Tag: cybersecurity

  • AI-Empowered Cyberattacks Prompt Businesses to Revamp Cybersecurity Tactics: Insights from Kaspersky

    AI-Empowered Cyberattacks Prompt Businesses to Revamp Cybersecurity Tactics: Insights from Kaspersky

    The integration of artificial intelligence (AI) technologies is necessitating a significant shift in business cybersecurity protocols. The evolving landscape of cyber threats is becoming increasingly complex due to the swift adoption of AI. Previously, successful cyberattacks required substantial planning and advanced technical proficiency, but AI has streamlined the process, decreasing the entry-level threshold for novice cyber threats.

    The Impact of AI on Cyber Threats

    AI has revolutionized the modus operandi of experienced cyber attackers, offering them speed and efficiency. Furthermore, it has also armed less skilled individuals with new capabilities. Vladislav Tushkanov, group manager at an AI technology research center, explains that AI technology allows both skilled and unskilled individuals to expedite their operations. Novice cyber attackers, who were previously required to spend extensive amounts of time learning programming, can now efficiently execute cyber threats.

    AI is being employed to create sophisticated phishing emails, imitated voices, images, and videos that are convincing and challenging to identify. Deepfakes have become an emerging hazard in the corporate world. An engineering firm in the UK reportedly suffered a loss of approximately US$25 million in 2024 when an employee was tricked into transferring funds due to a deepfake video call.

    AI’s capabilities extend beyond deepfakes and can support various stages of cyberattacks, such as reconnaissance, message customization, and evading detection by security systems.

    AI: A Double-edged Sword

    According to recent research, 72% of businesses express grave concerns regarding cyber attackers’ utilization of AI. Traditional defensive measures struggle to counter rapidly evolving and unpredictable threats. Simultaneously, AI proves to be an essential asset for bolstering cybersecurity. It allows organizations to detect threats with greater speed, mechanize aspects of the response procedure, and improve predictive abilities, thereby shifting from a reactive to a proactive security strategy.

    “To effectively manage the increasing number of alerts and to prevent analysts from becoming overwhelmed, machine learning is essential. It copes efficiently with these tasks and allows professionals to focus on complex or business-critical tasks,” Tushkanov said.

    However, the successful incorporation of AI in cybersecurity involves more than just technology. Businesses also require skilled personnel, practical implementation experience, and a solid data foundation.

    The Role of AI in Incident Investigation and Decision Making

    According to sources, AI is currently used to analyze and classify around 460,000 malware samples daily. This, combined with proprietary data, processing methods, and model training infrastructure, forms the foundation of increasingly complex cybersecurity strategies.

    Despite the significant advances of AI, it is not yet equipped to replace human expertise in incident investigation and decision-making processes. Risk assessments and response strategies still heavily depend on professional judgment. “At this point, the human role remains essential,” Tushkanov said, implying that while AI systems might support decision-making in the future, they cannot replace the need for human expertise.

    Questions & Answers

    Q: How has AI impacted cyber threats?
    A: AI has streamlined the process of executing cyber threats, reducing the need for substantial planning and advanced technical skills. It has made it easier for less experienced individuals to launch successful cyberattacks.

    Q: What is the role of AI in cybersecurity?
    A: AI plays a crucial role in enhancing cybersecurity. It allows organizations to detect threats quickly, automate parts of the response process, and enhance predictive capabilities.

    Q: Can AI replace human expertise in incident investigation and decision-making?
    A: Currently, AI cannot replace the need for human judgment in risk assessment and response strategy formulation. Despite the significant advances in AI, human expertise remains essential in incident investigation and decision-making processes.

  • Asia’s Telecom Titans Rise to Meet Cybersecurity Challenges: A Dive into 5G Security and Fraud Prevention

    Asia’s Telecom Titans Rise to Meet Cybersecurity Challenges: A Dive into 5G Security and Fraud Prevention

    As the telecommunications sector in Asia rapidly moves towards 5G technology, cloud-native architectures, and digital services, operators throughout the region contend with intensifying cyber threats. These threats, which range from data breaches to scams and fraud within mobile networks, impact not only businesses, but also a considerable number of consumers. Consequently, governments and mobile operators are implementing stricter regulations and enhancing enforcement strategies. In addition, they are investing in more sophisticated security systems to safeguard national networks.

    Increasing Cybersecurity Risks and Consumer Fraud in the Region

    The Asia Pacific region has experienced some of the highest levels of mobile fraud, digital scams, and identity-based attacks globally. A 2025 report commissioned by GSMA revealed that the percentage of consumers who fell victim to scams increased from 31% to 43% over the past year. Additionally, 81% of those surveyed said they are willing to switch financial providers to achieve better security. Consumers prefer solutions that prioritize verification, offer a confirmation-of-payee feature, provide safer payment tools, and allow for simple “official call-back only” habits for enhanced protection.

    Cybersecurity trust in Southeast Asia is dwindling as the number of cyber scams continue to rise. A significant number of mobile users have reported encounters with fraudulent calls, SMS, and online impersonation attempts. According to the GSMA’s Intelligence 2024 Report on Telco Security Landscape and Strategies – Asia Pacific, there is an urgent need for innovative telecom security solutions.

    Telecom Operators Enhancing Defenses and Security Practices

    Asian governments have started to enact laws and establish regulatory frameworks aimed at protecting critical infrastructure and personal data. These measures obligate telecom operators to bolster their networks’ security.

    In China, the Cybersecurity Law, the Data Security Law, and the Personal Information Protection Law (PIPL) regulate telecom operators. These laws demand strict protection of critical information infrastructure, data handling, security reviews, and compliance obligations. As a result, operators are compelled to integrate security measures from the inception of their projects.

    In South Korea, the Personal Information Protection Act (PIPA) regulates telecom operators. The legislation mandates the implementation of measures to securely handle data, maintain accountability, and safeguard user privacy. Though primarily regulating data protection rather than network infrastructure security, PIPA forms a crucial regulatory framework for safeguarding personal data as 5G networks and virtualization continue to grow across the country.

    In Japan, the Cybersecurity Basic Act and related national cybersecurity strategies guide the broad infrastructure protection framework. Telecom operators, including those exploring advanced network innovations such as virtualized RAN or 6G-ready systems, are expected to comply with government-endorsed security standards, threat-sharing mechanisms, and incident-response protocols.

    In the Philippines, national cyber defenses are progressively strengthening. The Cybercrime Prevention Act of 2012 (RA 10175) and the National Cybersecurity Plan 2023-2028 establish a legal framework and outline strategies for enhancing resilience across critical infrastructure.

    Several major telecommunications firms are investing in AI-based network analytics to bolster security and operational efficiency. For instance, Globe Telecom deploys AI and machine learning for anomaly detection across its infrastructure. Similarly, PLDT is mitigating phishing, DDoS attacks, and other cyber threats through its cybersecurity operations center and collaboration with government agencies.

    India, driven by its enormous telecom market, has introduced some of the region’s most comprehensive cybersecurity rules. CERT-In mandates prompt incident reporting, strict log retention for 180 days, and real-time collaboration with national cyber emergency response teams. The Department of Telecommunications now requires 5G network elements to be procured from trusted vendors under the Trusted Telecom Portal policy.

    Singapore has set up a robust cybersecurity framework for its telecom sector. Under the Cybersecurity Act, telecom and infocomm systems can be designated as Critical Information Infrastructure (CII), which mandates operators to implement a cybersecurity code of practice, conduct audits, and quickly report incidents.

    Building Collective Defense: Collaboration, Standards, and Shared Cyber Intelligence

    Given the scale and interconnectedness of modern telecom networks, many operators acknowledge the limitations of tackling cyber threats individually. As a result, collaborative initiatives, public-private partnerships, and industry-wide frameworks are emerging as fundamental strategies for defense.

    The theme of the 19th edition of the Telecom Review Leaders’ Summit was ‘Tech Intelligence Beyond Mobility.’ The event held in Dubai, UAE, facilitated discussions among leading experts on the evolving challenges of protecting information in an increasingly connected world. The summit served as a collaborative platform for telecom-based cybersecurity collaboration, standardization, and knowledge sharing.

    The Need for Collective Defense, Transparency, and Regulatory Backing in Asia

    The security challenge faced by Asia’s telecom sector is not limited to individual operators or markets. Scams, fraud, cross-border intrusion threats, and the growing complexity of virtualized networks have necessitated a regional and systemic response.

    The continual rise in consumer fraud, data protection failures, and regulatory scrutiny necessitates treating cybersecurity in the same vein as infrastructure policy, consumer protection, and national security. To cope with these risks, operators need to prioritize transparency, share threat intelligence, and adopt common security standards. Regulators should support these efforts with clear rules, consistent enforcement, and incentives that reward genuine compliance.

    By embracing an approach that combines strong governance, robust technical controls, and cross-border collaboration, Asia’s telecom sector can build networks that not only offer connectivity but also provide meaningful protection for users in an increasingly hostile digital environment.

    Questions & Answers

    What is the current state of cybersecurity in Asia’s telecom industry?
    The telecom industry in Asia is grappling with increasing cybersecurity risks, including data breaches, scams, and fraud within mobile networks. Governments and mobile operators are responding by implementing stricter regulations, enhancing enforcement strategies, and investing in advanced security systems.

    What measures are being taken to improve cybersecurity in Asia’s telecom industry?
    Governments across Asia are enacting laws and regulatory frameworks to protect critical infrastructure and personal data. Telecom operators are obligated to bolster their network security and are investing in AI-based network analytics to enhance security and operational efficiency.

    What strategies are recommended for managing cybersecurity risks in the telecom industry?
    Telecom operators need to prioritize transparency, share threat intelligence, and adopt common security standards. Regulators should support these efforts with clear rules, consistent enforcement, and incentives that reward genuine compliance. Collaborative initiatives, public-private partnerships, and industry-wide frameworks are also recommended.

  • India Boosts Cybersecurity: Enforces New Compliance Rules on OTT Platforms and Smartphone Manufacturers

    India Boosts Cybersecurity: Enforces New Compliance Rules on OTT Platforms and Smartphone Manufacturers

    In a bid to enhance digital security due to increasing episodes of online fraud and mobile-related cybercrime, India has released two key directives. These new rules demand compliance from Over The Top (OTT) communication platforms and smartphone manufacturers.

    Ensuring Secure Communication

    The Department of Telecommunications (DoT) in India has instructed messaging platforms such as WhatsApp, Telegram, Snapchat, Signal, and Arattai to enable SIM binding within a 90-day timeframe. According to the Telecommunications (Telecom Cyber Security) Rules, 2024, these applications must remain connected to the mobile number and active SIM card of a user’s device. Moreover, web and desktop versions must log users out every six hours, requiring them to reauthenticate via QR code pairing. Non-compliance will result in penalties as stipulated by the Telecommunications Act.

    This decision has been made in response to the increasing number of cyber fraud cases involving OTT apps accessed without the corresponding SIM or from foreign locations. Such situations allow for identity spoofing and misuse. This order has been issued following nearly a year of discussions between government officials and OTT companies.

    Representatives of the industry have expressed concerns about the impacts on user experience and technical feasibility. They emphasized that not all platforms, particularly iOS, can consistently carry out SIM checks. They also warned about potential disruptions for legitimate uses, including eSIM and dual-SIM devices, international travel, small businesses relying on persistent desktop sessions, and elderly user accessibility. Companies are also unsure if SIM binding will effectively decrease fraud involving Indian SIM cards obtained through intermediaries.

    Demand for Preloaded Cyber Safety App

    On the same day, the telecom ministry of India issued another mandate for leading smartphone manufacturers including Apple, Samsung, Vivo, Oppo, and Xiaomi. They are required to preload the government’s Sanchar Saathi cyber safety app on all new devices sold in the country. Users will not have the option to delete or disable this app. Devices that are already in the supply chain must receive the app via software updates.

    Sanchar Saathi, launched in January, allows users to block and track lost or stolen phones, verify device authenticity, and detect fraudulent mobile connections. Government data reveals that the app has assisted in the recovery of over 700,000 phones, including 50,000 in October alone, and has facilitated the blocking of over 3.7 million lost or stolen devices. Additionally, more than 30 million fraudulent mobile connections have been disconnected using its systems.

    Questions & Answers

    What is the purpose of the new directives issued by India’s Department of Telecommunications (DoT)?
    The new directives aim to tighten digital security due to rising incidents of online fraud and cybercrime related to mobile devices. They introduce new compliance requirements for Over The Top (OTT) communication platforms and smartphone manufacturers.

    What measures are messaging platforms expected to implement under these directives?
    Messaging platforms such as WhatsApp, Telegram, Snapchat, Signal, and Arattai are required to implement SIM binding, which means these apps must remain linked to the user’s mobile number and active SIM card. Web and desktop versions of these apps must also log out users every six hours and require reauthentication through QR code pairing.

    What is the Sanchar Saathi app and why are smartphone manufacturers required to preload it on new devices?
    The Sanchar Saathi app is a cyber safety application launched by the Indian government. It allows users to block and track lost or stolen phones, check device authenticity, and identify fraudulent mobile connections. Smartphone manufacturers are required to preload this app on all new devices sold in India to enhance digital security.

  • AI-Driven Defense: Globe Business and Cyble Unite to Reinforce Enterprise Cybersecurity in the Philippines

    AI-Driven Defense: Globe Business and Cyble Unite to Reinforce Enterprise Cybersecurity in the Philippines

    Globe Business has forged a groundbreaking alliance with global cybersecurity powerhouse, Cyble, to launch an innovative AI-focused threat intelligence platform in the Philippines. This collaboration is designed to fortify enterprise cybersecurity and arm organizations with the tools necessary to proactively address emerging cyber threats.

    This strategic partnership emerges amidst an escalating rise in cyberattacks across the nation. During the initial quarter of 2025, it was uncovered that over 1.2 million Filipinos’ credentials had been compromised and found on the dark web. Furthermore, the Philippines continues to grapple with a significant influx of phishing and credential theft incidents, while the evolving use of malware-as-a-service has rendered conventional network defenses increasingly fraught.

    Leveraging AI for Threat Detection

    The partnership leverages Globe Business’s in-depth local enterprise knowledge and Cyble’s cutting-edge AI-driven risk intelligence to enhance early threat detection and response capabilities. The newly introduced platform will collate and scrutinize data from various internet strata, alerting organizations to potential attacks, data breaches, or instances of brand impersonation before they escalate into major crises.

    KD Dizon, the Head of Globe Business, noted:

    “The battle against cybercrime is a contest of intelligence and speed. Our alliance with Cyble is about democratizing that power. It’s about equipping Philippine enterprises with AI-driven foresight, enabling them to transition from merely reacting to breaches to proactively leveraging data-informed resilience.”

    Cyble’s platform employs agentic AI and its unique BlazeAI engine, which continually learns from emerging threat patterns. This system scans over 20 billion pages daily and monitors in excess of 15,000 cybercrime sources in real-time. This robust strategy allows security teams to identify exposed data, fraudulent domains, or network vulnerabilities at an early stage.

    Facilitating Secure Digital Transformation

    Beenu Arora, the Co-founder and CEO of Cyble, remarked:

    “The Philippines confronts some of the world’s rapidly growing cyber risks. By marrying the scale of AI with Globe Business’s local expertise, we aim to help enterprises always maintain a step ahead of attackers.”

    Globe Business emphasizes that this partnership underscores its commitment to facilitating secure digital transformation. It also highlights the increasing demand for AI-driven prevention strategies in cybersecurity, as these strategies offer wide-ranging support for various industries. Banks and financial institutions can identify compromised data early on and halt fraudulent activities, while retail and e-commerce companies can keep an eye on brand misuse and counterfeit products. Additionally, government agencies can also leverage this platform to detect signs of planned breaches or cyberattacks.

    Questions & Answers

    What is the purpose of the partnership between Globe Business and Cyble?
    The partnership seeks to strengthen enterprise cybersecurity in the Philippines by introducing an AI-native threat intelligence platform.

    What capabilities does Cyble’s platform offer to security teams?
    Cyble’s platform uses agentic AI to process over 20 billion pages daily and monitor more than 15,000 cybercrime sources in real time, allowing early identification of exposed data, fraudulent domains, and network vulnerabilities.

    How does this partnership benefit different industries?
    This collaboration supports a variety of sectors. Financial institutions can detect compromised data early on, retail companies can monitor brand misuse, and government agencies can detect signs of planned cyberattacks.

  • Globe Business and Blackpanda Unveil Budget-Friendly AI Cybersecurity Solutions for Philippine Enterprises

    Globe Business and Blackpanda Unveil Budget-Friendly AI Cybersecurity Solutions for Philippine Enterprises

    Globe Business has joined forces with Blackpanda, the region’s premier cyber incident response specialist, to provide affordable, enterprise-grade cybersecurity solutions tailored for businesses in the Philippines. Their innovative partnership promises a fixed-cost incident response and digital forensics service designed to help organizations promptly detect, contain, and recover from cyberattacks. This offering, fondly dubbed a “cyber fire department,” includes continuous vulnerability scanning, dark web monitoring, and seamless access to cyber insurance, making it an invaluable resource for local enterprises aiming to neutralize digital threats swiftly.

    KD Dizon, Head of Globe Business, emphasizes the growing urgency of the situation:

    Cyber threats remain a pressing challenge for businesses of all sizes, and AI is amplifying both the sophistication and frequency of these attacks. Our partnership with Blackpanda makes immediate, expert incident response—once prohibitively expensive—accessible to organizations across the Philippines.

    The Rising Tide of Cyber Risks in Southeast Asia

    The threat landscape is escalating in the Philippines and Southeast Asia, fueled by inadequate cybersecurity preparedness, AI-driven vulnerabilities, and skyrocketing costs of attacks. Globe underscores the necessity for robust threat intelligence, skilled incident responders, collaboration, and the latest security technologies. In 2024 alone, 85% of Philippine firms reported AI-related attacks, while 84% faced supply chain breaches, with almost a third unable to detect these intrusions. The cost of breaches across ASEAN averaged an alarming USD 3.23 million last year, with the financial services sector suffering the most, racking up an average cost of USD 5.57 million. The region also witnessed a staggering 29% uptick in cyber incidents, accompanied by a rise in ransomware and phishing activities.

    Transforming Cybersecurity Accessibility with IR-1

    Historically, enterprise-level incident response services have been financially out of reach for many businesses, with hourly rates soaring to USD 500 and annual retainers typically ranging from USD 25,000 to USD 100,000. Blackpanda aims to disrupt this trend with its flagship solution, IR-1, which blends incident response, continuous vulnerability scanning, and cyber insurance support into a budget-friendly subscription model. This transformative approach lowers the financial barriers for firms, enhancing their operational resilience and cybersecurity posture.

    Gene Yu, CEO of Blackpanda, shares the vision behind this collaboration:

    Globe’s reach and trust in the Philippine market make them the ideal partner to scale our IR-1 cyber emergency subscriptions nationwide. By delivering always-on access to expert response through Globe’s trusted network, we’re ensuring that a small manufacturer in Cebu or a growing fintech in Makati can access the same level of cyber emergency support as multinational corporations.

    The IR-1 solution boasts automated access to cyber insurance with coverage up to USD 10 million, continuous monitoring for potential risks, and elite response teams located across Asia—Manila, Singapore, Tokyo, and Hong Kong. Unlike its competitors, IR-1 supports any endpoint detection and response (EDR) solution, offering enterprises maximum freedom and flexibility.

    Questions & Answers

    How will the partnership between Globe Business and Blackpanda benefit Filipino companies?
    The partnership aims to provide accessible, enterprise-grade cybersecurity solutions to Filipino businesses, allowing them to swiftly detect and respond to cyber threats without the prohibitive costs historically associated with such services.

    What are the key features of the IR-1 solution offered by Blackpanda?
    IR-1 includes automated access to cyber insurance, continuous attack surface monitoring, dark web scanning, and support for any endpoint detection and response solution, ensuring comprehensive coverage and flexibility for businesses.

    What trends are driving the increase in cyber incidents in Southeast Asia?
    The rise in cyber incidents is largely attributed to low cybersecurity readiness, the growing number of AI-related threats, and the increasing costs of attacks, necessitating urgent action and investment in cybersecurity measures.

  • Cybercriminals Target Organizations with Phony App to Steal Data and Demand Ransoms

    Cybercriminals Target Organizations with Phony App to Steal Data and Demand Ransoms

    In a worrying trend, hackers are escalating their tactics by targeting organizations across Europe and the Americas, employing social engineering to install a modified version of a legitimate data import tool. This seemingly innocuous application opens the door for attackers to steal sensitive information, gain access to cloud services, and navigate through networks, escalating their assaults and demands for extortion.

    Cybercriminals Craft Deceptive Strategies

    Tracking this malicious activity is the threat group known as UNC6040, which makes use of voice phishing, or vishing, to trick unsuspecting employees into downloading the malicious app. Designed to closely imitate a familiar enterprise tool, this rogue application secures an alarming level of access to corporate environments. Once in, it enables the exfiltration of critical data and compromises system integrity with ease.

    Consequences and Scope of the Attack

    The Google Threat Intelligence Group has reported that approximately 20 organizations have fallen victim to these attacks, some enduring confirmed data breaches that threaten their operational security. This ongoing operation is linked to a cybercriminal ecosystem referred to as ‘The Com,’ which engages in various illegal activities, underscoring the complex and interconnected nature of modern cybersecurity threats.

    The Human Element in Cybersecurity

    Experts warn that the root of this threat lies not in software vulnerabilities but in the effectiveness of social engineering tactics. This serves as a crucial reminder of the importance of heightened employee awareness and the implementation of robust controls over app authorization. It turns out that even the most sophisticated cybersecurity measures can be bypassed with a simple phone call — it’s a lesson every organization should take to heart.

    Questions & Answers

    What tactics are hackers using in these attacks?
    Hackers are using voice phishing to deceive employees into downloading a malicious version of a legitimate data import tool, allowing unauthorized access to sensitive data.

    How many organizations have been affected by these cyber attacks?
    Approximately 20 organizations have been affected, with some experiencing confirmed data breaches as a result.

    What steps should organizations take to mitigate such attacks?
    Organizations should focus on improving employee awareness regarding social engineering tactics and enforce stricter controls on app authorization to prevent unauthorized access.

  • Why Singapore’s Retailers Need to Take Heed of Recent Supply Chain Cyber Incidents

    Why Singapore’s Retailers Need to Take Heed of Recent Supply Chain Cyber Incidents

    As cyber threats continue to rise, understanding the impact of these threats and how they infiltrate the retail supply chain is vital for operational continuity. Singapore’s recently refreshed Industry Digital Plan (IDP) for the retail sector highlighted enhanced cyber hygiene measures for protection at different stages of growth.

    The region’s booming digital economy makes businesses operating here a prime target for cyberattacks. The retail sector is ripe for third-party cyberattacks, with threat actors exploiting vulnerabilities in Point-of-Sale (POS) terminals, supply chain systems, logistics platforms, and other interconnected technologies.

    Recent Cyber Attacks Targeting Supply Chains

    The retail industry has been shaken by a number of high-profile reported cyber incidents recently, affecting major players like Marks and Spencer (M&S) and Harrods.

    Closer to home, popular bubble tea chain Chica San Chen disclosed a data breach of one of its vendors’ servers, compromising the personal information of members, such as their names, mobile numbers, e-mail addresses and login passwords. In 2024, Filipino fast-food giant Jolibeewas reportedly subjected to a major data breach affecting the data of 11 million customers.

    These incidents not only tarnish brand reputations, but also disrupt operations and expose sensitive customer data, causing widespread concern. The financial fallout from these compromises highlights the crucial need for retailers to focus more diligently on the security of their digital and physical supply chains.

    According to BlueVoyant research, more than 70% of Singaporean organisations reported an average of 3.97 breaches impacting operations. Almost half (47%) of Singapore organisations indicated the news of breaches over the past 12 months are likely to lead to an increase in budget for additional internal and external resources to help protect against supply chain cyber security issues.

    Retail Under Growing Threat

    Threat actors like DragonForce have reportedly boldly claimed responsibility for a series of attacks targeting UK retailers, often partnering with groups like Scattered Spider to amplify their reach. Understanding the motivations and methods of these groups provides invaluable insight — such as exploiting supply chain vulnerabilities — to predict and prevent future attacks. Their evolving strategies represent a constant threat that requires ongoing vigilance and continuous improvements to third-party risk management practices in retailers.

    Retail businesses are often vulnerable to a catalogue of common cyber threats, including phishing schemes, ransomware, and supply chain compromises. Threat actors leverage malware and sophisticated social engineering to infiltrate retailers’ defences. By embedding malicious software within trusted channels, they can access secure areas usually safeguarded but overlooked in anticipation of direct attacks.

    In fact, more than a third (35%) of Singapore respondents to BlueVoyant research said they have no way of autonomously seeing the cyber risk posture of third parties and rely on self-reporting. This knowledge underscores the necessity for robust cyber security practices targeting every link in the retail supply chain.

    Harden defences and manage supply chain risk

    Singapore’s Cyber Security Agency (CSA)’s toolkit for enterprises highlight key areas for organisations to address increasing cyber risks, including the need for a third-party risk management programme to assess and manage the risks posed by third parties, including vendors, products, and services.

    Implementing effective third-party risk management practices, characterised by strong cross-business collaboration in vendor management, continuous cyber threat monitoring across the supply chain, and robust due diligence procedures, is essential for ensuring comprehensive visibility of risks associated with key suppliers.

    Additionally, both retailers and their suppliers must prioritise robust employee training in cyber security best practices, empowering them to recognise and respond to suspicious activity. Implementing multi-factor authentication adds an extra layer of security, making it significantly more difficult for unauthorised users to compromise the integrity systems. Securing helpdesk authentication can also help prevent deceptive access attempts, ensuring that customer service channels remain protected.

    Proactive incident response planning is crucial for effectively managing breaches, should they occur, with an eye towards the potential for a cross-business compromise. Retailers work with many suppliers and partners and so must maintain even greater vigilance within their extended ecosystem. Establishing network segmentation, sharing only strictly necessary data, and implementing access controls can help make sure that a potentially compromised vendor does not cause a cascade of issues.

    Regular drills and collaboration with cyber security partners can help ensure incident management is more seamless, minimising potential damage through quick containment and eradication. By embracing these defensive strategies, retailers can significantly bolster their security posture.

    As cyber threats become increasingly sophisticated, it is imperative for retailers in the region to maintain constant vigilance and adaptability in their cyber security posture. Ensuring robust protection of these essential services is vital due to their immediate impact on society’s well-being. Retailers must heed the call to integrate recommended cyber security measures, protecting themselves against potential compromises.

    By William Oh, Head of Asia Pacific, BlueVoyant

  • JB Hi-Fi partners with cyber-security firm to educate Students

    JB Hi-Fi partners with cyber-security firm to educate Students

    Leading electronics retailer JB Hi-Fi has partnered with cyber-security firm Family Zone to offer cyber-safe hardware, solutions, and training to schools across Australia.

    The mission is to give Australian students the opportunity to learn about the dangers of a technologically driven world in a safe, collaborative way.

    “Our Education customers play an important part in the future of Australia, as they shape the youth of today for the responsibilities of tomorrow,” JB Hi-Fi Solutions head of practices Jordan Barry said.

    “Today, more than ever, the rapid adoption of mobile and cloud-based technologies is creating an environment open to a cyber attack.

    “JB Hi-Fi Solutions believe that it is our role to guide our education client to help protect against this threat. Our exciting partnership with Family Zone allows us to rapidly expand our capability and capacity, reaching more education clients than ever before.”

    The partnership allows JB Hi-Fi to offer Family Zone products and services to its Solutions customers, including cyber-safe hardware, monitoring tools for parents, as well as the ability to deliver cybersecurity solutions to schools.

    “Our mission is to allow schools, parents, cyber safety experts and ultimately children to seamlessly collaborate; to set and agree to boundaries, to test them, to learn and prepare for a world of technology,” Family Zone managing director Tim Levy said.

    “Our exciting partnership with JB Hi-Fi progresses us rapidly down this path allowing us to expand our reach and streamline sales, deployment, and management of our solutions.”

    Family Zone also partnered with supermarket Woolworths in late 2018 to sell its cyber-safe and child-friendly mobile phone – a partnership that later expanded to include the ability to sell Family Zone solution services as well.

  • Banks Are Increasingly Victims of Data Theft

    Banks Are Increasingly Victims of Data Theft

    Cybercriminals who want to obtain a large amount of valuable data quickly are increasingly attacking financial institutions. Data breaches can be very expensive for banks.

    Credit Suisse seemingly cannot escape the negative headlines. After numerous scandals and annual results deeply in the red last year, a former employee is now making new negative headlines for the bank. An IT employee is alleged to have stolen personal data from Credit Suisse employees over the years.

    While the data was taken, there is so far no evidence of it being used maliciously.

    We have taken and are continuing to take steps, including legal remedies, to contain the incident adequately. To date, there is no evidence of any onward transmission or intent to use the data in any way,» according to a statement from Credit Suisse.

    Still, the security incident is seen as further damaging the image of the crisis-hit financial institution.

    Data security must be a top priority in a bank’s security concept since financial data contains some of the most sensitive information on individuals. Should cybercriminals get hold of such data, it can have devastating consequences for customers who have placed their trust in a financial institution that lacks adequate security measures.

    Financial institutions have been a popular target for data breaches and theft for years. The vast amount of data residing in banks on accounts, credit cards, and securities holdings is a juicy target for those with ill intent.

    According to a study by the security company Proxyrack that evaluated data breaches since 2004, the financial sector is the third most frequent target of hackers, with Citigroup a popular target. It was victimized by three hacker attacks since 2004, resulting in 4.4 million records being stolen or compromised.

    According to Proxyrack, only companies in the Web and healthcare industries have been affected more frequently than financial institutions. The top three causes of security incidents are hacker attacks, inadequate security measures, and lost or stolen data.

    Cybersecurity firm Flashpoint comes to a similar conclusion. According to its data, the financial sector recorded the second-highest number of data breaches globally after government agencies in 2022. US banks were the most affected, followed by institutions in Argentina, Brazil, and China. At least 79 US financial institutions reported data breaches affecting 1,000 or more customers last year.

    Data leaks and data theft can be very expensive. According to an IBM report on the cost of data breaches in 2022, the US financial sector recorded the second-highest average cost per security incident after healthcare. While the average cost of data breaches in healthcare reached a record high of $10.1 million, up over 40 percent since 2020, it was just under $6 million for financial firms.

    The largest known data breach to date involving a financial institution was at First American Financial Corp. In 2019, security specialist Brian Krebs discovered 885 million First American documents posted online that contained information such as account numbers, bank statements, tax records, and wire transfer receipts. The data of millions of customers was freely accessible.

    The US financial services provider Equifax also experienced a similar breach. In September 2017, the company informed its customers that cyber criminals had accessed 147 million accounts. Equifax had learned about the security breach a month earlier but failed to inform its customers immediately, resulting in a $700 million fine from US authorities.

    The third largest data breach also involved a US company when in 2009, Heartland Payment Systems announced it was the victim of a security breach in its processing system in 2008. A web form on the company’s website gave access to the corporate network allowing Russian hackers to gain to over 100 million credit and debit card numbers.

  • IronNet Cybersecurity adds new integrations to Collective Defense Platform

    IronNet Cybersecurity adds new integrations to Collective Defense Platform

    IronNet Cybersecurity, the leader in network detection and response and collective defense, announced new integrations with leading cloud, endpoint, and firewall platforms. These integrations enhance and expand the benefits of IronNet’s Collective Defense Platform for security operations teams.

    New capabilities in this release include integrations with:

    • Amazon Web Services (AWS): Adding new IronNet sensors that enable customers to leverage IronNet’s Collective Defense Platform to secure their AWS deployments.
    • Crowdstrike Falcon EDR: Enabling security analysts to seamlessly investigate threats detected by IronNet from the network to the host, and to contain compromised hosts.
    • Palo Alto Networks Strata Next-Generation Firewalls Native Response: Enabling security teams to generate firewall responses and stop threats detected by IronNet.
    • ZScaler Nanolog Streaming Service (NSS) Analysis: Enabling IronNet customers to apply IronNet’s IronDefenseⓇ NDR behavioral detection to HTTP/HTTPS logs.
    • Microsoft Office 365: Adding IronDefense behavioral detection of malicious login attacks targeting Microsoft’s productivity SaaS suite.

    In addition to these integrations, the new release includes:

    • New User & Entity Behavior Analytics (UEBA) to detect identity- and authentication-focused attack techniques.
    • Improved lateral movement and port-scanning detection.

    “The ability to correlate cloud, network, endpoint, and other security telemetry data into a richer, more complete picture of a risk-based event helps organizations more effectively evaluate and mitigate a threat. And that is the real value that network intelligence and threat analytics solutions like IronNet offer,” said Christopher Kissel, Research Director, Security & Trust Products, IDC. “IronNet’s additional capability to share information anonymously across a community of peers and enable security analysts to collaborate on threats is a noticeable differentiator in light of the rise of nation-state level cyber-attacks.”

    This expansion of IronNet’s capabilities continues the company’s momentum of growth in both technology and partnerships. David Lathrop, Vice President of the Utility Strategic Business Unit with Unlimited Technology, Inc., said, “IronNet’s latest release is exactly the kind of ecosystem support that helps us provide the unique, comprehensive cyber solutions we offer through the Enterprise Security Program Review.” Unlimited Technology is a founding partner, along with IronNet, DirectDefense, and Exero, of the ESPR, announced in January.

    “Empowering security teams and maximizing the effectiveness of their security investments against cyber threats targeting their enterprise, industry, or region is core to our Collective Defense mission,” said Don Closser, IronNet’s Chief Product Officer. “Together with our security ecosystem partners, IronNet can offer our customers a true, defense-in-depth approach that helps them reduce time to detection and scale up their ability to respond to cyber threats. This is especially important as factors like digital transformation and expanding supply chains are increasing the threat landscape exponentially.”

  • Cybersecurity Startup Plots APAC Expansion

    Cybersecurity Startup Plots APAC Expansion

    London-based cloud-native application security startup Snyk is eyeing Asia Pacific and Japan, following a breakout year in 2020.

    Snyk has announced plans to expand in Singapore, India, Japan, Korea, Australia, and New Zealand, and has appointed vice president of APJ sales Shaun McLagan to lead and build out dedicated teams in the region, the firm announced in a blog post on Thursday.

    The appointment comes as Snyk announced its latest $300 million Series E funding, led by new partners – Singapore state investor Temasek and Geodesic Capital, a venture capital firm that specializes in helping technology companies expand into Asia.

    The startup cited an explosion of digital transformation initiatives across the region and a greater need for security among companies. Its customers include Revolut and Volt Bank.

    With an estimated 27 million software developers worldwide today, and the strongest growth for developers expected in Asia Pacific specifically, Snyk collectively recognizes that there has never been a better time to serve this market, Peter McKay, Snyk CEO said.

    Founded in 2015, the company had a breakout year in 2020, recording a 200 percent year-over-year increase in revenue and making strategic acquisitions of DeepCode and Manifold.

    With the new funding round, the company has now raised $470 million to date, bringing the company valuation to US$4.7 billion, quadrupling it since the beginning of 2020.

  • Fintech Partners Plan Cybersecurity Platform

    Fintech Partners Plan Cybersecurity Platform

    the @-WISE Cybersecurity Centre of Excellence in Singapore aims to grow and groom cybersecurity talents.

    Plans for the cybersecurity platform were announced by partners Hong Kong-headquartered financial services group AMTD, the University of Waterloo, iQ4 and the Singapore FinTech Association (SFA) at a virtual signing ceremony on Thursday.

    The @-WISE Cybersecurity Centre of Excellence aims to raise the awareness of the importance of cybersecurity among digital platforms, fintechs, financial institutions, and other sectors in Singapore, the announcement said.

    As part of the partnership, the platform will also grow and groom cybersecurity talents, as well as build a cybersecurity ecosystem in response to the escalating cybersecurity threats, ultimately helping to shape a cyber talent strategy that will contribute to Singapore’s Smart Nation vision.

    AMTD and SFA previously announced a strategic agreement to promote entrepreneurship and innovation in Singapore’s fintech community, which builds on the two sides’ work under the MAS-SFA-AMTD Solidarity Grant.

  • BlackBerry To Offer Cybersecurity For Future Jaguar Land Rover Model

    BlackBerry To Offer Cybersecurity For Future Jaguar Land Rover Model

    Jaguar Land Rover and technology firm BlackBerry today announced the expansion of the companies’ corporate partnership to develop next-generation intelligent vehicles for the carmaker. As part of the extended collaboration, the BlackBerry, a trusted security software and services company, will help JLR develop future-ready vehicle safety technology for the automotive market. The company will share its Artificial Intelligence and Machine Learning technologies like – BlackBerry QNX and BlackBerry Cylance, to develop vehicle safety systems, with a range of capabilities like – predictive software maintenance and cybersecurity threat protection.

    For instance, the BlackBerry QNX, an integrating software will be used to help develop Jaguar Land Rover’s next-generation vehicle architecture, making it safer. On the other hand, its consultants and security testing technology, BlackBerry Cybersecurity Consulting services will help identify security vulnerabilities in connected and autonomous vehicles, across the full software library used in a vehicle.

    Speaking about the partnership Ralf D Speth, Jaguar Land Rover CEO, said “Jaguar Land Rover and BlackBerry share a common objective in bringing the most intelligent vehicles to reality. I am delighted that our partnership with BlackBerry continues to go from strength-to-strength, a company whose technology innovations uniquely address the expanding safety needs of the automotive industry.”

    As for John Chen, Executive Chairman & CEO, BlackBerry, he said, “BlackBerry is a trusted partner of the automotive industry because of our heritage and innovations in secure communications. We are pleased to be Jaguar Land Rover’s chosen partner for safety-certified technology, as we advance Artificial Intelligence and Machine Learning technologies to transform automotive safety.”

  • ZTE opens first cybersecurity lab in China

    ZTE opens first cybersecurity lab in China

    ZTE has launched the first in a series of planned dedicated cybersecurity labs aimed at reassuring customers of the security of its solutions, and developing end-to-end security products and services.

    The new lab in Nanjing, China will help ZTE provide customers with end-to-end security products and services.

    It also aims to help ZTE increase transparency and enhance trust with all third parties, including customers and global regulators, in light of the national security concerns that are prompting several countries to ban the use of equipment from Chinese vendors in 5G rollouts.

    The lab will provide security assessment and audit services such as source code review on ZTE products including 4G and 5G solutions.

    It will also offer security design audit, procedural document review, black box testing and penetration testing services, and facilitate research and development collaborations with other industry stakeholders and academia.

    Moving forward, the company plans to collaborate with major security organizations to jointly conduct security assessment, certification, training and consulting.

    Following the establishment of the Nanjing lab, ZTE plans to also launch cybersecurity labs in Italy and Belgium respectively in the near future as it builds out a global network.

    “The security lab is an open and cooperative platform for the industry,”  ZTE CSO Zhong Hong said during a speech at the opening of the new lab.

    “ZTE plans to gradually achieve the cybersecurity goals through three steps: first, meeting the requirements of cybersecurity laws, regulations and industry standards as well as certification schemes; second, conducting an open dialogue to enhance transparency and establishing cooperation with customers as well as regulatory agencies; and third, sustaining the open cooperation mechanism to contribute to cybersecurity standardization.”

  • AT&T joins Global Telco Security Alliance

    AT&T joins Global Telco Security Alliance

    The Global Telco Security Alliance, the industry alliance founded by Singtel, SoftBank, Etisalat and Telefónica. has welcomed a new member in US telecoms giant AT&T.

    The inclusion of AT&T will significantly increase the global presence and resources available to the alliance, which was first launched in April 2018.

    AT&T, which has joined the group as an equal member, has become the first North American member of the alliance.

    AT&T recently enhanced its cybersecurity capabilities and technologies though the acquisition of cybersecurity solutions provider AlienVault for an undisclosed sum. The acquisition target was converted into a wholly-owned subsidiary of AT&T named AT&T Cybersecurity.

    Globally, the alliance now has access to the expertise of more than 6,000 security experts and a global network of more than 28 Security Operations Centres. Combined, the members of the alliance have more than 1.2 billion customers in more than 60 countries across APAC, Europe, the Middle East and the Americas.

    “We are thrilled to be the first telco in North America to join the alliance, and to do so as a founding member,” AT&T Cybersecurity president Barmak Meftah said.

    te“Hackers have well established and organized communities that cooperate to produce cyber threats and it’s time large network operators work together to help deliver disruptive innovations and enable our global customers to detect and respond to threats faster and protect their digital footprint.”