Social Engineering: Placing Obstacles in the Path of Least Resistance

Organizations battle daily with social engineering-based cyberattacks and unfortunately often find themselves on the losing side. What can be done? To determine this, we need to step back from our technological tools and start with the psychological basis of why social engineering works and why it is a tactic of choice for cyber attackers. Armed with that knowledge, organizations can begin to mount a more effective defense.

When people think of social engineering they tend to think of phishing, which is a huge problem. According to the 2015 Verizon Data Breach Incident Report (DBIR), 23 percent of phishing recipients open messages, and 11 percent click on attachments. The 2013 DBIR reported 95 percent of incidents attributed to state-sponsored actors used phishing, and more than two-thirds of cyber-espionage incidents involved phishing.

A cybercrime campaign of only 10 emails yields a greater than 90 percent chance that one person will click on a malware link. Fifty percent of users open emails and click within the first hour of receiving.

Going Beyond Phishing
But the social engineering problem goes well beyond phishing.

It is no wonder hackers use social engineering techniques; they work. Hackers are in business and are looking for a return on investment. Whether it is stolen identities, bank account numbers, intellectual property or just notoriety, they are looking for a return for their time.

Think of it this way: If you had a choice to spend hundreds of hours scanning networks, identifying operating systems and applications in use, determining vulnerabilities, and crafting malware, or making one phone call pretending to be from the help desk and talking a user out of his/her password, which would you do? Social engineering provides a greater return on investment.

Social engineering is not an invention of the information or even the industrial age; it has been around throughout history—look at the original Trojan horse. There is a psychological basis for why social engineering works. All of the following can be turned against a target to gain a goal:

  • Trust
  • Sense of urgency
  • Desire to be helpful
  • Curiosity

There are many tools available to cybercriminals to conduct social engineering and gain valuable information from individuals, including Google and other search engines, dumpster dives, simple phone calls to just ask, burner phones (prepaid cell phones replaced frequently to avoid leaving a trail), caller ID spoofing, doppelganger domains, fake public Wi-Fi access points, and, yes, phishing email.

Fighting Back Against Social Engineering
So how do you block this path of least resistance and prevent attacks, detect attacks sooner and lessen impact? First, it is critical to know what information hackers are looking for in social engineering attacks and how to protect it. Having some technical security controls in place is critical, as well. And, finally, awareness training—making your people social engineering attempt detectors—will go a long way in addressing the weakest link in these sorts of attacks—humans.

Douglas Rausch is President of Aurora Cybersecurity Consultants, and an assistant professor of cybersecurity at Bellevue University, Bellevue, NE. His expertise centers on providing risk management, cybersecurity, governance and awareness training expertise to organizations worldwide. He brings 25 years of experience as a cyber operations officer in the US Air Force, leading risk management activities, assessing cybersecurity, and recommending cybersecurity policy and technologies for Department of Defense and Air Force terrestrial and space systems. He was recently appointed to the National Initiative for Cybersecurity Education (NICE), Training and Certification Sub-Working group.

Rausch will present a webinar, Social Engineering: Placing Obstacles on the Path of Least Resistance, on Tuesday, 23 February, at 11AM Central Standard Time. To sign up, click here.

Douglas Rausch, CISSP
President
Aurora CyberSecurity Consultants, Inc.

[ISACA Now Blog]

 

Security Breach Management: Handling The Storm With Aplomb

2015 was marked by far too many digital security breaches, a trend that every company hopes to see reversed in the coming year. Unfortunately, as industry expert Leo Scanlon notes, it is unlikely that we’ll be able to stop them all. In this digital era, security breaches are part of the new normal.

So, what should you do when facing a security breach? The most important thing that you can do is stay calm. If you keep your wits about you, you will be better able to approach the problem and implement a solution to protect your clients and your company. Here is how to move forward in the face of a digital security breach.

Plan Ahead
While you may not be able to plan for the exact details of a security breach – if you could, then you could prevent it from happening – what you can do is prepare a preliminary plan of action for any future breach. Write out a general timeline for what actions need to take place and in what order. This way, when something does happen, you do not lose any time giving direction. All you need to do is to fill in the specifics of the event.

Communicate Clearly and Calmly
When a breach does occur, it is important to prioritize communication with your team and with your clients. Start with your team. Describe the event, review the plan of action, and make sure that everyone is clear on his or her role.

It can be worth it to sit everyone down to discuss the breach rather than send emails about the issue. This allows people to ask questions in real time rather than sending lots of follow-up messages. You might even consider serving everyone a cup of tea. Green tea reduces stress and can calm down anxious team members in a visceral way, moving them from high anxiety to centered focus.

After you have alerted your team, everyone can split off to appropriate tasks ranging from developing a patch to prevent system attacks to calling high profile clients. You will also need to contact a range of other people, including a lawyer and police.

Additionally, make sure your public relations department is ready to issue a statement and field phone calls. Give them a quick FAQ sheet and a directory of who to call about which issues. By preparing public relations as well as you can, you avoid clogging up other employees’ lines with client issues.

Talk and Train
While a security breach tests training effectiveness on the ground, this is also a good opportunity to schedule follow-up training. Then, while working to resolve this breach, note the areas in which employees struggle. These should be central to your next training session.

You should also contact some of your industry peers to find out what they do to prevent security breaches. This does not mean that you need to mimic their strategies, but if you know that someone is using a different approach, you should document clearly why you are doing something else. That way, if you do suffer a breach, you have demonstrated a well-thought-out strategy rather than an arbitrarily chosen system.

Big Fixes, Small Details
Ultimately, when you suffer a data breach, it is important to focus your attention on two issues: the big problems that need to be remedied immediately and the small problems that contributed to the breach but were overlooked during earlier development phases. Start big, and then shift to the small to protect yourself now and down the road.

For the sake of companies and clients alike, hopefully 2016 holds fewer security breaches. But, to make this dream a reality, every company will need to assess regularly its security systems and breach preparation. Failure to plan is planning to fail, so put that plan in place now.

Larry Alton
Writer
[ISACA Now Blog]

5 Ways to Hack Your Leadership Communication

“The art of communication is the language of leadership.” James Humes

Good interpersonal skills are the hallmark of all great leaders. There is no leadership without effective communication. And those who possess the art of delivering thoughts and ideas in meaningful and befitting ways are those who are most successful.

No academic discourse or any business degree can teach you how to become a skillful communicator. It is self-taught and learned by exposing oneself to situations where interpersonal skills are tested the most. Regardless of which leadership style CEOs and managers adopt or have, delivering the right communication is a different matter altogether.

The best communicators are not only those who show the intent to listen to others, but also those who have incredible situational awareness and observation and problem-solving skills. Without being able to critically analyze, process the finer details and evaluate it holistically, leaders will not be able to communicate the “big picture” to their staff, and the business as a result will not grow as it should.

The following are a few ways leaders can uphold effective leadership communication:

Get personal—The positive value of any relationship intensifies the more emotions are involved. While it is important to have disciplined and professional relationships with your staff, it is also essential that leaders communicate with their staff using personalized tones and messages. Cultivating meaningful relationships is thus critical for leaders to communicate effectively.

Be specific—Leaders also need to practice ways of keeping their messages concise and to the point. There is nothing remarkable about making long speeches, if your staff cannot understand and remember half of the things you say. Business leaders are more pressed for time, and it can be very damaging if they do not deliver messages in a summarized and concise manner. The more summarized your messages are, the more clarity your staff will have.

Show empathy—“Leadership today is based on relationships built with trust, hope, love and encouragement,” Billy Cox. It is only natural that those vested with authority will exploit their position to show ego. That, however, is not the mark of a strong leader. A strong leader is one who can show empathy for his or her staff. Empathy contains the human element of compassion and care that can patch up emotional or psychological issues faced by employees in their work routines. Showing empathy means that you value human emotions and doing it enough can be precursor for influencing great motivation levels in your staff.

Demonstrate analytical reasoning—How well you analyze information and events is an important quality for a leader to have. What is more important is getting your employees to think like you and perceive things from your point of you. This does not necessarily mean that they have to agree with you; rather, it is about exercising one’s rational faculties to become better, data-driven staff that can achieve extraordinary results.

Leaders should ask employees to make their research and present their own analysis and solutions to a problem along with a case study, company/department objectives and conclusion. You can then ask a series of questions regarding how the business should quantify the solutions and how it can translate into long term business growth.

This is an important exercise to train your staff to think on their feet, appreciate their rational thinking and arrive at conclusions that can relate to worthwhile business strategies.

Listen and be silent—Listening with an open mind and out of genuine interest is one of the easiest ways to gain trust of your employees. By listening with a sincere heart, your employees feel valued and become encouraged to participate more closely with the activities of the organization. It sparks interest in your staff and allows them to be more at ease with their company culture.

Simon T. Bailey
Author, speaker and Brilliance Enabler

Bailey will be speaking at ISACA’s 2016 North America CACS conference 2-4 May 2016 in Las Vegas, Nevada, USA.

[ISACA Now Blog]

Flipping the Economics of Attacks

How can an organization make it difficult enough for an attacker that they dissuade or prevent an attack? Time-wise? Cost-wise? Potential profit-wise?

In Flipping the Economics of Attacks, sponsored by Palo Alto and conducted by Ponemon Institute, threat experts in the United States, United Kingdom and Germany were surveyed about what motivates attackers. The research revealed that most attackers are in it for the money.

To fight back against adversaries enterprises need to harden their organizations so it takes attackers longer to achieve their mission. Most malicious attackers are opportunistic when choosing a particular organization to attack and will quit the attack when the targeted organization presents a strong defense. Specifically, the majority of attacks can be stopped if more than about two days are needed for a successful attack.

The following are recommendations from the report that will help steel the organization against malicious actors:

  • Create a holistic approach to cybersecurity, which includes focusing on the three important components of a security program: people, process and technologies.
  • Implement training and awareness programs that educate employees on how to identify and protect their organization from such attacks as phishing.
  • Build a strong security operations team with clear policies in place to respond effectively to security incidents.
  • Leverage shared threat intelligence to identify and prevent attacks seen by your peers.
  • Invest in next-generation technology such as threat intelligence sharing and integrated security platforms that can prevent attacks and other advanced security technologies.

There are many questions that the cybersecurity community needs to answer: What are the typical annual earnings of a cybercriminal? What is the attacker’s cost of conducting a breach? Does crime pay? Are cybercriminals getting rich?

While many attackers may hope for a big payout, the reality can be quite different. The findings of the survey reveal attackers on average receive $28,744 for an average of 705 hours spent on attacks annually. Of course, some attackers do “earn” more than the average. However, this compensation is 38.8 percent, or one-quarter, less than the average hourly rate of IT security practitioners employed in the private and public sector.

We also learned that attacks are increasing because of the availability of low-cost and effective hacker toolkits. Technically proficient attackers are spending an average of $1,367 for specialized tool kits to execute one attack. The only other cost is their time.

For more information attend the ISACA webinar: Flipping the Economics of Cyber Attacks, 11 A.M. (CST), Tuesday, 26 January, presented by Scott Simkin is Sr. Manager, Threat Intelligence at Palo Alto Networks, and Dr. Larry Ponemon is the Chairman and Founder of the Ponemon Institute.

Dr. Larry Ponemon
Chairman & Founder, Ponemon Institute

[ISACA Now Blog]

Trusting the Cloud: HIPAA Risk Assessment for Cloud-Based Files

Cloud-based computing and storage is increasingly popular—to the extent that some companies are cutting hard drive space to encourage users to shift toward the cloud. And while the cloud is convenient, allowing your files to travel easily and across devices, that kind of convenience isn’t exactly what you want when it comes to protecting medical files. Is your cloud use secure enough to meet Health Insurance Portability and Accountability Act (HIPAA) standards? Here are some factors to consider.

A Quick Overview
There are a lot of cloud systems available these days, but the first thing you should do when choosing one is compare baseline HIPAA compatibility. Amazon S3, Dropbox and iCloud are not compatible with HIPAA practices out of the box. Most other major systems, including Box, Egnyte, Google apps, and CrashPlan Pro are HIPAA compliant. Identifying the outsiders reduces your choice of cloud systems, allowing you to focus in on the details of compliant plans.

EHR or HIPAA
In addition to cloud computing, many physicians are shifting to digital recordkeeping, using what are known as electronic health records (EHR) systems. These systems are great for centralizing patient data and encouraging collaboration across different medical practices that share the same EHR vendor. However, EHR requirements and HIPAA privacy standards aren’t exactly the same.

The first rule of managing EHR in accordance with HIPAA standards is that you should never trust an EHR vendor that says you don’t need to worry about their HIPAA compliance. Although your specific files may be HIPAA compliant, other practices used by external vendors may not be; for instance, their cloud storage security may be lacking. Additionally, although EHR systems have all the features needed to be fully HIPAA compliant, you’ll need to check to make sure they are properly configured. If necessary safeguards are turned off, your patients’ data may be at risk.

Don’t Play Hide and Seek
Rather than establishing thorough HIPAA compliant practices, some organizations still think that what is known as “security through obfuscation” is a valid system providing the necessary protections. Realistically, though, this is possibly the worst of all security practices. This kind of security focuses on hiding your computer network, but tends to disregard proper antivirus software.

Additionally, such practices tend to reveal other lacking security practices within the organization, such as indiscriminate file sharing (between virus-infected computers, no less). Simply hiding your network doesn’t count as securing your files – a skilled hacker can easily access even an invisible network.

BAAs Are Not Enough
Google has a great reputation in the cloud-computing world, and with health organizations with high security standards. This means that medical practices using Google apps often feel confident that their files are safe, as long as they’ve signed a Business Associate Agreement (BAA).

BAA agreements might keep your information safe on an internal level, but this agreement won’t help secure patient files when transferred to other digital environments. Instead, when transferring files, using end-to-end encryption is the safest bet. This system will keep your data HIPAA compliant, even when it leaves the Google cloud.

Consider Adoption Side Effects
It’s great to choose a new HIPAA-compliant cloud system for your business, but in our pursuit of better data management systems, we often forget to consider the human elements of adopting new systems. Before choosing a new system, then, it’s important to ask whether your employees will be able to effectively use the new system, and whether there are other options they may find more convenient.

This is a common problem for companies choosing between Office 365 and Google apps for their cloud computing activity. Both Microsoft and Google will sign BAAs that offer HIPAA compliance, but the two programs have different strengths. This is where considering use and convenience is important. If you work a lot with documents, you might think that Office 365 is the way to go—most of us came of age writing everything in Word, so why not? The main reason not to, it seems, is that Google Docs’ collaboration systems are helpful and the platform is more convenient. The reverse seems to hold for spreadsheets.

If you can’t get your team on board with a new computing system, no amount of security regulation in the world will help you. Be sure to clearly to tell your staff about organizations with which you have BAAs, the legal risks of using other systems, and their responsibility to patient privacy as health field employees.

Larry Alton
Writer
[ISACA Now Blog]
English
Exit mobile version