Retail News CRM

Tag: Security

  • Security on cloud still a major challenge for global firms, says study

    Security on cloud still a major challenge for global firms, says study

    Despite the continued importance of cloud computing resources to organizations, companies are not adopting appropriate governance and security measures to protect sensitive data in the cloud.

    This is just one of the findings of a Ponemon Institute study titled “The 2016 Global Cloud Data Security Study,” commissioned by digital security firm Gemalto.

    The study surveyed more than 3,400 IT and IT security practitioners worldwide to gain a better understanding of key trends in data governance and security practices for cloud-based services.

    According to 73% of respondents, cloud-based services and platforms are considered important to their organization’s operations and 81% said they will be more so over the next two years. In fact, 36% of respondents said their companies’ total IT and data processing needs were met using cloud resources today and that they expected this to increase to 45% over the next two years.

    Although cloud-based resources are becoming more important to companies’ IT operations and business strategies, 54% of respondents did not agree their companies have a proactive approach to managing security and complying with privacy and data protection regulations in cloud environments. This is despite the fact that 65% of respondents said their organizations are committed to protecting confidential or sensitive information in the cloud. Furthermore, 56% did not agree their organization is careful about sharing sensitive information in the cloud with third parties such as business partners, contractors and vendors.
    Larry Ponemon, chairman and founder of Ponemon Institute, said, “Cloud security continues to be a challenge for companies, especially in dealing with the complexity of privacy and data protection regulations.”

    “To ensure compliance, it is important for companies to consider deploying such technologies as encryption, tokenization or other cryptographic solutions to secure sensitive data transferred and stored in the cloud,” Ponemon said.

    Jason Hart, VP and CTO for Data Protection at Gemalto, said, “Organizations have embraced the cloud with its benefits of cost and flexibility but they are still struggling with maintaining control of their data and compliance in virtual environments.”

    “It’s quite obvious security measures are not keeping pace because the cloud challenges traditional approaches of protecting data when it was just stored on the network. It is an issue that can only be solved with a data-centric approach in which IT organizations can uniformly protect customer and corporate information across the dozens of cloud-based services their employees and internal departments rely every day,” Hart said.
    More customer information is being stored in the cloud and is considered the data most at risk.
    According to the survey, customer information, emails, consumer data, employee records and payment information are the types of data most often stored in the cloud. Since 2014, the storage of customer information in the cloud has increased the most, from 53% in 2014 to 62% of respondents saying their company was doing this today.

  • Singtel teams with SIT to train cybersecurity talent

    Singtel teams with SIT to train cybersecurity talent

    Singtel has announced a new partnership with the Singapore Institute of Technology (SIT) to train cybersecurity talent.

    The work-study program will support SIT students in the areas of Information Security and Software Engineering, which is expected to lead to career pathways such as cyber security R&D, product development, and management, cyber analysis and forensics, operations and cyber architects.

    Singtel country CEO and CEO, Group Enterprise Bill Chang said the undertaking aims to address two critical skills needs locally – the short supply of trained software engineers and the growing worldwide threat posed by cyber threats.

    “The economy is in great need for trained cybersecurity professionals,” he said.

    Under the work-study programs, participating students are trainees of the supporting company. They get to gather meaningful work experiences through industry induction, close mentorship, attachments and capstone projects to deepen industry-relevant skills.

    The students would acquire skills and experience relevant to the needs of the company while the company gains a productive contributor and an avenue to recruit, assess, groom and retain talent.

    Singtel has also worked with the InfoComm Development Authority of Singapore (IDA) on the Cyber Security Associates and Technologists Program.

  • More than 1 in 4 cloud apps are high risk

    More than 1 in 4 cloud apps are high risk

    More than a quarter (27%) of third-party apps can be classified as high risk, according to research from CloudLock Cyberlab.

    Analysis conducted across 10 million users, 1 billion files, and nearly 160,000 unique applications found that cybercriminals can exploit weaknesses in high-risk apps to gain programmatic access to corporate platforms impersonating end users. 

    The shadow IT dilemma is meanwhile only becoming more challenging as usage is increasing exponentially year over year, the company said.

    The past three years saw nearly a 30 times increase in the number of apps detected, from 5,500 to nearly 160,000. Each application instance represents a backdoor through which hackers can infiltrate and externalize sensitive corporate assets.

    CloudLock Cyberlab said an organization may embrace its employees’ “shadow” exploration of innovative technology solutions and sanction a subset of these apps as Productivity IT, but it’s essential to closely monitor the connected third-party apps and identify cloud native malware in real time.

    Security conscious enterprises recognize the high risk associated with connected third-party apps and take immediate action. While apps can be banned for any number of reasons, including concerns around productivity, a clear majority are banned because of the security vulnerabilities they introduce. 

    The key recommendation is to reduce cloud app risk by establishing an acceptable use policy, with which organizations can significantly reduce the application risk level organization-wide. Automating whitelisting or banning of potentially risky applications is an effective strategy. 

    “The shift to the cloud creates a new, virtual security perimeter that includes third-party apps granted access to corporate systems,” said Ayse Kaya Firat, CloudLock director of customer insights and analytics.

    “Today, most employees leverage a wide variety of apps to get their jobs done efficiently, unwittingly exposing corporate data and systems to malware and the possibility of data theft.”

  • Telstra invests in security company vArmour

    Telstra invests in security company vArmour

    Australian operator Telstra has formed a partnership with – and made an investment in – data center and cloud security company vArmour.

    Under the agreement, investment arm Telstra Ventures has participated in vArmour’s recent $41 million Series D funding round.

    Telstra will also add vArmour’s security offerings to its portfolio of enterprise services. In the long term, the operator said it will also be able to develop security consulting and managed services for its customers.

    The vArmour platform is designed to give organizations application-layer control over their networks to help stave off, detect and respond to cyber threats.

    Jeremy Howe, Telstra’s director of IP Data and Security Solutions, commented that the acquisition is aimed at addressing its enterprise customers’ evolving security demands.

    “We see a growing demand among enterprise customers for solutions that help them secure their data in a private, public and hybrid cloud mix. One of the main concerns companies have in embracing cloud services is data control and security,” he said.

    “vArmour’s distributed security software addresses the problem of traffic blindspots inside data centers. This helps businesses protect themselves from one of the critical emerging threats in the security environment, in addition to the benefits of having greater visibility of what is going on with your data.”

  • Singtel, Inmarsat join forces on maritime cyber security

    Singtel, Inmarsat join forces on maritime cyber security

    SingTel has forged a strategic alliance with Inmarsat to jointly offer cyber security tools for the global maritime industry.

    Under the partnership, Trustwave, the cyber security arm of Singtel, will provide its Unified Threat Management (UTM) managed solution, to be integrated with Inmarsat hardware onboard ships, to protect data reduce cyber risk for maritime companies.

    Singtel said the UTM service offers a suite of cyber security defenses, such as advance firewall, anti-virus, intrusion prevention and web-filtering.

    Singtel and Inmarsat plan to launch the new maritime cyber security service in the second half of 2016, the companies said a joint statement.

    The new service will be delivered through FleetXpress, the highly anticipated high-speed broadband communication service Inmarsat launched in March for maritime and offshore operators.

    Andrew Lim, managing director of business group at SingTel’s Enterprise Group, said the partnership with Inmarsat is important for the company as it marks the first phase in rolling out Singtel cyber security services for Inmarsat.

    “As maritime systems become more digital, it is imperative for the industry to protect data onboard ships against all forms of cyber attacks. Our partnership with Inmarsat will provide maritime companies with a cyber security solution to meet rapidly evolving cyber threats, globally,” the executive said.

    Gary Gagnon, Inmarsat’s senior vice president of global cyber security, said the partnership with Singtel supports the company’s commitment to the market and elevates the benchmark for maritime cyber security.

    “The landscape of shipping is changing. As we move from traditional shipping into the ship intelligence era, the threat of cyber attacks have never been more real,” commented Ronald Spithout, president of Inmarsat Maritime.

    “Risks from malicious attacks and unlawful access to a ship’s intelligence, its system infrastructure and networks cannot be ignored, and the shipping industry needs to take action.”

    The Singtel-Inmarsat collaboration comes a day after Inmarsat announced it will use its new Global Xpress satellite fleet to provide in-flight connectivity services for the airline industry.

  • Peruri expands operation to digital security business area

    Peruri expands operation to digital security business area

    The Indonesia state-owned money printing company Peruri has expanded operation to digital security business area in preparation to enter the era of integrated smart security to be competitive and able to keep pace with the modernization.

    “In order to have greater competitiveness in digital era we are expanding our wings to digital security that we could provide an integrated smart security service,” President Director of Peruri, Prasetio, said here, Thursday.

    The expansion is prompted by the rapid advancing technology that necessitated change in the world economic system that forces Peruri to continue to expand from service to business model, he said.

    “We are not only strengthening our core business of money printing , but we are also expanding operation to digital security business area through our subsidiary Peruri Digital Security by providing solution such as Certificate Authentication and Smart Card,” he said.

    Peruri also has a strategy in entering the era of integrated smart security, which is centered in transformation of company including transformation of human resources, business , structure and system as well as culture, according to him.

    “With the transformation we hope Peruri could continue to chalk up positive growth in the coming years,” he said.

    In a bid to achieve the positive growth, this year Peruri will be focused on market expansion, promoting reputation and strengthening competitiveness, he added.

    The strategic steps include reorientation of market from formerly focused only on domestic market to global market, and restructuring parent and subsidiaries to be more effective in marketing, he said.

    “Another strategic step is reorganization to be in line with the 2016 company budget working plan and long term business road map,” Prasetio said.

    With the strategic steps and preparation made ahead of the era of integrated smart security, the company is set to contribute significantly to the countrys economic development, he said.

    Peruri chalked up around Rp3.051 trillion in income in 2015 or more than doubling income of Rp1.39 trillion in the previous year.

    Its net profit rose to Rp284 billion or an increase of more than ten times from Rp23.49 billion in 2014.

    The company signed a memorandum of understanding to improve synergy with a number of state construction companies including construction companies — Adhi Karya, Amarta Karya, Brantas Abipraya, Hutama Karya, Istaka Karya, Pembangunan Perumahan, Nindya Karya, Perum Perumnas, Waskita Karya and Wijaya Karya.

    It also signed MoU with state-owned telecommunication company to develop digital business.

  • Gunnebo looks to expand above inflation

    Gunnebo looks to expand above inflation

    Sweden-based security service provider Gunnebo Security Group is looking to see its Indonesian business grow by better than inflation, especially with support from infrastructure projects and its newly installed cash-management facility, the company’s regional executive says.

    Senior vice president for Gunnebo’s Asia-Pacific region, Sacha de La Noe, said on Tuesday that his company would keep its investment focus on cash-management products, one of the group’s backbone businesses, while at the same time he expected growth from other lines, such as from its fire-system services.

    De La Noe said the presence of a local production facility in the country was also expected to have a significant impact on regional sales, with about 70 percent of the local production being shipped to other countries, he added.

    “With more cash to handle in society, we need to find more effective ways to manage that cash. In Indonesia, I see a high number of notes in circulation, and retailers are looking for better ways to handle the cash and that will increase,” he said.

    The group announced in a press statement dated Jan. 15 that it would optimize its cash management manufacturing footprint by transferring production from its Trier plant in Germany to manufacturing units in Binefar, Spain and in Indonesia, to improve customer service levels and manufacturing efficiency. The Trier plant has turnover of around 9 million.

    Indonesia is the second-largest market for Gunnebo in Asia Pacific, with the largest being India. Indonesia contributes around 20 percent to regional sales.

    Gunnebo Indonesia country manager Hindra C. Kurniawan said his company’s revenue normally grew by around 10 percent annually. He added that his company expected that local cash-handling facilities would be its backbone in five years.

    Among its attempts to boost its cash-handling business in Indonesia, Gunnebo has cooperated with taxi operator Express Transindo Utama (Express Group) since 2014 to provide cash-handling equipment in taxi pools in the greater Jakarta area.

    Besides focusing on the cash-handling business, Gunnebo is also looking to see growth in other businesses, such as fire systems, which will be supported by a number of infrastructure projects in the country.

    Among the company’s key projects is providing a fire system for a major power plant in Cirebon, West Java, and with the government’s massive 35-gigawatt power-generation expansion, De La Noe said the group expected an increase in future demand.

    He also said that his company would work with state-run airport operator Angkasa Pura to provide security services in 32 airports that were being built and expanded across the nation. He said that a discussion with the airport operator was scheduled in March.

    The company is also involved in Jakarta’s Mass Rapid Transport (MRT) project, providing, among other facilities, entrance security and ticketing, with De La Noe stating that the MRT’s security system was among the group’s key businesses.

    According to a previous report, Gunnebo produces 30,000 safety deposit boxes annually; 60,000 fire extinguishers and 5,000 to 10,000 cash-handling machines at its factory in Cibitung, West Java.

    Gunnebo had annual turnover of around 610 million in 2014. It has 32 sales companies worldwide, 11 factories across the globe and around 100 additional networks. Its businesses include cash management, safes and vaults, entrance security, electronic security and specifically in Indonesia, fire security.

  • Message apps pose growing risk for China securities regulator

    Message apps pose growing risk for China securities regulator

    While using mobile messaging and social media apps for trading is not unlawful in China, regulations require reliable monitoring and recording of trades to prevent activities such as insider trading or market manipulation, and to keep on top of threats to market stability such as excessive margin trading.

    China Securities Regulatory Commission (CSRC) has been clamping down on breaches, including fining four brokerages in September for failing to collect information about the identities of clients who traded stocks through external systems.

    It also shut down third-party trading software used by brokers that helped traders skirt regulations by dividing one account into many sub-accounts without the need to register a name, according to local media.

    Even so, using apps to buy and sell stocks over mobile phones is common in a country where retail investors account for 80 percent of share market volume.

    Despite closer scrutiny from China’s regulators, brokerages including large listed firms like China Galaxy Securities and smaller entities such as Great Wall Securities, started offering WeChat share trading account services last year in a bid to access the growing pool of retail traders.

    China Galaxy Securities and Great Wall Securities did not return requests for comment.

    Overall account openings swelled to around 46 million in the first half of 2015, from around 2 million over the same period in 2014, according to official data.

    For brokers, the advantages of using WeChat are obvious, since it is the preferred means of communication for many of its 600 million users.

    But a case in Hong Kong last month highlights regulators’ concerns with the trend.

    The regulator there suspended a trader for receiving a buy order on WhatsApp, a messaging app owned by Facebook Inc, in breach of the internal communication policies of the firm he then worked for, BTIG, noting that the company had no control over the recording and retention of such messages.

    GROWING RISKS

    While the Hong Kong Securities and Futures Commission code of conduct does not prohibit the use of social messaging apps, it encourages the strict recording and time stamping of all communications and says the use of mobile phones for orders is “strongly discouraged”.

    Some of China’s institutional investors are also using WeChat to instruct their brokers.

    “In practice lots of people don’t care about compliance and take orders on WeChat,” said a Hong Kong-based institutional sales trader specializing in China.

    The CSRC did not respond to requests for comment, nor did Tencent Holdings Ltd, the owner of WeChat.

    Such concerns are not limited to China.

    Clara Shih, chief executive and founder of Hearsay Social, Inc, a San Francisco-based social media compliance company, said messaging apps are also a potential gap in the compliance systems that U.S. financial services firms have spent years building.

    U.S. brokerages must monitor and store copies of employees’ electronic communications for three years and have a duty to protect clients’ personal information and confidentiality, tasks made more complicated by the proliferation of social media platforms.

    Technology has evolved in recent years to make it easier for companies to monitor employees’ activity on traditional social media platforms such as Facebook and Twitter. But WhatsApp and WeChat are not compatible with that technology, Shih said.

    Using social media for business is a growing trend but also a growing risk for compliance, said Craig Brauff, chief executive of Erado, a social media compliance company in Renton, Washington.

    “Regulations are designed to keep honest people honest. If someone really wants to be dishonest, there are lots of ways around it,” he said.

  • MasterCard online identity checks enhanced

    MasterCard online identity checks enhanced

    MasterCard has introduced a new online Identity Check, a suite of technology solutions that use advanced technologies to prove a consumer’s identity and simplifies the online shopping experience.

    The credit card system provider says existing methods to prove the identity of online shoppers often take consumers away from a retailer’s website, adding to the time it takes to shop online, too often leading to payments being declined or cart abandonment.

    MasterCard says Identity Check “will put identity verification at the cardholder’s fingertips” using technologies such as biometrics and SMS-delivered one-time passwords.

    “Today, people shop on all sorts of devices, and they expect technology to simplify and secure the transaction,” said Ajay Bhalla, president of Enterprise Security Solutions, MasterCard. “This is exactly what Identity Check delivers.”

    MasterCard Identity Check represents a shift in strategy from a reliance on what the consumer knows (passwords), to what they have (mobile phone or other smart device) and who they are (biometrics). Hundreds of cardholders in the Netherlands began using biometric-enabled payments last month, while a similar trial is also underway in the US.

    US financial institutions can choose to participate in MasterCard Identity Check beginning in the middle of 2016, with a global expansion in 2017.

    MasterCard research shows 53 per cent of shoppers forget crucial passwords more than once a week, losing more than 10 minutes when they reset their accounts. People in Singapore estimate that they lose more 15 minutes every time they have to reset a forgotten password.

    “As a result, more than a third of people abandon an online purchase, while six in 10 said it led to missing a time-sensitive transaction like buying concert tickets, and more than one in two in Australia and Singapore have been locked out of a website because of this,” MasterCard reports.

    On average, people have to enter passwords eight times per day for the 10 different online accounts or applications they regularly use every week. People in Japan and India enter passwords 11 and nine times a day, respectively, above the global average.

    More than one in five people use the same password for everything, while a further 58 per cent rely on only a few different variations – despite warnings it puts them at greater risk from fraud. In Singapore, nearly one in three people use the same password for all their accounts.

    Globally, more than half of people want to see passwords replaced by something more convenient, while continuing to deliver the same levels of protection and peace of mind.

  • Cyber attacks on US retailers drop, but records stolen remain high

    Cyber attacks on US retailers drop, but records stolen remain high

    Cyber attacks agains US retailers declined by as much as 50 percent since 2012, but the number of records stolen from them remains at near record highs, a new IBM study shows.

    IBM Security researchers recently reported that during the year cyber attackers still managed to steal more than 61 million records from retailers despite the decline in attacks, demonstrating cyber criminal’s increasing sophistication and efficiency.

    According to the research, cyber attackers are using new techniques to obtain massive amounts of confidential records with increased efficiency. This is why despite the decline in the number of attacks, the perpetrators were able to impact a far greater number of victims with each incident.

    “The threat from organized cyber crime rings remains the largest security challenge for retailers,” said Kris Lovejoy, General Manager, IBM Security Services. “It is imperative that security leaders and CISOs in particular, use their growing influence to ensure they have the right people, processes and technology in place to take on these growing threats.”

    Surprisingly, majority of cyber attackers scaled back their hacking efforts around Black Friday and Cyber Monday, the two biggest shopping days of the year.

    IBM’s Digital Analytics Benchmark, the number of daily cyber attacks during the two week period (24 November – 5 December) was 3,043, nearly one third less than the 4,200 average over this period in 2013.

    In a year’s time, the number of breaches also dropped by more than 50 percent for Black Friday and Cyber Monday. In 2013, there were more than 20 breaches disclosed including several large breaches that caused the number of records compromised to rise drastically, reaching close to 4 million. Over the same period in 2014, 10 breaches were disclosed which resulted in just over 72,000 records getting compromised

    Despite this “cyber threat slow down,” the retail and wholesale industries emerged as the top industry target for attackers in 2014, a potential result of the wave of high profile incidents impacting name brand retailers.

    IBM need that while there has been a rise in the number of Point of Sale (POS) malware attacks, the vast majority of incidents targeting the retail sector involved Command Injection or SQL injection. The complexity of SQL deployments and the lack of data validation performed by security administrators made retail databases a primary target.

  • Rise in the market for video surveillance

    Rise in the market for video surveillance

    The growing use of video surveillance systems in sectors such as hospitality, banking and financial, government, transportation, education and retail has created huge growth opportunities for the manufacturers, distributors and system integrators in this industry.