Friday, August 18, 2023

What The US Can Learn From Dubai For Cyber Proactiveness



When we hear about Cyber threats and attacks happening, we often think about where the breach has actually occurred at.  Most often, we think of the United States, Europe being impacted, and the culprit being from China, North Korea, or Russia.  But there is one part of the world which we often don’t think about, and that is the Middle East.  I have seen Saudi Arabia come out in the news a little bit more often, but there is one particular region that made headlines today.

That is Dubai, home of the previous World Cup.  This city (which is quite a beautiful one also), has actually seen its fair share of Cyber-attacks.  According to IBMs report, entitled:  “The Cost Of A Data Breach Study” claims that Dubai has lost well over $32 Million because of security breaches from 20180-2022.  This is illustrated in the diagram below:


(SOURCE:  https://www.darkreading.com/dr-global/overview-dubais-first-and-second-cybersecurity-strategy)

The IBM Report can actually be downloaded at this link:

http://cyberresources.solutions/blogs/IBM_Report.pdf

One of the primary reasons cited why Dubai is starting to become a target in the crosshairs of the Cyberattacker is that it is leading the way in digital innovation in that part of the Gulf region.  In fact, it can be considered to be one of the most modern “Smart Cities” in the world.  At the heart of this is of course both the IIoT and the IoT. 

In fact, Dubai started its full force venture into Cybersecurity, when it launched what it known as the “Dubai Electronic Security Centre”, or “DESC” for short. From here, this then became the launching pad for Dubai to launch its first Cybersecurity strategy, which involved the entire city, not just businesses or individuals.  More details on that can be seen at this link here:

http://cyberresources.solutions/blogs/Dubai_Strategy.pdf

Just recently, the Crown Prince of Dubai, Sheikh Hamdan bin Mohammed bin Rashid Al Maktoum, launched the next part of their Cybersecurity strategy on July 12th, 2023.  The first part of it can be seen in the above-mentioned report.  Here are the major components of this new phase:

1)     Creating a Cybersecurity Culture:

The goal is to give every citizen and business of Dubai access to any and all access to Cyber resources as they are needed.  It is hoped that this will lead to a proactive Cybersecurity society.

2)     Being the Incubator For Innovation:

The intent here is to expand upon the security center as just described, and update with the latest technologies so that Cybersecurity professionals can use the latest tools in figuring out ways to combat the latest threats.

3)     A Strong Cyber City:

Here, it is intended that Dubai will further enhance its reputation as being one of the safest Smart Cities in the world.

4)     A Place For Information Sharing:

Of the chief objectives of the Sheik of Dubai is to allow for the free flow of information and data between the government, businesses, and the people (and even vice versa).  The intent here is that by sharing these kinds of assets, Dubai will become much more proactive in fending off any kinds of Cyber threats and attack vectors.  Also, people will be highly encouraged to report any suspicious behavior, on an anonymous basis.

My Thoughts On This:

The city of Dubai has taken other steps as well to be the Gulf’s center for Cybersecurity.  For example:

*It is now sponsoring the various “Hack The Box” competitions, making a return after an 8-year halt.

*It is hosting other Cyber-related events as well, bringing in people from all over the world.

*The Sheik of Dubai just launched what is known as the “Dubai Cyber Index” to reflect the city’s level of resilience and readiness in the case of a large-scale attack.  More information about this can be seen at the link below:

https://gulfbusiness.com/sheikh-hamdan-launches-dubai-cyber-index-to-enhance-cybersecurity-among-government-entities/

In my opinion, I think it is great how the City of Dubai is coming together to bring its people, businesses, and even culture into a proactive mindset.  It is truly amazing what people can do when they all come together for a common cause.  Here in the United States, we can learn so much from this.


Saturday, August 12, 2023

Why OT Is A Huge Cyber Risk For The Maritime Industry

 


One term that you many have heard on and off in the world of Cyber is that of “Operational Technology”, also known simply as “OT” for short.  It has been used in conjunction with “IIoT”, which stands for the “Industrial Internet of Things”.  So, you may be wondering what exactly is OT?  Well, a technical definition of it as follows:

“It is the practice of using hardware and software to control industrial equipment, and it primarily interacts with the physical world.”

(SOURCE:  https://www.redhat.com/en/topics/edge/what-is-ot)

So as you can see, it pretty much deals with anything technological related to equipment that is involved in heavy industrial usage.  Some examples of this would include car assembly lines, logistics/supply chains, trucking, aviation, etc.  But the problem here is that these pieces of equipment are actually pretty archaic in nature.  Thus, they have become a prime target for the Cyberattacker because modern day software patches and upgrades simply will not work for them.

In fact, this is the problem that Critical Infrastructure is having.  Much of the technology that underlays our water supplies, oil/natura gas pipelines, and even the national power grid is also outdated.  And these too have become prime targets.  Probably one of the best examples of this is the Colonial Gas Pipeline attack, where the CEO ended  up making a payment of $4.4 Million.

This outdated OT is also starting to impact another industry, in which the entire world is dependent upon.  These are the cargo vessels that transport goods and supplies to all places.  This is technically known as the maritime industry.

So far in the news, we have not heard too much about Cyber attacks to these kinds of vessels.  But given their increased dependence upon them, they too will become a prized target.  Also note that these ships also use a wide myriad of electronic components, primarily to help them with navigation.  Some  of these include the following:

*Radar

*Electronic Charts

*Engine Monitoring

*The GPS System

One of the other biggest weaknesses facing the maritime industry is that they often still use weak and  easy to guess passwords.  Don’t forget to also take into consideration that these vessels carry hundreds of containers, and they are inherent risks with them also, especially when it comes to physical based security.

So, what are some of the Cyber risks that the maritime industry actually faces? Here is a sampling of them:

1)     High economic costs:

Because the OT that is used is so old, simply upgrading them to newer standards will not happen.  The primary reason for this is that many of these components are simply not available anymore.  IF anything, they have to be custom-made, which can take a very long time to achieve.  The only other option is to totally gut the old OT, and put in a new one.  But this would be too cost prohibitive for the shipping lines.

2)     Using the Cloud:

Although the vessels OT systems might be outdated, as mentioned, they make use of sophisticated electronics to keep them on their course.  These devices too can be prone to a Cyberattack.  But the good news here is that these kinds of devices should be upgraded, given that they are still new.

3)     Password Hacking:

Also as described, cargo vessels still use very weak passwords.  Advocates are claiming that it is time for them now to upgrade their process in this regard, and start using a password manager of sorts.  It would be even better if some sort of Privileged Access Manager could be put in place, and the Cloud would be a great option for this to happen.

4)     Third party risk:

Maritime transportation is of course heavily dependent upon third party suppliers  in order to deliver the cargo.  So, there is a lot of risk here as well.  The need for third party vetting now becomes crucial, but this is far easier said than done.  When you consider literally the hundreds of people involved with getting a cargo ship ready this process would take a long time to complete.  Also,  it should not be up to the cargo lines to do this.  It should be the countries from where they originate  that should take the ultimate responsibility for this happening.

My Thoughts On This:

IMHO, it may be time for these cargo vessels to upgrade their OT systems now finally.  But again, this will be a very expensive and time-consuming process.  But in the long run, these benefits will outweigh the costs of having to keep repairing and upgrading systems.  Also, many Cyber pundits feel that the maritime industry should also adopt the kinds of standards that Corporate America must adopt.

Some of these include:

*Intrusion Detection Systems

*Network Segmentation

*Zero Trust Framework Implementation

*Deploying EDR and XDR systems

*The use of AI and SIEM to keep track of the latest warnings and  alerts

More Information about the kinds of controls that should be implemented can be seen here at this link:

https://www.darkreading.com/ics-ot/4-big-mistakes-to-avoid-in-ot-incident-response

The concern over the security of the maritime industry both from a physical and Cyber one is nothing new.  As far as my remember, it goes back even as far as  after the 9/11 events took place.  But rather than waiting another twenty years to do something, the time to act is now.

Friday, August 11, 2023

Need To Get Cyber Insurance? Here Is A 9 Point Checklist

 


There is no doubt that the world of Cybersecurity is a highly complex, not only navigate through, but to fend off the Cyberattackers from attacking your business.  But now, there is another looming headache on the horizon, and it is a huge one.  This has to do with Cybersecurity Insurance.  Essentially, this is where you have a financial blanket if you are impacted by a security breach, much like if you have a car accident, or have a major medical mishap.

The thinking here is that if you are hit with a security breach, all you have to do is file a claim, and voila, you get your payout days later.  But unfortunately, the world is not working like that at all today.  Insurance carriers have really clamped down on making payments, and worst yet, they are  even being pickier as to who they will accept as a policy holder.

A good example  of this is n if a company pays the ransom if they become a victim of a Ransomware attacks.  Given the frequency by how this threat variant is occurring, many carriers are now fully denying a payout for these types of claims that are made.  Just consider some of these other stats:

*27% of all companies that filed a claim did not receive a full payout (in fact, some were even denied all together).

(SOURCE:  https://www.nedaglobal.com/ned-insights/publications/willis-towers-watson-cyber-claims-analysis-report/)

*The average cost of a data breach is now pegged at over $9 million for just one incident, and globally it has reached a staggering $4,25 million (on a per incident basis).

(SOURCE:  https://www.verizon.com/business/resources/reports/dbir/)

Here are some other examples of what an insurance carrier can do to you to deny coverage, or just make a partial payout:

*100% deny coverage if you do not have the required kinds and types of controls in place.

*If you are selected to be a policy holder, you premiums could be tied to how they view your security posture.  For example, if it is mediocre to average, you will then pay a might higher premium versus a business who has a much stronger posture.

*Impose other kinds of limitations on both coverage and payouts until you security posture has reached a level that is deemed to be acceptable.

So given that the screws are really starting to tighten up now, what can a company do to not only ensure that they can a reasonably good policy, but also be somewhat guaranteed of getting a payout?  Here are some quick tips that you can follow:

*Implement MFA, but to the point where you are no longer using passwords.  Anything but that.

*Segment out your IT and Network Infrastructures, in this regard, your best friend will be the Zero Trust Framework.

*Make sure that you are backing up data on a regular basis, and make sure also that you have multiple copies of them (both on site and offsite).  In this regard, using the Cloud, such as Azure, will be your best bet.

*Have an effective PAM strategy in place.

*Deliver security awareness training programs to your employees, on a regular basis (at least once a quarter is considered to be the bare minimum).

*Make sure you deploy anti virus and anti malware software on all of your endpoints.

*To whatever degree you can, try to have some sort of Security Operations Center in place.  Obviously, this is probably not affordable by many SMBs, but I think you can actually create a virtual one for a very affordable price by using Azure.

*Always make use of a SIEM.  This will show that you are being proactive by monitoring all of the real alerts and warnings that are coming in.  But even importantly, have an effective triaging strategy in place also.

*If you do make use of Azure, make sure that the Azure Active Directory (AAD) that you configure is airtight as possible, in order to avoid any data leakages.  All the controls that you will need for this reside within the Azure Portal.

My Thoughts On This:

Cybersecurity Insurance has always been a gray and murky area to deal with.  It is by no means an easy process to accomplish; it is nothing like shopping for car insurance, or even medical insurance for that matter.  Simply getting a policy is not enough, there are many other add ons and riders that you will need to explore in order to get the exact coverage that you need.  

But honestly, the best way to get started in the application process is to ask for a risk assessment questionnaire from the insurance provider with whom you are trying to get coverage with.  This is a few pages, and simply asks if you have the needed controls in place.  If you do, you can simply check off “Yes”, and if not, you will have some work to do before you can submit it back.

However, it is very important to remember that you cannot attest to the questionnaire your self.  It has to be validated by another person as well, such as your compliance officer or even a vCISO.  This also comes down to another point.  You shouldn’t maintain a strong security posture just to get Cybersecurity Insurance, you should have one to begin with.

Once you have submitted the questionnaire, the insurance company may even come out to an audit before they award a policy, and heck, there is nothing from stopping in doing that as well even after you become a policy holder.  It probably is in your best interest to get some sort of Cybersecurity Insurance now, if you don’t have one.

The reason for this is quite simple:  The cost of data breaches will soon far exceed the costs of what the insurance industry can offer.  For more information on this, click on the link below:

https://assets.lloyds.com/media/35926dc8-c885-497b-aed8-6d2f87c1415d/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdf


Thursday, August 10, 2023

The Real World Perspective Of Why SMB Cybersecurity Is So Important

 


In the world today, Cybersecurity has become a household term.  Hearing and talking about it is one thing, but actually taking the needed, proactive steps to secure your business is entirely a different matter.  Many business owners have their reasons for not taking a stronger stance, but one of the biggest reasons is that of cost. 

Many SMB owners cite the cost is too staggering.  While this may have been true some time ago, now the bottom line is that it is very affordable.  There are many Cyber vendors out there who now offer services just dedicated to serving the SMB market, and giving them enterprise class service, in a way that a Fortune 500 company would. 

EB Solution, based in Canada is one of those companies that offers such affordable services.  Although they are in a different country, their reach is quite global.  In this podcast, we have the honor and privilege of interviewing Johny Bogard, the CEO of this company.  Listen in to see how you can take advantage of not only their expertise, but also their very affordable SMB services.

You can download the podcast at this link:

https://www.podbean.com/site/EpisodeDownload/PB1476DC6FJQ2Z

Tuesday, August 8, 2023

Learn How To Ramp Up Your Cyber Awareness Training

 


One of the key mantras in the world of Cybersecurity is that of security awareness and training.  Although it may sound simple enough to do, it can actually be quite a difficult task to actually accomplish.  For example, whoever you are training, you have to hold their interest and attention so that they apply what the have learned in order to improve their current level of “Cyber Hygiene”.

Secondly, gone are the days of just giving a straight lecture for one hour.  The human attention span is simply not that long, and most importantly, you have to also engage your audience by keeping them engaged with various activities.

How can all of this be done?  In today’s podcast, we have the honor and privilege of interviewing Chris Ellis of Circadence.  They are globally known for developing effective strategies in creating and developing effective Cyber training strategies.  They are the pioneers in Gamification and other Real Time-based activities.

You can download the podcast at this link:

https://www.podbean.com/site/EpisodeDownload/PB1475785SSI7K

Saturday, August 5, 2023

How You Can Protect Your Data With The CA Delete Act

 


As I mentioned in the blog post from yesterday, data privacy is now becoming one of the main de facto standards in the world of Cybersecurity today.  Some of the most well-known ones in this regard are the GDPR and the CCPA.  But, as I was perusing the Cyber news headlines this morning, I came across an article which discusses how California is about to set a new version of its current CCPA.

So far, it is the proposed bill status, and it is entitled the “California Delete Act”.  It is geared primarily towards the data brokers that collect large amounts of consumer data, but don’t vet what is collected to protect the privacy of the consumer.  While the CCPA gives you the power to have data deleted from any company, this new bill will actually give you the ability to delete this data on your own authority.

The exact wording of the bill can be seen at this link:

https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240SB362

The details on the privacy risks that are brought on by the data brokers can be seen at this link:

https://www.darkreading.com/risk/the-danger-of-online-data-brokers

Some of the provisions of the proposed bill include the following:

*Require that all data brokers that collect data from California based consumers register with the CCPA.

*Provide opt out procedures for consumers.

*Keep a public listing of all of the consumers that have want to have their data deleted.

*In a manner similar to the “Do Not Call List”, provide a “No Consumer Tracking List”.

In order to facilitate these provisions in a quick manner all data brokers will be required to maintain an online portal where consumers can log in and immediately delete any data they want to. 

Some of the FAQs so far are as follows:

1)     Will this bill pass?

It is expected that it will pass by a wide margin, given that data privacy is such a hot topic issue today.

2)     How will it impact the data brokerage industry?

If this bill does indeed pass, it will be the first warning of its kind to the industry that they need to keep their guards up for any data leakages that could potentially happen.  They will also be audited,  and fined $200 per day per affected consumer until the proper remediations and controls have been established.

3)     How will compliance be enforced?

This is the part where there will be the most controversy.  If the bill passes, the state of California simply will not have all of the manpower that it needs to enforce each and every provision for every data broker.  This means that the industry will have to be on the honor system.  The only compliance efforts that will happen will come from the office of the Attorney General, and just like for the CCPA, this will only happen if there are a large number of complaints from the consumers.

My Thoughts On This:

Believe it or not, it was the passage of the CCPA that was the catalyst for the other states to create their own data privacy laws.  Once this new bill passes and becomes law, it is expected that the same will also happen.  But the problem now is that you are going to have fifty states with their own delete and opt out laws, which can be a nightmare for businesses to come into compliance with.

This is made only worse if they transact business in other states.  There will be a huge cost that will be borne to keep up with compliance, and this could even shut some businesses down, especially the SMBs.  Because of this, Congress has even looked into creating a federal version of the proposed California bill, so that there will be a sense of uniformity.

The details of this can be seen at the link below:

https://www.congress.gov/bill/117th-congress/senate-bill/3627

All of this reaffirms my belief yet once again that the United States needs a Department of Cybersecurity, so that any laws or bills will impact everybody across all of the fifty states in the same manner, nothing more and nothing less.  In fact, I will be writing a whitepaper on this very topic, so stay tuned!!!

Friday, August 4, 2023

Top 3 CISO Personality Types You Need To Know

 


Let’s admit it, one of the toughest jobs in Cybersecurity today has to be that of being a CISO.  To formally define, this is a role in which the designated person is hired on as full time, with a huge salary as well as a fat bonus package.  Btu behind all of this glitz and  glamor, the CISO is in a position where he or she is damned if they do  and damned if they don’t. 

There is no thanking or praise in this position.  The CISO is faced with a double-edged sword:  Not only do they have to keep in pace with the other members of the C-Suite, but they are in the perfect firing rage  in front of their Board  of  Directors. 

They literally have to do everything in their power to please them, because after all, their budget is literally in their hands.

The second part of the sword is in dealing with the members of the IT Security team with whom he or she is charged with leading.  Not only do they have to keep them motivated, but they have to listen, or at least make an attempt to do so.  In fact this is one of the areas that CISOs are blamed on. 

Many people feel, even outside of the IT Security team, that CISOs do a very poor job of both listening and  communicating.

While it is up to the CISO to change their personality traits, you can take some steps to help them listen to you better.  It all comes down to understanding the language they can understand and speak.  So, this is where you sort of have to figure out what kind of communication personalities they have.  Psychological research has shown that there are three distinct types,  which are as follows:

1)     The Business Minded One:

For this kind of CISO, all that matters to them (and rather unfortunately so) is the dollars and cents.  While they realize they have to maintain a strong security posture, they want to do it at the cheapest price possible.  While they make look good to their Board of Directors with this kind of personality, it often comes with a price:  Poor security.  Remember that old proverb, “You get what you pay for”?  Well, that certainly applies to this kind of situation.  Every recommendation or idea that you come up with and present will be countered with the question:  “How does this affect the bottom line”? 

2)     The Data Compliance Minded One:

There is no doubt that Data Privacy has become a huge concern today.  To make sure that businesses are compliant to protect their datasets, laws such as the GDPR and the CCPA have been created as a result.  If the right controls are not in place, there are very sharp financial penalties that can be imposed.  There are both civil and criminal  penalties that can also be imposed.  Because of this, the CISO has every right to be afraid.  After all, if there are any problems with auditors, it will be their heads that will roll.  Because of this, many CISOs have been now to take their fear to the extreme, and become totally obsessed by this.  Whie in a way this is good, because you will at least know your business will be compliant, it is also bad because the CISO will quickly lose sight of the other things that they are responsible for.  So in one end you will have some higher levels of protection, but on the other, your company could become more prone to security breaches because the CISO has not been able to keep up with the latest happenings in the Cyber Threat Landscape.

3)     The Technical Minded One:

These are the CISOs that have been brought up in the world of Geekdom.  All they have ever held were pure technical roles, and nothing else.  While you want a CISO that can understand and speak the techie side of things, this can also be a dangerous proposition if this is all they think about.  As a result, they cannot understand very easily the people side of things, and when they do communicate with other employees or their Board of Directors, it is often at a level that nobody can really understand.  Also, they will have a hard time communicating any kind of business to their higher ups, especially when it comes to getting an increased budget.  This kind of CISO personality also exhibits a very micro view of looking at things, because they want  to know about all of the moving parts that are happening.  Because of this, they can lose sight of the big picture very quickly.

My Thoughts On This:

Keep in mind that this is not an all-inclusive list.  There are other personality types that could potentially exist, but these are the three main ones that research has proven.  In an ideal world, you will want your CISO to speak through all three of these personalities.  But it is very difficult to find a person that can understand both the technical and business side of the Cyber world.

For this reason and  many others, many CISOs of today simply do not last long in their roles.  The average tenure these days is at best 1.5 years.  For this, as well as the current economic situation, many companies are now doing away with hiring full time, direct hire CISOs. 

Instead, they are opting much more favorably to what is known as the vCISO, where you hire a former CISO on a contract basis, for a fraction of the cost. 

But whatever route you go, keep in mind that the CISO or even vCISO is the ultimate reporting authority for the IT Security team.  If you want your ideas to be heard and even implemented, it is important to make some good efforts and try to understand not only if they fit in with any of the above-mentioned personality traits, but to try to speak their language as well. 

CrowdStrike One Year Later: 3 Key Lessons Learned

  Well guess what people?   It has been a year since the CrowdStrike fiasco, and from what we know, it was the biggest Cybersecurity   fiasc...