{"id":27501,"date":"2019-02-20T14:24:49","date_gmt":"2019-02-20T14:24:49","guid":{"rendered":"http:\/\/www.intelligentcio.com\/eu\/?p=27501"},"modified":"2019-02-20T14:39:05","modified_gmt":"2019-02-20T14:39:05","slug":"tenable-experts-discuss-security-vulnerabilities-and-poor-cyberhygiene","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/eu\/2019\/02\/20\/tenable-experts-discuss-security-vulnerabilities-and-poor-cyberhygiene\/","title":{"rendered":"Tenable experts discuss security vulnerabilities and poor cyberhygiene"},"content":{"rendered":"<p>Tenable, the cyberexposure company, has announced that Tenable Research has discovered several zero-day vulnerabilities in the PremiSys access control system developed by IDenticard. When exploited, the most severe vulnerability would give an attacker unfettered access to the badge system database, allowing him\/her to covertly enter buildings by creating fraudulent badges and disabling building locks. According to its website, IDenticard has tens of thousands of customers around the world, including Fortune 500 companies, K-12 schools, universities, medical centres and government agencies.<\/p>\n<p>Today\u2019s modern enterprise has an extremely complex digital infrastructure comprised of both traditional and modern assets \u2014 from workstations and on-premises servers to building security systems and smart devices. This level of complexity has made it increasingly difficult for security teams to establish secure networks in dynamic enterprise environments. The PremiSys zero-days are a stark reminder that the mass adoption of emerging technologies has quickly blurred the lines between physical and digital security. This discovery comes just a few months after Tenable Research found another zero-day flaw \u2014 dubbed Peekaboo \u2014 in global video surveillance software.<\/p>\n<p>PremiSys technology allows customers to grant and restrict access to doors, lockdown facilities and view integrated video. Once exploited, the most severe flaw would give cybercriminals administrator access to the entire badge system database via the PremiSys Windows Communication Foundation (WCF) service endpoint. Using the administrator privileges, attackers can perform a variety of actions like downloading the full contents of the system database, modifying its contents or deleting users.<\/p>\n<p>\u201cThe digital era has brought the cyber and physical worlds together thanks, in part, to the adoption of IoT. An organisation\u2019s security purview is no longer confined by a firewall, subnets, or physical perimeter \u2014 it\u2019s now boundary-less. This makes it critically important for security teams to have complete visibility into where they are exposed and to what extent,\u201d said Renaud Deraison, Co-founder and Chief Technology Officer, Tenable. <\/p>\n<p>\u201cUnfortunately, many manufacturers in the new world of IoT don\u2019t always understand the risks of unpatched software, leaving consumers and enterprises vulnerable to a cyberattack. In this case, organisations that use PremiSys for access control are at a huge risk as patches are not available. Beyond this particular issue, the security industry needs to have a wider dialogue about embedded systems and their maintainability over time. The complexity of the digital infrastructure is increasing and so is its maintenance. We need vendors to be committed to delivering security patches in a timely manner and in a fully automated way. Tenable Research is committed to cooperating with willing vendors on coordinated disclosures to help ensure consumers and organisations alike are secure. Industry collaboration is key to helping customers manage, measure and reduce their exposure.\u201d<\/p>\n<p><em>Intelligent CIO Europe<\/em> caught up with Gavin Millard, Vice President of Intelligence, Tenable to hear his views on the risks posed to businesses as a result of poor cyberhygiene:<\/p>\n<p><strong>Current cybersecurity risks facing enterprises and how these are being tackled<\/strong>  <\/p>\n<p>One of the biggest problems faced by organisations is basic cyberhygiene. If you consider some of the big breaches, they\u2019re always said to be sophisticated threat actors, nation-state and really advanced. I think that\u2019s a get-out. A lot of the issues organisations are facing are simple foundational things that they\u2019re not doing well such as patching. If you think about the way that an attacker gets in, they\u2019re taking advantage of known vulnerabilities to deploy code. Of all the big breaches, they are very rarely nation-state, they are very rarely advanced, they\u2019re just persistent. Any network that is broken into is done by finding the right flaw to take advantage of and this isn\u2019t done by a complex attack, it\u2019s usually a lack of a patch. <\/p>\n<p><strong>The evolving threat landscape<\/strong><\/p>\n<p>There are two main themes resulting from developments over time, one being the number of assets we\u2019re trying to manage is ever increasing and the amount of these assets is expanding exponentially. The problem with those assets is that they\u2019re also changing type. If you look back a few years ago, people were dealing with static and accessible physical assets. Nowadays, we\u2019re moving to ephemeral and immutable assets. Everyone is going through the Digital Transformation process and pushing things into the cloud &#8211; which is a good thing &#8211; but it means that their attack surface is increasing and the amount of available assets to target is increasing. Irrelevant of type, the amount of vulnerabilities that are being disclosed every day is increasing. This year, the amount of vulnerabilities is expected to grow to around 52% in comparison to last year. <\/p>\n<p>Another thing to consider is that many organisations are utilising Machine Learning (ML) and Artificial Intelligence (AI) and doing some really clever things with it. If cybercrime is a multi-billion-dollar industry, we must believe that they are making those same investments. So, leveraging ML and AI to automate flaws in people\u2019s environments. Attackers are going to get smarter, but so are defenders. As an example \u2013 we are building ML models to predict the vulnerabilities that attackers are going to use. We\u2019ve got PhD Data Scientists working on this right now, allowing them to predict which vulnerabilities attackers use. If we can predict this, irrelevant of their method, we can close that attack surface down. Defence and attack are going to increase in speed and volume.   <\/p>\n<p><strong>Prioritising patching vulnerabilities<\/strong> <\/p>\n<p>Not every vulnerability is the same and the ones that get noticed are the ones that have a catchy name and logo. They\u2019re not always the scariest vulnerabilities out there. The vulnerabilities that need to be patched are those that attackers are actually using. We need to take a more threat-centric approach to vulnerabilities. I don\u2019t care about the 15,000 vulnerabilities that were disclosed last year, I care about the 7% that actually had exploits available for them. I care about the assets of the 7% of those 15,000 vulnerabilities that are Internet-facing. They\u2019re the things we need to be patching. You can\u2019t patch everything, so let\u2019s make sure we patch the right things.<\/p>\n<p><strong>Greatest emerging threats<\/strong> <\/p>\n<p>I think the greatest threat is the money. The biggest issue that faces cybersecurity today isn\u2019t the latest vulnerability, it\u2019s the fact that cybercriminals can monetise. Compared to 20 years ago, cybercriminals of today can make millions from cyberattacks. Criminals are involved in attacking organisations through IT because it\u2019s massively profitable. As long as it continues to be easy for cybercriminals to break in and monetise the attack, it\u2019s just going to increase. <\/p>\n<p><strong>Combatting the cybersecurity issue and reaching a final solution<\/strong><\/p>\n<p>We can combat the cybersecurity issue today. The biggest threat in IT security isn\u2019t ATP, it\u2019s apathy. People aren\u2019t taking the right steps to solve this issue. Take WannaCry as an example, it was a massive vulnerability threat and Microsoft warned people before it came into effect. A month later, WannaCry hit and people were surprised. Systems weren\u2019t patched properly and the vulnerability targeted these systems. We know the answer, we\u2019re just not doing it. <\/p>\n<p><strong>Educating the end-user on potential threats to allow them to contribute to solving the issue<\/strong> <\/p>\n<p>We must question whose fault it is if, for example, an end-user clicked on a phishing email. I think end-user education is really important but you\u2019re not going to be able to identify a really clever phishing email. I\u2019ve been in this industry for 20 years and sometimes even I\u2019m not sure. What needs to happen in the industry is that everyone accepts these foundational controls and takes cybersecurity seriously, otherwise it\u2019s just going to continue. We should be making it difficult for cybercriminals to monetise and until we do, they\u2019ll just keep breeding.<\/p>\n<p><strong>Top tips for securing an enterprise<\/strong><\/p>\n<p>My top three tips are the same ones I\u2019ve been giving for 15 years: patch your systems; have good passwords; and reduce your attack surface. These are the cyber essentials. <\/p>\n<p><strong>Tenable\u2019s customer satisfaction<\/strong>  <\/p>\n<p>We\u2019re focused on solving one problem; vulnerability. Most vendors in this industry try and go inch-deep, mile-wide. We are 100% focused on fixing the vulnerability issue and we invest all of our resources into doing so. This problem has been around since IT began and has not yet been solved. We have the answer and we are executing on that and our customers love that they\u2019re with us on this journey. Tenable is laser-focused on execution; on solving the vulnerability problem. <\/p>\n<p><strong>Tenable\u2019s future in the next year<\/strong> <\/p>\n<p>Tenable is really focused on quantifying organisations\u2019 risk and really making that easy. If you don\u2019t know what your risk exposure is, it\u2019s really hard to address it. We\u2019re also focused on measuring \u2013 how well are you doing things &#8211; because you can\u2019t improve what you can\u2019t measure. In the coming months, we\u2019re going to enable all our customers to benchmark themselves. That benchmarking enables you to make decisions. <\/p>\n<p><strong>Advice to up and coming CISOs<\/strong><\/p>\n<p>It\u2019s really easy nowadays to fall for the marketing jargon that surrounds cybersecurity. Don\u2019t buy into the hype; focus on the foundation. Measure your effectiveness and make sure you\u2019re implementing those controls effectively. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tenable, the cyberexposure company, has announced that Tenable Research has discovered several zero-day vulnerabilities in the PremiSys access control system developed by IDenticard. When exploited, the most severe vulnerability would give an attacker unfettered access to the badge system database, allowing him\/her to covertly enter buildings by creating fraudulent badges and disabling building locks. According [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":27502,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[57,27,29,93,24],"tags":[10966,4969,10690,570,10964,10691,10696,28,10965,10689,10692,10693,54,10485,10695,8434,10694],"class_list":["post-27501","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-intelligent-technology-newsletter","category-software","category-top-stories","category-used","tag-attack-surface","tag-cyberattack","tag-cyberexposure","tag-digital-infrastructure","tag-gavin-millard","tag-identicard","tag-industry-collaboration","tag-iot","tag-patching","tag-premisys","tag-premisys-windows-communication-foundation","tag-renaud-deraison","tag-security","tag-tenable","tag-tenable-research","tag-threat-landscape","tag-unpatched-software"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/27501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/comments?post=27501"}],"version-history":[{"count":9,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/27501\/revisions"}],"predecessor-version":[{"id":27995,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/posts\/27501\/revisions\/27995"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media\/27502"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/media?parent=27501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/categories?post=27501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/eu\/wp-json\/wp\/v2\/tags?post=27501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}