<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Alan Levine Archives - International Finance</title>
	<atom:link href="https://internationalfinance.com/tag/alan-levine/feed/" rel="self" type="application/rss+xml" />
	<link>https://internationalfinance.com/tag/alan-levine/</link>
	<description>International Finance - Financial News, Magazine and Awards</description>
	<lastBuildDate>Fri, 13 Dec 2019 11:00:07 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.7</generator>

<image>
	<url>https://internationalfinance.com/wp-content/uploads/2020/08/favicon-1-75x75.png</url>
	<title>Alan Levine Archives - International Finance</title>
	<link>https://internationalfinance.com/tag/alan-levine/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Shielding Fortune 500 companies from cyberattacks</title>
		<link>https://internationalfinance.com/magazine/may-june-2018/shielding-fortune-500-companies-from-cyberattacks/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=shielding-fortune-500-companies-from-cyberattacks</link>
					<comments>https://internationalfinance.com/magazine/may-june-2018/shielding-fortune-500-companies-from-cyberattacks/#respond</comments>
		
		<dc:creator><![CDATA[Bharath Kumar]]></dc:creator>
		<pubDate>Mon, 28 May 2018 07:23:09 +0000</pubDate>
				<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[Magazine]]></category>
		<category><![CDATA[May - June 2018]]></category>
		<category><![CDATA[Alan Levine]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Fortune 500]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Phising]]></category>
		<category><![CDATA[Wombat Security]]></category>
		<guid isPermaLink="false">https://www.internationalfinance.com/magazine/?p=2865</guid>

					<description><![CDATA[<p>Alan Levine, security advisor of Pennsylvania headquartered Wombat Security, with offices in Colorado and the UK, talks about the rise of cyber threats in business and how Fortune 500 can protect their valuable assets.</p>
<p>The post <a href="https://internationalfinance.com/magazine/may-june-2018/shielding-fortune-500-companies-from-cyberattacks/">Shielding Fortune 500 companies from cyberattacks</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><span style="color: #000000;"><span style="font-size: large;">Cyber security has become a matter of utmost importance in today’s digital world. With the growing number of cyber threats and breaches, every company, big or small, try to fortify their security walls to prevent cyber attackers from breaching their network. However, despite having substantial security measures that are way stronger than the other companies, Fortune 500 companies are more susceptible to cyberattacks.</span></span></p>
<p><span style="color: #000000;"><span style="font-size: large;">Many of these Fortune 500 companies have reported an increase in instances of fraud or attempted fraud through wire transfer payments. Several c</span></span><span style="color: #222222;"><span style="font-size: large;">yber threat factions have been engaging in a widespread Business Email Compromise (BEC) scams against Fortune 500 companies since autumn last year.</span></span></p>
<p><span style="color: #000000;"><span style="font-size: large;">The threat groups have been successfully using BEC scams, which utilise credential harvesting, phishing and social engineering, to persuade account holders to initiate fraudulent wire transfers into attacker-controlled accounts, resulting in the theft of millions of dollars.</span></span></p>
<h2><span style="color: #000000;"><span style="font-size: large;">Delving deeper into the mechanism of cyber attacks is security expert Alan Levine:</span></span></h2>
<ul>
<li>
<p align="justify"><span style="font-size: large;"><b>Despite having advanced cyber security technologies, Fortune 500 companies still face cyber threats. What are the types of threats they are seeing and how do they occur?</b></span></p>
</li>
</ul>
<p><span style="font-size: large;">Business Email Compromise (BEC) is an attack vector that is seeing substantial growth; Trend Micro for example has predicted that impact from this particular form of phishing will increase by more than $9bn in 2018.</span></p>
<p><span style="font-size: large;">Companies in the Fortune 500 have reported a significant increase in instances of fraud or attempted fraud via wire transfer payments. Cyber threat groups have been successfully using BEC scams, which utilise credential harvesting, phishing and social engineering, to convince finance and accounts payable personnel to initiate fraudulent wire transfers into attacker-controlled accounts, resulting in the theft of millions of dollars. </span></p>
<p><span style="font-size: large;">It must be said, however, that although there has been a lot of focus on the risk to Fortune 500 companies from BEC, they are not by any means the only targets; all companies are at risk.</span></p>
<p><span style="font-size: large;">What is even more concerning is that attacks exploiting users may become more successful over the next decade. Wombat’s <a href="https://www.wombatsecurity.com/state-of-the-phish">2018 State of the Phish Report</a></span> <span style="font-size: large;">found that Millennials are less able to recognise phishing attacks than their older Baby Boomer colleagues.</span></p>
<ul>
<li>
<p align="justify"><span style="font-size: large;"><b>How do they resolve these threats?</b></span></p>
</li>
</ul>
<p><span style="font-size: large;">To defend against BEC, individuals in financial roles need to be specifically trained to identify and fend off these scams, which are particularly tricky to avoid because they are set up over time, with cyber criminals researching their targets and then building trust via multiple channels (phone, email, and social media). </span><span style="font-size: large;"><span lang="en-GB">There are specific things that Fortune 500 organisations can teach their end users to defend against the BEC threat:</span></span></p>
<ul style="list-style-type: circle;">
<li><span style="font-size: large;"><span lang="en-GB">All employees should be made aware of the dangers of sharing too much on social media. Teach users that they can’t always trust the legitimacy of their social contacts.</span></span></li>
<li><span style="font-size: large;"><span lang="en-GB">Ask users not to give out company-internal information — like mobile phone numbers, vacation schedules, and job titles — when they receive unsolicited emails or phone calls. They need to understand that criminals can use seemingly innocuous data points against your organisation. </span></span></li>
<li><span style="font-size: large;"><span lang="en-GB">Stress the need for users to verify all requests for wire transfers and highly sensitive data (like employee tax information). It’s a great idea to implement a ‘non-technical’ form of two-factor authentication with high-value targets, such as employees who can initiate wire transfers. For example, make it a policy that all such requests require voice-to-voice confirmation — via an established phone number — before financial transactions are facilitated.<br />
</span></span></li>
</ul>
<ul>
<li><strong><span style="font-size: large;">Cyber security is of top concern in countries all around the globe. US Homeland Security Secretary Kirstjen Nielson has also mentioned that her agency is making election cyber security top priority in an attempt to prevent foreign interference in this year’s elections. What is your outlook on this scenario? How can we advance cyber security so elections are secured?</span></strong></li>
</ul>
<p><span style="font-size: large;">Good cybersecurity is not one thing; it is a combination of elements, involving people, processes, and technology. Every cyberattack has a source, a vector, and a target. We should assume that nation states are sometimes the source of cyberattacks aimed at election interference. Their targets are the digital systems used to input and calculate election results.</span><br />
<span style="font-size: large;">We can try our best to thwart attackers by strengthening the technical defences of digital election systems. But, foremost, we should understand the common vector for these – and most other – cyberattacks. Even one malicious email, sent to IT personnel who administer an election system, can result in the compromise of their computer and then, via the exploitation of these assets, the extended compromise of an entire election system. While we deploy technology to defend election systems and develop processes to support those defences, we must place greater value on the impact, good and bad, of the very people who are central to those defences.</span></p>
<p><span style="font-size: large;">Thus, we should focus our efforts on the vector: emails that launch an attack and facilitate every devastating thing that may follow. If IT administrators and, indeed, all users, are trained to identify and report potentially malicious emails, then the very start of attacks against election systems can be stopped. Addressing the email vectors for cyberattacks means training the people who receive, read, and react to those emails, so that they know what to do, and do it with diligence everytime.</span></p>
<ul>
<li><span style="font-size: large;"><b>Do you think that better government intervention in cyber security will secure companies from cyber threats?</b></span></li>
</ul>
<p><span style="font-size: large;">It is great to see the UK’s National Cyber Security Centre adopting a much more active posture in helping defend the UK from the range of cyber threats facing the country. Closer partnerships have now been formed with government, industry and law enforcement by prioritising cybersecurity. However, ultimately it isn’t solely through government intervention and enforcement that organisations will become secure; security has to form part of any business’s DNA and includes a mixture of people, process and technology. Cyber criminals will always identify and attack the weakest links; therefore, businesses should work together to create a virtual ‘fence’ to limit the potential attack surface and subsequent effectiveness of cyberattacks.</span></p>
<ul>
<li><span style="font-size: large;"><b>What can be done differently to change the cyber security scenario all across the globe?</b></span></li>
</ul>
<p><span style="font-size: large;">There’s no doubt that organisations are under a greater threat from cybercriminals than they’ve ever been, and this is unlikely to simply drop off. For example, Wombat Security’s ‘<a href="https://www.wombatsecurity.com/state-of-the-phish">2018 State of the Phish Report</a></span>’<span style="font-size: large;"> found that 76% of organisations experienced phishing attacks in 2017. In addition, organisations are reporting more security impacts stemming from email-based social engineering. </span></p>
<p><span style="font-size: large;">There is no silver bullet when it comes to solving the challenge that cybercrime presents. However, a user who receives continuous cybersecurity training &#8211; and is therefore cyber-aware &#8211; is less likely to commit risky behaviours, and is more likely to spot and report suspicious activities. Don’t underestimate the power of educated users – effective training offers clear, measurable benefits for cyber risk reduction.</span></p>
<p><span style="font-size: large;">When strong technical defences are combined with an ‘army’ of knowledgeable users, organisations will prevent more successful attacks and chip away at the profitability of cybercrime, thus slowing its growth. </span></p>
<ul>
<li><span style="font-size: large;"><b>Is there any way for companies to augment their cyber security to an extent that cyber threats won’t stand a chance to breach into advanced systems?</b></span></li>
</ul>
<p><span style="font-size: large;">No system in the world is completely invulnerable to attack, but one of the most positive changes a company can make is to invest in its people. No company should rely on cyber security technologies alone. What’s needed is a layered approach that embraces a mixture of both technical safeguards and end user cybersecurity training and awareness. </span></p>
<p><span style="font-size: large;">Shockingly, according to the Online Trust Alliance’s (OTA) ‘<a href="https://otalliance.org/system/files/files/initiative/documents/ota_cyber_incident_trends_report_jan2018.pdf">Cyber Incident and Breach Trend Report</a></span>’<span style="font-size: large;">, 93% of cybersecurity incidents in 2017 could have been prevented by following basic security best practices, such as conducting phishing awareness training. With so much at stake financially and reputationally, organisations cannot afford to allow data breaches or damaging service outages to occur because of human error. Employees are a corporation’s last line of defence against cyberattacks, so they must be given the right skills and tools to effectively participate in the fight against cybercrime.</span></p>
<p>&nbsp;</p>
<p><span style="font-size: large;"><b> <img fetchpriority="high" decoding="async" class="size-medium wp-image-2867 alignleft" src="https://www.internationalfinance.com/magazine/wp-content/uploads/2018/05/Alan-Levine-259x300.jpg" alt="" width="259" height="300" srcset="https://internationalfinance.com/wp-content/uploads/2018/05/Alan-Levine-259x300.jpg 259w, https://internationalfinance.com/wp-content/uploads/2018/05/Alan-Levine-345x400.jpg 345w, https://internationalfinance.com/wp-content/uploads/2018/05/Alan-Levine.jpg 483w" sizes="(max-width: 259px) 100vw, 259px" />About Alan Levine</b></span></p>
<p><span style="font-size: large;">Alan Levine</span><span style="font-size: large;"> is a </span><span style="color: #000000;"><span style="font-size: large;">security advisor of Wombat Security </span></span><span style="font-size: large;">with extensive global experience and has specialisation in all facets of cyber security</span><span style="font-size: large;">, g</span><span style="font-size: large;">lobal data privacy with emphasis on European privacy provisions</span><span style="font-size: large;">, </span><span style="font-size: large;">Compliance, including SOX and related corporate compliance requirements.</span></p>
<p>&nbsp;</p>
<p>The post <a href="https://internationalfinance.com/magazine/may-june-2018/shielding-fortune-500-companies-from-cyberattacks/">Shielding Fortune 500 companies from cyberattacks</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/magazine/may-june-2018/shielding-fortune-500-companies-from-cyberattacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Cybercrime: How RBS fought back</title>
		<link>https://internationalfinance.com/technology/cybercrime-rbs-fought-back/#utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=cybercrime-rbs-fought-back</link>
					<comments>https://internationalfinance.com/technology/cybercrime-rbs-fought-back/#respond</comments>
		
		<dc:creator><![CDATA[Bharath Kumar]]></dc:creator>
		<pubDate>Fri, 13 Oct 2017 11:17:56 +0000</pubDate>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Alan Levine]]></category>
		<category><![CDATA[equifax]]></category>
		<category><![CDATA[RBS]]></category>
		<category><![CDATA[Wombat Security]]></category>
		<guid isPermaLink="false">https://www.internationalfinance.com/?p=10584</guid>

					<description><![CDATA[<p>Royal Bank of Scotland brought down click rates on simulated phishing emails from 47% in August 2016 to 22% in October 2016</p>
<p>The post <a href="https://internationalfinance.com/technology/cybercrime-rbs-fought-back/">Cybercrime: How RBS fought back</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Cyber-crime is growing exponentially. At the end of last month, <a href="http://breachlevelindex.com/assets/Breach-Level-Index-Report-H1-2017-Gemalto.pdf">Gemalto’s Breach Level Index</a> found that there had been 918 reported data breaches leading to the exposure of 1.9 billion data records worldwide. These statistics represent an increase of 164% from last year. This is a clarion call for better cyber defence, and why Cyber-Security Month (i.e. October) is so important. Raising awareness of cyber-crime and, perhaps even more importantly, demystifying it for those who don’t work in cyber-security or IT is important because it really is everyone’s problem.</p>
<p>No one is safe from the threat of cyber-attacks, but the financial services are one of the most vulnerable sectors, with banks arguably an especially lucrative target. We can clearly see this with the DDoS attack on Lloyd’s Bank where criminals stole more than $1bn from banks between 2013-2015.</p>
<p>A <a href="http://www.independent.co.uk/news/business/news/cyber-crime-financial-institutions-risk-bank-investment-management-finance-attack-wannacry-a7761381.html">recent survey</a> of senior professionals working in retail banks, investment banks and asset management firms found that 44% of those surveyed saw evolving criminal methodologies, namely cyber-crime, as the largest crime-related financial risk to their businesses. The survey found that 87% of organisations feel their businesses aren’t able to enhance their technology fast enough to fight back against evolving cyber-crime. But, a lesson that we’re increasingly learning is that technology isn’t the only answer. No matter how much technology you have in place defending your organisation’s network, if a user clicks on a malicious link or opens a malicious file, the cyber-criminals have found their way in.</p>
<p>Our research has pulled up some concerning statistics about end-users in finance. Our <a href="https://info.wombatsecurity.com/state-of-the-phish">State of the Phish Report</a> found that, in insurance, there is a 20% click rate on consumer based simulated phishing emails and a 17% click rate on commercial based simulated phishing emails.</p>
<p>Furthermore, our <a href="https://info.wombatsecurity.com/beyond-the-phish">Beyond the Phish Report</a> analysed different industries’ general cyber-security knowledge and, on average, those working in finance answered 21% of questions incorrectly.</p>
<p>It’s  impossible to reduce click rates to 0% but in industries like the financial sector where huge sums of money and a plethora of people’s incredibly sensitive details are at stake, the fact that these percentages are in the double figures is simply not acceptable.</p>
<p>A really interesting recent example, which has been dealt with in a very forward thinking manner by the US Congress, is Equifax. Credit company Equifax exposed Personally Identifiable Information (PII) from 145.5 million customers due to what Congress termed a ‘lax attitude’ to protecting consumers’ data. It’s really interesting that while the ex-CEO of Equifax Richard Smith blamed both ‘human error’ and ‘technology errors’, Congressman Frank Pallone didn’t recommend that Equifax up its security technology bur rather claimed that, “… its entire corporate culture needs to change to one that values security and transparency”. Starting to see why cyber-security month is so important?</p>
<p>‘Lax attitudes’ are a huge part of the reason why cyber-criminals are so successful, and this can be challenged by cyber-security awareness and training from the ground up to the board. No one should be exempt. Employees should be a vital part of every security strategy because if technology fails, they’re the organisations’ last line of defence.</p>
<p><strong>People as the Last Line of Defence</strong></p>
<p>As a former CISO of a Fortune 500 company, I’m one of the many cyber-security professionals that learnt the hard way that you can’t rely on technology to protect your organisation against attack. Cyber defence technology is complex and expensive and is especially designed to thwart the next attack – but, the data doesn’t lie. Cyber defences aren’t perfect because hackers will always find the weakness and exploit it. And when this happens it will be up to the user to make the right choice: click on a link or don’t. It was a simple click that brought my previous company’s heavily fortified cyber-security defences to its knees.</p>
<p>We need to understand that all computer users are the fulcrum of the current and expanding cyber storm, and that there are steps we can take toward threat mitigation and damage containment. One of the most important pieces of advice that I can give is that we should crystallise our confidence that users will do the right thing if they know the right thing. It is a C-Level responsibility to focus on elevating user understanding of threats so that everyone appreciates their role in cyber defence.</p>
<p><strong>End user focused: The Royal Bank of Scotland</strong></p>
<p>As I said before, no one is perfect. But, there are certain steps that forward thinking organisations are taking that are positioning them as cyber-security leaders. The Royal Bank of Scotland (RBS) is one such organisation.</p>
<p>RBS saw that they were experiencing an increase in ‘drive by’ malware entering their system via email. So they implemented an ongoing and effective security awareness programme to improve the bank’s 80,000 email users’ cyber-security skills. RBS initiated the training project in February 2016 and the results were staggering, with employee click rates on simulated phishing emails plummeting from 47% in August 2016 to 22% in October 2016. Today, RBS are operating at a click rate of under 10% and are showing that banks can, and will, fight back.</p>
<p>Cyber awareness programmes are the key to unlocking user sensitivity. Educating users on what to do and what not to do should be a fundamental element of every enterprise cyber security programme. The alternative is clear: If we don’t raise awareness, if we don’t appreciate the key role users play in cyber defence, and if we fail to train our users as frontline soldiers in our cyber defence programmes, then those initiatives are bound to fail.</p>
<p>And when cyber defence programmes fail, our users fail us and we fail our users. Then, in time, each of us will sadly be among the next cyber security statistics.</p>
<p><strong><em>Alan Levine is Security Advisor to Wombat Security</em></strong></p>
<p>The post <a href="https://internationalfinance.com/technology/cybercrime-rbs-fought-back/">Cybercrime: How RBS fought back</a> appeared first on <a href="https://internationalfinance.com">International Finance</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://internationalfinance.com/technology/cybercrime-rbs-fought-back/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
