ST. PETERSBURG, Fla.—Just as cyber-threats are changing and evolving into new types of attacks, CUs will also need to change how they think about defending member data.
That includes addressing legacy system issues and problems in server misconfiguration.
That was the message delivered by Gene Fredriksen, chief information security officer for PSCU, during the company’s webinar on Intelligence Driven Information Security Analytics.
“Look at how threats have been morphing,” said Fredriksen, adding that credit union security practices are not changing as quickly.
Simply building a strong perimeter with a firewall should not help CIOs to sleep well at night, according to Fredriksen. “You can’t rely on that. If the crooks want in, they will get in. Eighty-five percent of breaches go undetected and each costs an average of $9 million.”
Crooks All In
With cyber-thieves leaning on social engineering or phishing attacks, system and application vulnerabilities and malware, Fredriksen said crooks are utilizing all their tools.
“Just about every method is being used, and at the same time they are developing new techniques,” he said.
Although Frederickson pointed to some analyses that suggest as many as 69 new threats are being generated every minute minute, he said there remain common factors that lead to data breaches.
“In 2015, 44% of known breaches came from known vulnerabilities in two- to four-year-old legacy systems,” he said. “We have to address legacy systems. There are systems on our network which we either don’t patch or can’t patch. We need to get rid of these.”
Server misconfiguration has been a top vulnerability.
“I believe servers should be scanned when they are built and before they go into production,” said Fredriksen. “We can’t assume no new vulnerabilities have been introduced before they go into production.”
Fredriksen also cautioned that the so-called Internet of Things, in which all devices and appliances are connected, is opening doors for crooks that were not there before businesses began connecting more things to the web. He described how hackers recently proved they can access air conditioning units inside server rooms. And if the cooling unit is connected to the data system’s backbone, which it often is, then the thieves have a way in.
“Now they have a foothold into your network,” he said.
Perhaps most important, Fredriksen said, is that credit unions have to not only think about how to keep the bad guys out, but also monitor systems to see if they are already inside.
“These crooks, these organized crime rings, they will scan your systems for months until they gather enough information to determine the best way in,” Fredriksen said.
Trojan Opens The Door
Fredriksen explained that once crooks find the right method of entry, they send in a Trojan that then opens the door. He said the thieves will then gather more data, the Trojan will send out for additional code, all the time carefully hiding itself. Eventually the crooks will be ready to take control of their target, filtering out personal data.
“So instead of just focusing just on the perimeter and stopping what might come in, focus on monitoring what goes on inside your own network,” Fredriksen said. “Watch closely what goes out of our system. If you don’t watch that you will never know if thieves are inside your system, you will never have any advance notice before a breach occurs.”
