Ransomware: Healthcare Organizations Cannot Afford to Be Unprepared

I had just typed the last word of a new ISACA publication on governance of enterprise information technology for healthcare environments when today’s news on the National Health Service (NHS) ransomware attack broke.

As we now know (as of the time of this writing):
•  At least 16 UK National Health Service (NHS) trusts are affected, as well as unspecified other UK government departments and agencies
•  The malware used has been identified as “Wanna Decryptor,” which is preventable by some forms of anti-malware.
•  The action of the malware is to encrypt desktop-based files and position a ransomware message on the desktop and as a readme file.

The interruption of basic services such as email and network-dependent telephony (VOIP) can be devastating in healthcare environments. Targeted healthcare providers are particularly vulnerable to ransomware attacks. This is especially concerning, because according to ISACA’s global State of Cyber Security 2017 study, just half (53 percent) of organizations have a process in place to deal with ransomware attacks.

Most cyber attacks rely on basic deficits, such as not locking out administrative access, running unpatched operating systems or running ineffective anti-malware products.

My takeaway is this:

  • Organizations cannot afford to be out of touch with basic cybersecurity requirements. It is reported that many of the impacted systems were running operating systems that were no longer supported by their manufacturer, but were still connected to networks and managing email with no compensating controls.
  • Underinvestment in basic cybersecurity is a massive false economy. There is a danger that if budgets are looked at in silos, it can appear cheaper to leave vulnerable technologies in place without considering the huge cost impact of the operational interruption.
  • Some newer forms of anti-malware are now over 99 percent effective. Newer forms of anti-malware, some of which can also run on top of or alongside older anti-virus solutions, can now identify and block over 99 percent of malware, including polymorphic forms they have never seen. They do this by using a basic form of artificial intelligence and machine learning. They can even be configured to completely block power shell scripts for desktop environments.

As I finish this post, the news is still breaking, and the impact of this cyberattack appears to be targeting a much larger number of international organizations.

If you are not getting the traction you need for investment in basic cyber security measures, please use this as a valuable moment in time to give your management a wake-up call.

Raef Meeuwisse, CISM, CISA, Author, Cyber Security

[ISACA Now Blog]

The Vendors of My Vendor’s Vendor … What? … Wait? … I’m Confused?!

It is no secret that vendor management is one of the top security challenges we face today. But what compounds the challenge is not knowing the relationships beyond our direct vendors. What are the vendors of my vendor doing?

I don’t know what I don’t know
The scenario: A recent project was initiated by the business group that would greatly improve our customers’ experience with us as well as streamline internal processes. Great! But, and I know this is common with any organization, the assigned managers involved on the project are not trained in project management and most certainly are not focused on security issues.

We have vendor management report into the risk department so we are fortunate to have security “eyes” on it but, in this case, the vendor did not disclose that additional relationships would be required. It turns out that the additional vendors would be involved in processing funds and documents containing sensitive data. Isn’t that interesting? Now the vendor’s vendor, the one processing funds, has a vendor for backups and is backing up the sensitive data. So, my data is three vendors away and the PMs are shrugging their shoulders.

We were fortunate because we did have time to do our due diligence on those additional third-parties, but we might not be so lucky the next time and could find ourselves in damage control.

Here are three actions that will help with the vendor management security struggle:

  1. Stay close to home. What I mean is focus and hold your direct vendor accountable for the other, now required, vendors. They most likely will resist and say, “You need to do your own due diligence.” I would suggest you respond that part of your due diligence is understanding how they selected that company to partner with and what vetting and security reviews were performed. If they didn’t review the vendor’s security controls, how confident are you in their controls?
  2. Tie due diligence to the money. Require that due diligence be complete before issuing the P.O. If you don’t have ownership over vendor management, this might be a challenge. But write in your vendor management policy the requirement that all due diligence be completed prior to finance issuing the P.O. Project managers will be more motivated to dot the Is and cross the Ts if they know that the project could be delayed.
  3. Follow the guidance. Whether or not you’re in a regulated industry, modeling your vendor management program off guidance from large agencies with a breadth of experience will make for a stronger structure. At the core of this guidance is governance. And make sure that whatever risk you assign to your vendors, you communicate it to management and the board.

Brian Nesgoda, CISSP, SVP Risk Management/CIO

[ISACA Now Blog]

Data Loss Threatens M&A Deals

One of the most popular breakout sessions at Evolution17 featured a great merger and acquisition (M&A) scenario: Midway through the deal, critical information leaks, devastating the value of the deal. How can you figure out how much info leaked—by whom and to whom?

Here’s why that storyline was so riveting: 2016 saw more than $3.5 trillion in M&A deals. And the vast majority of those deals revolved around valuations of intellectual property (IP), which today makes up about 80 percent of a typical company’s value. If you’re a buyer organization, consider these questions:

  • Are you aware of all the IP within the target company?
  • Can you be sure all this IP will come with the deal?
  • Can you be certain it won’t leak to a competitor?

Data loss is a growing M&A problem
For most buyers, the answers to the questions above are no, no and no. This lack of visibility and security for the very assets a company is buying is startling, and it’s increasingly impeding the success of M&A deals. A 2016 survey of dealmakers found that about three in four M&A deals end up getting delayed—sometimes indefinitely—by data loss. Those that eventually get back on track often end up hobbled by missing data. Experts say this is a big part of the reason that 80 percent of M&As fail to achieve their potential or expected value.

M&A amps up the insider threat
Data loss is increasingly common in M&A for the same reason it’s increasingly common throughout the business world: More than half of all enterprise data now lives on endpoints, beyond traditional visibility and security tools centered on a network drive or central server. If the target company can’t see what its employees are doing with data on their laptops and desktops, then a potential buyer has near zero visibility. Couple that with the unique circumstances of an M&A deal and you’ve got a much higher risk of insider data theft. Laid-off employees freely take their endpoint data—sometimes for personal gain, other times just to sabotage their former employer. Those that do stick around tend to feel little loyalty toward their new company, lowering their inhibitions toward selling or taking data for personal gain.

There’s a better way to protect IP during M&A deals
IP is what an acquiring company is buying—the info that is critical to the value and competitive advantage gained through a deal. To make the most of an M&A opportunity, buyers need a better way to collect, protect and secure all data living on a target company’s endpoints—before, during and after a deal. Fortunately, with the right tools, a buyer can gain complete visibility of all endpoint data, take control of valuable IP and drive a deal to its most successful outcome.

Don’t let data loss sink an M&A. Read our new white paper, Best Practices for Data Protection During Mergers and Acquisitions.

Jeremy Zoss, Managing Editor, Code42

[Cloud Security Alliance Blog]

Three Reasons Why Cybersecurity Certifications are Essential

Other than a college degree, how can you validate your knowledge and skills? Certifications represent a way for professionals to validate their knowledge and expertise, as well as a path for continued education and professional development.

But what about value? Why are cybersecurity certifications essential today? What is the value of a cybersecurity certification?

Proves Your Worth
According to the 2017 (ISC)² Global Information Security Workforce Study (GISWS), when respondents were asked for the reasons why their organization requires staff to have information security certifications, employee competence was the most common answer. You can spend years working to prove your knowledge, but a third-party validated measure of competence displays your expertise (i.e., your worth) to your employer, colleagues and peers in your network. Not only do certifications require the testing of one’s knowledge and skillsets, but many certifications also require continuing professional education credits to ensure that the learning process doesn’t stop once certification is obtained. Certification also proves a candidate’s commitment to their respective profession – if they are dedicated enough to study for a lengthy exam and go through the entire certification process, that exemplifies commitment.

Instant Street Cred
Certifications are often difficult to obtain. Many people spend hours, weeks, even months studying for certification exams. When your managers and colleagues know that you’ve been validated by a third-party organization as having certain knowledge and skills by passing a tough exam, you earn credibility. When hiring managers are making decisions for staffing, 70 percent of GISWS respondents said it was at least somewhat important that the candidate has information security certifications. When asked if their organization requires its IT staff to have information security certifications, 40 percent said yes.

Catapults Your Career
Once you’re hired, you’ll probably start to think about career advancement and how to get to the next level. As part of the GISWS survey, respondents who hold certifications were asked how relevant their current certifications are to their potential career advancement. An incredible 90 percent of respondents said they are at least somewhat relevant. Members of (ISC)² (certification holders) also make a higher average annual salary than those who are not members – $103,000 for members compared to $76,300 for nonmembers. With certain certifications being required to obtain cybersecurity positions, it’s no wonder that they can be the way in the door and up the ladder.

Attaining certifications can be a key component in planning for and building a successful, well-respected career in cybersecurity. Certifications will show your value as a cybersecurity professional by helping to prove your worth as an employee, show street cred as a team member, and catapult your career, setting you up for a lifetime of success.

Validate your expertise and show your boss you have what it takes to protect your organization with a globally recognized (ISC)² certification. Choose which certification is right for you and download The Ultimate Guide.

[(ISC)² Blog]

What You Need to Know About Changes to the STAR Program

The CSA recently announced that the STAR Program will now allow a one-time, first-year only, Type 1 STAR Attestation report. What is a Type 1 versus Type 2 examination and what are the benefits for starting with a Type 1 examination?

Type 1 versus Type 2
There are two types of System and Organization Control (SOC) 2 reports, Type 1 and Type 2. Both types of reports examine a service organization’s internal controls relating to one or more of the American Institute of CPAs’ (AICPA) Trust Services Principles and Criteria, as well as the Cloud Security Alliance’s (CSA) Cloud Controls Matrix (CCM). Both reports include an examination on the service organization’s description of its system.

A Type 1 report examines the suitability of the design of the service organization’s controls at a point in time, also referred to as the Review Date. A Type 2 report examines not only the suitability of the design of controls that meet the criteria but also the operating effectiveness of controls over a specific period of time, also referred to as the Review Period.

In Type 2 examination, the auditor is required to perform more detailed testing, request more documentation from the organization, and spend more time performing a Type 2 examination than with a Type 1 examination. The additional documentation and testing requirements can put a greater strain on an organization and require more resources to complete the audit.

A service organization that has not been audited against the criteria in the past may find it easier to complete a Type 1 examination during the first audit as it requires less documentation, less preparation, and the organization can respond quicker to gaps noted during the examination.

The cost for a Type 1 examination is less than for a Type 2 examination because the examination testing efforts are less than what is needed for a Type 2. Additionally, fewer organization resources will be utilized for a Type 1, resulting in additional cost savings.

If the service organization, or specific service line or business unit of the organization, was recently implemented, the organization would have to not only ensure that controls were put in place to meet the criteria, but also ensure the controls have been operating for a certain period of time prior to completing a Type 2 examination. In this situation, there would not be enough history or length of time for a service auditor to perform a Type 2 examination. A Type 1 examination would allow for a quicker report rather than waiting for the review period in a Type 2 examination.

Benefits of a Type 1
There are several benefits to starting with a Type 1 report that include:

  • Quicker report turn-around time and STAR Registry
  • Shorter testing period
  • Cost efficiencies
  • Easier to apply to new environment or new service line

An organization might be trying to win a certain contract or respond to a client’s request for a STAR Attestation in a short period of time. A Type 1 examination does not require controls to be operating for a period of time prior to the examination. Therefore, the examination and resulting report can be provided sooner to the service organization.

Starting with a Type 1 report has many benefits for a first-year STAR Attestation. The organization will find this useful when moving to a Type 2 examination in the following year.

It is important to note, though, that Type 1 shall be considered just as an intermediate and preparatory step prior to achieving a Type 2 STAR Attestation.

Debbie Zaller, CPA, CISSP, PCI QSA, Principal, Schellman & Co., LLC

[Cloud Security Alliance Blog]

English
Exit mobile version