SPECIAL SUPPLEMENT BY
TRENDS FOR CYBER AND INDUSTRIAL SECURITY EXECUTIVES
MARCH 2019
ABUBAKAR ARSHAD, HEAD OF INFORMATION SECURITY
BATELCO
ALIGNING DIGITAL AND CYBER SECURITY STRATEGIES Top challenges l coping with incidents l skills shortages l technology evolution
Kamel Heus, Centrify
Kevin Flynn, Tenable
Anton Chuvakin, Gartner
Mahmoud Mounir, Secureworks
Harish Chib, Sophos
Michael Madon, Mimecast
CREDENTIAL HARVESTING FOR USER NAMES AND PASSWORDS
REVAMPING ORGANISATIONAL SECURITY THROUGH CYBER EXPOSURE
ARRIVAL OF THE NEW BREED OF SECURITY THREAT HUNTERS
MOVING FROM PERIMETRE PROTECTION TO END POINT PROTECTION
HOW DEEP LEARNING IS ENHANCING ENDPOINT DETECTION, RESPONSE
EMPLOYEES AND EMPLOYERS STRUGGLE WITH CYBERSECURITY NORMS
www.btxshow.com
APRIL 2019 SAUDI ARABIA
BAHRAIN
KUWAIT
OMAN
TRANSFORMATION IN
SECURITY NETWORKING BUSINESS APPLICATIONS IT & COMPUTING BROUGHT BY
OFFICIAL MEDIA PARTNERS
CONTENTS MARCH 2019
06
08
10
TOP OF MIND
TOP OF MIND
TOP OF MIND
Integrating security processes with business processes
Credential harvesting for user names and passwords
Revamping organisational security through Cyber Exposure
26
12
TOP EXECUTIVE
YOU CANNOT SECURE A HOUSE WITH OPEN DOORS
DEEP DIVE Moving from perimetre protection to end point protection
14
DEEP DIVE How deep learning is enhancing endpoint detection, response
16
18
30
32
TRENDING
CISO TALKS
VENDOR TALKS
36
44 HANDS-ON Integrating access control, plate recognition, video, analytics Genetec Version 5.8
46 DEEP DIVE
CHANNEL TEAM
Employees and employers struggle with cybersecurity norms
Expansion and growth through vendor extension services
AFTER THOUGHT Arrival of the new breed of security threat hunters
REAL LIFE
38 Founded by Siemens, Charter of Trust members reaches 18
39 Siemens suppliers must be cyber security compliant
40 Honeywell provides integrated security for new Cairo
41 Key takeaways from Cosmos Bank breach in India
03
M A R C H 2019
Discover the Edge.
Smart Solutions. Real Business. Rittal solutions for the technology of the future. Edge computing enables enormous amounts of data to be processed directly at the place where they arise. Securely and in real time. Rittal prepares you and your IT infrastructure for new challenges - exibly, economically, and globally.
Visit us at
Sheikh Rashid Hall Stand SR-E2
For Enquiries:
Rittal Middle East FZE Tel: +971-4-3416855 I Email: info-it@rittal-middle-east.com I www.rittal.com/uae-en
MANAGING DIRECTOR: TUSHAR SAHOO
EDITORIAL
CEO: RONAK SAMANTARAY DIRECTOR: ANUSHREE DIXIT anushree@gecmediagroup.com EDITOR: ARUN SHANKAR arun@gecmediagroup.com
The roll-over of businesses into a modern day, customer facing delivery model, built on digital technologies and digital experiences, has wide scale implications, both for the heads of information technology and cyber security, namely CIOs, CTOs and CISOs. Clearly there is a challenge of adoption and switch over, as in any transition. However, there is a much bigger, underlying and not so visible, expectation and evolutionary pressure, and that is to align, perform and deliver. In this issue of Cyber Sentinels, revamped from quarterly to monthly, Batelco’s Head of Information Security, Abubakar Arshad, spins the wheel into the challenges and priorities of a chief information security officer, as their organisation navigates the waters of digital and business transformation. Interviewed by Divsha Bhat, Arshad points out that his primary challenges are evolution of technologies and alignment of an organisation’s digital strategy with the cyber security strategy. Next in line is accurately gauging the implications of a major cyber incident and how it can affect the on-going cyber strategy. And the third is having suitable resources in cyber security while developing necessary talent. Rather than trying to protect a house with open doors, Arshad’s longer-term outlook is to have the right security architecture in place. ARUN SHANKAR He points out that vendors need to pay more Editor attention towards security by design, while arun@gecmediagroup.com channel partners need to look at the whole portfolio of security. While CISOs needs to work hard at understanding technology changes and the business impact of those changes. Fascinating reading! In this issue we also develop the ongoing dialogue and expectations between cybersecurity vendors and CISO end users. Two new sections, Vendor Talks and CISO talks, draw out responses from each side on potential day to day challenges and how they need to be addressed. No pre-rehearsed conversations here, thought leadership and experience will stand out, and may the best come back to write and share again. Another interesting, pick of the lot is the recent announcement by Siemens to ensure that its suppliers comply with minimum security requirements. The announcement states that, the goal is to better protect the digital supply chain against hacker attacks. In this regard, Siemens is following the course laid down by the Charter of Trust for cybersecurity. These requirements will apply primarily to suppliers of security-critical components such as software, processors and electronic components. An overdue role model in progress. Happy reading and look forward to seeing you at Gisec 2019. Arun Shankar arun@gecmediagroup.com. ë
SUB EDITOR: DIVSHA BHAT divsha@gecmediagroup.com EVENTS EXECUTIVE: SHRIYA NAIR shriya@gecmediagroup.com SALES EXECUTIVE: MOHAMMED MUBIN mubin@gecmediagroup.com BUSINESS DEVELOPMENT EXECUTIVE: SUSAN PAUL susan@gecmediagroup.com GROUP SALES HEAD: RICHA S richa@gecmediagroup.com + 971 529 943 982
VISUALIZER: MANAS RANJAN LEAD VISUALIZER: DPR CHOUDHARY DESIGNER: AJAY ARYA ASSISTANT DESIGNER: RAHUL ARYA, DEEPAK KUMAR
SUBSCRIPTIONS INFO@GECMEDIAGROUP.COM SOCIAL MARKETING & DIGITAL COMMUNICATION YASOBANT MISHRA yasobant@gecmediagroup.com
DESIGNED BY
PRINTED BY AL GHURAIR PRINTING & PUBLISHING LLC. MASAFI COMPOUND, SATWA, P.O.BOX: 5613, DUBAI, UAE
I N FO M E DIA PUBLISHED BY ACCENT INFOMEDIA MEA FZ-LLC PO BOX : 500653, DUBAI, UAE 223, BUILDING 9, DUBAI MEDIA CITY, DUBAI, UAE PHONE : +971 (0) 4368 8523 31 FOXTAIL LAN, MONMOUTH JUNCTION, NJ - 08852 UNITED STATES OF AMERICA PHONE NO: + 1 732 794 5918 A PUBLICATION LICENSED BY INTERNATIONAL MEDIA PRODUCTION ZONE, DUBAI, UAE @COPYRIGHT 2013 ACCENT INFOMEDIA. ALL RIGHTS RESERVED. WHILE THE PUBLISHERS HAVE MADE EVERY EFFORT TO ENSURE THE ACCURACY OF ALL INFORMATION IN THIS MAGAZINE, THEY WILL NOT BE HELD RESPONSIBLE FOR ANY ERRORS THEREIN.
M A R C H 2 019
05
TOP OF MIND
INTEGRATING SECURITY PROCESSES WITH BUSINESS PROCESSES Leigh McMullen and Paul Proctor at Gartner explain a business can move forward when cyber security processes are aligned and understood by executives. #2 HELP EXECUTIVES WITH DECISIONS THROUGH FOCUSED RISK ASSESSMENTS Start with a business process and conduct interviews with the people who execute that process. Offering executives decision-making in the context of operational outcomes makes these engagements more than interesting to them. It directly impacts the decisions they make. You are now helping them do their job.
#3 CREATE DEFENSIBILITY FOR YOUR EXECUTIVES LEIGH MCMULLEN,
PAUL PROCTOR,
RESEARCH VICE PRESIDENT, GARTNER.
VICE PRESIDENT DISTINGUISHED ANALYST, GARTNER.
Experiences shape the way we feel and act. This is why Ritz-Carlton offers highly-personalised service. They know the value of customer experience and have made it central to their business model. It is time for security and risk. Today, the battleground for the digital industrial revolution is the customer experience. Security should not wreck the customer experience, but it often does. For security and risk leaders, the customer is anyone in their enterprise. Long focused on operational excellence, such leaders must now work to create an effortless customer experience for their business executives. This can mean giving up control, which leads to the nexus of a culture clash. Your customers want the effort they put in, to match the value they expect to get. If you deliver the wrong experience, they will just tune you out. If you can improve their comfort and understanding of risk and security, you can help your company move faster. That is truly a business value of security. Five things security and risk leaders can do now to create a better experience for their executives.
#1 SPEAK TO EXECUTIVES ABOUT THINGS THAT MATTER TO THEM
06
M A R C H 2019
Talk to business leaders about what is important to them. Do not assume you know. Remember, it is about what they think matters. Ask the question: What types of decisions do you make every day. The answer can provide lots of insights. Show them how their business outcomes are directly dependent on technology.
KEY TAKEAWAYS n
THE BATTLEGROUND FOR
DIGITAL INDUSTRIAL REVOLUTION IS CUSTOMER EXPERIENCE. n
SECURITY SHOULD NOT WRECK
THE CUSTOMER EXPERIENCE BUT IT OFTEN DOES. n
FOR SECURITY AND RISK LEADERS
THE CUSTOMER IS ANYONE IN THEIR ENTERPRISE.
Executives do not directly control technology security and risk. But when things go wrong, they are usually held accountable. They need defensibility. We have treated security like a dark art for so long that when an organisation gets hacked, people do not understand. You cannot guarantee the organisation will not get hacked, so stop selling your executives protection, and start selling something they truly need, defensibility.
#4 TAKE TECHNOLOGY OUT OF CONVERSATIONS Your ability to put decisions in terms of business outcomes is critical to your success in a modern risk-based world. Do not talk about security and risk in only technology terms. Although technology will always be a part of the conversation, your partners need to understand what you are saying. Making risk and security transparent and business - aligned is an absolute requirement.
#5 MOVE FROM PROJECT TO PRODUCT MANAGEMENT Use product management to change the experience you deliver. Unlike project management, everything is continuous and typically organised around a business process and the IT requirements to support that process. Doing these five things will improve executive experience, their perceived value, and result in a better, more appropriately protected organisation. ë
TOP OF MIND
CREDENTIAL HARVESTING FOR USER NAMES AND PASSWORDS Threat actors are targeting end users for their credentials to penetrate networks and businesses must be proactive, explains Kamel Heus at Centrify. The recent Intersec 2019 held in January in Dubai had an interesting participant: an American company selling padlocks of increasing size and weight, guaranteed to be unbreakable. Today, threat actors are no longer intimidated by the size nor sophistication of the cyber security padlock. They are now looking for weak links - and in this case the weakest turns out to be the human element. Traditionally the threat actor has been looked at as someone who breaks the veritable software code - the code hacker. In present day times, the hacker now looks for the software defect that even its originators overlooked when they built or modified the business application - known as the zero-day vulnerability. Such threat actors who discover zero-day vulnerabilities and exploit them get their hefty investments either through the cyber-crime syndicates or are recruited by rogue nations targeting selected national infrastructures in target countries. But this is a long drawn out exercise, both in terms of time and effort, and is usually reserved for selected high-impact targets. Threat actors therefore target user credentials and, if the end user happens to be a network or system administrator or other privileged account holder, then that is always the luckiest break for them. Threat actors of all types and their associates are working to gather privileged access credentials in an activity now termed as credential harvesting. The 2018 Forrester Wave report for Privileged Identity Management points out that 80% of hacking-related breaches use either stolen,
default, or weak credentials. If these credentials are from a network or systems administrator or other privileged users, those stolen credentials can provide access to the veritable crown data jewels of the kingdom, inside the network. In short: hackers no longer hack in, they log in using compromised credentials. Here are some of the activities that can be planned by organisations:
AWARENESS OF PHISHING Users need to be shown the various types of phishing emails and other types of phishing tools like SMS and others. The more rigorous this training, the better for employee awareness and long-term stability.
PROTECT AND DOUBLE PROTECT
KAMEL HEUS, REGIONAL DIRECTOR, NORTHERN, SOUTHERN EUROPE, MIDDLE EAST AND AFRICA, CENTRIFY.
KEY TAKEAWAYS n
THREAT ACTORS ARE WORKING TO GATHER PRIVILEGED ACCESS IN AN ACTIVITY
TERMED AS CREDENTIAL HARVESTING. n
2018 FORRESTER WAVE REPORT FOR PRIVILEGED IDENTITY MANAGEMENT POINTS
OUT 80% OF HACKING-RELATED BREACHES USE STOLEN OR WEAK CREDENTIALS. n
08
HACKERS NO LONGER HACK IN, THEY LOG IN USING COMPROMISED CREDENTIALS.
M A R C H 2019
Administrators need to segregate the network based on corporate sensitivity and value of data and operations. This is called vaulting and the administrators area needs to have maximum security and protection.
REDUCE ATTACK SURFACE Top-to-bottom hierarchical privileges, logical workflow access, and just in time privilege requirements are some of the best practices to implement.
MULTI-FACTOR AUTHENTICATION Using another authenticator besides a password to verify an identity or an exception login instance is one of the most effective ways to secure against credential hacking. A Ponemon study indicates that the average amount of time required to identify a data breach by the end user organisation is 197 days, and the average amount of time needed to contain a data breach once it is identified is 69 days. That is a lot of time for a rogue actor to be floating inside a corporate network. Time for action!! ĂŤ
TOP OF MIND
REVAMPING BUSINESS SECURITY THROUGH CYBER EXPOSURE Tenable’s Kevin Flynn explains how five basic principles of Cyber Exposure can help CISOs align with business and revamp organisational security. In our work with IT and cybersecurity professionals, we often hear about the challenges of protecting all the isolated applications and the distributed computing and storage platforms in use throughout the enterprise. Organisations end up integrating applications through APIs and putting a multitude of clouds under a single management platform purview in order to manage the lot of them at once. It is no substitute for a holistic cybersecurity strategy which emphasizes visibility across the network and applies granular insights about the threats that may be lurking among them, so organisations can effectively prioritise responses. We call this approach Cyber Exposure. Cyber Exposure is an emerging discipline for managing and measuring cybersecurity risk in the digital era. Cyber Exposure transforms security from static and siloed visibility to dynamic and holistic visibility across the modern attack surface. Building a holistic cybersecurity strategy using the discipline of Cyber Exposure enables you to answer each of these four questions about your organisation at any point in time:
BALANCING SECURITY AND EXPOSURE
MAKING A PRIORITY LIST The answers to this question should be based on a combination of threat intelligence to understand the exploitability of the issue and asset criticality to understand the business context of the asset. Effective prioritisation of vulnerabilities needs to take in the business context in order to optimise your efforts, resources, and budget. It enables you to zero in on protecting the vulnerable areas likely to cost your organisation the most in terms of labor, penalties, time, recovery, and reputation.
EXPOSURE REDUCTION PLAN
KEVIN FLYNN,
SENIOR MANAGER PRODUCT MARKETING, TENABLE.
Answering this question requires visibility into all aspects of the organisation’s attack surface including cloud resources, containers, industrial control systems, and mobile devices, which may or may not be on the radar of IT. It involves taking inventory of where specific threats to your company exist.
KEY TAKEAWAYS n
CYBER EXPOSURE IS AN EMERGING DISCIPLINE FOR MANAGING AND MEASURING
CYBERSECURITY RISK IN THE DIGITAL ERA. n
CYBER EXPOSURE TRANSFORMS SECURITY FROM STATIC AND SILOED VISIBILITY TO
DYNAMIC AND HOLISTIC VISIBILITY ACROSS THE MODERN ATTACK SURFACE. n
CYBER EXPOSURE IS THE FOUNDATION UPON WHICH TO BUILD A CYBERSECURITY
STRATEGY THAT ACCOMMODATES THE ENTIRETY OF THE MODERN ATTACK SURFACE.
10
M A R C H 2019
Your ability to answer this question is a measure of your progress. You will need to identify the metrics and KPIs against which you will measure your efforts. Such metrics should be viewable by business unit, geography and asset type. The goal is to understand how your exposure profile is changing month to month, quarter to quarter, and year to year, so you can help your businessside colleagues and the c-suite understand whether the company’s investments in cybersecurity are paying off.
PEER TO PEER BENCHMARKING Answering this question forces you out of your company’s internal bubble to help you understand how your cybersecurity practices stack up against those of others in your field, as well as those in other industries. How your organisation ranks against industry peers, and against best-inclass security, is an important dialogue for every Board of Directors. Cyber risk is no different than other business risks and should be managed and measured the same way. Your ability to accurately answer these four questions is vital to understanding the total risk exposure and the effectiveness of your cybersecurity measures. But if you are dealing with a heavily compartmentalised IT infrastructure, it may seem daunting to know where to even start moving toward a more holistic strategy. ë
DEEP DIVE
MOVING FROM PERIMETRE TO END POINT PROTECTION Managed Detection and Response is the latest tools that bring together perimeter and endpoint telemetry, explains Mahmoud Mounir at Secureworks.
MAHMOUD MOUNIR,
REGIONAL DIRECTOR SECUREWORKS, META.
12
M A R C H 2019
DEEP DIVE
There is one phenomenon that makes cybersecurity both interesting and frustrating: Change. Constant, dispassionate, unpredictable change. Change brings new opportunities and disrupts existing strategies. One of the biggest changes in computer security in the past 10 years is the focus on the endpoint, as opposed to the network. As perimeter-based protection and detection strategies gained adoption, adversaries rethought their tactics to avoid these controls. Now perimeters are disappearing and endpoint-based visibility and control are critical. These changes bring two challenges. First, cybersecurity remains a developing area inside of many organisations. Most do not have a level of programme maturity that their risk profile requires. Second, many security practitioners do not have the tools or skills required to meet the threat. To address these challenges, organisations need to be more realistic about what they expect from their perimeter controls; they need faster adoption of advanced endpoint protection and detection technologies; and they must establish capabilities to perform investigations centered on the endpoint. For many organisations, these demands exceed their current and near-term resources of people, skills, and time. Security decision makers are seeking greater competency and specialised skills when selecting as-a-service security offerings and
KEY TAKEAWAYS n
NOW PERIMETERS ARE
DISAPPEARING AND ENDPOINT-BASED VISIBILITY AND CONTROL ARE CRITICAL. n
SECURITY LEADERS KNOW THAT THE
WHAT OF CYBERSECURITY IS MORE IMPORTANT THAN THE HOW. n
SECURITY LEADERS NEED TO GIVE
THEIR ORGANISATIONS CONFIDENCE THAT CYBER RISK CAN BE LIMITED AND MITIGATED TO ENABLE GROWTH. n
IT IS IMPORTANT TO REALISE THAT
REPEATABLE OUTCOMES ARE MORE VALUABLE TO MATURING A PROGRAMME THAN A TOOL THAT ALLOWS FOR ONE NEW CAPABILITY. n
SECURITY LEADERS WILL HAVE
TO NAVIGATE CHALLENGES IF THEY INCORPORATE A MANAGED DETECTION AND RESPONSE VENDOR INTO THEIR SECURITY PROGRAMME.
Managed Detection and Response services are often the best strategy. Managed Detection and Response aims to satisfy this client need by creating a service that brings together perimeter telemetry, advanced endpoint telemetry, and analysts who perform investigations. The end results are incident reports that approach the level of detail typically produced by very large in-house or outsourced security programmes. Managed Detection and Response solutions typically include these components:
ENDPOINT DETECTION AND RESPONSE Advanced endpoint security tools form the core of any Managed Detection and Response service. EDR tools quickly rose to prominence because they offered vastly superior detection and forensic capabilities than perimeter controls, traditional endpoint software, and OS or applications logs. However, EDR tools require additional skills and experience that many practitioners do not have.
PERIMETER TELEMETRY Perimeter controls still play an important role in Managed Detection and Response solution. Data from firewalls, IDS, IPS, WAFs, and network infrastructure like proxies are critical for confirming and expanding on what the endpoint reports. Managed Detection and Response service providers are able to correlate this data to more quickly investigate alerts. Faster investigation means that a Managed Detection and Response provider can provide better quality investigation in a shorter amount of time than most organisations can achieve on their own.
INCIDENT MANAGEMENT AND RESPONSE Anyone can douse a flame with water, but we do not all have the title of fire fighter. Serious security compromises should be rare occurrences. Therefore, it is unreasonable to expect in-house responders to match what a Managed Detection and Response vendor can provide for experts. Managed Detection and Response vendors are able to attract, retain, and utilise remote and in-field incident responders. The diversity of industries, threats, and events that these incident responders are exposed to likely make their value to an organisation far higher than an in-house responder with the same skill set.
THREAT INTELLIGENCE Threat Intelligence touches all parts of any
security services offering, but with a Managed Detection and Response service, the maximum value a vendor can provide is determined by that vendor’s threat intelligence gathering capability. Managed Detection and Response vendors must go beyond typical alerting to quickly provide the who, what, where, why, and how of a situation. The only way to do this without a lengthy incident response engagement is to have threat intelligence that is categorised by threat actor, tools, campaigns. When organisations with small security teams adopt Managed Detection and Response, they are able to reprioritise their day-to-day activities. They can focus on strategic or technical projects because detecting, alerting, and investigating L0-L2 security events are the vendor’s responsibility. The responsibility for the client starts to move from operational skills to risk management, communicating within the organisation, and being a champion for improving the organisation’s security posture based on legitimate business cases. The most qualified people to help a Managed Detection and Response vendor execute their service and to evaluate the quality of that service are the people who used to have those same responsibilities. Second, leadership will be required to take Managed Detection and Response findings and recommendations and use them to improve security posture. Managed Detection and Response vendors should be providing more insights into root cause of high-volume security events like opportunistic malware activity, exploit attempts on public facing resources. Those insights need to be mapped to risk and form the basis for policy or technology changes. Seasoned security leaders know that the what of cybersecurity is more important than the how. Security leaders need to give their organisations confidence that cyber risk can be limited and mitigated to enable growth. As more organisations develop or continue to invest in their cybersecurity programmes, it is important to realise that repeatable, predictable outcomes are more valuable to maturing a programme than a tool that allows for one new capability or a marginally better detection rate. Throughout our longstanding history in this still emerging industry, we have seen the adversary evolve in ways that outpace the traditional methodologies for prevention and detection. Managed Detection and Response helps deliver better outcomes by maximising visibility, reducing complexity and increasing speed response. It is a market-need driven offering that illustrates what the future of cybersecurity services looks like. ë
M A R C H 2 019
13
DEEP DIVE
HARISH CHIB, VICE PRESIDENT MIDDLE EAST AND AFRICA, SOPHOS.
KEY TAKEAWAYS n
THE HARDEST QUESTION FOR MOST
IT AND SECURITY TEAMS IS ARE WE SECURE RIGHT NOW. n
MOST NETWORKS HAVE SIZABLE
BLIND SPOTS THAT MAKE IT AND SECURITY TEAMS STRUGGLE TO SEE WHAT IS GOING ON. n
ORGANISATIONS STRUGGLE TO
UNDERSTAND THE SCOPE AND IMPACT OF ATTACKS. n
WHEN AN INCIDENT OCCURS,
THE TEAM ASSUMES THEY ARE SAFE BECAUSE THAT INCIDENT WAS DETECTED. n
DEEP LEARNING ENABLED
ENDPOINT DETECTION AND RESPONSE PROVIDES THIS ADDITIONAL INSIGHT AS WELL AS DETERMINES IF OTHER MACHINES WERE IMPACTED.
14
M A R C H 2019
DEEP DIVE
HOW DEEP LEARNING IS ENHANCING ENDPOINT DETECTION, RESPONSE Deep learning is helping CISOs answer whether they are secure now, by extending visibility of end point incidents, writes Harish Chib at Sophos.
Cybercrime is big business and hackers are continually looking for new attack vectors. SophosLabs team see 400,000 new malicious samples every day; this does not mean 400,000 programmers are writing code. It means heavily automated systems. The result is bespoke malware – a virus written just for you. With that reality, the best line of defense is to use a multi-layered security strategy to work to protect organisations against both known and unknown threats. The best endpoint technologies will protect organisations against the majority of malware and threats impacting their organisation. But as the threat landscape evolves and cybercriminals continue to morph attacks and work to find new security holes to access organisations, the unknown minority becomes important. Endpoint Detection and Response tools are about detecting that minority. Endpoint Detection and Response tools are built to supplement endpoint security with increased detection, investigation, and response capabilities. However, Endpoint Detection and Response tools can make it difficult to understand how exactly they can be used and why they are needed. Making matters worse, today’s Endpoint Detection and Response solutions often struggle to provide value for many organisations as they can be difficult to use, lack sufficient protection capabilities, and are resource intensive. The good news is deep learning enabled Endpoint Detection and Response tools provide the easiest way for organisations to answer the tough questions about security incidents. Here are ways how deep learning enabled Endpoint Detection and Response tools help organisations to add an additional layer to their security posture.
VIEW OF SECURITY POSTURE The hardest question for most IT and security
teams is are we secure right now? This is because most networks have sizable blind spots that make IT and security teams struggle to see what is going on inside their environments. Lack of visibility is the primary reason why organisations struggle to understand the scope and impact of attacks. This often manifests itself when an incident occurs and the team assumes, they are safe because that incident was detected. Deep learning enabled Endpoint Detection and Response provides this additional insight as well as determines if other machines were impacted. Generating a clear view of an organisation’s security posture provides the benefit of being able to report on compliance status. This information will help identify areas that may be vulnerable to attacks. It also allows administrators to determine if the scope of an attack has impacted areas where sensitive data is housed.
Endpoint Detection and Response can speed this up significantly. The first step an analyst might take during the incident response process would be to stop an attack from spreading. Analysts will often do this before investigating, buying time while they determine the best course of action. The investigation process can be a slow and painful one. This of course assumes an investigation occurs at all. Incident response traditionally relies heavily on highly-skilled human analysts. Most Endpoint Detection and Response tools also rely heavily on analysts to know which questions to ask and how to interpret the answers. However, with deep learning enabled Endpoint Detection and Response, security teams of all skill levels can quickly respond to security incidents thanks to guided investigations that offer suggested next steps, clear visual attack representations, and built-in expertise.
LAYER OF DETECTION
EXPERTISE WITHOUT HEADCOUNT
When it comes to cybersecurity, even the most advanced tools can be defeated given enough time and resources, making it difficult to truly understand when attacks are happening. Organisations often rely solely on prevention to stay protected, and while prevention is critical, Endpoint Detection and Response offers another layer of detection capability to potentially find incidents that have gone unnoticed. Organisations can leverage Endpoint Detection and Response to detect attacks by searching for indicators of compromise. This is a quick and straightforward way to hunt for attacks that may have been missed.
RESPONSE TIME Once incidents are detected, IT and security teams usually scramble to remediate them as fast as possible to reduce the risk of attacks spreading and to limit any potential damage. On average, security and IT teams spend more than three hours trying to remediate each incident.
By a large margin, organisations looking to add endpoint detection and response capabilities cite staff knowledge as the top impediment to Endpoint Detection and Response adoption. To combat the staff knowledge gap deep learning enabled Endpoint Detection and Response replicates the capabilities associated with hardto-find analysts. It leverages machine learning to integrate deep security insight, so organisations can add expertise without having to add staff.
HOW ATTACKS HAPPEN Threat cases, included with Endpoint Detection and Response, spotlight all the events that led up to a detection, making it easy to understand which files, processes, and registry keys were touched by the malware to determine the impact of an attack. More importantly, by understanding the root cause of an attack, the IT team will be much more likely to prevent it from ever happening again. ë
M A R C H 2 019
15
DEEP DIVE
EMPLOYEES AND EMPLOYERS STRUGGLE WITH SECURITY NORMS Company devices are being used for personal Internet activities during office hours signaling a disconnect explains Michael Madon at Mimecast.
MICHAEL MADON,
SVP AND GM, MIMECAST SECURITY AWARENESS.
16
M A R C H 2019
DEEP DIVE
Employees are increasingly using companyissued devices to complete their gift purchases while at work. Recent research from Robert Half Technology found that 75% of employees admitted to shopping during work hours on a company device on Cyber Monday and 23% spent even more time online bargain hunting while at the office. This data shows how critical it is for organisations to be aware of the risks that their employees pose throughout the holiday season, and beyond. To explore what today’s employees are doing during work hours when it comes to web usage, Mimecast surveyed more than 1,000 people who use company-issued devices that is mobile phones, desktop computers or laptops in the workplace. This allowed us to get a better sense of
KEY TAKEAWAYS n
THE TOP THREE PERSONAL USE
CASES ARE READING THE NEWS 53%, CHECKING PERSONAL EMAIL 33% AND BROWSING SOCIAL MEDIA 23%. n
CYBERATTACKS ARE THE NUMBER
ONE BUSINESS RISK IN NORTH AMERICA, YET NEARLY ONE-IN-FOUR EMPLOYEES ARE NOT AWARE OF THE MOST COMMON THREATS. n
JUST 45% OF MODERN BUSINESSES
PROVIDE MANDATORY FORMAL CYBERSECURITY TRAINING, DESPITE HUMAN ERROR BEING ONE OF THE MOST COMMON CAUSES OF SECURITY INCIDENTS. n
MANY COMPANIES ARE RELYING ON
RATHER ARCHAIC AND INEFFECTIVE PRACTICES, MOST COMMON APPROACH REVOLVES AROUND AN EMAIL OR PRINTED LIST OF TIPS AND REMINDERS.
not only their behavior, but also their awareness of basic threats plaguing organisations. We also inquired about how much—if any—cybersecurity awareness training they’ve received from their employer. Here is what we found: Cyberattacks are the number one business risk in North America, yet we found that nearly one-in-four employees are not aware of the most common threats plaguing today’s organisations— such as phishing attacks, impersonation attempts and ransomware. Additionally, 15% of respondents admit they could either be more cautious or just completely trust that the emails being sent to their devices are safe from any type of threats. In an age where one wrong click from a single employee can compromise a company’s entire infrastructure, these are rather alarming numbers. When we asked what they use their companyissued device for, more than two-thirds 69% said in-part for non-work-related activities. The top three personal use cases are reading the news 53%, checking personal email 33% and browsing social media 23%. Additionally, nearly 28% use their companyissued device for personal reasons for at least one hour per day, with the number rising to 40% among younger workers 18-24, year-olds. Shockingly, one-in-10 employees are using their devices for personal reasons for more than four hours per day. In addition to wasting valuable time at work, personal use of corporate devices presents security concerns. It is extremely difficult for employers and IT departments to know exactly what these individuals are clicking, browsing and engaging with each work day. So, employees are ultimately to blame for making hackers’ jobs easier, right? Well, not exactly. Let us take a look at what employers themselves are or are not doing to help the cause. Cybersecurity and awareness training are missing in a time when it is needed most. According to our findings, nearly 60% of employees either are not aware of their companies having a formal policy on their personal web use at work, or there is not one in place at all. In fact, just 45% of modern businesses provide mandatory formal cybersecurity training, despite human error being one of the most common causes of security incidents. Another 10% offer this type of training as optional. Additionally, amongst those businesses that do offer cybersecurity training and education in some capacity kudos to the brave few. Just 6% provide trainings monthly, while 4% do so quarterly, 9% of the respondents stated they
had only received formal cybersecurity training during the onboarding process when they started their job. As we drilled down a little deeper, many companies are relying on rather archaic, and frankly ineffective, practices. The most common approach revolves around an email or printed list of cybersecurity tips and reminders 33%. This is followed by issuing proactive prompts around safe and unsafe links 30% and interactive best practices videos 28%.
WHAT DOES THIS ALL MEAN? It could indicate that businesses are inherently trusting their employees to know what, and what not, to click on, and to be smart when it comes to browsing the web—for both professional and personal reasons. It could also mean that today’s organisations simply do not have the resources or know-how to implement formal cybersecurity and awareness training. And with cyberthreats continuing to evolve so they can bypass traditional security methods, like anti-virus and anti-spam filters, it is essential organisations integrate cybersecurity awareness training into their overall cyber resilience strategy. For organisations looking to kick-start, or refresh, their cybersecurity education practices, a few simple tips can make all the difference:
BE PERSISTENT A one and done approach is not enough. It is important to keep reiterating to employees what they need to be aware of when it comes to cyber threats and best practices to spotting malicious messages, websites. Do not try to get every bit of training out of the way in a single onboarding class or annual refresher session. Instead, teach in short bursts of no more than a few minutes.
MAKE IT MANDATORY Training should be provided at 30-day intervals. More importantly, after you train once or twice, do not stop there—make it a consistent, mandatory, company-wide practice.
MAKE IT FUNNY The easiest way to lose your audience is by making the training boring, irrelevant, and worst of all, forgettable. Incorporating personalities, recurring characters and relatable content can go a long way toward the content having a lasting impact. This is a perfect time for businesses to institute formal cybersecurity awareness training and education practices to defend against one of the biggest threats – themselves. ë
M A R C H 2 019
17
TRENDING
Tenable announces integrated solution covering IT and OT environments
RAY KOMAR, VICE PRESIDENT OF TECHNICAL ALLIANCES, TENABLE.
TENABLE ECOSYSTEM NOW SUPPORTS 50 INTEGRATIONS, 39 TECHNOLOGY PARTNERS
RENAUD DERAISON, CO-FOUNDER AND CHIEF TECHNOLOGY OFFICER, TENABLE.
Tenable, announced an integrated Cyber Exposure solution to provide a unified view of cyber risk spanning information technology networks and operational technology, from enterprise applications to industrial control systems. Security leaders can rely on a single platform to measure, manage and reduce cyber risk across both IT and OT environments with Tenable Industrial Security now integrated with Tenable.sc formerly SecurityCenter for vulnerability management on-premises. When used with industrial security, Tenable.sc solves this problem by delivering clarity into an organisation’s converged IT OT environments. Tenable.sc leverages industry-leading Nessus scanners to gather a wealth of security-related information from IT-based assets on OT and IT networks. Tenable.sc then combines that information with passively collected asset and vulnerability data from Industrial Security, which provides safe, reliable asset discovery and vulnerability management purpose-built for OT environments. Expanded OT Asset Coverage, includes coverage of several thousand new devices from leading industrial manufacturers, such as Yokogawa and Emerson. These new manufacturers join the top ten leading industrial manufacturers, including Siemens, Schneider, Rockwell Allen-Bradley, Honeywell, Mitsubishi and others, whose devices are already covered by Industrial Security. “The interconnectedness of digital infrastructure today means the security of IT directly impacts OT, and vice versa. Without a single, unified view into converged IT OT environments, CISOs are basically being asked to defend their organisations blindfolded and with one arm tied behind their backs. It is bad cyber strategy and it places the business at serious risk,” said Renaud Deraison, Co-founder and Chief Technology Officer.
18
M A R C H 2019
Tenable, announced that the company more than doubled its Cyber Exposure Ecosystem throughout 2018, including 43 new or enhanced technology integrations and 20 new integration partners. The ecosystem now supports a total of 50 integrations and 39 technology partners. Tenable’s market-leading integration partners span some of the most widely deployed Security and IT technologies, including industry-leading Privileged Access Management, SIEM, IT Ticketing and Configuration Management Database solutions. Together, these integrated solutions accelerate the time-to-detect and remediate issues through a greater breadth of visibility across the modern attack surface, depth of analytics, and integrated data and workflows fostering better collaboration across Security and IT Operations teams. “Organisations today are struggling to manage and connect the dots between the dozens of disparate security tools in their environments,” said Ray Komar, Vice President of Technical Alliances. “We are committed to partnering with other industry leaders to help organisations address their cyber risk holistically through an integrated ecosystem that addresses each stage of the Cyber Exposure lifecycle.” Through Tenable’s open platform, partners of all sizes can easily integrate their solutions into the Cyber Exposure ecosystem. Additionally, Tenable’s dedicated integrations team works with technology partners to ensure integrations are consistently updated to maintain compatibility and to take advantage of the latest product capabilities. A sample of new and enhanced integrations across the Tenable.sc and Tenable.io platforms include: Atlassian, Cisco, CyberArk, Palo Alto Networks, ServiceNow, Splunk, amongst others.
TRENDING
Trend Micro detects flaws in industrial machinery RF controllers Trend Micro released a new report detailing inherent flaws and new vulnerabilities in radio frequency remote controllers found and disclosed through the Zero Day Initiative. The report, A Security Analysis of Radio Remote Controllers for Industrial Applications, demonstrates how an attacker could persistently and remotely take control of, or simulate the malfunction of, the attacked machinery. The report’s findings cover RF remote controllers found in cranes, drills, mining machinery and other industrial devices produced by the seven most commonly deployed vendors. These types of devices have become a major point of security weakness because of their connectivity. Long lifespans, high replacement costs, and cumbersome patching processes compound this problem. Trend Micro discovered three basic failings
in RF controllers: no rolling code; weak or no cryptography; and a lack of software protection. Leveraging these basic weaknesses enabled five remote and local attack types, which are detailed in the report. To help facilitate the research, an RF analysing tool, RFQuack, was also developed. “This research demonstrates a concerning reality for owners and operators of heavy industrial machinery where RF controllers are widely found,” said Bill Malik, VP of Infrastructure Strategies for Trend Micro. “By testing the vulnerabilities our researchers discovered, we confirmed the ability to move full-sized industrial equipment deployed at construction sites, factories, and transportation businesses. This is a classic example of both the new security risks that are emerging, as well as how old attacks are being revitalised, to attack the convergence of OT and IT.”
BILL MALIK, VP OF INFRASTRUCTURE STRATEGIES FOR TREND MICRO.
TELCOS CAN LEVERAGE 5G HOME PROTECTION SUITE FROM TREND MICRO
TREND MICRO CONSUMER CONNECT COMBINES ENDPOINT PROTECTION, NETWORK DEFENSE, DATA SECURITY CAPABILITIES.
Trend Micro, announced a comprehensive security suite designed for telecom companies to deploy to better protect their users. This suite protects customers’ whole digital life against known and unknown threats by laying a virtual security layer around devices. Trend Micro Consumer Connect is scalable, easy to integrate and
20
M A R C H 2019
simple to deploy, adding a competitive advantage for leading telecom providers. With 5G set to drive a new era of IoT adoption, telecoms have a unique opportunity to add value by protecting their customers. Trend Micro research predicts an IoT worm war will emerge this year, as hackers compete to compromise
home devices including routers, conscripting them into botnets like the notorious Mirai campaigns that led to some of the biggest DDoS attacks ever recorded. Trend Micro Consumer Connect combines endpoint protection, network defense and data security capabilities, leveraging Trend Micro’s industry leading Smart Protection Network for global threat intelligence. A handy smartphone app provides visibility and control where users need it most, enabling them to check which devices are protected. It protects against ransomware, zero-day threats, info-stealing trojans, crypto-mining, and other online threats designed to compromise IoT endpoints, covering all smart home devices plus PCs and mobiles. Features include: simple API-based integration into the partner’s infrastructure and processes; flexible solution to align to customers’ needs; a security dashboard to help partners better understand their customers; exceptional support throughout the customer journey; and built-in marketing toolkits to drive ARPU and business growth.
should be a fundamental right for every organisation!
ERICOM SOFTWARE IS A LEADER IN SECURING & CONNECTING THE DIGITAL WORKSPACE Ericom's offerings include innovative remote browser isolation, secure remote access & zero trust browsing solutions
TRENDING
Centrify relooks at Zero Trust approach for cloud base security
MATRIX RANSOM NOTES ARE EMBEDDED IN THE ATTACK CODE, BUT VICTIMS DO NOT KNOW HOW MUCH THEY MUST PAY UNTIL THEY CONTACT THE ATTACKERS.
SOPHOS ANNOUNCES MATRIX NEW RANSOMWARE FAMILY THAT USES RDP
TIM STEINKOPF, CEO OF CENTRIFY.
Centrify, announced new cloud-ready solutions to help stop the leading cause of data breaches, privileged credential abuse. Centrify Zero Trust Privilege helps customers grant least privilege access based on verifying who is requesting access, the context of the request, and the risk of the access environment. In addition, the company has successfully integrated the Centrify Privileged Access Service with SailPoint’s open identity platform, IdentityIQ, easing the coordinated adoption of Zero Trust Privilege and Identity Governance best practices. Organisations may consider approaching Privileged Access Management by solely implementing password vaults, a legacy approach that leaves gaps which can easily be exploited. In today’s environment, privileged access not only covers infrastructure, databases, and network devices but is extended to cloud environments, Big Data projects, and DevOps, and must secure hundreds of containers or microservices. By implementing zero trust privilege, Centrify minimises the attack surface, improves audit and compliance visibility, and reduces risk, complexity and costs for the modern, hybrid enterprise. The old way of securing critical enterprise resources simply will not work in today’s diverse and sophisticated IT environments. Zero Trust assumes bad actors are already inside the network, hunting for privileged accounts and credentials that help them gain access to an organisation’s most critical on-premises and cloud infrastructure, as well as sensitive data. According to a recent survey of 1,000 IT decision makers, 74% of data breaches involved privileged credential abuse. Organisations must embrace a Zero Trust mandate of never trust, always verify, enforce least privilege, to minimise the risk of falling victim to a data breach. “The solutions we are announcing today take a big step forward in redefining legacy PAM to secure access to modern attack surfaces with Zero Trust Privilege,” said Tim Steinkopf, CEO of Centrify.
22
M A R C H 2019
Sophos, released a new report about a ransomware family called Matrix. The malware has been operating since 2016 and Sophos has tracked 96 samples in the wild. Like previous targeted ransomware, including BitPaymer, Dharma and SamSam, the attackers who are infecting computers with Matrix have been breaking in to enterprise networks and infecting those computers over Remote Desktop Protocol, a built-in remote access tool for Windows computers. However, unlike these other ransomware families, Matrix only targets a single machine on the network, rather than spreading widely through an organisation. SophosLabs reverse engineered the evolving code and techniques employed by the attackers, as well as the methods and ransom notes used to attempt to extract money from victims. The Matrix criminals evolved their attack parameters over time, with new files and scripts added to deploy different tasks and payloads onto the network. Matrix ransom notes are embedded in the attack code, but victims do not know how much they must pay until they contact the attackers. For most of Matrix’s existence, the authors used a cryptographically-protected anonymous instant messaging service, called bitmsg.me, but that service has now been discontinued and the authors have reverted to using normal email accounts. The threat actors behind Matrix make their demand for cryptocurrency ransom in the form of a US dollar value equivalent. This is unusual as demands for cryptocurrency normally come as a specific value in cryptocurrency, not the dollar equivalent. It is unclear whether the ransom demand is a deliberate attempt at misdirection, or just an attempt to surf wildly fluctuating cryptocurrency exchange rates. Based on the communications SophosLabs had with the attackers, ransom demands were for $2,500, but the attackers eventually reduced the ransom when researchers stopped responding to demands.
Protect Your Information Wherever It Travels
Data Classification, DLP, and CASB only solve part of your data security challenge. Seclore Data-Centric Security makes it easy to unify your best-of-breed solutions and automatically add granular usage controls as information is discovered, classified, and shared. Ensure your information is protected and trackable wherever it travels with Seclore.
We look forward to showing you Seclore Data-Centric Security in action during the Future of IT Summit 2019, Dubai
www.seclore.com
TRENDING
Palo Alto’s Unit 42 identifies Windshift as targeted Middle East attack
UNIT 42 WAS ABLE TO IDENTIFY ATTACKER ACTIVITY AND CAN NOW PROVIDE SPECIFIC DETAILS ON A TARGETED WINDSHIFT ATTACK AS IT UNFOLDED AT A MIDDLE EASTERN GOVERNMENT AGENCY.
In August of 2018, DarkMatter released a report, which unveiled a threat actor with tactics and techniques very similar to those of Bahamut. Pivoting on specific file attributes and infrastructure indicators, Unit 42 was able to identify and correlate additional attacker activity and can now provide specific details on a targeted Windshift attack as it unfolded at a Middle Eastern government agency. As seen from the timeline, the Windshift activity observed by Unit 42 falls between January and May of 2018. The first attack occurred in early January of 2018 with an inbound Windtail sample, the backdoor family used by Windshift originating from the remote IP address 109.235.51[.]110 to a single internal IP address within the government agency. As per the timeline, at the time this event occurred, the IP address 109.235.51[.]110 was associated with the domain flux2key[.]com, a known Windshift domain. Upon further analysis, Unit 42 determined the sample’s corresponding C2 server IP address was 109.235.51[.]153. At the time this event occurred, that IP was associated with the domain string2me[.]com, which is a known Windshift
24
M A R C H 2019
domain. While Unit 42 does not have any insight into the attempted infection methodology in this case, the actor’s tactics and techniques would suggest that spearphishing was almost certainly involved. After the initial infection attempt, several additional Windtail samples from the same external IP address, 109.235.51[.]110, were directed at the same internal IP address from January through May of 2018. All related Windtail samples were Mac OSX app bundles in zip archives, which is consistent with Windshift TTPS. By analyzing this attack in detail, Unit 42 was able to gain valuable insight into the real-world tactics and techniques of a known threat actor group. Of particular importance are the following findings: Unit 42 assesses with high confidence that both the IP address 185.25.50[.]189 and the domain domforworld[.]com is associated with Windshift activity. Additionally, the IP addresses 109.235.51[.]110 and 109.235.51[.]153, corresponding to the previously validated Windshift domains flux2key[.]com and string2me[.]com, respectively, were also observed in use during this campaign.
The attacker-owned IP address 109.235.50[.]191 was subsequently identified in a Norman Security report from as being associated with Hangover threat actor activity, and both IP addresses 109.235.51[.]110 and 109.235.50[.]191 shared the name XENEUROPE within their organizational registrant WHOIS information. This organizational name is tied to a number of IP addresses of Hangover-associated infrastructure as per the Norman report. Collectively, this evidence serves to strengthen the implication from other security researchers that Operation Hangover and Windshift activity are possibly related. Based on Unit 42’s observations of multiple inbound Windtail samples directed at the same internal IP address, Unit 42 assesses with moderate confidence that the attackers were not able to establish persistence within the targeted environment. While Unit 42 cannot definitively determine the attempted delivery vector of these samples, Windtail tactics and techniques would indicate that it was likely standard spearphishing chicanery.
veritas.com | +971 4 279 2600
Today, companies are digitally transforming at an ever-more-rapid pace. Keeping up requires absolute confidence in information and a solution that facilitates new ways to re-invent processes and engage customers. Companies need a reliable way to sort through these immense changes and mountains of data to reach clarity.
Reveal the truth in information.
TOP EXECUTIVE
YOU CANNOT SECURE A HOUSE WITH OPEN DOORS Building organisational security on the basis of formidable design, speaking language of business, and aligning digital and cyber security strategies, are amongst top priorities for Abubakar Arshad.
n B Y: D I V H S A B H AT < D I V S H A @ G E C M E D I A G R O U P. C O M >
A
CHALLENGES
sation today is immune to cyber incidents and how you react and communicate in case of such a huge incident can affect the profitability and reputation of the organisation. The third challenge would be having suitable resources in cyber security. In between the growing demand for cybersecurity individuals and professionals, the biggest concern would be to fill in the right positions at the right time and also to be able to develop necessary talent in terms of cybersecurity.
“These are the number of things that would be at the top of the agenda for a typical CISO of a large organisation. In today’s digital world, a Chief Information Security faces multiple challenges in their day to day job role,” reflects Abubakar Arshad, Head of Information Security, Batelco. The evolution of technologies is one of the biggest challenges. As we are moving towards cloud transformation along with newer technologies like artificial intelligence, to keep up with these changes is one of the biggest challenges. Alignment of the organisation’s digital strategy with the cyber security strategy in view of growing complexities of cyber threats, is one of the biggest concern areas for a CISO. The second one is accurately gauging the implications of a major cyber incident and how it can affect the on-going cyber strategy. It is one of the challenges because no organi-
Firstly, a CISO truly needs to understand the business environment of the organisation and needs to tie the business environment to the necessary security requirement, to tailor the security and to enable the organisation to conduct its business securely over the digital space. The second thing is to be able to adequately communicate with the senior management the requirements of security and the key concerns related to security. Until the senior management does not buy into the security vision and strategy, they would not be able to support it. And each time you want to have some initiatives implemented in the organisation, you need to have the right buy-in from the stakeholders. “Right from the CEO, the chairman, the board to get a
s Head of Information Security at Batelco, Abubakar Arshad is responsible for security governance, security strategy, cloud transformation initiatives of the organisation, as well as developing the enterprise security architecture. Overall, he is involved in the security governance and management practice of Batelco.
26
M A R C H 2019
BUSINESS AND MANAGEMENT
TOP EXECUTIVE
ABUBAKAR ARSHAD, HEAD OF INFORMATION SECURITY, BATELCO.
M A R C H 2 019
27
TOP EXECUTIVE
Be cloud ready since the organisation is on a journey towards cloud transformation.
Build an enterprise security architecture so that design is in the right place and in the right manner.
Work on developing a long-term resource strategy to build talent resources rather than recruitment.
KEY TAKEAWAYS n
THE EVOLUTION OF TECHNOLOGIES
IS ONE OF THE BIGGEST CHALLENGES. n
FIRST STEP IS TO HAVE THE RIGHT
SECURITY ARCHITECTURE RATHER THAN PROTECTING A HOUSE WITH OPEN DOORS. n
VENDORS NEED TO PAY MORE
ATTENTION TOWARDS SECURITY BY DESIGN. n
PARTNERS NEED TO LOOK AT THE
WHOLE PORTFOLIO OF SECURITY. n
CISOS NEEDS TO BE WELL VERSED
WITH TECHNOLOGY CHANGES AND UNDERSTAND THE BUSINESS IMPACT OF THOSE CHANGES.
28
M A R C H 2019
buy-in support is extremely important for security. So, a CISO truly needs to have that,” stresses Arshad. Also, a CISO needs to be well versed with the technology changes and understand the business impact of those technology changes. Because if they do not get that understanding, they would not be able to take the right decisions that enable business or support business. Essentially you need a technologist at heart. Someone who is a technologist but understands business in a manner that can truly add value to the business stakeholders.
RELOOK AT DIGITAL Digital Transformation is slightly different from typical digitisation. For example, migrating paperwork over to a digital medium is a typical example of digitisation, that is slightly different from complete digital transformation of an organisation where you re-engineer business processes to maximise the value of digital ecosystem that is available to you. Another example, cloud transformation has not only the potential in terms of efficiency, but it gives us an opportunity to completely re-engineer and redesign business processes. So not only does digital transformation help in terms of efficiency, but it also opens up new revenue streams for organisations and new business opportunities for organisations. And that truly is the value of digital
transformation for organisations.
INDUSTRY EXPECTATIONS A lot of consultants need to start with the basics to be able to design security. The first step is to have the right security architecture design in order to have the right security approach, rather than protecting a house with open doors. They should be able to provide solutions and advise based on security by design; they should be able to architect the right security and focus on various different solutions in order to respond first; and finally detect complex security stress. “That is one of the key areas lacking with the vendors. They might have great bits and pieces of solutions for protecting and detecting cyber incidents, but much of these security incidents happen because of fundamental design flaws in the organisation itself,” he points out. From that perspective, vendors need to increasingly pay more attention towards security by design and then move on to other areas like incident detection and response capabilities. Channel partners and consultants need to look at the whole portfolio of security and not be lopsided and focus on one area of security only. While incident detection and response are today’s buzzword, we cannot ignore the overall picture of security. Security needs to be built through the right basics. ë
CISO TALKS
With the multitude of cybersecurity solutions, what is the process of due diligence that you follow in the selection of the most suitable solution and the most suitable vendor for your organisation. Security vendors pose this question for CISOs to answer. Here is what they have to say
VIMAL MANI,
PARVEZ AHMED,
INFORMATION SECURITY OFFICER, BANK OF SHARJAH.
CISO AT EMIRATES NETS SYSTEM.
The due diligence process below is recommended to look into the following aspects: functionality of the solution proposed by the supplier, including whether the products features meet the end user requirements or not; price versus worthiness of the solution; security posture of the product and whether the product is free from all sorts of vulnerabilities or not; technical ability of the vendor; quality and timeliness of support proposed; flexibility of support terms and conditions; market reputation of the solution vendor; verifiable references from other implementation sites. ë
30
M A R C H 2019
As per an organisation’s various predefined processes, the business case is developed, along with options for consideration, including business strategy, benefits, timescales, costs, return on investment and risk. An organisation can also conduct a proof of concept, and identify compatibility and interoperability of the cybersecurity solution with existing environment. They can also identify product features that are meeting these requirements, as well as mitigation of cyber risk. The steering committee can review these reports and take a decision regarding the product and vendor. For third party selection, the assessment needs to be based on reputational, financial, legal, product reports submitted by the third party. ë
CISO TALKS
IF YOU PREPARE FOR IT WITH PREVENTIVE MAINTENANCE YOU WOULD END UP WITH LESS INCIDENTS OR LESS IMPACTFUL ONES.
AYAD (ED) SLEIMAN, INFORMATION SECURITY AND TECHNOLOGY MANAGER, KING ABDULLAH UNIVERSITY OF SCIENCE AND TECHNOLOGY.
KEY TAKEAWAYS n
AS PER AN ORGANISATION’S
VARIOUS PREDEFINED PROCESSES THE BUSINESS CASE IS DEVELOPED. n
FOR THIRD PARTY SELECTION,
THE ASSESSMENT NEEDS TO BE BASED ON REPUTATIONAL, FINANCIAL, LEGAL, PRODUCT REPORTS. n
THE URGENCY IN WHICH
PROCUREMENT IS APPROACHED OVERSTEPS PROPER PLANNING BASED ON RISK MANAGEMENT PRINCIPLES.
CISOs rush to the market to purchase these technical controls that they believe may be the silver bullet and cure to all of their problems. The urgency in which procurement is approached oversteps proper planning based on risk management principles. CISOs could be better off if they plan their purchases properly and not react to the latest cyber breach they hear about. Much like owning a house, preventive maintenance could save some headaches. Fixing items that break in your house, like your air-conditioning, is like responding to a security incident after it happens. You will be breached one day and cannot be avoided. If you prepare for it with preventive maintenance, you would end up with less incidents or less impactful ones. Planning starts with creating a strategy driven by your information security policy. The strategy objectives should be clearly outlined so that you can create a three to five-year roadmap to achieve them. A continual risk management exercise needs to be conducted. A pre-requisite is the existence of a risk management framework and policy that defines the organisation’s risk appetite. Anything that falls above the risk appetite needs a control to be identified. You then need to prioritise the risks by the rating of the residual risk from critical to low. This will allow you to prioritise the set of controls needed based on risk and provides justification for your management when you are asking for a budget. Your management may provide you a budget to purchase controls for the top three risks, or may be top ten risks. Make sure they accept the remaining risks at least temporarily for the current year, if they cannot supply the budget and human resources for it this year. This control can be a process, people, or technology. If it is technology, a solution needs to be identified to reduce the risk. Choosing a control among the list of controls available in the market can be painful and lengthy. In order to shorten that cycle and make it less painful, pick the top three vendors selling this technical control by looking at one of the top data analyst firms like Gartner’s Magic Quadrant, or IDC’s MarketSpace, or Forrester’s Wave. This saves a lot of time and money. A pre-requisite to meeting with these vendors is defining your exact requirements and coming up with a set of questions to uniformly ask each. Once that is completed, score the vendors based on technical compliance, after which you can solicit financial bids. The next step is tricky. If your organisation selects the best price regardless of the winner of the technical bid, then you are doomed. Sometimes, you can work around that by selecting the best technical proposal and conducting a proof of concept first. If the proof of concept is successful, you can solicit three or more bids from the vendor’s partners and have your procurement select the best price. ë
M A R C H 2 019
31
VENDOR TALKS
With medium and large organisations, using multiple cloud business application platforms, as public, private, or hybrid deployments, what are your recommendations for CISOs to build an end to end, cloud security access and monitoring management solution, thereby increasing the ability to extend corporate security policies into the extended business cloud environment. CISOs pose this question for industry vendors to answer. Here is what the vendors have to say:
GIHAN KOVACS, ENTERPRISE SALES MANAGER UAE, FORCEPOINT.
Forcepoint is assisting enterprises and governments on their digital transformation journey by enabling secure migration of data, applications, and business operations to the cloud. For cloud security specifically, organisations could consider implementing a Cloud Access Security Broker, or CASB. A CASB secures data flowing in and out of cloud vendor environments by enforcing a company’s compliance policies, but that is not where it truly shines. You need crystal clear visibility into the related end-users, data, and apps. You must be able to answer questions like, where is my data in the cloud? and more importantly, where is my data most at risk in the cloud? CASBs do exactly that, offering a consolidated view of sanctioned and unsanctioned cloud service usage along with data regarding who is accessing what data, on what device, and from what location. And when paired with data loss prevention, CASBs can help foster closed loop monitoring and controls over user interactions with data. There is a plethora of other benefits to using a CASB. In fact, security teams getting the most out of their CASBs are using their analytics capabilities to gain insight into risk via behavior, using the reporting features to see company-wide trends and deviations from safe behaviors. ë
KEY TAKEAWAYS n
JUST BECAUSE A SYSTEM HAS BEEN MOVED TO THE CLOUD, DOES NOT MEAN ITS
RISKS HAVE CHANGED. n
SINCE IT IS NOT YOUR COMPUTING ENVIRONMENT RISKS HAVE ACTUALLY INCREASED
AND TRAFFIC PATTERNS MUST BE MONITORED. n
USE YOUR CLOUD ACCESS SECURITY LAYER AND A PLATFORM THAT ULTIMATELY
UNIFIES YOUR POLICY AND THREAT IDENTIFICATION APPROACHES.
32
M A R C H 2019
VENDOR TALKS
HAIDER PASHA, SENIOR DIRECTOR AND CHIEF SECURITY OFFICER, EMERGING MARKETS, PALO ALTO NETWORKS.
In today’s evolving digitised environment, CISOs need to plan for a broader security strategy. They need to realise that their new perimeter is where their data lives and they need to focus on securing their data which may reside within mobile devices, private cloud, SAAS, or public cloud environments. Storing your data with another entity - cloud service providers, really boils down to trust, control and visibility. In order to regain each of those attributes, CISOs need to rely on a Zero Trust approach that extends to the cloud, an ability for them to limit access to sensitive data by micro-segmenting, applying least-privilege access, and inspecting all the relevant traffic to ensure continuous compliance. With the right tools, CISOs should be able to build a complete end-to-end cloud security access and management platform. They would do this by focusing firstly on all inline traffic capabilities that can protect and segment cloud workloads. They would also need to protect the hosts in the cloud with technologies that can secure the OS and applications within those workloads. To ensure compliance and security are maintained, they should focus on working with an open API-based solution that can integrate new cloud solutions with the same speed and agility the cloud offers. Tools such as CASB, VFWs, Identity, Cloud DLP Compliance, Host-based protection and automated Security Orchestration Response should all be leveraged and integrated into their cloud security fabric. CISOs can deploy each of these capabilities as they achieve cloud maturity from maintaining hybrid to multi-cloud and SAAS solutions. ë
KEY TAKEAWAYS n
MOVING TO THE CLOUD OFTEN REQUIRES YOUR ORGANISATION TO CLEAN UP YOUR
IDENTITY DIRECTORY TO BE READY FOR SHARED SIGN-ON. n
HOW THE OVERALL SECURITY POSTURE IS AFFECTED DEPENDS ON THE LEVEL OF
DILIGENCE THAT GOES INTO ONBOARDING NEW CLOUD PROVIDERS. n
ENSURE YOUR COMPANY REQUIRES BUSINESS UNIT EXECUTIVES TO APPLY OR
ACCEPT THE RISK OF COMPLIANCE OBLIGATIONS.
M A R C H 2 019
33
VENDOR TALKS
JOHN HATHAWAY, REGIONAL VICE PRESIDENT, MIDDLE EAST AND INDIA, BEYONDTRUST.
With medium and large organisations, using multiple cloud business application platforms, as public, private, or hybrid deployments, there are a few recommendations for CISOs to consider when building an end to end cloud deployment. Decide on the acceptable user policy for sensitive data stored in the cloud. This data is your crown jewels and must be treated with tighter security than when it existed on premises. Decide on the access policies required to access sensitive data and applications. Standard credentials, username and password pairs should never be used alone in the cloud. Consider adding Two Factor Authentication or Multi Factor Authentication for all cloud operational, administrative, and management accounts. Decide on your network architecture for the cloud. This includes, zones, micro-services, containers, instances, applications, hypervisors, others. Then decide how you are going to isolate each zone, configure ACLs, and implement segmentation. Most importantly collect logs and events to a SIEM to trace all normal and abnormal behavior to determine a threat. Just because a system has been moved to the cloud, does not mean its risks have changed. In fact, since it is not your computing environment, they have actually increased and traffic patterns must be monitored regardless of source and destination. Perform the following cyber security basics for all cloud computing environments: vulnerability management, patch management, and privileged access management, to ensure the lowest hanging attack vectors are not available to threat actors. ë
KEY TAKEAWAYS n
CONSIDER ADDING MULTI FACTOR AUTHENTICATION FOR ALL CLOUD OPERATIONAL,
ADMINISTRATIVE, AND MANAGEMENT ACCOUNTS. n
YOUR LEGAL TEAM SHOULD BE A PART OF THE INITIAL PURCHASE DECISIONS,
ARMED WITH TECHNICAL KNOWLEDGE TO HELP IDENTIFY POTENTIAL ROGUE CLOUD SERVICES. n
IT IS IMPORTANT TO KNOW AN ORGANISATION’S COMPLIANCE ARE NOT MITIGATED
SIMPLY BECAUSE THE DATA HAS LEFT YOUR INTERNAL ENVIRONMENT.
34
M A R C H 2019
VENDOR TALKS
TAJ EL-KHAYAT,
SCOTT MANSON,
MENA REGIONAL DIRECTOR, CITRIX.
MANAGING DIRECTOR, MIDDLE EAST AND TURKEY, MCAFEE.
In this work from anywhere era, cloud computing offers a new way of delivering computing resources instantly, on-demand and inexpensively. But enterprises face increasing challenges meeting various compliance and regulatory requirements applicable to them. Here are tips on building an end-to-end security and monitoring solutions: create a secure bridge and access between cloud and enterprise data centre; ensure secure networking and monitoring; maintaining a unified cloud and data centre view; security process monitoring and updating. To assure the adequacy of their risk mitigation strategy and implementation, network and host activity must be monitored to identify policy violations, anomalous behavior, unauthorised configurations and other risky conditions. This can be done by log monitoring and SIEM tools that can quickly identify, classify, escalate report and guide responses to security events. As the lines between one application and another continue to blur, certain components of an application may continue to execute in the enterprise data centre even though the majority of the app may be hosted in the cloud. Or, the inverse can be true. In these cases, security and associated application management services running in the cloud should be extensible to cover components running in the enterprise data centre and vice versa. This is distinct from security monitoring as it focuses on whole security process and not current security events. This includes services like vulnerability scanning, and penetration testing as well as threat monitoring and analysis. ë
Whether you are switching up your multi-cloud strategy or starting from scratch, here are a few things your organisation needs to know first about multi-cloud. These include: determining what features will either make or break your multi-cloud strategy; security measurements are important when architecting a multi-cloud structure; ensuring compliance; secure a buy-in from executive and C-level on a multi-cloud strategy. For a successful multi-cloud migration, use your cloud access security layer and a platform that ultimately unifies your policy and threat identification approaches. Moving to the cloud at scale often requires your organisation to clean up your identity directory to be ready and accommodating of shared sign-on. By using an identity management and aggregation platform to expose identity to well-known cloud services, you will be able to ease the cloud implementation burden and threat exposure of any given provider. Organisations will often upgrade in some areas of basic security, when making the move to well-known cloud providers. How the overall security posture is affected depends heavily on the level of diligence that goes into onboarding new cloud providers. Implementing critical technical measures like the Cloud Access Security layer and policy around how the cloud is procured and technically implemented should drive basic control requirements. Initially, ensure that your company requires business unit executives to apply or accept the risk of compliance obligations where service providers may not have every requirement. Your legal team should be a part of the initial purchase decisions, armed with technical knowledge to help identify potential rogue cloud services and policy guidelines that dissuade employees from adding services on a credit card without appropriate oversight. It is important to know that your organisation’s compliance requirements are not mitigated or transmuted simply because the data has left your internal environment and entered the one your cloud provider uses. As your organisation gains more experience with the cloud, request that providers share copies of the SSAE16 attestations audits. This, together with more formal due diligence processes, should become commonplace. ë
M A R C H 2 019
35
CHANNEL TEAM
SPECTRAMI
EXPANSION AND GROWTH THROUGH VENDOR EXTENSION SERVICES Spectrami has grown its value-added services for channel partners acting as an extension of vendors in the region and across countries.
ANAND CHOUDHA,
CHIEF EXECUTIVE OFFICER, SPECTRAMI.
36
M A R C H 2019
UAE headquartered, security and niche, value added distributor, Spectrami started its operations in 2011. The specialist distributor is headed by Chief Executive Officer, Anand Choudha. Since 2011, Spectrami has expanded operations across the region into multiple other countries. Spectrami now operates in UK, Germany, Austria, Netherlands, UAE, Kuwait, Oman, Saudi Arabia, Bahrain, Qatar, Turkey and Egypt. Its full portfolio of security and niche solutions covers the following areas: Application Delivery Controller, Continuous Attack Validation, Deceptive Technology, Enterprise Mobility Management, Network and Application Layer Security, Open Source Intelligence, Open Source Solutions, Privileged Identity Management, Secure Sharing, Security Information and Event Management, Threat Detection, Threat Intelligence, User Behaviour Analytics, Vulnerability Management, amongst others. In order to deliver these solutions, Spectrami has partnered with various vendors including A10 Networks, Anomali, AttackIQ, Attivo Networks, Authologics, Blackberry, CA Technologies, Cloudera, Cofense, Contrast Security, cpacket, Crowdstrike, Cubro, Fidelis, Flashpoint, Galaxykey, Intel 471, Logrhythm, Microfocus, Osirium, Pulse Secure, Red Hat, Savvius, Shadow Dragon, Swimlane, Tenable, Titus, ZeroFox, amongst others. Choudha indicates that Spectrami creates a differentiation in the market based on the following strengths covering customer experience, operational excellence, ethical compliance, strategic go-to-market opportunities, collabora-
tive leadership, market agility, diverse portfolio, passion for winning, value added services, and focused execution. One key differentiator of Spectrami is its Vendor Extension Model. Explains Choudha, “Through this model, we help our customers and partners with enterprise solutions including but not limited to multi-point engagement from sales, pre-sales, marketing, delivery, logistics and channel fulfillment, which are at par with vendor benchmarks.” Choudha divides the vendor extension model into four sectors including information security, networking, applications, and niche solutions. The vendor extension model faces the channel partners, delivers customer engagement, technical and marketing services. A key reason for Spectrami’s rapid geographic expansion has been its go to market activities with vendor and channel partners. In the last 12 to 18 months, Spectrami has conducted multiple road shows with multiple vendors and key channel partners. This includes: Anomali customer event in UK; Channel enablement workshop with Cofense, Anomali, GalaxyKey; Innovera event in Turkey; Insight Information Security convention; ISACA events in Abu Dhabi and Dubai; MENA event with Anomali and Virtuport; Micro Focus demo event with MOI and ISYX; Pulse Secure channel event; Red Hat Forum in Riyadh; Shield Event in Turkey; UAE Army roundtable with ITQAN and Tenable, Anomali, Attivo Networks. Spectrami also completed a number of its own events including Spectrami and Innovative
CHANNEL TEAM
SPECTRAMI HAS EXPANDED OPERATIONS ACROSS THE REGION INTO MULTIPLE OTHER COUNTRIES.
ONE KEY DIFFERENTIATOR OF SPECTRAMI IS ITS VENDOR EXTENSION MODEL.
KEY TAKEAWAYS n
DUBAI SME RATING FRAMEWORK
HAS GIVEN SPECTRAMI AN A-RATING RECOGNIZING ITS PERFORMANCE AS A SMALL AND MEDIUM ENTERPRISE. n
ONE KEY DIFFERENTIATOR OF
SPECTRAMI IS ITS CHANNEL FACING, SVENDOR EXTENSION MODEL. n THE FULL PORTFOLIO OF SPECTRAMI’S VALUE ADDED SERVICES INCLUDES SECURITY AND NICHE SOLUTIONS. n
SPECTRAMI’S FULL PORTFOLIO OF SECURITY AND NICHE SOLUTIONS COVERS MULTIPLE AREAS.
KEY REASON FOR SPECTRAMI’S
GEOGRAPHIC EXPANSION HAS BEEN ITS GO TO MARKET ACTIVITIES WITH VENDOR AND CHANNEL PARTNERS.
Solutions Techcafe including Logrhythm and Tenable; Spectrami Customer Event in Dubai with Anomali, Micro Focus, ZeroFOX, Titus; Spectrami Cybersecurity forum in Saudi Arabia with IDC; Spectrami Tech workshop with MOI with Micro Focus in Abu Dhabi; Spectrami Techcafe Cofense, Crowdstrike, Micro Focus; Spectrami Techcafe in Kuwait with Cofense, Crowdstrike, Micro Focus; Spectrami Techcafe with Attivo Networks, Cofense, Micro Focus;
amongst others. Amongst its recognitions, Dubai SME Rating has given Spectrami an A-rating recognising its performance as a small and medium enterprise. As a value-added distributor Spectrami has also received recognition from Pulse Secure and A10 Networks, while continuing its exemplary performance and raising the bar for the rest of the field. ë
M A R C H 2 019
37
REAL LIFE
FOUNDED BY SIEMENS, CHARTER OF TRUST MEMBERS REACHES 18 Key global players in the Charter include Airbus, Allianz, Atos, Cisco, Daimler, Dell Technologies, Deutsche Telekom, IBM, NXP, SGS, Total and TÜV Süd.
JOE KAESER,
CEO OF SIEMENS.
The recent Intersec 2019 held in January in Dubai had an interesting participant: an American company selling padlocks of increasing size and weight, guaranteed to be unbreakable. Today, threat actors are no longer intimidated by the size nor sophistication of the cyber security padlock. They are now looking for weak links - and in this case the weakest turns out to be the human element. At the Munich Security Conference in February 2018, nine organisations signed the world’s first joint charter for greater cybersecurity. A year on, the Charter of Trust has grown to 16 members. In addition to Siemens and the Munich Security Conference, the signatories include AES, Airbus, Allianz, Atos, Cisco, Daimler, Dell Technologies, Deutsche Telekom, Enel, IBM, NXP, SGS, Total and TÜV Süd. Now, the Charter of Trust welcomes two government authorities to its ranks as associate members for the very first time: the BSI German Federal Office for Information Security, which is one of the most relevant institutions for cybersecurity experts and the CCN National Cryptologic Center of Spain. CCN is an agency of the Spanish State annexed to the National Intelligence Center. In addition, the Graz University of Technology in Austria will be joining the charter as an associate member. The team there focuses on cybersecurity research and for instance was one of the teams that discovered
38
M A R C H 2019
the IT vulnerabilities Meltdown and Spectre. The associate partner is a new format, through which the Charter is opening up for important government representatives, universities and think tanks for cooperation. A benefit to such organisations is that they can cooperate on specific projects without having to become full members with all rights and duties. An area of early and intense focus has been security of supply chains. Third-party risks in supply chains, are becoming a more prevalent issue and are the source of 60% of cyberattacks, according to Accenture Strategy. Charter of Trust member companies have worked out baseline requirements and propose their implementation for making cybersecurity an absolute necessity throughout all digital supply chains. These requirements address all aspects of cybersecurity – including people, process and technology. Examples of these requirements include: l Data shall be protected from unauthorised access throughout the data lifecycle. l Appropriate level of identity and access control and monitoring, including third parties, shall be in place and enforced. l A process shall be in place to ensure that products and services are authentic and identifiable. l A minimum level of security education and training for employees shall be regularly deployed.
Charter of Trust members are establishing a risk-based methodology for implementing these requirements in their own supply chains, involving supply chain partners in the process. In 2018 Charter of Trust round tables worldwide opened up an in-depth exchange between policy makers and the Charter partners. Governments and industry are aligning at the global, regional and national levels in the pursuit of common security goals. According to the Center for Strategic and International Studies, threats to cybersecurity in 2018 caused 500 billion euros in losses worldwide. And threats to cybersecurity are constantly on the rise as the world digitalises further: according to Gartner, 8.4 billion networked devices were in use in 2017 – 31% more than in 2016. The figure is expected to rise to 20.4 billion by 2020. “In the age of the Internet of things, cybersecurity is a crucial task. Our Charter of Trust Initiative is a very important first step,” said Joe Kaeser, CEO of Siemens. “We are open to many more partners. Cybersecurity is the key enabler for successful digital businesses as well as protecting critical infrastructure. We hope that this initiative will lead to a lively public awareness and, ultimately, to binding rules and standards.” ë
REAL LIFE
SIEMENS SUPPLIERS MUST BE CYBER SECURITY COMPLIANT From February 2019, Siemens suppliers providing components for control units, will need to comply step-by-step with binding cybersecurity requirements.
New Siemens suppliers must comply with minimum binding cybersecurity requirements, which will be introduced step-by-step starting in February 2019, and anchored in a separate, binding clause in all new contracts. These requirements will apply primarily to suppliers of security-critical components such as software, processors and electronic components for certain types of control units. Existing suppliers who do not yet comply with the requirements are to implement them gradually. The goal is to better protect the digital supply chain against hacker attacks. In this regard, Siemens is following the course laid down by the Charter of Trust for cybersecurity. The requirements stipulate, for example, that suppliers must integrate special standards, processes and methods into their products and services. The reason: to prevent vulnerabilities and malicious codes at suppliers – and thus in Siemens products as well. In the future, suppliers themselves must, for example, perform security reviews, conduct tests and take corrective action on a regular basis. Siemens is making these requirements mandatory for its own activities as well. In the fall of 2018, Siemens further strengthened its internal capacities for repelling hacker attacks and restructured its cyber organisation. Operating as a worldwide network, the new unit combines what were once separate areas. As a result, Siemens is now the first major company to take a holistic approach to the topic of cybersecurity. Not only does the new Siemens organisation investigate, analyse and repel hacker attacks; it also develops new cybersecurity services and teams up with the company’s business units to launch these services on the market. The goal is to react to attacks with even greater speed and flexibility. In every region and at every division, the company has also strengthened its network of cybersecurity managers, who now report to Natalia Oropeza, Siemens’ Chief Cybersecurity Officer. Siemens has been active in the field of cybersecurity for about 30 years.
ROLAND BUSCH,
MEMBER OF SIEMENS’ MANAGING BOARD AND THE COMPANY’S CHIEF OPERATING OFFICER AND CHIEF TECHNOLOGY OFFICER.
KEY TAKEAWAYS n
SIEMENS IS THE FIRST MAJOR
COMPANY TO TAKE A HOLISTIC APPROACH TO THE TOPIC OF CYBERSECURITY. n
NEW SIEMENS SUPPLIERS MUST
COMPLY WITH MINIMUM CYBERSECURITY REQUIREMENTS, WHICH WILL BE INTRODUCED IN FEBRUARY 2019. n
THESE REQUIREMENTS WILL
APPLY TO SUPPLIERS OF SECURITYCRITICAL COMPONENTS SUCH AS SOFTWARE, PROCESSORS, ELECTRONIC COMPONENTS. n
EXISTING SUPPLIERS WHO DO NOT
YET COMPLY WITH THE REQUIREMENTS ARE TO IMPLEMENT THEM GRADUALLY.
Its first cybersecurity team was established back in 1986. “This step will enable us to reduce the risk of security incidents along the entire value chain in a holistic manner and offer our customers greater cybersecurity,” said Roland Busch, Member of Siemens’ Managing Board and the company’s Chief Operating Officer and Chief Technology Officer. “If all our partner companies put their global weight behind these measures and implement them together with their suppliers, we can generate tremendous impact and make the digital world more secure.” ë
M A R C H 2 019
39
REAL LIFE
HONEYWELL PROVIDES INTEGRATED SECURITY FOR NEW CAIRO Honeywell is implementing Integrated Command and Control Centre for new Cairo smart city integrating video feeds over wireless and providing analytics for crowd, traffic, theft, people, objects.
KEY TAKEAWAYS n
HONEYWELL WILL DEPLOY CITY-
WIDE SECURITY AND SURVEILLANCE SYSTEMS AS PART OF THE FIRST PHASE OF DEVELOPMENT. n
IN COLLABORATION WITH MTI,
HONEYWELL WILL INTEGRATE SECURITY ACROSS THE CAPITAL INTO A SINGLE POINT OF CONTROL. n
THE INTEGRATED COMMAND AND
CONTROL CENTRE WILL PROVIDE UNIFIED PUBLIC SAFETY SERVICES, COORDINATING SECURITY RESPONSE UNITS, CITY POLICE AND MEDICAL DISPATCH. n
THE CONTROL CENTRE WILL
CONNECT VIDEO FEEDS FROM MORE THAN 6,000 IP CAMERAS OVER A WIRELESS NETWORK.
Khaled Hashem, Honeywell’s President for Egypt and Libya, appears with General Eng Mohamed Abd Allatief, ACUD General Manager.
Egypt’s new administrative capital will feature public safety and security infrastructure following an agreement signed between the Administrative Capital for Urban Development, ACUD and Honeywell. The new capital, one of the world’s largest smart city projects, is being built in three phases, 45 kilometers east of Cairo and will expand to cover more than 700 square kilometers once complete. Honeywell will deploy city-wide security and surveillance systems as part of the first phase of development, in collaboration with its partner MTI, to integrate security systems across the capital into a single point of control, known as an Integrated Command and Control Centre, ICCC.
40
M A R C H 2019
The contract was signed in Cairo by General Eng Mohamed Abd Allatief, ACUD General Manager and Khaled Hashem, Honeywell President for Egypt and Libya in the presence of Deputy Head of Information Systems Department ISD, General Hesham Shendy and US Chief of Mission and Chargé d’Affaires, Thomas H Goldberger. The Integrated Command and Control Centre will integrate advanced Internet of Things, IoT software and hardware solutions onto one common platform for a holistic city view that provides unified public safety services, coordinating security response units, city police and medical dispatch. The control centre will also connect video
feeds from more than 6,000 IP cameras over a futureproof wireless network, and run sophisticated video analytics to monitor crowds and traffic congestion, detect incidents of theft, observe suspicious people or objects, and trigger automated alarms in emergency situations. The technology deployed at the New Capital will include Honeywell’s cyber security systems. The Integrated Command and Control Centre has already been successfully implemented across smart city projects in India. Honeywell is playing a defining role in the growth of India’s 100 Smart Cities. The agreement reinforces Honeywell’s commitment to developing smart cities in Egypt, and
REAL LIFE
A group photo including Honeywell, ACUD, MTI and others.
The Control Centre will run video analytics to monitor crowds, traffic, theft, suspicious people, objects, trigger automated alarms.
enabling effective skills and knowledge transfer in line with the goals of Egypt Vision 2030. The company’s diverse hardware and software solutions promote greater safety, security and energy efficiency for cities and buildings, and drive operational efficiencies by leveraging data analytics and cloud technologies. Operating from Cairo, Honeywell works with some of Egypt’s key government and private sector entities in the fields of smart cities, building automation, oil and gas, refining and petrochemicals, defense, aviation, infrastructure development, logistics, security and fire safety. The company has been present in Egypt for more than 50 years, and is committed to providing the
best talent and technologies to support development across Egypt’s major industries. “Honeywell is working with government entities across the region to help realise smart city visions. We have successfully played a role in deploying critical infrastructure in a number of countries such as India, where we have helped create smarter buildings and cities. We do this by turning buildings into smarter and responsive assets, and by bringing together knowledge, people and technology to create connected solutions. With our connected building solutions, we design, install, integrate and maintain the systems that help keep your facilities: safe and secure, comfortable, productive and energy efficient,”
explains Khaled Hashem, Honeywell President for Egypt and Libya. Continues Hashem, “We are strategic partners with state governments and local authorities to implement our Internet of Things - enabled citywide security and surveillance systems, including the installation of 10,000 closed-circuit televisions, emergency response solutions, automatic number plate reading system, and intelligent traffic management technologies at work in 65 cities and towns across the country. Our sensors capture data, analyse it, and turn it into information that enables better situational awareness for decision makers, aiding their smart city and surveillance goals.” ë
M A R C H 2 019
41
REAL LIFE
KEY TAKEAWAYS FROM COSMOS BANK BREACH IN INDIA Prior to the ATM switch malware attack, a global advisory had been issued about a possible ATM-cash out attack, explains Rajarshi Purkayastha at Tata Communications.
In August this year, Cosmos Bank became the latest victim of a major cyber-attack. Hackers breached the bank’s ATM switch server in Pune, India stealing details of multiple Visa and Rupay debit card owners. The details were then used to carry out around 12,000 fraudulent transactions across 28 countries on August 11, with a further 2,841 transactions taking place in India. The attack did not stop here. Two days later, on August 13th, in another malware attack on the bank’s server, a SWIFT transaction was initiated – transferring funds to the account of ALM Trading Limited in Hanseng Bank, Hong Kong. The total losses from the attack stand at INR 94 crore, or $13.5 million. Cosmos Bank was forced to close its ATM operations and suspend online and mobile banking facilities. How did the attack happen? MALWARE ATTACK The Core Banking System of the bank receives debit card payment requests via a switching system. During the malware attack,
42
M A R C H 2019
REAL LIFE
a proxy switch was created and all the fraudulent payment approvals were passed by the proxy switching system. ATMS COMPROMISED When depositors withdraw money at ATMs, a request is transferred to the respective bank’s Core Banking System. If the account has sufficient balance, the Core Banking System will allow the transaction. In the case of Cosmos Bank, the malware created a proxy system that bypassed the Core Banking System. While cloning the cards and using a parallel or proxy switch system, the hackers were able to approve the requests – withdrawing over INR 80.5 crore in approximately 15,000 transactions. GUIDELINES Reserve Bank of India has clear guidelines to protect against incidents such as the Cosmos Bank attack, which must be followed. The security measures across Indian banks are moderate and given the high level of coordinated international attacks, all banks need to upgrade their security mechanisms. GLOBAL THREAT Just a few days prior to this attack, the American FBI had warned banks of a major hacking threat to ATMs worldwide. According to Krebs On Security, the influential cyber-security blog run by journalist Brian Krebs, a confidential alert to international banks informed them that criminals were plotting an imminent, concerted global malware attack on ATMs. Smaller banks with less sophisticated security systems were believed to be most vulnerable to attack – with a scheme known as ATM cashout as the likely approach that the criminals might take. This is where crooks hack a bank or payment card processor and use cloned cards at ATMs around the world to fraudulently withdraw millions of dollars in just a few hours. Banking experts and industry players fear this
KEY TAKEAWAYS n
SMALLER BANKS ARE BELIEVED TO BE MOST VULNERABLE TO ATM CASH-OUT
ATTACKS n
THREAT ACTOR HACK A PAYMENT CARD PROCESSOR AND USE CLONED CARDS AT
ATMS TO FRAUDULENTLY WITHDRAW MILLIONS. n
BANKING EXPERTS AND FEAR THIS COULD BE A PILOT RUN UNLESS AUTHORITIES
TAKE THE ATTACK SERIOUSLY. n
THIS MALWARE ATTACK WAS NOT AGAINST ANY BANK BUT RATHER THE BANKING
SYSTEM. n
IT WAS CARRIED OUT AT INTERNATIONAL SCALE IN A METICULOUSLY COORDINATED
MANNER.
RAJARSHI PURKAYASTHA, HEAD OF PRODUCT AND SERVICES MARKETING, TATA COMMUNICATIONS.
could be a pilot run unless the authorities take the attack seriously. Essentially, this malware attack was not against any bank but rather, the banking system. It was carried out at international scale in a meticulously coordinated manner. PROTECTIVE MEASURES • To defend your company from the spread of malware, it is essential that you are equipped to detect and defeat such threat in real-time. • These are our recommended immediate best practices: • Back up data regularly, verifying data integrity and testing the restoration process. • Secure your offline backups, ensuring backups are not connected permanently to the computers and networks they are backing up on. • Audit firewalls, servers and Intrusion Prevention System configurations – block access to known malicious IP addresses and Server Message Block ports 139 and 445, and disable SMBV1 and Windows Management Instrumentation Command Line in servers and Active Directory. • Patch operating systems, software and firmware on devices, use a centralised patchmanagement system. • Scan all incoming and outgoing emails, detect threats and filter executable files from reaching end users using sandboxing. • Enable strong spam filters to prevent phishing emails, authenticate inbound email using technologies such as Sender Policy Framework. • Domain Message Authentication Reporting and Conformance, and Domain Keys Identified Mail to prevent spoofing. • Enterprises need to ensure that security is inbuilt end-to-end starting at the very beginning. Protecting your network should be the number one priority to safely extend your reach virtually anywhere. ë
M A R C H 2 019
43
HANDS-ON
INTEGRATING ACCESS CONTROL, PLATE RECOGNITION, VIDEO Genetec’s Version 5.8 ensures optimisation of the physical security environment as well as greater visibility and analytical trends into operations.
Mobile, camera: The new mobile application lets users pull up live camera feeds, door information and automatic license plate recognition events with a simple tap.
Mobile, map interface: Nearby cameras, doors and automatic license plate recognition units can easily be located using the new application’s map-based interface.
Mobile, messaging: Messages can be sent between mobile and desktop application users directly within the application, ensuring the operator’s focus stays on his task.
Genetec, a technology provider of unified security, public safety, operations, and business intelligence announced the launch of a new version of Security Center, the company’s open-architecture platform that unifies video surveillance, access control, automatic license plate recognition, communications, and analytics in the Middle East. Version 5.8 ensures that users can optimise their physical security environment while benefiting from greater visibility into their operations. The new version provides customisable live dashboards, enhanced privacy protection
features, brand-new map-driven mobile application, new functionalities to help users monitor the health of their system and ensure compliance with cybersecurity best practices,
using simple point-and-click tools, and instantly combine data from the entire Genetec portfolio video, access control, automatic license plate recognition, in one screen to gain a new perspective on the evolution of events and key metrics across their operations.
44
M A R C H 2019
CUSTOMISABLE LIVE DASHBOARD Security Center 5.8 will enable users to create custom dashboards that will display real-time data, such as video feeds, alarms, reports and charts in a way that is meaningful to them and their specific job function security, operations, IT, others. Users can set up their dashboards
MOBILE APPLICATION Security Center 5.8 will introduce a brand-new collaborative mobile application to provide operators complete access to their Security Center system when they are on the move and allow them to turn their smartphone into a valu-
HANDS-ON
Dashboard, campus access control: Dashboards let users mix data from their entire security environment with maps, charts and camera streams to build a unique experience tailored to their day to day.
Dashboard, security score: The new Security Score widget tracks the system’s compliance to cybersecurity best practices and guidelines, helping system administrators assess potential exposure to external threats.
Mobile, collaboration: Built-in messaging, live position tracking and video sharing helps field and office operators stay in sync.
able contributing sensor to their security system. In addition to recording incidents, accessing nearby video, access control, and automatic license plate recognition devices as well as sharing video from their phones to Security Center, the new mobile application will let operators share their location with colleagues in the operations center, send in-application messages and share live and recorded video through an intuitive map-oriented interface. Key features will include: l Video live and recorded playback, PTZ controls, bookmarking, time and event-based reports. l Access control check door status, lock, unlock doors, override schedule, set maintenance mode. l Automatic license plate recognition live reads, hits, plate reports, and access hotlists.
l Interactive maps that increase local awareness and put critical information much closer to the operators, enabling them to easily visualise their environment and respond quickly. l Built-in messaging allows for instantaneous sharing of information between operators and personnel in the field. l This extends to sharing live or recorded video clips, text messages and other security information.
SYSTEM RESILIENCE AND CYBERSECURITY System administrators are acutely aware of the critical nature of security systems, but often lack the tools to assess the potential exposure of their software, operating systems and physical security devices. Security Center 5.8 will introduce a new Security Score feature to track each system’s
compliance with hardening guidelines, firmware availability and updates, password strength, as well as several other dimensions of cybersecurity. Available through the built-in System Health dashboard, the Security Score will measure individual cybersecurity processes and verify that they are followed by the system. This will enable users to get a better understanding of the cyber security risks they face and enable them to take the necessary steps to harden their system. With the new KiwiVision Camera Integrity Monitor feature, the system will also automatically detect potential camera position changes, loss of image quality or tampering, and alert administrators immediately. This allows them to get ahead of problems and take the necessary corrective action immediately, rather than wait to find out there is a problem when they need footage and it is not available.
PRIVACY The new version of Security Center will also feature enhanced privacy protection layers to help customers comply with global privacy regulations such as GDPR. Building on the patented dynamic blurring and encryption technology in KiwiVision Privacy Protector, which is now included at no cost for all Genetec Advantage customers, Security Center will help users define and control who has access to sensitive data and footage, without slowing down investigations and incident response. Users will be able to define strict access procedures such as the Four Eyes Principle, which will ensure that organisations do not have to choose between protecting the privacy of individuals and their physical security. Security Center version 5.8 is expected to be available in Q2 2019. ë
M A R C H 2 019
45
AFTER THOUGHT
ARRIVAL OF THE NEW BREED OF SECURITY THREAT HUNTERS Threat hunters are a new breed of creative security specialists who look for trails of threat actors inside an organisation explains Anton Chuvakin at Gartner. IT security teams are constantly on the lookout for the next hack or vulnerability. As attacks become more advanced and pervasive, the concept and practice of threat hunting has emerged. To hunt for security threats means to look for traces of attackers, past and present, in the IT environment. Organisations that employ threat hunting use an analyst-centric process to uncover hidden, advanced threats missed by automated, preventative and detective controls. The practice is distinct from threat detection, which relies heavily on rules and algorithms. If you can simply write a rule, write a rule. But then you do not need to hunt. While threat hunting includes the use of various tools and processes, people are at the core. These rare IT security professionals are highly and uniquely skilled, are known as threat hunters, and the best ones have a combination of systems, security, data analysis and creative thinking skills. Threat hunting is suitable for well-resourced security organisations facing persistent and stealthy threats. Those who hire a threat hunter or team of hunters have typically maximised their alert triage and detection content development processes and matured their security incident response functions. To understand what threat hunting is and how it works, familiarise yourself with the characteristics central to the practice.
BREACH ASSUMPTIONS Hunters assume that a breach or traces of, however subtle, have been left by the attackers in your IT environment.
INTERACTIVE AND ITERATIVE Although hunting involves a process of following an initial lead or clue, there will likely be many pivots and side quests — all in pursuit of intruder evidence.
CREATIVE METHODOLOGY Most experts agree that hunting is not about following the rules, but rather a creative process and a loose methodology focused on outsmarting a skilled human attacker.
ANTON CHUVAKIN, VICE PRESIDENT AND DISTINGUISHED ANALYST AT GARTNER.
KEY TAKEAWAYS n
IF YOU CAN SIMPLY WRITE A RULE,
WRITE A RULE BUT THEN YOU DO NOT
PROACTIVE Hunting is about looking for an intruder before any alerts are generated. Proactive in this context refers to taking action before the intrusion alerts, not before intrusions occur.
CLUES AND HYPOTHESES Hunting focuses on following clues and ideas, not cooked conclusive alerts from tools and rule-based detections. However, hunting informs outputs that can later become rules.
46
ANALYST-CENTRIC The practice is analyst-centric. The tools used by hunters play an auxiliary role in helping them see hidden threats.
M A R C H 2019
NEED TO HUNT. n
WHILE THREAT HUNTING INCLUDES
THE USE OF VARIOUS TOOLS PEOPLE ARE AT THE CORE. n
THREAT HUNTERS HAVE COMBINATION
OF SYSTEMS, SECURITY, DATA ANALYSIS AND CREATIVE SKILLS. n
THREAT HUNTING IS SUITABLE FOR
ORGANISATIONS FACING PERSISTENT AND STEALTHY THREATS.
KNOWLEDGE-RELIANT Threat hunting relies on both advanced threat knowledge and deep knowledge of the organisation’s IT environment. Organisations then learn more about their IT environment and find the places where attackers hide. The following questions will help you to determine whether or not you need to hire a threat hunter or team of hunters: l Are you targeted by stealthy advanced threats? l Do you have a legitimate need to push threat response time? l Are you worried about residual risk after security controls are deployed? l Have you had incidents not started by an alert? Organisations can get started with a consultant, vendor or an existing employee, someone who occasionally conducts ad-hoc hunting activities, but has not yet been formally made a hunter. While outsourcing options do exist, few vendors have the required capabilities. Many are managed security service providers not managed threat hunting providers. ë
OFFICIAL GOVERNMENT CYBER SECURITY PARTNER
OFFICIALLY SUPPORTED BY
THE WORLD'S MOST FAMOUS HACKER AND EX-#1 ON THE FBI'S MOST WANTED LIST TO HACK LIVE IN DUBAI See the jaw-dropping live hack by KEVIN MITNICK for as little as AED 1,999. #GISEC www.gisec.ae I gisec@dwtc.com I +971 4 308 6805
OFFICIALLY SUPPORTED BY
STRATEGIC PARTNERS
GOLD SPONSORS
IOT PARTNER
POWERED BY
CO-LOCATED WITH
PLATINUM SPONSOR
ORGANISED BY
DIAMOND SPONSOR