/* ---- Google Analytics Code Below */
Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Monday, June 26, 2023

MIT-based AI apps startup aims to block supply chain attacks with advanced cybersecurity

IT-based AI apps startup aims to block supply chain attacks with advanced cybersecurity

Join top executives in San Francisco on July 11-12, to hear how leaders are integrating and optimizing AI investments for success. Learn More   in Venturebeat

The digital pandemic of increasing breaches and ransomware attacks is hitting supply chains and the manufacturers who rely on them hard this year. VentureBeat has learned that supply chain-directed ransomware attacks have set records across every manufacturing sector, with medical devices, pharma and plastics taking the most brutal hits. Attackers are demanding ransoms equal to the full amount of cyber-insurance coverage a victim organization has. When senior management refuses, the attackers send them a copy of their insurance policy. 

Disrupting supply chains nets larger payouts 

Manufacturers hit with supply chain attacks say attackers are asking for anywhere between two and three times the ransomware amounts demanded from other industries. That’s because stopping a production line for just a day can cost millions. Many smaller to mid-tier single-location manufacturers quietly pay the ransom and then scramble to find cybersecurity help to try to prevent another breach. Still, too often, they become victims a second or third time.  ... '


Thursday, March 23, 2023

Wave of Stealthy China Cyberattacks Hits U.S., Private Networks, Google Says

 Wave of Stealthy China Cyberattacks Hits U.S., Private Networks, Google Says

By The Wall Street Journal, March 22, 2023

China has routinely denied hacking into businesses or governments in other countries.

Said Charles Carmakal, Mandiant’s chief technology officer, “There is a lot of intrusion activity going undetected. We think the problem is a lot bigger than we know today.”

Researchers in Google's Mandiant division found that state-sponsored hackers in China have been using techniques that allow them to evade common cybersecurity tools and spy on government and business networks for years without being detected.

The researchers said hackers are compromising devices on the edge of the network and targeting software from VMware Inc. or Citrix Systems Inc., among others, which often run on computers without antivirus or endpoint detection software.

Mandiant's Charles Carmakal said the attacks, which generally exploit previously undetected flaws, likely are more widespread than previously known.

Carmakal noted this cyberattack method "is a lot harder for us to investigate, and it is certainly exponentially harder for victims to discover these intrusions on their own. Even with our hunting techniques, it's hard for them to find it."

From The Wall Street Journal

View Full Article - 


Wednesday, March 01, 2023

The 26 Words that Created the Internet

Recall having this being pointed out to us when we started advertising online.  Plan to buy. 

JEFF KOSSEFF

Important book,  Supreme Court today arguing on today on  related work.  Section 230 of the Communications Decency Act.   Ordering capability at  the link.    Plus new book also mentioned below.

See Book:   'The 26 Words that Created the Internet'

Jeff Kosseff is an associate professor of cybersecurity law in the United States Naval Academy’s Cyber Science Department. He is the author of four books and more than 20 academic journal articles.  

In fall 2023, Johns Hopkins University Press will publish his latest book, Liar in a Crowded Theater: Freedom of Speech in a World of Misinformation, which examines and defends legal protections for false speech. In 2019, he was named an Andrew Carnegie Fellow by the Carnegie Corporation of New York, to support his 2022 book The United States of Anonymous: How the First Amendment Shaped Online Speech. His 2019 book, The Twenty-Six Words That Created the Internet, traced the history of Section 230 of the Communications Decency Act. He also is the author of Cybersecurity Law, a textbook and treatise whose third edition was published by Wiley in 2022.  

His articles have appeared in Iowa Law Review, Illinois Law Review, Wake Forest Law Review, Berkeley Technology Law Journal, Computer Law & Security Review, and other law reviews and technology law journals. His research interests include cybersecurity regulation, online intermediary liability, and the law of armed conflict as applied to cyberspace.

Jeff practiced cybersecurity, privacy, and First Amendment law at Covington & Burling, and clerked for Judge Milan D. Smith, Jr. of the United States Court of Appeals for the Ninth Circuit and Judge Leonie M. Brinkema of the United States District Court for the Eastern District of Virginia. Before becoming a lawyer, he was a technology and political journalist for The Oregonian and was a finalist for the Pulitzer Prize for national reporting and recipient of the George Polk Award for national reporting.  

He received a J.D. from Georgetown University Law Center, and a B.A. and M.P.P. from the University of Michigan.   .... '   (Much more at the link) x


Tuesday, February 28, 2023

Securing Machine Learning is hard

 Via Schneier, with the usual insightful comments.

This is really interesting research from IEEE a few months ago:

Abstract: Given the computational cost and technical expertise required to train machine learning models, users may delegate the task of learning to a service provider. Delegation of learning has clear benefits, and at the same time raises serious concerns of trust. This work studies possible abuses of power by untrusted learners. We show how a malicious learner can plant an undetectable backdoor into a classifier. On the surface, such a backdoored classifier behaves normally, but in reality, the learner maintains a mechanism for changing the classification of any input, with only a slight perturbation. Importantly, without the appropriate “backdoor key,” the mechanism is hidden and cannot be detected by any computationally-bounded observer. We demonstrate two frameworks for planting undetectable backdoors, with incomparable guarantees. .... '

Saturday, February 18, 2023

What will it Take for Security to be Taken very Seriously?

Good considerable piece by Bruce Schneier, aiming at the  Policy Makers.  Intro: 

What Will It Take?

What will it take for policy makers to take cybersecurity seriously? Not minimal-change seriously. Not here-and-there seriously. But really seriously. What will it take for policy makers to take cybersecurity seriously enough to enact substantive legislative changes that would address the problems? It’s not enough for the average person to be afraid of cyberattacks. They need to know that there are engineering fixes—and that’s something we can provide. ...  (much more) 

Saturday, October 22, 2022

NSA cyber chief says Ukraine war is compelling more intelligence sharing with industry

 Cybersecurity as it evolves under global conditions. 

NSA cyber chief says Ukraine war is compelling more intelligence sharing with industry

NSA Cybersecurity Directorate Director Rob Joyce spoke Wednesday at the Trellix Cybersecurity Summit. (Pixelme Studios).

Written by AJ Vicens  OCT 19, 2022 | CYBERSCOOP

Rapidly and proactively sharing intelligence on cyberthreats with industry and critical infrastructure providers “can really make a big and decisive difference,” Rob Joyce, director of the NSA Cybersecurity Directorate, said Wednesday.

It’s one of the key lessons his agency “took away personally” from the ongoing war in Ukraine, Joyce said at the Trellix Cybersecurity Summit in Washington.

“Over time, I’ve changed my view about what it is to protect sources and methods,” Joyce said, noting that in his 30-plus years at NSA “it’s in our DNA” to protect sources and methods to ensure the ability to “know secrets into the future.”

But “what we know is often not sensitive, it is how we know it,” Joyce said. “We can make available the insights about what we know without putting at risk how we know it. That’s really an inflection point that lets us get to more prolific, more extensive and more closely sharing for operational outcomes.”

Joyce added that “it doesn’t do anybody any good if we know a thing and don’t do something. Doing is really the focus in the cybersecurity area. And if you’ve got secrets and understanding and you don’t operationalize those, they don’t count.”

Joyce pointed to what he called the “maturation” of the NSA’s Cybersecurity Collaboration Center as the venue for “working with industry to operationalize those ideas.” Information is shared with technology providers, major infrastructure providers and others, “who can then take action at scale.”

A recent example of such information sharing came earlier this month when the NSA, the FBI and the Cybersecurity and Infrastructure Security Agency released a joint advisory warning of state-aligned hackers using Impacket, an open-source toolkit to aid in network compromise, and a custom data exfiltration tool known as CovalentStealer against an unnamed defense industrial base entity.

More broadly, the U.S. government has been more aggressive about sharing intelligence about Russian plans, both in the days before the Feb. 24 invasion and since, as part of an effort to disrupt Russian attacks on Ukraine.

“When we set up that protection, protecting us protects you,” he said.  .... ' 

Friday, October 21, 2022

How Should Companies Prepare for Cybersecurity Regulations?

Very good, useful piece,  there are many links,  use the link just below to get a version that includes all links in the original  ...

A collection of observations, news and resources on the changing nature of innovation, technology, leadership, and other subjects.   By Irving Wladawsky-Berger

How Should Companies Prepare for the Coming Cybersecurity Regulations

“Cybersecurity has reached a tipping point,” wrote MIT professor Stuart Madnick in a recent Harvard Business Review article, New Cybersecurity Regulations Are Coming. Here’s How to Prepare. “After decades of private-sector organizations more or less being left to deal with cyber incidents on their own, the scale and impact of cyberattacks means that the fallout from these incidents can ripple across societies and borders.”

Given the growing threat of cyberattacks, there’s an urgent need to improve the security of IT systems. However, we still don’t know a lot about cyberattacks, including how many attacks have taken place and who’s been attacked. Until recently, cybersecurity regulation were mostly focused on data privacy, and the only attacks that had to be reported were those involving personal information, such as the theft of names and credit card numbers.

For example, when Colonial Pipeline suffered a serious ransomware attack in May of 2021 that shut down nearly 50% of fuel deliveries to the US East Coast, neither the company nor the pipeline operators were required to report the attack because personal information wasn’t stolen. “As a result, it’s almost impossible to know how many cyberattacks there really are, and what form they take,” said Madnick. “Some have suggested that only 25% of cybersecurity incidents are reported, others say only about 18%, others say that 10% or less are reported.” We need detailed information on who is being attacked, how are they getting attacked, what are the attackers after, and what have they’ve actually stolen.

Governments around the world are now proposing or enacting new laws and regulations. The General Data Protection Regulation (GDPR) requires that the EU’s 27 member states must report serious data breaches withing 72 hours. In the US, new regulations and enforcements are likely to come from the White House, Congress, the Cybersecurity & Infrastructure Security Agency (CISA), the Securities and Exchange Commission, the Federal Trade Commission, and a number of other agencies. Thirty six states have already enacted new cybersecurity legislation.

These new rules would require companies to report cyber incidents, like the Colonial Pipeline attack, especially when critical infrastructure industries are involved, such as energy, health care, communications and financial services. ....'   (click through above for all links) 

Saturday, August 27, 2022

Military Grade Cybersecurity Needed in Business

Good thoughts regards key issues. 

ACM NEWS

Raising the Ramparts, By David Geer, Commissioned by CACM Staff,   August 11, 2022

The global military cybersecurity market will grow from US$25,692.4 million in 2021 to US$ 43,675.2 million by 2031, says Visiongain Research, Inc., a U.K. market intelligence firm.

That growth is no surprise, with commonplace nation-state attacks on critical infrastructure and government data assets. The U.S. federal government and its agencies, with the aid of the Cybersecurity & Infrastructure Security Agency (CISA), are ramping up cyber defenses to combat disabling ransomware and complex attacks. They are using approved security products that the government and the military vet specifically for these purposes.

However, government organizations are not the only ones in jeopardy.

Nation-states target private enterprises, too, with support from their military and insidious Advanced Persistent Threat (APT) groups. Facing the same threats that government agencies do, companies need military-grade cybersecurity.

Military-grade cybersecurity proceeds from a Military Specification (MIL-SPEC) purchasing process, with rigorous testing to ensure cybersecurity components are the most secure, resilient product the military can get, says Peter Hay, Lead for Instruction at SimSpace Corporation, a military-grade cybersecurity risk management platform. The military uses extensive mission-based training to ensure its human cybersecurity talent adheres to MIL-SPEC security requirements, too.

MIL-SPEC cybersecurity products are a necessity, as high-profile cases of military-level attacks demonstrate. The Indian APT group ModifiedElephant stealthily attacked dissidents for 10 years without detection. The group used military-grade remote access trojans (RATs), keyloggers, and other attack tools, according to SC Media, a publication of the CyberRisk Alliance, an organization that, according to its Website, was "formed to help cybersecurity professionals face the challenges and obstacles that threaten the success and prosperity of their organizations."

The APT group Shadow Brokers stole the EternalBlue military-grade exploit from the U.S. National Security Agency (NSA) in 2017. It released the exploit to criminal hackers globally via subscription-based access to data dumps, according to The New York Times. Cybercriminals have since used EternalBlue successfully in many attacks.

According to Tom Van de Wiele, a principal of WithSecure, an endpoint detection and response company in Finland, the 2010 Stuxnet attack was the most profound military-level cyberattack on record. Stuxnet used intelligence gathering, local spies bridging air-gapped networks using USB thumb drives, and zero-day exploits to gain access and persist long enough to disrupt Iranian uranium enrichment infrastructure, he says.

With an increase in nation-state data breaches, cybersecurity vendors serving the military are offering comparable products and services to the private sector to maintain the balance of power against nation-state attacks.

For example, CrowdStrike provides its cloud-based endpoint and identity product Falcon to the U.S. Government with FedRAMP authorization, according to a CrowdStrike media release. Falcon also is available to private enterprises. ... 

Facing the same threats that government agencies do, companies need military-grade cybersecurity...

Wednesday, July 27, 2022

Bluetooth Signals Used to Identify, Track Smartphones

Tracking Smartphones

Bluetooth Signals Can Be Used to Identify, Track Smartphones

UC San Diego News Center

Ioana Patringenaru, June 8, 2022

Engineers at the University of California, San Diego (UCSD) have demonstrated an exploit that taps Bluetooth beacon signals emitted by smartphones to track individuals. The researchers showed the signals bear a unique fingerprint, which UCSD's Nishant Bhaskar said poses a serious threat "as it is a frequent and constant wireless signal emitted from all our personal mobile devices." The fingerprint stems from manufacturing flaws in hardware that are unique to each device, which generate novel Bluetooth distortions that attackers could use to bypass anti-tracking measures. Experiments validated the feasibility of using the exploit in real-world settings, although the researchers noted it requires attackers to possess significant expertise. ... 

Saturday, May 28, 2022

Call for a Cyber Secure Tech NATO

May make sense, but should it be connected to a largely military alliance?    Create incentives for cooperative cybersecure regulation and behavior. 

AI News

Darktrace CEO calls for a ‘Tech NATO’ amid growing cyber threats  By Ryan Daws | May 27, 2022 | TechForge Media

The CEO of AI cybersecurity firm Darktrace has called for a “Tech NATO” to counter growing cybersecurity threats.

Poppy Gustafsson spoke on Wednesday at the Royal United Services Institute (RUSI) – the UK’s leading and world’s oldest defense think thank – on the evolving cyber threat landscape.

Russia’s illegal and unprovoked invasion of Ukraine has led to a global rethinking of security. 

While some in the West had begun questioning the need for NATO post-cold war, and many members have failed to meet their defense spending commitments, the invasion of Ukraine has proven why the defense alliance remains a bedrock of Western security.

NATO members are now spending more on defense, increasing cooperation, and the alliance is now preparing to accept Sweden and Finland into its fold.   Russia has thrown out the rule book with its conduct and will eventually face war crime trials as a result. NATO members, in contrast, have acted in accordance with the UN charter and only provided resources to Ukraine that it can use to defend its territory from the invaders.

However, any provision of long-range weapons that could pose a threat to Moscow would be seen as going beyond helping an ally to defend itself into helping attack Russia itself—likely triggering a disastrous global conflict.

Those kinds of norms around conventional warfare are well-established. In the cybersphere, they’re yet to be set.  .... ' 

Sunday, May 22, 2022

Pentagon Making Cybersecurity Progress

Worked at the Pentagon, but long before this level of analysis was being done, but like to see advances being completed.   It is now essential now that cyber security is fundamentally well done.  Here a brief overview.  

Pentagon making progress on cybersecurity amid challenges, watchdog says    By Colin Demarest

The U.S. Government Accountability Office published on May 19 a review of the Department of Defense's cyber efforts to secure controlled unclassified information, sensitive data either created or possessed by the government. (File/Provided) .... 

WASHINGTON — The Department of Defense is making significant progress locking down sensitive networks amid cyber challenges from foreign adversaries bent on gaining access to intel, a report from a federal watchdog shows.

The department as of January recorded compliance at 70% or higher  in implementing four select protections for controlled unclassified information, which may include data tied to critical technologies or the development and operation of weapons and defense infrastructure, according to the Government Accountability Office.  .... ' 

Tuesday, May 17, 2022

Data Poisoning in AI

 Out of O'Reilly, had never heard of it, but can understand it happening: 

O'Reilly Infrastructure and Ops Newsletter: "...The next cybersecurity crisis: Poisoned AI was inevitable that AI and cybersecurity would collide in ways that are both beneficial and bad. One specific danger: data poisoning.      Manipulating the information used to train machines can be a nearly untraceable method for getting around AI-powered defenses..... " 

Friday, April 01, 2022

Cybersecurity Workers Needed

Qualified workers needed for talent pipeline. 

 Hackers' Path Eased as 600,000 U.S. Cybersecurity Jobs Sit Empty

Bloomberg, Olivia Rockeman, March 30, 2022   in Boomberg

Cybersecurity jobs search platform CyberSeek estimates roughly 600,000 vacant U.S. cybersecurity positions, including 560,000 private-sector jobs. The pandemic compounded a shortfall of cybersecurity professionals, while phishing and ransomware attacks escalated due to many employees using their home networks and computers. The Massachusetts Institute of Technology Sloan School of Management's Stuart Madnick cites a lack of qualified cybersecurity workers, while Bryan Palma at cybersecurity company Trellix said nations like Russia and China host better talent pipelines at the government level of people trained in cybersecurity. Max Shuftan at the SANS Institute cybersecurity training organization said the worker shortage especially impacts smaller organizations like civilian public agencies, most of which cannot match private companies' pay. As a result, Shuftan warned, "They're probably not going have the staff and that makes them more vulnerable to attacks."

Full Article 

Friday, January 28, 2022

Ways AI and ML will improve cybersecurity in 2022

 Good thoughts, its all about patterns in context. 

Ways AI and ML will improve cybersecurity in 2022, By Louis Columbus, January 19, 2022 8:40 AM in Venturebeat

Cyberattacks are happening faster, targeting multiple threat surfaces simultaneously using a broad range of techniques to evade detection and access valuable data. A favorite attack strategy of bad actors is to use various social engineering, phishing, ransomware, and malware techniques to gain privileged access credentials to bypass Identity Access Management (IAM) and Privileged Access Management (PAM) systems.

Once in a corporate network, bad actors move laterally across an organization, searching for the most valuable data to exfiltrate, sell, or use to impersonate senior executives. IBM found that it takes an average of 287 days to identify and contain a data breach, at an average cost of $3.61M in a hybrid cloud environment. And when ransomware is the attack strategy, the average cost of a data breach skyrockets to $4.62M.

Using AI to anticipate and lure attacks

A perfect use case for AI and machine learning (ML) is deciphering the millions of concurrent data connections a typical enterprise has with the outside world at any given minute. Training supervised machine learning algorithms with data streams helps them identify potential anomalies, even before the algorithm understands what the definition of an anomaly is, according to Boston Consulting Group.

Friday, October 29, 2021

Microsoft to Help Train Cybersecurity Personnel.

 Good to see many more people being involved in the strengthening of our technical security.  Just having more people understand the challenge has value.   Congrats to Microsoft.

Microsoft to Work with Community Colleges to Fill 250,000 Cyber Jobs

By Reuters  October 29, 2021  in CACM

Microsoft Corp  plans to work with community colleges across the United States to fill 250,000 cybersecurity jobs over the next four years.

Microsoft said it will provide scholarships or assistance to about 25,000 students and will provide training for new and existing teachers at 150 community colleges across the country. The company also said that it will provide curriculum materials for free to all community colleges, as well as four-year schools, in the country.

Microsoft President Brad Smith said many Microsoft customers have suffered hacks that could have been prevented or mitigated with better practices but lack the cybersecurity personnel to do so. "We clearly need to move quickly to train people," Smith said. ... 

From Reuters  full article

Sunday, October 03, 2021

Active, Self-Healing Cybersecurity

 Ideal, intelligent, but like AI, how generally practical today? 

On Active, Self-Healing Cybersecurity

ACM NEWS, Active Defenders

By David Geer, Commissioned by CACM Staff, September 30, 2021

The U.S. Federal Bureau of Investigation (FBI) Internet Crime Complaint Center received 791,790 cybercrime complaints in 2020, with losses exceeding US$4.1 billion, according to the FBI's 2020 Internet Crime Report. Cyberthugs have been automating cyberattacks for years using tools such as command and control (C&C) servers to puppet their botnets and malicious infections. Cybersecurity needs to automate its response to the schemes of these criminal hackers.

According to Innovation Origins, a European platform for independent journalists who write about innovation, start-ups, and "technologies that will shape the world of tomorrow," Dutch bank ABN AMRO will use self-healing cybersecurity software developed by TNO (The Netherlands Organization for Applied Science Research) to protect applications running in software containers. Containerization benefits software development with standardized application container images that accelerate secure development and deployment. The human immune system inspired the self-healing concept, which will replace containers periodically to remove unknown infections. The self-regenerating software solution will replenish containers when security monitoring and threat detection tools identify infections.

Developers from TNO created and integrated software called Lympho, which implements the Self-Healing-4-Cyber-Security (SH4CS) concept, with Kubernetes + Docker platforms to heal containers through regeneration automatically. Kubernetes is a popular open-source container orchestration platform from Google, which many organizations use to develop and deploy their software. Docker is a popular open-source application container platform that automates deployment, typically using container images.  ... ' 

Thursday, September 30, 2021

Cyber Security in Oil and Gas

 Already broadly attacked, examples below. 

Oil and Gas Companies Must Act Now on Cybersecurity      Via Siemens

August 13, 2021, Oil and Gas Companies Must Act Now on Cybersecurity

The World Economic Forum’s Cyber Resilience in the Oil and Gas Industry: Playbook for Boards and Corporate Officers Provides a New Blueprint to Secure Critical Infrastructure, the most personally disruptive incident in recent memory came in May 2021 with the ransomware attack that shut down a major U.S. oil and gas pipeline responsible for supplying nearly half of the East Coast’s petroleum. But for global energy industry leaders – and the oil, gas and utility sectors in particular – this is another incident in a series of cyber attacks on critical infrastructure in the increasingly harried digitally connected energy ecosystem that requires an urgent solution.

The energy sector is no stranger to cyber attacks. For many American families and businss Navigating big challenges, from the NotPetya cyber attack on a Ukrainian utility in 2017 that shut down much of the country’s power grid, to the attack on the Colonial Pipeline in 2021, is a responsibility that now falls on the energy sector’s top executives and board members. These leaders need to mitigate cyber risk in a sector undergoing a digital revolution and is now frequently targeted for geopolitical purposes and financial gain by cyber criminals. While governments around the world develop new policies, norms and consequences for future cyber attacks, oil and gas executives and board members cannot wait on government to come to a geopolitical détente, issue new regulations or aid in efforts to secure critical energy systems.

Instead, CEOs and board members must draw from their decades of expertise in integrating energy assets with operational technology (OT) and leveraging information technology (IT) networks to reduce cyber risk across their hyperconnected operating environments. For decades, oil and gas companies have pursued productivity gains by linking physical energy assets with OT control systems and IT networks. That trend continues today with energy organizations seeking big data, artificial intelligence (AI), and automation solutions to reduce costs, improve efficiency and help reduce emissions. Throughout this process, industry executives have also pioneered key management principles and risk-based approaches to securing the technologies and processes that serve as the foundation for their hyperconnected industrial Internet of Things (IoT) business model.  ... '

Saturday, September 04, 2021

Impact of Cybersecurity and International Trade

 Wladawsky-Berger's latest piece as applied to cybersecurity.  Below the intro, then much more inked to: 

Irving Wladawsky-Berger

A collection of observations, news and resources on the changing nature of innovation, technology, leadership, and other subjects.

Understanding the Impact of Cybersecurity on International Trade

The explosive success of the Internet in the 1990s led to a historical transition from the industrial age of the past two centuries to an economy and society increasingly based on global, digital interactions.  This transition has continued to advance over the past two decade with the advent of billions of smartphones, hundreds of billions of IoT devices, a wide variety of online applications and mobile apps, and huge amounts of data, all connected via Internet-based broadband networks.

Then came Covid-19. A recent McKinsey survey found that the pandemic has accelerated the overall adoption of digital technologies and applications by three to seven years in just a few months.

At the same time, cybersecurity threats have been growing. Large-scale fraud, data breaches, and identity thefts have become far more common. As we moved from a world of physical interactions and paper documents, to a world primarily governed by digital data and transactions, our existing cybersecurity methods have been far from adequate.  ... ' 

Wednesday, August 04, 2021

The Cyber Risk in Digital Transformation

Its not brought up enough as a key part of the transformation effort.  It is essential as threats enlarge.  What do you have if the attackers get control? 

Cyber Risk in Digital Transformation   By David Geer, Commissioned by CACM Staff August 3, 2021

Organizations globally are engaged in Digital Transformation (DX), a sort of cyber-industrial revolution promising digital automation and operational agility. According to Salesforce, "Digital Transformation uses digital technologies to create new—or modify existing—business processes, culture, and customer experiences to meet changing business and market requirements."

In a recent use case, Bed, Bath, and Beyond applied Digital Transformation to add same-day delivery services, buy-online-pickup-in-store, and contactless curbside pickup. The new services are attractive to customers, and are possible thanks to digital change.

Yet rapid, unbridled Digital Transformation adds cybersecurity risks. According to a Ponemon Institute report, organizations that rush to the cloud and third-party (vendor) relationships to accelerate digital projects invite attacks via unsecured cloud environments and poorly vetted vendors.

The pandemic was just cause for our digital cloud stampede, but the success of Work From Home has been seminal for attacks that leapfrog to the cloud. According to Tim Rawlins, senior adviser, NCC Group, a large global security consultancy, many organizations that responded to COVID-19 by rapidly enabling Work From Home took on new cloud services without their normal levels of due diligence around security and resilience.  ... 

One study warns that organizations that rush to the cloud and third-party relationships to accelerate digital projects invite attacks via unsecured cloud environments and poorly vetted vendors.  .... 

Thursday, July 08, 2021

Automotive Cybersecurity

Vehicles in particular will require specialized cybersecurity as their autonomy increases.

Keeping Control of the Wheel   By David Geer   in ACM

The rising need for cybersecurity will trigger investments over the next few years. We expect to see the market grow from US$4.9 billion in 2020 to US$9.7 billion in 2030, with software business representing half of the market by 2030," according to "Cybersecurity in automotive: Mastering the challenge," a 2020 market study by global management consulting firm McKinsey & Company.

The study "Automotive Cybersecurity Market: the Development of Autonomous Cars and Other Notable Growth Drivers," by market intelligence firm Infinity Research, identifies the market forces advancing automotive cybersecurity as including:

The development of autonomous vehicles with wireless connections.

The increasing number of in-vehicle electronic control units and their wireless connections.

Regulatory mandates and standards targeting the cyber-safety of vehicles and data .

Nobody wants criminal hackers in the driver's seat. "Much of the motivation to implement enhanced security systems stems from advances in in-vehicle capabilities. Progress in these internal capabilities includes Advanced Driver Assistance Systems (ADAS). These systems necessitate heightened computer control over sensitive actuators (drive by wire, including steer by wire, throttle by wire, and brake by wire)," says Josh Siegel, assistant professor of computer science and engineering at Michigan State University (MSU).

According to the 2021 HSB Cyber Car Tech Survey by cyber risk insurer HSB Group, more than a third of U.S. consumers say they are concerned about the cybersecurity of connected cars. Another third say they fear a computer virus, hacking incident, or other cyberattack that could damage or destroy their vehicle's data, software, or operating systems.

To MSU's Siegel, growing hacker expertise suggests automotive cyberattacks are unleashed by criminal hackers with malicious intent, and not just discovered by researchers to bring vulnerabilities to light. There have been targeted hacks turning vehicles into espionage devices at military bases and disabling engines, so the individual has to take other transportation to work, says Siegel. "I assume that nation-states or well-resourced entities are executing these attacks," says Siegel.

The 2021 Global Automotive Cybersecurity Report by connected vehicle cybersecurity provider Upstream Security, found that malicious blackhat hackers last year carried out 55% of automotive cyberhacks to disrupt business, steal property, and demand ransom. Whitehat hackers and researchers, including those participating in automotive bug bounty programs, performed 38.6% of hacks, the report says. Bug Bounty programs pay white hat hackers a reward or "bounty" for finding critical vulnerabilities in an organization's software.  ... '