Skip to main content

Cyber Sentinels October 2019

Page 1

SPECIAL SUPPLEMENT BY

TRENDS FOR CYBER AND INDUSTRIAL SECURITY EXECUTIVES

OCTOBER 2019

NIDAL OTHMAN, MANAGING DIRECTOR

MAHMOUD NIMER, GENERAL MANAGER

BASHAR BASHAIREH, CEO

STARLINK

TARGETING $1 BILLION The global True VAD has restructured at the top, bringing in Bashar Bashaireh as CEO of the company. ...32


Swing

Local

-

Connect

Global

2019-20 AUSTRALIA AZERBAIJAN BAHRAIN BOTSWANA CANADA CHINA EGYPT FRANCE GERMANY GHANA

INDIA INDONESIA IRELAND ITALY KAZAKHSTAN KENYA MADAGASCAR MALAYSIA MAURITIUS NEW ZEALAND

40

PARTICIPATING COUNTRIES

NEPAL NIGERIA OMAN PAKISTAN PORTUGAL RWANDA RUSSIA SAUDI ARABIA SCOTLAND SINGAPORE

SRI LANKA SPAIN SOUTH AFRICA SWITZERLAND THAILAND TURKEY UAE UNITED KINGDOM US ZIMBABWE

60 QUALIFYING ROUNDS

4500 C-LEVEL EXECUTIVES

FOR MORE VISIT: www.gecopen.com CONTACT: ronak@gecmediagroup.com, vineet@gecmediagroup.com, bharat@gecmediagroup.com


SEPTEMBER-DECEMBER, 2019

WORLDS LARGEST IT & INNOVATION EXCELLENCE PROGRAMME

3

15

CONTINENTS QATAR 22 OCT

COUNTRIES KUWAIT 03 NOV

BAHRAIN 06 NOV

3000+

C-LEVEL EXECUTIVES GHANA 11 NOV

OMAN 13 NOV

SINGAPORE 15 NOV

USA 17 OCT

CANADA 14 OCT

SOUTH AFRICA 8-9 OCT

UAE

09-10 DEC DOUBLETREE BY HILTON, RAK

KENYA 18 NOV

INDIA 21 NOV

PAKISTAN 23 NOV SAUDI 11 SEP

EGYPT 25 NOV

BROUGHT BY

3 1 FOXTAIL LAN, MONMOUTH JUNCTION , N J - 0 8 8 5 2 , ​U N I T E D STAT E S O F A M E R I C A EMAIL; INFO@GLOBALCIOFORUM.COM ,

W W W. G LO BA LC I O FO R U M . C O M


CONTENTS OCTOBER 2019

14

16

TOP OF MIND

TOP OF MIND

The art of detecting and protecting

Cloud Security Essentials Session Monitoring

22

24

TOP OF MIND Protecting Your Organization from Network File Encryption Attacks

28

STARLINK

REACHING THE $1 BILLION MARK

The global True VAD has set itself an ambitious revenue target and is driving incremental business from datacentre and cloud and new geographies.

TOP OF MIND Network Detection & Response The New Network Security Paradigm

EVENTS

30

32

38

18

PRESENTS

04

TOP OF MIND

TOP OF MIND

TOP OF MIND

EMAIL SECURITY GATEWAYS TO SAVE YOUR LIFE

Sizing Up Risks for Third-parties & Vendors

Why IoT DDoS threats continue to loom in emerging new tech

O CTO B E R 2019

DEEP DIVE

40

New nCipher HSM as a Service delivers high-assurance security


MANAGING DIRECTOR: TUSHAR SAHOO CEO: RONAK SAMANTARAY

EDITORIAL

DIRECTOR & EDITOR: ANUSHREE DIXIT   anushree@gecmediagroup.com SUB EDITOR: DIVSHA BHAT   divsha@gecmediagroup.com EVENTS EXECUTIVE: SHRIYA NAIR   shriya@gecmediagroup.com SALES MANAGER : NEHA SHARMA

NEW PARADIGMS IN SECURITY Cybersecurity, networking and connectivity are the pivotal pillars in creating a smart city. As the Middle East region is progressing at a rapid pace towards creating smart cities, companies are placing strong emphasis on intelligence-led security. And this intelligence, we are talking about, is not artificial— its human. The business evolutions that are steadily making their way into digital transformation need a perfect blend of human expertise and advanced technologies that can not only detect a potential threat or breach, but also remediate it with immediate effect. On the threat side, we saw a significant rise in email and fileless events. To cite a few reports, Trend Micro published its roundup report for the first half of 2019, revealing a surge in fileless attacks designed to disguise ANUSHREE DIXIT malicious activity. Detections of this threat Editor & Director alone were up 265% compared to the first anushree@gecmediagroup.com half of 2018. In Middle East and North Africa (MENA), the United Arab Emirates (UAE) saw the highest number of malicious URLs accessed by people in-country (4,269,043), and the second-highest number of malware threats detected (893,908), based on data from Trend Micro. Our GITEX issue special cover feature puts StarLink in the spotlight where the company talks about its plan to touch the $1 Billion mark. The VAD has gone through significant restructuring at the top management level. Bringing in Bashar Bashaireh as Chief Executive Officer is one of the biggest move in this direction. In this issue, we are presenting some very interesting read that have some unique subject matter like BeyondTrust’s expert opinion piece on ‘Shoulder Surfing’; A10’ guest blog on how hackers have made the new devices their weapon of choice for DDOS attack. Bitdefender’s thought piece talks about the new network security paradigm. This and much more in the October issue of Cyber Sentinels. Stay secure. Happy reading! ë

neha@gecmediagroup.com GROUP SALES HEAD: RICHA S   richa@gecmediagroup.com   + 971 529 943 982

VISUALIZER: MANAS RANJAN LEAD VISUALIZER: DPR CHOUDHARY DESIGNER: AJAY ARYA ASSISTANT DESIGNER: RAHUL ARYA

SUBSCRIPTIONS INFO@GECMEDIAGROUP.COM SOCIAL MARKETING & DIGITAL COMMUNICATION YASOBANT MISHRA   yasobant@gecmediagroup.com

DESIGNED BY

PRINTED BY AL GHURAIR PRINTING & PUBLISHING LLC. MASAFI COMPOUND, SATWA, P.O.BOX: 5613, DUBAI, UAE

PUBLISHED BY ACCENT INFOMEDIA MEA FZ-LLC PO BOX : 500653, DUBAI, UAE 223, BUILDING 9, DUBAI MEDIA CITY, DUBAI, UAE PHONE : +971 (0) 4368 8523 31 FOXTAIL LAN, MONMOUTH JUNCTION, NJ - 08852 UNITED STATES OF AMERICA PHONE NO: + 1 732 794 5918 A PUBLICATION LICENSED BY INTERNATIONAL MEDIA PRODUCTION ZONE, DUBAI, UAE @COPYRIGHT 2013 ACCENT INFOMEDIA. ALL RIGHTS RESERVED. WHILE THE PUBLISHERS HAVE MADE EVERY EFFORT TO ENSURE THE ACCURACY OF ALL INFORMATION IN THIS MAGAZINE, THEY WILL NOT BE HELD RESPONSIBLE FOR ANY ERRORS THEREIN.

O CTO B E R 2 019

05


NEWS

SPECTRAMI Unveiled Predictive Cyber Defense Roadshow 2019

BITDEFENDER TO SHINE SPOTLIGHT ON IOT SECURITY AT GITEX

ANAND CHOUDHA, CEO AND PRESIDENT, SPECTRAMI

TAREK KUZBARI, REGIONAL DIRECTOR, MIDDLE EAST, AT BITDEFENDER

SPECTRAMI reviles a 7 countries and 8-city security roadshow, SPECTRAMI Predictive Cyber Defense Roadshow 2019. This initiative is designed to educate organizations on the merits of predictive cyber security approach as against the prevention or detection-based approaches, which is a decent approach but, in many cases, leaves them vulnerable. The roadshow highlighted the key solutions and services deliberated to support predictive cyber defense model. The company kick started its multi-city roadshow campaign from Dubai and conducted the first roadshow at Burj Al Arab, Dubai, UAE on 9th September 2019. After Dubai, the roadshow travelled to Muscat, Doha, Kuwait, Riyadh, Dammam, Cairo and Istanbul. The SPECTRAMI Predictive Cyber Defense Roadshow 2019 has been crafted to provide an interactive platform to disseminate information and network with security decision makers from most prominent organizations in the region. Anand Choudha, the CEO and President at SPECTRAMI commented: “With our key technology partners, we addressed the challenges faced by end-users not just from product or solution perspective but from the framework and policy aspect too. Time has come for industry leaders to adopt the predictive security approach rather than the preventive security approach.” Echoing the similar sentiments, the CTO of SPECTRAMI, Sarfaraz Kazi said “Technology is evolving very fast, which is driving the need to relook at our strategies and develop a predictive risk management strategy that will enable organisations to proactively identify threats and allows them to stay ahead of potential threats.”

Bitdefender will be participating in the 39th edition of GITEX Technology Week. Over the last couple of years, enterprises and governments in the Middle East, particularly in the healthcare and industrial sectors, have been changing the way they operate by connecting a plethora of disparate systems across operations, to mine untapped data. However, this radical shift toward the Internet of Things (IoT) is expanding the attack surface considerably. Bitdefender plans to use the MENA region’s premier technology tradeshow as a platform to discuss the most critical threats associated with IoT and demonstrate to customers and partner’s unique solutions to protect IoT infrastructures that are increasingly more exposed to cyberthreats. Speaking about the importance of deploying robust cybersecurity solutions that specifically address IoT security, Tarek Kuzbari, regional director, Middle East, at Bitdefender said, “Given the region’s appetite for technology and innovation, governments and enterprises across the Middle East are increasingly turning to cloud environments and IoT applications to transform their operations and achieve growth. But at the same time, it is imperative that these same organizations also realize the security implications associated with these initiatives. The consequences of an IoT attack can range from downtime and loss of revenue and reputation, to - in the case of an attack on medical devices in the healthcare sector—even loss of life.”

06

O CTO B E R 2019


NEWS

Citrix Delivers Expanded Network Protection with Palo Alto Networks

CHALAN ARAS, VICE PRESIDENT, SD-WAN AND INTELLIGENT TRAFFIC MANAGEMENT, CITRIX

Business today is more global and collaborative than ever. People work anywhere, anytime on any number of devices. And they access and share information and ideas across systems and

borders. This promises new levels of productivity and innovation that can transform entire industries – and even create new ones. But it also introduces new risks via an expanded attack sur-

face that companies must vigilantly guard against. And Citrix Systems is expanding its network protection capabilities to help them do this. The company today said that it is partnering with Palo Alto Networks to enable easy deployment and management of next-generation firewalls within Citrix® SD-WAN, providing companies with added layers of security to protect their assets at branches and beyond. “Applications and workloads are migrating to the cloud at a very aggressive rate and security needs to follow them,” said Chalan Aras, Vice President, SD-WAN and Intelligent Traffic Management, Citrix. “With Palo Alto Networks, we can deliver an advanced SD-WAN security solution that enables companies to protect users, data and applications across branches, data centers and public clouds in a simple, flexible way.” Citrix SD-WAN is a next-generation WAN Edge solution that delivers the automated, secure connectivity required to optimize performance of applications and drive a superior user experience. With the integration of the Palo Alto Networks VMSeries virtual next-generation firewalls and Prisma Access with the Citrix SD-WAN solution, distributed enterprises can enhance their network and cloud protection in a straightforward, cost-effective manner. “In today’s hybrid, multi-cloud world, security needs to be as agile as your applications, data and users,” said Adam Geller, senior vice president, Products, Palo Alto Networks.

NOZOMI NETWORKS TO SHOWCASE INDUSTRIAL CYBER SECURITY SOLUTIONS AT GITEX Nozomi Networks at GITEX will showcase its real-time industrial control system (ICS) and Operational Technology (OT) network visibility products and demonstrate how they can be integrated into existing platforms, such as Fortinet’s Network Access Control (FortiNAC) at the region’s biggest ICT exhibition. “As IT and operational networks become more interconnected across the UAE and elsewhere, the attack surface for cyber threats has also expanded. Nozomi Networks arms enterprises

with proactive tools, delivering OT visibility, threat detection and insight within a single solution to hundreds of thousands of critical infrastructure, energy, manufacturing, mining, transportation and other industrial devices worldwide. GITEX Technology Week 2019 offers the perfect platform to showcase these tools to an audience of targeted customers and partners from across the region visiting the exhibition to scout for the latest technologies,” says Marcus Josefsson, Nozomi Networks Director – Middle

East, Africa & Russia. Nozomi Networks has witnessed a rising demand for ICS cyber security solutions recently, against an increasingly sophisticated threat landscape as greater numbers of industrial and critical infrastructure sectors are targeted. “As industrial cyber security becomes a budgeted line-item for the mainstream market across the Middle East, we are experiencing phenomenal customer, partner and market growth. 2019 is the year for ICS cyber security,” Mr. Josefsson explains.

O CTO B E R 2 019

07


NEWS

Proofpoint to showcase its peoplecentric cybersecurity solutions at GITEX Proofpoint will be participating at GITEX 2019 Technology Week, where it will showcase its portfolio of people-centric cybersecurity solutions that protect organisations’ greatest assets and biggest risks their people. Threat actors are increasingly targeting the human factor: in fact, 99% of today’s targeted cyber-attacks are human activated. These attacks rely on a person at the other end to open a weaponised document, click on an unsafe link, type their credentials, or even carry out the attacker’s commands directly (such as wiring money or sending sensitive files). These highly targeted, socially engineered attacks rely in cybercriminals identifying who inside a company has access to the information they want and tricking unsuspecting employees through email, cloud apps, and social media channels. Against this ever-evolving threat landscape, it is vital that organisations, not just in the Middle East, but globally, recognise the importance of the human factor threat. “Cybercriminals relentlessly target the people who will provide the most lucrative pay-out and that’s why we are committed to delivering innovative people-centric security and training solutions that ensure an organisation’s most attacked people are protected,” Emile Abou Saleh, Regional Director, Middle East and Africa for Proofpoint. “We continue to invest in the Middle East and are excited for our participation at GITEX. The week represents a cornerstone in the Middle East cybersecurity events calendar, and a fantastic opportunity to educate partners, customers and prospects on the cyber risks facing employees today”. With an integrated suite of cloud-based solutions, Proofpoint provides unique visibility into organisation’s most targeted employees and they often aren’t the traditional VIPs, but rather their much attacked people (VAPs).

08

O CTO B E R 2019

SONICWALL TO SHOWCASE INTEGRATED CYBERSECURITY PLATFORM AT GITEX

MOHAMED ABDALLAH, REGIONAL DIRECTOR FOR MIDDLE EAST & TURKEY, SONICWALL

SonicWall is participating at GITEX 2019 where it will exhibit its integrated cybersecurity platform designed to help SMBs, mid to large enterprises and government agencies defend against today’s sophisticated and rapidly growing cybersecurity threats. “SonicWall has been working relentlessly with our partners to better understand and serve our customers in the region,” said Mohamed Abdallah, Regional Director for Middle East & Turkey, SonicWall. “While businesses continue to be a prime target for cybercriminals, we have seen organizations demonstrating a clear maturity and readiness for the next level of cybersecurity. We look forward to demonstrating the depth of our growing solutions portfolio, including our patent-pending Real-Time Deep Memory Inspection (RTDMI) technology that has discovered 104,000 never-before-seen attack variants from January to August alone.” SonicWall will showcase its networking and security solutions, including next-generation firewalls, RTDMI™, next-generation endpoint protection, secure SD-WAN, secure Wi-Fi, Securityas-a-Service, Cloud App Security (CAS), WAN acceleration, web application firewalls, security analytics, email security and secure remote access. “SonicWall solutions help drive and secure our customers’ digital transformation journey,” said Mohamed Abdallah. “With our singlepane-of-glass integrated security management, coupled with analytics and real-time threat intelligence protection across our ecosystem, we are providing partners with a complete cybersecurity portfolio to meet every security need.”


NEWS

Sophos to Showcase Its Latest Cybersecurity Innovations at GITEX Sophos will showcase its latest cybersecurity innovations at GITEX. Visitors to the stand will be able to hear more about Sophos’ endpoint and network security solutions that are powered by deep learning and synchronized security and help organizations of all sizes battle today’s ever changing threat landscape. “Organizations do not have the resources to combat cyber threats like malware, exploits, ransomware and automated, active attacks. Moreover, our research shows the lack of visibility, protection and response capability

in the IT security of organizations globally. Under such circumstances businesses need intelligent security solutions that are predictive, multi-layered, and can work together as a system,” said Harish Chib, vice president, Middle East and Africa, Sophos. “GITEX offers us a great opportunity to demonstrate why every organization needs security that is innovative, integrated and scalable and how next-gen cybersecurity protection from Sophos proactively protects against sophisticated threats. It is also an ideal platform

for us to meet partners and develop new partnerships that will strengthen the Middle East channel.” Sophos Synchronized Security technology allows its network and endpoint protection products to share threat intelligence and respond to security incidents. Synchronized Security is made possible through Security Heartbeat and reduces threat discovery, protection and incident response time – which ordinarily could take hours, days or weeks – to seconds.

Exclusive Networks hosts inaugural “Cloud First” forum in Saudi Arabia

Cloud is increasingly becoming a top priority for C-level executives across all vertical markets in the Kingdom. Organizations in Saudi Arabia

10

O CTO B E R 2019

are rapidly adopting cloud solutions as the need flexibility and speed takes effect. Exclusive Networks Middle East organised its

inaugural Cloud First conference at Narcissus Hotel & Residences, Riyadh on 17th September. Attendees had the opportunity to meet the company’s Cyber and Cloud specialists and acquaint themselves with disruptive technologies in the space. Exclusive Networks is taking the lead to help customers in the Kingdom to accept and embrace the cloud transformation that is taking over the industry. During the course of the event, customers were enlightened on best practices in cybersecurity and cloud. The forum served as a perfect platform to help them to formulate the most ideal strategy for their businesses. Exclusive Networks’ vendor partners such as Fortinet, F5, SentinelOne, Nutanix, Thales , Gigamon and Infoblox were present at the event and attendees had a unique opportunity to network with them. Participants at the conference were treated to a host of thought-provoking discussions that revolved around different aspects of the cloud.


Ready-to-connect IT infrastructure

Rittal Data Center Container Experience Ready-to-connect IT infrastructure in a robust container shell, as standardised IT modules in a range of output categories for SME, Cloud and Edge applications.

RDC All-in-One Container

IT modules including UPS system and cooling in a range of output categories for SME, Cloud and Edge applications.

RDC Power Container

Modular UPS systems with redundancy to supply one or more IT modules.

RDC Cooling Container

Efficient recooling systems in a container frame, ready-to-connect and system-tested with redundant chillers with integral free cooler or additional external free cooler.

FOR ENQUIRIES:

Rittal Middle East FZE Tel: +971-4-3416855 I Email: info-it@rittal-middle-east.com I www.rittal.com/uae-en

Data Center Container

Data Centre Container for mobile or temporary use of IT systems including an innovative, direct free cooling of up to 20 kW.


TOP OF MINDADVISER ENTERPRISE

TOP CISOS OF THE INDUSTRY ENGAGE AT GCF ORGANIZED

BEYONDTRUST BREAKFAST BRIEFING Brought by Enterprise Adviser and Powered by BeyondTrust, ‘PAM: The Critical Missing Piece in Your Security Strategy’ roundtable was held successfully on 4th September at The Address Boulevard, Dubai. The highly customised CISO breakfast Meet

12

O CTO B E R 2019

was attended by the top CISOs of the industry. The sessions covered what privilege means to businesses and how implementing a PAM solution drives significant improvement across the organization. The CISOs also discussed on why organiza-

tions should make PAM their top investment and why quickly controlling and automating key PAM capabilities is critical to an organization’s success. John Hathway, Regional VP-Middle East & India and Michael Byrnes, Senior Solutions Architect, Middle East put forward some excellent presentations on the topics.


ENTERPRISE TOP OF ADVISER MIND

O CTO B E R 2 019

13


TOP OF MIND

CLOUD SECURITY ESSENTIALS SESSION MONITORING “What is often overlooked is the potential sensitivity and security of recorded sessions, just like having cameras in your home. This is similar to the security of preventing an over-the-shoulder attack from occurring in the first place. The access needs to be restricted.”

The near-perfect personal attack vector is “shoulder surfing.” If you are not familiar with the concept, it is literally a threat actor looking over your shoulder and observing everything you type, see on the screen and interact with in the physical world, including paper, pens and even removable media. Shoulder surfing is the ultimate method a threat actor can use to compromise a system because the only method of detection is just to say “no” or obfuscate the screen with a polarized filter and shield the keyboard from view. Both, however, are not typically present in a corporate environment when dealing with trusted individuals. But what about untrusted identities? This is where session monitoring fills the gap and provides a valuable tool to determine if remote access is appropriate. But before we dive into session monitoring, we need to draw the analogy a little tighter and translate its importance to the cloud. Over the last decade, we have seen exponential growth in the number of cameras on cell phones, within homes, present within businesses and in the public looking for potential social disruptions. Cameras are similar to over-the-shoulder attacks because they provide a view (with optional audio) of what is occurring within their field of view or frame. Using advanced software, they can identify people (tagging) and suspicious behavior (using artificial intelligence or motion-based detection) and even see in the dark. When dealing with the cloud, there is no physical presence it is someone else’s computer, and for the most part, based on Linux. Over-theshoulder attacks can therefore only occur in the cloud when remote sessions are established. This is where session monitoring comes into play. It is the only way to record the activity of a cloud session, to determine if the activity was appropriate. While this model is also true for remote sessions on-premise, it is the only viable method for the cloud due to the lack of computing ownership,

14

O CTO B E R 2019

MOREY HABER, CTO, BEYONDTRUST

physical presence and methods for interactive session activity available today. These are typically VNC-, SSH-, RDP- or HTTPS-based. So how does session monitoring work? Based on the protocol, all text on the screen and keystrokes are recorded. These are inspected in real time for critical pattern matches that can perform automated actions like alerting, session pausing and even session termination. The list is typically defined by administrators, but most vendors provide a critical list—out of the box governing database commands, lateral movement, sensitive operating system commands and other suspicious behavior. The data is captured and indexed for future searching and audit reviews and typically processed via a security information and event

management (SIEM) or analytics engine for advanced user behavior based on time, data source, concurrent sessions, users, commands and so on. The result is as close to over-the-shoulder recording as you can provide, for viewing or reviewing at a later time, when no physical presence is possible. What is often overlooked is the potential sensitivity and security of recorded sessions, just like having cameras in your home. This is similar to the security of preventing an over-theshoulder attack from occurring in the first place. The access needs to be restricted. Finally, all protocols implemented for session monitoring are not the same. Text-based sessions like SSH are easily captured and indexed and can be alerted based on characters on the screen or entered on the keyboard. Graphic and web-based sessions are not the same. These remote sessions are typically RDP, VNC or HTTPS. Keystrokes and command prompts are easy to capture, but text in a graphic window can be embedded, displayed as graphics or across multiple screens or even rendered with a plug-in like Flash. This is where session monitoring benefits from monitoring mouse clicks, processes launched and titles in application frames. This data is not as complete as logging everything in an SSH session, but it helps provide the visibility necessary to determine if the remote session is appropriate and if malicious behavior is potentially occurring. The importance of session monitoring is a critical buying need when working with the cloud. It is the only method to observe, document, record and detect inappropriate behavior when access is always initiated remotely. While other techniques can monitor other protocols or API-based access to the cloud, only session monitoring can capture the real-time behavior of interactive users and their interactions. And, if the users know they are being recorded , the deterrent alone may be enough to curb some malicious behavior or even innocent snooping. ë


AUTOMATE CYBER DEFENSE FOR 5G, DDoS & MULTI-CLOUD JOIN A10 NETWORKS @ GITEX TECHNOLOGY WEEK BOOTH SR-J10 | 6-10 OCT 2019 SCAN QR CODE TO BOOK YOUR MEETING & GET A FREE SECURITY ASSESSMENT* * Terms & Conditions apply


TOP OF MIND

HOW A DISJOINTED WORK-LIFE BALANCE CAN LEAVE BUSINESSES VULNERABLE TO CYBER THREATS The lines between personal and professional life are becoming increasingly blurred. People are often now spending more hours in the office than they do at home. Yet, as many as a quarter do corporate tasks outside of the office. Hinting that the ideal work-life balance may simply not be achievable in modern society. The lack of separation of what should be carried out at work and what can be done at home could be caused by a rapid rise in the amount of digital information we are all contending with. Both our personal and professional lives are now reliant on such data – storing in social media and email accounts, digital documents and shared folders. A recent Kaspersky report has found that those in employment are often disorganized in how they manage files and credentials. So, whilst IT departments need to carry the burden of protecting staff from ever-growing cyber threats, the sheer volume of information needed to do jobs effectively has created a huge pressure on employees to help keep the organizations they work for secure.

THE DEATH OF THE WORKLIFE BALANCE Working in an office from nine to five has clear benefits. Steady employment, steady income and steady working hours. Except, the era of the nine to five has long gone. We are all now expected to stay at work a little longer, whether it is for a one-off meeting, a tight deadline or even the Christmas party. For millions of workers, working late is necessary to do their jobs effectively. In fact, it is estimated that staff in Mexico are at work 43 hours a week, with workers in Costa Rica, Greece and South Korea not too far behind. Such circumstances, while accepted, have led to workers juggling their professional and personal lives across both their workplaces and homes. Leaving personal belongings at the office and doing domestic tasks at our desk is a common occurrence, as we try to strike a balance between our personal and professional lives. It isn’t uncommon for

16

O CTO B E R 2019

workers to have a change of clothes in their office, so why wouldn’t we do the same for digital information? Having access to the data we need, regardless of its use, at both our house and our office makes life easier. The big problem with this behaviour for businesses is that staff can become complacent with where they store corporate information. Workers who are comfortable storing it on their personal devices are not being cautious enough to keep it secure. Information can be compromised and left at risk of cyber-theft if it becomes too accessible. This, of course, has far-reaching consequences for the affected business.

BUSINESSES LEFT MANAGING DATA AND THEIR WORKFORCE As workers struggle to manage their personal and business information, businesses are left with the extremely tough task of overseeing an ever-growing number of files and data, while also keeping them secure. The Kaspersky report revealed that 80% of employees don’t think they are responsible for ensuring emails, files and documents have the appropriate access permissions, regardless of whether or not they have created them. Sensitive personal data, payment details and authorisation codes are just a few examples of the data businesses rely on daily to run efficiently. But staffs are not storing these details securely or properly. Only just over half (56%) of employees delete outdated items from their email inbox on a regular basis and a mere third (34%) get rid of outdated files on their hard drives, This digital clutter becomes an even greater issue when information is stored in places where it is difficult to control, such as in the cloud, in shared folders or file transfers. Add to this the rapid rise in the number of files being generated and it becomes harder for organizations to manage corporate information. Despite this, they are still responsible for ensuring sensitive or confidential data isn’t easy to access and find by those who are not permitted to


TOP OF MIND

see it. If an employee can stumble across their colleagues’ salaries, for example, then why not a hacker? Businesses rely on their staff to support them in managing data securely. If employees and organizations can tackle the challenge of information security together, it is more likely to foster a corporate ethos and culture where everyone cares about protecting the business and helps one another to achieve it. This is where educating employees is so important, so they understand the importance of data security, their role in it and the steps they need to take to keep data safe. Only then will employees better manage their professional and personal information.

AMIR KANAAN, MANAGING DIRECTOR - META, KASPERSKY

RELIEVING THE PRESSURE Modern working habits may have resigned the concept of a work-life balance to the brink of extinction, but businesses still have a chance to turn things around for their workers and the security of corporate data. This may seem difficult at first, as you need to retain employees’ freedom to do their jobs well, whilst reminding them to remain cautious about how they use and access corporate information. One way to alleviate this pressure is to encourage staff to leave the office on time and only put in extra hours when it is completely necessary. This not only gives employees more time to spend with their family or socialize with their friends, but also allows them to manage their personal information at home. Additionally, while working from home does have its benefits; businesses need to ensure their staffs are properly equipped to keep corporate data out of the wrong hands. For instance, companies can ensure information remains safe by installing dedicated security solutions onto personal devices, such as mobile devices that employees normally used for working purposes. Coupled with security awareness training, these measures can help staff improve their personal digital lives too. Organizations can show they not only care about their employees’ work-life balance, but also want them to stay protected at home. By introducing rigorous processes to protect corporate information (such as endpoint security, two-factor authentication, strong passwords, security awareness training and corporate cybersecurity policies) businesses can grant access only to those who need it. Such measures relieve pressure on employees and reduce the risk of data falling into the wrong hands. With a bit of understanding, organizations can revive the work-life balance and stop digital clutter from leaving them vulnerable to cybercrime. ë

O CTO B E R 2 019

17


TOP OF MIND GECSS

PRESENTS

The second edition of GEC Security Symposium and CISO Awards 2019 held in association with Dubai Police Cybercrime Department eCrime concluded on a grand note on 4th September 2019 at The Address Boulevard Dubai. The event was addressed by Ms. Anushree Dixit, Editor, GEC Media Group. The Guest of Honor for the event – Brigadier Jamal Al Jallaf, Director of Dubai Police Cybercrime Department expressed his pleasure in associating with The Cyber Sentinels Magazine and spoke about the critical role played by the e-crime platform in combatting and addressing cybercrimes that often goes under the wraps. The Symposium witnessed some interesting presentations from the end customers and solution providers. The prominent CISO speakers were – Dr Erdal Ozkaya, Standard Chartered Bank, Adam El Adama, ADNOC Sour Gas, Mohammed Shakeel Ahmed, Abu Dhabi Aviation, Bilal Ahmad Fashoo, Union Co-Operative Society. The speakers

18

O CTO B E R 2019

from the solution providers were Marc Leipoldt, SAI Global, Ashith Piriyattiath, Guardian One Technologies, Tarek Kuzbari, Bitdefender. The event also witnessed an interesting presentation from Saurabh Verma, Frost and Sullivan. The GEC Security Symposium also had an excellent Power Panel Session moderated by Mr. Arun Shankar, Editor, Business Transformation. The key panelists were Mansoor Mughal, Dubai Financial Market, Hasan Isam Naser Muhi, Kuwait Finance House Bahrain, Salman Sarfraz, Sky News Arabia and Saurabh Verma, Frost and Sullivan. The power panel was successful in captivating and engaging the audience views as well. The Symposium ended by honouring the top CISOs of the region. The GEC Security Symposium and CISO Awards 2019 Saudi Edition was held on 11th September at the Movenpick Hotel Riyadh. Mr. Shaker Al Anazi, Cyber Security Senior Manager, Zain KSA shared an excellent presentation on the topic – ‘Towards effective cybersecurity measurement.’.


TOP OF GECSS MIND

O CTO B E R 2 019

19


GECSS

CISO AWARDS 2019 WINNERS - UAE EDITION

TOP OF MIND PRESENTS

Dr. Erdal Ozkaya Adam El Adama Illyas Kooliyankal

Standard Chartered Bank ADNOC Sour Gas ADIB

Mohammed Shakeel Ahmed Abu Dhabi Aviation George Eapen

Petrofac

Ahmed Al Lawati

Ooredoo Oman

Hasan Isam Naser Muhi

Kuwait Finance House Bahrain

Mansoor Mughal

Dubai Financial Market

Vivek Gupta

GEMS Education

Srinivas Mathala

OSN (Gulf DTH FZ LLC)

Rakesh Narang

Aldar Properties

Bittu Balakrishnan

Adyard Abu Dhabi LLC

Irshad Mohammed Shailesh Mani Parvez Ahmad Safdar Zaman Abubakar Arshad Ross McNaughton Jurageswaran Shetty Bilal Ahmad Mohammed Mudasar

VPS Healthcare Flemingo International Emirates Nets System Nakheel PJSC Batelco Ahli United Bank Gulftainer Company Ltd. Union Co-Operative Society ETA Facilities Management

CISO AWARDS & CYBER SENTINELS SECURITY AWARDS 2019 WINNERS - SAUDI ARABIA EDITION

20

O CTO B E R 2019

Shaker ALanazi Muhammad Saleem Mohammed Alshamrani

Zain KSA Ministry of Health Bidaya Home Finance

Amin Mohammed Siddiqui

Public Investment Fund

Abdullah Alomari

Etihad Etisalat Co. – Mobily

Saghir Ahmad Khan

Al Rajhi Bank

Aneesh Salimkumar

STC Solutions

Vivek Silla Abdelmajed Ahmed Saeed Fadol Kais Barakat Cyber Sentinels Security Awards 2019 – Top VAD Cyber Sentinels Security Awards 2019 – Top VAD – Cloud Services Cyber Sentinels Security Awards 2019 – Top SI – Security Services Shailesh Mani Parvez Ahmad Safdar Zaman Abubakar Arshad Ross McNaughton Jurageswaran Shetty Bilal Ahmad Mohammed Mudasar

Public Investment Fund Al Hammadi Development & Investment Saudi Aramco Screencheck Middle East Al Jammaz Distribution STME Flemingo International Emirates Nets System Nakheel PJSC Batelco Ahli United Bank Gulftainer Company Ltd. Union Co-Operative Society ETA Facilities Management


TOP OF MIND

AMMAR ENAYA,

REGIONAL DIRECTOR METNA VECTRA

22

O CTO B E R 2019


TOP OF MIND

PROTECTING YOUR ORGANIZATION FROM NETWORK FILE ENCRYPTION ATTACKS When we think of ransomware, WannaCry is probably the first example that jumps to mind, for obvious reasons—to date, it is one of the most devastating ransomware attacks. WannaCry spread quickly across the globe using opportunistic methods that targeted organizations vulnerable to the Eternal Blue exploit. However, in 2019, ransomware evolved from opportunistic into targeted attacks that victimize organizations likely to pay a larger ransom to regain access to their files. This made networks— particularly those of cloud service providers the number one attack vector.

NETWORK FILE ENCRYPTION Because the goal in a ransomware attack is to propagate as wide and as quickly as possible, it is desirable for file encryption to occur beyond the local files. As such, the most effective weapon in carrying out a ransomware attack is the network itself, which is instrumental in enabling the malicious encryption of shared files known as file shares—on network servers. Ransomware scans the network for shared files on servers and computers to which it has access privileges, and then spreads from one computer to many others. In those cases where the infected computer has access to documents in network shared volumes, with their high capacity data storage, that single host can lock access to documents across several departments in the company. It is standard practice to employ volume sharing protocols such as the Server Message Block (SMB) with networked shares in order to make documents easily accessible to the users. This occurs in both cloud and private data centers. Documents are stored in shared volumes to ensure good backup procedures and for productivity in sharing content for teamwork, especially with a mobile workforce. However, this also makes files more vulnerable to exposure as the shared volumes are reachable from any system in the organization, which could be an infected system. In a volume sharing system a single infected client host could encrypt a whole networked

volume, with a global impact on the organization business and systems. The files must be recovered from the most recent backup. Regular and frequent backups are a common policy and the main recovery mechanism to a known good state after a ransomware attack. They are easier to implement in scenarios with centralized volumes shared through a network. Upon suffering a ransomware infection, as much work time is lost as was taken to detect the intrusion, because all the documents modified from the previous backup are only in the encrypted volumes.

DETECTING & RESPONDING TO RANSOMWARE In the event where the utilised vulnerability is unknown or there hasn’t been enough time to patch, organizations need a method for rapid detection and response. Look for early indicators of a ransomware breach. Because modern ransomware attacks are targeted and modular, attacker dwell-times can be quite lengthy before shared network files are encrypted. From the time of the initial infection to the deployment of the ransomware, attackers perform reconnaissance inside a compromised network to discover which systems are critical before encrypting files. So, one way to improve detection is to focus on monitoring internal traffic for immutable attacker behaviors like reconnaissance, lateral movement and file encryption, rather than attempting to detect specific ransomware variants in network flows or executables. For response, spotting and isolating early in the attack lifecycle stops the loss of data. Rapid host isolation should be considered good practice once an infected device has been identified. Isolation can occur by quarantine of hosts, removal of offending systems from the network, and killing the processes causing propagation. Due to the speed and severity of ransomware attack, isolation could require the use of automation like automation and orchestration tools and native integration with detection and enforcement points. It is also vital to observe privileged access to

know which accounts have access to critical systems. Ransomware can only run with the privileges of the user or the application that launches it. Comprehensive knowledge about the systems and users that access specific services will enable security operations teams to monitor misuse of privileged access and respond when that access is compromised well before network file encryption occurs.

THE CASE FOR AI Organizations hit by a ransomware outbreak find themselves in an all-hands-on-deck emergency that requires comprehensive contextual understanding to effectively halt the attack’s further progress and then restore systems immediately while business functions are held hostage. Even if an organization is willing to pay the ransom, there is no guarantee that the encryption key will be provided by the attacker. Without the encryption key, files will have to be restored from a backup, and any changes since the last backup will be lost. As such, when ransomware encrypts file shares, attacks become very costly due to resulting scale, operational downtime and data loss. To reduce the impact of future attacks, we need to move to a model of detecting behavior rather than detecting the specific tool or malware used. Such behavior detection is much more effective, but it also requires in-depth analysis of network traffic. With advances in artificial intelligence (AI) augmenting security teams, we’re already seeing the industry shift to identifying attacker behavior in real time. AI can detect subtle indicators of ransomware behaviors at a speed and scale humans and traditional signature-based tools simply cannot achieve. This enables organizations to prevent widespread damage. When organizations recognize these malicious behaviors early in the attack lifecycle, they can limit the number of files encrypted by ransomware, stop the attack from propagating, and prevent a disastrous business outage. When you are fighting a ransomware attack, time and contextual understanding are your most precious resources. ë

O CTO B E R 2 019

23


COVER FEATURE

NIDAL OTHMAN, MANAGING DIRECTOR

MAHMOUD NIMER, GENERAL MANAGER

BASHAR BASHAIREH, CEO

24

O CTO B E R 2019


COVER TOP EXECUTIVE FEATURE

STARLINK

REACHING THE $1 BILLION MARK The global True VAD has set itself an ambitious revenue target and is driving incremental business from datacentre and cloud and new geographies.

$1BILLION GAME PLAN

that with a lot of initiatives,” says Bashaireh. From Bashaireh’s point of view, there are two fundamentals for reaching the $1 Billion mark. One is to sustain the current base of revenue and relationships with vendor and partners. The other is to drive incremental revenue and business through new channel partners, new geographies, new vertical markets, cross-selling across technology stacks, amongst others. Inside StarLink, the first part of the business is managed by the product management team, that looks after vendor relationships and maintains the existing channel relationships of each vendor. Also, the channel managers based in each country manages 10-15 strategic partners each, to form a strong base of 100+ strategic partners globally. The incremental business is managed by an ambitious sales team along with the channel managers based in each country. The challenge for a value-added distributor to reach the $1 Billion mark is vastly different from that of a volume distributor, that shifts boxes. “This requires a completely different mindset, unique business model, significant investment and skilled resources. “ stresses Bashaireh. StarLink’s Co-founder and General Manager, Mahmoud Nimer who previously managed the regional sales teams, will now focus on driving the company’s strategy and new initiatives along with Othman.

As CEO and part of the management of StarLink, Bashaireh will be responsible for sales and operations across all the geographies and will drive revenue towards the vision of reaching the $1 Billion mark. His primary goal along with rest of the leadership team is to bring in innovation. “I think this is one of the core differentiators between us and the others. We are ahead of the game. We understand the demand in the market and we address

Distribution of information technology products has always followed two sides of the coin. One side has been commodity trading, the run rate business, or volume distribution. The other side has been solution-selling, using a multivendor stack, built up through competence, skills, training, also called value-added

2019 was a positive year for StarLink in terms of management and leadership restructuring. In February this year, StarLink announced the appointment of its Chief Operating Officer, Zaidoun Arbad. Arbad was previously with Cisco and HP. StarLink also announced its most important leadership appointment in September this year, bringing in Bashar Bashaireh as Chief Executive Officer. Bashaireh was previously with Symantec, Unify, Aruba and Fortinet. Preparing for 2020 and beyond, and with the appointment of Bashaireh and Arbad, StarLink has set itself an ambitious target of reaching the $1 Billion mark. From its current revenue base of $400 Million, and growing at a rate of 30% YoY, StarLink believes it can reach the figure of $1 Billion by 2024. StarLink’s Co-founder and Managing Director, Nidal Othman, points out that Bashaireh’s long baseline of working with vendors is valuable to StarLink. For all our vendors, StarLink works as an extension of their teams, in the various market we operate in. By bringing in Bashaireh, StarLink will be able to set internal expectations to understand what the vendor really expects from the distributor and what they need to do. “And that definitely will allow Bashaireh to drive the organisation to our ultimate goal,” remarks Othman.

TECHNOLOGY BUSINESS

O CTO B E R 2 019

25


COVER FEATURE

distribution. Focus, deep relationships with vendors, and a long base line of continuity, are key attributes of success in value-added distribution. In the past StarLink had primarily built its vendor solution stack in the area of cybersecurity. Today it is looking at becoming a key player in datacenter and cloud space as well. Its revenue distribution has shifted from being previously heavy on cybersecurity to the current spread of 55% in cybersecurity to 45% in datacenter and

cloud. StarLink has built its vendor stack under the following solution categories: datacenter and cloud, communication, data protection, access control and risk and compliance. StarLink’s solution stack starts with the storage and monitoring of sensitive data - its location whether on cloud or datacenter; who has access to the data; and how it is communicated. Next, it tracks the security of the data, the levels of risk and compliance around the data, and protec-

tion of the data. The end of the solution stack is management of the data, through security management or IT services management. Along with the scaling of its multi-stack vendor solution portfolio, StarLink ensures that they receive satisfactory returns for their vendors by scaling into different business verticals and multiple geographies. “Five years ago, we started investing and expanding more and more into datacenter and

SNAPSHOT StarLink is considered the largest specialised True Value-Added Distributor, VAD in the region and the third largest on a global level. It has a target to reach the $1B revenue mark in three to four years’ time, by delivering a minimum of 30% YoY growth. For that, StarLink has to be agile and dynamic to address the ever-changing technology and market landscape. With the introduction of new and disruptive technologies, IT is becoming a real business enabler, and the role of the distributor is becoming more and more challenging. There is a focus on new platforms: cloud, mobile, social networks, big data, and data analytics. Customers today are more knowledgeable in terms of technology knowhow, have high expectations and business has become more demanding. With the global economic challenges, business consolidations through mergers and acquisitions have become a business preference for organisations to address those challenges. Consolidations have a direct impact on IT, where newly emerged entities have to capitalise on best of breed technologies and integrate them in a smooth way. This represents a genuine opportunity, where integrated cyber and cloud solutions approach can help organisations address those changes associated with consolidations. For the last 15 years, StarLink has been redefining the distribution landscape in the region. It has been bringing niche and new technology vendors into the region, while espousing its unique true valueadded distributor business model. It has been empowering channel partners to differentiate their offering and become true value-added resellers.

26

O CTO B E R 2019

It has introduced special initiatives reinforcing its commitment to vendors, partners and end customers. And today, it has evolved from being a leading, specialised, cyber security, value added distributor to becoming cyber and cloud, specialised value-added distributor. SOLUTION PORTFOLIO StarLink has evolved since its inception to be a specialised Value Added Distributor focusing on Security, Cloud and Datacentre through an organic growth by building the right infrastructure and integrated technologies. StarLink operates in a value-added strategy where the distributor starts by identifying customer challenges. Technical consultants recommend the right solutions based on an integrated set of technology domains. The technology domains that StarLink supports are Datacentre and Cloud, Communication, Access Control, Risk and Compliance, and Data Protection and Management platform integrated SIEM solutions. StarLink uses a lifecycle wheel to describe its solution stack. First is Datacentre and the Cloud, specifically where does the data reside. Then it addresses communication that facilitates data transfer, internally or externally. Then comes Access Control, which addresses who has the right to access the data and in what manner. Next data risks need to be mitigated to ensure regulatory and compliancy frameworks are adhered to. Data is the most important asset within an organisation, which needs to be protected regardless of location, on premises, in cloud or in motion. This includes data

classification, data loss prevention and data encryption. Next a management platform is integrated with a SIEM solution to provide necessary forensics, threat intelligence and incidents response tools needed to address any malicious threats. PARTNER ENABLEMENT StarLink has an established network of 1,500 partners across 20 countries, servicing 2,200+ customers. The strategy is to continue delivering incremental business to partners based on integrated end to end solutions and technologies. Partner mapping is important and is done through a study of the vendors existing partner field engagement systems. StarLink sees where it can deliver impact through its partner ecosystem. Partner onboarding and enablement is a continuous one, where StarLink signs-up partners that can support incremental technologies, industries or new geographies. Though most partners cater to specialised technologies and business verticals in their region, StarLink delivers integrated end to end solutions, which is an incremental business for them. An essential element of StarLink Partner Programme is enablement, where product management and pre-sales teams carry out periodic training, knowledge transfer and cross technologies enablement workshops. StarLink product teams are trained to engage with partners with this approach and enhance partner profitability, while at the same time improve vendor market reach. Types of partners include global system integrators across multiple geographies, strategic and managed partners that mostly carry multiple solutions and technology domains within their portfolio


COVER FEATURE

cloud . Today, our revenue sees a balance between Cyber and Datacenter and Cloud. We now have an end-to-end story starting from datacenter and cloud and communication of this data.” says Othman. “That is our complete solutions offering and we have worked very hard in the last twentyfour months to complete this story,” he points out. While StarLink does transact with close to 1,500 channel partners across all its geographies, the top 100 strategic partners generate 80% of its

business. With its successful vendor partner solution stack and global geographic reach, StarLink is increasingly seeing global system integrators engaging with it. According to Bashaireh, global system integrators can see value in the countries they are operating in, across managed security services and Infrastructure-as-a-Service. “We see a shift right now in the market to procure IT. And that is an area that we are focusing on to have alliances

offering, managed security services partners, also channel partners targeting small and medium businesses.

eMarketPlace, StarLink Advisory Board, StarLink Elite Club, StarLink Capital, that has taken affiliation to the next level.

ORGANISATION StarLink has a structured organisation including Business Development, Product Management, Marketing, Pre-Sales, Inside-Sales, Regional Teams, Professional and Training Services to manage vendor portfolios across geographies. A recent business initiative is the StarLink MarketPlace portal which allows partners regardless of their location to transact and do business through this cloud portal.

PARTNER LOYALTY StarLink Choice is an incentive programme for Strategic Partners to facilitate Partner revenue growth, improve partner commitment, differentiate partner services, secure partner ROI, challenge competition, reward performers and celebrate partner success.

Each partner has a unique account with secure access, where through a unified dashboard can place and track orders, have an overview of pending orders, deliveries and accounts. This portal makes it easier and faster to do business with StarLink and improves overall partner experience. StarLink’s vendor partner relationships and operations work hand in hand. StarLink believes that collective success lies in working closely to ensure there is visibility and transparency. StarLink acts as the extended arm for vendors partners, rolling out the StarLink Partner Programme, which is aligned with the Vendors Channel Programmes. This ensures roll out of the same programme regardless of locations. StarLink performs quarterly business reviews with vendors and partners to make sure programmes are executed and gives the chance to introduce improvements. In the past two years, StarLink has started initiatives such as StarLink Innovation Centre, StarLink Academy,

From StarLink’s side and in line with StarLink Choice programme, the distributor is proportionally investing into partners technical and solutions knowhow to enable them achieve higher levels of business and accordingly continue benefiting from loyalty programme. Recently it has introduced StarLink Capital, through which loyal partners can benefit from to address qualified projects. The StarLink Partner Programme is aligned to the Vendors Channel Programmes, so it is essential that channel partners adopt this programme to avail from the many associated benefits such as enablement and training that will ensure they are empowered to sell integrated solutions. Another benefit is marketing and lead generation programmes that are important for sustaining the right levels of business growth. It is important that relationship with partners enjoy the highest levels of loyalty and transparency. StarLink offers partners many tools for empowering their business, so it is important for them to have the ability to leverage on these provided tools.

with major service providers across the region, and wherever we operate,” he explains. As a value-added distributor, selling innovative solution stacks, selecting the right vendor is as critical for StarLink, just as selecting the right distributor is important for the vendor. For partners, StarLink offers a rich portfolio of solutions to take them to the next level of growth and profitability. “This is what we are good at, and we are selective. We select the right vendor - we are a specialised distributor that builds solutions by integrating technologies and between the vendors, partners, customers and our expert workforce, we work together as one team - this is what differentiates us, emphasizes Nimer.

MARKET OPERATIONS “StarLink started its operations in the Middle East region and have expanded into Turkey and Africa, Europe and the US. The distribution of revenue by geography has also followed this historical pattern. In 2019, Middle East contributed 70% of the revenue, while the combined, rest of the geographies contributed 30%. By 2020, we are optimistic about rebalancing the distribution of revenue to 60% from the Middle East and 40% from rest of the geographies eventually bringing it to 50-50% . This is our goal,” remarks Nimer. With majority of StarLink’s vendors and partners operating across the Middle East, Africa and Turkey markets, the distributor experienced a smooth transition while expanding into Africa and Turkey. However, its expansion into Europe and the US have been a different learning experience. StarLink has entered Europe with a focused approach, selecting only UK, Germany and Netherlands as its initial points of entry. Othman considers Europe to be a brand-new market, with completely different dynamics and different culture. “It took us a couple of years to understand the dynamics of our channel and the vendors’ requirements and the gaps in these markets.” In parallel with Europe, StarLink also entered the US market. With the majority of its vendors based out of the US, entering this geography has helped StarLink strengthen its relationships with them. “So, I could say, US is a startup. For Europe, it’s a learning curve. And in Turkey, South Africa and Africa in general we are at a mature stage,” says Othman. StarLink has got all the pieces in place and has started making the right moves to reach its target of $1 Billion over the next five years. As we enter 2020 and beyond, with the rapidly changing technology and geopolitical landscape, for StarLink it may just be the start of a new beginning. ë

O CTO B E R 2 019

27


TOP OF MIND

NETWORK DETECTION & RESPONSE THE NEW NETWORK SECURITY PARADIGM The threat of a cyber incident – at the hands of an adversary or an insider — looms large in organizations of all sizes. In recent years, the number of sophisticated attacks on large infrastructures has surged, dealing billions of dollars in damage to enterprises worldwide. Malicious or negligent insiders further increase the risk of a breach or data leak. Making matters worse, the rapid adoption of cloud services and the Internet of Things (IoT) solutions, without proper safeguards, is expanding the attack surface for bad actors. Large enterprises strive to build a secure ecosystem where multi-vendor components, on all levels, work seamlessly together. However, this is easier said than done in a dynamic infrastructure teeming with endpoints and just as many hands-on deck. While employees remain the weakest link in the attack kill chain, recent studies show rapid adoption of new technologies like Infrastructure as a Service (hybrid clouds), Industrial IoT (IIoT) and Bring Your Own Device (BYOD) practices are opening the floodgates to new waves of cyber incidents. One of the biggest problems IT security chiefs face is the speed with which their teams can detect and respond to a potential security incident.

and network-wide remediation. It supports both manual and automated remediation actions and saves time and resources without requiring additional hires or skill. Network-centric security isn’t new, but it’s certainly a recent hot topic in the context of evolving cyber threats. To better combat advanced persistent threats, malware, malicious insiders or negligent behavior, vendors have started to craft solutions using machine learning and behavior analytics with insights from cloud threat intelligence derived from millions of sensors globally.

CHOOSING THE NDR SOLUTION THAT’S RIGHT FOR YOU

TAREK KUZBARI, REGIONAL DIRECTOR - MIDDLE EAST, BITDEFENDER

PREVENTION IS KEY, AND SPEED IS KEY TO PREVENTION Prevention is better than cure, and nowhere is this more true than in cybersecurity. There is no one-size-fits-all solution for every kind of threat or infrastructure. However, in recent years, progressive organizations have started taking a proactive approach to combating cyber incidents. Their new strategy which marks a paradigm shift for cybersecurity — deploys multiple layers of detection, prevention, and remediation for all kinds of threats, both external and internal, at the network level as well as at endpoint level. Even if a sophisticated attack gets past one layer, security operations centers (SOCs) can still catch the attack somewhere in transit. However, because the time between detection and response

28

O CTO B E R 2019

is critical, for this strategy to work, some AImagic is required automation.

NETWORK DETECTION AND RESPONSE Network Detection and Response (NDR) — the brainchild of Network Traffic Analytics, Network Forensics and Endpoint Detection and Response combines advanced security traffic monitoring and analytics, in-depth investigative capabilities and remediation measures on both endpoint and network levels. A next-generation solution, NDR enables SOC teams to perform fast triage, root cause analysis,

A business handling large clusters of customer data should prospect NDR solutions that only analyze traffic meta-data, eliminating the risk of exposing payload data on unencrypted communication, and ensuring compliance with both local and international data privacy laws. The exclusive focus on traffic meta-data eliminates privacy concerns surrounding non-encrypted traffic, but still lets SOCs identify network behavior that violates policy. The ideal NDR deployment can further ease compliance by analyzing encrypted traffic for suspicious behavior without having to decrypt actual data packets. Enterprises everywhere must protect corporate-issued endpoints, user-managed devices and network elements, as well as BYOD and IoT deployments. This is particularly true in most UAE and Saudi firms. Besides the main pain points of protection, costs and skills, NDR will help dramatically in terms of interoperability within the IT ecosystem, especially for hybrid infrastructures with smart devices, IoT, Operational Technology (OT), and even legacy systems. Finally, all prospecting NDR buyers should seek a single-pane solution that offers a bird’s eye view of all network activity across the infrastructure, saving them time and money without requiring an extensive, skilled staff to maintain the solution, while stepping up the security maturity ladder. ë


Integrated Risk Management Software, Advisory & eLearning SOFTWARE TO MANAGE

ETHICS & COMPLIANCE LEARNING

•

Enterprise Risk Management

•

Operational Risk Management

•

Regulatory Change Management

•

Internal Control over financial reporting

•

IT Risk & Compliance

•

Cybersecurity & Vendor Risk

•

GDPR & Data Privacy

•

Internal Audit

•

Business Continuity Management

• •

eLearning covering 20+ risk topics including data privacy, code of conduct & anti-bribery Micro-content, videos/teasers, phishing simulations

•

59+ languages

•

Mobile responsive customisable content

•

Configurable to meet brand requirements

•

Tools to measure programme effectiveness

solutions to advance confidently

For more information visit www.saiglobal.com email: info.emea@saiglobal.com Tel: +971 50 728 7247 SAI Global ABN 67 050 611 642 ©2019 SAI Global. The SAI Global name and logo are trademarks of SAI Global. All Rights Reserved.


TOP OF MIND

EMAIL SECURITY GATEWAYS TO SAVE YOUR LIFE EMAIL SECURITY GATEWAYS TO SAVE YOUR LIFE

IMPORTANCE OF EMAIL SECURITY GATEWAYS?

No trick to security it’s just common sense. Digital era has become a big boon for all of us. People during the earlier days Practiced Traditional methods of securing their data’s, and all the important transactions. With the growth of the digitalization and modernization we have become more dependent on Digital Media. Emails are the most trusted and effectively used by all Business Organizations. Email security ought to be a top need for your organization. Email is the main objective utilized by programmers to gain admittance to your organization’s private information, utilizing assaults like phishing. Your first line of resistance ought to be an Email Secure Gateway. This is a stage which watches your messages against programmers, spam and infections. There’re many Email Security Gateway arrangements accessible. Some are focused towards enterprise clients searching for granular administrator controls and propelled usefulness. Some are more qualified for littler organizations searching for a simple to utilize stage with a decent value point. To enable you to locate the correct arrangement, Expert Insights has denied a rundown of a portion of the top Secure Email Gateway stages. We’ll take you through their highlights; that they are so natural to utilize and how well they work.

Email is the main objective utilized by programmers to gain admittance to your organization’s private information, utilizing assaults like phishing. Email is a frail point inside business systems, and techniques for assaulting email are developing more focused on and modern. Organizations from all ventures are confronting an expanding number of focused dangers, for example, phishing assaults, ransomware and malignant connections. Your first line of safeguard ought to be an Email Security Gateway. These arrangements secure organizations by blocking vindictive substance contained in messages and preventing malevolent messages from being conveyed into the inbox.

SECURE EMAIL GATEWAYS Email Security Gateways, or Secure Email Gateways, provide predelivery protection by blocking email-based threats before they reach a mail severity protect businesses from spam, viruses, malware and denial of service attacks. The gateway scans all incoming, outbound and internal email communications, including attachments and URLs for signs of malicious or harmful content. Email Gateways will also offer protection from social engineering attacks such as phishing, or malware attacks. The gateway can check the domain of incoming emails, as well as scan and

30

O CTO B E R 2019

PAVIN VARUGHESE,

VP - CYBER SECURITY, MINDFIRE TECHNOLOGIES

Filter for suspicious content within the email, to stop harmful content from coming into the network. Emails that have been marked as malicious are quarantined or rejected. Alongside blocking and Filtering incoming threats, Email Gateways will also scan outgoing content. This can help protect businesses from data loss. They also provide business with Continuity features, which mean that even if their email network goes down, they will still be able to access their emails. Email Gateways will also provide businesses with a management dashboard and a range of reports and analytics. These give businesses visibility into all email traffic in a network. This is important for businesses to gain insights into their network security.

HOW DO EMAIL SECURITY WORKS? Secure Email Gateways function as a gathering of various innovations that work together to square email dangers. They fill in as a firewall for email interchanges, authorizing a lot of principles about what email can enter or leave your email arrange. They check all inbound and outbound vindictive messages, to prevent malignant substance from entering your representative’s inboxes. Secure Email Gateways can be founded on various cloud-based models. Secure Email Gateways take a shot at a system level, separating email before they reach inboxes. Thusly, they don’t affect end-client gadgets by any stretch of the imagination. This implies they offer a solid degree of assurance for email customers on all gadgets, not only those on the organization. This enables you to secure representatives working remotely or utilizing their own PCs for work.

FEATURES OF A SECURE EMAIL GATEWAY The key highlights of a Secure Email Gateway are spam sifting, infection and malware blocking, phishing insurance and administrator controls and announcing. l Spam Filtering: Spam sifting is the center component of a Secure Email Gateway. All SEGs


TOP OF MIND

use separating advancements that squares or isolates email from realized spam email spaces. They help in effective filtration of the emails and report the spam and corrupted emails. l Infection and Malware Protection Secure Email Gateways square infections and malware from tainting business systems. This functions as the SEG channels email with hostile to infection advancements that distinguish, and afterward isolate messages found with pernicious URLs and connections. l Phishing Protection: Email portals give organizations a degree of insurance from phishing assaults. Utilizing against misrepresentation innovations, they can spot and anticipate sender satirizing, and use space name approval, to distinguish and square phishing assaults. The infection and malware assurance will likewise expel messages with malignant URLs and connections, which will stop messages with connections to phishing sites from entering inboxes. l Administrator Controls and Reporting: SEGs give administrators command over all email approaches. They offer administrators the capacity to oversee security over the entire email arrange, with a unified administrator dashboard. Mechanized and configurable reports permit administrators more prominent perceivability over their email security scene.

BENEFITS OF SECURE EMAIL GATEWAY Secure Email Gateways offer organizations various advantages. They shield representatives from email dangers like spam, infections and phishing assaults, which thusly secures organizations. Workers are greatest assault vector for business systems, and email is a practical objective for assailants to arrive at representatives. Having a Secure Email Gateway set up enables organizations to improve security for workers by blocking pernicious messages and halting phishing assaults. Many Secure Email Gateways offer email documenting and encryption that enable associations to verify their delicate information and address consistence issues by putting away duplicates of email for lawful reasons. This implies organizations can accomplish more noteworthy security and meet lawful consistence. ĂŤ

O CTO B E R 2 019

31


TOP OF MIND

RAJEEV DUTT,

REGIONAL BUSINESS DIRECTOR - MEA, SAI GLOBAL

32

O CTO B E R 2019


TOP OF MIND

SIZING UP RISKS FOR THIRD-PARTIES & VENDORS Third parties and vendors can bring a lot of value to the table – but with that also comes risk.  How do you assess, address, and mitigate? Continuation from September issue…….

Third-party and vendor risk mitigation can take many forms:

REQUIRE THE VENDOR TO CHANGE THEIR PROCESS OR BUSINESS TO MEET YOUR NEEDS Depending on the severity of the risk and the willingness of the vendor, this is often the best approach…but also not often the easiest.

ENSURE A LEVEL OF TRUST THROUGH DOCUMENTATION Third-party validation through certifications, reviews, audits, and the like can instill a level of confidence in the business that the third-party is operating to a satisfactory level. PROTECTING AGAINST MISSTEPS WITH LEGAL LANGUAGE Defining and agreeing to specific (minimum, average, etc.) levels of performance can be achieved with service-level agreements (SLAs). Further, these can limit liability or define recourse in the event that something in the partnership runs afoul. PERIODICALLY CHECK ON THE PERFORMANCE OF THE VENDOR Whether remote or on-site, checking that the vendor is indeed honoring their terms of the contract through actual observations demonstrates the business’s level of concern to potential risk issues. Further, these observations can be regular or irregular; announced or unannounced.

TERMINATE THE VENDOR/BUSI-

NESS RELATIONSHIP COMPLETELY This may not address missteps from the past but severing the working relationship can prevent may further risks from occurring.

IN CASE OF EMERGENCY, BREAK GLASS Changing climates, business processes and even our growing dependence on technology and third-party vendors means that there is an increased risk for a multitude of business disruptions. To ensure stability, a robust business continuity plan (BCP) is crucial. A thorough BCP plan ensures all critical functions will continue to operate at minimum levels – or be recovered quickly – in the face of an outage to safeguard the longevity of the organization. Business continuity is complex. All areas of the business are subject to potential threats, however understanding the order in which processes and functions need to be recovered to maintain operations is imperative. For instance, l Is it more important to keep your online or brick and mortar store open? l Is internet access necessary to deliver your goods and services? l If facilities are inaccessible, where will your employees report for work, and when? Further complicating the development of a plan is the level of dependence upon third-party vendors. What goods and services do they provide to your organization and how important

are they in regard to the continuance of your business? Do they have a BC plan in place, when was it last tested, and what were the results in regard to the SLAs you hold with them? Many businesses often overlook planning for the scenario when a critical partner has a service outage. Just as Business Continuity Management is used to plan for an outage, Vendor Continuity Management should be applied to ensure all scenarios are covered.

THE BOOK OF RISK IS NEVER CLOSED You’ve spent considerable time building a BC plan – from basic due diligence to ranking internal and external risk levels to figuring out how you’ll address issues. But unfortunately, you’re not done. Risk evolves over time. Some get bigger. Some compound one another. Some are replaced by newer and more impactful risks. Smart businesses need to stay agile. As our dependency on external changing business processes, vendors and technology deepens, risks keep evolving as well. You simply can’t rely on checking in once per year. Evaluating risks and the plans to mitigate them, to be continuous, robust, and improve over time. As the saying goes, “you need the right tool for the job.” And in this case, the right tool, or tools, are ones that can help you respond and react to the ever-changing risks of the business landscape. The best tools, therefore, will not only aid in capturing the data, but also enable the business to query and report on that data, notify when important changes occur, and suggest actions for addressing, before issues get out of hand. ë

O CTO B E R 2 019

33


TOP OF MIND

XHUNT CAMPAIGN: ATTACKS ON KUWAIT SHIPPING AND TRANSPORTATION ORGANIZATIONS

Between May and June 2019, Unit 42 observed previously unknown tools used in the targeting of transportation and shipping organizations based in Kuwait. The first known attack in this campaign targeted a Kuwait transportation and shipping company in which the actors installed a backdoor tool named Hisoka. Several custom tools were later downloaded to the system in order to carry out post-exploitation activities. All of these tools appear to have been created by the same developer. We were able to collect several variations of these tools including one dating back to July 2018. The developer of the collected tools used character names from the anime series Hunter x Hunter, which is the basis for the campaign name “xHunt.” The names of the tools collected include backdoor tools Sakabota, Hisoka, Netero and Killua. These tools not only use HTTP for their command and control (C2) channels, but certain variants of these tools use DNS tunneling or emails to communicate with their C2 as well. While DNS tunneling as a C2 channel is fairly common, the specific method in which this group used email to facilitate C2 communications has not been observed by Unit 42 in quite some time. This method uses Exchange Web Services (EWS) and stolen credentials to create email “drafts” to communicate between the actor and the tool. In addition to the aforementioned backdoor tools, we also observed tools referred to as Gon and EYE, which provide the backdoor access and the ability to carry out post-exploitation activities. Through comparative analysis, we identified related activity also targeting Kuwait between July and December 2018, which was recently reported by IBM X-Force IRIS. While there are no direct infrastructure overlaps between the two campaigns, historical analysis shows that the 2018 and 2019 activities are likely related.

ACTIVITY OVERVIEW On May 19, 2019, we observed a malicious

34

O CTO B E R 2019

binary named inetinfo.sys installed on a system at an organization within the transportation and shipping sector of Kuwait. The file inetinfo.sys is a variant of a backdoor called Hisoka, specifically noted as version 0.8 within the code. Unfortunately, we do not have telemetry on how the actor gained initial access to the system to install the Hisoka backdoor. Within two hours of gaining access to the system through Hisoka, the actor deployed two additional tools named Gon and EYE, whose names were based on the filenames Gon.sys and EYE.exe. At a high level, the Gon tool allows the actor to scan for open ports on remote systems, upload and download files, take screenshots, find other systems on the network, run commands on remote systems and create a Remote Desktop Protocol (RDP) session. The actor can use Gon as a command-line utility or by using a Graphical User Interface (GUI), as seen in Figure 1. The actor uses the EYE tool as a failsafe while they are logged into the system via RDP, as the tool will kill all processes created by the actor and remove other identifying artifacts if a legitimate user logs in. Please reference the Appendix for more detailed information on Gon and EYE. By hunting within our data set, we were able to identify a second Kuwait organization also in the transportation and shipping industry targeted by the same threat group. Between June 18-30, 2019, threat actors installed the Hisoka tool. This time version 0.9, which contained the filename netiso.sys. On June 18, this file was observed being transferred to another system via the Server Message Block (SMB) protocol from an internal IT service desk account. Shortly after, a file named otc.dll was seen transferred in the same manner. The otc.dll file is a tool named Killua that is a simple backdoor that allows an actor to issue commands from a C2 server to run on the infected system by communicating back and forth using DNS tunneling. Based on string comparisons, we believe with high confidence

Figure 1. Gon’s GUI

that the same developer created both the Killua and Hisoka tools. We first observed Killua in June 2019 leading us to believe that Killua is a possible evolution of Hisoka. Details on the Killua tool are included in the Appendix. On June 30, we observed related activity that was quite interesting, as the actor used a third-party help desk service account to copy the files to an additional system on the network. This activity began with the transfer of another Hisoka v0.9 file, followed by two different Killua files within a 30 minute timeframe.

HISOKA EMAIL-BASED C2 During our analysis, we identified two different versions of Hisoka, specifically v0.8 and v0.9, both installed onto the network of two Kuwait organizations. Both versions contain command sets that allow the actor to control a compromised system. In both versions, the actor can


TOP OF MIND

communicate via a command and control (C2) channel that uses either HTTP or DNS tunneling. However, v0.9 also added the ability for an email-based C2 channel as well. A more detailed analysis of the two variants can be found in the Appendix. The email-based C2 communications capability added to Hisoka v0.9 relies on Exchange Web Services (EWS) to use a legitimate account on an Exchange server in order to allow the actor to communicate with Hisoka. The malware attempts to log into an Exchange server using supplied credentials and uses EWS to send and receive emails in order to establish communications between the target and the actor. To initiate communications, Hisoka notifies the actor that it is ready to receive commands by creating an initial email draft that is analogous to the beacon in other command and control channels. The initial email draft contains the subject “Present” with an empty email body and an email address in the “To” field that has an identifier unique to the compromised system (“ABCDEF” in our testing) appended to “@contoso.com”. Figure 2 shows the initial draft email created by Hisoka viewed by logging into the account via Outlook Web App. To issue commands, the actor will log into the same account and create a draft with the subject “Project” and a specially crafted message body that contains the command as an encrypted string. We determined the structure of this message body by analyzing the code and found that the email must contain the string <body> with a base64 encoded ciphertext on the following line. While we have not seen the actor using this email channel for C2, we believe the email was sent as an HTML email, as Hisoka will check that the email contains three lines after the <body> tag. This is done by checking for three carriage return characters (\r), which we speculate is meant to include: one line for the ciphertext, one line for the closing </body> tag and the last line for the closing </html> tag. The actor will encrypt the desired command by using the XOR operation on each character with the value 83 (0x53) and base64 encoding the ciphertext. Figure 3 shows the email draft we created to test the C2 channel that issues the command C-get C:\\Windows\\Temp\\test.txt, which Hisoka will parse and treat as a command to upload the file at the path C:\Windows\Temp\ test.txt. After parsing and running the commands obtained from the draft email containing the subject “Project”, Hisoka will create another email draft to send the results of the command to the actor. This email draft will again have

36

O CTO B E R 2019

“Present” as its subject with the same email address constructed with the system’s unique identifier and “@contoso.com” in the “To” field. The message body of the email draft is base64 encoded ciphertext that contains the response or result of the command and uses the same XOR cipher with 83 (0x53) as the key used to encrypt the data. In the case of the file upload command, Hisoka will attach a file of interest to the email draft as well. The email draft has the file test.txt attached and the decoded and decrypted message body is the string [!] C:\\Windows\\Temp\\test. txt Attached.\r\n\t\t\t\t\t\t{ Hisoka}. While this is not the first email-based C2 channel we have seen in threat activities, the use of saved drafts and a legitimate Exchange account shared between the malware and the actor is rather uncommon and has not been observed in quite some time.

OVERLAPS IN TOOLSET During our analysis of the malware activities occurring at the Kuwait organizations, we began seeing a trend in string observables between Hisoka and other tools identified in this activity. These strings led us to identify a separate tool referred to as Sakabota by its author with the earliest sample identified around July 2018. We analyzed dozens of samples during this analysis, which resulted in the identification of two separate campaigns — one in mid-to-late 2018 using Sakabota and the other in mid-2019 using Hisoka. Our analysis of the two campaigns revealed that Sakabota is the predecessor to Hisoka, which was first observed in May 2019. By analyzing both Hisoka and Sakabota as well as the additional tools identified in the aforementioned activity, we have determined that Sakabota is likely the basis for the development of all the tools used in these attack campaigns. The Hisoka backdoor tool shares a significant amount of code from Sakabota, which is what leads us to believe that Hisoka evolved from Sakabota’s codebase. The number of functions and variable names are exactly the same in both Sakabota and Hisoka suggest, which infers that the same developer created both and spent little effort trying to hide this lineage. The following screenshot depicts a code comparison for Hisoka and Sakabota showing several variable name overlaps (“Chenged_Host”, “Host_Port”, etc) as well as the same general flow by which both tools determine if they should use the hardcoded C2 domain name or one provided as an argument on the command line. We also observed shared code between Sakabota and the other tools used in the 2019

campaign. For instance, the Self_Distruct method in EYE matches the Self_Distruct method in several Sakabota samples, and both tools print the highly unique string we be wait for you boss !!! to the window. In addition to those code overlaps, the string “Sakabota” was also observed numerous times within Hisoka and the post-exploitation tools Gon and EYE observed in the 2019 Kuwait activity. First, Hisoka will display usage instructions if supplied with the appropriate command-line argument. The usage instructions contain a changelog at the bottom that includes the string Compatible with Sakabota v3.2 that suggests a linkage between Hisoka and Sakabota. Throughout our analysis of all Hisoka samples collected, we observed usage instructions containing references up to Sakabota v3.4.

CONNECTION TO 2018 CAMPAIGN After identifying a relationship between Hisoka and Sakabota, we conducted a search and found several Sakabota samples — all of which were configured to use the domain pasta58[.]com for its C2 server. During general infrastructure analysis, this domain was seen in overlapping infrastructure previously observed in attacks on organizations in Kuwait between April and November 2018. Additional related activity was observed in July 2018, which involved spearphishing emails that delivered macro-enabled documents to install PowerShell-based payloads. We do not have additional telemetry on these attacks at this time.

CONCLUSION While there are similarities in the targeting of Kuwait organizations, domain naming structure and the underlying toolset used, it remains unclear at this time if the two campaigns (July to December 2018 and May to June 2019) were conducted by the same set of operators. Historical infrastructure analysis, as depicted in the link analysis chart, shows a close relationship between Hisoka and Sakabota infrastructure as well as with known OilRig infrastructure. Palo Alto Networks customers are protected by these threats through the following: l Customers using AutoFocus can view this activity by using the following tags: xHunt, Sakabota, Hisoka, Killua, Gon, EYE l DNS Tunneling activity referenced in this blog is detected through DNS Security automated detection. l All tools identified are detected as malicious by WildFire and Traps. ë


POWERED BY

DUBAI

RIYADH

DOHA

02 SEP 2019

11 SEP 2019

22 OCT 2019

KUWAIT

MUSCAT

KARACHI

03 NOV 2019

13 NOV 2019

ABU DHABI

NOV 2019

23 NOV 2019

CUT COSTS BY GAINING INSIGHT INTO YOUR MULTIVENDOR INFRASTRUCTURE AND MULTI-CLOUD

Executive Breakfast Briefing Sessions BROUGHT BY

FOLLOW US:

MEDIA PARTNERS

Enterprise Channels MEA

EC_MEA

STRATEGIC PARTNER

Enterprise Channels MEA

www.ec-mea.com


TOP OF MIND

WHY IOT DDOS THREATS CONTINUE TO LOOM IN EMERGING NEW TECH There’s a flood of connected devices making their way into our homes and businesses – a deluge exacerbated by recent holiday gifts and the latest and greatest from CES, where connected devices always take top billing. From mobile, wearables and car technology to advancements in smart homes, TVs and cameras, the tech world is awash with internet-connected devices. By 2020, it’s estimated that there will be more than 30 billion connected devices in the world – more than four times the earth’s population.

HACKERS ARE WATCHING Tech-hungry consumers keep their eyes peeled for major device announcements. Also watching are distributed denial of service (DDoS) attackers who have made the Internet of Things (IoT) their weapon of choice. These nefarious actors exploit millions of vulnerable IoT devices to create sophisticated malware-based DDoS botnets they then use to initiate devastating attacks. IoT vulnerabilities give these hackers the ability to scale their attacks across tens of millions of devices and unique IP addresses. These new device announcements add more weapons to an already stocked arsenal of connected gadgets hackers have at their disposal that they can weaponise and leverage to launch DDoS attacks. If we’ve learned anything from the Mirai botnet’s path of destruction in late 2016, during which attackers hijacked more than 500,000 webcams to launch a DDoS attack topping 1 Tbps, and last year’s WireX and Reaper threats, it’s that bad actors will latch onto unsecured devices and use them to do their bidding. “Millions of unsecure, internet-enabled devices provide new threat vectors. Given the rapid proliferation of Internet of Things devices in

38

O CTO B E R 2019

advance of IoT-oriented security standards and configuration practices, expect these devices to be increasingly used as weapons for DDoS and other attacks,” said Adam Isles, principal at The Chertoff Group, a global advisory firm that provides security risk management, business strategy and merchant banking advisory services.

IOT THREATS A GROWING CONCERN AMONG BUSINESSES According to a recent AT&T Cybersecurity Insights report, nearly a third (32 percent) of surveyed organisations said IoT-based DDoS attacks are their biggest future cybersecurity concern. AT&T found that more than a third (35 percent) of all its survey respondents say IoT devices were the primary source of a data breach experienced over the prior year. And the outlook for future IoT attacks remains bleak, with 68 percent of survey respondents saying they expect IoT threats to increase in the coming year. That said, AT&T found that 90 percent of organisations have conducted enterprise-wide cyber risk assessments in the past year, but only half (50 percent) have conducted risk assessments specific to IoT threats. Meanwhile, according to this Application Intelligence Report (AIR), distributed denial of service (DDoS) attacks took the top spot among cyberthreats against businesses, with more than one third (38 percent) of IT decision makers saying their company has suffered an attack at least once over the past 12 months, with another 9 percent noting they’re not aware whether they’ve been attacked or not. Frighteningly, that means that nearly half of IT professionals say their company has either been a victim of a DDoS attack or they don’t know if they’ve been a victim. AIR respondents, however, don’t fear IoT as

much as they probably should. For example, AIR respondents rank laptops as the most vulnerable type of device, more so than smartphones and even more so than IoT devices, a misperception that, if exploited, could give hackers an inroad into corporate networks. This rash of IoT-based DDoS attacks when paired with lack of awareness and the growing roster of IoT devices hitting the market creates a potentially catastrophic cocktail of opportunity for savvy cyberattackers. The consensus: IoT-based DDoS attacks will grow in both bot size and traffic volumes mostly due to their use of vulnerable, poorly-secured IoT devices. Contributing to those millions of vulnerable IoT devices will be this year’s crop of marquee CES announcements and the myriad gadgets found under the Christmas tree.

PROTECTION FROM IOT DDOS ATTACKS The rise of IoT DDoS attacks makes it imperative to rethink DDoS defences to thwart these sophisticated and often devastating threats. Here are key things to look for in an effective DDoS defence solution to ensure that IoT DDoS attacks can’t take you down: l DDoS defence solutions should be capable of detecting, mitigating and reporting on multivector DDoS attacks at the network edge and in centralised scrubbing centers to scale to defend against colossal IoT-fueled attacks l DDoS defence solutions must differentiate botnet traffic from legitimate traffic and users, so services stay available when battling an attack l DDoS defence solutions should include intelligence into known botnets and agents to defend networks against known threats l DDoS defence solutions must scale yet maintain cost-efficiency ë


TOP OF MIND

RONALD SENS,

EMEA DIRECTOR, A10 NETWORKS

O CTO B E R 2 019

39


DEEP DIVE

NEW NCIPHER HSM AS A SERVICE DELIVERS HIGH-ASSURANCE SECURITY nShield as a Service provides cryptography on-demand using cloud-based nCipher hardware security modules (HSMs), and allows secure code execution in the cloud

nCipher Security, an Entrust Datacard company, unveiled nShield as a Service, a cloud-based hardware security module (HSM) service that allows organizations to protect sensitive data and applications and helps meet compliance mandates – simply and efficiently, using on-demand cryptography. “Organizations embracing cloud-first strategies require cloud-first encryption,” said Peter Galvin, vice president of strategy, nCipher Security. “This means remote, automated management at scale, and flexible access control both in the cloud and onsite. nShield as a Service makes it easy to adopt a secure, multi-cloud encryption strategy using the same nShield HSMs organizations deploy onsite today.” nShield as a Service is ideal for cloud-first strategies, selective cloud migration, or adding HSM capacity to handle workload spikes. The customer experience is consistent and familiar – users interact with the cloud-based nShield® HSMs in the same way as with nShield appliances in their own data centers. And customers utilizing nCipher’s unique secure execution environment to run sensitive application code within a secure FIPS-validated boundary now have that same opportunity using cloud-based as well as on premises HSMs. Using nShield as a Service, customers can: l implement Bring Your Own Key and Host Your Own Key solutions with a trusted third party service l maintain full control over key material and maintain separation of data from the encryption keys l extend cloud-based cryptography and key management across multiple clouds l implement secure code execution for cloud-b ased workloads l integrate with third party applications in the cloud

40

O CTO B E R 2019

“The nShield as a Service launch highlights the synergies we’ve gained since becoming an Entrust Datacard company in June,” Galvin said. “We were able to accelerate and enhance nShield as a Service by combining our HSM and cryptography expertise with Entrust Datacard’s experience in data centers, cloud services and HSM operations. The result is a powerful HSM as a service solution that complements the company’s cloud-based PKI and IoT security solutions.” Hamid Qureshi, territory sales manager EMEA and Middle East at nCipher Security, says: “Here in the Middle East we’re experiencing unprecedented digital transformation, especially when it comes to implementation of cloud technologies. The beauty of nShield as a Service is that it will allow enterprises across the region to embed an encryption framework in their organization that’s efficient, flexible and cost-effective, whether their focus is on a cloud-only or a hybrid approach.” “Encryption is a powerful tool,” said Robert Westervelt, Research Director, Security Products, IDC. “Delivering it easily across distributed infrastructure can be very effective in protecting data and applications against cyberattacks. Solutions such nShield as a Service allow even the largest organizations to secure their public cloud workloads with all the conveniences of software-as-a-service offerings. Now, there are no excuses for not using encryption in the cloud.”

HOW NSHIELD AS A SERVICE WORKS nShield as a Service uses nShield HSMs to generate, access and protect cryptographic key material separately from sensitive data. All nShield HSMs are managed through nCipher’s unique Security World key management architecture that spans cloud-based and on premises HSMs. This lets customers efficiently scale HSM operations while

retaining control of their key material, even if they change their cloud service provider. Organizations can utilize nShield as a Service to supplement or replace on premises HSMs, while keeping the benefits of HSM ownership. The subscription model lets enterprises budget predictably, manage capacity, reduce data center footprint and decrease time spent on routine maintenance and monitoring. Customers seeking cloud-first solutions can work with market-leading cybersecurity vendors in nCipher’s nFinity Strategic Technology Partner program. Applications include SSL, code signing and database encryption and more. Customers seeking cloud-first solutions can work with market-leading cybersecurity vendors in nCipher’s nFinity Strategic Technology Partner program, including F5, IBM, Micro Focus Voltage and Venafi (see quote sheet below). Applications include SSL/TLS, code signing, data and database encryption and more.

NCIPHER SECURITY NFINITY STRATEGIC TECHNOLOGY PARTNERS TALK ABOUT NSHIELD AS A SERVICE: F5 “F5 has deep experience in application delivery and security services and helps customers protect their critical applications, ensuring they are safe, secure, and available. The launch of nShield as a Service from nCipher Security gives F5 customers enhanced security choices with the ability to achieve data sovereignty on a subscriptionbased model. Shifting security from a capital to an operational expenditure enables greater flexibility and cost-effectiveness for organizations,” said John Morgan, VP & GM Security at F5 Networks.


Synergising the Mind & Technology Economy The biggest tech show in the Middle East, North Africa & South Asia

#GITEX2019

gitex.com

#gitexfuturestars

futurestarsSales@dwtc.com


DEEP DIVE

nShield as a Service deployment options Customer – Self Managed

Data Center 1

RAC

VPN Remote Admin Remote Server File System ACS

TVD

Customer – Self Managed

Customer – Fully Managed

nShield HSM

nShield HSM

Network Management & Monitoring

Network Management & Monitoring

Application Server

ACS

Customer Cloud

TVD

RAC

RFS

RAS

Trusted Team

Data Center 2 VPN Application Server

ACS: Administrator Card Set

TVD: Trusted Verification Device

RICK ROBINSON, WW OFFERING MANAGER, ENCRYPTION AND KEY MANAGEMENT, IBM SECURITY: “As enterprises increasingly migrate business processes to the cloud, security continues to be a major concern. Ensuring that critical applications and their underpinning cryptographic keys can be protected and managed throughout their lifecycle is vital. The launch of nShield as a Service from nCipher Security gives our joint customers greater choice and the ability to have subscription-based data sovereignty,” said Rick Robinson, WW Offering Manager, Encryption and Key Management, IBM Security. MICRO FOCUS VOLTAGE “Data is one of the most abundant and valuable assets for an organization today,” said Reiner Kappenberger, Director Product Management,

42

O CTO B E R 2019

Customer – Fully Managed

nShield HSM

nShield HSM

Application Server

Customer Cloud

Customer – Fully Managed KEY

Customer Self Customer – Self–Managed

RAS: Remote Administration Server

Voltage Data Security at Micro Focus. “However, without reliable ways to protect data at rest, in motion, and in use, these very assets can become liabilities. As Voltage SecureData customers increasingly migrate storage and workloads to cloud-based environments, they are looking to establish an HSM-based root of trust in the cloud that can maintain the highly available, highly performant data-centric solution they currently enjoy. nShield as a Service from nCipher Security, through its support of Voltage SecureData’s innovative Stateless Key Management, enables Micro Focus to offer its customers continuing relief from the burden of traditional key management in both hybrid and zero data center cloud deployments.” VENAFI “As the leader in machine identity protection, Venafi welcomes the launch of the new nShield as

RFS: Remote File System

a Service capability from nCipher Security,” said Kevin Bocek, VP Security Strategy and Threat Intelligence at Venafi. “With the number of machines growing exponentially, and the definition of machines expanding to include everything from containers in Kubernetes clusters running in cloud to embedded IoT devices that will be deployed for next 20 years, securing machine identities is critical for every business and government. The new nShield as a Service delivers the same robust root of trust that customers have come to depend on with on-premises nShield HSMs, adding a subscription-based security alternative that is easy to use, flexible, and cost-effective for organizations no matter their size. This is an exciting development that will help fast DevOps and security teams move at cloud speed to secure TLS and code signing keys certificates.” ë


SEPTEMBER-DECEMBER, 2019

3

CONTINENTS

15

COUNTRIES

3000+

C-LEVEL EXECUTIVES

B R O U G H T BY

W W W. G LO BA LC I O FO R U M . C O M


Turn static files into dynamic content formats.

Create a flipbook
Cyber Sentinels October 2019 by GEC Media Group - Issuu