Tag: cybersecurity

New Study Finds Cybersecurity as Top Concern Among Automotive Manufacturers

National, June 21, 2024Rockwell Automation, Inc., the world’s largest company dedicated to industrial automation and digital transformation, today announced the results of the 9th annual “State of Smart Manufacturing Report: Automotive Edition.” The study encompasses the responses of 182 leaders from automotive manufacturers, automotive supply manufacturers, and electric vehicle manufacturers across 15 of the leading manufacturing countries, including India.

This year’s report emphasizes the evolution of the automotive industry, revealing a focus on harnessing emergent technology to reduce risk, generate growth, and maximize workforce potential. Automotive manufacturers are acutely aware of the industry’s evolution in the era of Industry 4.0, particularly as cyberattacks resulted in $1.99 billion in system downtime costs in the first half of 2023 alone.

Key global findings include:

  • Cybersecurity risk is listed as the top external obstacle for automotive manufacturers in 2024 – up from ninth position in 2023.
  • 97% of automotive manufacturers are using or evaluating smart manufacturing technology – up from 85% in 2023.
  • Technology investments increased 35% year-over-year, from 23% to 31% of the operating budget.
  • Wearable technology is listed as one of the top ten investment areas for automotive manufacturers in 2024, ranking third overall.
  • Employee engagement is the top workforce-related obstacle for automotive manufacturers in 2024.
  • Reducing manufacturing waste is the factor that matters most to automotive manufacturers’ ESG programs.

Dilip Sawhney, Managing Director, Rockwell Automation India, said, ” In the age of Industry 4.0, cybersecurity is emerging as the major concern for automotive manufacturers, which underscores industry’s heightened recognition of digital threats and the urgent need for robust cybersecurity measures.”

“As the Indian automotive sector shifts towards electric vehicles, manufacturers need to adopt smart technologies to improve resilience, reduce waste, optimize production, and drive growth, in a sustainable way. At Rockwell Automation, we are committed to assisting the Indian automotive sector in overcoming these challenges by offering innovative solutions that enhance security, drive growth, and foster sustainability,” added Dilip.

Automotive manufacturers are focusing on strategies that prioritize workforce retention, upskilling, and engagement. Technologies such as smart manufacturing and automation, which complement and augment the value brought by their employees, are key to driving positive business outcomes.

The full findings of the report can be found here.

Methodology

This report is based on the responses of 182 managers and executives from automotive manufacturers, automotive supply manufacturers, and electric vehicle manufacturers in 15 countries. It’s part of the 9th annual State of Smart Manufacturing report, which surveyed 1,567 manufacturing leaders across multiple industries and was conducted in association with Sapio Research and Rockwell Automation.

Mitigating Evolving Cybersecurity Risks in the BFSI Sector: Best Practices

Govind Rammurthy, CEO and Managing Director, eScan

By Govind Rammurthy, CEO and Managing Director, eScan

With the Government of India’s steadfast push towards digitization across various sectors, especially in facilitating paperless financial transactions, cyber security has surged to the forefront of concerns for entities operating within the BFSI domain.

It’s evident that as virtually every individual participates in what can be aptly termed the financial ecosystem; cybercriminals are actively seeking vulnerabilities within this sector. Moreover, the complex landscape of technology not only provides opportunities for these criminals to perpetrate crimes but also enables them to obscure their activities, thereby complicating potential investigative processes.

As delineated above, the BFSI sector confronts a diverse array of emerging threats owing to its pivotal role in managing sensitive financial data and transactions. Presented below are some of these emerging threats, along with corresponding measures that can be adopted to effectively mitigate them:

Ransomware Attacks – Ransomware Attacks represent a constantly evolving threat landscape, casting a formidable shadow over organizations across all sectors. Particularly targeting financial institutions, cybercriminals employ increasingly sophisticated ransomware variants engineered to encrypt vital data and extort ransom payments for decryption keys. While encryption constitutes just one facet of the threat, institutions often maintain disciplined backup practices for critical data, facilitating restoration processes. However, the gravest concern arises from cybercriminals’ adeptness at exfiltrating sensitive information, subsequently leveraging it to coerce and blackmail institutions.

Measures to tackle such attacks: Implementing robust endpoint security solutions, such as eScan EDR on endpoints and gateways, is paramount. These solutions leverage advanced threat detection and prevention technologies to proactively mitigate ransomware attacks. Additionally, adopting a comprehensive solution for detecting vulnerabilities in assets is crucial, as it helps identify potential entry points for attacks against institutions.

Advanced Persistent Threats: APTs represent highly sophisticated and targeted cyber attacks orchestrated to infiltrate networks, aiming to pilfer sensitive information or engage in espionage over extended periods. APT actors employ advanced techniques, skirting traditional security defences to elude detection for prolonged durations.

Measures to tackle APT: Effectively thwarting APTs necessitates deploying advanced threat intelligence solutions and conducting regular threat-hunting activities to intercept and neutralize APTs early in the attack lifecycle. Furthermore, eScan advocates for network segmentation,colloquially termed “silos,” and the implementation of stringent access controls to curtail lateral movement within the network, thereby mitigating the impact of APTs. Additionally, CISOs are urged to conduct routine assessments of firewall traffic flows to countries with less robust cyber security frameworks, ensuring heightened vigilance against potential threats.

Insider Threats: Within the realm of cyber security, insider threats—whether deliberate or inadvertent—constitute a formidable peril to financial institutions. Individuals including employees, trusted insiders, and system administrators with access to servers and credentials, and disgruntled staff members may exploit their privileged access to pilfer or erase sensitive data, or commandeer systems for personal gain or malevolent intent.

Measures to handle Insider Threats: Chief Information Security Officers (CISOs) must oversee measures such as regular audits, stringent access controls, credential reviews, and the prompt revocation of rights for departing employees. Also, stakeholders ought to adhere to the principle of least privilege, thereby restricting access to sensitive data and systems based on job roles and responsibilities. The implementation of User and Entity Behaviour Analytics (UEBA) within endpoint and perimeter security solutions, enables the monitoring of user activities and perform behaviour analytics. This facilitates the identification of anomalies indicative of insider threats, such as unauthorized access or abnormal data exfiltration.

Third-Party Risks: Organizations frequently depend on third-party vendors, suppliers, and service providers to fulfil diverse business functions and processes, thereby heightening the susceptibility to supply chain attacks and data breaches stemming from third-party vulnerabilities.

Measures to tackle TP risks: To mitigate such risks, organizations must conduct thorough vendor risk assessments and due diligence processes to evaluate the security posture of third-party vendors and assess their compliance with best practices. Furthermore, regular monitoring of information flow tothird-party vendors, coupled with routine audits of third-party activities, is essential for the timely detection and mitigation of potential risks.

Cloud Security Challenges: The integration of cloud computing, cloud storage, always-on smartphone applications, and Software-as-a-Service (SaaS) solutions presents novel security hurdles for BFSI organizations, encompassing concerns related to data privacy, compliance, and unauthorized access.

Measures to address Cloud Security: Financial institutions must prioritize the implementation of robust cloud security controls and encryption mechanisms to safeguard sensitive data stored in the cloud. Furthermore, the activation of audit trails across all cloud services, periodic review of security policies, and the establishment of methods for detecting anomalous activities within cloud environments are imperative steps toward bolstering cloud security defences.

Regulatory Compliance and Data Privacy: The introduction of the DPDP bill has compelled BFSI organizations to adhere to rigorous regulatory standards and data privacy laws, underscoring the importance of safeguarding customer data and upholding trust and confidence in financial systems’ integrity.

Measures to comply with DPDP: To fulfill these mandates, BFSI entities must deploy enterprise Data Loss Prevention (DLP) solutions to adhere to stringent cybersecurity protocols and procedures, thus ensuring alignment with regulatory mandates. Moreover, conducting regular compliance assessments, facilitated by external auditors, is essential to guarantee adherence to regulatory frameworks and guidelines.

By proactively addressing the above threats and implementing effective cybersecurity measures, financial organizations can strengthen their resilience to cyberattacks and safeguard their critical assets, data, and reputation in an increasingly digital and interconnected landscape in India.

Redefining Cybersecurity: Check Point Unveils Quantum Force Gateway Series

New Delhi, February 29 2024 — Check Point® Software Technologies Ltd., a leading AI-powered, cloud-delivered cyber security platform provider, introduces Check Point Quantum Force series: an innovative lineup of ten high-performance firewalls designed to meet and exceed the stringent security demands of enterprise data centers, network perimeters, campuses, and businesses of all dimensions. Powered by the advanced Check Point Infinity Platform, which integrates cloud-based security intelligence, a sophisticated automated threat response system, and over 50 AI engines, Quantum Force Security Gateways boast the capability to deliver up to 1 Tbps of AI-fueled threat prevention, achieving an unparalleled malware block rate of 99.8%. The Quantum Force series redefines the benchmarks for firewall performance, offering double the threat prevention efficacy, double the power efficiency, and compact 1RU/2RU form factors for space optimization, alongside unified management to cater to the most rigorous security scenarios.

“Thirty years ago, Check Point created the firewall. Today, we revolutionize it with Quantum Force. Built upon our legacy of innovation, this next-generation solution delivers robust protection powered by collaborative AI-driven threat prevention, seamlessly integrating unified security and policy management whether in the cloud or on-premises,” said Nataly Kremer, Chief Product Officer at Check Point Software Technologies. “With Quantum Force, users can confidently navigate the digital terrain, protected against the most sophisticated malware and supply chain threats, while benefiting from enhanced network performance, streamlined operations, and automated threat response and remediation.”

Digital and cloud transformation is happening at an unprecedented rate. With the hybrid workforce now a permanent fixture in most companies, there is a growing need for secure and fast networks to seamlessly enable remote work. At the same time, organizations face a multitude of cyber security challenges that can hinder their ability to effectively protect their assets and maintain operational efficiency. From navigating the complexities of technology and managing numerous vendors to ensuring the security of increasingly encrypted traffic, businesses are under constant pressure to enhance their security posture while optimizing resources.

“Hybrid work and multi-cloud adoption have expanded the attack surface and made enterprise security more complex. Given the shortage of IT security talent, enterprises should consider AI enhanced solutions to empower analytics and automation and protect against the growing threat landscape.”, said Pete Finalle, Security Research manager at IDC, “Check Point’s new Quantum Force series of ten AI-powered and cloud delivered security gateways provide up to 1 Tbps of threat prevention performance, automated blocking of sophisticated threats, while unifying management, simplifying operations, reducing time to response and improving security efficacy.”

Check Point Quantum Force Firewalls offer a cost-effective solution, enhancing network performance while simplifying technology infrastructure and reducing power, infrastructure, and operational expenses. Check Point Quantum Force’s capabilities include:

Highest levels of security performance: Quantum Force delivers 2X higher threat prevention performance up to 63.5 Gbps. Its compact 2RU/1RU form factor and high density of 1/10/25/40/100 Gbps interfaces contribute to its efficiency. Quantum Force features a uniquely modular and flexible architecture, designed to seamlessly adapt to customers’ evolving network requirements while delivering 2x more power efficiency. This enhances operational efficiency and lowers infrastructure expenses.

 AI-driven threat prevention: With an Industry-leading block rate against advanced threats and attacks, facilitated by AI-driven threat prevention, Quantum Force provides automated threat response, real-time global threat intelligence, and the power of 50+ AI engines, ensuring proactive defense against evolving cyber threats.

 Consolidated Security & Policy Management: Data centers can streamline security operations with consolidated security and policy management across on-premises, cloud, and FWaaS (Firewall-as-a-Service) environments.

Rivial Data Security Releases New Cybersecurity Platform

Rivial Data Security, pioneer of the Security Management Orchestration (SMO) space, has released their premier cybersecurity software, the Rivial Platform. Developed specifically for banks and credit unions, this advanced software fills the gap on holistically managing the many aspects of a cybersecurity program and updates many outdated, traditional ways of tracking and analyzing IT risk and compliance.

One of the most impressive and distinguishing features of the Rivial Platform is the interconnectedness of the modules and their ability to communicate with one another. This concept alone increases the efficiency of any information security officer by tenfold. Another highlight of the Rivial Platform is how intuitive it is to navigate, a feature not found in many existing cybersecurity tools.

2021 saw the highest average cost of a data breach in 17 years, rising from $3.86 million to $4.24 million (IBM Cost of a Data Breach Report 2021). Breaches and cybersecurity incidents are no longer an if, but a when. The importance of cybersecurity for financial institutions cannot be minimized. These institutions often have minimal resources to manage an IT security program that includes keeping track of multiple tools, documents, spreadsheets, screenshots, and any organization’s weakest link, human error.

The Rivial Platform helps financial institutions manage:

Program Governance

Risk

Compliance

Testing

Vendor Cybersecurity

Incident Response

“For 23 years I’ve watched organizations struggle with the growing burden of cybersecurity management as separate, unrelated functions. Knowing how dropping one ball can be catastrophic, having a single pane of glass to manage an entire security program is critical for today’s information security officer. We wanted to create software that ties everything together—risk, compliance, testing, etc—to quickly and easily manage a world-class security program. We achieved that vision of Security Management Orchestration with the Rivial platform.” -Randy Lindberg, Founder & CEO of Rivial Data Security

Top 4 Indian cybersecurity alternatives to look out for government procurement

Recently, the IT Ministry of India has announced to focus on the local cybersecurity products for the cybersecurity needs. The Ministry of Electronics and Information Technology has asked central government departments, public sector units (PSUs) and other government organisations to give preference to Made in India cybersecurity products, while procuring such products for official uses.

The Department of Telecommunications (DoT) has also recently directed all state-owned companies, central ministries and government departments to give preference to locally produced cyber security products in all public procurements. The telecom ministry and MeitY’s together instructed to all government undertakings to buy locally manufactured cybersecurity products.The step is taken at a time when cybersecurity attacks and breaches in the country are reckoned to have jumped more than 500% since the government imposed a nationwide lockdown in March 2020 to contain the spread of Covid-19.

As per the 2019 notification by the government, anti-virus, end-point, cloud and mobile security products, system information and event, identity and access, and incident response management products and others such as data classification and forensic tools were included in the list of cybersecurity products for which preference was to be given to domestic companies.

Here are the top 4 Indian cybersecurity startup to the rescue of rising attacks:

WiJungle: WiJungle, a Jaipur-based cybersecurity startup, is the Unified Network Security Gateway that enables organizations to manage and secure their entire network through a single-window. In the past years, it has vehemently won the confidence of India’s governmental organizations as well as various verticals of enterprises. WiJungle currently serves government and private giants across industry verticals like hospitality, healthcare, education, BFSI, retail, defense, transportation, ITES, etc. WiJungle, the only prominent player in the Unified Network Security space, has emerged as the Government’s New Face of Cyber Security. It is extensively serving more than 15 ministries & PMO in the central government along with numerous state-level organizations.

Aristi Labs: Bhopal-based Aristi Labs offers security solutions to help businesses protect data and intellectual property. Founded in 2016 by Utkarsh Bhargava, the startup’s core product ‘Securign’ provides a security information and event management platform (SIEM) to help businesses with threat detection capabilities across cloud and on-premises landscape. It aims to help businesses eliminate security blind spots and regain control over shadow IT. The bootstrapped startup, which counts the Indian Army as one of its clients for the Securign software, is now looking at expanding its business to the US and European markets.

Securden: Incorporated in 2018 by ex-Zoho executives Balasubramanian Venkatramani and Kumaran Balan, cybersecurity startup Securden aims to solve the fundamental IT infrastructure access security challenges faced by IT, operations, and security teams in enterprises by preventing cyber attacks, insider exploits, and malware propagation. Amidst the lockdown, the Securden suite caters to the needs of the remote workforce too. It offers a remote access solution for IT staff and an end-point permissions management tool for remote employees that together make remote work secure and productive.

Prophaze: It is the emerging cybersecurity startup in India. They provide Docker Security using WAF Container, Web Application Firewall for Kubernetes Platform, OWASP TOP 10, API Security, etc. Headquartered in Cochin, Kerala, it is providing cybersecurity solutions to various companies. It is the state-of-the-art web application security for businesses and SaaS providers. They provide enterprises with solutions from beginning to end and offer all the services needed to secure the web applications including application architecture review, testing, onboarding assistance, product deployment, DevOps training, and compliance.

5 Products Helping Companies to Avoid Data Security Threats

The rapidly evolving technology has been one of the major factors leading to digital transformation worldwide. However, it is also not surprising to know that it has also proportionally raised serious concerns around data security, especially with increasing malicious activities including data breaches and leaks.

At present, several companies are consistently using connected networks to work remotely. Also, we are now working from home and often share our laptop or computer screen during meetings. In such a scenario, it becomes imperative to ensure that sensitive information is protected before an individual allows remote access to his/her PC or laptop.

We know data theft can result in a huge loss to an organization along with customer dissatisfaction. In this regard, let’s look at 5 products/services helping companies to avoid data security threats.

Instasafe Technologies

During the pandemic, the internet instantly became the channel for effective human interaction and the primary way we work, contact, and support one another. Corporates and businesses adopted multi-cloud models for application access. Thus, adopting apt cybersecurity measures, and investing in solutions became the top priority of every business.

IAN backed InstaSafe Technologies is a leading cloud-based Security-as-a-Service solution provider delivering comprehensive protection to mobile and remote workers enabling them to safely and securely access enterprise apps, email, and web from anywhere on any network. It’s Zero Trust security model became the preferred choice for organizations that have a diverse workforce when they moved to “Work from Home” or “Remote Working” since the pandemic outbreak.

SafeHats

The potential threat to business from cybercrime has increased in the past months. Therefore, organizations turned to SafeHats’ bug bounty program that helps in the continuous testing process of applications to know if they have been exposed to vulnerabilities. Also, the number of email scams and phishing attacks saw an exponential rise since the pandemic outbreak. Considering this, SafeHats, under its community yellow page initiative, launched a program “SPOOF- Spot the Fake” for reporting spoof mail ids and domains.

SAFE Me

IIT Bombay-incubated and California-headquartered startup, Lucideus came up with SAFE Me, a mobile application that provides every user with a cyber risk score on a scale of zero to five. Using SAFE Me, companies can now conduct real-time cybersecurity assessments. Powered by artificial intelligence and machine learning, the app is available in three versions and has been helping a diverse range of consumer and business-level cybersecurity needs during this time of crisis.

Wijungle

In no time, most of the business operations had to move from physical to digital. Jaipur-based cybersecurity startup is working towards developing a unified network security gateway for companies. It helps enterprises to do away with multiple products like routers, load balancer, VPN servers, firewalls, guest management solutions, and proxy servers, among others. Some of its clients include government departments and private firms across hospitality, healthcare, education, financial services, retail, defence, and transportation.

Threatsys

Cybersecurity breaching is costly and damaging to any organization. Threatsys, one of the leading cybersecurity companies, has been playing a crucial role in the current situation. The company has been working on its Cyber Security Framework with a focus on four important aspects: protect, control, detect, and respond to mitigate any kind of security breaches and protect organizations from being the next victim.
We know cyber attacks are emerging rapidly. However, in addition to the above-mentioned solutions, it is equally important to educate employees of several organizations and train them around security awareness.

Softline with the highest Number of New SMB Customers among Kaspersky Lab Partners in 2019

Softline has received an award from Kaspersky Lab in the category Leader for the Number of SMB customers in 2019.

This October, Kaspersky Lab held their XIVth annual partner conference, Efficient Collaboration. Softline was awarded as Leader for the Number of SMB customers in 2019. The history of cooperation between Softline and Kaspersky Lab—a globally acclaimed leader in terms of cybersecurity and anti-malware—goes back over 20 years. Over this time, Softline has become one of the top three Russian information security companies and received many prestigious awards from Kaspersky Lab in various categories, including for consistent work in all regions of Russia.

The pace of digital transformation is increasing in all business areas. Cybersecurity teams are expected to guarantee the protection of all corporate sites and offices in a short amount of time. At the same time, corporate executives are tending to optimise cybersecurity budgets and want to make them more predictable. These trends create not only new challenges for modern businesses but also new opportunities for organisations that are ready for change. Softline keeps its solution and service portfolio in line with the relevant trends and expands it with new solutions from Kaspersky Lab that cover the entire cybersecurity perimeter and ensure maximum infrastructure protection from all types of cyberthreats. Softline successfully promotes its partner’s products and helps Kaspersky Lab fulfil its mission to create a secure digital space.

“Softline has been cooperating with Kaspersky Lab since the day our company was founded. We are proud of being one of its best-performing vendor partners, demonstrated by the awards that we regularly receive. Softline has been working actively to engage new customers, not only in Russia but also abroad. Ensuring data safety and business continuity has become the most relevant task for SMB customers. Softline has put a lot of effort into raising customer awareness of various types of threat and preparing special offers and promotional campaigns for vendor products. We will do our best to continue protecting our customers with Kaspersky Lab products of the highest quality. We are confident that we will be able to achieve many victories in the future, including in the Enterprise category,”—says Evgeny Ponomarev, Head of Softline’s Kaspersky Channel Sales Group.

Platforms to watch out for if you want to learn to code!

Gone are the days when it was believed that coding is only for absolute computer nerds. Now, anyone can participate in the process of writing code for their own creations such as websites, mobile applications and software. Coding and programming are vital skills and demand is expected to rise in the future, especially when it comes to managing cybersecurity, cloud services and SaaS platforms.

Coding has become a part of the curriculum for school going students. Therefore, students who can be engaged in coding now can have better potential prospects once they do leave school. The beauty of programming is that you can build whatever you can think of, with a toolset that could guide you through the process. Suppose you are a newcomer to the world of web development and coding. In that case, it makes the most sense to start by teaching yourself how to code so that you may discover what you do and don’t like before investing resources into courses for a particular coding language.

Here are the five unique platforms to learn how to code.

SOAL

School of Accelerated Learning is the first Hybrid Product school for learners who are looking to build tech-focused careers founded by Raj Desai. SOAL claims to be India’s first-ever hybrid coding boot camp for emerging technologies and future work skills. Their product-driven boot camp is now available at three major cities -Mumbai, Hyderabad and Delhi. SOAL provides in-depth knowledge of courses in Product Engineering and Product Design. SOAL helps to build real-life, robust web applications from scratch. SOAL gives you access to global experts with both online learning modules and the excitement of learning with peers in its offline campuses. Aside from learning, you’ll have the ability to connect with mentors who are currently at the top of their field.

SP robotics

Founded by Sneha Priya, SP robotics is an ed-tech platform to learn, build and showcase robotics, coding, image processing, virtual reality and other next-generation skills or education. The best part is that concepts are taught using animation videos and real-world examples. It only enhances coding skills but also problem-solving skills and creativity. Currently, the Android and AI courses are being offered for a free trial, but one can proceed to purchase the entire course after knowing their interest. Those who complete their course will get a certificate.

Udacity

Udacity is an online learning platform offering groundbreaking credential programs in fields such as AI, machine learning, self-driving cars, and robotics as well as app and web development. They collaborate with companies like Google, Facebook, Amazon, IBM to build cutting – edge curriculum. It empowers students to succeed while in school, but also in their daily life after school is completed. It aims to teach the skills that are needed by leaders today, delivers the credentials that are endorsed by employers and give valuable education at just a fraction of the cost that is asked in traditional schools. The mentors, reviewers band coaches ensure that those who are in the program will complete it and be ready for the job that they want. Students can learn JavaScript for free while the more intense courses and nanodegree programs do come at a price.

Coursera

Founded in 2012, Coursera is a worldwide online platform that offers massive open online courses, specializations, degrees, professional and master track courses. It offers over 1,000 courses that come from 119 institutions. It provides coding-based courses, tutorials and resources taught by professors at leading universities. There some introductory programming courses that are free while there are some more advanced courses available for a fee. Courses are available in English, Spanish and French and can be subtitled in English, Spanish or Chinese. Those who complete their course will receive an electronic course certificate.

Some of the variety of courses available-

Python
Java
HTML and CSS
IoT programming
C language.

Coding Ninjas

Founded in 2016, Coding Ninjas is one of the largest online tech education company in India, focusing on courses like C++, Java, Python, Android, Machine learning, Data science, etc. It is perhaps one of the best programming language platforms in India. They provide you a hassle-free, adaptive and excelling online courses to help you achieve your code the panache it deserves. With TA sessions, Live webinars, Discussion forums and Certifications, Coding Ninjas is a great place to build a solid programming foundation.