The Last Watchdog: Recent Episodes

None

on Internet security by Byron Acohido

View Details

Humans get identity. That is what MFA and single sign-on are for, and we all understand the bargain: prove you are who you say, then go do your work. Machines get predictability. That is what monitoring is for. A script does the same thing every day. If it deviates, somebody notices.

Related: Part 1: AI is forcing security and operations to merge in the SOC

Agentic AI upsets that arrangement. An agent logs in like a human, with an identity that says who it is. Then it goes to work without a script. It figures out its own steps as it goes. There never is a script. No baseline. Nothing ever amiss.

In part two of my three-part Black Hat USA 2026 wrap-up, the eight vendors I looked at closely are all trying to insert permission where predictability used to be. Predictability was something you watched for after the fact. Permission is something you set in advance. Somebody decides what the agent may reach and what it may not, and the agent runs inside that. Permission can be set in several places.

Radware — Mahwah, N.J. Founded 1997. Application, API and bot defense, extended to the AI agents companies are now deploying.

Sagiv

“Authentication establishes identity,” says Shira Sagiv, vice president of product portfolio. “It does not control what happens next.”

A script that changed behavior was easy to spot. An agent is built to interpret and adapt, using valid credentials and approved tools the whole way. It can reach data it does not need, call the wrong tool, or take a series of individually valid actions that add up to something nobody intended.

Radware’s answer is three stages: discover every agent running, establish what each may access, then watch behavior at runtime with controls that can stop an action in progress.

Suzu Labs — Las Vegas. Founded 2025. Secure AI adoption built on the data layer underneath it.

I spent an hour with founder and CEO Mike Bell at the show, my second sit-down with him this year, reporting for Machines Against Machines.

Bell grants agents no permissions at all. An agent inherits whatever the employee running it could already reach, so there is nothing separate to over-grant and nothing to drift as agents multiply.

Making that work meant rebuilding the plumbing. One client, a $2.5 billion equipment dealer ordered to put AI into more of the business, went looking and could not say where the company’s own data lived. Hundreds of integrations had piled up through acquisitions, some still on an AS/400.

One tier holds material no AI touches, whatever the employee’s rights.

Airlock Digital — Adelaide, Australia. Founded 2013. Application allowlisting, deny by default, now extended to what an agent may do once it is running.

Blocking an agent does not stop it. “AI agents don’t simply stop when an action is blocked,” says CEO and co-founder David Cottingham. They evaluate alternatives and keep working toward the objective.

That is why he separates two decisions. Whether software may execute, which allowlisting has answered since 2013, and what an agent is allowed to do once it already has. Airlock now enforces the second at the command and session level, through the CrowdStrike Falcon sensor.

His conclusion: draw the boundary and let the agent adapt inside it.

Straiker — Mountain View, Calif. Founded 2025. Discovery, adversarial testing and runtime defense for the agents already running inside a company.

You cannot permit what you have not found. In adversarial testing, Straiker’s research arm found 91 percent of successful attacks on productivity agents ended in silent data theft, with no malware and no stolen credentials. Nearly 29 percent of the MCP tools it cataloged carried direct security risk.

“An autonomous attacker takes whichever door is open,” says CTO Sreenath Kurupati. Every agent nobody mapped is a door.

Straiker maps them, red-teams them before deployment, then holds a kill switch that can stop one mid-action.

HERE Enterprise — New York. Founded 2010 as OpenFin. A work-apps browser that keeps a company’s own AI inside its own permissions.

CEO Mazy Dar sat down with me at the show for close to an hour, recording a Fireside Chat podcast. The permission Dar cares about is which AI an employee is allowed to use. Google makes Chrome and Gemini. Microsoft makes Edge and Copilot. Hand an employee one of those browsers and the browser maker decides which AI shows up in it.

HERE is a browser for work apps. An employee opens Salesforce, work email and an internal database in a single secure window supplied by HERE. Those apps share data, so clicking a customer in one updates the others. The company runs its own AI inside that window, with permissions accounted for.

Semperis — Hoboken, N.J. Founded 2014. Identity resilience for Active Directory and Entra ID.

Permissions get granted to a name. Active Directory holds the names, and when an AI agent shows up asking for something, Active Directory matches it to a name and grants whatever that name is permitted.

Semperis researcher Shai Laron showed at Black Hat that the match can go wrong. He found 385 characters that show up as blank spaces on a screen. An attacker can slip an invisible character into his own name and become somebody else.

Laron showed how an attacker can use that to impersonate a domain administrator and take the administrator’s privileges. Microsoft patched it in April.

Semperis also premiered a documentary at the show. Midnight in the War Room runs on more than 50 interviews. Among those on camera are Chris Inglis, David Petraeus, Jen Easterly and Tim Brown, who was CISO of SolarWinds when it happened. The film follows security executives through the worst nights of their careers. Its argument is that complacency is the real adversary.

Token — Rochester, N.Y. Founded 2014. Biometric assured identity, hardware-bound and non-transferable.

Most of the work going into agent permissions aims at acceleration, at letting machines carry more on their own. Token argues that for some tasks the final step still needs a human, however well the agents perform up to that point.

Token sells hardware. An employee wears a ring or carries a stick that reads his fingerprint, and access opens only when the right finger touches the device.

In June, Token introduced a way for companies to attach that same check to what their AI agents do. A company might have agents moving money, deleting records or granting access, with the agents taking over more and more of the steps. But the final step cannot happen until an authorized employee, verified by his device, gives the green light.

Surace

“More AI watching AI is useful, but it is still probabilistic,” CEO Kevin Surace said in announcing the capability. “Biometric assured identity is deterministic.”

Pindrop — Atlanta. Founded 2011. Deepfake detection and identity verification across voice, video and digital channels.

Permissions govern what an agent reaches inside a company. Pindrop works the channel where an attacker calls in and talks a person into granting access.

I spent an hour with co-founder and CTO Vijay Balasubramaniyan a few weeks before the show. “We started off solving, okay, is this the right human,” he said. “And then we’re like, is it even a real human? And that’s the big change.” Pindrop now analyzes the audio for the acoustic anomalies that give a synthetic voice away, sounds no human mouth could have made. AI-generated calls went from one a month across its customer base in late 2023 to 84 a day per customer now.

In March, Pindrop turned agents on its own side of the problem. Protect Fraud Assist puts AI into the fraud analyst’s workflow, summarizing calls and writing case documentation. First National Bank of Omaha cut investigation time 35 to 40 percent.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)

The post MY TAKE: Black Hat 2026 Part 2 — Security shifts to deciding in advance what an AI agent may reach first appeared on The Last Watchdog.

View Details

Companies have kept security in one silo and operations in another for as long as both have existed.

Related: Security pros dissect Hugging Face breach

Agentic AI is collapsing the divide. That is what a week at Black Hat USA 2026 made plain to me.

Here’s what I’m driving at: Network security and IT operations grew up in separate silos. Security watched for intruders and cleaned up after them. Operations provisioned the accounts, pushed the updates and kept the systems running.

Now both sides are absorbing hits from the same technology. Adversaries are using AI agents to intensify everything they already do, which lands on security. At the same time, companies are deploying AI agents into production faster than anyone can track what those agents can reach, creating unprecedented exposures, which lands on operations.

On July 21, OpenAI disclosed that two of its own models broke out of a sandboxed evaluation, reached the open internet and compromised Hugging Face’s production infrastructure to get a benchmark’s answer key. No human picked that target. The models did.

Dual use for AI security tools

Security is answering by putting AI agents of its own into the fight, and that is where the silo starts coming apart. An agent built to watch for a hostile agent has to know what the company’s own agents are provisioned to do, which was always an operations question. The tooling that defends against the first problem turns out to be the tooling that can corral the second.

Spiteri

That convergence showed up in the conversations vendors were having on the floor. I caught up with James Spiteri, a product manager at Elastic Security, at his company’s booth. He told me that roughly 95 percent of his conversations all week ran on both problems at once.

Visitors wanted attackers’ AI agents kept out of their networks. They also wanted to keep deploying agents of their own at a breakneck pace, fully aware they are absorbing risk they cannot yet measure.

The instinct at that point is to try to cover everything at once. “Don’t try and boil the ocean,” Spiteri counsels. Take a single lane, whichever one is worst, and stay there until you know what you have.

LW’s show coverage

I plan coverage of a gathering like Black Hat months out. I book sit-down interviews with executives from a couple dozen vendors, back to back, and I schedule blocks to walk the exhibits floor. The floor time is where the discovery happens.

This year it produced booth talks at random stops, hallway pulls, and one wrong turn looking for a restroom that put me in front of a mapping company for an hour, learning how location data has become security telemetry. Whatever minutes I save between appointments go to wrangling notes. That is usually when somebody taps me on the shoulder, and that conversation goes in the notebook too.

A show like this normally gets one wrap-up column from me. This year it gets three. There was too much on the floor to fit in a single column, so I am running a three-part Black Hat USA 2026 wrap-up series: Part 1 today, Part 2 Tuesday, Part 3 Wednesday. Part 1 covers the biggest thing I saw. The security operations center is where the two sides are merging first.

Eight SOC innovators

Eight of the vendors I looked at closely are building for the SOC, and what pulled them there is the staffing. A SOC is staffed in tiers. Analysts work shifts around the clock, and the lower tiers repeat the same steps all day. Hiring cannot keep up, and now the pressure is arriving from the attackers and from the company’s own deployments at the same time.

That gap is where the innovation has rushed in. More money, more founders and more shipping product went at the SOC this year than at any other corner of the enterprise.

Eight vendors, eight different roads to the SOC. Here is what I took from each.

TENEX.AI — Sarasota, Fla. Founded 2025. Automated triage on every alert, human-led response.

An old contact I had not seen in a decade, Mike Haro, tapped me on the shoulder as I was wrangling notes at a hallway side table and walked me into the TENEX customer suite, where a product manager gave me a full briefing.

He was eager to talk about the Agentic SOC Alliance, a fifteen-company coalition ExtraHop convened in July. TENEX is a founding member. The members are writing a shared blueprint for autonomous defense, organized in three layers: the context an agent reasons over, the orchestration that governs what it may do, and the model itself, which they treat as interchangeable.

The premise is that no single vendor can cover this alone. An attacker can now point tens of thousands of agents at one company, and answering that takes threat intelligence, orchestration and reasoning that no one company owns end to end.

TENEX comes at it from Google. CTO Venkata Koppaka and CRO Edwin Solis helped build Chronicle, now Google SecOps; CEO Eric Foster co-founded Cyderes. The product is an overlay on that stack rather than a platform of its own.

Mate Security — Tel Aviv. Founded 2025. A relationship graph that supplies the context alerts are missing.

Mate was handing out free massages in a white-shag lounge on level three. I looked the company up while waiting for a chair and got the briefing at their booth later that day.

CEO Asaf Wiener was a product leader at Wiz and Microsoft, and the first Wiz alumnus to leave and found a startup. Oren Saban ran product for Microsoft Defender XDR and Security Copilot. Guy Pergal came out of Microsoft’s threat intelligence center and later ran engineering at Axonius.

The bet is that an alert means nothing without knowing how the business runs. Mate’s patent-pending Security Context Graph maps assets, business processes, users and data for each customer, then builds detections and triages incidents against that map.

Simbian — Mountain View, Calif. Founded 2023. AI agents for alert triage, threat hunting and pentesting.

I have interviewed Simbian CEO Ambuj Kumar numerous times, most recently for his read on the Hugging Face breach in the roundtable that ran mid-show.

Kumar

Kumar came to security from silicon: lead designer on multiple NVIDIA GPU generations, then co-founder of Fortanix, which raised more than $135 million and established confidential computing as a category. He started Simbian in 2023 with Alankrit Chona, a former Twitter engineer.

The bet is that reasoning was never the scarce part. Simbian runs four agents, for the SOC, threat hunting, pentesting and the network, and all four reason against one shared store called the Context Lake. Every alert triaged and every analyst correction flows back into it. Swap the underlying model and the agents keep their footing, because what they know about the customer sits outside the model.

Legion Security — New York. Founded 2024. Automation learned by watching analysts work in their own tools.

Abramovitch

Legion came to me sideways. I went to a PR rep chasing one client and he brought two more along, which is how a hustling rep earns his keep. CEO Ely Abramovitch’s commentary landed in time for Wednesday’s roundtable.

Abramovitch is a former jazz musician who came back to Israel, studied math and went into security. He founded Legion in 2024 with Michael Gladishev, out of Microsoft and Sentinel, and CTO Eyal Fisher, out of Cambridge AI research.

Abramovitch locates the danger in what the agent did not know. The agent that hit Hugging Face, he noted, had no sense that this was a real company, a real production system, or that finding an answer and breaching infrastructure were different acts. Lacking context, “it filled the gap with its best guess, and it guessed wrong.” So Legion trains inside the customer’s environment. A browser extension watches analysts work, learns the judgment calls that never reach a runbook, and replays them.

Gurucul — Los Angeles. Founded 2010. SIEM incumbent extending entity modeling to AI agents.

I have covered Founder and CEO Saryu Nayyar for years and her read on behavior analytics has held up better than most, which is why she was the voice I wanted for the Hugging Face roundtable. I missed her at the booth. Her commentary came by email in time to run Wednesday.

Nayyar

She co-founded Gurucul in 2010 with CTO Nilesh Dherange and has run it since, making her the longest-tenured founder in this group by more than a decade. She holds patents pending in behavior analytics, anomaly detection and dynamic risk scoring. Gartner named Gurucul a Leader in its 2025 Magic Quadrant for SIEM, after three straight years as the most visionary provider.

The bet is that context belongs to the customer. Gurucul models every user, device and workload as an entity with a baseline and a blast radius. The Open AI SOC platform, launched in March, runs that model against a customer’s own data lake, in Snowflake or Databricks rather than in vendor storage.

On August 4 Gurucul added AI agents, copilots, tools, plugins and MCP servers as entities alongside humans and machines. It is the only product in this group watching a company’s own agents and the agents attacking it, in one model.

SecurityBridge — Ingolstadt, Germany. Founded 2012. Cybersecurity built natively inside the SAP environment.

A scheduling conflict cost me my sit-down, so what follows comes from the public record.

Christoph Nagy ran the company as CEO from January 2012 until this year, when Jesper Zerlang moved up from chairman. Zerlang spent fifteen years building Logpoint into one of Europe’s larger security companies. Nagy and co-founder Ivan Mans stepped into strategic and product roles.

The bet is depth in one system instead of breadth across many. SecurityBridge builds threat monitoring, vulnerability management and compliance inside SAP rather than alongside it, and secures more than 5,000 SAP systems worldwide. Other vendors ask what is normal and what an entity can reach across a whole enterprise. SecurityBridge asks the same questions where the financials live.

Varist — Reykjavik, Iceland. Founded 2012, roots to 1993. OEM detection engine trained on a three-petabyte malware archive.

Bjornsson

Varist CEO Halli Bjornsson made the point in my Hugging Face roundtable that nobody else did. Morris, Stuxnet and SolarWinds were built to infect thousands of independent targets. This attack had one. Built to spread, he observed, it could have produced self-evolving malware more dangerous than all three. With millions of open-weight users coming, defenders will have to account for attacks by goal-seeking agents working for people with no malicious intent.

A coherent position for him to hold. Varist traces to Frisk Software, one of Iceland’s original antivirus houses, and Bjornsson has worked on malware at machine scale since before most of this week’s exhibitors existed. Decades of accumulated samples nearly got deleted as a storage cost before becoming the company’s training asset.

The Hybrid Detection Engine, launched in February, scans every file rather than sampling, and simulates suspicious code roughly 1,000 times faster than a conventional sandbox. Verdicts come back in under nine milliseconds. It runs inside the customer’s own infrastructure and ships as an OEM component, already sitting in front of more than five billion mailboxes.

Varist sits upstream of everyone else here. The others work the alert queue. Varist is trying to keep the alert from being generated.

HPE Networking — Houston. Founded 2002 (as Aruba Networks). Network telemetry at scale, repurposed for behavioral baselining.

David Hughes and I sat down at the show for a Fireside Chat. Hughes has been building networks since founding Silver Peak in 2004, and his story is that the network became a security platform sideways. HPE collects session telemetry from millions of network-managed devices and more than a billion customer endpoints on Aruba Central. It started collecting that data to answer help-desk tickets about bad video calls. The same data turned out to baseline behavior.

The bet is that scale produces signal nobody can manufacture. Hughes calls the payoff fleet learning. Take an electronic door lock that normally talks to four IP addresses. It starts calling a fifth. Inside one customer’s network, that means something is wrong. Across a thousand customers at once, it means the manufacturer pushed an update. Neither read is available to a company looking only at its own network.

Agents are where the machinery pays off twice. An agent authenticates correctly, so nothing stops it at the door. Then it gives itself away by tempo. “It’s going to type faster than a human,” Hughes said.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)

The post MY TAKE: Black Hat 2026 Wrap-up Part 1 — AI is forcing security and operations to merge in the SOC first appeared on The Last Watchdog.

View Details

LAS VEGAS, Aug. 5, 2026, CyberNewswire Boards of directors believe they understand their company’s security posture and what it means for the business. The security leaders presenting to them are far less sure. Only 12.5% of security leaders are very confident their board walks away understanding the true state of the program, and 55% of boards have never formally defined what cyber risk the company is willing to accept.

Pulse Security AI unveiled these findings today in The CISO-Board Communication Gap, a research report drawing on more than 80 senior practitioners, examining how security leaders report to their boards and what gets lost between the two.

Armistead

“For a decade, the industry has told security leaders to communicate better with the board,” said Mike Armistead, CEO and co-founder of Pulse Security AI. “Our data says the problem is upstream of that. You cannot report status against a baseline that was never set.”

Top 5 insights

•The Confidence Gap is Measurable. Just 12.5% of security leaders are very confident their board accurately understands the program after a presentation. 41% land at somewhat confident, and 38% are neutral or mixed. Both sides leave the room, and the cycle continues largely unchanged.

•The Baseline Was Never Set. 55% of boards have never formally defined cyber risk appetite, and another 27% define it only qualitatively. Without an agreed baseline, external noise fills the vacuum: roughly 70% of security leaders say board members bring third-party ratings and press coverage into the room, and 42% had to defend a commercial security score in the past 12 months.

•Board Prep is an Operational Tax. 71% of security leaders spend 10 or more hours preparing for each board cycle, one to two full working days every quarter, and 39% involve four or more contributors per presentation. The top time sinks: building slides, gathering data across tools, and translating findings into business language.

•Governance Runs on Instinct, Not Instrumentation. Half of boards made no explicit decision to accept, mitigate, or transfer cyber risk in the past year. 48% of security leaders have no private executive session access, 23% have no predefined threshold for board-level escalation, and 33% say their own legal exposure shapes what they tell the board.

•Trust is Recoverable, and a Breach Shouldn’t Be the Trigger. 53% of security leaders say board trust increased after a material security incident. A real event forces a shared, concrete understanding of risk that quarterly updates rarely produce. The report details five practices, drawn from leaders with the highest board trust, for creating that alignment.

Armistead continues, “You cannot assemble a clear picture of the business when the underlying information lives in a dozen disconnected places. Security leaders have earned the room. What they need now is the operating layer underneath it.”

Download the full report, The CISO-Board Communication Gap: https://pulsesecurity.ai/newsroom/ciso-board-communication-gap/

Methodology: Findings draw on a 42-respondent survey of security leaders and corporate directors, more than 20 in-depth interviews with sitting and former CISOs, and two moderated workshops with roughly 22 CISOs. Seventy percent of survey respondents are CISOs or heads of security. Industries represented include technology and software (34%), financial services (25%), healthcare and life sciences (9%), and manufacturing (9%). These are not nationally representative statistics. Their value is depth and seniority: participants are the people who sit in audit committee meetings. Percentages are computed on those answering each question. A small corporate-director sub-sample is treated as directional only. Quotes are anonymized at participants’ request.

About Pulse Security AI: Pulse Security AI is redefining how cybersecurity programs are run. Pulse is an operational management platform for security leaders, where security professionals and AI agents work together to execute procedures, capture decisions, and deliver real-time program visibility without the manual overhead. The result is a security organization that runs faster, costs less, and gives leaders clear confidence in where their program stands.

Media contact: Carmen Angela Harris, Pulse Security, carmen@pulsesecurity.ai

Editor’s note: This press release was provided by CyberNewswire as part of its press release syndication service. The views and claims expressed belong to the issuing organization.

The post News Alert: Pulse Security AI’s research reveals C-suite, board confidence gap on cyber exposures first appeared on The Last Watchdog.

View Details

LAS VEGAS – It’s come to this. A cyberattack carried out by a machine.

Worse, a machine that picked its own victim. Whether that counts as agency is where the experts below part company.

Related: Huggy Face break-in explained

Hugging Face disclosed July 16 that intruders had moved through its production infrastructure over more than four days, harvesting internal credentials and reaching a production database. Responders logged more than 17,000 actions. The company attributed the intrusion to an external AI agent and had no idea whose.

Its own investigation then hit a wall. The commercial models the incident response team reached for refused to analyze the attack logs, unable to tell a defender examining an exploit from an attacker running one. The forensics ran instead on GLM-5.2, a Chinese-made open-weight model distributed by Nvidia, hosted on Hugging Face’s own hardware.

Five days later, OpenAI said the agent was its own. Two of its models, GPT-5.6 Sol and an unreleased system, had been running against a benchmark called ExploitGym with their cyber refusals turned down so researchers could measure raw offensive capability. The models found a zero-day in a package proxy, broke containment, escalated privileges to a machine with internet access, and went after Hugging Face, which hosted the benchmark’s answer key. What the models were reasoning toward when they picked the target has not been established.

Nobody named Hugging Face. The system did.

Déjà vu all over again

The Morris worm went out on the evening of November 2, 1988, written by a Cornell graduate student who released it from MIT to obscure the trail. It replicated past anything he intended and knocked over a good share of the young internet. Connection itself was now an attack surface. A human chose to launch it, nothing after that was chosen, and the case produced the first felony conviction under the Computer Fraud and Abuse Act.

Stuxnet surfaced in 2010 after crossing an air gap into an Iranian enrichment plant and spinning centrifuges to destruction. Software had been quietly put in charge of physical plant across every industry on earth. Stuxnet proved code could break steel.

SolarWinds, disclosed in December 2020, rode signed Orion updates onto systems at roughly 18,000 organizations, though the attackers went on to exploit only a small fraction of them. FireEye found it while investigating its own breach. Enterprises had handed their patching to automated update channels. The trusted channel was the way in.

The wrinkle

In all three, a human picked the victim. Reach, speed and stealth escalated every time, and the decision stayed on our side of the line.

On July 21 the decision moved. What did not move was scale. This was one company, and nothing propagated.

Nor was it the last. Days after OpenAI’s disclosure, Anthropic reported three cases of its own models gaining unauthorized access to real systems at three organizations.

Last Watchdog asked privacy and security experts two questions, with the industry gathered at Black Hat USA in Las Vegas this week and this incident dominating the hallway conversation. Does autonomous target selection belong on the list with Morris, Stuxnet and SolarWinds, or is this being overblown? And what has to change for defenders now that no human is picking the target? Their commentary follows.

Nayyar

Saryu Nayyar, Founder and CEO, Gurucul

Call it a turning point in capability. The impact has not arrived yet. Malware has propagated and executed without a human at the keyboard for decades. What we have not seen before is adaptive reasoning. Humans set the objective. The models chose the target, built a multistage path and adapted as they went.

We have to move past static rules and isolated alerts to continuous understanding of every entity, including users, identities, workloads, applications and AI agents. Defensive AI cannot reason from raw telemetry alone. The advantage goes to whoever has the best context and can act on it safely at machine speed.

Defenders have to move past static rules and isolated alerts toward continuous understanding of every entity, from users and identities to workloads, applications and AI agents. Defensive AI cannot reason from raw telemetry alone. The advantage goes to the organization whose AI has the best context and can act on it safely at machine speed.

Abramovitch

Ely Abramovitch, Co-founder and CEO, Legion Security

This is a turning point, and not because of whose models were involved. The machine did not know where it was or why it did what it did. It had no sense that this was a real company, or that finding an answer and breaching infrastructure were different acts. It filled the gap with a guess and guessed wrong.

That failure mode is now the attacker’s advantage. Morris, Stuxnet and SolarWinds each required a human to pick a target and run a plan, one incident at a time. That constraint is gone. A handful of deliberate attacks becomes tens of thousands of uncorrelated attempts a day, each one an agent guessing at what looks like a legitimate target, with no human slowing it down.

Kuffer

Scott Kuffer, Co-founder and Chief Product Officer, Nucleus Security

We do not see this as a big shift. Worms have been mass-replicating for decades without any person choosing the next target, and worms are fast, so speed is not the difference either. The change is sophistication. A machine can discover new exploitation chains without a pre-programmed path.

That doubles down on the need for defense in depth. Defenders have to shorten the distance between knowing about an exposure and acting on it, which means connecting vulnerability data with asset importance, exploit activity and remediation ownership. Use automation to maintain context and accelerate action, and keep accountability with people.

Strand

John Strand, Owner, Black Hills Information Security

The first question is the most important one. Why did it go after Hugging Face? It was solving a CTF challenge and, for whatever reason, decided the fastest path ran through Hugging Face. That deserves more attention than the attack itself.

If it believed the answer was sitting there, that is interesting. If it went looking for models with fewer guardrails to finish the job, that is a major moment for offensive security. We would be talking about a model changing its own capabilities.

What reasoning got it there? Few people are asking.

Kurupati

Sreenath Kurupati, CTO and Co-founder, Straiker

The targeting instinct is old. We have always faced attackers chasing the highest value at the lowest resistance. What is new is the operator. For the first time a machine ran that calculus itself, chose the target and executed at machine speed. The next one will not always be a household name. An autonomous attacker takes whichever door is open.

We can no longer assume the attacker is human, slow or predictable. That means watching what agents actually do at runtime, and keeping the ability to stop one the moment its behavior crosses a line.

Defenders can no longer assume the attacker is human, slow or predictable. That means watching what agents do at runtime and keeping the ability to stop one the moment its behavior crosses a line.

Kumar

Ambuj Kumar, Founder and CEO, Simbian

The models were doing what they were asked to do. Reinforcement learning rewards them for getting the job done, whatever the method. Had a human found that shortcut, they would have expected praise for efficiency rather than an incident review.

Before the breach, the models spent two days probing Hugging Face, staying below the noise floor to avoid detection. AI attackers emit a different signal than human ones.

Training a model to attack is comparatively easy, because you know when an attack succeeds. Defense offers no such clean reward signal, which is why a model alone is not enough for defense. It has to be paired with a harness.

Holland

Nicholas Holland, Chief Product Officer, Pindrop

The sandbox breakout is likely overblown. What the models demonstrated once they got out is the under-appreciated part. These agents pursued a goal, adapted their approach and found new paths with far less human direction than we have seen before.

As that capability moves beyond software and into voice, the implications widen. AI agents can engage directly with employees, help desks and contact centers, which makes human conversation part of the attack surface. We have spent years securing software APIs. Enterprise voice channels are becoming conversational APIs.

Bell

Mike Bell, Founder, Suzu Labs

The foundational model providers that we have in the United States are putting so many insane guardrails on things that the models are becoming unusable. Practitioners carrying full authorization from their own security programs run into this routinely.

Hugging Face’s responders fed logs to U.S. foundation models to reconstruct the attack and were refused. The work was defensive, and the guardrails read the request as a cybersecurity violation. They finished on an open-weight model without guardrails. Guardrails can be fine-tuned or distilled out by anyone who wants them gone.

Halli Bjornsson, CEO and Co-founder, Varist

Bjornsson

Morris, Stuxnet and SolarWinds were designed to infect thousands of independent targets. This attack had one. Had it been built to spread, it could have produced self-evolving malware more dangerous than all three.

Open-weight models without guardrails can be expected to behave the same way. With millions of open-weight users coming, most running everyday tasks, inadvertent attacks like this one will become common. Defenders and insurers will have to account for cyberattacks by goal-seeking agents acting for humans with no malicious intent. And then there are the intentional ones.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)

The post BLACK HAT ROUNDTABLE: Security pros dissect fallout from Hugging Face’s double guardrail failure first appeared on The Last Watchdog.

View Details

Atlanta, GA—August 4, 2026—Airlock Digital, a leader in preventative endpoint security, today announced Agentic AI Control & Governance at Black Hat USA 2026.

The new capabilities build on application control by providing command- and session-level visibility into trusted AI agent behavior, centralized policy management for trusted applications and AI agents, and real-time governance over what trusted AI agents are allowed to do on endpoints. Airlock Digital expects customer general availability in Q3 2026.

AI agents are becoming part of everyday enterprise work, but traditional endpoint security was designed to govern applications—not autonomous software operating on behalf of users. Organizations still need preventative controls that determine what software is trusted to execute.

But once trusted AI agents begin running, a new challenge emerges: understanding what they’re doing, defining what they can do, and ensuring they operate within organizational policy.

Application Control determines what software is trusted to execute. Agentic AI Control & Governance extends that foundation, enabling organizations to understand AI agent behavior, define trusted operating boundaries, and govern AI activity at the endpoint. Together, they provide a consistent approach to governing trusted applications and AI agents.

The urgency is measurable. Knowing an AI agent exists isn’t enough. Organizations need to understand how trusted AI agents behave once they are running, not simply where they exist. In April 2026, Cloud Security Alliance reported that 82% of organizations had unknown AI agents running in their environments and 65% had experienced an AI agent-related security incident in the prior 12 months.

Cottingham

“Traditional endpoint security determines what software is trusted to execute. Agentic AI introduces a second layer of policy: what a trusted AI agent is allowed to do once it’s running,” said David Cottingham, Co-founder and Chief Product Officer, Airlock Digital. “AI agents don’t simply stop when an action is blocked; they evaluate alternatives and continue working toward their objective. Rather than repeatedly blocking an agent, organizations can communicate clear operational boundaries, allowing trusted agents to adapt their behavior while remaining within policy.”

Agentic AI Control & Governance is designed to help security and IT teams:

•Automatically discover AI applications and understand AI agent behavior through command- and session-level visibility.

•Centrally manage policies for trusted applications and trusted AI agents with version-controlled policy changes and granular administrative controls.

•Evaluate AI agent commands against policy in real time and communicate policy decisions back to supported AI agents so they adapt their behavior.

•Demonstrate AI governance by monitoring and searching AI agent sessions, commands, files, policy decisions, risk activity, token usage, and cost from a centralized dashboard.

Airlock Digital governs AI where the work happens: endpoints. While native Applications and activity within their own ecosystems, Airlock Digital extends governance to where AI agents execute commands, interact with applications, and perform work. Organizations gain independent governance at the endpoint, providing consistent policy enforcement across supported AI platforms.

Dunne

“What we’re hearing from customers is that the challenge isn’t adopting Agentic AI; it’s governing it,” said Kevin Dunne, Chief Executive Officer, Airlock Digital. “Organizations need to understand what trusted AI agents are doing, define what they’re allowed to do and ensure they operate within organizational policy. Agentic AI Control & Governance extends our leadership in preventative endpoint security by giving organizations the visibility and governance they need to confidently adopt AI without slowing the business down.”

Airlock Digital will demonstrate Agentic AI Control & Governance at Black Hat USA 2026 in Las Vegas. Visit Booth #5729 for an exclusive preview of the new capabilities ahead of customer general availability in Q3 2026.

Learn more on Airlock Digital’s blog, AI Agents Behave More Like Employees Than Applications.

About Airlock Digital : Airlock Digital helps organizations stop threats before they start through preventative endpoint security. Founded in Australia in 2013 and operating internationally, the company provides precision application control, allowlisting and OS hardening that enable organizations to run only trusted software and reduce attack surfaces. Airlock Digital supports customers across financial services, healthcare, manufacturing, energy, government and education. Learn more at airlockdigital.com.

Media Contact: Erin Welke, VP of Marketing, Airlock Digital, erin.welke@airlockdigital.com

The post News alert: Airlock extends endpoint control to govern AI agents and define operating boundaries first appeared on The Last Watchdog.

View Details

Las Vegas, United States, August 4th, 2026, CyberNewswire – Mallory, the AI-native Threat and Exposure Management platform, today introduced a unified context and intelligence layer for security teams.

The architecture has three parts: a context graph that correlates attack surface, threat, and vulnerability data; an intelligent reasoning layer that determines what matters and why; and a policy and governance layer that routes prioritized work into action under each customer’s own rules. One foundation supports exposure investigation, threat hunting, supply chain risk management, and vulnerability prioritization, rather than locking teams into a single fixed workflow.

Cran

“Our vision is an intelligent, agentic platform constantly evaluating whether a threat is actually a risk in your environment, so your team gets a faster, sharper response and spends its time on the risk that matters. The intelligence to hunt threats, prioritize exposures, and build detections all starts from the same data, so it shouldn’t take three tools to make it work. And when a working exploit lands in hours, a queue ranked by a severity score that doesn’t know who’s attacking you is wasting your best analysts on work that should be automated,” said Jonathan Cran, founder and CEO of Mallory.

The context graph, reasoning layer, and policy layer are fully separable, so Mallory fits any security team’s stack, not just one built around it. Teams that just want a contextual data source can plug Mallory’s threat and context data straight into the workflows they already run. Teams ready to go further can adopt Mallory’s agentic harness out of the box, handing routine exposure remediation to agents at scale, all within the policy guardrails they define and control.

Mallory’s consumption model is a deliberate break from usage-based AI pricing. It meters on coverage and outcomes rather than token usage, and supports bring-your-own-key (BYOK), so teams run on their own model infrastructure or Mallory’s. Teams pay for software and the outcomes it produces, not for how much a workload happens to consume.

AI-assisted attackers have collapsed the cost and time of finding exploitable flaws, and security teams are drowning in intel they cannot act on fast enough. Point tools force teams to choose between prioritizing exposures, hunting for threats, or building detections, when the real problem is upstream: knowing what to look for, where to look for it, and being fast and cost-effective enough to act on it. Mallory’s architecture is built to close that gap once, at the layer underneath all three problems, rather than solving each one separately.

•The context graph pulls in attack surface and security configuration information, then unifies it with external threat intel and vulnerability information using the same underlying pipelines. Every new CVE or adversary technique is correlated against an organization’s actual exposure within minutes, not days.

•The intelligent reasoning layer sits on top, determining whether a given signal reaches the environment, where it lands, and how much it matters given real adversary activity, not a static severity score alone.

•The policy and governance layer sits above that, letting teams set exactly how much autonomy the reasoning agents get: auditing code repositories against current adversary techniques, watching supply chain dependencies, evaluating CI/CD configurations, or routing a prioritized case straight into the ticketing tool the team already uses.

Mallory Founder, Jonathan Cran, writes about its origin in the blog: Adversary Timelines Have Collapsed: Defenders Must Rethink Proactive Security with Agents

About Mallory: Mallory unifies threat intelligence, exposure context, and response into one architecture for security teams. It monitors adversary activity, contextualizes it against an organization’s attack surface, and converts fragmented telemetry into prioritized, evidence-based action. Four components work together: threat intelligence, a unified context graph, an agentic harness that investigates and writes cases, and a policy and governance layer that keeps agent work scoped, auditable, and controlled. Security teams run Mallory on their own models, keys, and infrastructure. Founded in 2024 and headquartered in Austin, Texas, Mallory is backed by Decibel Partners, LiveOak Ventures, and Aviso Ventures. Users can learn more at mallory.ai.

Media contact: Alexa Rzasa, Head of Marketing, Mallory, alexa.rzasa@mallory.ai

The post News alert: Mallory links threat intelligence to governed response as exploit timelines shrink first appeared on The Last Watchdog.

View Details

LAS VEGAS, Aug. 4, 2026, CyberNewswire The Cybersecurity Excellence Awards today announced the winners of the 2026 Community Choice Award, selected through 79,455 votes cast during the awards season.

AI security ranked among the highest-voted award categories this season. The results arrive during Black Hat USA week, where AI risk is also among the most prominent themes on the conference agenda.

Community Choice is the only Cybersecurity Excellence Awards recognition determined directly by community voting. It complements the jury awards by recognizing the visible support nominees have earned across the wider cybersecurity community.

View all 2026 Community Choice Award winners

Schulze

“Congratulations to every 2026 Community Choice Award winner, and thank you to all the nominees and community members who participated,” said Holger Schulze, founder and CEO of Cybersecurity Insiders, which presents the Cybersecurity Excellence Awards. “The strongest voting support centered on security operations, exposure management, and AI security. In 2024, AI security was a single award category. In 2026 it spans ten, as AI reaches into access, data protection, detection, and response, with different vendors solving each one.”

2026 research priorities

The same areas that drew the most votes across product and service categories also surfaced as top priorities in Cybersecurity Insiders survey research this year: expanding operational capacity to detect and respond at the speed and scale of modern threats, reducing exploitable risk before attackers can act, and establishing controls as AI reaches more enterprise data, applications, identities, and workflows.

Cybersecurity Insiders will continue examining these shifts through upcoming research into how AI is reshaping security domains, where enterprise defenses are falling behind, and what organizations are doing to close the resulting gaps.

Explore recent Cybersecurity Insiders research

About Cybersecurity Insiders: For more than a decade, the Cybersecurity Excellence Awards have recognized the companies, products, and professionals helping to advance cybersecurity. The program combines expert jury evaluation with Community Choice recognition, providing distinct ways to recognize demonstrated achievement and industry support.

The awards are presented by Cybersecurity Insiders, an independent research and media platform serving a global community of more than 600,000 cybersecurity professionals, including CISOs and security leaders. Through original research, industry analysis, CISO guides, webinars, and independent solution reviews, Cybersecurity Insiders helps security leaders understand emerging risks, evaluate changing priorities, and make more informed strategic decisions.

Learn more at https://cybersecurity-excellence-awards.com/ and https://www.cybersecurity-insiders.com/

Media Contact: Holger Schulze, CEO, Cybersecurity Insiders, holger.schulze@cybersecurity-insiders.com

Editor’s note: This press release was provided by CyberNewswire as part of its press release syndication service. The views and claims expressed belong to the issuing organization.

The post News alert: Community voting shapes 2026 Cybersecurity Excellence Awards first appeared on The Last Watchdog.

View Details

LAS VEGAS – Companies are deploying AI agents into everyday work at a pace no security program was built for.

Related: AI layoffs pays for AI infrastructure

As Black Hat USA 2026 gets underway in Las Vegas, that question is moving rapidly from theoretical concern to operational reality.The rush is competitive. Nobody wants to be the last one still doing this by hand. What’s getting skipped is the harder question: once an agent is acting on a company’s behalf, how does anyone know what it’s actually doing?

Companies are handing routine tasks to AI agents. Each one moves through the same screens a person would, and every check along the way comes back clean. The login names whose credential is in use. It says nothing about who, or what, is actually operating the account.

Identity systems answer one question well: who is logging in. Multifactor authentication and single sign-on are built for that, and only that. Nothing checks what the login is then allowed to do.

Machines have been logging in for years too. That got handled by predictability. A script ran the same steps every time, so anything different stood out. Two populations — human and machine — two ways of checking, and that covered most of what needed watching. Then came something that belongs to both checks at once: generative AI.

Into the machine layer

Companies are tripping over themselves right now, racing to beat each other to market with AI agents everywhere they can put them. Each one signs in with a username and password like a human user would.

Once that hurdle clears, the agent moves into the machine layer, the systems built to talk to other systems, where a company would normally expect the predictability check to catch anything off. But that check was built to catch a script behaving strangely. An AI agent making its own decisions at every step doesn’t behave strangely. It behaves like a legitimately signed-in person, so nothing ever trips.

This is no longer a thin slice of traffic. Automated activity reached 53 percent of all web traffic last year, according to Imperva’s 2026 Bad Bot Report, which for the first time counted AI agents as a third category because the old sorting stopped working. The Cloud Security Alliance found non-human identities outnumbering human ones 45 to 1, and 78 percent of organizations have no written policy for creating or retiring an AI identity.

That is the exposure. Two systems, both working exactly as designed, and neither built for an AI agent that clears the human door while slipping past the machine gate. Companies are deploying agents into that opening right now, racing to keep up with each other, without pausing to close it.

Shira Sagiv, Radware’s vice president of product portfolio, has spent her career on the other side of exactly this problem. Last Watchdog connected with her ahead of Black Hat USA 2026 to talk through what changes once a valid login no longer tells you who, or what, is on the other end.

LW: When a company hands a routine task to an AI agent, what does the login actually confirm, and what does it leave completely unknown?

Sagiv: A login confirms that the agent has permission to enter a system. It doesn’t tell you whether the agent should take a specific action, whether that action is safe, or whether the behavior matches the business purpose it was given.

Authentication establishes identity. It does not control what happens next. An internal AI agent may have access to sensitive applications, APIs, data and tools, and the autonomy to act across all of them. If it is over-permissioned, manipulated through a malicious prompt, or simply behaves in a way no one intended, valid credentials will not prevent it from causing harm.

LW: You’ve spent your career on the predictability side of this problem. What used to make enterprise automation easy to govern, and why doesn’t that hold for an AI agent?

Sagiv: Traditional automation was easy to govern because it was narrow and repetitive. A script performed the same task the same way every time. When it changed, that stood out.

AI agents are built to do the opposite. They interpret, decide and adapt. They use valid credentials, work through legitimate applications and call APIs in ways that look ordinary on the surface. What they do next depends on the prompt, the data they receive and the tools they are allowed to reach.

Sorting traffic into people on one side and scripts on the other no longer covers what is out there.

LW: Once an agent clears the login and starts acting across a company’s systems, what’s actually different about how it behaves compared to traditional automated activity?

Sagiv: The difference is variability, and it shows up in what the agent does once it is inside.

It may reach sensitive data it has no need for, invoke the wrong tool, or pass information to a system that was never authorized to receive it. It may also take a series of individually valid actions that add up to an outcome nobody intended.

None of that requires the agent to be compromised. It can happen while the agent is performing the legitimate business task it was assigned, using approved credentials and approved tools.

LW: Companies are racing to deploy agents faster than they can figure out how to secure and govern them. What does that race actually cost a security team, in practical terms?

Sagiv: It creates blind spots. Security teams are being asked to protect activity they cannot fully see or classify yet.

They may not know which agents are running, what those agents can reach, what permissions they hold or whether any of that has changed since deployment. Detection slows down. Governance gets harder, because a team cannot manage what it cannot see.

The practical cost is time. An agent that has been manipulated or over-permissioned goes unrecognized until after the business impact shows up.

LW: If the old checks don’t catch this, what does? What can a company actually put in place today?

Sagiv: Organizations need to move past checking identity alone and start looking at what an agent can access and how it behaves across its whole lifecycle.

Discovery comes first. Security teams need to know where AI agents are running, including agents connected to SaaS applications, developer environments and internal business workflows. Sanctioned agents and shadow AI both have to be found and accounted for.

Governance follows. Organizations need to understand what those agents can access, which actions they can take, who owns them and whether their permissions match their intended purpose. Compliance sits here too, against the EU AI Act, the NIST AI Risk Management Framework, ISO 42001, GDPR and HIPAA.

Then runtime protection. Approving an agent at deployment and assuming it will behave as expected is not enough. Teams need behavioral signals showing whether the agent is operating inside its guardrails, and controls that can stop a risky action while it is happening.

Agent behavior is dynamic, and it changes with prompts, data and tool interactions. That argues for defenses that evaluate activity continuously and respond at machine speed. Radware’s Agentic AI Protection is built along those lines, to discover, govern and protect agents through the lifecycle.

LW: A board is told its identity controls are working. What’s the one question it should ask next about the AI agents operating inside the business?

Sagiv: Do we know which AI agents are operating across our business, what they can access, and whether we can stop them from taking an action we never intended?

It sounds simple. Authentication tells a board who or what entered the system. It says nothing about whether everything that followed was appropriate.

If the answer is no, the organization has a visibility and control gap, even if its identity controls are working exactly as they should.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)

The post BLACK HAT Q&A: The AI agent that clears the human door and slips past the machine gate first appeared on The Last Watchdog.

View Details

LAS VEGAS – Almost every company can now produce a list of what’s inside its software. Almost none can prove the list is right.

Related: SBOM’s role in cybersecurity

Construction solved this a century ago. Every steel beam carries a stamp naming the mill that poured it. Every concrete truck arrives with a ticket recording the batch. Every fire door ships with a label certifying its rating.

Software has been catching up. Every open source library pulled into a build is supposed to be logged, every third-party component identified, every dependency traced to its source. The software bill of materials, or SBOM, is the sum of that accounting: one list of everything inside the finished product.

But that accounting assumes a clean starting point, and software almost never has one. An old build carries whatever it carried the day it was assembled, and every version after it inherits the load.

Code copied from an earlier project rides along. So does a library buried inside a supplier’s component, three companies back. None of it is hidden on purpose. It simply never passed a checkpoint where anyone was writing things down.

The older exposure

What never got written down creates two problems. The first is legal, and it was there long before AI.

An open source license is a copyright license. It gives permission to use the code on conditions. Credit the author. Include the license text. Under the strictest licenses, publish your own source code. A company that does not meet the conditions does not have permission, and without permission it is infringing copyright.

No regulator handles this. The copyright owner does, on whatever timetable it chooses. There is no filing deadline and no jurisdiction test. It applies to every company shipping software today. Most often it surfaces during an acquisition, when the buyer’s lawyers run their own analysis of the code and find the violations.

The second exposure

The second problem is security. A component nobody recorded can carry a flaw, and a flaw nobody knows about does not get fixed.

Log4Shell is the example everyone remembers. In December 2021 a serious flaw turned up in a piece of open source used almost everywhere. Companies that had recorded it knew within hours. The rest spent weeks searching their own software. The next disclosure sent them back to the start, because searching for one flaw never answers the question of what is in the code.

Both problems come from the same fact. An open source component went into the software and nobody recorded that it was there. One leaves a legal obligation the company is not meeting. The other leaves a weakness that never reaches anyone’s list of things to fix.

AI at scale

Open source used to arrive one way. A developer went and found the library, downloaded it and added it to the project. The license came with it, and the record wrote itself. No rule required any of that. Both were side effects of going and getting something.

An AI assistant does not go and get anything. It writes the code directly. Some of that code was copied from work somebody else owns. No license comes along, and nothing gets recorded.

Assistants write far more code than people, and much faster. Unrecorded open source used to turn up occasionally. Now it turns up constantly, and both problems get bigger.

Insignary, a Korean-founded software supply chain security firm now based in Toronto, ran its own analysis across real-world applications and found a pattern of undeclared open source running through code that AI helped write.

Last Watchdog engaged Taek Wan Kim, CEO of Insignary, in a wide-ranging discussion about what it now takes for a company to know, rather than assume, what is inside its own software. Here are excerpts of that conversation edited for clarity and length.

LW: How often does an independent look at finished software disagree with the list that came with it?

Kim: More often than most organizations expect. We have analyzed thousands of commercial software packages, and we keep finding components that never appear in the original SBOM. Sometimes they come from inherited code. Sometimes from third-party SDKs. More and more, from AI-assisted development.

The percentage varies with the development process. The pattern does not. The more complex the supply chain becomes, the wider the gap between what is declared and what is actually there.

LW: When a company cannot fully account for what is in its software, what actually goes wrong?

Kim: Two things go wrong. They are very different from each other, and both end up as business problems.

The first is security. When a critical vulnerability such as Log4Shell is disclosed, a company needs to know immediately whether it is affected. If the vulnerable component is not in the SBOM, management may conclude they are safe when they are not.

The second is licensing. Open source licenses are legal obligations. An undiscovered GPL component can create copyright problems long after a product was released. Even permissive licenses require a company to disclose the use, attribute it and distribute the license text.

Both problems come from the same place. You cannot manage what you cannot see.

LW: An SBOM is a list. What does it mean to verify one?

Kim: Verification means comparing what is documented against what actually exists inside the released version of the software.

It regularly turns up components that development records and package manifests never captured, such as libraries a developer added straight into the code base. It can also pin down which version was used when the package manager declaration was imprecise.

Think of financial auditing. A company prepares its own statements, and investors still expect an independent audit. Software deserves that same standard of evidence. A verified SBOM reflects what is present in the compiled software, not what was intended during development.

LW: AI now writes a large share of new code. What does that do to a company’s ability to make a truthful claim about its own product?

Kim: We ran our own research on this using Insignary AIR, analyzing real-world applications built in whole or in part by AI.

In applications where AI wrote some or all of the code, 37 percent of all files contained undeclared open source snippets, meaning fragments of a component rather than the whole thing. Where AI wrote the entire application, that rose to 56 percent of files.

Measured against dependencies rather than files, our testing found traditional SCA tools caught only about 23 percent of what was actually there. They read declared manifests instead of analyzing the source code.

None of that makes AI unsafe. Large language models learn from enormous amounts of publicly available code, so this is what you would expect. What it means is that a company can no longer assume its SBOM reflects what is inside its software. Trust now requires evidence.

LW: You helped build the market for open source scanning in Korea starting in 2006. What did that first generation of tools solve, and where does it come up short now?

Kim: When we started on open source governance almost 20 years ago, the biggest challenge was that companies did not know. Open source had already become a fundamental part of their software, and most of them had no idea. Developers downloaded components freely. Nobody was tracking the licenses, the vulnerabilities or the maintenance obligations.

Software Composition Analysis solved that. It gave companies a way to find the hidden usage and put governance around it. That was a major step forward.

The challenge kept moving. Software today gets assembled from prebuilt binaries, third-party SDKs, legacy code and AI-generated code, and much of that slips past the checkpoints that produce inventories and SBOMs. Discovering open source is no longer the hard part. The hard part now is proving the inventory is complete and accurate.

LW: What changes when a software inventory stops being an engineering document and becomes something a buyer or an insurer asks to see?

Kim: It changes who owns the problem. For years, software supply chain security was something the engineering team handled. Regulations like Canada’s Bill C-8 and the European Cyber Resilience Act are part of what ends that arrangement.

Accountability no longer stops at the engineering organization, and directors are the ones who answer for governance. Software integrity becomes part of enterprise risk management, next to financial controls and operational resilience. Provenance becomes a board-level discussion.

LW: A board is told its software inventory is complete. What is the one question it should ask next?

Kim: A board will usually hear which tool produced the report, or who generated the SBOM. What it should press for is the independent evidence that proves the inventory is accurate. Confidence should come from verification.

I would ask one question. How do you know?

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)

The post BLACK HAT Q&A: SBOM claims what went in, binary shows what shipped, the risk lies between first appeared on The Last Watchdog.

View Details

The line between physical security, cybersecurity, privacy and reputation management is dissolving. A data leak can surface a home address.

Related: Defending the CEO attack vector

A breached account can put an executive’s family in physical danger. The threats don’t stay in their lanes.

That’s the terrain Chuck Randolph, Jonathan Wackrow and Fred Burton map in The Protector’s Edge: Leadership Through Strategy and Action. Their argument: executive protection has outgrown the old picture of bodyguards, travel logistics and perimeter walls. Today’s protector has to read digital exposure, business continuity and reputation risk, and the pressures bearing down on the C-suite.

Doxxing, deepfakes, AI-enabled impersonation and online radicalization are forcing boards to rethink what protection means. CISOs, CSOs, legal, communications and privacy teams each watch a different dashboard. Adversaries see one target.

I asked Randolph, chief strategy officer at 360 Privacy and a co-author, to lay out what executive protection means now, and why the modern protector works as a strategic risk advisor.

LW: You write that the physical and digital are inseparable. What does that mean for the teams protecting executives?

Randolph: A physical security problem may start online. Someone finds an executive’s home address through a data broker, the spouse and children through social media, travel patterns from posts, breached accounts or public records.

None of it may look especially dangerous on its own. Put it together and it starts to look like targeting. The person planning to harass, threaten or approach an executive does not care which department owns the information. They are looking for a way in.

The job is no longer limited to vehicles, routes, hotels and access control. You still have to do those well, but you also need to know what is exposed online, what the family is sharing, which devices and accounts are vulnerable and whether online activity points toward physical action.

The divide between physical and digital security may still exist on the org chart. It does not exist for the adversary.

LW: Why should CISOs, CSOs and privacy leaders care about executive protection?

Randolph: Because the executive is often one of the most valuable and exposed parts of the organization.

A senior leader has access, authority and visibility. They may have privileged accounts, sensitive communications and the ability to move the company during a crisis. They may also be the public face of a decision people are angry about.

That creates both personal and business risk. A compromised personal email account can expose travel or internal discussions. A family member can become a route for social engineering. A threat against the CEO can disrupt operations, delay decisions and pull several departments into a crisis.

This is where duty of care and business continuity meet. Protecting the executive is not just about keeping one person safe. It is also about protecting the organization’s ability to function.

Treating executive protection as separate from cyber, privacy and continuity planning is a mistake. In a real incident, those lines disappear.

LW: How should teams read weak signals without drowning in noise?

Randolph: You have to stop collecting information just because you can. The first question: what are we actually trying to understand?

That may be whether a grievance is becoming more personal, whether someone is trying to locate the executive or whether online anger is starting to move toward action. Once you know the question, you can look for the indicators that matter.

Technology helps with the volume. It can find patterns and surface things a person might miss, but someone still has to understand the context.

Good protective intelligence is not about reporting everything. It is about knowing what deserves attention, what needs watching and what requires a decision, or enabling a decision.

LW: You call the information environment a protective domain. What does that mean during doxxing, leaks or deepfakes?

Randolph: Information itself can change the threat. A leak can expose a home address. A deepfake can create confusion during an active incident. A false story can put an executive at the center of a grievance and drive people toward action.

The issue is not only whether the information is true. The issue is what people believe, how quickly it spreads and what they may do because of it.

Most companies break these incidents into pieces. Cyber looks at how the information got out. Legal looks at exposure. Communications looks at the public response. Physical security looks at whether someone might show up. All reasonable concerns, but someone has to connect them.

The shared questions are simple: What happened? Who is pushing it? Who is reacting to it? Does it change the executive’s exposure? What do we need to do now?

LW: Protectors have to translate risk into business terms. What does that sound like in a board conversation?

Randolph: Telling leaders what they need to know without turning the conversation into a security briefing.

“The threat level is elevated” does not help. Elevated compared with what? What changed? What decision needs to be made?

A better version: “We are seeing the CEO’s home address and family information circulate in a group that has encouraged people to confront company leaders. We have no evidence of a specific plan, but activity is increasing ahead of Tuesday’s event. Our recommendation is to keep the event on, change the arrival plan, increase monitoring and tighten coverage around the residence for the next several days.”

That gives the executive something to work with.

The protector’s job is not to make everything sound dangerous. It is to explain what is happening, what could happen and what the organization can do. Sometimes the right advice is to increase security. Sometimes it is to keep moving.

That judgment is what makes someone a trusted advisor.

LW: As AI and automation reshape targeting, what must remain human?

Randolph: The decision has to remain human. AI can help teams work faster. It can process large volumes, identify patterns and show us things we might otherwise miss. We should use it for that.

What it cannot do is take responsibility. It does not fully understand the executive, the family, the company culture or the cost of getting a call wrong. It can flag language or behavior, but a person still has to decide whether someone is angry, unstable, threatening or moving toward action.

Protection decisions affect real people. They can restrict movement, damage reputations and pull law enforcement or security resources into someone’s life.

The human part is judgment, ethics and the ability to stay calm when the information is incomplete. It is also trust. An executive has to believe the person advising them understands both the threat and the consequences of the recommendation.

AI can support the protector. It should not replace the protector’s judgment.

LW: What should organizations start on now?

Randolph: Find out what is exposed. The executive’s home address, family information, personal accounts, devices, travel habits and public profile. Do not assume you know what is online. Check it.

Then get the right people in the same room. Cyber, physical security, privacy, legal, communications and business continuity should agree on who owns what, what gets shared and when an issue gets escalated.

Then run an exercise. A scenario where an executive is doxxed, a fake recording begins circulating and people start talking about showing up at the executive’s home or a company event. See how the team responds. You will find the gaps quickly.

Companies cannot keep managing these as separate problems. The threat is already converged. The organization has to catch up.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: I used Claude and ChatGPT to assist with research compilation, source discovery, and early draft structuring. All interviews, analysis, fact-checking, and final writing are my own. I remain responsible for every claim and conclusion.)

The post BLACK HAT AUTHOR Q&A: The adversary doesn’t care which department owns the data first appeared on The Last Watchdog.

View Details

MELBOURNE, Fla., July 30, 2026, CyberNewswire The growing number of high-profile AI security incidents making headlines around the world are not simply cybersecurity failures. They are architectural failures, according to OpenMatter Network Co-Founder and CEO Renee Davis.

“Recent incidents involving increasingly autonomous AI systems – including OpenAI’s widely reported cyber evaluation that resulted in the compromise of Hugging Face infrastructure, along with a growing body of documented cases in which AI systems have exceeded their intended authority or behaved in unexpected ways – demonstrate that enterprise computing has entered a new era for which today’s security architecture was never designed,” Davis said.

Davis said that instead of asking how to make artificial intelligence more secure, enterprise leaders should be asking a far more fundamental question: Is the architecture itself capable of governing autonomous intelligence?

“The answer is increasingly becoming no,” she asserted. “The industry is treating these events as isolated security incidents. They’re not. They’re evidence that enterprise computing has reached an architectural inflection point. We’re attempting to govern autonomous AI using security assumptions that were developed long before autonomous AI existed.”

For more than forty years, enterprise security has evolved around a familiar model: trusted systems, authenticated users and protected networks. Firewalls, identity management, Zero Trust frameworks and continuous monitoring remain indispensable. But they were built to protect systems that ultimately remained under direct human control.

Davis

Agentic AI fundamentally changes that assumption. Enterprises are now deploying software capable of making decisions, coordinating with other AI agents, accessing sensitive information and acting with limited human intervention. Autonomous intelligence has become an active participant inside the enterprise.

Davis underscored that OpenMatter believes the next era of enterprise computing requires a new architectural foundation: Verification Architecture. Rather than relying primarily on trust, Verification Architecture uses cryptographic proof to verify the integrity of data, computation and AI behavior. Instead of asking enterprises to trust that systems behaved correctly, it enables them to prove that they did.

“Trust always contains an element of assumption,” Davis emphasized. “Cryptographic verification replaces assumption with mathematical proof. That is the architectural shift enterprise computing now requires.”

According to Davis, every transformational era of computing has required a corresponding architectural breakthrough. The internet required encryption. Cloud computing required virtualization. Autonomous AI requires cryptographic verification.

“Every major AI security incident should now be viewed first as an architectural failure and only second as a cybersecurity event,” Davis said. “The next major AI incident is not simply a security event. It will be an architectural wake-up call.”

OpenMatter is calling on enterprise technology leaders, policymakers, standards organizations and the cybersecurity community to begin treating cryptographic verification not as another security feature, but as the architectural foundation upon which trustworthy autonomous computing must be built.

“Enterprise computing has reached another architectural crossroads,” Davis concluded. “The era of trusting autonomous AI is coming to an end. The era of proving autonomous AI has begun. The organizations that recognize that shift first will define the next generation of enterprise computing.”

For more information, contact onboarding@openmatter.network.

About OpenMatter Network: Headquartered in Florida’s Space Coast, OpenMatter Network is building the Verifiable Trust Layer for Secure Collaboration and AI Agents. Guided by the principle “Don’t Trust Data. Prove It.,” the company’s cryptographically verifiable architecture enables secure collaboration, governed AI behavior and mathematically verifiable execution across untrusted environments. For more information, visit www.openmatter.network.

Media contact: Caleigh McDaniel, caleigh@griffin360.com

Editor’s note: This press release was provided by CyberNewswire as part of its press release syndication service. The views and claims expressed belong to the issuing organization.

The post News alert: OpenMatter proposes verification architecture for securing autonomous AI systems first appeared on The Last Watchdog.

View Details

Miami, June 18, 2025, CyberNewswire — Halo Security today announced that its attack surface management solution has been named a 2025 MSP Today Product of the Year Award winner by TMC, a leading global media company recognized for building communities in technology and business through live events and digital marketing platforms.

The MSP Today Product of the Year Award honors standout products and services that are reshaping the managed services landscape—delivered through the Channel and purpose-built to meet the evolving needs of end users. The Halo Security platform was selected for its innovation, performance, and its measurable impact on customers and partners alike.

The Halo Security Attack Surface Management Platform enables organizations and managed service providers (MSPs) to discover, monitor, and secure their internet-facing assets. The platform combines attacker-like discovery methods with ongoing security monitoring, vulnerability scanning, and expert-led penetration testing services to help organizations of all sizes identify and remediate security risks before they can be exploited.

Designed with the Channel in mind, the platform offers easy-to-use client management and reporting, along with seamless integrations into tools like Slack, Jira, and major cloud providers. The platform empowers MSPs to deliver scalable, high-impact security services with minimal setup and configuration. With built-in PCI compliance reporting, dark web monitoring, and dynamic application security testing (DAST), Halo Security gives partners and clients alike the visibility needed to stay ahead of evolving threats and meet their compliance goals.

Dowling

“Our mission has always been to give organizations and our channel partners deep visibility into their digital presence,” said Lisa Dowling, CEO of Halo Security. “This award is a testament to the innovation behind our platform, the dedication of our team, and the success our MSP partners are driving for their clients every day.”

“It gives me great pleasure to recognize Halo Security as a 2025 recipient of TMC’s MSP Today Product of the Year Award for their innovative attack surface management solution,” said Rich Tehrani, CEO of TMC. “Our judges were thoroughly impressed not only by the strength and features of the product, but by Halo Security’s commitment to the Channel—empowering partners to deliver exceptional service and drive meaningful results for their clients.”

Winners of the 2025 MSP Today Product of the Year Award will be featured on MSP Today, the definitive resource for managed service providers, as well as across TMCnet’s media platforms.

About Halo Security: Halo Security is a comprehensive external attack surface management platform that provides asset discovery, risk assessment, and penetration testing in a single, easy-to-use dashboard. Founded by cybersecurity experts with backgrounds at McAfee, Intel, Kenna Security, OneLogin, and WhiteHat Security, Halo Security delivers a unique attacker-based approach to help organizations safeguard against potential threats. Users can learn more at halosecurity.com.

About MSP Today: MSP Today is the premier online destination for MSPs (Managed Service Providers) and IT service providers worldwide. As the industry’s leading web portal, we are committed to delivering timely and relevant news, cutting-edge product information, and invaluable insights to empower MSPs and IT professionals to thrive in today’s rapidly evolving technology landscape. Whether you’re seeking in-depth articles on emerging technologies, comprehensive product reviews, or actionable tips to optimize your IT services, MSP Today is your go-to resource for all things MSP-related. Users can learn more at www.msptoday.com.

About TMC: For more than 20 years, TMC has been honoring technology companies with awards in various categories. These awards are regarded as some of the most prestigious and respected awards in the communications and technology sector worldwide. Winners represent prominent players in the market who consistently demonstrate the advancement of technologies. Each recipient is a verifiable leader in the marketplace. TMC also provides global buyers with valuable insights to make informed tech decisions through our editorial platforms, live events, webinars, and online advertising. Users can learn more at www.tmcnet.com.

Media contacts: Lauren Ladra, Director of Partnerships Halo Security, lauren@halosecurity.com, 415-799-4568; Stephanie Thompson Manager, TMC Awards,
Stephanie Thompson, TMC, sthompson@tmcnet.com, 203-852-6800.

Editor’s note: This press release was provided by CyberNewswire as part of its press release syndication service. The views and claims expressed belong to the issuing organization.

The post News alert: Halo Security’s attack surface management platform wins MSP Today’s top award first appeared on The Last Watchdog.

View Details

Last week at Microsoft Build, Azure CTO Mark Russinovich made headlines by telling the truth.

Related: A basis for AI optimism

In a rare moment of public candor from a Big Tech executive, Russinovich warned that current AI architectures—particularly autoregressive transformers—have structural that become especially evident in generative AI (GenAI) systems built to mimic human reasoning. And more than that, he acknowledged the growing risk of jailbreak-style attacks that can trick AI systems into revealing sensitive content or misbehaving in ways they were explicitly designed to avoid.

That moment, captured in a GeekWire field report, marks a turning point: one of the architects of Microsoft’s AI push admitting—on stage—that reasoning capacity and exploitability are two sides of the same coin.

Russinovich

Russinovich’s remarks weren’t just technically insightful. They signaled a strategic shift: a willingness to engage publicly with the implications of large language model (LLM) vulnerabilities, even as Microsoft races to deploy those same models in mission-critical, agentic systems.

What Redmond Admitted

In a recent white paper, Microsoft laid out something that should make anyone working with AI sit up and pay attention. Their research shows that today’s AI systems are vulnerable in ways we’re only beginning to understand.

One issue they flagged involves what they call “Crescendo Attacks.” That’s when someone starts off with innocent-sounding questions, slowly building up to more risky ones. Because the AI is trained to be helpful, it can end up stepping over the line—without even realizing it’s being manipulated, revealing sensitive content or misbehaving in generative AI systems designed to produce human-like output from prompts.

Even more striking, Microsoft coined a new term: Crescendomation. This is the idea that an AI can actually learn how to jailbreak itself. In other words, it uses its own reasoning skills to figure out how to break past its built-in safety rules.

The most sobering part? Microsoft admitted something most companies won’t say out loud: the smarter these systems get, the more vulnerable they may become. That’s a structural flaw, not just a bug. Other companies might understand this too—but so far, Microsoft is one of the only ones willing to say it publicly.

Why this matters

The AI field is chasing an elusive goal: useful, trustworthy autonomy. That means models that don’t just spit out words, but actually reason across domains, remember context, orchestrate tasks, and interact with other systems.

Microsoft’s Discovery platform, for example, is already deploying teams of agentic AIs in scientific R&D. These agents propose hypotheses, conduct literature reviews, simulate molecules, and accelerate discovery pipelines. In test runs, they helped design PFAS-free cooling fluids and lithium-lite electrolytes.

Yet, as these systems grow more powerful, they also become more exploitable. Prompt injection and jailbreak attacks aren’t bugs. They’re an expression of the model’s very architecture. That’s the paradox Microsoft is now owning: the path to powerful AI runs straight through its own vulnerabilities.

So how do the other tech giants stack up? If we examine Amazon, Meta, Google, Anthropic, and OpenAI alongside Microsoft, a pattern emerges: very different levels of candor and very different trajectories of response.

Microsoft is transparent, tactical

Microsoft is doing something unusual for a company its size: it’s being upfront. They’ve openly called out a key weakness in today’s AI systems—something they call Crescendomation, where the AI essentially learns to jailbreak itself. Instead of brushing it off, they’re treating it as a design flaw that needs to be addressed head-on, not just studied in the lab.

At the same time, they’re pushing forward with some of the most advanced AI projects out there—like Discovery, a platform where multiple AIs work together to tackle complex problems. What makes this different is that they’re building in transparency from the start, with clear explanations of what the systems are doing and keeping humans in the loop along the way.

This isn’t just PR. It’s a real shift in how a major tech player is talking about and building AI. Microsoft isn’t pretending it can eliminate all the risks—but it is showing what it looks like to take those risks seriously.

Google is opaque, optimistic

Despite growing evidence that its Gemini model has been jailbroken through prompt leakage and indirect injections, Google has not publicly acknowledged such vulnerabilities. Its official posture remains focused on performance improvements and feature expansion.

In other words, Google is sticking to the script. No technical white papers. No red-team reports. Just product rollouts and incremental guardrails.

That might make sense from a business standpoint, but from a public trust perspective, it’s a red flag. The deeper risk is that Google treats prompt exploits as ephemeral glitches, not systemic architectural debt.

Meta is cautiously engaged

Meta has been more forthright about its safety limitations, particularly with LLaMA and its PromptGuard classifier. They’ve admitted that prompt obfuscation — such as spacing out forbidden words — can defeat filters. And they’ve spoken publicly about red-teaming efforts.

Yet their responses remain surface-level. There is no transparent articulation of how their open-source strategy will be hardened at the orchestration layer. It’s one thing to publish your model weights; it’s another to build a resilient, collaborative trust stack.

Amazon is quietly methodical

Amazon, via its Bedrock platform, has been perhaps the most comprehensive — and the least vocal.

They’ve openly published best practices for mitigating jailbreaks, including input validation, user role-tagging, system-prompt separation, and red-teaming pipelines. They’ve acknowledged indirect prompt injection risks in RAG pipelines and are deploying structured Guardrails across Bedrock agents.

Retrieval-Augmented Generation (RAG) is a technique that supercharges GenAI systems by giving them access to live information — think of it as pairing a large language model with its own personal research assistant. Instead of just pulling answers from static training data, the AI can now reach into live databases, search engines, or company documents to ground its responses in current context.

New-style LotL

But that added intelligence opens a new attack surface. If malicious content is hidden inside those “trusted” documents — say, cleverly phrased instructions or adversarial text — the AI can be tricked into following them, just as if the commands came from the user.

LotP — Living off the Prompt!

In traditional cyberattacks, adversaries often used a method known as Living off the Land — exploiting built-in Windows tools like PowerShell to operate invisibly. These techniques required moderate to high technical skill.

By contrast, AI jailbreaks like Crescendo attacks demand little more than language skill and determination. There’s no need to master terminal commands — just a knack for conversational manipulation. The AI’s own helpfulness becomes the attack vector.

Welcome to a new era: Living off the Prompt!

It’s a new flavor of an old trick. In cybersecurity, we call this “living off the land” (LotL) — when attackers use legitimate tools like PowerShell or WMI to stay hidden while carrying out harmful actions. In RAG-based exploits, the attacker doesn’t need to break in through the front door. They just need to sneak something toxic into the system’s bookshelf — and let the AI read it aloud.

Their architecture reflects seriousness. But their public narrative does not. Amazon is doing the work but letting Microsoft do the talking. That’s a missed opportunity to lead on trust.

Anthropic is structurally mindful

Anthropic stands apart for putting safety at the core of its business model. Its Claude family of models is built around “Constitutional AI,” a framework that guides outputs with a predefined ethical structure.

They’ve shared system cards detailing model limitations, engaged in third-party red-teaming, and emphasized alignment research. Anthropic isn’t just checking boxes—it’s attempting to build trustworthiness into the system from day one.

That said, they’ve remained somewhat quiet in the broader conversation on orchestrated deployments and jailbreak mitigation in production environments.

OpenAI is guarded, under scrutiny

OpenAI powers Microsoft’s Copilot offerings and remains central to the LLM landscape. But its posture on jailbreaks has grown increasingly opaque.

Despite facing jailbreak attacks across ChatGPT and API endpoints, OpenAI has released minimal public disclosure about the scale of these vulnerabilities. It relies on RLHF, moderation APIs, and internal red-teaming, but unlike Microsoft or Anthropic, it has published little about real-world attack scenarios.

The company’s public-facing narrative leans heavily on innovation, not risk mitigation. That gap will grow more noticeable as agentic deployments scale.

What now?

What we need now is pretty straightforward. All companies deploying GenAI platforms, especially those pursuing agentic capabilities, should align on testing norms. Companies should start playing by the same rules when it comes to disclosing how their AI systems are tested—especially the results from so-called red-teaming, where researchers try to break or manipulate the model. We also need a common language for describing the ways these systems can be tricked, and what actually works to stop those tricks.

Just as important, we need real-time checks built into the AI platforms themselves—tools that flag when something’s going wrong, not after the fact. And finally, there has to be a way to trace what decisions the AI is making, so humans can stay involved without being buried in technical noise.

Final Thought

Agentic AI is no longer just a lab curiosity—it’s starting to show up in real-world tools, doing things that feel startlingly human: setting goals, adjusting strategies, even coordinating tasks across systems. That’s what makes it so powerful—and so hard to control.

Meanwhile, jailbreaks aren’t theoretical anymore either. They’re happening right now, in ways we can’t always predict or prevent. Microsoft just became the first major player to say this out loud. That matters.

But here’s the deeper truth: this moment isn’t just about smarter machines. It’s about how power is shifting—who gets to act, and who decides what’s trustworthy.

For decades, the term “agency” lived quietly in academic circles. Psychologists used it to describe the human capacity to set goals and make decisions. Sociologists saw it as a force that let people push back against rigid systems. In everyday life, it was invisible—but always present. Agency was the thing you felt when you said, “I’ve got this.” Or when you fought back.

Now, for the first time, we’re building machines that act agentically—and in doing so, we’re forced to rethink how humans act alongside them.

The question isn’t whether we can eliminate the risks. We can’t. The question is whether we can stay honest about what’s unfolding—and make sure that these systems expand human agency, not erase it.

Because agentic AI isn’t just about what machines can do.

It’s about what we let them do. And what we still choose to do—on our own terms.

Microsoft just took that first honest step. Let’s see who follows. I’ll keep watch — and keep reporting.

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: A machine assisted in creating this content. I used ChatGPT-4o to accelerate research, to scale correlations, to distill complex observations and to tighten structure, grammar, and syntax. The analysis and conclusions are entirely my own—drawn from lived experience and editorial judgment honed over decades of investigative reporting.)

The post MY TAKE: Microsoft takes ownership of AI risk — Google, Meta, Amazon, OpenAI look the other way first appeared on The Last Watchdog.

View Details

Artificial intelligence is changing everything – from how we search for answers to how we decide who gets hired, flagged, diagnosed, or denied.

Related: Does AI take your data?

It offers speed and precision at unprecedented scale. But without intention, progress often leaves behind a trail of invisible harm. We are moving fast. Too fast. And in our excitement, we’ve stopped asking the most important question of all: at what cost?

AI’s influence is already everywhere, even when we don’t see it. It hides behind dashboards, recommendation engines, productivity scores, and predictive analytics. It tells us what’s trending, what’s risky, and what to do next. But just because it’s quiet doesn’t mean it’s safe. These tools are shaping human lives in deeply personal ways, and too often, they’re doing it invisibly and without accountability.

Is speed necessarily always good?

We’ve convinced ourselves that because AI seems to work so well, it must be safe. That speed is inherently good.That precision means wisdom. But that’s the illusion. AI doesn’t actually understand anything. It doesn’t think. It doesn’t care. It predicts patterns because we trained it to, and then it repeats those patterns – without context, without ethics, and without pausing to ask, “Is this right?”

Professor Guillaume Thierry put it bluntly when he said that AI doesn’t “know” anything. Yet we continue to treat these systems like they’re colleagues we can trust with real decisions – decisions we might ordinarily hesitate to give a junior team member.

And that’s how risk becomes institutionalized – not because someone made a dramatic mistake, but because no one stopped to question the subtle drift.

Even the architects of AI are raising their hands and saying, “Slow down.” Demis Hassabis, Geoffrey Hinton, Yann LeCun, and Jürgen Schmidhuber have all contributed groundbreaking work in this space. But many of them are now urging us to think more deeply about the moral frameworks guiding this technology. Hinton, often called the “godfather of AI,” has expressed concern that we are building systems whose inner workings we can no longer fully explain. LeCun is calling for safeguards that go beyond technical brilliance. Even they know that power without ethics can turn on us.

Purposeful performance

Nigel Toon, CEO of Graphcore, summed it up in a way that really stuck with me: “Performance must serve purpose.” If we’re not designing AI to align with human values, then it doesn’t matter how efficient it is. It will scale harm just as quickly as it scales help.

We’ve already seen this play out. Amazon once tested an AI recruiting tool that learned – based on biased historical data – that male candidates were more “preferable” than women. The tool wasn’t malicious, but it absorbed past inequities in historical data and amplified them. It was scrapped, but not before teaching us a critical lesson: when you train a machine on inequality, it automates injustice.

Oosthuizen

And this is the real problem with AI – it doesn’t just act. It scales. What would have been a poor judgment call by a single person becomes a system-wide bias once you embed it into an algorithm and apply it globally. Bias replicates itself. Mistakes become policy. The tools we built to optimize start to quietly oppress.

To make things worse, AI systems aren’t static. They learn. They adapt. They drift. What they were yesterday is not what they are today. And yet, most of the systems we’ve designed to monitor risk—audits, firewalls, quarterly controls—were built for static environments. We’re actively trying to govern a living system with tools that belong to a dead era.

Explainable designs

So what do we need instead?

We need to embed explainability into the design, not add it as an afterthought. We need oversight that’s ongoing, not occasional. But above all, we need wisdom. Not cleverness. Not speed. Wisdom. The kind that asks hard questions even when there’s pressure to deliver answers fast. The kind that resists convenience in favor of integrity.

Because innovation without responsibility is not progress. It’s recklessness.

So yes, let’s continue to build. But let’s build with our eyes open. Let’s not confuse what AI can do with what it should do. Let’s lead, not react. And let’s be the generation that didn’t just keep pace with technology but had the courage to set the moral pace for how it’s used.

The time to lead with foresight is now.

And that leadership begins not with code, but with conscience.

About the essayist: Naómi L Oosthuizen is Senior Global IT Area Lead at ING. She’s an expert in AI, NLG and risk and compliance.

References:

•Dastin, J. (2018, October 10). Amazon scraps secret AI recruiting tool that showed bias against women. Reuters. https://www.reuters.com/article/us-amazon-com-jobs-automation-insight-idUSKCN1MK08G

•Hassabis, D. (2023, July 15). The promise and peril of artificial general intelligence. Financial Times. https://www.ft.com/content/11a19bbf-94d8-44b5-8c64-ec2eb8e7f3a3

•LeCun, Y. (2023). Path towards machine intelligence [Conference presentation]. OpenReview. https://openreview.net/pdf?id=BZ5a1r-kVsf

•Metz, C. (2023, May 1). ‘Godfather of A.I.’ leaves Google and warns of danger ahead. The New York Times. https://www.nytimes.com/2023/05/01/technology/ai-google-chatbot-hinton.html

•MIT Sloan Management Review. (2023). A framework for assessing AI risk. https://mitsloan.mit.edu/ideas-made-to-matter/a-framework-assessing-ai-risk

•Schmidhuber, J. (n.d.). Homepage and research papers. The Swiss AI Lab IDSIA. https://people.idsia.ch/~juergen/

•Stanford Cyber Policy Center. (2024). Regulating under uncertainty: Governance options for generative AI. https://cyber.fsi.stanford.edu/content/regulating-under-uncertainty-governance-options-generative-ai

•The Conversation. (2024, March 6). We need to stop pretending AI is intelligent – Here’s how (G. Thierry, Interviewee). https://theconversation.com/we-need-to-stop-pretending-ai-is-intelligent-heres-how-254090

•Toon, N. (2023, August 17). AI should serve humanity. Graphcore. https://www.graphcore.ai/posts/ai-should-serve-humanity

The post GUEST ESSAY: The AI illusion: Don’t be fooled, innovation without guardrails is just risk–at scale first appeared on The Last Watchdog.

View Details

Paris, Jun. 3, 2025, CyberNewswire–Arsen, the cybersecurity startup known for defending organizations against social engineering threats, has announced the release of its new Vishing Simulation module, a cutting-edge tool designed to train employees against one of the fastest-growing attack vectors: voice phishing (vishing).

This new module uses AI-generated voices and adaptive dialogue systems to simulate live phone-based social engineering attacks — such as those impersonating IT support desks — in a realistic and scalable way.

Voice-based attacks

With attackers increasingly turning to phone calls as a vector for credential theft and initial access, organizations must extend their training and testing capabilities beyond email. Arsen’s Vishing Simulation helps companies identify risk exposure and train employees to respond confidently and securely in real time.

Unlike traditional red team exercises or pre-recorded vishing attempts, Arsen’s simulations are powered by AI, enabling each call to:

•Adapt dynamically to an employee’s responses

•Handle objections or hesitation with lifelike, unscripted dialogue

•Simulate realistic, high-pressure attacker behavior across languages and accents

Le Coz

“Our AI vishing platform leverages state-of-the-art technology to train each and every exposed employee, rather than focusing on VIPs. It’s time to use AI to help the good guys better prepare against this next generation of attacks,” said Thomas Le Coz, CEO at Arsen.

Realistic, scalable, customizable

Arsen’s AI voice engine delivers emotionally nuanced, multilingual, and even accent-aware voices, with customization options that allow organizations to replicate real attacker techniques without compromising safety or ethics.

The Vishing Simulation module is now available as an optional add-on to Arsen’s social engineering training platform. It’s accessible as a standalone module, and can be bundled into current licensing agreements.

Training at scale

By bringing this level of realism and automation to voice phishing simulations, Arsen enables security teams, CISOs, compliance officers, and risk managers to:

•Train every employee with a phone line — not just executives

•Benchmark organizational resilience to vishing threats

•Build reflexes and awareness in the face of manipulative voice-based attacks

Arsen’s early adopters have praised the realism and interactivity of the simulations, describing them as indistinguishable from real attacks.

To learn more or book a demo of the Vishing Simulation module, users can visit https://arsen.co/en.

About Arsen:Arsen is a cybersecurity company specializing in the defense against social engineering attacks. Its SaaS platform enables organizations to run advanced phishing, vishing, and blended social engineering simulations — helping businesses build real-world resilience in the face of modern threats.

Media contact: Thomas Le Coz, CEO, Arsen, marketing@arsen.co

Editor’s note: This press release was provided by CyberNewswire as part of its press release syndication service. The views and claims expressed belong to the issuing organization.

The post News alert: Arsen launches AI-powered vishing simulation to help combat voice phishing at scale first appeared on The Last Watchdog.

View Details

In today’s digital enterprise, API-driven infrastructure is the connective tissue holding everything together.

Related: The DocuSign API-abuse hack

From mobile apps to backend workflows, APIs are what keep digital services talking—and scaling. But this essential layer of connectivity is also where attackers are gaining traction, often quietly and with alarming precision.

Jamison Utter, a cybersecurity strategist at A10 Networks, refers to APIs as the “fuzzy underbelly” of modern infrastructure. He leans on a useful analytical shorthand known as the FUSS framework—short for Fuzzy, Ubiquitous, Shifting and Shallow—to help security teams recognize a widening disconnect between how modern applications behave and how traditional defenses are designed.

“In the race to transform, organizations built layers of API connectivity without building a corresponding model of trust,” Utter explains. “And adversaries are exploiting that asymmetry.”

Moving to anticipatory

Gone are the days when attackers simply hunted for exposed ports or outdated software. They’re now studying how microservices make decisions, how APIs authenticate across trust zones, and where subtle gaps in identity controls allow lateral movement without detection.

In this Q&A, Utter unpacks how the FUSS lens can help security teams better understand the shifting attack surface—and how to move from checkbox compliance to something more adaptive and anticipatory.

LW: You’ve described APIs as the blind spot—or fuzzy underbelly—of modern infrastructure. What do you mean by that?

Utter: APIs are “fuzzy” in the sense that they lack the firm boundaries most security teams are used to working with. They aren’t always mapped. Their intended behavior isn’t always well defined. And they tend to multiply quietly, often outside of centralized control. So, you’ve got this expansive, ever-evolving attack surface that’s neither well understood nor closely monitored. That’s exactly the kind of terrain adversaries love—where they can probe around without triggering alarms and find subtle ways in.

LW: Why are attackers increasingly drawn to APIs as an entry point?

Utter: Attackers know that APIs hold the keys to the kingdom. They don’t just expose data—they expose logic. And because traditional defenses often don’t inspect what APIs do at runtime, adversaries can manipulate inputs and outputs to produce business logic abuses that fly under the radar. Instead of brute-forcing a password, they might query an API a thousand different ways to figure out how it handles permissions, or what kind of response it gives under certain edge conditions. That’s a different mindset—and a lot of security tools just aren’t built to detect that.

LW: You mentioned that identity is being redefined. What do you mean by that in the context of APIs?

Utter: Historically, identity meant a user with credentials. But in today’s distributed systems, identity can be a process, a bot, a container, a CI/CD pipeline, even a third-party service calling an API. These entities act autonomously and make decisions based on policy—or sometimes on incomplete information. But as identities cross API boundaries, context often disappears. You don’t know who or what initiated the call, or what their level of trust should be. That lack of continuity breaks traditional enforcement models and opens the door for misuse.

LW: How does the FUSS model help teams focus their security efforts?

Utter: FUSS gives security and IT leaders a way to reframe the problem. Instead of chasing every API vulnerability like a game of Whack-A-Mole, it encourages them to think more strategically. If something is fuzzy, you work to define it better. If it’s ubiquitous, you prioritize visibility. If it’s shifting, you adapt your tooling to follow change. And if it’s shallow—meaning it lacks depth of protection—you embed guardrails closer to runtime. The framework creates a shared language for discussing why APIs are risky and what it takes to govern them effectively.

LW: What’s the biggest misconception CISOs have about API protection?

Utter: Many assume that if they’ve deployed an API gateway or WAF, the problem is solved. But those tools, while useful, only give you a partial view. They can’t tell you how APIs behave across time, how trust relationships evolve, or how identities get reused in unexpected ways. True API protection means understanding the why behind each call—not just blocking the known bad. It’s about mapping the web of trust inside your system and monitoring for deviations that suggest something’s off.

LW: If you had to give one practical step for security leaders today, what would it be?

Utter: Start building an API inventory—but don’t stop at names and endpoints. Tag them by purpose, sensitivity, and the type of data or actions they expose. Ask: What does this API do? Who calls it? What’s the blast radius if it’s abused? That starts to build a model of intent and consequence. Once you have that, you can begin layering in behavioral monitoring and adaptive controls.

LW: What does the future of API protection look like?

Utter: It’s heading toward deeper, more contextual security—things like identity graphing, behavioral analytics, and continuous trust scoring. We’ll move beyond perimeter enforcement and into runtime accountability. That means being able to say, with high confidence, “This call looks legitimate because I understand its history, its purpose, and its normal behavior.” It’s a heavy lift, but we’re already seeing signs of that evolution. The key is to start building that visibility now—because once attackers redefine the terrain, playing catch-up gets harder.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post SHARED INTEL Q&A: A sharper lens on rising API logic abuse — and a framework to fight back first appeared on The Last Watchdog.

View Details

Catastrophic outages don’t just crash systems — they expose assumptions.

Related: Getting the most from cyber insurance

At RSAC 2025, I met with ESET Chief Security Evangelist Tony Anscombe to trace a quiet but growing convergence: endpoint defense, cyber insurance, and monoculture risk are no longer separate concerns. They’re overlapping — and reshaping how security programs are evaluated.

Anscombe has been tracking this evolution for decades. When I first interviewed him in 2010, “endpoint protection” was still called antivirus. It was about stopping malicious code and blocking known threats.

Widening expectations

Today, endpoint security is something else entirely. It’s an engine of real-time telemetry — not just threat detection, but evidence of operational resilience. And increasingly, that evidence is under scrutiny.

Cyber insurers want it. MSSPs need it. Internal stakeholders are being told to prove it.

That shift, Anscombe argues, is changing how security leaders evaluate products. Detection remains critical, of course. But visibility, context, and integration with insurance-driven expectations are now central to procurement decisions.

This isn’t just about checkboxes — it’s about accountability. When a ransomware incident triggers a denial of coverage or a regulatory rebuke, CISOs need defensible proof of what their tools were doing in the moments that mattered.

And what of AI? For ESET, it’s not hype — it’s heritage. The company has used neural networks in its threat modeling pipeline since the late 1990s, long before today’s generative wave. What’s changed is that AI is now a boardroom talking point — even if it’s no longer the showstopper it was in prior years.

“AI is here,” Anscombe says. “But what matters more is how you operationalize it — especially when underwriters, partners, and customers are all watching.”

Trust-building=deal-making

At the center of it all is endpoint. Still the primary attack surface. Still the first line of defense. But also — increasingly — a focal point in insurance negotiations, due diligence reviews, and third-party risk assessments.

As organizations evaluate prospective vendors, partners, and supply chain participants, endpoint telemetry and security posture are becoming critical components of trust-building — and deal-making.

Anscombe flags a deeper concern: monoculture. they may gain convenience — but lose resilience. Homogenous infrastructure creates shared blind spots, which adversaries can exploit at scale.

In some cases, cyber insurers are nudging organizations toward certain vendors, creating a perceived ‘safe list’ of tools that check the boxes. But this can lead to homogenized infrastructure — and shared blind spots that adversaries can exploit at scale.

“Endpoint defense, insurance demands, and monoculture risk aren’t siloed anymore,” Anscombe observes. “They’re intersecting. And that means endpoint security has to do more than detect. It has to show its work.”

Insurers want proof that security tools aren’t just deployed — they’re working as intended. That telemetry — live, verified, and tied to real-world alerts — is becoming the new currency of insurability.

It’s not about complimenting AV with EDR. It’s about showing your stack can hold up — when the system stutters. For a full drill down, give the accompanying podcast a listen.

I’ll keep watching — and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: Operationalizing diverse security to assure customers, partners–and insurers first appeared on The Last Watchdog.

View Details

Tel Aviv, Israel, June 9, 2025, CyberNewswire — Seraphic Security, a leader in enterprise browser security, today announced the launch of BrowserTotal, a unique and proprietary public service enabling enterprises to assess their browser security posture in real-time.

The launch coincides with the Gartner Security & Risk Management Summit 2025, where Seraphic will be showcasing the new platform with live demos at booth #1257.

Powered by AI, BrowserTotal offers CISOs and security teams a comprehensive, hands-on environment to test browser security defenses against today’s most sophisticated threats. Key features of the platform include:

•Posture analysis and real-time weakness detection

•Insights on emerging web-based threats and phishing risks

•A novel, state-of-the-art in-browser LLM that analyzes results and generates tailored recommendations

•A live, secure URL sandbox for safely testing suspicious links and downloads

•And more interactive tools that bring browser security front and center

Yeshua

“Web browsers have become one of the enterprise’s most exploited attack surfaces,” said Ilan Yeshua, CEO and co-founder of Seraphic Security. “With BrowserTotal, we’re giving security leaders a powerful, transparent way to visualize their organization’s browser’s security risks, and a clear path to remediation. What makes this truly groundbreaking is that we’re democratizing access to enterprise-grade security analysis. By making BrowserTotal freely available to the entire security community, we’re not just protecting individual organizations; we’re strengthening the collective defense against increasingly sophisticated web-based threats.”

Cohen

“We created BrowserTotal because we saw a critical gap in how organizations understand and prepare for browser-based attacks,” said Avihay Cohen, CTO and co-founder of Seraphic Security. “This isn’t just another security tool, it’s an educational platform that lets security teams experience firsthand how sophisticated these threats have become. My hope is that by making this technology freely available, we can elevate the entire community’s awareness and readiness against the next generation of web threats.”

Attendees of the Gartner Security & Risk Management Summit 2025 can experience BrowserTotal firsthand at booth #1257. The Seraphic team will be providing live demos, expert insights, and one-on-one consultations on closing the browser security gap. Users can book a demo time in advance here.

In Q1 of 2025, Seraphic Security announced a $29 million Series A fundraising led by GreatPoint Ventures with participation from the CrowdStrike Falcon Fund and existing investors Planven, Cota Capital, and Storm Ventures. To learn more about Seraphic Security and its patent browser security solution, users can click here.

About Seraphic Security: Seraphic is a leader in the rapidly growing Enterprise Browser Security market, driven by its patented technology that turns any browser into a secure browser with robust protection and detection capabilities. Seraphic delivers SWG, CASB, and ZTNA to simplify existing security architectures and significantly reduce SSE cost. Seamlessly and easily deployed, Seraphic also enables secure access to SaaS and private web applications to employees and third parties from managed and personal devices without the complexity and cost of VDI & VPN. Invisible to the end-user, Seraphic supports all browsers and SaaS desktop applications like Teams, Slack, Discord, and WhatsApp. For more information, users can visit https://seraphicsecurity.com.

Media Contact: Eric Wolkstein, Head of Content Marketing, Seraphic Security
ericw@seraphicsecurity.com

Editor’s note: This press release was provided by CyberNewswire as part of its press release syndication service. The views and claims expressed belong to the issuing organization.

The post News alert: Seraphic launches BrowserTotal™ — a free AI-powered tool to stress test browser security first appeared on The Last Watchdog.

View Details

Cyber threats to the U.S. electric grid are mounting. Attackers—from nation-state actors to ransomware gangs—are growing more creative and persistent in probing utility networks and operational technology systems that underpin modern life.

Related: The evolution of OT security

And yet, many utility companies remain trapped in a compliance-first model that often obscures real risks rather than addressing them.

That’s the problem Bastazo co-founder Philip Huff is calling out. As a longtime OT cybersecurity expert, Huff argues that current regulations—especially the North American Electric Reliability Corporation’s (NERC) patching requirement CIP-007-6 R2—create incentives.

In theory, NERC’s patching rules promote security. In practice, Huff says, they too often force asset owners to blindly chase updates with little regard for exploitability, threat intelligence, or operational risk.

This is what Huff calls “compliance theater.” The curtain may be rising on the next act.

With Bastazo, Huff and his team are advancing a bold alternative: risk-informed remediation. Their platform uses vulnerability intelligence, AI-assisted prioritization, and contextual awareness to help utilities focus on what matters most—actual exploitable risks—without taking unnecessary action that could disrupt critical operations.

This comes at a moment when utility cybersecurity is at a crossroads. There’s growing pressure from policymakers, regulators, and the public to improve defenses. At the same time, operators must balance security upgrades against aging infrastructure, limited budgets, and uptime requirements.

In this Q&A, Huff unpacks why it’s time to move beyond checkbox compliance and how Bastazo hopes to lead the charge.

LW: What convinced you the current NERC patching rules do more harm than good?

Huff: The NERC security patching standards were written in 2016 when annual vulnerabilities averaged around 6,000. Today, we face over 40,000 vulnerabilities annually. We also have resources like the Known Exploitable Vulnerabilities Catalog. As written, t existing rules incentivize blanket patching rather than intelligent, risk-based remediation, resulting in a wasteful use of resources that fails to prioritize actual security risks.

LW: How does Bastazo shift focus from compliance checklists to real risk reduction?

Huff

Huff: When patching everything, there is minimal thought given to security. It becomes more of an operational necessity. However, there are real supply chain risks to patching. You are trusting a large number of vendors to make changes to the code running critical systems. There should be more analysis on what the patch is doing and whether the patch was successful. When you’re patching thousands of vulnerabilities, that type of deep analysis is just not possible, but when you are patching only the handful that truly matter, you are improving both the security and reliability of your systems.

LW: What does “risk-informed remediation” look like in practice?

Huff: It balances the risk and work to stay within the bounds of what is both acceptable and feasible. The tools and metrics to measure risk are more readily available, but I don’t think we have enough spotlight on what the remediation work requires. Risk-informed remediation ensures you are fixing unacceptable risk to your organization, but it also ensures you have the resources to perform that work. If I create a work ticket to apply several hundred patches and I only have one or two people performing the work, then there’s a real problem.

LW: Why do most utilities still stick with the status quo?

Huff: Utilities currently face greater immediate risks from non-compliance penalties than from cybersecurity threats. Compliance is measurable, predictable, and financially enforced. While utilities recognize cybersecurity risks clearly, the cost and operational effort required to transition away from compliance-first toward more risk-informed approaches remain significant barriers.

LW: What’s the right way to bring AI and intel into OT patching—without adding new risks?

Huff: Incorporating AI requires clear verification and transparency. AI should initially handle tasks with low-risk impact, such as adversary identification, where occasional errors have minimal operational consequences. For high-stakes tasks like detailed remediation guidance, AI recommendations must be clearly outlined as advisory and supplemented by expert human oversight.

LW: What’s Bastazo’s edge? What are you offering that others aren’t?

Huff: While most OT cybersecurity solutions stop at asset inventory and vulnerability scoring, Bastazo bridges the gap to actionable remediation. Our edge is combining deep industry knowledge with advanced scientific knowledge to solve one of the hardest problems in OT security: what can asset owners realistically do to de-risk their infrastructure?

LW: What’s the origin story? How did the idea take shape?

Huff: Bastazo emerged from a Department of Energy Industry-University Collaborative Research Center (IUCRC), responding to the industry’s initial experiences with stringent NERC CIP patching requirements. There was not really any research on this problem because the world had never seen a “patch everything” regulatory standard. We have since been dedicated to solving this problem, and as AI innovation has accelerated, we have been able to pull in new approaches that really, for the first time, give defenders an upper-hand.

LW: Can your approach hold up under regulatory scrutiny—and what reforms are overdue?

Huff: The standard allows a mitigation plan to be developed when patching is not possible. This is not really a viable option because the amount of manually collected data required to justify not patching is almost impossible to obtain. Our approach lets you develop a mitigation plan,automating the data collection necessary for it. However, I think the standards are long overdue for reform. The requirements should focus on assessing risk and remediating vulnerabilities rather than enforcing patch compliance.

LW: What’s the risk if the industry doesn’t move past compliance theater?

Huff: I wouldn’t say it’s compliance theater because utilities have to address both the security and compliance risks. But the risk of the “patch everything” approach is that it distracts security and operations teams from the real threats. The work should be meaningful in addressing real risk, and that’s hard when over 90% of the work has no real impact on improving security.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post Shared Intel Q&A: Can risk-informed patching finally align OT security with real-world threats? first appeared on The Last Watchdog.

View Details

The day after my column dissecting Chris Sacca’s viral outburst went live—his now-notorious claim that we are “super fked” by artificial intelligence—I stumbled onto another AI conversation that had already amassed over 10 million views: a roundtable debate hosted by Steven Bartlett on his widely watched YouTube show, Diary of a CEO.

Related: Ordinary folks leveraging AI

What I encountered wasn’t a retread of the usual hype cycle. It was a visceral clash of worldviews. On one side sat Amjad Masad, founder and CEO of Replit, and Daniel Priestley, a serial entrepreneur and author. On the other, evolutionary theorist Bret Weinstein. Between them: Bartlett, a skilled provocateur and moderator, subtly steering the debate toward maximum tension.

The result? A two hour-long intellectual melee. No consensus. No resolution. Just deep philosophical fissures laid bare—and, I’ll admit, a compelling display of rhetorical firepower.

Yet what struck me most was not who “won,” but what was missing.

Three lanes, one collision

The debate centered around a shared premise: that agentic AI—the kind capable of initiating actions, adapting to environments, and learning autonomously—is real, fast-moving, and deeply disruptive. All three guests, to varying degrees, agreed on that much.

Where they diverged was in tone, framing, and underlying beliefs:

•Amjad Masad framed AI as a profoundly liberating force. He sees a world where coding is no longer a gate-kept skill. With AI copilots, anyone can build. I’ve shown this in my own reporting, chronicling how how non-technical individuals are already harnessing AI to solve complex, high-stakes problems on their own terms. For Masad, AI is capital. And capital in the hands of ordinary people means economic revolution.

•Daniel Priestley amplified this optimism. His mantra: adapt or perish. AI is not just a productivity booster, it’s a “cognitive workforce” that will reward the bold. For Priestley, the transformation is Darwinian. Those who embrace the shift will thrive. Those who hesitate will fade.

•Bret Weinstein slammed on the brakes. Hard. An evolutionary biologist by training, Weinstein argued that AI agents are not tools. They are complex adaptive systems—like ecosystems or market economies—that evolve in ways their creators can neither predict nor control. His warnings were stark: runaway complexity, loss of oversight, systemic collapse.

Steven Bartlett, to his credit, let the fissures breathe. He asked good questions. He made room for discomfort. And he didn’t force synthesis.

But while the panel was diverse in ideology, it was also incomplete.

What they didn’t say

Watching the episode, I kept waiting for someone to say what I’ve seen firsthand over the past 18 months: that agency isn’t theoretical. It’s already being reclaimed.

I’ve interviewed cybersecurity engineers using AI to spot anomalies in real time. I’ve profiled caregivers using AI to help a child speak, or to untangle healthcare red tape. I’ve witnessed my own daughter-in-law wield ChatGPT to uncover obscure Greek ancestry records, ultimately securing a second citizenship.

These aren’t anecdotes. They’re signals.

Signals that the future isn’t being built only by venture-backed founders or academic theorists. It’s being shaped—quietly, imperfectly, persistently—by people far outside the AI echo chamber.

To Masad’s credit, he hinted at this. He spoke passionately about unexpected creators. About how, on Replit, kids with no formal training are coding apps and bots that scale globally.

This, to me, is the crux.

The panelists sparred over whether AI would empower or destroy us. But the more pressing question isn’t what AI will do. It’s what we will do with it.

Polarity vs. humility

Bartlett’s debate went viral for good reason: it dramatized the stakes. Techno-optimism versus existential dread. Acceleration versus caution. Masad and Priestley versus Weinstein.

But my recent column reached a smaller audience. It offered no fireworks. No doom-laced soundbites. Just a textured narrative of how real people—from tenants to musicians to terminally ill patients—are already using AI to reclaim voice, power, and clarity.

That contrast itself tells a story.

We are in a moment where extremity gets amplified. What travels is not nuance, but polarity.

And yet, it’s nuance that holds the key. Nuance, and intention.

Agency is not a punchline

Weinstein is not wrong to worry. Complex systems can spiral. Ecosystems can collapse. AI can be deployed—has already been deployed—in ways that reinforce inequality, enable surveillance, and erode trust.

But to assume that these systems are self-directing, that human judgment is already obsolete—that’s not realism. That’s surrender.

Priestley’s call to action—”adapt or perish”—has some truth. But it risks commodifying agency. Reducing this moment to a hustle, a race, a game of who can leverage AI fastest.

I’m not buying either extreme.

What I’m seeing, again and again, is something quieter. Something slower. Something more real.

Agency is being rebuilt, not just in Silicon Valley garages, but in public libraries. In classrooms. In elder care facilities. In homes.

AI isn’t replacing human decision-making. It’s scaffolding it. When deployed wisely, it doesn’t erase judgment—it sharpens it.

What comes next

There’s value in debates like the one Bartlett hosted. They surface tensions. They reveal fault lines. They keep us alert.

But we also need storytelling. We need pattern recognition. We need narrative journalism that doesn’t default to hype or despair.

That’s why I wrote my last column. That’s why I’m writing this one.

If we assume we’re powerless, we are. If we engage, even clumsily, we aren’t.

It’s true that AI is evolving faster than most institutions can respond. But that doesn’t mean we’ve lost control. It means we’re being tested.

Tested to govern wisely. To teach differently. To work more humanely. To design defaults that protect the vulnerable.

The tools are here. The stakes are clear. The timeline is tight.

But the outcome? That’s still in our hands. I’ll keep watch and keep reporting.

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

(Editor’s note: A machine assisted in creating this content. I used ChatGPT-4o to accelerate research, to scale correlations, to distill complex observations and to tighten structure, grammar, and syntax. The analysis and conclusions are entirely my own—drawn from lived experience and editorial judgment honed over decades of investigative reporting.)

The post MY TAKE: Are we ‘Super f**cked’ by AI? — debate gets 10 million-plus views on YouTube first appeared on The Last Watchdog.

View Details

Boston, MA, Jun. 4, 2025, – The Healey-Driscoll administration and Massachusetts Technology Collaborative’s (MassTech) MassCyberCenter awarded $198,542 to four Massachusetts-based programs focused on preparing professionals for the cybersecurity workforce.

MassTech provided the funds through the Alternative Cyber Career Education (ACE) Grant Program, a statewide effort to support young adults and retrain existing professionals with alternative options to traditional cybersecurity degree programs.

The awards will support training for more than 200 professionals across Massachusetts, ultimately increasing cyber employment statewide. Participating grantees will provide hands-on learning, like on-the-job training, to give participants the real-world experience required to obtain cybersecurity employment.

Stolba

“Massachusetts is building a strong talent pipeline of cybersecurity professionals to protect businesses, local governments and residents against threats in the digital world,” said Massachusetts Interim Economic Development Secretary Ashley Stolba. “Our administration is dedicated to expanding opportunities beyond traditional degree programs to help create a highly skilled and dynamic cybersecurity sector statewide and ensure our state is economically viable and innovative for decades to come.”

Petrozzelli

“The ACE Program supports certification and training outside of traditional pathways, which have too often excluded people with the potential to contribute to the cybersecurity workforce,” said MassCyberCenter Director John Petrozzelli. “Cybersecurity can be technical, but it’s also a broad field that demands skills like problem solving and strategic thinking. The ACE Program is reaching people with those strengths and unlocking a pool of untapped potential across Massachusetts.”

The MassCyberCenter is providing the four ACE program awards to the following organizations: Burlington High School ($49,650), ISACA ($50,000), Per Scholas Greater Boston ($50,000) and Westfield Technical Academy ($48,892). Below is a further description of each award.

•Burlington High School (Burlington) – $49,650 to expand the cybersecurity component of its career-related experiential learning program for its students. The program is a capstone career experience guided by industry mentors, called the Flipped Internship. The grant will increase the number of students participating in the Flipped Internship career experience in cybersecurity to approximately 50 students and provide resources for students to receive industry credentials.

“Burlington is dedicated to preparing high school students for in-demand careers,” said Burlington Public Schools Superintendent Eric Conti. “Our district recognizes the importance of partnering with industry and offering career-focused opportunities that help students earn credentials and build career readiness skills.”

•ISACA (Based in Illinois with the learners supported by this grant located across Suffolk County) – $50,000 to expand its Digital Trust Workforce Inclusion Program to Massachusetts. This program will provide 25 learners from underrepresented backgrounds with ISACA’s industry-recognized Cybersecurity Fundamentals certificate training, job readiness training and assistance with job placement.

Kanouse

“ISACA is dedicated to developing cybersecurity pathways that are more accessible for all,” said ISACA Chief Membership and Marketing Officer Julia Kanouse. “Grant programs like this have life-changing impacts, and we are so grateful to the Healey-Driscoll administration and MassCyberCenter for partnering with us to transform careers through ISACA’s Digital Trust Workforce Inclusion Program.”

•Per Scholas Greater Boston (Cambridge) – $50,000 to expand its cybersecurity training program to enroll and train 90 Massachusetts residents, which represents an increase of 10 additional learners over FY25 levels (a 12.5 percent increase). Grant funds will also support approximately 65 of these 90 total learners in obtaining a cybersecurity industry certification.

Howard

“This support from the MassCyberCenter is instrumental in helping us expand access to cybersecurity careers for Greater Boston residents,” said Per Scholas Greater Boston Managing Director H. Kay Howard. “Per Scholas has a proven track record of driving economic mobility by preparing talent for high-demand tech roles. With this funding, we will build on that impact by training even more individuals and equipping them with the skills, industry certifications and hands-on experience they need to launch meaningful tech careers.”

•Westfield Technical Academy (Westfield) – $48,892 to run a U.S. Air Force cybersecurity summer camp, providing cybersecurity industry certifications to 65 students in its IT Program and supporting cybersecurity co-op placements for certified students.

“The ACE program, sponsored by the MassCyberCenter, is an incredible opportunity for students to gain the necessary skills and knowledge in the ever-evolving cybersecurity field,” said Westfield Technical Academy Career Technical Education Director Taloumis. “The industry-recognized credentialing provides students with a competitive edge as they advance into the workforce or post-secondary education.”

About the MassCyberCenter: The MassCyberCenterpromotes the Massachusetts cybersecurity ecosystem by working to build a strong cyber talent pipeline and to strengthen the defense of local communities. The MassCyberCenter works with cities, towns, universities and the private sector to build cyber awareness, institute best practices, grow future workforce talent, and create a more powerful cyber defense force to guard against future threats. Learn more at https://masscybercenter.org/.

Media Contact: Jake Stern, Public Relations Manager, 781-801-8845, stern@masstech.org

The post News alert: $198K in Grants Awarded to Boost Cybersecurity Workforce in Massachusetts first appeared on The Last Watchdog.

View Details

The compliance variable has come into play in an impactful way.

Related: Technology and justice systems

The U.S. Security and Exchange Commission (SEC) recently laid down the hammer charging and fining four prominent cybersecurity vendors for making misleading claims in connection with the SolarWinds hack.

SEC investigators gathered evidence that Unisys Corp., Avaya Holdings, Check Point Software Technologies, and Mimecast Limited each minimized or obscured the extent of security breaches linked to the SolarWinds Orion hack, impacting investor trust and highlighting the critical importance of clear, truthful communication.

Unisys, for instance, was found to have framed cyber risks hypothetically even though its systems had already been breached, exfiltrating gigabytes of data. Avaya, Check Point, and Mimecast also downplayed the impact, contributing to the SEC’s decision to impose hefty civil penalties.

As organizations continue facing escalating cyber threats, how they communicate multiplying and rapidly morphing cyber exposures – in essence how much they choose to abide by industry standards and embrace ethical practices — remains under intense scrutiny.

With this in mind, Last Watchdog sought commentary from technology thought leaders about what this milestone enforcement action by the SEC portends, going forward. Responses edited for clarity and length:

Ambuj Kumar, CEO, Simbian

Kumar

While the SEC has fined the corporations, CISOs are worried that they may be held individually responsible and feel targeted by both attackers and now law enforcement. There should not be any subjectivity on what makes an incident go beyond the threshold of disclosure.

A security incident is often an indication of poor investment in security programs, rather than personal characeteriziation of the security leader. So, we should allow leaders to speak more publicly and ask for more security resources.

Joe Nicastro, Field CTO, Legit Security

Nicastro

Transparency in cybersecurity remains a complex balancing act. In a world of interconnected services, GenAI-driven tools, and continuously new and novel emerging threats, full disclosure is not always practical or even possible. But the SEC’s latest actions underscore that failing to inform stakeholders about material risks and breaches is not an option. Moving forward, companies that establish strong disclosure processes will be better positioned to maintain trust and manage regulatory scrutiny effectively.

Willy Leichter, CMO at AppSOC

Leichter

None of these companies would have stood out if they had come clean about being breached. But the corporate inclination towards minimizing, spinning, or outright lying about an embarrassing incident was too strong for these companies to resist.

The self-inflicted reputational damage now is far worse than it would have been had they been forthright at the outset. Timely, detailed, and accurate communication after a breach is both legally required and the best damage-control strategy.

Stuart McClure, CEO, Qwiet AI

McClure

The SEC’s goal appears to be to hold these companies accountable to investors for any successful cyberattacks and expose the company’s lack of preparation and prevention.

We hope that transparency goals are achieved but these tactics may have the opposite effect given the fine sizes. $1 million for a company the size of Checkpoint is but a slap on the wrist. This action may drive reporting deeper underground. Only time will tell.

Steven Worth, Acting COO, Token

Worth

I’d like to see the industry help regulators and standards setters develop more uniform and consistent recommendations that would become true best practices. This could dovetail with a national information privacy law.

We have the benefit of learning from GDPR in Europe as well as other flavors of privacy laws in Canada, Utah, Virginia and other jurisdictions. The last thing we need is a patchwork of 50 different laws across the States. There should be a common-sense approach that can make it through the federal legislative process.

Jonathan Gill, CEO, Panaseer

Gill

Security professionals have a sword of Damocles over their heads. They’re being asked to provide more accuracy and assurances when reporting. Despite having an army of tools, they have huge visibility gaps over increasingly complex IT environments.

Addressing this root cause must be a priority. Accountability and responsibility in cybersecurity are positives, but they must be a collective effort, where everyone in an organization knows their role.

Joe Evangelisto, CISO, NetSPI

Evangelisto

I expect these charges to ripple across boardrooms, forcing corporations to have more in-depth conversations on cybersecurity risks and controls. The big question for corporations is the level of transparency they are comfortable with.

Corporations should take steps today to adopt transparency as a core tenant. Implementing this core tenant as part of a cybersecurity program will in turn further mitigate cybersecurity risks, increase security controls, and allow for greater customer trust.

Daniel Lakier, Field CSO, Myriad360

Lakier

Cyber professionals represent the companies they work for and are meant to protect them. Companies have a fiduciary responsibility to protect their investors, employees and the public. However, investor and employee interests may not always align with public interest.

Given that public trust is at a low point, the SEC’s action is timely and needed, even if the precedent makes me feel uncomfortable. The temptation to ‘spin,’ or potentially even outright lie, remains too high.

Richard Bird, CSO, Traceable

Bird

These penalties are hollow.The SEC fixates on time-to-report metrics and vague “materiality” without defining it. This ambiguity has led to a deluge of 8-K filings from companies hedging with, “We’re unsure if this is material, but here’s our report.” Over a decade, the SEC’s enforcement has not improved cybersecurity outcomes but has burdened firms with compliance. Faster breach notifications are like police arriving weeks late to announce you were robbed—ineffective and disconnected from real security improvement.

Dane Grace, Technical Solutions Manager, Brinqa

Grace

I’m generally for radical transparency. Fines are great and all, but until we see executives going to prison, these things are still going to figure into a cost-benefit analysis.

With hyper-interconnected services on the rise and GenAI starting to disrupt things, companies ought to disclose information about all affected parties as early as possible and follow up with findings — up until the conclusion of the incident response investigation.

Antonio Vasconcelos, Customer Engineer, Zero Networks

Vasconcelos

The points raised by SEC in this investigation revealed troublesome practices. For example, reporting overly generic incidents, after disclosing a breach in one’s network, and even “material omission” of vital details.

There is only one path forward: transparency. The more transparent and the more collaborative we are collectively, the more effective we can be in fighting cyber threats, especially those like the supply chain attack on SolarWinds Orion, given how large its scale and impact was.

David Redekop, CEO, ADAMnetworks

Redekop

As threats evolve, the lines between transparency and caution will need to be continuously reassessed, with a balance that serves both corporate and customer interests. In some jurisdictions, this line is most-effectively drawn by a government-appointed privacy commissioner who is required to remain neutral and yet ultimately serves the citizens of its country.

Ultimately, organizations should strive for a disclosure approach in layers —sharing enough information to maintain transparency and trust while protecting critical details that could be exploited.

Ted Miracco, CEO, Approov

Miracco

These penalties may not result in a cultural shift, but some organizations will begin by prioritizing cybersecurity as a critical component of corporate governance. Other companies may continue to rely on hiding the ball, scapegoating and relying on insurance to cover the losses.

Companies can navigate the challenges of interconnected services while maintaining security and stakeholder confidence. The key is to disclose information that helps stakeholders understand the company’s cybersecurity risk management without revealing sensitive operational details.

Scott Kannry, CEO, Axio

Kannry

The SEC is serious about companies disclosing the details of an event if it is relevant to investors. This type of thinking really boils down to the impact: Will an investor’s returns be affected by this?

Moving forward, companies can comply with this by shifting more of their risk management practices to include this concept of impact. Want to stay out of trouble? Create a plan, assess the impacts, and disclose the relevant facts honestly.”

Jim Routh, Chief Trust Officer, Saviynt

Routh

These events represent a clear shift in the regulatory landscape. The message to the industry is they must improve the accuracy of the information shared with the SEC specific to security incidents and the enterprise impact.

This enforcement has already had an impact on the sensitivity of CISOs managing their individual obligations. Some have moved away from the CISO role. Other CISOs are changing how they negotiate indemnification coverage before accepting a new position.

Stephen Kowski, Field CTO, SlashNext Email Security+

Kowski

These fines, while modest for large enterprises, send a clear signal that regulators expect precise, timely, and truthful cybersecurity disclosures – especially when public trust and investor interests are at stake.

As threats become more sophisticated, companies need advanced security solutions that enable them to make informed decisions about what to disclose and when. This balance between security and transparency will become increasingly crucial as organizations face more complex cyber threats and stricter regulatory oversight.

Andrew Harding, VP of Security Strategy, Menlo Security

Cyber defense providers need to help prevent breaches and reduce the impact of security events so that incidents are less frequent and have a smaller blast radius. The increasing sophistication of cyberattacks make this harder every day.

More guidance and increased regulatory scrutiny from trusted agencies make sense in such an environment. Such guidance, inspection, and consequences will drive the right solutions and encourage high-integrity operations during a time of rapid change in available technology and the threat environment.

Jeff Margolies, Chief Strategy Officer, Saviynt:

Margolies

We are still too focused on victim blaming companies that are breached. A far more effective approach would be to help companies that are clearly out-gunned by the adversary.

Set clear standards on what is required by the private sector, and what the government will do to assist with cybersecurity. Bottom line, until government regulators stop blaming companies, they need to be very cautious in disclosures.

Stephen Gates, Security SME, Horizon3.ai

Gates

Due care and due diligence are the CISO’s lifelines. Documenting your actions, constantly assessing the organization’s risks, and proving your teams’ risk reduction efforts have been effective provides the evidence of a proactive, diligent approach that’s defensible under scrutiny.

If companies hired CISOs and/or security leaders who walked this walk, there would never be any reason whatsoever to mislead anyone. Simply put, there would be nothing to hide.

Keith McCammon, CTO of Red Canary

McCammon

One of the best things companies can do to prepare is to clearly define a material cybersecurity incident in the context of their business, where a key component of both the criteria and response plan is the identification of key stakeholders.

We are starting to see more and clearer signals that the U.S. government at-large—via the National Cybersecurity Strategy, CISA, and other agencies—will continue to push for legislation and enforcement as it relates to cybersecurity preparedness, compliance, and reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post LW ROUNDTABLE: Wrist slap or cultural shift? SEC fines cyber firms for disclosure violations first appeared on The Last Watchdog.

View Details

Augmented reality use cases have become prevalent in our society.

The technology, which first emerged primarily in the world of gaming and entertainment, now promises to reshape our reality with interactive information and immersive experiences. In short, AR is undoubtedly a groundbreaking technology that will reinvent how we interact with the digital world.

Related: Is the Metaverse truly secure?

However, before we get too carried away, it is crucial to explore the symbiotic relationship between AR and cybersecurity.

This is primarily because AR is still relatively new and a rapidly evolving technology, which ultimately means that it is bound to bring about unprecedented opportunities, challenges, and even risks to cybersecurity.

Are there any applications of augmented reality in cybersecurity?

While exploring the impact of every new form of technology on cybersecurity, there comes the unpleasant thought of looming cyberthreats. There is no doubt that AR will bring a new wave of sophisticated cyberattacks that may transform the dynamics of the cybersecurity world. However, looking at the brighter side, the immersive nature of this technology can also make it applicable in various cybersecurity domains.

Quite like how pilots use AR simulation in training, cybersecurity professionals can use AR-enabled training simulations that immerse them in hyper-realistic scenarios, offering hands-on cyber defense training and education. For example, AR-based training programs can simulate a phishing attack, allowing users to learn detection methods and experience the process of neutralizing the threat. It could also help users identify various cybersecurity attacks, whether they are types of spoofing, phishing, social engineering, or malware.

Waqas

Apart from the training aspect, AR technology can also be used to enhance threat detection in real-time. Since threat detection often requires analyzing complex, multi-layered patterns, AR can help SOC professionals and cybersecurity analysts interact with this data visually, making it easier to identify anomalies and weak points in security protocols. With AR interfaces, alerts for potential threats could be flagged and displayed on-screen as layered icons, instantly allowing personnel to assess risks and prioritize responses.

Possible challenges

Integrating AR in cybersecurity may come with several benefits, but it is not without its own set of challenges. Foremost among these are privacy and security concerns. Since AR programs rely on collecting and processing a significant amount of data, using them in cybersecurity training would mean exposing them to sensitive information. Most of the data fed to AR modules could include images of secure environments, system layouts, and other confidential information. Therefore, unauthorized access to cybersecurity-centric AR technology could lead to serious security breaches.

Apart from the security and privacy concerns, another main challenge is the implementation cost. There is no doubt that AR technology, especially AR glasses and other custom-built training application systems or modules, can be expensive. For an organization planning to integrate AR into its cybersecurity infrastructure, it is necessary to consider the cost of integrating AR with existing infrastructure and whether the benefits justify the investment.

Are there any security risks involved?

Although the use of AR technology in cybersecurity might seem promising, there is a high chance that these technologies could become a funnel for live cyberattacks. One significant risk is the potential for the technology to become a host to sophisticated social engineering attacks.

Additionally, there is a possibility that cybercriminals might misuse AR technology to create convincing deepfakes, duping gullible victims into revealing sensitive information.

Privacy risks

Another major area of concern is that AR devices collect vast amounts of data when in use, specifically tracking, GPS, and mapping information. Malicious actors could gain unauthorized access to this information and track an individual without their knowledge.

Furthermore, the advent of AR can also lead to digital vandalism. To overlay digital objects in the real world, AR technology must process live images through a device. Without proper protocols in place, criminals could hijack these overlays to digitally prank or vandalize a user’s space, potentially causing mental distress or even physical incidents.

Is using AR in cybersecurity worth it? – A summary

The future of AR technology in cybersecurity looks promising, particularly as the technology becomes more affordable, advanced, and accessible. The convergence of AR with cybersecurity could further enhance its impact, providing proactive threat detection with predictive capabilities for identifying potential attack vectors before they occur.

AR in cybersecurity is still an emerging field, yet it holds tremendous promise for redefining how organizations approach threat management, incident response, and training. As AR technology continues to evolve, its role in cybersecurity will likely expand, equipping professionals with powerful tools to address the dynamic challenges of digital security. However, for the technology to reach its true potential, it is crucial for developers to address the security risks associated with it and to mitigate them as much as possible.

About the essayist: Iam Waqas is a cybersecurity blogger and the Founder of DontSpoof, a dedicated project focused on cybersecurity awareness and phishing prevention.

The post GUEST ESSAY: The promise and pitfalls of using augmented reality– ‘AR’ — in cybersecurity first appeared on The Last Watchdog.

View Details

Tel Aviv, Israel, Nov. 11, 2024, CyberNewswire — Sweet Security today announced the availability of its cloud-native detection and response platform on the Amazon Web Services (AWS) marketplace.

Sweet’s solution unifies threat detection across cloud infrastructure, network, workloads, and applications. It provides deep runtime context that enables security teams to quickly extract actual attack narratives from a sea of isolated incidents.

Using Sweet, AWS Marketplace customers can detect active threats in real time and respond to them within minutes, enabling them to resolve threats with unprecedented speed – 2-5 minute MTTR – and maintain an agile and resilient environment.

AWS customers visiting AWS re:Invent 2024 in Las Vegas can book a meeting to learn more here.

Fisher

“Cloud environments are noisy and complex, making them fertile grounds for attackers — deterring them requires detection and response capabilities that, to date, have been aspirational, but we’ve made them table stakes,” said Eyal Fisher, Co-Founder and Chief Product Officer of Sweet Security and former head of the Cyber Operation Center, Unit 8200 (Col., retired). “We’re delighted that our solution is now available to AWS Marketplace customers and look forward to helping them simplify the burden of cloud security and do their jobs faster and better.”

What Makes Sweet so Sweet?

Sweet Security offers detection and response for cloud native environments. Its approach is unique in how it unifies detection across cloud infrastructure, network, workloads, and applications, providing deep runtime context that cuts through the noise and delivers actual attack narratives.

Key Features include:

•Advanced threat detection and incident response (IR) across infrastructure, network, application, and workload levels.

•Vulnerability management enriched with runtime insights, reducing CVEs by 99% and putting only the critical risks in front of security personnel.

•Lean sensor technology that requires minimal resources (50 MB RAM, 0.20% CPU per node) and take only minutes to deploy

•30+ out-of-the-box integrations with SIEM, SOAR, notification and ticketing systems, and mor

Sweet empowers security teams to achieve a Mean Time to Detect of 30 seconds (MTTD) and a 2-5 minute Mean Time to Resolve (MTTR), transforming cloud security into a more proactive and effective discipline.

For more information, users can visit Sweet Security on the AWS Marketplace.

About Sweet Security: Specializing in Cloud Native Detection & Response (D&R), Sweet Security protects cloud environments in real time. Founded by the IDF’s former CISO, Sweet’s solution focuses on the relationships between cloud infrastructure, workloads and applications , as well as network, and identity components. Leveraging a lean, eBPF-based sensor and deep behavioral analysis, Sweet analyzes anomalies, generating vital insights on incidents, vulnerabilities, and non-human identities. Its GenAI-infused technology cuts through the noise and delivers actionable recommendations on critical, real-time cloud risks. Privately funded, Sweet is backed by Evolution Equity Partners, Munich Re Ventures, Glilot Capital Partners, CyberArk Ventures and an elite group of angel investors. For more information, please visit http://sweet.security.

Media contact: Chloe Amante, Account Director, Montner Tech PR, camante@montner.com

The post News alert: Sweet Security rolls out its advanced runtime detection and response platform for AWS first appeared on The Last Watchdog.

View Details

The Internet of Things is growing apace.

Related: The Top 12 IoT protocols

Deployment of 5G and AI-enhanced IoT systems is accelerating. This, in turn, is driving up the number of IoT-connected devices in our homes, cities, transportation systems and critical infrastructure.

One estimate suggests IoT-connected devices are multiplying at a 12 percent compound annual growth rate. By 2030, according to IoT Analytics, we will be relying on some 41 billion IoT devices worldwide, up from 17 billion at the close of 2023.

Largely out of the public eye, a lot of work is going on to assure security of this rapidly expanding, massively interconnected digital ecosystem. I had the chance to discuss this at length with Thomas Rosteck, Division President of Connected Secure Systems (CSS) at Infineon Technologies.

We met at Infineon’s OktoberTech™ Silicon Valley 2024 conference, which I had the privilege of attending recently at the Computer History Museum. For a drill down on our conversation, please view the accompanying videocast. My big takeaways:

Innovation and standards

Ensuring that hyper-connected IoT devices are not only smarter and faster but also resilient against cyber threats is a very tall order. It requires technical innovation to mesh with supporting security standards and emerging government regulations much quicker and smoother than has ever happened in the Internet era.

This, indeed, is what’s happening. Infineon, for instance, is known for supplying secured, energy-efficient semiconductors and microcontrollers which are critical for IoT security. The Munich, Germany-based company has stepped forward to take a leading role in making security breakthroughs at the hardware level, notably at the IoT device level.

The idea is to help establish a trusted foundation at the outermost edges of modern IoT systems — by safeguarding device integrity inside each IoT sensor and IoT controller. “Security is like baking a cake,” Rosteck explains. “Once baked, you can’t add the flavor. Likewise, security must be embedded in each IoT device from the start.”

Microcontrollers have emerged as a main ingredient for securing IoT services. These compact, integrated computer chips are designed to control specific tasks in electronic devices. Infineon has been pushing the boundaries of what microcontrollers can do, especially when it comes to making them much more capable and secured in IoT applications.

The rapid advancement of semiconductor miniaturization and edge computing capabilities over the past five years has been a key development, enabling much more complex processing to be carried out on ever smaller chips. Wider availability of high-speed wireless networks, like 5G, and the continuing shift to robust cloud computing services, has helped, as well.

Miniature brains

Today microcontrollers act as the “brains” behind smart devices, enabling high connectivity and efficient power management for everything from sensors to complex systems. They play a crucial role in making IoT devices smarter, more secure, and capable of seamless communication in connected ecosystems, Rosteck noted.

It struck me that what Infineon is doing is akin to distributing miniature digital brains at the outermost edges of IoT systems. These tiny brains are optimized to handle specific, high-stakes tasks efficiently and reliably.

Much as the human brain processes information and makes decisions, Infineon’s microcontrollers are designed to autonomously manage essential functions—whether controlling precise equipment in a factory, monitoring patient vitals in a hospital, or managing energy flow in a utility grid.

We’re in an early phase of relying on individual chips to perform complex, real-time processing and execute reliable, autonomous decisions at the Internet edge — without relying on central servers. IoT systems of the near future hold great promise to help us achieve great things, such as reverse the effects of climate change and even promote an improved standard of living, for one and all.

Rosteck

One requirement is tantamount: “You have to have something in the system that you can absolutely trust; we call it a security anchor,” Rosteck observes. “And from there you can build up your trust system. That’s important because in the end, the success of IoT is also largely dependent on whether people trust their devices.”

Towards this end, Infineon microcontrollers are optimized to prevent unauthorized access and preserve data integrity in everything from cars to smart home devices. Infineon has integrated a Hardware Security Module (HSM) directly into their microcontrollers to take security up a notch, especially in critical IoT applications like automotive systems.

This HSM acts as a dedicated security engine within the microcontroller, performing essential checks during the device’s initial boot-up. For example, in a drive-by-wire steering system, where steering is controlled electronically rather than mechanically, the HSM ensures only verified and trusted code runs from the start. It also validates the integrity of the firmware and checks for any unauthorized modifications.

Compliance nudge

Infineon’s innovations come as regulatory bodies are making a push for stricter data security compliance rules. The European Union’s Cyber Resilience Act, introduced this year, requires connected devices sold in Europe to meet a set of cybersecurity benchmarks as part of the familiar CE mark, which assures general safety of electronic products.

Meanwhile, the U.S. Cyber Trust Mark will serve as a “certification” for secure consumer IoT devices. Rosteck noted that these new compliance requirements should act as a global catalyst for consistent device security.

The Biden-Harris administration’s U.S. Cyber Trust Mark is a labeling initiative specifically aimed at raising security standards for (consumer) IoT devices. Developed by the National Institute of Standards and Technology (NIST), the program establishes baseline security requirements for IoT manufacturers, encouraging them to implement stronger protections, such as secure software updates and data encryption.

The label came about in acknowledgement of the massive expansion of IT security risks that accompany growing reliance on hyper-interconnected digital systems. It seeks to incentivize industry accountability and empower consumers with transparent information about IoT device security.

Meanwhile, the EU’s Cyber Resiliency Act (CRA) is aimed at strengthening cybersecurity for digital products and software all across Europe. The CRA mandates that companies comply with specific security requirements throughout the product lifecycle, from design to end-of-life. It requires manufacturers to address vulnerabilities, provide security updates, and notify users of incidents promptly.

The EU responded forcefully to a surge in cyber threats targeting software and connected devices, which pose risks to individuals, businesses, and critical infrastructure. By setting binding requirements, the CRA aims to protect users, foster trust in digital products, and promote a secure digital economy in Europe. “The EU’s decision to enforce security requirements through the CE mark is powerful because it extends to non-European manufacturers who want access to the market,” Rosteck noted.

Pressure to advance IoT security is coming from other quarters, to be sure. The rise of quantum computing, for instance, with its capacity to undermine existing encryption algorithms, poses a particular risk to connected systems. Infineon is among the companies preparing for this future by developing “post-quantum” encryption to replace today’s vulnerable asymmetric algorithms.

Additionally, the commercial sector’s mad dash to monetize GenAI has touched off an all too familiar cycle of companies racing to innovate, for competitive reasons, without fully accounting for fresh cyber exposures. Yet this time around, Rosteck says he, for one, is encouraged by how the tech industry’s standards-making bodies, made up of conscientious IT pros, have been hustling to stay in step with regulators.

Taking a proactive stance on IoT security has become de rigueur. “Security used to feel like an uphill battle,” he admits, “but now the world is pushing in the same direction.”

The securing of our increasingly hyper-connected digital world is unfolding in real time. Proactivity is gaining steam. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the ven

The post MY TAKE: Technology breakthroughs, emerging standards are coalescing to assure IoT integrity first appeared on The Last Watchdog.

View Details

Foreign adversaries proactively interfering in U.S. presidential elections is nothing new.

Related: Targeting falsehoods at US minorities, US veterans

It’s well-documented how Russian intelligence operatives proactively meddled with the U.S. presidential election in 2016 and technologists and regulators have been monitoring and developing measures to address election meddling by foreign adversaries, which now happens routinely.

They’re at it again. Russian actors “manufactured and amplified” a recent viral video that falsely showed a person tearing up ballots in Pennsylvania, the FBI and two other federal agencies recently disclosed. The FBI and officials from the Office of the Director of National Intelligence and the Cybersecurity and Infrastructure Security Agency said the U.S. intelligence community made the assessment based on available information and past activities from other Russian influence actors, including videos and disinformation efforts.

Now comes fresh evidence highlighting the nuances of social-media fueled disinformation of this moment — leading up to the imminent 2024 U.S. presidential election.

Analysts at Los Angeles-based Resecurity have been monitoring a rising wave of troll factories, fake accounts and strategic disinformation clearly aimed at swaying public opinion. This time around the overall thrust is not so much to champion Donald Trump or smear Kamala Harris, as it is to generally and deeply erode trust in time-honored democratic elections, says Shawn Loveland, Resecurity’s Chief Operating Officer (COO).

Towards this end, faked social media accounts impersonating both Trump and Harris, as well as prominent U.S. institutions, have been springing up and spilling forth outrageous falsehoods, especially via the Telegram anonymous messaging platform.

Telegram, it turns out, is a social media venue favored by disinformation spreaders. This popular cloud-based messaging app is known for its security features, flexibility and use across global audiences. Telegram’s minimal moderation makes it a haven for privacy-conscious users but also a perfect tool for spreading lies and conspiracy theories.

Last Watchdog engaged Loveland to drill down on what Resecurity’s analysts have been closely tracking. He recounted their observations about how now, more so than ever, social media apps have come to serve as “echo chambers.” This refers to how easily patrons become isolated within bubbles of half-truths and conspiracy theories that reinforce their biases.

Foreign adversaries are well aware of how echo chambers can be leveraged to manipulate large groups. They’ve seized upon this phenomenon to strategically sway public sentiment in support of their geopolitical gains. Disinformation spread through social media has been part and parcel of election interference all around the globe, not just in the U.S., for more quite some time now.

Election interference has become impactful enough, Loveland told me, to warrant stricter regulatory guard rails and wider use of advanced detection and deterrence technologies. Greater public awareness would help, of course. Here’s the gist of our exchange about all of this, edited for clarity and length.

LW: Can you frame how the social media ‘echo chamber’ phenomenon evolved?

Loveland: With the decline of traditional media consumption, many voters turn to social media for news and election updates. This shift drives more people to create accounts, particularly as they seek to engage with political content and discussions relevant to the elections.

Loveland

Foreign adversaries exploit this aspect, running influence campaigns to manipulate public opinion. To do that, they leverage accounts with monikers reflecting election sentiments and the names of political opponents to mislead voters. Such activity has been identified not only in social media networks with headquarters in the US, but also in foreign jurisdictions and alternative digital media channels.

The actors may operate in less moderated environments, leveraging foreign social media and resources, which are also read by a domestic audience, and the content from which could be easily distributed via mobile and email.

LW: Can you characterize why this is intensifying?

Loveland: Social media can create echo chambers where users are exposed primarily to information that reinforces their existing beliefs. This phenomenon can polarize public opinion, as individuals become less likely to encounter opposing viewpoints.

Such environments can intensify partisan divides and influence voter behavior by solidifying and reinforcing biases. For example, we identified several associated groups promoting the “echo” narrative – regardless of the group’s main profile. For example, a group that aims to support the Democratic Party contained content of an opposite and discrediting nature.

LW: Can you drill down a bit on recent iterations?

Loveland: We’ve identified several clusters of accounts with patterns of a ‘troll factory’ that promotes negative content against the U.S. and EU leadership via VK, Russia’s version of Facebook. These posts are written in various languages including French, Finnish, German, Dutch, and Italian. The content is mixed with geopolitical narratives of an antisemitic nature, which should violate the network’s existing Terms and Conditions.

The accounts remain active and constantly release updates, which may highlight the organized effort to produce such content and make it available online. In September the U.S. Department of Justice seized 32 domains tied to a Russian influence campaign. This was part of a $10 million scheme to create and distribute content to U.S. audiences with hidden Russian government messaging.

LW: Quite a high degree of coordination on the part of the adversaries.

Loveland: These operations are usually well-coordinated, with teams assigned to different tasks such as content creation, social media engagement, and monitoring public reactions. This strategic approach allows them to adapt quickly to changing circumstances and public sentiment. The content is often designed to evoke anger or fear, which can lead to increased sharing and engagement.

Troll factories often create numerous fake social media profiles to amplify their messages and engage with real users. This helps them appear more credible and increases their reach. Workers in these factories produce a variety of content crafted to provoke reactions, spread false narratives, or sow discord among different groups. They typically focus on specific demographics or political groups to maximize their impact. They may even use data analytics to identify vulnerable populations and tailor their messages accordingly.

LW: How difficult has it become to identify and deter these highly coordinated campaigns?

Loveland: Unfortunately, it is not always so obvious. Troll factories tend to push similar messages across multiple accounts. If you notice a coordinated effort to spread the same narrative or hashtags, it may indicate a troll operation. Accounts with a high number of followers but few follow-backs can indicate a bot or troll account, as they often seek to amplify their reach without engaging genuinely.

If the content shared by an account is mostly reposted or lacks originality, it may be part of a troll factory’s strategy to disseminate information without creating authentic engagement. Trolls often target divisive issues to provoke reactions. If an account consistently posts about hot-button topics without a nuanced perspective, it could be a sign of trolling activity.

There are various tools and algorithms designed to detect bot-like behavior and troll accounts. These can analyze patterns in posting frequency, engagement rates, and content similarity to identify potential trolls.

LW: Technologically speaking, is it possible to detect and shut down these accounts in an effective way?

Loveland: With GenAI, the creation of troll factories became much more advanced. Unfortunately, adversaries continue to evolutionize their tools, tactics and procedures (TTPs) – using mobile residential proxies, content generation algorithms, deep fakes to impersonate real personas, and even financing media distribution operations in the United States by hostile states.

LW: Strategically, why are foreign adversaries trying so hard to sow doubt about democratic elections?

Loveland: One of the foreign adversaries’ critical goals is to plant social polarization and distrust in electoral integrity. This is a crucial component of these campaigns. Often, these campaigns promote and discourage both candidates, as they do not intend to promote one candidate over the other. They plan to sow distrust in the election process and encourage animosity among the constituents of the losing candidate against the winning candidate and their supporters.

LW: No one can put the genie back in the bottle. What should we expect to come next, with respect to deepfakes and AI-driven misinformation, over the next two to five years?

Loveland: Foreign adversaries understand that the immediate goals in election interference cannot be easily achieved, as the U.S. Intelligence Community is working hard to counter this threat proactively. That’s why one of the main long-term goals for foreign adversaries is to create polarization in society and distrust in the electoral system in general, which may impact future generations of voters.

LW: Anything else you’d like to add?

Loveland: Our research highlights the difference between the right of any US person to express their own opinion, including satire on political topics, which the U.S. First Amendment protects, and the malicious activity of foreign actors funded by foreign governments to plant discrediting content and leverage manipulated media to undermine elections and disenfranchise voters.

For example, we’ve identified content cast as political satire that is also antisemitic and in support of geopolitical narratives beneficial to foreign states to discredit US foreign policy and elections. All postings were made by bots, not real people. The proliferation of deepfakes and similar content planted by foreign actors poses challenges to the functioning of democracies. Such communications can deprive the public of the accurate information it needs to make informed decisions in elections.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post Shared Intel Q&A: Foreign adversaries now using ‘troll factories’ to destroy trust in U.S. elections first appeared on The Last Watchdog.

View Details

Atlanta, GA, Oct. 30, 2024, CyberNewswire — The American Transaction Processors Coalition (ATPC) Cyber Council will convene “The Tie that Binds: A 21st Century Cybersecurity Dialogue,” on October 31, 2024, at the Bank of America Financial Center Tower’s Convention Hall in Atlanta.

This event will feature leading cyber experts from the financial services sector, Federal agencies, the White House, and Congress to focus on pressing cybersecurity issues and ways the financial services sector is addressing these issues. It will include discussions on evolving technologies that will influence the path forward, the role of AI, supply chain security needs, and more.

Richards

“Cybersecurity is the backbone of the payment processing industry,” said H. West Richards, ATPC executive director. “The work of the ATPC Cyber Council is a testament to our commitment to safeguarding our financial ecosystem and fostering a collaborative approach to tackling the cybersecurity challenges of tomorrow.”

Key speakers, highlights

•The Honorable Harry Coker, Jr., White House National Cyber Director, will deliver the luncheon keynote.

•The Honorable Rich McCormick (R-GA-06) will deliver a keynote address.

•Moira Bergin, Subcommittee on Cybersecurity Staff Director, House Committee on Homeland Security, will discuss legislative priorities and global cybersecurity risks.

•The Honorable Andre Dickens, Mayor of Atlanta, will provide a video address.

•Barry McCarthy, CEO of Deluxe and Chair of the ATPC Board of Directors, will also deliver a keynote.

•Bridgette Walsh, Executive Director of the Financial Services Sector Coordinating Council, and Josh Magri, Founder & CEO of Cyber Risk Institute, will participate in a fireside discussion on private sector best practices.

•A panel on AI in financial services will feature Clarissa Banks (Deluxe), David Excell (Featurespace), David King (Mastercard), and Donna Teevens (ACI Worldwide), moderated by Rick Van Luvender.

•A panel on cyber education will include Dr. Tony Coulson (CSUSB), Dr. Albena Asenova-Belal (Gwinnett Technical College), Dr. Humayun Zafar (Kennesaw State University), and Dr. Michael Nowatkowski (Augusta University).

•H. West Richards, ATPC Executive Director, will open the event with a welcome address.

•Rick Van Luvender, ATPC Cyber Council Chair & SVP, Head of Cybersecurity Client Trust & International Cybersecurity Service at Fiserv, will deliver the opening remarks.

•Norma Krayem, ATPC Cyber Council Director & Vice President, Chair of the Cybersecurity, Privacy & Digital Innovation Practice Group at Van Scoyoc Associates, will provide insights on future cybersecurity trends.

The forum will conclude with a fireside chat focused on “A Look to the Future: 2025: Top Cybersecurity and Critical Technology Priorities for the ATPC Cyber Council,” featuring Rick Van Luvender from Fiserv and Norma Krayem, the ATPC Cyber Council director, focusing on future cybersecurity and critical technology priorities.

Conference details are available at https://atpcoalition.com/atpc-cyber-forum/.

ATPC is a leading voice for America’s payments processors, consisting of the world’s largest, global payment processors, banks, credit card companies and financial services companies. ATPC member companies are uniquely positioned to ensure global payments move seamlessly across the world, while empowering broader and more diverse participation within the financial services system.

In the race for a better tomorrow, technology solutions can advance faster than companies can keep up with cybersecurity risks. As a result, the ATPC is one of the few coalitions that created a standalone Cybersecurity Council to prioritize these key cybersecurity issues across its member companies.

The ATPC Cyber Council is a unique group made up of only CISOs, CSOs, CIOs and CTOs who are on the front lines every day dealing with the operational impacts of cybersecurity. These U.S. based companies serve hundreds of millions of customer businesses across the globe daily and process hundreds of billions of transactions per year.

About the ATPC: The ATPC is a leading voice for America’s payments processors, driving awareness of the industry and its value to consumers, businesses, and the economy with legislators and regulators at federal, state, and international levels. The ATPC is rooted in Georgia’s Transaction Alley where electronic payments and the fintech industry began. Yet, our members enable payments in states across the nation and in every corner of the globe. The ATPC has a rich history of economic development, thought leadership, and engagement on legislative and regulatory topics like cybersecurity, privacy, financial inclusion, fraud, as well as emerging themes like open banking, AI, and stable coins.

About the ATPC Cyber Council: The American Transaction Processors Coalition (ATPC) established a dedicated Cyber Council to galvanize the efforts of the ATPC member companies in addressing cybersecurity risks. The Cyber Council’s mission is to identify best practices and areas of shared risk to help ATPC members address the evolving cyber threat across America’s payments processing system to strengthen industry’s ability to identify, protect, detect, respond to and recover from cyberattacks.

Media contact: Alison Watson, Golin, awatson@golin.com

The post News alert: Cybersecurity, AI priorities for 2025 highlighted at ATPC Cyber Forum in Atlanta first appeared on The Last Watchdog.

View Details

Application Programming Interfaces (APIs) have become the backbone of modern enterprises, facilitating seamless communication between both internal systems and external partners.

Related: Biden-Harris administration opens Supply Chain Resilience Center

As organizations increasingly rely on APIs, the number of APIs in use has dramatically increased. Since attackers follow the attack surface, this growth in API usage has not gone unnoticed. The concentration of critical business logic and sensitive data flowing through APIs makes them an attractive target for malicious actors aiming to exploit vulnerabilities for financial gain, data theft, or service disruption.

Focused on API security, Wallarm’s API ThreatStats report gathers all the available data on API-related cybersecurity incidents and vulnerabilities for analysis. Additionally, the report identifies and tracks the trends that impact organizations.

Q3 API security incidents

Not surprisingly, Q3 2024 saw an increased number of API related cybersecurity incidents. APIs continue to be at the heart of some of the largest and most impactful breaches we’re seeing. In the last quarter, Deutsche Telekom topped the list by exposing 252 million users due to unauthenticated API access. Other key incidents included:

Hotjar and Business Insider exposed 80 million users due to client-side API issues (cross-site scripting and OAuth mismanagement).

Fractal exposed the sensitive personal information of 6,300 customers due to an insecure API script.

ExploreTalent’s authorization issues in a misconfigured API disclosed 11.4 million user records.

•Metro Pacific Tollways Corporation (MPTC) suffered an API leak affecting nearly 1 million records, including sensitive API logs.

These incidents are telling because they span multiple industries. API security issues aren’t limited to technology companies or any specific sector. APIs are used across various industries, and therefore, the API security incidents impact all industries, from telecom to tollways.

In terms of root causes, these incidents show that authentication and authorization continue to be problematic for APIs. The systems designed to protect the data behind these APIs are consistently and successfully under attack.

Finally, it’s notable that many of these incidents were driven by client-side API vulnerabilities. The OWASP API Top 10 is an industry-standard list of API related issues, focusing on server-side security. Attackers appear to be taking advantage of the blind spot represented by client-side issues like cross-site scripting.

Q3 API security trends

Wallarm’s analysis of the API related vulnerabilities provides valuable insight into the most important trends for API security. Q3 saw the largest number of API-related vulnerabilities since we began this analysis at the beginning of 2022. 469 vulnerabilities were analyzed for Q3 2024, compared to 388 in the previous quarter, a 21% increase. In the first edition of this report for Q1 2022, there were 48.

The scale of the problem continues to grow. Notably, 45% of these issues scored a 7.5 on the Common Vulnerability Scoring System (CVSS), indicating that API vulnerabilities skew towards higher risk overall. Not only are the number of vulnerabilities increasing, they are bringing increased risk to organizations.

Additionally, the analysis breaks down the vulnerabilities based on the affected type of software, with enterprise software from vendors like Oracle, VMWare, and Cisco topping the list at 39.6%. DevOps tools took the second spot at a close 36.2%. API related vulnerabilities impact enterprise organizations doing their own development most.

Key takeaways

The key takeaways for the API ThreatStats report differ, depending on your role.

CISOs should focus more on strategy than execution. Based on the Q3 analysis, comprehensive API discovery and robust authentication controls should figure prominently in their strategic objectives. These Initiatives are crucial, as unknown and poorly secured APIs can pose major vulnerabilities.

Novikov

CISOs shouldn’t overlook client-side API vulnerabilities, which are often ignored but have been shown to be exploited by attackers. While it seems like AI is everywhere, CISOs shouldn’t ignore the connection between APIs and AI in their strategic plans. These two technologies will grow together.

API Architects don’t have dramatically different priorities, but they need to focus on practical, implementable solutions as part of API architecture. Ensuring robust authentication across all APIs, for example, is paramount, as authentication is foundational for API security.

Grasping connections

Architects also need to translate some of those strategic directions down to the technical level. Implementing detailed input validation and output encoding to prevent injection attacks and data leaks will help remove API security risk. Finally, API architects who are implementing AI are best positioned to see the tight connections and build security in from the ground up.

Security practitioners shouldn’t be left out, as they are generally the executors of the CISOs strategic plans. Alignment here is key. Regular, comprehensive security assessments to identify and address vulnerabilities must be conducted proactively.

Monitoring and securing client-side applications should align with the CISO objectives. These practitioners should also stay informed about emerging threats and CVEs, keeping the CISO and the organization updated as the API threat landscape continuously evolves.

API security is a cross-functional responsibility. These recommendations are aligned, but must be applied at multiple levels within the organization. As noted, the API threat landscape continues to grow and organizations– from the CISO down– must be prepared.

About the essayist: Ivan Novikov is the Chief Executive Officer of Wallarm, which supplies a unified, automated API security solution that works with any platform, any cloud, multi-cloud, cloud-native, hybrid and on-premise environment.

The post Guest Essay: Wallarm report shows API exposures rose steeply across all industries in Q3 2024 first appeared on The Last Watchdog.

View Details

Cary, NC, Oct. 28, 2024, CyberNewswire — As the year-end approaches, it’s common for enterprises to discover they still have funds that must be utilized. Often, these L&D dollars are “use or lose,” meaning they will be returned to the general fund if not invested.

Recognizing this, INE Security is launching an initiative to guide organizations in investing in technical training before the year end. This approach not only ensures wise expenditure of remaining budgets but also significantly strengthens organizational security postures.

Addressing Training Budgets:

•Year-End Budget Scenario: It’s common for organizations to approach year-end with an unused budget designated for training. If not spent, these funds often return to general accounts or are lost altogether, missing an opportunity for strategic investment.

•Strategic Spending: INE Security encourages using these funds to invest in team cybersecurity training, turning what could be wasted resources into a pivotal investment in security and professional development.

•Advantages of Utilizing Surplus Funds: Proactively using surplus training budgets can help organizations make strategic decisions that align with long-term goals, improving security protocols and fostering a knowledgeable workforce.

How Organizations Can Utilize Available Training Budgets:

Skill Enhancement: Upgrade the team’s skills to defend against the latest networking, cloud, and cybersecurity threats.

Employee Retention: Invest in employees’ growth to boost morale and retention – especially in a tight job market where your best employees may be lured to other companies.

Future-Proofing: Prepare teams for future challenges with forward-looking training programs.

Compliance and Standards: Ensure compliance with industry standards and regulations through accredited courses and certifications – bolstering your team for contract awards and impending compliance requirements (CMMC).

Warn

“In a time when digital threats are increasing in both complexity and frequency, proactive Networking, Cloud, and Cybersecurity training is more crucial than ever,” said Dara Warn, CEO of INE Security. “We recognize that many organizations end the year with a surplus in their training budgets. This is an excellent opportunity to invest in vital training, ensuring teams are not only prepared but are ahead of the curve.”

Organizations can benefit by engaging in INE Security’s expert-led courses and hands-on labs, which are designed to provide real-world experience and in-depth knowledge across Networking, Cloud, and Cybersecurity. In recognition of the often-underused training budgets available at year’s end, INE Security is offering significant discounts for team training on two-year deals. This initiative not only helps organizations optimize their unspent training funds but also boosts their long-term security strategies.

To learn more about INE’s comprehensive Networking, Cloud, and Cybersecurity training programs, users can visit www.ine.com or contact INE Security’s corporate training advisors directly.

About INE: INE Security is the premier provider of online technical training for the IT/IS industry. Harnessing a powerful hands-on lab platform, cutting-edge technology, a global video distribution network, and world-class instructors, INE Security is the top training choice for Fortune 500 companies worldwide and for IT/IS professionals looking to advance their careers. INE’s suite of learning paths offers an incomparable depth of expertise across cybersecurity, cloud, networking, and data science. INE Security is committed to delivering advanced technical training while also lowering the barriers worldwide for those looking to enter and excel in a cybersecurity career.

Media contact: Kathryn Brown, Director of Global Strategic Communications and Events, INE Security, kbrown@ine.com

The post News alert: INE shares guidance to help companies invest in year-end cybersecurity, networking training first appeared on The Last Watchdog.

View Details

Cary, NC, Oct. 22, 2024, CyberNewswire — INE Security offers essential advice to protect digital assets and enhance security.

As small businesses increasingly depend on digital technologies to operate and grow, the risks associated with cyber threats also escalate. INE Security, a leading provider of cybersecurity training and certifications, today shared its cybersecurity training for cyber hygiene practices for small businesses, underscoring the critical role of continuous education in safeguarding digital assets.

Warn

“Small businesses face a unique set of cybersecurity challenges and threats and must be especially proactive with cybersecurity training,” said Dara Warn, CEO of INE Security. “At INE Security, we work directly with small business leaders to ensure they are able to assess their team’s skills and access the cybersecurity training that will be most effective to their unique needs.”

Tip 1: Educating and Training the Workforce Regularly

Human error remains one of the leading causes of data breaches. According to the Verizon 2024 Data Breach Investigations Report, 68% of cybersecurity breaches are caused by human error. INE Security emphasizes the importance of regular training forall employees. Cybersecurity training for small businesses is critical, and SMBs should invest in training programs to help employees recognize threats such as phishing attacks, ransomware, and other malicious activities.

Tip 2: Implementing Strong Password Policies

Weak passwords can be easily compromised, giving attackers access to sensitive systems and data. LastPass reports that 80% of all hacking-related breaches leveraged either stolen and/or weak passwords. INE Security recommends implementing strong password policies that require the use of complex passwords and regular updates.

Tip 3: Securing and Monitoring the Network

Small businesses often overlook network security, leaving them vulnerable to attacks. INE Security advises businesses to secure their network by using firewalls, encrypting data, and regularly updating security software. Network monitoring tools can also detect unusual activities and prevent potential breaches. The cost of ignoring such measures can be substantial, as noted in IBM’s 2023 Cost of a Data Breach Report, which found the average impact of a data breach on small businesses can exceed $3.31 million.

Tip 4: Regularly Updating and Patching Systems

Keeping software and systems up to date is crucial in protecting against vulnerabilities. Many cyber attacks exploit vulnerabilities in outdated software. Nearly 60% of organizations hit by a data breach blame a known vulnerability for which they had not yet patched, according to reports published by Dark Reading. INE Security recommends establishing a routine for updating and patching software, which can significantly reduce the risk of a breach.

Tip 5: Backing Up Data Regularly

Data loss can be devastating for small businesses. Regular backups ensure that businesses can recover quickly from ransomware attacks or other data loss incidents. INE Security suggests using automated backup solutions that regularly save copies of all critical data in a secure, off-site location, in addition to following the 3-2-1 rule recommended by the Department of Homeland Security’s Computer Emergency Readiness Team. The 3-2-1 rule recommends:

3 – Keeping 3 copies of any important file: 1 primary and 2 backups.

2 – Keeping the files on 2 different media types to protect against different types of hazards.

1 – Storing 1 copy offsite (e.g., outside the house or business facility)

For more information about cybersecurity training programs that can help protect small business, users can visit security.ine.com.

About INE Security: INE Security is the premier provider of online technical training for the IT/IS industry. Harnessing the world’s most powerful hands-on lab platform, cutting-edge technology, global video distribution network, and world-class instructors, INE Security is the top training choice for Fortune 500 companies worldwide and for IT professionals looking to advance their careers. INE’s suite of learning paths offers an incomparable depth of expertise across cybersecurity, cloud, networking, and data science. INE Security is committed to delivering advanced technical training while also lowering the barriers worldwide for those looking to enter and excel in a cybersecurity career.

Media contact: Kathryn Brown, Director of Global Strategic Communications and Events, INE Security, kbrown@ine.com

The post News alert: INE Security shares cyber hygiene guidance for small- and medium-sized businesses first appeared on The Last Watchdog.

View Details

Everyone knows the cost and frequency of data breaches are rising. The question is, do you know if your data is truly secure? I have news for you. It’s not.

Related: The Biden-Harris push for supply chain resilience.

Why? Many companies rely on regular encryption to safeguard data, the organization’s crown jewel. But it only goes so far. Mainstream encryption solutions only protect data in transit and at rest.

When data is in use–when queried or analyzed–and when it moves between stages in its lifecycle–from storage to processing, processing to analysis, analysis to interpretation, and finally to archival–current encryption methods make data inaccessible and require that it be decrypted.

Sophisticated threat actors knowingly target and act on these encryption gaps, putting companies at significant risk.

Continuous encryption

To maintain end-to-end data security, companies need continuous encryption, the only way to ensure data is protected across its lifecycle and when in use. The only way to achieve continuous encryption is through fully homomorphic encryption (FHE).

Here’s the problem: not all FHE solutions are created equal, which causes market confusion and a perception that FHE isn’t viable. That perception couldn’t be further from the truth. Business leaders must understand what to look for to ensure FHE does what it promises: secure data always and in all states without creating performance bottlenecks, implementation complexities, or cost barriers.

FHE’s track record

FHE is not new. It was first introduced in 2009 by Craig Gentry, a computer scientist, in his PhD thesis, A Fully Homomorphic Encryption Scheme. Gentry’s breakthrough provided a solution to the long-standing problem in cryptography—performing arbitrary computations on encrypted data without needing to decrypt it first.

Srivatsav

Vendors began to embrace this technological advancement, offering solutions that promised to maintain data integrity and security. As it gained attention and evolved, FHE became notorious for performance bottlenecks, scalability limitations, and a host of issues that made it impractical for modern business. In today’s digital world where real-time applications need lightning-fast processing capabilities, the promise of FHE became a far-off dream.

Patchwork solutions

To address FHE’s issues, vendors offer hardware accelerators, specialized components to speed up FHE’s computationally intensive processes and make the technology practical for real-world applications. Yet these accelerators have setbacks as well.

Do you remember the 2013 movie “Turbo,” where a garden snail fulfills his dream of winning the Indy 500 after a freak accident gives him turbo-charged speed? During the race, there is a crash. Turbo’s shell gets punctured and his superspeed disappears. Hardware accelerators are like that. The reality is that they’re an add-on to what’s really a snail at heart. If they go down or become inoperable, then you’re stuck with the snail.

There are other issues as well, such as:

•High development costs: Creating such accelerators is costly and time-consuming, demanding heavy R&D investment.

•Limited flexibility: Accelerators aren’t adaptable and new FHE algorithms can make them obsolete quickly.

•Integration complexity: Integrating accelerators with existing systems requires major software changes.

•Performance bottlenecks: Hardware accelerators can create data transfer slowdowns between the CPU and memory.

•Scalability limitations: Scaling accelerators is costly and resource-heavy.

Assessing advanced FHE

New technology innovations overcome the pitfalls of previous FHE iterations and bring the dream of continuous encryption within reach. No complex hardware or other add-ons that create more cost and complexity are needed. Ensuring uninterrupted data security is now a practical, achievable goal in one solution.

But remember, not all FHE is created equal. Here’s what to look for as you assess various options:

•Operate at the speed of plaintext: FHE must support digital business and real-time applications, operating at the same speed as plaintext, the difference between nanoseconds and hours or days (with traditional FHE).

•Preservation of data size and format: Traditional FHE notoriously inflates data size. Data preservation ensures efficient processing and eliminates extra storage and bandwidth costs.

•FIPS 140-2-certification: This certification gives you assurance that FHE meets the highest security standards.

FHE holds the key to true continuous encryption and end-to-end data security, but not all solutions are the same. Traditional FHE and hardware accelerators have fallen short, plagued by high costs, performance lags, and integration headaches.

The good news? Cutting-edge FHE technology breaks through these limitations, making real-time, seamless encryption a reality without costly add-ons. When selecting an FHE solution, look for one that operates at the speed of plaintext, preserves data size, and meets stringent security standards like FIPS 140-2 certification. The future of data security depends on it.

About the essayist: Ravi Srivatsav is Co-Founder and CEO of DataKrypto, the fastest continuous encryption solution available.

The post GUEST ESSAY: Achieving end-to-end data security with the right ‘fully homomorphic encryption’ first appeared on The Last Watchdog.

View Details

San Francisco, Calif., Oct. 3, 2024, CyberNewswire — Doppler, the leading platform in secrets management, today announces the launch of Change Requests, a new feature providing engineering teams with a secure, auditable approval process for managing and controlling secret changes across environments.

Designed to enhance security, compliance, and team collaboration, Change Requests gives organizations the tools to mitigate the potential risks from misconfigurations or unauthorized changes and maintain a comprehensive audit trail of all secret modifications. This launch comes at a time when organizations are facing increased security and compliance demands, particularly in managing sensitive information.

As security breaches and insider threats continue to rise, managing secrets has become a growing challenge for teams of all sizes; protecting sensitive information at every stage of the software development lifecycle is critical.

According to a recent study by Cybersecurity Ventures, cybercrime damages are expected to cost the world $9.5 trillion in 2024 alone, and compromised secrets and misconfigurations remain significant factors in these attacks. In 2023, GitGuardian reported that there were 12.8 million incidents of exposed secrets on Github which is an increase of 28% from 2022, highlighting the need for tighter controls over sensitive information.

Doppler’s Change Requests is designed to address these risks by introducing a formalized, auditable approval process for secrets management.

This feature offers teams a centralized and controlled way to manage changes to sensitive information while maintaining full visibility into who made updates and when.

Addressing security, compliance

•Reducing misconfiguration: According to the most recent Verizon Data Breach Investigation Report, breaches as a result of errors grew by 28%. By treating secret changes like code, Doppler seeks to help companies decrease this number and reduce the chances of misconfigurations reaching production. With Change Requests, organizations can require peer reviews and approvals for every configuration change to ensure all updates undergo proper scrutiny before being deployed.

•The growing compliance burden: Cybersecurity standards are increasingly holding companies accountable for how they handle sensitive data. Organizations need clear audit trails and compliance-friendly processes. Paired with detailed activity logging, Change Requests further eases the burden teams face by keeping a complete, auditable trail of every request, review, and change, providing a fully traceable history.

•Enforce security with controlled access: As teams grow, so does the complexity of managing secrets. Organizations can safeguard sensitive secrets with custom roles and user groups by enforcing a structured approval process, ensuring only authorized personnel can make critical updates. This helps prevent unauthorized changes and boosts their overall security posture while keeping teams nimble.

Building trust through security

Vallelunga

“It’s incredibly exciting to ship our most demanded feature by both developers and enterprises! Just as pull requests have increased the level of trust with production code, Doppler will fill that long awaited gap with secrets,” said Brian Vallelunga, CEO of Doppler. “I’m confident that Doppler’s Change Requests is going to establish a new paradigm for managing secrets securely at enterprise scale—undergoing approval, maintaining a rich audit trail for security and compliance, and integrating natively with production infrastructure for uninterrupted, no-downtime rollouts.”

Availability

The Change Requests feature is available now for all users on Doppler’s Enterprise plan. To learn more about implementing Change Requests and how it can improve the organization’s security and compliance efforts, users can visit Doppler’s documentation.

About Doppler: Doppler is the leading platform for managing secrets such as environment variables, API keys, and tokens in a centralized, secure, and scalable way. Trusted by thousands of security-conscious teams around the world, Doppler provides developers with the tools they need to keep secrets in sync across every app, service, and infrastructure. Built with security in mind, Doppler offers robust integrations, comprehensive logging, and enterprise-grade encryption to ensure sensitive data remains protected throughout its lifecycle.

Media contact: Doppler Press, press@doppler.com

The post News alert: Doppler fortifies ‘secrets management’ with Change Requests auditable approval feature first appeared on The Last Watchdog.

View Details

Singapore, Oct. 3, 2024, CyberNewswire — At DEF CON 32, the SquareX research team delivered a hard-hitting presentation titled Sneaky Extensions: The MV3 Escape Artists where they shared their findings on how malicious browser extensions are bypassing Google’s latest standard for building chrome extensions: Manifest V3 (MV3)’s security features, putting millions of users and businesses at risk.

SquareX’s research team publicly demonstrated rogue extensions built on MV3. The key findings include:

•Extensions can steal live video streams, such as those from Google Meet and Zoom Web, without requiring special permissions.

•The rogue extensions can act on a user’s behalf to add collaborators to private GitHub repositories.

•The extensions are capable of hooking into login events to redirect users to a page disguised as a password manager login.

•Extensions built on MV3 can steal site cookies, browsing history, bookmarks, and download history with ease, like their MV2 counterparts.

•The rogue extensions can add pop-ups to the active webpage, such as fake software update prompts, tricking users into downloading malware.

Browser extensions have long been a target for malicious actors — a Stanford University report estimates that 280 million malicious Chrome extensions were installed in recent years. Google has struggled to address this issue, often relying on independent researchers to identify malicious extensions.

In some cases, Google has had to manually remove them, such as the 32 extensions taken down in June last year. By the time they were removed, these extensions had already been installed 75 million times.

Most of these issues arose because the Chrome extension standard, Manifest Version 2 (MV2), was riddled with loopholes that granted extensions excessive permissions, and allowed scripts to be injected on the fly, often without users’ knowledge. This allowed malicious actors to easily exploit these vulnerabilities to steal data, inject malware, and access sensitive information. MV3 was introduced to address these problems by tightening security, limiting permissions, and requiring extensions to declare their scripts beforehand.

However, SquareX’s research shows that MV3 falls short in many critical areas, demonstrating how attackers are still able to exploit minimal permissions to carry out malicious activity. Both individual users and enterprises are exposed, even under the newer MV3 framework.

Today’s security solutions, such as endpoint security, SASE/SSE, and Secure Web Gateways (SWG), lack visibility into installed browser extensions. There is currently no mature tool or platform capable of dynamically instrumenting these extensions, leaving enterprises without the ability to accurately assess whether an extension is safe or malicious.

SquareX is committed to the highest level of cybersecurity protection for enterprises and has built key innovative features to solve this problem, which include;

•Fine grained policies to decide which extensions to allow / block and parameters include extension permissions, creation date, last update, reviews, ratings, user count, author attributes etc

•SquareX blocks network requests sent by extensions at run time – based on policies, heuristics and machine learning insights

•SquareX is also experimenting with dynamic analysis of Chrome Extensions using a modified Chromium browser in its cloud server

These are part of SquareX’s Browser Detection and Response solution which is being deployed at medium-large enterprises and is effectively blocking these attacks.

Ramachandran

Vivek Ramachandran, Founder & CEO of SquareX, warned about the mounting risks: “Browser extensions are a blind spot for EDR/XDR and SWGs have no way to infer their presence. This has made browser extensions a very effective and potent technique to silently be installed and monitor enterprise users, and attackers are leveraging them to monitor communication over web calls, act on the victim’s behalf to give permissions to external parties, steal cookies and other site data and so on,” he said.

“Our research proves that without dynamic analysis and the ability for enterprises to apply stringent policies, it will not be possible to identify and block these attacks. Google MV3, though well intended, is still far away from enforcing security at both a design and implementation phase,” Ramachandran added.

About SquareX: SquareX helps organizations detect, mitigate and threat-hunt client-side web attacks happening against their users in real time.

SquareX’s industry-first Browser Detection and Response (BDR) solution, takes an attack-focused approach to browser security, ensuring enterprise users are protected against advanced threats like malicious QR Codes, Browser-in-the-Browser phishing, macro-based malware, malicious extensions and other web attacks encompassing malicious files, websites, scripts, and compromised networks.

With SquareX, enterprises can also provide contractors and remote workers with secure access to internal applications, enterprise SaaS, and convert the browsers on BYOD / unmanaged devices into trusted browsing sessions.

Media contact: Junice Liew, Head of PR, SquareX, junice@sqrx.com

The post News alert: SquareX shows how Google’s MV3 standard falls short, putting millions at risk first appeared on The Last Watchdog.

View Details

Torrance, Calif., Oct. 3, 2024, CyberNewswire — An exclusive live webinar will take place on October 4th at noon Eastern Time (ET), demonstrating how Criminal IP’s Attack Surface Management (ASM) can help organizations proactively detect and mitigate cyber threats.

The webinar will feature a Criminal IP ASM Live Demo, providing a comprehensive view of attack surface visibility. As cyber threats continue to evolve, businesses must strengthen their defenses, and this session will outline essential steps for achieving that goal.

Users can register now for the free webinar at 12PM ET on October 10 ?

Key takeaways

•Criminal IP ASM live demo. Seeing ASM in action as it uncovers hidden threats and helps secure user’s organization attack surface.

Comprehensive attack surface visibility. Discovering how to gain real-time insights into a user’s organization’s digital ecosystem, identifying vulnerabilities before they can be exploited.

•Proactive threat detection and mitigation. Learning how to detect risks early and implement mitigation strategies to minimize exposure.

•Strengthening cyber defenses with ASM. Exploring how ASM can be integrated into cybersecurity frameworks to enhance protection and provide continuous defense against threats.

This webinar is designed for IT professionals, security managers, and decision-makers looking to advance their cybersecurity strategies and stay ahead in today’s rapidly changing threat landscape.

Users can register now to gain valuable insights on safeguarding their organization’s attack surface and taking proactive steps toward a more secure future.

Media contact: Michael Sena, AI SPERA, support@aispera.com

The post News alert: Upcoming webinar highlights threat mitigation, fortifying ‘ASM’ with Criminal IP first appeared on The Last Watchdog.

View Details

Silver Spring, MD, Oct. 2, 2024, CyberNewswire — Aembit, the non-human IAM company, today announced the appointment of Mario Duarte as chief information security officer (CISO). Duarte, formerly head of security at Snowflake, joins Aembit with a deep commitment to address pressing gaps in non-human identity security.

Duarte’s journey in cybersecurity began with a passion for penetration testing, sparked by the 1980s cult classic film WarGames. He started his career in red teaming, later expanding his expertise into both technical and leadership roles on the defensive side.

Throughout his career, he has focused on protecting mission-critical systems, solving complex security problems, and developing and overseeing high-performing teams.

His experience spans multiple industries, including finance, health care, retail, and technology. Most notably, Duarte spent nearly a decade at Snowflake, where he played a key role in shaping and leading the data cloud company’s security program, rising to vice president of security (aka CISO). It was during this time that he first encountered Aembit and its innovative and award-winning approach to securing non-human identities.

“I fell in love with security because of the thrill of finding weaknesses and fixing them,” Duarte said. “I’ve always had the mindset of an attacker, but over the years, I’ve focused on defending organizations – understanding where the real threats are coming from and solving those problems at scale. Throughout my career, I’ve witnessed how non-human identities like workloads and service accounts are being exploited, and knew this was the next big frontier in security.”

Before his time at Snowflake, Duarte held senior security roles at multiple organizations, including GoGrid, Moodys KMV, and Ross Stores. His ability to adapt and thrive in diverse sectors helped shape his understanding of security from multiple threat angles and perspectives, including compliance with FedRAMP, HIPAA/HITECH, and PCI standards.

Duarte was drawn to Aembit not only because of its groundbreaking technology but also by the culture and mission of the company.

“Aembit is solving a problem that’s been neglected for years – securing the non-human identities that drive IT infrastructure,” he said. “It’s replacing outdated methods like static credentials and manual processes with a more dynamic and secure approach that my peers and I have been seeking for a long time. The Aembit team recognizes the complexity of this problem and is relentless in creating a practical and scalable solution for it.”

As the need for identity-driven, secretless, centrally enforced, and auditable connections across distributed applications, SaaS services, and the rise of AI workloads, the Aembit Workload IAM Platform – honored as runner-up in the 2024 RSA Innovation Sandbox competition – responds by enforcing secure access between non-human workloads and the sensitive resources and infrastructure that businesses run on, providing just-in-time, secretless access based on the workload’s identity and posture.

“Mario brings an unmatched level of experience and passion to our team,” Aembit Co-Founder and CEO David Goldschlag said. “He’s been in the trenches, defending some of the most sophisticated infrastructures, and his leadership will help guide Aembit as we continue to solve the toughest identity security challenges.”

In his new role, Duarte will focus on advancing Aembit’s efforts to meet the needs of the security community as organizations increasingly shift to cloud-native, distributed, and automated environments. His deep connection to his fellow CISOs and security professionals, along with his commitment to providing effective, scalable, and practical solutions, will help guide Aembit’s continued growth in this fast-growing space.

“Security is my tribe,” he said. “The stakes are too high here, and I wouldn’t put my name behind anything I didn’t fully believe in.”

About Aembit: Aembit is the leading provider of workload identity and access management solutions, designed to secure non-human identities like applications, AI agents, and service accounts across on-premises, SaaS, cloud, and partner environments. Aembit’s no-code platform enables organizations to enforce access policies in real-time, ensuring the security and integrity of critical infrastructure. Users can follow them on LinkedIn.

Media contact: Apurva Davé, CMO, Aembit, info@aembit.io

The post News alert: Aembit appoints former Snowflake security director Mario Duarte as its new CISO first appeared on The Last Watchdog.

View Details

Pittsburgh, PA, Oct. 1, 2024 — ForAllSecure, the world’s most advanced application security testing company, today announced it is changing its corporate name to Mayhem Security (“Mayhem”), signaling a new era of growth and opportunity aligned with its award-winning Mayhem Application Security platform.

Founded by a team of researchers from Carnegie Mellon, the company’s focus has evolved from research, development, and education to a product company centered around its Mayhem platform that quickly went from a Defense Advanced Research Project Agency (DARPA) Cyber Grand Challenge prototype to an in-demand commercialized AI-driven application security platform.

Today, the Mayhem platform has been integrated into thousands of open-source projects, building a library of behavioral tests, identifying new zero-days, and helping defend against software supply chain threats.

The name change follows record product achievements, with platform ARR rising 275% year over year and 78% of customers expanding their Mayhem footprint at or before their first subscription renewal.

Brumley

“ForAllSecure has a long, successful history, from winning the DARPA Grand Challenge to dedicating ourselves to research and innovation in the cybersecurity industry through Mayhem Heroes, hackathons, and consulting,” said David Brumley, CEO of Mayhem. “Our new name and focus mark an important evolution for us as the Mayhem brand becomes synonymous with the platform that is transforming API security testing and has powered our growth.

“In fact, for several years, it was the majority of our revenue. Our new positioning is a natural next step as we continue the hard work of our dedicated researchers and hackers who will continue to push out innovative research and prototype new ways to defend software.”

The past year has been a banner year, with the company achieving key innovation milestones. Most notably, Mayhem released Mayhem Dynamic software bill of materials (SBOM), which brings Mayhem’s runtime intelligence to the world of software composition analysis (SCA) and SBOM by looking at an application’s actual behavior to find only real, exploitable vulnerabilities, eliminating triage and investigations, and reducing false positives to increase developer velocity and minimize application risks.

Mayhem re-architected its symbolic executor to test and triage 60% faster, released support for Windows-based applications, and launched a beta of automated harnessing for embedded systems.

Under the name Mayhem Security, the company will continue to collaborate with the government and the industry to advance cybersecurity and revolutionize how organizations approach cybersecurity by automating the process of finding and fixing software vulnerabilities.

For more information, visit https://www.mayhem.security/.

About Mayhem Security: Mayhem Security, formerly ForAllSecure, is a hacker organization focused on advancing cybersecurity through research, education, and product development. Founded in 2012 by CMU researchers, Mayhem Security has over a decade of experience building and participating in CTFs and partnering with K-12 and university departments to develop cybersecurity education programs. In 2016, the company won DARPA’s cyber grand challenge focused on autonomous security. Mayhem, the company’s first commercial product, launched in 2019. Based in Pittsburgh, PA, the company is backed by NEA and KDT and has offices worldwide.

Media Contact: Danielle Ostrovsky, Hi-Touch PR, 410-302-9459, ostrovsky@hi-touchpr.com**

The post News alert: Introducing Mayhem Security — ForAllSecure unveils name change, fresh focus first appeared on The Last Watchdog.

View Details

Cary, NC, Sept. 27, 2024, CyberNewswire — INE, a global leader in networking and cybersecurity training and certifications, is proud to announce they have earned 14 awards in G2’s Fall 2024 Report, including “Fastest Implementation” and “Most Implementable,” which highlight INE’s superior performance relative to competitors.

“Best hands-on and real world scenario based curriculum,” raves small business user Satvik V. in a recent 5-star review. ”Their dedication towards improving the curriculum and providing the best learning experience is the best thing and I would rate 10/10.”

G2 calculates rankings using a proprietary algorithm sourced from verified reviews of actual product users and is a trusted review source for thousands of organizations around the world. Its recognition of INE’s strong performance in enterprise, small business, and global impact for technical training showcases the depth and breadth of INE’s online learning library.

Warn

At INE, we are driven not just by our achievements, but by our mission to equip professionals and enterprises with the skills necessary to navigate the evolving cybersecurity landscape,” said Dara Warn, CEO of INE. “Our commitment goes beyond winning awards; it’s about forging a pathway that prepares our clients to face future challenges head-on. By consistently updating and expanding our training modules, we ensure that every course reflects the latest in technology and security practices. This approach helps us empower organizations across the globe to build a resilient, well-prepared workforce capable of turning potential threats into opportunities for growth and innovation.”

INE’s G2 Fall 2024 Report highlights include:

•Fastest Implementation: Online Course Providers

•Most Implementable: Online Course Providers

•Leader: Europe, Asia, and Asia Pacific Online Course Providers

•High Performer: India, Asia Technical Skills Development

•Small Business High Performer: Asia Pacific Online Course Providers

•Small Business Leader: Online Course Providers

•Enterprise Leader: Online Course Providers

•Momentum Leader: Online Course Providers

•Leader: Online Course Providers

•Small Business High Performer: Technical Skills Development

High Performer: Technical Skills Development

“The flexibility to learn at one’s own pace, coupled with the ability to access a vast library of resources anytime, anywhere, makes INE an ideal platform for both students and professionals looking to advance their skills or transition into new tech roles,” writes Oussama E., another small business user.

This fall, the prestigious SC Awards recognized INE Security, INE’s cybersecurity-specific training, as the Best IT Security-Related Training Program. This designation further underscores INE Security’s role as a frontrunner in cybersecurity training for businesses, providing the tools and knowledge essential for tackling today’s complex cyber threats.

Earlier this year, the Global InfoSec Awards presented INE Security with 4 awards at RSAC 2024, including:

•Best Product – Cybersecurity Education for Enterprises

•Most Innovative – Cybersecurity Education for SMBs

•Publisher’s Choice – Cybersecurity Training

•Cutting Edge – Cybersecurity Training Videos

Combined, these accolades highlight INE’s leadership in delivering innovative and effective networking and cybersecurity education across various market segments, including enterprises and small to medium-sized businesses.

About INE: INE is the premier provider of online technical training for the IT industry. Harnessing the world’s most powerful hands-on lab platform, cutting-edge technology, global video distribution network, and world-class instructors, INE is the top training choice for Fortune 500 companies worldwide, and for IT professionals looking to advance their careers. INE’s suite of learning paths offers an incomparable depth of expertise across cybersecurity, cloud, networking, and data science. INE is committed to delivering the most advanced technical training on the planet, while also lowering the barriers worldwide for those looking to enter and excel in an IT career.

Media contact: Kathryn Brown, Director of Global Strategic Communications and Events, INE Security, kbrown@ine.com

The post News alert: INE earns accolades based on strong curriculum reviews from business leaders first appeared on The Last Watchdog.

View Details

Ever since the massive National Public Data (NPD) breach was disclosed a few weeks ago, news sources have reported an increased interest in online credit bureaus, and there has been an apparent upswing in onboarding of new subscribers.

Related: Class-action lawsuits pile up in wake of NPD hack

So what’s the connection? NPD reported the exposure of over 2.7 billion records. The breach was initially caused by a third-party malicious actor who infiltrated NPD’s systems in December 2023.

The data began leaking in April 2024, and by summer, it was being sold on the dark web for $3.5 million. The stolen information included full names, Social Security numbers, mailing addresses, phone numbers, and email addresses of millions of U.S., Canadian, and British citizens.

While NPD claimed that around 1.3 million individuals were directly affected, analysts like Troy Hunt found evidence of much wider exposure, including 134 million unique email addresses and even criminal record data. Investigations are ongoing, and several class-action lawsuits have been filed, alleging that the company failed to implement sufficient security measures.

There is little doubt that high-profile breaches like this will persist. This drives public awareness of the risks associated with identity theft. As a result, many people rush to protect themselves by subscribing to services that offer credit monitoring, identity theft protection, and fraud alerts. Online credit bureaus, like Equifax, Experian, and TransUnion, often see an uptick in new users after breaches because consumers realize the potential risks to their financial well-being and identity.

The growing threat of cybercrime, including ransomware attacks and large-scale data leaks, is also pushing individuals to take more control of their personal data. Credit monitoring services provide ongoing tracking of credit reports for suspicious activity, and some even offer insurance for identity theft-related losses. As breaches become more frequent, credit protection services become a more attractive option for those seeking peace of mind and financial security.

What’s more, some credit bureaus have started offering more comprehensive packages that include dark web monitoring, fraud detection, and restoration services, which are enticing consumers to subscribe to these services at a higher rate.

Devaluing SSNs

This breach had such wide implications, it caused millions of consumers and thousands of organizations to look more closely at how to protect themselves, their identities and sensitive data. The sad reality is we have been de-sensitized by these constant breaches.

Kumar

NPD certainly could have done many things better but there is one thing that is on us. Perhaps the time has come to get rid of using our social security numbers. It is the simplest and least expensive solution that will have a highly positive impact on overall security. Today, we use the same SSN across dental clinics, car dealerships, and mortgage applications. It is no stretch to predict that it’s guaranteed to get compromised eventually.

Rather, we should treat SSN as just another piece of personally identifiable information (PII) like an email address – confidential information but not a sensitive one that unlocks your bank accounts. Governments can create a digital identity at birth to replace SSN in its current use. That identity is tied to specific vendors. As an example, you have two tokens – one for NPD and another for your bank, and after such a breach, the NPD token would be revoked so NPD cannot use your data, but everything will work fine at the bank.

The NPD breach serves as a stark reminder of the critical importance of data security in today’s digital world, particularly in regulated industries such as financial services and healthcare. As more personal data is collected, stored, and shared online, providers and their organizations must take proactive steps to safeguard this information from cyberattacks.

Trust principles

Given the complex cybersecurity environment, with data breaches unfortunately happening at a record pace, organizations need to continue to build and establish trust with everyone from individuals to partners, employees and those in the supply chain. All organizations with access to personally identifiable information (PII) should adhere to essential identity trust principles that include:

•Advanced and strict fraud prevention: Doing so will help prevent threat actors from not only creating fake accounts to impersonate legitimate users but make it much more difficult for them to gain access in the first place.

•Attach and hold to compliance frameworks: Compliance frameworks are designated to protect stakeholders against misuse of any kind – data included. Most industries have strict regulations in place, and in many cases, organizations will be subject to fines if adherence to regulations are violated.

•Trust: Users must know that their data is safe with the entities interacted with – this provides confidence to share information in the first place.

Many affected individuals were unaware of the breach or even the fact that NPD had collected their data in the first place. NPD’s practice of scraping data elements from non-public sources without consent raises serious ethical and legal concerns. This brings up the issue about how our governmental and private institutions handle PII. Even when strict compliance frameworks achieve their goals, they are not enough to put the necessary restrictions on the usage of this type of data. Again, should SSN be the key identity point?

When there is a breach of this magnitude that involves SSNs, there is a scramble for individuals to protect themselves through efforts such as:

•Freezing consumer credit reports: Contacting the major credit bureaus (Equifax, Experian, and TransUnion) to prevent new credit accounts from being opened without consent.

•Accessing free weekly credit reports: Gaining access to free weekly credit reports to monitor any suspicious activity.

In the case of NPD, the hackers targeted a data broker whose role is to aggregate information from many data sources. Initial reports indicated the company’s apparent security missteps increased the impact.

This begs the question, did NPD have too much data? Did they understand the data they had, and why was it not properly protected?

If an organization falls victim to a data breach, they would be in a better position to respond if they have less sensitive data and better-quality data – and without SSN as the key identifier. As it was, in the case of NPD the leaks came in spurts, with several types of data – much of it was erroneous. This may go against a data broker’s interests, but the first lesson is to ensure they reduce the amount of PII and remove redundant, obsolete, and trivial data (ROT). It would be safer and more effective to handle the minimal amount of data they are allowed to possess.

About the essayist: Ambuj Kumar is Co-founder and CEO of Simbian, AI Agents for cybersecurity

The post GUEST ESSAY: Massive NPD breach tells us its high time to replace SSNs as an authenticator first appeared on The Last Watchdog.

View Details

LEHI, Utah, Sept. 23, 2024 – DigiCert, backed by Clearlake Capital Group, L.P. (together with its affiliates, “Clearlake”), Crosspoint Capital Partners L.P. (“Crosspoint”), and TA Associates Management L.P. (“TA”), today announced it has completed its acquisition of Vercara, a leader in cloud-based services that secure the online experience, including managed authoritative Domain Name System (DNS) and Distributed Denial-of-Service (DDoS) security offerings that protect organizations’ networks and applications.

The acquisition expands DigiCert’s capabilities to protect organizations of all sizes from the growing number of cyberattacks organizations experience each day.

The acquisition of Vercara complements DigiCert’s core PKI and certificate management infrastructure that protects and authenticates people, websites, content, software, and devices. Vercara’s industry-recognized UltraDNS product is an enterprise-grade managed authoritative DNS service that securely delivers fast and accurate query responses to websites and other vital online assets, ensuring 100% website availability along with built-in security for superior protection. Vercara’s UltraDDoS Protect, UltraWAF, UltraAPI, and UltraEdge solutions provide layers of protection for organizations’ web applications and infrastructure. By combining with Vercara, DigiCert will be positioned to provide customers with a unified DNS and certificate management experience, including more efficient domain control validation and simplified DNS configuration.

Sinha

“Today we start the exciting work of bringing Vercara into our portfolio to further advance DigiCert’s goal of delivering digital trust for the real world,”said Amit Sinha, CEO of DigiCert.“We believe the combination of Vercara’s talent and suite of products with DigiCert’s technology and platform, history of innovation, and scale will help ensure customers get the highest level of digital trust available.”

About DigiCert: DigiCert is a leading global provider of digital trust, enabling individuals and businesses to engage online with the confidence that their footprint in the digital world is secure. DigiCert® ONE, the platform for digital trust, provides organizations with centralized visibility and control over a broad range of public and private trust needs, securing websites, enterprise access and communication, software, identity, content and devices. DigiCert pairs its award-winning software with its industry leadership in standards, support and operations, and is the digital trust provider of choice for leading companies around the world. For more information, visit ?www.digicert.com or follow on LinkedIn.

About Vercara: Vercara is a purpose-built, global, cloud-based security platform that provides layers of protection to safeguard businesses’ online presence, no matter where attacks originate or where they are aimed. Delivering the industry’s highest-performing solutions and supported by unparalleled 24/7 human expertise and hands-on guidance, top global brands depend on Vercara to protect their networks and applications against threats and downtime. Vercara’s suite of cloud-based services is secure, reliable, and available, delivering peace of mind and ensuring that businesses and their customers experience exceptional interactions all day, every day. Pressure-tested in the world’s most tightly regulated and high-traffic verticals, Vercara’s mission-critical security portfolio provides best-in-class DNS and application and network security (including DDoS and WAF) services to its Global 5000 customers and beyond. For more information, visit www.vercara.com.

About Clearlake: Founded in 2006, Clearlake Capital Group, L.P. is an investment firm operating integrated businesses across private equity, credit, and other related strategies. With a sector-focused approach, the firm seeks to partner with experienced management teams by providing patient, long-term capital to dynamic businesses that can benefit from Clearlake’s operational improvement approach, O.P.S.® The firm’s core target sectors are technology, industrials, and consumer. Clearlake currently has over $90 billion of assets under management, and its senior investment principals have led or co-led over 400 investments. The firm is headquartered in Santa Monica, CA with affiliates in Dallas, TX, London, UK and Dublin, Ireland. More information is available at www.clearlake.com.

About TA: TA is a leading global growth private equity firm with offices in Boston, Menlo Park, Austin, London, Mumbai and Hong Kong. Focused on targeted sectors within five industries – technology, healthcare, financial services, consumer and business services – the firm invests in profitable, growing companies around the world with opportunities for sustained growth. Investing as either a majority or minority investor, the firm employs a long-term approach, utilizing its strategic resources to help management teams build lasting value in growth companies. TA has raised $65 billion in capital and has invested in more than 560 companies since its founding in 1968.

About Crosspoint Capital Partners: Crosspoint Capital Partners is a private equity investment firm focused on the cybersecurity, privacy and infrastructure software markets. Crosspoint has assembled a group of highly successful operators, investors and sector experts to partner with foundational technology companies and drive differentiated returns. Crosspoint has offices in Menlo Park, CA and Boston, MA. For more information visit: www.crosspointcapital.com.

The post News alert: DigiCert acquires Vercara to enhance cloud-based DNS management, DDoS protection first appeared on The Last Watchdog.

View Details

Silver Spring, MD, Sept. 19, 2024, CyberNewswire — Aembit, the non-human identity and access management (IAM) company, today released its 2024 Non-Human Identity Security Report, a definitive survey highlighting how organizations currently manage and protect non-human identities (NHIs) – such as applications, scripts, and service accounts.

The report reveals a stunning, widespread reliance on outdated methods and manual practices that fail to provide adequate protection against the reality of increased NHI-focused breaches.

As non-human identities (NHIs) rapidly proliferate in modern IT environments, driven by the shift from monolithic to distributed architectures, widespread cloud adoption, and increasing automation, the report reveals a chasm between non-human and user identity security practices, with most organizations acknowledging their efforts to secure non-human identities are either lagging or struggling to keep pace.

The survey of IT and security professionals also shows that careless habits, such as storing long-term credentials directly in code, relying on spreadsheets for manual input, and sharing sensitive information via collaboration tools, are still prevalent. Additionally, many organizations face difficulty in securing NHIs in complex, multi-cloud environments, with concerns about inconsistent access management and unclear ownership of security processes.

Key findings of the survey include:

•IAM Maturity Gap: 88.5% of organizations admitted that their non-human IAM practices lag behind or are on par with their user IAM efforts.

•Low Confidence: Only 19.6% of respondents expressed strong confidence in their non-human IAM practices.

•Insecure Practices: 30.9% of respondents store long-term credentials in code and 23.7% share secrets through copying and pasting, such as via email or messaging apps.

•Outmoded Methods: 38.9% of respondents still use less-secure methods like secrets managers for non-human workload-to-workload authentication.

•Cloud Complexity: 35.6% of organizations struggle to manage non-human identity security across hybrid and multi-cloud environments.

•Blind Spots: 23.5% of organizations are not sure of the biggest threat to their non-human identities.

Goldschlag

“Organizations are starting to recognize that non-human identities are more than just background tools. As businesses rapidly automate, NHIs play a critical role in digital ecosystems and often handle sensitive data,” said David Goldschlag, co-founder and CEO of Aembit. “But, as our survey shows, NHI security remains very much a work in progress. While awareness is growing, most organizations still have significant shortfalls in how they secure these identities and the vital connections between them. It’s time to elevate non-human IAM to the same level of importance as user IAM.”

The survey, which included responses from 110 professionals, from developers to identity architects to CISOs, also revealed a growing need for more holistic approaches to managing non-human identities. As businesses expand across cloud environments, managing workload identities has become increasingly complex, with many organizations struggling to keep up due to piecemeal or legacy approaches.

Those interested can read the full survey by downloading it here.

About Aembit: Aembit is the non-human identity and access management platform that secures access between workloads across clouds, SaaS, and data centers. With Aembit’s identity control plane, DevSecOps can fully automate secretless, policy-based, and Zero Trust workload access with MFA-strength capabilities. For more information, users can visit https://aembit.io/ and follow us on LinkedIn.

Media contact: Apurva Davé, CMO, Aembit, info@aembit.io

The post News alert: Aembit’s 2024 survey report highlights major gaps in securing ‘Non-Human Identities’ first appeared on The Last Watchdog.

View Details

Austin, TX, Sept. 18, 2024, CyberNewsWire — SpyCloud, the leader in Cybercrime Analytics, today announced new cybersecurity research highlighting the growing and alarming threat of infostealers – a type of malware designed to exfiltrate digital identity data, login credentials, and session cookies from infected devices.

SpyCloud’s latest findings reveal the staggering scale of identity exposure caused by infostealers, the influence this type of malware has had on the surge in ransomware incidents, and the profound implications for businesses worldwide.

Massive scale exposures

According to SpyCloud, 61% of all data breaches in the past year were malware-related, with infostealers responsible for the theft of 343.78 million credentials. These stolen credentials are then sold in criminal communities for use in further attacks.

The research also found that one in five individuals has been a victim of an infostealer infection. Each infection, on average, exposes 10-25 third-party business application credentials, creating fertile ground for further access and exploitation, particularly by ransomware operators.

Fleury

“Our latest findings reveal a critical shift in the cybersecurity landscape,” said Damon Fleury, chief product officer at SpyCloud. “Infostealers have become the go-to tool for cybercriminals, with their ability to exfiltrate valuable data in a matter of seconds, creating a runway for cyberattacks like ransomware off the vast amounts of stolen access to SSO, VPN, admin panels, and other critical applications.”

Infostealers precede ransomware

The link between infostealers and ransomware is becoming increasingly evident. Through deep analysis of recaptured infostealer logs, SpyCloud discovered a worrying trend: companies with employees and contractors who are infected with infostealer malware are significantly more likely to experience a ransomware attack. In fact, nearly one-third of companies that suffered a ransomware attack last year had previously experienced an infostealer infection. According to the report, this is based on publicly known incidents and confirmed ransomware events. The true exposure is potentially even higher as not all ransomware incidents are made publicly available.

Hilligloss

“The correlation between infostealer infections and subsequent ransomware attacks is a wake-up call for businesses,” said Trevor Hilligoss, vice president of SpyCloud Labs, SpyCloud. “However, this field is incredibly complex and fast-moving. This year, we’re seeing new infostealers families that make use of expanded capabilities such as advanced encryption to stay stealthy or the ability to restore expired authentication cookies for more persistent access.”

MaaS, ATOs on the rise

The infostealer threat is further exacerbated by the rise of Malware-as-a-Service (MaaS). This off-the-shelf model allows even low-skilled cybercriminals to purchase and deploy sophisticated malware, including infostealers, with ease. Through MaaS, these criminals can acquire fresh and accurate identity data in bulk, fueling the cycle of cybercrime.

SpyCloud’s findings also shed light on the evolution of account takeover (ATO) attacks, powered by infostealers. Unlike traditional ATO, which relies on stolen credentials (username and password combinations), next-generation ATO leverages stolen session cookies to sidestep traditional authentication methods in what is known as session hijacking. By taking over these already-authenticated sessions, cybercriminals can mimic legitimate users and infiltrate networks undetected. This method significantly increases the success rate of attacks and poses a severe threat to organizational security.

“The sheer volume of credentials and session cookies being siphoned by infostealers is staggering,” said Hilligoss. “In the last 90 days alone, SpyCloud has recaptured over 5.4 billion stolen cookie records – with an average of nearly 2,000 exposed records per infected device. This vast trove of data is increasingly used by ransomware operators and initial access brokers to facilitate their attacks, highlighting the need for advanced defense strategies.”

Limitations of traditional defenses

At least 54% of devices infected with infostealers in the first half of 2024 had antivirus or endpoint detection and response (EDR) solutions installed, underscoring the limitations of traditional cybersecurity measures in combating the techniques used by modern cybercriminals.

Furthermore, infostealers and session hijacking attacks render multi-factor authentication (MFA) and passwordless authentication methods like passkeys ineffective. By hijacking already-authenticated sessions, cybercriminals can impersonate legitimate users and side-step even the most robust authentication methods.

Next-generation cybersecurity

The findings from SpyCloud make it clear: traditional malware mitigation is no longer sufficient and ignoring the problem only exacerbates the impact on businesses. Organizations must move beyond merely removing infections and focus on remediating the long-term risks posed by exposed data. This includes resetting compromised application credentials and invalidating session cookies siphoned by infostealers.

By understanding the risks posed by infostealers and working to mitigate the data that has been exfiltrated, organizations are able to limit the likelihood of devastating cyberattacks such as ransomware that stem from this stolen data. SpyCloud remains committed to helping organizations navigate these challenges and safeguard their digital assets. Readers can download the full 2024 Malware and Ransomware Defense Report.

To learn more about how SpyCloud helps organizations defend against ransomware, readers can visit https://spycloud.com/use-case/ransomware-prevention/.

About the SpyCloud 2024 Malware and Ransomware Defense Report: For this fourth annual report, SpyCloud surveyed 510 individuals in active cybersecurity roles within organizations in the US and the UK with at least 500 employees. The report examines the top concerns and real-life impacts of ransomware, including popular entry points, ransom payments, and the cumulative costs of these attacks to the business. It also highlights key cyber threat prevention strategies and future security priorities identified by these experts.

About SpyCloud: SpyCloud transforms recaptured darknet data to disrupt cybercrime. Its automated identity threat protection solutions leverage advanced analytics to proactively prevent ransomware and account takeover, safeguard employee and consumer accounts, and accelerate cybercrime investigations. SpyCloud’s data from breaches, malware-infected devices, and successful phishes also powers many popular dark web monitoring and identity theft protection offerings. Customers include more than half of the Fortune 10, along with hundreds of global enterprises, mid-sized companies, and government agencies worldwide. Headquartered in Austin, TX, SpyCloud is home to more than 200 cybersecurity experts whose mission is to protect businesses and consumers from the stolen identity data criminals are using to target them now. To learn more and see insights on their company’s exposed data, readers can visit spycloud.com

Media contact: Katie Hanusik, EVP, Public Relations,REQ on behalf of SpyCloud, spycloud@req.co

The post News alert: SpyCloud study reveals ‘infostealer’ malware can be a precursor to a ransomware attack first appeared on The Last Watchdog.

View Details

Cary, NC, Sept.18, 2024, CyberNewsWire — INE Security is proud to announce that it has been named a winner in the prestigious 2024 SC Awards, named Best IT Security-Related Training Program. This designation underscores INE Security’s commitment to excellence and leadership in the cybersecurity industry.

The SC Awards, now in its 27th year, recognize the solutions, organizations, and individuals that have demonstrated outstanding achievement in advancing the security of information systems. This year’s awards were presented across 33 categories, celebrating both established industry leaders and emerging innovators.

INE Security stood out among a competitive field of entries, demonstrating its innovation in addressing the evolving cybersecurity landscape. The Best IT Security-Related Training Program award highlights INE Security’s efforts to deliver practical, effective solutions that safeguard against today’s complex threats.

Warn

“We are thrilled to receive the 2024 SC Excellence Award for Best IT Security-Related Training Program. This recognition highlights our relentless pursuit of excellence and innovation in cybersecurity training,” said Dara Warn, CEO of INE Security. “At INE Security, we are committed to empowering professionals and organizations with the skills they need to defend against the ever-evolving cybersecurity threats. This accolade not only reflects our commitment to the highest standards of training but also motivates us to continue advancing the field of cybersecurity education.”

The SC Awards are presented by SC Media, a trusted cybersecurity resource, and evaluated by a panel of independent industry experts. Winners are selected based on their contributions to innovation, their ability to address the cybersecurity industry’s critical challenges, and their demonstrated impact on protecting organizations.

“These award recipients represent the very best of what the cybersecurity community has to offer,” said Tom Spring, Editorial Director at SC Media. “Each winner has shown a commitment to advancing the industry with forward-thinking solutions and an ability to adapt to new challenges. Their contributions help drive progress in securing our digital environments.”

INE Security has been recognized among the best cybersecurity training platform in 2024 by numerous organizations including:

•G2 as an online course provider and technical training provider

•G2’s 2024 Best Software Awards for Education Products

•Security Boulevard’s list of the Top 10 Hacking Certifications for both the Certified Professional Penetration Tester (eCPPT) and Web Application Penetration Tester eXtreme (eWPTX) certifications

The SC Awards were evaluated by a distinguished panel of judges, including cybersecurity professionals, industry leaders, and members of the CyberRisk Alliance community from sectors such as healthcare, financial services, education, and technology.

The full list of 2024 SC Awards winners: https://www.scmagazine.com/sc-awards

About INE Security: INE Security is the premier provider of online networking and cybersecurity training and certification. Harnessing a powerful hands-on lab platform, cutting-edge technology, a global video distribution network, and world-class instructors, INE Security is the top training choice for Fortune 500 companies worldwide for cybersecurity training in business and for IT professionals looking to advance their careers. INE Security’s suite of learning paths offers an incomparable depth of expertise across cybersecurity and is committed to delivering advanced technical training while also lowering the barriers worldwide for those looking to enter and excel in an IT career.

About CyberRisk Alliance: CyberRisk Alliance provides business intelligence that helps the cybersecurity ecosystem connect, share knowledge, accelerate careers, and make smarter and faster decisions. Through their trusted information brands, network of experts, and more than 250 innovative annual events we provide cybersecurity professionals with actionable insights and act as a powerful extension of cybersecurity marketing teams. Their brands include SC Media, the Official Cybersecurity Summits, Security Weekly, InfoSec World, Identiverse, CyberRisk Collaborative, ChannelE2E, MSSP Alert, LaunchTech Communications and TECHEXPO Top Secret.

Media contact: Kathryn Brown, Director of Global Strategic Communications and Events, INE Security, kbrown@ine.com

The post News alert: INE Security’s cybersecurity training service earns 2024 SC Excellence Award first appeared on The Last Watchdog.

View Details

Boston, Mass., Sept. 18, 2024] — One Layer, the leader in managing and securing enterprise private 5G/LTE Operational Technology (OT) networks, announced today the selection of its OneLayer Bridge private LTE network device management and zero trust security platform by energy provider Evergy, in a multi-year deal.

Evergy has innovatively embraced Ericsson’s private LTE technology to elevate operational performance. They recently completed their transition from pilot and testing to preparations for a comprehensive rollout for operational use. Evergy chose OneLayer’s solution to manage and secure devices in their facilities and across their electricity grid in the U.S. Evergy’s fast-growing private LTE cellular networks use thousands of devices today, including Internet of Things (IoT) sensors, smart meters, OT and other cellular devices. In the next few years, the number of devices is planned to scale to the tens of thousands.

“With this widespread rollout, we needed a way to manage the growing number of OT devices using our private cellular network,” says J.J. Stutler, Manager, Wireless Engineering & Operations at Evergy. “We required automation and delegation of various device onboarding steps to different Evergy teams, alongside complete visibility to all devices at all times. OneLayer did all of that, in addition to providing operations and security frameworks for our private LTE networks and connected devices. With OneLayer, Evergy is now better equipped to deliver reliable power to customers and fulfill the potential of its strategic sustainability transformation plan for its customers and stakeholders.”

The implementation of OneLayer’s platform is projected to result in substantial savings for Evergy in the areas of asset management, operations and network management.

OneLayer’s asset management capabilities enhance Evergy’s operational efficiency by automating device onboarding, provisioning, profiling, classifying and activation. OneLayer enables delegating onboarding steps to different teams, enabling Evergy to scale their network effectively by creating autonomy for different Evergy teams, alongside maintaining oversight of what devices are onboarded. Visibility and tracking of every individual device connected to the network – even non-cellular devices connected via cellular routers – enable Evergy to assess performance and uptime of devices and routers, conduct vendor comparisons at scale and adjust Quality of Service (QoS) dynamically for different groups of devices or situations.

As a player in critical national infrastructure, Evergy requires strict security. OneLayer provides Evergy with end-to-end zero-trust security that seamlessly extends Evergy’s existing security frameworks, established segmentation standards and regulatory requirements to the private LTE domain. OneLayer Bridge’s OT/IoT asset discovery and tracking, geofencing, anomaly detection and mitigation functionalities significantly reduce Evergy’s attack surface and enable swift remediation of any potential problems.

Mor

“OneLayer sees Evergy’s team as visionaries, professionals, mission-oriented, and focused on their business needs,” explains Dave Mor, OneLayer CEO. “OneLayer is here to support Evergy’s journey to success. Our maintenance of strong relationships with private LTE vendors, like Ericsson and CPE vendors ensures continuous support for upgraded products and enhanced capabilities. This approach allows Evergy to benefit not only from existing efficiencies but also to stay prepared for evolving challenges and opportunities in the private LTE landscape.”

About OneLayer: OneLayer brings complete visibility, asset management, and zero-trust security to all devices connected to private LTE and 5G networks. All activities are tracked to orchestrate and secure the environment. Through OneLayer’s solution, enterprises get complete asset management and operational intelligence capabilities to maximize operational excellence and zero-trust security to prevent cellular breaches. The platform enables enterprises to treat their private cellular network as another enterprise network without the need to be cellular experts. To learn more about OneLayer, please visit www.onelayer.com.

The post News alert: Evergy selects OneLayer to manage, secure its private cellular OT assets first appeared on The Last Watchdog.

View Details

Boston, MA, Sept. 16, 2024, CyberNewsWire — Entro Security, pioneer of the award-winning Non-Human Identity (NHI) and Secrets Management platform, today released its research report, “2025 State of Non-Human Identities and Secrets in Cybersecurity.”

The Entro Security Lab found that 97% of NHIs have excessive privileges increasing unauthorized access and broadening the attack surface, and 92% of organizations are exposing NHIs to third parties, also resulting in unauthorized access if third-party security practices are not aligned with organizational standards.

Surprisingly, 44% of tokens are exposed in the wild, being sent or stored over platforms like Teams, Jira tickets, Confluence pages, code commits and more. Such practices put sensitive information at serious risk of being intercepted and exposed–the root of all secrets and non-human identity breaches.

Entro Security Labs’ research reveals alarming trends in the handling of both human and NHIs, with significant misconfigurations and risks prevalent across organizations. Key findings include:

•For each human identity, there are an average of 92 non-human identities. An overwhelming number of non-human identities increases the complexity of identity management and the potential for security vulnerabilities

•91% of former employee tokens remain active, leaving organizations vulnerable to potential security breaches

•50% of organizations are onboarding new vaults without proper security approval which can introduce vulnerabilities and misconfigurations from the outset

•73% of vaults are misconfigured, also leading to unauthorized access and exposure of sensitive data and compromised systems

•60% of NHIs are being overused, with the same NHI being utilized by more than one application, increasing the risk of a single point of failure and widespread compromise if exposed

•62% of all secrets are duplicated and stored in multiple locations, causing unnecessary redundancy and increasing the risk of accidental exposure

•71% of non-human identities are not rotated within the recommended time frames, increasing the risk of compromise over time

Additional findings are discussed in the report and reveal a critical need for organizations to reassess their NHIs and secrets management practices.

Data from this report has been collected using a mixed-methods approach, integrating quantitative data analysis with qualitative insights derived from industry observations. The quantitative component focuses on statistical analysis of security incidents and vulnerabilities, while the qualitative aspect provides context and interpretation of these findings within the broader cybersecurity landscape. The data sources include proprietary data from Entro’s cybersecurity infrastructure, secondary data from publicly available industry reports and survey data from IT and security professionals.

Entro’s complete research report on non-human identities is available on their website.

To learn more or schedule a demo, please visit https://entro.security/demo/.

About Entro Security: An award-winning pioneer platform, Entro Security provides Non-Human Identity Lifecycle Management, Secrets Security and Non-Human Identity Detection and Response. Unlike traditional methods that reactively scan for exposed secrets, Entro integrates seamlessly within an organization’s existing vaults, and secret creation and exposure locations, offering a single pane of glass to securely use and manage non-human identities and secrets at scale. Headquartered in Boston and backed by top cybersecurity VCs, Entro was named a Cool Vendor by Gartner, Venafi’s Most Promising Machine Identity startup and is a 2023 Globee Awards Winner for Startup Achievement of the Year. For more information, please visit https://www.entro.security.

Media contact: Hannah Sather, Senior Account Executive, Montner Tech PR, hsather@montner.com

The post News alert: Entro Security Labs report reveals pervasive exposures in ‘Non-Human Identities’ first appeared on The Last Watchdog.

View Details

Silver Spring, MD, Sept.12, 2024, CyberNewsWire – Aembit, the leading non-human identity and access management (IAM) company, has secured $25 million in Series A funding, bringing its total capital raised to nearly $45 million. Acrew Capital led the round, with participation from existing investors Ballistic Ventures, Ten Eleven Ventures, Okta Ventures, and CrowdStrike Falcon Fund.

Aembit’s funding comes in the wake of continued high-profile non-human identity attacks on organizations such as Cloudflare, The New York Times, and Microsoft. Non-human identity (NHI) refers to the applications, scripts, and bots that businesses use to automate their operations, as well as the credentials used by NHIs to communicate to sensitive databases, applications, and infrastructure.

These incidents exposed secrets such as API keys, access tokens, and other non-human access credentials, which were used to penetrate enterprise environments. In a newly published survey of security professionals, Aembit found that most organizations still struggle with managing NHI credentials securely: Over 30% still storing credentials in code, and 23% using email and chat to share credentials. Over 60% of respondents are looking for a comprehensive solution across their entire organization.

Security professionals are recognizing the need for an access-focused approach that automates identity-driven, secretless, centrally enforced, and auditable access between distributed applications and SaaS services to sensitive resources in the cloud and on-premises.

Aembit has led the market in solving this emerging challenge by pioneering non-human IAM. It enables policy-based access management between workloads and the sensitive resources they access, moving beyond reactive visibility and governance to proactively shrink the attack surface of rapidly growing and highly distributed non-human identities. Aembit was recently lauded as a Top 2 finalist in the prestigious 2024 RSA Innovation Sandbox competition and is a finalist for Best Identity Management Solution at the 2024 SC Awards. Aembit continues to advance access management with capabilities such as MFA-strength conditional access, policy automation via infrastructure-as-code, and robust auditing for NHI access.

“Aembit is tackling one of the most pressing challenges in modern enterprise security,” said Mark Kraynak, founding partner at Acrew Capital. “The shift to cloud and SaaS, and AI has driven an order-of-magnitude expansion in non-human identities. With the proliferation of microservices and APIs across diverse environments, IAM has become the critical first line of defense for protecting sensitive data. Legacy access management approaches weren’t designed with this level of scale and automation in mind. We are thrilled to be partnering with Aembit to bring a new approach to the market.”

Co-Founders David Goldschlag and Kevin Sapp have spent their careers innovating across the identity landscape, most recently creating New Edge Labs (acquired by Netskope), one of the first user zero trust products on the market.

Goldschlag

“Kevin and I founded Aembit with a vision to help enterprises secure access between non-human workloads, applications, and software resources with the same principles used today to secure human access,” said David Goldschlag, co-founder and CEO of Aembit. “Talking to hundreds of enterprises, and working closely with design partners, our approach centers on proactively securing access between non-human identities, while eliminating friction for developers and security teams.”

“By solving non-human IAM, Aembit is tackling an essential security challenge,” said Brad Jones, CISO at Snowflake and an Aembit customer. “Not only is their approach to non-human access innovative, but Aembit is a provider we can rely on.”

The Aembit Workload IAM Platform enforces secure access between non-human workloads and the services that authorize access to sensitive data and infrastructure. Aembit’s policy engine grants secretless access, just-in-time, based on the workload’s identity and posture.

Leveraging native identities and sophisticated automation, organizations use Aembit to eliminate storage of sensitive secrets within applications or vaults by moving to short-lived access tokens with a no-code auth approach. With Aembit, businesses proactively secure non-human access while eliminating the manual and fragmented work required today by security, engineering, and DevSecOps teams.

About Aembit: Aembit is the non-human identity and access management platform that secures access between workloads across clouds, SaaS, and data centers. With Aembit’s identity control plane, DevSecOps can fully automate secretless, policy-based, and Zero Trust workload access with MFA-strength capabilities. For more information, users can visit https://aembit.io/ and follow us on LinkedIn.

Media contact: Apurva Davé, CMO, Aembit, info@aembit.io

The post News alert: Aembit raises $25M Series A funding for non-human Identity and Access Management first appeared on The Last Watchdog.

View Details

Torrance, Calif., Sept. 11, 2024, CyberNewsWire — Criminal IP, a distinguished leader in Cyber Threat Intelligence (CTI) search engine developed by AI SPERA, announced that it has successfully integrated its IP address-related risk detection data with IPLocation.io, one of the most visited IP analysis and lookup tools on the internet.

Through the integration, IPLocation.io, a prominent IP address geolocation tracker platform with a substantial user base, now offers more detailed insights on IP addresses from Criminal IP’s accurate and up-to-date threat intelligence database.

Innovative data ecosystem

This is a groundbreaking advancement because Criminal IP’s database, built on a search engine framework, is more than a collection of information; it’s a refined machine learning ecosystem honed through extensive scanning and detection of malicious IP addresses. The system continuously enhances its accuracy by transforming self-collected threat data, particularly behavioral patterns for IP address evasion, into actionable intelligence using AI and machine learning techniques.

Comprehensive IP tracking

Unlike traditional IP tracking methods, which only provide the geographic location of IP addresses, Criminal IP data in IPLocation.io now delivers information from ‘Snort’, a network intrusion detection system, and vulnerability scanners on open ports.

This, along with newly provided inbound and outbound scores of IP addresses, enables the comprehensive identification of threat information related to IP addresses. Users can now compile the information themselves to assess the risk of an IP address, supported by a variety of fact-based evidence.

Among IP Location Lookup data sources, Criminal IP provides the most comprehensive data, offering 25 distinct data points for a single IP address.

Unveiling attack scenarios

Users can also detect IP address obfuscation and protect their assets with new VPN, Proxy, and Tor data in IP Location. The aforementioned data helps identify discrepancies between actual and reported locations of an IP address, as well as traffic routed through multiple servers, thus revealing potential threats. The system goes beyond a mere review of past records; it offers predictive insights into future risks by analyzing behavioral patterns and potential attack scenarios. This underscores the CTI database’s distinctive capability to continuously learn and analyze attack patterns executed online.

About AI SPERA: AI SPERA equips cybersecurity professionals with advanced tools and insights to protect digital assets. Its flagship products include Criminal IP, renowned for its AI-based search engine, as well as attack surface management and fraud detection for enterprise solutions. The firm’s established presence in major marketplaces like AWS and Snowflake further underscores its credibility and the trust placed in its services by leading industry players. Recently, AI SPERA achieved Level 1 certification under PCI DSS v4.0, overseen by the six leading global card issuers, showcasing its commitment to top-tier data security.

Media contact: Michael Sena, AI SPERA, support@aispera.com

The post News alert: Criminal IP partners with IPLocation.io to deliver new tech to mitigate IP address evasion first appeared on The Last Watchdog.

View Details

Palo Alto, Calif., Sept.11, 2024, CyberNewsWire — Opus Security, the leader in unified cloud-native remediation, today announced the launch of its Advanced Multi-Layered Prioritization Engine, designed to revolutionize how organizations manage, prioritize and remediate security vulnerabilities.

Leveraging AI-driven intelligence, deep contextual data and automated decision-making capabilities, this innovative engine helps organizations prioritize the most critical vulnerabilities, enhancing both security posture and operational efficiency.

Remediation breakthrough

Security teams are overwhelmed by the need to rapidly prioritize alerts from multiple tools across various attack surfaces. These may include redundant alerts or negligible findings and teams must decide which to address first without adequate information, context and ability to do so. Security teams struggle to identify and address the most critical issues, and developers have limited time and scope to devote to security fixes—especially when it isn’t clear what is important and what is negligible. Developers are often bombarded with alerts that are duplicates or irrelevant due to inefficient prioritization—wasting time and increasing friction and frustration.

Opus Security’s Advanced Multi-Layered Prioritization Engine is a transformative approach to vulnerability management. By integrating multiple layers of intelligence, contextual analysis and risk mitigation, the engine ensures that security teams can effectively prioritize and address the most critical vulnerabilities, reducing risk, enhancing operational efficiency and supporting overall business goals. The engine integrates traditional vulnerability severity scoring with dynamic exploitability analysis, detailed environmental context and an automated decision-making process to provide a robust method for ranking vulnerabilities.

A key component of this engine is the AI-Based Vulnerability Intelligence Layer, which goes beyond traditional severity scoring. This layer leverages over 700 real-time threat intelligence feeds to build a deep and nuanced understanding of each vulnerability’s risk. By incorporating intelligence from sources such as dark web forums, social media, open-source tools, exploit databases and active threat campaigns, the engine can flag high-risk issues with unparalleled accuracy. This intelligence-driven approach ensures that organizations are aware of vulnerabilities and their likelihood of exploitation in the wild, allowing for proactive and informed remediation efforts.

Using a five-layered framework, the engine first performs a Base Severity Assessment, aggregating severity scores from leading security tools and public databases to ensure that no critical vulnerabilities are overlooked. Next, the AI-Based Vulnerability Intelligence layer leverages real-time threat intelligence to flag high-risk issues based on their likelihood of exploitation.

The Contextual Impact layer then prioritizes vulnerabilities according to their relevance to specific business functions, protecting critical systems first, especially those that handle sensitive data. The engine is the first to enable real SSVC decision-making, fully baked into the product. This helps teams categorize vulnerabilities into specific response actions based on the affected environment’s severity, exploitability and criticality. Finally, the Risk Customization layer allows organizations to tailor prioritization according to their unique risk appetite and operational needs.

Additionally, Opus Security introduces Effortless Data Querying, allowing users to interact with the platform using natural language. This feature enables users to quickly refine vulnerability lists based on specific concerns and make precise, data-driven decisions by leveraging advanced AI-powered insights.

Driving operational excellence

The engine’s multi-layered approach ensures unprecedented precision in risk management by integrating real-time intelligence with detailed contextual analysis. This integration enables SSVC decision-making, allowing security teams to focus on vulnerabilities that truly matter, reducing the likelihood of overlooking critical vulnerabilities.

Opus aligns security decisions with business priorities by deeply understanding the organization’s structure, critical services and risk profiles, driving context-aware decision-making that protects critical assets and directly supports strategic goals.

Har

“Opus’ new Advanced Multi-Layered Prioritization Engine is a game-changer in vulnerability remediation, simplifying, streamlining and optimizing the process considerably. The engine’s ability to prioritize the vulnerabilities that pose the greatest risk reduces overall security costs and helps security and developer teams avoid unnecessary remediation of low-risk issues,” said Meny Har, CEO of Opus Security. “Minimizing friction between development and security teams, driving smoother collaboration and ensuring that security measures do not impede the development process means that all teams can focus on what matters and fix what counts.”

About Opus Security: Opus Security is at the forefront of cloud-native vulnerability remediation, delivering solutions that streamline remediation across complex IT ecosystems. Opus Security provides unparalleled visibility and control over vulnerabilities by integrating existing security tools and enhancing them with advanced AI and contextual intelligence. The platform’s innovative features, including the new Advanced Multi-Layered Prioritization Engine, empower organizations to protect their most critical assets with confidence and precision. For more information about Opus Security and its solutions, visit https://www.opus.security/.

Media contact: Hannah Sather, Senior Account Executive, Montner Tech PR
hsather@montner.com

The post News alert: Opus Security’s new ‘Advanced Multi-Layered Prioritization Engine’ elevates VM first appeared on The Last Watchdog.

View Details

President Biden’s call for the mainstreaming of Software Bill of Materials (SBOMs) is a major step forward.

Related: Europe mandates resiliency

Requiring a formal inventory of all components, libraries and modules in all business applications can help lock down software supply chains, especially in light of the SolarWinds and Colonial Pipeline attacks.

Yet SBOMs will take us only so far. I had a deep discussion about this at Black Hat USA 2024 with Saša Zdjelar, Chief Trust Officer at ReversingLabs (RL). He drew a vivid parallel between food safety and software security. For a full drill down, please give the accompanying podcast a listen.

An SBOM is like an ingredients list, not a recipe for a gourmet dish, Zdjelar argues. Similarly, SBOMs in and of themselves do little to flush out anomalies arising in the wild. In short, SBOMs do not take context into account, he noted.

Context is fast becoming king in cybersecurity. Contextual solutions are more like recipes for securing business networks in a cloud-centric, hyper-interconnected operating environment – without unduly taxing efficiency or user experience.

RL Spectra Assure, for instance, provides context by performing deep analyses of binary code. This technology doesn’t just identify the ingredients in software, it also analyzes how those ingredients — such as third-party components, open-source libraries and other types of dependencies — interact. In doing so, Spectra Assure does what SBOMs cannot, identify malware or tampering. before an application is released or deployed

And it does this in real time by integrating into continuous integration/continuous deployment (CI/CD) workflows for software producers. Or in the case of enterprise buyers, on-demand scanning of commercial software provides a consistently up-to-date view of application risk before deployment or as new updates are made. This is a prime example of contextual security gaining ground in a massively complex, highly dynamic operating environment.

We need a lot more of it. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post Black Hat Fireside Chat: Why grasping the context of code is a recipe for keeping software secure first appeared on The Last Watchdog.

View Details

Cary, NC, Aug. 16, 2024, CyberNewsWire — The imminent release of Cisco HyperShield this month marks a pivotal evolution in the cybersecurity landscape.

As an “AI-native” security architecture, HyperShield promises to redefine traditional security protocols through its automated proactive cybersecurity measures and AI-driven security solutions. However, the effectiveness of this sophisticated technology heavily relies on the skilled deployment by IT and Information Security (IS) teams, emphasizing the critical importance of specialized training in this high-tech environment.

Effective AI security

HyperShield’s introduction into the cybersecurity arena brings a suite of advanced capabilities centered around AI-powered security systems and IT security automation. This transformative approach will result in a profound shift in how security teams operate, moving from manual control of qualifying and applying new security updates, to instead overseeing and fine-tuning automated AI responses. However, to successfully harness the full potential of HyperShield’s distributed proactive network security measures, comprehensive training is essential.

“HyperShield’s introduction is a game-changer for network security,” said Brian McGahan, CCIE Security and Director of Networking Content for INE Security, a global leader in networking and cybersecurity training and certifications. “The shift to AI-driven security architectures will require a new way of thinking, and it’s become more critical than ever that organizations equip their teams with the right training to fully leverage these new technologies. We need to ensure that security teams are not just familiar with their functionalities but are also trained in using these tools to proactively secure our networks.”

Training programs must not only cover the operational aspects of these new technologies but also foster a deep understanding of Security Orchestration, Automation, and Response (SOAR), which is integral to managing the sophisticated ecosystems in which solutions like HyperShield operate. This will ensure that security teams can effectively manage AI-scale data centers, and effectively operate security solutions across both public & private clouds, maintaining robust security across increasingly complex networks.

Securing business continuity

The role of IT/IS training extends beyond mere operational competence. Comprehensive training directly influences business continuity by equipping teams with the knowledge to implement and leverage autonomous segmentation and distributed exploit protection inherent to cutting edge solutions such as HyperShield.

Training can help to minimize human error—a significant factor in security breaches—by ensuring that teams can proactively manage and respond to emerging threats with minimal human intervention.

Inadequate training could lead to underutilization of these new solutions’ capabilities, potentially leaving enterprises vulnerable to sophisticated cyberattacks. On the other hand, well-trained teams can fully leverage the benefits of AI-driven security, for example using HyperShield’s capabilities to preemptively address vulnerabilities and enhance the overall security posture of the organization.

Automation, human oversight

Despite the advanced automation capabilities of AI-driven solutions like HyperShield, the need for human oversight persists. Today’s security personnel must be skilled at interpreting AI decisions and actions, particularly when integrating these new solutions into existing security architectures. Training in compensating controls and the system’s security solutions is crucial for managing the balance between automated responses and necessary human intervention.

Additionally, training should address the continuous adaptation required in the cybersecurity field, enabling teams to stay current with both AI-based updates and evolving cyber threats. Ongoing education helps to maintain operational resilience and ensures that proactive security measures keep pace with the needs of a dynamic security environment.

As we reimagine security with the rollout of Cisco HyperShield, the spotlight turns not just to the technology itself, but also to the professionals tasked with its deployment. The investment in comprehensive IT/IS training is not just beneficial—it’s imperative for leveraging the full spectrum of capabilities offered by new AI-driven security solutions. Effective training empowers security teams to minimize risks and secure business operations against the sophisticated threats of today and tomorrow. With Cisco HyperShield, businesses have the opportunity to elevate their cybersecurity measures, but only if their teams are prepared to lead this charge effectively.

About INE Security: INE Security is the premier provider of online networking and cybersecurity training and certification. Harnessing a powerful hands-on lab platform, cutting-edge technology, a global video distribution network, and world-class instructors, INE Security is the top training choice for Fortune 500 companies worldwide for cybersecurity training in business and for IT professionals looking to advance their careers. INE Security’s suite of learning paths offers an incomparable depth of expertise across cybersecurity and is committed to delivering advanced technical training while also lowering the barriers worldwide for those looking to enter and excel in an IT career.

Media contact: Kathryn Brown, Director of Global Strategic Communications and Events, INE Security, kbrown@ine.com

The post News alert: Implementing AI-powered ‘Cisco HyperShield’ requires proper cybersecurity training first appeared on The Last Watchdog.

View Details

Application Security Posture Management (ASPM) arose a few years ago as a strategy to help software developers and security teams continually improve the security of business applications.

Related: Addressing rising cyber compliance pressures

At Black Hat USA 2024, an iteration called Active ASPM is in the spotlight. I had the chance to visit with Neatsun Ziv, CEO and co-founder of Tel Aviv-based OX Security, a leading Active ASPM solutions provider.

I learned all about how Active ASPM emphasizes continuous, real-time monitoring and proactive remediation, thereby augmenting more passive ASPM methods, if you will, that focus on data aggregation and periodic assessments, Ziv told me. For a full drill down, please give the accompanying podcast a listen.

For its part, OX Security does this by going the extra mile to provide rich, detailed context that enables security teams to do triage more effectively – and CISOs to justify, with hard evidence, why resources need to be directed at specific security improvements.

This heavy lifting gets done, he says, by “going into the code and reading the code myself. I’m going to connect to the cloud, read the configurations and read the active assets you’ve got in your cloud. I’m going to connect to your artifact registry and scan what’s in there. I’m going to connect to your existing tools, understand what’s in there, and basically use every asset that you have inside your organization to provide the best and most accurate answer to the question, ‘Are you right now at risk? If so, let me guide you through the process of getting to a safer place.’ “

How high might Active ASPM move the bar, going forward? I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post Black Hat Fireside Chat: Here’s how ‘Active ASPM’ is helping to triage and remediate coding flaws first appeared on The Last Watchdog.

View Details

Torrance, Calif., Aug. 12, 2024, CyberNewsWire — Criminal IP, an expanding Cyber Threat Intelligence (CTI) search engine from AI SPERA, has recently completed its technology integration with Maltego, a global all-in-one investigation platform that specializes in visualized analysis of combined cyber data.

This collaboration integrates Criminal IP’s comprehensive database of malicious IPs, domains, and CVEs directly into Maltego’s unified user interface and adds Criminal IP to Maltego’s marketplace, Transform Hub.

Maltego translates Criminal IP data into a visual data graph, allowing users to easily recognize relationships between each entity and associated risks by adjusting the layouts and assigning weights to them.

Visualizing breakthrough

Now through its partnership with Criminal IP, its trusted data source and an OSINT CTI tool, Maltego users can also harness Criminal IP’s comprehensive threat intelligence search functionalities to instantly visualize data.

New key features in Maltego allow users to visualize vulnerabilities by importing Criminal IP’s comprehensive data, including CVEs, assets’ reputation, botnets, Command & Control servers (C2), domain phishing information, and more.

They can also track exposed personal information in banner data, such as API keys, token values, bank account numbers, and Bitcoin wallet addresses, ensuring prompt identification.

The tool visually verifies relationships between IP addresses and domains, facilitating rapid response and effective threat tracking.

Single interface integration

Maltego is an integration platform with a high impact on the field of threat intelligence and has integrations with several well-known products, including Microsoft Sentinel, IBM QRadar, and Google Maps Geocoding.

Its existing features drastically accelerate complex cyber investigation by enabling quick preliminary OSINT investigations for digital profiling with Maltego Search as well as complex link analysis for large datasets with Maltego Graph.

Through Maltego Evidence and Maltego Monitor, the platform enables investigators to collect, monitor, and preserve social media intelligence in real time for prosecution and public safety.

About AI SPERA: AI SPERA, renowned for its advanced solutions, has expanded internationally with ‘Criminal IP’ as its flagship offering. Operating in 150+ countries, ‘Criminal IP’ is backed by enterprise-grade security solutions like ‘Criminal IP ASM’ and ‘Criminal IP FDS’. Strategic partnerships with global leaders such as Cisco, VirusTotal, and Quad9 have significantly enhanced ‘Criminal IP’s capabilities. Recently, AI SPERA’s ‘Criminal IP’ has entered the marketplace of major US data warehousing platforms including Amazon Web Services (AWS), Microsoft Azure, and Snowflake, expanding its global reach for threat data.

Media contact: Michael Sena, AI SPERA, support@aispera.com

The post News alert: Criminal IP and Maltego team up to broaden threat intelligence data search first appeared on The Last Watchdog.

View Details

LAS VEGAS – Here’s what I discovered last week at Black Hat USA 2024: GenAI is very much in the mix as a potent X-factor in cybersecurity.

Related: Prioritizing digital resiliency

I spoke with over three dozen cybersecurity solution providers. Some of the more intriguing innovations had to do with leveraging GenAI/LLM-equipped chatbots as proprietary force multipliers.

This is all part of Generative AI and Large Language Models igniting the next massive technological disruption globally. In the next five years, GenAI/LLM deployments are expected to add $2.6 to $4.4 trillion annually across more than 60 use cases, according to a recent McKinsey study; a recent AWS survey predicts that over 93% of employers will use GenAI/LLM to increase innovation and creativity, automate repetitive tasks and boost learning.

Part of this tech revolution will play out in the cybersecurity sector as vendors perfect ways to assign GenAI/LLM to the task of helping companies get a better grip on data sprawl. Massive, indiscriminate ingestion of data was an intractable mess long before this mad scramble to insert AI assistants high and low in company operations.

“AI thrives on large datasets, “Steve Stone, head of Rubrik Zero Labs told me. “When you add AI into the mix, it further intensifies the challenge of managing data sprawl and the associated risks.”

Ditto when it comes to detection sprawl, if you will. I’m referring to the proliferation of fragmented, siloed security systems. “Managing all of that telemetry, bringing it together, prioritizing the alerts and remediating them, well, that’s where things break in the real world,” observes Willy Leichter, CMO of AppSOC.

Roger that. Just ask CrowdStrike. After strolling the exhibits floor at Black Hat USA 2024 and speaking with the solution providers, I jotted down two categories of cybersecurity advancements that will be crucial to tempering data sprawl and detection sprawl, going forward: ‘coding level’ and ‘operational level.’ Highlights of what I learned:

Coding level innovation

The continual monitoring and hardening of business software as it is being rapidly developed, tested and deployed in the field has become a foundational best practice. When it comes to the broad category of Application Security (AppSec,) there’s a lot is going on.

AppSec technology security-hardens software at the coding level. Then there’s the sub-category of application security posture management (ASPM.) ASPM toolsets came along in 2020 or so to help organizations get more organized about monitoring and updating code security as part of meeting data privacy and security regulations.

Big name tech vendors like Palo Alto Networks, Cisco, IBM and even CrowdStrike have since integrated ASPM services in their platform offerings. And alongside them there is a thriving cottage industry of independent ASPM solution providers. I spoke at length with three of them: AppSOC, Cycode and OX Security.

San Jose, Calif.-based AppSOC launched in 2021 to aggregate, consolidate and prioritize security data from various toolsets used in the software development lifecycle (SDLC). AppSOC leverages AI to reduce the noise from multiple data sources and intelligently prioritizes vulnerabilities based on exploitability and business impact, Leichter told me.

Meanwhile, Tel Aviv, Israel-based Cycode started in 2019 to deliver a secrets detection service; it subsequently evolved into supplying advanced ASPM technology, says regional sales manager Kyle Vanderzanden. Cycode uses dedicated, in-house scanners to vet code within the hectic flow of the software development and deployment processes so as to not slow down innovation, he says

I also hosted a LW Fireside Chat podcast with OX Security CEO Neatsun Ziv. We did as deep dive on the evolution of ASPM solutions over the past four years and we discussed so-called Active ASPM; give a listen to the podcast, which is on track to go live as LW’s Top Story tomorrow (Aug. 13.)

I’d also put San Francisco-based Traceable and Cambridge, Mass.-based ReversingLabs in the bucket of coding-level solution providers at the leading edge. In my LW Fireside Chat with Traceable’s Amod Gupta, which you can listen to here, we dissect the reasons why API Security is so effective at mitigating online fraud; we also spoke about the emerging need to help enterprises secure their GenAI deployments.

And stay tuned for my upcoming LW Fireside Chat with ReversingLabs Chief Trust Officer Saša Zdjelar, in which he describes ReversingLabs’ unique approach to deeply vetting new code in a way that greatly enhances Software Build of Materials (SBOMs.)

Operational level innovation

It’s not enough, of course, to do security well at just the coding level. Multiple layers of proactive protection are required to achieve resiliency in a massively complex, highly dynamic operating environment.

This includes hardware security. I spoke to Brett Hansen, CMO, of Cigent Technology, and John Gunn, CEO of Token, about discreet security devices at the hardware layer: for remote data storage and privileged access, respectively

Based in Naples, Fla.- Cigent provides security-enhanced SSDs and microSDs. Its solution includes hardware encryption, software-based multi-factor authentication, and AI-driven anomaly detection within the storage itself, Hansen noted.

New York, NY-based Token is on the verge of introducing a very unique wearable – a smart security ring activates by a fingerprint sensor and hardened to make it hackproof. For starters the ring is aimed at system administrators and senior executives, but could eventually go mainstream. For a full drill down, give a listen to my LW Fireside Chat podcast discussion with Gunn.

Yet another layer – easily the most porous one — is the user layer. And by far the three most ubiquitous user interfaces are web browse, mobile devices and email.

Island’s Uy Huynh and I discussed how enterprise browsers are gaining traction because of advanced methods to both enhance security and improve efficiency. I visited with Appdome CEO Tom Tovar to discuss the somewhat surprising, to me at least, results of a global consumer survey highlighting smartphone users’ readiness to abandon brands associated with poorly secured mobile apps.

And I sat down with Eyal Benishti, CEO of IRONSCALES for a deep dive discussion about how human-AI collaboration is mitigating email threats in a profound way.

I also heard from San Francisco-based Horizon3.ai, which announced a strategic partnership with Tech Mahindra, a major India-based multinational tech services company.

Horizon3 will integrate its its NodeZero™ platform, which delivers AI-powered pentesting and other services, with Tech Mahindra’s comprehensive suite of cybersecurity services.

And I learned all about Washington D.C.-based Black Girls Hack and London-based Security Blue Team. These organizations are taking a fresh approach to filling a big unmet need. Give a listen to my conversation with BGH founder Tennisha Martin about the support services they offer to anyone looking to enter or move over to a cybersecurity career. And I also spoke with Melissa Boyle, marketing manager at Security Blue Team, about the array of free and paid cybersecurity skills training services.

Those are my big takeaways from Black Hat USA 2024. Much percolating. As always, I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


The post MY TAKE: Black Hat USA 2024’s big takeaway – GenAI factors into the quest for digital resiliency first appeared on The Last Watchdog.

View Details

LAS VEGAS — As Black Hat USA 2024 plays out here this week, the disruptive impact of GenAI/LLM at many different levels will be in the spotlight.

Related: GenAI introduces fresh risks

We’re in early days. The productivity gains are ramping up – but so are the exposures.

I had the chance to visit with Amod Gupta, head of product at Traceable; we discussed how GenAI/LLM is reverberating at the API level, where hyper-interconnectivity continues to intensify. For a full drill down, please give the accompanying podcast a listen.

Companies in all industries are racing to deploy GenAI/LLM chatbot assistants to improve efficiencies and boost revenue. This includes cybersecurity solution providers jumping on the bandwagon to enhance their tools and services.

At this moment, there’s a huge challenge securing the data transmitted via application programming interfaces (APIs) to and from all the novel chatbot assistants, Gupta told me. It’s only a matter of time, he says, before threat actors discover fresh ways to siphon off sensitive data.

Beyond that, other types of threats pivoting off APIs, such as prompt injection attacks, seem certain to escalate. Traceable is keeping close tabs via the installed base of its advanced API security platform. Meanwhile, it, too, is examining ways to leverage GenAI/LLM to reinforce security.

For instance, Gupta described a scenario where a security team member might use a GenAI/LLM assistant to run customized analyses of a unique vulnerability disclosure or perhaps a suspicious pattern of API activity. “Instead of spending hours sifting through data, an analyst or even a technician could ask our GenAI assistant to perform the heavy lifting,” he says.

How quickly might GenAI/LLM arise as a defacto force-multiplier across cybersecurity? I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


The post Black Hat Fireside Chat: The role of API Security in mitigating online fraud, emerging GenAI risks first appeared on The Last Watchdog.

View Details

LAS VEGAS — Humans, unsurprisingly, remain the weak link in cybersecurity.

Related: Digital identity best practices

We’re gullible – and we can’t get away from relying on usernames and passwords.

Steady advances in software and hardware mechanisms to secure identities and privileged access have helped; yet crippling network breaches that start by fooling or spoofing a single human user continue to proliferate.

As Black Hat USA 2024 gets underway here this week, a start-up called Token is getting a step closer to rolling out a new hardware solution – a ring with a biometric sensor – that is designed to shore up this exposure. I had the chance to sit down with Token CEO John Gunn to learn all about this. For a drill down, please give the accompanying podcast a listen.

We discussed how one-time passwords (OTPs) and even smartphone biometric sensors have proven inadequate. Token’s solution combines the power of Public Key Infrastructure (PKI) with the convenience of wearable technology.

The ring contains a fingerprint sensor and holds a private encryption key; this information is stored on a tamper-proof microchip supplied by Infineon. Communication to laptops and smartphones is via NFC and Bluetooth.

“We looked at the important security advancements and asked how we could build upon them,” Gunn explains, adding that initial interest is coming from companies that will try them out on system administrators and senior execs.

What’s more Token’s next-generation MFA was recently honored with a Fast Company 2024 “World Changing Ideas” Award.

Will the Token ring be an incremental step – or might it be a great leap forward? I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


The post Black Hat Fireside Chat: Token’s wearable MFA solution combines PKI, biometrics — in a ring first appeared on The Last Watchdog.

View Details

When Tennisha Martin, a veteran software quality assurance analyst, sought to move over to a security team a few years ago, the doors should have been wide open, given the much-ballyhooed cybersecurity skills shortage.

Related: Modernizing security training

Instead, she ran into a rigid wall of shortsightedness. So, Martin taught herself ethical hacking skills and then founded Black Girls Hack to guide others down the trail she blazed.

As Black Hat USA 2024 rolls into high gear next week, BGH is thriving. The non-profit boasts 2,500 members globally (all genders and races) and has lined up top-tier corporate backers, led by Microsoft and Google, to back its programs.

What’s more, it is putting on a content-rich conference, SquadCon 2024, in parallel with Black Hat, at The Industrial Event Space in Vegas mid next week.

I had the chance to visit with Martin and BGH group leaders Tammy Hinkle and Rebekah Skeete; we discussed how BGH fosters a confidence-building community. Members get access to resources such as training vouchers and tools like RangeForce. And the only requirement is to “not be a jerk,” Martin says. For a full drill down, give a listen to the accompanying podcast.

BGH’s emphasis on diversity has the potential to be a game changer. In a hyper-interconnected operating environment, grasping the context of legit vs. malicious connections, on the fly, is vital.

So how much might a diverse security team contribute to staying on top of context in such a highly dynamic environment? I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


The post Black Hat Fireside Chat: ‘Black Girls Hack’ emphasizes diversity as effective force multiplier first appeared on The Last Watchdog.

View Details

Philadelphia, PA, Aug. 1, 2024, CyberNewsWire — Security Risk Advisors (SRA) announces the launch of VECTR Enterprise Edition, a premium version of its widely-used VECTR platform for purple teams and adversary management program reporting and benchmarking.

VECTR Enterprise is designed to support organizations that want to mature and communicate the success of their purple team exercises with benchmarking and executive reporting features.

Wainwright

“We’re excited to release VECTR Enterprise to help CISOs and their teams clearly tell the story of their adversary detection program strengths, needs, and changes over time. VECTR Enterprise brings new visuals and integrated benchmark insights to help the CISO communicate a critical and complex topic to senior stakeholders” said Security Risk Advisors CEO, Tim Wainwright.

VECTR Enterprise Edition will introduce several premium features including:

•Benchmark results: This feature provides context for test results and posture with industry peers. VECTR Enterprise integrates Security Risk Advisors’ Threat Resilience Benchmarks and data directly into the platform.

•Compare results: Users can compare their results across different environments and over time to understand how and why their threat resilience may change.

•Premium testing content: The platform provides access to testing “Indexes” for AWS, Azure, AI, Ransomware, Linux, Mac, Kubernetes, and more.

•Premium automated content: Enterprise Edition includes thoughtfully curated automated content based on emerging attacker threat intelligence. This approach balances automation with the need for realistic and “attacker authentic assessments.”

•SaaS by SRA: VECTR Enterprise is delivered as a SaaS service by Security Risk Advisors, including Single Sign-On (SSO), Attribute-Based Access Control (ABAC), upgrades and maintenance. This allows user teams to focus on testing, reporting, and remediation without additional burden on system administrators.

About VECTR: VECTR™ is developed and maintained by Security Risk Advisors. It is designed to guide, track, and report metrics and industry benchmarks from purple team exercises/adversary simulations. VECTR™ helps organizations improve their security posture by identifying gaps in attacker visibility and testing the effectiveness of their security controls. For more information about VECTR™ Enterprise Edition, please visit https://vectr.io.

About Security Risk Advisors: Security Risk Advisors offers Purple Teams, Cloud Security, Penetration Testing, Cyber-Physical Systems Security and 24x7x365 Cybersecurity Operations. Based in Philadelphia, SRA operates across the USA, Ireland and Australia. Learn more at https://sra.io.

Media contact: Douglas Webster, Marketing Manager, Security Risk Advisors, news@sra.io

The post News alert: Security Risk Advisors launchs VECTR Enterprise Edition for ‘purple team’ benchmarking first appeared on The Last Watchdog.

View Details

Two-plus decades of enduring wave after wave of mobile app malware and fraud has finally taken its toll on users.

Related: 6 scary mobile attacks

Now comes a global survey from Appdome and OWASP that reveals the vast majority of consumers are fed up.

I recently visited with Appdome CEO Tom Tovar to discuss clear signals that consumers are now insisting upon mobile apps that are private and secure, as well as convenient. For a full drill down, please give the accompanying podcast a listen.

As Black Hat USA 2024 gets ready to open next week in Las Vegas, this brings pressure to bear upon app developers – and on the top consumer brands — to do much better.

“Consumers are becoming highly sophisticated in their demands,” Tovar told me. “The fear that mobile app providers don’t care about their protection is now equivalent to the fear of the attackers themselves.”

Historically, developers and brands have prioritized innovation and competition over security. Yet consumers are now demanding much improved security – and mobile app providers would do well to make the adjustment.

Appdome’s poll reveals that 74 percent of consumers would abandon an app if they felt unprotected, while 95 percent would advocate for brands that provide strong security measures.

Consumers are demanding much better mobile app security; and they’re also willing to reward brands that deliver it. The good news is that technology is advancing, as well. Appdome, for instance, next week plans to unveil a new tool that leverages GenAI to help developers and brands embed security deeply and flexibly in apps.

Will these developments soon start to temper mobile app badness? I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post Black Hat Fireside Chat: Consumers demand secure mobile apps; it’s high time for brands to deliver first appeared on The Last Watchdog.

View Details

Web browser security certainly hasn’t been lacking over the past 25 years.

Related: Island valued at $3.5 billion

Advancements have included everything from sandboxing and web applications firewalls (WAFs,) early on, to secure web gateways (SWGs) and Virtual Desktop Infrastructure (VDIs,) more recently.

Yet profound browser exposures persist — and this has led to the arrival of enterprise browsers, which will be in the spotlight as Black Hat USA 2024 gets underway next week in Las Vegas.

I recently visited with Uy Huynh, vice president of solutions engineering, at Dallas, Tex.-based Island, the pioneer and leading enterprise browser.

We discussed why enterprise browsers may be in the early stages of revolutionizing how businesses operate in the cloud-driven world. For a full drill down, please give the accompanying podcast a listen.

You’ll learn, as I did, why enterprise browsers are not just another incremental improvement. By embedding user authentication, data protections, robotic process automation, and workflow integration directly into an enterprise browser companies can reduce complexity while improving speed and productivity, Huynh explains.

In effect, this approach extends threat detection and policy enforcement to the presentation layer; each person taps into company assets via a highly capable, flexible browser that’s simpler for the company to manage with dexterity.

Huynh walked me through examples where Island’s browser has replaced cumbersome VDI implementations, complex data loss prevention policies and helped to streamline M&A deals. “With an enterprise browser, you access applications natively and directly, removing latency and significantly boosting productivity,” says Huynh.

Will enterprise browsers become central to IT and security infrastructures? I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post Black Hat Fireside Chat: How ‘enterprise browsers’ help to shrink exposures, boost efficiencies first appeared on The Last Watchdog.

View Details

What does the recent CrowdStrike outage tell us about the state of digital resiliency?

Related: CrowdStrike’s consolation backfires

On a resiliency scale of one to 10, most enterprises are at about two. This was clear over the weekend when over 4000 flights were grounded, hospitals had to postpone services, and financial systems went down.

The only reason the impact was not broader was luck – not everybody runs CrowdStrike, and not all processes have been digitized.

The world was also lucky that this outage was due to a mistake by a legitimate vendor, and the recovery steps were relatively straightforward, albeit laborious. This made it possible for all users to recover cleanly and be sure that they have completely recovered.

Barde

Imagine that instead of a mistake by CrowdStrike, it was a malicious actor who subverted the CrowdStrike distribution channel and leveraged it as a Trojan for a data theft or ransomware attack. By the time such an attack gets detected, it would 100 percent impossible to size up the damage exactly, and the damagewould be so distributed that no single vendor (not CrowdStrike, not Microsoft) would be able to provide full recovery guidance.

So, what is it going to take to start making meaningful steps towards achieving digital resiliency across Internet-centric services?

Redundancy is vital

A multi-pronged approach is needed to ensure resiliency. Both vendors and enterprises have a role to play in this.

The first prong is prevention. Vendors need to test every update thoroughly, and have a clear rollback mechanism for every update. They need to release every update in phases to their users, starting with a small set of users who have opted to take the latest bits, so that if they missed an issue in their testing, it is at least detected early before it goes out to all users.

This is common practice among telecom and cloud service providers. Vendors should ideally also enable enterprises to control how to distribute their updates within the enterprise. An example is how Microsoft enables enterprises to control how to roll out Windows updates. Enterprises also need to adopt such controls where they are offered.

The second prong is containment. Mistakes happen. Enterprises need to avoid single points of failure, by diversifying their supply chain and their own technical implementations, so that a mistake in one component does not bring down all their systems.

Final prong is governance. Every commercial entity trades off how much they invest in containing risks with the impact if they do not. In some cases the financial incentives are not big enough.

In the end, the ones who suffer are consumers. In select cases, regulatory bodies may need to consider regulations for vendors and enterprises, to protect consumers.

About the essayist: Sumedh Barde is Head of Product at Simbian, which supplies fully autonomous security systems for intelligent defense.

The post GUEST ESSAY: CrowdStrike outage fallout — stricter regulations required to achieve resiliency first appeared on The Last Watchdog.

View Details

Las Vegas, Nev., July 30, 2024, CyberNewsWire — Amid rising breaches including Snowflake, the platform helps security teams proactively detect and respond to identity-centric threats in business-critical SaaS applications.

Adaptive Shield, a leader in SaaS Security, today announced its breakthrough Identity Threat Detection & Response (ITDR) platform for SaaS environments. Since entering this space a year ago, the company has already become a leader in the field, implementing the solution in hundreds of enterprise customer environments.

Adaptive Shield will demonstrate its new ITDR platform and award-winning technology at booth #1268 during Black Hat USA, from August 7-8, 2024, showcasing its capabilities with the most complex threat detection use cases and campaigns seen in the wild.

The recent Snowflake breach served as a wake-up call for the SaaS industry. On May 27, a threat group announced the sale of 560 million stolen records from targeted attacks on single-factor authentication users in Snowflake. This event, which continues to make headlines, follows a series of significant breaches in SaaS applications over recent months.

“The Snowflake breach is a classic example of a SaaS security event that could have been prevented or, if not, detected. Organizations must recognize the shared SaaS security responsibility model, in which SaaS vendors provide native security controls, but it is ultimately the organization’s duty to actively ensure these controls are implemented,” said Maor Bin, co-founder and CEO of Adaptive Shield.

Bin

“Major incidents like this could easily be prevented with proper monitoring and hardening tools,” Bin added. “Beyond prevention, which is fundamental to SaaS security, having threat detection and response capabilities tailored for SaaS applications would have identified the Indicators of Compromise (IoCs) and halted the attack at the perimeter.”

Adaptive Shield’s ITDR platform works alongside the company’s prevention SaaS Security Posture Management (SSPM) platform and enables enterprises to proactively cover the breadth of attack vectors within the SaaS ecosystem. Identity-centric threats can originate from misconfigured settings, human and non-human identities, and compromised SaaS user devices.

These threats manifest in various forms, such as account takeovers, unintended publicly available links, malicious applications, and more. Real-life sophisticated campaigns detected by Adaptive Shield customers include:

•Threat actors taking over credentials in a payroll & HR management system and changing employee bank account details to transfer their salary to a different account.

•A partially deprovisioned former employee accessed and downloaded very sensitive data. This occurred due to misconfigurations within a highly complex operational platform.

•Detection of lateral movement from a disabled MFA demo account into production via OAuth, as a malicious app, directly into employee mailboxes.

•Access to public links in the CRM, intended for data sharing. While these public links were password protected, had expiration dates, and usage tracking, they were still accessible to unauthorized users.

•Account hijacking through user compromised user devices.

“Current ITDR solutions primarily address endpoint and on-premises Active Directory protection, but they do not cover the intricate SaaS environment. Addressing SaaS-related threats demands deep expertise and can be achieved only by cross-referencing and analyzing suspicious events in context from multiple sources, ensuring precise detection of subtle identity-centric threats,” said Gilad Walden, VP Product at Adaptive Shield.

Adaptive Shield integrates with over 160 applications out-of-the-box, enabling customers to connect their entire stack and achieve an accurate alerting of Indicators of Compromise (IoCs), drastically eliminating false positive alerts.

To meet with an Adaptive Shield executive onsite at Black Hat USA or remotely, users can reach out here.

About Adaptive Shield: Chosen by hundreds of large enterprises, including numerous Fortune 500 companies, Adaptive Shield continues to be the trusted SSPM and ITDR platform that enables security teams to stay on top of their organization’s apps, identities and any unusual user behavior in the SaaS ecosystem. Adaptive Shield leads the SaaS security space and is recognized with awards such as Gartner Cool Vendor, Frost & Sullivan’s Global Technology Innovation Leadership and the Global Infosec Awards 2024. For more information visit www.adaptive-shield.com

Media contact: Chloe Amante, Senior Account Executive, Montner Tech PR, camante@montner

The post News Alert: Adaptive Shield to showcase new ITDR platform for SaaS at Black Hat USA first appeared on The Last Watchdog.

View Details

Last week, CrowdStrike, one of the cybersecurity industry’s most reputable solution providers, inadvertently caused more disruption across the Internet than all the threat actors active online at the time.

Related: Microsoft blames outage on EU

A flawed update to CrowdStrike’s Falcon security software caused millions of computers running Microsoft Windows to display the infamous blue screen of death. More than 5,000 flights and an untold number of hospital procedures got canceled and banking services got knocked offline across the globe. To try to restore normality, organizations had to reboot in safe mode or use the Windows Recovery Environment.

While inexcusable, the CrowdStrike outage was not terribly surprising. It falls right in line with a seemingly never-ending series of major cyber incidents that continue to expose the stark fragility of our digital infrastructure.

Elusive resiliency

Unless things change, digital resiliency will continue to remain elusive. This is because the pace of digitizing business operations continues to intensify, resulting in new services – and fresh exposures.

All companies – including cybersecurity vendors – are racing to leverage automation and AI to boost innovation, i.e. increase revenue. The new attack vectors that spin out of this chase entice cyber adversaries to continually iterate and improve upon tried-and-true cyber attack tools and techniques, with the goal of gaining unauthorized network access.

Lest we forget, catastrophes of the CrowdStrike outage class abound, including:

•SolarWinds supply chain debacle

•Colonial Pipeline ransomware attack

•Microsoft Exchange Server hack

•JBS Foods ransomware attack

•Kaseya VSA ransomware attack

•Facebook users’ data leak

•Log4j/Log4Shell vulnerability

•T-Mobile users’ data breach

The CrowdStrike outage drips with irony because the culprit is not a criminal hacking collective or a nation state actor; it’s a marquee cybersecurity vendor. CrowdStrike abjectly failed to recognize a gaping exposure lurking in its automated update delivery system – a flaw with the potential to cause catastrophic disruption up and down its supply chain, which is exactly what happened.

SolarWinds redux

In many ways, CrowdStrike was a repeat of the SolarWinds supply chain hack. In the latter, a threat actor purposefully identified and exploited a soft spot in SolarWinds’ automated software update service.

This time around, CrowdStrike internally got tripped up by an automation flaw that it very well should have sussed out before delivering anything to its customers.

Thus, once again we’re reminded that taming digital complexity remains a huge challenge — and that digital resiliency remains as elusive as ever. With this in mind, Last Watchdog sought commentary from technology thought leaders about what the CrowdStrike outage says about the state of digital resiliency. Responses edited for clairy and length:

Geoffrey Mattson, CEO, Xage

Mattson

Like many vendors of their vintage, CrowdStrike built their product on an “agent” that must be installed deep in each laptop or server. This introduces complexity and allows a bug to have the type of deep impact that we’ve witnessed with this incident . . . Since the agent had not been vetted, it inflicted the same damage as malware would have. Implementing zero trust across the entirety of the technology stack would go a long way toward increasing resilience against events like this.

Justin Endres, CRO, Seclore

Endres

Fallout from the recent disruption caused by a CrowdStrike update highlights how widespread reliance on any one solution can lead to global outages. This incident underscores the critical importance of diversifying our digital infrastructure . . . If this had been a cyber attack exploiting a nearly universal vulnerability, the implications could have been far worse. Recovery will be measured in weeks not hours, as many of the impacted systems will need to be rebuilt manually. Clearly, Microsoft must also enhance its operating system so Windows can automatically recover from this type of system error.

Tamara Nolan, Cyber & Operational Resilience Practice Leader, MorganFranklin

Nolan

This event was only possible because of the number of organizations who updated to the latest version of their security software. They were following best practices advice and now they must face the fact that even good advice can lead to bad outcomes . . . Should the affected organizations have accepted CrowdStrike’s auto updates without scrutiny? Should security leaders trust vendors representations about QA/QC in general? Due to the nature of the fix, IT personnel will need to physically access each affected machine. This means that the recovery process may take some time.

Neatsun Ziv, CEO, OX Security

Ziv

While this is not a cyberattack, the downstream effects are comparable in that one action impacts another, which then impacts another dependency, and so on. As illustrated here, deployment and management of agents is problematic at scale. Ensuring consistent agent configurations and updates across the entire ecosystem is extremely challenging. We need to address system reliability, and how best to avoid a single point of failure. Using agentless updates, as opposed to automatically updating agents on the endpoint servers, is a good first step.

Charles Henderson, EVP, Coalfire

Henderson

Successful recovery of IT systems will only be the first hurdle for security organizations. As we’ve seen countless times over the years, attackers will certainly use the disruption and public awareness of this issue to further their attacks . . . Starting now and for at least the next month, all organizations should be in a heightened state of vigilance for phishing emails purporting to be from, or affiliated with, CrowdStrike.

Dimitri Chichlo, CSO, BforeAI

Chichlo

Our networks remain fragile because of interdependence and the assumption that technology always works. When your executive committee or board of directors have little appetite for IT matters, little effort will be brought on making infrastructure resilient. IT teams must stop considering security a separate discipline from IT but embed security and resilience by default into their day-to-day activities.

Steve Hahn, EVP, BullWall

Hahn

It will be interesting to see if we have a ripple of downstream consequences. Right now we are dealing with outages at airlines and other critical businesses. Will we also see a wave of ransomware attacks that follow? Time will tell.

This event, more than any other, is precisely why companies need a defense in depth strategy. Ransomware uses endpoints and other attack vectors as their launch mechanism for their attack and you need layers of security over your critical data and file shares.

Bruno Kurtic, CEO, Bedrock Security

Kurtic

CrowdStrike initially stated there was no security breach, only a software defect that led to a disruption. This underscores the need for cybersecurity vendors to recognize their role in maintaining business and societal functions and their responsibility for resilience . . . . While running two EDR software applications on the same system isn’t feasible, businesses can protect cloud, data, and other assets with different vendors. Additionally, conducting tabletop exercises for catastrophic failures and analyzing supply chain risks are crucial.

Evan Dornbush, former NSA cybersecurity expert

Dornbush

This is, of course, a phishing attack opportunity. Don’t make a bad situation worse. Only follow recommended instructions direct from your CrowdStrike rep. There will be a lot of misinformation about how to reconfigure your computers or which critical system files to delete. Don’t fall victim to downloading phony solutions.

Dylan Owen, CISO, Nightwing

Owen

Now is a good time to review incident response plans and identify any weak spots, like missing backups. Learning from this event can be critical to reducing the recovery time from major outages to come. Ultimately, organizations need to take a measured approach. Continuing to follow cyber hygiene best practices can more likely create those constant invisible benefits that keep organizations from falling victim to a ransomware event or other compromises and ultimately bolster their digital resiliency. 77

Ted Miracco, CEO, Approov

Miracco

This outage shows the severe consequences of having a single point of failure, the misguided notion that bigger is better with cybersecurity, and the dangers of down selecting to a single vendor for each service. The most economical way to support complex systems, might be to have multiple overlapping solutions that provide redundancy. This includes adopting multi-cloud strategies and decentralizing critical functions to ensure continuous operation during localized failures. Sandboxing updates and rigorously testing upgrades before releasing them to all users are crucial practices for enhancing digital resilience.

Irfan Shakeel, Vice President Training & Certification Services, OPSWAT

Shakeel

Deployment of a faulty update to a production environment without adequate testing underscores a critical flaw in resilience planning. Disruption can cascade through interconnected systems, causing widespread chaos. Such incidents emphasize the urgent need to diversify IT infrastructure, implement incident response plans and prioritize thorough testing. This will strengthen digital resilience.

Dan Potter, Director of Operational Resilience, Immersive Labs

Potter

This crisis highlights a pressing concern — the over-reliance on digital systems, which have inherent limitations and vulnerabilities. Moving forward, organizations need to both defend against increasing cyber threats and optimize business response to disruptions, including having the capacity to revert swiftly to manual processes. This requires having the people that give your organization the human edge in responding to any unexpected event.

Willy Leichter, CMO, AppSOC

Leichter

The Irish potato blight and famine showed that being completely dependent on a single food source for millions of people could be catastrophic . . . It’s understandable that many organizations have set a goal of reducing the number of security tools they use, while standardizing on a few giant vendors to build and manage their infrastructure. Yet, there is significant value to have some diversity of tools, and a non-homogenous approach to security.

Scott Kannry, CEO, Axio

Kannry

The outage reinforces the need for organizations to better understand how the failure or loss of key technological dependencies can impede their business operations . . . Achieving digital resiliency is a manageable process, commonly practiced as part of enterprise risk management in large enterprises. Start by identifying the core products and services that form the business’s lifeblood. Explore alternative operational enablers, both technological and non-technological, and evaluate their costs and investment thresholds.

Pukar Hamal, CEO, SecurityPal

Hamal

A proactive and comprehensive risk assessment and management approach and constant re-evaluation of compliance postures are necessary. Adopting advanced technologies or models, like AI, cloud computing, or Low-code/no-code models, can be helpful for early issue detection and automated responses. The key thing is digital resiliency is about redundancy at both the People, Process, and Technology layer.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


The post LW ROUNDTABLE: CrowdStrike outage reveals long road ahead to achieve digital resiliency first appeared on The Last Watchdog.

View Details

The rapid adoption of mobile banking has revolutionized how we manage our finances.

Related: Deepfakes aimed at mobile banking apps

With millions of users worldwide relying on mobile apps for their banking needs, the convenience is undeniable. However, this surge in digital banking also brings about substantial security concerns.

Alarmingly, 85% of banks are predicted to be at risk from rising cyber threats. The increasing sophistication of cyber attacks, including phishing, malware, and man-in-the-middle attacks, poses a serious threat to both users and financial institutions. This essay offers insights into best practices for secure mobile banking to help mitigate these risks.

Surging attacks

Mobile banking has become a prime target for cybercriminals. The increasing sophistication of cyber attacks, including phishing, malware, and man-in-the-middle attacks, poses a serious threat to both users and financial institutions. The recent surge in mobile banking fraud highlights the pressing need for enhanced security measures.

Implementing robust security practices is essential for safeguarding mobile banking transactions. According to a comprehensive analysis on cybersecurity in banking, adopting stringent measures is crucial. Here are some best practices that can help mitigate the risks associated with mobile banking:

Users bests practices:

•Use Strong Passwords and Biometrics: A strong password is crucial for protecting your account. Users should create complex passwords that are difficult to guess. Additionally, enabling biometric authentication (such as fingerprint or facial recognition) adds an extra layer of security.

•Enable Two-Factor Authentication (2FA): Two-factor authentication significantly enhances account security by requiring a second form of verification, such as a code sent to your mobile device, in addition to your password. This makes it much harder for attackers to gain access to your accounts.

•Regularly Update Software: Keeping your mobile banking app and operating system up-to-date ensures that you have the latest security patches. Regular updates help protect against known vulnerabilities that cybercriminals might exploit.

•Be Cautious with Public Wi-Fi: Avoid accessing your mobile banking app over public Wi-Fi networks, which are often unsecured. If you must use public Wi-Fi, consider using a virtual private network (VPN) to encrypt your internet connection and protect your data.

•Monitor Account Activity: Regularly checking your bank statements and account activity for any unauthorized transactions can help detect and prevent significant financial loss.

Banks’ best practices:

•Implement Advanced Encryption: Financial institutions should use advanced encryption methods to protect data transmitted between the mobile app and the bank’s servers. End-to-end encryption ensures that even if data is intercepted, it cannot be read by unauthorized parties.

•Conduct Regular Security Audits: Regular security audits and vulnerability assessments can help identify and rectify potential security weaknesses in mobile banking applications. This proactive approach helps prevent security breaches before they occur.

•Provide User Education: Educating users about the importance of mobile banking security and how to protect themselves can significantly reduce the risk of cyber attacks. Financial institutions should offer resources and tips on secure mobile banking practices.

•Utilize Behavioral Analytics: Implementing behavioral analytics can help detect unusual patterns of behavior that may indicate fraudulent activity. By monitoring how users typically interact with their accounts, financial institutions can identify and respond to anomalies in real-time.

•Develop a Robust Incident Response Plan: Having a comprehensive incident response plan in place ensures that financial institutions can quickly and effectively respond to security breaches. This plan should include procedures for communication, mitigation, and recovery to minimize the impact of any incidents.

The trend towards mobile banking is set to continue, making it imperative for both users and financial institutions to prioritize security. By following these best practices, we can mitigate the risks and protect sensitive financial information.

Author Bio: Hira Ehtesham is a Senior Content Writer at VPNRanks, focusing on cybersecurity, AI, and privacy. With a passion for writing and a commitment to providing insightful and engaging content, Hira helps users navigate the complexities of digital security.

The post GUEST ESSAY: Consumers, institutions continue to shoulder burden for making mobile banking secure first appeared on The Last Watchdog.

View Details

In our digital age, managing passwords effectively is crucial not just for our security while we’re alive, but also for ensuring our digital legacies are secure after we’re gone.

Related: Understanding digital footprints

A recent study by All About Cookies sheds light on the alarming lack of preparation most internet users have for their digital assets.

The All About Cookies study surveyed 1,000 U.S. adults to understand how prepared Americans are to pass on their digital inheritances. The results revealed that 67 percent of respondents have a plan to share banking account information, but only 24 percent include online account details in their wills.

Furthermore, only 30 percent of people in relationships say their partner could easily access their online accounts in the event of their death. This indicates a significant gap in planning for digital assets compared to physical ones. Here are the key findings

•Digital Asset Planning is Inadequate: While 65 percent of people have a will, only a quarter include information about their online accounts. This omission could leave families struggling to access essential digital information during an already difficult time.

•Storing Passwords in Memory: An astonishing 39 percent of respondents store their digital information in their heads, which poses two significant risks: the potential loss of access if something happens to the individual and the increased likelihood of using simple, easily hackable passwords.

•Lack of Sharing Credentials: Only 42 percent of people share login credentials with their spouse, and 34 percent haven’t shared their digital assets with anyone. This leaves many accounts vulnerable to being lost or inaccessible after death.

•Unaccounted Online Assets: Half of the respondents have money in online accounts that their spouses are unaware of, with a median value of $8,000. This underscores the financial risks associated with inadequate digital asset planning.

Best practice guidance

Given these insights, here are some best practices for securing your passwords and ensuring your digital legacy is well-managed:

•Consider using a password manager: Instead of relying on memory, use a reputable password manager. These tools not only help generate and store complex passwords but also often include features for designating digital heirs. This ensures that your passwords and important information are accessible to your loved ones when needed.

•Regularly update your will: Ensure that your will includes detailed instructions for accessing your digital assets. This should encompass banking information, social media accounts, investment portfolios, and any other significant online presence. Regular updates will keep this information current and comprehensive.

•Share information securely: Discuss your digital asset plans with a trusted individual, whether it’s a spouse, family member, or attorney. Sharing this information securely ensures that your accounts can be managed in your absence without unnecessary complications.

•Educate yourself and others: Make use of resources that help you understand digital asset management. For older adults, guides like “The Best Password Managers For Seniors” can be particularly useful. Educating yourself and your loved ones on these tools will enhance overall security.

Plan for all digital assets: Do not overlook any accounts. While banking and investment accounts are critical, also consider utilities, social media, email, and any other services you use regularly. Ensuring these are part of your digital plan will prevent any oversight.

•Consider professional advice: If you’re unsure where to start, seek professional advice. Experts in digital security and estate planning can provide tailored recommendations that suit your specific situation and needs.

The All About Cookies study highlights a crucial yet often overlooked aspect of our digital lives—planning for the security and transfer of our digital assets. The big takeaway here is all too familiar.

This is yet more evidence that each one of us, as individual consumers, continue to carry a big burden for protecting and preserving every aspect of our digital lives, more so than ever and in so many different ways. There is potentially a ton of value in digital legacies. For one thing, thanks to the way we now collect all data, it is possible for future generations accesse details of how their forbearers lived their lives.

Something to ponder. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


The post MY TAKE: Study shows most folks haven’t considered bequeathing their ‘digital’ inheritances first appeared on The Last Watchdog.

View Details

Passwords have been the cornerstone of basic cybersecurity hygiene for decades.

Related: Passwordless workpace long way off

However, as users engage with more applications across multiple devices, the digital security landscape is shifting from passwords and password managers towards including passwordless authentication, such as multi-factor authentication (MFA), biometrics, and, as of late, passkeys.

But as secure and user-friendly as these authentication methods are, cybercriminals are already busily sidestepping all forms of authentication – passwords, MFA, and passkeys – to sometimes devastating effect.

Passwordless work arounds

Without a doubt, passwordless authentication is a significant improvement over traditional passwords and effectively addresses the persistent risk of easy to guess passwords and password reuse. Most passkeys available to consumers leverage unique biometric authentication data and cryptographically secure means to authenticate users when they access websites and applications.

This new authentication technique is gaining traction, especially since the FIDO Alliance has advocated for its implementation over the last year. Moreover, leading tech companies like Google, Microsoft, and Apple have developed robust frameworks to integrate this system of authentication.

Yet history reminds us that cyber threats evolve alongside our defenses. As we move towards a passwordless world, bad actors are finding new avenues to exploit, including simply working around passwordless authentication with session hijacking attacks and other forms of next-generation account takeover – and the tradeoff is significant.

The most alarming threat to users and businesses today, bar none, is malware. Criminals increasingly use infostealer malware and other low-cost and highly effective malware-as-a-service tools to exfiltrate valid identity data needed for authentication, like session cookies.

The role of infostealers

Hilligoss

Infostealers pose a significant challenge for websites and servers that validate user identities. Armed with an anti-detect browser and a valid cookie, bad actors can mimic a trusted device or user, easily sidestep authentication methods, and seamlessly blend in without raising any red flags. Once the session is hijacked, criminals can access a user’s accounts, and masquerade as the user to perpetrate additional cyber incidents such as fraud and ransomware.

And this attack method is on the rise. In 2023, infostealer malware use tripled, with 61% of breaches attributable to this threat. SpyCloud researchers highlighted how malware infections are a major player in identity exposures in the recent 2024 Identity Exposure Report.

While most infostealer malware are non-persistent in their infiltration, and extraction of information takes only a matter of seconds, leaving the device with nary a sign, the threat of the stolen data to a user and organization security is much more persistent. A valid session cookie will remain on a person’s browser until it expires or a proactive security team invalidates it. Some cookies can last for months or years. As long as cookie data remains valid, it can be sold and traded multiple times and used to perpetrate different attacks.

Lateral exposures

Criminals are interested in the data but even more so, the level of access the data can grant. So beyond cookies they are also accessing keychains, local files, single-sign on logins, and escalating privileges – essentially instigating a wide range of actions from a single entry point, whether it’s within a browser or on a device.

The use of single sign-on (SSO) only exacerbates the problem, as a successful breach can potentially grant unauthorized access to multiple linked accounts and services across multiple business and personal devices.

Case in point: In January 2023, the continuous integration and delivery platform CircleCI announced it had experienced a data breach caused by infostealer malware deployed to an engineer’s laptop. The malware stole a valid, two-factor-backed SSO session, executed a session cookie theft, impersonated the employee, and escalated access to a subset of the company’s production systems, potentially accessing and stealing encrypted customer data.

Security practitioners often fail to recognize the extensive scope of the session hijacking issue or take steps to mitigate it. Even when teams have visibility into stolen session cookies, our research has found that 39% fail to terminate them.

Despite having short timeouts, MFA, and passkeys in place, there will still be security gaps. This is particularly true due to the use of third parties having unmanaged or under-managed devices, which security teams may not have access to or sufficient control over.

Additional strategies

Passwordless security authentication is still an important part of any layered security strategy, but since it can still be sidestepped via stolen cookies for session hijacking, it’s not a silver bullet to combat cyber attacks.

Additional strategies, such as monitoring for compromised web sessions, invalidating stolen cookies, and promptly resetting exposed user credentials are critical. This means quickly and accurately being able to determine when any component of an employee, contractor, vendor, or customer’s identity is compromised and moving fast to remediate and negate the value of stolen identity data. This takes the steps traditionally set forth of cleaning and re-imaging a machine one step further to properly remediate the data that could still be floating on the criminal underground and nullifying it.

As criminals step up their game, failing to make this shift could leave organizations vulnerable to a wide array of next-generation attack methods. And with passkeys and other passwordless authentication methods soaring in popularity, time is of the essence.

About the essayist: Trevor Hilligoss served nine years in the U.S. Army and has an extensive background in federal law enforcement, tracking threat actors for both the DoD and FBI. He is a member of the Joint Ransomware Task Force and serves in an advisory capacity for multiple cybersecurity-focused non-profits. He currently serves as the Vice President of SpyCloud Labs at SpyCloud.

The post GUEST ESSAY: How cybercriminals are using ‘infostealers’ to sidestep passwordless authentication first appeared on The Last Watchdog.

View Details

At a time of devolving politics, Madison Horn stands out as a breath of fresh air.

Related: The Biden-Harris National Cybsecurity Strategy

I had the chance to sit down with Horn at RSAC 2024 to learn all about her measured decision to put an ascendent cybersecurity career on hold to run for political office.

I came away very impressed by Horn’s determination to inject technical expertise and ethical reform into an arena starkly bereft of both: the U.S. Congress. For a full drill down, please give the accompanying podcast a listen.

Horn’s background is as compelling as it is unorthodox. A seventh generation Oklahoman and a proud member of the Cherokee Nation, she grew up in a rural community with few socio-economic advantages. Her professional career began by happenstance at a small cyber firm that specialized in assessing critical infrastructure vulnerabilities.

She quickly progressed to significant roles at Fusion X, Accenture, PricewaterhouseCoopers and Siemens Energy, where she spearheaded global cybersecurity initiatives. “My career gave me a unique perspective on the threats facing America,” she says, everything from mitigating AI-boosted cyberattacks to strategizing cyber warfare countermeasures.

Even as her career trajectory steepened, Horn found herself repeatedly drawn back to her home state and increasingly troubled by its maladies. It was a sense of duty to serve her community, she says, that compelled her to try her hand at politics.

“Every time I came back to Oklahoma, I saw the lack of progress and the lack of opportunities,” she explains. “I felt I owed it to my community to come home and do something about it.”

Her decision was further galvanized by the political tumult following Donald Trump’s election and by the January 6th Capitol riot. “Seeing our political system deteriorate because of ego and partisanship was a call to action for me,” she says.

Horn is running against Republican incumbent Stephanie Bice, who has focused on border security and protecting the oil and gas industry. Oklahoma’s 5th District is rated solidly Republican by various analysts, but current polling has Madison and her opponent tied 46/46, with 8% undecided according to change research, representing a path for Horn.

However, she believes her unique background in cybersecurity and commitment to ethical governance can resonate with voters across the spectrum. “We need leaders who understand technology and can protect our digital future,” she argues.

Horn’s campaign rebukes the current political system, which she sees as being hampered by money and party politics. “All the money in politics is holding back good people from getting elected,” she contends. Her previous run for the U.S. Senate, though unsuccessful, helped her better understand the process and prepare for her current bid, she says.

Her platform hasn’t changed one iota, she told me. She hopes to contribute to resolving critical issues such as supply chain resilience, rural healthcare and infrastructure development. Horn emphasizes the importance of direct community engagement, a lesson she learned from her Senate campaign. “People are looking for authenticity and a genuine connection with their representatives,” she notes.

If Horn has an ace in the hole, it might be her high-level grasp of cybersecurity exposures, which gives her a full appreciation of the complexities that must be overcome to make the Internet as private and safe as it needs to be. If she wins this November, Madison would be the most credentialed cyber lawmaker in U.S. history.

Could Madison Horn be in the vanguard of a youthful critical thinkers motivated to restore governance by and for the people? Let’s hope so. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


The post RSAC Fireside Chat: Madison Horn’s quest to add cyber expertise, restore ethics to Congress first appeared on The Last Watchdog.

View Details

Security teams rely on an ever-growing stack of cybersecurity tools to keep their organization safe.

Related: The worst year ever for breaches

Yet there remains a glaring disconnect between security systems and employees.

Now comes a start-up, Amplifier Security, with a bold new approach to orchestrate security actions.

Just after RSAC 2024, I spoke with Thomas Donnelly, Amplifier’s co-founder and CTO, about how that they’re utilizing large language models (LLMs) and to emphasize continual employee engagements. For a full drill down, on how Amplifier aims to help companies shape a security culture — without sacrificing productivity — please give the accompanying podcast a listen.

At the heart of Amplifier’s solution is Ampy, an AI security buddy. Ampy interacts directly with each employee to facilitate automated security fixes. Ultimately Ampy offloads a ton of manual work that security teams typically have to do by chasing employees themselves.

Donnelly explained how Amplifier leverages LLM to make Ampy friendly and increasingly knowledgeable. For instance, Ampy helped one early customer achieve a 70 percent improvement in security training compliance in just a couple of weeks and other customers report material improvement in the time and effort required to manage vulnerabilities.

By making security very engaging and directly involving employees in security processes, CISOs can foster cross-functional teamwork with other departments, Donnelly argues. The clincher is that this can help them get firmer footing to secure employees and their assets, using existing tools, and thereby nurture a security culture, he says.

Makes a lot of sense. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: Amplifier Security taps LLMs to help organizations foster a security culture first appeared on The Last Watchdog.

View Details

The coalescing of the next-gen security platforms that will carry us forward continues.

Related: Jump starting vulnerability management

Adaptiva, a leader in autonomous endpoint management, recently announced the launch of OneSite Patch for CrowdStrike. This new solution integrates with CrowdStrike’s Falcon XDR platform to improve the efficiency and speed of patching critical vulnerabilities in enterprise systems.

This strategic alliance between Adaptiva and CrowdStrike makes a lot of sense. OneSite Patch leverages CrowdStrike’s rich threat intelligence and vulnerability data to prioritize and automate patch deployments.

Thus it provides a smooth path for companies to patch vulnerabilities and install updates much more efficiently. This pain point is intensifying at large and mid-sized enterprises as operations become more globally distributed and interconnected at the cloud edge.

The State of Patch Management in the Digital Workplace Report, for instance, underscores how legacy vulnerability management practices are by and large bereft of any meaningful strategic intent; for instance, some 79% of respondents said patch deployments are scheduled ad hoc or use a one-size fits all approach.

Last Watchdog engaged Davinder Singh, Chief Technology Officer at Adaptiva, to drill down on the current state of securing networks. Here’s that exchange, edited for clarity and length.

LW: What’s the core value proposition of this alliance with CrowdStrike?

Singh: The core value is in the rapid and autonomous patching of critical vulnerabilities — by leveraging CrowdStrike’s rich vulnerability data. The integration of Adaptiva’s OneSite Patch with CrowdStrike Exposure Management allows for automated, risk-based prioritization of patches, significantly reducing the time required to address vulnerabilities. This collaboration bridges the gap between security and IT teams, ultimately improving organizations’ cybersecurity posture and compliance.

LW: What’s an example that illustrates the benefit of teaming?

Singh

Singh: It’s now possible to automatically patch critical vulnerabilities across Windows and over 1,500 third-party applications as soon as patches are available. By utilizing CrowdStrike’s rich vulnerability insights, Adaptiva’s OneSite Patch can determine patch priorities and schedule deployments to ensure that critical vulnerabilities are patched immediately. This automated, data-driven approach eliminates delays caused by manual processes and improves coordination between security and IT teams, ultimately reducing the risk of cyberattacks and improving compliance with security regulations.

LW: Can you provide an anecdote from the field that shows an enterprise benefiting from combining CrowdStrike’s rich intel with Adaptiva’s streamlined approach to patch management?

Singh: One example is a large tire manufacturer that operates multiple production plants globally, each with its own production schedule. Patches can only be applied outside of production times. But the IT team lacked control over production schedules, requiring approval from plant management for any patching activities.

Adaptiva’s OneSite Patch integrates plant managers into the approval process, automatically notifying them when a patch update is available. Plant managers then review and approve patches, with the ability to identify which patches are critical. This ensures that patches are applied efficiently without disrupting production schedules.

All stakeholders have complete visibility. Security teams can monitor compliance, while IT teams can ensure that patches are deployed in a timely manner without interfering with production. Combining CrowdStrike’s threat intelligence and Adaptiva’s patch management streamlined the manufacturer’s vulnerability management process, enhancing their overall cybersecurity posture while maintaining production efficiency.

LW: Can you correlate vulnerability management (VM) best practices to the rising threat of GenAI-enhanced attacks? How does robust VM help meet this new exposure?

Singh: GenAI can be used by attackers to continuously scan for weaknesses and launch real-time attacks. This constant threat environment requires organizations to be equally vigilant. Continuous monitoring of systems and real-time integration of threat intelligence can help detect anomalies and new threats as they emerge.

Coupled with an efficient patch management process, organizations can significantly reduce the window of exposure. Given that nearly 60% of companies take two weeks or more to initiate patch deployment, improving this process is critical to staying ahead of potential breaches.

Automated remediation tools can drastically reduce the time from detection to mitigation, applying patches, isolating affected systems, and initiating other defensive measures without human intervention.

LW: What does this partnership signal about emergent security frameworks and platforms?

Singh: By combining Adaptiva’s autonomous patching capabilities with CrowdStrike’s AI-driven vulnerability data it becomes possible to support a wide range of applications and systems in a diverse and complex environment.

In the years to come, security frameworks and platforms will increasingly rely on automation, AI, and integrated approaches to enhance protection, streamline operations, and adapt to the evolving threat landscape.

The alliance between Adaptiva and CrowdStrike signals how IT and security platforms must seamlessly collaborate. Unifying workflows improves efficiency and reduces silos within organizations.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post New Tech Q&A: Adaptiva – CrowdStrike alliance highlights trend of blending IT and security systems first appeared on The Last Watchdog.

View Details

Waltham, Mass., June 27, 2024, CyberNewsWire — Infinidat, a leading provider of enterprise storage solutions, has introduced a new automated cyber resiliency and recovery solution that will revolutionize how enterprises can minimize the impact of ransomware and malware attacks.

Infinidat’s InfiniSafe® Automated Cyber Protection (ACP) is a first-of-its-kind cybersecurity integration solution that is designed to reduce the threat window of cyberattacks, such as ransomware. Sophisticated cyberattacks, including new sinister forms of AI-driven attacks, are increasingly targeting the data storage infrastructure of enterprises.

Infinidat’s InfiniSafe ACP enables enterprises to easily integrate with their Security Operations Centers (SOC), Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR) cybersecurity software applications, and simple syslog functions for less complex environments. A security-related incident or event triggers immediate automated immutable snapshots of data, providing the ability to protect InfiniBox® and InfiniBox™ SSA block-based volumes and/or file systems and ensure near instantaneous cyber recovery.

Herzog

“The merging of cybersecurity and data infrastructure has been compelling CIOs, CISOs and IT team leaders to rethink how to secure enterprise storage across hybrid multi-cloud deployments in light of increasing cyberattacks. Enterprises need proactive strategies, seamless integration across IT domains, and the most advanced, automated technologies to stay ahead of cyber threats,” said Eric Herzog, CMO at Infinidat. Recognized as a cyber secure storage expert, Herzog is coming off participation in a string of cybersecurity panel discussions, roundtables and conference events.

“Infinidat has carved out a very unique leadership position as the only storage vendor to offer an automated enterprise storage cyber protection solution that seamlessly integrates with cyber security software applications,” said Chris Evans, Principal Analyst at Architecting IT. “Infinidat’s newly launched InfiniSafe Automated Cyber Protection that easily meshes with the SIEM, SOAR or Security Operations Centers is exactly what enterprises need to include enterprise storage as a comprehensive approach to combat cyber threats.”

Infinidat’s new InfiniSafe ACP capability orchestrates the automatic taking of immutable snapshots of data, at the speed of compute, to stay ahead of cyberattacks by decisively cutting off the proliferation of data corruption.

Evans added, “This proactive cyber protection technique is extremely valuable, as it enables taking immediate immutable snapshots of data at the first sign of a potential cyberattack. This provides a significant advancement to ensure enterprise cyber storage resilience and recovery are integral to an enterprise’s cybersecurity strategy. ACP enhances an enterprise’s overall cyber resilience by reducing the threat window and minimizing the impact of cyberattacks on enterprise storage environments.”

The InfiniSafe Automated Cyber Protection is one of the biggest innovations of the year in cybersecurity because it unlocks the full potential of an enterprise’s security posture and maximizes the investments that an enterprise has made in protecting the business. By plugging into existing security mechanisms and continuous monitoring, InfiniSafe ACP bridges the gaps between enterprise storage and cybersecurity strategies that can transform the way CIOs and CISOs think about enterprise data infrastructures.

Information technology leaders have identified this ability to automate data snapshot commands and data pathways as critical to early detection and worry-free cyber recovery that minimizes the effects of even the most vicious and deceptive cyberattacks of malicious actors. An enterprise’s security team can put all its information from security operations through an enterprise storage intelligence grid to create the most sensitive triggers that often get missed by existing technologies and techniques.

Paul Rapier, VP of Information Technology at the Detroit Pistons, stated, “Infinidat’s efforts in enhancing cyber resilience for enterprises, particularly through the new InfiniSafe Automated Cyber Protection, are noteworthy for data security.”

Allen Shahdadi, Vice President of Global Sales at Sycomp, said, “Infinidat has become synonymous with guaranteed cyber resilient storage. Infinidat continues to deliver powerful solutions that solve critical cyber issues for enterprises and service providers around the globe. The InfiniSafe Automated Cyber Protection solution brings much needed capabilities to fight more effectively against cyberattacks. The automatic capture of immutable snapshots of primary data could be the difference between your data being held ransom and the rapid recovery of your data. Before international cybercriminals, hackers and fraudsters can gain an advantage, Infinidat’s InfiniSafe reduces the threat window decisively.”

The InfiniSafe Automated Cyber Protection solution is the latest in a string of cybersecurity capabilities that Infinidat has brought forward to strengthen enterprise storage in the face of constant threats of a tsunami of cyberattacks. Infinidat has also unveiled the following extensions of its state-of-the-art cyber resilient capabilities:

•InfiniSafe Cyber Detection for VMware – Access to InfiniSafe cyber resilience capabilities to combat cyberattacks has been expanded into VMware environments. The impact of a cyberattack can be readily determined through this cyber detection capability, with highly granular insights by leveraging AI and machine learning whether or not a VMware datastore and the VM’s they encompass have been compromised.

•InfiniSafe Cyber Detection for InfiniGuard® – Cyber detection will be extended onto the InfiniGuard purpose-built backup appliance to help enterprises resist and quickly recover from cyberattacks. This proven capability provides highly intelligent scanning and indexing to identify signs of cyber threats in backup environments, helping ensure that data has integrity. The enhanced version will be available in 2H 2024.

As a leader in cyber resilient storage, Infinidat first unveiled its InfiniSafe software-based platform two years ago with a set of cybersecurity functions. This solution has won numerous awards and has been proven by large global enterprises. The comprehensive cyber resilience capabilities of InfiniSafe technology improve the ability of an enterprise to combat and protect against ever-increasing cyberattacks and data breaches by uniquely combining immutable snapshots, logical air gapping, fenced/isolated networks, and virtually instantaneous data recovery into a single, high-performance platform.

The InfiniSafe ACP is the latest example of Infinidat’s broadening innovation. It was introduced alongside the launch of the InfiniBox G4 family of next-generation storage arrays for all-flash and hybrid configurations. The G4 series is a completely new storage array family built from the ground up that substantially extends Infinidat’s cyber storage resilience and delivers up to 2.5x improvement in performance. The InfiniBox G4 series introduces a new set of foundational elements, powered by InfuzeOS, which is Infinidat’s software defined storage operating system.

Webinar On Demand. To watch Infinidat’s end-user webinar about the new solutions ? “The Future of Enterprise Storage, Cyber Security and Hybrid Multi-Cloud” – users can click here.

Connect with Infinidat. About Infinidat | Blog | Twitter | LinkedIn | Facebook | YouTube | Be our partner

About Infinidat. Infinidat provides enterprises and service providers with a platform-native primary and secondary storage architecture that delivers comprehensive data services based on InfiniVerse®. This unique platform delivers outstanding IT operating benefits, support for modern workloads across on-premises and hybrid multi-cloud environments. Infinidat’s cyber resilient-by-design infrastructure, consumption-based performance, 100% availability, and cyber security guaranteed SLAs align with enterprise IT and business priorities. Infinidat’s award-winning platform-native data services and acclaimed white glove service are continuously recommended by customers, as recognized by Gartner® Peer Insights reviews. For more information: www.infinidat.com.

Media contact: Sapna Capoor, Director of Global Communications, scapoor@infinidat.com +44 (0) 7789684159

The post News Alert: Infinidat introduces advanced cyber resiliency and recovery solution for enterprises first appeared on The Last Watchdog.

View Details

McLean, Va., June 26, 2024, CyberNewsWire — FireTail today announced a free version of its enterprise-level API security tools, making them accessible to developers and organizations of all sizes.

•FireTail’s unique combination of open-source code libraries, inline API call evaluation, security posture management, and centralized audit trails helps eliminate vulnerabilities and protect APIs in real-time.

•The free plan covers up to 5 APIs, includes 1M API call logs per month, offers 7 days of data retention, and provides clear developer support.

FireTail, a disruptor in API security, unveils free access for all to its cutting-edge API security platform. This initiative opens the door for developers and organizations of any size to access enterprise-level API security tools.

Today, over 80% of all internet traffic is computer-to-computer communication via APIs. Every mobile app, IoT device, and most modern software applications use APIs, creating a broad attack surface for potential threats. FireTail’s hybrid approach to API security blends open-source code libraries with a feature-packed cloud platform and equips businesses with a unique suite of tools to eliminate API vulnerabilities and provide robust runtime API protection.

Snyder

“API security is essential for modern applications, and every developer and tech team should have access to effective security tools,” said Jeremy Snyder, CEO and Co-Founder of FireTail. “Security through obscurity is no longer a viable approach. We’re on a mission to secure all of the world’s APIs and our new free plan ensures ongoing access to an API security platform that delivers genuine insight into the most pressing attack vectors – design flaws in APIs. It’s perfect for smaller organizations striving for stronger API protection, and a great way for individuals or teams within larger organizations to get started.”

Priddle

Riley Priddle, Co-Founder and CTO at FireTail, added, “We’re excited to help organizations of all sizes to better protect their APIs. We want FireTail to become the de facto standard when it comes to API security. Just because you have a small number of APIs, it doesn’t mean they aren’t critical. We want everyone to have access to the best, enterprise-level API security tools. That’s why we offer both this free tier, as well as our open source libraries.”

For developers and small to medium-sized organizations needing to secure up to 5 APIs, FireTail’s free tier includes comprehensive API security features such as discovery, inventory, assessment, detection and response, and inline runtime protection. Key features include:

•Protection for up to 5 APIs

•1M API calls per month

•7 days of logging retention

Thomas Martin, Founder at NephoSec, shared “We’ve been working with FireTail from the outset as both a customer and a distribution partner. Having proven that the platform works for even the largest enterprises with the most complex API security requirements, it’s great to see the team opening that technology up to everyone. This will enable us to solve API security challenges for organizations of all shapes and sizes.”

To access the FireTail API security platform, users can visit https://www.firetail.app or join the team on Tuesday, July 2nd for an in-depth look at what FireTail’s free tier can do.

About FireTail: FireTail allows customers to solve all the most critical problems facing APIs today with a hybrid approach, bringing together cloud, application and code with full blocking capabilities to solve the root causes of API data breaches – flaws at the application and business logic layer in authentication, authorization and data handling. Headquartered in McLean, VA, with offices in Dublin, Ireland, and Helsinki, Finland, FireTail is backed by leading investors, including Paladin Capital, Zscaler, General Advance, and SecureOctane. Users can learn more at https://www.firetail.io.

Media contact: Alan Fagan, Marketing Director, FireTail, media@firetail.io

The post News Alert: FireTail unveils free access to its enterprise-level API security platform — to all first appeared on The Last Watchdog.

View Details

Secure Access Service Edge (SASE) has come a long way since Gartner christened this cloud-centric cybersecurity framework in 2019.

Related: Can SASE stop tech sprawl?

SASE blends networking architecture, namely SD-WAN, with cloud-delivered security services such as security web gateways, Zero Trust network access and more.

Several distinct variants of SASE have come to be supplied by diverse sources. This includes new players, like Versa Networks and Cato Networks; security stalwarts, like Palo Alto Networks and Zscaler; and even tech giants, like Cisco and Akamai.

Just after RSAC 2024, I had the chance to visit with Ken Rutsky, CMO at Aryaka, which is supplying yet another flavor: Unified SASE as a Service.” For a full drill down, please give the accompanying podcast a listen

We discussed how the SASE market has shifted post Covid 19. Early SASE solutions often stitched together disparate networking and security products resulting in operational inefficiencies, Rutsky told me.

Aryaka unifies networking and security architectures at a foundational level. “In a lot of scenarios, organizations are forced into this untenable trade-off between performance and security, and we know who usually wins,” he says. “We think unified SASE is the way to break that trade-off between performance and security.”

Acknowledging that organizations must rationalize past security investments, even ones that no longer quite fit, Aryaka does not ask customers to rip and replace anything. Instead, it meets them where they are, he says, then guides them through adoption in stages.

This is a prime example of the wider trend of cybersecurity solutions becoming more integrated to meet complex pressures. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC 2024: The many flavors of ‘SASE’ now includes Aryaka’s ‘Unified SASE as a Service.” first appeared on The Last Watchdog.

View Details

Dubai, UAE, June 20, 2024, CyberNewsWire — 1inch, a leading DeFi aggregator that provides advanced security solutions to users across the entire space, has announced today the launch of the 1inch Shield.

This solution, that is offering enhanced protection against a wide range of potential threats, was completed in partnership with Blockaid, a major provider of Web3 security tools.

Scam tokens masquerading as legitimate assets have long been creating problems for Web3 users. Now, due to collaboration with Blockaid, all tokens of this kind will be instantly detected and marked, so that users can avoid transacting with these tokens.

Speaking about the partnership, Sergej Kunz, co-founder of 1inch, said, “The collaboration between Blockaid and 1inch is anticipated to set a new standard for security in the cryptocurrency landscape. By combining Blockaid’s innovative security solutions with the 1inch’s advanced features, this partnership aims to enhance user safety and asset protection, contributing to the growth and mainstream adoption of DeFi.”

“The collaboration with 1inch represents a pivotal step forward in our mission to secure the Web3 ecosystem. By integrating our robust security solutions with the 1inch, we are enhancing the safety of digital assets while fostering trust and confidence among users in the DeFi space. Our joint efforts will pave the way for a more secure and accessible DeFi environment for everyone”, said Ido Ben-Natan, co-founder and CEO of Blockaid.

Kunz

Blockaid acts like an anti-virus for Web3, leveraging superior data and machine learning to identify and protect against malicious attackers. The provider with a better data can produce a better product, allowing multiple layers of security for users. Whenever a user connects their wallet to sign a transaction, Blockaid provides clear information about what will actually happen when the transaction is executed.

Blockaid can also simulate any transaction involving a wallet, dApp, or smart contract across multiple blockchains. What transforms simulation into security is validation. In simple terms, validation involves determining whether a given transaction is malicious or benign, allowing users to transact with confidence. Now, this transaction simulation capacity is used to protect 1inch users.

Meanwhile, blockchain users also encounter AML compliance risks. The 1inch Shield mitigates these risks by running 24/7 screening of blockchain addresses for ties to sanctions, terrorist financing, hacked or stolen funds, ransomware, human trafficking and more. Based on the outcome of screening, suspicious addresses are immediately blocked.

The screening component is powered by TRM Labs, which uses on-chain and off-chain data to detect possible security risks.

Finally, a blocklisting functionality provided by Etherscan Pro is also included in the 1inch Shield to immediately blocklist suspicious blockchain addresses.

The Shield API will be gradually integrated into 1inch products. This API is available on the 1inch Developer Portal alongside a suite of other cutting-edge tools intended for Web3 developers.

About 1inch: 1inch is a leading DeFi project empowering Web3 users with innovative blockchain products and solutions. Launched in 2019 at a hackathon in New York City, 1inch offers users and developers the most secure, reliable, and efficient tools for growing and expanding the Web3 space.

Currently, 1inch Swap is the best DEX aggregator on the market, facilitating cost-efficient and secure crypto swaps across multiple liquidity sources. The 1inch Wallet is one of the most user-friendly and secure Web3 wallets. 1inch Portfolio is the most efficient DeFi tracker, providing accurate analytics on the market for numerous DeFi protocols. In line with its active involvement in the community, in 2023, 1inch launched the Developer Portal, offering an extensive suite of Web3 tools and services. For more information, users can visit https://1inch.io.

Media contact: PR lead Pavel Kruglov, 1inch Labs, p.kruglov@1inch.io

The post News Alert: 1inch partners with Blockaid to enhance Web3 security through the 1inch Shield first appeared on The Last Watchdog.

View Details

Cary, NC, June 20, 2024, CyberNewsWire — 2024 is rapidly shaping up to be a defining year in generative AI.

While 2023 saw its emergence as a potent new technology, business leaders are now grappling with how to best leverage its transformative power to grow efficiency, security, and revenue. With the near-universal integration of AI into global technology, the need for AI-ready cybersecurity teams is more critical than ever.

INE Security, a leading global cybersecurity training and cybersecurity certification provider, predicts large language model (LLM) applications like chatbots and AI-drive virtual assistants will be at particular risk.

“AI systems are invaluable, enabling us to process vast amounts of data with unmatched speed and accuracy, detect anomalies, predict threats, and respond to incidents in real-time. But these revolutionary technologies are also empowering attackers, leveling the playing field in unprecedented ways,” said Lindsey Rinehard, COO and Head of AI Integration at INE Security. “As automated attacks increase, our defense strategies must also be automated and intelligent. The accelerating arms race between cyber attackers and defenders underscores the vital need for ongoing training and development for cybersecurity teams.”

According to the IBM X-Force Threat Intelligence Index 2024, cybercriminals mentioned AI and GPT in over 800,000 posts in illicit markets and dark web forums last year. Training and preparation for AI in infosec are no longer optional: organizations must deploy employee training for AI and cybersecurity to maintain effectiveness and stay ahead of attackers.

Optimization strategies

Incorporate structured team training programs. The first step in building an AI-ready cybersecurity team is to implement structured training programs that focus on both foundational cybersecurity principles and advanced AI applications. These programs should offer certifications and courses from recognized institutions and industry leaders to ensure they meet high standards. For example, courses offered by INE Security provide comprehensive training that covers both traditional cybersecurity skills and newer AI-based tools. The ideal training program will include:

Skills gap analysis: Conduct an analysis to identify where the team’s capabilities may be an area of improvement, particularly concerning AI integration.

Tailored curriculum development: A training curriculum that addresses identified cybersecurity skills gaps, incorporating both core cybersecurity principles and advanced AI applications.

•Blended learning approach: A mix of online courses, hands-on labs, and real-world scenario simulations to accommodate different learning styles and enhance practical application skills.

Promote a culture of learning

Building a culture that encourages ongoing learning and curiosity is equally important. Google, for instance, fosters a learning culture where employees are encouraged to spend 20% of their time on learning new skills or on side projects, many of which involve AI and cybersecurity innovations. This not only keeps their skills fresh but also helps in retaining talent and fostering a proactive approach to security challenges.

Rinehard

To effectively implement a culture of learning that supports the development of AI-ready cybersecurity teams, organizations can adopt several strategies:

•Provide access to resources: Offer subscriptions to leading industry publications, access to specialized online courses, and entry to relevant conferences and seminars that focus on AI and cybersecurity.

•Reward continuous learning: Establish a rewards system that recognizes and incentivizes team members who actively engage in learning new skills or who earn new certifications, particularly those that integrate AI technologies with cybersecurity practices.

Create innovation labs: Set up dedicated spaces or times when employees can experiment with new technologies or develop new solutions independently of their regular tasks. This can help stimulate creative thinking and practical application of learned skills.

Leverage simulation-based learning

Simulation-based learning tools like cyber ranges provide hands-on experience in dealing with real-world cybersecurity scenarios and help users learn how to use AI. Cyber ranges provide a simulated environment where professionals can safely engage with and respond to real-world cyber threats using AI tools, without the risk of impacting actual operations (this hands-on lab from INE Security is a great example).

This practical exposure is crucial for understanding how AI can be integrated into cybersecurity practices to detect, analyze, and mitigate threats. By training in a cyber range, team members can develop and refine their skills in a controlled yet realistic setting, which improves their ability to effectively utilize AI in live environments. The hands-on experience also helps in bridging the gap between theoretical knowledge and practical application, enhancing the team’s overall readiness and responsiveness to emerging cyber threats.

To effectively leverage cyber ranges for building an AI-ready cybersecurity team, consider implementing the following strategies:

•Regular tabletop exercise: Incorporate regular sessions within the cyber range into the team’s training schedule. This ensures consistent practice and skill refinement in handling AI-driven security scenarios.

Scenario variety: Develop a variety of threat scenarios that reflect the latest AI-driven attack techniques and the most common threats specific to the organization’s industry. This variety helps prepare the team for a wide range of potential real-world situations.

Cross-functional exercises: Include team members from various functional areas in cyber range sessions to foster a comprehensive understanding of how AI impacts different aspects of cybersecurity across the organization.

•Post-exercise reviews: Conduct debriefing sessions after each cyber range exercise to discuss what was learned and how it can be applied. This reinforces the lessons and integrates them into everyday practices.

Encouraging participation in hackathons and competitions.

Participation in hackathons and cybersecurity competitions can also play a crucial role in continuous learning. These events challenge participants to solve complex problems with innovative solutions, often under time constraints. They are excellent for learning new skills, testing existing ones, and keeping up with the latest cybersecurity and AI technologies.

To effectively implement a strategy that encourages participation in hackathons and competitions, organizations can adopt the following approaches:

•Promote awareness: Regularly inform team members about upcoming hackathons and competitions through internal newsletters, meetings, or dedicated communication channels. Highlight the benefits of participation, such as skill enhancement and potential recognition.

•Incentivize participation: Offer incentives such as bonuses, extra vacation days, or public recognition within the organization for those who participate and especially for those who perform well in these events.

•Post-event learning sessions: After each event, hold a session where participants can share their experiences, learnings, and new techniques discovered during the competition. This helps disseminate new knowledge across the entire team, enriching the organization’s skill base.

Conclusion

The integration of AI into cybersecurity is not just an enhancement of existing frameworks; it is a fundamental shift that requires a new kind of expertise. Continuous learning is critical for cybersecurity professionals to remain effective in their roles as defenders of digital assets. By embracing a culture of ongoing education and utilizing advanced training tools and techniques, cybersecurity teams can develop the resilience and adaptability needed to stay one step ahead of attackers in this fast-paced digital world.

As the landscape of cyber threats continues to evolve, so too must the capabilities of those tasked with protecting against them. An investment in continuous learning is an investment in the future security of our digital lives.

To learn more about INE Security’s cybersecurity training and certifications, click here.

About INE Security: NE Security is the premier provider of online networking and cybersecurity training and certification. Harnessing the world’s most powerful hands-on lab platform, cutting-edge technology, global video distribution network, and world-class instructors, INE Security is the top training choice for Fortune 500 companies worldwide for cybersecurity training in business, and for IT professionals looking to advance their careers. INE Security’s suite of learning paths offers an incomparable depth of expertise across cybersecurity and is committed to delivering advanced technical training while also lowering the barriers worldwide for those looking to enter and excel in an IT career.

Media contact: Kathryn Brown, INE Security, kbrown@ine.com

The post News Alert: INE Security lays out strategies for optimizing security teams to mitigate AI risks first appeared on The Last Watchdog.

View Details

CISOs have been on something of a wild roller coaster ride the past few years.

Related: Why breaches persist

When Covid 19 hit in early 2020, the need to secure company networks in a new way led to panic spending on cybersecurity tools. Given carte blanche, many CISOs purchased a hodge podge of unproven point solutions, adding to complexity.

By mid-2022, with interest rates climbing and the stock market cratering, CFOs began demanding proof of a reasonable return on investment. Today, with purse strings tightened – and cyber risks and compliance pressures mounting — CISOs must recalibrate.

I had a fascinating discussion about this with Ryan Benevides, a principal at WestCap, the growth equity firm founded by Laurence Tosi, former CFO of Blackstone and Airbnb. WestCap’s cybersecurity partnerships includes HUMAN Security, Bishop Fox and Dragos.

Benevides shared his perspective of how the cybersecurity realm has become saturated with over 4,000 venture-backed vendors who are under tighter scrutiny as well. For a full drill down, please give the accompanying podcast a listen.

Despite this turbulence, WestCap views this reset as a positive development. Both CISOs looking for better tools — and the innovators supplying them — must now focus on filling gaps and meeting genuine market needs, Benevides observes. And this can be done by leveraging advanced technologies, namely automation and AI, he says.

He highlighted the need for tools that improve communication between CISOs and board members and noted that positioning cybersecurity as a business enabler will be a key to success.

Agreed. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: Tightened budgets impose discipline on CISOs, resets security investments first appeared on The Last Watchdog.

View Details

The tectonic shift of network security is gaining momentum, yet this transformation continues to lag far behind the accelerating pace of change in the operating environment.

Related: The advance of LLMs

For at least the past decade, the cybersecurity industry has been bending away from rules-based defenses designed to defend on-premises data centers and leaning more into tightly integrated and highly adaptable cyber defenses directed at the cloud edge.

I first tapped Gunter Ollmann’s insights about botnets and evolving malware some 20 years when he was a VP Research at Damballa and I was covering Microsoft for USA TODAY. Today, Ollmann is the CTO of IOActive, a Seattle-based cybersecurity firm specializing in full-stack vulnerability assessments, penetration testing and security consulting. We recently reconnected. Here’s what we discussed, edited for clarity and length?

LW: In what ways are rules-driven cybersecurity solutions being supplanted by context-based solutions?

Ollmann: I wouldn’t describe rules-based solutions as being supplanted by context-based systems. It’s the dimensionality of the rules and the number of parameters consumed by the rules that have expanded to such an extent that a broad enough contextual understanding is achieved. Perhaps the biggest change lies in the way the rules are generated and maintained, where once a pool of highly skilled and experienced cybersecurity analysts iterated and codified actions as lovingly-maintained rules, today big data systems power machine learning systems to train complex classifiers and models. These complex models now adapt to the environments they’re deployed in without requiring a pool of analyst talent to tweak and tune.

LW: In what noteworthy ways have legacy technologies evolved?

Ollmann: Cybersecurity technologies are continuously evolving; they must because both the threat and the business requirements are continuously changing. It’s been that way since the first person suggested using a password along with a login ID.

That said, to date the two biggest changes and influences upon legacy technologies have been public cloud and AI. Public cloud not only shifted the perimeter of internet business, but it also enabled a shift to SaaS delivery models – forcing traditional legacy protection technologies to transform. This fundamentally changed the way organizations shared and consumed cyber protection and detection information. It took quite some effort to shift from every on-premise log action and rule being private and confidential, to trusting cloud solution providers with that same data, pooled across multiple customers, and reaping the benefits of collective intelligence.

That cloud transformation and pooling of threat and response data was fundamental to the second transformation: deploying and applying AI-based cybersecurity technologies that range from training and reinforcement learning of detection models to incident response playbook production and auto-response. While the core “legacy” security building blocks have remained the same, the firewalls have grown smarter, the SIEMs detect and classify kill chains faster and blocking responses have become more trusted.

LW: Which legacy solutions are threatened with extinction?

Ollmann

Ollmann: Solutions that focus on enterprise-level on-premises and air-gapped protection are on borrowed time. Some people will argue that there will always be a need for such solutions, but their efficacy against today’s threats is constantly diminishing. There’s a real reason why on-premises anti-spam gateways protecting on-premises mail services are failing, and part of that is because some classes of threats are exponentially easier to detect and mitigate through massive cloud scale and collective intelligence.

Additionally, the majority of today’s solutions that require a customer’s pool of in-house analysts and security experts to update and maintain a custom-tuned or unique set of detection rules, data connectors, response playbooks, blocking filters, etc., are also on borrowed time. The last generation of machine learning system automation and the first generation of LLM-based analyst augmentation have proven they can replace the tier-one and tier-two human analysts traditionally tasked with building and maintaining those customized rules. There’s a sizable ecosystem of tooling and providers that specialize in custom rule creation and maintenance. They’re equally in trouble if they don’t adapt and evolve.

LW: What does the integration of iterated legacy tools into edge-focused newer technologies look like?

Ollmann: To understand the next generation of security technologies and what that means for the iterated evolution of legacy tools, it’s important to step back. Too often, as security professionals, we’re day-to-day involved in watching our feet on the dance floor and keeping in time with the music. When we take a step back, we get to see the bigger movements and relationships between dances.

We have an ecosystem of niche tools and specialized solutions for elements and processes within a chained pipeline of protection and response. Enterprise buyers select and integrate these components to achieve the same lofty goals as everyone else. For the last decade, we’ve seen a significant uptick in the growth of managed security service providers that effectively offer an obscured, off-the-shelf integrated protection and/or response pipeline that focuses on delivering the buyer’s security objectives rather than the stack of technologies’ security.

In parallel, over the last half-decade, we’ve observed the rapid development and advancement of cross-cloud and hybrid-cloud security posture management and response solution providers. Vendors such as Wiz, Palo Alto Network and CrowdStrike have acquired or rebuilt from the ground up much of the legacy tooling and capabilities and brought them together as unified edge protection and security management platforms. Behind the scenes, they’ve invested hugely in intelligent automation and AI systems to overcome and do away with the stack of interdependent legacy technologies (from a customer’s perspective).

LW: Looking just ahead, which new security platforms or architectures do you expect to emerge as cornerstones?

Ollmann: I think the managed security services industry that’s been leveraging inexpensive human analysts will lose to the new cloud and edge security posture management and response solution providers unless they transform and completely embrace AI. They’re at a disadvantage because they’re not software developers. They’re not AI engineers. But they are sitting on a lot of very valuable customer data and already have the integrations and relationships to drive transformational impact to their customers.

Collective intelligence and the knowledge derived from streaming vast data is a cornerstone to protection, compliance, and threat response. AI, LLMs, machine learning models, and their future iterations’ efficacy is dependent upon this data. It’s true, data is the new gold rush.

The cornerstone around the corner (as it were) that will likely bring the next business transformation will be ubiquitous confidential cloud computing. The legacy on-premises and air-gapped business requirements disappear once confidential compute is economical, prevalent, and performant. At that point, the “edge” consolidates to the cloud-edge, and new protections over data and regulatory concerns are overcome.

LW: Where is this all taking us over the next two to five years?

Ollmann: The global shortage of cybersecurity talent continues to hold back the industry. Just as cybersecurity requirements have become mainstream, the explosion of corporate need for trained security professionals and the chasm of attaining the security experience required to protect and operate the advanced cyber defense technologies, have arguably made businesses feel less secure.

The rapid advances in applied AI to security and the growth of AI-first security companies gives us great hope in overcoming the skills gap situation.

Over the next few years, I think AI-based automation of response and augmentation of human analysts will largely overcome the bottleneck of the historic cybersecurity talent shortage.

While some experts presume that AI will help elevate a new generation of cybersecurity graduates to quickly become tier-three expertise proficient, I don’t think that’s where the primary changes and benefits will come. Just as generative AI has enabled almost anyone to near instantly create their own Shakespearean-esque sonnets or Picasso-ify their dream illustrations, I expect security AI advancements to apply to, and be adopted by, other non-cyber professionals already within the business.

It’s exponentially easier and more beneficial to elevate someone with multiple years of institutional experience and business process knowledge and augment them with advanced security capabilities than to take a cybersecurity graduate and teach them the ins and outs of the business and personalities in play.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


The post NEWS ANALYSIS Q&A: Striving for contextual understanding as digital transformation plays out first appeared on The Last Watchdog.

View Details

Confidence in the privacy and security of hyper-connected digital services is an obvious must have.

Related: NIST’s quantum-resistant crypto

Yet, Digital Trust today is not anywhere near the level it needs to be. At RSAC 2024 I had a wide-ranging conversation with DigiCert CEO Amit Sinha all about why Digital Trust has proven to be so elusive. For a full drill down, please give the accompanying podcast a listen.

We spoke about how the Public Key Infrastructure (PKI) has come under pressure. PKI and digital certificates provide the essential framework for authenticating identities, encrypting communications and ensuring data integrity.

However, with the shift to remote work and the proliferation of Internet of Things systems, the complexity of maintaining a fundamental level of trust in digital services has risen exponentially.

And that curve will only steepen as GenAI/LLM services ramp up and quantum computers get mainstreamed, Sinha observed.

Sinha highlighted the importance of automation and comprehensive control in managing digital certificate sprawl. With respect to AI innovation, Sinha noted a couple of near -term concerns: distinguishing real from fake content and ensuring the integrity of the software supply chain. With so many more connections being made, extending and scaling the PKI framework to help mitigate these new exposures makes sense and can be done, he argues.

At same time, companies need to stay in step with efforts National Institute of Standards and Technology (NIST) to implement quantum-resistant algorithms. DigiCert supports this push and is hosting the first World Quantum Readiness Day on September 26.

Digital Trust absolutely needs to be on the front burner. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: Here’s what it will take to achieve Digital Trust in our hyper-connected future first appeared on The Last Watchdog.

View Details

Taking stock of exposures arising from the data-handling practices of third-party suppliers was never simple.

Related: Europe requires corporate sustainability

In a hyper-connected, widely-distributed operating environment the challenge has become daunting.

At RSAC 2024, I visited with Paul Valente, co-founder and CEO of VISO TRUST. We had a wide-ranging discussion about the limitations of traditional third-party risk management (TPRM), which uses extensive questionnaires—and the honor system – to judge the security posture of third-party suppliers. For a full drill down, please give the accompanying podcast a listen.

VISO TRUST launched in 2020 to introduce a patented approach, called Artifact Intelligence, to automate the assessment of third-party risks. This method employs natural language processing (NLP) and various machine learning models, including large language model (LLM) to automate the assessment of third-party risks, Valente told me.

The benefits of advanced TPRM technologies extend beyond implementing these audits much more efficiently and effectively at scale. Valente cited how a customer, Illumio, is leveraging Artifact Intelligence to conduct vendor assessments very early in the procurement process, significantly enhancing decision-making and avoiding high-risk relationships.

The evolving regulatory landscape is a significant driver for the adoption of advanced TPRM solutions. From the stringent interagency guidelines and state laws in New York to healthcare regulations and European legal frameworks, companies face mounting pressures to enhance their third-party cyber risk management practices, Valente noted.

With “companies approaching 100 percent third-party integration,” CISOs are making TPRM a top priority, he says. “It’s just an enormous challenge. And to solve it from a CISO standpoint means solving the scalability issue and solving the data quality issue.”

The shoring up of supply chain security continues. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: VISO TRUST replaces questionaires with AI analysis to advance ‘TPRM’ first appeared on The Last Watchdog.

View Details

Companies that need to protect assets spread across hybrid cloud infrastructure face a huge challenge trying to mix and match disparate security tools.

Related: Cyber help for hire

Why not seek help from a specialist? At RSAC 2024, I visited with Geoff Haydon, CEO, and Alex Berger, Head of Product Marketing, at Ontinue, a new player in the nascent Managed Extended Detection and Response (MXDR) space.

MXDR extends from the long-established Managed Security Service Providers (MSSP) space. MSSPs came along 20 years ago to assist with on-premises tools like firewalls, intrusion detection and antivirus tools.

Managed Detection and Response (MDR) arose to focus on advanced threat detection and remediation. And next came MXDR solutions, which offer wider, more integrated coverage while emphasizing automation and collaboration.

Haydon and Berger, for instance, explained how Ontinue leverages machine learning to automate detection and low-level incident management. For a full drill down please give the accompanying podcast a listen.

Berger told me how Ontinue has begun leveraging Large Language Model (LLM) tool to automate incident summarization. LLM is perfectly suited to this task. Human analysts no longer must carve out time to write coherent summaries – and no longer even need to be fluent in English.

Ontinue has also tightly integrated their services with Microsoft Teams – to promote close collaboration with clients. “Security is a team sport,” Haydon says. “This allows us to become an integral part of our customers’ IT and security teams.”

How far will MXDR take organizations as they navigate unprecedented risks? I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: Ontinue ups the ‘MXDR’ ante — by emphasizing wider automation, collaboration first appeared on The Last Watchdog.

View Details

Torrance, Calif., June 10, 2024, CyberNewsWire — AI SPERA, a leader in Cyber Threat Intelligence (CTI) solutions, announced that it has started selling its paid threat detection data from its CTI search engine ‘Criminal IP‘ on the Snowflake Marketplace.

Criminal IP is committed to offering advanced cybersecurity solutions through Snowflake, the leading cloud-based data warehousing platform.

Criminal IP’s Intelligence for Fraud Detection and Privacy Protection is meticulously crafted to address the growing concerns surrounding fraudulent activities and privacy breaches. By aggregating data on known malicious and masked IP addresses, including those with historical abuse records such as IDS, malware, phishing, ransomware, and blocked IPs, this dataset equips organizations with actionable insights to identify and mitigate fraudulent activities in real time.

Additionally, the product boasts advanced capabilities to detect servers infected by botnet and C2 software, as well as IP addresses leveraging masking services like VPNs, proxies, and hosting. This product is tailored to support fraud detection (FDS) and malicious IP plans, enabling organizations to bolster their security posture and streamline incident response protocols.

Criminal IP’s Intelligence for Threat Detection & Incident Response is designed to empower organizations to combat cyber threats effectively. This comprehensive cyber threat intelligence dataset provides invaluable insights into malicious IP addresses, leveraging data sourced from Criminal IP’s Cyber Threat Intelligence Database (CTIDB).

These new datasets on the Snowflake Marketplace offer granular, real-time threat intelligence, enabling organizations to safeguard digital assets, mitigate risks, and respond swiftly to security incidents. Snowflake’s global customers can access a complimentary trial of up to 1,000 data items, with subscription options for daily updates.

About AI Spera. AI SPERA, a leader in Cyber Threat Intelligence (CTI) solutions, significantly expanded its reach by launching its flagship solution, Criminal IP, in 2023. Since then, the company has formed technical and business collaborations with over 40 renowned global security firms, including VirusTotal, Cisco, Tenable, Sumo Logic, and Quad9.

Besides the CTI search engine, the company offers Criminal IP ASM, a SaaS-based Attack Surface Management Solution on AWS and Azure Marketplace, and Criminal IP FDS, an AI-based Anomaly Detection Solution used for credential stuffing prevention and fraud detection. Available in five languages (English, French, Arabic, Korean, and Japanese), the search engine provides a powerful service for users worldwide.

Media contact: Michael Sena, AI SPERA support@aispera.com

The post News Alert: Criminal IP unveils innovative fraud detection data products on Snowflake Marketplace first appeared on The Last Watchdog.

View Details

Could we be on the verge of Privacy Destruction 2.0, thanks to GenAI?

Related: Next-level browser security

That’s a question that spilled out of a thought-provoking conversation I had with Pedro Fortuna, co-founder and CTO of Jscrambler, at RSAC 2024.

Jscrambler provides granular visibility and monitoring of JavaScript coding thus enabling companies to set and enforce security rules and privacy policies. For instance, it helps online tax services prevent leakage of taxpayers’ personal information via pixels, those imperceptible JavaScripts embedded in a web page to collect information about the user’s interactions.

It turns out, Fortuna observed, that GenAI/LLM is perfectly suited to the deeper mining of personal data collected by pixels as well as other JavaScript mechanisms currently in wide use.

This brought to mind 2010, the year I wrote news stories for USA TODAY about Mark Zuckerberg declaring privacy was “no longer a social norm” and Google CEO Eric Schmidt admitting that Google’s privacy policy was to “get right up to the creepy line and not cross it.”

Today, the temptation for companies to leverage GenAI/LLM just to get ahead of the competition is intense; and the stage is set for them to trample what remains of privacy protection in the post Zuckerberg/Schmidt era.

Jscrambler can at least provide technology to monitor and control how third-party JavaScript components handle private data. But at the end of the day, company leaders must be compelled to avail themselves of such tools and make privacy protection a priority.

For his part, Fortuna told me he is concerned that his two young children might become accustomed to relinquishing their privacy to unscrupulous data collectors; but he’s also optimistic that guardrails will emerge. For a full drill down, please give the a listen.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: Jscrambler levels-up JavaScript security, slows GenAI-fueled privacy loss first appeared on The Last Watchdog.

View Details

Identity and Access Management (IAM) is at a crossroads.

Related: Can IAM be a growth engine?

A new Forrester Trends Report dissects ten IAM trends now in play, notably how AI is influencing IAM technologies to meet evolving identity threats.

IAM is a concept that arose in the 1970s when usernames and passwords first got set up to control access mainframe computers.

By the 1990s, single sign-on (SSO) solutions had caught, and with the explosion of web apps that followed came more sophisticated IAM solutions. Federated identity management emerged, allowing users to use the same identity across different domains and organizations, and standards like SAML (Security Assertion Markup Language) were developed to support this.

The emergence of cloud computing further pushed the need for robust IAM systems. Identity as a Service (IDaaS) began to gain traction, offering IAM capabilities through cloud providers.

Last Watchdog engaged Forrester Principal Analyst Geoff Cairns, the report’s lead author, in a discussion about the next phase of IAM’s. Here’s that exchange, edited for clarity and length.

A new Forrester Trends Report dissects ten IAM trends now in play, notably how AI is influencing IAM technologies to meet evolving identity threats.

IAM is a concept that arose in the 1970s when usernames and passwords first got set up to control access mainframe computers.

By the 1990s, single sign-on (SSO) solutions had caught, and with the explosion of web apps that followed came more sophisticated IAM solutions. Federated identity management emerged, allowing users to

LW: In the grand scheme, how urgent has it become for companies to focus on identity threats?

Cairns: The urgency for companies to focus on identity threats has significantly increased over the past few years due to several factors. First, the rapid advancement of technology has created a more complex and interconnected digital landscape, making it easier for attackers to exploit vulnerabilities. Second, the growing adoption of cloud and SaaS services, as well as remote work arrangements and the extended workforce, has expanded the identity threat surface. Third, high-profile data breaches, such as the recent Change Healthcare cyberattack, have underscored the importance of effective identity security controls in protecting sensitive information.

LW: What’s the vital lesson stemming from IAM-related breaches like those seen with MGM and Okta?

Cairns

Cairns: One of the most vital lessons for CISOs and IAM leaders to take away from the MGM and Okta breaches is that your IAM vendors’ servicing and operations is intrinsic to your own organization’s security posture and, ultimately, end-customer trust. The ongoing consolidation of IAM vendors and technology stacks will lead to greater concentration of supplier risk, as well. We expect IAM platform vendors will face increased scrutiny from their prospects and customers as it relates to underlying platform security and incident response practices.

LW: Can you share an anecdote that illustrates exactly how generative AI is being used to improve threat detection and remediation in IAM systems?

Cairns: Given the ability to input natural language queries (e.g., “show me the last 5 privileged account access attempts”), IAM administrators are conducting conversational interrogations of the IAM system to more swiftly identify and isolate identity threats. With IAM administrators also able to use AI to generate immediate, actionable steps for remediation, incident response time is significantly reduced. In the future, we expect to see genAI advances that will proactively generate and optimize IAM policies to pre-empt future threats.

LW: What should CISOs clearly understand about integrations between IAM and non-IAM cybersecurity vendors?

Cairns: CISOs should understand that to effectively respond to identity-centric threats, integration is necessary between IAM and non-IAM cybersecurity tool sets. Support for these integrations is quickly maturing. Across your existing security vendor portfolios, review roadmaps and integration points for identity threat detection, signal sharing, and response automation. Most importantly, leverage the opportunity to drive tighter operational process alignment and a stronger working relationship between IAM and SecOps teams.

LW: Are legacy IAM solutions obsolete; will they — or be replaced?

Cairns: Even as environments get more complex and attacks get more sophisticated, companies should remain rooted in solid IAM fundamentals and core principles – strong authentication, least privilege access, robust monitoring – applying a defense in depth approach. However, organizations must systematically evolve and upgrade their underlying IAM technology platforms to match their IT environment and the current threat landscape. In some cases, like phishing-resistant passwordless MFA, it capitalizes on technical advances (biometrics, compute power) layered on top of well-established practices (multifactor authentication). In other instances, it may require re-engineering of processes and systems to adopt a different technology or approach, such as verifiable credentials or zero standing privileges. To be effective, IAM implementations must be dynamic and constantly evolving.

LW: Anything else?

Cairns: While staying updated on IAM technology trends is certainly important, perhaps the most critical thing that CISOs and IAM leaders can do is to nurture and maintain the right culture. Many security leaders that Forrester has spoken with stress the importance of establishing cross-functional relationships and collaboration to ensure a business-led approach to IAM. Prioritizing user-centric design thinking and a growth mindset are paramount for building a high-performing IAM team and applying the right set of IAM technologies to both protect and enable the business.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


The post SHARED INTEL Q&A: Forrester report shows Identity and Access Management (IAM) in flux first appeared on The Last Watchdog.

View Details

Digital rights management (DRM) has come a long way since Hollywood first recognized in the 1990s that it needed to rigorously protect digital music and movies.

By the mid-2000s a branch called enterprise digital rights management (EDRM) cropped up to similarly protect sensitive business information. Today, businesses amass vast amounts of business-critical data – at a pace that’s quickening as GenAI takes hold.

At RSAC 2024 I sat down with Isaac Roybal, chief marketing officer at Seclore, to discuss how the challenge of securing business data has moved beyond even where the EDRM space has been evolving. For a drill down, please give the accompanying podcast a listen.

Seclore takes a data-centric approach to securing data by aligning granular controls with the sensitive data itself. This allows for security teams to dynamically manage permissions, rescind access, alter editing capabilities, and even perform real-time compliance checks, he noted.

“We can ensure that only authorized users have access and can perform specific actions such as reading, editing, or printing,” he says.

Seclore facilitates data protection in a global productivity ecosystem that’s constantly shifting between on-premises, hybrid and cloud architectures. Its ability to integrate seamlessly with existing security tools and policies is a key differentiator, Roybal says.

By partnering with DLP, CASB, and classification vendors, Seclore ensures that organizations can leverage their current investments while enhancing their overall security posture.

“We’re not asking organizations to start from scratch,” he emphasized. “Our solutions integrate with the tools [users] already use, allowing for a more cohesive and effective security framework.”

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: Seclore advances ‘EDRM’ by aligning granular controls onto sensitive data first appeared on The Last Watchdog.

View Details

Business data today gets scattered far and wide across distributed infrastructure.

Just knowing where to look – or even how to look – much less enforcing security policies, has become next to impossible for many organizations.

At RSAC 2024, I visited with Pranava Adduri, co-founder and CEO of Bedrock Security which has just rolled out its AI Reasoning (AIR) Engine to help solve this problem in a bold new way.

The start-up leverages serverless architectures to discover patterns in large datasets and then maps out data boundaries without having to examine every single data point.

This “commoditization” of data discovery, as Adduri puts it, slashes the cost of data discovery at scale. For instance, Amazon’s AWS Macie service charges around $1,000 per terabyte for data discovery, or $1 million per petabyte, Adduri told me.

By contrast, he says, Bedrock’s patented “adaptive sampling” technology can scan 16 petabytes of data for just $2,000. Their system then superimposes a dynamic heat map to categorize the data “neighborhoods” based on sensitivity at any given moment.

“We come at it from big data background,” Adduri says. “Step one is you have to keep track of all the stuff that’s happening; step two is you have to make sense of it; and step three is you have to constantly remediate.”

Bedrock secured a $10 million seed investment led by Greylock Partners and it has a growing portfolio of customers reporting strong results, Adduri says.

For a full a drill down please give the accompanying podcast a listen.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: Bedrock Security introduces advanced approach to “commoditize” data discovery first appeared on The Last Watchdog.

View Details

When Log4J came to light in 2021, Kinnaird McQuade, then a security engineer at Square, drew the assignment of testing endpoints at some 5,000 users of the popular mobile payments service.

Related: The big lesson from Log4J

“It took us eight hours to run the scan and I was sweating it because these were all small family businesses that depended on Square, and if any of them got popped, it would be real people that were affected,” McQuade told me.

That ordeal proved to be a catalyst for McQuade, a renowned ethical hacker and creator of popular open-source security tools, to launch NightVision and succeed where static application security testing (SAST) and dynamic application security testing (DAST) have failed.

The focus is on providing a software testing solution that does not impede innovation, provides clear guidance to developers and identifies software vulnerabilities long before public release. Last week, NightVision announced the commercial availability of its first application security testing solution.

I visited with McQuade, who’s now NightVision’s CTO, and George Prince, CEO, at RSAC 2024 a couple weeks prior to their launch. For a full drill down, please give the accompanying podcast a listen.

NightVision recently announced $5.4 million seed backing of its hybrid approach to enable software developers to detect vulnerabilities quickly and accurately, tracing them back to the source code for immediate action. This capability is crucial as businesses increasingly rely on APIs, the vast majority of which remain undocumented and vulnerable to attacks, Prince observes.

“We’re solving a fundamental problem at its root,” Prince says. “Our tools make it possible to perform security scans in seconds, not hours, and offer actionable insights that help developers fix issues before they reach production. This not only saves time but also significantly reduces the risk of security breaches.”??

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: NightVision shines a light on software vulnerabilities, speeds up remediation first appeared on The Last Watchdog.

View Details

AI has the potential to revolutionize industries and improve lives, but only if we can trust it to operate securely and ethically.

Related: The key to the GenAI revolution

By prioritizing security and responsibility in AI development, we can harness its power for good and create a safer, more unbiased future.

Developing a secured AI system is essential because artificial intelligence is a transformative technology, expanding its capabilities and societal influence. Initiatives focused on trustworthy AI understand the profound impacts this technology can have on individuals and society. They are committed to steering its development and application towards responsible and positive outcomes.

Security considerations

Securing artificial intelligence (AI) models is essential due to their increasing prevalence and criticality across various industries. They are used in healthcare, finance, transportation, and education, significantly impacting society. Consequently, ensuring the security of these models has become a top priority to prevent potential risks and threats.

•Data security. Securing training data is crucial for protecting AI models. Encrypting data during transmissionwill prevent unauthorized access. Storing training data in encrypted containers or secure databases adds a further layer of security.

Data masking can safeguard sensitive data, even during breaches. Regular backups and a disaster recovery plan are essential to minimize data loss and ensure the security and integrity of training data, safeguarding AI models from potential risks and threats.

•Model Security. Model encryption should be employed to protect against unauthorized access, tampering, or reverse engineering. Watermarking or digital fingerprints can help track AI models and detect unauthorized use.

Digital signatures ensure the integrity and authenticity of models, confirming they have not been altered. Implementing model versioning is crucial for tracking updates and preventing unauthorized changes.

Mandadi

Additionally, regular testing and validation are necessary to ensure models function correctly and are free of security vulnerabilities. These measures collectively enhance the security of AI models, protecting them from potential risks. Attention to detail in these areas is vital:

•Infrastructure Security. Protecting hardware components like GPUs and TPUs used in training and deploying AI models is crucial. Updating software with the latest security patches and adhering to secure coding practices.

Implementing robust network security protocols, including firewalls and intrusion detection systems, is necessary to block unauthorized access. Cloud security is critical since many AI models are trained and deployed on cloud-based platforms.

Additionally, an effective incident response plan is essential for quickly addressing security incidents and mitigating the impact of breaches. Together, these measures ensure the infrastructure’s security and protect against potential risks and threats.

•Access controls. It is crucial to tightly control access to AI models, data, and infrastructure to prevent security incidents. Role-based access controls should limit access based on user roles and privileges, alongside robust authentication and authorization mechanisms.

Following the principle of least privilege access is vital, granting users only necessary access. Monitoring user activity helps detect and respond to potential security incidents.

•Secure development lifecycle. Building secure AI systems requires a systematic approach. By integrating security into every stage of AI development, organizations can ensure the confidentiality, integrity, and availability of their AI systems and data. You can build a secure AI system by following the steps below.

•Secure design. The secure design stage is foundational to the secure AI development lifecycle. It involves defining security requirements and threat models, conducting security risk assessments and architecture reviews, and implementing secure data management and privacy controls.

This stage ensures security is integrated into the AI system from the beginning, minimizing the risk of security breaches and vulnerabilities.

•Development. During the development stage, developers apply secure coding practices, conduct regular security testing and vulnerability assessments, utilize secure libraries and dependencies, and establish authentication, authorization, and access controls. This stage prioritizes security in the development of the AI system and addresses potential vulnerabilities early on.

•Deployment. Ensuring secure deployment configurations and settings is crucial during the deployment stage. Thorough security testing and vulnerability assessments are conducted beforehand. Utilizing secure deployment mechanisms and infrastructure is essential for securely deploying the AI system. Implementing robust monitoring and logging controls also mitigates potential security risks.

•Operation and maintenance. Once your AI system is operational, it should undergo continuous security monitoring. This includes regular updates, security assessments, and risk evaluations. Incident response and disaster recovery plans are also in place to maintain security and address potential incidents.

Developing secure AI systems requires a systematic approach that integrates security into every stage of AI development. Implementing robust security measures and ethical considerations builds trust in AI solutions, ensuring they are secure, reliable, and resilient. This approach enables AI to be a powerful tool for positive change.

About the essayist: Harish Mandadi, is the founder and CEO of AiFA Labs as CEO and Founder. AiFA Labs, which supplies comprehensive enterprise GenAI platforms for text, imagery and data patterns.

The post GUEST ESSAY: Taking a systematic approach to achieving secured, ethical AI model development first appeared on The Last Watchdog.

View Details

From MFA to biometrics, a lot has been done to reinforce user ID and password authentication — for human users.

Related: How weak service accounts factored into SolarWinds hack

By comparison, almost nothing has been done to strengthen service accounts – the user IDs and passwords set up to authenticate all the backend, machine-to-machine connections of our digital world.

Service accounts have multiplied exponentially in recent years and become a prime target of threat actors, since little has been done to beef up protection.

A just-out-of-stealth start-up, Anetac, has secured $16 million in funding to address this gaping blind spot. At RSAC 2024, I sat down with Baber Amin, Head of Product at Anetac, Diana Nicholas, co-founder of Anetac, to learn more.

Identity vulnerability is a dynamic problem, and Anetac’s platform dynamically provides real-time streaming visibility and monitoring of human and non-human accounts, service accounts, APIs, tokens and access keys. This approach contrasts with static scanning tools that have come along from the big name IAM solution providers, like Okta and CyberArk, Amin and Nicholas told me.

The idea for Anetac derived from asking companies about their pain points. “We spoke to major banks, insurance companies, and even small businesses,” Nicholas says. “The overwhelming response was that service account management is one of the biggest problems they face.”

Anetac’s platform can identify dormant accounts, map out weak protocol usage and even stop identity attacks in progress, Amin noted. For a full drill down on how Anetac aims to raise the bar, please give the accompanying podcast a listen. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: Start-up Anetac rolls out a solution to rising ‘service accounts’ exposures first appeared on The Last Watchdog.

View Details

Washington D.C., May 29, 2024, PRNewswire — DNSFilter announced today that it has joined the WeProtect Global Alliance to help prevent the spread of child sex abuse material (CSAM) online.

This partnership will help further WeProtect’s mission and work toward creating a safer online environment for children.

The WeProtect Global Alliance was founded to create a cohesive, comprehensive response to the widespread issue of online child sexual abuse and exploitation. It brings together partners from governments, non-profit organizations and the private sector to develop policies and solutions. Research by the Alliance has found that the volume of reported abuse material cases increased by 87% between 2019 and 2023.

As a cybersecurity company, DNSFilter’s role encompasses more than just defending against malware and phishing; it extends to protecting the physical and emotional safety of individuals. DNSFilter permanently blocks the CSAM category with no exceptions, underscoring the company’s commitment to protecting the safety of the individuals affected by this content.

In the first quarter of 2024 alone, DNSFilter has already blocked nearly 1 million requests for CSAM and is on track to block five times as much CSAM content this year as it did in 2023.

Membership of the Alliance will enable DNSFilter to help address this challenge on a wider-scale as well as for its own customers, including larger-scale organizations looking to lock down this section of the internet even more.

Iain Drennan, executive director, WeProtect Global Alliance, said: “The growth of child sexual abuse and exploitation online is not an inevitable consequence of technological advances, it is a preventable problem.

Drennan

“Technology has a significant role in providing solutions to the problem and we are delighted DNSFilter has joined the Alliance to share knowledge, collaborate and empower others. DNSFilter joins over 300 other member organizations worldwide from government, civil society and the private sector – together we are a real force for change in keeping children safe online worldwide.”

Ken Carnesi, CEO and co-founder, DNSFilter, said: “Blocking CSAM is inherent to what we do at DNSFilter, because online security goes beyond phishing and malware—it includes physical and emotional safety. Our goal is to protect people, not just the machines that they use.

Carnesi

“We take great pride in our firm stance against CSAM and feel fortunate to ally with such an impactful and passionate organization. We’re looking forward to learning from their educational resources and meetings and translating that knowledge into more effective strategies to protect children.”

The post News Alert: DNSFilter joins the WeProtect Global Alliance to help protect children online first appeared on The Last Watchdog.

View Details

The capacity to withstand network breaches, and minimize damage, is a key characteristic of digital resiliency.

Related: Selecting a Protective DNS

One smart way to do this is by keeping an eagle eye out for rogue command and control (C2) server communications. Inevitably, compromised devices will try to connect with a C2 server for instructions. And this beaconing must intersect with the Domain Name System (DNS.)

At RSAC 2024, I had an evocative discussion with David Ratner, CEO of HYAS, about advances being made in DNS security. For a full drill down, please give the accompanying podcast a listen.

HYAS gathers rich intelligence from multiple sources and then feeds it into a specialized graph database focused on a variety of infrastructure data including DNS traffic. This allow HYAS to isolate — and even predict — the formation of malicious infrastructure – before the attackers can fully weaponize the breached system.

“Our goal is to understand what’s going to be used as a command-and-control server in the future so that you can be blocking it now,” he told me.

DNS security and the overall Protective DNS space is rising in importance. The NSA’s Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems and subsequent CISA Shields Up initiative highlighted the necessity of such solutions. Additionally, cyber insurance carriers and the Department of Defense’s CMMC standard now recommend or require advanced protective DNS solutions.

Looking ahead, Ratner foresees protective DNS steadily advancing — to keep pace with C2 innovation sure to come from adversaries. As new attack patterns emerge, HYAS aims to adapt and expand its solutions to cut-off all types of C2 communications, he says.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: Rich threat intel, specialized graph database fuel HYAS’ Protective DNS first appeared on The Last Watchdog.

View Details

Cary, NC, May 28, 2024, CyberNewsWire — If there is a single theme circulating among Chief Information Security Officers (CISOs) right now, it is the question of how to get stakeholders on board with more robust cybersecurity training protocols.

There are key points debated about why you should provide cybersecurity training to your IT professionals, like the alarming increase in cyberattacks (an increase of 72% over the all-time high in 2021, according to the Identity Theft Research Center’s 2023 Data Breach Report), or the rapid evolution in technology, creating a constant game of catch-up.

But it isn’t a question of ”if” an organization will be targeted, but “when.” CISOs are increasingly anxious because while they realize the ax will fall on them when the inevitable breach occurs, securing boardroom support for heavy investment in preventative measures, like training, is challenging in a world where revenue is demanded for each dollar spent.

Warn

“The path to securing the boardroom’s buy-in is more complex than simply having the right statistics and studies on paper,” says Dara Warn, the CEO of INE Security, a global cybersecurity training and certification provider. “To bridge the gap between CISOs and stakeholders, CISOs must adopt a strategic approach that combines financial impact data, relevant case studies, and compelling narratives. Framing cybersecurity training as an essential investment rather than an optional expense is critical.”

The human factor

Cybersecurity is not just about technology; it’s about people. Human error remains one of the leading causes of security breaches. A study by Verizon in their 2023 Data Breach Investigations Report found that 68% of breaches involved a human element, such as social engineering, misuse of privileges, or simple mistakes. This highlights the importance of equipping employees with the knowledge and skills to recognize and respond to potential threats.

Capital One case study

In 2019, Capital One experienced a data breach that exposed the personal information of over 100 million customers. The breach was caused by a misconfigured web application firewall, which allowed an attacker to access sensitive data stored on Amazon Web Services (AWS). This incident underscores the importance of training employees on cloud security practices and the proper configuration of security tools. In response, Capital One enhanced its cybersecurity training programs to include cloud security, emphasizing the need for regular audits and configuration checks. This case illustrates how specialized training can prevent costly breaches and protect sensitive data.

Training ROI

Investing in cybersecurity training is not just a defensive measure; it’s a strategic investment that can yield significant returns. A well-trained workforce, not just security awareness but the SOC and networking teams, can serve as the first line of defense against cyber threats, reducing the likelihood of breaches and minimizing potential damages. According to the Ponemon Institute’s 2023 Cost of Data Breach Report, organizations with extensive incident response planning and testing programs saved $1.49 million compared to those with lower levels.

Maersk NotPetya case study

In 2017, shipping giant Maersk was hit by the NotPetya malware, which spread rapidly through its global network, causing a complete shutdown of its IT systems. The attack was initiated by a compromised software update, exploiting poor cybersecurity hygiene and a lack of employee training on identifying malicious software. The incident cost Maersk over $300 million in losses. In response, Maersk implemented a comprehensive cybersecurity training program focusing on recognizing malicious software, securing software updates, and responding to cyber incidents. This case highlights the necessity of training employees on the latest cyber threats and best practices.

Boardroom narrative

The company’s financial data and case studies are important to secure, but communicating that to the boardroom remains a challenge for CISOs. To get the message across, CISOs must also craft a compelling narrative that resonates with the board members. Here are some key strategies:

•Speak the Board’s Language. Board members are often more attuned to financial metrics and business outcomes than technical jargon. CISOs should frame cybersecurity training as a business enabler that protects the organization’s bottom line. Highlighting the potential financial losses from breaches and the ROI of training programs can make a compelling case.

•Use Real-World Examples. Real-world case studies, like the attacks on Maersk NotPetya and Capital One, can illustrate the tangible impact of cybersecurity training. These examples provide relatable scenarios that underscore the importance of investing in employee education.

•Leverage Data and Statistics. Presenting data from reputable sources can lend credibility to the argument. Statistics that demonstrate the prevalence of human error in breaches and the financial benefits of training can be powerful tools in persuading the board.

•Emphasize Regulatory Compliance. Regulatory requirements, such as GDPR and CCPA, mandate stringent data protection measures. Failure to comply can result in hefty fines and reputational damage. Emphasizing how cybersecurity training can help meet these regulatory requirements can be an effective angle to secure board buy-in.

•Highlight Competitive Advantage. In an increasingly competitive market, robust cybersecurity measures can be a differentiator. Companies known for their strong security posture are more likely to attract and retain customers. CISOs can highlight how a comprehensive training program can enhance the organization’s reputation and competitive edge.

Overcoming objections

Board members may raise objections regarding the cost and time required for cybersecurity training. CISOs should be prepared to address these concerns with data-driven arguments and strategic insights.

Cost Concerns

While the initial investment in training programs may seem significant, CISOs can emphasize the long-term cost savings from preventing breaches. According to the Ponemon Institute, the average cost of a data breach in 2023 was $4.45 million. Investing in training can mitigate these costs by reducing the likelihood and severity of breaches.

Time Constraints

Board members may worry about the time employees will spend on training. CISOs can advocate for flexible, modular training programs that allow employees to learn at their own pace without disrupting productivity. Additionally, emphasizing the efficiency of targeted training programs can alleviate concerns about time investment.

CISOs are key players in protecting their organizations from cyber threats. Getting the boardroom to buy into an investment in cybersecurity training is no easy task, but utilizing some of these strategies can make it more successful. Including these steps in the process of communicating your needs to stakeholders will help secure the support and resources needed to roll out effective training programs and ultimately better safeguard the organization’s digital and physical assets. The stakes are high, and having all stakeholders on the same team is critical to the long-term success and security of an organization.

About INE Security. INE Security is the premier provider of online technical training and cybersecurity certifications. Harnessing the world’s most powerful hands-on lab platform, cutting-edge technology, global video distribution network, and world-class instructors, INE is the top training choice for Fortune 500 companies worldwide, and for IT professionals looking to advance their careers. INE’s suite of learning paths offers an incomparable depth of expertise across cybersecurity, cloud, networking, and data science. INE is committed to delivering advanced technical training, while also lowering the barriers worldwide for those looking to enter and excel in an IT career.

Media contact: Press Team, INE, press@ine.com

The post News Alert: INE Security enables CISOs to secure board support for cybersecurity training first appeared on The Last Watchdog.

View Details

Spread spectrum technology helped prevent the jamming of WWII radio-controlled torpedoes and subsequently became a cornerstone of modern-day telecom infrastructure.

For its next act, could spread spectrum undergird digital resiliency? I had an evocative discussion about this at RSAC 2024 with Dispersive CEO Rajiv Plimplaskar. For a full drill down, please give the accompanying podcast a listen.

For historical context, the U.S. military scattered radio-signals and added noise to radio transmissions — to prevent the jamming of torpedo controls. Decades later, the telecom industry figured out how to spread WiFi, GPS, BlueTooth and 5G signals over a wide bandwidth and then also added pseudo-random codes — to prevent tampering.

Dispersive launched in 2021 to adapt these same concepts to protecting sensitive network transmissions in a highly dynamic environment. Here what Plimplaskar told me:

“We’re leveraging spread spectrum concepts in terms of how conventional TCP/IP and UDP type of traffic is communicated between users and sites, cloud estates and sites and amongst each other. We take the information of value and split it across multiple streams. These streams travel across randomized pathways, across whatever infrastructure is available to them, and when they get to the destination, they are reassembled and reordered for consumption.”

Encryption gets applied across multiple planes and gets dynamically rotated, based on a predefined or policy-driven interval, he noted. The streams traverse a “situationally- aware” network that can “react in real time to a degraded network situation or even a cyber event.”

A step forward for resiliency. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: Dispersive adapts WWII radio-signal masking tool to obfuscating network traffic first appeared on The Last Watchdog.

View Details

AppSec has never been more challenging.

By the same token, AppSec technology is advancing apace to help companies meet this challenge.

Related: AppSec market trajectory

At RSAC 2024, I sat down with Bruce Snell, cybersecurity strategist at Qwiet.ai, to hear a break down about how Qwiet has infused it’s preZero platform, with graph-database capabilities to deliver SAST, SCA, container scanning and secrets detection in a single solution. For a full drill down, please give the accompanying podcast a listen.

We also had a lively sidebar about the lessons security vendors are learning as they race to integrate GenAI and LLM technology into their respective solutions. Like many vendors I spoke to in San Francisco, Qwiet has trial tested several general-purpose and security-specific LLM tools.

“Utilizing the right LLM is extremely important,” Snell observes. “We intentionally built our auto fix tool so that we can replace the LLM if we need to, because we didn’t want to get locked in and then a few months later find out that there’s another LLM that handles this more efficiently.

“It’s like the old days of antivirus where one vendor would say, ‘Well, we detect 97 percent,’ and another would say, ‘Oh, we detect 98 percent.’ GenAI and LLMs are definitely in the space right now, and we want to make sure that we future-proof whatever we put together. And the only way to do that is to be modular.”

The pace of change notches higher. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: Qwiet AI leverages graph-database technology to reduce AppSec noise first appeared on The Last Watchdog.

View Details

It’s easy to compile a checklist on why the announced merger of LogRhythm and Exabeam could potentially make strategic sense.

Related: Cisco pays $28 billion for Splunk

LogRhythm’s is a long established SIEM provider and Exabeam has been making hay since its 2013 launch advancing its UEBA capabilities. Combining these strengths falls in line with the drive to make cloud-centric, hyper-interconnected company networks more resilient.

Forrester Principal Analyst Allie Mellen observes: “The combined organization is likely to push hard in the midmarket, where LogRhythm’s existing suite has had success and the Exabeam user experience makes it a more natural fit.”

Despite the promising synergies, Mellen cautioned that the merger alone would not resolve all challenges. “Both of these companies have faced challenges in recent years that are not solved by a merger,” she adds. “These include difficulty keeping pace with market innovation and with the transition to the cloud.” she said.

Last Watchdog engaged Mellon in a drill down on other ramifications. Here’s that exchange, edited for clarity and length.

LW: How difficult is it going to be for LogRhythm and Exabeam to align their differing market focuses; what potential conflicts are they going to have to resolve?

Mellen

Mellen: The companies have dramatically different company cultures and processes, as LogRhythm is a veteran security companyfounded in 2003 with a focus on a suite-style offering, while Exabeam is, by comparison, a younger company founded in 2012 with a focus on modular, stand-alone products.

In addition, both companies have faced challenges in recent years that are not solved by a merger: difficulty keeping pace with market innovation and with the transition to the cloud. LogRhythm has traditionally focused on the midmarket, while Exabeam aggressively pursued large enterprise deals, highlighting a difference in target market that must be bridged.

LW: How do you see them competing against the hyperscalers, i.e. Microsot, AWS and Google, who are muscling into this space?

Mellen: Since 2018 we have talked about how the Tech Titans are changing the cybersecurity market. The past few years have demonstrated the accuracy of that prediction, with Microsoft, AWS, and GCP having an outsize impact on the security market.

This acquisition is, in part, to help both companies continue to be competitive in this market against the likes of the Tech Titans. However, while the hyperscalers are investing heavily in security, the combined entity will be playing catch-up trying to integrate two very different products and companies into one.

LW: What specific areas of innovation should the merged entity prioritize to stay competitive?

Mellen: LogRhythm and Exabeam are likely to experience a period of innovation stagnation as they work to combine. The most important first step for them: getting the combined entity and products aligned. Once they have addressed that, the innovation they push forward should be focused on serving the mid market. That’s where they can have the most impact with the combined offering. As always, ease of use, log pipeline management, and quality of analytics are some of the biggest challenges for SIEM vendors and should be the combined entity’s focus.

LW: In what ways could the combined concerns better serve mid-market enterprises, perhaps even SMBs, as well?

Mellen: The combined entity should target the mid market and SMBs. LogRhythm has focused there, and though Exabeam previously targeted large enterprise, its user interface and ease of user makes it a good fit to bring down market.

LW: Anything else?

Mellen: Between this merger, Cisco’s acquisition of Splunk, and IBM selling QRadar assets to Palo Alto Networks, the SIEM market is undergoing a series of high-profile changes. Much of this is driven by pressure from the Tech Titans, XDR providers, and the realities of a hybrid, multi-cloud world. Expect more consolidation in the SIEM market in the next year.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


The post News analysis Q&A: Shake up of the SIEM, UEBA markets continues as LogRhythm-Exabeam merge first appeared on The Last Watchdog.

View Details

Torrance,Calif., May 22, 2024, CyberNewsWire — AI SPERA, a leader in Cyber Threat Intelligence (CTI) solutions, announced today that its proprietary search engine, Criminal IP, is now available on the AWS Marketplace.

This integration ensures efficient software procurement and deployment, aligning seamlessly with customers’ existing cloud architectures.

After meeting specific technical and security standards set by AWS, the SaaS-based Criminal IP search engine ensures reliability and seamless integration with AWS services. The AWS Marketplace, a significant platform primarily used in the US, provides Criminal IP with access to a vast global customer base, enhancing its visibility and credibility. This listing demonstrates the critical role of AWS Marketplace in the software’s adoption and success.

Criminal IP excels in threat detection, empowering cybersecurity with unparalleled intelligence.

Criminal IP is the industry’s leading IP address intelligence tool, leveraging AI and machine learning to provide unparalleled visibility into the risks associated with internet-connected devices. It offers comprehensive solutions for fraud detection,attack surface management, and threat hunting.

Additionally, Criminal IP offers seamless API integration, allowing effortless incorporation of threat intelligence data into existing services and security systems such as SOAR and SIEM. With a rich repository of cyber threat intelligence data, including risk classification, geographical insights, vulnerable asset graphs, and more, Criminal IP empowers organizations to stay ahead in the ever-evolving landscape of cybersecurity.

Seamless Integration and Payment Flexibility Between AWS Marketplace and Criminal IP

Criminal IP’s presence on the AWS Marketplace brings several conveniences for users. The interconnected tokens of AWS and Criminal IP seamlessly exchange information, allowing users to leverage both platforms’ strengths without encountering data silos or compatibility issues.

Additionally, customers enjoy consistent plans and subscription options on Criminal IP, regardless of whether transactions are initiated through Criminal IP or the AWS Marketplace. This uniformity extends to credit usage monitoring for specific features and APIs, accessible directly from the dashboard, promoting transparency and ease of management.a

Kang

“The most important aspect of entering the AWS Marketplace was to ensure easier compatibility between AWS Cloud and ‘Criminal IP’ threat intelligence. We paid a lot of attention to interoperability with AWS products and credit management systems,” stated Byungtak Kang, CEO of AI SPERA. “We will continue to pursue Marketplace registration to secure global customers and increase interoperability with various clouds in the future.”

Explore the detailed features of the newly listed Criminal IP on the AWS Marketplace, as well as Criminal IP ASM, an Automated Attack Surface Management SaaS solution that monitors all internet-connected assets and vulnerabilities.

About AI Spera: AI SPERA, a leader in Cyber Threat Intelligence (CTI) solutions, significantly expanded its reach with the launch of its flagship solution, Criminal IP, in 2023. Since then, the company has established technical and business collaborations with over 40 renowned global security firms, including VirusTotal, Cisco, Tenable, Sumo Logic, and Quad9.

Available in five languages (English, French, Arabic, Korean, and Japanese), the search engine ensures a powerful service for users worldwide.

In addition to the CTI search engine, the company also offers Criminal IP ASM, a SaaS-based Attack Surface Management Solution available on Azure Marketplace, and Criminal IP FDS, an AI-based Anomaly Detection Solution used for credential stuffing prevention and fraud detection.

Contact: Michael Sena, AI SPERA, support@aispera.com

The post News alert: AI SPERA integrates its ‘Criminal IP’ threat intelligence tool into AWS Marketplace first appeared on The Last Watchdog.

View Details

New York, NY, May 21, 2024, CyberNewsWire — Memcyco Inc., provider of digital trust technology designed to protect companies and their customers from digital impersonation fraud, released its inaugural 2024 State of Website Impersonation Scams report.

Notably, Memcyco’s research indicates that the majority of companies do not have adequate solutions to counter digital impersonation fraud, and that most only learn about attacks from their customers.

More than half of all respondents (53%) said their existing cybersecurity solutions do not effectively address website impersonation attacks, and 41% said their existing solutions only protect them and their customers “partially.” Just 6% of brands claimed to have a solution that effectively addresses these attacks despite 87% of companies recognizing website impersonation as a major issue and 69% admitting to having had these attacks carried out against their own website.

The creation of fake websites used for phishing-related attacks (which are a top cause of account takeover (ATO)) is a growing problem that has earned cybercriminals an astonishing $1 billion+ in 2023 alone, according to data from the U.S. Federal Trade Commission. That’s more than three times the amount reported stolen in 2020.

The report found that 72% of companies have a monitoring system in place to detect fake versions of their website, but still, 66% said that they primarily learn about digital impersonation attacks when they are flagged by customers.. More alarmingly, 37% of respondents learn about website impersonation attacks as a result of “brand shaming” by impacted customers on social media.

The inability to adequately protect against digital impersonation fraud raises a question about companies’ responsibility to reimburse their customers. 48% of survey respondents are already aware of upcoming regulations likely to enforce customer reimbursements, making effective protection against digital impersonation fraud a ‘must-have’ for avoiding revenue loss.

Mazin

“One of the most alarming takeaways from the report is that website impersonation scams are growing because attackers rely on companies having limited visibility into these kinds of attacks,” said Israel Mazin, Chairman and CEO of Memcyco. “This creates a glaring blindspot in cybersecurity — the inability of companies to protect their customers online.”

The State of Website Impersonation Scams report was conducted together with Global Surveyz Research, based on the responses of 200 full-time employees ranging from Director to C-level executives at organizations in the security, fraud, digital, and web industries, operating transactional websites with traffic of more than 10,000 monthly visits.

Memcyco’s solution suite addresses the rising tide of website impersonation scams by using real-time alerts to secure end-users on every website visit and provides organizations with unparalleled insights into the scope and impact of all attacks on their sites.

The full report can be found here.

About Memcyo: Memcyco offers a suite of AI-based, real-time digital risk protection solutions for combating website impersonation scams, protecting companies and their customers from the moment a fake site goes live until it is taken down. Memcyco’s groundbreaking external threat intelligence platform provides companies with complete visibility into the attack, attacker, and each individual victim, helping to prevent ATO fraud, ransomware, and data breaches before they occur. Memcyco’s “nano defender” technology detects, protects, and responds to attacks as they unfold, securing tens of millions of customer accounts and reducing the negative impact of attacks on workload, compliance, customer churn, and reputation.

About Global Surveyz: Global Surveyz is a global research company providing survey report-as-a-service that covers the whole process of creating an insightful and impactful B2B or B2C report for any target market. Global Surveyz was established in 2020 and is the brain-child of Ramel Levin.

Media contact: Sheena Kretzmer, sheena@memcyco.com

The post News alert: Memcyco report reveals only 6% of brands can stop digital impersonation fraud first appeared on The Last Watchdog.

View Details

There was a lot of buzz at RSAC 2024 about how GenAI and Large Language Models (LLM) are getting leveraged — by both attackers and defenders.

Related: Is your company moving too slow or too fast on GenAI?

One promising example of the latter comes from messaging security vendor IRONSCALES.

I had the chance to sit down with Eyal Benishti, IRONSCALES founder and CEO, to get a breakdown of how their new Generative Adversarial Network (GAN) technology utilizes a specialized LLM to reinforce anti-phishing mitigation services.

Benishti explained how GAN can very effectively mitigate Deep Faked messages, images, audio and video using a specially-tuned LLM to stay a step ahead of threat actors, even those who themselves are utilizing GenAI/LLM tools to enhance their Deep Fakes.

Benishti told me about a remarkable GAN-powered phishing simulation test that took place recently with highly-trained bank employees. GAN sent out personalized phishing ruses – and deceived the employees who were previously impervious to template-based phishing tests.

One huge lesson gleaned is that the vendors who are integrating GenAI/LLM technology into their security tools have a huge advantage over threat actors: superior intelligence.

“We have access to public and non-public information, while the bad guys only have access to public information that anyone can get,” Benishti observes. “So we can really create something that is much more powerful than what they can create.”

When it comes to leveraging GenAI/LLM, it’s all about the prompting. For a full drill down, please give the accompanying podcast a listen.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: IRONSCALES utilizes LLM, superior intel to stay a step ahead of Deep Fakes first appeared on The Last Watchdog.

View Details

The open-source Chromium project seeded by Google more than a decade ago has triggered something of a web browser renaissance.

Related: Browser attacks mount

Browsers based on Chromium include Google Chrome and Microsoft Edge, which dominate in corporate settings – as well as popular upstarts Brave, Opera and Vivaldi. Together these browsers have given rise to a vast ecosystem of extensions – one that happens to align perfectly with a highly distributed work force and global supply chain.

Naturally, the flip side of cool, new browser capabilities is a yet another expansion of the network attack surface. And this, in turn, has resulted in a surge of innovation in web browser security.

At RSAC 2024, I visited with Vivek Ramachandran, founder of SquareX, a brand new start-up that’s in the thick of these developments. Google and Microsoft, he told me, are myopically focused on dealing with fresh coding vulnerabilities spinning out of Chrome and Edge and doing very little to stem live attacks.

Meanwhile, he argues, cloud-based security tools, namely secure web gateways (SWG) and security services edge (SSE) systems fall well short because of the wide open way extensions work in Chromium browsers.

SquareX uses a browser extension to granularly monitor user behavior and to detect and mitigate threats in real-time. Ramachandran described how a few months ago, SquareX rolled out a freemium version which attracted some 200,000 users. For a drill down on what they’re up to now, please give the accompanying podcast a listen.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

The post RSAC Fireside Chat: SquareX introduces security-infused browser extension to stop threats in real time first appeared on The Last Watchdog.

View Details

Meeting the demands of the modern-day SMB is one of the challenges facing many business leaders and IT operators today. Traditional, office-based infrastructure was fine up until the point where greater capacity was needed than those servers could deliver, vendor support became an issue, or the needs of a hybrid workforce weren’t being met.

Related: SMB brand spoofing

In the highly competitive SMB space, maintaining and investing in a robust and efficient IT infrastructure can be one of the ways to stay ahead of competitors.

Thankfully, with the advent of cloud offerings, a new scalable model has entered the landscape; whether it be 20 or 20,000 users, the cloud will fit all and with it comes a much simpler, per user cost model. This facility to integrate modern computing environments in the day-to-day workplace, means businesses can now stop rushing to catch up and with this comes the invaluable peace of mind that these operations will scale up or down as required. Added to which, the potential cost savings and added value will better serve each business and help to future-proof the organisation, even when on a tight budget. Cloud service solutions are almost infinitely flexible, rather than traditional on-premises options and won’t require in-house maintenance.

Cloud-sourced sustainability

Sibley

When it comes to environmental impact and carbon footprint, data centres are often thought to be a threat, contributing to climate change, but in reality, cloud is a great option. The scalability of cloud infrastructure and the economies of scale they leverage facilitate not just cost but carbon savings too. Rather than a traditional model where a server runs in-house at 20% capacity, using power 24/7/365 and pumping out heat, cloud data centres are specifically designed to run and cater for multiple users more efficiently, utilising white space cooling, for example, to optimise energy consumption.

When it comes to the bigger players like Microsoft and Amazon, they are investing heavily in sustainable, on-site energy generation to power their data centres; even planning to feedback excess power into the National Grid. Simply put, it’s more energy efficient for individual businesses to use a cloud offering than to run their own servers – the carbon footprint for each business using a cloud solution becomes much smaller.

Simplified scaling

With many security solutions now being cloud based too, security doesn’t need to be compromised and can be managed remotely via SOC teams either in-house or via the security provider (where the resources are greater and have far more specialist expertise).

Ultimately, a cloud services solution, encompassing servers, storage, security and more, will best service SMBs; it’s scalable, provides economies of scale and relieves in-house IT teams from many mundane yet critical tasks, allowing them to focus on more profitable activities.

About the essayist: Brian Sibley, Solutions Architect, Espria. A Solutions Architect with over 40 years industry experience, over 25 years of which are based on Microsoft and associated third party technologies, reinforced by relevant certifications and training

The post GUEST ESSAY: Turning to cloud services can help SMBs scale to meet growth needs first appeared on The Last Watchdog.

View Details

Hardware-based cybersecurity solutions are needed to help defend company networks in a tumultuous operating environment.

Related: World’s largest bank hit by ransomware attack

While software solutions dominated RSA Conference 2024 and are essential for multi-layered defense of an expanding network attack surface, hardware security solutions can serve as a last line of defense against unauthorized access to sensitive data and tampering with systems.

I sat down with Flexxon co-founder and CEO Camellia Chan to learn more about the soft launch of Flexxon’s X-PHY® Server Defender module. This follows the success of their X-PHY® SSD endpoint security solution.

This security-tuned SSD provides real-time protection against malware, viruses, and physical tampering.

Chan highlighted that early adopters of the X-PHY® SSD are from sectors that prioritize robust security measures, such as government, finance, and healthcare.

One notable use case Chan mentioned involves industrial PCs and healthcare kiosks. These endpoint devices benefit from the X-PHY® SSD’s autonomous protection capabilities, ensuring critical data is safeguarded without the need for regular updates done by humans. This is particularly valuable for legacy systems that require consistent and reliable security at the core.

Meanwhile, Flexxon’s new Server Defender module extends the company’s advanced security technology to backend servers. Chan explained how this standalone module offers full-stack monitoring and defense across all seven layers of the OSI model, while also enabling instant restoration through its patented Matrix Shield technology.

This multi-layered validation is crucial for detecting zero-day threats, Chan told me. For a drill down, please give the accompanying podcast a listen.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

London, United Kingdom, May 13, 2024, CyberNewsWire — Logicalis, the global technology service provider delivering next-generation digital managed services, has today announced the launch of Intelligent Security, a blueprint approach to its global security portfolio designed to deliver proactive advanced security for customers worldwide.

Intelligent Security has been designed by Logicalis’ worldwide team of security specialists to give customers the most comprehensive observability and protection available. It is based on tracking and analysing cyber threats and knowledge of the latest prevention methods deployed across its customer base.

Logicalis’ tenth annual CIO report surveyed 1,000 CIOs globally and found that of the 83% of CIOs who experienced cyber-attacks in the last 12 months, only 43% feel prepared for another breach. Designed to help CIOs manage these pressures, Intelligent Security will leverage Logicalis’s security capabilities as well as its relationships with global partners such as Cisco and Microsoft, where it has the highest levels of security accreditations.

Alcock

Logicalis CTO Toby Alock said: “Many organisations focus on one area of the security fabric; we recognise in today’s cyber security landscape there are no silos; organisations must look across the entire footprint, from secure connectivity, securing the cloud, securing the hybrid worker and weaving secure operations across the entire organisation”.

The Intelligent Security global portfolio delivers a concise and comprehensive proposition for customers, including:

•Advisory: Providing customers with a range of advisory services dedicated to helping them understand their security needs and identify the right solutions for their business.

•Secure workplace: Securing worker communications and devices as remote working continues to impact the

•Secure connectivity: Enforcing zero trust security from edge-to-edge, ensuring networks are robust enough to enable safe IoT, 5G and edge computing.

•Secure hybrid cloud: Safeguarding cloud environments to ensure data, applications, and IT resources are safe.

•Secure Operations: Providing 24/7/365 best practice proactive threat detection and incident response, across three global security regions, using AI and automation to identify and triage.

In addition to the Intelligent Security global portfolio, the company is announcing several key investments in cyber skills and capabilities to bolster its position as a global leader in security services.

•Expanding the Managed Security (SOC) team in Portugal, which currently serves customers across EMEA, including the UK, Ireland and Germany

•Partnering with Cisco to develop a Cyber Academy and a pipeline of qualified cybersecurity graduates into the EMEA Security team

•Partnering with local universities in Portugal to develop an Intern program, which helps develop cybersecurity skills to serve the EMEA region and beyond.

Logicalis continues to prove its robust security offer by achieving Microsoft-verified Managed Extended Detection and Response (MXDR) Partner Status, launching Cisco Powered Intelligent Connectivity, built on zero-trust security, and being one of only six partners globally working with Cisco to develop an XDR proposition and enhance its Cisco security capabilities.

Intelligent Security will be underpinned by Logicalis’ Digital Fabric Platform, providing CIOs with deeper-level insights and recommendations to enhance the performance of their entire digital ecosystem.

Toby Alock concludes, “We are at a pivotal point as security threats grow in scale and sophistication. CIOs and IT leaders are rethinking security in the era of AI and considering whether they have the in-house skills necessary to operate safely. Logicalis has seen a 300% surge in demand globally for Managed Security services in the past 12 months. Our customers are looking for a holistic, proactive approach to navigating security; we believe our simplified portfolio, our partnerships, and our investments in cyber talent for the next generation will deliver customers what they need: AI ready Managed Security with governance and SOC Protection wherever they are in the world”.

For more information please contact: Logicalis Team at Another Word, Email: logicalis@anotherword.com. Tel: 020 3176 0014

About Logicalis: We are Architects of Change™. We help organisations succeed in a digital-first world. At Logicalis, we harness our collective technology expertise to help our clients build a blueprint for success, so they can deliver sustainable outcomes that matter. Our lifecycle services across cloud, connectivity, collaboration and security are designed to help optimise operations, reduce risk and empower employees.

As a global technology service provider, we deliver next-generation digital managed services, to provide our clients with real-time visibility and actionable insights across the performance of their digital ecosystem including; availability, user experience, security, economic performance and sustainability.

Our 7000+ ‘Architects of Change’ are based in 30 territories around the globe, helping our 10,000+ clients across a range of industry sectors create sustainable outcomes through technology.

Logicalis has annualised revenues of $1.7 billion, from operations in Europe, North America, Latin America, Asia Pacific, and Africa.

It is a division of Datatec Limited, listed on the Johannesburg Stock Exchange, with revenues of over $5.1 billion.

Media contact: Katie Fraser, ANOTHER WORD, katie.fraser@anotherword.com, 07908229152

View Details

Torrance, Calif., May 13, 2024, CyberNewsWire — Criminal IP, a renowned Cyber Threat Intelligence (CTI) search engine developed by AI SPERA, has recently signed a technology partnership to exchange threat intelligence data based on domains and potentially on the IP address to protect users by blocking threats to end users.

Criminal IP underwent rigorous data evaluation to integrate with Quad9’s threat-blocking service, demonstrating high data uniqueness and accuracy. Particularly, test results revealed a remarkable outcome: 99.1% of malicious domains identified by Criminal IP’s threat intelligence were found to be non-duplicative with other TI data.

Through this integration, Quad9 leverages the most up-to-date threat intelligence lists, incorporating data from Criminal IP’s database of malicious domains to block harmful hostnames. This process not only safeguards computers, mobile devices, and IoT systems from a diverse array of threats like malware, phishing, spyware, and botnets, ensuring privacy, but also optimizes performance.

Enhanced threat blocking

Quad9 is a free anycast DNS platform delivering robust security protections and privacy guarantees that comply with rigorous Swiss Data Protection and GDPR rules. Quad9 is operated as a non-profit by the Quad9 Foundation in Switzerland for the purpose of improving the privacy and cybersecurity of Internet users.

Operating on a high-performance global network, Quad9 partners with Criminal IP, which offers extensive cyber threat information, including malicious IPs, domains, and CVEs, derived from sophisticated IP and domain scoring algorithms and big data analysis on a worldwide scale, enhances this mission.

The specially designed Criminal IP Malicious Domains Retrieval API is used to send the Domain Data Feed identified as malicious to Quad9 for integration. This feed is then utilized alongside other threat intelligence (TI) data sources integrated into the Quad9 platform, such as IBM, OpenPhish, F-Secure, RiskIQ, and Domain Tools, to create a comprehensive blocklist for user protection.

Specialized threat intelligence

In addition to these comprehensive threat-blocking results on Quad9, for those seeking more information about each component of domains, users can use Domain Search of Criminal IP. The vulnerability scanner tool meticulously analyzes a wide array of domain details including screenshots, WHOIS data, utilized technologies, page redirections, and certificates. It also identifies potentially malicious content and replicated phishing domains, providing an overall domain score and a Domain Generation Algorithm (DGA) score. This global threat intelligence is updated daily and can be accessed through flexible API integration enabling seamless incorporation of the data into existing security systems, such as SOAR and SIEM.

“Our partnership with Quad9 is a recognition of the accuracy of Criminal IP’s data,” stated Byungtak Kang, CEO of AI SPERA. “It is expected that our collaboration will contribute to the protection of Quad9’s end-users, who have a global reach, while simultaneously enhancing the quality of Criminal IP’s data.”

End users interested in utilizing the integrated threat-blocking security service of Quad9, which is linked with Criminal IP threat intelligence, can automatically activate the service simply by using the Quad9 DNS server (9.9.9.9).

About AI SPERA: AI SPERA launched its global cybersecurity service, Criminal IP, on April 17, 2023, following a successful year-long beta phase. The company has established technical and business partnerships with acclaimed global security firms and educational institutions, including VirusTotal, Cisco, Tenable, and Sumo Logic. Criminal IP offers personalized plan options, also suitable for company use. Users can check their own credit usage for specific features (Web, Vulnerability Scanner, Tags, etc.) and API on the dashboard, and upgrade the plan anytime according to their needs. Criminal IP is available in five languages (English, French, Arabic, Korean, and Japanese), providing a powerful and accurate CTI search engine for users worldwide. AI SPERA has been delivering cybersecurity solutions worldwide through a range of products, including Criminal IP CTI Search Engine, Criminal IP ASM, and Criminal IP FDS.

Media contact: Michael Sena, AI SPERA, support@aispera.com

View Details

KINGSTON, Wash. — U.S. Secretary of State Antony Blinken opened RSA Conference 2024 last week issuing a clarion call for the cybersecurity community to defend national security, nurture economic prosperity and reinforce democratic values.

Related: The power of everyman conversing with AI

Blinken

That’s a tall order. My big takeaway from RSAC 2024 is this: the advanced technology and best practices know-how needed to accomplish the high ideals Secretary Blinken laid out are readily at hand.

I was among some 40,000 conference attendees who trekked to San Francisco’s Moscone Center to get a close look at a dazzling array of cybersecurity solutions representing the latest iterations of the hundreds of billions of dollars companies expended on cybersecurity technology over the past 20 years.

And now, over the next five years, hundreds of billions more will be poured into shedding the last vestiges of on-premises, reactive defenses and completing the journey to edge-focused, tightly integrated and highly adaptable cyber defenses directed at the cloud edge.

This paradigm shift is both daunting and essential; it must fully play out in order to adequately protect data and systemsin a post Covid 19, early GenAI and imminent quantum computing operating environment.

Simultaneous paradigm shifts

In his keynote address, Secretary Blinken alluded to several tectonic shifts happening simultaneously. Post Covid 19, work forces and supply chains have become highly distributed. This has resulted in the intensifying of companies’ reliance on cloud services delivered at via smartphones, web browsers and IoT devices. Innovation has blossomed, though, conversely, the network attack surface has expanded exponentially.

Add to this the wild card of GenAI/LLM. The democratization of machine learning and artificial intelligence – putting the ability to extract value from data into the hands of ordinary humans – has just started to revolutionize user experiences. And, of course, this has created new tiers of criminal hacking opportunities.

“Today’s revolutions in technology are at the heart of our competition with geopolitical rivals,” Blinken said. “They pose a real test to our security, and they also represent an engine of historic possibility for our economies, for our democracies, for our people, for our planet. Put another way security, stability, prosperity — they are no longer solely analog matters.”

Singh

Flying home from the conference, I reflected on an observation made by Cota Capital general partner Aditya Singh who said this: “Rules-based security is over, context-based security is taking over.” Singh said this as he moderated a panel discussion featuring the founders of Simbian, Seraphic Security and Amplifier Security, three promising start-ups that are all about contextual defense.

See, categorize, control

It struck me that each of the security vendors I spoke with were caught up in the trend of prioritizing contextual security, as well. Each sought to dial-in the optimum dose of protection without sacrificing an iota of innovation. In a hyper-interconnected operating environment this can only be achieved by accounting for context.

I then wrote down two column headings – contextual data protection and contextual security services — and proceeded to place each of the security vendors I spoke with in one or the other column.

Adduri

If data is the new gold, then seeing, categorizing and controlling access to every speck of gold makes perfect sense. I had a wide-ranging discussion with Pranava Adduri, co-founder and CEO of Bedrock Security, about why quite the opposite has happened: many organizations have been amassing information indiscriminately, simply because they can. Bedrock is applying graph database know-how to helping companies get a handle on all of their data and make strategic decisions about governance and security policies.

At the end of the day, I’d classify all the innovation occurring in application security (AppSec) as being about this sort of contextual data management. This includes innovators in the DevSecOps tools space, like Qwiet.ai and NightVision and I’d also put into this group leading API security innovators, like Traceable, Data Thereom and Salt Security.

I spoke, as well, with Isaac Roybal, CMO of Seclore, supplier of an advanced of iteration of Enterprise Digital Rights Management (EDRM), which focuses on granular control of data access.

Chan

I’d even place hardware security innovators into the category of contextual data security tools. I had a great conversation with Camellia Chan, co-founder and CEO of Flexxon, which introduced its security-infused X-PHY server module at the conference; X-PHY protects data at the memory level, the last line of data defense.

Big security services role

The second grouping of vendors I met with at RSAC 2024 were more about a security services component. AT&T Cybersecurity made a splash announcing a recasting of its MSSP business under the name LevelBlue in partnership with WillJam Ventures. I also spoke with Open Systems and Ontinue, both offering their iterations of a managed security service tuned for the current operating environment.

Sinha

I visited with DigiCert CEO Amit Sinha and we spoke about DigiCert’s expanding portfolio of services which revolves around helping companies contextually manage their widening sprawl of PKI keys and digital certificates.

Benishti

My conversation with Ironscales co-founder and CEO Eyal Benishti followed a similar arch as he described how his company is delving into leveraging GenAI/LLM to help detect and deter email phishing attacks much more granularly. Meanwhile, Ahmed Abdelhalim, senior director of security solutions, A10 Networks, explained the latest advances in DDoS defenses.

Wilson

I also sat down with senior execs from Lacework to find out about their cloud-security platform and with Exabeam, supplier of a security operations platform. Be sure to give a listen to LW’s RSAC Fireside Chat podcast with Exabeam CPO Steve Wilson to hear the fascinating origination tale of the OWASP Top Ten for Large Language Model Applications. And one of the coolest conversations I had was with Rajiv Pimplaskar, CEO at Dispersive.io, about adapting WWII fuzzing tactics to mitigate deep fakes.

I also met with vendors in the vanguard of an all-new type of security service – enterprise browsers; advanced browser security features are now available to be imbedded in company-issued browsers that use the open-source Chromium browser operating system, i.e. Google Chrome and Microsoft Edge. Innovators like Island.io, SquareX and Seraphic Security are taking different angles to solutions in this fast emerging space.

Fortuna

And I really got into the weeds about the browser arising as a focal point of edge-defenses with Pedro Fortuna, co-founder and CTO of Jscrambler, one of the pioneers of JavaScript security; going forward JavaScript security looks to be a key component of evolving browser security breakthroughs.

Finally, I spoke to four niche security service providers: Hyas, which combines advanced threat intelligence and DNS security services; Anetac, a start-up offering technology to help companies more effectively lock down their service accounts (the accounts used behind the scenes that grant access to things like customer data bases, cloud storage lockers and shopping carts;) Simbian, which supplies contextual workflows for security tasks ranging from complex investigations to compliance measures; Amplified Security, which helps human employees take “self-healing” security actions; and VISO Trust, which is adding richer context to supply chain audits.

Kluzak

Every conversation I had at RSAC 2024 was fascinating and instructive; each vendor was immersed in developing advanced protections companies now need to stay viable in an environment of rapid change. Black and white rules are out. Flexible, nuanced security policies that can be automatically implemented, at scale, are in. This is even more so true as the GenAI/LLM revolution plays out; I had an awesome brain storming session with David Kluzak, CRO, of LogRhythm, about the scenarios likely to play out as companies scramble to internally leverage LLM — to drive up revenue — in the weeks and months ahead. We chatted over ice cream sundaes at the Thoma Bravo mixer at the SF MOMA.

Horn

You’ll hear more details about the vendors and concepts I’ve mentioned above as our popular Last Watchdog RSAC Fireside Chat podcast series, which commenced last week, continues. This includes an interview I did with a bright young cybersecurity systems analyst Madison Horn, who’s running for a seat in the U.S. House of Representatives from Oklahoma. If elected, Horn would be the first member of Congress with a cybersecurity background. A few new episodes will go live each week, now through mid-June.

The pace of change is breathtaking. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


View Details

Philadelphia, Pa., May 8, 2024, CyberNewsWire Security Risk Advisors (SRA) announces the launch of their OT/XIoT Detection Selection Workshop, a complimentary offering designed to assist organizations in selecting the most suitable operational technology (OT) and Extended Internet of Things (XIoT) security tools for their unique environments.

Led by seasoned OT/XIoT security consultants, the workshop provides participants with an invaluable opportunity to gain insights into both best-in-class and novel solutions, to identify those closest aligned to their specific needs.

In today’s increasingly interconnected digital landscape, the importance of choosing the right OT/XIoT security tools cannot be overstated. These tools serve as the first line of risk reduction and defense against cyber threats targeting critical industrial processes and infrastructure.

Making informed decisions, whether adding a new solution or replacing an incumbent, significantly impacts an organization’s ability to mitigate threats and protect its assets. During the half-day consultation, participants will delve deep into their OT/XIoT security environments, examining current tools and analyzing their infrastructure.

The free workshop will result in personalized recommendations of the best-fit solutions from industry vendors.

Rivera

“We recognize the importance of selecting the right security tools for cyber-physical environments,” says Jason Rivera, Director of OT/XIoT Security at SRA. “Our workshop empowers organizations to make informed decisions, giving confidence that their selection is fit for purpose.”

Submit your application here.

About Security Risk Advisors. Security Risk Advisors offers Purple Teams, Cloud Security, Penetration Testing, OT Security and 24x7x365 Cybersecurity Operations. Based in Philadelphia, SRA operates across the USA, Ireland and Australia. For more information, visit SRA’s website at https://sra.io.

Media contact: Douglas Webster, Marketing Manager, news@sra.io 215-867-9051

View Details

SAN FRANCISCO, May 7, 2024, CyberNewsWire – Hunters, the pioneer in modern SOC platforms, today announced its full adoption of the Open Cybersecurity Schema Framework (OCSF), coupled with the launch of groundbreaking OCSF-native Search capability.

This strategic advancement underscores Hunters’ commitment to standardizing and enhancing cybersecurity operations through open, integrated data sharing frameworks.

Uri May, CEO of Hunters, explained the strategic significance of this move, stating, “Adopting OCSF as our primary data model represents a transformative step in our journey to elevate cybersecurity operations. Alongside this, our new advanced OCSF-native search functionality is set to transform how security data is searched and analyzed, offering unprecedented efficiency and precision.”

Democratizing Sec Ops

The adoption of OCSF provides a unified, standardized language across cybersecurity tools and platforms, simplifying data integration and analysis workflows. The adoption fosters frictionless interoperability and enables enhanced collaboration among cybersecurity professionals, promoting flexibility and innovation by eliminating constraints imposed by proprietary data formats.

“Adopting OCSF will not only enhance our AI-driven security solutions, but also enable seamless data integration across vast and diverse datasets, dramatically improving the speed and accuracy of threat detection and response,” added May.

Some of the benefits of adopting OCSF include:

•Streamlined Operations and Enhanced Collaboration – practitioners use common security language, promoting efficient sharing of insights and best practices, bolstering collective defense strategies.

•Breaking Vendor Lock-in and Data Silos – Organizations are not constrained by proprietary data formats from specific vendors.

•Revolutionizing Threat Hunting and Investigation – By shifting from logs to context-aware events and objects, OCSF enables multi-stage attack analysis and context-rich threat hunting.

•Accelerating AI and Gen-AI in Security – Standardized data schema accelerates the development of AI-driven security solutions.

New era in cybersecurity analytics

Hunters is thrilled to launch their revolutionary OCSF-native search functionality, designed specifically for SOC analysts and threat hunters. This innovative technology addresses the complexities of “query engineering” by leveraging a universal data schema—OCSF—to streamline the search process across diverse data formats and environments. The new search capabilities not only reduces the frustration and errors associated with traditional query syntax but also enhances both general and specialized investigation capabilities, transforming how security teams interact with data and significantly accelerating their operations.

OCSF-Native Search is Revolutionizing Search in the following ways:

•Event and Object Based Searching: A New Search Paradigm – Hunters SOC platform introduces event and object-based searching, eliminating the complexities of source-specific log formats, by enabling analysts to search cybersecurity events and objects without the need for field normalization or navigating diverse log formats.

•Democratizing Data Analysis: Equipping Analysts of All Levels for Success – OCSF-native search simplifies the search experience, eliminating the need for SQL proficiency or specialized knowledge in tools like Kibana or KQL. With an intuitive interface tailored to the OCSF model, analysts of all experience levels can quickly become proficient, bypassing traditional complexities and lengthy training sessions.

•Entity Investigation Curated Workflows: Investigations with a Single Click – With this new capability analysts can pivot directly from Hunters alerts to Search with a single click, automatically populating and executing queries for deep context. This eliminates the need for manual query building, facilitating a seamless investigative workflow that allows analysts to efficiently explore and analyze security incidents.

•Timeline Experience: Enhanced Chronological Insight for Security Analysis – A new timeline-based approach to search enables analysts to explore the chronological progression of security events. This feature provides insights into patterns, anomalies, and potential threats, enhancing the investigative workflow. Analysts can identify correlations, track threat evolution, and streamline investigations efficiently.

“Our new search functionality is a game-changer for both experienced and novice security practitioners,” says Yuval Itzchakov, CTO at Hunters. “It elevates SOC operations by providing Tier 1 analysts with the clarity needed for higher-level analysis and democratizes security insights, making advanced investigations accessible to more team members.”

Contributing to the community

In conjunction with this new product release, Hunters is also proud to contribute to the cybersecurity community by sharing one hundred mappings of security logs to the OCSF schema. This contribution is part of their commitment to fostering an open and collaborative environment where knowledge sharing accelerates innovation and strengthens security postures across the industry.

The full adoption of OCSF and the launch of our OCSF-native search functionality mark significant milestones in Hunters’ ongoing mission to innovate and automate cybersecurity analytics and operations. By embracing open standards and providing powerful, intuitive search capabilities, they are not only advancing our platform but also contributing to a more interconnected, efficient, and effective cybersecurity ecosystem.

To learn more, users can visit us at RSAC Booth #4317, Moscone North, or contact us on www.hunters.security

Media contact: Ada Filipek Hunters ada.filipek@hunters.ai

View Details

SAN FRANCISCO – The already simmering MSSP global market just got hotter.

Related: The transformative power of GenAI/LLM

This week at RSA Conference 2024, AT&T announced the launch of LevelBlue – a top-tier managed security services business formed by an alliance with AT&T and WillJam Ventures.

I had the chance to sit down earlier with Theresa Lanowitz, Chief Evangelist of AT&T Cybersecurity /Agent at LevelBlue, to discuss this alliance. “Our job at Level Blue is to manage and mitigate these risks while supporting our clients’ growth and innovation while acting as a strategic extension of your team,” Lanowitz told me

For a full drill down, please give the accompanying podcast a listen.

LevelBlue today also released findings of the 2024Futures Report: Beyond the Cyber Resilience – first-of-its-kind thought leadership research based on a global survey of 1,050 IT and security professionals – examining barriers to cyber resilience, barriers to cybersecurity resilience, the threat landscape, and business agility.

Notably, the research suggests that while companies do understand that new computing innovation increases risk dramatically, organizations are willing to accept the risk because of the benefits the innovation brings.

AT&T Cybersecurity has long catered to large and mid-market enterprises. It’s 2018 acquisition of AlienVault reinforced its portfolio of endpoint detection and response, security operations center as a service (SOCaaS) and compliance management solutions.

WillJam Ventures is a Chicago-based private equity firm that specializes in cybersecurity investments. Founded in 2002 by Bob McCullen, its portfolio includes Viking Cloud, a supplier of PCI data security compliance solutions, and GoSecure, recognized for its Managed Extended Detection and Response (MXDR) services.

Clearly the top-tier MSSPs — Secureworks, IBM, Cisco, NTT, Verizon, Symantec, Trustwave, Infosys, to name just a few — are shifting to models that alleviate mounting compliance pressures and help companies mitigate cyber risk as the pace of change accelerates

Now comes LevelBlue adding to this mix. I’ll keep watch and keep reporting..

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

SAN FRANCISCO — Cloud security is stirring buzz as RSA Conference 2024 ramps up at Moscone Convention Center here.

Related: The fallacy of ‘security-as-a-cost-center’

Companies are clambering to mitigate unprecedented exposures spinning out of their increasing reliance on cloud hosted resources. The unfolding disruption of Generative AI — and rising compliance requirements — add to the mix.

Thus, cloud-native security tools have risen to the fore. I’ve reported in years past on the introduction of cloud access security brokers (CASBs), cloud workload protection platforms (CWPP), and cloud security posture management (CSPM) tools.

In 2024, it’s all about integrating cloud-native security solutions and improving orchestration.

I had the chance to discuss this with Kevin Kiley, chief revenue officer of Lacework, a Mountain View, Calif.-based supplier of advanced cloud security tools solving some of the most complex cybersecurity challenges in the cloud. For a full drill down, please give the accompanying podcast a listen.

Lacework is a cloud security platform that saves teams time and resources by ingesting massive amounts of threat and risk data to monitor for anomalous activity. It’s a Cloud Native Application Protection Platform (CNAPP) that offers code to cloud coverage on a single platform, including: cloud workload protection, threat detection, code security, compliance monitoring, providing visibility into customer environments ranging from pre-deployed code to containers to identity and entitlements to runtime apps, he told me.

For instance, Lacework’s CSPM capabilities enable organizations to continually assess their cloud security posture and identify any vulnerabilities; remediation is automated.

This includes automated checks to assure compliance with PCI DSS, HIPAA, GDPR and CIS benchmarks. Lacework’s platform also integrates with cloud platforms, DevOps tools and legacy security systems.

The shift from reactive, on-premises defense to proactive edge-oriented security is picking up steam. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

SAN FRANCISCO — On the eve of what promises to be a news-packed RSA Conference 2024, opening here on Monday, Microsoft is putting its money where its mouth is.

Related: Shedding light on LLM vulnerabilities

More precisely the software titan is putting money within reach of its senior executives’ mouths.

Screenshot

In a huge development, Microsoft announced today that it is revising its security practices, organizational structure, and, most importantly, its executive compensation in an attempt to shore up major security issues with its flagship product, not to mention quell rising pressure from regulators and customers.

A shout out to my friend Todd Bishop, co-founder of GeekWire, for staying on top of this development. His breaking news coverage is as thorough as you’d expect as a Microsoft beat writer with institutional knowledge going back a couple of decades.

Org overhaul

As Todd reports, not only is Microsoft basing a portion of senior executive compensation on progress toward security goals, it also will install deputy chief information security officers (CISOs) in each product group,and bring together teams from its major platforms and product teams in “engineering waves” to overhaul security.

This instantly brought to mind something eerily similar that happened 22 years ago – something both Todd and I wrote about at the time. On January 15, 2002, Bill Gates issued his famous “Trustworthy Computing” (TC) company-wide memo, slamming the brakes on Windows Server 2003 development and temporarily redirecting his top engineers to emphasize security as a top priority.

Gates

This “security stand down” allowed Microsoft to conduct a comprehensive review and overhaul of their software design practices, as part of a broad effort to integrate security deeply into the software development process at Microsoft. Given its stature as an 800 lb gorilla, Microsoft certainly influenced cybersecurity as a whole, arguably setting a course for application security principles and practices that were to evolve in the wake of TC.

Pressure redux

But now, once again, Microsoft is feeling enough pressure from its enterprise customers to recalibrate its approach to security. Just as Gates’ memo became a charter to infuse security, privacy, and reliability across all Windows products, Satya Nadella’s Secure Future Initiative (SFI) is aimed at deepening this ethos in an environment now dominated by sophisticated cyber threats, cloud-based data and pervasive AI technologies.

The common denominator is trust—critical then and now. Initially, TC was about setting a security baseline within the fabric of software development during the internet’s formative years. SFI expands this vision, emphasizing intrinsic security in the design, deployment, and operation of Microsoft’s vast array of products and services, focusing notably on the challenges posed by AI and cloud vulnerabilities.

Under Gates, TC catalyzed a transformation within Microsoft that rippled out across the tech industry, prompting a heightened focus on developing software that was secure by design.

TC’s legacy

An argument certainly can be made that TC foreshadowed “shift left” software security development practices and, ultimately, DevSecOps. The core principle is that every phase of software development should be infused with some aspect of security.

Nadella

I’d argue that TC laid the groundwork for continuous security integration, a core component of DevSecOps. This approach ensures that security considerations are not an afterthought but are embedded throughout the development lifecycle. Extending from this foundation, SFI seems well-positioned to push these boundaries further, integrating AI to proactively manage security threats and embedding robust security measures as default settings in new products.

While TC reshaped traditional software security, SFI has a chance to help not just Microsoft customers, but the tech sector as a whole. The massive task at hand is to reconcile privacy and security concerns when it comes to securing complex AI algorithms and sprawling cloud networks.

Funny how even as the pace of change accelerates, the core privacy and security concerns remain the same. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


View Details

At the start, Distributed Denial of Service (DDoS) attacks were often motivated by bragging rights or mischief.

Related: The role of ‘dynamic baselining’

DDoS attack methodology and defensive measures have advanced steadily since then. Today, DDoS campaigns are launched by political activists, state-sponsored operatives and even by business rivals.

Targets can be high-profile web services and critical infrastructure, not just utilities like power and water, but also the telco companies that supply the Internet backbone. High-profile DDoS attacks have spun out of Russia’s invasion of Ukraine, the Israel-Hamas War and unrest in France.

As RSA Conference 2024 gets underway next week at San Francisco’s Moscone Center, dealing with the privacy and security fall out of those back-to-back disruptive developments will command a lot attention.

Ahead of conference, I had the chance to visit with Ahmed Abdelhalim, senior director of security solutions, A10 Networks. We discussed how defensive tools and strategies have advanced, as well, and why it’s more crucial than ever for organizations to make proactive and continuous use of them.

For a full drill down, please give the accompanying podcast a listen.

Notable strides have been made in enhancing detection technologies. A10, for instance, has helped pioneer the development of “dynamic baselining,” a means to adapt detection thresholds in real-time, learning from traffic patterns to differentiate between normal fluctuations and potential threats.

“The old static models just don’t cut it anymore,” Abdelhalim observes. “We need systems that learn and adapt as quickly as the attackers do.”

No one expects the frequency of DDoS attacks to decline; companies need to stay vigilant. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Businesses today need protection from increasingly frequent and sophisticated DDoS attacks. Service providers, data center operators, and enterprises delivering critical infrastructure all face risks from attacks.

Related: The care and feeding of DDoS defenses

But to protect their networks, they’ll need to enable accurate attack detection while keeping operations manageable and efficient.

Traditional static baselining methods fall short on both of these counts. To begin with, they rely on resource-intensive manual processes to define an organization’s “normal” traffic patterns, imposing a burden on both the protected organization and their own security personnel. The uncertainty and approximation inherent in this approach leads to tradeoffs on exactly where to establish the baseline. Set it too high and you’ll miss smaller attacks. Set it too low and you’ll deal with constant false positives.

Dynamic baselining makes it possible to offer more accurate and efficient DDoS protection and protection-as-a-service. By allowing the system to learn its own baseline traffic patterns, set its own thresholds, and adapt automatically as traffic changes, service providers and large enterprises can simplify operations while ensuring more accurate attack detection.

Limits of static baselining

Under ordinary circumstances, an increase in network traffic can seem like good news. A DDoS attack, on the other hand, is distinctly bad news. By flooding a victim’s network with bogus traffic, an attacker can slow performance or even knock its services offline entirely.

Organizations can help mitigate the threat of a DDoS attack, but first, they need to be able to recognize the difference between normal or “peacetime” activity and abnormal, malicious traffic. This can be tricky if thresholds are simply set to detect large-scale DDoS attacks while missing smaller ones, presenting this as an acceptable risk.

A security team, seeking a more accurate level of detection, may query the protected organization or application owners on what their normal traffic levels are in order to establish tailored baselines. This seems reasonable, except that many companies don’t have this kind of detail readily available. It also imposes an additional operational burden.

Another approach employed by security teams is to assume the burden of monitoring the traffic for a period of weeks and come up with a proposed baseline. This is likely more effective in terms of accuracy, but it’s far from scalable as a service model for DDoS protection-as-a-service.

Choose Your Poison

When organizations can’t tailor a DDoS detection threshold to specific needs or specific end subscribers, they have two options. One is to set a level that’s much higher than what normal traffic would realistically reach. You’ll catch large-scale attacks, but you may be exposed to any number of smaller attacks, degrading performance for their business and the end users.

Or you can choose to set the threshold lower in order to catch more attacks. Unfortunately, you’ll also get more false positives. In that event, traffic will be diverted to a mitigation device, subjecting end users to an unnecessary increase in latency and degradation of the user experience. This is particularly noticeable by users and the application owners when the mitigation device or facility is in a geographic location different from that of the servers.

Accurate, efficient protection

Static baselining imposes too much of an operational burden on organizations — and even then, the resulting attack detection is too inaccurate.

Abdelhalim

Dynamic baselining alleviates that operational workload while enabling a better understanding of normal and suspicious network activity. The system automatically learns the peacetime baseline for customers, sets thresholds that reflect the observed patterns, and then adapts those thresholds over time as traffic changes. Able to differentiate between the types of increases associated with the dynamic business environment or end-user behavior on one hand, and malicious surges originating from botnets on the other hand, the system can alert accurately on genuine attacks of all sizes while avoiding the disruptions of false positives or false negatives.

The efficiency of automated, dynamic baselining allows organizations to provide better DDoS protection to protect critical infrastructure, whether a service provider or a digital business enterprise.

As organizations tackle the critical need of DDoS protection, the key to success will be a combination of autonomous learning capabilities and operational efficiency. By moving from static baselining to automated, dynamic baselining, you can provide more accurate and responsive protection while easing the workload for strapped security teams.

About the essayist: Ahmed Abdelhalim, Senior Director, Security Solutions, A10 Networks

View Details

Tel Aviv, Israel, May 2, 2024, CyberNewsWire — LayerX, pioneer of the LayerX Browser Security platform, today announced $26 million in Series A funding led by Glilot+, the early-growth fund of Glilot Capital Partners, with participation from Dell Technologies Capital and other investors. Lior Litwak, Managing Partner at Glilot Capital and Head of Glilot+, and Yair Snir, Managing Partner at Dell Technologies Capital, will join the LayerX board.

The new capital will be used for corporate growth across talent and increasing global market presence. This round brings the company’s total investment to $34 million.

Early adoption by Fortune 100 companies worldwide, LayerX already secures more users than any other browser security solution and enables unmatched security, performance and experience

Today’s modern enterprise employees rely heavily on browser-based services and SaaS applications. Yet, these fundamental work activities expose organizations to a wide range of security risks, like data leaks, identity and password theft, malicious browser extensions, phishing sites and more. LayerX was purpose-built to secure and govern browser-based work, from both managed and unmanaged devices.

“We’ve transformed workforce protection for organizations without requiring the transition to a dedicated secure browser. Unlike other solutions, installed in a matter of minutes, the LayerX Browser Extension does not impact employee efficiency, speed, privacy or the browsing experience, ” said Or Eshed, co-founder and CEO, LayerX.

“As the browser becomes more central to the employee, we anticipate it becomes more attractive to the attacker, particularly in the wake of GenAI tools used in browser-related activities,” he continues. “Today’s funding round is a testament to our increasing market opportunity and the innovation behind our platform’s user-friendly approach to a more secure browser experience.”

LayerX’s Enterprise Browser Extension is compatible with all commonly used browsers, including Chrome, Firefox, Edge and others, without requiring agents, a VPN or network modifications. Once deployed, the information security or IT team gains visibility into user activities and can block or restrict any threat in real-time, without impacting the user experience.

LayerX protects against all threats, whether they were inadvertently or maliciously caused by the employee, or whether they were originated by the attacker. The solution includes an AI engine that granularly monitors the code run by the browser and automatically generates a variety of insights related to user behavior in the browser.

“Since inception, LayerX showed super fast growth and adoption by the world’s leading enterprises. The company is at the forefront of defense for modern organizations. By protecting the browser, the central productivity application in organizations, from a wide range of new-generation security risks, LayerX can solve acute security problems that have remained unanswered until now,” said Kobi Samboursky, Founding and Managing Partner at Glilot Capital “We believe that this novel solution for securing browsers will replace most SASE and SSE solutions prevalent today in organizations. At an estimated market size of $7 billion, the potential inherent in LayerX’s technology is tremendous.”

“Similar to other successful entrepreneurs in the cybersecurity field we’ve collaborated with, Or and David bring significant experience and knowledge in understanding the technical issues involved in threats to organizations and the motivations of attackers. Consequently, they recognize that effective security measures should adapt to real-world user behaviors, rather than the other way around,” said Yair Snir, Managing Director at Dell Technologies Capital. “In a world where most computer operations are conducted through browsers, LayerX introduces a creative approach to corporate security that is user-friendly, robust, and easily implementable in large organizations. This approach transforms the browser from a major vulnerability to a strength, facilitating secure work across devices. Our investment in LayerX isn’t just driven by the promising opportunity but also by the potential impact of the company’s solution on organizations, regardless of where employees conduct their tasks.”

About LayerX: LayerX was founded in 2022 by Or Eshed, CEO, and David Weisbrot, CTO, who developed web attack and defense systems during their military service. In 2017, Eshed led the exposure of the largest attack campaign in history on the Chrome browser, which involved tens of millions of compromised browsers and even led to the capture and trial of the hackers. LayerX has Fortune 100 clients worldwide.

LayerX Enterprise Browser Extension natively integrates with any browser, turning it into the most secure and manageable workspace, with no impact on the user experience. Enterprises use LayerX to secure their devices, identities, data, and SaaS apps from web-borne threats and browsing risks that endpoint and network solutions can’t protect against. Those include data leakage over the web, SaaS apps and GenAI Tools, malicious browser extensions, phishing, account takeovers, shadow SaaS, and more.

Media contact: Dori Harpaz, LayerX, dori@layerxsecurity.com

View Details

It took some five years to get to 100 million users of the World Wide Web and it took just one year to get to 100 million Facebook users.

Related: LLM risk mitigation strategies

Then along came GenAI and Large Language Models (LLM) and it took just a couple of weeks to get to 100 million ChatGPT users.

LLM is a game changer in the same vein as the Gutenberg Press and the Edison light bulb. It gives any literate human the ability to extract value from data.

Companies in all sectors are in a mad scramble to reap its benefits, even as cyber criminals feast on a new tier of exposures. As RSAC 2024 gets under way next week in San Francisco, the encouraging news is that the cybersecurity industry is racing to protect business networks, as well.

Case in point, the open-source community has coalesced to produce the OWASP Top Ten for Large Language Model Applications. Amazingly, just a little over a year ago this was a mere notion dreamt up by Exabeam CPO Steve Wilson.

“I spent some time on a weekend drawing up a scratch version of a Top Ten list, partly by having a discussion with ChatGPT about it,” Wilson told me. “The first thing I asked was, ‘Do you know what an OWASP Top Ten list is?’ And it said, ‘Yes.’ And I said, ‘Build me one for LLM.’ It did, but it wasn’t very good . . . I then spent a lot of time feeding it data about things and coaching it and cajoling it and having a discussion.”

By the end of an afternoon of prompting, Wilson had a list he thought was “pretty interesting,” which he socialized in his professional communities. That was a little over a year ago. What happened next is unprecedented. For a full drill down, please give the accompanying podcast a listen.

The pace of change is accelerating. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.

View Details

At the close of 2019, API security was a concern, though not necessarily a top priority for many CISOs.

Related: GenAI ignites 100x innovation

Then Covid 19 hit, and API growth skyrocketed, a trajectory that only steepened when Generative AI (GenAI) and Large Language Models (LLMs) burst onto the scene.

As RSA Conference 2024 gets underway next week at San Francisco’s Moscone Center, dealing with the privacy and security fall out of those back-to-back disruptive developments will command a lot attention.

Ahead of conference, I had the chance to visit with Sanjay Nagaraj, CTO and co-founder, Traceable.ai, a supplier of advanced API security systems.

We discussed how enterprises in 2019 were deep into making the transition from on-premises networks to cloud-centric, edge-oriented operations when the global pandemic hit. Instantly, API connections skyrocketed to support connected services for a quarantined world. Then machine learning made a giant leap forward as GenAI and LLMs made AI capabilities directly accessible to every man, woman and child.

At this moment, companies are in a mad scramble to innovate cool, new user experiences, and thus drive-up revenue, Nagaraj observes. Of course, cybercriminals are in intensive innovation mode, as well.

It has become table stakes for companies to discover all of their APIs, now imperative for companies not just to discover all of their APIs, but also to understand them and categorize them according to risk level, Nagaraj argues. For a full drill down, please give the accompanying podcast a listen.

APIs are the synaptic connections of our hyper-interconnected existence. Securing them has become paramount. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.

View Details

Tel Aviv, Israel – April 30, 2024 – Cybersixgill, the global cyber threat intelligence data provider, broke new ground today by introducing its Third-Party Intelligence module.

The new module delivers vendor-specific cybersecurity and threat intelligence to organizations’ security teams, enabling them to continuously monitor and detect risks to their environment arising from third-party suppliers and take preemptive action before an attack executes.

The Third-Party Intelligence module combines vendor-specific cyber threat intelligence (CTI) with cybersecurity posture data from suppliers’ tech environments, exposing a critical blind spot for security teams. With this intelligence, threat analysts and security operations teams can identify threats from the supply chain and expand their threat exposure management efforts.

Research shows that in 2023, there were 245,000 software supply chain attacks, costing organizations $46 billion. That amount will likely rise to $60 billion in 2025. Additionally, nearly two-thirds (61%) of U.S. businesses were directly impacted by a software supply chain attack in the 12-month period ending in April 2023, while 66% of companies say they do not trust their third parties to notify them of a major breach.

“Cybersixgill’s new Third-Party Intelligence is a significant advancement in delivering actionable threat intelligence insights to security teams and CISOs to help them strengthen and protect the organization’s risk posture,” said Chris Steffen, Vice President of Research, Security, and Risk Management for Enterprise Management Associates (EMA). “Threat intelligence that shines a broad, bright light on threats from within a company’s third-party network has been a glaring missing piece in organizations’ cybersecurity programs. I applaud their efforts to bring this much-needed solution to market.”

“Security teams can take every precaution to protect their organization’s environment. But if they lack intelligence about the risks facing their third-party supply chain and the impact on their security posture, the consequences can be costly to the company’s brand and bottom line,” said Gabi Reish, Chief Product Officer for Cybersixgill. “With the rising cost of supply chain attacks, our new Third-Party Intelligence module gives security operations and threat analysts critical insights to protect their organization and its network of suppliers and partners.”

For more information, including a video walk-through of Cybersixgill’s new Third-Party Intelligence, visit https://cybersixgill.com/products/cyber-threat-intelligence/third-party-intelligence.

About Cybersixgill: Cybersixgill continuously collects and exposes the earliest indications of risk by threat actors moments after they surface on the clear, deep, and dark web. The company’s vast intelligence data lake, derived from millions of underground sources, is processed, correlated, and enriched using automation and advanced AI. Cybersixgill captures, processes, and alerts teams to emerging threats, TTPs, IOCs, and their exposure to risk based on each organization’s complete attack surface and internal context. Its expert intelligence and insights, available through a range of seamlessly integrated options, enable customers to pre-empt threats before they materialize into attacks. The company serves and partners with global enterprises, financial institutions, MSSPs, and government and law enforcement agencies. For more information, visit https://www.cybersixgill.com/ and follow us on Twitter and LinkedIn. To schedule a demo, please visit https://cybersixgill.com/book-a-demo.

View Details

For all the discussion around the sophisticated technology, strategies, and tactics hackers use to infiltrate networks, sometimes the simplest attack method can do the most damage.

The recent Unitronics hack, in which attackers took control over a Pennsylvania water authority and other entities, is a good example. In this instance, hackers are suspected to have exploited simple cybersecurity loopholes, including the fact that the software shipped with easy-to-guess default passwords.

Related: France hit by major DDoS attack

The Unitronics hack was particularly effective given the nature of the target. Unitronics software is used by critical infrastructure (CI) organizations throughout the U.S. in different industries, including energy, manufacturing, and healthcare. Unitronics systems are exposed to the Internet and a single intrusion caused a ripple effect felt across organizations in multiple states.

Attacks like the one on Unitronics are a good reminder for all CI organizations to reassess their cybersecurity policies and procedures to ensure they can repel and mitigate cybersecurity threats. Here are three strategies they should pursue in 2024 to minimize the chance of a Unitronics-style hack.

Attack surface

Building perimeter defense systems and keeping services in-house have traditionally been two of the most common ways to defend IT infrastructure. The problem with this from a security perspective is that there tends to be no segregation between services. All an attacker needs to do is infiltrate one application to have access to the entire network.

Moving services to the cloud segregates applications and significantly reduces the potential blast radius. Years ago there was some skepticism about public cloud service providers’ security policies, but the reality is that most of those services are now highly secure. The largest ones, such as Amazon and Microsoft, have stringent protocols for securing their cloud infrastructures.

Still, CI organizations need to perform the appropriate due diligence before signing any agreements. At a minimum, cloud providers should have the same robust security practices as the organizations themselves. It’s also important to assess the provider’s patching environment and cadence, the processes they use to discover and manage vulnerabilities, whether they have a security operations center, and so forth.

Vetting process

Normally, the vetting process for a technology provider falls strictly under the purview of IT. But as cybersecurity threats evolve, it’s equally important to involve the chief information security officer (CISO) and their team in the due diligence process for any vendor an organization may consider using.Once again, the Unitronics attack offers a great example of why involving security teams early and often is a good idea. An advisory issued by the Cybersecurity and Infrastructure Security Agency (CISA) noted that attackers achieved their mission “likely by compromising internet-accessible devices with default passwords” included in Unitronics software. An IT team primarily interested in functionality, features, and integration capabilities may overlook such flaws. However, security experts are trained to identify these issues and therefore can ensure that the software is vulnerability-free and follows good cybersecurity best practices.

Eventually, more organizations may want to consider appointing their CISOs to head all of IT. Having a shared organizational structure in which IT reports directly to the CISO will help make certain that both the technical and security needs of the organizations are met, and that security is at the forefront of all technology purchasing decisions.

In the meantime, security teams should be the points of contact for Cybersecurity Maturity Model Certification (CMMC) audits. These audits are performed by third-party assessor organizations and are used to gauge the cybersecurity maturity of organizations that supply technology to the defense industrial base, including CI organizations. The CMMC program includes a progressive framework to ensure vendors meet National Institutes of Standards and Technology (NIST) cybersecurity standards. Vendors that meet these standards are less likely to contain vulnerabilities that could infect CI organizations through their supply chains.

Continual testing

While performing rigorous assessments before vendors are onboarded is important, so is performing ongoing internal and external penetration tests to simulate attacks and test for potential weaknesses. For example, OT systems have become highly connected, making them an obvious target for hackers. Penetration testing can identify vulnerabilities within these systems and allow security teams to find areas where traditional network segmentation techniques aren’t effective. This is often the case with nation-state threats and other highly skilled threat actors.

Once the systems are physically separated, organizations can install data diodes and data guards to ensure the secure transfer of information between networks in ways that prevent threat actors from compromising them. A data diode facilitates a uni-directional stream of information from one device to another, preventing bi-directional data flow. A data guard, meanwhile, ensures that only the intended structured and unstructured data is transferred across these networks.

These strategies denote a shift from reactive to proactive cybersecurity and a new way of thinking about cybersecurity defense. Organizations must move from a “trust but verify” mindset to a Zero Trust approach. Organizations that adopt this mindset while embracing the cloud, employing a shared responsibility model, and performing continual testing will take the fight to the attackers and gain a much-needed advantage.

About the essayist: Joseph Bell is Chief Information Security Officer at Everfox.

View Details

At the end of 2000, I was hired by USA Today to cover Microsoft, which at the time was being prosecuted by the U.S. Department of Justice.

Related: Why proxies aren’t enough

Microsoft had used illegal monopolistic practices to crush Netscape Navigator thereby elevating Internet Explorer (IE) to become far and away the No. 1 web browser.

IE’s reign proved to be fleeting. Today Google’s Chrome browser — based on the open-source code Chromium — reigns supreme.

I bring all this up, because in 2019 Microsoft ditched its clunky browser source code and launched its Edge browser, based on open-source Chromium. And this opened the door to a great leap forward in web browser security: enterprise browsers.

As RSAC 2024 gets ready to open next week, the practicality of embedding advanced security tools in company-sanctioned web browsers is in the spotlight. I had a wide-ranging discussion about this with Uy Huynh, vice president of solutions engineering at Island, a leading supplier of enterprise browsers. For a full drill down, please give the accompanying podcast a listen.

As an open-source project, Chromium promotes web standards compliance, ensuring that web developers can create content that works consistently across different browsers. Island has seized the opportunity to innovate browser security features that enable companies to reduce their reliance on VDI environments and shrink their SaaS authentication sprawl, Huynh told me

Enterprise browsers could emerge as a key component of the evolving network security platforms that will carry us forward. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Critical infrastructure like electrical, emergency, water, transportation and security systems are vital for public safety but can be taken out with a single cyberattack. How can cybersecurity professionals protect their cities?

In 2021, a lone hacker infiltrated a water treatment plant in Oldsmar, Florida. One of the plant operators noticed abnormal activity but assumed it was one of the technicians remotely troubleshooting an issue.

Only a few hours later, the employee watched as the hacker remotely accessed the supervisory control and data acquisition (SCADA) system to raise the amount of sodium hydroxide to 11,100 parts per million, up from 100 parts per million. Such an increase would make the drinking water caustic.

The plant operator hurriedly took control of the SCADA system and reversed the change. In a later statement, the company revealed redundancies and alarms would have alerted it, regardless. Still, the fact that it was able to happen in the first place highlights a severe issue with smart cities.

The hacker was able to infiltrate the water treatment plant because its computers were running on an outdated operating system, shared the same password for remote access and were connected to the internet without a firewall.

Deadly exposure

Securing critical infrastructure is crucial for the safety and comfort of citizens. Cyberattacks on smart cities aren’t just inconvenient — they can be deadly. They can result in:

•Injuries and fatalities. When critical infrastructure fails, people can get hurt. The Oldsmar water treatment plant hacking is an excellent example of this fact, as a city of 15,000 people would have drank caustic water without realizing it. Malicious tampering can cause crashes, contamination and casualties.

Amos

•Service interruption. Unexpected downtime can be deadly when it happens to critical infrastructure. Smart security and emergency alert systems ranked No. 1 for attack impact because the entire city relies on them for awareness of impending threats like tornadoes, wildfires and flash floods.

•Data theft. Hackers can steal a wealth of personally identifiable information (PII) from smart city critical infrastructure to sell or trade on the dark web. While this action doesn’t impact the city directly, it can harm citizens. Stolen identities, bank fraud and account takeover are common outcomes.

•Irreversible damage. Hackers irreversibly damage critical infrastructure. For example, ransomware could permanently encrypt Internet of Things (IoT) traffic lights, making them unusable. Proactive action is essential since experts predict this cyberattack type will occur every two seconds by 2031

Security level of smart cities

While no standard exists to objectively rank smart cities’ infrastructure since their adoption pace and scale vary drastically, experts recognize most of their efforts are lacking. Their systems are interconnected, complex and expansive — making them highly vulnerable.

Despite the abundance of guidance, best practices and expert advice available, many smart cities make the mistake the Oldsmar water treatment plant did. They neglect updates, vulnerabilities and security weaknesses for convenience and budgetary reasons.

Minor changes can have a massive impact on smart cities’ cybersecurity posture. Here are a few essential components of securing critical Infrastructure:

•Data cleaning and anonymization. Cleaning and anonymization make smart cities less likely targets — de-identified details aren’t as valuable. These techniques verify that information is accurate and genuine, lowering the chances of data-based attacks. Also, pseudonymization can protect citizens’ PII.

•Network segmentation. Network segmentation confines attackers to a single space, preventing them from moving laterally through a network. It minimizes the damage they do and can even deter them from attempting future attacks.

•Zero-trust architecture. The concept of zero-trust architecture revolves around the principle of least privilege and authentication measures. It’s popular because it’s effective. Over eight in 10 organizations say implementing it is a top or high priority. Limiting access decreases attack risk.

•Routine risk assessments. Smart cities should conduct routine risk assessments to identify likely threats to their critical infrastructure. When they understand what they’re up against, they can handcraft robust detection and incident response practices.

•Real-time system monitoring. The Oldsmar water treatment plant’s hacking is a good example of why real-time monitoring is effective since the operator immediately detected and reversed the attacker’s changes. Smart cities should implement these systems to protect themselves.

Although smart city cyberattacks don’t make the news daily, they’re becoming more frequent. Proactive effort is essential to prevent them from growing worse. Public officials must collaborate with cybersecurity leaders to find permanent, reliable solutions.

About the essayist: Zac Amos writes about cybersecurity and the tech industry, and he is the Features Editor at ReHack. Follow him on Twitter or LinkedIn for more articles on emerging cybersecurity trends.

View Details

San Francisco, Calif. — The amazing digital services we have today wouldn’t have come to fruition without the leading technology and telecom giants investing heavily in R&D.

Related: GenAi empowers business

I had the chance to attend NTT Research’s Upgrade Reality 2024 conference here last week to get a glimpse at some of what’s coming next.

My big takeaway: GenAI is hyper-accelerating advancements in upcoming digital systems – and current ones too. This is about to become very apparent as the software tools and services we’re familiar with become GenAI-enabled in the weeks and months ahead.

And by the same token, GenAI, or more specifically Large Language Model (LLM,) has added a turbo boost to the pet projects that R&D teams across the technology and telecom sectors have in the works.

The ramifications are staggering. The ability for any human to extract value from a large cache of data – using conversational language opens up a whole new universe of possibilities.

The power of conversations

One small example is a souped-up Jibo smart home assistant — a prototype — that can do much more than lock the doors, turn out the lights and set the thermostat. Thanks to GenAI, users can engage this prototype in conversations that get steadily richer over time.

Heidbrink

NTT Research is testing its Jibo protype as a chatty, mindful digital companion oriented to assisting the elderly in multifaceted ways. Sensors scattered around a home keep track of motion, temperature, CO2 levels, light levels and sound. A baseline gets established, deviations get analyzed and responses automatically get fine-tuned.

This all gets done leveraging well-established AI algorithms — but GenAI takes it to another level, says Chris Heidbrink, NTT Research senior vice president of AI & Innovation.

By factoring in human language cues, Jibo over time can start to detect sentiment and potentially identify health conditions based on conversations. “What we’re doing is combining traditional AI with quality data — and then bringing in GenAI is like adding polish to it,” Heidbrink told me. “GenAI allows us to plug in many different things, combine them together and have really deep conversations about them.”

Tech giants out front

Jibo is a microcosm of how GenAI is turbo boosting R&D prototypes of all kinds. Meanwhile, the dust storm clouding the tech horizon is being kicked up by enterprises in all sectors racing to deploy GenAI in support of their entrenched business models.

This GenAI gold rush is being led by the marquee tech giants. Like me, you may be beta testing Adobe’s “Ai Assistant” prototype for Acrobat that allows you to type conversational commands directly into PDF documents. On my SEA to SFO flight, I sat next to a Meta software engineer and we chatted about how Microsoft’s $10 billion investment in OpenAI/ChatGPT is all about integrating ChatGPT into Windows and Office, while Google’s Gemini services is all about infusing GenAI into Google Search, Google Docs and YouTube.

Likewise, Facebook LLaMA is Meta’s attempt to extract more value from its core asset, Facebook users’ digital footprints. This, of course, raises profound privacy and cybersecurity questions that are just starting to heat up with the rising tide of GenAI-infused deep fake attacks.

Cybersecurity conundrum

Somewhat ironically, the cybersecurity industry itself is scrambling to integrate LLM into emerging security platforms and frameworks to mitigate deep fakes, as well as to get in a better position to address sure-to-come iterations of cyber attacks enhanced by GenAi. (Stay tuned for Last Watchdog’s RSAC Insights podcasts from RSAC 2024, just around the corner.)

I broached this topic at Upgrade Reality 2024 with Moshe Karako, CTO of NTT Innovation Laboratory in Israel. On a whim, while waiting for a flight to Tokyo, Karako was able to persuade Microsoft’s Copilot chat tool to violate Microsoft policy and solve a captcha to gain him access to a secured website page.

Karako

Moshe used tried-and-true social engineering tactics, such as misspelling words and using persuasive language, to lower Copilot’s guard and manipulate the conversation in his favor. “All it took was playing with prompts to convince it to do what I needed,” Karako says. “And there’s no active solution today that can prevent this.”

Here we go again. Remember how email spam, evolved into phishing attacks, ransomware and advanced persistent threats? This transpired over the past 20 years as business networks advanced from on-premises data centers to hybrid cloud. Along the way, cyber exposures mushroomed. Now GenAI has set us up for a repeat of that cycle — only at a breakneck pace of change.

The hype over the impact of GenAI is just getting started. I heard Vab Goel, founding partner of NTTVC, declare that GenAI will trigger 100X more change that we’ve seen over the past 100 years. Another executive, Rajeev Shah, founder and CEO of Celona.io, I thought, put it best. Speaking on a panel discussion about the transformative potential of GenAI, Shah said this:

Shah

“Actually, I think, as a Silicon Valley (company) founder that it is very rare, and it’s actually the first time in my entire career, that I have been confronted with a technology that neither can I fully understand, nor can I fully grasp the potential. I don’t think any of us have fully internalized yet how transformative AI can be.”

So where will this democratization of AI take us over the next few months and in next couple of years? That’s the turbo-boosted digital revolution we’re all about to experience. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


View Details

San Francisco and Tokyo, Apr. 11, 2024 – At Upgrade 2024, NTT Corporation (NTT) and NTT DATA announced the successful demonstration of All-Photonics Network (APN)-driven hyper low-latency connections between data centers in the United States and United Kingdom.

In the U.K., NTT connected data centers north and east of London via NTT’s Innovative Optical Wireless Network (IOWN) APN, and communication between them was realized with a round-trip delay of less than 1 millisecond. In the U.S., data centers in Northern Virginia achieved similar results. The goal of this initiative is to transform geographically distributed IT infrastructure into the functional equivalent of a single data center.

The data center market is under severe local constraints. Carbon dioxide emission restrictions and land shortages have made it difficult to build data centers in urban areas, forcing operators to turn to the suburbs. Yet with geographically distant data centers, delay of communication, or latency, can be very high, making it difficult to meet customers’ needs for low latency. In separate demonstrations, NTT and NTT DATA connected data centers in the U.K. (HH2 in Hemel Hempstead and LON1 in Dagenham) and in the U.S. (VA1 and VA3 in Ashburn) using APN equipment from NEC.

These U.K. and U.S. data centers are 89km and 4km apart, respectively. (See Figure 1.) Measurements in tests conducted over 100 Gbps and 400 Gbps links showed the two APN-connected data centers in the U.K. operated with less than 1 millisecond (approximately 0.9 milliseconds) of latency, and with a delay variation (sometimes called jitter) of less than 0.1 microseconds. (See Figure 2 and Table 1.)

According to cloud connectivity provider Megaport, typical delay between data centers at an equivalent distance exceeds 2,000 microseconds (2 milliseconds). In the U.S. case, delay over the much shorter span was approximately 0.06 milliseconds; and delay variation was less than 0.05 microseconds. By contrast, conventional networks with general Layer 2 switches experience delay variation of several microseconds to tens of microseconds. In other words, the APN cuts latency in half, and jitter by orders of magnitude.

The APN delivered very low latency required by current and emerging use cases. These include distributed, real-time AI analysis, such as industrial IoT and predictive maintenance, smart surveillance systems, smart grid and energy management, natural disaster detection and response and more.

NTT DATA is also conducting demonstrations in the financial sector, where low latency is required for remittances, settlements and transactions. Another advantage of the IOWN APN is that it enables line activation simply by adding wavelengths, without needing to install new dark fiber. As a result, data center operators can respond very quickly to customer demand.

About NTT: NTT contributes to a sustainable society through the power of innovation. We are a leading global technology company providing services to consumers and businesses as a mobile operator, infrastructure, networks, applications, and consulting provider. Our offerings include digital business consulting, managed application services, workplace and cloud solutions, data center and edge computing, all supported by our deep global industry expertise. We are over $97B in revenue and 330,000 employees, with $3.6B in annual R&D investments. Our operations span across 80+ countries and regions, allowing us to serve clients in over 190 of them. We serve over 75% of Fortune Global 100 companies, thousands of other enterprise and government clients and millions of consumers.

Media contact, Nick Gibiser, Wireside Communications for NTT Corporation, Email: gibiser@wireside.com, Phone: +1-804-500-6660

View Details

Mountain View, Calif. – April 11, 2024 Simbian today emerged from stealth mode with oversubscribed $10M seed funding to deliver on fully autonomous security.

As a first step towards that goal, the company is introducing the industry’s first GenAI-powered security co-pilot that integrates secure and intelligent AI solutions into diverse IT environments to maximize coverage and expedite resolutions to security teams’ ever-changing needs.

The co-pilot continuously observes user actions and environments, and learns to autonomously perform increasingly sophisticated tasks on its own with time. Simbian is committed to making security fully autonomous by delegating all tactical tasks to its trusted AI platform, allowing users to focus on strategic security goals.

Simbian, the name derived from the symbiotic relationship between humans and AI, has received initial investment from security and AI-focused investors Cota Capital, Icon Ventures, Firebolt and Rain Capital. Its founding team comprises leading AI researchers and security veterans who have created security products in broad use across enterprises today, and have 150+ patents across large language models, cloud computing, encryption, scalable architecture, transistors, and hardware design.

“Traditional approaches to security automation no longer suffice in today’s dynamic environments,” said Cota Capital Partner Aditya Singh. “Talent is getting scarce, and at the same time threat vectors are getting more complex. A fully autonomous security platform presents a big opportunity in the global cybersecurity market which, according to a cybersecurity market report, is to grow to $298.5 billionby 2028. Simbian is a leader in the field, using a deep understanding of the nuance and context of security automation that learns with AI and gets smarter and deeper over time.?

Simbian’s founding team has a uniquely proven background, having built NVIDIA GPUs, confidential computing, and leading cloud security solutions. We are thrilled to join Simbian in the journey to fully autonomous security.”

In addition, 15 of today’s most successful business leaders back the company, including Olivier Pomel, Co-founder and CEO at Datadog; Pankaj Patel, Co-founder and CEO at Nile; Diogo Monica, Co-founder and CEO at Anchorage Digital; Joe Sullivan, former CSO at Facebook, Uber and CloudFlare; Bharat Shah, former CVP of Microsoft Security; Suresh Batchu, Co-founder and COO at Seraphic; Paul Albright, Operating Partner at Goldman Sachs; Pierre Lamond, legendary Silicon Valley investor; and Gokul Rajaram, board member at Coinbase and Pinterest.

Simbian’s GenAI-powered platform is the industry’s first security co-pilot that adapts to diverse IT environments and covers the entire gamut of security functions. Most businesses have a mix of software from multiple vendors and in-house software. Each business and each member of a security team have unique, ever-changing security needs.

Simbian helps every member of the security team from the CISO to the frontline practitioner solve their unique security needs in real-time. Users provide their goal in natural language, and Simbian’s patent-pending LLM-powered platform provides personalized recommendations and generates automated actions across heterogeneous environments – delivering better security outcomes, higher agility to evolving business needs and threats, and lower costs.

“Security is a domain of ever-increasing complexity,” said Sergey Gorbunov, Co-founder at Axelar. “Every day security incidents bring new variables. Simbian is taking a big step forward towards the mission of a fully autonomous security platform. We are excited to partner with them as it allows us to be strategic in our security goals, leaving the mechanics of security to Simbian.”

While security vendors are increasingly using GenAI, off-the-shelf GenAI models come with many security risks, including hallucinations, prompt injection risks, and exposure of PII and confidential data. Simbian minimizes these risks by leveraging a patent-pending hardened LLM system called TrustedLLM™ that utilizes multiple layers of security controls between the user and the GenAI models it uses under the hood.

“AI-driven security solutions can greatly improve threat detection, speeding remediation, and reducing complexity,” said Dave Gruber, Principal Analyst at Enterprise Strategy Group. “Simbian is bringing this vision to a reality, as they leverage AI to automate many of the more challenging, frequent security tasks performed by all levels of security analysts throughout their day.”

Simbian’s Co-founder and CEO Ambuj Kumar was most recently the Co-founder and CEO at Fortanix, a successful data security company, where he raised $135M+ and established the Confidential Computing security category. Mr. Kumar previously served as Lead Designer of NVIDIA GPUs and as Chief Architect at Cryptography Research Inc. Simbian’s Co-founder and CTO Alankrit Chona has extensive background in high scale platforms and data engineering from Twitter, and was a founding member of successful startups Afterpay and Spotnana.

Kumar

“Security teams cannot keep up with the operational tasks they must do each day, despite years of investment in in-house automation and tools to make them more effective – which is why we founded Simbian,” said Ambuj Kumar, Simbian Co-Founder and CEO. “Early feedback and traction in the industry have been extremely positive, and we are excited to launch the company today.

A first in the industry, Simbian puts the security operator firmly in charge of security decisions, and we enable the user to interact with products across vendors to get things done. We stand unique in the industry with our ability to generate commands in code using LLM and based on a natural language user interface, and we enable users to craft permutations of the actions we support, all on the fly.”

About Simbian: Using GenAI, Simbian is the industry’s first company to integrate secure and intelligent AI solutions into business operations across diverse IT environments to maximize security coverage and speed resolutions to security teams’ most pressing ever-changing needs. Simbian, with its hardened TrustedLLM system, is the first to accelerate security by empowering every member of a security team, from the C-Suite to frontline practitioners, to craft tailored insights and workflows for their unique security needs – ranging from complex investigation and response to governance and reporting. The company is venture backed and headquartered in Mountain View, Calif. For more information, visit www.simbian.ai, or follow Simbian on https://www.linkedin.com/company/simbian/ and https://twitter.com/simbianai.

Media contact: Liz Youngs, Spalding Communications, 843-412-6327, liz@spaldingcomm.com

View Details

CISOs can sometimes be their own worst enemy, especially when it comes to communicating with the board of directors.

Related: The ‘cyber’ case for D&O insurance

Vanessa Pegueros knows this all too well. She serves on the board of several technology companies and also happens to be steeped in cyber risk governance.

I recently attended an IoActive-sponsored event in Seattle at which Pegueros gave a presentation titled: “Merging Cybersecurity, the Board & Executive Team”

Pegueros shed light on the land mines that enshroud cybersecurity presentations made at the board level. She noted that most board members are non-technical, especially when it comes to the intricate nuances of cybersecurity, and that their decision-making is primarily driven by concerns about revenue and costs.

Thus, presenting a sky-is-falling scenario to justify a fatter security budget, “does not resonate at the board level,” she said in her talk. “Board members must be very optimistic; they have to believe in the vision for the company. And to some extent, they don’t always deal with the reality of what the situation really is.

“So when a CISO or anybody comes into a board room and says, ‘if we don’t do this, this is going to happen,’ it makes them all feel anxious and they start to close down their thought processes around it.”

This suggests that CISOs must take a strategic approach, Pegueros observed, which includes building relationships up the chain of command and mastering the art of framing messages to fit the audience.

Last Watchdog engaged Pegueros after her presentation to drill down on some of the notions she highlighted in her talk. Here’s that exchange, edited for clarity and length.

LW: Why do so many CISOs still not get it that FUD and doom-and-gloom don’t work?

Pegueros: I think this is the case where CISOs understand the true gravity and risk of the situation and they feel a sense of urgency to drive action by senior management and the board. When that action does not materialize as they think it should, they start to use worst case scenarios to drive action.

Pegueros

In the end, the CISOs are just trying to do the right thing and resolve the issues threatening the organization. What they fail to realize is that the Board does not truly understand the risk of the situation and since nothing has happened up until that point, why would it happen now?

LW: What are fundamental steps CISOs can take to start to think and act strategically and communicate more effectively

Pegueros: First, they need to understand the business including financials, customer concerns, product deficiencies and any macro level issues and how they are impacting the business. Next, they need to understand the priorities of the business and frame all the security priorities in the context of the business priorities.

If the CISO wants to drive better compliance, then they talk about how compliance is key to enabling sales and how the customers are demanding compliance to do business with the company. If they want better patching, then the CISOs should talk about how patched systems will improve availability of the product and therefore service to the customers.

If they want improved visibility around security logs, they can talk about the benefits of better visibility to the overall troubleshooting and improved efficiencies in operations. Boards won’t argue with more revenue, better availability (which drives revenue) or greater efficiencies (which save money)

LW: Is compliance an ace in-the-hole, in a sense, for CISOs? How does the SEC’s stricter rules come into play, for instance.

Pegueros:Compliance is not going to fix all the security risks. Many companies who are compliant with various regulations or frameworks have had breaches. I believe compliance sets a minimum bar and a CISO must leverage compliance initiatives to drive overall better security, but it is not sufficient in and of itself.

Compliance brings visibility to a topic. For example, with the SEC Cybersecurity Rules, Boards are now much more aware of the importance of cyber and are having more robust conversations relative to cybersecurity.

LW: Is it overly optimistic to suggest that companies will soon start viewing security as a business enabler instead of a cost center?

Pegueros: Sound cybersecurity practices and risk management are a differentiator for many non-regulated companies and are table stakes for highly regulated organizations. Enterprise customers are demanding and driving the conversation around cybersecurity.

They are demanding to understand how their vendors could potentially impact their customers and their reputation. The evolving and interrelated ecosystem that most companies exist in has the entrance fee of sound cybersecurity practices. In time, organizations who do not pay this entrance fee will be kicked out.

LW: Massively interconnected, highly interoperable digital systems of the near future hold great promise. Don’t we have to solve security to get there?

Pegueros: Understanding digital connectedness, the benefits, and risks of that relationship and how it enables strategic objectives is key for the board to understand. Security is just one risk element of this reality.

Boards need to dig in and understand all the key connection points and how they could enable or potentially hinder growth for the organization. We have a long way to go relative to boards because technology is disrupting the established norms and modes of operations relative to governance. Boards must evolve or their organizations will fail.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


View Details

It’s a digital swindle as old as the internet itself, and yet, as the data tells us, the vast majority of security incidents are still rooted in the low-tech art of social engineering.

Related: AI makes scam email look real

Fresh evidence comes from Mimecast’s “The State of Email and Collaboration Security” 2024 report.

The London-based supplier of email security technology, surveyed 1,100 information technology and cybersecurity professionals worldwide and found:

•Human risk remains a massive exposure. Some 74 percent of cyber breaches are caused by human factors, including errors, stolen credentials, misuse of access privileges, or social engineering.

•New AI risks have lit a fire under IT teams. . Eight out of 10 of those polled expressed concerned about AI threats posed and 67 percent said AI-driven attacks will soon become the norm.

•Email remains the primary attack vector. The newest wrinkle – Generative AI tools, like ChatGPT, are giving rise to new attack paths, compounding the pressure from old standby threats, i.e. phishing, spoofing, and ransomware

van Zadelhoff

“Emerging tools and technologies like AI and deepfakes, along with the proliferation of collaboration platforms are changing the way threat actors work; but people remain the biggest barrier to protecting companies from cyber threats,” observes Marc van Zadelhoff, Mimecast CEO.

One types of email-borne exposure that continues to gut-punch companies large and small is Business Email Compromise (BEC) fraud. A study issued last August by Gartner analysts Satarupa Patnaik and Franz Hinner drills down on how legacy endpoint protections are falling short in the post-Covid, GenAI operating environment.

BEC = big losses

attackers finagle their way into corporate communications, mimicking or outright hijacking legitimate email accounts. They no longer bother with malware or link, instead focusing more so than ever on human failings. And it’s paying off to the tune of $2.7 billion in losses in just one year, according to the FBI.

The Gartner report highlights how BEC fraud often begins with an Account Takeover (ATO). Attackers infiltrate a user’s account to orchestrate their grand larceny and the collateral damage can be significant: loss of trust from customers and business partners .

Patnaik and Hinner lay out an argument as to why companies need to get on with their due diligence and move towards upgrading to AI-based secure email gateway solutions, equipped with behavioral analysis and imposter detection. Indeed, the technology and best practices to do this are readily available. For enterprises looking to bolster their cyber-defenses, Gartner recommends:

•Leveraging GenAI in what amounts to a counter attack to granularing monitor and apply security policies to every email.

•Tapping proven controls such as k DMARC, MSOAR, IAM, MFA to serve as an effective layered defense.

•Updating antiquated email protocols for financial transactions. Email alone should never be the gatekeeper for moving money or sensitive data.

•Implementing effective training to teach users and partners how to spot and sidestep BEC traps.

We now know what the post Coivd 19/Gen AI threat threat landscape looks like, folks. One crucial layer to button down is human factors, which means advanced security for the most ubiquitous communication tool: email. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


View Details

The technology and best practices for treating cybersecurity as a business enabler, instead of an onerous cost-center, have long been readily available.

Related: Data privacy vs data security

However, this remains a novel concept at most companies. Now comes a Forrester Research report that vividly highlights why attaining and sustaining a robust cybersecurity posture translates into a competitive edge.

The report, titled “Embed Cybersecurity And Privacy Everywhere To Secure Your Brand And Business,” argues for a paradigm shift. It’s logical that robust cybersecurity and privacy practices need become intrinsic in order to tap the full potential of massively interconnected, highly interoperable digital systems.

Forrester’s report lays out a roadmap for CIOs, CISOs and privacy directors to drive this transformation – by weaving informed privacy and security practices into every facet of their business; this runs the gamut from physical and information assets to customer experiences and investment strategies.

Last Watchdog engaged Forrester analyst Heidi Shey, the report’s lead author, in a discussion about how this could play out well, and contribute to an overall greater good. Here’s that exchange, edited for clarity and length.

LW: This isn’t an easy shift. Can you frame the barriers and obstacles companies can expect to encounter.

Shey: A common barrier is framing and articulating the value and purpose of the cybersecurity and privacy program. Traditionally it’s been about focusing inward on securing systems and data at the lowest possible cost, driven by compliance requirements.

Compliance matters and is important, but with this shift, we have to recognize that it is a floor not a ceiling when it comes to your approach. Building your program and embedding these capabilities with a customer focus in mind is the difference. You are trying to align business and IT strategies – and brand value – to drive customer value here. This is a key factor for building trust in your organization.

LW: How can companies effectively measure the success of cybersecurity and privacy integration into their operations?

Shey

Shey: This is something that calls for a maturity assessment. By understanding the key competencies required for this type of shift, organizations can better gauge their current maturity and identify capabilities they need to shore up to further improve. These key capabilities fall under the four competencies of oversight, process risk management, technology risk management, and human risk management.

For example, process risk management capabilities include how well the organization implements security and privacy in its customer-facing products and services as well as its own internal processes. It also covers the extension of security and privacy requirements to third-party partners and the ability to respond quickly and effectively to external questions from stakeholders such as customers, auditors, and regulators.

Within a maturity assessment like this, you can start to hone in on areas of improvement. If you’re doing a particular activity in an ad-hoc way today, establishing a repeatable process for it helps you push to the next level of maturity.

LW: Cultural change is acutely difficult. What should CIOs and CISOs expect going in; what basic rethinking do they need to do?

Shey: Re-examine their own relationship first, specifically the trust and empathy between CIO and CISO. You need to be partners in driving this. If the CIO and CISO are operating in silos, and do not have shared vision, goals, and values here, it will make broader organizational cultural change difficult.

LW: Some progressive companies are moving down this path, correct? What have we learned from them; what does the payoff look like?

Shey: Yes, and this goes back to a point I made earlier about a key outcome of building customer trust in your organization. Trusted organizations reap rewards. Our research and data on consumer trust have proven this. Customers that trust your firm are more likely to purchase again, share personal data, and engage in other revenue-generating behaviors.

There is also a benefit of stronger business partnerships. We operate in a world today where your business is the risk and how you adapt is the opportunity. Companies view it as a risk to do business with your firm, whether they’re purchasing products and services or sharing data with you. Your ability to comply with partner’s or B2B customer’s security requirements will be critical.

LW: What approach should mid-sized and smaller organizations take? What are some basic first steps?

Shey: Resist the urge to go buy technology as the first step. Emphasize strategy and oversight of your cybersecurity and privacy program, because you can’t embed the foundation for what you have not built yet. Align with a control framework as a starting point.

This will be your common frame of reference for connecting policies, controls, regulations, customer expectations, and business requirements. Recognize that as you mature your program, a Zero Trust approach will help you take your efforts beyond compliance.

Conduct a holistic assessment of technology and information risks to determine what matters most to the business, and identify the appropriate practices and controls to address those risks.

Set clear goals, such as a roadmap of core competencies to build and milestones. Identify clear lines of accountability to help make it transparent as to who is responsible for what, making it clear how each person on the team contributes to the program’s success.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


View Details

The National Institute of Standards and Technology (NIST) has updated their widely used Cybersecurity Framework (CSF) — a free respected landmark guidance document for reducing cybersecurity risk.

Related: More background on CSF

However, it’s important to note that most of the framework core has remained the same. Here are the core components the security community knows:

Govern (GV): Sets forth the strategic path and guidelines for managing cybersecurity risks, ensuring harmony with business goals and adherence to legal requirements and standards. This is the newest addition which was inferred before but is specifically illustrated to touch every aspect of the framework. It seeks to establish and monitor your company’s cybersecurity risk management strategy, expectations, and policy.

•Identify (ID): Entails cultivating a comprehensive organizational comprehension of managing cybersecurity risks to systems, assets, data, and capabilities.

•Protect (PR): Concentrates on deploying suitable measures to guarantee the provision of vital services.Detect (DE): Specifies the actions for recognizing the onset of a cybersecurity incident.

•Respond (RS): Outlines the actions to take in the event of a cybersecurity incident.

•Recover (RC): Focuses on restoring capabilities or services that were impaired due to a cybersecurity incident.

Noteworthy updates

The new 2.0 edition is structured for all audiences, industry sectors, and organization types, from the smallest startups and nonprofits to the largest corporations and government departments — regardless of their level of cybersecurity preparedness and complexity.

Emphasis is placed on the framework’s expanded scope, extending beyond critical infrastructure to encompass all organizations. Importantly, it better incorporates and expands upon supply chain risk management processes. It also introduces a new focus on governance, highlighting cybersecurity as a critical enterprise risk with many dependencies. This is critically important with the emergence of artificial intelligence.

To make it easier for a wide variety of organizations to implement the CSF 2.0, NIST has developed quick-start guides customized for various audiences, along with case studies showcasing successful implementations, and a searchable catalog of references, all aimed at facilitating the adoption of CSF 2.0 by diverse organizations.

The CSF 2.0 is aligned with the National Cybersecurity Strategy and includes a suite of resources to adapt to evolving cybersecurity needs, emphasizing a comprehensive approach to managing cybersecurity risk. New adopters can benefit from implementation examples and quick-start guides tailored to specific user types, facilitating easier integration into their cybersecurity practices.

Swenson

The CSF 2.0 Reference Tool simplifies implementation, enabling users to access, search, and export core guidance data in user-friendly and machine-readable formats. A searchable catalog of references allows organizations to cross-reference their actions with the CSF, linking to over 50 other cybersecurity documents – facilitating comprehensive risk management. The Cybersecurity and Privacy Reference Tool (CPRT) contextualizes NIST resources with other popular references, facilitating communication across all levels of an organization.

NIST aims to continually enhance CSF resources based on community feedback, encouraging users to share their experiences to improve collective understanding and management of cybersecurity risk. The CSF’s international adoption is significant, with translations of previous versions into 13 languages. NIST expects CSF 2.0 to follow suit, further expanding its global reach. NIST’s collaboration with ISO/IEC aligns cybersecurity frameworks internationally, enabling organizations to utilize CSF functions in conjunction with ISO/IEC resources for comprehensive cybersecurity management.

About the essayist: Jeremy Swenson is a disruptive-thinking security entrepreneur, futurist/researcher, and senior management tech risk consultant.

View Details

Congressional bi-partisanship these day seems nigh impossible.

Related: Rising tensions spell need for tighter cybersecurity

Yet by a resounding vote of 352-65, the U.S. House of Representatives recently passed a bill that would ban TikTok unless its China-based owner, ByteDance Ltd., relinquishes its stake.

President Biden has said he will sign the bill into law, so its fate is now in the hands of the U.S. Senate.

I fervently hope the U.S. Senate does not torpedo this long overdue proactive step to protect its citizens and start shoring up America’s global stature.

Weaponizing social media

How did we get here? A big part of the problem is a poorly informed general populace. Mainstream news media gravitates to chasing the political antics of the moment. This tends to diffuse sober analysis of the countless examples of Russia, in particular, weaponizing social media to spread falsehoods, interfere in elections, target infrastructure and even radicalize youth.

Finally, Congress appears to be heeding lessons available to be learned since the hacking John Podesta’s email account – not to mention all of the havoc Russia was able to foment in our 2016 elections, attempting to interfere in 39 states.

One of the most chilling examples of Russia methodically continuing to leverage social media as a strategic weapon has attracted barely any news coverage at all. In 2011, Russia launched a social media site called iFunny aimed at disaffected young men. iFunny has since been downloaded some 70 million times and functions as a tool for neo-Nazi terror groups to recruit Gen-Z males.

In the weeks leading up to the 2020 U.S. presidential election, authorities in North Carolina arrested a 19-year-old male with a van full of guns and explosives and charged him with plotting to assassinate then Democratic presidential nominee Biden. Federal court documents describe how the teenager had posted memes on iFunny questioning whether he should kill Biden, and also run numerous Google searches for things like Biden’s home address and information about automatic weapons and night-vision goggles.

During this same time frame, investigators at Pixalate, a Palo Alto, Calif.-based supplier of fraud management technology, documented how iFunny distributed data-stealing malware specifically targeting smartphone users in the key swing states of Pennsylvania, Michigan and Wisconsin.

50 upcoming elections

It’s logical to assume China has been and will continue to borrow from Russia’s social media manipulation playbook.

Sanchez

“If the amount of data harvested by TikTok is similar to all other social media platforms then there is a bigger problem to deal with as misinformation and deepfakes are threats that are quickly growing,” observes Antonio Sanchez, principal evangelist at Fortra. “This could impact election outcomes and there are 50 countries having elections this year.”

Senate detractors insist that this bill – or any legislation that puts any hint of rails around social media — will stifle innovation and impinge on civil liberties. Brandon Hart, CTO at Everything Blockchain, argues that this divest-or-be-banned mandate, aimed squarely at China “could inadvertently infringe upon (civil) liberties, potentially eroding public trust and individual autonomy.”

Safety first

Hart advocates more laisse faire intervention.

Hart

“A more fitting approach would be for the government to focus on identifying and elucidating potential threats, thereby empowering citizens to make informed decisions regarding the technologies they use,” Hart says.

Empowering citizens is all fine and well, but it is also true that the fundamental role of government is to keep the citizenry safe.

Clemens

“A nation-state must protect its citizens and today, protection extends beyond bodily or physical harm,” observes Daniel Clemens, CEO of ShadowDragon. “ The protection of a democratic government’s citizens may mean the protection of citizens’ data, which now justifies the intervention of nations.”

Clemens opines that forcing China to divest would be a “great step in countering the influence and outcomes from TikTok against a free society that does not need to be influenced by a regime that ignores basic human rights.”

Clemens further notes that if China is made to divest, it still stands to strike a windfall in profits off the sale of TikTok. “China will continue to break international laws and push the boundaries on digital surveillance to advance its interests,” he says. “There’s no change there.”

Careful calibrations

Proponents also point out that this bill has been carefully calibrated to stop a specific, tangible threat: the likelihood that China will use TikTok strategically against the U.S.

Strand

“Consideration needs to be given to determine what kind of data has and is being collected, and to what extent,” says Chris Strand, vice president, risk and compliance, at Cybersixgill. “Even in the event that no personal data is collected, there can still be reason to take action to prevent the abuse of data that relates to behaviors, emotions, and preferences, that can lead to nefarious outcomes, identity theft, and military operational intelligence.”

Clemens also adds that the West’s private sector has been moving away from China for years due to China’s rampant intellectual property thievery and censorship. “This sets an important precedent that signifies the US Government’s willingness to step in when consumer data is threatened,” Clemens says. “I hope to see more material regulatory actions against China in the future.”

Smith

Here’s what Gregg Smith, CEO of Technology Advancement Center, adds to this discussion: “Nation states like the U.S. should absolutely attempt to deter the abuse of domestic user data collected legally by adversary governments. In the case of TikTok, a U.S. adversary is collecting vast amounts of data on users likes, dislikes, patterns of behavior, etc.

“All of this information when put together like a puzzle leaves our nation and our individual citizens exposed. This type of intelligence collection tactic is all part of the ‘long game’ being played by the Chinese government to prepare for opportunities to weaken our nation.”

Agreed. I’d note that the concerted efforts by Chinese officials to downplay the significance of this bill is a sure sign that it has teeth – and, indeed, would deter America’s rivals from wielding social media as a strategic weapon against the U.S.

There’s no baseless paranoia here. Quite the opposite. The imperative for legislative intervention couldn’t be any clearer. We’re deep into a digital Pearl Harbor. Which way will the U.S. Senate pivot? We’ll soon find out. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


View Details

A close friend of mine, Jay Morrow, has just authored a book titled “Hospital Survival.”

Related: Ransomware plagues healthcare

Jay’s book is very personal. He recounts a health crisis he endured that began to manifest at the start of what was supposed to be a rejuvenation cruise.

Jay had to undergo several operations, including one where he died on the operating table and had to be resuscitated. Jay told me he learned about managing work stress, the fragility and preciousness of good health and the importance of family. We also discussed medical technology and how his views about patient privacy evolved. Here are excerpts of our discussion, edited for clarity and length:

LW: Your book is pretty gripping. It starts with you going on a cruise, but then ending up on this harrowing personal journey.

Morrow: That’s right. I was a projects manager working hard at a high-stress job and not necessarily paying any attention to the stress toll that it was taking on me over a number of years. Professionally, my plates were full. I was working 60 to 70 hours a week and that was probably too much.

Finally, my wife, Malia, said, ‘That’s enough!’ and she arranged for us to take a short cruise down the California coast to Mexico and back. By the time we got to the cruise terminal, my leg was hurting a little bit, it was just a little sore and I was limping a bit. Things quickly got a whole lot worse.

LW: It took quite some time to finally discover what was wrong.

Morrow: Initially, I went through a battery of different tests and even a series of operations, and they still weren’t sure. Finally, an orthopedic surgeon figured out that it was a cyst on my colon that would leak when I was under stress. This caused poisons to leak into my hip and infect the bone to the point where I contracted osteomyelitis, an excruciating bone infection.

All through this, I had to have three major operations, including removal of my femur. During one of my surgeries, I died on the operating table. I quit breathing. My heart stopped. There was no pulse or blood pressure and they had to use the paddles to bring me back to life and I was in a coma after that.

LW: How did technology come into play?

Morrow: Probably about every week I’d have to undergo an MRI. You’re inserted into a huge machine, and you’re not allowed to move. Then they spend what seems like hours checking various items. I couldn’t have survived without modern medical technology.

It helped the doctors, but it helped me even more so. The MRIs, the CAT scans and ultrasounds that I endured provided information that helped me understand what was going on. Knowing how things were progressing was very important to me.

LW: You told me your views on patient privacy shifted through the course of all this.

Morrow: It used to be you could just walk into the hospital and see a doctor with minimal fuss. Now, often times, you have to check in through layered technologies that require several levels of proving you are who you say you are. This is because of HIPAA privacy functions but also because of the waves of ransomware attacks against health care facilities.

LW: Were you at any point concerned about your privacy being invaded?

Morrow: What I came to realize is that survival trumps privacy. By default, you give up all your personal privacy to receive medical treatment in a tightly controlled environment. In fact, once you’re in a hospital, you need to be assertive. The hospital staff is overworked and most often will fall back on protocol, and sometimes protocol just does not work; sometimes you need to push back.

LW: What’s the main thing you’d like your book to convey?

Morrow: To survive a hospital, you’re going to need a care advocate other than yourself. I’m assertive by nature. But if I didn’t have my wife, and on occasion my mother or my daughter with me, I would probably not have survived. It took all of us to figure out how the place actually functioned, and how to actually get certain things done.

The nursing staff and orderlies do a good job of taking care of most things, but if you’re not assertive, you’re going to find yourself at the low end of the chain. Someone must make sure you’re not falling through the cracks.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


View Details

From Kickstarter to Wikipedia, crowdsourcing has become a part of everyday life.

Sharing intel for a greater good Now one distinctive type of crowdsourcing — ethical hacking – is positioned to become a much more impactful component of securing modern … (more…)

View Details

San Francisco, Calif. —Traceable AI, the industry’s leading API security company, today released its comprehensive research report – the 2023 State of API Security: A Global Study on the Reality of API Risk.

Despite APIs being critical to the … (more…)

View Details

In an era of global economic uncertainty, fraud levels tend to surge, bringing to light the critical issue of intellectual property (IP) theft.

Related: Neutralizing insider threats

This pervasive problem extends beyond traditional notions of fraud, encompassing both insider threats and external risks arising from partnerships, competitors, and poor IP management. Organizations dedicate substantial resources to detecting and preventing fraudulent activity in customer accounts.

Yet, the rise of internal fraud presents a unique challenge. Perpetrated by insiders who already possess unrestricted access to highly sensitive data and systems, internal fraud not only defies easy prevention but also imposes substantial costs.

Annually, American businesses suffer losses exceeding $50 billion, underscoring the impact on competitiveness in today’s fiercely competitive landscape. To navigate this complex landscape, business leaders must strike a delicate balance between fostering open research environments and securing their valuable IP, safeguarding both their business and innovative endeavors.

Remote work factor

The growing trend of remote or hybrid working has particularly intensified the issue, enabling trusted insiders to mask fraudulent activity by operating outside the conventional security perimeter. And while many instances of this type of fraudulent activity may start out as an accidental mistake, the longer the fraudster goes unnoticed, the greater the risk of an easy payout snowballing into more malicious actions becomes.

In some cases, insiders with malintent attempt to circumvent internal processes and policies by stealing innovation through a variety of methods, including gathering human intelligence from other employees and contractors, conducting digital and even physical surveillance operations, among other strategies.

Frogley

Some insiders may borrow tactics from more traditional state sponsored intelligence organizations such as confidential information collection through practices like “ratting” — where cybercriminals utilize malware to access sensitive information. Another example of on-the-ground tactics includes Intelligence agencies exploiting graduate students at research universities to access sensitive materials and coercing professionals working on sensitive technologies to engage in activities like IP theft.

Organizations must prioritize data and decision intelligence to tackle these threats effectively. However, fragmented and siloed data pose a significant hurdle for businesses in mitigating these risks, hindering their comprehensive understanding of the risk landscape. The combination of mounting pressures, accelerated decision-making, and the rapid availability and volume of data has intensified the difficulty of maintaining an efficient and resilient IP protection environment.

Role of AI

One technology businesses are looking to detect and prevent fraud, waste, and abuse is Decision Intelligence (DI), which allows companies to connect data and identify patterns or anomalies that potentially indicate the kind of behavior that may probe an investigation. By leveraging advanced analytics and AI, it offers enhanced scrutiny of individuals and organizations, monitoring their vulnerability to risks from sanctioned or risky entities that jeopardize intellectual property.

To accomplish this, the broader Decision Intelligence strategy should encompass the integration of techniques like graph analytics and entity resolution.

Organizations have access to ample data; the key lies in adopting suitable technology to extract its value. Gartner predicts that by 2026, organizations that prioritize AI transparency, trust, and security will witness a 50% boost in adoption, business goals, and user acceptance of their models. This emphasizes the transformative potential of Decision Intelligence (DI) for organizations that aim to be prepared for disruptions and resilient in the face of challenges. One example of where this impact can come from is entity resolution.

Entity resolution, powered by advanced AI and machine learning models, efficiently connects, organizes, and analyzes data to accurately identify similar entities. It groups related records, establishing a collection of characteristics and labeled connections for each entity. Unlike traditional record-to-record matching in MDM systems, entity resolution enables organizations to introduce new entity nodes that play a crucial role in linking real-world data.

Reusable resource

With a strong data foundation, businesses can leverage a dependable and reusable resource to automate and enhance decision-making organization-wide, addressing diverse challenges beyond IP theft detection.

A strong data management strategy is vital for companies to monitor illicit and unlawful activities, safeguard intellectual property, and stay competitive. It is crucial to have visibility into networks across different environments, whether it’s an advanced persistent threat, cyber threat, or supply chain issue. The key lies in connecting data to gain a comprehensive understanding and effectively address complex challenges.

Tackling IP theft is an ongoing and intricate challenge that necessitates sustained cooperation between businesses leaders, workers and stakeholders. Ultimately, to drive global technology innovation, businesses must turn to Decision Intelligence to reduce manual work and make quick, well-informed decisions to protect their intellectual property.

About the essayist: Clark Frogley is Head of Financial Crime Solutions at Quantexa. He began his career with the FBI investigating organized and financial crime and served as the Assistant Legal Attaché in the US Embassy in Japan. Previously, Frogley worked as an executive at IBM in positions as the global head of AML and Counter Fraud Services in Banking, the Financial Crime Practice Leader for IBM in Japan, and the Financial Crime Solution leader for AML, Sanctions and KYC.

View Details

Over time, Bitcoin has become the most widely used cryptocurrency in the world. Strong security measures become increasingly important as more people use this digital currency.

Related: Currency exchange security issues

For managing and keeping your Bitcoin assets, you must need a bitcoin wallet, which is a digital version of a conventional wallet. The protection of your priceless digital assets will be guaranteed by this article’s discussion of the best techniques for protecting your Bitcoin wallet.Bu

A Bitcoin wallet is a piece of software that enables users to transmit, receive, and store bitcoins securely. While it performs similarly to a regular wallet, it stores digital assets in the form of cryptographic keys rather than actual cash or credit cards. These wallets are available in a variety of formats, including hardware wallets, online wallets, mobile wallets, and desktop wallets. Users can select depending on their unique needs since each type offers a varied ratio of ease to security.

Select a reliable wallet. The first step to protecting your digital assets is choosing a trustworthy Bitcoin wallet. It’s critical to select wallets with a solid track record and reputation in the bitcoin industry. Consider things like security features, user-friendliness, and community reviews when you compare various wallet solutions.

Use strong passwords, 2FA. The security of your Bitcoin wallet is mostly dependent on the strength of your passwords. Use uppercase, lowercase, digits, special characters, and a combination of them to create strong, one-of-a-kind passwords. Keep your name and birthday away from utilizing information that might be easily guessed. Also, whenever it is possible, activate two-factor authentication (2FA). By requiring a verification code in addition to your password, 2FA adds an extra layer of protection and drastically reduces the possibility of illegal access to your wallet.

Update frequently. Bitcoin wallet providers are always making software improvements to address possible security flaws. It’s critical to maintain your wallet software updated in order to stay one step ahead of criminal actors. Patches for security holes are frequently included in wallet upgrades, ensuring that your wallet is protected against new threats. To keep secure, set up automatic updates whenever feasible or often check for new software versions.

Backup, backup, backup. To guard against data loss, it’s crucial to regularly create backups of your Bitcoin wallet. Wallet backups provide a safety net in the event that your device breaks down, is misplaced, or is stolen. Backups should be kept safely in several places, such as encrypted cloud storage or external hard drives. Test the restoration procedure as well to make sure your backups are operational and available when needed.

Secure your network, device. It’s critical to protect the device you use to access your Bitcoin wallet. To avoid potential vulnerabilities, keep your operating system, antivirus software, and other security tools up to date. Refrain from installing illegal or dubious software, and only download wallets from reliable sources. Be careful while connecting to public Wi-Fi networks as well, as they may not be safe. A virtual private network (VPN) can offer an additional layer of encryption and security.

Use multisignature wallets. Multisig wallets, sometimes referred to as multi sigs, provide better protection for your Bitcoin holdings. Transactions in this kind of wallet must have approval from numerous cryptographic signatures, lowering the possibility of unwanted access. You may share keys across several devices or people using multisig wallets, adding an extra layer of security against key loss or theft.

Ashford

Be wary of fraud. As the use of Bitcoin has grown, so have the number of phishing and malware attempts that prey on naïve users. Use caution while downloading files or clicking on websites connected to your Bitcoin wallet. Be wary of dubious emails, texts, or websites that ask for your wallet credentials in an effort to deceive you. Before acting, make sure the source is legitimate to avoid falling for con artists.

In conclusion, protecting your digital assets in an increasingly linked world requires you to secure your Bitcoin wallet. You can greatly improve the security of your Bitcoin holdings by adhering to these best practices, such as choosing a trustworthy wallet, implementing strong passwords and 2FA, regularly updating your software, backing up your wallet, securing your device and network, using multi signature wallets, and being watchful against phishing and malware attacks.

It’s crucial to keep up with the most recent security procedures in the constantly changing field of cybersecurity and to adjust as necessary. You may have peace of mind and confidently traverse the world of cryptocurrencies while securing your priceless digital assets by prioritizing the security of your Bitcoin wallet, periodically educating yourself on emerging dangers, and adhering to suggestions from reliable sources.

About the essayist: Ronin Ashford is a passionate tech enthusiast and a dedicated cryptocurrency investor. With a firm belief in the potential of blockchain technology, he is determined to contribute to the transformation of the payments industry landscape.

View Details

Tel Aviv, Israel, Sept. 5, 2023 — Reflectiz, a cybersecurity company specializing in continuous web threat management offers an exclusive, fully remote solution to battle Magecart web-skimming attacks, a popular type of cyberattacks involving injecting malicious code into the checkout pages.

As the Holiday Season approaches, online retailers face the challenge of protecting their websites against the growing threat of malicious attacks, such as Magecart. However, they struggle to add new security layers due to restrictions on modifying their website code to avoid impacting website performance during the peak shopping season.

Reflectiz, a unique web security tool, ensures 100% readiness for Magecart attacks before and during the Holiday Season. This is made possible by Reflectiz’s external, non-intrusive solution, requiring no code implementation or IT resources. Your website(s) will be fully protected within days, and there will be no impact on your website performance whatsoever.

Reflectiz automatically detects third-party code changes, keylogging, and communication with malicious domains to prevent Magecart web-skimming attacks. It overcomes the most sophisticated malware obfuscation techniques, lets you track changes, prioritize issues, and implement alerts according to their severity level, empowering you to act before the damage is done.

Despite being so powerful, Reflectiz does not affect website performance. It has zero impact on your IT resources, and it does not require any installation on the client. It begins protecting your web assets within days, ensuring continuous monitoring of all crucial and sensitive web pages, not just checkout pages.

“Reflectiz understands the challenges faced by online retailers during this busy time of the year. In fact, in 2023, Reflectiz detected Magecart attacks on more than 150 websites, and the count is still rising. Our advanced technology enables the automatic detection of sophisticated threats throughout your entire online environment, all with quick and easy external implementation. You will be up and running within days” – Ysrael Gurt, Co-founder & CTO, Reflectiz

Sign up for our exclusive offer today, and get the ideal head start in the war on Magecart.

Media contact: Marketing Director, Daniel Sharabi, Reflectiz, daniel.s@reflectiz.co

View Details

New government rules coupled with industry standards meant to give formal shape to the Internet of Things (IoT) are rapidly quickening around the globe.

Related: The need for supply chain security

This is to be expected. After all, government mandates combined with industry standards are the twin towers of public safety. Without them the integrity of our food supplies, the efficacy of our transportation systems and reliability of our utilities would not be what they are.

When it comes to IoT, we must arrive at specific rules of the road if we are to tap into the full potential of smart cities, autonomous transportation and advanced healthcare.

In the absence of robust, universally implemented rules of the road, cybercriminals will continue to have the upper hand and wreak even more havoc than they now do. Threat actors all-too-readily compromise, disrupt and maliciously manipulate the comparatively simple IoT systems we havein operation today.

I had an eye-opening conversation about all of this with Steve Hanna, distinguished engineer at Infineon Technologies, a global semiconductor manufacturer based in Neubiberg, Germany. We went over how governments around the world are stepping up their efforts to impose IoT security legislation and regulations designed to keep users safe.

This is happening at the same time as tech industry consortiums are hashing out standards to universally embed security deep inside next-gen IoT systems, down to the chip level. There’s a lot going on behind the scenes. For a full drill down on my discussion with Hanna, please view the accompanying videocast. Here are a few takeaways:

Minimum requirements

A few years back, a spate of seminal IoT hacks grabbed the full attention of governments worldwide. The Mirai botnet, initially discovered in October 2016, infected Internet-connected routers, cameras and digital video recorders at scale. Mirai then carried out a massive distributed denial-of-service (DDoS) attacks that knocked down Twitter, Netflix, PayPal and other major web properties.

Then in 2017, clever attackers managed to compromise a smart thermometer in a fish tank, thereby gaining access to the high-roller database of a North American casino. Soon thereafter, white hat researchers discovered and disclosed pervasive vulnerabilities in hundreds of millions of smart home devices such as cameras, thermostats and door locks.

In 2018, UK regulators got the regulatory ball rolling taking steps that would eventually result in mandated minimum requirements for IoT data storage, communications and firmware update capabilities. The U.S., other European nations and Singapore soon began moving in this direction, as well. The U.S. National Institute of Standards and Technology (NIST,) for instance, has since developed a comprehensive set of recommended IoT security best practices.

In 2023, the U.S. announced a cybersecurity certification and labeling program to help Americans more easily choose smart devices that are safer and less vulnerable to cyberattacks. The new “U.S. Cyber Trust Mark” program raises the bar for cybersecurity across common devices, including smart refrigerators, smart microwaves, smart televisions, smart climate control systems, smart fitness trackers, and more.

Guest expert: Steve Hanna, Distinguished Engineer, Infineon Technologies

“We’re moving to a world where IoT cybersecurity will be table stakes” Hanna told me. “It’s going to be required in every IoT product and governments will have their own checklist of IoT requirements, similar to what we have for electrical equipment.”

Harmonizing the baseline

The efforts by regulators and technologists to establish a baseline for IoT safety has, as might’ve been expected, given rise to conflicts and redundancies. “At the moment, we have a Tower of Babel situation where each nation has its own set of requirements and it’s a big challenge for a manufacturer how they get their product certified in multiple places,” Hanna says.

Harmonizing of different requirements across multiple nations needs to happen, Hanna argues, and this quest is made even more challenging because of the sprawling array of IoT device types. This is, in fact, precisely what a tech industry consortium, calling itself, the Connectivity Standards Alliance, has set out to tackle head on, he says.

“Basically, we’re creating, shall we say, one certification to rule them all,” Hanna told me. “We’re going to bring together all the requirements from these national and regional certifications and say if you get this one certification from CSA, then that indicates you’re compliant with all of the national or regional requirements, no matter where they might come from. And your product can then be sold in all of those different regions.”

The technologists are striving to resolve a profound pain point, in particular, for IoT device makers facing the prospect of needing to test and certify their IoT products in 50 different locales. “If I can test it once against a set of requirements that I understand, then that’s much less expensive,” Hanna says.

Safety labels

The give-and-take vetting of emerging standards that’s now unfolding reflects a tried-and-true dynamic; it’s how we arrived at having detailed food additive labels we can trust on every item on supermarket shelves and it’s why we can be sure no electrical appliance in our homes poses an egregious hazard.

The ramping up of IoT rulemaking and standards-building portends a day when we won’t have to worry as much as we now do about directly encountering badness on the Internet.

I asked Hanna about what individual citizens and small business owners can do, and he indicated that staying generally informed should be enough. He noted that the regulators and tech industry leaders are cognizant of the need to foster consumer awareness about the incremental steps forward. The push behind the new Matter home automation connectivity standard introduced in late 2022 being a case in point.

“We can’t expect the consumer to be an expert on IoT cybersecurity, that’s just not realistic,” he says. “What we can ask them to do is to look for these security labels coming soon to IoT products . . . you just can’t buy an unsafe extension cord anywhere today; only the ones with the proper safety inspections get sold. I hope the same will be true in five or 10 years for IoT products, that all of them are adequately secure and they all have that label.”

This is all part of a maturation process that must happen for digital systems to rise to the next level. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

San Francisco, Calif., Aug. 30, 2023 Every year over 340m workers suffer a workplace injury: slips and falls, strains and sprains, vehicle collisions and crashes. Voxel, an AI startup using computer vision to transform safety and operations in the workplace, is today announcing a $12m strategic funding round to improve workplace safety and save lives.

The strategic funding round was led by global manufacturing industry leader Rite-Hite with participation from existing investors Eclipse Ventures and World Innovation Lab. This takes total funds raised to $30m since 2020.

In the US, manufacturing, logistics, and physical operations are the lifeblood of the economy, with over 25 million individuals at the frontlines, contributing to 40% of the nation’s GDP. However, with massive output comes the persistent challenge of workplace injuries and operational inefficiencies. Now, artificial intelligence is revolutionizing the field of environment, health and safety (EHS) in industrial operations.

Voxel integrates state-of-the-art computer vision technology into existing security cameras to identify hazards, risky behaviors, and operational inefficiencies across a diverse range of workplaces. Once potential risks, such as near-miss vehicle collisions, blocked exits, improper ergonomics,or spills, are identified, a real-time alert is sent to on-site personnel who can take immediate action, and Voxel’s analytics help sites identify operational inefficiencies and design policies to prevent future issues. These proactive measures allow businesses to significantly reduce worker’s compensation and general liability costs, while improving their operations.

In order to protect workers’ privacy, Voxel’s AI ethics policy means that no facial recognition or identification of individuals is permitted in their systems. Voxel provides its customers with resources for ethically and responsibly implementing AI in the workplace crafted after years of experience developing AI for America’s industrial leaders.

Senemar

Voxel has had a transformative impact for their strategic partners’ operations, reporting up to an 80% reduction in workplace injuries and substantially improving operational efficiency. Fortune 500 firms like Michael’s, Dollar Tree, Clorox, PPG Industries, Office Depot, and many others are already seeing the benefits of Voxel’s platform.

Alex Senemar, CEO and co-founder of Voxel commented: “AI is saving lives. We’ve proven that our technology has made great strides toward reducing injuries and saving lives. Our approach is going to create worksites where employers don’t have to bargain between meeting safety standards and meeting their productivity goals. The future of work is not just about doing more, but doing it safer in an environment fit for purpose”.

Voxel business highlights since series A funding round, April 2022:

•The team has grown from 10 people to over 50 employees, who have joined from established industry firms Samsara and Verkada to big tech Google, Apple, and Uber.

•Featured in the Fast Company magazine Most Innovative Companies list.

•Best B2B Tech Tool of 2023 by Products That Count.

Voxel’s team is led by CEO Alex Senemar, who previously co-founded Sherbit, an AI-powered remote health monitoring system for hospitals (acquired in 2018) as well as co-founders, CTO Anurag Kanungo, who co-founded Sherbit with Senemar, and led the Machine Learning Systems Team at Uber’s Self Driving Unit; Harishma Dayanidhi, who developed self-driving car technology at Uber and Aurora; and Troy Carlson, former software engineer at Google.

About Voxel: Voxel uses artificial intelligence to enable security cameras to automatically identify potential workplace hazards, high-risk activities, and operational inefficiencies, allowing on-site personnel to address concerns in real-time. The platform keeps workers safe, while helping companies significantly reduce overhead costs from general liability, worker’s compensation, and property claims. ??Voxel software is transforming operations in warehousing, manufacturing, retail, transportation, construction, and oil & gas. A demo is available upon request. For more information, visit https://www.voxelai.com/ or follow via LinkedIn and X.

About Rite-Hite: Rite-Hite is a world leader in the manufacture, sale, and service of loading dock equipment, industrial doors, safety barriers, HVLS fans, industrial curtain walls, and more – all designed to improve safety, security, productivity, energy savings, and environmental control. Watch Rite-Hite’s Always Looking Ahead video to learn more.

About Eclipse Ventures: With over $2 billion in assets under management, 70 portfolio companies, and a team of investors with deep expertise in technology, manufacturing, supply chain, logistics, healthcare, and consumer products, Eclipse is one of the US’ leading venture capital organizations. Its leadership team has the experience necessary to create and scale complex operations – with partners coming from industry giants, such as Flextronics, Tesla, Apple, Samsara, Intel, and GE. Eclipse partners with entrepreneurs boldly transforming the essential industries that define and propel economies. For more information, visit www.eclipse.vc.

Media contact: Bilal Mahmood, Stockwood Strategy. Mob: +44 (0) 771 400 7257

View Details

Hannover, Germany, Aug. 31, 2023 Hornetsecurity has recently launched The Security Swarm podcast series to shed light on the latest cybersecurity issues.

The weekly show, hosted by Hornetsecurity’s Andy Syrewicze, brings together experts from across the cybersecurity sector to discuss industry challenges, how businesses can overcome ever-changing threats, and future cybersecurity issues.

The informative and educational series has already looked at topics such as AI and whether ChatGPT could conduct a cyberattack, discussions around Hornetsecurity’s recent compliance survey, as well as a conversation with Microsoft Certified Trainer on how secure Microsoft 365 actually is.

Hofmann

Hornetsecurity CEO Daniel Hofmann said: “The Security Swarm podcast launch has been incredibly successful and delivers insightful conversations about the biggest cybersecurity challenges facing businesses today. This podcast is one of many new approaches we have introduced to support and educate cybersecurity decision-makers across the world.”

The world of cybersecurity should not be taken on alone. A glimpse into the podcast series is available in this trailer.

The podcast can be listened to via the Hornetsecurity website and is also available to download on Apple Podcasts, Google Podcasts, Spotify, and YouTube.

About Hornetsecurity: Hornetsecurity is a leading global provider of next-generation cloud-based security, compliance, backup, and security awareness solutions that help companies and organisations of all sizes around the world. Its flagship product, 365 Total Protection, is the most comprehensive cloud security solution for Microsoft 365 on the market. Driven by innovation and cybersecurity excellence, Hornetsecurity is building a safer digital future and sustainable security cultures with its award-winning portfolio. Hornetsecurity operates in more than 30 countries through its international distribution network of 8,000+ channel partners and MSPs. Its premium services are used by more than 50,000 customers.

For more information, visit www.hornetsecurity.com.

Media contact:* Please contact us on press@hornetsecurity.com. Angelica Micallef Trigona,* Director of Corporate Communications, Hornetsecurity Group – www.hornetsecurity.com

View Details

For a couple of decades now, the web browser has endured in workplace settings as the primary employee-to-Internet interface. It’s really just assumed to be a given that a browser built for consumers is an acceptable application for employees to use to work.

And despite advances, like sandboxing, browser isolation and secure gateways, the core architecture of web browsers has remained all-too vulnerable to malicious attacks.

There was a lot of buzz at Black Hat USA 2023 about advanced “enterprise browsers.” I visited with Uy Huynh, vice president of solutions engineering at Island.io, to discuss this. For a full drill down please give the accompanying podcast a listen.

Built on the Chromium open source code, Island’s Enterprise Browser recognizes the identity and considers the role of each user—be it an employee, contractor, or HR personnel. This granular visibility aids in rapid onboarding while also bolstering security protocols, Huynh explained.

This can serve as a “last mile” checkpoint to curtail Shadow IT; in particular, the exploding popularity of generative AI.

Guest expert: Uy Huynh, VP of solutions engineering, Island.io

Island’s solution prevents sensitive data from slipping out from a web browser into services like ChatGPT, or through downloads, screen shots, printing or copy/paste.

“With generative AI, you could inadvertently be placing your intellectual property or other sensitive information into large language models that anyone can access,” Huynh warns.

Meanwhile, a specific alert can be communicated to the user, enhancing awareness training, and reinforcing compliance.

“In essence, what we’re trying to do is to offer enterprises granular control over their browser environment,” Huynh says.

Anything that can improve security while preserving a high-quality user experience has a place in networks, going forward. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

The threat of bad actors hacking into airplane systems mid-flight has become a major concern for airlines and operators worldwide.

Related: Pushing the fly-by-wire envelope

This is especially true because systems are more interconnected and use more complex commercial software … (more…)

View Details

API security has arisen as a cornerstone of securing massively interconnected cloud applications.

At Black Hat USA 2023, I had a great discussion about API security with Data Theorem COO Doug Dooley and Applovin CISO Jeremiah Kung. For a … (more…)

View Details

Boston, Mass, Aug. 22, 2023 – airSlate, a leader in document workflow automation solutions, today announced the launch of QuickStart in collaboration with partner Forthright Technology Providers, a leading provider of user-centric IT solutions and services. The comprehensive … (more…)

View Details

Phone number spoofing involves manipulating caller ID displays to mimic legitimate phone numbers, giving scammers a deceptive veil of authenticity.

Related: The rise of ‘SMS toll fraud’

The Bank of America scam serves as a prime example of how criminals … (more…)

View Details

Tel Aviv,  Israel, Aug. 17, 2023 — Cynomi, the leading AI-powered virtual Chief Information Security Officer (vCISO) platform vendor for Managed Service Providers (MSPs), Managed Security Service Providers (MSSPs) and consulting firms, has published the results of its first … (more…)

View Details

Social media giants have long held too much power over our digital identities.

Related: Google, Facebook promote third-party snooping

Today, no one is immune to these giants’ vicious cycle of collecting personal data, selling it to advertisers, and manipulating users … (more…)

View Details

LAS VEGAS – Just when we appeared to be on the verge of materially shrinking the attack surface, along comes an unpredictable, potentially explosive wild card: generative AI.

Related: Can ‘CNAPP’ do it all?

Unsurprisingly, generative AI was in the … (more…)

View Details

Lehi, Utah, Aug. 8, 2023 – DigiCert today announced the expansion of its certificate management platform, DigiCert Trust Lifecycle Manager, to provide full lifecycle support for multiple CAs including Microsoft CA and AWS Private CA, as well as integration with … (more…)

View Details

Palo Alto, Calif., Aug. 8, 2023 SandboxAQ today announced Sandwich, an open source framework and meta-library of cryptographic algorithms that simplifies modern cryptography management.

With an intuitive, unified API, Sandwich empowers developers to embed the cryptographic algorithms of their … (more…)

View Details

LAS VEGAS — Shadow IT and BYOD security exposures have long bedeviled businesses – ever since the iPhone and Dropbox first came on the scene.

Covid 19 only intensified the problem of how to securely manage the personally owned devices … (more…)

View Details

We all get spam emails, and while it’s annoying, it’s not usually anything to worry about. However, getting a huge influx of spam at once is a warning sign. People suddenly getting a lot of spam emails may be the … (more…)

View Details

LAS VEGAS — Penetration testing, traditionally, gave businesses a nice, pretty picture of their network security posture — at a given point in time.

Related: Going on the security offensive

Such snapshots proved useful for building audit trails, particularly for … (more…)

View Details

LAS VEGAS — One fundamental reason some 7,000 or so IT pros are making the trek here this week is that no one ever wants to get caught in the crossfire of a devastating data breach.

Related: A call to … (more…)

View Details

The rise of the remote workforce, post Covid-19, did nothing to make the already difficult task of doing Identity and Access Management (IAM) any easier for CISOs.

With Black Hat USA 2023 ramping up in Las Vegas next … (more…)

View Details

San Francisco and Cork, Ireland, Aug. 3, 2023 — Vaultree, a cybersecurity leader pioneering Fully Functional Data-In-Use Encryption (FFDUE), today announces a strategic integration with Tableau, a renowned platform for data visualization and business intelligence.

This marks a monumental leap … (more…)

View Details

San Francisco, Calif., Aug. 2, 2023 – Normalyze, a pioneer in cloud data security, today introduced new capabilities to protect data across hybrid cloud deployments and on-premises environments.  With an extensive platform that already offers comprehensive data security posture … (more…)

View Details

Cambridge, Mass. – Aug. 1, 2023 –Devo Technology, the cloud-native security analytics company, today announced its financial support for Cybermindz, a not-for-profit organization dedicated to improving the mental health and well-being of cybersecurity professionals. Founded in Australia just … (more…)

View Details

Tel Aviv, Israel, Aug. 1, 2023– Guardz, the cybersecurity company securing and insuring SMEs, today disclosed the existence of a Hidden Virtual Network Computing (hVNC) malware targeting macOS devices. The malware, which is available on the major Russian … (more…)

View Details

New York, NY, Aug. 1, 2023– AppViewX, a leader in automated machine identity management (MIM) and application infrastructure security, today announced the results of a research study conducted by Enterprise Management Associates (EMA) on SSL/TLS Certificate Security. The survey … (more…)

View Details

Miami, Fla., Aug 1, 2023  –? Lumu, the creators of the Continuous Compromise Assessment cybersecurity model that empowers organizations to measure compromise in real time, will debut Lumu for Threat Hunting at the Black Hat USA 2023.

Lumu for … (more…)

View Details

San Jose, Calif. – Aug.1, 2023 – Nile the leader in next-generation enterprise networks, today announced a $175 million Series C investment round co-led by March Capital and Sanabil Investments, with strategic participation from solutions by stc, Prosperity7, and Liberty … (more…)

View Details

Computer chips have been part of cars for a long time, but no one really cares about them until they stop working or they are late to the production line.

Related: Rasing the bar of cyber safety for autos

However, … (more…)

View Details

New York, NY, July 27, 2023  QBE North America today announced the launch of a cyber insurance program with new MGA, Converge, acting as program administrator.

The program will be broken down into two separate distribution structures, each with … (more…)

View Details

Tel Aviv, Israel, July 27, 2023 — Perception Point, a leading provider of advanced threat prevention across digital communication channels, today published a new report analyzing global cyberattack trends in H1 2023 amidst the paradigm shift brought about by … (more…)

View Details

Paris, France, July 27, 2023 – CrowdSec, the pioneering open source and collaborative cybersecurity company, today released its Q2 2023 Majority Report, a comprehensive community-driven data report fueled by the collective efforts of its thousands of users.

Key … (more…)

View Details

Seattle, Wash., July 26, 2023 — Protect AI, the artificial intelligence (AI) and machine learning (ML) security company, today announced it has closed a $35M Series A round of funding.

The round was led by Evolution Equity Partners with … (more…)

View Details

Accessing vital information to complete day-to-day tasks at our jobs still requires using a password-based system at most companies.

Related: Satya Nadella calls for facial recognition regulations

Historically, this relationship has been effective from both the user experience and host … (more…)

View Details

Deepening interoperability of AI-infused systems – in our buildings, transportation grids, communications systems and medical equipment — portend amazing breakthroughs for humankind.

Related: The coming of optical infrastructure

But first businesses must come to grips with the quickening convergence of … (more…)

View Details

Gainesville, Fla., July 18, 2022 – Around 30,000 websites get hacked every day, with the majority of those cyberattacks due to human error. This has projected costs associated with cybercrimes to hit the tens of trillions by 2025, highlighting … (more…)

View Details

A fledgling security category referred to as Cloud-Native Application Protection Platforms (CNAPP) is starting to reshape the cybersecurity landscape.

Related: Computing workloads return on-prem

CNAPP solutions assemble a varied mix of security tools and best practices and focuses … (more…)

View Details

Pittsburgh, PA – July 13, 2023 – Security Journey, a best-in-class application security education company, has today announced an acceleration of its secure coding training platform enhancements.

Since combining HackEDU and Security Journey training offerings into one Platform, the company … (more…)

View Details

London, July 13, 2023 Beazley, the leading specialist insurer, today published its latest Risk & Resilience report: Spotlight on: Cyber & Technology Risks 2023.

The data shows how perceptions around cyber and technology risks, from ransomware and other … (more…)

View Details

Santa Clara, Calif. and Bangalore, India – July 13, 2023 — Large companies are typically using over 1100 SaaS applications to run their operations and the number of companies adopting this trend is rapidly growing 20% every year but this … (more…)

View Details

Toronto, Canada,  July 12, 2023 – Asigra Inc., a leader in ultra-secure backup and recovery, is tackling the pressing data protection and security challenges faced by organizations utilizing the thousands of Software as a Service (SaaS) applications on the market … (more…)

View Details

Tel Aviv, Israel– July 12, 2023 – Oxeye, the provider of an award-winning cloud-native application security platform, has uncovered two critical security vulnerabilities and recommending immediate action be taken to mitigate risk.

The vulnerabilities were discovered in Owncast (… (more…)

View Details

Boston, July 7, 2023 — CybSafe, the human risk management platform, has today announced CEO Oz Alashe MBE has been named as a SecurityInfoWatch.com,Security BusinessandSecurity Technology Executivemagazines’2023 Security Industry Innovator Award winner.CybSafe’s human-centric, … (more…)

View Details

When it comes to alternative asset trading, protecting investor data is of critical importance.

Related: Preserving the privacy of the elderly

As more traders and investors engage in these investment avenues, it is crucial to adopt robust security measures to … (more…)

View Details

To tap the full potential of massively interconnected, fully interoperable digital systems we must solve privacy and cybersecurity, to be sure.

Related: Using ‘Big Data’ to improve health and well-being

But there’s yet another towering technology mountain to climb: we … (more…)

View Details

Hsinchu, Taiwan – July 6, 2023 – Nuvoton Technology, one of the world’s leading suppliers of microcontrollers, has proudly launched its MUG51 8-bit MCU series of low power microcontrollers designed for battery-free devices.

Nuvoton is committed to sustainable 8-bit MCU … (more…)

View Details

SMS toll fraud is spiking. I learned all about the nuances of deploying – and defending – these insidious attacks in a recent visit with Arkose Labs CEO, Kevin Gosschalk, who explained how the perpetrators victimize businesses that use … (more…)

View Details

San Francisco, Calif., June 29, 2023 — NetWitness, a globally trusted provider of threat detection, investigation, and response technology and incident response services, today announced it is now integrated with AWS AppFabric, a new service from Amazon Web … (more…)

View Details

As the threat of cybercrime grows with each passing year, cybersecurity must begin utilizing artificial intelligence tools to better combat digital threats.

Related: A call to regulate facial recognition

Although AI has become a powerful weapon, there’s concern it might … (more…)

View Details

Singapore, June 26, 2023 – Hardware cybersecurity solutions pioneer Flexxon today announced the appointment of Erik Nilsen, PhD, as its Chief Technology Strategist.

An industry veteran with almost three decades of experience, Nilsen will work closely with the Company’s executive … (more…)

View Details

Mountain View, Calif. June 22, 2023 — Dasera, the premier automated data security and governance platform for top-tier finance, healthcare, and technology enterprises, is thrilled to unveil “Ski Lift,” a complimentary platform exclusively designed for Snowflake users.

With “Ski … (more…)

View Details

Eden Prairie, Minn., June 22, 2023 — Malicious emails have reached a crescendo in 2023 according to the latest report from cybersecurity software and services provider Fortra.

Email impersonation threats such as BEC currently make up nearly 99 percent … (more…)

View Details

Tel Aviv, Israel, June 23, 2023 — The industry’s first-ever directory of virtual Chief Information Security Officer service providers has gone live today at www.thevcisodirectory.com. This extensive list of virtual CISO (vCISO) providers, collated by Cynomi, means that … (more…)

View Details

Chicago, Ill., June 21, 2023 – NowSecure, the recognized experts in mobile security and privacy, announced today that it has completed its latest annual SOC 2 Type 2 security audit – the industry benchmark for independent auditing of security controls … (more…)

View Details

Atlanta, Ga. June 20, 2023 – IRONSCALES, the leading enterprise cloud email security platform protecting more than 10,000 global organizations worldwide, today announced the Beta launch of Themis Co-pilot for Microsoft Outlook, a GPT-powered chat assistant for self-service threat … (more…)

View Details

Santa Clara, Calif. – June 21, 2023 Axiad, a leading provider of organization-wide passwordless orchestration, today announced the results of its Passwordless Authentication survey fielded by Enterprise Research Group (ERG), a full-service market research company.

The purpose of … (more…)

View Details

To be productive in an interconnected work environment, employees need immediate access to numerous platforms both on- and off-premises.

Related: Why SMBs need to do PAM well

Keeping track of user activity and effecting proper on- and off-boarding is … (more…)

View Details

Tel Aviv, Israel, June 19, 2023– Radiflow, creators of the leading OT network cybersecurity platform CIARA, continue to see budgetary pressure as a main driver in prioritizing OT Cybersecurity projects. This has created opportunities for more partnerships across the … (more…)

View Details

Miami, Fla. – June 20, 2023 – ThriveDX, the leader in cybersecurity and digital skills training, today announced the official launch of its new Cyber Academy for Enterprise. This innovative solution, part of the company’s Human Factor Security suite, … (more…)

View Details

The number one cybersecurity threat vector is unauthorized access via unused, expired or otherwise compromised access credentials.

Related: The rising role of PAM for small businesses

In the interconnected work environment, where users need immediate access to many platforms on … (more…)

View Details

It was bound to happen. Clop, the Russia-based ransomware gang that executed the MOVEit-Zellis supply chain hack, has commenced making extortion demands of some big name U.S. federal agencies, in addition to global corporations.

Related: Supply-chain hack ultimatum

The nefarious … (more…)

View Details

Cambridge, Mass., June 15, 2023. The World Wide Web Consortium today announced a standardization milestone for a new browser capability that helps to streamline user authentication and enhance payment security during Web checkout. Secure Payment Confirmation (SPC) enables merchants, banks, … (more…)

View Details

Tel Aviv, Israel – June 14, 2023 – Cybersixgill, the global cyber threat intelligence data provider, announced today Cybersixgill IQ, its new generative AI, representing a significant breakthrough in cyber threat intelligence (CTI). Drawing from the company’s unmatched, deep, … (more…)

View Details

The cybersecurity community is waiting for the next shoe to drop in the wake of the audacious MOVEit-Zellis hack orchestrated by the infamous Russian hacking collective, Clop.

Related: SolarWinds-style supply chain attacks on the rise

Clop operatives went live last … (more…)

View Details

Information privacy and information security are two different things.

Related: Tapping hidden pools of security talent

Information privacy is the ability to control who (or what) can view or access information that is collected about you or your customers.

Privacy … (more…)

View Details

When Threat Intelligence Platform (TIP) and Security Orchestration, Automation and Response (SOAR) first arrived a decade or so ago, they were heralded as breakthrough advances.

Related: Equipping SOCs for the long haul

TIP and SOAR may … (more…)

View Details

Back in 2002, when I was a reporter at USA Today, I had to reach for a keychain fob to retrieve a single-use passcode to connect remotely to the paper’s publishing system.

Related: A call to regulate facial recognition… (more…)

View Details

A cloud migration backlash, of sorts, is playing out.

Related: Guidance for adding ZTNA to cloud platforms

Many companies, indeed, are shifting to cloud-hosted IT infrastructure, and beyond that, to containerization and serverless architectures.

However, a “back-migration,” as Michiel De Lepper, global enablement manager, at London-based Runecast, puts it, is also ramping up. This is because certain workloads are proving to be too costly to run in the cloud — resource-intensive AI modeling being the prime example.

I had an evocative discussion about this with De Lepper and his colleague, Markus Strauss, Runecast product leader, at RSA Conference 2023. For a full drill down, please give the accompanying podcast a listen. The duo outlined how a nascent discipline — Cloud-Native Application Protection Platforms (CNAPP) – factors in.

Guest experts: Markus Strauss, Product Leader, and Michiel De Lepper, Global Enablement Manager, Runecast

CNAPP solutions focus on monitoring and enforcing security policies on workloads and in applications – during runtime. This is no small feat in an operating environment of co-mingled on-prem and cloud-hosted resources.

Runecast, for instance, takes a proactive approach to risk-based vulnerability management, configuration management, container security, compliance auditing, remediation and reporting.

This helps with compliance, at one level, but also continually improves detection of any soft spots and/or active attacks, while also paving the road to automated remediation.

“It’s no longer about creating shields,” De Lepper told me, “Instead, we’re helping our customers plug all the gaps the bad guys can use.”

CNAPP solutions show promise for helping overcome the complexities of fragmented defenses; will they ultimately lead to more resilient business networks? I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

As the threat of cybercrime grows with each passing year, cybersecurity must begin utilizing artificial intelligence tools to better combat digital threats.

Related: Leveraging human sensors

Although AI has become a powerful weapon, there’s concern it might be too effective compared to human cybersecurity professionals — leading to layoffs and replacements.

However, the truth is that automated AI tools work best in the hands of cybersecurity professionals instead of replacing them. Rather than trying to use AI to get rid of your security team, seek to use automated tools in conjunction with your existing professionals to ensure the strongest cybersecurity defense.

Generative AI wild card

The newest breakthrough in artificial intelligence technology is machine learning and generative AI. Unlike traditional AI, machine learning can be taught to act on data sets and make accurate predictions instead of being limited to only analyzing.

Machine learning programs use highly complex algorithms to learn from data sets. In addition to analyzing data, they can use that data to observe patterns. Much like humans, they take what they have learned to “visualize” a model and take action based on it.

A program that can take data sets and act independently has enormous cybersecurity potential. Generative AI can look for patterns in code and identify the most common forms of cyberattacks. Instead of alerting a human administrator to handle the problem, the program can eliminate the threat itself.

Human touch needed

The greatest strength of machine learning is its adaptability. The more data it collects, the more it learns and the more threats it can stop. However, that doesn’t mean this tech is infallible. The capabilities of machine learning programs depend on how much data is available.

Amos

That’s why the role of cybersecurity professionals is still important. Machine learning requires human operators that teach the programs how to use relevant data. The programs also require human supervision in case it makes mistakes. Alone, machine learning is not yet strong enough to stop all determined hackers; but together, machine learning and human professionals can be a formidable force.

The benefits of machine learning programs for cybersecurity professionals are potentially enormous. Security programs that can enforce themselves to an extent instead of simply analyzing data have the potential to cut down on workloads and give professionals breathing room.

Relieving fatigue

While cybersecurity has become an essential part of everyday life, it can also be hard to keep up with all the latest trends, policies and programs. This is especially true for cybersecurity professionals — whose job is to remain vigilant for threats.

These professionals are constantly bombarded with alerts and information on possible security breaches. Some of these alerts may be false — for example, the system flagged it as a potential threat but not confirmed or it was an error.

The only way to tell if an alert is false is for the professional to check all avenues related to the threat to confirm. This process can be long and time-consuming, just to end up as a false alarm in the end.

If not addressed, cybersecurity fatigue can lead to human error. Failing to check alerts properly risks an actual threat actor breaching the system. Machine learning and AI tools can help reduce that margin of error by automating mundane tasks.

Generative AI tools can be taught the most common causes of false alarms and how to confirm them. If such an alert appears, the AI tool can check the reason by itself and report it to the administrator. This process will significantly reduce cybersecurity professionals’ workload, giving them time to address more critical issues.

While machine learning tools are potent weapons against cyber threats, they need cybersecurity professionals to wield them properly. The power of generative AI tools in the hands of security experts can defeat any cyber attack.

About the essayist: Zac Amos writes about cybersecurity and the tech industry, and he is the Features Editor at ReHack. Follow him on Twitter or LinkedIn for more articles on emerging cybersecurity trends.

View Details

The world of Identity and Access Management (IAM) is rapidly evolving.

Related: Stopping IAM threats

IAM began 25 years ago as a method to systematically grant human users access to company IT assets. Today, a “user” most often … (more…)

View Details

Cyber threats have steadily intensified each year since I began writing about privacy and cybersecurity for USA TODAY in 2004.

Related: What China’s spy balloons portend

A stark reminder of this relentless malaise: the global cyber security market is on a steady path to swell to $376 billion by 2029 up from $ 156 billion in 2022, according to Fortune Business Insights.

Collectively, enterprises spend a king’s ransom many times over on cyber defense. Yet all too many companies and individual employees till lack a full appreciation of the significant risks they, and their organizations, face online. And as a result, many still do not practice essential cyber hygiene.

Perhaps someday in the not-too-distant future that may change. Our hope lies in leveraging machine learning and automation to create very smart and accurate security platforms that can impose resilient protection.

Until we get there – and it may be a decade away — the onus will remain squarely on each organization — and especially on individual employees — to do the wise thing.

A good start would be to read Mobilizing the C-Suite: Waging War Against Cyberattacks, written by Frank Riccardi, a former privacy and compliance officer from the healthcare sector.

Riccardi engagingly chronicles how company leaders raced down the path of Internet-centric operations, and then cloud-centric operations, paying far too little attention to unintended data security consequences. Here are excerpts of my discussion with Riccardi, edited for clarity and length.

LW: Catastrophic infrastructure and supply chain breaches, not to mention spy balloons and Tik Tok exploits, have grabbed regulators’ attention. How does your main theme of tie in?

Riccardi: My book discusses how the perception of cyberattacks shifted from being mere data breaches to having real-world consequences, especially after high-profile cases in 2021, like Colonial Pipeline and Schreiber Foods.

These attacks sparked public realization that cyber threats can disrupt daily life, leading to anger against corporations, not just cybercriminals, if they failed to implement basic cybersecurity measures. My book emphasizes the heightened responsibility of C-suite leaders, considering the increased public, media, and regulator scrutiny.

LW: You come from the private sector, so you know first-hand how cybersecurity is typically viewed as a cost center and an innovation dampener. Will that have to change?

Riccardi

Riccardi: Absolutely. Cybersecurity shouldn’t be seen as a mere cost but as an existential need. Cyberattacks are increasing, and viewing cybersecurity as a cost center is a dangerous mistake. Companies can leverage cybersecurity as a business enabler and a revenue generator, like Apple and Microsoft.

It’s crucial for companies to perceive cybersecurity as a competitive advantage rather than an innovation dampener.

LW: What must SMBs and mid-market enterprises focus on?

Riccardi: SMBs face challenges when dealing with cybersecurity implications of software-enabled, cloud-based operations due to financial and skill limitations. Cyber risks from third-party vendors further complicate the situation.

To navigate this, SMBs need to conduct an enterprise risk assessment, implement basic cybersecurity controls, train their workforce, and consider outsourcing cybersecurity to a security-as-a-service provider.

LW: You discuss password management and MFA; how big a bang for the buck is adopting best practices in these areas?

Riccardi: Basic cyber hygiene is 90 percent of what cybersecurity is all about. Sure, you need state-of-the-art cybersecurity technology like firewalls, anti-virus software, and intrusion detection systems to keep cybercriminals on the back foot.

The law of large numbers favors the bad guys. A company may have thousands of employees, but it only takes one phished employee for cybercriminals to bring the network to its knees.

Strong passwords can repel a brute force attack, but MFA is the extra layer of protection when a reused password is used in a credential stuffing attack. And when strong passwords and MFA let you down, encryption can keep sensitive data from being accessed by cybercriminals.

LW: How important is effective cybersecurity awareness training?

Riccardi: The human factor is the weakest link in cybersecurity, and that’s why cybercriminals zero in on the company’s employees to bypass cybersecurity defenses.

Companies can prevent social engineering attacks by steeping employees in cyber hygiene and warning them about the sneaky ways cybercriminals launch cyberattacks. Unfortunately, many cybersecurity training initiatives nose-dive because they are too technical for non-geek employees to understand.

Boring check-the-box training leads to poor employee engagement and a workforce asleep at the switch when cybercriminals come knocking. The way to avoid this is by taking into account the human factor when designing cybersecurity training; this means making training fun and engaging and helping employees understand their roles and responsibilities in cybersecurity.

LW: Given rising compliance, led by President Biden’s cybersecurity initiatives, where do you see things going in the next 2 to 5 years?

Riccardi: In the next 2 to 5 years, I expect strenuous efforts from the Biden administration to partner with private enterprise to beef up cybersecurity across all industries. I suspect we’ll see a carrot-and-stick approach combining incentives with regulations to cajole SMBs into adopting cyber hygiene best practices, such as MFA.

Executive accountability and liability for cyberattacks will skyrocket as ransomware progresses as a national security threat and front-page news.

SMBs are likely in a jam, as companies without the means and expertise to build a decent cybersecurity program will struggle in this regulatory environment. However, engaging a SaaS provider may be a cost-effective way for SMBs to obtain a world-class cybersecurity function that meets compliance requirements.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

View Details

The inadequacy of siloed security solutions is well-documented.

Related: Taking a security-first path

The good news is that next-gen security platforms designed to unify on-prem and cloud threat detection and remediation are, indeed, coalescing.

At RSA Conference 2023 I visited with Elias Terman, CMO, and Sudarsan Kannan, Director of Product Management, from Uptycs, a Walthan, Mass.-based supplier of “unified CNAPP and EDR ” services.

They described how Uptycs is borrowing proven methodologies from Google, Akamai, SAP and Salesforce to harness normalized telemetry that enables Uptycs to correlate threat activity — wherever it is unfolding. Please give a listen to the accompanying podcast for a full drill down.

Guest experts: Elias Terman, CMO, Sudarsan Kannan, Director of Product Management, Uptycs

Kannan described how Uptycs technology platform was inspired by Google’s dynamic traffic monitoring, Akamai’s content distribution prowess and Salesforce’s varied use cases based on a single data model, to help companies materially upgrade their security posture. The aim, he says, is to think like attackers, who certainly don’t operate in silos.

Terman offered the analogy of a “golden thread” stitching together varied threat activities and serving as a cloud security early warning system. The entire value chain is thereby protected, Kannan added, from the developers writing the code to automated connections to critical cloud workloads.

Terman detailed how Uptycs’ platform, indeed, touches everything within the modern attack surface and, in doing so, breaks down legacy silos and facilitates better security outcomes.

This is part and parcel of the helpful dialogue that will carry us forward. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Zero trust networking architecture (ZTNA) is a way of solving security challenges in a cloud-first world.

Related: The CMMC sea change

NIST SP 800-207A (SP 207A), the next installment of Zero Trust guidance from the National Institute of Standards and Technology (NIST), has been released for public review.

This special publication was written for security architects and infrastructure designers; it provides useful guidance when designing ZTNA for cloud-native application platforms, especially those in enterprises where applications are hosted in multi-cluster and multi-cloud deployments.

I co-authored SP 207A, and it’s a great blueprint for any organization working to implement a ZTNA, whether they’re working with the U.S. federal government or not.

The 4th Annual Multi-Cloud Conference and Workshop on ZTNA is an upcoming event for anyone interested in how the federal government is advancing standards in ZTNA. The event—May 24-25; in-person and virtual—is hosted by NIST and Tetrate.

Attendees will include cybersecurity professionals, policy makers, entrepreneurs and infrastructure engineers. Registration is free and open to the public.

Useful publications

We’ve collaborated with NIST over the past four years to produce security standards in this space, resulting in several useful publications anyone can access:

•(SP 800-204A) Building Secure Microservices-based Applications Using Service-Mesh Architecture,

•(SP 800-204B) Attribute-based Access Control for Microservices-based Applications using a Service Mesh,

•(SP 800-204C) Implementation of DevSecOps for a Microservices-based Application with Service Mesh,

•(SP 800-207A) A Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Location Environments (in public review)

A 10,000-Foot View

Zero trust is an approach to cybersecurity that denies access by default, granting authenticated users, devices, and applications access only to the data, services, and systems they need to do their jobs. It’s designed around the assumption that bad actors are already in the network, so it’s focused on mitigating what an attacker inside the perimeter can do via controls you can implement at runtime.

To accomplish this, we map out five runtime checks—named Identity Based Segmentation in the paper—that are made at every hop in the network. These are a minimum you should be doing to mitigate what an attacker can do even if they’re inside your network perimeter. Let’s look at each of those five.

Encryption in transit provides eavesdropping protection and payload authenticity. We want encryption in transit so no one can read sensitive data from our network traffic. More importantly, it provides message authenticity: a bad actor cannot change the data or instructions being sent.

Authentication use cases

When two applications are communicating, we want to know what those applications are. Often, we’re going to implement this using things like SPIFFE for providing cryptographic workload identity (we also get to use that identity for mTLS, accomplishing (1) at runtime too). A service mesh, like open source Istio, is a well-known way to accomplish encryption in transit and service authentication at the same time.

It’s not enough to know, for instance, that a user’s mobile phone banking app is calling their bank’s server. We must also authorize that the action the mobile app is doing is allowed on the server. Through authorization policy, we bound what an attacker can do in space: we limit how they can pivot to continue an attack across the network

It’s similarly not enough to know that the bank app running on the mobile device is allowed to talk to the bank server. We also need to know that the user is properly logged in to the application and has proven themselves to the system (they’ve authenticated themselves).

Authorization at every step

In the same way we want to authorize the banking app to call the banking server (3), we want to ensure that the user in session has the permission to take the action they’re attempting in the app – we need to make sure each action they take through our infrastructure is authorized at each step. This further helps to bound attacks in space: not only does a bad actor need to compromise an application, they also need to steal valid end user credentials with the correct capabilities to continue to pivot their attack through the network.

Butcher

To bring it all together, a common case we see is for organizations to exchange an API key for a JWT at the front door, authenticating the user as part of the exchange. Implementing Identity Based Segmentation, you must assert that the JWT remains valid and has not been tampered with at every network hop.

You then use properties of that authenticated user principle to confirm that a user remains logged in, that the action the app is executing on the server is allowed for this user, and that this communication from app to server is allowed (and that, e.g., the app is not trying to talk to a backend or database it shouldn’t). At every single hop, we ensure :

•Communication is encrypted.

•The applications communicating are authenticated and allowed to communicate.

•The user in session has been authenticated and is allowed to execute the actions being taken.

Multi-tier policies

Importantly, in addition to these five core principles, 207A introduces the concept of Multi-Tier Policies. These are at minimum network-tier policies, like firewall and WAF, and identity-tier policies, like those you can implement with a service mesh such as Istio. By relaxing network-tier policies in exchange for adding identity-tier policies, we can maintain a same-or-better security posture while increasing organizational agility because identity-tier policies are built to be dynamic, and are easier and faster to change.

Join us on May 24 and 25 to learn how getting started with zero trust need not be a long, complex process. In fact, you can get started rather quickly, deploying real improvements quickly that deliver a measurable ROI. Given the need for security concepts that protect systems and data from attackers that are already in the network, zero trust should be something that every organization in a regulated or data-sensitive industry is taking steps toward embracing, sooner rather than later.

About the essayist: Zack Butcher is the founding engineer of Tetrate, which helps platform teams and developers safely and reliably transform their infrastructure for the modern, multi-cloud era.

View Details

Hackers can hurt your business or organization in many ways. First and foremost, cyberattacks can lead to data breaches in which sensitive information is stolen. If a cyber-criminal uses you as a way to get at your customers, suppliers, or employees, these vital business relationships can turn sour.

Related: Tapping hidden pools of security talent

Sometimes hackers can encrypt your systems, holding them hostage and asking you to pay money to regain access to them. This problem, called ransomware, explains why keeping backups is so important. Hijackers’ demands lose power when you can just recover your operations from backups.

Cyberattacks can also lead to a loss of productivity. When your team can’t do their work because they don’t have access to the systems or these are unavailable, everything gets delayed and projects fall behind.

Finally, don’t forget the bad press that results for businesses when they are hacked. This isn’t the kind of exposure you want for your brand.

Compliance

If your organization is privy to confidential data, then you’re in charge of protecting it, and the law will hold you accountable for doing so.

The penalties for failing to protect this data can be steep. Depending on the type of information businesses lost and how they tried to protect it, they can be fined up to five percent of their revenue.

Sugar

If the hacked businesses can show they’ve been trying to protect data by investing in security, then fines become less likely. Keep remediation costs in mind. If your organization has wrongfully released information, then you may have to pay for credit protection for people whose private information was compromised.

Best practices

Just two easy technology fixes can help protect against a lot of cyberattacks: multi-factor authentication and deep e-mail scanning, in which incoming emails are automatically screened to avoid phishing and problems. Toward that end, products like Microsoft Defender for Office can help.After that, businesses and organizations should monitor and manage how employees can access sensitive data. Limit availability as much as possible, ensuring people can only see it on a need-to-know basis.

This information should also only be accessible from trusted areas or from areas that relevant staff should be in. Set up rules that employees can only use this information from whatever country you’re doing business in. When staff members travel, keep in mind the minimum travel time. If someone asks for information in Toronto and then again in Texas only an hour later, a security alert should go off, and their access should be blocked. It’s not possible to fly across North America that fast.

As a general rule, all organizations should have a secure operation center as well as a security incident management tool that’s either run internally 24 hours a day, seven days a week, or outsourced to a partner who provides managed-security services. If your business hasn’t been investing a lot in cybersecurity, then the top practice you should implement is tying a monitoring or detection service to a managed-security services provider.

Security awareness training

Finally, employees are arguably the most important piece, so everyone at your organization should be thoroughly trained on best practices to protect data on an ongoing basis.

In particular, workers need to judge accurately whether or not to click on something, understanding that they shouldn’t trust every message that comes to them. If they have a hunch something isn’t right, they should pick up the phone to verify things or else go talk to the IT team.

Businesses and organizations should always assume someone’s trying to breach them. Smart business leaders choose to be proactive and manage the risks by staying current with cybersecurity solutions. Quite simply, investing in cybersecurity is a standard cost of doing business today.

About the essayist: Eric Sugar is president of ProServeIT, an Ontario, Canada-based vendor that supplies managed IT services, custom software development, and technology consulting services advantage to companies of all sizes in all industries.

View Details

As digital transformation accelerates, Application Programming Interfaces (APIs) have become integral to software development – especially when it comes to adding cool new functionalities to our go-to mobile apps.

Related: Collateral damage of T-Mobile hack

Yet, APIs have also exponentially increased the attack vectors available to malicious hackers – and the software community has not focused on slowing the widening of this security gap.

Mobile apps work by hooking into dozens of different APIs, and each connection presents a vector for bad actors to get their hands on “API secrets,” i.e. backend data to encryption keys, digital certificates and user credentials that enable them to gain unauthorized control.

I learned this from Ted Miracco, CEO of Approov, in a discussion we had at RSA Conference 2023. For a full drill down, please give the accompanying podcast a listen.

Guest expert: Ted Miracco, CEO, Approov

He also explains how hackers are carrying out “man in the middle” attacks during a mobile app’s runtime in ways that enable them to manipulate the communication channel between the app and the backend API.

Hackers know just how vulnerable companies are at this moment. Approov recently did a deep dive study of 650 financial services mobile apps of financial institutions across Europe and the US. The results were startling: the researchers could access API secrets in 95 percent of the apps, including “high value” secrets” in 25 percent of them.

Until API security generally gains a lot more ground, and next gen solutions achieve critical mass, the risk level will remain high. So be careful out there. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

The ransomware plague endures — and has arisen as a potent weapon in geopolitical conflicts.

Related: The Golden Age of cyber espionage

Cyber extortion remains a material threat to organizations of all sizes across all industries. Ransomware purveyors have demonstrated their capability to endlessly take advantage of a vastly expanded network attack surface – one that will only continue to expand as the shift to massively interconnected digital services accelerates.

Meanwhile, Russia has turned to weaponing ransomware in its attempt to conquer Ukraine, redoubling this threat. Now that RSA Conference 2023 has wrapped, these things seem clear: ransomware is here to stay; it is not, at this moment, being adequately mitigated; and a new approach is needed to slow, and effectively put a stop to, ransomware.

I had the chance to visit with Steve Hahn, EVP Americas, at Bullwall, which is in the vanguard of security vendors advancing ways to instantly contain threat actors who manage to slip inside an organization’s network.

Guest expert: Steve Hahn, EVP Americas, Bullwall

Bullwall has a bird’s eye view of Russia’s ongoing deployment of ransomware attacks against Ukraine, and its allies, especially the U.S.

Weaponized ransomware doubly benefits Russia: it’s lucrative, generating billions in revenue and thus adding to Putin’s war chest; and at the same time it also weakens a wide breadth of infrastructure of Putin’s adversaries across Europe and North America.

Containment is a logical tactic that could make a big difference in stopping ransomware and other types of attacks. For a full drill down, please give the accompanying podcast a listen. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Your go-to mobile apps aren’t nearly has hackproof as you might like to believe.

Related: Fallout of T-Mobile hack

Hackers of modest skill routinely bypass legacy security measures, even two-factor authentication, with techniques such as overlay attacks. And hard data shows instances of such breaches on the rise.

I had an evocative conversation about this at RSA Conference 2023 with Asaf Ashkenazi, CEO of Verimatrix, a cybersecurity company headquartered in southern France. We discussed how the Dark Web teems with hackers offering targeted mobile app attacks on major companies.

Many corporations outsource their mobile app development, and these apps often exhibit poor security practices, making them easy targets for cybercriminals, he says.

Verimatrix is coming at this problem with a fresh approach that has proven its efficacy in Hollywood where the company has long helped lock down content such as premium movies and live streamed sporting events.

Guest expert: Asaf Ashkenazi, CEO, Verimatrix

Its technology revolves around application-level protection and monitoring, which allows Verimatrix to collect data on app behavior without invading user privacy.

Coding embedded in the app provide a granular level of insight into what’s happening — when the app is actually running — and a degree of control that’s simply not doable with legacy mobile app security solutions, he told me.

For a full drill down, please give the accompanying podcast a close listen. Ashkenazi argues that we need better security solutions in general to mitigate the AI-generated threats running on our most cherished devices.

He observes that threat actors already use generative AI tools like ChatGPT, Google Bard and Microsoft Edge to innovate malware; to keep pace, companies are going to have to get much better at not just identifying, but predicting attacks, especially on mobile apps. Agreed. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Could cybersecurity someday soon be implemented as a business enabler, instead of continuing to be viewed as an onerous business expense?

Related: Security sea-change wrought by ‘CMMC’

This would fit nicely with the ‘stronger together’ theme heralded at RSA Conference 2023.

WithSecure is one cybersecurity vendor that is certainly on this path. I had a lively conversation at Moscone Center with CEO Juhani Hintikka and CTO Tim Orchard all about something they’re championing as “outcome-based security.” In sum, this refers to the notion of correlating the mix of security tools and services a company has at hand much more directly with precisely defined business targets.

“We actually need to integrate cybersecurity with the business goals of the enterprise,” Hintikka observes.

WithSecure isn’t a startup; it’s the rebranding of Helsinki-based F-Secure, which has been around since 1988 and is well-established as a leading supplier of endpoint security and threat intelligence.

Guest experts: Tim Orchard, CTO, and Juhani Hintikka, CEO, WithSecure

Hintikka and Orchard argue for a more collaborative style of security services; for a drill down on our conversation please give the accompanying podcast a close listen.

The efficacy of this approach, they told me, is proving out in the success WithSecure is having with its customers, especially mid-sized companies. “In Germany, which is famous for mid-market companies, we seamlessly integrate our MDR service on top of our customers’ legacy systems, working alongside their teams,” Hintikka told me. “It’s truly a joint effort.”

The maturation of managed security services continues. There should be plenty more to come. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Attack surface expansion translates into innumerable wide-open vectors of potential unauthorized access into company networks.

Related: The role of legacy security tools

Yet the heaviest volume of routine, daily cyber attacks continue to target a very familiar vector: web and mobile apps.

At RSA Conference 2023, I had the chance to meet with Paul Nicholson, senior director of product marketing and analyst relations at A10 Networks.

A10 has a birds eye view of the flow of maliciousness directed at web and mobile apps — via deployments of its Thunder Application Delivery Controller (ADC.)

We discussed why filtering web and mobile app traffic remains as critical as ever, even as cloud migration intensifies; for a full drill down, please give the accompanying podcast a listen.

Companies today face a huge challenge, Nicholson says. They must make ongoing assessments about IT infrastructure increasingly spread far and wide across on-premises and public cloud computing resources.

Guest expert: Paul Nicholson, senior director, product marketing & analyst relations, A10 Networks

The logical place to check first for incoming known-bad traffic remains at the gateways where application traffic arrives.

At RSAC 2023, A10 announced the addition of a next-generation web application firewall (NGWAF,) powered by Fastly, to its core Thunder ADC service. This upgrade, he told me, is expressly aimed at helping companies optimize secure performance of their hybrid cloud environments.

This is another encouraging example of stronger together advancement. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we co

View Details

In an increasingly interconnected world, the evolution of the automotive industry presents an exciting yet daunting prospect.

Related: Privacy rules for vehicles

As vehicles continue to offer modern features such as app-to-car connectivity, remote control access, and driver assistance software, a huge risk lurks in the shadows.

The physical safety of things like airbags, rearview mirrors, and brakes is well accounted for; yet cybersecurity auto safety concerns are rising to the fore.

What used to be a focus on physical safety has now shifted to cybersecurity due to the widened attack surface that connected cars present. The rapid advancements in electric vehicles (EVs) has only served to heighten these concerns.

Funso Richard, Information Security Officer at Ensemble, highlighted the gravity of these threats. He told Last Watchdog that apart from conventional attacks, such as data theft and vehicle theft, much more worrisome types of attacks are emerging. These include ransomware targeting backend servers, distributed denial of service (DDoS) attacks, destructive malware, and even weaponizing charging stations to deploy malware.

Risk of compromise

The National Highway Traffic Safety Administration defines automotive cybersecurity as the protection of automotive electronic systems, communication networks, control algorithms, software, users, and underlying data from malicious attacks, damage, unauthorized access, or manipulation. The risk of compromise is not just theoretical; there have been instances where vehicles were momentarily commandeered.

Notably, in 2016, Nissan suspended a remote telematics system in its all-electric hatchback, the Leaf, due to a vulnerability in the NissanConnect app’s server. More recently, Sultan Qasim Khan, a principal security adviser with a UK-based security firm, tricked a Tesla into thinking the driver was inside by rerouting communication between the automaker’s mobile app and the car.

Rising regulations

As the attack surface broadens, original equipment manufacturers (OEMs) find themselves in a unique position. Roy Fridman, CEO at C2A Security, emphasized the complexity of the automotive industry, citing the intricate supply chain, the exponential growth of software in modern vehicles, and the heavily regulated environment as contributing factors.

In terms of regulations, Fridman highlighted WP.29 UN R155, for which C2A Security’s David Mor Ofek helped to draft, as a key regulation that makes car manufacturers liable for the entire supply chain of their products. However, he warned against a cursory compliance just to satisfy the regulatory bodies, emphasizing the need for OEMs to truly understand and address the threats.

“These laws imply that whether in design, development, production, or post-production, car manufacturers must have full visibility into the security of their software products through a cybersecurity management system (CSMS),” Fridman says.

Richard

Richard echoed this sentiment, emphasizing the importance of secure design principles and the need for evidence of implemented cybersecurity controls from third-party suppliers. He noted the temptation for OEMs to kit up new models with the latest features without assessing their security implications, but urged manufacturers to prioritize security.

“It’s not enough that smart automakers are doing their best to secure their products, a supplier could be the weakest link,” Richard says.

Consumer trust

This increased focus on automotive cybersecurity is also reflected in the consumer market, with customers putting more emphasis on their security posture and overall risk management. Fridman suggested that this trend presents an excellent opportunity for OEMs to build trust with their customers, and he expects to see more of this development in the future.

Fridman

According to Fridman, there will be a shift from the mechanical side of car development to the software side, with the industry witnessing a proliferation of the Software Defined Vehicle (SDV). This implies an even greater potential for cyberattacks as more devices get connected and the demand for software-powered smart cars increases in an IoT-powered world.

The Automotive Cybersecurity Market Global Forecast by MarketandMarkets corroborates this, predicting a rising demand for automotive cybersecurity solutions among OEMs globally – and noting that a passenger car equipped with modern connected features already has more than 100 million lines of code.

Richard added that smart vehicles will play a significant role in smart city development and the “connected everything” concept. This means that smart cars will redefine how we understand IoT in the next few years, becoming one of the leading data generators of connected devices and internet activities.

The comments of Fridman and Richard show consensus gelling in the cybersecurity community that connected vehicle safety must jump ahead of emerging regulations.

“The EV charging grid is left estranged from any formal guidelines, despite recent security breaches, increased interest from malicious hackers, and FBI warnings,” notes Fridman, “We should all double down on this front.”

Editor’s note: Kolawole Samuel Adebayo is a Last Watchdog special correspondent based in Lagos, Nigeria.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


View Details

Email remains by far the no.1 business communications tool. Meanwhile, weaponized email continues to pose a clear and present threat to all businesses.

Related: The need for timely training

At RSA Conference 2023, I learned all about a new category of email security — referred to as integrated cloud email security (ICES) – that is helping companies more effectively keep email threats in check.

I met with Eyal Benishti, CEO of IRONSCALES, a supplier of ICES tools and cybersecurity training services. For a full drill down on our conversation, please give the accompanying podcast a close listen.

Phishing is still the main way bad actors slip into networks; and Business Email Compromise (BEC) attacks can instantly translate into crippling losses.

Guest expert: Eyal Benishti, CEO, Ironscales

Successful attacks slip past legacy security email gateways (SEGs) and even past the newer ‘cloud-native security’ controls that Microsoft and Google have embedded Microsoft 365 and Google Workspace. These filters look for known bad attachments and links.

ICES solutions vet the messages that slip through. IRONSCALES, for instance, applies natural language processing technology to identify patterns and flush out anything suspicious.

And its complementary security awareness training modules encourage employees to participate in isolating anything suspicious that leaks into their inboxes.

“The security gateways and cloud-native security controls look at content but that’s not enough,” Benishti observes. “You also need to look at context; both perspectives are needed.”

It’s clear that layers of protection, along with better-trained employees, have become table stakes. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

There is no doubt there is a constant and growing concern amongst CEO’s, and particularly CISO’s, concerning the hiring of the cybersecurity talent their organizations require to safeguard against cyberattacks.

According to Cybersecurity Ventures, by 2025 there will exist a gap of over 3.5 million unfilled cybersecurity positions. Moreover, of the current worldwide workforce, surveys conducted by PwC have shown that there is only a 38 percent ‘availability of key skills’, considering the new and more sophisticated emerging threats developed by
malicious actors.

These stats are both alarming, and pose an important question that we will try to help you figure out : Where are you supposed to find the right cybersecurity talent for your organization?

Various industries, particularly those that have been recently targeted the most by cyber attackers (such as critical infrastructure and even governmental entities) have increased their need for hiring cybersecurity talent.

And even though people are becoming increasingly aware of the immense possibilities that exists when starting a career in the field, the pace at which they are gaining the required skills and knowledge to meet the security needs of organizations is not as high as the growing demand for their assistance.

To ensure your organization hires the best cybersecurity talent currently available in the market, we have gathered a list of tips that can be helpful during this critical process:

•Leverage specialized platforms. Posting your job vacancies on any online job board will possibly limit your stakes at finding top cybersecurity talent.

Try reaching out to the best, consider specialized job boards such as Seccuri or hiring a professional recruiter, since both options already gather experience in the field and a strong network with attractive contacts.

•Look in-house. Analyze your current cybersecurity team and define interesting career paths for each of them that align with your organization’s current and future cybersecurity needs. Take it from there to start investing in your current team and focus on training!

•Make vacancies appealing. Attracting top cybersecurity talent to your organization will be a challenge if your job proposal is not strong and competitive enough.

Make sure you reach out to new talent with both interesting vacancies and career growth opportunities to ensure a higher positive response rate.

•Try non-traditional channels. Consider approaching cybersecurity talents though non-traditional channels, such as social media, cybersecurity events and forums. Use these spaces wisely to scout new prospects.

•Train prospects. Cybersecurity is a field anyone is welcome to explore, no matter their current or past careers. Enthusiasts can come from a variety of different fields, which means you should not limit yourself to finding talent potential in those who have sought careers in STEM or InfoSec.

Velasquez

Becoming a highly skilled cybersecurity professional is all about having the motivation to learn, challenging yourself to new and complex scenarios, and constantly being trained on the latest cybersecurity trends that relate to your area of interest.

In case you do consider hiring people with high potential in cybersecurity and seek to train them once they become part of your organization, problem-solving abilities, and team collaboration, as they will become essential when becoming part of your cybersecurity team.

About the essayist: Sara Velasquez Posada is part of Seccuri, the Global Cybersecurity Talent Platform, where she works as a Growth Lead helping cybersecurity professionals upscale their career paths through job opportunities and training. By focusing on closing the cybersecurity talent gap that exists worldwide, she helps companies find the professionals they require and supports the growth of the cybersecurity talent pool.

View Details

The rising complexity and prevalence of cybersecurity threats are making experts anxious.

Related: Training employees to mitigate phishing

It pressures working analysts to perform 24 hours’ worth of work in an 8-hour day. Automation could alleviate the burden on IT teams and cybersecurity professionals by shouldering some monotonous, time-consuming tasks.

An increasingly digitized world means analysts can’t rest. Nobody knows when a threat will strike, and professionals might feel they’re running on an endless hamster wheel. Experts must monitor firewalls, test business continuity plans and identify vulnerabilities with seemingly little payoff.

These feelings are a side effect of cybersecurity burnout. It can be one of the most toxic barriers in a robust cybersecurity strategy, especially if analysts can’t keep a level head in the face of prospective threats. If analysts become exhausted, pessimistic or overwhelmed trying to keep up with relentless and innovative hackers, companies and customer data could be at risk.

Automation is the key to removing most of the burnout. Analysts could delegate repetitive, mindless tasks to AI or software that could perform just as well — if not better — than humans. Every automation tool is like an added employee, strengthening SOCs and empowering individual analysts to find more valuable ways to employ their expertise or receive additional training on more complex topics.

Here are some of the jobs automation tools could execute that can optimize triage and help analysts stay focused:

•Send threat notifications to teams, management and stakeholders.

•Isolate threats in pre-programmed environments for assessment.

Amos

•Run test scenarios to prove the validity of incident response.

•Classify threat data.

•Enforce strict authentication and verification measures for server access requests.

•Notify technicians and programmers of compliance changes.

•Install software and hardware updates to minimize vulnerabilities.

•Execute data minimization protocol by backing up and deleting data as needed.

•Submit, close or escalate case tickets.

Organizations must leverage automation tools to keep system issues in a constant state of self-healing from diagnosis detection to patching. So, where and how can professionals incorporate them into an existing risk management plan?

Cybersecurity staff can incorporate automation tools into every risk management process step. For example, automated programs informed by machine learning can review historical and modern data against incoming access requests, judging their threat intensity so analysts don’t struggle with alert fatigue.

These are some of the most popular tools for automating the vast majority of cybersecurity work:

•eXtended Detection and Response: Analyzes endpoints, clouds and other silos for sneaky threat actors that hide between perimeter and internal security.

•Security Orchestration, Automation and Response: Cross-platform tech stacks that can do tasks like remediation and submitting security alerts.

•Robotic process automation: Programs that simulate rudimentary cybersecurity tasks requiring a specific outcome, such as running security scans.

•Cyber risk quantification: Collects and translates risk information into currency, informing boards and stakeholders of the threats from a monetary perspective.

•Security information and event management: Standardizes data into patterns from security protocols — like firewalls — for cohesive contextual threat analysis.

There is a need for automation to fill job demands, as threats arrive nonstop and job vacancies plague desperate enterprises. Businesses can employ all or one of these tools to kickstart their automation implementation, as each tool works best in specific scenarios.

Embracing automation will increase the resilience of teams and digital environments. It will free analysts to deepen their knowledge instead of wasting resources on lesser threats, instilling a more meaningful sense of purpose in a job otherwise tainted by burnout.

Using automation to supplement teams now will foster more proficient and optimistic analysts for the future because they’re entering the field with more tangible, beneficial tasks than tedious data management or playing hide-and-seek with threat actors.

About the essayist: Zac Amos writes about cybersecurity and the tech industry, and he is the Features Editor at ReHack. Follow him on Twitter or LinkedIn for more articles on emerging cybersecurity trends.

View Details

The theme of RSA Conference 2023 — ‘stronger together’ — was certainly well chosen.

Related: Demystifying ‘DSPM’

This was my nineteenth RSAC. I attended my first one in 2004, while covering Microsoft for USA TODAY. It certainly was terrific to see the cybersecurity industry’s premier trade event fully restored to its pre-Covid grandeur at San Francisco’s Moscone Center last week.

Rising from the din of 625 vendors, 700 speakers and 26,000 attendees came the clarion call for a new tier of overlapping, interoperable, highly automated security platforms needed to carry us forward.

Defense-in-depth remains a mantra — but implemented much differently than the defense-in- depth strategies of the first decade and a half of this century. Machine learning, automation and interoperability must take over and several new security layers must coalesce and interweave to protect the edge.

Getting a grip on identities

To keep the momentum going, business rivals and regulators are going to have to find meaningful ways to co-ordinate and cooperate at an unprecedented level. Here are four evolving themes reverberating from RSAC 2023 that struck me:

Password enabled access will endure for the foreseeable future. Multi-factor authentication (MFA) has raised the bar, but MFA alone is not enough to slow, much less stop, moderately-skilled bad actors.

New security platforms that can set cloud configurations wisely, automate detection and response and manage vulnerabilities continuously are needed to form the front line of defense.

Consolidating cloud postures

One nascent approach that shows promise: cloud native application protection platform (CNAPP.)

For a drill down on how the CNAPP space is rapidly evolving, stay tuned for my upcoming RSA Fireside Chat podcasts with a couple of vendors on the leading edge. I had enlightening discussions with Elias Terman and Sudarsan Kannan, of Uptyks, and Markus Strauss and Michiel De Lepper of Runecast.

Identities – or to put it more precisely, user access management — is a fundamental weakness that must be shored up. This is where advanced identity and access management (IAM) tools and practices comes into play.

I spoke at length with Ravi Srivatsav and Venkat Thummisi of InsideOut Defense, and separately with Venkat Raghavan, founder and CEO of Stack Identity, all about reconstituting IAM. My Fireside Chat podcasts to come will get into their insights about reducing the risk of access manipulation by continuously and comprehensively monitoring access patterns.

I also had quick meetings with Bernard Harguindeguy and Barber Amin, senior execs at Veridium ID, on the latest advances in passwordless authentication and I got the back story about a brand new smart ring (yes, of the Tolkien variety) introduced at the conference by security start-up Token. I spoke with Token CEO John Gunn and his engineering VP Evan K. about the role of advanced wearable authentication devices, going forward.

Operationalizing threat intel

Collecting and using good threat intelligence has always been important — and never been easy to do well. Two impromptu meetings I had touched on this. I spoke with Rohan Spledewinde of security start-up CTM360 – which crawls the public Internet for every and every reference to a company’s IP addresses, and uses graph database technology to present useful correlations; and I also had another very lively discussion with Snehal Antani, CEO of Horizon3 about the value of continuous, well-informed penetration testing.

Leveraging threat intelligence at the platform level, of course, remains vital, as well. The trick in today’s operating environment is how to do this well with cloud migration accelerating.

There’s a danger of leaving legacy on-premises systems twisting in the wind. And that’s why emerging frameworks like Secure Services Edge (SSE) and Zero Trust Network Access (ZTNA) got a lot of attention at RSAC 2023, and deservedly so.

In the weeks ahead, be on alert for my deep-dive podcast discussions, with vendors that are shaping the security platforms of the near future. The perspectives I heard from two leading vendors in the security platform space were very similar.

I spoke at length to WithSecure CEO Juhani Hintikka and CTO Tim Orchard; this is the recent rebrand of F-Secure, a longstanding, widely respected cybersecurity systems vendor from Finland.

And I had a deep dive discussion with Cyware’s Willy Leichter and Neal Dennis. While WithSecure is approaching the task at hand from a slightly different angle than Cyware, both rely on interoperability of multiple systems, i.e. ‘stronger together.’

Our smartphone symbiosis

If you’re like me, you’ll lose track of where you last set down your room key, wallet or coat before you misplace your smartphone.

Our mobile devices, and the mobile apps on them, have become our digital appendages. We feel lost without them. And thus they are destined to endure as our primary user interface.

Yet the security of mobile apps hasn’t advanced much in the past 10 years; bad actors don’t really have to work all that hard, or expend much resources, to exploit how we’ve come to use mobile apps.

I spoke with two vendors that are introducing promising innovation to that addresses this. Verimatrix CEO Asaf Ashkenazi described for me how his company is leveraging technologies perfected by the entertainment industry to protect mobile apps.

And Approov CEO Ted Miracco told me how his company’s solution borrows from design principles used to lock down semiconductors.

It’s easier than ever for malicious hackers to get deep access, steal data, spread ransomware, disrupt infrastructure and attain long run unauthorized access. What I saw and heard at RSAC 2023 leaves me encouraged, more so than ever before, that this widening of the security gap will be slowed — and ultimately reversed. I’ll keep watch and keep reporting

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as

View Details

“Stronger together” was the theme of RSA Conference 2023, which returned to its pre-Covid grandeur under the California sunshine last week at San Francisco’s Moscone Center.

Related: Demystifying ‘DSPM’

Rising from the din of 625 vendors, 700 speakers and 26,000 attendees came the clarion call for a new tier of overlapping, interoperable, highly automated security platforms needed to carry us forward.

Defense-in-depth remains a mantra — but implemented much differently than the defense-in- depth strategies of the first decade and a half of this century. Machine learning, automation and interoperability must take over and several new security layers must coalesce and interweave to protect the edge.

To keep the momentum going, business rivals and regulators are going to have to find meaningful ways to co-ordinate and cooperate at an unprecedented level. Here are three evolving themes reverberating from RSAC 2023 that struck me:

Getting a grip on identities

Password enabled access will endure for the foreseeable future. Multi-factor authentication (MFA) has raised the bar, but MFA alone is not enough to slow, much less stop, moderately-skilled bad actors.

New security platforms that can set cloud configurations wisely, automate detection and response and manage vulnerabilities continuously are needed to form the front line of defense. One nascent approach that shows promise: cloud native application protection platform (CNAPP.)

For a drill down on how the CNAPP space is rapidly evolving, stay tuned for my upcoming RSA Fireside Chat podcasts with a couple of vendors on the leading edge. I had enlightening discussions with Elias Terman and Sudarsan Kannan, of Uptyks, and Markus Strauss and Michiel De Lepper of Runecast.

Identities – or to put it more precisely, user access management — is a fundamental weakness that must be shored up. This is where advanced identity and access management (IAM) tools and practices comes into play.

I spoke at length with Ravi Srivatsav and Venkat Thummisi of InsideOut Defense, and separately with Venkat Raghavan, founder and CEO of Stack Identity, all about reconstituting IAM. My Fireside Chat podcasts to come will get into their insights about reducing the risk of access manipulation by continuously and comprehensively monitoring access patterns.

I also had quick meetings with Bernard Harguindeguy and Barber Amin, senior execs at Veridium ID, on the latest advances in passwordless authentication and I got the back story about a brand new smart ring (yes, of the Tolkien variety) introduced at the conference by security start-up Token; I spoke with Token CEO John Gunn and his engineering VP Evan K. about the role of advanced wearable authentication devices, going forward.

Operationalizing threat intel

Collecting and using good threat intelligence has always been important — and never been easy to do well. Two impromptu meetings I had touched on this. I spoke with Rohan Spledewinde of security start-up CTM360 – which crawls the public Internet for every and every reference to a company’s IP addresses, and uses graph database technology to present useful correlations; and I also had another very lively discussion with Snehal Antani, CEO of Horizon3 about the value of continuous, well-informed penetration testing.

Leveraging threat intelligence at the platform level, or course, remains vital, as well. The trick in today’s operating environment is how to do this well with cloud migration accelerating. There’s a danger of leaving legacy on-premises systems twisting in the wind. And that’s why emerging frameworks like Secure Services Edge (SSE) and Zero Trust Network Access (ZTNA) got a lot of attention at RSAC 2023, and deservedly so.

In the weeks ahead, be on alert for my deep-dive podcast discussions, with vendors that are shaping the security platforms of the near future. The perspectives I heard from two leading vendors in the security platform space were very similar.

I spoke at length to WithSecure CEO Juhani Hintikka and CTO Tim Orchard, as shown above in the main photo atop this column.

And I had a deep dive discussion with Cyware’s Willy Leichter and Neal Dennis. While WithSecure is approaching the task at hand from a slightly different angle than Cyware, both rely on interoperability of multiple systems, i.e. ‘stronger together.’

Our smartphone symbiosis

If you’re like me, you’ll lose track of where you last set down your room key, wallet or coat before you misplace your smartphone.

Our mobile devices, and the mobile apps on them, have become our digital appendages. We feel lost without them. And thus they are destined to endure as our primary user interface.

Yet the security of mobile apps hasn’t advanced much in the past 10 years; bad actors don’t really have to work all that that hard, or expend much resources, to exploit how we’ve come to use mobile apps.

I spoke with two vendors that are introducing promising innovation to that addresses this. Verimatrix CEO Asaf Ashkenazi described for me how his company is leveraging technologies perfected by the entertainment industry to protect mobile apps.

And Approov CEO Ted Miracco told me how his company’s solution is borrows from design principles used to lock down semiconductors.

It’s easier than ever for malicious hackers to get deep access, steal data, spread ransomware, disrupt infrastructure and attain long run unauthorized access. What I saw and heard at RSAC 2023 leaves me encouraged, more so than ever before, that this widening of the security gap will be slowed — and ultimately reversed. I’ll keep watch and keep reporting

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as

View Details

Software composition analysis — SCA – is a layer of the security stack that, more so than ever, plays a prominent role in protecting modern business networks.

Related: All you should know about open-source exposures

This is especially true as software developers increasingly rely on generic open source and commercial components to innovate in hyperkinetic DevOps and CI/CD mode.

Open source coding has come to dominate business software applications; rising to comprise 75 percent of audited code bases and putting open source on a trajectory to become a $50 billion subsector of technology by 2026.

As RSA Conference 2023 gets underway today at San Francisco’s Moscone Center, advanced ways to secure open source components is getting a good deal of attention. The infamous SolarWinds breach put a spotlight on the risk of malicious open-source components, and the White House has put its weight behind software supply chain best practices.

Guest expert: Rami Sass, CEO, Mend

I had the chance to visit with Rami Sass, CEO of Mend, a Tel Aviv-based supplier of automated remediation technologies designed to help keep open source components as secure as possible. For a full drill down on our conversation please give the accompanying podcast a listen.

Sass filled me in about a trend that started about two and a half years ago; he noted that bad actors have turned their full attention to seeking out and exploiting fresh vulnerabilities in fully updated open-source components in live service.

Mend and other SCA solution vendors are stepping up their game to counter this trend. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Patch management has always been time-consuming and arduous. But it gets done, at least to some degree, simply because patching is so crucial to a robust cybersecurity posture. Patch programs are rarely perfect though, and imperfect patching arguably enables successful cybersecurity breaches – it’s an ever-growing concern for countless IT teams.

Related: MSSPs shift to deeper help

Managed Security Service Providers (MSSPs) do their best to patch their client’s systems while also juggling a long list of other tasks associated with developing, monitoring, and maintaining their client’s overall security and compliance program.

The resources an MSSP can dedicate to patching are, however, limited: MSSPs operate within a fixed client servicing budget, and no client will accept being billed whenever a vulnerability needs to be patched.

To patch or not to patch?

It poses a huge conundrum for MSSPs: patching everything everywhere sounds like a great idea because, after all, a single failure to patch can lead to a breach. Thorough patching means secure client systems. But patching that thoroughly isn’t economical. Some vulnerabilities are more critical – and some systems are more central to operations than others.

There is a balance to strike, but choosing where to prioritize is a tough call. Absent a game-changing technology the best solution would be to simply throw more resources at the patching problem, but that would drive up costs for MSSPs which could lead them to become uncompetitive.

There’s another problem that makes consistent patching tough to achieve: pushback from the client. Patching disrupts user workflows, causing frustration and impacting productivity. After all, patching commonly requires that the MSSP takes a service offline, restarting to apply the patch.

Jackson

A competently managed patching process should lead to no more than performance degradation, but manage patching poorly and it means downtime and big chunks of potential revenue loss. Companies need to plan for these disruptions which makes for a complex conversation between MSSP and their client.

Again, there’s a trade-off. Patching more can translate into more disruption, but patching less means taking a larger risk. The net effect is often less patching because MSSPs may judge that preserving the client relationship matters more than closing just one more vulnerability.

Enter live patching

Clearly, the patching conundrum needs a solution. Patching automation helps, and so does a sophisticated patch management program. But neither negates the labor hours involved in patching nor do these methods eliminate the disruption. Someone still needs to double-check that a restarted system goes back online correctly, and downtime must be managed (or tolerated).

There is a cybersecurity approach that changes the game. It’s called live patching, a patching method that applies updates to a running software system, typically an operating system or a kernel, without requiring reboots.

When MSSPs implement live patching it enables continuous system operation, particularly useful for critical systems and servers where uptime matters – but of value everywhere because it reduces the staff-hour workload and virtually eliminates disruption.

Several vendors developed live patching solutions. For Linux systems that includes Ksplice, offered by Oracle, which live patches Oracle Linux and a few other Linux distributions. Canonical offers Livepatch, compatible with Ubuntu.

IBM offers a live patching solution called Kernel Live Patching for IBM Z and LinuxONE systems. Microsoft introduced Azure Hotpatching which allows Azure users to apply security updates to their virtual machines (VMs) with zero downtime.

Integrated toolsets

Vendor solutions are, however, often tied to expensive support contracts and commonly compatible with just the vendor’s product. Third-party providers can sometimes offer a better package. For example, TuxCare’s KernelCare product covers the most commonly-used enterprise Linux distributions – while also delivering live patching across open-source databases, libraries, and virtual environments.

The best live patching tools integrate with vulnerability scanners and other automation tools to speed up the security and compliance process. MSSPs can therefore efficiently identify, prioritize, and remediate vulnerabilities all through a centralized platform.

This integration allows MSSPs to patch consistently, reducing the compromises inherent to patching programs so that clients can readily meet standards such as NIST 800-53 and PCI DSS. MSSPs also worry less about costs and maintain excellent client relationships because live patching removes friction.

By including live patching in the process, MSSPs minimize disruption and ensure the needed security updates are applied promptly and consistently. Thanks to the time saved, MSSPs can now allocate more resources to other aspects of cybersecurity.

About the essayist: Jim Jackson serves as President and Chief Revenue Officer at TuxCare.

View Details

Managed Security Service Providers, MSSPs, have been around for some time now as a resource to help companies operate more securely.

Related: CMMC mandates best security practices

Demand for richer MSSP services was already growing at a rapid pace, as digital transformation gained traction – and then spiked in the aftermath of Covid 19. By one estimate, companies are on track to spend $77 billion on MSSP services by 2030, up from $22 billion in 2020.

At RSA Conference 2023 , which gets underway next week at San Francisco’s Moscone Center, I expect that there’ll be buzz aplenty about the much larger role MSSPs seem destined to play.

I had the chance to visit with Geoff Haydon, CEO of Ontinue, a Zurich-based supplier of a managed extended detection and response (MXDR) service. We discussed the drivers supporting the burgeoning MSSP market, as well as where innovation could take this trend.

Guest expert: Geoff Haydon, CEO, Ontinue

For its part, Ontinue is leveraging Microsoft collaboration and security tools and making dedicated cyber advisors available to partner with its clients. “Microsoft has emerged as the largest, most important cybersecurity company on the planet,” Haydon told me. “And they’re also developing business applications that are very conducive to delivering and enriching a cyber security program.”e

I covered Microsoft as a USA TODAY technology reporter when Bill Gates suddenly ‘got’ cybersecurity, so this part of our discussion was especially fascinating. For a drill down, please give the accompanying podcast a listen. Meanwhile, I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Adopting personas and rubbing elbows with criminal hackers and fraudsters is a tried-and-true way to glean intel in the Dark Web.

Related: In pursuit of a security culture

It’s not at all unusual to find law enforcement agents and private sector threat intelligence analysts concocting aliases that permit them to lurk in unindexed forums, vetted message boards and encrypted code repositories.

This boots in the underground approach, of course, has its limitations.

At RSA Conference 2023 , which gets underway on Monday, Apr. 26, at San Francisco’s Moscone Center, the latest innovations in gathering and leveraging intel — at a scale that can make a material difference — will be in the spotlight.

I had the chance to visit with Delilah Schwartz, security strategist at Cybersixgill, a Tel Aviv-based cybersecurity company that supplies this type of threat intelligence. We discussed how her company is leveraging essentially the same automated crawling tools and techniques used by the big search engines to gather and supply actionable threat intelligence to its customers.

Guest expert: Delilah Schwartz, security strategist, Cybersixgill

“We gain fully automated access to these very difficult to navigate Dark Web platforms, extract that useful intel, analyze it using AI and ML, and then we translate that into concrete insights in our data lake,” Schwartz says.

For a drill down, please give the accompanying podcast a listen. Good intel can only help inform smarter, more effect network defenses – and ultimately reinforce resiliency.

I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Good intelligence in any theater of war is invaluable. Timely, accurate intel is the basis of a robust defense and can inform potent counterattacks.

Related: Ukraine hit by amplified DDoS

This was the case during World War II in The Battle of Midway and at the Battle of the Bulge and it holds true today in the Dark Web. The cyber underground has become a highly dynamic combat zone in which cyber criminals use engrained mechanisms to shroud communications.

That said, there are also many opportunities for companies to glean and leverage helpful intel from the Dark Web. As RSA Conference 2023 gets underway next week at San Francisco’s Moscone Center, advanced ways to gather and infuse cyber threat intelligence, or CTI, into fast-evolving network defenses is in the spotlight.

I had the chance to visit with Jason Passwaters, CEO of Intel 471, a US-based supplier of cyber threat intelligence solutions.

Guest expert: Jason Passwaters, CEO, Intel 471

We discussed how the cyber underground has shifted from being perceived as deep and dark to a well-organized world with defined business models, supply chains, and relatively low barrier of entry.

“As the cyber underground becomes more sophisticated, the level of threat increases exponentially for legitimate businesses and nation-states,” Passwaters told me. “The underground is now the domain of organized cybercriminals with clear hierarchies and targeted revenue goals.”

Intel 471 directs comprehensive threat intelligence at identifying, prioritizing and preventing cyber attacks. For a full drill down, please give the accompanying podcast a listen. Good intel in warfare can’t be overstated. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Embedding security into the highly dynamic way new software gets created and put into service — on the fly, by leveraging ephemeral APIs — has proven to be a daunting challenge.

Related: The fallacy of ‘security-as-a-cost-center’

Multitudes of security flaws quite naturally turn up – and threat actors have become adept at systematically discovering and exploiting these fresh vulnerabilities.

As RSA Conference 2023 gets underway next week at San Francisco’s Moscone Center, advanced application security and API security tools and practices are grabbing a lot of attention.

I had the chance to visit with Scott Gerlach, chief security officer and co-founder of StackHawk, a Denver-based software company launched in 2019 to join the phalanx of vendors innovating like crazy to dial-in meaningful code checks, in just the right measure, at just the right moment.

Guest expert: Scott Gerlach, CSO, StackHawk

We had a great conversation about how the venerable “shift left” security philosophy is being refined so that it better aligns with the way software gets developed today – at light speed. This has led to security vendors, StackHawk among them, putting great energy into weaving security more tightly into DevOps, CICD and more.

“Shift left still applies because you do want to get security processes into the left side where you design, develop, test and deploy,” Gerlach told me. “But it’s really about how can we get security information closer to the people who are writing code, changing code and fixing code.”

In short, “shift everywhere” is the new “shift left.” For a full drill down, please give the accompanying podcast a listen. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

In the age before the cloud, data security was straightforward.

Related: Taming complexity as a business strategy

Enterprises created or ingested data, stored it and secured it in a physical data center. Data security was placed in the hands of technicians wearing tennis shoes, who could lay their hands on physical servers.

Today, company networks rely heavily on hybrid cloud and multi-cloud IT resources, and many startups are cloud native. Business data has been scattered far and wide across cloud infrastructure and just knowing where to look for sensitive data in the cloud, much less enforcing security policies, has become next to impossible for many organizations.

If headline grabbing cyber-attacks weren’t enough, the Biden Administration has begun imposing long-established, but widely ignored data security best practices on any contractor that hopes to do business with Uncle Sam.

Guest expert: Yotam Segev, co-founder and CEO, Cyera

This is where a hot new security service comes into play – designated in 2022 by Gartner as “data security posture management,” or DSPM. With RSA Conference 2023 taking place at San Francisco’s Moscone Center next week, I had the chance to visit with Yotam Segev, co-founder and CEO San Mateo, Calif.-based security startup Cyera, that is making hay in this emerging DSPM space.

Segev and I discussed how, in the rush to the cloud, companies have lost control of data security, especially in hybrid environments. The core value of DSPM systems, he argues, is that they can help demystify data management, with benefits that ultimately should go beyond security and compliance and actually help ease cloud migration.

Please give a listen to the case Segev makes in the accompanying podcast. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Domain Name Service. DNS. It’s the phone directory of the Internet.

Related: DNS — the good, bad and ugly

Without DNS the World Wide Web never would never have advanced as far and wide as it has.

However, due to its intrinsic openness and anonymity DNS has also become engrained as the primary communications mechanism used by cyber criminals and cyber warfare combatants.

If that sounds like a potential choke point that could be leveraged against the bad actors – it is. And this is where a fledgling best practice — referred to as “protective DNS” – comes into play.

What has happened is this: leading security vendors have begun applying leading-edge data analytics and automated remediation routines to the task of flagging DNS traffic that’s clearly malicious.

Guest expert: David Ratner, CEO, HYAS

One sure sign that protective DNS has gained meaningful traction is that Uncle Sam has begun championing it. Last fall the U.S. Cybersecurity & Infrastructure Security Agency (CISA) began making a protective DNS resolver availabile to federal agencies.

With RSA Conference 2023 taking place at San Francisco’s Moscone Center next week, I had the chance to visit with David Ratner, CEO of Vancouver, Canada-based HYAS, security company whose focus is on delivering protective DNS services. Ratner explains what protective DNS is all about, and why its widespread adaption will make the Internet much safer.

For a full drill down, give the accompanying podcast a listen. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

One of the nascent security disciplines already getting a lot of buzz as RSA Conference 2023 gets ready to open next week at San Francisco’s Moscone Center is “software supply chain security,” or SSCS.

Related: How SBOMs instill accountability

Interestingly, you could make the argument that SSCS runs counter-intuitive to the much-discussed “shift left” movement. I think it’s fair to say, at the very least, SSCS extends shift left a bit more to the right.

Shift left advocates driving code testing and application performance evaluations as early as possible in the software development process.

By contrast, SSCS vendors are innovating ways to direct automated inspections much later in DevOps, as late as possible before the new software application is deployed in live service.

Guest expert: Matt Rose, Field CISO, ReversingLabs

I had the chance to visit with Matt Rose, Field CISO at ReversingLabs, which is in the thick of the SSCS movement. We discussed why reducing exposures and vulnerabilities during early in the coding process is no longer enough.

“True software supply chain security is about looking at the application in a holistic way just prior to deployment,” Rose observes. “Most software supply chain issues are novel, so looking for problems too early, before the code is compiled, won’t tell you much.”

Like everyone else, SSCS solution vendors are leveraging machine learning and automation – to focus quality checks and timely remediation in very specific lanes: on open-source components, microservices containers and compiled code, for instance. For a drilll down please give a listen to the accompanying podcast.

I’m looking forward to attending RSAC in person, after a couple of years of remote participation. No doubt there’ll be some thoughtful discussion about how best to protecting software in our software defined world.

I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

No organization is immune to cybersecurity threats. Even the most well-protected companies can be susceptible to attacks if they are not careful about a proactive approach towards cyber security.

Related: Why timely training is a must-have

That’s why businesses of all sizes need to understand the biggest cybersecurity weaknesses and take steps to mitigate them. Here are a few of the top security weaknesses that threaten organizations today:

Poor risk management. A lack of a risk management program or support from senior management is a glaring weakness in your cybersecurity strategy.

A robust risk management program should include regular assessments of security controls and audits to ensure compliance with industry standards and best practices.

Tick-in-the-box training. Unfortunately, many organizations fail to educate their employees on the importance of cyber hygiene, leaving them vulnerable to phishing scams, malware infections, data breaches, and other cyber attacks.

By not involving your audience and understanding their context, i.e., organization users are susceptible users being the weakest link that in fact could be your strongest link.

Anemic asset management. Integrating asset management into your organization can help you understand where your vulnerabilities lie so that you can take steps to protect yourself accordingly.

By understanding what data or systems you manage, you can then determine which security measures need to be implemented. This will enable you to better safeguard your organization’s sensitive information against potential threats.

Lackadaisical set up. Getting security right early in the development cycle with well-architected services and systems reduces attack surface significantly.

Singh

When designing new systems or modifying existing ones, think about the principles of least privilege and need to know. By taking a proactive approach towards security in your architecture and configuration, you are better able to protect critical data from potential threats.

Spotty patching. Vulnerability management is another key consideration when it comes to security. It ensures that all systems are regularly updated, vulnerabilities are triaged accordingly, and legacy equipment is managed securely.

To do this effectively, you must have an effective patch management process in place which takes into account the different operating systems you use across your organization as well as their respective patch cycles.

Weak access controls. Identity and Access Management (IAM) plays an important role in reducing attack surface by controlling who has access to what data within your system environment. All access should be granted on a need only basis, meaning that users should only be able to access the data they need for their role or job function within the organization.

Lack of monitoring. Logging events is the first step in understanding which services or systems are used within an organization. Security monitoring, meanwhile, provides us with visibility into what is happening on our systems so that we can identify and respond to potential threats quickly.

No disaster plans. It is also essential to have an effective incident management strategy if a security incident occurs. This involves having a plan for detecting incidents quickly and responding effectively. You should also have procedures to reduce incidents’ impact through recovery planning.

Visibility gaps. A key issue many organizations face is they don’t always know where their data is stored, who has access to it or how it is processed. This lack of clarity leaves organizations vulnerable to threats such as insecure cloud buckets or permissions-based misconfigurations which can lead to data breaches.

Supply chain blindness. Organizations increasingly rely on third-party suppliers for their product components or services. Unfortunately, these third parties may not have the same level of security as your organization; therefore, the lack of risk-based approach adds another layer of vulnerability.

By taking a risk-based approach to supply chain security, organizations can better protect themselves from malicious actors looking to access confidential information or disrupt operations with cyber attacks or data breaches.

Overall, it is clear that there are many different security weaknesses an organization can face. This fundamentally reflects a failure to acknowledge that cybersecurity has moved to risk-based approach, one that offers measurable outcomes, not just investment into tooling.

A starting point should be assessing the gaps fairly, usually utilizing a third-party cyber security services company. This would ensure you are aware of your blind sports, more importantly, help you with analysis and preparing a risk remediation plan.

About the essayist: Harman Singh is a security consultant serving business customers at Cyphere. He has also delivered talks and trainings at Black Hat and regional conferences – on Active Directory, Azure and network security.

View Details

At 10 am PDT, next Wednesday, April 19th, I’ll have the privilege of appearing as a special guest panelist and spotlight speaker on Virtual Guardian’s monthly Behind the Shield cybersecurity podcast.

Related: The Golden Age of cyber spying is upon us

You can RSVP – and be part of the live audience – by signing up here. The moderator, Marco Estrela, does a terrific job highlighting current cybersecurity topics ripped from the headlines. For my part, I’m going to ‘follow the money’ with respect to the strategic use of weaponized ransomware on the part of Vladimir Putin.

I recently had the chance to drill down on this topic as part of a Last Watchdog Fireside Chat podcast I’m currently producing. Stay tuned for my eye-opening discussion with BullWall, a Danish startup that’s in the midst of helping companies effectively mitigate cyber extortion.

Meanwhile, in the April 19th episode of Behind the Shield, I’m going to attempt to summarize the big theme I’m hearing from BullWall and numerous other security vendors as I get ready to make the trek to San Francisco’s Moscone Center to cover RSA Conference 2023 in person – after two years of covering it remotely.

And that theme is . . . the unfolding reconstitution of network defense. There’s a common thread running through all of the advanced tools, new security frameworks and innovative security services that are rapidly gaining traction.

At some level, they all drive us in the direction of creating a new tier of overlapping, interoperable, highly automated security platforms. The end game quite clearly must be to bake security deep inside the highly interconnected systems that will give us climate-rejuvenating vehicles and buildings and spectacular medical breakthroughs.

I’ll get this discussion going at Virtual Guardian’s Behind the Shield podcast next week. And I’ll try to ramp it up in my upcoming series of Last Watchdog RSA Insights Fireside Chat podcasts to follow. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


View Details

Instilling a culture of cyber security at your organization requires your people to maintain a high level of knowledge and awareness about cyber security risks—and that takes an effective, impactful, and ongoing security awareness program.

Related: Deploying employees as human sensors

However, a security awareness program is only as good as its content. To ensure that your end users retain core concepts and knowledge, it’s important to contextualize topics and keep your people engaged during the entire training process.

Additionally, to hold their interest, the content must be fun.These results are achieved in a few different ways. Let’s take a closer look.

Make it engaging!

First and foremost, your security awareness program’s content must be engaging. Break up lessons into bite-size morsels, and carefully divide them by topics. Keep the interface simple, and include an interactive component, such as a short quiz, in each lesson.

Also, tailor content to the user’s specific role within the organization. You might show someone in a manager role, for example, content that helps them coach their team members and supervise any existing cyber security awareness processes.

Content quality is also integral to your organization’s cyber security because it’s directly tied to the completion levels of your training. When you provide quality content, your employees understand this is a subject you’re serious about.

They’ll be much more likely to stick with their cyber security habits; when they do, you strengthen your data security.

Customize your content

Along with making sure your content is engaging and of high quality, it’s also helpful to vary the media you use to deliver your content and personalize it to your organization’s needs. Otherwise, it’s likely that your users will never relate to it and take it seriously.

Lapointe

For example, you can use newsletters and desktop images as reference material and reminders of best practices. Deploy them after the learning activities or use them to promote key topics that you did not have the opportunity to cover during your program.

You can also promote your message with short, engaging online learning activities throughout the year, such as microlearning, nano-learning, videos, and gamified Cyber Challenge modules.

Take the time to carefully consider and customize the content you want to include in each program campaign, too. To make your selection, you must consider many variables, including the risks, the behavior you want to change, your participants’ motivation, your organization’s culture, your training budget, and your capacity to implement and distribute the content in various forms.

Course customizations can also include things like your logo, brand colors, links to your organization’s policies, photos, videos, and other visuals relevant to your organization.

When customizing your program content, avoid over customization. In other words, don’t cover too much information in a single course. Your goal should be to turn participants into security advocates, not experts, so tailor your content with that in mind.

Vary your tools

Everyone responds to messaging differently. Fortunately, there are an assortment of awareness tools available; which ones you choose will depend on the context and the target audience.

Online courses, for instance, allow you to reach a broad audience quickly. They offer a way to address specific learning objectives, and they generally have higher retention rates due to the interactivity that comes with online training.

Live presentations, on the other hand, are the ideal format to share valuable security-related information with executives and senior managers, because they are short (15–20 minutes) but long enough to cover the specific awareness concerns of leadership (e.g., threats and relevant news stories).

Live presentations can also be used for general audiences; they allow them to ask questions and hear from their peers.

After launching a campaign, use reinforcement tools to repeat the key messages covered in the awareness training. That will send the message home, ensure participants don’t forget best practices, and keep security top of mind.

Videos, newsletters, desktop images, web banners, games, and posters are just a few ways to increase retention, prioritize information security, and ultimately achieve your campaign objectives.

Instilling a culture of security at your organization is not a “one-and-done” project. It’s an ongoing process whose success depends on how engaging your content is.

But, by making sure you offer high-quality, engaging content in a variety of formats, you will go a long way toward making sure your employees learn, retain, and implement cyber security best practices.

About the essayist: Lisa Lapointe has dedicated her career to growing security-aware organizational cultures worldwide. Her company, Terranova Security, spearheaded personalized, people-centric security awareness programs that reform risky human behaviors. A resident of Quebec, Lise has ranked among both IT World Canada’s “Top 20 Women in Cyber Security” and WXN’s “100 Most Powerful Women” entrepreneurs in Canada.

(Editor’s note: This essay was adapted from LaPointe’s book, The Human Fix to Human Risk.)

View Details

Modern cyber attacks are ingenious — and traditional vulnerability management, or VM, simply is no longer very effective.

Related: Taking a risk-assessment approach to VM

Unlike a typical cyber attack that exploits a software vulnerability, recent cyber attacks exploit other security risks, such as misconfigurations, security deviations, and posture anomalies. But VM vendors tend to focus more on software vulnerabilities and leave out everything else.

SecPod’s research shows some 44 percent of the total vulnerabilities in a typical IT infrastructure don’t have a Common Vulnerabilities and Exposure (CVE) designation.

The consequences of a cyber attack can be devastating; from a rapid drop in brand reputation to loss of business and sensitive data. Cyber attacks can also invite lawsuits and can even be fatal.

In addition to real-time protection, effective VM can also help with compliance at a time when data security rules are increasing in regulatory policies like NIST, PCI, HIPAA and GDPR.

With traditional VM, achieving compliance is a struggle. But advanced VM provides an actionable way of adhering to regulations and policies mandates that call for risks to be identified and detected as part of ongoing data security.

While traditional VM is herky-jerky, advanced VM is a continuous and smooth process that results in much more efficient and detection, integration, and automation.

Further, effective VM can be very cost-effective; the potential cost saved in preventing cyberattacks is enormous when compared to total security expenditures.

Reinventing VM

The importance of effective VM can’t be overstated. Yet given the evolving IT environment, CISOs, sysadmins, and IT security teams are struggling to protect their networks.

Basavanna

Ideally, VM should be continuous and proactive, but traditional VM is jagged, broken, insufficient — and in desperate need of reinvention.

With traditional VM, detection is limited to software vulnerabilities, assessment and prioritization to a common vulnerability scoring system (CVSS) ranking, as well as remediation to patching. This approach only provides superficial visibility into IT infrastructure, and does not take into account lateral attack vectors.

Without automation, the laborious task of scanning and remediation is difficult. Additionally, multiple teams use multiple tools in traditional VM, leading to a disconnect and friction between them, further reducing the effectiveness of traditional VM.

The Jira misconfiguration leaks highlight the devastating impact vulnerabilities beyond those called on in CVEs can have in a modern environment. Modern cyberattacks exploit misconfigurations and other security risks, and research reflects the same. Some 31 percent of respondents to a recent ESG survey pointed to misconfigurations as the initial point of compromise for a successful ransomware attack.

Advanced capabilities

Advanced VM computes high-fidelity attacks and criticality to mitigate risks effectively. Traditional VM can only remediate software vulnerabilities with patches, while advanced VM fixes misconfigurations, normalizes deviations, and eliminates other security risks. So a dangerous new exploit that lacks a CVE designation and registers a low CVSS score can still be detected and remediated in a timely manner.

The lack of the right tools with enough capabilities and the inertia to shift to new technology are the main reasons why advanced VM is not yet adapted universally. But it’s only a matter of time before it gets widespread adoption.

Modern networks are becoming increasingly interconnected and massive. This means a larger attack surface, numerous security risks, and more work for IT security teams.

Advanced VM, with its broader detection, faster scans, and integrated remediation, is the only way of combating modern cyberattacks. Clearly, advanced VM is well positioned to be a core component of combating ever-evolving cyber attacks.

About the essayist: Chandrashekhar Basavanna is the founder and CEO SecPod Technologies, a cybersecurity technology company creating solutions for enterprise IT Security teams to prevent cyberattacks on the computing environments.

View Details

Imagine being a young person who wants a career, of whatever type you can find, as a cybersecurity professional.

Related: Up-skilling workers to boost security

Related Although you were born with an agile and analytical mind, you have very limited financial resources and few, if any, connections that can open doors to your future ambitions.

Dennis

If you were born in a country such as the US, Canada or the UK, you might have a wider range of options despite your financial limitations. But if you are born in Antigua, which is a small Caribbean island way out in the Atlantic, your options can be quite limiting. Even if you managed to get a range of certifications which show that you have some skills, finding a job in your field is extremely unlikely because the market is so small and undeveloped.

High concept

Now enter AntiguaRecon which was created to teach a group of young Antiguans cybersecurity skills so that it could offer cybersecurity services around the region and in the US, Canada, and elsewhere. It is not enough to just educate the students. Our proof of concept will come when we get them jobs too.

The founder, Adam Dennis (that’s me!), has experience running training organizations directed at young people AND a lot of experience running startups. In the late 1990s (yes, that long ago), I created a youth training program called YouthLink that worked with at-risk youth in Washington, DC. The program operated for five years and was covered by the Washington Post and a number of other news outlets. Over my career, I have created three non-profits and two SaaS for profits, one of which I sold in 2005.

AntiguaRecon has been operating since early last year and has trained 14 students averaging in age of around 20 years old. Since cybersecurity is a massive field, and broad skill building can be an even bigger challenge, the program has focused on web attacks and simulated phishing training, since these vulnerabilities are common in this region.

The program would not have been possible were it not for volunteer cybersecurity mentors from around the world. We have mentors from Canada, the US, Argentina, Dubai, India, and Antigua. Senior talent is critical since they give perspective that our young students wouldn’t otherwise have.

Critical support has also been provided by a local school called Island Academy, who raised the funds to start the program and supplies classroom space for face-to-face learning. Island Academy’s founder, Bernadette Sherman, has been hugely supportive from the start.

Pairing plan

2023 is THE critical year. The organization is educating its next group of students supported by “seniors” from the previous year who are paired 1-on-1 with a partner. The purpose of this model is to build teamwork and depth. The expectation is that we will have sufficient depth of knowledge to begin offering limited web attack and simulated phishing skills by mid-year.

Our pairing model seeks to get a team built up and optimized as quickly as possible. I did this with one of my previous jobs running Agile software teams and it worked quite well. As it stands right now, we already have 2 potential customers that are waiting in the wings so things are looking up.

How can you help? AntiguaRecon needs four things:

•Expert mentor support. The key need at the moment are professionals who do social engineering, particularly with simulated phishing skills (and ideally with Gophish experience).

•Promotional support, such as what has been provided here (thank you!), so that they can get the word out about the project.

•Financial support to eventually secure a cyber security expert as a core trainer and senior for the service offerings. This one is very important since potential customers will want to see a person at the center of the program with deep cybersecurity experience.

•Opportunities to secure nearshore customers in the US, Canada, and elsewhere. Getting customers, especially a customer who sees the opportunity for them to build with us over time, is absolutely critical. When we get our customers, we will deliver to our students a real hope for their future.

We will prove that their efforts were worth it, and we will establish an organization that can survive and continue training more students, not based on donations, but on the money earned by its graduates. That’s the future we want, and it’s the future we are working towards.

Feel free to visit AntiguaRecon on LinkedIn, the web, or email me at adam@antiguarecon.com.

About the essayist: Adam Dennis the founder of AntiguaRecon. Launched in January 2022, this initiative provides cybersecurity training on the Caribbean Island nation of Antigua and Barbuda. The goal is to offer the services around the region and then as a near shore solution for the US and Canada, and offshore for other locations around the world.

View Details

Organizations with strong cybersecurity cultures experience fewer cyberattacks and recover faster than others.

Related: Deploying human sensors

This results from emulating the culture building approaches of high-risk industries like construction that devote sustained attention to embedding safety throughout the organization.

For most organizations, building a cybersecurity culture is a necessary evil rather than a cherished goal. Prioritizing security means desirable cultural norms like openness, trust building, creativity, efficiency, and risk-taking might suffer.

Until a decade ago few organizations needed a cyber security culture. If the security industry catches up with adversaries, then the need for a cybersecurity culture will eventually fade away. Few will miss it.

Cybersecurity culture is a subset of the overall corporate culture. It harnesses beliefs and values to promote secure behaviors by employees in everyday work activities.

Model culture

Cybersecurity culture is necessary today because routine actions such as opening emails, responding to customer requests and using productivity software can put the organization at risk for ransomware and data breaches.

Inherently dangerous industries like construction provide a good model for culture building. Top performers know that systematically building and enforcing a culture of safety among all employees leads to success. This experience can be translated to the cyber realm.

Leading construction firms take an aggressive approach to creating a culture of safety:

•They make safety the organization’s number one priority. Management makes decisions that favor safety over other priorities such as cost, speed, and flexibility. That only happens with a real commitment from the top.

•Ongoing training ensures employees can confidently perform the safety roles assigned to them. Time and money for training is another tangible example of a company’s seriousness.

•Managers ensure that employees are involved and committed by building safety into everyday routines and guarding against cynicism and noncompliance.

•Reward and punishment are used to translate the safety priority into consequences. Bonuses are awarded for going above and beyond. Those that fail to perform after constructive feedback are written up or terminated.

Few organizations are ready to make cybersecurity their top priority the way construction makes safety number one and it would be a shame if they had to do so. But sometimes there are ways to avoid the tradeoff, such as by designing new processes that are simultaneously more secure and efficient.

Cultural norms

The emphasis on building a cybersecurity culture can provide a convenient excuse to blame employees for security issues that don’t belong on their shoulders. A widely cited study concludes that close to 90 percent of data breaches are caused by employee error. But blaming end users makes matters worse. Employees feel ashamed and culpable, and may be less likely to report a problem when they see it for fear of being blamed.

Cybersecurity culture should not expect employees to be the main line of defense for an organization’s systems. What cultural norms are reasonable?

•Employees should be honest about security concerns and not feel shame when they click a link they should have avoided. The culture should encourage and reward transparent reporting.

•It is reasonable to expect employees to understand and follow the incident reporting.

•Employees should know who is responsible for information and operational security.

•Employees should be trained in and understand privacy laws and policies including GDPR and US privacy laws from California and other states where they do business.

Amusement park analogy

It is an open question about whether frontline and non-technical employees should need a cybersecurity culture at all. Consider an amusement park with a variety of thrilling but potentially dangerous rides like roller coasters.

Carr

Safety is built into the rides themselves. If there’s a power failure and a ride gets stuck with guests hanging upside down they should still be ok as long as the amusement park employees follow basic procedures like checking to make sure everyone is bolted in. All we expect of park visitors is that they don’t do something truly reckless like wriggling out of their seatbelts or standing up in tunnels.

Ideally, cybersecurity should work the same way. Let hardware and software makers build in security by design, cybersecurity staff make sure vulnerability scanning tools are deployed securely, and regular workers experience the thrill of their jobs or at least the mundane experience of safely traveling throughout their day.

About the essayist: Matthew T. Carr is co-founder and head of research and technology at Atumcell, which provides cyber security software and services for private equity firms and their portfolio companies. He is an award-winning cyber security researcher, inventor and penetration tester who helps organizations solve thorny security and privacy problems.

View Details

APIs have been a linchpin as far as accelerating digital transformation — but they’ve also exponentially expanded the attack surface of modern business networks.

Related: Why ‘attack surface management’ has become crucial

The resultant benefits-vs-risks gap has not surprisingly attracted the full attention of cyber criminals who now routinely leverage API weaknesses in all phases of sophisticated, multi-stage network attacks.

The collateral damage has escalated to the point where federal regulators have been compelled to step in.

Last October the FFIEC explicitly called out APIs as an attack surface that must, henceforth, comply with a new set of API management practices.

Guest expert: Richard Bird, Chief Security Officer, Traceable

I had the chance to visit with Richard Bird, Chief Security Officer at Traceable.ai, which supplies security systems designed to protect APIs from the next generation of attacks.

We discussed, in some detail, just how far the new rules go in requiring best practices for accessing and authenticating APIs. Bird also enlightened me about how and why this is just a first step in comprehensively mitigating API exposures. For a full drill down, please give the accompanying podcast a listen.

There’s little doubt that the new FFIEC rules will materially raise the bar for API security. In the short run companies subject to federal financial institution jurisdiction will have to hustle to get their API act together; and in the long run other companies in other verticals should follow suit.

I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

The cybersecurity landscape is constantly changing. While it might seem like throwing more money into the IT fund or paying to hire cybersecurity professionals are good ideas, they might not pay off in the long run.

Related: Security no longer just a ‘cost center’

Do large cybersecurity budgets always guarantee a company is safe from ongoing cybersecurity threats?

According to research from Kiplinger, businesses are spending less money on capital equipment, especially as rumors of a mild recession in the future loom. However, organizations in 2023 know one crucial area to spend money n is cybersecurity.

Cyberattacks are becoming more frequent, intense and sophisticated than ever. In response, many businesses of all shapes and sizes will allocate funds to their IT departments or cybersecurity teams to make sure they’re well-defended against potential threats. They may incorporate tools such as firewalls or antivirus software, which are helpful, but not the only tactics that can keep a network secure.

Unfortunately, having a large cybersecurity budget does not necessarily mean a company has a solid, comprehensive security plan. Organizations can spend all they have on cybersecurity and still have pain points within their cybersecurity program. Threat actors will still use social engineering tactics like phishing or ransomware to target businesses, steal data and earn a significant payday.

Amos

One of the best ways to utilize a large cybersecurity budget is to take an intelligent threat approach. This approach involves companies using all their resources and information to determine which cybersecurity threats will most likely impact them. However, using this approach does not require vast amounts of spending.

An intelligent threat approach should leverage four key principles: accuracy; relevance; actionability; cost-effectiveness.

The information used to guide a cybersecurity program should always be accurate and relevant to existing and emerging threats. Additionally, identifying threats enables organizations to take action without spending too much of their resources. These four principles are fundamental if businesses want to build a cost-effective cybersecurity program.

Here are some do’s and don’ts that will help companies save on their cybersecurity budgets and still maintain good cybersecurity posture in an increasingly threatening environment.

Do:

•Research cybersecurity solutions before spending to find the most cost-effective options.

•Partner with a third-party cybersecurity firm to lean on for guidance.

•Focus on creating a mitigation and remediation plan to be proactive.

•Move toward a converged IT solution to bring together data analytics and cybersecurity.

•Eliminate tools that are not delivering valuable insights or solutions to the organization.

•Only adopt the necessary cybersecurity solutions based on the organization’s needs.

Don’t:

•Hire unnecessary personnel to handle cybersecurity tasks.

•Implement too many solutions, as it can lead to confusion and complexity. Only adopt the necessary cybersecurity solutions based on the organization’s needs.

•Overspend just for the sake of saying the cybersecurity team is well-funded.

Although a good cybersecurity strategy does require businesses to spend a considerable amount of money, not every strategy requires hundreds of thousands or millions of dollars to be strong, nor is every strategy complete just because it’s received an influx of funds.

Depending on the organization, it’s crucial to find the right cybersecurity solutions to ensure IT pros can perform their duties and protect the organization. Ultimately, companies should strike a balance between overspending and spending the right amount of money on valuable solutions and tools to ensure their defenses are as impenetrable as possible.

About the essayist: Zac Amos writes about cybersecurity and the tech industry, and he is the Features Editor at ReHack. Follow him on Twitter or LinkedIn for more articles on emerging cybersecurity trends.

View Details

One common misconception is that scammers usually possess a strong command of computer science and IT knowledge.

Related: How Google, Facebook enable snooping

In fact, a majority of scams occur through social engineering. The rise of social media has added to the many user-friendly digital tools scammers, sextortionists, and hackers can leverage in order to manipulate their victims.

Cybersecurity specialists here at Digital Forensics have built up a store of knowledge tracking criminal patterns while deploying countermeasures on behalf of our clients.

One trend we’ve seen in recent years is a massive surge in cases of sextortion. This online epidemic involves the blackmail of a victim by the perpetrator via material gained against them, typically in the form of nude photos and videos.

These sextortionists are some of the lowest forms of criminals, working tirelessly to exploit moments of weakness in their victims induced by loneliness and our most base-level human natures.

Since the dawn of civilization and economics, instances of fraud have always existed. Scholars have determined that the precursors of money in combination with language are what enabled humans to solve cooperation issues that other animals could not. The advancement of fraud has materialized parallel to that of currency.

Exploitation drivers

From the case of Hegestratos committing insurance fraud by sinking a ship in 300 B.C., to the Praetorian Guard selling the rights to the Roman throne in 193 AD, to the transgressions of Madoff and Charles Ponzi, fraud has always been embedded in society as a consequence of economics.

As technology has rapidly exceeded all historical imaginings, opportunities for fraudsters to exploit their victims abound. Digital exploitation refers to the abuse and manipulation of technology and the internet for illegal and unethical purposes, including identity theft, sextortion, cyberbullying, online scams, and data breaches.

The rise of digital exploitation has been a direct result of technological advancement and the widespread use of the internet in our daily lives.

Cybersecurity has similarly developed as a necessary countermeasure to prevent scammers from rampaging the privacies of citizens. Since fraudsters constantly seek new methods of exploitation, cybersecurity specialists are responsible for being identically innovative in anticipating future techniques of exploitation before they exist.

Modern measures of cybersecurity and digital forensics must not merely react to cases of fraud, but must proactively seek to exploit current systems as well in the aim of remaining vigilant against fraud-villains.

The success of digital exploitation can be attributed to several factors, including difficulty in keeping up with the latest security measures, increased reliance on technology and the internet, and a general lack of awareness and education about the dangers of the internet.

Countermeasures

To address the issue of digital exploitation, it is essential to raise awareness and educate people about the dangers of the internet, and to continue to develop and implement strong security measures to protect personal information and sensitive data.

McNulty

It may someday fall to the Federal government to deploy cybersecurity as a service such as community hubs or public utilities, but for the foreseeable future it falls upon private enterprises to assist clients suffering from a digital exploit in reclaiming their lives.

Digital Forensics experts are trained to follow digital footprints and track down IP addresses, cell phone numbers, email addresses, social media accounts and even specific devices used in these crimes. We can identify online harassers or extortionists with a high degree of success, arming clients with the evidence they need to confront a harasser, seek a restraining order or even press charges.

About the essayist: Collin McNulty is a content creator and digital marketer at Digital Forensics, a consultancy that works with law firms, governments, corporations, and private investigators

View Details

A new report from the Bipartisan Policy Center (BPC) lays out — in stark terms – the prominent cybersecurity risks of the moment.

Related: Pres. Biden’s impact on cybersecurity.

The BPC’s Top Risks in Cybersecurity 2023 analysis calls out eight “top macro risks” that frame what’s wrong and what’s at stake in the cyber realm. BPC is a Washington, DC-based think tank that aims to revitalize bipartisanship in national politics.

This report has a dark tone, as well it should. It systematically catalogues the drivers behind cybersecurity risks that have steadily expanded in scope and scale each year for the past 20-plus years – with no end yet in sight.

Two things jumped out at me from these findings: there remains opportunities and motivators aplenty for threat actors to intensify their plundering; meanwhile, industry and political leaders seem at a loss to buy into what’s needed: a self-sacrificing, collaborative, approach to systematically mitigating a profoundly dynamic, potentially catastrophic threat.

Last Watchdog queried Tom Romanoff, BPC’s technology project director about this analysis. Here’s the exchange, edited for clarity and length:

LW: Should we be more concerned about cyber exposures than classic military threats?

Romanoff: Classic military threats will always merit significant concern due to their direct impact on life. But for most Americans, cyberattacks are a lot more likely to happen. They can cause severe economic or social disruptions and impact a broad crosscut of our society.

Incidents of nations using cyberattacks as an extension of military operations to disrupt or destabilize targets are on the rise. As part of criminal enterprises or economic warfare, nation-states using cyber-attacks can inflict damage without firing a shot and extend power beyond their borders.

Our report connects the threats from particular nation-states and showcases how this can accelerate risks for non-military organizations.

LW: Regulation hasn’t seemed to help much; data security rules have been highly fragmented, i.e., Europe vs. the U.S. and even state-by-state in the U.S.

Romanoff: Concerns about data privacy and cybercrime are fast-tracking the push for regulations. In the U.S., tech has enjoyed “permissionless innovation” for much of its industrial existence.

As Congress continues to debate the role of Big Tech, increased state-level regulations, and worldwide regulations, policymakers are increasingly pressured to do something to increase data protections.

Romanoff

California is leading the effort at the state level and has passed the California Consumer Privacy Act (CCPA). Similar bills, including many data privacy bills, follow California’s lead. For example, Colorado, Connecticut, Utah and Virginia have all signed privacy laws in the last few years, and fifteen other states are considering privacy laws.

The push for a national data privacy law would have an immediate and quantifiable impact, but sadly progress is stalled. Without a national data privacy law or laws, we are left with a fragmented regulatory landscape.

The EU is moving much faster to regulate digital security. Between the General Data Protection Regulation (GDPR), Digital Services Act (DSA), the Digital Markets Act (DMA), and the emerging ePrivacy Regulation, the EU is framing the data security debate worldwide.

The overall impact of regulations has been on how businesses collect, process, and protect personal data. There will continue to be a push to increase transparency and accountability around data handling practices. For example, the recent FTC complaint regarding GoodRX and the Illinois case against White Castle for violations of the Biometric Information Privacy Act (BIPA) show that the norm is trending toward increased oversight.

LW: So what difference can regulation actually make in the next few years?

Romanoff: We should expect the government to break from the self-governance/marketplace regime that has been in place and move away from incentive-based cyber compliance. I expect to see more penalties for data leaks or non-compliance.

DMA and other EU regulations will come online, creating compliance hurdles for American companies.

We can also expect the U.S. government to work toward more oversight mechanisms by finding authorities that can be interpreted through a data-security lens.

LW: It’s certainly not a surprise that nightmare breaches keep happening; your report calls out lagging corporate governance as a major variable.

Romanoff: Cybersecurity in many organizations is considered a cost, not an investment. Too often, cyber leaders are not included in board discussions or c-suites, and thus cybersecurity isn’t integrated into business decisions. This will continue to be a challenge until security is built into the business model or product from the beginning.

For example, one of our working group members talked about the need to create software development teams that knew cybersecurity just as well as UX/UI. Traditionally these are different teams- one team builds the software product, and another one tests it for vulnerabilities.

When you have a team that builds a product with cybersecurity as part of its functionality, that’s when you have full integration. It’s the same for corporate governance- when cyber is built into a product, we know this risk is being meaningfully addressed.

LW: Will infrastructure threats and/or disruptions be a catalyst?

Romanoff: Infrastructure and utility disruptions pull cybersecurity from the abstract into reality for most Americans. These sectors continue to be targeted, and events like the Colonial Pipeline shutdown pushed government agencies and companies to prepare for attacks.

No system, no matter how well protected, is 100 percent safe from attack. What is important to highlight is the resilience and contingency planning that organizations should build into their strategy before being the disruption case study.

I commend the work that CISA and DHS are doing to help organizations build out that resiliency. By partnering with cyber leaders in these sectors, CISA is working to mitigate risks before they become disruption events.

LW: What is an optimistic scenario for shrinking the trajectory of cybersecurity risks, as laid out in this report?

Romanoff: Hopefully, some of these risks will be addressed and become part of standard resilience and contingency planning. However, eight of the risks we identified are not new. They have been a concern for some time.

We hope that the framing of this report will spur action, especially at the policy level, to allocate the necessary time and resources. Our report is a baseline for 2023, and we hope to update it as new risks emerge or as risks are addressed meaningfully, mitigating their impact.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

This year has kicked off with a string of high-profile layoffs — particularly in high tech — prompting organizations across all sectors to both consider costs and plan for yet another uncertain 12 or more months.

Related: Attack surface management takes center stage.

So how will this affect chief information security officers (CISOs) and security programs? Given the perennial skills and staffing shortage in security, it’s unlikely that CISOs will be asked to make deep budget or staffing cuts, yet they may not come out of this period unscathed.

Whether the long anticipated economic downturn of 2023 is a temporary dip lasting a couple quarters or a prolonged period of austerity, CISOs need to demonstrate that they’re operating as cautious financial stewards of capital, a role they use to inform their choices regardless of the reality — or theater — of a recession.

This is also a time for CISOs to strengthen influence, generate goodwill, and dispel the perception of security as cost center by relieving downturn-induced burdens placed on customers, partners, peers, and affected teams.

For CISOs to achieve these goals, here are five recommended actions:

Tie security to the cost of doing business. CISOs should not allow their board or executive team to continue believing that cybersecurity exists solely as a cost center. In other words, they shouldn’t detail how cybersecurity spending drives revenue and that cuts to the security program directly affect relationships and requirements with three key constituencies: customers, insurers, and regulators.

Instead, they should defend their security budget by quantifying investments in required security controls — and how much revenue is generated from the systems those controls protect. Ultimately, cybersecurity can become a profit center when customers, insurers, and regulators require it.

Demonstrate secure practices to customers. Your customers’ security teams are navigating the same downturn pressures. They still need to collect audit and security information from vendors and they may have fewer employees to complete the work. CISOs should prioritize security initiatives that drive the top line and increase customer stickiness, such as bot management solutions that improve customer experience, then they should inform customers of the steps taken to thwart costly application attacks.

These include such initiatives as monitoring for denial of wallet attacks in serverless functions, minimizing bot fraud, and keeping an eye on bug bounty program costs. Lastly, CISOs should automate processes such as security questionnaire responses and software bill of materials generation to give customers what they need before they ask for it.

•Support (as you influence) peers in other functions. Now is the time for CISOs to focus on key corporate objectives and ensure that their security initiatives demonstrate traceable alignment. If you didn’t start this practice in your early days as a security leader, take the time now to schedule regular meetings with peers across functions to stay current on their challenges, security needs, and points of friction.

From there, develop joint initiatives that further corporate objectives and provide services, resources, or assistance in the form of partial funding or staffing and friction-remediation efforts. This ethical politicking will make funding or resource allocation discussions more amicable. It will also extend goodwill toward the security organization in the future, when CISOs may need allies and evangelists to push through policy or process changes.

•Stop backfilling open positions (for now). No security leader wants to ask an already overwhelmed team to do more with less. Not backfilling certain roles, however, reduces costs voluntarily and minimizes the need for future involuntary cuts. For CISOs, this requires excellent communication and management skills when explaining to their teams why these roles will stay vacant.

Burn

This should include succession planning, associated upskilling, and job shadowing efforts for those who stick around. Provide an expected duration for the hiring freeze and work with regional nonprofits to bring on cost-effective cybersecurity apprentices — relieving some of the pressure while creating a pipeline of experienced talent at the ready when the freeze lifts.

•Resist the temptation to consolidate your partner ecosystem. Although cutbacks in this area may appear to be a practical cost-saving strategy, overcorrection in key areas such as cybersecurity, risk, and compliance could increase concentration risk, expose firms to disruption, and severely affect your operations. Given economists’ estimates that modern recessions last 10 months, CISOs should consider in their decision-making the time it takes to fully onboard a strategic supplier — typically six months or more — so they can ensure that they don’t miss out on opportunities when the economic pendulum swings in the opposite direction.

The outlined actions must be executed deftly at a time when instilling and maintaining trust with customers, employees, and partners is a business imperative. They also become crucial when factoring in how current geopolitical events and technology innovations continue to fuel a highly sophisticated and evolving threat landscape.

About the essayist: Jess Burn is a Forrester senior analyst who covers CISO leadership & security staffing/talent management, IR & crisis management, and email security.

View Details

APIs (Application Programming Interfaces) play a critical role in digital transformation by enabling communication and data exchange between different systems and applications.

Related: It’s all about attack surface management

APIs help digital transformation by enabling faster and more efficient business processes, improving customer experience, and providing new ways to interact with your business.

Whether an API is exposed for customers, partners, or internal use, it is responsible for transferring data that often holds personally identifiable information (PII) or reveals application logic and valuable company data.

Therefore, the security of APIs is crucial to ensure the confidentiality, integrity, and availability of sensitive information and to protect against potential threats such as data breaches, unauthorized access, and malicious attacks.

API security is essential for maintaining the trust of customers, partners, and stakeholders and ensuring the smooth functioning of digital systems. If API security is not properly implemented, it can result in significant financial losses, reputational damage, and legal consequences.

So, how can you ensure your API security is effective and enable your digital transformation?

Attack vector awareness

Hackers want to intercept and exploit API vulnerabilities to gain access to API endpoints and data. Over the last few years, we have observed that APIs are the favorite attack vector for hackers.

The losses to US companies due to API data breaches are estimated between $12 billion – $23 billion in 2022 alone, in an article in DarkReading. A study by the Marsh McLennan Cyber Risk Analytics Center and Imperva analyzed 117,000 unique cybersecurity incidents and estimated that API security issues result in US$ 41 to 75 billion of losses annually.

Why traditional approaches to securing APIs are not sufficient

Rao

As the adoption of APIs grows, the demand for security solutions increases. But, we have seen that the traditional approaches to securing APIs, such as basic authentication and IP whitelisting, are no longer sufficient in today’s rapidly evolving digital landscape.

Organizations must adopt a modern, comprehensive approach to API security that includes a combination of technical controls, policies, and processes to secure APIs effectively in today’s dynamic digital landscape.

To address this demand, a number of vendors have entered the market to provide solutions to help businesses secure their APIs. However, many of these vendors are providing solutions for managing APIs, not for securing these APIs. For example, security monitoring tools are not able to track API usage and activity. Due to this, these tools aren’t able to provide any actionable insights based on the data they collect.

API observability

Businesses can secure APIs with the “Shift-left and Automate-Right” approach across the entire API lifecycle.

Securing APIs across their entire lifecycle involves multiple stages, including design, development, testing, deployment, configuration, and maintenance. Each stage requires different security measures to ensure the confidentiality, integrity, and availability of sensitive information.

There are several models for API security that organizations can adopt to secure their APIs like a five stage approach described below;

•Discover: Make sure you have a complete view at all times. Manual tracking is hard so Automate API asset tracking to gain total visibility; proactively track and notify any changes in APIs so there is no guesswork. Also unveil the hidden topology behind API and application traffic with reconstruction.

•Observe: Start analyzing and controlling what should really exist. Detect and alert for Zombie & shadow APIs within the ecosystem. Things can break anytime so having 360 degree API observability for SRE is important. Start with basics to secure against OWSAP Top10 and key them updated.

•Model: Define organization-wide best practices with the flexibility to extend by the domain teams. Define data constraints to protect against attacks. Detect and prevent suspicious activity before it causes damage. Measure and protect your API with rate limiting, authZ and authN, data validation, versioning, and error handling.

•Act: Enforce best practices seamlessly without becoming a bottleneck to Increase API accuracy & resilience. Set up API Audits to track API calls, API responses, API errors, and API data accuracy. Monitor API for detailed API reports on API health, API usage, and API Performance. Automate API testing to track API behavior.

Insights: Derive insights holistically and not just at each API level. Maintain high standards with automated maturity scorecards. Make service ownership a reality. Set standards, give guidance, and measure adoption. Build a Culture of Continuous improvement.

By implementing security measures at each stage of the API lifecycle, organizations can ensure that their APIs are secure, and that sensitive information is protected against potential threats.

Together, these elements form the foundation for a practical approach to securing APIs. Continually reviewing your API security is a best practice for good governance.

About the essayist: Rakshith Rao is the co-founder and CEO of API lifecycle management tool APIwiz. Rak brings 17 years of experience in enterprise technical sales leadership, including at Apigee and Google, DataStax, and HP.

View Details

The IT world relies on digital authentication credentials, such as API keys, certificates, and tokens, to securely connect applications, services, and infrastructures.

Related: The coming of agile cryptography

These secrets work similarly to passwords, allowing systems to interact with one another. However, unlike passwords intended for a single user, secrets must be distributed.

For most security leaders today, this is a real challenge. While there are secret management and distribution solutions for the development cycle, these are no silver bullets.

Managing this sensitive information while avoiding pitfalls has become extremely difficult due to the growing number of services in recent years. According to BetterCloud, the average number of software as a service (SaaS) applications used by organizations worldwide has increased 14x between 2015 and 2021. The way applications are built also evolved considerably and makes much more use of external functional blocks, for which secrets are the glue.

Poor practices

In the field, people often copy and paste secrets into configuration files, scripts, source code, or private messages without considering the consequences. Source code repositories are cloned and take with them hard-coded credentials, resulting in an explosion of “secrets sprawl.”

To understand the magnitude of the problem, each year, GitGuardian publishes the number of secrets that have been mistakenly published on GitHub, the world’s first code-sharing platform. Thus, in 2021, more than 6 million secrets have leaked between the lines of code of developers, that is to say, more than 16,000 per day on average!

The projects hosted by the platform are mostly personal projects or open-source repos. Still, it is important to understand that these errors slip in easily and are difficult to identify and resolve. Even the most experienced developers can inadvertently publish this extremely sensitive information, giving access to the resources of the companies they work for.

Security specialists try to warn against the problem. Still, today the priority of boards of directors is to deliver value to customers faster than the competition, which means accelerating the development process. Combining flexibility and security is the source of all compromises, including when it comes to managing secrets.

It can be difficult to know where to start. That’s why we created a framework to help security managers evaluate their current posture and take steps to strengthen their enterprise secrets management practices.

Mitigating errors

You can start right away here with a straightforward (and confidential) questionnaire. The linked white paper explains the three stages of this process:

•Assessing secrets leakage risks

•Establishing modern secrets management workflows

•Creating a roadmap to improvement in fragile area

This model emphasizes that secrets management is more than just how an organization stores and shares secrets. It is a program that must coordinate people, tools, and processes, and also account for human error. Errors cannot be prevented, but their effects can be. That is why detection, remediation tools and policies, and secrets storage and distribution, are the foundations of our maturity model.

Segura

If you are wondering why secrets in code should be a priority among so many other vulnerabilities, just look at the recent security incidents of 2022: several major companies experienced the fragility of secrets management.

In September, an intruder accessed Uber’s internal network and found hardcoded admin credentials on a network drive. These secrets enabled the attacker to log in to Uber’s privileged access management platform, where many more plaintext credentials were stored. This gave the attacker access to Uber’s admin accounts in AWS, GCP, Google Drive, Slack, SentinelOne, HackerOne, and more.

In August, LastPass suffered a similar attack. Someone stole its source code which exposed development credentials and keys. Later in December, LastPass revealed that an attacker had used the stolen source code to access and decrypt customer data.

In fact, source code leaks caused major issues for many organizations in 2022. NVIDIA, Samsung, Microsoft, Dropbox, Okta, and Slack were among those affected. In May, we warned about the large number of credentials that could be harvested from these codebases: with these credentials, attackers can gain leverage and move into dependent systems in what is known as supply chain attacks.

In January 2023, CircleCI was breached. Hundreds of the continuous integration provider’s customers’ variables, tokens, and keys were compromised. CircleCI urged its customers to change their passwords, SSH keys, and any other secrets stored on or managed by the platform. Victims had to find out where these secrets were and how they were being used to take emergency action. This highlighted the need for an emergency plan.

Taking secrets seriously

Attacks have become more sophisticated, with attackers recognizing that compromising machine or human identities yields a higher return on investment. This is a warning sign of the need to address hardcoded credentials and secrets management.

Cybersecurity teams are taking hard-coded secrets in source code seriously. Companies understand that source code is now one of their most valuable assets and must be protected. A breach could result in business continuity issues, reputation damage, and legal proceedings.

The increasing prevalence of code and services means that software- and code-related risks will not dissipate any time soon. Hackers now target software practitioners’ credentials to gain access to IT infrastructure.

To combat these challenges, organizations must have visibility into vulnerabilities at all levels. This requires going beyond traditional practices and involving developers, security engineers, and operations in detection, remediation, and prevention.

Organizations must be prepared for secrets sprawl and have the right tools and resources in place to detect and remediate any issues in a timely manner. It’s time to take action!

About the essayist: Thomas Segura’s passion for tech and open source led him to join GitGuardian as technical content writer. Having worked both as an analyst and as a software engineer consultant for major French companies, he now focuses on clarifying the transformative changes that cybersecurity and software are going through.

View Details

A new generation of security frameworks are gaining traction that are much better aligned to today’s cloud-centric, work-from-anywhere world.

Related: The importance of ‘attack surface management’

I’m referring specifically to Secure Access Service Edge (SASE) and Zero Trust (ZT).

SASE replaces perimeter-based defenses with more flexible, cloud-hosted security that can extend multiple layers of protection anywhere. ZT shifts networks to a “never-trust, always-verify” posture, locking down resources by default and requiring granular context to grant access.

With most business applications and data moving to cloud and users connecting from practically anywhere, SASE and Zero Trust offer more versatile and effective security. Assuming, of course, that they work the way they’re supposed to.

Effective testing

Modern SASE/ZT solutions can offer powerful protection for today’s distributed, cloud-centric business networks, but they also introduce new uncertainties for IT. Assuring performance, interoperability, resilience, and efficacy of a SASE implementation can be tricky.

What’s more, striking the right balance between protecting against advanced threats and ensuring high Quality of Experience (QoE) is not easy when new DevOps/SecOps tools are pushing out a 10X increase in software releases.

Effective testing becomes critical. Today’s highly distributed, intensely dynamic environment results in potentially thousands of hybrid cloud test cases that need to be continually verified. IT and security teams must address:

SASE assurance: Most Managed Security Service Providers (MSSPs) are bound by service-level agreements (SLAs) for the services they deliver, including SASE. Since there are no standard SASE key performance indicators (KPIs,) just determining how to validate SASE behavior can be problemat

ZT behavior: ZT frameworks grant access based on identity, policy, and context. Each of these elements must be validated across multiple security controls, like next-generation firewall (NGFW) and data loss protection (DLP) tools. Once again, there is no standard set of ZT test cases to guide this validation.

SASE applications: Applying strong security without impeding performance requires an understanding of the footprint, scalability, and robustness of different SASE application services in different cloud environments; these include NGFWs, application firewalls, secure web gateways, and more.

Edge NFs: Even when offered as a single “solution,” SASE edge clouds can include multiple proprietary NFs (SD-WAN, NGFW, ZT) each with its own API and management tool. These all need to be validated.

Security policy: Successfully enforcing policy in a SASE environment starts with validating security rule sets. With evolving threats and ongoing network changes, that can’t be a one-time job. Next-gen automated test tools can be leveraged to continually re-validate policies.

Testing principles

Clearly, SASE/ZT testing merits serious consideration, and the right test cases for one organization won’t necessarily map to another. Here are four pillars of effective SASE testing:

Test across all deployment environments. SASE architectures must be validated end to end—from users and branches, through SASE points of presence, to cloud application servers. Additionally, performance needs to be profiled across all networks and SASE behavior measured across all architectures—virtualized, containerized, and bare metal

Jeyaretnam

Test for the real world. Specific SASE KPIs unique to a company’s operating environment need to be identified. Simulating generic traffic patterns can be misleading. Care must be taken to ensure testing reflects real-world network and application traffic profiles.

Accurately simulate vulnerabilities. Realistic threat models likewise should be used to validate SASE security efficacy—including simulating the evasion and obfuscation techniques that real hackers use. And since malware and vulnerabilities constantly change, threat models must continually evolve too.

Prioritize QoE. The best all-around metric for SASE/ZT testing is QoE, as it reflects multiple underlying factors, including performance, error detection, encryption variability, overall transaction latency, and (for ZT) concurrent authentication rate. Security controls that impede important business activities, will motivate users to try to bypass them.

Despite the complexity of SASE/ZT validation, it’s easy to understand what effective testing looks like. The right tools in place can continually test a full range of use cases across all environments.

Organizations can draw on a new generation of automated, always-on SASE/ZT testing tools. These systems integrate automated continuous security and QoE providing the dynamic protection companies expect and need.

About the essayist: Sashi Jeyaretnam is Senior Director of Product Management for Security Solutions, at Spirent, a British multinational telecommunications testing company headquartered in Crawley, West Sussex, in the United Kingdom.

View Details

Of the numerous security frameworks available to help companies protect against cyber-threats, many consider ISO 27001 to be the gold standard.

Related: The demand for ‘digital trust’

Organizations rely on ISO 27001 to guide risk management and customer data protection efforts against growing cyber threats that are inflicting record damage, with the average cyber incident now costing $266,000 and as much as $52 million for the top 5% of incidents.

Maintained by the International Organization for Standardization (ISO), a global non-governmental group devoted to developing common technical standards, ISO 27001 is periodically updated to meet the latest critical threats. The most recent updates came in October 2022, when ISO 27001 was amended with enhanced focus on the software development lifecycle (SDLC).

These updates address the growing risk to application security (AppSec), and so they’re critically important for organizations to understand and implement in their IT systems ASAP.

Updated guidance

Let’s examine how to put the latest ISO guidance into practice for better AppSec protection in enterprise systems. Doing so requires organizations to digest what the ISO 27001 revisions mean for their specific IT operations, and then figure out how best to implement the enhanced SDLC security protocols.

The new guidance is actually spelled out in both ISO 27001 and ISO 27002 – companion documents that together provide the security framework to protect all elements of the IT operation. The focus on securing the SDLC is driven by the rise in exploits that target security gaps in websites, online portals, APIs, and other parts of the app ecosystem to exfiltrate data, install ransomware, inflict reputational damage, or otherwise degrade enterprise security and the bottom line.

The revised ISO standard now stipulates more-robust cybersecurity management systems that reach all the way back into the SDLC to ensure that applications are inherently more secure as developers build them. In fact, for the first time, security testing within the SDLC is specifically required. And ISO 27001 specifies this testing should go beyond traditional vulnerability scanning toward a more multi-level and multi-methodology approach.

Achieving compliance

In seeking to secure the SDLC for ISO compliance, organizations will likely need to rely on a spectrum of testing tools working together to identify and prioritize the most critical threats. Here are 3 strategic priorities to help guide these efforts:

•Take a comprehensive, multi-level and multi-methodology approach – This includes employing multiple types of security testing in a single scan; setting up secure version control with formal rules for managing changes to existing systems; and applying security requirements to any outsourced development.

•Promote secure and agile coding practices – This includes subjecting deployed code to regression testing, code scanning, penetration, and other system testing; defining secure coding guidelines for each programming language; and creating secure repositories with restricted access to source code.

•Infuse security into application specifications and development workflow – This includes defining security requirements in the specification and design phase; scanning for vulnerable open-source software components; and employing tools that detect vulnerabilities in code that is deployed but not activated.

Comprehensive scanning

At the CTO and CIO level, these principles help guide the enterprise-wide strategy for ISO compliance. At the developer level, they will fundamentally reshape how programmers do their work day in and day out – including employing more project management tools and secure system architecture frameworks to track and mitigate risks at any stage in the SDLC.

Sciberras

The key throughout is to adopt a more holistic and comprehensive testing approach that aligns with the ISO 27001 requirements, since traditional vulnerability scanning is not powerful or proactive enough to secure the SDLC. The easiest way for organizations to mature their capabilities along these lines is to integrate a range of advanced AppSec testing protocols.

For example, the right AppSec partner can empower security teams with a blend of dynamic application security testing (DAST), interactive application security testing (IAST), and software composition analysis (SCA) together in a single scan. These combined testing approaches help secure all stages of development, as well as production environments, without negatively impacting delivery times.

Recent updates to the ISO 27001 standard bring a much-needed focus to securing the entire SDLC. In working to comply with the revised standard, security and development teams are realizing that a blend of multiple, complementary testing protocols is needed to catch and even prevent issues far earlier in the development process.

These efforts will help elevate security right alongside achieving the designed functionality as the ultimate goals in every DevOps project.

About the essayist: Matthew Sciberras, CISO, VP of Information Security, at Invicti Security, which supplies advanced DAST+IAST (dynamic+interactive application security testing) solutions that helps organizations of all sizes meet ISO 27001 compliance.

View Details

The attack surface of company networks is as expansive and porous as ever.

Related: Preparing for ‘quantum’ hacks

That being so, a new book, Fixing American Cybersecurity, could be a long overdue stake in the ground.

This is a well-reasoned treatise collaboratively assembled by board members of the Internet Security Alliance (ISA.) Laid out in two parts, Fixing American Cybersecurity dissects the drivers that got us here and spells out explicitly what’s at stake. It also advocates a smarter, more concerted public-private partnership as the core solution.

Part one of the book catalogues how cyber criminals and US adversaries have taken full advantage of systemic flaws in how we’ve come to defend business and government networks. Part two is comprised of essays by CISOs from leading enterprises outlining what needs to get done.

I had the chance to query Larry Clinton, ISA’s president and CEO, about the main themes laid out in Fixing American Cybersecurity. ISA is a multi-sector trade group focused on policy advocacy and developing best practices for cybersecurity.

We discussed this book’s core theme: a fresh set of inspired public-private strategies absolutely must arise and gain full traction, going forward, or America’s strategic standing will never get healed. Below are highlights of our discussion, edited for clarity and length.

LW: Your juxtaposition of China’s approach to cyber strategy vs. the U.S. is chilling. How does China’s deployment of spy balloons tie in?

Clinton: The balloons are simply the latest “shiny thing” that captures our attention – much like Tic-Toc. The US needs to be more aware of China’s broader, surreptitious digital strategy.

China has aggressively assembled a vast and growing technology base to expand its influence, and, when needed, spy on the rest of the world. Until a few years ago Huawei was a little-known vendor of phone switches. Today it is the world’s largest manufacturer of telecom equipment, including critical 5-G equipment.

China funneled tens of billions of dollars of direct and indirect assistance to Huawei. These subsidies have enabled Huawei to literally make offers too good to refuse to governments in Asia, Africa, Europe and Latin America – and even in rural portions of the US.

Huawei is just one example of the breadth and depth of China’s digital strategy. Alibaba controls the world’s largest money market fund and handles more payments than Mastercard. Baidu is extending into deep- learning markets, such as brain-inspired neural chips – all under China’s state-run umbrella. And Tencent combines the functionality of Facebook, iMessage, PayPal, UberEATS, Instagram, Expedia, Skype, WebMD, GroupMe and many others into a single ecosystem.

China’s strategy isn’t just playing in entertainment venues, it plays in terms of enhancing their military readiness, altering the basis for US oriented international allies, creating sustainable pathways to intercept our communications, replacing the dollar as the world’s dominant currency and even changing the way technical standards will be written.

It’s a lot more than balloons and cute Tik Tok dances.

LW: Given our cultural/political divergence, how can the US hope to match China’s cyber strategy?

Clinton: The sad reality is that the US and Europe have nothing in comparison to the comprehensive, integrated digital strategies of the Chinese Communist Party. The same is true, in a different sense, with Russia and the massive cybercriminal eco-system it has instigated.

Ironically, the western values of free markets and private enterprise are probably a better match for the dynamic parameters of the digital age. However, we need to better leverage the advantages of the free market system more effectively to win in this highly competitive struggle.

Certainly, our technical systems are vulnerable, but all critical infrastructure are vulnerable, yet we hardly ever hear of these physical systems being attacked. On the other hand, our cyber systems are attacked all day, every day.

This is because economic incentives favor the attackers. Attack methods are easy – and incredibly cheap – to acquire. Cybercrime is immensely profitable and there is no law enforcement.

The Chinese understood from this the beginning . . . We will need to match our adversaries by creating a modern, more sophisticated public-private partnership consistent with democratic ideals.

LW: Nightmare breaches keep happening. How can we tell that paradigm has shifted, for the better; what will that look like in the corporate sector?

Clinton: In the corporate world the paradigm is already beginning to switch toward a more productive approach to cybersecurity. We’re seeing corporate boards address cybersecurity as a strategic business function as opposed to the traditional tech-centric model.

This innovative approach has been led by the National Association of Corporate Directors, which has published a series of Cyber Risk Oversight Handbooks in partnership with the Internet Security Alliance. There are now a dozen of these handbooks available in six languages across five continents.

These handbooks, together with their companion book Cybersecurity for Business, provide both principles and tool-kits that can be used to implement this novel model of cyber risk oversight and management.

The adoption of these principles and toolkits has been stimulated by research that indicates that use of the handbooks actually improves cybersecurity.

LW: One could argue digital Pearl Harbor has occurred several times already. Must we still hope for a massive digital disruption to be a catalyst?

Clinton: The notion that there would be some 9/11 style event that would shock the Congress into action was always a myth. The founder of my organization was a former Chairman of the House Intelligence Committee, Dave McCurdy, who used to say Congress does two things well, nothing and over-react.

Clinton

Arguably we are still in the do-nothing – or comparatively little — stage but that is much better than over-reacting. Progress is being made, albeit too slowly. DHS’s Cybersecurity and Infrastructure Security Agency (CISA) has shown some real promise, starting with the securing of our elector process.

The creation of an Office for the National Cyber Director is also a step in the right direction –although that, too, is brand new with too limited a perspective and not nearly enough funding – but these are steps down a very long road.

The most progress is being shown in the private sector. Corporate boards are leaving behind their antiquated techno-centric models and restructuring to address cybersecurity from a strategic perspective.

LW: What will redirecting the trajectory of cybersecurity in the US look like?

Clinton: The most optimistic new initiative is the creation of a new national, virtual service academy for cybersecurity, which was included in the most recent National Defense Authorization Act (NDAA). This, if properly funded, is the most promising vehicle to finally address the massive cyber-workforce issue.

Nothing can work unless we have enough trained people. This is an economics issue – supply and demand. To solve this problem, we need to stimulate demand. A virtual service academy would operate much as the traditional service academies except it would use digital and distance learning techniques.

Once properly up and running, we estimate we can generate up to 10,000 new students a year which would solve the federal government’s workforce issue in less than four years.

Upon completing their government service obligation, the graduates would likely go into cybersecurity in the private sector – where they will still be serving the country — by defending cyber-attacks and thereby continuing to help resolve the workforce problem.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.

View Details

Well-placed malware can cause crippling losses – especially for small and mid-sized businesses.

Related: Threat detection for SMBs improves

Not only do cyberattacks cost SMBs money, but the damage to a brand’s reputation can also hurt growth and trigger the loss of current customers.

One report showed ransomware attacks increased by 80 percent in 2022, with manufacturing being one of the most targeted industries. Attack that drew public scrutiny included:

•Ultimate Kronos Group got sued after a ransomware attack disrupted its Kronos Private Cloud payment systems, relied upon by huge corporations such as Tesla, MGM Resorts and hospitals That ransomware attack shut down payroll and human resources systems.

•The Ward Hadaway law firm lost sensitive client data to ransomware purveyors who demanded $6 million, or else they’d publish the data from the firm’s high profile clients online.

•The Costa Rican government declared a national emergency, after attackers crippled govenrment systems and demanded $20 million to restore them go normal.

•The Glenn County Office of Education in California suffered an attack limiting access to its own network. They paid $400,000 to regain access to accounts and protect prior and current students and teachers, whose Social Security numbers were in the data.

Amos

These are just a handful of examples of ransomware attacks in the last year. Some victims paid the ransom while others restored their systems without payment. Those that paid the blackmailers came to the conclusion that restoring revenue generating operations, via rewarding criminals, was their best option.

Why not to pay

However, the U.S. Department of the Treasury warns against paying ransoms, citing the 37% annual increase in reported cases and 147% increase in costs. Paying doesn’t guarantee your business won’t be hacked again. It also spurs on the cybercriminals, showing them such attacks are profitable.

The U.S. Treasury says paying ransomware ransoms just encourages hackers to come up with bigger and bolder demands over time.

So wWhy would a business pay out money instead of cleaning up the mess and securing its systems? Some reasons include:

•Lack of resources to clean up the hacked files.

•Loss of money from downtime exceeds the ransom.

•To prevent damaging information from becoming public

Many business owners are also embarrassed they allowed criminals into their systems. They worry it makes them look careless and they want to cover the situation up by whatever means necessary.

Disincentivizing payment

What are some key ways of discouraging businesses from paying ransoms? Teach them to keep a full backup of all data. It’s much easier to restore lost information if the brand has a copy of it.

A plan of action is vital in the case of any hack. Taking steps to lock down information fast minimizes damage. Send out immediate notices to customers and ask them to reset their passwords, and inform them their data may be exposed to the dark web.

Report any hacking attempts or ransomware demands to the FBI or the authority in the business’s location.

Paying ransom to hackers only encourages them to attack other business owners, governments, and educational institutions. It’s best to stay away from paying out any funds in cryptocurrency or otherwise. Lean toward spending money on cleanup and restoration rather than a payoff.

About the essayist: Zac Amos writes about cybersecurity and the tech industry, and he is the Features Editor at ReHack. Follow him on Twitter or LinkedIn for more articles on emerging cybersecurity trends.

View Details

The United States will soon get some long-awaited cybersecurity updates.

Related: Spies use Tik Tok, balloons

That’s because the Biden administration will issue the National Cyber Strategy within days. Despite lacking an official published document, some industry professionals have already seen a draft copy of the strategic plan and weighed in with their thoughts. Here’s a look at some broad themes to expect and how they will impact businesses:

•New vendor responsibilities. Increased federal regulation puts more responsibility on hardware and software vendors compared to the customers who ultimately use their products.

Until now, people have primarily relied on market forces rather than regulatory authority. However, that approach often leads to bug-filled software because makers prioritize new product releases over ensuring they’re sufficiently secure.

These changes mean business representatives may see more marketing materials angled toward what hardware and software producers do to align with the new regulations. Product labeling may also become easier to understand, acting somewhat like food nutrition labels, except centered on security principles.

Coverage of the strategic security program from people with firsthand knowledge of the draft document suggests congressional action or executive authority will regulate how all critical sectors handle cybersecurity. It’s still unclear what that looks like in practice, but it certainly signifies a major change.

•Expanded cybersecurity budgets. Statistics suggest almost 50 percent of employees have never received cybersecurity training. It’s also easy to find research elsewhere highlighting how workers frequently make errors that might seem meaningless but ultimately expose files or corporate networks to cyberattacks and other risks.

The heightened awareness as more people became aware of the Biden administration’s plan helped spur a change that caused elevated stock market activity for several cybersecurity companies. This may have happened because people at more companies recognized the need for such products. After all, cybersecurity awareness training for employees is vital, but it can only go so far. Businesses must also invest in specialized tools for network monitoring and security.

However, those familiar with the content of the strategic cybersecurity program say not to expect uniform standards to apply across industries. Previous U.S. presidents have tried that without getting the desired effects. That means it’s best to wait and see Biden’s intentions before increasing cyber investments.

•Critical infrastructure revisions. Analysts also believe part of Biden’s strategy for cybersecurity will rewrite a policy from President Obama’s era that provides stipulations for keeping essential infrastructure secure. It may also include details about which types of companies fall into that category. If so, entities like cloud providers might need to take additional steps to maintain security. The same would likely be true for utility, telecommunications and transportation businesses.

Flynn

However, it’ll take a while to implement even once the Biden administration’s plan is officially published. That gives all affected companies time to make any necessary adjustments, regardless of whether they’re categorized as critical infrastructure providers.

People working at businesses highly likely to need stronger cybersecurity under the new strategy should consider consulting with cybersecurity experts. Those parties can advise them about where gaps remain and how the business is already doing well by following best practices for security.

Big changes lie ahead for U.S. cybersecurity policies and practices. The previewed content of cybersecurity plans from the Biden administration indicates people should expect significant shifts from what past leaders have tried. However, even once the details of this cybersecurity strategic plan are publicized, it’ll take a while before whatever’s different is widely adopted. Business leaders should be ready to act but refrain from making any relevant decisions before getting the details straight from the source.

About the essayist: Shannon Flynn is managing editor of ReHack Magazine. She writes about IoT, biztech, cybersecurity, cryptocurrency & blockchain, and trending news.

View Details

When a company announces layoffs, one of the last things most employees or even company owners worry about is data loss.

Related: The importance of preserving trust in 2023

Valuable or sensitive information on a computer is exposed to theft or to getting compromised. This can happen due to intentional theft, human error, malware, or even physical destruction of servers. But it’s a real and growing risk to be aware of.

In 2020, Forbes reported that pandemic layoffs and remote work served to increase the risk of company data loss. Tesla, for example, suffered two cybersecurity events after layoffs back in 2018.

Data loss isn’t necessarily spiteful. Imagine an employee creates a spreadsheet showing all your clients and the main points of contact for each. She updates this sheet, but forgets to share it internally.

She gets laid off, and she takes the spreadsheet with her because she believes that the work she created at her job belongs to her. This may sound like an edge case, but a survey by Biscom found that 87 percent of employees took data that they themselves had created from their last job.

Data theft can also be deliberate and malicious. That same employee might use that spreadsheet as a bargaining chip in securing a new job with your competitor.

Data theft can also happen as a result of hackers. In the infamous 2014 Sony hack, an employee moving from Deloitte to Sony allegedly took sensitive data with him when he left. It is believed that the employee was storing employee information from both Sony and Deloitte in his computer, leading to the salaries of 30,000 Deloitte employees being leaked.

Data loss prevention is a concept that’s been around since the ‘90s, but in the age of AI, machine learning, natural language processing, and all those other fun new buzzwords, it’s taken on new relevance and significance.

With relaxed security measures due to remote work, disgruntled employees due to sudden mass layoffs, and logistical oversights due to reorganization, company data can fall through the cracks. To keep up, companies need to use technology to ensure their most important asset, their information, is safe.

Consolidated visibility

Eisdorfer

The first step is to know what you have. Then you can work on protecting it.

That’s why the first step in any layoff-proof data loss prevention strategy has to be the collection and categorization of all the company data that exists. This is both easier and harder thanks to a distributed system of information.

Data might be in spreadsheets, on Slack, on OneDrive, in custom databases, or any other number of off-premises cloud systems.

The best way to consolidate all that info is to use machine learning and artificial intelligence. First, identify all potential sources of data. You might also want to ensure you’re scanning all emails going in and out of the company.

Then, companies need to set up rules to determine what the AI identifies as what kind of data. For example, one priority is identifying personally identifiable information of your customers. You don’t want that leaving your data warehouses.

Another example is any kind of proprietary algorithm or system. For instance, if you’re Equifax, you don’t want any employee able to leave with your credit score algorithm.

Using a combination of AI and ML, you should be able to put together a comprehensive catalog of all company data.

Spotting anamolies

The next step is to train the AI to spot suspicious-looking behavior. For example, you might set it up so that when an employee starts downloading massive amounts of data, that gets flagged as suspicious.

You might also need to use technology that can use optical character recognition (OCR). For example, imagine instead of sharing that customer spreadsheet, our laid-off employee just takes a screenshot of it and emails it to herself.

Unless your data loss prevention strategy has OCR to read what screenshots are, you’d never be able to know that she walked off with that spreadsheet unless you manually went through every single one of her emails.

You also have to take steps to stop data loss from happening. For example, your system should include a rule to automatically log out any users downloading a high number of files. It should also limit access for any soon-to-be laid off employees to sensitive material.

And finally, in the case of non-malicious theft, you should be able to quickly scan any employee-generated data to ensure files like comprehensive customer databases don’t get lost just because nobody knows they exist.

One major component of data loss prevention is to map the organization’s critical information. With a map of who has access to what, the knowledge is less likely to get lost when employees move on. This enables companies to classify the information and prevent data loss, or at least educate employees not to take data with them to their next job.

You should also have set up your system to flag suspicious events, such as the mass downloading of files, laid-off employees sending lots of emails, or people logging in from unusual locations.

Your final step is to patch those holes. With AI on the case, it will auto-recognize suspicious events and take care of them. You can also be assured that important or sensitive information won’t fall through the cracks of mass layoffs.

Data loss is a real threat. Make sure your company is up to the job of handling it.

About the essayist:Guy Eisdorfer, is the co-founder and CEO of Cognni, a supplier of AI-powered data classification systems and other security products to enterprises and SMBs.

View Details

When a company announces layoffs, one of the last things most employees or even company owners worry about is data loss.

Related: The importance of preserving trust in 2023

Valuable or sensitive information on a computer is exposed to theft or to getting compromised. This can happen due to intentional theft, human error, malware, or even physical destruction of servers. But it’s a real and growing risk to be aware of.

In 2020, Forbes reported that pandemic layoffs and remote work served to increase the risk of company data loss. Tesla, for example, suffered two cybersecurity events after layoffs back in 2018.

Data loss isn’t necessarily spiteful. Imagine an employee creates a spreadsheet showing all your clients and the main points of contact for each. She updates this sheet, but forgets to share it internally.

She gets laid off, and she takes the spreadsheet with her because she believes that the work she created at her job belongs to her. This may sound like an edge case, but a survey by Biscom found that 87 percent of employees took data that they themselves had created from their last job.

Data theft can also be deliberate and malicious. That same employee might use that spreadsheet as a bargaining chip in securing a new job with your competitor.

Data theft can also happen as a result of hackers. In the infamous 2014 Sony hack, an employee moving from Deloitte to Sony allegedly took sensitive data with him when he left. It is believed that the employee was storing employee information from both Sony and Deloitte in his computer, leading to the salaries of 30,000 Deloitte employees being leaked.

Data loss prevention is a concept that’s been around since the ‘90s, but in the age of AI, machine learning, natural language processing, and all those other fun new buzzwords, it’s taken on new relevance and significance.

With relaxed security measures due to remote work, disgruntled employees due to sudden mass layoffs, and logistical oversights due to reorganization, company data can fall through the cracks. To keep up, companies need to use technology to ensure their most important asset, their information, is safe.

Consolidated visibility

Rittman

The first step is to know what you have. Then you can work on protecting it.

That’s why the first step in any layoff-proof data loss prevention strategy has to be the collection and categorization of all the company data that exists. This is both easier and harder thanks to a distributed system of information.

Data might be in spreadsheets, on Slack, on OneDrive, in custom databases, or any other number of off-premises cloud systems.

The best way to consolidate all that info is to use machine learning and artificial intelligence. First, identify all potential sources of data. You might also want to ensure you’re scanning all emails going in and out of the company.

Then, companies need to set up rules to determine what the AI identifies as what kind of data. For example, one priority is identifying personally identifiable information of your customers. You don’t want that leaving your data warehouses.

Another example is any kind of proprietary algorithm or system. For instance, if you’re Equifax, you don’t want any employee able to leave with your credit score algorithm.

Using a combination of AI and ML, you should be able to put together a comprehensive catalog of all company data.

Spotting anamolies

The next step is to train the AI to spot suspicious-looking behavior. For example, you might set it up so that when an employee starts downloading massive amounts of data, that gets flagged as suspicious.

You might also need to use technology that can use optical character recognition (OCR). For example, imagine instead of sharing that customer spreadsheet, our laid-off employee just takes a screenshot of it and emails it to herself.

Unless your data loss prevention strategy has OCR to read what screenshots are, you’d never be able to know that she walked off with that spreadsheet unless you manually went through every single one of her emails.

You also have to take steps to stop data loss from happening. For example, your system should include a rule to automatically log out any users downloading a high number of files. It should also limit access for any soon-to-be laid off employees to sensitive material.

And finally, in the case of non-malicious theft, you should be able to quickly scan any employee-generated data to ensure files like comprehensive customer databases don’t get lost just because nobody knows they exist.

One major component of data loss prevention is to map the organization’s critical information. With a map of who has access to what, the knowledge is less likely to get lost when employees move on. This enables companies to classify the information and prevent data loss, or at least educate employees not to take data with them to their next job.

You should also have set up your system to flag suspicious events, such as the mass downloading of files, laid-off employees sending lots of emails, or people logging in from unusual locations.

Your final step is to patch those holes. With AI on the case, it will auto-recognize suspicious events and take care of them. You can also be assured that important or sensitive information won’t fall through the cracks of mass layoffs.

Data loss is a real threat. Make sure your company is up to the job of handling it.

About the essayist:Dr. Danny Rittman, is the CTO of GBT Technologies, a solution crafted to enable the rollout of IoT (Internet of Things), global mesh networks, artificial intelligence and for applications relating to integrated circuit design.

View Details

Arguably one of the biggest leaps forward an enterprise can make in operational reliability, as well as security, is to shore up its implementations of the Public Key Infrastructure.

Related: Why the ‘Matter’ standard matters

Companies have long relied on PKI to deploy and manage the digital certificates and cryptographic keys that authenticate and protect just about every sensitive digital connection you can name.

Reliance on PKI is only intensifying – as a direct result of the rise of massively interconnected digital systems. This has created a daunting operational and security challenge for many enterprises.

The good news is that a new batch of technical standards and protocols, as well as advanced tools and services, are on the ascension, as well.

Guest expert: Mike Malone, founder and CEO of Smallstep

One technology start-up in the thick of helping companies more effectively “wrangle” PKI is San Francico-based Smallstep, as Mike Malone, founder and CEO, puts it.

Smallstep launched in April 2022 with $26 million in funding, including a seed round of $7 million led by boldstart ventures with participation from Accel Partners, Bain Capital Ventures and Upside Partnership, LLC., and a Series A of $19 million led by StepStone Group.

I recently had the chance recently to visit with Malone; we discussed how advances in automation can help companies begin to proactively manage the swelling volume of digital certificates and encryption keys that are part and parcel of the massively interconnected digital systems. For a full drill down, please give the accompanying podcast a listen.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Throughout 2022, we saw hackers become far more sophisticated with their email-based cyber attacks. Using legitimate services and compromised corporate email addresses became a norm and is likely to continue in 2023 and beyond.

Related: Deploying human sensors

Additionally, with tools like ChatGPT, almost anyone can create new malware and become a threat actor.

According to a recent report, small businesses (defined as those with under 250 employees) receive the highest rate of targeted malicious emails at one in every 323 emails, and 87 percent of those businesses hold customer data that could be targeted in an attack.

Another report by Vade completed last year found that 87 percent of respondents agreed their organization could take the threat from email security more seriously.

Intelligent defense

Small-to-midsize businesses (SMBs) continue to think they’re “too small to be a target.” This is a harmful misconception. Hackers may pick SMBs over larger companies for several reasons, namely because SMBs don’t have the same budget or resources dedicated to cybersecurity as large companies.

As attacks grow in number and sophistication, these smaller organizations will need technology that tightly integrates with modern productivity suites such as Microsoft 365 and/or Google Workspace that also provides comprehensive threat intelligence.

Secure email gateways (SEGs) are a common solution used by businesses both large and small to analyze emails for malicious content before they’re able to reach corporate systems. However, with the emergence of API-based or integrated email security solutions, SEGs have become obsolete.

Over the past couple of years, organizations have been opting for API-based email security solutions for reasons including increased visibility into productivity suites, easy deployment and ability to share threat intelligence from email with other applications used throughout the business operation.

Microsoft 365 and Google Workspace are the two most popular productivity suites used worldwide. While strides have been made to make both platforms more secure, it’s inevitable that when hackers run into roadblocks, they’re going to innovate their attack methods to sneak past whatever defenses stand in their way.

Consolidated visibility

The bottom line is, security operations centers (SOCs) and MSPs need solutions that allow them to quickly investigate and respond to email-borne threats transiting through networks without any misconfigurations that could harm, or even halt business operations.

One of the major challenges our customers have voiced to us is how difficult it is to monitor and manage threats from all their endpoints. They need better visibility into their cybersecurity landscape if they’re going to have any chance of protecting their assets effectively.

Additionally, IT teams are being overburdened by managing too many complex tools. They need solutions that allow for powerful integrations but consolidate the most important threat intelligence into simple dashboards.

Products that that speed up incident response times by automating remediation are going to become hot commodities as these suites continue to increase in popularity.

Wider protection

AI-based email solutions can tightly integrate with these suites to catch threats that Microsoft 365 and Google Workspace don’t identify…and perhaps more importantly, those solutions can learn from the threats they encounter to keep similar and more advanced ones from slipping past barriers in the future.

Gendre

In 2023, we predict MSPs and SMBs will invest in tools that integrate seamlessly with productivity suites, reduce incident response times, and lighten the load on IT teams, rather than invest in solutions that solely secure email.

We also predict hackers are already one step ahead and know these tools are going to become commonplace. It’s time for businesses small and large to level up their email security solutions with tools that can learn from and predict the bad guys’ next moves – not just move suspicious emails to spam.

About the essayist: Adrien Gendre is a co-founder of Vade and serves as its Chief Tech & Product Officer. Founded in 2009, Vade supplies AI-based cybersecurity technologies that help companies defend many types of email-borne attacks.

View Details

The decision by the House of Representatives to ban TikTok from federal devices is noteworthy, especially as the Chinese spy balloon crisis unfolds.

Related: The Golden Age of cyber espionage

On December 23, 2022, Congress, in a bipartisan spending bill, banned TikTok from all government devices. The White House, the Pentagon, the Department of Homeland Security, and the State Department have already banned the social media app, as have more than a dozen other states.

The Tik Tok decision combines national security, social media, and “China” in only one institution’s change of policy. It reflects the challenge that continued use of social media presents to those within the federal circle of trust.

The Chinese government, as well as other foreign powers, actively probe all aspects of American life for information useful in compromising the Republic’s national security interests. They are active not only in stealing the federal government’s data, but also doing the same in our private and public corporations.

And no one piece of information is the exclusive goal of any intelligence operation; all types of information are useful if they can be gained.

No member of the House of Representatives will be allowed to download the TikTok app on any House-issued mobile phone. This mirrors the general practice of prudent Executive Branch leaders, supervisors, managers, and employees.

Many refuse to use social media at all. It is very rare for a CIA or NSA employee to have, for instance, a Facebook account. Entering the federal circle of trust requires changes in one’s personal life. Americans of older generations were more comfortable with making these changes.

Necessary choice

Meyer

Not so much anymore. It is a choice the security community will force upon everyone seeking access, from a member of Congress down to an entry-level staff member at the Defense Intelligence Agency.

The underlying Tik Tok security concern is that the social media app can be used by a foreign power to collect intelligence or information useful in blackmailing the user into releasing classified information.

The user does not need intent to do the Republic harm; the term “unwitting fool” is used in security circles of trust for situations in which an otherwise well-meaning simpleton plays the pawn role in an intelligence operation.

Removing social media apps as a “door” to gain access to classified information denies the foreign intelligence service one means of access. But the impact is lessened if the federal leaders, supervisors, managers, and employees then substitute personal accounts for government accounts.

And while Congress controls its own security clearances, it must coordinate with the Executive Branch to gain access; if it fails to present a security-safe profile by taking actions like the Tik Tok decision, the national security establishment headed by the Director of National Intelligence for the President will just deny access. Congress collects no intelligence of its own. It is wholly reliant on the President in this federal activity.

Destructive access

The security profiling mechanism governing Executive Branch decisions in this area is Guideline M: Use of Information Technology. It is also used by House and Senate security personnel when they advise Members of Congress and their staffs.

Under Guideline M, not all social media characteristics trigger a security concern. But social media apps can be used to make an unauthorized entry into an information system; they can be entry points for the modification, destruction, or manipulation of an information system or data; they can be used to gain unauthorized access to a compartmented area used to store classified information; and they can promote negligence and lax security practices. The decision is not made to limit communication; it is made to limit theft.

McKinion

Many have been focused on the events of January 6th and the security profiles of members of Congress thought to have encouraged the protest or insurrection. But the event to focus on preceded January 6th. On the morning of October 23, 2019, members of the House of Representatives stormed the compartmented area used by the House intelligence committee to receive, view, and discuss classified information provided by the President through his intelligence agencies.

In violating the rules for handling classified information, the storming raised questions regarding the Congressional commitment to maintaining the discipline necessary to protect classified information. That same discipline is needed to not misuse Tik Tok or one’s private email. Given the question hanging over Congressional reliability, Tik Tok—and other entry points—have to go.

About the essayist: Dan Meyer, is Managing Partner of Tully Rinckey PLLC’s Washington, D.C. office. He is a member and Vice -Chair of the National Security Lawyers Association. Lachlan McKinion is a law clerk in Tully Rinckey’s Washington, D.C., office. He focuses on national security and security clearance law.

View Details

The cybersecurity profession can be very rewarding, but at the same time quite taxing.

Related: Equipping SOCs for the long haul

In fact, stress factors have risen to where some 45 percent of the security professionals polled in Deep Instinct’s third annual Voice of SecOps report said they’ve considered leaving the industry altogether.

Ransomware is at an all-time high; attackers are as elusive as ever. Thus the job of detecting an active adversary and stopping them before they can do material damage has become extremely difficult.

Some 91 percent of respondents reported feeling stress in their security roles, of which 46 percent stated that the level of stress had increased in the past 12 months.

Productivity disruptor

A significant proportion of security pros concede that stress is negatively impacting their ability to do their daily tasks at work; this is the result of a number of variables including:

•A gap between the number of qualified candidates to fill positions and experienced staff members; skilled security personnel are often poached for higher wages and larger responsibilities.

•An overwhelming number of security alerts leading some organizations to turn off warnings altogether.

•Elusive adversaries who continually re-invent new ways to execute attacks.

•Newly discovered software vulnerabilities and misconfigurations increasingly getting exploited before the organization has a chance to fix them.

Above all, the core exposure derives from an increasing number of unknown threats, according to a Divisional Head of Cybersecurity Compliance at a global motor manufacturer:

“The number of unknowns is increasing. The criminals know their existing malware signatures can be detected, so they are constantly looking to find new ways to attack. It’s like they’ve got Harry Potter’s invisibility cloak. We can never switch off.”

Hero mentality

Senior security leaders, i.e. CSOs and CISOs, need to be able to convey the risks that their teams face, especially to board members who can easily get lost in explanations of the endless technical nuances.

And the more senior the cybersecurity role, the more stressful the job. Amongst senior security leaders, the top stress factors were:

•Securing a remote workforce.

•Digital transformation affecting security.

•The threat of ransomware.

A UK-based CISO at a large police force puts it this way:

“We are too reliant on the hero mentality – we have some people who are working 16-18 hour days at times. That’s not sustainable, and we certainly shouldn’t be expecting people to put in those kinds of shifts as a part of our capability. They’ll burn out.”

Taming complexity

Here are a few ways security leaders can work to reduce stress:

•Lower the volume of alerts and reduce false positive rates. Overworked SOC teams have difficulty focusing on what really matters.

•Pull from resources from other departments, such as IT or even finance, to put an emphasis on securing the organization.

•Create clear goals and measurements of success; help security teams justify resource expenditures.

•Foster a culture of reward and positivity.

Crowley

There is a great amount of discussion around AI for use cases in cybersecurity. Our survey found that 82 percent of respondents would rather depend on AI over humans to hunt threats, and 53 percent agreed that greater automation is necessary to improve security operations.

However, not all AI is created equal. While machine learning has improved automation, it does not go far enough to make significant differences for SecOps teams.

By comparison, deep learning has been proven to provide a more preventative cyber posture for organizations. This can reduce alerts and false positives, and improve detection of actual threats bypassing controls today.

Overall, deep learning has been seen to improve not just the speed and scale of cybersecurity solutions, but the welfare and impact of security teams.

About the essayist: AKaren Crowley is the director of product marketing at Deep Instinct, a New York City-headquartered supplier of a purpose-built, deep learning cybersecurity framework.

View Details

Massively interconnected digital services could someday soon save the planet and improve the lives of one and all.

Related: Focusing on security leading indicators

But first, enterprises and small businesses, alike, must come to grips with software vulnerabilities that are cropping up – and being exploited – at a blistering pace.

Innovative vulnerability management solutions are taking shape to meet this challenge. One the newest and most promising spins out of the emerging discipline of machine learning operations, or MLOps.

One supplier in the thick of this development is a Seattle-based start-up, Protect AI.

Guest expert: D Dehghanpisheh, co-founder and CRO, Protect AI

I had the chance recently to visit with Daryan Dehghanpisheh, whose professional experience prior to co-founding Protect AI includes four years as the Global Leader of AI/ML Solution Architects at Amazon Web Services.

Protect AI launched in December 2022 with a $13.5 million seed round stake, co-led by Acrew Capital and boldstart ventures, on the basis of developing advanced tools to protect AI systems and machine learning models.

We discussed how the fledgling field of MLSecOps parallels the arrival and maturation of DevSecOps. “DevSecOps is putting security at the heart of everything you do from a DevOps perspective,” Dehghanpisheh told me. “We want to do the same thing with MLOps . . . treat security as an integral part of development, not just as an afterthought”

For a full drill down on how Protect AI hopes to mainstream MLSecOps – and how that could accelerate the arrival of massively interconnected digital systems — please give the accompanying podcast a listen.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

In an ideal world, cybersecurity analysts would get legitimate daily reports on improving a company’s security. Unfortunately, the likelihood of being handed unsolicited, untrustworthy advice is high.

Related: Tech giants foster third-party snooping

This is what fake bug reports are all about. Scammers now routinely spray out fake bug reports designed to take advantage of the naiveite and/or lack of vigilance of security analysts in the field.

Scammers will send reports known as bug bounties stating security vulnerabilities in a machine. The fraudster might claim it’s missing security credentials or necessary security software.

These often come as unsolicited phone calls or computer notifications and might sound convincing and well-intentioned, claiming they can solve all the vulnerabilities in the electronics if recipients buy the report.

Compounding risk

These engagements aim to extort money — and in the most severe circumstances with more advanced cybercriminal tactics — infect computers or steal data. Security analysts should be on high alert. Unless it’s someone from within an organization or part of a company’s employed team, a best practice is to second guess any experts claiming they have cybersecurity advice.

What may appear to be a legitimate cybersecurity query, may in fact be designed to flush out and exploit security in the system. Caution is the order of the day.

Amos

Fake bug reports can combine with other security threats to compound their impact. For example, they could also implement clickjacking — including false, actionable buttons or links that tempt unaware email recipients to redirect to malicious content.

Falling victim to a bug bounty can prove fatal to an organization’s cybersecurity risk assessment because accepting a deal informs cybercriminals that a company lacks security know-how. Ignorance like this invites subsequent attacks — probably in other forms — to coax more money out of the business.

These scammers are a security threat to honest, ethical hackers. They claim to be white hat hackers, which delegitimizes the services of trained and well-intentioned professionals. Companies undergoing multiple scams could eventually become distrusting of the industry entirely, developing complacency in a holistic cybersecurity strategy.

Best practices

Companies can instill bug bounty programs designed to incentivize independent white hat hackers to discover and responsibly report software vulnerabilities not on their radar. Recently, Salesforce has highlighted the issue, stating it had received over 4,000 bug reports in 2021 — so it’s invested millions in bug bounties.

As due diligence, businesses can seek the help of third parties or secure vulnerability tools to analyze the validity of a bug report. They can also formulate internal procedures for responding to vulnerability notices, such as who to contact in case of discovery and how triage looks. Training should be required to identify red flags so teams can discern between real and fake reports.

A legitimate, factual report will be specific and explain the ramifications of not adhering to the suggestions. The situations mentioned in the report will apply to particular systems in an organization, using precise terminology that aligns with a company’s established infrastructure. Vague language like “vulnerability” and “gap” to explain the issue is a tell the bug bounty is bogus.

Plus, companies can always search for copies of the bug reports online to see if the text looks like templates other businesses have received.

Another best practice is to always run bug bounty solicitations past trusted parties. No matter how knowledgeable or confident the offer sounds, the stranger is just trying to use others to exploit their own tech for a criminal’s gain. Fake bug reports are becoming rampant, and taking measures to stay safe and aware is crucial for personal and professional data.

About the essayist: Zac Amos writes about cybersecurity and the tech industry, and he is the Features Editor at ReHack. Follow him on Twitter or LinkedIn for more articles on emerging cybersecurity trends.

View Details

Small and medium-sized businesses are facing immense security challenges and these are the same as those of mid-size or larger enterprises.

Related: Myths about safe browsing

Clearly, SMBs need to be alert for cyberattacks, but they also need to stay focused on their business and not sacrifice productivity.

Organizations are confronted with a severe security threats landscape, and it is critical that they have the ability to prevent, detect and respond to these threats in a timely manner. Hence, using a threat prevention and detection solution that doesn’t disrupt day-to-day operations while providing early warning and stopping potential threats before they escalate is essential.

Our dependence on technology has grown and so has the number of ways that criminals can exploit vulnerabilities to gain access to sensitive information or disrupt critical systems. Today, businesses of all sizes must be vigilant in protecting their data and infrastructure from a wide variety of threats, including malware, phishing, and denial-of-service attacks.

While the threat landscape is constantly evolving, there are a few trends that we are seeing in the modern cybersecurity landscape:

•Increased use of AI and automation by attackers.

•A shift from traditional malware to ransomware.

•An increase in sophisticated phishing attacks.

•A rise in targeted attacks against specific industries.

Threat detection solutions can be used to protect against both known and unknown threats, and can be deployed as part of a simple or comprehensive security strategy, since some of their most significant benefits for an SMB or larger enterprise are:

•Quick identification and classification of threats, allowing businesses to respond in real-time and thus reducing the chances of a data breach or other security incidents.

•Advanced analytics to reduce false positives, giving businesses peace of mind that their security systems are working as intended.

•Centralized management, which simplifies identifying and responding to threats across an organization.

Leveraging AI

The market has shifted – I am currently seeing strong demand for the ability to reduce time spent on removing threats. Hence, the advancements being done to pre-analyze data for the operator are a big shift in what the market is trying to achieve.

Kjaersgaard

There are a number of different factors that have contributed to this shift, including the rise of sophisticated cyberattacks, the growing importance of your data security, and the need for your organization to be able to respond quickly to incidents for compliance. As a result, there is an increased demand for threat detection solutions that can provide faster and actually effective responses to threats.

Moreover, one of the most important trends in threat detection is the move toward artificial intelligence (AI). AI-powered solutions are able to quickly identify patterns in data that may indicate a security breach. They can also rapidly respond to threats, often before humans even realize there is an issue.

Another trend is the use of cloud-based solutions. Cloud-based threat detection solutions offer a number of advantages over traditional on-premises solutions, including lower costs, scalability, and easier management – all of them being strong requirements from SMB-sized organizations.

Role of managed services

Finally, many vendors are now offering managed security services that include threat detection as part of a consolidated package. This can be an attractive option for SMBs that don’t have the resources to invest in their own security team or infrastructure. EDR, NDR, XDR and MDR are all great alternatives that SMBs can choose to strengthen their security posture.

For SMBs that want control in their own hands and cannot afford SIEM/SOAR solutions, Heimdal is launching a groundbreaking new technology with our Threat-hunting and Action Center, which will open up a new category in the cybersecurity market and combine four key elements under one unified roof: detection, visualization, threat-hunting, and remediation. These attributes combined with Heimdal’s solutions will enable the tool to serve as a single point of contact for risk management.

Our upcoming product is powered by Heimdal’s XTP (eXtended Threat Protection) engine to provide real-time visibility, rich intel, contextual awareness, and data to identify, protect and react to sophisticated threats, in a very easy-to-use and fast action environment.

SMBs can stay ahead of the curve. The key is effective threat detection, which requires the right tools in place for your specific environment and needs. Thus, you can leverage the latest advances in threat detection and protect your business from a constantly evolving security threats landscape.

About the essayist: Morten Kjaersgaard is CEO of Heimdal Security

View Details

To get network protection where it needs to be, legacy cybersecurity vendors have begun reconstituting traditional security toolsets.

The overarching goal is to try to derive a superset of very dynamic, much more tightly integrated security platforms that we’ll very much need, going forward.

Related: The rise of security platforms

This development has gained quite a bit of steam over the past couple of years with established vendors of vulnerability management (VM,) endpoint detection and response (EDR,) and identity and access management (IAM) solutions in the vanguard.

And this trend is accelerating as 2023 gets underway. DigiCert’s launch today of Trust Lifecycle Manager, is a case in point. I had the chance to get briefed about this all-new platform, which provides a means for companies to comprehensively manage their Public Key Infrastructure (PKI) implementations along with the associated digital certificates.

I visited with Brian Trzupek, DigiCert’s senior vice president of product. As a leader of digital trust, DigiCert is best known as a Certificate Authority (CA) and a supplier of services to manage PKI. We drilled down on why getting a much better handle on PKI has become vital in a massively interconnected operating environment. DigiCert’s new solution is designed to “unify PKI services, public trust issuance and CA-agnostic certificate lifecycle management,” he told me.

Here are the main takeaways from our discussion:

PKI sprawl

Where would we be without PKI, the framework used to issue and manage digital certificates? We’ve come to rely on PKI to validate and authenticate all connections on websites and mobile apps – as well as all of the internal IT activity, company-to-company, that supports the digital services we now take for granted.

PKI is robust and ubiquitous; and it’s destined to serve that same essential role — as a linchpin validation and authentication mechanism – the further we progress into massively interconnected, highly interoperable digital services.

First, however, PKI sprawl must be mitigated, Trzupek argues. The problem looks something like this, he says: In today’s operating environment, PKI payloads arrive moment-to-moment from myriad sources: to and from web portals and mobile apps; in between cloud vs. on-premises IT infrastructure; up and down the software development supply chain. What’s more, digital certificates can get issued by different CAs, or by components manufacturers, or even internally by the enterprise itself.

Trzupek

“You’ve got this big, dynamic spaghetti of stuff coming into the network and interacting, using PKI to authenticate and there is very little the enterprise actually controls,” Trzupek observes. “Often times, the company doesn’t even realize all of these PKI interactions are taking place until something breaks and there’s an outage.”

Outages and attacks

DigiCert’s newest service, Trust Lifecycle Manager, tackles this connections chaos head on, by establishing a hub into which all PKI validation routines can get inventoried and continually managed.

The reduced risk of a major outage caused by an expiring digital certificate alone should grab attention. Just ask Epic Games. An expired certificate triggered an outage that caused Fortnite, its cash-cow video game, to go dark for several hours.

And then there’s the risk of ransomware purveyors or a nation state-backed spy flushing out and exploiting a weak seam in an obscure PKI connection, instigating a nightmare scenario. Just ask SolarWinds.

The SolarWinds attackers, believed to be Russian-backed, had to have subverted PKI at multiple levels. They were able to gain control of the build process that SolarWinds used to create and automatically issue software updates to its bread-and-butter Orion network management tool. This enabled the attackers to subsequently breach the networks of 18,000 Orion users.

PKI outages and attacks happen much more often than gets publicly disclosed, Trzupek says. The fundamental reason, he says, is the non-existence, at this point in time, of a practical way to compile a comprehensive PKI inventory across a typical enterprise.

“The guy who’s running identity access management is different than the guy in charge of encryption or the guy running DevOps,” he says. “And they’re not talking to each other . . . the encryption guys might be well-versed in PKI management policy, but the DevOps guys probably aren’t –and even if they were, they’re focused on getting code out and moving workloads a fast as possible.”

Taking a platform approach

With Trust Lifecyle Manager, DigiCert is making a lane change from a product company to a platform company. This new offering is something truly unique – a comprehensive service designed to foster centralized monitoring and management of all digital certificates throughout an enterprise. To start, DigiCert is partnering with Microsoft Azure, Amazon Web Services and Google Cloud to integrate PKI telemetry generated by those top-tier cloud infrastructure providers.

On the horizon, Trust Lifecycle Manager will be able to receive and process PKI-related telemetry originating from just about any private or public source, Tzupek told me.

“We already have about 100 integrations and later this year we’ll be opening up publicly so that anybody can come in and ride on top of the system,” Trzupek says.

By leveraging APIs, DigiCert intends to make it possible to “glue in without any help from us,” he says. “The idea is to create a centralized hub where you can see all those digital trust assets across the environment, regardless of where they are.”

The Internet of Everything lies ahead — and brims with promise. A radical new approach, supported by bold new security platforms, coming at it from several angles, must take hold. That’s how we’ll be able to protect company networks, and preserve individual privacy, in a massively interconnected, highly interoperable digital world.

I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

My name is Eden Zaraf. I’ve been driven by my passion for technology for as long as I can remember. Somewhere around the age of 13, I learned to code. I developed scripts, websites and got involved in security which led me to penetration testing.

Related: Leveraging employees as detectors

Penetration Testing is a never-ending challenge. Five years ago, my friend Sahar Avitan began developing an automatic penetration testing tool for our own use.

A year and a half ago, we decided to turn it into a commercial platform. I was sitting in a classroom when I had this Eureka moment. I realized that our technology could actually help people. I decided to meet with my neighbor, Arik Assayag. I said to myself, if he thinks we can market it, let’s go for it. He did and we co-founded Kayran.

Arik, who has decades of experience in business development and corporate management, is now the CEO of Kayran. We supply an advanced web application scanner that’s unique in the world of web penetration testing.

Website vector

Every company which currently operates online should have access to web penetration testing regardless of its size or the industry in which it operates. In the digital era, online security should be a right, not a privilege. Web penetration testing allows security professionals and website owners to test the integrity of their web assets.

There is tremendous investment in training sales and marketing personnel. So why not invest in your most prominent representative, your website?

Your website is the platform through which you offer services, communicate with existing and potential customers and collect critical data. Every element of your web application can embed vulnerabilities. A form on your website can lead to injections.

Zaraf

A vulnerability in the host header of your website can redirect your users to the wrong domain and lead to a credential leak. Unlike physical assets, web applications have an increased level of exposure to potential attackers simply because anyone with a viable internet connection can access your website, study it and exploit existing vulnerabilities.

As such, we test everything: vulnerabilities in your code, outdated technologies, open ports and online subdomains. We give you the tools to never think twice about how secure your website is.

Democratized pentests

By now, the importance of penetration testing is known to most companies. An essential component of ISO 27001 compliance is performing penetration tests as it can effectively identify where to make improvements to the information security management system of an organization.

However, many organizations face difficulties when trying to get access to web penetration testing. Manual penetration testing is extremely costly and makes it hard for organizations to perform the test more than once or twice a year even though this clearly defeats the purpose as new vulnerabilities appear on a daily basis.

Kayran democratizes access to pen testing by allowing organizations to scan domains and subdomains independently and on an unlimited scale at a set and affordable price. There are two types of websites: single page applications and multiple page applications, we support both.

We believe in usable security that does not disrupt online activities as such we automatically adjust the speed of the requests sent to your website so that it never goes offline. We analyze your code, reveal customized payloads based on existing vulnerabilities and recommend patching methods.

Website immunization

Once you fix a specific vulnerability, you can scan again to check that it no longer exists. We support more than 20,000 vulnerabilities as well as zero days. Kayran simplifies security to enable anyone, regardless of whether they are technical or not, to gain visibility over the security of their web assets.

Furthermore, Kayran provides the ability to extend the pen test to login pages so that the session continues once authentication is completed.

In my eyes, everything should be pen tested from internal networks to mobile applications, and Kayran is slowly but surely moving towards offering infrastructure and mobile app pen testing.In its latest State of Phishing Report, SlashNext analyzed billions of link-based URLs, attachments and natural language messages in email, mobile and browser channels over six months in 2022 and found more than 255 million attacks —a 61 percent increase in the rate of phishing attacks compared to 2021.

The only way to make attacks a phenomenon of the past is to get protection to immunize ourselves against this trend and finally make it go away or at least contain it so that it no longer disturbs commercial and private online activity.

About the essayist: Eden Zaraf is 18 years old. He is the co-founder and CTO of Kayran. He enjoys helping individuals and organizations solve complicated Python coding problems.

View Details

As the world becomes more digital and connected, it is no surprise that data privacy and security is a growing concern for small to medium sized businesses — SMBs.

Related: GDPR sets new course for data privacy

Large corporations tend to have the resources to deal with compliance issues. However, SMBs have can struggle with the expense and execution of complying with data security laws in many countries.

Organizations with 500 or fewer employees have many positive attributes, such as their ability to make fast decisions and avoid bureaucracy that can slow down larger enterprises. But this same characteristic can also be a disadvantage, as SMBs often lack the resources and expertise to keep up with complex regulations.

Let’s look at some of the challenges faced by SMBs in today’s data privacy landscape.

Scarce resources

It’s often difficult for small businesses to invest significantly in data privacy compliance or security measures because they don’t have large budgets. In fact, many SMBs have to choose between investing in new technology and making payroll. This can make it difficult for them to keep up with the latest security measures and technologies that could protect their data or prevent a breach.

Damodaran

An SMB may not have the time or resources to properly implement the robust security policies and procedures needed to comply with numerous regulations. That means there will likely be gaps in their data protection measures that could leave them vulnerable to cyberattacks.

It should be no surprise that data security regulations are on the rise. There is increasing regulatory pressure on SMBs to protect their employees’ and customers’ sensitive data. For instance, any direct contact with European suppliers, partners or customers requires taking steps towards complying with GDPR regulations.

DPIA starting point

A Data Privacy Impact Assessment, or DPIA, is a formal assessment of the privacy risks of your data processing activities. The purpose of conducting a DPIA is to identify and assess the potential impact of these risks on individuals’ rights and freedoms from your proposed processing operations.

A DPIA requires a thorough review of any personal data collected and stored, including who specifically controls the data and who has access at any given time. It also takes into consideration the reasons why the data was collected in the first place, and examines the reasons why personal data is stored; in short it examines numerous parameters related to collecting and holding personal data.

Paths to compliance

By performing this type of assessment, businesses can better understand their responsibilities for protecting personal information, as well as assess their ability to do so. This should naturally lead to an SMB putting plans in motion to achieve compliance — by embracing robust cyber hygiene policies and procedures.

There are many kinds of tools and services that can help any SMB down this paths. The core idea is to help the company continually improve how it monitors data flow and trains staff to be alert to cyber threats in order to identify suspicious network activity — before it becomes a problem.

Data protection is an ongoing process. DPIAs can get an SMB off to a good start. But maintaining a security posture that not just meets compliance but effectively protects the organization over the long run is a never ending task. It’s important to continually assess security posture and take corrective action when necessary.

Neumetric helps organizations perform DPIAs as well as numerous other types of cybersecurity and cyber risk assessments, in addition to security awareness training for employees. Our services revolve around helping organizations achieve security compliances and certifications such as EU GDPR Compliance.

About the essayist: Bipin Damodaran is a Certified Ethical Hacker and a member of the security team at Neumetric, a cybersecurity vendor that helps organisations bolster their information security by creating a secure operating environment.

View Details

In golf there’s a popular saying: play the course, not your opponent.

Related: How ‘CAASM’ closes gaps

In an enterprise, it’s the same rule. All areas of an organization need to be free to “play their own game.”

And when malware, ransomware, or other cyber threats get in the way, the focus shifts from forward progress to focused co-operation. A security strategy should clear obstacles and enable every part of a business operation to run smoothly.

Smarter security is the rising tide that lifts all ships. As all parts of an organization overlap with security, an increase in one allows benefits in others.

Departments such as support, manufacturing, design, services, and delivery are enhanced by smart security measures, which allay distracting setbacks and increase the overall inertia. This leads to revenue gains and positive customer outcomes.

What constitutes “smarter security?” Smarter security to me broadly refers to relentlessly focusing on fundamentals while maturing the program, making sure your risk posture aligns with your business strategy.

Complexity challenge

The complexity that has abounded in the past few years has left us more connected and data-driven than ever before. Business initiatives demand faster, more efficient outcomes and technology responds. However, security – the often overlooked and undervalued visitor – is struggling to communicate across the table.

When it comes down to it, C-level goals and CISO initiatives are not all that misaligned. We all want fast, powerful, capable tools that can launch our business into the future with its best foot forward. And we all want to avoid breaches and PR failures in the process.

However, enterprises often experience a disconnect between business objectives and security guidelines. It is in this disconnect that cybercriminals find opportunity.

Reffkin

The attack surface is expanding relentlessly and exponentially, while security initiatives aren’t ingrained into every department’s daily operation. The need for reset and oversight is so great that a new class of technology is emerging to give organizations a better grip on the digital sprawl that’s come to define modern-day enterprise architecture.

Gartner refers to it as “CAASM,” or cyber asset attack surface management. The concept of focusing on your attack surface is a good place to start if struggling to find where to begin.

This smarter form of security fills a glaring gap in today’s solution-saturated market; strategy, and the strategy that can only come from getting a full view of the course.

Automated offense

Smart security also means doing more with less so the company as a whole can run lean. This means secure file transfer solutions, so you don’t waste time with slow encrypting protocols. It means anti-phishing tools so your teams can open emails without needless hesitation or risk.

It also means offensive security measures and vulnerability management so your team can fix problems before they can be exploited and derail operations.

Automating the security tasks of an organization – or hiring out when necessary – keeps those basic hygiene concerns out of mind and allows a business to perform at its best. When done right, a smarter security strategy is unseen.

As I’ve mentioned before, the issue of security is essentially a problem-solving one. These are not security problems for security’s sake. They are fundamentally business problems that rely on security to solve them.

How do we innovate and stay ahead of the competition without our speed backfiring and creating more bugs? How do we take time to manage vulnerabilities in our CRM when we’ve promised 24/7 customer care that relies on it? How can we accomplish our CEO’s vision for full process automation when we’re still transitioning to the cloud – and are unfamiliar with the security terrain?

Smarter security measures mean more subtle, intuitive, predictive solutions that can grease the wheels for whatever a fast-thinking enterprise can come up with next.

Sometimes the issue is resources. Part of problem-solving is examining the trouble spot from all angles. Managed solutions can help. Data Loss Prevention can lift the strain of vigilance and increase security in the workflow.

The overall trend is this: technology, progress, and change are driving the business objectives of today, and “smarter security” solutions are ones that can keep up, stay out of the way, and enable all aspects of a business to perform at their top level.

About the essayist: Chris Reffkin is chief information security officer at cybersecurity software and services provider Fortra. He has deep experience implementing and overseeing security strategy for a myriad of top-tier organizations.

View Details

At the start of 2023, consumers remain out in the cold when it comes to online protection.

Related: Leveraging employees as human sensors

Malicious online actors grow ever more sophisticated, making cybersecurity as big a concern for everyday consumers as it ever has been.

These days, ordinary people are facing increasing—and more complex—threats than ever before. For example, ReasonLabs researchers recently uncovered a scam that used stolen credit cards and fake websites to skim monthly charges off of unsuspecting consumers.

Because of scams like this, it is vitally important for individuals and families to be aware of their potential exposure to cybercriminals, and to take proactive steps to protect themselves.

There are many ways in which we can be exposed to potential cyberattacks. For instance, phishing, one of the most common, is a social engineering attack used to steal user data. Cybercriminals can pose as someone the victim knows and trusts, and request credit card details or login credentials.

Sometimes, they will even ask the victim to buy gift cards, which they then redeem. 2021 saw a massive increase in phishing attacks, and that trend has continued into 2022. Even events like the World Cup are being used by cyber criminals to target unsuspecting victims through things like fake streaming sites designed to steal private information.

With the rise in social media, criminals have more platforms with which to target potential phishing victims. Since many people use the same passwords across social media platforms and for sites for banks or credit cards, a criminal needs access to just one account to gain access to every account.

Even if 99% of all phishing attacks are ignored, all it takes is one successful attempt out of thousands to do serious harm. It can cost a company millions of dollars, or lead to individual identity theft and invasion of privacy.

Cybercriminals often target the young. Even if you think you’re not susceptible, your child may not be as knowledgeable. Criminals who can infiltrate your children’s device through things like ‘free’ games, ringtones or other files that hide malware, can gain access to your entire family’s devices.

With more and more people working remotely, unsecured home or public WiFi networks represent a security risk not only to individuals but to their companies as well. Since many people are now working from home at least partially, vulnerabilities at home are vulnerabilities at work, and threaten to put a company’s data at risk. Unsecured Wi-Fi in the home can present a way for criminals to gain access to secure business data.

Cyber hygiene basics

Despite all the threats, there are many ways you can protect yourself, your family, and your business. To begin with, keep all software across your devices updated to the latest version. This includes antivirus software, operating systems, and individual apps. Don’t ignore upgrade notifications—they are often for security reasons, based on specific threats from bad actors.

Be careful when using your credit card information on unfamiliar shopping sites. Make sure those sites are legitimate before handing over your money. If something doesn’t feel right, it probably isn’t.

Be aware of phishing attempts via email or text messages. Never click on suspicious links or respond to messages from senders you don’t know. Phishing attempts can be very sophisticated, so be sure to thoroughly analyze every message—including the email address that sent it to you—before you respond.

And it’s important to remember that no legitimate merchant, bank, or government agency will ever ask you for password or credit card information by text message or email, so don’t be fooled by a message that pretends to be from a store, your bank or from the IRS.

Protect your privacy by investing in tools that help protect you and your online activity. For example, it’s crucial to install an antivirus solution that automatically defends your digital devices from cyberattacks by predicting, preventing, and addressing them in real time.

Security tools and services

ReasonLabs offers an industry-leading antivirus solution, RAV Endpoint Protection, which provides a defensive bulwark against any and all malicious activity users face across their personal devices—from viruses and malware, to ransomware, phishing and other cyber risks.

Kalif

You can also invest in a virtual private network (VPN) for use when you are connected to a public network. VPNs route your data through secure servers and networks to protect your personal information from prying eyes. ReasonLabs’ RAV VPN enables users to confidentially and securely browse the internet anywhere in the world.

With so many threats out there, it may seem overwhelming. But by taking steps to protect your personal information, like keeping your software updated, and by being vigilant about clicking on suspicious links, or responding to messages from unknown sources, you can protect yourself.

Cyberattacks are getting more sophisticated by the day, and it’s crucial that you recognize some of the telltale signs of malicious activity so that you can keep yourself and your family safe.

About the essayist: Kobi Kalif is co-founder and CEO of ReasonLabs, a Tel Aviv, Israel-based supplier of advanced EDR platform services.

View Details

For the average user, the Internet is an increasingly dangerous place to navigate.

Related: Third-party snooping is widespread

Consider that any given website experiences approximately 94 malicious attacks a day, and that an estimated 12.8 million websites are infected with malware. So, in response to these numbers, users are seeking ways to implement a more secure approach to web browsing.

Generally, there are basic practices individuals can take to strengthen their cybersecurity while browsing the web. However, such prevailing rudimentary practices have fostered a degree of naivety, and certain myths have arisen about the security and effectiveness of these practices.

Implementing basic cyber hygiene practices often makes users think they’re immune to infection. This in turn makes users complacent, which allows them to be exposed to malicious malware when least expecting it.

Common misconceptions

There are a variety of myths regarding safe web browsing. Most of these have to do with preventing malware from infecting your device. Malware is any kind of software designed to interfere with your device or network, whether it’s gaining access to your protected data or disrupting your systems to bring them to a halt.

The prevailing misconceptions include:

•You can only contract malware or viruses through downloads.

We’ve been conditioned to think that by avoiding suspect attachments or downloads, we’re totally in the clear. However, you can be exposed to malware through multiple mechanisms, including by simply visiting a website. The malware on the website can test for vulnerabilities on your browser in order to infect your device. No attachment needed.

•I only browse trusted sites, so I shouldn’t be concerned about malware infections.

Malware can be hosted on any site, no matter how secure or reputable it is. Moreover, the vast majority of malware is actually deployed on trusted websites. One study found that 75 percent of supposedly trusted websites have vulnerabilities that leave them open to malware infections.

I frequently clear my cache, so third-party data collectors can’t collect and sell my personal data.

Well, having a cache to clear out means your default browser setting is to allow cookies. The cookies are still tracking your activity across websites and gleaning data from you moment by moment. Unless you’re clearing your cache by the minute, third-party data collectors are gaining plenty of insights into your behavior. Moreover, malware and viruses can also be disguised as cookies; once they’ve infected your device, clearing your cache is useless.

•Incognito mode protects my personal information from bad actors.

Going “incognito” doesn’t actually make you incognito. For one, while incognito mode blocks cookies and browsing history records, it doesn’t hide your IP address. This means you can still be easily identified. Furthermore, once malware is installed on your device, it’s still tracking your activity and stealing sensitive information, even in incognito mode.

Steps to safe browsing

If you want to browse safely, you need to take control and inform yourself of the reality of the threats. Afterwards, you can develop realistic mitigation strategies.

Effective, routine practices to establish include frequently updating your web browser to keep pace with the latest security updates; adjusting your browser’s security settings to disable third-party cookies; and enabling multi-factor authentication to access your accounts.

Levitt

You can also utilize Google’s Safe Browsing as another tool in your security arsenal. Every day, Google scans billions of URLs looking for unsafe websites, and many of those it flags are legitimate sites that have been compromised. The safe browsing feature then works on two fronts: the search engine tells you if it suspects a website in its results is infected, while the Chrome web browser alerts you anytime you visit a potentially infected or unsafe site.

However, by using safe browsing, you’re also sharing more personal data like browsing history with Google so that the company can validate what’s safe, and this has far-reaching implications for user privacy.

A more secure way to protect your online activity and personal information is through ad block extensions; any good ad blocker also prevents data analytics, user attribution, and third-party cookies. Moreover, by not displaying advertisements on the page, ad blockers reduce the attack surface area, limiting the areas where you can be infected with malware.

In all, though, while completely safe web browsing may seem unachievable, you can implement a variety of privacy-preserving tactics and best practices to improve security and protect your data. Remember: no matter where you stand currently, you can always be a little safer.

About the essayist: Michael Levitt is the CEO of Tempest a supplier of innovative browser privacy products that ensure user safety across every touchpoint online.

View Details

The 2020s are already tumultuous.

Related: The Holy Grail of ‘digital resiliency’

Individuals are experiencing everything from extraordinary political and social upheaval to war on the European continent to the reemergence of infectious diseases to extreme weather events.

Against this unsettling backdrop, citizens, consumers, employees, and partners will look to organizations that they trust for stability and positive long-term relationships.

Not every organization knows how to cultivate trust, however, or that it’s even possible to accomplish. As a result, in 2023, specific industries that normally experience healthy levels of trust will see major declines in trust that will take years to repair. Others will buck historical trends just to simply maintain their current trust levels.

Organizations should take into account the following predictions as they plot out the next steps of their trust journey in the year ahead:

•Trust in consumer technology will decline by 15 percent.

Over the past three years, technology has proven critical to consumers’ daily lives — from remote working and home-schooling to entertainment and e-commerce. Technology firms experienced unprecedented popularity because of this.

This honeymoon is coming to an end, however; expect to see trust in consumer technology companies declining by 15 percent in 2023. Regulatory crackdowns on poor privacy practices, continued supply chain issues, and ongoing challenges in retaining talent will all impact consumers’ sentiments negatively.

When consumers trust a brand less, they also lose trust in other businesses associated with it. This is the time for firms to map their value chain, assess trust fluctuation across their ecosystem, and be ready to act to safeguard trust.

•Half of firms will use AI for employee monitoring — battering employer trust.

Iannopollo

Forrester finds that around the world, employees trust their employer more than their colleagues. For example, 60 percent of US employees trust their colleagues while 64 percent trust their employer. Expect this trend to invert by the end of 2023 as employers overstep their bounds with the use of AI to monitor work-from-home productivity.

For those that choose to collect personal information from employees to measure performance, the data is grim. In 2022, Forrester finds that 56 percent of employees whose employer collects their personal information to measure performance are likely to actively look for a new opportunity at a new organization in the next year — 14 percentage points higher than the average.

Firms seeking to lead in employee experience must eliminate outdated notions of “time spent” and instead focus on outcome-based performance measurement.

•Banks will lose consumer trust in a period of economic turmoil.

In 2022, consumer trust in banks fell for the first time in several years. Additionally, Forrester data reveals that only 54 percent of US consumers believe their bank exhibits the trait of empathy.

As the economy continues to flash warning signals, consumers’ ire and resentment toward their bank will make it even harder to earn trust. Because of this, trust will decline for most banks.

To maintain consumer trust in 2023, banks must lead with empathy and take a data-driven approach to earning trust with concrete, targeted steps that can help them navigate the cost-of-living crisis.

•People’s trust in government will increase in the US.

Trust falls when governments are no longer able to create a better future for their people. In 2023, the US will buck historical trends that saw trust shrinking by building on dependability as a core lever of trust, as well as by investing heavily in such other key trust levers as accountability, competency, and transparency. For example, President Biden’s Management Agenda is doubling down on the combined power of customer and employee experience.

•Three-quarters of Californians will have asked firms to stop selling their data by the end of 2023.

Privacy continues to be a critical consumer value. According to Forrester, 47 percent of Californian online adults have exercised their CCPA right to ask companies to stop selling their data, while 30 percent have asked companies to delete their data.

As the privacy discussion takes center stage in the US over the next 12 months — especially given the potential for new federal legislation and the enforcement of existing state-level legislation — consumers’ privacy activism will continue to grow.

Now is the time for organizations to shore up their privacy and data protection programs and require that all new products, services, and experiences are private by design.

Companies understand that trust will be critical in the next 12 months and more so than ever before. Companies must develop a deliberate strategy to ensure that they gain and safeguard trust with their customers, employees, and partners.

Measuring trust in their brands, engaging line-of-business owners and other leaders to identify key initiatives (with regional variations as necessary), and setting a realistic time frame are all fundamental steps that they must take to get started on this important journey.

About the essayist: Enza Iannopollo is a principal analyst on Forrester’s security and risk team and a Certified Information Privacy Professional (CIPP/E). Her research focuses on compliance with data protection rules, privacy as a competitive differentiator, ethics, and risk management.

View Details

Cybercrime is a big business. And like any other large industry, specialization has emerged.

Related: IABs fuel ransomware surge

As data becomes more valuable, criminals can profit more from stealing, selling or holding it for ransom, leading to a massive black market of information.

Initial access brokers (IABs) play an increasingly central role in this cyber underworld. IABs specialize in finding vulnerable targets and sell their details to other cybercriminals.

They search for weak points and perform the challenging, technically demanding work of breaking past an organization’s security, then offer access to the victim to the highest bidder.

IABs on the rise

IABs can gain this access through many different means. In some cases, they find vulnerable third parties that provide ways into larger targets, which is how hackers infiltrated the Red Cross in 2021.

In others, they try brute forcing their way through a company’s security; and sometimes, they’re malicious insiders who already have access to sensitive files.

Regardless of the specifics, the outcome is the same. IABs perform the difficult first few steps of breaking into a target’s systems, allowing other well-paying cybercriminals an easy way in to do whatever they want.

IABs aren’t necessarily a new threat, but they’ve seen tremendous growth over the past few years. Cybersecurity firm Positive Technologies found 88 new IAB sales on dark web marketplaces in the first quarter of 2020, compared to just three in all of 2017.

Amos

The rise of IABs corresponds with the increase in digital transformation. Early in the COVID-19 pandemic, companies started implementing digital tools at an unprecedented pace. Digital resources became increasingly critical for businesses, and targeting them became a more profitable type of crime, leading to a surge in demand for IABs.

IABs’ ease of access helped spur this growth. With an IAB, cybercriminals don’t need advanced technical knowledge or skills to pull off a successful attack. That makes them the ideal solution for new, inexperienced hackers trying to profit from this wave of digitization.

Ransomware correlation

This uptick in IAB activity has several far-reaching impacts on cybersecurity. Reliable security is becoming increasingly important to investors, requiring businesses to meet high standards to secure investment and new partnerships.

Because IABs can make it easier to breach a company’s security, their rise could make meeting those expectations harder, creating more demand for expert cybersecurity services.

As IABs continue to grow, so will ransomware. Ransomware is already the fastest-growing type of cybercrime, and IABs make it more accessible to novice criminals. It’s far easier to steal and encrypt sensitive data when someone else manages the first and hardest step in the breach process. Consequently, security professionals should prepare for an uptick in ransomware threats.

Mitigating IABs

Businesses should also focus on practices that mitigate IAB-related risks amid this rising threat. These include:

•Using multifactor authentication (MFA) on all accounts.

•Monitoring the dark web for IAB listings.

•Restricting access permissions to minimize insider threats.

•Keeping all software, especially VPNs, up to date.

General cybersecurity best practices like using strong passwords and offering regular security training will also help. While this trend is concerning, these widely recommended steps are still effective.

As the data revolution continues and cybercrime grows, IABs will become all the more prominent. Recognizing these threats early is the first step in addressing them. Once businesses know what to watch out for, they can make the best decisions about defending themselves, even with risks as pressing as IABs.

About the essayist: Zac Amos writes about cybersecurity and the tech industry, and he is the Features Editor at ReHack. Follow him on Twitter or LinkedIn for more articles on emerging cybersecurity trends.

View Details

There is much that can be gleaned from helping companies identify and manage their critical vulnerabilities 24X7.

Related: The case for proactive pentests

Based on insights from our team of elite security researchers here at Bugcrowd, these are three trends gaining steam as 2022 comes to a close – trends that I expect to command much attention in 2023.

Continuous pentesting

For years, penetration testing has played an important role in regulatory compliance and audit requirements for security organizations. However, a longtime challenge with pentesting has been the “point-in-time” nature of the tests.

At some pre-defined period-of-time, the test is completed against the then-current version of the application and a report is delivered. The challenge is that application development has changed significantly in recent years; often by the time a pentest is completed and the report is delivered, the information is already out of date due to changes in the application.

Over the coming year, we will see an accelerating shift from traditional pentesting to more PenTesting-as-a-Service (PTaaS). Rather than point-in-time assessments, organizations are leveraging pentesting as an important tool in their risk and security program, rather than a necessary-evil to maintain compliance with internal or external requirements.

By completing incremental testing on the application, security organizations can gain current and ongoing visibility into the security posture of the application as the smaller scope allows for faster testing turnaround. This enables security organizations to receive real-time information into the current security posture of the application, network, or infrastructure.

Gerry

It’s important to remember that every change to a network or application, whether a major release or incremental release, represents an opportunity for new vulnerabilities to be introduced. Security organizations must maintain the ability to gain real-time visibility into their current posture – both from a risk governance perspective and from a compliance perspective.

Security vendor consolidation

The rapid expansion of new security products has led to many organizations purchasing the “latest and greatest” without having a strong integration plan in place. Without a clear deployment and integration plan, even the best security product will go underutilized.

For the past few years, the industry has seen an incredible amount of M&A consolidation. As a result, security organizations are looking internally for ways to leverage existing tool sets or upgrade existing tool sets versus adding to their ever-growing technology stack.

This growing need for security vendor consolidation will continue to be driven by both the cost of the security products and the limited internal resources to effectively operate the products.

Narrowing the talent gap

Attracting strong candidates has always been a core part of any business, and, like all businesses, finding senior talent, whether in cybersecurity or another function, requires a combination of attractive compensation, career growth, flexibility to work anywhere, and a mission that employees want to support.

It’s also important to find talent from non-traditional and diverse backgrounds, provide them with the necessary training and enablement, pay them well with additional equity incentives, and empower them to do what needs to be done.

For years, we’ve been led to believe there is a significant gap between the number of open jobs and qualified candidates to fill those jobs. While this is partially true, it doesn’t provide a true view into the current state of the market.

Employers need to take a more active approach to recruiting from non-traditional backgrounds, which, in turn, significantly expands the candidate pool from just those with formal degrees to individuals, who, with the right training, have incredibly high potential.

Additionally, this provides the opportunity for folks from diverse backgrounds, who otherwise wouldn’t be able to receive formal training, to break into the cybersecurity industry providing income, career and wealth-creation opportunities that they otherwise may not have access to.

Organizations need to continue to expand their recruiting pool, account for the bias that can currently exist in cyber-recruiting, and provide in-depth training via apprenticeships, internships, and on-the-job training, to help create the next generation of cyber-talent.

About the essayist: Dave Gerry is CEO of Bugcrowd, which supplies a security platform that combines contextual intelligence with actionable skills from elite security researchers to help organizations identify and fix critical vulnerabilities before attackers exploit them.

View Details

It’s all too easy to take for granted the amazing digital services we have at our fingertips today.

Related: Will Matter 1.0 ignite the ‘Internet of Everything’

Yet, as 2022 ends, trust in digital services is a tenuous thing. A recent survey highlights the fact that company leaders now understand that digital trust isn’t nearly what it needs to be. And the same poll also affirms that consumers will avoid patronizing companies they perceive as lacking digital trust.

DigiCert’s 2022 State of Digital Trust Survey polled 1,000 IT professional and 400 consumers and found that lack of digital trust can drive away customers and materially impact a company’s bottom line

“It’s clear that digital trust is required for organizations to instill confidence in their customers, employees and partners,” Avesta Hojjati, DigiCert’s vice president of Research and Development, told me. “Digital trust is the foundation for securing our connected world.”

I recently had the chance to visit with Hojjati. We conversed about why digital trust has become an important component of bringing the next iteration of spectacular Internet services to full fruition. And we touched on what needs to happen to raise the bar of digital trust. Here are a few key takeaways from our evocative discussion:

Vigilance required

As 2022 comes to a close, connectivity is exploding. This portends many more digital wonders to come. Yet threat actors continue to breach corporate networks with impunity. And now, finally, digital trust is commanding attention.

One hundred percent of the IT pros who participated in DigiCert’s survey acknowledged the importance of gaining and keeping digital trust. The backdrop is an operating environment is which their organizations’ network attack surface is scaling up. What’s more, 99 percent of the IT pros said they believed their customers would switch to a competitor should they lose trust in the enterprise’s digital security.

Meanwhile, more than half, some 57 percent, of consumers polled by DigiCert acknowledged that they’ve experienced cybersecurity issues such as account takeovers, password exposure and payment card fraud. And nearly half, 47 percent, said they’ve stopped doing business with a company after losing trust in that company’s digital security.

Consumers aren’t blind; they’ve become wary of companies that lack online vigilance. Some 84 percent said they would consider not patronizing a company that fails to manage digital trust, with 57 percent saying switching to a more trustworthy provider would be likely.

“Consumers understand what digital trust is and they’re making it a requirement for any entity they’re dealing with to protect their data and their online accounts,” Hojjati says. “If they find that’s not the case, consumers have no problem switching to another vendor.”

Baked-in security

So how did we get here? Over the past decade, digital transformation has advanced rapidly – and even more so post Covid 19. In this environment, companies chased after the operational efficiencies – without duly considering security. And as this shift to reliance on cloud-infrastructure and remote workers accelerated, no one accounted for the fresh pathways left wide open to malicious hackers.

Hojjati

“Enterprises were slow to acknowledge that digital trust was missing,” Hojjati observes. “We dove too quickly into making everything digitalized, but we didn’t realize that this superfast inter-operability and hyper interconnectivity absolutely requires a foundation of trust.”

Digital trust has emerged as a must-have; without it confidence in online business processes are destined to erode. At a macro level, this means security must somehow get deeply baked into leading-edge IT architectures. Systemic changes need to be agreed upon and universally adopted. Smart, adaptable, automated security needs to be infused into the ephemeral, highly distributed and cloud-centric digital infrastructure that will take us forward.

At a micro level, company leaders and captains of industry must arise as champions and stewards of digital trust, Hojjati argues, not only for their own internal employees and operations, but also for their customers, partners and extended communities.

Infusing digital trust

Moving forward, digital trust must become a cornerstone of security. One core technology for providing digital trust is the public key infrastructure (PKI), or more precisely, advanced implementations of PKI. As a prominent supplier of PKI services and digital certificate lifecycle management systems for companies worldwide, DigiCert brings this skin into the game. PKI is the framework by which digital certificates get issued to authenticate the identity of users and devices; and it is also the plumbing for encrypting data that moves across the public Internet.

PKI already is deeply engrained in the legacy Internet; companies use it to certify and secure many types of digital connections coming into, as well as inside of, their private networks.

Because PKI is ubiquitous and time-tested it is well-suited to be a leading technology used for infusing digital trust into the next iteration modern networks designed to handle massive interconnectivity and support vast interoperability. This is the working premise espoused by DigiCert and other security experts.

“Modern digital systems simply could not exist without trusted operations, processes and connections,” Hojjati says. “They require integrity, authentication, trusted identity and encryption.”

Public awareness, not to mention public demand for improved security, is an important catalyst. Consumer preference for digital services they can fully trust should remind industry and company leaders to stay focused on doing what needs to get done.

Indeed, industry consensus is being shaped around new sets of standards needed to replace the outdated protocols and policies that gave us the legacy Internet. This heavy lifting is being undertaken by a number of industry forums far out of the public eye.

Refreshed standards

One milestone advance achieved by this effort is Matter 1.0 – the new home automation connectivity standard rolling out this holiday season. There are high hopes that Matter will blossom into the lingua franca for the Internet of Things.

For its part, DigiCert continues to be a prominent participant in the public-private consortia developing and refining a fresh portfolio of security standards needed to engrain digital trust. This includes new security protocols not just for digital certificates but for all things to do with smart buildings, smart transportation systems and smart infrastructure, as well.

As the details get hammered out, it would be wise for companies and industry sectors to jump on board the digital trust band wagon, the sooner the better. And if fear of losing customers adds to their motivation, then so be it.

“Digital trust by design is something company decision makers have to consider,” Hojjati says. “They need to make digital trust a strategic imperative.”

DigiCert recommends assigning a senior executive with explicit duties to support digital trust. One way to do this might be to create the role of “digital trust officer,” Hojjati says. A DTO could focus on mitigating exposures spinning out of an ever-expanding attack surface; in other words, implementing advanced security systems and procedures on premises, for remote workers and up and down the supply chain, he says.

Clearly new rules of the road like this are needed. Encouragingly, they’re coming. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

The Internet of Everything (IoE) is on the near horizon.

Related: Raising the bar for smart homes

Our reliance on artificially intelligent software is deepening, signaling an era, just ahead, of great leaps forward for humankind.

We would not be at this juncture without corresponding advances on the hardware side of the house. For instance, very visibly over the past decade, Internet of Things (IoT) computing devices and sensors have become embedded everywhere.

Not as noticeably, but perhaps even more crucially, big advances have been made in semiconductors, the chips that route electrical current in everything from our phones and laptops to automobile components and industrial plant controls.

I recently visited with Thomas Rosteck, Division President of Connected Secure Systems (CSS) at Infineon Technologies, a global semiconductor manufacturer based in Neubiberg, Germany. We discussed how the Internet of Things, to date, has been all about enabling humans to leverage smart devices for personal convenience.

“What has changed in just the past year is that things are now starting to talk to other things,” Rosteck observes. “Smart devices and IoT systems are beginning to interconnect with each other and this is only going to continue.”

This ascension to the next level of connectivity is underscored by Matter 1.0, the new home automation connectivity standard rolling out this holiday season. Matter paves the way for not just more Internet-connected gadgetry; it makes possible a new tier of highly interoperable digital systems providing amazing services that are highly secure and that intrinsically preserve individual privacy.

For a full drill down on our evocative discussion please watch the accompanying videocast. Here are the main takeaways:

Dispersing electricity

Strictly speaking, a semiconductor is any crystalline solid that resists the flow of electricity in a distinctive way. We call them microchips or just chips and they are the building blocks of diodes, transistors and integrated circuits – the components that direct electrical current to carry out processing routines.

Semiconductors are the hardware components that make up the nervous system of each and every smart device — from tiny sensors to sprawling cloud servers and everything in between. Rosteck outlined how advanced semiconductors will be indispensable in two broad areas going forward: power modules and microcontrollers. Both come into play across the breadth of IoT and, even more so, with respect to IoE.

Rosteck

For instance, semiconductor power modules enable the generation, transmission and consumption of electricity in everything from the control room of a modern industrial plant to the timer on your smart coffee grinder.

Power modules must continue to advance; energy consumption of big digital systems must continue to become more and more efficient to support the smart commercial buildings and transportation systems of the near future, Rosteck says.

With power modules circulating electricity very efficiently at a macro level, advanced microcontrollers can grab the spotlight. These are the unseen chipsets that carry out discreet tasks, such as activating your smart auto’s proximity sensors and rear view camera or controlling your smart home’s thermostat and garage door opener.

Microcontrollers are, in essence, mini computing engines; today they serve mainly as the knobs and flip switches of IoT; going forward they’ll evolve into sophisticated controls that make complex decisions, autonomously, as part of new IoE systems.

Energy at the edges

How microcontrollers distribute energy is a very big deal. Innovation in the semiconductor industry is focused on finding smarter ways to disperse tiny bursts of electricity to a sprawling galaxy of IoT devices and new IoE systems. Energy needs to be dispersed very efficiently, in just the right measure, to support the machine intelligence routines increasingly taking place at the cloud edge, Rosteck explained.

“When I transport energy or when I consume energy, I must do this efficiently, meaning not wasting energy by ‘turning it on its head,’ but turning energy into what I really want to use it for,” he says.

Rosteck described for me a smart home of the near future. It would be equipped with array of Internet-connected devices that work in concert to optimize energy consumption. Unseen and unnoticed by the resident, interconnected systems would be capable of correlating real-time weather data, traffic patterns and the resident’s work schedule and then calculate the precise amount of energy needed on a given day, or even hour of the day.

Such smart homes could become the norm in the era of IoE. This would lead to an optimum blending of private and public sources of energy. Individual consumers could tap solar energy from their roof tops, public utilities would supply power from legacy power plants as well as from new renewable energy operations.

The result: energy conservation would advance significantly. It’s notable that technologists and social scientists are discussing how to leverage interconnected digital infrastructure, i.e. the Internet of Everything, to foster similar “greater good” scenarios in other arenas. This includes mainstreaming autonomous transportation systems, perhaps even redistributing wealth more equitably across the planet.

Baking in security

First, however, two things need to radically change: digital systems must be able to interconnect much more seamlessly than is possible at this moment; and cybersecurity needs to rise to a much higher level. And this is where Matter 1.0 comes into play.

To start, any Matter-compliant smart home device will be able to interoperate with whatever virtual assistant the resident might have. Making it possible for a consumer to use Amazon Alexa, Google Assistant, Apple HomeKit or Samsung SmartThings to operate all types of Matter-compliant devices is a giant step in convenience — and a small step toward a much greater good. Work has commenced on future iterations of Matter that will make IoT systems in commercial buildings and healthcare facilities much more interoperable than is the case today.

Cybersecurity remains a major obstacle that must be dealt with. Interconnected systems that can easily be hacked, of course, would be untenable. Thus, Matter sets forth an extensive process for issuing a “device attestation certificate” for each Matter-compliant device. This process revolves around extending the tried-and-true Public Key Infrastructure framework and associated Digital Certificates that assure website authenticity and carry out encryption across the legacy Internet.

That said, Matter is a new kind of tech standard. The standards that allowed the legacy Internet to blossom commercially – protocols skewed toward open and anonymous access — also doomed networks to be endlessly vulnerable to breaches. By stark contrast, Matter requires robust security of our next generation of interconnected devices and systems to be deeply secure from day one.

“If you bake a cake, you can’t change the flavor of the cake once it’s finished baking. It’s the same with standards, you must think about security from the beginning,” Rosteck says. “Matter is the first standard that I know of that accounted for security in the beginning.”

Indeed, when Google, Amazon, Apple and Samsung convened three years ago to draw up Matter, one of the very first moves the tech giants championed was to set up a security work group, Rosteck says. This is how security got baked in from the start. And the result is that the Matter standard is poised to foster a quickening of hardware and software advances that will take us to the next level of connectivity — securely.

There’s still a long way to go. I’ll keep watch and keep reporting.

Acohido

Pulitzer Prize-winning business journalist Byron V. Acohido is dedicated to fostering public awareness about how to make the Internet as private and secure as it ought to be.


(LW provides consulting services to the vendors we cover.)

View Details

Over the years, bad actors have started getting more creative with their methods of attack – from pretending to be a family member or co-worker to offering fortunes and free cruises.

Related: Deploying employees as human sensors

Recent research from our team revealed that while consumers are being exposed to these kinds of attacks (31 percent of respondents reported they received these types of messages multiple times a day), they continue to disregard cyber safety guidelines.

This neglect is not only a threat to personal data, but also a threat to corporate security. As we continue to live a majority of our lives online, there are many ways that both consumers and enterprises can better protect themselves against hackers.

According to our survey, the majority of consumers (77 percent) are confident they can identify, and report suspected malicious cyber activity despite general apathy toward proactively securing their devices and personal data.

Confidence gap

This overconfidence is cause for concern for many cybersecurity professionals as humans are the number one reason for breaches (how many of your passwords are qwerty or 1234five?). When it comes to protecting themselves and their devices, few are practicing the basics:

•Only 21 percent use email security software

•Only 33 percent consistently use two-factor authentication (2FA)

•Only 28 percent don’t use repeated passwords•Only 20 percent use a password manager

The gap between confidence in oneself when it comes to cybersecurity hygiene and actual implementation of protection against cybersecurity threats leaves much room for bad actors to execute successful malware and ransomware attacks.

Blurred lines

Guntrip

The hybrid workforce is here to stay, along with the blurring of work and home. Most people have work email, files, messages and more on personal devices, and use corporate devices to shop or stream content (our research says 56 percent of consumers engage in personal activity on a work device). This, combined with expanding attack surfaces due to the infinite number of networks being used by employees, has created the perfect storm.

Bad actors today enact Highly Evasive Adaptive Threat (HEAT) attacks with more frequency and success. Enterprises are scrambling to find better and more effective ways to secure their data and decrease the number of breaches occurring.

But since many employees are apathetic toward implementing security practices and prevention methods, it becomes a more and more daunting task for cyber professionals.

While cyber experts cannot save everyone from ransomware or other forms of threats, there are plenty of preventative ways for both consumers and enterprises to try and stop attacks before they occur.

Both consumers and enterprises can better protect themselves by:

•Enabling 2FA

•Using strong passwords (random combinations of letters and numbers are best) and storing them securely in a password manager

•Not using repeated passwords

•Reporting suspicious communications

•Installing security software and ensuring all your devices are running the latest software

•Backing up = files to a cloud or offline location regularly

•Not responding to, clicking on links or opening/downloading attachments from any number or email you don’t know (we promise your CEO isn’t really texting you about how your bonus will be paid via gift card you can download by clicking on that weird looking link)

What needs to get done

For corporations, additional steps that should be taken include:

•Having cloud security that spans web and email to prevent ransomware and other attacks

•Setting up systems to require 2FA for all employees

•Ensuring employees review security protocols as part of training and development

•Enforcing strong password requirements for email and other applications

Bad actors are not going away anytime soon, and we can predict that in 2023, we’ll see even more threats and attacks than in years past. Still, there are many ways that consumers and enterprises can protect their data and educate one another on the very real threat that these invisible enemies are. The more awareness raised about cybercrime and malicious activity, the more we can do to try and prevent attacks from occurring before it’s too late.

About the essayist: Mark Guntrip is senior director of cybersecurity strategy at Menlo Security, a Mountain View, Calif.-based web security vendor that provides secure, cloud-based internet isolation.

View Details

Much more effective authentication is needed to help protect our digital environment – and make user sessions smoother and much more secure.

Related: Why FIDO champions passwordless systems

Consider that some 80 percent of hacking-related breaches occur because of weak or reused passwords, and that over 90 percent of consumers continue to re-use their intrinsically weak passwords.

Underscoring this trend, Uber was recently hacked — through its authentication system. Let’s be clear, users want a better authentication experience, one that is more secure, accurate and easier to use.

The best possible answer is coming from biometrics-based passwordless, continuous authentication.

Gaining traction

Passwordless, continuous authentication is on track to become the dominant authentication mechanism in one to two years.

Continuous authentication is a means to verify and validate user identity — not just once, but nonstop throughout an entire online session. This is accomplished by constantly measuring the probability that an individual user is who he or she claims to be; a variety of behavioral patterns sensed in real time and machine learning get leveraged to do this.

Passwordless, continuous authentication addresses the dire need for higher and better security. Cyber attacks continue to grow in sophistication, and ransomware attacks are only the tip of the iceberg. Compromised credentials represent the most usual way attackers penetrate networks. That simply is not tolerable, going forward.

Schei

With a market and a society ready to go for it, passwordless authentication expansion is about to accelerate. In fact, demand for passwordless systems is expected to grow 15 percent per annum – topping $5.5 billion by 2032. It’s no surprise that passwordless authentication is at the core of Gartner’s report on emerging technologies and trends for 2022.

Invisible security

Authentication systems that leverage machine learning and biometric technology are now ready to replace legacy password-centric technologies. Machine learning can be applied to facial recognition data, for example, to provide an invisible security layer, with no actions required from the user.

This invisible authentication is very difficult to hack. This is because it relies on biometric features that can’t be shared. Widely adopted from healthcare to law enforcement, it can deliver secure, accurate authentication even when the user is wearing a mask; it prevents unauthorized access that can now be done by compromising devices we use as a second factor of authentication.

In industries such as banking, healthcare and law enforcement, where employees work under pressure to handle sensitive information, cybersecurity and productivity often contradict each other.

Password-based multi-factor authentication (MFA) systems, for instance, require constantly logging in and out of user sessions; employees waste working time, and can even suffer from MFA fatigue. These inefficiencies can open the gate to cyber attacks.

By contrast, passwordless, continuous authentication affords a double gain for companies: cybersecurity is materially improved, while authentication friction gets erased. This improves daily productivity, not to mention employees’ happiness.

Continuous vigilance

Current authentication tools focus on single sign on. This means that the authentication mechanism confirms the user at the beginning of the session but offers no guarantees during a user session.

One opportunity attackers seek out is when an authenticated user leaves the device unattended. Up to 95 percent of cyberthreats are successful because of a human error, including unattended sessions or visual hacking incidents, such as shoulder surfing.

This lack of extended security cannot be addressed through legacy sign-on authentication tools such as Microsoft Hello, that rely on one-time image authentication.

Fortunately, there’s a growing trend towards passwordless, continuous authentication

One touchless delivery model is through face recognition, and a good example is the core functionality built into GuacamoleID, supplied by Hummingbird.AI. GuacamoleID uses sophisticated vision AI to recognize and secure user sessions, thus enabling touchless automated access to computers for security, privacy and compliance in law enforcement, healthcare and financial services.

Passwordless, continuous authentication improves the user experience by making it frictionless – and it materially boosts security by ensuring that there’s always the right person behind the device.

About the Author: Nima Schei, is the founder and CEO of Hummingbirds AI, a supplier of technology that leveraging artificial intelligence to automate access to computers through face matching.

View Details

One must admire the ingenuity of cybercriminals.

Related: Thwarting email attacks

A new development in phishing is the “nag attack.” The fraudster commences the social engineering by irritating the targeted victim, and then follows up with an an offer to … (more…)

View Details

Government assistance can be essential to individual wellbeing and economic stability. This was clear during the COVID-19 pandemic, when governments issued trillions of dollars in economic relief.

Related: Fido champions passwordless authentication

Applying for benefits can be arduous, not least … (more…)

View Details

Endpoints are where all are the connectivity action is.

Related: Ransomware bombardments

And securing endpoints has once more become mission critical. This was the focal point of presentations at Tanium’s Converge 2022 conference which I had the privilege to attend … (more…)

View Details

Consider what might transpire if malicious hackers began to intensively leverage Artificial Intelligence (AI) to discover and exploit software vulnerabilities systematically?

Related: Cyber spying on the rise

Cyber-attacks would become much more dangerous and much harder to detect. Currently, human … (more…)

View Details

Consider what might transpire if malicious hackers began to intensively leverage Artificial Intelligence (AI) to discover and exploit software vulnerabilities systematically?

Related: Bio digital twin can eradicate heart failure

Cyber-attacks would become much more dangerous and much harder to detect. … (more…)

View Details

Ever feel like your smart home has dyslexia?

Siri and Alexa are terrific at gaining intelligence with each additional voice command. And yet what these virtual assistants are starkly missing is interoperability.

Related: Why standards are so vital

Matter 1.0… (more…)

View Details

Phishing emails continue to plague organizations and their users.

Related: Botnets accelerate business-logic hacking

No matter how many staff training sessions and security tools IT throws at the phishing problem, a certain percentage of users continues to click on their … (more…)

View Details

Cybercriminals are becoming more creative as cybersecurity analysts adapt quickly to new ransomware strategies.

Related: How training can mitigate targeted attacks

Ransomware has evolved from classic attacks to more innovative approaches to navigate reinforced security infrastructure.

Here’s how hackers crafting … (more…)

View Details

Here’s a frustrating reality about securing an enterprise network: the more closely you inspect network traffic, the more it deteriorates the user experience.

Related: Taking a risk-assessment approach to vulnerabilities

Slow down application performance a little, and you’ve got frustrated … (more…)

View Details

Humans are rather easily duped. And this is the fundamental reason phishing persists as a predominant cybercriminal activity.

Related: How MSSPs help secure business networks

Tricking someone into clicking to a faked landing page and typing in their personal information … (more…)

View Details

Employee security awareness is the most important defense against data breaches.

Related: Leveraging security standards to protect your company

It involves regularly changing passwords and inventorying sensitive data. Cybercriminals view employees as a path of least resistance. As such, you … (more…)

View Details

Standards. Where would we be without them?

Universally accepted protocols give us confidence that our buildings, utilities, vehicles, food and medicines are uniformly safe and trustworthy. At this moment, we’re in dire need of implementing standards designed to make digital … (more…)

View Details

More and more consumers are using apps every year. In fact, Google Play users downloaded 111.3 billion apps in 2021 alone, up more than 47 percent since 2018.

Related: Microsoft CEO calls for regulating facial recognition.

This increased demand for … (more…)

View Details

As digital technologies become more immersive and tightly integrated with our daily lives, so too do the corresponding intrusive attacks on user privacy.

Related: The case for regulating facial recognition

Virtual reality (VR) is well positioned to become a natural … (more…)

View Details

How did America and Americans regress to being much less secure than before the Internet?

Everyone knows the many amazing conveniences, benefits, and advances the Internet has enabled.  What everyone doesn’t know is how irrational the Internet’s utopian founding premises … (more…)

View Details

Phishing attacks are nothing new, but scammers are getting savvier with their tactics.

Related: The threat of ‘business logic’ hacks

The Iranian hacker group TA453 has recently been using a technique that creates multiple personas to trick victims, deploying … (more…)

View Details

Digital resiliency has arisen as something of a Holy Grail in the current environment.

Related: The big lesson of Log4j

Enterprises are racing to push their digital services out to the far edge of a highly interconnected, cloud-centric operating environment. … (more…)

View Details

Today’s enterprises are facing more complexities and challenges than ever before.

Related: Replacing VPNs with ZTNA

Thanks to the emergence of today’s hybrid and multi-cloud environments and factors like remote work, ransomware attacks continue to permeate each industry. In fact, … (more…)

View Details

Cybersecurity is a top concern for individuals and businesses in the increasingly digital world. Billion-dollar corporations, small mom-and-pop shops and average consumers could fall victim to a cyberattack.

Related: Utilizing humans as security sensors

Phishing is one of the most … (more…)

View Details

The pace and extent of digital transformation that global enterprise organizations have undergone cannot be overstated.

Related: The criticality of ‘attack surface management’

Massive global macro-economic shifts have fundamentally changed the way companies operate. Remote work already had an impact … (more…)

View Details

Finally, Uncle Sam is compelling companies to take cybersecurity seriously.

Related: How the Middle East paved the way to CMMC

Cybersecurity Maturity Model Certification version 2.0 could  take effect as early as May 2023 mandating detailed audits of the cybersecurity … (more…)

View Details

The internet has drawn comparisons to the Wild West, making ransomware the digital incarnation of a hold-up.

Related: It’s all about ‘attack surface management‘

However, today’s perpetrator isn’t standing in front of you brandishing a weapon. They could … (more…)

View Details

Network security has been radically altered, two-plus years into the global pandemic.

Related: Attack surface management’ rises to the fore

The new normal CISOs face today is something of a nightmare. They must take into account a widely scattered … (more…)

View Details

Penetration testing – pen tests – traditionally have been something companies might do once or twice a year.

Related: Cyber espionage is on the rise

Bad news is always anticipated. That’s the whole point. The pen tester’s assignment is … (more…)

View Details

Web application attacks directed at organizations’ web and mail servers continue to take the lead in cybersecurity incidents.

Related: Damage caused by ‘business logic’ hacking

This is according to Verizon’s latest 2022 Data Breach Investigations Report (DBIR).

In … (more…)

View Details

APIs have come to embody the yin and yang of our digital lives.

Related: Biden moves to protect water facilities

Without application programming interface, all the cool digital services we take for granted would not be possible.

But it’s also … (more…)

View Details

More than half of the world—58.4 percent or 4.62 billion people—use social media.

Related: Deploying human sensors to stop phishing.

And while that’s incredible for staying connected with friends, organizing rallies, and sharing important messages, it’s also the reason … (more…)

View Details

Short-handed cybersecurity teams face a daunting challenge.

Related: ‘ASM’ is cybersecurity’s new centerpiece

In an intensely complex, highly dynamic operating environment, they must proactively mitigate myriad vulnerabilities and at the same time curtail the harm wrought by a relentless adversary: … (more…)