The 100 Coins Exercise: Cybersecurity Priorities Advice from Leading CISOs

One of the biggest challenges faced by CISOs is that there is always more that can be done to secure an organization and a finite amount of resources with which to do things. It’s a common problem for security leaders. To help CISOs and other security leaders better address investment priorities about their cybersecurity portfolios Fortinet teamed up with Early Adopter Research to develop research into the choices and decisions CISOs have made.

What Is the Fortinet 100 Coins Project?

The 100 Coins research project asks leading CISOs to allocate a budget of 100 coins over 25 categories of cybersecurity capabilities. It started at the RSA conference two years ago when some CISOs were asked to allocate 100 coins, that is, units of cybersecurity spending, over 25 different categories of cybersecurity capabilities. This exercise was repeated at another conference until a total of 7 CISOs participated.

According to Fortinet’s Phil Quade, the inspiration for this approach came from Quade’s experience doing similar exercises during his tenure at the National Security Agency. They sometimes use a “100 Coins” exercise as an aid for thinking about planning and resource allocation. The general idea of the exercise is for participants to suppose they had a couple of hundred things they might wish to buy, but only one-hundred coins to spend. What would they choose to buy, and why?

The resulting report captures thinking from leading CISOs about how to make the difficult decisions and tradeoffs when allocating a fixed amount of money across a portfolio. 

Running the 100 Coins Exercise with Leading CISOs

Each participant was presented with a fixed portfolio of solutions spanning 25 different categories, with items in each area assigned a value. CISOs had to make selections using their limited budget, and then explain their decision-making process.

The results of this exercise, combined with more extensive research from the Early Adopter Research team, have been summarized in a new paper entitled, “Creating the Ideal Cybersecurity Portfolio: Leading CISOs Reveal Their Priorities.”

A Peek at the Results

The report starts with the results of the 100 Coins exercise, and then provides practical advice from interviews with CISOs.

Portfolio Goals, Priorities, and Tradeoffs

In this section, the consensus is that CISOs need to avoid diving in on specific technologies and instead think strategically. Here are three areas CISOs discussed:

  • Determine the balance you need to strike between prevention, detection, and response. This decision depends on things like the kind of industry you are in, the kinds of data and resources you use, the nature of your environment, and things like digital transformation plans. The answers to these questions can have a significant impact on balancing your security strategy.
  • You also need to understand your organization’s tolerance for risk. Understanding what resources are table stakes that must be protected at all costs, their general vulnerability to different sorts of attacks, and the impact to the organization if they are compromised all help set the agenda for this part of an evaluation. Only then can you decide whether, and how much, you want to play offense, and where to play defense when it comes to acquiring and deploying cybersecurity resources.
  • The hardest challenge is that many problems don’t have easy answers. When creating a hierarchy of needs, you still need to decide whether you should address your worst-case scenarios or your most common risks. This requires scoping out any challenges and then mapping them to  solutions in place to determine which resources need to be replaced or upgraded or what critical gaps exist in your current security portfolio. This may also include evaluating enduring problems that you can’t simply spend your way out of.

Aspects of the Ideal Solution

This section of the report focuses on critical qualities of any cybersecurity solution under consideration, such as making sure you match solutions to your maturity level. This needs to be done both in terms of your infrastructure and the expertise of your security team. Solutions that are too complex or require a lot of fine-tuning might be ideal for some organizations but may end up sitting on a shelf collecting dust in others. This would also include deciding if or when to adopt leading-edge solutions.

Platform readiness is another essential element that needs to be understood before deploying any technology. Can you run this technology in your environment? Can it be integrated with other solutions in place, or will it be a standalone and largely isolated solution? How well does it work across other platforms? This includes whether it can be deployed as a cloud native solution, whether it runs consistently across multi-cloud environments, and if it can seamlessly share and enforce policies and protocols regardless of where it is deployed.

Summary 

This new report captures detailed thinking from several leading CISOs about how to make difficult tradeoffs when allocating a fixed amount of money across a portfolio. Processes and strategies are discussed in detail, helping CISOs as well as those seeking to better understand cybersecurity make better and more effective decisions.

Read the full report, “Creating the Ideal Cybersecurity Portfolio: Leading CISOs Reveal Their Priorities,” to learn more about how leading CISOs allocated their cybersecurity spending in the 100 coins exercise.

Find out how Fortinet’s Security Fabric delivers broad, integrated, and automated protection across an organization’s entire digital attack surface from IoT to the edge, network core and to multi-clouds. 

Sourced from Fortinet

Key Findings from Fortinet’s 2019 State of DevOps Security Report

Digital transformation involves redistributing data, computing and processes to reduce overhead, simplify operations and enhance productivity. One of the most impactful outcomes is that workflows, data access and analysis, and transactions are all being moved to web applications. DevOps went mainstream in 2017 with 84% of enterprises adopting DevOps principles, enabling customers to easily conduct transactions using their smart phones and other devices.

This enabled employees to use web applications to do things like conduct business, generate reports, and collaborate with other workers, resulting in increased productivity and the ability to respond more quickly to market demands. IoT devices use similar applications to share, collect, and correlate data to contribute to Big Data and bridge the gap between IT and OT networks.

The Challenge of DevOps

As web applications increasingly become the responsibility of the DevOps team, which uses special development strategies to build, assemble, update and maintain these applications. For the most part, these applications leverage cloud native services in order to accelerate their ability to develop these tools.

One of the most unexpected results of digital transformation is that online consumers tend to be much more fickle. They are willing to abandon brand loyalty in exchange for a faster, simpler, or slicker user interface. And internal users exhibit many of the same tendencies. So, to keep up with this new reality, DevOps teams are under constant pressure to adapt new technologies and maintain a competitive edge in a space driven by change.

Today, DevOps is impacting more strategic business initiatives in the company than ever. Web applications have evolved from an interesting business novelty to strategic tools supporting the mainline business. And because of this increasingly visible and important business function, 69% of DevOps team leaders now report directly to a member of the C-suite.

The Need for Speed and Security

Because DevOps applications have become essential to business success, proper security is critical for these tools. Exploiting the right web application can not only expose the personally identifiable information (PII) of a customer, but have a serious impact on critical business functions. According to Fortinet’s recent 2019 State of DevOps Security Report, 92% of organizations have seen at least one vulnerability slip into production in the past 12 months, with the typical organization experiencing 3 to 5 vulnerabilities in production in that time. And catching those vulnerabilities is equally challenging, as only 14% of organizations have enabled full visibility into their DevOps environment from their SOCs. As a result, 70% of organizations plan to roll DevOps security under their CISO in the next year.

However, there are some concerns that this commitment is little more than lip service. The reason is time to market. Speed is a critical component of DevOps efforts, and failure to provide applications and updates means falling behind, which in today’s digital marketplace can have devastating consequences.

 What DevOps professionals fear, and rightly so, is that traditional security solutions will inevitably slow down their projects. And as a result, according to a recent survey, 52% of companies admitted to scaling back security measures to meet a business deadline or objective. In fact, 68% say their CEOs demand that DevOps and security teams never slow down a business process. Unfortunately, the speed at which code needed to be published has likely played a role in a number of high-profile data breaches.

Combining Best Practices with Security Solutions

What DevOps teams need are security tools that reduce risk without impeding their work or requiring them to become security experts. They need to be able to stitch security tools and functions into an application where they are needed, but without the time and energy required to build and manage those tools from scratch. Instead, they need configuration and updates, lifecycle maintenance, and monitoring to be automated. And when not, those functions need to be performed by the security team.

However, security solutions alone are not enough. The analysis in the 2019 State of DevOps Security Report of those organizations that consistently manage to catch application vulnerabilities and avoid security breaches shows that they also practice a similar set of good security hygiene protocols. These best practices include:

  • Security audit tracking
  • Tracking and reporting on compliance with security standards
  • Tracking and reporting security compromises
  • Dependencies analysis
  • Scanning public cloud instances for misconfigurations
  • Vulnerability assessment and management scanning
  • Monitoring and managing code commits

Meeting DevOps Goals While Reducing Risk

The findings in our 2019 State of DevOps Security Report indicate that security solutions for a DevOps environment must be scalable, agile, and automated. Which also means that traditional approaches to network security simply do not have the agility to support a DevOps environment. Instead, network security must include integrated and automated solutions that can address the current threat landscape—in which cyber criminals are using advanced technologies such as artificial intelligence and swarm technology to create customized threats that move at machine speeds—while not impeding the speeds at which DevOps needs to operate.

This needs to be done by combining best practices with security solutions that simplify implementation, minimize false positives through machine learning, and automate threat response. Organizations that establish and adhere to such a holistic, fully integrated approach to security can reap the benefits of DevOps without increasing risk to themselves or their customers. 

Learn more about how Fortinet’s multi-cloud solutions provide the necessary visibility and control across cloud infrastructures, enabling secure applications and connectivity from data center to cloud.

Read these customer case studies to see how Cuebiq and Steelcase implement Fortinet’s multi-cloud services for secure connectivity and application security.

Sourced from Fortinet

Cyber Threats And Financial Services

This is a summary of an article written for Global Banking and Finance Review by Fortinet’s Senior Security Strategist/Researcher and CTI Lead, Tony Giandomenico. The entire article can be accessed here.

Cyber criminals continue to target the financial services industry to steal payment card data, online banking accounts, and to compromise ATM machines using ransomware, cryptomining, and other malware. Defending against this is made more difficult due to challenges such as blending new technology with legacy systems while meeting evolving compliance standards.

Threats Are Constantly Evolving

A recent Fortinet Threat Landscape Report highlights threats targeted at a number of industries, including financial services. Coinhive, originally launched in 2017, focused on the Monero cryptocurrency, and had great success in the black market. However, Coinhive announced in February that it would be shutting down, in part because Monero value crashed, and the introduction of an algorithm that made mining Monero slower.

However, cyber criminals have been quick to fill the gap by developing several new techniques to replace CoinHive.

Targeted Threats Target Financial Services

One such criminal enterprise is Silence Group. While they primarily target financial institutions in Russia and eastern Europe, the infrastructure they rely on to support their criminal activities has expanded to include Australia, Canada, France, Ireland, Spain, Sweden, and the United States.

At the same time, Silence Group has grown more sophisticated, recently employing “living off the land” tactics by leveraging pre-installed and publicly available tools such as PowerShell, that allowing them to accelerate lateral movement across a network while enhancing evasiveness because they use processes the network has already identified as legitimate.

In another attack, this one a spear phishing strategy, the Silence Group managed to compromise banks to gather financial data and enable the remote withdrawal of money from ATMs, an attack known as “jackpotting.”

Another criminal team, known as Emotet, launched several new campaigns during Q1 of 2019 using information-stealing, ransomware, and banking Trojan modules.

 Targeting Financial Networks for Financial Gain

One serious development is a shift away from random attacks and towards things like tailored ransomware. One recent example is LockerGoga, a ransomware variant that surfaced early this year.

“Despite causing severe disruption to targets in Europe and the United States through attacks informed by research and due diligence, researchers have pointed out the end goal of these attacks was not extortion. There is still not a clear understanding of the motivation.”

– Anthony Giandomenico, June 26, 2019

However, what is clear is that highly targeted attacks, especially when combined with advance living off the land tactics, help cybercriminals evade detection, bypass security sensors, and achieve their goals with little to no recourse from their targets. For example, there is little about LockerGoga that sets it apart from other ransomware in terms of functional sophistication, but while most ransomware tools use some level of obfuscation to avoid detection, there was little of it used when analyzed.

 Final Thoughts

“Cyber criminals continue to modify their attack strategies to increase accuracy and achieve their primary goals. For the financial services industry, this can result in the targeting of online banking accounts, payment cards, and, as was demonstrated in Q1, even ATM machines.”

– Anthony Giandomenico, June 26, 2019

In order to defend against these sophisticated threats, financial institutions must rely on threat intelligence and advanced behavioral and system analytics in order to identify threats and circumvent the impact of these new targeted cyberattacks.

This is a summary of an article written for Global Banking and Finance Review entitled, Understanding the Impact of Targeted Cyber Threats on Financial Services, written by Fortinet’s Senior Security Strategist/Researcher and CTI Lead, Anthony Giandomenico, and published on GlobalBankingandFinance.com on June 26, 2019. 

Learn more about FortiGuard Labs and the FortiGuard Security Services portfolioSign up for our weekly FortiGuard Threat Brief. 

Read about the FortiGuard Security Rating Service, which provides security audits and best practices.

Sourced from Fortinet

Leveraging Cloud APIs for Comprehensive Security

This is a summary of an article written for CloudTech by Fortinet’s Lior Cohen. The entire article can be accessed here.

According to research published by the IBM Institute for Business Value, 85% of enterprises currently operate a multi-cloud environment, and 98% of companies plan to use multiple clouds by 2021. And because of new digital business requirements, those clouds don’t operate in isolation. Business processes, transactions, applications, and workflows now move across and between physical networks, branch offices, mobile devices, and multi-cloud networks.

The challenge is for data, workflows, and applications to move quickly and seamlessly across and between these different physical and virtual environments without compromising security. What’s needed is a consistent security posture across all local and cloud-based resources so policies and enforcement can follow and protect cross-platform communications.

Leveraging the Cloud’s Native Controls and APIs

Gartner predicts that through 2022 at least 95% of cloud security failures will be the result of misconfiguration. Part of the  problem is that many organizations are trying to overlay traditional security tools into their cloud environments. Unfortunately, many of these tools were never designed to consistently secure cloud platforms, scale to cloud requirements, or operate at cloud speeds.

Instead, to truly secure the cloud, security tools need to natively integrate into the cloud so they can run in the same elastic and distributed way that cloud applications run – which is fundamentally different from the way most traditional security tools function when operating as a cloud overlay solution.

What security teams need to do is collect critical cloud security information and share those findings with cloud DevOps teams. This allows security issues to be incorporated into ongoing cloud development for consistent compliance reporting across multiple clouds, enable streamlined and correlated incident investigation, and a provide a live, centralized cloud threat and heat map to provide real-time insight into the state of security across the entire cloud environment.

“To make this possible, cloud security management and analytics tools need to be integrated into the public cloud API, enabling them to simultaneously monitor the activity and configurations of multiple cloud resources across regions and public cloud types. This level of consistent visibility enables such things as instant insight into regulatory compliance violations to enhance compliance with industry or government standards. They also empower threat and risk management tools to effectively trace misconfigurations to their source.”

–Lior Cohen, CloudTech, May 2014, 2019

What You Need

Organizations need to leverage tools designed specifically for cloud security with native integration into the various cloud platforms being used. This allows security to solve multiple cloud adoption challenges, including migrating applications and infrastructure to the cloud and building and consuming SaaS applications.

Today’s unique cloud environments cannot be secured using traditional independent or isolated security systems. Instead, they need to span across a multi-cloud ecosystem to ensure consistent security policy enforcement across the entire distributed infrastructure. True visibility and control in a multi-cloud environment requires cloud native security solutions bound together with a policy management and analytics solution that can be seamlessly integrated through a central cloud management system.

This is a summary of an article written for CloudTech, entitled: “How leveraging APIs will help to enable comprehensive cloud security,” written by Fortinet’s Lior Cohen and published on the CloudTech website on May 24, 2019. 

Learn more about how Fortinet’s multi-cloud solutions provide the necessary visibility and control across cloud infrastructures, enabling secure applications and connectivity from data center to cloud.

Read these customer case studies to see how Cuebiq and Steelcase implement Fortinet’s multi-cloud services for secure connectivity and application security.

Sourced from Fortinet