Having issues accessing the video above? Watch the video here.
Data Security Basics
In this webinar, SecurityMetrics' Eric Smith, Director of Content Marketing, covers:
- The fundamentals of data security
- Data security best practices
- Recommendations to increase data security at your business
Learn more about SecurityMetrics data security solutions: https://www.securitymetrics.com/data-security
This webinar was hosted on November 14th, 2018.
Data Security Basics Transcript
Welcome everyone to today's webinar, data security basics, the what, why, and how.
My name is Andrew, and I work in marketing here at Security Metrics, and we're glad you're able to join us today. Our presenter is Eric Smith, and he is the content marketing manager here at Security Metrics. And he has a lot of experience writing content about data security.
He's written our PCI guide and HIPAA guide, and he has a lot of experience just, really explaining to both small businesses and large organizations what they can do to better improve their data security efforts and best practices at their organizations.
So he's going to share a little bit about what he's learned over the last few years and his experience.
And, just a couple of housekeeping items before we get started. So, this webinar is being recorded for your review. So if you would like to share this recording with others in your organization, feel free to do so.
And also at the conclusion of the webinar today, we will have a short q and a session. So if if you have any questions that come up during this webinar, feel free to chat those in, and we will get to as many of those as we can at the end of the webinar.
Alright. Well, with that, I'll go ahead and turn the time over to Eric Smith, and we will go from there. Thanks.
K. So to get started, I think it's always important to think about why you really want to do some data security. So this quote, it takes twenty years to build a reputation and a few minutes of cyber incident to ruin it.
And that is so true, especially you see so many breaches nowadays.
And a lot of customers, their primary concern is being able to trust, those that they share their sensitive data with. So just a little bit about us. So here at Security Metrics, we help, customers and businesses close data security and compliance gaps to help them really avoid data breaches. So our CEO, Brad Caldwell, founded our company in two thousand.
The company he worked at before had a website that was hacked. And back then, there really was no inexpensive solution to help him find out what the problem was and how to fix it. So that's really the genesis and the reason Security Metrics was founded and started.
So okay. Now let's discuss three data breaches that may have been avoided if only individuals had followed data security basics and best practices.
Okay. So here is probably one of the most classic examples of a data breach. So target's data breach, though it was a little complicated, it actually wasn't the most genius and perfect hacking of all time, and it really could have been easily avoided and prevented.
And there were multiple levels of negligence that occurred, which ended up exposing one in three Americans to identity theft.
So after investigating what really went wrong, the FireEye security system target used and had installed it had showed that, there were warnings coming to them, and it was coming all along. However, the security team in Bangalore missed them, or maybe they chose to ignore them. Honestly, the Equifax breach might have affected more than one hundred forty three million US customers, but this was another example where this breach could have been stopped.
So Equifax reportedly was breached in mid May of two thousand seventeen through a web application vulnerability.
But this vulnerability already had a patch that was available back in March of two thousand seventeen.
But because they ignored or maybe they forgot to patch their systems, they opened themselves up to such a devastating attack.
So for Uber, the hackers behind the Uber breach accessed the personal information of fifty seven million users, information including names, email addresses, and phone numbers. But more importantly, about six hundred thousand driver's license numbers of Uber users were stolen.
For this breach, Uber didn't have the right technology and processes in place.
For example, they didn't have an automated incident response in place. But had they, they likely would have known about the data breach immediately and probably they could have avoided paying such a high ransom for the sensitive data in the first place along with all the other consequences.
Here's a fun stat. The second leading cause of data breaches in recent years is employee negligence.
This is definitely a stat that you see everywhere online.
And in other places, it's actually stated as the top reason for a data breach, which is why you really need to properly train your staff. Since cybersecurity and the threats you face are constantly evolving, and as the time goes by, there are easier and more sophisticated ways criminals can access and steal your data.
For example, phishing campaigns were once fairly simple and easy to detect, but now they can be really difficult to detect. There's some cases that they actually can trick security experts.
I actually saw a recent demonstration a few years back, by this penetration tester who had a buddy try to trick him into clicking a malicious link. This pen tester, you know, he forgot his Amazon account password, so he requested a new one, opened what he thought was the account password email, and, you know, he went about his day. But then his friend later told him that he had spoofed the password email and was able to gain access to pretty much everything.
Now all phishing attacks aren't that sophisticated, but imagine how devastating that phishing attacks could be for your employees. Think about it. If a staff member clicks on a link or submits data like a username or a Social Security number, they essentially could be handing over the keys to your organization's data environment.
Honestly, it can be terrifying that something as simple as a fake email could create a point of entry for attackers to exploit your business. So keep in mind that no matter how extensive your training program is, people will make mistakes.
Back up your training program with technical security controls that prevent employees from installing malware and or visiting spoofed websites.
So over the past two years, we've interviewed over one hundred health care professionals who were responsible for HIPAA compliance.
So fifty six in two thousand sixteen and in two thousand seventeen about how they really conducted HIPAA training.
So from this graph, we see organizations really often forget the importance of actually testing their employees on training.
And so I think it was eighty two or eighty three percent of the organizations of these respondents, they had trained their employees.
But, honestly, how much do you think, you know, the average employee will remember when going through a normal workday? And especially if they're focusing on something that they're passionate about, such as in this case, helping their patients receive the best possible care.
Okay. Second point.
You likely handle and process many types of data at your business every single day. Some of it, you know, things like your inventory data, they really don't need to be protected from a compliance mandate perspective.
But there is some information that you really need to protect, such as, credit card and banking data, Social Security or other identifying numbers, birth date, address, or age, and, of course, any physical or mental health records.
First off, encryption is and should be a part of almost every service or device that we use, especially if we're going to entrust these systems with our sensitive data.
So, really, if you need to keep data on your systems for any period of time, you need to encrypt it.
Encryption renders stored data useless to attackers by turning it into an unusable string of indecipherable characters.
So, basically, a bunch of gibberish that needs to be put back together by these encryption keys.
And because of how complex encryption technology can be, it's not really a good idea to come up with your own encryption algorithms.
So it's recommended to always use industry accepted and proven encryption methods. For example, a e s one two eight, a e s two five six, or something better.
So from the stat, fifty seven percent of IT professionals believe encryption helped their organization avoid a data breach. Honestly, I think that this number should be much higher since most hackers really aren't gunning to go against organizations.
They're usually just trying to find the path of least resistance. So whatever steps you take to keep your environment secure and protected, the less likely you are to be targeted.
But if you are targeted, proper data encryption will definitely help keep your organization secure. So in another HIPAA survey we conducted, we asked whether health care professionals, if they encrypted patient data, which for them is a security must.
And, surprisingly, twenty percent of these health care organizations, they didn't know whether they even encrypted patient debt data or not, which is terrifying.
Historically, one of the largest reported threats to electronic data has been loss or theft of a physical device. While you should always make sure that you have adequate physical security and mobile device procedures in place, theft can still occur sometimes.
But that's where full disk encryption comes along. So full disk encryption is for laptops and desktops and other things, but it's very easy to utilize and usually comes with no additional cost. Since most current operating systems come equipped with this capability.
But most of these solutions rely on your login password as a key for the decryption.
This means that your full disk encryption is only as secure as your login password.
That's where you may want to consider full disk encryption software that you can be installed that does not fully rely on your login password, but you implement a second decryption passphrase.
So for mobile encryption, if you really can, avoid storing sensitive data on any type of mobile computing platform such as laptops, smartphones, tablets, etcetera, because this really helps limit the threat of a data breach altogether.
But if you do need to store data on these devices, you need to be careful because encryption software may not be as readily available and easy to to maintain from a corporate perspective.
Also, remember, if you do backup your mobile device on your hard drive, ensure that these backups are also encrypted.
To make sure that you've properly encrypted sensitive data on your system, you really need to run a data discovery tool regularly.
These tools can really help search specifically for unencrypted sensitive information such as Panscan or Pyscan from Security Metrics.
Panscan searches specifically for unencrypted card data. Pyscan can search for this data as well, but they can search for other sensitive data such as Social Security and insurance numbers.
Over the years, we've actually conducted a number of studies on, our tool, Panscan, that searches for unencrypted primary account numbers or PAN, so a lot of credit card information. And I believe that as of early two thousand eighteen, Panscan has discovered over one point six billion unencrypted primary account numbers. And the trends of Panscan users finding unencrypted card data on their network has really stayed consistent over the years.
So for two thousand eighteen, sixty nine percent of security metrics pan scan users found unencrypted card data on their network.
And so these are people who are trying to find data.
And those who don't search for it, they may have even more. It's just very hard to say. But whatever you do decide to do, make sure to thoroughly examine your network for unencrypted sensitive data. So third tip.
So there's really no silver bullet when it comes to preventing data breaches, but working to protect your data and secure your network vulnerabilities is a vital job. So having the right tools can mean the difference between a data breach and business as usual. In this section, we'll discuss some basic cybersecurity tools and how they can help you.
So first tool, firewalls. So network firewalls are vital for your security. A firewall's purpose is to filter potentially harmful Internet traffic to protect your sensitive data.
But simply installing a firewall on your organization's network perimeter doesn't make you secure, though it's definitely an important step in the right direction. Remember, only manage the firewall from within your network.
Disable external management services unless it's part of a secure managed firewall infrastructure.
Second tool, antivirus software.
Antivirus software offers an additional layer of security to any system within a network.
Antivirus software needs to be installed on all systems that are commonly affected by malware regardless of its location.
Make sure antivirus or anti malware programs are updated regularly so that it can detect known malware. Maintaining an up to date anti malware program will help you prevent known malware from infecting your systems.
K. So third, intrusion detection and prevention systems.
So one of the reasons data breaches are so prevalent these days is a lack of proactive comprehensive security that's dedicated to monitoring your system's irregularities.
So things such as intrusion detection systems, AKIDS, or intrusion prevention systems, AKIPS.
So using these systems can help you identify a suspected attack and help you locate security holes in your network that attackers use.
Without the knowledge derived from IDS logs, it can be extremely difficult to find system vulnerabilities and determine if cardholder data or other sensitive data has actually been accessed or stolen.
So by setting up your alerts on an IDS, you can actually be warned as soon as suspicious activity is identified and be able to significantly minimize compromised risk within your organization.
An IDS could even actually help you detect a security breach as happening in real time.
But keep in mind that an IDS isn't really preventative.
Similar to something like a private investigator, an intrusion detection system doesn't interfere with what it observes.
It simply follows the action, takes pictures, records conversations, and alerts their client. So if you want some more preventative measures, you might consider an intrusion prevention system, which also monitors networks for malicious activities, logs this information, and reports on it. But it goes further, so it can actually help prevent and block many of these intrusions that it detects. And in IPS, they can also help drop malicious packets, block traffic from the malicious source address, and help you reset connections.
So another one is vulnerability scanning. So not only should you use security tools to monitor your systems in real time, you need to know your network environment and find weaknesses through tools like external and internal vulnerability scans.
Vulnerability scanning is considered by almost every security expert as one of the best ways to find potential vulnerabilities.
Vulnerability scans assess computers, systems, and networks for exposed security weaknesses, you know, also known as vulnerabilities.
These scans are typically automated and give you an introduction into what could possibly be exploited in your environment.
Keep in mind, vulnerability scans are more of a passive approach to vulnerability management because they don't go behind and beyond reporting vulnerabilities that are detected. So it's really up to your organization's risk or IT staff to patch discovered weaknesses on a prioritized basis to log monitoring.
You should collect and regularly analyze system event application and access logs even though this really isn't always the case.
But these logs, they record stuff, from computer systems like servers, firewalls, office computers, networking hardware, and printers.
So think of log monitoring almost like a watchman on a watchtower.
So this log information can really help warn you of potential danger and attacks as well as help you figure out what happened after, a compromise has occurred and what data the hackers may have actually accessed.
So log files can actually be a great resource of information for your data security program, but that's really only if you review them, and you need to review them regularly.
Honestly, these log files need to be reviewed daily.
So if you simply go out and purchase a and deploy a log management solution, you really won't receive that additional security you're looking for.
So you need to make sure to also take time to correctly configure your alerts to make sure that it fits your own specific environment and, of course, constantly making sure that you're not forgetting to review what pops up.
Okay.
Fourth point for following compliance mandates. So based on the type of data your company handles will really determine which compliance regulation that you'll likely need to follow.
For example, if you handle credit card data, you need to follow the PCI DSS.
Becoming PCI compliant can seem like a frustrating compliance, especially if you're a small to medium sized business.
Just to give you a quick overview of PCI. So PCI was kind of founded by Visa, Mastercard, and American Express with these card brands just wanting to come up with regulation to help businesses and customers avoid card data theft and fraud.
So they created a council, so paint the Payment Card Industry Security Standards Council or PCI See?
They created a standard, so PCI DSS.
So the PCI DSS is a set of twelve specific requirement areas, or I guess you could call them card handling best practices that have to be followed to handle and process payment card data securely.
So because it's an industry standard, anyone that's accepting credit card payments needs to meet these standards.
Okay. So for securing the privacy and security of protected health information or PHI, that's one of the major concerns of HIPAA or the Health Insurance Portability and Accountability Act, which is law in the United States. So there are two specific rules that relate to privacy and cybersecurity best practices.
So the HIPAA privacy and security rules.
These rules really are meant to help protect electronic health care data from being compromised.
And, you know, this compromise can happen as a result of a hacker, unauthorized access, or employee negligence.
And it's important for health care organizations to focus on their data security because breaches aren't going away. And in fact, in recent years, it's on a trend of upwards.
So because of all of the personal information that is likely stored in health care systems and its potential use in identity theft, there are a lot of criminals targeting this information.
The GDPR or the general data protection regulation, it replaces the EU's data protection directive and is meant to help unify data privacy laws across Europe and strengthen EU citizens' data privacy.
The GDPR applies to any organization that handles, processes, or stores personally identifiable information or PII of EU citizens.
PII is data that's kept by an organization which can be used to distinguish or trace an individual's identity.
So PII could include things like names, birth dates, birthplaces, mother's maiden's names, addresses, emails, IP addresses, or Social Security and insurance numbers.
So whether your business is located in the EU or not, if you have customers from the EU, this regulation likely applies to you.
K. So the fifth point, you need to be ready to react. So no organization wants to find themselves in the middle of a data breach, but how you prepare for that possibility can determine how much damage it ultimately causes.
For well prepared businesses, they can really diminish bad press, reduce negative impacts, and potentially lower their fines.
So, again, although it's not always the funnest thing to think about, it's critical to be prepared for your organization to be breached.
That's why you do need a planned response that is easy to execute and that's also thoroughly designed and followed.
So here are some five basic steps you should take after a data breach.
So the first step, carry out your response and mitigation steps. Second, stop the attack and contain the threat to privacy and security of your sensitive data and your system.
Third, report the incident to law enforcement.
Fourth, submit the relevant cyber threat indicators to federal and information sharing and analysis organizations.
Fifth, notify the necessary and relevant mandate bodies, agencies, organization, and forces as quickly as possible, such as the OCR for HIPAA related breaches, super advisory authorities for GDPR breaches, and the PCI Council for credit card breaches.
And I think this is a great overall message and thought when assessing your own security posture. So for every lock, there's someone out there trying to break it or break in.
That's why data security is not a single check the box goal or moment in time or process. Rather, it is a continual process that's always evolving and changing just like your own business.
Alright. Thanks, Eric, for taking that time to explain some data security best practices to us.
At this time, we're gonna go ahead and take any questions that you may have.
So if you wanna go ahead and chat those in, we'll take just a minute, and then we'll be right back to answer your questions. Thanks.
Okay. It looks like we have a question coming in, asking about the difference between vulnerability scanning and penetration testing.
So we we talked a little bit about vulnerability scanning, but we didn't touch much on pen testing. So, Eric, do you have any thoughts on kind of the difference between the two and, what situation might call for a pen test versus a vulnerability scan?
So yeah. Vulnerability scanning, it's, again, more kind of a automated process, and it just goes through every security and vulnerability issues it can find.
So sometimes it it will give you some more false positive results and at least issues according whatever according to whatever vendor you go with.
Well, penetration testing is much, much more thorough. It's almost like having a hacker go through and checking your organization's security.
But instead of, you know, having the negative results, they tell you exactly what the issue is and give an even more thorough way for you to help your organization.
And and just also an important note, a number of organizations do try and pass off a vulnerability scan as a penetration test, because another huge difference is vulnerability scanning is a whole lot cheaper because it is a machine, and an automated scan compared to a penetration test is a person. So, you know, with penetration testing, it is a a little bit higher, but you do get a more thorough analysis of your environment.
So if you think that it's too cheap, it probably is for a penetration test, and they're probably trying to pass off a vulnerability scan as that.
K. Awesome. Thanks, Eric.
K. Another question that we have coming in, we have a question about, additional resources, in particular, some employee trainings and, kind of an an area where organizations can go for more information.
So for that, I'll go ahead and pass it over to Eric as well.
K.
So it all depends on what you're looking for. Are if you're looking specifically for employee trainings, we offer some great trainings in GDPR, PCI, and HIPAA compliance, which are fantastic for, you know, your Joe Schmoe and your company.
But for, more information in general on data security, so that way you can get, an even more in-depth look into what you should be doing.
We've come out with a great resource, so Security Metrics Academy.
There's either one course where it goes through pretty much every single aspect you could think about for, you know, the basics, and that's, you know, three hour course.
We also have broken that down into five courses that are smaller. So they're, you know, thirty thirty five minutes each.
So that way, if you really want to drill down in a specific area, like, okay. I really wanna know more about security tools or, okay, policies and procedures.
That way, you can just focus on that. We also have some other resources. So we've got for if you're curious about PCI compliance, we have created a PCI guide.
And for HIPAA, a HIPAA guide that goes those both go through the major issues and topics covered in for those requirements.
Awesome. Well, thanks, Eric.
That looks like all the questions we have for today.
Thanks again for your attendance. Again, if you'd like to review this webinar, we have been recording it. And And if you have any follow-up questions for us, you can always send us an email at events at security metrics dot com.
Thanks, everyone, and we'll see you next time.
