Tag: Cybersecurity

  • The Dark Net:  Anonymity, Infrastructure, and the Future

    The Dark Net: Anonymity, Infrastructure, and the Future

    Register

    Webinar Info

    Wednesday, Aug. 5, 2020

    United States
    8am PT | 10am CT | 11am ET

    United Kingdom
    4pm BST

    Get CLE or CPE, a complete set of materials, and answers to your questions!

    Email us your:
    Speaker questions
    CLE questions

    Topics Covered

    Physical and Logical Topology and Method of Data Transmission

    Using the Dark Net for Threat Hunting

    Hacking Groups and Malicious Hackers  

    The Future of The Dark Net and Anonymity

    The Dark Net: Anonymity, Infrastructure, and the Future
    Is the Dark Web Getting Darker? 

    Wed., Aug. 5, 2020 | Produced for Access Data by HB Litigation Conferences

    The web, however singular it may seem from behind an everyday user’s computer or smartphone screen, comprises three distinctive parts: the public net (or web), the deep net, and the dark net. Though the dark net contains some innocuous content and is used for legitimate purposes, it also operates as a platform for illegal marketplaces. These offer almost anything a criminal or cybercriminal might want to buy or sell like malware, exploits, hackers-for-hire, information lifted from data breaches, censored content, and goods like drugs, guns, and other contraband.

    Observers report that the dark web is getting darker, meaning hardcore criminals make up a greater percentage of its user base. Exploits and other hacking tools and techniques used to disrupt business, critical infrastructure, and misappropriate confidential information are continually diversifying and becoming more complex. According to Cyber Defense Magazine, the annual cost of cybercrime damages to users, online businesses, and nations is expected to hit $5 trillion this year, with some estimates ranging as high as $10 trillion.

    Join two highly experienced data security professionals – Mary T. Frantz of Enterprise Knowledge Partners and Frank Krahn of Burdock Consulting – as they discuss how cybercrime fighters must overcome a variety of challenges as they threat-hunt on the dark net: detecting, monitoring, and gathering intelligence on cybercrimes and the actors behind them. Frantz and Krahn will discuss how the cybersecurity community will address emerging threats, what changes the web may undergo as a result, and more. The session will be moderated by the head of international training at AccessData, Sarah Hargreaves, who brings her own experience in forensics to the discussion.

    Meet our panelists.


    Frank Krahn
    Co-Founder, Burdock Consulting, LLC

    Before co-founding Burdock Consulting, Frank had a long tenure with the Mayo Clinic, where he served as the Director of Operational Risk Management. He holds various specialist certificates in information security and computer crime investigation and forensics. Frank has taught classes and consulted for law enforcement agencies on computer crime-related matters, and has worked with the FBI. He is also an e-discovery specialist.


    Mary T. Frantz

    Founder & Managing Partner, Enterprise Knowledge Partners, LLC

    Mary is a technology and strategy professional with more than 25 years’ experience as a corporate and consulting firm executive. Her expertise includes IT strategy, e-discovery, compliance, enterprise risk, information security, and enterprise architecture. Mary has served as a legal expert on a variety of cyber security topics. She is also an author, keynote speaker, and adjunct professor.


    moderator

    Sarah Hargreaves ACI, ACE
    Director of Training – International
    AccessData, United Kingdom

    Sarah started her career in digital forensics in 2003.  Previously working in a criminal law practice, Sarah moved over to forensics after working on a number of investigations which inspired her to change career path.  Her journey continued with a number of roles in Digital Forensic Laboratories, primarily supporting law enforcement in Child Sexual Exploitation investigation and general crime.  Sarah progressed to Laboratory Management and later into Training Management.

    Sarah is experienced in digital investigation, laboratory management, ISO17025 and evidential process.

    Sarah lives in the North West of England and is a mum to two young children.  She enjoys days out with her family and traveling.

  • Setting the record straight on cyber insurance claim denials and the ‘war exclusion’

    Is insurance coverage for cyber claims barred by a war exclusion?  Judy Selby and Peter McLaughlin asked this question in a recent post for IAPP.

    Two corporate giants, Mondelez International and Merck, made the headlines recently as they sustained serious damage as a result of a NotPetya infection, an encrypting ransomware. They have each filed declaratory judgments after their carriers denied their claims. Reports of these insurance disputes have led to concerns that cyber incidents involving state actors would not be covered by cyber policies with war exclusions.

    The Verizon 2019 Data Breach Investigations Report attributes 23% of breaches  to nation-states or state-affiliated players. “These state-sponsored attacks typically range from theft or espionage to financial gain; however, some attacks appear to have been driven by grudge or by swatting a neighbor,” Selby and McLaughlin write.

    “[P]erhaps we are viewing this through an old lens. Insurance has often been purchased to address hazards. Specifically, an organization obtains a policy to counter the slim risk of a fire, flood or other catastrophe. Fred Kaplan wrote an article for Slate in April in which he argues the inevitability of attacks – state-sponsored or otherwise – means that we should view cyber insurance more like we do health insurance: coverage against the inevitable, rather than against a hazard risk.”

    Read on for what else Selby and McLaughlin had to say here.

  • Cyber Captive Survey 2019 — AON

    Aon’s Cyber Captive Survey 2019 says that the rapid growth in the captive market of cyber-specific policies underscores that cyber is one of the primary risks for organizations across the world driven by an increasingly complex operational, technological and regulatory environment.

    Key findings include:

    • Healthcare and energy industries are leading the way, with 19% and 15% of organizations in these industries utilizing captives for cyber coverage respectively.

    • 41% of captives surveyed are incubating cyber risk.

    • The range in limits of cover taken out is up to USD$100 million.

    • An estimated 34% of all captives will be writing cyber in five years’ time.

    Read the complete report here! 

  • First Class Action Lawsuit Filed on Behalf of Victims of First American Title Company Data Breach — Yahoo!

    “Gibbs Law Group LLP has filed the first nationwide class action lawsuit accusing First American Title Company of failing to properly secure 885 million sensitive customer files, instead choosing to store them in a ‘woefully insecure,’” publicly-accessible system. “First American has turned the American dream of home ownership into a financial security nightmare for its customers,” according to the complaint.

    Specifically, the lawsuit alleges that First American Title Company was negligent, and violated its contracts with customers, in the way it stored their personal information, which included bank account numbers, Social Security numbers, financial and tax records, and photos of their drivers’ licenses. “This grave lapse in security resulted in publicly exposing hundreds of millions of customers’ personal files, leaving them vulnerable to identify theft and other cybercrimes,” the plaintiffs maintain. 

    Read the complete Press Release on Yahoo! here

  • The Future of Cyber Operations and the Government

    In the forthcoming National Defense Authorization Act the House Armed Services Committee — specifically the Subcommittee on Intelligence and Emerging Threat Capabilities — seeks to amend the annual legislation to ensure that Congress is informed when the executive branch executes offensive or defensive cyber operations.

    The bill defines offensive or defensive cyber operations as a “sensitive military operation.” The goal of this shared information is additional oversight, especially given the newness of cyber tactics.

    As reported by journalist Derek B. Johnson of FWC.com, two covert cyber operations have taken place since POTUS announced the new policy. The first was in October 2018, a cyber operation with a goal of informing Russian operatives not to meddle with the midterm election. The second took place the following November in which the U.S. Cyber Command blocked access to Russian Internet Research Agency post election.

    While these two operations have been called “mild” in some critiques, former White House Director of Cyber Infrastructure Protection under President George W. Bush, Jason Healey, believes this highly specialized tactic is ideal since it presents the least potential for collateral damage. While Healey warns against grand and overt attacks, he states that sometimes “conflict is straightforward and you just have to stop adversaries from punching you in the mouth.”

    Read the complete post by Derek B. Johnson on FCW.com here.

  • Dr. Babyl: Artificial Intelligence Could Save Lives, Time and Money — TheDailyBeast.com

    Itchy throat? Headache? Upset stomach? There’s an app for that. There is a new AI healthcare system called Babylon UK’s National Health Service which features an AI-driven app that is reportedly able to separate “run-of-the-mill” illnesses from more life-threatening ones, while saving time, money, and anxiety for patients and doctors alike.

    Babylon offers more than diagnostic assistance; it is accessible to people in remote areas. “For example, Babyl, the Rwandan version of Babylon, offers remote appointments with clinicians, fills prescriptions, orders lab tests, and issues referrals.”

    Babyl enables affordable, personalized healthcare, combined with “the brains of thousands of doctors at once” to reach patients who cannot get to a doctor’s officer.

    In addition to assisting doctors with everyday check-ups and treating the common cold, the AI’s abilities extend to clinical trials. “In 2018 the Mayo Clinic partnered with IBM’s Watson to match patients with breast cancer to accessible clinical trials covered by their health plans. The matching program increased the enrollment of breast cancer sufferers in Mayo Clinic’s own clinical trials by 80%.”

    Questions are being raised, however, about how to mitigate risks posed by hacking or by nefarious manipulation of the system. Read about this and more in the complete post by Joelle Renstrom on TheDailyBeast.com. 

  • Artificial Intelligence: DeepMind on Debugging Learned Predictive Models

    DeepMind, an artificial intelligence research company, in a recent blog post discusses three ways to eliminate bugs in learned predictive models. The company was founded in London in 2010. Google acquired it in 2014. In addition to London they have research centers in Edmonton and Montreal, Canada, and a DeepMind Applied team in Mountain View, California.

    “Bugs and software have gone hand in hand since the beginning of computer programming,” the post reads. “Over time, software developers have established a set of best practices for testing and debugging before deployment, but these practices are not suited for modern deep learning systems. Today, the prevailing practice in machine learning is to train a system on a training data set, and then test it on another set. While this reveals the average-case performance of models, it is also crucial to ensure robustness, or acceptably high performance even in the worst case. In this article, we describe three approaches for rigorously identifying and eliminating bugs in learned predictive models: adversarial testing, robust learning, and formal verification.”

    Read the complete post here! 

  • The Cloud: Selected Benefits, Risks, and Insurance Coverage Issues (Part 1) — Barnes & Thornburg

    Cloud Risk: Do You Transfer Liability Along with Data?

    Many of us were using data clouds before we even knew what they were. Now, while most of us are comfortable with the concept, we may not be comfortable knowing who is liable when data is lost, damaged or breached. It’s not a given that your cloud provider absorbs any liabilities, and it’s not a given they can even afford the liability should it arise. Below are quotes from an article by Scott Godes, Kara Cleary, and Heidi Fessler of Barnes & Thornburg LLP on the subject, and a link to their complete article. 

    Godes, Cleary, and Fessler list several cloud-related risks: data breaches, data loss, interruption of access, compromised credentials and broken authentication, and denial of service.  But two other categories for concern are: 

    #1. BYOC, or Bring Your Own Cloud. Employees may be innocently using productivity applications that store work data on non-company clouds, in effect, “bringing their own clouds” to the workplace.

    #2. Multi-Tenancy. This involves risks posed when unrelated cloud users are sharing the same computing resources. 

    “Both the cloud provider and the user must be aware of system and data security to prevent a breach in the security. In addition, when a risk is realized, it may not always be clear who is at fault for the system or security failure.

    “There are a lot of misconceptions around the cloud and liability,” the Barnes & Thornburg attorneys write. 

    “Many companies assume that along with the transfer of their data, they have also transferred their risk to the cloud provider,” they say. “Absent a clear agreement that shifts liability to the cloud provider, the practical reality is that in most cases, there’s very little protection in terms of liability with cloud providers, unless parties are willing to engage in protracted litigation to determine otherwise. The shifting of liability is not nearly as easy as the transfer of data and often it may be the case that the responsibility for a data breach rests with the party that collected and maintained the data originally. Perhaps the most notable exception has been in the healthcare industry, where companies providing support often are classified as ‘business associates’ under HIPAA and might be subject to the same obligations for protecting data as the entity with the original patient relationship. Even here, one could argue that liability transfer does not occur, but rather a liability expansion that includes the cloud provider.” 

    Read the complete article, the first in a series, on the Barnes & Thornburg blog.

  • Anderson Kill’s 5th Annual Cyber Insurance Recovery Conference

    [one-half-first][/one-half-first] [one-half]Recent news of “Collection 1”, a cache of sensitive data now appearing for sale on the dark web and comprised of an astonishing 773 million records, is a grim reminder of the scope of cyber perils for most.  Last year’s staggering tally of serious data breaches and theft coupled with a spate of new legislation for companies gathering, hosting and selling consumer data means policyholders must rise to the challenge.  New state legislation compounds an already daunting federal and international regulatory landscape, and regulatory compliance will be a must to deal with the attendant fines, penalties and consumer claims that non-compliance can trigger.  New technology also continues to drive the evolving conversation about the legal relationships between parties transacting business electronically.  Risks range from anonymity that raises jurisdictional and collection issues to “immutable” record keeping that creates a permanent, public record of transactions. –Anderson Kill [/one-half]

    Find out more about this complimentary seminar from Anderson Kill here!

  • South Korea, EU Having ‘Adequacy’ Discussions

    Because of its robust network connectedness, its advanced use of mobile devices and its rich collection of intellectual property, South Korea is a leading target for hackers.

    Discussions are under way between the EU and South Korea to determine, as a non-EU country, whether its data protections are adequate. Also, South Korea has joined the APEC Cross-Border Privacy Rules system. Significant caselaw is developing regarding this country’s 2011 data protection statute as well as its sector-specific laws.

    Daniel Solove and Paul Schwartz have selected Professor Haksoo Ko from the Law School at Seoul National University to speak at the International #PrivacySecurity Forum April 3-5, 2019. Ko will co-present to provide an up-to-date account of developments in South Korea and analyze the most important compliance hurdles.

    Learn more: http://bit.ly/IPSF-2019