Sunday, March 3, 2024

The Clash Between AI & Data Privacy: How It Can Be Resolved

 


One thing that is for sure is that there are a lot of data privacy laws out there.  As I have written about many times before, some of the most notable ones are the GDPR, CCPPA, and HIPAA.  In the simplest terms, they have tenets and legislations embedded into them to make sure that businesses are maintaining all of the needed controls in order to make sure that the datasets that they have in their possession about their customers and employees are in safe hands.

There is much more to it of course, but the good news is that at least there are the regulators out the who are watching these companies, and should they go astray, they will come under the eyes of a comprehensive audit and possible financial penalties.  But the main problem here is that at least in the United States, there is no one central law that can handle all of the 50 states.

In other words, there can be 50 different privacy laws created each with their own set of requirements and caveats.  So, what if a business owner transacts business in all of the states, is he or she still responsible for becoming compliant with them?  The short answer to this is yes.   It will of course be a herculean task to accomplish, but whether it is fair or not, they will ultimately be held responsible.

Now, there is another issue which is further compounding this problem even more:  The explosion of AI on a global basis.  Obviously, AI models will be holding and transacting a ton of information and data.  After all, that is how they function and operate.  Because of the “black box” nature of AI, many people are now concerned about how they personal data will be protected here as well, and rightfully so.

So far, 8 states in total have come out with their own version of a data privacy law, and some of those include Oregon, Montana, and Texas.  Privacy surrounding the use of AI has also been addressed in these pieces of legislation.  But, even from within these states, these laws are wildly different.  For example, because of its much smaller population size (only about one million), the threshold of what constitutes data privacy has been set much lower, thus resulting in a lower ratio of audits and penalties if businesses are not compliant.

In terms of Texas, they have spelled out various financial thresholds in which businesses have to meet certain data privacy requirements.  For example, an organization that produces far less revenue will not be held to nearly the same standards as one that is a Fortune 500 company.  And in Oregon, the data privacy laws have been extended to include protection for linked devices (such as IoT based ones), to fitness watches, to even transgender health records.

So now as AI becomes much more entrenched into American Society, these data privacy laws will have to be adjusted on a big-time basis in order to accommodate and take into these advancements.  Here are four top trends to be on the lookout for as this year continues to unfold:

*Data leaks and exfiltration from Large Language Models (LLMs), which is a component of AI.

*Using existing customer information to train new AI models, without their knowledge or consent.  A good example of this is the recent fiasco with Zoom.  More details about this can be found at the link below:

https://www.darkreading.com/cybersecurity-analytics/following-pushback-zoom-says-it-won-t-use-customer-data-to-train-ai-models

*Expect more passage of widely varying data privacy laws from states located in the Northeast sector of the United States.

*Many unforeseen security breaches will occur as businesses continue to adopt AI on a rapid scale. To this effect, the Federal Trade Commission (FTC) will be a key regulatory body here.

*The Presidential Election of this year will only heighten the negative uses of AI, especially when it comes to Deepfakes, Phishing email attacks, and phony websites asking for political donations.

*There will be an increased awareness in terms of determining who owns the data, and under which data privacy law it should fall under.  This is also known as “Data Sovereignty”.  For example, suppose you run an online business, and you store all of your customer’s information and data in the Cloud.  Who owns it?  You? Your Cloud Provider?  Also, which data privacy law should it fall under?  The CCPA, or the GDPR?

My Thoughts On This:

Right now, it is the United States Federal Government who is our best friend right now to make sure that the states follow data privacy and protection.  In fact, the Biden Administration has passed some key pieces of legislation and even Executive Orders (EOs) to enforce this.  But the problem is that the technology is advancing far too rapidly than what the laws can keep up with.

For example, if a set of law is passed today, it will quickly become outdated tomorrow with the pace of innovation that is taking place in AI today.  One way to possibly resolve this to some degree is to have another department within the Federal Government called the “Department of Cybersecurity”.  From here, all of the AI and data privacy laws can be created and passed here, then trickling down to all of the 50 states.

The prime benefit here will be that there will be just one common set of standards and best practices, with no wild variations in the legislation, as we are seeing today.

Saturday, March 2, 2024

What The MTTR Is & How To Improve It

 


Believe it or not, just a couple of weeks ago, I signed the contract for my 18th book.  I just started writing the manuscript for it a few days ago, but now it is being bumped into my 15th book.  I am hoping to get it done by the early summer.  Interestingly enough, the topic is about Generative AI, and how that can be used to help improve the security metrics that are used in Cybersecurity today.

No doubt there are many of them, but the two key ones that I plan to focus on are what is known as the “Mean Time To Detect” (also known as the “MTTD”) and the “Mean Time To Respond” (also known as the “MTTR”). 

Although the definitions to them can vary and be complex, in simpler terms, the former refers to how quickly (or slow) the IT Security team is in detecting an imminent threat, and the latter refers to how long it takes for them to contain and/or mitigate it.

Astonishingly enough, it takes on average 270 days for an IT Security team to control an imminent threat.  To you and me, this seems to be unfathomable, but it’s true.  The source in which this information is available can be seen at the link below:

https://www.mend.io/blog/securing-the-software-supply-chain-mend-open-source-risk-report/

Because of this, it is the MTTR that is becoming a very key metric to the CISO and its higher ups today.  You may be asking at this point, why is this metric so bad?  Here are some reasons for it:

*With the advent of AI, many new innovations are proceeding at a very fast pace.  In fact it is so quick that many IT Security teams of today simply cannot keep up with what it takes to secure them.  And, this trend is only expected to quicken even more.  Many more tools are being used, such as Virtual Machines (VMs) and the like.  This can also be technically referred to as “Sprawl”.

*There is the issue of context.  With so many new products and services being AI driven, the sheer number of false positives is becoming totally numbing.  Although AI can also be used in this regard to only present the real and legitimate threats to an IT Security team via the SIEM, it still takes time to have to manually configure all of this.  By spending more time on this effort, much less resources are dedicated to actually fighting off the threats that are already present.

*Many organizations lack a cohesive Vulnerability Management program that can be easily deployed and enforced.  Because of the lack of this, just like the false positives, there is a very strong blur as to what can even be considered to be a vulnerability or not.  For instance, only 33% of them can be deemed of a critical nature.  So that leaves about 67% of them that are not real.  So how is an IT Security team supposed to filter through all of this?

(SOURCE:  https://www.edgescan.com/intel-hub/stats-report/)

To make matters even worse, there has been recorded a mind blowing 25,082 total number of vulnerabilities, which represents a staggering 24% increase from the previous year.

(SOURCE:  https://www.cvedetails.com/browse-by-date.php)

So given these dire situations, what can you, as the CISO of your business do help improve your MTTR metric?  Here are some steps to start with:

*Conduct a comprehensive Risk Analysis:  I have always been a huge fan of this.  With this approach, you are inventorying all of your assets, both physical and digital, and ranking them according to a Vulnerability Scale.  There are already frameworks that are out there to help you do this, most notably from CISA and NIST.  By doing this, you can also examine what you truly need and don’t need.  In turn, this will help to reduce Sprawl, which will then decrease the amount of vulnerabilities that in the end you have to manage.

*Examine your Triaging Structure:  See what you have in place right now, and determine if it is really working or not.  If it is not, then you and your IT Security team will have to produce a way to either improve it or replace it in its entirety.  But whatever you end up doing, test it in a sandbox environment first before deploying into your production environment.

*Be proactive it:  Once you have done the above two things, make sure that you keep a proactive watch on how your MTTR is doing.  Keep measuring on a regular schedule, because after all in the end, being the CISO, you will be ultimately held responsible for it.

My Thoughts On This:

The above are just some steps that you can take, and of course, as things evolve (especially with AI), there will be other actions you need to take as well.  But one of the big benefits of a lower MTTR is that your C-Suite will be more prone to give you a higher budget – in the name of keeping the business safe.

Also, keep an eye on my new book.  It will actually discuss how a Digital Person can help your IT Security team in bringing down your MTTR.

Saturday, February 24, 2024

4 Golden Tips On How To Make Cybersecurity A Priority

 


With all of the tech layoffs that have been happening, the disappointing financial news from Palo Alto, the emergence of AI, etc. Cybersecurity is getting another look over.  While the total number of attacks have gone down since last year, the total number of extortion attacks have actually increased, in large part due to Ransomware.  More information about this can be seen at the link below:

https://newsroom.orange.com/cyberextortion/

Also, with the complexities of the Cyber Threat Landscape changing almost every minute, now is the time for you, the CISO, to reevaluate your priorities when it comes to Cybersecurity.  So to help you get started, here is a starting point of what you should consider:

1)     Everybody is responsible:

Unfortunately in today’s world, everybody thinks that combatting security breaches is still the sole responsibility of the IT Security team.  This couldn’t be further from the truth.  Everybody has a role in keeping their place of employment safe!!!  This has to be emphasized over and over again in order for all involved to fully understand this.  This even includes external parties, such as contractors, suppliers, etc.  But even more important, the mindset of the C-Suite has to change as well.  Yes, the buck stops with you (as the CISO) for Cybersecurity, but all responsibility has to be shared with everybody on this level, going all the way from the CEO to the CFO to the COO, etc.  In this regard, Cybersecurity should not be viewed as just an expense, rather, it must be viewed as an investment!!!  Bring things down in terms of dollars and cents, and what it will mean if there is any kind of downtime.

2)     Know thy data:

Believe it or not, even to this day, CISOs do not even know where their data sets even reside at.  So, now you must take the time to get a grasp of this, and know exactly where everything is.  If needed, create a separate team to map out where everything is, even all of the databases.  Keep this document backed up, both as a hard copy and an electronic copy.  Make sure that it is updated at all times, no matter what.  Also, conduct regular audits of your datasets to make sure that there are no instances of data exfiltration that could be occurring.

3)     Have your plans:

When the COVID-19 pandemic hit, companies were in a huge scramble to figure out how to deploy their remote workforce.  A large part of this nightmare was due to the fact that none of these entities had a formal Incident Response (IR) plan in place.  This is a formal document which details as to how you will respond in the case of a security breach.  A future blog will outline the details of what should be included in this kind of plan.  But the bottom line here is that if you don’t have this in place, create one immediately, and practice it on a regular basis.  Even more importantly, update it from the lessons learned each time to practice it!!!

4)     Keep training:

Keep training your employees in the sheer importance of maintaining strong levels of Cyber Hygiene.  There are different ways in which to deliver this kind of training, but make sure that it fits the role of the employees.  In other words, don’t take a one size fits all approach, the training has to be customized, in order for your employees to truly understand what is at stake.  Also, don’t make these just lecture sessions, make it interactive so that the audience can take away something from it, and apply what they have learned.

My Thoughts On This:

It is even more important now than ever to take Cybersecurity seriously.  Just because a security breach has not happened to you does not mean it will not happen down the road.  Spending some time now and some money will pale in comparison to the exorbitant costs you will face if you do become a victim!!!

Sunday, February 18, 2024

3 Effective Ways To Keep Up With The Cyber Landscape In 2024

 


The world of Cybersecurity as we know it today is always changing, and will forever be changing.  It will by no means be a static one, like perhaps it was in the late 20th century.  Given how everything is all connected together now, the evolution of AI, the stealthier mindset of the Cyberattacker, etc. will all be changing this for a very long time to come.

So the question now comes down to as to how a business, or even a CISO of a much larger organization come to grips with this, and how they can keep up. It will by no means be an easy task, and trying even to do it will be a full-time job.  So to get started with, here are three key areas which will become important this year on the Cyber landscape:

1)     Threat Hunting:

The bottom line here is that the days of simply doing these kinds of tests whenever you felt the need to do it no longer suffice.  Many people have their own definition of what Threat Hunting is, but IMHO, this is a deep and comprehensive test that tries to find any threat actors or malicious payloads that have been deployed into your IT and Network Infrastructure.  It has been recommended that this kind of test be done at least once a quarter, but even now this is not proving to be enough.  It has come to the point that it needs to be done almost every day.  But the good news here is that the Cyber vendors who make these kinds of tools are fully aware of this, and are producing new services that will allow you to do this, such as a Cloud based deployment, so it remains highly affordable to you.  My recommendation is to start looking at this as soon as you can.

2)     UEBA:

This is an acronym that stands for “User and Entity Behavior Analytics”.  Long story short, this is where you deploy the needed tools to keep track of how well your employees are keeping up on their Cyber Hygiene.  But the key difference here is that you will not just be getting a holistic picture, but rather, a full report on each and every employee of yours.  Given the advancements that have been made today, you can even get an entire picture painted for you of just risky the behavior of your employee is.  Of course, you will need to tell them how you will be watching them ahead of time.  But once again, given how things are changing, you cannot take anything for granted.  This is especially true of hiring contractors.  Also, by deploying UEBA, you will get far better indications of when an Insider Threat could be happening.  Another key advantage if using UEBA is that it can create updated baseline profiles for you, on a real time basis.  For more information about UEBA, click on the link below:

https://www.darkreading.com/cyber-risk/how-to-get-the-most-out-of-ueba

3)     The rise of data:

There is no doubt that today, there is a sheer explosion of data that is happening today.  Not only can it be a nightmare to store all of it, but worse yet, it can be almost disastrous to try to keep up with the data privacy laws and their rules/regulations.  But, data can carry a lot more meaning these days.  For example, Big Data sets often contain hidden trends that convey a lot of meaning.  For example, it can give you greater insights into your competition and customers.  But above all, it can even give you very subtle clues as to who is gaining access to your system, what times that it is happening, etc.  But don’t attempt to do this all by yourself.  Rather, use both AI and ML to do this for you.  They can do it in just a matter of sheer minutes, and give extremely granular insights into each and every bit of data that your business has.

My Thoughts On This:

For you the business owner, this is of course a lot to digest in.  But I always keep a motto:  Take things one day at a time.  The one nice thing about the Cyber community is that we all band together in a time of need.  So if you need help with any of these above-mentioned items, please reach out to me or I can refer you to somebody else.

Also, stay tuned for future blogs on this very topic, but focusing in on other areas of concern that you need to be aware about.

Saturday, February 10, 2024

How To Correct Medical Device Cyber Weaknesses: 2 Golden Tips

 


The US Healthcare system has been regarded as one of the best in the world.  A lot of this has not only to do with the extensive amount of training that future doctors, nurses, and other practitioners have to undergo, but we are also blessed that we have all of the advanced technology in the world.  Not many countries can say the same.

But there is one area in our great healthcare system that is still lacking:  Yep, you guessed it, it has to do with our Cybersecurity.  Attackers still love to pounce on the targets here, especially when it comes to the heisting of patients information and data.  But there is yet another area here where it is even more detrimental:  Implanted medical devices.

A good example of this is the pacemaker.  It is used to control the heartbeat, so that it maintains a proper rhythm.  But unfortunately, it is now accessible via radio control by the patient’s doctor.  While this is a good thing, it can be a bad thing also, because the Cyberattacker can also take control of it, take control of the pacemaker, and literally kill the patient wherever they are at.

Luckily to my knowledge nothing like this has happened yet, but the potential for it is quite strong.  In response to this, the United States FDA has now mandated that all manufacturers of medical devices follow a principle called “Secure By Design”.  This is where certain kinds of controls have to be literally embedded into the device, in order to safeguard the security of the patient.

More information about the FDA requirements can be seen at the link below:

http://cyberresources.solutions/blogs/fda.pdf

More details about “Secure By Design” can also be found at the link below:

https://www.darkreading.com/application-security/lock-down-the-software-supply-chain-with-secure-by-design

An example of such a control is Multifactor Authentication, also known as “MFA” for short.  This is where at least three or more differing mechanisms are used to confirm the identity of an individual. 

But another problem now is that a lot of the healthcare providers are now moving to the Cloud (such as the AWS or Azure) in order to host the applications that support these medical devices.  As a result, this comes under the guise of what is known as the “Share Responsibility Model”.  As a user of the Cloud, you actually share your resources with other “tenants” in order to keep your monthly costs down.

While this is of course a good thing, it can be a bad thing because now your datasets can theoretically become that much more accessible to malicious third parties.  But, the Cloud providers do give you the resources and the tools that you need to protect your part of the Cloud, but you have to take responsibility to make sure that they are configured properly to your security requirements.

But to make implanted medical devices more secure, it is recommended that the following steps be taken, and quickly:

1)     The hospitals have to do their part:

Usually, the medical device vendors will provide information to the practitioners about the devices that they are interested in using.  An example of this is the “Manufacturer Disclosure Statement for Medical Device Security”, also known as the “MDS2”.  It spells out all of the details of the security features that a particular device has, and from there, the facility can make an informed decision as to whether to use it or not.  But the bottom line is that it must be read, and just discarded away!!!

2)     Configure those devices:

The vendors will also have documentation on how to further fine tune your procured devices to best meet your security requirements.  Heed these documents carefully also!!!  Most medical facilities don’t do this, and instead rely on the default settings.  Don’t do this!  This is where you will have more back doors open than you realize. 

My Thoughts On This:

Another catalyst that is leading to the explosion of implanted medical devices is the Internet of Things, also known as the “IoT”.  The connections between devices still remain unencrypted, making it more a risk to use.  Also, the growth of AI and ML isn’t helping matters much either on the Cybersecurity front, either.

The best advice I can give here for the medical practitioners are to stay proactive, and make sure that ever security control is used to the maximum extent possible.

Sunday, February 4, 2024

6 Golden Tips To Get Prepared For The CMMC Certification

 


For those companies in the defense sector, you know very well that the Department of Defense (DoD) is pretty much your main bread and butter.  But as the Cyber Threat Landscape has evolved, so have the security precautions that the DoD has set into place to make sure that whatever information is transmitted to during and after the bidding process remains confidential.

To this end, they have implemented what is known as the “Cybersecurity Maturity Model Certification”, also known as the “CMMC” for short.  Long story short, this is where the Defense Industrial Base (DIB) and their subcontractors have to reach a certain level of Cyber certification before they will even be allowed to bid on any kind of contract. 

The CMMC framework has been going on for a number of years now.  In fact, there are two different versions of it.  In the first one, there were five different levels of certification that could be achieved, but with the newer version of it, there are only three.  In fact, the requirements have actually eased up a bit in this round to help defense contractors get their certifications quicker.

Although achieving CMMC certification at any level can be both a herculean and daunting task, as a CISO of a defense business, you have to realize that simply achieving it is not the end of your Cybersecurity efforts to beef up your  lines of defenses.  You will have to keep pushing through, no matter how hard and long the journey might be.

To this end, I came across an article in which a 30-year-old veteran of the Cyber industry who echoes these same thoughts.  His mantra is “Harden”, and he has a six-step approach to this:

1)     Harden your people:

This includes both the members of your IT Security team and the other employees in your company.  The best way to do this is through constant security awareness training programs, and holding mock simulation attacks.

2)     Harden your Cloud:

Whatever Cloud platform you make use of, such as the AWS, Azure, or the GPC, make sure to use all of the tools that are available to you in your subscription to protect your IaaS, PaaS, and your SaaS environments.  An important thing to keep in mind here is that you are ultimately responsible for the configuration of these tools, not your Cloud provider!!!

3)     Harden they endpoints:

The term “endpoint” can be confusing, but for purposes of this blog, it simply means all of the devices in your company that are being used by your employees, whether they are on site, hybrid, or remote.  The best level of protection that you can offer here is to use what is known is known as an “Endpoint and Detection Response” (also known as “EDR”) solution to fortify all of those devices.

4)     Increase your levels of both visibility and detection:

This simply means collecting all of the information and data from your network security devices into one central repository, such as that of a SIEM.  This will show you all activity on a real time basis from just one point of view.  You can also make use of both AI and ML tools to help filter out for the false positives, so that only the real and authentic ones are presented to your IT Security team for appropriate triaging.

5)     Keep hunting:

As a CISO, you can never assume that all of your weaknesses and gaps have been filled.  There will always be some, so therefore, you should always on a regular basis, be engaged in both Penetration Testing and Threat Hunting exercises on a regular basis (at least on a quarterly basis).  Also, conducting Vulnerability Scans would be a good thing here to do as well.

6)     Respond quickly:

The bottom line here:  If you detect a threat, respond immediately!!!  Don’t wait for seven months or so in order to detect it (that is currently how long it takes Corporate America to detect a security breach).  For this to happen, you have the right Incident Response (IR), Disaster Recovery (DR), and Business Continuity (BC) plans in place, and they must be rehearsed also on a regular basis.

My Thoughts On This:

Don’t wait to get CMMC certification to take these above-mentioned steps.  In fact, the DoD even recommends that the best way to get certified is for your company to be proactive on the Cyber front at all times, and take all of the steps that are necessary to protect your lines of defense.

Friday, February 2, 2024

The Top 3 Security Breaches Of 2023 & Why They Happened

 


I know that it seems kind of unusual to be posting about some of the top Cyberattacks that happened in 2023 (just last year), but I am going to take a shot now at it, and review those that were some of the major ones.  So, here we go:

1)     MOVEit:

This has probably been of the largest Cyber breaches that happened last year.  It is essentially a file transfer software package.  The malicious payload that was deployed into was the ever so famous SQL Injection Attack.  Here are some of stats into its large impact:

“*More than 62 million individuals were impacted.

*Over 2,000 organizations were breached.

*Approximately 84% of breached organizations are US-based.

*Approximately 30% of breached organizations are from the financial sector.

*$10 billion is the total cost of the mass hacks so far.”

(SOURCE:  https://www.darkreading.com/cyberattacks-data-breaches/top-3-data-breaches-2023-what-lies-ahead-2024).

This security breach demonstrated just how wide scale a single piece of malicious payload can be.  In fact, it can even be likened to the Solar Winds hack, there just one backdoor was used to infiltrate and infect thousands of victims, which included some of the largest of the Fortune 500 companies and even the US Federal Government.

Although three major patches have been released, it still continues to impact victims.  Some of the notable ones include Sony Interactive Entertainment, the BBC, British Airways, the US Department of Energy, and Shell.  This truly represents a broad spectrum of industries and only proves that nobody is immune to a Cyberattack.

2)     The Indian Council of Medical Research (ICMR):

This security breach has been deemed to be one of the largest in terms of data exfiltration.  By using a simple alias of “pwn0001”, the names, addresses, and phone numbers of over 81 million Indian citizens was exposed.  They were also able to hijack the datasets from the COVID-19 databases owned and operated by the Indian Government.  More information about this can be seen at the link below:

https://www.thehindu.com/news/national/us-cyber-security-form-indicates-data-breach-sourced-from-icmr/article67477424.ece

Here are some of the stats of this breach:

“*5 million breached personal records and COVID test details from the New Delhi-based organization.

*90GB of data offered for sale for $80,000.”

(SOURCE:  https://www.darkreading.com/cyberattacks-data-breaches/top-3-data-breaches-2023-what-lies-ahead-2024).

This Cyberattack simply underscores the need to keep auditing the controls that you have in place for protecting your information and data, and the need to have an effective response plan in place to contain any breaches like this.

3)     23andMe:

In this particular Cyberattack, credential stuffing was the main threat vector that was used.  Login information (such as usernames and passwords) were hijacked, and were able to gain access to private data, which included the following:

*Names

*Email addresses

*Dates of birth

*Genetic ancestry and history

Here are the stats of the impact:

“*9 million user accounts were compromised — about half of the company's users.

*More than 5.5 million customer records were scraped and leaked.

*$6 is the average black-market price of a breached account.”

(SOURCE:  https://www.darkreading.com/cyberattacks-data-breaches/top-3-data-breaches-2023-what-lies-ahead-2024).

This security breach only underscores the need to deploy and maintain strong levels of Cyber              Hygiene, as well as the need to implement Multifactor Authentication (also known as “MFA”).

My Thoughts On This:

As I said earlier in this blog, nobody is immune to becoming a victim of a Cyberattack.  As I have said time and time again, the key is in mitigating that risk from happening.  Corporate America really needs to step up to the plate and take accountabilities for all of the datasets that are in their possession.  They have to realize, that we, as US citizens, are trusting them with the safekeeping of them.

They need to know where all of the datasets reside at, and continually do Risk Assessments not only to make sure that the controls protecting them are optimized, but to address and quickly remediate any gaps or weaknesses that have been found. 

Also, the need to keep training employees is a must to make sure that they are maintaining their contributions to a high caliber of Cyber Hygiene.  Also, companies need to make sure that they have all of the right plans in place in order to contain the breach, should it happen.

These include the Incident Response (IR), Disaster Recovery (DR), and Business Continuity (BC) Plans.  They must not only be documented, but they must practice on a regular basis to keep them updated.

CrowdStrike One Year Later: 3 Key Lessons Learned

  Well guess what people?   It has been a year since the CrowdStrike fiasco, and from what we know, it was the biggest Cybersecurity   fiasc...