Showing posts with label security awareness. Show all posts
Showing posts with label security awareness. Show all posts

Thursday, March 16, 2017

Who's Getting Hacked?




Forrest Carman from Owen Media passed along something fun I think might interest you. IT training company CBT Nuggets just analyzed the responses of over 2000 survey respondents, testing knowledge about online security.

Some interesting results:

  • Apple users are 22% more likely to be victims of online identity theft than Windows users.
  • People who identify as “tech savvy” are 18% more likely to be victims of online identity theft than those who don’t.
  • Those who have PhDs are more likely to be victims of online identity theft than high school graduates.
  • Millennials are less likely than their older counterparts to have secure information stolen online, although this may be because they haven’t risked having their personal information compromised for as long as the other age groups.

Tuesday, October 4, 2016

National Cyber Security Awareness Month


National Cyber Security Awareness Month  

From KnowBe4:

DHS site has lots of tools, hints and themes you can use. In their words:

October is National Cyber Security Awareness Month. This is an annual campaign to raise awareness about cybersecurity. We live in a world that is more connected than ever before. The Internet touches almost all aspects of everyone’s daily life, whether we realize it or not.

National Cyber Security Awareness Month (NCSAM) is designed to engage and educate public and private sector partners through events and initiatives to raise awareness about cybersecurity, provide them with tools and resources needed to stay safe online, and increase the resiliency of the Nation in the event of a cyber incident.

Books on Security Awareness

Asset Protection through Security Awareness by Tyler Speed

Managing an Information Security and Privacy Awareness and Training Program, Second Edition by Rebecca Herold

Wednesday, September 14, 2016

FREE Guide on How to Communicate Security Issues to Employees


Creating a secure and safe working environment has become an essential priority for employers. Cyber-attacks, terrorist activity and even inadvertent employee actions feature all-too-frequently in the media. No organization or individual is immune.

Effective communication and education are central to developing a robust, security-conscious culture. But this has been highlighted as one of the biggest challenges faced by employers. So how do you get your employees to sit up and take notice of security issues?

Global communications company SnapComms has developed a new white-paper to help organizations implement an ongoing security framework for all staff through better communication and training. You can download the white paper, "How to Communicate Security Issues to Employees," here.

The white paper outlines common threats and activity that lead to security issues, as well as recommended training techniques for avoiding these security situations and methods for communicating better practices to employees such as:

•       Making your security message personal;
•       Targeting communications by employee role;
•       Cutting through the noise to share messages that build culture;
•       Tracking employee progress;
•       Keeping messages simple; and
•       Developing a theme that resonates with your workforce.






Related Books

Asset Protection through Security Awareness

Managing an Information Security and Privacy Awareness and Training Program, Second Edition

Tuesday, August 30, 2016

Study Finds Employees’ Security Hygiene Getting Worse Just As Ransomware Exposes Insider Negligence

Varonis-Sponsored Ponemon Institute Report Examines Widening Gap between End Users and IT Professionals as Data Breaches Increase

LONDON, UK -- August 30, 2016 -- At a time when ransomware and other attack techniques that exploit insider negligence become rampant, only 39 percent of end users believe they take all appropriate steps to protect company data accessed and used in the course of their jobs. This is a sharp decline from 56 percent in 2014, according to a new survey of more than 3,000 employees and IT practitioners across the U.S. and Europe. The report was conducted by the Ponemon Institute and sponsored by Varonis Systems, Inc.

Moreover, while 52 percent of IT respondents believe that policies against the misuse or unauthorised access to company data are being enforced and followed, only 35 percent of end user respondents say their organizations strictly enforce those policies.

The new release, "The Widening Gap between End Users and IT," compares end-user practices and beliefs with those of their colleagues in IT security and IT generalist roles. This new analysis draws from the same data released by Varonis and the Ponemon Institute August 9, 2016, in a report entitled "Closing Security Gaps to Protect Corporate Data: A Study of US and European Organisations," which found a sharp rise in the loss or theft of data, an increase in the percentage of employees with access to sensitive data, and the belief among participants that insider negligence is now the #1 concern for organizations trying to prevent these losses.

The survey results are derived from interviews conducted in April and May 2016, with 3,027 employees in the United States, United Kingdom, France, and Germany. Respondents included 1,371 end users and 1,656 IT and IT security professionals, in organizations ranging in size from dozens to tens of thousands of employees from a variety of industries including financial services, public sector, health care and life sciences, retail, industrial, and technology and software.

Among the key findings:
•    Sixty-one percent of respondents who work in IT or security roles view the protection of critical company information as a very high or high priority. In contrast, only 38 percent of respondents who are considered end users of this data believe it is a very high or high priority.
•    Asked about their organization's attitude on productivity vs. security, 38 percent of IT practitioners and 48 percent of end users say their organizations would accept more risk to the security of their corporate data in order to maintain productivity. 
•    Asked to agree or disagree that the protection of company data is a top priority for their CEO and other C-level executives, only 35 percent of end users agreed while 53 percent of IT professionals believe it is a top priority for senior executives.
•    Asked for the most likely causes of the compromise of insider accounts, 50 percent of IT practitioners and 58 percent of end users say negligent insiders. "Insiders who are negligent" was by far the most frequent response for both IT and end users, more than twice as common as "external attackers" and more than three times as common as "malicious employees."
•    End users are far more likely to attribute data breaches to insider mistakes than IT or security professionals. Seventy-three percent of end users say data breaches are very frequently or frequently due to insider mistakes, negligence or malice, while only 46 percent of IT respondents draw the same conclusions.

Dr. Larry Ponemon, Chairman and Founder of Ponemon Institute, a leading research center dedicated to privacy, data protection and information security policy, observed, "At a time when one would expect general improvement in end-user hygiene due to increased awareness of cyberattacks and security breaches, this survey instead found an alarming decline in both practices and attitudes. If an organization’s leadership does not make data protection a priority, it will continue to be an uphill battle to ensure end users' compliance with information security policies and procedures. Major differences between the IT function and end users about appropriate data access and usage practices make it harder to reduce security risks related to mobile devices, the cloud and document collaboration."

Yaki Faitelson, Co-Founder and CEO of Varonis, said, "Human error will always be a weak link in security. Insiders compromise security maliciously or accidentally and outside attackers continue to hijack the credentials and systems of employees, administrators, contractors, and executives. The only way to stem this tide is to implement controls on data access, monitor all activity and implement the most advanced user behavior analytics and alerting technologies throughout the organization."

NEW BOOK ON MITIGATING INSIDER THREATS

We'll be publishing "Walling Out the Insiders: Controlling Access to Improve Organizational Security" by Michael Erbschloe in February 2017. The book is grounded in the reality that many, if not most organizations have limited security budgets and security personnel. It

  • Explains security planning and management strategies in a manner that can be understood by security professionals as well as non-security managers and executives.
  • Provides long-term security design, implementation, and management methods to guide managers through the long process of achieving improved security.
  • Provides practical advice on how to determine security weaknesses and security needs.
  • Provides practical advice on how to select security vendors and service providers.
For more on the insider threat, read these articles:

The Insider Threat: A View from the Outside

Why Insider Threats Are Succeeding

The Top 10 Ways to Combat Insider Threats

Insider Threat Concepts and Concerns

Tuesday, June 28, 2016

Building Cyber Awareness: What I Would Do First


Cyber security experts are often asked what strides an organization should take in order to measurably reduce their exposure to cyber threat actors, and their relentless cyber-attacks. Deploying the right security technologies obviously makes good sense. However, no matter how much security technology you deploy, it will never completely replace good common sense. Most cyber-attacks that result in data theft involve the human element, and the dreaded 'click;' that is, the act of an employee being fooled by a phishing E-mail and clicking a link or attachment that installs malicious software without detection. Reducing this single liability would serve to improve anyone's defensive posture. This article discusses how to solve this problem.

Thursday, June 16, 2016

Building Cyber Awareness: What I Would Do First

Cyber security experts are often asked what strides an organization should take in order to measurably reduce their exposure to cyber threat actors, and their relentless cyber-attacks. Deploying the right security technologies obviously makes good sense. However, no matter how much security technology you deploy, it will never completely replace good common sense. Most cyber-attacks that result in data theft involve the human element, and the dreaded 'click.' That is, the act of an employee being fooled by a phishing E-mail and clicking a link or attachment that installs malicious software without detection. Reducing this single liability would serve to improve anyone's defensive posture. This article by Stephen Gates, Chief Research Intelligence Analyst, NSFOCUS, discusses his recommendations on how to solve this problem. 

Tuesday, March 15, 2016

Deadly Dridex Gang Muscles Into Ransomware Racket

March 15, 2016 -- Ransomware is moving rapidly into the malware mainstream. One of the driving factors is the high dollar numbers being racked up by the notorious Dridex banking Trojan gang muscling into ransomware with their new Locky strain. Locky was linked to the Dridex gang by IT security companies Palo Alto Networks and Proofpoint. The Russian Dridex group is the most prominent operating banking malware and has taken the lead over from CryptoWall.

According to KnowBe4 CEO, Stu Sjouwerman, “Ransomware is seeing unprecedented growth with cyber-gangs competing for criminal market share. This competition has spurred furious innovation in strategy and tactics and we see ransomware taking the lead in criminal business models. It isn’t going to get easier. The only way around these tactics are to recognize the Red Flags and inoculate your employees with effective security awareness training and simulated phishing tests.”

The Dridex Locky ransomware strain isn't more sophisticated than other latest generation crypto-ransom malware, but it is rapidly spreading to victim systems. Forbes claims Locky is infecting approximately 90,000 systems per day (that’s over 1 per second) and it typically asks users for 0.5-1 Bitcoin (~420 dollars) to unlock their systems. Locky is disseminated through phishing emails containing Microsoft Word attachments. Each binary of Locky is reportedly uniquely hashed; consequently, signature-based detection by a traditional antivirus product is nearly impossible.

The Dridex gang is the 800-pound gorilla in banking Trojans. Apparently they have seen the profit potential of ransomware and leveraged their extensive criminal infrastructure to get their Locky strain infecting as many machines as possible. Consequently, financial institutions are likely the next major sector to be actively targeted. The FBI just stated that the threat from ransomware is expected to grow, according to an interview in the WSJ.

In the past few days, the Dridex botnet has sent at least 4 million phishing emails with a zip file as the attachment. The zip file contains a JavaScript file which downloads and installs Locky.

What to do about it
1. Block any and all emails with .zip extensions or macros at your email gateway level.
2. Disable Adobe Flash Player, Java and Silverlight if possible. These are used as attack vectors.
3. Step all employees through effective security awareness training, so they can recognize the red flags related to ransomware attacks.
4. Print out this free job aid, laminate it, and hand it out to employees so they can pin it on their wall. 
5. Do a phishing security test on your users and find out if they are going to click on something they shouldn't. 

SOURCE:  Michael Becce, MRB Public Relations, Inc.

Wednesday, February 17, 2016

New Ransomware Hidden in Word Docs: New “Locky” Ransomware Is Loaded with Professional Grade Malware

Recent reports indicate that the actors behind Dridex, originally a banking Trojan distributor, have switched tactics, and are now heavily pushing out a new ransomware called Locky. The current method of distribution is via a spam email, which contains a Word document. Additional reports state that it is being distributed via the Neutrino Exploit Kit.

KnowBe4 issued a warning to its customers today of a vicious new strain of ransomware disguised within Word documents. This new ransomware strain, called "Locky," is professional grade malware and starts out with an email and a Microsoft Word attachment containing malicious macros, making it hard to filter out. Few antivirus products are catching it. Social engineering is used twice to trick users into opening the attachment and again to enable the macros in the Word file. When the Word document is opened, it looks like the content of the document is scrambled and the document will display a message stating that you should enable the macros if the text is unreadable.

According to KnowBe4’s CEO Stu Sjouwerman, “Once a victim enables the macros, they download an executable from a remote server in the %Temp% folder and execute it. This executable is the Locky ransomware that when started will begin to encrypt the files on your computer and network.”

The email message will contain a subject similar to ATTN: Invoice J-98223146 and a message such as "Please see the attached invoice (Microsoft Word Document) and remit payment according to the terms listed at the bottom of the invoice." This new strain was first reported in the UK by Kevin Baumont, and Larry Abrahms at BleepingComputer did a more in-depth analysis.  

According to Abrams, "It targets a large amount of file extensions and even more importantly, encrypts data on unmapped network shares.  Encrypting data on unmapped network shares is trivial to code and the fact that we saw the recent DMA Locker with this feature and now in Locky, it is safe to say that it is going to become the norm. Like CryptoWall, Locky also completely changes the filenames for encrypted files to make it more difficult to restore the right data."

Dodi Glenn, VP of Cyber Security at PC Pitstop says, “If an individual opens the spam email, ignores the macro Word alert and clicks "enabled content, Locky will immediately scan the system for specific files, and encrypt or modify them so they can no longer be used - that is, unless a ransom is paid, which Locky’s current amount is .5 BTC, or the equivalent of $209.33. These file types are commonly found on end users’ machines, such as .doc, .csv, .pdf, .jpg, etc. However, what should be more concerning to enterprise customers is that it will also look for .SQL, .SQLiteDB, and .SQLite3 files, which are associated with databases.  The transaction is all too familiar for many of the other types of ransomware out there. PC Matic users should know that this malware is blocked, and cannot be executed on machines protected with Super Shield.”

Sjouwerman noted, “The old Office macros from the nineties have not gone away and the bad guys are combining this old technology with clever social engineering. If you trust antivirus software and your users not clicking ‘Enable macros’ you are going to have a problem. You can’t just disable all macros across the whole company because a lot of legacy code relies on macros. Telling all users to sign their macros will also take months.”

KnowBe4 advises the following steps be taken:

1. Go hunt for this Group Policy Setting in the Trust Center, and set it to “Disable all except digitally signed macros”.
2. Now check out Trusted Locations: User Configuration/Administrative Templates/Microsoft Office XXX 20XX/Application Settings/Security/Trust Center/Trusted Locations
3. Set your shared folder location URL in here, e.g. \\blah.local\public\office   (More detail can be found at Microsoft Technet.)
4. Now instruct your users to make sure all macros are used from shared folders. Macros should work as before on their regular documents. If Mr. Bad Guy emails Joe in Accounts Payable a Bad File, the macro won’t run.”

Users won’t see a prompt to enable the macro, nor can they from the Office options.

Sjouwerman added, “Technically speaking, your users are the new DMZ, and you need to create a human firewall. Effective security awareness training is a must these days.”

Monday, February 8, 2016

8 of the Largest Data Breaches of All Time


According to the Identity Theft Resource Center, there have been 5,754 data breaches between November 2005 and November 2015 that have exposed 856,548,312 records. According to their data, there were 783 breaches in 2014, the largest number of data breaches in a single year to date. Although this data includes a comprehensive list of data breaches, whether large-scale or small, there are a few that stand out from the rest as some of the worst data breaches in history in terms of resulting costs and the number of records compromised. This list of eight of the worst breaches in history highlights the cause of the breach and the effects on the public and business sectors.

Tuesday, December 15, 2015

Protecting the Oil and Gas Industry from Email Threats

According to a recent report from the US Industrial Control Systems Cyber Emergency Response Team (ICS-CERT), the energy sector is facing a significant rise in cyber attacks. The high volume of business communications conducted via email within this industry give hackers quite the window of opportunity to intercept sensitive information through the use of spear phishing. This article by OPSWAT's Doug Rangi describes spear phishing attacks that have occurred in various sectors of oil and gas, along with recommendations on how the industry can boost their cyber security and specifically adopt new preventative measures to protect against these and other email-borne threats.

Wednesday, December 9, 2015

Changing Human Behavior Is the Key to Thwarting Cyber Threats in 2016


London (UK) - 08 December 2016 - PhishMe today offered three predictions for the threats it believes UK organizations will battle in 2016:

1. Phishers Will Continue to Divide and Conquer

Phishing has been the number one attack vector for over five years and 2016 will be no different.

Rohyt Belani, CEO of PhishMe explains his thinking, "We, as an industry, have lagged in engaging employees to be a part of the organization’s security posture. For decades, enterprises have focused on traditional security awareness techniques like computer-based training (CBT) that simply don't work; they have no sustained impact on behavioral change. At PhishMe, we have succeeded in helping our customers engage their employee base by turning them into informants of suspicious emails, providing such employees with the necessary tools to report the same in a frictionless manner, and then most importantly in providing the incident response teams at these organizations a solution to rapidly triage these reports and operationalize the attack intelligence obtained. The human is no longer the weakest link for our customers; they are the strongest asset."

2. Focus Will Move Back to Prevention of Breaches, Rather than Detection after the Fact

While prevention of individual infections is almost impossible, preventing the breach of confidential and proprietary data as a result is paramount.

"The industry gave up. They surrendered and turned to post-breach detection and mitigation because the hackers were winning," explains Scott Greaux, VP Product Management at PhishMe, "With average time to detection still over 200 days this approach hasn't worked either and I think in 2016 we will see the focus shift again. System infections will occur, and at the moment there's no silver bullet to change this, but we need to prevent these infections from translating to large data breaches. That means conditioned email users will play a key role, providing the timely and actionable threat intelligence thus minimizing attacker dwell times, that will help prevent breaches in 2016."

3. All Forms of Trust Will be Abused

It seems that criminals listen to the advice given to people about cybercrime and turn it around in a bid to thwart defenses. The traditional wisdom was 'don't click links or open attachments from un-trusted sources.' In 2015, the increase in attacks targeting email is primarily about abusing those trust relationships. In 2016, other forms of trust are going to be under attack. Passwords stored in browsers, especially on mobile devices and 'Bring Your Own Device' phones and tablets will be a big target. 

The advice from Gary Warner, Chief Threat Scientist at PhishMe is that, "This year we need to be encouraging the adoption of two factor authentication and 'unknown device' alerting as never before – including on internal systems.  In another area of trust, a malware compromised workstation logs in to the corporate systems with the same power as an authorized user. Big data breaches are largely enabled by the concept that certain users should be allowed to 'See Everything' and this must be reeled back to 'see only some things' or 'see anything,' but only at reasonable volumes."

With increased reporting of suspicious activity, advances in threat analysis to enable better campaign identification, and raising the shield by challenging all of the 'trust' assumptions made, organizations can make 2016 a safer year.

Thursday, December 3, 2015

U.S. Presidential Campaign Will be Affected by a Cyber Attack, and Other 2016 Predictions


It's the of the year for predictions of how bad the security environment will be for the coming year.  Here are predictions from David Gibson, VP of strategy and market development at Varonis. By the way, focusing on end-user education and monitoring is long overdue. I don't think it's hyperbole to say, "Insiders are the new malware."

1. The U.S. Presidential campaign will be affected by a cyber attack.  
Hillary Clinton's private email server has already brought cybersecurity into the U.S. Presidential race. In 2016, a cyberattack will strike the campaign, causing a major data breach that will expose donors' personal identities, credit card numbers, and previously private political preferences. Imagine being a donor with an assumption of anonymity. Or a candidate whose “ground game” depends on big data analytics about voter demographics and factors affecting turnout – data that turns from an asset to a liability if it isn't protected. The breach will affect the campaign not only as a setback for the unfortunate candidate or party affected, but by bringing the issue of cybersecurity prominently into the campaign as a major issue that is closely related to geopolitical threats such as the spread of terrorism. Campaign data is a gold mine for hackers (donor lists, strategies, demographics, sentiment, opposition research), and an event like this will serve as another wake-up call to the U.S. government that cybersecurity needs to be a continual, central focus and investment at the highest levels. The candidate who demonstrates knowledge and command of cybersecurity threats and government readiness will win the election.
  
2. The frequency of public data breaches will increase substantially.
The Identity Theft Resource Center (ITRC) reports a total of 641 data breaches recorded publicly in 2015 through November 3. Most organizations know this number represents the tip of the iceberg. The frequency of known data breaches will increase in 2016, due not only to increasing privacy and breach disclosure laws but also the increasing failure of traditional perimeter-focused security investments to protect valuable data. Employees' use of mobile devices and companies' migration of IT workloads to the cloud will also contribute to a sharp rise in breaches. Over time, this should help to shift priorities toward investing in more proactive data-centric protection, but it's likely things will become worse before they get better.

3. End-user education and monitoring will become the focal point of data security efforts.
Insiders are the new malware. Executives and IT professionals are becoming as afraid of their own employees – as innocent vessels for outside attackers with dangerous levels of access to sensitive data – as they are of outside attackers. Companies will turn to the importance of end-user education in 2016 as they realize that, no matter how intensely they invest in security, they hit a dead end if their users don’t drive by the rules of the road. They need to be involved in the security processes, observe classification and disposition policies (that need to be defined) and know to stop clicking on phishing emails. Employees are crucial to the security process, and have more power in controlling it than they realize. You can't patch users but you can educate them. You can also monitor and analyze how they use data to spot unwanted attacks.

4. At least five more C-level executives will be fired because of a data breach.
In recent years we have seen the careers of several top executives suffer in the wake of cyber attacks. Target CEO Gregg Steinhafel and CIO Beth Jacob, U.S. Office of Personnel Management Director Katherine Archuleta, Sony Pictures' Amy Pascal and others were either fired or forced to resign after massive data leaks cost their organizations money, customers and credibility. This will accelerate in 2016.  Blame for data breaches is shifting from IT to the C-suite. Data impacts every facet of an organization. If management is not investing in and focusing heavily on securing data and its use, it is now understood that they are putting the entire company and its stakeholders at risk.

5. Increasing false positives in data security bring to light the need for limited, accurate information.
Organizations will get much more serious about how much data they collect and their deletion efforts. When Target suffered its massive breach during the 2013 holiday season, the alerting capabilities of its IT team had generated months of warnings.  Still, no one caught it. This remains a common problem today. Why? The plethora of security tools installed in most companies overwhelms IT security. Their teams are strapped and the amount of false positives generated by exponentially growing volumes of information cause these teams to miss crucial vulnerabilities. In 2016, smart IT teams will focus on signal-to-noise ratio improvements in the analysis and alerting solutions they deploy.

Monday, November 9, 2015

Anyone Hit by the Power Worm Will Lose the Data Forever

Today's news reports that a new kind of ransomware, called Power Worm, contains coding mistakes that means anyone hit by it will be unable to recover their files, even if they pay the ransom. The coding errors mean that the worm destroys the keys that could help recover any data that the worm did scramble.

Fred Touchette, Manager of Security Research at AppRiver has shared the following insights:

Q. Power Worm - could it be deliberate instead of a mistake?
"It’s unlikely that this was a deliberate mistake. Creating malware that simply destroys files would be much easier than adding that sort of "functionality" into an already complex ransomware variant."

Q. Linux.encoder - what makes this one different to all the others?
"One of the main differences is that it attacks websites. Until now the biggest target group was the home and business end user. It makes sense that this type of malware, including their potential targets, would continue to evolve."

Q. It feels as if there's been a spike in ransomware - would you agree? Any stats that substantiate this?
"There has been an obvious spike, but I don't have metrics specific to this type of attack."

Q. Why is ransomware increasing?
"Ransomware is increasing because it is working. Victims continue to pay these cyber criminals and in turn, the bad guys keep doing what's working so well for them."

Q. Should organizations ever pay a ransom? Assuming not, what should they do instead?
"No. Organizations should backup their files."

Q. What else can be done to rid yourself of ransomware? Is there anything?
"Yes, #1 back up your files. #2 Stop paying criminals. Avoiding 100% of the damage caused by ransomware is quite simple, by having a backup of one’s data, all that needs to be done in case of a ransomware infection is to restore said backups. Also, aside from ransomware attacks, there are a million other reasons that people should backup their systems, it’s kind of amazing that these attacks are working so well."

Monday, August 31, 2015

How to Solve the Five Biggest Email Security Problems

How to Solve the Five Biggest Email Security Problems

By now we all know that if email is not properly managed, it can cause major security headaches, including infected machines, system downtime and embarrassing data breaches. With nuisances such as spam being mostly blocked by anti-spam products, organizations need to focus their attention on other major security issues that are being less successfully defended against. But what are the biggest email security problems that companies face today and how can they be solved? This article discusses how to solve the five biggest email security problems, including the five biggest email security problems that are facing companies today. It also provides tips and advice on software that can help you better protect your company against email threats.

Wednesday, October 15, 2014

CryptoWall 2.0 Ransomware Moves to TOR Network


Dangerous new ransomware variant storms onto the scene using the anonymous TOR network, taking down systems and networks unlucky enough to be caught in its path

Tampa Bay, FL (October 15, 2014) KnowBe4  issued an alert to IT Managers that a  new version of the world's most widespread ransomware CryptoWall has migrated to the TOR network. It has been upgraded to version 2.0, and continues to encrypt files so that a ransom can be extracted if there are no backups or if the backup process fails, often a common occurrence.

KnowBe4, received a panic call from an IT admin who was hit this week with CryptoWall. The admin’s workstation became infected with the malware. The workstation was mapped to 7 servers and within an hour, the entire server farm was shut down. The admin explained he had backups but it would take days to recover the data and get them back up and running. The company’s operations would be severely impacted.

 “The cyber criminals hit pay dirt with this one and the admin ended up paying the ransom, 1.3 Bitcoin, rather than face the serious costs caused by days of downtime, said Stu Sjouwerman, KnowBe4’s CEO. “This is the next generation of ransomware and you can expect this new version to spread like wildfire.”

 CryptoWall 2.0 went live October 1st and is now using the anonymous TOR network, making it very difficult to analyze or take down. Earlier versions of CryptoWall were not using TOR but HTTP, which allowed researchers to analyze the communication between the infected machine and the command & control server so they could take down the servers that delivered the malware. This version of CryptoWall has been tested for months and the malware uses innovative ways to propagate itself, like using ads on websites that take advantage of  vulnerabilities in browsers and unpatched plug-ins.

Sjouwerman advises these three steps as something IT admins HAVE TO, HAVE TO do:

1. Make regular backups, and have a backup off-site as well. TEST your restore function regularly to make sure your backups actually work.

2. Patch browsers as soon as possible, and keep the amount of plug-ins as low as you can. This diminishes your attack surface.

3. Step all users through effective training on security to prevent malware infections to start with.

 For end users, Sjouwerman advises, “Think before you click. Don’t open anything from someone unless you are expecting it. Hover over an email address to make sure its from a valid domain, one you know and recognize.”

Monday, June 2, 2014

CISOs Reveal Top Firms Failing on Security Awareness Training



Is this a failure of will, or of process, or of failing to enforcement policies and procedures? There's something to be said about a draconian approach to enforcement. Touchy-feely really doesn't work.

With resources like these books available, there's no reason for this failure.

Managing an Information Security and Privacy Awareness and Training Program, Second Edition
Asset Protection through Security Awareness

Here's a partial list of available articles:

Why Information Security Training and Awareness Are Important

The ABCs of a Persuasive Security Awareness Program

Implementing an Information Security Awareness Program

Monday, April 1, 2013

It's Official. Consumers Don't Care Much Online Privacy

This interesting NY Times story  focuses on the reseach of Alessandro Acquisti, co-editor of Digital Privacy: Theory, Technologies, and Practices.

And, if they don't care much about their own privacy, they likely care less about security at work.

Wednesday, March 27, 2013

Tuesday, August 21, 2012

WeKnowYourHouse.com and PleaseRobMe.com

This is amazing. WeKnowYourHouse.com and PleaseRobMe.com. This is social media openness run amuck, and gives new meaning to "openness." Remember stories of robbers checking for wakes, funerals, and weddings to determine when no one will be home, and use that information to rob those houses. Why anyone would broadcast, or narrowcast, his or her location using something like foursquare or any location-based service is beyond me.

I'm also hearing stories of how people claim they're safe because they don't use social networking. Then, someone checks their kids Facebook page and see that daddy's going to Bentonville, Arkansas, Well, there's only one reason to go to Bentonville, and this knowledge could be corporate intelligence.

We're publishing a book on data anonymization, which deals with this from an enterprise perspective, particularly PII and PHI. Supposedly, 87% of US citizens can be linked using zipcode, data of birth, and sex. So, by using publicly available information such as voter records and supposedly clean data on health insurance, it's possible to identify and tie an individual to a health record. There are many good reasons why PHI, for example, needs to be private. Yet, it's remarkedly easy to get it.

I don't know why it's so hard to increase users awareness of the dangers of the Web, and their willingness to barter PII for free access. I guess it's the free part.