SPECIAL SUPPLEMENT BY
TRENDS FOR CYBER AND INDUSTRIAL SECURITY EXECUTIVES
APRIL 2019
ABDULLAH HAMOOD KHALID AL BARWANI, GENERAL MANAGER CORPORATE SECURITY
OMANTEL
ROLLING OUT A CYBER RESILIENCE PROGRAMME There are many areas that need to be protected and controlled, existing gaps closed, backup plans tested, and the organisation made cyber resilient.
Paul Potgieter, Dimension Data
Joe Baguley, VMware
USING AUTOMATION AND ORCHESTRATION TO TRANSFORM SECURITY
FIVE BASIC SECURITY TIPS TO REMAIN AHEAD OF THREAT ACTORS
Snehaa E, ManageEngine .
DEVELOPING A 360-SECURITY PROTECTION SOLUTION
Gamal Emara, Aruba HPE
Shyam Sundar, Valto
Firas Jadalla, Genetec
MONITOR NETWORK ALERTS LIKE YOUR JOB DEPENDS ON IT
USING A PROTECTED SHELL BROWSER TO ISOLATE RANSOMWARE
REDUCING LIABILITIES BY INVESTING IN CYBER INSURANCE
CONTENTS APRIL 2019
08
06
TOP OF MIND
TOP OF MIND
Developing a versatile 360-security protection solution
Using automation and orchestration to transform security
22
10
TOP EXECUTIVE
BUILDING OMANTEL’S CORPORATE SECURITY PROGRAMME
DEEP DIVE Using a protected shell browser to isolate ransomware
12
DEEP DIVE Monitor network alerts like your job depends on it
14
16
26
30
TRENDS
VENDOR TALKS
CHANNEL PARTNER
32
40 HANDS-ON
34
CISO’s left out of transformation, KPMG survey
Ensuring compliance and best practices in the Emirate
42 AFTER THOUGHT Why businesses should start embracing password-less
CHANNEL PARTNER
DEEP DIVE Reducing liabilities by investing in cyber insurance
03
A P R I L 2019
Protecting and securing transformed organisations
REAL LIFE
36 Python attack on Middle East government by Chafer
Epicor ERP Positioned as a Visionary in Gartner 2018 Magic Quadrant for Cloud ERP for Product-Centric Midsize Enterprises
MANAGING DIRECTOR: TUSHAR SAHOO
EDITORIAL
CEO: RONAK SAMANTARAY DIRECTOR: ANUSHREE DIXIT anushree@gecmediagroup.com
By around 2010, IDC was seriously talking about the role change of CIOs in the region. The fact that keeping the lights on would no longer be their key challenge and instead it would be about driving innovation. Close to a decade later, the real challenges are beginning to take shape. Cloud has extended the reach of business and its workers but has also vastly expanded its threat surface. The legacy abbreviation of BYOD or bring your own device has leapfrogged into tens and thousands of connected devices, working on the edge of networks. A new variable that has emerged, as integral to the success of digital transformation, is the role of the chief information security officer or CISO. Raising a key question: are the transformation strategies of the CIO and the CISO and the rest of the business heads all aligned? Or will the role of the CISO be brought in as an after-thought, in the entire gamut of transformational to-dos. According to the recent KPMG Consumer Loss Barometer report, covering 2,000 consumers and 1,800 CISOs, there is mismatch between the priorities of CISOs and consumers in the event of a breach. The report points out: that the continuous evolution of digital transformation is outstripping the pace of cyber security in organizations. As a result, we are witnessing a fundamental disconnect between consumer expectations and concerns, and the ability of organizations to meet those expectations. The learning curve: keep the CISO in the loop from day ARUN SHANKAR one, when you begin the process of digital Editor transformation. arun@gecmediagroup.com For Omantel’s General Manager of Corporate Security, Abdullah Al Barwani, digital technologies create a services eco system to reduce cost, reduce time to market, and have loyal happy customers. But does it impact the security surface of the organization? Generally speaking, digital transformation will increase the attack surface and exposure of the information assets to a wider audience. Hence, more controls are required to protect the organization, he points that out in our Top Executive section. With every business headed towards becoming a digital business, cyber security can no longer remain isolated from rest of the subsystems. Cybersecurity is therefore considered a subset of the digital environment. Moving ahead, we tackle some of the vexing CISO challenges and ask the vendors to give their recommendations for the following: How should CISOs protect and monitor cloud assets; and How should CISOs manage data compliance and data integrity. Also, included in this issue is a recap on the concluded Gisec 2019, which rose to the occasion in terms of thought leadership delivery and key note speakers. Watch these pages for our key takeaways made from onsite discussions during Gisec 2019. Happy reading and Ramadan Kareem. ! Arun Shankar arun@gecmediagroup.com. ë
EDITOR: ARUN SHANKAR arun@gecmediagroup.com SUB EDITOR: DIVSHA BHAT divsha@gecmediagroup.com EVENTS EXECUTIVE: SHRIYA NAIR shriya@gecmediagroup.com BUSINESS DEVELOPMENT EXECUTIVE: SUSAN PAUL susan@gecmediagroup.com GROUP SALES HEAD: RICHA S richa@gecmediagroup.com + 971 529 943 982
VISUALIZER: MANAS RANJAN LEAD VISUALIZER: DPR CHOUDHARY DESIGNER: AJAY ARYA ASSISTANT DESIGNER: RAHUL ARYA, DEEPAK KUMAR
SUBSCRIPTIONS INFO@GECMEDIAGROUP.COM SOCIAL MARKETING & DIGITAL COMMUNICATION YASOBANT MISHRA yasobant@gecmediagroup.com
DESIGNED BY
PRINTED BY AL GHURAIR PRINTING & PUBLISHING LLC. MASAFI COMPOUND, SATWA, P.O.BOX: 5613, DUBAI, UAE
I N FO M E DIA PUBLISHED BY ACCENT INFOMEDIA MEA FZ-LLC PO BOX : 500653, DUBAI, UAE 223, BUILDING 9, DUBAI MEDIA CITY, DUBAI, UAE PHONE : +971 (0) 4368 8523 31 FOXTAIL LAN, MONMOUTH JUNCTION, NJ - 08852 UNITED STATES OF AMERICA PHONE NO: + 1 732 794 5918 A PUBLICATION LICENSED BY INTERNATIONAL MEDIA PRODUCTION ZONE, DUBAI, UAE @COPYRIGHT 2013 ACCENT INFOMEDIA. ALL RIGHTS RESERVED. WHILE THE PUBLISHERS HAVE MADE EVERY EFFORT TO ENSURE THE ACCURACY OF ALL INFORMATION IN THIS MAGAZINE, THEY WILL NOT BE HELD RESPONSIBLE FOR ANY ERRORS THEREIN.
A P R I L 2 019
05
TOP OF MIND
USING AUTOMATION TO TRANSFORM SECURITY Security inside digital organisations can become more productive, predictable, consistent, cost effective, explains Paul Potgieter at Dimension Data. With the benefits of cloud platforms and mobility becoming increasingly obvious in the region, organisations have now started migration to digital platforms. While legacy businesses may require employees to work from office with limited amount of work and data portability, digital organisations offer their employees the flexibility to work from anywhere and with any device. This is tremendously changing the nature of employee productivity but is also putting stress on the organisational culture to adapt and change. As an offshoot, digital organisations are creating a more serious situation inside for the cyber security department. Security has continued to be paramount as large scale changes in the usage of IT platforms towards private, public, and hybrid cloud; distribution of data across multiple data centers; usage of customer data by third party suppliers; transformation of networks to allow upstream data from edge sensors; has in the short term exposed huge gaps in the fabric of organisational security platforms. Threat actors realising the existence of such widely exposed attack surfaces of organisations, have exploited these vulnerabilities through blended attacks. These blended attacks while not of highly sophisticated nature have used innovative social engineering and highly focused and personalised attempts to breach the organisational perimeter. Being an agile and digital organisation puts the responsibility of securing such an organisation back to the architects of the technology organisation. There is little business purpose of being an
PAUL POTGIETER, MANAGING DIRECTOR UAE, DIMENSION DATA.
innovative and pioneering digital organisation if all your doors are left open and flapping. All this learning has resulted in some positive changes. Security is now being included in agile software development, namely security
KEY TAKEAWAYS n
WITH CYBER SECURITY SKILLS IN SHORTAGE AND NO RESPITE IN SIGHT,
AUTOMATION AND ORCHESTRATION WILL HELP REDEPLOY RESOURCES. n
THREAT ACTORS REALISING THE EXISTENCE OF EXPOSED SURFACES OF
ORGANISATION HAVE EXPLOITED VULNERABILITIES THROUGH BLENDED ATTACKS n
BEING A DIGITAL ORGANISATION PUTS THE RESPONSIBILITY OF SECURING AN
ORGANISATION BACK TO THE ARCHITECTS OF THE TECHNOLOGY ORGANISATION.
06
A P R I L 2019
in DevOps. Security risk and compliance has become a Board concern. And equipment manufacturers have begun to accept responsibility for incorporating security during product development in a more systemic manner. But the real ray of sunshine is the arrival of automation and orchestration capabilities inside the realm of security systems. Security automation is the computerisation of a manual task across one or multiple security tools, so that they can be executed automatically, faster and without any delay once initiated. Security orchestration on the other hand is about automation of multiple tasks, processes, and workflows across siloed, security subsystems, making them work as an integrated holistic system. The time spent on managing individual subsystems can now be better deployed into monitoring a complete system end to end, that is automated and orchestrated. With cyber security skills in a long-term shortage cycle and no short-term respite in sight, automation and orchestration will help redeploy costly resources into more strategic roles rather than operational. With this approach, security inside digital organisations becomes more productive, predictable, consistent, and cost effective. Heads of security can choose to start automation and orchestration in any of the following areas: l Threat monitoring: visibility into threat landscape l Incident response: following up on incidents l Security lifecycle management: offloading patch management, reporting l Operational efficiency: repeatable and measurable processes The real gains for the organisation are when processes that do not require human intervention, are time consuming, fragmented, and free up resources, are targeted for automation and orchestration. This is where human skills can generate large scale return and monetary benefits for the organisation. ĂŤ
TOP OF MIND
DEVELOPING A 360-SECURITY PROTECTION SOLUTION Here are six definitive steps implementing versatile security covering networks, applications, end points according to Snehaa E, at ManageEngine. Every IT administrator has succumbed to at least one sleepless night from worrying about data security and fearing the outcome of a security breach. Overthinking is second nature to humans, but there would be one less problem to worry about if we found a permanent fix for cyberattacks. But is there a cyberdefense strategy out there that is completely foolproof? One that keeps all cyberattacks at bay? No, a perfect strategy does not currently exist, but that does not have to stop us from striving for a well-rounded one. Understanding the nature of attacks and employing different security solutions to cover all bases will help us approach the ideal security strategy. So, where do we start? You should opt for a combination of network security solutions and endpoint management solutions. This combination will provide robust protection against most known cyberattack variants. Let us break down these solutions’ components to get a better understanding of how they keep cyberattacks at bay:
#1 FIREWALL Setting up a firewall for your organisation forms the first line of defense against malicious network connections. A firewall controls incoming and outgoing traffic, and protects your network based on a defined set of security rules. You can adjust your security rules to allow outgoing traffic from particular applications while preventing incoming traffic for certain applications. Combine a firewall with an intrusion prevention system that selectively prevents
server acts as a gateway between your network and the Internet. Configuring your proxy to block known malicious websites helps protect your network from malware, phishing, and other cyberattacks.
#3 INVENTORY Taking inventory of all the devices that are present in your organisation helps you identify devices that should not be present. You should also identify the applications and software that these devices use.
# APPLICATION CONTROL Blacklisting unwanted or possibly malicious applications reduces the opportunities for data to be lost or stolen.
#5 PATCHES
SNEHAA E, MARKETING ANALYST, MANAGEENGINE.
threats or controls applications based on the type of firewall.
#2 PROXY Configuring a proxy server forms the next line of defense in cybersecurity. Whereas a firewall detects and blocks certain network traffic, a proxy
KEY TAKEAWAYS n
TRADITIONAL ENDPOINT MANAGEMENT SOLUTIONS DO NOT EXTEND THEIR
PROTECTION TO BROWSERS. n
SETTING UP A FIREWALL FORMS THE FIRST LINE OF DEFENSE AGAINST MALICIOUS
NETWORK CONNECTIONS. n
CONFIGURING A PROXY SERVER FORMS THE NEXT LINE OF DEFENSE IN
CYBERSECURITY.
08
A P R I L 2019
Consistently patching the software used in your infrastructure is crucial for eliminating potential attacks that occur through vulnerabilities present in outdated versions of software.
#6 ANTIVIRUS Using antivirus software stops known malware from being installed on your endpoints. Antivirus software also typically scans downloads for malware and blocks malicious executable files from being downloaded. With the complexity of cyberattacks steadily increasing, the most common attack vector into an organisation is shifting towards browsers and since browsers are an integral part of today’s mobility-first, cloud-based world, this trend will only continue to increase. So, here is the final step to realising your ideal security strategy: implement a dedicated solution that scans for and secures all the loopholes present in your browsers, monitors and controls the add-ons used by your browsers, and controls the traffic accessed through your browsers. With a browser security solution, you will round out your security strategy, ensuring that you have fortified your enterprise’s defenses against cyberattacks. ë
DEEP DIVE
USING A PROTECTED SHELL BROWSER TO ISOLATE RANSOMWARE Daniel Miller from Ericom Software and Shyam Sundar from Valto Information Technology, explain how to contain browser triggered ransomware malware.
Imagine coming into the office and booting up your computer, but instead of your usual desktop screen you are greeted by a red page with the message: Your personal files have been encrypted! The page explains that you need to pay the specified ransom in bitcoin to get your files decrypted. If you do not respond within 3 days, the price doubles; if you do not respond within 7 days, your data is lost forever. Worse yet, it is not only your computer that has been affected: it is every
DANIEL MILLER, SENIOR DIRECTOR OF PRODUCT MARKETING, ERICOM SOFTWARE.
10
A P R I L 2019
computer on the company’s network. Ransom demands in the tens of thousands of dollars are common; demands in the millions are not unheard of. Are you prepared for such a scenario? Do you know how to prevent it?
WHAT IS RANSOMWARE? Ransomware is a modern version of the old protection racket. In the pre-technology version, you
paid money to thugs and in exchange they did not throw rocks through your windows. In the modern version, you pay money to cyber-thugs so that they let you make use of your own data. Ransomware is a very big problem: one cybersecurity research firm estimated the costs of ransomware in 2018 as exceeding $8 billion. Europol, the EU’s law enforcement agency, said in a report on organised crime that, Ransomware remains the key malware threat in both law
SHYAM SUNDAR, BUSINESS DEVELOPMENT MANAGER, VALTO INFORMATION TECHNOLOGY.
DEEP DIVE
CONVENTIONAL APPROACHES AGAINST RANSOMWARE ARE NOT GOOD ENOUGH. enforcement and industry reporting. In recent months, ransomware attacks have disrupted public sector organisations and hospitals as well as ordinary businesses. And to add insult to injury, paying the ransom does not guarantee you will get your data released: according to one survey, in 30% of cases where victims paid the ransom, the bad guy still did not release their data.
HOW DO YOU PROTECT YOUR ORGANISATION FROM RANSOMWARE?
KEY TAKEAWAYS n
RANSOMWARE IS A MODERN
VERSION OF THE OLD PROTECTION RACKET. n
RANSOMWARE REMAINS THE
KEY MALWARE THREAT IN LAW ENFORCEMENT. n
RANSOMWARE CAN ALSO BE HIDDEN
IN FILES THAT A USER DOWNLOADS FROM THE WEB. n
USE A METHOD THAT DOES NOT RELY
ON IDENTIFYING MALWARE SUCH AS REMOTE BROWSER ISOLATION. n
42% WERE ABLE TO RESTORE 100%
OF THEIR LOST DATA FROM BACKUPS AFTER A RANSOMWARE ATTACK.
The traditional tools for protecting against ransomware are based on a find and block or destroy technique: firewalls, antivirus, antimalware software, and secure web gateways are based on identifying malware and either blocking it from getting through to the endpoint device or destroying or disabling it. These tools rely on a combination of regularly updated databases of known threats and heuristic analysis, which applies various algorithms to detect threats that aren’t in the database. There are two problems with databases: l If your database is not absolutely up-to-date, new malware will not be caught l They afford no protection against zero-day threats, brand new attacks that have not been seen before. Thousands of computers and networks can be infected on the first day a new type of malware is released, before it can be identified, and antivirus databases can be updated. That is why antivirus software often includes heuristic analysis as well, to try and identify malware that is not in the database. Unfortunately, cyberthieves are often able to mask their activities and slip past these defenses. Conventional approaches to protecting an organisation against ransomware and other types
of malware are not good enough. Some attacks can still get through.
WHAT ABOUT BACKUPS? You follow good IT practices and make frequent backups of your data. Can you not just ignore the ransomware and simply restore everything from a backup? Unfortunately restoring from a backup does not always go smoothly. One survey found that even though most companies do regular backups, only 42% were able to successfully restore 100% of their lost data from backups after a ransomware attack. And what if your backup is infected too? Unless you have offline backups, your backups are likely also encrypted. And offline backups generally are not real time so you will inevitably lose some data.
WHAT IS THE SOLUTION? The only way to have full ransomware endpoint protection is to use a method that does not rely on identifying malware as the first step, such as Remote Browser Isolation. An RBI solution isolates all web browsing in a separate safe server, away from the organisation’s network. When a user opens a browser or clinks a link in an email, the browser is opened in a one-timeuse remote container. The user sees a dynamic image of the website – the actual code on the website never reaches the endpoint device. If a site is infected, the malware or ransomware cannot spread outside of the one-time-use container, which is destroyed when the browsing session is over. Ransomware can also be hidden in files that a user downloads from the web. Some solutions come with built-in file cleansing technology to protect against those threats as well. When a user downloads a file, it is scanned and sanitised remotely before being downloaded to the user’s computer or other device. In a world where malevolent hackers are growing increasingly sophisticated, the conventional approaches to protection against ransomware and other forms of malware are no longer enough. Standard best practices such as firewalls, antivirus software, and regular backups do not guarantee protection. A remote browser isolation solution, that does not rely on detection, offers a much greater degree of security from malicious ransomware. ë
A P R I L 2 019
11
DEEP DIVE
MONITOR NETWORK ALERTS LIKE YOUR JOB DEPENDS ON IT With growing accountability for breaches attributed to CISO failure, monitoring of network alerts is a good start, writes Gamal Emara at Aruba HPE.
GAMAL EMARA, COUNTRY MANAGER UAE, ARUBA HPE.
12
A P R I L 2019
DEEP DIVE
It is your worst possible nightmare. A hacker has breached the company’s network and shut down its operations. Millions in revenue is being lost. And the even worse part is you are blamed. This is becoming an all too familiar scenario for CIOs and CISOs tasked with securing their companies’ networks. No sooner have they entered an organisation and put security systems in place, then they find themselves blamed for a successful breach of the company. So, where does it all go wrong?
NETWORK VISIBILITY IS NOT A NICE-TO-HAVE Most CIOs or CISOs allocate their funding towards securing their datacentre. However, when it comes to implementing a system that provides them with full visibility of their network, they consider it simply a nice-to-have. They implement basic security elements like a firewall and assume they will be okay. But, in reality, should an attack happen at the edge of the company’s network, the only way they can possibly know is by doing a deep dive to investigate each and every occurrence that might indicate a breach. We all know this simply is not possible though. When a user is locked out of their account, the IT department will rarely ever take the time to investigate why. They simply unlock the account and move on to the next problem. It is true that when a user is locked out, it might be because they forgot their password, but it could also be an indication of something far more sinister.
EVERY LOCK-OUT IS A POTENTIAL ATTACK
KEY TAKEAWAYS n
AN END-TO-END SYSTEM THAT
CAN DETECT ATTACKS AND RESPOND RAPIDLY IS VITAL. n
THE SYSTEM NEEDS TO COVER
ENTIRE NETWORK FROM DATACENTRE TO THE EDGE. n
67% OF CRITICAL INFRASTRUCTURE
SUFFERED AT LEAST ONE ATTACK DURING 12 MONTHS.
A recent case, where a client kept on getting locked out of their system. Not realising there was a problem, they kept unlocking the system and moving on. That is until one Sunday morning when around 1,000 lock-outs occurred simultaneously. On taking the matter up it was discovered these lock-outs were a direct result of hackers attacking the network in order to access sensitive information. And, the most concerning part of all this was that the devices being used to launch the attacks were, in fact, the company’s own devices. On investigating further, it was found these devices had actually been stolen some time ago.
YOUR GREATEST VULNERABILITY IS UNGUARDED So, while CIOs essentially have no idea if and when attacks are happening at the edge, this
is exactly where an organisation’s greatest vulnerability lies. Think of the average digital environment today – thanks to IoT, there are more connected devices than there have ever been before. Each device is a potential gateway for a major breach. And think of the consequences of the massive data breaches which have been occurring across the world. Millions are being lost on a regular basis. One only needs to take a look at the statistics to see the odds of escaping one of these attacks are not good. In fact, according to the 2016 Global Megatrends in Cybersecurity report, 67% of companies with critical infrastructure suffered at least one attack during the course of those 12 months.
HOW CAN CIOS AND CISO’S SECURE THEIR POSITIONS? The only way a business can possibly remain secure under these circumstances is if the CISO or security team receives notifications as soon as something occurs on the network that is deemed to be out-of-the-norm. Essentially an end-to-end system that can detect attacks and respond rapidly is vital. And it needs to cover the entire network from the datacentre to the edge. A combination of a network access control solution that is device agnostic, and covers everything from a company’s vending machine to industrial IoT equipment, combined with an analytics solution that sits on top of a company’s security solutions, for example its firewall. Based on its analyses of these security solutions, the analytics technology creates profiles for individual users. Then if activity takes place on the network which is outside of a user’s typical profile, it immediately alerts the security officer. Say for example, a particular user typically logs into the company network from UAE between 08h00 and 22h00, but then one day that user logs in from Russia at 02h00, the analytics solution will immediately know something is wrong. And it can take this analysis as far as detecting when a user is typing more slowly to how they would normally. Then once the analytics technology identifies a network intruder, the network access control solution automatically logs them off from the network. Combined, these two technologies effectively ensure CIOs have, not only visibility, but also complete control of their entire network. It is the only way to truly ensure you are not the next CIO a network breach sends packing. ë
A P R I L 2 019
13
DEEP DIVE
REDUCING LIABILITIES BY INVESTING IN CYBER INSURANCE If your organisation invests rigorously in cybersecurity compliance then cyber insurance is a logical next step, says Firas Jadalla at Genetec.
FIRAS JADALLA, REGIONAL DIRECTOR MIDDLE EAST, TURKEY AND AFRICA, GENETEC.
14
A P R I L 2019
DEEP DIVE
Business insurance and other forms of insurance are nothing new to most organisations. However, as risks have evolved into the cybersphere, insurance policies and products have too. Today, there are over 100 insurance companies worldwide offering cyber liability policies which help to absorb the risks for their customers who experience a breach or who fail to comply to evolving legislation. In fact, experts estimate the global market value for written cyber liability policies to be around $2.5 billion. Yet, insurance providers such as Allianz predict that this figure could reach $20 billion by 2025.
KEY TAKEAWAYS n
ESTIMATED GLOBAL MARKET VALUE
FOR WRITTEN CYBER LIABILITY POLICIES TO BE AROUND $2.5 BILLION. n
INSURANCE PROVIDERS SUCH AS
ALLIANZ PREDICT THIS FIGURE COULD REACH $20 BILLION BY 2025. n
THE BIGGEST BENEFIT DERIVED
FROM THIS INSURANCE IS PEACE OF MIND SHOULD A BREACH OCCUR. n
IT IS ALSO A GREAT WAY FOR
SECURITY PROFESSIONALS TO STRENGTHEN CYBERSECURITY POSTURE. n
COVERAGE IS ONE ASPECT TO
CONSIDER WHEN SHOPPING FOR A CYBER LIABILITY INSURANCE POLICY AND CLAIMS PROCESS IS ANOTHER. n
SINCE CYBER LIABILITY INSURANCE
IS A NEW PRODUCT, THERE ARE STILL MANY UNKNOWNS FOR INSURERS>
On one hand, these policies help mitigate risk and uncertainty. In the event of a security breach at a client site, a cyber liability insurance policy will give integrators peace of mind. The systems integrator company will be able to access funds to manage response and keep the business running. On the other hand, these policies are requiring companies to follow strict cybersecurity protocols. That is because to become eligible for the policy, the integrator must prove that they are adhering to advanced cybersecurity standards and measures. Even when the policy is active, should the integrator make an insurance claim, they will need to show that all cybersecurity best practices were implemented from the project’s start, or the claim could be denied. Since cyber liability insurance is a new product, there are still many unknowns for insurers on how to properly assess and calculate risks. Usually, costing out coverage involves filling out a standard questionnaire on IT policies, organisation hierarchy, IT infrastructure size and the nature of the business. In many cases, insurance providers will tend to overestimate liability and keep premiums high. Even so, integrators cannot wholly rely on this insurance to save them from unexpected cyber threats. It is critical that they continue to maintain the highest standards of cybersecurity at each client site. These include implementing various levels of defense such as encryptions, authentications, and authorisations. It should also include employing various tools to better protect data privacy and properly installing devices using strong passwords. System integrators should take time to properly vet suppliers and select partners who are prioritising the cybersecurity in the development of their products. They must stay on top of updates and patches, ensuring their clients are working with versions which have addressed any known vulnerabilities. It is also important they take a more active role in educating their clients’ employees, proving general guidelines which can help them avoid unnecessary risks. Key considerations when buying cyber liability insurance:
#1 IDENTIFYING THE CYBER RISKS Since cybersecurity can encompass a lot of different facets, so can the liability insurance. Experts suggest that there are as many as 12 different types of coverage are available for various triggers. That is why it is critical to have a clear understanding of the cyber risks for which your organisation needs protection. These can include a range of online and offline
risks, spanning everything from data breaches to theft of corporate assets. When an integrator company can be very specific about the potential pitfalls they need to address, they are in a better position to find the policy that will match their organisation and needs.
#2 UNDERSTANDING THE POLICY COVERAGE Cyber liability insurance does not need to stand alone. Existing insurance policies might be very complementary to these new cyber policies. Some business might also require a combination of products to get adequate coverage. That is why it is important to understand how each product could benefit an organisation should they become liable for a data breach. Furthermore, the damages resulting from cyber liability can be difficult to quantify and grasp. Translating cyber risks into a financial model is a key step in ensuring adequate coverage. While cybersecurity remains a business risk, the cyber-relevant aspects should be studied and articulated by a cybersecurity professional. It is in an integrators best interest to seek guidance from a professional broker or field expert who understands both worlds of business and cybersecurity risks.
#3 KNOWING THE CLAIMS PROCESS Coverage is one aspect to consider when shopping for a cyber liability insurance policy. The claims process is another. Generally, an integrator can expect to receive monetary compensation when a claim is approved, which is helpful. However, each insurance provider will have a process in place for vetting the claim’s authenticity, and a general timeline for which funds can be paid. If a data breach happens, an integrator should know how quickly relief will become available. Also, some insurance companies provide access to other expert services such as cyber investigators or public relations firms. While an integrator might be busy managing response to a breach, the extra assistance during this time could be a welcomed perk. The prevalence of cybersecurity threats will only increase as the Internet of Things gains more momentum. It is why all organisations including security system integrators must do their due diligence and look into cyber liability insurance. The biggest benefit derived from this insurance is peace of mind should a breach occur. However, it is also a great way for security professionals to strengthen their cybersecurity posture. ë
A P R I L 2 019
15
TRENDS
HUMAN FACTOR REVEALED WEAKEST LINK IN GISEC 2019 Gisec 2019 demonstrated that with continuing sophistication into cybersecurity solutions, the human factor will remain isolated as the weakest link.
Dr Marwan Al Zarooni, Director of Information Service Department at Dubai Electronic Security Centre, at Gisec 2019.
Gisec 2019 was officially opened by Her Excellency Dr Aisha Bint Butti Bin Bishr, Director General of Smart Dubai. It is the largest cybersecurity event in the Middle East, Africa and South Asia. Supported by Dubai Electronic Security Centre, Dubai Police and Smart Dubai, the annual cybersecurity meet aims to unravel the complex web of cyber security, attracting an audience of industry experts and business leaders. At the event, more than 170 companies from over 86 countries showcased their products and services to meet the growing demands for cybersecurity solutions in the region and beyond. Key stands included Dubai Electronic Security Centre, Dubai Police, Nedaa, as well as Spire, Huawei, Proofpoint, SAP, Carbon Black, Crowdstrike, Vodafone Business, Etisalat Digital, Recorded Future and Tahaluf Al Emarat Technical Solutions, amongst others. The Middle East and Africa cybersecurity market is forecast to reach $34.6 billion by 2023, at a CAGR of 15.6%. Two of the world’s most famous hackers, Kevin Mitnick, once on the FBI’s Most Wanted list after hacking more than 40 major corporations and Jamie Woodruff, Europe’s top ethical hacker renowned for hacking Kim Kardashian’s website, as well as that of Google, Microsoft, Facebook and Twitter, were the draw for Gisec’s first ever Dark Stage for groundbreaking hacking expertise. The Dark Stage is an open forum to deep dive
16
A P R I L 2019
Her Excellency Dr Aisha Bint Butti Bin Bishr officially inaugurates Gisec 2019.
into the dark web and perform live hacks exposing potential threats this new platform poses. More than 200 talks, briefing sessions and live hacking demos were completed at this forum. One reoccurring theme however stood out: human error remains one of the largest obstacles to cyber security. Leading experts have warned that human error continues to play a significant role in cyber security and online crime, requiring a strategic approach to educate users and employees to prevent companies and individuals from falling victim to cyber-crime. Jamie Woodruff, the Ethical Hacker reemphasised how humans are often at the heart of both on and offline crime. People are much more susceptible through social engineering to attacks than they are in person. Vulnerabilities of businesses exist a lot of the time through their employees, and social engineering allows us to observe and learn their patterns, allowing entry into the company, a technique that can have dire consequences, Woodruff pointed out. Providing an apt example, one of Woodruffs anecdotes included one of his ethical hacking projects in which he gained access to the server rooms of a London-based banking institution. To do so, the expert hacker had to intercept phone conversations and CCTV cameras. Observing the bank and its employees for a whole month, he gained entry by dressing up as a pizza
delivery driver. With unrestricted access to the IT infrastructure, said Woodruff, the consequences for the bank and its customers could have been disastrous. Woodruff live-hacked the CCTV camera of a nuclear plant. He also obtained the two-year payment history of ten volunteers that took to the stage with their contactless credit cards – data he compromised within seconds – and showed how children toys, car keys and smart watches are all open to attack. US-hacker Kevin Mitnick, warned on the same topic that when teaching staff about security, companies need something relevant, entertaining and informative, not a boring book that they will not read. You need to educate, train and inoculate your users. The hacker is always going to go after the weakest link, and social engineering is the easiest way in and easiest attack your enemies will use today. Mitnick opened with a stark warning to the region’s businesses: make your staff hackconscious, or it could bring your company to its knees. Flown in from the US specifically to present at Gisec, Mitnick, 55, saw him demonstrate the ease with which someone could plunder information online to impersonate another and go on a hacking spree. His prime method is social engineering, which is a form of hacking that relies on influence, deception and manipulation to
TRENDS
At the Dubai Electronic Security Centre booth at Gisec 2019.
US-hacker Kevin Mitnick, said when teaching staff about security, companies need something relevant, entertaining, informative.
Jamie Woodruff, Ethical Hacker emphasised how humans are at the heart of both online and offline crime.
The Gisec agenda is directed by an advisory Board of senior end users and attracts an audience of decision makers.
convince another party to comply with a request in order to compromise their computer network. In live examples, Mitnick managed to obtain confidential email data that would have allowed him to penetrate a local bank. He also burrowed his way through Google Mail accounts and LinkedIn, live on stage. And while his more in-depth investigation was performed using a number of pieces of intricate computing soft and hardware, he was absolutely conclusive in saying that the main point of weakness for any company lies in poor cybersecurity awareness in staff. He said: People are not being trained about how to defend their workplace from these
attacks. If they are, then they are not listening. These social engineering tricks worked in the 1970s and still work in 2019. People are way too polite. Experts agree that the human factor remains a key obstacle for cyber security. Ankush Johar, Investor at HumanFirewall and a cyber-security authority, said there are over 20,000 types of attacks. Given those numbers, training employees to successfully identify them remains a huge challenge and leaves us prone to human error. One of the keys is to alter the psychology of employees and make them suspicious by nature. Emile Abou Saleh, Regional Director, Middle
East and Africa, Proofpoint said, cyber-criminals take advantage of the human factor to execute their campaigns. Companies need to ensure they deploy effective security awareness training to educate employees for best-practices, as well as establish a people-centric strategy to defend against threat actors’ unwavering focus on compromising end-users. The Gisec agenda is directed by an advisory Board of senior end-users from Dubai Electronic Security Centre, Dubai Police and Smart Dubai, and attracts an audience of decision makers from 200 government departments and leading enterprises in the Middle East. Í
A P R I L 2 019
17
Discover the Edge.
Smart Solutions. Real Business. Rittal solutions for the technology of the future. Edge computing enables enormous amounts of data to be processed directly at the place where they arise. Securely and in real time. Rittal prepares you and your IT infrastructure for new challenges - exibly, economically, and globally.
Visit us at
Sheikh Rashid Hall Stand SR-E2
For Enquiries:
Rittal Middle East FZE Tel: +971-4-3416855 I Email: info-it@rittal-middle-east.com I www.rittal.com/uae-en
TRENDS
GISEC 2019 COMMENTARY
MACHINE LEARNING APPLIED TO SECURITY TELEMETRY
SANS ADDRESSES CHALLENGES OF IT AND OT CONVERGENCE
DRAGAN PETKOVIC,
DOUG WYLIE,
SECURITY PRODUCT LEADER ECEMEA, ORACLE.
DIRECTOR OF SANS INDUSTRY PRACTICE AREA.
Oracle and KPMG recently published the Cloud Threat Report 2019. Industry estimates put nearly half of all security breaches down to inadvertent human error. Email phishing took the top spot as the attack vector that was experienced most often during that period. The inability to analyse and respond to security events is a long-standing issue and one that has been at the centre of numerous prominent data breaches. Only one in ten participating organisations are able to process over 75% of their security event data. As such, the vast majority of companies currently lack visibility by being unable to process the growing stream of security event telemetry. However, new and perennial security issues can be addressed with automation and machine learning, which promises to improve operational and threat detection efficacy. Machine learning is now incorporated into seemingly every new cybersecurity control intended to protect core-to-edge applications and data assets from compromise. More than half of the respondents report they are using machine learning technology for cybersecurity purposes to some degree, up from 47% in 2018. 25% of research respondents cited the ability of machine learning to detect new and unknown zero-day threats as a primary benefit of machine learning. No cloud service should be without data encryption. Encryption is one of the easiest technical controls to implement and a number of organisations opt for it as a quick win since it requires minimum human intervention. It has been used for decades and it is a matter of concern that some organisations are still not using it to protect their confidential data.
Each SANS Industrial Control System, cybersecurity course has been intentionally designed from the ground up to educate, IT and operational technology convergence as an essential risk management topic that spans people, technology and processes. Each Industrial Control System course covers to varying degrees relevant, control and IT system architectures, technical designs, configuration challenges, and technical and non-technical risk management strategies that today’s control systems face. These are core and fundamental building-blocks of all SANS Industrial Control System cybersecurity courses. Each course and our instructors alike take into account that students come from a one or both IT and operational technology domains. As one example of how the topic of IT operational technology convergence topic is addressed, consider the SANS ICS410 ICS SCADA Security Essentials course. ICS410 was intentionally designed, and it is delivered in a way that provides specific training to security professionals and practitioners who must deal with both operational technology and IT domains. These are individuals who often carry direct responsibilities for the operational integrity of systems, including the effects of one system onto another. SANS has already trained thousands with this course, and our ICS410 student mix is a balance of IT, operational technology and IT operational technology hybrid roles. The ICS410 course is complemented with the Global Industrial Cyber Security Professional certification that provides an accredited means for students to demonstrate they have built skills and an understanding of the importance of IT operational technology convergence to today’s industrial control systems.
A P R I L 2 019
19
TRENDS
GISEC 2019 COMMENTARY
PRODUCT INNOVATION WITH CUSTOMER FOCUS
B ROBERT RAJA,
CEO ODYSSEY TECHNOLOGIES.
Odyssey Technologies participated at Gisec 2019 where it launched its latest software offering styled Xorkee, a key routing framework for authentication, encryption and digital signatures. Xorkee breaks new ground on several dimensions. For the first time, users get to connect their cryptographic tokens to mobile phones using the USB-OTG feature available on most smart phones. To sweeten this still further, the connection is driverless and compatible with most brands in the market and works on PCs and phones identically. An even bigger advantage of Xorkee is that it separates the security channel from the transaction channels making it usable for multiple applications with a uniform and simple interface. The end user experience is the same across applications making user education absolutely simple and eventually unnecessary. Xorkee infrastructure complements the ones existing
today like the PKI or other key management frameworks. Xorkee’s key routing has been implemented with the emerging privacy and encryption needs of the Internet user in mind and helps organisations to implement a user consent layer for better compliance with various data security regulations in most countries. Odyssey offers a bouquet of products for authentication, digital signatures and encryption including format preserving encryption models running on the Xorkee framework. For the users who have been grappling with the complexity of implementing large PKI based applications, OTP applications or biometric and other authentication solutions, the working of Xorkee is a relief. Odyssey believes that Xorkee represents a paradigm shift in security and will de facto become the universal model over the next two to three years.
EXPERTISE IN FINDING VULNERABILITIES
UMESH THOTA,
FOUNDER AND CEO, AUTHBASE.
AuthBase is a cybersecurity company that provides frameworks to help developers secure their applications by finding, fixing and monitoring the web, mobile and networks against current and future vulnerabilities. “We are a three-year-old company. We are into the cybersecurity domain and use deep learning to identify threats and then mitigate them,” said Umesh Thota, Founder and CEO, AuthBase. When a threat is identified, system is locked by signatures and passwords due to which firewalls or antiviruses do not work. Umesh says, “We have an AI that identifies the threats without them. It is able to understand the
behaviour of a network and the machine. We use those behaviours to identify threats across the networks or machine and block those causing harm to the network.” Being a start-up in the industry, Umesh believes that if you have an interesting use case and problem area to solve, the size of the company does not matter. With regards to Gisec 2019, Umesh says, “Gisec 2019 is one of the events where friends and competitors meet. Cyber security domain is the only area where you interact with your competitors with the same joy like your friends. So, it is always mutual learning and we are happy to be a part of this show.”
DEFENCE IN-DEPTH APPROACH The growing number of businesses attract attackers who tend to use the brand value of a company for their benefit. One of the major channels they use to attack is email. The majority of the cyberattacks begin with one simple phishing email. ProDMARC analytics platform has been setup by ProgIST, a new age cyber security firm. ProDMARC has been built with a mission to achieve secure and spoofing free email channel across the Internet space. At Gisec 2019, the company showcased their email security solution.
CHAITANYA RAO,
FOUNDER, PRODMARC.
20
A P R I L 2019
ProDMARC stops domain spoofed phishing attacks by automating the process of Domain-based Message Authentication, Reporting and Conformance email authentication. It helps protect customers from cyberattacks, maintain trust in the brand and improve digital communications, says Chaitanya Rao, Founder, ProDMARC. The company plans to have a local office soon and is also in search of new partnerships at the event. RAK Bank, Network International, are its in-country customers.
Protect Your Information Wherever It Travels
Data Classification, DLP, and CASB only solve part of your data security challenge. Seclore Data-Centric Security makes it easy to unify your best-of-breed solutions and automatically add granular usage controls as information is discovered, classified, and shared. Ensure your information is protected and trackable wherever it travels with Seclore.
We look forward to showing you Seclore Data-Centric Security in action during the Future of IT Summit 2019, Dubai
www.seclore.com
TOP EXECUTIVE
BUILDING OMANTEL’S CORPORATE SECURITY PROGRAMME In large organisations like Omantel, there are many areas that need to be protected and controlled, existing gaps closed, backup plans tested and ready, and the organisation made cyber resilient.
n B Y: D I V S H A B H AT < D I V S H A @ G E C M E D I A G R O U P. C O M >
F
or chief information security officers, working in large organisations like Omantel, there are many areas that need to be protected and controlled. The plan is to be proactive, close as many gaps as possible, and develop backup plans for all types of identified and unknown contingencies. As the General Manager of Corporate Security at Omantel, Abdullah Hamood Khalid Al Barwani’s role is to establish and maintain the organisation’s security programme. This includes setting up the right procedures and technical controls to minimise cybersecurity risks inside Oman’s national telecom operator. For an organisation like Omantel, hiring and training qualified resources is essential. Another key requirement to manage pan-organisational cybersecurity risks is to develop strategic alignments and partnerships. Abdullah Al Barwani stresses that the most important and critical aspect of his job role is to be prepared and cyber resilient. “As cybersecurity risks are becoming universal and complex in nature, collaboration is required to mitigate more advanced risks,” he says. “Cybersecurity risks are universal in nature and could happen anytime and anywhere. Hence the cybersecurity professional needs to be always alert and prepared.”
22
A P R I L 2019
To manage any type of incident, organisations need security professionals who are well qualified and experienced to handle such challenges, as well as having the right tools. After the incident is over, the work of such professionals does not end, and the work of putting the house back in order begins. A key part of the success is to have well defined cyber security policies, processes and procedures in place, that are regularly updated based on the cybersecurity risk profile. “All the above require very stringent policies that are fine-tuned in short time spans to accommodate the everchanging cyber risks,” explains Abdullah Al Barwani. Going forward, the best way to combat security risks in the future is to consider security-by-design in future technologies. With this, the control lies within the technology itself and no additional controls need to be added to the architecture. Also, cloud security-as-a service offering is going to be the best choice for customers for two reasons. One reason is that risks are becoming more complex and the second reason, is due to scarcity of skilled security resources. Even with these two measures, namely security-by-design and cloud security, strong governance and know-how are still required in any large organisation.
TOP EXECUTIVE
ABDULLAH HAMOOD KHALID AL BARWANI,
GENERAL MANAGER CORPORATE SECURITY AT OMANTEL.
A P R I L 2 019
23
TOP EXECUTIVE
SECURITY GAPS
MY TOP CHALLENGES
In large organisations, identifying security gaps and risks is a difficult task since you would naturally have dispersed infrastructure, teams and applications especially when you operate an international company.
SECURITY CULTURE
LEGACY SYSTEMS
Legacy systems and applications are always a challenge to secure since they do not comply to modern standards and technologies. Sometimes it is a high risk to even try to scan them for security vulnerabilities.
KEY TAKEAWAYS n
CYBERSECURITY RISKS ARE
UNIVERSAL IN NATURE AND COULD HAPPEN ANYTIME AND ANYWHERE. n
THE CYBERSECURITY
PROFESSIONAL NEEDS TO BE ALWAYS ALERT AND PREPARED. n
THE MOST IMPORTANT AND
CRITICAL ASPECT OF THE JOB ROLE IS TO BE CYBER RESILIENT. n
WITH EVERY BUSINESS HEADED
TOWARDS BECOMING A DIGITAL BUSINESS, CYBER SECURITY CAN NO LONGER REMAIN ISOLATED. n
DIGITAL TRANSFORMATION WILL
INCREASE ATTACK SURFACE AND EXPOSURE OF INFORMATION ASSETS TO A WIDER AUDIENCE.
24
A P R I L 2019
Security is not always visible to business heads and decision makers. There is always a belief that security delays business and time-to-market. CISOs needs to understand this and provide the right solution with minimal impact to the business.
As the domain is getting more complex and cybersecurity protection is getting more costly for organisations, customers are counting on security vendors to advise them with cost effective solution. Vendors need to provide the right advice to customers based on the business requirements for that particular organisations, using a risk-based approach instead of selling technologies that worked somewhere else. “The right advice is a more sustainable longterm strategic partnership rather than short term gains,” feels Abdullah Al Barwani. So how is digital transformation impacting an organisation’s security posture? For Abdullah Al Barwani, digital technologies create a services eco system to reduce cost, reduce time to market, and have loyal happy customers. Does it impact the security surface of the organisation? Continues Abdullah Al Barwani, “This really depends how the organisation handles its information assets before the digital transformation.” Generally speaking, digital transformation will increase the attack surface and exposure
SECURITY SKILLS
Finding the right cybersecurity skills is a universal challenge with an estimated shortage of 3.5 million in these skills worldwide.
SECURITY POLICIES
The dynamics and pace of cybersecurity risks requires a security programme that moves at the same speed, which is quite a challenge for bigger organisations.
of the information assets to a wider audience. Hence, more controls are required to protect the organisation. With every business headed towards becoming a digital business, cyber security can no longer remain isolated from rest of the subsystems. “Cybersecurity is now considered a subset of the digital environment by professionals,” adds Abdullah Al Barwani. As a reality check, the digital world includes both physical and virtual assets that need to be protected. The CISO’s role needs to be expanded to mandate the protection of digital assets, as well, thinks Abdullah Al Barwani. Longer term, digital transformation promises to bring great value to a business, while introducing new security risks. As an example, for service providers like Omantel, introduction of 5G is going to be a key enabler driving adoption of new use cases such as IoT, autonomous cars, amongst others. “We are at a stage, where we are working closely with international bodies to identify key security risks and the best ways to mitigate these risks,” summarises Abdullah Al Barwani. ë
UPTO
10TB CAPACITY
SUPPORTS UPTO
64
CAMERAS
247
OPERATION
READY FOR
NVR, DVR HYBRID DVR & RAID STORAGE
180 TB/YEAR WORKLOAD
UPTO
256MB BUFFER SIZE
ROTATION VIBRATION
RV SENSOR
VENDOR TALKS
HOW SHOULD CISOs PROTECT AND MONITOR CLOUD ASSETS With regional organisations beginning to use multiple cloud platforms, what do vendors recommend to CISOs, on how to build an end to end, cloud security access and monitoring management solution.
KAMEL HEUS, REGIONAL DIRECTOR, NORTHERN, SOUTHERN EUROPE, MIDDLE EAST AND AFRICA, CENTRIFY.
YAZAN HAMMOUDAH, SENIOR MANAGER, SYSTEM ENGINEERING, FIREEYE.
Organisations may consider approaching privileged access management by solely implementing password vaults, a legacy approach that leaves gaps which can easily be exploited. In today’s environment, privileged access not only covers infrastructure, databases, and network devices but is extended to cloud environments, Big Data projects, and DevOps, and must secure hundreds of containers or microservices. By implementing zero trust privilege, CISOs can minimise the attack surface, improve audit and compliance visibility, and reduce risk, complexity and costs for the modern, hybrid enterprise. In turn, customers can easily scale their privileged access solution across multiple IaaS regions or providers without expensive operating models that include replicating and constantly syncing vault instances. The old way of securing critical enterprise resources simply will not work in today’s diverse and sophisticated IT environments. Zero Trust assumes bad actors are already inside the network, hunting for privileged accounts and credentials that help them gain access to an organisation’s most critical on-premises and cloud infrastructure, as well as sensitive data. According to a recent survey of 1,000 IT decision makers, 74% of data breaches involved privileged credential abuse. Organisations must embrace a Zero Trust mandate of never trust, always verify, enforce least privilege, to minimise the risk of falling victim to a data breach. ë
The usage of emerging technologies has prompted an increasing reliance on the cloud, but most companies are not doing anywhere near as much work as they need to be doing to protect the cloud. Especially compared to the way they used to protect their own data centers, and the bad guys know this. There is a reason why roughly 20% of the incident responses and breaches involve the cloud. With cloud, there is a whole chunk of attack surface that does not have advanced technology to detect malicious activity. It is not really about cloud being more or less secure. The questions CISOs need to address when evaluating end-to-end solutions are: Do you have visibility for the things that are going on in the cloud, and are you able to set up your security operations center to be able to respond to something that happens? Do you know who is logging into your infrastructure right now? Do you know who is accessing it? If someone downloads a file, do you know if they were supposed to download it? Perhaps the number one priority for cloud is email security, because phishing is just so hard to defend against. That is the number one way that attackers are coming through. ë
CISOs POSE THIS QUESTION FOR INDUSTRY VENDORS TO ANSWER. HERE IS WHAT THE VENDORS HAVE TO SAY
26
A P R I L 2019
VENDOR TALKS
EMAD FAHMY,
FABIO PICOLI,
CONSULTING ENGINEERING TEAM
MANAGING DIRECTOR GCC, TREND MICRO.
LEAD FOR MIDDLE EAST, NETSCOUT.
A key driver for digital transformation is cloud computing. Digital transformation has an impact on every part of the organisation from retail to financial services, manufacturing to heavy industry. It is not just about securing the cloud and a monitoring management solution, but more importantly migrating to the cloud. You are setting up your company for success by implementing a successful cloud deployment that incorporates service assurance to yield best results. Cloud implementation plans should be based on pervasive visibility into the organisation’s IT environment before, during and after the move to cloud. Businesses everywhere are moving to cloud in this digital transformation era. Most importantly they are aware of the challenges that cloud migration presents. To successfully implement cloud, you must do your research. This is when companies quickly realise the need for instrumentation for aggressive monitoring, end-to-end visibility, and comprehensive service assurance. Once deployment is accomplished, constant network visibility is what keeps that network safe from cyber threats. Prevention of cyberattacks is the most effective form of cyber security. The rapid growth of business migration to hybrid cloud and multi-cloud architecture increases the IT network and infrastructure complexity, thereby increasing the attack surface and exposing new vulnerabilities. There is a need for extra security layers when it comes to securing the cloud as more and more businesses migrate to the cloud. Í
While cloud-focused malware samples are certainly nothing new, there are a few dangerous threats poised to impact enterprise cloud usage. One issue that is continuing to create vulnerabilities for enterprise cloud environments are insecure account credentials and other insider threats. In addition, inconsistent patching can create additional holes for malicious actors and other threats to slip through the cracks. Cryptojacking is also threatening cloud platforms and resources across industry sectors. While this threat may not appear as malicious at first glance, the unauthorised use of considerable resources required to support cryptocurrency mining can severely impact performance levels, impeding legitimate user processes. This then begs the question, what is then the role of security? We are all caught up in the rapid response, recover, and repeat cycle of cybersecurity. We rarely step back and evaluate whether our current approach and organisational structures align with our desired outcome. In order to align security efforts with a cultural shift, we need to clearly understand the goal of security. Cultural change is hard. It is one of the hardest things an organisation can undertake. It takes persistence and dedication. It is a difficult path to travel, but there are positive examples. The push from waterfall to agile development methodologies followed quickly by the cultural push to a DevOps mentality. You cannot achieve this goal from within the cybersecurity team alone. It requires collaboration and cooperation with the rest of the organisation. That is how we will address the security skills gaps. Not by training more and more of what we currently think of as security people, but by raising the level of security knowledge throughout the organisation. The DevOps movement represents the most significant opportunity for security implementation to align with desired outcomes in the past generation. That sounds dramatic but it is also accurate. DevOps helps in making smart design decisions like encrypting by default, using well maintained and accepted sanitisation libraries, and reducing the amount of personal information stored, which means that mistakes have a smaller chance of exposing valuable information. In the coding phase, security thinking helps ensure that test coverage is adequate for the data being processed. It helps developers use secure, well-understood patterns for secrets management, and other resilient coding practices. DevOps is not a single person or business unit; it is a development philosophy that exists within many organisations.
A P R I L 2 019
27
VENDOR TALKS
HOW SHOULD CISOs MANAGE DATA COMPLIANCE AND INTEGRITY With focus on data ownership and governance, what do vendors recommend to CISOs, to be able to track origin and movement of data across the organisation.
EPHREM TESFAI,
DR ALEKSANDAR VALJAREVIC,
SALES ENGINEERING MANAGER MIDDLE EAST, TURKEY AND AFRICA, GENETEC.
HEAD OF SOLUTIONS ARCHITECTURE, HELP AG MIDDLE EAST.
Integration is a common goal for security and IT teams within organisations looking for efficiencies by linking video with access control and ALPR. While integration can increase situational awareness, it does not lead to significant productivity gains. With integration, organisations are still deploying distinct security solutions from multiple vendors, purchasing multiple servers, attending multiple vendor-specific training, and maintaining several systems. However, a better approach exists – unification. True unification allows you to deploy a single platform that embeds multiple security systems, minimises IT infrastructure expenditures, and reduces your total cost of ownership. A unified security platform enables deep integrations with video surveillance and other key security systems such as access control, video analytics, intrusion, and license plate recognition, providing more consolidated information for faster decision-making. This technology encourages a greater collaboration between stakeholders, ensuring that if something does happen, critical information is available. When crowds draw in by the thousands, unification will make the difference in keeping them safe. It is important to have a reporting platform that can help data controllers monitor state of their systems or to conduct research around who had access to and downloaded information from their systems. ë
CISOs POSE THIS QUESTION FOR INDUSTRY VENDORS TO ANSWER. HERE IS WHAT THE VENDORS HAVE TO SAY 28
A P R I L 2019
As cloud and data analytics take centre stage in IT discussions, networks are expanding, and traditional perimeters are being erased. In the world of tomorrow, we will be become ever more dependent on data and together with our identities, this will become the only thing that we could and would be able to control and protect. Regulations such as the European Union’s GDPR are clear indication that today, consumers are becoming more conscious of their data and how it is used and secured. For these reasons, data protection and the various elements it entails such as data compliance, data governance, access control and authentication, data encryption, data ownership, and data residency are becoming increasingly important to businesses. To be able to protect your organisation’s data it is most critical to have complete visibility over it. This means having the ability to understand how it is being accessed and transmitted at every point in the network. From a technical perspective, achieving this means first identifying, and evaluating all touch points. These could include end point devices, email, web proxies to applications, and the cloud. With this clear understanding of what assets need to be secured, it is critical to not only implement the necessary security solutions, but to ensure they are seamlessly integrated to ensure end-to-end visibility and security. The next step is to ensure that technical controls for data classification, data leak prevention, and data encryption for data that is at rest, in transit or that is being processed, are in place. Finally, we must acknowledge that humans still present the weakest link in the cybersecurity chain. According to the 2018 Cost of Data Breach study conducted by the Ponemon Institute, 25% of data breaches are triggered by human error, including one’s failure to properly delete data from devices. Recognising this, it is imperative to address the human aspects of data protection as ultimately, technology will not add value unless it is supported by security policies and processes that are well created, and well enforced. ë
VENDOR TALKS
YAZAN HAMMOUDAH, SENIOR MANAGER, SYSTEM ENGINEERING, FIREEYE.
The new data governance laws that have gone into effect such as GDPR do not just affect CISOs but the whole spectrum of an organisation’s leadership from board members to IT managers to SOC analysts. From a cybersecurity standpoint, organisations should focus on making sure they have the right security foundation in place. Here are some recommendations for transforming your cyber security solution: Understand that cyber security is no longer solely an IT issue: The most senior members of a company’s management team must engage and be at least conversant with this dynamic risk. In your organisation, can the CEO, the CFO or the GC answer the following three questions: What are your company’s principal cyber vulnerabilities? What are your key strategies for mitigating those risks? Are adequate resources being devoted to the task at hand? Conduct essential vulnerability assessments. The best place to start is to benchmark your cyber protocols against an established standard. What are your most critical cyber assets? Does your organisation primarily rely upon proprietary data or industrial control systems? Have you assessed the true financial consequences of a large-scale breach? Get your board on board. Supervisory boards will be putting far more focus and pressure on management teams. Expect your board to ask questions about patching of software vulnerabilities, implementing multi-factor authentication for user access, and conducting risk assessments of third-party vendors and suppliers. If it takes your organisation three times longer to identify a cyber intrusion as other companies, will that be satisfactory for your board? ë
WERNO GEVERS, BUSINESS DEVELOPMENT MANAGER MIDDLE EAST, MIMECAST.
Organisations rely on email to conduct business, which often involves sharing sensitive or personal information. However, there is so much emphasis placed on the protection of inbound email that organisations often forget about the threats that exist within their own business. Monitoring and tracking the movement of data within and out of an organisation is just as important, and not having sight of how data is being used can have serious implications for compliance and governance. Organisations face a wide variety of risks when internal email traffic is left unprotected. These can be attributed to two general categories of users. The first is the compromised insider. External attackers take over the accounts, credentials, or systems of unsuspecting users. These attacks can then easily be spread internally via email and even worse, externally to customers, partners, and suppliers. The second is careless insiders. These are employees who do not fully understand or simply ignore security policies and rules or who make innocent – even well-intentioned – mistakes. And although less common, organisations also face risks from malicious and abusive insiders who are disgruntled, behaving inappropriately, or who intentionally seek to do damage. Most organisations do not have the advanced inside-the-perimeter defences, like data leak prevention, remediation, URL inspection, and sophisticated malware detection, required to effectively protect internally generated email traffic. An important issue to consider is how data is shared externally. When intellectual property, customer data or sensitive information like employee personnel files are purposely or unintentionally leaked, the damage can be irreparable. Data leakage can cause customers to lose confidence and business deals to go bad, in addition to fines, legal action and reputation damage. What organisations must adopt is a data loss prevention strategy that protects against accidental and malicious leaks of data via email. Finally, organisations need to consider how they store their data and ensure they have the right tools in place to not only protect it but also allow it to be easily accessible. As the volume of business email in your organisation grows exponentially, email compliance becomes an increasingly costly and complicated task. To manage email compliance effectively, you require policy enforcement tools to ensure outbound email conforms to regulations and corporate policies. You need retention processes to determine which emails to archive with enough storage to satisfy company policies. Fast capabilities for search and retrieval are essential to prevent email compliance from consuming your IT staff ’s time. And you need complete archive access logging for data assurance and encrypted storage to prevent tampering. Being able to prove chain of custody and log every operation performed on a bit of data is also crucial, especially for e-discovery. Your archive solutions should be able to deliver this robust a level of information. Chains of custody allow administrators to track emails, document delivery and prove the authenticity of the email. ë
A P R I L 2 019
29
CHANNEL PARTNER
HELP AG CSOC
DELIVERING HIGH VALUE, ON-DEMAND SECURITY SERVICES The managed services provider CSOC has ISO 27001 certification including 110 check points ensuring a high degree of compliance for services delivered.
SIMON WILLGOSS,
HEAD OF MANAGED SECURITY SERVICES, HELP AG.
30
A P R I L 2019
The Help AG cyber security operations centre is based in Dubai and has received the Information Security Management System ISO IEC 27001:2013 certification. This confirms that Help AG have implemented over 110 stringent security controls relating to Physical and Environmental Security, Technical Security, Personnel Security, Supplier Relations, Operations Security, Business Continuity, Incident Management, and Compliance. The two main factors driving managed security services adoption are access to expertise and cost efficiency. Managed services help move IT budgets from intimidating CapEx to more manageable OpEx while trusting the IT infrastructure to a team of qualified experts. This is especially helpful in the Middle East wherein the lack of qualified cyber security professionals is a pressing concern. Managed security service providers have teams of expert qualified and certified technical professionals. Through their work with large pools of clients, they are exposed to and therefore knowledgeable of the threat landscape. Security intelligence will be one of the key pillars of cyber security in the years ahead so having access to large client pools provides managed security service providers with the wealth of information they need to analyse and act upon. Furthermore, managed security service providers can invest in best-of-breed technologies that customers- especially SMBs and SMEs simply would not be able to afford. The pay-as-you-go model lends itself to both upward or even downward scalability. And then,
availability is also a factor since with a managed security service provider, customers get 24x7 support with assured 99+% availability which ensures that business is always on. A managed security service providers IT infrastructure can be compared to fully fledged enterprise’s infrastructure with even more controls as it is protecting customers’ as well as its own data. Help AG needs to ensure controls to limit and to be able to audit any access into critical segments. For Help AG the infrastructure to consist of domain environment, patch management, AV and DLP solutions, multiple layers of firewalls, web applications, databases, two-factor authentication solution, web application firewalls, outbound inbound proxies, PAM solution, Incident Response Platform, Threat Intelligence Platform, solution for knowledge management, SIEM environment, tools for automation, and vulnerability management.
THE VARIOUS HELP AG CSOC SERVICES INCLUDE: 24x7 Security Monitoring Security Event Management and Incident Response l Managed Remediation Services l Managed Web Defence, Application Layer DDOS, Anti-Defacement, Anti-Phishing l Managed Web Application Firewall l Managed Vulnerability Assessments l Managed Endpoint Security l Managed Endpoint Threat Detection and l l
CHANNEL PARTNER
HELP AG’S MANAGED SECURITY SERVICES CAN BE COMPARED TO AN ENTERPRISE’S INFRASTRUCTURE WITH EVEN MORE CONTROLS
HELP AG HAS TEAMS OF EXPERT QUALIFIED AND CERTIFIED TECHNICAL PROFESSIONALS.
Response l Managed Threat Intelligence
THE KEY DIFFERENTIATORS THAT MAKE HELP AG’S CSOC UNIQUE IN
THE REGIONAL MARKET PLACE INCLUDE: 24x7 operation with guaranteed service availability of 99.5% and higher l Locally managed security services delivering in full compliance with the UAE government’s l
regulatory frameworks No log data leaves customer premises due to a unique and specifically designed architecture built in-house by Help AG ë
l
A P R I L 2 019
31
CHANNEL PARTNER
EHDF CYBER DEFENSE CENTRE
PROTECTING AND SECURING TRANSFORMED ORGANISATIONS As regional organisations increase their scale of digital transformation, they will need to access specialised managed security services to remain secure.
RAJESH ABRAHAM, DIRECTOR PRODUCT DEVELOPMENT, EHOSTING DATAFORT.
32
A P R I L 2019
eHosting DataFort launched its specialised Cyber Defense Centre to tackle the increasing need for cyber security for the region in 2017. It offers a portfolio of Managed Security Services along with Remote Managed Security Information and Event Management Services, delivered either within eHDF’s Data Centre, on customer premise or in the Cloud. The services include, Real Time log collection and Analysis, Remote Managed SIEM RMSS, Incident Management and Response, Advanced Threat Protection, Vulnerability Management and Penetration Testing, End point Security Management, DDoS Protection, Web Application Firewall Protection WAF, Identity and Access Management, others. According to MarketsandMarkets, the global managed security services market size is expected to grow from $24.05 Billion in 2018 to $47.65 Billion by 2023, at a CAGR of 14.7% during the forecast period. It also highlights that the demand for managed security services is expected to be driven by stringent government regulations and increasing instances of cyber-attacks on enterprises. Moreover, the growing BYOD trend amongst organisations and the cost-effectiveness in implementing services are expected to increase the demand for managed security services during the forecast period. “The threat landscape is changing consistently with an increasing number of specialised service requirements. As a Managed Services Provider, eHosting DataFort has always been at the forefront with our customer centric approach and have made timely additions to our services portfolio. From specialised Managed Security Services to a dedicated Security Operations Centre, we have been able to provide our customers with a range of services to tackle their current
CHANNEL PARTNER
security concerns,” said Rajesh Abraham, Director Product Development, eHosting DataFort. “Our customers are aware of the wealth of experience and domain knowledge that we bring to the table. We have made significant inroads into a wide network of businesses including government, media, construction and real estate, electronics and communications, banking and finance, automotive and retail sectors. This is also strengthened by the on-going certifications that we have acquired including PCI-DSS and Cloud Security Alliance CSA STAR Certification, and others that help our clients with their regulatory commitments,” Abraham added. eHDF offers customers a complete security lifecycle which includes monitoring, patching, collecting and analysing security data. The services include incident management which offers a single dashboard of a customer’s security posture, attacks, and incidents. eHDF passes on tangible cost benefits to customers planning to procure new security technologies. Purchasing capital assets through eHDF on an opex model eliminates the need for lengthy evaluation and procurement cycles and provides ongoing flexible monthly based payment plans for customers. The Real Time Threat Monitoring services collects and directs customer data to the Security Information and Event Management SIEM solution. Subsequently it also offers data analysis and provides short- and long-term remedial solutions. For customers who have already invested in SIEM, eHDF provides on-premise Remote Managed SIEM. eHDF also offers the SIEM platform as a service on a pay-as-you-go-model, for companies who have not invested in this technology. The advanced managed security services from eHDF include:
SECURITY INFORMATION EVENT MANAGEMENT, SIEM As part of the Managed SIEM service, any customer premises equipment is set up and maintained by eHDF. eHDF’s SIEM helps businesses achieve compliance with regulations and requirements, including the PCI DSS. Managed SIEM ranges from simple agent-based solutions to Log Management and SIEM Enterprise Appliances. These appliances offer extensive capabilities for additional correlation, reporting and ad-hoc analysis, both locally on the appliance and via
services provided through CDC.
REAL TIME THREAT MONITORING, RTTM RTTM combines log collection, 24x7 log analysis and incident classification, notification to provide better visibility to an organisation’s cyber risk. The service offers comprehensive set of dashboards that allow eHDF customers to make quick and effective decisions of how to improve their cyber defenses.
REMOTE MANAGED SECURITY SERVICE The service allows customers to outsource the management and monitoring of their SIEM including the people and process required to manage the entire security incident response life cycle.
the company has developed an advanced Cloud Access Security Broker, gateway that allows customers to route their employees via a cloudbased proxy solution to control access to cloud applications and monitor application usage and data loss.
OTHER SERVICES These services include, r DDoS, Security Log Collection and Management, Managed Web Application Firewall, Web Defacement Protection, End point Security Management, File Integrity Monitoring, Social Media Tracking, Mobile Application Tracking, Data Base Security Management, Privileged Account Management, Security Hardware Management, Server Hardening, Managed Data Loss Prevention, Database Security, Managed Network Access Control and Identity and Access Management. ë
PCI SECURITY SERVICES eHDF is a fully approved provider of PCI services and can assist customers who need to comply with PCI from an assessment and ongoing monitoring point of view.
ADVANCED THREAT PROTECTION, ATP In partnership with major ATP vendors, the company also offers cloud-based sandboxing, mail blocking and endpoint quarantine in the event of an outbreak.
VULNERABILITY MANAGEMENT, VM Offers managed Vulnerability Management services to customers based on a platform deployed within the eHDF Cloud, delivered from datacentres based in UAE. This fully managed service includes the provision of licenses, scanners and skilled resources to managed the VM lifecycle and integrate it into the SIEM solution.
INCIDENT RESPONSE, IR Remote and on-site IR services that remove the guesswork following a breach or data loss. eHDF has IR members on standby to assist customers in managing an incident from identification via the RTTM and RMSS services through containment and root cause analysis.
CLOUD ACCESS SECURITY BROKER, CASB In partnership with a global security vendor,
A P R I L 2 019
33
REAL LIFE
DUBAI ELECTRONIC SECURITY CENTRE
ENSURING COMPLIANCE AND BEST PRACTICES IN THE EMIRATE As regional organisations increase their scale of digital transformation, they will need to access specialised managed security services to remain secure.
DR MARWAN AL ZAROUNI,
AMER SHARAF,
DIRECTOR OF INFORMATION SERVICES, DUBAI ELECTRONIC SECURITY CENTRE.
DIRECTOR OF COMPLIANCE, SUPPORT AND ALLIANCES, DUBAI ELECTRONIC SECURITY CENTRE.
Dubai Electronic Security Centre, DESC was founded in 2014. Pursuant to Law No 11 and with the aim to develop and implement information security practices, it has been setting goodpractice criteria for cyber security across the Emirate. DESC’s strategic plan includes initiatives to combat threats, cyber-attacks, and cyber-crime. The goals of technological development will never be met in the absence of supportive frameworks that promote the security and safety of
information systems. The cyber security strategy aims to do just that here in Dubai. DESC services also include the Information Security Regulation Compliance. This ensures that all Dubai Government entities are in compliance in terms in information security regulations being at an excellent level at all times. Subsequently, providing regular security awareness trainings, workshops and education in order to increase societies capabilities and understanding
34
A P R I L 2019
in terms of information security concepts and regulations. “Digital transformation and the rise of disruptive technologies has a great and positive impact on economic growth in the gulf region. Consequently, the sophistication of cyber threats is becoming increasingly popular. At DESC we are always a step ahead through introducing the latest security standards for these distributive technologies, said Dr Marwan Al Zarouni, Director of Information Services, Dubai Electronic Security Centre. “These days the volume of cyberattacks are getting more sophisticated and disruptive as they pose a great risk to the growth of the digital economy and smart infrastructures. Our main priority is to protect Dubai digitally against cyber threats by securing their privacy and data, and safeguard Dubai’s digital wealth,” said Amer Sharaf, Director of Compliance Support and Alliances, Dubai Electronic Security Centre. The sophistication and frequency of cybercrime is on the rise: from disruption and loss of revenue at the enterprise level to data theft at the individual level, cyber-attacks have devastating consequences. One prediction estimates cybercrime will cost the world in excess of $6 trillion annually. But awareness levels, too, are on the rise: the market for cyber security services in the Middle East is expected to grow to $22.14 billion by 2022, up from $11.38 billion in 2017, nearly doubling in the five-year. Sharaf added, “DESC is perpetually working to implement the Dubai Cyber Security Strategy. As Dubai is moving deeper into its digital transformation, we aim to create a society that is highly aware of risks and able to stay vigilant against
REAL LIFE
to manage cyber security risks for government, Individuals and private sectors thus creating a cyber smart society. DESC has recently developed biomedical standard for ensuring the secure operation of electronic biomedical devices in Dubai. This standard is largely based on the IoT Security Standard, which also has been produced by DESC. It covers all electronic biomedical devices. There are several interest groups that have done work on the security of biomedical devices.
RESPONSIBILITIES OF DESC n Set and implement the Government Information Security policy of the Emirate. n Set and supervise the implementation of standards for ensuring electronic security in the Emirate. n Hold, and participate in conferences and seminars, and cooperate with regional and international organizations in relation to the work of DESC. n Monitor compliance by government entities with the information security requirements issued by DESC, and follow up implementation of these requirements. n Combat various cybercrimes and information technology crimes. n Provide technical and advisory support to all government entities in the Emirate. n Prepare and finance the studies and research required to develop electronic security in the Emirate in coordination with government entities. n Propose legislation concerning electronic security.
cyber-attacks.”
KEY ACTIVITIES Dubai Electronic Security Centre has highlighted the key changes of the Information Security Regulation, ISR into Version 2.0. The ISR’s purpose is to provide government entities with optimal and most secure standards to ensure mitigation of any vulnerabilities and external risks across all Dubai Government Entities. The main intention of ISR is to preserve an appropriate level of confidentiality, integrity, and availability for information assets handling controls in Dubai government entities. ISR Version 2.0 is going to be a step forward and a way to ensure the improvement of informa-
tion Security. According to the ISR team. Dubai Government Entities are expected to implement the enhanced security regulation version 2.0 with all its divisions within the entity to ensure a unified consistency with their mandates to enhance cyber resilience. The ISR Version 2.0 is introduced in 13 improved domains and related controls in order to ensure the successful implementation of the enhanced ISR. These new set of domains include cloud security, governance of security risks, and communication management. DESC’s role draws upon conducting an annual ISR audit to verify its compliance. DESC’S most prominent strategy domain is to achieve awareness through acquiring skills
PARTNERSHIP WITH DUBAI FUTURE FOUNDATION Dubai Future Foundation DFF announced its partnership with five government organisations in Dubai to support the implementation of the second phase of the Dubai 10X initiative. Partners in the initiative include Government of Dubai Media Office, the Department of Economic Development, the Department of Tourism and Commerce Marketing, Smart Dubai Office, Dubai Electronic Security Centre, and Dubai Future Foundation’s initiative; the Dubai Future Accelerators. Abdulaziz Al Jaziri, Deputy CEO and Chief of Projects of DFF, highlighted that these strategic partnerships are an important addition and a qualitative boost to the Dubai 10X initiative. It includes collaborating with leading government entities in the second phase to implement 26 projects approved by His Highness Sheikh Hamdan bin Mohammed bin Rashid Al Maktoum, Crown Prince of Dubai, Chairman of the Executive Council of Dubai and Chairman of the Board of Trustees of DFF. “We aim to make Dubai the safest city in cyber space, and we are aware of what the Dubai 10X initiative is trying to achieve, ahead of what others have been aiming for 10 years. Hence, we work in partnership with various teams to secure their projects with standards and policies that align with the needs of the future,” said Dr Zarouni. As the cyber security partner of the second phase of the Dubai 10X initiative’s projects, Dubai Electronic Security Centre will be reviewing the information security standards of the participating projects to contribute to creating projects that achieve the best levels of information security to achieve sustainability of life and government work in Dubai. This comes in line with the Dubai Cyber Security Strategy which aims to establish Dubai as the global leader in innovation, safety and security. ë
A P R I L 2 019
35
REAL LIFE
PYTHON ATTACK ON MIDDLE EAST GOVERNMENT BY CHAFER Threat actor Chafer has been active in Middle East since 2015 and according to Palo Alto’s Unit 42 has used for the first time a Python-based payload.
36
A P R I L 2019
REAL LIFE
T
he Chafer threat group has been active since at least 2015 focused on both private and public sector entities within the Middle East. Unit 42 has specifically observed the targeting of Turkish government entities since at least 2016; however, this is the first instance where Unit 42 has observed Chafer using a Python-based payload. This payload, now known as MechaFlounder was created by Chafer using a combination of actor developed code and code snippets freely available online in development communities. The MechaFlounder Trojan contains enough functionality for the Chafer actors to carry out the necessary activities needed to accomplish their goals, specifically by supporting file upload and download, as well as command execution functionality. In November 2018 the threat group targeted a Turkish government entity reusing infrastructure that they used in campaigns reported earlier in 2018, specifically, the domain win10-update[.]com. While Unit 42 lack visibility into the initial delivery mechanism of this attack, Unit 42 did observe a secondary payload hosted on 185.177.59[.]70, the IP address to which this domain resolved at the time of the activity. This new secondary payload is Python-based and compiled into executable form using the PyInstaller utility. This is the first instance where Unit 42 has identified a Python-based payload used by these operators. Unit 42 also identified code overlap with OilRig’s Clayside VBScript but at this time track Chafer and OilRig as separate threat groups. Unit 42 have named this payload MechaFlounder for tracking purposes and discuss details below.
TARGETING A GOVERNMENT Unit 42 visibility into this Chafer activity involves the identification of a malicious executable downloaded from the IP address 185.177.59[.]70. How the attackers are targeting victims and causing them to download this file are currently not known. The file named ‘lsass.exe’ was downloaded from win10-update[.]com via an HTTP request. The win10-update[.]com domain has been noted in https://twitter.com/clearskysec/ status/976170940722708480 as an indicator associated with Chafer threat operations. The lsass.exe file downloaded from this domain is a previously unreported python-based payload that Unit 42 are currently tracking as MechaFlounder. Unit 42 believe Chafer uses MechaFlounder as a secondary payload that the group downloads from a first-stage payload to carry out its postexploitation activities on the compromised host. Based on our telemetry, the first-stage payload was not observed in this activity. In February 2018, IP address 134.119.217[.]87 resolved to win10-update[.]com and several other domains likely associated with Chafer activity. Of interest, the domain turkiyeburslari[.]tk, which mirrors the legitimate Turkish Scholarship government domain turkiyeburslari[.]gov[.]tr, also resolved
KEY TAKEAWAYS n
MECHAFLOUNDER WAS CREATED BY CHAFER USING A COMBINATION OF ACTOR
DEVELOPED CODE AND CODE SNIPPETS. n
MECHAFLOUNDER TROJAN CONTAINS ENOUGH FUNCTIONALITY FOR THE CHAFER
ACTORS TO CARRY NECESSARY ACTIVITIES TO ACCOMPLISH THEIR GOALS. n
THE OVERLAP IN OILRIG’S CLAYSIDE VBSCRIPT AND CHAFER’S AUTOIT PAYLOADS
DOES NOT COME AS A COMPLETE SURPRISE. n
UNIT 42 HAS TAKEN REFERENCE TO THE VARIOUS OVERLAPS IN THE TWO SETS OF
ACTIVITIES AND CONTINUES TO TRACK THESE OPERATIONS SEPARATELY.
A P R I L 2 019
37
REAL LIFE
THIS PAYLOAD, NOW KNOWN AS MECHAFLOUNDER TARGETING A MIDDLE EASTERN GOVERNMENT, WAS CREATED BY CHAFER USING A COMBINATION OF ACTOR DEVELOPED CODE AND CODE SNIPPETS FREELY AVAILABLE ONLINE IN DEVELOPMENT COMMUNITIES.
INFRASTRUCTURE ASSOCIATED WITH 134.119.217[.]87
to this IP and may likely have been used in other Chafer collection operations.
THE MECHAFLOUNDER PAYLOAD The python-based payload, ‘lsass.exe’ was retrieved from a command and control (C2) server via an HTTP request to the following URL: win10-update[.]com/update. php?req=<redacted>&m=d This payload, (SHA256: 0282b7705f13f9d9811b722f8d7ef8fef907bee2ef00bf8ec89df5e7d96d81ff), which Unit
38
A P R I L 2019
42 are tracking as MechaFlounder, was developed in Python and bundled as a portable executable using the PyInstaller tool. This secondary payload acts as a backdoor allowing the operator to upload and download files, as Unit 42ll as run additional commands and applications on the compromised system. MechaFlounder begins by entering a loop that will continuously attempt to communicate with its C2 server. The Trojan will use HTTP to send an outbound beacon to its C2 server that contains the user’s account name and hostname in the
URL. The code builds the URL by concatenating the username and hostname with two dashes “–” between the two strings. The code then creates the URL string by using the username and hostname string twice with the back-slash “\” character between the two and by appending the string “-sample.html”. During this analysis, the code generated anomalous HTTP requests for its beacons, as shown in Figure 3 below. One might notice that the GET request in Figure 3 does not start with a forward-slash “/” character and includes a backslash character “\” in the URL. This causes a legitimate web server, such as nginx used in our test environment, to respond with a ‘400 Bad Request’ error message. This may suggest that even though the code uses the HTTPConnection class from the httplib module to generate the anomalous HTTP beacon, it is likely that the threat actors created a custom server to handle this C2 channel instead of relying on a standard web server. Additionally, the malware author used the variable name ‘cmd’ to build the string used for the HTTP method and path and checks the HTTP method portion of the string for the word ‘exit’. Unit 42 are unsure of the purpose of this check, as the HTTP method in this string would never be ‘exit’ and therefore would never be true. Unit 42 believe this is an artifact likely derived from a previous version of the script that the author forgot to remove. If the C2 server were to accept the beacon, it would respond with HTML that contains a command intended for the Trojan to parse and execute. The Trojan begins by converting the HTML in the response to text using the code. The HTML to text code is available in several locations on the Internet, but it appears to have possibly originated from a discussion at Stack Overflow titled https://stackoverflow. com/a/3987802, which may be where the malware author obtained this code. After converting the HTML to text, the Trojan discards the first 10 characters of the response and treats the remainder of the string as a command. The C2 can also provide the string “yes ” in this command string, which instructs the Trojan to decode the command as a base16 encoded string with the “yes ” substring removed. The Trojan subjects the command supplied by the C2 to a handler that determines the activities the Trojan will perform. The commands in the command handler provides the necessary functionality for Chafer to interact with the remote system. Unit 42 gained more insight into the custom C2 server application by analyzing the activities
REAL LIFE
TROJAN CODE USED TO BUILD ANOMALOUS HTTP REQUEST.
virtual-machine-service.html’ file, which effectively issues a command to the Trojan. The Trojan responds to the command ‘runtime 5’ with the message “5||rob–rob-virtual-machine**runtime changed to runtime 5” that it encodes in base16. It then sends this to the C2 server without any HTTP headers using the same socket as the initial HTTP request.
ONE MORE THING
EXAMPLE HTTP REQUEST ISSUED BY TROJAN IN TEST ENVIRONMENT.
HTML TO TEXT CODE IN TROJAN POSSIBLY OBTAINED FROM STACK OVERFLOW DISCUSSION.
that MechaFlounder carries out if it receives the ‘upload’ command. To upload a specified file from the compromised system to the C2 server, the Trojan uses the Browser class in the mechanize module, partial basis of the MechaFlounder name, to submit the file to an HTML form on the C2 server. This suggests that in addition to being able to handle the anomalous HTTP GET requests previously mentioned, the custom C2 server application must also be able to: Serve HTML that contains a form to receive
uploaded files, Handle legitimate HTTP POST requests generated by the mechanize module, and ave files uploaded with the HTTP POST request. After carrying out the activities for the command, the Trojan will encode the results or output message of the command using the ‘base64.b16encode’ method. Each command has an output message for both a successful and failed execution of the command with the exception of ‘empty’ and ‘terminate’. Table 2 below shows the success and failure messages associated with each command. Unlike the initial beacon that uses the anomalous HTTP GET request, the Trojan will send the encoded results to the C2 server using the same socket as the initial HTTP beacon. The use of the same socket and the anomalous portions of the HTTP beacon further suggests that the threat actor likely created a custom C2 server to handle this network traffic. To show these network communications, Unit 42 patched the Trojan to issue beacons that use legitimate HTTP GET requests that the HTTP server (nginx) in our test environment could support. The patches involved changing the paths within the HTTP request, specifically setting the path to start with a forward-slash “/” and have the forward-slash “/” instead of a back-splash “\” within the URL path itself. In our test environment, Unit 42 added the string “0123456789runtime 5” to the file ‘rob–robvirtual-machine-service.html’ in the ‘rob–robvirtual-machine’ folder. When the Trojan issues the beacon, the HTTP server responds with contents of the ‘rob–rob-
If you think you’ve seen the “&m=d” parameter before, you’d be correct. The “&m=d” parameter seen in the initial download URL of the MechaFlounder payload appears in many URLs related to both Chafer and OilRig threat groups. This parameter has been seen in VBScript downloader payloads installed by delivery documents associated with both Oilrig and Chafer. Unit 42 have also seen this parameter used in URLs generated by Chafer’s AutoIT payload. The VBScript and AutoIT payloads also share common variable names and the same overall functionality, which suggests there may be some code sharing occurring between the two threat groups. Figure 6 below shows a VBScript run by an OilRig delivery document (SHA256: 1b2fee00d28782076178a63e669d2306c37ba0c417708d4dc1f751765c3f94e1) on the left compared to a Chafer AutoIT script (SHA256: 332fab21cb0f2f50774fccf94fc7ae905a21b37fe66010dcef6b71c140bb7fa1) on the right, which have colored boxes surrounding code overlaps. Unfortunately, Unit 42 are unable to ascertain the specifics between the code sharing between OilRig and Chafer. At this time, Unit 42 are not combining the two threat groups together based on these code overlaps.
CONCLUSION MechaFlounder was created by Chafer using a combination of actor developed code and code snippets freely available online in development communities. The MechaFlounder Trojan contains enough functionality for the Chafer actors to carry out the necessary activities needed to accomplish their goals, specifically by supporting file upload and download, as well as command execution functionality. The overlap in Oilrig’s Clayside VBScript and Chafer’s AutoIT payloads does not come as a complete surprise. Oilrig and Chafer have for quite some time appeared very similar operationally and potentially having access to the same code or resources for payload development makes sense. Unit 42 has taken reference to the various overlaps in the two sets of activities and continues to track these operations separately. ë
A P R I L 2 019
39
HANDS-ON
CISO’S LEFT OUT OF TRANSFORMATION, KPMG Only few businesses are integrating cybersecurity into transformation from outset, with others attempting to retrofit security to completed outcomes.
The role of the CISO has evolved. CISOs are now pivotal in supporting their organisations’ growth ambitions, largely through delivering trust in the digital products and services. The survey shows that CISOs regard themselves as integral to their organisations’ growth, but remain insufficiently integrated into the business transformation agenda. Still, there is cause for optimism. Many CISOs feel that they receive the support of their organisations, with adequate budgets and levels of investment. As consumer trust becomes increasingly critical to commercial success, it will become more and more important for cybersecurity to be treated as a board-level investment priority, and be seen as a key enabler of business growth.
Trust is crucial to attracting and retaining consumers, but this is critically tested when incidents occur. KPMG’s 2018 Global CEO Outlook found that half of chief executive officers believe that it is purely a matter of time before their organisation experiences a cyber incident. But if such an event is handled sensitively and in a way that reinforces consumer trust, KPMG has found that this can actually strengthen the trust ecosystem and improve a company’s ability to retain consumers. Digital transformation is now a way of life for all organisations: every organisation we surveyed is on a journey to create additional business value from data and technology and create agility in their business’s core operations. The scale and pace of technology evolution, however, means
WHAT ARE THE TOP CONCERNS FOR SECURITY PROFESSIONALS?
According to the security executives surveyed, malware is the top concern followed by phishing or social engineering. Distributed denial of service attacks is the third largest concern for organisations, with direct impact on the company’s ability to provide digital products and services. Despite multiple high profile, global incidents during 2018, ransomware such as NotPetya worried less than a third of responses, with third-party access being of greater concern. Security professionals should rightly be worried about attacks from partner and supplier networks, as cyber attackers shift their focus to target supply chains and the weak points in managed service providers, rather than larger, more mature companies that are harder to break into. E-commerce and digital channels are also becoming more of a target, as are cryptocurrencies.
40
A P R I L 2019
that organisations find themselves constantly integrating data and technology to create new sources of value and the process of transformation is now continuous. These transformation activities are being led by executive leadership, not IT, as reflected in KPMG’s 2018 Global CEO Outlook survey. KPMG research found that corporate leaders across industries are taking personal ownership of driving digital transformation, with 72% of CEOs saying they are ready to lead a radical organisational change. The majority of survey participants stated that they were in the intermediate stage of their digital transformation journey, with those in the technology and telecommunications industries further along their journeys than financial
WHAT IS TOP OF MIND WHEN A BREACH OCCURS?
Despite the opportunity security executives see for cybersecurity to support customer engagement, less than a third of the survey respondents are concerned about the impact of a breach on the organisation’s relationship with customers. In the age of the customer, organisations need to prepare for an attack and determine a strategy for maintaining the trust of consumers throughout their response activities. In this way, consumers will not be forgotten about in the event of a breach. New regulations, such as the GDPR, threaten to exact very heavy fines from organisations that break the rules as they relate to consumers. Trust is being demanded by both consumers and regulators, and companies will feel the pinch on their pockets from both sides when things go wrong.
HANDS-ON
CYBERSECURITY IN THE DIGITAL TRANSFORMATION AGENDA?
While the security executives KPMG surveyed appreciate the potential for cyber to add value to the business growth agenda, the downside is that security teams are not yet consistently embedded with the digital transformation agenda. Part of the problem may be that security professionals often prefer to work with a fixed technology architecture, even though data flows and business processes are changing more rapidly than ever. A contributing factor may be the structure of cybersecurity teams within an organisation, often straddling the line between IT and risk management, with reduced line of sight of the business strategy and growth agenda activities. Cybersecurity needs to match the agility of the digital organisation, adapting to meet the fast-changing needs of stakeholders with the right mandate to enable digital transformation.
ARE SECURITY FUNCTIONS CHANGING AT THE SPEED OF BUSINESS?
As digital transformation becomes the norm and becomes a business imperative, the role of the cybersecurity function needs to change accordingly, to enable agile adoption, experimentation and implementation of technology. Cybersecurity functions that remain as reactive or compliance-based function focused on established IT and processes will be left behind in the transformation agenda. KPMG believes that organisations that entrench cybersecurity into their digital innovation and customer-centric functions, with a mandate to enable speed and agility, can be able to bridge the cybersecurity gap between consumers and the organisations that serve them. This will help generate consumer trust and propel business growth.
WHAT ARE THE LEVELS OF DIGITAL TRANSFORMATION?
KPMG research found that corporate leaders across industries are taking personal ownership of driving digital transformation, with 72% of CEOs saying they are ready to lead a radical organisational change. The majority of survey participants stated that they were in the intermediate stage of their digital transformation journey, with those in the technology and telecommunications industries further along their journeys than financial services, retail or auto manufacturers.
services, retail or auto manufacturers. As digital transformation becomes the norm and becomes a business imperative, the role of the cybersecurity function needs to change accordingly, to enable agile adoption, experimentation and implementation of technology. Cybersecurity functions that remain as reactive or compliance-based function focused on established IT and processes will be left behind in the transformation agenda. KPMG believes that organisations that entrench cybersecurity into
their digital innovation and customer-centric functions, with a mandate to enable speed and agility, can be able to bridge the cybersecurity gap between consumers and the organisations that serve them. This will help generate consumer trust and propel business growth. Encouragingly, the potential opportunity for cybersecurity to add value to business objectives was shared by security leadership respondents, with securing customer engagement and supporting digital and business transforma-
tion agendas being the top opportunities for cybersecurity. While the security executives we surveyed appreciate the potential for cyber to add value to the business growth agenda, the downside is that security teams are not yet consistently embedded with the digital transformation agenda. Part of the problem may be that security professionals often prefer to work with a fixed technology architecture, even though data flows and business processes are changing more rapidly than ever. ĂŤ
A P R I L 2 019
41
AFTER THOUGHT
WHY BUSINESSES SHOULD START EMBRACING PASSWORD-LESS Businesses are starting to consider a passwordless environment set up by biometric or mobile device techniques, explains Ant Allan at Gartner. Despite their weaknesses, passwords are still widely used. Easy-to-guess and reused legacy passwords are vulnerable to a wide range of attacks and, by themselves, do not provide proper security for sensitive systems and confidential information. While eliminating passwords has been a long-standing goal, it is finally seeing real traction in the marketplace. During the past year, we have seen a small increase in client inquiries specifically citing passwordless and an increase in inquiries about other passwordless approaches. By 2022, Gartner predicts that 60% of large and global enterprises, and 90% of midsize enterprises, will implement passwordless methods in more than 50% of use cases, up from 5% in 2018. Passwordless authentication, by its nature, eliminates the problem of using weak passwords. It also offers benefits to users and organisations. For users, it removes the need to remember or type passwords, leading to better user experience and customer experience. For organisations, there is no longer a need to store passwords, leading to better security, fewer breaches and lower support costs. Security and identity and access management leaders can implement a passwordless approach in two ways.
REPLACE A LEGACY PASSWORD AS THE SOLE AUTHENTICATION FACTOR Biometric authentication such as touch ID is a common way of going passwordless. It is now widely deployed in mobile banking apps, and is making its way into other customer and enterprise applications. Other options include passwordless knowledge methods, such as pattern-based, one-time password methods; tokens, including phone-as-atoken modes, as a single factor; and Fast IDentity Online, Universal Authentication Framework, which enables passwordless authentication via a
42
M A R C H 2019
method local to a person’s device.
REPLACE A LEGACY PASSWORD AS ONE FACTOR IN 2FA
ANT ALLAN, VICE PRESIDENT ANALYST, GARTNER.
Current mainstream strong authentication solutions are two-factor authentication 2FA solutions that add some kind of token to an existing password. Recently, vendors have come to market with 2FA solutions that are passwordless by default, providing a single-step 2FA that can combine mobile push with a local PIN or device-native biometric mode to create sufficient trust in medium-risk use cases. Non-native biometric modes provide more in a single-step 2FA, as they are independent of the phone’s power-on passcode, provide organisations with control over whose biometric data is being stored, and typically provide better protection against attacks using images or recordings. These advantages are critical when mobile push is being used to authenticate access from a smartphone. Although it is not always possible to completely eliminate passwords from legacy implementations, Gartner recommends that organisations prioritise assessing and implementing more robust passwordless authentication methods. In doing so, organisations will improve security and user experience. ë
KEY TAKEAWAYS n
PASSWORDLESS AUTHENTICATION, BY
ITS NATURE, ELIMINATES THE PROBLEM OF USING WEAK PASSWORDS. n
VENDORS HAVE COME TO MARKET
PROVIDING A SINGLE-STEP 2FA WITH SUFFICIENT TRUST IN MEDIUM-RISK USE CASES. n
GARTNER RECOMMENDS
ORGANISATIONS PRIORITISE ASSESSING MORE ROBUST PASSWORDLESS AUTHENTICATION METHODS.
should be a fundamental right for every organisation!
ERICOM SOFTWARE IS A LEADER IN SECURING & CONNECTING THE DIGITAL WORKSPACE Ericom's offerings include innovative remote browser isolation, secure remote access & zero trust browsing solutions