Wednesday, 2 September 2015

California, Virginia Take Steps to Bolster Cybersecurity Stance

Two governors, on opposite sides of the country, took executive action to beef up cybersecurity in their respective states on Monday, Aug. 31. California Gov. Jerry Brown and Virginia Gov. Terry McAuliffe both instituted aggressive cybersecurity orders to prepare for and defend against potentially damaging cyberattacks in their states.
While both mandates are geared toward the implementation of better cyberprotection protocols, Brown’s order outlined the need for a multi-stakeholder California Cybersecurity Integration Center (Cal-CSIC) under the state’s Office of Emergency Services (OES).
Brad Alexander, spokesperson for the OES, said the newly announced center will serve as a single location for cyberthreat reporting and will help to ensure best practices are adopted across the state’s public and private sectors.
“The governor’s order will strengthen the integration between cyberintelligence and law enforcement communities in California and will increase our ability to effectively prepare for, prevent and respond to cyberattacks. Such attacks are a very real threat to Californians and this order is the next step to increase the state’s security and decrease our vulnerabilities.” he said.
As part of the order, a Cyber Incident Response Team will also be created to coordinate with private and public stakeholders and law enforcement in the event of an incident.
According to the text of Executive Order B-34-15, “The Integration Center’s primary mission will be to reduce the likelihood and severity of cyberincidents that could damage California’s economy, its critical infrastructure or public- and private-sector computer networks in our state.”
Center stakeholders will include representatives from state information technology, education, health-care and law enforcement agencies, as well as representatives from federal agencies, like the FBI, the Department of Homeland Security and the U.S. Coast Guard.
Other members can be designated at the discretion of OES Director Mark S. Ghilarducci.
In Virginia, McAuliffe’s executive directive took a less extensive, but no less focused, approach to the state’s technology-based security and set a hard timeline for the Virginia Information Technologies Agency (VITA) to fully review the state’s cybersecurity risk management stance.
The IT agency will be responsible for taking a comprehensive inventory and reporting on data and computer systems to the governor’s office no later than Oct. 15, 2015. In addition to the general inventory, the agency is expected to prioritize risks and determine the sensitivity of the state data systems.
Virginia Secretary of Technology Karen Jackson and VITA are also obligated to make recommendations on statewide strategies to strengthen and modernize agencies’ cybersecurity profiles by Oct. 15, 2015. This is expected to include the completion of cybersecurity audits, risk mitigation and resilience plans and remediation plans with defined end dates.
“A key ingredient to building a new Virginia economy is a solid cyberinfrastructure,” said Gov. McAuliffe in a press release. “That is why it’s vital that the Commonwealth take the proper precautions to protect and safeguard the information entrusted to our care. I am proud to sign this directive, which initiates enhanced risk management processes that will increase our ability to mitigate the ever increasing flow of cyberthreats.”
According to the text of McAuliffe’s directive, VITA will also be held accountable for reporting the progress of statewide strategy implementation by Oct. 1, 2016.
“Cybersecurity is a responsibility shared by every level of government,” said Secretary Jackson in the release. “These risk mitigation steps will allow the Commonwealth to take a more strategic approach to securing our systems and data.”
Officials from the Virginia Office of the Governor and the Office of the Secretary of Technology were not immediately available to comment on this directive as of press time Tuesday.
View the original content and more from this author here: http://ift.tt/1L3HdYX


from cyber security caucus http://ift.tt/1L3Q0dz
via IFTTT

SageNet purchases Turnberry Solutions’ Cybersecurity Division

SageNet, a Tulsa-based network solutions provider, has acquired the cybersecurity division of Turnberry Solutions, an IT consulting service based in the Philadelphia area.

The purchase, which gives SageNet five additional employees, will help the firm provide top-of-the-line cybersecurity for its clients, said Daryl Woodard, CEO of SageNet.

“These guys are experts in the field,” he said. “It will take us to a much higher level.”

The five employees will continue to work in the Philadelphia area. The cost of the acquisition was not disclosed.

SageNet’s cybersecurity offerings now include security strategy, security assessments, audit and compliance assessments, risk management, cloud security, security intelligence, e-discovery, managed security programs and managed security operations.

Woodard said the acquisition also takes on the division’s existing clients, though the services will also be offered to SageNet’s clientele.

SageNet and Turnberry Solutions have also entered into strategic alliance under which SageNet will be the preferred supplier of cybersecurity solutions to Turnberry, and Turnberry will provide IT staffing solutions to SageNet clients.

SageNet manages communications at more than 160,000 locations for retail, health care, financial and energy companies, as well as public utilities, state lotteries and government agencies.

View the original content and more from this author here: http://ift.tt/1LTmoVM



from cyber security caucus http://ift.tt/1N1ZZUX
via IFTTT

China Amends Criminal Law Related to Data Privacy and Cybersecurity

On August 29, 2015, China’s legislature, the National People’s Congress, amended the Criminal Law, effective November 1, 2015. Among other things, the amendments modify and add several provisions related to data privacy and cybersecurity. We discuss some of these key amendments below.

  • Expanded criminal sanctions for illegal sale or provision of personal information. Previously, criminal sanctions for selling or providing personal information applied only to government personnel and certain sectors such as finance, telecommunications, transportation, education, and healthcare. Article 253 as amended now applies criminal sanctions to anyone who, in violation of relevant State rules, sells or provides the personal information of others if the circumstances are serious. The crime is punishable by fixed-term imprisonment of no more than three years and/or a fine. If the circumstances are “extremely serious,” the penalties are more severe: three to seven years imprisonment, plus a concurrent fine. The new amendments also provide that those who, in violation of relevant State rules, sell or provide personal information obtained in the course of conducting professional duties or providing services shall face penalties on the harsher end of the ranges described in the preceding paragraph.

  • New penalties on internet service providers. Under the new Article 286(a), network service providers (and responsible individuals therein) who fail to fulfill “information network security administration duties prescribed by laws and/or administrative regulations” and refuse to take remedial measures ordered by regulatory authorities face criminal liability — fixed-term imprisonment of no more than three years, criminal detention, or public surveillance, with a fine either concurrently with such punishment or in lieu thereof — if one of the following circumstances occurs: (1) illegal information is widely disseminated, (2) user information is divulged and the circumstances are serious, (3) evidence in a criminal case is lost and the circumstances are serious, or (4) other “serious” circumstances are involved. We understand the term “network service provider” to include both internet service providers (e.g., telecom companies) and internet content providers (including websites). While the breadth of the term “serious” creates certain challenges to interpretation, these new provisions are consistent with the Chinese government’s recent focus on disciplining activities in cyberspace.

  • Criminal liability for conducting and facilitating certain online activity. A new Article 287(a) explicitly provides criminal penalties for those who use information networks to (1) establish websites or communication groups to engage in illegal or criminal activities, (2) publish illegal information such as pornography or information regarding prohibited items (e.g., guns, illegal drugs), or (3) publish other information for the purposes of engaging in fraud or other illegal activities. Under a new Article 287(b), criminal penalties also may be applied to those who, with clear knowledge that another individual is using an information network to commit a crime, provides internet access, storage, hosting, or other technical support, or provides advertising, settlement of payments, and any other assistance for such crime.

These amendments come amidst a series of significant developments in China’s data protection and cybersecurity regime. (See, for example, our post on China’s recently published draft Network Security Law here, and another specifically on the implications of that draft law for data privacy in China

View the original content and more from this author here:  http://ift.tt/1JxvzFI



from cyber security caucus http://ift.tt/1hxml4T
via IFTTT

Putin: Russia-China ‘Partnership’ Stronger Than Ever Amid Cybersecurity Accusations, Economic Trouble

With his trip to China approaching, Russian President Vladimir Putin spoke to reporters about how the two countries recently fortified their relationship after years of discord. Putin, who is scheduled to travel Wednesday to China, said relations were at a “historic peak” as commonalities between the two have developed, despite “illegitimate Western restrictions,” Russian news outlet RT reported.

Schisms in the Sino-Russian relationship have persisted for decades because of ideological differences and an economic gap, but the two have found some common ground as trade amid increasing trade. Russian-Chinese gas supply and nuclear power deals have fostered closer cooperation.

“Our countries are consistently moving toward the creation of a strategic energy alliance,” Putin said.

Both also face potential U.S. economic sanctions in response to cybersecurity allegations. Putin said “illegitimate restrictions imposed by certain Western countries against Russia” have not affected the Russian-Chinese partnership.

Even with China’s recent economic decline, the country still remains Russia’s major trading partner, the Moscow Times reported. Putin said that he believes China has made a lot of progress in the past few decades and that has strengthened their partnership.

“The development road China has covered over these years is a path of successful economic reform and wise social policy. This experience is of great value for us,” Putin said.

While in China, Putin will take part in the celebration of the 70th anniversary of the end of World War II. Putin noted the two countries both try to preserve the history of the Holocaust and condemn those who deny its occurrence.

“Our two countries were allies in the fight against Nazism and Japanese militarism and bore the brunt of the aggression, and they not only withstood this battle, but won it, liberating enslaved peoples and bringing peace to the planet,” Putin said. “Efforts by certain countries to glorify and exonerate war criminals and their henchmen are an outrageous flouting of the Nuremberg and Tokyo trials.”

During the visit, Putin plans to also hold bilateral meetings with Chinese leadership regarding energy and other issues, Radio Free Europe reported.

View the original content and more from this author here: http://ift.tt/1NWtYP3



from cyber security caucus http://ift.tt/1N2023l
via IFTTT

After a quarter million iPhones hacked, a reminder ‘jailbreaking’ devices still not safe

For years, iPhone owners stripped their devices of Apple’s security settings, allowing the handsets to work overseas or run apps the company didn’t approve.

Many users thought the practice, known as “jailbreaking,” was harmless. But it frustrated Apple, which said it left the devices vulnerable to hackers.

Now, it turns out more than 225,000 of those phones have been hacked, according to cybersecurity company Palo Alto Networks this week. Each was a jailbroken device, the firm added, supporting Apple’s years-long warnings.

The cybersecurity researchers found the users’ breached information on the black market and estimated that 20,000 people had used the information to download apps and make fake purchases within apps. The users affected were in 18 different countries, including China, where the hackers were also located, the report said.

The hack is a double-edged sword for Apple: It validates its years-long campaign against jailbreaking, saying users who do so are violating their terms of service and opening their phones up to attackers. At the same time, it underscores how security flaws can be exploited by hackers, putting the words “iPhone” and “hacked” together in a story.

Apple, which is expected to announce new iPhones next week, took this opportunity to remind people this is why its phones come with security systems in the first place. “To protect our users from malware, we curate App Store content and ensure all apps in the App Store adhere to our developer guidelines,” an Apple representative said regarding the hack, which researchers are calling KeyRaider.

But as the trend continues, security experts say that both Apple and app developers must face a world in which users don’t accept the iPhone on the Cupertino, Calif.-based company’s terms.

As a result, warning users not to jailbreak their phones doesn’t do enough to protect their devices from hacking threats, said Adam Ely, an executive at Bluebox, a company that helps app developers protect their services from the abuses of hackers.

The reason, according to Stephen Coty, an executive at cybersecurity company Alert Logic, is that people will remain curious about what Apple isn’t allowing people to do on their devices. Additionally, Apple users may want apps that the company won’t make available, or they might just want to see how the gizmo works from the inside, he said.

Coty himself has disabled security protocols on some devices so that he could install cybersecurity testing tools for his work.

So, what of all the people who have jailbroken their phones?

Coty said they shouldn’t feel like they’re constantly about to be hacked. There are plenty of cybersecurity apps that can help protect the phone, once it’s been jailbroken.

“If you’re going to jailbreak and make those changes,” he said, “you should also secure yourself.”

View the original content and more from this author here: http://ift.tt/1LTmnRL



from cyber security caucus http://ift.tt/1hxml4E
via IFTTT

Tuesday, 1 September 2015

CMIT offers seminar on cybersecurity

CMIT Solutions of Appleton will host an educational seminar on cybersecurity from 4 to 6 p.m. Sept. 16 at the Appleton Yacht Club, 1200 S. Lutz Dr., Appleton.

Those in attendance will be given detailed information, guidance and training on how to secure and protect their network including strategies on preventing and recovering from a cybersecurity breach.

Small and medium-sized businesses are receiving more attention from cybercriminals because they tend to have weaker security and data encryption measures; to a hacker, every employee and workstation represents a possible entry point, which is why staff need to be trained to secure and protect company data; and malware, phishing attacks and social engineering tactics are on the rise.

View the original content and more from this author here: http://ift.tt/1X9pSXR



from cyber security caucus http://ift.tt/1JIO6Oq
via IFTTT

Exclusive: U.S. weighs sanctioning Russia as well as China in cyber attacks

The United States is considering sanctions against both Russian and Chinese individuals and companies for cyber attacks against U.S. commercial targets, several U.S. officials said on Monday.

The officials, who spoke on condition of anonymity, said no final decision had been made on imposing sanctions, which could strain relations with Russia further and, if they came soon, cast a pall over a state visit by Chinese President Xi Jinping in September.

The Washington Post first reported the Obama administration was considering sanctioning Chinese targets, possibly within the next few weeks, and said that individuals and firms from other nations could also be targeted. It did not mention Russia.

A move against Chinese entities or individuals before Xi’s trip, the officials said, is possible but unlikely because of the strain it could put on the top-level diplomatic visit, which will include a black-tie state dinner at the White House hosted by President Barack Obama.

“The Chinese government staunchly upholds cyber security, firmly opposes and combats all forms of cyber attacks in accordance with law,” Chinese Embassy spokesman Zhu Haiquan said in a statement.

He said China wants enhanced dialogue and cooperation with  the United States and that “groundless speculation, hyping up or accusation is not helpful to solve the problem.”

The  Russian Embassy did not respond to Reuters requests for comment.

The U.S. government has suffered a series of embarrassing cyber attacks in recent months, including one on the White House Office of Personnel Management (OPM) that potentially provided a treasure trove of data about government employees to foreign spies.

U.S. officials suspect that attack was linked to China, which has denied any involvement in hacking U.S. databases and says it too has been a victim of cyber attacks.

The sanctions Washington is currently considering would not target suspected hackers of government data, but rather foreign citizens and firms believed responsible for cyber attacks on commercial enterprises, one official said.

If taken, the action would be the administration’s  first use of an executive order signed by Obama in April to crack down on foreign hackers accused of penetrating U.S. computer systems.

The officials declined to name any potential targets, concerned that advance warning would allow them to hide assets.

One U.S. official said that sanctions imposed on individuals or companies would effectively cut them off from using the U.S. financial system, which could be a death-sentence for a serious business venture.

The official also said that entities or individuals from countries other than Russia or China could face sanctions.

Another U.S. official suggested that a decision on targeting Chinese entities could depend partly on whether diplomatic efforts, such as last week’s visit by White House national security adviser Susan Rice to Beijing last week, produce positive results going forward.

Assistant Secretary of State Daniel Russel visits China next weekend for further talks ahead of Xi’s U.S. trip in the second half of September.

STRAINED U.S.- RUSSIAN RELATIONS

U.S.-Russian relations have been deeply strained in recent years, notably by Russia’s March 2014 annexation of Crimea from Ukraine as well as its continued support for pro-Russian rebels fighting government forces in eastern Ukraine.

Cyber security was a major issue between China and the United States during the June Strategic and Economic Dialogue that gathers some of the top financial and foreign policy officials in the two governments.

“The United States, as we all know, has sharp disagreements with China over its actions in cyber space,” State Department spokesman Mark Toner told reporters on Monday.

“We have remained deeply concerned about Chinese government-sponsored cyber-enabled theft of confidential business information and proprietary technology from U.S. companies,” he added at his daily briefing.

White House spokesman Josh Earnest declined to confirm the United States was weighing sanctions against Chinese entities, though he said U.S. cyber security concerns were “not a surprise” to Beijing.

“It would be strategically unwise for us to discuss potential sanctions targets because that would only give the potential targets of sanctions the opportunity to take steps that would allow them to evade those sanctions,” he told reporters aboard Air Force One.

He said an executive order signed by Obama in April provided “an additional tool in the toolbox to confront this particular challenge.”

View the original content and more from this author here: http://ift.tt/1Jtqoq5



from cyber security caucus http://ift.tt/1X9pE30
via IFTTT