Why be concerned about Cyber Security?
The increasing number of internet users, availability of essential services such as banking and shopping on the Internet, heavy presence of individuals on social networking sites and lack of web surfing has made the cyberspace highly vulnerable. Vulnerabilities in the cyberspace, more often than not, are caused by software programming errors. Typically, criminal hackers have been focussed on web-based malware, such as the ZeuS Trojan, for over ten years. Most recently, the trend has been the increased frequency and evolving sophistication of cyber-attacks from bank accounts to corporate networks, such as attempts of account takeover, payment fraud and identity spoofing, around the world. The attackers use applications to breach security and create weak points in networks and even modify original data. Botnet, fast flux, zombie computer – social engineering, skimmers, phishing, Trojan attacks and logical bombing are some of the common methods that the attackers use to break into the systems. “It is not just governments and large organizations that fall victim to cyber-attacks, but also specific individuals within organizations. The nature of these attacks is swiftly becoming more targeted towards the individual. Apart from this, as these attacks become more targeted, they are also becoming more personalized,” explains Ambarish Deshpande, Managing Director – India, Blue Coat.
Dinesh Pillai
CEO
Mahindra Special Services Group
“The ‘National Cyber Security Policy 2013’ is a great step by Indian Government in the right direction.”
Apparently, in most cases, it is the human factor which has been found to be most susceptible. Hackers may choose to target either the systems using a variety of methodologies – SQLi, LFI, RFI and even DDOS. Alternatively, they may choose to target the individual with an array of attacks ranging from spear-phishing to social engineering, in order to gain a foothold into the network. It is baffling that many people are not even aware how cyberspace today is not a secure environment. Interestingly, an IDC report mentions that 50% of the Indian cyberspace can be easily hacked and when it comes to companies and organizations, 80% of them are most likely to experience some kind of cybersecurity threat or data loss. Nowadays, almost every data, be it personal or work related, is on the Cloud which makes us susceptible to hacker attacks
Dhanya Thakkar
Managing Director
India & SEA, Trend Micro
|The ‘National Cyber Security Policy 2013’ aimed at protecting the public and private infrastructure from cyberattacks was most certainly a step ahead in order to put some order to curb cybercrimes.
“Cyberspace is not at all a safe place. The larger it gets, the worse the security. It is a hacker’s playground and he has invented plenty of ways to do his work. From Trojan viruses to email propagation of malicious code, there are new ways of hacking entering the market almost daily,” explains Altaf Halde, Managing Director, Kaspersky Lab – South Asia. The most common method employed is to hack one’s identity by installing spyware, use viruses to crash your system, or use malware like Trojans to gain unauthorized access amongst other things. From a consumer perspective, following are the threats that are coming to light-
Altaf Halde
Managing Director
Kaspersky Lab -South Asia
From Trojan viruses to email propogation of malicious code, there are new ways of hacking entering the market almost daily.
• Mobile worms that infect devices with near-field communications (NFC) capabilities (which enable tap-and-pay purchases via kiosks), allowing criminals to access to the victims' wallet accounts
• Malware that blocks security updates to mobile phones, making it increasingly difficult to remove a virus or prevent another malware infection
• PC and mobile phone ransomware “kits” that allow criminals without programming skills to hold a system or smartphone hostage and extort payments from victims
Jagdish Mahapatra
MD for India and SAARC at McAfee, part of Intel Security
McAfee Cloud Security helps organizations safely and confidently leverages secure cloud computing services and solutions
• Covert and persistent attacks deep within and beneath operating system
• Rapid development of ways to attack Windows 8 and HTML5
• Large-scale attacks like Stuxnet that attempt to destroy infrastructure, rather than make money
• A further narrowing of attacks using the Citadel Trojan, enabling more targeted attacks with potentially bigger financial gain
• Malware that renews a connection even after a botnet has been taken down, allowing infections to grow again
• SMS spam sent from infected phones, increasing the possibility that a victim may have their account closed by their wireless provider
• "Hacking as a Service", where anonymous sellers and buyers in underground forums exchange malware kits and development services for money
• The decline of the online hacktivist group, Anonymous, to be replaced by more politically committed or extremist groups
Govind Rammurthy
MD & CEO
eScan
Funding for cyber-security should in fact be the last to be considered during budget cuts”.
Cybersecurity scenario in India
India is not at all safe from cyber-attacks. What is even more troubling is that cyberecurity skills development is also missing in India and we do not have the appropriate cyber professionals to deal with sophisticated cyber-attacks. More than 57 million people in India are online on an everyday basis and the number of smartphones users has reached close-to 225 million. It is extremely easy for hackers to target users in India, as they are completely oblivious of the dangers relating to cyberspace. The Frost & Sullivan report on network security market in India has forecasted a fast growth during the period 2012-19, and is expected to hit revenue of US$634 million in 2019, representing a stable CAGR of 15.3 per cent.
Michael Joseph
Manager System Engineering, India & SAARC, Fortinet
The policy has stressed on public-private partnership in tackling cyber threats through proactive measures besides creating a think tank for cyber security in future.
As per the cyber law in the country, cybercrimes can involve criminal activities that are traditional in nature, such as theft, fraud, forgery, defamation and mischief, all of which are subject to the Indian Penal Code. The abuse of computers has also given birth to a gamut of new-age crimes that are addressed by the Information Technology Act, 2000. Cyber complaints have been time and again registered under the law. There are various activities that constitute cybercrimes in India that include Hacking, Data theft, Identity theft, Spreading virus or worms and email spoofing which are the major pain points in terms of security.
“The ‘National Cyber Security Policy 2013’ aimed at protecting the public and private infrastructure from cyber-attacks was most certainly a step ahead in order to put some order to curb cybercrimes. The policy also intends to safeguard ‘information, such as personal information (of web users), financial and banking information and sovereign data’,” informs Dhanya Thakkar, Managing Director, India & SEA, Trend Micro. The policy reflects India’s increasing sensitization towards protection of personal information against cyber threats, but perhaps its greatest strength lies in how it offers great incentives to small and medium businesses to invest in security and encourages wider usage of Public Key Infrastructure within the government as well. Sharing his views, Dinesh Pillai, CEO, Mahindra Special Services Group, exerts, “This policy is a great step in the right direction. However, it has failed to protect the privacy rights of users in the country. It needs to be updated and improved at regular intervals for it to keep pace with technology and innovations. The policy also needs to be communicated rightly.” Most of the Internet users don’t realize online environment is like being on a razor’s edge. On the one hand, you need to be there and on the side you need to take steps. The implementation of such a policy clearly shows that the Indian Government is acknowledging the extent and effect of cyber-attacks and the implementation of the much-needed precautionary steps. Sudeep Charles, Product Marketing Manager, Akamai Technologies, adds, “We are yet to see a significant impact of the policy. However, this will change over a period of time as the right infrastructure, legal framework and workforce are formed.”
Tarun Kaura
Director, Technology Sales, Symantec India
“The adoption of BYOD (Bring Your Own Device) has led to an unprecedented increase in endpoints thus amplifying the accessibility of the corporate information on premise and outside the corporate network.
What is making Cybersecurity even more challenging?
Technology is redefining everything – the way work is conducted, the management of data centers, servers and the corporate network. Strong and growing trends such as the consumerisation of IT, Cloud and virtualization technologies and targeted, sophisticated cyber threats have introduced real challenges to the task of information security. In the context of the changing paradigms of IT delivery such as Cloud as well as new technologies like BYOD, mobility, web 2.0, etc, some complexities are highlighted that today’s IT administrators in enterprises are facing:
Cloud Computing: Many Indian organizations are looking for Cloud- like models, which means services are on an “on-demand” kind or self-services. They turn to technologies and solutions which can take the existing physical environment and deliver them in a Cloud-like manner. Security will remain the biggest topic in Cloud computing, especially as even more enterprises demand greater transparency and security controls from their Cloud providers. For Cloud, there are a few security solutions that are in place, although it is still nothing compared to the end-point security you yourself can implement. The idea is to keep your personal data as safe as you can and think twice before letting go of personal/sensitive information. If possible, make sure you check the security credentials of any website that is asking for sensitive information.
Sunil Sharma
VP Sales & Operations
India & SAARC, Cyberoam
CIOs should aim for and invest in security that will support every need including securing head-offices, remote offices, data centres’, virtual environments, BYOD visibility, and more with ease.
The recent Heartbleed attacks were an efficient reminder of just how unsafe websites like even ebay are when it comes to securing passwords. Cybercriminals are all very smart programmers and if we want to keep things secure online, we need to be smarter than them. And right now, prevention is the best defence. Jagdish Mahapatra, Managing Director for India and SAARC, McAfee, part of Intel Security, adds, “McAfee Cloud Security helps organizations safely and confidently leverage secure Cloud computing services and solutions. Rather than adopting the unique – and sometimes unknown – security practices and policies of each Cloud vendor, McAfee Cloud Security allows businesses to extend and apply their own access and security policies into the Cloud by securing all the data traffic moving between the enterprise and the Cloud, as well as data being stored in the Cloud.” Data that is secure in one country may not be secure in another. In many cases though, users of Cloud services don't know where their information is held. Agreeing to this, Michael Joseph, Manager System Engineering, India & SAARC, Fortinet, adds, “The policy has stressed on public-private partnership in tackling cyber threats through proactive measures and adoption of best practices besides creating a think tank for cybersecurity in the future. However, the policy is silent on provisions to address security risks emanating due to use of new technologies like Cloud Computing and Social Media networking.”
Sudeep Charles
Product Marketing Manager, Akamai Technologies
“We are yet to see significant impact of the policy, however, this will change over a period of time as the right infrastructure, legal framework and workforce are formed.
Enterprise Mobility and BYOD: With predictions that there will be more users connecting to the Internet on a mobile device in the next year, compared to a more traditional desktop or laptop, together with the massive explosion in applications, organizations will have to deal with Mobility and BYOD in the enterprise or risk total loss of control. Many organizations expect one single solution to help secure BYOD on an end-to-end basis which is practically not possible. Tarun Kaura, Director, Technology Sales, Symantec India, adds, “The adoption of BYOD (Bring Your Own Device) has led to an unprecedented increase in endpoints, thus amplifying the accessibility of the corporate information on-premise and outside the corporate network.” So, BYOD needs to be looked at from different dimensions like Data Loss Prevention, Network access Control, Authentication system, internal intrusion prevention systems, internal firewalls, securing Wi-Fi etc, it would demand for complete relook at the network and security architecture of an organization and rebuild to fit BYOD needs. On top of all is the internal IT policy which should be detailed and fool-proof to drive the initiative and guide effectively and prevent failure of specific tools. Security vendors should have a comprehensive approach towards addressing the BYOD needs of organizations.
Social Networking: Social Networking websites such as Facebook, Twitter and My-Space have been growing rapidly in the past few years with now over two billions users. Because of social networks large population and information base, and its simple accessibility, social networking websites have become new targets that attract cybercriminals. Privacy issue is one of the main concerns, since many social network users are not careful about what they expose on their social network space. The second issue is identity theft. Attackers make use of social networks account to steal victim’s identities. The third is the spam issue. Attackers make use of social networks to increase spam click through rate, which is more effective than the traditional email spam. The forth is the malware issue. Attackers use social networks as a channel to spread malware, since it can spread very fast through connectivity among users. Social networking sites are always facing a new kind of malware. Lastly, there are physical threats which are the most dangerous of the issues. Because of some of the social network features such as location-based service, it is easier for criminals to track and approach victims. Joe Sebastian, Co-Founder & COO, Webbzer, states, “Social networking sites try to implement different security mechanisms to prevent such issues, and to protect their users, but attackers will always find new methods to break through those defences. Therefore, social network users should be aware of all these threats, and be more careful when using them.”
Ranjit Nambiar
Director of Sales
HID Global
Online service providers should consider more complex solutions whilst in the current threat landscape, as even two factor authentication) may be insufficient.
Web 2.0 attacks: As Web 2.0 technologies continue to gain popularity amongst employees, IT departments are struggling to understand and manage the challenges. The Internet is an incredible productivity enhancer that you have to treat carefully. Although users can’t trust every link that people post or control, companies can put forward best practices to arm employees with the tools they need to be productive and safe. Between this type of education and technology that can block dangerous links and applications, Web 2.0 can be used safely for business. Ranjit Nambiar, Director of Sales, HID Global, shares, “Online service providers should consider more complex solutions whilst in the current threat landscape, as even two- factor authentication may be insufficient.”
Ashesh Thanawala
Sales Director – India & SAARC
SafeN
We at Safenet pride ourselves for protecting our customers every step of the way-from cyber security to data in the cloud, security has always been our main concern and an assured promise.
How essential is it to keep cybersecurity funding intact?
Cybersecurity is something that you just can’t play around with. In India, the idea has always been to only fix something after it is broken. With information security, that idea just cannot be the norm. Most times, it is way too late to be implementing security as the damage has already been done. Organizations need to keep their security up-to-date and even if that means the annual profit margins might be dropping due to allocation of funds for security, so be it. Pankaj Jain, Director, ESET India, says that data is money nowadays. Taking a hit on data is risking business, companies need to allocate handsome budget to ensure cybersecurity. Many times, companies do not take this seriously. In such a scenario, they have a high risk of loss in business in the long run. Cybersecurity is necessity.
Joe Sebastian
Co-Founder & COO
Webbzer
Social networking users should be aware of all the security threats, and be more careful when using them.
Investing in a secure and stable network not only helps an organization prevent such a situation, it also acts as a reassurance to its clients and customers that their information is safeguarded. Insurers in today’s economy are increasingly interested in how companies secure their information assets and this is a major talking point in discussions regarding renewal. Thus, this makes cybersecurity something organizations cannot afford to compromise on. Not only does consistent IT maintenance procedures and security practices enable efficient business operations, these practices also cut down on IT costs and vulnerabilities that exist in the system. Govind Rammurthy, MD & CEO, eScan, exerts, “Cybersecurity is proactive and needs constant update either with respect to knowledge or applications. Funding for cybersecurity should, in fact, be the last to be considered during budget cuts.”
Vishal Bindra
CEO
ACPL
As the attacks are getting sophisticated, a lot of technologies are getting commercialized and it needs our infrastructure to be also upgraded and updated with time.
A single breach could cause irreparable damage to a business even to the extent of businesses being wiped out or government losing out on secret information, banks losing customers, etc. Vishal Bindra, CEO, ACPL, comments, “As the attacks are getting sophisticated, a lot of technologies are getting commercialized and it needs our infrastructure to be also upgraded and updated with time. So even during an economic slowdown all required financial support must be made available to ensure security of information in the business.”
Ambarish Deshpande
Managing Director - India
Blue Coat
It is not just governments and large organizations that fall victim to cyber-attacks, but also specific individuals within organizations.
What is next?
Security has become a critical deliverable and a strategic aspect to ensure IT and Network transformation is achieved successfully. For most CIOs, security has become a catalyst element in driving IT-led reforms and change. Hence, there is a need to allocate adequate measure of investment in the right kind of security, which will enable long-term relevance to accommodate growing security needs and will also dovetail easily with existing infrastructure. Sunil Sharma, VP Sales & Operations, India & SAARC, Cyberoam, opines, “CIOs should aim for and invest in security that will support every need including securing head offices, remote offices, data centers’ virtual environments, BYOD visibility, centralized security management and more with ease.” Agreeing to this, Ashesh Thanawala, Sales Director – India & SAARC, SafeNet, adds, “It is advisable to understand that even though it is great to be updated with the latest technology but one must also be able to understand the risks attached with this and we, at Safenet, pride ourselves for protecting our customers every step of the way – from cybersecurity to data in the Cloud. Security has always been our main concern and an assured promise.”
Pankaj Jain
Director
ESET India
Data is money now-a-days. Taking a hit on data is risking business, companies need to allocate handsome budget to ensure cyber security.
Keeping all the security threats in mind, the Indian Government must take necessary steps before shifting public delivery of services in India to e-governance mode. Also, Cyber security of banks in India is also required to be upgraded. This way, the cyber security issues for the Modi government would not be easy job to manage keeping in mind the messed position of Indian cyber security.
Well! At this point of time, we can only hope for good.
satinder@varindia.com
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.
