Showing posts with label DLP. Show all posts
Showing posts with label DLP. Show all posts

Tuesday, November 17, 2015

The Threat Within: 3 Out of 4 Companies Affected by Internal Information Security Incidents


Costly cyberattacks are now almost routine for businesses, but while many organizations are focusing on external attackers, it's important to also look at threats from within. According to the IT Security Risks Survey conducted by Kaspersky Lab and B2B International, 73% of companies have been affected by internal information security incidents. The survey also found that the largest single cause of confidential data losses is by employees (42%). Read more here.

Monday, October 26, 2015

10 Facts You Need to Know About Data Breaches

2014 was dubbed as "the year of the data breach." With many new data breaches dominating the headlines in 2015, including Anthem, the White House, banking attacks, and the latest employee data theft at the US federal government, one can only imagine what the name for 2015 will be: the year of even more data breaches? According to the Ponemon Institute, 43% of companies experienced a data breach in 2014. Not only is the number of data breaches rising, the number of records stolen per breach is increasing as well as the cost per stolen record. It is apparent that current security measures are not sufficient to protect organizations from data breaches. This article highlights the top 10 most interesting, remarkable and troubling facts about data breaches.

Thursday, September 10, 2015

Top 3 Factors Driving the Rise in Data Breaches



It comes as no surprise that the number of companies falling victim to data breaches is on the rise. These stories are making headlines, and making CEOs and employees alike nervous that they will be the next victim. As computers are getting faster, so are hacking attempts. Hackers are now more capable than ever to implement their plans. This article outlines the top three factors that are contributing to the rise of data breaches.

Tuesday, December 9, 2014

New Survey Shows Widespread Employee Access to Sensitive Files Puts Critical Data at Risk


It's been 18 months since Snowden demonstrated the inability of the Puzzle Palace to identify and mitigate internal threats. Now, a new survey from Varonis Systems and the Ponemon Institute suggests--not surprisingly--that most organizations are having difficulty balancing the need for improved security with employee productivity demands. Employees with needlessly excessive data access privileges represent a growing risk for organizations due to both accidental and conscious exposure of sensitive or critical data.

Friday, December 5, 2014

Varonis Perspective on the Sony Breach


This is an amazing story. It's all about not paying attention in Security 101. In the following unattributed analysis, Varonis adds detail and insight on this breach. 

FROM VARONIS:

While we have few details on the Sony Pictures attack itself, this very public breach—or pwning in hacker slang--has shown the extent of the actual exposure—it is massive. The always informative Krebs knows, at this point, as much as the rest of us—possible North Korean connection and perhaps the use of destructive erase-all malware. That’s not to say this incident hasn’t revealed significant insights about our collective data security practices: don’t think the Sony incident doesn’t apply to you!

Krebs provides a link to the sprawling Sony directory hierarchy. This should definitively settle any doubt about the scope of this thing.

There are a few points to make. 

Unlike the big-box retailer incidents, this breach is not, for the most part, about personally identifiable information or PII. Certainly, there are employee social security numbers, email addresses, passwords, and health identifiers that are now out there for the world to see. But the Sony breach does not involve millions of consumer records and the subsequent issuing of new credit card numbers along with subscriptions to credit monitoring services.
This incident, though, is centered on sensitive data, perhaps even valuable IP, which was found in the 25 gigabytes of file data scooped up by the hackers. The leaked information should look all too familiar to any worker in a larger organization: readable files and emails, or, as we like to refer to it, unstructured, human-generated data.  So we’re talking employee salaries, financial data, internal presentations, company information under NDA, legal memos, the CEO’s private notes, and on and on. 

We should add that plain-text user passwords were found in files named, um, passwords. They certainly violated the "prime directive" on credentials.

From a broader perspective, we expect this is just one very public instance of a problem that can be found in enterprises globally. The amount of human-readable formation is growing exponentially. These documents live in file shares, intranets and in email as attachments, where far too many people have far more access than they really need, and usage is rarely monitored or analyzed for abuse.

No one should be casting any stones: we have all been or are Sony.

As we’ve seen in other breaches, the compromise of one employee email account can expose troves of sensitive data.  It’s likely the hacker harvested credentials —not necessarily of privileged admins or power users-- through PtH and other techniques. With their group memberships and access rights, combined with a loosely permissioned file system, they had a panoramic view of the Sony data landscape.

How did the situation get to be so dire?  Consider these two very common business-as-usual scenarios:

Scenario 1: A folder, containing sensitive data, becomes accessible to large group of people
A folder on your network share is used by your HR department—it might even be someone’s "home drive." At some point, someone makes the folder accessible to a broad group of people (this happens a lot), and it’s forgotten. Usage information about this folder (who is opening, creating, deleting, changing, moving files) isn’t tracked or analyzed (this is the norm).

Over time, sensitive files—say salaries, financial data, etc.—accumulate in these publicly sharable folders. No one really thinks about it, but everyone knows that a certain presentation or spreadsheet is just there so there's no need to formally request the data from the relevant owner. It's a data exposure incident waiting to happen, requiring a hacker to gain access to an average users' credentials—a simple phish mail often will do.

Scenario 2: Company emails become web browser enabled and gets hacked
You’ve enabled web browser access to your email system (try mail.yourcompany.com or owa.yourcompan.com if you're wondering), so anyone can log into their email from anywhere with only their password. Usage information about your email system is not tracked or analyzed (you can’t see who is sending or reading email or reading and marking them as unread, etc. – this is also the norm). The hacker gains the password of the email account—maybe by just guessing it.  Now the attacker can log in and read all the executive’s email (including the attachments) without leaving his home – and no one will know. Again, very valuable information—merger talks, new customers—in readable formats.

Another Teachable Moment
As Sony’s hackers gained access to more than just passwords, but movie budgets, salaries, social security numbers, health care information and so much more, the Sony breach provides us with yet another teachable moment. It reminded us all the importance of proper access controls, identification of sensitive data – who has access, who is using it, where it’s overexposed to the everyone group and who it belongs to, as well as implementation of real-time alerts.

Monday, July 22, 2013

US information leakage shows sloppiness in managing secrets

An interesting piece in Japan News in defense of Snowden and, by implication, Bradley Manning, Julian Assange, and others. I wonder if Snowden ever read about Kim Philby and how much he enjoyed life in the worker's paradise after fleeing England? It's a cold, lonely life.

Speaking of insider threats, you might want to take a look at Managing the Insider Threat: No Dark Corners. It identifies new management, security, and workplace strategies for categorizing and defeating insider threats.