This content is restricted.
Month: July 2013
New Trojan could create headaches for banks, customers
This content is restricted.
Cyber threat well understood but organisations lack ‘intelligence’ to deal with it
Malcolm Marshall, KPMG partner and head of the firm’s Information Protection & Business Resilience team, said: “Increased awareness of cyber security threats is a positive trend, but indications are that organisations now need to focus on putting into place the fundamentals of intelligence management to gain real value from what they know. These revolve around creating an intelligence-led mindset within organisations, implementing an operating model similar to those employed by the intelligence community and building a decision-making process which is centred on a tightly controlled “information gathering programme”.
“Cyber threat: intelligence and lessons from law enforcement” argues that an intelligence-led mindset establishes a direct connection between the threats and vulnerabilities organisations face and the consequences of their compliance or inaction.
The report also goes on to argue that to embed intelligence-led decision-making, business leaders should follow the example set by law enforcement agencies. For example, rather than simply collating data, KPMG’s report urges organisations to set parameters for the type of information being gathered, so that haphazard approaches to analysis and actions can be avoided.
Hackers’ StealRat botnet turns 85,000 unique IPs into malware-spreading tools
This content is restricted.
HP Updates ArcSight Portfolio With Security Analytics
“Typically batch in nature, big data analytics allows an organization to organize and analyze vast amounts of structured and unstructured information to facilitate the detection of rogue employees, partners or criminal or collusive rings of fraudulent or abusive activity,” Avivah Litan, an analyst at IT research firm Gartner, said in a statement. “Adversaries only need to get it right once to invoke serious damage on an organization’s private data, ability to provide critical service or corporate reputation,” Haiyan Song, vice president and general manager of ArcSight, Enterprise Security Products for HP, said in a statement. “With solutions designed to enhance threat detection through improved security analytics for big data, HP enables customers to quickly identify potential attackers and take action proactively to minimize business impact and prevent disruption to critical client services.”
With the launch of IdentityView 2.5, HP has expanded the number of users that a single instance can monitor by 10 times, an enhancement designed to help organizations correlate security incident and event data across an expansive user base to reduce insider threat risk.
“With a mission to provide superior health care, it is critical that we prevent system disruptions that might impact patient safety or quality of care,” Keith Duemling, information security officer at Lake Health, said in a statement. “By automating threat detection across our network, HP ArcSight allowed us to move to a much more proactive approach to information security and improve our ability to detect risks that might affect overall system performance by a factor of 10.”
Link: http://www.eweek.com/small-business/hp-updates-arcsight-portfolio-with-security-analytics/
Big banks staged mega-cyberattack drill last Thursday
An employee sitting at his desk might get a prompt saying, “this bank is having integrity issues with money,” or “you cant make trades over this technical system.” The employee then might role-play talking to an FBI agent — likely an actual one enlisted to help with the drill, said Dave Aitel, CEO of the security firm Immunity, who formerly worked as a research scientist for the National Security Agency.
The financial sector is hoping to prepare itself for a massive, disruptive attack — a growing concern lately, as “hacktivists,” organized cybercriminals and government-spnosored attacks become increasingly large and successful. Though still a far-off doomsday scenario, some security industry experts say the financial sector is vulnerable to cyber-terrorists aiming to damage the U.S. economy. That’s because banks and other financial institutions have to do deal with money flows in real time, with markets hanging in the balance.
Though some skeptical security experts dismissed Quantum Dawn as a PR stunt, SIFMA said the first run was useful in uncovering flaws in the industry’s cyberattack protocols. The trade group found that banks were largely good at sharing information with one another, but bad at making real-time critical decisions for mitigating the threats.
Link: http://money.cnn.com/2013/07/18/technology/security/bank-cyberattack/index.html