{"id":23428,"date":"2016-07-22T18:55:31","date_gmt":"2016-07-22T10:55:31","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=23428"},"modified":"2016-07-24T15:02:43","modified_gmt":"2016-07-24T07:02:43","slug":"special-report-cybercrime-pandemic-no-single-company-can-fight-alone","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2016\/07\/22\/special-report-cybercrime-pandemic-no-single-company-can-fight-alone\/","title":{"rendered":"SPECIAL REPORT | Cybercrime: A pandemic which no single company can fight alone"},"content":{"rendered":"<p><strong>Ginni Rometty, IBM CEO, once said, \u201cwe need to think about security like a human immune system. Without a healthy one, you are susceptible to all kinds of diseases.\u201d\u00a0<\/strong><\/p>\n<p>Indeed, the increasing number of cyberattacks happening everyday is proof that the information systems of companies and government organizations aren&#8217;t \u201chealthy,\u201d as many have been vulnerable to all kinds of attacks, from website hacking to ransomware.<\/p>\n<p>\u201cCybercriminals rely on exploiting known vulnerabilities to conduct their attacks \u2013 this is due to the fact that many organizations are slow to implement software updates on their corporate computers,\u201d said Yury Namestnikov, Senior Security Researcher at <a href=\"http:\/\/www.kaspersky.com.ph\/?domain=kaspersky.com\">Kaspersky Lab<\/a>, in an email interview with <em>UpgradeMag.com.<\/em><\/p>\n<p>A new study conducted by <a href=\"http:\/\/www.upgrademag.com\/web\/cyber-threats-ph-increases-48-says-trend-micro\/\">Trend Micro<\/a> reveals that cyber threats in the Philippines increased at an alarming rate of 48 percent in the second quarter of 2016 compared to the previous quarter, with the banking and finance industry mostly affected. Online attacks for online banking credentials of users in the Philippines have increased, currently accounting for 8% of online banking attacks across its client base globally.<\/p>\n<p><span lang=\"EN-US\"><span style=\"color: #000000; font-family: Times New Roman;\">The security firm revealed that in the Philippines, the most favored industries of cyber criminals are banking and financial services industry (FSI), followed by information and communications technology, manufacturing, and transportation.<\/span><\/span><\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/Fireeye-Cyber-Attack-Chart.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-23434\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/Fireeye-Cyber-Attack-Chart.jpg\" alt=\"Fireeye Cyber Attack Chart\" width=\"720\" height=\"405\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/Fireeye-Cyber-Attack-Chart.jpg 720w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/Fireeye-Cyber-Attack-Chart-300x169.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/Fireeye-Cyber-Attack-Chart-195x110.jpg 195w\" sizes=\"auto, (max-width: 720px) 100vw, 720px\" \/><\/a><\/p>\n<p>The speed in which cybercrime is committed is also alarming. In 93 percent of cases, it took attackers minutes or less to compromise systems and data exfiltration occurred within minutes in 28 percent of the cases, according to the Verizon 2016 Data Breach Investigations Report.<\/p>\n<p>Elad Ben-Meir, VP for Marketing at Israeli-based IT security company, <a href=\"https:\/\/www.cyberint.com\">CyberInt<\/a>, notes that the Philippines is a favorite of cybercriminals because of its high exposure to social media and weak cybersecurity.\u00a0 Ben-Meir said that the Philippines ranks 7th in Asia Pacific for ransomware attacks, with an average of 17 attacks per day.<\/p>\n<p>Ben-Meir also said that the country\u2019s malware encounter rate is nearly double the global average at 29.1 percent.<\/p>\n<p>\u201cCyber security in the Philippines today is relatively poor,\u201d added Bryce Boland, Chief Technology Officer for Asia Pacific of FireEye, in an interview with <a href=\"http:\/\/upgrademag.com\">UpgradeMag.com<\/a><i>. <\/i>\u201cSome organizations do an adequate job, and a select few do a good job, but most organizations remain exceptionally vulnerable to advanced cyber attacks.\u201d<\/p>\n<div id=\"attachment_23429\" style=\"width: 310px\" class=\"wp-caption alignleft\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/canstockphoto30019921.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-23429\" class=\"size-medium wp-image-23429\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/canstockphoto30019921-300x300.jpg\" alt=\"CREDIT: CanStockPhoto\" width=\"300\" height=\"300\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/canstockphoto30019921-300x300.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/canstockphoto30019921-150x150.jpg 150w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/canstockphoto30019921-768x768.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/canstockphoto30019921-50x50.jpg 50w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/canstockphoto30019921.jpg 800w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-23429\" class=\"wp-caption-text\"><strong><em>PHOTO CREDIT: CanStockPhoto<\/em><\/strong><\/p><\/div>\n<p><b>Wake-up call<\/b><\/p>\n<p>One of the most highlighted incidents in the Philippines this year was the hacking of the Commission on Elections website in March which leaked the personal data of 55 million Filipino voters, putting them at risk of identity theft.<\/p>\n<p>Another newsmaker which put the Philippines on the global spotlight around the same time was the <a href=\"http:\/\/www.upgrademag.com\/web\/malware-helped-hacker-fraudulently-transfer-money-bangladesh-bank-ph\/\">Bangladesh heist<\/a>. According to security experts at BAE Systems, malware was used to help an unknown attacker gain access to the Bangladesh Bank\u2019s (BB) SWIFT payment system and reportedly instructed an American bank to transfer money from BB\u2019s account to accounts in the Philippines. The attackers attempted to steal $951m, of which $81m is still unaccounted for.<\/p>\n<p>The aforementioned statistics and incidents make Philippines one of the countries with weak information technology systems. In fact, the Philippines is among the top 50 countries with hacked services listed in the <a href=\"http:\/\/www.upgrademag.com\/web\/massive-underground-market-selling-over-70000-hacked-servers-for-as-low-as-6\/\">xDedic site<\/a>, a global online marketplace where cybercriminals can buy and sell access to compromised servers for as little as $6 each.<\/p>\n<p>The xDedic marketplace, discovered by Kaspersky Lab and which appears to be run by a Russian-speaking group, listed, in May this year, 70,624 hacked Remote Desktop Protocol (RDP) servers for sale.<\/p>\n<div id=\"attachment_23433\" style=\"width: 310px\" class=\"wp-caption alignright\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/Luis-Pineda_IBM.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-23433\" class=\"size-medium wp-image-23433\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/Luis-Pineda_IBM-300x199.jpg\" alt=\"Luis Pineda, President &amp; Country General Manager, IBM Philippines\" width=\"300\" height=\"199\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/Luis-Pineda_IBM-300x199.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/Luis-Pineda_IBM-768x509.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/Luis-Pineda_IBM-84x55.jpg 84w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/Luis-Pineda_IBM.jpg 800w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><p id=\"caption-attachment-23433\" class=\"wp-caption-text\"><strong><em>Luis Pineda, President &amp; Country General Manager, IBM Philippines<\/em><\/strong><\/p><\/div>\n<p>\u201cThe current events highlighting the country\u2019s vulnerabilities served as a \u2018wake-up call,\u2019 putting security at the center of every business discussion,\u201d Luis Pineda, President &amp; Country General Manager, IBM Philippines, told <i>UpgradeMag.com.<\/i><\/p>\n<p><b>Prominent threats<\/b><\/p>\n<p>Citing a report from FortiGuard Labs, Jeff Castillo, <a href=\"https:\/\/www.fortinet.com\">Fortinet <\/a>Philippines Country Manager, said there are three prominent threats that are causing damaging impact to most institutions and enterprises in the Philippines: exploits, botnets, and malware.<\/p>\n<p>Castillo explained that hackers cast and install automated systems and software tools to exploit application vulnerabilities, and worse, to compromise corporate data.<\/p>\n<p>\u201cSurprisingly, the report revealed that utilizing exploits has dropped by 52 percent in the Philippines. Some exploits, however, are still rampantly used by hackers like SSH server key exchange overflow, WordPress pingback Dos and TCP split handshake exploit,\u201d said Castillo.<\/p>\n<p>Andromeda, on the other hand, is the top botnet in the country, followed by Zero access, H-worm, and Crypto botnet traffic.<\/p>\n<div id=\"attachment_1147\" style=\"width: 206px\" class=\"wp-caption alignleft\"><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/07\/Jeff-Castillo.png\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-1147\" class=\"size-full wp-image-1147\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2013\/07\/Jeff-Castillo.png\" alt=\"Jeff Castillo, Country Managing Director of Fortinet Philippines.\" width=\"196\" height=\"265\" \/><\/a><p id=\"caption-attachment-1147\" class=\"wp-caption-text\"><strong><em>Jeff Castillo, Country Manager,\u00a0Fortinet Philippines<\/em><\/strong><\/p><\/div>\n<p>The report also showed that 2016 opened a new era for more android malicious apps like WM\/TrojanDownloader.9BB7!trend and MS Windows Word Macros(WM). For example, Triada, another top mobile malware in the country redirects the money used in in-app purchases to the hacker. This Trojan modifies and integrates itself to a system, making it easier for threat actors to conduct their malicious operations.<\/p>\n<p>According to Symantec\u2019s latest Internet Security Threat Report (ISTR), the biggest security risks to companies today are: explosion of zero-day vulnerabilities; multiple attacks; and the increasing number of companies choosing to hold back critical details of a breach.<\/p>\n<p>\u201c2015 saw some of the largest data breach made public, but more companies are choosing not to reveal the full extent of the breaches they experienced,\u201d says Peter Sparkes, Symantec Senior Director for Cyber Security Services for Asia Pacific and Japan.<\/p>\n<p>\u201cThis disturbing trend could pose more problems to companies that hold back critical information. Transparency is critical to security. By hiding the full impact of an attack, it becomes more difficult to assess the risk and improve security posture to prevent future attacks.\u201d<\/p>\n<p>Other IT security threats identified by security experts interviewed by <a href=\"http:\/\/upgrademag.com\">UpgradeMag.com<\/a> are cyberespionage, intellectual property theft, reputational damage, fraud, and disgruntled employees.<\/p>\n<p>An IBM study\u00a0unveils that\u00a070% of CxOs think rogue individuals make up the largest threat to their organizations. The reality is that 80% of cyberattacks are driven by highly organized crime rings in which data, tools, and expertise are widely shared, according to a United Nations report.<\/p>\n<p>A breach can also be very costly, depending on the extent of damage caused. The average budget required to recover from a security breach is US$551,000 for enterprises and $38,000 for small and medium sized businesses, according to a<a href=\"https:\/\/press.kaspersky.com\/files\/2015\/09\/IT_Risks_Survey_Report_Cost_of_Security_Breaches.pdf\"> global report<\/a> released by Kaspersky Lab.<\/p>\n<p>Conducted in cooperation with B2B International in 2015, the survey reveals the most expensive types of security breaches are employee fraud, cyber espionage, network intrusion and the failure of third party suppliers.<\/p>\n<p><span lang=\"EN-US\"><span style=\"color: #000000; font-family: Times New Roman;\">Myla Pilao, Director of Core Technology Marketing at Trend Micro, says the growth in cyber attacks in the last six months was driven by three factors: poor device control, which remains to be the successful method of attacks; social engineering, considered as the second most favored attack in the Philippines; and insider information. <\/span><\/span><\/p>\n<p><span lang=\"EN-US\"><span style=\"color: #000000; font-family: Times New Roman;\">Pilao pointed out that the most prominent attack that hit the Philippines in the second quarter was data-stealing malware or breaches which accounted for 41% of Philippine infections. This attack, which arises from the use of old or legacy systems, gained prominence as it victimized more local industries.<\/span><\/span><\/p>\n<p><span lang=\"EN-US\"><span style=\"color: #000000; font-family: Times New Roman;\">\u201cLocal businesses are also still susceptible to old-school threats like file-infecting viruses and worms that spread through removable drives,\u201d Pilao notes<\/span><\/span><\/p>\n<p><span lang=\"EN-US\"><span style=\"color: #000000; font-family: Times New Roman;\">Apart from information-stealing threats, Trend Micro claimed that organizations worldwide were experiencing a rise in business email compromise (BEC) and targeted attacks. BECs are sophisticated scams carried out through business emails, while targeted cyber attacks are aimed specifically at a company, individual or software<\/span><\/span><\/p>\n<p><b>More dangerous<\/b><\/p>\n<p>According to Kaspersky Lab\u2019s Namestnikov, the tools used to attack businesses differ from those used against home users. In attacks on corporate users, exploits for office application vulnerabilities are used much more often, malicious files are often signed with valid digital certificates, and cybercriminals try to use legitimate software for their purposes, so they can go unnoticed for longer.<\/p>\n<p>\u201cWe have also observed strong growth in the numbers of corporate user computers targeted by ransomware. This also applies to incidents not classified as APT attacks, where cybercriminals merely focus on corporate users, and sometimes on employees of specific companies.<\/p>\n<p>\u201cThe fact that cybercriminal groups use APT methods and programs to attack businesses takes them to a different level and makes them much more dangerous. Cybercriminals have begun to use these methods primarily to steal large sums of money from banks. They can use the same methods to steal a company\u2019s money from bank accounts by gaining access to its corporate network,\u201d said Namestnikov.<\/p>\n<p>Namestnikov noted that cybercriminals also make use of signed malicious files and legitimate tools to create channels for extracting information. These tools include popular remote administration software, SSH clients, and password restoration software, among others.<\/p>\n<p><b>Mitigate the threat rather than the incident<\/b><\/p>\n<p>\u201cTodays threats have become more advanced, targeted, and attackers are much more organized. As a result, the skill and knowledge required to defend from threats have gone up. Unfortunately, the Philippines does not have many expert resources to meet the skills required for security,\u201d said IBM\u2019s Pineda.<\/p>\n<p>\u201cOne of the greatest defense against attacks is by educating employees and by creating awareness,\u201d said Pineda. Pineda also advises companies to establish a security governance program,\u00a0 implement continuos security monitoring, leverage incident forensics, and utilize threat intelligence to secure their environment.<\/p>\n<p>Pineda\u2019s comment on security talent is confirmed by statistics shared by CyberInt\u2019s Ben-Meir during a press conference to announce the company&#8217;s entry into the Philippines market. Ben-Meir\u00a0revealed\u00a0there are only 84 Certified Information Systems Security Professionals (CISSP) in the Philippines. In comparison, Malaysia has 275 CISSPs while the US has around 67,000.<\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/IMG_0198.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-23436\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/IMG_0198-1024x768.jpg\" alt=\"IMG_0198\" width=\"640\" height=\"480\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/IMG_0198-1024x768.jpg 1024w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/IMG_0198-300x225.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/IMG_0198-768x576.jpg 768w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/IMG_0198-600x450.jpg 600w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/IMG_0198-210x158.jpg 210w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2016\/07\/IMG_0198-390x293.jpg 390w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/a><\/p>\n<p>Given the scarcity of IT security talent in the Philippines today, what then, should companies do to mitigate attacks?<\/p>\n<p>\u201cLeaders must realize they&#8217;re up against real people, not technology. Determined attackers will eventually find a way in,\u201d comments FireEye\u2019s Boland.\u00a0 \u201cThe initial focus focus should be to ensure that they can detect the attacks. After that, they should turn to effectively responding to attacks. Very few organizations get that far. A few organizations go one step further and actively hung for attackers they are not aware of, but assure are there.\u201d<\/p>\n<p>For his part, Ben-Meir advises companies to \u201cmitigate the threat rather than the incident.\u201d This, he said, can be done in four phases: 1) identify early stage weaponization online; 2) detect\u00a0 phishing tools targeting customers and employees in social media; 3) spot hacked databases for sale; and 4) monitor and investigate exploitations.<\/p>\n<p>For <a href=\"https:\/\/www.symantec.com\">Symantec<\/a>\u2019s Sparkes, advanced analytics is key. \u201cAttackers are becoming more sophisticated and industrialized but companies are stuck on the same strategy,\u201d said Sparkes in an interview with<i> <\/i><a href=\"http:\/\/upgrademag.com\"><i>UpgradeMag.com<\/i><\/a><i>. <\/i>\u201cIn the past, analytics are effectively placed into a piece of software which a company can deploy. This used to work before. But to catch all of the advanced threats today, an organization needs to do more advanced analytics which cannot be done by software alone.\u201d<\/p>\n<p><b>Back to Basics<\/b><\/p>\n<p>Kaspersky Lab\u2019s Namestnikov lists the four basic strategies that reduce the possibility of a successful targeted attack:<\/p>\n<p>\u00b7 \u00a0\u00a0\u00a0\u00a0\u00a0Use application whitelisting to help prevent malicious software and unapproved programs from running<\/p>\n<p>\u00b7 \u00a0\u00a0\u00a0\u00a0\u00a0Patch applications such as Java, PDF viewers, Flash, web browsers and Microsoft Office<\/p>\n<p>\u00b7 \u00a0\u00a0\u00a0\u00a0\u00a0Patch operating system vulnerabilities<\/p>\n<p>\u00b7 \u00a0\u00a0\u00a0\u00a0\u00a0Restrict administrative privileges to operating systems and applications, based on user duties.<\/p>\n<p>\u201cSophisticated attacks offer lucrative rewards, that\u2019s why massive data breaches are continuously occurring. There is no silver bullet that could protect an organization perfectly. Once the malware is installed, it will be automatically controlled by cybercriminals, morph, adapt, and move freely undetected,\u201d stressed Fortinet\u2019s Castillo. \u201cFor optimal and powerful security, individual security products should function together as one.\u201d<\/p>\n<p>Gene Ng, Security Leader, IBM ASEAN, companies should look at their information and business critical systems from an attacker\u2019s point of view and then ask themselves how an attacker could do the most damage.<\/p>\n<p>\u201cA big chunk of risk factors are related to the people who operate, manage or even simply use any of the organizational services or assets,\u201d said Ng. \u201cMake sure your security program has ownership and leadership assigned across critical business areas. By expanding accountability and awareness across the company, the underlying and enforcement of the security controls are heightened \u2014 creating a more secure business environment.\u201d<\/p>\n<p>Pineda notes that a greater willingness for businesses, government organizations, and other parties to collaborate must be achieved to elevate the Philippines\u2019 defense against threats.<\/p>\n<p>\u201cThere is a dichotomy that needs to be resolved\u2014external parties need to do more, the government needs stronger oversight, industry collaboration must increase, and cross-border sharing must be strengthened,\u201d said Pineda.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ginni Rometty, IBM CEO, once said, \u201cwe need to think about security like a human immune system. Without a healthy one, you are susceptible to all kinds of diseases.\u201d\u00a0 Indeed, the increasing number of cyberattacks happening everyday is proof that the information systems of companies and government organizations aren&#8217;t \u201chealthy,\u201d as many have been vulnerable [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":23429,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15,19,22],"tags":[4609,4608,495,1558,169,214,286,117,1591,274],"class_list":["post-23428","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-business","category-headlines","category-spotlight","tag-breach","tag-cyberint","tag-cybersecurity-and-cybercrime","tag-fireeye","tag-fortinet","tag-ibm","tag-it-security","tag-kaspersky-lab","tag-ransomware","tag-symantec"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/23428","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=23428"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/23428\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/23429"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=23428"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=23428"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=23428"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}