Showing posts with label National Cybersecurity Awareness Month. Show all posts
Showing posts with label National Cybersecurity Awareness Month. Show all posts

Monday, October 7, 2019

FBI: October Is National Cybersecurity Awareness Month


The FBI released the below information:
Internet-enabled crimes and cyber intrusions are becoming increasingly sophisticated and preventing them requires each and every user of a connected device to be aware and on guard.
“It’s no longer enough to be on the lookout for something in your inbox that appears suspicious,” said FBI Cyber Division Assistant Director Matt Gorham. “As criminals have grown savvier and their efforts more targeted, individuals and organizations need to scrutinize messages and requests that appear legitimate.”
Some of the most common and damaging Internet-enabled crimes begin with an employee clicking a link in an email that appears to be from a colleague, following the instructions in a message that looks like it came from a supervisor, or opening an account link or invoice that seems to be from a trusted vendor.
“These routine actions can be what exposes a computer or an entire network to a ransomware attack, data breach, or another crime,” said Gorham. “As we mark National Cybersecurity Awareness Month, our hope is to focus attention on the efforts required to safeguard individual computers and accounts and secure and protect critical data and infrastructure.”
Now in its 16th year, National Cybersecurity Awareness Month is hosted every October by the Department of Homeland Security and the National Cyber Security Alliance. Multiple agencies and organizations, including the FBI, collaborate to raise awareness about cybersecurity and stress the collective effort needed to stop cyber intrusions and online thefts and scams.
“Today’s cyber threat is bigger than any one government agency—frankly, bigger than government itself,” FBI Director Christopher Wray said at a cybersecurity conference in March. “But I think no agency brings the same combination of scope and scale, experience, tools, and relationships that the FBI has.”
The FBI works in close coordination with the private sector as well as with state, local, and international partners to understand and anticipate cyber threats and pursue cyber criminals.
During National Cybersecurity Awareness Month, the FBI joins in asking every user of a connected device to Own IT. Secure IT. Protect IT.
“We look to the public and to organizations to engage by understanding these threats, taking preventive action, and reporting cyber crimes when they occur,” said Gorham.
Cyber Safety Tips
All computer users should keep systems and software up to date and use a good anti-virus program. These programs are not foolproof, however, and computer users themselves often help cybercriminals get through these safeguards. To avoid inadvertently downloading malicious code that can harm your network or giving a criminal money or valuable information, the FBI recommends these tips:
  • Examine the email address and URLs in all correspondence. Scammers often mimic a legitimate site or email address by using a slight variation in spelling.
  • If an unsolicited text message or email asks you to update, check, or verify your account information, do not follow the link provided in the message itself or call the phone numbers provided in the message. Go to the company’s website to log into your account or call the phone number listed on the official website to see if something does in fact need your attention.
  • Do not open any attachments unless you are expecting the file, document, or invoice and have verified the sender’s email address.
  • Carefully scrutinize all electronic requests for a payment or transfer of funds.
  • Be extra suspicious of any message that urges immediate action.
  • Confirm requests for wire transfers or payment in person or over the phone as part of a two-factor authentication process. Do not verify these requests using the phone number listed in the request for payment.
Own IT
Understand Your Digital Profile
Internet-based devices are present in every aspect of our lives: at home, school, work, and on the go. Constant connection provides opportunities for innovation and modernization, but also presents opportunities for potential cybersecurity threats that can compromise your most important personal information. Understand the devices and applications you use every day to help keep you and your information safe and secure.
Secure IT
Secure Your Digital Profile
Cybercriminals are very good at getting personal information from unsuspecting victims, and the methods are getting more sophisticated as technology evolves. Protect against cyber threats by learning about security features available on the equipment and software you use. Apply additional layers of security to your devices—like multi-factor authentication—to better protect your personal information.
Protect IT
Maintain Your Digital Profile
Every click, share, send, and post you make creates a digital trail that can be exploited by cybercriminals. To protect yourself from becoming a victim, you must understand, secure, and maintain your digital profile. Be familiar with and routinely check privacy settings to help protect your privacy and limit Internet-enabled crimes.

Monday, October 2, 2017

National Cybersecurity Awareness Month: The U.S. Navy Says The Cyber Threat Is Real


The Office of the Deputy Chief of Naval Operations for Information Warfare released the below information:

WASHINGTON (NNS) -- Throughout National Cybersecurity Awareness Month this October, and in subsequent articles, the Office of the Deputy Chief of Naval Operations for Information Warfare (N2N6) will describe the things you can do, at home and at work, to protect yourself and the Navy from cyber threats.

Few people today need to be convinced that our networks, computers and smart phones are at risk of compromise. We've grown accustomed to the news of computer hacks.

The confidential information of 143 million Americans was potentially compromised in the recent Equifax breech. In May 2017, the WannaCry ransomware attack infected 150,000-plus computers in over 150 countries within the first 24 hours.

If you keep up with the news, you know of Russia's election-focused data thefts and disclosures. More distant high profile attacks, such as the 2015 Office of Personnel Management hack that resulted in the theft of 21.5 million personnel records, are memorable because they affected many of us in the Navy.

From these example hacks, you can safely assume anything connected to the internet is at risk.

In fact, any electronic device for storing and processing data - a computer - is at risk, regardless of whether it's connected to the internet or whether it looks like the desktop or laptop computers we use at home and at work.

Disconnected systems are also vulnerable as attackers have employed innovative tactics to reach systems not connected to the internet. For example, thumb drives loaded with damaging software were picked up by unsuspecting technicians and used to spread the Stuxnet virus to centrifuges in an underground Iranian nuclear research facility.

Although the compromise of Iran's nuclear facility was well publicized, less well known are other news reports that also demonstrate physical systems controlled by computers (control systems) are at risk.

In 2016, hackers who were thought to be from Russia compromised a Ukrainian power company, knocking out power to part of Kiev for over an hour. A 2015 breech of a Ukrainian energy company, which resulted in a power outage to 80,000 customers, may have been related to the 2016 attack. Closer to home, in 2016 "...the Justice Department claimed Iran had attacked U.S. infrastructure online, by infiltrating the computerized controls of a small dam 25 miles north of New York City."

The control systems that manage the Navy's critical infrastructure and other services at Navy bases and facilities are commercial products that have known weaknesses. Like the Ukrainian control systems and the systems controlling the New York dam, Navy control systems and networks used by operational forces could also be at risk of compromise.

During June 2017, a commercial ship off the Russian coast discovered its GPS navigation system erroneously located the ship at an airport 32 kilometers inland. At least 20 other ships in the area had similar problems with their Automatic Identification System, which U.S. Navy ships also use. "Experts think this is the first documented use of GPS misdirection - a spoofing attack that has long been warned of but never seen in the wild."

Chief of Naval Operations (CNO) Admiral John Richardson sums up the current cyber threat environment, "The threats reach well beyond what you would consider a traditional computer or information technology network into the control systems and indeed almost every aspect of our lives and of our Navy mission."

These cyber threats can come from nations with highly sophisticated cyber programs, countries with lesser technical capabilities but possibly more disruptive intent, ideologically motivated hackers or extremists and/or insiders within our organizations, with a variety of motivations. Even cyber criminals threaten the Navy because they sell malicious software to state and non-state actors, thereby increasing the number of potential threat actors.

Vigilance and ensuring a robust defense-in-depth framework that incorporates people, processes and technology to assure our networks are safe is key.

The threat will continue to increase as adversaries look for potential vulnerabilities and increase their level of sophistication for cyber-attacks. In Congressional testimony, former Director of National Intelligence James Clapper described the threat saying, "Cyber threats to US national and economic security are increasing in frequency, scale, sophistication and severity of impact. The ranges of cyber threat actors, methods of attack, targeted systems and victims are also expanding."

But you can make a difference.

By adhering to cybersecurity policies, directives and best practices you can help keep the Navy secure and also protect yourself and your families while online, outside of work. It's an all hands effort, like damage control on a ship.

Knowing adversaries are actively seeking to penetrate our systems, steal our data and disrupt operations should help you understand the CNO's perspective: "Wherever you are, whatever system you're operating, every time you log in, you are in the cyber battlespace."

Be vigilant. Be safe.

Note: You can click on the above illustration to enlarge.  

Tuesday, October 12, 2010

My On Crime & Security Column: Stop. Think. Connect, October is National Cybersecurity Awareness Month

The online small business magazine Businessknowhow.com published my On Crime & Security column today.

My column covered National Cybersecurity Awareness Month and a major FBI roll up of an international cybercrime operation.

You can read my column via the below link:

http://www.businessknowhow.com/security/cybersecurity.htm