Ransomware Q&A With Garry Barnes

ISACA Now recently had the opportunity for a Q&A with Garry Barnes, CISA, CISM, CGEIT, CRISC, MAICD and ISACA International Vice President. Barnes is practice lead, Governance Advisory at Vital Interacts (Australia). He has more than 20 years of experience in information and IT security, IT audit and risk management, and governance, having worked in a number of New South Wales (NSW) public sector agencies and in banking and consulting.

Who is deploying ransomware?
Ransomware is developed and deployed by cybercriminals looking primarily to gain financial rewards. Some ransomware will encrypt your files preventing you from gaining access while earlier types locked your computer by displaying pornography or other images. The ransomware contains a demand payment to obtain the key to unlock your system. These payments are routed through untraceable digital currencies, via SMS, or simply using cash transfer systems.

In its Q1 2015 Threat Report, McAfee cited a new family of ransomware, CTB-Locker, leading to a rise in attacks. This malware is distributed in numerous ways, and its payload is hidden in layered zip files. According to McAfee, it was supported by an “affiliate” program, enabling it to be easily added to phishing campaigns.

Who are they targeting?
Ransomware developers are targeting the desktop and Android phone devices of both individuals and organizations in North America and Europe, where there is a higher likelihood of the ransom being paid. They use a variety of techniques to deliver their payload, including email and web pop-ups. Recently ransomware has been detected in content management systems such as Joomla! and WordPress. The SynoLocker strain of ransomware targets network storage devices.

What is an organization’s chance of suffering this type of attack?
The odds are pretty high that a ransomware attack will occur. ISACA identified ransomware as one of the Five Cyber Risk Trends for 2016, noting that the instance of victimized enterprises—most of them small businesses—agreeing to make ransomware payments increased from 2.9 percent in 2012 to 41 percent in 2015.

What can be done to prevent it?
There are a number of steps you can take to minimize your risk. Technical controls are important, and security awareness is also key. Users need to be vigilant not to click on links, remain cautious with links and attachments in unsolicited emails, avoid clicking on pop-ups on web sites, and have up-to-date antivirus software.

Desktop architecture should include:

  • Reputable A/V to scan for malicious payloads
  • Firewalls to prevent unwanted services including blocking Tor
  • Periodic back up of both data and software
  • Disconnection of the backup storage device after successful backup
  • Patching of operating systems and applications
  • Use of a web pop-up blocker to prevent clicking on infected ads
  • Use of cloud backup may also help

What should be done once your organization has been hit?
A quick response by the affected user is needed, hence the value of security awareness training. Once hit, an organization should activate its incident response process. This would include alerting the service desk so they can contain the impact and prevent others in your business from falling victim. They will need to initiate recovery of data from backup and restoration of the operation system and applications from a reliable copy.

Garry Barnes, CISA, CISM, CGEIT, CRISC, MAICD, past ISACA Board director

[ISACA Now Blog]

Cultivating and Retaining IT Audit Talent

People with deep technical skills are in high demand, so internal audit needs to take extra care to ensure the profession is attracting and retaining the right people. According to PricewaterhouseCoopers’ 19th annual global CEO survey released earlier this year, 72 percent of CEOs consider the availability of key skills a threat to their organization’s growth prospects.

As we discussed in New Orleans at the IT Audit Director Forum—part of ISACA’s North America CACS conference—there are steps companies can take to ensure IT audit develops the quality workforce needed to thrive amid this evolving landscape.

Work With Universities to Strengthen Workforce
The nature of audit is becoming more real-time and continuous, and less forensic. A number of factors have impacted the speed at which universities have been able to prepare their students for the effects of technology and automation on the IT audit profession.

That is problematic as the day is fast-approaching when professionals who lack broad, technical knowledge and skills around data analysis will be unable to successfully function in the field. This is especially true because the more organizations rely upon technology, the more necessary it becomes to tap into technology when auditing them.

Universities might be receptive to weaving more data analysis, cybersecurity and technical prep into their curriculums—they may just need some additional support and guidance from alumni and business leaders to keep pace with the changing demands of the profession.

Take Compensation Seriously—and Not Just the Dollars
Organizations cannot take a knife to a gunfight when it comes to offering the competitive compensation packages needed to land talented technology professionals. As organizations seek skilled IT auditors equipped for the modern landscape—and greater demands are placed on IT audit professionals—compensation must reflect the reality that talented candidates will have plenty of options.

Additionally, HR departments need to place an emphasis on going beyond salary when attracting talent. Particularly among millennials, other perks such as flexible work schedules, the ability to work remotely and even casual workplace attire are becoming increasingly meaningful.

At PwC, a flexible dress policy was recently implemented, allowing employees to wear jeans at the office when they are not meeting with clients. In the traditionally buttoned-up world of public accounting, that’s practically a tidal wave of workplace progress, and it’s a sea change many welcome.

Find Sensible Enticements to Encourage Progress
The perception is that internal audit lacks the glamour of other fields tied to emerging technologies. Internal audit needs to overcome that stigma to pull in the tech talent needed to perform at a high level.

Internal audit affords professionals rapid and exciting opportunities to tackle major projects involving high-level influencers. Being open to the idea of quickly giving employees such major responsibilities is worth considering.

Those who enter the job with high technical IQs might soon be ready to take on more senior tasks than was the norm in the past, and recognizing that potential quickly will not go unappreciated by employees. A word of caution, though—the potential downside of giving somebody a task beyond his or her ability is substantial. These judgments are about being open-minded and require a measured, case-by-case approach.

Working across departments to identify quicker paths to promotion as circumstances justify can be another worthwhile way for your organization to retain top talent.

There never has been a more exciting time to be in IT audit. Nothing is becoming less automated or less reliant on technology, so this is a career path with permanence. Still, challenges remain in attracting and retaining quality professionals. Organizations that take inventory of the evolving state of IT audit and are responsive to the priorities of prospective employees will be best positioned to assemble the high-caliber workforces that they need.

A. Michael Smith, Partner, PricewaterhouseCoopers LLP, and Khalid Wasti, Partner,
PricewaterhouseCoopers LLP

[ISACA Now Blog]

Cloud Security Alliance Launches Crowdfunded Cloud Security Management Solution

STARWatch SaaS Application Empowers Organizations to Manage Compliance & Risks Using CSA Standards and Best Practices

SAN FRANCISCO – November 15, 2016 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today announced the launch of its new STARWatch application, a Software as a Service (SaaS) application designed to help organizations manage compliance with CSA requirements. STARWatch delivers the content of CSA’s Cloud Control Matrix (CCM) and CSA’s Consensus Assessments Initiative Questionnaire v3.0.1 (CAIQ) in a database format, enabling users to manage compliance of cloud services with the CSA best practices. CSA is delivering STARWatch using an innovative and heavily discounted crowdfunded model to make this solution accessible to the broadest spectrum of customers.

STARWatch is designed to provide cloud users, cloud providers, cloud auditors and security providers assurance on demand. STARWatch provides users the ability to:

  • Manage all cloud service providers and their own private clouds to assure a consistent security baseline is maintained
  • Build and maintain a CSA Security Trust and Assurance Registry (STAR) entry and provide customers with rapid responses to their compliance questions
  • Perform audits and assessments of cloud provider security
  • Leverage the STARWatch solution database format and technical specifications to integrate its capabilities within their own solutions

During the current open beta period, customers may now purchase a STARWatch license with a discount of up to 70%. The discount will expire at the time of the official STARWatch release on February 13, 2017 at the CSA Summit at the RSA Conference. At that time, STARWatch open beta licenses will convert to a full year license. By acting now, customers will receive 15 months of access to STARWatch at a fraction of the one year license price. More information can be found at https://cloudsecurityalliance.org/star/watch.

“Compliance and assurance are becoming complex matters, but they are critical in building the best cloud computing practices and a trusted cloud ecosystem,” said Daniele Catteddu, CTO for the Cloud Security Alliance. “We created the STARWatch application to assist organizations in managing their compliance with CSA requirements. We’re providing a higher level of assurance and transparency and streamlining the entire compliance process.”

The CSA STAR program is the industry’s most powerful program for security assurance in the cloud and encompasses the key principles of transparency, rigorous auditing, harmonization of standards, with continuous monitoring. Currently there are 228 Cloud Service Providers in the STAR program including STAR Self Assessment, STAR Certification, STAR Attestation and C-STAR Assessment.

For more information on the STARWatch application, please visit https://cloudsecurityalliance.org/star/watch.

About Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products. CSA’s activities, knowledge and extensive network benefit the entire community impacted by cloud — from providers and customers, to governments, entrepreneurs and the assurance industry — and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem.

Contact

Kari Walker for the CSA
ZAG Communications
703.928.9996
kari@zagcommunictions.com

[Cloud Security Alliance Research News]

Augmented Reality has Arrived: Time to Embrace the Opportunities

Whether the business community is ready or not, augmented reality (AR) has arrived, and it only will grow more prominent in the near future.

Consumers – mindful of this year’s Pokémon Go phenomenon – are recognizing AR’s potential benefits, a surefire indicator that the marketplace will respond quickly.

In ISACA’s annual IT Risk/Reward Barometer—a two-pronged survey that examines both consumer and IT/business perspectives—the majority of consumers see clear benefits of AR-enhanced devices in everyday life and work. For now, though, a disconnect exists, as only 21 percent of global business and technology professionals are convinced that the benefits of AR outweigh the risks.

The hesitance of many professionals to embrace AR – technology that superimposes a computer-generated overlay on a user’s view of the real world – is both understandable and predictable since it is still in the early stages. With the emergence of any new technology, the attack surface increases. AR-related privacy and security concerns are legitimate, especially when factoring in a proliferation of Internet of Things (IoT) devices. Concerted attention from device manufacturers and security professionals is a must.

Yet this natural caution must not keep enterprises from keeping up with the competitive landscape. Of critical importance, one in four enterprises has a way to detect pictures, posts and videos tagged or geotagged to their business locations and advertisements. That means there are best practices to learn from as enterprises look to move forward securely while incorporating components of AR.

While the resounding popularity of Pokémon Go alerted consumers and enterprises to the buzz that AR can generate, the potential applications of AR in the workplace are numerous. Adoption figures to be especially swift from a marketing standpoint as organizations learn to leverage AR for signage, social media and other purposes.

Enterprises can realize the benefits of AR and overcome potential barriers through some of the following steps:

  • Extend social media monitoring to AR platforms. Leverage and extend current social media policies and monitoring to augmented reality platforms. Social media is a key source of information for many augmented viewing apps.
  • Consider how AR can improve your business. Training, diagnostics and marketing are three areas with particularly strong potential.
  • Review your governance framework and update your policies. Incorporate use of AR as part of the business into organizational policies and procedures—including BYOD (bring your own device) and privacy policies. 63% of organizations do not have a policy to address AR in the workpalace.
  • Build security into every part of the process. Security is a crucial component of AR initiatives that helps ensure confidence in the data.

While AR is a new concept for many, some industries have drawn upon aspects of it for years, such as the airline industry’s use of flight simulators to train pilots on new equipment. As AR becomes more popular and more affordable, it is inevitable that more industries invest in the technology. Since today’s smartphones are capable of running AR apps, adoption could be swift and even viral, as Pokémon Go demonstrated. According to Slice Intelligence, millennials accounted for more than half the paying population of Pokémon Go during launch week, but now are only 44 percent of buyers as other age groups also gain interest.

Business and technology professionals will become more comfortable with that reality the more that they explore AR. On that front, there is much progress to be made. The IT Risk/Reward Barometer shows that only 3 percent of professionals have used AR applications for business use within the past year and only 16 percent have done so for personal purposes.

The business community will be well-served to accelerate their exposure because consumers have spoken – AR is in demand. Now it is up to security professionals to address the risks so that consumers and enterprises alike can benefit from this promising technology.

Rob Clyde, CISM, ISACA Board Director and Executive Advisor at BullGuard Software

[ISACA Now Blog]

CSX Europe Illuminates Key Cyber Security Insights and Advancements

ISACA’s inaugural CSX Europe conference convened last week in London, and I had the privilege of serving as emcee. During a panel discussion on the second day of the conference, Mark Sayers of the UK’s Cabinet Office discussed the announcement that morning of the UK Government’s £1.9bn investment in a national cybersecurity strategy—a strategy that makes clear the UK’s preparedness for cyber attacks and will include a cyber security skills strategy. Sayers made it clear that organizations like ISACA are extremely important to further the initiative.

The cyber security event left a strong impression on attendees, including several critical takeaways:

•  Collaboration is critical. Intel’s Raj Samani emphasized collaboration and communication to best contend with today’s threat landscape. Professionals on the more technical side need to be able to communicate with business decision-makers and other stakeholders to effectively solve problems. As speaker Aviram Zrahia notes, “one company’s detection become another’s protection.”
•  Internet of Things devices pose new security challenges. Security professionals are capable of preventing attacks, but consumers need to understand that connected devices have security vulnerabilities. Justine Bone, director and CEO, MedSec, presented the findings of ISACA’s new firmware security report, highlighting how easy it is for security to be overlooked when creating IoT devices.
•  New solutions are needed. In closing the conference, technology futurist Simon Moores observed that organisations will no longer be able to handle the scale of cyber threats alone. In many cases, automated, cloud-based solutions involving artificial intelligence (AI) will be part of the solution, though there is no substitute for developing a highly skilled workforce.

The conference also provided another valuable networking opportunity through ISACA’s Connecting Women Leaders in Technologyprogram, which is helping to advance female leadership within the global technology workforce.

Editor’s note: Additional insights from global security experts will be on display at CSX 2016 Asia Pacific, set to make its debut 14-16 November in Singapore. Next year’s CSX Europe conference will take place in London on 30 October-1 November 2017.

Richard Hollis, CISM, CRISC, CPP, PCI, QSA, Chief Executive Officer for Risk Factory Ltd and emcee of CSX 2016 Europe

[ISACA Now Blog]

English
Exit mobile version