Skip to main content

What the Hack - Q4 2021

Page 1

What the Hack? Secon Cyber Quarterly Newsletter

LEADERSHIP INTERVIEW: Koert Wilmink, Fugro

2021 THREAT TRENDS What lessons can we take into next year?

AZURE SENTINEL The ROI of Microsoft’s SIEM platform

GLOBAL CYBER RESILIENCE From a growing skills shortage to a widening cyber disparity between nations, how do we ensure the global population remains protected?

Q4 2021


CONTENTS 3 Foreword from our CEO 4 Industry Report The Total Economic Impact™ of Microsoft Azure Sentinel

6 Thought Leadership What can we learn from 2021’s global

cyber security events?

10 Secon Cyber Leadership Interviews Janakan Nadarajah, COO, Secon Cyber, in conversation with Koert Wilmink, Global IT Infrastructure and Security Manager, Fugro

14 Zscaler Infographic Anatomy of a ransomware attack

16 Insights How can we solve the cyber security skills crisis?

20 Insights Cyber security policy in developing

4

countries: Rowing in a unfamiliar world without a paddle

SECON CYBER2


Foreword from our CEO: Welcome to the October 2021 edition of ‘What the Hack?’ Since our last issue in July 2021, and living close to the centre of London, I am encouraged to see the return of commuters and putting the ‘rush’ back into rush hour. Some organisations have asked everybody to return full-time to the office while others are adopting a hybrid model. Enabling a ‘work-from-anywhere’ policy is a security challenge for any organisation as hackers take advantage of the remote workforce. Many of our clients are now faced with the challenge of how to give secure access to applications to their employees without compromising fast user experience, visibility, and protection from cyber threats. As we all prepare for 2022, our consultants have been busy helping customers address such concerns (successfully, may I add). In this edition of ‘What The Hack?’ we are yet again privileged to speak to leaders in our industry. We speak to Koert Wilmink, Global IT Infrastructure and Security Manager at the world’s leading geo-data specialist, Fugro, who addresses how a global organisation’s security remains consistent across different country and regional regulations. We also discuss the cyber security skills shortage and what we should do about it. Separately, we review the state of cyber security in the developing world, as well as a round-up of 2021’s biggest cyber attacks. I hope you enjoy this edition of ‘What the Hack?’ and on behalf of the Secon Cyber team, we hope that you have smooth run up to Christmas.

Robert Gupta Chief Executive Officer

WHAT THE HACK - Q4 2021

3


Industry Report

The Total Economic Impact™ of Microsoft Azure Sentinel Microsoft recently commissioned a Total Economic Impact™ report from Forrester to determine the ROI of its SIEM platform, Azure Sentinel. Amongst its findings, the report found that investment in Azure Sentinel’s cloud-native SIEM infrastructure lead to tangible cost savings, increased threat detection efficiency for SOC teams, improved time to deploy and configure, and a reduced MTTR. Key metrics from the report’s conclusions can be found on the opposite page. Secon Cyber has been working closely with Microsoft Azure Sentinel’s development team for the past three years. Through this close work, we’ve seen the benefits of this mature security solution for ourselves and know how well it integrates with both Microsoft products and other third party security solutions. We’re so confident in this capable, versatile solution that we’ve used Azure Sentinel and Microsoft’s expertise as the building blocks to help bring ConnectProtect®, our own centralised security platform, to market. If you’re interested in learning more about Forrester’s findings, click here to read the full report. Additionally, if you would like to talk to us about how Azure Sentinel or our ConnectProtect® platform could benefit your organisation, click below to book a call with our Chief Security Evangelist Andrew Gogarty.

Book a consultation 4

SECON CYBER


48%

Payback in

Less expensive than legacy SIEM solutions

< 6 MONTHS

201%

ROI with Azure Sentinel

79% Reduction in false positives over 3 years

56%

Reduction in SIEM management effort

WHAT THE HACK - Q4 2021

5


Thought Leadership

What can we learn from 2021’s global cyber security events? by Raymund Taylan, Senior Security Advisor

Regardless of the amount of investment and effort spent on cyber security, anyone can experience or be targeted by a data breach. 2020 is the year everyone will remember for the global disruption caused by COVID-19. The pandemic brought unforeseen changes in the cyber world that accelerated digital transformations and in just a few months, brought about digital advancements that once could have been considered impossible for many organisations. COVID-19-related threats have persisted into 2021, and cyber threats actors continue to adapt attack techniques to exploit unprepared organisations who are still struggling to adopt digitalisation, support their remote workforce, and enable their business to grow. Now that we’re nearly at the end of 2021, let’s look at high-profile cyber security attacks and critical vulnerabilities that surfaced in the news and reflect on how we can build an ecosystem that enables trust and resilience in an organisation.

Supply chain attacks and critical vulnerabilities As 2021 began, the SolarWinds supply-chain attack and Accellion vulnerabilities came along with it, making the first month of the new year difficult for organisations who were directly, and indirectly, impacted by these attacks. In December 2020, the SolarWinds attack was initially discovered. This breach affected more than 18,000 organisations who received an automatic software update for SolarWinds Orion system. This update allowed the attackers to add a backdoor called “Sunburst,” enabling attackers to spy on the organisations’ assets both in the cloud and on-premises. 6

ZERO-DAY VULNERABILITIES RANSOMWARE

Accellion Breach

Microsoft Excha Server Data Brea DEC 2020

JAN 2021

FEB 2021

MA 20

SolarWinds Breach SUPPLY CHAIN ATTACK RANSOMWARE

SECON CYBER


In the same month, Accellion, a secure file sharing company, started to discover and patch zero-day vulnerabilities on their File Transfer Appliance (FTA) software. Accellion’s FTA is a 20-year-old product that specialises in large file transfers. The December vulnerabilities found in FTA software allowed attackers to bypass the appliance’s built-in anomaly detector, navigate in FTA’s internal database and decrypt file names. The software and products targeted in these attacks are developed by top global tech brands and are widely used by organisations from different sectors and industries. This makes them perfect candidates for supply-chain attacks, which allow cyber criminals to target multiple organisations at once to extort money from victims. While other organisations were working to remediate exploited vulnerabilities in SolarWinds and Accellion, in January Microsoft was made aware of on-premises Microsoft Exchange Server critical vulnerabilities that were being exploited and targeting organisations who hadn’t migrated to Microsoft cloud-based services. Cyber threat actors utilised four zero-day vulnerabilities to comproange mise Microsoft Exchange Server’s Outlook Web Access (OWA). This en-

ach

AR 021

APR 2021

MAY 2021

JUN 2021

abled them to download all the emails, passwords and email addresses of users from Exchange’s stored memory of the victim. It has been reported that Microsoft Exchange Server versions 2010, 2013, 2016 and 2019 are the ones susceptible to cyber attacks and require immediate patching to address the exploit. An estimated 250,000 servers around the globe were impacted, including 7,000 servers in United Kingdom and around 30,000 organisations in the United States.

Ransomware takes all Cyber criminals have used more sophisticated technologies and techniques to increase their effectiveness and execute stealthier ransomware attacks. With the use of double extortion, cyber criminals make sure that all their efforts pay off by demanding a ransom in exchange for decrypting the data. To heighten the urgency of paying the ransom, cyber criminals threaten the victim by releasing their confidential data on underground or leak sites. In July of 2021, Kaseya Limited, an American software company, was targeted by cyber criminals through its virtual system administrator (VSA) software authentication bypass vulnerability. VSA is a remote monitoring management system that is widely used by their managed service provider (MSP) customers. Through

JUL 2021

AUG 2021

SEPT 2021

KASEYA Virtual System Administrator (VSA) SUPPLY CHAIN ATTACK

Accenture Ransomware Attack

RANSOMWARE

WHAT THE HACK - Q4 2021

7


this vulnerability, cyber criminals were able to distribute a malicious payload through hosts managed by the software and encrypt more than one million systems during the attack. A month after the Kaseya attack, Accenture, a global consulting firm, reported that they were hit by a ransomware attack and assured the public that the attack hadn’t make any impact on the company. In Accenture’s statement, they said, “Through our security controls and protocols, we identified irregular activity in one of our environments. We immediately contained the matter and isolated the affected servers. We fully restored our affected servers from back up. There was no impact on Accenture’s operations, or on our clients’ systems.” For the past eight months, we have seen cyber criminals improve their tactics to exfiltrate data and extort money from their victims. From SolarWinds’ attackers, a “Russian in origin” hacker group, to the cyber gangs behind Accellion’s attack, dubbed UNC2546 and UNC2582 who have links to FIN11 and CLOP, these are just some of the cyber criminal groups who are well organised and determined to achieve one goal – extorting money from their victims. In addition, we’ve also seen Hafnium, a Chinese

state-sponsored hacking group behind the Microsoft Exchange server attack, the REvil gang behind Kaseya ransomware attack, and LockBit ransomware gang, who were responsible for Accenture’s ransomware threat.

What can we do? By looking at the tactics being used by cyber gangs to infiltrate secured systems, the number one lesson we can learn is organisations must create an ecosystem that enables trust and resilience. Before you think about having advanced visibility and control, first focus on the current risks present that prevent delivering business outcomes and determine how and where critical data flows. Once all critical assets are identified, invest in a detection and response system instead of perfecting decentralised controls to protect your organisation. To learn more about the principles of building trust and resilience, our Security Advisors can run a Cyber Risk Assessment to help your senior management team navigate through emerging threats, maintain a high level of security, and adapt to the latest technology.

If you’re interested receiving your own Cyber Risk Assessment, click to book an initial consultation with one of our Security Advisors. Book consultation

8

SECON CYBER


Stay up to date with the latest security updates

Follow us on LinkedIn or visit our website for daily vulnerability announcements View our LinkedIn profile

View Security Announcement page


Secon Cyber Leadership Interviews

Janakan Nadarajah in conversation with Koert Wilmink, Global IT Infrastructure and Security Manager, Fugro JN: Tell us a bit about yourself and how you came into information technology and security? KW: I started my career in 1986, so it’s a long time ago. I started as a Unix engineer, I still remember it, AT&T System V Release 4. I also was introduced with TCP/IP. There was a lot of serial networking in those days. There was hardly any TCP/IP, so I was introduced in TCP/IP and networking. That’s how I started and grew in IT. I did infrastructure security for many years, but for the last 25 years, it’s been more senior leadership roles, especially global roles. And I’m now five months with Fugro, it’s a very exciting company and security there is very important. How I started with security in those days was with a book written by Clifford Stoll. I don’t know if you remember that from 1989. It was called The Cuckoo’s Egg. It was the first book I think there was about espionage and hacking and was about a German that hacked into American universities and military systems and sold that information to Russia, to the KGB. But in those days, hacking and security was already important. I moved from Unix into networking because there was 10

nobody there who knew anything about TCP/IP, so I was introducing security as well. I was in Silicon Valley with Netscape, and also with Internet Security Scanner, ISS in those days, and I think I was the first certified person in the Netherlands for the Check Point 1 Firewall, so that’s how I was introduced into security and a lot of the challenges are still the same. I had the chance also to move into the SAP space and do SAP implementation in Europe. I like infrastructure security. It’s just fantastic, right?

JN: You’re part of a large enterprise organisation with a global footprint. How do you make sure that security remains consistent across a global enterprise and how do you address the regional variations and requirements across different parts of the global estate? KW: In my 25 years of experience in global roles, there are many areas, right? You have local laws and regulations you have to adhere to, so in some cases data needs to stay local. You have data retention poli-

SECON CYBER


cies and in some countries it’s seven years or some places it’s about 10 years. In most cases about security compliance, I’ve got legal involved, especially when I’m doing large contracts, it’s important. That’s a legal issue and these vendors understands that they have to adhere to local law, and I’ll make sure that’s covered in the contracts as well. That’s what I’m doing mainly and it’s the experience of other vendors as well to help us out. That’s the main part and for the rest it’s setting policies, global policies as much as possible. My previous company did growth by acquisition, so we had many small companies. I consolidated all infrastructure globally to be centrally managed. So, it’s all about setting the right policies and standards and only deviating by exception if it’s required because of local laws or local regulations. In most cases it’s a regional approach. Actually, if you’re WHAT THE HACK - Q4 2021

regional, you’re using maybe private cloud, you’re using public cloud, but you always need some local presence, especially in some countries. JN: Secon Cyber has been in cyber security for over 22 years however as this industry grows, we probably have 10 new organisations joining the industry every day. As a consumer, how do you decide who is the right partner or make sure something is fit for your organisation? KW: It’s talking to a lot of vendors, right? It’s about technology as well, but there’s also cultural fit which is very important. And as an example, you at Secon Cyber, there’s already a long relationship so there’s also trust and you share what you know, your knowledge, your experience, which creates a partnership, which is important I think. When I’m looking what’s out there, I’m talking to a lot of vendors. I’ve got good archi-

tecture, and my team has got a lot of knowledge so they can challenge those vendors as well and understand if what’s they’re telling us makes sense. But I’m looking at partnerships, I think that’s important, and not looking at vendors, because then we understand how we can help each other. JN: Now looking to the future and one of the challenges that we see, and I’m sure you’ve also come across at this, is a scarcity of talent in this industry. Based on your experience, how do you prepare the next generation of cyber security professionals for where we’re heading? KW: I was referring to that book The Cuckoo’s Egg, maybe please read that book! But there’s also more books available nowadays. There are many journalists that wrote books about military agencies and what’s happening with Russia, North Korea, China; there’s a war going on on the Inter11


Maybe some of the systems aren’t so important if they get compromised, but it’s still the name of your company that’s out there on the news. That’s the highest impact, so that’s not what you want.

net. They try to get into companies, large companies, to get intellectual property or to know what’s going on. I tell them to read what’s really going on, and then you’ll get excited, and you’ll understand the importance, and then you can tell a story to your stakeholders as well. That’s what I’m doing. I’m telling them, you know what’s going on out there, it’s just a matter of time, right? So we have to protect ourselves. JN: On the same theme of what you’ve just covered, as a cyber security professional, do you see cyber security professionals as security or technology focused? KW: It’s a good question. I think it’s more security related, right? So they need to understand hacking patterns and how hackers are approaching companies. They need to understand that part and then the technology part, deep technology part, if you need to do something on a switch 12

or whatever, that’s technology. Security is totally different. You need to have that oversight and understand what’s going on and understand those hackers and what they’re doing. JN: Focusing on the future and looking ahead into 2022, what’s your guidance for security leaders? What should they focus on in 2022 to make sure they’re solving those challenges? What would your recommendations be? KW: There are many aspects of course for security, but I think it’s more and more important to train and educate our users or people. The amount of phishing attacks are increasing rapidly. Keep educating your people, training, doing tests. Ransomware attacks will increase as well so we have to increase our security posture, and use multifactor authentication everywhere. One of the biggest challenges is operational technology. I think in the future, there

are risks there and we should really be separating OT from IT. In many industries you still have industry devices or IoT devices running on very old hardware or old operating systems, so you need to do something about it, separated from the rest of your environment. Look at your investment, build out your SCADA, ICS, and IoT security expertise. Get the right expertise in. I just published six vacancies on LinkedIn so I’m adding resources, I’m adding knowledge, expertise - OT, cloud, we need to invest there. Also to start consulting with government bodies, a UFD industrial control system, and a cyber emergency response team; be proud to implement standards. Around that, it’s getting more and more important for the future. Maybe some of the systems aren’t so important if they get compromised, but it’s still the name of your company that’s out there on the news. That’s the highest impact, so that’s not what you want. SECON CYBER


Be all seeing and all knowing. ConnectProtect® is the cloud-based security platform developed by Secon Cyber to give you complete visibility and control.

Book your demo today

Examples of technologies ingested into ConnectProtect®:


Macro Document Google Drive

Anatomy of a ransomware attack Limited SSL inspection Can’t find hidden threats

Out-of-band Sandboxing Zero-day attacks bypass detection

Malware loader

ZIA

Cloud browser isolation Safely render email links

Next-gen threat prevention SSL inspection In-line sandbox Link scanning & reputation IPS

Identify domain controller

Lateral

Pass through Break free from legacy technology - prevention is possible. Data loss Protection movement Architecture and Cloud Firewall stops

File allowed

Break free from legacy technology prevention is possible

crown jewelshow from leaving Attackers have evolved, and traditional firewalls haven’t kept pace. Learn Zscaler’s fundamentally Next-gen the network new approach can stop ransomware cold. Our cloud-native architecture starts with complete visibility threat prevention Complex, into SSL traffic, eliminates your attack surface with a holistic Zero Trust strategy, and applies best-inTrue in-line protection inefficient class complimentary protections across the entire attack lifecycle. Break free from legacy pass-through with quarantine for segmentation Steal unknown threats policies approaches. Get true prevention with Zscaler. Admin nightmare credentials

Attackers have evolved, and traditional firewalls haven’t

ZPA Zero Trust Legacy Next-Generation Ransomware attack Zscaler kept pace. LearnCompromise how Zscaler’s fundamentally new Exchange Firewalls additional lifecycle Zero Trust approach can stop systems ransomware cold. Zscaler’s cloudEliminates the lateral movement Requires native architecture starts with complete visibility into SSL standalone NTA Steal data traffic, eliminates your attack surface with a holistic Zero Can’t detect advanced attacks Trust strategy, and applies best in class complimentary with ML Pass through Cloud native proxy With the 500% rise in SSLprotections across the entire attack liferansomware cycle. Break delivers based attacks, architecture & complex architecture Phishing Install you need full inspection of operations across a unified platform all encrypted traffic Get true Email free from legacy pass-through approaches. ransomware disjointed tools for comprehensive Gmail ransomware prevention with Zscaler. Requires standalone EDR & DLP No support for detection & response or data Limited SSL loss protection inspection Can’t find hidden threats

Macro Document Google Drive

Threaten to release data & demand payment Malware loader

ZIA

prevention

If you’re interested in learning more about how youThreat can & Data Loss Prevention Cloud browser stop ransomware cold, click below to watch Zscaler’s Completeisolation content inspection Safely render Advance webinar or click here to book a Zscaler demoZIAwith emailCloud links Firewall Secon Cyber today. Out-of-band Sandboxing Zero-day attacks bypass detection

Pass through Architecture Watch File allowed

the webinar

Identify domain controller

Lateral movement

Stopping Ransomware Cold Complex, inefficient ©2020 Zscaler, Inc. All rights reserved. Zscaler™is either (i) a registered trademark or service mark or (ii) a trademark or service mark of segmentation Zscaler, Inc. in the United States and/or other countries. Any other trademarks are the properties of their respective owners. Steal policies Admin nightmare credentials

Data loss Protection and Cloud Firewall stops crown jewels from leaving the network

Next-gen threat prevention SSL inspection In-line sandbox Link scanning & reputation IPS

Next-gen threat prevention True in-line protection with quarantine for unknown threats


Legacy Next-Generation Firewalls

Ransomware attack lifecycle

Pass through architecture & complex operations across disjointed tools

Limited SSL inspection Can’t find hidden threats

Phishing Email Gmail Macro Document Google Drive Malware loader

Out-of-band Sandboxing Zero-day attacks bypass detection

Lateral movement

Complex, inefficient segmentation policies Admin nightmare

Steal credentials

Requires standalone NTA Can’t detect advanced attacks with ML

Next-gen threat prevention SSL inspection In-line sandbox Link scanning & reputation IPS

Next-gen threat prevention True in-line protection with quarantine for unknown threats

ZPA Zero Trust Eliminates the lateral movement

Steal data

Install ransomware

the webinar

Cloud browser isolation Safely render email links

ZIA

Data loss Protection and Cloud Firewall stops crown jewels from leaving the network

Compromise additional systems

WHAT THE HACK - Q4 2021 Watch

Cloud native proxy architecture delivers a unified platform for comprehensive ransomware prevention

Identify domain controller

Pass through Architecture File allowed

Requires standalone EDR & DLP No support for detection & response or data loss protection

Zscaler Zero Trust Exchange

With the 500% rise in SSLbased ransomware attacks, you need full inspection of all encrypted traffic

Threaten to release data & demand payment

ZIA Threat & Data Loss Prevention Complete content inspection Advance Cloud Firewall

15


Insights

How can we solve the cyber security skills crisis? by Taylor Roth, Marketing Communications Executive It’s no secret that there’s a huge shortfall of talent in the cyber security industry. The number of people entering the industry is not at all proportionate to the volume of threats that continue to target users across the globe. According to a report released by the UK government’s Department for Digital, Culture, Media & Sport in March of this year, in order to keep up with demand, the UK should be attracting over 17,000 new people annually to cyber security jobs. Unfortunately, the current figure only stands at 7,500. As threats grow and evolve, so too does the technology developed to combat them. Since, technology is constantly changing to keep up with the pace and sophistication of cyber criminals’ tactics, an individual’s previous education, certification, and training may not align to current threat trends. However, it takes time for security professionals to develop knowledge of the latest tech and gain new, specialised skills. With this understanding, it’s not surprising to learn that 50% of all businesses in the UK have a basic cyber security skills gap. This means these businesses don’t have the internal skills necessary to carry out the tasks outlined in Cyber Essentials.

What are the consequences of this gap? Without a steady stream of new people entering cyber roles, organisations will struggle to achieve cyber security maturity. Currently, 45% of all businesses have just one employee tasked with managing all their cyber security. In addition, nearly 9 in 10 of all staff carrying out cyber functions in the private sector have taken them on from an existing, non-cyber related role. Without a robust team of experienced security professionals, UK businesses will be targets for cyber criminals and struggle to keep up with 16

the digital world, resulting a loss of money, sensitive data, and their brand’s reputation. In fact, 71% of employers already believe that the talent gap has caused direct, measurable damage to their business and growth plans. The shortage has also made it harder for smaller organisations to compete. In a review of the skills shortage across the EU, it was found that larger, wealthier organisations snatched up much of the talent in the market leaving “smaller companies and non-profit organisations struggling to attract the knowledge and skills that would allow them to run their business safely.” In our current digital landscape, we can’t allow smaller business to fall behind simply because there aren’t enough security experts available to for them to hire.

So, what can we do to close it? There are multiple approaches that address the problem from different angles including exposure, education, training, and recruiting. All these perspectives are important for driving more people to the industry, ensuring they have the right skills for the job, and sustaining a pool of qualified cyber security professionals in the future.

1. Exposure Getting kids interested and excited about cyber security is the first step to cultivating a pool of future talent. A number of organisations in the UK run programmes to attract young people to cyber security activities. One such organisation, Cyber Security Challenge UK, was founded in 2010 and aims to find and nurture cyber security talent by running events, competitions, and games across the country. SECON CYBER


Its Executive Chair Dr Robert Nowill, who previously served as a cyber director at BT and GCHQ, says Cyber Security Challenge UK’s mission is more critical now than it was in the beginning. He commented, “When we were created, it was all about working with the skills agenda of the government at the time to get more people in [the cyber security industry]. We knew there was a skills shortage then, and now I could say exactly the same thing.” Through Cyber Security Challenge UK’s roster of events, such as CyberCenturion, a teambased competition for 12-18-year-olds, and Cyberland, a series of online games to introduce kids to key concepts in cyber security, the organisation hopes to inspire the next generation of cyber professionals. “We can’t talk to every child or every perspective cyber security professional in the UK individually,” said Dr Nowill, “but it’s just laying out a carpet of things to make them interested in the hope they come back to us and have got enthused.” Cyber Security Challenge UK also hosts university networking events, career fairs, organisational training days, and more to help nurture talent and attract new people to the industry. These kind of efforts are important because in order to fill the skills gap, we need to make sure people are aware of the career possibilities available to them, even if they come from outside the industry or non-traditional educational backgrounds or disciplines. Initiatives such as these will help feed the WHAT THE HACK - Q4 2021

pipeline of talent to ensure there are more people entering both cyber security education programmes and the industry later down the line.

2. Education Education transformation will not happen overnight and it’s going to take cyber security champions inside institutions to get the ball rolling initially. “I think at school, it depends very much on whether you’ve got a keen teacher. Not all schools have someone that keen because quite simply there aren’t enough hours in the day,” says Dr Nowill. However, he says once there’s a champion inside an organisation, more cyber skills start being added to the syllabus, even at primary level. “Anything is better than nothing…it’s moved on from just ‘Can you use Word?’ to ‘Do you have an appreciation of basic coding?’” To help accelerate this process and bring cyber security into more curricula, the NCSC supplies a set of resources for schools to help provide training and guidance to governors, trustees, and staff. In addition, their programme CyberFirst provides bursaries, free courses and competitions for 11-17-year-olds. As part of this, the NSCS continues to develop their CyberFirst Schools/Colleges scheme, which aims to encourage “young people to engage with computer science and the application of cyber security in every day technology.” The scheme allows the NCSC to accredit schools that have adopted a structured approach to cyber securi17


ty education. In terms of higher education, universities need to ensure their curricula keep with the pace and demands of the cyber security industry. Employers have stated they feel current graduates don’t have the right practical skills or fully understand the fundamentals of a career in information security and that cyber security education programmes don’t meet the needs of their organisations. “We not only have a shortage of the highly technically skilled people required to operate and support systems already deployed,” says Franklin K. Reeder and Katrina Timlin in their research on the skills crisis, “but an even more desperate shortage of people who can design secure systems, write safe computer code, and create the ever more sophisticated tools needed to prevent, detect, mitigate and reconstitute from damage due to system failures and malicious attacks.” However, it should also be acknowledged that although courses should be kept updated, not every programme can fully encompass every specialty area and specialised skill employers may be looking for. It’s been suggested that cyber security courses should be designed according to career objectives, whether that be academia, industry, or government. Those wishing to enter the industry should be taught more technical, hands-on skills to better prepare them for their future career. Employers should also build relationships with local colleges and universities to share their critical workforce needs and what they’re looking for in potential employees. By working together, employers and educators can ensure courses align with the industry’s needs.

3. Training One of the most important elements for developing a pool of cyber security talent that fits an organisation’s needs is to complete ongoing training and development courses. “Recruiting well qualified and accredited cyber security professionals is very expensive,” says Dr Nowill, “the best thing to do is bring in talent that’s emerging and train them yourself. “It’s easy to say and hard to do, but if the companies need somebody to do their IT security properly, unless they want to outsource of course, they need to get somebody in. Also, the 18

investment in emerging talent is a good investment for the long term since those people are a bit more sticky. Cyber security professionals tend to move around a lot, but if you’re growing and you’ve been trained by someone, you tend to be a bit more sticky and stay a few more years.” Organisations should also consider establishing internal, retraining programmes to pull talent from other areas of their business to fill their shortages. This would allow for a more consistent stream of talent and open new career paths for those who may not have considered it previously. And of course, training should not only be limited to just an organisation’s cyber team if it hopes to achieve security maturity. However, it always bears repeating since only 10% of all businesses have provided cyber security training to wider staff in the last 12 months.

4. Recruiting Although there’s not an unlimited pool of candidates recruiters can draw from, they can’t expect to find one person to solve all their problems. One recruitment agent said that they considered over 30% of new cyber job postings “unfillable.” This is because employers tend to overestimate what one person can do or expect them to have in-depth knowledge across the entire cyber security spectrum. This leads to unrealistic job adverts that request every cyber qualification imaginable or try to recruit for two or three jobs in one. Hiring managers need to ensure they’re familiar with the various qualifications or career pathways candidates may possess and how these are relevant for different roles. They should also work to understand exactly how much capacity each member of their cyber team has and should not expect one person to have all the skills they may be looking for.

What else should be considered? Staffing issues are usually exacerbated by the fact boards and IT teams may not have an appreciation for cyber or recognise how critical it is to the future of their organisations. This can lead to poor cyber staff retention, a lack of investment in cyber, and minimal training opportunities. Once organisations accept that cyber SECON CYBER


is a business risk, not just an IT problem, more focus can be put on training, recruiting, and working to discover new talent. If an organisation is facing a tough skills gap and doesn’t have the ability to train its current staff or the budget to recruit additional skilled security engineers, outsourcing is a good option. Outsourcing can expand cyber capacity and help fill in specialised skills that may be lacking in one’s internal team. This is especially helpful for incident response, which can be challenging for organisations with minimal cyber resources. In fact, for the 38% of organisations that currently outsource some aspect of their cyber function, 82% get their security partner to handle incident response and recovery. However, if the industry can’t attract more would-be cyber security professionals, soon managed security service providers will begin struggling to find qualified employees as well.

• By exposing students to cyber-related activities from a young age, the industry can get kids more interested in careers in cyber • There are multiple pathways into cyber security. If someone is interested in a career in cyber, they should look at the career options available to them, even if they have a non-technical background. • Education will take time to evolve, but organisations can work with educators and the NCSC to shape new curricula and champion efforts like CyberFirst Schools. • Internal training should be adopted to allow people develop their skills and create a pipeline of talent for organisations. Re-training programmes can also help to bring over trusted talent from other areas of an organisation. • More realistic hiring standards need to be adopted amongst hiring managers. One person will not be able to solve all your cyber security requirements and management need to understand what roles an employee can realistically perform. • Continue to educate boards about the risks of neglecting cyber security and why it’s not just an IT problem, it’s a major business risk. This will allow for more investment in cyber security talent and training programmes.

In conclusion, what recommendations can we take away from all this? • The need for cyber security professionals is growing at a much higher rate than those entering it. We need to attack the problem from multiple angles to make up the shortfall. WHAT THE HACK - Q4 2021

• Outsourcing may be a route to consider for organisations that cannot hire more cyber security staff inhouse, especially those who lack incident response capabilities. Reach out to a qualified partner like Secon Cyber who has an in-house SOC and experienced team of security engineers to help keep your organisation secure. 19


Insights

Cyber security policy in developing countries: Rowing in an unfamiliar world without a paddle by Mars Cacacho, Senior Security Engineer The advent of borderless information has struggling to comprehend. brought endless opportunities to all nations Coming from a developing country in Southwith tech playing a vital role in the core of eco- east Asia, one cannot set aside envy whenever nomic stability. Citizens bear witness to how one thinks of even a minuscule of comparison governments can be at the mercy of advance- to what developed nations have to offer. It does ment, especially so when it comes to curbing not take a genius to learn in kindergarten the the pandemic. very names of developed countries, their capIn this era where data and information are ital cities, and the plethora of adjectives that already more valuable than gold and oil, gain- come with them. The facts just became more ing the upper hand in acquiring, and eventu- and more obvious by the day: developing counally monopolising, information is an unspoken, tries are indeed a couple of decades behind round-the-clock Olympics. first worlds. This goes beyond employment The world is evolving at an insane pace. rate, GDP, healthcare, and higher education, to We’re now used to seeing first world countries’ name a few. home garage-grown startups become unicorns Developed countries have mustered roand help shape the bust cyber security world, generation afcapabilities. Since ter generation. Along they’re viewed as “Nurturing knowledge, with this progress prominent models of upskilling, and building comes the predicacyber security stratments of technology, egies, policies, and competencies could help and especially setech advancement, close the cyber security gap curity. Critical bugs, developing nations unsanitised codes, try to mimic Europebetween developed and exploited vulnerabilian countries and the developing countries” ties, denial of service, United States. Relucbotnet attacks, cyber tant leaders hastily espionage, advanced jump to legislation, persistent threats, and data breaches continue initiate large-scale propositions, create CERTs, to target organisations large and small. These and find ways to generate resources for national attacks can ground planes, cripple industrial cyber security infrastructures. They do so withplants, and even disrupt nuclear plants’ centri- out reviewing their own ICT roadmaps or first fuges. improving the very foundations of their state of Whilst developed countries are already tak- technology: internet services, communications, ing strides towards sustaining multifaceted cy- peace and order, costs of doing businesses, reber security approaches, developing countries sources, and investment security. are navigating their own labyrinths of internal With the promise of comfort in computing, issues in lobbying policies for digital infrastruc- government institutions begin digitising servictures. Meanwhile, underdeveloped nations are es without considering the risks. Unnecessary at the foot of digital transformation and are still automation has created a lucrative avenue – a 20

SECON CYBER


new breeding ground for corruption. And even if frauds, scams, and rampant online malpractices, aside from the regular cyber crimes, appear, unfortunately there are no concrete laws in place to penalise offenders. If there are, they usually fall under the discretion of the jurisdiction. But unlike other domestic crimes, cyber crimes transcend physical and political boundaries. Although a cyber criminal may be in your jurisdiction, their victims could be halfway around the world. Even if they get caught in the act, they can still get away with it since authorities do not have the competency to do digital forensics and provide irrefutable evidence to pin them down. With this, international cooperation is paramount. Recent examples include the Esthost takedown in Estonia and the Emotet takedown. The Bangladesh Heist, which cost a local bank $81M (from an attempted $951M), routed a substantial chunk to a bank in the Philippines. Investigations were haywire because of relaxed anti-money laundering and dysfunctional cyber crime laws, the perfect ingredients for big game hunting. Cameroon in Africa is among the countries greatly impacted by cyber crime. A few years ago, there were talks to launch multiple cyber security skills programmes to help combat this problem. Policy makers, however, feared that after finishing the training, the trainees would use the skills gained to commit cyber crime. Its neighbour’s ‘Nigerian Prince’ has become the standard of phishing. Though unsophisticated, the scheme has already sucked billions from gullible individuals and trusting pockets around the globe. Nigerian fraud rings have been intercepted in multiple different countries, but indictment depends on the nations where they’re apprehended. It is therefore possible that we have large cyber crime dens in developing countries. We have seen fraud call centres in India. The operatives working in Joker’s Stash or new silk roads on the dark web may be established anywhere, away from the prying eyes of those who know all too well what they’re up to. If the citizenry cannot trust its legal system to protect them, other socioeconomic factors are drastically affected. Sustainable development highly depends on an incorruptible and stable justice system, and able law enforcement. WHAT THE HACK - Q4 2021

Whilst developed nations open-mindedly adhere to bug bounty programs to assist them in protecting their national infrastructure and government systems, developing countries abhor responsible vulnerability disclosures and go after security researchers as criminals. On a different note, perhaps the only amusing advantage of poor countries in a tech world would be its ability to fend off DDoS attacks, cut off unauthorised remote-control access, and obstruct lateral attacks due to internet instability. Also, industrial critical infrastructures are obsolete and were created before cyber security became a thing. Though some may be vulnerable due to hardcoded credentials, most may still be running on relatively old industrial

21


systems. No SCADA systems to be bothered with, no imminent Stuxnet, Duqu, Flame, and Gauss-like weaponised malware attacks to be haunted with. With this, a technological handicap can be quite rewarding. Even if there are myriads of attack vectors coming from adversaries both foreign and domestic, most in the public and government sectors think they already have sufficient defence capabilities and breach mitigations in place. This is not the case. They downplay malware outbreaks in their devices filled with cracked software, torrent downloads, apps which came from malvertisements, and have paid excessive amounts for software that they do not religiously update. Also, in the midst of COVID-19 when employees were transitioned to a work from home setup, most didn’t have the proper protection configuration in place. In addition, the lack of awareness on basic cyber safety sits like a time bomb, which just waits for the proper website, clickbait, or email attachment to detonate. BYOD has warped into ‘Bring Your Own Disaster – Home Edition.’ If we stand back and take a broader look at nations’ cyber security capabilities, one common denominator amongst first world countries would be their wealth in human resources, and it all starts with proper education and training. Nurturing knowledge, upskilling, and building competencies could help close the cyber security gap between developed and developing countries. In completing studies, undergraduates are schooled with engineering, scientific, industrial, and technological concepts, and best practices. Scholars on the other hand are just re-echoing what they learned back then. They may have seemingly forgotten that one size does not fit all. Demographically and geographically, we are all different, and we also do have different resources and traditions. But one thing is for sure, technology is so agile and fickle minded that textbooks alone cannot cope. It may be cultural in nature, but most developing countries have trouble interacting with other sectors. Let the lessons of the past remind us of Government-Academe-Industry-Linkages (GAIL), which was the first step towards a

22

holistic cyber security capability approach. We may be lacking in resources, but if we concentrate strengths from each sector, it would be a great start. This could include: No nonsense academic curricula to produce industry ready graduates Proper government allocation of budget for infrastructure, policies, and roadmaps Cyber security organisations lending human resources and corporate machinery to aid and provide consultancy to the government to make sure they are doing things as they should Stakeholders should collectively address the increasing cyber security risks of interconnectivity in the developing world. These are perils that not only impact the most vulnerable populations, but have economic and political repercussions to developed nations as well. Interestingly, although neither noted as a nation for tech or cyber security, Malaysia quietly made it to the top of worldwide cyber security index, sitting next to the EU and US. Leveraging policy capacity with a broad network of international intel, their first cyber security policy dates back 15 years ago and they have constantly evolved ever since. This perfect example shows us that we do not need to drain our banks to achieve cyber security maturity. The operative word here is manpower: the concerted efforts of different sectors in society. It was not done overnight, it took a while, but consistency, clear vision, and political will were all key. As third world countries gather the right armaments to secure their domains, despite the “silent,” constant cyber war amongst governments, developing nations are left with one alarming stance: will they be ready when worse comes to worst and state sponsored attacks point toward them? They may have been breached already, they just haven’t noticed it yet.

SECON CYBER


www.seconcyber.com

Always on hand, supporting your vision. Organisations need uninterrupted operations to achieve their goals. That’s why we work at a deeper level of knowledge and understanding to put more than just security in place.

Managed Detection & Response - Managed Security Services - Server Patching as a Service - Security Advisory


Contact us: www.seconcyber.com Email: hello@seconcyber.com Phone: +44(0)207 657 0707


Turn static files into dynamic content formats.

Create a flipbook