Looking Ahead to 2015 and What’s in Store for Enterprise Security

If this wild 2014 taught us anything, it’s that cyber threats are becoming more pervasive and no one is immune to them. All organizations – regardless of vertical segment – need to apply a heightened sense of urgency and sophisticated security measures that:

  • Lean more towards strict security policies versus a predominantly open environment
  • Address attacks at every step in an attack lifecycle
  • Cover all aspects of an enterprise – from the data center and branch offices to endpoints

We invite you to learn more about the Palo Alto Networks Enterprise Security Platform, which offers a unique preventative approach with three essential components – Next-Generation Firewall, Advanced Endpoint Protection and Threat Intelligence Cloud – to secure computing environments, prevent known and unknown threats, and safely enable an increasingly complex and rapidly growing number of applications.

Below you’ll find all of our 2015 predictions by subject.

 

These topics are among many planned for Ignite 2015, where you will tackle your toughest security challenges, get your hands dirty in one of our workshops, and expand your threat IQ. Register now to join us March 30-April 1, 2015 in Las Vegas — the best security conference you’ll attend all year.

 [Palo Alto Networks Blog]

 

A Forecast of the Cyberthreat Landscape in 2015


Ryan Olson, Intelligence Director, Palo Alto Networks

As I look back over the cyberthreat landscape in 2014, I’m amazed by the volume of activity handled by our community this year. From Heartbleed toWireLurker, we certainly had our hands full.

Sophisticated, targeted attacks will be the new normal in 2015 and I expect to see at least one new report each week. Here are some other trends from 2014 and predictions for the coming year that I think are significant.

Longstanding vulnerabilities revealed
In 2014 we learned about multiple major vulnerabilities in code, which in some cases had been in place for more than a decade. Heartbleed, ShellShock,POODLE and SChannel all existed in source code for years, but weren’t publicly disclosed until 2014. It’s possible that these vulnerabilities had been independently discovered by attackers who exploited them unnoticed for years. 

The discovery of these vulnerabilities started reviews of major open source repositories the community had assumed were rock solid. Those reviews are likely to bear fruit in 2015, resulting in the disclosure of more long-standing vulnerabilities.

Continued success of ransomware
Ransomware, a class of malware that extorts users into paying an attacker, has existed in various forms for years, but 2014 was when the “Locker” malware really took off. Lockers work by infecting a system, quickly finding important files on the hard drive, encrypting them and telling the user they can recover the files if they pay a ransom, normally a few hundred dollars. Lockers are distributed through many mechanisms (spam email, for example) and are often installed by other botnets as secondary payloads.

The best-known locker variant, “CryptoLocker,” was detected in late 2013. One of the reasons for this malware’s success was that its operators actually decrypted files once the ransom was paid. If word got out that victims who paid the ransom never recovered their files, nobody would pay up. But infected users trusted CryptoLocker and were willing to pay the ransom to retrieve their stolen files. Other variants of lockers discovered in 2014 included CryptoWall and CryptoDefense.

The massive success of these in 2014 impacted companies large and small and the revenue streams generated by ransom payments are unlikely to be disrupted any time soon.

Ongoing PoS attacks
Starting at the end of 2013, organizations began reporting a series of attacks on retail point-of-sale (POS) systems, which impacted tens of millions of users. These attacks used malware that infected Windows systems attached to credit card readers, and searched those systems’ memory for credit card data.

In August, the U.S. Secret Service released an advisory about one of those malware tools, known asBackOff. The advisory estimated that more than one thousand businesses were affected by BackOff. While many organizations reported PoS breaches this year, the total of publicly announced breaches was well under a thousand, indicating that many breaches may have gone unreported.

The U.S. credit card payment system is moving away from legacy magnetic stripe technologies toward chip-and- PIN systems, which are less vulnerable to these attacks. Apple released its own payment system (ApplePay) in October, which uses near field communication (NFC) for contactless payments, in part to help make in-store payments more secure.

POS attacks and new malware are likely to extend well into 2015 and beyond – depending on how quickly new security measures are adopted.

Mobile is a valuable target
In 2014 we saw multiple new attacks on Android and iOS devices, most significantly WireLurker, which attacked non-jailbroken iOS devices. As more data moves onto these devices they are becoming a valuable target for all types of attackers.

Mobile devices are ripe for attack for many reasons: They often hold user credentials for applications and websites, they’re used for out-of-band authentication, they are almost constantly connected to the internet and they have audio and video recording capabilities

For high-profile targets, these devices are a treasure-trove of information. Mobile platforms often do not receive the same level of monitoring (anti-virus, IPS, etc.) that desktop systems do. An infected phone could go unnoticed for months or longer while monitoring the user and stealing their data.

In 2015 I expect to see the discovery of significant targeted attacks against mobile devices designed to steal data.

[SC Magazine]

Why Am I a Huge Fan of COBIT?

If you’ve been thinking about looking into COBIT, but haven’t because you are not quite sure what it can do for your enterprise, now is the time to get started. As an IT professional who has used COBIT for several years, I can say without hesitation that it has more to offer than you might imagine. COBIT can help you look at your organization from the governance and management standpoints, and expands the view beyond just processes through the use of enablers. This framework is not an academic reference that grew out of the audit, risk and security areas. It is a flexible, useable tool that has completely won me over, and here are five reasons I’m a big fan:

  1. COBIT is relevant—the goal is to deliver value.
    The enterprise exists to create value for its stakeholders. This is simple in theory, but tough in real life. COBIT was created from the top down, meaning that the entire model focuses on the primary facets of providing value by realizing benefits while optimizing risks and resources. From the goals cascade to the enablers, COBIT helps you focus on value.
  2. COBIT still focuses on information.
    If an enterprise does not manage its information, it will no longer exist. COBIT focuses on the information first, and that is the right way to look at it. Without information, there is no need for the technology.
  3. COBIT is not just for the big companies.
    COBIT has escaped the “for big companies only” misconception. Whether you have a small IT organization or several hundred resources, COBIT fits any size; you just need to identify your business goals, objectives and mission to operate as a going concern. I have seen an organization with two IT staff members leverage COBIT.
  4. COBIT is a framework that looks beyond just processes.
    COBIT’s seven enablers are designed to help you get beyond just looking at processes. These enablers include 1) Principles, Polices and Frameworks, 2) Processes, 3) Organizational Structures, 4) Culture, Ethics and Behavior, 5) Information, 6) Services, Infrastructure and Applications, and 7) People, Skills and Competencies. These provide a more holistic approach to governance where changes in one enabler must be adequately assessed across all enablers.
  5. COBIT is a great reference for process owners.
    All processes should have owners. I will even take that a step further and say that all processes should have assigned roles. Within COBIT 5 there is a wealth of information regarding processes. There are 37 processes organized into five domains (one governance domain and four management domains). Within this process reference model, the biggest hitters for me include: process description and purpose, practices and activities, inputs and outputs, RACI charts, goals, and related industry standards and frameworks.

And the benefits don’t end there. See five additional reasons here.

Whether you are a board member, executive, auditor or IT operator, do yourself a favor and learn more about COBIT. Admittedly, many people find it difficult to simply thumb through the various publications and experience the “ah, I get it now” feeling. My advice to anyone who wants to learn more about it is to go to the ISACA site and download some of the key publications, or visit COBIT online. And consider joining me at the first-ever COBIT Conference, taking place in March 2015 in Orlando, Florida, USA.

Adopting a framework does not guarantee your governance success, but it sure does offer a great starting point. COBIT offers a common language that can be shared across the enterprise, but real adoption requires executive support, a desire to improve and a strong desire to achieve the governance of enterprise IT.

Mark Thomas, CGEIT, CRISC, ITIL, MOF
President of Escoute

To learn more about the COBIT Conference, visit www.isaca.org/cobitconference.

[ISACA]

English
Exit mobile version