Showing posts with label data loss prevention. Show all posts
Showing posts with label data loss prevention. Show all posts

Wednesday, September 20, 2017

Survey Reveals the "5 Deadly Sins" That Increase the Risks of a Data Breach

Despite prioritizing privileged access management, a majority of enterprises fail to prevent the abuse or misuse of privileged credentials

PHOENIX, September 20, 2017 -- BeyondTrust today announced its annual Privileged Access Management survey which identified "The Five Deadly Sins of Privileged Access Management," and how they prevent organizations from effectively protecting sensitive information.

For years, security experts have outlined best practices for privileged access management (PAM) in an effort to reduce problems associated with the abuse of privileged credentials. Despite this, IT organizations continue to struggle with privileged access management.

To understand why, BeyondTrust recently surveyed nearly 500 IT professionals from around the world with involvement in privileged access management. Because so many attacks start with the misuse of privileged accounts, it is not surprising that respondents rated the following three security measures as somewhat to extremely important to their efforts:
  • Privileged access management (83%)
  • Privileged session management (74%)
  • Privilege elevation management (74%)
When asked what issues keep them awake at night, respondents most often cited the misuse of personally identifiable information (86%), downtime of computing systems (85%), and loss of intellectual property (80%).

Yet, despite these widespread concerns, Forrester research finds that 80 percent of data breaches are the result of the abuse or misuse of privileged credentials[1]. The BeyondTrust survey finds "The Five Deadly Sins of Privileged Access Management" are to blame for this contradiction between the fact that so many IT organizations struggle to secure sensitive information despite their high levels of awareness and commitment to PAM:

Apathy: When asked to list the top threats associated with passwords, respondents listed employees sharing passwords with colleagues (79%), employees not changing default passwords their devices ship with (76%), and using weak passwords like "12345" (75%). Despite knowing better, respondents admitted that many of these same bad practices are common within their organization. A third of the respondents report users routinely share passwords with each other, and a fourth report the use of weak passwords. Shockingly, one in five report many users don’t even change the default passwords!

Greed: Users often insist they need full administrative privileges over their devices, and that creates problems for IT. 79% of respondents cite allowing users to run as administrators on their machines as their biggest threat, followed by not having control over applications on users’ machines (68%). Yet, nearly two in five respondents admit it is common for users to run as administrators on their machines. It is no surprise that many respondents say these practices have directly caused downtime of computing systems.

Pride: As the saying goes, pride cometh before the fall. One in five respondents say attacks combining privileged access with exploitation of an unpatched vulnerability are common. Simply patching known system vulnerabilities can prevent most of today’s commonly-reported attack vectors. Yet, too often, IT does not stay current on their patches.
 
Ignorance: Two-thirds say managing least privilege for Unix/Linux servers is somewhat to extremely important. One popular option is Sudo. However, just 29 percent say Sudo meets their needs. The most commonly cited problems with Sudo include being time-consuming to use (32%), complexity (31%) and poor version control (29%). Despite this, the typical respondent runs Sudo on 40 workstations and 25 servers.
 
Envy: Enterprises are rushing to embrace cloud computing. Yet, more than a third report that they are not involved in protecting SaaS applications from privileged access abuse.

There are steps any organization can take to address the Five Deadly Sins of Privileged Access Management:

1. Deploy enterprise password management globally across all data centers, virtual and cloud. A centralized password management solution that includes built-in session monitoring will ensure that both important capabilities are met with strong workflow and ease of use.
2. Remove local admin rights from ALL Windows and MacOS end users immediately. 94% of Microsoft system vulnerabilities in 2016 can be attributed to users with admin rights. Once all users are standard users, IT teams can elevate a user’s access to specific applications to perform whatever action is necessary as part of their role without elevating the entire user on the machine.
3. Prioritize and patch vulnerabilities. Better prioritization and patching of vulnerabilities provides IT with better insight into whether to delegate privileges to an asset or application. The result is better intelligence and less risk of unknowns.
4. Replace Sudo for complete protection of Unix/Linux servers. With pressure on budgets, organizations may have to use Sudo, but it doesn’t offer the industrial-strength capabilities that today's security needs.
5. Unify privileged access management--on-premise, in the cloud--into a single console for management, policy, reporting and analytics.

As organizations race to adopt SaaS/PaaS/IaaS to keep pace with business demands, IT must provide the same level of protection to cloud-based systems as for on-premise systems. This includes capabilities such as enabling automation for DevOps; finding, grouping and scanning cloud assets; protecting virtual and cloud management consoles and instances; using a cloud access service broker to enable third-party access; and performing vulnerability assessments for hybrid and public cloud infrastructures.

Download the full report from the BeyondTrust web site.

Monday, September 18, 2017

What Businesses Need to Know in the Wake of the Equifax Breach



What Businesses Need to Know in the Wake of the Equifax Breach
By Jason Tan, CEO of Sift Science

Online businesses everywhere are going to be dealing with the effects of the recent Equifax breach. It’s a tough truth to swallow, but these large-scale data breaches have become a fact of life – and it’s not just the breached business that pays the price. As fraudsters mine the valuable data that’s been compromised, all e-commerce sites and financial institutions need to be on alert.

Keep an eye out for signs of account takeover.

Last year, 48% of online businesses saw an increase in account takeover (ATO), according to the Sift Science Fraud-Fighting Trends report. And the Equifax breach is likely to exacerbate this trend, potentially flooding the dark web with names, addresses, Social Security numbers, and other personal information that fraudsters can leverage to gain access to a legitimate user’s account. They then make purchases with a stored payment method or drain value from the user’s account.

Some of the signals that could point to an ATO:

  • Login attempts from different devices and locations
  • Switching to older browsers and operating systems
  • Buying more than usual, or higher priced items
  • Changing settings, shipping address, or passwords
  • Multiple failed login attempts
  • Suspicious device configurations, like proxy or VPN setups

Keep in mind that taken individually, each of these signs may be normal behavior for a particular user. It’s only when you apply behavioral analysis on a large scale, looking at all of a user’s activity and all activity of users across the network, that you can accurately detect ATO.

Monitor for fake accounts and synthetic identity fraud.

Fraudsters can also take all of the different pieces of personal data leaked in the Equifax breach to steal someone’s identity and create new accounts. They may also pick and choose pieces from various people’s accounts – like a birthday, Social Security number, and name – and mix them together to create an entirely new ID.

To keep tabs on fake accounts, you can monitor new signups to look for risky patterns, like a sudden spike in new accounts that can’t be attributed to a specific promotion or seasonal trend. If the average time it takes a new user to sign up suddenly gets much faster, that may point to fraudsters using a script to quickly create accounts. And seeing multiple new accounts coming from the same IP address or device is a red flag for a single person creating many accounts.

Stay focused on maintaining user trust.

Even if a breach doesn’t happen on your site, any downstream fraud attacks still happen on your watch. If you don’t invest in protecting your users from the devastating effects of ATO, identity theft, and fraud, you will soon lose their trust. Trust is earned in drops, but lost in buckets.

At the same time, e-commerce businesses and financial institutions should make sure they aren’t overly cautious to the point where they’re rejecting good customers and denying legitimate accounts. Preventing fraud is a delicate balancing act, and the right technology – which looks at a range of data points to make an accurate prediction about what is and isn’t fraudulent – can help you strike the right balance.

About the Author:
Jason Tan is the CEO of Sift Science, a trust platform that offers a full suite of fraud and abuse prevention products designed to attack every vector of online fraud for industries and businesses across the world.

Tuesday, August 30, 2016

Study Finds Employees’ Security Hygiene Getting Worse Just As Ransomware Exposes Insider Negligence

Varonis-Sponsored Ponemon Institute Report Examines Widening Gap between End Users and IT Professionals as Data Breaches Increase

LONDON, UK -- August 30, 2016 -- At a time when ransomware and other attack techniques that exploit insider negligence become rampant, only 39 percent of end users believe they take all appropriate steps to protect company data accessed and used in the course of their jobs. This is a sharp decline from 56 percent in 2014, according to a new survey of more than 3,000 employees and IT practitioners across the U.S. and Europe. The report was conducted by the Ponemon Institute and sponsored by Varonis Systems, Inc.

Moreover, while 52 percent of IT respondents believe that policies against the misuse or unauthorised access to company data are being enforced and followed, only 35 percent of end user respondents say their organizations strictly enforce those policies.

The new release, "The Widening Gap between End Users and IT," compares end-user practices and beliefs with those of their colleagues in IT security and IT generalist roles. This new analysis draws from the same data released by Varonis and the Ponemon Institute August 9, 2016, in a report entitled "Closing Security Gaps to Protect Corporate Data: A Study of US and European Organisations," which found a sharp rise in the loss or theft of data, an increase in the percentage of employees with access to sensitive data, and the belief among participants that insider negligence is now the #1 concern for organizations trying to prevent these losses.

The survey results are derived from interviews conducted in April and May 2016, with 3,027 employees in the United States, United Kingdom, France, and Germany. Respondents included 1,371 end users and 1,656 IT and IT security professionals, in organizations ranging in size from dozens to tens of thousands of employees from a variety of industries including financial services, public sector, health care and life sciences, retail, industrial, and technology and software.

Among the key findings:
•    Sixty-one percent of respondents who work in IT or security roles view the protection of critical company information as a very high or high priority. In contrast, only 38 percent of respondents who are considered end users of this data believe it is a very high or high priority.
•    Asked about their organization's attitude on productivity vs. security, 38 percent of IT practitioners and 48 percent of end users say their organizations would accept more risk to the security of their corporate data in order to maintain productivity. 
•    Asked to agree or disagree that the protection of company data is a top priority for their CEO and other C-level executives, only 35 percent of end users agreed while 53 percent of IT professionals believe it is a top priority for senior executives.
•    Asked for the most likely causes of the compromise of insider accounts, 50 percent of IT practitioners and 58 percent of end users say negligent insiders. "Insiders who are negligent" was by far the most frequent response for both IT and end users, more than twice as common as "external attackers" and more than three times as common as "malicious employees."
•    End users are far more likely to attribute data breaches to insider mistakes than IT or security professionals. Seventy-three percent of end users say data breaches are very frequently or frequently due to insider mistakes, negligence or malice, while only 46 percent of IT respondents draw the same conclusions.

Dr. Larry Ponemon, Chairman and Founder of Ponemon Institute, a leading research center dedicated to privacy, data protection and information security policy, observed, "At a time when one would expect general improvement in end-user hygiene due to increased awareness of cyberattacks and security breaches, this survey instead found an alarming decline in both practices and attitudes. If an organization’s leadership does not make data protection a priority, it will continue to be an uphill battle to ensure end users' compliance with information security policies and procedures. Major differences between the IT function and end users about appropriate data access and usage practices make it harder to reduce security risks related to mobile devices, the cloud and document collaboration."

Yaki Faitelson, Co-Founder and CEO of Varonis, said, "Human error will always be a weak link in security. Insiders compromise security maliciously or accidentally and outside attackers continue to hijack the credentials and systems of employees, administrators, contractors, and executives. The only way to stem this tide is to implement controls on data access, monitor all activity and implement the most advanced user behavior analytics and alerting technologies throughout the organization."

NEW BOOK ON MITIGATING INSIDER THREATS

We'll be publishing "Walling Out the Insiders: Controlling Access to Improve Organizational Security" by Michael Erbschloe in February 2017. The book is grounded in the reality that many, if not most organizations have limited security budgets and security personnel. It

  • Explains security planning and management strategies in a manner that can be understood by security professionals as well as non-security managers and executives.
  • Provides long-term security design, implementation, and management methods to guide managers through the long process of achieving improved security.
  • Provides practical advice on how to determine security weaknesses and security needs.
  • Provides practical advice on how to select security vendors and service providers.
For more on the insider threat, read these articles:

The Insider Threat: A View from the Outside

Why Insider Threats Are Succeeding

The Top 10 Ways to Combat Insider Threats

Insider Threat Concepts and Concerns

Wednesday, March 23, 2016

Why Most Companies Are Easy Prey for Cyber Attackers


Alarming Data Reveals Why Most Companies Are Easy Prey for Cyber Attackers

LONDON, UK, March 22, 2016 – Varonis Systems, Inc. today revealed the results of a year of anonymous data collected during risk assessments conducted for potential customers on a limited subset of their file systems. The 2015 results show a staggering level of exposure in corporate file systems, including an average of 9.9 million files per assessment that were accessible by every employee in the company.

Of the insights gleaned from dozens of customer risk assessments conducted in mid-to-large enterprises prior to remediation, in a subset of each company’s file systems, Varonis found the average company had:
35.3 million files, stored in 4 million folders, meaning the average folder has 8.8 files
  • 1.1 million folders, or an average of 28% of all folders, with “everyone” group permission enabled –open to all network users
  • 9.9 million files that were accessible by every employee in the company regardless of their roles
  • 2.8 million folders, or 70% of all folders, contained stale data – untouched for the past six months
  • 25,000 user accounts, with 7,700 of them or 31% “stale” – having not logged in for the past 60 days, suggesting former employees, employees who changed roles, or consultants and contractors whose engagements have ended
The ‘everyone’ group is a common convenience for permissions when originally set up. That mass access also makes it astonishingly easy for hackers to steal company data.

Some individual companies’ lowlights that were gleaned from the Varonis risk assessments:
In one company, every employee had access to 82% of the 6.1 million total folders.
  • Another company had more than 2 million files containing sensitive data (credit card, social security or account numbers) that everyone in the company could access.
  • 50% of another company’s folders had “everyone” group permission and more than 14,000 files in those folders were found to contain sensitive data.
  • A single company had more than 146,000 stale users – accounts whose users had not logged in for the past 60 days.  That’s nearly three times more users than the average FORTUNE 500 company has total employees.
David Gibson, Vice President of Strategy and Market Development at Varonis, said, “Although this data presents a bleak look at the average enterprise’s corporate file system environment, the organizations running these risk assessments are taking these challenges seriously. Most of them have since implemented Varonis, embracing a more holistic view of the data on their file and email systems and closing these gaping, often unseen security holes before the next major breach causes heavy damage. Our software is able to provide a granular look at where sensitive data lives, where it is over-exposed within an organization, who is accessing that data, and how to lock it down. While that remediation process is running, our ability to start detecting and stopping many types of insider threats has been a major revelation for our customers.”

Tuesday, January 5, 2016

What Santa Didn't Bring Me


I was a little disappointed on Christmas morning when I discovered that Santa didn't leave any manuscripts of the following topics:

threat hunting
moving target security
insider threats
security kill chain
physical security and the IT department
security operations
synchronized security
security awareness
data loss prevention
SIEM

It's still not to late to bring some Christmas joy to a boy's heart. If you or a friend or a colleague have any interest in writing a book in 2016 on these or some related topics, please let me know.

Best wishes for 2016.

Rich

Wednesday, December 9, 2015

Changing Human Behavior Is the Key to Thwarting Cyber Threats in 2016


London (UK) - 08 December 2016 - PhishMe today offered three predictions for the threats it believes UK organizations will battle in 2016:

1. Phishers Will Continue to Divide and Conquer

Phishing has been the number one attack vector for over five years and 2016 will be no different.

Rohyt Belani, CEO of PhishMe explains his thinking, "We, as an industry, have lagged in engaging employees to be a part of the organization’s security posture. For decades, enterprises have focused on traditional security awareness techniques like computer-based training (CBT) that simply don't work; they have no sustained impact on behavioral change. At PhishMe, we have succeeded in helping our customers engage their employee base by turning them into informants of suspicious emails, providing such employees with the necessary tools to report the same in a frictionless manner, and then most importantly in providing the incident response teams at these organizations a solution to rapidly triage these reports and operationalize the attack intelligence obtained. The human is no longer the weakest link for our customers; they are the strongest asset."

2. Focus Will Move Back to Prevention of Breaches, Rather than Detection after the Fact

While prevention of individual infections is almost impossible, preventing the breach of confidential and proprietary data as a result is paramount.

"The industry gave up. They surrendered and turned to post-breach detection and mitigation because the hackers were winning," explains Scott Greaux, VP Product Management at PhishMe, "With average time to detection still over 200 days this approach hasn't worked either and I think in 2016 we will see the focus shift again. System infections will occur, and at the moment there's no silver bullet to change this, but we need to prevent these infections from translating to large data breaches. That means conditioned email users will play a key role, providing the timely and actionable threat intelligence thus minimizing attacker dwell times, that will help prevent breaches in 2016."

3. All Forms of Trust Will be Abused

It seems that criminals listen to the advice given to people about cybercrime and turn it around in a bid to thwart defenses. The traditional wisdom was 'don't click links or open attachments from un-trusted sources.' In 2015, the increase in attacks targeting email is primarily about abusing those trust relationships. In 2016, other forms of trust are going to be under attack. Passwords stored in browsers, especially on mobile devices and 'Bring Your Own Device' phones and tablets will be a big target. 

The advice from Gary Warner, Chief Threat Scientist at PhishMe is that, "This year we need to be encouraging the adoption of two factor authentication and 'unknown device' alerting as never before – including on internal systems.  In another area of trust, a malware compromised workstation logs in to the corporate systems with the same power as an authorized user. Big data breaches are largely enabled by the concept that certain users should be allowed to 'See Everything' and this must be reeled back to 'see only some things' or 'see anything,' but only at reasonable volumes."

With increased reporting of suspicious activity, advances in threat analysis to enable better campaign identification, and raising the shield by challenging all of the 'trust' assumptions made, organizations can make 2016 a safer year.

Thursday, December 3, 2015

U.S. Presidential Campaign Will be Affected by a Cyber Attack, and Other 2016 Predictions


It's the of the year for predictions of how bad the security environment will be for the coming year.  Here are predictions from David Gibson, VP of strategy and market development at Varonis. By the way, focusing on end-user education and monitoring is long overdue. I don't think it's hyperbole to say, "Insiders are the new malware."

1. The U.S. Presidential campaign will be affected by a cyber attack.  
Hillary Clinton's private email server has already brought cybersecurity into the U.S. Presidential race. In 2016, a cyberattack will strike the campaign, causing a major data breach that will expose donors' personal identities, credit card numbers, and previously private political preferences. Imagine being a donor with an assumption of anonymity. Or a candidate whose “ground game” depends on big data analytics about voter demographics and factors affecting turnout – data that turns from an asset to a liability if it isn't protected. The breach will affect the campaign not only as a setback for the unfortunate candidate or party affected, but by bringing the issue of cybersecurity prominently into the campaign as a major issue that is closely related to geopolitical threats such as the spread of terrorism. Campaign data is a gold mine for hackers (donor lists, strategies, demographics, sentiment, opposition research), and an event like this will serve as another wake-up call to the U.S. government that cybersecurity needs to be a continual, central focus and investment at the highest levels. The candidate who demonstrates knowledge and command of cybersecurity threats and government readiness will win the election.
  
2. The frequency of public data breaches will increase substantially.
The Identity Theft Resource Center (ITRC) reports a total of 641 data breaches recorded publicly in 2015 through November 3. Most organizations know this number represents the tip of the iceberg. The frequency of known data breaches will increase in 2016, due not only to increasing privacy and breach disclosure laws but also the increasing failure of traditional perimeter-focused security investments to protect valuable data. Employees' use of mobile devices and companies' migration of IT workloads to the cloud will also contribute to a sharp rise in breaches. Over time, this should help to shift priorities toward investing in more proactive data-centric protection, but it's likely things will become worse before they get better.

3. End-user education and monitoring will become the focal point of data security efforts.
Insiders are the new malware. Executives and IT professionals are becoming as afraid of their own employees – as innocent vessels for outside attackers with dangerous levels of access to sensitive data – as they are of outside attackers. Companies will turn to the importance of end-user education in 2016 as they realize that, no matter how intensely they invest in security, they hit a dead end if their users don’t drive by the rules of the road. They need to be involved in the security processes, observe classification and disposition policies (that need to be defined) and know to stop clicking on phishing emails. Employees are crucial to the security process, and have more power in controlling it than they realize. You can't patch users but you can educate them. You can also monitor and analyze how they use data to spot unwanted attacks.

4. At least five more C-level executives will be fired because of a data breach.
In recent years we have seen the careers of several top executives suffer in the wake of cyber attacks. Target CEO Gregg Steinhafel and CIO Beth Jacob, U.S. Office of Personnel Management Director Katherine Archuleta, Sony Pictures' Amy Pascal and others were either fired or forced to resign after massive data leaks cost their organizations money, customers and credibility. This will accelerate in 2016.  Blame for data breaches is shifting from IT to the C-suite. Data impacts every facet of an organization. If management is not investing in and focusing heavily on securing data and its use, it is now understood that they are putting the entire company and its stakeholders at risk.

5. Increasing false positives in data security bring to light the need for limited, accurate information.
Organizations will get much more serious about how much data they collect and their deletion efforts. When Target suffered its massive breach during the 2013 holiday season, the alerting capabilities of its IT team had generated months of warnings.  Still, no one caught it. This remains a common problem today. Why? The plethora of security tools installed in most companies overwhelms IT security. Their teams are strapped and the amount of false positives generated by exponentially growing volumes of information cause these teams to miss crucial vulnerabilities. In 2016, smart IT teams will focus on signal-to-noise ratio improvements in the analysis and alerting solutions they deploy.

Tuesday, November 17, 2015

The Threat Within: 3 Out of 4 Companies Affected by Internal Information Security Incidents


Costly cyberattacks are now almost routine for businesses, but while many organizations are focusing on external attackers, it's important to also look at threats from within. According to the IT Security Risks Survey conducted by Kaspersky Lab and B2B International, 73% of companies have been affected by internal information security incidents. The survey also found that the largest single cause of confidential data losses is by employees (42%). Read more here.

Monday, October 26, 2015

10 Facts You Need to Know About Data Breaches

2014 was dubbed as "the year of the data breach." With many new data breaches dominating the headlines in 2015, including Anthem, the White House, banking attacks, and the latest employee data theft at the US federal government, one can only imagine what the name for 2015 will be: the year of even more data breaches? According to the Ponemon Institute, 43% of companies experienced a data breach in 2014. Not only is the number of data breaches rising, the number of records stolen per breach is increasing as well as the cost per stolen record. It is apparent that current security measures are not sufficient to protect organizations from data breaches. This article highlights the top 10 most interesting, remarkable and troubling facts about data breaches.