Showing posts with label Jennifer Johnson. Show all posts
Showing posts with label Jennifer Johnson. Show all posts

Monday, December 18, 2017

New Study: Many Consumers Lack Understanding of Basic Cyber Hygiene

Data breaches have been a headache for many years and for a long time there seemed to be a general apathy about them. Our sense was that things may have changed in the wake of the most severe breach ever – the theft of 145 million social security numbers and other sensitive data from Equifax – which leaves most Americans with the burden of having to monitor for identity theft for the rest of their lives.

Against this backdrop, we decided to find out how aware Americans are of cybersecurity threats and risks, how concerned they are about getting their information stolen, and what they might be doing, or more importantly, not doing about it. We also wanted to learn if recent breaches have caused Americans to change their behavior at all. Tenable recently commissioned a survey, conducted online by Harris Poll of more than 2,000 U.S. adults, to determine how data breaches – and media attention around them – are impacting consumers’ perceptions about their online security and their behavior.

Going into this project, our hypothesis was that because of all the recent breaches, Americans are more aware of security breaches than they were in the past, but that they likely continue to use poor security practices. The results are worse than we anticipated. According to the survey, more than 9 in 10 Americans (94%) have heard news stories about security breaches in the past 12 months, but among them, more than 2 in 5 (43%) have not changed their online habits as a result of these stories. This suggests many Americans may not understand that they have a role in accountability when it comes to taking specific actions to safeguard their personal data.

Cyber illiteracy is rampant

While many Americans are aware of breaches in the news, it appears that about 1 in 5 (21%) aren’t sure if they have been impacted by security breaches in the past 12 months. Only 12 percent of Americans say their personal information has been stolen by hackers due to a security breach in the past 12 months. But given that the Equifax breach exposed sensitive data of as many as 143 million Americans, that number is statistically impossible. Given the Yahoo! breach and countless others, this data suggests an alarming lack of understanding about the pervasiveness of recent breaches and the risks they pose to average Americans. It’s cyber illiteracy.

While most Americans (94%) have heard of news stories about security breaches in the last year and a majority say they are worried about risks associated with activities as basic as use of public Wi-Fi hotspots and online shopping, many still have not taken some critical steps to protect their data. For example, only 25 percent of Americans have implemented two-factor authentication on their devices to protect their personal information in the past 12 months, even though security experts and major online services and technology companies like Facebook and Google strongly encourage it. Although more than 2 in 3 Americans (68%) say they have avoided opening links/attachments from unsolicited emails or texts in the past 12 months, we suggest more Americans do this as this has been an industry best practice for security since the early 2000s. In addition, only about 3 in 10 Americans who have heard of any news stories on security breaches in the past 12 months (32%) have reduced their use of public Wi-Fi or unknown hotspots as a result, which could mean many still frequently do this – a major no-no.

Many Americans do not seem very confident about the security of their data, as nearly 2 in 5 (37%) said they think it’s likely their personal information will be stolen as a result of a security breach in the next six months. Additionally, it appears many Americans are worried about their personal information getting stolen as a result of some of the most common online activities. While 63 percent are worried about their data getting stolen when connecting to public or unknown Wi-Fi hotspots, nearly 3 in 5 (58%) are worried about their personal information being stolen when online shopping, half (50%) are worried when banking online, and 35 percent are concerned when connecting with their friends/family through social media.

Roughly one in two Americans lacks basic cyber hygiene

The survey demonstrates that nearly all consumers are aware of security breaches, but many do not take some basic precautions to protect their data. In the past 12 months, only 56 percent of Americans have used a password to lock their computer and only 45 percent use a PIN to lock their mobile devices. Roughly half of Americans (53%) say they have made their account passwords more complicated in the past 12 months, and 15 percent have used a password management tool. Another emerging authentication technology – biometrics – is still not widespread, with only 19 percent of Americans reporting that they have implemented it on their devices in the past 12 months. This is a surprising result given the fact that Apple has offered the user’s thumbprint as a security measure since 2013.

Even when the minimal is offered, Americans may not be capitalizing on some of the easiest ways to stay on top of their personal cybersecurity. Using credit monitoring services, which Equifax and other breach victims offer for free for a year, is one of the many ways to monitor for identity fraud. So we were surprised to find that so few Americans have signed up for such a service. Only roughly one-quarter of Americans (26%) have used a credit monitoring service to protect their personal information in the past 12 months, and only 12 percent have used an identity monitoring service.

Another basic tactic is to update, update, update and FAST! Apps that are downloaded onto devices can offer a popular inroad for hackers to compromise devices and steal data if the apps have security vulnerabilities, which is fairly common. Hackers who uncover the security weaknesses can exploit them only as long as they haven’t been patched. So, minimizing that window of opportunity is key to staying safe. While some Americans seem to be trying to stay on top of their software updates, many still aren’t updating their apps in a timely manner when the updates are available. Fourteen percent of smartphone users wait more than a week to update apps on their smartphone (or never do it) after receiving a prompt. Meanwhile, 13 percent of computer users wait more than a week to update the apps on their computer – including 3 percent who wait longer than a month after receiving a prompt to do so and 5 percent who don’t update apps on their computer at all.

Consumer security checklist

  1. Where applicable, enable two-factor authentication for all online services.
  2. Update your apps and computers within 24 hours of receiving a notification.
  3. Assign strong passwords to your computer, mobile phone and tablet – and don’t share them with others.

What does this mean for enterprises?

Organizations are scrambling to shore up their defenses in light of all the breaches, as they should be. But they also need to lead the way in basic security practices that keep their customer and critical business data safe. It seems there is a need for a “top down” approach where organizations provide comprehensive cybersecurity, but also team up with customers and employees to educate them about what they can do extend their best practices across their own personal attack surface. This starts with companies being more transparent about their own security practices and holding themselves accountable for lapses. If they don’t make security a top business priority and they aren’t sensitive to these changing consumer patterns and needs, they risk losing customers. Today, being customer-focused isn’t just about making good products; it’s about listening to customers and making sure the products and services they are using don’t cause them harm.

The irony is that cyber poses an existential threat to our economy and our very social fabric – safeguarding ourselves is therefore a shared responsibility. Enterprises must lead the way by practicing fundamental hygiene and enforcing a basic standard of care for their customers’ data. But individuals must do their part, too – both as consumers and, in many cases, as employees of those same enterprises – and that starts with cyber literacy. 

Survey methodology:

This survey was conducted online within the United States by Harris Poll on behalf of Tenable from November 28-30, 2017 among 2,196 U.S. adults ages 18 and older. This online survey is not based on a probability sample and therefore no estimate of theoretical sampling error can be calculated. For complete survey methodology, including weighting variables and subgroup sample sizes, please contact Sarah Spitz of Bateman Group at 347-382-9731. 

The post New Study: Many Consumers Lack Understanding of Basic Cyber Hygiene appeared first on Security Boulevard.



from New Study: Many Consumers Lack Understanding of Basic Cyber Hygiene

Sunday, July 23, 2017

Cyber Exposure: The Next Frontier for Security

The stakes have never been higher when it comes to cybersecurity. Global cyber attacks such as the recent WannaCry ransomware attack is a sobering reminder that cybersecurity is the existential threat of this generation. A new report from Lloyd’s of London estimates a serious cyber attack could cost the global economy more than $120 billion - as much as catastrophic natural disasters such as Hurricane Katrina and Sandy. According to the report, the most likely scenario is a malicious hack that would take down a cloud service provider at an estimated loss of $53 billion. With all of the attention and the hundreds of vendors in the security industry, why are we still here in this same situation, with it only getting worse and more severe?

The reality is these "future" technologies and compute platforms, such as IoT and cloud, are no longer the future. They are here and now. This means the cyber attack surface is no longer a laptop or a server in a data center. According to Business Intelligence, there will be nine billion active IoT devices in the enterprise by 2019. That’s more than the entire smartphone and tablet markets combined. According to a 2016 IDG Enterprise Cloud Computing Survey, over 90 percent of organizations either have applications running in the cloud today or are planning to adopt cloud applications in 2017. We’re also seeing development shifts such as DevOps become mainstream, and with that comes the rise of containers and microservices as a way to make changes to smaller parts of the application in a more agile way. According to 451 Research, the container market is the fastest growing market of cloud-enabling technologies, with a CAGR of 40 percent through 2020, growing from $762 million to $2.7 billion by 2020.

So What Do We Do in Response?

We throw hundreds of tools at the problem, each designed to protect the organization from a nice, many times advanced "threat of the week" style attack. We have Configuration Management Databases (CMDBs) which give the organization an IT view of assets and configurations, but weren’t built to keep pace with modern assets and aren’t a security view. Vulnerability Management (VM) technologies are used by most organizations to scan the network to identify issues, but the problem with legacy VM tools is they are a "one size fits all" approach designed in the world of client/server and on-premise data centers which only assess "known" assets which are running at the time of the scan or that can have an agent deployed on them.

We are in the new, modern world of IoT, cloud, SaaS, mobile and DevOps, which means organizations need to approach understanding their cyber risk in a way that adapts to this new world of modern assets. For example, IoT and mobile devices may be undetectable with traditional tools, containers and cloud workloads which, as opposed to other types of assets that have lives of months to years, may have a life of minutes to hours, making them extremely hard to see and protect. There are also safety-critical infrastructure and Operational Technology like Industrial Control Systems which are a rising attack vector. These systems were designed to be walled off from the network and isolated from threats, and therefore not designed for frequent change or software deployments. As software permeates through every industry, these Industrial IoT devices which are now connected devices need to be protected but the old way is too intrusive.

Welcome to the Era of Modern Cyber Exposure

We believe that Cyber Exposure is the next frontier for empowering organizations to accurately understand, represent and ultimately reduce their cyber risk against the rapidly changing modern attack surface. Cyber Exposure transforms security from a static or fragmented view to live and holistic visibility across every asset - whether that’s IoT or traditional IT devices, cloud infrastructure or Industrial Control Systems. From this live picture then you can start to accurately assess and analyze these assets for areas of exposure. This could be misconfigurations but it could also be other hygiene types of health indicators such as out-of-date antivirus or flagging high-risk users. By correlating this information with additional sources data, such as a CMDB or threat intelligence, you can get a more complete picture of the business criticality and severity of the issue to prioritize remediation and work with IT to fix it.

Cyber Exposure is analogous to IT Service Management and how the execution of ITSM processes is supported with specialized software technology. At the core of ITSM software suites are a workflow management system (service desk) for managing incidents and maintaining a knowledge base system of record, and a Configuration Management Database (CMDB) for discovering and mapping Configuration Items and their dependencies. Bringing these technologies together creates an intuitive way to link incidents with change and service requests together, but also provides a view of business services and the underlying IT infrastructure to help accelerate troubleshooting and change impact analysis, for example. Just as ITSM provides a process for planning, delivering and operating IT services to better support customers, Cyber Exposure provides a discipline and a process for managing and measuring cyber risk against the modern attack surface. This will help security and IT teams collaborate to more effectively and efficiently identify and resolve issues, but will also provide an objective way for the CISO, CIO and the business to measure cyber risk and use it for strategic decisions and planning. Cyber Exposure technologies will provide the data, visualization, process management and metrics to help drive a new way to manage security to reduce risk, make better business decisions and actually enable digital transformation instead of being the impediment to it.

Communicating Cyber Risk to the Board

There has also been a lot of conversation around cybersecurity awareness and readiness within the C-suite and the board of directors: how do you represent and communicate cyber risk in non-technical, business terms? Today the CISO has to translate a mountain of data in multiple spreadsheets into intuitive insights the business can use to make decisions from. Cyber Exposure will help the CISO drive a new level of dialogue with the business. If you know which areas of your business are secure - or exposed - and you can measure your organization against a larger set of data. This opens up a whole new set of discussions and decisions about where the organization needs to focus, how much and where to invest to reduce risk to an acceptable amount and help drive strategic business decisions. Every function has its organizational system of record to manage, measure and predict the business exposure relevant to that function, for example, CRM for revenue and forecasting exposure, ERP for financial and supply chain exposure and Human Capital Management (HCM) for employee satisfaction and attrition exposure. Imagine a future where every strategic business decision factors in Cyber Exposure data as a key risk metric, just as the business does with all of these types of exposure. We believe the future doesn’t need to be in the future.

We’re excited to apply our years of expertise and knowledge in understanding assets, networks and vulnerabilities to usher in this new modern era of Cyber Exposure. And we’re just getting started...



from Cyber Exposure: The Next Frontier for Security