Showing posts with label access control. Show all posts
Showing posts with label access control. Show all posts

Wednesday, September 20, 2017

Survey Reveals the "5 Deadly Sins" That Increase the Risks of a Data Breach

Despite prioritizing privileged access management, a majority of enterprises fail to prevent the abuse or misuse of privileged credentials

PHOENIX, September 20, 2017 -- BeyondTrust today announced its annual Privileged Access Management survey which identified "The Five Deadly Sins of Privileged Access Management," and how they prevent organizations from effectively protecting sensitive information.

For years, security experts have outlined best practices for privileged access management (PAM) in an effort to reduce problems associated with the abuse of privileged credentials. Despite this, IT organizations continue to struggle with privileged access management.

To understand why, BeyondTrust recently surveyed nearly 500 IT professionals from around the world with involvement in privileged access management. Because so many attacks start with the misuse of privileged accounts, it is not surprising that respondents rated the following three security measures as somewhat to extremely important to their efforts:
  • Privileged access management (83%)
  • Privileged session management (74%)
  • Privilege elevation management (74%)
When asked what issues keep them awake at night, respondents most often cited the misuse of personally identifiable information (86%), downtime of computing systems (85%), and loss of intellectual property (80%).

Yet, despite these widespread concerns, Forrester research finds that 80 percent of data breaches are the result of the abuse or misuse of privileged credentials[1]. The BeyondTrust survey finds "The Five Deadly Sins of Privileged Access Management" are to blame for this contradiction between the fact that so many IT organizations struggle to secure sensitive information despite their high levels of awareness and commitment to PAM:

Apathy: When asked to list the top threats associated with passwords, respondents listed employees sharing passwords with colleagues (79%), employees not changing default passwords their devices ship with (76%), and using weak passwords like "12345" (75%). Despite knowing better, respondents admitted that many of these same bad practices are common within their organization. A third of the respondents report users routinely share passwords with each other, and a fourth report the use of weak passwords. Shockingly, one in five report many users don’t even change the default passwords!

Greed: Users often insist they need full administrative privileges over their devices, and that creates problems for IT. 79% of respondents cite allowing users to run as administrators on their machines as their biggest threat, followed by not having control over applications on users’ machines (68%). Yet, nearly two in five respondents admit it is common for users to run as administrators on their machines. It is no surprise that many respondents say these practices have directly caused downtime of computing systems.

Pride: As the saying goes, pride cometh before the fall. One in five respondents say attacks combining privileged access with exploitation of an unpatched vulnerability are common. Simply patching known system vulnerabilities can prevent most of today’s commonly-reported attack vectors. Yet, too often, IT does not stay current on their patches.
 
Ignorance: Two-thirds say managing least privilege for Unix/Linux servers is somewhat to extremely important. One popular option is Sudo. However, just 29 percent say Sudo meets their needs. The most commonly cited problems with Sudo include being time-consuming to use (32%), complexity (31%) and poor version control (29%). Despite this, the typical respondent runs Sudo on 40 workstations and 25 servers.
 
Envy: Enterprises are rushing to embrace cloud computing. Yet, more than a third report that they are not involved in protecting SaaS applications from privileged access abuse.

There are steps any organization can take to address the Five Deadly Sins of Privileged Access Management:

1. Deploy enterprise password management globally across all data centers, virtual and cloud. A centralized password management solution that includes built-in session monitoring will ensure that both important capabilities are met with strong workflow and ease of use.
2. Remove local admin rights from ALL Windows and MacOS end users immediately. 94% of Microsoft system vulnerabilities in 2016 can be attributed to users with admin rights. Once all users are standard users, IT teams can elevate a user’s access to specific applications to perform whatever action is necessary as part of their role without elevating the entire user on the machine.
3. Prioritize and patch vulnerabilities. Better prioritization and patching of vulnerabilities provides IT with better insight into whether to delegate privileges to an asset or application. The result is better intelligence and less risk of unknowns.
4. Replace Sudo for complete protection of Unix/Linux servers. With pressure on budgets, organizations may have to use Sudo, but it doesn’t offer the industrial-strength capabilities that today's security needs.
5. Unify privileged access management--on-premise, in the cloud--into a single console for management, policy, reporting and analytics.

As organizations race to adopt SaaS/PaaS/IaaS to keep pace with business demands, IT must provide the same level of protection to cloud-based systems as for on-premise systems. This includes capabilities such as enabling automation for DevOps; finding, grouping and scanning cloud assets; protecting virtual and cloud management consoles and instances; using a cloud access service broker to enable third-party access; and performing vulnerability assessments for hybrid and public cloud infrastructures.

Download the full report from the BeyondTrust web site.

Monday, August 28, 2017

Chipping People: Are You Ready?

Shelly Palmer notes that "Proponents of the technology tout its convenience and the idea that you never have to remember your wallet or a password, ever again. While they are technically correct, chipping people invokes a train of thought that quickly descends to the darkest of places."

Would you voluntarily submit to this? What if chipping was a term of employment?

There's a link to a survey at the end of the article. Although it's not my survey, I'm interested in the results.

Thursday, June 16, 2016

Security Experts Offer Password Hygiene Tips

PORTLAND, Ore. -- June 15, 2016 -- In May 2016, security researchers discovered that millions of user accounts from popular sites like LinkedIn, MySpace and Tumblr were for sale in underground marketplaces. The victims' personal data came from multiple widespread data breaches, many of which took place between 2011 and 2013. Overall, the breaches revealed over 642 million passwords, and the FBI has issued a warning that cyber criminals have already started using information stemming from the breaches in blackmail and ransomware schemes.

According to the FBI, "The recipients are told that personal information, such as their name, phone number, address, credit card information, and other personal details, will be released to the recipient's social media contacts, family, and friends if a ransom is not paid. The recipient is instructed to pay in Bitcoin, a virtual currency that provides a high degree of anonymity to the transactions."

"With the increase of breaches that we've seen over the past few years, it's likely at least one of your passwords has been stolen by a hacker," said Travis Smith, senior security research engineer for Tripwire. "It's entirely possible one of your accounts has been compromised and that the website or service has not yet discovered the breach."

"Passwords are often the weakest link in an otherwise secure system," said Craig Young, security researcher for Tripwire. "The reuse of passwords across multiple systems and the use of simple passwords commonly found in password cracking dictionaries account for a large number of account hijackings."

Major vendors like Microsoft are taking direct steps to ban common passwords, but the attacks stemming from recent data breaches serve as serious reminders for users to take a closer look at their passwords. Tripwire security experts offer the following advice for consumers to improve their password hygiene:

•    Change your passwords on a regular basis. Many of the passwords from these recent data breaches are being sold on the dark web and are over three years old. Using stale passwords can keep you exposed to threats.
•    Stop using passwords and start using passphrases. Using a series of words is far less likely to show up in an attacker’s password dictionary than a single word. A starting point for a secure passphrase could be a favorite quote or a line from a song, complete with spaces and punctuation.
•    Be liberal with character substitutions. A password can be made stronger by replacing 'o' with '0,' 'e' with '3,' or 'a' with '@.'
•    Use a different password for each website or service. If an attacker manages to steal a password for one website, they cannot use the same password to access other websites. 

"Creating unique credentials for each website may seem daunting, but one option is to add something you associate with the website’s service to the passphrase," Young added. "For example, if I were to create a password for an online book retailer, I might start with the quote "It was the best of times," and then change it to "It w$s th3 b3st 0f tim3s." To make an ever stronger, more unique passphrase, I could add 'books': "It w$s th3 b3st 0f tim3s b00ks.""

An additional way to utilize unique credentials is to take advantage of two-factor authentication. "Employing multiple authentication factors prevents an attacker from gaining access by simply compromising your password," said Tim Erlin, director of IT security and risk strategist at Tripwire. "Two-factor authentication often uses a password and a one-time code sent to a mobile device. Other factors used for authentication could be a fingerprint, retinal scan or a physical card. Many websites and online services now support two-factor authentication, and users should enable it where possible."