Domain Computer rename failed with access denied


Issue:

IT Helpdesk or desktop admins are not able to rename a computer that is already a member of a domain. Similarly, they have issues in resetting the user’s password remotely.

Environment:

Windows Server 2016 Domain Controllers hardened with STIG/CIS benchmark

Reference:

The SAMRPC protocols makes it possible for a low-level or non-privileged user to query a machine on network for information. Generally, a user can use SAMRPC to enumerate users, including privileged accounts such as local or domain administrators, or to enumerate groups and group membership from local SAM and Active Directory. An attacker can use this information as starting point to compromise a domain or network.

To mitigate this risk, configure ‘Network access: Restrict clients allowed to make remote calls to SAM’ security policy setting to force the security account manager (SAM) to do an access check against remote calls.

By default security descriptor on computers beginning with Windows 10 version 1607 and Windows Server 2016 allows only the local (Built-in) Administrators group remote access to SAM on member servers, and allow Everyone access to domain controllers.
CIS Benchmark also recommend allowing only Administrators on MS only.

Problem start with if the Domain Controllers are also configured with same security policy setting.

Solution:

This security policy setting can be configured to allow low-level or non-privileged account either through group policy or registry setting on each DC.

Security Consideration:

The SAMRPC protocol has a default security posture that makes it possible for low-privileged attackers to query a machine on the network for data that is critical to their further hacking and penetration plans.

The following example illustrates how an attacker might exploit remote SAM enumeration:
1.      A low-privileged attacker gains a foothold on a network.
2.      The attacker then queries all machines on the network to determine which ones have a highly privileged domain user configured as a local administrator on that machine.
3.      If the attacker can then find any other vulnerability on that machine that allows taking it over, the attacker can then squat on the machine waiting for the high-privileged user to logon and then steal or impersonate those credentials.

Countermeasure

You can mitigate this vulnerability by enabling the Network access: Restrict clients allowed to make remote calls to SAM security policy setting and configuring the SDDL for only those accounts that are explicitly allowed access.

Active Directory Security: Leverage AdminSDHolder for persistent backdoor in AD


Leverage AdminSDHolder for persistent backdoor in AD

Each domain in Active Directory contains an AdminSDHolder object which resides in System partition of a domain. Distinguished Name (DN) of this object is “CN=AdminSDHolder, CN=System, DC=PENLAB, DC=LOCAL”.  Active Directory Domain Services uses this object, protected groups and SDPROP to secure privileged users and groups from unintentional modification. The AdminSDHolder object has unique set of Access Control List (ACL) which is used to control the permission of security principals that are member of built-in privileged Active Directory groups. Each time the process runs on PDC Emulator operation master role, it compare the ACL on all security principals (users, groups, and computers) that belong to protected groups against the ACL of AdminSDHolder object.

Protected Objected

 Listed groups and their members are protected by AdminSDHolder object. Look for the AdminCount attribute in Active Directory with value set to 1. AdminCount value never set back to 0 even though account is removed from the protected groups. This is by design as per Microsft.
  •          Account Operators
  •         Administrators
  •         Administrator
  •         Backup Operators
  •         Domain Admins
  •         Domain Controllers
  •         Enterprise Admins
  •         Schema Admins
  •         Krbtgt
  •        Print Operators
  •         Read-only Domain Controllers
  •          Server Operators
  •         Replicators

Default AdminSDHolder object ACL

  •         Authenticated Users: Read
  •         SYSTEM: Full Control
  •         Administrators: Modify
  •         Domain Admins: Modify
  •         Enterprise Admins: Modify

SDPROP process runs every 60 minutes and reset the ACL as per AdminSDHolder object if found modified. This process can be run manually.

AdminSDHolder object

An attacker can use AdminSDHolder object to grant the ability to modify the privileged groups in Active Directory by leveraging a key security component. This will provide an attacker, persist way of exploiting the Active Directory.  Even the system administrator or Active Directory Administrator changed the protected group or user, SDPROP will change the security ACL as per of the AdminSDHolder.

1. Open AdminSDHolder object and check the default permission
2. Add domain account penlab\pentest1 to AdminSDHolder object permission and grant Full Control.


3. Verify the user pentest1 is only Domain Users group member


4   Run the SDPROP manually or just wait for next cycle of the process
5   Open the Domain Admins group property and see that penlab\pentest1 is added to security permission with full control


6   Logon with penlab\pentest1 account to a member server or workstation and open Active Directory snap-in. Since this user have full access to object, add the pentest1 account to Domain Admins or Enterprise Admin


 Add pentest1 account to Domain Admins group




7    Now the penlab\pentest1 become the Domain Admins
8    Penlab\pentest1 user account now is able to manipulate not only high privileged group but also all the privileged user accounts, like enable, disable, deletion, creation and a lot

Detection and Control

It is now so important to monitor the ACLs configured on the AdminSDHolder object. It is recommended to keep the default ACL unless there is an absolute requirement to add a group or user. Monitor the users and groups with attribute AdminCount set to 1 to identify accounts with ACLs set by SDPROP

GDPR - Individual Rights on Privacy


GDPR - Individual Rights 

The GDPR is more specific about the information that need to be provided to people about what the organizations do with their personal data. Organizations must actively provide this information to individuals in a way that is easy to access, read and understand.
When an organization collect personal data from the individual it relates to, or personal data is collected from a source other than the individual it relates to it must provide them with privacy information at the time their data is collected as per below:
  • ·         Within a reasonable period of obtaining the personal data and no later than a month;
  • ·         If organization use data to communicate with the individual, at the latest, when the first communication takes place; or
  • ·         If organizations envisage disclosure to someone else, at the latest, when they disclose the data.

Organizations must actively provide privacy information to individuals. Organizations can meet this requirement by putting the information on company’s website, but must make individuals aware of it and give them an easy way to access it.
When obtaining personal data from other sources, organizations do not need to provide individuals with privacy information if:
  • ·         the individual already has the information;
  • ·         providing the information to the individual would be impossible;
  • ·         providing the information to the individual would involve a disproportionate effort;
  • ·         providing the information to the individual would render impossible or seriously impair the achievement of the objectives of the processing;
  • ·         organizations are required by law to obtain or disclose the personal data; or
  • ·         organizations are subject to an obligation of professional secrecy regulated by law that covers the personal data.

Individual Rights on Privacy

The GDPR is more specific about the information you need to provide to people about that what the organizations do with the personal data. I have summarized some of the key elements of the individual’s right on privacy to understand it concisely. The GDPR provides the following rights for individuals:

The Right to be Informed

The right to be informed covers some of the key transparency requirement of the GDPR. It is about providing individuals with clear and concise information about their personal data collection and uses. Article 13 and 14 of the GDPR specify what individuals have the right to be informed about. Below are some of the points:
  • ·         Individual have the right to be informed about the collection and use of their personal data. This is the key transparency requirement under the GDPR.
  • ·         Organizations must provide individuals with ‘privacy information’ including purpose for processing personal data, retention period of that personal data, and who it will be shared with.
  • ·         Organizations must provide privacy information to individuals at the time of collection of their personal data from them.
  • ·         If the organizations collect personal data from other sources (such as publicly accessible sources), they must provide individuals with privacy information with a reasonable period and no later than a month.
  • ·         Organizations must provide privacy information to individuals which is concise, transparent, intelligible, easily accessible, and must use clear and plain language.
  • ·         Organizations must regularly review, and where necessary, update the privacy information. They must bring any new uses of an individual’s personal data to their attention before you start the processing.
  • ·         If organizations apply AI (Artificial Intelligence) to personal data, must be upfront about it and explain your purposes for using AI.

The Right of Access

The right of access gives individuals the right to obtain a copy of their personal data as well as other supplementary information. It helps individuals to understand how and why they are using their data and check that they are doing it lawfully. An individual is entitled to:
  • ·         Get confirmation that the organization is processing their personal data
  • ·         Get a copy of their personal data and other supplementary information
  • ·         Organizations have one-month time to respond to the request and cannot charge a fee in most of the circumstances

In addition to a copy of their personal data, organizations also have to provide individuals with the following information:
  • ·         The purpose of data processing
  • ·         The categories of personal data concerned
  • ·         The recipients or categories of recipient organization disclose the personal data to
  • ·         Retention period for sorting the personal data or, where this is not possible, the criteria for determining how long data will be stored
  • ·         The existence of individuals rights to request rectification, erasure or restriction or to object to such processing
  • ·         The right to file a complaint with the supervisory authority
  • ·         Information about the source of the data, where it was not obtained directly from the individual
  • ·         The existence of automated decision-making (including profiling)
  • ·         The safeguards organization provide if personal data is transferred to a third country or international organization

The Right to Rectification

Under Article 16 of the DGPR, individuals have the right to have inaccurate or misleading personal data be rectified. Although organizations may have already taken steps to ensure that the personal data was accurate when they collected it, this right imposes a specific obligation to reconsider the accuracy upon request.
  • ·         An individual can make a request for rectification verbally or in writing
  • ·         An individual has a right to have inaccurate personal data be rectified, or completed if it is incomplete.
  • ·         Organizations have one calendar month to respond to a request

Organizations can refuse to comply with request for rectification if they consider that a request is manifestly unfounded or excessive, considering whether the request if repetitive in nature. In such case organization can request a ‘reasonable fee’ to deal with the request; or refuse to deal with the request.
The GDPR does not give a definition of the term accuracy. However, the Data Protection Act 2018 (DPA 2018) states that personal data is inaccurate if it is incorrect or misleading as to any matter of fact.

The Right to Erasure

Under the Article 17 of the GDPR, individuals have the right to have personal data erased. This is also known as the ‘Right to be Forgotten’. This right is not absolute and only applies in certain circumstances.
  • ·         The personal data is no longer necessary for the purpose for which the organizations originally collected.
  • ·         Organizations are replying on consent as their lawful basis for holding the data, and the individuals withdraw their consent
  • ·         An individual object to processing their data, and there is no overriding legitimate interest to continue this processing
  • ·          Organizations are processing the personal data for direct marketing purposes and the individual objects to that processing
  • ·         Organizations are processing the data unlawfully

There is an emphasis on the right to have personal data erased if the request related to data collected from the children. This reflects the enhanced protection of children’s information, especially in online environments, under the GDPR.
If organization process data collected from children, they should provide particular weight to any request for erasure if the processing of data is based upon consent given by a child especially any data processing of their personal data on the internet. This is still the case when the data subject is no longer a child, because a child may not have been fully aware of the risks involved in the processing at the time of consent.

The Right to Restrict Processing

Under Article 18 of the GDPR, individuals have right to restrict the processing of their personal data where they have a reason for wanting the restriction. This maybe because they have issue with the content of the information, an organization hold. Individual have the right to request the organization to restrict the processing of their personal data in the following circumstances:
  • ·         Individual contests the accuracy of their personal data and organization are verifying the accuracy of the data
  • ·         The data has been unlawfully processed and the individual opposes erasure and request restriction instead
  • ·         The individual has objected to organization their data under Article 21(1), and organizations are considering whether their legitimate grounds override those of the individual
  • ·         If an individual has challenged the accuracy of their data and asked organization to rectify it, they also have a right t request to restrict the processing while rectification request is pending
  • ·         an individual exercise their right to object under Article 21(1), they also have a right to request to restrict the processing, while their objection request is under consideration
  • ·         Individual have the right to request the restriction or suppression of their personal data
  • ·         When processing is restricted, organizations are permitted to store the personal data but not use it
  • ·         An individual can make a request for restriction verbally or in writing

Organizations must not process the restricted data in any way except to store it unless:
  • ·         Organizations have the individual’s consent
  • ·         It is for the establishment, exercise or defense of legal claims
  • ·         It is for the protection of the rights of another person
  • ·         It is for reasons of important public interest

Organizations must inform the individual before listing the restriction.

The Right to Data Portability

The right to data portability gives individuals the right to receive personal data they have provided to a controller in a structured, commonly used and machine-readable format. It also gives them the right to request that a controller transmits this data directly to another controller.
  • ·         The right to data portability allows individual to obtain and reuse their personal data for their own purposes across different services
  • ·         It allows individuals to move, copy or transfer personal data easily from one IT environment to another in a safe and secure way, without affecting its usability
  • ·         The right only applies to information an individual has provided to a controller
  • ·         This enables individuals to take advantage of applications and services that can use this data to find them a better deal or help them understand their spending habits

The right to data portability only applied when: organization’s lawful basis for processing this information is consent or the performance of a contract; and organizations are carrying out the processing by automated means.

The Right to Object

Under Article 21 of the GDPR, individuals have the right to object to the processing of their personal data. This effectively allows individuals to ask you to stop processing their personal data. Individuals have the absolute right to object to processing of their personal data if it is for direct marketing purposes. Individuals can also object if the processing is for:
  • ·         A task carried out in the public interest
  • ·         The exercise of official authority vested in organization
  • ·         Organization’s legitimate interests or those of a third party

The right to object only applies in certain circumstances. Whether it applies depends on organization’s purposes for processing and its lawful basis for processing.
If the organizations are processing data for scientific or historical research, or statistical purposes, the right to object is more limited.

Rights in relation to Automated decision-making and Profiling

Organizations obtain personal information about individuals from a variety of different sources. Internet searches, buying habits, lifestyle and behavior data gathering from mobile phones, social networks, video surveillance systems and the Internet of Things are examples of the types of data organizations might collect.
The GDPR has provisions on:
  • ·         Automated individual decision-making (making a decision solely by automated means without any human involvement)
  • ·         Profiling (automated processing of personal data evaluates certain things about an individual). Profiling can be part of an automated decision-making process.

The GDPR applies to all automated individual decision-making and profiling. Article 22 of the GDPR has additional rules to protect individuals if organizations are carrying out solely automated decision-making that has legal or similarly significant effect on them
Organizations can only carry out this types of decision-making where the decision is:
  • ·         Necessary for the entry into or performance of a contract; or
  • ·         Automated by Union or Member state law applicable to the controller: or
  • ·         Based on the individual’s explicit consent

Organizations must identity whether any of their processing falls under Article 22 and, if so, make sure that they:
  • ·         Give individuals information about the processing;
  • ·         Introduce simple ways for them to request human intervention or challenge a decision;
  • ·         Carry out regular checks to make sure that organization’s systems are working as intended.

Automated individual decision-making and profiling can lead to quicker and more consistent decisions. But if they are used irresponsibly there are significant risks for individuals. The GDPR provisions are designed to address these risks.

References:

Privileged Access Management - Compliance Review


Introduction


Privileged Access Management (PAM) has recently emerged as a critical foundation for the realizing the business benefits in terms of cost saving, management control, and operational efficiency. Enterprises need to manage access to information and application scattered across internal and external application systems. PAM comprises of people, processes and product to manage Privileged identities and access to resources of an enterprise. Additionally, enterprise shall have to ensure the correctness of data in-order for the PAM Framework to function properly. 

Attackers, both internal and external, exploit privileged accounts in multiple ways. They use privileged accounts to bypass controls, cover the tracks of an attack, improperly access confidential data, install malware, and make changes that impact system and data security. Proper auditing of privileged accounts access can help uncover inappropriate privileged account use, and can also provide part of the check-and-balance required for compliance with IT Security Standards.

What is a Privileged Account?


Privileged accounts are valid credentials used to gain access to systems. These accounts provide elevated, non-restrictive access to the underlying platform to alter, create, delete, modify and provide ability to access resources across the network. These accounts are designed to be used by System Admins to deploy and manage IT technologies, like Operating Systems, Network Devices, Applications, databases and more.

These accounts are highly critical to infrastructure, therefore, attractive to attackers, hackers, and malicious insiders seek to steal them. It is important to manage, monitor, review and audit the activities associated with privileged accounts and comply with Identity management life cycle.

Privileged Access Management


Most breaches involve gaining access to privileged credentials because they provide unlimited access to systems and data – creating a major security and compliance concern. The principles of Privileged Access management are generally as follows

  • Ensure that only those users who absolutely need access to a given set of privileges on desktop and servers have those privileges, and only those systems for which they have a need
  • Ensure that least-privileged policy is enforced
  • Ensure that privileged access is only used when it is needed and ideally, is only granted when it is needed and un-granted when it is no longer required
  • Centrally manage privileged access such that access can be granted and revoke quickly
  • Ensure that there is an audit logs for any privileged activity
  • Ensure that privileged accounts are monitored correlatively
     

Privileged Access Life Cycle – Strategy and Governance


The IAM life cycle illustrate the steps below that privileged users process through when joining a business workforce and obtaining privileged access to tools, systems and application to do their job. This also include the step to ensure that employee maintain appropriate access as they move within the organization with access being revoked or changed when they separate or change roles.

  1. Privileged access request and approve

    • Gaining access to the applications, systems and data required to be productive
    • Process that is based on ‘request and approval’ must be in place

  1. Provisioning and De-provisioning

    • Granting users appropriate privileged access in a timely manner
    • Revoking privileged access in a timely manner when no longer required due to termination or transfer

  1. Enforce the authentication method

    • Enforcing privileged access to applications and system using authentication and authorization
    • Enforcing compliance with privileged access management policies and standards

  1. Report and Audit

    • Audit privileged user access and activities
    • Report on business-relevant KPIs and metrics

  1. Review and certify

    • Review privileged access periodically to realign it with job function and role
    • Document the process for audit purpose

  1. Reconcile

    • Enforcing that access within the system is matching with approved access levels
    • Remediate and document the changes

Compliance Objectives


The objectives of the compliance is to assess the controls implementation and effectiveness of the governance, risk management, and control over the Privileged accounts and their access to ensure that:

  • Review the Privileged Access Life-Cycle processes, and procedures followed by the organization for granting and revoking the Privileged Access
  • Review the Privileged accounts’ roles and responsibilities, policies, and standards are defined and implemented to enforce role base access controls (RBAC)
  • Systems, applications, databases, network devices are securely provided privileged access based on least-privileged access control
  • Review and documents the use of shared accounts, default accounts come with application or appliances
  • Third party service provider(s) supporting the Privileged Accesses are effectively managed to provide consistency and quality of service delivered
  • Identify and management of common types of privileged accounts: systems, application, databases, network devices
  • Identify and mitigate the risks associated with privileged access accounts and documents
  • Controls for monitoring, audit trails and security of the Privileged Access Accounts are designed and implemented effectively

Privileged Access Management - Best Practices


  • Identify and Inventory all the Privileged Accounts and Assign Ownership and purpose
  • Implement complex password policies for privileged accounts
  • Minimize service accounts with ‘non-expiry’ password
  • Implement least-privileged, role-based access control policy
  • Use Shared Accounts for sporadic and Contingent Use
  • Minimize the Number of Personal and Shared Privileged Accounts
  • Limit Scope for Each Privileged Account
  • Implement “Separation of Duties” Model to manage Administrative Privileges
  • Establish Processes and Controls for Managing the Use of Shared Accounts
  • Use Default Administrator, Root or similar accounts only in Extreme Circumstances
  • Monitor and Reconcile all the Privileged Access Activities
  • Establish a Privileged Access Governance Model by Extending Identity Governance Controls to Privileged Accounts
  • Train employees in the proper use of elevated access privileges including logging out after doing required tasks
  • Use of industry-recognized Privileged Access Management (PAM) tools

Active Directory Security - 10 most common issues


For last 15 years, I have been working on Active Directory Security and Operation. I have done Active Directory Security and operation assessment for many organizations. In the beginning, I figured out many security issues but not all. That was the good initiative though. Later through my experience and sharing knowledge with like-minded security and system admins professional, I realized that there so many most common issues related to Active Directory Security. I have tried to compile them as 10 most common Active Directory Security issues. I totally agree there are more issues to talk about but let us focus on top 10 according to me.



1. Too many Domain Admins

By default, Domain Admins group members have full administrative rights on all workstations, servers, Domain Controllers, Active Directory, Group Policy etc. This is too much power for anyone account in an organization. Only Active Directory Administrators require Domain Admins privileges. Whoever is not actively managing Active Directory, should not be in Domain Admins group. Delegations must be used if in case someone need to work on specific part of the Active Directory. Also service accounts should not be in this group.




2. Delegated Access are not tracked

Default groups in Active Directory provide too much privileges. For example, help desk people in Account Operators group will have more rights then they actually need. It is better to use delegation instead and monitor it. Delegation can be leveraged to insure that appropriate rights for each admin group.




3. Service Accounts with short password and over-permissioned

I have seen many times when vendor simply ask for Domain Admins rights for its service account which is actually may not be needed at all. Hackers are fond of privileged accounts and specially loves service accounts because it is less attentive. Additional privileges to service accounts can be used maliciously to escalate privilege on network.

it is to insure that service accounts get the rights they actually need to do their job. Service accounts credentials are in protected memory of LSASS process, an attacker can easily extract that password which may lead to compromise the network.

Another mitigation against Kerberos brute force attack (offline) is to use the password longer than 15 characters. This can be achieved by configuring the fine grained password policy for service accounts.



4. Using credential in GPP

Windows 2008 came out with Group Policy Preferences which provide additional functionality to system administrators. They can manage local accounts and credential, local groups and schedule task etc. This has created a big issue because encrypted credentials are stored in XML file which are located in SYSVOL share. This share can be access from any domain joined systems. If the credential is already configured in GPP, remove it immediately. Delete the XML files from the SYSVOL. Microsoft also release the patch MS14-068 to address this vulnerability which remove the functionality to manage credentials.

5. Unpatched Servers and workstations

Regular patching of servers have been an issue in many organization. According to Verizon Data Breach report published in 2015, 99% of the vulnerabilities exploited in breaches had a patch for more than a year. Patching is the most critical for maintaining the security of the systems. Its is actually not realistic having a system not patched for months when a vendor released a patch. Unpatched systems provide the ability to attackers to gain privileged access to the systems.



6. Unmanaged Admin group membership

When a snowball start rolling on snow, its size getting bigger and bigger. Same thing happen with group in Active Directory. Most of the time group membership keep increasing slowly but hardly go down. Admin groups specially in Active Directory need to be monitor and scrutinized. Group automation will be the best choice just to make sure that appropriate users are in their appropriate groups all the time. These admins groups are need to be reviewed on regular basis, some of them, Domain Admins, Administrators group, Account Operators, and any other user-created group which provide privileged access to systems.



7. Local administrator account password is same across the network

Local account is used to logon to the system when Active Directory is not available. Most of the time, system administrators build servers with the same password for local administrator account. it may end that all systems will have the same password for local administrator account. if the account is hacked, this will provide the access to all the system, make the life easy for hackers. Therefore, each system must have unique password for its local administrator password. There are many software available that will not only manage the unique password but also rotate them on regular basis.



8. Unmanaged inactive user and computer accounts

Enabled stale accounts in Active Directory always attract the attackers because it can be leveraged to get access to resources without being noticed. There are few different ways to take control of the account, since it is inactive, most probably the usage will not be noticed.

We should have a plan to deal with inactive users accounts.



9. No isolation for highly privileged accounts and systems

Pass-the-Hash attack is the perfect example for such type of environment where same privilege account is being used to logon to servers, domain controllers and workstations. We have been talking about this attack for so many years but still organizations are lacking behind. Imagine if the malware get onto computers inside the network. Attackers using this malware will search for the credentials to steal and re-use it. if the privileged accounts logon to various computers, those credential on the system can be stolen. It is important that all highly privileged accounts must be isolated. Domain Admins account must not be used to logon to workstation and member servers. Regular accounts must not be given administrative level of privileges on any system, rather separate accounts must be created for admin level of work.



10. Using legacy authentication on network

When we talk about legacy authentication, we simply talk about LM/NTLMv1 authentication. These legacy authentication protocols are insecure, therefore it is very important to completely remove these legacy protocols. Windows Server 2008 R2 include the feature to help identify the NTLM authentication use on the network. The minimum protocols for authentication should be NTLMv2 and Kerberos

Cybersecurity: Create culture of security and trust among people


Watch out for cyber threats in 2015-2016. Many research companies have posted lot of information on cyber threats, cyber attacks, and cybercrimes. Top cyber threats that have been dominating the news for past couple of years are identity theft, retail data hacks, healthcare data hacks, phishing and social engineering attacks, mobile and smartphone security threats, and financial institution attacks.

The US and UK research shows that the behavior of employees present one of the biggest risks to the organizations. BYOD solution, growth of social media, remote working and mind-set of younger generation employees that don’t value traditional control, all together create new threats in an organization’s cyber defense.

Recently US House identified that inside is the number one threats. Insider means, all employees, short-term, long term contractor, vendors who have access to some of the resources. Number of government and private case studies have shown that insider who knowingly participate in cyberattacks have a motivations: revenge, desire for power and recognition, financial gain, loyalty to others on organization, and political beliefs. Organized crime and activist groups’ collaboration with insider has become common.

Attack on South Carolina Department of Revenue, where almost 4 million unencrypted bank accounts and tax returns were stolen by Russian gang. Forensics established link with an employee who facilitated the attack by opening a link in an email, enabling the hackers to steal the employee’s credential and access the state’s data.

We understand that technical defenses are very important to protect organization’s perimeter. But these defenses will limited effect if they are undermined by employees who do not follows the security policies just because these are inconvenient or they don’t understand why these policies are necessary.

“People”, hence become the essential component of strong and effective cyber defense. Cyber security strategies must focus on human aspects, developing a positive security culture based on trust and not surveillance.

  • Cyber security is a shared responsibility of each and every employee of the organization. Organization should stress the responsibility of individual as well as whole team for protecting the critical data and make no exception for leader. Employee must act as a role model by adopting the positive way of working, such that, in response to a security breach, acknowledge what had happened openly and treat it as an opportunity to learn rather than firing or imposing the fear on employee’s mind set.
  • Encourage employees to view security as something that enables the organization to deliver its promise to customers and achieve its vision
  • Social media and home based work are normal behavior. Make it easy for employee to do the right thing. Investing resources and effort in employees and culture, can significantly improve the security and reduce the potential of successful cyberattack.

Organizations can reduce their exposure to employee risk by adopting the ‘human aspects of organization’, building a security culture that focus on building and maintaining trust. There are ways to build the trust within the organization

  • Create an open, ethical and proportionate approach to cyber security
    Employees first must accept that there is a credible threat and have clear understanding of why these measures are essential. It also mean that enabling proportionate checks and balances in place, focus where it focus most and prepare to challenge controls that are unnecessary and/or redundant.
  • Tag the culture with shared values and beliefs
    The culture, build on values, focused around the integrity, security and trust develops commitment ad challenges a ‘culture of blame’. People need social reinforcement from the norms of behaviors around them rather than just putting a poster in hallway or lobby.
  • Power of the majority
    People look to follow the social norms, they want to like and trust each other. These traits can be used as strong key to help reinforce the right behavior. Organization to achieve the deeper understanding of failures, how they were detected and implications, acts as a strong deterrent. It may not be necessary that increasing the controls is the right thing to do but getting behaviors right is also effective.

Top data security breaches in 2015-2016


 

  • Anthem: In February 2015, health care provider, Anthem acknowledged that it was hacked by then unknown attackers, who accessed 80 million records from the people
  • Ashley Madison: A group called Impact Team stole the site’s user database in July, hackers released everything which included the personal information such as email and physical addresses for 37 million users
  • An unknown group infiltrated hundreds of banks in multiple countries, stolen somewhere in $1 billion
  • Nearly 15 million T-Mobile customers had their information stolen after credit-checking company Experian was hacked
  • US government agency Office of Personal Management, was breached and exposing information of about 22 million records
  • There are many more to be noted like Target (70 million), Home Depot (56 million), MySpace (16 million), LinedIn (117 million)