#SecTorCa: Defining the Security Metrics that Matter

#SecTorCa: Defining the Security Metrics that Matter

According to security trainer Tanya Janca, not all metrics actually matter for cybersecurity and there are some that can have significantly more impact than others.

Janca, the founder of training firm We Hack Purple, detailed her views on metrics during a session at the virtual SecTor security conference.

She began by stating that most people simply define metrics as a method of measuring something. The reality though is that there is more to metrics than just measurement. When done properly, metrics provide a way to spot patterns and trends that can help improve cybersecurity outcomes.

“We measure things and gather metrics specifically so that we can report and so that we can improve,” she said. “We report up to management and other teams on what we’re up to and then we use metrics so that we can improve ourselves.”

Why Reports Matter

As cybersecurity professionals, Janca said that generating reports for management is critical for a number of reasons. Reports are used to help get budget for tools and are typically also necessary for regulatory compliance. She added that reports also make management happy.

“If you don’t write reports, your boss doesn’t know what you’re doing,” Janca added. “You can’t have a security program that costs hundreds of thousands or millions of dollars and then not tell them [management] how you’re doing, that’s not going to go on for very long.”

However, while it’s important to keep management informed with reports, it’s equally important to have useful metrics that are tracked, Janca said. For example, some companies will count the number of vulnerabilities they have as a metric. She doesn’t see counting vulnerabilities as anything more than a “vanity metric” as it’s not particularly helpful. Having more software vulnerabilities could just mean that the organization has done a better job of testing and not that the organization is any more, or less, secure.

Metrics that Matter

Among the metrics that Janca does see as having meaning for cybersecurity professionals and the organizations that employ them is time to detection for a given security issue or vulnerability. Equally important is time to remediation of the issue as it’s critical to understand what the capabilities of the organizations are for fixing or patching a given issue.

Looking at vulnerabilities, understanding if the organization is detecting the same vulnerabilities time and again, or if it is finding different new vulnerabilities, is also important to measure. It’s also important to identify if there is a decline, or a rise, in a particular type of vulnerability. By identifying trends in vulnerabilities as opposed to just generically counting them, it’s possible to target categories of issues for training to help reduce them over time.

When looking at measuring the impact of an incident Janca said that it’s important to identify if established best practices were followed or not and if the various teams within the company worked together.

“If we aren’t measuring, we don’t know where to start,” she concluded.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Researcher Guesses Password to Access Trump Twitter Account

Researcher Guesses Password to Access Trump Twitter Account

A security researcher claims to have been able to access Donald Trump’s Twitter account after guessing his password.

Victor Gevers, a researcher at the non-profit GDI Foundation and chair of the Dutch Institute for Vulnerability Disclosure, revealed his findings on the social media site.

He posted the following, referencing an incident four years ago when the same thing happened:

“Dear @realDonaldTrump, I’ve tried to notify multiple times because of your passwords for Twitter are too weak. Last Friday, I contacted @CISAgov, @TeamTrump, @WhiteHouse, @DonaldJTrumpJr, and @twittersecurity, just like in Oct 2016. But no one responds. Please keep 2FA enabled!”

Back in 2016, Gevers and two others managed to access Trump’s account after guessing the password, “yourefired.” This time he claims it was “maga2020!” with no two-factor authentication enabled.

Although a Twitter spokesperson said it had “seen no evidence to corroborate this claim” and that it “proactively implemented account security measures for a designated group of high-profile, election-related Twitter accounts in the United States,” an article in Dutch paper De Volksrant, says different.

According to the report, Gevers took screenshots to document his steps, which included four failed attempts before he hit upon the magic password. Although he reached out to the Twitter accounts listed above, none replied.

However, the next day, Gevers noticed two-factor authentication had been activated on the account and two days after that he reportedly received an email from the Secret Service requesting more info on the account takeover and thanking him for highlighting the security snafu.

“Given the President’s near-constant activity on Twitter, his 87 million followers and the sheer power that he holds as the leader of the free world, Trump’s ‘maga2020!’ password is incomprehensibly dangerous,” argued ProPrivacy researcher, Andreas Theodorou.

“In fact, any other year I would be inclined to believe that this was fake news.”

Earlier this week, Trump drew ridicule from the cybersecurity community with comments he made at a rally in Arizona.

“Nobody gets hacked. To get hacked you need somebody with 197 IQ and he needs about 15% of your password,” he claimed.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#COVID19 Vaccine-Maker Shuts Global Plants After Cyber-Attack

#COVID19 Vaccine-Maker Shuts Global Plants After Cyber-Attack

An Indian pharmaceutical giant has been forced to shut operations at several global facilities after suffering an unspecified cyber-attack.

Dr Reddy’s, which produces COVID-19 treatments remdesivir and favipiravir and has just signed a deal to manufacture Russia’s Sputnik-V vaccine, saw shares plummet by over 4% following the announcement.

A statement from CIO Mukesh Rathi sought to calm investors after the news was first reported on Indian channel ET Now.

“We are anticipating all services to be up within 24 hours and we do not foresee any major impact on our operations due to this incident,” he reportedly said in a statement.

There’s little publicly available information on the attack, except that the pharma giant has been forced to “isolate” all of its data centers and shut down plants in the United States, UK, Brazil, India and Russia.

It’s therefore unclear whether the intent of the attackers was to spread ransomware, steal data, or both.

Bill Conner, UK government advisor and CEO of SonicWall, argued that research and pharmaceutical facilities are home to some of the most valuable IP in the world today.

“If seized, it could grant a significant advantage to the party who holds it, and indeed catapult a whole economy,” he added. “Given this, whoever holds this research can claim a high price for it. Hostile actors who wish to influence or control global healthcare at this time of great need, to gain either monetary or geopolitical advantage, will be willing to pay this bounty.”

The Hyderabad-headquartered firm, which also produces medicines for the NHS, announced last week that it had received approval from the Drugs Controller General of India to begin an adaptive phase 2/3 human clinical trial for Sputnik-V in India.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

#SecTorCa: A Hacker’s Perspective on Your Infrastructure

#SecTorCa: A Hacker’s Perspective on Your Infrastructure

Being aware of potential risks can help organizations to mitigate those risks, but first they really need to understand what hackers are looking at. That’s the view of IT security auditor Paula Januszkiewicz, founder of CQURE.

Januszkiewicz delivered her message during a keynote session at the virtual SecTor security conference. Januszkiewicz noted that during the pandemic there has been an increase in cybersecurity attacks as attackers aim to exploit weaknesses for their own benefit. In her view, defenders should take a hacker viewpoint to gain better situational awareness.

“So awareness means we know what’s going on with cybersecurity, we know, different cases and examples, and we are educated in cybersecurity,” Januszkiewicz said.

Hacker Confidence

To help highlight what awareness means from her perspective, she gave an example of how she was able to get into a company that she was doing a penetration test for in Switzerland.

Simply by following an authorized employee into the building then making small talk with another in an elevator, she was able to gain access to an employee area. When employees were out at lunch, she found her way to a desktop that was unlocked and inserted a digispark USB device to steal information.

“That is the beauty of social engineering; people expect that, when you do things with confidence, they are the things that you were supposed to be doing,” she said.

Seven Security Issues That Shouldnt Happen

In Januszkiewicz’s view there are seven key security issues that defenders need to be aware of, that hackers love to exploit.

The first issue is weak passwords. She noted that in one case her company was conducting an audit of an oil and gas company and executed a password spraying attack. She explained that her firm simply took a list of the company’s 6000 employees and attempted to access user accounts with the employees’ name as the username and a password of {CompanyName}2020. She was able to access 29 accounts with that method.

The second key issue she identified as “Peeping ROM,” which is where workers are able to sneak a peak at a co-worker or stranger’s workstation in the workplace or in a public place. She suggested that organizations have a policy for locking desktops, so when an employee is not active, the desktop is locked. The third key issue she called “USB Stick Up,” which is when victims pick up a random USB stick and plug it into their system to see what’s on it. That’s an activity that can lead to exploitation.

Januszkiewicz said that there are a lot of phishing messages today that get past spam filters which leads to the fourth key issue that she called “Phish Biting.” The unfortunate reality is that untrained users still click on phishing emails, especially when they get past spam filters. “Reckless Abandon” is the fifth issue, which is when users simply do not take basic precautions to secure their devices, such as not putting a passcode on a smartphone.

Using someone else’s Wi-Fi connection is also a bad practice that Januszkiewicz advocated against, as an attacker can potentially see all your traffic. The last key issue that she discussed was being too social. Some people have a tendency to share too much information on social media. The hacker perspective on that is that it can provide information that might be useful to help exploit the user.

“We had a case where there was a guy on LinkedIn from a certain company, and he liked Tesla cars, and for one of his personal emails he was using, there was a recovery question of what’s your favorite car and we typed in Tesla,” Januszkiewicz recounted. “That worked and that was so much fun because this information was super easy to find.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk