Calls for standardized cybersecurity breach reporting 0 163

cybersecurity breach reporting

Internet security company ESET East Africa has added its voice to the call for legislation to compel organizations to share or release information to a supervisory authority, affected individuals or organizations in case of cybersecurity breaches.

According to Teddy Njoroge, ESET Country Manager in charge of Kenya, Uganda, Tanzania and Rwanda, this would help responsible branches of government, businesses as well as Cybersecurity services vendors to keep ahead of cyber-criminals.

“Due to the siloed and secretive manner in which breaches are reported in Kenya, another attack similar to ‘WannaCryptor’ ransomware could be devastating if directed to critical institutions such as health, government, and especially the financial services sector”, He said.

On Tuesday, May 17, Joe Mucheru, Cabinet Secretary in the Ministry of Information and Communication Technology (MoICT) challenged the financial services sector in Kenya to improve information sharing and reporting on Cyber-security breaches.

“Breach notification eliminates the clandestine attempts by hackers to attack systems and enables synergized efforts towards the prevention of the criminal activity as well as their prosecution”, he said.

Speaking at the Cyber-Security & Banking Forum organized by Citibank and the ICT Authority, the CS said standardized reporting would also help in quantifying the exposure and resilience of organizations both in public and private sector to cyber security incidents.

”A shared reporting system would be a welcome move in developing a unified preventive and counteractive measure to hamper the growth of malware such as ‘WannaCryptor’ and other forms of cybercrime in the country.”

The encrypting – type malware is also known as ‘WannaCry‘  or ‘Wcrypt’ that hit the world on Friday, May 14, 2017, spread rapidly around the globe by exploiting a vulnerability in computers running unpatched versions of Microsoft’s Windows Operating System.

Njoroge added that a standardized and shared reporting system would be a welcome move in developing a unified preventive or counteractive measure to hamper the growth of malware and other forms of cybercrime in the country.

“In the aftermath of ‘Wannacryptor’ ransomware attack we can see from statistics a trend that indicates potential under-reporting of both successful and unsuccessful attacks especially noting that over eighty percent of personal computers and servers in Kenya run on the Windows Operating System”, he explained.

ESET recorded eight ‘Wannacryptor attack attempts in Kenya during the period May 14th to 16th 2017. In Africa, worst hit was Egypt which recorded 1,592 attempts followed by South Africa at 386 and Nigeria at 42 attempts out of the 15 countries that registered attack attempts.

Around the globe, ESET recorded the highest number of attacks in Russia with 30,189 cases, followed by Ukraine – 7,955, Taiwan – 7736 and The Philippines at 1,973 cases and which was followed by Egypt.

“In this period 14,383 ESET clients reported 66,566 attack attempts which were all detected and stopped. 60,187 attacks were detected through file or memory detection while another 6,379 attack attempts were stopped through ESET’s Attack Network Protection module”, said Njoroge.

Previous ArticleNext Article

Security trends to look out for in 2018 0 247

After a turbulent 2017 with Cyber Security making regular headlines, looking ahead to the coming year, there will no doubt be further discussions about the threat landscape.

Ransomware Revolution  – Ransomware of Things

Technological advances and their accelerated use have led to a number of scenarios considered unlikely just few years prior, are now within the realm of possibility. The advice going into 2018 from ESET researchers is to back up everything that matters to you, often, by keeping at least some backups offline – to media that aren’t routinely exposed to corruption by ransomware and other malware – in a physically secure location. As the Internet of Unnecessarily Networked Things becomes less avoidable, the attack surface increases, with networked devices and sensors embedded into unexpected items and contexts: from routers to fridges to smart meters, from TVs to toys, from power stations to petrol stations and pacemakers. As everything gets ‘smarter’, the number of services that might be disrupted by malware becomes greater.

Criminals following the money

With data being the most valuable asset, ransomware is set to remain in great demand among cybercriminals. It is important to note that many ransomware attacks are not sophisticated enough or never intended to recover the victim’s data once the ransom has been paid. For these reasons we suggest not only backing up of data online and offline but also implementing proper security measures such as proactively training staff on what phishing emails entail and how to avoid clicking on them and entering any credentials.

Critical infrastructure attacks on the rise

Cyber attacks on the Ukrainian power companies resulted in electricity service being turned off in hundreds of thousands of homes. The implications of this for future attacks of this kind include more than just the power grid but also includes critical manufacturing and food production, water and transport and the defence and healthcare sectors.

Safer for all

This year has seen ESET’s malware analysts continue to help law enforcement crack down on malicious campaigns and, by extension, the criminals spewing them. We are confident that 2018 will bring further successful investigations as we will continue to lend a hand to authorities so that, ultimately, the internet can become a safer place for everyone – except cybercriminals.

Download the full Security Trends 2018 report here

ESET’s top 5 tips for safe online shopping this festive season 0 288

safe online shopping

Holiday shopping is so quick and easy to do online, no traffic to get to the store, no waiting in queues or travelling to one specific shop just to find out – oh no, they’re out of stock of the one item you went there for.

We want to make sure your holiday shopping experience is quick, easy and most of all safe. Here are our top 5 tips for safe shopping this festive season:

  1. Don’t have the same passwords for all online shopping sites, have strong passwords and for extra security, change them before the holiday shopping commences.
  2. Only shop on trusted sites and directly from vendors.
  3. Don’t click on links from emails, instead go straight to the site on your browser.
  4.  When shopping online use a secure internet connection such as your home WiFi and make sure the necessary firewalls are in place – Avoid online payments via public WiFi.
  5. This coupled with a strong antivirus and/or anti-spyware software for scanning email, applications, and data that resides on your computer, you can rest assured that only you will catch or detect any form of intrusion in good time.

To find out how ESET can help secure your online shopping experience visit our website or contact us at sales@esetafrica.com