100% found this document useful (1 vote)
5K views16 pages

Understanding Cybersecurity Essentials

Cybersecurity consists of technologies, processes, and controls to protect systems, networks, and data from cyber attacks. Effective cybersecurity is achieved through implementing controls based on people, processes, and technology. This three-pronged approach helps organizations defend against both organized attacks and common threats like human error.

Uploaded by

Sucharita Sarkar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
100% found this document useful (1 vote)
5K views16 pages

Understanding Cybersecurity Essentials

Cybersecurity consists of technologies, processes, and controls to protect systems, networks, and data from cyber attacks. Effective cybersecurity is achieved through implementing controls based on people, processes, and technology. This three-pronged approach helps organizations defend against both organized attacks and common threats like human error.

Uploaded by

Sucharita Sarkar
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
  • Introduction to Cybersecurity
  • Elements of Cybersecurity

Cybersecurity

Cyber security consists of technologies, processes and controls designed to protect systems,
networks and data from cyber attacks. Effective cyber security reduces the risk of cyber
attacks and protects against the unauthorised exploitation of systems, networks and
technologies.

Robust cyber security involves implementing controls based on three pillars: people,
processes and technology. This three-pronged approach helps organisations defend
themselves from both organised attacks and common internal threats, such as accidental
breaches and human error.

The three pillars of Cyber security:


People:
Every employee needs to be aware of their role in preventing and reducing cyber threats, and
specialised technical cyber security staff need to stay fully up to date with the latest skills and
qualifications to mitigate and respond to cyber attacks.

Processes:

Processes are crucial in defining how the organisation’s activities, roles and
documentation are used to mitigate the risks to the organisation’s information. Cyber threats
change quickly, so processes need to be continually reviewed to be able to adapt alongside
them.

Technology:

By identifying the cyber risks that your organisation faces you can then start to look at what
controls to put in place, and what technologies you’ll need to do this. Technology can be
deployed to prevent or reduce the impact of cyber risks, depending on your risk assessment
and what you deem an acceptable level of risk.

Why is cyber security important?


The costs of data breaches are soaring:

With the EU GDPR (General Data Protection Regulation) now in force, organisations could
be faced with fines of up to €20 million or 4% of annual global turnover for certain
infractions. There are also non-financial costs to be considered, such as reputational damage
and loss of customer trust.
Cyber-attacks are becoming increasingly sophisticated:

Cyber-attacks have become more sophisticated with attackers using an ever-growing variety
of tactics to exploit vulnerabilities, such as social engineering, malware and ransom ware (as
was the case with Petya, WannaCry and NotPetya).

Cyber security is a critical board issue:

New regulations and reporting requirements make cyber security risk oversight a challenge.
The board will continue to seek assurances from management that their cyber risk strategies
will reduce the risk of attacks and limit financial and operational impacts.

A strong cyber security stance is a key defence against cyber-related failures and errors and
malicious cyber-attacks, so it’s vital to have the right cyber security measures in place to
protect your organisation.

Elements of cyber security


A strong cyber security posture hinges on a systematic approach that encompasses:

 Application security
Web application vulnerabilities are a common point of intrusion for cyber criminals.
As applications play an increasingly critical role in business, organisations urgently
need to focus on web application security to protect their customers, their interests
and their assets.

 Information security
Information is at the heart of any organisation, whether it’s business records, personal
data or intellectual property. ISO/IEC 27001:2013 (ISO 27001) is the international
standard that provides the specification for a best-practice information security
management system (ISMS).

 Network Security
Network security is the process of protecting the usability and integrity of your
network and data. This is usually achieved by conducting a network penetration test,
which aims to assess your network for vulnerabilities and security issues in servers,
hosts, devices and network services.

 Business continuity planning


Business continuity planning (BCP) involves being prepared for disruption by
identifying potential threats to your organisation early and analysing how day-to-day
operations may be affected.

 Operational security
Operations security (OPSEC) protects your organisation's core functions by tracking
critical information and the assets that interact with it to identify vulnerabilities.
 End-user education
Human error remains the leading cause of data breaches, and your cyber security
strategy is only as strong as your weakest link. Organisations need to make sure that
every employee is aware of the potential threats they face, whether it’s a phishing
email, sharing passwords or using an insecure network.

 Leadership commitment
Leadership commitment is the key to the successful implementation of any cyber
security project. Without it, it is very difficult to establish, implement and maintain
effective processes. Top management must also be prepared to invest in cyber
security measures. Cyber security should be given appropriate priority by the board to
support further investment in technology, resources and skills.

What are the consequences of a cyber attack?


Cyber attacks can disrupt and cause considerable financial and reputational damage to even
the most resilient organisation. If you suffer a cyber attack, you stand to lose assets,
reputation and business, and potentially face regulatory fines and litigation – as well as the
costs of remediation.

Types of cyber security threat


Ransom-ware
One of the fastest-growing forms of cyber-attack, ransom-ware is a type of malware that
demands payment after encrypting the victim’s files, making them inaccessible. Paying the
ransom does not guarantee the recovery of all encrypted data.

Phishing
Phishing attacks are continually on the rise. Often indistinguishable from genuine emails, text
messages or phone calls, these scams can inflict enormous damage organisations.

Malware
Malware is a broad term used to describe any file or programme intended to harm a
computer, and encompasses Trojans, social engineering, worms, viruses and spyware.

Social engineering
Social engineering is used to deceive and manipulate victims to gain computer access. This is
achieved by tricking users into clicking malicious links or by physically gaining access to a
computer through deception.
Outdated software
The use of outdated (unpatched) software (e.g. Microsoft XP) opens up opportunities for
criminal hackers to take advantage of known vulnerabilities that can bring entire systems
down.

Vulnerabilities in web application and network


Cyber criminals are constantly identifying new vulnerabilities in systems, networks or
applications to exploit. These activities are conducted via automated attacks and can affect
anyone, anywhere.

How to protect against cyber security attacks?


The most effective strategy to mitigate and minimise the effects of a cyber attack is to build a
solid foundation upon which to grow your cyber security technology stack.

Solution providers often tell their clients their applications are 100% compatible and will
operate seamlessly with the current IT infrastructure, and for the most part, this is true. The
problem arises when we start adding IT security solutions from different manufacturers
regardless of the granularity of their configuration settings – technology gaps will always be
present.

And technology gaps will always appear for one simple reason: developers will always keep
certain portions of their code proprietary as part of their competitive advantage. Hence, true
compatibility and interoperability may only be 90%. These are known as technology gaps. It
is through these gaps that attacks usually occur.

A solid cyber security foundation will identify these gaps and propose the appropriate action
to take to mitigate the risk of an attack, enabling you to build a robust cyber security strategy.

Cyber space
“A global domain within the information environment consisting of the interdependent
network of information technology infrastructures, including the Internet,
telecommunications networks, computer systems, and embedded processors and controllers.“
-- A Definition of Cyberspace

Life in a Networked World • Rapid Development in Information Technology – Speed of


Microprocessor chips doubles every 12-18 months – Storage Density doubles every 12
months – Bandwidth is doubling every 12 months – Price keeps dropping making technology
affordable & pervasive

The New “Net” monitors & controls critical Infrastructure. Its integrity & availability is
critical for economy, public safety and national security.
Defining the term “Cyber”:
 Cyberspace is the connected Internet Ecosystem.
 Trends Exposing critical infrastructure to increased risk:
o Interconnectedness of Sectors
o Proliferation of exposure points
o Concentration of Assets
 Cyber Intrusions and Attacks have increased dramatically over the last decade,
exposing sensitive personal and business information, disrupting critical operations,
and imposing high costs on the economy.
 Cyber Security is protecting our cyber space (critical infrastructure) from attack,
damage, misuse and economic espionage.
Cyber Security Challenges
Cyberspace has inherent vulnerabilities that cannot be removed:
• Innumerable entry points to internet.
• Assigning attribution: Internet technology makes it relatively easy to misdirect attribution to
other parties.
• Computer Network Defence techniques, tactics and practices largely protect individual
systems and networks rather than critical operations (missions).
• Attack technology outpacing defence technology.
• Nation states, non-state actors, and individuals are at a peer level, all capable of waging
attacks.

Evolution Of Cyber Security


 Viruses (1990s)
Anti-Virus, Firewalls

 Worms (2000s)
Intrusion Detection & Prevention

 Botnets (late 2000s to Current)


DLP, Application-aware Firewalls, SIM

 APT, Insiders (Current)Network Flow Analysis


Cyber Attacks in India

JULY 2016
UNION BANK OF INDIA HEIST
Through a phishing email sent to an employee, hackers accessed the credentials to execute a fund
transfer, swindling Union Bank of India of $171 million, Prompt action helped the bank recover
almost the entire money

MAY 2017
WANNACRYRANSOMWARE
The global ransom ware attack took its toll in India with several thousand computers getting
locked down by ransom-seeking hackers. The attack also impacted systems belonging to the
Andhra Pradesh police and state utilities of West Bengal.

MAY 2017
DATA THEFT AT ZOMATO
The food tech company discovered that data, including names, email Ids and hashed
passwords, of 17 million users was stolen by an ‘ethical’ hacker-who demanded the company
must acknowledge its security vulnerabilities-and put up for sale on the Dark Web.
Financial and Insurance
Frequency 998 incidents, 471 with confirmed data disclosure
Top 3 patterns
1. Denial of Services,
2. Web Application Attacks and
3. Payment Card skimming
Represent 88 % of all security incidents within financial services

Threat actors 94% External, 6 % Internal, <1% Partner (all incidents)

Actor Motives 96% Financials, 1% Espionage (all incidents)

Data Compromised
71% Credentials, 12 % Payment, 9% Personal

Summary: DoS attacks were the most common incident type. Confirmed data breaches
were often associated with banking Trojans stealing and reusing customer passwords, along
with ATM skimming operations
Cyber Threats and Sources
Sources
a) Nation States b) Cyber Criminal Organisations
c) Terrorists, DTOs, etc., d) Hackers / Hacktivists
Threats
 Malware – Malicious software to disrupt computers.
 Viruses, worms, etc.
 Theft of Intellectual Property or Data.
 Hactivism – Cyber protests that are socially or politically motivated.
 Mobile Devices and applications and their associated Cyber Attacks.
 Social Engineering – Entice Users to click on malicious links.
 Spear Phishing – Deceptive Communications (e-mails, texts, tweets)
 Domain Name System (DNS) Attacks.
 Router Security – Border Gateway Protocol (BGP) Hijacking.
 Denial of Service (DoS) – blocking access to websites.
 Others.
Bottom line – easier to be a Bad Guy and volume of threats is
Growing
Hardware Cyber Security Concerns
Most equipment and technology for setting up Cyber Security infrastructure in India are
currently procured from global sources. These systems are vulnerable to cyber threats just
like any other connected system.

There are various types of hardware attacks which includes the following:
• Manufacturing backdoors may be created for malware or other penetrative purposes.
Backdoors may be embedded in radiofrequency identification (RFID) chips and memories.
• Unauthorized access of protected memory
• Inclusion of faults for causing the interruption in the normal behaviour of the equipment.
• Hardware tampering by performing various invasive operations
• Through insertion of hidden methods, the normal authentication mechanism of the systems
may be bypassed.
Above hardware attacks may pertain to various devices
or systems like:

• Network systems
• Authentication tokens and systems
• Banking systems
• Surveillance systems
• Industrial control systems
• Communication infrastructure devices

Trends, Challenges and Threats in 2018


1. AI and machine learning can boost cyber defences

• As artificial intelligence and machine learning gathers pace, and starts to impact more and
more industries, it’s sure to play a bigger role in cyber security.
• Because the battle with cyber criminals moves so quickly, machine learning models that can
predict and accurately identify attacks swiftly could be a real boon for InfoSec professionals.
• These models need to be trained and honed. However, there is also a risk that AI and
machine learning may be exploited by attackers.

2. Be proactive about ransom ware


• Ransom ware has been a growing threat for the last few years, but it continues to claim high
profile victims.
• It’s not yet clear what everyone learned from the WannaCry Ransom ware attacks,
highlighted the need to back up regularly, keep patching and updating systems, and
strengthen your real-time defences. If organizations took these simple steps, we could
dramatically reduce the impact of ransom ware.

3. Handling data breaches gracefully


• It may prove impossible to eradicate data breaches completely, but every organization has
the power to lessen the blow by handling the aftermath correctly.
• Equifax gave us a master class in how not to handle a data breach earlier this year. By
delaying disclosure, misdirecting potential victims, and failing to patch a known
vulnerability, one can make a instructive for others in the year ahead.
4. The IoT is a weak link
• We’re rolling out more and more sensor-packed, internet connected devices, but the
Internet of Things remains a major weak point for defences.
• All too often these devices lack basic security features, or they aren’t properly configured
and rely upon default passwords that can give attackers easy access.
• This in turn is giving rise to botnets, which can be used for volumetric attacks, to exfiltrate
stolen data, to identify further vulnerabilities, or for brute force attacks. We need to properly
secure the IoT or it will continue to be a big issue in 2018.
5. There’s still a skills shortage
• The dearth of skilled cyber security professionals continues to be a major problem for many
organizations.
• Even with average InfoSec salaries soaring, there are thousands of vacant positions.
• This is leading many companies to engage external cyber security services and virtual
CISOs. We expect to see more outsourcing as employers try to find a way to fill the skills
gap.

6. Developing a common language


• While the spectre of multiple threats looms, there are also positive developments in the
cyber security realm, not least the creation and adoption of things like NIST’s Cyber security
Framework.
• As more organizations and cyber security experts come together to develop a common
language, our collective defences grow stronger.

7. Patching and application testing


• It’s not shiny or new or exciting, but it should still be top of mind. The number of data
breaches in 2017 that were made possible by known vulnerabilities and a sluggish approach
to patching is horrifying. It’s not enough to identify problems – you must act.
• Application testing falls into the same bucket, in that it’s too often ignored.
• If you don’t test your security, then you don’t know how secure your application is.
• If everyone put a fresh effort into patching and app testing in the coming year, we would see
a dramatic drop in data breaches

Cyber Security HR Requirements


Challenge
– Acute Shortage of Resource persons
– Inadequate research in academia
• Trustworthy System Design: Multidisciplinary Field
1. Computer Science
2. Electronics and Computational System Engineering
3. Software Engineering
4. Information Technology

• Such courses currently not offered in India


– Courses can be developed
– Offered over NKN in MOOC model
Human Resource Development

Specialists in Trustworthy Information Systems Engineering


• Build Curriculum at UG/PG/PhD Levels
• Courses should be offered in three tracks

Systems Area
• Focus on Attacks from within the system boundary with an emphasis on platform,
operating systems, and secure system development.

Networks Area
• Focus on protecting information assets from network-based intrusion and from
attacks that are primarily focused on remote exploitation of protected systems.
• Cyber security approaches that are effective in this paradigm should be explored in
depth and various defensive approaches should be investigated.

Analysis Area
• Focus on both the systems and networks tracks. Analysis courses study low-level
behaviour, code, and data to understand anomalies and develop the ability to identify
unexpected patterns and malicious events.
Recommendations on Cybersecurity
Framework for States
P-P-P Model for Cyber security
• State Cyber security Framework shall be envisaged in P-P-P Model.
• Government shall partner with the private sector and the academia to strengthen cyber
security posture of the state.

Information Security Policy and Practices


• IS Policies & practices shall be mandated at govt. functionaries & its service providers.
• Security Audit adhering to international standards applicable for all govt. websites,
applications before hosting and publishing.
• Govt. to ensure ISPs operating in the state shall deploy cyber security plans in line with
State cyber security policy.

State Computer Emergency Response Team


Establishment of the State CERT to operate in conjunction ICERT and coordinate with
NCIIPC.
• Cyber security drills shall be carried out under the supervision of I-CERT.

Identity Theft and Security Incident Prevention


State cyber security framework to support strategy and implementation mechanisms to
prevent digital impersonation and identity theft and the security incidents.

Assurance Framework
Framework of assurance shall be established to provide guidance on security certifications,
qualification criteria and prescribe security audits of govt. ICT systems, projects and
applications.

Security Budget
Govt. agencies implementing IT Projects shall allocate appropriate budget towards
compliance with the security requirement of IT Act 2000 and State cyber security policy,
ISMS, security solution procurement and trainings.

Information Sharing
State Information Sharing Network for CII shall be established.

Capacity Building and Awareness


Govt. shall take appropriate steps for enhancing awareness of citizens and small business for
cyber security
• Cyber security Capacity building and training for professional, extending ISEA program,
introducing curricula academia and organizing conferences
• Strengthening LEAs through training, establishment of forensics labs, etc.
By:
Raj Shree
Sucharita Sarkar
Siddhartha Bhattacharjee

Common questions

Powered by AI

The three pillars of a robust cyber security strategy are people, processes, and technology. People are critical as every employee needs to be aware of their role in preventing cyber threats, and technical cyber security staff need to keep up with the latest skills to effectively respond to cyber attacks . Processes define how the organization’s activities mitigate risks, requiring continuous review to adapt to rapidly changing cyber threats . Technology involves deploying controls to prevent or reduce cyber risks based on risk assessment . Together, these pillars help organizations defend against organized attacks and internal threats by creating a comprehensive defense mechanism.

To mitigate the risk of ransomware attacks, organizations should regularly back up data, keep systems and applications patched and updated, and strengthen real-time defenses . Proactive measures include educating employees about phishing risks, employing robust email filtering systems, and conducting regular security assessments to identify new threats and vulnerabilities . These strategies help in reducing the likelihood and impact of ransomware incidents.

Artificial intelligence and machine learning enhance cyber defenses by quickly predicting and identifying attacks, providing InfoSec professionals with advanced tools to respond to threats . These models, however, must be trained and refined constantly. A risk associated with AI is its potential exploitation by attackers, who can use the technology to carry out more sophisticated attacks . Thus, while AI has benefits in bolstering defenses, organizations must remain vigilant about its misuse.

Leadership commitment is essential because it drives the establishment, implementation, and maintenance of effective cyber security processes. Without the support of top management, it is challenging to prioritize cyber security, make necessary investments in technology and skills, and allocate adequate resources . This commitment also helps in overcoming barriers to change and fostering a culture of security throughout the organization.

Business continuity planning helps organizations to be prepared for disruptions by identifying potential threats early on and analyzing their impact on day-to-day operations . By doing so, organizations can ensure they have measures in place to maintain essential functions, even in the event of a cyber attack, thereby minimizing downtime and operational interruptions.

Organizations suffering cyber attacks can face significant financial, reputational, and operational damage, including asset loss, regulatory fines, litigation, and costly remediation efforts . To better handle these consequences, organizations can establish contingency plans, educate staff on incident response procedures, secure cyber insurance, and maintain clear communication with stakeholders during incidents to retain trust and credibility.

The proliferation of IoT devices creates vulnerabilities due to a lack of basic security features, improper configurations, and reliance on default passwords, making them targets for botnets and other attacks . To secure IoT devices, organizations should ensure robust configurations, regular updates and patches, utilize strong passwords, implement network segmentation, and conduct security assessments to identify and address vulnerabilities.

The discrepancy arises because solution providers often design applications claiming full compatibility with existing IT infrastructure, but technology gaps persist due to proprietary code retained by developers for competitive advantage . These gaps in technology compatibility can create unforeseen vulnerabilities that cyber criminals might exploit, demonstrating that even slight misalignments or integrations between technologies can compromise overall security.

Cyber criminals exploit vulnerabilities in web applications and networks primarily through automated attacks which target unpatched systems and applications. These vulnerabilities may stem from outdated software, unaddressed security gaps in web applications, and inadequate network security configurations . Fixing these vulnerabilities involves regular security audits and updates to ward off potential exploits.

The skills shortage persists because the demand for cybersecurity expertise outpaces the supply of qualified professionals, even as salaries rise to attract talent . Addressing this gap requires investment in education and training, such as developing comprehensive cyber security curricula at undergraduate and postgraduate levels, promoting interdisciplinary approaches, and leveraging online learning platforms to scale up the training of new professionals .

Cybersecurity 
Cyber security consists of technologies, processes and controls designed to protect systems, 
networks and dat
Cyber-attacks are becoming increasingly sophisticated: 
Cyber-attacks have become more sophisticated with attackers using an
 End-user education 
Human error remains  (https://www.itgovernance.co.uk/staff-awareness)the leading cause of data breaches
Outdated software 
The use of outdated (unpatched) software (e.g. Microsoft XP) opens up opportunities for 
criminal hackers
Defining the term “Cyber”: 
  Cyberspace is the connected Internet Ecosystem. 
 Trends Exposing critical infrastructure
Cyber Security Challenges 
 
Cyberspace has inherent vulnerabilities that cannot be removed: 
• Innumerable entry points to i
Cyber Attacks in India  
  
 
JULY 2016 
UNION BANK OF INDIA HEIST  
Through a phishing email sent to an employee, hackers ac
Financial and Insurance 
 
Frequency 998 incidents, 471 with confirmed data disclosure 
Top 3 patterns  
1. Denial of Service
Cyber Threats and Sources 
Sources 
a) Nation States b) Cyber Criminal Organisations 
c) Terrorists, DTOs, etc., d) Hackers /

You might also like