Tuesday, 1 September 2015

CMIT offers seminar on cybersecurity

CMIT Solutions of Appleton will host an educational seminar on cybersecurity from 4 to 6 p.m. Sept. 16 at the Appleton Yacht Club, 1200 S. Lutz Dr., Appleton.

Those in attendance will be given detailed information, guidance and training on how to secure and protect their network including strategies on preventing and recovering from a cybersecurity breach.

Small and medium-sized businesses are receiving more attention from cybercriminals because they tend to have weaker security and data encryption measures; to a hacker, every employee and workstation represents a possible entry point, which is why staff need to be trained to secure and protect company data; and malware, phishing attacks and social engineering tactics are on the rise.

View the original content and more from this author here: http://ift.tt/1X9pSXR



from cyber security caucus http://ift.tt/1JIO6Oq
via IFTTT

Exclusive: U.S. weighs sanctioning Russia as well as China in cyber attacks

The United States is considering sanctions against both Russian and Chinese individuals and companies for cyber attacks against U.S. commercial targets, several U.S. officials said on Monday.

The officials, who spoke on condition of anonymity, said no final decision had been made on imposing sanctions, which could strain relations with Russia further and, if they came soon, cast a pall over a state visit by Chinese President Xi Jinping in September.

The Washington Post first reported the Obama administration was considering sanctioning Chinese targets, possibly within the next few weeks, and said that individuals and firms from other nations could also be targeted. It did not mention Russia.

A move against Chinese entities or individuals before Xi’s trip, the officials said, is possible but unlikely because of the strain it could put on the top-level diplomatic visit, which will include a black-tie state dinner at the White House hosted by President Barack Obama.

“The Chinese government staunchly upholds cyber security, firmly opposes and combats all forms of cyber attacks in accordance with law,” Chinese Embassy spokesman Zhu Haiquan said in a statement.

He said China wants enhanced dialogue and cooperation with  the United States and that “groundless speculation, hyping up or accusation is not helpful to solve the problem.”

The  Russian Embassy did not respond to Reuters requests for comment.

The U.S. government has suffered a series of embarrassing cyber attacks in recent months, including one on the White House Office of Personnel Management (OPM) that potentially provided a treasure trove of data about government employees to foreign spies.

U.S. officials suspect that attack was linked to China, which has denied any involvement in hacking U.S. databases and says it too has been a victim of cyber attacks.

The sanctions Washington is currently considering would not target suspected hackers of government data, but rather foreign citizens and firms believed responsible for cyber attacks on commercial enterprises, one official said.

If taken, the action would be the administration’s  first use of an executive order signed by Obama in April to crack down on foreign hackers accused of penetrating U.S. computer systems.

The officials declined to name any potential targets, concerned that advance warning would allow them to hide assets.

One U.S. official said that sanctions imposed on individuals or companies would effectively cut them off from using the U.S. financial system, which could be a death-sentence for a serious business venture.

The official also said that entities or individuals from countries other than Russia or China could face sanctions.

Another U.S. official suggested that a decision on targeting Chinese entities could depend partly on whether diplomatic efforts, such as last week’s visit by White House national security adviser Susan Rice to Beijing last week, produce positive results going forward.

Assistant Secretary of State Daniel Russel visits China next weekend for further talks ahead of Xi’s U.S. trip in the second half of September.

STRAINED U.S.- RUSSIAN RELATIONS

U.S.-Russian relations have been deeply strained in recent years, notably by Russia’s March 2014 annexation of Crimea from Ukraine as well as its continued support for pro-Russian rebels fighting government forces in eastern Ukraine.

Cyber security was a major issue between China and the United States during the June Strategic and Economic Dialogue that gathers some of the top financial and foreign policy officials in the two governments.

“The United States, as we all know, has sharp disagreements with China over its actions in cyber space,” State Department spokesman Mark Toner told reporters on Monday.

“We have remained deeply concerned about Chinese government-sponsored cyber-enabled theft of confidential business information and proprietary technology from U.S. companies,” he added at his daily briefing.

White House spokesman Josh Earnest declined to confirm the United States was weighing sanctions against Chinese entities, though he said U.S. cyber security concerns were “not a surprise” to Beijing.

“It would be strategically unwise for us to discuss potential sanctions targets because that would only give the potential targets of sanctions the opportunity to take steps that would allow them to evade those sanctions,” he told reporters aboard Air Force One.

He said an executive order signed by Obama in April provided “an additional tool in the toolbox to confront this particular challenge.”

View the original content and more from this author here: http://ift.tt/1Jtqoq5



from cyber security caucus http://ift.tt/1X9pE30
via IFTTT

State to focus on cybersecurity

Russian and Chinese hackers, beware! California’s preparedness and response to destructive cyberattacks is being beefed up by the state government.

Cyberattacks increase the state’s vulnerability to economic disruption and can cause infrastructure damage, privacy violations and identify theft.

In answer to those worries, the state is forming what’s being called the Cybersecurity Integration Center, or CSIC.

It’s being made responsible for strengthening the state’s cybersecurity strategy and improving inter-agency, cross-sector coordination to reduce the likelihood and severity of cyber-attacks.

CSIC is to work closely with the State Threat Assessment System and the U.S. Department of Homeland Security. It’s also to facilitate more integrated information sharing and communication with local, state and federal agencies, tribal governments, utilities and other service providers, academic institutions and non-governmental organizations.

CSIC will also establish a multi-agency “Cyber Incident Response Team” to serve as the state’s primary unit to lead cyber threat detection, reporting, and response in coordination with public and private entities across the state.

View the original content and more from this author here: http://ift.tt/1X9pSXI



from cyber security caucus http://ift.tt/1X9pCYL
via IFTTT

FTC’s Authority in Cybersecurity Cases Resoundingly Confirmed

In a widely anticipated opinion, the Third Circuit on August 24, 2015, left no doubt about the Federal Trade Commission’s (FTC) authority to prosecute cybersecurity actions. The Court determined in FTC v. Wyndham1 that:

  • The FTC could prosecute cybersecurity cases under the unfair or deceptive acts provisions of The Federal Trade Commission Act (FTCA)

  • The FTC’s past investigations and publications (and the statute itself) provided sufficient notice to businesses of potential liability under the Act

In short, the era of FTC investigations of and enforcement actions against businesses relating to the implementation and execution of appropriate cybersecurity protection measures is here.

Facts

The Wyndham case arose from multiple cybersecurity breaches suffered by Wyndham Worldwide Corporation in 2008 and 2009. The FTC brought an action against Wyndham contending that it engaged in unfair cybersecurity practices that “taken together, unreasonably and unnecessarily exposed consumers’ personal data to unauthorized access and theft.” Specifically, the FTC charged that the defendant:

  • Improperly stored payment card information

  • Allowed the use of easily guessed passwords to access property management systems

  • Failed to use available security measures such as firewalls

  • Failed to implement cybersecurity policies and procedures (including the use of an obsolete operating system)

  • Failed to maintain an adequate inventory of computers connected to its network

  • Failed to restrict access to cyber information

  • Failed to institute measures to detect and prevent unauthorized access

  • Failed to follow proper incident response procedures

Unfairness

The defendant argued that cybersecurity practices could not be determined to be unfair under the FTCA. The Court found that a determination by the FTC that a particular practice “causes substantial injury to consumers” was sufficient to be deemed unfair. The FTC also made short work of the defendant’s argument that an unfair practice also must be inequitable, noting that “[a] company does not act equitably when it publishes a privacy policy to attract customers who are concerned about data privacy, fails to make good on that promise by investing inadequate resources in cybersecurity, exposes its unsuspecting customers to substantial financial injury, and retains the profits of their business.” Wyndham, p. 17. The Court also noted that unfair acts might include deceptive acts under the statute and that such claims “may be brought on the basis of likely, rather than actual, injury.”

Notice

Having determined that the FTC has the authority to prosecute cases regarding cybersecurity issues, the Court next turned to whether the defendant received proper notice of its potential liability under the FTCA. The Third Circuit confirmed that proper notice had been given because the FTC had frequently publicized its beliefs that cybersecurity practices could be determined unfair under the statute through public statements, publicized prosecutions and investigations, the FTC’s website, and the Federal Register. Further, the Court held that because the statute was civil rather than criminal, the standards for fair notice are lax. The less stringent standards were held particularly applicable where the statute regulates economic issues. The Court found that “[f]air notice is satisfied here as long as the company can reasonably foresee that a court could construe its conduct as falling within the meaning of the statute.”

View the original content and more from this author here: http://ift.tt/1JIOfBv



from cyber security caucus http://ift.tt/1JIO9d8
via IFTTT

California Governor Creates Cybersecurity Agency To Prevent Attacks On State Agencies

SACRAMENTO, Calif. (AP) – Gov. Jerry Brown ordered the creation of a new security center Monday that will be responsible for strengthening online security to prevent cyber-attacks on state agencies.

Brown signed an executive order to create the California Cybersecurity Integration Center to help reduce the likelihood of online attacks that that could leave the state and its residents vulnerable to data breaches.

The center will serve as a central hub for the state’s online security and coordinate with state departments, federal agencies and tribal governments, utilities and other service providers, academic institutions and non-governmental organizations, Brown said.

The center, which will be a branch of the Governor’s Office of Emergency Services, will also establish a multi-agency response team to provide warnings of cyber-attacks and asses the state agencies’ risk of falling victim to one.

The announcement comes a week after the state auditor reported many state agencies are not complying with California’s information technology standards, leaving them vulnerable to a major security breach of sensitive data such as Social Security numbers, health information or tax returns.

In her report, auditor Elaine Howle said she found many agencies have not sufficiently planned for interruptions or disasters and that the agency in charge of ensuring compliance with IT standards, the Department of Technology, has failed to ensure agencies are complying.

View the original content and more from this author here: http://ift.tt/1JyAkB0



from cyber security caucus http://ift.tt/1Ju053d
via IFTTT

Monday, 31 August 2015

Is Ashley Madison Hack Story More About Cybersecurity Or Infidelity?

The long-awaited Ashley Madison data release came Tuesday as hackers dumped some 9.7 gigabyte’s worth of user information on the dark web.

A lot of files – which includes user account credentials, billing records and sexual fetishes for some 37 million customers of the infidelity site – has been circulating online Tuesday in the form of a massive, 10-gigabyte torrent.

A separate analysis of the data found that the city with the highest concentration of Ashley Madison users was Washington DC, and that some 15,000 email addresses involved were hosted on US government and military servers.

“We are actively monitoring and investigating this situation to determine the validity of any information posted online and will continue to devote significant resources to this effort”, said social media director Anthony Macri.

“We have explained the fraud, deceit, and stupidity of ALM and their members….” Sony had to cancel the much-anticipated release of the comedy film The Interview previous year after hackers threatened action if the film was released theatrically.

But he stressed that an email address on the dating database is not proof the person associated with it ever registered with or visited the site, because Ashley Madison did not use an email verification system to check users are linked to that address.

Up to 700 Australian government and police workers have been revealed as account holders on the Ashley Madison dating web service, following a leak by hacking group Impact Team. “Now everyone gets to see their data”, the group wrote in its data dump.

According to Trustify’s Danny Boice, he claims that they are getting about one search per second, and that there are just as many men using the tool as there are women. “If that distinction matters”.

Avid Life has once hoped to raise up to $200 million by going public in London in 2015. “Then move on with your life”, the statement read. However, Ashley Madison does not require users verify their addresses, so conceivably, anyone can sign anyone else up.

“This dump appears to be legit”, said David Kennedy, CEO of information security company TrustedSec, which monitors cyber attacks, in a blog post. In its statement, Avid Life Mediaaccused the hackers of seeking to impose “a personal notion of virtue on all of society”

View the original content and more from this author here: http://ift.tt/1O30uNh



from cyber security caucus http://ift.tt/1KxPKaO
via IFTTT

The CryptoLocker virus and cybersecurity

Cody Gough, Brian’s producer, tells the tale of how his computer was infiltrated by a CryptoLocker virus, a ransomware trojan that resulted in a Bitcoin ransom, conversations with federal authorities, and more drama than you would ever expect from your average computer virus. Learn about the Cryptolocker virus, ways to protect yourself from it, and what happened to Brian’s intrepid producer! Plus, hear a more detailed background on the situation on Cody’s podcast on WGN Plus.

View the original content and more from this author here: http://ift.tt/1O30uNe



from cyber security caucus http://ift.tt/1KxPKaM
via IFTTT