Thursday, December 8, 2011

Cybersecurity Is Material To The Business Says The SEC – Finally

The Securities and Exchange Commission’s Disclosure Guidance on Cybersecurity, issued on October 13, is another big step towards the widespread realization that for many organizations, IT and the business are one. More and more critical business processes are dependent on hardware and software and today a company’s worth is just as likely to be based on its intellectual property as its physical assets. Much of that intellectual property is under the trust of IT and can be stolen in a cyberattack.

Take a glance and the disclosure guidance may not seem that important at first, since it contains no new rules or regulations. Read it carefully and you’ll see that the SEC is sending a clear message that publicly traded companies can no longer pretend cyber attacks and vulnerabilities are immaterial to the business.

The guidance spells out several existing business disclosure requirements that should take cybersecurity into account:

Risk Factors Companies should disclose the risk of cybersecurity incidents if they are “among the most significant factors that make an investment in the company speculative or risky.” Disclosures may include the frequency and nature of prior incidents, the probability of future cyber incidents, all the potential costs and other consequences resulting from attacks, and even the adequacy of business’s current preventive actions. The guidance is pretty thorough, even spelling out less tangible financial costs of an attack that should be taken into account, such as lost revenue from unauthorized use of proprietary information, reputational damage, litigation, and failure to retain or attract customers.

Management’s Discussion and Analysis of Financial Condition and Results of Operations (MD&A) Companies should address cybersecurity risks and incidents if the cost or other consequences are likely to have a material effect on results of operations, liquidity or financial condition. Companies may be expected to describe the effects of an actual attack and the actual property that was stolen, as well as whether the impact changes the validity of already reported financial information.

Description of the Business Cybersecurity incidents should be reported if they materially affect a company’s products, services, customer or supplier relationships, or competitive position.

Legal Proceedings Companies should disclose the details of litigation resulting from cyber attacks, such as that resulting from theft of customer information.

Financial Statement Disclosures Companies should carefully consider whether cyber risks and incidents have a broad impact on their financial statements. Some things to take into account include the costs of preventing attacks, customer incentives after attacks, and losses from warranties, breaches of contract, and product recalls or replacement.

Disclosure Controls and Procedures Companies should disclose the impact of incidents on their ability to record, process, summarize, and report information required in SEC filings, if it’s significant, and consider whether existing disclosure controls and procedures have been rendered ineffective.
If you work for a public company you should take this guidance seriously. It’s likely that publicly traded companies will be expected to start reevaluating their cybersecurity practices and audits and become more proactive about disclosing cybersecurity vulnerabilities and attacks. If you haven’t yet incorporated IT security experts in your Risk Management teams, it’s probably time to start thinking about doing so. Even if there are no new regulations here, it’s likely that after a damaging cyber attack, questions will come up about adherence to the SEC’s guidance. You can also bet this is just the beginning of a progression of new legislation and regulatory action addressing the issue of cybersecurity’s impact on the business.

By: Leon Erlanger

Wednesday, December 7, 2011

Phishers Piggyback on Indian Websites

Contributors: Avdhoot Patil, Ayub Khan, and Dinesh Singh

Have Indian websites become a safe haven for phishers? To better understand, let’s explore how phishers create a phishing site. There are several strategies phishers frequently use: hosting their phishing site on a newly registered domain name, compromising a legitimate website and placing their phishing pages in them, or hosting their phishing site using a web hosting service.

Let’s now focus on the second method which involves the use of compromised legitimate websites.
From April, 2011, to October, 2011, about 0.4% of all phishing sites were hosted on compromised Indian websites. These compromised websites belonged to a wide range of categories but the most targeted was the education category which included websites of Indian schools, colleges, and other educational institutions. Symantec has previously reported on the websites of Indian educational institutions compromised by phishers. The education category consisted of 13% of compromised Indian websites. Some of the other top categories were information technology (11%), sales (9%), Web services (8%), and e-commerce (6%).

The existence of Indian phishing sites in the education category may not be alarming but phishers have exploited Indian websites owned by individuals and organizations across many disciplines:

The phishing sites hosted on these Indian websites spoofed a multitude of brands. The majority of these brands belonged to the banking sector (comprising about 68%). The e-commerce sector comprised about 22%, and information services 3%.

Internet users are advised to follow best practices to avoid phishing attacks:
  • Do not click on suspicious links in email messages.
  • Avoid providing any personal information when answering an email.
  • Never enter personal information in a pop-up page or screen.
  • When entering personal or financial information, ensure the website is encrypted with an SSL certificate by looking for the padlock, ‘https’, or the green address bar.
  • Frequently update your security software (such as Norton Internet Security 2012) which protects you from online phishing.
By: Mathew Maniyara