Insider Cloud Data Theft Plagues Healthcare Sector

Insider Cloud Data Theft Plagues Healthcare Sector

Over a third (35%) of global healthcare organizations suffered cloud data theft by malicious insiders last year, according to data from Netwrix.

The findings come from the security vendor’s 2021 Netwrix Cloud Data Security Report, based on interviews with 937 IT professionals around the world.

It claimed that while insider theft was less common than phishing (44%) and ransomware (39%) last year, it took far longer to detect and remediate.

In fact, over a quarter of respondents (28%) said they needed weeks to discover such incidents, while in the case of the other threats nearly half of IT pros (49%) said they detected phishing in minutes and 43% that they spotted ransomware and other malware within hours.

Over two-fifths (43%) said they needed weeks to resolve insider data theft incidents, versus just 25% for phishing and 28% for ransomware.

This matters, because 61% of healthcare organizations store customer data in the cloud and 54% store personal health records there. As a result of insider incidents, many are experiencing unplanned expenses to fix security gaps (24%) and compliance fines (23%) at a time when resources need to be focused on fighting COVID-19.

A lack of lack of budget (61%), IT/security skills shortages (56%) and employee negligence (39%) were cited as the sector’s key security challenges.

Netwrix VP of product management, Ilia Sotnikov, argued that healthcare organizations need to focus their investments on stronger data governance processes to reduce the attack surface, real-time user activity monitoring to speed time-to-detection and training and awareness programs for IT staff and employees.

“An explosion of telehealth services and the shift of non-clinical employees to work-from-home increased the need for cloud technologies in the healthcare sector. As a result, new avenues for cyber-threats opened up,” he added.

“Moreover, because hospitals and health systems are dealing with high caseloads caused by the pandemic, the threat to care delivery remains extremely high. Our report highlights the lack of security fundamentals that could improve the security posture of these organizations.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

One Ransomware Victim Every 10 Seconds in 2020

One Ransomware Victim Every 10 Seconds in 2020

A new organization became a victim of ransomware every 10 seconds in 2020 with remote workers experiencing a sharp uptick in threats, according to Check Point.

The security vendor’s 2021 Security Report is compiled from its ThreatCloud intelligence sensor data, its own research and recent surveys of IT professionals.

The report claimed that consumers and organizations face 100,000 malicious websites and 10,000 malicious files every day, with double extortion ransomware in particular on the rise. In Q3 2020, nearly half of all ransomware incidents involved theft of data from the targeted organization.

However, there’s still plenty of room for expansion in the market in 2021, as only 5% of malware attacking global corporate networks was ransomware last year, according to Check Point. The most popular by far was botnet traffic (28%) followed by crypto-miners (21%), information stealers (16%), mobile (15%) and banking malware (14%).

RDPs were the most popular attack vector for ransomware in the first half of the year, with brute force attacks targeting weak or previously breached passwords a popular tactic.

Remote workers were also targeted via email: Check Point pointed to the increasing popularity of “thread hijacking” functionality in Emotet and Qbot Trojans.

“Once a single victim is infected, the attackers leverage that person’s old email conversations for malware distribution, forwarding the last email of the thread and adding malicious files as attachments,” the report explained.

“This makes it easier to trick new victims that are within the victim’s social and professional domain, as from their perspective they’re receiving an email from a trusted colleague concerning a known subject.”

Elsewhere, Check Point highlighted the risks of cloud and mobile. It claimed that 80% of enterprises found their existing security tools don’t work at all or only have limited functionality in the cloud, while nearly half (46%) of organizations have had at least one employee download a malicious mobile app.

In terms of verticals, monthly attacks on healthcare jumped 37% in 2020 as cyber-criminals sought to capitalize on organizations distracted by the fight against COVID-19.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Facebook Takes Out Myanmar Military After Bloody Coup

Facebook Takes Out Myanmar Military After Bloody Coup

Facebook has banned Myanmar’s military (Tatmadaw) from its platform following a coup earlier this month which led to the overthrow of the country’s democratically elected government.

The social network argued that the emergency situation in the Asian nation necessitated a full and indefinite ban from Facebook and Instagram of both Tatmadaw and any state and media entities it controls, as well as ads from military-linked businesses.

Director of policy in APAC emerging countries, Rafael Frankel, said that Facebook’s actions were guided by the UN Fact-Finding Mission on Myanmar’s 2019 report and the UN Guiding Principles on Business and Human Rights.

He explained that the decision came as a result of four key factors: notably the likelihood of “military-incited violence” and human rights abuses when the army’s power is left unchecked.

The Tatmadaw also has a history of platform content and behavior violations and has been trying to rebuild networks of “coordinated inauthentic behavior” and content inciting violence and harm, Frankel said.

“The coup greatly increases the danger posed by the behaviors above, and the likelihood that online threats could lead to offline harm,” he added.

In practice, the ban has resulted in the removal of Tatmadaw True News Information Team Page, and MRTV and MRTV Live Pages as well as a reduction in distribution of 23 pages and profiles controlled and/or operated by the Tatmadaw.

Facebook had already banned 20 military linked individuals from its platform in 2018 including commander-in-chief Min Aung Hlaing, and removed six propaganda networks over the past couple of years.

The ban doesn’t include ministries administering essential services like health and education.

Despite the Myanmar army’s history of bloody violence and the deaths that have already occurred due to the coup, the unilateral move by the social network will reignite the debate over who should police freedom of speech on the platform.

That argument came to a head when Facebook, and most other major social platforms, banned Donald Trump for inciting deadly violence at the Capitol earlier this year.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

On Chinese-Owned Technology Platforms

I am a co-author on a report published by the Hoover Institution: “Chinese Technology Platforms Operating in the United States.” From a blog post:

The report suggests a comprehensive framework for understanding and assessing the risks posed by Chinese technology platforms in the United States and developing tailored responses. It starts from the common view of the signatories — one reflected in numerous publicly available threat assessments — that China’s power is growing, that a large part of that power is in the digital sphere, and that China can and will wield that power in ways that adversely affect our national security. However, the specific threats and risks posed by different Chinese technologies vary, and effective policies must start with a targeted understanding of the nature of risks and an assessment of the impact US measures will have on national security and competitiveness. The goal of the paper is not to specifically quantify the risk of any particular technology, but rather to analyze the various threats, put them into context, and offer a framework for assessing proposed responses in ways that the signatories hope can aid those doing the risk analysis in individual cases.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

SOC Health Check: Prescribing XDR for Enterprises 

It is near-certain the need for security across the enterprise will never cease – only increase if year-over-year trends are any indication. We constantly see headlines with repetitive buzzwords and phrases calling attention to the complexity of today’s security operations center (SOC) with calls to action to reimagine and modernize the SOC. We’re no different here at McAfee in believing this to be true.  

In order for this to happen, however, we need to update our thinking when it comes to the SOC.  

Today’s SOC truly serves as an organization’s cybersecurity brain. Breaking it down, the brain and SOC are both the ultimate central nervous system and are extremely complex. While the brain fires neurons, connects synapses, and constantly communicates in order for the body to function, the SOC similarly works as a centralized system where people, processes, and technology must be in-sync to function.The unfortunate reality is though, SOC analysts and staff do not feel empowered to act in this manner. According to the 2021 SANS Cyber Threat Intelligence Report, respondents cited several reasons for not being able to implement cybersecurity holistically across their organization, including lack of trained staff, time, funding, management buy-in, technical capabilities, and more.  

The technology that has the power to enable this synchronicity and further modernize enterprise security by taking SOC functionality to the next level is already here – Extended Detection and Response (XDR). It has the ability to provide prevention, detection, analysis, and response in a purposefully orchestrated and cooperative way, with its components operating as a whole. Think of it this way: XDR mimics the brain’s seamlessness in operation, with every element working toward the same goal of maintaining sound security posture across an entire organization.  

Put another way, the human brain has approximately 100 trillion synapses, synchronizing and directing to make it possible to walk and chew bubble gum at the very same time with seemingly no effort on the human’s end. However, if one synapse misfires or becomes compromised due to an unknown element – you might end up on the ground.  

Similarly, we’re already seeing many enterprises falter, trip, and fall. According to Ernst & Young, 59% of companies experienced a significant breach in the last twelve months – and only 26% of respondents say the SOC identified that event. These statistics show the case for XDR is clear – and that it is time to learn and reap the benefits of taking a proactive approach.   

Purposeful Analysis vs. Analysis Paralysis 

Organizations are still vulnerable to malicious actors attempting to take advantage of disparate remote workforces – and we’re seeing them get craftier, acting faster and more frequently. This is where XDR offers a pivotal differentiator by providing actionable intelligence and integrated functionality across control vectors, resulting in more proactive investigation cycles.  

When it comes to analysis, data can quickly become overwhelming, introducing an opportunity to miss critical threats or malicious intent with more manual or siloed processes. Meaningful context is crucial and no industry is exempt from needing it. 

This is where McAfee is providing the advantage with MVISION XDR powered MVISION Insights. The ability to know likely and prioritized threat campaigns based on geographical and industry prevalence – and have them correlated and assessed across your local environment – provides the situational awareness and analysis that can allow SOC teams to act before threats occur. Additionally, as endpoints only promise to increase, MVISION XDR works in conjunction with McAfee’s endpoint protection platform (EPP), increasing effectiveness with added safeguards including antivirus, encryption, data loss prevention technologies and more at the endpoint 

Think of the impact and damage that can happen without this crucial and context MVISION Insights can provide. The consequences can be dire when looking at industries that have faced extreme upheaval.  

For example, in keeping with our theme, we know the importance of essential healthcare workers and cannot be grateful enough for their contributions. But as the industry faces extreme challenges and an increase in both patient load and data, we also need to be paying close attention to how this data is being managed, who has privilege to it, and what threats exist as even this typical in-person industry shifts virtual due to our updated circumstances. Having meaningful context on potential threats will help this industry avoid added challenges so focus can remain steadfast on creating impact and positive results.  

Greater Efficiency is Essential 

Outside of the tremendous advantage of being less vulnerable to threats and breaches due to proactivity, incredible efficiencies can be gained by freeing cybersecurity staff from those previously manual tasks and management of multiple silos of solutions. The time is definitely now too – according to (ISC)², 65% of organizations already report a shortage of cybersecurity staff. 

Coupled with staff shortages and lack of skilled workers, an IBM report also found that the average time to detect and contain a data breach is 280 days. Going back to the view that the SOC serves as an organization’s cybersecurity brain – 280 days can cause massive amounts of damage if an anomaly in the brain were to occur unnoticed or unaddressed.  

For the SOC, the longer a breach goes undetected, the more information and data becomes vulnerable or leaked – leading not only to a disruption in business, but ultimately financial losses as well.  

The SOC Has a Cure 

XDR is the future of the SOC. We know that simplified, cohesive visualization and control across the entire infrastructure leads the SOC to better situational awareness – the catalyst for faster time to remediation. The improved, holistic viewpoint XDR provides across all vectors from endpoint, network, and cloud helps to eliminate mistakes and isolated endeavors across an organization’s entire IT framework.  

With AI-guided investigation, analysts have an automatic exchange of data and information to move faster from validation to decision when it comes to threats. This is promising as organizations not only tackle a shortage in cybersecurity staff, but skilled workers as well. According to the same (ISC)² survey as above, 36% of those polled cite lack of skilled or experienced staff being a top concern.  

Knowing the power of data and information, we can confidently assume that malicious actors will never stop their quest to infiltrate and extort enterprises. True to the well-known anecdote, this knowledge brings about great responsibility. Enterprises will face challenges as threats increase while talent and staff decrease – all while dealing with vendor sprawl and choice-overload across the market.  

SOC Assessment Tool

Check Your SOC Maturity Level

Time to schedule a check-up for your SOC. It may not be as healthy as you think and true to both the medical and security industries, proactivity and prevention can lead to optimized functionality.

Take the Assessment Now

 Want to learn more about McAfee’s investment in XDR and explore its approach? Check out McAfee MVISION XDR.  

The post SOC Health Check: Prescribing XDR for Enterprises  appeared first on McAfee Blogs.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk