Showing posts with label BOHH Breakdown. Show all posts
Showing posts with label BOHH Breakdown. Show all posts
Tuesday, 13 February 2018
BOHH Breakdown Part 22: Inside Cryptojacking - What Is It and Why It's So Popular
In our last post, we talked about the hot topic of cryptocurrency and how to better protect your investments. This week we will continue the cryptocurrency topic and take a closer look at one type of attack – cryptojacking (what it is and why it is becoming so popular).
To understand the concept of cryptojacking, we first must address how it’s possible. Cryptocurrencies such as the popular Bitcoin and Ethereum are not created by a central bank like regular money, but are instead created or mined by distributed computing resources solving complex equations. This means a big cost of mining new coins is electricity. As such, cryptojacking has become popular to avoid this issue and involves passing the electricity cost off of mining to an unsuspecting user. It works by slipping a mining component without the knowledge of users on to devices or websites and harvesting power off of those to steal cryptocurrency digital cash.
What are the methods?
The most popular methods to carry out a cryptojacking attack include in-browser cryptojacking where a JavaScript code lives in the browser. When a user visits a page where the JavaScript code is already embedded, it is then activated in the background and consuming resources without the user knowing; The other is server access to install a attack. This is where an attacker finds and exploits an existing vulnerability and deploys a full-scale cryptocurrency miner on a system.
Why Is This a Cybersecurity Risk?
What makes cryptojacking so tricky is that you’re paying for electricity and stress on your hardware without realizing it, without approving it. Because it’s clandestine, you don’t know whether cryptojacking stops when you leave the website or whether they’ve placed a cookie that will carry on once you’ve navigated away.
While there is no immediate way to tell if a website page you are using or device has a hidden mining component on it, there are some ad blockers and website plugins coming out. However, if you want to keep yourself fully protected, the best way to prevent it at the moment is pulling the plug on your network and turning off your computer. The risk is yours!
Today was the last BOHH Breakdown, but not the last blog. We will continue our blogging on a weekly basis and will have a diverse set of thought pieces coming from our team of experts. Thank you for coming back each week to read our BOHH Breakdown and we look forward to continuing to deliver interesting thought pieces for our readers.
Tuesday, 6 February 2018
BOHH Breakdown Part 21: How to Better Protect your Cryptocurrency Investments
In our last post, we addressed how to support digital innovations without sacrificing security. Today, we are talking about the hot topic of cryptocurrency and how to better protect your investments.
Many of the major cryptocurrency exchanges have seen a major drop in price over the last few days. Bitcoin, one of the most popular cryptocurrency exchanges is reported to have had a major downfall from its highest value of almost $20,000 to now trading below $7,500 as of Monday according to an article from Ars Technica.
Does this mean we are headed for the burst of the cryptocurrency bubble? Only time will tell if this will be the start of the end or if this is just a natural dip in the market adjusting to mainstream adoption. One thing is for sure though, with over 1,000 cryptocurrencies on the market and many celebrities jumping in on the cryptocurrency craze, there are still many people excited to jump on the cryptocurrency bandwagon.
Because cyber criminals are starting to capitalize on the money being put in to cryptocurrency trading, it’s important for users to know proper security measures to take to help keep their cryptocurrency wallets more protected. Below are several tips people should think about when they are investing in cryptocurrencies.
- Use Multi-factor authentication: this will add extra security layers for hackers to get through while trying to empty your wallet.
- Don’t store all your passwords in the same place: make sure to have your wallets and passwords stored in different places so both are not compromised in a hack.
- Use different passwords: don’t use a password that you have used before and make sure the password you choose is unique. Here is a past blog we have featured on the do’s and don’ts of picking a good password.
- Don’t save your passwords on your phone or computers.
- Think about where you are transacting from. For example, by using public Wi-Fi, it makes you more vulnerable for someone to intercept your data in a man-in-the-middle attack. It is advisable to use your own Wi-Fi network that is setup with password protection to your cryptocurrency trading.
- Be careful of what you post on social media. This may sound silly, but by posting personal information about yourself and the cryptocurrency exchanges you are using on your social tools can give criminals easy access to find more information about you and use it to their advantage.
- Have a dedicated email for each of your cryptocurrency exchange. Never use the same one for different exchanges.
- Spread your cryptocurrencies among several wallets, so if one gets hacked, not all of them are compromised.
While these are not full-proof plans to ensure your cryptocurrency exchanges are not hacked, it does help add more layers of protection. Hopefully these tips offer some insight in security measures to take before investing in cryptocurrency exchanges.
Come back next week and we will continue focusing on the cryptocurrency topic and look specifically at one type of attack – cryptojacking and how to protect against it.
Tuesday, 30 January 2018
BOHH Breakdown 20: Supporting Digital Innovation Without Sacrificing Security
In our last post, we took a closer look at Artificial Intelligence and how it can enhance the cybersecurity industry. Today, we are addressing how to support digital innovations without sacrificing security.
What makes a company successful? Ask almost any enterprise today and they will tell you that innovation is a critical piece to ensuring long-term success in the current and evolving business environment. The companies that are able to adapt to the ways in which the market is evolving, compete with newer entrants, and even capitalize on the opportunities and possibilities innovation brings, will be the ones to emerge as successful leaders. Since 2000, a significant number of Fortune 500 companies that are no longer trading, as they couldn’t embrace business change.
Innovation can mean a lot of different things, but for today’s purpose, we will focus on digital innovation of new devices, tools and methods to help businesses streamline their operations and communication engagements with customers. As such, cloud services, IoT implementations and chatbots are some of the top digital innovations that are dominating today’s enterprise ecosystem. Adoption of these technologies is exploding across enterprise cloud services. And while every enterprise would agree these channels are good business investments, there are still challenges of these tools opening their systems and users to massive, widespread and malicious security threats.
At BOHH, we believe that innovation should not come at the expense of security and vice versa. While it may be tricky, there is a way to find balance between the two. Below are several recommendations to support integrating digital innovations in to your business strategy without sacrificing security.
- Consider how these new innovations are handling data before full adoption. Organizations must plan for how the information is stored, how long it’s stored for, how it’s used, and who has access to it on these new channels. This is especially important for highly regulated industries that will deal with sensitive customer information. Perhaps before initiating complete adoption, organizations should consider automating some services using digital innovation tools but still have them working in tandem with human teams to improve the data flow without sacrificing security.
- Research thoroughly the digital innovation tools you plan to integrate if you are using a third party. Many brands are integrating tools such as chatbots and IoT devices that are third-party platforms. While this is a convenient solution, it does mean that the security features are decided by the third party’s own security branch, which means the organization does not have as much control over the security features on the tools they are using to interact with customer data that needs to be protected. If possible, businesses should rely on building their own digital innovation channels from scratch with security built in at the foundation level or working with third party platforms that follow this same rule. Because businesses hold responsibility in keep their data and customers’ data safe, it is important to do a lot of research on the security protocols needed before integrating these tools in to their business strategy.
- All communication on these new tools should be encrypted and deployed only on encrypted channels. This is something that is relatively easy to set up on an organization’s own website and encryption is a great tool to help keep data protected. However, it is important to note that if the data is not encrypted from end-to-end in the transaction process, it leaves an opening for hackers to get access to that data once they have penetrated your system. End-to-end encryption is key to keeping data encrypted throughout the whole data journey, so the data stays better protected from bad actors no matter what channel it is being stored on or accessed through.
Hopefully these tips offer some good balance on adding innovative digital tools to your business strategy without compromising security. Come back next week and we will switch gears a bit and talk about the hot topic of cryptocurrency and how to better protect your investments.
Tuesday, 23 January 2018
BOHH Breakdown Part 19: AI is Booming in Cybersecurity – Let’s Looks at How and Why
In our last post, we talked about the good and bad to come out of the Intel microprocessor security flaws. Today, we are taking a closer look at AI and how it can enhance the cybersecurity industry.
Since its inception more than 50 years ago, much of the conversation associated Artificial Intelligence (AI) was centered on the future of robots and science fiction; however, in recent years AI has been dominating the conversation in the volatile cybersecurity market. AI is becoming so popular as tool to combat cybersecurity in the last couple of years, that it is quickly becoming a standard tool to have in your overall security strategy. But what makes it so great for fighting cybercrime?
Staying ahead of hackers has become increasingly challenging, and the sheer number of beach attempts on a given company daily is unmanageable by humans alone. This is where AI can be helpful by looking for and detecting any network traffic abnormalities. AI uses a compound set of algorithms to detect patterns and predict outcomes from a large amount of data online. As such, the self-learning capabilities and ability to recognize patterns and anomalies within them, makes AI a great tool to detect cybersecurity threats within the network in real time.
This means AI will be influential in helping security teams prioritize important and relevant information among the high volume of data now available to reduce noise and solve attacks more rapidly. It will enable security teams to automate the irregular activity detection process and help reduce/flag breach attempts to a few thousand worthy of human review.
Another area AI offers great potential is in the cybersecurity workforce. In 2017 there were a lot of conversations surrounding a global shortage of cybersecurity professionals with the specialized skills to address the evolving security challenges faces companies daily. So far, not much progress has been made. AI could be a good method to help address the growing cybersecurity skills gap as some of the areas it can help with include helping automate some of the security tasks like network scanning, as well as help train employees on cybersecurity awareness.
Additionally, security companies are not the only ones noticing the benefits of AI – many hackers are too. It is predicted that 2018 will bring a rise in AI-based attacks from cyberhackers to mimic human behaviors. In order to keep up with these complex and coordinated attacks, there will be an even greater need for companies to invest in their AI cybersecurity tools to meet these new threats head on, making it an important spend in they cybersecurity strategy.
Like many companies, BOHH believes AI capabilities are a great tool to integrate in a cybersecurity strategy and our AI Engine is a core component to our security approach. We use an AI Engine to do threat analysis and to prevent intrusion – it manages ports, interacts with user requests, and maintains a secure connection by identifying and removing any unwanted traffic before it is passed along and gets access to any of the backend applications or databases.
AI offers great promise in the cybersecurity realm, and it will be exciting to see how the technology continues to develop and impact the industry.
Come back next Tuesday for our breakdown on how to support digital innovations without sacrificing security.
Tuesday, 16 January 2018
BOHH Breakdown Part 18: Highlighting the Good and Bad of the Intel Security Flaw
In our last post, we shared tips for kicking your security strategy off right in 2018. Today, we will take a deeper look at the recent Intel chip security flaw news that shocked the world and highlight the good and bad to come out of it.
When it came out that Intel chips were exposed to security flaws and the vulnerabilities affect almost all the microprocessor chips manufactured by Intel, it immediately put fear in to pretty much everyone who owns a computer or cell phone. In fact, according to the industry consultancy IDC, the Intel chips back 98 percent of data center operations The two flaws are called Meltdown and Spectre and could potentially allow hackers access to all the memory contents of computers, mobile phones, and servers.
While the flaw discoveries highlight some of the issues with security, there is also a silver lining. Below we highlight several of the good and bad points to come out of this.
Since everyone likes good news before the bad, we will start with the good:
- This news has prompted users to make sure they update their systems with the new patches and updates. Additionally, in order to protect themselves from the chip flaws, many security experts have recommended that users go in to their settings and install security updates automatically – this will ensure their systems stay up to date as possible as manufacturers release system updates. This is a great start in getting every day users more invested in security and show them how the much talked about cybersecurity industry can affect them personally.
- One of the two flaws, Meltdown, can be addressed with software updates, which many of the major manufactures including Apple, Google, Microsoft, and Amazon, jumped on top of getting a patch out for their systems quickly to protect against the Meltdown vulnerability. It is a positive too see these top companies make the fix a priority.
- So far, there has not been any evidence that hackers have been able to capitalize on these flaws. This means, this is just a good warning for better security preparation.
Unfortunately, with the good always comes the bad:
- The flaws were discovered by independent researchers. While it is great the flaws were discovered, it does bring to question why Intel was not more on top of it.
- One of the flaws, Spectre, is not an easy fix. Unlike the Meltdown flaw which is a software fix, Spectre is a hardware fix that could mean the need to redesign the processor itself some researchers suggest. This means it is not an easy fix.
- The sheer size of the potential danger these flawed microprocessor chips could inflict across the world globally needs to be taken very seriously. This highlights our reliance on technology and assumption that they are built securely from the foundation, and how just one flaw exploited by a hacker could impact the entire world.
The ramifications of how these bugs will impact computing the industry is still yet to be fully determined, but in the meantime, it’s important to look what we can learn from it. Come back next Tuesday when we take a closer look AI and how it can enhance the cybersecurity industry.
Tuesday, 9 January 2018
BOHH Breakdown Part 17: Advice from BOHH for Starting 2018 Right and Tackling Security
It’s the start of a new year and with that comes new goals and resolutions. As cybersecurity continues to be a top concern for companies, it will most certainly be at the top of most companies’ resolution lists. However, staying ahead of the quickly evolving cybersecurity industry has become increasingly challenging, and it’s hard for companies to stay on top of all the threats and solutions they should have in place. Below are several ways BOHH recommends for companies to start 2018 right and help them better tackle their security resolutions.
Finalize your General Data Protection Regulation Plan:
If this is not in action now or at the top of your list, it is time to get started on this now. Going in to effect later this year in May, companies will need to comply with the GDPR regulations, which applies to all companies that use or process data in the European Union. Since there are a lot of moving parts to ensuring compliance, it is important to take a strategic approach. There are many new changes that companies will be accountable for, so it’s critical to research them properly and have a specific plan for each one. Having your GDPR plan in action and completed by May 2018, will help you avoid fines or penalties imposed on a non-compliant company, as well as stand out as leader in the market committed to security.
Always Implement New Security Patches and Update Old Systems:
Because software systems are constantly evolving, security updates and patches are commonly released to keep up with software improvements. Often, these patches come with instructions to make the updates, and failure integrate these into your system can lead to vulnerabilities and allow hackers to gain access company and customer data. Unfortunately, as we saw in many data breach instances in 2017, many businesses often ignore patches or updates until they encounter issues. When this happens, it leaves the door open for hackers use malware and other type of attacks to exploit these holes and get into your system. Companies that monitor when new patches and updates are out and implement them immediately will face less risk to breaches than those do not and avoid having to undergo an embarrassing explanation on why they are not up-to-date with the recommended security systems.
Create a Zero Trust Model:
There is no longer any trust in security. It’s clear there are no longer any trusted and an untrusted engagements on our security devices, networks or even users. In 2018, companies need to eliminate the idea of a trusted network and start implementing a zero-trust model approach that views all users and network traffic as untrusted that must be verified and enforce strict access control.
There’s No One Size Fits All:
When it comes to security, there is no quick fix or a magical solution that will solve all your security woes. Because there are more tactics to get into a company’s network, it’s hard for companies to rely on just one or two solutions to stay protected. The best way to stay on top of all the threats is by having a combination of solutions like patched systems, constant updates, multi-factor authentication, firewalls, encryption, AI-based tools and more. More than ever, it is important to take the time to make sure you have the right security investments in place and not rely on just one or two.
Hopefully these recommendations will be useful to get your 2018 security strategy started right. Come back next Tuesday when we take a closer look back at the latest news on the Intel chip security flaw and what is the good and bad to take from it.
Tuesday, 19 December 2017
The BOHH Breakdown, Part 16: A Year in Review
BOHH Labs entered the market this year and what a great year it has been. We received some excellent media attention this year and built some great media relationships. We also hit the ground running with industry networking events, speaking and attending at 10 events including SAP Teched Las Vegas, Oracle Open World and an IBM Watson Summit.
BOHH Labs also kicked off its first year in business being recognized as a winner of the Google/SAP Intelligent App Challenge. This was the inaugural year for the challenge, and BOHH Labs was selected as innovative solution winner among hundreds of global entrants for its submission including the use of SAP HANA Express Edition, Google Cloud Platform, Machine Learning, Artificial Intelligence and encryption to address the security of data transport and access for Cloud and Internet of Things (IoT) streamline workflows.
While BOHH Labs has been off to a great start in 2017, unfortunately the same can’t be said for the state of the cybersecurity industry. The number of attacks, methods to carry them out, and the number of people affected by breaches continues to rise. However, BOHH Labs remains committed to tackling the cybersecurity industry and delivering a new approach that will help keep data protected that the traditional security methods are no longer able to provide. We predict 2018 will continue to be a challenging year for the cybersecurity industry, but we are ready to tackle that challenge head on.
At the closing of a great first year, we are excited with the progress made in 2017 and we look forward to seeing what 2018 holds in store.
We have enjoyed sharing some of our thoughts with you over the past several months through the BOHH Breakdown blogs and we are eager to get started again in 2018.
Tuesday, 12 December 2017
The BOHH Breakdown, Part 15: How to Get Your Board Involved in Your Cybersecurity Strategy
In our last post, we shared tips for individuals to stay safe as they begin their Christmas holiday shopping this season. Today, we will address an increasingly important topic – how to address cybersecurity with your board of directors.
One thing is becoming increasingly clear in today’s climate of nonstop breaches: security matters and data is becoming an asset. It’s time organizations treat cybersecurity as a core business value. Business leaders, starting from the Board of Directors and moving through the C-suite, must insist on their organizations adapting the most effective security measures in their IT platforms, workflows and processes today.
However, many board members feel they lack the technical aspects about what their role should be as directors when it comes to cybersecurity. Below are some tips to get the conversation started.
- Speak in language your board understands. Many board members may not know the technical terms when speaking about technology and security. Try to break it down in terms that are simple and easy for a non-technical professional to understand.
- Talk about security investments and cybersecurity risks in terms of how it impacts the organization’s business and financial bottom line.
- Communicate everything in numbers. The board is the oversight of the company, so money matters. If you can relate security investments, potential breach loss, etc. in dollars, it will have a greater impact to how cybersecurity can impact the organization overall.
- Tie cybersecurity measures to the competitive marketplace. Highlight what the company’s competitors are doing, so the board can understand how the company needs to keep pace with the market.
- Share examples of how cybersecurity breach incidents have impacted other organizations in your similar market (Equifax, Uber etc.) – did they lose customers, pay a breach settlement fine, pay a ransom fee?
- Present the facts of the company. To start a conversation on why having proper security strategies in place is important, gather a list of the organization’s valuable data assets that require protection, so you can customize the conversation to your company’s specific needs.
- Share a game plan on where and how you think the board should be involved in the company’s cybersecurity strategy. Having this prepared ahead of time will help show the board where they fit into the plan.
- Bring in a security expert to talk to your board about the importance of having proper cybersecurity measures in place. Having a trusted source always goes a long way in the decision-making process, plus highlights the consequences of a breach such as fines, potential senior job losses etc.
- Educate them on all of the laws and industry compliance rules in place. This will help them understand why a certain amount of the business strategy needs to be designated to security investments. Highlight that General Data Protection Regulation (GDPR) is effective starting in May 2018, so there must be a strategy to meet this deadline.
- Be concise and clear. Do not waste their time. Prepare ahead of time the main points you want to hit to educate them on the necessary security investments.
Leaders who make security a business priority and an integral part of their organizations daily operations, can help navigate their organization to better long-term performance and success.
Hopefully these will be a useful tool to get the conversation started. Come back next Tuesday when we take a look back at all of the developments and accomplishments made by BOHH this year.
Tuesday, 5 December 2017
The BOHH Breakdown, Part 14: How to Stay Cyber Safe During the Christmas Holiday Shopping Season
In our last post, we shared what the team at BOHH Labs believes will be the hot topics in 2018. Today, we offer tips for individuals to stay safe as they begin their holiday shopping this season.
We have all heard the stories: people losing money in a cyber scam, a bankcard that has had to be replaced because it has been compromised, and many other ways that simply swiping our cards this holiday season put our finances at risk. So, with the holidays right around the corner, here are a few steps to protect yourself while you are out shopping for your near and dear:
- Check for encryption on websites when shopping online. Look for a small lock icon somewhere on your browser and URLs that begin with “https:” This means the site is secured and your data is encrypted.
- Make sure your security software is up-to-date, regardless of if you are using a computer or mobile device.
- Phishing attacks are more frequent than ever and are projected to be one of the top methods for cybercriminals to carry out scams this season. Learn to recognize and avoid phishing emails, threatening calls, and texts from thieves posing as legitimate organizations such as your bank, or credit card company. With lots of coupons, discounts and sales, be cautious on what links you click on and don’t download attachments from unknown or suspicious emails.
- Don’t respond to emails requesting your account details. Do not ever send personal information or credit card information via email. It is best to call back instead using a phone number you can verify from their official website.
- When shopping online, think about where you are doing it from. For example, by using public Wi-Fi, it’s rather simple for someone to intercept your data in a man-in-the-middle attack. It is advisable to use your own Wi-Fi network that is setup with password protection when doing online holiday shopping.
- Sign out of your accounts when you complete your purchases online. This may sound easy, but you should always log out of your online session rather than let it expire. This will help reduce the chances of your session being hacked. Most site will log you out automatically after you are idle for a couple of minutes, but logging out is still a good habit.
- Make sure that when you purchase online you know the seller. If it is your first purchase from them, check other users feedback. It’s not necessary to get 100%, but two or three bad reviews over poor customer service or non-delivery should raise an alarm.
- When withdrawing cash at ATM’s (remember the days when it was used for everything?), security is not just about looking over your shoulder. Scammers often target an ATM and place a card reader over the card slot so that they can copy your card details. This is not as easy with a chip card, but they also can have a camera on the machine to access the details required to skim your card. Always check the slot to make sure it has not been tampered with.
- Passwords (yawn). Boring maybe. A necessity? Definitely. Also, the biggest hole in your security? Probably. Use different passwords for every site so that when one is hacked, and your details are stolen, only that site is compromised, not all of them.
Now that we’ve highlighted some of the tools to employ when holiday shopping this season to stay cyber safe, come back next Tuesday when we will share ideas to get your board members involved in your cybersecurity strategy.
Tuesday, 28 November 2017
The BOHH Breakdown, Part 13: BOHH Predicts the Top Security Trends for 2018
In our last post, we reviewed some of the best security techniques being used to keep our data protected and that we are grateful for in honor of Thanksgiving. Today, we will shed some light on what the team at BOHH Labs believes will be the hot topics in 2018 and share our predictions.
Every year experts turn to their magic crystal ball and share their thoughts on predictions they have for the upcoming year. Will we see the same trends from 2017 repeat themselves or we will see new ones develop in 2018? Below our experts from BOHH Labs weigh in on the discussion and offer their predictions for what’s ahead.
Blockchain will be the Heart of The Finance Industry:
It’s no secret that blockchain is the hot new technology, and we will see this technology be embraced predominantly by the financial industry. Because of its decentralized and distributed nature, more financial services institutions are looking at blockchain to replace the centralized business model. As an example, KPMG, one of the “Big Four” accounting firms, recently just joined the Blockchain Advocacy Group.
As Bitcoin is based around blockchain technology, and it has seen significant growth in value during 2017 event though it’s an unregulated currency, will continue to increase when security is a potential issue or will it fall off the tracks?
NASDAQ Advising People to Jump on Security Boards:
We all know security breaches are a big deal, so why aren’t more board of directors versed in the area? As the oversight of an organization’s value and growth, it’s critical for security to become a business priority and an integral part of their organizations’ daily operations. This means a companies’ cybersecurity activities must hold as much weight in decision-making in the same way as they do in the financial ones. As such, in 2018, we will see NASDAQ advise more security expert to join companies’ boards, so they can help companies navigate to better long-term performance and success.
Website Attacks Become a Bigger Target:
One of the type of attacks that we will see gain more traction this year is the website attack. With the growing use of online services (checking accounts, merchant accounts and Point-of-Sale (POS) systems, etc. now going through the web) the risk of attacks is large and has the potential to affect any institution using these services, as it opens access to institutions’ backend databases, document stores and applications all within easy reach.
Because an attacker gains access to the website through a hijack of a user’s requests and then makes a simple change of code to redirect payment information their way, while NOT stopping the requests correct path, this type of attack is very hard to find, but incredibly easy for attackers to undertake.
The website is no longer just a marketing tool. It has become a business tool, and as such, it now needs to be properly protected from attacks and placed inside a firewall, and preferably completely encrypted, so that attackers are unable to change, manipulate and delete code to their advantage.
Continued Chat Bot Growth:
The growth in the business use of chat bots will continue to increase based on their interactive nature and their capabilities to complement existing call center activities by taking away mundane tasks. However, with their interactive capabilities and the ability to use location services to reserve a table in your proximity and even order an item such as a coffee, it is becomingly increasingly important that all chat bot transports are secure. Similar to website data breaches, should intrusion attacks penetrate the chat bots, user trust will be lost as well as the possible loss of confidential data.
Public Cloud Adoption will Continue to Challenge Enterprise Companies:
While Cloud adoption is the goal of most global enterprise companies to help improve their IT speed, business agility, and modernize existing on-premise applications such as ERP, Finance and HR, adoption will be limited due to the time and money needed to implement cloud security standards that emulate enterprise on premise infrastructures.
By using a secure gateway to a Public cloud provider, enterprise accounts could accelerate their cloud deployments and benefit from the economics of cloud, plus have the ability of choice and move Cloud providers as the business sees fit.
IoT Attacks Will Keep Growing:
We will continue to see companies scramble to implement security for IoT devices and applications. We’ve already seen the significant and expansive impact that hacks on IoT devices can have and it will only continue as we move in to 2018.
General Data Protection Regulation:
Effective from 25th May 2018 companies will need to comply with the General Data Protection Regulation (GDPR) which applies to all companies that use or process data in the European Union. As several analyst articles suggest, only 25% of companies are expected to be in full GDPR compliance in May 2018, and as a consequence of this, the initial fine or penalties imposed on a none compliant company will be significant to warn other companies of its importance.
Now that we’ve highlighted some of the major security themes we predict will take center stage in 2018, come back next Tuesday when we will share some tips to stay cyber safe in the holiday shopping season.
Tuesday, 21 November 2017
The BOHH Breakdown, Part 12: Giving Thanks to Our Favorite Security Techniques
In our last post, we talked about some of the most famous corporate data breaches and how BOHH could have prevented them. This week, in honor of Thanksgiving, we are looking at some of the best security techniques being used to keep our data protected and giving thanks.
Encryption
This is hardly a new strategy for keeping our data protected, but it is has become a standard protocol in today’s security measures. The core foundation of encryption focuses on converting information or data into a form unreadable by anyone except the intended recipient. While encryption itself does not prevent hackers from getting access to data, it does make it unreadable to those who intercept it. At BOHH, we believe the parties at the two ends of a data message – the sender and requester – should be the only ones who have access to that data message. We use a keyless encryption algorithm from end-to-end to ensure all data – both at rest and in transit – stays protected, without any possibility of decrypting it, even at the sever level.
Artificial Intelligence
Though popular culture used to associate Artificial Intelligence (AI) with robots and science fiction, it is on the rise as a technology influencing a variety of sectors, including the cybersecurity industry. Staying ahead of hackers has become increasingly challenging. As such, the self-learning capabilities and ability to recognize patterns and anomalies within them, makes AI a great tool to detect threats. At BOHH, our AI Engine is a core component to our security approach. We use an AI Engine to do threat analysis and to prevent intrusion – it manages ports, interacts with user requests, and maintains a secure connection by identifying and removing any unwanted traffic before it is passed along and gets access to any of the backend applications or databases.
Firewalls
Firewalls have been around for a while and are often overlooked as a part of a security strategy, but they are a useful tool to help thwart attacks from external bad actors. Much like its name describes, firewalls are used to keep networks protected and act as a first line of defense of all data traffic that passes in and out of the network. Based on pre-set rules and security requirements set by a company, firewalls examine incoming traffic against those pre-set rules and blocks unauthorized attempts trying to get in. Firewalls continue to be one of the most popular tools in the IT industry and continue to evolve over time as more sophisticated security challenges and attacks develop. At BOHH, we work in conjunction with a firewall system. The BOHH security platform sits on top of the firewall and enables full encryption inside the firewall for added security to keep data protected.
Multi-Factor Authentication
As technology advances and hackers’ attacks evolve and become more sophisticated to take advantage of these advancements, using only a single authentication system, like a password is no longer enough. This is where multi-factor authentication comes in. The goal is to add multiple layers of security to make it more difficult for unauthorized users to take over an account. Multi-Factor Authentication is a great technique because if one factor is compromised, an attacker still has one or two other barriers to get through before successfully breaking into the target. There are many different methods to do Multi-Factor Authentication such as password followed by text, email, pin number confirmation, or even biometric authentication (voice, fingerprint, etc.) which is gaining popularity as technology advances. At BOHH, we employ multi-factor authentication via voice authentication, fingerprint or sending code confirmation messages to your mobile phone or email for verification.
Each of these technologies have a critical place in companies’ security strategy; however, each of these are just on piece of the whole puzzle and should not be the only tool used to combat security threats. For security to keep pace with the evolving and complex attacks in today’s complex environment, there must be a more holistic approach when securing data by combining the various security solutions available.
Now that we’ve highlighted some of the security techniques we are thankful for, come back next Tuesday when we will share some of our predictions for what lie ahead in 2018.
Tuesday, 14 November 2017
The BOHH Breakdown, Part 11: Famous Data Breaches & How BOHH's Approach Could Have Helped
In our last post, we talked about the state of security for the Internet of Things (IoT) and how BOHH Labs’ approach brings more confidence to keeping these devices secure. This week, we will take a look at some of the most famous corporate data breaches to occur, and how BOHH could have prevented them.
Breach: Equifax (2017)
One of the biggest data breaches to dominate headlines recently is the Equifax breach. While it may not go down in history as one of the biggest breaches, it certainly made a big splash due to the sensitive nature of the data that was leaked. Over 143 million consumer records were exposed, and the information exposed included names, Social Security numbers, birth dates, addresses and in some cases, driver's license numbers. Due to poor network security and failure to update its software, hackers gained access to Equifax’s database through a web application vulnerability. While it was thought it was a US attack, its impact was global and affected Equifax customers and non-customers.
Type of Breach: Web Application Attack, leaving gaping holes to its network for hackers to exploit.
How BOHH Would Have Prevented It: Because BOHH’s service intersects all data requests, it is able to stop malicious attacks on the back-end database. Each data request has to go through a validation process before it gains authorized access to the backend database. BOHH also uses a patented system so a user’s data request never has direct access to the network server It can also check the return from the database, making sure only authorized information is returned.
Breach: Target (2013)
Though this breach took place several years ago, this is still one of the most famous breaches that has occurred due to the volume of people affected that compromised millions of its customers’ credit card and debit card accounts. All it took for 70 million people to have their credentials stolen was changing one line to the source code in the payment processing system and voilĂ . Target was unaware of the redirection of credit card details for a significant period of time which impacted their ability to resolve the issue and reduce the customer and finance impact.
Type of Breach: Phishing Attack, threat from unwanted access to a website, where changes are made to the website code enabling data to be re-routed/pushed to thief.
How BOHH Would Have Prevented It: BOHH prevents data from being re-routed through its patented block file system enabling full encryption of a website inside the firewall. When a user requests the website, BOHH goes to the server, and the AI engine pulls up the right blocks and decrypts them. It then puts the page together and passes it in memory to the web browser. This is without any direct access to the server from the requester, preventing phishing attacks and website changes to confidential data.
Breach: NSA Contractor Edward Snowden (2013)
One of the biggest intelligence leak in US history took place thanks to a NSA contractor abusing his system administrator insider access to the database and confidential information.
Type of Breach: Insider Threat/System Administrator abusing internal control and weakness in security procedures to leak confidential information.
How BOHH Would Have Prevented It: With BOHH, each dataset is encrypted with dynamically allocated keys and no encryption keystore, making it impossible for any user (including database admin) to steal useable data. This means that even if an insider gets access to confidential information, it is unreadable because there is no way to hack the encryption key.
These are just a few of the many attacks that could have been prevented by BOHH’s innovative approach to security.
Now that we’ve highlighted how BOHH could have helped prevented some of the most famous breaches around, come back next Tuesday when we take a look at some of the best security techniques being used to keep our data protected and give thanks in honor of Thanksgiving.
Tuesday, 7 November 2017
The BOHH Breakdown, Part 10: How BOHH Brings More Confidence to IoT Security
In our last post, we talked about the rise in popularity of chat bots and how BOHH supports the security of them. For this week’s installment, we will take a look at the state of security for the Internet of Things (IoT) and how BOHH Labs’ approach brings more confidence to keeping these devices secure.
Market analysts predict dramatic growth in the adoption of enterprise cloud services incorporating IoT technologies. In fact, Gartner predicts that more than half of major new business processes and systems will incorporate some element of the IoT by 2020.
However, the world has already witnessed some of the consequences to the growing adoption of IoT with the likes of the infamous Mirai botnet that took down major companies including Twitter, Amazon, PayPal and Netflix and off the Internet.
While this trend continues to gain popularity in updating companies’ strategies, the IoT industry continues to be a top challenge for security professionals and keeping those devices and networks safe.
Some of the major challenges companies are faced with by integrating IoT applications include:
- Many IoT products are designed with convenience in mind and don’t have the proper security measures built in place at the design level/product development, leaving them insecure from the start.
- IoT devices often come with old or unpatched operating systems. Additionally, these systems often need frequent software updates to patch for vulnerabilities, and if users do not complete these, it opens the devices to risks.
- Most IoT devices come with a default password that users don’t often change, making it easier for cybercriminals to hack these devices and easily hop on to a company’s network that the user is trying to connect with.
- IoT devices communicate with your network, as well as multiple other outside systems and networks companies don’t have control over. This throws open the door to malicious attacks directly on the enterprise databases and applications accessed by these services.
Although the security industry has been talking about how to secure IoT devices for years now, there are still too many backdoors and insecure devices being used today. Unfortunately, with the rise in IoT networks, comes the rise of security threats and questions about who is really at the other end of the connection.
Companies’ digital strategies should not come at the expense of security. At BOHH, we support the use of IoT devices, while keeping the enterprise network safe by enabling a secure flow of all data traffic between these devices and the end enterprise services.
We help enterprise networks stay better protected against attacks open by IoT services by managing the whole data transaction process and working natively with the IoT devices to secure the messages that are passed back and forth between the requestor and the responder. Our approach separates out the requestor from the request and securely allows, after AI validation, the request to navigate to whatever end-point is required. This leaves the requestor waiting until the response has been collected and checked before moving it forward and returning the request to the requestor.
Unlike other security approaches, our approach prevents a request in to the network without being validated before gaining authorized access to a backend system or application. This approach enables BOHH to separate, recognize and maintain a secure connection to all relevant enterprise systems (i.e. the many different IoT devices and systems they connect with) and prevents any third parties from trying to hop on (piggyback onto) the connection and get to the backend database/application.
The use of IoT is here to stay, and is only predicted to grow, so it is more important than ever that new security is applied to securing enterprise networks to keep pace with innovation in enterprise IoT services.
Now that we’ve highlighted how BOHH helps enhance IoT security, check back in next Tuesday when we take a look at some of the most popular past breaches and how BOHH could have helped.
Tuesday, 31 October 2017
The BOHH Breakdown, Part 9: The Rise of Chatbots and How BOHH Helps you Use Them Securely
In our last post, we looked at several ways companies can increase their potential to prevent data breaches. This week will be addressing the rise in popularity of chat bots and how BOHH supports the security of them.
Bots (chat bots) are quickly becoming the interface of choice for many organizations and individuals (particularly the younger generation), as they are an invaluable way that people, computers and IoT devices can access and update information on demand.
While bot technology has been around for some time now, there are several reasons why we are seeing a major uptick in their use.
First, the core technology that powers bots is improving dramatically and enables computers to process language and converse with humans in ways they never could before. The advancements in Artificial Intelligence (AI) and Natural Language Processing (NLP) is making it possible for bots to better understand users’ needs and how to complete them.
Additionally, the way we communicate has changed drastically – gone are the days where in-person visits, phone calls and even emails are the primary services for companies to engage with customers. Instead, people today demand conversational (voice) rather than browsing (keyboard) services that integrate into their digitally connected lives and offer them 24/7 interaction from anywhere at any time. One of the major appeals of bots for organizations is that they are a cheaper and faster method to serve and reach their customers like never before and offer more on-demand services that often results in cost savings for a more streamlined experience. Bots are not replacing customer services teams, but complimenting them by improving customer satisfaction (Net Promoter Score) indicators. It also supports organizations’ objectives of providing greater customer self-service, especially when user’s will make swifter decisions to move from one provider to another if customer service is poor.
As such, we are beginning to see a major uptick in companies integrating bots services into their business and customer engagement strategies. However, while bots offer many advantages, current bot solutions are NOT secure and leave a new door open to malicious attacks as they provide direct access to an organizations’ network, applications and databases.
By not addressing these security implications, companies are at risk of jeopardizing confidential data, as well as revenue from malicious attacks. At BOHH Labs, we believe that digital and technology advancements should not come at the expense of enterprise security. So, to help prevent attacks that are opened from bot services, BOHH’s approach to bots secures beyond what the market currently offers today, and ensures that the data request is validated before gaining authorized access to a backend system or application. The BOHH Bot Security Service separates out the requestor from the request and securely allows the request to navigate to whatever end-point is required. This leaves the requestor waiting until the response has been collected and checked before moving it forward and returning the request to the requestor.
We do this in a number of ways, but mainly with our AI and NLP engines, which manage the data transaction process – the AI engine looks at and cleans any unwanted traffic, while the NLP engine takes the incoming message and determines where it should be sent – meaning the user can use plain text with no command languages. Together, these two technologies can separate, recognize and maintain a secure connection to many different systems and prevent any third parties from trying to hop on the connection and get to the backend database.
All of this is done in real time (hundredths of a second), so there is no disruption to the user experience, just the confidence that their transaction/request is secure.
Now that we’ve highlighted why bots usage among companies is on the rise and how BOHH helps enhance bot security, check back in next Tuesday when we take a look at IoT security.
Tuesday, 24 October 2017
The BOHH Breakdown, Part 8: Many Breaches Are Preventable – Let’s Look at How
In our last post, we revisited some of the most pressing cybersecurity trends in 2017 and tracked where the industry is at as the end of the year nears. Today, we will address an important subject: breaches and how many of them can be prevented.
This year has seen its fair share of major breaches – from WannaCry and Petya to Equifax and the recent Deloitte email server hack. All these breaches have something in common – and it is not just the fact that millions of records were exposed – they all could have been prevented or greatly reduced by simple patches and software updates.
Unfortunately, these are just a few of the attacks that could have been prevented by simply updating software systems and vulnerabilities. While security is no easy feat, it is becoming too common that many breaches are occurring due to companies’ negligence caused by failure to update software components that are known to be vulnerable for months or even years.
There is no excuse for breaches when there are known security updates available to fix the vulnerabilities. A large part of the issue today is that companies have not been prioritizing these fixes and other security solutions. Below are several recommendations from BOHH Labs that companies can employ to help bring better tools to their security strategy.
Update old systems and Implement Security Patches
Businesses often ignore server patches or updates until they encounter issues. When this happens, hackers use malware and other type of attacks to exploit these holes and get into your system. Because Software systems are constantly evolving, security updates and patches are commonly released to keep up with software improvements. Often, these patches come with instructions to make the updates and failure integrate these into your system can lead to vulnerability and allow hackers to gain access company and customer data.
Implement a Zero Trust Model
In today’s complex cyber world, there is no longer any trust in security. It is clear there are no longer a trusted and an untrusted engagement on our security devices, on our networks or even users. It is time companies eliminate the idea of a trusted network and start implementing a zero-trust model approach that views all users and network traffic as untrusted that must be verified and enforce strict access control. At BOHH Labs, we have embraced the Zero Trust Model into our security approach and prevent unauthorized third-party interaction with all data traffic by a keyless encryption algorithm that automatically invalidates data when accessed by unauthorized users, rendering it useless to the unauthorized party.
Break the Data Request for Better Security
Following off the concept of the Zero Trust Model, it is important not to assume that every data request that comes in is from a trusted source. As such, a user’s data request should never have direct access to the network server as there could be malicious attackers who have jumped on to the connection to get entrance into your system. One way to help prevent this situation is to break every data request before it goes into your network. At BOHH, we employ this technique and when a data request comes in to the company network, the BOHH security appliance receives the request first and decrypts the request before passing it through, knocking out any other requests trying to hop on the original request and get into the network.
Encrypt End-to-End
Encryption is a great tool to help keep data protected, but if the data is not encrypted from end-to-end in the transaction process, it leaves an opening for hackers to get access to that data once they have penetrated your system. At BOHH, we believe the parties at the two ends of the data message – the sender and requester – should only have access to that data message. At BOHH, we use keyless encryption from end-to-end to ensure all connections to backend assets reveal no infrastructure details to an attacker as to location of firewall, keystore, database, or other assets if they find a way in to the network. End-to-end encryption is key to keeping data encrypted, without any possibility of decrypting, even at the sever level.
There is no sign of hackers and attacks against companies stopping any time soon but these are a few tools companies can use to help stay better protected from tomorrow’s breach.
Now that we’ve highlighted some ways companies can increase their potential to prevent data breaches, check back in next Tuesday when we take a dive in to the world of bots and how they can be used to securely.
Subscribe to:
Posts (Atom)


