Shyam's Slide Share Presentations

VIRTUAL LIBRARY "KNOWLEDGE - KORRIDOR"

This article/post is from a third party website. The views expressed are that of the author. We at Capacity Building & Development may not necessarily subscribe to it completely. The relevance & applicability of the content is limited to certain geographic zones.It is not universal.

TO VIEW MORE CONTENT ON THIS SUBJECT AND OTHER TOPICS, Please visit KNOWLEDGE-KORRIDOR our Virtual Library

Showing posts with label Ransomeware. Show all posts
Showing posts with label Ransomeware. Show all posts

Wednesday, August 9, 2017

Cybersecurity and cybersecurity professionals 08-10





From Bitcoin and Blockchain to hacks and ransomware, security is a hot topic in tech. According to a recent Cybersecurity Ventures Report, the cost of cybercrime damage is predicted to reach $6 trillion by 2021, and global spending on cybersecurity products and services for defending against cyber crime is projected to exceed $1 trillion by 2021. With that much at stake, the business world certainly has security on their minds.

It’s critical for technology marketers to stay on the pulse of today’s trends – and what better way to do so than by following influential peers on LinkedIn? To learn from today’s best writers, content curators, and opinion leaders on all things security, look no further.

Below, we’re showcasing five professionals providing a helpful portal into the world of security – those that can keep you — and your organization — in the know!

Bill Brenner, Infosec Scribe at Sophos

Bill has been on a number of “top tech” lists, and for good reason. He is active in the LinkedIn security community and focused on sharing real-time info about the current state of the industry. Following him ensures that you’ll be alerted about recent ransomware attacks – and fed great articles on how to combat it.

One of Bill’s recent posts shared an angle not often seen, talking about his own “Rockstar” status in the security world and how it caused his content and point of view to become stale. When an influencer takes time to step back and assess his or her influence and POV, it’s anything but stale; Bill is a breath of fresh air in an oftentimes cluttered conversation.

Tech marketer takeaway: If you think you’ve learned everything about a particular topic or industry, you’re probably wrong. As Bill put it, “Never stop seeking truth.” Your customers and prospects will thank you for this – it’s never fun talking to a person or company who thinks they have all the answers. Keep an open mind when it comes to new content, ideas and perspectives, and you’ll be a much better marketer for it!

Maya Schirmann, CMO at Deep Instinct

Maya is a great go-to connection when it comes to security marketing. Her company, Deep Instinct, is “the first company to apply deep learning to cybersecurity” and she also takes a “deep learning” approach to her own content. Tech marketers can benefit from her great approach to discussing security. As data breaches and hacks are in the headlines more often than not these days, Maya shares frequent helpful updates, podcasts and go-to lists on the all of the latest cybersecurity news. She also covers a number of insightful topics  in her published posts such as weak password management, “hacking highlights” and an Oscar-themed awards post containing actionable security advice for organizations both large and small.

Tech marketer takeaway: Creatively tying your topic of choice to current events and impactful discussions is a great way to get noticed – and it’ll pique the interest of potential customers. Tying content into interesting trends and current events is an effective way to set your content apart.

Steve Morgan, Founder & Editor-In-Chief, Cybersecurity Ventures

Steve is a veritable fountain of security info – he’s written dozens of reports on cybercrime, cybersecurity products and services, and launched the “Cybersecurity 500” list of the hottest cybersecurity companies to watch each year. He shares updates on cybersecurity employment, defense firms, hacks and data breaches – and how companies can be proactively preparing for their IT security futures. Many of his shared posts are helpful because they are so proactive – they often include step-by-step instructions for companies looking to boost their cybersecurity efforts, where to best spend their security budgets and what risks they should be most aware of and on the lookout for. Steve doesn’t just want companies to be in the know – he wants them to do something about it!

Tech marketer takeaway: Simply knowing about the current trends and buzzwords in an industry isn’t enough. To be truly effective as a security marketer, you must provide actionable insights to your customers and prospects. Everyone knows that cyberattacks can and will hit: but are you contributing to the conversation and equipping people who are preparing for the worst?

Yotam Gutman, VP Marketing at CyberDB

Yotam not only frequently posts interesting cybersecurity trends, he actively wants to engage and have meaningful discussions with his LinkedIn audience of almost 15,000 followers. He takes cybersecurity incredibly seriously and shares intricate, detailed data – but he also doesn’t shy away from sharing a fun story or video with his followers now and then. Yotam often attends IT security events around the world and takes the time to share what he’s learned –  reminding his followers and their companies that amongst the hustle and hype around cybersecurity, it’s important to define who you are and have a definitive brand for your organization.

Tech marketer takeaway: You don’t have to be a technical expert in all things security to come at this topic from a new angle and appeal to your tech buyers with your insights. Tech professionals want to be part of an active community that both gives out relevant info and engages in a more meaningful way (and events are a great way to do this). It’s all about the conversation!

Bob Carver, Manager of Network Security, Verizon

Bob knows his stuff when it comes to risk management, cyber resiliency and strategy, incident management and threat intelligence – he’s monitored tens of thousands of infected endpoints at Verizon, at one point overseeing the company’s Security Incident Response team. Follow Bob for a more in-depth take on many IT security conversations, from Botnet monitoring and cryptocurrency to the NSA. Bob’s content comes from the fact that he’s most likely “seen it all” throughout his career – and he wants to put that in-depth knowledge to good use for companies around the globe looking to proactively fight cyberattacks.

Tech marketer takeaway: A little technical in-depth info goes a long way. It might take some serious time and a lot of research to truly understand complex security topics that your customers care about – but it’s worth the hassle in the end.

As security is becoming more and more of a priority for many in the tech industry, it’s important to stay abreast of the latest security trends and innovations. These security leaders are invaluable within the LinkedIn technology community, and each showcases the true power of the LinkedIn network: that anyone can both access and participate in greater industry discussions across the globe. It’s time to take what we learn from them and put it into action!

Monday, July 10, 2017

Finding a strategic cybersecurity model 07-10


Cybersecurity has become an 'Inevitable Essential' for the organisations operating in the cyberspace. However to what degree it needs to used or to what degree it needs to be scaled up is a strategic question that needs to be addressed.

The customised cybersecurity model required for every business is different  in scale and intensity and has to be addressed by the cybersecurity experts.

Image credit: Shyam's Imagination Library

Protecting critical and sensitive information is of paramount importance in business and government, but plans must be in place to handle inevitable breaches too.
          
Cybersecurity has become one of the biggest priorities for businesses and governments, as practically all of life migrates its way to data centers and the cloud. In this episode of the McKinsey Podcast, recorded at the Yale Cyber Leadership Forum in March, Sam Palmisano, chairman of the Center for Global Enterprise and the retired chairman and CEO of IBM, and Nathaniel Gleicher, head of cybersecurity strategy at data-and-cloud-security company Illumio, speak with McKinsey about how governments and companies can vastly improve their cyberprotections.

Podcast transcript 

Roberta Fusaro: Cybersecurity has become one of the biggest priorities for businesses and governments, as practically all of life migrates its way to data centers and the cloud. In this episode of the McKinsey Podcast, recorded at the Yale Cyber Leadership Forum in March, we catch up with two leading thinkers on security issues. Sam Palmisano is the retired chairman and CEO of IBM, who served as vice chair of the US Commission on Enhancing National Cybersecurity. Nathaniel Gleicher is the head of cybersecurity strategy at Illumio, a data and cloud security company.

First up from the forum is Sam Palmisano, who, in this wide-ranging conversation with McKinsey’s Marc Sorel, makes the case that strong cybersecurity programs are critical for improved innovation and economic growth.

Sam, thank you for joining us today. I want to talk a little bit about your work on the Commission on Enhancing National Cybersecurity. What was the original mandate?

What was the process by which you came up with your findings? And what were some of the most surprising results?

Sam Palmisano: Thank you, Roberta. The thing was that President Obama had reached the conclusion that the digital economy or the Internet is so fundamental now to economic growth and society that something needed to be done to make some recommendations to enhance it or strategically position it for the future.

A great example is the Internet of Things, because it’s no longer just phones and desktop computers. It’s everything in life. It’s self-driving cars, it’s thermostats, it’s music players, it’s cameras.

Now you take this infrastructure and you’re making billions of things that are computers, which are smart devices. But that’s what they are, they’re chips with software with all the vulnerabilities, unless you design for security from the beginning. And you’ve taken this problem and you’ve put it on steroids.

The complexity there is one of getting consensus to go fast and address the issues prior to billions of things being out there that aren’t secure, which is the path we’re headed down.

Marc Sorel: How do you think about what the private sector, and to some extent the social sector, need to do now to be part of that?

Sam Palmisano: We need to form a private-public collaboration. The reason for it, the government doesn’t have the skills to do this themselves. We spent nine months crawling through their statements of skill. They can argue all they want. They don’t. That doesn’t mean that elements of government don’t have some skill. To take the intelligence agencies out of this discussion and get to that commercial side, it doesn’t have the capability. They need the capability, so they had to form a partnership. The skills exist in the academic community and in the research universities and in the technology community.

Marc Sorel: Did you all as a commission see a model in the market today for what that collaboration could look like?

Sam Palmisano: There are established entities within government that are a combination of academic, private sector, government, and technical. A lot of the technical communities come together.

General Keith Alexander ran the Cyber Command Center. There were probably 20 of us that met once a quarter for five, six years. The same guys that were running IBM, Google, Dell, Microsoft, HP, and Verizon, plus all the government appropriate people would meet quarterly. The technical people would meet even more often to tackle some of these issues, and it was self-funding. We solved problems just by pitching in because it was in the best interest of everyone to solve some of these issues, and in the best interest of the industry because you wanted to expand and grow.

To really do this, though, this was going to require funding, To solve the problem we’re talking about, it’s going to require some amount of money and research, like a DARPA or related fund, pick something like that as the funding source that government can coordinate, and then convene this body. Then do the work as we suggest. Now, the work is going to get complicated. Because there’s two pieces to it. One is, let’s say for example, to come up with a standard for the Internet of Things that you would put in this device, this object. Then within that object, you’d have this standard. Then you’d also have a nutrition label on the standard. We called it the Cyber Star. It’s like the health seal that says, “OK, if you’re the manufacturer and you’ve complied with these standards, you get the star.” You get the Cyber Star.

There were also guys that recommended a thing called secure, they call it clean pipes. With clean pipes, there are a lot of policy implications, a lot of criminal-justice-systems implications. But technically, you could create a clean path and you could have a secure path, and you could argue for certain areas where life is threatened.

In the autonomous vehicles or drones or things where people could actually be seriously injured or die, you’d want a secure, clean path. You don’t want this on the open Internet.

Marc Sorel: So you’re talking about creating a separate secure environment for these privileged parts of the ecosystem.

Sam Palmisano: Right. Think of it as a commercial virtual private network but beyond that. Put that on steroids from an encryption and security perspective. For all these Internet of Things devices. Health, heart monitor, things you’re putting in your body. Pacemakers, et cetera. Defibrillators. Those kinds of things. Not Fitbits that you wear on your wrist, but serious things that could do serious harm like stop your heart. You want to have that information flowing in a secure way. In an encrypted, secure way. That doesn’t mean everything should be that. If you’re sharing your photos with friends, I don’t think you need that level or cost associated with those kinds of technologies.

Marc Sorel: You’re basically saying at some level, there should be a tiering of Internets to acknowledge the degree of security required for different pieces of the ecosystem to communicate.

Sam Palmisano: That is a solution to the problem. Now you have to make it commercially viable, which gets you into things like net neutrality. But if you were to technically solve the problem, you would begin to architect portions of the Internet. You can’t go recreate the past. It’s just too old, it’s too cobbled together. Let that be what it is.

But anything that’s life-threatening or takes down the infrastructure or the world economy. Let’s just start there. The premise or the assumption is that you can’t solve this in the Internet as it exists today. It just was too complicated. It’s too convoluted. It’s too open by design. That’s why it was so successful, because it was an open architecture. We had all these debates, all of the technical guys. And said, “Look. We used to do this 40 years ago.” ATMs never got hacked. Money didn’t start spitting out on the curb and stuff because it was a secure connection. It was, it was a proprietary network. We know how to do it technically.

But there are people that did these things for years. We’ve moved onto an open innovative system which is terrific because it drives innovation at a much more rapid pace. It also gives people more economic opportunity to participate. That’s a big plus. But in certain areas where you’re dealing with, let’s say, major societal issues, we ought to go back to some of the classical approaches to how you design the systems.

Roberta Fusaro: Most people today would say, “If I had to place a bet on who’s going to gain ground on whom and put space between themselves, it’s the attackers that are going to continue to distance themselves in terms of capability from the defenders in terms of their capabilities.” Do you agree with that?

Sam Palmisano: Eighty percent of the cybersecurity issues that have occurred in the commercial world are internal process and people. It’s not the disgruntled employees who got fired and therefore they gave somebody their access codes. It’s also people who didn’t protect their access codes or they tape it to their computer. Or they leave it in the top drawer of their desk, and the cleaning people can go get the stuff. You would get rid of half of your problems as an enterprise if you just train your folks and put controls in place.

It’s a combination of monitoring, process training, audit people. Did you follow the process? So there’s an accountability in the system. That’ll clean up a lot of the stuff in the commercial world. Password authentication and end points. If the civilian side of government, .gov, did those things, they would clean up probably 95 percent of their problems and save a ton of money, too.

We also talked about this idea, which never got traction in the commission report, but we thought it was a good idea where you basically would create a national ID like a credit bureau. You could create this national ID foundry where you get your birth certificate. You also get your digital identity at birth, and that digital identity is secure and protected. Now, you can modify for simple things—sharing your photos on the Internet—or you can modify it for very sophisticated things like financial transactions, your health information.

Marc Sorel: Why didn’t it catch on?

Sam Palmisano: In the commission itself?

Marc Sorel: Yeah.

Sam Palmisano: What we did was said, further studies should take place, and we recommended that Treasury would look at, further look at creating this kind of an entity. We also looked at commercial insurance as well, and the purpose of commercial insurance.

The purpose of commercial insurance was that if you agreed on the standards, and therefore you complied with those standards, you should be able to get higher liability coverage at a lower rate than somebody who didn’t.

Our view was that would drive up the adoption rate because people are going to want to find an insurance policy for cyber. That’s going to happen. How do you get these companies to make the investments to move up the risk-protection curve? Well, you make it to their advantage by having insurance that says, “We could audit those standards. And if you’ve complied with those standards, like burglar alarm systems or fire alarms in your home, you’re going to get higher liability coverage at a lower rate.” That’s to make it an economic-based system versus a government-mandated system.

The commission was very biased toward private-sector solutions versus government-mandated solutions. You need a private sector or an economically driven set of motivations to solve the problem.

Roberta Fusaro: This has been a fascinating conversation. Thank you, Sam, for taking the time to be with us today.

Sam Palmisano: Oh, thank you. It was great being with you.

Next up from the Forum, is Nathaniel Gleicher, who describes how businesses can learn a lot from the model of protection used by the US Secret Service.

Roberta Fusaro: Welcome, Nathaniel. Thank you for joining us today for the McKinsey Podcast.

Nathaniel Gleicher: No problem. Glad that I could join.

Roberta Fusaro: Your company has been providing cyber options for four or five years now, and I’m wondering how you’ve seen the market change over that time in terms of what customers are looking for or technologies that have emerged.

Nathaniel Gleicher: There used to be a perception that cybersecurity was black magic, particularly outside of the technical community, and that outside of that community, people would sort of say, “I don’t understand this. Just make it work.” As long as you don’t hear anything, no news is good news. The increasing scope and scale of breaches and the degree to which organizations are moving into these exposed environments has changed that. If you look at business leaders, I think they are focused on how do you quantify the risks that you face, and how do you measure the benefit that you’re getting from the solutions you invest in? It’s a much more quantification-driven industry than it used to be. I don’t know that we’re very good at quantification yet. But the desire to quantify is an important change.

Roberta Fusaro: Apart from quantification, are there other hot topics in cyber that you’re seeing or managing right now?

Nathaniel Gleicher: Sometimes I think we do cybersecurity like fourth graders play soccer. Chase the ball across the field, the whole group runs. There are always hot topics. What’s interesting to me is that we’ve known for a while there are a few steps that if you took them, environments would be much more secure.

If you think about encrypting data, using strong passwords, white-listing your applications, segmenting your environment, patching your vulnerabilities, and people generally haven’t done that because it’s been hard to figure out how to do that at scale across these large organizations.

One of the biggest challenges that we face in cybersecurity today is that we don’t really have a single, coherent strategic model to describe how to protect an environment. There are a lot of tactical models, so if you look at the SANS top 20, if you look at NIST, if you look at some of these other frameworks, they will tell you, you should be investing in encryption. You should be investing in segmentation. You should be investing in certain kinds of detection. They’ll tell you all the tools you should use and you can think about how to line them up, but it’s very tactical. It’s hard to find a model that lets you pull back and think about the threat as a whole.

I’m starting to see groups of companies trying to solve that problem, trying to think, how do you do these steps that don’t seem all that sexy, but that actually drive to security.

Roberta Fusaro: What are some of the potential remedies?

Nathaniel Gleicher: If you look at security disciplines through the ages, whether it’s law enforcement, executive protection, physical security for locations, military security, any of these sort of well-built disciplines, the foundation of every security discipline is understanding the environment you’re protecting and exerting control over that environment.

In cybersecurity, we are not good at understanding the environment we’re defending. Most organizations don’t understand the network. They don’t understand what’s connected and what’s communicating with what. Because of that, they have relatively few options to control that environment. I mentioned before a few simple things people could do to strengthen their environment. Those are all about control, and what I mean by control, people often think there’s prevention, keeping the bad guys out, and then there’s detection and response, catching them once they get in.

Those are both important components. In general today, people would tell you, you can’t invest all in one or the other, that prevention by itself isn’t enough. People are going to get in. What people miss in that debate is the reason detection and response works is because you understand your environment, and you control it.

If you don’t know where your high-value assets are, and if you don’t know what connects to them, how someone would access them, it’s incredibly hard to know what you need to protect. If you don’t have the resources to control that, you’re defending an open field. So you have hundreds and hundreds of paths you need to defend, potential connections you need to worry about, and the attacker gets to move first. On the flip side, if you invest to understand your environment first, and control your environment first, it actually makes detection and response better.

Roberta Fusaro: What are some ways to identify the crown jewels, the things that really do matter? I can imagine that that could be an incredibly difficult task, given all the assets that companies manage.

Nathaniel Gleicher: It’s different for every organization, to some degree, but it’s about understanding business risk. The question is, what are the assets that I defend, or that my business relies on, such that if they were exposed or compromised, it would fundamentally harm the way I do business?

Whether that’s health care data about your customers, or customer information, whether that’s the systems on which your business runs, whether that’s the exchanges across which you connect, every business has a different set of factors they need to judge. But often, if you think in terms of business risk, we’re pretty good at figuring that out because businesses have been measuring and concerned about risk for quite some time. It’s just a question of translating that and understanding the technical implications.

A model that I like to use when I think about this is the way the Secret Service protects the president. The president is a lot like a high-value asset in a data center, in that he’s very valuable, very targeted, and also very exposed. The Secret Service doesn’t get to take the president, put him in a box somewhere, and have him not talk to anyone. He’s constantly talking to people, so the job is really about managing risk, which is similar to the way we’re protecting assets in the data center.

When the Secret Service is protecting the president, if you imagine the president speaking in an auditorium, the Secret Service shows up months before the president is going to be there. The first thing they do is they map the auditorium to understand that if the president’s going to be here, speaking on this stage, here are all the attack vectors.

Here are all the ways someone could reach the president. An auditorium is built for openness, so there are going to be a lot. The Secret Service tries to control that environment, to shrink the number of attack vectors. The reason they do this is, as we said before, if you have to watch a hundred attack vectors, it’s really expensive, and you’re really spread out thin. If you have to watch 20, you’re in much better shape as a defender. So you can say we don’t leave this doorway open, and no one’s going to sit in this portion of the auditorium. You can close things down to simplify your environment. That’s important for a lot of reasons, but the biggest reason is it makes detection much easier.

If there’s a section of the auditorium where no one is supposed to sit, that doesn’t necessarily mean no one will show up there. People always do strange things. But if someone does, you know they’ve broken a policy. It’s not a false positive. There’s no risk of confusion. You can simply react, and it lets the Secret Service act much more quickly because rather than basing their actions on uncertain analysis, they’re basing it, they create firm boundaries. When someone breaks a boundary, they know what to do. If the Secret Service wanted to, they have a lot of resources, they could put a metal detector at every seat in the auditorium.

They could put one at every single seat. They could get the best metal detector in the world. The problem is, they would never do that. They would get thousands and thousands of alerts and lots of them would be because someone had a particularly heavy watch on, or had change in their pocket. Whatever it might be. In order to test those alerts, they would have to send Secret Service agents out into the auditorium to check each one. And Secret Service agents are really expensive, and they’re rare. It takes a long time to train them. They’re hard to find. What you really want to do, is take your precious resource, your Secret Service agents, and you want to direct them at the hardest, smallest slice of the problem.

So take that and apply it to the data center. If you are detecting everything everywhere, and you don’t have control over the environment, you’re going to get a lot of alerts. The statistics we see right now back that up. Organizations get 500, 1,000 critical alerts a day, which is a huge number of alerts that supposedly you have to deal with.

On average, organizations say they have the capacity to investigate something like 1 percent of them. So you’re investigating 1 percent of all these critical alerts. Quickly you start to turn things off because that data is dirty. If you’re following the model, you would do the same thing the Secret Service does. You don’t put a metal detector everywhere.

What you do is you control the environment. You limit the places people can be, the paths they can take, so you know where to watch. So you know if this is my high-value asset in my data center, then if anything strange happens there, obviously it should be my highest priority. If anything strange happens in something connected to it that might be a secondary priority. You can start to prioritize these alerts and focus on the problems that matter more.

Roberta Fusaro: What are some of the policies or regulations that are emerging that business executives need to concern themselves with?

Nathaniel Gleicher: In a lot of ways, 2017 will be a year of regulation in cybersecurity. Not exactly the regulation people think about. I don’t know that it’ll come from DC. SWIFT, the financial-transactions organization, recently put out controls that all of its members need to comply with to segment and protect their SWIFT application.

This is in response to all the criminal activity targeting SWIFT applications. That’s one. The New York DFS, the financial regulator, put out controls around cybersecurity quite recently. The European Union recently put out a new general data-protection regulation, which has a whole range of controls built into it, but there are specific pieces around where is data stored, and how is it stored, which raise serious concerns for companies.

There are a lot of pieces coming out from different places, that depending on what industry you sit on, you need to watch. The pattern that I’m seeing, though, is each of these has components that require organizations to do a better job exerting control over the data in their possession.

Organizations have said, “My data just pools in all these places. I don’t even know where it is. It moves through these systems too fast for me to follow.” It has been acceptable for companies not to know answers to these technical questions. You’re seeing these regulations start to come out that push back on that. There’s this increasing requirement on organizations to understand what’s happening in those systems, and where that data’s going.

Roberta Fusaro: How might this increased oversight affect companies’ ability to innovate? So many new business models are data- and analytics-driven.

Nathaniel Gleicher: There’s this old apocryphal joke that if we built cars like we built computers, cars would go 500 miles an hour, get 500 miles a gallon, and blow up once a week. We’ve made this choice, historically, around computer and Internet innovation that the consequences of unreliability aren’t all that high.

We’d rather have rapid innovation, but what’s happening now is more and more you see the technical world, the Internet world, colliding or reconnecting with the physical world, whether it’s autonomous cars, whether it’s health innovation like you’re seeing, whether it’s integrating smart solutions into the home, whether it’s integrating smart solutions into our transportation framework.

There are more and more opportunities integrating technology and smart solutions into the financial systems that our society runs on. There are more and more opportunities for surprisingly small bugs to cause very big chain effects in the physical world. The push and pull that you’re seeing is how do you maintain the pace of innovation that has been so valuable, and such an engine of economic growth, an engine of competitive edge for us, while still mitigating the risks of all of these autonomous systems, and more and more sophisticated systems that are impacting the physical world.

Roberta Fusaro: What are the opportunities for VCs and start-ups in this changing environment?

Nathaniel Gleicher: There are huge opportunities in pointing artificial intelligence solutions and orchestration solutions at problems that are incredibly hard to do at scale for large organizations. We tend to think of cybersecurity as a technology solution because that’s convenient.

The truth is, it’s really an organizational solution. If you only have one computer, obviously anyone can make a computer secure by turning it off. But if you have one computer, if you have one system, a sophisticated defender is going to be much better able to protect that than if you have a thousand systems and hundreds of employees, or 10,000 systems, and hundreds or thousands of employees.

The challenge is getting large organizations to operate in a coherent fashion, when large organizations are made up of people, and we aren’t always good at operating in a coherent fashion. What organizations really need, and where there’s real potential, is how do you make it so those things we talked about at the beginning, encryption, strong passwords, segmentation, white-listing applications, patching vulnerabilities can be done reliably, consistently and at scale because if we can do that, we would solve a large chunk of our security problem.

Roberta Fusaro: Nathaniel, thank you so much for joining us today.

Nathaniel Gleicher: Thank you for having me.

About the author(s)

Nathaniel Gleicher is the head of cybersecurity strategy at Illumio, and Sam Palmisano is chairman of the Center for Global Enterprise and retired chairman and CEO of IBM. Roberta Fusaro is a senior editor of McKinsey Publishing, and Marc Sorel is a consultant in McKinsey’s Washington, DC, office.

View at the original source

Thursday, June 29, 2017

What you need to know about the Petya ransomware outbreak 06-29





A new strain of ransomware has appeared in multiple countries. On June 27, 2017, Petya ransomware emerged and began spreading itself to large organizations across Europe. This ransomware uses what is called the Eternal Blue exploit in Windows computers. It is not impacting individual users at the time of this writing.

What is Ransomware?

Ransomware generally presents users with an ultimatum: pay a fee to unlock and reclaim personal data, or don’t pay the fee and lose the data indefinitely. Ransomware is able to automatically corrupt and delete files in the event that monetary compensation is not received, leaving most users with little time to resolve the problem through alternate means.

How to deal with Ransomware:

  1. Do not pay the ransom. It only encourages and funds these attackers. Even if the ransom is paid, there is no guarantee that you will be able to regain access to your files.                                             
  2. Be sure you are backing up your data on a regular basis. If you do become a victim of a ransomware attack, you will be able to restore any impacted files from a known good backup. Restoration of your files from a backup is the fastest way to regain access to your data.                               
  3. Do not provide personal information when answering an email, unsolicited phone call, text message or instant message. Phishers will try to trick employees into installing malware, or gain intelligence for attacks by claiming to be from IT. Be sure to contact your IT department if you or your coworkers receive suspicious calls.                                                                                       
  4. Use reputable internet security software and a firewall. Maintaining a strong firewall and keeping your security software up to date are critical. It’s important to use antivirus software from a reputable company because of fake software out there.                                                                        
  5. Employ content scanning and filtering on your mail servers. Inbound e-mails should be scanned for known threats and should block any attachment types that could pose a threat.                           
  6. Make sure that all systems and software are up-to-date with relevant patches. Exploit kits hosted on compromised websites are commonly used to spread malware. Regular patching of vulnerable software is necessary to help prevent infection.                                                                                            
  7. If traveling, alert your IT department beforehand, especially if you’re going to be using public wireless Internet. Make sure you use a trustworthy Virtual Private Network (VPN) when accessing public Wi-Fi like Norton WiFi Privacy.
Symantec is continuing to analyze this threat and will post further information as soon as it becomes available.

This article is authored by an employee of Norton by Symantec.

View at the original source

Thursday, May 18, 2017

What you need to know about the WannaCry Ransomware 05-20


The WannaCry ransomware struck across the globe in May 2017. Learn how this ransomware attack spread and how to protect your network from similar attacks.

Symantec has uncovered two possible links that loosely tie the WannaCry ransomware attack and the Lazarus group:
  • Co-occurrence of known Lazarus tools and WannaCry ransomware: Symantec identified the presence of tools exclusively used by Lazarus on machines also infected with earlier versions of WannaCry. These earlier variants of WannaCry did not have the ability to spread via SMB. The Lazarus tools could potentially have been used as method of propagating WannaCry, but this is unconfirmed. 
  • Shared code: As tweeted by Google’s Neel Mehta, there is some shared code between known Lazarus tools and the WannaCry ransomware. Symantec has determined that this shared code is a form of SSL. This SSL implementation uses a specific sequence of 75 ciphers which to date have only been seen across Lazarus tools (including Contopee and Brambul) and WannaCry variants. 
While these findings do not indicate a definite link between Lazarus and WannaCry, we believe that there are sufficient connections to warrant further investigation. We will continue to share further details of our research as it unfolds. 
A virulent new strain of ransomware known as WannaCry (Ransom.Wannacry) has hit hundreds of thousands of computers worldwide since its emergence on Friday, May 12. WannaCry is far more dangerous than other common ransomware types because of its ability to spread itself across an organization’s network by exploiting a critical vulnerability in Windows computers, which was patched by Microsoft in March 2017 (MS17-010). The exploit, known as “Eternal Blue,” was released online in April in the latest of a series of leaks by a group known as the Shadow Brokers, who claimed that it had stolen the data from the Equation cyber espionage group.

Am I protected from the WannaCry ransomware?

Symantec Endpoint Protection (SEP) and Norton have proactively blocked any attempt to exploit the vulnerability used by WannaCry, meaning customers were fully protected before WannaCry first appeared.
The Blue Coat Global Intelligence Network (GIN) provides automatic detection to all enabled products for web-based infection attempts.
Symantec and Norton customers are automatically protected against WannaCry using a combination of technologies.
Proactive protection was provided by:
  • IPS network-based protection
  • SONAR behavior detection technology
  • Advanced Machine Learning
  • Intelligent Threat Cloud
Customers should have these technologies enabled for full proactive protection. SEP customers are advised to migrate to SEP 14 to take advantage of the proactive protection provided by Advanced Machine Learning signatures.

What is the WannaCry ransomware?

WannaCry searches for and encrypts 176 different file types and appends .WCRY to the end of the file name. It ask users to pay a US$300 ransom in bitcoins. The ransom note indicates that the payment amount will be doubled after three days. If payment is not made after seven days, the encrypted files will be deleted.

Can I recover the encrypted files or should I pay the ransom?

Decryption of encrypted files is not possible at present. If you have backup copies of affected files, you may be able to restore them. Symantec does not recommend paying the ransom.
In some cases, files may be recovered without backups. Files saved on the Desktop, My Documents, or on a removable drive are encrypted and their original copies are wiped. These are not recoverable. Files stored elsewhere on a computer are encrypted and their original copies are simply deleted. This means they could be recovered using an undelete tool.

When did WannaCry appear and how quickly did it spread?

WannaCry first appeared on Friday, May 12. Symantec saw a dramatic upsurge in the number of attempts to exploit the Windows vulnerability used by WannaCry from approximately 8:00 GMT onwards. The number of exploit attempts blocked by Symantec dropped slightly on Saturday and Sunday but remained quite high. Exploit numbers increased on Monday, presumably as people returned to work after the weekend.  




Figure 1. Number of exploit attempts blocked by Symantec of Windows vulnerability used by WannaCry per hour





Figure 2. Number of exploit attempts blocked by Symantec of Windows vulnerability used by WannaCry per day



Figure 3. Heatmap showing Symantec detections for WannaCry, May 11 to May 15 



Who is impacted?

Any unpatched Windows computer is potentially susceptible to WannaCry. Organizations are particularly at risk because of its ability to spread across networks and a number of organizations globally have been affected, the majority of which are in Europe. However individuals can also be affected.

Is this a targeted attack?

No, this is not believed to be a targeted attack at this time. Ransomware campaigns are typically indiscriminate.

Why is it causing so many problems for organizations?

WannaCry has the ability to spread itself within corporate networks without user interaction, by exploiting a known vulnerability in Microsoft Windows. Computers that do not have the latest Windows security updates applied are at risk of infection.

How is WannaCry spread?

While WannaCry can spread itself across an organization’s networks by exploiting a vulnerability, the initial means of infection—how the first computer in an organization is infected—remains unconfirmed. Symantec has seen some cases of WannaCry being hosted on malicious websites, but these appear to be copycat attacks, unrelated to the original attacks.

How does the ransom payment work?

The Wannacry attackers request that the ransom be paid using Bitcoins. Wannacry generates a unique Bitcoin wallet address for each infected computer, however due to a race condition bug this code does not execute correctly. Wannacry then defaults to three hardcoded Bitcoin addresses for payment. The attackers are unable to identify which victims have paid using the hardcoded addresses, meaning that victims are unlikely to get their files decrypted.
The Wannacry attackers subsequently released a new version of the malware that corrected this flaw, however this version was not as successful as the original.
Network-based protection
Symantec has the following IPS protection in place to block attempts to exploit the MS17-010 vulnerability:

What are the details on Symantec's protection?

SONAR behavior detection technology
Advanced Machine Learning
Antivirus
For expanded protection and identification purposes, the following Antivirus signatures have been updated:
Customers should run LiveUpdate and verify that they have the following definition versions or later installed in order to ensure they have the most up-to-date protection:
  • 20170512.009
The following IPS signature also blocks activity related to Ransom.Wannacry:

What are best practices for protecting against ransomware?

  • New ransomware variants appear on a regular basis. Always keep your security software up to date to protect yourself against them.
  • Keep your operating system and other software updated. Software updates will frequently include patches for newly discovered security vulnerabilities that could be exploited by ransomware attackers.
  • Email is one of the main infection methods. Be wary of unexpected emails especially if they contain links and/or attachments.
  • Be extremely wary of any Microsoft Office email attachment that advises you to enable macros to view its content. Unless you are absolutely sure that this is a genuine email from a trusted source, do not enable macros and instead immediately delete the email.
  • Backing up important data is the single most effective way of combating ransomware infection. Attackers have leverage over their victims by encrypting valuable files and leaving them inaccessible. If the victim has backup copies, they can restore their files once the infection has been cleaned up. However organizations should ensure that backups are appropriately protected or stored off-line so that attackers can’t delete them.
  • Using cloud services could help mitigate ransomware infection, since many retain previous versions of files, allowing you to roll back to the unencrypted form.  

Reproduced from Symantec Blog.