Popular password managers found to have serious flaws


Clare Hopping

21 Feb, 2019

Security researchers have revealed that some of the most popular password managers around are also the most vulnerable, allowing hackers to break in and steal information as easily as they would be able to if the information was stored in a text file.

Independent Security Evaluators (ISE) tested a range of password managers – those embedded in browsers and also paid-for software that claim to stop people from being able to steal passwords. It found that every single tool could be broken into and so failed to sufficiently protect information as claimed.

“Although password managers provide some utility for storing login/passwords and limit password reuse, these applications are a vulnerable target for the mass collection of this data through malicious hacking campaigns,” ISE chief executive Stephen Bono said.

The company looked in detail at 1Password, Dashlane, KeePass, and LastPass to see how robust they were at securing users from having their credentials stolen. They all work in the same way – “securely” storing passwords so users are able to keep track of their different credentials across services from one place.

However, every single application had “serious” vulnerabilities, including ease of stealing the master password used to protect the others from prying eyes. Access to the master password means all other passwords stored can be easily obtained, making these platforms pretty useless in terms of their core purpose. 

All four password managers can be hacked when in the background running state when they’re locked by the master password, which is the most common way the applications are used. However, the most recent version of 1Password and Dashlane can be broken into and all passwords leaked while in both the locked and unlocked state. All four password managers could be intercepted using keylogger malware.

“People believe using password managers makes their data safer and more secure on their computer,” added ISE executive partner Ted Harrington. “Our research provides a public service to vendors of these widely-adopted products who must now mitigate against attacks based the discovered security issues, as well as alert consumers who have a false sense of security about their effectiveness.”

ISE recommends that users properly shut down their password managers when they’re not in use.

«Password managers are an important and increasingly necessary part of our lives. In our opinion, users should expect that their secrets are safeguarded according to a minimum set of standards that we outlined as ‘security guarantees’. Initially our assumption and expectation were that password managers are designed to safeguard secrets in a ‘non-running state’, which we identified as true. However, we were surprised in the inconsistency in secrets sanitisation and retention in memory when in a running unlocked state and, more importantly, when placed into a locked state,» ISE concluded in its research. 

«If password managers fail to sanitise secrets in a locked running state then this will be the low hanging fruit, that provides the path of least resistance, to successful compromise of a password manager running on a user’s workstation.

«Once the minimum set of ‘security guarantees’ is met then password managers should be re-evaluated to discover new attack vectors that adversaries may use to compromise password managers and examine possible mitigations for them.»

The cloud in 2020: Enterprise compatibility with edge computing, containers and serverless

In the future, as we speed down the motorway in our self-driving vehicles, historians will mark the 2010s as the decade of the cloud. Some would argue that the tenets of cloud computing were established in the 1960s, when U.S. government scientist J.C.R. Licklider planned an “intergalactic computer network”. In 2006 the cloud experienced a seminal moment, when Amazon entered the space with EC2. However, it is in the 2010s that cloud forged its role as the transformational technology of its generation.

The majority of leading brands embraced the cloud; and even the Central Intelligence Agency in the U.S. made the move in 2013. Some of the largest digital businesses in the world, Facebook, Netflix, Amazon, are not only cloud native, but achieved huge success because they chose that model.

In 2010 Amazon Web Services, Microsoft and Google – three leading lights of the cloud – had all launched their cloud businesses. The same year OpenStack, the leading open-source software platform for cloud, started as well. Worldwide spending on the public cloud started the decade at $77 billion, according to Statista, and was predicted to conclude it at $411 billion – a fivefold increase. Remarkable momentum, given that the cloud was still in its infancy. In the coming years, the development of business and consumer applications will accelerate from cloud enabled to cloud native – as exciting new cloud technologies flourish. Even the definition of what cloud means is changing, with the addition of edge and hybrid environments.

The world shifts too rapidly to make consistent predictions about the future; but commanding trends are at work and moulding the cloud as we head towards 2020.   

Enterprises finalise transition to public cloud

Despite the hype around the cloud, not every business has made the jump. According to Forrester: “Cloud's impact has been global, yet fewer than half of all enterprises use a public cloud platform. Yet recent research from 451 Research has shown that it is the financial services industry who is leading in terms of adopting cloud technologies. Faced with the agility from cloud native disruptors and increased competition, 60% of financial services companies surveyed said they expect to use various cloud platforms in combination with one another – slightly higher than the number for other businesses (58%).

Edge is not the end of cloud computing – but a natural evolution that will see telcos, manufacturers and more employing it as the new decade dawns

Indeed, as a McKinsey survey noted, even many companies that have adopted the cloud are far from complete operation in it: “While almost all respondents are continuing to build sophisticated cloud programs, there is a clear gap between the leaders (those who have migrated more than 50% of their processing workloads) and the laggards (those who have moved less than 5%)”.

A common concern putting businesses off employing an enterprise cloud computing strategy is security. Two-thirds of IT professionals state that security is their greatest concern in this respect, according to a study by LogicMonitor. As the decade draws to a close, the industry will seek to strengthen cloud security. Solutions to address compliance and data control needs will trigger adoption from those companies that are still holding out. Indeed, solutions that answer questions around data, as opposed to compute needs, will dictate who provides the most compelling answers for the enterprise.

The responsibility for security rests mostly with the customer though; and increasing amounts are deploying cloud visibility and control tools to lower security failures, according to the analyst firm. Strides in machine learning, predictive analysis and artificial intelligence will accelerate the number of large-scale, highly distributed deployments – as they become more feasible and secure to manage. Foolproof security does not exist in any computing environment. Nevertheless, increasing numbers of businesses will feel safer working with the cloud, triggering higher adoption rates by 2020; preparing the path for nearing total adoption in the following decade.

The cloud reimagined by edge computing

Consider cloud computing and typically centralised data centres, running thousands of physical servers, come to mind. However, this vision misses one of the greatest new opportunities for cloud – distributed cloud infrastructure. As businesses find themselves requiring near-instant access to data and compute resources to serve customers, they are increasingly looking to edge computing.

Edge computing directs certain compute processes away from centralised data centres to points in the network nearer to users, devices and sensors. IDC describes it as a “mesh network of micro data centres that process or store critical data locally and push all received data to a central data centre or cloud storage repository, in a footprint of less than 100 square feet”.

This environment is very valuable for the Internet of Things (IoT), with its requirement to collect and process vast amounts of data in near-real-time, with a very low level of latency. It can lower connectivity costs by sending only the most important information, as opposed to raw streams of sensor data. For example, a utility with sensors on field equipment can analyse and filter the data prior to sending it and taxing network and computing resources.

Edge is not the end of cloud computing, but rather a natural evolution that will see telcos, manufacturers and many organisations employing it as the new decade dawns.

Containerisation continues

Containers, which enable developers to manage and easily migrate software code, have become very popular. That is not going to change over the coming decade. Forrester estimates that a third of enterprises are testing containers for use in production; while 451 Research forecasts that the application containers market will grow 40% annually to $2.7 billion in 2020. 53% of organisations are either investigating or using containers in development or in production, according to a Cloud Foundry report.

The majority of businesses are leveraging containers to enable portability between cloud services from AWS, Microsoft Azure and Google Cloud as they firm up their DevOps strategies for more rapid software production.

Kubernetes is making waves in container deployment, by using operating-system-level virtualisation over hardware virtualisation. Vendors delivering pragmatic answers without getting caught up in the craze will achieve meaningful market penetration. The hype around containerisation is going to translate into widespread adoption as the decade turns.

Serverless computing grows in popularity

For some time organisations have developed applications and deployed them on servers. With serverless computing, a cloud provider manages the code execution, executes it only when required and charges it only when the code is running. With this model, businesses no longer have to worry about provisioning and maintaining servers when putting code into production. (“Serverless” is a somewhat misleading term, as applications still run on servers).

Serverless computing is not going to be an overnight sensation, but more of a natural route taken when usage increases over time

Serverless computing came into being back in 2014 at the AWS re:Invent conference, with Amazon Web Services’ announcement of Lambda and has recently gotten further traction with open source project Firecracker. Serverless computing, potentially, is a very big development, with one caveat. Not everyone is going to be ready for it. Going serverless requires an overhaul of traditional development and the production paradigm. In effect, it’s outsourcing entire pieces of infrastructure. In fact, it’s everything apart from the app itself.

This will mean that serverless computing is not going to be an overnight sensation, but more of a route taken when usage increases over time. While existing solutions usually lock customers into a specific cloud provider, the arrival of open source solutions in this space will accelerate and broaden the portfolio of implementations of serverless computing across the industry.

Open source continues its reign

Open source enterprise software has never been more popular. An increasing number of organisations are introducing open source software into their processes and even building entire businesses around it. Black Duck Software’s 2017 survey of executives and IT professionals identified that 60% of respondents reported that their company’s use of open source increased over the previous year. Two-thirds of the businesses surveyed contribute to open source projects. The cloud has ensured that the open source ecosystem is thriving, relying on a large range of open source DevOps tools, aggressive use of build automation and infrastructure platforms, like OpenStack and Kubernetes, unlocking application delivery in the cloud.

As cloud adoption increases, open source technologies will carry on boosting innovation for the rest of the 2010s and beyond. Cloud domination has been a staple of this decade and with such several exciting trends shaping it, it certainly seems the best days for cloud computing are still yet to come.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Support for Multi-Cluster Kubernetes Applications | @KubeSUMMIT @Rancher_Labs #CloudNative #Serverless #DevOps #AWS #Kubernetes

Applications with high availability requirements must be deployed to multiple clusters to ensure reliability. Historically, this has been done by pulling nodes from other availability zones into the same cluster. However, if the cluster failed, the application would still become unavailable. Rancher’s support for multi-cluster applications is a significant step forward, solving this problem by allowing users to select the application and the target clusters, providing cluster specific data. Rancher then initiates deployment to those clusters.

read more

Multi-Cloud Kubernetes Solution for Healthcare | @KubeSUMMIT @ClearDataCloud #CloudNative #Serverless #Docker #Kubernetes

With the new Kubernetes offering, ClearDATA solves one of the largest challenges in healthcare IT around time-to-deployment. Using ClearDATA’s Automated Safeguards for Kubernetes, healthcare organizations have access to the container orchestration to dynamically deploy new containers on demand, monitor the health of each container for threats and seamlessly roll back faulty application updates to a previous version, avoid system-wide downtime and ensure secure continuous access to patient data.

read more

Google acquires Alooma to bolster cloud migration efforts


Rene Millman

20 Feb, 2019

Google has announced plans to buy cloud migration company Alooma in a bid to boost its cloud migration capacities.

In a blog post, Amit Ganesh, vice president  of engineering at Google, said that the addition of Alooma, subject to closing conditions, “is a natural fit that allows us to offer customers a streamlined, automated migration experience to Google Cloud, and give them access to our full range of database services, from managed open source database offerings to solutions like Cloud Spanner and Cloud Bigtable”.

“This simplified migration path also opens the door for customers to take advantage of all the technologies we have to offer, including analytics, security, AI and machine learning,” he said.

Alooma was founded in 2013 and specialises in Extract, Transform, Load (ETL) applications. This enables users to pull in data from many sources, including Oracle, Azure, and SaaS providers such as SalesForce and mapping this data to data warehouses such as Redshift and BigQuery.

The deal would bring ETL services to Google Cloud. Amazon and Microsoft have ETL services in the form of Azure Data Factory and AWS Glue.

In a blog post, Yoni Broyde and Yair Weinberger, co-founders of Alooma, said the acquisition is the evolution of their company’s long-standing partnership with Google Cloud.

“It follows several native integrations, over the years, from Google Ads and Analytics to Cloud Spanner and BigQuery,” they said.

“We believe that as part of Google Cloud — bringing together the best-in-class data migration and integration services — we can make our customers and partners even more data-driven and successful.”

The co-founders added that the move would bring the company closer to delivering a full self-service database migration experience bolstered by the power of their cloud technology, including analytics, security, AI, and machine learning.

The terms of the deal were not disclosed nor was a date for when the acquisition will be finalised.

Four reasons why your company might not be ready for DevOps just yet

Let’s get one thing straight: I’m a huge fan of DevOps. It has been shown to increase quality, reduce problems, and shorten development cycles. It’s often considered a panacea for large organisations looking to transform their development, production and operational lifecycles. But is it right for every business? Companies that do it successfully can reap the benefits of continuous deployment and testing, but companies that fail get trapped in endless loops of missed deadlines.

There are some criteria that any IT team should investigate before making the transformational shift to CI/CD. It involves taking a hard look at the existing culture, process, and even management style. There’s no shortage of ink spilled on articles that try to convince you why DevOps is the future. Instead, I want to focus on when and why DevOps doesn’t work to truly help identify if it’s right for you.

Is the culture ready?

Because the transformation to DevOps is simultaneously a change in process, tools, and philosophy, it requires a cultural shift in collective mindset that’s fraught with potential failure. DevOps success relies on three Cs: communication, collaboration, and coordination between different teams (including software developers, quality, operations teams, and executive stakeholders). The first challenge is to understand and unpack how these groups are aligned and interrelated. Then, the executive leadership must develop a working model of communication between them with incremental milestones to gradually shift culture toward more openness and connectivity.

If your business is too siloed or relies on legacy organisational structure, chances are good that this cultural shift may prove to be too difficult. I’ve seen it often fail in large organisations with entrenched leadership or processes. Some companies could be hundreds of years old, while others could be the latest and greatest modern organisations that are simply stuck in their existing ways. And if the culture won’t change, then the actual DevOps process is ultimately doomed.

Can the structure handle it?

DevOps is highly culture-dependent, but it also requires a shift in how software is architected, built, tested and deployed. At first, this may seem like common sense, but in reality, it’s often not discussed during the transition.

Monolithic software architecture with complex dependencies between different layers and teams can cause a DevOps evolution to struggle and fail. Often, quality is sacrificed in the name of agility and speed. Organisations using a modern, cloud-native microservices architecture are typically more successful in adopting a DevOps practice. In these organizations, product or service teams can operate independently while staying aligned toward the ultimate business goals or customer experience objectives. The company is already broken into purpose-built sprint pipelines that can move with agility.

Where to begin? Identify the warning signs

Before building your DevOps roadmap, it’s critical to spend some quality time soul-searching and stress testing your organisational culture. If you see any of these, you might face some steep uphill challenges in your evolution:

  • Your company has a well-defined process: Companies that are already in love with their culture and software development process will cling to it with white knuckles. These companies resist change and might not fit the DevOps profile
  • Your company wants to dive in head first: If your company just wants a DevOps process because it’s trendy and innovative, you might not be ready for it. Proper implementations require a true understanding of business outcomes with pros and cons. Remember, it’s a mindset, not just a movement
  • Your company wants a “department of DevOps”: Trying to create DevOps as a separate department, without bringing current Dev and Ops teams together, is a recipe for failure. DevOps isn’t a side hustle. It’s transformational
  • Your company has fiefdoms: Organisations whose Development and Ops teams are highly distributed and isolated from each other could struggle to bring them together without providing each team with some common leadership.

In short, DevOps must become the culture of the organisation, driven by the CEO and his/her team of functional and organisation leaders with a clear understanding of the implications and outcomes. It’s a mindset that requires a transformation in process, organisation, technology, and information to drive a meaningful, sustainable change. The rewards are huge. But as with any potential upside, your company will have to work for it.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Google Cloud acquires Alooma to bolster enterprise data migration capabilities

Google Cloud chief executive Thomas Kurian promised an aggressive approach to enterprise cloud strategy going forward – and the company has immediately put its money where its mouth is with the acquisition of California and Tel Aviv-based startup Alooma.

Alooma aims to solve a key problem for enterprise organisations in their move to the cloud by offering a single data pipeline which is able to crunch data from various sources, from Snowflake, to Google-tied BigQuery, Azure and Amazon RedShift, to provide real-time insights.

The company, which had received around $15 million across three funding rounds during its tenure, had previously been a long-term partner of Google with several native integrations, from Google Ads and Analytics to database service Cloud Spanner, not to mention BigQuery. Its roster of customers includes OkCupid, Sony, and The New York Times, which already uses Google App Engine for its gaming platform, having moved from Amazon Web Services (AWS) in 2017.

In a letter to Alooma’s customers and partners, published on the company’s blog, founders Yoni Broyde and Yair Weinberger noted the evolutionary nature of the acquisition. “The journey is not over,” Broyde and Weinberger wrote. “Alooma has always aimed to provide the simplest and most efficient path toward standardising enterprise data from every source and transforming it into actionable intelligence.

“Joining Google Cloud will bring us one step closer to delivering a full self-service database migration experience bolstered by the power of their cloud technology, including analytics, security, AI, and machine learning,” they added.

From Google’s perspective the acquisition focuses on three primary areas; the need for open source, the continued enterprise push, as well as bolstering its Israel presence. Writing in a blog, VP engineering Amit Ganesh and director of product management Dominic Preuss noted parallels with Google’s acquisition of cloud migration provider Velostrata last year, which ticked all three boxes.

Earlier this month, Kurian told delegates at a Goldman Sachs conference of his vision for the company and how its cloud offering differs from the likes of AWS and Azure. These were, in order, security and reliability for mission critical applications; hybrid and multi-cloud; ‘very advanced’ AI solutions; ‘vastly different’ capabilities for managing data at scale; and ‘integrating a number of Google’s technology advances with cloud to deliver industry solutions.’

The proposed acquisition of Alooma certainly focuses on managing data at scale, as well as promised initiatives around AI and machine learning – so watch this space.

Financial terms of the acquisition were not disclosed.

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.

Why DevOps is the future of your business

21 Feb, 2019

If you’ve spent any time at all in the IT world, you’ll likely have heard about DevOps and how it’s the future of enterprise software development. Companies both large and small have adopted DevOps processes and methodologies as part of their organisation, chasing faster development cycles and greater application stability.

For the uninitiated, DevOps is a software development method that involves merging development and operations teams together. The goal is to shorten the time it takes to build, patch, and update software by monitoring and testing it as it’s being built. This allows problems to be caught earlier, leading to a shorter time-to-market.

Multiple advantages

DevOps has a number of advantages over traditional software development approaches like the waterfall method. The first and most obvious is speed; DevOps can radically accelerate development cycles, which means software can be delivered to users faster.

“Reducing the time between inception and value when delivering services is the key benefit,” says Guy Smith, CDW’s head of technology solutions. “In addition, bringing application developers closer to the operational challenges of running a live system can provide a useful feedback loop that results in applications that are designed to be operated, with consideration for proper abstraction, state handling, failure tolerance, and simple scaling.”

Because it’s also based around smaller and more frequent releases, users can also get used to new changes gradually, rather than having to acclimatise to lots of new things at the same time. It’s also easy to roll back to a previous version in the event of an unexpected bug and ensures that fixes for said bug can be issued faster. This shouldn’t be required that often, though, as DevOps generally has a lesser failure rate than waterfall development.

In many ways, DevOps is the cornerstone of digital transformation. Among the most common goals of a digital transformation project is for the company to become software-driven, with an agile approach to both its strategy and its IT, and DevOps is essential for all of those goals. Without being able to rapidly iterate on the software and apps that a business creates, it can’t be truly agile or software-driven, as it will constantly be behind the curve and slowed down by clunky, outdated methodologies.

Many major organisations have already embraced DevOps as a way to speed up their software pipelines; Companies like Hertz, American Airlines, Accenture and more have all implemented DevOps methodologies, using them to drive greater efficiencies, faster workloads and more frequent releases.


‘Digital Disruption’ dives into the findings of a roundtable with industry experts about the future of technology in the workplace, and looks at the strategies needed to thrive in an era of unprecedented change.

Download now


An agile world

DevOps isn’t just applicable to IT, however. It’s closely tied to the agile movement, and many of its principles are effective across the business as a whole. Take the Scrum method, for example; this framework involves taking a project-based approach to solving business challenges.

A cross-functional team is created, made up of members from every relevant area of the business. The team establishes the end goal of the project, then works towards accomplishing this goal in a short series of ‘sprints’ lasting from two to four weeks, in which a small series of tasks are devised, planned, completed and tested.

The idea is to break a project up into more manageable chunks, with regular testing and monitoring throughout the process. Although this is generally applied to software development, it can be equally suited to projects like marketing campaigns, IT refreshes or quarterly reporting efforts.

Implementing DevOps can be extremely beneficial for a business, but it can be a rather daunting undertaking too, especially for a mature, established organisation that already has a more traditional development structure in place. As with any major organisational change, it’s crucial to ensure that the implementation is meticulously planned out beforehand and carefully managed during the roll-out itself.

“Be really clear about what problem you’re trying to solve and exactly how the new model will improve service delivery to users,” Smith says. “It’s very easy to get sucked into the dogma and fashion of DevOps/Agile but it isn’t always the appropriate approach or done with the end-user in mind. In addition, clear expectations need to be set about where responsibility lies, not just with ‘make stuff live faster’ but how real world problems such as bugs, operational issues and security incidents will be dealt with at 3am.”

Are you ready for DevOps?

One of the most important elements of moving to a DevOps approach is making sure the culture and management style of the organisation is ready to support it by obtaining buy-in from all the necessary stakeholders within the business and establishing a set of guiding principles that everyone is on board with. Beyond that, however, there are a number of technical tools which comprise the foundation of a successful DevOps organisation.

Version control systems, for example, are the bedrock of DevOps. One of the most essential principles of DevOps is rapidly deploying code, testing it to see if it works and then rolling it back and trying again if it doesn’t. By using a version control system like Git, CVS or Team Foundation Version Control, this process is made infinitely easier, allowing you to easily track iterations of code and work collaboratively on them without having to manually shuffle between multiple near-identical files.

Similarly, code-sharing platforms like Github or the aforementioned TFVC are a must-have for any DevOps team. Close collaboration is essential for speedy software releases, and the ability to have an entire DevOps team collaborating simultaneously on one piece of code will make the process much, much faster. Modern code-sharing platforms will also integrate with a swathe of other tools to help speed up and automate your workflows.

Continuous integration and continuous delivery (CI/CD) tools, for example, are another essential part of the DevOps toolchain that work in concert with code-sharing platforms and version control systems. Tools, such as Jenkins, are designed to automatically assemble and test a new build of a piece of software every time a developer commits a change to the version control system. This ensures that developers working on different features don’t accidentally break each others’ work when they commit changes to the main branch, resulting in fewer bugs and faster working releases.

Another key pillar of DevOps is Infrastructure as Code. This principle involves treating the various components of infrastructure – such as VMs, networks, and so on – in the same way as the code that’s running on it. New environments are spun up according to a pre-set template using the same version control model as the code itself, which means all your environments will be identical unless expressly designed to be different.

DevOps teams will need to spin up new test environments quickly and often, and spinning them up and administering them manually can mean that, over time, you’re left with a large number of environments which are all subtly different to each other. This can often lead to deployment issues, but using Infrastructure as Code platforms like Puppet prevents this by ensuring consistency across your environment.

Every organisation is different, and building the right DevOps toolchain can be a tricky business. Working with a skilled partner, however, can dramatically reduce the complexity and hassle of implementing a DevOps structure. CDW can offer not just the toolsets you need to get your DevOps pipeline moving, but also the expert strategic guidance to help make your DevOps journey a success from the word go.

“CDW can help you navigate the challenges of delivering services quickly, cost-effectively and securely whilst focusing on user-need,” explains Smith. “We have a significant breadth and depth of products, in-house expertise and partner relationships that allow us to think ‘outcome first, approach/tool second’ and provide solutions that offer true business benefit.”

To learn more about CDW Cloud Services, download your free guide or contact CloudEnquires@uk.cdw.com

Cloud resources are increasingly targeted by cyber criminals


Clare Hopping

20 Feb, 2019

Hackers are increasingly aiming cyber attacks at cloud infrastructure, using it as an entry point to drive other attacks and relying on employees and businesses to misconfigure their infrastructure, leaving it open to attack.

That’s according to cyber security firm Symantec’s latest Internet Threat Security Report, which noted misconfigured servers and cloud infrastructure are providing tempting targets for cyber  criminals. 

«The same security mistakes that were made on PCs during their initial adoption by the enterprise are now happening in the cloud<» Symantec’s report explained. 

«A single misconfigured cloud workload or storage instance could cost a company millions of dollars or land it in a compliance nightmare. In the past year alone, more than 70 million records were stolen or leaked from poorly configured S3 buckets. There are also numerous, easily-accessible tools that allow attackers to identify misconfigured cloud resources on the internet.» 

The security company explained that hardware chip vulnerabilities, which can be found in the systems that underpin cloud infrastructure, such as Meltdown, Spectre, and Foreshadow are also exposing data to criminals.

The reason for cloud infrastructure to increasingly draw the eye of cyber criminals is that they are looking for alternative ways to generate income. as returns from ransomware and cryptojacking attacks are reducing. 

The report noted that cyber criminals are also increasingly targeting online retailers to steal customer details using methods such as formjacking.

Formjacking allows criminals to steal user card data while they’re shopping online. It involves injecting code into badly-secured checkouts on retailer websites used to steal card details.

Symantec reported that more than 4,800 unique websites are injected with malicious code used in such attacks every month and it had blocked 3.7 million attempts to use such methods to steal card details in 2018.

“Formjacking represents a serious threat for both businesses and consumers,” said Greg Clark, CEO at Symantec.

“Consumers have no way to know if they are visiting an infected online retailer without using a comprehensive security solution, leaving their valuable personal and financial information vulnerable to potentially devastating identity theft. For enterprises, the skyrocketing increase in formjacking reflects the growing risk of supply chain attacks, not to mention the reputational and liability risks businesses face when compromised.”

During 2018, Symantec revealed that the number of hackers using more traditional methods of disrupting a company’s infrastructure, such as ransomware and cryptojacking had decreased significantly in 2018.

The reasons for this, Symantec cited, was that the value of cryptocurrency has reduced significantly and more businesses are adopting mobile and cloud computing, which makes attacks “less effective”.

Exploring a data-centric approach to data privacy as cloud workloads proliferate

If your organisation, like many others, is putting more and more data into the cloud, you will already know that it’s probably making your security team have kittens. Greater amounts of data being transported in real-time – not to mention the vastly increased number of mobile devices and attack vectors – means the chances for catastrophe have proliferated.

A new study from data protection provider Virtru has looked at the steps for taking a ‘data-centric’ approach to data protection and privacy. The report, conducted by Forrester Research and which polled more than 200 director, VP and C-suite employees across security, risk and IT, argues organisations’ current IT priorities are conflicting – and that data protection is not high on the list.

Almost half (46%) of those polled said that they were adopting a data-centric approach to data protection because they were putting more and more business data into the cloud. The same number said they were particularly concerned around protecting data from cybercriminals, as well as insider theft and abuse.

When it came to the primary capabilities organisations needed to execute data-centric protection, 85% of respondents said enforcing access control was either critical or very important. Encrypting data stored in cloud drives (79%), as well as encrypting data in motion and at rest within the enterprise (79%), were also highly cited.

The key issue in putting this important approach across is prioritisation. For those polled, the key aim this year is to deliver IT projects more quickly (45%). 41% said a major aim was to better comply with privacy regulations, while shifting resources to improve the customer experience (37%) and increasing the business’ role in defining the priorities of IT investments (35%) were also cited.

Naturally, there is an impasse between those who see the need for greater productivity in the organisation and those who see greater security. 39% said they feared data privacy controls would hinder productivity, while a third (34%) said their companies lacked staff with sufficient data privacy expertise. 30% said there was confusion around the differences between data privacy and security.

Yet there are a multitude of benefits to a data-centric protection approach. Almost half (49%) of those polled said the move would improve their organisation’s ability to meet regulatory requirements, while reduction of data theft (47%) and lowered risk of data loss (47%) were also key.

“As IT organisations seek to find ways to deliver on their initiatives more quickly and with a greater focus on regulatory compliance, many struggle to keep these two objectives from conflicting with one another,” the report concluded. “To address these challenges, firms are turning to data-centric data protection solutions, while seeking to overcome challenges with costs, use, and integration that can arise with onboarding new technologies.

“Putting data security and privacy front and centre will help firms realise numerous benefits like improved customer and partner relationships and lower risk of a data incident,” it added. “Failing to properly secure your data puts customer trust, the business’ reputation, and considerable revenues and potential penalties at risk.”

https://www.cybersecuritycloudexpo.com/wp-content/uploads/2018/09/cyber-security-world-series-1.pngInterested in hearing industry leaders discuss subjects like this and sharing their experiences and use-cases? Attend the Cyber Security & Cloud Expo World Series with upcoming events in Silicon Valley, London and Amsterdam to learn more.