securitylinkindia

Cybersecurity Trends 2018

How can businesses better protect themselves from the increasing volume and complexity of cyberattacks while preparing for the opportunities of automation and digitalization of industries – this is the burning question of the day and our goal is to raise awareness to help them address it. This article focuses where we see the most significant threats and opportunities emerging, and highlights the implications of the increasingly connected world, how global regulation is responding, the need to inject trust into cybersecurity, ways to protect ourselves from intelligent cyberattacks, and what we should do to close the skills gap in an environment starved for cybersecurity talent, yet overwhelmed by volumes of data. The leading cybersecurity experts from TÜV have forecasted eight challenges that organizations will cope with in coming times. The forcast is based on a survey of TÜV Rheinland’s leading cybersecurity experts where inputs were collected from clients in Europe, North America and Asia. Following are highlights of the 8 cybersecurity trends identified this year: Trend 1: A rising global tide of cyber-regulation increasing the price of privacy Data protection is a critical concern in an increasingly digital world and May 25, 2018 is a turning point for data protection in Europe. It marked the end of the transitional period for the EU General Data Protection Regulation (GDPR) as it becomes enforceable by law. It disrupts data governance and how information is protected for any organisation controlling or processing EU citizen personal data, and leads a growing list of emerging data protection regulations from around the globe. Data protection is a critical concern in an increasingly digital world As business undergoes digital transformation and becomes increasingly connected, cyberattacks continue to grow in both sophistication and volume. Recent highprofile cyberattacks have showed just how vulnerable organisations are. The ransomware WannaCry infected more than 300,000 computers across multiple organisations, countries, and continents in less than 48 hours. 87 million Facebook profiles harvested by political consultancy Cambridge Analytica is being dubbed one of the most consequential data breaches in history, rivalling the breach of financial records from Equifax. These attacks predict a dark future for privacy. GDPR disrupts the data governance and how information should be protected Increasingly, organisations must be able to prove that they are processing personal data in accordance with the legal requirements of this evolving regulatory environment. GDPR introduces a number of key components including extra-territorial reach over EU data, individual right, data privacy officers, notice and consent, restrictions on secondary users, privacy impact assessment, and data breach notification. These requirements are forcing organisations to rethink data governance, systems architecture, documentation and data loss prevention. Failure to comply could result in fines of up to 4% of global turnover The related business risk is material. In the event of noncompliance or contravention, the EU is envisioning sanctions amounting to four percent of the previous year’s turnover, or EUR 20m, whichever is the greater. Weaknesses in technical and organisational data security such as outdated encryption standards leave organisations vulnerable to these fines. Many organisations are underestimating the extent of such requirements Few organisations are going to be ready by the impending deadline. Most, having underestimated the extent of the requirements, are still developing their plan for GDPR compliance. Some have decided not to develop a plan, choosing instead to treat non-conformity as just another operational risk to be managed – perhaps doubting the seriousness with which the EU commission will enforce it. Others are not sure if the regulation applies. As a result, the majority of organisations are starting late with implementation. An emerging list of data protection regulations from around the globe GDPR is leading a global trend as European regulators are not alone in mandating greater accountability at the executive level. The USA, Argentina, Brazil, Switzerland, Africa, India and China – all are revising their data protection regulations. Many share similar concepts like informed user consent and data breach notification obliging organisations to notify the relevant authority and all affected data subjects when a breach occurs – an often costly exercise. Yet this also leads to fragmentation and emerging market barriers driven by territorial requirements for data protection and data flows across borders. For global organisations, this will make international operations an increasingly costly and complex challenge. Trend 2: The Internet of Things drives the convergence of safety, cybersecurity and data privacy Today, product development, time to market considerations, and technical power constraints leave IoT devices exposed by exploitation of critical vulnerabilities. The impact of data breaches now extends far beyond simple data monetization to kinetic threats to health and safety, as devices and systems are directly connected to open networks. It is widely accepted that the state of IoT security is poor and with over 500 connected devices expected to cohabit with us in our homes by 2022, these represent a major risk to safety, cybersecurity and data privacy. Mirai proved that IoT devices can be effectively weaponised as botnets On October 21, 2016 a massive Distributed Denial of Service (DDoS) attack hit DYN Inc. and temporarily disrupted much of the internet on the East Coast of the United States. It affected companies like Twitter, Spotify, Amazon, Netflix, Reddit, the Guardian, CNN, and the New York Times. Formed mainly of hacked IoT devices, the Mirai botnet was a wake-up call about the vulnerability of internet connected things to cyberattacks. Commercial and technical constraints leave IoT devices vulnerable to exploits Many IoT devices are fundamentally insecure, leaving product manufacturers and customers exposed to the inherent risk of cyberattacks. This should not come as a surprise as manufacturers are not in the business of cybersecurity. Instead, they are under increasing pressure to innovate faster than the competition, while protecting their margins. Ensuring devices are easy to produce, functional, connected and secure – while limiting power consumption to extend battery life – is a complex technical challenge leading to difficult trade-offs. Vulnerabilities often reside deep in the product software stack To save time and money, software developers use open source…

Read More

VPNFilter Malware: What is known so far

Recently, a malware known as VPNFilter was discovered infecting various types of routers. VPNFilter is a modular, multi-stage malware that works mainly on home or small office routers. Since 2016, when the malware was initially introduced, it has compromised more than 500,000 home and small office routers and NAS boxes. Infection of such a large scale could allow the malware’s creators to utilize the affected nodes as a private VPN, making the trace back to the origin of a targeted attack very difficult. Though the infection vector is not yet clear, it is most likely to exploit known vulnerabilities affecting the various routers. There is no indication at present that the exploit of zero-day vulnerabilities is involved in spreading this threat. Some researchers and other US governmental bodies such as the FBI link this attack to the constant cat-and-mouse game between Russia and Ukraine. VPNFilter affected devices Devices infected by the VPNFilter malware include home and small office routers made by Linksys, MikroTik, Netgear and TP-Link, as well as network attached storage devices from QNAP. Magnitude of VPNFilter attack VPNFilter has been active since 2016, affecting some 500,000 devices in more than 54 countries. During May of 2018, two major attacks have been spotted targeting devices located in Ukraine. Threat behind VPNFilter The FBI hints to readers in its post that the VPNFilter malware attack could be the work of Sofacy Group, also referred as APT28, Sandworm, X Agent, Pawn Storm, Fancy Bear and Sednit. They have also seized a key domain that was used to infect home routers. It was also noted by Cisco researchers that the pattern of the attack indicates that the malware is part of a state-backed effort to create a versatile and effective botnet or data harvesting campaign, and shows the hallmarks of previous Eastern European malware efforts. Additionally, parts of this malware overlap code from the BlackEnergy malware which was responsible for multiple large-scale attacks that targeted devices in Ukraine, which was also attributed to a Russian government backed threat actor. VPNFilter infection process McAfee has provided a write-up on VPNFilter’s three-stage infection process: Stage 1 – completes the persistence on the system and uses multiple control mechanisms to find and connect the Stage 2 deployment server. Stage 2 – focuses on file collection, command execution, data extraction, and device management. Some versions possess a self-destruct capability to render itself unusable. Stage 3 – includes two known modules, possibly there are more to come: A traffic sniffer to steal website credentials and monitor Modbus SCADA protocols. Tor to communicate with anonymous addresses. How to prevent VPNFilter attack on the router Steps to protect against this malware are very generic and include the following: Reboot your device; if the device is infected with VPNFilter, rebooting will temporarily remove the destructive elements (outlined in stages 2 and 3 above). Perform a hard reset of the device, restoring factory settings to wipe it clean (removes elements from stage 1 above). Make sure you have the latest firmware installed. How Skybox Security can help defend your network Skybox Security can help identify vulnerability on a network quickly and provide recommendations for patching or other forms of mitigation – based on security controls such as firewalls and intrusion prevention systems (IPS). For this purpose, information about the vulnerability is analyzed in the Skybox Research Lab. A team of security analysts scours dozens of public and private safety data sources every day and investigates websites on the dark web. This allows Skybox to provide validated and up-to-date threat information. The Research Lab also provides vulnerability information regarding exploitability levels, exploitation preconditions and effects, and configures attack patterns to be used in Skybox’s patented attack simulations. By means of a vulnerability assessment without an active scan, the existence of vulnerability in a customer environment is to be derived. Vulnerabilities are then integrated into an attack surface model that includes the network topology, security controls and resources. The model performs attack simulations using information feed data to identify vulnerable assets directly or indirectly exposed to a potential attack. With Skybox, customers can quickly respond to threats such as theVPNFilter malware. Instead of focusing solely on the severity of the vulnerability, Skybox analyzes more factors than any other solution to determine the risk of attack. This can prevent an exploit like this from becoming a risk for companies. By Marina Kidron – Director, Threat Intelligence, Skybox Research Lab  

Read More

CAPSI Stages Peaceful Protest against GST Rules

The Goods and Services Tax in India that is hailed as one of the most successful accomplishments of the current Government turned one year old on 30 June 2018.   The imposition of GST regime has echoed a mixed bearing on the service sector. On one hand, it is beneficial in various aspects such as one country one tax mode, seamless flow of credit, avoidance of multi-taxation etc., on the other it has produced snags in ease of doing business.  The Private Security Industry in particular, which is one of the largest employment generating industries in India making a workforce of over 7 million personnel is not going well along with the GST executions. They have shown utter disappointment with the regime and raised strong objections on the GST implementation.  Amongst others, the major impediment stems from the fact that GST is due to be deposited on the 20th day of every month while private security agencies receive payments for their respective services after 60 to 90 days; in the interim, however, they are mandated to meet the statutory compliances without fail. The gap between the business module of the private security industry and the imposed GST compliance regulations has created an unpleasant state of affairs for the industry. Central Association of Private Security Industry (CAPSI), the preeminent organisation for private security professionals in India have made several representations with the Government to amiably reach out to a rational reconciliation, but they could not fructify well. The CAPSI delegations knocked the doors of the Secretary, GST, CCI and MSME to suggest them to enable the system of reverse charge mechanism for security. Although the delegations at each stage were given a patient hearing, but no assurance towards the rectification of the anomaly has been suggested so far. The industry has decided not to give up and to proceed more pro-actively to counter the indifference. To begin with afresh, CAPSI has recently resolved to stage a nationwide peaceful protest (Dharna) on 18 July 2018 in front of GST offices of the respective states. The basic ethos of the protest is to simultaneously carry out multiple Dharna’s across the country with adequate media coverage in order to make the authorities aware about the seriousness of the issue. In this respect CAPSI State Chapter Presidents will sensitise all the security agencies in their states to participate whole heartedly in the protest. Along with CAPSI members, non-members of the industry are also requested to support the cause and participate in order to ensure adequate strength from the Industry. The participants will wear black T-shirts. CAPSI will also hold a press conference prior to the main event on 16 July at Press Club of India, which will coincide with the scheduled media conference at Delhi by CAPSI. The Dharna envisages an active involvement of APDI as well. APDI State Chapter Presidents are requested to garner the cooperation and indulgence of all the detective agencies operating in the states to actively participate in the Dharna and make it a huge success.  

Read More

Improving Personnel Productivity with Cloud Telephony

The private security industry in India has gained a strong footing in the last decade. With the largest number of private security agents – estimated at 7 million – this industry provides employment to a huge section of people. Urbanisation, and introduction of government proposals such as Mission Smart Cities and Make in India have created a demand for more and more security personnel. Current state of affairs Private security industry plays a huge role in the safety of commoners. For a densely populated country like India, the police to people ratio is not significant enough, which has made the private security industry all the more popular. However, this industry grapples with many crises every day. One of the major problems is the lack of accountability from the security personnel. Security industry in India is largely unregulated, and it’s not uncommon to see guards swapping their shifts without intimating their employer. This impersonation can be potentially harmful, not just for the customer, but also for the security company This is just one of the many problems plaguing the security service providers. Unless there’s a scheduled visit or patrolling by a supervisor, there’s no way to monitor if the guards are alert on their job. Surprise visits to the premises are not a productive alternative either. The human body which is designed to retire at sunset starts to inevitably feel tired and dull during night shifts. Therefore, it makes sense to place your trust in systems, rather than a person to supervise the security personnel. How cloud telephony can help Automated Calls with IVR based check-in To check if the guards are alert, a simple mechanism such as an automated call can be set to trigger at particular time intervals. These calls can solicit input from the guards to ensure that they’re alert. Alternatively, they can be imparted with small training modules in vernacular that are a minute long, asked a related question towards the end of the module, and solicit a response from them. A lot has been said about the lack of training for the security guards. This is an interesting and engaging way to keep them alert and awake. Their call response is an attestation to their situational awareness and alertness. Actions can be initiated by the agency if they fail to respond or answer the call. This method is more proactive than reactive, and adheres to the urgency of the situation. Apart from these call check-ins that fall into a predictive pattern, surprise check-ins can be done by triggering calls at random times. This keeps the security officers alert and ensures they don’t nod off on duty. Automated check-in calls are a more sustainable solution, and the message or structure of the call can be changed every now and then to break the monotony, which is one of the major gripes of security officers. Reminder calls for shift changes Automated reminder calls can be set to go out an hour or 30 minutes prior to the shift, which ensures that the security officer is on time to relieve the on-duty officer. This reduces the chances of no-show or turning up late to the shift. SMS updates to the customer Since the shift rotation chart is prepared in advance, the details of security personnel on duty can be setup to be sent to the customer via an automated SMS message, which they can verify with the help of the personnel identification card. This ensures no impersonation can take place, thus assuring the safety of the customer. IVR to handle new/ potential customer queries For a security services provider, it is essential to be available at all times and put the customer’s safety interests first. Instead of employing a full-scale call center solution, IVR automation can be introduced to answer FAQs. This helps to optimize existing resources better, while also ensuring that an agent does not have to be on-call at all times. A technology like cloud telephony can bring responsibility to this unorganized sector. What’s more – it is not a stand-alone solution. A virtual number that is obtained from a cloud telephony service provider can help provide all the features mentioned above. By Shivakumar Ganesan – CEO & Co-founder of Exotel  

Read More

The Rise of IT and Integration with ID Management

Convergence has been a continual trend in the security industry for over a decade. It began with simple integrations of similar types of security equipment such as adding video cameras to an intrusion system or break-glass detectors to an access control system. The level of integration, however, has quickly evolved – now physical security is being integrated with systems designed with functionality outside of security applications. End users are no longer satisfied with a lack of return on investment from security equipment. Rather, their priorities have shifted from wanting to improve the effectiveness of their security systems toward finding new ways to earn a positive return on investment from these very systems. Historically, physical access control has always been a local, on-site responsibility for those in charge of security management. This is due to huge variations in the methods used to secure buildings, both regionally and by building type. As such, it has always been difficult for larger enterprises to roll out ‘one-size fits all’ access control solutions across multiple sites because of huge variances in the requirements for a given system. The result therefore is that end users responsible for managing these systems now require different training or must issue multiple credentials for multiple locations. Many of these pain points and inefficiencies could be eliminated if credentials are managed centrally; this is where logical integration becomes beneficial. Despite companies often possessing multiple access control systems (each with their own unique database of access rights), they also often have a central database, known as an active or corporate directory. An active or corporate directory is a database that companies use to keep track of employees, contractors, and even customers for a variety of purposes including human resources or IT login credential management. As this database spans multiple sites, it could potentially be used to pull user credentials to create physical access control credentials for the entire enterprise. There is already a wide variety of different levels of logical and physical access control integration. However, pulling physical security access rights from the corporate or active directory is essentially doing so in its most basic and simple form. Features and benefits of integrating these two systems Automation of credential management: Rules-based access control can be implemented by automating system assignments. For example, when a new user is added from the corporate/ active directory, the system can also look every attribute (location, job role, time with the company, etc) associated with the employee. The system then sets default access rights depending on an employee’s attributes. This can greatly speed up the process of adding new users, and it also helps sync access rights with the company’s corporate structure. Unifying credentials: Integrating logical and physical security systems also creates more opportunities to unify credentials. Access control badges or cards can be used for additional functions outside of physical security. Examples include using the credential for two-factor authentication when accessing the IT network, secure printing, or micropayments in the company cafeteria. Improved auditing capabilities and increased accountability: Across an enterprise, the summation of access right changes, on-boarding/off-boarding, and temporary access rights provisioned from its access control system equals a huge volume of requests each month. Without an overarching system, the methods available to senior management for accessing and reviewing logs are limited and inefficient. Corporate governance integration and automation: Logical integration provides the potential to roll out uniform governance across all of the company’s access control systems by enforcing company policy through identity management. Policy checks can be programmed into permission requirements, allowing companies to ensure that best practices are followed. The system also allows the company to verify whether policy was followed, further increasing accountability among employees. Barriers to further adoption Cybersecurity concerns: Connecting every access control system to the IT network, and also managing all of the identities associated with the company via a single system creates huge network risk. If the system is hacked, every identity associated with the company is quickly compromised. Additionally, connecting all the new devices offers hackers new routes into the network, which means that all of the hardware’s software needs to be updated regularly to reduce cybersecurity risk. The lack of an ‘off-the-shelf’ solution: Logical integration projects often require large commissioning and design efforts because they are highly complex both initially and after implementation, particularly with respect to maintenance. This means there is a cost involved for the entire lifecycle that the system remains in place. Lack of developed identity management infrastructure: Many smaller-sized enterprises lack identity management platforms capable of supporting physical access management. And with many larger-sized projects, end users often find that their current authorization policies and best practices have not been updated since they first adopted the identity management system. The result is that these systems must be updated before being integrated with physical access. By Jim Dearing – Analyst, Access Control & Fire, IHS Technology  

Read More

Security and Fire Expo – South India 2018

UBM India is all set to bring in the fourth edition of ‘Security and Fire Expo (SAFE) South India’ for the first time at Hitex, Hyderabad during 28 – 30 June 2018. The expo aims to bring together renowned Indian and international brands from video surveillance, access control, entrance and home automation, and perimeter protection industry to interact, network, view latest innovations, and source and gather business solutions  and invaluable expert supports – all under one roof. SAFE South India is supported by the Electronic Security Association of India (ESAI) and Asian Professional Security Association (APSA).  Highlights: Security services revenue to reach USD1.69 Billion by 2019 Central Government has shown commitment to enhance the security budget by 35% 70 plus brands showcasing their latest technological advancements Conference on the changing paradigm in security technologies With a distinguished line up of key exhibitors and thought leaders on board, the expo will add immense value to the commitment shown by the Central Government to enhance its security budget by 35 per cent for creation of a dedicated homeland security department, developing coordinated intelligence gathering, protecting critical infrastructure and upgrading maritime security. The revenue for security services accounted for 61% three years ago in 2015, and is expected to increase to 66% by 2020. Security spending on hardware, software and services in India is expected to cross the USD 1.69 billion mark by 2019. SAFE South India will be a launch pad for security companies to introduce products in this emerging market, and establish relationships with the key decision makers. The congregation will see security professionals from across industries including security and safety managers from hospitality, IT/ BPO & service industry, real estate, port authorities, power plants, logistics, construction, architecture, automobile, manufacturing, industrial, retail, jewellery, health, education, IT, networking, telecoms, automation, BFSI etc. The 4th edition of SAFE South India has attracted prime exhibitors such as Mark Electronics Corporation, Timewatch Infocom Pvt. Ltd., RoadPoint Ltd., N S Enterprises, ACJ Computronix, Advance Infotech, WYSE Biometrics Systems Pvt. Ltd., Mantra Softech (I) Pvt. Ltd., Matrix Comsec Pvt. Ltd., Prama hikvision India Pvt. Ltd., Pictor Telematics Pvt. Ltd., Axestrack Software Solutions Pvt. Ltd., R G International, Lana Technologies Private Limited, Tekno Electro Solutions (P) Ltd., Face ID Systems LLP, HiFocus Electronics India Pvt. Ltd., Enterprise Software Solutions Lab Pvt. Ltd., Futureeye Global Technologies, CAMTECH Solutions, Dahua Technology India Pvt. Ltd., and Vamo Systems Pvt. Ltd., amongst others. The event will also be organizing a unique conference on The Changing Paradigm in Security Technologies, slated for Day one. The conference will comprise in-depth speaker sessions and panel discussions on trending subjects such as ‘Security of a New-Age City,’ ‘The Role of Drones and UAVs in Homeland Security,’ ‘Visual Analytics in Ensuring Safe Cities,’ ‘IoT and Security of Assets’ and ‘The Threat of Cyber Attacks on Surveillance Systems,’ among others.  “The expenditure on surveillance and security has been increasing in the Indian market in recent years. The government has taken various initiatives to increase security services revenue which will benefit the citizens as well as the security and surveillance services industry. After all, a modern civil city should be able to showcase seamlessly safe, smart, energy efficient and technologically advanced features.  Notably, for the first time since its inception, SAFE South India is being brought to Hyderabad as a strategy to get the show closer to the end users by rotating it across the several key Indian cities that are situated in South India. SAFE South India provides an exclusive platform for the leading players in the security industry to tap into the growing South Indian market by    forging joint ventures, partnerships/associations, sourcing, dealerships and networks.”   Yogesh Mudras, Managing Director, UBM India Pvt. Ltd.                           

Read More

Implementing Mobile Credentials in the Access Control Market

There are several factors that make the widespread adoption now difficult, the first of which is the pitfalls of different phones and the platforms on which they run. Not everyone carries the same type of phone – or even a smartphone. When you have 3,000 people in a company who all need credentials to access a facility, it is rarely feasible to give each person a phone that will run the application needed. Another consideration is how to handle visitors and contractors that might require short- or long-term access to a facility. Perhaps more obvious is the challenge that emerges when a mobile device runs out of battery, thereby rendering it useless when trying to access a facility. Considering privacy Another challenge end users face when considering implementing a mobile-based access control solution is the concern employees may have regarding privacy. When using mobile credentials on a private mobile phone, there’s a certain level of access an employer has to the phone. Employees are concerned as to how employers are using their information with regards to location-based data, or where an employee is at any given moment. Naturally, with this level of access to personal information, there’s going to be a concern about how that data is used. While there is definite movement in the direction of mobile credentials across enterprises, another issue is the proprietary nature of the technology. Since it’s still emerging, there are no common standards in place that police can use, so end users that choose to invest in the technology are often locked into a single manufacturer’s system without the flexibility that more open-platform solutions allow. Addressing these concerns Many end users are now shifting toward a hybrid approach to access control that utilizes both traditional badges that allow access to a facility, as well as the option to use their mobile device as their credentials. The argument is that many employees will have their phones on them at all times, but might not always remember a badge or ID. Having the option to use either solution is becoming a more widespread use of mobile-based systems. With regard to privacy concerns, it’s important for security managers to work closely with human resources and other C-level executives to implement best practices for the use of this technology in an effort to better inform employees and guide implementation. Customer point-of-view We are seeing an increasing customer demand for mobile credentials, so it’s important to understand their needs when discussing which access control solutions are ‘right’ for an organization. Many want the flexibility to offer multiple options to their employees, but again, have to consider the privacy implications as well as the technology involved in trying to implement such a solution. Another consideration is the actual physical implementation. Most mobile based credentialing systems are built with bluetooth, which has a long-range capability; and this can be problematic. For example, turnstiles that are in close proximity to each other might pick up credentials that are a greater distance away. Standards such as near-field communications (NFC) that can be found in a lot of devices can address some of these concerns, but NFC’s ability to be used openly in an iPhone environment is not fully established and therefore isn’t a viable option unless the same kind of devices is used across an organization.

Read More

COP Portal to Verify Private Security Guards

Joint Secretary (PM) Ministry of Home Affairs has recently issued directions to all Controlling Authorities to use CCTNS (Crime & Criminal Tracking Network System) to check the crime record of private security guards, as well as the owners/ directors of the private security agencies so that the police verification of the private security guards can be done speedily and certificates can be issued at the earliest. This will speed up the verification processes for the renewal of PSARA license. Almost 90% police stations across country have been connected through computer network under CCTNS, thereby antecedents of a person especially his/ her criminal records can be checked and verified soon. CAPSI has been persuading MHA to speed up the verification process so that every security guard is verified through its systems. This notification of the MHA will really help in renewal of pending licenses.

Read More

Confronting the New-Age Cybercriminal

Over the last few years, cybercrimes have become more intense, sophisticated, and potentially debilitating for individuals, organizations and nations. Law enforcement agencies are finding it difficult to check and prevent the crimes in the cyber space because the perpetrators are faceless and incur very low cost to execute a cybercrime whereas the cost of prevention is extremely high. Targets have increased exponentially due to the increasing reliance of people on the internet. Cybercrimes which were restricted to computer hacking till some time ago, have diversified into data theft, ransomware, child pornography, attacks on critical information infrastructure (CII) and so on. “Cyber related risks are a global threat of bloodless war. India can work towards giving the world a shield from the threat of cyber warfare” Narendra Modi Prime Minister of India India is becoming increasingly vulnerable to this menace because of rapid digitization and proliferation of mobile data without matching pace of cyber security and cyber hygiene. At present, India is ranked at 3% in terms of cybercrime incidents as per data shared by a leading security vendor, which compiled data of bot-infected systems controlled by cyber criminals in different countries. As per CERT-In, one cybercrime was reported every 10 minutes in India during 2017. These statistics are quite alarming and therefore, merit focused and collective attention from law enforcement agencies (LEAs).   Expansion of cyber ecosystem and its impact The increase in technology convergence has created an extremely complex ICT ecosystem of interdependencies within and among critical sectors. This leads to an increased number of stakeholders and a larger attack surface which can be easily exploited by cyber criminals. There is no silver bullet technology which can identify or predict which element of the system (people, process or technology) is more susceptible to cybercrime, though empirically it is observed that the people are the weakest component of the cyber ecosystem. Inherent anonymity and closed nature of the dark web has turned it into a safe haven for cyber criminals and their wares. The dark web hosts a wide range of illegal online markets of cyber exploit kits, drugs, counterfeit documents, stolen credit cards, bank account credentials, human trafficking, illegal immigration etc. It has thousands of forums which operate in a tightly controlled environment. Crypto-currencies are used for transactions so that these transactions cannot be traced to individuals or organizations. Ransomware continues to be a major threat the world over. In 2017, WannaCry, Petya, NotPetya etc., caused major disruptions in the connected cyber ecosystem of the world. India was also affected. CERT-In confirmed 37 incidents of WannaCry and Petya attacks in India between May and June last year. Petya caused extensive disruption of services in India. One terminal of JNPT (Jawaharlal Nehru Port), Mumbai had to switch over to manual operations due to this attack. India was the worst affected country in Asia and seventh overall, due to Petya attack. Apart from ransomware, another area of significant concern is theft of personal identifiable information (PII) and financial credentials of individuals. In another incident of cybercrime, criminals stole personal data of over 2.74 lakh Indian users of the Ashley Madison website. Hackers, who stole 300GB of personal information of the users, put it up on sale over the dark web. Also, Cryptojacking is another lucrative method adopted by attackers to deploy a malware forcefully and unknowingly into a victim’s computer to use their hardware for generating crypto-currency. It is becoming yet another tool of choice for cyber criminals because it cannot be classically categorized as a crime. Figure 2: Top cybercrimes in 2017 “The advent of Digital India and Smart City initiatives has brought about a paradigm shift in terms of connectivity, services and threats for both urban and rural eco-systems. While greater connectivity promises wider deliverables, it also paves the way for the emergence of new vulnerabilities. Leading companies in energy, telecommunications, finance, transportation and other sectors are targeted by new-age cyber criminals. The ‘Make in India’ initiative has identified 25 core sectors as part of its effort to give a special thrust. While cyber security is not one of the sectors, it could be embedded in certain sectors like defence manufacturing, electronic systems, and IT & BPM. It is crucial for ‘Make-in-India’ to focus on cyber security as well as promote development of indigenous solutions to combat cyber-crime.” – Dilip Chenoy Secretary General, FICCI Figure 3: Rise in cyber crime Cybercrimes in the connected world One reason why cybercrimes are becoming more sophisticated, better orchestrated and increasingly ambitious is because many of the perpetrators operate outside the jurisdiction of the victim’s country. As per industry estimates, 32% of the threat vectors originate from Eastern Europe and Russia, and social engineering is the preferred mode of launch for most perpetrators. A report indicates that there are four distinct groups of cyber-criminals – traditional gangs, state-sponsored attackers, ideological hackers and hackers-for-hire. The report also states that the entrance of new participants has transformed cybercrime from isolated and individualized acts into pervasive, savage practices run by distinct groups of individuals. Outsourcing is also possible for execution of these crimes on the dark web where cybercrime is offered as a service. “Cybercrime is the biggest challenge these days with development and access to technology across the globe. Cyber space is increasingly being used to radicalize young minds” Rajnath Singh Union Home Minister of India Cybercrime-as-a-service not only allows malicious actors to leverage other cybercriminals’ resources to conduct attacks but also provides a cheap and easy option to others who are willing to enter the world of cybercrime at a very low entry cost. Netizens have increasingly become more active in leveraging these services, which is driving a surge in activities like illicit drug sale, trafficking of human beings, terrorism, child pornography and other crimes. Illustrative rates of some of the services offered are given next page. Cybercrime-as-a-service model has led to the emergence of a complex and multi-layered cybercrime economy where overt acts of crime have been replaced by a covert criminal…

Read More
House-Break

4 Ways to Proactively Protect Your Home

The statistics don’t lie. Home burglary rates are high. According to a survey of 1,000 Australians, 1 in 5 people have had experienced a burglary or attempted burglary. When compared to the rest of the world, it’s clear we have a problem. The international average of home burglaries is 1.8%, and ours is 2.5%. This means that 1 in 40 Australian homes may be burglarized this year. These figures are startling, but you can take action to avoid becoming another statistic. Here are 4 easy ways to proactively protect your home. With these tips, you can safeguard your family, property, and home. 1.     Install a home security system Only 1 in 3 people from the above-study responded that they had a home security system. However, the presence of a home security device is a powerful deterrent for a would-be intruder. A study by the University of North Carolina found that 60% of burglars would be deterred by the presence of an alarm. Technological advances have now made it easy to install home security. As a leader in the DIY home security space for over 30 years, Swann is dedicated to helping keep your home safe around the clock with affordable solutions. Our wireless security cameras eliminate messy cabling and make installation easy. In addition, our high-definition security cameras can capture facial features, license plates, and see in the dark up to 30m. You can even check on your property remotely from anywhere in the world with your smartphone and a Swann app. Additionally, Swann has cameras with True Detect™ heat- and motion-detection and the ability to generate push notifications and video recording when the camera detects activity. Using heat-sensor technology versus only motion detection means fewer false triggers and more reliable notifications. This combination can help prevent burglaries while also capturing and recording valuable video evidence most efficiently. How do I choose between wire-free cameras or wired system? First, decide how many cameras you need and where you need them, try analysing potential break-in points around your home. Take a look at your home from the road and consider all of the potential points of entry. Next, consider whether you want to install a system that connects to your home’s Wi-Fi network or not, including the distance from your router and how many devices will be connected. Do you want a system that is hardwired into your home, or totally wire-free cameras? Hard-wired security systems give you more recording features. For example, if you’re concerned about a specific area of your property, you can set parameters to include or exclude certain areas from your camera’s view. All of these features provide you with reliable, affordable, and userfriendly home security. Also, wired cameras can offer a more stable signal at times. Installing a home security system with cameras allows you to take proactive steps to protect your family, home, and valuables before anything happens. Not only does a visible security presence at your home mean that you may be less likely to be broken into, but it also gives you peace of mind. 2.     Be vigilant Having a home security system isn’t the only action you can take to protect your home and family from intruders. A few easy steps can potentially make your home less attractive to burglars It’s difficult for a burglar to steal what they can’t see. Don’t tempt would-be burglars. It’s advisable to keep valuables hidden and your blinds closed when you leave your home. Or if you’re expecting a package, ask a neighbour to collect it for you to decrease the risk of theft and so it doesn’t look like you’re not home. While seemingly minor, these tips may help keep your property safe. Are you among the 35% of Australians who leaves a spare key outside their home? If so, it’s time to rethink the idea of hiding a key under a flower pot or somewhere outside your home. This is a common practice, so it’s often one of the first things that a potential intruder will look for. Don’t make it easy for them to enter your home by leaving a key for them. And, be aware of potential hiding spots on your property. You may not realise that you are creating the ideal blind spot outside of your home with poor lighting. Investing in simple outdoor lighting, including sensor lights, can sometimes be enough to help prevent a home break-in. 3.     Work with your neighbours You may not realise it, but you have strong allies in the fight against burglary – your neighbours. When you get to know the people who live near you, you can look out for their homes while they keep an eye on yours. Watchful eyes can be very helpful against home invasions and theft. After you get to know your neighbours, consider taking your safety efforts a step further by creating a neighbourhood watch program. Together, you and your neighbours can arrange for community meetings and nightly patrols. 4.     Discuss insurance coverage Your best efforts sometimes aren’t enough to prevent a break-in. Home or renter’s insurance can make sure that you’re prepared if something does happen. Budget Direct Home Insurance offers a number of options that protect your home and belongings from burglaries, fire, storm damage, and more. The act of obtaining insurance is another great way to protect you from the unthinkable. By following these easy home security tips, you can feel confident that you have taken proactive steps to reduce your risk of being a victim of a home break-in. We recommend taking a proactive approach regardless of if you’re going on holiday, especially if everyone in your home is gone during the day. Nothing can compare to the peace of mind that you have when you know that you’ve protected your home, property, and family.

Read More