Showing posts with label financial. Show all posts
Showing posts with label financial. Show all posts

Saturday, December 14, 2019

Kaspersky research finds 174 municipal institutions targeted with ransomware in 2019

According to Kaspersky security experts, 2019 has seen a significant spike of ransomware attacks on municipalities. This conclusion comes after the company’s researchers observed at least 174 municipal institutions with more than 3,000 subset organizations have been targeted by ransomware throughout the last year. This represents a 60 percent increase from the same figure in 2018.


Ransomware is notorious in the corporate sector for financial devastation and has affected businesses around the world for several years. This year has seen rapid development of an earlier trend where malware distributors have targeted municipal organizations. 

Researchers note that while these targets might be less capable of paying a large ransom, they are more likely to agree to cybercriminals’ demands. Blocking any municipal services directly affects the welfare of citizens in financial losses as well as other significant and sensitive consequences.

When considering publicly available information, ransom amounts have varied greatly with highs reaching up to $5,300,000 and $1,032,460 on average. Researchers note that these figures do not accurately represent the final costs of an attack, as the long-term consequences are far more devastating.

The malware that was most often observed were varied, yet three families were named as the most notorious by Kaspersky researchers: Ryuk, Purga and Stop. Ryuk appeared on the threat landscape more than a year ago and has since been active all over the world in public and in the private sector. Its distribution model usually involves delivery via backdoor malware which spreads by the means of phishing with a malicious attachment disguised as a financial document. 


Purga malware has been recognized since 2016, yet only recently municipalities have been discovered to fall victims to this Trojan having various attack vectors from phishing to brute force attacks. Stop cryptor is relatively new as it is only a year old. It propagates by hiding inside software installers. This malware continues to be prevalent, ranking at number seven in the top 10 most popular cryptors ranking of the third quarter this year.

“One must always keep in mind that paying extortionists is a short-term solution which only encourages criminals and keeps them funded to quite possibly repeat the same acts,” said Fedor Sinitsyn, a security researcher at Kaspersky. “In addition, once a city has been attacked, the whole infrastructure is compromised and requires an incident investigation and a thorough audit. This inevitably results in costs that are in addition to the ransom requested. Based on our observations, cities might be inclined to pay because they usually cover the cyber risks with help of insurance and allocating budgets for incident response. The better approach would be to invest in proactive measures like proven security and backup solutions as well as regular security audit. While the trend of attacks on municipalities is only growing, it can be stifled by adjusting the approach to cybersecurity and what is more important by the refusal to pay ransoms and broadcasting this decision as an official statement.”

Saturday, December 7, 2019

Gartner reveals that just 22 percent of CFOs are personally effective; while most are overinvested in finance tasks

Only 22 percent of CFOs achieve a high degree of personal effectiveness, and Gartner Inc. research shows that a limited set of activities and relationships outside the finance department are the biggest contributors to a CFO’s personal effectiveness.

The research was based on more than 100 CFO interviews and it assessed CFO personal performance and effectiveness across 231 attributes to reveal what the most effective CFOs do differently with their time, relationships and teams.



Gartner determined CFO personal effectiveness based on how closely a CFO’s organization aligned to efficient growth behaviors, such as positive risk taking to drive long-term growth, as well as the CFO’s ability to meet CEO expectations around revenue growth, margin expansion, return on invested capital and balance sheet health.

As part of the analysis, Gartner studied the average weekly activities of CFOs and found that the average CFO lost one full day of work per week to ineffective activities. The largest misallocation was in how much time CFOs spent working within their own departments.


“CFOs want to reinvent their departments, keep their talent pipelines full and provide services more efficiently to internal business partners, so it’s not surprising that most respondents noted that managing these activities were a huge demand on their time,” said Mr. Nagy. “However, none of these activities, even if mastered, ultimately impacted how effective a CFO was in their overall job performance.”

Gartner found that there was no correlation between an organization’s size or industry in how effectively their CFO performed. Within the finance department, a CFO taking personal ownership of finance talent acquisition, mergers and acquisitions strategy, cost management or digital transformation also had no material impact in how effective the CFO was rated in overall job performance.


“CFOs tell us they have more demands than ever, but the surprise in this research is just how few activities differentiate the most successful operators from the rest of the pack,” said Peter Nagy, research vice president in Gartner Finance practice. “The most important relationships that drive high performance in the CFO role are found in the boardroom and where the customers are, not in the finance department.”

Tuesday, December 3, 2019

Kaspersky releases its financial threat predictions for 2020, as fintech, mobile banking and e-commerce are likely to intensify

According to Kaspersky experts, financially motivated cyberthreat actors may start to target investment apps, online financial data processing systems and upcoming cryptocurrencies in 2020. Additionally, experts predict they may offer paid access to banks’ infrastructures and develop new strains of mobile banking malware based on leaked source code.

Financial cyberthreats are considered to be some of the most dangerous, as their impact usually results in direct financial losses for victims. 2019 has seen some significant developments in the industry and also in how financial attackers operate. 


These events allowed Kaspersky researchers to suggest several important potential developments for the financial threat landscape for 2020. 

Fintech is under attack. Mobile investments apps have become more popular among users around the globe, and this trend won’t go unnoticed by cybercriminals in 2020. Not all of these apps utilize best security practices, like multi-factor authentication or protection of the app connection, which may give cybercriminals a potential way to target users of such applications

Kaspersky research and monitoring of underground forums suggests that the source code of some popular mobile banking Trojans was actually leaked into the public domain. Previous similar cases of malware source code leakage such as Zeus and SpyEye that resulted in an increased number of new variations of these Trojans. In 2020 this pattern may repeat.


In 2020, Kaspersky experts expect an increase in the activity of groups specialised in criminal-to-criminal sale of network access to banks in the African and Asian regions, as well as in Eastern Europe. Their prime targets are small banks as well as financial organizations recently bought by big players who are rebuilding their cybersecurity system in accordance with the standards of their parent companies. it is also expected that the same banks may become victims of targeted ransomware attacks, as banks are among those organizations that are more likely to pay a ransom than accept the loss of data.

Magecarting 3.0 features more cybercriminal groups will target online payment processing systems. Over the past couple of years, so-called JS-skimming (the method of stealing of payment card data from online stores) has gained immense popularity among attackers. 

Currently, Kaspersky researchers are aware of at least 10 different actors involved in these type of attacks and experts believe that their number will continue to grow during the next year. The most dangerous attacks will be on companies that provide services such as e-commerce as-a-service, which will lead to the compromise of thousands of companies.


“This year has been one of many important developments,” says Yuriy Namestnikov, a security researcher at Kaspersky. “Just as we predicted at the end of 2018, it has seen the emergence of new cybercriminal groups like CopyPaste, new geography of attacks by Silence group and cybercriminals shifting their focus to data that helps to bypass antifraud systems in their attacks. Behavioral and biometrics data is on sale on the underground market. Additionally, we expected JS-skimmer base attacks to increase and they did. With 2020 on the horizon, we recommend security teams in potentially affected areas of the finance industry to gear up for new challenges. There is nothing inevitable in potential upcoming threats, it is just important to be properly prepared for them.”

In addition to financial sector, Kaspersky researchers identified other industries that will face new security related challenges in the upcoming year, such as the healthcare industry is advised to focus on protecting medical records and connected medical devices, as they are becoming the target of threat actors. 

Corporate security teams should pay more attention to cloud infrastructure and also to addressing growing risks of insiders accessing their networks. There are groups of criminals specializing on recruiting insiders through various techniques, including blackmail. 

Telecommunications and other industries that vastly use cellular communications should be prepared to assess and address risks that will come with wider adoption of 5G, which is expected to start in 2020. 

Thursday, November 7, 2019

Apptio introduces Insights & Action Plans to automatically discovery cost optimization opportunities

Apptio Inc. has introduced "Insights & Action Plans," which will be available throughout Apptio's cost analytics applications, starting with cost transparency and IT financial management, and provides users with intelligent alerts designed to highlight opportunities for cost savings, increased productivity, risk reduction, and improved data quality.  

The scale of technology spending in most modern enterprise organizations has grown at a rate that is nearly impossible to manage manually. The average enterprise organization spends hundreds of millions of dollars on technology, often managed in spreadsheets alone. 


This lack of a business management system can lead to pervasive overspending, waste, and no discernible business value across hundreds of vendors, cloud services, infrastructure, labor and more. 

To address this complexity, Apptio is launching Insights & Action Plans to automate the identification and delivery of cost saving insights to users.    
Insights & Action Plans users will receive automated notifications of spend overages, hidden spending, costs associated with closed projects, poor forecast accuracy and much more. This solution works by applying machine learning and a system of rules to users' financial, operational, and vendor data, analyzing anomalies and identifying areas of redundancy. 


Apptio then alerts users to these insights and tracks and manages progress made against them through Action Plans. The first set of insights launching today was selected based on input and validation from hundreds of Apptio customers and represent the highest areas of risk for overspending.

"Today's launch represents one of the most important advancements to Apptio's technology platform since our founding," said Sunny Gupta, Apptio CEO. "More than a year in the making, our vision is to eliminate the need for our customers to 'insight hunt' within their own data, one of the most pervasive challenges with modern business intelligence and analytics platforms."  


After each insight is discovered, users have the option to track and manage progress through dedicated Action Plans. These plans start by assigning work to an insight owner, correlating the associated data with each insight, and automatically updating the plan once action is taken. These Action Plans track the history of each insight and project future efficacy. 

"We've heard from customers who spend a significant amount of time every month attempting to achieve this level of awareness and understanding using spreadsheets or paying a premium for specialized consultants to conduct the work on their behalf," said Scott Chancellor, Apptio chief product officer. "Our customers want timely and actionable insights into their IT investments without that level of overhead—we've unlocked this today with Insights & Action Plans."


Additional insights will be added quarterly, examples include notification of unused SaaS licenses, non-critical applications using Tier 1 storage, end of life on mission-critical assets, new development work on retired applications and physical serves running non-production workloads.
Insights & Action Plans and Action Plans are currently in beta and will be generally available in early next year.

Sunday, October 27, 2019

C2 Systems is now a Microsoft Certified Partner; helps to push cutting edge technology across the Azure platform

C2 Systems achieving this week certification from Microsoft that helped strengthens the relationship between the two organizations as C2 becomes an official channel partner of the software giant. 

Teams inside each company will now work more closely together to become intimately familiar with both C2’s Covalent and Microsoft’s Azure as well as the clients of each organization to deliver a combined solution that best serves the specific needs of their mutual clients.



The Dallas, Texas-based company delivers the commitment to deliver comprehensive, multi-channel, end-to-end loan origination platform, as well as to provide secure, compliant, cloud-delivered solution for consumer and small business lending that is powered by the scalable and secure Microsoft Azure framework. 

C2’s Covalent solution was built from the ground up to utilize Microsoft’s technology to provide lenders with modern and intuitive tools from which to deliver the highest level of customer experience.




C2 Covalent helps financial institutions make fast, consistent, high-quality credit decisions in an easily-deployable, cloud-based Loan Origination System (LOS). For associates, this enables consumer and small business loan origination with regulatory compliance and significant cost savings. For customers, it means a more seamless and efficient point of sale experience through additional product offerings, and lending decisions that are made within minutes.

The C2 Covalent ecosystem includes tools that can be utilized from point of sale, through underwriting and document preparation. Covalent connects to key third-party data sources for the various types of consumer and small business lending that gets done. Using its automation layer architecture, new data sources of tomorrow can be easily integrated so that users can always stay current.

All of these components can be combined to create the workflow and level of automation that is custom fit for the institution.

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...