Talk to us Risks to Watch

Why Privileged Access Management is an indispensable tool?

The insider threats remain one of the most feared threats. Indeed, almost 66% of organizations, as per our research, believe that insider threats are more likely than external attacks as the disguise of a legitimate user is truly lethal. 

Malicious insiders in disguise of genuine users, inadequate user authentication measures, poor password management policy are some of the loopholes in IT security, which is why compromised insiders often target enterprise confidential data. 

Here we have discussed three recent IT incidents where a Privilege Access Management solution would have averted data breach. 

Lack of authorization and monitoring: The challenge of insider threats has risen exponentially during the last two years due to changes in the work patterns. The hybrid work culture has made the situation riskier as employees and third-party users are managed both remotely and on-prem. This offers an opportunity for end-users with malicious intent to abuse or misuse the data. 

At the beginning of 2021, a large organization from the aviation industry in the Asia Pacific subcontinent suffered a data breach that involved details of thousands of passengers. A malicious insider turned out to be the culprit. 

Expansion of IT infrastructure leads to expansion of the threat surface and thus monitoring every end-user session is the only way to address insider threats. A robust PAM will not only ensure authorization of end-users including provisioning and deprovisioning of the users, but will also authenticate the end-users and monitor the session and raise the alerts if some anomalous activity happens.

Inadequate User Authentication: Authorizing and authenticating end-users before allowing access to the critical systems or applications has become very important for organizations having distributed IT infrastructure and hybrid work conditions. 

A government organization in the Indian subcontinent recently suffered data breach of thousands of applicants due to the absence of any user authentication mechanism. Such incidents not just put the individual identity privacy at stake but also maligns the reputation. 

Multi-factor authentication tool offered by a comprehensive Privileged Access Management (PAM) solution ensures a secured access control mechanism for critical IT infrastructure. Multiple layers of user authentication become difficult for the hackers to circumvent the authentication process and thereby protects the data assets from unauthorized access. It eventually protects the business-critical data from misuse. 

Poor Password Management: Do we ever share our ATM passwords or internet banking passwords with others? In fact, banks always recommend that we change our passwords at regular intervals to ensure financial security. In large organizations where the business-critical applications, systems or databases are continuously and regularly accessed by multiple users, what extent of risks do they bear? 

Recently, in the middle of 2021, a nationalized bank in the Asia-Pacific region suffered data breach of millions of customers due to password hack. Industries like banking, telecom, government, healthcare and utilities are challenged by poor/ inadequate password management policy time and again. Almost 80% of data breach incidents happen due to poor privileged password management today. The vulnerability of passwords is more evident in a shared and distributed environment and is prone to compromise.

Password vault and frequent randomization of passwords, especially privileged passwords, helps to overcome the challenges of password breach. Deploying a mature Privileged Access Management (PAM) solution like ARCON | PAM automates the process of password randomization which is mandated by major regulatory standards. Not only that, the passwords are stored in a highly secured electronic vault and it helps in forensic analysis to understand who has done what to the passwords.

Conclusion

Digitalization is accepted and adopted by organizations globally to stay competitive with the advanced solutions. Simultaneously, organizations keep on striving with the emerging IT threats that challenge enterprise data security and data privacy every now and then. The above incidents vividly explain why Privilege Access Management solution (PAM) is an indispensable tool for small, midsize and large organizations in every industry. Deploy it and stay worry-free!

Another Year Another Reason to Celebrate

Overview

ARCON continued with its global growth story accompanied by several recognitions and awards in 2021. 

The organization’s continuous R&D along with the development of new solutions with added features and functionalities to address several emerging use-cases not only helped the organizations to stay compliant with global standards but also to protect data from emerging threats. 

Being a customer-centric organization, ARCON always ensures how its clients can keep a  proactive security approach. The focus is to mitigate  emerging IT threats in order to maintain data security, data integrity and data privacy.

While working on this mission, ARCON kept on achieving several milestones in the entire calendar year. These achievementsunderpin ARCON’s credibility as a global brand in the Privileged Access Management (PAM) space even as we continue to build some other robust continuous risk management solutions.

ARCON@2021: Some of the High Points 

  • ARCON began the year 2021 with a bang. Gartner Peer Insights ‘Voice of the Customer: Privileged Access Management’ recognized ARCON as a Customers’ Choice in the Privileged Access Management space. Gartner Peer Insights is a free peer review and ratings platform designed for enterprise IT software and services decision-makers. This recognition by Gartner Peer Insights we believe reemphasized the fact that ARCON always put customers first.

  • ARCON won the prestigious 2020 Deloitte Technology Fast 50 India award. The nomination process began in November 2020, and the results were announced in the first quarter of 2021. This recognition is given to some of the fastest-growing technology providers in India. 

  • In July 2021 ARCON was named as a Leader in the 2021 Gartner Magic Quadrant for Privileged Access Management. It is a sheer result of Team ARCON’s hard work towards attaining excellence in the Privileged Access Management space. The global IT community considers the Magic Quadrant reports as a benchmark to evaluate the Information Technology solution providers in terms of vision and their ability to execute.
  • Another feather on the cap! Another recognition! ARCON | PAM’s capability to address and solve global enterprise, midsize and large enterprise use-cases was validated in the 2021 Gartner Critical Capabilities for Privileged Access Management report. ARCON received respectable scores on several evaluated use-cases that included products and services scores for secret management use-cases along with PASM and PEDM capabilities. 

  • ARCON was also featured in Gartner’s exclusive research report on the APAC region, named as Gartner Asia-Pacific Context: Magic Quadrant for Privileged Access Management. This exclusive report by Gartner focused on the PAM trends in the said region and featured ARCON in its report. As per Gartner, “Magic Quadrant contextualization provides actionable advice to Magic Quadrant readers on the market direction, technology selection, and providers to consider from an industry, region or company-size perspective.

  • ARCON’s leadership is acknowledged everywhere! In August 2021, KuppingerCole named ARCON as an Overall Leader in the 2021 Kuppingercole Leadership Compass for Privileged Access Management. ARCON maintained its leadership in the ‘Innovation’ compass as well. This recognition was given post evaluation of 26 vendors in PAM capabilities. 

  • It’s time for recognition in the MEA region! ARCON bagged the coveted Cyber Sentinels Future Security Award at the GEC Security Symposium 2021 organized in Dubai. ARCON’s robust flagship product, Privileged Access Management solution, was recognized by the jury for addressing enterprises’ growing access control vulnerabilities. The award emphasizes that ARCON | Privileged Access Management (PAM) solution is widely acclaimed as a leading access control solution provider in the MEA region.

  • In the last quarter of 2021, ARCON received another prestigious award “Top Vendor in PAM” at the GEC Awards 2021 for its services in the MEA region. GEC Media Group recognized ARCON’s contribution towards reinforcing the Information Security posture in the region with the help of use-case-based solutions and recommendations. ARCON was adjudged as the “Top Vendor” of PAM solution that addresses and solves enterprises’ growing access control vulnerabilities.

The Way Forward

The entire ARCON team is enthusiastic to welcome 2022. We foresee another year of opportunity where we are ready to strive for betterment. All these achievements, as we believe, are a premonition of another successful year. Being highly optimistic about the future road-map, ARCON is ready to come up with more solutions to address newer industry use-cases – as always! Stay tuned!

How can User Behavior Analytics Benefit your Business?

60% of small companies that face data breaches go out of business within 6 months of the attack. With hackers targeting the weak zones of business, a cyberattack can cost a company millions in damage control and restitution pay-offs. Most businesses fail to recover from such hefty financial penalties after major data breaches. 

Organizations commit a grave mistake by limiting the user behavior analytics only to outsiders. External attackers are not the only ones responsible for causing cyberattacks. Research suggests that 60% of all cyberattacks are due to insider threats. 

User Behavior Analytics is a tool that can quickly detect behavioral anomalies and respond to potential insider threats on time to prevent such attacks. 

 

Why are Insider Attacks Dangerous?

Detecting insider threats can be challenging, such that many threats go overlooked for months or years. In a 2019 report on advanced threats, it has been concluded that insider threats go unnoticed due to the lack of visibility into the normal user behavior baseline and the management of privileged user accounts, and thus become an even more attractive target for cyberattacks. An average insider data breach can cost as much as 3.86 million dollars, according to a report. 

Insiders already have legitimate security access to vital credentials, which is what makes them hard to detect. Insiders already know where the sensitive data is stored and often have high-security clearance. For an insider threat, your system needs to detect when an employee shows signs of suspicious or abnormal behavior. But what is considered abnormal in one case might not be the same for others, which makes the detection even harder. Fortunately, user behavior analytics makes detection much easier. 

 

How Does User Behavior Analytics Work?

User Behavior Analytics or UBA refers to a segment of data analytics that offers essential insights about customers’ and prospects’ behavior while interacting online. UBA provides an exhaustive profile of the end users’ actions on the system.

User Behavior Analytics can be effectively applied to cybersecurity to differentiate between a major data breach and ward off a potential attack for enhancing conversions and revenue. 

Leveraging aggregated behavioral data, it is possible to determine common user behaviors. This data is used as the foundation of the analysis which eventually creates a user behavior profile. The more information the software can collect, the better the scope to identify behavioral anomalies. 

The software is programmed to collect data about the programs accessed, websites visited, locations, and others. All this data is further used to create a unique employee profile or baseline, which is always being monitored. 

 

How can User Behavior Analytics be Beneficial in Cybersecurity? 

User Behavior Analytics can be constantly used to monitor the activities of employees all the time. The integrated software is designed exclusively to compare data collected in each unique employee profile. 

Smarter security monitoring:

User Behavior Analytics can be applied to other segments of cybersecurity as well. It can monitor the users, assets as well as network. Not only for understanding baseline user behaviors, but the tool can also derive fundamental data about the actions of prospects and customers. Simultaneously, it can alert the admins to statistical anomalies and help mitigate business risks. 

 

Generates essential insights:

A vast amount of data leads to a better scope of comparison. By asking the right questions, these anomalies can be spotted on time. Anything outside the ‘normal behavior’ spectrum can be spotted as abnormal behavior, indicating the possibility of an insider threat. 

 

Correlates data across systems:

Correlating data maximizes the utility of User Behavior Analytics in network security, deriving a broader picture of what is occurring within the organization, identifying the anomaly proficiently while allowing the security and risk management team to understand what credentials have been compromised. 

 

Opportunities for Advanced Analytical Models

Leveraging unsupervised analytics for security operations adds value as it automates the overall hunting process. The discovery of anomalies can be more efficient, which can be later turned into supervised behavior analytics. 

Therefore, simply applying one facet of the analytics is never enough. The application should be made to all the levels – network, user, and assets – to determine threats quickly before any malicious activity goes into action. 

ARCON presents state-of-the-art technology specially designed to mitigate risks related to IT infrastructure. ARCON | User Behavior Analytics (UBA) offers an efficient framework for better visibility and robust protection, simultaneously providing insights about anomalies. The ARCON | User Behavior Analytics solution offers essential tools needed to spot anomalies, presenting the ability to trigger real-time alerts.

Ready to Comply with New RBI Mandates?

Overview

In the midst of increasing digital banking services, cybersecurity and IT risk management have been among the top priorities for governments and regulatory authorities. The changes in the work patterns, and the associated risks arising from those patterns in the last two years have further made the compliance framework more stringent. 

The New RBI Mandates on Digital Banking and Cybersecurity 

In our earlier blogs, we have discussed how the global regulatory compliances are getting stringent day by day. Recently, the Reserve Bank of India (RBI) announced that it will soon launch a web-based supervisory system that can supervise digital banking and ensure cybersecurity. Most of the nationalized and private banks are finding it challenging to meet the supervisory requirements in the post pandemic period.

It is evident that the IT governance standards, access control policies and IT risk assessment procedures are taking priority right at this moment. In order to stay compliant, the RBI has mandated the following:

  • Verify compliance before investing in new technologies
  • As per governance standards, the organizations need to form the business model
  • Standard and strict allocation of risk management team and service assurance team
  • End-to-end workflow automation system to ensure continuous monitoring
  • Immediate incident reporting mechanism
  • Vulnerability remediation through workflow through alerts and notifications against anomalies

From the IT risk management point of view, once the new RBI guidelines are effective, it could be a boon for both national and international banks. Robust IT risk management helps to protect highly sensitive data from various IT risks and threats that prevails in large financial institutions’ IT infrastructure. These threats and  risks are continuously evolving in today’s dynamic environment as organizations are adopting new technologies for business productivity, scalability and efficiency. 

What does the RBI’s New Mandates Imply? 

The crux of the matter is the enterprise data, and its security and confidentiality. In the case of financial organizations, maintaining the confidentiality of data is comparatively challenging. 

The huge amount of data, vast IT infrastructure, and a large number of users that access systems make it very challenging to ensure data security and privacy. 

What the RBI’s fresh mandates demand is that financial institutions possess the necessary safeguards to securely store, access and process the data. The central bank expects that organizations have explicit policies for people (end-users) and IT processes. Besides, organizations must adopt adequate preventive measures including vulnerability assessment mechanisms to detect anomalies in a timely manner. 

Compliance with the RBI mandates can ensure data security as on close inspection it is clear that the central bank requires every access to data is authorized, authenticated and documented. 

Compliance: Are organizations doing enough? 

The RBI has imposed non-compliance penalties worth upto INR two crore on fourteen different banks in a single calendar year of 2021, as per Business Standard. Not just India, the global non-compliance scenario is quite similar. Non-compliance penalties have grown by 23% globally in the post-pandemic time. On closer assessment, it is obvious that abrupt change in the work pattern and fast adoption of new technologies is the main reason behind this. 

Conclusion

The banking industry has to stay agile. This industry can never afford to stay stagnant in terms of technological adoption. As a result, a well-communicated IT security policy helps organizations to allocate relevant resources in relevant areas to ensure safe IT operations. It walks hand in hand with business strategy to ensure overall business growth. The new RBI norms are stepping stones towards attaining that ‘growth’.