Michael Ellis as NSA General Counsel

Over at Lawfare, Susan Hennessey has an excellent primer on how Trump loyalist Michael Ellis got to be the NSA General Counsel, over the objections of NSA Director Paul Nakasone, and what Biden can and should do about it.

While important details remain unclear, media accounts include numerous indications of irregularity in the process by which Ellis was selected for the job, including interference by the White House. At a minimum, the evidence of possible violations of civil service rules demand immediate investigation by Congress and the inspectors general of the Department of Defense and the NSA.

The moment also poses a test for President-elect Biden’s transition, which must address the delicate balance between remedying improper politicization of the intelligence community, defending career roles against impermissible burrowing, and restoring civil service rules that prohibit both partisan favoritism and retribution. The Biden team needs to set a marker now, to clarify the situation to the public and to enable a new Pentagon general counsel to proceed with credibility and independence in investigating and potentially taking remedial action upon assuming office.

The NSA general counsel is not a Senate-confirmed role. Unlike the general counsels of the CIA, Pentagon and Office of the Director of National Intelligence (ODNI), all of which require confirmation, the NSA’s general counsel is a senior career position whose occupant is formally selected by and reports to the general counsel of the Department of Defense. It’s an odd setup — ­and one that obscures certain realities, like the fact that the NSA general counsel in practice reports to the NSA director. This structure is the source of a perennial legislative fight. Every few years, Congress proposes laws to impose a confirmation requirement as more appropriately befits an essential administration role, and every few years, the executive branch opposes those efforts as dangerously politicizing what should be a nonpolitical job.

While a lack of Senate confirmation reduces some accountability and legislative screening, this career selection process has the benefit of being designed to eliminate political interference and to ensure the most qualified candidate is hired. The system includes a complex set of rules governing a selection board that interviews candidates, certifies qualifications and makes recommendations guided by a set of independent merit-based principles. The Pentagon general counsel has the final call in making a selection. For example, if the panel has ranked a first-choice candidate, the general counsel is empowered to choose one of the others.

Ryan Goodman has a similar article at Just Security.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Trump Fires Security Chief Christopher Krebs

President Trump on Tuesday fired his top election security official Christopher Krebs (no relation). The dismissal came via Twitter two weeks to the day after Trump lost an election he baselessly claims was stolen by widespread voting fraud.

Chris Krebs. Image: CISA.

Krebs, 43, is a former Microsoft executive appointed by Trump to head the Cybersecurity and Infrastructure Security Agency (CISA), a division of the U.S. Department of Homeland Security. As part of that role, Krebs organized federal and state efforts to improve election security, and to dispel disinformation about the integrity of the voting process.

Krebs’ dismissal was hardly unexpected. Last week, in the face of repeated statements by Trump that the president was robbed of re-election by buggy voting machines and millions of fraudulently cast ballots, Krebs’ agency rejected the claims as “unfounded,” asserting that “the November 3rd election was the most secure in American history.”

In a statement on Nov. 12, CISA declared “there is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised.”

But in a tweet Tuesday evening, Trump called that assessment “highly inaccurate,” alleging there were “massive improprieties and fraud — including dead people voting, Poll watchers not allowed into polling locations, ‘glitches’ in the voting machines that changed votes from Trump to Biden, late voting, and many more.”

Twitter, as it has done with a remarkable number of the president’s tweets lately, flagged the statements as disputed.

By most accounts, Krebs was one of the more competent and transparent leaders in the Trump administration. But that same transparency may have cost him his job: Krebs’ agency earlier this year launched “Rumor Control,” a blog that sought to address many of the conspiracy theories the president has perpetuated in recent days.

Sen. Richard Burr, a Republican from North Carolina, said Krebs had done “a remarkable job during a challenging time,” and that the “creative and innovative campaign CISA developed to promote cybersecurity should serve as a model for other government agencies.”

Sen. Angus King, an Independent from Maine and co-chair of a commission to improve the nation’s cyber defense posture, called Krebs “an incredibly bright, high-performing, and dedicated public servant who has helped build up new cyber capabilities in the face of swiftly-evolving dangers.”

“By firing Mr. Krebs for simply doing his job, President Trump is inflicting severe damage on all Americans – who rely on CISA’s defenses, even if they don’t know it,” King said in a written statement. “If there’s any silver lining in this unjust decision, it’s this: I hope that President-elect Biden will recognize Chris’s contributions, and consult with him as the Biden administration charts the future of this critically important agency.”

KrebsOnSecurity has received more than a few messages these past two weeks from readers who wondered why the much-anticipated threat from Russian or other state-sponsored hackers never appeared to materialize in this election cycle.

That seems a bit like asking why the year 2000 came to pass with very few meaningful disruptions from the Y2K computer date rollover problem. After all, in advance of the new millennium, the federal government organized a series of task forces that helped coordinate readiness for the changeover, and to minimize the impact of any disruptions.

But the question also ignores a key goal of previous foreign election interference attempts leading up to the 2016 U.S. presidential and 2018 mid-term elections. Namely, to sow fear, uncertainty, doubt, distrust and animosity among the electorate about the democratic process and its outcomes.

To that end, it’s difficult to see how anyone has done more to advance that agenda than President Trump himself, who has yet to concede the race and continues to challenge the result in state courts and in his public statements.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Verizon Releases First Cyber-Espionage Report

Verizon Releases First Cyber-Espionage Report

American telecommunications company Verizon today released its first ever data-driven report on cyber-espionage attacks. 

The 2020 “Cyber Espionage Report” (CER) draws from seven years of Verizon “Data Breach Investigations Report” (DBIR) content and more than 14 years of the company’s Threat Research Advisory Center (VTRAC) Cyber-Espionage data breach response expertise. 

Verizon said that it published the CER to serve as a guide for cybersecurity professionals searching for ways to improve their organization’s cyber-defense posture and incident response (IR) capabilities.

Key findings of the report are that for cyber-espionage breaches, 85% of actors were state affiliated, 8% were nation-state affiliated, and just 4% were linked with organized crime. Former employees made up 2% of actors. 

The industries most impacted by cyber-espionage breaches in the previous seven years were the public sector, manufacturing, professional, information, mining and utilities, education, and the financial industry.

Of the three most-targeted industries, the public sector bore the brunt of the breaches (31%), while manufacturing and professional were hit by 22% and 11%, respectively. 

The top compromised asset varieties in cyber-espionage breaches were desktop or laptop (88%), cell phone (14%), and web application (10%). For all breaches, the top asset varieties were web application (43%), desktop or laptop (31%), and email (21%).

Of the attributes most commonly compromised in cyber-espionage breaches, 91% involved software installation and 73% were secrets. The top compromised data varieties were credentials (56%), secrets (49%), internal (12%), and classified (7%).

The report found that while an organization can be compromised in seconds, discovering the breach can take years. Time to compromise was seconds to days (91%), time to exfiltration was minutes to weeks (88%), time to discovery was months to years (69%), and time to containment was days to months (79%). 

The most common types of breaches were web application (27%), miscellaneous errors (14%), and “everything else” (14%), with cyber-espionage making up 10% of breaches. 

Researchers noted: “Because cyber-espionage is a difficult incident pattern to detect, the numbers may be much higher. The kinds of data stolen in Cyber-Espionage breaches (e.g., secrets, internal or classified) may not fall under the data types that trigger reporting requirements under many laws or regulatory requirements.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Cybercrime to Drain $44bn from Russian Economy in 2020

Cybercrime to Drain $44bn from Russian Economy in 2020

A state-owned Russian banking and financial services company has estimated that the Russian economy will lose $44bn to cybercrime in 2020. 

Reuters reports that the estimate was published on Tuesday by Sberbank, which has held the title of Russia’s largest bank since 2014. 

From its headquarters in Moscow, Sberbank said that the shift away from store-based cash transactions to digital payments triggered by the outbreak of COVID-19 had exacerbated security concerns. 

With the novel coronavirus still raging around the world and lockdowns being reimposed, the bank’s predictions for 2021 are glum. Sberbank, which has nearly 100 million active clients, predicted that the economic fallout from cybercrime could double in the year ahead. 

“On average, we have to deal with 26 billion cybersecurity events every day,” said Stanislav Kuznetsov, deputy chairman of Sberbank’s executive board.

Speaking to Russia’s parliament, the Duma, in March of this year, President Vladimir Putin called for a crackdown on internet-enabled crime. 

Interior ministry data released in October revealed that the number of crimes linked to bank cards in Russia had increased by 500% in 2020.

“I’m asking for a system, a set of measures to reduce the number of such crimes,” said Putin.

Later that month, Russia’s Federal Security Service, the FSB, announced that as part of a joint operation with the Ministry of Internal Affairs, it had detained over 30 individuals across 11 regions of the country and charged 25 of them with selling stolen credit and debit card data online. 

Authorities said that the individuals had created more than 90 online stores through which they sold stolen data. 

In 2019, Russia’s minister of internal affairs, Alexander Kolokoltsev, said that cybercrimes in Russia had increased dramatically while other types of crimes had diminished.  

“In the last few years Internet crime has seen a 16-fold surge,” Kolokoltsev told a meeting of the Ministry’s Social Council. 

“This number is huge, despite the fact that crime in general is subsiding, felonies included. It’s precisely here, where we can concentrate and unite our efforts.”

Kolokoltsev added that the increase in cybercrime could be partly due to a lack of awareness of online scams and fraudulent schemes among Russia’s vulnerable citizens.  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Druva Acquires sfApex

Druva Acquires sfApex

Texas Salesforce developer tool and data migration service provider sfApex has been acquired by California software company Druva.

The acquisition, carried out to bolster Salesforce data protection and governance, was announced on November 17.

The deal will allow Druva to offer customers an integrated solution that combines advanced data protection with sandbox management and data governance, delivered via a cloud-native SaaS platform.

SaaS-based CRM Salesforce discontinued its own recovery feature in July of this year. The new combination of Druva and sfApex says it will deliver comprehensive SaaS data protection and management for Salesforce with granular backup and data recovery as well as streamlined and automated migrations and improved tools for developers. 

“Salesforce is critical to every organization: the data stored within it fuels growth, ensures strong customer relationships, and helps identify opportunities to expand relationships,” said Jaspreet Singh, founder and CEO, Druva. 

“Given its sensitivity and potential business impact, keeping this data available and compliant is a business critical function.”

Singh said that by welcoming sfApex into the family, Druva will ensure that Salesforce customers never have to “worry about the lights going out.” 

In addition to enhanced backup and recovery for Salesforce data, customers are set to benefit from data protection and governance support for Salesforce sandboxes. The integrated solution aims to make it easier for customers to manage CRM data effectively, reducing risk to production environments.

Druva said that users will be able to accelerate Salesforce developer cycles by up to 40% thanks to automated testing and developer sandbox creation and the ability to mask existing data in order to remain compliant with privacy requirements. 

Kashyap Patel, one of the founders of sfApex, has joined Druva as senior director of product management. 

“After years as a developer on Salesforce, in 2012 my co-founders and I recognized an opportunity to improve the platform’s data protection and governance for sandbox environments,” said Patel.

“Since then, the power of Salesforce data has only grown, and we are incredibly excited to join the Druva family and expand these capabilities even further. 

“Combining the strengths of sfApex with Druva’s extensive resources and industry leadership, we are committed to bringing a best-in-class experience and innovations to protect Salesforce customers’ most critical data.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#ISC2Congress: The #COVID19 Cyber-Threat Landscape for Businesses

#ISC2Congress: The #COVID19 Cyber-Threat Landscape for Businesses

The cyber-threats faced by businesses in 2020 have not varied a significant amount in 2020, despite the major changes to working practices brought about by COVID-19, according to Graham Cluley, cybersecurity blogger and researcher, speaking during a keynote session at the virtual (ISC)2 Security Congress.

“Most of the attacks we’re seeing during 2020 are variations on a theme that we’ve seen many times, such as phishing attacks, ransomware and business email compromise (BEC),” he explained. “They haven’t disappeared into thin air during the COVID-19 pandemic; they’ve multiplied and continued to target unprepared users and ill-prepared organizations.”

However, companies are much more vulnerable to these common tactics now, with employees operating at home where they are often heavily distracted and without easy access to IT support. Cluley noted: “We’re still being expected to determine if a link can be trusted or not and we’re sometimes making big mistakes as a result.”

He added that these attempts to trick users into clicking malicious links are becoming increasingly sophisticated, easily mistaken for something legitimate, such as appearing to be Google docs.

Another big issue is that there is now no longer a single building that can be fortified to protect companies, with their infrastructure spread out across multiple homes and networks. This means an individual falling prey to a phishing scam at home can lead to major consequences for organizations. Cluley outlined: “It’s presence may not be noticed for weeks, and stealing information and credentials, learning about your business.” Therefore, protecting against unauthorized access, such as through using more multi-factorial authentication (MFA), critical in this new environment.

Organizations also need to consider the threats posed by additional physical access into people’s homes and therefore their work environments. This can include cleaners or tradesmen. “Sometimes these people can be on a low wage and might be looking for additional ways to boost their income,” he said.

The stakes of ransomware attacks have been ramped-up over recent times, according to Cluley, and he outlined the phenomenon whereby some news organizations are willing to pay for stolen information and publicize anything “juicy” uncovered. He stated: “The exfiltration of data, from a ransomware-attacked company, can be monetized by the hacker, either by offering to sell it on the dark market to other hackers, or they can simply use it as leverage and say ‘we are going to embarrass you as a company and reveal your secrets.’”

In addition, BEC remains a huge danger, with businesses being “attacked more than ever” via this method. Cluley explained that this generally occurs following extensive research into organizations by cyber-criminals, who then pose as genuine suppliers to trick finance departments into wiring them money. He cited FBI figures which estimate businesses globally have lost $12bn from these types of scam, which don’t require any programming knowledge.

He highlighted a recent case in which $90m was successfully scammed after the French government defense minister was impersonated using a silicon mask on a web cam requesting a loan from people to pay a ransom. The use of video to conduct scams could prove to be especially effective during the COVID-19 pandemic. “The chances are people are more trusting of a conversation they are having over a Zoom call than they would over email,” observed Cluley.

Despite the growing threat phishing, ransomware and BEC attacks pose to home workers, Cluley believes there are reasons for positivity. “It hasn’t actually resulted in a surge in breaches,” said Cluley, noting that “an increase in attacks does not necessarily mean an increase in breaches.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#ISSE2020: ‘Real’ Digital Identity Can Exist with New Technology

#ISSE2020: ‘Real’ Digital Identity Can Exist with New Technology

Speaking as part of the virtual ISSE Conference, panelists discussed the concept of whether “real digital identity” can exist. Chaired by Heather Flanagan, principle at Spherical Cow Consulting, the panel proposed ways in which digital identities can exist, and what is required to make them work.

Pamela Dingle, director of identity standards at Microsoft, said businesses need to encourage sharing and collaboration in order to help employees get their job done, but two issues tend to stand in the way: friction and fraud. “We are told to not allow crime to occur and to make users successful, so how do we be successful and collaborate without causing chaos and devastating action?”

Dingle said that we are in a situation where fraud “is so brutal” that users are pushed into a position of friction, and “you cannot resist friction if you’re pulled into fraud.” She argued organizations can choose to give up everything and try new things, or try new things you’re not doing today and embrace where automation help you.

Kim Cameron, CIO of Convergence Technology, suggested the idea of a global identity concept, where the user owns their own identity and other “realms” connect into that. “Realms are not identity systems, but authentication systems,” he said.

“So my way of thinking on how to solve the problem is for a mechanism for people to have their own identity and realms should recognize them, and you don’t need to give them keys,” Cameron said.

“It should work to any realm, but not be a super cookie. It should allow services to recognize you, not correlate you.”

As for who provides this digital identity, Cameron said this “wallet” doesn’t contain any personally identifiable information, and is managed by your identity service provider, as the wallet manages your universal identity. “The idea is the wallet can live on mobile device and also live in cloud.”

Calling this “something optimistic and within our reach,” he said the common issue is that businesses mix new concepts with “old technology stacks” and that doesn’t solve the problems.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Employees Have Access to an Average of 10 Million Files

Employees Have Access to an Average of 10 Million Files

The average employee has access to around 10.8 million files, with larger organizations having around 20 million files accessible.

According to new research by Varonis, 64% of financial services organizations have more than 1000 sensitive files open to every employee. “Securely transitioning to remote work and locking down exposed data to mitigate the risk of remote logins were two of the highest security priorities for IT teams in financial services,” Varonis said.

“Mobilizing without proper security controls exponentially increases the risk posed by insiders, malware and ransomware attacks, and opens companies up to possible non-compliance with regulations such as SOX, GDPR and PCI.”

Inside financial services, the average number of folders open to all access is 1.3 million in large organizations, although this drops to 778,045 in medium organizations and 101,717 in small firms.

Brandon Hoffman, CISO at Netenrich, said restricting access to sensitive data is a foundational security step, but unfortunately, many organizations don’t do it.

He said: “They don’t because there are a few steps you need to take to ensure it is actually restricted. These steps can be daunting but they are critical to success in cyber. First, you need to classify all the data in the business and determine prioritization relative to risk. You then need to ensure that identity of users is organized and limited. The third, and most crucial step, is to put controls in place that limit access to and manipulation of high priority data by specific users. This does not only solve the challenge of users stealing or mishandling data, but will drive efficiency and security in several other areas.

“It does not come as a surprise then to find out that this is not being done as we continue to see the leakage/breach of personal data year-over-year.”

Heather Paunet, senior vice-president at Untangle, told Infosecurity she found it surprising that so many employees, especially at content-sensitive workplaces such as financial institutions, continue to have a depth of access to millions of files.

“To streamline network access, safeguard files and address vulnerable access points within the network, businesses and IT leaders should establish a set of criteria during any employee onboarding process in relation to their network access,” she said.

“Defining which positions have access to specific information creates layers of access that are not easily broken. For example, a marketing team member should not have the same access to employee information as an HR manager, and neither should have the same access as a member of the finance team dealing with sensitive business information.”

She recommended routinely auditing this access, especially in times of high turnover or during a large-scale transition to working from home, to allow IT teams to address any unauthorized access points or redefine access policies as needed.

“If employees should need additional access to systems or data, formal requests can be made, creating a procedure for opening access to specific employees for an approved amount of time,” Paunet said. 

“Hopefully, businesses now understand that it takes a single access point to wreak havoc on an entire network, and minimizing these access points is one of the best ways to compliment any network security solution in place.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#ISSE2020: Look to Decentralized (Rather than Legacy) Identity Approvals

#ISSE2020: Look to Decentralized (Rather than Legacy) Identity Approvals

A robust onboarding system that works for users and businesses should be built, as current systems “struggle to know who users are” which leads to frustration.

Speaking as part of the virtual ISSE Conference, John Erik Setsaas, VP identity and innovation at Signicat, said the infrastructure “we thought we had” takes longer and longer to work, and “we don’t want to bequeath to our children an identity onboarding system.” He argued there is a need for a robust onboarding system that knows the people that need to be involved in the system.

“We have had the same problem for the last 20 years, it [an identity system] struggles to know who you are,” he said, citing an example of how hard it was to access a bank from a different country due to the required levels of authentication.

Displaying survey results, Setsaas said 41% of respondents were unable to access financial services during the COVID-19 pandemic, and 63% had abandoned onboarding in financial services.

Showing other statistics, just over 10% of respondents abandoned onboarding due to “confusing language,” between 15-20% abandoned due to it taking too long and requiring too much personal information, and just over 20% left as they “changed their mind.”

He said: “Most people say it is a difficult process, but we need to think like the new generation.”

David Rihak, digital identity director, ADUCID, asked if the issue of identity is “even solvable,” as if it is not, “what are we doing wrong?”

He claimed that applications expect us to create an identity, and that has been accepted by society, so when looking at secure identity, we need to look at it from point of secure recovery. “We need to work with cryptography, as that is how the internet works, and how to bind it to users and scenarios where needed,” he said.

Katryna Dow, CEO, Meeco, discussed “decentralized identity,” as it is more important to think about the customer and their role than to think about any sort of technology, and she advised  to not “get hung up on what flavor” of technology you are using.

She said identity and access management technology had evolved, but decentralized identity “is often seen as a fad or not catching on.” However, she said there is more confidence in how to marry existing infrastructure with new capabilities, and that is where decentralized can be an enabler “as it allows ecosystems to form without the need for tight integration.”

She concluded that technology and emerging standards can help with trust and onboarding, and these additional tools “represent a way to bring these together in a way where everyone wins.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk