By continuing to use the site or forum, you agree to the use of cookies, find out more by reading our GDPR policy

The National Security Agency (NSA) has released a new report that gives all organizations the most current advice on how to protect their IT network infrastructures from cyberattacks. NSA's report 'Cybersecurity Technical Report (CTR): Network Infrastructure Security Guidance' is available freely for all network admins and CIOs to bolster their networks from state-sponsored and criminal cyberattacks. The report covers network design, device passwords and password management, remote logging and administration, security updates, key exchange algorithms, and important protocols such as Network Time Protocol, SSH, HTTP, and Simple Network Management Protocol (SNMP). The US Cybersecurity and Infrastructure Security Agency (CISA) is encouraging tech leaders to view the NSA document as part of its new push for all organizations in the US and elsewhere to raise defenses after the recent disk wiper malware targeting Ukrainian organizations. The document, from NSA's cybersecurity directorate, encourages the adoption of 'zero trust' networks. Zero trust assumes malicious insiders and threats existing inside and outside classical network boundaries. The NSA says it "fully supports the Zero Trust model" and offers recommendations for creating it, from installing routers and using multiple vendors to creating firewalls that reduce the potential of an exploit impacting one vendor's product. However, the agency also notes that its guidance focuses on mitigating common vulnerabilities and weaknesses on existing networks. The Biden administration has given federal agencies until 2024[/color] to implement zero trust architectures, so the NSA's guidance joins recommendations from the National Institute of Standards and Technology's (NIST) work to explain what zero trust is with key vendors such as Microsoft and Google. The UK is also pushing organizations to adopt zero trust. Among other things, the document focuses closely on Cisco and its widely used IOS networking software for routers and switches, including configuring its one to 15 levels of privileged access to network devices and how to store passwords with algorithms that Cisco IOS devices use. The NSA knows a lot about Cisco gear, as Edward Snowden's 2013 leaks revealed. NSA recommends that similar systems within a network should be grouped together to protect against an attacker's lateral movement after a compromise. Attackers will target systems like printers that are more easily exploitable, for example. It also recommends removing backdoor connections between devices in the network, using strict perimeter access control lists, and implementing network access control (NAC) that authenticates unique devices connected to the network. Regarding VPNs, it says to "disable all unneeded features and implement strict traffic filtering rules". It also specifies the algorithms that should be used for key exchanges in IPSec VPN configurations. NSA says local administrator accounts should be protected with a unique and complex password. It recommends enforcing a new password policy and warns that "most devices have default administrative credentials which are advertised to the public". Admins should remove all default configurations and then reconfigure them with a unique secure account for each admin. "Do not introduce any new devices into the network without first changing the default administrative settings and accounts," NSA says. The new report follows NSA's guidance to help people and organizations choose virtual private networks (VPN). VPN hardware for securing connections between remote workers to corporate networks became a prime target during the pandemic. Follow this thread on OUR FORUM.

 

Russia's invasion of Ukraine is creating new cracks in the world-spanning foundation of the internet. Since Feb. 25, the day after Russia began an assault on its neighbor, Moscow has made it harder for citizens to reach Facebook and Twitter. Separately, Facebook, YouTube, and TikTok have limited access to Russian state-owned media in the European Union at the request of governments in the 27-country bloc. Russia has also exercised the power of its Sovereign Internet Law, which President Vladimir Putin signed in 2019. The law is designed to help the Russian internet survive any Western attempt to cut it off, but it also centralizes state network control so that the government can take actions like censoring sites or hobbling social networks. The increasing fragmentation of the internet, a phenomenon commonly called the "splinternet," reflects the differences in how countries treat both low-level technology that shuttles data around the planet and higher-level applications, such as search engines and messaging apps. Increasingly, a patchwork of different national rules threatens to cripple one of the most powerful means of connection and communication that humanity has created. If the splinternet trend continues, the internet will be replaced by "a bunch of national islands that are sometimes connected to other places," said Andrew Sullivan, chief executive of the Internet Society, a nonprofit seeking to expand internet access. Overall, the internet still works as originally designed, an interlinked collection that now includes more than 32,000 smaller networks run by entities like internet service providers, tech giants, universities, and governments. Technology standards govern how your emails and Instagram photos traverse these networks, hopping across routers and switches linked by fiber-optic lines, radio links, and copper cables. The technologists who invented the internet and created many of its most influential companies have fought fragmentation for years. For example, the Internet Society, the European Commission, the Internet Engineering Task Force (IETF), and Ripe Labs pushed back against a Chinese call for centralized internet standards, which the internet pioneers considered antithetical to the network's distributed ethos. The most powerful manifestation of the splinternet is China's Great Firewall, an internet monitoring and control system the country uses to block companies like US social networks or content like Hong Kong protest information. Now, however, some restrictions are coming from liberal democracies like the EU. However well-intentioned, every regional change adds new complexity, cost, and usage barriers to the internet. As with many industries, governmental restrictions vary around the world. Europe and California created their own privacy laws; China imposes top-down government censorship; India has banned Chinese apps such as TikTok, WeChat, and Weibo; former President Donald Trump attempted to ban TikTok and WeChat, and Russia forced the ejection of a voting app from Google's and Apple's app stores. Russia's war in Ukraine is changing the rules again thanks to government actions and corporate policies against problems such as disinformation. After Russia's invasion, the European Union's effort to "ban the Kremlin's media machine in the EU" meant Facebook, Microsoft and TikTok restricted access to Russian state-controlled media, notably RT and Sputnik. The moves came after similar though smaller actions had been taken. For example, Russia restricted access to Facebook and hobbled Twitter for some users, and Facebook and Twitter restricted ads on Russian state channels. Google's YouTube also reportedly curtailed Russian state-owned media ad revenue and reduced the likelihood their videos would be recommended. Russian law requires larger streaming video services to carry state-run media, although Netflix refused to do so because of the Ukrainian invasion, according to The Wall Street Journal. US sanctions blocked Apple Pay and Google Pay for some Russian bank customers. Mykhailo Fedorov, Ukraine's vice prime minister, wants more. On Feb. 25, the day after Russia invaded Ukraine, he called on Apple CEO Tim Cook to stop selling Apple products and services in Russia and to block Russians from using its app store. "Modern technology is perhaps the best answer to the tanks, multiple rocket launchers ... and missiles," he tweeted, and Apple granted at least some of his wish. For more please visit OUR FORUM.

Cybersecurity pros have an unenviable task: helping businesses mitigate risk and keep consumer data safe, all in the midst of a continually evolving threat landscape. Yet even in the face of daily news stories of data breaches, they manage to spot some silver linings. When it comes to digital security, each year brings a bit of good along with the bad, and cybersecurity professionals celebrate the former while reminding us we need to be constantly improving if we want to protect our customers and our companies. A look back in the rearview shows 2021 was no different. The bad: by the end of September, the U.S. had already seen more data breaches than all of 2020. Even more concerning, a 2021 Forrester survey of individuals responsible for implementing enterprise passwordless authentication, a proven cybersecurity measure that helps defend against these breaches, showed adoption is lagging with half of the respondents less than three months into the process. The silver lining: that same Forrester survey revealed businesses are taking steps to combat fraud with more than two-thirds of respondents in the process of adopting passwordless authentication for employees or partners. This uptick in businesses deploying passwordless authentication demonstrates their comfort embracing an increasingly common trend in identifying and authenticating individuals with high levels of accuracy, while also greatly improving the customer experience: voice biometrics. Most newer smartphones and laptops feature face recognition and fingerprint scanning tools, which has pushed biometric authentication out of dystopian sci-fi literature and into the hands of millions. Such passwordless authentication methods are far superior and more secure than their knowledge-based and token-based authentication predecessors, which are compromised when a fraudster gains access to either. We’re taught in grade school biology that each human’s fingerprints are unique, which has led them to become a highly secure authentication method. But we may have forgotten another biological truism -- our voices are also uniquely ours, a characteristic highly coveted by security professionals and, increasingly, customer support teams fielding countless inbound calls in places like contact centers. While the applications of voice biometrics are myriad, it is finding swift adoption in contact centers which, due to the large volume of calls and personal data they manage, are frequent targets of fraudsters’ attacks and of customers’ frustrations. Contact centers have been under significant pressure over the past two years, amplified by the shift of many of their agents to remote work and by the overall uptick in customer support calls. Key performance indicators (KPIs) important to contact centers have been trending in the wrong direction as a result: average abandonment rate, average talk time, average handle time (AHT), and average speed of answer are all moving backward, per a recent study my company issued. Customers suffer most, and while there is no single culprit, some of this decline can be mitigated through improved security measures that expedite authentication through self-service automation, without compromising (and to the contrary, often improving) security and the overall customer experience. Further details are posted on OUR FORUM.