#RSAC365: How to Achieve Next Level Security Automation

#RSAC365: How to Achieve Next Level Security Automation

Speaking at the RSAC 365 Virtual Summit Tomasz Bania, cyber-defense manager, Dolby, explored how organizations can transition from manually doing the security basics to implementing full end-to-end security automation.

Bania explained that the amount of work security teams are having to handle is increasing rapidly, but without the tooling or staffing to keep up.

Furthermore, levels of alert volumes received by security teams are increasing, “without a matching growth in the skilled technical resources that are available to us,” Bania continued.

By utilizing security automation there is “an opportunity to automate the monotonous and bring things that are much more interesting to them [security professionals] so that they are more engaged and feel more valued within the organization.”

When it comes to measuring an organization’s automation capabilities, Bania suggested a five-level framework:

  1. Manual processing
  2. Limited orchestration and no automation
  3. Significant orchestration and some automation
  4. Full orchestration and significant orchestration
  5. End-to-End SOAR implementation

The fifth level is the goal when it comes to achieving full-scale automated security, Bania said, allowing organizations to leverage automation through the security entire process, from identification to automated handling and reporting.

To achieve such a holistically automated security position, Bania advised organizations to follow an incremental process guideline, starting with actions to achieve in the first 30 days.

“Over the next 30 days, validate your existing manual IR processes,” he said. “If you’re holding this as tribal knowledge you might want to start documenting what all those processes are.”

Once that is achieved (likely around the 90-day mark) the next step is to “develop your single or heuristic scoring algorithm,” tailoring it to what matters most in your organization, Bania said.

Next, between 90 and 180 days, “validate your scoring efficacy with manual analysis” and “move forward to developing your first machine learning model.

“Once you’ve developed your first machine learning model, one of the very important things you’re going to want to do [at the 180+ day stage] is conduct a back test of that model compared to your pre-automation datasets if you have them available.”

To conclude, Bania said: “The earlier you can start documenting alerts, events and metadata for future analysis, the better chance you have of developing this machine learning model quickly and effectively.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#RSAC365: Organizations Must Prepare for New #COVID19 Data Privacy Challenges

#RSAC365: Organizations Must Prepare for New #COVID19 Data Privacy Challenges

New data protection issues brought about by the COVID-19 pandemic were discussed by Behnam Dayanim, partner and global chair of privacy and cybersecurity practice at Paul Hastings LLP, during a session at the RSAC 365 Virtual Summit.

With COVID-19 vaccines now being rolled out across the world, many organizations are preparing to enable the safe return of staff to their offices. In the view of Dayanim, it is important to question and challenge the storing of sensitive personal data related to this return. He cited a recent IAPP/EY study analyzing data collection by organizations of staff returning to physical work locations. Among the findings, 76% of organizations have asked employees to notify them if they are diagnosed with COVID-19, 53% asked staff about personal travel and 23% have taken temperature tests of employees. He asked: “Is there really a need to record that, or is it simply enough to know that you have that process in place?”

Dayanim also said that, over the next few months, it is likely employers will ask their staff to notify them about whether or not they have been vaccinated. “All of these things are quite novel; not the types of questions that one would normally have expected employers to be asking of their employees,” he added.

Another data privacy issue regards organizations sharing sensitive COVID-related data about their employees with third parties. For instance, it has been shown that three in 10 organizations have been asked to share anonymized COVID data with governmental bodies or NGOs, while 20% have shared the names of staff diagnosed with other employees or government agencies.

Over the coming months, it is important that procedures are put in place to safeguard the collection and use of data of this nature, according to Dayanim. This includes considering whether it is necessary to hold such data, who collects it and how this information should be communicated to other employees. “Those are the kinds of questions that are important to think about now before we have wide scale reopening, because even post-vaccination, there will be quite a large number of people that have not been vaccinated and therefore might be susceptible to the virus,” he noted, adding that “having in place a process to deal with it will be really important.”

US-based organizations also need to take note that COVID-19 testing or temperature checks do not fall under the provisions of the federal Health Insurance Portability and Accountability Act (HIPAA). This means that when they are working with third parties to conduct such tests, it is important to carefully review the contract for its provisions on privacy, as simply stating data privacy falls under the HIPAA will not be sufficient. Dayanim explained: “You have to modify that provision to say either they will comply with HIPAA requirements irrespective of whether HIPAA applies, or to build in specific requirements for privacy and security.”

Concluding, Dayanim advised organizations to be “reviewing your reopening protocols, understand what kind of data you’re collecting and how you protect it, and ask, question, challenge: do we need to collect this information?”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Remote Workers Could Offer Brexit Britain Cybersecurity Lifeline

Remote Workers Could Offer Brexit Britain Cybersecurity Lifeline

Many UK IT leaders are concerned that a security hiring freeze last year could ramp up cyber-risk, but the new remote working environment may offer a partial solution, according to CrowdStrike.

The security vendor released new UK-centric findings today from its Global Security Attitude Survey which polled 2200 IT and security decision makers around the world.

A majority (63%) of UK respondents claimed their organization is now at a higher risk from cyber-attacks due to the pandemic, yet 44% had a hiring freeze in place last year.

In fact, the UK had the lowest average of new cybersecurity hires of all countries surveyed, with 31% taking on between one and five new cybersecurity staffers last year.

This concerned respondents: many argued that the hiring freeze (40%) and reduction in available talent (45%) will amplify the increased cyber-risk resulting from the pandemic.

However, the adoption of mass remote working by most organizations could open up a global talent pool for Brexit-bound businesses, argued Zeki Turedi, EMEA CTO at CrowdStrike.

“How UK organizations will approach hiring in 2021 ultimately comes down to whether they see cybersecurity as being an important and integral part of their business. Whilst a zero-trust mindset should be the norm for all firms, the importance placed on cybersecurity varies massively depending on the sector and type of business,” he told Infosecurity.

“Hopefully, the work-from-anywhere policies that many companies are adopting will allow organizations to invest and bring in the right people to support their cybersecurity efforts, no matter where they may call home.”

This matters, because many respondents claimed that intrusion detection times have become slower (40%) over the past year, and that the pandemic has made it harder to prevent cyber-intrusions (51%).

Turedi argued that this was due to an uptick in attacks on organizations and forced architectural shifts that were sometimes made without security baked-in from the start.

“The added complexity of teams working from home, using tools not made to deal with remote security incidents and growing threats — all with a change of architecture — can make detection times a lot longer,” he said.

“This complexity is exactly what cybercrime groups use against victims to gain an advantage. We recently revealed that threat actors were in organizations’ networks for on average of 79 days before the victims realized.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Consumers Falling for $100m Clone Firm Scams

Consumers Falling for $100m Clone Firm Scams

British consumers lost nearly £80m ($109m) to so-called “clone firm” scams last year, as pandemic-related money woes persuaded many to make ill-judged investments, according to the Financial Conduct Authority (FCA).

The financial regulator reported consumers losing an average of £45,242 each when interacting with fraudsters masquerading as legitimate investment companies. Reports surged 29% between March, when the country went into its first lockdown, and April 2020.

As the name suggests, clone firms are fake entities set up by fraudsters who use the name, address and Firm Reference Number (FRN) of legitimate FCA-regulated companies.

Scam emails spammed out to consumers will link to the real companies’ websites to add legitimacy, and the fraudsters often copy FRN numbers and encourage victims to check the FCA Register to prove they are the real deal.

Three-quarters (75%) of investors told the FCA they felt confident they could spot a scam, although even more (77%) admitted they did not know, or were unsure, what a “clone investment firm” was.

The regulator urged anyone considering investing to check the firm’s details with the FCA Register and to use the phone number listed there to double-check any information.

The COVID-19 crisis is making scams like these increasingly profitable for cyber-criminals. The FCA revealed that 42% of investors are currently worried about their finances because of the pandemic, and 77% have already or plan to make an investment within the next six months to boost their finances.

“Last year we issued alerts in relation to over 1100 firms including clones, which has more than doubled since 2019, and we are working with the National Economic Crime Center (NECC) and National Cyber Security Center to take down clone sites when they are discovered,” explained Mark Steward, the FCA’s executive director of enforcement and market oversight.

“If you’re considering an investment, visit the FCA Register to make sure the firm you’re dealing with is authorized. When it comes to clones, I cannot emphasize enough how important it is to double check every detail.”

A report from thinktank RUSI this week warned that fraud has become a serious threat to the UK’s national security and called for a “major systemic shift” in government strategy to tackle it.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#DataPrivacyDay: Leaks and Breaches Soared 93% in 2020

#DataPrivacyDay: Leaks and Breaches Soared 93% in 2020

Breaches and leaks of sensitive information from organizations doubled last year, even as consumer concerns over data privacy surged, according to two new reports published on Data Protection Day.

January 28 marks the signing in 1981 of Convention 108, the first legally binding international treaty dealing with privacy and data protection. Also known as Data Privacy Day in North America, it is now an awareness raising event aimed at organizations and consumers alike.

However, new research from Imperva warned today that unauthorized transmissions of data from organizations’ networks to external destinations had soared 93% in 2020.

The security vendor detected 883,865 such incidents at the start of the year, rising to 1.7 million by the end of December, and argued the figure would be even higher if loss of data via physical devices, print-outs and the like were included.

“Data security should never be an afterthought – but sadly it often is, particularly when organizations prioritize speed over security. The rush to maintain business continuity in 2020 has accelerated change at such a pace that huge gaps now exist in process and protection around data,” said Chris Waynforth, AVP Northern Europe at Imperva.

“It is naïve to think that it is only human access to data that leads to compromise. Over 50% of access requests to databases are coming not from users, but application to application.”

The risk of major regulatory fines should be making this a board-level issue, the vendor added.

Imperva urged organizations to follow several key steps to better protect their data, starting with discovery and classification, and moving on to access controls, continuous monitoring and quarantining in the event of an attack.

Data minimization should be front-of-mind throughout, as information continues to disperse across complex multi- and hybrid cloud environments, the firm argued.

However, consumers also have a big part to play in keeping their information out of harm’s way. Some 77% told Entrust they are concerned about data privacy, and 64% said their awareness about the issue has increased over the past 12 months.

At the same time, though, many (63%) were wiling to hand over more information to applications in return for greater personalization. Nearly half (47%) said they don’t review the T&Cs of an app before downloading, with most claiming it was because these take too long to read.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk