Security Headlines: Hacking ATMs, HBO and more


ATMs, HBO, democracy … what can’t be hacked? Here are the top security headlines for the week of July 31, 2017:

[(ISC)² Blog]

Five Questions With Jigsaw CEO and CSX North America Keynoter Jared Cohen

Editor’s note: Jared Cohen, CEO of Jigsaw (the successor of Google Ideas), will deliver the opening keynote address at CSX North America 2017, which will take place 2-4 October in Washington D.C. Cohen, co-author of the New York Times best-selling book “The New Digital Age,” recently visited with ISACA Now about the cyber security skills gap, advancements in machine learning and his extensive world travels. The following is an edited transcript:

ISACA Now: How did Jigsaw come to be?
I was hired to Google in 2010 to build out a new division of the company called Google Ideas. I had gotten to know the CEO while I was still advising Hillary Clinton and we took a trip to Iraq together. It was a transformative trip because we both realized that the vast majority of future Internet users still had not yet come online, and companies like Google needed to be better prepared for that ubiquitous moment. I ran it as a think tank for many years and then a product organization. When the company restructured to become Alphabet, Jigsaw became the letter “J” in the Alphabet suite of companies. We are an engineering organization working on the cutting edge of AI, cyber security, and tackling some of the toughest global challenges with technology.

ISACA Now: What type of reaction have you received to The New Digital Age?
The New Digital Age captures the last mile of an access revolution that has been playing out for the past decade and a half. It is a book about the advent of technology and how it will impact war, terrorism, interactions between states, and so many other geopolitical trends. So much of what we wrote about and predicted in that book has happened faster than expected. So, I suppose the most common reaction I get from people is whether or not I’m surprised that the predictions came true as quickly as they did. I am.

ISACA Now: Which emerging technologies do you foresee being most impactful in the next 3-5 years?
This is a clear answer. The advancements in machine learning are going to be the most important innovation that defines the next decade. We are entering a ubiquitous moment where technology is everywhere and we are all mass producing data at record speed and volume. The combination of data and even bigger data, coupled with the ability to process that data through multiple machines and build deep neural nets, means that we will be able to build machine learning models to tackle challenges never before possible. Eventually we will reach something called inventive AI, where we train a machine on a particular type of data that enables it to tackle a broader set of challenges. This will have a profound impact on everything from security to health.

ISACA Now: The cyber security skills gap is well-documented. What are your thoughts on the best ways to influence more young people to pursue careers in cyber security?
Young people are ambitious and often want to work on the next zeitgeist. It doesn’t get more of the next zeitgeist than cyber security. It is a barren field that is ripe for innovation. It is also a field that bridges the technical and non-technical disciplines. It’s a skill set that will be desired by every sector, discipline and company. If every country in the future is also a technology company, then it is only as good as its security.

ISACA Now: You’ve traveled to more than 110 countries in your role advising two US Secretaries of State. How has all that travel influenced your view of the transformative potential of technology, from a global perspective?
I’ve seen first-hand how technology is transforming every society around the world, from the most connected to literally the least connected. What I’ve also learned is that the physical world shapes the digital world and vice versa. Every technology we build today has global implications. It expands the digital topography that complements the physical world we know. If all people are splitting their time between both worlds, it also means that the challenges of the physical world are spilling over online. In order to build technology responsibly and in a way that will have impact, we need to make sure we don’t lose the human intelligence side of things. For me, this means showing up places and asking questions, meeting people, and going to countries and places I haven’t visited.

[ISACA Now Blog]

Is the Cloud Moving Too Fast for Security?

In February 2017, a vulnerability in Slack was discovered which had the potential to expose the data of the company’s reported four million daily active users. Another breach in February on CloudFlare, a content delivery network, leaked sensitive customer data stored by millions of websites powered by the company. On March 7, the Wikileaks CIA Vault 7 exposed 8,761 documents on alleged agency hacking operations. On June 19, Deep Root Analytics, a conservative data firm, misconfigured an Amazon S3 Server that housed information on 198 million U.S. voters. On July 12, Verizon had the same issue and announced a misconfigured Amazon S3 data repository at a third-party vendor that exposed the data of more than 14 million U.S. customers.

That’s at least five-major cloud application and infrastructure data breach incidents for 2017, and we’re only in July. Add in the number of ransomeware and other attacks during the first half of this year and it’s clear the cloud has a real security problem.

By now, most everyone recognizes the benefits of the cloud; bringing new applications and infrastructure online quickly and scaling it to meet ever changing business demands. Although highly valuable for the business side, when security teams lose control over how and where new services are implemented, the network is at risk and subsequently, so is their data. The balance of allowing businesses to move at the speed of the cloud and maintain the needed security controls is becoming increasingly difficult. With the spike in data exposures and breaches, it shows that security teams are struggling to secure cloud use.

The Slack breach is a great example at the application-level. Slack is simple to use and implement, which has driven the application’s record-breaking growth. Departments, teams, and small groups can easily spin up Slack without IT approval or support, and instances of the application can spread quickly across an organization. Although Slack patched the vulnerability identified in February before any known exposure occurred, if it were hacked, the attacker could have had full access and control over four million user accounts.

In the Verizon situation, a lack of control at the infrastructure level is what caused so many of their customers to be exposed this month. When servers can be brought online so easily and configured remotely by third-party partners, the right security protocols can be missed or ignored.

As more businesses move to the cloud and as cloud services continue to grow, organizations must establish a unified set of cloud security and governance controls for business-critical SaaS applications and IaaS resources. In most cases, cloud providers will have stronger security than any individual company can maintain and manage on-premise. However, each new service comes with it’s own security capabilities, which can increase risks because of feature gaps or human error during configuration. Adding additional encryption and policy controls independently of the vendor, is a proven way for organizations to fully entrust their data to a cloud provider without giving up complete control over who can access it while also making sure employees are compliant when using SaaS applications. These controls allow businesses to move at the speed of the cloud without placing their data at risk.

The reality is that threats are increasing in frequency and severity. The people behind attacks are far more sophisticated and their intentions far more sinister. We, as individuals and businesses, entrust a mind-boggling amount of data to the cloud but there doesn’t exist today a way to entirely prevent hackers from getting through the door at the service, infrastructure or software provider. Remaining in control of your data that traverses all the cloud services that you use is the safest thing you can do to protect your business. Because, in the end, if they can’t read it or use it, is data really data?

Doug Lane, Vice President/Product Marketing, Vaultive

[Cloud Security Alliance Blog]

Cyborg’ Society Necessitates Governance, Compliance and Security Vigilance

Today’s security professionals face a daunting reality as the attack surface swells and cyber criminals prey upon the speed at which new devices are hurried to market.

“As soon as we put out a device, there’s going to be somebody who starts tinkering with it and finding vulnerabilities,” said Kimberlee Ann Brannock, senior security advisor with HP. “That’s just a fact.”

Brannock, an ISACA member, presented this week at Black Hat USA on how organizations can leverage governance, compliance and security to protect themselves. She said a comprehensive, multilayered approach is especially critical given powerful trends such as accelerated innovation and globalization. “I’m a huge proponent of defense in layers, security in layers,” Brannock said. “One-dimensional does not work.”

Sound governance and security programs also help drive compliance, she said.

“When you have all of these different layers and all of these different strategies, and you bring all of those together, one of the amazing things is you start to develop security intelligence,” Brannock said. “And then because you’re documenting your processes, you’re documenting your procedures, you’re doing your assessments, you’re getting the evidence from that, that helps you to demonstrate compliance as well.”

Brannock recommended three actions enterprises should take to mitigate their risk:

  1. Focus on end-to-end security. Include security in considerations when evaluating potential IoT product purchases, such as printers. (The presentation began with a video featuring an organization having its network compromised through a malware attack on an insecure printer).
  2. Deploy strong administration tools. Avoid using system defaults for user names and password purchases. “It is amazing how many sophisticated organizations that have spent millions of dollars on their infrastructure, on their end points and their devices, they have the default settings,” Brannock said.
  3. Do not share access. Account access should not be shared with anyone, and secure password practices should be emphasized with those who do have access.

Brannock also encouraged organizations to adopt applicable cyber security frameworks, conduct thorough risk assessments and be mindful of firmware security in their devices.

“Every device that we can think of is hackable in one way or another,” Brannock said. “As security professionals, as IT professionals, we need to be aware, and we need to get the conversation started about it.”

When organizations put governance policies and procedures in place, Brannock said it is important to avoid shrugging off shortcomings that might surface.

“As an organization, you want to tell people what you’re wanting to accomplish and why, and how to do it,” Brannock said. “But you also want to make them accountable … so there has to be consequences.”

Brannock shared industry statistics about the mounting use of data and devices on an everyday basis, leading to a corresponding spike in security threats.

“We are plugged in all the time,” Brannock said. “We carry around a device all the time. We are cyborgs – whether we acknowledge it or not, we are. So, with this digital and physical world colliding, we need to be at the ready to address it from a security standpoint.”

[ISACA Now Blog]

Not Just Smart Cities – A Smart Community Ecosytem

Much consideration has been given to the creation of smart cities in the connected devices era, but Gary Hayslip thinks that security professionals should broaden their perspectives.

Hayslip, CISO of Webroot and an ISACA member, spoke of a wider ecosystem that must be accounted for during a presentation this week at Black Hat USA 2017. The session, titled “Protecting Tomorrow’s Smart Community … Today,” was presented together with Tom Caldwell, Webroot’s senior director of engineering.

“I look at the smart community ecosystem as more than just cities,” Hayslip said. “I look at it as also being corporations. I look at it as being small mom and pop stores. I look at it as even being users now who are downloading and using so many different types of IoT devices. It is a full ecosystem.”

The explosion of connected devices means more and more technologies and networks are becoming intertwined, each introducing new risk and control considerations. One of the most important steps organizations should take is assessing which devices are utilizing legacy systems that could pose major security risks.

“I’ve never run into a network that is all brand new,” Hayslip said. “You’re going to have legacy. It’s just one of those things that you’ve got to deal with. So, if you’ve got legacy, how are you handling it? Are you segmenting it and putting it aside, or is it intertwined with what have on your corporate network? If you can’t segment it, what controls can you put in place to get visibility so you can catch those anomalies?”

Connected devices also are challenging CISOs with the erosion of the physical perimeter.

“I look at my perimeter as basically on my employees’ laptops, on their phones, mobile,” Hayslip said. “From a risk perspective, as a CISO, how do I go in and really understand where my data’s at and how my networks are being used?”

Given the expanding threat landscape, Hayslip said organizations must face the reality that they are going to deal with breaches, and put their emphasis on reducing their impact and moving forward with business. To do so, Hayslip said security leaders need to understand the full life cycle of the organization’s data, not just who is using it and whether it is being backed up.

Hayslip also highlighted the importance of effective communication with third-party vendors so that critical information is swiftly shared when either side is slammed with a breach.

“Is that happening within an acceptable time frame and not 48 hours later?” Hayslip said. “I mean, 48 hours in the life of cyber, you can rule the world in 48 hours.”

Emphasizing the complexity of today’s security ecosystem, Hayslip urged CISOs to draw upon each other’s experiences on these and a variety of other topics, such as how to contend with various cloud environments, which vendors are worth pursuing and how to navigate budget constraints.

Caldwell’s portion of the session dealt largely with the ramifications of AI and machine learning, dissecting use cases involving threat intelligence, endpoint protection and behavioral analytics. As promising as machine learning may be, Caldwell said “the human feedback loop” remains indispensable in ensuring the technology is implemented effectively.

[ISACA Now]

English
Exit mobile version