Blockchain, a Technology Innovation That Can Change Everything

Sometimes a technology intended to fill one purpose is found to have much greater potential filling a different purpose; a potential so impactful that it could literally change everything. Blockchain, the underlying technology behind bitcoin, has that potential.

While changing everything is perhaps an overstatement, blockchain is seen as a technological solution to the centuries old problem of how to create a secure and open ledger system of transactions.

Bitcoin is a cryptocurrency, which means it is a digital currency that uses encryption techniques to regulate the generation of currency units and verify fund transfers, all independent of a central bank. It exists completely outside of the government-controlled global monetary system in the world of bits and bytes, not as a physical entity.

Acceptance Growing
While bitcoin is an intangible that lives in the virtual world of the Internet, bitcoins have value and are used for commercial transactions and as an avenue for currency speculation. Technology giant Microsoft accepts bitcoins for purchases of apps, games and videos from Windows phones and Xbox platforms. Dell, in collaboration with Coinbase, accepts bitcoins, as do merchants such as Overstock.com, TigerDirect and French retailer Monoprix. Bitcoins can even be used to purchase gift cards, and some physical stores are beginning to accept bitcoin as a form of payment.

As of June 4th there were 15,617,825 mined bitcoins with a current value of $581.76 per coin, making the global value of bitcoins worth over $9 billion. Bitcoin represents a value greater than the national domestic product of many countries.

Ledger the Real Innovation
While bitcoin is a potential game changer, the real innovation is the technology behind bitcoin that creates the ledger of all coin transactions from the first coin created to the latest bitcoin transfer.

Blockchain is an open, public and secure digital ledger that uses cryptography to create ledger entries unique to each individual that are free from intentional or accidental change that forms the basis of bitcoin. For example, when an individual buys, sells or trades bitcoins they present ledger entries representing value to complete a transaction that in turn is recorded as a blockchain entry. The up-to-date, transparent ledger is visible to all parties and shows the most recent transactions as well as the history of transactions.

Though it was first applied to bitcoin trading, bitcoin has been found to be an enabling technology that can be used for a variety of applications with a number of advantages. Traditional ledger systems often depend on a third party, such as a clearing corporation, which matches buyers and sellers. Blockchain takes this “middle man” out of the equation, making the transaction more profitable by reducing the cost, while ensuring the transaction is legitimate and accurate.

Blockchain can be used wherever there is a ledger system to track transactions involving anything of value that needs to be traded securely. Applications could range across supply chain management, manufacturing, corporate treasury and trade finance. In the food industry, for example, blockchain could be used to ensure the integrity of the product throughout the supply chain. Banks may even transition to digital currency alone using the technology.

Enabling Micropayments
It also has implications for the “unbanked.” By enabling micropayment capabilities (to the millionth of a cent), blockchain can enable people to make transactions that previously were impossible, due to the monetary units involved.

Of all the emerging technologies we’re currently seeing, blockchain has the potential to have the biggest impact on businesses and society at large. Enterprises are increasingly looking at how they can adopt this technology and revolutionize how they deliver products and services. As such, audit and risk professionals need to ensure they can bring knowledge and perspective to that conversation.

Editor’s note: Hale will present a session titled What Is Blockchain and What Are the GRC Implications at the 2016 Governance, Risk and Control Conference 22-24 August in Fort Lauderdale, FL, USA. For more information click here.

Ron Hale Ph.D., CISM, ISACA Chief Knowledge Officer

[ISACA Now Blog]

Opportunity for Young People

In recent years, many young people have felt disenfranchised and robbed of opportunities to pursue career ambitions. This sits in contrast to the fast-developing field of cybersecurity, where hiring managers regularly report staff shortages and lead times of over six months to fill positions.

Cybersecurity is fundamental to the digital economy, but the (ISC)2 Global Information Security Workforce Study forecasts a growing workforce shortage of 1.5 million by 2020. As cybersecurity is a relatively new discipline, most organisations look for a minimum of three to five years’ experience, as well as a good understanding of cybersecurity concepts for the roles they are creating. Newcomers struggle to get these roles as employers find it difficult to judge their instincts. Often only the largest employers can consider entry-level or graduate training, which only goes so far in meeting the needs of a growing digital economy. There are few opportunities for young people or the uninitiated to step into this career opportunity and meet the need.

Directed by our EMEA Advisory Council, we have been working with universities across the United Kingdom to both inspire interest in and improve access to our field. We take, as our model, established professions such as engineering, that support the development of three and four-year university courses. These not only teach fundamentals, but also serve as a filter for people who have the right instincts. Graduates move into a workplace that has a level of confidence in them, whilst the professional community supports their ongoing development. Our aim is to mature cybersecurity in this same manner.

Working with the Council of Professors and Heads of Computing (CPHC), our efforts brought industry, academia, professional bodies and several government departments together to define Principles and Learning Outcomes for undergraduate computing science degrees (published in June 2015). Realising their importance, BCS, the Chartered Institute for IT, a key participant, immediately included the Principles within their degree accreditation guidelines. Cybersecurity is now a mandatory component of most computing science degrees in the U.K., affecting 20,000 new graduates a year.

Publication was followed by a curriculum development roadshow this year supported by the U.K. Office of Cyber Security and Information Assurance (Cabinet Office), where a real will to champion and embed cybersecurity concepts more comprehensively was expressed by 60 of the approximately 100 U.K. universities that teach computing science. Not everyone who pursues a computing science degree will choose a career in cybersecurity.  This effort aims to address a breadth of need and motivate the development of a cyber-competent society, including interested and skilled individuals who will be able to secure it. It will also boost employer confidence in graduates with inherent instincts for security as they pursue careers in IT.

The ambition doesn’t stop with computing science: there is now interest in integrating cybersecurity in business degrees. Knowing the fundamentals of our field is becoming critical to nearly every professional vocation.

By Dr. Adrian Davis, CISSP, Managing Director, EMEA, (ISC)²

[(ISC)² Blog]

Cloud Security Alliance Announces Strong Line Up of Trainings and Working Group Sessions Scheduled for Privacy. Security. Risk. 2016 Conference

Presented by CSA Congress and IAPP Privacy Academy, Event to Provide Forum for Professionals to Expand Education and Collaborative Work in IoT, Containerization, Privacy Audits, Threat Intelligence and Privacy Risk Analysis

San Jose, CA – August 8, 2016 – The Cloud Security Alliance (CSA), the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment, today released its schedule of workshops and CSA Working Group sessions taking place in conjunction with the upcoming Privacy. Security. Risk. 2016 conference scheduled for September 13-16 at the San Jose Convention Center. Presented by CSA Congress and IAPP Privacy Academy, the workshops and working group sessions will provide attendees with advanced knowledge and collaboration opportunities on some of the most forward-looking cloud computing technologies, initiatives and global concerns.

This year’s workshop schedule includes the following:

  • Software Assurance: Putting Industry Best Practices into Action
  • Cloud Controls Matrix Foundation Workshop
  • Cloud Security and Privacy Audits: A 360-Degree Crash Course
  • Meeting the Challenges of Privacy, Security and Compliance in the Cloud

“This year, we have worked to design a training track that will provide attendees with valuable knowledge, no matter where they are in their cloud adoption, to better understand and tackle some of the top challenges and concerns organizations are facing when implementing and managing cloud technology,” said J.R. Santos, Executive Vice President of Research at the CSA. “These workshops are designed to really get to the heart of the matter at a deeper level and in an intimate setting that naturally fosters knowledge building, idea exchange and problem solving.”

All workshops are scheduled to take place on Wednesday, September 14 and are offered at an additional cost to the main conference. For more information and to register visit:https://my.iapp.org/nc__event?id=a0l1a000000nBgQAAU.

Aside from the workshops, Privacy. Security. Risk. 2016 will serve as host to a number of important CSA Working Group sessions where CSA members will look to collaborate on and move forward with a number of important research and guidance efforts on behalf of the CSA. Scheduled for Tuesday, September 13 at the Blossom Hill Room at San Jose Marriot, CSA Working Groups scheduled to meet include:

  • Containerization
  • Internet of Things
  • Mobile Application Security Testing Initiative
  • Open API
  • Open Certification Framework
  • Quantum Safe Security
  • Security as a Service
  • New Research Working Groups: Blockchain & Data Center Security

Participation in the working group sessions are free and open to all CSA members. For schedule information and to register to attend a session visit: https://www.eventbank.com/event/683/.

Presented by the IAPP Privacy Academy and CSA Congress, the P.S.R. Conference, now in its third year, is expected to draw approximately 1,500 privacy and cloud security professionals. The event brings together two related fields—privacy and security – with important perspective to help practitioners excel in their role. The event aims to deliver the most thought-provoking speakers and sessions led by the foremost experts and provides invaluable opportunities to connect and share ideas. The join event will provide attendees with more than double the education and networking opportunities with the leading innovators and practitioners in technology, security and privacy for the price of a single conference.

Registration is now open and with an early registration discount of $200 available until August 19. The most current conference program can be found at https://iapp.org/conference/privacy-security-risk-2016/sessions-psr16/.

WHAT: Cloud Security Alliance Congress US 2016 at P.S.R.
WHEN: Workshops: September 13-14 Conference: September 15-16 9:00 am – 5:00 pm
WHERE: San Jose Marriott and San Jose Convention Center
ATTENDEE REGISTRATION: https://my.iapp.org/nc__event?id=a0l1a000000nBgQAAU
MEDIA REGISTRATION: kari@zagcommunications.com

About Cloud Security Alliance

The Cloud Security Alliance (CSA) is the world’s leading organization dedicated to defining and raising awareness of best practices to help ensure a secure cloud computing environment. CSA harnesses the subject matter expertise of industry practitioners, associations, governments, and its corporate and individual members to offer cloud security-specific research, education, certification, events and products. CSA’s activities, knowledge and extensive network benefit the entire community impacted by cloud — from providers and customers, to governments, entrepreneurs and the assurance industry — and provide a forum through which diverse parties can work together to create and maintain a trusted cloud ecosystem. CSA has developed the definitive best practices for the industry, such as the “Security Guidance for Critical Areas of Focus in Cloud Computing”, the “Cloud Controls Matrix”, “Top Threats to Cloud Computing” and 50 other cloud security research artifacts. For further information, visit us atwww.cloudsecurityalliance.org.

About the IAPP
The International Association of Privacy Professionals is the world’s largest association of privacy professionals with more than 25,000 members across 86 countries. The IAPP is a not-for-profit association that helps to define and support the privacy profession globally. More information about the IAPP is available at www.iapp.org.

Media Contact
Kari Walker
ZAG Communications
703.928.9996
kari@zagcommunications.com

[Cloud Security Alliance Research News]

Ransomware Growing More Common, More Complex; Modern Endpoint Backup Isn’t Scared

The growing ransomware threat isn’t just about more cybercriminals using the same cryptoware tools. The tools themselves are rapidly growing more sophisticated—and more dangerous.

Ransomware growing exponentially, with no signs of slowing
A new report from InformationWeek’s Dark Readinghighlights key trends in the ransomware landscape, starting with the dramatic increase in total ransomware attacks. Ransomware attacks increased by 165 percent in 2015 (Lastline Labs), and this trend isn’t letting up. Anti-spyware company Enigma Software reported a 158 percent jump in the number of ransomware samples it detected between February and March 2016—and April 2016 was the worst month on record for ransomware in the U.S.

It’s also clear that ransomware growth is independent of the overall increase in cyberattacks over the past several years. The 2016 DBIR reported that phishing attacks are more common than ever, and Proofpoint found that in the first quarter of 2016, nearly 1 in 4 (24%) of all email attacks using malicious attachments contained just one strain of ransomware (Locky).

Not just more common—ransomware growing stronger and more effective
Most alarmingly, DarkReading reports that cyberattackers are rapidly evolving and diversifying their ransomware arsenal. Ransomware has become big business, and with that cash flow comes development of more complex ransomware strains and more clever techniques for infecting targets. In an ironic twist, creators of popular ransomware such as Locky are now working to “protect” their cryptoware from enterprising copycats who create knockoff versions and variants. No honor among thieves, indeed.

Better phishing lures, more brute-force attacks
DarkReading spotlighted two examples of this increasing sophistication. On the one hand, cybercriminals are developing new, more obscure ways of luring a user to install ransomware. From personalized landing pages to actually hacking a device’s boot-up process, stopping these techniques is much more complicated than just saying, “Don’t click suspicious links.”

At the same time, attackers increasingly skip the phishing lure and go straight to brute-force attacks on internet-connected remote desktop servers. For the skilled hacker, this technique is more reliable than phishing, and immediately gets the attacker much deeper into an enterprise network, allowing them to compromise more devices and ransom more data.

“No backup, no protection”
With ransomware mutating into an even bigger threat, Dark Reading encouraged companies to go back to basics, citing data backup as the essential first step in enterprise ransomware defense. We couldn’t agree more. No matter how complex and advanced the ransomware, modern endpoint backup isn’t scared. Modern endpoint backup gives you guaranteed recovery in the face of ransomware. But its protection goes beyond backup: Modern endpoint backup sees your endpoint data, sees your users’ endpoint activities, and gives you the visibility to identify and neutralize an attack as soon as it hits.

Download The Guide to Modern Endpoint Backup and Data Visibility to learn more about selecting a modern endpoint backup solution in a dangerous world.

Susan Richardson, Manager/Content Strategy, Code42

[Cloud Security Alliance Blog]

Whaling Goes After the Big Phish

The bigger the phish, the fatter the payoff for cybercriminals. That thinking is driving a spate of whaling cyberattacks targeting C-level executives and their employees around the globe.

Whaling attacks go far beyond the typical phishing expedition in that perpetrators do their homework and learn everything they can about their intended C-suite victims and their organizations to ultimately convince them or their associates to give up credentials, information and/or financial assets. They produce believable emails that appear to be from trusted internal or external business partners that actually contain malware and URLs to download malicious payloads and link to dubious web sites all in hopes of a handsome payday. Whaling uses social engineering to prey on the weakest link in cyberdom:  humans.

I expect the surge in whaling to continue because cybercriminals are having success duping top executives and their associates. Similar to advanced persistent threats (APTs), whalers study how people write, what their email looks like and whatever else they need to know to show potential victims the personal touches that really sell the impersonation. Producing genuine-appearing email is how the criminals succeed in convincing top executives the requests are real. A key part of the ruse is the request for confidentiality and the need to bypass approval channels.

Whaling Costs Enterprises Plenty
Successful whaling attempts are so believable and seemingly trustworthy that executives who should probably know better are clicking on links and attachments that appear to be from fellow executives, employees or business partners. One stellar example of this includes a senior executive with a security firm who received an email that appeared to be from an underling but was actually from a whaler. He was tricked into giving up employee W-2 data.

Another incident involved an executive from a major soft drink company that was in talks to choose a bottler in a highly profitable, under-serviced country. Before negotiations were completed, someone working under the executive was spear phished, and the whaler was able to harvest all email related to the negotiations, jeopardizing the talks and putting the company at a distinct disadvantage.

A third case involved a top executive of a 40-year-old company that made a unique product that had just one competitor in the world. One day the executive noticed the sudden appearance of a new competitor that was selling a nearly identical product but at a significantly lower price. It turned out that the man had been whaled. Through social media, the cyberattackers learned he had a passion for antique cars. They concocted an email with a link to a fake online auto trading ad for a car deal that was too good to be true. Excited by the car and the unbelievable deal, he double clicked on the link and almost immediately 40 years of research, development and blueprints were in the hands of an unknown competitor. The company was unaware that their information had been compromised until the new competitor showed up on the market six months later.

One whaling email can sink a company or cost top leadership their jobs. A January 2016 whaling attack against an Austrian aircraft parts manufacturer resulted in the loss of US $45,693,480 and the firing of both its CFO and CEO.

Challenges Go Deep
Email is the lifeblood of business today, so living without it is not an option. But addressing the whaling problem presents a number of challenges thanks primarily to the human factor. For example, employees who receive emails from high-ranking executives are often hesitant to question their validity. They want to handle any and all requests from higher ups quickly and efficiently to gain favor with their boss. On top of that people are often overworked, so the last thing on their mind is whether or not an email is legitimate. Finally, employees today are often less committed to their organizations than we would like. Allegiance to employers can be weak or nonexistent, so why should they care about whaling attempts? Your company’s whaling defenses are only as good as your least knowledgeable and dedicated employee.

Training, Training, Training
What can be done to protect organizations against whaling? In a word:  training. Training to increase education and awareness of cyber schemes such as whaling, phishing and the like, is critical to combatting these incidents. For email requesting out of the ordinary access to data or assets, secondary verification is critical. A quick phone call is all it takes. And always check the sender’s email address. Security should never be weakened in exchange for speed or expediency.

Training should be regular, engaging and include every person in the organization, including C-suite personnel. Poor or condescending training can be worse than none at all, so make sure you develop effective training and do not talk down to employees. Training and awareness efforts should be ongoing and can include weekly email blasts to reinforce training and maintain and increase awareness.

Obviously, if your organization has an IT professional with cybersecurity credentials such as a CSX Cybersecurity, Fundamentals,Practitioner, Specialist or Expert certificate, they can provide invaluable resources to ensure effective training.

Daniel Libby, Director and Chief Examiner, Digital Forensics Inc.

[ISACA Now Blog]

English
Exit mobile version