Schauinsland-Reisen, an independent travel agency based in Duisburg, Germany, is the seventh largest package tour operator in Germany and currently offers travel services to over 60 traveldestinations. This nearly 100-year-old company, with a team of over 300, provides excellent customer service, but with a growing web business and a network of over 11,600 partner travel agencies, Schauinsland-Reisen saw a steady rise in cyberthreats.
Unfortunately the company’s Linux-based firewall and antivirus software did not provide adequate protection of critical network assets and endpoint devices. Since implementing the Palo Alto Networks Next-Generation Security Platform, Schauinsland-Reisen has seen a dramatic improvement in network visibility and intrusion prevention.
The platform, consisting of Palo Alto Networks Next-Generation Firewall, Threat Intelligence Cloud, and Advanced Endpoint Protection, blocks daily cyberattacks while ensuring the smooth flow of legitimate network traffic, and also proactively guards against new cyberthreats and prevents damaging code transported by malicious emails and applications from infecting its endpoint devices.
Schauinsland-Reisen is happy to now have a comprehensive, end-to-end cybersecurity platform to protect its business and assure travel customers that their private information is safe on Schauinsland-Reisen’s systems.
“The Palo Alto Networks Next-Generation Security platform opened a whole new universe of options for us. We could finally see how many cyberattacks were coming in from the web every day. It was quite alarming,” Michael Mrugowski, technology team leader at Schauinsland-Reisen comments. “Yet, having the Palo Alto Networks security platform in place, we can say with certainty that compromises to our network are being effectively prevented.”
Investments in cybersecurity tend to be fairly significant, so organizations continually seek ways to determine whether the investments are appropriate based on return. However, companies are challenged to apply and fit the traditional discounted cash flow methods to calculate a return on investment (ROI) and justify cybersecurity initiatives. Return on (cyber)security investment (ROSI) with a method to quantify the intangible returns on cybersecurity initiatives are even harder to calculate than traditional IT initiatives using traditional accounting methods.
The perceptions and views of non-IT management toward cybersecurity are among the contributing factors posing the challenge to justify the expense of such initiatives. A communication gap has resulted and is apparent in some of the following views and questions:
Security is not an investment.
Is cybersecurity an IT discipline?
The investment justification methodology proposed in my recent Journal article applies to situations in which company competitiveness is examined, critical success factors are defined, and risk and challenges are identified. The objective of the company’s cybersecurity decision model (CSDM) is to frame cybersecurity initiatives with justifications in alignment with company business objectives and governance.
One critical component of my proposed cybersecurity investment decision model formation is based on the company’s collective efforts managed in a workshop environment. The tool used in the workshop based on analytic hierarchy process (AHP) is the technique used to facilitate and determine the degree of impacts and priorities of the proposed initiatives
In my recent Journal article, I stated several benefits and byproducts to expect through the use and performance of the ROSI nontraditional justification methodology, including:
Establishing a clear and dynamic link among company goals, objectives, risk and cybersecurity initiatives
Elevating cybersecurity planning and implementation to the corporate governance level with easier interpretation for nontechnical and technical personnel
Providing a communication platform for management team alignment and support
Developing a company business model that is well understood by the management team and other company entities
Identifying and prioritizing the interrelated elements where management is able to establish better planning, rationalization and deployment of initiatives
Quantifying the impact the proposed initiative might have on each of the company objectives and on the bottom line
Seeking the support of the management team for future departmental initiatives and operational decisions
A new version of the Palo Alto Networks threat intelligence portal AutoFocus is out! And it’s packed with several nifty features that make threat research a breeze.
STIX for AutoFocus API: STIX (Structured Threat Indicator eXpression) is an XML-based standard that provides a consistent format for storing and sharing cyberthreat data. The AutoFocus API now lets you send API requests to AutoFocus and receive STIX-compliant responses. Sharing AutoFocus threat intelligence is easier than ever!
New Threat Analysis Features: Assess your level of coverage against malware by viewing which signatures were matched to a sample during WildFire analysis. Additionally, for behaviors observed in a sample during WildFire analysis, you can now view a list of activities exhibited by the samples that were used as evidence of the observed behavior.
AutoFocus Feedback Tool: A new feedback tool built into the AutoFocus navigation pane lets you get in touch with the AutoFocus team in just a couple of clicks. Send your rave reviews of AutoFocus or request features you’d like to see in future releases.
Workflow Improvements: Be an AutoFocus power user in no time with various time-saving enhancements to the portal. Changes include the ability to:
Start searching for an artifact from any page on AutoFocus
View the API request for a search directly in the AutoFocus interface
Conduct multiple searches simultaneously in different browser windows
For questions or comments about these features, contact your SE or account representative. For questions about documentation, email us at documentation@paloaltonetworks.com.
What keeps CISOs up at night? Of all the cyberthreats, malware sends chills down a CISO’s spine, according to The CyberEdge Group’s recently released 2016 Cyberthreat Defense Report. Malware bogeymen come in many shapes and sizes. Here are three of the most nefarious in their respective categories:
Ransomware: CryptoWall Ransomware has come a long way since 1989, when the AIDS Trojan first encrypted a user’s hard drive files and demanded money to unlock them. The latest version of CryptoWall, the most significant ransomware threat in the States, not only encrypts the file, it also encrypts the file name—making it a challenge to even find “kidnapped” files.
CryptoWall cost victims more than $18 million in losses in a single year, according to the FBI. While individual ransom fees are typically only $200 to $10,000, additional costs can include loss of productivity, mitigating the network, incorporating security countermeasures, and purchasing credit monitoring services for employees and/or customers.
Banking Trojan: Dyreza Banking Trojans use a man-in-the-browser attack. They infect web browsers, lying in wait for the user to visit his or her online banking site. The Trojan steals the victim’s authentication credentials and sends them to the cyberthief, who transfers money from the victim’s account to another account, usually registered to a money mule.
For nearly a decade, the ZeuS Trojan conducted a reign of terror in the banking world. Even after Europol took down the Ukrainian syndicate suspected of operating ZeuS in 2015, new strains kept appearing. But it seems ZeuS has met its match in Dyreza (aka Dyre, aka Dyzap). More than 40% of banking Trojan attacks in 2015 were by Dyreza, according to Kaspersky Lab’s 2015 Security Bulletin. Dyreza’s one-two punch? It can now attack Windows 10 machines and hook into the Edge browser.
Mutant two-deaded worm: Duqu 2.0 There isn’t an official category yet for the most sophisticated malware seen to date. At a London press conference announcing an attack by the new version of the Duqu worm on its corporate network, Kaspersky Lab founder Eugene Kaspersky described the malware as a “mix of Alien, Terminator and Predator, in terms of Hollywood.”
The original Duqu worm was mysterious enough, being written in an unknown, high-level programming code. Now Duqu 2.0 is further flabbergasting the security experts. Some describe it as a compound sequel of the Duqu worm that assimilates the features of a Trojan horse and a computer worm. Others call it a collection of malware or a malware platform.
I’m dubbing it the Mutant Two-Headed Worm because it has two variants. The first is a basic back door that gives attackers an initial foothold on a victim network. The second variant contains multiple modules that give it multiple superpowers: it can gather system information, steal data, do network discovery, infect other computers and communicate with command-and-control servers. And did I mention Duqu 2.0 has an invisibility Cloak? The malware resides solely in a computer’s memory, with no files written to disk, making it almost impossible to detect.
If Duqu 2.0 attacks increase in 2016, expect malware to be a CISO’s worst nightmare next year too.
The modern day Payment Card Industry Data Security Standard (PCI DSS) v3.1, applies a robust layered approach for the security of cardholder data, applying the concept of defence in depth (DiD). This concept is nothing new and can be seen to have been applied by the Roman Empire in the 4th century AD1 and developed over 700 years, during the enhancements of the city of Troy2 , between 1700 BC and 1190 BC.
DiD was successfully developed as the result of numerous ‘lessons identified’, following numerous conflicts and incidents over many years.
However, given this strong legacy and long history of successful application of the DiD methodology, why is it that successful business leaders are still struggling to recognise the importance of creating a robust PCI DSS citadel, for the safety and security of their customers’ cardholder data operations?
The major difference between the Romans and the Trojans and now is that the types of assets have changed.
Historically, the assets were visible, tangible assets (Helen of Troy, precious jewellery, etc.) that were clearly identifiable and easier to see. Today, technological advancements have changed the assets into a mix of tangible assets (physical credit cards, receipts, chargeback letters, etc.) and virtual, intangible assets (eCommerce, Mail Order/Telephone Order computer processed, etc.) that are more difficult to identify and locate where they might reside (databases, spreadsheets, flat files, etc.).
Added to this is the fact that most acquiring banks grant approval for merchants to process cardholder data before they have created their secure citadel, in support of their card payment operations, or they are not made aware of the associated costs and complexities of building and maintaining secure card payment processes.
How can the lessons of the Romans and Trojans be applied to modern day business card payment operations?
Likened to history, today there is a clear and present threat from hostiles attempting to penetrate your defences, in order to gain from stealing customers’ cardholder data. These attackers can range from the opportunist, amateur hacker, who is driven by 3 incentives:
Inquisitiveness
Challenge
Reward (mostly not financial reward, but more personal reward—like winning a game of strategy)
Or:
The attacker could be a determined, organised criminal gang, who is informed of the value of the assets within an organisation. The criminal fraternity have changed their modus operandi to reflect the gains of the modern day. No longer do they need to go through the complexities of planning to rob a bank, much like they might have done in the 1950s or 1960s, when they can gain the same benefit from dropping in a simple piece of malware (such as a RAM scraper) into a large retail business.
These examples present the ‘kinetic’ (external) threat vectors. However, the successful application and management of PCI DSS also helps protect against the non-kinetic (insider) threat—that authorised insider who carries out an activity (either maliciously or accidentally) that causes a breach.
Would your staff help to wheel a Trojan Horse through your suite of defensive countermeasures?
What steps are required?
The city of Troy took 700 years to construct; PCI DSS is only 12 years old and still in development. However, there are a great deal of lessons we can take from history, as shown in figure 1 and listed here:
Figure 1: Nettitude PIE FARM methodology
Plan & Prepare3
Set up a team, within the business, to design architectural and project plans, presented within a business case, which clearly articulates what the predicted set-up and maintenance costs might be, along with defined milestones.
Identify & Isolate
What are the methods of taking card payments (payment channels)?
What are your businesses card data flows?
What assets (technologies, people, processes, locations, etc.) support the card payment operations?
Are there any inter-connecting assets?
Is it possible to reduce the scope, through the creation of a Secure Bunker/Citadel (RED Channel) where the card payment systems reside, that is isolated from the non-card payment systems?
Which of the PCI DSS controls apply to the business?
Evaluate
Having established the baseline, carry out a gap analysis to provide the rapid identification of areas requiring improvement.
Fix
Work through a suite of remediation activities.
Assess
Carry out an investigation into the maturity and effectiveness of the application of the baseline controls.
Report
Complete a Self-Assessment Questionnaire (SAQ), against each of your payment channels (low-volume merchants) or have an independent onsite assessment, by a Qualified Security Assessor (QSA), to validate that your card payment operations are safe and secure.
Maintain
Do not become complacent, once having completed the process to ‘get across the line’ and achieve the compliance status. PCI DSS requires a number of mandated, scheduled activities:
6-month firewall reviews
Quarterly card data discovery
Annual web application testing
Vulnerability and patch management
Daily audit trails reviews
Weekly change detection reviews
Quarterly wireless checks
Quarterly internal and external
Annual penetration testing (or after any significant change)
In complex environments, how can you hope to effectively govern your PCI DSS footprint, ensuring that assigned responsibilities are being carried out effectively and in a timely manner?
Scheduling?
On The Job (OJT)?
Security Awareness?
Well-written and -communicated, effective policies and procedures?
Effective security incident response?
Employment of a governance, risk and compliance tool? (shown in figure 2)4
The associated PCI DSS worlds are ever-changing, dynamic environments, with the attackers become ever more creative. Therefore, as attackers create new and innovative approaches, we need to ensure that our defensive responses are just as innovative and responsive.
The benefit of this approach is that it will help to reduce the chance of suffering a breach, whilst reducing the cost and improve the overall security culture within an organisation.
“Cyber Security is everyone’s responsibility”
Federal Bureau of Investigations5