Startups

As war escalates in Europe, it’s ‘shields up’ for the cybersecurity industry

Comment

Cropped Hand Holding Umbrella During Rainfall
Image Credits: Rosley Majid / EyeEm / Getty Images

Yaron Tal

Contributor

CTO and founder of Reposify, Yaron Tal is a tech entrepreneur and cybersecurity expert with nearly two decades of experience developing cybersecurity software solutions.

In unprecedented times, even government bureaucracy moves quickly. As a result of the heightened likelihood of cyberthreat from Russian malactor groups, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) — part of the Department of Homeland Security — issued an unprecedented warning recommending that “all organizations — regardless of size — adopt a heightened posture when it comes to cybersecurity and protecting their most critical assets.”

The blanket warning is for all industries to take notice. Indeed, it’s a juxtaposition of sorts to think the cybersecurity industry is vulnerable to cyberattack, but for many nation state groups, this is their first port of call.

Inspired by the spike in attacks on cybersecurity agencies globally, a report from Reposify assessed the state of the cybersecurity industry’s external attack surface (EAS). It coincides with CISA’s warning, and highlights critical areas of concern for the sector and how they mirror trends amongst pharmaceutical and financial companies, providing vital insight into where organizations can focus their efforts, and reinforce the digital perimeter.

The report examined 35 cybersecurity companies and their 350+ subsidiaries with shocking results: during only a two-week period in January 2022, more than 200,000 exposed assets were uncovered at top firms, 42% of which were identified as high-severity issues.

As CISA outlines in its “Shields Up” guidance, the first step to resiliency is to reduce the likelihood of a damaging cyber intrusion in the first place. Recognizing the problem is only the first in a series of actionable moves organizations can make to minimize their external weaknesses to bad actors.

If addressing digital perimeter exposures is the foundation, zoning-in on problem areas is the framing. A deep dive into these deficiencies points to clear solutions all industries – cybersecurity or otherwise – can embrace to protect themselves.

What do companies need to do?

Many factors, including the transition to remote work environments, increased reliance on third-party vendors, digital transformation and offloading services onto the cloud, have significantly increased companies’ external attack surface.

According to the report, the rise of remote access sites saw 89% of identified assets classified as part of the unofficial perimeter. Similarly, 87% of databases were unaccounted for, along with 67% of development tools and 62% of all network assets.

Databases were found to be among the most vulnerable to cybersecurity threat, with over half (51%) of cybersecurity companies hosting an exposed database. Nearly all (97.14%) of security agencies have exposed assets on their Amazon Web Services (AWS), and 86% of those analyzed have at least one sensitive remote access service exposed to the internet.

Now that the problem areas have been identified – remote access servers, open network computing remote procedure call (ONC RPCs), service message block services, and databases among them — the best tool in any CISOs arsenal is anticipation and mitigation.

Leveraging cybersecurity best practices across infrastructure, applications and user management should be the first port of call before deploying tools to support in minimizing an organization’s EAS.

Best practice for OpenSSH and remote access servers like RDP and Telnet is to ensure access only via VPN. This provides critical protection through proxy walls and will properly shield internal data. Furthermore, ONC RPCs like Portmapper should only service data on internal networks (intranet). If it holds any two-way connection to the internet, it should be bound only to non-confidential data.

Unmaintained web servers (e.g., Apache, NGINX and IIS) also represent a major risk to any organization, potentially exposing networks to exploitations that could result in a data leak or remote code execution (RCE).

Similarly, databases are today’s treasure chests. Without adequate protection via MFA, SSO, VPN or proxy, valuable corporate information, intellectual property and privacy data could all be lost to the work of malactors. Exposed storage and backup sites like FTP, rsync, S3 and Azure Blob should be stored off public IP to prevent a doorway for cyber-attack, as opportunists could use this as a means to compromise or tamper with corporate data, potentially leveraging ransomware to generate profit.

DevOps tools where companies may store software and information-critical documents should, at the very least, leverage two-factor authentication for employee use. Ensuring these tools, and web servers, are patched with the latest software is another example of simple-fix companies can use to protect themselves and minimize their EAS.

In the same vein, the reliance on cloud computing can potentially put company assets at risk. Contrary to popular belief, the onus to protect cloud data falls on the customer, not the service provider.

There are a number of ways corporations can become vulnerable through cloud service providers: Incomplete control over who can access sensitive data, cloud misconfiguration, cloud applications provisioned outside IT visibility, lack of staff with skills to manage security for cloud applications, among others.

We’ve anticipated and mitigated. Now what?

Even with these critical steps, the EAS still exists and is therefore not immune to threat. EASM tools can help. Before, online assets had to be cleared and itemized by a central IT team. Now, product, marketing and technology teams have the ability to create and own online assets – everything from test pages to entire databases – often without informing IT departments.

In addition to rendering central control of asset inventory near useless, decentralization of asset management has brought about significant changes in the types of threats that organizations can expect, and highlighted an issue for every industry: human error.

For maximum effectiveness, assets must be continuously monitored in real time. Often, subsidiaries and partner companies are overlooked when mapping the external attack surface. Critical asset identification must extend to all associated companies.

This is particularly important in the case of mergers and acquisitions, where a parent company may overlook critical exposed assets at a subsidiary. If the chosen EASM tool can’t recognize the link between the two companies, an unknown asset becomes far more likely to be exploited and could become a significant cybersecurity threat.

The cybersecurity industry is no exception to human error

At the end of the day, security company CISOs are no different from those in any other industry. They, too, are subject to budgeting issues that may not allow for adequate infosec resources, leaving small teams to manage a growing number of assets.

Automated cybersecurity tools are thrown at problems as a half-hearted fix, potentially creating new attack vectors in the process. It’s a lot to keep track of for anyone, and so, human error kicks in and systems are unintentionally missed or overlooked.

As reinforced by CISA’s “Shields Up” warning, we live in a world where cybercrime is a weapon to be yielded. Battles are being fought online in retaliation to sanctions, or other penalties, often alongside ground or fiscal war.

Cybersecurity companies house valuable assets of U.S. businesses, and we must do everything in our power to protect them. We can begin with our digital perimeter by being watchful, ultimately leading to a safer world for all.

To read “The State of External Attack Surface 2022” report, click here (registration required).

More TechCrunch

Hydrow, the at-home rowing machine, announced Thursday that it has acquired a majority stake in Speede Fitness, the company behind the AI-enabled strength training machine. The rowing startup also announced…

Rowing startup Hydrow acquires a majority stake in Speede Fitness as their CEO steps down

Call centers are embracing automation. There’s debate as to whether that’s a good thing, but it’s happening — and quite possibly accelerating. According to research firm TechSci Research, the global…

Retell AI lets companies build ‘voice agents’ to answer phone calls

TikTok is starting to automatically label AI-generated content that was made on other platforms, the company announced on Thursday. With this change, if a creator posts content on TikTok that…

TikTok will automatically label AI-generated content created on platforms like DALL·E 3

India’s mobile payments regulator is likely to extend the deadline for imposing market share caps on the popular UPI payments rail by one to two years, sources familiar with the…

India weighs delaying caps on UPI market share in win for PhonePe, Google Pay

Line Man Wongnai, an on-demand food delivery service in Thailand, is considering an initial public offering on a Thai exchange or the U.S. in 2025.

Thai food delivery app Line Man Wongnai weighs IPO in Thailand, US in 2025

The problem is not the media, but the message.

Apple’s ‘Crush’ ad is disgusting

Ever wonder why conversational AI like ChatGPT says “Sorry, I can’t do that” or some other polite refusal? OpenAI is offering a limited look at the reasoning behind its own…

OpenAI offers a peek behind the curtain of its AI’s secret instructions

The federal government agency responsible for granting patents and trademarks is alerting thousands of filers whose private addresses were exposed following a second data spill in as many years. The…

US Patent and Trademark Office confirms another leak of filers’ address data

As part of an investigation into people involved in the pro-independence movement in Catalonia, the Spanish police obtained information from the encrypted services Wire and Proton, which helped the authorities…

Encrypted services Apple, Proton and Wire helped Spanish police identify activist

Match Group, the company that owns several dating apps, including Tinder and Hinge, released its first-quarter earnings report on Tuesday, which shows that Tinder’s paying user base has decreased for…

Match looks to Hinge as Tinder fails

Private social networking is making a comeback. Gratitude Plus, a startup that aims to shift social media in a more positive direction, is expanding its wellness-focused, personal reflections journal to…

Gratitude Plus makes social networking positive, private and personal

With venture totals slipping year-over-year in key markets like the United States, and concern that venture firms themselves are struggling to raise more capital, founders might be worried. After all,…

Can AI help founders fundraise more quickly and easily?

Google has found a way to bring a variation of its clever “Circle to Search” gesture to iPhone users. The new interaction, launched in January, allows Android users to search…

Google brings a variation on ‘Circle to Search’ to iPhone users

A new sculpture going live on Wednesday in the Flatiron South Public Plaza in New York is not your typical artwork. It combines technology, sociology, anthropology and art to let…

Always-on video portal lets people in NYC and Dublin interact in real time

Apple’s iPad event had a lot to like. New iPads with new chips and new sizes, a new Apple Pencil, and even some software updates. If you are a big…

TechCrunch Minute: When did iPads get as expensive as MacBooks?

Autonomous, AI-based players are coming to a gaming experience near you, and a new startup, Altera, is joining the fray to build this new guard of AI agents. The company announced…

Bye-bye bots: Altera’s game-playing AI agents get backing from Eric Schmidt

Google DeepMind has taken the wraps off a new version of AlphaFold, their transformative machine learning model that predicts the shape and behavior of proteins. AlphaFold 3 is not only…

Google DeepMind debuts huge AlphaFold update and free proteomics-as-a-service web app

Uber plans to deliver more perks to Uber One members, like member-exclusive events, in a bid to gain more revenue through subscriptions.  “You will see more member-exclusives coming up where…

Uber promises member exclusives as Uber One passes $1B run-rate

We’ve all seen them. The inspector with a clipboard, walking around a building, ticking off the last time the fire extinguishers were checked, or if all the lights are working.…

Checkfirst raises $1.5M pre-seed to apply AI to remote inspections and audits

Close to a decade ago, brothers Aviv and Matteo Shapira co-founded a company, Replay, that created a video format for 360-degree replays — the sorts of replays that have become…

Controversial drone company Xtend leans into defense with new $40 million round

Usually, when something starts to rot, it gets pitched in the trash. But Joanne Rodriguez wants to turn the concept of rot on its head by growing fungus on trash…

Mycocycle uses mushrooms to upcycle old tires and construction waste

Monzo has raised another £150 million ($190 million), as the challenger bank looks to expand its presence internationally — particularly in the U.S. The new round comes just two months…

UK challenger bank Monzo nabs another $190M as US expansion beckons

iRobot has announced the successor to longtime CEO, Colin Angle. Gary Cohen, who previous held chief executive role at Timex and Qualitor Automotive, will be heading up the company, marking a major…

iRobot names former Timex head Gary Cohen as CEO

Reddit — now a publicly-traded company with more scrutiny on revenue growth — is putting a big focus on boosting its international audience, starting with francophones. In their first-ever earnings…

Reddit tests automatic, whole-site translation into French using LLM-based AI

Mushrooms continue to be a big area for alternative proteins. Canada-based Maia Farms recently raised $1.7 million to develop a blend of mushroom and plant-based protein using biomass fermentation. There’s…

Meati Foods bites into another $100M amid growth to 7,000 retail locations

Cleaning the outside of buildings is a dirty job, and it’s also dangerous. Lucid Bots came on the scene in 2018 with its Sherpa line of drones to clean windows…

Lucid Bots secures $9M for drones to clean more than your windows

High interest rates and financial pressures make it more important than ever for finance teams to have a better handle on their cash flow, and several startups are hoping to…

Israeli startup Panax raises a $10M Series A for its AI-driven cash flow management platform

The European Union has deepened the investigation of Elon Musk-owned social network, X, that it opened back in December under the bloc’s online governance and content moderation rulebook, the Digital Services Act…

EU grills Elon Musk’s X about content moderation and deepfake risks

For the founders of Atlan, a data governance startup, data has always been at the heart of what they do, even before they launched the company. In fact, co-founders Prukalpa…

Atlan scores $105M for its data control plane, as LLMs boost importance of data

It is estimated that about 2 billion people, especially those in lower and middle-income countries, lack access to quality and affordable essential medicines. The situation is exacerbated by low-quality or even killer…

Axmed raises $2M from Founderful to streamline drug supply chains in underserved markets