No wonder Brit universities report hacks so often: Half of staff have had zero infosec training, apparently
- Reference: 1596009669
- News link: https://www.theregister.co.uk/2020/07/29/half_uk_uni_staff_no_infosec_training/
- Source link:
Most worryingly, 8 per cent of the 86 universities that answered pentesting biz Redscan's Freedom of Information questions said they had reported five or more breaches to the Information Commissioner's Office over the past 12 months.
The concerning results continued when further education institutions were asked to disclose how much security training their staff received. 46 per cent of staff received no training at all, while one Russell Group uni said that just 12 per cent of its staff had received "any" training in infosec matters.
Brit unis hit in Blackbaud hack inform students that their data was nicked, which has gone as well as you might expect [1]READ MORE
"The fact that such a large number of universities don't deliver cybersecurity training to staff and students, nor commission independent penetration testing, is concerning," said Redscan chief techie Mark Nicholls. "These are foundational elements of every security program and key to helping prevent data breaches."
Making up for the lack of widespread security training was the level of dedicated infosec staff employed by universities, which stood at a grand averaged total of three qualified people. Those three people were at least supported by the 51 per cent of universities that said they did provide some cybersecurity training to their students.
The news comes as universities continue mopping up from the Blackbaud supply chain attack, where a provider of cloud-based CRM systems used for alumni relations and fundraising suffered a ransomware attack. Blackbaud then [2]paid off the criminals, notifying customers two months later .
'Blackbaud has stated this copy [of your data] was then destroyed'.... Well, if they say so!
Newcastle, De Montfort and Brunel Universities are the latest to tell students and alumni their data was handed to criminals. In an email seen by The Register , De Montfort warned its alumni: "Blackbaud has stated this copy [of your data] was then destroyed before it could be passed on further or misused, although this cannot be guaranteed."
Newcastle University said that "no direct action in relation to this incident is required at this stage".
Despite [3]urgings from GCHQ and similar agencies to be on alert for cybersecurity threats, it appears universities are still largely fumbling in the dark. Last year the academic Joint Information Systems Committee (JISC) said a pentesting exercise it ran [4]resulted in a 100 per cent compromise rate .
"Even at this time of intense budgetary pressure, institutions need to ensure that their cybersecurity teams receive the support they need to defend against sophisticated adversaries. Breaches have the potential to seriously impact organisations' reputation and funding," concluded Redscan's Nicholls. ®
Get our [5]Tech Resources
[1] https://www.theregister.com/2020/07/24/blackbaud_uk_universities_data_breaches/
[2] https://www.theregister.com/2020/07/24/blackbaud_uk_universities_data_breaches/
[3] https://www.theregister.com/2019/09/18/ncsc_university_cyber_threats/
[4] https://www.theregister.com/2019/04/04/jisc_uni_pentesting_report/
[5] https://whitepapers.theregister.com/
Common Sense
I think it's a lot more than common sense. I regularly try to tell my family members about risks online. Most are gobsmacked to find out that an email can appear to have been sent my someone they know yet still contain dangerous content. As for it not being feasible to run courses - a simple cost-based risk evaluation should put paid to that - just ask the Garmin directors.
Re: Common Sense
The financial question is, what is the return? Sure you can give basic training to everyone for £x thousand, but "basic training" will only do so much. And for the same money, you can probably hire one or more full time infosec specialists - which may be a better use of your budget.
Re: Common Sense
Agreed.
Another way to look at it is to say that it's not a financial 'problem', it's a cost of doing business. Do they want to continue being a University is the question they should be asking themselves. Because ransomware attacks are not going to go away.
On-line courses are naff and boring, but cover the basics quite well. Certainly better than nothing.
It ought to be part of the normal induction. No login ID nor .ac.uk email address without it.
part of normal induction
Making it part of normal induction probably wouldn't help that much as normal induction is generally a perfunctory exercise run from a checklist. One time training won't stick either. Unless the entire corporate culture is security aware, nothing will really help. A lax culture breeds lax habits, and most corporate cultures I've encountered in a couple of decades of risk consulting are lax. Even "standards compliance" is rarely more than a paper exercise to satisfy periodic audit.
Just for example, "don't click on links" doesn't work where the Board regularly circulate emails containing links to documents "all staff must familiarise themselves with". Expecting a busy non-technical staffer to be able to distinguish between a genuine email from the CEO and a bogus one is pie in the sky.
However it shouldn't be possible for malicious code run at a user's workstation to spread throughout the infrastructure. Setting up and managing your infrastructure so it contains breaches locally rather than letting them spread globally is not beyond the realms of possibility. But this is rarely done, witness [1]Equifax among many others. The fundamental problem is not expert adversaries, but inadequate defenders.
[1] https://www.hsgac.senate.gov/download/majority-and-minority-staff-report_-how-equifax-neglected-cybersecurity-and-suffered-a-devestating-data-breach
Thousands on Infosec training?
What a pathetic excuse, I'll do it for a fraction of that.
1. Produce a Youtube video with basics such as passwords, links and spotting dodgy websites. Make people watch it.
2. Stick posters up saying stuff like "Don't Click It" or "Verify the source" rather than crap motivational posters.
3. Randomly try basic social engineering work on people and make everyone aware ofbthe failures.
Get it done for free by getting Cyber Security and Physcology Students to run the program.
The thing is, it isn't always common sense. I've seen some phishing emails that really do look legit. Gone are the days when scammers would send out emails (with bad spelling and grammar) that just bluntly asked you to enter your login details into some website the URL of which bore no resemblance to their actual company website URL, to sort out some invented problem on your account.
Some scammers do send out emails that look a lot like they come from Amazon, or Paypal, with URLS that are just a slight misspelling of the original. Even those that come from a scammer pretending to be an educational institution can look very convincing, Admittedly it *is* difficult for a scammer to get hold of an ".ac.uk" domain, but how many people would notice if the URL shown was
Also, when determining the value of doing courses like this, you need to factor in the costs of a breach. Not only with the costs of the breach include the cost of any damage done to the institution and it's systems, but there will be a loss of reputation (hard to actually put a value on this), and there may be a legal cost, whether from legal action (users suing etc) or even fines from the ICO. Bear in mind that the ICO's maximum fines are calculated as a percentage of the institutions gross turnover, so can be many millions of pounds.
Training isn't perfect, and no automated system will prevent 100% of scam emails organisation wide, but I would argue that both help reduce the chances of users getting and acting on scam emails, and a course costing a few thousand pounds is a lot better for the balance sheet than legal action that can run into the hundreds of thousands, or even millions of pounds.
The problem is that such sense is clearly not common. Hence the need for actual training.
Re: Ah IT 'managers'
Cybersecurity training, day 1, lesson 1 - don't use public cloud. :)
Which is really ironic as I'm doing an online MSc in Computer Science with Cyber Security at guess where?
University of York!
University of York!
Whereas all the others are at the University of B ork, I daresay.
University of York!
... and did they make you do a relevant induction process?
Worryingly?
I'm not worried about the 8% that report 5+ incidents. "Prof sends a mail to students and uses CC instead of BCC" is a data breach that technically needs to be reported. Frankly, "prof has former student's mail still in address book" is probably an incident in and of itself because the reason for processing is gone.
I'm worried about the 92%, because I fear 91% don't look or don't report, and only 1% is running a proper shop.
(And we all know that all it takes to make a university stop dead is a handful of current or former students requesting the full extent of information GDPR entitles them to. Yes, that includes paper files.)
At the university where I work, we have an online training course on cyber security and data protection which is mandatory for all staff to complete annually. When we ran a phishing test a sizeable proportion of staff still clicked on the link in the fake phishing email.
This, right here, is the thing. The kind of training that can feasibly be delivered en masse to those sorts of numbers of people - is going to be of questionable value. Heck, the very fact that it's being given to everyone is probably enough to devalue it for some people, who will assume - not unreasonably - that if the bosses really cared, something more targeted would be happening.
It's not if they click on the first link, it's if they still click after round 3.
This has to be iterative
Chop one hand off each time they click on the phishing test. If they manage a third time they're probably beyond help
Little by little, the lesson is sinking in
Security. It's a thing you need to take into account. People are learning that the way they usually do : the hard way.
In this particular case, it's not the universities that are at fault. It's one of their suppliers that was clueless. The only mistake the unis made was using that supplier.
I'm guessing they won't learn anything from that either.
No need to worry, Privacy Figleaf and those special contract clauses will protect you.
Of course as data subjects whose data got breached you can only take legal action in the US. Surely the class action lawyers must be right onto this already.
Do not pay off criminals
So now we have Blackbaud joining the ranks of the people who have paid extortion money, and think that a criminal is going to suddenly turn white as snow just because they have managed to screw some money out of a mark. This is the height of folly; paying a ransom merely demonstrates to the criminal that the info is worth money, something that they didn't know beforehand. Oh lookey here, now we have something of value in our hands; let's hawk it round the darknet forums and see what anyone else will pay for it...
Idiots.
Re: Do not pay off criminals
Look at the numbers hit. If only 5% pay up, thats a huge amount of money with very little risk.
staff competence
From my experience, part of the problem is the recruitment process, the salary for support staff, and general work procedures.
In the places I've worked, all they've asked for is basic computer literacy as a desirable requirement for staff, if they even ask at all.
And with the peanuts they pay admin staff, you get a very low number of applicants.
When I started at an organisation a few years ago I was required to read and sign the staff rules. The section relating to computer use was a generic cut and paste piece of boilerplate that was at least 15 years out of date. One of the first things I did after joining was get them to re-write it.
Mostly it's common sense for the users, don't click on stuff, don't visit sketchy sites, don't share your password.
The problem is that running a special course for all staff and students is not feasible, with externally sourced courses it's a financial problem. Internally you could pull something off during the orientation phase of the first semester. I actually did run an intro course to our Linux pool a decade or so ago (ok, more than a decade).
Plus isn't the theory that the digital naives don't need that?
(I like the auto correct typo above.. Not on purpose)