Follow Your Passions to a Meaningful Career

Throughout the pandemic, there has been a great deal of upheaval in the job market. With millions of people rethinking how they work and live—and how to better balance the two—we’ve seen hordes of workers changing careers or jobs. From income stagnation and precarious job security to burnout and dissatisfaction with their role, there are a number of factors that have contributed to the “Great Resignation”.

However, there are some sectors that have only been growing with more job openings than qualified job seekers—and technology is one of them.

According to research, the cybersecurity industry has a critical need for talented workers and is in fact short 2.7 million people worldwide

Growing up, I never imagined that I would pursue a career in technology. My parents worked in computer programming and although I had access to computers from a young age, I didn’t intend to follow their example. However, a winding journey led me into a meaningful career as a full-stack software developer working in cybersecurity. It’s something I am proud of and genuinely enjoy.

My path certainly wasn’t direct. At college, I met people pursuing computer science and they all seemed to be whiz-kids who were programming before middle school. Since that didn’t correspond with my experience, I opted for a business program as it seemed much less technical and I thought it would hold opportunities more suited to my skill set.

While attending college, I worked in a variety of industries, trying as many roles as possible to get a sense of what I liked and wanted to do long-term. I held jobs in construction, customer service, and even payroll administration but nothing really felt right. I was almost through my business diploma when I decided to take an elective in computer programming and it changed everything.

Where my other courses didn’t always motivate me, this programming class was extremely engaging and more importantly, I enjoyed it. This translated to spending extra time on all my assignments simply because it was fun. As a result, I came in at the top of my class and discovered I had more in common with my classmates than I thought.

That was a wake-up call for me. Even as I finished my business diploma, I knew that my next step would be to pursue computer science. I enrolled at the British Columbia Institute of Technology (BCIT) for Computer Systems Technology (CST). This two-year, accelerated and intensive program was perfectly suited to my learning style with more opportunities for problem-solving and hands-on application and little memorization and testing.

The program was hard work, but it felt more manageable than the business program because I loved what I was doing and when I completed it, I was ready for the workforce.

Finding that right career fit by uncovering what you’re passionate about can take time and it did with me. In fact, you could say I spent my time discovering what I wasn’t passionate about. But when I found computer programming, everything clicked into place. I found a great job working with Fortinet. Now, I am in the process of finishing a CST Bachelor of Technology with a double specialization in Network Security Applications Development and Network Security Administration.

And I still love it. It feels less like work and more like a hobby I enjoy. You really can’t beat that.

If I could offer advice to those looking to pursue a new career path, I would tell them to take the time to try things out. Explore different opportunities and learn as much as possible until you discover what you truly enjoy.

 I would also encourage people to be brave and test their limits. I let misconceptions about the field turn into fears that computer programming would be too technical for me but I was wrong. The combination of natural interest and good training was all I needed to excel.

While I enrolled in formal education to course-correct my career path, there are many other ways to learn—including free online resources such as Fortinet’s NSE Training Institute courses, which are designed to make cyber learning available to everyone. If any of this sounds appealing to you, I’d recommend checking it out. You may be surprised at what you learn about the field of cybersecurity, and about yourself.

Find out more about how Fortinet’s Training Advancement Agenda (TAA) and NSE Training Institute programs, including the Certification Program, Security Academy Program and Veterans Program, are helping to solve the cyber skills gap and prepare the cybersecurity workforce of tomorrow.

Sourced from Fortinet

Closing the Homework Gap Through the Emergency Connectivity Fund

The Federal Communications Commission (FCC) in the United States recently extended the deadline for Emergency Connectivity Fund (ECF) awardees to spend their funding. To the delight and relief of many, the new service delivery deadline has been moved back by 12 months to June 30, 2023. Fortinet applauds the FCC’s action to provide this critical program extension.

What Is the Emergency Connectivity Fund?

Using the resources provided under the FCC-administered Emergency Connectivity Fund program, schools are allowed to purchase and distribute broadband devices such as “hot spots” to enable students to access learning resources from home. Solutions are available on the market to provide the services and security needed by remote-learning students.

As most educators know, there is a “homework gap” as students without the broadband access they need for remote learning or completing homework assignments are struggling to keep up with their peers. The problem became more acute during the pandemic as stay-at-home children without broadband and internet devices—in rural and urban communities—were unable to participate in online education.

Prior to the pandemic, 15% of students were unable to do their homework due to lack of reliable internet services at home.

The ECF was set up to address this problem as part of the American Rescue Plan Act of 2021. FCC Chairwoman Jessica Rosenworcel is a passionate supporter of the program seeing the homework gap as an “especially cruel part of the digital divide.”

Last year when the ECF program kicked off, Rosenworcel promised, “We won’t consider the job done until we have policies in place that can help every student get the connection they now need for class, no matter who they are, where they live, or where they go to school.”

Available Funds and Options Moving Forward

According to the FCC’s ECF website in early February 2022, “The Commission to date has committed nearly $4.5 billion in program funding to support more than 10,800 schools, 875 libraries, and 125 consortia for nearly 9.9 million connected devices and over 4.9 million broadband connections.” This is a considerable feat.

Before the extension, many schools and libraries participating in the ECF program were in danger of not being able to use the funds by the June 2022 deadline due to delays in application processing and other factors. Now, with the extension it appears that funding will not be left on the table and more students and institutions will be able to fully utilize these resources. This also provides certainty to teachers, students, and parents heading into the next school year.

“Extending the ECF deadline will help millions of students and library patrons maintain their internet connections for several more months. We’ve been hearing from applicants that the June 30, 2022 deadline would have imposed a severe hardship on schools and libraries who might have seen their funding go to waste due to supply chain delays and other factors beyond their control,” said John Windhausen Jr., executive director of the Schools, Health & Libraries Broadband Coalition, in a statement following the ECF extension announcement.

There are additional steps the FCC could take to further close the homework gap. One of the most timely options proposed by a coalition of entities representing schools and libraries is the establishment of a new application round for ECF participation. Noting the availability of $800 million of remaining ECF funds, a third funding window could have a broader reach given that “some schools and libraries that were unfamiliar with the ECF program last year.” Other entities including the Information Technology Industry Council and the U.S. Chamber have expressed support for this new funding window as well.

The Challenges Driving the Need for Wireless Services

Even before the pandemic, the homework gap was not being adequately addressed. According to many educators like Crystal Haskins, principal of James Blair Middle School in Williamsburg, VA, the amount of homework being given was not always adding value to learning. Haskins asks, “If students are not gaining mastery of tier one material, why are we giving homework?”

30% of all public K–12 students fall into the homework gap.

When COVID-19 forced an explosion of remote learning for K–12 schools, the issue had to be addressed with more care, speed, and intensity. Inserting parents or caregivers into the teaching ecosystem overnight was a huge challenge as they had to assist their children/students in acclimating to a learning management system without any formal instruction. This resulted in a far-from-ideal classroom learning experience and the 1-to-1 student to teacher relationship also suffered greatly.

The list of challenges schools face with remote learning is long:

1) Figuring out the process. Principal Haskins recalls the difficult challenge of bringing teachers and students together to figure out how to download assignments and course materials and then upload completed assignments.

2) Adequate cellular coverage. Students without internet access at home were being issued wireless hot spots when they were available and affordable. Even then, some of those hot spots were either defective or there was not adequate cellular coverage for the technology to work properly and provide the right data speeds and capacity.

3) Substitute teachers. When the assigned teachers had to be out of the classroom to take care of themselves or family, the substitute teachers may not have had the right internet access or understand the learning management system and how it works for that school or school district.

4) Lack of technology expertise. Principal Haskins says that teachers and administrators have had to become functional experts on the school’s learning systems in a short amount of time, and they need a better understanding of how to maximize the tools. Ongoing professional development is required for teachers and to do it in context with their students’ needs.

5) Burnout. Principal Haskins strongly believes that if the teachers had more hours in a day, they could and would “make it happen.” Add to these issues the fact that teacher burnout is real and it is impacting their ability to jump across the digital divide. She concludes, “Right now, the only impact of the technology is to make the teacher’s day longer.”

Now that students are returning to the brick-and-mortar classrooms, learning needs to catch up with the pandemic from a technology perspective. Better training is one issue. Adapting the tools toward age, ability, and the appropriate pedagogy is another. In both areas, extending the ability of funding the tools and training using the ECF is vital.

What the Future May Hold for Closing the Homework Gap

It might be a small issue to some, but the parents, caregivers, and students need the ability to manage homework to maintain their pace of academic growth. For some, wireless hotspots and related services provided under the ECF may be the only way to get broadband access. Fortinet supports further efforts to close the homework gap, including the FCC taking additional steps to maximize utilization of the ECF program as recommended by the education community.

Find out how Fortinet’s transformative approach to security enables educational institutions to secure their digital learning infrastructure.

Sourced from Fortinet

Be Prepared for Social Engineering Scams This Tax Return Season

As people get ready to file their taxes in many parts of the world, cybercriminals are getting ready too. Tax-return time is open season for cybercrime, and it’s likely to be worse this year because so many people are still working from home on various devices connected to unsecured networks. Although cybercriminals use other sophisticated tactics to steal information, social engineering scams are low-hanging fruit, especially during tax season. Fortunately, everybody can take steps to avoid falling victim to a social engineering scam. 

Watch Out for These Social Engineering Attacks

Cybercriminals are out in force, eager to prey on the stress and uncertainty surrounding tax season. Attacks may take the form of phishing email campaigns or phone calls from people claiming to be from the IRS or a collection agency. To appear legitimate, scammers may use stolen data with personal information, such as Social Security numbers. 

Cybercriminals use a “spray and pray” model for phishing campaigns. They send thousands of emails, hoping that at least one person will fall victim to the attack. Spear-phishing attacks are a targeted form of phishing that can be more difficult to detect because the emails are personalized to appear as if they were sent by someone the recipient knows. In the past, spear phishing was challenging to implement, but now some advanced cybercriminals use machine learning and artificial intelligence to execute these attacks more efficiently.

Who Is the Most Vulnerable to Social Engineering Attacks?

During tax season, the prime targets for tax refund scams are Green Card holders, small business owners, new taxpayers under the age of 25, and older taxpayers over 60. Cybercriminals assume these people may be less informed about tax policies and what to expect, so they may be more vulnerable to emotional manipulation. For example, the scammer may claim that the potential victim has missed an important tax deadline and pressure the victim to act quickly. 

How to Protect Yourself Against Tax Refund Scams

If you know what to look for and how to handle suspect emails or phone calls, you can avoid becoming a victim of tax season social engineering attacks. Here are a few tips for effectively defending against social engineering attacks: 

  • Look for grammatical issues and typos. Often, phishing emails contain errors that are easy to spot. If a message includes several spelling or grammar errors, odds are good that it is not legitimate.
  • Be skeptical. Always consider any unexpected emails or phone calls claiming to be from the IRS or other governmental agencies to be suspect. If you are concerned about the legitimacy of a sender or caller, don’t give the person any information. Instead, contact the IRS or governmental agency directly to verify the caller’s identity. 
  • Don’t share personal information. Don’t give out your Social Security number or credit card information over the phone or via email. Scammers may pressure you to do so and try to convince you that something terrible will happen if you don’t act immediately. Hang up or delete the email. 
  • Warn family and friends who may be vulnerable to attacks. Share cybersecurity information with others and encourage them to get educated. The Fortinet NSE Training Institute offers cybersecurity awareness training that covers key cybersecurity terms, the motivations behind cybercrime, attack methods, and protection tactics.
  • Use technology to help prevent attacks. Secure email gateway (SEG) solutions such as FortiMail can protect all inbound and outbound email traffic. Like other Fortinet products, FortiMail integrates seamlessly with the Fortinet Security Fabric and is backed by FortiGuard Labs. FortiClient is an advanced endpoint protection solution with a built-in VPN client and zero-trust network access. It connects an endpoint such as a laptop with the Security Fabric and delivers integrated endpoint and network security.  

Knowing what is and isn’t normal communication from the IRS or equivalent is critical, particularly during tax season. If you do encounter an IRS-related phone or email scam, you can report it to the Treasury Inspector General for Tax Administration using the form on the IRS Impersonation Scam Reporting website or by sending an email to phishing@irs.gov with the subject line “IRS Impersonation Scam.”

Educate Yourself and Stay Safe During Tax Season 

Although tax-return season can be stressful, knowing the signs of a social engineering attack can keep you from becoming a victim. By learning how the IRS contacts individuals, what constitutes a legitimate message, and what information should be provided, you can stay ahead of cybercriminals and keep your data out of their hands.

Fortinet made all of its self-paced online courses from the Fortinet Training Institute available for free to all, starting at the beginning of 2020. Whether you know very little about cybersecurity, you’re a student, or already have a career in computer science, these courses are designed to give participants a foundational and advanced understanding of cybersecurity tools and principles as well as the threat landscape. Learn about how you can become cyber aware and educated.

Learn more about the Fortinet free cybersecurity training initiative, the Fortinet NSE Training programSecurity Academy program, and Veterans program.

Sourced from Fortinet

Break the Bias and Create a More Diverse and Inclusive Cybersecurity Workforce

This year, on International Women’s Day, governments, organizations, and individuals worldwide are being asked to help envision and create a gender-equal world. A world free of bias, stereotypes, and discrimination. A world that is diverse, equitable, and inclusive. A world where difference is valued and celebrated. That is this year’s theme: #BreakTheBias.

One of the industries struggling with significant bias and gender stereotypes is cybersecurity. This field plays an increasingly crucial role in our digital world and, as a result, offers many fulfilling career paths and opportunities. However, there are still significant barriers and misperceptions driving the belief that a career in cybersecurity is not for women.

Women are underrepresented in cybersecurity

While women have been disproportionately impacted by pandemic-driven unemployment (for example, one in four women reported job loss due to a lack of childcare—twice the rate of men), the technology sector was less affected. This was mainly due to their being better prepared to pivot to remote work and flexible work models. As a result, according to a report by Deloitte Global, large global technology firms still managed to achieve “nearly 33% overall female representation in their workforces in 2022, up slightly more than two percentage points from 2019.” 

While such progress is good, the technology sector still has a long way to go compared to other industries. Outside of the high-tech sector, women account for 47.7% of the global workforce. And they also make up 50.2% of the college-educated workforce.

And the gender gap is even wider within the cybersecurity industry where, according to the (ISC)² Cybersecurity Workforce Study, women only make up 25% of the global cybersecurity workforce. This gap is certainly not because there aren’t any jobs. According to that same study, the cybersecurity industry urgently needs 2.72 million more professionals. And while 700,000 cybersecurity professionals entered the workforce in the past year, the global workforce gap was only reduced by 400,000, indicating that global demand continues to outpace supply. Women are just generally not applying for or being recruited to fill these positions.

This lack of gender equity has also directly contributed to the low percentage of women who hold cybersecurity leadership roles. In 2021, for example, only 17% of Fortune 500 CISO positions were held by women, with only one female CISO in the top ten US companies.

Stereotypes and misconceptions persist

There are three main reasons why women continue to be underrepresented in the cybersecurity industry:

Problem #1: Cybersecurity is seen as a man’s career

Many women don’t consider cybersecurity a career path because it’s primarily seen as a male profession. This image is reinforced by popular media, such as Eliot Alderson in the Mr. Robot TV series, where cyber activities are performed by young geeks in hoodies working late at night in a dark room lit only by their computer screen. While it may make for compelling TV, this stereotype is inaccurate and off-putting for many women, inadvertently contributing to gender disparity in the workforce.

While cybersecurity certainly has its technical aspects, it is not just a technical industry. Like any growing industry, there are a wide variety of job opportunities that require human skills.  These include analytical, communication, management, and interpersonal skills that are equally important to the organization’s success and positively impact the industry.

Problem #2: Young women are underrepresented in STEM programs

One reason why so few women apply for cybersecurity positions is they are less represented in STEM-based programs. But there is no reason why the technical aspects of a career in cybersecurity should be off-putting for women. The fact is, standardized math tests for fourth, eighth, and 12th graders show little gap in the scores between female and male students. But according to MIT WIM (Women in Mathematics), one of the drivers of the gender gap in technology fields is not ability but “stereotype threat.” This happens when an individual worries about confirming negative stereotypes, leading women to conform to gender expectations by performing worse on assessments and decreasing their interest and persistence in STEM fields.

Pervasive gender biases, few female role models, mistaken beliefs about technology being a male-oriented industry, and, sadly, teachers and parents who steer girls away from technology studies have combined to break the confidence of many young women otherwise suited to pursue a STEM-related degree. This is a global issue, with women generally earning less than 20% of all STEM degrees. According to Yale University, US women only earned 18.7% of computer science degrees. In the UK and across 35 European countries, fewer than 1 in 5 computer science graduates are women. And women hold only 18.5 percent of STEM positions in South and West Asia and 23.4 percent in East Asia and the Pacific. This bias starts early in their college careers. 49.2% of women intending to major in science and engineering switch to a non-STEM major during their first year.

Problem #3: Bias in cybersecurity hiring

We cannot cure the lack of women in STEM overnight. So, organizations need to think differently about the composition of their cybersecurity staff. Many hiring managers—and HR—view individuals with backgrounds in computer science, engineering, and other STEM fields as the most qualified cybersecurity candidates, often ignoring those with degrees in other areas. But if they want to build successful cybersecurity teams, they need to broaden the scope of backgrounds they consider when looking for new employees.

But the challenge goes beyond hiring. The reality is that women in cybersecurity roles also tend to be promoted more slowly than men—something known as the “first rung” problem. According to Fortinet CISO Renee Tarun, “Men are four times more likely to hold executive roles than their female counterparts, they’re nine times more likely to have managerial roles than women, and [on average] they’re paid 6% more than women.” In addition, women tend to leave the field at twice the rate of men, citing gender bias, discrimination, and harassment as their reasons for leaving.

Five steps for creating a more diverse and inclusive cybersecurity workforce 

In addition to the primary objectives of the UN’s Sustainable Development Goals that call for equality and equity for women (goals four and five), organizations need to seriously consider how to merge their DEI (Diversity, Equity, and Inclusion) objectives into their equally important digital innovation strategies. Because the evidence is clear: businesses that employ gender equality practices across their organization report increased profitability and productivity.

Given the rate at which digital innovation is transforming organizations (and the efforts of cybercriminals to exploit those digital acceleration efforts), now is the time to break our cybersecurity stereotypes. We must work together to remove the bias that cybersecurity is a gender-specific field and change the perception that it is purely a computer science discipline. In cybersecurity, technology is only one of the silver bullets required to eliminate cyberattacks. The three critical elements of an effective cybersecurity strategy are People, Products, and Processes. But when we continue to recruit the same people—same gender, same educational background, same perspective—we are unlikely to develop strategies that allow us to get out ahead of our cyber adversaries. For example, it is not a stretch to say that the failure to rethink security strategies—starting with who makes up cybersecurity teams—played a part in the nearly 1100% increase in ransomware attacks organizations worldwide experienced last year.

To change this perception and get out ahead of the cybercrime crisis we all face, we must bring more voices, perspectives, and diversity to our cybersecurity teams. Here are five basic principles we need to adopt as we work to refine our cybersecurity teams and strategies:

  1. Highlight the contributions of women in cybersecurity in our classrooms and businesses, identify and promote positive role models and examples, and actively encourage diverse career paths, experiences, and job functions to our young women.
  2. Encourage young women to pursue STEM-based degrees and careers at a young age.
  3. Create and/or be part of mentorship programs at all levels, beginning with basic technology classes in elementary schools that model success in technology for girls that continues throughout their higher education and professional careers.
  4. Implement more inclusive work environments by identifying and breaking bias in hiring practices, training all employees (not just executives) about true inclusiveness, and actively making every employee feel involved, valued, and respected. And we need to ensure that women, especially women of color, are treated fairly and are fully embedded in the workplace.
  5. Eliminate “first rung” barriers by actively promoting more women to leadership at every level of the organization, beginning with roles as project and team leads and first-tier managers.
This must be a commitment we are all willing to make. On this day, we reaffirm our commitment to promoting gender diversity, equity, and inclusion inside Fortinet by helping engage more women in the cybersecurity sector through concrete action across the above strategies.  

Final Thoughts

Cybersecurity plays an essential role in our modern society. However, a variety of skills and experiences must come together to guarantee the cyber industry’s success. And as with any other industry, diversity is crucial. By bringing greater awareness to the diverse skills and backgrounds cybersecurity requires, we can help shrink both the gender and skills gaps while making strides in our battle with our cyber adversaries.

Cybersecurity offers many fulfilling career paths and opportunities for women. Because technology—and cyberthreats—continue to accelerate, it is an industry in constant evolution, making the field of cybersecurity very stimulating intellectually. And because there are so many open jobs to fill, this sector is also attractive financially. But joining the cybersecurity industry also means having a significant impact on society. We live in a digital world where protecting data and individual privacy has become a critical sustainability issue. And as always, women play a vital role in making this possible.

Find out more about how Fortinet’s Training Advancement Agenda (TAA) and NSE Training Institute programs, including the Certification ProgramSecurity Academy Program and Veterans Program, are helping to solve the cyber skills gap and prepare the cybersecurity workforce of tomorrow.

Sourced from Fortinet

Department of Justice Collaboration Works to Disrupt Ransomware Ecosystems

In discussions of ransomware, there’s not always lots of good news. However, recently the Department of Justice (DOJ) has had a few victories against ransomware operators. What’s important to note is that these successes are collaborative efforts and pushing back against the ransomware ecosystem, not just individual operators.

It’s important to remember that cybercrime is big business with a vast network of players. The ransom-as-a-service (RaaS) model is part of it. This model features “developers,” “operators,” and “affiliates.” Developers are responsible for creating and updating the ransomware. Operators are responsible for running the business, including creating the affiliate program, making the ransomware available to affiliates, and managing rates and settlement payouts. Affiliates identify and attack high-value victims with ransomware, and after a victim pays, the operator pays the ransom money out to affiliates. In some cases, this process is automated with control panels to make payouts.

Although ransomware and RaaS are certainly not on the decline according to FortiGuard Labs threat research, collaboration and attribution are helping. When it comes to threat intelligence and research, finding people is the ultimate goal. Even getting other data, such as discovering why a group is attacking or the vertical markets or infrastructure they’re targeting can help disrupt campaigns and activity and reduce the number of ransomware settlements paid out.

Partnerships that span across countries and vendors are helping to identify cybercrime syndicates. For example, the World Economic Forum’s Partnership Against Cybercrime is working to serve as a bridge between the digital expertise of the private sector and the global public sector organizations. Tracking down attackers and tactics makes it easier to know what to do about an attack. Attributing where funds are moving also helps, including crypto wallets and currency flows. And instead of focusing solely on operators, more investigations are going after affiliates, which sends the message that they are not immune from prosecution.

Examples of DOJ Success Fighting Cybercrime

Here are a few successful examples where working together has led to DOJ successes.

DOJ Action Against NetWalker Affiliates Leads to Jail Time

On January 27, the DOJ announced a coordinated international law enforcement action to disrupt a sophisticated form of ransomware known as NetWalker, which affected companies, municipalities, hospitals, law enforcement, emergency services, school districts, colleges, and universities. The NetWalker attacks specifically targeted the healthcare sector during the COVID-19 pandemic, taking advantage of the global crisis to extort victims.

A NetWalker affiliate Sebastien Vachon-Desjardins was arrested and, on January 31, subsequently was sentenced to seven years in jail and ordered to pay restitution to a number of organizations. Authorities in Bulgaria also seized a dark web hidden resource used by NetWalker ransomware affiliates to provide payment instructions and communicate with victims.  This success is notable because it required cross-border coordination and focused on the affiliate.

DOJ Arrests Criminals Who Stole Cryptocurrency

On February 8, two individuals were arrested in New York City for conspiring to launder the proceeds of 119,754 bitcoin that were stolen from a virtual currency exchange and initiated more than 2,000 unauthorized transactions. Law enforcement has seized over $3.6 billion in cryptocurrency linked to that hack so far. As this arrest shows, with due diligence and proper resources, even crypto blockchain can be traced. Although the criminals tried to obfuscate funds through multiple transactions and addresses, effectively “laundering” the money, they still were caught.

DOJ Charges in 2018 Leads to More Arrests in 2022

Back in 2018, the DOJ announced that it had unsealed a federal indictment charging 36 individuals for their alleged roles in the Infraud Organization, an Internet-based cybercriminal enterprise engaged in the large-scale acquisition, sale, and dissemination of stolen identities, compromised debit, and credit cards, personally identifiable information, financial and banking information, computer malware, and other contraband. At the time, federal, state, local, and international law enforcement authorities arrested 13 defendants from the United States and six countries. And on January 24, the Russian news agency TASS announced that four members of the Infraud Organization were arrested in Russia.

REvil Ransomware Gang Members Arrested

In January, 14 members of the notorious REvil cybersecurity gang were arrested in Russia at the request of US authorities. REvil was responsible for the Kaseya attack, and one of the hackers was also involved in the Colonial Pipeline incident.

Every Little Bit Helps in Fighting Cybercrime

These DOJ successes don’t mean ransomware is going away any time soon. Because cybercriminals are paying affiliates commissions to wage attacks, there’s likely to be more diversification in cybercrime operations. When you think about all the elements that fall under cybercrime like money laundering, all of those networks will expand and add to advanced persistent threats and threats from nation-state threat actors.

But here’s some good news. The coordinated effort by global law enforcement agencies to dismantle the Emotet botnet led to a decline in activity. Emotet isn’t completely dead, but the activity is well below what it once was and not nearly as rampant globally.

There are multiple ways to disrupt the cybercriminal ecosystem, and all of them can make a difference, in small amounts or collectively. Lowering ransomware activity means a reduced number of attacks, less lost data, and fewer ransomware settlements. Although it may be a long, slow, and frustrating process, detection, enforcement, and prosecution do have an impact. 

Learn more about FortiGuard Labs threat research and the FortiGuard Security Subscriptions and Services portfolio.  

Sourced from Fortinet

Why Upgraded Infrastructure Needs Interoperability and Security

In the United States, the $1.2 trillion Infrastructure Investment and Jobs Act is being called a “once-in-a-generation investment” in infrastructure. A lot of that money will flow to state and local governments throughout the nation. Virtually all of the infrastructure that is being repaired, replaced, or initiated has a digital element. Whether you’re talking about bridges, dams, roads, or wastewater conduits, they all have some type of network component, ranging from passive sensors that report on environmental conditions to operational technology (OT) devices that control core functions.

Considerations for Government Leaders on Infrastructure Concerns

Much of the new infrastructure money will go to states to disperse; other funds will flow directly to local government. But in any jurisdiction, here are some topics government officials should consider as they plan or execute infrastructure upgrades.

1. Focus on Interoperability

It is too easy to focus on addressing each of these digital infrastructures in isolation—especially since the money often comes from a funding source that is focused on a particular mission (in the case of a federal agency that may be dispersing funds under the Infrastructure Investment and Jobs Act). Funds are likely to be spent by state and local government officials or their private sector partners on discrete projects in specific infrastructures. Yet, as understandable as this outcome may be, taking such a stove-piped view breeds a form of institutional myopia that limits the potential benefit that can accrue from investing in and upgrading multiple infrastructures simultaneously. I consider this an updated version of the line in the 1980’s movie Field of Dreams: If you connect them, we will benefit. Can anyone readily forecast how enabling, for example, railway switches and wastewater pipes to communicate with each other will be useful? Perhaps not—but neither when the bill creating the interstate highway system was signed in 1956 could anyone have predicted how upgrading road infrastructure would transform American life and even our landscape.

For those who worry that connecting these disparate infrastructures will give malicious actors greater ability to attack multiple sectors and create broader impact, the reality is that we already see malicious cyberactivity that targets multiple sectors or demonstrates the ability to move from one critical infrastructure to another. Failing to ensure that the security component of our upgraded infrastructure can, at a minimum, share threat data, will leave us unprepared to face threats that are already present and that are only likely to become more severe.

2. Plan for the Long-Term

Digital technology evolves and improves rapidly, but physical infrastructure typically doesn’t. At least one major U.S. city still uses water pipelines that were installed before the Civil War. Unlike our personal electronics, where we routinely swap out older products for new and improved ones, with infrastructure, you typically can’t “rip and replace,” so it’s essential to consider the long-term implications of your purchases. If there’s a choice, instead of adding hardware that is difficult to update later, opt for software-based solutions, such as software-defined networking (e.g., software-defined wide-area network or SD-WAN) and cloud solutions. To the extent that capabilities can be achieved through either software- or hardware-based solutions, software-based approaches typically are more readily and affordably updated and upgraded. 

Set broad functional requirements instead of identifying specific levels of performance. Using cybersecurity as an example, consider requiring that infrastructure devices employ endpoint protection/endpoint detection and response (EDR) capabilities, rather than specifying how fast or comprehensive these capabilities should be. Choose standards that can evolve, such as relevant National Institute of Standards and Technology (NIST) or International Standards Organization (ISO) standards that will be updated. Defining specific performance levels (such as “use 512 bit encryption”) may be attractive in the short term but risks locking important aspects of performance into premature obsolescence as technology and threats evolve. Choosing software-defined functions and externally derived standards can provide a degree of future-proofing for infrastructure.

3. Security Needs to Be an Essential Element

The top priorities for operational technologies in infrastructure are usually safety and reliable performance. Security comes third. But cybersecurity needs to be included in every infrastructure project. Failing to do so not only leaves that infrastructure and its users vulnerable, because of the interconnected nature of infrastructure, but it also leaves us collectively more vulnerable to cascading failures and consequences that can spread across sectors and regions.

CISA’s new Common Baseline Cybersecurity Performance Goals are reasonably comprehensive and give exemplars that can help non-experts plan implementation. These goals are both user-friendly and can accommodate both use by organizations such as small, local infrastructure providers and large organizations that have a bench of cyber experts and tools. Following common goals should facilitate interoperability across the spectrum of size and complexity of connected organizations within and across infrastructures.

Start with the basics. Recent analysis by the Center for Internet Security reiterates that implementing a modest set of basic/essential cyber hygiene measures can reduce vulnerability to attack by 75%. These are measures that can be implemented even by personnel and resource-constrained small infrastructure providers.

For small infrastructure organizations such as public utilities that may require additional protection, externally provided Security-as-a-Service may be more feasible than trying to generate it from scarce in-house security talent. Security-as-a-Service solutions range from simple offerings such as externally managed niche products through more complex offerings such as SOC-as-a-Service or full portfolios of externally managed capabilities. These products are available at a range of levels of performance and price. In some cases, potential users might band together in state or regional markets with economy of scale and greater security efficiency.  

Next Steps to Secure Infrastructure

Our refreshed infrastructure needs to be “smart.” Disparate infrastructures should be able to talk to one another, and funding agencies and infrastructure providers need to plan ahead to avoid siloed solutions to achieve interoperability. Because threats can move across networks and even to other networks, no infrastructure can afford to operate in an information vacuum, and cybersecurity plans need to include sharing of threat information. You can’t protect yourself against a threat that you don’t understand and that you can’t see. Cyberattacks are inevitable, so infrastructure providers should be able to coordinate their responses to improve their ability to recover from them. Much like first responders in neighboring jurisdictions need to be able to use common communications in the event of an emergency that requires a multi-jurisdiction response, it’s easier to plan for interoperability at the front end rather than to improvise it during a crisis.

Before agencies start putting potentially incompatible systems into place, now is the time for government to consider the role of interoperability, standards, and to look for creative ways of facilitating upgrades as systems age. And all of this digitally enabled and connected infrastructure needs to be secured. Obviously, no one sets out to buy solutions that aren’t secure, but not everyone in local government or an infrastructure’s procurement office is likely to be aware of all the options that exist across the cybersecurity industry or to be cognizant of the latest threats. Executives and legislators need to be smart in thinking about the money they are about to receive. This once-in-a-generation opportunity is our best chance to reshape infrastructure in a way that can be transformational. It’s worth taking the time to make smart choices as we prepare to build this smart infrastructure.

Learn more about how Fortinet can help State and Local governments protect digital assets and critical infrastructure against evolving advanced cyber threats. 

Sourced from Fortinet

FortiGuard Labs Reports Ransomware Relentless and More Destructive

If you were to pick a single word to describe cybersecurity events in recent months, it would be “fast.” FortiGuard Labs has just released the latest semiannual FortiGuard Labs Global Threat Landscape Report, and it indicates that cybercriminals are developing attacks faster than ever. They continue to exploit the expanding attack surface of hybrid workers and IT and are using advanced persistent cybercrime strategies that are more destructive and less predictable than those in the past.

A quick review of four significant takeaways from the threat report

1. Log4j Demonstrates the Speed of Exploits

In December, a critical vulnerability disclosed in the Apache Log4j Java-based logging framework impacted nearly every environment with a Java application. The vulnerability was trivially easy to exploit and gave attackers a way to gain complete control of vulnerable systems. Within days, Log4j became the most prevalent IPS detection in the second half of the year. Shortly after the original disclosure, two other vulnerabilities were discovered that forced organizations to update their Log4j deployments three times in a single week. Despite emerging in the second week of December, exploitation activity escalated quickly enough, in less than a month, to make it the most prevalent IPS detection of the entire second half of 2021. In addition, Log4j had nearly 50x the activity volume in comparison to the well-known outbreak, ProxyLogon, that happened earlier in 2021. Although there were no reports of significant compromises involving the Log4j flaw in the month after it was discovered, it’s possible that attackers exploited the bug to breach networks and are now just waiting for the right time to strike.

2. Adversaries Rapidly Targeting New Vectors – Linux

Not long ago, Linux was one of the least attacked platforms in IT, even though it runs the back-end systems of many networks and container-based solutions for IoT devices and mission-critical applications. However, threat actors are expanding their toolsets and rapidly increasing their use of Linux-based malware. During 2021, malware detections of Executable and Linkable Format (ELF) files, the binary format for Linux, doubled. Additionally, the number of new antivirus (AV) detections Fortinet needed to create quadrupled. The growth in variants and spread suggests that Linux malware is increasing. And with Microsoft actively integrating Windows Subsystem for Linux (WSL) into Windows 11, it’s inevitable that malware will follow. We had ample evidence and reasons to include the continued increase in Linux attacks on our list of 2022 cyber threat predictions.

3. Ransomware Attacks Remain Relentless

The sophistication, aggressiveness, and impact of ransomware continued relentlessly in the second half of 2021. Threat actors continue to attack organizations with a variety of new and previously unseen ransomware strains. 

The Kaseya VSA remote monitoring and management technology attack attracted particular attention because of its widespread impact. This incident was another demonstration of the effectiveness of the breach-once-compromise-many nature of software supply chain attacks.

Another troubling trend is the use of old ransomware that’s being actively updated, enhanced, and reused. For example, BlackMatter was used in multiple attacks against U.S. infrastructure, and it is thought to be a rebranding of DarkSide, the ransomware used in the Colonial Pipeline attack. With the enterprise model of Ransomware-as-as-Service, it’s possible for multiple threat actors to distribute malware more easily.

4. Deeper Understanding of Attack Techniques Stops Criminals Faster

To observe the malicious outcomes of various attacks, FortiGuard Labs analyzed the functionality of detected malware by detonating the malware samples collected. The result was a list of the individual tactics, techniques, and procedures (TTPs) the malware would have accomplished if the attacks had been executed. This high-resolution intelligence shows that stopping an adversary earlier is more critical than ever, and that by focusing on a handful of those identified techniques, in some situations an organization could effectively shut down a malware’s methods for attack.

For example, the top three techniques for the “execution” phase account for 82% of the activity. The top two techniques for obtaining a foothold in the “persistence” phase represent nearly 95% of the observed functionality. Leveraging this analysis can have a dramatic effect in how organizations prioritize their security strategies to maximize their defense. 

Smarter Solutions for Better Protection

These attacks are just some of the many we saw in the second half of 2021. As attacks continue to get faster, organizations need to move away from collections of point products to integrated solutions that are designed to work together. To secure against evolving attack techniques, organizations need smarter solutions that can ingest real-time threat intelligence, detect threat patterns and fingerprints, correlate massive amounts of data to detect anomalies, and automatically initiate a coordinated response. The centralized management and broad visibility of a cybersecurity mesh platform can help ensure that policies are enforced consistently, configurations and updates are delivered promptly, and a coordinated threat response can be launched when suspicious activity is detected.

The FortiGuard Labs Threat Landscape Report Overview

The latest Global Threat Landscape Report represents the collective intelligence of FortiGuard Labs. Its data is drawn from the Fortinet array of sensors that collect the billions of threat events observed worldwide. Using the first three groupings of reconnaissanceresource development, and initial access from the MITRE ATT&CK framework, the FortiGuard Labs Global Threat Landscape Report classifies adversary tactics and techniques to describe how threat actors find vulnerabilities, build malicious infrastructure, and exploit their targets. The report also covers global and regional perspectives to provide security professionals with broad and specific insight into the threat landscape, empowering them to make decisions calculated to reduce their risks and better protect and preserve their critical digital resources. 

Learn more about FortiGuard Labs threat research and the FortiGuard Security Subscriptions and Services portfolio.  

Learn more about the Fortinet free cybersecurity training initiative, the Fortinet NSE Training programSecurity Academy program, and Veterans program.

Sourced from Fortinet

Key Findings from the 2H 2021 FortiGuard Labs Threat Report

If you were to pick a single word to describe cybersecurity events in late 2021 and early 2022, it would be “fast.” The high speed at which cyber criminals operate was highlighted in the semiannual FortiGuard Labs Global Threat Landscape Report for 2H 2021. Findings within this report indicate that cyber criminals are developing attacks faster than ever. They continue to exploit the expanding attack surface of hybrid workers and IT and are using advanced persistent cybercrime strategies that are more destructive and less predictable than those used in the past.

2H 2021 Threat Report Findings: A Summary

The 2021 threat landscape presented several new challenges for security teams. But while some threats came to light for the first time, others proved themselves to be omnipresent, continuing to cause as much damage as they have in past years. The following takeaways from the 2H 2021 FortiGuard Labs Global Threat Landscape Report highlight how these threats – both old and new – worked in tandem to put security measures to the test.

1. Log4j Demonstrates the Speed of Exploits

In December 2021, a critical vulnerability disclosed in the Apache Log4j Java-based logging framework impacted nearly every environment with a Java application. The vulnerability was trivially easy to exploit and gave attackers a way to gain complete control of vulnerable systems. Within days, Log4j became the most prevalent IPS detection in the second half of the year. Shortly after the original disclosure, two other vulnerabilities were discovered, forcing organizations to update their Log4j deployments three times in a single week. 

Despite emerging in the second week of December, exploitation activity escalated quickly enough, in less than a month, to make it the most prevalent IPS detection of the entire second half of 2021. In addition, Log4j had nearly 50x the activity volume in comparison to the well-known outbreak, ProxyLogon, that happened earlier in 2021. Although there were no reports of significant compromises involving the Log4j flaw in the month after it was discovered, it’s possible that attackers exploited the bug to breach networks and are now just waiting for the right time to strike.

2. Adversaries Rapidly Targeting New Vectors – Linux

Not long ago, Linux was one of the least attacked platforms in IT, even though it runs the back-end systems of many networks and container-based solutions for IoT devices and mission-critical applications. However, threat actors are expanding their toolsets and rapidly increasing their use of Linux-based malware

In 2021, malware detections of Executable and Linkable Format (ELF) files – the binary format for Linux – doubled. Additionally, the number of new antivirus (AV) detections Fortinet needed to create quadrupled. The growth in variants and spread suggests that Linux malware is increasing. And with Microsoft actively integrating Windows Subsystem for Linux (WSL) into Windows 11, it’s inevitable that malware will follow. We had ample evidence and reasons to include the continued increase in Linux attacks on our list of 2022 cyber threat predictions.

3. Ransomware Attacks Remain Relentless

The sophistication, aggressiveness, and impact of ransomware continued relentlessly into the second half of 2021. Threat actors continue to attack organizations with a variety of new and previously unseen ransomware strains. One instance of this was the Kaseya VSA remote monitoring and management technology attack, which attracted particular attention because of its widespread impact. This incident was another demonstration of the effectiveness of the ‘breach once, compromise many’ nature of software supply chain attacks.

Another troubling trend is the use of old ransomware that’s being actively updated, enhanced, and reused. For example, BlackMatter was used in multiple attacks against U.S. infrastructure, and it is thought to be a rebranding of DarkSide, the ransomware used in the Colonial Pipeline attack. With the enterprise model of Ransomware-as-as-Service, it’s possible for multiple threat actors to distribute malware more easily.

4. A Deeper Understanding of Attack Techniques Stops Criminals Faster

To observe the malicious outcomes of various attacks, FortiGuard Labs analyzed the functionality of detected malware by detonating the malware samples collected. The result was a list of the individual tactics, techniques, and procedures (TTPs) the malware would have accomplished if the attacks had been executed. This high-resolution intelligence shows that stopping an adversary earlier is more critical than ever, and that by focusing on a handful of those identified techniques, in some situations an organization could effectively shut down a malware’s methods for attack.

For example, the top three techniques for the “execution” phase account for 82% of the activity. The top two techniques for obtaining a foothold in the “persistence” phase represent nearly 95% of the observed functionality. Leveraging this analysis can have a dramatic effect in regard to how organizations prioritize their security strategies to maximize their defense. 

Smarter Solutions for Better Protection

These attacks are just some of the many we saw in the second half of 2021. As attacks continue to get faster, organizations need to move away from collections of point products to integrated solutions that are designed to work together. To secure against evolving attack techniques, organizations need smarter solutions that can ingest real-time threat intelligence, detect threat patterns and fingerprints, correlate massive amounts of data to detect anomalies, and automatically initiate a coordinated response. The centralized management and broad visibility of a cybersecurity mesh platform can help ensure that policies are enforced consistently, configurations and updates are delivered promptly, and a coordinated threat response can be launched when suspicious activity is detected.

Analyzing Findings from the 2H 2021 FortiGuard Labs Threat Landscape Report

The latest Global Threat Landscape Report represents the collective intelligence of FortiGuard Labs. Its data is drawn from the Fortinet array of sensors that collect the billions of threat events observed worldwide. Using the first three groupings of reconnaissanceresource development, and initial access from the MITRE ATT&CK framework, the FortiGuard Labs Global Threat Landscape Report classifies adversary tactics and techniques to describe how threat actors find vulnerabilities, build malicious infrastructure, and exploit their targets. The report also covers global and regional perspectives to provide security professionals with broad and specific insight into the threat landscape, empowering them to make decisions calculated to reduce their risks and better protect and preserve their critical digital resources. 

Learn more about FortiGuard Labs threat research and the FortiGuard Security Subscriptions and Services portfolio.  

Learn more about the Fortinet free cybersecurity training initiative, the Fortinet NSE Training programSecurity Academy program, and Veterans program.

FortiGuard Labs Global Threat Landscape Report 2H 2021 | Threat Intelligence

Sourced from Fortinet

Cybersecurity Mesh Architectures: Fortinet CISOs Discuss The Importance

CISO on CISO Perspectives

The expanding attack surface, increasingly sophisticated cyber threats and network security complexity create challenges for organizations in virtually every industry. A cybersecurity mesh architecture is an approach that is designed to create a collaborative ecosystem of security tools operating across the digital infrastructure. The primary objective is to place security everywhere it’s needed, anywhere in the network, even as users, devices, and applications multiply and become more mobile. Fortinet Field CISOs Alain Sanchez, Joe Robertson, and Courtney Radke joined us to discuss the approach and what it means for CISOs.

What does a cybersecurity mesh architecture approach mean for CISOs?

Alain: With the explosion of edge devices, the complexity of the architectures, and the paramount importance of securing our hyperconnected world, the old-school approach of using security point solutions that aren’t natively integrated doesn’t make sense anymore. In the past, some level of security could be reached by wrapping a layer of interconnectivity around security technologies. But these days are gone. Integrated, automated platforms that provide visibility and trigger superfast defense mechanisms are being adopted even as we speak.

Joe: In fact, Gartner® has done a good job of succinctly describing how to streamline threat defenses with its Cybersecurity Mesh Architecture (CSMA) in its report, Top Strategic Technology Trends for 2022: Cybersecurity Mesh.1

Because cybersecurity is so complex, streamlining cannot be done by simply removing devices. If anything, organizations will need more tools to detect ever subtler tactics and techniques in the future. To reduce complexity, devices need to share threat information and shrink the gaps that attackers slip through. Many executives I meet with are looking to consolidate vendors down from 40 to 50 to a more manageable 5 to 10. But to simplify without losing security coverage requires interoperation and communication among devices.

Courtney: The timing of this discussion couldn’t be more appropriate. We’ve seen the number of security vendors increase significantly and become more pervasive. With that said, CIOs have been looking at the consolidation of technology and functions for some time now. Almost every tech leader I speak with has expressed a desire to decrease sprawl, reduce unnecessary singular-use products and widgets, and move into a more cohesive platform approach.

What are the key attributes of this new security architecture?

Alain: A cybersecurity mesh architecture is how advanced security strategies are designed as we speak. The explosion of edges is already a reality, and mobility and work-from-anywhere are now second nature for a large percentage of the connected population over the last 24 months.

The pandemic accelerated the trend toward a mesh architecture, but many organizations were headed that way already with the focus on platforms and integration. For example, securing the OT environment requires seeing, monitoring, and acting on a scale that is broader than the typical IT inventory. This visibility needs to go beyond the company boundaries and deeper into packets. At the same time, corporations of all sizes are seeing the need for a native and direct integration of concepts like zero-trust network access (ZTNA) and endpoint detection and response (EDR) as part of their strategies. And because the human brain is not fast enough to correlate and evaluate the damage of events happening in different locations, automation is a must these days.

Broad reach, native integration, and advanced, artificial intelligence–based automation are the key attributes of this mesh approach. They are precisely the core attributes of the Fortinet Security Fabric, which was introduced in 2016.

Joe: The key ideas behind a cybersecurity mesh architecture are:

1.  A wide variety of security devices, tools, and applications are needed to identify, block, and quarantine attacks.
2. The devices should share threat intelligence by communicating with each other directly, preferably using standardized formats rather than through a SIEM or SOAR intermediary.
3. The devices in the mesh should be able to take on-board threat intelligence from a variety of external sources, such as the Cyber Threat Alliance, MITRE, CISA, and vendors.
4. The mesh should be able to incorporate scripts, playbooks, artificial intelligence, and machine learning to correlate, analyze, and respond to threats, attacks, and unusual behavior in real time.

Courtney: Like other industries, a technology explosion has been occurring in retail. They want to learn more about their consumers, create more tailored and consistent experiences, and hopefully gain more loyalty and wallet share. As we know, adding technology often comes at a cost to security. Many times, there is a lack of focus on protecting the whole environment cohesively in favor of the individual pieces. I see the security challenges manifest in three ways:

1. You cannot protect what you can’t see. Do you have the tools and services in place to detect advanced threats, even in encrypted traffic?
2. You cannot see where you aren’t looking. Does your visibility extend across your entire digital landscape?
3. When you see something, can you identify it? What intelligence sharing exists between teams, tools, and partners to better mitigate risk and reduce dwell time?

A cybersecurity mesh architecture aims to consolidate visibility, policy management, identity, and intelligence into a single consumable platform that stretches throughout the entire attack surface, reducing security gaps and blind spots more effectively and affordably than performing these roles separately.

What should organizations consider going forward?

Alain: If I judge by the massive adoption of our Fortinet Security Fabric, I’d say the cybersecurity mesh architecture approach has already been adopted for a while, in reality. As we understand it, Gartner gave it a name and a fundamental approach, but corporations have been adopting mesh architectures for a while now.

Joe: Keep in mind that the CSMA doesn’t have to happen all at once. Organizations can add pieces to the architecture a few bricks at a time. As they choose new security tools, they can select those that adhere to an intercommunication philosophy. Our Fortinet Security Fabric mesh architecture has been available for a number of years now, and over time, customers keep adding to it. Perhaps they start with a next-generation firewall, then add intrusion protection, then endpoint detection and response, and so on.

Courtney: The CSMA is a strategy that provides alignment for organizations that want to embrace the concept quickly. The Fortinet Security Fabric is the most mature and well-defined mesh architecture example to date. Still, organizations may feel like they have to make sweeping changes before seeing any results. Luckily, the shift doesn’t have to occur all at once. While big changes may help set the foundation, an iterative approach can still provide significant benefits and opportunities for greater integrations on the journey to a more complete mesh architecture.

What do you think are key pillars of a cybersecurity mesh architecture approach?

Alain: We believe that approaching the network side and the security side together is a paramount condition for a successful mesh strategy. We call this concept Security-driven Networking. Organizations shouldn’t have to compromise between network performance and superior security. Today, we’re witnessing the ability for advanced security to enable levels of innovation we’ve never seen before. Organizations can consider innovations, collaborative applications, and real-time delivery of advanced services that were inconceivable before. In addition to security-driven networking, zero-trust network access, adaptive cloud security, and open architectures are other fundamental building blocks of a mesh design.

Joe: Any mesh architecture must be built around a next-generation firewall, identity and access management, the network, and integrated management, analysis, and response tools. All of these solutions need to have versions appropriate for data centers, clouds, branches, and remote. Other tools, devices, and applications can and should be added on, but these are the most important items. Much of the “smarts” for security is in the NGFW, with its capacity for deep-packet inspection and L7 analysis. In addition to security intelligence, it is also crucial to know who and what is in your environment, hence the identity and access pillar, which includes remote access, branch interconnectivity, identity management, and zero trust. I include the network as one of the fundamental pillars because all threats traverse the network at some time, so the network is the logical place to intercept, identify, block, and quarantine them. The network should be an integral part of the security architecture. And finally, the management of all of this must be simple and understandable for the network and security staff to use. Due to the sheer volume of traffic, events, and threats, much of the correlation and supervision must be automated with tools that incorporate machine learning and artificial intelligence.

Courtney: The success of a CSMA approach relies on the convergence of network and security everywhere. A mesh architecture needs to protect people, devices, and data on any network regardless of the edges they cross. The firewall is at the core of the approach, providing high levels of security and robust inspection for the edge at the edge to increase the speed and effectiveness of detecting threats in real-time. Zero-trust methodologies must also be part of the approach because establishing identity and assessing posture is critical, and it’s more decentralized with multiple sources feeding in. Protection of the endpoint using EDR and XDR will also be necessary as the need to support increasingly connected experiences rises. A unified policy management and orchestration engine with supporting APIs must allow for many native and third-party integrations as well as meaningful automation and valuable intelligence for everything to come together. Without this unification, many organizations are unlikely to adopt CSMA and instead maintain the status quo until a compelling event forces a change.

Gartner, Top Strategic Technology Trends for 2022: Cybersecurity Mesh, 18 October 2021, By Felix Gaehtgens, James Hoover, Et Al.

Gartner is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

Sourced from Fortinet

Cybersecurity Roundtable: Fortinet CISOs Discuss Mesh Architectures

CISO on CISO Perspectives

The expanding attack surface, increasingly sophisticated cyber threats and network security complexity create challenges for organizations in virtually every industry. A cybersecurity mesh architecture is an approach that is designed to create a collaborative ecosystem of security tools operating across the digital infrastructure. The primary objective is to place security everywhere it’s needed, anywhere in the network, even as users, devices, and applications multiply and become more mobile. 

Cybersecurity Experts Discuss Cybersecurity Mesh Architecture

Mesh architectures offer a wealth of benefits to businesses, but they require cybersecurity professionals to completely rethink their approach to security. That’s why Fortinet Field CISOs Alain Sanchez, Joe Robertson, and Courtney Radke joined us to discuss the approach and what it means for CISOs.

What does a cybersecurity mesh architecture approach mean for CISOs?

Alain: With the explosion of edge devices, the complexity of the architectures, and the paramount importance of securing our hyperconnected world, the old-school approach of using security point solutions that aren’t natively integrated doesn’t make sense anymore. In the past, some level of security could be reached by wrapping a layer of interconnectivity around security technologies. But these days are gone. Integrated, automated platforms that provide visibility and trigger superfast defense mechanisms are being adopted even as we speak.

Joe: In fact, Gartner® has done a good job of succinctly describing how to streamline threat defenses with its Cybersecurity Mesh Architecture (CSMA) in its report, Top Strategic Technology Trends for 2022: Cybersecurity Mesh.1

Because cybersecurity is so complex, streamlining cannot be done by simply removing devices. If anything, organizations will need more tools to detect ever subtler tactics and techniques in the future. To reduce complexity, devices need to share threat information and shrink the gaps that attackers slip through. Many executives I meet with are looking to consolidate vendors down from 40 to 50 to a more manageable 5 to 10. But to simplify without losing security coverage requires interoperation and communication among devices.

Courtney: The timing of this discussion couldn’t be more appropriate. We’ve seen the number of security vendors increase significantly and become more pervasive. With that said, CIOs have been looking at the consolidation of technology and functions for some time now. Almost every tech leader I speak with has expressed a desire to decrease sprawl, reduce unnecessary singular-use products and widgets, and move into a more cohesive platform approach.

What are the key attributes of this new security architecture?

Alain: A cybersecurity mesh architecture is how advanced security strategies are designed as we speak. The explosion of edges is already a reality, and mobility and work-from-anywhere are now second nature for a large percentage of the connected population over the last 24 months.

The pandemic accelerated the trend toward a mesh architecture, but many organizations were headed that way already with the focus on platforms and integration. For example, securing the OT environment requires seeing, monitoring, and acting on a scale that is broader than the typical IT inventory. This visibility needs to go beyond the company boundaries and deeper into packets. At the same time, corporations of all sizes are seeing the need for a native and direct integration of concepts like zero-trust network access (ZTNA) and endpoint detection and response (EDR) as part of their strategies. And because the human brain is not fast enough to correlate and evaluate the damage of events happening in different locations, automation is a must these days.

Broad reach, native integration, and advanced, artificial intelligence-based automation are the key attributes of this mesh approach. They are precisely the core attributes of the Fortinet Security Fabric, which was introduced in 2016.

Joe: The key ideas behind a cybersecurity mesh architecture are:

1.  A wide variety of security devices, tools, and applications are needed to identify, block, and quarantine attacks.
2. The devices should share threat intelligence by communicating with each other directly, preferably using standardized formats rather than through a SIEM or SOAR intermediary.
3. The devices in the mesh should be able to take on-board threat intelligence from a variety of external sources, such as the Cyber Threat Alliance, MITRE, CISA, and vendors.
4. The mesh should be able to incorporate scripts, playbooks, artificial intelligence, and machine learning to correlate, analyze, and respond to threats, attacks, and unusual behavior in real time.

Courtney: Like other industries, a technology explosion has been occurring in retail. They want to learn more about their consumers, create more tailored and consistent experiences, and hopefully gain more loyalty and wallet share. As we know, adding technology often comes at a cost to security. Many times, there is a lack of focus on protecting the whole environment cohesively in favor of the individual pieces. I see the security challenges manifest in three ways:

1. You cannot protect what you can’t see. Do you have the tools and services in place to detect advanced threats, even in encrypted traffic?
2. You cannot see where you aren’t looking. Does your visibility extend across your entire digital landscape?
3. When you see something, can you identify it? What intelligence sharing exists between teams, tools, and partners to better mitigate risk and reduce dwell time?

A cybersecurity mesh architecture aims to consolidate visibility, policy management, identity, and intelligence into a single consumable platform that stretches throughout the entire attack surface, reducing security gaps and blind spots more effectively and affordably than performing these roles separately.

What should organizations consider going forward?

Alain: If I judge by the massive adoption of our Fortinet Security Fabric, I’d say the cybersecurity mesh architecture approach has already been adopted for a while, in reality. As we understand it, Gartner gave it a name and a fundamental approach, but corporations have been adopting mesh architectures for a while now.

Joe: Keep in mind that the CSMA doesn’t have to happen all at once. Organizations can add pieces to the architecture a few bricks at a time. As they choose new security tools, they can select those that adhere to an intercommunication philosophy. Our Fortinet Security Fabric mesh architecture has been available for a number of years now, and over time, customers keep adding to it. Perhaps they start with a next-generation firewall, then add intrusion protection, then endpoint detection and response, and so on.

Courtney: The CSMA is a strategy that provides alignment for organizations that want to embrace the concept quickly. The Fortinet Security Fabric is the most mature and well-defined mesh architecture example to date. Still, organizations may feel like they have to make sweeping changes before seeing any results. Luckily, the shift doesn’t have to occur all at once. While big changes may help set the foundation, an iterative approach can still provide significant benefits and opportunities for greater integrations on the journey to a more complete mesh architecture.

What do you think are key pillars of a cybersecurity mesh architecture approach?

Alain: We believe that approaching the network side and the security side together is a paramount condition for a successful mesh strategy. We call this concept Security-driven Networking. Organizations shouldn’t have to compromise between network performance and superior security. Today, we’re witnessing the ability for advanced security to enable levels of innovation we’ve never seen before. Organizations can consider innovations, collaborative applications, and real-time delivery of advanced services that were inconceivable before. In addition to security-driven networking, zero-trust network access, adaptive cloud security, and open architectures are other fundamental building blocks of a mesh design.

Joe: Any mesh architecture must be built around a next-generation firewall, identity and access management, the network, and integrated management, analysis, and response tools. All of these solutions need to have versions appropriate for data centers, clouds, branches, and remote. Other tools, devices, and applications can and should be added on, but these are the most important items. Much of the “smarts” for security is in the NGFW, with its capacity for deep-packet inspection and L7 analysis. In addition to security intelligence, it is also crucial to know who and what is in your environment, hence the identity and access pillar, which includes remote access, branch interconnectivity, identity management, and zero trust. I include the network as one of the fundamental pillars because all threats traverse the network at some time, so the network is the logical place to intercept, identify, block, and quarantine them. The network should be an integral part of the security architecture. And finally, the management of all of this must be simple and understandable for the network and security staff to use. Due to the sheer volume of traffic, events, and threats, much of the correlation and supervision must be automated with tools that incorporate machine learning and artificial intelligence.

Courtney: The success of a CSMA approach relies on the convergence of network and security everywhere. A mesh architecture needs to protect people, devices, and data on any network regardless of the edges they cross. The firewall is at the core of the approach, providing high levels of security and robust inspection for the edge at the edge to increase the speed and effectiveness of detecting threats in real-time. Zero-trust methodologies must also be part of the approach because establishing identity and assessing posture is critical, and it’s more decentralized with multiple sources feeding in. Protection of the endpoint using EDR and XDR will also be necessary as the need to support increasingly connected experiences rises. A unified policy management and orchestration engine with supporting APIs must allow for many native and third-party integrations as well as meaningful automation and valuable intelligence for everything to come together. Without this unification, many organizations are unlikely to adopt CSMA and instead maintain the status quo until a compelling event forces a change.

Gartner, Top Strategic Technology Trends for 2022: Cybersecurity Mesh, 18 October 2021, By Felix Gaehtgens, James Hoover, Et Al.

Gartner is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally and is used herein with permission. All rights reserved.

Sourced from Fortinet