Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Thursday, March 18, 2021

Understanding ransomware and the impact of repeated attacks

 


We know ransomware is one of the greatest threats in cybersecurity currently, and we know that once your organization has been hit, you’re likely to be targeted again. But how much do we understand its impact?

To gain greater insight into the risks of repeated ransomware attacks, we took a look at The State of Endpoint Security Today. This report details the findings of a survey polling more than 2,700 IT decision-makers from mid-sized businesses across ten countries.

Despite the splash ransomware made in 2017, the survey found that organizations are still not fully prepared to face today’s rapidly-evolving threats.


What was the impact of ransomware in 2017? For starters, more than half of organizations surveyed were hit with a ransomware attack last year, most more than once. Traditional antivirus alone appears to be insufficient compared to an in-depth IT Services Florence SC, as 75% of the organizations surveyed were running up-to-date endpoint protection when the ransomware attack occurred.

Perhaps unsurprisingly, the survey also found that ransomware attacks are expensive. The median total cost of an attack was $133,000 – not just the cost of the ransom, but lost hours, downtime, device and network costs, and lost opportunities. And when a business was hit hard, it got costly fast: 5% of respondents reported ransomware attacks that cost $1.3 to $6.6 million.

Arguably more telling than the ransomware statistics revealed by this report are the findings uncovered about exploits and anti-exploit technology. Nearly 70% of IT support Florence SC professionals weren’t able to correctly define anti-exploit technology, even while understanding that it is critical to prevent modern, evolving attacks.

DEEP LEARNING FOR DEEPER CYBERSECURITY

Watch Video

 

More than half of organizations don’t yet have anti-exploit technology, leaving them open to falling prey to these effective tactics by hackers.

There is a lack of understanding around predictive, next-generation technologies like machine or deep learning, with more than half (56%) admitting they don’t fully understand the differences between machine and deep learning. Though the understanding of the need for predictive, next generation technology is trending in the right direction – 60% of respondents are planning to implement such technology within a year – currently only 25% have such technology in place.

The state of endpoint protection and how current attacks are impacting users and administrators may be worrying, but we’ve got good news…

The latest version of Intercept X stops ransomware in its tracks, employs deep learning to identify malicious or potentially unwanted files without having ever seen them before and uses anti-exploit technology to block the techniques attackers use to control vulnerable software.

Find out more about our unmatched next-gen endpoint protection.


Call SpartanTec, Inc. now if you need to know more about our IT and computer security solutions. 


SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Serving: Myrtle Beach, North Myrtle Beach, Columbia, Wilmington, Fayetteville, Florence


Wednesday, February 10, 2021

Cybersecurity In this New Political Era

 

President Biden begin his term in the midst of dramatic transitions happening across the world. This isn’t about the deficit or foreign policy or climate change. Advisors well versed in strategies related to those issues surround the President.

What needs to be addressed is the global transition to a digital economy. This change is affecting every aspect of our society, from how businesses generate profit to how individuals live their lives and interact socially. The digital economy and society combine technologies and services to unlock new value in the form of better quality of life and better business outcomes. It is affecting every economic sector, from manufacturing to healthcare to finance to energy. It is changing what people do for a living, how they spend their leisure time, and where and how they spend their money, get educated, and even raise their children. The reality is that we haven’t seen such a complete and dramatic change since at least the advent of the industrial revolution, and frankly, the speed of change is unprecedented in human history.

Along with this change comes increased risks. In the rush by individuals and organizations to adopt the new tools and technologies of the digital economy, IT Support Florence SC seems to have taken a back seat. In many cases, legacy security solutions are ill-equipped to address these new challenges. For example, according to Gartner, it is estimated that by 2018 25% of corporate data traffic will bypass perimeter security (up from 4% today) and flow directly from mobile devices to the cloud, and the need to prevent data breaches from public clouds will drive 20% of organizations to develop their own data security governance programs. And by 2020 more than 25% of identified enterprise attacks will involve IoT, though IoT will account for only 10% of IT security budgets. 

The historical challenge with government trying to address these issues is that the legislative process is purposefully designed to be slow, so any regulations tend to either be too generic to be enforceable, or so specific that they are quickly out of date. However, there are a number of areas that can be addressed to get out ahead of the new IT Services Florence SC challenges that could seriously disrupt the emerging digital economy. 



1) Cybersecurity Advisory Council – Expand the role and function of the administration’s Commission on Enhancing National Cybersecurity to include more managed IT Services professionals and developers to enhance and promote industry-specific security standards and best practices, provide real-time guidance on how to respond to fast moving or consumer-facing issues, and establish accountability for failure to appropriately prepare for a cyberattack. 

In the physical world, a business has to meet certain standards, such as building codes or health inspections, in order to open a store for business. For standards and best practices, the current NIST cybersecurity framework and industry standards such as PCI-DSS are good starts. But the growth of smart devices, IoT networks, connected devices, big data, smart buildings and cities, and interconnected critical infrastructures continue to dramatically change our social and financial landscape, and have correspondingly expanded the risk facing our growing digital economy. Guidelines need to be expanded for these new industries and markets, business security certification processes need to be developed, and security training standards and incentives need to be implemented to close the growing computer security skills gap.

2) Accelerate Information Sharing - We won’t be able to respond fast enough to emerging threats without good threat intelligence. And that means information sharing between organizations responsible for our critical infrastructure. The Cybersecurity Act of 2015 established a framework for the sharing of information on cybersecurity threats and defensive measures among private sector entities and between the private sector and the government, and encourages the voluntary participation in informal bodies like ISAOs. But organizations still only share a fraction of the intelligence that is needed. 

Too many industries and organizations are still understandably skittish about sharing information. It’s time to establish governing bodies that can set information sharing standards for critical industries, and insist on auditing and certifications of compliance. 

3) Accountability – The risks imposed on consumers and the economy due to cybercrime is well understood. It is time for organizations to accept greater accountability for data breaches, especially those affecting consumers’ financial or personal data. The recent massive Mirai denial of service attack, largely based around vulnerable IoT devices, is a perfect example. Security professionals have been issuing warnings about the lax security standards for connected devices, and the dire consequences billions of such devices pose. Unfortunately, those industries building IP-enabled appliances and devices have generally failed to respond. Their development and manufacturing models often do not adequately account for risk, or the speed at which modern threats can escalate. But as a society, we simply cannot afford to let the cost of a security breach and associated fines simply be rolled into the cost of doing business. 

Accountability is fundamental, and is beginning to move upstream. For example, the SEC’s Office of Compliance Inspections and Examinations (OCIE) now examines financial services institutions to ensure that governance and risk assessment measures are in place to mitigate cyber risk. And former SEC commissioner Luis Aguilar argued that corporate directors could be held personally liable for cyber breaches if they fail to ensure that appropriate cybersecurity is in place. Establishing stricter standards for accountability need to be considered. 

4) Business Incentives – To properly motivate organizations, financial incentives need to be established to encourage businesses to meet security standards. This could include requiring cyber insurance for a company that has been breached, and a path for reducing cyber insurance premiums based on meeting a series of established security standards. Publicly traded companies should also be required to clearly post penalties and progress towards compliance in quarterly and annual financial reports.

Another such approach would be to establish a business security rating that is shared publicly. A scaled rating system shared with consumers, based on an organization’s meeting security standards set by the cybersecurity advisory council, would motivate businesses to achieve certification, implement stronger security standards, and advertise them as a business differentiator. 

Security differentiation would be revenue generating, and inevitably create a safer environment for everyone. This same approach has been very successful in the automotive industry. The introduction of air bags, for example, not only drove the decisions of safety conscious buyers, but buyer behavior combined with compliance requirements motivated the entire industry to adopt these standards. Now there is a race to include more and better safety equipment, such as traction and stability control, cameras, accident avoidance systems, and environment monitoring technologies. And as a result, auto accident related deaths and injuries are at an all time low.

5) Public Awareness - Finally, we need to encourage risk-based situational awareness campaigns for companies and consumers. There have been massive public campaigns designed to encourage people to reduce risky behavior in other areas of national interest, such as warning of the risks of smoking, or texting and driving. And they work. We need something like this for cyberspace. 

We recommend funding a series of public awareness campaigns designed to raise consumer intelligence about cybersecurity. Raising the national profiles of October as National Cyber Security Awareness Month, would help, as would the commissioning and placement of a series of public service announcement ads on television, online, and in print. While security standards and strategies need to take into account that people have and will continue to engage in risky online behavior, developing awareness campaigns will improve security generally and make everyone’s job easier.

Next, establish local cybersecurity agencies and offerings along the lines of a health clinic, such as that provided to Federal agencies and critical infrastructure organizations by the Department of Homeland Security’s National Protection and Programs Directorate. Local versions of such an agency could offer educational programs and information, issue warning about threats and viruses, and provide reduced-cost services for businesses and users, such as security checkups, device “vaccinations,” and troubleshooting based on need.

And finally, the establishment of cybersecurity training in public school STEM/STEAM programs for every student in grades K-12. We need to raise a generation of technology-savvy citizens and consumers who understand the fundamental necessity of integrated and adaptive security built into the cyberworld that increasingly surrounds them and permeates every aspect of their lives.

This post originally appeared as a byline in The Huffington Post.

Call SpartanTec, Inc. now if you are looking for professionals who can provide you with top quality IT Services Florence SC. 


SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Serving: Myrtle Beach, North Myrtle Beach, Columbia, Wilmington, Fayetteville, Florence


Friday, November 27, 2020

Q&A: How Secure Are Your Company’s Applications?


 Organizations of all types today face an ever evolving threatscape and growing pressure to rethink security strategies for long-term sustainability. Today’s enterprises operate in a complex technological environment, with a variety of devices, applications, and users accessing the network. Fortinet’s Mark Byers discusses the issues and trends affecting the security of enterprise applications.


Q&A with Mark Byers


What do companies need to know about security as it relates to their application infrastructure?


When most companies think about cyber security Florence SC, they think of their network. This is a great place to start—but it’s not the whole picture. The question we need to ask is, what exactly needs to be secured, and why? At the end of the day, we’re really talking about the need to secure data—whether it’s customers’ credit card data, health information, corporate financial data, employee information, proprietary information, etc. And that means we need to consider all the different access points that need to be secured. One of the weakest links is applications. You can have multiple layers of network security, but once you expose an application to the Internet, your network security is not enough. When a company provides users access to an online application with a user ID and password, that user and attackers now have access to the data that can potentially bypass many layers of carefully crafted security protections.

 

 

So where do companies need to focus to ensure their applications are secure?


This sounds daunting but the truth is, they need to consider everywhere. You need to protect all access points to data – where it sits in a repository or server, where and when the data is accessed through an application, and when it’s shared with other applications or users. This is why a security fabric is critically important. You need policies to ensure enterprise users have different passwords for certain systems, two-factor authentication to verify they are who they say they are and that they’re authorized to access particular systems or information. Companies need increased intelligence of network services that allow users to identify threats in emails and machine learning that helps detect threat signatures. Administrators need a system strategy that correlates data and helps identify threats spanning multiple systems. They need security systems that are deeply integrated so that they can share threat intelligence and events to close the gap between devices and applications.


Talk about some of the well-known application security issues we have heard in the media. What’s happening?


From an enterprise perspective, the UK telecommunications company TalkTalk was in the news in October 2015 when nearly 157,000 customer data records were compromised. At fault was a breach in an application code; a simple SQL command opened up a back door to their data. This event resulted in the loss of more than 200,000 customers and significant dip in their revenues.

In general, though, some of the most well-known security issues involve Adobe Flash. In fact, Google recently announced that their Chrome browser will no longer support Flash by the end of 2016. Flash is so pervasive; it’s used by the majority of devices. And the challenge is that when a critical vulnerability is  uncovered, it’s then only a matter of days before an attack occurs. That means one vulnerability in this one platform can have a widespread effect. What’s also concerning is that users do not regularly update to the latest version of Flash as it’s available. According to the Verizon 2016 Data Breech Investigations Report (DBIR) in one year’s time 45 percent of devices still had not updated to the latest version of flash and so still have no patch to address security issues.


It seems like there are patches pushed every day. We are constantly being asked to update our applications. Are they really that insecure?


The short answer is yes. The common vulnerability and exposures section of DBIR is important to review to understand the variety of issues. As soon as vulnerabilities are exposed, malicious attackers will instantly act on and exploit these vulnerabilities. Using Flash again as an example, should users update Flash as soon as a new version is pushed out? Yes. Do they? No. And the consequence is that one infected computer can affect the rest of the system.

If you’re running an enterprise system and the SSL protocol is compromised, this must be updated as soon as possible. There are tools available to help patch security holes, to scan for problems and malware, and to help mitigate those situations when updates don’t occur regularly.


There are lots of different types of applications: cloud apps, enterprise apps, consumer apps, database apps. Are there different security concerns that customers need to address?


Cloud-based applications are generally fairly good in terms of their security. But if an end user doesn’t change his/her password regularly, then your data could be compromised. In most instances, breaches occur because users are sharing credentials, or they’re not changing their passwords regularly. So it’s really a user issue and not an application issue.

On the enterprise side, an organization may have great e-commerce system all based on code that needs to be kept up to date. As long as you’re patching regularly and staying up to date, you’re fine. Companies need to employ application firewalls to help with zero day attacks. And they need to isolate their systems so that they’re not sitting directly on the Internet, which makes them more vulnerable. If applications and data are on the same server, you need to ensure that all information is channeled through a secure access point. Often within a company there’s a need to bring up a web-based application quickly for many users to access, and simple steps are overlooked that are the security equivalent to forgetting to lock the door behind them.


Data is growing exponentially, and our use of applications to run our businesses and our lives is never ending. What lies ahead for security and applications?


It’s becoming more and more important to have a deeply integrated security fabric that can help close the gaps, share intelligence across systems, and sift through vast amounts of data rapidly. Companies and security administrators don’t have the ability to review thousands of pages of data only to realize that a breach occurred the prior week. Every minute counts.

Technology is trying to stay ahead of the bad guys, to better identify threats and determine behavior abnormalities. Advanced persistent threats are many times customized to an organization and can employ multiple attack types until the target is compromised. Behavioral tools with advanced heuristics can help diagnose attacks as they’re happening, even if they’re different from previously identified attacks. Companies can run a baseline behavioral view in as little as an hour, and then this information helps the system identify abnormal behaviors. It could be as overt as a user attempting to access unauthorized systems or as unique as a user who is logging into applications from an unknown device at an atypical time of day.

 

Companies need to enforce a robust security policy that includes passwords, two-factor authentication, and regularly updated training. Call SpartanTec, Inc. now for more information.

 

SpartanTec, Inc.
Myrtle Beach, SC 29577
(843) 420-9760
https://www.spartantec.com/

SpartanTec, Inc.
Florence, SC 29501
843-396-8762
http://manageditservicesflorence.com

Serving: Myrtle BeachNorth Myrtle BeachColumbiaWilmingtonFayettevilleFlorence