Talk to us Risks to Watch

New Work Environment demands Stronger IT Security

Overview

If we look a couple of years back, the concept of Work From Home (WFH) was limited to freelancers and a few working professionals. Over the passage of time, the sudden pandemic brought massive changes in the  enterprise work culture. Due to biological security, many organizations asked their employees to stay at home and thus Work From Home (WFH) became a familiar term for full-time working professionals. 

Situations have improved and now employees are back to the office gradually. However, there has been hybridization between ‘working from home’ and ‘working from office’. According to exclusive and latest CNBC research, over 70% of global employees are presently working remotely at least once a week. As a result, organizations are modifying their IT infrastructure so that flexibility of location cannot create any hindrance among the workforce. This has given birth to a new model – Work From Anywhere (WFA).

Some Challenges

The top three objectives of any business organization (both MNC & SME) are: 

  • Return on Investment (ROI)
  • Higher Revenue
  • Business Continuity

To ensure all the above in WFA conditions, organizations are revamping their IT environment, IT security policies, access management of critical data repositories and increasing the frequency of IT audits. Many organizations have considered this necessity as a challenge and banked on third-party service providers to ensure that there is no interruption in the business amid the pandemic. 

However, the circumference of IT risk expanded beyond assessment. Numerous threats have arised at the infrastructure level and hence, organizations necessitated the security of distributed workforce in multiple locations. Among all, the maximum risks lie with the ever-expanding number of privileged identities in the IT network periphery. In both remote and on-prem conditions, privileged accounts are the most vulnerable areas when it comes to data breach threats. Unrecognized third parties, external IT staff, and consultants break through privileged access, intrude on the privacy and compromise confidential business information and misuse it. The dominant threats in WFA conditions are majorly due to:

  • Poor or inadequate access control policies that lead to ambiguity in all the accesses happening in the enterprise IT environment. Malicious actors reap the benefits of this vulnerability and compromise privileged accounts.
  • Absence or inadequate end-user validation mechanism like multi-factor authentication fails to segregate authorized and genuine users from the suspicious ones who are accessing critical systems in the enterprise network time and again.
  • Employees access business-critical applications and systems every day with ‘always-on’ privileges. Risks multiply if there is the absence of an access control framework based only on ‘need-to-know’ and ‘need-to-do’ policies. 

Best Solutions

Protecting data is always the top priority for any enterprise. While adequate security controls are a must round the clock, they are even more important as employees are working in hybrid work conditions. Thus, the challenge of safeguarding enterprise data has intensified. Apart from the basic IT security cautiousness as expected from the workforce, organizations always prefer an all-in-one solution that could address all the WFA challenges under one roof. 

ARCON being a global brand offers best-in-class and feature-rich Privileged Access Management (PAM) and Identity Access Management (IAM) solutions for both remote and on-prem conditions. The access control risks intensify if hundreds of privileged users access the critical databases, systems or applications at different hours for different purposes. Starting from user authorization, elevated access authentication, password vaulting, maintaining workflow matrix, monitoring every privileged session and robust identity governance, ARCON ensures that it safeguards the organizations’ IT landscape from prevailing cyber threats with the robust features of the solutions. Here is a brief overview of the necessary and relevant ones:

ARCON | PAM

ARCON | IAM

It ensures that the privileged passwords are frequently rotated and stored in a vault to prevent any credential misuse It can seamlessly integrate with different authentication repositories for user provisioning and shares their credentials with other integrated cloud/ on-prem applications
This tool restricts, controls and continuously monitors the privileged users in both on-prem and cloud environment by applying the deepest granular level control and multi-factor authentication of the users It simplifies the IT administration by configuring and automating the approval process for privileged users, user groups and service groups; also, the workflow speeds up the process of assigning servers to the privileged users 
It captures every single privileged access log and generates customized reports and audit trails of all privileged activities in the enterprise network periphery It monitors and audits privileged activities in real time to spot any anomaly and it is displayed on live dashboard for both cloud and on-prem environment
This tool offers comprehensive visibility over privileged users by ensuring accountability and adherence to the Compliance standards as applicable  With this, the end-users can manage elevated credentials by automating and rotating as per policy standards; also, it ensures safe synchronization across the network so that there is no service disruption
It reinforces role-based access in the IT environment with “need-to-know” and “need-to-do” policy that is centralized in nature and ensures “Least Privilege” principle It safeguards the confidential business information by offering secured access only via approved and authorized user identities – with this, the identity governance is restored and provisioning/ deprovisioning of the identities is streamlined

Conclusion

According to The Economic Times, almost 64% of organizations from IT, Telecom, Financial services, Utilities sector have agreed upon workplace flexibility policy worldwide. The pandemic is not yet over and thus organizations are not taking chances with their business continuity. Work From Anywhere (WFA) policy has indirectly upgraded organizations’ IT infrastructure to the next level so that business operations remain unaffected in any given situation. After all, it’s better to be safe than sorry!

Business Startups: Are they prone to cyber threats?

Overview

According to The Economic Times survey, more than 39,000 Indian startups sprung up in 2020-21 that have created almost 4,70,000 jobs. Indian nation currently claims to have the third largest startup ecosystem in the world. In fact, in 2020 alone, despite the pandemic situation, the government opened up the space for private players to serve the country on space and satellite projects with funding, teams and structure. This number is expected to rise fast as technology plays a pivotal role to unlock India’s potential in space, aerospace, astrophysics and other emerging areas.

But startups will have to ensure stronger cyber-defenses. Statistics prove that when it comes to cyber risks, the size of an organization is irrelevant. According to Ponemon Institute’s research, 67% startups suffer data breach or any other cyber incident within one year of inception. Adding to this, Forbes has found that phishing and ransomware attacks among startups have risen to almost 300%. 

It precisely points out that cyber criminals are no more concerned about the volume of data, or the size of an organization. 

Where is the concern?

We are dwelling in the era of digitalization. Today, the business startups that are mushrooming across the country require technical prowess to survive the cut-throat competition. In order to stay a step ahead, most of the startups bank on advanced technologies. It is a ripe time for aspiring entrepreneurs to ensure secure IT practices right from the initiation of business. Today, even small businesses are equally at the risk of cyber threats as large enterprises. A preconceived notion that your business is too small to be a target is no more a fact.

Small startups typically have vulnerable IT defences, less cybersecurity awareness, less/ no resources to heep a vigil on cybersecurity and the response is typically slower to any cyber incident. This makes them more vulnerable targets to cyber criminals compared to larger organizations.

Compliance is another challenge! Even the smallest startups have access to a huge customer database that might fall under data regulations. Losing a hefty amount of money in a single stray incident might not only malign the credibility of the startup, but also bankrupt it beyond recovery. Thus, a startup becomes a soft target for hackers as chances of fight-back or other preventive consequences are too bleak.

Why is Cyber Resilience necessary?

Small startups need to be active, aware and knowledgeable about emerging threat patterns and how to address them. Today, most of the startups are directly or indirectly associated with ecommerce platforms.

The post pandemic era has witnessed a whooping demand for digital payment modes in every aspect of our lives. Technology and ecommerce startups make and receive a high volume of digital payments along with huge storage and processing of data records. Thus, startups, even with small IT infrastructure, become prone to vulnerabilities like weak access controls, authentication, and lack of monitoring of insider and third-party IT activities. 

There have been instances where identity and access management vulnerabilities have led to data breaches. For startups, a single similar incident might work as a barrier to the establishment of brand value and reputation. 

In this backdrop, a robust identity and access management practice is highly imperative for business startups as it allows the administrators to ensure authorized access for every login. A robust identity and access management system can ensure that each and every access to data resources is safe and secure.

In addition, some generic cautiousness can ensure no unwanted interruption in the business process for new ventures. These include adhering to the compliance standards, incorporating robust password management policy, and appointing a dedicated team (even if small, maybe 2 / 3 people) for regular end to end monitoring. 

Conclusion

Business Startups are the future of any nation. Hence, if it remains vulnerable to IT threats, then the nation’s growing economy can be marred by uncertainty. Numerous threat patterns target small businesses every now and then. The best way to prevent these threats is to have a comprehensive set of IT security tools in place, and to utilize Security Awareness Training to ensure that the users are aware of the threat patterns. This way, business startups can meet their revenue goals and contribute to the GDP.

How does ARCON PAM ensure PCI-DSS compliance?

Overview 

27 long years and still going strong with compliance standards! 

PCI-DSS (Payment Card Industry Data Security Standard) is a global standard that brings together all the stakeholders of the payment industry to adopt a set of data security standards and resources for safe payments across the world.

Against the backdrop of increasing digitalization and sophisticated cyber threats, organizations implement robust IT security measures to prevent unauthorized intrusions. The usage of digital payment modes and virtual money transfers has risen uncontrollably. Hence, PCI-DSS (Payment Card Industry Data Security Standards) compliance has become too crucial to ensure security of critical financial information. The main objective of PCI-DSS is to protect the payment card environment and prevent rampant security breaches happening in this digitization era.

The Mandates of PCI-DSS

The inception of PCI-DSS happened way back in 2004. As payment frauds became exorbitant, the credit card industry (initially credit card, later on debit card was also added) leaders convened to set up some common security standards across the globe. With this, the founding members of PCI-DSS – American Express, Discover Financial Services, JCB International, Mastercard and Visa announced the first version of PCI-DSS in December 2004. This compliance turned out to be mandatory for all merchants accepting credit cards and other payment processing organizations. Even today it is applicable to all organizations that store, process and transmit sensitive cardholder data such as:

  • Manufacturers (PCI PTS)
  • Payment Card Issuing Banks & Merchants
  • For vendors making payment application and store, process card holder data (PCI PA DSS)
  • Asset Management companies

The PCI security standards expect organizations to follow or maintain the below:

  • Maintain a secured network system
  • Ensure the security of card holders’ data
  • Implement stringent access management policy
  • Maintain vulnerability management
  • Frequent monitoring of the activities in the enterprise network

Incidents of Non-Compliance and Penalties

If adequate safeguards are lacking in an organization to ensure PCI-DSS compliance, then the sensitive card payment data is at grave risk, particularly if there is no system that can handle sensitive data. Card processors will be prone to data breaches even as noncompliance to industry standards will result in hefty fines. Some common PCI-DSS noncompliance examples include:

  • Large Music Group, USA: A popular music group based out of the USA was targeted in late 2020 where payment card information (card number), CVV number, and expiry date were exposed—each and every detail was exposed. After a hair-split investigation, it was found that the organization’s focus was completely on the supply chain, due to which customer data security was given less importance while purchases were made. This forced the organization to cough up hefty penalties.
  • Million Dollar Data Breach in a Software Company: Almost 38 million customers’ data  whose login information was stolen, among whom 3 million had their credit card records as well. The company lost its credibility in the market.
  • Big Payment Systems Loses Processing Privileges: In this rare instance, a USA-based payment systems company processed payment card transactions for more than 175,000 merchants whose details were compromised. The organization was eventually banned for 14 months following the revelation.
  • Data Breach in Cloth Retailer: One of the popular USA clothing retailers fell prey to the cyber criminals who stole credit card information from thousands of customers who used their card in the shop for payment. 

The monetary fines of PCI-DSS non-compliance can range from $5,000 to $100,000 per month, depending on the factors like business volume, vastness of the organization and the degree of non-compliance.

Role of Privileged Access Management in PCI-DSS Compliance

Payment card environment comprises highly sensitive information like ten-digit cards number, CVV number, card validity date, cardholders’ names among many other forms of confidential data. There are hundreds or maybe thousands of IT users accessing this information from time to time, that is, processing and storing data. During this practice, the information might fall in the wrong hands who might compromise the information with malicious intention such as illegal financial benefits or damaging the brand credibility. 

In this backdrop, it is critical to have a seamless control over data where the IT teams need to have complete knowledge of who is accessing the processed card data – when and for what purpose. This would help the payment card processing vendor to validate the user authenticity and prevent these cards data from unauthorized user access.

In other words, the identity and access control of the payment card environment demands a very stringent policy to ensure security so that no internal or external malefactor can obtain unauthorized access. Any organization could face the wrath of non-compliance penalties.  So, which is the best tool to get rid of this risk? 

A robust Privileged Access Management (PAM) solution ensures seamless managing, monitoring and controlling of the card data processors’ access to confidential data. In the current context, these are  privileged users that have access to customer data. 

ARCON | Privileged Access Management (PAM) enables an organization to overcome the risk of illegitimate access control. It offers a rule and role-based access control to ensure only authorized card processors have access to confidential data. With ARCON | PAM, the card processors have multiple shields to safeguard against unauthorized access. Tools like MFA, Password vaulting, Granular controls help to verify the trust at every step. 

Moreover, ARCON | PAM helps to adhere to the PCI-DSS standards by generating customized audit reports as per the mandates. To summarize, ARCON | PAM: 

  • Restricts, controls and continuously monitors the privileged users in the payment card environment by applying the deepest granular level control, robust password vaulting of the credentials and multi-factor authentication of the users. As a result, the risks of compromised insiders, third-party elements are also warded off.
  • Captures each and every log and generates customized reports and audit trails of all privileged activities around the payment card environment.
  • Meticulously segregates privileged users and controls the payment card environment through a centralized policy framework for every critical system and device.
  • Reinforces role-based access in the payment card environment with “need-to-know” and “need-to-do” philosophy.

Conclusion: 

ARCON | Privileged Access Management (PAM) solution safeguards card processing and transaction environment with robust PCI-DSS compliance and enables every organization to address the risks of stemming from unauthorized card processors.