Technology Cloud Contributor

“Management by AI”: Analytics in the Data Center

Management by AI Behind any cloud, hosted environment or enterprise computing environment are data centers with tens of thousands of servers, racks upon racks of networking equipment, and supporting critical infrastructure, from power distribution to thermal management. The scale, complexity and required optimization of these
Great Data Scientists Don’t Just Think Outside the Box, They Redefine the Box

Great Data Scientists Don’t Just Think Outside the Box, They Redefine the Box

Redefine the Box Special thanks to Michael Shepherd, AI Research Strategist, Dell EMC Services, for his co-authorship. Learn more about Michael at the bottom of this post. Imagine you wanted to determine how much solar energy could be generated from adding solar cells to a

CONTRIBUTORS

How Formal Verification Can Thwart Change-Induced Network Outages and Breaches

How Formal Verification Can Thwart Change-Induced Network Outages and Breaches

How Formal Verification Can Thwart  Breaches Formal verification is not a new concept. In a nutshell, the process uses sophisticated ...
IoT Security Intel

Cyber IoT Security: McAfee on Threats and Autonomous Cars

IoT Security Autonomous cars are just around the corner, there have been IoT security controversies surrounding their safety, and a ...
Predict ► Prescribe ► Prevent Analytics Value Cycle

Predict ► Prescribe ► Prevent Analytics Value Cycle

Predict ► Prescribe ► Prevent Organizations looking for justification to move beyond legacy reporting, should review this little ditty from ...

RECENT NEWS

The New Industrial Revolution – According to the WSJ

The New Industrial Revolution – According to the WSJ

The insert in today’s US print edition of the Wall Street Journal is called The New Industrial Revolution. The paper updates ...
Pressure grows on Zuckerberg to attend Facebook committee hearing

Pressure grows on Zuckerberg to attend Facebook committee hearing

Australia, Argentina and Ireland join UK and Canada in urging Facebook CEO to give evidence to parliaments Parliamentary committees from ...
Amazon picks New York City, Virginia for $5 billion new headquarters

Amazon picks New York City, Virginia for $5 billion new headquarters

SAN FRANCISCO (Reuters) - Amazon.com Inc (AMZN.O) said on Tuesday it will build offices for up to 25,000 people in ...
Capgemini in Gartner Magic Quadrant

Capgemini in Gartner Magic Quadrant

Paris, November 9, 2018 – Capgemini, today announced that Capgemini (Prosodie) has been positioned as a Leader by Gartner in its ...
Alibaba's on-demand online services unit valued at $30 billion: sources

Alibaba’s on-demand online services unit valued at $30 billion: sources

HONG KONG (Reuters) - Alibaba Group’s newly formed on-demand online services unit has rocketed in value to as much as ...
Vibhav Agarwal

Ransomware Cyber-Attacks: Best Practices and Preventative Measures

Ransomware Cyber-Attacks

WanaCrypt0r 2.0” or “WannaCry,” an unprecedented global ransomware cyber-attack recently hit over 200,000 banking institutions, hospitals, government agencies, and other organizations across more than 150 countries. The ransomware encrypted user data, and demanded a payment in bitcoins to unlock the data. The companies that were hit included Telefonica – Spain’s largest telecom provider, more than 16 hospitals in England’s National Health Service (NHS), US package delivery company – FedEx, and many other high profile targets.

Across the world, cyber-attacks are on the rise. CSO magazine cited the FBI as saying that $209 million had been collected in ransomware payments in the first quarter of 2016 alone. These attacks illustrate how unprepared most organizations are to counter the growing menace of cyber threats. Many large organizations still use unsupported or older versions of software, encounter significant delays in patching vulnerabilities, and perform fewer automated backups, thereby putting themselves at grave risk. As the scale and impact of cyber-attacks grow, it is imperative for CIOs, CISOs, and other business leaders to diligently address basic areas of cybersecurity to avoid disruptions in their critical business operations.

KEEPING CYBER THREATS IN CHECK

Detecting covert cyber threats lurking in enterprise networks, and orchestrating a common cyber risk taxonomy are integral to an organization’s security blueprint. The first step in that direction is to strengthen data governance and accountability by building a centralized repository and consistent taxonomy to manage the cybersecurity areas of compliance, IT assets, IT policies, risks, and controls, as well as the relationships across these data elements. In addition, an integrated IT GRC solution can be leveraged as a strategic and operational tool to solve complex ransomware and cyber security challenges. The solution can help manage and mitigate IT security risks, vulnerabilities, and advanced attack threats by leveraging multiple threat modeling and risk assessment methodologies such as STRIDE, DREAD, and other approaches based on quantitative factors. Pre-built methodologies for IT risk assessments and threat assessments can help organizations improve visibility into the overall IT and cyber risk landscape. Organizations will also gain from pre-built integrations with leading threat feed providers. By consolidating “early warnings” or notifications from these trusted sources into a searchable database, users receive comprehensive details on each threat, CVE ID, source, affected technologies, controls, threat and patch records, and possible remediation mechanisms.

Using this data, users can automatically notify the responsible personnel to proactively address the threats before systems are compromised. A robust IT GRC solution can also help organizations integrate with patch management solutions, vulnerability scanning devices, and infrastructure management tools to centralize data and assets, classify critical assets, identify issues, and track the vulnerability remediation status on an asset-by-asset basis. The solution can serve as a repository of the latest patches released by various software vendors to mitigate specific vulnerabilities. This data will enable enterprises to prioritize the implementation of patches or workarounds based on the criticality of each asset.

The other benefit of an IT GRC solution is that it can serve as a path to organizational compliance with industry-standard cybersecurity regulations by standardizing and harmonizing control sets across multiple regulations. It can also provide a consolidated view of the status of compliance with cybersecurity standards through a detailed gap report of operating controls that have not been mapped to reference controls as prescribed by the standard. This report will enable organizations to take proactive steps towards closing compliance gaps. Visualization tools can help users manage and monitor threat and vulnerability trends, as well as the organization’s risk posture, and issues in real time. Configurable dashboards can also help the company view underlying risk data, and gain a complete understanding of the potential impact of these risks on the business.

KEY BEST PRACTICES

  • Manage software updates systematically

Update old software and ensure that patches are also updated to avoid any weak spots that can be exploited by hackers.

  • Assess and mitigate IT security risks

Align IT security operations with business priorities, and perform periodic IT risk assessments based on vulnerabilities, patch levels, and security policy reviews to ensure a higher state of readiness.

  • Ensure consistent compliance, privacy, and security

Establish security policies or protocols to prevent external threats, and proactively anticipate potential ransomware attacks.

  • Develop contingency plans with regular online backups

Identify the most critical assets, and implement strong periodic backup mechanisms (e.g. cloud-based backups).

  • Gather threat intelligence

Ensure prior intelligence on threats which can help in patching the vulnerabilities that are most likely to be exploited by cyber criminals.

SUMMARY

With ransomware and other cyber-attacks on the rise, it is of utmost importance that organizations of all sizes have the right detection and preventive techniques to proactively counter these attacks. Getting one’s basics right is the first step. A robust backup strategy, coupled with threat or risk assessments, and employee training can go a long way towards preventing cyber-attacks. These small investments can eventually save the organization tens of millions of dollars, as well as its reputation and brand.

By Vibhav Agarwal

Vibhav Agarwal

Vibhav Agarwal is the Director, Product Marketing at MetricStream.

Vibhav has 11+ years of progressive experience in Enterprise product marketing, sales management, ERP & CRM program planning and delivery, software vendor selection and implementation across Hi-Tech, Trading & Capital Markets and Internet domains. Worked extensively in various roles dealing with multinational conglomerates as well as mid-sized companies like Info Edge India, in deals ranging between 0.5-30 million USD. Exposure to all stages of product and IT applications, sales & marketing, product management, and enterprise implementations.

View Website

Cloud Community Supporters

(ISC)²
Cisco
SAP
CA Technologies
Dropbox

Cloud community support comes from (paid) sponsorship or (no cost) collaborative network partnership initiatives.