15.11.21

 


Dix mesures clés à adopter après une violation de données

Phil Muncaster

On estime que, dans le monde, les brèches de données coûtent aujourd’hui plus de 4,2 millions $ US par incident. Elles se produisent à une échelle sans précédent alors que les organisations développent leur infrastructure numérique – et étendent involontairement la surface d’attaque de l’entreprise. Aux US,  le nombre de violations au troisième trimestre 2021 avait dépassé celui de l’année 2020. Il faut bien trop de temps à l’organisation moyenne pour trouver et contenir les violations de données –il faut en moyenne 287 jours. 

Une fois que les alarmes se déclenchent, que se passe-t-il ? Voici ce qu’il faut faire et éviter de faire, après une violation.

·       Rester calme

Une violation de données est une des situations les plus stressantes dans lesquelles une entreprise se trouve, surtout si l’incident a été causé par des rançongiciels, dont les cyber-attaquants ont crypté des systèmes clés et exigent un paiement. Les réactions impulsives peuvent faire plus de mal que de bien. S’il est important de remettre l’entreprise en état de fonctionnement, il est crucial de travailler avec méthode. Il faut passer en revue le plan de réponse aux incidents et comprendre l’étendue de la compromission avant de prendre des mesures importantes.

5 étapes essentielles avant de subir une attaque de rançongiciel 

 ·       Suivre  le plan de réponse aux incidents

La question n’est pas de savoir « si », mais « quand » votre organisation fera face à une violation de sécurité, un plan de réponse aux incidents est une pratique essentielle en matière de cyber-sécurité. Cela nécessite une planification avancée. On peut suivre les conseils de l’Institut national des normes et de la technologie (NIST) des US ou du Centre national de cybersécurité (NCSC) du Royaume-Uni. Lorsqu’une violation grave est détectée, une équipe de réponse préétablie, composée de parties prenantes de toute l’entreprise, doit suivre les processus étape par étape. Il faut tester ces plans périodiquement pour que tout le monde soit prêt et que le document lui-même soit à jour.

 ·       Évaluer la portée de la violation

La première étape après tout incident sécuritaire majeur est de comprendre l’ampleur de l’impact sur l’entreprise. Cela servira aux actions ultérieures, telles que la notification et la remédiation. Il faut savoir comment les malfrats sont entrés et déterminer le rayon d’action de l’attaque : quels systèmes ont été touchés, quelles données ont été compromises et s’ils sont encore dans le réseau. C’est là que des experts en criminalistique interviennent souvent.

 ·       Impliquer les services juridiques

Suite à une violation, il faut savoir où en est l’organisation. Quelles sont vos responsabilités ? Quels sont les organismes de réglementation qu’il faut informer ? Faut-il négocier avec les attaquants pour gagner du temps ? Quand les clients et/ou les partenaires doivent-ils être informés ? Le conseil juridique interne est le premier qui doit être informé. Mais  on peut aussi faire appel à des experts en réponse aux cyber-incidents. C’est là que les détails légaux sur ce qui s’est réellement passé sont essentiels, afin que ces experts puissent prendre les décisions les plus éclairées.

 ·       Savoir qui, quand et comment aviser

Selon les termes du RGPD, la notification au régulateur local doit avoir lieu dans les 72 heures suivant la découverte d’une violation. Il est donc important de savoir quelles sont les exigences minimales en matière de notification, car certains incidents peuvent ne pas l’exiger. Une bonne compréhension de la taille du problème est essentielle. Si l’on ne sait pas quelle quantité de données a été subtilisée ou comment les malfrats sont entrés, il faut envisager le pire lors de la notification au régulateur. Au Royaume-Uni, le bureau à l’information (ICO), qui a contribué à l’élaboration du RGPD, propose des lignes directrices utiles à ce sujet.

 ·       Informer les forces de l’ordre

Quoi qu’il arrive avec le régulateur, il faut probablement obtenir l’appui des forces de l’ordre, en particulier si le malfrats se trouvent encore dans le réseau de l’organisation. Il est judicieux de les mettre à contribution dès que possible. Dans le cas d’un rançongiciel, ils peuvent vous mettre en contact avec des fournisseurs de sécurité et d’autres tiers qui proposent des clés de décryptage et des outils d’atténuation.

 ·       Informer clients, partenaires et employés

C’est bien évident. Cependant, le nombre de clients/employés/partenaires à informer, ce qu’il faut leur dire et quand dépendra des détails de l’incident et de ce qui a été volé. Il faut d’abord publier une déclaration d’attente indiquant que l’organisation est au courant d’un incident et qu’une enquête est en cours. Mais comme la rumeur s’amplifie très vite, il faut rapidement donner plus de détails. Les équipes chargées de l’informatique, de la communication et des affaires juridiques doivent travailler en étroite collaboration sur ce point.

 ·       Commencer la récupération et la remédiation

Une fois que la portée de l’attaque est connue et que les équipes d’intervention et d’analyse sont sûres que les malfrats n’ont plus accès au site, il est temps de remettre les choses en marche. Il peut s’agir de restaurer des systèmes à partir de sauvegardes, de remettre à niveau des machines compromises, d’appliquer des correctifs aux terminaux affectés et de réinitialiser les mots de passe.

·       Commencer à renforcer la résilience face aux futures attaques

Les malfrats partagent souvent leurs connaissances dans les réseaux clandestins de la cybercriminalité. Ils reviennent parfois à plusieurs reprises pour compromettre les organisations victimes, notamment en faisant appel aux rançongiciels. Il est donc très important d’utiliser les informations glanées par les outils de détection et de réponse aux menaces et les outils de criminalistique pour s’assurer que les voies utilisées la première fois ne puissent plus l’être lors de futurs raids. Cela peut se traduire par des améliorations de la gestion des correctifs et des mots de passe, une meilleure formation à la sécurité, la mise en place de l’authentification multifactorielle (MFA) ou des changements plus complexes au niveau des personnes, des processus et de la technologie.

·       Étudier les erreurs dans la réponse aux incidents

La dernière chose à faire consiste à tirer des enseignements de l’expérience. Il s’agit en partie de renforcer la résilience pour l’avenir, comme indiqué ci-dessus. Mais on peut aussi s’inspirer de l’exemple des autres. L’histoire des violations de données est émaillée de cas très médiatisés de mauvaise réponse aux incidents. Dans ce cas très médiatisé, le compte Twitter d’une entreprise victime d’une violation a tweeté quatre fois un lien d’hameçonnage, le confondant avec le site de réponse aux violations de l’entreprise. Dans un autre cas, une grande société de télécommunications britannique a été très critiquée pour avoir diffusé des informations contradictoires.

Quoi qu’il arrive, les clients s’attendent de plus en plus à ce que les organisations avec lesquelles ils font affaire subissent des incidents de sécurité. C’est la façon dont on réagit qui déterminera s’ils resteront ou quitteront le navire et quels seront les dommages financiers et de réputation.

 

 


ESET steunt SAFER, nieuwe beveiligingsgroep opgericht om de onderzoeks- en onderwijssector te helpen beschermen

BRATISLAVA – 15 november  2021 –  ESET steunt Marc-Étienne Léveillé, Senior Malware Researcher en stichtend lid van SAFER Trust Group (Security Assistance For Education & Research), een nieuwe organisatie van onafhankelijke beveiligingsexperten die samenwerken om de onderzoeks- en onderwijssector (Research & Education - R&E) beter te beveiligen tegen bedreigingen. Als enige organisatie uit de privé sector, sluit ESET zich aan bij publieke organisaties om de stichtende leden die hun expertise inzetten om onderwijs en onderzoek te beschermen, veiliger te maken en te ondersteunen.

SAFER is een nieuwe organisatie met als doel het aanpakken van cyberdreigingen die wereldwijd gericht zijn op universiteiten, onderzoek- en onderwijssector. Het is opgericht door beveiligingsexperts, ondersteund door hun respectieve organisaties, waaronder ESET. Het heeft tot doel onderzoeks- en onderwijsorganisaties te voorzien van mogelijkheden om respons te bieden bij wereldwijde incidenten.

Als organisatie geleid door haar leden, accepteert SAFER geen sollicitaties maar nomineert het kandidaten die actief zijn in het beveiligen van de R&E-sector. Zo heeft elk lid een belangrijke bijdrage geleverd aan de veiligheid van de R&E-sector en is als betrouwbaar erkend. Marc-Étienne Léveillé, ondersteund door het malware-onderzoeksteam van ESET, werkte samen met de R&E-sector tijdens het diepgaande onderzoek naar Windigo en Kobalos. Kobalos is een Linux-backdoor die zich richt op supercomputers en meer bepaald op computers gebruikt in universiteiten en wetenschappelijke instellingen. ESET's onderzoek naar Kobalos gebeurde in samenwerking met CERN, een van de organisaties die SAFER ondersteunt. Andere organisaties die het werk van de SAFER-groep ondersteunen, zijn onder andere LBNL, DFN-CERT, ESnet, STFC en WLCG.

ESET ondersteunt al vele jaren onderwijs, universiteiten en onderzoek. Dit resulteerde in de oprichting van de ESET Foundation. Deze heeft tot doel onderwijs, onderzoek en wetenschappelijke vooruitgang te bevorderen ten behoeve van de samenleving. Naast haar andere activiteiten beloont de ESET Foundation de prestaties van wetenschappers in Slowakije tijdens haar jaarlijkse ESET Science Award.

Investeren in het onderwijs en de ontwikkeling van de gemeenschap, en in het bijzonder van kinderen, is een van de hoofddoelen van de ESET Foundation. Een ander voorbeeld van ESET's steun aan de academische wereld is de samenwerking met de Slowaakse Technische Universiteit in Bratislava (Slovak University of Technology), waar technologiespecialisten van ESET interuniversitaire vakken doceren en aan onderzoek doen. Op WeLiveSecurity publiceert ESET de resultaten van zijn eigen onderzoek in cyberbeveiliging om de sensibilisering voor bedreigingen te vergroten.

ESET's steun aan SAFER, nieuw initiatief gericht op de bescherming van de R&E-sector in een wereld waar toenemende dreigingen uitgaan van internationale criminele organisaties en natiestaten, is een bijdrage die overeenstemt met haar missie voor een veiliger internet.

Om meer te vernemen over ESET, ga naar https://www.eset.com/be-nl/

Over ESET

Al meer dan 30 jaar ontwikkelt ESET® geavanceerde IT-beveiligingssoftware en -diensten om bedrijven, kritieke infrastructuur en consumenten wereldwijd te beschermen tegen steeds meer gesofisticeerde digitale dreigingen. Van endpoint- en mobiele beveiliging tot detectie en respons van endpoints, encryptie en multi-factor authenticatie, beschermen en bewaken ESET's krachtige, gebruiksvriendelijke oplossingen discreet 24/7. Ze updaten in realtime de verdediging om ononderbroken gebruikers en ondernemingen te beveiligingen.

De constant veranderende bedreigingen vragen een schaalbare provider van IT-beveiliging zodat technologie veilig kan gebruikt worden. Dit wordt ondersteund door ESET’s R & D-centra over de hele wereld. Deze zetten zich in om onze gemeenschappelijke toekomst te ondersteunen.

Voor meer informatie bezoek www.eset.com  of volg het nieuws op LinkedIn, Facebook, en Twitter.

Om meer te vernemen over de ESET-oplossingen, bezoek https://www.este.com/be-nl/

 

22.10.21

 


Carrière in cybersecurity: wat moet je weten en hoe aan de slag gaan?

Hoe carrière maken in cybersecurity? Welke kwalificaties, certificeringen en vaardigheden heeft men nodig? Moet men de helft van de prijs van een huis uitgeven voor een diploma van hoog niveau? Moet men proberen het Pentagon te hacken? Dit zijn vragen die vaak aan ESET worden gesteld. Geen beter moment om ze te beantwoorden dan Cybersecurity Career Awareness Week, een campagne die deze week plaatsvindt en deel uitmaakt van Cybersecurity Awareness Month.

De vraag naar professionals in cybersecurity blijft het aanbod overtreffen. Het gebrek aan kandidaten blijft deprimerend omdat de dreigingen blijven toenemen. Geen enkele organisatie is immuun voor de talloze risico's die gepaard gaan met cyberaanvallen, aangezien bedreigingen in omvang en frequentie toenemen, dichter bij huis toeslaan en ongeziene schade aanrichten. Veel bedrijven zullen dus een hoge prijs betalen om talent in security binnen te halen en te behouden en het lijkt erop dat de sterren gunstig zijn afgestemd voor zij die de geboden kansen willen grijpen.

Maar waarom kiezen voor een carrière in cybersecurity?

Er zijn de klassieke redenen, zoals het najagen van roem en/of fortuin, maar een groot deel van de aantrekkingskracht is dat dit een van de weinige vakgebieden is waar één persoon, met zijn computer, zijn intelligentie en doorzettingsvermogen echt op een meetbare en merkbare manier het verschil kan maken. Aan de slag gaan in cybersecurity betekent de mogelijkheid hebben om iets te doen dat impact heeft en anderen helpt.

Houd er rekening mee dat succes uiteindelijk een individuele maatstaf is, en dat de dingen die ons de meeste voldoening geven, niet deze zijn die de meeste aandacht krijgen in de media, sociale of andere. Werken in cybersecurity biedt ook kansen die weinig andere beroepen bieden, zowel op het gebied van aangeleerde als toegepaste kennis.

Succes is uiteindelijk een individuele maatstaf en de dingen die ons de meeste voldoening geven zijn niet deze die de meeste aandacht krijgen in de media, sociale of andere. Maar werken in cybersecurity biedt kansen die weinig andere beroepen bieden, zowel op gebied van aangeleerde als toegepaste kennis.

Betaald worden om dingen kapot te maken voor het welzijn van iedereen? Benieuwd hoe iets werkt? Waarom gaan dingen kapot? Hoe zouden we kapotte dingen repareren, als we er de kans toe kregen? Al die dingen waarvoor we thuis in de problemen kwamen toen we opgroeiden, waren voor veel onderzoekers het begin van hun ontluikende talent en hun latere carrières.

Al die dingen die we uit elkaar hebben gehaald om te weten hoe ze werken, kunnen de bron van ons succes zijn. Hoewel onze populariteit thuis en op school regelmatig in twijfel werd getrokken, zijn dezelfde eigenschappen nuttig bij de beveiliging van software en hardware.

Wat houdt een baan in cybersecurity eigenlijk in?

Een groot deel van het werk bestaat uit praten met mensen. Een ander belangrijk rdeel is om naar mensen te luisteren. Er wordt ook tijd besteed aan lezen, dat kan variëren van een technisch document tot sociale media of interne documentatie. Soms moet men bepaalde dingen opschrijven. Een van de voordelen van zo’n baan is dat het erg afwisselend is. Om een ​​voorbeeld te geven van hoe al dit chatten en luisteren in de echte wereld werkt, kan het in een week gaan over:

• monitoren van opkomende dreigingen en van de actoren van deze dreiging

• gesprekken met een collega in Europa/VS over de verschillen in privacywetten en verwachtingen

• beantwoorden van een paar vragen van een overheid over ESET-software

• enkele antwoorden geven aan de ontwikkelaars over de volgende versie van een programma

• de security review van het nieuwe Microsoft Windows 11 besturingssysteem

• rapporteren van spammers en fraudeurs aan het ESET Threat Lab.

Er zijn ook activiteiten op langere termijn, zoals een project waarbij we proactief op zoek gaan naar valse positieve alarmen in onze bedreigingdetecties. Voor een bedrijf kan een vals positief zeer problematisch zijn, daarom doet ESET alles om dit te voorkomen.

Er zijn ook meer zakelijke/HR-achtige taken. Dingen uit elkaar halen is goed, maar werken voor een bedrijf dat dingen verkoopt, betekent dat men ook dingen moet opknappen en begrijpelijke moet kunnen rapporten aan mensen die geen binair spreken. En dit zijn de meeste mensen. Het moet logisch en nuttig zijn voor iemand die betrokken is bij het kopen of verkopen.

Welke vaardigheden en kwalificaties zijn vereist?

Voor een instapjob - waarvoor nul tot een jaar ervaring vereist is – moet men een goed begrip hebben van de manier waarop een computer werkt, alsook zijn besturingssysteem (inclusief de verschillende componenten ervan) en hoe informatie over netwerken wordt verzonden. Dit is een goede start. Valt er iets te verdedigen, dan zal een goed begrip van hoe het werkt, helpen om beter in te zien wat de zwakke punten zijn en hoe men ze kan verdedigen. Met een goed begrip van deze fundamentele principes heeft men we een solide basis waarop men zijn kennis zal verdiepen, diversifiëren en de gebieden die interessant zijn, zullen verkennen. Men zal zich verder kunnen opwerken met de hulp van de werkgever, aanvullende professionele training, enz.

Ga voor meer informatie naar https://www.eset.com/be-nl/

 


Carrière en cyber-sécurité : que faut-il savoir et comment se lancer ?

Faire carrière en cyber-sécurité? Quelles qualifications, certifications et compétences faut-il? Faut-il dépenser la moitié du prix d'une maison pour un diplôme de haut niveau? Faut-il essayer de pirater le Pentagone? Ce sont des questions qui sont fréquemment posées à ESET. Quel meilleur moment pour essayer d'y répondre que la Semaine de Sensibilisation aux Carrières en Cyber-sécurité, une campagne qui se déroule cette semaine et fait partie du Mois de la Sensibilisation à la Cyber-sécurité ?

La demande en professionnels de la sécurité continue à dépasser l'offre. Le manque de talents reste déprimant, notamment parce que les menaces de sécurité ne diminuent vraiment pas. Aucune organisation n'est à l'abri de la myriade de risques associés aux cyberattaques, car les menaces croissent en taille et en fréquence et frappent plus près de chez nous, causant des dommages incalculables. De nombreuses entreprises paieront le prix fort pour recruter et retenir des talents en sécurité et il semble que les astres soient bien alignées pour ceux qui souhaitent saisir les opportunités offertes.

Mais pourquoi choisir une carrière en cyber-sécurité?

Il y a les raisons classiques, telles que la recherche de la gloire et/ou de la fortune, mais une grande partie de l'attrait est que c'est l'un des rares domaines où une seule personne, armée de son seul ordinateur, de son intelligence et de sa persévérance, puisse réellement faire la différence d'une manière mesurable et perceptible. Entrer en cyber-sécurité signifie avoir la possibilité de faire quelque chose qui a un impact et qui aide les autres.

Il faut garder à l'esprit que le succès est finalement une mesure individuelle, et les choses qui nous apportent le plus de gratification peuvent ne pas être celles qui attirent le plus d'attention dans les médias, sociaux ou autres. Mais travailler dans la cyber-sécurité permet d’accéder à des opportunités que peu d'autres professions offrent, tant en termes de connaissances apprises que de connaissances appliquées.

Etre payé pour casser des trucs pour le bien de tous ? Curieux de savoir comment les choses fonctionnent ? Pourquoi les choses se cassent-elles ? Comment réparerions-nous les choses cassées, si on en avait l'occasion ? Toutes ces choses pour lesquelles, en grandissant, on a eu des ennuis à la maison donnent le coup d’envoi à une grande partie des talents naissants et des carrières en herbe pour bon nombre de chercheurs.

Toutes ces choses qu’on a démontées pour découvrir comment elles fonctionnent, pourraient être la source de notre succès. Bien que notre popularité à la maison et à l'école ait régulièrement été remise en question, ces mêmes qualités sont utiles dans la sécurité des logiciels et du matériel informatique.

Qu'est-ce qu'un job en cyber-sécurité implique réellement?

Une grande partie du travail consiste à parler aux gens. Une autre partie importante consiste à les écouter. Encore plus de temps est consacré à la lecture, pouvant aller d'un document technique aux médias sociaux en passant par la documentation interne. Parfois, il faut écrire certaines choses. L'un des avantages de ce travail est qu'il est très varié. Pour donner un exemple de la façon dont toutes ces conversations et ces écoutes fonctionnent dans le monde réel, en une semaine, il peut y avoir :

• la surveillance de menaces émergentes et des acteurs de cette menace

• des discussions avec un collègue en Europe/aux USA sur les différences entre les lois et les attentes en matière de confidentialité

• répondre à quelques questions d’un gouvernement sur le logiciel ESET

• donner quelques réponses aux développeurs sur la prochaine version d'un programme

• l’examen de la sécurité du nouveau système d'exploitation de Microsoft Windows 11

• signaler les spammeurs et les fraudeurs au laboratoire des menaces ESET.

 

Il y a des activités à plus long terme, telles qu'un projet où l’on recherche de manière proactive les fausses alarmes positives dans nos détections de menaces. Avoir un faux positif peut être très problématique pour une entreprise, c'est pourquoi ESET s'efforce de les prévenir.

Il y a plus de trucs de type corporate/RH. Démonter des choses, c'est bien, mais travailler pour une entreprise qui vend des choses signifie que l’on doit aussi remettre les choses en état et fournir des rapports compréhensibles aux personnes qui ne parlent pas binaire. Et ce sont la plupart des gens. Il faut que cela ait du sens et soit utile pour quelqu'un qui est impliqué  dans la vente ou l'achat de quelque chose.

De quelles compétences et qualifications a-t-on besoin ?

Pour un poste d'entrée - qui nécessite de zéro à un an d'expérience – il faut une compréhension des principes fondamentaux du fonctionnement d'un ordinateur, d’un système d'exploitation (y compris une compréhension de haut niveau de ses divers composants), et comment l'information est transmise sur les réseaux. C’est un bon point de départ. S’il faut défendre quelque chose, avoir une compréhension pratique de son fonctionnement aidera à mieux voir quels sont ses points faibles et comment les défendre. Avec une bonne compréhension de ces principes fondamentaux, on dispose d'une base solide sur laquelle on va approfondir ses connaissances, se diversifier et explorer les domaines qui nous intéressent ainsi que nous former davantage avec l'aide de notre employeur grâce à une formation professionnelle supplémentaire, etc.

Pour en savoir plus, rendez-vous sur https://www.eset.com/be-fr/ .

18.10.21

 

Employee offboarding: why companies must close a crucial gap in their security strategy

There are various ways a departing employee could put your organisation at risk of a data breach. How do you offboard employees the right way and ensure your data remains safe?

Phil Muncaster

The COVID-19 pandemic has created the perfect conditions for insider risk. Financial crises have in the past led to a spike in fraud and nefarious activity, and it’s reasonable to assume that the wave of job losses and uncertainty that emerged in early 2020 did the same. At the same time, companies have never been more exposed, through extensive supply chains and partnerships, and their remote working and cloud infrastructure – much of which was built up in response to the pandemic.

The bottom line is that, by design or accident, employees on their way out of the door may end up causing significant financial and reputational damage if the risks are not properly mitigated. The cost of insider-related incidents spiked 31 percent between 2018 and 2020 to reach nearly US$11.5 million. That makes effective offboarding processes an essential part of any security strategy – yet one that’s too often overlooked.

Can (departing) employees be trusted?

The corporate attack surface is often viewed through a lens of external threat actors. But it can also be abused by internal employees. Cloud-based applications, data stores and other corporate networked resources can be accessed today in many organizations from virtually any device, anywhere. This has become essential to supporting productivity during the pandemic, but it can also make it easier for employees to circumvent policies unless the right controls are in place. Unfortunately, research suggests that many (43 percent) organizations don’t even have a policy that forbids staff taking work data with them when they leave. Even more concerning, in the UK, only 47 percent revoke building access as part of offboarding and just 62 percent reclaim corporate devices.

Additionally, separate data finds that nearly half (45 percent) download, save, send or exfiltrate work-related documents before leaving employment. This happens most frequently in the tech, financial services and business, consulting and management sectors.

Why does it matter?

Whether they take data with them to impress a new employer, or steal or delete it as the result of a grudge, the potential impact on the organization is severe. A serious data breach could lead to: ·       Investigation, remediation and clean-up costs ·       Legal costs stemming from class action lawsuits ·       Regulatory fines ·       Brand and reputational damage ·       Lost competitive advantage 

In one recent case, a credit union employee pleaded guilty to destroying 21GB of confidential data after she was fired. Despite a colleague requesting that IT disable her network access during offboarding, it was not done in time and the individual was able to use her username and password to access the file server remotely for around 40 minutes. It cost the credit union US$10,000 to fix the unauthorized intrusion and deletion of documents.

How to create more secure offboarding

Many of these threats could have been better managed if the organizations involved had put in place more effective offboarding processes. Contrary to what you might think, these should begin well before an employee signals their intent to resign, or before they are fired. Here are a few tips:

Clearly communicate policy: An estimated 72 percent of office workers apparently think the data they create at work belongs to them. This could be anything from client lists to engineering designs. Helping them understand the limits of their ownership of IP, with clearly communicated and formally written policy, could prevent a great deal of pain down the line. This should be part of any onboarding process as standard, along with clear warnings about what will happen if staff break policy.

Put continuous monitoring in place: If an unscrupulous employee is going to steal information prior to leaving your company, they’re likely to begin doing so well before they notify HR of their job move. That means organizations must put in place monitoring technologies that continuously record and flag suspicious activity—whilst of course observing local privacy laws and any employee ethical concerns.

Have a policy and process ready and waiting: The best way to ensure seamless and effective offboarding of every employee is to design a clear process and workflow ahead of time. Yet while nearly all organizations have an onboarding process, many forget to do the same for departing staff. Consider including the following: ·       Revoke access and reset passwords for all apps and services ·       Revoke building access ·       Exit interview to check for suspicious behavior ·       Final review of monitoring/logging tools for evidence of unusual activity ·       Escalate to HR/legal if suspicious activity is detected ·       Reclaim any physical corporate devices ·       Prevent email forwarding and file sharing ·       Reassign licenses to other users

As organizations gear up to face the post-pandemic world, competition for customers will be fiercer than ever. They can little afford valuable IP walking out of the door with departing employees, or the financial and reputational damage that could result from a serious security breach. Offboarding is one small piece of the security puzzle. But it’s a critically important one.

14.10.21

 


Microsoft thwarts record‑breaking DDoS attack

The attack, which clocked in at 2.4 Tbps, targeted one Azure customer based in Europe

 Amer Owaida

Microsoft has revealed that it thwarted a Distributed Denial-of-Service (DDoS) attack that clocked in at a whopping 2.4 terabytes per second (Tbps). The onslaught, which targeted an Azure customer in Europe, surpasses the previous record holder – a 2.3 Tbps attack that was mitigated by Amazon Web Services (AWS) last year. It also dwarfs the previously largest DDoS attack (1 Tbps) on Azure from 2020.

According to Microsoft, the latest attack originated from some 70,000 sources and from several countries in the Asia-Pacific region, including Malaysia, Vietnam, Taiwan Japan, and China, as well as from the United States.

“The attack vector was a UDP reflection spanning more than 10 minutes with very short-lived bursts, each ramping up in seconds to terabit volumes. In total, we monitored three main peaks, the first at 2.4 Tbps, the second at 0.55 Tbps, and the third at 1.7 Tbps,” said Senior Program Manager at Azure Networking Amir Dahan in a blog post describing the incident.

“The pace of digital transformation has accelerated significantly during the COVID-19 pandemic, alongside the adoption of cloud services. Bad actors, now more than ever, continuously look for ways to take applications offline,” Dahan added.

Traditional DDoS attacks overwhelm a target with bogus web traffic that comes from a large number of devices that have been corralled into a botnet. The aim of the attack is to take the victim’s servers offline and denying access to their services. If the attackers utilize a reflection amplification attack, they can amplify the volume of malicious traffic while obscuring its sources.

Historically, DDoS attacks have been used as a smokescreen for other, even more damaging onslaughts, or as a means to demand massive ransom fees from the targeted companies. While the victims could stand to lose millions of dollars in revenue from the reputational damage combined with the cost of downtime caused by these attacks, there is no guarantee that the attackers would cease their onslaught even if the ransoms are paid.

 


Ransomware cost US companies almost $21 billion in downtime in 2020

The victims lost an average of nine days to downtime and two-and-a-half months to investigations, an analysis of disclosed attacks shows

 


Amer Owaida

An analysis of 186 successful ransomware attacks against businesses in the United States in 2020 has shown that the companies lost almost US$21 billion due to attack-induced downtime, according to technology website Comparitech. Compared to 2019, the number of disclosed ransomware attacks skyrocketed – by 245%.

“Our team sifted through several different resources—specialist IT news, data breach reports, and state reporting tools—to collate as much data as possible on ransomware attacks on US businesses. We then applied data from studies on the cost of downtime to estimate a range for the likely cost of ransomware attacks to businesses,” Comparitech said explaining its approach. However, it did concede that the figures may be merely a scratch on the surface of the ransomware problem.

On average, the affected companies lost nine days in downtime and it took them about two-and-a-half months to investigate the attacks and their impact on the company’s data and its systems. To put into context, Comparitech estimates that, when combined, ransomware attacks caused 340.5 days of downtime and a whopping 4,414 days of investigation. However, the downtimes varied, ranging from recovery efforts taking several months to minimal disruptions especially thanks to solid backup plans.

Cybercriminals usually requested ransoms ranging from half a million dollars all the way up to US$21 million. Some attackers also upped the ante by carrying out double-extortion attacks, where they pilfer data from the victims’ systems before going on to encrypt them with ransomware … which would lead to embarrassment and stock devaluation at best, and to huge regulation penalties at worst. With researchers estimating that the average cost per minute of downtime is US$8,662 and adding in the reputational damage, it’s no wonder some companies are willing to pay the ransoms as a way to fix the problem quickly. Based on the estimate, the cost of downtime to American business was US$20.9 billion. The analysis also found that the ransomware attacks resulted in over 7 million individual records being pilfered or/and abused, an almost 800% increase compared to the previous years.

RELATED READING: 5 essential things to do before ransomware strikes

Additionally, the researchers noted a shift in the targets of ransomware attacks. While previously cybercriminals would target educational institutions and government entities, during 2020 they shifted their focus towards businesses and healthcare organizations. This could be chalked up to the pandemic since many schools and governmental organizations were closed and their systems were down. Meanwhile, healthcare providers had to power through in order to tend to patients, and the pandemic forced a lot of businesses to transition to remote work probably making them easier targets to hack.

What about 2021?

Based on the trends and events of this year, it is little wonder that Comparitech estimates the costs to businesses will rise further. “If the second half of 2021 sees the same number of attacks as the first half (91), 2021’s figures will be in line with 2020s–over 180 individual ransomware attacks. However, with many attacks often revealed weeks or months after they’ve happened, these figures are likely to rise even higher over the coming months, suggesting 2021 will be a record-breaking year for ransomware attacks on US businesses,” the company warned.

To find out why ransomware remains one of the top threats and how businesses can defend against it, we suggest reading up on our recent white paper, Ransomware: A criminal art of malicious code, pressure and manipulation.