Welcome!

Cloud Security Authors: Elizabeth White, Liz McMillan, Pat Romanski, Zakia Bouachraoui, Yeshim Deniz

Related Topics: Cloud Security, Agile Computing, @CloudExpo

Cloud Security: Blog Feed Post

The Anthem Data Breach By @Vormetric | @CloudExpo [#Cloud]

Assumptions and allegations abound

The Anthem Data Breach-Assumptions and Allegations Abound
By Charles Goldberg

I’m writing this blog on Monday, February 9th, late afternoon with a very full stomach. Last week we launched Vormetric Tokenization with Dynamic Data Masking and today we took the engineers out for a big lunch to celebrate. Now feeling full and contemplative, I thought I’d join the club and write about the big industry news: Anthem’s massive loss of customer and employee data.

A lot’s happened since February 4, when Anthem announced the breach. Here are just a few groups that have been keeping busy:

Anthem phishing email as captured by Brian Krebs

  • Scammers. The hackers are working fast in using their new-found treasure trove of data. According to Anthem’s FAQ and several news sources, emails are already being sent claiming to offer “Free credit monitoring from Anthem.” But beware, these emails are scams to collect more information—Anthem is only sending snail mail on this matter. As an aside, since credit card information wasn’t stolen in this data breach, I’m not convinced that credit monitoring services have much value other than placating customers and auditors.
  • Regulators. Regulators and state governments moved quickly to launch investigations. On February 6, The National Association of Insurance Commissioners (NAIC) announced immediate action calling for a multi-state examination of Anthem, Inc. and its affiliates.
  • Lawyers. No surprise, the lawyers are working even faster! According to Fortune magazine, just days after the breach announcement, suits were filed in Alabama and California. The suits claim that Anthem didn’t adequately protect exposed customer data.
  • Journalists. In the days following the announcement, there has been a lot of conjecture about what went wrong at Anthem. What most of the news is circling around is The Wall Street Journal’s report that Anthem “encrypts personal data when it moves in or out of its database but not when it is stored, which is common in the industry.” This was backed up by Wired and other publications, with statements like, “Apparently the data breaches of Target, Sony, Home Depot and a host of others weren’t sufficient to convince Anthem to encrypt patient Social Security numbers.”

So what happened in the days preceding the announcement, and when did the breach actually occur? There is a lot of conjecture on this front as well. According to the Associated Press, the attacks were first detected on December 10 and continued until January 27. However, other analysis shows the attacks started in April 2014, as Brian Krebs effectively documents. In other words, it seems pretty clear that Anthem has no idea who took what and when.

Most of the reports are accusing China as the perpetrator. There are many different theories flying around about how the hackers gained access. Almost all the theories being published point to the stolen credentials of privileged users, which is common for most advanced persistent threat (APT) attacks. Other published reports and theories include the compromise of the credentials of Anthem executive(s).

In recent days, a lively on-line debate has emerged, with many arguing about whether “encryption” would have kept Anthem out of the news. Even as an employee of an encryption vendor, I’m here to say, “No”. The reality is that encryption alone probably wouldn’t have saved Anthem. What Anthem really needed was a data-centric security strategy. A strategy that would have focused on encrypting sensitive data, as well as controlling and tracking access to that data.

I would even take it a step further: For valuable data, such as Social Security numbers, employ granular and additional layers of control. Anthem claims customer Social Security numbers need to be in the database because it is the unique customer and employee identifier. That type of information should have additional layers of control, such as dynamic data masking. The reality is probably that more than 99% of Anthem employees don’t need to see the entire Social Security number, ever, including their executives (perhaps especially their executives who are primary targets for hackers). For the small subset of employees who do have to see Social Security numbers, most would be able to do their jobs by seeing only the last four digits, so why give them more.

The last 12 months have seen a continuous flow of high-profile organizations reporting that their security has been breached, including data theft by employees and the compromise of insider credentials. If you think the headlines are anomalies, think again. We have recently partnered with Harris Poll and Ovum surveying over 800 IT professionals globally to pinpoint risks, security stances and insights into how organizations can keep from becoming a statistic. The results of the 2015 Vormetric Insider Threat Report reflects that over 40% of organizations globally reported that they had either experienced a data breach or failed a compliance audit in the past, and that 50% are putting their budget in data breach prevention.

Responses to data breaches 2015 global insider threat

Here’s the point: Companies that hold personally identifiable information (PII) need to take a close look at who can access that information and who needs to access it. It isn’t very hard to restrict and track that access with the right tools. If you leverage a data-centric security platform, one that can encrypt, tokenize, and mask sensitive data, and provide granular control over privileged user access, it doesn’t even need to come with a high total cost of ownership.

Vormetric has the most flexible data-centric security platform on the market today. Consider learning more about it if you are holding PII, and you don’t want to read an article in the Wall Street Journal reporting how you lost it. If you think there is a better way to secure your customer data in your environment, please pursue that solution. (As a customer of Anthem, Home Depot, Target, and maybe your business as well, I’d personally appreciate any improvements in this area.) Because, if the news of the past week, let alone the past year, makes anything clear, it is that keeping this PII data in the clear is clearly unacceptable.

The post The Anthem Data Breach—Assumptions and Allegations Abound appeared first on Data Security Blog | Vormetric.

Read the original blog entry...

More Stories By Vormetric Blog

Vormetric (@Vormetric) is the industry leader in data security solutions that span physical, big data and cloud environments. Data is the new currency and Vormetric helps over 1400 customers, including 17 of the Fortune 30 and many of the world’s most security conscious government organizations, to meet compliance requirements and protect what matters — their sensitive data — from both internal and external threats. The company’s scalable Vormetric Data Security Platform protects any file, any database and any application’s data —anywhere it resides — with a high performance, market-leading data security platform that incorporates application transparent encryption, privileged user access controls, automation and security intelligence.

IoT & Smart Cities Stories
At CloudEXPO Silicon Valley, June 24-26, 2019, Digital Transformation (DX) is a major focus with expanded DevOpsSUMMIT and FinTechEXPO programs within the DXWorldEXPO agenda. Successful transformation requires a laser focus on being data-driven and on using all the tools available that enable transformation if they plan to survive over the long term. A total of 88% of Fortune 500 companies from a generation ago are now out of business. Only 12% still survive. Similar percentages are found throug...
CloudEXPO has been the M&A capital for Cloud companies for more than a decade with memorable acquisition news stories which came out of CloudEXPO expo floor. DevOpsSUMMIT New York faculty member Greg Bledsoe shared his views on IBM's Red Hat acquisition live from NASDAQ floor. Acquisition news was announced during CloudEXPO New York which took place November 12-13, 2019 in New York City.
OpsRamp is an enterprise IT operation platform provided by US-based OpsRamp, Inc. It provides SaaS services through support for increasingly complex cloud and hybrid computing environments from system operation to service management. The OpsRamp platform is a SaaS-based, multi-tenant solution that enables enterprise IT organizations and cloud service providers like JBS the flexibility and control they need to manage and monitor today's hybrid, multi-cloud infrastructure, applications, and wor...
The Master of Science in Artificial Intelligence (MSAI) provides a comprehensive framework of theory and practice in the emerging field of AI. The program delivers the foundational knowledge needed to explore both key contextual areas and complex technical applications of AI systems. Curriculum incorporates elements of data science, robotics, and machine learning-enabling you to pursue a holistic and interdisciplinary course of study while preparing for a position in AI research, operations, ...
Codete accelerates their clients growth through technological expertise and experience. Codite team works with organizations to meet the challenges that digitalization presents. Their clients include digital start-ups as well as established enterprises in the IT industry. To stay competitive in a highly innovative IT industry, strong R&D departments and bold spin-off initiatives is a must. Codete Data Science and Software Architects teams help corporate clients to stay up to date with the mod...
Tapping into blockchain revolution early enough translates into a substantial business competitiveness advantage. Codete comprehensively develops custom, blockchain-based business solutions, founded on the most advanced cryptographic innovations, and striking a balance point between complexity of the technologies used in quickly-changing stack building, business impact, and cost-effectiveness. Codete researches and provides business consultancy in the field of single most thrilling innovative te...
Atmosera delivers modern cloud services that maximize the advantages of cloud-based infrastructures. Offering private, hybrid, and public cloud solutions, Atmosera works closely with customers to engineer, deploy, and operate cloud architectures with advanced services that deliver strategic business outcomes. Atmosera's expertise simplifies the process of cloud transformation and our 20+ years of experience managing complex IT environments provides our customers with the confidence and trust tha...
Darktrace is the world's leading AI company for cyber security. Created by mathematicians from the University of Cambridge, Darktrace's Enterprise Immune System is the first non-consumer application of machine learning to work at scale, across all network types, from physical, virtualized, and cloud, through to IoT and industrial control systems. Installed as a self-configuring cyber defense platform, Darktrace continuously learns what is ‘normal' for all devices and users, updating its understa...
With the introduction of IoT and Smart Living in every aspect of our lives, one question has become relevant: What are the security implications? To answer this, first we have to look and explore the security models of the technologies that IoT is founded upon. In his session at @ThingsExpo, Nevi Kaja, a Research Engineer at Ford Motor Company, discussed some of the security challenges of the IoT infrastructure and related how these aspects impact Smart Living. The material was delivered interac...
Intel is an American multinational corporation and technology company headquartered in Santa Clara, California, in the Silicon Valley. It is the world's second largest and second highest valued semiconductor chip maker based on revenue after being overtaken by Samsung, and is the inventor of the x86 series of microprocessors, the processors found in most personal computers (PCs). Intel supplies processors for computer system manufacturers such as Apple, Lenovo, HP, and Dell. Intel also manufactu...