Widening gulf between perception and reality

April 2015 Information Security

The Cisco 2015 Annual Security Report, which examines both threat intelligence and cybersecurity trends, reveals that South African organisations must adopt an ‘all hands on deck’ approach to defend against cyber attacks. Attackers have become more proficient at taking advantage of gaps in security to evade detection and conceal malicious activity as evidenced by the recent attacks against the Gautrain and Eskom.

Greg Griessel, consulting systems engineer, security solutions, Cisco, South Africa.
Greg Griessel, consulting systems engineer, security solutions, Cisco, South Africa.

Defenders, namely security teams, must constantly improve their approach to protect their organisations from these increasingly sophisticated cyber attack campaigns. These issues are further complicated by the geo­political motivations of the attackers, conflicting cross-border data localisations and sovereignty requirements.

Cisco’s Security Manifesto

The report findings conclude that it’s time for South African corporate boards to take a role in setting security priorities and expectations. Cisco’s Security Manifesto, a formal set of principles, provides foundation to achieving security and can help corporate boards, secur­ity teams and the users in any organisation in the country, to better understand and respond to the cybersecurity challenges.

The manifesto’s principals are:

1. Security must support the business.

2. Security must work with existing architecture – and be usable.

3. Security must be transparent and informative.

4. Security must enable visibility and appropriate action.

5. Security must be viewed as a ‘people problem.’

Greg Griessel, consulting systems engineer, security solutions, Cisco, South Africa, says, “Security is now the responsibility of everyone within South African organisations, from the board room to individual users. Security leaders and practitioners need the support of the entire business to combat malicious actors who are increasing in their proficiencies to exploit weakness and hide their attacks in plain sight.

“To protect organisations against attacks across the attack continuum, CISOs need to ensure that their teams have the right tools and visibility to create a strategic security posture, as well as educate users to aid in their own safety and the safety of the business. Attackers have become more proficient in taking advantage of security gaps and are targeting unsuspecting South African users. At any given time, we should expect one percent of high-urgency vulnerabilities to be actively exploited while 56 percent of all OpenSSL ­versions are still vulnerable to Heartbleed.”

The attackers

Online criminals are expanding their tactics and morphing their messages to carry out cyber-attack campaigns and make it harder to detect them. The top three trends that Cisco’s threat intelligence uncovered are:

• Snowshoe spam: Emerging as a preferred strike method, attackers are sending low volumes of spam from a large set of IP addresses to avoid detection.

• Web exploits hiding in plain site: Widely used exploit kits are getting dismantled by security companies in short order. As a result, online criminals are using other less common kits to successfully carry out their tactics – a sustainable business model as it does not attract too much attention.

• Malicious combinations: Flash and JavaScript have historically been insecure on their own, but with advances in security, attackers are combining the weaker of the two parts. Flash malware can now interact with JavaScript to hide malicious activity by sharing an exploit between two different files: one Flash, one JavaScript. This type of blended attack is very hard to detect.

The users

Users are caught in the middle – not only are they the targets, but end-users are unknowingly aiding cyber attacks. Throughout 2014, Cisco threat intelligence research revealed that attackers have increasingly shifted their focus from servers and operating systems. This is because more users now are downloading from compromised sites leading to a 280% increase in Silverlight attacks along with a 250% increase in spam and malvertising exploits.

The defenders

Results from Cisco’s Security Benchmark Study, which surveyed Chief Information Security Officers (CISOs) and security operations executives at 1700 companies globally reveals a widening gap in defender intent and actions. Specifically, the study indicates that 75% of CISOs see their security tools as very or extremely effective. However, less than 50% of respondents use standard tools such as patching and configuration to help prevent security breaches and ensure that they are running the latest versions.

Heartbleed was landmark vulnerability last year, yet 56% of all OpenSSL versions are over 4.5 years old. That is a strong indicator that security teams are not patching.

While many defenders believe their security processes are optimised – and their security tools are effective – in truth, their security readiness likely needs improvement.

For a complete copy of Cisco’s Annual Security Research report go to www.cisco.com/go/asr2015





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Highest increase in global cyberattacks in two years
Information Security News & Events
Check Point Global Research released new data on Q2 2024 cyber-attack trends, noting a 30% global increase in Q2 2024, with Africa experiencing the highest average weekly per organisation.

Read more...
There is a SaaS for everything, but at what cost, especially to SMEs?
Editor's Choice Information Security Security Services & Risk Management
Relying on SaaS platforms presents significant cybersecurity risks as the number of providers in your landscape increases, expanding your attack surface. It is important to assess the strength of the SaaS providers in your chain.

Read more...
Addressing today’s mining challenges: cyber risks beyond IT
Editor's Choice Information Security Mining (Industry)
Despite the mining industry’s operational technology systems being vulnerable to cyberattacks, many decision-makers still see these threats as purely an IT issue, even though a breach could potentially disrupt mining operations.

Read more...
Get proactive with cybersecurity
Information Security
The ability to respond effectively to a cybersecurity breach is critical, but the missing piece of the puzzle is a thorough, proactive evaluation to ascertain weaknesses and identify any hidden threats.

Read more...
How to effectively share household devices
Smart Home Automation Information Security
Sharing electronic devices within a household is unavoidable. South African teens spend over eight hours per day online, making device sharing among family members commonplace. Fortunately, there are methods to guarantee safe usage for everyone.

Read more...
How to securely manage your digital footprint
Information Security Training & Education
Managing your online presence is critical to safeguarding your privacy and security. It is imperative to take a proactive approach, including using robust cybersecurity best practices.

Read more...
The state of code security in 2024
Information Security
The 2024 State of Code Security survey reveals that organisations have continued to shore up application security defences over the last year, according to OpenText Premier Partner iOCO Application Management.

Read more...
What is the level of safety and integrity of the software supply chain?
Information Security IoT & Automation
Organisations are embracing AppSec practices and focusing on their software security posture. However, they highlight that insufficient funding and security resources, plus a disconnect between developers and security teams, remain major roadblocks.

Read more...
Cybercriminals target financial service providers to get at sensitive client data
Information Security
According to Ryan van de Coolwijk, Product Head for cyber at iTOO Special Risks, hackers target financial service providers because they hold sensitive client information that unauthorised individuals could use for fraudulent activities.

Read more...
Fortinet establishes new point-of-presence in South Africa
News & Events Information Security
Fortinet has announced the launch of a new dedicated point-of-presence (POP) in Isando, Johannesburg, to expand the reach and availability of Fortinet Unified SASE for customers across South Africa and southern African countries.

Read more...