic, according to the latest government figures.

The Cyber Security Breaches Survey 2021 on the face of it showed a slight improvement over last year’s: 39% of UK businesses of all sizes said they were breached or attacked over the previous 12 months versus 46% last year.

However, while the report posits that this could be due to many firms reducing their trading activity and therefore being less visible to attackers, it’s more likely that they are simply less aware of threat activity.

Fewer businesses are deploying security monitoring tools (35% versus 40% last year) or undertaking any form of user monitoring (32% versus 38%), for example.

Frequency and most common threat vector types were consistent with previous years’ reports. Around a quarter (27%) of businesses experienced attacks at least once a week, with phishing (83%) and impersonation (27%) most common.

A fifth (21%) of those reporting attacks end up losing money, data or other assets as a result, and 35% reported other negative consequences such as business disruption or lost staff productivity.

On the positive side, this figure is lower than previous years, possibly due to more widespread adherence to best practices and GDPR rules, the report claimed.

Unsurprisingly, COVID-19 has had a major impact on cybersecurity: many firms reported mass remote working had made user monitoring harder, complicated hardware and software upgrades and stretched resources to the limit.

There’s still plenty of room for improvement. The report noted that fewer than half of UK businesses currently have cyber insurance, undertake risk assessments, train and test staff, carry out vulnerability audits, review supplier risks and have a business continuity plan in place.

Fewer than a quarter (23%) have policies that cover home working, the report claimed.

Mimecast UK VP, Jamal Shakir, agreed that a distributed workforce is making it harder for organizations to detect and block attacks.

“The past 12 months have seen an increase in sophisticated digital deception campaigns where threat actors combine COVID-19-related social engineering with multi-channel campaigns to gain credibility with their targets so they can then be tricked into giving away valuable information or credentials,” he argued.

“Organizations must not take their foot off the gas and ensure that they have adequate tools and training in place to deal with these attacks.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Half of UK Firms Suffer Cyber-Skills Gaps

Half of UK Firms Suffer Cyber-Skills Gaps

Half of UK businesses reported cyber-skills gaps last year, with diversity still woefully lacking in most organizations, according to the latest government figures.

The DCMS-sponsored Cybersecurity skills in the UK labour market 2021 report was compiled from representative surveys of security sector and wider organizations, as well as analysis of job postings and research with recruitment agencies.

It revealed that around 680,000 businesses in the country have staff in charge of cybersecurity that lack the confidence to carry out basic tasks laid out in the government’s best practice Cyber Essentials framework. This includes storing or transferring personal data, setting up configured firewalls and detecting and removing malware.

A third (33%) reported more advanced skills gaps such as in penetration testing, forensic analysis and security architecture, while a similar number (32%) have gaps in incident response and are not outsourcing the function.

Even within the cybersecurity sector there were problems, with nearly half (47%) saying they’d experienced challenges with current staff or job applicants not having the required technical skills. Over a third (37%) said vacancies since the beginning of 2019 have been hard to fill.

However, despite these concerning statistics, the report pointed out that things are slowly improving in some areas. Businesses are less likely to report basic skills gaps than in 2018, senior managers are described as more likely to understand cyber-risk and fewer security sector firms reported skills gaps.

The improvements do not extend to diversity, however, with just 17% of the workforce from ethnic minority backgrounds, falling to just 3% of those in senior cybersecurity roles. In addition, only 16% are female, versus 28% across all digital sectors, falling to 3% in senior roles, according to the report.

Amanda Finch, CEO of the Chartered Institute of Information Security (CIISec), argued that recruitment is in need of an overhaul, with communication between recruiters and employers currently poor.

“The fact is, challenges in recruitment come from all sides — from organizations being unclear or over demanding and recruiters not understanding the roles, to a lack of confidence or skills from applicants. Rather than pointing the finger, we need a collaborative approach to addressing these issues,” she said.

“One example is unrealistic and intimidating job descriptions which over-exaggerate the skills and experience needed for a role. Considering that women only apply for roles they are 100% qualified for, whilst men will apply if they meet 60% of the qualifications, this approach may be alienating women and other minority groups. Communicating the fundamentals of a position — who the organization wants to hire, what skillset is actually needed, what training applicants can receive — is crucial, as is providing accurate job descriptions.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#IMOS21: Six Components of a Bug Bounty Program

#IMOS21: Six Components of a Bug Bounty Program

Speaking at the Spring Infosecurity Magazine Online Summit, Sean Poris, director, product security at Verizon Media, explored how to run a bug bounty program, outlining the six components of a successful big bounty structure.

Poris explained that, by investing in bug bounties, organizations are potentially tapping into “hundreds of thousands of global hackers” that think about software and vulnerabilities in ways that internal staff might not.

He also said that knowing and understanding your objectives is key when it comes to running a bug bounty program, so organizations must have clear focus on “what they are trying to accomplish in standing up the program.” This should also include taking time to consider “what researchers will want from your program” and how you can work alongside them, along with the long-term goal of your program.

Once those aspects are established, Poris said there are six components to ensuring ongoing bug bounty success for an organization.

These six components are:

  1. Scope: what’s in, what’s out?
  2. Platform: report intake and communications
  3. Talent: hackers and teams
  4. Financials: budget, forecast and payments
  5. Operations: process, consistency and oversight (metrics)
  6. Policy: rules of the road, safe harbor and compliance

Ultimately, “a bug bounty program is a crowdsourcing initiative that rewards individuals for discovering and reporting software bugs,” and by taking a considered, federation-like approach, organizations can make a success of their bug bounty journeys.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FatFace Faces Customer Anger After Controversial Breach Response

FatFace Faces Customer Anger After Controversial Breach Response

British clothing retailer FatFace is facing a mounting storm of criticism for its handling of a “sophisticated criminal attack” which led to the compromise of customers’ personal data (PII).

In an email to customers posted by HaveIGotPwned? founder Troy Hunt this week, the firm revealed that the breached data included customers’ full names, email and home addresses and partial card details (last four digits and CVV).

“On January 17, 2021 FatFace identified some suspicious activity within its IT systems,” the email noted.

“We immediately launched an investigation with the assistance of experienced security professionals who, following thorough investigation, determined that an unauthorized third party had gained access to certain systems operated by us during a limited period of time earlier the same month. FatFace quickly contained the incident and started the process of reviewing and categorizing the data potentially involved in the incident.”

However, the firm has come in for criticism from security experts and customers for its handling of the incident.

Despite claiming in the email that its focus was on “customer care and regulatory requirements, including the UK and EU General Data Protection Regulation,” some reacted angrily on Twitter that it had taken over two months to notify customers.

It’s unclear when the privacy regulator was informed of the incident, but under the GDPR it must happen within 72 hours of discovery of a breach.

FatFace claimed in the email that it had taken this long to notify as it was trying to provide “the most accurate information possible” on what had been taken and who was affected.

Customers were also angry that the email, signed by CEO Liz Evans, did not offer a formal apology for the incident, but instead requested that the recipient “keep this email and the information included within it strictly private and confidential.”

Hunt described the missive as “misleading.” For example, although the notice says there’s no financial risk to customers from the compromise of partial card details, such data is often used for identity verification, he noted.

“It feels like a lot of emphasizing their security posture even in the face of breach and downplaying the severity of the incident followed by an acknowledgement that identity theft protection would be a good idea. I’d give it a 5/10 for quality disclosure notice,” he said on Twitter.

“Oh, and the subject of the disclosure email was ‘Strictly private and confidential – Notice of security incident’ – why? It contained no PII other than the recipient’s address, why is a notice of a breach ‘strictly private and confidential?’ That’s really odd.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk