FireSale HackBoy

Knowledge Shared By FireSale HackBoy...

Hacking

The Art Of Exploitation...

Ethical Hacking

Security Experts...Same Techniques To Make Hacker's Stuff Useless.

Black Hat Hacking

Dark Side Of Hacking... In Short Destruction Of Cyber Stuff.

Digital Stuff

All The Digital Stuff Is Under The Influence Of Cyber Attacks... Be Safe

Wednesday, May 3, 2023

Looking at a penetration test through the eyes of a target

The content of this post is solely the responsibility of the author.  AT&T does not adopt or endorse any of the views, positions, or information provided by the author in this article. 

Analyzing an organization’s security posture through the prism of a potential intruder’s tactics, techniques, and procedures (TTPs) provides actionable insights into the exploitable attack surface. This visibility is key to stepping up the defenses of the entire digital ecosystem or its layers so that the chance of a data breach is reduced to a minimum. Penetration testing (pentesting) is one of the fundamental mechanisms in this area.

The need to probe the architecture of a network for weak links through offensive methods co-occurred with the emergence of the “perimeter security” philosophy. Whereas pentesting has largely bridged the gap, the effectiveness of this approach is often hampered by a crude understanding of its goals and the working principles of ethical hackers, which skews companies’ expectations and leads to frustration down the line.

The following considerations will give you the big picture in terms of prerequisites for mounting a simulated cyber incursion that yields positive security dividends rather than being a waste of time and resources.

Eliminating confusion with the terminology

Some corporate security teams may find it hard to distinguish a penetration test from related approaches such as red teaming, vulnerability testing, bug bounty programs, as well as emerging breach and attack simulation (BAS) services. They do overlap in quite a few ways, but each has its unique hallmarks.

Essentially, a pentest is a manual process that boils down to mimicking an attacker’s actions. Its purpose is to find the shortest and most effective way into a target network through the perimeter and different tiers of the internal infrastructure. The outcome is a snapshot of the system’s protections at a specific point in time.

In contrast to this, red teaming focuses on exploiting a segment of a network or an information / operational technology (IT/OT) system over an extended period. It is performed more covertly, which is exactly how things go during real-world compromises. This method is an extremely important prerequisite for maintaining OT cybersecurity, an emerging area geared toward safeguarding industrial control systems (ICS) at the core of critical infrastructure entities.

Vulnerability testing, in turn, aims to pinpoint flaws in software and helps understand how to address them. Bug bounty programs are usually limited to mobile or web applications and may or may not match a real intruder’s behavior model. In addition, the objective of a bug bounty hunter is to find a vulnerability and submit a report as quickly as possible to get a reward rather than investigating the problem in depth.

BAS is the newest technique on the list. It follows a “scan, exploit, and repeat” logic and pushes a deeper automation agenda, relying on tools that execute the testing with little to no human involvement. These projects are continuous by nature and generate results dynamically as changes occur across the network.

By and large, there are two things that set pentesting aside from adjacent security activities. Firstly, it is done by humans and hinges on manual offensive tactics, for the most part. Secondly, it always presupposes a comprehensive assessment of the discovered security imperfections and prioritization of the fixes based on how critical the vulnerable infrastructure components are.

Choosing a penetration testing team worth its salt

Let’s zoom into what factors to consider when approaching companies in this area, how to find professionals amid eye-catching marketing claims, and what pitfalls this process may entail. As a rule, the following criteria are the name of the game:

  • Background and expertise. The portfolio of completed projects speaks volumes about ethical hackers’ qualifications. Pay attention to customer feedback and whether the team has a track record of running pentests for similar-sized companies that represent the same industry as yours.
  • Established procedures. Learn how your data will be transmitted, stored, and for how long it will be retained. Also, find out how detailed the pentest report is and whether it covers a sufficient scope of vulnerability information along with severity scores and remediation steps for you to draw the right conclusions. A sample report can give you a better idea of how comprehensive the feedback and takeaways are going to be.
  • Toolkit. Make sure the team leverages a broad spectrum of cross-platform penetration testing software that spans network protocol analyzers, password-cracking solutions, vulnerability scanners, and for forensic analysis. A few examples are Wireshark, Burp Suite, John the Ripper, and Metasploit.
  • Awards and certifications. Some of the industry certifications recognized across the board include Certified Ethical Hacker (CEH), Certified Mobile and Web Application Penetration Tester (CMWAPT), GIAC Certified Penetration Tester (GPEN), and Offensive Security Certified Professional (OSCP).

The caveat is that some of these factors are difficult to formalize. Reputation isn’t an exact science, nor is expertise based on past projects. Certifications alone don’t mean a lot without the context of a skill set honed in real-life security audits. Furthermore, it’s challenging to gauge someone’s proficiency in using popular pentesting tools. When combined, though, the above criteria can point you in the right direction with the choice.

The “in-house vs third-party” dilemma

Can an organization conduct penetration tests on its own or rely solely on the services of a third-party organization? The key problem with pentests performed by a company’s security crew is that their view of the supervised infrastructure might be blurred. This is a side effect of being engaged in the same routine tasks for a long time. The cybersecurity talent gap is another stumbling block as some organizations simply lack qualified specialists capable of doing penetration tests efficiently.

To get around these obstacles, it is recommended to involve external pentesters periodically. In addition to ensuring an unbiased assessment and leaving no room for conflict of interest, third-party professionals are often better equipped for penetration testing because that’s their main focus. Employees can play a role in this process by collaborating with the contractors, which will extend their security horizons and polish their skills going forward.

Penetration testing: how long and how often?

The duration of a pentest usually ranges from three weeks to a month, depending on the objectives and size of the target network. Even if the attack surface is relatively small, it may be necessary to spend extra time on a thorough analysis of potential entry points.

Oddly enough, the process of preparing a contract between a customer and a security services provider can be more time-consuming than the pentest itself. In practice, various approvals can last from two to four months. The larger the client company, the more bureaucratic hurdles need to be tackled. When working with startups, the project approval stage tends to be much shorter.

Ideally, penetration tests should be conducted whenever the target application undergoes updates or a significant change is introduced to the IT environment. When it comes to a broad assessment of a company’s security posture, continuous pentesting is redundant – it typically suffices to perform such analysis two or three times a year.

Pentest report, a goldmine of data for timely decisions

The takeaways from a penetration test should include not only the list of vulnerabilities and misconfigurations found in the system but also recommendations on the ways to fix them. Contrary to some companies’ expectations, these tend to be fairly general tips since a detailed roadmap for resolving all the problems requires a deeper dive into the customer’s business model and internal procedures, which is rarely the case.

The executive summary outlines the scope of testing, discovered risks, and potential business impact. Because this part is primarily geared toward management and stakeholders, it has to be easy for non-technical folks to comprehend. This is a foundation for making informed strategic decisions quickly enough to close security gaps before attackers get a chance to exploit them.

The description of each vulnerability unearthed during the exercise must be coupled with an evaluation of its likelihood and potential impact according to a severity scoring system such as CVSS. Most importantly, a quality report has to provide a clear-cut answer to the question “What to do?”, not just “What’s not right?”. This translates to remediation advice where multiple hands-on options are suggested to handle a specific security flaw. Unlike the executive summary, this part is intended for IT people within the organization, so it gets into a good deal of technical detail.

The bottom line

Ethical hackers follow the path of a potential intruder – from the perimeter entry point to specific assets within the digital infrastructure. Not only does this strategy unveil security gaps, but it also shines a light on the ways to resolve them.

Unfortunately, few organizations take this route to assess their security postures proactively. Most do it for the sake of a checklist, often to comply with regulatory requirements. Some don’t bother until a real-world breach happens. This mindset needs to change.

Of course, there are alternative methods to keep abreast of a network’s security condition. Security Information and Events Management (SIEM), Security Orchestration, Automation, and Response (SOAR), and vulnerability scanners are a few examples. The industry is also increasingly embracing AI and machine learning models to enhance the accuracy of threat detection and analysis.

Still, penetration testing maintains a status quo in the cybersecurity ecosystem. That’s because no automatic tool can think like an attacker, and human touch makes any protection vector more meaningful to corporate decision makers.

The post Looking at a penetration test through the eyes of a target appeared first on Cybersecurity Insiders.


May 03, 2023 at 09:11PM

Insider Risk: Unconventional Thoughts and Lessons Learned

By: Daron Hartvigsen, Managing Director, StoneTurn and Luke Tenery, Partner, StoneTurn

When insider threat or insider risk is discussed in a corporate context, often the relevant topics include misconduct, fraud, misuse, or even the idea that insiders can be unwitting accomplices to social engineering exploitation. The recent slowing of the US economy and volatility in the digital asset market have surfaced some less talked about aspects of insider risk that companies should consider.

Security: Often a Single Point of Failure

Whether it’s cryptocurrency, social media, or software engineering, it commonly occurs in startups and new innovations that a very small cadre of individuals propel the entire endeavor forward. Unfortunately, it often happens that these early leaders retain critical information about the project (design, developments, infrastructure, technology) in one location: their own brains. If this information is not properly documented and accessible, it can prove catastrophic if a key individual departs or is unavailable when something fails. Cue the chaos that can ensue.

As an example, StoneTurn has worked with very successful companies who operate IT systems supporting the storage, exchange, and/or trading of digital assets. Unfortunately, we often find these companies rely on infrastructure built by early innovators who fielded systems without the knowledge, funding, or motivation to build a more secure and redundant platform. When the Crypto “winter” hit in late 2022 and prices plunged, it was not surprising to see allegations of unauthorized and untraceable theft of digital assets from companies who laid off some of the very employees responsible for the IT systems that experienced the theft.

In some cases, the employees understood critical logging gaps or had oversight of the security measures intended to thwart unauthorized internal activity, and thus were able to exploit them. Initial build strategies for some players in the digital asset ecosystem focused solely on investing in protections from unauthorized external access, client fraud, or defenses from other external threats. Investment in internal access control, auditing, and logging are often seen as secondary risks. As a result, policies and protocols insufficient to prevent or detect insider risk are implemented and only become a priority when there is a loss or impactful security event.

Intellectual Property/Institutional Knowledge: Can Disappear Overnight

Companies that build a new product from the ground-up and rely on infrastructure built by a small team of innovators often do not plan for the eventual departure of that talent.

We have worked on more than one case where an entity worth more than $100 million USD relied on ONE person’s institutional knowledge to keep things going. When that situation goes bad, investigators like StoneTurn are called to understand what happened. What are the impacts to the core production environment when the person who built it and maintains it is laid off or quits? The short answer: it could be significant if redundancy in knowledge was not planned for. But it can go much deeper.

During the latter stages of 2022 we worked with clients who did lay off staff and downsize teams, and as a result created environments where the company’s ability to support key technologies just disappeared, essentially overnight. As headlines have indicated, this trend has carried over into 2023, with entities large and small across sectors continuing to make cuts in staffing. While a large company may be able to fill in the gaps, for a smaller digital asset exchange, the departure of foundational technical staff could cause a much more significant disruption.  Getting ahead of these disruptions is critical and companies can do many things to defend themselves from disappearing institutional knowledge. Those defenses need to be implemented early and built into engineering, security, and growth plans.

Bottom Line: Plan to Protect

Building a business off a great idea, maturing that idea into a product, and serving the market successfully are key goals many innovators reach for and something that is celebrated in the business ecosystem. Today, however, building a successful technology-enabled business must include a much broader set of goals to avoid common pitfalls.

  • Plan to protect intellectual property and institutional knowledge from the beginning.
  • While building out IT infrastructure, it is wise to secure what is valuable from day one and to do so with an eye to both external and internal risk.
  • Test controls and protocols frequently to ensure they are not circumvented, whether maliciously or for sake of perceived “efficiency.”

For today’s leaders, the end goal must change: Build a secure business off a great idea and plan to secure the IP associated with that idea right away. Mature the idea into a secure product with redundancies that defend against a single point of failure. By doing so, organizations can better serve the market successfully by securing fundamental business and client information in the long-term.

###

About Daron Hartvigsen

Daron Hartvigsen, Managing Director with StoneTurn, is a cyber threat response and pursuit expert having served both commercial and U.S. government information security domains. He brings a combined nearly 30 years of experience in commercial, U.S. intelligence, counter-intelligence, and law enforcement, and has conducted incident response, cyber threat pursuit, law enforcement investigations, counterintelligence operations, intelligence analysis, and cyber threat degradation activities.

About Luke Tenery

Luke Tenery brings over 20 years of experience helping leading organizations mitigate complex cybersecurity, data privacy, and digital risks. He applies expertise in cyber investigations, threat intelligence, incident response, and information risk management to assist clients—from prevention to detection, mitigation through to remediation and transformation.

Luke specializes in situational cyber risks, including assisting public companies and their Boards in addressing digital risks and remediation of complex cyber incidents. Luke has also advised on cyber issues at the intersection of risk and compliance, as well as those related to financial fraud and data integrity.

The post Insider Risk: Unconventional Thoughts and Lessons Learned appeared first on Cybersecurity Insiders.


May 03, 2023 at 05:52PM

FBI seizes 9 cryptocurrency exchange websites supporting cyber criminals and ransomware spread

FBI officials have released an official statement that they have seized the servers operating in United States, Ukraine and France linked to about 9 cryptocurrency exchange websites that supported cyber criminals in their actions by indulging in money laundering and exchange of fiat currency in crypto.

The list of seized websites includes-

1.     24xbtc.com

2.     100btc.pro

3.     Pridechange.com

4.     101crypta.com

5.     Uxbtc.com

6.     Trust-exchange.org

7.     Bitcoin24.exchange

8.     Paybtc.pro

9.     Owl.gold

Sources reporting to our cybersecurity insiders state that the operation was carried out by the Federal Bureau of Investigation (FBI) with the help of its Virtual Currency Response Team, le-gal prosecutors of European nations and America and the National Police of Ukraine. And the legal action was taken in accordance with a seizure warrant 18 U.S.C 1960 and 18 U.S.C 1956 issued by the US District Court of Michigan.

The law enforcement discovered in its criminal investigation and after analysis that these web-sites were helping criminals convert the BTC into hard to track digital currencies sources and leading to wallets based in Singapore, Malaysia, and Thailand. Where these currencies are of-ten invested in betting games like Poker and converted to local currencies that are later diverted to bank accounts of internationally recognized banks.

As these nations do not curtail earnings from criminal activities, funds transferred from such nations to bank accounts of international banks are often shown a blind eye by law enforce-ments across the world. Some banks having branches in these nations do not comply with any of the central banking units and do not collect customer details, that is mandatory for financial institutions operating in many of the developed and developing nations.

Some crime analysts suggest the ban of cryptocurrency to curb cyber-crime such as ransom-ware spread. But in practical it might not be possible as the dark web is filled with many such digi currencies that are hard to track and have very less life span over digital existence.

The post FBI seizes 9 cryptocurrency exchange websites supporting cyber criminals and ransomware spread appeared first on Cybersecurity Insiders.


May 03, 2023 at 10:21AM

Tuesday, May 2, 2023

Securing the Edge Ecosystem Global Research released – Complimentary report available

AT&T Cybersecurity is committed to providing thought leadership to help you strategically plan for an evolving cybersecurity landscape. Our 2023 AT&T Cybersecurity Insights™ Report: Edge Ecosystem is now available. It describes the common characteristics of an edge computing environment, the top use cases and security trends, and key recommendations for strategic planning.

Get your free copy now.

This is the 12th edition of our vendor-neutral and forward-looking report. During the last four years, the annual AT&T Cybersecurity Insights Report has focused on edge migration. Past reports have documented how we

This year’s report reveals how the edge ecosystem is maturing along with our guidance on adapting and managing this new era of computing.

Watch the webcast to hear more about our findings.

The robust quantitative field survey reached 1,418 professionals in security, IT, application development, and line of business from around the world. The qualitative research tapped subject matter experts across the cybersecurity industry.

At the onset of our research, we set out to find the following:

  1. Momentum of edge computing in the market.
  2. Collaboration approaches to connecting and securing the edge ecosystem.
  3. Perceived risk and benefit of the common use cases in each industry surveyed.

The results focus on common edge use cases in seven vertical industries – healthcare, retail, finance, manufacturing, energy and utilities, transportation, and U.S. SLED and delivers actionable advice for securing and connecting an edge ecosystem – including external trusted advisors. Finally, it examines cybersecurity and the broader edge ecosystem of networking, service providers, and top use cases.

As with any piece of primary research, we found some surprising and some not-so-surprising answers to these three broad questions.

Edge computing has expanded, creating a new ecosystem

Because our survey focused on leaders who are using edge to solve business problems, the research revealed a set of common characteristics that respondents agreed define edge computing.

  • A distributed model of management, intelligence, and networks.
  • Applications, workloads, and hosting closer to users and digital assets that are generating or consuming the data, which can be on-premises and/or in the cloud.
  • Software-defined (which can mean the dominant use of private, public, or hybrid cloud environments; however, this does not rule out on-premises environments).

Understanding these common characteristics are essential as we move to an even further democratized version of computing with an abundance of connected IoT devices that will process and deliver data with velocity, volume, and variety, unlike anything we’ve previously seen.

Business is embracing the value of edge deployments

The primary use case of industries we surveyed evolved from the previous year. This shows that businesses are seeing positive outcomes and continue to invest in new models enabled by edge computing.

Industry

2022 Primary Use Case

2023 Primary Use Case

Healthcare

Consumer Virtual Care

Tele-emergency Medical Services

Manufacturing

Video-based Quality Inspection

Smart Warehousing

Retail

Lost Prevention

Real-time Inventory Management

Energy and Utilities

Remote Control Operations

Intelligent Grid Management

Finance

Concierge Services

Real-time Fraud Protection

Transportation

n/a

Fleet Tracking

U.S. SLED

Public Safety and Enforcement

Building Management

 

A full 57% of survey respondents are in proof of concept, partial, or full implementation phases with their edge computing use cases.

One of the most pleasantly surprising findings is how organizations are investing in security for edge. We asked survey participants how they were allocating their budgets for the primary edge use cases across four areas – strategy and planning, network, security, and applications.

The results show that security is clearly an integral part of edge computing. This balanced investment strategy shows that the much-needed security for ephemeral edge applications is part of the broader plan.

Edge project budgets are notably nearly balanced across four key areas:

  • Network – 30%
  • Overall strategy and planning – 23%
  • Security – 22%
  • Applications – 22%

A robust partner ecosystem supports edge complexity

Across all industries, external trusted advisors are being called upon as critical extensions of the team. During the edge project planning phase, 64% are using an external partner. During the production phase, that same number increases to 71%. These findings demonstrate that organizations are seeking help because the complexity of edge demands more than a do-it-yourself approach.

A surprise finding comes in the form of the changing attack surface and changing attack sophistication. Our data shows that DDoS (Distributed Denial of Service) attacks are now the top concern (when examining the data in the aggregate vs. by industry). Surprisingly, ransomware dropped to eighth place out of eight in attack type.

The qualitative analysis points to an abundance of organizational spending on ransomware prevention over the past 24 months and enthusiasm for ransomware containment. However, ransomware criminals and their attacks are relentless. Additional qualitative analysis suggests cyber adversaries may be cycling different types of attacks. This is a worthwhile issue to discuss in your organization. What types of attacks concern your team the most?

Building resilience is critical for successful edge integration

Resilience is about adapting quickly to a changing situation. Together, resilience and security address risk, support business needs, and drive operational efficiency at each stage of the journey. As use cases evolve, resilience gains importance, and the competitive advantage that edge applications provide can be fine-tuned. Future evolution will involve more IoT devices, faster connectivity and networks, and holistic security tailored to hybrid environments.

Our research finds that organizations are fortifying and future-proofing their edge architectures and adding cyber resilience as a core pillar. Empirically, our research shows that as the number of edge use cases in production grows, there is a strong need and desire to increase protection for endpoints and data. For example, the use of endpoint detection and response grows by 12% as use cases go from ideation to full implementation.

Maturity in understanding edge use cases and what it takes to protect actively is a journey that every organization will undertake.

Key takeaways

You may not realize you’ve already encountered edge computing – whether it is through a tele-medicine experience, finding available parking places in a public structure, or working in a smart building. Edge is bringing us to a digital-first world, rich with new and exciting possibilities.

By embracing edge computing, you’ll help your organization gain important, and often competitive business advantages. This report is designed to help you start and further the conversation. Use it to develop a strategic plan that includes these key development areas.

  • Start developing your edge computing profile. Work with internal line-of-business teams to understand use cases. Include key business partners and vendors to identify initiatives that impact security.
  • Develop an investment strategy. Bundle security investments with use case development. Evaluate investment allocation. The increased business opportunity of edge use cases should include a security budget.
  • Align resources with emerging security priorities. Use collaboration to expand expertise and lower resource costs. Consider creating edge computing use case experts who help the security team stay on top of emerging use cases.
  • Prepare for ongoing, dynamic response. Edge use cases rapidly evolve once they show value. Use cases require high-speed, low-latency networks as network functions and cybersecurity controls converge.

A special thanks to our contributors for their continued guidance on this report

A report of this scope and magnitude comes together through a collaborative effort of leaders in the cybersecurity market.

Thank you to our 2023 AT&T Cybersecurity Insights Report contributors!

To help start or advance the conversation about edge computing in your organization, use the infographic below as a guide.

Cybersecurity Infographic Insights Report

The post Securing the Edge Ecosystem Global Research released – Complimentary report available appeared first on Cybersecurity Insiders.


May 03, 2023 at 09:09AM

The Evolution of Data Security Solutions

By Dan Benjamin, Co-Founder and CEO, Dig Security

Approximately 60% of corporate data now lives in the cloud, a number that has doubled over the last seven years. While the concept of cloud computing dates back decades, it is only in the past few years that organizations have begun to understand its full potential.

Cloud computing has enabled a new generation of products and services, facilitated a lightweight form of outsourced solutions, and improved the efficiency and cost of technology tools, among many other benefits. It has also brought additional security challenges.

In the days of exclusively on-prem computing, businesses could build a strong perimeter defense and know their data was contained. With data continually flowing between on-prem solutions, public clouds, and private clouds, organizations must rethink security – from how they use, house, and share data to the security vendors they work with.

Critical Need for New Solutions

The rapidly changing cloud landscape requires agile data security solutions built with this structure in mind. Traditional solutions and vendors were simply not built to handle the complexity of the cloud – they are either agent based, or network based. Moreover, cloud-native solutions only provide solutions for specific data types and particular clouds, significantly limiting their scope.

According to research, 89% of companies have multi-cloud environments. This underscores the importance of security leaders adopting multi-cloud solutions, as a single cloud solution creates additional siloes.

IT and security leaders must understand how their environment works in concert and know how data should – and perhaps more importantly – how data should not move between sources. For example, data sovereignty rules mandate that data remains within the geography in which it was collected.

While Cloud Security Posture Management (CSPM) solutions take a multi-cloud security approach, they lack the context of the data itself. Insight into the context of data is imperative. For example, is that data sensitive? Are the right controls set when it comes to sensitive data? Is the user allowed to access sensitive data? Is the action allowed in the case of sensitive data?

Technology like Data Security Posture Management (DSPM) is a great start to assess static risks and security posture taking a data centered approach, but it lacks real-time monitoring, detection, and response. Combining both static risk and real time detection and response is what security professionals today need to focus on. They require a single pane of glass covering the entire cloud and data store.

DSPM with real time data detection and response (DDR) offers visibility and classification, which is foundational to understanding the data an organization has and making informed decisions about how it flows across the different clouds. It’s key to leverage technologies that move at the speed of the cloud, enhancing security while reducing the operational burdens that IT and security teams face.

Both DSPM and DDR capabilities are critically important to meet today’s organizations’ needs around multi-cloud data security.

Protecting Data with DDR

DDR works on the data level, allowing organizations to create policies detecting and responding to data misuse and data exfiltration. When a bad actor, an inside threat, or even a well-meaning employee takes action that puts data at risk of exfiltrating the organization, DDR issues alerts to enforce a response to keep the data within proper areas across the company clouds.

A well-built DDR solution leverages extensive threat model of all data assets and can issue alerts based on a database of hundreds of real-life attacks.

An attack on data can be mapped to the different steps in a data kill chain, meaning the actor moves from reconnaissance to first move, and then to attack. Following are examples of such attacks on data:

  • Reconnaissance – attacker scoping out its target running large queries on data to find vulnerability
  • First Move – attacker disabling a specific configuration or other action that allows them to exfiltrate, delete, or manipulate data in production
  • Attack – database deleted, database shared outside of the organization, data stolen, etc.
  • Compliance – customer data flow without masking from production to development
  • Asset at Risk – e.g., sudden increase in attack surface such as severe misconfigurations

Evolving Solutions for New Challenges 

Modern problems call for modern solutions. Technology infrastructures continue to evolve, and security solutions must grow with them. Too many organizations try to patch together disparate solutions that protect each component individually, which is costly, inefficient, and, most importantly, ineffective.

Businesses must approach data security with a data focused approach. They need to protect data no matter where it goes or lives. Data remains an organization’s most important asset and must be protected as such.

As an organization grows, business and IT leaders must consider how security should evolve alongside it. The cloud improves how people work, connect, and operate companies – businesses need security solutions that go beyond previous iterations and meet today’s needs.

The post The Evolution of Data Security Solutions appeared first on Cybersecurity Insiders.


May 03, 2023 at 07:00AM

The CPRA compliance checklist every business should follow in 2023

The content of this post is solely the responsibility of the author.  AT&T does not adopt or endorse any of the views, positions, or information provided by the author in this article. 

The California Privacy Rights Act (CPRA) was passed in November 2020. It amends the 2018 California Consumer Privacy Act (CCPA) introduced in response to rising consumer data privacy concerns. It has significantly impacted data collection and handling practices, giving consumers more control over how businesses handle their data.

Companies were given until January 1st, 2023, to achieve compliance. This article will discuss the key requirements of the CPRA and provide practical tips for companies to implement the necessary changes to ensure compliance.

What is the California Privacy Rights Act (CPRA)?

The CPRA is California’s most technical privacy law to date. It resembles the EU’s older and more popular General Data Protection Regulation (GDPR). The main difference is that the GDPR framework focuses on legal bases for data processing. On the other hand, the CPRA relies on opt-out consent.

The CPRA builds on the six original consumer rights introduced by the CCPA in 2018. As a reminder, the CCPA rights are:

  • The right to know what personal information is being collected by a business
  • The right to delete that personal information
  • The right to opt in or opt out of the sale of personal information
  • The right of non-discrimination for using these rights
  • The right to initiate a private cause of action – limited to data breaches

CPRA created two additional rights:

  • The right to correct inaccurate personal information
  • The right to limit the use and disclosure of sensitive information

The CPRA also introduced the California Privacy Protection Agency (CPPA,) which is the privacy enforcement agency for the new regulations.

How does CPRA impact business operations?

Data collection is a nearly universal activity for companies in the 21st century. Significant changes to data collection and handling practices can cause slight disruptions in operations. For example, the new regulations force businesses to re-evaluate their service provider and contractor relationships. Service providers and contractors, regardless of location, must abide by the same laws when dealing with businesses in California.

Since enforcement action is possible even when there has not been a breach, businesses must quickly understand their CPRA obligations and implement reasonable security procedures.

How much does non-compliance cost?

Non-compliance with CPRA regulations results in financial penalties, depending on the nature of the offenses.

  • The penalty for a mistake is $2,000 per offense
  • The penalty for a mistake resulting from negligence is $2,500 per offense
  • The penalty for knowingly disregarding regulations is $7,500 per offense

Since the penalties are on a “per offense” basis, costs of non-compliance can easily reach millions, particularly in the event of a data breach.

7 Step CPRA checklist for compliance

Process the minimal amount of personal information

The CPRA introduces the data minimization principle. Businesses should only obtain the personal information they need for processing purposes. If you collect any more data than data, it’s time to update your collection practices. The collected data must be stored securely. A reputable cloud storage solution is an excellent way to keep consumer data.

Update your privacy policy and notices

With the eight new rights introduced by the CCPA and CPRA, there must be changes to your privacy policy to abide by these regulations. Adequate policy notices for consumers should accompany the policy changes. You must provide the notices at the starting point of data collection. To re-purpose any already-collected data, you must first get consent.

Establish a data retention policy

To comply with the retention requirements of the CPRA, you must delete the personal data you no longer need. Establishing a data retention policy is a great first step towards compliance. The policy should include the categories of collected information, their purpose, and the time you plan to store it before deletion.

Review contracts with service providers

Service providers must abide by the same regulations. That’s why any third-party contracts must include adequate measures for handling data to ensure its protection and security. Service providers must notify you if they can no longer comply with your requirements.

Take actions to prevent a data breach

Compliance with regulations is only the first step in consumer data protection. You should also take steps to improve your cyber resilience and minimize the chances of a data breach. Ensure employees use modern tools such as password managers to protect their online accounts. Train employees to recognize common scams attackers use to gain access.

You should also consider regular risk assessments and cybersecurity audits to identify system vulnerabilities. Knowing your risks will help you make the necessary changes to protect your data.

Make it easy for customers to opt out or limit data sharing

The CPRA requires businesses to provide consumers with links where they can change how they wish their data to be handled. Consumers must be able to opt out of the sale or sharing of their data. Additionally, consumers have the right to limit the use of sensitive information such as geolocation, health data, document numbers, etc.

Don’t retaliate against customers who exercise their rights

Retaliation against customers who exercise their CPRA rights clearly violates the new regulations. Customers have rights, and you must comply with them to avoid financial punishment.

Final thoughts

California businesses must comply with CPRA regulations. We also see other states implementing the same or similar data protection frameworks. Even if you’re not based in California, understanding these new laws and how they impact your business operations will help you start implementing positive changes.

The post The CPRA compliance checklist every business should follow in 2023 appeared first on Cybersecurity Insiders.


May 02, 2023 at 09:09PM

BlackCat Ransomware group breaches Australia HWL Ebsworth law firm servers

Australia’s HWL Ebsworth law firm has issued a statement stating that its servers have been hacked and the personal data of its clients and some employees were accessed and siphoned by criminals.

The Blackcat ransomware gang posted a statement on its website reiterating the same, stating that they had siphoned approximately 4TB of company data, including employee CVs, ID card details, financial reports, account information, client documentation, credit card information, and a blueprint containing the network map of the entire HWL Ebsworth computer network.

Blackcat, also known as ALPHV, is one of the three ransomware gangs that seems to focus on large organizations operating in Australia. According to the analysis conducted by Palo Alto Networks, the notorious group has started targeting businesses that operate in nations supporting Ukraine in its war with Russia, and this was reaffirmed by another cybersecurity firm named SOPHOS.

Security researchers from Sophos added in their statement that the gang of criminals was infiltrating networks by exploiting vulnerabilities created from unpatched software and firewalls. It immediately issued an alert to businesses to raise their defense line as per the needs of the current cyber landscape and can take the help of its experts in doing so.

Medibank, LJ Hooker, and Optus were among the other companies targeted by the ALPHV ransomware group. Therefore, the government led by Anthony Albanese warned all organizations in November last year to bolster their cybersecurity infrastructure before it was too late.

Blackcat usually demands a ransom of over $5 million on average, but HWL Ebsworth is not in the mood to entertain any such demands as it has an efficient data continuity plan in place.

The post BlackCat Ransomware group breaches Australia HWL Ebsworth law firm servers appeared first on Cybersecurity Insiders.


May 02, 2023 at 08:29PM