19.7.17

OneLogin: Businesses vulnerable to data breaches by ex-employees

Businesses leave themselves open to potential data breaches through their ex-employees by failing to disable their access to the corporate network, according to a new study by OneLogin.
Over half (58%) of ex-employees are still able to access all corporate applications after leaving the business.
Furthermore, this is a proven risk, with 24% of businesses being subject to data breaches carried out by former employees.
The UK-based report, based on responses from more than 600 IT decision-makers, revealed that half these respondents were not using automated deprovisioning technology to disable employees’ access.
The fact that the majority (92%) of businesses attempt to manually sever access may explain why a month after leaving the business, 28% of employees are still able to log onto corporate applications.
Alvaro Hoyos, chief information security officer at OneLogin, said: “Our study suggests that many businesses are burying their heads in the sand when it comes to this basic, but significant, threat to valuable data, revenue and brand image.”
This study follows OneLogin’s recent acknowledgement that it is unable to guarantee the security of encrypted data compromised by a cybercriminal, with regard to the security incident on May 31.
The report stated: “We know that a threat actor used one of our AWS keys to gain access to our AWS platform”, and made reference to an “ongoing investigation” with “an independent security firm to determine how the unauthorized access happened”.
Hoyos suggested that the upcoming General Data Protection Regulation (GDPR) might put the necessary pressure on businesses, stating: “With [GDPR] in mind, businesses should proactively seek to close any open doors that could provide rogue ex-employees with opportunities to access and exploit corporate data.
“The first step is acknowledging the problem, which businesses now have done by confessing they are aware of the issue. They now need to take steps to fix this issue by utilising the available tools”.


A major cyberattack could cost the global economy $53 billion


By Editor

Lloyd’s of London has reported that a serious cyberattack could cost the global economy as much as a devastating natural disaster.
According to the Guardian, average losses from a crippling cyberattack are estimated to be around $53 billion.
However, insurers are unable to give a specific estimate, due to the complexity of cyberattacks and the lack of historical data available. A worst case scenario could see the figure reaching up to $121 billion.
The report looked at the potential damage that could be triggered by an attack on a cloud service provider, which is believed to be the most likely target for an attack.
The paper judged the second-most likely threat to be to worldwide computer operating systems.
Lloyd’s published the report two months after WannaCryptor went global, at an estimated global cost of $8 billion.
The industry found to be most at risk is the financial sector, followed by software and technology and then hospitality.
Inga Beale, chief executive of Lloyd’s, said: “Because cyber is virtual, it is such a difficult task to understand how it will accumulate in a big event.”
She added: “Cyber events can cause a severe impact on businesses and economies, trigger multiple claims and dramatically increase insurers’ claims costs.”
Cybersecurity experts at ESET have recently identified Industroyer as a major threat, especially to Industrial Control Systems.
It is hoped that analysis of such threats will serve as a wakeup call for all those responsible for the security of critical infrastructure (systems) worldwide.
Such repeated warnings should not be falling on deaf ears.
Many governments and businesses run a huge financial risk by not being insured; but more crucially, risk falling victim to an attack by failing to ensure that employees and consumers heed expert advice.


12.7.17

Industrial control security practitioners worry about threats … for a reason


Last month, ESET researchers confirmed the discovery of a new type of sophisticated malware now known as Industroyer, highlighting the threat posed to industrial control systems. Indeed, this is considered to be the first-ever designed to affect ICS industrial control systems directly, and is thought to be behind the December 2016 cyberattack on Ukraine’s power grid.
Further research from the SANS Institute, the “global leader in information security training and certification”, confirms that security of industrial control systems is increasingly seen and understood to be a serious issue.
Their recent paper, Securing Industrial Control Systems—2017, is based on polling hundreds of professionals in the field of ICS security. Its goal is to gather related information and map the attitudes of industrial control security practitioners in regard to the security of their systems, threats and attack vectors, and defense measures.
The research shows that, predictably, the respondents’ highest priority is keeping their operational technology running. Answering the question “What are your primary business concerns when it comes to the security of your control systems?”, nearly a quarter put “Ensuring reliability and availability of control systems” first; among the top three priorities is this one for over 50% of respondents.
To measure the real scope of ICS security, the question “Have your control systems been infected or infiltrated in the past 12 months?” was included in the survey. The most common response, “Not that we know of,” was selected by 40%, while less than a half of respondents, 19%, chose “No, we’re sure we haven’t been infiltrated”.
“The SANS survey shows that ICS security experts seriously worry about security.”
As for the overall security, the respondents answered the same key question as in the previous years: “How serious does your organization consider the current threats to control system cybersecurity to be?” 69% of respondents rated the perceived level of threat as severe/critical or high – a two percentage point increase compared to last year’s survey.
The biggest three threats cited by the respondents were one, devices and “things” (that cannot protect themselves) added to networks; two, internal threats (accidental); and three, external threats (hacktivism, nation states). Extortion, ransomware and other financially motivated crimes came in fourth place, while external threats, via a supply chain or partnerships was far behind at number eight (out of 10 options offered to the respondents).
As for the defense measures that the respondents currently have in use, anti-malware technologies emerged as the most relied-upon measure, followed by access control solutions. The top three wanted technologies or solutions were industrial intrusion detection, control system network security monitoring and security awareness training for staff, contractors and vendors.
For interpreting the survey’s results, it should be noted that the responses were collected in February-March of 2017 (as its editors told WeLiveSecurity). This means that the respondents’ attitudes were not influenced by the news about the discovery of Industroyer – arguably the most important recent news story that is related to ICS security, which appeared in the industry’s media in May.
“The SANS survey shows that ICS security experts seriously worry about security,” commented Robert Lipovský, Senior Malware Researcher at ESET. “It will be interesting to see if the discovery of Industroyer pushes these worries to an even higher level – future reports will show.”
Industroyer was first analyzed by ESET researchers who discovered its capability to disrupt industrial processes – in the case investigated, precisely targeting a particular energy transmission infrastructure.
As a highly configurable tool, Industroyer can be easily refitted to attack similar energy infrastructures and even re-purposed to attack industrial control systems in other industries such as transportation or manufacturing.
“It is a reminder to all those responsible for critical systems around the world, many of which were designed without security in mind. Now’s the time to take measures for securing them – and the SANS research shows that security experts are taking this issue seriously,” concludes Lipovský.


Adobe Flash Player users should update their software NOW

One of the favourite pieces of software for malicious hackers to target on users’ computers is Adobe Flash Player.
Why? Well, there are a few reasons.
Firstly, Adobe Flash Player is on an awful lot of computers. Many users may have it installed it long ago in order to access Flash-based media content online, such as videos. Malicious hackers can rely upon a large number of people having Flash installed, making it a target for attack.
Secondly, the version of Adobe Flash Player installed on your computer may be out-of-date. Users may have failed to configure updates properly, or chosen to ignore reminders to update the software promptly when a new security update is released. There’s only one thing more attractive to a malicious hacker than widely-used ubiquitous software, and that’s widely-used ubiquitous software that hasn’t been kept updated with the latest patches.
It doesn’t matter if a hacker doesn’t have zero-day exploit to throw at your Adobe Flash Player if you haven’t been bothering to keep it protected against known vulnerabilities.
Thirdly, there has been a long history of malicious hackers finding critical security holes in Adobe Flash Player, and building their attacks into exploit kits for anyone to deploy. Flash is closed, proprietary software controlled by Adobe and it has been plagued with software vulnerabilities and serious flaws over many years. Quite why Flash has been targeted so often is open to some debate, but the mere fact that it has suggests that it will continue to be for some time to come.
The upshot of this is that when Adobe releases new security patches for Adobe Flash Player, it would be very sensible indeed for its users to sit up and take notice.
Earlier today Adobe issued a security advisory detailing updates it has released for Adobe Flash Player for Windows, Macintosh, Linux and Chrome OS.
The updates are said to address critical vulnerabilities that could potentially allow an attacker to take control of a vulnerable system, allowing a remote attacker to execute code on a victim’s computer and take control over their device.
Adobe recommends that users of the Adobe Flash Player Desktop Runtime for Windows, Macintosh and Linux update to Adobe Flash Player version 26.0.0.137 as soon as possible. You can do this either by visiting the official Adobe Flash Player download page, or ensuring that Flash’s global settings are set to “install updates automatically when available”.
Continued on:

5.7.17

Tosoh Europe automatiseert screening van exportzendingen


Volledig compliant en uiterst efficiënte exportcontrole dankzij oplossing van AEB


Tosoh Europe, leverancier van chemicaliën, heeft software van AEB geïmplementeerd om de controle en screening van exportzendingen te automatiseren. Dankzij deze oplossing is het dochterbedrijf van het Japanse Tosoh Corporation altijd volledig compliant.

Tosoh Europe levert chemicaliën voor onder meer diagnostische systemen en materialen aan de halfgeleiderindustrie. De meeste producten worden gemaakt op productielocaties buiten de Europese Unie. Ze worden direct getransporteerd naar klanten of tijdelijk opgeslagen – al dan niet in een entrepot - in het Europees distributiecentrum in Nederland of in andere regionale warehouses in Europa, Midden-Oosten of Afrika. Daarvandaan worden de gevaarlijke goederen verpakt en verzonden naar behoefte van klanten. “We verkopen veel in de EU natuurlijk, maar hebben ook klanten in andere landen zoals Rusland en in het Midden-Oosten en Afrika”, vertelt Lars Droog, manager supply chain en general affairs bij Tosoh Europe.

Exportcontrole en Europese, Amerikaanse én Japanse sanctielijsten
Voor exportcontrole en screening tegen sanctielijsten heeft Tosoh Europe een IT-oplossing van AEB geselecteerd: ATC :: Compliance Screening and Export Controls. De reden is de strenge regelgeving waaraan Tosoh Europe gebonden is. Die gaat verder dan het screenen op Europese en Amerikaanse sanctielijsten met personen en entiteiten. Als Tosoh Europe levert aan klanten buiten de Europese Unie, moeten de zendingen ook gescreend worden tegen de meest recente product- en embargolijsten van de Europese Unie en de Verenigde Staten. Chemicaliën die al eerder vanuit de Verenigde Staten zijn geïmporteerd, vallen namelijk nog steeds onder de Amerikaanse exportwetgeving. En omdat het bedrijf een Japans moederbedrijf heeft, moeten alle zendingen ook tegen de Japanse sanctielijsten worden gescreend. “Volledige compliance is het doel”, benadrukt Droog.

Sanctielijsten altijd up to date
De reden voor aanschaf van ATC: Compliance Screening and Export Controls is de wens op de arbeidsintensieve exportcontrole te automatiseren en te integreren in het totale bedrijfsproces. Dat is waarom Droog heeft gezocht naar een oplossing met meer dan alleen een krachtig screening algoritme. “Wij wilden een gecentraliseerde oplossing waar de content ook onderdeel van is, zodat we altijd over de meest recente versies van de verschillende sanctielijsten beschikken. Daarnaast moest de oplossing kunnen worden geïntegreerd met het SAP® systeem dat we in 2013 in Europa hebben geïmplementeerd.”

De oplossing van AEB voorziet in die behoefte. Via de data service van AEB blijven de lijsten in ATC :: Compliance Screening and Export Controls altijd up to date. De oplossing werkt als een plugin in SAP en zorgt op deze wijze voor een eenvoudige integratie. Daardoor kunnen de medewerkers van Tosoh Europe in de SAP omgeving blijven werken, terwijl de AEB-oplossing op de achtergrond draait.

Geen concessies aan efficiëntie
De implementatie nam twee maanden in beslag. In die twee maanden is de oplossing uitgebreid getest en zijn alle medewerkers intensief getraind. “Onze ervaring tot nu toe is positief. Het was voor ons erg belangrijk om geen concessies te doen aan de efficiëntie”, vertelt Droog.
De oplossing van AEB maakt dat mogelijk. De workflow wordt alleen onderbroken als dat wettelijk gezien nodig is, bijvoorbeeld omdat een extra procedure of vergunning benodigd is. In dat geval ontvangen alle betrokken partijen automatisch een bericht per email. De order blijft geblokkeerd tot dat duidelijk is dat er verder geen restricties van toepassing zijn en de zending kan worden vrijgegeven door de Compliance Officers.

Volledig inzicht
Lars Droog kijkt met tevredenheid terug op het project. “Wij zijn niet alleen blij met de oplossing, maar ook met de ondersteuning van AEB tijdens en na het project. We hebben nu volledig inzicht in alle zendingen die gecontroleerd en gescreend moeten worden en archiveren automatisch alle gegevens.”

2.7.17

Workplace social media security: 5 questions answered



Since it’s Social Media Day today, there is likely to be an increased focus on the impact of social media and the way it is used by businesses across the world.
Social media use has skyrocketed for businesses all over the world, with many companies using it as a way of strengthening their brands and reaching out to new and existing customers.
It’s clear that social media is likely to continue its popularity with businesses although, in an age where information security has never been such a pressing issue, there are still questions that need to be addressed.
1. Is social media really a threat to security?
The threat posed to security by social media is nothing new. A report released by Cisco in 2013 claimed mass audience sites, which include social media, pose a significant threat to information security.
One obvious threat is the potential for blurring the line separating personal information and company data, particularly when a user is using a social media account for both personal and work purposes.
This risk may be underestimated by workers, many of whom may believe their social media accounts are not carrying anything of interest for cybercriminals, but it can still be used as a portal into a company’s wider network.
2. So is social media a weak spot?
Potentially. The use of phishing to compromise email accounts has been well-documented, but they can take on a new dimension when combined with social media.
For example, if cybercriminals can compromise a LinkedIn account, they can potentially fool others on the network into thinking they are genuinely one of their coworkers, opening up the possibility of handing over sensitive information.
3. But if they don’t get that far, there’s nothing to worry about?
Not exactly. Social media output is a key component of a brand’s overall image. If a cybercriminal manages to compromise one of these channels it could prove damaging.
For instance, in 2013 a hacker was able to gain access to the Twitter account of Burger King and then used it to display the McDonald’s logo, along with explicit obscenities. Similarly, it’s not exactly reassuring when someone like Mark Zuckerberg has his social networks compromised.
4. What can be done to make things better?
Setting up a rigid social media policy to protect company accounts is always a good a start.
A code of conduct for employees, as part of a wider cybersecurity program, can include the implementation of strong passwords, with weak logins such as 123456 still all too common.
Other potential points include monitoring engagement with brand mentions, offering guidance on how to spot malicious software, implementing two-factor authentication, and ensuring that only brand-approved content is shared.
Implementing a policy is particularly important for businesses operating more than one social media account, although it is equally important not to discourage employee participation as this will hinder the benefits these platforms bring.
5. Is it the employer’s responsibility to safeguard social media security?
Employers should always try to educate their workforce on the potential dangers of social media as best they can, but employees themselves need to remain vigilant.
For example, it’s important to be cautious of links embedded in email messages, even if they appear to be from a social network provider.
Always ensure links come from trusted sources. If in doubt, connect to site’s URL directly by typing it into your browser.
Always keep a track of what devices have access to your accounts, and utilize any available service that will notify you when a new login occurs.
Furthermore, workers shouldn’t risk leaving themselves vulnerable by posting potentially sensitive information on social media.
For more on how to keep your organization safe from cybercrime, and boost cybersecurity knowledge among your employees, check out ESET’s free Cybersecurity Awareness Training.

29.6.17

ITvisors en InterSystems vereenvoudigen reserveringsproces van Eurail.com


ITvisors breidt zijn expertiseportfolio, bestaande uit technologie van SAP, Open Text/Documentum en Mendix uit met de Enterprise Service Bus (ESB) van InterSystems. Een van de eerste projecten waar ITvisors het ESB-platform Ensemble heeft ingezet, is bij Eurail.com, de organisatie die zich bezig houdt met de online verkoop van Europese treinpassen.
Eurail.com, een gezamenlijk verkoopkanaal van diverse Europese treinmaatschappijen, richt zich op mensen die per trein door geheel Europa willen reizen zonder voor elk traject een afzonderlijk kaartje te moeten kopen. Met de Eurail- of Interrail pas kunnen zij zich binnen 30 Europese landen via het spoor laten vervoeren. De Eurail.com- organisatie in Utrecht richt zich tevens op het maken van treinreserveringen voor haar klanten bij de betrokken Europese spoorwegbedrijven. Dit reserveringsproces verliep tot 2014 via e-mailcorrespondentie met veel handmatige verwerkingsprocessen. Een door ITvisors ondersteund onderzoek naar de mogelijkheid om werkprocessen binnen Eurail.com te stroomlijnen, resulteerde in de bouw van een reserveringsportaal in tweeënhalve maand tijd. Daarmee werd de tijdsduur per boeking van gemiddeld een uur teruggebracht tot een kwartier. Om de reizigers nog beter van dienst te kunnen zijn en gelijktijdig de verwerkingsprocessen verder te optimaliseren, heeft Eurail.com aan ITvisors de opdracht gegeven koppelingen tot stand te brengen tussen het eigen IT-systeem met de IT-voorzieningen van de aangesloten spoorwegorganisaties.
Inmiddels is één koppelingsproject voltooid met Trenitalia, de exploitant van treinen in Italië. Een tweede koppeling met een andere spoorwegorganisatie is in de maak. De IT-architecten van ITvisors zijn gecharmeerd van de ’simpele’, maar degelijke InterSystems technologie, waarmee koppelingen tussen verschillende systemen zijn in te richten, inclusief de ’business rules’ functionaliteit voor het orkestreren van het berichtenverkeer. InterSystems is een ideale tool gebleken om de diversiteit van niet gestandaardiseerde treinreserveringssystemen binnen Europa te ontsluiten. Daarmee kan de technologie een centrale rol vervullen bij de door ITvisors begeleide digitale transformatietrajecten. Gestart als consultants met SAP-expertise heeft ITvisors zich ontwikkeld tot een bureau met deskundigheid in de methodiek van Lean Six Sigma. Daarmee laten bedrijfsactiviteiten zich helder vastleggen in eenduidige, efficiënte processen, waarmee bedrijven klantwaarde realiseren.
Eurail.com heeft, met ondersteuning van ITvisors, het ontwikkelplatform Mendix ingezet voor het reserveringsportaal. Dit platform voorziet in het snel ontwikkelen van innovatieve (mobiele) toepassingen. De bus-architectuur van Intersystems Ensemble zorgt nu voor online integratie met de treinreserveringssystemen van de lokale Europese Treinvervoerders. Dit levert veilige en betrouwbare datastromen op tussen deze systemen en de klanteninteractie self-service portalen.
Over Eurail
Eurail is gespecialiseerd in de online verkoop van Eurail en Interrail passen. Eurail.com is gevestigd in Nederland, met fulfilment centra opererend vanuit de Verenigde Staten, Ierland en Singapore. Eurail helpt sinds 2006 reizigers van over de hele wereld aan een onvergetelijke treinreis. Meer informatie via www.eurail.com  en www.interrail.eu.
Over ITvisors
ITvisors wil een betrouwbare en innovatieve partner voor haar klanten zijn door het brengen van hoogwaardige kennis op het gebied van kritische bedrijfsapplicaties (build2last) en innovatieve IT technologie (designed2change). ITvisors is een specialist in beide omgevingen en is in staat om deze werelden samen te laten werken vanwege haar unieke positionering. Middels een complete aanpak vertaalt ITvisors business processen van haar klanten naar innovatieve en doelmatige IT oplossingen. Dit doen zij met een zeer ervaren team van professionals, gespecialiseerd in SAP, Mendix, OpenText en Intersystems. Innovatie komt vaak voort uit procesoptimalisatie. De consultants van ITvisors zijn daarom ook getrainde Lean Six Sigma experts. Door hun jarenlange ervaring, zijn zij deskundig in het optimaliseren van bedrijfsprocessen. ITvisors helpt haar klanten de reis van digitale transformatie succesvol te maken en is daarom aangemerkt als strategisch partner van Intersystems.