Monday, April 25, 2022

How Lapsus$ Breached Okta and What Organizations Should Learn

How Lapsus$ Breached Okta and What Organizations Should Learn

Protecting customer data is paramount to every business organization. Even though businesses deploy the most stringent security measures to safeguard data, malicious actors somehow find security shortcomings to access network systems and cause data breaches, compromising the confidentiality, integrity, and availability of information.

Cybersecurity firms like Okta, which provides identity management solutions and deals in authentication space, make the backbone of an organization's cybersecurity posture. Okta serves 15000+ customers worldwide. The Okta data breach by Lapsus$ is a recent example of what can happen if business organizations depend on third-party solution providers who show laxity in implementing robust cybersecurity strategies, frameworks, and controls.

It is also a cautionary tale for cybersecurity MSPs (Managed Services Providers) and ITSPs (IT Solution Providers) to ensure that they have the best of security controls in place to prevent incidents like this.

What Is Okta?

Okta is an identity platform and offers identity and access management solutions such as Single sign-on (SSO), Multi-Factor Authentication (MFA), etc., for an organization's customers and employees.

Why Is Okta In the News?

Okta’s CSO (Chief Security Officer) David Bradbury recently published an official statement about a support engineer whose computer was accessed by malicious actors for five days in mid-January (between January 16 to 21, 2022) and said they detected the unsuccessful attempt early on.

How Was the Attack Executed?

Okta has now confirmed that malicious actors had access to one of its employees' laptops for five days in January 2022 but maintained there has been no data breach and remains fully operational. However, they concede that around 2.5% of its customers (about 366) might have been affected.

Here is how the attack happened.

  • On March 22, 2022, a hacking group identifying itself as Lapsus$ posted some screenshots in its Telegram channel claiming to have compromised Okta's internal systems. The screenshots included Okta's Slack channels, super admin dashboard (access to reset passwords and MFA of their business customer’s employees — the customer in the screenshot was Cloudflare), and JIRA board.
  • Okta's CSO responded through a blog post stating that the incident that Lapsus$ refers to had happened in January 2021 when it detected an attempt by hackers to compromise the account of a customer support engineer working for a third-party service provider.
  • Okta alerted the service provider, suspended the engineer's account, and terminated the user's active Okta sessions. Besides, the company shared pertinent information with a third-party forensics firm for investigation.
  • The investigation reported that hackers accessed the engineer's laptop for five days in January 2022.
  • However, Lapsus$ claims that it had gained admin access to Okta's systems for two months, and it found Okta storing AWS keys in Slack channels. Furthermore, the hacker group claimed that it used its access to focus on Okta's customers.

Who Is Behind Okta’s Breach?

News reports show that a group of unscrupulous actors identifying themselves as Lapsus$ in their Telegram channel was behind this Okta breach. They were aided by a customer support engineer working for a third-party service provider whose laptop was accessed by these hackers to gain vital information. Lapsus$ is also known as a notorious threat actor group — DEV-0537. This group has a history of taking over individual user accounts to drain their crypto holdings at cryptocurrency exchanges.

The Key Reasons That Caused The Security Breach

The forensics report cited by Okta's CSO did not state how the hackers managed to gain access to the support engineer’s laptop, but the fingers point towards negligence by the engineer. However, the hackers claim to have had access to Okta's systems for more than a month before the January 2022 incident. If these claims are valid, it indicates a significant security breach at Okta's network center.

Okta Breach: What Was the Impact?

The Okta breach exposed the security frailties of the Okta network system and put 15,000 Okta customers’ data at risk. However, Okta stated it had contacted the affected 2.5% of customers, appraising them of the matter. Okta further noted that the customers need not take any precautionary measures as their data is safe.

The CSO blog post went on to add that the damage was restricted to the access that support engineers have, such as Jira tickets and lists of users. Though customer support engineers facilitate password resetting and MFA, the hackers did not seem to have obtained this information. The CSO also confirmed that customer service engineers could not create or delete users.

Notably, Okta's customers include high-profile enterprises like FedEx Corporation and Moody's Corporation. Hence, Okta's shares plunged 11% immediately after hackers claimed the breach that has put thousands of Okta customers at risk.

What to Learn From Okta's Cyber Hack?

1) Limit Access on a ‘Need-to-Know’ Basis

Limiting access and permissions to the employees is the first step to take. Employees and contractors should only be provided access on a 'need-to-know' basis and must be provided on a ‘least privilege’ basis (minimum access needed to perform a task or job). For example, support engineers shouldn't be able to access internal HR, accounting, or payroll systems. At the same time, marketing personnel should not have access to network configuration or applications that they do not use.

2) Validate Third-party Apps and SaaS Solutions

In an increasing multi-cloud and hybrid-cloud environment, it's paramount to understand the s IT ecosystem, third-party APIs (Application Programming Interfaces) and applications, and Software as a Service (SaaS) solutions deployed. Requesting SOC reports from vendors and contractors can help understand how their information systems are maintained and secured.

3) Implement Robust IAM-PAM Solutions

Implementing robust processes around Identity and Access Management (IAM) and Privileged Access Management (PAM) can help strengthen the cybersecurity posture by making it almost impossible for attackers to barge into the organization’s periphery.

4) Train Employees and Customers

'People' are the most valuable asset for any organization but can also be the weakest link in the cybersecurity chain. Therefore, organizations must regularly review the processes around training and educating employees, vendor-contractors, customers, and users to follow basic cyber hygiene.

5) Be Vigilant

Organizations must continue to monitor and audit the control environments. Leveraging automated monitoring and alerting tools can help overcome many challenges SOC teams face.

6) Audit and Review Regularly

Organizations should perform internal audits and review the systems and monitor the traffic and access permission more frequently. It is also advisable to engage third-party audit firms to get an external and independent view of the cybersecurity posture.

7) Communicate Transparently

In case of a security incident, it is essential to be transparent to the employees, customers, vendors, and regulators and communicate with them immediately about the incident. Organizations should also provide specific guidance on how to safeguard the information assets.

To Conclude

The Okta breach shows that no business organization is 100% safe from malicious attacks. One simplest security issue is sufficient for malicious actors to wreak havoc.

In this specific example, the hackers accessed the laptop of one of Okta's customer service engineers to gain vital insights into the company's customer data. Such incidents prove that customers can never be sure that their information is safe and leak-proof.

However, it offers a valuable learning experience that business entities should not ignore the minutest of details regarding network security. It surfaces the adage that ' A chain is only as strong as its weakest link.'


Originally Published at LoginRadius

How Lapsus$ Breached Okta and What Organizations Should Learn | LoginRadius Blog
Businesses have to be extra vigilant in safeguarding customer data. Minor mistakes can cause a massive data breach, violating data privacy regulations and attracting penalties from regulatory authorities.
How Lapsus$ Breached Okta and What Organizations Should Learn

https://bit.ly/3Khk8HY
https://bit.ly/38kIlQC


https://guptadeepak.com/content/images/2022/04/how-lapsus-breached-okta.png
https://deepakguptaplus.wordpress.com/2022/04/25/how-lapsus-breached-okta-and-what-organizations-should-learn/

Thursday, April 14, 2022

Everyone’s and identity driven company (even if you aren’t one)

Everyone's and identity driven company (even if you aren't one)

Identity remains the answer to the basic questions: Who are we? Why are we here? What drives us different from others?

But, what’s digital identity? Many people have used this term to relate to core IT services such as access controls, password resets, user directories, and authentication. Identity, on the other hand, is much more than that today.

It has truly become the digital economy's connective tissue. Thanks to the emergence of consumer identity and access management, users can now interface with businesses, technology, and consumers in the most personalized and efficient way possible by providing reliable access and protection across APIs, new sensors and devices (IoT), and intelligent machines.

The Current Competitive Landscape

A landscape has emerged in the past decade, and companies are having to make contingency plans for these changes. In this new landscape, companies not only have to keep up with current business, but also are working to understand a new way of thinking about their customers' identities and behaviors.

Companies need to be able to rapidly develop solutions and infrastructure to explore a problem space, then quickly ramp up if the opportunity turns out to be significant. In making this shift, companies need to consider many factors in addition to simply the technology that's available.

Protect Your Business Data On The Internet

Consumer identity is one of the most important factors in brand building, and it’s a major reason why there are so many identity-driven companies. Part of what makes such companies so successful is their constant attention to customer needs. It’s now more important than ever for companies to understand how consumer identities shape their decision-making processes.

It's not a secret that data is the most valuable asset of modern organizations. Protecting it is critical, particularly as it moves across an organization's infrastructure, applications, and people.

One thing that's often overlooked in this respect is identity management. Small-scale hacks and data breaches are becoming more common every year, and we've seen that there isn't always a clear understanding of how to protect against them. When it comes to protecting information online, many businesses believe that if they're not storing a ton of sensitive information on their servers, they don't have a problem at all. In reality, though, identity management is crucial in protecting yourself against identity theft and other risks related to personal information sharing.

How Important Is Security In An Identity-Driven Company?

Securing your consumer identity is crucial. After all, it is the identities that establish a baseline for which you can employ identity management solutions and offer them the correct level of access to your products and services. With appropriate identity management solutions, integration of user identities, role-based access, authorization, and privilege management, you can reduce the number of accounts in need of password resets.

As customer identity and access management (CIAM) has progressed, the focus of its early days has changed. In the beginning, companies focused on the client's identity. However, with the emergence of cloud computing, companies turned their attention to the customer's identity and driving cloud computing adoption. Nowadays, companies recognize that consumers' identity and security are both important elements to consider in CIAM implementations.

Why Is CIAM So Important?

Retaining customers is key to any consumer-oriented organization. So, the question is how can a consumer identity management system help an organization retain its customers?

One of the main strategies is to create personalized experiences. Ideally, organizations want customers to feel like they are always being taken care of and that they matter. Thus, if a company succeeds in creating personalized experiences for their customers, then they are likely to retain more of their customers.

That’s where the role of customer identity and access management comes into play. It helps organizations manage identities and access rights for customers, employees, and partners.

The benefits of CIAM include:

  • Improved customer experience by providing a secure and compliant environment for users.
  • Reduced security risks by automating identity management processes.
  • Increased efficiency by streamlining the authorization and compliance process.

Just like CIAM being an important factor, SSO is another business-critical solution that provides greater security and compliance.

What About Single Sign-On?

Authenticating multiple applications with a single set of credentials — that’s single sign-on. SSO has become an important identity management keystone of the consumer web, along with mobile identity applications, banks, and government agencies are also using federated identity systems. Some benefits include:

  • Reduced security risks. With a single credential, users are less likely to enter incorrect passwords into different sites.
  • Reduced IT costs. SSO can help reduce the number of password changes required by consumers, as well as the time spent managing those changes.

Conclusion

Consumer identity is the reason your company or brand exists. Whether you’re a startup or a long-established business, identity-driven marketing is critical to your success.

Identifying and focusing on your business's consumer identity is a great way to ensure that you stand out in the marketplace. To some people, this might seem like an unnecessary step—but it is actually a vital one.

Being identity-driven means that you focus on the things that make you different from your competition, and use this differentiation to attract and retain customers. By doing this, you can ensure that your business remains successful over the long term.


Originally Published at ValueWalk

Everyone’s An Identity-Driven Company (Even If You Aren’t One) – ValueWalk
Every company is driven by consumer identity. So, if companies don’t start collecting and managing data on customers now, they’ll never be able to adapt and evolve fast enough to meet changing customer expectations.
Everyone's and identity driven company (even if you aren't one)

https://bit.ly/3uHcpyt
https://bit.ly/3KLpRa3


https://guptadeepak.com/content/images/2022/03/business_1645471287-768x512.jpg.webp
https://deepakguptaplus.wordpress.com/2022/04/14/everyones-and-identity-driven-company-even-if-you-arent-one/

Thursday, April 7, 2022

Decentralized identity using blockchain

Decentralized identity using blockchain

Today, almost all of our digital identities are linked through devices, apps, and services. Service providers control these digital identities and their respective digital identity data.

Because of this, users are now experiencing misuse of personal data and data breaches that affect their social, financial, and professional lives.

Additionally, giving access to multiple third parties or service providers from different applications makes it harder for users to manage their personal data and revoke access to their information. Users need to own and control their digital identities to address these concerns, preferably from a single source.

A centralized system makes user identity data extremely prone to cyberattacks and privacy breaches. But decentralized identity solutions provide a new horizon by enabling users and service providers to have better authority over their identity and personal data.

This article addresses the following:

  • What is a decentralized identity?
  • How decentralized identity works with blockchain
  • How to authenticate using a decentralized identity
  • What happens when we fully adopt a decentralized identity procedure?
  • Benefits of using blockchain with decentralized identity

What is a decentralized identity?

Decentralized identity is based on a trust framework for identity management. It allows users to generate and control their own digital identity without depending on a specific service provider.

For example, digital identities can get approval from multiple issuers such as an employer, a government, or a university that remains stored in a digital wallet called an “identity wallet.” Using the identity wallet, the user (i.e., the identity owner) can present proof of their identity to any third party. The wallet helps users give and revoke access to identity information from a single source, making it easier.

According to Forrester, “Decentralized digital identity (DDID) is not just a technology buzzword: It promises a complete restructuring of the currently centralized physical and digital identity ecosystem into a decentralized and democratized architecture.”

How decentralized identity works with blockchain

The setup of decentralized identity with blockchain typically consists of the following elements:

  • Identity Wallet: An app that allows users to create their decentralized identity and manage their access to service providers.
  • Identity Owner: A user who creates their decentralized identity using the identity wallet.
  • Issuer/Verifier: The person who issues and verifies the identity information. They sign the transaction with their private key.
  • Service Providers: Applications that accept the authentication using the decentralized identity and access blockchain/distributed ledger to look for the DID that user shared.
  • Blockchain/Distributed Ledger: A decentralized and distributed ledger that provides the mechanism and features for DIDs and functioning.
  • DID (Decentralized Identifier): A unique identifier that contains details such as the public key, verification information, service endpoints.

In a decentralized form of identity, an application (an identity wallet) allows users to create their own digital identity. Upon identity creation, the respective cryptographic keys (a public and a private key) are generated.

The identity wallet submits a registration payload with a public key to the blockchain, which generates a unique identifier against your wallet. The private key remains with the user’s device/identity wallet and is used during the authentication.

Similarly, issuers such as the government, universities, and finance institutes verify the respective identity information and add to the digital identity data in a process that is like issuing certificates. The processes, for example, verifying user identity and issuing new credentials, require issuers to sign using their private keys.

How to authenticate using decentralized identity

These are the steps of authentication using decentralized identity and blockchain.

  • The identity wallet holds verified identity details of the user such as name, age, address, education, employment details, and financial information. This information helps establish trust and makes the user eligible to perform authentication.
  • The decentralized identity mechanism takes the public key associated with the private key and publishes it onto a distributed ledger such as blockchain.
  • As the decentralized system provides the public key to the distributed ledger, the identity wallet receives a decentralized identifier (DID). DID is a unique identifier representing the user across the internet.
  • The user shares this DID with the service provider for authentication.
  • The service provider looks for the shared DID in the distributed ledger. If found, distributed ledger sends matching data to the application.
  • The user signs this transaction with the private key to complete the authentication.
  • The service provider application confirms the authentication success and lets the user perform the actions.

What happens when we fully adopt the decentralized identity procedure?

Let’s assume an online shopping scenario where the required data will transit from the wallet associated with the decentralized identity. The wallet in this scenario contains the verified identity, address, and financial data.

The users share identity data to log in with the website by submitting the required information from the identity wallet. They are authenticated with the website without sharing the actual data. The same scenario applies to the checkout process; a user can place an order with the address and payment source already verified in his identity wallet.

Consequently, a user can go through a smooth and secure online shopping experience without sharing an address or financial data with an ecommerce website owner.

5 benefits of leveraging blockchain

  • Trustworthy: Blockchain technology uses a consensus approach to prove the data authenticity through various nodes and acts as the source of trust to verify user identity.  Along with the data, each block also contains a hash that changes if someone tempers the data.  These blocks are a highly-encrypted list of transactions or entries shared across all the nodes distributed throughout the network.
  • Data Integrity: The blockchain-based data storage mechanism is immutable and permanent, and hence, modification and deletion are not possible. The decentralized identity systems use this mechanism so that no external entity can tamper or modify the data.
  • Security: Another crucial reason for leveraging the blockchain in decentralized identity systems is to provide robust security. The blockchain system features an inherent design by maintaining data in a highly encrypted fashion. The blockchain also caters to digital signatures, consensus algorithms, and cryptographic hash functions to protect user identities from breaches and thefts.
  • Privacy: Decentralized identity systems leveraging blockchain with a pseudo-anonymous identifier (decentralized identifier) can help mitigate the privacy concerns among the identity owners.
  • Simplicity: Identity issuers leverage the seamless process of issuing digital identities. Identity verifiers can efficiently onboard new users and conduct the information verification process. Identity owners can effortlessly store and manage their identities within the identity wallet.

Conclusion

From all the above facts, it is evident that decentralized identity with blockchain can completely transform the digital identity landscape. It will make digital identity management decentralized and seamless, as no particular organization will govern the user data.

More importantly, users will be able to easily authenticate themself without sharing their sensitive personal information with third parties.


Originally published at Venturebeat

Decentralized identity using blockchain
Decentralized identity with blockchain could make digital identity management seamless and eliminate sharing sensitive personal information.
Decentralized identity using blockchain

https://bit.ly/3jd4LVQ
https://bit.ly/3LMSyn5


https://guptadeepak.com/content/images/2022/03/GettyImages-1266674885.jpg.webp
https://deepakguptaplus.wordpress.com/2022/04/07/decentralized-identity-using-blockchain/

Monday, April 4, 2022

API Security: 5 tips to ensure third party API security in your organization

API Security: 5 tips to ensure third party API security in your organization

Third-party APIs are being used everywhere. However, as an increasing number of enterprises adopt and utilize third-party APIs, how do they ensure API security?

API Security: 5 tips to ensure third party API security in your organization

Today, software and web development teams and enterprises are increasingly becoming somewhat dependent on some type of open source code, outsourced development, commercial-off-the-shelf (COTS) software, or some other form of outsourced development resources. And third party APIs, extensions, and applications are no different.

According to experts, at least 55% of global companies utilize third-party APIs to boost their organizational revenue. However, where using such third-party APIs can offer many benefits and features, it can also pose a myriad of security challenges for the development teams and organizations. Continue reading the article as we take a deep dive into the subject.

What Are Third-Party APIs?

Third-party APIs, extensions, and applications are special pieces of software, codes, or protocols provided by a third-party company to you for a specific purpose. Third-party APIs or applications work by providing a specific service or a set of features and functionalities that you do not have the resources to develop.

You can integrate pre-developed third-party APIs and extensions offered by different companies into your specific organizational infrastructure. For example, you can use Google’s Map API to integrate map features into your business website. Similarly, web and software developers can also use various pre-built third-party APIs to speed up the development process.

What is API Security?

Third-party web APIs can access sensitive data/information which can increase security risks such as data breaches.  Malicious web APIs can be malware-infected and can corrupt a whole web project and can cause other far-reaching complications. API security means taking necessary steps and deploying specific security evaluation criteria to determine if a third-party API poses any security risks to a development project or organizational assets.

Why is Third Party API Security important?

Third-party API cybersecurity risks pose a serious threat to the very existence of businesses and development projects. A single malicious third-party API can infiltrate the organizational security parameters and can bring down the whole organization’s infrastructure. Similarly, a fraudulent third-party API can also abuse its access and privileges and can secretly steal and misuse sensitive information or can even do worse.

Cybercriminals are also evolving with time and technology continues to progress. Today’s modern cybercriminals can also exploit a security vulnerability that may exist in a third-party application or API being used by your organization. Adversaries can use a vulnerable API as an entry point to execute a large-scale attack. Experts have reported that 51% of organizations have experienced a data breach caused by malicious third-party APIs and applications. The consequences of a breach caused by such APIs can include but are not limited to the following:

  • Data breach.
  • Process/services/operations corruptions.
  • Network downtimes.
  • Malware infections.
  • Revenue loss.
  • Compliance issues.
  • Project failures.
  • Asset damage.
  • Legal complications and more.

In addition to the above-mentioned, there can be other delayed complications accompanying a security incident caused by fraudulent third-party apps, APIs, and extensions. So how do you ensure third-party API cybersecurity? Continue reading as we share with you the top 5 ways you can evaluate third-party APIs to ensure security.

1- Making inventory and testing the APIs

How do you reduce the security risks of third-party APIs? You test them! Conducting beta testing of multiple third-party APIs can enable you to determine how a certain API performs in comparison to the others and can allow you to make informed decisions.

One of the most efficient ways to approach this is by making an inventory or a list. Make a list of all reputed third-party vendors and service providers that you can find online. Next, start by classifying them according to their impact level. Impact levels represent the level of access and control an API requires in order to perform. The more an API requires access to your organizational assets, the more level of impact/threat it poses.

The level of impact can be classified into; High, Medium, and Low. Determine what level of risk your organization is willing to accept and choose an API according to your acceptance criteria.

2- Assigning responsibilities and patching vulnerabilities

Who is responsible for patching the security vulnerabilities in third-party API? Does your organization have a dedicated IT or security team? You must never partner up with a third-party vendor if they do not provide regular security updates for their APIs or web extensions.

Assign appropriate team members to investigate and validate a particular third-party API is being maintained by the vendor appropriately. The assigned team should also evaluate the level of data and other assets accessed by the API and how the organization should react if the data accessed by the third-party API is misused. Developing a third-party incident response plan can help your organization deal with unexpected situations caused by malicious third-party APIs.

3- Investigate the API and the Vendor

Before partnering up with a third-party API vendor or before using a free API, it is always a best practice to ask specific questions from the vendor to get specific information and answers. It is imperative to investigate how a third-party API collects information, where it is stored, how it is being used by the vendor, and what specific security measures have been taken by the partnered vendor to secure the collected data and information.

Asking such questions can help you gather actionable information and make informed decisions to determine whether a third-party vendor has reliable security parameters in place to handle your organizational data/information or not.

4- Establish Zero-Trust cybersecurity policies

When it comes to organizational security, trust no one. That includes third-party API vendors and your organizational employees. 95% of security breaches are caused by negligent employees and human mistakes. Therefore, develop strict zero-trust cybersecurity policies that include compact cybersecurity rules and procedures for both your third-party vendors and your employees cooperating with them.

In order to ensure a cybersecurity culture in your organization, you must develop cybersecurity policies that do not just address third-party security procedures, but also educate and motivate your employees to develop a cybersecurity-conscious mindset. This will help your employees to develop a security-first mindset and will potentially lower the risks of employees making mistakes or implementing poor security practices.

5-  Limit access and privileges

Consider deploying a privileged access management solution to make sure that only legitimate users can access your company’s sensitive information. Secure your critical assets with two-factor authentication (2FA) to make it harder to compromise your organizational network even if someone’s credentials are stolen. One-time passwords and manual access approval also can help you prevent attackers from entering your network.

How to choose a secure API and a secure API Vendor for your organization?

How can you choose a secure third-party API for your organization? What elements should you look for while choosing a third-party API? The key metrics on which you may want to evaluate the security and functionality of a specific API may differ from business to business depending on a company’s security requirements and the end goals. However, in order to maximize your chances of choosing a secure third party API compare and evaluate a third party API against the following aspects:

Reputation: If a third-party API has no verifiable vendor details or a competitive digital footprint, then it is better to choose another API that is offered by a reputed vendor such as Google, Amazon, or Microsoft.

Security: Does an API have appropriate security controls? Run a security check by using third-party security testing tools or refer to the API documentation to verify the API security capabilities. If an API offers encryption capabilities, go for it!

Compliance: Integration of a third-party API or extension can cause compliance issues and may require you to produce additional documentation. Do not use a third-party API that comes with a compliance void warning.

Updates and patches: Always choose a third-party API that is regularly updated and patched by the vendor. APIs that are updated regularly perform well and are less vulnerable to security threats.

Review the documentation: Third-party API vendors may reveal gruesome details in the API documentation that may otherwise not be visible on their official websites. Always review an API’s documentation to ensure that everything mentioned in the documentation is digestible and does not raise any red flags and alarms.

Compare third-party APIs against international security standards: There are several international standards and commonly used cybersecurity frameworks that can serve as a basis for outlining your third-party risk management strategy. Examples include:

Consider Third-party vendor risk management: Third-party risk management (TPRM) can help you mitigate potential cybersecurity threats and manage third-party risks. TPRM solutions offer efficient detection, containment, and mitigation of potential third-party security risks while also boosting the performance and productivity of your overall organization.

As developers and businesses continue to rely on various third-party APIs, applications, and extensions, it is imperative that the legitimacy and security of the APIs be ensured in order to minimize potential security risks and unwanted situations. Careful evaluation of the third-party APIs and the third-party vendors is the key to making informed decisions.

https://bit.ly/3DC2qxf
https://bit.ly/3x8r2g1


https://guptadeepak.com/content/images/2022/03/AdobeStock_328528736-1.jpeg
https://deepakguptaplus.wordpress.com/2022/04/04/api-security-5-tips-to-ensure-third-party-api-security-in-your-organization/

Thursday, March 31, 2022

How Cloud Governance Allows Businesses to Become Compliant Superheroes

How Cloud Governance Allows Businesses to Become Compliant Superheroes

What Is Identity Governance and Administration (IGA)?

Identity governance and administration (IGA), also known as identity security, includes a policy framework and a set of security solutions that enable organizations to reduce access-related risks. It helps organizations provide automated access to the technology assets while managing potential security and compliance risks.

IGA can help an organization effectively address today’s most common business challenges.

  • Reduces operational cost: IGA automates access certifications, access requests, and password management, which effectively cuts down extra workload costs.
  • Reduces risk and strengthen security: Centralized visibility allows authorized users to detect inappropriate access, policy violations, and weak controls that lead organizations to risk.
  • Improves compliance: IGA allows organizations to meet the security and privacy requirements of regulations like SOX, HIPAA, and GDPR. Role-based access control helps companies significantly reduce the cost of compliance.
  • Delivers fast business services: With automated policy enforcement, IGA allows companies to meet business service level requirements without compromising security and compliance.

An organization-level identity governance solution must have the following features:

  • Access management: Ensures access provisioning policies are properly enforced. Its duties include usernames and password control, role management, and revoking access.
  • Access certification: Access certification validates the access rights of employees within a company network. It is essential to fulfilling the compliance mandate. Access certification ensures access rights are given to the employees for their particular job role. It also removes invalid access permissions.
  • Reporting and logging: The IGA solution must be able to capture information from logs and perform analytics, which is a requirement according to regulatory compliance mandates.
  • Workflow automation management: This automation eliminates approval delays and human errors that most commonly occur in the access request process.
  • Identity lifecycle management: Identity lifecycle management includes creating a digital identity during employee onboarding, managing and coordinating that identity’s access, and removing that identity during employee offboarding.

Capabilities of Cloud-Based Identity Governance

Managing cloud identity is something that the IT admin has always had to do. Now that we are moving to the cloud, it becomes even more important. According to Forrester, Cloud Identity Governance (CIG) is a critical factor that advances enterprise security. Every cloud platform offers different ways to define, manage, and authorize users, which makes cloud security particularly challenging.

The Cloud Identity Governance (CIG) approach focuses on the following areas:

Cloud Infrastructure Entitlement Management (CIEM): The concept of CIEM isn’t new. The adoption of private and public cloud solutions across the enterprise is limited, mostly because of complexities in license management and security risks. CIEM solutions help eliminate or mitigate these complexities from the cloud governance landscape.

This refined approach uses analytics and machine learning to manage entitlements and mitigate the risks of multi-cloud environments. It is essential for dynamic, complex cloud environments utilizing IaaS and PaaS. CIEM streamlines operations by removing manual oversight and automatically enforcing administered authorizations or privileges.

Cloud-Based Identity and Access Management (IAM): This approach includes establishing a comprehensive framework for authentication and authorization at the center of cloud connections and managing them effectively. The best IAM solutions simplify the account setup and deprovisioning across multiple software or systems. Thus, it is possible to improve security, audit performance, and regulatory compliance.

Cloud-Based Identity Verification: Validating the identity of a user is essential in any cloud framework or software. Multi-factor authentication (MFA) is a critical component for that. In most cases, organizations use two or three layers of authentication methods to secure identity. More advanced frameworks incorporate physical or virtual tokens to automate and improve the authentication process.

Privileged Access Management (PAM): Privileged accounts allow employees to access critical systems and applications, so it’s essential that only the right users have access to them. By using privileged access management (PAM), organizations can centralize their privileged accounts, which means they can avoid having to manage users in multiple places. This provides better security and less maintenance.

Zero Trust Network Access (ZTNA): ZTNA enforces adaptive and context-aware policies to provide secure and seamless zero-trust access to private applications hosted across clouds. This context may be the combination of user identity, user or service location, time, service type, and security posture of the device.

The Bottom Line

As customers adopt cloud governance strategies to manage their cloud resources, the need for better identity management will be one cornerstone of their success. Identity governance can achieve a higher level of visibility and access management control across all cloud services, empowering an organization to meet compliance requirements with ease. It is a useful tool for those interested in streamlining administrative and operational tasks in their organizations. Now is the time to evaluate your plan and establish a baseline for development.


Originally Published at Dataversity

How Cloud Governance Allows Businesses to Become Compliant Superheroes – DATAVERSITY
As customers adopt cloud governance strategies, the need for better identity management will be one cornerstone of their success.
How Cloud Governance Allows Businesses to Become Compliant Superheroes

https://bit.ly/3iT9xIc
https://bit.ly/3wTe3yp


https://guptadeepak.com/content/images/2022/03/AdobeStock_85721607.jpeg
https://deepakguptaplus.wordpress.com/2022/03/31/how-cloud-governance-allows-businesses-to-become-compliant-superheroes/

Monday, March 28, 2022

Navigating a Corporate Data Breach

Navigating a Corporate Data Breach

Data breaches have existed for as long as companies have maintained confidential information and private records. Although data breaches have been around for quite some time, instances of them are now on the rise, striking fear into both small and large companies alike. It is believed that data breaches are more common now than ever due to the sudden rise in the number of corporate entities switching over to cloud computing to support remote work operations. This occurrence is supported by a recent report by IMB, which found that the average cost was $1.07 million higher in breaches where remote work was a factor in causing the breach.

Although instances of data breaches are on the rise, many companies do not have an action plan in place for if one occurs. This is namely because there is much confusion surrounding data breach best practices on the part of corporations. Thankfully, there are expert-approved guidelines every business can and should refer to when they come face to face with a data breach.

Step #1 Confirmation

As a corporation, the first thing you should do is confirm a data breach. Remember, an email stating that there has been a breach is not enough to conclusively confirm that a real data breach did indeed occur. If you did receive an email, do not reply, as this email could be from scammers posing as a breacher to get your personal information. Your first step should always be to alert your breach task force so they can work on uncovering the source and extent of the breach.

Step #2 The Source and Extent

Ideally, you should have an intrusion detection and/or prevention system (IDS and IPS) in place that can automatically log security events in for you. Using these logs, you should be able to track the source of the breach, see which files were accessed, as well as which files were accessed by the hacker. It is crucial to uncover this information as it informs your next steps. If you do not have IDS/IPS for your network, all is not lost, this just means that collecting the above information will take considerably more time and be more labor-intensive for your IT team. In addition to uncovering the source, it is also crucial to uncover what exactly was breached at this step. If personal data was breached, it is important to remember that your customers/clients or employees are at serious risk for identity theft.

The Most Common Types of Data Breaches:

There are numerous types of data breaches corporations should be aware of to safeguard their data, the most common being ransomware, XSS attacks, man-in-the-middle attacks, and SQL injection attacks.

Ransomware is a specific type of malware that blocks authorized user access to data systems and files. Corporations that experience ransomware attacks will usually be asked for ‘ransom’ by hackers to regain control and access to their data. The most common form of a ransomware attack is known as a locker ransomware attack. Here, a user will be locked out of their computer after opening a file or link that was infected with malware.

XSS attacks have become one of the most widely used types of data breaches in recent years. This type of attack occurs when a cyber-attacker inserts a malicious script into a specific webpages HTML body. When a user accesses the infected webpage, the malicious script can then be executed against the web user’s browser. This gives the attacker direct access to the victim’s browser and its data.

Man-in-the-middle attacks involve a cyber-attacker intercepting communication between two parties to gain access to information such as logins, key dates, file locations, and more. In 2018, MITM attempts were associated with 35% of all security exploits, making them one of the more common data breaches organizations are advised to protect themselves against. Researchers have also identified vulnerabilities in 3G, 4G, and 5G wireless networks that are often exploited in this type of data breach attack.

SQL, or Structured Query Language, is a programming language commonly used for web-based data management systems. In a SQL injection attack, a hacker gains control over a web database to tamper with its contents. Since this is a type of data breach in which a cyber attacker can exert complete control over a web-based application, some hackers will also utilize this attack type to destroy a data system entirely.

It is crucial to identify the type of data breach your corporation experienced as this informs your security fix.

Step #3 Test your Security Fix

After encountering, identifying, and assessing the type of data breach, your IT team will then work to implement a short-term security fix to prevent any further outside access to company data. Immediately after implementing this fix, your team should then test this fix thoroughly to guarantee that the attacker cannot use the same method to attack your company again. This kind of penetration testing should be repeated for all your company’s servers to make sure the same vulnerability that led to the breach does not exist elsewhere.

Step #4 Inform Authorities and Affected Customers

Once you have a fix in place and have tested its effectiveness, you will then need to reach out to any customers that may have been affected by the breach. Your company should also inform federal authorities of the breach as they may be able to provide you with crucial instructions for complying with post-breach regulatory standards for your industry.

How to Notify Customers:

While the specific approach you will take in notifying customers of a breach will depend on the type of breach your company experiences and the industry you are in, some elements should be considered across the board. These critical elements relate to time, information, and thoroughness.

  • Time: the sooner you can alert customers to a breach, the more time they will have to protect themselves from potential fraud.
  • Information: when communicating with your customers affected, try to include some information about the nature and the extent of the breach in the document. For example, if a customer’s information was compromised, inform them of what information was taken. To further assist your customers, include ‘next step’ actions they should take to protect themselves from identity theft.
  • Thoroughness: it is important to make sure that all affected parties are notified of the breach. To cover more ground, try using more than one communication channel to make sure your message reaches all affected parties.

Step #5 Remedying Loss in Consumer Confidence

It’s no secret that a data breach can have severe impacts well after the initial breach has been seen. The most common impact revolves around a loss of consumer confidence which needs to be addressed by taking actions that restore public trust. By neutralizing a breach quickly and minimizing the impact of the breach, a corporation can reduce the cost of a breach. It is important to realize though that the corporate road to recovery after a business breach can be a long one, not just a costly one.

Step #6 Being Proactive Against Future Risk

The final step in handling a data breach cannot be completed, as it revolves around the continuous monitoring of a business’s implemented security, as well as continuous education on the latest data threats penetrating the industry. During this ongoing step, businesses should periodically review how their current security system stands against new threats. It is also pivotal that IT teams test if there is any room for improvement in security. Since cyber threats continuously evolve, it is crucial that a business’s security measures be taken, this way, businesses can always stay one step ahead of the latest threats.

Conclusion

When it comes to business data breaches, prevention is always better than dealing with the fallout. Unfortunately, prevention is becoming increasingly difficult to be certain of as hackers take advantage of weaknesses in new technology, technology which is being adopted at a rapid pace in response to the move towards a hybrid working environment. Thankfully, there are steps businesses can take to remedy damage and deal with the breach in the corporation’s and the public’s interest, which were outlined above.

https://bit.ly/3Di8qeh
https://bit.ly/3IFE5HO


https://guptadeepak.com/content/images/2022/03/AdobeStock_481722038.jpeg
https://deepakguptaplus.wordpress.com/2022/03/28/navigating-a-corporate-data-breach/

Thursday, March 24, 2022

How LoginRadius Creates a Perfect Harmony of UX and Security

Introduction

How LoginRadius Creates a Perfect Harmony of UX and Security

In a modern digital world where competition is neck-and-neck, creating a frictionless consumer experience should be the top priority of every business striving for success.

Brands that are delivering trusted digital experiences without compromising overall security are the ones that are highly preferred by consumers worldwide.

Moreover, amid the global pandemic, the way brands incorporated technology into their business and established frictionless interactions with consumers, the role of a robust consumer identity and access management (CIAM) solution can’t be overlooked.

Today, enterprises must be aware that the secret to success lies in quickly identifying and eliminating any troubles and pain points that occur when consumers interact with their organization (whether through website or application).

Here’s where the role of a cutting-edge CIAM solution like LoginRadius comes into play.

Let’s understand how LoginRadius paves the way for brands to deliver trusted digital experiences.

Security is Essential, Consumer Experience is Good – LoginRadius Gives You Both!

Adding stringent layers of security seems pretty unfair in a digital world where consumers are always on a hunt for a personalized and flawless user experience.

But that doesn’t mean that security can be compromised to deliver a rich user experience on a web application or a website.

Statistics show that 69% of internet users are concerned about data loss/leakage and 66% are worried about their data privacy and confidentiality.

On the other hand, 67% of consumers mentioned terrible experiences as a big reason for churn, but only a few complained.

Many people think that adding a robust layer of security would certainly hamper consumer experience and negatively impact the overall consumer onboarding journey.

So, what’s the trick that helps market leaders stay ahead of the curve? How do they secure consumer data without affecting the consumer experience?

Well, the key lies in creating a perfect harmony of security and user experience through a CIAM (Consumer Identity and Access Management) solution that helps scale business growth.

Yes, here’s the point where LoginRadius comes into action!

With industry-standard robust security, LoginRadius ensures your consumers are always catered with a trusted digital experience whether they’re interacting with your brand for the first time or the 100th time.

User Experience Backed with Security – The Key to Success in 2022 and Beyond

To keep pace with the ever-growing digital world, enterprises need to create a perfect harmony of a great user experience and robust security.

This can be achieved by leveraging a consumer identity and access management (CIAM) solution like LoginRadius.

The cutting-edge technology coupled with excellent user experience when your consumers first interact with your brand helps build consumer trust that guarantees conversion.

Whether you’re greeting your users with a personalized message or leveraging user data for product suggestions, every feature of the new-age CIAM helps your brand win consumer trust.

Moreover, the best-in-class security that comes with the LoginRadius Identity Platform assures your consumers of how vigilant you are about data privacy and security.

How LoginRadius Bridges the Gap Between Consumer Experience and Security?

At LoginRadius, we understand the importance of delivering user experience and security to our clients to ensure their clients and potential customers enjoy a frictionless experience while navigating their platform.

Here’s the list of our security features that reinforces consumer trust:

  • End-to-end SSL encryption: Protects data from unauthorized access and rogue attacks.
  • Automated security monitoring audits: Member use to prevent unwanted activity.
  • Advanced password security: Secures web and mobile applications with one-way hashing.
  • Multi-factor authentication: Strengthens account security and protects against system attacks.
  • Risk-based authentication: Strengthens account security in high-risk situations and automatically kicks a suspicious case.

Apart from this, the LoginRadius’ APIs use OpenID Connect (OAuth 2.0 protocol) technology—the same industry standard used by Google and LinkedIn.

Our legal team ensures that the LoginRadius Identity Platform adheres to strict and updated government regulations, compliances, and policies regarding information security.

Also Read: Working With Industry Authorization: A Beginner's Guide to OAuth 2.0

At the same time, we also ensure delivering the finest consumer experience by:

  • Designing the ideal customer journey: From the first step of onboarding to the thousandth login, create a welcoming and intelligent process to foster excellent customer relationships.
  • Unifying the login process with single sign-on: Easily connect your websites, mobile apps, and third-party services so that customers can interact with you everywhere using a single identity.
  • Leveraging social login: Social Login with LoginRadius supports over 40 of the most popular social ID providers globally.

Is Your Digital Experience Keeping Pace With Customer Expectations?

If you’re not delivering adequate security to your customers and your users face friction while exploring your online platform, you should rethink your overall digital experience.

Incorporating a robust CIAM solution like LoginRadius reinforces consumer information security and helps deliver a flawless user experience each time a user interacts with your brand.


Originally Published at LoginRadius

How LoginRadius Creates Trusted Digital Experiences
LoginRadius, a leading CIAM, helps brands deliver a flawless and secure user experience through its cutting-edge technology. Read on to know more.
How LoginRadius Creates a Perfect Harmony of UX and Security

https://bit.ly/37RVMqN
https://bit.ly/3Dg1Chl


https://guptadeepak.com/content/images/2022/03/digital-exp.jpg
https://deepakguptaplus.wordpress.com/2022/03/24/how-loginradius-creates-a-perfect-harmony-of-ux-and-security/

Palo Alto Networks + CyberArk: The $25 Billion Deal Reshaping Cybersecurity

Deal Overview Transaction Details : Palo Alto Networks announced on July 30, 2025, its agreement to acquire CyberArk for $45.00 in cash ...