Thursday, September 24, 2015

Healthcare industry sees 340% more security incidents than the average industry



Posted on 24 September 2015.

Raytheon|Websense examined the current state of cyber threats and data-stealing attacks against an increasingly digital healthcare industry. Healthcare is highly-targeted and increasingly vulnerable as the next wave of connected devices hits an already complex technology environment.


"The rapid digitization of the healthcare industry, when combined with the value of the data at hand, has lead to a massive increase in the number of targeted attacks against the sector," said Carl Leonard, Raytheon|Websense principal security analyst. "While the finance and retail sectors have long honed their cyber defenses, our research illustrates that healthcare organizations must quickly advance their security posture to meet the challenges inherent in the digital economy – before it becomes the primary source of stolen personal information."

In 2014, Websense identified a 600 percent increase in cyber-attacks against hospitals within a 10-month period. As a follow up to this discovery, Raytheon|Websense Security Labs recently examined the real-world attack telemetry against healthcare, uncovering new intelligence about the most prolific and effective cyber-attack tools, techniques and security trends impacting the industry.

Top findings include:

1. The healthcare industry sees 340 percent more security incidents and attacks than the average industry and, as a result, is more likely to be impacted by data theft: Medical information is 10 times more valuable on the black market making healthcare a major target for cybercriminals. The proliferation of electronic health records creates a data-heavy environment, while networks comprising thousands of providers present an enormous attack surface.

2. One in every 600 attacks in the healthcare sector involve advanced malware. In fact, the healthcare sector is four times more likely to be impacted by advanced malware than any other industry: With many organizations lacking budget and the administrative, technical or organizational skills necessary to detect, mitigate and prevent cyber-attacks, advanced malware presents a significant threat to healthcare infrastructure.

3. The healthcare sector is 74 percent more likely to be impacted by phishing schemes: A lack of effective security awareness training and employee security awareness programs often compounds the danger of increased phishing attempts, resulting in more security incidents.

4.Healthcare is 4.5 times more likely to be impacted by Cryptowall and three times more likely to be impacted by Dyre: First used to target the financial sector successfully stealing hundreds of millions of dollars, new exploit capabilities make Dyre malware a significant data loss threat for healthcare organizations worldwide, while Cryptowall encrypts and holds hostage critical healthcare data for ransom.

Friday, September 11, 2015

Ex-Citi trader points finger at bosses for culture that allowed breaches


Ex-Citi trader points finger at bosses for culture that allowed breaches

Reuters
                       
A view of the exterior of the Citibank Corporate headquarters in the Manhattan borough of New York
.
View photo
A view of the exterior of the Citibank Corporate headquarters in the Manhattan borough of New York City, …
By Steve Slater
 
LONDON (Reuters) - A former foreign exchange trader claiming he was unfairly dismissed by Citigroup said the sharing of client information looks wrong now it has come under scrutiny from regulators, but was condoned by senior management at the time.
Perry Stimpson, a forex trader at the banking group until he was fired last November, is claiming unfair dismissal at a London employee tribunal. Citi says he was dismissed for serious breaches of contract, alleging he shared confidential client information with traders at other banks via electronic chatrooms.
"Now in the glare of scrutiny from regulators these activities look wrong. But at the time they were market convention," Stimpson said under cross-examination on Friday.
Citigroup is one of seven banks to be fined more than $10 billion for failing to stop traders manipulating the forex market.
Stimpson said he saw senior forex staff sharing information about client activities, and even more senior staff effectively condoning this activity as they were aware of it but took no action.
"If you look at any organization, surely you look to senior management," Stimpson said. "The culture in any organization is set by senior management down. If you see senior management do something, it implies to you it's OK."

WITHOUT MERIT
Citigroup said in a statement: "Mr. Stimpson is making these allegations to deflect attention from his own misconduct.  All of the allegations of wrongdoing being made by Mr Stimpson have been investigated and were found to be without merit." Its lawyer told the tribunal the investigations had been conducted internally and by its external counsel.
Stimpson admitted he shared information about a central bank client in a chatroom. But he said whether client information could be shared was a "bit of a gray area". Citi staff knew details of some client activities were strictly confidential, but the actions of central banks were widely shared, he said.
"It was implicitly understood that central banks were OK to talk about ... It was standard market practice that went on for years," he said.
Citigroup told the tribunal it had concerns that Stimpson breached client confidentiality on at least 12 occasions in chatroom conversations, which broke its code of conduct. The dates of the breaches have not been disclosed, but they include conversations in 2010.
Citigroup said its code of conduct made no exceptions for central banks or any clients. Stimpson agreed, but said the bank did not provide guidelines on what was allowed in chatrooms until January 2013.
Citi's lawyer Diya Sen Gupta said because other traders shared information in chatrooms did not allow Stimpson to do so. "Just because other people are doing something wrong, doesn't mean you are excused from your own behavior."
The hearing will extend into next week. Employment tribunal Judge Alison Russell is expected to give her decision by early October.

(Editing by David Holmes)

Tuesday, September 8, 2015

Caesars Palace pays $8 million penalty for compliance 'blind spot'

Caesars Palace pays $8 million penalty for compliance 'blind spot'




The Treasury Department's Financial Crimes Enforcement Network said Tuesday that the owner of Caesars Palace casino in Las Vegas will pay an $8 million civil penalty for "willful and repeated violations" of the anti money-laundering provisions of the Bank Secrecy Act.
The casino owner -- Desert Palace, Inc. -- also agreed to conduct periodic external audits and independent testing of its anti-money laundering (AML) compliance program.
The casino will report to FinCEN on improvements to its compliance program, and adopt "a rigorous training regime."
Caesars Las Vegas is a 3,960-room hotel and casino located on the strip. The casino includes 1,371 slot machines, 141 table games, a race & sports book, and private gaming salons.
"The casino allowed a blind spot to exist in its compliance program -- private gaming salons -- which are reserved for Caesars’ wealthiest clientele who may gamble millions of dollars in a single visit, and which openly allowed patrons to gamble anonymously," FinCEN said.
Caesars marketed the salons through branch offices in the U.S. and overseas, particularly in Asia. But it didn't "adequately monitor transactions, such as large wire transfers, conducted through these offices for suspicious activity."
FinCEN said,
Despite the elevated money laundering risks present in these salons, Caesars failed to impose appropriate
AML scrutiny, which allowed some of the most lucrative and riskiest financial transactions to go unreported.
The failures compromised Caesars, FinCEN said, and exposed the casino and the U.S. financial system to illicit activity.
“Caesars knew its customers well enough to entice them to cross the world to gamble and to cater to their every need,” FinCEN director Jennifer Shasky Calvery said. “But, when it came to watching out for illicit activity, it allowed a blind spot in its compliance program."
The blind spot "caused systemic and severe AML compliance deficiencies," FinCEN said.
Caesars petitioned for bankruptcy in January 2015. The bankruptcy remains pending.
The casino's agreement with FinCEN needs approval from the bankruptcy court. 
- See more at: http://www.fcpablog.com/blog/2015/9/8/caesars-palace-pays-8-million-penalty-for-compliance-blind-s.html#sthash.6aOtM47W.dpuf

Monday, September 7, 2015

End-to-end encryption is key for securing the Internet of Things

End-to-end encryption is key for securing the Internet of Things
by Vaughan Emery - CEO and President, CENTRI Technology - Monday, 7 September 2015.
The Internet of Things (IoT) is one of the hottest buzzwords these days. It seems like almost everything is being connected, including cars, streetlights, oil rigs, wearables and more. By the end of this decade, Gartner estimates there will be 26 billion IoT devices in service, while IDC predicts 28.1 billion.

There’s no safety in those numbers. Just the opposite: Every IoT device is an endpoint, like a PC or smartphone, which means every one is a potential back door for hackers. Worse, many IoT devices are connected to mission-critical equipment, such as switches at electric utility substations, or telemedicine monitors in patients’ homes. Those roles make IoT devices tempting targets for terrorists, rogue nations and others who want to wreak a lot of havoc with a single attack.

Those attacks are in addition to those that leverage the IoT to steal credit information, corporate secrets and other data. The Ponemon Institute’s 2015 Cost of Data Breach Study: Global Analysis says the average cost of each lost or stolen record containing sensitive and confidential information increased from $145 in 2014 to $154 this year. IoT will drive that cost even higher simply because it increases the number of attack opportunities. In fact, IDC predicts that by the end of 2016, 90 percent of all IT networks will have experienced an IoT-based security breach.

There are other consequences when businesses, organizations and entire industries don’t take IoT security seriously – and fast. One example is a IoT-enabled attack on railway infrastructure so big and embarrassing that results in onerous, expensive new regulations that the industry could have avoided by being proactive. Another is an automotive brand sullied by the public’s perception that its smart vehicles are easily hacked.

Securing the IoT begins with understanding why it requires a fundamentally different set of strategies and tools than those currently used in IT, telecom and other domains. IoT networks are typically not behind a firewall, but rather mobile or spread over too large of an area. SSL/TLS is not sufficient for small devices with the need to protect the data in use, in motion and at rest. SSL was simply not designed for the challenges facing IoT Therefore, firewalls and SSL won’t be able to keep up with IoT’s scale and device fragmentation, which spans everything from wearable health devices to smart vehicles to industrial controls. And although IDC estimates that there are already more than 9 billion IoT devices in service today, it’s still a relatively new space, where many standards and best practices that would aid security are still in development.

For some perspective, consider how enterprises currently struggle to keep up with evolving attacks on a relatively small set of familiar devices, such as servers, PCs and smartphones. IoT makes that look like a walk in the park.

Next-gen encryption for a new paradigm

Within the next five years, 90 percent of all IoT data will reside in third-party clouds, IDC predicts. That statistic is just one example of why enterprises, government agencies and other organizations should take adopt an “encrypt-everything” strategy to protect against IoT-enabled breaches.

This strategy maximizes protection regardless of whether the data resides in a public or private cloud, on an IoT endpoint and when it’s in transit. Encrypting everything also complements the traditional focus on network security because even when that initial line of defense fails, the data remain protected. That wasn’t the case in several recent, high-profile attacks such as Anthem, where hackers accessed unencrypted personal information for 80 million policy holders

For every organization, network breaches are a matter of when, not if, and IoT means more of them simply because it’s increasing the number of endpoints exponentially. So why don’t more organizations encrypt everything? One reason is because standards such as AES and IPSec are so processor-intensive, making them a poor fit for laptops, smartphones and IoT devices such as wearables. It’s not just battery life that suffers. The IoT market is notoriously price-sensitive, so those devices have limited processor capabilities in order to keep the bill-of-materials cost low enough to enable the widest possible adoption.

That’s why organizations should build their encrypt-everything strategy around next-generation technologies, which are much less resource-intensive but with no trade-offs in protection. For example, instead of encryption methods based on blocks or files, look for solutions that encrypt and compress data in real time in a single pass at the byte level. This design also ensures that the user experience isn’t compromised, such as slow performance.

Network data efficiency is also essential for any large scale IoT solution – if the IoT devices send too much wireless data then the costs become too high. For example, many IoT devices will use cellular or wireless connections, so compression becomes an important feature to reduce the cost that the user pays for that connectivity or bandwidth. The sheer amount of IoT devices also will create traffic loads large enough to overwhelm even the most robust wired network. An efficient low-latency data compression technology can be an effective means to minimize the workload for wired and wireless networks alike.

The ideal next-gen solution also adds synchronized data to the standard encryption key, making it impossible to decrypt the information remotely even if the key is compromised. Secure device authentication with near real-time speed to reduce latency is another key to IoT security and efficiency. Device authentication and packet encapsulation can also mitigate DDoS attacks to reduce service interruptions.

Best of all, an encrypt-everything strategy can be applied to non-IoT devices and applications. That broad applicability increases the return on those encryption investments by expanding that protection throughout an organization.

In the Internet of Everything, data will reside everywhere, which means a lot of that data can’t be protected by traditional, network-centric devices such as firewalls. Only end-to-end encryption can provide the security necessary to minimize IoT-enabled breaches. However, the encryption technology must be designed for modern use cases and devices, such as by making the most efficient possible use of processors and batteries. Organizations that choose the right encryption solution and then apply it everywhere will be best equipped to address IoT-enabled threats.

Tuesday, August 25, 2015

Cloud Encryption: It’s All About the Key Management

Cloud Encryption: It’s All About the Key Management


August 4, 2015





















Cloud Encryption - Key Management IconFor security professionals, one of the primary challenges that arises with cloud computing is that they are faced with somehow protecting resources that, to varying degrees, they no longer have control over and for which traditional security controls like firewalls and IPS devices are ineffective.  However, regardless of which cloud model you adopt – IaaS, PaaS, SaaS, hosted private cloud, etc. – one thing you can still have some control over is your data.  But how to accomplish this when the data lives – at least part of the time – in someone else’s infrastructure?
As in other sectors of security, the emergence of cloud computing has breathed new life into certain long-existing security technologies, and in recent years, we’ve seen a ‘rebirth’ of encryption as a primary way to ensure that sensitive data remains protected even outside the corporate confines.  Encryption is arguably one of the oldest security tools and has been around for a millennia, but its complexity has often meant encryption has been relegated to the background and reserved for only the most stringent use cases.
Cloud has changed that.
As in the pre-cloud world, encryption does come with some potential drawbacks.  One of the main challenges is to implement encryption in a way that allows critical application features to still function normally, and also without impacting performance, uptime, and perhaps most importantly, the user experience.
The second major challenge, and arguably the more important one, is key management.  How you handle encryption keys, share them securely with others, rotate them, etc. is critical, since whoever controls the keys literally owns the data – history has given us plenty of examples of how either weak crypto or bad key management can be worse than having no encryption in the first place.
With respect to cloud security – and SaaS applications specifically – the issue of key management has been somewhat contentious.  A number of vendors have emerged in recent years that provide encryption for various SaaS applications using a gateway model that intercepts traffic en route to SaaS applications and encrypts sensitive data.  Most importantly, these vendors are able to do so in a way that most of the functionality of the SaaS app is preserved, and customers retain control of the keys on their own premises to ensure that nobody at the SaaS provider can access critical data – either maliciously, or perhaps in the event of a legal order.  The primary potential drawbacks to this approach are that it can be costly, both in terms of hardware and integration work, and application performance can be affected (particularly when applications are updated).
In addition to third-party encryption solutions, we’ve recently seen a move by both SaaS providers as well as big-data distributors to offer encryption and key management natively, so their customers can protect their data without the added cost and integration work that sometimes comes with third-party solutions.  Examples include big-data distributors Cloudera and Hortonworks, each of which acquired encryption vendors last year that allow them to offer encryption to their customers as either a standard feature or as a premium service.
Among SaaS providers, Box also offers its own native encryption, and earlier this year introduced a premium version that allows customers to maintain control over their encryption keys by physically separating them from Box’s internal servers and admins.  The most recent example is Salesforce’s launch of native encryption – called Platform Encryption – as part of its new Salesforce Shield premium security offering.  Platform Encryption has a variety of interesting features and has been architected in a way that makes it extremely difficult to be misused by Salesforce employees.  However, customers don’t have the option of keeping their encryption keys on their own premises, which may be OK with many customers, but not those facing strict compliance or data residency requirements.
The $64k question, then, is how many customers fall into each camp?  Cloud security is still at an early stage of development, and the market’s acceptance of Box’s EKM and Salesforce’s Platform Encryption should provide interesting test cases for how the cloud data-protection industry will unfold over time.  For the near-term, however, we think it’s likely that several models will co-exist, with both native and third-party offerings, as well as both provider-managed and customer-managed keys.  Either way, as cloud infrastructure and applications become more tightly woven into the fabric of most modern enterprises, encryption will increasingly be expected as a standard feature of most cloud offerings.  And as encryption assumes its rightful place in the cloud security toolkit, so too will the need for a key management system that supports a variety of cloud and encryption architectures and also scales to meet the demands of an elastic, on-demand infrastructure.  After all, whoever controls the keys, controls the kingdom.
Regardless of which camp you may fall in, historically, ‘good enough security’ has been, well – good enough.  Too many organizations have been content to check off compliance boxes and move on.  However, we are seeing increasing evidence that this may be changing, and the seemingly endless parade of data breaches may be causing more companies to think about implementing security best practices rather than just doing the bare minimum.   That said, our guess is that for the time being, the lack of an on-prem key management option is not a deal killer for the majority of customers.
For large SaaS, IaaS and big-data providers, we are likely to see more native encryption options come to market as they look to meet customer demands for data protection. But how will they handle key management?  Will they follow Salesforce’s lead and keep the keys to themselves, or adopt Box’s model and let customers keep control?
As mentioned earlier, for customers with strict internal security policies or those facing data residency requirements, on-prem key management will remain a must, and for this group, third-party encryption vendors will still play a large role.  Either way, we see third-party vendors evolving more towards key management and away from basic encryption, particularly as more customers adopt multiple cloud applications and may have a need for a centralized way of managing their keys.
For smaller SaaS providers, many may opt to integrate third-party encryption and key management offerings directly into their products rather than expending the time and resources that Salesforce and Box likely did to develop with their own native offerings.
Regardless of how things play out, key management will remain a central issue in the battle for cloud data security.
Larger SaaS, IaaS and big-data providers are likely to deliver more native encryption options as they look to meet customer demands for data protection, and many will opt to architect their offerings with an on-premise key management option.  Smaller SaaS providers with less internal resources and expertise may opt to integrate third-party encryption and key management offerings directly into their products.
Garrett Bekker is a Senior Analyst in the Enterprise Security Practice at 451 Research, drawing on more than 15 years of enterprise security experience. For more security insights from Garrett, follow him on Twitter via @gabekker and read his 451 Research reports.
- See more at: http://data-protection.safenet-inc.com/2015/08/cloud-encryption-its-all-about-the-key-management/#sthash.MzShzomz.5xwzQfow.dpuf

Target to pay up to $67m in data breach settlement with Visa

Target to pay up to $67m in data breach settlement with Visa

By Sooraj Shah       
21 Aug 2015         
targer-customers-have-been-affected-by-the-data-breach
US retailer Target could pay up to $67m to Visa and banks that issue Visa cards for the costs incurred as a result of the devastating hack in which the payment card details of 40 million customers were stolen.
The attack, which occurred in 2013, saw approximately 110 million Target customers' personal data being stolen, and the company has since faced legal action from consumer groups and financial institutions over the breach.
           
However, any bank that agrees to this settlement deal will have to drop their involvement in any other legal action, according to Reuters. Many Visa card-issuing banks support the legal action brought forward by Visa, according to The Wall Street Journal.
Target is now working on a similar deal with MasterCard, after an initial $19m settlement was not supported by a sufficient number of MasterCard-issuing banks.
The US retailer's card details were stolen after the attackers, using compromised network-access credentials stolen from one of the company's suppliers, were able to plant malware onto Target's security and payments system. This enabled them to cream off the credit card details from every transaction at the company's 1,797 US stores.
While the attack was spotted almost straightaway by FireEye, the company's security monitoring company, and by its own IT security staff in Bangalore, staff at the company's headquarters completely failed to heed their warnings. Target head office staff only responded when the US Department of Justice notified the retailer of the breach in mid-December 2013.
Had Target acted on the initial warnings, the attack would have been prevented.
As a result of the hack, Target's CEO Gregg Steinhafel and its CIO Beth Jacob resigned from their roles. The firm hired Bob DeRodes in a fire-fighting CIO role in the aftermath of the hack, but he has since retired and been replaced by former Tesco CIO Mike McNamara.

Wednesday, August 19, 2015

Walmart FCPA spending just topped $650 million


Walmart FCPA spending just topped $650 million

Walmart said in a management call Tuesday that FCPA and compliance-related costs were about $30 million during the second quarter, with $23 million for ongoing investigations and $7 million for the company's global compliance program.
The company said it expects to spend between $130 million and $150 million on FCPA-related costs for the full year.
First quarter FCPA and compliance-related costs this year were $33 million.
In April 2012, the New York Times reported that Walmart's Mexico unit paid $24 million in bribes to speed up licensing and permitting for new stores. The paper said top managers in the United States covered up the bribery after learning about it.
The DOJ and SEC are investigating possible FCPA violations in Mexico, as well as in China, India, and Brazil, among others.
The Bentonville, Arkansas-based retailer said for fiscal 2015 (ended January 31), FCPA-related costs were $173 million.
In its fiscal 2014 Global Compliance Program Report, Walmart said it had spent $439 million in legal fees and other costs associated with investigations of alleged FCPA violations, and to revamp its global compliance program.
FCPA costs were $282 million in 2014 and $157 million in 2013, the company said.
- See more at: http://www.fcpablog.com/blog/2015/8/19/walmart-fcpa-spending-just-topped-650-million.html#sthash.aR2aZCl3.dpuf