Showing posts with label cyber. Show all posts
Showing posts with label cyber. Show all posts

Wednesday, August 12, 2020

Trend Micro Lands Industry’s Most Comprehensive XDR Platform in Asia Pacific, Middle East, and Africa


Trend Micro Incorporated (TYO: 4704); the leader in cloud security, today announced that its XDR suite is officially available in Asia Pacific, Middle East, and Africa (AMEA). Trend Micro XDR is the first in the cybersecurity industry that offers the most extensive correlated detection going beyond endpoint detection and response (EDR). It collects and analyzes activity data from emails, endpoints, servers, cloud workloads, and networks, enabling security operations center (SOC) teams to detect, investigate, and respond to threats more effectively.  

Today’s SOC analysts are up against sophisticated threats that are designed to circumvent the most advanced protection. Adding fire to the fuel is the massive volume of alerts they have to triage on a daily basis. Low job satisfaction and cybersecurity talent shortage are commonplace challenges for SOCs across the region.  

Trend Micro’s XDR is designed to address such operational nightmares in a SOC. It delivers three major benefits, unparalleled by any other existing point solution:  

Reducing alert fatigue: XDR automatically correlates and analyzes data from multiple security vectors to tell a bigger story. With XDR, level one SOC analysts no longer have to comb through mountains of noisy alerts and logs to identify a potential attack. XDR does it automatically for them and generates a few high-fidelity alerts instead of a thousand low-confidence ones, significantly reducing alert volume.  

Powerful workbench that provides contextual visibility for alerts: The XDR dashboard presents attacks in a visualized manner, enabling SOC analysts to see the different stages, attack vectors, dwell time, and the spread and impact. XDR also offers contextually aware response options so SOC analysts can take quick actions within the platform.  

Augmenting SIEM and effortless API integration: Trend Micro XDR augments SIEM for the SOC team, with centralization of normalized data and incident response capability that improve operational efficiency and productivity. XDR provides pre-built SIEM connector for Splunk to pull high-fidelity alerts into SIEM dashboards. For customers with their preferred SIEM solution, a public API can be used for the integration.  

Trend Micro’s XDR is also available as a managed service (MDR), to further alleviate the pressure of constrained in-house teams. The MDR team conducts 24/7 full-threat analysis and threat hunting, and provides response plans and remediation recommendations.  

“EDR is only one piece of the whole detection and response puzzle. It’s great but it has limited reach, as it only collects data on the endpoints. To have integrated visibility across multiple security vectors is a top-priority item on any SOC’s to-do list. And XDR ticks that box”, says Dhanya Thakkar, senior vice president for AMEA. “There has been tremendous demand from our customers in the region for XDR capabilities since last year. Now they will be able to have the full XDR experience.”  

“XDR gives us an additional dimension in threat detection - it allows for faster correlation of endpoints events to related services, such as network and email, to help us quickly identify entry point and the spread of infection visually. This is a tremendous boost to the efficiency of our incident response teams”, shares Ian Loe, Senior Vice President, Cybersecurity, Infrastructure & Performance Architecture, at NTUC Enterprise Co-operative Limited.  

Trend Micro’s XDR is recently named by Forrester as a Leader in enterprise detection and response, and achieved the highest initial detection in the MITRE ATT&CK Framework.  

Wednesday, July 29, 2020

Tech Mahindra and Hinduja Group’s CyQureX Sign a Global Strategic Partnership

Tech Mahindra, a leading provider of digital transformation, consulting, and business re-engineering services and solutions, announced a global strategic partnership with Hinduja Group’s CyQureX, a leading provider of advanced Cyber Security solutions world-wide, with a view to offer world class cyber security solutions in support of clients through successful digital transformation.  

The strategic partnership will enable the organizations to become leaders in the emerging ‘Zero Trust’ environment, leveraging CyQureX’s core SDP (Software Defined Perimeter) technology and solutions, alongside Tech Mahindra’s strategic focus on cybersecurity and other next generation technologies. The partnership will enable Global customers to have access to state-of-the-art cyber security protection for Data Assets across the entire life cycle i.e “Data in Motion”, “Data in Use” and “Data at Rest”.

With decades of consulting and digital transformation expertise, Tech Mahindra will provide consulting, planning, designing, integration, orchestration and automation of services. CyQureX, which represents a new and critical business vertical of the well diversified, multimillion dollar turnover transnational Hinduja Group, with research and development centers in India and USA and offices spread across USA, Europe/United Kingdom, Middle East and India, will prioritize capabilities in the ‘Cyber Security domain - the new middleware of the future’.

CP Gurnani, Managing Director and Chief Executive Officer, Tech Mahindra, said, “Organisations have accelerated their digital transformation journey to emerge stronger and smarter from the current crisis. As a global leading provider of digital services, Tech Mahindra is committed towards leveraging new-age technologies to unleash new business opportunities and experiences for our customers and partner ecosystem through strategic partnerships and world class solutions. We see cybersecurity not only as an essential service but as a key business differentiator for our clients. The partnership with Hinduja Group’s CyQureX aligns with our core business proposition, and will further strengthen our position as the cybersecurity partner of choice for our customers globally.

GP Hinduja, Co-Chairman, Hinduja group is of the view that “This partnership is a game changer in the cyber security domain. It brings the leading security services company Tech Mahindra, and our newest technology company, CyQureX, together to create a highly secure, agile and resilient digital world. I am extremely delighted to see this strategic partnership formed, as it is in line with one of the core principles of our founder, Partnership for Growth. With rapid transformation of business to digital, we believe cybersecurity will be the cornerstone to protect all digital assets, particularly for digital transformation of India and other geographies. We are committed to develop many more indigenous state-of-the-art cyber security products and technologies in the coming years, with a vision to be a major global player in the emerging cyber security solutions market”.

“I am very excited about the alliance with Tech Mahindra” observes M.K.Narayanan, Executive Chairman of CyQureX, a Former National Security Advisor and Special Advisor on Intelligence and Security to the Prime Minister of India.  “This is a critical alliance and I am hopeful that it will be the catalyst to leverage next generation technologies like Cyber Security, Artificial Intelligence, Blockchain and create Cyber Security platforms to protect businesses, critical infrastructure and government. It promises to take digitalisation to the next level, providing clients across the globe with fully integrated cyber security solutions.”

The strategic partnership between Tech Mahindra and Hinduja Group’s CyQureX  will not only provide affordable protection to critical data, and defend nations against ‘stealth offences’, but would provide Cyber Security solutions for agile deployment that are critically important for business continuity, competitiveness and flexibility. Together, given TechMNxt charter, which focuses on leveraging next-generation technologies, and Hinduja Group’s CyQureX as a leading provider of cyber security solutions, exciting new opportunities have become available in the arcane world of Cyber security. Simultaneously, Tech Mahindra and Hinduja Group’s CyQureX will work towards Product Development, Consulting Services and Delivery in the Cyber Security space.

About CyQureX

Established in 2017, CyQureX is a cyber security solutions provider headquartered in London, UK. A Hinduja Group company, CyQureX focuses on design, development and delivery of next generation cyber security portfolio and services. Providing Software defined perimeter based network security solutions to a diversified set of industries such as banking, engineering and financial institutions.

About Hinduja Group

The Hinduja Group is one of India’s premier diversified and transnational conglomerates. Employing nearly a 150,000 employees, with presence across 38 countries it has multi-billion dollar revenue. The Group was founded over a hundred years ago by Shri P.D. Hinduja whose credo was "My duty is to work so that I can give."

The Group owns businesses in Automotive, Information Technology, Media, Entertainment & Communications, Banking & Finance Services, Infrastructure Project Development, Cyber Security, Oil and Specialty Chemicals, Power, Real Estate, Trading and Healthcare. The group also supports charitable and philanthropic activities across the world through the Hinduja Foundation.

Tuesday, July 28, 2020

What COVID-19 Means for the Data Breach Landscape?


A three-month analysis on the possible impact of COVID-19 on the data breach landscape has shed light on an increasing number of threat actors worrying cyber-security specialists.  The Verizon Business study reviewed 474 data breach incidents from March – June 2020 based on contributor data, publicly disclosed incidents and Verizon’s own observations drawn from its collective years of experience. It focuses on 36 confirmed data breaches which were identified as being related directly to the COVID-19 pandemic. 

“ In view of the COVID19 pandemic,  many large and small organisations have adopted new technologies such as software- as-a-service (SaaS) solutions, increased cloud-based storage and the use of third-party vendors in record time to continue to support their customers. While the  SaaS solutions mentioned above, or the cloud itself, are not inherently less secure, however the  concern arises from the fact that due to the conditions the pandemic has created, most organizations are adopting them in a hurried fashion, and they are often forced to do so while relying on fewer resources in terms of both personnel and revenue thereby multiplying the risk.. ” said Prashant Gupta, Head of Solutions, Verizon Business.  

The analysis has thrown up an increasing number of commonly seen threat actors, which include: 

Increase in Error -- The Verizon Business 2020 Data Breach Investigations Report (DBIR) outlined that almost a quarter of all breaches were due to human error and this trend continues during the pandemic. This is due in part to organizations operating with a reduced number of staff due to illness, redundancies and/or with staff who have limitations due to their remote status. At the same time, these organizations are often experiencing unusually heavy workloads with a much higher reliance on new and unfamiliar solutions that need to be deployed quickly. 

Stolen credential-related hacking -- The DBIR shows that over 80 percent of breaches within the hacking category are caused by stolen or brute­ forced credentials. During the pandemic, this is now being exacerbated by the large number of employees working from home and the maintaining external workstations for remote access, leaning on SaaS platforms. Business IT departments are being challenged to secure company assets on the corporate network while the majority of the workforce is out of the office. 

Phishing -- In order to utilize stolen credentials, an attacker must first be able to obtain them and phishing remains one of the most commonly used methods. Prior to COVID-19 the 2020 DBIR flagged that credential theft and social attacks such as phishing and business email compromises were at the root of the majority of breaches (over 67 percent) and this trend has continued. Specific terms in combination with "COVID" or "CORONAVIRUS," such as "masks," "test," "quarantine" and "vaccine” were found to be widely used within the time period. In March, a phishing simulation, conducted by a DBIR contributor, performed on approximately 16,000 people found that almost three times as many people not only clicked through a phishing link, but also provided their credentials to the simulated login page.  

“Businesses need to start taking far greater responsibility in protecting their technology infrastructure. From deploying more robust security protocols to ensuring timely data breach disclosure policies. Once you lose public confidence, gaining that credibility back can often be an uphill task”, said Dr Zaki Qureshy, Founding Father, Hyderabad Security Cluster. 

Verizon Business 2020 Data Breach Investigations Report 

The Verizon Business 2020 Data Breach Investigations Report, analysed 32,002 security incidents, of which 3,950 were confirmed breaches; almost double the 2,013 breaches analysed last year. These cases came from 81 global contributors from 81 countries including the Government of Telangana and the Hyderabad Security Cluster.  

Thursday, July 16, 2020

Trend Micro Research Discovers Botnet Battle for Home Routers


Trend Micro Incorporated, a global leader in cybersecurity solutions, today released new research warning consumers of a major new wave of attacks attempting to compromise their home routers for use in IoT botnets. The report urges users to take action to stop their devices from enabling this criminal activity.

There has been a recent spike in attacks targeting and leveraging routers, particularly around Q4 2019. This research indicates increased abuse of these devices will continue as attackers are able to easily monetize these infections in secondary attacks.

"With a large majority of the population currently reliant on home networks for their work and studies, what's happening to your router has never been more important," said Jon Clay, director of global threat communications for Trend Micro. "Cybercriminals know that a vast majority of home routers are insecure with default credentials and have ramped up attacks on a massive scale. For the home user, that's hijacking their bandwidth and slowing down their network. For the businesses being targeted by secondary attacks, these botnets can totally take down a website, as we've seen in past high-profile attacks."

Trend Micro's research revealed an increase from October 2019 onwards in brute force log-in attempts against routers, in which attackers use automated software to try common password combinations. The number of attempts increased nearly tenfold, from around 23 million in September to nearly 249 million attempts in December 2019. As recently as March 2020, Trend Micro recorded almost 194 million brute force logins.

Another indicator that the scale of this threat has increased is devices attempting to open telnet sessions with other IoT devices. Because telnet is unencrypted, it's favored by attackers – or their botnets – as a way to probe for user credentials. At its peak, in mid-March 2020, nearly 16,000 devices attempted to open telnet sessions with other IoT devices in a single week.

This trend is concerning for several reasons. Cybercriminals are competing with each other to compromise as many routers as possible so they can be conscripted into botnets. These are then sold on underground sites either to launch Distributed Denial of Service (DDoS) attacks, or as a way to anonymize other attacks such as click fraud, data theft and account takeover.

Competition is so fierce that criminals are known to uninstall any malware they find on targeted routers, booting off their rivals so they can claim complete control over the device.

For the home user, a compromised router is likely to suffer performance issues. If attacks are subsequently launched from that device, their IP address may also be blacklisted – possibly implicating them in criminal activity and potentially cutting them off from key parts of the internet, and even corporate networks.

As explained in the report, there's a thriving black market in botnet malware and botnets-for-hire. Although any IoT device could be compromised and leveraged in a botnet, routers are of particular interest because they are easily accessible and directly connected to the internet.

Trend Micro makes the following recommendations for home users:

Make sure you use a strong password. Change it from time to time.
Make sure the router is running the latest firmware.
Check logs to find behavior that doesn't make sense for the network.
Only allow logins to the router from the local network.

Friday, June 26, 2020

ICICI Lombard Introduces Cyber Insurance Cover for Individuals


In these unprecedented times owing to the COVID-19 crisis, remote working has become the new normal. Since the lockdown was announced, like everywhere else, S. Mohan’s company too announced remote working. Before everything shut down, Sameer wanted to buy a laptop, since his device was faulty. He kept browsing different websites to find a good deal for the new laptops. One day, he got a mail offering an unbelievable deal on his favorite brand.  However, buying the laptop needed his credit card information. Since the website offered home delivery within 48 hours (even in the lockdown) he made an impulsive purchase through his credit card. Next morning Mr. Mohan woke up to a message from his bank stating that he has surpassed his credit card limit which was around INR 3, 00,000. When he opened the mail again, the ‘page was not found’. It then dawned upon Mr. Mohan that he has fallen prey to online fraud. He had lost approx. INR 3, 75,000 in a single night. He could do nothing about it as he did not have any protection to see him through.

To help customers overcome such tragedies, ICICI Lombard General Insurance, India's leading private sector non-life insurance company, announced the launch of its Retail Cyber Liability Insurance policy. This policy offers complete protection to individuals and their families against any cyber frauds or digital risks that could result in a financial or reputational loss. The retail cyber insurance product is a form of insurance that protects individuals against losses that individually vary from online theft to unauthorized transactions.

India is one of the most prominent digital markets, with a vast potential for exponential growth. Data shows on a country level; we have over  560 mn internet subscribers and over 350 mn social media users. India is the second-largest App Market by Download and has over 180 Mn+ e-commerce users. When it comes to phone-based transactions, we have over INR 1 Trillion UPI transactions.  This lays the ground for a huge potential for cyberattacks. Undoubtedly, and this opportunity is followed by the menace of cyber risks and frauds which, too, have been growing considerably. Research shows that:

* Cyber-attacks have soared 86% in the four weeks roughly between March and April & overall 37% in first quarter of 2020
* Hackers based in China attempted over 40,300 cyber-attacks on India in 3rd week of week of June, mostly covid-19 based scams. The attacks aimed at causing issues such as denial of service, hijacking of Internet Protocol and phishing
* Rs 1.24 trillion is the amount lost in India in the past 12 months due to cybercrime.
* 131.2 million is the number of cybercrime victims in India in 2019 & 63% of them were impacted financially

According to the Internet Crime Report for 2019, released by FBI's Internet Crime Complaint Centre (IC3), India ranks third among the top 20 countries that are victims of cybercrimes. Going by this data, we are at a high risk of exposure, and personal cyber insurance seems the only respite.

The company's product is designed to secure the digital world against losses in the event of a cyberattack. The coverage will include protection against:

* Identity theft
* Cyber-bullying
* Cyber extortion
* Malware intrusion
* Financial loss due to unauthorized and fraudulent use of bank account, credit card and mobile wallets
* Legal expenses arising out of any covered risk

ICICI Lombard has Innovated by Covering Newer Threats Such As

* Reputation injury - all the expenses incurred in restoring digital reputation with means of removal of the harmful publication from the internet can also be claimed.
* Individual lost wages – if someone loses wages that would have been otherwise earned, for the time necessarily taken off from work to rectify facts arising out of any covered risk can also be claimed

The policy can be purchased at an affordable rate by all digitally active individuals. The premium ranges from INR 6.5 per day to INR 65 per day. The Sum Insured for the cover ranges from INR 50,000 to INR 10,000,000 as opted by the policyholder. The policy provides coverage to the entire family, including children for a duration of 1 year.  

Speaking on the launch, Sanjay Datta, Chief - Claims, Underwriting and Reinsurance said, "We are living in a digital world where data is being engendered, transmitted and deposited every nanosecond. Today, data is gold. And, to protect it, is paramount. While we live a digital life, the risks of cyberattacks have also grown exponentially. Our new product comes at an opportune moment when everybody is working remotely, using social media and net banking and is digitally active. The product is designed to protect individuals against the dangers that come with the connected life like cyber-bullying, identity theft and more. The policy asserts the company's pledge to provide innovative new-age risk solutions to our customers while protecting their reputation, prospective data breaches and losses in case any vital information is stolen or abused."

ICICI Lombard's commitment to providing the best for its consumers reflects through these offerings and more which ensure that the policyholders are stress-free while they work from home and even after. True to its ethos of "Nibhaaye Vaade" (Keeping Promises), ICICI Lombard always aims at being ahead of the curve to provide the customers with innovative and unique products against the new risks.

For more information on the policy and the full range of ICICI Lombard’s Insurance portfolio please visit the website www.icicilombard.com for further details on risk factors, exclusions, terms and conditions.

About ICICI Lombard General Insurance Company Ltd

We are the largest private sector non-life insurer in India based on gross direct premium income in fiscal 2020 (Source: IRDAI). We offer our customers a comprehensive and well-diversified range of products, including motor, health, crop, fire, personal accident, marine, engineering and liability insurance, through multiple distribution channels. 

Tuesday, March 31, 2009

Internet rip-offs causes $265 million loss

Internet-based rip-offs jumped 33 percent last year over the previous year, causing a loss of $265 million to the victims, with the fifth largest number of complaints coming from India, according to a new report.

Americans filed 275,284 reports (92.4 percent), claiming to be ripped off on the Internet, the highest number reported since the Internet Crime Complaint Centre, a partnership of the Federal Bureau of Investigation (FBI) and the National White Collar Crime Centre, began keeping statistics in 2000.

Canada came a distant second with 1.77 percent complaints followed by Britain (0.95 percent), Australia (0.57 percent) and India 0.36 percent.

"This report illustrates that sophisticated computer fraud schemes continue to flourish as financial data migrates to the Internet," said Shawn Henry, the FBI's assistant director of the cyber division.

At $265 million the total dollar loss from such crimes was $26 million more than the price tag in 2007, the Centre said. For individual victims, the average amount lost was $931.

The dollar loss has been on a steady increase since 2004, while the number of cases referred to law enforcement has decreased steadily since that same year.

Henry said the figures show the need for computer users, in businesses and in homes, to be wary and use sound security practices while using the Internet.

The centre said the top three most frequent complaints were about merchandise that wasn't delivered or payment that wasn't received, Internet auction fraud and credit/debit card fraud. Other scams include confidence frauds such as Ponzi schemes, cheque fraud, the Nigerian letter fraud and identity fraud.

One popular identity fraud scam used during 2008 involved sending e-mails crafted to appear as if they had been sent by the FBI. Sometimes the scammers went so far as to say the mailings were from FBI Director Robert Mueller himself, according to the centre.

The e-mails would ask the recipient for personal information, such as a bank account numbers, claiming the FBI wanted the information to look into an impending financial transaction.

One variation of the scheme, according to the centre, was to send an e-mail saying the recipient is entitled to lottery money or an inheritance and the funds can be moved as soon as bank account information is supplied.

The FBI has issued warnings about such scams in the past and Monday's report included a new one: "The FBI does not contact US citizens regarding personal financial matters through unsolicited e-mails."

Agencies

Total Pageviews