Aston Martin Partners with SentinelOne

Aston Martin Partners with SentinelOne

American cybersecurity company SentinelOne was today named as the official cybersecurity partner of Aston Martin‘s Cognizant Formula One Team.

SentinelOne operates from offices in Mountain View, California. The company was founded in 2013 by Almog Cohen and Tomer Weingarten, who still acts as the company’s CEO. 

Today’s partnership announcement follows SentinelOne’s ongoing partnership with Aston Martin Lagonda. SentinelOne’s AI-powered Singularity XDR platform was selected by Aston Martin in 2018 to protect the team’s cloud workload, IoT devices, and endpoints. 

“The parallels between Aston Martin and SentinelOne are strong, and it is an honor to support Aston Martin Cognizant Formula One Team’s much anticipated return to the top tier of global motorsport,” said Weingarten.

“We both share a relentless passion for innovation and desire to disrupt the status quo, and an appreciation of the significance of speed. These core principles are at the soul of this partnership and represent the power of Aston Martin Cognizant Formula One Team and SentinelOne.”

Aston Martin Cognizant Formula One Team officially launches next month. The team’s debut race will take place in Bahrain on March 28.

“I am delighted that SentinelOne will be one of Aston Martin Cognizant Formula One Team’s key partners as we take Aston Martin back where it belongs, the top table of international motorsport, namely Formula One,” said Lawrence Stroll, chairman of the Aston Martin Cognizant Formula One Team. 

“Tomer and I have enjoyed our discussions, and it is clear that our two companies have much in common. Ours will be a very real partnership, delivering genuine performance enhancements to the safe and smooth running of our team.” 

A British independent manufacturer of luxury sports cars and stylish grand tourers, Aston Martin was founded in 1913. During its extensive history the company has gone bankrupt seven times. 

In August 2017, a 1956 Aston Martin DBR1/1 previously driven by Carroll Shelby and Stirling Moss was sold at a Sotheby’s auction at the Concours d’Elegance held in Pebble Beach, California, for $22,550,000. According to Sotheby’s, the vehicle was the most expensive British car ever sold at an auction. 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

84% of CNI Orgs Experienced Cyber-Attacks in the Last Year

84% of CNI Orgs Experienced Cyber-Attacks in the Last Year

The vast majority (86%) of critical national infrastructure (CNI) organizations in the UK have experienced cyber-attacks on their operational technology (OT) and industrial control systems (ICS) in the past 12 months, according to a new study by Bridewell Consulting.

Worryingly, more than nine in 10 (93%) of those that experienced attacks in this period admitted that at least one was successful.

The survey of 250 UK IT decision makers in the aviation, chemical, energy, transport and water sectors also found that a substantial proportion of organizations use legacy OT systems. A third (34%) rely on systems that are between 11-20 years old, while 79% use systems aged between six-20 years.

CNI organizations’ legacy infrastructure is also becoming increasingly connected, which is potentially widening the attack surface, with 84% confirming their OT/ICS environments are accessible from corporate networks. Additionally, just 42% of those surveyed said their OT/ICS systems are not currently accessible from the internet, and over half of those plan to make them accessible in the future.

The researchers also revealed that almost a third (32%) of CNI organizations have reduced their security budgets since the start of the COVID-19 pandemic, which has led to 85% of IT and security teams feeling growing pressure to improve cybersecurity controls for their OT/ICS environment.

Lack of skills and increasing responsibilities was another challenge outlined by IT decision makers (both cited by 23% of respondents), and 84% of CNI organizations believe they will be impacted by a critical cyber-skills shortage in the next three to five years.

Despite this troubling landscape, more than three-quarters (78%) of respondents expressed confidence that their OT systems are protected from cyber-threats.

Scott Nicholson, Co-CEO at Bridewell Consulting, commented: “The report highlights some nuances between how some CNI organizations perceive their cybersecurity posture versus reality. Security vulnerabilities, whilst challenging to remediate within some CNI organizations, could have serious implications, not just in terms of substantial monetary fines but also risks to public safety and even loss of life, so organizations simply cannot afford to be complacent.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

In-House Legal Teams Increasingly Responsible for Cybersecurity

In-House Legal Teams Increasingly Responsible for Cybersecurity

Cybersecurity is increasingly becoming the responsibility of in-house legal departments within organizations.

That’s according to a survey from the Association of Corporate Counsel (ACC), which discovered that this year, for the first time, cybersecurity has overtaken compliance as the most important issue facing businesses, as ranked by company chief legal officers (CLOs).

ACC surveyed almost 1000 global CLOs from 21 industries, with just under half stating that responsibility for cybersecurity and data privacy within their business falls under their umbrella.

The research highlights the challenges brought about by increased remote working due to the COVID-19 pandemic and the growing integration of business strategy and technology policies.

Commenting on the findings, Robin Grossfeld, senior VP, global initiatives at ACC, said: “As people continue working from home for the foreseeable future, CLOs are increasingly being asked to assume responsibility for their company’s cybersecurity efforts. This is presenting a new challenge for many in-house legal teams, and one that is helping to redefine their day-to-day corporate roles.”

In previous research ACC research, it was discovered that 71% of organizations have their CLO either in a leadership role regarding cybersecurity strategy, or working as part of a team with cybersecurity responsibilities.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Experts Discuss How #COVID19 Impacted the Cyber-Threat Landscape

Experts Discuss How #COVID19 Impacted the Cyber-Threat Landscape

The impact of COVID-19 on the cyber-threat landscape was discussed by a panel during a virtual roundtable session held by Orange Cyberdefense and the UK Cyber Security Association.

Citing Orange’s Security Navigator 2021 report, Charl van der Walt, head of security research at Orange Cyberdefense, began by outlining some unexpected trends in regards to incidents detected in the early stages of the crisis. Comparing two countries that took differing approaches to dealing with COVID-19 infections, in the tightly locked down France, there was a decrease in confirmed cyber-incidents of 18%, whereas in Sweden, where there was a much lighter approach to social distancing taken, the number of incidents remained similar. This “inverse” effect may be explained by the reduction in economic activity in these early months. “There were fewer people busy, connected to the network, fewer computers online and less interaction,” noted van der Walt. Therefore, the predicted surge in attacks did not occur over this time.

However, Lisa Ventura, CEO and founder, Cyber Security Association, said that her organization has observed attacks on SME businesses in the UK rise substantially since the start of COVID-19. From research and conversations with these organizations, “the vast majority have suffered a data breach or cyber-attack and a considerable two-in-five have admitted that they’ve suffered multiple breaches,” she outlined. The types of attack vectors have been varied in nature, including phishing, malware, ransomware and CEO fraud, with COVID-19 frequently used as a theme.

A major factor in this increase is the shift to home working, making organizations particularly vulnerable. Encouragingly though, “with the move to getting everybody working from home quickly last year from a business continuity perspective, we’re seeing more SMEs finally starting to take their cybersecurity posture much more seriously.”

There are parallels between these two apparently competing observations, according to Stuart Reed, UK director of Orange Cyberdefense. He noted that during COVID-19, the “digital attack surface has got wider” which is why SMEs are suffering more breaches. Yet, the tactics employed by cyber-criminals haven’t changed substantially, other than using the theme of COVID-19 in attacks.

Orange Cyberdefense also revealed that, in line with Ventura’s observations, smaller businesses have become increasingly heavily targeted by cyber-criminals, which could be due to having less security resources at their disposal, something that has been especially exposed amid the current situation. “Per employee, we’re seeing more attacks on small organizations than on large organizations,” commented van der Walt, adding that, compared to large organizations, “it’s actually growing faster.”

Ventura reiterated that the pandemic has “brought cybersecurity to the forefront for a lot of these organizations.”

One tactic that has become more prevalent over the past year is ransomware, which has “noticeably” gone up, according to van der Walt. This method has significantly impacted SMEs, whose IT gaps have been exploited by ransomware gangs. Ventura said that in many cases, SMEs have rushed to pay the ransom “rather than deal with those encrypted files and recovering their IT systems, and this in turn created a vicious cycle: the more often those types of attacks succeeded, the more often they occurred.”

As a result, Reed advised that it is always best not to pay a ransom, regardless of the consequences, as it will only worsen the problem over the long term for everyone. “By paying the extortion, there is naturally going to be the incentive to use that mechanism time and again,” he explained.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Think Tank Warns of “Silent Stealing” Fraud

Think Tank Warns of “Silent Stealing” Fraud

Fraudsters may increasingly be moving away from major corporate scams to target large numbers of consumers for very small amounts, according to a new think tank report.

The report from RUSI, The UK’s Response to Cyber Fraud, is intended to provide long-term recommendations for government and private sector organizations to help tackle the modern online scourge.

It noted that some researchers consulted by the report’s authors have posited that some fraudsters are migrating from “industrial scale” attacks on businesses to easier prey.

“For all the protections that can be put in place to help individuals stay safe online, a bank cannot always increase a customer’s level of protection directly, and a level of awareness and action is incumbent on customers themselves,” it noted. “This leaves gaps which criminals can exploit, with some research participants conceptualizing this as ‘silent stealing.’”

The rationale is that, rather than trying to steal £10m from a bank direct, it would be easier to steal £10 each from 100,0000 consumers. This theoretically keeps the scammers under the radar as, even if a consumer found out they had lost the money, few would bother reporting it.

Home workers are increasingly susceptible to such threats given that home networks and devices may be less well protected than those in the office and used by various members of the household for potentially risky activities.

However, Adenike Cosgrove, cybersecurity strategist, international at Proofpoint, argued that it’s important to put the findings into perspective. BEC losses reported to the FBI hit nearly $1.8bn last year, for example.

“Our research has shown that almost two-thirds of businesses worldwide faced these attacks in 2020, and we expect this trend to get even worse throughout 2021,” she said.

“From the attacker’s perspective, the barrier to entry is low, yet with the potential reward so high, BEC will remain a draw for cyber-criminals and isn’t going away any time soon.”

Last month, RUSI warned that fraud had become a grave threat to the UK’s national security and urged government to get a handle on it.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FireEye: Accellion FTA Attacks Could be FIN11

FireEye: Accellion FTA Attacks Could be FIN11

A string of attacks exploiting a legacy file transfer product have been linked to well-known financial cybercrime gang FIN11.

The attacks on the New Zealand Central Bank, Singtel, Kroger and many more exploited multiple zero-day vulnerabilities in Accellion’s FTA product and are being tracked by FireEye as UNC2546.

“The motivation of UNC2546 was not immediately apparent, but starting in late January 2021, several organizations that had been impacted by UNC2546 in the prior month began receiving extortion emails from actors threatening to publish stolen data on the ‘CL0P^_- LEAKS’ .onion website,” the vendor explained.

“Some of the published victim data appears to have been stolen using the DEWMODE web shell.”

FireEye said that the FIN11 gang has previously published stolen victim data from CLOP ransomware attacks on the same .onion site, in double dip extortion campaigns. Although there was no ransomware in the Accellion attacks, investigators found other links with the group.

It said many of the organizations compromised by UNC2546 were previously targeted by FIN11, and that an IP address that communicated with a DEWMODE web shell was in the “Fortunix Networks L.P.” netblock. This is a network frequently used by FIN11 to host download and FRIENDSPEAK command and control (C2) domains, FireEye claimed.

The vendor is tracking the extortion activity related to the Accellion attacks as UNC2582 and said it found even more overlaps between this and FIN11, including emails sent from the same IP addresses as FIN11 phishing campaigns.

In an update yesterday, Accellion itself revealed that “fewer than 100” of the 300 corporate users of FTA were affected by the campaign, and “fewer than 25 appear to have suffered significant data theft.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Most Firms Now Fear Nation State Attack

Most Firms Now Fear Nation State Attack

A majority of businesses now regard state-sponsored or led attacks as a major threat, marking a potentially critical shift in perception, according to new research from the Economist Intelligence Unit.

The study, sponsored by the Cybersecurity Tech Accord, is compiled from interviews with over 500 director-level or above executives from businesses in Asia-Pacific, Europe and the United States.

Conducted before the SolarWinds campaign even came to light, the research nevertheless revealed that 80% are concerned about falling victim to a nation state attack, with a majority claiming these worries have increased over the past five years.

What’s more, they want their respective governments to play a bigger role in meeting these challenges: 60% said their country only offers a medium or low-level of protection.

“Although cyber-attacks are a silent threat, they can have devastating and long-lasting effects on our society. Given the recent escalation of tensions in cyberspace, cooperation between governments is becoming increasingly complicated as political systems differ and technological competition rises,” said Marietje Schaake, president of the CyberPeace Institute.

“This survey is an important call to action for democratic governments to step up and think more inclusively about the kind of cyber-assistance they provide to protect companies in key sectors, and ultimately civilians.”

Worryingly, the study also pointed to a false sense of security among the senior executives interviewed, potentially because they have little direct experience of being attacked.

Over two-thirds (68%) of executives said they feel their organization is “very” or “completely” prepared to deal with a cyber-attack.

Annalaura Gallo, secretariat of the Cybersecurity Tech Accord, said she hoped the survey would start a global conversation around the topic.

“This survey shows that businesses see state-led and sponsored cyber-attacks as a pressing issue that demands governments act nationally and internationally,” she added.

“We need agreement at the United Nations and the involvement of business and civil society through multi-stakeholder forums, such as the Paris Call for Trust and Security in Cyberspace.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

New Partnership Launched to Improve Cyber-Resilience in Scotland

New Partnership Launched to Improve Cyber-Resilience in Scotland

A new collaboration has been formed by 10 strategic organizations as part of efforts to enhance cyber-resilience and increase awareness of cyber-risks in Scotland. The CyberScotland partnership, which includes the Scottish Government, Police Scotland and the Scottish Business Resilience Center (SBRC), will work on ensuring individuals and organizations have easy access to up-to-date guidance on cybersecurity and resilience.

The UK’s National Cyber Security Center (NCSC) will act as a technical advisor to the partnership.

The partnership’s first move has been to launch a new online resource, offering information and support across a range of cybersecurity issues for all individuals and organizations in the public, private and third sectors. Funded by the Scottish government, the website also provides information on skills development for those considering pursuing a career in cybersecurity.

The website has been launched on the opening day of CyberScotland week, a series of events aimed at improving cyber-awareness and resilience in Scotland.

Ivan McKee, minister for trade, innovation and public finance at the Scottish Government, commented: “The new strategic framework for a cyber-resilient Scotland launched by the deputy first minister earlier this week outlines Scotland’s intention to be a digitally secure and resilient nation. The CyberScotland partnership will help drive forward this ambition. As well as providing advice and guidance, improved coordination of skills opportunities, the partnership will help to promote Scotland’s flourishing cybersecurity products and service industry. Greater awareness of the cyber-risks leads to greater demand for solutions and our cybersecurity industry can produce innovative solutions and offer high quality employment.

“The organizations involved in this partnership play leading roles in effectively delivering the new strategic framework. A formal collaboration will further increase our effectiveness and reduce duplication of effort. The partnership will further reinforce Scotland as a global leader in the battle against cybercrime and a champion for ensuring a secure online environment for all.”

Jude McCorry, CEO of the SBRC, said: “The events of 2020 drove home the importance of remaining focused on cybersecurity. The reliance on technology for work and socializing grew alongside a corresponding rise in cyber-attacks. The SBRC has discussed the formation of a collaboration between the organizations involved in the CyberScotland partnership for some time, as we have seen some confusion from the public about where to get the support they need. Together, we can improve awareness and share knowledge of cybersecurity threats around Scotland. The CyberScotland.com website is a seamless solution to ensure everyone can access the right information from the right source.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk