What the Hack? Secon Cyber Quarterly Newsletter
LEADERSHIP INTERVIEWS: Gerry Grant, NHS Tayside
ZERO TRUST The key to enabling the new hybrid workforce
SIX QUESTIONS with Red Sift CEO Rahul Powar
GOING CLOUD FIRST? How to ensure your digital transformation is secure
Q3 2021
CONTENTS 3 Foreword from our CEO 4 Secon Cyber Leadership Interviews Janakan Nadarajah, COO, Secon Cyber,
in conversation with Gerry Grant, Cyber Security Manager, NHS Tayside
8 Thought Leadership Enable the new hybrid workforce
with cloud-native zero trust
10 Best Practice Spotlight How to secure your perimeter and device’s firewall
12 Insights You’re going “cloud first.” Have you made sure it’s secure?
16
Vendor Showcase
Six questions with Rahul Powar, Chief Executive Officer, Red Sift
19 Stats from our SOC 20 Success Story How we helped a local council identify 4
and mitigate their cyber risks
SECON CYBER2
Foreword from our CEO:
Welcome to our July 2021 edition of ‘What the Hack?’ Since our last quarterly issue in April 2021, so much has happened in the cyber security industry, and it just goes to show how fast the pace is in our industry. In the first half of 2021 we have seen initial public offerings from KnowBe4 and Dark Trace, demonstrating that there is a healthy pipeline of cyber security technologies ripe for IPO. We have also seen a spike in M&A activity, such as the acquisition of Forcepoint by global investment firm Fransico Partners. This hiatus of acquisitions is a clear indication of the interest and value in our industry. Despite such positive activity, organisations are unfortunately still being hit by cyber attacks, notably the high-profile attacks of meat supplier JBS, gaming giant EA Sports, and the attack on the Colonial Pipeline. When speaking with our Security Advisors and Security Operations teams about these attacks, there is a common set of themes that come out time and time again. As an industry, until we have collectively addressed the basics, such as providing user awareness training, consistently patching applications and operating systems, ensuring all installed security technologies are configured properly, and monitoring traffic for anomalies with the readiness to quickly respond, I fear we will see more and more successful attacks. However, from a ‘local’ perspective, I am encouraged to see UK organisations taking the security of their estate more seriously than ever, as demonstrated by the number of recent engagements we have seen at Secon Cyber. In this edition of ‘What The Hack?’ we have been speaking to some of the leaders in our industry to get their perspective on how they are addressing the challenge of cyber. We are privileged to hear from Gerry Grant, Cyber Security Manager at NHS Tayside, who shares his wisdom of how to secure such a large and complex organisation. Also, Lisa Lorenzin, Senior Director of Transformation Strategy at Zscaler, explains why now is the right time to implement a zero-trust strategy. And we speak to Rahul Powar, CEO of Red Sift, who tells us why most CISOs would rate business email compromise amongst their top concerns but are unaware of what they need to do to solve this issue. I hope you enjoy this edition of ‘What the Hack?’ and on behalf of the Secon Cyber team, we wish you an enjoyable summer.
Robert Gupta Chief Executive Officer WHAT THE HACK - Q3 2021
3
Secon Cyber Leadership Interviews
Janakan Nadarajah in conversation with Gerry Grant, Cyber Security Manager, NHS Tayside JN: Tell me a bit about your role and what you do. GG: I’m the Cyber Security Manager for NHS Tayside. It’s my responsibility to look after the cyber security of pretty much everything within NHS Tayside, so that goes down to the endpoints, the laptops, the desktops the majority of my colleagues use all the way to MRI scanners and all the other various bits of technology that may be used in hospitals to monitor patients and help save their lives. It’s quite a wide and varied type of thing that I’ll see on a daily basis. One day I might be looking at a proposal for a new piece of equipment in A&E and the next day I will be trying to get somebody update their iPad, so a whole variety of different things. For me, it’s that diversity that makes it interesting and was one of the reasons that I wanted to come and work in this environment. JN: How did you get into working in cyber security? GG: I’d like to say it was a long time ago, but it wasn’t really that long ago. I had a bit of a mid-life crisis and wasn’t sure what I wanted to do with my life. The more I thought about it, I’ve always been interested in technology, and I just saw the way the world was going and that we’re becoming more connected and the internet of things is beginning to take over our lives. That’s a fantastic opportunity, there’s loads of things that we can do with it, and part of me 4
loves the prospect of being able to turn an oven on when I’m on my way home, but part of me is nervous because how secure is it? And who thinks about the security of these things? That’s what started to get me interested in cyber security. The more I investigated it, the more curious I became and as time has gone on, I’ve learned and understood more about cyber security. I feel that I’ve got an obligation to try and pass that knowledge on to other people and to try to make people aware of what the consequences of their actions are and how we can make a safer world. I love the technology. I love what it can potentially do. I just want people to be aware of the drawbacks and think about how that might actually affect not just their business life, but their personal life as well. JN: What do you love about working in cyber security? And what do you not like about it? GG: I like most of it. I love the challenge, every day you’re faced with different challenges. For me, cyber security is about managing risk and making people aware of what the risk level is. In an organisation a big and diverse as the NHS, that can be difficult because what I might consider very risky, a doctor might think is not risky at all. I get to communicate and speak to people at board level and I also get to speak to the doctors and all the other people within the organisation so I kind of feel like I have an impact on everybody, not just on one depart-
ment. And yes, I’ve got reports to write and I’ve got meetings I need to go to, but I’m
still thinking about different things all the time and that’s what I really like. One of the challenges is it changes so quickly and the types of attacks you’re getting are changing all the time, so it’s trying to get that buy in from staff as well. People go ‘Cyber security is really important, but I already understand it so I don’t need to listen to you.’ It’s trying to do something to spark reimagination to make them engage with you a little bit more. Trying to get doctors to come to a cyber security awareness training, good luck with that because they’re way too busy actually saving somebody’s life. They don’t want to sit and listen to me drone at them, so it’s trying to find different ways and that’s SECON CYBER
really the challenge that keeps coming. But I enjoy even the difficulties when I reflect on them. 99% of the time I would say I love it, it’s just the 1%, and that’s probably just before I go on holiday. JN: How did the events of 2020 affect your organisation, its digital transformation, and cyber security agenda? GG: 2020 was a difficult year for everybody and I’ve only had just over a year with the organisation. I joined right at the peak of the crisis and you know the NHS is unique in terms of how it impacted us and the response that we had to come up with. It certainly made us transform a lot quicker than we would have done in
terms of digital transformation. I think we’ve been on a higher level of alertness when it comes to cyber attacks and the impact that would have on us. In the last year, the number of conversations we’ve had around cyber security has been increased. It’s something that’s higher up on the agenda now than it previously WHAT THE HACK - Q3 2021
“The only way for me to give back to the NHS is to take on a role like this. I want to make the NHS more secure for all the people that work here, but I want to make sure that all the patients’ data is safe, and I want to make sure that we’ve got systems and process in place that give the best patient experience.” was because they know now how reliant we are on the technology to ensure that our staff can keep that constant line of communication going. It put a lot of pressure on the IT departments to make sure that everything was in place. We were made acutely aware of how important we were, and I think if you’re to take a positive out of it, it’s shown the organisation how quickly we can adapt and how important the work is that we do and how important the infrastructure is that we have in place. When I took the job last May, I thought long and hard about it. I knew it would be a challenge and it has been the challenge that I expected. It’s a totally unique organisation that has unique challenges and you know, people talk about end life software and legacy systems, but it’s not cheap to go buy a new MRI scanner and you’re not going to do that every five years just because part of the software’s reached end of life. You have to put other mitigating measures in place, and I knew it was going to be hard. In a public sector organisation, things move a little bit slower than they do in the in the corporate world and budgets are little bit tighter. You’ve got to fight
for every single penny, but it was the challenge that I wanted, and I think going forward, it gives me such great experience you wouldn’t get anywhere else. I’m never going to be a doctor, there’s no way I could stand the sight of all that blood. The only way for me to give back to the NHS is to take on a role like this. I want to make the NHS more secure for all the people that work here, but I want to make sure that all the patients’ data is safe, and I want to make sure that we’ve got systems and process in place that give the best patient experience. Cyber security is there not just to protect NHS Tayside as an entity, but to protect their customers, which is everybody that lives in the area. JN: What do you think organisations need to do to increase cyber security awareness and understanding amongst employees? GG: I don’t think there’s an easy answer, but it’s about communication and it’s about creating a nudge culture that is showing the end user how it benefits their personal life. Generally speaking, the user doesn’t particularly care that they have to have a 12 5
in at the beginning. It’s getting better, but they need to think about the life cycle of these bits of kit as well. How long are they going to support it for? What are the plans if the operating system does reach end of life? Do they have a backup or is there something different that can be put in place that’s not going to be too expensive? There’s a lot of challenges, especially getting a doctor whose primary job is making people better and saving lives to think about cyber security even though they’ve got 101 other things to think about. I claim it’s important and they’re like yes, but how does it save somebody’s life? They need to begin to understand the risk they bring in and how we’re trying to help them mitigate it. character password to keep the company safe, but if you explain to them why it’s good to have a 12 character password for their personal banking, they understand it a little bit better. You really need to get buy in from board level, it has to come from the top down. It’s about making the board aware of what the risks are and how it can affect their organisation and them personally. It’s difficult because you don’t want to create a fear culture. It’s more about explaining how we can protect ourselves and the steps that we can take. If we can teach that and get our users to understand that from a personal level, they’re not upset about it. It’s about just that constant drip of awareness in the same way that health and safety was a big, massive thing in sort of the 90s and the early 2000s. We need to try and follow a similar sort of thing. It’s about trying to get people to understand the risk and the consequences of the things that they do. JN: Focusing specifically on the NHS and healthcare, what do you see as the greatest secu6
rity threat or challenge for the healthcare industry? GG: One of the biggest challenges is making the clinicians understand the risk that they bring to the business. It’s not always the clinicians’ fault, I think vendors have got a lot to answer for as well when it comes to pieces of medical equipment. They sell pieces of equipment that are not built in a secure manner. It’s trying to get that understanding from the clinicians that they need to ask the right questions and we as cyber security professionals need to provide them with the questions to ask. It’s about creating the right culture within healthcare. We’re a public organisation, there’s not buckets full of money set aside for us to pour into cyber security and even from a public perspective, if we were to turn around and say we’ve spent x millions of pounds on cyber security, I’m pretty sure there’s a few people in the public that would be like ‘How many nurses and doctors could that have paid for?’ We need to speak to the vendors and get them to understand that they need to have security
JN: What are your key cyber security focus areas for the next 12 months? GG: We’ve touched on cyber security awareness and training, so I’ve got whole strategy put in place around awareness and how we can roll that out across the organisation to begin that cultural change to get people to start thinking about cyber security. Other focuses are around visibility of what’s happening on the network, how can we improve our alerting to any potential incident that’s come up, and how can we start to be a lot more proactive in looking for issues before they actually become an issue. We’ve got different tools in place that should mitigate it should it happen, but we need to make sure that it’s a strong point for us. We can only do that with added visibility and the extra ability to see what the endpoints are up to. They are the key objectives and I think if I got those in place over the next 12 months, I’ll be pretty happy and will definitely feel that we’ve moved forward.
SECON CYBER
www.seconcyber.com
Anyone who orders a Secon Cyber Cyber Risk Assessment between 7th July and 30th September 2021 will be entitled to claim a FREE 3 month trial of our ConnectProtect® Managed Detection and Response platform.
Learn more and request a consultation
3 month trial includes maximum log ingestion of 1GB per day and log retention of 90 days. Terms and Conditions Apply.
Thought leadership in partnership with
Enable the new hybrid workforce with cloud-native zero trust by Lisa Lorenzin, Senior Director, Transformation Strategy, Zscaler The rapid expansion of remote work due to the pandemic has forever changed the face of enterprise cyber security, and the effects are still rippling across the business landscape. Even as users return to the office, we’ll still need to secure a sizable work-from-anywhere (WFA) population. This new hybrid workforce is here to stay: some people work remotely, some go into the office, and some toggle between the two as needs dictate. As a result, there is no better time than now to implement a zero trust strategy.
A rebalancing act The massive move to WFA during the pandemic eroded the foundations of network-centric, castle-and-moat legacy architecture through shifting patterns and sheer volumes of traffic. To compensate, many organizations invested heavily in virtual private network (VPN) technology. As users return to the office, those same VPNs are over-provisioned, depreciating in value, and don’t support ongoing network and security transformation. VPNs lack the necessary flexibility to follow users, devices, and applications to new virtual perimeters. The net is that security costs and complexity increased, but granular visibility didn’t. Forward-looking IT teams, in turn, are seizing the opportunity to overcome the challenges of VPNs by turning to new cloud-native secure access solutions to help drive innovation both within IT and for the business. Modern cloud-native security solutions extend zero trust principles to enable and secure WFA access to applications, without requiring public exposure or complex network segmentation. Security, simplicity, and user experience go hand-in-hand in this new model, which al8
lows for seamless access across all the permutations of the hybrid workforce.
Regaining your footing with zero trust Zero trust initially envisioned context-based controls for least-privilege access for on-premise users accessing internally hosted apps. But as the pandemic demonstrated, IT teams also require a solution that offers seamless access for remote workers. By extending these tenets to the new hybrid workforce, IT teams can provide secure access to any application or asset without publicly exposing the application, asset, or even the infrastructure that supports access. A zero trust architecture provides security, granularity, and visibility no matter where users, applications, or assets live. At Zscaler, our cloud-delivered zero trust solution, Zscaler Private Access (ZPA), allows IT teams to deliver a consistent, frictionless user experience for employees, third parties, and B2B communication. Access is seamless regardless of whether the user is “off-network” or “on-network”—the network doesn’t matter anymore. The policy environment is simplified, becoming user- and app-centric rather than network-centric, and consistent across cloud and data centre application environments. Granular policies for context-based access ensure least-privileged connections, combining user and device attributes to permit access only by authorized users on compliant devices. Since zero trust connects users to specific applications rather than allowing endpoints access to the entire network, yesterday’s “virtual private network” evolves into today’s secure access service edge (SASE). Public service edges provide transport to remote applications, while private service edges support local and SECON CYBER
on-premises access. Furthermore, while ZPA connects users to an enterprise’s internal applications, Zscaler Internet Access (ZIA) connects users to internet and SaaS applications on the internet. Backhauling everyone’s traffic to a few internet egress points just to send it through a stack of security appliances no longer makes sense: WFA users can leverage the same Zscaler Zero Trust Exchange and access public resources via direct internet connections protected by ZIA. Application of the fundamental zero trust principles of context-based, least-privileged access beyond their initial narrow scope of on-premises users connecting to internally hosted applications is on the rise. Protection of outbound as well as inbound traffic, identity-based access controls for machine-to-machine as well as user-to-machine traffic, and integration of additional context all combine to offer more granular and adaptive access decisions. But nobody does this overnight. Solutions need to work seamlessly across hybrid use cases to protect both legacy resources and infrastructures as well as modernized workflows.
The path forward The past year rapidly accelerated existing cloud migration and remote work trends. Traditional security models struggled to accommodate the huge change in traffic flows when the global digital workforce went home en masse. Companies that had already embraced digital transformation absorbed the change and adapted more easily. In the space of a couple of months, we helped many companies use zero trust to transition their entire workforce to WFA. Now we have the luxury of thinking and planning more strategically for how to best support the evolving hybrid workforce post-pandemic. A continuing theme in 2021 will be the importance of flexible, resilient solutions that adapt to ongoing change. It’s time to seize the zero trust moment! Modern cloud-delivered zero trust architectures apply security functions consistently across an ever-evolving landscape, and will remain a critical component to accommodating and securing the new hybrid workforce. WHAT THE HACK - Q3 2021
9
Best Practice Spotlight
1. Identify all inbound and outbound ports that needs to be open on the perimeter or a particular device. 1a. For perimeter, it is best practice to set all traffic bound to the internet to pass through a proxy to filter the traffic. 1b. For devices, allow only internet bound traffic using an endpoint agent that filters traffic. The majority of inbound ports should be blocked apart from those that the estate needs.
How t your pe device
4. Employ IPS/ IDS solutions. 4a. Adding these solutions will help the perimeter firewall prevent any attacks and unwanted sniffing of information from the perimeter device. This will be the same for the endpoint device.
10
SECON CYBER
2. Identify all services or applications that need access beyond your perimeter or device.
to secure erimeter or e’s firewall
2a. For perimeter, identify all hosted or cloud based services and ensure that they scanned for malicious content.
2b. For devices, identify all services, add them to the exclusion of the firewall application, and only specify that specific port.
3. Set the rest of the inbound and outbound traffic to block. 3a. Block all unnecessary ports exposed by the perimeter device or user device.
WHAT THE HACK - Q3 2021
11
Insights
You’re going “cloud first.” Have you made sure it’s secure? by Andrew Gogarty, Chief Security Evangelist What does “cloud first” actually mean? A growing numbers of organisations are now exploiting the benefits of moving to the cloud and for many of these, this was accelerated to ensure business continuity as a result of the pandemic. But before we consider the implications on resilience and security, let’s break down what’s typically in scope when organisations are adopting a “cloud first” strategy. The NCSC has broken down cloud into three main areas: • Infrastructure as a Service (IaaS) • Platform as a Service (PaaS) • Software as a Service (SaaS) For more detail about the associated risks of each of these areas, click here. To further simplify and consolidate things for the purpose of this article, lets break cloud into two distinctive areas: Workloads - Infrastructure moving to the cloud, e.g. servers, in-house applications, and databases (IaaS and PaaS) Applications - Cloud applications “as a service,” e.g. Salesforce, O365, and ServiceNow (SaaS) Both areas help with operational efficiencies, but the security fundamentals remain the same: you have data required to operate your organisation, and you have people/applications/services that require access to that data. 12
When moving to the cloud, security is still incumbent on the owners of the data in the cloud “Using the cloud securely should be your primary concern - not the underlying security of the public cloud...Instead, concentrate your security effort on making sure your data is secure. In our experience, data breaches in the cloud mostly come from the customer failing to protect their own data. Leaving your data insecure and hoping no-one will find it is like leaving the car unlocked and hoping no-one will steal it.” Source: The National Cyber Security Centre (www.ncsc.gov.uk) As with securing on-premise environments, to ensure effective resilience against cyber attacks, you need visibility and control over the security of data and the access to that data. According to a recent report by Gartner, it is estimated that through to 2023, at least 99% of cloud security failures will be the customer’s fault. The report goes onto the outline two of the main causes of cloud security breaches: Misconfiguration: “50% of enterprises will unknowingly and mistakenly have exposed some IaaS storage services, network segments, applications or APIs directly to the public internet.” Access: “75% of security failures will result from inadequate management of identities, access, and privileges.” A key driver fuelling these causes is ultimately a lack of visibility of cloud usage within organSECON CYBER
isations. Without visibility it is impossible to ensure you have effective controls in place. The flexibility of cloud enables anyone in an organisation with web access and a credit to sign up for a cloud platform or application that has not been sanctioned by the organisation. This represents a real challenge for security teams in securing data and is often referred to as shadow IT.
How to address the problem As with most cyber security challenges, the solution requires a combination of policy, tooling, process, and people to ensure consistency of visibility and control across all cloud applications and cloud workloads, both ones sanctioned by the organisation and shadow IT. This article aims to serve as a guidance to improving cloud security maturity, but it needs to be noted that for this approach to be effective, it needs to be incorporated into a wider security plan that addresses other cyber security best practices such as end user device security and email security. A holistic approach to cloud is required that starts with a well-defined cloud security strategy that should look to encompass the following:
Cloud applications (SaaS) According to the NCSC, regardless of the type of service being consumed, the following recommendations should be considered: • SaaS offerings should be centrally managed and users given the correct level of access. • SaaS offerings should be accessed using up-to-date and regularly patched software. • Devices accessing the SaaS offering should be configured in line with the NCSC EUD Guidance. • User accounts on the service should be suspended when no longer required. • Audit logs should be monitored and any suspicious activity investigated. • SaaS providers publish their security claims in a publicly accessible and easy-to-find location.
• Understanding what your critical data is and where it is stored.
• Establishing a target state and roadmap to serve as a benchmark to ensure ongoing governance.
• Understanding who and what services have access to the data and how it’s being accessed.
• Monitoring 24x7 to be able to identify and respond to anomalous activity.
• Defining your security, compliance and regulatory requirements for storing and processing data. • Rationalising on the right set of controls for complete visibility and control to meet requirements. • Establishing a security baseline for all your cloud environments. • Establishing a target state and roadmap to serve as a benchmark to ensure ongoing governance. • Monitoring 24x7 to be able to identify and respond to anomalous activity. WHAT THE HACK - Q3 2021
13
The diagram below shows the key areas for consideration if you want to realise centralised visibility and control over cloud applications to reduce the risk of a cloud data breach.
Cloud workloads (IaaS and PaaS) According to Gartner, “By 2021, 50% of enterprises will unknowingly and mistakenly have some IaaS storage services, network segments, applications or APIs directly exposed to the public internet, up from 25% at year-end 2018. In their report, 5 Things You Must Absolute-
4a. Do you monitor all cloud activity 24x7 for suspicious activity? e.g. a user downloading more data than they usually would to undertake their role?
ly Get Right for Secure IaaS and PaaS, Gartner outlines the following guiding principles to consider when security cloud workloads: proper use of identity and access management permissions, importance of data encryption, application of zero-trust network access to reduce risk exposure, implementation of cloud security posture management tools, and the ability to capture, log and analyse cloud data. The diagram on the opposite page outlines the key areas for consideration to realise centralised visibility and control over cloud workloads to reduce the risk of a cloud data breach.
1. Cloud web security gateway
4b. In the event of a suspected breach, are you confident that you will quickly have the data points required to contain and investigate the entirety of the breach?
1a. Do you have persistent visibility and control over ALL your users’ web access and traffic? 1b. If YES, does this include remote users, even when not connected to the network via a VPN?
Cloud Applications 4. Monitoring
(SaaS - e.g. Salesforce, Workday)
3a. Do you have persistent visibility and control to ensure secure access across ALL in-house hosted applications and third party cloud applications? 3b. Are you confident that you are preventing unauthorised access to your environment, both on-premise and in the cloud?
14
3. Access (user and device) into cloud applications
2. Cloud access security broker
2a. Do you have the ability to prevent users from inputting or uploading sensitive data into cloud applications not sanctioned by the business (shadow IT)? 2b. Do you have full visibility and control over who can access sensitive data in your cloud applications? 2c. In the event of a breach, would you be able to prove (with evidence) that no sensitive or PII data had been accessed as a result of the breach?
SECON CYBER
5a. Do you have persistent visibility and control to ensure secure access across all cloud workloads?
1a. Do you have visibility over what cloud workload assets you have and that they have definitely been configured securely, without misconfigurations? (e.g. default passwords, exposed services, etc.)
1. Cloud posture and security management
1b. Can you demonstrate that your cloud workloads meet your relevant compliance standards? (e.g. GDPR, PCI, etc.)
5b. Do you ensure only trusted and secure devices are used to access your cloud workloads?
5. Access (user and device) into cloud workloads
Cloud Workloads (e.g. AWS, Azure)
2. Cloud workload segmentation
4a. Are you protecting your cloud workloads with antivirus, firewalls, and IPS? 4b. Have you locked down your cloud workloads to ensure only the desired applications intended for that workload can run/ execute?
4. Securing the workloads
3. Cloud SecOps
3a. Do you continuously ensure your server workloads have critical and security patches deployed and do you have the ability to demonstrate that to the business or any third parties should it be requested?
2a. Do you have full visibility and control over east to west network communications with your cloud workload environments? 2b. Can you ensure any new applications deployed to your cloud workloads are appropriately segmented to prevent the risk of lateral movement in the event of a breach?
3b. Do you monitor your cloud workloads 24x7 for threats to enable you to respond quickly to any threats that could have a negative impact on your organisation?
Conclusion The core principles of cyber security with cloud are no different to the principles of how you secured your on-premises data centres. The ever-growing cloud landscape just adds a layer of complexity around where your data resides and how it is accessed. You need to ensure that you have visibility and control over all access to the environments. The good news is that achieving visibility and control in the cloud is achievable with the right WHAT THE HACK - Q3 2021
combination of people, process and technology. No matter what stage you are at on your cloud journey, Secon Cyber has the expertise and experience to assist you in making your cloud journey more secure and resilient against today’s and tomorrow’s cyber threats. If you’d like to discuss how we can help you, click below to book an initial, free consultation with me.
Book meeting with Andrew Gogarty 15
Vendor Showcase:
Six questions with Rahul Powar, Chief Executive Officer, Red Sift
2
As you know, there are many solutions out there in the market place all promising to help organisations address the risks associated with not having DMARC properly implemented. How does RedSift differentiate itself from the increasing list of solutions?
1
It’s evident from speaking with customers across multiple different industry verticals, that many organisations are still not aware of what DMARC is and why they need to take it seriously. Can you help our readers by articulating what DMARC is all about and why our readers should take action? DMARC is an industry standard protocol that levels up the email security posture of your organisation. When fully deployed, it prevents bad actors from impersonating you to your colleagues, supply chain and customers over email. It does this robustly and automatically and is supported by most actors in the email ecosystem. Yet amongst the largest companies such as those in the FTSE100, DMARC rollout is just 35% as of Jun ‘21. This lack of consistent adoption is a major cause of the growing risk across the email ecosystem.
16
When finding the DMARC solution for your business, I recommend taking a long-term view. DMARC is a lifetime project, but many DMARC solutions start and stop at reporting as this is the simplest part of the problem. Reporting is just a stepping stone to getting DMARC fully deployed and your domain protected. Red Sift’s OnDMARC provides a full circle solution for DMARC compliance. Customers are guided through the entire DMARC configuration process within our platform or by our customer success team if needed. Unlike other providers, we focus on the entire problem and offer a comprehensive solution. As a result, the majority of our customers successfully reach full DMARC compliance in 4 to 8 weeks, and 67% do this without needing additional support. How much time your security teams must invest in maintaining DMARC once it’s implemented depends on the level of automation, insight and support your chosen DMARC tool provides. We’ve invested heavily in technology, data partnerships and people to provide the highest fidelity of product and level of service on the market, and this is reflected by our roster of customers, case studies and reviews. While we can’t list every customer and the success they’ve enjoyed, I can virtually guarantee that every UK reader of this content has an email in their inbox today that is invisibly authenticated by us. SECON CYBER
3
Are you able to share a real life example where lack of DMARC implementation has resulted in a breach, and a brief breakdown of the steps taken by the bad actor to execute the breach? We can’t share specific incidents, but the pattern of attack is likely very familiar to your readers. Most chains of compromise start with a phishing email that’s launched simply and at scale with minimal technical expertise. Domains that don’t have full DMARC configuration are easily impersonated, and because it looks legitimate, controls fail to stop the email and sometimes even promote it. It’s almost impossible for the end user to distinguish this message as inauthentic, especially if the email content is well crafted. One mistake (i.e. a link clicked or invoice paid) and ransomware is planted, details are stolen, and chaos ensues.
4
Now I know having DMARC implemented properly just not just give security benefits. How else can having DMARC properly implemented help our readers? Organisations that have deployed DMARC see various benefits. We have a number of case studies that indicate improved deliverability and inbox placement as a side effect of cleaning up mail flows and blocking bad actors who are negatively influencing their reputation. In addition, very soon a number of major inboxes will be showing logos against properly DMARC authenticated emails via a new standard BIMI.
WHAT THE HACK - Q3 2021
5
We are getting asked a lot of questions around BIMI. Can you share with us what BIMI is all about and when it will be available for implementation?
BIMI is a standard that relies on DMARC to present logos next to emails in a user’s inbox. These logos will take the place of default avatars in your typical email clients and Apps. Organisations worldwide are excited about the opportunity for enhanced brand recognition and engagement which for many will translate into improved commercial outcomes from their email activity. We expect BIMI will be available starting with pilot customers in H2 2021 on Google inboxes, but we’ve already helped a number of our customers get early access to the Google pilot. For the BIMI curious, we exclusively track global adoption in real time on BimiRadar.
6
Organisations are facing a number of risks to address and its becoming increasing challenging to prioritise budgets and internal resources. Why should addressing DMARC be a priority for them?
Most CISOs would rate Business Email Compromise (BEC) as a top 3 concern in 2021. Yet many are unaware of DMARC and the role it plays in reducing this problem. DMARC is one of the few projects every business can roll out that will immediately eliminate this dangerous threat vector without complex machine learning or end user involvement. US and UK governments have directives that spell out DMARC, many private institutions require it for their supply chain and a number of our customers have found BIMI and it’s brand-boosting benefits to be an incentive for getting this project prioritised. Ultimately, if you use email for meaningful commercial activity or interact with organisations who do, DMARC should be at the forefront of your priorities. 17
www.seconcyber.com
Get the most out of your Zscaler cloud security solutions Our Zscaler Managed Service is designed to help you get the best out of your Zscaler investments. You can tailor the service to meet your unique needs by selecting from the following Managed Service options: - Product Support - Product Maintenance - Security Monitoring - Security Monitoring and Response
Speak to us about our Zscaler Managed Service
Stats from our SOC Cases closed by our SOC per reason Jan - June 2021
17.77%
37.25%
5.41%
Threat detection Configuration
5.72%
ConnectProtect® Rule Update
8.66%
Scanning/Filtering
25.19%
Access Permission Other
“By leveraging our ConnectProtect® platform, Secon Cyber’s 24x7x365 experienced SOC team can monitor security alerts, network traffic and endpoint event logs to identify any potential attacks that may affect our managed customers. Over 37% of the incidents we have closed (year-to-date) were threat related. In detail, we have identified that the most common alerts pertain to Potentially Unwanted Applications (PUA) that were inadvertently downloaded or installed on endpoints, followed by access to suspicious URLs and intrusion prevention events which manifest active attempts to exploit existing vulnerabilities on endpoints. Aside from continuously identifying and validating threat alerts, our team also engages with our clients to address product issues and concerns. Our seasoned consultants WHAT THE HACK - Q3 2021
ensure that the products our customers are using are properly deployed and configured according to best practice, maximising the security solutions’ features and capabilities to thwart threats. Our team also constantly strives to reduce alert fatigue that our customers experience because of the vast amount of telemetry and data being analysed. This is where innovative technology and human expertise come into play. In fact, from January 2021 where we have received over 28,000 incidents, noise has reduced dramatically by 86%.”
Realyn Vasquez, Security Operations Team Leader
19
Success Story
How we helped a local council identify and mitigate their cyber risks Despite being a long-standing client, a large district council wanted to gain a deeper understanding of their cyber risk and potential weak points in their defences. To address these concerns, we conducted a workshop with the local authority to build a high-level view of the state of their cyber security and what it would take for them to achieve best practice. To do this, we assessed three areas and their current level of cyber maturity: • The ability to protect against cyber criminal activity • The ability to detect cyber criminal activity • The ability to recover from a cyber related incident
What was achieved? After the workshop, our findings identified a number of high-risk areas within the council’s environment. These included low levels of visibility across their estate and gaps in protection that would have made it difficult for the council to quickly detect a threat, or even establish whether an intrusion had taken place at all. Using the information provided by the council, we prepared recommendations to improve their cyber resilience and reduce the risk of operational impact from cyber criminal activity.
20
We provided recommendations for the following areas: • Endpoint security • Server security • Network security • Email security • Web security • Cloud security • Identity and access security In particular, we determined that the council needed to focus their attention on improving the protection of their sensitive data and their overall approach to visibility and response. Despite having email and web gateway solutions with the ability to implement data leak prevention, the different management interfaces made it difficult for the council to implement a unified data leak prevention policy across their entire environment, which left gaps in the visibility and control of their sensitive data. We recommended the council take a unified approach across all devices and applications SECON CYBER
to facilitate centralised data classification, visibility, and control over all critical data. The council also lacked centralised log storage and consistent monitoring of their security alerts, which presented an increased risk of an undetected intrusion. In order to address this issue and the council’s lack of visibility, we recommended the council should leverage a security incident & event management (SIEM) solution. By correlating and monitoring security alerts 24x7, the council would be able to quickly detect genuine security incidents. This also would help them avoid the onerous task of reviewing security alerts from multiple siloed security tools, which could also result in genuine attacks being missed. By working closely with the council, we were able to create an achievable and pragmatic cyber risk improvement programme that fit within the council’s resource and budget constraints. This included implementing 24x7 security monitoring and response to prevent a breach, saving the council the cost, time, and reputational impact involved with cleaning up a major cyber incident.
During this project we: • Worked with the council’s IT team to discuss the state of their current cyber security environment and how they were protecting their sensitive data • Determined the areas the council needed to improve, especially their centralised visibility and monitoring • Outlined a plan to close the council’s security gaps that considered both their current security investments and budget constraints •
Suggested managed services that could provide 24x7 monitoring and support for the council’s cyber security environment to actively prevent a breach and supplement their internal resource
If you’re interested receiving your own personalised cyber risk improvement programme, click to book an initial consultation with one of our Security Advisors. Book consultation
WHAT THE HACK - Q3 2021
21
Contact us: www.seconcyber.com Email: hello@seconcyber.com Phone: +44(0)207 657 0707