Just 8% of Firms Offer Regular Security Training

Just 8% of Firms Offer Regular Security Training

A majority of UK businesses are failing to adequately train their remote working employees to spot security threats, according to new research from iomart.

The cloud services company based its Cyber Security Insights Report on the views of 1167 UK workers at C-level, director, manager and employee level.

It found that over a quarter (28%) of their employers offer no cybersecurity training for the distributed workforce, while a further 42% do but only to select employees.

Of those who were offered training, 82% claimed that it was a short briefing rather than something more comprehensive. Less than a fifth (17%) said they had regular training sessions.

That means, overall, just 8% of those surveyed receive regular security training.

This comes at a time when threats are on the rise. A fifth (20%) of those surveyed reported seeing an increase in cyber-attacks as a result of working remotely.

Cyber-criminals have been targeting remote workers with phishing emails often themed with COVID-19 lures, as well as vulnerabilities in VPN infrastructure and insecure RDP endpoints that can be easily brute-forced or their credentials bought off the dark web.

The number of RDP ports exposed to the internet grew from three million to 4.5 million in the period from January to March 2020, according to McAfee research released in May.

Bill Strain, security director at iomart, warned that organizations still aren’t placing security and data protection at the top of their priority list.

“They need to understand what the potential threats are and build resilience into their business strategy so they can react quickly and maintain operations if their IT systems are compromised,” he urged.

“Many businesses would not survive the operational — let alone financial — impact of a data breach. By understanding the potential risk and introducing positive behavior around cyber awareness, they have a much better chance of surviving an incident.”

Remote workers are thought of as a potential cyber risk as many may be more distracted at home and likely to click through on phishing emails, whilst their devices may not be as well protected as corporate equivalents.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Big Tech Joins Up to Ransomware Task Force

Big Tech Joins Up to Ransomware Task Force

A group of big-name security and technology vendors, non-profits and other industry stakeholders have come together to create a new group focused on combatting ransomware.

The Ransomware Task Force (RTF) is the brainchild of Bay Area firm the Institute for Security and Technology (IST) and will see member organizations unite to provide “clear recommendations for both public and private action that will significantly reduce the threat posed by this criminal enterprise.”

Members announced at the official launch yesterday include tech firms Citrix, Microsoft, McAfee, Rapid 7, Team Cymru and Cybereason, law firm Venable LLP, and policy-maker groups like Digital Aspen and the Cybersecurity Coalition. Others on board include insurer Resilience, non-profit the Shadowserver Foundation and data sharing group the Cyber Threat Alliance.

“Ransomware incidents have been growing unchecked, and this economically destructive cybercrime has increasingly led to dangerous, physical consequences. Hospitals, school districts, city governments, and others have found their networks held hostage by malicious actors seeking payouts,” the IST argued.

“This crime transcends sectors and requires bringing all affected stakeholders to the table to synthesize a clear framework of actionable solutions, which is why IST and our coalition of partners are launching this Task Force for a two-to-three-month sprint.”

According to the most recent stats, ransomware grew as a percentage of total detected malware from 39% to 51% during the period Q2-Q3 2020. Healthcare organizations have been most notably targeted through the COVID-19 crisis, as have vaccine developers.

Big names such as French IT services giant Sopra Steria have been on the receiving end of a surge in “big game hunting” attacks using APT-style tactics to infiltrate large organizations. It said a Ryuk attack in October could end up costing the firm as much as $60 million.

However, the truth is that SMBs are much more likely to get caught out, according to Coveware. The vendor claimed that organizations with up to 1000 workers accounted for 73% of attacks in Q3 2020.

“The RTF will assess existing solutions at varying levels of the ransomware kill chain, identify gaps in solution application, and create a roadmap of concrete objectives and actionable milestones for high-level decision-makers,” said the IST.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Eavesdropping on Phone Taps from Voice Assistants

The microphones on voice assistants are very sensitive, and can snoop on all sorts of data:

In Hey Alexa what did I just type? we show that when sitting up to half a meter away, a voice assistant can still hear the taps you make on your phone, even in presence of noise. Modern voice assistants have two to seven microphones, so they can do directional localisation, just as human ears do, but with greater sensitivity. We assess the risk and show that a lot more work is needed to understand the privacy implications of the always-on microphones that are increasingly infesting our work spaces and our homes.

From the paper:

Abstract: Voice assistants are now ubiquitous and listen in on our everyday lives. Ever since they became commercially available, privacy advocates worried that the data they collect can be abused: might private conversations be extracted by third parties? In this paper we show that privacy threats go beyond spoken conversations and include sensitive data typed on nearby smartphones. Using two different smartphones and a tablet we demonstrate that the attacker can extract PIN codes and text messages from recordings collected by a voice assistant located up to half a meter away. This shows that remote keyboard-inference attacks are not limited to physical keyboards but extend to virtual keyboards too. As our homes become full of always-on microphones, we need to work through the implications.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Russia Officially Denies Large-scale US Hack

Russia Officially Denies Large-scale US Hack

Russia has officially denied any culpability for a recent cyber-attack that impacted at least six federal agencies in the United States.

America’s Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive last week after cyber-criminals trojanized updates to SolarWinds’ Orion IT monitoring and management software to launch a large-scale cyber-attack. 

CISA said that the incident poses “unacceptable risk to the security of federal networks” and urged all federal civilian agencies to review their networks for indicators of compromise and to disconnect or power down SolarWinds Orion products immediately.

SolarWinds, an IT company based in Austin, Texas, which serves government customers across the executive branch, the military, and the intelligence services, stated on December 20 that it was the victim of a sophisticated supply-chain attack that “could potentially allow an attacker to compromise the server on which the Orion products run.” 

The company has not attributed the attack to any particular threat actor, stating only that “we’ve been advised that the nature of this attack indicates that it may have been conducted by an outside nation state, but SolarWinds has not verified the identity of the attacker.”

While the US government has not publicly identified who might be behind the hacking, Reuters reported on December 15 that “three of the people familiar with the investigation said Russia is currently believed to be responsible for the attack.”

Secretary of State Mike Pompeo publicly laid the blame for the cyber-attack at Russia’s door on December 18. 

Discussing the cyber-incident during an interview with radio host Mark Levin, Pompeo stated: “This was a very significant effort, and I think it’s the case that now we can say pretty clearly that it was the Russians that engaged in this activity.” 

Today, Russian News Agency Tass reported that Moscow was not responsible for the hacking attack that impacted US government bodies and companies. 

“Russia is not involved in such attacks, namely this one. We state this officially and firmly,” Kremlin spokesperson Dmitry Peskov told reporters on Monday.

He added that “any accusations of Russia’s involvement are absolutely baseless; they are more likely to be a continuation of blind Russophobia that is resorted to in case of any incident.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

BlueHalo Acquires Base2 and Fortego

BlueHalo Acquires Base2 and Fortego

Arlington Capital Partners portfolio company BlueHalo today announced that it has completed the acquisition of Maryland businesses Base2 LLC and Fortego LLC.

While both companies are leading providers of complex, mission-critical cyber and Signals Intelligence (SIGINT) solutions, Base2 specializes in the design and development of cyber-solutions in the areas of Computer Network Operations (CNO), SIGINT, and Quick Reaction Capability (QRC).

“We reached a point where it was time to consider being part of a larger organization that could help our company grow long term,” said Base2 co-founders Edward Wright and Michael Curry.

“BlueHalo resonated with us because they focus on solving the hardest engineering problems while contributing to national defense imperatives.”

Fortego, formed to fill a niche need for highly specialized technical analysts and developers focused on current cyber-warfare techniques and technologies, is known for its capabilities in advanced SIGINT and cyber operations solutions, with end-to-end solutions in cyber-analytics, vulnerability research, and CNO engineering.

“Combining with BlueHalo, who also believes in the importance of an employee- and mission-focused culture, was a natural fit as we lead Fortego into the next phase of its evolution,” said Chad Price and Eric Rothenberger, co-founders of Fortego.

BlueHalo said that the freshly sealed deal will enable the company to address the most complex cyber programs in the national security community. 

“We are thrilled to partner with the management teams at both Base2 and Fortego,” said Jonathan Moneymaker, CEO of BlueHalo. 

“The strong cultural alignment between our organizations around driving inspired engineering of complex solutions for our customers and our mission focus and unique access to specialized programs attracts the best of the best to the team.

“BlueHalo is leading the transformation of modern warfare, and the acquisitions of Base2 and Fortego enhance our ability to deliver on this vision and accelerate our ability to grow organically into new mission areas.”

BlueHalo was formed through the combination of AEgis Technologies and its previously integrated acquisitions Excivity and EMRC Heli, Applied Technology Associates, and Brilligent Solutions.

The company has nearly 900 employees located across 11 states chosen for their proximity to major intelligence and Department of Defense organizations.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk