SPECIAL SUPPLEMENT BY
TRENDS FOR CYBER AND INDUSTRIAL SECURITY EXECUTIVES
JUNE 2019
ROSS MCNAUGHTON, CISO, AHLI UNITED BANK GROUP
The
Disruptive CISO
CONTENTS JUNE 2019
06
12
SPECIAL REPORT
DEEP DIVE
Combatting e-Crime with 7 Steps
Tackle Tomorrow’s Digital Business Security Risks
14
22
TOP EXECUTIVE
The
Disruptive CISO
DEEP DIVE Safeguarding Your Organization from Attacks Via Your Third-Party Vendors
15
DEEP DIVE Tenable Unveils New Innovations for Cyber Exposure Analytics
16
26
28
30
REPORT
VENDOR TALKS
CHANNEL PARTNER
20
32
REAL LIFE
34 Insights on Building Scalable Cybersecurity Systems
PRODUCT SECTION
38 TOP OF MIND
TRENDING Infoblox Reveals Top Cybersecurity Challenges in Healthcare Organizations
03
J U N E 2019
Why your Cloud provider’s business must be as stable as yours?
CHANNEL PARTNER Delivering the Best In-Depth Services
A10 Networks’ Thunder 14045 TPS
Epicor ERP Positioned as a Visionary in Gartner 2018 Magic Quadrant for Cloud ERP for Product-Centric Midsize Enterprises
MANAGING DIRECTOR: TUSHAR SAHOO
EDITORIAL
CEO: RONAK SAMANTARAY DIRECTOR: ANUSHREE DIXIT anushree@gecmediagroup.com
Three recent interesting research surveys by Dimension Data, Fortinet and KPMG, give us a 360-degree view into the regional and global state of cybersecurity and the role of the CISO. The Dimension Data, NTT Security’s 2019 Global Threat Intelligence Report stunningly reveals that global enterprises are woefully prepared to meet the onslaught of cyber security challenges. The global average for cybersecurity maturity is 1.45 out of a maximum score of 5. Regionally, the Dimension Data and NTT report indicates that things are better here in comparison to the global average. The ranking of cybersecurity maturity across Middle East and Africa is 1.77, above the global average of 1.45. While these are positive gains for the region, and show a high level of concern, because of the GCC’s volatile geopolitical centricity, CISO’s need to continuously invest and remain ahead of state-led threat actors. Another fascinating report comes from Fortinet, that assesses the ability of an organisation built up using industrial control systems to integrate with digital technologies, while remaining secure. Fortinet’s State of Operational Technology and Cybersecurity Report reveals that a stunning 74% of industrial organisations, some of them mission critical organisations, experienced a data breach in the last 12 months. While 62% organisations stated intentions to dramatically increase their cybersecurity budgets, another stunning revelation was that only 9% of CISOs are overseeing OT or industrial control systems security. Those organisaARUN SHANKAR tions are now adjusting their cybersecurity Editor strategies, with 70% stating their intention arun@gecmediagroup.com to make the CISO responsible. Considering these statistics, it is evident that industrial organisations have just begun their journey into adoption of cybersecurity fundamentals. In the third revealing survey, this time around consumer sentiment, KPMG’s Consumer Loss Barometer report indicates continuous evolution of digital transformation is outstripping the pace of cyber security in consumer facing organisations, such as retail. As a result, there is a disconnect between consumer expectations and ability of organisations to meet those expectations. In our top executive feature for this month, Ahli United Bank Group’s CISO, Ross McNaughton eloquently spells out the balancing act that CISO’s undertake on day to day basis, managing investments to contain short term, medium term and long-term threats. McNaughton draws attention to IT Debt, that every CISO inherits, based on how the organisation has managed its IT and cybersecurity policies and investments. With regard to challenges of managing an organisation’s digital transformation and cyber security profile, McNaughton indicates it is a fine balancing act between now and tomorrow. For more on what McNaughton has to say and other in-depth stories turn the pages of this month’s Cyber Sentinel. Best wishes and Eid Mubarak to all our readers and followers. Arun Shankar arun@gecmediagroup.com ë
EDITOR: ARUN SHANKAR arun@gecmediagroup.com SUB EDITOR: DIVSHA BHAT divsha@gecmediagroup.com EVENTS EXECUTIVE: SHRIYA NAIR shriya@gecmediagroup.com GROUP SALES HEAD: RICHA S richa@gecmediagroup.com + 971 529 943 982
VISUALIZER: MANAS RANJAN LEAD VISUALIZER: DPR CHOUDHARY DESIGNER: AJAY ARYA ASSISTANT DESIGNER: RAHUL ARYA, DEEPAK KUMAR
SUBSCRIPTIONS INFO@GECMEDIAGROUP.COM SOCIAL MARKETING & DIGITAL COMMUNICATION YASOBANT MISHRA yasobant@gecmediagroup.com
DESIGNED BY
PRINTED BY AL GHURAIR PRINTING & PUBLISHING LLC. MASAFI COMPOUND, SATWA, P.O.BOX: 5613, DUBAI, UAE
I N FO M E DIA PUBLISHED BY ACCENT INFOMEDIA MEA FZ-LLC PO BOX : 500653, DUBAI, UAE 223, BUILDING 9, DUBAI MEDIA CITY, DUBAI, UAE PHONE : +971 (0) 4368 8523 31 FOXTAIL LAN, MONMOUTH JUNCTION, NJ - 08852 UNITED STATES OF AMERICA PHONE NO: + 1 732 794 5918 A PUBLICATION LICENSED BY INTERNATIONAL MEDIA PRODUCTION ZONE, DUBAI, UAE @COPYRIGHT 2013 ACCENT INFOMEDIA. ALL RIGHTS RESERVED. WHILE THE PUBLISHERS HAVE MADE EVERY EFFORT TO ENSURE THE ACCURACY OF ALL INFORMATION IN THIS MAGAZINE, THEY WILL NOT BE HELD RESPONSIBLE FOR ANY ERRORS THEREIN.
J U N E 2 019
05
SPECIAL REPORT
CYBER WARFARE ACROSS THE GLOBE – VARIOUS ATTACKS, VARIOUS MULTITUDES
KEY STATS TO NOTE
Cybersecurity Ventures predicts cybercrime will cost the world in excess of $6 trillion annually by 2021, up from $3 trillion in 2015.
Global spending on cybersecurity will exceed $1 trillion cumulatively for the 5 year period from 2017-2021, according to Cybersecurity Ventures.
world will need to cyber protect 300 billion passwords globally by 2020.
There were nearly 4 billion Internet users in 2018 (nearly half of the world’s population of 7.7 billion), up from 2 billion in 2015.
$6 tn
$1tn
4 bn
300 bn
4 bn
According to Q2 2019 Cyberwarfare Report, Phone hacking became prominent during the first three months of the year as reports emerged of the mobiles of prominent people—such as Amazon CEO Jeff Bezos, as well as a prominent candidate for Prime Minister of Israel, and a former PM of the country—being compromised
Nine out of 10 teens who have been bullied through social media report that they’ve ignored it. A further 84% said they’ve seen others attempt to stop cyberbullies. (Source: DoSomething.org)
06
J U N E 2019
There were 137.5 million new malware samples in 2018 (AV Test) and we’re already at 24,55 million new samples in 2019
The world’s digital content is expected to grow from 4 billion terabytes (4 zettabytes) in 2016 to 96 zettabytes by 2020
In 2018, 93% of malware observed was polymorphic, meaning it has the ability to constantly change its code to evade detection (2019 Webroot Threat Report)
A UK survey of more than 10,000 youths discovered that 69 percent reported doing something about abusive online behavior directed toward another person. (Source: DoSomething.org)
On March 12, 2019 Wall Street Journal reports an internal U.S. Navy report finds that service branch and its industry partners “under cyber siege” by Chinese hackers and others who have stolen national security secrets in recent years
The Global Youth Online Behaviour Survey conducted by Microsoft ranked India third in cyberbullying, with 53% of the respondents, mainly children admitting to have experienced online bullying, falling behind only China and Singapore
93 %
137.5 mn
IN NEWS
According to a Pew Research Center study, Some 45% of teens say they are online almost constantly, and these constant users are more likely to face online harassment. Fully 67% of teens who are online almost constantly have been cyberbullied, compared with 53% of those who use the internet several times a day or less.
Thailand, UAE and Iran are the countries with highest share of users attacked with ransomware from 2017 to 2018. (KSN Report: Ransomware and malicious cryptominers 2016-2018)
Mobile ransomware has skyrocketed: it increased by 33% in 2018 (2019 Internet Security Threat Report by Symantec)
SPECIAL REPORT
COMBATTING E-CRIME WITH 7 STEPS
Dubai Police has always been a step ahead when it comes to introducing advanced and out-of-the-box platforms to address citizens’ problems. As a pivotal step towards encouraging the citizens to not shy away from reporting e-crimes, Dubai Police recently launched the e-crime platform.
complaint regarding electronic crimes ranging from blackmail to hacking and illegal money transfers on www.ecrime.ae. “In the past, victims of online crime were confused of who to report their complaint to,” said Al Shehhi. “They either went to a police station or called 999 or 901, but the e-crime platform is an easy way for the public to lodge complaints. Dubai Police are keen to provide innovative solutions and easy and smart services,” he added. “The platform has been launched to encourage people to come forward and lodge their complaints in a confidential and secure way if they are victims of e-crimes,” said Al Shehhi. Often victims of e-crime don’t report crimes committed against them because they are embarrassed and don’t want their personal information going public, but with this new platform, Dubai Police believe they will be able to better assess e-crime rates and be in a better position to combat it. A victim can visit the site, register by entering their Emirates ID and phone numbers before submitting details of the incident they want to report. To date there have been 5,000 tip offs.
CAPTAIN ABDULLAH AL SHEHHI, DEPUTY DIRECTOR OF THE CYBERCRIMES DEPARTMENT OF DUBAI POLICE
HOW TO USE THE PLATFORM Click on www.ecrime.ae Answer the question: Is the report submitted related to the internet or cyberspace? (Email, social media, internet calls, cybercrime, hacking, blackmail) l Choose the complaint type: Personal, private entity, local government entity or federal entity l Submit your Emirates ID electronically l Submit your address, mobile number and email address l The platform will text you a verification code to your mobile phone which you then enter on the platform l Enter the complaint details and submit l l
In wake of the recent WhatsApp hacks that left the consumers with no access to their account or stolen data, Dubai Police assured them a viable assistance and technical support. Residents who have their WhatsApp accounts hacked can recover their accounts by contacting Dubai Police through their e-crime platform, according to a statement released by Dubai Police lately. Captain Abdullah Al Shehhi, Deputy Director of the Cybercrimes Department of Dubai Police, said that residents can report crimes on the
platform as well as recover their hacked accounts. Dubai Police said that the e-crime platform had received 9,046 complaints since its launch on May 3 last year. “About 1,277 complaints were for technical support to recover hacked social media accounts. We recovered 1,177 WhatsApp accounts, 90 Instagram accounts and ten accounts of Facebook and SnapChat.” Al Shehhi urged the public to use the e-crime platform instead of coming to the station for quicker turnaround times. A victim can lodge a
J U N E 2 019
07
SPECIAL REPORT
GEN. DEPT. OF CRIMINAL INVESTIGATIONS
CYBER INVESTIGATIONS DEPT.
About eCrime eCrime is an online service for receiving internet-related crime reports and complaints such as online threats, extortion, hacking and fraud. This service was initiated based on Dubai's 2021 strategy, where it was agreed to design and initiate an online service that is developed to receive complaints that are related to cybercrime.
This service was studied and analyzed on the behalf of the (Cyber Investigations Department). The purpose and design of the eCrimes platform is to serve and support the community by creating a platform that allows the public to easily submit cyberrelated reports and complaints. The service will be efficient and responsive to all complaints submitted by the public. 08
J U N E 2019
www.ecrime.ae
DEEP DIVE
AN ANALYSIS OF TINYPOS
For the last year Forcepoint X-Labs has been collecting samples of Point-ofSale (POS) malware that stood out for their hand-crafted nature, were written in assembly code and were very small in size (2-7kB). In this blog Forcepoint examines the attributes of TinyPOS and explore why retail organisations are still faced with POS malware and thus what can be done to protect organisations, consumers and their personal data.
WHAT MAKES POS TERMINALS SUCH AN ATTRACTIVE TARGET? Put simply, POS malware is still effective at collecting large amounts of personal information. For example, in March 2019 Earl Enterprises issued a public-facing notification of a data breach affecting multiple restaurants in their portfolio including the Planet Hollywood and Buca di Beppo brands. They had discovered that POS malware had been siphoning personal information from their systems for approximately 10 months. On 9 April 2019 Microsoft ended support for Windows Embedded POSReady2009 (a Windows XP-derived POS OS). As systems continue to use legacy software, and hardware, it becomes increasingly difficult to protect from opportunistic and determined adversaries. We then have to factor in human fallibility. Consumers may still prefer to sign for their transaction, or even swipe their credit card, rather than convert to EMV Chip-and-PIN. Further, many regions have not yet benefited from the improved security afforded by wide-scale adoption of EMV to authenticate card transactions. While Swipe-and-Sign still exists merchants may not be adopting the more secure standards demanded of EMV. Data from EMVCo shows the United States still lags behind other regions in that only 53% of card-present transactions are EMV, compared with up to 97% in Europe. As such we believe that POS malware looking
10
J U N E 2019
for Track 1 and Track 2 credit card data will still continue for as long as wide-scale adoption of EMV remains a challenge.
TINYPOS – POINT-OFSALE MALWARE TO COLLECT SWIPE-AND-SIGN DATA During our study we collected 2000 unique samples within the Tiny ecosystem. We grouped these into “loaders”, “mappers”, “scrapers” and “cleaners”. Loaders – an obfuscated executable with simplistic downloader functionality. The core functionality of a loader is to establish communication with a hard-coded set of Command-and-Control servers. This communication results in longer code snippets being downloaded into memory, concatenated and executed. A system process list is then generated confirming the presence of a POS system. Additional downloads then occur. Remember that the loaders are incredibly small in size (2-7kB). Mappers – this component gathers information about the machine and environment upon which it was executed. Through this network reconnaissance activity we believe mappers helped the operators to gather extensive knowledge of different POS system layouts and deploy campaigns targeting only specific retailers. Scrapers – these components work like any other POS memory scraper with the goal of collecting Track 1 and Track 2 credit card data.
Cleaners – a component that cleans up running processes, registry keys, tasks and files once the operation is finished. The most probable initial vector would be a remote hack into the POS system to deliver the Loaders. Other options could include physical access (unlikely) or a rogue auto-update to deliver a compromised file to the POS operating system.
PROTECTION STATEMENT AND INDICATORS OF COMPROMISE Forcepoint customers are protected against TinyPOS at the following stages of attack: Stage 5 (Payload) - protection from the deployed POS malware components. Stage 6 (Command and Control) – protection from the communication to and from the hardcoded C&C servers.
CONCLUSION While Swipe-and-Sign exists as an authentication option for card-present transactions, POS malware like TinyPOS will continue to be effective. We strongly recommend that retailers and banks aggressively pursue a move to EMV (at least Chipand-Signature, preferably Chip-and-PIN). It is recommended that an audit be performed on any system storing and transmitting personal data in relation to how that data is managed and stored. The goal should be to make it harder for credit card data to be extracted from the retailer’s systems. This includes while in transit. ë
G L O RY AWAITS THE CHAMPIONS
1 ST OCTOBER 2019 FOR MORE VISIT g e c m e d i a g r o u p. c o m
DEEP DIVE
TACKLE TOMORROW’S DIGITAL BUSINESS SECURITY RISKS As cybersecurity risks increase in digital business, organizations continue to struggle in attracting, retaining and, most critically, developing security talent.
EARL PERKINS,
VICE PRESIDENT, GARTNER ANALYST
Security and risk management leaders responsible for information security must evolve their practices and organizational cultures to keep pace with the digital business era. “Risk management, governance, business continuity and people — the most important asset — are critical elements of a successful risk and security program,” says Earl Perkins, Vice President, Analyst at Gartner says. “When allocating resources and selecting products and services this year, security and risk management leaders should consider three important strategic planning assumptions.”
12
J U N E 2019
By 2022, 40% of business continuity management (BCM) programs will be integrated into the digital business risk management structure rather than exist as separate practices. The momentum of digital transformation projects within digital business will outpace the ability of organizations to accommodate changes related to security. Concurrently, the growing need to provide 24/7 technology services to support digital business and customer-facing services is changing the way that organizations interact internally and externally. These changes, as well as the constant threat of cyberattacks, will
lead organizations to formalize the relationship between BCM and digital information security functions. “Stakeholders should be urged to accept BCM as part of the organizational structure,” says Perkins. “Managers within the digital business who oversee the delivery of critical activities will need to gain the necessary skills to engage with resilience planning as a business-as-usual function.” Through 2022, 30% of large enterprises will build a security skills management program including experimental recruiting and talent development practices. Cybersecurity risks are increasing despite the efforts of trained security professionals. Organizations continue to struggle with attracting, retaining and developing security talent. Organizations must change their talent development and recruiting practices to be able to address missing skills. Start by building and developing a list of new competencies and skills required to support digital business initiatives. Then adapt short-term skills management practices by outsourcing security functions to managed security service providers (MSSPs) and/or delegating responsibilities to other internal staff. By 2022, 75% of organizations that outsource email and collaboration tools won’t meet their critical recovery objectives during a supplier outage. Email and collaboration applications are considered mission-critical resources for most organizations. Conducting business without them can impede production, result in lost transactions and hamper crisis management activities. When an organization outsources these applications, many suppliers do not provide recovery with short timeframes. “It’s imperative for the organization to maintain internal control and governance over all applications used in the delivery of products and services,” says Perkins. “It is also crucial to understand your vendor’s recovery commitments and communication protocols for outages to ensure they meet recovery requirements.” ë
DEEP DIVE
SAFEGUARDING YOUR ORGANIZATION FROM ATTACKS VIA YOUR THIRD-PARTY VENDORS Realizing that most large organizations today have sophisticated security defenses, bad actors are beginning to target third-party vendors, as a means to gain access to an enterprises’ network.
In 2018, over 11 significant breaches were caused by exploitation of third-party vendors and according to Carbon Black’s 2019 Global Incident Response Threat Report, 50% of today’s attacks leverage what they call, “island hopping”, where attackers are not only after an enterprises’ network, but all those along the supply chain as well. Given that third-party vendors are an integral part of most organizations’ ecosystem something that isn’t going to change anytime soon—there are seven steps you can take to exert better control over third-party vendor network connections and secure remote access.
standards you expect them to comply with, and you should routinely review compliance performance with your vendors. At a minimum, your vendors should implement the security basics, such as vulnerability management. You should also enforce strong controls over the use of credentials—always with a clear line-of-sight into who is using the credential, and for what purpose.
AUTHENTICATE USER BEHAVIOR
MONITOR & EXAMINE VENDOR ACTIVITY First, it’s imperative to scrutinize third-party vendor activity to enforce established policies for system access. You want to understand whether a policy violation was a simple mistake, or an indication of malicious intent. You should implement session recording to gain complete visibility over a given session. And finally, you should correlate information so that you have a holistic view that enables you to spot trends and patterns that are out of the ordinary.
LIMIT NETWORK ACCESS Most of your vendors only need access to very specific systems, so to better protect your organization, limit access using physical or logical network segmentation and channel access through known pathways. You can accomplish this by leveraging a privileged access management solution to restrict unapproved protocols and direct approved sessions to a predefined route.
APPLY MULTIPLE ROBUST INTERNAL SAFEGUARDS As with other types of threats, a multi-layered defense is key to protecting against threats arising
14
J U N E 2019
MOREY HABER, CTO, BEYONDTRUST
from third-party access. Apply encryption, multifactor authentication (MFA), and a comprehensive data security policy, amongst other measures.
EDUCATE YOUR INTERNAL AND EXTERNAL STAKEHOLDERS On average, it takes about 197 days for an organization to realize that it has been breached. A lot of damage can be done in 197 days. Educate across the enterprise and continually reinforce the message that the risks are real.
CONDUCT VENDOR ASSESSMENTS Your service-level agreement (SLA) with third-party vendors should spell out the security
Vendor and partner credentials are often very weak and susceptible to inadvertent disclosure. Therefore, the best way to protect credentials is to proactively manage and control them. You can do this by eliminating shared accounts, enforcing onboarding, and using background checks to identity-proof third-party individuals that are accessing your systems.
PREVENT UNAUTHORIZED COMMANDS & MISTAKES One step you want to take is to broker permissions to various target systems using different accounts, each with varying levels of permission. You should restrict the commands that a specific user can apply, via blacklists and whitelists, to provide a high degree of control and flexibility. To this end, use a privileged access management solution, enable fine-grained permission controls, and enforce the principle of least privilege (PoLP). Vendor access is often inadequately controlled, making it a favored target of cyberattackers. By layering on these seven steps, you can exert better control over third-party access to your environment and make significant progress toward reducing cyber risk. ë
DEEP DIVE
TENABLE UNVEILS NEW INNOVATIONS FOR CYBER EXPOSURE ANALYTICS Tenable unveiled new innovations to its Cyber Exposure analytics capabilities in Tenable Lumi. These innovations leverage machine learning to automatically correlate vulnerability and threat data together with asset criticality in a single platform. For the first time, organizations can accurately score, trend and benchmark their cyber exposure based on the likelihood the exposure will be exploited and the business criticality of the impacted assets. This will enable organizations to evolve from a technology - to a risk-based approach to prioritize remediation, communicate to the business and make datadriven decisions to reduce cyber risk. Tenable has unveiled the following innovations for Cyber Exposure analytics via Tenable Lumin: Cyber Exposure Score: The Cyber Exposure score is an objective measure of cyber risk, derived through data science-based measurement of vulnerability data together with threat intelligence and asset criticality. The score is automatically generated through machine learning algorithms which combine the Tenable Vulnerability Priority Rating (VPR), for the likelihood of exploitability, with the Tenable Asset Criticality Rating (ACR), for the business criticality of the impacted asset. Organizations can also leverage scoring to trend improvement over time as a measure of security program effectiveness. Cyber Exposure Benchmarking: Organizations can use the Cyber Exposure score to benchmark themselves against industry peers and measure their overall cyber risk posture. Tenable has the industry’s most extensive vulnerability intelligence, processing over 1.5 billion instances of vulnerabilities per week, which is coupled with data science to create its benchmarking knowledge base. Organizations can also drill down to benchmark internal groups against each other by business unit or geography, for example. Remediation Guidance Workflow: Security teams will receive a list of the top recommended remediation actions to reduce the organization’s cyber exposure. For additional information, teams can drill down into specific vulnerabilities
OFER BEN-DAVID, CHIEF PRODUCT OFFICER AT TENABLE
or assets for business and technical context to enable more effective remediation. “As Cyber Exposure continues to rise in strategic importance, the fundamental question facing organizations is ‘how secure are we?’ These innovations fill a huge void in the industry by enabling organizations to apply business impact and risk data to answer this question with confidence,” said Ofer Ben-David, chief product officer at Tenable. “Extending our deep
expertise in vulnerabilities to create an objective measure of cyber risk will help transform how cyber-related technology and business decisions are made.” Tenable unveiled these innovations today at Edge 2019, its annual user conference. They will be available to customers starting in Q3 2019 as part of the Tenable Lumin beta. Tenable Lumin will be generally available in the second half of 2019. ë
J U N E 2 019
15
TRENDING
INFOBLOX REVEALS TOP CYBERSECURITY CHALLENGES IN HEALTHCARE ORGANIZATIONS IT Professionals still struggle with patching operating systems and managing shadow IT
Almost two years since WannaCry, the ransomware attack that brought the NHS (National Health Service) in UK to a halt, healthcare IT professionals feel more confident in their ability to respond to a cyber-attack. That’s according to new research from Infoblox Inc., the leader in Secure Cloud-Managed Network Services. As healthcare providers continue to undertake digital transformation initiatives in an effort to improve efficiencies and the quality of care they deliver, the risk of falling victim to cyberattack is increasing. Infoblox commissioned a survey of healthcare IT professionals in the UK, US, Germany and the Benelux Union to gauge the preparedness of the industry to tackle cyberthreats. The research reveals that 92 percent of healthcare IT professionals are confident in their organization’s ability to respond to a cyber-attack, compared to only 82 percent two years ago. More than half (56%) have automated systems in place that actively scan their networks for suspicious activity, and around a third (31%) have their own Security Operation Centers (SOCs) for the same purpose. However, despite this confidence, the industry still faces challenges.
ASHRAF SHEET,
REGIONAL DIRECTOR - MEA, INFOBLOX
RANSOMWARE In the event of ransomware, nearly half (39.7%) of IT professionals are not aware if their organization would be willing to pay a ransom in the event of a cyber-attack. Additionally, a quarter (24%) remain defiant, however, stating that they would be unwilling to pay a ransom. A large amount of uncertainty remains for IT professionals about how they should respond to potential ransomware attacks.
GREATER INVESTMENT Healthcare organizations are spending between 11 and 20 percent more on cybersecurity than in 2017, with the top three investments being anti-virus software (59%), firewalls) (52%),
16
J U N E 2019
and application security (51%). Additionally, employee education has grown in popularity, with a ten percent higher investment in 2019 compared to 2017. The reason for this has much to do with improving email hygiene in an effort to avoid phishing scams and the delivery of ransomware.
CONNECTED DEVICES Healthcare IT professionals are addressing the growing adoption of the Internet of Things (IoT) and as a result the number of security policies in
place for new connected devices has increased from 85 to 89 percent, with fewer respondents doubting the effectiveness of these policies (9% in 2019 vs. 13% in 2017). The majority (66%) of connected devices now run on Microsoft Windows 10, however Linux (33%) and Mac OS X (31%) popularity is growing significantly since 2017. Over a quarter of medical devices continue to run on old operating systems including Microsoft Windows 7 (26.5% running medical devices) and Microsoft Windows 8 (4.6% running medical devices). Also, an alarming number of IT professionals (16.6%) do not have the ability to patch their operating systems, leaving their network wide open for attacks. Victor Danevich, CTO of Systems Engineering at Infoblox said: “Healthcare companies hold some of the most sensitive and valuable personal data, making them extremely vulnerable to cyberattack. Additionally, as the number of internet connected devices in this industry continues to skyrocket, cybercriminals will have a surplus of options to mine for network vulnerabilities” “Although healthcare IT providers are some of the most educated and concerned security buyers, they mustn’t become complacent, and must continue to think strategically about ensuring the security of their networks and – most importantly – the safety of their patients.” Ashraf Sheet, Regional Director, Middle East & Africa at Infoblox says, “It’s encouraging to see healthcare organizations across the globe taking action in the form of increased cybersecurity spending, managing connected devices, and educating employee security protocols. By taking such precautions, healthcare IT providers are right to be more confident about their ability to tackle threats to their network. They mustn’t become complacent, though, and must continue to think strategically about ensuring the security of their networks and – most importantly - the safety of their patients.” ë
Discover the Edge.
Smart Solutions. Real Business. Rittal solutions for the technology of the future. Edge computing enables enormous amounts of data to be processed directly at the place where they arise. Securely and in real time. Rittal prepares you and your IT infrastructure for new challenges - exibly, economically, and globally.
Visit us at
Sheikh Rashid Hall Stand SR-E2
For Enquiries:
Rittal Middle East FZE Tel: +971-4-3416855 I Email: info-it@rittal-middle-east.com I www.rittal.com/uae-en
TRENDING
FAIZ SHUJA, CO-FOUNDER, SIRP
18
J U N E 2019
TRENDING
A COORDINATED APPROACH TO CYBERSECURITY A.I. automation, quantum computing, agile neural networks and advanced image processing powers are just some of the latest technologies at our disposal to improve both business and public services. However, these same advantages are also being used by cyberattackers to create increasingly malicious code and formidable forms of infiltration. An alarming increase in significant security breaches worldwide suggests that organizations are struggling to keep ahead of these changes with current cybersecurity methods. Despite this, 75% of enterprise organizations admit to routinely ignoring security alerts. Suffering a high-profile breach can not only cause major financial losses but untold damage to the perceived reliability of an organization to its users and stakeholders. With this in mind it becomes imperative that security teams employ the same level of sophistication in their defence mechanisms to help mitigate the risk of a major cyber attack. Whilst the sheer number of security tools to hand can seem daunting, the safest way to strategise efforts and build a proactive plan combines four key components: threats, vulnerabilities, incidents and risks.
CRITICAL COMPONENTS TO A STRATEGIC CYBERSECURITY PROGRAM The ability to efficiently identify and manage vulnerabilities across the infrastructure sets the foundation for any robust cybersecurity program. It involves staying on top of activities such as patch management. The number of possible vulnerabilities can climb to the thousands for large and complex infrastructures making it difficult to prioritize and manage this to scale, particularly without an effective automation platform in place. Mis-management of this process not only risks preventable security breaches, such as the recent cyberattack on Dubai’s ride-hailing app Careem, but can cost companies major deals and projects. Huawei, the world’s largest maker of mobile network equipment, is currently being called into question as a reliable provider of 5G infrastructure due to its failure to demonstrate an ability to address and remedy weaknesses in its security systems. Next, security teams must have access to the latest global threat intelligence in order to make informed and strategic decisions. In 2017-18 attackers used Triton malware to infiltrate
industrial control systems at petrochemical plants in Saudi Arabia on two occasions. Publicly available research released by FireEye revealed the slow and subtle approach used to avoid detection, the attackers motivations, and a list of indicators of compromise used in the attack. This type of data provides the crucial insight required to create effective and preventative security measures. Even with a robust defence system in place, proper incident management plans will ensure a rapid response to any potential or actual breaches. $6 million was stolen from Bank Islami Pakistan accounts through fraudulent payments made using personal customer details in 2018. As the attacks were originating from outside Pakistan the bank was able to suspend its international payment system and implement real-time monitoring of all card transactions. This created a controlled response to the incident which limited net loss and the number of affected customers. Last but not least, a comprehensive risk assessment allows organizations to assess potential threats and vulnerabilities against their likelihood and how critical the impact would be. In one thoroughly conducted example, researchers from the University of Georgia simulated ransomware attacks on industrial controls at a water treatment plant, allowing them to change chlorine levels, shut down valves and send false readings, providing vital intel. However, the majority of assessments can effectively identify and analyse risks through table-top exercises. When done properly, this exercise should provide a clear scoring metric and a numerical baseline to measure improvements against. This clearly presented data will act as a communication tool to board members and executives, helping to justify the correct cybersecurity solutions for the organization and the financial backing to do so.
MANAGING AND MITIGATING CYBERSECURITY RISKS All of these components provide crucial sources of information but are often considered as
individual elements which operate in silo. This can create significant weaknesses in a system even if respective areas are being properly managed. For instance, the infamous WannaCry ransomware attack managed to infiltrate the UK’s National Health Service (NHS) in 2017. It took teams one-week to control the outbreak and regain secure access to all systems, during which time over 80 hospital trusts and 8% of all general practitioners nationwide were severely disrupted. This resulted in a total cost of £92 million through lost clinical services and reactive security implementation, in addition to a PR storm of bad press. The implementation of organization-wide software updates, including a new patch released by Microsoft two-months prior, could have prevented the breach, and the UK’s government were advised on a critical need to address improvements in NHS security systems up to year before the attack. The length of time it took to secure the infrastructure was exacerbated through a lack of contingency planning, meaning individual hospital sites had no clear process in place to control the breach. In response to the situation, £60 million of public funds were immediately allocated to cybersecurity efforts with a further £150 million added to budgets for 2018/19 – 2020/21. Proactive management should not only consolidate information on threats and vulnerabilities but ensure governance and compliance of policy, mitigating the risk of problematic outcomes such as these.
A CONSOLIDATED SOLUTION FOR A SECURE FUTURE In cybersecurity taking a risk-based approach to operations ensures a unique edge. Consolidating the vast amounts of data and information is one sure way to streamline the efforts of security teams. Organizations will do well to take advantage of powerful software solutions which can support automisation, present intelligence and provide clear updates on scoring metrics in one platform. ë
J U N E 2 019
19
TOP OF MIND
WHY YOUR CLOUD PROVIDER’S BUSINESS MUST BE AS STABLE AS YOURS? Digital businesses cannot afford to have unauthorized data access in the Cloud nor have their Cloud Services Provider unexpectedly shut down shop, says Yasser Zeineldin, CEO at eHosting DataFort.
At the start of this decade, many regional IT managers expressed concern whether their organizations would ever embrace Cloud as a platform or not. They mused that Cloud is perhaps suitable for very specific workloads, but they would never migrate these mission critical workloads to an external platform. As we move into the next decade, much of the regional mindset has changed to embrace Cloud as a business enabling platform, while keeping mission critical workloads on a Private Cloud or even Hybrid Cloud platform. The sheer cost and agility advantages of the Public Cloud platform is driving regional IT spending into this area at a double-digit growth rate. The requirements of in-country data regulations and compliance is attracting large Cloud providers to invest locally. And such players are increasingly investing inside the region and in countries like the UAE and Saudi Arabia, in a relatively steady but consistent manner. According to global research and consulting firm Gartner, the number of Managed Cloud Services Providers is predicted to triple by 2020. So, all seems to be well established for rapid movement forward into the realm of wide spread Cloud adoption and migration. But global risk and cyber security executives continue to remain concerned about relatively weak security controls and policies that exist across emerging Clouddata platforms in general. According to Gartner’s latest Emerging Risks Report and Monitor, the majority of risk executives reported being most concerned about the probability and impact of potential data risks associated with Cloud Computing. While adoption and migration of Cloud delivers immediate capex and opex benefits and brings agility into the organization, IT and cyber security managers must balance the speed of adoption with increasing levels of control
20
J U N E 2019
YASSER ZEINELDIN, CEO AT EHOSTING DATAFORT
and compliance into the Cloud. Institutional and country level audits like GDPR, punitive measures by the Board, and other corporate shareholder guidelines, do not allow any lack of rigor by IT and cybersecurity managers in this area. For enterprises that are actively moving to the Cloud, there are the two principal risk areas that need to be actively monitored going forward. The first area of risk is the migration of on-premises
data to Cloud platforms and this could include sensitive, private and confidential information as well as historical transactional data about the organization, its suppliers as well as its customers. IT and cybersecurity managers must ensure that the same level of compliance around security policies and employee sign-on that exist on-premises are maintained for Cloud platforms as well. They must know where the data is resident and who is responsible for the migration and movement of the data to Cloud platforms. Once resident on the Cloud, they must remain in control and responsible for who has access to data in the Cloud. The Cloud data access policies must remain mirrored to the on-premise policies and it is the IT and cybersecurity managers who are responsible for this in-cloud compliance. The second area of risk is around the economic, financial and technology stability of the Cloud Hosting Provider and its ecosystem of suppliers. Rapid migration of data to the Cloud is driving the spawn of gold-rush Cloud Service Providers, either as direct or indirect players. IT and cyber security managers must be particularly concerned if their Cloud Services Providers change their Service Level Agreements or display any evidence of inability to provide their services. The combination of the above two risks, namely unauthorized access to Cloud data and inability to provide Cloud services, due to lack of compliance by either the organization or the Cloud Service Provider, can have disastrous consequences for the organization. While such an extreme situation is yet to occur in the region, global advisory firms like Gartner are drawing attention to the possibility, as an emerging data risk in Cloud Computing. As a corollary, end users are advised to engage with economically stable and well-entrenched Cloud Services Providers, while the gold-rush is ongoing. ë
Protect Your Information Wherever It Travels
Data Classification, DLP, and CASB only solve part of your data security challenge. Seclore Data-Centric Security makes it easy to unify your best-of-breed solutions and automatically add granular usage controls as information is discovered, classified, and shared. Ensure your information is protected and trackable wherever it travels with Seclore.
We look forward to showing you Seclore Data-Centric Security in action during the Future of IT Summit 2019, Dubai
www.seclore.com
TOP EXECUTIVE
The
Disruptive CISO In his current role at Ahli United Bank Group, Ross McNaughton serves as the Chief Information Security Officer for the nine different banks and entities that operate in the Middle East, Africa and the UK, overseeing all information and cyber security across the group.
n B Y: D I V S H A B H AT < D I V S H A @ G E C M E D I A G R O U P. C O M >
In an exclusive interview with Cyber Sentinels, Ross McNaughton shares his views about the cyber security industry. What are the skills required to be a CISO? The skills required to be a CISO tend to be a mix of business understanding, risk management and technical security. Nowadays, many CISOs are studying an MBA for this purpose in addition to the security-focused certifications. CISO’s who have come from a more technical background where there was pressure to fix all security issues need to learn that risk-aware appetite coupled with business drivers drive the cybersecurity programme. Business communication skills are crucial, especially when dealing with security subjects with executives and board level to ensure that they understand the business context of the often-technical security issues. A CISO must break these complex security subjects into risk-based definitions or concepts mapped to business issues. A CISO should also be able to step back and look at the overall risk posture and appetite of the organisation as Business leaders do not understand terms like malware and vulnerability. Explaining the risks to the business in terms of financial loss and loss avoidance will produce buy-in from management who previously may not have been receptive on the subject of cybersecurity. What are the challenges faced by a CISO? Generally, as a CISO, the priority is always being able to assist the board and the management in defining an
22
J U N E 2019
information and cybersecurity risk approach that is realistic for the organisation based upon how quickly the business is wanting to grow or change. The challenge during this is translating for the board and management the current levels of information and cybersecurity risk that they are running and the “IT Debt” from historic deployments within the environment. Often there is a perception that the business is in a reasonably secure state; however, the investment profile in security has not kept pace with the organisation’s pace of change, the increase in IT complexity or the dynamic threat landscape. Management awareness that there is no risk-free environment from cyber and information security events is crucial and planning to minimise the impact and disruption of a cyber event is just as important as trying to prevent the incident in the first place. Overall, this will assure the business that the organisation has cyber resilience against the threats that target them within the confines of the risk appetite and the investment costs they are willing to spend. Attacks on organisations are becoming increasingly sophisticated, cyber threat landscapes are evolving, and attackers are using increasingly diverse techniques and tactics coupled with machine learning to target organisations. An organisation needs to invest continuously and understand that what was sufficient three years ago is no longer adequate against modern attack vectors, and those one-time point investments which were cutting edge before, are no longer enough to protect large organisations who have public digital profiles. Unfortunately, businesses no longer have the capability,
TOP EXECUTIVE
ROSS MCNAUGHTON, CISO, AHLI UNITED BANK GROUP
J U N E 2 019
23
TOP EXECUTIVE
TOP PRIORITIES AS A CISO Cyber Security Awareness and Awareness Training
Managing and minimising Privileged Access
time nor funding to implement security controls to meet every threat all the time, so the focus becomes a question of what can be realistically protected by prioritising the information and cyber protection based upon the material business risk to deliver the business objectives. Often implementing various security controls and processes 80% of the way is better than pushing to achieve matured methods comprehensively due to the increasing time demands, cost and complexity of delivering the upper levels of maturity of a process, and other mitigating techniques can be used to alleviate the risks of the remaining gap. One of the examples would be during digital transformation. In the case of banks, when they want to launch a digital bank, managing the security risk on an on-going basis is a must as
Control Effectiveness
Managing Third Party Risk to the organisation
the evolutionary requirements of implementing rapid change require flexible approaches to continuously managing security risk throughout the process. According to you, how does digital transformation affect the security posture of any business? The core concepts of digital transformation are actually about beating the competition with innovative products using data-driven analytics as a differentiator. It is not just about putting everything into systems. With digital transformation, an organisation will launch features new to the market or launch services that bypass their competitors addressing a new market demand. The first entrant in the marketplace that has
ADVICE TO THE
SECURITY VENDORS
“LET THE CISOS BREATHE” 24
J U N E 2019
transformed digitally and has a unique value proposition delivered generally captures that market segment very rapidly and gains the vast majority of the business. To mitigate cybersecurity risks in this process requires these transforming organisations to understand how to manage risk on an ongoing more fluid basis rather than demanding a traditional cyber control-based approach which can be very rigid and slow. A significant proportion of cyber risk can be mitigated quickly but still not within the timelines required to meet the launch targets needed to stay competitive, so agile security risk management techniques must be embedded in the iterative business processes and technology development cycles to deliver securely and quickly. For example, in the Middle East, hackers like to attack banks on Thursday evenings as they know everyone is looking forward to the weekend. So, with regards to a new product launch which can often become a weekly event in a digitally transformed organisation, the threat profiles associated with product launches close to a weekend or public holiday would be higher than a typical business day or a mid-week launch. These threat scenarios and profiling activities become critical when managing cyclical cyber risk management cycles as part of digital transformation. At present, what are your expectations from cyber security solution vendors, channel partners, consultants? I wish they would stop over-selling in marketing publications, as it builds unrealistic expectations with organisation management on security product or security monitoring capabilities. For example, almost every vendor talks about cybersecurity AI’s when in reality there may be just 1 or 2 products in the market with real deepthinking AI. What most vendors have currently in the “AI” space are trained machine learning algorithms or trained behaviour analytics but not a “magic bullet” AI. Only when a person with knowledge of the current technology capabilities challenges the vendors on the claims of AI, do they accept the fact that it is not AI and just machine learning or sophisticated analytics. To counter this often misleading advertising, it is always better to have views from research analyst firms, as they spend significant amounts of analyst time assessing the capabilities of the current products, services and trends, as well as the upcoming product roadmaps and can provide insight into what is hype versus reality. ë
UPTO
10TB CAPACITY
SUPPORTS UPTO
64
CAMERAS
247
OPERATION
READY FOR
NVR, DVR HYBRID DVR & RAID STORAGE
180 TB/YEAR WORKLOAD
UPTO
256MB BUFFER SIZE
ROTATION VIBRATION
RV SENSOR
REPORT
THIRD ANNUAL STATE OF EMAIL SECURITY REPORT Mimecast Report Reveals a Major Increase in Targeted Attacks Like Impersonation Fraud, Spear Phishing and Business Disrupting Ransomware
Mimecast has unveiled its third-annual State of Email Security report. The report includes insights from 1,025 global IT decision makers, including the UAE. As cybercriminals continue to use email as a primary vehicle to steal data and deliver advanced threats, the results of this research provide valuable insights and trends around what’s affecting organisations the most and how they can improve their overall security posture. Social engineering attacks are a rising concern for organisations because they’re often one of the most difficult to control. Most notably, the report found that in the UAE impersonation attacks increased by 75 percent, with 77 percent of those organisations impacted by impersonation attacks having experienced a direct loss, specifically loss of customers (23%), financial loss (21%) and data loss (40%). Phishing attacks were the most prominent type of cyberattack, with 94 percent of respondents having experienced phishing and spear phishing attacks in the previous 12 months, and 75 percent cited seeing an increase in phishing attacks over the same time period. Not only are email-based attacks on the rise, but they’re affecting how confident people are in their organisation’s cybersecurity defenses – and ultimately the ability to do their jobs. According to the report, 39 percent believe it is likely or inevitable their organisation will suffer a negative business impact from an email-borne attack this year. The report also found that almost a third (62%) encountered a ransomware attack that directly impacted business operations. Fifty-eight percent of UAE respondents noted having downtime for two to three days, whereas 29 percent experienced downtime for four to five days. Email security systems are the frontline defence for most of attacks. Yet, just having and providing data on these attacks is not what creates value for most respondents,” said Josh Douglas, vice president of threat intelligence at Mimecast. “Survey results indicate that vendors need to be able to provide actionable intelligence out of the mass of data they collect, and not just focus on indicators of compromise which would only address past problems. The Mimecast Threat Analysis Center was also able to identify the top 5 industries being impacted by impersonation attacks which closely aligned with the findings in the report. Financial, Manufacturing, Professional Services, Science/Technology as well as Transportation Industries are top targets globally. Understanding these key pain points helps organisations build a more comprehensive cyber resilience plan.” ë
The State of Email Security Report 2019 United Arab Emirates Findings
Email Attacks 6%
39%
believe suffering a NEGATIVE BUSINESS IMPACT from an email-borne attack is either LIKELY OR INEVITABLE
feel it’s INEVITABLE their organisation will suffer a NEGATIVE BUSINESS IMPACT from an email-borne attack
Impersonation and Phishing Attacks: Rising and Worsening
75% saw the volume of impersonation ATTACKS INCREASE
43%
77%
saw increase in PHISHING
35%
94%
saw an increase in TARGETED SPEAR-PHISHING attacks with MALICIOUS LINKS
87%
of impersonation attack victims experienced a DIRECT RESULTING LOSS
saw email-based spoofing of business partners or vendors looking to gain access to money, sensitive intellectual property or login credentials (45% have seen this increase)
experienced a PHISHING ATTACK
Internal Email Threats and Data Leaks Short falls of Email security systems:
81%
39%
25%
saw an attack where malicious activity was spread from ONE INFECTED USER TO OTHER employees (10% above the global average)
noted an INCREASE in internal threats & data leaks
58%
reported a spread of infected URLS via email
32% 34%
41%
reported a spread of infected ATTACHMENTS via email
feel their email security systems fall short in MONITORING AND PROTECTING against email-borne attacks or data leaks in INTERNAL-TOINTERNAL EMAILS feel they fall short when it comes to OUTBOUND EMAILS not confident in the AUTOMATED DETECTION AND REMOVAL of malicious emails that have already landed in employees’ inboxes
Ransomware and Downtime
Almost a Third 62% encountered a ransomware attack that DIRECTLY IMPACTED BUSINESS OPERATIONS
92%
3 days
of ransomware victims suffered at least TWO DAYS OF DOWNTIME
average DOWNTIME after a ransomware attack
Attack Aftermath: The Real Cost of Email Intrusion
77%
of impersonation attack victims dealt with a DIRECT RESULTING LOSS (data, financial or loss of customers)
30%
40% experienced data loss
noted DATA LOSS as the thing that HURT THEIR ORGANISATION the most
21% cited financial loss
23% noted customer loss
Awareness Training :
26
J U N E 2019
All organisastions offer
72%
Other popular methods:
of awareness training happens IN A GROUP SESSION – the most widely used method
INTERACTIVE VIDEOS
61% 62%
60%
92%
62% encountered a ransomware attack that DIRECTLY IMPACTED BUSINESS OPERATIONS
of ransomware victims suffered at least TWO DAYS OF DOWNTIME
average DOWNTIME after a ransomware attack
Attack Aftermath: The Real Cost of Email Intrusion
77%
30%
40% experienced data loss
noted DATA LOSS as the thing that HURT THEIR ORGANISATION the most
21% cited financial loss
of impersonation attack victims dealt with a DIRECT RESULTING LOSS (data, financial or loss of customers)
REPORT
23% noted customer loss
Awareness Training
72%
:
All
Other popular methods:
of awareness training happens IN A GROUP SESSION – the most widely used method
61% 62%
INTERACTIVE VIDEOS
organisastions offer CYBERSECURITY AND AWARENESS TRAINING to their employees
60%
FORMAL ONLINE
68%
1:1 TRAINING SESSIONS REFERENCE LIST TIPS
32%
31%
say training is ongoing
conduct security awareness training only quarterly or less
5%
conduct training once at induction and never again or on an ad-hoc basis after a security breach
STATE OF EMAIL SECURITY REPORT – UNITED ARAB EMIRATES
Threat Intelligence
99%
ONLY
69% 24% 76%
ARE USING THREAT INTELLIGENCE sources, whether in-house or commercial
see threat intelligence as an EXTREMELY IMPORTANT asset to their organisation RIGHT NOW says it’s VERY IMPORTANT note that it will be EXTREMELY IMPORTANT in the NEXT 12 MONTHS
74%
4%
noted that threat intelligence efforts are NOT HAPPENING NOW OR IN THE FUTURE
are using email security systems that provide threat intelligence data to their security teams.74% said their organisation’s email security system can consume and apply threat intelligence data to their other security systems
Cyber Resilience
21%
currently planning or have a longer timeline for launching their cyber resilience plan
19%
in the process of rolling one out
59%
have a cyber resilience strategy in place
On average there are six different areas of focus EMAIL SECURITY NETWORK SECURITY
DATA BACKUP AND RECOVERY
WEB SECURITY END-POINT PROTECTION INTERNAL EMAIL PROTECTION
85% 82% 79% 78% 70% 79% Get The Full Report *Results from Mimecast-commissioned Vanson Bourne survey of 1,025 global IT decision-makers, Nov. 2018-Feb. 2019
Mimecast is a cybersecurity provider that helps thousands of organisations worldwide make email safer, restore trust and bolster cyber resilience.
Over the previous 12 months: 94% of organisations experienced phishing attacks 87% experienced email-based spoofing of business partners or vendors 75% of organisations saw increases in impersonation attacks; 43% phishing; and 39% internal threats/data leaks l 99% are using threat intelligence sources, whether in-house or commercial l Yet only 69% consider it an extremely important asset to their organisation right now l 24% say it’s very important l 76% note that it will be extremely important in the next 12 months l 74% use email security systems that provide threat intelligence data to their security teams l And 74% said their email security system can consume and apply threat intelligence data to their other security systems l 4% noted that threat intelligence efforts are not happening now or in the future 77% of impersonation attack victims dealt with a direct resulting loss 81% saw an attack where malicious activity was spread from one infected user to other employees 62% of organisations experienced a business-disrupting ransomware attack 39% believe it’s likely or inevitable they’ll suffer a negative business impact from an email-borne attack
www.mimecast.com | © 2019 Mimecast | SA-577
J U N E 2 019
27
TRENDING VENDOR TALKS
MR. SANJAY KATKAR,
JOINT MANAGING DIRECTOR & CTO AT QUICK HEAL TECHNOLOGIES LIMITED
28
J U N E 2019
VENDOR TALKS
BYOD SECURITY: WHY ENTERPRISES SHOULD BE KEEN TO SECURE THEIR CORPORATE NETWORKS FROM THE BYOD THREAT “For an effective BYOD policy, it is also crucial for the firm to clearly outline the ownership of apps and the security requirements for connected devices. Many companies have started adopting state-of-the-art enterprise mobility management (EMM) products from top enterprise security companies to enhance their enterprise security profiles.”
The concept of Bring Your Own Device (BYOD) is gradually becoming the new normal in today’s corporate world. Multiple organisations are adopting it without any second thought, largely since multiple research studies indicate that adopting a BYOD approach at the workplace can help drive significant operational benefits for businesses. The BYOD approach has been shown to significantly enhance cost effectiveness and time saving. Individuals are accustomed to their respective devices and are hence more comfortable using them, which helps them get more tasks done in lesser time. This drastically improves employee productivity and allows organisations to enhance their employee costto-output ratio. Given such multifaceted benefits, it is little wonder that the BYOD market is expected to cross $367 billion by 2022. However, the growing interconnectivity at the workplace and the proliferation of personal devices connected to enterprise networks is also leaving organisations vulnerable to newer, more sophisticated threats and cyber-attacks targeting mobile devices. The threat is further exacerbated by the fact that most personal mobile devices have extremely poor level of security and can be breached by cybercriminals to gain access to the larger enterprise network. Moreover, managing individual mobile devices through traditional device management measures becomes
impractical for IT teams, given the number of devices that are today connected to enterprise networks. BYOD: How enterprises can ensure robust security for connected mobile devices This is why businesses need to adopt cuttingedge enterprise security solutions which offer them greater control over the data and applications accessed by their employees’ personal devices, and allow them to seamless set policies and restrictions for individual devices. Doing so will enable organisations to keep pace with a fast-changing business environment and benefit from the advantages that the ever-increasing digitisation brings, without compromising their security. For an effective BYOD policy, it is also crucial for the firm to clearly outline the ownership of apps and the security requirements for connected devices. Many companies have started adopting state-of-the-art enterprise mobility management (EMM) products from top enterprise security companies to enhance their enterprise security profiles. Not only do such solutions whitelist/blacklist specific applications and application categories, but can also block installation through thirdparty app stores or suspicious links – one of the most prominent sources of malware infection in mobile devices. Moreover, EMM solutions can help IT teams ensure that all mobile apps remain updated to the latest version by allowing
them to push app installations/updates through a centralised server. Certain EMM solutions also enable effective containerization of data by creating a virtual sandbox for enterprise applications and data. This virtual sandbox cannot be accessed without internet connectivity. All critical data is also erased whenever the user exits the sandbox, or when the internet connectivity is lost. This helps ensure that employees can use their devices without unduly risking critical business data to breaches and hacks, and saves a significant amount of time and effort for IT teams. EMM solutions also allow companies to monitor the GPS location and internet traffic on BYOD devices to detect unusual activity or locate the device in case if it is lost. But no security policy can be a success without the most critical component of the enterprise ecosystem: the employees. This is why organisations must also look to conduct regular employee awareness initiatives to ensure that security policies are implemented across the board without fail. One thing is certain: BYOD is here to stay. There is absolutely nothing that can impede its growing proliferation in today’s corporate workplace. Companies should therefore accept the reality of BYOD, address the existing challenges, and embrace it to the fullest in order to capitalise on newer opportunities and achieve accelerated growth. ë
J U N E 2 019
29
CHANNEL PARTNER
THE NEXT STEP IN CYBER RESILIENCY ‘Disruptive Distributor’ Spire Solutions teams up with ThreatGEN™ to boost industrial cybersecurity capabilities in the Middle East by introducing the region’s first gamified industrial control systems/SCADA cybersecurity training
Recent cyberattacks such as WannaCry, NotPetya, and TRITON continue to threaten Industrial Control Systems (ICS) and Operational Technology (OT) networks increasing the risk of costly production outages, safety failures, environmental incidents and theft. According to Gartner insights on OT Security Hygiene, 2018, “by 2021, disruptive attacks on unsecured OT networks will have led to environmental damage or/and harm to people”. As most malware incidents in ICS/OT systems are caused by inappropriate human activity, an understanding of ICS Red Team/Blue Team capabilities is required to prevent security incidents. Training plays a pivotal role to protect against malware infections to Industrial Control Systems. To address customers’ challenges related to industrial cybersecurity capabilities and improve overall resiliency in the region, Spire Solutions has signed a strategic partnership with ThreatGEN™, founded in the US by worldrenowned industrial cybersecurity experts. This new cooperation brings the region’s first ICS cyber security training to the Middle East, that leverages cutting-edge computer gaming and simulation technology. The first training will be conducted in Dubai from July 8th to 11th, 2019. “The Middle East represents such an important economic region of the world, with energy organizations at the forefront. Protecting those organizations’ industrial control systems is paramount to safety and continued economic growth. We are extremely excited about the opportunity to work with Spire Solutions and to be a part of the mission to secure industrial control systems and train the workforce”, commented Clint Bodungen, Founder/President & CEO at ThreatGEN™. “Security awareness and training is the most
30
J U N E 2019
AVINASH ADVANI, CEO, SPIRE SOLUTIONS
fundamental component of an organization’s overall security posture and risk mitigation strategy. Learning cybersecurity from a hacker’s perspective is critical when it comes to understanding how attackers think. Based on computer
gaming technology, our ICS Red Team/Blue Team Training course will provide local organizations’ teams with an opportunity to learn adversarial tactics in conjunction with defensive methods”, said Avinash Advani, CEO at Spire Solutions. ë
CHANNEL PARTNER
SAMIR CHOPRA, FOUNDER & CEO, RNS TECHNOLOGY SERVICES
32
J U N E 2019
CHANNEL PARTNER
DELIVERING THE BEST IN-DEPTH SERVICES
With a team of experienced professionals, RNS Technology Services is determined in delivering the best possible information security technologies to its customers. Cyber Sentinels in an exclusive interview with the Founder and CEO of the company Samir Chopra. n B Y: D I V S H A B H AT < D I V S H A @ G E C M E D I A G R O U P. C O M
COMPANY ESTABLISHMENT Ten years ago, when Samir Chopra, currently the founder and CEO of RNS Technology Services stepped into this country as a Sales Manager for a privately held company, he realized that the branding and value that a partner brings to a customer is because of the depth of knowledge. “Unfortunately, in this country, partners are not recognized for the value of their knowledge and the depth that they bring in. Unlike vendors, partners can share their knowledge with technological discussions. Instead of working for one brand, I wanted to learn all aspects of technology. In 2015, we decided to launch a new flavour of offerings. In cyber security field, even today there are a lot of people who know to sell but not service,” said Samir. “We wanted to give value to the customers of not just spending millions while buying something but get an RoI based on their contribution. Feeling of making a difference and creating a brand was my ambition,” he added.
THE BUSINESS GROWTH Since 2015, every quarter has been a growth quarter for RNS. The year 2018 was particularly amazing as the company doubled their business. “We closed a double digit million dollars. This year we have also ranked up our hiring and today we are 30 employees in the United Arab Emirates. We have two offices in the region. Our headquarters is in Dubai and regional office is based in Abu Dhabi. We have taken steps to achieve our dream of being a security-oriented value-added partner across the globe. We have an operational office in Singapore and India and shall soon be opening an office in Qatar. We have high end security engineers who bring the highest knowledge and in-depth services to our customers.”
IN-DEPTH SOLUTIONS The company’s approach is always been to look at various layers of security and mix that with key
service offerings. We have 4 key pillars of security joined by one layer. Samir explains their solutions in brief l Endpoint Security We have signature-based endpoint protection and advanced endpoint security. Today, a lot of phishing, ransomware attacks, advanced malware threats are taking place. Attacks have become more sophisticated specially with emerging technologies coming in like AI, machine learning etc. EDR, patch management and Mobile Threat Prevention are the key areas that we look into. l Detection and Response The longer it takes to detect and respond to threats, the higher the cost it is as the damage is done. In the recent years, detection and response have become extremely important. With solutions like file integrating monitoring, security change management, configuration management, the expert security teams of RNS identify the full scope of a threat and identify the breaches. l Network Security Gone are the days people used to only rely on antivirus defences. Today, this term has undergone a dramatic shift. Organizations that used anti-malware are re-inventing security with the use of sensors for multi layered, centralized security systems. “Today with the perimeter disappearing and a lot of data centres moving to the cloud, network security plays a key part. These solutions adapt to the new changes and new architecture. They take care of not just the traditional forms of attack but new attacks like cloud-based attacks” l Identity and Data Governance Managing access to data, especially unstructured data, is a growing problem for organizations around the world. In this domain, Samir proudly says that they are making the strongest difference to organizations. “We are working with the largest banks, biggest ministries, etc. As a country we are very dynamic and adopting new technologies, so everything is getting tied to our identity. To make the society a secure digital workplace, is
where identity and access management helps. Enterprise Privileged Access Management is one of the key focus areas as well.” PAM helps to police the policemen to keep the integrity and keep the accountability and a software running in the system with privileges.
MANAGED SERVICES AND INFORMATION SECURITY RNS possesses the skill sets that customers require as a Managed Service Provider. Their team is built up with exceptional skills and provide the best possible services.
WHAT MAKES RNS DIFFERENT FROM ITS COMPETITION? The package to right path is making difference to the projects and giving customers the confidence. “There are organizations in Dubai who hire employees who have just passed out from universities, send them on field to work, ask them to open the help pages and configure. We are not here to experiment on the customer’s site. We are subject matter experts, focused on key technologies and key brands. We have chosen those brands as we know they have some key benefits that they bring over. We try to break the products before onboarding them.” The Key differentiators are l Being a specialist in particular domain l Focus on particular technologies l Invest in building key skill sets l Continuous training of employees who can deliver those services l Motivating employees with the right rewards to ensure that they keep customers
TOP PRIORITY Samir’s top priority has and will always be his team. “Taking care of my team is utmost important to me so that they take care of my business. If I take care of my team, how can anything else go wrong?” he concludes. ë
J U N E 2 019
33
REAL-LIFE
INSIGHTS ON BUILDING SCALABLE CYBERSECURITY SYSTEMS Today, enterprises are faced with a plethora of network security solutions attempting to address requirements including higher throughput, as well as advanced threat detection and mitigation. The challenges also require easy deployment across virtual and non-virtual infrastructures while also being cost-effective. Achieving a solution across those diverse and often competing requirements can be a challenge. In this article, we will provide insights and suggested best practices addressing how organizations may build secure network processing systems by introducing new approaches and their advantages.
4 KEY NETWORK-BASED CYBERSECURITY CONSIDERATIONS 1. HIGH THROUGHPUT The fundamental challenge with cybersecurity in today’s networks is that the amount of processing required for advanced cybersecurity detection and mitigation on a single packet or flow as it passes through the network fabric is increasing while network line rates are also increasing, resulting in less time to process the network traffic without impacting network latency. Figure 1 below highlights (per packet latency column) just how small the time is for security systems to process a packet at different lines rates. For a modern 4 gigahertz CPU, without taking into account pipelining and branch protection,
the CPU can execute 4,000 clock cycles per microsecond and execute one instruction per clock cycle on a single core. For scale, a simple C program that prints “Hello World” can take about 1,000 to 10,000 clock cycles to perform. Conclusion: As network speeds approach 40 gbps and above line rate, modern CPUs will struggle to execute the necessary cybersecurity protection code without impacting throughput or latency.
2. NETWORK TRAFFIC VARIABILITY Given the nature of different network protocols, as well as deliberate malicious manipulation of network traffic, cybersecurity systems must handle unexpected data in packet contents and headers.
WES BROWN,
DISTINGUISHED ENGINEER, LOOKINGGLASS CYBER SOLUTIONS
FIGURE 1: PER PACKET LATENCY BY LINE RATE
34
J U N E 2019
REAL-LIFE
Malformed network traffic can be the result of poorly implemented systems, inadvertent configuration problems or deliberate malicious changes to protocols, or applications or systems communicating over the network. Conclusion: Cybersecurity systems must handle traffic variability no matter what reason where that processing typically requires greater clock cycles, as more decisions need to be made.
3. DYNAMIC MANAGEMENT Cybersecurity systems must handle behavioral changes in detection and mitigation logic to meet the changing nature of network security. Conclusion: Systems must be provisioned and updated as conditions change without downtime, without impact to their service and with minimal latency.
4. COST EFFECTIVE As networks expand to the cloud and hybrid environments – where it may not be possible or desirable to deploy specialized hardware solutions – the cost of solutions to deliver on the other highlighted requirements is a key driver in the effectiveness of a solution. Conclusion: Where it makes sense, cybersecurity systems can leverage off-the-shelf hardware acceleration to make the solution more cost effective, or to reach performance levels that are not achievable with pure software.
Pros l Well understood, relatively fast l Most cost-effective when measured in programmer knowledge and time l Cost-effective hardware acceleration is possible using LLVM backend targets, i.e. eBPF Cons l Having to manage memory and call stack impacts security severely l Has historically been vulnerable to network variability due to C stack and buffer overruns l Memory management is hard and detailoriented, another source of variability issues such as memory leaks l Dynamic behavior requires the implementation of some level of interpretation, magnifying the above issues The following diagram shows a simplified flow of executing add_this(add_this(2, 1), 3) in C/ C++. In particular, data and execution state share the same stack – the parameters and return values are interleaved with the return address in the stack frame.
MODEL 2: VARIABLE MACHINE
Description l Statically allocated variables l All operations accept these variable addresses as arguments, and the result is put in a variable address l Strongly typed; operations are not polymorphic. A 16-bit addition will not accept anything other than 16-bit variables l Procedure calls and returns are explicit; calls store return values in variables that are then used by returns Pros l Lack of registers and static allocation can make this far more secure than a traditional register machine Cons l Limited dynamism due to static allocation, and much lower performance due to lack of registers Diagram: The next diagram shows a simple rendering of how a variable machine would execute add_this(add_this(2, 1), 3). All variables are statically allocated, and return locations are stored in return variables. This approach can be more secure than the C/C++ stack, but takes a lot more memory and is costly in performance due
CYBERSECURITY PROGRAMMING MODELS One of the key factors in how cybersecurity systems address their requirements is on how the system is designed and programmed. The Programming Machine Model is a model of computation and how a programmer’s instructions in a high-level language such as C, C++, or Java are translated into low-level instructions. Below are 4 different models and some of the trade-offs that influence one model choice over another.
FIGURE 2
MODEL 1: TRADITIONAL REGISTER MACHINE (E.G. C/C++; C CALLING CONVENTION)
Description l Variables can be statically allocated but are more often allocated on the call stack. l Separate allocation of memory using malloc(); programmer has to manage memory. l Procedure calls involve storing register state onto the stack and then restoring them on return to the calling procedure.
FIGURE 3
J U N E 2 019
35
REAL-LIFE
to the lack of data locality.
MODEL 3: STACK MACHINE
Description: l Dual-stack (data stack, return stack) l Separation of code addresses on the return stack, from the data stack. l All operations take values from the stack as arguments, and place return values onto the stack l Single value type per stack; some stack machines have a separate floating point stack l Code is extremely dense, as no operands are required for most operations Pros l Separation of return and data stacks improves security considerably l Code density allows the data and program logic to stay in the CPU cache l The security of a Stack Machine program can be verified algorithmically due to most operations occurring upon the stack with very little side effects, similar to functional programming l Extremely fast, with interpreted instructions executing in 3 clock cycles or less, due to most opcodes consuming operands from the stack rather than memory addresses or variables Cons l Most compilers and languages are optimized for register machines; different model of thinking than most l This is mitigated by ongoing research and development of stack-based targets and intermediate languages, e.g. WebAssembly. Diagram: The following diagram shows a Stack Machine that splits the Call Stack and the Data Stack. This offers more security than the C/C++ Stack does, as return addresses do not share the same stack as the program data.
MODEL 4: VECTOR MACHINE (GPUS)
Description l Executes the same operations on many pieces of data (vector), in parallel l Generally optimized for floating point numeric types, due to graphical focus l Highly optimized for tasks that are executed in sequence, with no deviation or branches l Very poor at branching code; code that requires a decision made that determines what code to execute next Pros l Extremely high throughput with repeatable and pipelined processes Cons l Very poor at branching logic, where decisions need to be made on every item; concurrent
36
J U N E 2019
FIGURE 4
FIGURE 5
programming is hard for most programmers
WHICH MODEL IS BEST? A combination of models works best; effectively leveraging each where they shine. The following scenarios show where each would work best: l User-Facing Applications and Server APIs: For leveraging other people’s code, whether internal or open source, the C/C++ Calling Convention and Stack offers the best amount of compatibility. The application would have restricted exposure to potential attacks, and so it is generally safe to use a more general purpose and lower security programming model. l For dynamic and secure packet processing with good performance, a Stack Machine is the best approach due to: 1. Code Density – Stack Machine instructions are very small and entire programs can fit in a CPU cache 2. Separation of Data and Call Stacks – the likelihood of a buffer overrun attack is much less due to this separation 3. Dynamic Management – Stack Machines are safer to execute dynamic rules and code on, due to stack separation above, as well as the capa-
bility to programmatically assess the potential inputs and outputs 4. Execution Speed and Latency – Instructions are small, simple, and very fast, allowing packet transforms in a minimal amount of clock cycles l For scenarios where security is paramount, and the high-cost in performance and lack of dynamic behavior is acceptable, the Variable Machine is best due to: 1. Static Allocation – Variables are always going to be known sizes and quantities 2. No Memory Addressing – No pointers that can be suborned 3. No Call or Data Stack – Calls and returns are to variables which are known ahead of time 4. For more complex security programs that are required nowadays where the machine has to execute complex tasks, a variable machine programming model has performance limitations if the static variables don’t map to registers and automatically spill to the heap; therefore, on balance a stack machine programmed correctly to effectively take advantage of the stack programming model will execute significantly faster without compromising security. ë
Swing
Local
-
Connect
Global
2019-20 AUSTRALIA AZERBAIJAN BAHRAIN BOTSWANA CANADA CHINA EGYPT FRANCE GERMANY GHANA
INDIA INDONESIA IRELAND ITALY KAZAKHSTAN KENYA MADAGASCAR MALAYSIA MAURITIUS NEW ZEALAND
40
PARTICIPATING COUNTRIES
NEPAL NIGERIA OMAN PAKISTAN PORTUGAL RWANDA RUSSIA SAUDI ARABIA SCOTLAND SINGAPORE
SRI LANKA SPAIN SOUTH AFRICA SWITZERLAND THAILAND TURKEY UAE UNITED KINGDOM US ZIMBABWE
60 QUALIFYING ROUNDS
4500 C-LEVEL EXECUTIVES
FOR MORE VISIT: www.gecopen.com CONTACT: ronak@gecmediagroup.com, vineet@gecmediagroup.com, bharat@gecmediagroup.com
PRODUCT SECTION
A10 NETWORKS’ THUNDER 14045 TPS
A10 Networks unveiled a new capacity enhancement to its Thunder 14045 TPS, which delivers industry-leading attack traffic mitigation capabilities. This capacity gain provides the highest performance available in the market with 500 Gbps of defense in one appliance. The smaller form factor reduces the number of devices required, while building scalable DDoS defenses that meet the challenge of emerging attacks. As service providers look to expand their service offerings, the Thunder TPS solution enables them to build profitable DDoS mitigation services that protect their own networks, as well as their subscribers. Distributed denial of service (DDoS) attacks are only going to increase over time and attackers have an ever-expanding opportunity to use new device types, particularly connected-home devices like home hubs, routers and IP cameras to mount even larger attacks. In fact, the most recent A10 Networks’ DDoS Weapons Intelligence report describes the significant potential for attackers to use an IoT-related protocol, the Constrained Application Protocol (CoAP),
38
J U N E 2019
deployed on IoT devices to marshal attacks. With their expansive attack surface and absolute need for 24x7 uptime, global communications providers, cloud and online gaming service providers require the highest levels of protection from DDoS attacks. Service providers can rely on A10 Networks for expanded L3-7 DDoS protection, high scalability and advanced automated defenses that intelligently leverage machine learning. “The proliferation of connected devices, and the increases in bandwidth and new application services enabled by advanced 5G networks mean that the size and intensity of DDoS attacks will increase exponentially. Customers require a modern approach to automated defenses with new technologies like machine learning and advanced threat intelligence to mitigate these attacks. The performance and automation available with Thunder TPS will help service providers deliver effective protection to their subscribers in this new and evolving attack landscape,” said Ahmed Abdelhalim, director of product management, A10 Networks.
With 500 Gbps mitigation capacity per Thunder TPS device, A10 Networks continues to drive innovation in the fast-growing DDoS market, leaving legacy suppliers behind. Thunder TPS solution is core to A10 Networks’ DDoS defense strategy delivering: l One-DDoS Protection – The industry’s only connected intelligence system that provides full-spectrum multi-vector DDoS defense with distributed detection and machine learning capabilities within targeted infrastructure, including Thunder TPS, ADC, CGN, and CFW. l Predictive, Automated Cyber Defense – Intelligent Automation, granular protection capabilities and zero-touch operation accelerate responses to ensure optimal, efficient protection. l Actionable DDoS Weapons Intelligence - Incorporates global intelligence from A10 Networks DDoS weapons research for improved security posture and real-time insights into emerging threats. l Industry-leading Performance – The highest performance in a small form factor enables fast detection and mitigation while lowering costs, reducing complexity, and increasing reliability in the field. ë
should be a fundamental right for every organisation!
ERICOM SOFTWARE IS A LEADER IN SECURING & CONNECTING THE DIGITAL WORKSPACE Ericom's offerings include innovative remote browser isolation, secure remote access & zero trust browsing solutions
#REVOLVESENTINELS PRESENTS
04 SEPTEMBER 2019
DUBAI, UNITED ARAB EMIRATES
11 SEPTEMBER 2019
KSA, RIYADH, KINGDOM OF SAUDI ARABIA
ARE YOUR CYBER SENTINELS ARMED? BROUGHT BY
OFFICIAL MEDIA PARTNER
FOR MORE VISIT: gecmediagroup.com CONTACT: arun@gecmediagroup.com, anushree@gecmediagroup.com, divsha@gecmediagroup.com, ronak@gecmediagroup.com, FOLLOW US:
www.youtube.com/channel/UCbR-mbzVb6RThghxHg_HxRg