This website uses cookies to store information on your computer. Some of these cookies are used for visitor analysis, others are essential to making our site function properly and improve the user experience. By using this site, you consent to the placement of these cookies. Click Accept to consent and dismiss this message or Deny to leave this website. Read our Privacy Statement for more.
Home   |   Contact Us   |   Sign In   |   Register
Article Library
Blog Home All Blogs

Mitigating Risk by Segmenting and Separating Data – Network Security Architecture Explained

Posted By USFN, Thursday, February 15, 2024

By Alexander Craddock and NateBraun

NetDirector

USFN Associate Member

 

With the latest generation of phishing and social engineering assisted by the newest AI technologies, information security is more important than ever for small businesses. According to the Acronis Cyberthreats Report, H2 2023, AI-enhanced phishing attacks affected over 90% of organizations surveyed and resulted in a 222% increase in email attacks in 2023 when compared to the same time period in 2022.

 

This risk is especially great for any business dealing in PII (Personally Identifiable Information), financial data, or legal – for the default servicing industry, this is the triple threat that makes security a high priority across the organization. One of the best strategies to ensure data security is data segregation.

 

The goal is to ensure that only the individuals who are authorized to view certain data sets have access to them – and that while that access is secure, it remains easy and convenient for the team members who need the data to do their job.

 

It’s easiest to envision a complete data segregation strategy by visualizing the way a layered, segmented security protocol works on physical documents. The familiar layers of security are present for most hard copies of documents in the physical world. An example:

 

·         a property gateway (potentially with a security guard) exists, verifying access to the property.

·         the building entrance uses a badge reader or biometric scan, and a secondary badge entrance would provide further segregated access to a particular wing.

·         within the wing, even fewer key cards would grant access to certain hallways or individual rooms.

·         a certain key is required to unlock a particular cabinet full of sensitive files.

 

In this example, there are up to six layers of security present between the “outside world” and the sensitive information, each of which limits access in steps. Could an outside unknown malicious actor get access to a document in the file cabinet (without the use of “Hollywood writers”)? The short answer is no. In this scenario, the only people who could do harm are a very limited number of internal employees, restricted by the many layers of access and significantly narrowing down potential threats.

 

What if one of those layers is compromised, like the lock on the cabinet? Even with one or two less layers of security, the documents themselves are still secure from outside access. Risk probability decreases exponentially after each layer of security in place.

 

An equivalent layered segregation process is the best approach to ensure a secure environment for digital data. For example:

 

·         A VPN gateway functions as the property access, with as many as eight factors of verification in this “frontline” defense: a username and password, with multifactor authentication (MFA) tokens matching the PC/Device, IP Address/location, a one-time PIN from Authenticator, mobile device registration for authenticating devices, and FaceID on the authenticated device.

·         Firewall/security rules work as the building key card: after VPN connection is established, the VPN client with an Endpoint Security Profile can determine what access is allowed based on the user’s account and group membership; denying or granting specific IP/port access.

·         Application authentication represents key card access to specific rooms and hallways, and is separately managed in a similar way to the VPN (factors include Internal WebUIs, File Shares, RDP, SSH, and a different username/password requiring a new MFA)

·         Finally, the file cabinet lock is represented by specific application access. After authentication in the previous steps, what data is available to that authenticated user in the specific application? This is the final step to ensuring the right data is readily available to users who need it, and can also determine read/write permissions, modification availability, etc.

 

Final questions to consider around data segregation include:

Q: How many layers does our company need?

A: One layer, even with MFA, is no longer enough. Companies should have at minimum two layers each with their own multifactor authentication before classified/protected information can be reached.

Q: Which technologies are most important to secure?

A: Endpoint security for physical devices (laptops, phones, etc.) through which employees can access classified information is most important. Authentication and file transfers for Unified Messaging technologies (email, IM, phone, online conference, voicemail) is second most important. Web based interfaces, applications, and connections would be third on the list. These are the big three that absolutely need their own layers of security, including MFA.

 

Copyright © 2024 USFN

USFNews - Feb. 21

Tags:  #Briefing  #Cybersecurity 

PermalinkComments (0)
 

Key Takeaways and Practical Tips from USFN’s Recent Briefing: Cyberattacks & How to Respond

Posted By USFN, Thursday, February 15, 2024

by Tina Crivello

Brock & Scott, PLLC *

USFN Member (CT, NC, RI, AL, FL, GA, KY, MA, MD, ME, MI, NH, NJ, OH, PA, SC, TN, VA, VT)

 

USFN kicked off the new year with a Briefing on one of the industry’s most timely and critical topics for today and the foreseeable future – Cyberattacks & How to Respond. On January 23, a panel of industry leaders, including attorneys, fintech leaders, and insurance experts, provided attendees key insight into the state of cyberattacks and what we can do now to prevent and prepare.

 

Cyberattack prevention as the first line of defense should be at the forefront of everyone’s efforts. Ronny Loew, ProCirrus Technologies, Inc., and Jan Duke, a360inc, shared the top elements of a prevention plan which includes a three-prong approach of user education, using application controls, and increasing awareness throughout an organization. Loew reminded attendees, “Eighty-two percent of the issues that are occurring are due to the human element.” Security training and simple, yet effective, controls such as multifactor authentication can help prevent many attacks. Just as important is email security, patching and updating of anything connected to the network or internet, and cybersecurity services such as endpoint monitoring. Duke suggested to ensure that phishing training campaigns in organizations are relevant to users, “so it’s something that really will try to appeal” to employees. She encourages organizations to have town hall meetings to discuss the dangers and “make it real” to employees, so they hear it from the top of how important this is.

 

Wendy Lee, of Sagent, covered highlights of communication plans once an incident has unfortunately occurred. She stressed the importance of pre-planning a crisis communication plan and how the onslaught of communication will be handled. Most critical is understanding federal law, state breach notification laws, contractual obligations, as well as executive buy-in and control. Lee shared a story about a recent settlement related to failure to disclose timely to victims of a cyberattack and stressed how critical it is to meet the notification requirements. Federal requirements, such as the Securities and Exchange Commission’s (SEC) four-day time limit, may not directly impact your business, but it could impact a company you do business with if they are a publicly traded company. Customers may require reporting in one day due to the SEC’s requirement for reporting events “that could have a material impact.” Evaluating materiality in a 24-hour window may be almost impossible, which means potentially reporting an incident whether it’s known yet if there is a material impact. Big companies today are making the required filing regardless of potential material impact to ensure adherence to the law.

 

Key points to include in a crisis communication plan include:

·         Understanding who to notify – victims, state Attorneys General, or other government entities

·         Knowing when to notify the above

·         Adhering to specific requirements about the notice contents

·         Following any state specific form of requirement – in writing, electronic, or by phone

 

Perhaps even before, or at minimum at the same time, as sending any other notices, Harrison Tropp of SGP Advisors, recommended immediately notifying your cyber insurance carrier or broker. Carriers have designated claims hotlines through which you are assigned an adjuster who will begin assembling the claim team. This may include the insurance adjuster and broker, a legal expert, a data security firm, and law enforcement. They will help a company figure out next steps. In cases of ransomware, this will almost always include immediately paying the ransom so companies can regain access to systems as expeditiously as possible. Tropp notes it’s critical to have draft communication ready to go should an event happen. It is also important to have an action plan in place and test it regularly. He also highlighted how the underwriting process, “especially in the default space has gotten increasingly more difficult.” During the underwriting process, insurance companies may run certain tests on a company’s systems and if they don’t meet the requirements they will refuse to underwrite.

 

Brian Nicholas, Esq., McCalla Raymer Leibert, Pierce, LLC, stressed the importance of running a test of a company’s action plan and key questions to ask. First response type questions may include, “How do you know if the attack is real?” and “Who should you contact first?,” among others. Second to answering those questions is knowing what your cyber insurance policy covers, how it helps, and how to activate coverage. In today’s online world, Nicholas recommends having a hard copy of your policy and response plan available to key members of your organization. Finally, Nicholas posed the question of how we reduce the risk of Personally Identifiable Information (PII) exposure. “The biggest risk is loss of that confidential information.” Understanding how companies keep or expunge that data, especially when considering, for many, adhering to state bar guidelines.

 

Nate Braun, of NetDirector, provided pointers on risk reduction with data segregation and segmentation. Network segmentation, which is the grouping and isolation of information systems by function and classification through use of controls, virtual environments, and disk encryption, are just a few steps an organization can take to protect data. Braun cleverly compared network security to being akin to physical security and showed how the multiple check points needed to access a physical file in a cabinet are analogous to the multifactor authentication steps needed when accessing data on a network.

 

The briefing was concluded by moderator Elizabeth DeSilva, Esq., and Brian Nicholas discussing what it really means to run a “table-top” drill. Nicholas explained it is just like your disaster recovery drills, where you run through the steps as if it had been a real event. It’s important to throw a few “curveballs” into the drill as well. What happens if your CIO is on vacation? If your email is down, do you have a secondary system or plan in place to communicate with employees and clients?

 

USFN is committed to helping the industry combat cybersecurity issues and will continue to bring members together to learn and share experiences and expertise surrounding this critical topic.

 

In the meantime, bookmark USFNevents.org and plan to join us for these upcoming virtual programs: 

  • March 12: USFN Briefing: Show Me the Judicial Foreclosure
  • May 7: USFNgage: Artificial Intelligence

 

Copyright © 2024 USFN

USFNews - Feb. 21

 

* Denotes Member is a 2023 USFN Award of Excellence Recipient

Tags:  #Briefing  #Cybersecurity 

PermalinkComments (0)
 
Membership Software Powered by YourMembership  ::  Legal