Showing posts with label City of NY. Show all posts
Showing posts with label City of NY. Show all posts

Sunday, October 16, 2016

Ransomware: Osterman Research Survey for Malwarebytes

https://www.integrissecurity.com/index.php?aboutus=JosephConcannon
Joseph Concannon
Today I receive a note from a friend who said he had fallen victim to a Ransomware attack.  So I figured its a good time to review some up to date expert research.  This review is a product of Integris Security LLC and we gladly share this with the community.

First, Ransomware is a global issue effecting enormous sized companies as well as my local friend.  Ransomware is a global threat/problem.  We must recognize the size and depth of this issue.  A survey was conducted during June of 2016 that included CIO's, CTO's, CISO's and other executives.  The survey included 165 corporations in the United States as well as companies from around the world.  39% percent of the companies that were contacted were impacted by a ransomware attack in the U.S. alone.  This is truly a global problem and issue but let's keep the focus here at home.  The report shows the various priorities by country.

The FBI talks about Ransomware as a, "an insidious type of malware that encrypts, or locks, valuable digital files and demands a ransom to release them". Integris Security LLC evangelizes through its President, Joseph Concannon the value of Risk Management and the ongoing development of a solid business continuity program.  Concannon states: "this isn't a once a year review, this is a daily, weekly, monthly, quarterly and semi-annual program.  Risk Management opens the eyes of the Executive Team and Boards of Directors".

Second, it comes as no surprise that the survey results identified healthcare and financial services industry as the prime target.  Each are highly dependent upon business critical information according to Osterman Research, Inc.Cyber criminals lay and weight until they find the prime target for an attack; one which they can not recover from due to the lack of ransomware fighting software.  In Osterman's survey U.S. companies were most likely to fall victim to a ransomware attack (79% fell victim according to the survey).

Third, Ransomware ranks the fourth highest security concern for senior executives in the United States as surveyed by Osterman Research, Inc., and more:

 U.S. organizations are also more likely to place a high or very high priority on investing in education and training about ransomware for their end users; and for investing in resources, technology, and funding to address the ransomware problem.

Note well: What the Osterman Research reveals is the power play between tenured industry executives and newly appointed CIO's, CISO's, CTO's learning the mine field of budgeting.  Where do these technology executives make the push to gain budget for their projects and can they convince business unit managers to join their team?  Who pays for training and education and how does that weigh in the balance of getting things done?  Here's how its playing out so far:
Somewhat ironically, however, U.S. organizations are also the least likely to have implemented any sort of ransomware training for their end users, and are among the most likely to offer only minimal training when they actually do so.  U.S. companies rate Ransomware as a high or extremely high priority, unlike their European counterparts in Germany and the UK or Canada which consider it less of a threat. 
Yet the training dollars in the U.S. continue to lag behind.   

The survey that I am reviewing is called, "Understanding The Depth of The Global Ransomware Problem" a report promoted by a company called Malwarebytes
The perceived importance of regular, on-premises backups as a ransomware-recovery tool is quite high among U.S. and German organizations, but somewhat lower among the organizations we surveyed in Canada and the United Kingdom. However, Canadian and UK-based organizations were more likely to use regular, cloud-based backups to recover from ransomware. Other capabilities in place to address ransomware included on-premises ransomware-detection solutions (highest penetration in the U.S.), network segmentation (highest in Germany), and air gaps between data stores and the Internet (highest in Canada).
At Integris Security LLC we point out that segmentation and air gaps are important as well as on-premises backups NOT connected to the network you are backing up.  Strong passwords that are changed every 90 days.  Here are the top 15 Cyber Security Precautions to follow.  Here are some very good tips for enterprise environment security teams to review (FBI):

Here are some tips for dealing with ransomware (primarily aimed at organizations and their employees, but some are also applicable to individual users):
  • Make sure employees are aware of ransomware and of their critical roles in protecting the organization’s data.
  • Patch operating system, software, and firmware on digital devices (which may be made easier through a centralized patch management system).
  • Ensure antivirus and anti-malware solutions are set to automatically update and conduct regular scans.
  • Manage the use of privileged accounts—no users should be assigned administrative access unless absolutely needed, and only use administrator accounts when necessary.
  • Configure access controls, including file, directory, and network share permissions appropriately. If users only need read specific information, they don’t need write-access to those files or directories.
  • Disable macro scripts from office files transmitted over e-mail.
  • Implement software restriction policies or other controls to prevent programs from executing from common ransomware locations (e.g., temporary folders supporting popular Internet browsers, compression/decompression programs).
  • Back up data regularly and verify the integrity of those backups regularly.
  • Secure your backups. Make sure they aren’t connected to the computers and networks they are backing up.

For those at home we strongly recommend backup on USB stick, or other storage drive with proper security "on board" to assess the devices health each time the device is accessed.  Saving important documents to a computer is a thing of the past.  Time to think 2016 and the threats that come with the technological age we live in.  Store important documents in a safe deposit box (whether in paper or USB or storage drive or other form).  If its important, then take the extra security steps.

https://www.stopthinkconnect.org/STOP THINK CONNECT is the U.S. Department of Homeland Security Campaign promoted during Cyber Security Awareness Month (October each year).  However, the evil email attachment continues to lure an seemly endless waterfall of users into the brink.  Nothing beats education and awareness in preventing the lost of your computer to a cyber attack.  While on the computer remember you are not in your living room.  You are in the "Wild West" and everyone's your friend.  You wouldn't leave your front door open at night, so don't leave your computer open either.  
Integris Security LLC grew from our passion for protecting our nation’s critical infrastructures and years of providing industry professionals with best of breed solutions, proven best practices and top notch security education. We work tirelessly to nurture our clients’ TRUST. We will work equally diligently to EARN your trust.


Thursday, December 18, 2014

Banks: Federal/State Rules

No holiday would be complete with out a stern warning to the banking industry from both state and federal regulators, right?  Ho, ho, ho Merry Christmas - can you please assure us that your security controls are in order!

I was going to review Governor Andrew Cuomo's Department of Financial Services as it pertained to "new" security regulations for chartered banks in New York State.  The Superintendent of the Department of Financial Services initiated a press release and letter to chartered New York financial institutions.  After reviewing the memo I concluded that if all companies implemented the items in the Superintendent's letter, the public and private industries would be in a much better place. 

Then late yesterday the FFIEC (federal financial institutions examination council)  OCC (Office of the Comptroller of Currency) spokesman Joel Anderson spoke up.  Mr Anderson responding in a interview in American Banking Magazine stated, "we already do this" and what's going on in New York is nothing new. 

This is what New York DFS said they would look for:

New Rules: NYS
  • Corporate governance, including organization and reporting structure for cyber security related issues;
  • Management of cyber security issues, including the interaction between information security and core business functions, written information security policies and procedures, and the periodic reevaluation of such policies and procedures in light of changing risks;
  • Resources devoted to information security and overall risk management;
  • The risks posed by shared infrastructure;
  • Protections against intrusion including multi-factor or adaptive authentication and server and database configurations;
  • Information security testing and monitoring, including penetration testing;
  • Incident detection and response process, including monitoring;
  • Training of information security professionals as well as all other personnel;
  • Management of third-party service providers;
  • Integration of information security into business continuity and disaster recovery policies;
  • Cyber security insurance coverage and other third party protections
These are all things we at Integris Security does.

New York State then went on to list more topics which chartered banks in NYS would be expected to furnish.  We list them here for your review:


1.  Provide the CV and job description of the current Chief lnformation Security Officer or the individual otherwise responsible for information security, describe that individual's information security training and experience, and identify all reporting lines for that individual, including all committees and managers. In addition, provide an organization chart for your institution's IT and information security functions.
2.  Describe the extent to which your institution maintains information security policies and procedures designed to address the information security goals of confidentiality, integrity, and availability. Provide copies of all such information security policies.
3.  Describe how data classification is integrated into information risk management policies and procedures.
4.  Describe your institution's vulnerability management program as applicable to servers, endpoints, mobile devices, network devices, systems, and applications.
5.  Describe the organization's patch management program including how updates, patches, and fixes are obtained and disseminated, whether processes are manual or automated, and how often they occur.
6.  Describe identity and access management systems employed by the organization for both internal and external users, including all administrative, logical, and physical controls and whether such controls are preventive, detective, or corrective in nature.
7.  Identify and describe the current use of multi-factor authentication for any systems or applications.
8.  Describe your institution's due diligence process regarding information security practices that is used in vetting, selecting, and monitoring third-party service providers.
9.  Describe all application development standards utilized by the organization, including the use of a secure software development life cycle, and the extent to which security and privacy requirements are assessed and incorporated into the initial phases of the application development process.
10. Provide a copy of, to the extent it exists in writing, or otherwise describe, the organization's incident response program, including how incidents are reported, escalated, and remediated.
11. Describe the extent to which information security is incorporated into the organization's BCP/DR plan, how and how often the BCP/DR is tested, and the results of the most recent test.
12. Describe any significant changes to the institution's IT portfolio over the last 24 months resulting from mergers, acquisitions, or the addition of new business lines.

 Analysis:

It is a positive step forward for New York State Department of Financial Services to require its chartered financial institutions to meet minimum guidelines for the security of its information technology processes.  These security baselines are critically important not just to financial services institutions but to all public and private entities.  Since NYS has published these official rules it should now become the benchmark or de facto standard by which all other organizations are measured against.  These rules are appropriate and an outstanding starting point for any one who is not sure where to start.

The federal government provides an seemingly endless amount of guidance for the protection of information technology assets.  The fed's use the NIST framework and numerous NIST publications to assist everyone involved in the security of IT assets.  The federal regulators have been the go to professionals in the banking space for establishing standards so its not unusual to hear from Mr. Anderson of OCC or any of the regulators who are apart of the FFIEC. 

What is the news with this New York letter?  The federal regulators often calibrate their examinations according asset size.  Thus larger institutions receive more intense evaluation then smaller organizations.  However, New York has a very specific set of rules in which every institution must be prepared to comply with.  This is not a little matter and could have significant cost ramifications. 

Lastly, I have for years heard from administrators, mangers and CISO's who have tried to get budget authority to make the purchases necessary to secure their environments.  I am suggesting that security personnel use the NYS standards to present to CFO's as justification for future purchases.

http://dfs.ny.gov/about/press2014/pr1412101.htm

http://dfs.ny.gov/banking/bil-2014-10-10_cyber_security.pdf

www.americanbanker.com/news/bank-technology/occ-our-cybersecurity-exams-are-plenty-detailed-too-1071708-1.html

http://www.americanbanker.com/

Friday, June 20, 2014

The Future of NYC Is Up For Grabs...


As many of you know last year at the request of every Law Enforcement entity in NYC I was requested to run for City Council.  Why?  Because then NYC Councilman Mark Weprin of the 23rd District where I live lied to police officers at every rank and put them in personal legal jeopardy.

The pivitol campaign issue was all about something called local law 71, the Community Safety Act of 2013.   Former mayoral candidate Bill DeBlasio and City Councilman Mark Weprin of NYC for nine months hammered NYPD and asserted they were out of control violating the rights of everyone out of hand (stopping and frisking anyone in sight).  The law, the NYS criminal procedure law and case law shapes the circumstances upon which search and seizure may occur and when a police officers common right of inquiry for Stop, Question and Frisk can occur.  Local Law 79 on page two for the first time places NYC Police Officers in defined personal legal jeopardy which today NYS Supreme Court Judge Singh just affirmed.  Police Officers will not be covered by the City Law Department which is the usual case for those city workers carrying out their paid function.  Anyone can just file a law suite against a police officer and out of pocket those officers will be force to defend themselves, their families, reputations, estates, assets and more.

The magnitude of this law is far reaching and has with the strike of the pen "handcuffed" the NYPD from conducting even lawful Stop, Question and Frisks for fear of legal jeopardy coming into play.  Anyone, anywhere can choose to sue them personally.  No wonder why shootings in NYC are up 13% for the first six months of 2014 and up 1800% in the confines of the 75th Precinct for the current 28 day period.  Bad law has consequences and if their ever was a bad law with horrible consequences this law is the poster child. Remember as a result of past NYPD activities in NYC over 7700 people are alive today, not from some affluent community but in the harshest places NYC Police Patrol.

Today, Ed Mullins president of the NYC Sergeants Benevolent Association spoke out as a result of a NYS Supreme Court ruling.  Here's what he had to say:

Some Excellent Advice That Should Definitely Be Heeded           [Applicable to All Ranks]

NYPD members can be SUED! - State Supreme Court Judge Anil Singh
By Ed Mullins — Thursday, June 19th, 2014; 4:42 p.m.  ‘Sergeants Benevolent Association E-mail’


On Wednesday June 18, 2014 State Supreme Court Judge ruled members of the NYPD who engage in Stop, Question and Frisk can now be sued in accordance with the provisions of Local Law 71 as passed by City Council. 

Once again I remind each of you, this law impacts your career, family and overall well-being.

As you go to work each day, your only assignment is to return home to your family. The POLITICIANS and the PEOPLE of this city are NOT SUPPORTING you, make no mistake about it!   

Shootings are on the rise and gun arrests are down.  DO NOT jeopardize your safety, careers and pensions!  We are currently exploring an appeal.


Below is a summary of Judge Singh’s decision.

The court made three rulings. First, it ruled that the SBA and PBA had standing to challenge Local Law 71 and had properly brought suit against the City Council on behalf of their members.  Second, it ruled that Local Law 71 is not preempted (and thus not invalidated) by state law, either because the state occupies the field of criminal procedure or because Local Law 71 conflicts with state law.  Third, the court ruled that Local Law 71 is not unconstitutionally vague.

1-      The court determined that the SBA and the PBA had standing to challenge the law because the availability of lawsuits against police officers, including the potential for police officers to be held individually liable for attorneys’ fees and costs that would not be indemnified, was an immediate threat of harm.

2-      The court therefore rejected the City Council’s argument that the harm to police officers resulting from Local Law 71 was speculative.

3-      The court also agreed with the SBA and PBA that the reputational harm that would result from such lawsuits was an injury that could be protected in courts as a matter of law.  The court found that the SBA and PBA as organizations had properly brought suit on behalf of their members, because their mission and core function is to protect the rights and interests of law enforcement officers.
4-      On the issue of whether Local Law 71 is preempted by the New York Criminal Procedure Law (the “CPL”) as an impermissible intrusion into the field of criminal procedure, the court concluded that the two laws exist in two different fields, because Local Law 71 is not a criminal procedure law, but rather a civil rights law.  Noting that other municipalities have similarly enacted laws regarding civil rights, including racial profiling laws, the court observed that Local Law 71 does not prevent police officers from making stops, and that it simply creates consequences for police officers who engage in bias-based activities.
5-      The CPL, according to the court, applies only to criminal prosecutions and procedural rights of defendants.  In effect, the court agreed with the City Council that the CPL governs only matters that occur in criminal court, and found that, because investigative stops occur outside of court, they are not covered by the CPL.
6-      The court further found that Local Law 71 does not conflict with the CPL because it does not place any restrictions on a police officer’s ability to stop, question, and frisk an individual beyond those established by the Supreme Court in Terry v. Ohio and by subsequent related cases.  Instead, the court found, it requires only that a police officer consider an individual’s behavior or other circumstances linking the individual to criminal activity.
7-      According to the court, prohibiting the use of race or another protected characteristic as the “determinative factor” in making a stop is consistent with state and federal law, and a stop that was based on such a characteristic would not satisfy the Terry standard in any event.  Because Local Law 71 does not set a higher standard for stops than what is already required, the court reasoned, it is not inconsistent with state law. Nor, the court found, does Local Law 71’s use of a subjective standard result in a conflict, because, regardless of whether the stop is viewed objectively or subjectively, the same factual basis must exist before the stop can lawfully occur.
8-      The court disagreed with the SBA and PBA that Local Law 71 is unconstitutionally vague.  While the court acknowledged that in some circumstances Local Law 71 operates in a “grey area” because of the lack of definitions of its terms, it concluded that courts and administrative bodies could develop meanings for those terms over time, as cases come before them.  The court also emphasized that the phrase “determinative factor” originates from the NYPD’s own internal anti-profiling policy, and asserted that the NYPD had acknowledged in a FINEST message that Local Law 71 is consistent with NYPD policy and training concerning investigative stops.


Fraternally,
 / s /

Ed Mullins


Elections have consequences and NYC just spent twenty years cleaning up the streets of NY.  Police Officers are humanbeings and as such with guidance from supervisors and Union leadership will find themselves hard pressed to aggressively fight crime in our city especially as case after case winds its way though the courts.  Which NYC Police Officer wants to be the test case to see if he or she acted within the scope of this new law.  We say, few will opt in to make themselves an example for all others to follow.  As such, the NYPD is pulling back and today we can begin to see the results starting to crystallize.  The 75th precinct is notibly one of the toughest places in the City to work.  Crime and violence now are returning to the streets, the City Council is demanding more police officers to patrol the street (the cost of this bad law is already showing), children are stabbed during daylight in elevators, people shot openly in the streets as crime, disorder and fear once again return to NYC.

This is a sad day for the City of NY.