This month marks the start of the 12-month countdown for organisations to be ready to comply with either – or in some cases both – the General Data Protection Regulations or the NIS Directive becoming law in Europe on the 25th and 10th of May 2018, respectively.
Whether you have started working towards compliance in the last year or not, the deadline to be ready for these new laws is fast approaching, and the pressure to review, change and test new cybersecurity systems increasing.
So, what’s the current state of mind of cybersecurity and business leaders as we count down? In research recently commissioned for Palo Alto Networks, we found that IT security professionals across Europe are generally optimistic about how these laws will help avoid personal data and cybersecurity breaches. However, there is still some hesitation when it comes to how easy the change will be. What is immediately clear is there are vast geographical differences when it comes to openness to new ideas; senior management in countries like Sweden are least likely (28 per cent) to accept suggested ideas for change from internal stakeholders, whereas Dutch respondents were far more willing to adopt new ways to best protect their organisation (39 per cent).
A fear of the unknown continues to present a significant roadblock over the next year, and not all businesses can see the benefit in change. Only a third of respondents think they will get the support to implement the necessary changes, while the majority still feel there will be obstacles to overcome.
With only one in ten respondents admitting that pressure to comply with new laws would make them open to ideas for change, there is a major shift in perception needed to ensure European businesses are ready come May 2018. Our research found that:
43 per cent of IT security practitioners were concerned changes to legislation will unleash a wave of previously unknown personal data and cybersecurity breaches that need to be reported.
Half of all IT professionals (49 per cent) said they avoid security system changes or updates because they think their current system is already broadly secure.
56 per cent of IT security professionals think the GDPR/NIS implementation will be a pain both financially and operationally.
With all that in mind, there are several ways businesses can prepare themselves today ahead of May 2018:
Gain visibility of what information is being used and through which applications. If you don’t have ongoing insight into how your business is already processing information through technology, then you can’t validate if this is appropriate and what controls must be wrapped around it.
Too much of cybersecurity is legacy technology – leverage the new regulations as an opportunity to clean your house, validate that everything is fit for a purpose, today and in the future, especially considering that cybersecurity will continue to evolve, and the biggest shortfall is skilled cybersecurity people. Consider how you apply and maintain an adaptive cybersecurity ecosystem that is automated to work at the same speed as the attacker.
Ensure that you have clear leading and lagging metrics to validate the effectiveness of your cybersecurity. Can you prove to your own business and others that you are effectively aligning current best practices to the risks?
Test your capabilities – not just the technology, but also the people and processes around these, including the broader businesses teams.
Cybersecurity leaders will need to validate that their cybersecurity capabilities are relevant to the risk they face and that they leverage current best practices, referred to as “state of the art”, with clearly documented processes and measures.
To learn more about how you can prepare your business for the upcoming new laws, please see the following Palo Alto Networks assets:
The National Association of Corporate Directors says that directors do not feel adequate in terms of mitigating cybersecurity issues. The problem is that we have led ourselves to believe that cybersecurity risk is somehow different from all the other risks that directors deal with daily. This is incorrect. The same risk strategies apply: acceptance, avoidance, mitigation and/or transfer. The needed change is that directors must insist that their technical C-level executives transform technical risk into business risk. The board needs to help them with this because many are not comfortable doing it. But once done, all that is left to do is for the board to learn and understand at a high level some of the technical issues involved in these strategies. Start with the Cybersecurity Canon Project: a collection of network defender-recommended books about all aspects of security. As a priority, read these three books first: “Navigating the Digital Age,” “How to Measure Anything in Cybersecurity Risk,” and “Measuring and Managing Information Risk: A FAIR Approach.”
Introduction
Based on a recent survey conducted by the National Association of Corporate Directors, only 19 percent of board directors feel confident that they grasp the nuance of cybersecurity risks well enough to make well-informed decisions. A whopping 59 percent of directors surveyed by the NACD say that they feel inadequate to oversee these risks. [1] Those are shocking numbers since most every business today has some sort of cyber component. As the world sprints into the digital age, you would be hard-pressed to find a business that has no digital component helping to drive the efficiency and innovation of the company.
How Did We Get Here?
This situation is largely the fault of the network defender community: your CIOs, CSOs and CISOs. From the first CISO who was hired back in the mid-1990s [2] until the present day, the network defender community has insisted that the risks associated with cybersecurity were somehow unique compared to the myriad of other risks that directors deal with every day. They said that, because this kind of risk is mostly associated with computers, the internet and hackers, it belongs in some sort of risk category that requires special handling. This is wrong.
Cyber Risk Is Not a Special Kind of Risk
Risk is risk, whether it manifests from employee injury, property loss, business interruption, liability or a cybersecurity breach. Directors deal with this cyber risk the same way they deal with all other risks: they find ways to alleviate or eliminate potential material risk to the business. They use basic risk management strategies like acceptance, avoidance, mitigation or transfer. [3] From these strategies, all that is new to the director in dealing with cybersecurity risks are the potential technical mitigation strategies you might choose. But that is why you have the technical C-staff working for you. The CIO, CSO and CISO will understand the technical details. What you should be asking them to portray is the potential risk to the business.
This is hard for most technical C-levels. They understand the technical details, but many have trouble transforming that technical risk into business risk. They will need your help with understanding the business risk strategies that directors already understand and separating all the “scary” risks – because they come from hackers – from the potential-material-impact risks that threaten the company. In other words, there are many alarming scenarios that we all can manufacture when it comes to hacker stories, but articulating the scenarios that will have high impact to the business if they occur and, at the same time, have a high probability of occurring in the short term is the key. This is a conversation with which many technical C-level executives do not have a lot of experience. Once done, the last thing to do is for the director to gain a high-level understanding of the technical solutions your technical C-level executives recommend.
Director Homework
When learning about a new knowledge domain, the thing to do is to check the literature. Fortunately, there is a community project at your disposal on which directors can rely, called the Cybersecurity Canon Project. [4] Think of it as the Rock and Roll Hall of Fame for cybersecurity books. This is not just a book list. In order to get on the list, some network defender has to write a book review justifying why a particular book should have been read by all of us by now. There is a committee that consists of all types of network defender experts who read all of the submissions and decide which books make it onto the candidate list, and which books ultimately get put into the canon. For directors, I recommend two books that are currently on the candidate list and one book that is already in the canon.
“Navigating the Digital Age: The Definitive Cybersecurity Guide for Directors and Officers,” published by the New York Stock Exchange and Palo Alto Networks
“Navigating the Digital Age” is the first comprehensive book specifically designed to enlighten and educate corporate directors and officers in terms of cybersecurity. The book includes more than 30 contributors, so it is meaty; and while there is some overlap in the material covered, it contains a dense collection of information around fundamental principles for the board members to do their jobs; board standards to consult; the executive on whom they should rely – the CISO; which committees they should create to support their efforts; what they should worry about in terms of fiduciary responsibility and the potential for litigation; the perceived cybersecurity disconnect between shareholders and board members; and finally, how they should think about disclosing breach information to the public. [5] This is a free-to-download book published in partnership by the New York Stock Exchange and Palo Alto Networks. Since the publication of this book, Palo Alto Networks has published companion books in France, Australia, Japan, Singapore and the U.K. We plan to publish books in Germany and Holland this year too. [6]
“How to Measure Anything in Cybersecurity Risk,” by Douglas W. Hubbard and Richard Seiersen
“How to Measure Anything in Cybersecurity Risk” is a book anyone who is responsible for assessing risk should read. It is grounded in classic quantitative analysis methodologies and provides a good balance of background and practical examples. The authors lay out a solid case for why other industries with the similar challenge of a lack of quantifiable, standardized or historical actuarial table-like data are able to use classic statistical modeling and methodologies to measure risk in a qualified, repeatable way. [7]
“Measuring and Managing Information Risk: A FAIR Approach,” by Jack Freund and Jack Jones
“Measuring and Managing Information Risk” is a book that not only describes what risk is but also teaches you how to measure it quantitatively so that practitioners can demonstrate to their leadership that they understand the problem. It shows how to deliver financially derived results tailored for enterprise risk management and is intended for organizations that need to either build a risk management program from the ground up or strengthen an existing one.
It covers key areas, such as risk theory, risk calculation, scenario modeling and risk communication within the organization. [8]
Conclusion
Cybersecurity risk is no different from any other kind of risk that directors normally handle in their day-to-day jobs. In the early internet days, we let the technicians convince us otherwise. Now we are trying to re-learn what the real truth is: that we can use the same traditional risk strategies for cybersecurity as we do with all other business risks: acceptance, avoidance, mitigation and/or transfer. Many of our technical C-level executives need help transforming technical risk into business risk. The director can help with that. Insist that your technical C-levels sort out the “scary” risks from the probable high-impact risks. To gain a high-level understanding of some of the issues, directors should refer to the Cybersecurity Canon Project and read the literature that the network defender community recommends, beginning with these three books: “Navigating the Digital Age,” “How to Measure Anything in Cybersecurity Risk,” and “Measuring and Managing Information Risk: A FAIR Approach.”
[2] Evolution of the CISO and the Confluence of IT Security 7 Audit,” by Thomas Borton, ISACA (March 13, 2014), https://goo.gl/ocM6RL (last visited April 15, 2017).
This Unit 42 blog provides an update on the threat situation surrounding the WanaCrypt0r ransomware attacks and how the attack propagates.
Initial reports said that the WanaCrypt0r attack began as part of a spam/phishing campaign. Unit 42 and other researchers have concluded that these reports are not substantiated. While the initial attack vector for these attacks is unknown, it is certain that the spread of the ransomware occurs through active exploitation of the ETERNALBLUE vulnerability (CVE-2017-0144) in Microsoft Windows. Patches for this vulnerability for all supported versions of Windows have been available since March 2017. On Friday May 12, 2017, Microsoft took the extraordinary step of releasing patches for out-of-support versions of Windows to help protect against these attacks.
As the attack leverages this Microsoft vulnerability, the most appropriate first step to take against the attack is to apply the patches. Unit 42 researchers have confirmed that the patch is effective against the WanaCrypt0r Ransomware attacks.
As with all ransomware attacks, Palo Alto Networks and Unit 42 recommends that anyone affected NOT pay the ransom. Unit 42 is not aware of any reports where paying the ransom to the WanaCrypt0r attackers has resulted in the recovery of data. In addition, Unit 42 research has shown that very few have attempted to pay the ransom.
Unit 42 is following this situation very closely and will update this blog with any new information as it becomes available.
Overview
WanaCrypt0r is a global ransomware attack that emerged on Friday, May 12, 2017. It immediately gained broad media attention, due to its destructive nature, how widespread it was, and multiple high profile victims. This attack uses the version 2.0 of this ransomware. WanaCrypt0r v 1.0 was first reported a few months ago but did not include the worm capability associated with this attack.
Reports quickly emerged that this attack was effective due to the presence of code exploiting a vulnerability (CVE-2017-0144) in Microsoft Windows (code named: ETERNALBLUE) that was released as part of the Equation Group dump by the Shadow Brokers in their fifth leak on April 14, 2017. Microsoft patched this vulnerability as part of the March 2017 Monthly Security Update Release by Microsoft Security Bulletin MS17-010. This is a SYSTEM-level remote code execution (RCE) in the handling of the Server Message Block (SMB) protocol in Microsoft Windows.
The attack uses this vulnerability to spread the WanaCrypt0r ransomware on the network. This is a classic network worm-class vulnerability like MS-Blaster and Conficker.
Early reports indicated that the initial attack vector was via spam and/or phishing email. However, this has not been confirmed and is unlikely to account for the global spread of the malware.
When the WanaCrypt0r ransomware executes successfully, it will encrypt key files on the system and display a ransom note as shown below (SOURCE: Microsoft).
Figure 1 Ransom note for WanaCrypt0r
One thing reports have indicated that make this attack unique is a “killswitch” capability built into the malware. This “killswitch” will prevent the WanaCrypt0r ransomware from executing. The “killswitch” is code which will attempt to connect to an extremely long domain that should not resolve. The initial variant of WanaCrypt0r uses hxxp://iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com, however, there are reports of newer variants using different domains. If it was successful in connecting to the domain, the ransomware would not execute. However, it was easily subverted to work against the malware. A security researcher in the United Kingdom initially registered this domain in order to track this threat, and soon discovered that in doing so, he had enabled this “killswitch”, causing a number of instances of WanaCrypt0r to not execute for a large number of infected systems.
On Friday, May 12, 2017, Microsoft announced that they were making an emergency patch available for out-of-support versions of Windows (Windows XP, Windows 8 and Windows Server 2003).
As of this writing attacks appear to have subsided. This is likely due to increased uptake of the patch MS17-010 in light of the WanaCrypt0r attacks, as well as efforts made within the security community.
Unit 42 research shows there is likely very little actual payment of ransom. We analyzed our known WanaCrypt0r samples and extract the following Bitcoin (BTC) addresses likely associated with the attackers and associated totals:
13AM4VW2dhxYgXeQepoHkHSQuy6NgaEb94 – 12.42466618
12t9YDPgwueZ9NyMgw519p7AA8isjr6SMw – 11.83101346
115p7UMMngoj1pMvkpHijcRdfJNXj6LrLn – 8.74393075
1DefE3HEeBaR4EBbAajjHatFzMuPe885Hf – 3.12308549
This results in a total of 36 BTC, or roughly $63k based on the current price of BTC. Given that WanaCrypt0r requests $300 per infected machine, we can infer that approximately 210 victims have made payments to the attackers.
Reconnaissance
This attack does not appear to be targeted. Therefore, there appears to be little recon as part of this attack. There are some reports that there may be scanning of TCP port 445, which is one of the ports associated with SMB. But these reports haven’t been conclusively verified.
Delivery
There is no consensus in the industry on what the delivery method/initial infection vector is. There have been several theories:
Spam/Phishing: Initial theories suggested that delivery occurred through a spam or phishing email with a link in the body or in an attached Adobe .PDF file and the user could click the link and execute the attacker’s code in their security context to initiate the attack which would then spread on the network by attacking the ETERNALBLUE vulnerability.
Direct attack against MS17-010: This theory suggests that the attack would establish a beachhead by attacking the ETERNALBLUE vulnerability on Internet-exposed systems and the attack would then spread on the network by attacking the ETERNALBLUE vulnerability from these compromised systems.
RDP: This theory suggests that the initial attack comes by attacking systems using the Remote Desktop Protocol (RDP) and then the attack which would then spread on the network by attacking the ETERNALBLUE vulnerability from these compromised systems. This theory suggests an attack pattern similar to what Unit 42 outlined in the Shamoon 2 attacks followed by using RDP as the initial delivery method and then attacking the internal network from the compromised RDP system. There are theories suggesting this could be due to brute force attacks against the RDP system, while other theories suggest this could be due to a successful attack against a vulnerability on these RDP systems (theories do not state what vulnerability this could be or where the vulnerability might occur).
Unit 42 believes the most likely delivery method is method #2. However, this is not conclusively provenLateral Movement
Lateral Movement
The WanaCrypt0r ransomware spreads itself by heavily scanning over TCP port 445 (associated with SMB) and attempting to exploit the ETERNALBLUE vulnerability on systems. A successful attack against this vulnerability will infect the target system with the WanaCrypt0r ransomware, which will encrypt data on the target system and attempt to spread itself once again.
Multiple vendorsreport that the malware includes the ability to spread via port 445 scans and attacks against the ETERNALBLUE vulnerability not only on internal networks but also across the Internet. These reports indicate that in addition to the internal lateral movement already outlined, the WanaCrypt0r ransomware will scan for port 445 on random external IP addresses and if it finds an IP address with an open port 445, it will then scan all devices on the same /24 IP range (i.e. that share the first three octets as that IP address with the open port 445).
Command and Control (C2)
In general, WanaCrypt0r does not have C2 capabilities but it does utilize the TOR network to communicate encryption keys for decryption upon payment of ransom. It has been reported that the DOUBLEPULSAR backdoor (also from the Equation Group leak by Shadow Brokers) is installed and used to execute the malware after successful exploitation of a host via ETERNALBLUE, but this warrants further analysis.
Conclusion
Overall, WanaCrypt0r has been a notable incident within the security community, as the threat couples a wormable vulnerability/exploit with a ransomware family. Users are urged to apply the necessary Microsoft patch to protect themselves against this threat.
For protections, customers are advised to view this blog post that outlines the various ways the Palo Alto Networks platform prevents this threat.
With only three years left before the Tokyo Summer Olympic Games in 2020, Japan is facing a shortfall of cybersecurity manpower. According to the Ministry of Economy, Trade and Industry (METI), the current shortfall of IT professionals to available opportunities is 132,060, which will further increase to 193,010 in 2020. About half of end-user companies believe they are deficient in IT security employees, and only 26 percent think they have enough talent in these roles.
The Japanese government plans to issue a new national cybersecurity strategy for human resources development, the Program to Develop Cybersecurity Human Resources, in 2017. The draft released in March 2017 emphasizes that cybersecurity is not a cost center, but it provides opportunity to invest to create new business values and increase companies’ international competitiveness. Reflecting the Cybersecurity Guidelines for Business Leadership in December 2015, the draft encourages business executives to take cybersecurity measures as part of their social responsibility and raise cybersecurity awareness. This is crucial now, because the government learned 34 percent of Japanese business executives do not consider cybersecurity part of their business challenges.
The current business environment, however, demands end-user companies find a balance between outsourcing and insourcing IT or cybersecurity-related work. Business operations heavily rely on computers, hardware, software, cloud computing, cell phones, tablets and SaaS, and more adopt general purpose technologies for cost-saving and efficiency. Each technology requires specific security expertise. Moreover, business risk management, critical infrastructure operations, finance, legal, human resources and even national security touch upon cybersecurity. Business executives must take the lead to craft a business strategy to deal with a wide variety of risks – including cyber risks – and take advantage of innovative technologies for security and convenience.
METI and the Japanese Ministry of Internal Affairs and Communications (MIC) are tackling the aforementioned challenges to cultivate cybersecurity-driven C-level executives and next-generation professionals for end-user companies and critical infrastructure companies. Both ministries are launching separate cybersecurity training centers in 2017. While MIC focuses on IT research and development, METI covers both the operational and information technology sides of critical infrastructure protection, including industrial control system/supervisory control and data acquisition (ICS/SCADA).
As cyber risks against ICS/SCADA are growing, METI established the Industrial Cybersecurity Center of Excellence (COE) under the Information-Technology Promotion Agency (IPA) in April 2017. COE has three pillars for their mission: the development of human resources; the evaluation of the security and reliability of ICS/SCADA; and the research and analysis of cyberthreat intelligence.
COE will serve a total of up to 100 students per year, and provide two courses: one for mid-career people and one for C-level executives. Both courses will be a golden opportunity for professionals from different sectors to get connected, create a trusted community, and help each other later.
While the course for C-suites will consist of several classes over a short term, the course for mid-career people will run from July to June. It will aim to cultivate professionals able to propose cybersecurity strategy drafts and brief business executives about cyber risks, using business management and financial terms; who understand the current cyberthreat landscape and best practices overseas and in other sectors to apply to such cyberattacks, and can use the information to craft cybersecurity tactics and strategy; and who can evaluate the safety and reliability of cybersecurity solutions, technologies, and costs to employ and deploy the best one. The course starts at Primary level (July to September), and moves onto Basic (October to January), Advanced (February to April), and Graduation Project (May to June), though more advanced students do not need to participate in Primary classes. It covers IT/OT basics, such as corporate governance, business continuity, forensics, ICS/SCADA risks and cyber exercises; business management and ethics, such as leadership, accounting/finance, presentation skill, budgeting and relevant legislations; and global case studies.
MIC released the IoT Cybersecurity Action Program 2017 in January 2017 to enhance IoT security and prepare for Tokyo 2020. One of the main pillars of the program is to accelerate the national effort to cultivate cybersecurity workforce by hosting cyber exercises and establishing a training center. The National Cyber Training Center was created under the National Institute of Information and Communications Technology (NICT) in Tokyo this April. NICT was chosen for its assets: NICTER (Network Incident analysis Center for Tactical Emergency Response) to watch cyberattacks and visualize them; and a cloud-based StarBED platform for cyber exercises.
The National Cyber Training Center offers the SecHack365 program to train 40 students under 25 years old each year; implement 100 Cyber Defense Exercise with Recurrence (CYDER) exercises for 3,000 central and local municipal government officials and critical infrastructure personnel all over Japan; and host the Cyber Colosseo exercises for the Tokyo Organising Committee of the Olympic and Paralympic Games. The center accepted 359 applications from young industry people and college and university students including teenagers in April. SecHack365 students can take classes remotely to develop computer programs and participate in cyber exercises and hackathons. Competent students will be sent overseas for additional education. The center also aims to build a community for next-generation engineers to lead IT-driven innovation in Japan and develop computer programs to resolve unsolved challenges, rather than relying only on existing technologies.
CYDER used to target only Tokyo. In Japanese Fiscal Year 2015 (April 2015 to March 2016), 200 people from the central government and critical infrastructure people participated in CYDER. In JFY 2016, however, CYDER was also provided in eleven places outside Tokyo, and 1,500 people attended. CYDER expanded to cover local municipal governments because they have residents’ My Number information (a new personal identification system for Social Security and taxation information), and more cybersecurity is required as cyberattacks and breaches are growing.
Cyber Colosseo exercises allow Tokyo 2020 cybersecurity personnel to simulate potential cyberattacks on Tokyo 2020 and review and enhance defensive capabilities with Blue and Red Teams. The exercises are expected to help team-building between security personnel and relevant organizations.
These METI- and MIC-led initiatives will allow IT and OT personnel to learn from each other, power mid-career professionals by business operation mindset to bridge between technical engineers and business executives, make C-level executives more mindful about the current cyberthreat landscape and cybersecurity, and cultivate next generation R&D engineers. They will also form tight bonds between professionals from different sectors and cultures. Of course, it will take at least one year for students to bring back what they learn to their organizations and make reforms for better IT/OT balance. Still, this is a positive step forward for Japan and the world’s cybersecurity. Unfortunately, almost all information about these projects is only available in Japanese, but this is definitely worthy of a global audience.
No screens, no candies, no toys, no instant gratification. Thousands of kids at The Tech Challenge 2017 wanted something more. They wanted to try their hand at being engineers.
On April 29, a few colleagues from Palo Alto Networks and I volunteered to be judges at The Tech Museum of Innovation’s signature event, held in the heart of Silicon Valley in downtown San Jose, California. As judges, we had the honor of interacting with fourth- to sixth-graders. They captivated us with their approach to engineering, problem-solving and iterative experimentation. There is something spectacular about interacting with kids who are so passionate about innovatively combining technology and building with their hands, rather than interacting with technology only through computers and mobile devices.
This year’s The Tech Challenge centered on the theme of “Rock the Ravine.” Months prior to the event, students in grades 4–12 were presented with the challenge to design a device to help explorers cross an ice field with multiple ravines. More than 2,500 students responded to this year’s challenge with innovation, teamwork and healthy doses of creativity.
Insights From The Tech Challenge
By spending a day with the young developers, each of the other volunteer judges and I walked away with valuable lessons. Here are a few of mine:
Don’t assume there aren’t developers among our elementary school students. One of the most impressive teams I met was two sixth-grade girls, “The Flaming Firebirds” (seen going through the judging process in the photo below), who built their project from the ground up – and hacked technology to make it work the way they needed. They custom wrote the code necessary for the project to come together, and they won “Best Overall 1st Place” (for all of Grade 6) through their planning, ingenuity and creativity!
All kids should be encouraged to get involved. We should encourage as many kids as possible to get involved in events like this, even if engineering isn’t an area of passion. The spirit of what this event is about builds a strong foundation for a variety of professions that look well beyond STEM. Participating children were able to hone valuable life skills like imaginative problem-solving, prototyping, iterating, failing fast and recovering, documenting failures and successes, sharing responsibility, paying attention to safety, setting goals, planning projects, researching, and so much more that will serve them well no matter where their paths lead them.
Adults and parents can benefit too. As a father of three girls, I am constantly struggling with the question, “What kind of projects should I do with the kids that are fun and engaging, and will help them later in life?” The Tech Challenge gives parents a structured means to bring their children along on a journey that is rewarding, challenging and teaches fundamentals that are core to problem-solving.
The Tech Challenge started 30 years ago and has been inspiring kids to find solutions to real-world problems, such as harnessing the wind to move water to people who need it – and even beyond Earth, such as creating solutions to deploy scientific instruments from spacecraft to asteroids. The raw wonder of young minds is refreshing. The final products these students have developed are truly remarkable.
I look forward to competing in next year’s The Tech Challenge with my girls, and I know they will absolutely love it. To our future innovators: let the learning begin!