4 ms·
I have investigated multiple cyber incidents pertaining to swift transfers including malware and insider collaboration, the ground reality at the most instituti
by rishabhd 8y ago
I have investigated multiple cyber incidents pertaining to swift transfers including malware and insider collaboration, the ground reality at the most institutions is that their infrastructure are poorly designed and are insecure by default. In one of the bank's I visited, the Swift AGS was on the same vlan as the rest of the network, including admin and receptionist's PC. No EDR, basic AV, no application aware firewalls, no network baselining, improperly configured AD events, 2 month log retention period, lack of standardized OS golden images and pirated operating systems cracked using executables downloaded from internet. Worst, AGS was managed through a PC accessible via TeamViewer protected through a weak password. You may consider this as an isolated case, but on ground, most of the banks only focus on CBS and security takes a backseat, until something happens.
- craftyguy 8y agoWow. And I'm assuming you cannot name names, for the benefit of society, because lawyers.
- rishabhd 8y agoIf only there was a stringent regulatory audit across financial sector that only focused on cyber security as a substance, they you would see that 7 out of 10[1] financial institutions lack even the most basic defenses / ignore the basic sanity measures / or have poorly configured point solutions as their best defense against any cyber attack. A member of my team came across an institution that hosted the PII data for a country on third party cloud accessible via a poorly written API. Since, regulatory laws were pretty lax, they (the institution) simply shrugged it off. The recommendations and remediation measures (wonder if there were any) get lost in the ocean of PPT files. [1]from my own experience as an IR+Red team guy.
- heartbreak 8y agoThere is such regulation. It's supposedly enforced by the FFIEC.
- rishabhd 8y agoAgreed, but it is US only. Bank's in Middle East and in South East Asia are in pretty bad shape because of lax regulators.
- arca_vorago 8y agoYou don't know how right you are about infrastructure in businesses. I've seen the inside of hundreds of companies over the years... everything from 5 man law firms to fortune 500, and it was a rarity to see good infrastructure. It's a management problem, but it's also a problem because the people responsible aren't doing a good job convincing management. Which is why I think enginners/sysadmins/devs who have the ambition should start getting mbas and going for the CTO/CIO position... which is the main executive position (if it even exists) failing. It's also why I'm working on my data science degree now. Execs don't like you, they don't trust you, and they generally don't listen well... but they love numbers and pretty graphs!
- lovich 8y agoI mean, can you actually convince execs it's a good idea, no matter how charismatic you are? As a citizen, an engineer, and a consumer I think software and infrastructure security needs to be taken much more seriously due to how much breaches hurt people. But if I was an executive or shareholder? Why would I care? We've seen time and time again how data breaches are just a blip in the stock price, the government doesn't punish anyone for negligence, and if someone manages to take serious money from you the government will go after them on your behalf. Security is expensive, and the odds of you having a breach that actually hurts you for more than a short period seem astronomically low. We have more businesses saying they are shutting down or leaving the EU market over the fact that they can't take user data without permission than we have shutting down because they leaked all their users data or let hackers in through complete negligence of any modern security practices
- obelix_ 8y agoWell the pressure allows for new models to emerge. It's like a never ending war. The front lines keep moving back and forth between those who put themselves before others and those who don't. The thing to remember is one side cannot fully ever take out the other.
- gruturo 8y ago> I mean, can you actually convince execs it's a good idea, no matter how charismatic you are? As a citizen, an engineer, and a consumer I think software and infrastructure security needs to be taken much more seriously due to how much breaches hurt people. On SWIFT, yes, you can, thanks to their own reply to the Bangladesh incident: a reasonably thorough set of security guidelines called CSP/CSCF (Customer Security Program/Control Framework), compliance to which is now mandatory. Network isolation, 2-factor authentication, secure VDI for access, physical access controls, log retention, it's all in there. It's the perfect chance to get money and people from management and sanitize the situation. Actually if in May 2018 you don't already have a running project and resources for compliance, you should be quite worried.
- CharlesDodgson 8y agoThen you get situations where the cabled network security is incredibly restricted but the wifi network works off the same 10 digit code for years. Folks then have to log off the restricted network and onto the wifi to run simple processes that require data that is inaccessible through the cabled network. The potential for abuse by an intruder is obvious.
- tomohawk 8y agoYou could be describing the security of any organization. I've seen the same sort of mess at well funded government organizations that should (and do) know better. It's interesting that those cable cars in Switzerland get more frequent and in-depth inspections.
- gruturo 8y agoI'm responsible for a SWIFT installation and the stuff you quote is outright horrifying. I am not formally in charge of security - we have dedicated teams of professionals for that - but it's been a past occupation of mine so I strive to stay on top of things, and literally cannot imagine the work attitude leading to the situations you describe. I actually run my local firewall in addition to the network one (to which I have no access) and am toying with a WAF I'm adding to the picture, gradually tightening the ruleset. Just one question: AGS = SAG? I've never seen it written like that.
- rishabhd 8y agoMea culpa, it indeed is SAG. We typically refer it as Alliance Gateway Server during investigations.