4 Infosec Resolutions For The New Year


Don’t look in the crystal ball, look in the mirror to protect data and defend against threats in 2015.

As the year draws to a close, security gurus begin the annual ritual of predicting what horrors will befall us after the calendar turns from December to January. While this gloomy approach ignores the potential for actually improving infosec, it also sidesteps the opportunity for reflection. The truth is, any security incidents that will occur in 2015 will be the result of lingering errors created in the past. Here are four dangers that will continue unless we resolve to act now.

Legacy code, present danger
Just because some bit of code has been used since the dawn of time does not mean it has been thoroughly vetted. In the past few months, we saw years-old (or even decades-old) vulnerabilities unearthed in the form of the Heartbleed,Shellshock, Poodle, and Unicorn bugs. It’s nearly impossible to predict where the next of these ancient vulnerabilities will surface, but it’s a fair bet that you’ll find them wherever there is a piece of code that has been used by millions and has been largely unchanged for years. In 2015, security teams should resolve to give that legacy code a thorough review.

Expedience at the expense of security
Last year was not a good one as far as major payment card security goes. It brought us breaches at Neiman Marcus, Michael’s craft store, P.F. Chang’s, Dairy Queen, Jimmy Johns, Goodwill, Staples, and Home Depot, among others. Predicting another year full of yet more breaches seems like something of a no-brainer. In the largest of these breaches, at Home Depot, company officials had been warned about flaws in their security. Instead of taking action, they chose expediency over security, and they are now paying the price of millions of unhappy customers. The causes of all these breaches are all basic security concerns: loss of login credentials, lack of adequate network segmentation, absence of encryption, use of default device passwords, and disabling of security features. While we can’t say better security would have prevented all of these events, we can resolve to make breaking-in far more difficult for the attackers.

Malware: Everything old is new again
The headlines may be all about the newest and most unusual malware, but the majority of what affects the average person is still the same old, boring stuff that has been around for ages. Infecting computers usually doesn’t require the newest vulnerabilities, and it doesn’t necessitate the stealthiest tactics. The most effective threats often still rely on old-fashioned social engineering, because criminals are not going to pull out the metaphorical “big guns” if they know they can get their payday with tactics that are simply “good enough.”

Right now, the cost of entry for malware writers is exceedingly low, and the return on investment is very high. Until that equation changes, we’re not likely to see much of a decrease in malware in particular or cybercrime in general. The coming year is likely to bring some improvements, but in fits and starts rather than as a complete sea change. Let’s get that process moving faster.

Looking back to look ahead
For most people, technology is a new and often confusing thing. Many organizations are going digital fairly reluctantly, choosing only the easiest and most user-friendly aspects to deploy. Historically, this has led to a general perception that information security is a drag on innovation — not an essential feature of the technology infrastructure. As people become more informed, as security products become easier to implement, and as more people become aware of the costs of leaving themselves open to attack, this situation is likely to evolve for the better.

The good news is that old problems, by and large, already have solutions: All we have to do is recognize and implement them. There are a lot of things that we can all do to improve our security. Once we remove the low-hanging fruit, we will make it more costly and difficult for criminals to do their jobs. That’s not to say that removing that fruit will be an easy task — in fact, it’s far more difficult than our current policy of worrying about the most challenging (one might even say “advanced, persistent”) fruit.

It is my hope that in the coming year, the brilliant minds in this industry will reflect on what we can do to make security simpler and more approachable for the general public.

What are your infosec resolutions for 2015? Please share them in the comments.

Lysa Myers began her tenure in malware research labs in the weeks before the Melissa virus outbreak in 1999. She has watched both the malware landscape and the security technologies used to prevent threats from growing and changing dramatically. Because keeping up with all this change can be difficult for even the most tech-savvy users, she enjoys explaining security issues in an approachable manner for companies and consumers alike. Over the years, Myers has worked both within antivirus research labs, finding and analyzing new malware, and within the third-party testing industry to evaluate the effectiveness of security products. As a Security Researcher for ESET, she focuses on providing practical analysis and advice of security trends and events.

[DarkReading]

Don’t Miss A Single Threat Intelligence Update from Unit 42!

Unit 42 is the Palo Alto Networks threat intelligence team. Made up of accomplished cybersecurity researchers and industry experts, Unit 42 gathers, researches, analyzes, and provides insights into the latest cyber threats, then shares them with Palo Alto Networks customers, partners and the broader community to better protect enterprise, service provider, and government computing environments.

You can now have up-to-the-minute threat intelligence updates from Unit 42 delivered right to your inbox, as they’re posted. Click here to subscribe.

Regular research analysis is posted to the Unit 42 threat intelligence blog. Unit 42 also publishes whitepapers examining, in detail, threats to mobile device ecosystems, APTs, malware attack patterns and other subjects crucial to any security practitioner or business executive’s understanding of the current cyber threat landscape.

Recent Unit 42 whitepapers include:

And here are some recent highlights from the Unit 42 threat intelligence blog:

 

Unit 42 team leads will lead a track at Ignite 2015, where they will discuss all your toughest security challenges and work out ways to help you solve them. Register now to join Palo Alto Networks in Las Vegas, March 30-April 1, 2015.

 [Palo Alto Networks Blog]

 

Get An Enterprise Risk Report and Learn What’s Really Happening On Your Network

The sheer volume of malware, application vulnerabilities and advanced persistent threats makes it difficult for security teams to make the right decisions when it comes to protecting their networks. Wouldn’t it be great if there were a way to understand exactly who and what have been trying to get onto your network, and where threats are coming from?

Well, there is.

Palo Alto Networks Enterprise Risk Report (ERR) provides actionable security intel that allows you to make targeted recommendations based on an analysis of your actual network traffic. It helps you better understand the strengths and weaknesses of your current cybersecurity posture and serves as an effective tool for showing management exactly what your network is up against and how to minimize your organization’s exposure to risk.

Get your customized Enterprise Risk Report underway by registering here.

Your custom report will include:

  • Total scope of unknown threats observed
  • Percent of malware undetected by top AV solutions
  • Malware prevented by Palo Alto Networks WildFire™
  • Application threat vectors and malicious file types
  • Additional threat intelligence for your organization

[Palo Alto Networks Blog]

Ten 2015 Security Risk Lessons from 2014 Breaches

During this time of year, we start to see the lists of top 10 breaches and predictions for the next year. How accurate are these predictions anyway? Did anyone predict that we would have a social media breach (Snapchat) the first week of 2014? Or that the string of breaches at major retailers such as Michaels, P.F. Changs, Urban Outfitters, Jimmy Johns, Ebay, Home Depot and others would have happened so soon after the prominent late 2013 Target breach exposed information on 110 million individuals? Or that one of the largest healthcare breaches involving 4.5 million patients across 206 hospitals would be compromised due to one of the media-highlighted vulnerabilities (Heartbleed, Bashbug, Poodle, etc.)?

As if these breaches were not enough, information stored in faraway online cloud places, such as Apple iCloud, made us pause and wonder where the right places were to store our personal data. Banking organizations are continually attacked, but who would have predicted that JP Morgan Chase, an organization that invests US $250 million annually on security and employs 1,000 security professionals, would have been breached?

Target hired a new CEO, CIO and CISO, each from outside of the company, as a result of the headline-grabbing breach. While there have been multiple retailers coming clean with announcing breaches in the aftermath, Target has been the unfortunate 2014 security-investment-conversation-starter for many organizations at the board of directors level. Target must be breathing a sigh of relief these days with the recent press surrounding the Sony Pictures breach. The focus has now shifted from a retailer attack that was compromised through a third party to nation state breaches and their prevention and/or risk reduction, freedom of speech and appropriate government response.

And let’s not forget that there were many news articles expressing concern about the February Sochi Olympics in Russia. Either we had great defenses and cyber intelligence that made this a non-event, or it was just thata non-event. Will we ever really know? The FBI regularly notifies companies of breaches. There were more than 3,000 in 2013a number that we could have predicted would increase in 2014. Did it?

Would we have predicted that, according to the Identity Theft Resource Center (ITRC), approximately 750 breaches exposing more than 81 million records (56 million attributed to Home Depot) would be reported by mid-December 2014? And what about the breaches that are not required to be reported by legislation or the cases where breaches were reported, but the numbers exposed were simply unknown? Should we expect more or less next year?

Lessons learned
While some of these questions are difficult to answer, there are some clear takeaways for CISOs, auditors and information security professionals:

  1. Information security will remain in the news as a frequent event. The breach of Sony Pictures has implications for how companies should respond to the breach (such as Sony’s pulling the release of the Interview due to the threats received), and how governments should respond to breaches. Expect political posturing and rhetoric within the US and between the US and North Korea for at least the first half of 2015. Discussions will shift to how nation state attacks should be dealt with by private enterprises and what is the cybersecurity responsibility of government.
  2. There should be an increased push for NIST Cybersecurity Framework adoption. While released in early 2014 in response to the President’s executive directive, this voluntary framework could receive an increased government desire to move the framework beyond voluntary. ISACA’s COBIT is a key information reference in this framework, and a guide existsto help you implement the NIST framework using COBIT.
  3. Vendor risk management should increase. The Target breach highlighted the importance of appropriately segregating networks and understanding vendor security practices. More attention will be placed on vendors, particularly cloud providers, with requests for SSAE16 SOC2, ISO27001 certification, or other independent assurance.
  4. Incident response is as important as prevention. While the details of how the JP Morgan Chase breach occurred are still being investigated, it is clear that significant spending goes so far, and that every organization needs to ensure that they can adequately respond to a breach in a timely manner.
  5. Public relations departments will continue to minimize the events. Unless the breach is in tens of millions of records or individuals, they will not be sustained by the news media. Expect to see these “small” breaches in the single-digit millions minimized by their respective organizations.
  6. Encrypt external storage and hold the keys. With cloud providers maintaining the data, expect to see more attacks focused on these organizations. Small Software as a Service (SaaS) providers may be particularly vulnerable.
  7. Data location will remain a top privacy issue. As countries do not trust each other with obtaining access to data without going through a lawful process, the preference for countries will be to have the data stored regionally (e.g., Canada, USA, European Union, Asia Pacific) and privacy laws will be promoted to retain information within country.
  8. Security professionals will need to embrace mobile technology. With smartphone availability becoming ubiquitous concentrated with several top players, tablet shipments surpassing desktops, and an appetite for BYOD, actions must shift from BYOD avoidance to mobile embracement and ensuring secure mobile code development and administration.
  9. Blocking and tackling has never been more important. Organizations must up the internal bar before the breach happens and invest in technologies that support COBIT 5 for security, NIST Cybersecurity Framework, ISO27001 Certification, SANS Top 20 Critical Controls, OWASP Top 10 and others. Running large organizations with one to two full-time security professionals (outside of identity and access management staff) can no longer be the model. A surprising number of large organizations run very lean with security leadership staffing. End-user behavior must be elevated with security awareness training and phishing simulations, as many of the breaches today start with malware introduced by phishing an end user.
  10. Security skills shortage will continue and recruiters will need to be creative. Some accounts have indicated a near-zero information security professional unemployment rate. Organizations may need to turn to managed security service providers and developing interested internal professionals in security practices to provide assistance. Breaches have heightened awareness of the need, which in turn reduced the supply of available talent. This is one key area that ISACA’sCybersecurity Nexus (CSX) is addressing. Through CSX, ISACA aims to help companies develop their security workforces and help individuals develop or advance a career in cybersecurity.

Next year, we will have a new list of companies that have experienced major breaches. Odds are, one or more of the top 10 takeaways listed above will be involved. As we move into 2015, each of us needs to decide for our organizations which areas we will focus on most. To reduce the risk that we will not be the result of the latest comedy of errors, in the modified words of well-known comedian Larry the Cable Guy, we need to just “Git-R-Done.” I don’t care who you are, having a breach is not funny.

Todd Fitzgerald, CISA, CISM, CRISC, CISSP, CIPP/US, CIPP/E, PMP
Global Director Information Security, Grant Thornton International, Ltd.

[ISACA]

What’s Your Favorite Cybersecurity Book? Maybe It Should Be In the Canon

The Cybersecurity Canon is official, and you can see our website here. We modeled it after the Baseball or Rock & Roll Hall-of-Fame, except for cybersecurity books. We have 20 books on the initial candidate list but we are soliciting help from the cybersecurity community to increase the number to be much more than that. Please write a review and nominate your favorite – we’re actively soliciting your feedback!

The Cybersecurity Canon is a real thing for our community. We have designed it so that you can directly participate in the process. Please do so!

The members of our Cybersecurity Canon committee have been submitting reviews of Canon-worthy books throughout the past year. Here are just some of the titles that have entered the discussion since we began publishing reviews in November 2013:

 

We will celebrate the Cybersecurity Canon and make a new induction at Ignite 2015. Register now to join us March 30-April 1, 2015 in Las Vegas.

[Palo Alto Networks Blog]

English
Exit mobile version